<?xml version="1.0" encoding="ISO-8859-1"?>

<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/">
	<channel>
		<title><![CDATA[EXTREME Overclocking Forums - Antivirus & Spyware]]></title>
		<link>http://forums.extremeoverclocking.com</link>
		<description>Help with viruses, trojans, worms, spyware, malware, adware, etc...</description>
		<language>en</language>
		<lastBuildDate>Sat, 21 Nov 2009 20:11:38 GMT</lastBuildDate>
		<generator>vBulletin</generator>
		<ttl>60</ttl>
		<image>
			<url>http://forums.extremeoverclocking.com/images/misc/rss.jpg</url>
			<title><![CDATA[EXTREME Overclocking Forums - Antivirus & Spyware]]></title>
			<link>http://forums.extremeoverclocking.com</link>
		</image>
		<item>
			<title><![CDATA[HiJack This and Malwarebytes' logs]]></title>
			<link>http://forums.extremeoverclocking.com/showthread.php?t=331996&amp;goto=newpost</link>
			<pubDate>Thu, 19 Nov 2009 21:40:17 GMT</pubDate>
			<description><![CDATA[I came back to my computer after a few hours and Comodo blocked *ironclk.exe* from accessing anything.  After seeing this I ran Malwarebytes' and HiJack This.  Here are the logs:

