<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>HJT Log - Changes Windows Background automatically in Security Cleanup</title>
<link>http://www.dslreports.com/forum/r20762617</link>
<description></description>
<language>en</language>
<pubDate>Tue, 01 Dec 2009 03:23:54 EDT</pubDate>
<lastBuildDate>Tue, 01 Dec 2009 03:23:54 EDT</lastBuildDate>

<item>
<title>Re: HJT Log - Changes Windows Background automatically</title>
<link>http://www.dslreports.com/forum/remark,20768258</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : It all seem to be running again! <br>Thanks for your help!!!!!  :)  :) :)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20768258</guid>
<pubDate>Thu, 10 Jul 2008 03:14:59 EDT</pubDate>
</item>

<item>
<title>Re: HJT Log - Changes Windows Background automatically</title>
<link>http://www.dslreports.com/forum/remark,20764714</link>
<description><![CDATA[<A HREF="/useremail/u/693977"><b>bcastner</b></A> : 1. Use Add or Remove Programs and uninstall <b>MBAM</b><br><br>Download the software again, just as in the original instructions.<br><br>Using my original instructions, run this again, but slightly differently.<br>Rather than do a <b>Quick</b> scan, unselect that option (so that a longer scan is done).  Be absolutely sure you <b>Checkmark</b> every item shown in the log result prior to asking it to do the cleaning.<br><br>I will not need to see a log result from this session.<br><br>2. Using your mouse, <b>Highlight</b> and then do a Right-click | Copy of the entire Box below:<br><br><textarea name="code" class="text" cols=50 rows=10>@echo off&#012;cd %~dp0&#012; &#012;REM Batch script from the DSLR/BroadBandReports Forum&#012;REM If you see this file, go ahead and delete it.&#012;REM Written by MS-MVP &amp; DSLR-MVM Bill Castner&#012; &#012;for %%g in (&#012;"C:\WINDOWS\system32\ulrofafb.dll"&#012;"C:\WINDOWS\system32\yaywvWPG.dll"&#012;"C:\WINDOWS\system32\GPWvwyay.ini"&#012;) do (&#012;attrib -r -s-h %%g&#012;del /a/f %%g&#012;)&#012; &#012;del %0&#012;exit&#012; &#012;</textarea><!--end code block--><br>Open a new <b>Notepad</b> document. (Do not use a Word Processor or WordPad).  Click "Format" and be certain that Word Wrap is not enabled. <br>Right-click | <b>Paste</b> the Code box contents from above into Notepad.  Click File, <b>Save as...</b>,  and enter (including quotation marks) as the filename: "TempFix.CMD".   Exit Notepad.<br><br>Double click your new file to run the batch script.  You can then delete this new file.<br><br>We should be finished.<br><br>Open <b>Acrobat</b> if you have the Full Version installed  Click <b>Help</b> and run the <b>Upgrade</b> applet found there.  If no update is offered:  Use the Preferences, Internet submenu of Acrobat and uncheck to integrate with your Browser.  Close Acrobat.<br>Whether you had the Full Version of Acrobat or not, download and install <b>Adobe Reader 9</b> and use this as the integrated PDF Reader insider your browser:  &raquo;<A HREF="http://www.adobe.com/products/acrobat/readstep2.html" >www.adobe.com/products/acrobat/r&middot;&middot;&middot;ep2.html</A><br><br><b><u>Clean-up & Prevention:</u></b><br><br>&#8226;  Right click "My Computer", Properties, and then click the System Restore tab.  <b>Checkmark</b> the box at the top to stop System Restore on all drives.  Click the "<b>Apply</b>" button.  Agree to the deletion of old Restore Points.  Then <b><u>uncheck</u></b> the box at the top and again click the "<b>Apply</b>" button.  Finally, click the "<b>OK</b>" button.  This will create a new Restore Point reflecting your clean system state.<br><br>&#8226; Click <b>Start</b>, then click <b>Run</b>.<br>Enter into the command box that opens:  <b>combofix /u</b> and then click <b>OK</b>.<br>(If we have renamed this file, please use the current name for the program in this instruction.)<br> <IMG SRC="http://i78.photobucket.com/albums/j116/amateur_photos/CFuninstall.png"> <br><br>&#8226; Please download <b>OTMoveIt2</b> by OldTimer to your Desktop (only):<br><br><textarea name="code" class="text" cols=50 rows=10>http://download.bleepingcomputer.com/oldtimer/OTMoveIt2.exe&#012;</textarea><!--end code block--><br>&#8226; Please double-click OTMoveIt.exe to run it.<br>&#8226; Click on the green <b>CleanUp!</b> button. When you do this a text file named cleanup.txt will be downloaded from the internet. If you get a warning from your firewall or other security programs regarding OTMoveIt attempting to contact the internet you should allow it to do so. <br>&#8226; After the list has been download you'll be asked if you want to Begin cleanup process? Select "Yes".<br>&#8226; This step removes the files, folders, and shortcuts created by the tools I had you download and run.<br><br>&#8226; Run <b>ATF Cleaner</b>  <IMG SRC="http://www.geekstogo.com/misc/guide_icons/ATF.gif"> , and checkmark "Empty Recycle Bin", click "Empty Selected" and exit the program.  You can delete or keep this utility as you wish.<br><br>&#8226; Use Control Panel, Add or Remove Programs, and Uninstall any entry related to an On-Line scanner we may have used.  <br>If you find any files or folders created during this cleanup operation remaining, please feel free to delete them.<br><br>&#8226; Configure your Antivirus software to check for updates daily, at a time in which you are sure the computer will be on.<br><br>&#8226; If I asked you to <b>Disable</b> something like TeaTimer or another malware blocker, please go ahead an re-enable them if you wish.<br><br>&#8226;  <b>Download and Install Windows Defender by Microsoft (free):</b><br><textarea name="code" class="text" cols=50 rows=10>http://www.microsoft.com/downloads/details.aspx?FamilyId=435BFCE7-DA2B-4A6A-AFA4-F7F14E605A0D&#012;</textarea><!--end code block--><br>&#8226;  <b>Suggestion:  Download and install Comodo BOClean (free):</b><br><textarea name="code" class="text" cols=50 rows=10>http://www.comodo.com/boclean/CBO_download.html&#012;</textarea><!--end code block--><br>&#8226;  <b>Suggestion:  Download, install, and keep updated Spyware Blaster (free):</b><br><textarea name="code" class="text" cols=50 rows=10>http://www.javacoolsoftware.com/spywareblaster.html&#012;</textarea><!--end code block--><br>&#8226; Refer to my first set of instructions above, and reconfigure <b>Hidden Files and Folders</b> to your choosing.<br><br>Best wishes.<br>Bill Castner<br><br><small>--<br><b>============</b><br><b>MS-MVP 2004 - -2008, ASAP Member</b><br><b><i>Users Helping Users</i></b><br><br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20764714</guid>
<pubDate>Wed, 09 Jul 2008 14:16:02 EDT</pubDate>
</item>

<item>
<title>Re: HJT Log - Changes Windows Background automatically</title>
<link>http://www.dslreports.com/forum/remark,20763711</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : First i want to thank you very much for your help!!<br><br>So here the are the log-files:<br><br><b>mbam-log-7-9-2008 (16-47-21).txt</b><br><br>Malwarebytes' Anti-Malware 1.20<br>Datenbank Version: 930<br>Windows 5.1.2600 Service Pack 2<br><br>16:47:26 09.07.2008<br>mbam-log-7-9-2008 (16-47-21).txt<br><br>Scan Art: Schnell Scan<br>Objekte gescannt: 39130<br>Scan Dauer: 3 minute(s), 31 second(s)<br><br>Infizierte Speicher Prozesse: 1<br>Infizierte Speicher Module: 3<br>Infizierte Registrierungsschl&uuml;ssel: 42<br>Infizierte Registrierungswerte: 2<br>Infizierte Datei Objekte der Registrierung: 5<br>Infizierte Verzeichnisse: 1<br>Infizierte Dateien: 78<br><br>Infizierte Speicher Prozesse:<br>C:\WINDOWS\system32\uoyzsydz.exe (Trojan.Agent) -> No action taken.<br><br>Infizierte Speicher Module:<br>C:\WINDOWS\system32\ulrofafb.dll (Trojan.Vundo) -> No action taken.<br>C:\WINDOWS\system32\yaywvWPG.dll (Trojan.Vundo) -> No action taken.<br>C:\WINDOWS\system32\qomNefcA.dll (Trojan.Vundo) -> No action taken.<br><br>Infizierte Registrierungsschl&uuml;ssel:<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6f993b06-1230-40fb-96e9-ea62844695b5} (Trojan.Vundo) -> No action taken.<br>HKEY_CLASSES_ROOT\CLSID\{6f993b06-1230-40fb-96e9-ea62844695b5} (Trojan.Vundo) -> No action taken.<br>HKEY_CLASSES_ROOT\AppID\{8d71eeb8-a1a7-4733-8fa2-1cac015c967d} (Adware.BHO) -> No action taken.<br>HKEY_CLASSES_ROOT\Interface\{1e404d48-670a-4085-a6a0-d195793ddd33} (Adware.BHO) -> No action taken.<br>HKEY_CLASSES_ROOT\Interface\{9f593aac-ca4c-4a41-a7ff-a00812192d61} (Adware.BHO) -> No action taken.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5321e378-ffad-4999-8c62-03ca8155f0b3} (Trojan.BHO) -> No action taken.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{00110011-4b0b-44d5-9718-90c88817369b} (Fake.Dropped.Malware) -> No action taken.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{086ae192-23a6-48d6-96ec-715f53797e85} (Fake.Dropped.Malware) -> No action taken.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{150fa160-130d-451f-b863-b655061432ba} (Fake.Dropped.Malware) -> No action taken.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{17da0c9e-4a27-4ac5-bb75-5d24b8cdb972} (Fake.Dropped.Malware) -> No action taken.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1f48aa48-c53a-4e21-85e7-ac7cc6b5ffb1} (Fake.Dropped.Malware) -> No action taken.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1f48aa48-c53a-4e21-85e7-ac7cc6b5ffb2} (Fake.Dropped.Malware) -> No action taken.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2d38a51a-23c9-48a1-a33c-48675aa2b494} (Fake.Dropped.Malware) -> No action taken.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2e9caff6-30c7-4208-8807-e79d4ec6f806} (Fake.Dropped.Malware) -> No action taken.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{467faeb2-5f5b-4c81-bae0-2a4752ca7f4e} (Fake.Dropped.Malware) -> No action taken.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{587dbf2d-9145-4c9e-92c2-1f953da73773} (Fake.Dropped.Malware) -> No action taken.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6cc1c91a-ae8b-4373-a5b4-28ba1851e39a} (Fake.Dropped.Malware) -> No action taken.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{79369d5c-2903-4b7a-ade2-d5e0dee14d24} (Fake.Dropped.Malware) -> No action taken.