<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Security Cleanup forum - dslreports.com community</title>
<link>http://www.dslreports.com/forum/cleanup</link>
<description>Security Cleanup forum current topics</description>
<language>en</language>
<copyright>Copyright 2007, dslreports.com</copyright>
<pubDate>Tue, 10 Nov 2009 16:30:51 EDT</pubDate>
<lastBuildDate>Tue, 10 Nov 2009 16:30:51 EDT</lastBuildDate>

<image>
<title>dslreports.com</title>
<url>http://i.dslr.net/bbrdisc1.gif</url>
<link>http://www.dslreports.com</link>
<width>19</width>
<height>18</height>
<description>bbr disc</description>
</image>

<item>
<title>HJT Log Intermittant internet connection</title>
<link>http://www.dslreports.com/forum/remark,23277047</link>
<description><![CDATA[Internet starts and stops every few seconds. Fast when it is working.

Link to another thread for more info

http://www.dslreports.com/forum/r23269679-Intermittant-connection-Lompoc-CA

Mod Note: Please follow these steps:
http://www.dslreports.com/faq/13616

The FAQ will tell you what programs to run, what logs to post & where to locate them.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,23277047</guid>
<pubDate>2009-11-02 02:36:35</pubDate>
</item>

<item>
<title>HJT Log - Agent.PBY</title>
<link>http://www.dslreports.com/forum/remark,23275649</link>
<description><![CDATA[A bunch of programs requiring COMRes.dll are bombarding me with pop-ups because it can't be found, including spybot. Whatever has infected me is also preventing me from accessing cnet to download ad-aware. I ran the ESET scanner and Anti-Malware, which found around a thousand infections. It's cleaned up a lot of stuff, but I'm still getting errors about COMRes.dll.

Edit: I think that the best course of action at this point is just to wipe windows and reinstall.
--
My pbase gallery]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,23275649</guid>
<pubDate>2009-11-01 18:35:59</pubDate>
</item>

<item>
<title>[Trojan] No HJT Log - can not run any .exe</title>
<link>http://www.dslreports.com/forum/remark,23197531</link>
<description><![CDATA[Got the Windows Antivirus Pro and Windows Police Pro pop-up/virus.  Those windows no longer come up, but the computer is now unable to launch any .exe program except internet explorer.

>Computer will not boot in Safe Mode, goes to blue "stop" screen.
>Malwarebytes - downloaded but will not run, even if I rename it.
>Spybot Search & Destroy 1.6.2 - downloaded but will not run.
>Ad-aware AE Free - will not run.
>Windows Defender (Microsoft) - installed, ran scan, found Program:Win32/PowerRegScheduler, did not remove. 
>Malicious Software Removal Tool - downloaded but will not run.
>&raquo;www.eset.com/onlinescan - ran scan, 8 infections found and cleaned/deleted.  Log below.
>Trend Micro Housecall - can not load the Java-based HouseCall kernel. 
>Trend Micro Hijack This - downloaded, will not run.

ESST LOG

ESETSmartInstaller@High as CAB hook log:
OnlineScanner.ocx - registred OK
# version=7
# iexplore.exe=6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)
# OnlineScanner.ocx=1.0.0.6208
# api_version=3.0.2
# EOSSerial=dff4521b7b6a37449fbaedafe84d0868
# end=finished
# remove_checked=true
# archives_checked=false
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2009-10-17 02:29:28
# local_time=2009-10-16 10:29:28 (-0500, Eastern Daylight Time)
# country="United States"
# lang=1033
# osver=5.1.2600 NT Service Pack 2
# compatibility_mode=3839 16777215 0 0 0 0 0 0
# compatibility_mode=5890 16777214 0 0 0 0 0 0
# compatibility_mode=8447 16777215 0 0 0 0 0 0
# scanned=77534
# found=8
# cleaned=8
# scan_time=4949
C:\Program Files\Windows Police Pro\windows Police Pro.exe&#9;a variant of Win32/Adware.WindowsAntivirusPro.B application (cleaned by deleting - quarantined)&#9;00000000000000000000000000000000&#9;C
C:\Program Files\Windows Police Pro\tmp\dbsinit.exe&#9;Win32/Adware.WinAntiVirus application (deleted - quarantined)&#9;00000000000000000000000000000000&#9;C
C:\Program Files\Windows Police Pro\tmp\wispex.html&#9;Win32/Adware.WinAntiVirus application (cleaned by deleting - quarantined)&#9;00000000000000000000000000000000&#9;C
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1203\A0062766.exe&#9;a variant of Win32/Adware.WindowsAntivirusPro.B application (cleaned by deleting - quarantined)&#9;00000000000000000000000000000000&#9;C
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1203\A0062767.exe&#9;Win32/Adware.WinAntiVirus application (deleted - quarantined)&#9;00000000000000000000000000000000&#9;C
C:\WINDOWS\svchasts.exe&#9;Win32/Adware.WindowsAntivirusPro application (cleaned by deleting - quarantined)&#9;00000000000000000000000000000000&#9;C
C:\WINDOWS\SYSTEM32\dddesot.dll&#9;a variant of Win32/Adware.WindowsAntivirusPro.B application (cleaned by deleting - quarantined)&#9;00000000000000000000000000000000&#9;C
C:\WINDOWS\wt\wtupdates\wtwebdriver\files\3.3.1.001\npwthost.dll&#9;probably a variant of Win32/Agent trojan (cleaned by deleting - quarantined)&#9;00000000000000000000000000000000&#9;C

THANKS in advance for all your help!!!!]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,23197531</guid>
<pubDate>2009-10-16 23:16:15</pubDate>
</item>

<item>
<title>Machine completely hosed?</title>
<link>http://www.dslreports.com/forum/remark,23212230</link>
<description><![CDATA[I have no Internet access and I can't run any security software at all. I ran a previously installed Spybot S&D, but it exited and became unrunnable. Many of my services aren't running and say I have no permission to start them.

