<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Re: [Vundo] Vundo again.. can I get help 1 more time.. in Security Cleanup</title>
<link>http://www.dslreports.com/forum/r20705605</link>
<description></description>
<language>en</language>
<pubDate>Thu, 03 Dec 2009 05:07:31 EDT</pubDate>
<lastBuildDate>Thu, 03 Dec 2009 05:07:31 EDT</lastBuildDate>

<item>
<title>Re: [Vundo] Vundo again.. can I get help 1 more time..</title>
<link>http://www.dslreports.com/forum/remark,20757597</link>
<description><![CDATA[<A HREF="/useremail/u/693977"><b>bcastner</b></A> : Open <b>OTMOVEIT2</b> again and click the <b>CleanUP!</b> button.  Some firewalls might notify you that it is trying to accesss the internet -- it is, to download a script, please permit it.<br><br>You can uninstall <b>MBAM</b>.  You can delete or keep <b>ATF Cleaner</b> as you wish.<br><br>See about getting Service Pack 1 for Vista installed.<br><br>Best wishes,<br>Bill Castner<br><small>--<br><b>============</b><br><b>MS-MVP 2004 - -2008, ASAP Member</b><br><b><i>Users Helping Users</i></b><br><br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20757597</guid>
<pubDate>Tue, 08 Jul 2008 09:21:54 EDT</pubDate>
</item>

<item>
<title>Re: [Vundo] Vundo again.. can I get help 1 more time..</title>
<link>http://www.dslreports.com/forum/remark,20754209</link>
<description><![CDATA[<A HREF="/useremail/u/290394"><b>Ap4mvp</b></A> : Sorry guys been busy.. Everything is working normally again.. no popups or anything. Thanks again?<br><small>--<br>Uh-huh, and let me know when Elvis gets here.</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20754209</guid>
<pubDate>Mon, 07 Jul 2008 15:37:43 EDT</pubDate>
</item>

<item>
<title>Re: [Vundo] Vundo again.. can I get help 1 more time..</title>
<link>http://www.dslreports.com/forum/remark,20708526</link>
<description><![CDATA[<A HREF="/useremail/u/693977"><b>bcastner</b></A> : Well, just to be thorough and sure about things:<br><br>Please download<b>  <i>ATF Cleaner</i></b>  <br><br><textarea name="code" class="text" cols=50 rows=10>http://www.atribune.org/ccount/click.php?id=1&#012; &#012;</textarea><!--end code block-->It does not require any installation.. It is set up to clean Windows 2k, XP & Vista TEMP folders, as well as IE, FireFox and Opera, Temporary Internet Files and Cookies.<br>&#8226;      Double-click <b>ATF-Cleaner.exe</b> to run the program. <br><b>For all browsers:</b><br>&#8226;      Under <b>Main</b> choose: <b>Select All</b><br>&#8226;      Click the <b>Empty Selected</b> button. <br><b><u>Next, if you use Firefox (and <i>some</i> Mozilla-based browsers)</u></b> <br>&#8226;      Click Firefox at the top and choose: <b>Select All</b><br>&#8226;      Click the <b>Empty Selected</b> button. <b><u><br>Next, if you use the Opera browser</u></b> <br>&#8226;      Click <b>Opera</b> at the top and choose: <b>Select All</b> <br>&#8226;      Click the <b>Empty Selected</b> button. <b>:!: Click Exit on the Main menu to close the program.</b><br><br><b>Reconfigure Windows Vista to show hidden files:</b><br>To enable the viewing of Hidden files follow these steps: <br>&#8226; Close all programs so that you are at your desktop. <br>&#8226; Open the Control Panel menu and click <b>Folder Options</b>. <br>&#8226; After the new window appears select the <b>View</b> tab. <br>&#8226; Put a checkmark in the checkbox labeled Display the contents of system folders. <br>&#8226; Under the Hidden files and folders section select the radio button labeled Show hidden files and folders. <br>&#8226; Remove the checkmark from the checkbox labeled Hide file extensions for known file types. <br>&#8226; Remove the checkmark from the checkbox labeled Hide protected operating system files. <br>&#8226; Press the Apply button and then the OK button and exit My Computer. <br>&#8226; Now your computer is configured to show all hidden files. <b><u>Malware Removal Steps</u></b><br><br>1. Open <b>HijackThis</b> again, System scan only.  <b>Checkmark</b> these items:<br><br><b>O2 - BHO: (no name) - {61EF0506-799C-40DD-95AF-872B400563A8} - C:\Users\Bry4n\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SSQW9AEV\3077ahntdksr[1].dll<br>O2 - BHO: (no name) - {C7B2C876-660F-478E-B52D-FA2A4600E3C2} - C:\Users\Bry4n\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SSQW9AEV\3077ahntdksr[1].dll</b><br><br>Click "<b>Fix checked</b>" and when the log panel clears exit HijackThis.<br><br>2. Manually do a definition update in AVAST!, then do as thorough a complete system scan as can be configured.<br><small>--<br><b>============</b><br><b>MS-MVP 2004 - -2008, ASAP Member</b><br><b><i>Users Helping Users</i></b><br><br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20708526</guid>
<pubDate>Fri, 27 Jun 2008 15:04:19 EDT</pubDate>
</item>