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{799a370d-5993-4887-9df7-0a4756a77d00} (Fake.Dropped.Malware) -> No action taken.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{98dbbf16-ca43-4c33-be80-99e6694468a4} (Fake.Dropped.Malware) -> No action taken.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{a55581dc-2cdb-4089-8878-71a080b22342} (Fake.Dropped.Malware) -> No action taken.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{b847676d-72ac-4393-bfff-43a1eb979352} (Fake.Dropped.Malware) -> No action taken.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{bc97b254-b2b9-4d40-971d-78e0978f5f26} (Fake.Dropped.Malware) -> No action taken.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{cf021f40-3e14-23a5-cba2-717765721306} (Fake.Dropped.Malware) -> No action taken.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{e2ddf680-9905-4dee-8c64-0a5de7fe133c} (Fake.Dropped.Malware) -> No action taken.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{e3eebbe8-9cab-4c76-b26a-747e25ebb4c6} (Fake.Dropped.Malware) -> No action taken.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{e7afff2a-1b57-49c7-bf6b-e5123394c970} (Fake.Dropped.Malware) -> No action taken.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{fcaddc14-bd46-408a-9842-cdbe1c6d37eb} (Fake.Dropped.Malware) -> No action taken.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{fd9bc004-8331-4457-b830-4759ff704c22} (Fake.Dropped.Malware) -> No action taken.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{ff1bf4c7-4e08-4a28-a43f-9d60a9f7a880} (Fake.Dropped.Malware) -> No action taken.<br>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MsSecurity1.209.4 (Trojan.Agent) -> No action taken.<br>HKEY_CLASSES_ROOT\AppID\Sidebar.DLL (Adware.BHO) -> No action taken.<br>HKEY_CURRENT_USER\SOFTWARE\MySidesearch (Adware.BHO) -> No action taken.<br>HKEY_LOCAL_MACHINE\SOFTWARE\xpre (Trojan.Downloader) -> No action taken.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\aoprndtws (Malware.Trace) -> No action taken.<br>HKEY_CLASSES_ROOT\WR (Malware.Trace) -> No action taken.<br>HKEY_CURRENT_USER\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> No action taken.<br>HKEY_CLASSES_ROOT\CLSID\{c738f3d2-1891-449d-ae67-d1969094f1df} (Trojan.Vundo) -> No action taken.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{c738f3d2-1891-449d-ae67-d1969094f1df} (Trojan.Vundo) -> No action taken.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\qomnefca (Trojan.Vundo) -> No action taken.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> No action taken.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> No action taken.<br><br>Infizierte Registrierungswerte:<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{c738f3d2-1891-449d-ae67-d1969094f1df} (Trojan.Vundo) -> No action taken.<br>HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\General\wallpaper (Hijack.Desktop) -> No action taken.<br><br>Infizierte Datei Objekte der Registrierung:<br>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Notification Packages (Trojan.Vundo) -> Data: c:\windows\system32\yaywvwpg -> No action taken.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Trojan.Agent) -> Data: c:\windows\system32\uoyzsydz.exe -> No action taken.<br>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Authentication Packages (Trojan.Vundo) -> Data: c:\windows\system32\yaywvwpg  -> No action taken.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Hijack.UserInit) -> Bad: (C:\WINDOWS\SYSTEM32\Userinit.exe,C:\WINDOWS\system32\uoyzsydz.exe,) Good: (userinit.exe) -> No action taken.<br>HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr (Hijack.TaskManager) -> Bad: (1) Good: (0) -> No action taken.<br><br>Infizierte Verzeichnisse:<br>C:\Programme\AntiSpywareMaster (Rogue.AntiSpywareMaster) -> No action taken.<br><br>Infizierte Dateien:<br>C:\WINDOWS\system32\yaywvWPG.dll (Trojan.Vundo) -> No action taken.<br>C:\WINDOWS\system32\GPWvwyay.ini (Trojan.Vundo) -> No action taken.<br>C:\WINDOWS\system32\GPWvwyay.ini2 (Trojan.Vundo) -> No action taken.<br>C:\WINDOWS\system32\ulrofafb.dll (Trojan.Vundo) -> No action taken.<br>C:\WINDOWS\system32\bfaforlu.ini (Trojan.Vundo) -> No action taken.<br>C:\WINDOWS\mrofinu1000106.exe (Trojan.DownLoader) -> No action taken.<br>C:\WINDOWS\mrofinu572.exe (Trojan.DownLoader) -> No action taken.<br>C:\WINDOWS\mrofinu572.exe.tmp (Trojan.DownLoader) -> No action taken.<br>C:\WINDOWS\system32\lcntktdm.exe (Adware.Agent) -> No action taken.<br>C:\WINDOWS\system32\mysidesearch_sidebar_uninstall.exe (Adware.BHO) -> No action taken.<br>C:\WINDOWS\system32\rswnw64m.exe (Adware.Agent) -> No action taken.<br>C:\WINDOWS\system32\rwwnw64d.exe (Adware.Agent) -> No action taken.<br>C:\WINDOWS\explore.exe (Trojan.Agent) -> No action taken.<br>C:\WINDOWS\iexplorer.exe (Trojan.Agent) -> No action taken.<br>C:\WINDOWS\x.exe (Trojan.Agent) -> No action taken.<br>C:\WINDOWS\y.exe (Trojan.Agent) -> No action taken.<br>C:\WINDOWS\xxxvideo.hta (Trojan.Agent) -> No action taken.