<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>[Vundo] Vundo Infection in Security Cleanup</title>
<link>http://www.dslreports.com/forum/r20477044</link>
<description></description>
<language>en</language>
<pubDate>Fri, 10 Oct 2008 14:47:28 EDT</pubDate>
<lastBuildDate>Fri, 10 Oct 2008 14:47:28 EDT</lastBuildDate>

<item>
<title>Re: [Vundo] Vundo Infection</title>
<link>http://www.dslreports.com/forum/remark,20491710</link>
<description><![CDATA[<A HREF="/useremail/u/679515"><b>CalamityJane</b></A> : What we removed was mostly Vundo related.  It doesn't usually involve a keylogger (and the logs you posted didn't show signs of one), but I don't know what the other pre-cleaning you used may have removed.<br><br>Some final cleanup and prevention recommendations follow.<br><br>This step will uninstall the ComboFix tool, delete any remaining quarantined files, and reset your Windows Folder options to default (to rehide operating system files, etc), since it isn't needed anymore:<br><br>Click Start, then click Run.<br>Enter into the command box that opens: <b>combofix /u</b> and then click OK.<br><br>Do a disk cleanup.  Go to Start > Run and type in the box:  <b>Cleanmgr</b><br>Wait while Windows scans your system for files to delete.<br>Make sure these 3 are checkmarked and press *ok* to delete them.<br><br>Temporary Files<br>Temporary Internet Files<br>Recycle Bin<br><br>Now that your PC is clean, make sure all programs are running properly and then you'll need to reset your restore point in Windows XP.......why?<br><br>One of the best features of Windows ME or XP is the System Restore option, however if a malware infects a computer with this operating system it can be backed up in the System Restore folder.  Therefore, clearing the restore points is necessary after malware removal.<br><br>To reset your restore points, please note that you will need to log into your computer with an account which has full administrator access. You will know if the account has administrator access because you will be able to see the System Restore tab. If the tab is missing, you are logged in under a limited account. <br><br>(winXP)<br><br>1.  Turn off System Restore.<br>Go to Start and right-click on *My Computer*.<br>Click Properties.<br>Click the System Restore tab.<br>Put a Checkmark in the box next to "Turn off System Restore".<br>Click Apply, and then click OK.<br><br>2.  Reboot.<br><br>3.  Turn ON System Restore.<br>Go to Start and right-click on *My Computer*.<br>Click Properties.<br>Click the System Restore tab.<br>Remove the checkmark next to "Turn off System Restore".<br>Click Apply, and then click OK.<br><br>How to Turn On and Turn Off System Restore in Windows XP<br>&raquo;<A HREF="http://support.microsoft.com/default.aspx?scid=kb;en-us;310405" >support.microsoft.com/default.as&middot;&middot;&middot;s;310405</A><br>......................<br><br>Also, I can't stress enough the importance of having your Windows critical Security Updates.  Most malware today uses exploits on unpatched systems to creep onto your system without your even doing anything but visiting an infected webpage!!<br>Make sure that you keep your Operating System and IE updated with the latest Critical Security Updates from Microsoft...they usually come out once a month, on the 2nd Tuesday of each month.  This is the first step in malware prevention, as many nasties now take advantage of new exploits and if not patched, you are vulnerable!<br>Windows Update<br>&raquo;<A HREF="http://update.microsoft.com/microsoftupdate/" >update.microsoft.com/microsoftupdate/</A><br><br>Watch what you download, be careful where you surf, and don't trust attachments or even links in email and Instant messages.  Even if they come from a buddy, that buddy could be the one infected and it is the virus sending that link from his account.  You click on it thinking he is trusted, and *boom* you're infected.<br>Many "Phishing" attempts are made by cleverly crafted email to look like it is coming from an "official" source (like Microsoft, or your bank, or some other provider).  Don't click on links in those.  Go directly to the site instead and navigate the menus - don't trust email you think came from a "safe source" unless you are expecting it!  There is more in the link I will provide below, but those are the choice avenues of infection these days.<br>Stay far AWAY from cracks and warez sites - you're sure to get infected files there, and the same can be said for files downloaded from p2p (more than half are usually infected and probably not detectable by your current security software - the newest nasties are always released in those venues).<br><br>A word about shared computers and networks.<br>Share Your PC<br>&raquo;<A HREF="http://www.microsoft.com/windowsxp/using/setup/learnmore/share/intro.mspx" >www.microsoft.com/windowsxp/usin&middot;&middot;&middot;tro.mspx</A><br>Not all users need to have Admin Accounts.  It is much safer to have most of your users on a shared system running as Limited User accounts.  That way, if there is "an accident", it will only affect one user's account and not the entire system.<br><br>I also highly recommend to get the free tool, Microsoft Baseline Security Analyzer (MBSA) from Microsoft to analyze your PC security for prevention purposes. <br><br>MBSA Version 2.0  will scan for common system misconfigurations on Windows 2000, Windows XP, and Windows Server 2003 systems.  This program will identify the system security weaknesses in your browser and operating system and provides easy instructions to correct them.  This includes any missing critical Windows security updates, system vulnerabilities and your IE Browser security settings.  Get the download here:<br>Microsoft Baseline Security Analyzer <br>&raquo;<A HREF="http://www.microsoft.com/technet/security/tools/mbsahome.mspx" >www.microsoft.com/technet/securi&middot;&middot;&middot;ome.mspx</A><br>Choose MBSAsetup-EN.msi = (English Version) or the language appropriate for you.<br><small>--<br>It takes a disaster to make a woman out of a female<br>Microsoft MVP/Windows Security 2003-2008<br>Proud Member of <A HREF="http://asap.maddoktor2.com/">ASAP </a> (Alliance of Security Analysis Professionals)</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20491710</guid>
<pubDate>Fri, 16 May 2008 08:32:21 EDT</pubDate>
</item>

<item>
<title>Re: [Vundo] Vundo Infection</title>
<link>http://www.dslreports.com/forum/remark,20489110</link>
<description><![CDATA[<A HREF="/useremail/u/999223"><b>fundamentalz</b></A> : <div class="bquote"><small>said by  CalamityJane <A HREF="/useremail/u/679515"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>Looks good now :)<br><br>How is your computer acting at this point?<br><br>Don't forget to turn back on your Security Programs.<br> </div>It feels like things are back to normal now. Thanks a lot.<br>By the way, do you know what it was that I was infected with, such as a keylogger?<br><br>Anyways, your efforts are very much appreciated.<br><small>--<br>I subscribe to the theory of intellectual osmosis. Unfortunately, I must now cease our conversation and move away from you before my intelligence begins to drop. Good day.</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20489110</guid>
<pubDate>Thu, 15 May 2008 18:38:44 EDT</pubDate>
</item>

<item>
<title>Re: [Vundo] Vundo Infection</title>
<link>http://www.dslreports.com/forum/remark,20488299</link>
<description><![CDATA[<A HREF="/useremail/u/679515"><b>CalamityJane</b></A> : Looks good now :)<br><br>How is your computer acting at this point?<br><br>Don't forget to turn back on your Security Programs.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20488299</guid>
<pubDate>Thu, 15 May 2008 16:26:50 EDT</pubDate>
</item>

<item>
<title>Re: [Vundo] Vundo Infection</title>
