<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>[Vundo] Vundo keeps coming back in Security Cleanup</title>
<link>http://www.dslreports.com/forum/r20755959</link>
<description></description>
<language>en</language>
<pubDate>Sun, 29 Nov 2009 09:35:15 EDT</pubDate>
<lastBuildDate>Sun, 29 Nov 2009 09:35:15 EDT</lastBuildDate>

<item>
<title>Re: [Vundo] Vundo keeps coming back</title>
<link>http://www.dslreports.com/forum/remark,20757485</link>
<description><![CDATA[<A HREF="/useremail/u/855835"><b>CajunTek</b></A> : <div class="bquote"><small>said by  bronc0fan <A HREF="/useremail/u/591558"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>Thanks for your help, everything running fine so far.<br> </div>No problem... Glad we could help!!!<br><small>--<br>da Cajun  Darn I hate Malware</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20757485</guid>
<pubDate>Tue, 08 Jul 2008 08:42:26 EDT</pubDate>
</item>

<item>
<title>Re: [Vundo] Vundo keeps coming back</title>
<link>http://www.dslreports.com/forum/remark,20757387</link>
<description><![CDATA[<A HREF="/useremail/u/591558"><b>bronc0fan</b></A> : Thanks for your help, everything running fine so far.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20757387</guid>
<pubDate>Tue, 08 Jul 2008 07:59:37 EDT</pubDate>
</item>

<item>
<title>Re: [Vundo] Vundo keeps coming back</title>
<link>http://www.dslreports.com/forum/remark,20757324</link>
<description><![CDATA[<A HREF="/useremail/u/855835"><b>CajunTek</b></A> : Your logs are now clean.. It looks like between mbam and combofix we got it. Are you still having problems? If so let us know and we can try other measures.<br><small>--<br>da Cajun  Darn I hate Malware</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20757324</guid>
<pubDate>Tue, 08 Jul 2008 07:21:56 EDT</pubDate>
</item>

<item>
<title>Re: [Vundo] Vundo keeps coming back</title>
<link>http://www.dslreports.com/forum/remark,20756724</link>
<description><![CDATA[<A HREF="/useremail/u/591558"><b>bronc0fan</b></A> : OK here are the 3 logs you need:<br><br>Malwarebytes' Anti-Malware 1.20<br>Database version: 931<br>Windows 5.1.2600 Service Pack 2<br><br>9:49:16 PM 7/7/2008<br>mbam-log-7-7-2008 (21-49-16).txt<br><br>Scan type: Quick Scan<br>Objects scanned: 53811<br>Time elapsed: 6 minute(s), 21 second(s)<br><br>Memory Processes Infected: 0<br>Memory Modules Infected: 0<br>Registry Keys Infected: 6<br>Registry Values Infected: 0<br>Registry Data Items Infected: 0<br>Folders Infected: 0<br>Files Infected: 4<br><br>Memory Processes Infected:<br>(No malicious items detected)<br><br>Memory Modules Infected:<br>(No malicious items detected)<br><br>Registry Keys Infected:<br>HKEY_CLASSES_ROOT\CLSID\{87255c51-cd7d-4506-b9ad-97606daf53f3} (Adware.Coupons) -> Quarantined and deleted successfully.<br>HKEY_CURRENT_USER\SOFTWARE\Trymedia Systems (Adware.Trymedia) -> Quarantined and deleted successfully.<br>HKEY_CURRENT_USER\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> Quarantined and deleted successfully.<br><br>Registry Values Infected:<br>(No malicious items detected)<br><br>Registry Data Items Infected:<br>(No malicious items detected)<br><br>Folders Infected:<br>(No malicious items detected)<br><br>Files Infected:<br>C:\WINDOWS\system32\pmevclms.dll (Trojan.Vundo) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\smlcvemp.ini (Trojan.Vundo) -> Quarantined and deleted successfully.<br>C:\WINDOWS\cookies.ini (Malware.Trace) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\clkcnt.txt (Trojan.Vundo) -> Quarantined and deleted successfully.<br>*******<br>ComboFix 08-07-05.1 - Owner 2008-07-07 22:07:07.1 - NTFSx86<br>Microsoft Windows XP Professional  5.1.2600.2.1252.1.1033.18.1271 [GMT -6:00]<br>Running from: C:\Documents and Settings\Owner.MAINCPU\Desktop\ComboFix.exe<br> * Created a new restore point<br><br>[color=red]<b>WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!</b>[/color]<br>.<br><br>(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br><br>C:\WINDOWS\BM131879de.txt<br>C:\WINDOWS\pskt.ini<br>C:\WINDOWS\system32\akgimlto.dll<br>C:\WINDOWS\system32\faobkbeb.dll<br>C:\WINDOWS\system32\gnfnjeib.ini<br>C:\WINDOWS\system32\igweyqxn.ini<br>C:\WINDOWS\system32\mcrh.tmp<br>C:\WINDOWS\system32\nherhfnm.ini<br>C:\WINDOWS\system32\OrAycccf.ini<br>C:\WINDOWS\system32\OrAycccf.ini2<br>C:\WINDOWS\system32\qdykemlv.dll<br>C:\WINDOWS\system32\qgfxyz.dll<br>C:\WINDOWS\system32\usugkjvi.ini<br>C:\WINDOWS\system32\uyrfzd.dll<br>C:\WINDOWS\system32\vicpjlfp.ini<br>C:\WINDOWS\system32\wqknvsil.ini<br>C:\WINDOWS\system32\xxtwnrnn.ini<br>D:\Autorun.inf<br><br>.<br>(((((((((((((((((((((((((   Files Created from 2008-06-08 to 2008-07-08  )))))))))))))))))))))))))))))))<br>.<br><br>2008-07-07 21:36 . 2008-07-07 21:36&#9;&#9;d--------&#9;C:\Program Files\Malwarebytes' Anti-Malware<br>2008-07-07 21:36 . 2008-07-07 21:36&#9;&#9;d--------&#9;C:\Documents and Settings\Owner.MAINCPU\Application Data\Malwarebytes<br>2008-07-07 21:36 . 2008-07-07 21:36&#9;&#9;d--------&#9;C:\Documents and Settings\All Users\Application Data\Malwarebytes<br>2008-07-07 21:36 . 