<br>C:\WINDOWS\lfn.exe (Trojan.Agent) -> No action taken.<br>C:\WINDOWS\default.htm (Trojan.Agent) -> No action taken.<br>C:\WINDOWS\svchost32.exe (Trojan.Agent) -> No action taken.<br>C:\WINDOWS\loader.exe (Trojan.Agent) -> No action taken.<br>C:\WINDOWS\internet.exe (Trojan.Agent) -> No action taken.<br>C:\WINDOWS\system32\gside.exe (Trojan.Agent) -> No action taken.<br>C:\WINDOWS\system32\uoyzsydz.exe (Trojan.Agent) -> No action taken.<br>C:\WINDOWS\system32\winpfz33.sys (Malware.Trace) -> No action taken.<br>C:\WINDOWS\accesss.exe (Fake.Dropped.Malware) -> No action taken.<br>C:\WINDOWS\astctl32.ocx (Fake.Dropped.Malware) -> No action taken.<br>C:\WINDOWS\avpcc.dll (Fake.Dropped.Malware) -> No action taken.<br>C:\WINDOWS\clrssn.exe (Fake.Dropped.Malware) -> No action taken.<br>C:\WINDOWS\cpan.dll (Fake.Dropped.Malware) -> No action taken.<br>C:\WINDOWS\ctfmon32.exe (Fake.Dropped.Malware) -> No action taken.<br>C:\WINDOWS\ctrlpan.dll (Fake.Dropped.Malware) -> No action taken.<br>C:\WINDOWS\directx32.exe (Fake.Dropped.Malware) -> No action taken.<br>C:\WINDOWS\dnsrelay.dll (Fake.Dropped.Malware) -> No action taken.<br>C:\WINDOWS\editpad.exe (Fake.Dropped.Malware) -> No action taken.<br>C:\WINDOWS\Explorer32.exe (Fake.Dropped.Malware) -> No action taken.<br>C:\WINDOWS\funniest.exe (Fake.Dropped.Malware) -> No action taken.<br>C:\WINDOWS\funny.exe (Fake.Dropped.Malware) -> No action taken.<br>C:\WINDOWS\gfmnaaa.dll (Fake.Dropped.Malware) -> No action taken.<br>C:\WINDOWS\helpcvs.exe (Fake.Dropped.Malware) -> No action taken.<br>C:\WINDOWS\iedll.exe (Fake.Dropped.Malware) -> No action taken.<br>C:\WINDOWS\inetinf.exe (Fake.Dropped.Malware) -> No action taken.<br>C:\WINDOWS\msconfd.dll (Fake.Dropped.Malware) -> No action taken.<br>C:\WINDOWS\msspi.dll (Fake.Dropped.Malware) -> No action taken.<br>C:\WINDOWS\mssys.exe (Fake.Dropped.Malware) -> No action taken.<br>C:\WINDOWS\msupdate.exe (Fake.Dropped.Malware) -> No action taken.<br>C:\WINDOWS\mswsc10.dll (Fake.Dropped.Malware) -> No action taken.<br>C:\WINDOWS\mswsc20.dll (Fake.Dropped.Malware) -> No action taken.<br>C:\WINDOWS\mtwirl32.dll (Fake.Dropped.Malware) -> No action taken.<br>C:\WINDOWS\notepad32.exe (Fake.Dropped.Malware) -> No action taken.<br>C:\WINDOWS\olehelp.exe (Fake.Dropped.Malware) -> No action taken.<br>C:\WINDOWS\qttasks.exe (Fake.Dropped.Malware) -> No action taken.<br>C:\WINDOWS\quicken.exe (Fake.Dropped.Malware) -> No action taken.<br>C:\WINDOWS\rundll16.exe (Fake.Dropped.Malware) -> No action taken.<br>C:\WINDOWS\system32\clbdll.dll (Trojan.Agent) -> No action taken.<br>C:\WINDOWS\system32\pac.txt (Malware.Trace) -> No action taken.<br>C:\WINDOWS\rundll32.vbe (Fake.Dropped.Malware) -> No action taken.<br>C:\WINDOWS\searchword.dll (Fake.Dropped.Malware) -> No action taken.<br>C:\WINDOWS\sistem.exe (Fake.Dropped.Malware) -> No action taken.<br>C:\WINDOWS\svcinit.exe (Fake.Dropped.Malware) -> No action taken.<br>C:\WINDOWS\systeem.exe (Fake.Dropped.Malware) -> No action taken.<br>C:\WINDOWS\systemcritical.exe (Fake.Dropped.Malware) -> No action taken.<br>C:\WINDOWS\time.exe (Fake.Dropped.Malware) -> No action taken.<br>C:\WINDOWS\users32.exe (Fake.Dropped.Malware) -> No action taken.<br>C:\WINDOWS\waol.exe (Fake.Dropped.Malware) -> No action taken.<br>C:\WINDOWS\win32e.exe (Fake.Dropped.Malware) -> No action taken.<br>C:\WINDOWS\win64.exe (Fake.Dropped.Malware) -> No action taken.<br>C:\WINDOWS\winajbm.dll (Fake.Dropped.Malware) -> No action taken.<br>C:\WINDOWS\window.exe (Fake.Dropped.Malware) -> No action taken.<br>C:\WINDOWS\winmgnt.exe (Fake.Dropped.Malware) -> No action taken.<br>C:\WINDOWS\xplugin.dll (Fake.Dropped.Malware) -> No action taken.<br>C:\WINDOWS\system32\drivers\clbdriver.sys (Rootkit.Agent) -> No action taken.<br>C:\WINDOWS\system32\msnav32.ax (Malware.Trace) -> No action taken.<br>C:\WINDOWS\system32\zxdnt3d.cfg (Malware.Trace) -> No action taken.<br>C:\WINDOWS\system32\tuvSmkhg.dll (Trojan.Vundo) -> No action taken.<br>C:\WINDOWS\system32\qomNefcA.dll (Trojan.Vundo) -> No action taken.<br>C:\WINDOWS\system32\opnlJARI.dll (Trojan.Vundo) -> No action taken.<br>C:\WINDOWS\system32\iifdbYon.dll (Trojan.Vundo) -> No action taken.<br><br><b>ComboFix.txt</b><br><br>ComboFix 08-07-08.5 - Administrator 2008-07-09 16:58:24.1 - NTFSx86<br>ausgef&uuml;hrt von:: C:\Dokumente und Einstellungen\Administrator\Desktop\ComboFix.exe<br>Command switches used :: C:\Dokumente und Einstellungen\Administrator\Desktop\CFscript.txt<br><br>[color=red]<b>WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!</b>[/color]<br><br>FILE ::<br>C:\WINDOWS\mrofinu572.exe<br>C:\windows\system32\rswnw64m.exe<br>C:\WINDOWS\system32\uoyzsydz.exe<br>.<br><br>((((((((((((((((((((((((((((((((((((   Weitere L&#148;schungen   ))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br><br>C:\Dokumente und Einstellungen\Administrator\Startmen&uuml;\Programme\Autostart\Deewoo.lnk<br>C:\Dokumente und Einstellungen\Administrator\Startmen&uuml;\Programme\Autostart\DW_Start.lnk<br>C:\Temp\1cb<br>C:\Temp\1cb\syscheck.log<br>C:\WINDOWS\444.470<br>C:\WINDOWS\mainms.vpi<br>C:\WINDOWS\megavid.cdt<br>C:\WINDOWS\muotr.so<br>C:\WINDOWS\system32\clbdll.dll<br>C:\WINDOWS\system32\clbinit.dll<br>C:\WINDOWS\system32\hljwugsf.bin<br>C:\WINDOWS\system32\MSINET.oca<br><br>.