<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Re: [Trojan] AVWA.DLL Removal in Security Cleanup</title>
<link>http://www.dslreports.com/forum/r20451966</link>
<description></description>
<language>en</language>
<pubDate>Thu, 08 Jan 2009 02:53:34 EDT</pubDate>
<lastBuildDate>Thu, 08 Jan 2009 02:53:34 EDT</lastBuildDate>

<item>
<title>Re: [Trojan] AVWA.DLL Removal</title>
<link>http://www.dslreports.com/forum/remark,20493162</link>
<description><![CDATA[<A HREF="/useremail/u/693977"><b>bcastner</b></A> : No one would certify any computer as clean.  As far as I can tell there are no obvious issues with malware at this time.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20493162</guid>
<pubDate>Fri, 16 May 2008 13:15:18 EDT</pubDate>
</item>

<item>
<title>Re: [Trojan] AVWA.DLL Removal</title>
<link>http://www.dslreports.com/forum/remark,20492771</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Thanks again. I did all that. DOes that mean the computer should be clean now?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20492771</guid>
<pubDate>Fri, 16 May 2008 12:09:14 EDT</pubDate>
</item>

<item>
<title>Re: [Trojan] AVWA.DLL Removal</title>
<link>http://www.dslreports.com/forum/remark,20492435</link>
<description><![CDATA[<A HREF="/useremail/u/693977"><b>bcastner</b></A> : Right-click on the header of the Code box below, where on the right side it says:  "<b>Copy to clipboard</b>":<br><textarea name="code" class="text" cols=50 rows=10>KILLALL::&#012; &#012;Driver::&#012;euigmvks&#012; &#012;RootKit::&#012;C:\WINDOWS\system32\avwa.dll &#012;C:\WINDOWS\system32\drivers\egdndhqn.dat &#012; &#012;Registry::&#012;&#91;-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4BF0B7A0-F35A-4DA4-B4EE-06BB4693133E}&#93;&#012; &#012;</textarea><!--end code block--><br>Open a new Notepad session - (Do <b><i>not</i></b> use a Word Processor or WordPad).  Click "<b>Format</b>" and be certain that Word Wrap is not enabled.  Right-click | <b>Paste</b> the Code box contents from above into Notepad.  Click File, <b><i>Save as...</i></b>, and set the location to your Desktop, and enter (including quotation marks) as the filename: <b>"CFscript.txt"</b> .  <br><br>&#8226; Disconnect from the Internet.<br>&#8226; Disable your Antivirus.  If the Antivirus software you use has any Script Blocking features, be certain to disable these as well.<br><b> Important:  </b> Have no other programs running.  Your Task Bar should be clear of any program entries including your Browser.<br>&#8226; A window will open with a warning.  Accept any Disclaimers to start the fix.<br>Using your mouse, drag the new file CFscript.txt and drop it on the ComboFix.exe icon as shown in this little picture:<br> <IMG SRC="http://users.pandora.be/bluepatchy/miekiemoes/images/CFScript.gif"> <br><br>When the scan completes Notepad will open with with your results log open. Do a File, Exit and answer 'Yes' to save changes.<br>&#8226;<b>!</b>&#8226; A caution - Do <b>not</b> run Combofix more than once. Do not touch your mouse/keyboard until the scan has completed, as this may cause the process to stall or your computer to lock.<br><br>I will not need to see the log results of this session.<br><br>Open <b>Acrobat</b> if you have the Full Version installed  Click <b>Help</b> and run the <b>Upgrade</b> applet found there.  If no update is offered:  Use the Preferences, Internet submenu of Acrobat and uncheck to integrate with your Browser.  Close Acrobat.<br>Whether you had the Full Version of Acrobat or not, download and install <b>Adobe Reader 8.1.1</b> and use this as the integrated PDF Reader insider your browser:  &raquo;<A HREF="http://www.adobe.com/products/acrobat/readstep2.html" >www.adobe.com/products/acrobat/r&middot;&middot;&middot;ep2.html</A><br><br>Head to the Sun web site and update your version of Java.  Te version installed is woefully out of date.  The current version is 1.6.06:  &raquo;<A HREF="http://java.sun.com/javase/downloads/index.jsp" >java.sun.com/javase/downloads/index.jsp</A><br><br><b><u>Clean-up & Prevention:</u></b><br><br>&#8226;  Right click "My Computer", Properties, and then click the System Restore tab.  <b>Checkmark</b> the box at the top to stop System Restore on all drives.  Click the "<b>Apply</b>" button.  Agree to the deletion of old Restore Points.  Then <b><u>uncheck</u></b> the box at the top and again click the "<b>Apply</b>" button.  Finally, click the "<b>OK</b>" button.  This will create a new Restore Point reflecting your clean system state.<br><br>&#8226; Click <b>Start</b>, then click <b>Run</b>.<br>Enter into the command box that opens:  <b>combofix /u</b> and then click <b>OK</b>.<br>(If we have renamed this file, please use the current name for the program in this instruction.)<br> <IMG SRC="http://i78.photobucket.com/albums/j116/amateur_photos/CFuninstall.png"> <br><br>&#8226; Run <b>ATF Cleaner</b>  <IMG SRC="http://www.geekstogo.com/misc/guide_icons/ATF.gif"> , and checkmark "Empty Recycle Bin", click "Empty Selected" and exit the program.  You can delete or keep this utility as you wish.<br><br>&#8226; Use Control Panel, Add or Remove Programs, and Uninstall any entry related to an On-Line scanner we may have used.  <br>If you find any files or folders created during this cleanup operation remaining, please feel free to delete them.<br><br>&#8226; Configure your Antivirus software to check for updates daily, at a time in which you are sure the computer will be on.<br><br>&#8226; If I asked you to <b>Disable</b> something like TeaTimer or another malware blocker, please go ahead an re-enable them if you wish.<br><br>&#8226;  <b>Download and Install Windows Defender by Microsoft (free):</b><br><textarea name="code" class="text" cols=50 rows=10>http://www.microsoft.com/downloads/details.aspx?FamilyId=435BFCE7-DA2B-4A6A-AFA4-F7F14E605A0D&#012;</textarea><!--end code block--><br>&#8226;  <b>Download and install Comodo BOClean (free):</b><br><textarea name="code" class="text" cols=50 rows=10>http://www.comodo.com/boclean/CBO_download.html&#012;</textarea><!--end code block--><br>&#8226;  <b>Download, install, and keep updated Spyware Blaster (free):</b><br><textarea name="code" class="text" cols=50 rows=10>http://www.javacoolsoftware.com/spywareblaster.html&#012;</textarea><!--end code block--><br>&#8226; Refer to my first set of instructions above, and reconfigure <b>Hidden Files and Folders</b> to your choosing.<br><br>Best wishes.<br>Bill Castner<br><br><small>--<br><b>============</b><br><b>MS-MVP 2004 - -2008, ASAP Member</b><br><b><i>Users Helping Users</i></b><br><br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20492435</guid>
<pubDate>Fri, 16 May 2008 11:04:55 EDT</pubDate>
</item>

<item>
<title>Re: [Trojan] AVWA.DLL Removal</title>
