<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Re: Hopefully Clean Now in Security Cleanup</title>
<link>http://www.dslreports.com/forum/r20393587</link>
<description></description>
<language>en</language>
<pubDate>Fri, 29 Aug 2008 23:21:10 EDT</pubDate>
<lastBuildDate>Fri, 29 Aug 2008 23:21:10 EDT</lastBuildDate>

<item>
<title>Re: Hopefully Clean Now</title>
<link>http://www.dslreports.com/forum/remark,20393587</link>
<description><![CDATA[<A HREF="/useremail/u/431519"><b>Anav</b></A> : Thanks worked just fine!]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20393587</guid>
<pubDate>Sun, 27 Apr 2008 00:39:21 EDT</pubDate>
</item>

<item>
<title>Re: Hopefully Clean Now</title>
<link>http://www.dslreports.com/forum/remark,20393250</link>
<description><![CDATA[<A HREF="/useremail/u/693977"><b>bcastner</b></A> : The registry key for regedit entries is correct, and no changes are required.  Trojan Remover is in error.<br><br>1. Click Start, click Run, and enter into the command bar that opens:<br><br>"C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript<br><br>Then do a Ctrl+Shift+Enter to run the command with elevated priviliges.<br><br>2. Open again HijackThis, System scan only, and checkmark this item:<br><br><b>O4 - HKUS\S-1-5-21-3920879651-1156754597-3977887299-1002\..\Run: [BM994decab] Rundll32.exe "C:\Users\CAPTDA~1\AppData\Local\Temp\muxvfknm.dll",s (User 'Capt Dad')</b><br><br>Click <b>Fix checked</b> and exit HijackThis.<br><br><small>--<br><b>============</b><br><b>MS-MVP 2004 - -2008, ASAP Member</b><br><b><i>Users Helping Users</i></b><br><br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20393250</guid>
<pubDate>Sat, 26 Apr 2008 22:48:02 EDT</pubDate>
</item>

