<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Malware Protector 2008 - HJT Log in Security Cleanup</title>
<link>http://www.dslreports.com/forum/r20643341</link>
<description></description>
<language>en</language>
<pubDate>Wed, 09 Dec 2009 11:49:48 EDT</pubDate>
<lastBuildDate>Wed, 09 Dec 2009 11:49:48 EDT</lastBuildDate>

<item>
<title>Re: Malware Protector 2008 - HJT Log</title>
<link>http://www.dslreports.com/forum/remark,20663674</link>
<description><![CDATA[<A HREF="/useremail/u/751678"><b>lilhurricane</b></A> : Veddy nice, Matt, Bruce, CJ & Bill :)<br><br>"Y'all" done good ;)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20663674</guid>
<pubDate>Wed, 18 Jun 2008 18:22:41 EDT</pubDate>
</item>

<item>
<title>Re: Malware Protector 2008 - HJT Log</title>
<link>http://www.dslreports.com/forum/remark,20663509</link>
<description><![CDATA[<A HREF="/useremail/u/693977"><b>bcastner</b></A> : Thank you for your kind comments.<br><br>Your were very fortunate to have <b>CalamityJane</b>, one of the very best in the world at end user support for  malware removal to be your guide.<br><br>And it goes without saying that choosing to visit BroadBandReports for issues such as yours shows some brilliance on our part as well.<br><br>Best wishes,<br>Bill Castner<br><small>--<br><b>============</b><br><b>MS-MVP 2004 - -2008, ASAP Member</b><br><b><i>Users Helping Users</i></b><br><br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20663509</guid>
<pubDate>Wed, 18 Jun 2008 17:51:58 EDT</pubDate>
</item>

<item>
<title>Re: Malware Protector 2008 - HJT Log</title>
<link>http://www.dslreports.com/forum/remark,20662464</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : hi, this is the nephew.  i just wanted to express my appreciation for all the help.  i find it incredibly amazing that y'all would take the time to help me on this and give such clear and concise instructions on the fix.  <br><br>its working great and now i'm doing the follow up steps.<br><br>thanks so much]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20662464</guid>
<pubDate>Wed, 18 Jun 2008 14:10:10 EDT</pubDate>
</item>

<item>
<title>Re: Malware Protector 2008 - HJT Log</title>
<link>http://www.dslreports.com/forum/remark,20662435</link>
<description><![CDATA[<A HREF="/useremail/u/329157"><b>babacher</b></A> : It worked!  Thank you SO much.<br><br>I think he's gonna come back here and post the final logs as you requested, but for now Normal Mode is back and better than before the infection.<br><small>--<br>Help us cure TSC and cancer:  <b><A HREF="http://www.dslreports.com/forum/disco">Team Discovery</a></b></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20662435</guid>
<pubDate>Wed, 18 Jun 2008 14:06:39 EDT</pubDate>
</item>

<item>
<title>Re: Malware Protector 2008 - HJT Log</title>
<link>http://www.dslreports.com/forum/remark,20661307</link>
<description><![CDATA[<A HREF="/useremail/u/329157"><b>babacher</b></A> : Good article!<br><br>I don't know whether he's tried the "last known good" thing.  It doesn't actually FAIL to boot... it just tries and tries and tries forever.  He let it go for an hour-and-a-half and it still wasn't finished booting - so he shut it down.  Every time he looked it showed signs of being further along, but who knows how long it would have taken.<br><br>I warned him a few days ago that even if he could get it running again with you-all's (y'all's) help, it may never be the same again.  That's one reason he thought about taking it to the fix-it shop for them to fix (probably the nuke and pave approach), but he doesn't want to spend that money if he doesn't have to.<br><br>Now that we have a distinct plan of action, we'll cross our fingers and hope for the best - while preparing for the worst. <br><br>He bought the machine from Dell with the OS installed (Win XP).  He can't find the OS disk, assuming he ever had one.  But, at least he has proof of ownership so maybe Dell would send him another disk? <br><small>--<br>Help us cure TSC and cancer:  <b><A HREF="http://www.dslreports.com/forum/disco">Team Discovery</a></b></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20661307</guid>
<pubDate>Wed, 18 Jun 2008 10:41:29 EDT</pubDate>
</item>

<item>
<title>Re: Malware Protector 2008 - HJT Log</title>
<link>http://www.dslreports.com/forum/remark,20659300</link>
<description><![CDATA[<A HREF="/useremail/u/693977"><b>bcastner</b></A> : Yes, it would work in Safe Mode.<br>But I would prefer some attempts first to repair Normal boot.<br><br>Lets see how it goes after the above instructions.  <br><br>I warn you that in my opinion a machine that can only boot to Safe Mode, and not Normal mode, after the standard "Last Known Good" and other efforts have been tried, should have a clean reformat of all drives and XP reinstalled. <br><br>A while ago CalamityJane wrote about this strong recommendation as to how to proceed.  All I can tell you is that at the time I ageed with her, and did the following write-up about this approach and why:  &raquo;<A HREF="http://aumha.net/viewtopic.php?f=26&t=28580" >aumha.net/viewtopic.php?f=26&t=28580</A><br><small>--<br><b>============</b><br><b>MS-MVP 2004 - -2008, ASAP Member</b><br><b><i>Users Helping Users</i></b><br><br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20659300</guid>
<pubDate>Tue, 17 Jun 2008 22:24:24 EDT</pubDate>
</item>

<item>
<title>Re: Malware Protector 2008 - HJT Log</title>
<link>http://www.dslreports.com/forum/remark,20659078</link>
<description><![CDATA[<A HREF="/useremail/u/329157"><b>babacher</b></A> : My nephew is at work right now, so I'll call him tomorrow to work through this.<br><br>One question before we start:  this will all work in Safe Mode, right?  His machine won't boot in normal mode.  Presumably Safe Mode with Networking to allow downloading...<br><small>--<br>Help us cure TSC and cancer:  <b><A HREF="http://www.dslreports.com/forum/disco">Team Discovery</a></b></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20659078</guid>
<pubDate>Tue, 17 Jun 2008 21:49:22 EDT</pubDate>
</item>

