Help - Search - Members - Calendar
Full Version: Broadcast Desktop As Webpage
Suggest A Fix PC Support Forums > Security > Malicious Code: Viruses, Trojans, Spyware and Browser HiJacking
Miranda
Hi, I'm new to this forum, well all "forums" actually I have never posted to any before. I am on my comp 24/7 and recently I noticed that it was acting very different (ie everything on my desktop was a "shortcut", sync menu appeared on program list, programs I have never used before appearing in my program list). Not to mention that I was on it last week I was online and logged onto msn messenger when my desktop wallpaper and icons on desktop and toolbar disappeared. I thought that my b/f did something with my computer somehow through messenger (he works for a web design/hosting/SAAS co) and I asked him what he did, he told me that his entire computer just refreshed and that their lights were started flickering, he said it was because 2 of their networking guys were downtown at their server facility installing some type of NAS storage device and it could have reset his connection.

This is when I started becomming suspicious because I also run a web design business in the same area and think that they somehow are connected to my comp. My b/f said it was probably a virus and that he would get a new copy of windows burned for me to put on my comp.

Also, one of his friends that works there has sometype of network where he can "broadcast" his home computer as a webpage and access it from work, maybe this is what is happening to mine?

I am currently connected through an unsecured wireless network. We have a Linksys motem and router hooked up in a different room.

I just completed reinstalling windows and the only programs I have run since then was Winpatrol and Hijack this that I downloaded through Download.com... some programs and background services seem strange to me. I am rambling on long enough, I just really need some help knowing if somehow they are accessing my comp.

I have attached my HiJAck this logs, please someone help me.

------WinPatrol Report Log -----
Report created by WinPatrol version 11.2.2007:11.2.2007 at 1:19:08 PM, on 3/30/2007

Platform: Windows XP Home Edition Service Pack 2 (Build 2600)
Browser: Internet Explorer - Internet Explorer version 6.00.2900.2180
Memory currently in use: 36%

MSIE: Internet Explorer (6.00.2900.2180)
IE Cookie Path: C:\Documents and Settings\Miranda\Cookies\

HKLM Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?p...&ar=msnhome
HKCU Start Page = http://www.microsoft.com/isapi/redir.dll?p...&ar=msnhome
HKLM Start Page = http://www.microsoft.com/isapi/redir.dll?p...ER}&ar=home

WinLogon DefaultUserName=Miranda
WinLogon DefaultDomainName=INSIGHSTYLE
WinLogon Shell=Explorer.exe
WinLogon UserInit=C:\WINDOWS\system32\userinit.exe,


Startup Programs
Active Tasks
Scheduled Tasks
IE Helpers
File Types
Services

• Startup Programs •
WinPatrol
winpatrol.exe WinPatrol System Monitor
Version: 11.2.2007 Copyright © 1997- 2007 BillP Studios
Location: HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Path: C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
First Detected by WinPatrol: 03/30/2007 11:49 AM
Click for Plus Info


DellSupport
DSAgnt.exe /startup Dell Support
Version: 1, 1, 1, 121 Copyright © 2000 - 2005 Gteko Ltd.
Location: HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Path: C:\Program Files\Dell Support\DSAgnt.exe /startup
First Detected by WinPatrol: 03/30/2007 11:49 AM
Click for Plus Info


Winlogon Userinit
userinit.exe Userinit Logon Application
Version: 5.1.2600.2180 © Microsoft Corporation. All rights reserved.
Location: HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon Userinit
Path: C:\WINDOWS\system32\userinit.exe
First Detected by WinPatrol: 03/30/2007 11:49 AM
Click for Plus Info


Winlogon Shell
Explorer.exe Windows Explorer
Version: 6.00.2900.2180 © Microsoft Corporation. All rights reserved.
Location: HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon Shell
Path: Explorer.exe
First Detected by WinPatrol: 03/30/2007 11:49 AM
Click for Plus Info


• Delayed Start •
• Active Tasks •
Windows NT Session Manager
smss.exe Windows NT Session Manager
Version: 5.1.2600.2180 © Microsoft Corporation. All rights reserved.
Path: C:\WINDOWS\system32\smss.exe
First Detected by WinPatrol: 03/30/2007 11:49 AM
Click for Plus Info


