<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Re: [Vundo] Vundo Removal in Security Cleanup</title>
<link>http://www.dslreports.com/forum/r20304853</link>
<description></description>
<language>en</language>
<pubDate>Thu, 08 Jan 2009 09:23:08 EDT</pubDate>
<lastBuildDate>Thu, 08 Jan 2009 09:23:08 EDT</lastBuildDate>

<item>
<title>Re: [Vundo] Vundo Removal</title>
<link>http://www.dslreports.com/forum/remark,20308125</link>
<description><![CDATA[<A HREF="/useremail/u/855835"><b>CajunTek</b></A> : That's what we like to hear!!!  Happy Surfing!<br><small>--<br>da Cajun  Darn I hate Malware</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20308125</guid>
<pubDate>Wed, 09 Apr 2008 12:53:10 EDT</pubDate>
</item>

<item>
<title>Re: [Vundo] Vundo Removal</title>
<link>http://www.dslreports.com/forum/remark,20307347</link>
<description><![CDATA[<A HREF="/useremail/u/727524"><b>fatheadx</b></A> : Thank you very much for the help!  Everything is back to normal and running great.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20307347</guid>
<pubDate>Wed, 09 Apr 2008 10:34:12 EDT</pubDate>
</item>

<item>
<title>Re: [Vundo] Vundo Removal</title>
<link>http://www.dslreports.com/forum/remark,20306688</link>
<description><![CDATA[<A HREF="/useremail/u/855835"><b>CajunTek</b></A> : That looks much better. Are you having any further problems?<br><br>If so, let us know. If not here is my standard post cleanup advice:<br><br><ol><br>&#8226; <b>Visit Windows Update:</b><br>Make sure that you have all the Critical Updates recommended for your operating system and Internet Explorer. This includes SP1 and SP2 if you use Windows XP. The first defense against infection is a properly patched Operating System.<br>         <ul><br>         &#8226; Windows Update: <A HREF="http://windowsupdate.microsoft.com/"><u>Windows Update</u></a><br><br>         &#8226; If you have Word, Excel, Outlook or other Office programs installed. Consider using Microsoft Update instead of Windows Update. See the FAQ page here for more information: <br><A HREF="http://update.microsoft.com/microsoftupdate/v6/default.aspx?ln=en-us"><u>Microsoft Update</u></a><br>         </ul><br>&#8226;Also, download and install Microsoft Baseline Analyzer.(Note that MBSA is only for Win 2000 SP3 or later and Office XP or later) When run, it will check system for security exposures, including missing updates. I suggest running it weekly. You can obtain more information here: <A HREF="http://www.microsoft.com/technet/security/tools/mbsahome.mspx"><u>MS Baseline Analyzer</u></a><br><br>&#8226; Adjust your security settings for ActiveX:<br>Select Internet Options from the Control Panels, or from Internet Explorer (Tools -> Internet Options)<br>Press 'default level', then OK<br>Now press "Custom Level."<br>     <ul><br>     &#8226;In the ActiveX controls and plug-ins section set these options:<br>'Download signed ActiveX controls' - Prompt<br>'Download unsigned ActiveX controls' - Disable<br>'Initialize and script ActiveX controls not maked as safe'- Disable<br>All other options accept the default<br>     </ul>     <br>&#8226; For Windows XP2 SP2 users, check this link for additional steps you can take to secure Internet Explorer:  <A HREF="http://www.microsoft.com/technet/security/smallbusiness/prodtech/windowsxp/iesecxp.mspx"><u>Securing IE in Windows XP SP 2</u></a><br><br>&#8226;Also,for Sp2 SP2 and IE users, in IE, Tools -> Manage Add-ons will give you a list of all BHO's, Extensions, and ActiveX modules installed on your computer. You can update, enable or disable them.<br>&#8226; Download and install the following free programs<br>     <ul><br>     &#8226; <A HREF="http://www.javacoolsoftware.com/spywareblaster.html"><u>SpywareBlaster</u></a> <br>     &#8226; <A HREF="http://www.spywarewarrior.com/uiuc/main.htm"><u>IESpyad</u></a><br>     &#8226; and while you are getting IEspyad you should look at Enough is Enough as well<br>     </ul><br><br>&#8226; Install Spyware Detection and Removal Programs:<br>You may also want to consider installing one (or all) of the following:<br>     <ul><br>     &#8226; <A HREF="http://www.microsoft.com/athome/security/spyware/software/default.mspx"><u>Windows Defender</u></a><br>NOTE: Windows Defender only runs on Windows 2000, XP, and 2003.<br>     &#8226;<A HREF="http://security.kolla.de/index.php?lang=en&page=download"><u>Spybot S&D</u></a><br>     &#8226;<A HREF="http://www.nsclean.com/index.html">BOClean</a><br>     </ul><br><br>&#8226;Use these programs to regularly scan your system for and remove many forms of spyware/malware. I recommend a combination of Windows Defender and BOClean from Comodo.<br><br>&#8226; Install <A HREF="http://www.corestreet.com/spoofstick"><u>'Spoofstick"</u></a><br>Spoofstick is a simple browser extension that helps users detect spoofed (fake) websites. This extension is free and installs in Internet Explorer and Mozilla Firefox.<br><br>&#8226; Reset System Restore<br>If you are using Windows ME or Windows XP, please reset your System Restore. See Windows help for information.<b>You should do this now</b><br><br>&#8226; Clean Temporary Files and Folders<br>Download and install the disk cleanup utility called <A HREF="http://cleanup.stevengould.org"><u>Cleanup!</u></a><br>     <ul><br>     &#8226;Cleanup! will get rid of any malware which may be hiding in your temp folders (a common hiding place). You may also regain a massive amount of disk space.