<link>http://www.dslreports.com/forum/remark,20492068</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Sorry it took so long. Here are the results:<br><br>Logfile of The Avenger Version 2.0, (c) by Swandog46<br>&raquo;<A HREF="http://swandog46.geekstogo.com" >swandog46.geekstogo.com</A><br><br>Platform:  Windows XP<br><br>*******************<br><br>Script file opened successfully.<br>Script file read successfully.<br><br>Backups directory opened successfully at C:\Avenger<br><br>*******************<br><br>Beginning to process script file:<br><br>Rootkit scan active.<br>No rootkits found!<br><br>Completed script processing.<br><br>*******************<br><br>Finished!  Terminate.<br><br><b>SDFix: Version 1.182 </b><br>Run by Lauren Cortese on Fri 05/16/2008 at 09:24 AM<br><br>Microsoft Windows XP [Version 5.1.2600]<br>Running From: C:\SDFix<br><br><b>Checking Services </b>:<br><br>Restoring Windows Registry Values<br>Restoring Windows Default Hosts File<br><br>Rebooting<br><br><b>Checking Files </b>: <br><br>Trojan Files Found:<br><br>C:\33.TMP - Deleted<br>C:\34.TMP - Deleted<br>C:\38.TMP - Deleted<br>C:\39.TMP - Deleted<br><br>Removing Temp Files<br><br><b>ADS Check </b>:<br> <br><br>                                 <b>Final Check </b>:<br><br>catchme 0.3.1359.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, &raquo;<A HREF="http://www.gmer.net" >www.gmer.net</A><br>Rootkit scan 2008-05-16 09:35:44<br>Windows 5.1.2600 Service Pack 3 NTFS<br><br>scanning hidden processes ...<br><br>scanning hidden services & system hive ...<br><br>scanning hidden registry entries ...<br><br>scanning hidden files ...<br><br>scan completed successfully<br>hidden processes: 0<br>hidden services: 0<br>hidden files: 0<br><br><b>Remaining Services </b>:<br><br>Authorized Application Key Export:<br><br>[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]<br>"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"<br>"C:\\StubInstaller.exe"="C:\\StubInstaller.exe:*:Enabled:LimeWire swarmed installer"<br>"C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program Files\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire"<br>"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"<br>"C:\\PROGRA~1\\ExamSoft\\SofTest\\SoftLnch.exe"="C:\\PROGRA~1\\ExamSoft\\SofTest\\SoftLnch.exe:*:Enabled:SofLaunch"<br>"C:\\PROGRA~1\\ExamSoft\\SofTest\\softest.exe"="C:\\PROGRA~1\\ExamSoft\\SofTest\\SofTest.exe:*:Enabled:SofTest"<br>"C:\\Program Files\\AIM\\aim.exe"="C:\\Program Files\\AIM\\aim.exe:*:Enabled:AOL Instant Messenger"<br>"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"="C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe:*:Enabled:AOL Loader"<br>"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"<br>"C:\\Program Files\\iTunes\\iTunesHelper.exe"="C:\\Program Files\\iTunes\\iTunesHelper.exe:*:Disabled:iTunesHelper Module"<br>"C:\\Program Files\\CyberLink\\PowerDVD\\DVDLauncher.exe"="C:\\Program Files\\CyberLink\\PowerDVD\\DVDLauncher.exe:*:Disabled:CyberLink PowerCinema Resident Program"<br>"C:\\Program Files\\ExamSoft\\SofTest\\SoftLnch.exe"="C:\\Program Files\\ExamSoft\\SoftLnch.exe:*:Enabled:SofLaunch<br><br>"<br>"C:\\Program Files\\ExamSoft\\SofTest\\softest.exe"="C:\\Program Files\\ExamSoft\\SofTest.exe:*:Enabled:SofTest<br><br>"<br>"C:\\Program Files\\AIM6\\aolsoftware.exe"="C:\\Program Files\\AIM6\\aolsoftware.exe:*:Enabled:AOL"<br>"C:\\Program Files\\Internet Explorer\\iexplore.exe"="C:\\Program Files\\Internet Explorer\\iexplore.exe:*:Enabled:Internet Explorer"<br>"C:\\Program Files\\AIM6\\aim6.exe"="C:\\Program Files\\AIM6\\aim6.exe:*:Enabled:AIM"<br><br>[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]<br>"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"<br>"C:\\Program Files\\AIM\\aim.exe"="C:\\Program Files\\AIM\\aim.exe:*:Enabled:AOL Instant Messenger"<br>"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"<br><br><b>Remaining Files </b>:<br><br>File Backups: - C:\SDFix\backups\backups.zip<br><br><b>Files with Hidden Attributes </b>:<br><br>Thu  9 Aug 2001        64,512 A..H. --- "C:\i386\PackethSvc.exe"<br>Thu  9 Aug 2001        64,512 A..H. --- "C:\Program Files\wmconnect\packethsvc.exe"<br>Thu  9 Aug 2001        40,960 A..H. --- "C:\Program Files\wmconnect\RBM.exe"<br>Thu 19 Jan 2006       102,467 A..H. --- "C:\Program Files\wmconnect\wmphx.exe"<br>Fri 10 Feb 2006        38,576 A..H. --- "C:\Program Files\wmconnect\wmtray.exe"<br>Fri 26 Oct 2001       151,615 A..H. --- "C:\Program Files\wmconnect\wwm.exe"<br>Thu  9 Aug 2001        64,512 A..H. --- "C:\WINDOWS\system32\PackethSvc.exe"<br>Sat 18 Nov 2006         4,348 ..SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"<br>Wed  5 Oct 2005        33,792 ...H. --- "C:\Documents and Settings\Lauren Cortese\My Documents\~WRL0001.tmp"<br>Tue 11 Dec 2007        43,520 ...H. --- "C:\Documents and Settings\Lauren Cortese\My Documents\~WRL1214.tmp"<br>Fri 15 Dec 2006       125,440 ...H. --- "C:\Documents and Settings\Lauren Cortese\My Documents\~WRL1522.tmp"<br>Wed  6 Dec 2006        35,328 ...H. --- "C:\Documents and Settings\Lauren Cortese\My Documents\~WRL1820.tmp"<br>Wed 12 Dec 2007        44,032 ...H. --- "C:\Documents and Settings\Lauren Cortese\My Documents\~WRL2317.tmp"<br>Tue  8 Apr 2008        30,208 ...H. --- "C:\Documents and Settings\Lauren Cortese\My Documents\~WRL2324.tmp"<br>Sun 12 Feb 2006        77,824 ...H. --- "C:\Documents and Settings\Lauren Cortese\My Documents\~WRL2856.tmp"<br>Thu 14 Dec 2006        81,408 ...H. --- "C:\Documents and Settings\Lauren Cortese\My Documents\~WRL2910.tmp"<br>Thu 14 Dec 2006        65,024 ...H. --- "C:\Documents and Settings\Lauren Cortese\My Documents\~WRL2926.tmp"<br>Fri 15 Dec 2006       102,912 ...H. --- "C:\Documents and Settings\Lauren Cortese\My Documents\~WRL3088.tmp"<br>Wed  6 Dec 2006        40,960 ...H. --- "C:\Documents and Settings\Lauren Cortese\My Documents\~WRL3378.tmp"<br>Mon  4 Dec 2006        60,416 ...H. --- "C:\Documents and Settings\Lauren Cortese\My Documents\~WRL3696.tmp"<br>Tue 13 Nov 2001       172,032 A..H. --- "C:\Program Files\wmconnect\COMIT\cswitch.exe"<br>Fri 27 Oct 2006         2,996 ...H. --- "C:\Documents and Settings\All Users\Application Data\inData\wmfnnrh.dll"<br>Fri 16 Mar 2007             0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"<br>Tue 13 Mar 2007        36,352 ...H. --- "C:\Documents and Settings\Lauren Cortese\My Documents\spring 2007\~WRL3383.tmp"<br>Mon 28 Jan 2008             0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\523d056929e13eacf8392044f602e53e\BIT17.tmp"<br>Thu  7 Dec 2006     3,096,576 A..H. --- "C:\Documents and Settings\Lauren Cortese\Application Data\U3\temp\Launchpad Removal.exe"<br>Tue 13 Nov 2007        31,232 ...H. --- "C:\Documents and Settings\Lauren Cortese\Application Data\Microsoft\Word\STARTUP\~WRL1898.tmp"<br>Mon 17 Mar 2008        55,296 ...H. --- "C:\Documents and Settings\Lauren Cortese\Application Data\Microsoft\Word\STARTUP\~WRL2130.tmp"<br>Tue 13 Nov 2007        33,280 ...H. --- "C:\Documents and Settings\Lauren Cortese\Application Data\Microsoft\Word\STARTUP\~WRL3580.tmp"<br>Thu 14 Dec 2006       311,296 ...H. --- "C:\Documents and Settings\Lauren Cortese\Application Data\Microsoft\Word\STARTUP\~WRL3854.tmp"<br><br><b>Finished!</b><br><br>catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, &raquo;<A HREF="http://www.gmer.net" >www.gmer.net</A><br>Rootkit scan 2008-05-16 09:43:08<br>Windows 5.1.2600 Service Pack 3 NTFS<br><br>scanning hidden processes ...<br><br>scanning hidden services & system hive ...<br><br>scanning hidden registry entries ...<br><br>scanning hidden files ...<br><br>scan completed successfully<br>hidden processes: 0<br>hidden services: 0<br>hidden files: 0]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20492068</guid>