2008-07-07 17:42&#9;34,296&#9;--a------&#9;C:\WINDOWS\system32\drivers\mbamcatchme.sys<br>2008-07-07 21:36 . 2008-07-07 17:42&#9;17,144&#9;--a------&#9;C:\WINDOWS\system32\drivers\mbam.sys<br>2008-07-07 18:41 . 2008-07-07 18:51&#9;&#9;d--------&#9;C:\HJT<br>2008-07-06 20:52 . 2008-07-06 20:52&#9;&#9;d--------&#9;C:\VundoFix Backups<br>2008-07-06 02:14 . 2008-07-06 02:14&#9;&#9;d--------&#9;C:\Program Files\Windows Defender<br>2008-07-05 10:11 . 2008-07-05 10:22&#9;&#9;d--------&#9;C:\Program Files\SpywareBlaster<br>2008-07-05 09:48 . 2008-07-05 09:48&#9;&#9;d--------&#9;C:\Program Files\Trend Micro<br>2008-06-23 19:32 . 2008-06-23 19:32&#9;&#9;d--------&#9;C:\Program Files\Lavasoft<br>2008-06-23 19:32 . 2008-06-23 19:33&#9;&#9;d--------&#9;C:\Documents and Settings\All Users\Application Data\Lavasoft<br>2008-06-23 19:31 . 2008-06-23 19:31&#9;&#9;d--------&#9;C:\Program Files\Common Files\Wise Installation Wizard<br>2008-06-21 23:44 . 2008-07-05 10:11&#9;110,369&#9;--a------&#9;C:\WINDOWS\BM131879de.xml<br>2008-06-21 11:35 . 2008-06-21 11:35&#9;&#9;d--------&#9;C:\Program Files\Sony Setup<br>2008-06-21 11:29 . 2008-06-21 11:29&#9;&#9;d--------&#9;C:\Program Files\Free RAR Extract Frog<br>2008-06-11 05:51 . 2008-06-13 07:10&#9;272,128&#9;---------&#9;C:\WINDOWS\system32\drivers\bthport.sys<br>2008-06-11 05:51 . 2008-06-13 07:10&#9;272,128&#9;-----c---&#9;C:\WINDOWS\system32\dllcache\bthport.sys<br>2008-06-08 16:28 . 2008-06-08 16:28&#9;&#9;d--------&#9;C:\Documents and Settings\Owner.MAINCPU\Application Data\DivX<br>2008-06-08 16:07 . 2008-06-08 16:07&#9;&#9;d--------&#9;C:\Documents and Settings\Owner.MAINCPU\Temp<br>2008-06-08 09:19 . 2008-05-22 16:22&#9;120,056&#9;---------&#9;C:\WINDOWS\system32\pxcpyi64.exe<br><br>.<br>((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br>2008-07-08 04:13&#9;---------&#9;d-----w&#9;C:\Program Files\BOINC<br>2008-07-08 04:10&#9;---------&#9;d-----w&#9;C:\Documents and Settings\Owner.MAINCPU\Application Data\DNA<br>2008-07-08 03:22&#9;---------&#9;d---a-w&#9;C:\Documents and Settings\All Users\Application Data\TEMP<br>2008-07-08 00:12&#9;---------&#9;d-----w&#9;C:\Program Files\Java<br>2008-07-07 23:32&#9;---------&#9;d-----w&#9;C:\Program Files\McAfee<br>2008-07-04 20:42&#9;1,252&#9;----a-w&#9;C:\Documents and Settings\Owner.MAINCPU\Application Data\wklnhst.dat<br>2008-07-01 04:44&#9;---------&#9;d-----w&#9;C:\Program Files\Oberon Media<br>2008-06-27 04:42&#9;---------&#9;d-----w&#9;C:\Documents and Settings\Owner.MAINCPU\Application Data\Move Networks<br>2008-06-27 01:18&#9;---------&#9;d-----w&#9;C:\Documents and Settings\All Users\Application Data\Zylom<br>2008-06-24 05:55&#9;---------&#9;d-----w&#9;C:\Documents and Settings\Owner.MAINCPU\Application Data\SiteAdvisor<br>2008-06-23 03:56&#9;---------&#9;d-----w&#9;C:\Program Files\Gateway Games<br>2008-06-10 03:14&#9;---------&#9;d--h--w&#9;C:\Program Files\InstallShield Installation Information<br>2008-06-10 03:12&#9;---------&#9;d-----w&#9;C:\Program Files\CyberLink<br>2008-06-09 01:24&#9;---------&#9;d-----w&#9;C:\Documents and Settings\Owner.MAINCPU\Application Data\Azureus<br>2008-06-08 22:08&#9;---------&#9;d-----w&#9;C:\Program Files\Azureus<br>2008-06-08 15:19&#9;---------&#9;d-----w&#9;C:\Program Files\DivX<br>2008-06-07 04:57&#9;---------&#9;d-----w&#9;C:\Program Files\DNA<br>2008-06-06 03:56&#9;---------&#9;d-----w&#9;C:\Documents and Settings\All Users\Application Data\Azureus<br>2008-05-30 23:12&#9;---------&#9;d-----w&#9;C:\Program Files\Windows Media Connect 2<br>2008-05-22 11:50&#9;---------&#9;d-----w&#9;C:\Program Files\SiteAdvisor<br>2008-05-08 12:28&#9;202,752&#9;----a-w&#9;C:\WINDOWS\system32\drivers\rmcast.sys<br>2007-01-26 12:40&#9;92,064&#9;----a-w&#9;C:\Documents and Settings\Owner.MAINCPU\mqdmmdm.sys<br>2007-01-26 12:40&#9;9,232&#9;----a-w&#9;C:\Documents and Settings\Owner.MAINCPU\mqdmmdfl.sys<br>2007-01-26 12:40&#9;79,328&#9;----a-w&#9;C:\Documents and Settings\Owner.MAINCPU\mqdmserd.sys<br>2007-01-26 12:40&#9;66,656&#9;----a-w&#9;C:\Documents and Settings\Owner.MAINCPU\mqdmbus.sys<br>2007-01-26 12:40&#9;6,208&#9;----a-w&#9;C:\Documents and Settings\Owner.MAINCPU\mqdmcmnt.sys<br>2007-01-26 12:40&#9;5,936&#9;----a-w&#9;C:\Documents and Settings\Owner.MAINCPU\mqdmwhnt.sys<br>2007-01-26 12:40&#9;4,048&#9;----a-w&#9;C:\Documents and Settings\Owner.MAINCPU\mqdmcr.sys<br>2007-01-26 12:40&#9;25,600&#9;----a-w&#9;C:\Documents and Settings\Owner.MAINCPU\usbsermptxp.sys<br>2007-01-26 12:40&#9;22,768&#9;----a-w&#9;C:\Documents and Settings\Owner.MAINCPU\usbsermpt.sys<br>2007-03-09 07:12&#9;27,648&#9;--sha-w&#9;C:\WINDOWS\system32\AVSredirect.dll<br>.<br><br>(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br>.