<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: I'm Infected - Please Help in Norton Internet Security / Norton AntiVirus</title>
    <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/I-m-Infected-Please-Help/m-p/189958#M95018</link>
    <description>&lt;p&gt;Hi CoCo&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;It is better to download these programs from different websites than the original ones because the malware writers know that people will try and use these sites to get the programs and often block them from the infected computers.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Please download HiJackThis from &lt;a href="http://free.antivirus.com/hijackthis/" target="_blank"&gt;http://free.antivirus.com/hijackthis/&lt;/a&gt; Choose the executable and save it on your desktop. Run the file and select the first option on the main menu &amp;quot;Do a system scan and save a log file&amp;quot;. When this is finished, Notepad will open with the log file in it. Save the log file and attach it to a post here via the Add Attachments under the orange Post button Please don't attempt to fix anything that it shows until someone checks out the log. Thanks. It should be version 2.0.2&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Download the free version, install and update then run a FULL scan. After the scan completes you should post the logs back to this thread.&lt;br&gt;&lt;br&gt;You can find Malwarebytes here&lt;br&gt;&lt;br&gt;&lt;a href="http://www.filehippo.com/download_malwarebytes_anti_malware/" target="_blank"&gt;http://www.filehippo.com/download_malwarebytes_anti_malware/&lt;/a&gt;&lt;br&gt;&lt;br&gt;It is a safer location to get the program from than malwarebytes themselves because the malware writers some times block the security programs' websites.&lt;/p&gt;</description>
    <pubDate>Tue, 05 Jan 2010 16:11:31 GMT</pubDate>
    <dc:creator>floplot</dc:creator>
    <dc:date>2010-01-05T16:11:31Z</dc:date>
    <item>
      <title>I'm Infected - Please Help</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/I-m-Infected-Please-Help/m-p/189864#M94979</link>
      <description>&lt;div&gt;I know I'm infected, because here's the behavior that's happening:&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;- When Norton is installed I keep getting errors every few minutes about a Symantec Service Framework crash and a CCSVCHST.EXE crash.&lt;/div&gt;&lt;div&gt;- And it shuts down Norton so it won't work. &lt;/div&gt;&lt;div&gt;- And it won't let me connect to the internet.&lt;/div&gt;&lt;div&gt;- So I used the NRT tool to get rid of Norton.&lt;/div&gt;&lt;div&gt;- But even when I uninstall Norton, it redirects my browser when I try to go to webpages. I could type in Norton.com, but it'll go by itself to 91.212.132.200 and then redirect me to same random AntiVirus site or try to sell me a gun. Phishing, I assume.&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;So I ran Malwarebytes and it said I'm clean. (See attached).&lt;/div&gt;&lt;div&gt;And I also ran HiJackThis (Output pasted below).&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;Do you have any ideas what I caught and how I can get rid of it? It won't let me run Norton to try and catch it.&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;I appreciate your help. I need this computer for school.&lt;/div&gt;&lt;div&gt; &lt;/div&gt;&lt;div&gt;&lt;img title="Malwarebytes.JPG" alt="Malwarebytes.JPG" src="/t5/image/serverpage/image-id/4105i1A3A633F97C26288/image-size/original?v=mpbl-1&amp;amp;px=-1" border="0" align="center"&gt;&lt;/div&gt;&lt;div&gt; &lt;/div&gt;&lt;div&gt;Logfile of HijackThis v1.99.1&lt;/div&gt;&lt;div&gt;Scan saved at 11:10:47 PM, on 1/4/2010&lt;/div&gt;&lt;div&gt;Platform: Windows XP SP3 (WinNT 5.01.2600)&lt;/div&gt;&lt;div&gt;MSIE: Internet Explorer v8.00 (8.00.6001.18702)&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;Running processes:&lt;/div&gt;&lt;div&gt;C:\WINDOWS\System32\smss.exe&lt;/div&gt;&lt;div&gt;C:\WINDOWS\system32\winlogon.exe&lt;/div&gt;&lt;div&gt;C:\WINDOWS\system32\services.exe&lt;/div&gt;&lt;div&gt;C:\WINDOWS\system32\lsass.exe&lt;/div&gt;&lt;div&gt;C:\WINDOWS\system32\svchost.exe&lt;/div&gt;&lt;div&gt;C:\WINDOWS\System32\svchost.exe&lt;/div&gt;&lt;div&gt;C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe&lt;/div&gt;&lt;div&gt;C:\WINDOWS\system32\spoolsv.exe&lt;/div&gt;&lt;div&gt;C:\WINDOWS\system32\agrsmsvc.exe&lt;/div&gt;&lt;div&gt;C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe&lt;/div&gt;&lt;div&gt;C:\Program Files\Bonjour\mDNSResponder.exe&lt;/div&gt;&lt;div&gt;C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe&lt;/div&gt;&lt;div&gt;C:\Program Files\Intel\Wireless\Bin\EvtEng.exe&lt;/div&gt;&lt;div&gt;C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe&lt;/div&gt;&lt;div&gt;C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe&lt;/div&gt;&lt;div&gt;C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE&lt;/div&gt;&lt;div&gt;C:\TOSHIBA\IVP\ISM\pinger.exe&lt;/div&gt;&lt;div&gt;C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe&lt;/div&gt;&lt;div&gt;C:\WINDOWS\system32\svchost.exe&lt;/div&gt;&lt;div&gt;c:\TOSHIBA\IVP\swupdate\swupdtmr.exe&lt;/div&gt;&lt;div&gt;C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe&lt;/div&gt;&lt;div&gt;C:\WINDOWS\system32\TODDSrv.exe&lt;/div&gt;&lt;div&gt;C:\WINDOWS\Explorer.EXE&lt;/div&gt;&lt;div&gt;C:\WINDOWS\system32\wscntfy.exe&lt;/div&gt;&lt;div&gt;C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe&lt;/div&gt;&lt;div&gt;C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe&lt;/div&gt;&lt;div&gt;C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe&lt;/div&gt;&lt;div&gt;C:\Program Files\TOSHIBA\TOSHIBA Direct Disc