<pubDate>Fri, 16 May 2008 09:53:48 EDT</pubDate>
</item>

<item>
<title>Re: [Trojan] AVWA.DLL Removal</title>
<link>http://www.dslreports.com/forum/remark,20468880</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Sorry just saw the request for a follow up. I will try to get that information posted later today.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20468880</guid>
<pubDate>Mon, 12 May 2008 09:51:23 EDT</pubDate>
</item>

<item>
<title>Re: [Trojan] AVWA.DLL Removal</title>
<link>http://www.dslreports.com/forum/remark,20455257</link>
<description><![CDATA[<A HREF="/useremail/u/693977"><b>bcastner</b></A> : We still have a rootit issue.<br><br>Note that your log results of file activity in the last 30 days has a huge gap:<br><br>2008-05-08 10:32 . 2003-09-06 15:55 57,556 --a------ <br>C:\WINDOWS\guard.bmp<br><br><b>  (Huge Gap of No activity) </b><br><br>2008-04-25 23:14 . 2008-04-25 23:14 d-------- C:\Program Files\MyPublisher<br><br>Note that even some of the utilites you just downloaded and ran are not showing in the Folders and Files summary.<br><br>This looks like a rootkit from the Gromazon family.<br>I am going to have to script this one away, and it will require a little bit of thought; and on your part we will have to build a little toolkit.<br><br>Create a New Folder on your Desktop. Name it "RootKit"<br><br>Download to your Desktop <b>The Avenger by Swandog46</b> from:<br><br><textarea name="code" class="text" cols=50 rows=10>http://swandog46.geekstogo.com/avenger2/download.php&#012;</textarea><!--end code block--><br>&#8226; Unzip/extract it to your New Folder "RootKit"  on your desktop.<br>&#8226; Double click on Avenger.exe to run <b>The Avenger</b>.<br>&#8226; Click <b>OK</b>.<br>&#8226; Make sure that the box next to <b>Scan for rootkits</b> has a tick in it and that the box next to <b>Automatically disable any rootkits found</b> does not have a tick in it.<br>&#8226; Click the <b>Execute</b> button.<br>&#8226; You will be asked <b>No script has been entered. Do you want to execute a rootkit scan only?</b>.<br>&#8226; Click <b>Yes</b>.<br>&#8226; You will now be asked <b>First step completed --- The Avenger has been successfully set up to run on next boot. Reboot now?</b>.<br>&#8226; Click <b>Yes</b>.<br>&#8226; Your PC will now be rebooted.<br>&#8226; After your PC has completed the necessary reboots, a log should automatically open. If it does not, as sometimes happen, do not be concerned.  If you see Notepad open with a log result, save the file and Exit. </b><br><br>Download <b>SDFix</b> and save it to your Desktop.<br><textarea name="code" class="text" cols=50 rows=10>http://downloads.andymanchesta.com/RemovalTools/SDFix.exe&#012;</textarea><!--end code block--><br>Double click <b>SDFix.exe</b> and it will extract the files to  the Windows Directory,  <b>C:\SDFix</b>. <br><br>Please then reboot your computer in <b><i>Safe Mode</i></b> by doing the following :<br>&#8226; Restart your computer <br>&#8226; After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually; <br>&#8226; Instead of Windows loading as normal, the Advanced Options Menu should appear; <br>&#8226; Select the first option, to run Windows in Safe Mode, then press [Enter]. <br>&#8226; Choose your usual account. <br>&#8226;  Open the extracted SDFix folder and double click <b>RunThis.ba</b> to start the script. <br>&#8226;  Type <b>Y[</b> to begin the cleanup process. <br>&#8226;  It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot. <br>&#8226;  Press any Key and it will restart the PC. <br>&#8226;  When the PC restarts the Fixtool will run again and complete the removal process then display <b>]Finished</b>, press any key to end the script and load your desktop icons. <br>&#8226;  Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as <b>Report.txt</b> <br>(Report.txt will also be copied to Clipboard ready for posting back on the forum). <br>&#8226;  For now, simply close Notepad.<br><br>Finally, Download <b>Catchme.exe by GMER</b>  to your new folder "<b>RootKit</b>":<br><textarea name="code" class="text" cols=50 rows=10>http://files.thespykiller.co.uk/catchme.exe&#012;</textarea><!--end code block--><br>Double click catchme.exe to run it<br>Click the "<b>Scan</b>" button to start scan<br>When the scan completes, Exit the program.<br><br><b><i>Post back to the Forum:</i></b><br>&#8226; The contents of C:\Avenger.txt;<br>&#8226; The contents of C:\SDFix\Report.txt<br>&#8226; The contents of "catchme.log" found in the new folder "RootKit"<br><br>Bill Castner<br><small>--<br><b>============</b><br><b>MS-MVP 2004 - -2008, ASAP Member</b><br><b><i>Users Helping Users</i></b><br><br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20455257</guid>
<pubDate>Fri, 09 May 2008 05:32:54 EDT</pubDate>
</item>

<item>
<title>Re: [Trojan] AVWA.DLL Removal</title>
<link>http://www.dslreports.com/forum/remark,20452298</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Here are the results after I followed the directions:<br><br>ComboFix 08-05-07.1 - Lauren Cortese 2008-05-08 15:04:24.1 - NTFSx86<br>Microsoft Windows XP Professional  5.1.2600.2.1252.1.1033.18.171 [GMT -4:00]<br>Running from: C:\Documents and Settings\Lauren Cortese\Desktop\ComboFix.exe<br>Command switches used :: C:\Documents and Settings\Lauren Cortese\Desktop\CFscript.txt<br> * Created a new restore point<br><br>[color=red]<b>WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!</b>[/color]<br><br>FILE ::<br>C:\WINDOWS\system32\avwa.dll<br>.<br><br>(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br><br>C:\Documents and Settings\Lauren Cortese\Application Data\DOBE~1<br>C:\Documents and Settings\Lauren Cortese\Application Data\ICROSO~1<br>C:\Documents and Settings\Lauren Cortese\Application Data\ICROSO~1\?icrosoft\<br>C:\Documents and Settings\Lauren Cortese\Application Data\STEM~1<br>C:\Documents and Settings\Lauren Cortese\My Documents\ICROSO~1.NET<br>C:\Documents and Settings\Lauren Cortese\My Documents\SCURIT~1<br>C:\Documents and Settings\Lauren Cortese\My Documents\YSTEM3~1<br>C:\Program Files\Common Files\crosof~1<br>C:\Program Files\Common Files\curity~1<br>C:\Program Files\Common Files\ystem~1<br>C:\Program Files\fnts~1<br>C:\Program Files\ISM2<br>C:\Program Files\sembly~1<br>C:\Program Files\Temporary<br>C:\Program Files\WinAble<br>C:\Program Files\ystem~1<br>C:\WINDOWS\dobe~1<br>C:\WINDOWS\system32\drivers\fad.sys<br>C:\WINDOWS\system32\MabryObj.dll<br>C:\WINDOWS\system32\ppatch~1<br>C:\WINDOWS\system32\wnscpicom.exe<br>C:\WINDOWS\winhelp.ini<br>C:\WINDOWS\system32\avwa.dll . . . . failed to delete<br><br>.<br>(((((((((((((((((((((((((   Files Created from 2008-04-08 to 2008-05-08  )))))))))))))))))))))))))))))))<br>.<br><br>2008-05-08 12:13 . 2008-05-08 12:13&#9;&#9;d--------&#9;C:\Program Files\Trend Micro<br>2008-05-08 11:57 . 2008-05-08 11:57&#9;4,130&#9;--a------&#9;C:\WINDOWS\system32\tmp.reg<br>2008-05-08 11:53 . 2008-05-08 11:53&#9;&#9;d--------&#9;C:\Documents and Settings\Lauren Cortese\Application Data\TrojanHunter<br>2008-05-08 11:04 . 2008-05-08 12:01&#9;&#9;d--------&#9;C:\Program Files\TrojanHunter 5.0<br>2008-05-08 10:47 . 