Client Server Runtime Process
csrss.exe Client Server Runtime Process
Version: 5.1.2600.2180 © Microsoft Corporation. All rights reserved.
Path: C:\WINDOWS\system32\csrss.exe
First Detected by WinPatrol: 03/30/2007 12:05 AM
Click for Plus Info


Windows NT Logon Application
winlogon.exe Windows NT Logon Application
Version: 5.1.2600.2180 © Microsoft Corporation. All rights reserved.
Path: C:\WINDOWS\system32\winlogon.exe
First Detected by WinPatrol: 03/30/2007 11:49 AM
Click for Plus Info


Services and Controller app
services.exe Services and Controller app
Version: 5.1.2600.2180 © Microsoft Corporation. All rights reserved.
Path: C:\WINDOWS\system32\services.exe
First Detected by WinPatrol: 03/30/2007 11:49 AM
Click for Plus Info


LSA Shell (Export Version)
lsass.exe LSA Shell (Export Version)
Version: 5.1.2600.2180 © Microsoft Corporation. All rights reserved.
Path: C:\WINDOWS\system32\lsass.exe
First Detected by WinPatrol: 03/30/2007 11:49 AM
Click for Plus Info


Generic Host Process for Win32 Services
svchost.exe Generic Host Process for Win32 Services
Version: 5.1.2600.2180 © Microsoft Corporation. All rights reserved.
Path: C:\WINDOWS\system32\svchost.exe
First Detected by WinPatrol: 03/30/2007 11:49 AM
Click for Plus Info


Spooler SubSystem App
spoolsv.exe Spooler SubSystem App
Version: 5.1.2600.2696 © Microsoft Corporation. All rights reserved.
Path: C:\WINDOWS\system32\spoolsv.exe
First Detected by WinPatrol: 03/30/2007 11:49 AM
Click for Plus Info


Application Layer Gateway Service
alg.exe Application Layer Gateway Service
Version: 5.1.2600.2180 © Microsoft Corporation. All rights reserved.
Path: C:\WINDOWS\system32\alg.exe
First Detected by WinPatrol: 03/30/2007 12:05 AM
Click for Plus Info


Windows Security Center Notification App
wscntfy.exe Windows Security Center Notification App
Version: 5.1.2600.2180 © Microsoft Corporation. All rights reserved.
Path: C:\WINDOWS\system32\wscntfy.exe
First Detected by WinPatrol: 03/30/2007 11:49 AM
Click for Plus Info


Windows Explorer
explorer.exe Windows Explorer
Version: 6.00.2900.2180 © Microsoft Corporation. All rights reserved.
Path: C:\WINDOWS\explorer.exe
First Detected by WinPatrol: 03/30/2007 11:49 AM
Click for Plus Info


WinPatrol
WINPATROL.EXE WinPatrol System Monitor
Version: 11.2.2007 Copyright © 1997- 2007 BillP Studios
Path: C:\PROGRAM FILES\BILLP STUDIOS\WINPATROL\WINPATROL.EXE
First Detected by WinPatrol: 03/30/2007 11:49 AM
Click for Plus Info


Dell Support
DSAgnt.exe Dell Support
Version: 1, 1, 1, 121 Copyright © 2000 - 2005 Gteko Ltd.
Path: C:\PROGRAM FILES\DELL SUPPORT\DSAgnt.exe
First Detected by WinPatrol: 03/30/2007 11:54 AM
Click for Plus Info


Internet Explorer
IEXPLORE.EXE Internet Explorer
Version: 6.00.2900.2180 © Microsoft Corporation. All rights reserved.
Path: C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
First Detected by WinPatrol: 03/30/2007 11:49 AM
Click for Plus Info


WinPatrol
WINPATROLEX.EXE WinPatrol Explorer
Version: 11.2.2007 Copyright © 2004-2007 BillP Studios
Path: C:\PROGRAM FILES\BILLP STUDIOS\WINPATROL\WINPATROLEX.EXE
First Detected by WinPatrol: 03/30/2007 11:50 AM
Click for Plus Info


• Scheduled Tasks •
• IE Helpers •
• File Types •
Video Clip
wmplayer.exe /prefetch:8 /Open %L Windows Media Player
Version: 9.00.00.3250 © Microsoft Corporation. All rights reserved.
Path: C:\Program Files\Windows Media Player\wmplayer.exe /prefetch:8 /Open %L
.AVI
Startup Type: avifile
Click for Plus Info