<br>Here is a <A HREF="http://www.bleepingcomputer.com/forums/tutorial93.html"><u>tutorial</u></a> which describes its usage:<br>     &#8226;Run the disk cleanup utility called Cleanup! that you have already downloaded and installed<br>Check the custom settings to your liking under options, but be sure to delete temporary files and temporary internet files for all user profiles. Also, cleanout the prefetch folder and the recycle bin.<br>Then reboot into normal mode to let it clean out the remaining files,  I also like  <A HREF="http://www.ccleaner.com"><u>Ccleaner</u></a> for the same purposes.<br>     </ul>    <br>&#8226;If you use, or plan on using, additional spyware/malware detection and/or removal programs, please check the following two Items.<br><br>&#8226; <A HREF="http://www.spywarewarrior.com/rogue_anti-spyware.htm"><u>Rogue/Suspect Anti-Spyware</u></a><br>Before using or purchasing any Spyware/Malware protection/removal program, always check the Rogue/Suspect Spyware List. It will save you a lot of grief, as well as money if you are thinking of purchasing.<br><br>&#8226; <A HREF="http://www.spywarewarrior.com/asw-test-guide.htm"><u>Anti-Spyware Programs Compared</u></a><br>Want to know just how effective your anti-spyware program is? Wonder how well any of the "rogue" programs listed above work?  <br><br>&#8226;Alternate Browser<br>Consider using an alternate browser as your default. I recommend and use <A HREF="http://www.mozilla.com"><u>Firefox</u></a> as my primary browser another excellent choice is <A HREF="http://www.opera.com"><u>Opera</u></a>. It is still necessary to keep Internet Explorer current and protected in order to use Windows Update.<br></ol><br><br>For more information about Spyware, the tools available, and other informative material, including information on how you may have been infected in the first place, please check out <A HREF="http://www.dslreports.com/faq/13620"><u>This faq at DSLreports</u></a><br><br>"In the end It is your responsibility to read and adhere to the End User Licensing Agreement (EULA) of all software and services mentioned." This is especially true of the rogue or suspect ones.. Sometimes these Eulas will even admit the badware is going to be installed.. You really should read these carefully.<br><br>Good luck, and thanks for coming to our forums for help with your security and malware issues.<br><small>--<br>da Cajun  Darn I hate Malware</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20306688</guid>
<pubDate>Wed, 09 Apr 2008 06:51:25 EDT</pubDate>
</item>

<item>
<title>Re: [Vundo] Vundo Removal</title>
<link>http://www.dslreports.com/forum/remark,20306050</link>
<description><![CDATA[<A HREF="/useremail/u/727524"><b>fatheadx</b></A> : Java is now updated.  Thanks again for getting me out of this mess!  Here is the HijackThis log:<br><br>Logfile of Trend Micro HijackThis v2.0.2<br>Scan saved at 22:09, on 2008-04-08<br>Platform: Windows XP SP2 (WinNT 5.01.2600)<br>MSIE: Internet Explorer v7.00 (7.00.6000.16608)<br>Boot mode: Normal<br><br>Running processes:<br>C:\WINDOWS\System32\smss.exe<br>C:\WINDOWS\system32\winlogon.exe<br>C:\WINDOWS\system32\services.exe<br>C:\WINDOWS\system32\lsass.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\Program Files\Windows Defender\MsMpEng.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\Program Files\Intel\Wireless\Bin\EvtEng.exe<br>C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe<br>C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe<br>C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe<br>C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe<br>C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe<br>C:\WINDOWS\system32\spoolsv.exe<br>C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br>C:\Program Files\Symantec AntiVirus\DefWatch.exe<br>C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE<br>C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe<br>C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe<br>C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe<br>C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe<br>C:\Program Files\Dell\QuickSet\quickset.exe<br>C:\Program Files\Common Files\Symantec Shared\ccApp.exe<br>C:\Program Files\HP\hpcoretech\hpcmpmgr.exe<br>C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe<br>C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe<br>C:\Program Files\HP\HP Software Update\HPWuSchd2.exe<br>C:\Program Files\Windows Defender\MSASCui.exe<br>C:\Program Files\QuickTime\qttask.exe<br>C:\Program Files\iTunes\iTunesHelper.exe<br>C:\WINDOWS\system32\ctfmon.exe<br>C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe<br>C:\Program Files\Digital Line Detect\DLG.exe<br>C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe<br>C:\Program Files\iPod\bin\iPodService.exe<br>C:\WINDOWS\explorer.exe<br>C:\Documents and Settings\ebopp\Desktop\HiJackThis.exe<br>C:\WINDOWS\system32\msiexec.exe<br><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=69157" >go.microsoft.com/fwlink/?LinkId=69157</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=69157" >go.microsoft.com/fwlink/?LinkId=69157</A><br>O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll<br>O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll<br>O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll<br>O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar5.dll<br>O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll<br>O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\Program Files\BAE\BAE.dll<br>O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar5.dll<br>O4 - HKLM\..