<br>(((((((((((((((((((((((((((((((((((((((   Drivers/Services   )))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br><br>-------\Legacy_CLBDRIVER<br>-------\Legacy_MSSECURITY1.209.4<br>-------\Service_clbdriver<br><br>(((((((((((((((((((((((   Dateien erstellt von 2008-06-09 bis 2008-07-09  ))))))))))))))))))))))))))))))<br>.<br><br>2008-07-09 16:41 . 2008-07-09 16:41&#9;&#9;d--------&#9;C:\Programme\Malwarebytes' Anti-Malware<br>2008-07-09 16:41 . 2008-07-09 16:41&#9;&#9;d--------&#9;C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Malwarebytes<br>2008-07-09 16:41 . 2008-07-09 16:41&#9;&#9;d--------&#9;C:\Dokumente und Einstellungen\Administrator\Anwendungsdaten\Malwarebytes<br>2008-07-09 16:41 . 2008-07-07 17:42&#9;34,296&#9;--a------&#9;C:\WINDOWS\system32\drivers\mbamcatchme.sys<br>2008-07-09 16:41 . 2008-07-07 17:42&#9;17,144&#9;--a------&#9;C:\WINDOWS\system32\drivers\mbam.sys<br>2008-07-09 09:44 . 2008-07-09 09:44&#9;&#9;d--------&#9;C:\Programme\Trend Micro<br>2008-07-09 09:33 . 2008-07-09 09:33&#9;&#9;d--------&#9;C:\Programme\CCleaner<br>2008-07-08 23:00 . 2008-07-09 16:48&#9;81,104&#9;---------&#9;C:\WINDOWS\system32\ulrofafb.dll<br>2008-07-08 22:59 . 2008-07-09 16:48&#9;314,656&#9;---------&#9;C:\WINDOWS\system32\yaywvWPG.dll<br>2008-07-08 22:59 . 2008-07-09 16:49&#9;1,435&#9;--ahs----&#9;C:\WINDOWS\system32\GPWvwyay.ini<br>2008-07-08 22:46 . 2008-07-08 22:46&#9;&#9;d--------&#9;C:\WINDOWS\system32\ver<br>2008-07-08 22:46 . 2008-07-08 22:46&#9;&#9;d--------&#9;C:\WINDOWS\system32\olixds01<br>2008-07-08 22:46 . 2008-07-08 22:46&#9;&#9;d--------&#9;C:\WINDOWS\system32\IP3<br>2008-07-08 22:46 . 2008-07-08 22:46&#9;&#9;d--------&#9;C:\WINDOWS\system32\dapi<br>2008-07-08 22:46 . 2008-07-08 22:46&#9;&#9;d--------&#9;C:\Temp\stmpv4<br>2008-07-08 22:46 . 2008-07-09 16:58&#9;&#9;d--------&#9;C:\Temp<br>2008-07-08 22:46 . 2008-07-08 22:46&#9;&#9;dr-------&#9;C:\Dokumente und Einstellungen\LocalService\Favoriten<br>2008-07-08 22:46 . 2008-07-09 08:55&#9;&#9;dr-h-----&#9;C:\$VAULT$.AVG<br>2008-07-08 22:46 . 2008-07-08 22:46&#9;152,259&#9;--a------&#9;C:\WINDOWS\system32\g65.exe<br>2008-07-08 22:46 . 2008-07-09 16:48&#9;26,016&#9;---------&#9;C:\WINDOWS\system32\qomNefcA.dll<br>2008-07-08 22:46 . 2004-11-11 13:00&#9;4,224&#9;--a------&#9;C:\WINDOWS\system32\beep.sys<br>2008-07-05 07:05 . 2008-07-05 07:05&#9;32,768&#9;--a------&#9;C:\WINDOWS\system32\olixds01\olixds011065.exe<br>2008-06-10 15:50 . 2008-06-10 15:50&#9;54,156&#9;--ah-----&#9;C:\WINDOWS\QTFont.qfn<br>2008-06-10 15:50 . 2008-06-10 15:50&#9;1,409&#9;--a------&#9;C:\WINDOWS\QTFont.for<br><br>.<br>((((((((((((((((((((((((((((((((((((   Find3M Bericht   ))))))))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br>2008-07-09 14:55&#9;---------&#9;d-----w&#9;C:\Dokumente und Einstellungen\Administrator\Anwendungsdaten\AVG7<br>.<br><br><b>hijackthis.log</b><br><br>Logfile of Trend Micro HijackThis v2.0.2<br>Scan saved at 17:08, on 2008-07-09<br>Platform: Windows XP SP2 (WinNT 5.01.2600)<br>MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)<br>Boot mode: Normal<br><br>Running processes:<br>C:\WINDOWS\System32\smss.exe<br>C:\WINDOWS\system32\winlogon.exe<br>C:\WINDOWS\system32\services.exe<br>C:\WINDOWS\system32\lsass.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\WINDOWS\system32\spoolsv.exe<br>C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe<br>C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe<br>C:\WINDOWS\system32\nvsvc32.exe<br>C:\WINDOWS\Explorer.EXE<br>C:\WINDOWS\system32\wscntfy.exe<br>C:\Programme\Launch Manager\LaunchAp.exe<br>C:\Programme\Launch Manager\HotkeyApp.exe<br>C:\Programme\Launch Manager\OSD.exe<br>C:\Programme\Launch Manager\Wbutton.exe<br>C:\Programme\Synaptics\SynTP\SynTPEnh.exe<br>C:\WINDOWS\RTHDCPL.EXE<br>C:\WINDOWS\system32\ctfmon.exe<br>C:\Programme\Gemeinsame Dateien\Ahead\Lib\NMBgMonitor.exe<br>C:\Programme\Synaptics\SynTP\SynMedion.exe<br>C:\Programme\Gemeinsame Dateien\Ahead\Lib\NMIndexStoreSvr.exe<br>C:\WINDOWS\system32\wuauclt.exe<br>C:\Programme\Trend Micro\HijackThis\HijackThis.exe<br><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=69157" >go.microsoft.com/fwlink/?LinkId=69157</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll<br>O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Programme\Spybot - Search & Destroy\SDHelper.dll<br>O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll<br>O4 - HKLM\..\Run: [LaunchAp] "C:\Programme\Launch Manager\LaunchAp.exe"<br>O4 - HKLM\..\Run: [HotkeyApp] "C:\Programme\Launch Manager\HotkeyApp.exe"<br>O4 - HKLM\..\Run: [LMgrOSD] "C:\Programme\Launch Manager\OSD.exe"<br>O4 - HKLM\..\Run: [Wbutton] "C:\Programme\Launch Manager\Wbutton.exe"<br>O4 - HKLM\..