MS-DOS Batch File
%1 %*
Path: %1 %*
.BAT
Startup Type: batfile
Click for Plus Info


Cabinet File
Explorer.exe /idlist,%I,%L Windows Explorer
Version: 6.00.2900.2180 © Microsoft Corporation. All rights reserved.
Path: C:\WINDOWS\Explorer.exe /idlist,%I,%L
.CAB
Startup Type: CLSID\{0CD7A5C0-9F37-11CE-AE65-08002B2E1262}
Click for Plus Info


Security Catalog
rundll32.exe cryptext.dll,CryptExtOpenCAT %1 Run a DLL as an App
Version: 5.1.2600.2180 © Microsoft Corporation. All rights reserved.
Path: rundll32.exe cryptext.dll,CryptExtOpenCAT %1
.CAT
Startup Type: CATFile
Click for Plus Info


Compiled HTML Help file
hh.exe %1 Microsoft® HTML Help Executable
Version: 5.2.3790.2453 © Microsoft Corporation. All rights reserved.
Path: C:\WINDOWS\hh.exe %1
.CHM
Startup Type: chm.file
Click for Plus Info


MS-DOS Application
%1 %*
Path: %1 %*
.COM
Startup Type: comfile
Click for Plus Info


Windows NT Command Script
%1 %*
Path: %1 %*
.CMD
Startup Type: cmdfile
Click for Plus Info


WordPad Document
WORDPAD.EXE %1 WordPad MFC Application
Version: 5.1.2600.2180 © Microsoft Corporation. All rights reserved.
Path: C:\Program Files\Windows NT\Accessories\WORDPAD.EXE %1
.DOC
Startup Type: WordPad.Document.1
Click for Plus Info


Outlook Express Mail Message
msimn.exe /eml:%1 Outlook Express
Version: 6.00.2900.2180 © 2004 Microsoft Corporation. All rights reserved.
Path: C:\Program Files\Outlook Express\msimn.exe /eml:%1
.EML
Startup Type: Microsoft Internet Mail Message
Click for Plus Info


Application
%1 %*
Path: %1 %*
.EXE
Startup Type: exefile
Click for Plus Info


Setup Information
NOTEPAD.EXE %1 Notepad
Version: 5.1.2600.2180 © Microsoft Corporation. All rights reserved.
Path: C:\WINDOWS\System32\NOTEPAD.EXE %1
.INF
Startup Type: inffile
Click for Plus Info


JScript Script File
WScript.exe %1 %* Microsoft ® Windows Based Script Host
Version: 5.6.0.8820 Copyright © Microsoft Corp. 2002
Path: C:\WINDOWS\System32\WScript.exe %1 %*
.JS
Startup Type: JSFile
Click for Plus Info


Text Document
NOTEPAD.EXE %1 Notepad
Version: 5.1.2600.2180 © Microsoft Corporation. All rights reserved.
Path: C:\WINDOWS\system32\NOTEPAD.EXE %1
.LOG
Startup Type: txtfile
Click for Plus Info


Windows Installer Package
msiexec.exe /i %1 %* Windows® installer
Version: 3.1.4000.1823 © Microsoft Corporation. All rights reserved.
Path: C:\WINDOWS\System32\msiexec.exe /i %1 %*
.MSI
Startup Type: Msi.Package
Click for Plus Info


MIDI Sequence
wmplayer.exe /Open %L Windows Media Player
Version: 9.00.00.3250 © Microsoft Corporation. All rights reserved.
Path: C:\Program Files\Windows Media Player\wmplayer.exe /Open %L
.MID
Startup Type: midfile
Click for Plus Info


MP3 Format Sound
wmplayer.exe /prefetch:6 /Open %L Windows Media Player
Version: 9.00.00.3250 © Microsoft Corporation. All rights reserved.
Path: C:\Program Files\Windows Media Player\wmplayer.exe /prefetch:6 /Open %L
.MP3
Startup Type: mp3file
Click for Plus Info


Shortcut to MS-DOS Program
%1 %*
Path: %1 %*
.PIF
Startup Type: piffile
Click for Plus Info


Registration Entries
regedit.exe %1 Registry Editor
Version: 5.1.2600.2180 © Microsoft Corporation. All rights reserved.
Path: regedit.exe %1
.REG
Startup Type: regfile
Click for Plus Info