<br>*Note* empty entries & legit default entries are not shown <br>REGEDIT4<br><br>[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<br>"Power2GoExpress"="NA" [X]<br>"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2006-10-24 17:10 4662776]<br>"McAfee QuickClean Imonitor"="C:\Program Files\McAfee\McAfee QuickClean\Plguni.exe" [2005-12-01 07:01 110592]<br>"Aim6"="C:\Program Files\AIM6\aim6.exe" [2008-01-03 10:15 50528]<br>"ResChanger 2005"="C:\Program Files\ResChanger 2005\ResChanger2005.exe" [2005-05-26 18:30 885248]<br>"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-05-23 19:40 68856]<br>"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 13:54 5674352]<br>"BitTorrent DNA"="C:\Program Files\DNA\btdna.exe" [2008-06-06 22:57 289088]<br><br>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<br>"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-07 00:46 57344]<br>"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2005-12-14 16:51 7323648]<br>"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-04-20 08:31 185896]<br>"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-06-29 06:24 286720]<br>"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe" [2008-03-25 04:28 144784]<br><br>C:\Documents and Settings\Owner.MAINCPU\Start Menu\Programs\Startup\<br>BOINC Manager.lnk - C:\Program Files\BOINC\boincmgr.exe [2007-07-04 22:06:20 3846912]<br>Last.fm Helper.lnk - C:\Program Files\Last.fm\LastFMHelper.exe [2007-12-26 19:49:39 106496]<br><br>C:\Documents and Settings\All Users\Start Menu\Programs\Startup\<br>BigFix.lnk - C:\Program Files\BigFix\bigfix.exe [2006-08-09 10:08:14 2348584]<br>HP Digital Imaging Monitor.lnk - C:\Program Files\HP\digital imaging\bin\hpqtra08.exe [2004-05-28 23:31:38 241664]<br>HP Image Zone Fast Start.lnk - C:\Program Files\HP\digital imaging\bin\hpqthb08.exe [2004-05-29 00:06:36 53248]<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]<br>"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles<br>"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]<br>"AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]<br>"msacm.iac2"= C:\PROGRA~1\REPLAY~1\iac25_32.ax<br>"msacm.clmp3enc"= C:\PROGRA~1\CYBERL~1\Power2Go\CLMP3Enc.ACM<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\security center]<br>"AntiVirusDisableNotify"=dword:00000001<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]<br>"DisableMonitoring"=dword:00000001<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]<br>"DisableMonitoring"=dword:00000001<br><br>[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]<br>"EnableFirewall"= 0 (0x0)<br><br>[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]<br>"%windir%\\system32\\sessmgr.exe"=<br>"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=<br>"C:\\Program Files\\Common Files\\AolCoach\\en_en\\player\\AOLNySEV.exe"=<br>"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=<br>"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=<br>"C:\\Program Files\\Messenger\\msmsgs.exe"=<br>"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=<br>"C:\\Program Files\\MSN Messenger\\livecall.exe"=<br>"C:\\Program Files\\iTunes\\iTunes.exe"=<br>"C:\\Program Files\\DNA\\btdna.exe"=<br>"C:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=<br>"C:\\Program Files\\CyberLink\\PowerDVD8\\PowerDVD8.exe"=<br><br>R2 {FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};{FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};C:\Program Files\CyberLink\PowerDVD8\[u]0[/u]00.fcl [2008-02-01 17:24]<br>R2 IOPort;IOPort;C:\WINDOWS\system32\IOPORT.SYS [1998-11-27 19:57]<br>R2 Viewpoint Manager Service;Viewpoint Manager Service;C:\Program Files\Viewpoint\Common\ViewpointService.exe [2007-01-04 15:38]<br>S3 APLMp50;APLMp50 NDIS Protocol Driver;C:\WINDOWS\system32\Drivers\APLMp50.sys [2006-11-28 23:46]<br>S3 NPF;NetGroup Packet Filter Driver;C:\WINDOWS\system32\drivers\npf.sys [2007-01-25 11:31]<br><br>[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f7e6734b-27be-11db-b115-806d6172696f}]<br>\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe folder.htt 480 480<br><br>.<br>Contents of the 'Scheduled Tasks' folder<br>"2008-07-04 20:28:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"<br>- C:\Program Files\Apple Software Update\SoftwareUpdate.exe<br>"2008-07-08 01:34:01 C:\WINDOWS\Tasks\HP Usg Daily FY04.job"<br>- C:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\pexpress\hphped06.exe<br>"2008-06-15 07:37:58 C:\WINDOWS\Tasks\McDefragTask.job"<br>- c:\program files\mcafee\mqc\QcConsol.exe'<br>"2008-06-01 07:01:09 C:\WINDOWS\Tasks\McQcTask.job"<br>- c:\program files\mcafee\mqc\QcConsol.exe<br>"2008-07-08 04:14:45 C:\WINDOWS\Tasks\MP Scheduled Scan.job"<br>- C:\Program Files\Windows Defender\MpCmdRun.exe<br>"2008-06-08 14:44:03 C:\WINDOWS\Tasks\MSK_ABImport_Weekly_Owner.job"<br>- C:\WINDOWS\system32\rundll32.exe=<br>.<br>- - - - ORPHANS REMOVED - - - -<br><br>BHO-{670AE285-CD19-4F60-8539-5D4C9A533969} - C:\WINDOWS\system32\fcccyArO.dll<br>BHO-{E23136A1-1AC4-4D1B-926F-5D537CFFF359} - C:\WINDOWS\system32\tuvwVoLd.dll<br>ShellExecuteHooks-{E23136A1-1AC4-4D1B-926F-5D537CFFF359} - C:\WINDOWS\system32\tuvwVoLd.dll<br>Notify-tuvwVoLd - tuvwVoLd.dll<br><br>**************************************************************************<br><br>catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, &raquo;<A HREF="http://www.gmer.net" >www.gmer.net</A><br>Rootkit scan 2008-07-07 22:12:13<br>Windows 5.1.2600 Service Pack 2 NTFS<br><br>scanning hidden processes ... <br><br>scanning hidden autostart entries ...