<link>http://www.dslreports.com/forum/remark,20487767</link>
<description><![CDATA[<A HREF="/useremail/u/999223"><b>fundamentalz</b></A> : ComboFix 08-05-12.1 - Hady 2008-05-15 11:31:14.2 - NTFSx86<br>Microsoft Windows XP Professional  5.1.2600.2.1252.1.1033.18.1498 [GMT -7:00]<br>Running from: C:\Documents and Settings\Hady\Desktop\ComboFix.exe<br>Command switches used :: C:\Documents and Settings\Hady\Desktop\CFScript.txt<br> * Created a new restore point<br> * Resident AV is active<br><br>FILE ::<br>C:\WINDOWS\BM671f7a6f.xml<br>C:\WINDOWS\system32\d3d9caps.dat<br>C:\WINDOWS\system32\myancbov.dll<br>C:\WINDOWS\system32\yalhhjii.dll<br>.<br><br>(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br><br>C:\WINDOWS\BM671f7a6f.xml<br>C:\WINDOWS\system32\d3d9caps.dat<br><br>.<br>(((((((((((((((((((((((((   Files Created from 2008-04-15 to 2008-05-15  )))))))))))))))))))))))))))))))<br>.<br><br>2008-05-14 20:13 . 2008-05-14 20:13&#9;1,024&#9;--ah-----&#9;C:\WINDOWS\system32\config\systemprofile\ntuser.dat.LOG<br>2008-05-13 14:59 . 2008-05-13 14:59&#9;&#9;d--------&#9;C:\Program Files\Trend Micro<br>2008-05-12 23:34 . 2008-05-12 23:36&#9;&#9;d--------&#9;C:\Program Files\EsetOnlineScanner<br>2008-05-12 22:36 . 2008-05-12 22:37&#9;&#9;d--------&#9;C:\Program Files\Mozilla Firefox 3 Beta 5<br>2008-04-21 18:39 . 2008-04-21 18:39&#9;&#9;d--------&#9;C:\Program Files\Hamachi<br>2008-04-21 18:39 . 2008-04-21 21:15&#9;&#9;d--------&#9;C:\Documents and Settings\Hady\Application Data\Hamachi<br>2008-04-21 18:39 . 2008-04-21 18:39&#9;25,280&#9;--a------&#9;C:\WINDOWS\system32\drivers\hamachi.sys<br>2008-04-16 20:26 . 2008-04-18 20:17&#9;&#9;d--------&#9;C:\Documents and Settings\All Users\Application Data\TrackMania<br>2008-04-16 20:10 . 2008-04-16 20:10&#9;&#9;d--------&#9;C:\VundoFix Backups<br>2008-04-16 20:01 . 2008-04-16 20:03&#9;&#9;d--------&#9;C:\Program Files\Windows Live Safety Center<br>2008-04-16 19:29 . 2008-04-16 19:55&#9;500&#9;--a------&#9;C:\WINDOWS\wininit.ini<br>2008-04-16 18:58 . 2008-04-16 18:58&#9;&#9;d--------&#9;C:\Program Files\Spybot - Search & Destroy<br>2008-04-16 18:58 . 2008-04-16 19:04&#9;&#9;d--------&#9;C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy<br>2008-04-15 13:19 . 2008-04-15 13:19&#9;&#9;d--------&#9;C:\Program Files\Common Files\Macrovision Shared<br>2008-04-15 13:19 . 2008-04-15 13:19&#9;&#9;d--------&#9;C:\Documents and Settings\All Users\Application Data\FLEXnet<br><br>.<br>((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br>2008-05-15 18:35&#9;53,184,800&#9;--sha-w&#9;C:\WINDOWS\system32\drivers\fidbox.dat<br>2008-05-15 18:34&#9;1,645,344&#9;--sha-w&#9;C:\WINDOWS\system32\drivers\fidbox2.dat<br>2008-05-15 08:33&#9;718,820&#9;--sha-w&#9;C:\WINDOWS\system32\drivers\fidbox.idx<br>2008-05-15 08:33&#9;191,624&#9;--sha-w&#9;C:\WINDOWS\system32\drivers\fidbox2.idx<br>2008-05-15 03:22&#9;---------&#9;d-----w&#9;C:\Program Files\Kaspersky Lab<br>2008-05-14 20:37&#9;---------&#9;d-----w&#9;C:\Program Files\Digsby<br>2008-05-14 09:22&#9;---------&#9;d-----w&#9;C:\Documents and Settings\Hady\Application Data\Azureus<br>2008-05-01 06:51&#9;---------&#9;d-----w&#9;C:\Documents and Settings\Hady\Application Data\Skype<br>2008-04-30 23:40&#9;---------&#9;d-----w&#9;C:\Documents and Settings\Hady\Application Data\skypePM<br>2008-04-17 03:00&#9;---------&#9;d-----w&#9;C:\Program Files\Common Files\Wise Installation Wizard<br>2008-04-17 01:27&#9;---------&#9;d-----w&#9;C:\Documents and Settings\Hady\Application Data\Move Networks<br>2008-04-15 20:19&#9;---------&#9;d-----w&#9;C:\Program Files\Common Files\Adobe<br>2008-04-14 23:40&#9;32&#9;----a-w&#9;C:\Documents and Settings\All Users\Application Data\ezsid.dat<br>2008-04-14 23:38&#9;---------&#9;d-----w&#9;C:\Program Files\Skype<br>2008-04-14 23:38&#9;---------&#9;d-----w&#9;C:\Program Files\Common Files\Skype<br>2008-04-14 23:38&#9;---------&#9;d-----w&#9;C:\Documents and Settings\All Users\Application Data\Skype<br>2008-04-12 21:34&#9;---------&#9;d-----w&#9;C:\Documents and Settings\Hady\Application Data\Digsby<br>2008-04-10 16:14&#9;---------&#9;d--h--w&#9;C:\Program Files\InstallShield Installation Information<br>2008-04-10 16:14&#9;---------&#9;d-----w&#9;C:\Program Files\THQ<br>2008-04-10 16:12&#9;---------&#9;d-----w&#9;C:\Program Files\Gadwin Systems<br>2008-04-09 14:48&#9;---------&#9;d-----w&#9;C:\Program Files\Java<br>2008-04-08 22:19&#9;---------&#9;d-----w&#9;C:\Documents and Settings\Hady\Application Data\SEGA<br>2008-04-08 22:18&#9;---------&#9;d-----w&#9;C:\Program Files\Sonic<br>2008-04-08 19:19&#9;22,328&#9;----a-w&#9;C:\WINDOWS\system32\drivers\PnkBstrK.sys<br>2008-04-08 19:19&#9;107,832&#9;----a-w&#9;C:\WINDOWS\system32\PnkBstrB.exe<br>2008-03-29 03:59&#9;43,520&#9;----a-w&#9;C:\WINDOWS\system32\CmdLineExt03.dll<br>2008-03-27 08:12&#9;151,583&#9;----a-w&#9;C:\WINDOWS\system32\msjint40.dll<br>2008-03-19 09:47&#9;1,845,248&#9;----a-w&#9;C:\WINDOWS\system32\win32k.sys<br>2008-03-15 02:22&#9;21,840&#9;----atw&#9;C:\WINDOWS\system32\SIntfNT.dll<br>2008-03-15 02:22&#9;17,212&#9;----atw&#9;C:\WINDOWS\system32\SIntf32.dll<br>2008-03-15 02:22&#9;12,067&#9;----atw&#9;C:\WINDOWS\system32\SIntf16.dll<br>2008-03-15 02:09&#9;94,208&#9;----a-w&#9;C:\WINDOWS\DIIUnin.exe<br>2008-03-15 02:09&#9;2,829&#9;----a-w&#9;C:\WINDOWS\DIIUnin.pif<br>2008-03-01 13:06&#9;826,368&#9;----a-w&#9;C:\WINDOWS\system32\wininet.dll<br>2008-02-20 06:51&#9;282,624&#9;----a-w&#9;C:\WINDOWS\system32\gdi32.dll<br>2008-02-20 05:32&#9;45,568&#9;----a-w&#9;C:\WINDOWS\system32\dnsrslvr.dll<br>2007-12-17 08:08&#9;22,328&#9;----a-w&#9;C:\Documents and Settings\Hady\Application Data\PnkBstrK.sys<br>.<br><br>(((((((((((((((((((((((((((((   snapshot@2008-05-14_20.22.10.39   )))))))))))))))))))))))))))))))))))))))))<br>.<br>+ 2008-01-23 04:56:21&#9;554,008&#9;----a-w&#9;C:\WINDOWS\$hf_mig$\KB950749\SP2QFE\dao360.dll<br>+ 2007-12-10 12:41:11&#9;518,944&#9;----a-w&#9;C:\WINDOWS\$hf_mig$\KB950749\SP2QFE\msexch40.dll<br>+ 2007-12-10 12:41:11&#9;326,432&#9;----a-w&#9;C:\WINDOWS\$hf_mig$\KB950749\SP2QFE\msexcl40.dll<br>+ 2007-12-10 12:41:11&#9;1,516,568&#9;----a-w&#9;C:\WINDOWS\$hf_mig$\KB950749\SP2QFE\msjet40.dll<br>+ 2007-12-10 12:41:11&#9;355,112&#9;----a-w&#9;C:\WINDOWS\$hf_mig$\KB950749\SP2QFE\msjetol1.dll<br>+ 2008-03-27 07:39:13&#9;151,583&#9;----a-w&#9;C:\WINDOWS\$hf_mig$\KB950749\SP2QFE\msjint40.dll<br>+ 2007-12-10 12:41:12&#9;60,192&#9;----a-w&#9;C:\WINDOWS\$hf_mig$\KB950749\SP2QFE\msjter40.dll<br>+ 2007-12-10 12:41:12&#9;248,608&#9;----a-w&#9;C:\WINDOWS\$hf_mig$\KB950749\SP2QFE\msjtes40.dll<br>+ 2007-12-10 12:41:12&#9;219,936&#9;----a-w&#9;C:\WINDOWS\$hf_mig$\KB950749\SP2QFE\msltus40.dll<br>+ 2007-12-10 12:41:12&#9;355,104&#9;----a-w&#9;C:\WINDOWS\$hf_mig$\KB950749\SP2QFE\mspbde40.dll<br>+ 2007-12-10 12:41:13&#9;432,928&#9;----a-w&#9;C:\WINDOWS\$hf_mig$\KB950749\SP2QFE\msrd2x40.dll<br>+ 2007-12-10 12:41:13&#9;322,336&#9;----a-w&#9;C:\WINDOWS\$hf_mig$\KB950749\SP2QFE\msrd3x40.dll<br>+ 2007-12-10 12:41:13&#9;559,904&#9;----a-w&#9;C:\WINDOWS\$hf_mig$\KB950749\SP2QFE\msrepl40.dll<br>+ 2007-12-10 12:41:13&#9;264,992&#9;----a-w&#9;C:\WINDOWS\$hf_mig$\KB950749\SP2QFE\mstext40.dll<br>+ 2007-12-10 12:41:13&#9;838,432&#9;----a-w&#9;C:\WINDOWS\$hf_mig$\KB950749\SP2QFE\mswdat10.dll<br>+ 2007-12-10 12:41:14&#9;621,344&#9;----a-w&#9;C:\WINDOWS\$hf_mig$\KB950749\SP2QFE\mswstr10.dll<br>+ 2007-12-10 12:41:14&#9;355,104&#9;----a-w&#9;C:\WINDOWS\$hf_mig$\KB950749\SP2QFE\msxbde40.dll<br>+ 2007-03-06 01:22:36&#9;14,048&#9;----a-w&#9;C:\WINDOWS\$hf_mig$\KB950749\spmsg.dll<br>+ 2007-03-06 01:22:41&#9;213,216&#9;----a-w&#9;C:\WINDOWS\$hf_mig$\KB950749\spuninst.exe<br>+ 2007-03-06 01:22:34&#9;22,752&#9;----a-w&#9;C:\WINDOWS\$hf_mig$\KB950749\update\spcustom.dll<br>+ 2007-03-06 01:22:59&#9;716,000&#9;----a-w&#9;C:\WINDOWS\$hf_mig$\KB950749\update\update.exe<br>+ 2007-03-06 