2008-05-08 10:47&#9;76&#9;--a------&#9;C:\WINDOWS\lsoon.ini<br>2008-05-08 10:45 . 2008-05-08 10:45&#9;40&#9;--a------&#9;C:\WINDOWS\system32\Partizan.RRI<br>2008-05-08 10:33 . &#9;C:\WINDOWS\(2)&#9;&#9;C:\ComboFix\winstart.bat<br>2008-05-08 10:32 . 2008-05-08 10:32&#9;&#9;d--------&#9;C:\Program Files\Greatis<br>2008-05-08 10:32 . 2008-05-08 10:32&#9;&#9;d--------&#9;C:\Documents and Settings\Lauren Cortese\Application Data\Regrun<br>2008-05-08 10:32 . 2008-05-08 10:32&#9;&#9;d--------&#9;C:\backreg<br>2008-05-08 10:32 . 2003-09-06 15:55&#9;57,556&#9;--a------&#9;C:\WINDOWS\guard.bmp<br>2008-04-25 23:14 . 2008-04-25 23:14&#9;&#9;d--------&#9;C:\Program Files\MyPublisher<br>2008-04-25 23:14 . 2008-04-25 23:14&#9;&#9;d--------&#9;C:\Documents and Settings\Lauren Cortese\Application Data\MyPublisher<br><br>.<br>((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br>2008-06-05 20:37&#9;---------&#9;d-----w&#9;C:\Documents and Settings\All Users\Application Data\Examsoft<br>2008-05-08 19:07&#9;---------&#9;d-----w&#9;C:\Program Files\Symantec AntiVirus<br>2008-04-08 02:21&#9;---------&#9;d-----w&#9;C:\Program Files\Comodo<br>2008-04-03 17:40&#9;---------&#9;d-----w&#9;C:\Program Files\Google<br>2008-03-31 19:16&#9;---------&#9;d-----w&#9;C:\Program Files\IrfanView<br>2008-03-08 02:40&#9;---------&#9;d-----w&#9;C:\Program Files\StudySmartMPRE<br>.<br><br>(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br>.<br>*Note* empty entries & legit default entries are not shown <br>REGEDIT4<br><br>[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4BF0B7A0-F35A-4DA4-B4EE-06BB4693133E}]<br>2004-08-04 06:00&#9;101888&#9;--a------&#9;C:\WINDOWS\system32\avwa.dll<br><br>[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<br>"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 12:24 1694208]<br>"Aim6"="" []<br>"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 06:00 15360]<br><br>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<br>"Apoint"="C:\Program Files\Apoint\Apoint.exe" [2004-09-13 17:33 155648]<br>"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2005-02-15 16:02 155648]<br>"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2005-02-15 16:02 126976]<br>"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe" [2005-11-10 13:03 36975]<br>"Dell QuickSet"="C:\Program Files\Dell\QuickSet\quickset.exe" [2005-03-04 12:26 606208]<br>"Dell Wireless Manager UI"="C:\WINDOWS\system32\WLTRAY" [ ]<br>"DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [2004-04-26 09:04 53248]<br>"UpdateManager"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" [2004-01-07 02:01 110592]<br>"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2004-12-06 02:05 127035]<br>"RealTray"="C:\Program Files\Real\RealPlayer\RealPlay.exe" [2005-08-20 17:50 26112]<br>"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2005-10-06 18:03 278528]<br>"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2005-10-19 18:46 155648]<br>"LXSUPMON"="C:\WINDOWS\system32\LXSUPMON.exe" [2002-01-28 13:48 885760]<br>"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe" [2003-05-07 01:56 188416]<br>"HPHUPD05"="C:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe" [2003-05-22 09:03 49152]<br>"HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [2003-04-08 13:45 212992]<br>"HP Software Update"="C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe" [2002-12-17 12:40 49152]<br>"HPHmon05"="C:\WINDOWS\system32\hphmon05.exe" [2003-05-22 08:55 483328]<br>"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2006-03-24 18:14 53408]<br>"vptray"="C:\PROGRA~1\SYMANT~1\VPTray.exe" [2006-06-15 02:40 124656]<br><br>C:\Documents and Settings\All Users\Start Menu\Programs\Startup\<br>Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26 29696]<br>Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2005-08-12 11:24:40 24576]<br>Netscape Connect Tray Icon.lnk - C:\Program Files\wmconnect\wmtray.exe [2005-08-20 17:50:13 38576]<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\security center]<br>"AntiVirusOverride"=dword:00000001<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]<br>"DisableMonitoring"=dword:00000001<br><br>[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]<br>"%windir%\\system32\\sessmgr.exe"=<br>"C:\\StubInstaller.exe"=<br>"C:\\Program Files\\LimeWire\\LimeWire.exe"=<br>"C:\\Program Files\\iTunes\\iTunes.exe"=<br>"C:\\PROGRA~1\\ExamSoft\\SofTest\\SoftLnch.exe"=<br>"C:\\PROGRA~1\\ExamSoft\\SofTest\\softest.exe"= C:\\PROGRA~1\\ExamSoft\\SofTest\\SofTest.exe<br>"C:\\Program Files\\AIM\\aim.exe"=<br>"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=<br>"%windir%\\Network Diagnostic\\xpnetdiag.exe"=<br>"C:\\Program Files\\iTunes\\iTunesHelper.exe"=<br>"C:\\Program Files\\CyberLink\\PowerDVD\\DVDLauncher.exe"=<br>"C:\\Program Files\\ExamSoft\\SofTest\\SoftLnch.exe"= C:\\Program Files\\ExamSoft\\SoftLnch.exe<br>"C:\\Program Files\\ExamSoft\\SofTest\\softest.exe"= C:\\Program Files\\ExamSoft\\SofTest.exe<br>"C:\\Program Files\\AIM6\\aolsoftware.exe"=<br>"C:\\Program Files\\Internet Explorer\\iexplore.exe"=<br>"C:\\Program Files\\AIM6\\aim6.exe"=<br><br>R0 euigmvks;euigmvks;C:\WINDOWS\system32\drivers\egdndhqn.dat []<br>R2 PackethSvc;Virtual NIC Service;C:\WINDOWS\system32\PackethSvc.exe [2001-08-09 16:46]<br>R3 GTIPCI21;GTIPCI21;C:\WINDOWS\system32\DRIVERS\gtipci21.sys [2004-05-03 22:26]<br>S0 Partizan;Partizan;C:\WINDOWS\system32\drivers\Partizan.sys []<br><br>[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{df77db84-283d-11dc-893a-0014a50c1caa}]<br>\Shell\AutoRun\command - E:\setupSNK.exe<br><br>.<br>**************************************************************************<br><br>catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, &raquo;<A HREF="http://www.gmer.net" >www.gmer.net</A><br>Rootkit scan 2008-05-08 15:09:18<br>Windows 5.1.2600 Service Pack 2 NTFS<br><br>scanning hidden processes ... <br><br>scanning hidden autostart entries ...<br><br>scanning hidden files ... <br><br>scan completed successfully<br>hidden files: 0<br><br>**************************************************************************<br><br>[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\euigmvks]<br>"ImagePath"="system32\drivers\egdndhqn.dat"<br>.<br>------------------------ Other Running Processes ------------------------<br>.<br>C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe<br>C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe<br>C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe<br>C:\WINDOWS\system32\WLTRYSVC.EXE<br>C:\WINDOWS\system32\BCMWLTRY.EXE<br>C:\WINDOWS\system32\LEXBCES.EXE<br>C:\WINDOWS\system32\LEXPPS.EXE<br>C:\WINDOWS\system32\scardsvr.exe<br>C:\WINDOWS\system32\BAsfIpM.exe<br>C:\Program Files\Symantec AntiVirus\DefWatch.exe<br>C:\Program Files\Dell\NicConfigSvc\NicConfigSvc.exe<br>C:\Program Files\Symantec AntiVirus\Rtvscan.exe<br>C:\Program Files\Apoint\ApntEx.exe<br>C:\WINDOWS\system32\WLTRAY.EXE<br>C:\WINDOWS\system32\fxssvc.exe<br>C:\Program Files\Symantec AntiVirus\DoScan.exe<br>C:\Program Files\iPod\bin\iPodService.exe<br>.<br>**************************************************************************<br>.