<?xml version="1.0" encoding="ISO-8859-1"?>

<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/">
	<channel>
		<title>Tech Support Forums - TechIMO.com - Security and Privacy Issues</title>
		<link>http://www.techimo.com/forum</link>
		<description>OS/app security updates, virus reports, securing systems, privacy, spam.</description>
		<language>en</language>
		<lastBuildDate>Sat, 21 Nov 2009 05:19:42 GMT</lastBuildDate>
		<generator>vBulletin</generator>
		<ttl>60</ttl>
		<image>
			<url>http://www.techimo.com/forum/images/misc/rss.jpg</url>
			<title>Tech Support Forums - TechIMO.com - Security and Privacy Issues</title>
			<link>http://www.techimo.com/forum</link>
		</image>
		<item>
			<title><![CDATA[Dept. of HS: NSA 'Helped' Develop Vista and Windows Seven]]></title>
			<link>http://www.techimo.com/forum/security-privacy-issues/239776-dept-hs-nsa-helped-develop-vista-windows-seven.html</link>
			<pubDate>Fri, 20 Nov 2009 04:56:55 GMT</pubDate>
			<description><![CDATA[http://news.softpedia.com/news/Windows-7-Hardened-with-the-Help-of-the-National-Security-Agency-127426.shtml


---Quote---
Following the release of Windows XP, Microsoft implemented the Security Development Lifecycle in the building of Windows Vista, touting a tangibly superior operating system in terms of security. [more]
---End Quote---
Windows 7 probably has all kinds of spyware communicating with Microsoft. ITS THE WORST OS FOR PRIVACY!! (Even if doing nothing wrong,PRIVACY SHOULD BE YOURS *ON YOUR COMPUTER!*)]]></description>
			<content:encoded><![CDATA[<div><a href="http://news.softpedia.com/news/Windows-7-Hardened-with-the-Help-of-the-National-Security-Agency-127426.shtml" target="_blank">http://news.softpedia.com/news/Windo...y-127426.shtml</a><br />
<br />
<div style="margin:20px; margin-top:5px; ">
	<div class="smallfont" style="margin-bottom:2px">Quote:</div>
	<table cellpadding="6" cellspacing="0" border="0" width="100%">
	<tr>
		<td class="alt2">
			<hr />
			
				Following the release of Windows XP, Microsoft implemented the Security Development Lifecycle in the building of Windows Vista, touting a tangibly superior operating system in terms of security. [more]
			
			<hr />
		</td>
	</tr>
	</table>
</div>Windows 7 probably has all kinds of spyware communicating with Microsoft. ITS THE WORST OS FOR PRIVACY!! (Even if doing nothing wrong,PRIVACY SHOULD BE YOURS <b>ON YOUR COMPUTER!</b>)</div>

]]></content:encoded>
			<category domain="http://www.techimo.com/forum/security-privacy-issues/">Security and Privacy Issues</category>
			<dc:creator>Dude111</dc:creator>
			<guid isPermaLink="true">http://www.techimo.com/forum/security-privacy-issues/239776-dept-hs-nsa-helped-develop-vista-windows-seven.html</guid>
		</item>
		<item>
			<title>IE is considered MORE secure than Firefox</title>
			<link>http://www.techimo.com/forum/security-privacy-issues/239735-ie-considered-more-secure-than-firefox.html</link>
			<pubDate>Thu, 19 Nov 2009 09:24:16 GMT</pubDate>
			<description>http://gcn.com/articles/2009/11/16/opera-internet-explorer-browser-security.aspx

*Firefox was the most vulnerable browser, logging 44 percent of the total vulnerabilities found, according to the report. Safari, at 35 percent, ranked next to Firefox at the bottom. IE had 15 percent of the vulnerabilities, and Opera only 6 percent.*

Interesting indeed......</description>
			<content:encoded><![CDATA[<div><a href="http://gcn.com/articles/2009/11/16/opera-internet-explorer-browser-security.aspx" target="_blank">http://gcn.com/articles/2009/11/16/o...-security.aspx</a><br />
<br />
<b>Firefox was the most vulnerable browser, logging 44 percent of the total vulnerabilities found, according to the report. Safari, at 35 percent, ranked next to Firefox at the bottom. IE had 15 percent of the vulnerabilities, and Opera only 6 percent.</b><br />
<br />
Interesting indeed......</div>

]]></content:encoded>
			<category domain="http://www.techimo.com/forum/security-privacy-issues/">Security and Privacy Issues</category>
			<dc:creator>Dude111</dc:creator>
			<guid isPermaLink="true">http://www.techimo.com/forum/security-privacy-issues/239735-ie-considered-more-secure-than-firefox.html</guid>
		</item>
		<item>
			<title>Interesting issue with Winpea.exe</title>
			<link>http://www.techimo.com/forum/security-privacy-issues/239712-interesting-issue-winpea-exe.html</link>
			<pubDate>Thu, 19 Nov 2009 00:50:18 GMT</pubDate>
			<description><![CDATA[I was sitting here browsing the web when suddenly I noticed some strange slow down on my pc. Oddly enough I checked the task manager and see some strange entries for a service (winpea.exe) as well as a few other odd acting services.

I've been running scans with MSE and hadn't been doing any high risk activity so I wasn't sure what was going on. Well here's what I found via malwarebytes


---Quote---
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\raidhost (Trojan.Agent) -> Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoActiveDesktopChanges (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Windows\Cursors\lsass.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Windows\Cursors\supdate.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Windows\raidhost.exe (Trojan.Agent) -> Delete on reboot.

update two more hits that showed on a second scan

C:\Users\Rich\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\73RJU374\xrupdate[1].exe (Spyware.Passwords) -> No action taken.
C:\Windows\update.exe (Spyware.Passwords) -> No action taken.
C:\Windows\updatekl.exe (Spyware.Passwords) -> No action taken.
---End Quote---
Not sure were the heck they came from but the only reason I caught it was the Winpea.exe entry, which oddly enough doesn't show as being infected or being malicious. I'm running a few more scans to be sure but thought I'd share some findings.

edit: Alright well since I can't find much info - here's what it affected- Winpea.exe was installed to c:>windows>Syswow64, along with a few other files as listed above. I first noticed two instances running in the task manager. One would activate then run for a second then a second instance would activate just before the first shut down. Making it nearly impossible to kill via the TM. I noticed several cmd and console task running all with high CPU usage. Not sure what it was doing but Malwarebytes seems to have caught it, MSE however did not.]]></description>
			<content:encoded><![CDATA[<div>I was sitting here browsing the web when suddenly I noticed some strange slow down on my pc. Oddly enough I checked the task manager and see some strange entries for a service (winpea.exe) as well as a few other odd acting services.<br />
<br />
I've been running scans with MSE and hadn't been doing any high risk activity so I wasn't sure what was going on. Well here's what I found via malwarebytes<br />
<br />
<div style="margin:20px; margin-top:5px; ">
	<div class="smallfont" style="margin-bottom:2px">Quote:</div>
	<table cellpadding="6" cellspacing="0" border="0" width="100%">
	<tr>
		<td class="alt2">
			<hr />
			
				Registry Values Infected:<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr  entVersion\Run\raidhost (Trojan.Agent) -&gt; Quarantined and deleted successfully.<br />
<br />
Registry Data Items Infected:<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr  entVersion\Policies\Explorer\NoActiveDesktopChange  s (Hijack.DisplayProperties) -&gt; Bad: (1) Good: (0) -&gt; Quarantined and deleted successfully.<br />
<br />
Folders Infected:<br />
(No malicious items detected)<br />
<br />
Files Infected:<br />
C:\Windows\Cursors\lsass.exe (Trojan.Agent) -&gt; Quarantined and deleted successfully.<br />
C:\Windows\Cursors\supdate.exe (Trojan.Agent) -&gt; Quarantined and deleted successfully.<br />
C:\Windows\raidhost.exe (Trojan.Agent) -&gt; Delete on reboot.<br />
<br />
update two more hits that showed on a second scan<br />
<br />
C:\Users\Rich\AppData\Local\Microsoft\Windows\Temp  orary Internet Files\Content.IE5\73RJU374\xrupdate[1].exe (Spyware.Passwords) -&gt; No action taken.<br />
C:\Windows\update.exe (Spyware.Passwords) -&gt; No action taken.<br />
C:\Windows\updatekl.exe (Spyware.Passwords) -&gt; No action taken.
			