<br><br>scanning hidden files ... <br><br>**************************************************************************<br><br>[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\{FE4C91E7-22C2-4D0C-9F6B-82F1B7742054}]<br>"ImagePath"="\??\C:\Program Files\CyberLink\PowerDVD8\[u]0[/u]00.fcl"<br>.<br>------------------------ Other Running Processes ------------------------<br>.<br>C:\Program Files\Windows Defender\MsMpEng.exe<br>C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe<br>C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br>C:\WINDOWS\arservice.exe<br>C:\WINDOWS\ehome\ehrecvr.exe<br>C:\WINDOWS\ehome\ehSched.exe<br>C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe<br>C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe<br>C:\PROGRA~1\COMMON~1\McAfee\McProxy\McProxy.exe<br>C:\PROGRA~1\McAfee\VIRUSS~1\Mcshield.exe<br>C:\Program Files\McAfee\MPF\MpfSrv.exe<br>C:\Program Files\McAfee\MSK\msksrver.exe<br>C:\WINDOWS\system32\nvsvc32.exe<br>C:\WINDOWS\system32\HPZipm12.exe<br>C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS<br>C:\Program Files\CyberLink\Shared Files\RichVideo.exe<br>C:\Program Files\SiteAdvisor\6261\SAService.exe<br>C:\WINDOWS\ehome\mcrdsvc.exe<br>C:\Program Files\Common Files\AOL\Loader\aolload.exe<br>C:\Program Files\HP\digital imaging\bin\hpqgalry.exe<br>C:\Program Files\BOINC\boinc.exe<br>C:\WINDOWS\system32\dllhost.exe<br>C:\PROGRA~1\McAfee.com\Agent\mcagent.exe<br>C:\Program Files\BOINC\projects\www.worldcommunitygrid.org\wcg_faah_autodock_6.05_windows_intelx86<br>C:\Program Files\AIM6\aolsoftware.exe<br>C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe<br>C:\PROGRA~1\McAfee\MSC\mcuimgr.exe<br>.<br>**************************************************************************<br>.<br>Completion time: 2008-07-07 22:17:50 - machine was rebooted<br>ComboFix-quarantined-files.txt  2008-07-08 04:16:46<br><br>Pre-Run: 211,091,800,064 bytes free<br>Post-Run: 212,021,428,224 bytes free<br><br>215&#9;--- E O F ---&#9;2008-07-07 05:15:03<br>********<br>Logfile of Trend Micro HijackThis v2.0.2<br>Scan saved at 10:29:01 PM, on 7/7/2008<br>Platform: Windows XP SP2 (WinNT 5.01.2600)<br>MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)<br>Boot mode: Normal<br><br>Running processes:<br>C:\WINDOWS\System32\smss.exe<br>C:\WINDOWS\system32\winlogon.exe<br>C:\WINDOWS\system32\services.exe<br>C:\WINDOWS\system32\lsass.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\Program Files\Windows Defender\MsMpEng.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe<br>C:\WINDOWS\system32\spoolsv.exe<br>C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br>C:\WINDOWS\arservice.exe<br>C:\WINDOWS\eHome\ehRecvr.exe<br>C:\WINDOWS\eHome\ehSched.exe<br>C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe<br>c:\program files\common files\mcafee\mna\mcnasvc.exe<br>c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe<br>C:\Program Files\McAfee\VirusScan\McShield.exe<br>C:\Program Files\McAfee\MPF\MPFSrv.exe<br>C:\Program Files\McAfee\MSK\MskSrver.exe<br>C:\WINDOWS\system32\nvsvc32.exe<br>C:\WINDOWS\system32\HPZipm12.exe<br>C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS<br>C:\Program Files\CyberLink\Shared Files\RichVideo.exe<br>C:\Program Files\SiteAdvisor\6261\SAService.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\Program Files\Viewpoint\Common\ViewpointService.exe<br>C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe<br>C:\Program Files\Common Files\Real\Update_OB\realsched.exe<br>C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe<br>C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe<br>C:\Program Files\McAfee\McAfee QuickClean\Plguni.exe<br>C:\Program Files\AIM6\aim6.exe<br>C:\Program Files\ResChanger 2005\ResChanger2005.exe<br>C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe<br>C:\Program Files\MSN Messenger\MsnMsgr.Exe<br>C:\Program Files\DNA\btdna.exe<br>C:\Program Files\BigFix\bigfix.exe<br>C:\Program Files\BOINC\boincmgr.exe<br>C:\Program Files\Last.fm\LastFMHelper.exe<br>C:\Program Files\Common Files\AOL\Loader\aolload.exe<br>C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe<br>C:\Program Files\BOINC\boinc.exe<br>C:\WINDOWS\system32\dllhost.exe<br>C:\PROGRA~1\McAfee.com\Agent\mcagent.exe<br>C:\Program Files\BOINC\projects\www.worldcommunitygrid.org\wcg_faah_autodock_6.05_windows_intelx86<br>C:\Program Files\AIM6\aolsoftware.exe<br>C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe<br>c:\PROGRA~1\mcafee\msc\mcuimgr.exe<br>C:\WINDOWS\explorer.exe<br>C:\WINDOWS\system32\notepad.exe<br>C:\Program Files\Internet Explorer\IEXPLORE.EXE<br>C:\Program Files\SiteAdvisor\6261\SiteAdv.exe<br>C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=69157" >go.microsoft.com/fwlink/?LinkId=69157</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = &raquo;<A