HiJack This


Code:
---------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:01:47 PM, on...]]></description>
			<content:encoded><![CDATA[<div>I came back to my computer after a few hours and Comodo blocked <b>ironclk.exe</b> from accessing anything.  After seeing this I ran Malwarebytes' and HiJack This.  Here are the logs:<br />
<br />
HiJack This<br />
<br />
<div style="margin:20px; margin-top:5px">
	<div class="smallfont" style="margin-bottom:2px">Code:</div>
	<hr /><code style="margin:0px" dir="ltr" style="text-align:left">Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 3:01:47 PM, on 11/19/2009<br />
Platform: Windows Vista SP2 (WinNT 6.00.1906)<br />
MSIE: Internet Explorer v7.00 (7.00.6002.18005)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe<br />
C:\Program Files (x86)\Spybot - Search &amp; Destroy\TeaTimer.exe<br />
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe<br />
C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe<br />
D:\iTunes\iTunesHelper.exe<br />
C:\Program Files (x86)\HP\HP Software Update\hpwuSchd2.exe<br />
D:\VirtualCloneDrive\VCDDaemon.exe<br />
C:\Program Files (x86)\Java\jre6\bin\jusched.exe<br />
D:\OpenOffice.org 3\program\soffice.exe<br />
C:\Program Files\Logitech\SetPoint\x86\SetPoint32.exe<br />
C:\Windows\SysWOW64\ironclk.exe<br />
D:\OpenOffice.org 3\program\soffice.bin<br />
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSTE08.exe<br />
D:\Opera\opera.exe<br />
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe<br />
C:\Program Files (x86)\Trend Micro\HijackThis\HijackThis.exe<br />
<br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157<br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157<br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896<br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896<br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157<br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = <br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = <br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = <br />
R3 - URLSearchHook: DeviceVM Url Search Hook - {0063BF63-BFFF-4B8F-9D26-4267DF7F17DD} - C:\Windows\SysWOW64\dvmurl.dll<br />
O1 - Hosts: ::1 localhost<br />
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll<br />
O2 - BHO: Spybot-S&amp;D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll<br />
O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe<br />
O4 - HKLM\..\Run: [StartCCC] &quot;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe&quot; MSRun<br />
O4 - HKLM\..\Run: [Name of App] C:\Program Files (x86)\SAMSUNG\FW LiveUpdate\FWManager.exe r<br />
O4 - HKLM\..\Run: [NBKeyScan] &quot;D:\Nero\Nero8\Nero BackItUp\NBKeyScan.exe&quot;<br />
O4 - HKLM\..\Run: [ISUSScheduler] &quot;C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe&quot; -start<br />
O4 - HKLM\..\Run: [iTunesHelper] &quot;D:\iTunes\iTunesHelper.exe&quot;<br />
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe<br />
O4 - HKLM\..\Run: [VirtualCloneDrive] &quot;D:\VirtualCloneDrive\VCDDaemon.exe&quot; /s<br />
O4 - HKLM\..\Run: [QuickTime Task] &quot;C:\Program Files (x86)\QuickTime\QTTask.exe&quot; -atboottime<br />
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] &quot;D:\Adobe\Reader\Reader\Reader_sl.exe&quot;<br />
O4 - HKLM\..\Run: [Adobe ARM] &quot;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe&quot;<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] &quot;C:\Program Files (x86)\Java\jre6\bin\jusched.exe&quot;<br />
O4 - HKLM\..\Run: [ick] ironclk.exe<br />
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] &quot;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe&quot; /install /silent<br />
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun<br />
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search &amp; Destroy\TeaTimer.exe<br />
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe<br />
O4 - HKCU\..\Run: [ISUSPM Startup] C:\PROGRA~2\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup<br />
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')<br />
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')<br />
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')<br />
O4 - Startup: OpenOffice.org 3.0.lnk = D:\OpenOffice.org 3\program\quickstart.exe<br />
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe<br />
O4 - Global Startup: Logitech SetPoint.lnk = ?<br />
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll<br />
O9 - Extra 'Tools' menuitem: Spybot - Search &amp; Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll<br />
O13 - Gopher Prefix: <br />
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab<br />
O20 - AppInit_DLLs:&nbsp; &nbsp; &nbsp; C:\Windows\SysWOW64\guard32.dll<br />
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)<br />
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\Windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)<br />
O23 - Service: Ati External Event Utility - Unknown owner - C:\Windows\system32\Ati2evxx.exe (file missing)<br />
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe<br />
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe<br />
O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)<br />
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)<br />
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe<br />
O23 - Service: GEST Service for program management. (GEST Service) - Unknown owner - C:\Program Files (x86)\GIGABYTE\EnergySaver\GSvr.exe<br />
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe<br />
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe<br />
O23 - Service: iPod Service - Apple Inc. - C:\Program Files (x86)\iPod\bin\iPodService.exe<br />
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)<br />
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe<br />
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe<br />
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)<br />
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe<br />
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)<br />
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe<br />
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)<br />
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)<br />
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)<br />
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files (x86)\Spybot - Search &amp; Destroy\SDWinSec.exe<br />
O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)<br />
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)<br />
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)<br />
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe<br />
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)<br />
O23 - Service: ASUS Virtual MFP Service (UsbService) - ASUSTek COMPUTER INC. - C:\Program Files (x86)\ASUS\Printer Utilities\UsbService64.exe<br />
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)<br />
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)<br />
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)<br />
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)<br />
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)<br />
<br />
--<br />
End of file - 9861 bytes</code><hr />
</div>A lot of the entries listes as Service have missing files.  I'm not sure what that is.<br />
<br />
<br />
<br />
Malewarebytes'<br />
<br />
<div style="margin:20px; margin-top:5px">
	<div class="smallfont" style="margin-bottom:2px">Code:</div>
	<hr /><code style="margin:0px" dir="ltr" style="text-align:left">Malwarebytes' Anti-Malware 1.41<br />
Database version: 3198<br />
Windows 6.0.6002 Service Pack 2<br />
<br />
11/19/2009 3:33:32 PM<br />
mbam-log-2009-11-19 (15-33-32).txt<br />
<br />
Scan type: Full Scan (C:\|)<br />
Objects scanned: 247568<br />
Time elapsed: 37 minute(s), 33 second(s)<br />
<br />
Memory Processes Infected: 0<br />
Memory Modules Infected: 0<br />
Registry Keys Infected: 0<br />
Registry Values Infected: 0<br />
Registry Data Items Infected: 0<br />
Folders Infected: 0<br />
Files Infected: 5<br />
<br />
Memory Processes Infected:<br />
(No malicious items detected)<br />
<br />
Memory Modules Infected:<br />
(No malicious items detected)<br />
<br />
Registry Keys Infected:<br />
(No malicious items detected)<br />
<br />
Registry Values Infected:<br />
(No malicious items detected)<br />
<br />
Registry Data Items Infected:<br />
(No malicious items detected)<br />
<br />
Folders Infected:<br />
(No malicious items detected)<br />
<br />
Files Infected:<br />
C:\Users\4-n-zics\AppData\Local\Temp\A386.tmp (Rootkit.TDSS) -&gt; Quarantined and deleted successfully.<br />
C:\Users\4-n-zics\AppData\Local\Temp\cxomerswan.exe (Trojan.Downloader) -&gt; Quarantined and deleted successfully.<br />
C:\Users\4-n-zics\AppData\Local\Temp\nramwexsoc.exe (Trojan.Downloader) -&gt; Quarantined and deleted successfully.<br />
C:\Windows\System32\net.net (Trojan.Downloader) -&gt; Quarantined and deleted successfully.<br />
C:\Windows\SysWOW64\net.net (Trojan.Downloader) -&gt; Quarantined and deleted successfully.</code><hr />
</div>I had those found by Malwarebytes' deleted.<br />
<br />
Below is the image found for the ironclk.exe in the SysWOW64 folder.  Comodo shows ironclk.exe belonging to a company called EP-Service.</div>


