<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>[Vundo] Vundo removal in Security Cleanup</title>
<link>http://www.dslreports.com/forum/r20428963</link>
<description></description>
<language>en</language>
<pubDate>Sat, 26 Jul 2008 13:28:45 EDT</pubDate>
<lastBuildDate>Sat, 26 Jul 2008 13:28:45 EDT</lastBuildDate>

<item>
<title>Re: [Vundo] Vundo removal</title>
<link>http://www.dslreports.com/forum/remark,20442245</link>
<description><![CDATA[<A HREF="/useremail/u/693977"><b>bcastner</b></A> : No, it is not related.<br>Vundo does not cause "loud beeping noises", and the last thing it wants is for the computer to be shutdown.<br><br>Since this appears to be a new machine running Vista, time to call the tech support folks at the computer manufacturer -- Dell.  It sounds from your description like it is overheating, or there is a RAM failure or some other fairly serious system level hardware issue.<br><br>If you have a Dell diagnostic disk that came with computer, boot with that the next time the problem occurs and test the entire system.  Write down in detail any error messages you might receive, as this will be critical when you talk with Dell.<br><small>--<br><b>============</b><br><b>MS-MVP 2004 - -2008, ASAP Member</b><br><b><i>Users Helping Users</i></b><br><br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20442245</guid>
<pubDate>Tue, 06 May 2008 20:19:30 EDT</pubDate>
</item>

<item>
<title>Re: [Vundo] Vundo removal</title>
<link>http://www.dslreports.com/forum/remark,20441512</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : I still seem to be experiencing some problems with my system. If I have too many things running at once it locks up and I have to switch off and start again. It makes a loud beeping noise and then nothing works. I've never had this problem prior to getting the vundo virus. Is this related and is there anything I can do to fix it?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20441512</guid>
<pubDate>Tue, 06 May 2008 18:00:25 EDT</pubDate>
</item>

<item>
<title>Re: [Vundo] Vundo removal</title>
<link>http://www.dslreports.com/forum/remark,20435239</link>
<description><![CDATA[<A HREF="/useremail/u/693977"><b>bcastner</b></A> : You are very welcome.<br><br>Best wishes,<br>Bill Castner]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20435239</guid>
<pubDate>Mon, 05 May 2008 15:49:12 EDT</pubDate>
</item>

<item>
<title>Re: [Vundo] Vundo removal</title>
<link>http://www.dslreports.com/forum/remark,20435189</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : It looks as if the problem is gone now! I just wanted to thank you for all your help! You do a brilliant job!!]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20435189</guid>
<pubDate>Mon, 05 May 2008 15:42:48 EDT</pubDate>
</item>

<item>
<title>Re: [Vundo] Vundo removal</title>
<link>http://www.dslreports.com/forum/remark,20429964</link>
<description><![CDATA[<A HREF="/useremail/u/693977"><b>bcastner</b></A> : Documents and Setting is a virtual folder; it is used for backwards compatibility. You do not have as much freedome with these "virtual" representations of real folders.   Vista instead writes all profile data in the folder "C:\Users".<br><br>I think we are done.<br><br>Open <b>Acrobat</b> if you have the Full Version installed  Click <b>Help</b> and run the <b>Upgrade</b> applet found there.  If no update is offered:  Use the Preferences, Internet submenu of Acrobat and uncheck to integrate with your Browser.  Close Acrobat.<br>Whether you had the Full Version of Acrobat or not, download and install <b>Adobe Reader 8.1.1</b> and use this as the integrated PDF Reader insider your browser:  &raquo;<A HREF="http://www.adobe.com/products/acrobat/readstep2.html" >www.adobe.com/products/acrobat/r&middot;&middot;&middot;ep2.html</A><br><br><b><u>Clean-up & Prevention:</u></b><br><br>&#8226; From the Start menu, click Control Panel, System, and on the left "System Protection."  <b>Un-</b>checkmark all drives.  When asked:  "Are you sure you want to turn System restore off", click <b>Turn off System Restore</b>. Now repeat, this time reversing the steps to enable System Restore on all drives.<br><br>&#8226; Click <b>Start</b>, then click <b>Run</b>.<br>Enter into the command box that opens:  <b>combofix /u</b> and then click <b>OK</b>.<br>(If we have renamed this file, please use the current name for the program in this instruction.)<br> <IMG SRC="http://i78.photobucket.com/albums/j116/amateur_photos/CFuninstall.png"> <br><br>&#8226; Run <b>ATF Cleaner</b>  <IMG SRC="http://www.geekstogo.com/misc/guide_icons/ATF.gif"> , and checkmark "Empty Recycle Bin", click "Empty Selected" and exit the program.  You can delete or keep this utility as you wish.<br><br>&#8226; Use Control Panel, Add or Remove Programs, and Uninstall any entry related to an On-Line scanner we may have used.  <br>If you find any files or folders created during this cleanup operation remaining, please feel free to delete them.  For example, Uninstall <b>MBAM</b>.<br><br>&#8226; Refer to my first set of instructions above, and reconfigure <b>Hidden Files and Folders</b> to your choosing.<br><br>&#8226; If you have not purchased "StopZilla", please reconsider this software.  While not a true "rogue" antimalware product, it is not a very good one.<br>See other User reviews:  &raquo;<A HREF="http://www.download.com/Stopzilla/3640-8022_4-10104765.html" >www.download.com/Stopzilla/3640-&middot;&middot;&middot;765.html</A><br><br>Best wishes.<br>Bill Castner<br><small>--<br><b>============</b><br><b>MS-MVP 2004 - -2008, ASAP Member</b><br><b><i>Users Helping Users</i></b><br><br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20429964</guid>
<pubDate>Sun, 04 May 2008 12:46:34 EDT</pubDate>
</item>

<item>
<title>Re: [Vundo] Vundo removal</title>
<link>http://www.dslreports.com/forum/remark,20429891</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : I am being refused access to folders such as my documents and documents and settings so I had to re-install and run another scan.<br><br>Malwarebytes' Anti-Malware 1.11<br>Database version: 715<br><br>Scan type: Quick Scan<br>Objects scanned: 31778<br>Time elapsed: 5 minute(s), 12 second(s)<br><br>Memory Processes Infected: 0<br>Memory Modules Infected: 0<br>Registry Keys Infected: 0<br>Registry Values Infected: 0<br>Registry Data Items Infected: 0<br>Folders Infected: 0<br>Files Infected: 0<br><br>Memory Processes Infected:<br>(No malicious items detected)<br><br>Memory Modules Infected:<br>(No malicious items detected)<br><br>Registry Keys Infected:<br>(No malicious items detected)<br><br>Registry Values Infected:<br>(No malicious items detected)<br><br>Registry Data Items Infected:<br>(No malicious items detected)<br><br>Folders Infected:<br>(No malicious items detected)<br><br>Files Infected:<br>(No malicious items detected)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20429891</guid>
<pubDate>Sun, 04 May 2008 12:22:16 EDT</pubDate>
</item>

<item>
<title>Re: [Vundo] Vundo removal</title>
<link>http://www.dslreports.com/forum/remark,20429851</link>
<description><![CDATA[<A HREF="/useremail/u/693977"><b>bcastner</b></A> : Look in:<br><br>C:\Users\<b>laff</b>\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\<b>mbam-log-{date Time}</b>.txt]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20429851</guid>
<pubDate>Sun, 04 May 2008 12:08:19 EDT</pubDate>
</item>

<item>
<title>Re: [Vundo] Vundo removal</title>