HREF="http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html" >us.rd.yahoo.com/customize/ie/def&middot;&middot;&middot;rch.html</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://www.gateway.com/g/startpage.html?Ch=Retail&Br=GTW&Loc=ENG_US&Sys=DTP&M=GT5228" >www.gateway.com/g/startpage.html&middot;&middot;&middot;M=GT5228</A><br>O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6261\SiteAdv.dll<br>O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll<br>O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll<br>O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll<br>O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll<br>O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll<br>O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll<br>O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6261\SiteAdv.dll<br>O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"<br>O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup<br>O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot<br>O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime<br>O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"<br>O4 - HKCU\..\Run: [Power2GoExpress] NA<br>O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet<br>O4 - HKCU\..\Run: [McAfee QuickClean Imonitor] C:\Program Files\McAfee\McAfee QuickClean\Plguni.exe /START<br>O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp<br>O4 - HKCU\..\Run: [ResChanger 2005] C:\Program Files\ResChanger 2005\ResChanger2005.exe<br>O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe<br>O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background<br>O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"<br>O4 - Startup: BOINC Manager.lnk = C:\Program Files\BOINC\boincmgr.exe<br>O4 - Startup: Last.fm Helper.lnk = C:\Program Files\Last.fm\LastFMHelper.exe<br>O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\bigfix.exe<br>O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\digital imaging\bin\hpqtra08.exe<br>O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\digital imaging\bin\hpqthb08.exe<br>O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm<br>O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000<br>O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm<br>O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm<br>O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm<br>O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll<br>O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll<br>O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll<br>O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe<br>O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll<br>O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe<br>O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe<br>O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - &raquo;<A HREF="http://go.microsoft.com/fwlink/?linkid=39204" >go.microsoft.com/fwlink/?linkid=39204</A><br>O16 - DPF: {3107C2A8-9F0B-4404-A58B-21BD85268FBC} (PogoWebLauncher Control) - &raquo;<A HREF="http://www.pogo.com/cdl/launcher/PogoWebLauncherInstaller.CAB" >www.pogo.com/cdl/launcher/PogoWe&middot;&middot;&middot;ller.CAB</A><br>O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - &raquo;<A HREF="http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab" >download.mcafee.com/molbin/share&middot;&middot;&middot;sctl.cab</A><br>O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - &raquo;<A HREF="http://floridakeysmedia.tv/axiscam/Codebase/AxisCamControl.ocx" >floridakeysmedia.tv/axiscam/Code&middot;&middot;&middot;trol.ocx</A><br>O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL<br>O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe<br>O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br>O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br>O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe<br>O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br>O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe<br>O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe<br>O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe<br>O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe<br>O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan\McShield.exe<br>O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe<br>O23 - Service: McAfee SpamKiller Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe<br>O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe<br>O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe<br>O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS<br>O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe<br>O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe<br>O23 - Service: SiteAdvisor Service - Unknown owner - C:\Program Files\SiteAdvisor\6261\SAService.exe<br>O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe<br><br>--<br>End of file - 10410 bytes<br><small>--<br>&raquo;<A HREF="/forum/disco">Team Discovery</A> "Long live rock, be it dead or alive" --The Who.   Americans are getting stronger.  20 years ago, it took 2 people to carry $10 worth of groceries; now a  5 year old can do it.</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20756724</guid>