			<hr />
		</td>
	</tr>
	</table>
</div>Not sure were the heck they came from but the only reason I caught it was the Winpea.exe entry, which oddly enough doesn't show as being infected or being malicious. I'm running a few more scans to be sure but thought I'd share some findings.<br />
<br />
edit: Alright well since I can't find much info - here's what it affected- Winpea.exe was installed to c:&gt;windows&gt;Syswow64, along with a few other files as listed above. I first noticed two instances running in the task manager. One would activate then run for a second then a second instance would activate just before the first shut down. Making it nearly impossible to kill via the TM. I noticed several cmd and console task running all with high CPU usage. Not sure what it was doing but Malwarebytes seems to have caught it, MSE however did not.</div>

]]></content:encoded>
			<category domain="http://www.techimo.com/forum/security-privacy-issues/">Security and Privacy Issues</category>
			<dc:creator>RicheemxX</dc:creator>
			<guid isPermaLink="true">http://www.techimo.com/forum/security-privacy-issues/239712-interesting-issue-winpea-exe.html</guid>
		</item>
		<item>
			<title>Virus advise</title>
			<link>http://www.techimo.com/forum/security-privacy-issues/239687-virus-advise.html</link>
			<pubDate>Wed, 18 Nov 2009 13:46:15 GMT</pubDate>
			<description>Could anyone please tell me which section of the forum should i post for advise on a virus i have picked up?

Thanks for any replies.</description>
			<content:encoded><![CDATA[<div>Could anyone please tell me which section of the forum should i post for advise on a virus i have picked up?<br />
<br />
Thanks for any replies.</div>

]]></content:encoded>
			<category domain="http://www.techimo.com/forum/security-privacy-issues/">Security and Privacy Issues</category>
			<dc:creator>Minger</dc:creator>
			<guid isPermaLink="true">http://www.techimo.com/forum/security-privacy-issues/239687-virus-advise.html</guid>
		</item>
		<item>
			<title>C:\RECYCLER\S-1-5-21-515967899-162531612-839522115-1003\Dc11.exe</title>
			<link>http://www.techimo.com/forum/security-privacy-issues/239488-c-recycler-s-1-5-21-515967899-162531612-839522115-1003-dc11-exe.html</link>
			<pubDate>Fri, 13 Nov 2009 23:07:05 GMT</pubDate>
			<description><![CDATA[Found this on my system with AdAware and now I can't seem to get it to go away. Help!!


Here is the AdAware scan log

Logfile created: 11/8/2009 7:56:46
Lavasoft Ad-Aware version: 8.0.8
Extended engine version: 8.1
User performing scan: Mike

*********************** Definitions database information ***********************
Lavasoft definition file: 149.88
Extended engine definition file: 8.1

******************************** Scan results: *********************************
Scan profile name: Full Scan  (ID: full)
Objects scanned: 243058
Objects detected: 3


Type              Detected
==========================
Processes.......:        0
Registry entries:        1
Hostfile entries:        0
Files...........:        2
Folders.........:        0
LSPs............:        0
Cookies.........:        0
Browser hijacks.:        0
MRU objects.....:        0



Skipped items:
Description: HKLM:HKEY_CLASSES_ROOT\CLSID\{376892AE-1825-4E5F-9F85-23F9640051CC}: Family Name: unknown Clean status: Success Item ID: 1 Family ID: 0

Quarantined items:
Description: C:\System Volume Information\_restore{29738EDF-543B-4F0F-9399-E166B53629A1}\RP13\A0008022.exe Family Name: Win32.Adware.MeMedia Clean status: Success Item ID: 1327738 Family ID: 2094
Description: C:\RECYCLER\S-1-5-21-515967899-162531612-839522115-1003\Dc11.exe Family Name: Win32.Monitor.SpyBuddy Clean status: Success Item ID: 937664 Family ID: 3212

Scan and cleaning complete: Finished correctly after 8969 seconds

*********************************** Settings ***********************************

Scan profile:
ID: full, enabled:1, value: Full Scan
  ID: scancriticalareas, enabled:1, value: true
  ID: scanrunningapps, enabled:1, value: true
  ID: scanregistry, enabled:1, value: true
  ID: scanlsp, enabled:1, value: true
  ID: scanads, enabled:1, value: true
  ID: scanhostsfile, enabled:1, value: true
  ID: scanmru, enabled:1, value: true
  ID: scanbrowserhijacks, enabled:1, value: true
  ID: scantrackingcookies, enabled:1, value: true
    ID: closebrowsers, enabled:1, value: false
  ID: folderstoscan, enabled:1, value: C:\,D:\
  ID: usespywareheuristics, enabled:1, value: true
  ID: extendedengine, enabled:0, value: true
    ID: useheuristics, enabled:0, value: true
      ID: heuristicslevel, enabled:0, value: mild, domain: medium,mild,strict
  ID: filescanningoptions, enabled:1
    ID: scanrootkits, enabled:1, value: true
    ID: archives, enabled:1, value: true
    ID: onlyexecutables, enabled:1, value: false
    ID: skiplargerthan, enabled:1, value: 20480

Scan global:
ID: global, enabled:1
  ID: addtocontextmenu, enabled:1, value: true
  ID: playsoundoninfection, enabled:1, value: false
    ID: soundfile, enabled:0, value: *to be filled in automatically*\alert.wav

Scheduled scan settings:
<Empty>

Update settings:
ID: updates, enabled:1
  ID: launchthreatworksafterscan, enabled:1, value: normal, domain: normal,off,silently
  ID: softwareupdates, enabled:1, value: downloadandinstall, domain: dontcheck,downloadandinstall
  ID: licenseandinfo, enabled:1, value: downloadandinstall, domain: dontcheck,downloadandinstall
  ID: schedules, enabled:1, value: true
    ID: updatedaily, enabled:1, value: Daily
      ID: time, enabled:1, value: Fri Jul 24 17:35:00 2009
      ID: frequency, enabled:1, value: daily, domain: daily,monthly,once,systemstart,weekly
      ID: weekdays, enabled:1
        ID: monday, enabled:1, value: false
        ID: tuesday, enabled:1, value: false
        ID: wednesday, enabled:1, value: false
        ID: thursday, enabled:1, value: false
        ID: friday, enabled:1, value: false
        ID: saturday, enabled:1, value: false
        ID: sunday, enabled:1, value: false
      ID: monthly, enabled:1, value: 1, minvalue: 1, maxvalue: 31
      ID: scanprofile, enabled:1, value: 
      ID: auto_deal_with_infections, enabled:1, value: false
    ID: updateweekly, enabled:1, value: Weekly
      ID: time, enabled:1, value: Fri Jul 24 17:35:00 2009
      ID: frequency, enabled:1, value: weekly, domain: daily,monthly,once,systemstart,weekly
      ID: weekdays, enabled:1
        ID: monday, enabled:1, value: true
        ID: tuesday, enabled:1, value: false
        ID: wednesday, enabled:1, value: false
        ID: thursday, enabled:1, value: false
        ID: friday, enabled:1, value: true
        ID: saturday, enabled:1, value: false
        ID: sunday, enabled:1, value: false
      ID: monthly, enabled:1, value: 1, minvalue: 1, maxvalue: 31
      ID: scanprofile, enabled:1, value: 
      ID: auto_deal_with_infections, enabled:1, value: false

Appearance settings:
ID: appearance, enabled:1
  ID: skin, enabled:1, value: default.egl, reglocation: HKEY_LOCAL_MACHINE\SOFTWARE\Lavasoft\Ad-Aware\Resource
  ID: showtrayicon, enabled:1, value: true
  ID: language, enabled:1, value: en, reglocation: HKEY_LOCAL_MACHINE\SOFTWARE\Lavasoft\Ad-Aware\Language

Realtime protection settings:
ID: realtime, enabled:1
  ID: processprotection, enabled:1, value: true
  ID: registryprotection, enabled:0, value: true
  ID: networkprotection, enabled:0, value: true
  ID: usespywareheuristics, enabled:0, value: true
  ID: extendedengine, enabled:0, value: true
    ID: useheuristics, enabled:0, value: true
      ID: heuristicslevel, enabled:0, value: strict, domain: medium,mild,strict
  ID: infomessages, enabled:1, value: onlyimportant, domain: display,dontnotify,onlyimportant


****************************** System information ******************************
Computer name: DRAGONMA-GQNUHE
Processor name: AMD Athlon(tm) 64 X2 Dual Core Processor 5000+
Processor identifier: x86 Family 15 Model 107 Stepping 2
Raw info: processorarchitecture 0, processortype 586, processorlevel 15, processor revision 27394, number of processors 2
Physical memory available: 1263267840 bytes
Physical memory total: 2145824768 bytes
Virtual memory available: 1980641280 bytes
Virtual memory total: 2147352576 bytes
Memory load: 41%
Microsoft Windows XP Professional Service Pack 3 (build 2600)
Windows startup mode:

