help please

The Hijack log does not show the proxy override setting, but each time I log on, I get

ProxyOverride" -> <local>;cgi*.ebay.com;disney.go.com;msa_e1.ebay.com;rhapsody_app*.listen.com

The ark.txt is probably defective. I think I saved it too early, but each time I tried to do it again, the program crashed my computer before I could save anything.

Any help would be greatly appreciated. I have spent many hours trying to figure this out.


I can't figure out how to upload the hijack log, so I am including the text. Sorry.

Logfile of Trend Micro HijackThis v2.0.4

Scan saved at 6:02:12 PM, on 8/2/2010

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v8.00 (8.00.6001.18702)

Boot mode: Normal

Running processes:







C:\Program Files\Microsoft Security Essentials\MsMpEng.exe


C:\Program Files\Common Files\Microsoft Shared\Ink\KeyboardSurrogate.exe

C:\Program Files\Intel\WiFi\bin\S24EvMon.exe





C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe

C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe

C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe

C:\Program Files\ThinkPad\Tablet Shortcut\ASR\ASRSVC.exe

C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe

C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe

C:\Program Files\ThinkPad\Utilities\DOZESVC.EXE

C:\Program Files\Intel\WiFi\bin\EvtEng.exe


C:\Program Files\Soluto\soluto.exe

C:\Program Files\Google\Update\\GoogleCrashHandler.exe


C:\Program Files\Java\jre6\bin\jqs.exe



C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe

C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe

C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe

C:\Program Files\Common Files\Motive\McciCMService.exe

C:\Program Files\Norton AntiVirus\Engine\\ccSvcHst.exe

C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe

C:\Program Files\Common Files\Microsoft Shared\Ink\TCServer.exe

C:\Program Files\Common Files\PC Tools\sMonitor\StartManSvc.exe

C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe

C:\Program Files\Common Files\Microsoft Shared\Ink\TabTip.exe

C:\Program Files\Soluto\SolutoService.exe



c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe

C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe



c:\program files\lenovo\system update\suservice.exe


C:\Program Files\ThinkPad\Tablet Shortcut\TSMService.exe


C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe

C:\Program Files\Lenovo\Zoom\TpScrex.exe


C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe

C:\Program Files\ThinkPad\Tablet Shortcut\TSMRESIDENT.EXE

C:\Program Files\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe


C:\Program Files\Lenovo\Rescue and Recovery\rrpservice.exe

C:\Program Files\Lenovo\Rescue and Recovery\rrservice.exe


C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe


c:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe

C:\Program Files\Lenovo\Rescue and Recovery\UpdateMonitor.exe

C:\Program Files\ThinkPad\Utilities\PWMDBSVC.EXE

C:\Program Files\Norton AntiVirus\Engine\\ccSvcHst.exe

C:\Program Files\Lenovo\Client Security Solution\cssauth.exe


C:\Program Files\Analog Devices\Core\smax4pnp.exe

C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe

C:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe



C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe

C:\Program Files\Microsoft Security Essentials\msseces.exe

C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

C:\Program Files\Microsoft ActiveSync\wcescomm.exe

C:\Program Files\interMute\AdSubtract\AdSub.exe


C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe


C:\Program Files\Microsoft Office\Office12\WINWORD.EXE

C:\Program Files\putty.exe

C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE

C:\Program Files\Mozilla Firefox\firefox.exe

C:\Program Files\Mozilla Firefox\plugin-container.exe

C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.exe

C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe

C:\Program Files\Winamp\winamp.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=74005

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=localhost:1047

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 0x00000000 (0)

F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\Program Files\Soluto\soluto.exe /userinit

O2 - BHO: (no name) - AutorunsDisabled - (no file)

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)

O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton AntiVirus\Engine\\IPSBHO.DLL

O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll

O2 - BHO: Password Manager Browser Helper Object - {BF468356-BB7E-42D7-9F15-4F3B9BCFCED2} - C:\Program Files\Lenovo\Client Security Solution\tvtpwm_ie_com.dll

