Wednesday I was doing business as usual, when I got one of those fake malware virus scanners pop up and tell me i was infected. So I do some reading, and someone tells me Kaspersky had the best scores with identifying and removing malware, esp zero day stuff. Also internet explorer keeps getting a proxy setup for localhost with some odd port number. TXT -------------------------------------------------------------------------- DDS (Ver_10-12-12.02) - NTFSx86 Run by Rich at .06 on Sat 01/29/2011 Internet Explorer: 8.0.6001.18702 Browser Java Version: 1.6.0_14 Microsoft Windows XP Professional 5.1.2600.2.1252.1.10.2375 [GMT -] AV: Kaspersky Internet Security *Enabled/Updated* FW: Kaspersky Internet Security *Enabled* ============== Running Processes =============== C:\WINDOWS\system32\nvsvc32C:\WINDOWS\system32\svchost -k Dcom Launch C:\WINDOWS\System32\-k netsvcs C:\WINDOWS\system32\C:\Program Files\Common Files\Apple\Mobile Device Support\Apple Mobile Device C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\C:\Program Files\Bonjour\m C:\Program Files\Java\jre6\bin\C:\Program Files\Common Files\Logi Shrd\LVCOMSER\LVCom C:\Program Files\Common Files\Logi Shrd\LVMVFM\LVPrc C:\Program Files\NDAS\System\C:\Program Files\Common Files\Intuit\Quick Books\QBCFMonitor C:\WINDOWS\system32\-k imgsvc C:\Program Files\Xobni\Xobni C:\WINDOWS\Explorer. \Software Update\Yahoo C:\Program Files\Common Files\Logi Shrd\LVCOMSER\LVCom C:\Program Files\NVIDIA Corporation\Network Access Manager\bin32\n Svc App C:\Program Files\NVIDIA Corporation\Network Access Manager\bin32\n Svc C:\WINDOWS\system32\Search C:\Program Files\Logitech\Quick Cam\C:\Program Files\Microsoft Life Chat\Life C:\Program Files\Brother\Brmfcmon\Br Mfc C:\Program Files\Common Files\Logi Shrd\LCom Mgr\Communications_C:\Program Files\Common Files\Logishrd\LQCVFX\C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\C:\Program Files\Brother\Brmfcmon\Br C:\WINDOWS\system32\C:\Program Files\Spybot - Search & Destroy\Tea C:\WINDOWS\System32\-k HTTPFilter C:\WINDOWS\system32\C:\Program Files\SUPERAnti Spyware\SUPERAnti C:\Program Files\NDAS\System\C:\Program Files\Tech Smith\Snagit 9\Snagit32C:\WINDOWS\system32\C:\Documents and Settings\Rich\Desktop\Prc View_5_2_15\Prc C:\Program Files\Tech Smith\Snagit 9\C:\Program Files\Tech Smith\Snagit 9\Snag C:\Program Files\Tech Smith\Snagit 9\C:\Program Files\Mozilla Firefox\C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\C:\Program Files\Mozilla Firefox\C:\Program Files\Microsoft Office\Office12\OUTLOOK.

Ive had them happen once or twice, so i popped open Spybot S&D to clean it. Spybot did its thing, found some cookies and such, and said it needed to reboot to finish scanning. 3 hours later, after a full chkdsk and a fixmbr, I was finally able to boot back into windows. I managed to delete the file (had to use the recovery center do to so), but the issue keeps happening. EXE C:\WINDOWS\system32\Search Protocol C:\WINDOWS\system32\Search Protocol C:\Documents and Settings\Rich\Desktop\PC_Downloads\============== Pseudo HJT Report =============== u Start Page = hxxp:// u Internet Settings, Proxy Override = u Internet Settings, Proxy Server = http= u URLSearch Hooks: Yahoo! \companion\installs\cpn0\m URLSearch Hooks: H - No File BHO: Snag It Toolbar Loader: - c:\program files\techsmith\snagit 9\Snagit BHO: &Yahoo! \companion\installs\cpn0\BHO: Adobe PDF Reader Link Helper: - c:\program files\common files\adobe\acrobat\activex\Acro BHO: - No File BHO: Spybot-S&D IE Protection: - c:\progra~1\spybot~1\BHO: IEVkbd BHO Class: - c:\program files\kaspersky lab\kaspersky internet security 2011\BHO: Groove GFS Browser Helper: - c:\program files\microsoft office\office12\Groove Shell BHO: Last Pass Browser Helper Object: - c:\program files\lastpass\BHO: - No File BHO: Java™ Plug-In 2 SSV Helper: - c:\program files\java\jre6\bin\jp2BHO: Filter BHO Class: - c:\program files\kaspersky lab\kaspersky internet security 2011\BHO: JQSIEStart Detector Impl Class: - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_BHO: Single Instance Class: - c:\program files\yahoo!