Running processes:
PID: 692 name: \SystemRoot\System32\smss.exe owner: SYSTEM domain: NT AUTHORITY
PID: 756 name: \??\D:\WINDOWS\system32\csrss.exe owner: SYSTEM domain: NT AUTHORITY
PID: 780 name: \??\D:\WINDOWS\system32\winlogon.exe owner: SYSTEM domain: NT AUTHORITY
PID: 824 name: D:\WINDOWS\system32\services.exe owner: SYSTEM domain: NT AUTHORITY
PID: 836 name: D:\WINDOWS\system32\lsass.exe owner: SYSTEM domain: NT AUTHORITY
PID: 1012 name: D:\WINDOWS\system32\nvsvc32.exe owner: SYSTEM domain: NT AUTHORITY
PID: 1044 name: D:\WINDOWS\system32\svchost.exe owner: SYSTEM domain: NT AUTHORITY
PID: 1116 name: D:\WINDOWS\system32\svchost.exe owner: NETWORK SERVICE domain: NT AUTHORITY
PID: 1212 name: D:\WINDOWS\System32\svchost.exe owner: SYSTEM domain: NT AUTHORITY
PID: 1336 name: D:\WINDOWS\System32\svchost.exe owner: NETWORK SERVICE domain: NT AUTHORITY
PID: 1412 name: D:\WINDOWS\System32\svchost.exe owner: LOCAL SERVICE domain: NT AUTHORITY
PID: 1456 name: D:\Program Files\Lavasoft\Ad-Aware\AAWService.exe owner: SYSTEM domain: NT AUTHORITY
PID: 1612 name: D:\WINDOWS\system32\spoolsv.exe owner: SYSTEM domain: NT AUTHORITY
PID: 2032 name: D:\WINDOWS\Explorer.EXE owner: Mike domain: DRAGONMA-GQNUHE
PID: 492 name: D:\Program Files\Google\Update\1.2.183.13\GoogleCrashHandler.exe owner: SYSTEM domain: NT AUTHORITY
PID: 620 name: D:\PROGRA~1\AVG\AVG8\avgtray.exe owner: Mike domain: DRAGONMA-GQNUHE
PID: 440 name: D:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe owner: Mike domain: DRAGONMA-GQNUHE
PID: 676 name: D:\WINDOWS\system32\hphmon04.exe owner: Mike domain: DRAGONMA-GQNUHE
PID: 744 name: D:\WINDOWS\RTHDCPL.EXE owner: Mike domain: DRAGONMA-GQNUHE
PID: 736 name: D:\WINDOWS\System32\svchost.exe owner: LOCAL SERVICE domain: NT AUTHORITY
PID: 972 name: D:\PROGRA~1\AVG\AVG8\avgwdsvc.exe owner: SYSTEM domain: NT AUTHORITY
PID: 840 name: D:\Program Files\Bonjour\mDNSResponder.exe owner: SYSTEM domain: NT AUTHORITY
PID: 1160 name: C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe owner: Mike domain: DRAGONMA-GQNUHE
PID: 1640 name: D:\Program Files\Java\jre6\bin\jqs.exe owner: SYSTEM domain: NT AUTHORITY
PID: 208 name: D:\Program Files\BOINC\boinctray.exe owner: Mike domain: DRAGONMA-GQNUHE
PID: 3100 name: D:\Program Files\Java\jre6\bin\jusched.exe owner: Mike domain: DRAGONMA-GQNUHE
PID: 3800 name: D:\Program Files\uTorrent\uTorrent.exe owner: Mike domain: DRAGONMA-GQNUHE
PID: 2944 name: D:\Program Files\DAEMON Tools Lite\daemon.exe owner: Mike domain: DRAGONMA-GQNUHE
PID: 3012 name: D:\PROGRA~1\AVG\AVG8\avgrsx.exe owner: SYSTEM domain: NT AUTHORITY
PID: 1236 name: D:\PROGRA~1\AVG\AVG8\avgnsx.exe owner: SYSTEM domain: NT AUTHORITY
PID: 3096 name: D:\WINDOWS\system32\ctfmon.exe owner: Mike domain: DRAGONMA-GQNUHE
PID: 3168 name: D:\WINDOWS\System32\svchost.exe owner: SYSTEM domain: NT AUTHORITY
PID: 3312 name: D:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe owner: Mike domain: DRAGONMA-GQNUHE
PID: 3364 name: D:\Program Files\PeerGuardian2\pg2.exe owner: Mike domain: DRAGONMA-GQNUHE
PID: 3368 name: D:\PROGRA~1\AVG\AVG8\avgemc.exe owner: SYSTEM domain: NT AUTHORITY
PID: 3644 name: D:\Program Files\AVG\AVG8\avgcsrvx.exe owner: SYSTEM domain: NT AUTHORITY
PID: 3664 name: D:\Program Files\WallpaperToy\Wallpapertoy.Exe owner: Mike domain: DRAGONMA-GQNUHE
PID: 1072 name: D:\WINDOWS\System32\wbem\unsecapp.exe owner: SYSTEM domain: NT AUTHORITY
PID: 1184 name: D:\WINDOWS\system32\HPHipm11.exe owner: SYSTEM domain: NT AUTHORITY
PID: 1796 name: D:\WINDOWS\system32\wbem\wmiprvse.exe owner: SYSTEM domain: NT AUTHORITY
PID: 2452 name: D:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe owner: SYSTEM domain: NT AUTHORITY
PID: 2692 name: D:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe owner: SYSTEM domain: NT AUTHORITY
PID: 1488 name: D:\WINDOWS\System32\alg.exe owner: LOCAL SERVICE domain: NT AUTHORITY
PID: 2976 name: D:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe owner: Mike domain: DRAGONMA-GQNUHE
PID: 3956 name: D:\Program Files\BOINC\boinc.exe owner: Mike domain: DRAGONMA-GQNUHE
PID: 2296 name: D:\WINDOWS\system32\wuauclt.exe owner: Mike domain: DRAGONMA-GQNUHE
PID: 2492 name: D:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe owner: Mike domain: DRAGONMA-GQNUHE
PID: 2676 name: D:\Program Files\Mozilla Firefox\firefox.exe owner: Mike domain: DRAGONMA-GQNUHE
PID: 1576 name: D:\WINDOWS\system32\wuauclt.exe owner: SYSTEM domain: NT AUTHORITY
PID: 532 name: D:\Program Files\Lavasoft\Ad-Aware\Ad-Aware.exe owner: Mike domain: DRAGONMA-GQNUHE

Startup items:
Name: PostBootReminder
          imagepath: {7849596a-48ea-486e-8937-a2a3009f31a9}
Name: CDBurn
          imagepath: {fbeb8a05-beee-4442-804e-409d6c4515e9}
Name: WebCheck
          imagepath: {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
Name: SysTray
          imagepath: {35CEC8A3-2BE6-11D2-8773-92E220524153}
Name: UPnPMonitor
          imagepath: {e57ce738-33e8-4c51-8354-bb4de9d215d1}
Name: WPDShServiceObj
          imagepath: {AAA288BA-9A4C-45B0-95D7-94D524869DB5}
Name: {438755C2-A8BA-11D1-B96B-00A0C90312E1}
          imagepath: Browseui preloader
Name: {8C7461EF-2B13-11d2-BE35-3078302C2030}
          imagepath: Component Categories cache daemon
Name: AVG8_TRAY
          imagepath: D:\PROGRA~1\AVG\AVG8\avgtray.exe
Name: HPDJ Taskbar Utility
          imagepath: D:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe
Name: HPHmon04
          imagepath: D:\WINDOWS\system32\hphmon04.exe
Name: HPHUPD04
          imagepath: "D:\Program Files\HP Photosmart 11\hphinstall\UniPatch\hphupd04.exe"
Name: RTHDCPL
          imagepath: RTHDCPL.EXE
Name: Alcmtr
          imagepath: ALCMTR.EXE
Name: Acrobat Assistant 8.0
          imagepath: "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
Name: Adobe_ID0EYTHM
          imagepath: D:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE
Name: boincmgr
          imagepath: "D:\Program Files\BOINC\boincmgr.exe" /a /s
Name: boinctray
          imagepath: "D:\Program Files\BOINC\boinctray.exe"
Name: NvCplDaemon
          imagepath: RUNDLL32.EXE D:\WINDOWS\system32\NvCpl.dll,NvStartup
Name: nwiz
          imagepath: nwiz.exe /install
Name: NvMediaCenter
          imagepath: RUNDLL32.EXE D:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
Name: 
Name: NeroFilterCheck
          imagepath: D:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
Name: SunJavaUpdateSched
          imagepath: "D:\Program Files\Java\jre6\bin\jusched.exe"
Name: 
          imagepath: D:\Documents and Settings\All Users\Start Menu\Programs\Startup\desktop.ini