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless<br>O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe<br>O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"<br>O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"<br>O4 - HKLM\..\Run: [DXDllRegExe] dxdllreg.exe<br>O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"<br>O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup<br>O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe<br>O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide<br>O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime<br>O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"<br>O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"<br>O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br>O4 - HKCU\..\Run: [GoldMinerSESetup.exe] C:\DOWNLO~1\GOLDMI~1.EXE /r<br>O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe<br>O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')<br>O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')<br>O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe<br>O4 - Global Startup: Digital Line Detect.lnk = ?<br>O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000<br>O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll<br>O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll<br>O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL<br>O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br>O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br>O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - &raquo;<A HREF="http://a1540.g.akamai.net/7/1540/52/20070501/qtinstall.info.apple.com/qtactivex/qtplugin.cab" >a1540.g.akamai.net/7/1540/52/200&middot;&middot;&middot;ugin.cab</A><br>O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - &raquo;<A HREF="http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB" >www.pcpitstop.com/pcpitstop/PCPitStop.CAB</A><br>O16 - DPF: {1842B0EE-B597-11D4-8997-00104BD12D94} (iCC Class) - &raquo;<A HREF="http://www.pcpitstop.com/internet/pcpConnCheck.cab" >www.pcpitstop.com/internet/pcpConnCheck.cab</A><br>O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - &raquo;<A HREF="http://sdlc-esd.sun.com/ESD39/JSCDL/jdk/6u5b/jinstall-6u5-windows-i586-jc.cab?AuthParam=1207713777_353d15dc7cd59b5b3f07220385ee438d&GroupName=JSC&BHost=javadl.sun.com&FilePath=/ESD39/JSCDL/jdk/6u5b/jinstall-6u5-windows-i586-jc.cab&File=jinstall-6u5-windows-i586-jc.cab" >sdlc-esd.sun.com/ESD39/JSCDL/jdk&middot;&middot;&middot;6-jc.cab</A><br>O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = pfeiffer-vacuum.com<br>O17 - HKLM\Software\..\Telephony: DomainName = pfeiffer-vacuum.com<br>O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = pfeiffer-vacuum.com<br>O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL<br>O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe<br>O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br>O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe<br>O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe<br>O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe<br>O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe<br>O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe<br>O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe<br>O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br>O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe<br>O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br>O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe<br>O23 - Service: OpcEnum - OPC Foundation - C:\WINDOWS\system32\OpcEnum.exe<br>O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe<br>O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe<br>O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation  - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe<br>O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe<br>O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe<br>O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe<br>O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe<br>O23 - Service: WLANKEEPER - Intel&reg; Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe<br><br>--<br>End of file - 9665 bytes]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20306050</guid>
<pubDate>Wed, 09 Apr 2008 00:09:50 EDT</pubDate>
</item>

<item>
<title>Re: [Vundo] Vundo Removal</title>
<link>http://www.dslreports.com/forum/remark,20305524</link>
<description><![CDATA[<A HREF="/useremail/u/855835"><b>CajunTek</b></A> : Run hijackthis again, select scan only, place a check next to these two lines, close all browser windows and click on fix.<br><br>O2 - BHO: (no name) - {0E7F99D0-67F9-44E8-8568-7FCEE6FEC837} - C:\WINDOWS\system32\awvvv.dll (file missing)<br>O20 - Winlogon Notify: fccyyay - fccyyay.dll (file missing)<br><br>Reboot<br><br>Note: One of the reasons you got this is the very old very vulnerable version of java you have.. <br>Remove that version of java, then visit &raquo;<A HREF="http://java.com" >java.com</A> and download the latest version there.<br>See here (at the bottom) &raquo;<A HREF="/faq/seclean">Security Cleanup FAQ</A> &raquo;<A HREF="/faq/13619">Trojan Vundo/Virtumonde/Winfixer Removal</A><br><br>Post one more log]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20305524</guid>
<pubDate>Tue, 08 Apr 2008 22:22:34 EDT</pubDate>
</item>

<item>
<title>Re: [Vundo] Vundo Removal</title>
<link>http://www.dslreports.com/forum/remark,20305415</link>