O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll

O2 - BHO: Google Gears Helper - {E0FEFE40-FBF9-42AE-BA58-794CA7E3FB53} - C:\Program Files\Google\Google Gears\Internet Explorer\\gears.dll

O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

O2 - BHO: (no name) - {F040E541-A427-4CF7-85D8-75E3E0F476C5} - (no file)

O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll

O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)

O3 - Toolbar: AdSubtract Toolbar - {F14AABDD-0232-4e5a-9B52-4178AC0A62B5} - C:\WINDOWS\system32\adsubtb.dll

O4 - HKLM\..\Run: [TabletWizard] C:\WINDOWS\help\SplshWrp.exe

O4 - HKLM\..\Run: [TabletTip] "C:\Program Files\Common Files\microsoft shared\ink\tabtip.exe" /resume

O4 - HKLM\..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor

O4 - HKLM\..\Run: [bLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog

O4 - HKLM\..\Run: [TPFNF7] C:\PROGRA~1\Lenovo\NPDIRECT\TPFNF7SP.exe /r

O4 - HKLM\..\Run: [TrackPointSrv] C:\Program Files\Lenovo\TrackPoint\tp4serv.exe

O4 - HKLM\..\Run: [TPHOTKEY] C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe

O4 - HKLM\..\Run: [TpShocks] TpShocks.exe

O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe

O4 - HKLM\..\Run: [TSMResident] "C:\Program Files\ThinkPad\Tablet Shortcut\TSMRESIDENT.EXE" /r

O4 - HKLM\..\Run: [soundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray

O4 - HKLM\..\Run: [LPManager] C:\PROGRA~1\THINKV~2\PrdCtr\LPMGR.exe

O4 - HKLM\..\Run: [iSUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup

O4 - HKLM\..\Run: [iSUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start

O4 - HKLM\..\Run: [LPMailChecker] C:\PROGRA~1\THINKV~2\PrdCtr\LPMLCHK.exe

O4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper

O4 - HKLM\..\Run: [DNS7reminder] "C:\Program Files\Nuance\NaturallySpeaking10\Ereg\Ereg.exe" -r "C:\Documents and Settings\All Users\Application Data\Nuance\NaturallySpeaking10\Ereg.ini

O4 - HKLM\..\Run: [cssauth] "C:\Program Files\Lenovo\Client Security Solution\cssauth.exe" silent

O4 - HKLM\..\Run: [AMSG] C:\PROGRA~1\THINKV~2\AMSG\Amsg.exe /startup

O4 - HKLM\..\Run: [soundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe

O4 - HKLM\..\Run: [TVT Scheduler Proxy] C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe

O4 - HKLM\..\Run: [LENTBCTL] "C:\Program Files\ThinkPad\Tablet Shortcut\LENTBCTL.EXE" /r

O4 - HKLM\..\Run: [TabletButton] "C:\Program Files\ThinkPad\Tablet Shortcut\TabletButton.EXE" /STARTUP

O4 - HKLM\..\Run: [DiskeeperSystray] "C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe"

O4 - HKLM\..\Run: [AwaySch] C:\Program Files\Lenovo\AwayTask\AwaySch.EXE

O4 - HKLM\..\Run: [igfxTray] C:\WINDOWS\system32\igfxtray.exe

O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe

O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe

O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray

O4 - HKLM\..\Run: [MSSE] "C:\Program Files\Microsoft Security Essentials\msseces.exe" -hide -runkey

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"

O4 - HKCU\..\RunOnce: [TSClientMSIUninstaller] cmd.exe /C "cscript %systemroot%\Installer\TSClientMsiTrans\tscuinst.vbs"

O4 - HKUS\S-1-5-19\..\Run: [TabletWizard] %windir%\help\wizard.hta (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-19\..\RunOnce: [] (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-20\..\Run: [TabletWizard] %windir%\help\wizard.hta (User 'NETWORK SERVICE')

O4 - HKUS\S-1-5-20\..\RunOnce: [] (User 'NETWORK SERVICE')

O4 - HKUS\S-1-5-18\..\RunOnce: [] (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\RunOnce: [] (User 'Default user')