	<br />
	<div style="padding:6px">
	
	
		<fieldset class="fieldset">
			<legend>Attached Thumbnails</legend>
			<div style="padding:3px">
			<a href="http://forums.extremeoverclocking.com/attachment.php?attachmentid=141141&amp;d=1258666814" target="_blank"><img class="thumbnail" src="http://forums.extremeoverclocking.com/attachment.php?attachmentid=141141&amp;stc=1&amp;thumb=1&amp;d=1258666814" border="0" alt="Click image for larger version

Name:	ironclk.jpg
Views:	N/A
Size:	22.6 KB
ID:	141141" /></a>
&nbsp;
			</div>
		</fieldset>
	

	
	
	
	
	
	
	</div>
]]></content:encoded>
			<category domain="http://forums.extremeoverclocking.com/forumdisplay.php?f=258"><![CDATA[Antivirus & Spyware]]></category>
			<dc:creator>4-n-zics</dc:creator>
			<guid isPermaLink="true">http://forums.extremeoverclocking.com/showthread.php?t=331996</guid>
		</item>
		<item>
			<title>recomendation for top 3 antivirus.</title>
			<link>http://forums.extremeoverclocking.com/showthread.php?t=331693&amp;goto=newpost</link>
			<pubDate>Sat, 14 Nov 2009 18:30:19 GMT</pubDate>
			<description><![CDATA[Well the response that i got to fix the problem in my comp was to reformat, and i will do so, the problem is i have panda and i don't really like it at all, in your opinion what are the top 3 antivirus on the market right now. Thanks]]></description>
			<content:encoded><![CDATA[<div>Well the response that i got to fix the problem in my comp was to reformat, and i will do so, the problem is i have panda and i don't really like it at all, in your opinion what are the top 3 antivirus on the market right now. Thanks</div>

]]></content:encoded>
			<category domain="http://forums.extremeoverclocking.com/forumdisplay.php?f=258"><![CDATA[Antivirus & Spyware]]></category>
			<dc:creator>thegt1</dc:creator>
			<guid isPermaLink="true">http://forums.extremeoverclocking.com/showthread.php?t=331693</guid>
		</item>
		<item>
			<title>In need of assistance for a potential antivirus problem.</title>
			<link>http://forums.extremeoverclocking.com/showthread.php?t=331631&amp;goto=newpost</link>
			<pubDate>Fri, 13 Nov 2009 15:33:16 GMT</pubDate>
			<description>Hi fellows about 4 days ago i got what seem to be a virus on my system, every time that i click on anything i was getting a message unable to open the application i went and got panda security suite and as soon as the system sense that i was installing this thing it shut the comp all by itself i...</description>
			<content:encoded><![CDATA[<div>Hi fellows about 4 days ago i got what seem to be a virus on my system, every time that i click on anything i was getting a message unable to open the application i went and got panda security suite and as soon as the system sense that i was installing this thing it shut the comp all by itself i tried to stop it before finishing the install but it shut it down anyways.<br />
<br />
the next time that i try to boot up all i got was a blue screen with the cursor only, at this time i did  a repair install and i was able to boot the system up but is really in bad shape, i need it to install new video drivers, and a ton of programs are not even working, services are not able run, after all this i ran malware, spyware and finally ran the panda suite.<br />
<br />
This combo found a ton of stuff, but still not running properly, at the present when i try to connect to a site it gets sent to a different one, i have panda running and it doesn't detect anything even so is clear there's something messing the system.<br />
<br />
Any help on what should i do next, will be greatly appreciated. Thank in advance.</div>