<description><![CDATA[<A HREF="/useremail/u/727524"><b>fatheadx</b></A> : Thank you for the help!  Here is the ComboFix log and HiJackThis log:<br><br>____________________________________________________________<br>ComboFix 08-04-08.7 - ebopp 2008-04-08 18:50:00.1 - NTFSx86<br>Microsoft Windows XP Professional  5.1.2600.2.1252.1.1033.18.192 [GMT -6:00]<br>Running from: C:\Documents and Settings\ebopp\Desktop\ComboFix.exe<br>.<br><br>(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br><br>C:\Documents and Settings\ebopp\Application Data\SMANTE~1<br>C:\Documents and Settings\ebopp\Application Data\SMANTE~1\S?mantec\<br>C:\Program Files\JavaCore<br>C:\Temp\gbRve12<br>C:\WINDOWS\BM8bc50ae1.xml<br>C:\WINDOWS\cookies.ini<br>C:\WINDOWS\pskt.ini<br>C:\WINDOWS\system32\ddwrpgqt.dll<br>C:\WINDOWS\system32\marxpwsv.dll<br>C:\WINDOWS\system32\mcrh.tmp<br>C:\WINDOWS\system32\pac.txt<br>C:\WINDOWS\system32\stem~1<br>C:\WINDOWS\system32\uhyxxojh.dll<br>C:\WINDOWS\system32\vswpxram.ini<br>C:\WINDOWS\system32\xwjxurqy.dll<br><br>.<br>(((((((((((((((((((((((((((((((((((((((   Drivers/Services   )))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br><br>-------\Legacy_NETWORK_MONITOR<br><br>(((((((((((((((((((((((((   Files Created from 2008-03-09 to 2008-04-09  )))))))))))))))))))))))))))))))<br>.<br><br>2008-04-07 13:01 . 2008-04-07 13:16&#9;&#9;d--------&#9;C:\VundoFix Backups<br>2008-04-05 17:47 . 2008-04-05 17:48&#9;&#9;d--------&#9;C:\Program Files\National Pastime Almanac 1876-2007<br>2008-04-05 17:47 . 2008-04-05 17:47&#9;249,856&#9;---------&#9;C:\WINDOWS\Setup1.exe<br>2008-04-05 17:47 . 2008-04-05 17:47&#9;73,216&#9;--a------&#9;C:\WINDOWS\ST6UNST.EXE<br>2008-04-04 09:21 . 2008-04-04 09:21&#9;104,972&#9;--a------&#9;C:\PVIQ11065 nrel choi tpu 1201.pdf<br>2008-04-04 08:57 . 2008-04-04 08:57&#9;1,158&#9;--a------&#9;C:\WINDOWS\mozver.dat<br>2008-04-04 08:49 . 2008-04-05 10:56&#9;1,467,093&#9;---hs----&#9;C:\WINDOWS\system32\mfrnbwws.ini<br>2008-04-03 09:21 . 2008-04-03 09:21&#9;0&#9;--a------&#9;C:\WINDOWS\nsreg.dat<br>2008-04-03 08:45 . 2008-04-04 08:46&#9;1,923,474&#9;---hs----&#9;C:\WINDOWS\system32\xayepfcx.ini<br>2008-04-02 08:47 . 2008-04-03 08:30&#9;1,625,053&#9;---hs----&#9;C:\WINDOWS\system32\ebwbgoxf.ini<br>2008-04-02 08:45 . 2008-04-06 07:22&#9;0&#9;--a------&#9;C:\WINDOWS\system32\thdcroue.dll<br>2008-04-02 08:26 . 2008-04-02 08:26&#9;104,184&#9;--a------&#9;C:\PVIQ10961 sandia 422.pdf<br>2008-04-01 08:53 . 2008-04-01 12:45&#9;1,593,796&#9;---hs----&#9;C:\WINDOWS\system32\tbiyspyd.ini<br>2008-04-01 08:47 . 2008-04-06 07:21&#9;0&#9;--a------&#9;C:\WINDOWS\system32\pbbtopoq.dll<br>2008-04-01 08:44 . 2008-04-06 07:21&#9;0&#9;--a------&#9;C:\WINDOWS\system32\qjhmayhw.dll<br>2008-03-31 08:44 . 2008-04-01 08:36&#9;1,594,668&#9;---hs----&#9;C:\WINDOWS\system32\sxwwnstr.ini<br>2008-03-28 22:18 . 2008-03-28 22:18&#9;&#9;d--hs----&#9;C:\Documents and Settings\LocalService\UserData<br>2008-03-28 18:31 . 2008-03-28 21:35&#9;0&#9;--a------&#9;C:\WINDOWS\system32\yaywuus.dll<br>2008-03-28 18:27 . 2008-03-28 18:32&#9;&#9;d--------&#9;C:\WINDOWS\system32\aqVreo01<br>2008-03-28 18:27 . 2008-04-08 18:50&#9;&#9;d--------&#9;C:\Temp<br>2008-03-26 08:55 . 2008-03-26 08:55&#9;33,187&#9;--a------&#9;C:\trunca email contacts 0308.pdf<br>2008-03-24 09:59 . 2008-03-24 09:59&#9;6,820&#9;--a------&#9;C:\lead nist grossman cube 0308.pdf<br>2008-03-24 09:58 . 2008-03-24 09:58&#9;6,892&#9;--a------&#9;C:\lead nist grossman tcp 0308.pdf<br>2008-03-19 13:11 . 2008-03-19 13:11&#9;29,696&#9;--a------&#9;C:\pChem Turbo Pump Cables 0308.doc<br>2008-03-17 15:34 . 2008-03-17 15:34&#9;62,060&#9;--a------&#9;C:\lead sic robbins feedthru 0308.pdf<br>2008-03-17 15:11 . 2008-03-17 15:11&#9;62,001&#9;--a------&#9;C:\lead itn gomez gauge 0308.pdf<br>2008-03-17 09:27 . 2008-03-17 09:27&#9;106,830&#9;--a------&#9;C:\PVIQ10816 sundew sneh okta duo.pdf<br>2008-03-17 08:55 . 2008-03-17 12:01&#9;&#9;d--------&#9;C:\pchem 0308<br>2008-03-14 15:12 . 2008-03-14 15:13&#9;23,643&#9;--a------&#9;C:\email sundew sneh quote 0308.pdf<br>2008-03-13 11:12 . 2008-03-13 11:12&#9;99,121&#9;--a------&#9;C:\PVIQ10688 pernicka usbrs485 rev.pdf<br>2008-03-13 10:30 . 2008-03-13 10:30&#9;100,381&#9;--a------&#9;C:\PVIQ9506 lanl weinberg tsu 071e.pdf<br>2008-03-13 07:58 . 2008-03-13 07:56&#9;41,984&#9;--a------&#9;C:\Copy of Blank Expense Report Form 02 04 08.xls<br>2008-03-12 13:10 . 2008-03-12 13:10&#9;124,416&#9;--a------&#9;C:\PR #62384 Reps and Certs.doc<br>2008-03-11 02:28 . 2008-03-11 02:28&#9;22,243&#9;--a------&#9;C:\Certificate_HiPace_training_EricBopp.pdf<br>2008-03-10 11:58 . 2008-03-10 11:58&#9;104,538&#9;--a------&#9;C:\pviq10727.pdf<br>2008-03-10 08:48 . 2008-03-10 08:48&#9;61,847&#9;--a------&#9;C:\lead nist bickman tmu 071 0308.pdf<br><br>.<br>((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br>2008-04-09 00:35&#9;---------&#9;d-----w&#9;C:\Program Files\Symantec AntiVirus<br>.<br><br>(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br>.