<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>[Trojan] HJT Log: Having trouble with virus/spyware in Security Cleanup</title>
<link>http://www.dslreports.com/forum/r20337393</link>
<description></description>
<language>en</language>
<pubDate>Tue, 02 Dec 2008 05:12:15 EDT</pubDate>
<lastBuildDate>Tue, 02 Dec 2008 05:12:15 EDT</lastBuildDate>

<item>
<title>Re: [Trojan] HJT Log: Having trouble with virus/spyware</title>
<link>http://www.dslreports.com/forum/remark,20338386</link>
<description><![CDATA[<A HREF="/useremail/u/555588"><b>LoPhatPhuud</b></A> : <b>First:</b><br>Please download ATF Cleaner<br><textarea name="code" class="text" cols=50 rows=10>http://www.atribune.org/ccount/click.php?id=1&#012;</textarea><!--end code block--><br>Double-click <b>ATF-Cleaner.exe</b> to run the program.<br>Under <b>Main</b> choose: <b>Select All</b><br>Click the <b>Empty Selected</b> button.<br></ul>[u]If you use Firefox browser[/u]Click <b>Firefox</b> at the top and choose: <b>Select All</b><br>Click the <b>Empty Selected</b> button.<br><b>NOTE:</b> If you would like to keep your saved passwords, please click <b>No</b> at the prompt.<br></ul>[u]If you use Opera browser[/u]Click <b>Opera</b> at the top and choose: <b>Select All</b><br>Click the <b>Empty Selected</b> button.<br><b>NOTE:</b> If you would like to keep your saved passwords, please click <b>No</b> at the prompt.<br></ul>Click <b>Exit</b> on the Main menu to close the program.<br>For <b>Technical Support</b>, double-click the e-mail address located at the bottom of each menu.<br><br><b>Second:</b><br>Please download MalwareBytes and save it to your Desktop<br><textarea name="code" class="text" cols=50 rows=10>http://www.besttechie.net/tools/mbam-setup.exe&#012;http://malwarebytes.gt500.org/mbam-setup.exe&#012;http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html&#012;</textarea><!--end code block-->[*]Make sure you are connected to the Internet.<br>[*]Double-click on <b>Download_mbam-setup.exe</b> to install the application. <i>(If using Windows Vista, be sure to<br>&raquo;<A HREF="http://windowshelp.microsoft.com/Windows/en-US/Help/fb464905-31d5-4427-89a2-ed5322327fc21033.mspx]Run" >windowshelp.microsoft.com/Window&middot;&middot;&middot;mspx]Run</A> As Administrator<br>[*]When the installation begins, follow the prompts and do not make any changes to default settings.<br>[*]When installation has finished, make sure you leave both of these checked:[list]<br>[*]<b>Update Malwarebytes' Anti-Malware</b><br>[*]<b>Launch Malwarebytes' Anti-Malware</b></ul><br>[*]Then click <b>Finish</b>.<br>[*]MBAM will automatically start and you will be asked to update the program before performing a scan. If an update is found, the program will automatically update itself. Press the <b>OK</b> button to close that box and continue.<br>[*][i][color=green]If you encounter any problems while downloading the updates, manually download them from[/color] <A HREF="http://www.malwarebytes.org/mbam/database/mbam-rules.exe">[COLOR=blue]here[/COLOR]</a> and just double-click on mbam-rules.exe to install.</i><br>[*]On the Scanner tab:<br>[*]Make sure the "<b>Perform Quick Acan</b>" option is selected.<br>[*]Then click on the <b>Scan</b> button.</ul><br>[*]The next screen will ask you to select the drives to scan. Leave [u]all the drives[/u] selected and click on the <b>Start Scan</b> button.<br>[*]The scan will begin and "<i>Scan in progress</i>" will show at the top. It may take some time to complete so please be patient.<br>[*]When the scan is finished, a message box will say "<i>[color=green]The scan completed successfully. Click 'Show Results' to display all objects found[/color]</i>".