Bootexecute items:
Name: 
          imagepath: autocheck autochk *
Name: 
          imagepath: lsdelete

Running services:
Name: ALG
          displayname: Application Layer Gateway Service
Name: AudioSrv
          displayname: Windows Audio
Name: avg8emc
          displayname: AVG Free8 E-mail Scanner
Name: avg8wd
          displayname: AVG Free8 WatchDog
Name: BITS
          displayname: Background Intelligent Transfer Service
Name: Bonjour Service
          displayname: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762##
Name: Browser
          displayname: Computer Browser
Name: CryptSvc
          displayname: Cryptographic Services
Name: DcomLaunch
          displayname: DCOM Server Process Launcher
Name: Dhcp
          displayname: DHCP Client
Name: dmserver
          displayname: Logical Disk Manager
Name: Dnscache
          displayname: DNS Client
Name: Eventlog
          displayname: Event Log
Name: EventSystem
          displayname: COM+ Event System
Name: FastUserSwitchingCompatibility
          displayname: Fast User Switching Compatibility
Name: FLEXnet Licensing Service
          displayname: FLEXnet Licensing Service
Name: helpsvc
          displayname: Help and Support
Name: HidServ
          displayname: HID Input Service
Name: JavaQuickStarterService
          displayname: Java Quick Starter
Name: lanmanserver
          displayname: Server
Name: lanmanworkstation
          displayname: Workstation
Name: Lavasoft Ad-Aware Service
          displayname: Lavasoft Ad-Aware Service
Name: LmHosts
          displayname: TCP/IP NetBIOS Helper
Name: Netman
          displayname: Network Connections
Name: Nla
          displayname: Network Location Awareness (NLA)
Name: NMIndexingService
          displayname: NMIndexingService
Name: NVSvc
          displayname: NVIDIA Display Driver Service
Name: PlugPlay
          displayname: Plug and Play
Name: Pml Driver HPH11
          displayname: Pml Driver HPH11
Name: PolicyAgent
          displayname: IPSEC Services
Name: ProtectedStorage
          displayname: Protected Storage
Name: RasMan
          displayname: Remote Access Connection Manager
Name: RemoteRegistry
          displayname: Remote Registry
Name: RpcSs
          displayname: Remote Procedure Call (RPC)
Name: SamSs
          displayname: Security Accounts Manager
Name: Schedule
          displayname: Task Scheduler
Name: seclogon
          displayname: Secondary Logon
Name: SENS
          displayname: System Event Notification
Name: SharedAccess
          displayname: Windows Firewall/Internet Connection Sharing (ICS)
Name: ShellHWDetection
          displayname: Shell Hardware Detection
Name: Spooler
          displayname: Print Spooler
Name: srservice
          displayname: System Restore Service
Name: SSDPSRV
          displayname: SSDP Discovery Service
Name: stisvc
          displayname: Windows Image Acquisition (WIA)
Name: TapiSrv
          displayname: Telephony
Name: TermService
          displayname: Terminal Services
Name: Themes
          displayname: Themes
Name: TrkWks
          displayname: Distributed Link Tracking Client
Name: W32Time
          displayname: Windows Time
Name: WebClient
          displayname: WebClient
Name: winmgmt
          displayname: Windows Management Instrumentation
Name: wscsvc
          displayname: Security Center
Name: wuauserv
          displayname: Automatic Updates
Name: WZCSVC
          displayname: Wireless Zero Configuration]]></description>
			<content:encoded><![CDATA[<div>Found this on my system with AdAware and now I can't seem to get it to go away. Help!!<br />
<br />
<br />
Here is the AdAware scan log<br />
<br />
Logfile created: 11/8/2009 7:56:46<br />
Lavasoft Ad-Aware version: 8.0.8<br />
Extended engine version: 8.1<br />
User performing scan: Mike<br />
<br />
*********************** Definitions database information ***********************<br />
Lavasoft definition file: 149.88<br />
Extended engine definition file: 8.1<br />
<br />
******************************** Scan results: *********************************<br />
Scan profile name: Full Scan  (ID: full)<br />
Objects scanned: 243058<br />
Objects detected: 3<br />
<br />
<br />
Type              Detected<br />
==========================<br />
Processes.......:        0<br />
Registry entries:        1<br />
Hostfile entries:        0<br />
Files...........:        2<br />
Folders.........:        0<br />
LSPs............:        0<br />
Cookies.........:        0<br />
Browser hijacks.:        0<br />
MRU objects.....:        0<br />
<br />
<br />
<br />
Skipped items:<br />
Description: HKLM:HKEY_CLASSES_ROOT\CLSID\{376892AE-1825-4E5F-9F85-23F9640051CC}: Family Name: unknown Clean status: Success Item ID: 1 Family ID: 0<br />
<br />
Quarantined items:<br />
Description: C:\System Volume Information\_restore{29738EDF-543B-4F0F-9399-E166B53629A1}\RP13\A0008022.exe Family Name: Win32.Adware.MeMedia Clean status: Success Item ID: 1327738 Family ID: 2094<br />
Description: C:\RECYCLER\S-1-5-21-515967899-162531612-839522115-1003\Dc11.exe Family Name: Win32.Monitor.SpyBuddy Clean status: Success Item ID: 937664 Family ID: 3212<br />
<br />
Scan and cleaning complete: Finished correctly after 8969 seconds<br />
<br />
*********************************** Settings ***********************************<br />
<br />
Scan profile:<br />
ID: full, enabled:1, value: Full Scan<br />
  ID: scancriticalareas, enabled:1, value: true<br />
  ID: scanrunningapps, enabled:1, value: true<br />
  ID: scanregistry, enabled:1, value: true<br />
  ID: scanlsp, enabled:1, value: true<br />
  ID: scanads, enabled:1, value: true<br />
  ID: scanhostsfile, enabled:1, value: true<br />
  ID: scanmru, enabled:1, value: true<br />
  ID: scanbrowserhijacks, enabled:1, value: true<br />
  ID: scantrackingcookies, enabled:1, value: true<br />
    ID: closebrowsers, enabled:1, value: false<br />
  ID: folderstoscan, enabled:1, value: C:\,D:\<br />
  ID: usespywareheuristics, enabled:1, value: true<br />
  ID: extendedengine, enabled:0, value: true<br />
    ID: useheuristics, enabled:0, value: true<br />
      ID: heuristicslevel, enabled:0, value: mild, domain: medium,mild,strict<br />
  ID: filescanningoptions, enabled:1<br />
    ID: scanrootkits, enabled:1, value: true<br />
    ID: archives, enabled:1, value: true<br />
    ID: onlyexecutables, enabled:1, value: false<br />
    ID: skiplargerthan, enabled:1, value: 20480<br />
<br />
Scan global:<br />
ID: global, enabled:1<br />
  ID: addtocontextmenu, enabled:1, value: true<br />
  ID: playsoundoninfection, enabled:1, value: false<br />
    ID: soundfile, enabled:0, value: *to be filled in automatically*\alert.wav<br />
<br />
Scheduled scan settings:<br />
&lt;Empty&gt;<br />
<br />
Update settings:<br />
ID: updates, enabled:1<br />
  ID: launchthreatworksafterscan, enabled:1, value: normal, domain: normal,off,silently<br />
  ID: softwareupdates, enabled:1, value: downloadandinstall, domain: dontcheck,downloadandinstall<br />
  ID: licenseandinfo, enabled:1, value: downloadandinstall, domain: dontcheck,downloadandinstall<br />
  ID: schedules, enabled:1, value: true<br />
    ID: updatedaily, enabled:1, value: Daily<br />
      ID: time, enabled:1, value: Fri Jul 24 17:35:00 2009<br />
      ID: frequency, enabled:1, value: daily, domain: daily,monthly,once,systemstart,weekly<br />
      ID: weekdays, enabled:1<br />
        ID: monday, enabled:1, value: false<br />
        ID: tuesday, enabled:1, value: false<br />
        ID: wednesday, enabled:1, value: false<br />
        ID: thursday, enabled:1, value: false<br />
        ID: friday, enabled:1, value: false<br />
        ID: saturday, enabled:1, value: false<br />
        ID: sunday, enabled:1, value: false<br />
      ID: monthly, enabled:1, value: 1, minvalue: 1, maxvalue: 31<br />
      ID: scanprofile, enabled:1, value: <br />
      ID: auto_deal_with_infections, enabled:1, value: false<br />
    ID: updateweekly, enabled:1, value: Weekly<br />
      ID: time, enabled:1, value: Fri Jul 24 17:35:00 2009<br />
      ID: frequency, enabled:1, value: weekly, domain: daily,monthly,once,systemstart,weekly<br />
      ID: weekdays, enabled:1<br />
        ID: monday, enabled:1, value: true<br />
        ID: tuesday, enabled:1, value: false<br />
        ID: wednesday, enabled:1, value: false<br />
        ID: thursday, enabled:1, value: false<br />
        ID: friday, enabled:1, value: true<br />
        ID: saturday, enabled:1, value: false<br />
        ID: sunday, enabled:1, value: false<br />
      ID: monthly, enabled:1, value: 1, minvalue: 1, maxvalue: 31<br />
      ID: scanprofile, enabled:1, value: <br />
      ID: auto_deal_with_infections, enabled:1, value: false<br />
<br />
Appearance settings:<br />
ID: appearance, enabled:1<br />
  ID: skin, enabled:1, value: default.egl, reglocation: HKEY_LOCAL_MACHINE\SOFTWARE\Lavasoft\Ad-Aware\Resource<br />
  ID: showtrayicon, enabled:1, value: true<br />
  ID: language, enabled:1, value: en, reglocation: HKEY_LOCAL_MACHINE\SOFTWARE\Lavasoft\Ad-Aware\Language<br />
<br />
Realtime protection settings:<br />
ID: realtime, enabled:1<br />
  ID: processprotection, enabled:1, value: true<br />
  ID: registryprotection, enabled:0, value: true<br />
  ID: networkprotection, enabled:0, value: true<br />
  ID: usespywareheuristics, enabled:0, value: true<br />
  ID: extendedengine, enabled:0, value: true<br />
    ID: useheuristics, enabled:0, value: true<br />
      ID: heuristicslevel, enabled:0, value: strict, domain: medium,mild,strict<br />
  ID: infomessages, enabled:1, value: onlyimportant, domain: display,dontnotify,onlyimportant<br />
<br />
<br />
****************************** System information ******************************<br />
Computer name: DRAGONMA-GQNUHE<br />
Processor name: AMD Athlon(tm) 64 X2 Dual Core Processor 5000+<br />
Processor identifier: x86 Family 15 Model 107 Stepping 2<br />
Raw info: processorarchitecture 0, processortype 586, processorlevel 15, processor revision 27394, number of processors 2<br />
Physical memory available: 1263267840 bytes<br />
Physical memory total: 2145824768 bytes<br />
Virtual memory available: 1980641280 bytes<br />
Virtual memory total: 2147352576 bytes<br />
Memory load: 41%<br />
Microsoft Windows XP Professional Service Pack 3 (build 2600)<br />
Windows startup mode:<br />
<br />
Running processes:<br />
PID: 692 name: \SystemRoot\System32\smss.exe owner: SYSTEM domain: NT AUTHORITY<br />
PID: 756 name: \??\D:\WINDOWS\system32\csrss.exe owner: SYSTEM domain: NT AUTHORITY<br />
PID: 780 name: \??\D:\WINDOWS\system32\winlogon.exe owner: SYSTEM domain: NT AUTHORITY<br />
PID: 824 name: D:\WINDOWS\system32\services.exe owner: SYSTEM domain: NT AUTHORITY<br />
PID: 836 name: D:\WINDOWS\system32\lsass.exe owner: SYSTEM domain: NT AUTHORITY<br />
PID: 1012 name: D:\WINDOWS\system32\nvsvc32.exe owner: SYSTEM domain: NT AUTHORITY<br />