<br>*Note* empty entries & legit default entries are not shown <br>REGEDIT4<br><br>[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0E7F99D0-67F9-44E8-8568-7FCEE6FEC837}]<br>&#9;&#9;&#9;C:\WINDOWS\system32\awvvv.dll<br><br>[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<br>"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 04:00 15360]<br>"GoldMinerSESetup.exe"="C:\DOWNLO~1\GOLDMI~1.exe" [ ]<br>"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-20 09:33 68856]<br><br>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<br>"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2004-10-30 13:59 385024]<br>"Dell QuickSet"="C:\Program Files\Dell\QuickSet\quickset.exe" [2005-12-15 09:44 839680]<br>"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2005-04-08 15:52 48752]<br>"HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [2005-01-12 15:54 241664]<br>"DXDllRegExe"="dxdllreg.exe" []<br>"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-06 23:46 57344]<br>"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2007-08-07 12:47 1836544]<br>"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2005-02-16 23:11 49152]<br>"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 19:20 866584]<br>"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-04-27 09:41 282624]<br>"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-06-28 09:14 270648]<br><br>[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]<br>"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 16:38 39264]<br><br>C:\Documents and Settings\All Users\Start Menu\Programs\Startup\<br>Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 23:05:26 29696]<br>Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2006-04-14 02:29:13 24576]<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\fccyyay]<br>fccyyay.dll<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless]<br>C:\Program Files\Intel\Wireless\Bin\LgNotify.dll 2004-09-07 15:08 110592 C:\Program Files\Intel\Wireless\Bin\LgNotify.dll<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]<br>"AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]<br>"DisableMonitoring"=dword:00000001<br><br>[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]<br>"%windir%\\system32\\sessmgr.exe"=<br>"C:\\WINDOWS\\system32\\mshta.exe"=<br>"C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE"=<br>"%windir%\\Network Diagnostic\\xpnetdiag.exe"=<br>"C:\\Program Files\\QUADERA\\Quadera.exe"=<br>"C:\\Program Files\\iTunes\\iTunes.exe"=<br><br>[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]<br>"135:TCP"= 135:TCP:DCOM<br>"23269:UDP"= 23269:UDP:QMG Detection<br><br>[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]<br>\Shell\AutoRun\command - rundll32.exe url.dll,FileProtocolHandler LapNetWizard.exe<br><br>[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{281c9246-6a84-11db-8710-00166f6b07cc}]<br>\Shell\AutoRun\command - rundll32.exe url.dll,FileProtocolHandler LapNetWizard.exe<br><br>[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a8fe6767-a9b8-11dc-8746-00166f6b07cc}]<br>\Shell\AutoRun\command - E:\wd_windows_tools\setup.exe<br><br>[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{cd36c517-fe3f-11db-8730-00166f6b07cc}]<br>\Shell\AutoRun\command - rundll32.exe url.dll,FileProtocolHandler LapNetWizard.exe<br><br>[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d7f2a564-76c8-11dc-8742-00166f6b07cc}]<br>\Shell\AutoRun\command - E:\LapNetWizard.exe<br><br>.<br>Contents of the 'Scheduled Tasks' folder<br>"2008-03-26 17:38:03 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"<br>- C:\Program Files\Apple Software Update\SoftwareUpdate.exe<br>"2008-04-09 01:38:11 C:\WINDOWS\Tasks\MP Scheduled Scan.job"<br>- C:\Program Files\Windows Defender\MpCmdRun.exe<br>.<br>**************************************************************************<br><br>catchme 0.3.1351 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, &raquo;<A HREF="http://www.gmer.net" >www.gmer.net</A><br>Rootkit scan 2008-04-08 19:46:17<br>Windows 5.1.2600 Service Pack 2 NTFS<br><br>scanning hidden processes ... <br><br>scanning hidden autostart entries ...<br><br>scanning hidden files ... <br><br>scan completed successfully <br>hidden files: 0 <br><br>**************************************************************************<br>.<br>------------------------ Other Running Processes ------------------------<br>.<br>C:\Program Files\Windows Defender\MsMpEng.exe<br>C:\Program Files\Intel\Wireless\Bin\EvtEng.exe<br>C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe<br>C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe<br>C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe<br>C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe<br>C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe<br>C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br>C:\Program Files\Symantec AntiVirus\DefWatch.exe<br>C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE<br>C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe<br>C:\WINDOWS\system32\HPZipm12.exe<br>C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe<br>C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe<br>C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe<br>C:\Program Files\iPod\bin\iPodService.exe<br>.<br>**************************************************************************<br>.<br>Completion time: 2008-04-08 19:48:49 - machine was rebooted<br>ComboFix-quarantined-files.txt  2008-04-09 01:48:45<br>Pre-Run: 41,981,128,704 bytes free<br>Post-Run: 41,906,843,648 bytes free<br>.<br>2008-04-06 13:24:10&#9;--- E O F ---  <br>____________________________________________________________<br>Logfile of Trend Micro HijackThis v2.0.2<br>Scan saved at 19:56, on 2008-04-08<br>Platform: Windows XP SP2 (WinNT 5.01.2600)<br>MSIE: Internet Explorer v7.00 (7.00.6000.16608)<br>Boot mode: Normal<br><br>Running processes:<br>C:\WINDOWS\System32\smss.exe<br>C:\WINDOWS\system32\winlogon.exe<br>C:\WINDOWS\system32\services.exe<br>C:\WINDOWS\system32\lsass.