<pubDate>Tue, 08 Jul 2008 00:35:44 EDT</pubDate>
</item>

<item>
<title>Re: [Vundo] Vundo keeps coming back</title>
<link>http://www.dslreports.com/forum/remark,20756292</link>
<description><![CDATA[<A HREF="/useremail/u/855835"><b>CajunTek</b></A> :  <br>1. Please download MalwareBytes Anti-malware (MBAM) from one of the following links:<br><textarea name="code" class="text" cols=50 rows=10>http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html&#012;http://www.besttechie.net/tools/mbam-setup.exe&#012;</textarea><!--end code block-->Once downloaded, close all programs and Windows on your computer (including this one.)<br><br>Double-click on the icon on your desktop named Download_mbam-setup.exe. This will start the installation of MBAM onto your computer.<br><br>When the installation begins, keep following the prompts in order to continue with the installation process. Do not make any changes to default settings and when the program has finished installing, make sure you leave both the Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware checked. Then click on the Finish button.<br><br>MBAM will now automatically start and you will see a message stating that you should update the program before performing a scan. As MBAM will automatically update itself after the install, you can press the OK button to close that box and you will now be at the main program.<br><br>On the Scanner tab, make sure the the Perform quick scan option is selected and then click on the Scan button to start scanning your computer.<br><br>MBAM will now start scanning your computer for malware. This process can take quite a while, so we suggest you go and do something else and periodically check on the status of the scan.<br><br>When the scan is finished a message box will appear that it has completed scanning successfully. Click OK. Now click Show Results. Make sure all entries have a checkmark at their far left. You should now click on the Remove Selected button to remove all the listed malware. MBAM will now delete all of the files and registry keys and add them to the programs quarantine.<br><br>When MBAM has finished removing the malware, it will open the scan log and display it in Notepad. Review the log as desired, and then close the Notepad window. Remember where you saved the log file, as we will want to see it later.<br><br> <br>2. Download and Run -- ComboFix&copy; <br>Download this file -- to your Desktop -- from any of these sources:<br><textarea name="code" class="text" cols=50 rows=10>http://download.bleepingcomputer.com/sUBs/ComboFix.exe&#012;http://www.forospyware.com/sUBs/ComboFix.exe&#012;http://subs.geekstogo.com/ComboFix.exe&#012;</textarea><!--end code block-->&#149; Disconnect from the Internet.<br>&#149; Disable your Antivirus software -- this includes any Script Blocking Feature it may have.<br><br>Important: Have no other programs running. Your Task Bar should be clear of any program entries including your Browser.<br>&#149; A window will open with a warning. Accept any disclaimers to start the fix. When the scan completes Notepad will open with with your results log open. Do a File, Exit and answer 'Yes' to save changes.<br><br>Do not run Combofix more than once. Do not touch your mouse/keyboard until the scan has completed, as this may cause the process to stall or your computer to lock.<br><br>3. Run HijackThis again, and save the log file.<br><br>In your next post we need to see:<br>&#149; Your MBAM log results;<br>&#149; The contents of C:\Combofix.txt;<br>&#149; The new HijackThis log.<br><br><small>--<br>da Cajun  Darn I hate Malware</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20756292</guid>
<pubDate>Mon, 07 Jul 2008 22:44:34 EDT</pubDate>
</item>

<item>
<title>[Vundo] Vundo keeps coming back</title>
<link>http://www.dslreports.com/forum/remark,20755959</link>
<description><![CDATA[<A HREF="/useremail/u/591558"><b>bronc0fan</b></A> : Hello all!  I can't seem to get rid of this Vundo.  Windows Defender detected it after I got logged on and removed it (C:/win32/vundo.gen!R)  This is the second day I have got this, although I've must have had it for a week now with computer issues such as: Internet Explorer 6 running very slow or locking up; the Windows Security Updates is shut off; and after booting up Windows, I get no display although my monitor's power light is on.<br><br>The symptoms come at the end of the evening before I log off for the night i.e. getting ads for all kinds of anti-virus software on my browser, ads to join Fubar, and other spam.<br><br>My computer's operating system is Windows XP Media Center Version 2002 SP2.  I have also copy and pasted the  VundoFix and Hijack This logs for you.<br><br>Scan started at 8:52:13 PM 7/6/2008<br><br>Listing files found while scanning....<br><br>No infected files were found.<br><br>VundoFix V7.0.6<br><br>Scan started at 11:46:41 PM 7/6/2008<br><br>Listing files found while scanning....<br><br>No infected files were found.