PID: 1044 name: D:\WINDOWS\system32\svchost.exe owner: SYSTEM domain: NT AUTHORITY<br />
PID: 1116 name: D:\WINDOWS\system32\svchost.exe owner: NETWORK SERVICE domain: NT AUTHORITY<br />
PID: 1212 name: D:\WINDOWS\System32\svchost.exe owner: SYSTEM domain: NT AUTHORITY<br />
PID: 1336 name: D:\WINDOWS\System32\svchost.exe owner: NETWORK SERVICE domain: NT AUTHORITY<br />
PID: 1412 name: D:\WINDOWS\System32\svchost.exe owner: LOCAL SERVICE domain: NT AUTHORITY<br />
PID: 1456 name: D:\Program Files\Lavasoft\Ad-Aware\AAWService.exe owner: SYSTEM domain: NT AUTHORITY<br />
PID: 1612 name: D:\WINDOWS\system32\spoolsv.exe owner: SYSTEM domain: NT AUTHORITY<br />
PID: 2032 name: D:\WINDOWS\Explorer.EXE owner: Mike domain: DRAGONMA-GQNUHE<br />
PID: 492 name: D:\Program Files\Google\Update\1.2.183.13\GoogleCrashHandler.  exe owner: SYSTEM domain: NT AUTHORITY<br />
PID: 620 name: D:\PROGRA~1\AVG\AVG8\avgtray.exe owner: Mike domain: DRAGONMA-GQNUHE<br />
PID: 440 name: D:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb0  7.exe owner: Mike domain: DRAGONMA-GQNUHE<br />
PID: 676 name: D:\WINDOWS\system32\hphmon04.exe owner: Mike domain: DRAGONMA-GQNUHE<br />
PID: 744 name: D:\WINDOWS\RTHDCPL.EXE owner: Mike domain: DRAGONMA-GQNUHE<br />
PID: 736 name: D:\WINDOWS\System32\svchost.exe owner: LOCAL SERVICE domain: NT AUTHORITY<br />
PID: 972 name: D:\PROGRA~1\AVG\AVG8\avgwdsvc.exe owner: SYSTEM domain: NT AUTHORITY<br />
PID: 840 name: D:\Program Files\Bonjour\mDNSResponder.exe owner: SYSTEM domain: NT AUTHORITY<br />
PID: 1160 name: C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe owner: Mike domain: DRAGONMA-GQNUHE<br />
PID: 1640 name: D:\Program Files\Java\jre6\bin\jqs.exe owner: SYSTEM domain: NT AUTHORITY<br />
PID: 208 name: D:\Program Files\BOINC\boinctray.exe owner: Mike domain: DRAGONMA-GQNUHE<br />
PID: 3100 name: D:\Program Files\Java\jre6\bin\jusched.exe owner: Mike domain: DRAGONMA-GQNUHE<br />
PID: 3800 name: D:\Program Files\uTorrent\uTorrent.exe owner: Mike domain: DRAGONMA-GQNUHE<br />
PID: 2944 name: D:\Program Files\DAEMON Tools Lite\daemon.exe owner: Mike domain: DRAGONMA-GQNUHE<br />
PID: 3012 name: D:\PROGRA~1\AVG\AVG8\avgrsx.exe owner: SYSTEM domain: NT AUTHORITY<br />
PID: 1236 name: D:\PROGRA~1\AVG\AVG8\avgnsx.exe owner: SYSTEM domain: NT AUTHORITY<br />
PID: 3096 name: D:\WINDOWS\system32\ctfmon.exe owner: Mike domain: DRAGONMA-GQNUHE<br />
PID: 3168 name: D:\WINDOWS\System32\svchost.exe owner: SYSTEM domain: NT AUTHORITY<br />
PID: 3312 name: D:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe owner: Mike domain: DRAGONMA-GQNUHE<br />
PID: 3364 name: D:\Program Files\PeerGuardian2\pg2.exe owner: Mike domain: DRAGONMA-GQNUHE<br />
PID: 3368 name: D:\PROGRA~1\AVG\AVG8\avgemc.exe owner: SYSTEM domain: NT AUTHORITY<br />
PID: 3644 name: D:\Program Files\AVG\AVG8\avgcsrvx.exe owner: SYSTEM domain: NT AUTHORITY<br />
PID: 3664 name: D:\Program Files\WallpaperToy\Wallpapertoy.Exe owner: Mike domain: DRAGONMA-GQNUHE<br />
PID: 1072 name: D:\WINDOWS\System32\wbem\unsecapp.exe owner: SYSTEM domain: NT AUTHORITY<br />
PID: 1184 name: D:\WINDOWS\system32\HPHipm11.exe owner: SYSTEM domain: NT AUTHORITY<br />
PID: 1796 name: D:\WINDOWS\system32\wbem\wmiprvse.exe owner: SYSTEM domain: NT AUTHORITY<br />
PID: 2452 name: D:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe owner: SYSTEM domain: NT AUTHORITY<br />
PID: 2692 name: D:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe owner: SYSTEM domain: NT AUTHORITY<br />
PID: 1488 name: D:\WINDOWS\System32\alg.exe owner: LOCAL SERVICE domain: NT AUTHORITY<br />
PID: 2976 name: D:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe owner: Mike domain: DRAGONMA-GQNUHE<br />
PID: 3956 name: D:\Program Files\BOINC\boinc.exe owner: Mike domain: DRAGONMA-GQNUHE<br />
PID: 2296 name: D:\WINDOWS\system32\wuauclt.exe owner: Mike domain: DRAGONMA-GQNUHE<br />
PID: 2492 name: D:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe owner: Mike domain: DRAGONMA-GQNUHE<br />
PID: 2676 name: D:\Program Files\Mozilla Firefox\firefox.exe owner: Mike domain: DRAGONMA-GQNUHE<br />
PID: 1576 name: D:\WINDOWS\system32\wuauclt.exe owner: SYSTEM domain: NT AUTHORITY<br />
PID: 532 name: D:\Program Files\Lavasoft\Ad-Aware\Ad-Aware.exe owner: Mike domain: DRAGONMA-GQNUHE<br />
<br />
Startup items:<br />
Name: PostBootReminder<br />
          imagepath: {7849596a-48ea-486e-8937-a2a3009f31a9}<br />
Name: CDBurn<br />
          imagepath: {fbeb8a05-beee-4442-804e-409d6c4515e9}<br />
Name: WebCheck<br />
          imagepath: {E6FB5E20-DE35-11CF-9C87-00AA005127ED}<br />
Name: SysTray<br />
          imagepath: {35CEC8A3-2BE6-11D2-8773-92E220524153}<br />
Name: UPnPMonitor<br />
          imagepath: {e57ce738-33e8-4c51-8354-bb4de9d215d1}<br />
Name: WPDShServiceObj<br />
          imagepath: {AAA288BA-9A4C-45B0-95D7-94D524869DB5}<br />
Name: {438755C2-A8BA-11D1-B96B-00A0C90312E1}<br />
          imagepath: Browseui preloader<br />
Name: {8C7461EF-2B13-11d2-BE35-3078302C2030}<br />
          imagepath: Component Categories cache daemon<br />
Name: AVG8_TRAY<br />
          imagepath: D:\PROGRA~1\AVG\AVG8\avgtray.exe<br />
Name: HPDJ Taskbar Utility<br />
          imagepath: D:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb0  7.exe<br />
Name: HPHmon04<br />
          imagepath: D:\WINDOWS\system32\hphmon04.exe<br />
Name: HPHUPD04<br />
          imagepath: &quot;D:\Program Files\HP Photosmart 11\hphinstall\UniPatch\hphupd04.exe&quot;<br />
Name: RTHDCPL<br />
          imagepath: RTHDCPL.EXE<br />
Name: Alcmtr<br />
          imagepath: ALCMTR.EXE<br />
Name: Acrobat Assistant 8.0<br />
          imagepath: &quot;C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe&quot;<br />
Name: Adobe_ID0EYTHM<br />
          imagepath: D:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VER  SIO~2.EXE<br />
Name: boincmgr<br />
          imagepath: &quot;D:\Program Files\BOINC\boincmgr.exe&quot; /a /s<br />
Name: boinctray<br />
          imagepath: &quot;D:\Program Files\BOINC\boinctray.exe&quot;<br />
Name: NvCplDaemon<br />
          imagepath: RUNDLL32.EXE D:\WINDOWS\system32\NvCpl.dll,NvStartup<br />
Name: nwiz<br />
          imagepath: nwiz.exe /install<br />
Name: NvMediaCenter<br />
          imagepath: RUNDLL32.EXE D:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit<br />
Name: <br />
Name: NeroFilterCheck<br />
          imagepath: D:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe<br />
Name: SunJavaUpdateSched<br />
          imagepath: &quot;D:\Program Files\Java\jre6\bin\jusched.exe&quot;<br />
Name: <br />
          imagepath: D:\Documents and Settings\All Users\Start Menu\Programs\Startup\desktop.ini<br />
<br />
Bootexecute items:<br />
Name: <br />
          imagepath: autocheck autochk *<br />
Name: <br />
          imagepath: lsdelete<br />
<br />
Running services:<br />
Name: ALG<br />
          displayname: Application Layer Gateway Service<br />
Name: AudioSrv<br />
          displayname: Windows Audio<br />
Name: avg8emc<br />
          displayname: AVG Free8 E-mail Scanner<br />
Name: avg8wd<br />
          displayname: AVG Free8 WatchDog<br />
Name: BITS<br />
          displayname: Background Intelligent Transfer Service<br />
Name: Bonjour Service<br />
          displayname: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762#  #<br />
Name: Browser<br />
          displayname: Computer Browser<br />
Name: CryptSvc<br />
          displayname: Cryptographic Services<br />
Name: DcomLaunch<br />
          displayname: DCOM Server Process Launcher<br />
Name: Dhcp<br />
          displayname: DHCP Client<br />
Name: dmserver<br />
          displayname: Logical Disk Manager<br />
Name: Dnscache<br />
          displayname: DNS Client<br />
Name: Eventlog<br />
          displayname: Event Log<br />
Name: EventSystem<br />
          displayname: COM+ Event System<br />
Name: FastUserSwitchingCompatibility<br />
          displayname: Fast User Switching Compatibility<br />
Name: FLEXnet Licensing Service<br />
          displayname: FLEXnet Licensing Service<br />
Name: helpsvc<br />
          displayname: Help and Support<br />
Name: HidServ<br />
          displayname: HID Input Service<br />
Name: JavaQuickStarterService<br />
          displayname: Java Quick Starter<br />
Name: lanmanserver<br />
          displayname: Server<br />
Name: lanmanworkstation<br />
          displayname: Workstation<br />
Name: Lavasoft Ad-Aware Service<br />
          displayname: Lavasoft Ad-Aware Service<br />
Name: LmHosts<br />
          displayname: TCP/IP NetBIOS Helper<br />
Name: Netman<br />
          displayname: Network Connections<br />
Name: Nla<br />
          displayname: Network Location Awareness (NLA)<br />
Name: NMIndexingService<br />
          displayname: NMIndexingService<br />
Name: NVSvc<br />
          displayname: NVIDIA Display Driver Service<br />
Name: PlugPlay<br />
          displayname: Plug and Play<br />
Name: Pml Driver HPH11<br />
          displayname: Pml Driver HPH11<br />
Name: PolicyAgent<br />
          displayname: IPSEC Services<br />
Name: ProtectedStorage<br />
          displayname: Protected Storage<br />
Name: RasMan<br />
          displayname: Remote Access Connection Manager<br />
Name: RemoteRegistry<br />
          displayname: Remote Registry<br />
Name: RpcSs<br />
          displayname: Remote Procedure Call (RPC)<br />
Name: SamSs<br />
          displayname: Security Accounts Manager<br />
Name: Schedule<br />
          displayname: Task Scheduler<br />
Name: seclogon<br />
          displayname: Secondary Logon<br />
Name: SENS<br />
          displayname: System Event Notification<br />
Name: SharedAccess<br />
          displayname: Windows Firewall/Internet Connection Sharing (ICS)<br />
Name: ShellHWDetection<br />
          displayname: Shell Hardware Detection<br />
Name: Spooler<br />
          displayname: Print Spooler<br />
Name: srservice<br />
          displayname: System Restore Service<br />
Name: SSDPSRV<br />
          displayname: SSDP Discovery Service<br />
Name: stisvc<br />
          displayname: Windows Image Acquisition (WIA)<br />
Name: TapiSrv<br />
          displayname: Telephony<br />
Name: TermService<br />
          displayname: Terminal Services<br />
Name: Themes<br />
          displayname: Themes<br />
Name: TrkWks<br />
          displayname: Distributed Link Tracking Client<br />
Name: W32Time<br />
          displayname: Windows Time<br />
Name: WebClient<br />
          displayname: WebClient<br />
Name: winmgmt<br />
          displayname: Windows Management Instrumentation<br />
Name: wscsvc<br />
          displayname: Security Center<br />
Name: wuauserv<br />
          displayname: Automatic Updates<br />
Name: WZCSVC<br />
          displayname: Wireless Zero Configuration</div>