<item>
<title>Re: [Vundo] Vundo again.. can I get help 1 more time..</title>
<link>http://www.dslreports.com/forum/remark,20708131</link>
<description><![CDATA[<A HREF="/useremail/u/290394"><b>Ap4mvp</b></A> : I did have an internet explorer pop up and minute ago so I thought Vundo was back.. after I did a new HJT and didnt see any weird DLL files so Assume it was a normal antivirus popup..Ill let ya know if I have any more troubles.. thanks.<br><small>--<br>Uh-huh, and let me know when Elvis gets here.</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20708131</guid>
<pubDate>Fri, 27 Jun 2008 13:41:24 EDT</pubDate>
</item>

<item>
<title>Re: [Vundo] Vundo again.. can I get help 1 more time..</title>
<link>http://www.dslreports.com/forum/remark,20708095</link>
<description><![CDATA[<A HREF="/useremail/u/693977"><b>bcastner</b></A> : That looks like a clean result to me.<br><br>I am sorry to have pushed you about an antivirus software program.  It is just too tough out there on the internet to not have one installed and with current definitions.<br><br>If you intend to replace AVAST!, remember that less is more when it comes to active antivirus programs -- install only one, and after (not before) Uninstalling what is now in place.<br><br>But I suspect your Vundo infection has been cleared by the steps you have taken; your HijackThis log looks clean.<br><br>Best wishes,<br>Bill Castner<br><small>--<br><b>============</b><br><b>MS-MVP 2004 - -2008, ASAP Member</b><br><b><i>Users Helping Users</i></b><br><br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20708095</guid>
<pubDate>Fri, 27 Jun 2008 13:32:18 EDT</pubDate>
</item>