<link>http://www.dslreports.com/forum/remark,20429771</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Tried posting but it didnt appear so I'll try again. Still cant get mbam results up and if i try to run it it says error 732 (2) The rest of the results are as follows:<br><br>ComboFix 08-05-01.3 - Lisa 2008-05-04 15:18:20.1 - NTFSx86<br>Microsoft&reg; Windows Vista&#153; Home Premium   6.0.6000.0.1252.1.1033.18.1194 [GMT 1:00]<br>Running from: C:\Users\Lisa\Desktop\ComboFix.exe<br>Command switches used :: C:\Users\Lisa\Desktop\CFscript.txt<br> * Created a new restore point<br> * Resident AV is active<br><br>FILE ::<br>C:\Users\Lisa\AppData\Local\Temp\ddcYrRli.dll<br>.<br><br>(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br><br>C:\Windows\system32\x64<br><br>.<br>(((((((((((((((((((((((((((((((((((((((   Drivers/Services   )))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br><br>-------\Legacy_SZKG5<br>-------\Service_szkg5<br><br>(((((((((((((((((((((((((   Files Created from 2008-04-04 to 2008-05-04  )))))))))))))))))))))))))))))))<br>.<br><br>No new files created in this timespan<br><br>.<br>((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br>2008-05-04 14:21&#9;---------&#9;d-----w&#9;C:\ProgramData\STOPzilla!<br>2008-05-04 14:21&#9;---------&#9;d-----w&#9;C:\ProgramData\Kontiki<br>2008-05-04 14:01&#9;---------&#9;d-----w&#9;C:\ProgramData\SITEguard<br>2008-05-04 09:32&#9;---------&#9;d-----w&#9;C:\Program Files\XoftSpySE<br>2008-05-04 07:08&#9;---------&#9;d-----w&#9;C:\Program Files\Trend Micro<br>2008-05-04 07:00&#9;---------&#9;d-----w&#9;C:\Program Files\SUPERAntiSpyware<br>2008-05-04 07:00&#9;---------&#9;d-----w&#9;C:\Program Files\Common Files\Wise Installation Wizard<br>2008-05-04 06:55&#9;---------&#9;d-----w&#9;C:\Program Files\iTunes<br>2008-05-04 06:50&#9;---------&#9;d-----w&#9;C:\Users\Lisa\AppData\Roaming\Azureus<br>2008-05-04 06:50&#9;---------&#9;d-----w&#9;C:\Program Files\STOPzilla!<br>2008-05-04 06:50&#9;---------&#9;d-----w&#9;C:\Program Files\Safari<br>2008-05-04 06:50&#9;---------&#9;d-----w&#9;C:\Program Files\QuickTime<br>2008-05-04 06:50&#9;---------&#9;d-----w&#9;C:\Program Files\iPod<br>2008-05-04 06:50&#9;---------&#9;d-----w&#9;C:\Program Files\DivX<br>2008-05-04 06:50&#9;---------&#9;d-----w&#9;C:\Program Files\Apple Software Update<br>2008-05-04 06:37&#9;---------&#9;d-----w&#9;C:\ProgramData\Grisoft<br>2008-05-03 22:45&#9;---------&#9;d-----w&#9;C:\ProgramData\Grisoft(951)<br>2008-05-03 20:49&#9;---------&#9;d-----w&#9;C:\Program Files\Google<br>2008-05-03 20:02&#9;---------&#9;d-----w&#9;C:\Users\Lisa\AppData\Roaming\SUPERAntiSpyware.com<br>2008-05-03 20:02&#9;---------&#9;d-----w&#9;C:\ProgramData\SUPERAntiSpyware.com<br>2008-05-03 19:04&#9;---------&#9;d-----w&#9;C:\Program Files\Common Files\iS3<br>2008-05-03 17:01&#9;---------&#9;d-----w&#9;C:\ProgramData\Spybot - Search & Destroy<br>2008-05-03 14:39&#9;---------&#9;d-----w&#9;C:\ProgramData\Grisoft(74)<br>2008-05-03 13:58&#9;---------&#9;d-----w&#9;C:\ProgramData\Grisoft(106)<br>2008-05-03 13:36&#9;---------&#9;d-----w&#9;C:\ProgramData\TEMP<br>2008-05-03 13:36&#9;---------&#9;d-----w&#9;C:\ProgramData\PC Tools<br>2008-05-03 13:36&#9;---------&#9;d-----w&#9;C:\Program Files\ThreatFire<br>2008-05-03 11:33&#9;---------&#9;d-----w&#9;C:\ProgramData\Grisoft(108)<br>2008-05-03 11:05&#9;96,520&#9;----a-w&#9;C:\Windows\system32\drivers\avgldx86.sys<br>2008-05-03 11:04&#9;---------&#9;d-----w&#9;C:\ProgramData\avg8<br>2008-05-03 11:04&#9;---------&#9;d-----w&#9;C:\Program Files\AVG<br>2008-05-03 10:46&#9;---------&#9;d-----w&#9;C:\ProgramData\Lavasoft<br>2008-05-03 10:45&#9;---------&#9;d-----w&#9;C:\Program Files\Lavasoft<br>2008-05-02 14:23&#9;---------&#9;d-----w&#9;C:\Users\Lisa\AppData\Roaming\Apple Computer<br>2008-05-02 14:09&#9;---------&#9;d-----w&#9;C:\Program Files\iTunes(27)<br>2008-05-02 14:09&#9;---------&#9;d-----w&#9;C:\Program Files\iPod(26)<br>2008-05-02 14:08&#9;---------&#9;d-----w&#9;C:\Program Files\QuickTime(28)<br>2008-05-02 14:01&#9;---------&#9;d-----w&#9;C:\Program Files\Apple Software Update(1)<br>2008-03-11 22:39&#9;691,545&#9;----a-w&#9;C:\Windows\unins000.exe<br>2008-02-21 04:43&#9;52,736&#9;----a-w&#9;C:\Windows\AppPatch\iebrshim.dll<br>2008-02-14 03:03&#9;537,600&#9;----a-w&#9;C:\Windows\AppPatch\AcLayers.dll<br>2008-02-14 03:03&#9;449,536&#9;----a-w&#9;C:\Windows\AppPatch\AcSpecfc.dll<br>2008-02-14 03:03&#9;2,560&#9;----a-w&#9;C:\Windows\AppPatch\AcRes.dll<br>2008-02-14 03:03&#9;2,144,256&#9;----a-w&#9;C:\Windows\AppPatch\AcGenral.dll<br>2008-02-14 03:03&#9;173,056&#9;----a-w&#9;C:\Windows\AppPatch\AcXtrnal.dll<br>2007-11-27 15:25&#9;174&#9;--sha-w&#9;C:\Program Files\desktop.ini<br>.<br><br>(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br>.<br>*Note* empty entries & legit default entries are not shown <br>REGEDIT4<br><br>[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<br>"DellSupportCenter"="C:\Program Files\Dell Support Center\bin\sprtcmd.exe" [ ]<br>"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2006-11-02 13:35 125440]<br>"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 12:34 5724184]<br>"kdx"="C:\Program Files\Kontiki\KHost.exe" [2007-11-27 12:58 1032376]<br>"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 13:36 201728]<br><br>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<br>"RoxWatchTray"="C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2006-11-05 12:22 221184]<br>"RtHDVCpl"="RtHDVCpl.exe" [2007-05-11 14:26 4452352 C:\Windows\RtHDVCpl.exe]<br>"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-12-14 23:13 185896]<br>"Persistence"="C:\Windows\system32\igfxpers.exe" [2007-09-25 12:10 129560]<br>"HotKeysCmds"="C:\Windows\system32\hkcmd.exe" [2007-09-25 12:10 154136]<br>"IgfxTray"="C:\Windows\system32\igfxtray.exe" [2007-09-25 12:10 141848]<br>"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2007-11-28 00:11 1006264]<br>"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]<br>"MSServer"="C:\Windows\system32\ddcDTKby.dll" [ ]<br>"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-05-03 12:04 1177368]<br>"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-03-28 23:37 413696]<br>"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 10:36 267048]<br>"4oD"="C:\Program Files\Kontiki\KHost.exe" [2007-11-27 12:58 1032376]<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ddcYrRli.dll]<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]<br>"AppInit_DLLs"=avgrsstx.dll<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]<br>"vidc.ffds"= ffdshow.ax<br>"msacm.ac3filter"= ac3filter.acm<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]<br>"DisableMonitoring"=dword:00000001<br><br>[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]<br>"{71CE1E22-D3BF-43D4-88B9-F3BE9B27180F}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)<br>"TCP Query User{5638DCBE-8B56-411F-A61E-2FE6B2CD9AF0}C:\\program files\\azureus\\azureus.exe"= UDP:C:\program files\azureus\azureus.exe:Azureus<br>"UDP Query User{2475D0CB-F233-40D9-9C9F-7E299CEE5AE5}C:\\program files\\azureus\\azureus.exe"= TCP:C:\program files\azureus\azureus.exe:Azureus<br>"TCP Query User{F2FAFE83-B0D9-4B8B-9964-F415681E53FC}C:\\program files\\azureus\\azureus.exe"= UDP:C:\program files\azureus\azureus.exe:Azureus<br>"UDP Query User{4C3CD3C9-CC85-4D84-9180-2A2BA86394EE}C:\\program files\\azureus\\azureus.exe"= TCP:C:\program files\azureus\azureus.exe:Azureus<br>"TCP Query User{AC82F5DA-795E-45FD-965A-CD612B6BD45E}C:\\program files\\internet explorer\\iexplore.exe"= UDP:C:\program files\internet explorer\iexplore.exe:Internet Explorer<br>"UDP Query User{7D093470-FBAD-477E-8ECF-1567EDE13C64}C:\\program files\\internet explorer\\iexplore.exe"= TCP:C:\program files\internet explorer\iexplore.exe:Internet