]]></content:encoded>
			<category domain="http://www.techimo.com/forum/security-privacy-issues/">Security and Privacy Issues</category>
			<dc:creator>Mercenary Dragon</dc:creator>
			<guid isPermaLink="true">http://www.techimo.com/forum/security-privacy-issues/239488-c-recycler-s-1-5-21-515967899-162531612-839522115-1003-dc11-exe.html</guid>
		</item>
		<item>
			<title>mail returned emails when no emails sent</title>
			<link>http://www.techimo.com/forum/security-privacy-issues/239335-mail-returned-emails-when-no-emails-sent.html</link>
			<pubDate>Wed, 11 Nov 2009 10:58:58 GMT</pubDate>
			<description>hi i keepgetting emails in my aol email account telling me that mails has been returned when i have not even sent any emails, 
are these related to a virus or some other security issue, i have not read any of them as a precaution and would like to stop them but dont know how, could anybody tell me what they are about
i have attached a picture of my mailbox</description>
			<content:encoded><![CDATA[<div>hi i keepgetting emails in my aol email account telling me that mails has been returned when i have not even sent any emails, <br />
are these related to a virus or some other security issue, i have not read any of them as a precaution and would like to stop them but dont know how, could anybody tell me what they are about<br />
i have attached a picture of my mailbox</div>