<item>
<title>Re: [Vundo] Vundo again.. can I get help 1 more time..</title>
<link>http://www.dslreports.com/forum/remark,20708030</link>
<description><![CDATA[<A HREF="/useremail/u/290394"><b>Ap4mvp</b></A> : OK I downloaded and ran Avast.. and am planning on getting Norton.. it seems my Windows explorer is no longer crashing either.. Ran the steps again and here are my logs.. Ran ATF Cleaner and OTMoveit2..and installed Boclean.. Hows it look?<br><br>Malwarebytes' Anti-Malware 1.18<br>Database version: 895<br><br>12:00:26 PM 6/27/2008<br>mbam-log-6-27-2008 (12-00-26).txt<br><br>Scan type: Full Scan (C:\|J:\|)<br>Objects scanned: 129079<br>Time elapsed: 1 hour(s), 38 minute(s), 52 second(s)<br><br>Memory Processes Infected: 0<br>Memory Modules Infected: 1<br>Registry Keys Infected: 6<br>Registry Values Infected: 8<br>Registry Data Items Infected: 2<br>Folders Infected: 0<br>Files Infected: 7<br><br>Memory Processes Infected:<br>(No malicious items detected)<br><br>Memory Modules Infected:<br>C:\Windows\System32\ssQkJbAs.dll (Trojan.Vundo) -> Unloaded module successfully.<br><br>Registry Keys Infected:<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{f7b17545-4e7c-4433-b4f4-617a5944201f} (Trojan.Vundo) -> Delete on reboot.<br>HKEY_CLASSES_ROOT\CLSID\{f7b17545-4e7c-4433-b4f4-617a5944201f} (Trojan.Vundo) -> Quarantined and deleted successfully.<br>HKEY_CLASSES_ROOT\CLSID\{bd3c6f7c-6c8d-48f6-ac52-5e4071aeb257} (Trojan.Vundo) -> Quarantined and deleted successfully.<br>HKEY_CLASSES_ROOT\WR (Malware.Trace) -> Quarantined and deleted successfully.<br>HKEY_CURRENT_USER\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> Quarantined and deleted successfully.<br><br>Registry Values Infected:<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{bd3c6f7c-6c8d-48f6-ac52-5e4071aeb257} (Trojan.Vundo) -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\MSServer (Trojan.Agent) -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\6832c758 (Trojan.Vundo) -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\BM6b01f4c4 (Trojan.Agent) -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\bf (Trojan.Agent) -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\bk (Trojan.Agent) -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\iu (Trojan.Agent) -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\mu (Trojan.Agent) -> Quarantined and deleted successfully.<br><br>Registry Data Items Infected:<br>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Authentication Packages (Trojan.Vundo) -> Data: c:\windows\system32\ssqkjbas -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Authentication Packages (Trojan.Vundo) -> Data: c:\windows\system32\ssqkjbas  -> Quarantined and deleted successfully.<br><br>Folders Infected:<br>(No malicious items detected)<br><br>Files Infected:<br>C:\Windows\System32\ssQkJbAs.dll (Trojan.Vundo) -> Delete on reboot.<br>C:\Windows\System32\sAbJkQss.ini (Trojan.Vundo) -> Quarantined and deleted successfully.<br>C:\Windows\System32\sAbJkQss.ini2 (Trojan.Vundo) -> Quarantined and deleted successfully.<br>C:\Windows\System32\tcphklnx.dll (Trojan.Vundo) -> Quarantined and deleted successfully.<br>C:\Windows\System32\xnlkhpct.ini (Trojan.Vundo) -> Quarantined and deleted successfully.<br>C:\Windows\System32\akineiut.dll (Trojan.Agent) -> Delete on reboot.<br>C:\Windows\System32\clkcnt.txt (Trojan.Vundo) -> Quarantined and deleted successfully.<br><br>Logfile of Trend Micro HijackThis v2.0.2<br>Scan saved at 12:13, on 2008-06-27<br>Platform: Windows Vista  (WinNT 6.00.1904)<br>MSIE: Internet Explorer v7.00 (7.00.6000.16681)<br>Boot mode: Normal<br><br>Running processes:<br>C:\Windows\system32\Dwm.exe<br>C:\Windows\Explorer.EXE<br>C:\Windows\system32\taskeng.exe<br>C:\Program Files\Google\Gmail Notifier\gnotify.exe<br>C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe<br>C:\Program Files\iTunes\iTunesHelper.exe<br>C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe<br>C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe<br>C:\Windows\System32\igfxtray.exe<br>C:\Windows\System32\hkcmd.exe<br>C:\Windows\system32\igfxsrvc.exe<br>C:\Windows\System32\igfxpers.exe<br>C:\Program Files\Alwil Software\Avast4\ashDisp.exe<br>C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe<br>C:\Program Files\WinTidy\WinTidy.exe<br>C:\Windows\System32\mobsync.exe<br>C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe<br>C:\Program Files\Windows Media Player\wmplayer.exe<br>C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br><br>R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=69157" >go.microsoft.com/fwlink/?LinkId=69157</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=69157" >go.microsoft.com/fwlink/?LinkId=69157</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=69157" >go.microsoft.com/fwlink/?LinkId=69157</A><br>R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local<br>R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = <br>O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll<br>O2 - BHO: (no name) - {61EF0506-799C-40DD-95AF-872B400563A8} - C:\Users\Bry4n\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SSQW9AEV\3077ahntdksr[1].dll<br>O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll<br>O2 - BHO: (no name) - {C7B2C876-660F-478E-B52D-FA2A4600E3C2} - C:\Users\Bry4n\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SSQW9AEV\3077ahntdksr[1].dll<br>O4 - HKLM\..\Run: [PWRISOVM.EXE] "C:\Program Files\PowerISO\PWRISOVM.EXE"<br>O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] "C:\Program Files\Google\Gmail Notifier\gnotify.exe"<br>O4 - HKLM\..\Run: [AnyDVD] "C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe"<br>O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime<br>O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"<br>O4 - HKLM\..\Run: [NeroFilterCheck] "C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe"<br>O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"<br>O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"<br>O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe<br>O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe<br>O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe<br>O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\Windows\system32\WLTRAY.exe<br>O4 - HKLM\..\Run: [Switcher.exe] C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe<br>O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe<br>O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"<br>O4 - HKCU\..\Run: [DU Meter] C:\Program Files\DU Meter\DUMeter.exe<br>O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')<br>O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')<br>O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')<br>O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe<br>O4 - Startup: WinTidy.lnk = C:\Program Files\WinTidy\WinTidy.exe<br>O4 - Global Startup: hpzrcv01.LNK = ?<br>O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000<br>O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\npjpi160_06.dll<br>O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\npjpi160_06.dll<br>O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll<br>O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll<br>O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL<br>O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll<br>O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll<br>O13 - Gopher Prefix: <br>O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - &raquo;<A HREF="http://www.eset.eu/OnlineScanner.cab" >www.eset.eu/OnlineScanner.cab</A><br>O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - &raquo;<A HREF="http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab" >fpdownload2.macromedia.com/get/s&middot;&middot;&middot;lash.cab</A><br>O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~3\Office12\GR99D3~1.DLL<br>O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe<br>O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe<br>O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br>O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe<br>O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe<br>O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe<br>O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe<br>O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br>O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)<br>O23 - Service: DU Meter Service (DUMeterSvc) - Hagel Technologies Ltd - C:\Program Files\DU Meter\DUMeterSvc.exe<br>O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br>O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe<br>O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe<br>O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe<br>O23 - Service: VundoFix Service (VundoFixSvc) - Atribune.org - C:\Windows\SYSTEM32\VundoFixSVC.exe<br><br>--<br>End of file - 7495 bytes<br><br>Does anyone see anything else that needs to be fixed? Thanks.<br><small>--<br>Uh-huh, and let me know when Elvis gets here.</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20708030</guid>
<pubDate>Fri, 27 Jun 2008 13:21:24 EDT</pubDate>
</item>