O4 - Startup: AdSubtract.lnk = C:\Program Files\interMute\AdSubtract\AdSub.exe

O4 - Startup: AutorunsDisabled

O8 - Extra context menu item: AdSubtract: Bypass Site - res://C:\Program Files\interMute\AdSubtract\AdSub.exe/360

O8 - Extra context menu item: AdSubtract: Cloak Image - res://C:\Program Files\interMute\AdSubtract\AdSub.exe/361

O8 - Extra context menu item: AdSubtract: Report Site - res://C:\Program Files\interMute\AdSubtract\AdSub.exe/359

O9 - Extra button: (no name) - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Program Files\Google\Google Gears\Internet Explorer\\gears.dll

O9 - Extra 'Tools' menuitem: &Gears Settings - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Program Files\Google\Google Gears\Internet Explorer\\gears.dll

O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll

O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll

O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL

O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm

O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm

O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: (no name) - {F4F55DC8-0B69-4DFE-BA94-CB677B88B2A3} - C:\Program Files\Lenovo\Client Security Solution\tvtpwm_ie_com.dll

O9 - Extra 'Tools' menuitem: Lenovo Password Manager... - {F4F55DC8-0B69-4DFE-BA94-CB677B88B2A3} - C:\Program Files\Lenovo\Client Security Solution\tvtpwm_ie_com.dll

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O16 - DPF: {001EE746-A1F9-460E-80AD-269E088D6A01} (Infotl Control) - http://site.ebrary.com/lib/berkeley/suppor...s/ebraryRdr.cab

O16 - DPF: {2DAD3559-2923-4935-AD49-B673D2539944} (IASRunner Class) - http://www-307.ibm.com/pc/support/acpir.cab

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1240377929750

O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1240377904218

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/get/flash...ent/swflash.cab

O16 - DPF: {E0FEE963-BB53-4215-81AD-B28C77384644} (WebBrowserType Class) - https://pattcw.att.motive.com/wizlet/DSLAct...etInstaller.cab

O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll

O20 - Winlogon Notify: ACNotify - ACNotify.dll (file missing)

O20 - Winlogon Notify: AutorunsDisabled - Invalid registry found

O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll

O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll

O23 - Service: Ac Profile Manager Service (AcPrfMgrSvc) - Lenovo - C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe

O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe

O23 - Service: Access Connections Main Service (AcSvc) - Lenovo - C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe

O23 - Service: ASR Service (ASRSVC) - Lenovo Group Limited - C:\Program Files\ThinkPad\Tablet Shortcut\ASR\ASRSVC.exe

O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe

O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe

O23 - Service: Lenovo Doze Mode Service (DozeSvc) - Lenovo. - C:\Program Files\ThinkPad\Utilities\DOZESVC.EXE

O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel® Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe

O23 - Service: Google Update Service (gupdate1c9c9e97f109188) (gupdate1c9c9e97f109188) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe

O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: ThinkPad PM Service (IBMPMSVC) - Lenovo. - C:\WINDOWS\system32\ibmpmsvc.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe

O23 - Service: IPS Core Service (IPSSVC) - Lenovo Group Limited - C:\WINDOWS\system32\IPSSVC.EXE

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

O23 - Service: Lenovo Camera Mute (LENOVO.CAMMUTE) - Lenovo Group Limited - C:\Program Files\LENOVO\HOTKEY\CAMMUTE.exe

O23 - Service: Lenovo Microphone Mute (LENOVO.MICMUTE) - Lenovo Group Limited - C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe

O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe

O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe

O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe

O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe

O23 - Service: McciCMService - Alcatel-Lucent - C:\Program Files\Common Files\Motive\McciCMService.exe

O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe

O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe

O23 - Service: Norton AntiVirus - Symantec Corporation - C:\Program Files\Norton AntiVirus\Engine\\ccSvcHst.exe

O23 - Service: PC Tools Startup and Shutdown Monitor service (PCToolsSSDMonitorSvc) - Unknown owner - C:\Program Files\Common Files\PC Tools\sMonitor\StartManSvc.exe

O23 - Service: Power Manager DBC Service - Unknown owner - C:\Program Files\ThinkPad\Utilities\PWMDBSVC.EXE