<br>Completion time: 2008-05-08 15:15:39 - machine was rebooted<br>ComboFix-quarantined-files.txt  2008-05-08 19:15:31<br><br>Pre-Run: 47,938,162,688 bytes free<br>Post-Run: 47,933,448,192 bytes free<br><br>163&#9;--- E O F ---&#9;2008-04-13 19:56:14<br><br>Malwarebytes' Anti-Malware 1.12<br>Database version: 731<br><br>Scan type: Quick Scan<br>Objects scanned: 34759<br>Time elapsed: 5 minute(s), 33 second(s)<br><br>Memory Processes Infected: 0<br>Memory Modules Infected: 0<br>Registry Keys Infected: 7<br>Registry Values Infected: 1<br>Registry Data Items Infected: 0<br>Folders Infected: 0<br>Files Infected: 2<br><br>Memory Processes Infected:<br>(No malicious items detected)<br><br>Memory Modules Infected:<br>(No malicious items detected)<br><br>Registry Keys Infected:<br>HKEY_CLASSES_ROOT\Interface\{e4e3e0f8-cd30-4380-8ce9-b96904bdefca} (Adware.PopCap) -> Quarantined and deleted successfully.<br>HKEY_CLASSES_ROOT\Interface\{fe8a736f-4124-4d9c-b4b1-3b12381efabe} (Adware.PopCap) -> Quarantined and deleted successfully.<br>HKEY_CLASSES_ROOT\Typelib\{c9c5deaf-0a1f-4660-8279-9edfad6fefe1} (Adware.PopCap) -> Quarantined and deleted successfully.<br>HKEY_CLASSES_ROOT\popcaploader.popcaploaderctrl2 (Adware.PopCap) -> Quarantined and deleted successfully.<br>HKEY_CLASSES_ROOT\popcaploader.popcaploaderctrl2.1 (Adware.PopCap) -> Quarantined and deleted successfully.<br>HKEY_CLASSES_ROOT\CLSID\{df780f87-ff2b-4df8-92d0-73db16a1543a} (Adware.PopCap) -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{df780f87-ff2b-4df8-92d0-73db16a1543a} (Adware.PopCap) -> Quarantined and deleted successfully.<br><br>Registry Values Infected:<br>HKEY_CURRENT_USER\Software\Mozilla\Firefox\Extensions\{59a40ac9-e67d-4155-b31d-4b7330fcd2d6} (Adware.PurityScan) -> Quarantined and deleted successfully.<br><br>Registry Data Items Infected:<br>(No malicious items detected)<br><br>Folders Infected:<br>(No malicious items detected)<br><br>Files Infected:<br>C:\WINDOWS\system32\ClickToFindandFixErrors_US.ico (Malware.Trace) -> Quarantined and deleted successfully.<br>C:\Documents and Settings\Lauren Cortese\Desktop\Click to Find and Fix Errors.url (Rogue.Link) -> Quarantined and deleted successfully.<br><br>Logfile of Trend Micro HijackThis v2.0.2<br>Scan saved at 3:28:03 PM, on 5/8/2008<br>Platform: Windows XP SP2 (WinNT 5.01.2600)<br>MSIE: Internet Explorer v7.00 (7.00.6000.16640)<br>Boot mode: Normal<br><br>Running processes:<br>C:\WINDOWS\System32\smss.exe<br>C:\WINDOWS\system32\winlogon.exe<br>C:\WINDOWS\system32\services.exe<br>C:\WINDOWS\system32\lsass.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe<br>C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe<br>C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe<br>C:\WINDOWS\System32\wltrysvc.exe<br>C:\WINDOWS\System32\bcmwltry.exe<br>C:\WINDOWS\system32\LEXBCES.EXE<br>C:\WINDOWS\system32\spoolsv.exe<br>C:\WINDOWS\system32\LEXPPS.EXE<br>C:\WINDOWS\system32\PackethSvc.exe<br>C:\WINDOWS\system32\basfipm.exe<br>C:\Program Files\Symantec AntiVirus\DefWatch.exe<br>C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe<br>C:\Program Files\Apoint\Apoint.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\WINDOWS\system32\hkcmd.exe<br>C:\Program Files\Symantec AntiVirus\Rtvscan.exe<br>C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe<br>C:\Program Files\Apoint\Apntex.exe<br>C:\Program Files\Dell\QuickSet\quickset.exe<br>C:\WINDOWS\system32\WLTRAY.exe<br>C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe<br>C:\WINDOWS\system32\dla\tfswctrl.exe<br>C:\Program Files\Real\RealPlayer\RealPlay.exe<br>C:\Program Files\iTunes\iTunesHelper.exe<br>C:\Program Files\QuickTime\qttask.exe<br>C:\WINDOWS\system32\LXSUPMON.EXE<br>C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe<br>C:\WINDOWS\system32\fxssvc.exe<br>C:\Program Files\HP\hpcoretech\hpcmpmgr.exe<br>C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe<br>C:\WINDOWS\system32\hphmon05.exe<br>C:\Program Files\Common Files\Symantec Shared\ccApp.exe<br>C:\PROGRA~1\SYMANT~1\VPTray.exe<br>C:\Program Files\Messenger\msmsgs.exe<br>C:\WINDOWS\system32\ctfmon.exe<br>C:\Program Files\Digital Line Detect\DLG.exe<br>C:\Program Files\iPod\bin\iPodService.exe<br>C:\WINDOWS\explorer.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br><br>R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://tumail.temple.edu/" >tumail.temple.edu/</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=69157" >go.microsoft.com/fwlink/?LinkId=69157</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=69157" >go.microsoft.com/fwlink/?LinkId=69157</A><br>R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = ersatz.ocis.temple.edu:8080<br>O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll<br>O2 - BHO: (no name) - {4BF0B7A0-F35A-4DA4-B4EE-06BB4693133E} - C:\WINDOWS\system32\avwa.dll<br>O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br>O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll<br>O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll<br>O2 - BHO: Viewpoint Toolbar BHO - {A7327C09-B521-4EDB-8509-7D2660C9EC98} - C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBarBHO.dll (file missing)<br>O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe<br>O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe<br>O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe<br>O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe<br>O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe<br>O4 - HKLM\..\Run: [Dell Wireless Manager UI] C:\WINDOWS\system32\WLTRAY<br>O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"<br>O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r<br>O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe<br>O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER<br>O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"<br>O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime<br>O4 - HKLM\..\Run: [LXSUPMON] C:\WINDOWS\system32\LXSUPMON.EXE RUN<br>O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe<br>O4 - HKLM\..\Run: [HPHUPD05] C:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe<br>O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"<br>O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe"<br>O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\system32\hphmon05.exe<br>O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"<br>O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe<br>O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background<br>O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br>O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe<br>O4 - Global Startup: Digital Line Detect.lnk = ?