01:23:51&#9;371,424&#9;----a-w&#9;C:\WINDOWS\$hf_mig$\KB950749\update\updspapi.dll<br>- 2008-05-15 03:17:10&#9;2,048&#9;--s-a-w&#9;C:\WINDOWS\bootstat.dat<br>+ 2008-05-15 18:18:42&#9;2,048&#9;--s-a-w&#9;C:\WINDOWS\bootstat.dat<br>- 2004-08-04 04:56:44&#9;561,179&#9;-c--a-w&#9;C:\WINDOWS\system32\dllcache\dao360.dll<br>+ 2008-03-25 04:50:25&#9;554,008&#9;-c--a-w&#9;C:\WINDOWS\system32\dllcache\dao360.dll<br>- 2004-08-04 04:56:44&#9;512,029&#9;-c--a-w&#9;C:\WINDOWS\system32\dllcache\msexch40.dll<br>+ 2008-03-25 04:50:28&#9;518,944&#9;-c--a-w&#9;C:\WINDOWS\system32\dllcache\msexch40.dll<br>- 2004-08-04 04:56:44&#9;319,517&#9;-c--a-w&#9;C:\WINDOWS\system32\dllcache\msexcl40.dll<br>+ 2008-03-25 04:50:30&#9;326,432&#9;-c--a-w&#9;C:\WINDOWS\system32\dllcache\msexcl40.dll<br>- 2004-08-04 04:56:44&#9;1,507,356&#9;-c--a-w&#9;C:\WINDOWS\system32\dllcache\msjet40.dll<br>+ 2008-03-25 04:50:34&#9;1,516,568&#9;-c--a-w&#9;C:\WINDOWS\system32\dllcache\msjet40.dll<br>- 2004-07-17 15:34:48&#9;358,976&#9;-c--a-w&#9;C:\WINDOWS\system32\dllcache\msjetol1.dll<br>+ 2008-03-25 04:50:40&#9;355,112&#9;-c--a-w&#9;C:\WINDOWS\system32\dllcache\msjetol1.dll<br>- 2004-08-04 04:56:44&#9;151,583&#9;-c--a-w&#9;C:\WINDOWS\system32\dllcache\msjint40.dll<br>+ 2008-03-27 08:12:54&#9;151,583&#9;-c--a-w&#9;C:\WINDOWS\system32\dllcache\msjint40.dll<br>- 2004-08-04 04:56:44&#9;53,279&#9;-c--a-w&#9;C:\WINDOWS\system32\dllcache\msjter40.dll<br>+ 2008-03-25 04:50:42&#9;60,192&#9;-c--a-w&#9;C:\WINDOWS\system32\dllcache\msjter40.dll<br>- 2004-08-04 04:56:44&#9;241,693&#9;-c--a-w&#9;C:\WINDOWS\system32\dllcache\msjtes40.dll<br>+ 2008-03-25 04:50:42&#9;248,608&#9;-c--a-w&#9;C:\WINDOWS\system32\dllcache\msjtes40.dll<br>- 2004-08-04 04:56:44&#9;213,023&#9;-c--a-w&#9;C:\WINDOWS\system32\dllcache\msltus40.dll<br>+ 2008-03-25 04:50:44&#9;219,936&#9;-c--a-w&#9;C:\WINDOWS\system32\dllcache\msltus40.dll<br>- 2004-08-04 04:56:44&#9;348,189&#9;-c--a-w&#9;C:\WINDOWS\system32\dllcache\mspbde40.dll<br>+ 2008-03-25 04:50:45&#9;355,104&#9;-c--a-w&#9;C:\WINDOWS\system32\dllcache\mspbde40.dll<br>- 2004-08-04 04:56:44&#9;421,919&#9;-c--a-w&#9;C:\WINDOWS\system32\dllcache\msrd2x40.dll<br>+ 2008-03-25 04:50:47&#9;432,928&#9;-c--a-w&#9;C:\WINDOWS\system32\dllcache\msrd2x40.dll<br>- 2004-08-04 04:56:44&#9;315,423&#9;-c--a-w&#9;C:\WINDOWS\system32\dllcache\msrd3x40.dll<br>+ 2008-03-25 04:50:49&#9;322,336&#9;-c--a-w&#9;C:\WINDOWS\system32\dllcache\msrd3x40.dll<br>- 2004-08-04 04:56:44&#9;552,989&#9;-c--a-w&#9;C:\WINDOWS\system32\dllcache\msrepl40.dll<br>+ 2008-03-25 04:50:52&#9;559,904&#9;-c--a-w&#9;C:\WINDOWS\system32\dllcache\msrepl40.dll<br>- 2004-08-04 04:56:44&#9;258,077&#9;-c--a-w&#9;C:\WINDOWS\system32\dllcache\mstext40.dll<br>+ 2008-03-25 04:50:55&#9;264,992&#9;-c--a-w&#9;C:\WINDOWS\system32\dllcache\mstext40.dll<br>- 2004-08-04 04:56:46&#9;831,519&#9;-c--a-w&#9;C:\WINDOWS\system32\dllcache\mswdat10.dll<br>+ 2008-03-25 04:50:57&#9;838,432&#9;-c--a-w&#9;C:\WINDOWS\system32\dllcache\mswdat10.dll<br>- 2004-08-04 04:56:46&#9;614,429&#9;-c--a-w&#9;C:\WINDOWS\system32\dllcache\mswstr10.dll<br>+ 2008-03-25 04:50:58&#9;621,344&#9;-c--a-w&#9;C:\WINDOWS\system32\dllcache\mswstr10.dll<br>- 2004-08-04 04:56:46&#9;348,189&#9;-c--a-w&#9;C:\WINDOWS\system32\dllcache\msxbde40.dll<br>+ 2008-03-25 04:50:58&#9;355,104&#9;-c--a-w&#9;C:\WINDOWS\system32\dllcache\msxbde40.dll<br>- 2004-08-04 04:56:44&#9;512,029&#9;----a-w&#9;C:\WINDOWS\system32\msexch40.dll<br>+ 2008-03-25 04:50:28&#9;518,944&#9;----a-w&#9;C:\WINDOWS\system32\msexch40.dll<br>- 2004-08-04 04:56:44&#9;319,517&#9;----a-w&#9;C:\WINDOWS\system32\msexcl40.dll<br>+ 2008-03-25 04:50:30&#9;326,432&#9;----a-w&#9;C:\WINDOWS\system32\msexcl40.dll<br>- 2004-08-04 04:56:44&#9;1,507,356&#9;----a-w&#9;C:\WINDOWS\system32\msjet40.dll<br>+ 2008-03-25 04:50:34&#9;1,516,568&#9;----a-w&#9;C:\WINDOWS\system32\msjet40.dll<br>- 2004-07-17 15:34:48&#9;358,976&#9;----a-w&#9;C:\WINDOWS\system32\msjetoledb40.dll<br>+ 2008-03-25 04:50:40&#9;355,112&#9;----a-w&#9;C:\WINDOWS\system32\msjetoledb40.dll<br>- 2004-08-04 04:56:44&#9;53,279&#9;----a-w&#9;C:\WINDOWS\system32\msjter40.dll<br>+ 2008-03-25 04:50:42&#9;60,192&#9;----a-w&#9;C:\WINDOWS\system32\msjter40.dll<br>- 2004-08-04 04:56:44&#9;241,693&#9;----a-w&#9;C:\WINDOWS\system32\msjtes40.dll<br>+ 2008-03-25 04:50:42&#9;248,608&#9;----a-w&#9;C:\WINDOWS\system32\msjtes40.dll<br>- 2004-08-04 04:56:44&#9;213,023&#9;----a-w&#9;C:\WINDOWS\system32\msltus40.dll<br>+ 2008-03-25 04:50:44&#9;219,936&#9;----a-w&#9;C:\WINDOWS\system32\msltus40.dll<br>- 2004-08-04 04:56:44&#9;348,189&#9;----a-w&#9;C:\WINDOWS\system32\mspbde40.dll<br>+ 2008-03-25 04:50:45&#9;355,104&#9;----a-w&#9;C:\WINDOWS\system32\mspbde40.dll<br>- 2004-08-04 04:56:44&#9;421,919&#9;----a-w&#9;C:\WINDOWS\system32\msrd2x40.dll<br>+ 2008-03-25 04:50:47&#9;432,928&#9;----a-w&#9;C:\WINDOWS\system32\msrd2x40.dll<br>- 2004-08-04 04:56:44&#9;315,423&#9;----a-w&#9;C:\WINDOWS\system32\msrd3x40.dll<br>+ 2008-03-25 04:50:49&#9;322,336&#9;----a-w&#9;C:\WINDOWS\system32\msrd3x40.dll<br>- 2004-08-04 04:56:44&#9;552,989&#9;----a-w&#9;C:\WINDOWS\system32\msrepl40.dll<br>+ 2008-03-25 04:50:52&#9;559,904&#9;----a-w&#9;C:\WINDOWS\system32\msrepl40.dll<br>- 2004-08-04 04:56:44&#9;258,077&#9;----a-w&#9;C:\WINDOWS\system32\mstext40.dll<br>+ 2008-03-25 04:50:55&#9;264,992&#9;----a-w&#9;C:\WINDOWS\system32\mstext40.dll<br>- 2004-08-04 04:56:46&#9;831,519&#9;----a-w&#9;C:\WINDOWS\system32\mswdat10.dll<br>+ 2008-03-25 04:50:57&#9;838,432&#9;----a-w&#9;C:\WINDOWS\system32\mswdat10.dll<br>- 2004-08-04 04:56:46&#9;614,429&#9;----a-w&#9;C:\WINDOWS\system32\mswstr10.dll<br>+ 2008-03-25 04:50:58&#9;621,344&#9;----a-w&#9;C:\WINDOWS\system32\mswstr10.dll<br>- 2004-08-04 04:56:46&#9;348,189&#9;----a-w&#9;C:\WINDOWS\system32\msxbde40.dll<br>+ 2008-03-25 04:50:58&#9;355,104&#9;----a-w&#9;C:\WINDOWS\system32\msxbde40.dll<br>.<br>-- Snapshot reset to current date --<br>.<br>(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br>.<br>*Note* empty entries & legit default entries are not shown <br>REGEDIT4<br><br>[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<br>"DAEMON Tools"="C:\Program Files\DAEMON Tools\daemon.exe" [2007-04-03 15:29 165784]<br>"STYLEXP"="C:\Program Files\TGTSoft\StyleXP\StyleXP.exe" [2005-08-18 06:15 1359872]<br>"Steam"="d:\program files\valve\steam.exe" [2008-03-28 20:46 1271032]<br>"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 21:56 15360]<br>"SetDefaultMIDI"="MIDIDef.exe" [2006-08-11 14:42 25600 C:\WINDOWS\MIDIDEF.EXE]<br>"Gadwin PrintScreen"="C:\Program Files\Gadwin Systems\PrintScreen\PrintScreen.exe" [2007-08-20 01:42 495616]<br><br>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<br>"kav"="C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe" [2006-03-24 19:09 139367]<br>"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-12-05 01:41 8523776]<br>"nwiz"="nwiz.exe" [2007-12-05 01:41 1626112 C:\WINDOWS\system32\nwiz.exe]<br>"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-04-11 15:32 56080 C:\WINDOWS\KHALMNPR.Exe]<br>"DeadAIM"="C:\PROGRA~1\AIM\\DeadAIM.ocm" [2004-02-28 12:12 144896]<br>"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-02 20:24 32768]<br>"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 10:50 155648]<br>"AnyDVD"="C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe" [2005-07-07 15:17 455168]<br>"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]<br>"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 03:06 40048]<br>"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-07-31 01:30 286720]<br>"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-04-11 15:32 56080 C:\WINDOWS\KHALMNPR.Exe]<br>"CTHelper"="CTHELPER.EXE" [2006-08-11 14:56 17920 C:\WINDOWS\CTHELPER.EXE]<br>"CTxfiHlp"="CTXFIHLP.EXE" [2006-08-11 14:56 18944 C:\WINDOWS\system32\CTXFIHLP.EXE]<br>"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-12-05 01:41 