Writer\ddwmon.exe&lt;/div&gt;&lt;div&gt;C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe&lt;/div&gt;&lt;div&gt;C:\WINDOWS\RTHDCPL.EXE&lt;/div&gt;&lt;div&gt;C:\WINDOWS\system32\igfxtray.exe&lt;/div&gt;&lt;div&gt;C:\WINDOWS\system32\igfxsrvc.exe&lt;/div&gt;&lt;div&gt;C:\WINDOWS\system32\hkcmd.exe&lt;/div&gt;&lt;div&gt;C:\WINDOWS\system32\igfxpers.exe&lt;/div&gt;&lt;div&gt;C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe&lt;/div&gt;&lt;div&gt;C:\Program Files\Synaptics\SynTP\SynTPEnh.exe&lt;/div&gt;&lt;div&gt;C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe&lt;/div&gt;&lt;div&gt;C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe&lt;/div&gt;&lt;div&gt;C:\WINDOWS\system32\TPSMain.exe&lt;/div&gt;&lt;div&gt;C:\Program Files\TOSHIBA\ConfigFree\CFSServ.exe&lt;/div&gt;&lt;div&gt;C:\Program Files\Common Files\Real\Update_OB\realsched.exe&lt;/div&gt;&lt;div&gt;C:\Program Files\iTunes\iTunesHelper.exe&lt;/div&gt;&lt;div&gt;C:\Program Files\Microsoft IntelliPoint\ipoint.exe&lt;/div&gt;&lt;div&gt;C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe&lt;/div&gt;&lt;div&gt;C:\WINDOWS\system32\ctfmon.exe&lt;/div&gt;&lt;div&gt;C:\WINDOWS\system32\TPSBattM.exe&lt;/div&gt;&lt;div&gt;C:\Program Files\ltmoh\Ltmoh.exe&lt;/div&gt;&lt;div&gt;C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIEFA.EXE&lt;/div&gt;&lt;div&gt;C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe&lt;/div&gt;&lt;div&gt;C:\Program Files\Logitech\Logitech Vid\vid.exe&lt;/div&gt;&lt;div&gt;C:\Program Files\Skype\Phone\Skype.exe&lt;/div&gt;&lt;div&gt;C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe&lt;/div&gt;&lt;div&gt;C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe&lt;/div&gt;&lt;div&gt;C:\Program Files\iPod\bin\iPodService.exe&lt;/div&gt;&lt;div&gt;C:\WINDOWS\system32\mspaint.exe&lt;/div&gt;&lt;div&gt;C:\WINDOWS\system32\NOTEPAD.EXE&lt;/div&gt;&lt;div&gt;C:\Documents and Settings\Natalie\Desktop\NORTON\HijackThis1991.exe&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;a href="http://www.facebook.com/" target="_blank"&gt;http://www.facebook.com/&lt;/a&gt;&lt;/div&gt;&lt;div&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &lt;a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/a&gt;&lt;/div&gt;&lt;div&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &lt;a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/a&gt;&lt;/div&gt;&lt;div&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &lt;a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/a&gt;&lt;/div&gt;&lt;div&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/a&gt;&lt;/div&gt;&lt;div&gt;O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll&lt;/div&gt;&lt;div&gt;O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll&lt;/div&gt;&lt;div&gt;O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll&lt;/div&gt;&lt;div&gt;O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll&lt;/div&gt;&lt;div&gt;O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll&lt;/div&gt;&lt;div&gt;O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll&lt;/div&gt;&lt;div&gt;O4 - HKLM\..\Run: [THotkey] C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe&lt;/div&gt;&lt;div&gt;O4 - HKLM\..\Run: [TFncKy] TFncKy.exe&lt;/div&gt;&lt;div&gt;O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe&lt;/div&gt;&lt;div&gt;O4 - HKLM\..\Run: [DDWMon] C:\Program Files\TOSHIBA\TOSHIBA Direct Disc Writer\\ddwmon.exe&lt;/div&gt;&lt;div&gt;O4 - HKLM\..\Run: [SmoothView] C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe&lt;/div&gt;&lt;div&gt;O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE&lt;/div&gt;&lt;div&gt;O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE&lt;/div&gt;&lt;div&gt;O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe&lt;/div&gt;&lt;div&gt;O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe&lt;/div&gt;&lt;div&gt;O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe&lt;/div&gt;&lt;div&gt;O4 - HKLM\..\Run: [IAAnotif] &amp;quot;C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe&amp;quot;&lt;/div&gt;&lt;div&gt;O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe&lt;/div&gt;&lt;div&gt;O4 - HKLM\..\Run: [IntelZeroConfig] &amp;quot;C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe&amp;quot;&lt;/div&gt;&lt;div&gt;O4 - HKLM\..\Run: [IntelWireless] &amp;quot;C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe&amp;quot; /tf Intel PROSet/Wireless&lt;/div&gt;&lt;div&gt;O4 - HKLM\..\Run: [TPSMain] TPSMain.exe&lt;/div&gt;&lt;div&gt;O4 - HKLM\..\Run: [CFSServ.exe] CFSServ.exe -NoClient&lt;/div&gt;&lt;div&gt;O4 - HKLM\..\Run: [TkBellExe] &amp;quot;C:\Program Files\Common Files\Real\Update_OB\realsched.exe&amp;quot;  -osboot&lt;/div&gt;&lt;div&gt;O4 - HKLM\..\Run: [QuickTime Task] &amp;quot;C:\Program Files\QuickTime\qttask.exe&amp;quot; -atboottime&lt;/div&gt;&lt;div&gt;O4 - HKLM\..\Run: [iTunesHelper] &amp;quot;C:\Program Files\iTunes\iTunesHelper.exe&amp;quot;&lt;/div&gt;&lt;div&gt;O4 - HKLM\..\Run: [IntelliPoint] &amp;quot;C:\Program Files\Microsoft IntelliPoint\ipoint.exe&amp;quot;&lt;/div&gt;&lt;div&gt;O4 - HKLM\..\Run: [LogitechQuickCamRibbon] &amp;quot;C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe&amp;quot; /hide&lt;/div&gt;&lt;div&gt;O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe&lt;/div&gt;&lt;div&gt;O4 - HKCU\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe&lt;/div&gt;&lt;div&gt;O4 - HKCU\..\Run: [EPSON Stylus NX200 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIEFA.EXE /FU &amp;quot;C:\WINDOWS\TEMP\E_S83.tmp&amp;quot; /EF &amp;quot;HKCU&amp;quot;&lt;/div&gt;&lt;div&gt;O4 - HKCU\..\Run: [swg] &amp;quot;C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe&amp;quot;&lt;/div&gt;&lt;div&gt;O4 - HKCU\..\Run: [Logitech Vid] &amp;quot;C:\Program Files\Logitech\Logitech Vid\vid.exe&amp;quot; -bootmode&lt;/div&gt;&lt;div&gt;O4 - HKCU\..\Run: [Skype] &amp;quot;C:\Program Files\Skype\Phone\Skype.exe&amp;quot; /nosplash /minimized&lt;/div&gt;&lt;div&gt;O4 - HKCU\..