<item>
<title>Re: Malware Protector 2008 - HJT Log</title>
<link>http://www.dslreports.com/forum/remark,20658856</link>
<description><![CDATA[<A HREF="/useremail/u/693977"><b>bcastner</b></A> : <b>~~~ Likely unneeded Comment from Bill Castner ~~~ </b><br><br>I have (due to Google) dealt with a ton of this infection in the last two weeks.  So in that time I have developed some little scripts to catch things that might not have been causght by our standard weapons.<br>I offer this as a conclusion to what  CalamityJane <A HREF="/useremail/u/679515"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> has done.<br><br>To save some time, download to your Desktop <b>FixPolicies.exe</b>, a self-extracting ZIP archive  from here:<br><br><textarea name="code" class="text" cols=50 rows=10>http://downloads.malwareremoval.com/BillCastner/FixPolicies.exe&#012;</textarea><!--end code block--><br>&#8226;  Double-click <b>FixPolicies.exe</b><br>&#8226; Click the "Install" button on the bottom toolbar of the box that will open.<br>&#8226; The program will create a new Folder called FixPolicies,<br>&#8226; Double-click to Open the new Folder, and then double-click the file within:  <b>Fix_Policies.cmd</b>.<br>&#8226; A black box will briefly appear and then close. <br><br>Please delete this File:<br><b> C:\WINDOWS\SYSTEM32\blphcl2uj0egbl.scr</b><br><br>TeaTimer is an excellent tool for the prevention of spyware but it can sometimes prevent HijackThis from fixing certain things. Please disable TeaTimer for now until you are clean. TeaTimer can be re-activated once your HijackThis log is clean.<br>&#8226; Open Spybot Search & Destroy.<br>&#8226; In the Mode menu click "Advanced mode" if not already selected.<br>&#8226; Choose Yes at the Warning prompt.<br>&#8226; Expand the Tools menu.<br>&#8226; Click Resident.<br>&#8226; <b>Uncheck</b> the Resident "TeaTimer" (Protection of overall system settings) active. box.<br>&#8226; In the File menu click Exit to exit Spybot Search & Destroy.<br>&#8226; Download and Unzip to your Desktop:  &raquo;<A HREF="http://www.techsupportforum.com/sectools/ResetTeaTimer.zip" >www.techsupportforum.com/sectool&middot;&middot;&middot;imer.zip</A><br>&#8226; Double click <b>ResetTeaTimer.bat</b> to remove all entries set by TeaTimer.<br><br>Similarly, disable <b>Spyware Doctor</b><br><br>You can re-enable it after you're clean. <br>From within Spyware Doctor, click the "<b>OnGuard[</b>" button on the left side. <br><i>Uncheck</i> "Activate OnGuard". <br><br>1. With all other applications closed (Taskbar empty, open HijackThis again, System Scan only.  <b>Checkmark</b> these items (if found):<br><br><b>O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - (no file)<br>O3 - Toolbar: (no name) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)<br>O4 - HKCU\..\RunOnce: [SpybotDeletingB6606] command /c del "c:\Program Files\Altnet\Download Manager\asmps.dll"<br>O4 - HKCU\..\RunOnce: [SpybotDeletingD3125] cmd /c del "c:\Program Files\Altnet\Download Manager\asmps.dll"<br>O4 - HKCU\..\RunOnce: [SpybotDeletingB2138] command /c del "c:\Program Files\Altnet\Download Manager\asm.exe"<br>O4 - HKCU\..\RunOnce: [SpybotDeletingD1979] cmd /c del "c:\Program Files\Altnet\Download Manager\asm.exe"<br>O4 - HKCU\..\RunOnce: [SpybotDeletingB6627] command /c del "c:\Program Files\Altnet\Download Manager\asmend.exe"<br>O4 - HKCU\..\RunOnce: [SpybotDeletingD6580] cmd /c del "c:\Program Files\Altnet\Download Manager\asmend.exe"</b><br><br>:!:  Click "<b>Fix checked</b>" and when the log panel clears exit HijackThis.<br><br>2. Please download  to your Desktop <b>OT_MOVEIT</b>:<br><textarea name="code" class="text" cols=50 rows=10>http://download.bleepingcomputer.com/oldtimer/OTMoveIt2.exe&#012;</textarea><!--end code block--><br>Please double-click OTMoveIt2.exe to run the utility.<br><br>Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):<br><br><textarea name="code" class="text" cols=50 rows=10>%Temp%\.tt*.tmp &#012;c:\Program Files\shclkrj0etfg&#012;C:\Program Files\shcl25j0enft&#012;C:\Program Files\shcau0j0ejna&#012;C:\Program Files\shccq9j0etde&#012;C:\Program Files\shcrq0j0el6t&#012;C:\Program Files\shcev9j0e1b1 &#012;%UserProfile%\Application Data\shclkrj0etfg&#012;%UserProfile%\Application Data\shcl25j0enft&#012;%UserProfile%\Application Data\shcau0j0ejna&#012;%UserProfile%\Application Data\shccq9j0etde&#012;%UserProfile%\Application Data\shcrq0j0el6t&#012;%UserProfile%\Application Data\shcev9j0e1b1 &#012;c:\Documents and Settings\All Users\Desktop\Malware Protector 2008.lnk&#012;c:\Documents and Settings\All Users\Start Menu\Programs\Malware Protector 2008&#012;c:\Documents and Settings\All Users\Start Menu\Programs\Malware Protector 2008.lnk&#012;%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Malware Protector 2008.lnk &#012;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\shclkrj0etfg&#012;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\SMshclkrj0etfg&#012;C:\WINDOWS\system32\*.scr &#012;HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system\\NoDispBackgroundPage&#012;HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system\\NoDispScrSavPage&#012;C:\WINDOWS\system32\lphccu0j0ejna.*&#012;C:\WINDOWS\system32\blp*.*&#012;C:\WINDOWS\system32\lph*.*&#012;C:\WINDOWS\System32\blphcl2uj0egbl.scr&#012;C:\WINDOWS\System32\blph*.*&#012; &#012;</textarea><!--end code block--><br>Return to OTMoveIt2, right click in the <b>"Paste List Of Files/Patterns To Search For and Move"</b> window.<br><b><i> IMPORTANT -- </i></b> Paste only into the <u>bottom</u> input panel (under the <b>Yellow </b>bar),  The top panel will not help you.<br>Right-click and choose <b>Paste</b>.<br><br>Click the red <b>Moveit</b> button.<br>This will not be quick.  I am asking it to scan your entire Drive C twice.<br>When it has finished, use your mouse and do a Copy/Paste of the large right-hand panel that shows Results.<br>Save your Clipboard contents in a new Notepad file, as we will want to review these results later.<br>Close OTMoveIt2 when it has finished.<br><br>Note:  If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose <b>Yes.</b><br><br>3. Please download MalwareBytes Anti-malware (MBAM) from one of the following links:<br><textarea name="code" class="text" cols=50 rows=10>http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html&#012;http://www.besttechie.net/tools/mbam-setup.exe&#012;</textarea><!--end code block--><br>Once downloaded, close all programs and Windows on your computer (including this one.)<br><br>Double-click on the icon on your desktop named Download_mbam-setup.exe. This will start the installation of MBAM onto your computer.<br><br>When the installation begins, keep following the prompts in order to continue with the installation process. Do not make any changes to default settings and when the program has finished installing, make sure you leave both the Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware checked. Then click on the Finish button.<br><br>MBAM will now automatically start and you will see a message stating that you should update the program before performing a scan. As MBAM will automatically update itself after the install, you can press the OK button to close that box and you will now be at the main program.<br><br>On the <b>Scanner tab</b>, make sure the the <b>Perform quick scan</b> option is selected and then click on the <b>Scan</b> button to start scanning your computer.<br><br>MBAM will now start scanning your computer for malware. This process can take quite a while, so we suggest you go and do something else and periodically check on the status of the scan. <br><br>When the scan is finished a message box will appear that it has completed scanning successfully.  Click <b>OK</b>.  Now click <b>Show Results</b>.  Make sure all entries have a checkmark at their far left.  You should now click on the <b>Remove Selected</b> button to remove all the listed malware. MBAM will now delete all of the files and registry keys and add them to the programs quarantine.<br><br>When MBAM has finished removing the malware, it will open the scan log and display it in Notepad. Review the log as desired, and then close the Notepad window.  Remember where you saved the log file, as we will want to see it later.<br><br>4.  