<br><br>VundoFix V7.0.6<br><br>Scan started at 6:58:09 AM 7/7/2008<br><br>Listing files found while scanning....<br><br>No infected files were found.<br><br>VundoFix V7.0.6<br><br>Scan started at 6:18:33 PM 7/7/2008<br><br>Listing files found while scanning....<br><br>No infected files were found.<br>***Logfile of Trend Micro HijackThis v2.0.2<br>Scan saved at 6:35:11 PM, on 7/7/2008<br>Platform: Windows XP SP2 (WinNT 5.01.2600)<br>MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)<br>Boot mode: Normal<br><br>Running processes:<br>C:\WINDOWS\System32\smss.exe<br>C:\WINDOWS\system32\winlogon.exe<br>C:\WINDOWS\system32\services.exe<br>C:\WINDOWS\system32\lsass.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\Program Files\Windows Defender\MsMpEng.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe<br>C:\WINDOWS\Explorer.EXE<br>C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe<br>C:\Program Files\Common Files\Real\Update_OB\realsched.exe<br>C:\Program Files\Windows Defender\MSASCui.exe<br>C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe<br>C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe<br>C:\Program Files\McAfee\McAfee QuickClean\Plguni.exe<br>C:\Program Files\AIM6\aim6.exe<br>C:\Program Files\ResChanger 2005\ResChanger2005.exe<br>C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe<br>C:\Program Files\MSN Messenger\MsnMsgr.Exe<br>C:\Program Files\DNA\btdna.exe<br>C:\Program Files\BigFix\bigfix.exe<br>C:\Program Files\BOINC\boincmgr.exe<br>C:\Program Files\Last.fm\LastFMHelper.exe<br>C:\Program Files\Common Files\AOL\Loader\aolload.exe<br>C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe<br>C:\Program Files\BOINC\boinc.exe<br>C:\Program Files\AIM6\aolsoftware.exe<br>C:\Program Files\BOINC\projects\www.worldcommunitygrid.org\wcg_rice_6.17_windows_intelx86<br>C:\Program Files\BOINC\projects\www.worldcommunitygrid.org\wcg_faah_autodock_6.05_windows_intelx86<br>C:\WINDOWS\system32\spoolsv.exe<br>C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br>C:\WINDOWS\arservice.exe<br>C:\WINDOWS\eHome\ehRecvr.exe<br>C:\WINDOWS\eHome\ehSched.exe<br>C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe<br>c:\program files\common files\mcafee\mna\mcnasvc.exe<br>c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe<br>C:\Program Files\McAfee\VirusScan\McShield.exe<br>C:\Program Files\McAfee\MPF\MPFSrv.exe<br>C:\Program Files\McAfee\MSK\MskSrver.exe<br>C:\WINDOWS\system32\nvsvc32.exe<br>C:\WINDOWS\system32\HPZipm12.exe<br>C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS<br>C:\Program Files\CyberLink\Shared Files\RichVideo.exe<br>C:\Program Files\SiteAdvisor\6261\SAService.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\Program Files\Viewpoint\Common\ViewpointService.exe<br>C:\WINDOWS\system32\dllhost.exe<br>C:\PROGRA~1\McAfee.com\Agent\mcagent.exe<br>C:\Program Files\Internet Explorer\iexplore.exe<br>C:\Program Files\SiteAdvisor\6261\SiteAdv.exe<br>C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe<br>C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe<br>C:\WINDOWS\system32\NOTEPAD.EXE<br>C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = &raquo;<A HREF="http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html" >us.rd.yahoo.com/customize/ie/def&middot;&middot;&middot;rch.html</A><br>R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://www.gateway.com/g/startpage.html?Ch=Retail&Br=GTW&Loc=ENG_US&Sys=DTP&M=GT5228" >www.gateway.com/g/startpage.html&middot;&middot;&middot;M=GT5228</A><br>O1 - Hosts: 102.54.94.97 rhino.acme.com # source server<br>O1 - Hosts: 38.25.63.10 x.acme.com # x client host<br>O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6261\SiteAdv.dll<br>O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll<br>O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll<br>O2 - BHO: (no name) - {670AE285-CD19-4F60-8539-5D4C9A533969} - C:\WINDOWS\system32\fcccyArO.dll (file missing)<br>O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll<br>O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll<br>O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll<br>O2 - BHO: (no name) - {E23136A1-1AC4-4D1B-926F-5D537CFFF359} - C:\WINDOWS\system32\tuvwVoLd.dll (file missing)<br>O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll<br>O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6261\SiteAdv.dll<br>O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"<br>O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup<br>O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot<br>O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime<br>O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide<br>O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"<br>O4 - HKCU\..\Run: [Power2GoExpress] NA<br>O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet<br>O4 - HKCU\..\Run: [McAfee QuickClean Imonitor] C:\Program Files\McAfee\McAfee QuickClean\Plguni.exe /START<br>O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp<br>O4 - HKCU\..