\RunOnce: [Shockwave Updater] C:\WINDOWS\system32\Adobe\SHOCKW~1\SWHELP~1.EXE -Update -1103472 -&amp;quot;Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; GTB6; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)&amp;quot; -&amp;quot;file:///D:/muscular/muscrevw/topic1.html&amp;quot;&lt;/div&gt;&lt;div&gt;O8 - Extra context menu item: E&amp;amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000&lt;/div&gt;&lt;div&gt;O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html&lt;/div&gt;&lt;div&gt;O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll&lt;/div&gt;&lt;div&gt;O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll&lt;/div&gt;&lt;div&gt;O9 - Extra button: (no name) - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll&lt;/div&gt;&lt;div&gt;O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll&lt;/div&gt;&lt;div&gt;O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll&lt;/div&gt;&lt;div&gt;O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL&lt;/div&gt;&lt;div&gt;O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)&lt;/div&gt;&lt;div&gt;O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)&lt;/div&gt;&lt;div&gt;O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;/div&gt;&lt;div&gt;O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;/div&gt;&lt;div&gt;O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll&lt;/div&gt;&lt;div&gt;O11 - Options group: [INTERNATIONAL] International&lt;/div&gt;&lt;div&gt;O14 - IERESET.INF: START_PAGE_URL=&lt;a href="http://www.toshibadirect.com/dpdstart" target="_blank"&gt;http://www.toshibadirect.com/dpdstart&lt;/a&gt;&lt;/div&gt;&lt;div&gt;O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL&lt;/div&gt;&lt;div&gt;O20 - AppInit_DLLs: C:\WINDOWS\system32\PR19.DLL&lt;/div&gt;&lt;div&gt;O20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll (file missing)&lt;/div&gt;&lt;div&gt;O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll&lt;/div&gt;&lt;div&gt;O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll&lt;/div&gt;&lt;div&gt;O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll&lt;/div&gt;&lt;div&gt;O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\WINDOWS\system32\agrsmsvc.exe&lt;/div&gt;&lt;div&gt;O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe&lt;/div&gt;&lt;div&gt;O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe&lt;/div&gt;&lt;div&gt;O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe&lt;/div&gt;&lt;div&gt;O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe&lt;/div&gt;&lt;div&gt;O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe&lt;/div&gt;&lt;div&gt;O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe&lt;/div&gt;&lt;div&gt;O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe&lt;/div&gt;&lt;div&gt;O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe&lt;/div&gt;&lt;div&gt;O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe&lt;/div&gt;&lt;div&gt;O23 - Service: pinger - Unknown owner - C:\TOSHIBA\IVP\ISM\pinger.exe&lt;/div&gt;&lt;div&gt;O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe&lt;/div&gt;&lt;div&gt;O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation  - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe&lt;/div&gt;&lt;div&gt;O23 - Service: Swupdtmr - Unknown owner - c:\TOSHIBA\IVP\swupdate\swupdtmr.exe&lt;/div&gt;&lt;div&gt;O23 - Service: TOSHIBA Application Service (TAPPSRV) - TOSHIBA Corp. - C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe&lt;/div&gt;&lt;div&gt;O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\WINDOWS\system32\TODDSrv.exe &lt;/div&gt;</description>
      <pubDate>Tue, 05 Jan 2010 07:51:27 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/I-m-Infected-Please-Help/m-p/189864#M94979</guid>
      <dc:creator>CoCoRosie</dc:creator>
      <dc:date>2010-01-05T07:51:27Z</dc:date>
    </item>
    <item>
      <title>Re: I'm Infected - Please Help</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/I-m-Infected-Please-Help/m-p/189872#M94980</link>
      <description>&lt;p&gt;I am not clear if you already had Norton installed when you started to get this problem or if you got a problem and then installed Norton.&lt;/p&gt;&lt;p&gt;You also do not say which Norton product you have or had.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;You may have a routekit infection but nodoubt others will advise if this is the case and the software you need to download and run. Meanwhile, you have an awful lot of entries in your Hijack and many are not essential. I would advise temporary disabling ALCMTR.EXE.&lt;/p&gt;&lt;p&gt;I recommend Autoruns from Microsoft for this exercise as it actually moves entries rather than delete them so it is possible to recover easily. However, I Alcmtr is not your issue.&lt;/p&gt;</description>
      <pubDate>Tue, 05 Jan 2010 08:20:40 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/I-m-Infected-Please-Help/m-p/189872#M94980</guid>
      <dc:creator>cgoldman</dc:creator>
      <dc:date>2010-01-05T08:20:40Z</dc:date>
    </item>
    <item>
      <title>Re: I'm Infected - Please Help</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/I-m-Infected-Please-Help/m-p/189873#M94981</link>
      <description>&lt;p&gt;Disabling ALCMTR.EXE, will prevent it from reporting back to Realtek, but don't delete the file.  It is tied into the updating of Realtek audio drivers.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Can you clear your browser caches and temp files?&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Can you open task manager, msconfig, or regedit?&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Did you have Norton on a disc or a download.&lt;/p&gt;</description>
      <pubDate>Tue, 05 Jan 2010 08:37:26 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/I-m-Infected-Please-Help/m-p/189873#M94981</guid>
      <dc:creator>delphinium</dc:creator>