81920]<br>"Acrobat Assistant 8.0"="C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2007-05-10 22:46 624248]<br><br>C:\Documents and Settings\All Users\Start Menu\Programs\Startup\<br>Last.fm Helper.lnk - D:\Program Files\Last.fm\LastFMHelper.exe [2007-11-11 23:05:06 110592]<br>Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [2007-07-09 20:17:59 692224]<br><br>[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]<br>@=""<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\security center]<br>"AntiVirusDisableNotify"=dword:00000001<br>"UpdatesDisableNotify"=dword:00000001<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]<br>"DisableMonitoring"=dword:00000001<br><br>[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]<br>"EnableFirewall"= 0 (0x0)<br><br>[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]<br>"%windir%\\system32\\sessmgr.exe"=<br>"D:\\Program Files\\Valve\\Steam.exe"=<br>"D:\\Program Files\\Unreal Tournament 3 Demo\\Binaries\\UT3Demo.exe"=<br>"C:\\WINDOWS\\system32\\PnkBstrA.exe"=<br>"C:\\WINDOWS\\system32\\PnkBstrB.exe"=<br>"D:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=<br>"C:\\Program Files\\Skype\\Phone\\Skype.exe"=<br><br>S3 fixustor;fixustor;C:\WINDOWS\system32\drivers\fixustor.sys []<br>S3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;C:\WINDOWS\system32\DRIVERS\wg111v2.sys []<br>S3 SaiH8000;SaiH8000;C:\WINDOWS\system32\DRIVERS\SaiH8000.sys [2004-07-30 10:25]<br><br>*Newly Created Service* - CATCHME<br>.<br>Contents of the 'Scheduled Tasks' folder<br>"2008-05-14 02:37:02 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"<br>- C:\Program Files\Apple Software Update\SoftwareUpdate.exe<br>.<br>**************************************************************************<br><br>catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, &raquo;<A HREF="http://www.gmer.net" >www.gmer.net</A><br>Rootkit scan 2008-05-15 11:34:26<br>Windows 5.1.2600 Service Pack 2 NTFS<br><br>scanning hidden processes ... <br><br>scanning hidden autostart entries ...<br><br>scanning hidden files ... <br><br>scan completed successfully<br>hidden files: 0<br><br>**************************************************************************<br>.<br>Completion time: 2008-05-15 11:37:48<br>ComboFix-quarantined-files.txt  2008-05-15 18:37:44<br>ComboFix2.txt  2008-05-15 03:22:51<br><br>Pre-Run: 13,813,342,208 bytes free<br>Post-Run: 13,757,509,632 bytes free<br><br>242&#9;--- E O F ---&#9;2008-05-15 08:32:58<br><br>Logfile of Trend Micro HijackThis v2.0.2<br>Scan saved at 11:41:34 AM, on 5/15/2008<br>Platform: Windows XP SP2 (WinNT 5.01.2600)<br>MSIE: Internet Explorer v7.00 (7.00.6000.16640)<br>Boot mode: Normal<br><br>Running processes:<br>C:\WINDOWS\System32\smss.exe<br>C:\WINDOWS\system32\winlogon.exe<br>C:\WINDOWS\system32\services.exe<br>C:\WINDOWS\system32\lsass.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\WINDOWS\system32\spoolsv.exe<br>C:\WINDOWS\system32\nvsvc32.exe<br>C:\WINDOWS\system32\PnkBstrA.exe<br>C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe<br>C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe<br>C:\WINDOWS\CTHELPER.EXE<br>C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe<br>C:\Program Files\DAEMON Tools\daemon.exe<br>D:\program files\valve\steam.exe<br>C:\WINDOWS\system32\ctfmon.exe<br>C:\Program Files\Gadwin Systems\PrintScreen\PrintScreen.exe<br>D:\Program Files\Last.fm\LastFMHelper.exe<br>C:\Program Files\Logitech\SetPoint\SetPoint.exe<br>C:\Program Files\Common Files\Logitech\KhalShared\KHALMNPR.EXE<br>C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe<br>C:\WINDOWS\system32\wscntfy.exe<br>C:\Program Files\Digsby\Digsby.exe<br>C:\WINDOWS\explorer.exe<br>C:\PROGRA~1\MOZILL~1\FIREFOX.EXE<br>C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=69157" >go.microsoft.com/fwlink/?LinkId=69157</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=69157" >go.microsoft.com/fwlink/?LinkId=69157</A><br>R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=localhost:8080<br>O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll<br>O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br>O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll<br>O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll<br>O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll<br>O4 - HKLM\..\Run: [kav] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe"<br>O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup<br>O4 - HKLM\..\Run: [nwiz] nwiz.exe /install<br>O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE<br>O4 - HKLM\..\Run: [DeadAIM] rundll32.exe "C:\PROGRA~1\AIM\\DeadAIM.ocm",ExportedCheckODLs<br>O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"<br>O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe<br>O4 - HKLM\..\Run: [AnyDVD] C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe<br>O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"<br>O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"<br>O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime<br>O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE<br>O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE<br>O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE<br>O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit<br>O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"<br>O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033<br>O4 - HKCU\..\Run: [STYLEXP] C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide<br>O4 - HKCU\..\Run: [Steam] "d:\program files\valve\steam.exe" -silent<br>O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br>O4 - HKCU\..\Run: [SetDefaultMIDI] MIDIDef.exe<br>O4 - HKCU\..\Run: [Gadwin PrintScreen] C:\Program Files\Gadwin Systems\PrintScreen\PrintScreen.exe /nosplash<br>O4 - Global Startup: Last.fm Helper.lnk = D:\Program Files\Last.fm\LastFMHelper.exe<br>O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe<br>O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html<br>O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html<br>O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html<br>O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html<br>O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html<br>O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html<br>O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html<br>O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html<br>O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000<br>O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll<br>O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll<br>O9 - Extra button: Web Anti-Virus - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scieplugin.dll<br>O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL<br>O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe<br>O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br>O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br>O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O15 - Trusted Zone: &raquo;<A HREF="http://www.ca.com" >www.ca.com</A><br>O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - &raquo;<A HREF="http://a1540.g.akamai.net/7/1540/52/20070711/qtinstall.info.apple.com/qtactivex/qtplugin.cab" >a1540.g.akamai.net/7/1540/52/200&middot;&middot;&middot;ugin.cab</A><br>O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - &raquo;<A HREF="http://www.eset.eu/OnlineScanner.cab" >www.eset.eu/OnlineScanner.cab</A><br>O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - &raquo;<A HREF="http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase370.cab" >cdn.scan.onecare.live.com/resour&middot;&middot;&middot;e370.cab</A><br>O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - &raquo;<A HREF="http://www.nvidia.com/content/DriverDownload/srl/2.0.0.1/sysreqlab2.cab" >www.nvidia.com/content/DriverDow&middot;&middot;&middot;lab2.cab</A><br>O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - &raquo;<A HREF="http://download.divx.com/player/DivXBrowserPlugin.cab" >download.divx.com/player/DivXBro&middot;&middot;&middot;ugin.cab</A><br>O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL<br>O23 - Service: Kaspersky Anti-Virus 6.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe<br>O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe<br>O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe<br>O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe<br>O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe<br><br>--<br>End of file - 8357 bytes<br><small>--<br>I subscribe to the theory of intellectual osmosis. Unfortunately, I must now cease our conversation and move away from you before my intelligence begins to drop. Good day.</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20487767</guid>