<item>
<title>Re: [Vundo] Vundo again.. can I get help 1 more time..</title>
<link>http://www.dslreports.com/forum/remark,20705825</link>
<description><![CDATA[<A HREF="/useremail/u/693977"><b>bcastner</b></A> : This is a new infection.<br><br>I note only in declinging to personally help again, that you have not installed or use an active antivirus software program.<br><br>It appears that your Norton/Symantec license has expired, and the active components have been disabled as a result.<br><br>You are actually more infected than the last time, in terms of the complexity of the removal; but in terms of the number of infectors about the same.<br><br>It is obvious to me your surfing habits are unsafe, you have no antivirus installed, you are now completely dependent on SpySweeper and it cannot help you avoid this class of infection, just the like the last time.  Nothing has changed.<br><br>I hope my colleagues will have specific advice to offer, but I can only suggest:<br><br>1. Uninstall Norton/Symantec.  It no longer is an active antivirus for you.<br><br>2. If cost is an issue, install either Antivur or AVAST!, both very competent freeware choices.<br><br>3. Uninstall SpySweeper if it is not a fully current and paid subscription.  It has done nothing to help in the past, and its prospect for the future are equally dismal.<br><br>4. Use your new antivirus program to scan once in Safe Mode, and once in Normal mode.  Do not skip this step.<br><br>5. Then repeat my original instructions as to the use of a new installation of <b>MBAM</b>, and a new download and use of Combofix.<br><br>5. Redo your HijackThis report, and post it again.  I suspect you will get an "all clean" report from any helper, just from these steps alone.<br><br>Bill Castner<br><small>--<br><b>============</b><br><b>MS-MVP 2004 - -2008, ASAP Member</b><br><b><i>Users Helping Users</i></b><br><br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20705825</guid>
<pubDate>Fri, 27 Jun 2008 00:05:42 EDT</pubDate>
</item>

<item>
<title>Re: [Vundo] Vundo again.. can I get help 1 more time..</title>
<link>http://www.dslreports.com/forum/remark,20705605</link>
<description><![CDATA[<A HREF="/useremail/u/751678"><b>lilhurricane</b></A> : For reference only: &raquo;<A HREF="/forum/r20566030-Vundo-Ran-all-spyware-software-still-have-Vundo">[Vundo] Ran all spyware software.. still have Vundo..</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20705605</guid>
<pubDate>Thu, 26 Jun 2008 23:16:08 EDT</pubDate>
</item>