\Run: [SynTPEnh] C:\Programme\Synaptics\SynTP\SynTPEnh.exe<br>O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE<br>O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup<br>O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP<br>O4 - HKLM\..\Run: [CorelDRAW Graphics Suite 11b] C:\Programme\Corel\Corel Graphics 12\Languages\DE\Programs\Registration.exe /title="CorelDRAW Graphics Suite 12" /date=072308 serial=DR12WEX-1502297-EBB lang=DE<br>O4 - HKLM\..\Run: [CtrlVol] C:\Programme\Launch Manager\CtrlVol.exe<br>O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe<br>O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Programme\Gemeinsame Dateien\Ahead\Lib\NMBgMonitor.exe"<br>O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKALER DIENST')<br>O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOKALER DIENST')<br>O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETZWERKDIENST')<br>O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')<br>O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')<br>O8 - Extra context menu item: Ausgew&auml;hlte Verkn&uuml;pfungen in Adobe PDF konvertieren - res://C:\Programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html<br>O8 - Extra context menu item: Ausgew&auml;hlte Verkn&uuml;pfungen in vorhandene PDF-Datei konvertieren - res://C:\Programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html<br>O8 - Extra context menu item: Auswahl in Adobe PDF konvertieren - res://C:\Programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html<br>O8 - Extra context menu item: Auswahl in vorhandene PDF-Datei konvertieren - res://C:\Programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html<br>O8 - Extra context menu item: In Adobe PDF konvertieren - res://C:\Programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html<br>O8 - Extra context menu item: In vorhandene PDF-Datei konvertieren - res://C:\Programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html<br>O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000<br>O8 - Extra context menu item: Verkn&uuml;pfungsziel in Adobe PDF konvertieren - res://C:\Programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html<br>O8 - Extra context menu item: Verkn&uuml;pfungsziel in vorhandene PDF-Datei konvertieren - res://C:\Programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html<br>O9 - Extra button: Recherchieren - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL<br>O23 - Service: Adobe LM Service - Adobe Systems - C:\Programme\Gemeinsame Dateien\Adobe Systems Shared\Service\Adobelmsvc.exe<br>O23 - Service: Adobe Version Cue CS2 - Adobe Systems Incorporated - C:\Programme\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe<br>O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe<br>O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe<br>O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programme\Gemeinsame Dateien\InstallShield\Driver\1050\Intel 32\IDriverT.exe<br>O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Programme\Gemeinsame Dateien\Macromedia Shared\Service\Macromedia Licensing.exe<br>O23 - Service: NBService - Nero AG - C:\Programme\Nero\Nero 7\Nero BackItUp\NBService.exe<br>O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe<br>O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc) - TuneUp Software GmbH - C:\Programme\TuneUpUtilities2004\WinStylerThemeSvc.exe<br><br>--<br>End of file - 6077 bytes]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20763711</guid>
<pubDate>Wed, 09 Jul 2008 11:17:32 EDT</pubDate>
</item>

<item>
<title>Re: HJT Log - Changes Windows Background automatically</title>
<link>http://www.dslreports.com/forum/remark,20763389</link>
<description><![CDATA[<A HREF="/useremail/u/693977"><b>bcastner</b></A> : I can tell you right now there are likely forty or more Vundo infectors we cannot see in a HijackThis log.<br><br><b><u>First Steps</u></b><br><b>:!: The following instructions are <u>only</u> for this Forum member. Please do not use these instructions on another computer system. You can seriously damage your system by following the instructions below without guided assistance. You assuredly will make a cleanup of your system more difficult.</b><br><br>Download to your Desktop <b>FixPolicies.exe</b>, a self-extracting ZIP archive  from here:<br><br><textarea name="code" class="text" cols=50 rows=10>http://downloads.malwareremoval.com/BillCastner/FixPolicies.exe&#012;</textarea><!--end code block--><br>&#8226;  Double-click <b>FixPolicies.exe</b><br>&#8226; Click the "Install" button on the bottom toolbar of the box that will open.<br>&#8226; The program will create a new Folder called FixPolicies,<br>&#8226; Double-click to Open the new Folder, and then double-click the file within:  <b>Fix_Policies.cmd</b>.<br>&#8226; A black box will briefly appear and then close. <br><br>Please download<b>  <i>ATF Cleaner</i></b> <br><textarea name="code" class="text" cols=50 rows=10>http://www.atribune.org/ccount/click.php?id=1&#012;</textarea><!--end code block-->It does not require any installation.. It is set up to clean Windows TEMP folders, as well as IE, FireFox and Opera, Temporary Internet Files and Cookies.