	<br />
	<div style="padding:6px">
	
	
		<fieldset class="fieldset">
			<legend>Attached Thumbnails</legend>
			<div style="padding:3px">
			<a href="http://www.techimo.com/forum/attachments/security-privacy-issues/22814d1257937129-mail-returned-emails-when-no-emails-sent-spam.png" target="_blank"><img class="thumbnail" src="http://www.techimo.com/forum/attachments/security-privacy-issues/22814d1257937129t-mail-returned-emails-when-no-emails-sent-spam.png" border="0" alt="Click image for larger version

Name:	spam.PNG
Views:	N/A
Size:	71.3 KB
ID:	22814" /></a>
&nbsp;
			</div>
		</fieldset>
	

	
	
	
	
	
	
	</div>
]]></content:encoded>
			<category domain="http://www.techimo.com/forum/security-privacy-issues/">Security and Privacy Issues</category>
			<dc:creator>glendalf81</dc:creator>
			<guid isPermaLink="true">http://www.techimo.com/forum/security-privacy-issues/239335-mail-returned-emails-when-no-emails-sent.html</guid>
		</item>
		<item>
			<title>Trojan.Ramvicrype</title>
			<link>http://www.techimo.com/forum/security-privacy-issues/239313-trojan-ramvicrype.html</link>
			<pubDate>Tue, 10 Nov 2009 23:05:19 GMT</pubDate>
			<description>Hi Everyone:

Symantec recently became aware of a new Trojan Horse called Trojan.Ramvicrype. 

The Trojan encrypts files on infected computers, making them completely unusable. Any file with a “.vicrypt” extension means that your system has been compromised.

Trojan.Ramvicrype is different from most other ransomware programs we’ve previously identified. Usually, these kinds of threats display a message prompting users to visit a specific web page or email a specific address. Users end up paying online criminals in exchange for keys that can be used to unlock the computer or decrypt the encrypted files.

Trojan.Ramvicrype doesn’t directly demand money in return for keys.  However, we found that entering the term ‘vicrypt’ into a search engine includes a company offering a fix in the search results, which of course is a charged service.

Regardless of which security software you run, use the free removal tool below if you are infected with the Trojan:

Trojan.Ramvicrype Removal Tool (http://www.symantec.com/security_response/writeup.jsp?docid=2009-102921-3210-99)

Regards,
Andrew

Andrew Diaz
Norton Outreach
Symantec  Corporation
nortonoutreach.com (http://www.nortonoutreach.com)</description>
			<content:encoded><![CDATA[<div>Hi Everyone:<br />
<br />
Symantec recently became aware of a new Trojan Horse called Trojan.Ramvicrype. <br />
<br />
The Trojan encrypts files on infected computers, making them completely unusable. Any file with a “.vicrypt” extension means that your system has been compromised.<br />
<br />
Trojan.Ramvicrype is different from most other ransomware programs we’ve previously identified. Usually, these kinds of threats display a message prompting users to visit a specific web page or email a specific address. Users end up paying online criminals in exchange for keys that can be used to unlock the computer or decrypt the encrypted files.<br />
<br />
Trojan.Ramvicrype doesn’t directly demand money in return for keys.  However, we found that entering the term ‘vicrypt’ into a search engine includes a company offering a fix in the search results, which of course is a charged service.<br />
<br />
Regardless of which security software you run, use the free removal tool below if you are infected with the Trojan:<br />
<br />
<a href="http://www.symantec.com/security_response/writeup.jsp?docid=2009-102921-3210-99" target="_blank">Trojan.Ramvicrype Removal Tool</a><br />
<br />
Regards,<br />
Andrew<br />
<br />
Andrew Diaz<br />
Norton Outreach<br />
Symantec  Corporation<br />
<a href="http://www.nortonoutreach.com" target="_blank">nortonoutreach.com</a></div>

]]></content:encoded>
			<category domain="http://www.techimo.com/forum/security-privacy-issues/">Security and Privacy Issues</category>
			<dc:creator>Andrew Diaz</dc:creator>
			<guid isPermaLink="true">http://www.techimo.com/forum/security-privacy-issues/239313-trojan-ramvicrype.html</guid>
		</item>
		<item>
			<title>Windows Firewall and Service Pack 2</title>
			<link>http://www.techimo.com/forum/security-privacy-issues/239262-windows-firewall-service-pack-2-a.html</link>
			<pubDate>Mon, 09 Nov 2009 18:58:45 GMT</pubDate>
			<description><![CDATA[Got hold of my daughters laptop the other day to "clean it out."

Gave it a complete scan, checkdisk, malware and spybot.

A couple of problems though.
First is that the firewall will not stay on. (windows Firewall).
This was happening before i did the clean.

Second is when i try to install service pack 2 for Vista home premium, there is an error message which says..

Error: ERROR_NOT_FOUND(0x80070490)


Acer Aspire 5920
Vista Home Premium

Any more information then please ask.]]></description>
			<content:encoded><![CDATA[<div>Got hold of my daughters laptop the other day to &quot;clean it out.&quot;<br />
<br />
Gave it a complete scan, checkdisk, malware and spybot.<br />
<br />
A couple of problems though.<br />
First is that the firewall will not stay on. (windows Firewall).<br />
This was happening before i did the clean.<br />
<br />
Second is when i try to install service pack 2 for Vista home premium, there is an error message which says..<br />
<br />
Error: ERROR_NOT_FOUND(0x80070490)<br />
<br />
<br />
Acer Aspire 5920<br />
Vista Home Premium<br />
<br />
Any more information then please ask.</div>

]]></content:encoded>
			<category domain="http://www.techimo.com/forum/security-privacy-issues/">Security and Privacy Issues</category>
			<dc:creator>railfrog</dc:creator>
			<guid isPermaLink="true">http://www.techimo.com/forum/security-privacy-issues/239262-windows-firewall-service-pack-2-a.html</guid>
		</item>
		<item>
			<title>thefeedwater.com VIRUS</title>
			<link>http://www.techimo.com/forum/security-privacy-issues/239216-thefeedwater-com-virus.html</link>
			<pubDate>Sun, 08 Nov 2009 20:34:17 GMT</pubDate>
			<description><![CDATA[Has anyon heard of this? My pc picked up this bug yesterday. I was on the phone with Mcafee virus support till 3AM!!!!!! They did what they can do, and then it was a blame the other person game! Mcafee to Comcast, back to Mcafee to Comcast. All night long. 
 
When I contacted Comcast (internet provider) They said it's definitly a virus.  It redirects me to a bunch of BS websites. When ever I try to click on something, at the bottom of the page over top of my start button it says "thefeedwater.com" is now taking over and redirecting me. GGGRRRRRRRRR!
 
Any clue how I can get rid of this folks? Thank you for your help. 
 