Right-click on the header of the Code box below, where on the right side it says:  "<b>Copy to clipboard</b>" (or use your moue to Copy/Paste the contents):<br><textarea name="code" class="text" cols=50 rows=10>Driver::&#012;sysrest&#012; &#012;Registry::&#012;&#91;HKEY_CURRENT_USER\Control Panel\Colors&#93;&#012;"Background"="0 78 152"&#012;&#91;HKEY_CURRENT_USER\Control Panel\Desktop&#93;&#012;"WallpaperStyle"="0" &#012;&#91;HKEY_CURRENT_USER\Control Panel\Desktop&#93;&#012;"TileWallpaper"="0" &#012;&#91;HKEY_CURRENT_USER\Control Panel\Desktop&#93;&#012;"Wallpaper"=" " &#012;&#91;HKEY_CURRENT_USER\Control Panel\Desktop&#93;&#012;"OriginalWallpaper"="" &#012;&#91;HKEY_CURRENT_USER\Control Panel\Desktop&#93;&#012;"ConvertedWallpaper"=-&#012;&#91;HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run&#93;&#012;"ctfmona"=-  &#012;&#91;HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\srservice&#93;&#012;"Start"=dword:00000002 &#012;&#91;HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\sr&#93;&#012;"Start"=dword:00000000 &#012;&#91;HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\sr&#93;&#012;"ImagePath"="system32\DRIVERS\sr.sys"&#012;&#91;HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\SystemRestore&#93;&#012;"DisableSR"=dword:00000000&#012;&#91;HKEY_CURRENT_USER\Control Panel\Desktop&#93;&#012;"SCRNSAVE.EXE"=-&#012;&#91;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa&#93; &#012;"Authentication Packages"=hex(7):6d,73,76,31,5f,30,00,00 &#012;&#91;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop&#93;&#012;"NoChangingWallPaper"=dword:00000000&#012;"{450D8FBA-AD25-11D0-98A8-0800361B1103}"=dword:00000000&#012;&#91;HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop&#93;&#012;"NoChangingWallPaper"=dword:00000000&#012;&#91;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System&#93;&#012;"NoDispBackgroundPage"=dword:00000000&#012;"NoDispAppearancePage"=dword:00000000&#012;"Wallpaper"=-&#012;&#91;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer&#93;&#012;"ClassicShell"=dword:00000000&#012;&#91;HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System&#93;&#012;"NoDispBackgroundPage"=dword:00000000&#012;"NoDispAppearancePage"=dword:00000000&#012;"Wallpaper"=-&#012;&#91;HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer&#93;&#012;"ClassicShell"=dword:00000000&#012;&#91;HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system&#93;&#012;"DisableTaskMgr"=dword:00000000&#012;"NoDispAppearancePage"=dword:00000000&#012;"NoColorChoice"=dword:00000000&#012;"NoSizeChoice"=dword:00000000&#012;"NoDispScrSavPage"=dword:00000000&#012;"NoDispCPL"=dword:00000000&#012;"NoVisualStyleChoice"=dword:00000000&#012;"NoDispSettingsPage"=dword:00000000&#012;&#91;HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer&#93;&#012;"NoActiveDesktopChanges"=dword:00000000&#012;&#91;HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer&#93;&#012;"NoActiveDesktop"=dword:00000000&#012;"NoSaveSettings"=dword:00000000&#012;"NoThemesTab"=dword:00000000&#012;"ForceActiveDesktopOn"=dword:00000000&#012; &#012;</textarea><!--end code block--><br>Open a new Notepad session - (Do <b><i>not</i></b> use a Word Processor or WordPad).  Click "<b>Format</b>" and be certain that Word Wrap is not enabled.  Right-click | <b>Paste</b> the Code box contents from above into Notepad.  Click File, <b><i>Save as...</i></b>, and set the location to your Desktop, and enter (including quotation marks) as the filename: <b>"CFscript.txt"</b> .  <br><br>&#8226; Disconnect from the Internet.<br>&#8226; Disable your Antivirus.  If the Antivirus software you use has any Script Blocking features, be certain to disable these as well.<br><b> Important:  </b> Have no other programs running.  Your Task Bar should be clear of any program entries including your Browser.<br>&#8226; A window will open with a warning.  Accept any Disclaimers to start the fix.<br>Using your mouse, drag the new file CFscript.txt and drop it on the ComboFix.exe icon as shown in this little picture:<br> <IMG SRC="http://users.pandora.be/bluepatchy/miekiemoes/images/CFScript.gif"> <br><br>When the scan completes Notepad will open with with your results log open. Do a File, Exit and answer 'Yes' to save changes.<br>&#8226;<b>!</b>&#8226; A caution - Do <b>not</b> run Combofix more than once. Do not touch your mouse/keyboard until the scan has completed, as this may cause the process to stall or your computer to lock.<br><br>5. Download this INF repair file by MS-MVP Miekiemoes:  <br><br><textarea name="code" class="text" cols=50 rows=10>http://users.telenet.be/bluepatchy/miekiemoes/tools/VArestorepolicies.zip&#012;</textarea><!--end code block--><br>Unzip the download.  Open the folder <b>VArestorepolicies</b> and Right-click the file inside, <b>VArestorepolicies</b> and choose <b>Install</b>.<br>Delete the download, the unzipped folder and all contents.<br><br>6. Right click a blank area of your Desktop, and choose <b>Properties</b>.<br>Click Desktop, Customize Desktop, Web (tab).<br>Clear any entry in the top panel that might exits.<br>Be sure the checkbox near the bottom is unchhecked for "Lock desktop items".<br>Click Apply.<br>If you wish a custom Desktop color or theme or background, please set these now to your choices.<br>OK your way back to to the Desktop when done.<br><br>And, we shoud be finished.<br>I am sure CalmityJane will have some thoughts.<br>Here are mine as concluding comments:<br><br> Open <b>Acrobat</b> if you have the Full Version installed  Click <b>Help</b> and run the <b>Upgrade</b> applet found there.  If no update is offered:  Use the Preferences, Internet submenu of Acrobat and uncheck to integrate with your Browser.  Close Acrobat.<br>Whether you had the Full Version of Acrobat or not, download and install <b>Adobe Reader 8.1.1</b> and use this as the integrated PDF Reader insider your browser:  &raquo;<A HREF="http://www.adobe.com/products/acrobat/readstep2.html" >www.adobe.com/products/acrobat/r&middot;&middot;&middot;ep2.html</A><br><br><b><u>Clean-up & Prevention:</u></b><br><br>&#8226;  Right click "My Computer", Properties, and then click the System Restore tab.  <b>Checkmark</b> the box at the top to stop System Restore on all drives.  Click the "<b>Apply</b>" button.  Agree to the deletion of old Restore Points.  Then <b><u>uncheck</u></b> the box at the top and again click the "<b>Apply</b>" button.  Finally, click the "<b>OK</b>" button.  This will create a new Restore Point reflecting your clean system state.<br><br>&#8226; Click <b>Start</b>, then click <b>Run</b>.<br>Enter into the command box that opens:  <b>combofix /u</b> and then click <b>OK</b>.<br>(If we have renamed this file, please use the current name for the program in this instruction.)<br> <IMG SRC="http://i78.photobucket.com/albums/j116/amateur_photos/CFuninstall.png"> <br><br>&#8226; Please download <b>OTMoveIt2</b> by OldTimer to your Desktop (only):<br><br><textarea name="code" class="text" cols=50 rows=10>http://download.bleepingcomputer.com/oldtimer/OTMoveIt2.exe&#012;</textarea><!--end code block--><br>&#8226; Please double-click OTMoveIt.exe to run it.<br>&#8226; Click on the green <b>CleanUp!</b> button. When you do this a text file named cleanup.txt will be downloaded from the internet. If you get a warning from your firewall or other security programs regarding OTMoveIt attempting to contact the internet you should allow it to do so. <br>&#8226; After the list has been download you'll be asked if you want to Begin cleanup process? Select "Yes".<br>&#8226; This step removes the files, folders, and shortcuts created by the tools I had you download and run.<br><br>&#8226; Run <b>ATF Cleaner</b>  <IMG SRC="http://www.geekstogo.com/misc/guide_icons/ATF.gif"> , and checkmark "Empty Recycle Bin", click "Empty Selected" and exit the program.  You can delete or keep this utility as you wish.<br><br>&#8226; Use Control Panel, Add or Remove Programs, and Uninstall any entry related to an On-Line scanner we may have used.  <br>If you find any files or folders created during this cleanup operation remaining, please feel free to delete them.<br><br>&#8226; Configure your Antivirus software to check for updates daily, at a time in which you are sure the computer will be on.<br><br>&#8226; If I asked you to <b>Disable</b> something like TeaTimer or another malware blocker, please go ahead an re-enable them if you wish.<br><br>&#8226;  <b>Download and Install Windows Defender by Microsoft (free):</b><br><textarea name="code" class="text" cols=50 rows=10>http://www.microsoft.com/downloads/details.aspx?FamilyId=435BFCE7-DA2B-4A6A-AFA4-F7F14E605A0D&#012;</textarea><!--end code block--><br>&#8226;  <b>Suggestion:  Download and install Comodo BOClean (free):</b><br><textarea name="code" class="text" cols=50 rows=10>http://www.comodo.com/boclean/CBO_download.html&#012;</textarea><!--end code block--><br>&#8226;  <b>Suggestion:  Download, install, and keep updated Spyware Blaster (free):</b><br><textarea name="code" class="text" cols=50 rows=10>http://www.javacoolsoftware.com/spywareblaster.html&#012;</textarea><!--end code block--><br>&#8226; Refer to my first set of instructions above, and reconfigure <b>Hidden Files and Folders</b> to your choosing.<br><br>Best wishes -- and, please wait for CalamityJane's final thoughts,<br>Bill Castner<br><br><small>--<br><b>============</b><br><b>MS-MVP 2004 - -2008, ASAP Member</b><br><b><i>Users Helping Users</i></b><br><br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20658856</guid>
<pubDate>Tue, 17 Jun 2008 21:05:25 EDT</pubDate>
</item>