Explorer<br>"{63CB72BC-3069-4541-AE13-35E86C9B630D}"= UDP:C:\Program Files\Kontiki\KService.exe:Delivery Manager Service<br>"{37713B54-6072-40BE-851F-AAA289D93274}"= TCP:C:\Program Files\Kontiki\KService.exe:Delivery Manager Service<br>"{1A704448-96E8-428A-8C5E-E25658D130A5}"= UDP:C:\Program Files\Kontiki\KService.exe:Delivery Manager Service<br>"{715FDF81-1D5C-41C1-BB93-46C71D9BDC9E}"= TCP:C:\Program Files\Kontiki\KService.exe:Delivery Manager Service<br>"TCP Query User{F89977CF-B476-4C71-A4DD-D4528F5BDCB4}C:\\program files\\kontiki\\khost.exe"= UDP:C:\program files\kontiki\khost.exe:Delivery Manager<br>"UDP Query User{9B663E61-EA48-4438-8863-A76F893BB274}C:\\program files\\kontiki\\khost.exe"= TCP:C:\program files\kontiki\khost.exe:Delivery Manager<br>"TCP Query User{E10DA2A6-7BF7-421E-BF96-45C3DC491643}C:\\program files\\real\\realplayer\\realplay.exe"= UDP:C:\program files\real\realplayer\realplay.exe:RealPlayer<br>"UDP Query User{DA3B8ACB-1D8D-452D-982A-47D731C01907}C:\\program files\\real\\realplayer\\realplay.exe"= TCP:C:\program files\real\realplayer\realplay.exe:RealPlayer<br>"TCP Query User{EE7363F1-9714-433E-891B-CAF050662DDB}C:\\program files\\sopcast\\sopcast.exe"= UDP:C:\program files\sopcast\sopcast.exe:SopCast Main Application<br>"UDP Query User{75E04C65-F108-4E01-97DD-DBC0D2C9CDA7}C:\\program files\\sopcast\\sopcast.exe"= TCP:C:\program files\sopcast\sopcast.exe:SopCast Main Application<br>"TCP Query User{BD080E9A-798D-40A5-8074-91AA027509D1}C:\\program files\\sopcast\\adv\\sopadver.exe"= UDP:C:\program files\sopcast\adv\sopadver.exe:SopCast Adver<br>"UDP Query User{0BF15E42-15C6-48AB-A9D7-846690393641}C:\\program files\\sopcast\\adv\\sopadver.exe"= TCP:C:\program files\sopcast\adv\sopadver.exe:SopCast Adver<br>"{FE8459F4-4869-4307-8C3B-44FED415852C}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes<br>"{A99F0EE1-A9CF-48B5-B271-601992871DC1}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes<br>"{CB39DBE3-03C9-4A86-9189-98B4E845C915}"= C:\Program Files\AVG\AVG8\avgupd.exe:avgupd.exe<br><br>[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]<br>"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|<br><br>R1 AvgLdx86;AVG AVI Loader Driver x86;C:\Windows\system32\Drivers\avgldx86.sys [2008-05-03 12:05]<br>R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-05-03 12:04]<br>R3 igfx;igfx;C:\Windows\system32\DRIVERS\igdkmd32.sys [2007-09-25 12:10]<br>S3 R300;R300;C:\Windows\system32\DRIVERS\atikmdag.sys [2006-11-02 08:36]<br>S3 ss_bus;SAMSUNG Mobile USB Device 1.0 driver (WDM);C:\Windows\system32\DRIVERS\ss_bus.sys [2005-08-30 18:57]<br>S3 ss_mdfl;SAMSUNG Mobile USB Modem 1.0 Filter;C:\Windows\system32\DRIVERS\ss_mdfl.sys [2005-08-30 18:58]<br>S3 ss_mdm;SAMSUNG Mobile USB Modem 1.0 Drivers;C:\Windows\system32\DRIVERS\ss_mdm.sys [2005-08-30 18:59]<br><br>[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{dd3fc594-dd3b-11dc-b254-001d0978375e}]<br>\shell\AutoRun\command - K:\setupSNK.exe<br><br>*Newly Created Service* - SZKG5<br>.<br>Contents of the 'Scheduled Tasks' folder<br>"2008-05-03 15:16:18 C:\Windows\Tasks\User_Feed_Synchronization-{7E0D4AB1-DB41-4D4E-8CE5-64B8125A604C}.job"<br>- C:\Windows\system32\msfeedssync.exe<br>.<br>**************************************************************************<br><br>catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, &raquo;<A HREF="http://www.gmer.net" >www.gmer.net</A><br>Rootkit scan 2008-05-04 15:21:29<br>Windows 6.0.6000  NTFS<br><br>scanning hidden processes ... <br><br>scanning hidden autostart entries ...<br><br>scanning hidden files ... <br><br>scan completed successfully<br>hidden files: 0<br><br>**************************************************************************<br>.<br>------------------------ Other Running Processes ------------------------<br>.<br>C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe<br>C:\Windows\System32\audiodg.exe<br>C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe<br>C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br>C:\Program Files\Kontiki\KService.exe<br>C:\PROGRA~1\AVG\AVG8\avgrsx.exe<br>C:\Windows\System32\WUDFHost.exe<br>C:\Program Files\STOPzilla!\STOPzilla.exe<br>C:\Program Files\AVG\AVG8\avgtray.exe<br>C:\Windows\System32\igfxsrvc.exe<br>C:\Program Files\Windows Media Player\wmpnetwk.exe<br>C:\Windows\ehome\ehmsas.exe<br>C:\Program Files\iPod\bin\iPodService.exe<br>C:\Windows\System32\wbem\unsecapp.exe<br>C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe<br>.<br>**************************************************************************<br>.<br>Completion time: 2008-05-04 15:24:57 - machine was rebooted<br>ComboFix-quarantined-files.txt  2008-05-04 14:24:47<br><br>      The system cannot find message text for message number 0x2379 in the message file for Application.<br>      The system cannot find message text for message number 0x2379 in the message file for Application.<br><br>178&#9;--- E O F ---&#9;2008-05-04 07:04:06<br><br>Logfile of Trend Micro HijackThis v2.0.2<br>Scan saved at 16:14:13, on 04/05/2008<br>Platform: Windows Vista  (WinNT 6.00.1904)<br>MSIE: Internet Explorer v7.00 (7.00.6000.16643)<br>Boot mode: Normal<br><br>Running processes:<br>C:\Windows\system32\Dwm.exe<br>C:\Windows\Explorer.EXE<br>C:\Windows\system32\taskeng.exe<br>C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe<br>C:\Windows\RtHDVCpl.exe<br>C:\Windows\System32\igfxpers.exe<br>C:\Windows\System32\hkcmd.exe<br>C:\Windows\system32\igfxsrvc.exe<br>C:\Program Files\AVG\AVG8\avgtray.exe<br>C:\Program Files\iTunes\iTunesHelper.exe<br>C:\Program Files\Kontiki\KHost.exe<br>C:\Windows\ehome\ehtray.exe<br>C:\Windows\ehome\ehmsas.exe<br>C:\Program Files\Windows Media Player\wmpnscfg.exe<br>C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe<br>C:\Windows\system32\wbem\unsecapp.exe<br>C:\Program Files\STOPzilla!\STOPzilla.exe<br>C:\Program Files\Internet Explorer\ieuser.exe<br>C:\Program Files\Internet Explorer\iexplore.exe<br>C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe<br>C:\Windows\system32\NOTEPAD.EXE<br>C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br>C:\Windows\system32\DllHost.exe<br><br>R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://google.co.uk" >google.co.uk</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=69157" >go.microsoft.com/fwlink/?LinkId=69157</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = &raquo;<A HREF="http://uk.red.clientapps.yahoo.com/customize/btyahoo/defaults/sb/*http://uk.docs.yahoo.com/info/bt_side.html" >uk.red.clientapps.yahoo.com/cust&middot;&middot;&middot;ide.html</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://google.co.uk" >google.co.uk</A><br>R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = &raquo;<A HREF="http://uk.red.clientapps.yahoo.com/customize/btyahoo/defaults/su/*http://uk.search.yahoo.com/" >uk.red.clientapps.yahoo.com/cust&middot;&middot;&middot;hoo.com/</A><br>R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1<br>R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = <br>O1 - Hosts: ::1 localhost<br>O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll<br>O2 - BHO: SITEguard BHO - {1827766B-9F49-4854-8034-F6EE26FCB1EC} - C:\Program Files\STOPzilla!\SZSG.dll<br>O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll<br>O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\Program Files\Java\jre1.6.0\bin\ssv.dll<br>O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br>O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll<br>O2 - BHO: STOPzilla Browser Helper Object - {E3215F20-3212-11D6-9F8B-00D0B743919D} - C:\Program Files\STOPzilla!