<br>[*]Click <b>OK</b> to close the message box and continue with the removal process.<br>[*]Back at the main Scanner screen, click on the <b>Show Results</b> button to see a list of any malware that was found.<br>[*]Make sure that <b><i>everything is checked</i></b>, and click <b>Remove Selected</b>.<br>[*]When removal is completed, a log report will open in Notepad and you may be prompted to restart your computer. <i>(see Note below)</i><br>[*]The log is automatically saved and can be viewed by clicking the <b>Logs</b> tab in MBAM.<br>[*]Copy and paste the contents of that report in your next reply and exit MBAM.[/list]<i><b>Note</b>: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.</i><br><br><b>Third:</b><br>Download <b>Combofix</b> from any of the links below, and save it to your desktop.  For information regarding this download, please visit this webpage: &raquo;<A HREF="http://www.bleepingcomputer.com/combofix/how-to-use-combofix" >www.bleepingcomputer.com/combofi&middot;&middot;&middot;combofix</A><br><textarea name="code" class="text" cols=50 rows=10>http://download.bleepingcomputer.com/sUBs/ComboFix.exe&#012;http://www.forospyware.com/sUBs/ComboFix.exe&#012;http://subs.geekstogo.com/ComboFix.exe&#012;</textarea><!--end code block--><br>**Note:  It is important that it is saved directly to your desktop**<br><br>--------------------------------------------------------------------<br><br>1. Close any open browsers.<br><br>2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.<br><br>--------------------------------------------------------------------<br><br>Double click on <b>combofix.exe</b> & follow the prompts.<br>When finished, it will produce a report for you. <br>[*]Please post the <b>"C:\ComboFix.txt" </b>along with a <b>new HijackThis log</b> for further review.</ul><br><br>[color=blue]Note:<br>Do not mouseclick combofix's window while it's running. That may cause it to stall[/color]<br><br><small>--<br>When angry count four; when very angry, swear.<br><br>Microsoft MVP Consumer Security<br><br><A HREF="http://forum.gladiator-antivirus.com">Gladiator Security Forum</a></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20338386</guid>
<pubDate>Tue, 15 Apr 2008 14:49:20 EDT</pubDate>
</item>

<item>
<title>[Trojan] HJT Log: Having trouble with virus/spyware</title>
<link>http://www.dslreports.com/forum/remark,20337393</link>
<description><![CDATA[<A HREF="/useremail/u/1545305"><b>oofgeg</b></A> : I've been having trouble with this computer. It seems like it has spyware and/or a  virus because the symantec antivirus is warning me, plus there are pop ups from spybot. I am currently running both of those scans, but no results so far. This spyware/virus also has changed the background on the computer and added suspicious exe files around the computer that I have tried my best to find and delete. Do you think you can help me from this log?<br><br>Logfile of Trend Micro HijackThis v2.0.2<br>Scan saved at 11:45:24 AM, on 4/15/2008<br>Platform: Windows 2000 SP4 (WinNT 5.00.2195)<br>MSIE: Internet Explorer v5.51 SP1 (5.51.4807.2300)<br>Boot mode: Normal<br><br>Running processes:<br>C:\WINNT\System32\smss.exe<br>C:\WINNT\system32\winlogon.exe<br>C:\WINNT\system32\services.exe<br>C:\WINNT\system32\lsass.exe<br>C:\WINNT\system32\svchost.exe<br>C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe<br>C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe<br>C:\WINNT\system32\spoolsv.exe<br>C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe<br>C:\Program