      <dc:date>2010-01-05T08:37:26Z</dc:date>
    </item>
    <item>
      <title>Re: I'm Infected - Please Help</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/I-m-Infected-Please-Help/m-p/189894#M94990</link>
      <description>Hi CoCoRosie, I dont see anything overtly malicious in your HJT log. Since the MBAM scan found nothing but you are still having problems, I would advise you to run a scan with Dr.Web CureIt. Most people haven't heard of it but I can assure you it is a legitimate antimalware app. It often finds things that MBAM and SAS miss, and can even break some rootkits. You dont even need to install it, just download it to your desktop and run it, as long as you get it from the Dr.Web website it is always up to date. By default it runs a quick scan first but after that completes you can run a full scan. You can read more and download it &lt;a href="http://www.freedrweb.com/cureit/" target="_self"&gt;here&lt;/a&gt;</description>
      <pubDate>Tue, 05 Jan 2010 11:03:27 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/I-m-Infected-Please-Help/m-p/189894#M94990</guid>
      <dc:creator>Turbo</dc:creator>
      <dc:date>2010-01-05T11:03:27Z</dc:date>
    </item>
    <item>
      <title>Re: I'm Infected - Please Help</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/I-m-Infected-Please-Help/m-p/189925#M95000</link>
      <description>&lt;div&gt;Thanks so much for you help.&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;I bought and downloaded NAV online. When it didn't work, I got the NIS disk.&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;I can run msconfig, regedit, and Task Manager.&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;I'm downloading Dr.Web CureIt! now. You didn't mention the website is in Russian. Yikes, this is taking a leap in faith. It's also taking a long time to download. I'll report back later on how it did.&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;If it doesn't work, I'm also going to try installing Firefox and see if it hijacks that browser too.&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;Thanks for the help so far.&lt;/div&gt;</description>
      <pubDate>Tue, 05 Jan 2010 14:00:26 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/I-m-Infected-Please-Help/m-p/189925#M95000</guid>
      <dc:creator>CoCoRosie</dc:creator>
      <dc:date>2010-01-05T14:00:26Z</dc:date>
    </item>
    <item>
      <title>Re: I'm Infected - Please Help</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/I-m-Infected-Please-Help/m-p/189932#M95004</link>
      <description>&lt;div&gt;HaHa!&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;So Dr.Web CureIt! found nothing. &lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;So then I decided to try a different browser and opted for Google's Chrome. After installing it, it wouldn't browse anywhere and then promptly crashed. I reopened it and tried to browse somewhere, but nope: &amp;quot;The webpage is not available.&amp;quot;  I use IE, and I can browse just fine (except for 91.212.132.200 redirecting me to other places). So I don't know if that is Google Chrome's fault or the virus' fault. &lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;So I installed Firefox. And it shows the exact same behavior as IE. I'm able to browse around, but I randomly get redirected to bogus antivirus pages.&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;Hmm... I'm stumped.&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;Does anyone have any other ideas? Why is nothing detecting this ugly bugger?&lt;/div&gt;</description>
      <pubDate>Tue, 05 Jan 2010 14:39:52 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/I-m-Infected-Please-Help/m-p/189932#M95004</guid>
      <dc:creator>CoCoRosie</dc:creator>
      <dc:date>2010-01-05T14:39:52Z</dc:date>
    </item>
    <item>
      <title>Re: I'm Infected - Please Help</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/I-m-Infected-Please-Help/m-p/189942#M95009</link>
      <description>&lt;p&gt;Hi CoCo&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Was the scan you did with Malwarebytes updated before you did the scan? I ask that because I see you used an older version of HiJackThis. Are you able to get to sites like Malwarebytes or even the Symantec site without getting redirected?&lt;/p&gt; You are also using a very old Java. Java and Adobe products need to be kept up to date because they are always getting updated for security reasons.&lt;div class="message-edit-history"&gt;&lt;span class="edit-author"&gt;Message Edited by floplot on &lt;/span&gt;&lt;span class="local-date"&gt;01-05-2010&lt;/span&gt;&lt;span class="local-time"&gt; 10:43 AM&lt;/span&gt;&lt;/div&gt;</description>
      <pubDate>Tue, 05 Jan 2010 15:43:01 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/I-m-Infected-Please-Help/m-p/189942#M95009</guid>
      <dc:creator>floplot</dc:creator>
      <dc:date>2010-01-05T15:43:01Z</dc:date>
    </item>
    <item>
      <title>Re: I'm Infected - Please Help</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/I-m-Infected-Please-Help/m-p/189956#M95016</link>
      <description>I downloaded both HiJackThis and Malwarebytes directly from their website yesterday, and yup, MalwareBytes checked for updates.&lt;br&gt;&lt;br&gt;I used another computer to download, and copied over via a thumbdrive.&lt;br&gt;&lt;br&gt;If you'd like, I can update and check again. I was also thinking about trying to install NIS again. I don't know why; I guess doing something is better than sitting here and doing nothing.&lt;br&gt;&lt;br&gt;Help!</description>
      <pubDate>Tue, 05 Jan 2010 16:07:35 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/I-m-Infected-Please-Help/m-p/189956#M95016</guid>
      <dc:creator>CoCoRosie</dc:creator>
      <dc:date>2010-01-05T16:07:35Z</dc:date>