<item>
<title>Re: Malware Protector 2008 - HJT Log</title>
<link>http://www.dslreports.com/forum/remark,20655219</link>
<description><![CDATA[<A HREF="/useremail/u/329157"><b>babacher</b></A> : edit:<br><br>Never mind, he's ready to move forward with fixes here.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20655219</guid>
<pubDate>Tue, 17 Jun 2008 10:19:23 EDT</pubDate>
</item>

<item>
<title>Re: Malware Protector 2008 - HJT Log</title>
<link>http://www.dslreports.com/forum/remark,20651039</link>
<description><![CDATA[<A HREF="/useremail/u/329157"><b>babacher</b></A> : And here's the HJT log AFTER the combofix:<br><br>Logfile of Trend Micro HijackThis v2.0.2<br>Scan saved at 13:29:06, on 6/16/2008<br>Platform: Windows XP SP2 (WinNT 5.01.2600)<br>MSIE: Internet Explorer v7.00 (7.00.6000.16674)<br>Boot mode: Safe mode with network support<br><br>Running processes:<br>C:\WINDOWS\System32\smss.exe<br>C:\WINDOWS\system32\csrss.exe<br>C:\WINDOWS\system32\winlogon.exe<br>C:\WINDOWS\system32\services.exe<br>C:\WINDOWS\system32\lsass.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\WINDOWS\Explorer.EXE<br>C:\Program Files\Spyware Doctor\pctsAuxs.exe<br>C:\Program Files\Spyware Doctor\pctsSvc.exe<br>C:\Program Files\Spyware Doctor\pctsTray.exe<br>C:\WINDOWS\SYSTEM32\OSK.EXE<br>C:\WINDOWS\SYSTEM32\MSSWCHX.EXE<br>C:\WINDOWS\system32\ctfmon.exe<br>C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br>C:\WINDOWS\system32\wbem\wmiprvse.exe<br><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=69157" >go.microsoft.com/fwlink/?LinkId=69157</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = &raquo;<A HREF="http://www.dell.com" >www.dell.com</A><br>R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\1.bin\deSrcAs.dll<br>O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll<br>O2 - BHO: (no name) - {4D25F921-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\1.bin\deSrcAs.dll<br>O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll<br>O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll<br>O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll<br>O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - (no file)<br>O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll<br>O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll<br>O3 - Toolbar: (no name) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)<br>O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"<br>O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe<br>O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"<br>O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r<br>O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask<br>O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe<br>O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe<br>O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe<br>O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"<br>O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe<br>O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot<br>O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime<br>O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033<br>O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"<br>O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"<br>O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter<br>O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime<br>O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"<br>O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup<br>O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br>O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe<br>O4 - HKCU\..\RunOnce: [] OSK.exe<br>O4 - HKCU\..\RunOnce: [SpybotDeletingB6606] command /c del "c:\Program Files\Altnet\Download Manager\asmps.dll"<br>O4 - HKCU\..\RunOnce: [SpybotDeletingD3125] cmd /c del "c:\Program Files\Altnet\Download Manager\asmps.dll"<br>O4 - HKCU\..\RunOnce: [SpybotDeletingB2138] command /c del "c:\Program Files\Altnet\Download Manager\asm.exe"<br>O4 - HKCU\..\RunOnce: [SpybotDeletingD1979] cmd /c del "c:\Program Files\Altnet\Download Manager\asm.exe"<br>O4 - HKCU\..\RunOnce: [SpybotDeletingB6627] command /c del "c:\Program Files\Altnet\Download Manager\asmend.exe"<br>O4 - HKCU\..\RunOnce: [SpybotDeletingD6580] cmd /c del "c:\Program Files\Altnet\Download Manager\asmend.exe"<br>O4 - Global Startup: ATI CATALYST System Tray.lnk = C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe<br>O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe<br>O4 - Global Startup: VTAgentReboot.exe<br>O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\npjpi160_05.dll<br>O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\npjpi160_05.dll<br>O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll<br>O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll<br>O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br>O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br>O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll<br>O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (CDownloadCtrl Object) - &raquo;<A HREF="http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.6.108.cab" >www.fileplanet.com/fpdlmgr/cabs/&middot;&middot;&middot;.108.cab</A><br>O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - &raquo;<A HREF="http://lads.myspace.com/upload/MySpaceUploader1006.cab" >lads.myspace.com/upload/MySpaceU&middot;&middot;&middot;1006.cab</A><br>O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - &raquo;<A HREF="http://www.eset.eu/OnlineScanner.cab" >www.eset.eu/OnlineScanner.cab</A><br>O16 - DPF: {8E6AA867-94D4-4B4F-8791-1B048F8C122A} (WebInterface Class) - &raquo;<small>https</small>://<A HREF="https://fastsend.com/products/Fsplugin.cab">fastsend.com/products/Fsplugin.cab</A><br>O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - &raquo;<A HREF="http://download.games.yahoo.com/games/popcap/zuma/popcaploader_v6.cab" >download.games.yahoo.com/games/p&middot;&middot;&middot;r_v6.cab</A><br>O17 - HKLM\System\CCS\Services\Tcpip\..\{A150BA3B-2BAD-4082-A17D-55E52EDC29B4}: NameServer = 167.206.254.1,167.206.254.2<br>O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe<br>O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br>O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe<br>O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\SYSTEM32\ati2sgag.exe<br>O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe<br>O23 - Service: EarthLink Monitor Service (EarthLinkMonitor) - Boingo Wireless, Inc. - C:\Program Files\EarthLink TotalAccess\WENGINE\wmonitor.exe<br>O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br>O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe<br>O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br>O23 - Service: License Management Service ESD - Unknown owner - C:\Program Files\Common Files\element5 Shared\Service\Licence Manager ESD.exe<br>O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe<br>O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe<br>O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - McAfee, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe<br>O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe<br>O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe<br>O23 - Service: RaySatxsi5_0 Server (RaySatxsi5_0Server) - Unknown owner - C:\Softimage\XSI_5.0\Application\bin\raysatxsi5_0server.exe<br>O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe<br>O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe<br>O23 - Service: SPM License Server (spmd) - mental images GmbH - C:\WINDOWS\system32\spm\spmd.exe<br>O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe<br>O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe<br><br>--<br>End of file - 9798 bytes<br><small>--<br>Help us cure TSC and cancer:  <b><A HREF="http://www.dslreports.com/forum/disco">Team Discovery</a></b></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20651039</guid>
<pubDate>Mon, 16 Jun 2008 13:31:54 EDT</pubDate>
</item>