Rich Text Document
WORDPAD.EXE %1 WordPad MFC Application
Version: 5.1.2600.2180 © Microsoft Corporation. All rights reserved.
Path: C:\Program Files\Windows NT\Accessories\WORDPAD.EXE %1
.RTF
Startup Type: rtffile
Click for Plus Info


Screen Saver
%1 /S
Path: %1 /S
.SCR
Startup Type: scrfile
Click for Plus Info


Text Document
NOTEPAD.EXE %1 Notepad
Version: 5.1.2600.2180 © Microsoft Corporation. All rights reserved.
Path: C:\WINDOWS\system32\NOTEPAD.EXE %1
.TXT
Startup Type: txtfile
Click for Plus Info


Internet Shortcut
rundll32.exe shdocvw.dll,OpenURL %l Run a DLL as an App
Version: 5.1.2600.2180 © Microsoft Corporation. All rights reserved.
Path: rundll32.exe shdocvw.dll,OpenURL %l
.URL
Startup Type: InternetShortcut
Click for Plus Info


VBScript Script File
WScript.exe %1 %* Microsoft ® Windows Based Script Host
Version: 5.6.0.8820 Copyright © Microsoft Corp. 2002
Path: C:\WINDOWS\System32\WScript.exe %1 %*
.VBS
Startup Type: VBSFile
Click for Plus Info


VBScript Encoded Script File
WScript.exe %1 %* Microsoft ® Windows Based Script Host
Version: 5.6.0.8820 Copyright © Microsoft Corp. 2002
Path: C:\WINDOWS\System32\WScript.exe %1 %*
.VBE
Startup Type: VBEFile
Click for Plus Info


Windows Script File
WScript.exe %1 %* Microsoft ® Windows Based Script Host
Version: 5.6.0.8820 Copyright © Microsoft Corp. 2002
Path: C:\WINDOWS\System32\WScript.exe %1 %*
.WSF
Startup Type: WSFFile
Click for Plus Info


Windows Script Host Settings File
WScript.exe %1 %* Microsoft ® Windows Based Script Host
Version: 5.6.0.8820 Copyright © Microsoft Corp. 2002
Path: C:\WINDOWS\System32\WScript.exe %1 %*
.WSH
Startup Type: WSHFile
Click for Plus Info


• Services •
appmgmts.dll

Path: C:\WINDOWS\System32\appmgmts.dll
First Detected by WinPatrol: 03/30/2007 11:49 AM
Provides software installation services such as Assign, Publish, and Remove.
Created:
Accessed:
Written:
File Size: Bytes
Click for Plus Info


hidserv.dll

Path: C:\WINDOWS\System32\hidserv.dll
First Detected by WinPatrol: 03/30/2007 11:49 AM
Enables generic input access to Human Interface Devices (HID), which activates and maintains the use of predefined hot buttons on keyboards, remote controls, and other multimedia devices. If this service is stopped, hot buttons controlled by this service will no longer function. If this service is disabled, any services that explicitly depend on it will fail to start.
Created:
Accessed:
Written:
File Size: Bytes
Click for Plus Info


• Hidden Files •
pagefile
pagefile.sys
Path: C:\pagefile.sys
First Detected by WinPatrol: 03/30/2007 11:49 AM
Click for Plus Info


WindowsShell.Mani
WindowsShell.Manifest
Path: C:\WINDOWS\WindowsShell.Manifest
First Detected by WinPatrol: 03/30/2007 11:49 AM
Click for Plus Info


winnt
winnt.bmp
Path: C:\WINDOWS\winnt.bmp
First Detected by WinPatrol: 03/30/2007 11:49 AM
Click for Plus Info


winnt256
winnt256.bmp
Path: C:\WINDOWS\winnt256.bmp
First Detected by WinPatrol: 03/30/2007 11:49 AM
Click for Plus Info


default
default.LOG
Path: C:\WINDOWS\system32\config\default.LOG
First Detected by WinPatrol: 03/30/2007 11:49 AM
Click for Plus Info


SAM
SAM.LOG
Path: C:\WINDOWS\system32\config\SAM.LOG
First Detected by WinPatrol: 03/30/2007 11:49 AM
Click for Plus Info