O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel® Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe

O23 - Service: Intel® PROSet/Wireless WiFi Service (S24EventMonitor) - Intel® Corporation - C:\Program Files\Intel\WiFi\bin\S24EvMon.exe

O23 - Service: Soluto PCGenome Core Service (SolutoService) - Soluto - C:\Program Files\Soluto\SolutoService.exe

O23 - Service: System Update (SUService) - Lenovo Group Limited - c:\program files\lenovo\system update\suservice.exe

O23 - Service: Symantec RemoteAssist - Symantec, Inc. - C:\Program Files\Common Files\Symantec Shared\Support Controls\ssrc.exe

O23 - Service: TABLET Service (TabletSVC) - Lenovo Group Limited - C:\Program Files\ThinkPad\Tablet Shortcut\TSMService.exe

O23 - Service: ThinkVantage Registry Monitor Service - Lenovo Group Limited - C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe

O23 - Service: ThinkPad HDD APS Logging Service (TPHDEXLGSVC) - Lenovo. - C:\WINDOWS\System32\TPHDEXLG.exe

O23 - Service: On Screen Display (TPHKSVC) - Lenovo Group Limited - C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe

O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe

O23 - Service: TSS Core Service (TSSCoreService) - Lenovo - C:\Program Files\Lenovo\Client Security Solution\tvttcsd.exe

O23 - Service: TVT Backup Protection Service - Unknown owner - C:\Program Files\Lenovo\Rescue and Recovery\rrpservice.exe

O23 - Service: TVT Backup Service - Lenovo Group Limited - C:\Program Files\Lenovo\Rescue and Recovery\rrservice.exe

O23 - Service: TVT Scheduler - Lenovo Group Limited - c:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe

O23 - Service: TVT Windows Update Monitor (TVT_UpdateMonitor) - Lenovo Group Limited - C:\Program Files\Lenovo\Rescue and Recovery\UpdateMonitor.exe


End of file - 19763 bytes




Welcome to the forum.

Please disable Spybots TeaTimer:


When we are all done, you can enable with this small app:


[*]Close all programs leaving only HijackThis running. Place a check against each of the following, making sure you get them all and not any others by mistake:

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=localhost:1047

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 0x00000000 (0)

O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)

O2 - BHO: (no name) - {F040E541-A427-4CF7-85D8-75E3E0F476C5} - (no file)

O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)

O4 - HKUS\S-1-5-19\..\RunOnce: [] (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-20\..\RunOnce: [] (User 'NETWORK SERVICE')

O4 - HKUS\S-1-5-18\..\RunOnce: [] (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\RunOnce: [] (User 'Default user')

Click on Fix Checked when finished and exit HijackThis.


Download ComboFix from one of these locations:

Link 1

Link 2

ComboFix Guide

* IMPORTANT !!! Save ComboFix.exe to your Desktop

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon and choose disable/exit. More info HERE
    They may interfere with the running of ComboFix.
  • Double click on ComboFix.exe & follow the prompts.
    Notes: Combofix will run without the Recovery Console installed. Skip the Recovery Console part if you're running Vista or Windows 7.
    Note: If you have SP3, use the SP2 package.
    If Vista or Windows 7, skip the Recovery Console part
  • ComboFix will check to see if the Microsoft Windows Recovery Console is installed. It's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt using Copy / Paste in your next reply.


1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.

2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.

3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you -- please let me know.

4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

5.Give it atleast 20-30 minutes to finish if needed.


ComboFix 10-08-03.01 - Administrator 08/03/2010 13:41:25.1.2 - x86

Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2006.1018 [GMT -7:00]

Running from: f:\00000\ComboFix.exe

AV: Microsoft Security Essentials *On-access scanning disabled* (Updated) {BCF43643-A118-4432-AEDE-D861FCBCFCDF}

AV: Norton AntiVirus *On-access scanning disabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


c:\documents and settings\Administrator\Application Data\putty.exe

c:\documents and settings\All Users\Start Menu\Programs\Microsoft Security Essentials.lnk