    </item>
    <item>
      <title>Re: I'm Infected - Please Help</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/I-m-Infected-Please-Help/m-p/189958#M95018</link>
      <description>&lt;p&gt;Hi CoCo&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;It is better to download these programs from different websites than the original ones because the malware writers know that people will try and use these sites to get the programs and often block them from the infected computers.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Please download HiJackThis from &lt;a href="http://free.antivirus.com/hijackthis/" target="_blank"&gt;http://free.antivirus.com/hijackthis/&lt;/a&gt; Choose the executable and save it on your desktop. Run the file and select the first option on the main menu &amp;quot;Do a system scan and save a log file&amp;quot;. When this is finished, Notepad will open with the log file in it. Save the log file and attach it to a post here via the Add Attachments under the orange Post button Please don't attempt to fix anything that it shows until someone checks out the log. Thanks. It should be version 2.0.2&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Download the free version, install and update then run a FULL scan. After the scan completes you should post the logs back to this thread.&lt;br&gt;&lt;br&gt;You can find Malwarebytes here&lt;br&gt;&lt;br&gt;&lt;a href="http://www.filehippo.com/download_malwarebytes_anti_malware/" target="_blank"&gt;http://www.filehippo.com/download_malwarebytes_anti_malware/&lt;/a&gt;&lt;br&gt;&lt;br&gt;It is a safer location to get the program from than malwarebytes themselves because the malware writers some times block the security programs' websites.&lt;/p&gt;</description>
      <pubDate>Tue, 05 Jan 2010 16:11:31 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/I-m-Infected-Please-Help/m-p/189958#M95018</guid>
      <dc:creator>floplot</dc:creator>
      <dc:date>2010-01-05T16:11:31Z</dc:date>
    </item>
    <item>
      <title>Re: I'm Infected - Please Help</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/I-m-Infected-Please-Help/m-p/189962#M95022</link>
      <description>&lt;p&gt;If you have installed NAV and then installed NIS over top of it, you have caused yourself some major problems.  You can boot from the NIS disc and run a scan, but you may need to run the Norton Removal Tool first to clear off the double installation before it can work properly.  You will need your activation key from the disc.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;a href="http://www.symantec.com/norton/support/kb/web_view.jsp?wv_type=public_web&amp;amp;ssfromlink=true&amp;amp;sprt_cid=1a13409b-29db-4397-a286-9dec49f8e252&amp;amp;seg=hho&amp;amp;ct=us&amp;amp;lg=en&amp;amp;docurl=20080828154508EN " target="_blank"&gt;NRT&lt;/a&gt;&lt;/p&gt;</description>
      <pubDate>Tue, 05 Jan 2010 16:29:46 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/I-m-Infected-Please-Help/m-p/189962#M95022</guid>
      <dc:creator>delphinium</dc:creator>
      <dc:date>2010-01-05T16:29:46Z</dc:date>
    </item>
    <item>
      <title>Re: I'm Infected - Please Help</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/I-m-Infected-Please-Help/m-p/190029#M95048</link>
      <description>Heh, it took me a bit to figure out how to boot from the CD. Thank you, About.com!&lt;br&gt;&lt;br&gt;Then I used the Norton Bootable Recovery Tool. Total Risks Detected: 0&lt;br&gt;&lt;br&gt;Then I took floplot's suggestion and re-downloaded Malwarebytes and HiJackThis from the links he provided. I then updated them.&lt;br&gt;&lt;br&gt;Malwarebytes found nothing. (Database version: 3496)&lt;br&gt;&lt;br&gt;And the HiJackThis log is below.  Any thoughts?&lt;br&gt;&lt;br&gt;Logfile of Trend Micro HijackThis v2.0.3 (BETA)&lt;br&gt;Scan saved at 11:02:51 AM, on 1/5/2010&lt;br&gt;Platform: Windows XP SP3 (WinNT 5.01.2600)&lt;br&gt;MSIE: Internet Explorer v8.00 (8.00.6001.18702)&lt;br&gt;Boot mode: Normal&lt;br&gt;&lt;br&gt;Running processes:&lt;br&gt;C:\WINDOWS\System32\smss.exe&lt;br&gt;C:\WINDOWS\system32\winlogon.exe&lt;br&gt;C:\WINDOWS\system32\services.exe&lt;br&gt;C:\WINDOWS\system32\lsass.exe&lt;br&gt;C:\WINDOWS\system32\svchost.exe&lt;br&gt;C:\WINDOWS\System32\svchost.exe&lt;br&gt;C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe&lt;br&gt;C:\WINDOWS\system32\spoolsv.exe&lt;br&gt;C:\WINDOWS\system32\agrsmsvc.exe&lt;br&gt;C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe&lt;br&gt;C:\Program Files\Bonjour\mDNSResponder.exe&lt;br&gt;C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe&lt;br&gt;C:\Program Files\Intel\Wireless\Bin\EvtEng.exe&lt;br&gt;C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe&lt;br&gt;C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe&lt;br&gt;C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE&lt;br&gt;C:\TOSHIBA\IVP\ISM\pinger.exe&lt;br&gt;C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe&lt;br&gt;C:\WINDOWS\system32\svchost.exe&lt;br&gt;c:\TOSHIBA\IVP\swupdate\swupdtmr.exe&lt;br&gt;C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe&lt;br&gt;C:\WINDOWS\system32\TODDSrv.exe&lt;br&gt;C:\WINDOWS\Explorer.EXE&lt;br&gt;C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe&lt;br&gt;C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe&lt;br&gt;C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe&lt;br&gt;C:\Program Files\TOSHIBA\TOSHIBA Direct Disc Writer\ddwmon.exe&lt;br&gt;C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe&lt;br&gt;C:\WINDOWS\system32\igfxsrvc.exe&lt;br&gt;C:\WINDOWS\RTHDCPL.EXE&lt;br&gt;C:\WINDOWS\system32\igfxtray.exe&lt;br&gt;C:\WINDOWS\system32\hkcmd.exe&lt;br&gt;C:\WINDOWS\system32\igfxpers.exe&lt;br&gt;C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe&lt;br&gt;C:\Program