\Run: [ResChanger 2005] C:\Program Files\ResChanger 2005\ResChanger2005.exe<br>O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe<br>O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background<br>O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"<br>O4 - HKCU\..\Run: [DelayShred] c:\PROGRA~1\mcafee\mshr\ShrCL.EXE /P7 /q c:\DOCUME~1\OWNER~1.MAI\LOCALS~1\temp\TEMPOR~1\Content.IE5\ST67S5EF.SH! c:\DOCUME~1\OWNER~1.MAI\LOCALS~1\temp\TEMPOR~1\Content.IE5\SLUNC1E7.SH! c:\DOCUME~1\OWNER~1.MAI\LOCALS~1\temp\TEMPOR~1\Content.IE5\OFGJULUT.SH! c:\DOCUME~1\OWNER~1.MAI\LOCALS~1\temp\TEMPOR~1\Content.IE5\M38NM1KH.SH! c:\DOCUME~1\OWNER~1.MAI\LOCALS~1\temp\TEMPOR~1\Content.IE5\4XMBG927.SH! c:\DOCUME~1\OWNER~1.MAI\LOCALS~1\temp\TEMPOR~1\Content.IE5\0XIJK9U7.SH! c:\DOCUME~1\OWNER~1.MAI\LOCALS~1\temp\TEMPOR~1\Content.IE5\03M54JM7.SH! c:\DOCUME~1\OWNER~1.MAI\LOCALS~1\temp\TEMPOR~1\Content.SH! c:\DOCUME~1\OWNER~1.MAI\LOCALS~1\temp\TEMPOR~1.SH! c:\DOCUME~1\OWNER~1.MAI\LOCALS~1\temp\HSPERF~1.SH! C:\DOCUME~1\OWNER~1.MAI\LOCALS~1\TEMPOR~1\Content.IE5\ZYPSHBZZ\SIZE_1~1.SH! C:\DOCUME~1\OWNER~1.MAI\LOCALS~1\TEMPOR~1\Content.IE5\UM75XND7\SIZE_1~1.SH! c:\DOCUME~1\OWNER~1.MAI\LOCALS~1\temp\TEMPOR~1.SH!\Content.SH!\ST67S5EF.SH! c:\DOCUME~1\OWNER~1.MAI\LOCALS~1\temp\TEMPOR~1.SH!\Content.<br>O4 - Startup: BOINC Manager.lnk = C:\Program Files\BOINC\boincmgr.exe<br>O4 - Startup: Last.fm Helper.lnk = C:\Program Files\Last.fm\LastFMHelper.exe<br>O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\bigfix.exe<br>O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\digital imaging\bin\hpqtra08.exe<br>O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\digital imaging\bin\hpqthb08.exe<br>O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm<br>O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000<br>O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm<br>O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm<br>O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm<br>O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll<br>O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll<br>O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll<br>O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe<br>O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll<br>O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe<br>O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe<br>O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - &raquo;<A HREF="http://go.microsoft.com/fwlink/?linkid=39204" >go.microsoft.com/fwlink/?linkid=39204</A><br>O16 - DPF: {3107C2A8-9F0B-4404-A58B-21BD85268FBC} (PogoWebLauncher Control) - &raquo;<A HREF="http://www.pogo.com/cdl/launcher/PogoWebLauncherInstaller.CAB" >www.pogo.com/cdl/launcher/PogoWe&middot;&middot;&middot;ller.CAB</A><br>O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - &raquo;<A HREF="http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab" >download.mcafee.com/molbin/share&middot;&middot;&middot;sctl.cab</A><br>O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - &raquo;<A HREF="http://floridakeysmedia.tv/axiscam/Codebase/AxisCamControl.ocx" >floridakeysmedia.tv/axiscam/Code&middot;&middot;&middot;trol.ocx</A><br>O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL<br>O20 - Winlogon Notify: tuvwVoLd - tuvwVoLd.dll (file missing)<br>O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe<br>O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br>O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br>O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe<br>O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br>O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe<br>O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe<br>O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe<br>O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe<br>O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan\McShield.exe<br>O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe<br>O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe<br>O23 - Service: McAfee SpamKiller Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe<br>O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe<br>O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe<br>O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS<br>O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe<br>O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe<br>O23 - Service: SiteAdvisor Service - Unknown owner - C:\Program Files\SiteAdvisor\6261\SAService.exe<br>O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe<br><br>--<br>End of file - 11824 bytes<br>******<br><br>I ran VundoFix before coming to this forum and it came up with nothing.<br><br>Thanks for any help!<br><small>--<br>&raquo;<A HREF="/forum/disco">Team Discovery</A> "Long live rock, be it dead or alive" --The Who.   Americans are getting stronger.  20 years ago, it took 2 people to carry $10 worth of groceries; now a  5 year old can do it.</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20755959</guid>
<pubDate>Mon, 07 Jul 2008 21:22:36 EDT</pubDate>
</item>

</channel>
</rss>