I just copied Hijack this to a flash drive and tried to run it in safe mode (without networking). It started, but then exited, and now the executable won't run (says I don't have access). Do I need to throw out this flash drive?

Do I have any recourse besides reformatting at this point?

Thanks :(

Elizabeth]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,23212230</guid>
<pubDate>2009-10-20 11:40:38</pubDate>
</item>

<item>
<title>Directed to random webpages</title>
<link>http://www.dslreports.com/forum/remark,22983470</link>
<description><![CDATA[Good evening ladies and gentlemen

I apparently have a nasty on my laptop (I am posting from my PC). I tries to download the programs listed in the mandatory steps thread, but whatever I have is redirecting me to random internet pages, search engines, and other such junk; therefore  I am not able to download and run some of the detection programs. 

On another note I have Spybot downloaded with the icon on the desktop, but when I double click on it nothing happens. I have avast, ad ware, spy blaster and those are functional, but they are not detecting or removing whatever mother of a horse, bug, mal or wing-ding that I managed to invite onto my system. 

Please help and advise. 

Thank you

Flanker1-Nephew of RxDoxx]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22983470</guid>
<pubDate>2009-09-06 20:04:48</pubDate>
</item>

<item>
<title>[Virus] Unable to use hijackthis or any virus removal tools</title>
<link>http://www.dslreports.com/forum/remark,23142521</link>
<description><![CDATA[Reposted from Security forum: I think I have a virus similar to "antivirus 2007".
It changed my background to an image saying I had spyware and my computer wouldn't work because of it.
It has also logged me off and keeps trying to again.

It won't allow me to access regedit, task manager, hidden folders, or any antivirus or malware scanners.

Each time I download a scanner or removal tool it has a generic .exe icon and when I try to open it, it shows a brief dos prompt-type box and then disappears.

I tried making this post from the infected computer but it won't seem to let me.

I'm even having issues accessing safe mode. Whenever I do, it will start then do nothing.
What do I do?

I used trend micro web scanner and it didn't seem to help.
I can't use panda because IE won't work at all and I need to download and install something to use it on firefox and of course I can't do that..]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,23142521</guid>
<pubDate>2009-10-06 20:28:30</pubDate>
</item>

<item>
<title>HJT Log</title>
<link>http://www.dslreports.com/forum/remark,23253126</link>
<description><![CDATA[I attempted to follow all of the required steps. Malware and Spybot came back clean, as did avast and the trendmicro home scan. Adware grabbed a bunch of cookies and 5 objects that were removed. I could not download Defender, said I do not support it or some such. 

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:07:16 AM, on 10/28/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16915)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Fawkes Engineering\AccuRIP\RipCore.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\winsys2.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Adobe\Photoshop Elements 5.0\apdproxy.exe
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [SW20] C:\WINDOWS\system32\sw20.exe
O4 - HKLM\..\Run: [SW24] C:\WINDOWS\system32\sw24.exe
O4 - HKLM\..\Run: [WinSys2] C:\WINDOWS\system32\winsys2.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Elements 5.0\apdproxy.exe"
O4 - HKLM\..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [JeticoPFStartup] "C:\Program Files\Jetico\Jetico Personal Firewall\jpf.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [EPSON Stylus Photo 1400 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBUA.EXE /FU "C:\WINDOWS\TEMP\E_S164.tmp" /EF "HKCU"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O8 - Extra context menu item: &ieSpell Options - res://C:\Program Files\ieSpell\iespell.dll/SPELLOPTION.HTM
O8 - Extra context menu item: Check &Spelling - res://C:\Program Files\ieSpell\iespell.dll/SPELLCHECK.HTM
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Lookup on Merriam Webster - file://C:\Program Files\ieSpell\Merriam Webster.HTM
O8 - Extra context menu item: Lookup on Wikipedia - file://C:\Program Files\ieSpell\wikipedia.HTM
O9 - Extra button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra button: (no name) - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O23 - Service: Adobe Active File Monitor V5 (AdobeActiveFileMonitor5.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Jetico Personal Firewall server - Jetico, Inc. - C:\Program Files\Jetico\Jetico Personal Firewall\jpfsrv.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: RipCore - Unknown owner - C:\Program Files\Fawkes Engineering\AccuRIP\RipCore.exe

--
End of file - 8653 bytes]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,23253126</guid>
<pubDate>2009-10-28 08:15:44</pubDate>
</item>

</channel>
</rss>