Files\Synaptics\SynTP\SynTPEnh.exe&lt;br&gt;C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe&lt;br&gt;C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe&lt;br&gt;C:\WINDOWS\system32\TPSMain.exe&lt;br&gt;C:\Program Files\TOSHIBA\ConfigFree\CFSServ.exe&lt;br&gt;C:\Program Files\Common Files\Real\Update_OB\realsched.exe&lt;br&gt;C:\Program Files\iTunes\iTunesHelper.exe&lt;br&gt;C:\Program Files\Microsoft IntelliPoint\ipoint.exe&lt;br&gt;C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe&lt;br&gt;C:\WINDOWS\system32\ctfmon.exe&lt;br&gt;C:\WINDOWS\system32\TPSBattM.exe&lt;br&gt;C:\Program Files\ltmoh\Ltmoh.exe&lt;br&gt;C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIEFA.EXE&lt;br&gt;C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe&lt;br&gt;C:\Program Files\Logitech\Logitech Vid\vid.exe&lt;br&gt;C:\Program Files\Skype\Phone\Skype.exe&lt;br&gt;C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe&lt;br&gt;C:\WINDOWS\system32\wscntfy.exe&lt;br&gt;C:\Documents and Settings\Natalie\Local Settings\Application Data\Google\Update\1.2.183.13\GoogleCrashHandler.exe&lt;br&gt;C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe&lt;br&gt;C:\WINDOWS\System32\svchost.exe&lt;br&gt;C:\Program Files\iPod\bin\iPodService.exe&lt;br&gt;C:\WINDOWS\system32\msiexec.exe&lt;br&gt;C:\Program Files\TrendMicro\HiJackThis\HiJackThis.exe&lt;br&gt;&lt;br&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;a href="http://www.facebook.com/" target="_blank"&gt;http://www.facebook.com/&lt;/a&gt;&lt;br&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &lt;a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/a&gt;&lt;br&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &lt;a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/a&gt;&lt;br&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &lt;a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/a&gt;&lt;br&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/a&gt;&lt;br&gt;O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll&lt;br&gt;O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll&lt;br&gt;O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll&lt;br&gt;O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll&lt;br&gt;O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll&lt;br&gt;O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll&lt;br&gt;O4 - HKLM\..\Run: [THotkey] C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe&lt;br&gt;O4 - HKLM\..\Run: [TFncKy] TFncKy.exe&lt;br&gt;O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe&lt;br&gt;O4 - HKLM\..\Run: [DDWMon] C:\Program Files\TOSHIBA\TOSHIBA Direct Disc Writer\\ddwmon.exe&lt;br&gt;O4 - HKLM\..\Run: [SmoothView] C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe&lt;br&gt;O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE&lt;br&gt;O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE&lt;br&gt;O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe&lt;br&gt;O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe&lt;br&gt;O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe&lt;br&gt;O4 - HKLM\..\Run: [IAAnotif] &amp;quot;C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe&amp;quot;&lt;br&gt;O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe&lt;br&gt;O4 - HKLM\..\Run: [IntelZeroConfig] &amp;quot;C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe&amp;quot;&lt;br&gt;O4 - HKLM\..\Run: [IntelWireless] &amp;quot;C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe&amp;quot; /tf Intel PROSet/Wireless&lt;br&gt;O4 - HKLM\..\Run: [TPSMain] TPSMain.exe&lt;br&gt;O4 - HKLM\..\Run: [CFSServ.exe] CFSServ.exe -NoClient&lt;br&gt;O4 - HKLM\..\Run: [TkBellExe] &amp;quot;C:\Program Files\Common Files\Real\Update_OB\realsched.exe&amp;quot;  -osboot&lt;br&gt;O4 - HKLM\..\Run: [QuickTime Task] &amp;quot;C:\Program Files\QuickTime\qttask.exe&amp;quot; -atboottime&lt;br&gt;O4 - HKLM\..\Run: [iTunesHelper] &amp;quot;C:\Program Files\iTunes\iTunesHelper.exe&amp;quot;&lt;br&gt;O4 - HKLM\..\Run: [IntelliPoint] &amp;quot;C:\Program Files\Microsoft IntelliPoint\ipoint.exe&amp;quot;&lt;br&gt;O4 - HKLM\..\Run: [LogitechQuickCamRibbon] &amp;quot;C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe&amp;quot; /hide&lt;br&gt;O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe&lt;br&gt;O4 - HKCU\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe&lt;br&gt;O4 - HKCU\..\Run: [EPSON Stylus NX200 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIEFA.EXE /FU &amp;quot;C:\WINDOWS\TEMP\E_S83.tmp&amp;quot; /EF &amp;quot;HKCU&amp;quot;&lt;br&gt;O4 - HKCU\..\Run: [swg] &amp;quot;C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe&amp;quot;&lt;br&gt;O4 - HKCU\..\Run: [Logitech Vid] &amp;quot;C:\Program Files\Logitech\Logitech Vid\vid.exe&amp;quot; -bootmode&lt;br&gt;O4 - HKCU\..\Run: [Skype] &amp;quot;C:\Program Files\Skype\Phone\Skype.exe&amp;quot; /nosplash /minimized&lt;br&gt;O4 - HKCU\..\Run: [Google Update] &amp;quot;C:\Documents and Settings\Natalie\Local Settings\Application Data\Google\Update\GoogleUpdate.exe&amp;quot; /c&lt;br&gt;O4 - HKCU\..