<item>
<title>Re: Malware Protector 2008 - HJT Log</title>
<link>http://www.dslreports.com/forum/remark,20651025</link>
<description><![CDATA[<A HREF="/useremail/u/329157"><b>babacher</b></A> : OK!!  Here we go - here's the combofix log:<br><br>ComboFix 08-06-15.4 - Administrator 2008-06-16  4:47:32.1 - NTFSx86 NETWORK<br>Microsoft Windows XP Home Edition  5.1.2600.2.1252.1.1033.18.2076 [GMT -4:00]<br>Running from: C:\Documents and Settings\Administrator\Desktop\ComboFix.exe<br>Command switches used :: C:\Documents and Settings\Administrator\Desktop\WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe<br>.<br><br>(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br><br>C:\Documents and Settings\mattito\Application Data\macromedia\Flash Player\#SharedObjects\3WDMCC6G\www.broadcaster.com<br>C:\Documents and Settings\mattito\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.broadcaster.com<br>C:\Documents and Settings\mattito\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.broadcaster.com\settings.sol<br>C:\WINDOWS\Fonts\acrsec.fon<br>C:\WINDOWS\Fonts\acrsecB.fon<br>C:\WINDOWS\Fonts\acrsecI.fon<br>C:\WINDOWS\smdat32m.sys<br>C:\WINDOWS\system32\bszip.dll<br><br>.<br>(((((((((((((((((((((((((   Files Created from 2008-05-16 to 2008-06-16  )))))))))))))))))))))))))))))))<br>.<br><br>2008-06-16 01:47 . 2008-06-16 02:59  d-------- C:\Program Files\EsetOnlineScanner<br>2008-06-14 15:39 . 2008-06-14 15:39  d-------- C:\Program Files\Trend Micro<br>2008-06-14 11:59 . 2008-06-14 11:59  d-------- C:\Program Files\Spybot - Search & Destroy<br>2008-06-14 11:59 . 2008-06-14 12:01  d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy<br>2008-06-13 14:43 . 2005-03-31 03:49  d-------- C:\Documents and Settings\Administrator\Application Data\Sonic<br>2008-06-13 14:43 . 2005-03-31 03:43  d-------- C:\Documents and Settings\Administrator\Application Data\Jasc Software Inc<br>2008-06-13 14:43 . 2008-06-13 14:43  d-------- C:\Documents and Settings\Administrator<br>2008-06-12 14:33 . 2008-06-16 01:49  d-a------ C:\Documents and Settings\All Users\Application Data\TEMP<br>2008-06-12 14:33 . 2007-12-10 13:53 81,288 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\iksyssec.sys<br>2008-06-12 14:33 . 2007-12-10 13:53 66,952 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\iksysflt.sys<br>2008-06-12 14:33 . 2008-02-01 11:55 42,376 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\ikfilesec.sys<br>2008-06-12 14:33 . 2007-12-10 13:53 29,576 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\kcom.sys<br>2008-06-12 14:32 . 2008-06-16 01:49  d-------- C:\Program Files\Spyware Doctor<br>2008-06-12 14:32 . 2008-06-12 14:32  d-------- C:\Documents and Settings\mattito\Application Data\PC Tools<br>2008-06-12 13:17 . 2008-06-12 13:17  d-------- C:\Program Files\Enigma Software Group<br>2008-06-12 03:02 . 2008-06-12 03:02 118 --a------ C:\WINDOWS\SYSTEM32\MRT.INI<br>2008-06-11 04:30 . 2008-04-14 07:01 272,128 --------- C:\WINDOWS\SYSTEM32\DRIVERS\bthport.sys<br>2008-06-11 04:30 . 2008-04-14 07:01 272,128 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\bthport.sys<br>2008-06-10 13:05 . 2008-06-10 13:05 54,156 --ah----- C:\WINDOWS\QTFont.qfn<br>2008-06-10 13:05 . 2008-06-10 13:05 1,409 --a------ C:\WINDOWS\QTFont.for<br>2008-06-10 00:51 . 2008-06-14 20:14 3,058 --a------ C:\WINDOWS\SYSTEM32\tmp.reg<br>2008-06-09 21:43 . 2008-06-09 21:43  d-------- C:\Documents and Settings\mattito\Application Data\shcj2uj0egbl<br>2008-06-09 21:43 . 2008-06-14 20:29 52,736 --a------ C:\WINDOWS\SYSTEM32\blphcl2uj0egbl.scr<br>2008-05-27 10:50 . 2008-05-27 10:50 90,112 --a------ C:\WINDOWS\SYSTEM32\QuickTimeVR.qtx<br>2008-05-27 10:50 . 2008-05-27 10:50 57,344 --a------ C:\WINDOWS\SYSTEM32\QuickTime.qts<br>2008-05-21 18:53 . 2008-05-28 20:35 512 --a------ C:\drmHeader.bin<br><br>.<br>((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br>2008-06-12 01:32 --------- d-----w C:\Program Files\QuickTime<br>2008-06-12 01:29 --------- d-----w C:\Program Files\Apple Software Update<br>2008-06-10 04:39 --------- d-----w C:\Program Files\Windows Media Connect 2<br>2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys<br>2008-05-08 12:28 202,752 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\rmcast.sys<br>2008-05-07 05:18 1,287,680 ----a-w C:\WINDOWS\SYSTEM32\quartz.dll<br>2008-05-07 05:18 1,287,680 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\quartz.dll<br>2008-04-29 05:42 --------- d-----w C:\Program Files\eMule<br>2008-04-24 02:16 3,591,680 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\mshtml.dll<br>2008-04-22 07:40 625,664 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\iexplore.exe<br>2008-04-22 07:39 70,656 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\ie4uinit.exe<br>2008-04-22 07:39 13,824 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\ieudinit.exe<br>2008-04-20 05:07 161,792 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\ieakui.dll<br>2008-03-31 21:25 831,488 ----a-w C:\WINDOWS\SYSTEM32\divx_xx0a.dll<br>2008-03-31 21:25 823,296 ----a-w C:\WINDOWS\SYSTEM32\divx_xx0c.dll<br>2008-03-31 21:25 823,296 ----a-w C:\WINDOWS\SYSTEM32\divx_xx07.dll<br>2008-03-31 21:25 802,816 ----a-w C:\WINDOWS\SYSTEM32\divx_xx11.dll<br>2008-03-31 21:25 682,496 ----a-w C:\WINDOWS\SYSTEM32\DivX.dll<br>2008-03-31 21:25 161,096 ----a-w C:\WINDOWS\SYSTEM32\DivXCodecVersionChecker.exe<br>2008-03-27 08:12 151,583 ----a-w C:\WINDOWS\SYSTEM32\msjint40.dll<br>2008-03-27 08:12 151,583 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\msjint40.dll<br>2008-03-21 20:30 524,288 ----a-w C:\WINDOWS\SYSTEM32\DivXsm.exe<br>2008-03-21 20:30 3,596,288 ----a-w C:\WINDOWS\SYSTEM32\qt-dx331.dll<br>2008-03-21 20:30 200,704 ----a-w C:\WINDOWS\SYSTEM32\ssldivx.dll<br>2008-03-21 20:30 129,784 ------w C:\WINDOWS\SYSTEM32\pxafs.dll<br>2008-03-21 20:30 120,056 ------w C:\WINDOWS\SYSTEM32\pxcpyi64.exe<br>2008-03-21 20:30 118,520 ------w C:\WINDOWS\SYSTEM32\pxinsi64.exe<br>2008-03-21 20:30 1,044,480 ----a-w C:\WINDOWS\SYSTEM32\libdivx.dll<br>2008-03-21 20:28 81,920 ----a-w C:\WINDOWS\SYSTEM32\dpl100.dll<br>2008-03-21 20:28 593,920 ----a-w C:\WINDOWS\SYSTEM32\dpuGUI11.dll<br>2008-03-21 20:28 57,344 ----a-w C:\WINDOWS\SYSTEM32\dpv11.dll<br>2008-03-21 20:28 53,248 ----a-w C:\WINDOWS\SYSTEM32\dpuGUI10.dll<br>2008-03-21 20:28 344,064 ----a-w C:\WINDOWS\SYSTEM32\dpus11.dll<br>2008-03-21 20:28 294,912 ----a-w C:\WINDOWS\SYSTEM32\dpu11.dll<br>2008-03-21 20:28 294,912 ----a-w C:\WINDOWS\SYSTEM32\dpu10.dll<br>2008-03-21 20:28 196,608 ----a-w C:\WINDOWS\SYSTEM32\dtu100.dll<br>2008-03-21 20:28 12,288 ----a-w C:\WINDOWS\SYSTEM32\DivXWMPExtType.dll<br>2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\SYSTEM32\win32k.sys<br>2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\win32k.sys<br>.<br><br>(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br>.<br>*Note* empty entries & legit default entries are not shown <br>REGEDIT4<br><br>[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<br>"DellSupport"="C:\Program Files\DellSupport\DSAgnt.exe" [2007-03-15 11:09 460784]<br>"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 07:00 15360]<br>"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]<br><br>[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]<br>"@"="OSK.exe" [2004-08-04 07:00 215552 C:\WINDOWS\SYSTEM32\OSK.EXE]<br>"SpybotDeletingB6606"="command /c del c:\Program Files\Altnet\Download Manager\asmps.dll" [ ]<br>"SpybotDeletingD3125"="cmd /c del c:\Program Files\Altnet\Download Manager\asmps.dll" [ ]<br>"SpybotDeletingB2138"="command /c del c:\Program Files\Altnet\Download Manager\asm.exe" [ ]<br>"SpybotDeletingD1979"="cmd /c del c:\Program Files\Altnet\Download Manager\asm.exe" [ ]<br>"SpybotDeletingB6627"="command /c del c:\Program Files\Altnet\Download Manager\asmend.exe" [ ]<br>"SpybotDeletingD6580"="cmd /c del c:\Program Files\Altnet\Download Manager\asmend.exe" [ ]<br><br>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<br>"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]<br>"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-05-03 21:05 344064]<br>"DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [2004-10-12 17:54 57344]<br>"UpdateManager"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" [2004-01-07 03:01 110592]<br>"VSOCheckTask"="c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" [2005-03-02 19:19 143360]<br>"MCAgentExe"="c:\PROGRA~1\mcafee.com\agent\mcagent.exe" [2005-03-07 15:05 278528]<br>"MCUpdateExe"="C:\PROGRA~1\mcafee.com\agent\McUpdate.exe" [2005-03-07 15:07 180224]<br>"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2004-12-06 03:05 127035]<br>"VirusScan Online"="c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe" [2005-03-18 20:28 196608]<br>"MPFExe"="C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe" [2005-04-05 14:41 950272]<br>"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2005-06-28 14:23 180269]<br>"ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" [2005-08-31 00:40 57344]<br>"DAEMON Tools"="C:\Program Files\DAEMON Tools\daemon.exe" [2005-12-10 10:57 133016]<br>"dscactivate"="C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 10:24 16384]<br>"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 10:36 267048]<br>"DellSupportCenter"="C:\Program Files\Dell Support Center\bin\sprtcmd.exe" [2007-11-15 10:23 202544]<br>"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-05-27 10:50 413696]<br>"ISTray"="C:\Program Files\Spyware Doctor\pctsTray.exe" [2008-04-10 15:14 1107848]<br><br>C:\Documents and Settings\mattito\Start Menu\Programs\Startup\<br>Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-11-07 02:45:44 113664]<br>MEMonitor.lnk.lnk - C:\Program Files\Sprint music manager\MEMonitor.exe [2007-12-10 15:57:58 929792]<br><br>C:\Documents and Settings\All Users\Start Menu\Programs\Startup\<br>ATI CATALYST System Tray.lnk - C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe [2005-08-31 00:40:36 57344]<br>QuickBooks Update Agent.lnk - C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2004-11-11 13:59:36 806912]<br>VTAgentReboot.exe [2001-10-08 08:11:30 143360]<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]<br>"vidc.hdyc"= C:\PROGRA~1\BLACKM~1\BLACKM~2\BMDCOD~1.DLL<br>"vidc.v210"= C:\PROGRA~1\BLACKM~1\BLACKM~2\BMDCOD~1.DLL<br>"vidc.r210"= C:\PROGRA~1\BLACKM~1\BLACKM~2\BMDCOD~1.DLL<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\security center]<br>"AntiVirusDisableNotify"=dword:00000001<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]<br>"DisableMonitoring"=dword:00000001<br><br>[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]<br>"EnableFirewall"= 0 (0x0)<br><br>[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]<br>"%windir%\\system32\\sessmgr.exe"=<br>"C:\\Program Files\\eMule\\emule.exe"=<br>"C:\\Program Files\\Valve\\Steam\\Steam.exe"=<br>"C:\\Program Files\\Valve\\Steam\\SteamApps\\mharvill\\day of defeat source\\hl2.exe"=<br>"C:\\Program Files\\Valve\\Steam\\SteamApps\\mharvill\\counter-strike source\\hl2.exe"=<br>"C:\\Softimage\\XSI_5.0\\Application\\bin\\XSI.exe"=<br>"C:\\Program Files\\Valve\\Steam\\SteamApps\\mharvill\\lostcoast\\hl2.exe"=<br>"C:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Civilization4.exe"=<br>"C:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Warlords\\Civ4Warlords.exe"=<br>"C:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Warlords\\Civ4Warlords_PitBoss.exe"=<br>"C:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Beyond the Sword\\Civ4BeyondSword.exe"=<br>"C:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Beyond the Sword\\Civ4BeyondSword_PitBoss.exe"=<br>"%windir%\\Network Diagnostic\\xpnetdiag.exe"=<br>"C:\\Program Files\\uTorrent\\uTorrent.exe"=<br>"C:\\Program Files\\iTunes\\iTunes.exe"=<br><br>[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]<br>"8097:TCP"= 8097:TCP:EarthLink UHP Modem Support<br><br>S2 EarthLinkMonitor;EarthLink Monitor Service;"C:\Program Files\EarthLink TotalAccess\WENGINE\wmonitor.exe" [2005-01-26 11:47]<br>S2 sprtsvc_dellsupportcenter;SupportSoft Sprocket Service (dellsupportcenter);C:\Program Files\Dell Support Center\bin\sprtsvc.exe [2007-11-15 10:23]<br>S3 BCM42U;USB HPNA 10 Mbps Network Adapter Driver;C:\WINDOWS\system32\DRIVERS\BCM42U.SYS [2001-08-17 13:11]<br>S3 BW2NDIS5;BW2NDIS5;C:\WINDOWS\system32\Drivers\BW2NDIS5.sys [2004-11-01 14:16]<br>S3 cem56;Xircom CreditCard 10/100 + Modem 56 Network;C:\WINDOWS\system32\DRIVERS\CEM56n5.sys [2001-08-17 12:13]<br>S3 pc22nd5;Toshiba PCX2200 USB Cable Modem networking driver (NDIS);C:\WINDOWS\system32\DRIVERS\pc22nd5.sys [2001-11-08 15:58]<br>S3 pc22unic;Toshiba PCX2200 USB Cable Modem WDM driver;C:\WINDOWS\system32\DRIVERS\pc22unic.sys [2001-11-08 18:14]<br><br>[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]<br>\Shell\AutoRun\command - D:\baldur.exe<br><br>*Newly Created Service* - CATCHME<br>.<br>Contents of the 'Scheduled Tasks' folder<br>"2008-06-12 01:29:42 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"<br>- C:\Program Files\Apple Software Update\SoftwareUpdate.exe<br>"2008-06-06 22:30:00 C:\WINDOWS\Tasks\McAfee.com Scan for Viruses - My Computer (ELISSA2-mattito).job"<br>- c:\program files\mcafee.com\vso\mcmnhdlr.exe<br>"2008-06-14 17:28:27 C:\WINDOWS\Tasks\McAfee.com Update Check (D64V0671-Owner).job"<br>- c:\PROGRA~1\mcafee.com\agent\mcupdate.ex<br>- c:\PROGRA~1\mcafee.com\agent<br>"2008-06-15 00:29:52 C:\WINDOWS\Tasks\McAfee.com Update Check (ELISSA-mattito).job"<br>- C:\PROGRA~1\mcafee.com\agent\mcupdate.ex<br>- C:\PROGRA~1\mcafee.com\agent<br>"2008-06-14 17:28:27 C:\WINDOWS\Tasks\McAfee.com Update Check (ELISSA2-christine).job"<br>- C:\PROGRA~1\mcafee.com\agent\mcupdate.ex<br>- C:\PROGRA~1\mcafee.com\agen<br>"2008-06-15 00:33:17 C:\WINDOWS\Tasks\McAfee.com Update Check (ELISSA2-mattito).job"<br>- C:\PROGRA~1\mcafee.com\agent\mcupdate.ex<br>- C:\PROGRA~1\mcafee.com\agent<br>.<br>**************************************************************************<br><br>catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, &raquo;<A HREF="http://www.gmer.net" >www.gmer.net</A><br>Rootkit scan 2008-06-16 04:56:52<br>Windows 5.1.2600 Service Pack 2 NTFS<br><br>scanning hidden processes ... <br><br>scanning hidden autostart entries ...<br><br>scanning hidden files ... <br><br>scan completed successfully<br>hidden files: 0<br><br>**************************************************************************<br>.<br>Completion time: 2008-06-16  4:59:25<br>ComboFix-quarantined-files.txt  2008-06-16 08:59:23<br><br>Pre-Run: 49,191,612,416 bytes free<br>Post-Run: 49,354,342,400 bytes free<br><br>WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe<br>[boot loader]<br>timeout=2<br>default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS<br>[operating systems]<br>multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect<br>C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons<br><br>209 --- E O F --- 2008-06-12 07:03:33<br><small>--<br>Help us cure TSC and cancer:  <b><A HREF="http://www.dslreports.com/forum/disco">Team Discovery</a></b></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20651025</guid>
<pubDate>Mon, 16 Jun 2008 13:29:15 EDT</pubDate>
</item>