<br>O4 - Global Startup: Netscape Connect Tray Icon.lnk = C:\Program Files\wmconnect\wmtray.exe<br>O8 - Extra context menu item: &Viewpoint Search - res://C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBar.dll/CXTSEARCH.HTML<br>O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000<br>O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll<br>O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll<br>O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL<br>O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe<br>O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)<br>O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)<br>O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll<br>O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br>O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br>O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br>O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br>O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file:///C:/Program%20Files/Monopoly/Images/stg_drm.ocx<br>O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - &raquo;<A HREF="http://go.microsoft.com/fwlink/?linkid=39204" >go.microsoft.com/fwlink/?linkid=39204</A><br>O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - &raquo;<A HREF="http://lads.myspace.com/upload/MySpaceUploader1006.cab" >lads.myspace.com/upload/MySpaceU&middot;&middot;&middot;1006.cab</A><br>O16 - DPF: {6F750202-1362-4815-A476-88533DE61D0C} (Kodak Gallery Easy Upload Manager Class) - &raquo;<A HREF="http://www.kodakgallery.com/downloads/BUM/BUM_WIN_IE_2/axofupld.cab" >www.kodakgallery.com/downloads/B&middot;&middot;&middot;upld.cab</A><br>O16 - DPF: {6F750203-1362-4815-A476-88533DE61D0C} (Kodak Gallery Easy Upload Manager Class) - &raquo;<A HREF="http://www.kodakgallery.com/downloads/BUM/BUM_WIN_IE_2/axofupld.cab" >www.kodakgallery.com/downloads/B&middot;&middot;&middot;upld.cab</A><br>O16 - DPF: {9FC5238F-12C4-454F-B1B5-74599A21DE47} (Webshots Photo Uploader) - &raquo;<A HREF="http://community.webshots.com/html/WSPhotoUploader.CAB" >community.webshots.com/html/WSPh&middot;&middot;&middot;ader.CAB</A><br>O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - &raquo;<A HREF="http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab" >cdn2.zone.msn.com/binFramework/v&middot;&middot;&middot;6649.cab</A><br>O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file:///C:/Program%20Files/Monopoly%20Here%20and%20Now/Images/armhelper.ocx<br>O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - &raquo;<A HREF="http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab" >fpdownload2.macromedia.com/get/s&middot;&middot;&middot;lash.cab</A><br>O16 - DPF: {D6E7CFB5-C074-4D1C-B647-663D1A8D96BF} (Facebook Photo Uploader 4) - &raquo;<A HREF="http://upload.facebook.com/controls/FacebookPhotoUploader4_5.cab" >upload.facebook.com/controls/Fac&middot;&middot;&middot;r4_5.cab</A><br>O23 - Service: Broadcom ASF IP monitoring service v6.0.4 (BAsfIpM) - Broadcom Corp. - C:\WINDOWS\system32\basfipm.exe<br>O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe<br>O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe<br>O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe<br>O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe<br>O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe<br>O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE<br>O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE<br>O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe<br>O23 - Service: Virtual NIC Service (PackethSvc) - America Online, Inc. - C:\WINDOWS\system32\PackethSvc.exe<br>O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe<br>O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe<br>O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe<br>O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe<br><br>--<br>End of file - 10483 bytes]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20452298</guid>
<pubDate>Thu, 08 May 2008 16:48:02 EDT</pubDate>
</item>

<item>
<title>Re: [Trojan] AVWA.DLL Removal</title>
<link>http://www.dslreports.com/forum/remark,20452346</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Just wanted to update. After following the instructions I am no longer getting popups from the symantec. Hopefully that means it is removed successfully!]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20452346</guid>
<pubDate>Thu, 08 May 2008 15:43:29 EDT</pubDate>
</item>

<item>
<title>Re: [Trojan] AVWA.DLL Removal</title>
<link>http://www.dslreports.com/forum/remark,20451966</link>
<description><![CDATA[<A HREF="/useremail/u/693977"><b>bcastner</b></A> : <br><b><u>First Steps</u></b><br><b>:!: The following instructions are <u>only</u> for this Forum member. Please do not use these instructions on another computer system. You can seriously damage your system by following the instructions below without guided assistance. You assuredly will make a cleanup of your system more difficult.</b><br><br>Please download<b>  <i>ATF Cleaner</i></b> <br><textarea name="code" class="text" cols=50 rows=10>http://www.atribune.org/ccount/click.php?id=1&#012;</textarea><!--end code block-->It does not require any installation.. It is set up to clean Windows TEMP folders, as well as IE, FireFox and Opera, Temporary Internet Files and Cookies.<br>&#8226;      Double-click <b>ATF-Cleaner.exe</b> to run the program. <br><br><b>First Step:</b><br>&#8226;      Under <b>Main</b> choose: <b>Select All</b><br>&#8226;      Click the <b>Empty Selected</b> button. <br><b><u>Next, if you use Firefox (and <i>some</i> Mozilla-based browsers)</u></b> <br>&#8226;      Click Firefox at the top and choose: <b>Select All</b><br>&#8226;      Click the <b>Empty Selected</b> button. <b><u><br>Next, if you use the Opera browser</u></b> <br>&#8226;      Click <b>Opera</b> at the top and choose: <b>Select All</b> <br>&#8226;      Click the <b>Empty Selected</b> button. <b>:!: Click Exit on the Main menu to close the program.</b><br><br><b>Reconfigure Windows XP to show hidden files:</b><br><i>To enable the viewing of Hidden files follow these steps: </i><br>&#8226; Close all programs so that you are at your desktop. <br>&#8226; Double-click on the My Computer icon. <br>&#8226; Select the Tools menu and click Folder Options. <br>&#8226; After the new window appears select the View tab. <br>&#8226; Put a checkmark in the checkbox labeled Display the contents of system folders. <br>&#8226; Under the Hidden files and folders section select the radio button labeled Show hidden files and folders. <br>&#8226; Remove the checkmark from the checkbox labeled Hide file extensions for known file types. <br>&#8226; Remove the checkmark from the checkbox labeled Hide protected operating system files. <br>&#8226; Press the Apply button and then the OK button and exit My Computer. <br>&#8226; Now your computer is configured to show all hidden files. <br><br><b><u>Malware Removal Steps</u></b><br>1. Open <b>HijackThis</b> again, System scan only.  <b>Checkmark</b> these items:<br><br><b>O2 - BHO: (no name) - {336392C3-5274-06FC-0413-2900BEBC88E8} - (no file)<br>O2 - BHO: (no name) - {4BF0B7A0-F35A-4DA4-B4EE-06BB4693133E} - C:\WINDOWS\system32\avwa.dll<br>O2 - BHO: (no name) - {60827D62-EA88-B556-F549-9C2B5CE48CB9} - (no file)<br>O4 - HKCU\..\Run: [Uxnhamhi] C:\WINDOWS\?dobe\m?config.exe</b><br><br>Click "<b>Fix checked</b>" and when the log panel clears exit HijackThis.<br><br>2. Download -- but <i>do not</i> yet run  -- <b>ComboFix&copy; </b> <br><br>Download this file <b><u>-- to your Desktop --</u></b> [/b]from any of these sources:  <br><textarea name="code" class="text" cols=50 rows=10>http://download.bleepingcomputer.com/sUBs/ComboFix.exe&#012;http://www.forospyware.com/sUBs/ComboFix.exe&#012;http://subs.geekstogo.com/ComboFix.exe&#012;</textarea><!