Files\Symantec AntiVirus\DefWatch.exe<br>C:\WINNT\System32\svchost.exe<br>C:\WINNT\System32\svchost.exe<br>C:\WINNT\system32\regsvc.exe<br>C:\Program Files\Symantec AntiVirus\SavRoam.exe<br>C:\WINNT\system32\stisvc.exe<br>C:\Program Files\Symantec AntiVirus\Rtvscan.exe<br>C:\WINNT\System32\WBEM\WinMgmt.exe<br>C:\WINNT\system32\mspmspsv.exe<br>C:\WINNT\System32\SCardSvr.exe<br>C:\WINNT\system32\drivers\spools.exe<br>C:\WINNT\System32\igfxtray.exe<br>C:\WINNT\System32\hkcmd.exe<br>C:\Program Files\Common Files\Logitech\QCDriver\LVCOMS.EXE<br>C:\Program Files\Common Files\Symantec Shared\ccApp.exe<br>C:\PROGRA~1\SYMANT~1\VPTray.exe<br>C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe<br>C:\WINNT\system32\rundll32.exe<br>C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe<br>C:\Program Files\Symantec AntiVirus\VPC32.exe<br>C:\WINNT\explorer.exe<br>C:\WINNT\System32\MsiExec.exe<br>C:\WINNT\explorer.exe<br>C:\Program Files\HiJack.exe<br><br>R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank<br>R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank<br>F2 - REG:system.ini: Shell=Explorer.exe "C:\d.exe"<br>O2 - BHO: (no name) - {53523F59-DDD0-4A81-B85A-F7C2FFBA0DCD} - C:\WINNT\system32\pmnkLbAS.dll (file missing)<br>O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll<br>O2 - BHO: (no name) - {7C109800-A5D5-438F-9640-18D17E168B88} - C:\Program Files\NetProject\sbmdl.dll (file missing)<br>O2 - BHO: (no name) - {8E1BFC0E-8AD2-424D-AC8A-06038481516E} - C:\WINNT\system32\tuvVNDwt.dll<br>O2 - BHO: 403445 helper - {9E654A16-4765-4EAA-94EC-D5A6578053A4} - (no file)<br>O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx<br>O3 - Toolbar: Internet Service - {51D81DD5-55B7-497F-95DB-D356429BB54E} - C:\Program Files\NetProject\wamdl.dll (file missing)<br>O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon<br>O4 - HKLM\..\Run: [IgfxTray] C:\WINNT\System32\igfxtray.exe<br>O4 - HKLM\..\Run: [HotKeysCmds] C:\WINNT\System32\hkcmd.exe<br>O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Common Files\Logitech\QCDriver\LVCOMS.EXE<br>O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime<br>O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"<br>O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe<br>O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot<br>O4 - HKLM\..\Run: [autoload] C:\Documents and Settings\dmanning\cftmon.exe<br>O4 - HKLM\..\Run: [684fa9ee] rundll32.exe "C:\WINNT\system32\lgqgipsk.dll",b<br>O4 - HKLM\..\Run: [ntuser] C:\WINNT\system32\drivers\spools.exe<br>O4 - HKCU\..\Run: [invimthu] C:\WINNT\system32\bgxovizw.exe<br>O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe<br>O4 - HKCU\..\Run: [ntuser] C:\WINNT\system32\drivers\spools.exe<br>O4 - HKCU\..\Run: [autoload] C:\Documents and Settings\dmanning\cftmon.exe<br>O4 - HKLM\..\Policies\Explorer\Run: [FVQUAEwWDY] C:\Documents and Settings\All Users\Application Data\adevwvsx\wneruvsr.exe<br>O4 - HKLM\..\Policies\Explorer\Run: [some] C:\Program Files\NetProject\scit.exe<br>O4 - HKLM\..\Policies\Explorer\Run: [start] C:\Program Files\NetProject\sbmntr.exe<br>O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'Default user')<br>O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\outlook2k\Office\OSA9.EXE<br>O9 - Extra button: (no name) - {9034A523-D068-4BE8-A284-9DF278BE776E} - &raquo;<A HREF="http://www.ieservicegate.com/redirect.php" >www.ieservicegate.com/redirect.php</A> (file missing)<br>O9 - Extra 'Tools' menuitem: IE Anti-Spyware - {9034A523-D068-4BE8-A284-9DF278BE776E} - &raquo;<A HREF="http://www.ieservicegate.com/redirect.php" >www.ieservicegate.com/redirect.php</A> (file