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\Program Files\Windows Defender\MsMpEng.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\Program Files\Intel\Wireless\Bin\EvtEng.exe<br>C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe<br>C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe<br>C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe<br>C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe<br>C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe<br>C:\WINDOWS\system32\spoolsv.exe<br>C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br>C:\Program Files\Symantec AntiVirus\DefWatch.exe<br>C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE<br>C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe<br>C:\WINDOWS\system32\HPZipm12.exe<br>C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe<br>C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe<br>C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe<br>C:\Program Files\Dell\QuickSet\quickset.exe<br>C:\Program Files\Common Files\Symantec Shared\ccApp.exe<br>C:\Program Files\HP\hpcoretech\hpcmpmgr.exe<br>C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe<br>C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe<br>C:\Program Files\HP\HP Software Update\HPWuSchd2.exe<br>C:\Program Files\Windows Defender\MSASCui.exe<br>C:\Program Files\QuickTime\qttask.exe<br>C:\Program Files\iTunes\iTunesHelper.exe<br>C:\WINDOWS\system32\ctfmon.exe<br>C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe<br>C:\Program Files\Digital Line Detect\DLG.exe<br>C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe<br>C:\Program Files\iPod\bin\iPodService.exe<br>C:\WINDOWS\explorer.exe<br>C:\Documents and Settings\ebopp\Desktop\HiJackThis.exe<br><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=69157" >go.microsoft.com/fwlink/?LinkId=69157</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=69157" >go.microsoft.com/fwlink/?LinkId=69157</A><br>O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll<br>O2 - BHO: (no name) - {0E7F99D0-67F9-44E8-8568-7FCEE6FEC837} - C:\WINDOWS\system32\awvvv.dll (file missing)<br>O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll<br>O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar5.dll<br>O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll<br>O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\Program Files\BAE\BAE.dll<br>O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar5.dll<br>O4 - HKLM\..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless<br>O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe<br>O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"<br>O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"<br>O4 - HKLM\..\Run: [DXDllRegExe] dxdllreg.exe<br>O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"<br>O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup<br>O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe<br>O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide<br>O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime<br>O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"<br>O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br>O4 - HKCU\..\Run: [GoldMinerSESetup.exe] C:\DOWNLO~1\GOLDMI~1.EXE /r<br>O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe<br>O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')<br>O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')<br>O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe<br>O4 - Global Startup: Digital Line Detect.lnk = ?<br>O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000<br>O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll<br>O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll<br>O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL<br>O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br>O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br>O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - &raquo;<A HREF="http://a1540.g.akamai.net/7/1540/52/20070501/qtinstall.info.apple.com/qtactivex/qtplugin.cab" >a1540.g.akamai.net/7/1540/52/200&middot;&middot;&middot;ugin.cab</A><br>O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - &raquo;<A HREF="http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB" >www.pcpitstop.com/pcpitstop/PCPitStop.CAB</A><br>O16 - DPF: {1842B0EE-B597-11D4-8997-00104BD12D94} (iCC Class) - &raquo;<A HREF="http://www.pcpitstop.com/internet/pcpConnCheck.cab" >www.pcpitstop.com/internet/pcpConnCheck.cab</A><br>O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = pfeiffer-vacuum.com<br>O17 - HKLM\Software\..\Telephony: DomainName = pfeiffer-vacuum.com<br>O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = pfeiffer-vacuum.com<br>O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL<br>O20 - Winlogon Notify: fccyyay - fccyyay.dll (file missing)<br>O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe<br>O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br>O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe<br>O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe<br>O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe<br>O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe<br>O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe<br>O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe<br>O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br>O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe<br>O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br>O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe<br>O23 - Service: OpcEnum - OPC Foundation - C:\WINDOWS\system32\OpcEnum.exe<br>O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe<br>O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe<br>O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation  - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe<br>O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe<br>O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe<br>O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe<br>O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe<br>O23 - Service: WLANKEEPER - Intel&reg; Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe<br><br>--<br>End of file - 9291 bytes]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20305415</guid>