--end code block--><br>Right-click on the header of the Code box below, where on the right side it says:  "<b>Copy to clipboard</b>":<br><textarea name="code" class="text" cols=50 rows=10>KILLALL::&#012; &#012;File::&#012;C:\WINDOWS\system32\avwa.dll&#012; &#012;Registry::&#012;&#91;-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4BF0B7A0-F35A-4DA4-B4EE-06BB4693133E}&#93; &#012;&#91;-HKEY_CLASSES_ROOT\AppID\avwa.dll&#93; &#012;&#91;-HKEY_CLASSES_ROOT\AppID\{4BF0B7A0-F35A-4DA4-B4EE-06BB4693133E}&#93; &#012;&#91;-HKEY_CLASSES_ROOT\CLSID\{4BF0B7A0-F35A-4DA4-B4EE-06BB4693133E}&#93; &#012;&#91;-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4BF0B7A0-F35A-4DA4-B4EE-06BB4693133E}&#93; &#012; &#012;</textarea><!--end code block--><br>Open a new Notepad session - (Do <b><i>not</i></b> use a Word Processor or WordPad).  Click "<b>Format</b>" and be certain that Word Wrap is not enabled.  Right-click | <b>Paste</b> the Code box contents from above into Notepad.  Click File, <b><i>Save as...</i></b>, and set the location to your Desktop, and enter (including quotation marks) as the filename: <b>"CFscript.txt"</b> .  <br><br>&#8226; Disconnect from the Internet.<br>&#8226; Disable your Antivirus.  If the Antivirus software you use has any Script Blocking features, be certain to disable these as well.<br><b> Important:  </b> Have no other programs running.  Your Task Bar should be clear of any program entries including your Browser.<br>&#8226; A window will open with a warning.  Accept any Disclaimers to start the fix.<br>Using your mouse, drag the new file CFscript.txt and drop it on the ComboFix.exe icon as shown in this little picture:<br> <IMG SRC="http://users.pandora.be/bluepatchy/miekiemoes/images/CFScript.gif"> <br><br>When the scan completes Notepad will open with with your results log open. Do a File, Exit and answer 'Yes' to save changes.<br>&#8226;<b>!</b>&#8226; A caution - Do <b>not</b> run Combofix more than once. Do not touch your mouse/keyboard until the scan has completed, as this may cause the process to stall or your computer to lock.<br><br>3. Please download MalwareBytes Anti-malware (MBAM) from one of the following links:<br><textarea name="code" class="text" cols=50 rows=10>http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html&#012;http://www.besttechie.net/tools/mbam-setup.exe&#012;</textarea><!--end code block--><br>Once downloaded, close all programs and Windows on your computer (including this one.)<br><br>Double-click on the icon on your desktop named Download_mbam-setup.exe. This will start the installation of MBAM onto your computer.<br><br>When the installation begins, keep following the prompts in order to continue with the installation process. Do not make any changes to default settings and when the program has finished installing, make sure you leave both the Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware checked. Then click on the Finish button.<br><br>MBAM will now automatically start and you will see a message stating that you should update the program before performing a scan. As MBAM will automatically update itself after the install, you can press the OK button to close that box and you will now be at the main program.<br><br>On the <b>Scanner tab</b>, make sure the the <b>Perform quick scan</b> option is selected and then click on the <b>Scan</b> button to start scanning your computer.<br><br>MBAM will now start scanning your computer for malware. This process can take quite a while, so we suggest you go and do something else and periodically check on the status of the scan. <br><br>When the scan is finished a message box will appear that it has completed scanning successfully.  Click <b>OK</b>.  Now click <b>Show Results</b>.  Make sure all entries have a checkmark at their far left.  You should now click on the <b>Remove Selected</b> button to remove all the listed malware. MBAM will now delete all of the files and registry keys and add them to the programs quarantine.<br><br>When MBAM has finished removing the malware, it will open the scan log and display it in Notepad. Review the log as desired, and then close the Notepad window.  Remember where you saved the log file, as we will want to see it later.<br><br>4. Run <b>HijackThis</b> again, and save the log file.<br><br><b><i>Submit to the Forum:</i></b><br>&#8226; The contents of C:\Combofix.txt;<br>&#8226; The contents of the <b>MBAM</b> log;<br>&#8226; The new HijackThis log.<br><br><small>--<br><b>============</b><br><b>MS-MVP 2004 - -2008, ASAP Member</b><br><b><i>Users Helping Users</i></b><br><br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20451966</guid>
<pubDate>Thu, 08 May 2008 14:23:01 EDT</pubDate>
</item>

<item>
<title>Re: [Trojan] AVWA.DLL Removal</title>
<link>http://www.dslreports.com/forum/remark,20451367</link>
<description><![CDATA[<A HREF="/useremail/u/243195"><b>fatness</b></A> : Rob18, I was about to approve your post and I hit the wrong button, deleting it accidentally. I apologize. Here is the full text of it:<br><br>==============================================<br>Re: [Trojan] AVWA.DLL Removal<br><br>Also here is my HiJackThis log. Any help is really appreciated:<br><br>Logfile of Trend Micro HijackThis v2.0.2<br>Scan saved at 12:13:43 PM, on 5/8/2008<br>Platform: Windows XP SP2 (WinNT 5.01.2600)<br>MSIE: Internet Explorer v7.00 (7.00.6000.16640)<br>Boot mode: Normal<br><br>Running processes:<br>C:\WINDOWS\System32\smss.exe<br>C:\WINDOWS\system32\winlogon.exe<br>C:\WINDOWS\system32\services.exe<br>C:\WINDOWS\system32\lsass.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\WINDOWS\Explorer.EXE<br>C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe<br>C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe<br>C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe<br>C:\WINDOWS\System32\wltrysvc.exe<br>C:\WINDOWS\System32\bcmwltry.exe<br>C:\WINDOWS\system32\LEXBCES.EXE<br>C:\WINDOWS\system32\spoolsv.exe<br>C:\WINDOWS\system32\LEXPPS.EXE<br>C:\WINDOWS\system32\PackethSvc.exe<br>C:\WINDOWS\system32\basfipm.exe<br>C:\Program Files\Symantec AntiVirus\DefWatch.exe<br>C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\Program Files\Symantec AntiVirus\Rtvscan.exe<br>C:\Program Files\Apoint\Apoint.exe<br>C:\WINDOWS\system32\hkcmd.exe<br>C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe<br>C:\Program Files\Dell\QuickSet\quickset.exe<br>C:\WINDOWS\system32\WLTRAY.exe<br>C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe<br>C:\WINDOWS\system32\dla\tfswctrl.exe<br>C:\Program Files\Real\RealPlayer\RealPlay.exe<br>C:\Program Files\iTunes\iTunesHelper.exe<br>C:\Program Files\Apoint\Apntex.exe<br>C:\Program Files\QuickTime\qttask.