\SZIEBHO.dll<br>O3 - Toolbar: STOPzilla - {98828DED-A591-462F-83BA-D2F62A68B8B8} - C:\Program Files\STOPzilla!\SZSG.dll<br>O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"<br>O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe<br>O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot<br>O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe<br>O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe<br>O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe<br>O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide<br>O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"<br>O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe<br>O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime<br>O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"<br>O4 - HKLM\..\Run: [4oD] "C:\Program Files\Kontiki\KHost.exe" -all<br>O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter<br>O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe<br>O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background<br>O4 - HKCU\..\Run: [kdx] C:\Program Files\Kontiki\KHost.exe -all<br>O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe<br>O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')<br>O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')<br>O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')<br>O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000<br>O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\ssv.dll<br>O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\ssv.dll<br>O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL<br>O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll<br>O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll<br>O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll<br>O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll<br>O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll<br>O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll<br>O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll<br>O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll<br>O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll<br>O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll<br>O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll<br>O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll<br>O20 - AppInit_DLLs: avgrsstx.dll<br>O20 - Winlogon Notify: ddcYrRli.dll - C:\Windows\<br>O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe<br>O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br>O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe<br>O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe<br>O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe<br>O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br>O23 - Service: KService - Kontiki Inc. - C:\Program Files\Kontiki\KService.exe<br>O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe<br>O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe<br>O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe<br>O23 - Service: STOPzilla Service (szserver) - iS3, Inc. - C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe<br><br>--<br>End of file - 8005 bytes]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20429771</guid>
<pubDate>Sun, 04 May 2008 11:43:54 EDT</pubDate>
</item>

<item>
<title>Re: [Vundo] Vundo removal</title>
<link>http://www.dslreports.com/forum/remark,20429661</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : AM still unable to locate the malware log. I am being denied access to documents and settings and if I try to open mbam error 732(2) is showing. Here are the other results<br><br>Logfile of Trend Micro HijackThis v2.0.2<br>Scan saved at 16:14:13, on 04/05/2008<br>Platform: Windows Vista  (WinNT 6.00.1904)<br>MSIE: Internet Explorer v7.00 (7.00.6000.16643)<br>Boot mode: Normal<br><br>Running processes:<br>C:\Windows\system32\Dwm.exe<br>C:\Windows\Explorer.EXE<br>C:\Windows\system32\taskeng.exe<br>C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe<br>C:\Windows\RtHDVCpl.exe<br>C:\Windows\System32\igfxpers.exe<br>C:\Windows\System32\hkcmd.exe<br>C:\Windows\system32\igfxsrvc.exe<br>C:\Program Files\AVG\AVG8\avgtray.exe<br>C:\Program Files\iTunes\iTunesHelper.exe<br>C:\Program Files\Kontiki\KHost.exe<br>C:\Windows\ehome\ehtray.exe<br>C:\Windows\ehome\ehmsas.exe<br>C:\Program Files\Windows Media Player\wmpnscfg.exe<br>C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe<br>C:\Windows\system32\wbem\unsecapp.exe<br>C:\Program Files\STOPzilla!\STOPzilla.exe<br>C:\Program Files\Internet Explorer\ieuser.exe<br>C:\Program Files\Internet Explorer\iexplore.exe<br>C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe<br>C:\Windows\system32\NOTEPAD.EXE<br>C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br>C:\Windows\system32\DllHost.exe<br><br>R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://google.co.uk" >google.co.uk</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=69157" >go.microsoft.com/fwlink/?LinkId=69157</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = &raquo;<A HREF="http://uk.red.clientapps.yahoo.com/customize/btyahoo/defaults/sb/*http://uk.docs.yahoo.com/info/bt_side.html" >uk.red.clientapps.yahoo.com/cust&middot;&middot;&middot;ide.html</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://google.co.uk" >google.co.uk</A><br>R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = &raquo;<A HREF="http://uk.red.clientapps.yahoo.com/customize/btyahoo/defaults/su/*http://uk.search.yahoo.com/" >uk.red.clientapps.yahoo.com/cust&middot;&middot;&middot;hoo.com/</A><br>R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1<br>R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = <br>O1 - Hosts: ::1 localhost<br>O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll<br>O2 - BHO: SITEguard BHO - {1827766B-9F49-4854-8034-F6EE26FCB1EC} - C:\Program Files\STOPzilla!\SZSG.dll<br>O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll<br>O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\Program Files\Java\jre1.6.0\bin\ssv.dll<br>O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br>O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll<br>O2 - BHO: STOPzilla Browser Helper Object - {E3215F20-3212-11D6-9F8B-00D0B743919D} - C:\Program Files\STOPzilla!\SZIEBHO.dll<br>O3 - Toolbar: STOPzilla - {98828DED-A591-462F-83BA-D2F62A68B8B8} - C:\Program Files\STOPzilla!\SZSG.dll<br>O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"<br>O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe<br>O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot<br>O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe<br>O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe<br>O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe<br>O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide<br>O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"<br>O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe<br>O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime<br>O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"<br>O4 - HKLM\..\Run: [4oD] "C:\Program Files\Kontiki\KHost.exe" -all<br>O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter<br>O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe<br>O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background<br>O4 - HKCU\..