<pubDate>Thu, 15 May 2008 14:43:49 EDT</pubDate>
</item>

<item>
<title>Re: [Vundo] Vundo Infection</title>
<link>http://www.dslreports.com/forum/remark,20486051</link>
<description><![CDATA[<A HREF="/useremail/u/679515"><b>CalamityJane</b></A> : 1. Please open Notepad - don't use any other texteditor than notepad or the script will fail.<br><br>2. Now copy/paste the entire content of the text you see in the black box below into the Notepad window <br><small>registry code</small>:<div class="syntax"><pre><span class="codetext"><font color="#FFFFFF">File::<br>C:\WINDOWS\system32\d3d9caps.dat<br>C:\WINDOWS\BM671f7a6f.xml<br>C:\WINDOWS\system32\yalhhjii.dll<br>C:\WINDOWS\system32\myancbov.dll<br> <br>Registry::<br>[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\642c49f3]<br>[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BM671f7a6f]<br></font></span></pre></div><br>3. Save the notepad file above as: <b>CFScript.txt</b><br><br>4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.<br>[att=1]<br><br>5. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:<br><br>    * Combofix.txt<br>    * A new HijackThis log.<br><br><small>--<br>It takes a disaster to make a woman out of a female<br>Microsoft MVP/Windows Security 2003-2008<br>Proud Member of <A HREF="http://asap.maddoktor2.com/">ASAP </a> (Alliance of Security Analysis Professionals)</small><div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap WIDTH=33%><A HREF="/speak/slideshow/20486051?c=1307355&ret=L2ZvcnVtL3IyMDQ3NzA0NC54bWw%3D"><IMG TITLE="27742 bytes" BORDER=0 WIDTH=149 HEIGHT=65 SRC="/r0/download/1307355~e720b87c87cb17c6f4a015b6874d892d/CFScript.gif"></A></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20486051</guid>
<pubDate>Thu, 15 May 2008 09:17:42 EDT</pubDate>
</item>

<item>
<title>Re: [Vundo] Vundo Infection</title>
<link>http://www.dslreports.com/forum/remark,20485926</link>
<description><![CDATA[<A HREF="/useremail/u/679515"><b>CalamityJane</b></A> : That put a good sized dent in it.  Just some remnants left I think.  Give me a few minutes to review the results entirely and I'll post back with some final steps to take.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20485926</guid>
<pubDate>Thu, 15 May 2008 08:49:19 EDT</pubDate>
</item>

<item>
<title>Re: [Vundo] Vundo Infection</title>
<link>http://www.dslreports.com/forum/remark,20485273</link>
<description><![CDATA[<A HREF="/useremail/u/751678"><b>lilhurricane</b></A> : Let's open that up for easier viewing:<br><br>ComboFix 08-05-12.1 - Hady 2008-05-14 20:13:24.1 - NTFSx86 <br>Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1177 [GMT -7:00] <br>Running from: C:\Documents and Settings\Hady\Desktop\ComboFix.exe <br>* Created a new restore point <br>. <br><br>((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) <br>. <br><br>C:\WINDOWS\cookies.ini <br>C:\WINDOWS\pskt.ini <br>C:\WINDOWS\system32\gihOYJjl.ini <br>C:\WINDOWS\system32\gihOYJjl.ini2 <br>C:\WINDOWS\system32\iijhhlay.ini <br>C:\WINDOWS\system32\mcrh.tmp <br>C:\WINDOWS\system32\mSAJknmp.ini <br>C:\WINDOWS\system32\mSAJknmp.ini2 <br>C:\WINDOWS\system32\tuwmmxdm.ini <br><br>. <br>((((((((((((((((((((((((( Files Created from 2008-04-15 to 2008-05-15 ))))))))))))))))))))))))))))))) <br>. <br><br>2008-05-14 20:13 . 2008-05-14 20:13 1,024 --ah----- C:\WINDOWS\system32\config\systemprofile\ntuser.dat.LOG <br>2008-05-13 14:59 . 2008-05-13 14:59  d-------- C:\Program Files\Trend Micro <br>2008-05-12 23:34 . 2008-05-12 23:36  d-------- C:\Program Files\EsetOnlineScanner <br>2008-05-12 22:36 . 2008-05-12 22:37  d-------- C:\Program Files\Mozilla Firefox 3 Beta 5 <br>2008-04-21 18:39 . 2008-04-21 18:39  d-------- C:\Program Files\Hamachi <br>2008-04-21 18:39 . 2008-04-21 21:15  d-------- C:\Documents and Settings\Hady\Application Data\Hamachi <br>2008-04-21 18:39 . 2008-04-21 18:39 25,280 --a------ C:\WINDOWS\system32\drivers\hamachi.sys <br>2008-04-16 20:26 . 2008-04-18 20:17  d-------- C:\Documents and Settings\All Users\Application Data\TrackMania <br>2008-04-16 20:10 . 2008-04-16 20:10  d-------- C:\VundoFix Backups <br>2008-04-16 20:01 . 2008-04-16 20:03  d-------- C:\Program Files\Windows Live Safety Center <br>2008-04-16 19:37 . 2008-04-16 19:37 664 --a------ C:\WINDOWS\system32\d3d9caps.dat <br>2008-04-16 19:29 . 2008-04-16 19:55 500 --a------ C:\WINDOWS\wininit.ini <br>2008-04-16 18:58 . 2008-04-16 18:58  d-------- C:\Program Files\Spybot - Search & Destroy <br>2008-04-16 18:58 . 2008-04-16 19:04  d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy <br>2008-04-16 03:40 . 2008-04-16 15:00 101,165 --a------ C:\WINDOWS\BM671f7a6f.xml <br>2008-04-15 13:19 . 2008-04-15 13:19  d-------- C:\Program Files\Common Files\Macrovision Shared <br>2008-04-15 13:19 . 2008-04-15 13:19  d-------- C:\Documents and Settings\All Users\Application Data\FLEXnet <br><br>. <br>(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) <br>. <br>2008-05-15 03:18 1,639,200 --sha-w C:\WINDOWS\system32\drivers\fidbox2.dat <br>2008-05-15 03:17 52,957,216 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat <br>2008-05-15 03:16 716,492 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx <br>2008-05-15 03:16 191,216 --sha-w C:\WINDOWS\system32\drivers\fidbox2.idx <br>2008-05-14 20:37 --------- d-----w C:\Program Files\Digsby <br>2008-05-14 09:22 --------- d-----w C:\Documents and Settings\Hady\Application Data\Azureus <br>2008-05-01 06:51 --------- d-----w C:\Documents and Settings\Hady\Application Data\Skype <br>2008-04-30 23:40 --------- d-----w C:\Documents and Settings\Hady\Application Data\skypePM <br>2008-04-17 03:00 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard <br>2008-04-17 01:27 --------- d-----w C:\Documents and Settings\Hady\Application Data\Move Networks <br>2008-04-15 20:19 --------- d-----w C:\Program Files\Common Files\Adobe <br>2008-04-14 23:40 32 ----a-w C:\Documents and Settings\All Users\Application Data\ezsid.dat <br>2008-04-14 23:38 --------- d-----w C:\Program Files\Skype <br>2008-04-14 23:38 --------- d-----w C:\Program Files\Common Files\Skype <br>2008-04-14 23:38 --------- d-----w C:\Documents and Settings\All Users\Application Data\Skype <br>2008-04-12 21:34 --------- d-----w C:\Documents and Settings\Hady\Application Data\Digsby <br>2008-04-10 16:14 --------- d--h--w C:\Program Files\InstallShield Installation Information <br>2008-04-10 16:14 --------- d-----w C:\Program Files\THQ <br>2008-04-10 16:12 --------- d-----w C:\Program Files\Gadwin Systems <br>2008-04-09 14:48 --------- d-----w C:\Program Files\Java <br>2008-04-09 11:29 --------- d-----w C:\Program Files\Kaspersky Lab <br>2008-04-08 22:19 --------- d-----w C:\Documents and Settings\Hady\Application Data\SEGA <br>2008-04-08 22:18 --------- d-----w C:\Program Files\Sonic <br>2008-04-08 19:19 22,328 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys <br>2008-04-08 19:19 107,832 ----a-w C:\WINDOWS\system32\PnkBstrB.exe <br>2008-03-29 03:59 43,520 ----a-w C:\WINDOWS\system32\CmdLineExt03.dll <br>2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys <br>2008-03-15 02:22 21,840 ----atw C:\WINDOWS\system32\SIntfNT.dll <br>2008-03-15 02:22 17,212 ----atw C:\WINDOWS\system32\SIntf32.dll <br>2008-03-15 02:22 12,067 ----atw C:\WINDOWS\system32\SIntf16.dll <br>2008-03-15 02:09 94,208 ----a-w C:\WINDOWS\DIIUnin.exe <br>2008-03-15 02:09 2,829 ----a-w C:\WINDOWS\DIIUnin.pif <br>2008-03-01 13:06 826,368 ----a-w C:\WINDOWS\system32\wininet.dll <br>2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll <br>2008-02-20 05:32 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll <br>2007-12-17 08:08 22,328 ----a-w C:\Documents and Settings\Hady\Application Data\PnkBstrK.sys <br>. <br><br>((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) <br>. <br>. <br>*Note* empty entries & legit default entries are not shown <br>REGEDIT4 <br><br>[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] <br>"DAEMON Tools"="C:\Program Files\DAEMON Tools\daemon.exe" [2007-04-03 15:29 165784] <br>"STYLEXP"="C:\Program Files\TGTSoft\StyleXP\StyleXP.exe" [2005-08-18 06:15 1359872] <br>"Steam"="d:\program files\valve\steam.exe" [2008-03-28 20:46 1271032] <br>"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 21:56 15360] <br>"SetDefaultMIDI"="MIDIDef.exe" [2006-08-11 14:42 25600 C:\WINDOWS\MIDIDEF.EXE] <br>"Gadwin PrintScreen"="C:\Program Files\Gadwin Systems\PrintScreen\PrintScreen.exe" [2007-08-20 01:42 495616] <br><br>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] <br>"kav"="C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe" [2006-03-24 19:09 139367] <br>"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-12-05 01:41 8523776] <br>"nwiz"="nwiz.exe" [2007-12-05 01:41 1626112 C:\WINDOWS\system32\nwiz.exe] <br>"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-04-11 15:32 56080 C:\WINDOWS\KHALMNPR.Exe] <br>"DeadAIM"="C:\PROGRA~1\AIM\\DeadAIM.ocm" [2004-02-28 12:12 144896] <br>"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-02 20:24 32768] <br>"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 10:50 155648] <br>"AnyDVD"="C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe" [2005-07-07 15:17 455168] <br>"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784] <br>"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 03:06 40048] <br>"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-07-31 01:30 286720] <br>"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-04-11 15:32 56080 C:\WINDOWS\KHALMNPR.Exe] <br>"CTHelper"="CTHELPER.EXE" [2006-08-11 14:56 17920 C:\WINDOWS\CTHELPER.EXE] <br>"CTxfiHlp"="CTXFIHLP.EXE" [2006-08-11 14:56 18944 C:\WINDOWS\system32\CTXFIHLP.EXE] <br>"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-12-05 01:41 81920] <br>"Acrobat Assistant 8.0"="C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2007-05-10 22:46 624248] <br><br>C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ <br>Last.fm Helper.lnk - D:\Program Files\Last.fm\LastFMHelper.exe [2007-11-11 23:05:06 110592] <br>Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [2007-07-09 20:17:59 692224] <br><br>[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup] <br>@="" <br><br>[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\642c49f3] <br>C:\WINDOWS\system32\yalhhjii.dll <br><br>[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BM671f7a6f] <br>C:\WINDOWS\system32\myancbov.dll <br><br>[HKEY_LOCAL_MACHINE\software\microsoft\security center] <br>"AntiVirusDisableNotify"=dword:00000001 <br>"UpdatesDisableNotify"=dword:00000001 <br><br>[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus] <br>"DisableMonitoring"=dword:00000001 <br><br>[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] <br>"EnableFirewall"= 0 (0x0) <br><br>[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] <br>"%windir%\\system32\\sessmgr.exe"= <br>"D:\\Program Files\\Valve\\Steam.exe"= <br>"D:\\Program Files\\Unreal Tournament 3 Demo\\Binaries\\UT3Demo.exe"= <br>"C:\\WINDOWS\\system32\\PnkBstrA.exe"= <br>"C:\\WINDOWS\\system32\\PnkBstrB.exe"= <br>"D:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"= <br>"C:\\Program Files\\Skype\\Phone\\Skype.exe"= <br><br>S3 fixustor;fixustor;C:\WINDOWS\system32\drivers\fixustor.sys [] <br>S3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;C:\WINDOWS\system32\DRIVERS\wg111v2.sys [] <br>S3 SaiH8000;SaiH8000;C:\WINDOWS\system32\DRIVERS\SaiH8000.sys [2004-07-30 10:25] <br><br>. <br>Contents of the 'Scheduled Tasks' folder <br>"2008-05-14 02:37:02 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job" <br>- C:\Program Files\Apple Software Update\SoftwareUpdate.exe <br>. <br>************************************************************************** <br><br>catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, &raquo;<A HREF="http://www.gmer.net" >www.gmer.net</A> <br>Rootkit scan 2008-05-14 20:18:06 <br>Windows 5.1.2600 Service Pack 2 NTFS <br><br>scanning hidden processes ... <br><br>scanning hidden autostart entries ... <br><br>scanning hidden files ... <br><br>scan completed successfully <br>hidden files: 0 <br><br>************************************************************************** <br>. <br>------------------------ Other Running Processes ------------------------ <br>. <br>C:\WINDOWS\system32\nvsvc32.exe <br>C:\WINDOWS\system32\PnkBstrA.exe <br>C:\WINDOWS\system32\rundll32.exe <br>C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe <br>C:\Program Files\Common Files\Logitech\KhalShared\KHALMNPR.exe <br>C:\WINDOWS\system32\wscntfy.exe <br>. <br>************************************************************************** <br>. <br>Completion time: 2008-05-14 20:22:50 - machine was rebooted <br>ComboFix-quarantined-files.txt 2008-05-15 03:22:45 <br><br>Pre-Run: 13,354,393,600 bytes free <br>Post-Run: 13,882,781,696 bytes free <br><br>163 --- E O F --- 2008-04-11 09:34:09 <br><br><hr><br>Logfile of Trend Micro HijackThis v2.0.2 <br>Scan saved at 8:25:50 PM, on 5/14/2008 <br>Platform: Windows XP SP2 (WinNT 5.01.2600) <br>MSIE: Internet Explorer v7.00 (7.00.6000.16640) <br>Boot mode: Normal <br><br>Running processes: <br>C:\WINDOWS\System32\smss.exe <br>C:\WINDOWS\system32\winlogon.exe <br>C:\WINDOWS\system32\services.exe <br>C:\WINDOWS\system32\lsass.exe <br>C:\WINDOWS\system32\svchost.exe <br>C:\WINDOWS\System32\svchost.exe <br>C:\WINDOWS\system32\spoolsv.exe <br>C:\WINDOWS\system32\nvsvc32.exe <br>C:\WINDOWS\system32\PnkBstrA.exe <br>C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe <br>C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe <br>C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe <br>C:\WINDOWS\CTHELPER.EXE <br>C:\WINDOWS\system32\RUNDLL32.EXE <br>C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe <br>C:\Program Files\DAEMON Tools\daemon.exe <br>D:\program files\valve\steam.exe <br>C:\WINDOWS\system32\ctfmon.exe <br>C:\Program Files\Gadwin Systems\PrintScreen\PrintScreen.exe <br>D:\Program Files\Last.fm\LastFMHelper.exe <br>C:\Program Files\Logitech\SetPoint\SetPoint.exe <br>C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe <br>C:\Program Files\Common Files\Logitech\KhalShared\KHALMNPR.EXE <br>C:\WINDOWS\system32\wscntfy.exe <br>C:\WINDOWS\explorer.exe <br>C:\Program Files\Mozilla Firefox\firefox.exe <br>C:\Program Files\Trend Micro\HijackThis\HijackThis.exe <br><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=69157" >go.microsoft.com/fwlink/?LinkId=69157</A> <br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A> <br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A> <br>R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=69157" >go.microsoft.com/fwlink/?LinkId=69157</A> <br>R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=localhost:8080 <br>O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll <br>O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll <br>O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll <br>O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll <br>O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll <br>O4 - HKLM\..