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\WINDOWS\system32\LXSUPMON.EXE<br>C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe<br>C:\Program Files\HP\hpcoretech\hpcmpmgr.exe<br>C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe<br>C:\WINDOWS\system32\hphmon05.exe<br>C:\Program Files\Common Files\Symantec Shared\ccApp.exe<br>C:\PROGRA~1\SYMANT~1\VPTray.exe<br>C:\Program Files\Messenger\msmsgs.exe<br>C:\Program Files\iPod\bin\iPodService.exe<br>C:\WINDOWS\system32\ctfmon.exe<br>C:\Program Files\Digital Line Detect\DLG.exe<br>C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br><br>R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &raquo;www.dell.com<br>R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;tumail.temple.edu/<br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &raquo;go.microsoft.com/fwlink/?LinkId=69157<br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &raquo;go.microsoft.com/fwlink/?LinkId=54896<br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &raquo;go.microsoft.com/fwlink/?LinkId=54896<br>R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;go.microsoft.com/fwlink/?LinkId=69157<br>R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = ersatz.ocis.temple.edu:8080<br>O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll<br>O2 - BHO: (no name) - {336392C3-5274-06FC-0413-2900BEBC88E8} - (no file)<br>O2 - BHO: (no name) - {4BF0B7A0-F35A-4DA4-B4EE-06BB4693133E} - C:\WINDOWS\system32\avwa.dll<br>O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br>O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll<br>O2 - BHO: (no name) - {60827D62-EA88-B556-F549-9C2B5CE48CB9} - (no file)<br>O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll<br>O2 - BHO: Viewpoint Toolbar BHO - {A7327C09-B521-4EDB-8509-7D2660C9EC98} - C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBarBHO.dll (file missing)<br>O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe<br>O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe<br>O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe<br>O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe<br>O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe<br>O4 - HKLM\..\Run: [Dell Wireless Manager UI] C:\WINDOWS\system32\WLTRAY<br>O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"<br>O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r<br>O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe<br>O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER<br>O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"<br>O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime<br>O4 - HKLM\..\Run: [LXSUPMON] C:\WINDOWS\system32\LXSUPMON.EXE RUN<br>O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe<br>O4 - HKLM\..\Run: [HPHUPD05] C:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe<br>O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"<br>O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe"<br>O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\system32\hphmon05.exe<br>O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"<br>O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe<br>O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background<br>O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br>O4 - HKCU\..\Run: [Uxnhamhi] C:\WINDOWS\?dobe\m?config.exe<br>O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe<br>O4 - Global Startup: Digital Line Detect.lnk = ?<br>O4 - Global Startup: Netscape Connect Tray Icon.lnk = C:\Program Files\wmconnect\wmtray.exe<br>O8 - Extra context menu item: &Viewpoint Search - res://C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBar.dll/CXTSEARCH.HTML<br>O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000<br>O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll<br>O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll<br>O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL<br>O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe<br>O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)<br>O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)<br>O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll<br>O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br>O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br>O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br>O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br>O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file:///C:/Program%20Files/Monopoly/Images/stg_drm.ocx<br>O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - &raquo;go.microsoft.com/fwlink/?linkid=39204<br>O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - &raquo;lads.myspace.com/upload/MySpaceU&middot;&middot;&middot;1006.cab<br>O16 - DPF: {6F750202-1362-4815-A476-88533DE61D0C} (Kodak Gallery Easy Upload Manager Class) - &raquo;www.kodakgallery.com/downloads/B&middot;&middot;&middot;upld.cab<br>O16 - DPF: {6F750203-1362-4815-A476-88533DE61D0C} (Kodak Gallery Easy Upload Manager Class) - &raquo;www.kodakgallery.com/downloads/B&middot;&middot;&middot;upld.cab<br>O16 - DPF: {9FC5238F-12C4-454F-B1B5-74599A21DE47} (Webshots Photo Uploader) - &raquo;community.webshots.com/html/WSPh&middot;&middot;&middot;ader.CAB<br>O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - &raquo;cdn2.zone.msn.com/binFramework/v&middot;&middot;&middot;6649.cab<br>O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file:///C:/Program%20Files/Monopoly%20Here%20and%20Now/Images/armhelper.ocx<br>O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - &raquo;fpdownload2.macromedia.com/get/s&middot;&middot;&middot;lash.cab<br>O16 - DPF: {D6E7CFB5-C074-4D1C-B647-663D1A8D96BF} (Facebook Photo Uploader 4) - &raquo;upload.facebook.com/controls/Fac&middot;&middot;&middot;r4_5.cab<br>O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - &raquo;download.games.yahoo.com/games/w&middot;&middot;&middot;r_v6.cab<br>O23 - Service: Broadcom ASF IP monitoring service v6.0.4 (BAsfIpM) - Broadcom Corp. - C:\WINDOWS\system32\basfipm.exe<br>O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe<br>O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe<br>O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe<br>O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe<br>O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe<br>O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE<br>O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE<br>O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe<br>O23 - Service: Virtual NIC Service (PackethSvc) - America Online, Inc. - C:\WINDOWS\system32\PackethSvc.exe<br>O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe<br>O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe<br>O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe<br>O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe<br><br>--<br>End of file - 10913 bytes<br>====================================<br><small>--<br><A HREF="http://www.livescience.com/animals/071218-monkey-call.html">Female monkeys often utter loud, distinctive calls before, during or after sex.<a>.</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20451367</guid>
<pubDate>Thu, 08 May 2008 12:29:28 EDT</pubDate>
</item>

<item>
<title>[Trojan] AVWA.DLL Removal</title>
<link>http://www.dslreports.com/forum/remark,20450834</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : I have some kind of process that is recognized by Symantec as AVWA.dll. Symantec recognizes it and it pops up constantly, but it cannot remove it. So far I have tried a few programs and nothing removes it. Any help would be greatly appreciated.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20450834</guid>
<pubDate>Thu, 08 May 2008 10:50:57 EDT</pubDate>
</item>

</channel>
</rss>