\Run: [kdx] C:\Program Files\Kontiki\KHost.exe -all<br>O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe<br>O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')<br>O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')<br>O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')<br>O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000<br>O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\ssv.dll<br>O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\ssv.dll<br>O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL<br>O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll<br>O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll<br>O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll<br>O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll<br>O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll<br>O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll<br>O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll<br>O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll<br>O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll<br>O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll<br>O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll<br>O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll<br>O20 - AppInit_DLLs: avgrsstx.dll<br>O20 - Winlogon Notify: ddcYrRli.dll - C:\Windows\<br>O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe<br>O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br>O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe<br>O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe<br>O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe<br>O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br>O23 - Service: KService - Kontiki Inc. - C:\Program Files\Kontiki\KService.exe<br>O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe<br>O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe<br>O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe<br>O23 - Service: STOPzilla Service (szserver) - iS3, Inc. - C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe<br><br>--<br>End of file - 8005 bytes<br><br>ComboFix 08-05-01.3 - Lisa 2008-05-04 15:18:20.1 - NTFSx86<br>Microsoft&reg; Windows Vista&#153; Home Premium   6.0.6000.0.1252.1.1033.18.1194 [GMT 1:00]<br>Running from: C:\Users\Lisa\Desktop\ComboFix.exe<br>Command switches used :: C:\Users\Lisa\Desktop\CFscript.txt<br> * Created a new restore point<br> * Resident AV is active<br><br>FILE ::<br>C:\Users\Lisa\AppData\Local\Temp\ddcYrRli.dll<br>.<br><br>(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br><br>C:\Windows\system32\x64<br><br>.<br>(((((((((((((((((((((((((((((((((((((((   Drivers/Services   )))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br><br>-------\Legacy_SZKG5<br>-------\Service_szkg5<br><br>(((((((((((((((((((((((((   Files Created from 2008-04-04 to 2008-05-04  )))))))))))))))))))))))))))))))<br>.<br><br>No new files created in this timespan<br><br>.<br>((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br>2008-05-04 14:21&#9;---------&#9;d-----w&#9;C:\ProgramData\STOPzilla!<br>2008-05-04 14:21&#9;---------&#9;d-----w&#9;C:\ProgramData\Kontiki<br>2008-05-04 14:01&#9;---------&#9;d-----w&#9;C:\ProgramData\SITEguard<br>2008-05-04 09:32&#9;---------&#9;d-----w&#9;C:\Program Files\XoftSpySE<br>2008-05-04 07:08&#9;---------&#9;d-----w&#9;C:\Program Files\Trend Micro<br>2008-05-04 07:00&#9;---------&#9;d-----w&#9;C:\Program Files\SUPERAntiSpyware<br>2008-05-04 07:00&#9;---------&#9;d-----w&#9;C:\Program Files\Common Files\Wise Installation Wizard<br>2008-05-04 06:55&#9;---------&#9;d-----w&#9;C:\Program Files\iTunes<br>2008-05-04 06:50&#9;---------&#9;d-----w&#9;C:\Users\Lisa\AppData\Roaming\Azureus<br>2008-05-04 06:50&#9;---------&#9;d-----w&#9;C:\Program Files\STOPzilla!<br>2008-05-04 06:50&#9;---------&#9;d-----w&#9;C:\Program Files\Safari<br>2008-05-04 06:50&#9;---------&#9;d-----w&#9;C:\Program Files\QuickTime<br>2008-05-04 06:50&#9;---------&#9;d-----w&#9;C:\Program Files\iPod<br>2008-05-04 06:50&#9;---------&#9;d-----w&#9;C:\Program Files\DivX<br>2008-05-04 06:50&#9;---------&#9;d-----w&#9;C:\Program Files\Apple Software Update<br>2008-05-04 06:37&#9;---------&#9;d-----w&#9;C:\ProgramData\Grisoft<br>2008-05-03 22:45&#9;---------&#9;d-----w&#9;C:\ProgramData\Grisoft(951)<br>2008-05-03 20:49&#9;---------&#9;d-----w&#9;C:\Program Files\Google<br>2008-05-03 20:02&#9;---------&#9;d-----w&#9;C:\Users\Lisa\AppData\Roaming\SUPERAntiSpyware.com<br>2008-05-03 20:02&#9;---------&#9;d-----w&#9;C:\ProgramData\SUPERAntiSpyware.com<br>2008-05-03 19:04&#9;---------&#9;d-----w&#9;C:\Program Files\Common Files\iS3<br>2008-05-03 17:01&#9;---------&#9;d-----w&#9;C:\ProgramData\Spybot - Search & Destroy<br>2008-05-03 14:39&#9;---------&#9;d-----w&#9;C:\ProgramData\Grisoft(74)<br>2008-05-03 13:58&#9;---------&#9;d-----w&#9;C:\ProgramData\Grisoft(106)<br>2008-05-03 13:36&#9;---------&#9;d-----w&#9;C:\ProgramData\TEMP<br>2008-05-03 13:36&#9;---------&#9;d-----w&#9;C:\ProgramData\PC Tools<br>2008-05-03 13:36&#9;---------&#9;d-----w&#9;C:\Program Files\ThreatFire<br>2008-05-03 11:33&#9;---------&#9;d-----w&#9;C:\ProgramData\Grisoft(108)<br>2008-05-03 11:05&#9;96,520&#9;----a-w&#9;C:\Windows\system32\drivers\avgldx86.sys<br>2008-05-03 11:04&#9;---------&#9;d-----w&#9;C:\ProgramData\avg8<br>2008-05-03 11:04&#9;---------&#9;d-----w&#9;C:\Program Files\AVG<br>2008-05-03 10:46&#9;---------&#9;d-----w&#9;C:\ProgramData\Lavasoft<br>2008-05-03 10:45&#9;---------&#9;d-----w&#9;C:\Program Files\Lavasoft<br>2008-05-02 14:23&#9;---------&#9;d-----w&#9;C:\Users\Lisa\AppData\Roaming\Apple Computer<br>2008-05-02 14:09&#9;---------&#9;d-----w&#9;C:\Program Files\iTunes(27)<br>2008-05-02 14:09&#9;---------&#9;d-----w&#9;C:\Program Files\iPod(26)<br>2008-05-02 14:08&#9;---------&#9;d-----w&#9;C:\Program Files\QuickTime(28)<br>2008-05-02 14:01&#9;---------&#9;d-----w&#9;C:\Program Files\Apple Software Update(1)<br>2008-03-11 22:39&#9;691,545&#9;----a-w&#9;C:\Windows\unins000.exe<br>2008-02-21 04:43&#9;52,736&#9;----a-w&#9;C:\Windows\AppPatch\iebrshim.dll<br>2008-02-14 03:03&#9;537,600&#9;----a-w&#9;C:\Windows\AppPatch\AcLayers.dll<br>2008-02-14 03:03&#9;449,536&#9;----a-w&#9;C:\Windows\AppPatch\AcSpecfc.dll<br>2008-02-14 03:03&#9;2,560&#9;----a-w&#9;C:\Windows\AppPatch\AcRes.dll<br>2008-02-14 03:03&#9;2,144,256&#9;----a-w&#9;C:\Windows\AppPatch\AcGenral.dll<br>2008-02-14 03:03&#9;173,056&#9;----a-w&#9;C:\Windows\AppPatch\AcXtrnal.dll<br>2007-11-27 15:25&#9;174&#9;--sha-w&#9;C:\Program Files\desktop.ini<br>.<br><br>(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br>.<br>*Note* empty entries & legit default entries are not shown <br>REGEDIT4<br><br>[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<br>"DellSupportCenter"="C:\Program Files\Dell Support Center\bin\sprtcmd.exe" [ ]<br>"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2006-11-02 13:35 125440]<br>"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 12:34 5724184]<br>"kdx"="C:\Program Files\Kontiki\KHost.exe" [2007-11-27 12:58 1032376]<br>"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 13:36 201728]<br><br>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<br>"RoxWatchTray"="C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2006-11-05 12:22 221184]<br>"RtHDVCpl"="RtHDVCpl.exe" [2007-05-11 14:26 4452352 C:\Windows\RtHDVCpl.exe]<br>"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-12-14 23:13 185896]<br>"Persistence"="C:\Windows\system32\igfxpers.exe" [2007-09-25 12:10 129560]<br>"HotKeysCmds"="C:\Windows\system32\hkcmd.exe" [2007-09-25 12:10 154136]<br>"IgfxTray"="C:\Windows\system32\igfxtray.exe" [2007-09-25 12:10 141848]<br>"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2007-11-28 00:11 1006264]<br>"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]<br>"MSServer"="C:\Windows\system32\ddcDTKby.dll" [ ]<br>"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-05-03 12:04 