\Run: [kav] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe" <br>O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup <br>O4 - HKLM\..\Run: [nwiz] nwiz.exe /install <br>O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE <br>O4 - HKLM\..\Run: [DeadAIM] rundll32.exe "C:\PROGRA~1\AIM\\DeadAIM.ocm",ExportedCheckODLs <br>O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" <br>O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe <br>O4 - HKLM\..\Run: [AnyDVD] C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe <br>O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" <br>O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" <br>O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime <br>O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE <br>O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE <br>O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE <br>O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit <br>O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" <br>O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033 <br>O4 - HKCU\..\Run: [STYLEXP] C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide <br>O4 - HKCU\..\Run: [Steam] "d:\program files\valve\steam.exe" -silent <br>O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe <br>O4 - HKCU\..\Run: [SetDefaultMIDI] MIDIDef.exe <br>O4 - HKCU\..\Run: [Gadwin PrintScreen] C:\Program Files\Gadwin Systems\PrintScreen\PrintScreen.exe /nosplash <br>O4 - Global Startup: Last.fm Helper.lnk = D:\Program Files\Last.fm\LastFMHelper.exe <br>O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe <br>O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html <br>O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html <br>O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html <br>O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html <br>O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html <br>O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html <br>O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html <br>O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html <br>O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 <br>O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll <br>O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll <br>O9 - Extra button: Web Anti-Virus - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scieplugin.dll <br>O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL <br>O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe <br>O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll <br>O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll <br>O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe <br>O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe <br>O15 - Trusted Zone: &raquo;<A HREF="http://www.ca.com" >www.ca.com</A> <br>O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - &raquo;<A HREF="http://a1540.g.akamai.net/7/1540/52/20070711/qtinstall.info.apple.com/qtactivex/qtplugin.cab" >a1540.g.akamai.net/7/1540/52/200&middot;&middot;&middot;ugin.cab</A> <br>O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - &raquo;<A HREF="http://www.eset.eu/OnlineScanner.cab" >www.eset.eu/OnlineScanner.cab</A> <br>O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - &raquo;<A HREF="http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase370.cab" >cdn.scan.onecare.live.com/resour&middot;&middot;&middot;e370.cab</A> <br>O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - &raquo;<A HREF="http://www.nvidia.com/content/DriverDownload/srl/2.0.0.1/sysreqlab2.cab" >www.nvidia.com/content/DriverDow&middot;&middot;&middot;lab2.cab</A> <br>O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - &raquo;<A HREF="http://download.divx.com/player/DivXBrowserPlugin.cab" >download.divx.com/player/DivXBro&middot;&middot;&middot;ugin.cab</A> <br>O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL <br>O23 - Service: Kaspersky Anti-Virus 6.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe <br>O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe <br>O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe <br>O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe <br>O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe <br><br>-- <br>End of file - 8431 bytes <br><small>--<br><b>~<A HREF="/forum/cleanup">Safe Hex</a>~<A HREF="/forum/disco"> Team Discovery</a></b> <b><A HREF="http://www.tdprojecthope.com/"> ~ Project Hope ~ </b><b><A HREF="http://www.azlyrics.com/lyrics/neilyoung/likeahurricane.html">Like A Hurricane~</a></b></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20485273</guid>
<pubDate>Thu, 15 May 2008 02:23:40 EDT</pubDate>
</item>

<item>
<title>Re: [Vundo] Vundo Infection</title>
<link>http://www.dslreports.com/forum/remark,20484742</link>
<description><![CDATA[<A HREF="/useremail/u/999223"><b>fundamentalz</b></A> : Thanks for your help, CJ<div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap WIDTH=33%><A HREF="/r0/download/1307252~ffa9d213659f6ecce35617dee1fc8517/log.txt"><IMG  align=absmiddle TITLE="download" SRC="http://i.dslr.net/silk/arrow_down.png" border=0 width=16 height=16><IMG SRC="http://i.dslr.net/1ptrans.gif" WIDTH=10 HEIGHT=1 border=0><big>log.txt</big></A> <small>10,445 bytes</small><br>ComboFix</TD><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap WIDTH=33%><A HREF="/r0/download/1307253~029e86f58e8a26eca41a51f1e3af11ca/hijackthis.log"><IMG  align=absmiddle TITLE="download" SRC="http://i.dslr.net/silk/arrow_down.png" border=0 width=16 height=16><IMG SRC="http://i.dslr.net/1ptrans.gif" WIDTH=10 HEIGHT=1 border=0><big>hijackthis.log</big></A> <small>8,432 bytes</small><br>HJT</TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20484742</guid>
<pubDate>Wed, 14 May 2008 23:27:55 EDT</pubDate>
</item>

<item>
<title>Re: [Vundo] Vundo Infection</title>
<link>http://www.dslreports.com/forum/remark,20483776</link>
<description><![CDATA[<A HREF="/useremail/u/679515"><b>CalamityJane</b></A> : Let's use this free tool called ComboFix.<br> <br>Please visit this webpage for download links, and instructions for running the tool: &raquo;<A HREF="http://www.bleepingcomputer.com/combofix/how-to-use-combofix" >www.bleepingcomputer.com/combofi&middot;&middot;&middot;combofix</A> <br><br>If you do not have the Windows recovery console installed already, do follow the page's instructions for doing that before you run it.<br><br>When, the tool is finished, it will produce a report for you.  <br>Please post that report located at:  C:\<b>ComboFix.txt</b> along with a <b>new HijackThis log</b>.<br> <br><br>Note:  Kaspersky may alert on the ComboFix tool as a "risk tool" or similar.  Please either disable KAV while running it or ignore any of those alerts.<br><br>Spybot's teatimer may also interfere.  Best to turn that off during the scan as it will try to make fixes to malware found, if any, and Teatimer with throw up some alerts on that.<br><small>--<br>It takes a disaster to make a woman out of a female<br>Microsoft MVP/Windows Security 2003-2008<br>Proud Member of <A HREF="http://asap.maddoktor2.com/">ASAP </a> (Alliance of Security Analysis Professionals)</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20483776</guid>
<pubDate>Wed, 14 May 2008 20:47:45 EDT</pubDate>
</item>

<item>
<title>[Vundo] Vundo Infection</title>
<link>http://www.dslreports.com/forum/remark,20477044</link>