\RunOnce: [Shockwave Updater] C:\WINDOWS\system32\Adobe\SHOCKW~1\SWHELP~1.EXE -Update -1103472 -&amp;quot;Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; GTB6; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)&amp;quot; -&amp;quot;file:///D:/muscular/muscrevw/topic1.html&amp;quot;&lt;br&gt;O8 - Extra context menu item: E&amp;amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000&lt;br&gt;O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html&lt;br&gt;O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll&lt;br&gt;O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll&lt;br&gt;O9 - Extra button: (no name) - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll&lt;br&gt;O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll&lt;br&gt;O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll&lt;br&gt;O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL&lt;br&gt;O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;br&gt;O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;br&gt;O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;br&gt;O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;br&gt;O14 - IERESET.INF: START_PAGE_URL=&lt;a href="http://www.toshibadirect.com/dpdstart" target="_blank"&gt;http://www.toshibadirect.com/dpdstart&lt;/a&gt;&lt;br&gt;O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL&lt;br&gt;O20 - AppInit_DLLs: C:\WINDOWS\system32\PR19.DLL&lt;br&gt;O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll&lt;br&gt;O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll&lt;br&gt;O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\WINDOWS\system32\agrsmsvc.exe&lt;br&gt;O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe&lt;br&gt;O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe&lt;br&gt;O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe&lt;br&gt;O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe&lt;br&gt;O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe&lt;br&gt;O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe&lt;br&gt;O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe&lt;br&gt;O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe&lt;br&gt;O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe&lt;br&gt;O23 - Service: pinger - Unknown owner - C:\TOSHIBA\IVP\ISM\pinger.exe&lt;br&gt;O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe&lt;br&gt;O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation  - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe&lt;br&gt;O23 - Service: Swupdtmr - Unknown owner - c:\TOSHIBA\IVP\swupdate\swupdtmr.exe&lt;br&gt;O23 - Service: TOSHIBA Application Service (TAPPSRV) - TOSHIBA Corp. - C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe&lt;br&gt;O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\WINDOWS\system32\TODDSrv.exe&lt;br&gt;&lt;br&gt;--&lt;br&gt;End of file - 10843 bytes&lt;br&gt; </description>
      <pubDate>Tue, 05 Jan 2010 19:36:07 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/I-m-Infected-Please-Help/m-p/190029#M95048</guid>
      <dc:creator>CoCoRosie</dc:creator>
      <dc:date>2010-01-05T19:36:07Z</dc:date>
    </item>
    <item>
      <title>Re: I'm Infected - Please Help</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/I-m-Infected-Please-Help/m-p/190032#M95050</link>
      <description>&lt;blockquote&gt;&lt;hr&gt;floplot wrote:&lt;br&gt;&lt;p&gt;Hi CoCo&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;It is better to download these programs from different websites than the original ones because the malware writers know that people will try and use these sites to get the programs and often block them from the infected computers.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Please download HiJackThis from &lt;a href="http://free.antivirus.com/hijackthis/" target="_blank"&gt;http://free.antivirus.com/hijackthis/&lt;/a&gt; Choose the executable and save it on your desktop. Run the file and select the first option on the main menu &amp;quot;Do a system scan and save a log file&amp;quot;. When this is finished, Notepad will open with the log file in it. Save the log file and attach it to a post here via the Add Attachments under the orange Post button Please don't attempt to fix anything that it shows until someone checks out the log. Thanks. It should be version 2.0.2&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Download the free version, install and update then run a FULL scan. After the scan completes you should post the logs back to this thread.&lt;br&gt;&lt;br&gt;You can find Malwarebytes here&lt;br&gt;&lt;br&gt;&lt;a href="http://www.filehippo.com/download_malwarebytes_anti_malware/" target="_blank"&gt;http://www.filehippo.com/download_malwarebytes_anti_malware/&lt;/a&gt;&lt;br&gt;&lt;br&gt;It is a safer location to get the program from than malwarebytes themselves because the malware writers some times block the security programs' websites.&lt;/p&gt;&lt;hr&gt;&lt;/blockquote&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Ummmm, The poster already has Hijackthis as seen by the posted log and Malwarebytes as seen by the posted screenshot.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Quads &lt;/p&gt;</description>
      <pubDate>Tue, 05 Jan 2010 19:41:21 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/I-m-Infected-Please-Help/m-p/190032#M95050</guid>
      <dc:creator>Quads</dc:creator>
      <dc:date>2010-01-05T19:41:21Z</dc:date>
    </item>
    <item>
      <title>Re: I'm Infected - Please Help</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/I-m-Infected-Please-Help/m-p/190036#M95051</link>
      <description>Heh, yeah. I didn't remind re-doing the work... anything to get my computer back running again. I need it for school. Do you have any ideas to help me, Quads?</description>
      <pubDate>Tue, 05 Jan 2010 20:03:31 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/I-m-Infected-Please-Help/m-p/190036#M95051</guid>
      <dc:creator>CoCoRosie</dc:creator>
      <dc:date>2010-01-05T20:03:31Z</dc:date>
    </item>
    <item>
      <title>Re: I'm Infected - Please Help</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/I-m-Infected-Please-Help/m-p/190041#M95052</link>
      <description>&lt;p&gt;Hi&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;The log that was posted originally was from an older version of HiJackThis. When I recently posted a link for HiJackThis, I was told I was posting a link to the older one instead of the current 2.0.2 one. Therefore I thought that perhaps the 2.0.2 one might help more than the older one.&lt;/p&gt;</description>
      <pubDate>Tue, 05 Jan 2010 20:29:54 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/I-m-Infected-Please-Help/m-p/190041#M95052</guid>