1177368]<br>"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-03-28 23:37 413696]<br>"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 10:36 267048]<br>"4oD"="C:\Program Files\Kontiki\KHost.exe" [2007-11-27 12:58 1032376]<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ddcYrRli.dll]<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]<br>"AppInit_DLLs"=avgrsstx.dll<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]<br>"vidc.ffds"= ffdshow.ax<br>"msacm.ac3filter"= ac3filter.acm<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]<br>"DisableMonitoring"=dword:00000001<br><br>[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]<br>"{71CE1E22-D3BF-43D4-88B9-F3BE9B27180F}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)<br>"TCP Query User{5638DCBE-8B56-411F-A61E-2FE6B2CD9AF0}C:\\program files\\azureus\\azureus.exe"= UDP:C:\program files\azureus\azureus.exe:Azureus<br>"UDP Query User{2475D0CB-F233-40D9-9C9F-7E299CEE5AE5}C:\\program files\\azureus\\azureus.exe"= TCP:C:\program files\azureus\azureus.exe:Azureus<br>"TCP Query User{F2FAFE83-B0D9-4B8B-9964-F415681E53FC}C:\\program files\\azureus\\azureus.exe"= UDP:C:\program files\azureus\azureus.exe:Azureus<br>"UDP Query User{4C3CD3C9-CC85-4D84-9180-2A2BA86394EE}C:\\program files\\azureus\\azureus.exe"= TCP:C:\program files\azureus\azureus.exe:Azureus<br>"TCP Query User{AC82F5DA-795E-45FD-965A-CD612B6BD45E}C:\\program files\\internet explorer\\iexplore.exe"= UDP:C:\program files\internet explorer\iexplore.exe:Internet Explorer<br>"UDP Query User{7D093470-FBAD-477E-8ECF-1567EDE13C64}C:\\program files\\internet explorer\\iexplore.exe"= TCP:C:\program files\internet explorer\iexplore.exe:Internet Explorer<br>"{63CB72BC-3069-4541-AE13-35E86C9B630D}"= UDP:C:\Program Files\Kontiki\KService.exe:Delivery Manager Service<br>"{37713B54-6072-40BE-851F-AAA289D93274}"= TCP:C:\Program Files\Kontiki\KService.exe:Delivery Manager Service<br>"{1A704448-96E8-428A-8C5E-E25658D130A5}"= UDP:C:\Program Files\Kontiki\KService.exe:Delivery Manager Service<br>"{715FDF81-1D5C-41C1-BB93-46C71D9BDC9E}"= TCP:C:\Program Files\Kontiki\KService.exe:Delivery Manager Service<br>"TCP Query User{F89977CF-B476-4C71-A4DD-D4528F5BDCB4}C:\\program files\\kontiki\\khost.exe"= UDP:C:\program files\kontiki\khost.exe:Delivery Manager<br>"UDP Query User{9B663E61-EA48-4438-8863-A76F893BB274}C:\\program files\\kontiki\\khost.exe"= TCP:C:\program files\kontiki\khost.exe:Delivery Manager<br>"TCP Query User{E10DA2A6-7BF7-421E-BF96-45C3DC491643}C:\\program files\\real\\realplayer\\realplay.exe"= UDP:C:\program files\real\realplayer\realplay.exe:RealPlayer<br>"UDP Query User{DA3B8ACB-1D8D-452D-982A-47D731C01907}C:\\program files\\real\\realplayer\\realplay.exe"= TCP:C:\program files\real\realplayer\realplay.exe:RealPlayer<br>"TCP Query User{EE7363F1-9714-433E-891B-CAF050662DDB}C:\\program files\\sopcast\\sopcast.exe"= UDP:C:\program files\sopcast\sopcast.exe:SopCast Main Application<br>"UDP Query User{75E04C65-F108-4E01-97DD-DBC0D2C9CDA7}C:\\program files\\sopcast\\sopcast.exe"= TCP:C:\program files\sopcast\sopcast.exe:SopCast Main Application<br>"TCP Query User{BD080E9A-798D-40A5-8074-91AA027509D1}C:\\program files\\sopcast\\adv\\sopadver.exe"= UDP:C:\program files\sopcast\adv\sopadver.exe:SopCast Adver<br>"UDP Query User{0BF15E42-15C6-48AB-A9D7-846690393641}C:\\program files\\sopcast\\adv\\sopadver.exe"= TCP:C:\program files\sopcast\adv\sopadver.exe:SopCast Adver<br>"{FE8459F4-4869-4307-8C3B-44FED415852C}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes<br>"{A99F0EE1-A9CF-48B5-B271-601992871DC1}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes<br>"{CB39DBE3-03C9-4A86-9189-98B4E845C915}"= C:\Program Files\AVG\AVG8\avgupd.exe:avgupd.exe<br><br>[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]<br>"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|<br><br>R1 AvgLdx86;AVG AVI Loader Driver x86;C:\Windows\system32\Drivers\avgldx86.sys [2008-05-03 12:05]<br>R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-05-03 12:04]<br>R3 igfx;igfx;C:\Windows\system32\DRIVERS\igdkmd32.sys [2007-09-25 12:10]<br>S3 R300;R300;C:\Windows\system32\DRIVERS\atikmdag.sys [2006-11-02 08:36]<br>S3 ss_bus;SAMSUNG Mobile USB Device 1.0 driver (WDM);C:\Windows\system32\DRIVERS\ss_bus.sys [2005-08-30 18:57]<br>S3 ss_mdfl;SAMSUNG Mobile USB Modem 1.0 Filter;C:\Windows\system32\DRIVERS\ss_mdfl.sys [2005-08-30 18:58]<br>S3 ss_mdm;SAMSUNG Mobile USB Modem 1.0 Drivers;C:\Windows\system32\DRIVERS\ss_mdm.sys [2005-08-30 18:59]<br><br>[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{dd3fc594-dd3b-11dc-b254-001d0978375e}]<br>\shell\AutoRun\command - K:\setupSNK.exe<br><br>*Newly Created Service* - SZKG5<br>.<br>Contents of the 'Scheduled Tasks' folder<br>"2008-05-03 15:16:18 C:\Windows\Tasks\User_Feed_Synchronization-{7E0D4AB1-DB41-4D4E-8CE5-64B8125A604C}.job"<br>- C:\Windows\system32\msfeedssync.exe<br>.<br>**************************************************************************<br><br>catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, &raquo;<A HREF="http://www.gmer.net" >www.gmer.net</A><br>Rootkit scan 2008-05-04 15:21:29<br>Windows 6.0.6000  NTFS<br><br>scanning hidden processes ... <br><br>scanning hidden autostart entries ...<br><br>scanning hidden files ... <br><br>scan completed successfully<br>hidden files: 0<br><br>**************************************************************************<br>.<br>------------------------ Other Running Processes ------------------------<br>.<br>C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe<br>C:\Windows\System32\audiodg.exe<br>C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe<br>C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br>C:\Program Files\Kontiki\KService.exe<br>C:\PROGRA~1\AVG\AVG8\avgrsx.exe<br>C:\Windows\System32\WUDFHost.exe<br>C:\Program Files\STOPzilla!\STOPzilla.exe<br>C:\Program Files\AVG\AVG8\avgtray.exe<br>C:\Windows\System32\igfxsrvc.exe<br>C:\Program Files\Windows Media Player\wmpnetwk.exe<br>C:\Windows\ehome\ehmsas.exe<br>C:\Program Files\iPod\bin\iPodService.exe<br>C:\Windows\System32\wbem\unsecapp.exe<br>C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe<br>.<br>**************************************************************************<br>.<br>Completion time: 2008-05-04 15:24:57 - machine was rebooted<br>ComboFix-quarantined-files.txt  2008-05-04 14:24:47<br><br>      The system cannot find message text for message number 0x2379 in the message file for Application.<br>      The system cannot find message text for message number 0x2379 in the message file for Application.<br><br>178&#9;--- E O F ---&#9;2008-05-04 07:04:06]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20429661</guid>
<pubDate>Sun, 04 May 2008 11:16:19 EDT</pubDate>
</item>

<item>
<title>Re: [Vundo] Vundo removal</title>
<link>http://www.dslreports.com/forum/remark,20429627</link>
<description><![CDATA[<A HREF="/useremail/u/693977"><b>bcastner</b></A> : Please do not try to "attach" the files here.  Post their contents.<br><br>Using Explorer, find <b>C:\Combofix.txt</b><br>Double click the file; it will open in Notepad.  Do a Ctrl+A to highlight the entire file, then a Ctrl+C to copy the file to your internal Clipboard.  In your reply, do a Ctrl+V to "Paste" the file into the Reply box.<br><br>Similarly, look in the directory (I will use "laff" as your username in this example, substitute as appropriate):<br><br>C:\Documents and Settings\<b>laff</b>\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\<b>mbam-log-{date Time}</b>.txt<br><br>Copy and Paste its contents as well.<br><small>--<br><b>============</b><br><b>MS-MVP 2004 - -2008, ASAP Member</b><br><b><i>Users Helping Users</i></b><br><br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20429627</guid>