(took me a while just to get to this page)]]></description>
			<content:encoded><![CDATA[<div>Has anyon heard of this? My pc picked up this bug yesterday. I was on the phone with Mcafee virus support till 3AM!!!!!! They did what they can do, and then it was a blame the other person game! Mcafee to Comcast, back to Mcafee to Comcast. All night long. <br />
 <br />
When I contacted Comcast (internet provider) They said it's definitly a virus.  It redirects me to a bunch of BS websites. When ever I try to click on something, at the bottom of the page over top of my start button it says &quot;thefeedwater.com&quot; is now taking over and redirecting me. GGGRRRRRRRRR!<br />
 <br />
Any clue how I can get rid of this folks? Thank you for your help. <br />
 <br />
(took me a while just to get to this page)</div>

]]></content:encoded>
			<category domain="http://www.techimo.com/forum/security-privacy-issues/">Security and Privacy Issues</category>
			<dc:creator>BoomShaker</dc:creator>
			<guid isPermaLink="true">http://www.techimo.com/forum/security-privacy-issues/239216-thefeedwater-com-virus.html</guid>
		</item>
		<item>
			<title>Rootrepeal</title>
			<link>http://www.techimo.com/forum/security-privacy-issues/238693-rootrepeal.html</link>
			<pubDate>Fri, 30 Oct 2009 00:19:15 GMT</pubDate>
			<description>Anybody familiar with this program?</description>
			<content:encoded><![CDATA[<div>Anybody familiar with this program?</div>

]]></content:encoded>
			<category domain="http://www.techimo.com/forum/security-privacy-issues/">Security and Privacy Issues</category>
			<dc:creator>jagnorm</dc:creator>
			<guid isPermaLink="true">http://www.techimo.com/forum/security-privacy-issues/238693-rootrepeal.html</guid>
		</item>
		<item>
			<title>Antivirus system pro But with no Safe Mode</title>
			<link>http://www.techimo.com/forum/security-privacy-issues/238532-antivirus-system-pro-but-no-safe-mode.html</link>
			<pubDate>Mon, 26 Oct 2009 20:30:15 GMT</pubDate>
			<description><![CDATA[A friend of mine got infected with the NASTY antivirus system pro virus. Every site I visit with info on how to remove it says to run an antivirus/anti spyware software but that is impossible. I cant even ctrl-alt-delte because this virus stops every process from running. (Can't even run the command prompt, it terminates it as soon as it starts).

Well of course the next option is to run safe mode but when I do that the computer reboots. I don't know if this is directly because of the virus or not.

Anyway, does anyone have advice for removing this virus without safe mode?

I was thinking of getting Avast's Bart CD and running that since it runs in it's own OS.
I ran Kaspersky from and old Hiren's boot CD but it found nothing. Probably too old.]]></description>
			<content:encoded><![CDATA[<div>A friend of mine got infected with the NASTY antivirus system pro virus. Every site I visit with info on how to remove it says to run an antivirus/anti spyware software but that is impossible. I cant even ctrl-alt-delte because this virus stops every process from running. (Can't even run the command prompt, it terminates it as soon as it starts).<br />
<br />
Well of course the next option is to run safe mode but when I do that the computer reboots. I don't know if this is directly because of the virus or not.<br />
<br />
Anyway, does anyone have advice for removing this virus without safe mode?<br />
<br />
I was thinking of getting Avast's Bart CD and running that since it runs in it's own OS.<br />
I ran Kaspersky from and old Hiren's boot CD but it found nothing. Probably too old.</div>

]]></content:encoded>
			<category domain="http://www.techimo.com/forum/security-privacy-issues/">Security and Privacy Issues</category>
			<dc:creator>joker_927</dc:creator>
			<guid isPermaLink="true">http://www.techimo.com/forum/security-privacy-issues/238532-antivirus-system-pro-but-no-safe-mode.html</guid>
		</item>
		<item>
			<title>Vista home edition and Trend Micro Interent Security and Share USB printer</title>
			<link>http://www.techimo.com/forum/security-privacy-issues/238465-vista-home-edition-trend-micro-interent-security-share-usb-printer.html</link>
			<pubDate>Sun, 25 Oct 2009 11:21:56 GMT</pubDate>
			<description><![CDATA[file/printer sharing ports... Trend Micro Firewall issue - [H]ard|Forum (http://www.hardforum.com/showthread.php?t=1338456)

I have got one of my client has got a simple office network with three PCs (2 desktops A and B and one laptop C,,,,,all of them have got Vista Home edition).

Those desktop are connected through a modem router.

He bought a computer B recently and it has a Trend Micro Internet Security installed on it,,,,,,,a USB printer is connected to this B PC to be shared with A and C.

The other two PCs have not got Trend Micro Internet Security (I am aware of security implication , this is not the issue of our thread)

the printer is shared but A and C can not ping and can not print.

I am sure that the problem lies with the Firewall setting for Trend Micro Internet Security, because when I shut down it from A and C I can ping the B and I can print ,,,,while when Trend Micro Internet Security is running I can not ping B and I can not print.

I tried to search how to configure firewall to enable printer sharing I could not find that 
XP, Vista, Printer Sharing and One BIG Mess - Vista Forums (http://www.vistax64.com/network-sharing/191646-xp-vista-printer-sharing-one-big-mess.html)

---Quote---
If using Norton, McAfee, Trend Micro I.S., make sure file and printer sharing is enabled in THEIR firewall (or LAN allowed, depending on how their Exceptions are worded in their Firewall)
---End Quote---
I tired google without any success.

Micro Trend internet security enable printer sharing how - Google Search (http://www.google.com.au/search?client=firefox-a&rls=org.mozilla%3Aen-US%3Aofficial&channel=s&hl=en&source=hp&q=Micro+Trend+internet+security+enable+printer+sharing+how+&meta=&btnG=Google+Search)


http://www.microsoft.com/windowsmobile/en-us/help/synchronize/guide/activesync-trendmicros.mspx

Any idea how to configure the firewall to enable a printer sharing ?

Thanks]]></description>
			<content:encoded><![CDATA[<div><a href="http://www.hardforum.com/showthread.php?t=1338456" target="_blank">file/printer sharing ports... Trend Micro Firewall issue - [H]ard|Forum</a><br />
<br />
I have got one of my client has got a simple office network with three PCs (2 desktops A and B and one laptop C,,,,,all of them have got Vista Home edition).<br />
<br />
Those desktop are connected through a modem router.<br />
<br />
He bought a computer B recently and it has a Trend Micro Internet Security installed on it,,,,,,,a USB printer is connected to this B PC to be shared with A and C.<br />
<br />
The other two PCs have not got Trend Micro Internet Security (I am aware of security implication , this is not the issue of our thread)<br />
<br />
the printer is shared but A and C can not ping and can not print.<br />
<br />
I am sure that the problem lies with the Firewall setting for Trend Micro Internet Security, because when I shut down it from A and C I can ping the B and I can print ,,,,while when Trend Micro Internet Security is running I can not ping B and I can not print.<br />
<br />
I tried to search how to configure firewall to enable printer sharing I could not find that <br />
<a href="http://www.vistax64.com/network-sharing/191646-xp-vista-printer-sharing-one-big-mess.html" target="_blank">XP, Vista, Printer Sharing and One BIG Mess - Vista Forums</a><br />
<div style="margin:20px; margin-top:5px; ">
	<div class="smallfont" style="margin-bottom:2px">Quote:</div>
	<table cellpadding="6" cellspacing="0" border="0" width="100%">
	<tr>
		<td class="alt2">
			<hr />
			
				If using Norton, McAfee, Trend Micro I.S., make sure file and printer sharing is enabled in THEIR firewall (or LAN allowed, depending on how their Exceptions are worded in their Firewall)
			
			<hr />
		</td>
	</tr>
	</table>
</div>I tired google without any success.<br />
<br />
<a href="http://www.google.com.au/search?client=firefox-a&amp;rls=org.mozilla%3Aen-US%3Aofficial&amp;channel=s&amp;hl=en&amp;source=hp&amp;q=Micro+Trend+internet+security+enable+printer+sharing+how+&amp;meta=&amp;btnG=Google+Search" target="_blank">Micro Trend internet security enable printer sharing how - Google Search</a><br />
<br />
<br />
<a href="http://www.microsoft.com/windowsmobile/en-us/help/synchronize/guide/activesync-trendmicros.mspx" target="_blank">http://www.microsoft.com/windowsmobi...endmicros.mspx</a><br />
<br />
Any idea how to configure the firewall to enable a printer sharing ?<br />
<br />
Thanks</div>

]]></content:encoded>
			<category domain="http://www.techimo.com/forum/security-privacy-issues/">Security and Privacy Issues</category>
			<dc:creator>zillah</dc:creator>
			<guid isPermaLink="true">http://www.techimo.com/forum/security-privacy-issues/238465-vista-home-edition-trend-micro-interent-security-share-usb-printer.html</guid>
		</item>
	</channel>
</rss>