((((((((((((((((((((((((( Files Created from 2010-07-03 to 2010-08-03 )))))))))))))))))))))))))))))))


2010-08-02 16:49 . 2010-06-01 17:37 221568 ------w- c:\windows\system32\MpSigStub.exe

2010-08-02 16:45 . 2010-08-02 16:46 -------- d-----w- c:\program files\Microsoft Security Essentials

2010-07-28 20:34 . 2010-07-28 20:34 -------- d-----w- c:\program files\ATT-HSI

2010-07-28 20:34 . 2010-07-28 20:34 -------- d-----w- c:\documents and settings\All Users\Application Data\Motive

2010-07-28 20:34 . 2010-07-28 20:34 -------- d-----w- c:\program files\Common Files\Motive

2010-07-28 00:09 . 2010-07-28 00:09 -------- d-----w- c:\documents and settings\Administrator\Application Data\MSNInstaller

2010-07-27 21:19 . 2010-07-27 21:19 -------- d-----w- c:\program files\Trend Micro

2010-07-15 00:35 . 2007-03-01 05:24 451072 ------w- C:\putty.exe

2010-07-14 22:21 . 2010-07-14 22:21 -------- d-----w- c:\program files\Conduits Pocket Player

2010-07-11 04:15 . 2010-08-03 20:48 7301720 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat

2010-07-06 21:50 . 2010-07-06 21:50 -------- d-----w- c:\documents and settings\LocalService\Application Data\Intel

2010-07-06 21:50 . 2010-07-06 21:50 -------- d-----w- c:\documents and settings\All Users\Application Data\Intel

2010-07-06 21:50 . 2010-07-06 21:50 -------- d-----w- c:\documents and settings\Administrator\Application Data\Intel

2010-07-06 21:50 . 2010-07-06 21:50 -------- d-----w- c:\documents and settings\NetworkService\Application Data\Intel

2010-07-04 23:59 . 2010-07-04 23:59 -------- d-----w- c:\program files\ParaGraph


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))


2010-08-03 03:05 . 2008-03-19 11:44 -------- d-----w- c:\program files\Mozilla Thunderbird

2010-08-02 02:15 . 2009-10-12 03:32 664 ----a-w- c:\windows\system32\d3d9caps.dat

2010-07-29 04:53 . 2008-08-26 21:44 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP

2010-07-28 22:56 . 2008-03-23 14:33 3114 ------w- c:\documents and settings\Administrator\Application Data\SAS7_000.DAT

2010-07-27 23:49 . 2009-12-16 05:58 -------- d-----w- c:\program files\PC-Doctor

2010-07-27 23:49 . 2008-12-18 04:15 -------- d-----w- c:\documents and settings\All Users\Application Data\PCDr

2010-07-27 21:19 . 2010-07-27 21:19 388096 ------r- c:\documents and settings\Administrator\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe

2010-07-14 22:21 . 2008-03-13 15:37 -------- d--h--w- c:\program files\InstallShield Installation Information

2010-07-13 21:53 . 2008-03-13 16:08 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help

2010-07-06 21:51 . 2008-03-13 15:37 -------- d-----w- c:\program files\ThinkPad

2010-07-06 21:49 . 2008-03-13 15:37 -------- d-----w- c:\program files\Intel

2010-07-05 00:18 . 2008-03-20 01:23 -------- d-----w- c:\program files\Microsoft ActiveSync

2010-06-27 00:55 . 2010-06-27 00:55 -------- d-----w- c:\program files\Digital Line Detect

2010-06-27 00:55 . 2010-06-27 00:55 -------- d-----w- c:\program files\NetWaiting

2010-06-27 00:54 . 2008-03-13 15:41 -------- d-----w- c:\program files\CONEXANT

2010-06-20 00:04 . 2010-06-19 23:56 -------- d-----w- c:\documents and settings\All Users\Application Data\Soluto

2010-06-20 00:04 . 2008-03-13 16:15 69232 ------w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT

2010-06-20 00:03 . 2010-06-19 23:57 -------- d-----w- c:\program files\Soluto

2010-06-19 23:55 . 2010-06-19 23:57 926568 ------w- c:\documents and settings\All Users\Application Data\Soluto\Installer\SolutoInstaller.exe