<pubDate>Sun, 04 May 2008 11:06:25 EDT</pubDate>
</item>

<item>
<title>Re: [Vundo] Vundo removal</title>
<link>http://www.dslreports.com/forum/remark,20429577</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Did all of the things you asked but when it came to posting the results it is saying that the files cannot be located or they are located and cannot be opened!]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20429577</guid>
<pubDate>Sun, 04 May 2008 10:49:48 EDT</pubDate>
</item>

<item>
<title>Re: [Vundo] Vundo removal</title>
<link>http://www.dslreports.com/forum/remark,20429392</link>
<description><![CDATA[<A HREF="/useremail/u/693977"><b>bcastner</b></A> : <b><u>First Steps</u></b><br><b>:!: The following instructions are <u>only</u> for this Forum member. Please do not use these instructions on another computer system. You can seriously damage your system by following the instructions below without guided assistance. You assuredly will make a cleanup of your system more difficult.</b><br><br>Please download<b>  <i>ATF Cleaner</i></b>  <br><br><textarea name="code" class="text" cols=50 rows=10> &#012;http://www.atribune.org/ccount/click.php?id=1&#012; &#012;</textarea><!--end code block-->It does not require any installation.. It is set up to clean Windows 2k, XP & Vista TEMP folders, as well as IE, FireFox and Opera, Temporary Internet Files and Cookies.<br>&#8226;      Double-click <b>ATF-Cleaner.exe</b> to run the program. <br><b>For all browsers:</b><br>&#8226;      Under <b>Main</b> choose: <b>Select All</b><br>&#8226;      Click the <b>Empty Selected</b> button. <br><b><u>Next, if you use Firefox (and <i>some</i> Mozilla-based browsers)</u></b> <br>&#8226;      Click Firefox at the top and choose: <b>Select All</b><br>&#8226;      Click the <b>Empty Selected</b> button. <b><u><br>Next, if you use the Opera browser</u></b> <br>&#8226;      Click <b>Opera</b> at the top and choose: <b>Select All</b> <br>&#8226;      Click the <b>Empty Selected</b> button. <b>:!: Click Exit on the Main menu to close the program.</b><br><br><b>Reconfigure Windows Vista to show hidden files:</b><br>To enable the viewing of Hidden files follow these steps: <br>&#8226;Close all programs so that you are at your desktop. <br>&#8226;Open the Control Panel menu and click <b>Folder Options</b>. <br>&#8226;After the new window appears select the <b>View</b> tab. <br>&#8226;Put a checkmark in the checkbox labeled Display the contents of system folders. <br>&#8226;Under the Hidden files and folders section select the radio button labeled Show hidden files and folders. <br>&#8226;Remove the checkmark from the checkbox labeled Hide file extensions for known file types. <br>&#8226;Remove the checkmark from the checkbox labeled Hide protected operating system files. <br>&#8226;Press the Apply button and then the OK button and exit My Computer. <br>&#8226;Now your computer is configured to show all hidden files. <b><u>Malware Removal Steps</u></b><br><br>1. Right click, "Run as Administrator" to Open <b>HijackThis</b> again, System scan only.  <b>Checkmark</b> these items:<br><br><b>O4 - HKCU\..\Run: [MSServer] rundll32.exe C:\Users\Lisa\AppData\Local\Temp\ddcYrRli.dll,#1</b><br><br>Click "<b>Fix checked</b>" and when the log panel clears exit HijackThis.<br><br>2. Download -- but <i>do not</i> yet run  -- <b>ComboFix&copy; </b> <br><br>Download this file <b><u>-- to your Desktop --</u></b> [/b]from any of these sources:  <br><textarea name="code" class="text" cols=50 rows=10>http://download.bleepingcomputer.com/sUBs/ComboFix.exe&#012;http://www.forospyware.com/sUBs/ComboFix.exe&#012;http://subs.geekstogo.com/ComboFix.exe&#012;</textarea><!--end code block--><br>Right-click on the header of the Code box below, where on the right side it says:  "<b>Copy to clipboard</b>":<br><textarea name="code" class="text" cols=50 rows=10>File::&#012;C:\Users\Lisa\AppData\Local\Temp\ddcYrRli.dll&#012; &#012;Registry::&#012;&#91;HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ddcYrRli.dll&#93;&#012;&#91;HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run&#93;&#012;"MSServer"=&#012;&#91;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run&#93;&#012;"MSServer"=&#012;&#91;HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run&#93;&#012;"MSServer"=&#012;&#91;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa&#93; &#012;"Authentication Packages"=hex(7):6d,73,76,31,5f,30,00,00 &#012; &#012;</textarea><!--end code block--><br>Open a new Notepad session - (Do <b><i>not</i></b> use a Word Processor or WordPad).  Click "<b>Format</b>" and be certain that Word Wrap is not enabled.  Right-click | <b>Paste</b> the Code box contents from above into Notepad.  Click File, <b><i>Save as...</i></b>, and set the location to your Desktop, and enter (including quotation marks) as the filename: <b>"CFscript.txt"</b> .  <br><br>&#8226; Disconnect from the Internet.<br>&#8226; Disable your Antivirus.  If the Antivirus software you use has any Script Blocking features, be certain to disable these as well.<br><b> Important:  </b> Have no other programs running.  Your Task Bar should be clear of any program entries including your Browser.<br>&#8226; A window will open with a warning.  Accept any Disclaimers to start the fix.<br>Using your mouse, drag the new file CFscript.txt and drop it on the ComboFix.exe icon as shown in this little picture:<br> <IMG SRC="http://users.pandora.be/bluepatchy/miekiemoes/images/CFScript.gif"> <br><br>When the scan completes Notepad will open with with your results log open. Do a File, Exit and answer 'Yes' to save changes.<br>&#8226;<b>!</b>&#8226; A caution - Do <b>not</b> run Combofix more than once. Do not touch your mouse/keyboard until the scan has completed, as this may cause the process to stall or your computer to lock.<br><br>3.  Please download MalwareBytes Anti-malware (MBAM) from one of the following links:<br><textarea name="code" class="text" cols=50 rows=10>http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html&#012;http://www.besttechie.net/tools/mbam-setup.exe&#012;</textarea><!--end code block--><br>Once downloaded, close all programs and Windows on your computer (including this one.)<br><br>Double-click on the icon on your desktop named Download_mbam-setup.exe. This will start the installation of MBAM onto your computer.<br><br>When the installation begins, keep following the prompts in order to continue with the installation process. Do not make any changes to default settings and when the program has finished installing, make sure you leave both the Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware checked. Then click on the Finish button.<br><br>MBAM will now automatically start and you will see a message stating that you should update the program before performing a scan. As MBAM will automatically update itself after the install, you can press the OK button to close that box and you will now be at the main program.<br><br>On the <b>Scanner tab</b>, make sure the the <b>Perform quick scan</b> option is selected and then click on the <b>Scan</b> button to start scanning your computer.<br><br>MBAM will now start scanning your computer for malware. This process can take quite a while, so we suggest you go and do something else and periodically check on the status of the scan. <br><br>When the scan is finished a message box will appear that it has completed scanning successfully.  Click <b>OK</b>.  Now click <b>Show Results</b>.  Make sure all entries have a checkmark at their far left.  You should now click on the <b>Remove Selected</b> button to remove all the listed malware. MBAM will now delete all of the files and registry keys and add them to the programs quarantine.<br><br>When MBAM has finished removing the malware, it will open the scan log and display it in Notepad. Review the log as desired, and then close the Notepad window.  Remember where you saved the log file, as we will want to see it later.<br><br>4. Run <b>HijackThis</b> again, and save the log file.<br><br><b><i>Submit to the Forum:</i></b><br>&#8226; The contents of C:\Combofix.txt;<br>&#8226; The <b>MBAM</b> results;<br>&#8226; The new HijackThis log.<br><br><small>--<br><b>============</b><br><b>MS-MVP 2004 - -2008, ASAP Member</b><br><b><i>Users Helping Users</i></b><br><br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20429392</guid>