<pubDate>Tue, 08 Apr 2008 22:03:07 EDT</pubDate>
</item>

<item>
<title>Re: [Vundo] Vundo Removal</title>
<link>http://www.dslreports.com/forum/remark,20304853</link>
<description><![CDATA[<A HREF="/useremail/u/855835"><b>CajunTek</b></A> : Let's use another tool:<br><br>Download Combofix from any of the links below, and save it to your desktop. For information regarding this download, please visit this webpage:<br>&raquo;<A HREF="http://www.bleepingcomputer.com/combofix/how-to-use-combofix" >www.bleepingcomputer.com/combofi&middot;&middot;&middot;combofix</A><br><br>Note: It is important that it is saved directly to your desktop<br><textarea name="code" class="text" cols=50 rows=10>http://download.bleepingcomputer.com/sUBs/ComboFix.exe&#012;http://www.forospyware.com/sUBs/ComboFix.exe&#012;http://subs.geekstogo.com/ComboFix.exe&#012;</textarea><!--end code block-->1. Close any open browsers.<br><br>2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.<br><br>Double click on combofix.exe & follow the prompts.<br>When finished, it will produce a report for you.<br>Please post the "C:\ComboFix.txt" along with a new HijackThis log for further review.<br><br><b><u>Note</u>: Do not mouseclick combofix's window while it's running. That may cause it to stall</b><br><br><small>--<br>da Cajun  Darn I hate Malware</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20304853</guid>
<pubDate>Tue, 08 Apr 2008 20:19:57 EDT</pubDate>
</item>

<item>
<title>[Vundo] Vundo Removal</title>
<link>http://www.dslreports.com/forum/remark,20304174</link>
<description><![CDATA[<A HREF="/useremail/u/727524"><b>fatheadx</b></A> : I am infected.  So far, I have run vundofix.exe and hijackthis, logs posted below.<br>___________________________________________________________<br>VundoFix V7.0.3<br><br>Scan started at 1:01:41 PM 4/7/2008<br><br>Listing files found while scanning....<br><br>C:\windows\system32\awvvv.dll<br>C:\WINDOWS\system32\lcpamdfy.dll<br>C:\windows\system32\vvvwa.ini<br>C:\windows\system32\vvvwa.ini2<br>C:\WINDOWS\system32\yfdmapcl.ini<br><br>Beginning removal...<br><br> Attempting to delete C:\windows\system32\awvvv.dll<br>C:\windows\system32\awvvv.dll Has been deleted!<br><br> Attempting to delete C:\WINDOWS\system32\lcpamdfy.dll<br>C:\WINDOWS\system32\lcpamdfy.dll Could not be deleted.<br><br> Attempting to delete C:\windows\system32\vvvwa.ini<br>C:\windows\system32\vvvwa.ini Has been deleted!<br><br> Attempting to delete C:\windows\system32\vvvwa.ini2<br>C:\windows\system32\vvvwa.ini2 Has been deleted!<br><br> Attempting to delete C:\WINDOWS\system32\yfdmapcl.ini<br>C:\WINDOWS\system32\yfdmapcl.ini Has been deleted!<br><br>Performing Repairs to the registry.<br>Done!<br><br>Beginning removal...<br><br> Attempting to delete C:\WINDOWS\system32\lcpamdfy.dll<br>C:\WINDOWS\system32\lcpamdfy.dll Has been deleted!<br><br>Performing Repairs to the registry.<br>Done!<br><br>VundoFix V7.0.3<br><br>Scan started at 1:21:03 PM 4/7/2008<br><br>Listing files found while scanning....<br><br>No infected files were found.<br>____________________________________________________________<br>Logfile of Trend Micro HijackThis v2.0.2<br>Scan saved at 3:53:30 PM, on 4/8/2008<br>Platform: Windows XP SP2 (WinNT 5.01.2600)<br>MSIE: Internet Explorer v7.00 (7.00.6000.16608)<br>Boot mode: Normal<br><br>Running processes:<br>C:\WINDOWS\System32\smss.exe<br>C:\WINDOWS\system32\winlogon.exe<br>C:\WINDOWS\system32\services.exe<br>C:\WINDOWS\system32\lsass.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\Program Files\Windows Defender\MsMpEng.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\Program Files\Intel\Wireless\Bin\EvtEng.exe<br>C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe<br>C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe<br>C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe<br>C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe<br>C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe<br>C:\WINDOWS\system32\spoolsv.exe<br>C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br>C:\Program Files\Symantec AntiVirus\DefWatch.exe<br>C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE<br>C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe<br>C:\WINDOWS\system32\HPZipm12.exe<br>C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\Program Files\Symantec AntiVirus\Rtvscan.exe<br>C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe<br>C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe<br>C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe<br>C:\Program Files\Dell\QuickSet\quickset.exe<br>C:\Program Files\Common Files\Symantec Shared\ccApp.exe<br>C:\PROGRA~1\SYMANT~1\VPTray.exe<br>C:\Program