2010-06-18 01:00 . 2009-04-24 01:55 -------- d-----w- c:\documents and settings\Administrator\Application Data\Winamp

2010-06-15 21:46 . 2010-06-19 23:57 179656 ------w- c:\windows\system32\drivers\PCGenFAM.sys

2010-06-15 19:01 . 2010-06-15 19:00 -------- d-----w- c:\program files\Common Files\Adobe

2010-06-14 14:31 . 2006-04-30 23:11 744448 ------w- c:\windows\pchealth\helpctr\binaries\helpsvc.exe

2010-06-05 16:19 . 2009-01-07 18:53 -------- d-----w- c:\program files\Microsoft Silverlight

2010-06-02 21:49 . 2010-06-27 00:53 301624 ------w- c:\windows\system32\UCI32M57.dll

2010-06-02 21:49 . 2007-03-14 09:40 19384 ------w- c:\windows\system32\drivers\mdmxsdk.sys

2010-06-02 21:49 . 2007-03-14 09:40 100920 ------w- c:\windows\system32\mdmxsdk.dll

2010-06-02 21:49 . 2007-03-14 09:40 993464 ------w- c:\windows\system32\drivers\HSF_DPV.sys

2010-06-02 21:49 . 2007-03-14 09:39 738360 ------w- c:\windows\system32\drivers\HSF_CNXT.sys

2010-06-02 21:49 . 2007-03-14 09:40 217016 ------w- c:\windows\system32\drivers\HSFHWAZL.sys

2010-06-02 05:55 . 2010-06-02 05:55 1023061 ------w- C:\perelmancopyedits_my.zip

2010-05-12 08:25 . 2010-02-04 00:52 24304 ------w- c:\windows\system32\drivers\DOZEHDD.SYS

2010-05-12 08:25 . 2008-03-13 15:37 4442 ------w- c:\windows\system32\drivers\TPPWRIF.SYS

2010-05-12 08:25 . 2008-03-13 15:37 196608 ------w- c:\windows\PWMBTHLP.EXE

2010-05-06 10:41 . 2006-04-30 22:51 916480 ------w- c:\windows\system32\wininet.dll

2010-05-06 02:24 . 2010-05-06 02:22 38784 ------w- c:\documents and settings\Administrator\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe

2009-04-24 01:52 . 2008-03-20 01:20 5048 ------w- c:\program files\Winamp.ini

2009-04-24 01:52 . 2008-03-20 01:19 212 ------w- c:\program files\winamp.m3u

2008-10-24 04:16 . 2008-04-07 01:34 454656 ------w- c:\program files\putty.exe

2008-01-18 02:26 . 2008-03-20 01:20 5543 ------w- c:\program files\studio.xnf

2004-05-05 05:16 . 2008-03-20 01:19 3213 ------w- c:\program files\winampmb.htm

2004-05-05 05:16 . 2008-03-20 01:19 272 ------w- c:\program files\Winamp.lks

2004-03-26 14:54 . 2008-03-20 01:19 4587 ------w- c:\program files\Winamp.q1

2004-03-26 14:54 . 2008-03-20 01:20 43364 ------w- c:\program files\UninstWA.exe

2004-02-05 05:36 . 2008-03-20 01:20 5887 ------w- c:\program files\whatsnew.txt

2004-02-05 05:35 . 2008-03-20 01:20 968192 ------w- c:\program files\winamp.exe

2003-12-13 00:50 . 2008-03-20 01:19 33792 ------w- c:\program files\winampa.exe

2003-10-29 00:34 . 2008-03-20 01:20 110592 ------w- c:\program files\PXSDKPLS.dll

2001-11-15 18:45 . 2008-03-20 01:20 38912 ------w- c:\program files\demo.mp3

2008-06-30 20:44 . 2009-04-30 19:13 324976 ------w- c:\program files\mozilla firefox\components\coFFPlgn.dll



1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:


uInternet Settings,ProxyServer = http=localhost:1046

uInternet Settings,ProxyOverride =

Save this as CFScript.txt, in the same location as ComboFix.exe


Refering to the picture above, drag CFScript into ComboFix.exe

CAUTION: Do not mouse-click ComboFix while it is running. It may cause it to stall.