<pubDate>Sun, 04 May 2008 09:51:07 EDT</pubDate>
</item>

<item>
<title>[Vundo] Vundo removal</title>
<link>http://www.dslreports.com/forum/remark,20428963</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : I have a vunodo virus on my computer. I ran the vundo fixer that you indicate. It said that there are no infected files but I know it's on there! This is what is coming up on the hijackthis log:<br><br>Logfile of Trend Micro HijackThis v2.0.2<br>Scan saved at 08:27:25, on 04/05/2008<br>Platform: Windows Vista  (WinNT 6.00.1904)<br>MSIE: Internet Explorer v7.00 (7.00.6000.16643)<br>Boot mode: Normal<br><br>Running processes:<br>C:\Windows\system32\Dwm.exe<br>C:\Windows\system32\taskeng.exe<br>C:\Windows\Explorer.EXE<br>C:\Program Files\STOPzilla!\STOPzilla.exe<br>C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe<br>C:\Windows\RtHDVCpl.exe<br>C:\Windows\System32\igfxpers.exe<br>C:\Windows\System32\hkcmd.exe<br>C:\Program Files\AVG\AVG8\avgtray.exe<br>C:\Program Files\iTunes\iTunesHelper.exe<br>C:\Windows\ehome\ehtray.exe<br>C:\Program Files\Windows Media Player\wmpnscfg.exe<br>C:\Windows\system32\wbem\unsecapp.exe<br>C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe<br>C:\Windows\ehome\ehmsas.exe<br>C:\Windows\system32\igfxsrvc.exe<br>C:\Program Files\STOPzilla!\SZOptions.exe<br>C:\Program Files\Internet Explorer\ieuser.exe<br>C:\Program Files\Internet Explorer\iexplore.exe<br>C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe<br>C:\Users\Lisa\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\2MNDCQK0\VundoFix[1].exe<br>C:\Windows\System32\mobsync.exe<br>C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br>C:\Windows\system32\SearchFilterHost.exe<br><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=69157" >go.microsoft.com/fwlink/?LinkId=69157</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = &raquo;<A HREF="http://uk.red.clientapps.yahoo.com/customize/btyahoo/defaults/sb/*http://uk.docs.yahoo.com/info/bt_side.html" >uk.red.clientapps.yahoo.com/cust&middot;&middot;&middot;ide.html</A><br>R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=69157" >go.microsoft.com/fwlink/?LinkId=69157</A><br>R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = &raquo;<A HREF="http://uk.red.clientapps.yahoo.com/customize/btyahoo/defaults/su/*http://uk.search.yahoo.com/" >uk.red.clientapps.yahoo.com/cust&middot;&middot;&middot;hoo.com/</A><br>R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Packard Bell<br>R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1<br>R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = <br>O1 - Hosts: ::1 localhost<br>O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll<br>O2 - BHO: SITEguard BHO - {1827766B-9F49-4854-8034-F6EE26FCB1EC} - C:\Program Files\STOPzilla!\SZSG.dll<br>O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll<br>O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\Program Files\Java\jre1.6.0\bin\ssv.dll<br>O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)<br>O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br>O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll<br>O2 - BHO: STOPzilla Browser Helper Object - {E3215F20-3212-11D6-9F8B-00D0B743919D} - C:\Program Files\STOPzilla!\SZIEBHO.dll<br>O3 - Toolbar: STOPzilla - {98828DED-A591-462F-83BA-D2F62A68B8B8} - C:\Program Files\STOPzilla!\SZSG.dll<br>O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"<br>O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe<br>O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot<br>O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe<br>O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe<br>O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe<br>O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide<br>O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"<br>O4 - HKLM\..\Run: [MSServer] rundll32.exe C:\Windows\system32\ddcDTKby.dll,#1<br>O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe<br>O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime<br>O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"<br>O4 - HKLM\..\Run: [4oD] "C:\Program Files\Kontiki\KHost.exe" -all<br>O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter<br>O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe<br>O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background<br>O4 - HKCU\..\Run: [kdx] C:\Program Files\Kontiki\KHost.exe -all<br>O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe<br>O4 - HKCU\..\Run: [MSServer] rundll32.exe C:\Users\Lisa\AppData\Local\Temp\ddcYrRli.dll,#1<br>O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')<br>O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')<br>O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')<br>O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000<br>O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\ssv.dll<br>O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\ssv.dll<br>O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL<br>O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll<br>O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll<br>O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll<br>O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll<br>O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll<br>O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll<br>O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll<br>O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll<br>O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll<br>O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll<br>O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll<br>O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll<br>O20 - AppInit_DLLs: avgrsstx.dll<br>O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe<br>O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br>O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe<br>O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe<br>O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe<br>O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br>O23 - Service: KService - Kontiki Inc. - C:\Program Files\Kontiki\KService.exe<br>O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe<br>O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe<br>O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe<br>O23 - Service: STOPzilla Service (szserver) - iS3, Inc. - C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe<br><br>--<br>End of file - 8232 bytes<br><br>Please help me, Ive tried everything and nothing seems to work!!]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20428963</guid>
<pubDate>Sun, 04 May 2008 03:45:18 EDT</pubDate>
</item>

</channel>
</rss>