<item>
<title>Re: Malware Protector 2008 - HJT Log</title>
<link>http://www.dslreports.com/forum/remark,20649910</link>
<description><![CDATA[<A HREF="/useremail/u/679515"><b>CalamityJane</b></A> : Ok, so I'll be looking next for the second part (is he working on getting this step completed?):<br><br>Then download and run this free tool called ComboFix to produce a log please:<br>Please visit this webpage for download links, and instructions for running the tool: &raquo;<A HREF="http://www.bleepingcomputer.com/combofix/how-to-use-combofix" >www.bleepingcomputer.com/combofi&middot;&middot;&middot;combofix</A> <br><br>If you do not have the Windows recovery console installed already, do follow the page's instructions for doing that before you run it.<br><br>When, the tool is finished, it will produce a report for you.  <br>Please post that report located at:  C:\<b>ComboFix.txt</b> along with a <b>new HijackThis log</b>.<br><small>--<br>It takes a disaster to make a woman out of a female<br>Microsoft MVP/Windows Security 2003-2008<br>Proud Member of <A HREF="http://asap.maddoktor2.com/">ASAP </a> (Alliance of Security Analysis Professionals)</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20649910</guid>
<pubDate>Mon, 16 Jun 2008 09:34:53 EDT</pubDate>
</item>