      <dc:creator>floplot</dc:creator>
      <dc:date>2010-01-05T20:29:54Z</dc:date>
    </item>
    <item>
      <title>Re: I'm Infected - Please Help</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/I-m-Infected-Please-Help/m-p/190044#M95053</link>
      <description>&lt;p&gt;So I take your comments to mean that nothing stands out in that HiJackThis log either???&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;So where do I go from here?&lt;/p&gt;</description>
      <pubDate>Tue, 05 Jan 2010 20:33:57 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/I-m-Infected-Please-Help/m-p/190044#M95053</guid>
      <dc:creator>CoCoRosie</dc:creator>
      <dc:date>2010-01-05T20:33:57Z</dc:date>
    </item>
    <item>
      <title>Re: I'm Infected - Please Help</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/I-m-Infected-Please-Help/m-p/190072#M95059</link>
      <description>&lt;p&gt;&lt;font face="arial, helvetica, sans-serif"&gt;&lt;span class="Apple-style-span"&gt;I ran the NRT. Then NBRT. It found nothing. So just for good measure I ran NRT again. Restarted. Then tried installing NIS again. It installed. And then almost immediately I got the CCSVCHST error&lt;/span&gt;&lt;/font&gt;&lt;span class="Apple-style-span"&gt;&lt;font face="arial, helvetica, sans-serif"&gt;&lt;span class="Apple-style-span"&gt;. Then the Symantec Service Framework crash. Then it won't let me connect to the Internet. And it won't let NIS scan my computer. &lt;/span&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;span class="Apple-style-span"&gt;&lt;font face="arial, helvetica, sans-serif"&gt;&lt;span class="Apple-style-span"&gt;So sad. :smileysad:&lt;/span&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;</description>
      <pubDate>Tue, 05 Jan 2010 21:46:23 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/I-m-Infected-Please-Help/m-p/190072#M95059</guid>
      <dc:creator>CoCoRosie</dc:creator>
      <dc:date>2010-01-05T21:46:23Z</dc:date>
    </item>
    <item>
      <title>Re: I'm Infected - Please Help</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/I-m-Infected-Please-Help/m-p/190079#M95061</link>
      <description>&lt;p&gt;You could try a scan with Prevx, the free version will remove adware and MBR rootkits but you have to pay for it to remove any other malware that it finds. Detection is free, they claim to have the largest threat database in the world. If it finds something it will tell you what and hopefully where it is and you can go from there. &lt;a href="http://www.prevx.com/homeandfamilyusers.asp?val=max#boxxfree" target="_self"&gt;Prevx&lt;/a&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Note: I just read your latest post, Prevx wont work without an internet connection, after your connectivity is restored you can try it.&lt;/p&gt;</description>
      <pubDate>Tue, 05 Jan 2010 22:06:44 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/I-m-Infected-Please-Help/m-p/190079#M95061</guid>
      <dc:creator>Turbo</dc:creator>
      <dc:date>2010-01-05T22:06:44Z</dc:date>
    </item>
    <item>
      <title>Re: I'm Infected - Please Help</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/I-m-Infected-Please-Help/m-p/190114#M95071</link>
      <description>Can't help but when you get this fixed you should invest in a good image program an a external hard drive. Acronis saved my computer today for me. I'm sure you tried this but have you tried a system restore.&lt;div class="message-edit-history"&gt;&lt;span class="edit-author"&gt;Message Edited by squid13 on &lt;/span&gt;&lt;span class="local-date"&gt;01-05-2010&lt;/span&gt;&lt;span class="local-time"&gt; 05:39 PM&lt;/span&gt;&lt;/div&gt;</description>
      <pubDate>Tue, 05 Jan 2010 23:39:49 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/I-m-Infected-Please-Help/m-p/190114#M95071</guid>
      <dc:creator>squid13</dc:creator>
      <dc:date>2010-01-05T23:39:49Z</dc:date>
    </item>
    <item>
      <title>Re: I'm Infected - Please Help</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/I-m-Infected-Please-Help/m-p/190119#M95075</link>
      <description>&lt;blockquote&gt;&lt;hr&gt;CoCoRosie wrote:&lt;br&gt;Heh, yeah. I didn't remind re-doing the work... anything to get my computer back running again. I need it for school. Do you have any ideas to help me, Quads?&lt;hr&gt;&lt;/blockquote&gt;&lt;blockquote&gt;I no longer Remove Malware whether rootkits like TDL 3, rogues or the like on this forum.&lt;/blockquote&gt;&lt;blockquote&gt; &lt;/blockquote&gt;&lt;blockquote&gt;Quads &lt;/blockquote&gt;&lt;p&gt; &lt;/p&gt;</description>
      <pubDate>Tue, 05 Jan 2010 23:44:00 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/I-m-Infected-Please-Help/m-p/190119#M95075</guid>
      <dc:creator>Quads</dc:creator>
      <dc:date>2010-01-05T23:44:00Z</dc:date>
    </item>
    <item>
      <title>Re: I'm Infected - Please Help</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/I-m-Infected-Please-Help/m-p/190125#M95077</link>
      <description>&lt;blockquote&gt;&lt;hr&gt;Quads wrote:&lt;br&gt;&lt;blockquote&gt;I no longer Remove Malware whether rootkits like TDL 3, rogues or the like on this forum.&lt;/blockquote&gt;&lt;blockquote&gt;Quads &lt;/blockquote&gt;&lt;p&gt; &lt;/p&gt;&lt;hr&gt;&lt;/blockquote&gt;&lt;p&gt;&lt;!-- StartFragment  --&gt;  &lt;img title="cry.gif" alt="cry.gif" src="http://community.norton.com/t5/image/serverpage/image-id/4108i095A66DD629FBE8C/image-size/large?v=mpbl-1&amp;amp;px=-1" border="0" align="center"&gt;&lt;/p&gt;</description>
      <pubDate>Wed, 06 Jan 2010 00:10:44 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/I-m-Infected-Please-Help/m-p/190125#M95077</guid>
      <dc:creator>cgoldman</dc:creator>
      <dc:date>2010-01-06T00:10:44Z</dc:date>
    </item>
  </channel>
</rss>