<item>
<title>[Vundo] Vundo again.. can I get help 1 more time..</title>
<link>http://www.dslreports.com/forum/remark,20705599</link>
<description><![CDATA[<A HREF="/useremail/u/290394"><b>Ap4mvp</b></A> : I ran all the software again.. they all found Vundo but couldn't remove it :(  heres my HJT.. thanks!<br><br>Logfile of Trend Micro HijackThis v2.0.2<br>Scan saved at 10:14:20 PM, on 6/26/2008<br>Platform: Windows Vista  (WinNT 6.00.1904)<br>MSIE: Internet Explorer v7.00 (7.00.6000.16681)<br>Boot mode: Normal<br><br>Running processes:<br>C:\Windows\system32\Dwm.exe<br>C:\Windows\system32\taskeng.exe<br>C:\Program Files\Google\Gmail Notifier\gnotify.exe<br>C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe<br>C:\Program Files\iTunes\iTunesHelper.exe<br>C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe<br>C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe<br>C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe<br>C:\Windows\System32\igfxtray.exe<br>C:\Windows\System32\hkcmd.exe<br>C:\Windows\System32\igfxpers.exe<br>C:\Windows\system32\igfxsrvc.exe<br>C:\Windows\System32\rundll32.exe<br>C:\Windows\System32\rundll32.exe<br>C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe<br>C:\Program Files\DU Meter\DUMeter.exe<br>C:\Program Files\WinTidy\WinTidy.exe<br>C:\Windows\Explorer.exe<br>C:\Windows\System32\mobsync.exe<br>C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe<br>C:\Program Files\Mozilla Firefox\firefox.exe<br>C:\Windows\system32\SearchFilterHost.exe<br>C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br><br>R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=69157" >go.microsoft.com/fwlink/?LinkId=69157</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=69157" >go.microsoft.com/fwlink/?LinkId=69157</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=69157" >go.microsoft.com/fwlink/?LinkId=69157</A><br>R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local<br>R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = <br>O2 - BHO: (no name) - {3FB29DDE-1829-48F5-8DD5-E87B955B221e} - C:\Windows\system32\dtqfuysu.dll<br>O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll<br>O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll<br>O2 - BHO: (no name) - {929FB757-327A-4F9A-8081-5134D77C934D} - C:\Windows\system32\ssQkJbAs.dll<br>O2 - BHO: (no name) - {CBA8AE4E-7387-4D49-A626-39D7FADA98F0} - C:\Users\Bry4n\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SKPXE4XC\3077ahntdksr[1].dll<br>O4 - HKLM\..\Run: [PWRISOVM.EXE] "C:\Program Files\PowerISO\PWRISOVM.EXE"<br>O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] "C:\Program Files\Google\Gmail Notifier\gnotify.exe"<br>O4 - HKLM\..\Run: [AnyDVD] "C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe"<br>O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime<br>O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"<br>O4 - HKLM\..\Run: [NeroFilterCheck] "C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe"<br>O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"<br>O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"<br>O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"<br>O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe<br>O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe<br>O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe<br>O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\Windows\system32\WLTRAY.exe<br>O4 - HKLM\..\Run: [Switcher.exe] C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe<br>O4 - HKLM\..\Run: [6832c758] "rundll32.exe" "C:\Windows\system32\tcphklnx.dll",b<br>O4 - HKLM\..\Run: [MSServer] "rundll32.exe" C:\Windows\system32\iifdbBus.dll,#1<br>O4 - HKLM\..\Run: [BM6b01f4c4] Rundll32.exe "C:\Windows\system32\akineiut.dll",s<br>O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray<br>O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"<br>O4 - HKCU\..\Run: [DU Meter] "C:\Program Files\DU Meter\DUMeter.exe"<br>O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')<br>O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')<br>O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')<br>O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe<br>O4 - Startup: WinTidy.lnk = C:\Program Files\WinTidy\WinTidy.exe<br>O4 - Global Startup: hpzrcv01.LNK = ?<br>O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000<br>O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\npjpi160_06.dll<br>O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\npjpi160_06.dll<br>O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll<br>O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll<br>O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL<br>O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll<br>O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll<br>O13 - Gopher Prefix: <br>O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - &raquo;<A HREF="http://www.eset.eu/OnlineScanner.cab" >www.eset.eu/OnlineScanner.cab</A><br>O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - &raquo;<A HREF="http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab" >fpdownload2.macromedia.com/get/s&middot;&middot;&middot;lash.cab</A><br>O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~3\Office12\GR99D3~1.DLL<br>O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe<br>O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe<br>O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br>O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br>O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)<br>O23 - Service: DU Meter Service (DUMeterSvc) - Hagel Technologies Ltd - C:\Program Files\DU Meter\DUMeterSvc.exe<br>O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br>O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)<br>O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe<br>O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe<br>O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe<br>O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe<br>O23 - Service: VundoFix Service (VundoFixSvc) - Atribune.org - C:\Windows\SYSTEM32\VundoFixSVC.exe<br>O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe<br><br>--<br>End of file - 8277 bytes<br><small>--<br>Uh-huh, and let me know when Elvis gets here.</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20705599</guid>
<pubDate>Thu, 26 Jun 2008 23:14:57 EDT</pubDate>
</item>

</channel>
</rss>