After reboot, (in case it asks to reboot)......

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.


Please read carefully and follow these steps.

  • Download TDSSKiller and save it to your Desktop.
  • Doubleclick on TDSSKiller.exe to run the application, then on Start Scan.
  • If an infected file is detected, the default action will be Cure, click on Continue.
  • If a suspicious file is detected, the default action will be Skip, click on Continue.
  • It may ask you to reboot the computer to complete the process. Click on Reboot Now.

After the reboot (if it required) you'll find the log in C:\

Please post it back here along with the log from ComboFix, MrC

I forget what those settings are from, but why do you want them gone?

What are the symptoms?

Here's where those settings are at:

  • Open up Internet Explorer, and when the program is open, click on the Tools menu and then select Internet Options.
  • Another way to get to your Internet Properties:
    Go to your Start Button > Run > copy and paste this in: inetcpl.cpl > Click OK
  • Now click on the Connections
  • Now click on the Lan Settings
  • Make any changes there

Let me know, MrC

I know how to change the settings for a proxy server, but

1. It is a nuisance to do it every time I log on.

2. I am suspicious that the virus or whatever sets the proxy server in the registry to an address with ebay and disney & other companies. I assume it does that to do something bad.


Link to post
What are the symptoms that these entries give you when present?

It could be one of your malware programs is preventing the fix or a program that you have keeps reinstalling them.


Please do this:

Download Security Check by screen317 from HERE or HERE.

  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.


It does not show anything. If nothing happens when I reboot tonight, I will not respond, thanking you right now.

If not, I will pester you again tomorrow.

Results of screen317's Security Check version 0.99.5

Windows XP Service Pack 3

Internet Explorer 8


Antivirus/Firewall Check:

Windows Firewall Enabled!

Norton AntiVirus

Microsoft Security Essentials

Antivirus up to date! (On Access scanning disabled!)


Anti-malware/Other Utilities Check:

Malwarebytes' Anti-Malware

HijackThis 2.0.2


Java 6 Update 15

Out of date Java installed!

Adobe Flash Player

Adobe Reader 9.3.3

Chinese Simplified Fonts Support For Adobe Reader 9

Japanese Fonts Support For Adobe Reader 9


Process Check:

objlist.exe by Laurent

Norton ccSvcHst.exe

Malwarebytes' Anti-Malware mbamservice.exe

Malwarebytes' Anti-Malware mbamgui.exe

Microsoft Small Business Business Contact Manager BcmSqlStartupSvc.exe


DNS Vulnerability Check:

GREAT! (Not vulnerable to DNS cache poisoning)

``````````End of Log````````````

The first 2 times I restarted, no problem. Now it has returned. Even worse, I do all of my research and writing with an old DOS program. For some reason, ANSI.SYS no longer works. I cannot figure out why. It appears in my config.sys program.

Link to post
Did you read the 2 links I gave you? Please read through them.

Here's how to change the settings: (I don't have IE8 so I can't confirm this)

Select the Tools > Internet Options menu item.

Select the Security tab.

Select the Local intranet zone and

Ensure that Enable Protected Mode is unchecked.

Click the "Microsoft.com" link.


ComboFix creates a restore point just before it runs, go to your system restore and restore the computer back to a point just before ComboFix ran.

08/03/2010 13:41:25<----this is the first time you ran it.

See if that restores the function that doesn't work now.


Shouldn't it be in config.nt?

Found this:

Found the answer to my own question - so if anybody else

needs to know - of the MANY copies of config.nt to be

found you have to specifically modify the one contained in

C:\windows\system32 - picking up Config.nt from any of

it's sources, (I386 is fine) and include the device=c:\I386

\anis.sys line in the version of config.nt in the system32

folder - all this has wasted about 3 hours so far...


Link to post
There was no combofix restore file that I could find. I restored going back one month.

I think that the last program I used was what did the damage. I don't know if I should start over since it did not really fix my problem. I will try to change the IE settings now.

Link to post