<description><![CDATA[<A HREF="/useremail/u/999223"><b>fundamentalz</b></A> : I am having numerous issues with my computer as a result of a Vundo infection, from firefox crashing and not copy and pasting, IE 7's refusal to start, to a network process "SVCHOST.exe" 90% cpu usage. i have been trying to remove it for the better part of 3 weeks now, but new issues keep popping up.<br><br>I've run:<br>1) Kaspersky full system scan<br>2) Spybot<br>3) MS Malicious Software tool<br>4) ESET online scan<br>5) VundoFix<br><br>of these all except Spybot came back clean. I was unable to run the computer associates scan, and the Windows Defender.<br>Spybot detected Vundo, which I removed, yet i still keep getting the same problems. All of these except HJT were run in Safe Mode.<br><br>Logfile of Trend Micro HijackThis v2.0.2<br>Scan saved at 2:59:44 PM, on 5/13/2008<br>Platform: Windows XP SP2 (WinNT 5.01.2600)<br>MSIE: Internet Explorer v7.00 (7.00.6000.16640)<br>Boot mode: Normal<br><br>Running processes:<br>C:\WINDOWS\System32\smss.exe<br>C:\WINDOWS\system32\winlogon.exe<br>C:\WINDOWS\system32\services.exe<br>C:\WINDOWS\system32\lsass.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\WINDOWS\Explorer.EXE<br>C:\WINDOWS\system32\spoolsv.exe<br>C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe<br>C:\WINDOWS\system32\nvsvc32.exe<br>C:\WINDOWS\system32\PnkBstrA.exe<br>C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe<br>C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe<br>C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe<br>C:\WINDOWS\CTHELPER.EXE<br>C:\WINDOWS\system32\RUNDLL32.EXE<br>C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe<br>C:\Program Files\DAEMON Tools\daemon.exe<br>D:\program files\valve\steam.exe<br>C:\WINDOWS\system32\ctfmon.exe<br>C:\Program Files\Gadwin Systems\PrintScreen\PrintScreen.exe<br>D:\Program Files\Last.fm\LastFMHelper.exe<br>C:\Program Files\Logitech\SetPoint\SetPoint.exe<br>C:\Program Files\Common Files\Logitech\KhalShared\KHALMNPR.EXE<br>C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe<br>C:\Program Files\Digsby\Digsby.exe<br>C:\PROGRA~1\MOZILL~1\FIREFOX.EXE<br>C:\Program Files\Azureus\Azureus.exe<br>C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=69157" >go.microsoft.com/fwlink/?LinkId=69157</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=69157" >go.microsoft.com/fwlink/?LinkId=69157</A><br>R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=localhost:8080<br>O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll<br>O2 - BHO: (no name) - {20E95981-4968-41D6-9CF4-9EB5544B908D} - C:\WINDOWS\system32\pmnkJASm.dll (file missing)<br>O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br>O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll<br>O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll<br>O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll<br>O4 - HKLM\..\Run: [kav] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe"<br>O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup<br>O4 - HKLM\..\Run: [nwiz] nwiz.exe /install<br>O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE<br>O4 - HKLM\..\Run: [DeadAIM] rundll32.exe "C:\PROGRA~1\AIM\\DeadAIM.ocm",ExportedCheckODLs<br>O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"<br>O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe<br>O4 - HKLM\..\Run: [AnyDVD] C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe<br>O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"<br>O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"<br>O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime<br>O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE<br>O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE<br>O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE<br>O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit<br>O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"<br>O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033<br>O4 - HKCU\..\Run: [STYLEXP] C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide<br>O4 - HKCU\..\Run: [Steam] "d:\program files\valve\steam.exe" -silent<br>O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br>O4 - HKCU\..\Run: [SetDefaultMIDI] MIDIDef.exe<br>O4 - HKCU\..\Run: [Gadwin PrintScreen] C:\Program Files\Gadwin Systems\PrintScreen\PrintScreen.exe /nosplash<br>O4 - HKUS\S-1-5-21-682003330-1767777339-725345543-1003\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033 (User '?')<br>O4 - HKUS\S-1-5-21-682003330-1767777339-725345543-1003\..\Run: [STYLEXP] C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide (User '?')<br>O4 - HKUS\S-1-5-21-682003330-1767777339-725345543-1003\..\Run: [Steam] "d:\program files\valve\steam.exe" -silent (User '?')<br>O4 - HKUS\S-1-5-21-682003330-1767777339-725345543-1003\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User '?')<br>O4 - HKUS\S-1-5-21-682003330-1767777339-725345543-1003\..\Run: [SetDefaultMIDI] MIDIDef.exe (User '?')<br>O4 - HKUS\S-1-5-21-682003330-1767777339-725345543-1003\..\Run: [Gadwin PrintScreen] C:\Program Files\Gadwin Systems\PrintScreen\PrintScreen.exe /nosplash (User '?')<br>O4 - Global Startup: Last.fm Helper.lnk = D:\Program Files\Last.fm\LastFMHelper.exe<br>O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe<br>O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html<br>O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html<br>O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html<br>O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html<br>O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html<br>O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html<br>O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html<br>O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html<br>O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000<br>O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll<br>O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll<br>O9 - Extra button: Web Anti-Virus - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scieplugin.dll<br>O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL<br>O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe<br>O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br>O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br>O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O15 - Trusted Zone: &raquo;<A HREF="http://www.ca.com" >www.ca.com</A><br>O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - &raquo;<A HREF="http://a1540.g.akamai.net/7/1540/52/20070711/qtinstall.info.apple.com/qtactivex/qtplugin.cab" >a1540.g.akamai.net/7/1540/52/200&middot;&middot;&middot;ugin.cab</A><br>O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - &raquo;<A HREF="http://www.eset.eu/OnlineScanner.cab" >www.eset.eu/OnlineScanner.cab</A><br>O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - &raquo;<A HREF="http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase370.cab" >cdn.scan.onecare.live.com/resour&middot;&middot;&middot;e370.cab</A><br>O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - &raquo;<A HREF="http://www.nvidia.com/content/DriverDownload/srl/2.0.0.1/sysreqlab2.cab" >www.nvidia.com/content/DriverDow&middot;&middot;&middot;lab2.cab</A><br>O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - &raquo;<A HREF="http://download.divx.com/player/DivXBrowserPlugin.cab" >download.divx.com/player/DivXBro&middot;&middot;&middot;ugin.cab</A><br>O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL<br>O23 - Service: Kaspersky Anti-Virus 6.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe<br>O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe<br>O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe<br>O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe<br>O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe<br><br>--<br>End of file - 9432 bytes<br><br>edit: fixed HJT log]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20477044</guid>
<pubDate>Tue, 13 May 2008 17:58:00 EDT</pubDate>
</item>

</channel>
</rss>