SECURITY
SECURITY.LOG
Path: C:\WINDOWS\system32\config\SECURITY.LOG
First Detected by WinPatrol: 03/30/2007 11:49 AM
Click for Plus Info


software
software.LOG
Path: C:\WINDOWS\system32\config\software.LOG
First Detected by WinPatrol: 03/30/2007 11:49 AM
Click for Plus Info


system
system.LOG
Path: C:\WINDOWS\system32\config\system.LOG
First Detected by WinPatrol: 03/30/2007 11:49 AM
Click for Plus Info


logonui.exe.mani
logonui.exe.manifest Windows Logon UI
Version: 6.00.2900.2180 © Microsoft Corporation. All rights reserved.
Path: C:\WINDOWS\system32\logonui.exe.manifest
First Detected by WinPatrol: 03/30/2007 12:00 AM
Click for Plus Info


ncpa.cpl.mani
ncpa.cpl.manifest
Path: C:\WINDOWS\system32\ncpa.cpl.manifest
First Detected by WinPatrol: 03/30/2007 11:49 AM
Click for Plus Info


nwc.cpl.mani
nwc.cpl.manifest
Path: C:\WINDOWS\system32\nwc.cpl.manifest
First Detected by WinPatrol: 03/30/2007 11:49 AM
Click for Plus Info


filelist
filelist.xml
Path: C:\WINDOWS\system32\Restore\filelist.xml
First Detected by WinPatrol: 03/30/2007 11:49 AM
Click for Plus Info


sapi.cpl.mani
sapi.cpl.manifest
Path: C:\WINDOWS\system32\sapi.cpl.manifest
First Detected by WinPatrol: 03/30/2007 11:49 AM
Click for Plus Info


wuaucpl.cpl.mani
wuaucpl.cpl.manifest
Path: C:\WINDOWS\system32\wuaucpl.cpl.manifest
First Detected by WinPatrol: 03/30/2007 11:49 AM
Click for Plus Info


------HIJACK LOG---------
Logfile of HijackThis v1.99.1
Scan saved at 12:22:11 PM, on 3/30/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\DOCUME~1\Miranda\LOCALS~1\Temp\Temporary Directory 1 for hijackthis[1].zip\HijackThis.exe
C:\Documents and Settings\Miranda\Desktop\HijackThis.exe

O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=58813
O16 - DPF: {1E3F1348-4370-4BBE-A67A-CC7ED824CA85} (Microsoft Genuine Advantage Self Support Tool) - http://go.microsoft.com/fwlink/?LinkId=82580
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
Ironbender
Hi Miranda, welcome to SAF smile.gif

All we need to start with is the Hijackthis log. The one you posted is not complete. Please rename hijackthis.exe to any name you feel comfortable with (such as miranda.exe or myscan.exe), as some baddies are now able to detect hijackthis.exe and hide from it.

Next, post a fresh HJT log.

I am moving this thread to the proper forum.

Chris
Miranda
Click to view attachmentI'm sorry that I posted the wrong thing at the wrong place. Hopefully this will be the correct hijack this log, thank you for your patience. I would also like to ad that when I reinstalled Windows it was .xpsp_sp2_gdr or something like that. It was a burned copy from my b/f's work. I still have the cd, it is Windows Home edition.

Ironbender
Miranda,

The log is still not complete. The services (023) entries are missing... sad.gif
QUOTE
Logfile of HijackThis v1.99.1
Scan saved at 6:34:37 AM, on 4/1/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\Program Files\WLAN\802.11b+g USB WLAN\ZDWlan.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Miranda\Desktop\Miranda.exe

O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - Global Startup: 802.11b+g USB Wireless LAN Utility.lnk = C:\Program Files\WLAN\802.11b+g USB WLAN\ZDWlan.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=58813
O16 - DPF: {1E3F1348-4370-4BBE-A67A-CC7ED824CA85} (Microsoft Genuine Advantage Self Support Tool) - http://go.microsoft.com/fwlink/?LinkId=82580
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
.
.
.
Please run HJT in normal mode again, highlight "all" the notepad contents and copy/paste it on your next reply.

If there are still no 023 entries showing, your copy of HJT may be buggy or corrupted. Please download a new one from the link provided on this pinned tutorial: http://www.suggestafix.com/index.php?showtopic=16053

Chris
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2009 Invision Power Services, Inc.