<item>
<title>Re: Malware Protector 2008 - HJT Log</title>
<link>http://www.dslreports.com/forum/remark,20649603</link>
<description><![CDATA[<A HREF="/useremail/u/329157"><b>babacher</b></A> : Here's the HJT log after the vscan:<br><br>Logfile of Trend Micro HijackThis v2.0.2<br>Scan saved at 03:14:05, on 6/16/2008<br>Platform: Windows XP SP2 (WinNT 5.01.2600)<br>MSIE: Internet Explorer v7.00 (7.00.6000.16674)<br>Boot mode: Safe mode with network support<br><br>Running processes:<br>C:\WINDOWS\System32\smss.exe<br>C:\WINDOWS\system32\csrss.exe<br>C:\WINDOWS\system32\winlogon.exe<br>C:\WINDOWS\system32\services.exe<br>C:\WINDOWS\system32\lsass.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\Program Files\Spyware Doctor\pctsAuxs.exe<br>C:\Program Files\Spyware Doctor\pctsSvc.exe<br>C:\WINDOWS\Explorer.EXE<br>C:\Program Files\Spyware Doctor\pctsTray.exe<br>C:\Program Files\Internet Explorer\iexplore.exe<br>C:\WINDOWS\system32\ctfmon.exe<br>C:\WINDOWS\SYSTEM32\OSK.EXE<br>C:\WINDOWS\SYSTEM32\MSSWCHX.EXE<br>C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br>C:\WINDOWS\system32\wbem\wmiprvse.exe<br><br>R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = &raquo;<A HREF="http://bfc.myway.com/search/de_srchlft.html" >bfc.myway.com/search/de_srchlft.html</A><br>R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = &raquo;<A HREF="http://www.dell.com" >www.dell.com</A><br>R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\1.bin\deSrcAs.dll<br>O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll<br>O2 - BHO: (no name) - {4D25F921-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\1.bin\deSrcAs.dll<br>O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll<br>O2 - BHO: RXResultTracker Class - {59879FA4-4790-461c-A1CC-4EC4DE4CA483} - C:\Program Files\RXToolBar\sfcont.dll (file missing)<br>O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll<br>O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll<br>O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll<br>O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll<br>O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll<br>O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll<br>O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"<br>O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe<br>O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"<br>O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r<br>O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask<br>O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe<br>O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe<br>O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe<br>O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"<br>O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe<br>O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot<br>O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime<br>O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033<br>O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"<br>O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"<br>O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter<br>O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime<br>O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"<br>O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup<br>O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br>O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe<br>O4 - HKCU\..\RunOnce: [] OSK.exe<br>O4 - HKCU\..\RunOnce: [SpybotDeletingB6606] command /c del "c:\Program Files\Altnet\Download Manager\asmps.dll"<br>O4 - HKCU\..\RunOnce: [SpybotDeletingD3125] cmd /c del "c:\Program Files\Altnet\Download Manager\asmps.dll"<br>O4 - HKCU\..\RunOnce: [SpybotDeletingB2138] command /c del "c:\Program Files\Altnet\Download Manager\asm.exe"<br>O4 - HKCU\..\RunOnce: [SpybotDeletingD1979] cmd /c del "c:\Program Files\Altnet\Download Manager\asm.exe"<br>O4 - HKCU\..\RunOnce: [SpybotDeletingB6627] command /c del "c:\Program Files\Altnet\Download Manager\asmend.exe"<br>O4 - HKCU\..\RunOnce: [SpybotDeletingD6580] cmd /c del "c:\Program Files\Altnet\Download Manager\asmend.exe"<br>O4 - Global Startup: ATI CATALYST System Tray.lnk = C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe<br>O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe<br>O4 - Global Startup: VTAgentReboot.exe<br>O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\npjpi160_05.dll<br>O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\npjpi160_05.dll<br>O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll<br>O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll<br>O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br>O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br>O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll<br>O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (CDownloadCtrl Object) - &raquo;<A HREF="http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.6.108.cab" >www.fileplanet.com/fpdlmgr/cabs/&middot;&middot;&middot;.108.cab</A><br>O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - &raquo;<A HREF="http://lads.myspace.com/upload/MySpaceUploader1006.cab" >lads.myspace.com/upload/MySpaceU&middot;&middot;&middot;1006.cab</A><br>O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - &raquo;<A HREF="http://www.eset.eu/OnlineScanner.cab" >www.eset.eu/OnlineScanner.cab</A><br>O16 - DPF: {8E6AA867-94D4-4B4F-8791-1B048F8C122A} (WebInterface Class) - &raquo;<small>https</small>://<A HREF="https://fastsend.com/products/Fsplugin.cab">fastsend.com/products/Fsplugin.cab</A><br>O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - &raquo;<A HREF="http://download.games.yahoo.com/games/popcap/zuma/popcaploader_v6.cab" >download.games.yahoo.com/games/p&middot;&middot;&middot;r_v6.cab</A><br>O17 - HKLM\System\CCS\Services\Tcpip\..\{A150BA3B-2BAD-4082-A17D-55E52EDC29B4}: NameServer = 167.206.254.1,167.206.254.2<br>O18 - Filter hijack: text/html - {2AB289AE-4B90-4281-B2AE-1F4BB034B647} - C:\Program Files\RXToolBar\sfcont.dll<br>O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe<br>O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br>O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe<br>O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\SYSTEM32\ati2sgag.exe<br>O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe<br>O23 - Service: EarthLink Monitor Service (EarthLinkMonitor) - Boingo Wireless, Inc. - C:\Program Files\EarthLink TotalAccess\WENGINE\wmonitor.exe<br>O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br>O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe<br>O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br>O23 - Service: License Management Service ESD - Unknown owner - C:\Program Files\Common Files\element5 Shared\Service\Licence Manager ESD.exe<br>O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe<br>O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe<br>O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - McAfee, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe<br>O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe<br>O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe<br>O23 - Service: RaySatxsi5_0 Server (RaySatxsi5_0Server) - Unknown owner - C:\Softimage\XSI_5.0\Application\bin\raysatxsi5_0server.exe<br>O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe<br>O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe<br>O23 - Service: SPM License Server (spmd) - mental images GmbH - C:\WINDOWS\system32\spm\spmd.exe<br>O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe<br>O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe<br><small>--<br>Help us cure TSC and cancer:  <b><A HREF="http://www.dslreports.com/forum/disco">Team Discovery</a></b></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20649603</guid>
<pubDate>Mon, 16 Jun 2008 07:49:47 EDT</pubDate>
</item>

<item>
<title>Re: Malware Protector 2008 - HJT Log</title>
<link>http://www.dslreports.com/forum/remark,20649602</link>
<description><![CDATA[<A HREF="/useremail/u/329157"><b>babacher</b></A> : Here's the online vscan log:<br><br># version=4<br># OnlineScanner.ocx=1.0.0.56<br># OnlineScannerDLLA.dll=1, 0, 0, 51<br># OnlineScannerDLLW.dll=1, 0, 0, 51<br># OnlineScannerUninstaller.exe=1, 0, 0, 49<br># vers_standard_module=3188 (20080615)<br># vers_arch_module=1.064 (20080214)<br># vers_adv_heur_module=1.064 (20070717)<br># EOSSerial=ab201c828c608f439c28f5f7476ff0ba<br># end=finished<br># remove_checked=true<br># unwanted_checked=true<br># utc_time=2008-06-16 06:59:50<br># local_time=2008-06-16 02:59:50 (-0500, Eastern Daylight Time)<br># country="United States"<br># osver=5.1.2600 NT Service Pack 2<br># scanned=485077<br># found=11<br># scan_time=4270<br>C:\Documents and Settings\mattito\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\cnte-dhncgts.jar-4b17516f-655e746f.zip multiple infiltrations (deleted) 00000000000000000000000000000000<br>C:\Documents and Settings\mattito\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\cnte-dhncgts.jar-4b17516f-655e746f.zip &raquo;ZIP &raquo;BnnnnBaa.class Java/ClassLoader trojan (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000<br>C:\Documents and Settings\mattito\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\cnte-dhncgts.jar-4b17516f-655e746f.zip &raquo;ZIP &raquo;VaannnaaBaa.class Java/ClassLoader trojan (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000<br>C:\Documents and Settings\mattito\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\cnte-dhncgts.jar-4b17516f-655e746f.zip &raquo;ZIP &raquo;Dnnny.class Java/Exploit.Bytverify trojan (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000<br>C:\Documents and Settings\mattito\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\cnte-dhncgts.jar-4b17516f-655e746f.zip &raquo;ZIP &raquo;Bnnnnn.class Java/ClassLoader.AS trojan (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000<br>C:\Documents and Settings\mattito\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\cnte-dhncgts.jar-4b17516f-655e746f.zip &raquo;ZIP &raquo;Den.class Java/Exploit.Bytverify trojan (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000<br>C:\Documents and Settings\mattito\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\cnte-dhncgts.jar-4b17516f-655e746f.zip &raquo;ZIP &raquo;Din.class Java/Exploit.Bytverify trojan (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000<br>C:\Documents and Settings\mattito\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\cnte-dhncgts.jar-4b17516f-655e746f.zip &raquo;ZIP &raquo;Dun.class Java/Exploit.Bytverify trojan (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000<br>C:\Downloads\LSLMCLTSetup-dm[1].exe a variant of Win32/Adware.Trymedia application (unable to clean - deleted) 00000000000000000000000000000000<br>C:\WINDOWS\SYSTEM32\lphcl2uj0egbl.exe Win32/TrojanDownloader.FakeAlert.DK trojan (unable to clean - deleted) 00000000000000000000000000000000<br>C:\WINDOWS\SYSTEM32\phcl2uj0egbl.bmp Win32/TrojanDownloader.FakeAlert.DJ trojan (unable to clean - deleted) 00000000000000000000000000000000 <br><small>--<br>Help us cure TSC and cancer:  <b><A HREF="http://www.dslreports.com/forum/disco">Team Discovery</a></b></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20649602</guid>
<pubDate>Mon, 16 Jun 2008 07:48:47 EDT</pubDate>
</item>

<item>
<title>Re: Malware Protector 2008 - HJT Log</title>
<link>http://www.dslreports.com/forum/remark,20648490</link>
<description><![CDATA[<A HREF="/useremail/u/329157"><b>babacher</b></A> : I can't get hold of my nephew this evening - he must be working.  <br><br>Thanks for your suggestions - I'll get him to do those things and report back.<br><small>--<br>Help us cure TSC and cancer:  <b><A HREF="http://www.dslreports.com/forum/disco">Team Discovery</a></b></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20648490</guid>
<pubDate>Sun, 15 Jun 2008 22:22:25 EDT</pubDate>
</item>