<item>
<title>Hopefully Clean Now</title>
<link>http://www.dslreports.com/forum/remark,20393095</link>
<description><![CDATA[<A HREF="/useremail/u/431519"><b>Anav</b></A> : I was suffering from both firefox and IE popups, the kind that say you have a virus and then purport to start scanning the computer.  xponlinescanner in IE and anonymous something  in firefox. I ran both a-squared and avast which noted both a trojan dropper and a downloader and started quaranting and removing.  I followed the advice and also ran a myriad of programs (superantispyware, drwebcure it, malwarebyte program, trojan remover etc...... <br><br>I have just ran the online scanner esit, and nothing showed as well as nothing using windows defender.  <br><br>I still have some issues<br>a. at startup I get an error which is the first jpeg above<br>b. when the trojan remover program starts up it detects a registry issue, second jpg above<br>c. I also note that windows explorer defender jobbie alerts me of programs it blocks at startup.  Not sure when it started doing this but its annoying<br>d. my wireless mouse is jumpy and useless, so using usb MOUSE FOR NOW.<br><br>hijack LOG TO FOLLOW<br>Platform: Windows Vista SP1 (WinNT 6.00.1905)<br>MSIE: Internet Explorer v7.00 (7.00.6001.18000)<br>Boot mode: Normal<br><br>Running processes:<br>C:\Windows\system32\Dwm.exe<br>C:\Windows\system32\taskeng.exe<br>C:\Windows\Explorer.EXE<br>C:\Program Files\Windows Defender\MSASCui.exe<br>C:\hp\support\hpsysdrv.exe<br>C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe<br>C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe<br>C:\Windows\RtHDVCpl.exe<br>C:\Program Files\Alwil Software\Avast4\ashDisp.exe<br>C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe<br>C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe<br>C:\Windows\System32\rundll32.exe<br>C:\Windows\System32\rundll32.exe<br>C:\Program Files\HP\HP Software Update\hpwuSchd2.exe<br>C:\Program Files\Windows Sidebar\sidebar.exe<br>C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe<br>C:\Program Files\Windows Live\Messenger\msnmsgr.exe<br>C:\Windows\ehome\ehtray.exe<br>C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe<br>C:\Program Files\Windows Media Player\wmpnscfg.exe<br>C:\Program Files\NDAS\System\ndasmgmt.exe<br>C:\hp\kbd\kbd.exe<br>C:\Windows\system32\SearchFilterHost.exe<br>C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br><br>R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = <br>R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = <br>R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = <br>O1 - Hosts: ::1 localhost<br>O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll<br>O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll<br>O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll<br>O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)<br>O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br>O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide<br>O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe<br>O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KbdStub.EXE<br>O4 - HKLM\..\Run: [OsdMaestro] "C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe"<br>O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"<br>O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe<br>O4 - HKLM\..\Run: [CCUTRAYICON] FactoryMode<br>O4 - HKLM\..\Run: [SnapfishMediaDetector] C:\Program Files\Snapfish Media Detector\SnapfishMediaDetector.exe<br>O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe<br>O4 - HKLM\..\Run: [CloneCDTray] "C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" /s<br>O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"<br>O4 - HKLM\..\Run: [Start WingMan Profiler] C:\Program Files\Logitech\Gaming Software\LWEMon.exe /noui<br>O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"<br>O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"<br>O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"<br>O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime<br>O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart<br>O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup<br>O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit<br>O4 - HKLM\..\Run: [SansaDispatch] C:\Program Files\SanDisk\Sansa Updater\SansaDispatch.exe<br>O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe<br>O4 - HKLM\..\Run: [Malwarebytes Anti-Malware Reboot] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript<br>O4 - HKLM\..\Run: [TrojanScanner] C:\Program Files\Trojan Remover\Trjscan.exe<br>O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe<br>O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun<br>O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter<br>O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe<br>O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020<br>O4 - HKCU\..\Run: [CTSyncU.exe] "C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe"<br>O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')<br>O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')<br>O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')<br>O4 - HKUS\S-1-5-21-3920879651-1156754597-3977887299-1002\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun (User 'Capt Dad')<br>O4 - HKUS\S-1-5-21-3920879651-1156754597-3977887299-1002\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe (User 'Capt Dad')<br>O4 - HKUS\S-1-5-21-3920879651-1156754597-3977887299-1002\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020 (User 'Capt Dad')<br>O4 - HKUS\S-1-5-21-3920879651-1156754597-3977887299-1002\..\Run: [CTSyncU.exe] "C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe" (User 'Capt Dad')<br>O4 - HKUS\S-1-5-21-3920879651-1156754597-3977887299-1002\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe (User 'Capt Dad')<br>O4 - HKUS\S-1-5-21-3920879651-1156754597-3977887299-1002\..\Run: [BM994decab] Rundll32.exe "C:\Users\CAPTDA~1\AppData\Local\Temp\muxvfknm.dll",s (User 'Capt Dad')<br>O4 - Global Startup: NDAS Device Management.lnk = C:\Program Files\NDAS\System\ndasmgmt.exe<br>O4 - Global Startup: Snapfish Media Detector.lnk = C:\Program Files\Snapfish Media Detector\SnapfishMediaDetector.exe<br>O8 - Extra context menu item: Download All Files by HiDownload - C:\Program Files\HiDownload\HDGetAll.htm<br>O8 - Extra context menu item: Download by HiDownload - C:\Program Files\HiDownload\HDGet.htm<br>O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000<br>O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll<br>O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll<br>O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll<br>O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe (file missing)<br>O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe (file missing)<br>O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL<br>O9 - Extra button: HiDownload - {F4FBA929-A891-492C-A0F6-5C79CC4F1742} - C:\Program Files\HiDownload\hidownload.exe (file missing) (HKCU)<br>O13 - Gopher Prefix: <br>O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL<br>O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll<br>O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe<br>O23 - Service: Intel(R) Alert Service (AlertService) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\CCU\AlertService.exe<br>O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe<br>O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe<br>O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe<br>O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe<br>O23 - Service: DQLWinService - Unknown owner - C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe<br>O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe<br>O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe<br>O23 - Service: Intel DH Service (IntelDHSvcConf) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Tools\IntelDHSvcConf.exe<br>O23 - Service: Intel(R) Software Services Manager (ISSM) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\ISSM.exe<br>O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe<br>O23 - Service: Intel(R) Viiv(TM) Media Server (M1 Server) - Unknown owner - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe<br>O23 - Service: Intel(R) Application Tracker (MCLServiceATL) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\MCLServiceATL.exe<br>O23 - Service: NDAS Service (ndassvc) - XIMETA, Inc. - C:\Program Files\NDAS\System\ndassvc.exe<br>O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe<br>O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe<br>O23 - Service: Intel(R) Remoting Service (Remote UI Service) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe<br>O23 - Service: RoxMediaDB9 - Sonic Solutions - c:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe<br>O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe<br>O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\Windows\System32\ZoneLabs\vsmon.exe<br>O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe<br><br>--<br>End of file - 10543 bytes<br><small>--<br>Ain't nuthin but the blues! "Albert Collins". <br>Leave your troubles at the door! "Pepe Peregil" De Sevilla.  Just Don't Wifi without WPA, "Yul Brenner"<br><br><A HREF="http://www.llamaworks.ca">LlamaWorks Equipment</a></small><div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/20393095?c=1301483&ret=L2ZvcnVtL3IyMDM5MzU4Ny54bWw%3D"><IMG TITLE="12197 bytes" BORDER=0 WIDTH=511 HEIGHT=175 SRC="/r0/download/1301483~79f20df7e07534f67878e64fe387e18c/error%20block.jpg"></A></TD></TR><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/20393095?c=1301484&ret=L2ZvcnVtL3IyMDM5MzU4Ny54bWw%3D"><IMG class="apic" BORDER=0 TITLE="28412 bytes" WIDTH=600 HEIGHT=353 SRC="/r0/download/1301484.thumb600~a4a6a8477b3c42fdce13391fe8a71905/regremoval.jpg/thumb.jpg" ALT="Click for full size"></A></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20393095</guid>
<pubDate>Sat, 26 Apr 2008 22:06:00 EDT</pubDate>
</item>

</channel>
</rss>