Files\HP\hpcoretech\hpcmpmgr.exe<br>C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe<br>C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe<br>C:\Program Files\HP\HP Software Update\HPWuSchd2.exe<br>C:\Program Files\Windows Defender\MSASCui.exe<br>C:\Program Files\QuickTime\qttask.exe<br>C:\Program Files\iTunes\iTunesHelper.exe<br>C:\WINDOWS\system32\rundll32.exe<br>C:\WINDOWS\system32\ctfmon.exe<br>C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe<br>C:\Program Files\Digital Line Detect\DLG.exe<br>C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe<br>C:\Program Files\iPod\bin\iPodService.exe<br>C:\WINDOWS\explorer.exe<br>C:\Documents and Settings\ebopp\Desktop\HiJackThis.exe<br><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=69157" >go.microsoft.com/fwlink/?LinkId=69157</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=69157" >go.microsoft.com/fwlink/?LinkId=69157</A><br>O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll<br>O2 - BHO: (no name) - {0E7F99D0-67F9-44E8-8568-7FCEE6FEC837} - C:\WINDOWS\system32\awvvv.dll (file missing)<br>O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll<br>O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar5.dll<br>O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll<br>O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\Program Files\BAE\BAE.dll<br>O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar5.dll<br>O4 - HKLM\..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless<br>O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe<br>O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"<br>O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe<br>O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"<br>O4 - HKLM\..\Run: [DXDllRegExe] dxdllreg.exe<br>O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"<br>O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup<br>O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe<br>O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide<br>O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime<br>O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"<br>O4 - HKLM\..\Run: [88f6397d] rundll32.exe "C:\WINDOWS\system32\marxpwsv.dll",b<br>O4 - HKLM\..\Run: [BM8bc50ae1] Rundll32.exe "C:\WINDOWS\system32\xwjxurqy.dll",s<br>O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br>O4 - HKCU\..\Run: [GoldMinerSESetup.exe] C:\DOWNLO~1\GOLDMI~1.EXE /r<br>O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe<br>O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')<br>O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')<br>O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe<br>O4 - Global Startup: Digital Line Detect.lnk = ?<br>O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000<br>O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll<br>O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll<br>O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL<br>O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br>O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br>O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - &raquo;<A HREF="http://a1540.g.akamai.net/7/1540/52/20070501/qtinstall.info.apple.com/qtactivex/qtplugin.cab" >a1540.g.akamai.net/7/1540/52/200&middot;&middot;&middot;ugin.cab</A><br>O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - &raquo;<A HREF="http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB" >www.pcpitstop.com/pcpitstop/PCPitStop.CAB</A><br>O16 - DPF: {1842B0EE-B597-11D4-8997-00104BD12D94} (iCC Class) - &raquo;<A HREF="http://www.pcpitstop.com/internet/pcpConnCheck.cab" >www.pcpitstop.com/internet/pcpConnCheck.cab</A><br>O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = pfeiffer-vacuum.com<br>O17 - HKLM\Software\..\Telephony: DomainName = pfeiffer-vacuum.com<br>O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = pfeiffer-vacuum.com<br>O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL<br>O20 - Winlogon Notify: fccyyay - fccyyay.dll (file missing)<br>O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe<br>O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br>O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe<br>O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe<br>O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe<br>O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe<br>O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe<br>O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe<br>O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br>O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe<br>O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br>O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe<br>O23 - Service: OpcEnum - OPC Foundation - C:\WINDOWS\system32\OpcEnum.exe<br>O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe<br>O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe<br>O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation  - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe<br>O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe<br>O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe<br>O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe<br>O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe<br>O23 - Service: WLANKEEPER - Intel&reg; Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe<br><br>--<br>End of file - 9632 bytes]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20304174</guid>
<pubDate>Tue, 08 Apr 2008 18:02:51 EDT</pubDate>
</item>

</channel>
</rss>