]]></content:encoded>
			<category domain="http://forums.extremeoverclocking.com/forumdisplay.php?f=258"><![CDATA[Antivirus & Spyware]]></category>
			<dc:creator>thegt1</dc:creator>
			<guid isPermaLink="true">http://forums.extremeoverclocking.com/showthread.php?t=331631</guid>
		</item>
		<item>
			<title>HighJackThis Log</title>
			<link>http://forums.extremeoverclocking.com/showthread.php?t=331402&amp;goto=newpost</link>
			<pubDate>Mon, 09 Nov 2009 02:50:31 GMT</pubDate>
			<description>I could have swore that i posted this last night and even have the log from last night that i ran with the time on it, weird :confused:

Internets been little sluggish lately please look over this crunchie and thank you ahead of time :lol


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at...</description>
			<content:encoded><![CDATA[<div>I could have swore that i posted this last night and even have the log from last night that i ran with the time on it, weird :confused:<br />
<br />
Internets been little sluggish lately please look over this crunchie and thank you ahead of time :lol<br />
<br />
<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 9:50:12 PM, on 11/8/2009<br />
Platform: Unknown Windows (WinNT 6.01.3504)<br />
MSIE: Internet Explorer v8.00 (8.00.7600.16385)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\Windows\vVX3000.exe<br />
C:\Program Files (x86)\AIM\aim.exe<br />
C:\Program Files (x86)\iTunes\iTunesHelper.exe<br />
C:\Program Files (x86)\Java\jre6\bin\jusched.exe<br />
C:\Program Files (x86)\PowerISO\PWRISOVM.EXE<br />
C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe<br />
C:\Program Files (x86)\uTorrent\uTorrent.exe<br />
C:\Program Files (x86)\ooVoo\ooVoo.exe<br />
C:\Program Files (x86)\Mozilla Firefox\firefox.exe<br />
C:\Program Files (x86)\Trend Micro\HijackThis\HijackThis.exe<br />
<br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = <br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = <br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = <br />
R3 - URLSearchHook: DeviceVM Url Search Hook - {0063BF63-BFFF-4B8F-9D26-4267DF7F17DD} - C:\Windows\SysWOW64\dvmurl.dll<br />
F2 - REG:system.ini: UserInit=userinit.exe<br />
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll<br />
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~2\Office12\GR469A~1.DLL<br />
O2 - BHO: ooVoo Toolbar - {A1FB2F9A-D35E-11DD-8935-E46A56D89593} - C:\Program Files (x86)\oovootb\oovoodx.dll<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll<br />
O3 - Toolbar: ooVoo Toolbar - {A1FB2F9A-D35E-11DD-8935-E46A56D89593} - C:\Program Files (x86)\oovootb\oovoodx.dll<br />
O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe<br />
O4 - HKLM\..\Run: [LifeCam] &quot;C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe&quot;<br />
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] &quot;C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe&quot;<br />
O4 - HKLM\..\Run: [GrooveMonitor] &quot;C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe&quot;<br />
O4 - HKLM\..\Run: [QuickTime Task] &quot;C:\Program Files (x86)\QuickTime\QTTask.exe&quot; -atboottime<br />
O4 - HKLM\..\Run: [iTunesHelper] &quot;C:\Program Files (x86)\iTunes\iTunesHelper.exe&quot;<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] &quot;C:\Program Files (x86)\Java\jre6\bin\jusched.exe&quot;<br />
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files (x86)\PowerISO\PWRISOVM.EXE<br />
O4 - HKLM\..\Run: [AdobeCS4ServiceManager] &quot;C:\Program Files (x86)\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.ex  e&quot; -launchedbylogin<br />
O4 - HKLM\..\Run: [EVGAPrecision] &quot;D:\Program Files\EVGA Precision\EVGAPrecisionWrapper.exe&quot; /s<br />
O4 - HKLM\..\Run: [ISUSScheduler] &quot;C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe&quot; -start<br />
O4 - HKCU\..\Run: [Aim] &quot;C:\Program Files (x86)\AIM\aim.exe&quot; /d locale=en-US<br />
O4 - HKCU\..\Run: [ISUSPM Startup] C:\PROGRA~2\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup<br />
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')<br />
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')<br />
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')<br />
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000<br />
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll<br />
O9 - Extra 'Tools' menuitem: S&amp;end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL<br />
O13 - Gopher Prefix: <br />
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~2\MICROS~2\Office12\GRA32A~1.DLL<br />
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL<br />
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)<br />
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe<br />
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)<br />
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)<br />
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe<br />
O23 - Service: FLEXnet Licensing Service 64 - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe<br />
O23 - Service: GEST Service for program management. (GEST Service) - Unknown owner - C:\Program Files (x86)\GIGABYTE\EnergySaver\GSvr.exe<br />
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe<br />
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)<br />
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)<br />
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)<br />
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)<br />
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)<br />
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)<br />
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)<br />
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)<br />
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)<br />
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)<br />
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe<br />
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)<br />
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)<br />
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)<br />
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files (x86)\Viewpoint\Common\ViewpointService.exe<br />
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)<br />
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)<br />
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)<br />
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)<br />
<br />
--<br />
End of file - 8765 bytes</div>