missing)<br>O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)<br>O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll<br>O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll<br>O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll<br>O16 - DPF: {15905893-E335-4597-AAA6-406A02886ED6} - &raquo;<A HREF="http://www.bookingplus.com/ishield/DownloadsV3/setup.cab" >www.bookingplus.com/ishield/Down&middot;&middot;&middot;etup.cab</A><br>O16 - DPF: {1A26F07F-0D60-4835-91CF-1E1766A0EC56} (WebInstall Class) - &raquo;<A HREF="http://scanner2.malware-scan.com/setup/webinst.cab" >scanner2.malware-scan.com/setup/webinst.cab</A><br>O16 - DPF: {29EF91B9-7120-477C-A5CB-2D67F2FD088C} (TeleControl Class) - &raquo;<small>https</small>://<A HREF="https://raritan/wrc.cab">raritan/wrc.cab</A><br>O16 - DPF: {2DEF4530-8CE6-41C9-84B6-A54536C90213} (Crystal Report Viewer Control 9) - &raquo;<A HREF="http://208.254.39.208/viewer9/activeXViewer/activexviewer.cab" >208.254.39.208/viewer9/activeXVi&middot;&middot;&middot;ewer.cab</A><br>O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - &raquo;<A HREF="http://a1540.g.akamai.net/7/1540/52/20030530/qtinstall.info.apple.com/bonnie/us/win/QuickTimeInstaller.exe" >a1540.g.akamai.net/7/1540/52/200&middot;&middot;&middot;ller.exe</A><br>O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - &raquo;<A HREF="http://software-dl.real.com/20e9ade643138c21ae06/netzip/RdxIE601.cab" >software-dl.real.com/20e9ade6431&middot;&middot;&middot;E601.cab</A><br>O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - &raquo;<A HREF="http://a1540.g.akamai.net/7/1540/52/20030530/qtinstall.info.apple.com/abarth/us/win/QuickTimeInstaller.exe" >a1540.g.akamai.net/7/1540/52/200&middot;&middot;&middot;ller.exe</A><br>O16 - DPF: {7B2D3FF7-6016-4041-B71B-B0F25EE3EE60} - &raquo;<A HREF="http://208.254.39.202/installshield_staging/ishield/Downloads/setup.cab" >208.254.39.202/installshield_sta&middot;&middot;&middot;etup.cab</A><br>O16 - DPF: {8C875948-9C60-4381-9248-0DF180542D53} - &raquo;<A HREF="http://installs.spamblockerutility.com/installs/spamblockerutility/programs/spamblockerutility.cab" >installs.spamblockerutility.com/&middot;&middot;&middot;lity.cab</A><br>O16 - DPF: {95AEAF20-6005-43A3-BEBC-5CF85776C5BC} - &raquo;<A HREF="http://www.bookingplus.com/Downloads/setup.cab" >www.bookingplus.com/Downloads/setup.cab</A><br>O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = mac.ad<br>O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = mac.ad<br>O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = mac.ad<br>O20 - Winlogon Notify: tuvVNDwt - C:\WINNT\SYSTEM32\tuvVNDwt.dll<br>O22 - SharedTaskScheduler: hemimorphite - {12a31567-9883-4cc0-a684-ad5804394d69} - C:\WINNT\system32\vualf.dll<br>O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe<br>O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe<br>O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe<br>O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe<br>O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe<br>O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe<br>O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe<br>O23 - Service: Task Scheduler (Schedule) - Unknown owner - C:\WINNT\system32\drivers\spools.exe<br>O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe<br>O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe<br><br>--<br>End of file - 7804 bytes]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20337393</guid>
<pubDate>Tue, 15 Apr 2008 12:03:10 EDT</pubDate>
</item>

</channel>
</rss>