<item>
<title>Re: Malware Protector 2008 - HJT Log</title>
<link>http://www.dslreports.com/forum/remark,20645719</link>
<description><![CDATA[<A HREF="/useremail/u/679515"><b>CalamityJane</b></A> : You skipped an important step!<br><br>Using Safe mode with networking, go here and follow step 2 for a full system scan with the Eset online AV scan:<br>&raquo;<A HREF="/faq/seclean">Security Cleanup FAQ</A> &raquo;<A HREF="/faq/13616">Mandatory Steps Before  Requesting Assistance</A><br><br>Post the the scan log when done back here.<br><br>Then download and run this free tool called ComboFix to produce a log please:<br>Please visit this webpage for download links, and instructions for running the tool: &raquo;<A HREF="http://www.bleepingcomputer.com/combofix/how-to-use-combofix" >www.bleepingcomputer.com/combofi&middot;&middot;&middot;combofix</A> <br><br>If you do not have the Windows recovery console installed already, do follow the page's instructions for doing that before you run it.<br><br>When, the tool is finished, it will produce a report for you.  <br>Please post that report located at:  C:\<b>ComboFix.txt</b> along with a <b>new HijackThis log</b>.<br><small>--<br>It takes a disaster to make a woman out of a female<br>Microsoft MVP/Windows Security 2003-2008<br>Proud Member of <A HREF="http://asap.maddoktor2.com/">ASAP </a> (Alliance of Security Analysis Professionals)</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20645719</guid>
<pubDate>Sun, 15 Jun 2008 09:42:54 EDT</pubDate>
</item>

<item>
<title>Malware Protector 2008 - HJT Log</title>
<link>http://www.dslreports.com/forum/remark,20643341</link>
<description><![CDATA[<A HREF="/useremail/u/329157"><b>babacher</b></A> : Please help... my nephew wound up with Malware Protector 2008 on his system and it's well and truly hosed now.  When he tries to boot into normal mode, it sits for over an hour and barely gets anywhere.  He can boot into Safe Mode, but then his keyboard doesn't work. <br><br>We found a website that recommended SmitFraudFix for this problem, but it didn't work.<br><br>Using the Windows on-screen keyboard he was able to download and run Spybot S&D, but it didn't fix the problem either.  <br><br>Ad-Aware wouldn't run, saying "this program has been blocked by the administrator".  That was while he was logged into safe mode AS administrator...<br><br>Windows malicious software removal tool reports no problems.<br><br>So....  here's the HJT log:<br><br>Logfile of Trend Micro HijackThis v2.0.2<br>Scan saved at 15:39:50, on 6/14/2008<br>Platform: Windows XP SP2 (WinNT 5.01.2600)<br>MSIE: Internet Explorer v7.00 (7.00.6000.16674)<br>Boot mode: Safe mode with network support<br>Running processes:<br>C:\WINDOWS\System32\smss.exe<br>C:\WINDOWS\system32\winlogon.exe<br>C:\WINDOWS\system32\services.exe<br>C:\WINDOWS\system32\lsass.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\Program Files\Spyware Doctor\pctsAuxs.exe<br>C:\Program Files\Spyware Doctor\pctsSvc.exe<br>C:\Program Files\Spyware Doctor\pctsTray.exe<br>C:\WINDOWS\Explorer.EXE<br>C:\Program Files\Internet Explorer\iexplore.exe<br>C:\WINDOWS\system32\ctfmon.exe<br>C:\My Downloads\windows-kb890830-v1.42.exe<br>c:\feaaee2d5ab2f21dca42aee1305aa7\mrtstub.exe<br>C:\WINDOWS\system32\MRT.exe<br>C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br>R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = &raquo;<A HREF="http://bfc.myway.com/search/de_srchlft.html" >bfc.myway.com/search/de_srchlft.html</A><br>R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = &raquo;<A HREF="http://www.dell.com" >www.dell.com</A><br>R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\1.bin\deSrcAs.dll<br>O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll<br>O2 - BHO: (no name) - {4D25F921-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\1.bin\deSrcAs.dll<br>O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll<br>O2 - BHO: RXResultTracker Class - {59879FA4-4790-461c-A1CC-4EC4DE4CA483} - C:\Program Files\RXToolBar\sfcont.dll (file missing)<br>O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll<br>O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll<br>O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll<br>O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll<br>O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll<br>O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll<br>O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"<br>O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe<br>O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"<br>O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r<br>O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask<br>O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe<br>O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe<br>O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe<br>O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"<br>O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe<br>O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot<br>O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime<br>O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033<br>O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"<br>O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"<br>O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter<br>O4 - HKLM\..\Run: [lphcl2uj0egbl] C:\WINDOWS\system32\lphcl2uj0egbl.exe<br>O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime<br>O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"<br>O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup<br>O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br>O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe<br>O4 - HKCU\..\RunOnce: [] OSK.exe<br>O4 - HKCU\..\RunOnce: [SpybotDeletingB6606] command /c del "c:\Program Files\Altnet\Download Manager\asmps.dll"<br>O4 - HKCU\..\RunOnce: [SpybotDeletingD3125] cmd /c del "c:\Program Files\Altnet\Download Manager\asmps.dll"<br>O4 - HKCU\..\RunOnce: [SpybotDeletingB2138] command /c del "c:\Program Files\Altnet\Download Manager\asm.exe"<br>O4 - HKCU\..\RunOnce: [SpybotDeletingD1979] cmd /c del "c:\Program Files\Altnet\Download Manager\asm.exe"<br>O4 - HKCU\..\RunOnce: [SpybotDeletingB6627] command /c del "c:\Program Files\Altnet\Download Manager\asmend.exe"<br>O4 - HKCU\..\RunOnce: [SpybotDeletingD6580] cmd /c del "c:\Program Files\Altnet\Download Manager\asmend.exe"<br>O4 - Global Startup: ATI CATALYST System Tray.lnk = C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe<br>O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe<br>O4 - Global Startup: VTAgentReboot.exe<br>O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\npjpi160_05.dll<br>O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\npjpi160_05.dll<br>O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll<br>O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll<br>O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br>O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br>O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll<br>O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (CDownloadCtrl Object) - &raquo;<A HREF="http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.6.108.cab" >www.fileplanet.com/fpdlmgr/cabs/&middot;&middot;&middot;.108.cab</A><br>O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - &raquo;<A HREF="http://lads.myspace.com/upload/MySpaceUploader1006.cab" >lads.myspace.com/upload/MySpaceU&middot;&middot;&middot;1006.cab</A><br>O16 - DPF: {8E6AA867-94D4-4B4F-8791-1B048F8C122A} (WebInterface Class) - &raquo;<small>https</small>://<A HREF="https://fastsend.com/products/Fsplugin.cab">fastsend.com/products/Fsplugin.cab</A><br>O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - &raquo;<A HREF="http://download.games.yahoo.com/games/popcap/zuma/popcaploader_v6.cab" >download.games.yahoo.com/games/p&middot;&middot;&middot;r_v6.cab</A><br>O17 - HKLM\System\CCS\Services\Tcpip\..\{A150BA3B-2BAD-4082-A17D-55E52EDC29B4}: NameServer = 167.206.254.1,167.206.254.2<br>O18 - Filter hijack: text/html - {2AB289AE-4B90-4281-B2AE-1F4BB034B647} - C:\Program Files\RXToolBar\sfcont.dll<br>O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe<br>O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br>O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe<br>O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\SYSTEM32\ati2sgag.exe<br>O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe<br>O23 - Service: EarthLink Monitor Service (EarthLinkMonitor) - Boingo Wireless, Inc. - C:\Program Files\EarthLink TotalAccess\WENGINE\wmonitor.exe<br>O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br>O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe<br>O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br>O23 - Service: License Management Service ESD - Unknown owner - C:\Program Files\Common Files\element5 Shared\Service\Licence Manager ESD.exe<br>O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe<br>O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe<br>O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - McAfee, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe<br>O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe<br>O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe<br>O23 - Service: RaySatxsi5_0 Server (RaySatxsi5_0Server) - Unknown owner - C:\Softimage\XSI_5.0\Application\bin\raysatxsi5_0server.exe<br>O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe<br>O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe<br>O23 - Service: SPM License Server (spmd) - mental images GmbH - C:\WINDOWS\system32\spm\spmd.exe<br>O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe<br>O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe<br><small>--<br>Help us cure TSC and cancer:  <b><A HREF="http://www.dslreports.com/forum/disco">Team Discovery</a></b></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20643341</guid>
<pubDate>Sat, 14 Jun 2008 16:06:45 EDT</pubDate>
</item>

</channel>
</rss>