]]></content:encoded>
			<category domain="http://forums.extremeoverclocking.com/forumdisplay.php?f=258"><![CDATA[Antivirus & Spyware]]></category>
			<dc:creator>Huttar</dc:creator>
			<guid isPermaLink="true">http://forums.extremeoverclocking.com/showthread.php?t=331402</guid>
		</item>
		<item>
			<title>Microsoft Security Essentials</title>
			<link>http://forums.extremeoverclocking.com/showthread.php?t=330831&amp;goto=newpost</link>
			<pubDate>Thu, 29 Oct 2009 03:22:46 GMT</pubDate>
			<description>Is anyone using this antivirus/spyware/malware program yet, its in its infancy but its a start... cant beat it for free.

http://www.microsoft.com/Security_Essentials/</description>
			<content:encoded><![CDATA[<div>Is anyone using this antivirus/spyware/malware program yet, its in its infancy but its a start... cant beat it for free.<br />
<br />
<a href="http://www.microsoft.com/Security_Essentials/" target="_blank">http://www.microsoft.com/Security_Essentials/</a></div>

]]></content:encoded>
			<category domain="http://forums.extremeoverclocking.com/forumdisplay.php?f=258"><![CDATA[Antivirus & Spyware]]></category>
			<dc:creator>BigE4u</dc:creator>
			<guid isPermaLink="true">http://forums.extremeoverclocking.com/showthread.php?t=330831</guid>
		</item>
		<item>
			<title>Avira Antivir failing to install on 7 Ultimate x64</title>
			<link>http://forums.extremeoverclocking.com/showthread.php?t=330672&amp;goto=newpost</link>
			<pubDate>Mon, 26 Oct 2009 04:29:41 GMT</pubDate>
			<description>I would like to continue using Antivir. Has anyone gotten it to work?</description>
			<content:encoded><![CDATA[<div>I would like to continue using Antivir. Has anyone gotten it to work?</div>

]]></content:encoded>
			<category domain="http://forums.extremeoverclocking.com/forumdisplay.php?f=258"><![CDATA[Antivirus & Spyware]]></category>
			<dc:creator>Carozzeria</dc:creator>
			<guid isPermaLink="true">http://forums.extremeoverclocking.com/showthread.php?t=330672</guid>
		</item>
		<item>
			<title>Noob virus/spyware question</title>
			<link>http://forums.extremeoverclocking.com/showthread.php?t=330587&amp;goto=newpost</link>
			<pubDate>Sat, 24 Oct 2009 16:47:47 GMT</pubDate>
			<description>Hello, sorry if this is a stupid question, which it probably is.

If a computer on my home network is infacted, can it infect the other computers in my house using the same wireless network?  ...even if the infected computer doesnt send me any emails or files, ect.???

Thanks for your help guys. ...</description>
			<content:encoded><![CDATA[<div>Hello, sorry if this is a stupid question, which it probably is.<br />
<br />
If a computer on my home network is infacted, can it infect the other computers in my house using the same wireless network?  ...even if the infected computer doesnt send me any emails or files, ect.???<br />
<br />
Thanks for your help guys.  My cousins computer has a bunch of viruses and spyware but he wont let me reformat it.</div>

]]></content:encoded>
			<category domain="http://forums.extremeoverclocking.com/forumdisplay.php?f=258"><![CDATA[Antivirus & Spyware]]></category>
			<dc:creator>chocotiger</dc:creator>
			<guid isPermaLink="true">http://forums.extremeoverclocking.com/showthread.php?t=330587</guid>
		</item>
	</channel>
</rss>