<br>&#8226;      Double-click <b>ATF-Cleaner.exe</b> to run the program. <br><br><b>First Step:</b><br>&#8226;      Under <b>Main</b> choose: <b>Select All</b><br>&#8226;      Click the <b>Empty Selected</b> button. <br><b><u>Next, if you use Firefox (and <i>some</i> Mozilla-based browsers)</u></b> <br>&#8226;      Click Firefox at the top and choose: <b>Select All</b><br>&#8226;      Click the <b>Empty Selected</b> button. <b><u><br>Next, if you use the Opera browser</u></b> <br>&#8226;      Click <b>Opera</b> at the top and choose: <b>Select All</b> <br>&#8226;      Click the <b>Empty Selected</b> button. <b>:!: Click Exit on the Main menu to close the program.</b><br><br><b>Reconfigure Windows XP to show hidden files:</b><br><i>To enable the viewing of Hidden files follow these steps: </i><br>&#8226; Close all programs so that you are at your desktop. <br>&#8226; Double-click on the My Computer icon. <br>&#8226; Select the Tools menu and click Folder Options. <br>&#8226; After the new window appears select the View tab. <br>&#8226; Put a checkmark in the checkbox labeled Display the contents of system folders. <br>&#8226; Under the Hidden files and folders section select the radio button labeled Show hidden files and folders. <br>&#8226; Remove the checkmark from the checkbox labeled Hide file extensions for known file types. <br>&#8226; Remove the checkmark from the checkbox labeled Hide protected operating system files. <br>&#8226; Press the Apply button and then the OK button and exit My Computer. <br>&#8226; Now your computer is configured to show all hidden files. <br><br><b><u>Malware Removal Steps</u></b><br>1. Open <b>HijackThis</b> again, System scan only.  <b>Checkmark</b> these items:<br><br><b>F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\uoyzsydz.exe,<br>O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k<br>O4 - HKLM\..\Run: [{2C-CD-D7-73-DW}] C:\windows\system32\rswnw64m.exe DWram02FF<br>O4 - HKLM\..\Run: [runner1] C:\WINDOWS\mrofinu572.exe 61A847B5BBF728173599284503996897C881250221C8670836AC4FA7C8833201749139<br>O4 - HKLM\..\Run: [ExploreUpdSched] C:\WINDOWS\system32\lcntktdm.exe DWram02FF<br>O4 - HKLM\..\Run: [18a2cddc] rundll32.exe "C:\WINDOWS\system32\ulrofafb.dll",b<br>O15 - Trusted Zone: *.amaena.com<br>O15 - Trusted Zone: *.avsystemcare.com<br>O15 - Trusted Zone: *.gomyhit.com<br>O15 - Trusted Zone: *.imageservr.com<br>O15 - Trusted Zone: *.imagesrvr.com<br>O15 - Trusted Zone: *.onerateld.com<br>O15 - Trusted Zone: *.safetydownload.com<br>O15 - Trusted Zone: *.storageguardsoft.com<br>O15 - Trusted Zone: *.trustedantivirus.com<br>O15 - Trusted Zone: *.virusschlacht.com<br>O15 - Trusted Zone: *.amaena.com (HKLM)<br>O15 - Trusted Zone: *.avsystemcare.com (HKLM)<br>O15 - Trusted Zone: *.gomyhit.com (HKLM)<br>O15 - Trusted Zone: *.imageservr.com (HKLM)<br>O15 - Trusted Zone: *.imagesrvr.com (HKLM)<br>O15 - Trusted Zone: *.onerateld.com (HKLM)<br>O15 - Trusted Zone: *.safetydownload.com (HKLM)<br>O15 - Trusted Zone: *.storageguardsoft.com (HKLM)<br>O15 - Trusted Zone: *.trustedantivirus.com (HKLM)<br>O15 - Trusted Zone: *.virusschlacht.com (HKLM)<br>O23 - Service: MsSecurity Updated (MsSecurity1.209.4) - Unknown owner - C:\WINDOWS\444.470.exe (file missing)</b><br><br>Click "<b>Fix checked</b>" and when the log panel clears exit HijackThis.<br><br>2. Please download MalwareBytes Anti-malware (MBAM) from one of the following links:<br><textarea name="code" class="text" cols=50 rows=10>http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html&#012;http://www.besttechie.net/tools/mbam-setup.exe&#012;</textarea><!--end code block--><br>Once downloaded, close all programs and Windows on your computer (including this one.)<br><br>Double-click on the icon on your desktop named Download_mbam-setup.exe. This will start the installation of MBAM onto your computer.<br><br>When the installation begins, keep following the prompts in order to continue with the installation process. Do not make any changes to default settings and when the program has finished installing, make sure you leave both the Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware checked. Then click on the Finish button.<br><br>MBAM will now automatically start and you will see a message stating that you should update the program before performing a scan. As MBAM will automatically update itself after the install, you can press the OK button to close that box and you will now be at the main program.<br><br>On the <b>Scanner tab</b>, make sure the the <b>Perform quick scan</b> option is selected and then click on the <b>Scan</b> button to start scanning your computer.<br><br>MBAM will now start scanning your computer for malware. This process can take quite a while, so we suggest you go and do something else and periodically check on the status of the scan. <br><br>When the scan is finished a message box will appear that it has completed scanning successfully.  Click <b>OK</b>.  Now click <b>Show Results</b>.  Make sure all entries have a checkmark at their far left.  You should now click on the <b>Remove Selected</b> button to remove all the listed malware. MBAM will now delete all of the files and registry keys and add them to the programs quarantine.<br><br>When MBAM has finished removing the malware, it will open the scan log and display it in Notepad. Review the log as desired, and then close the Notepad window.  Remember where you saved the log file, as we will want to see it later.<br><br>3. Download -- but <i>do not</i> yet run  -- <b>ComboFix&copy; </b> <br><br>Download this file <b><u>-- to your Desktop --</u></b>  from any of these sources:  <br><textarea name="code" class="text" cols=50 rows=10>http://download.bleepingcomputer.com/sUBs/ComboFix.exe&#012;http://www.forospyware.com/sUBs/ComboFix.exe&#012;http://subs.geekstogo.com/ComboFix.exe&#012;</textarea><!--end code block--><br>Right-click on the header of the Code box below, where on the right side it says:  "<b>Copy to clipboard</b>":<br><textarea name="code" class="text" cols=50 rows=10>KILLALL::&#012; &#012;File::&#012;C:\WINDOWS\system32\uoyzsydz.exe&#012;C:\windows\system32\rswnw64m.exe&#012;C:\WINDOWS\mrofinu572.exe&#012; &#012;Driver::&#012;MsSecurity1.209.4&#012;MsSecurity Updated&#012;runner1&#012; &#012;</textarea><!--end code block--><br>Open a new Notepad session - (Do <b><i>not</i></b> use a Word Processor or WordPad).  Click "<b>Format</b>" and be certain that Word Wrap is not enabled.  Right-click | <b>Paste</b> the Code box contents from above into Notepad.  Click File, <b><i>Save as...</i></b>, and set the location to your Desktop, and enter (including quotation marks) as the filename: <b>"CFscript.txt"</b> .  <br><br>&#8226; Disconnect from the Internet.<br>&#8226; Disable your Antivirus.  If the Antivirus software you use has any Script Blocking features, be certain to disable these as well.<br><b> Important:  </b> Have no other programs running.  Your Task Bar should be clear of any program entries including your Browser.<br>&#8226; A window will open with a warning.  Accept any Disclaimers to start the fix.<br>Using your mouse, drag the new file CFscript.txt and drop it on the ComboFix.exe icon as shown in this little picture:<br> <IMG SRC="http://users.pandora.be/bluepatchy/miekiemoes/images/CFScript.gif"> <br><br>When the scan completes Notepad will open with with your results log open. Do a File, Exit and answer 'Yes' to save changes.<br>&#8226;<b>!</b>&#8226; A caution - Do <b>not</b> run Combofix more than once. Do not touch your mouse/keyboard until the scan has completed, as this may cause the process to stall or your computer to lock.<br><br>4. Run <b>HijackThis</b> again, and save the log file.<br><br>5.  Right click a blank area of your Desktop, and choose <b>Properties</b>.<br>The click in succession:  Desktop, Customize Desktop (a button choice), and finally <b>Web</b> (a tab choice).<br>Clear the top panel of any entries found.<br>Leave unchecked the chocie box:  "Lock desktop items"<br>Click <b>Apply</b>.  Then <b>OK</b> your way back to the Desktop.<br><br><b><i>Submit to the Forum:</i></b><br>&#8226;Your MBAM log results;<br>&#8226; The contents of C:\Combofix.txt;<br>&#8226; The new HijackThis log.<br><br><small>--<br><b>============</b><br><b>MS-MVP 2004 - -2008, ASAP Member</b><br><b><i>Users Helping Users</i></b><br><br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20763389</guid>
<pubDate>Wed, 09 Jul 2008 10:20:43 EDT</pubDate>
</item>

<item>
<title>HJT Log - Changes Windows Background automatically</title>
<link>http://www.dslreports.com/forum/remark,20762617</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Hallo you!<br><br>I start my PC and every 3 minutes he wants to connect to the Internet, although i told he should be working offline. (there is no Internet connected) <br><br>There is also a Popup-Windows, which tells me, that there is Spyware on my Computer named "ctrlpan.dll". Its a window named "Windows Spyware Center system warning".<br><br>Also a program changes my Desktop-Background into a warning "warning spyware threat has been detected on your PC....." There is a link in it th scan my PC for Spyware.<br><br>I already updated AS, AV and AT and made scans. <br>I also used CC-Cleaner. And i used CSShredder, but the Problem is still there.<br><br>So here is my Hijack this log-file:<br><br>Logfile of Trend Micro HijackThis v2.0.2<br>Scan saved at 10:32:14, on 09.07.2008<br>Platform: Windows XP SP2 (WinNT 5.01.2600)<br>MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)<br>Boot mode: Normal<br><br>Running processes:<br>C:\WINDOWS\System32\smss.exe<br>C:\WINDOWS\system32\winlogon.exe<br>C:\WINDOWS\system32\services.exe<br>C:\WINDOWS\system32\lsass.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\WINDOWS\system32\spoolsv.exe<br>C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe<br>C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe<br>C:\WINDOWS\444.470<br>C:\WINDOWS\system32\nvsvc32.exe<br>C:\WINDOWS\system32\uoyzsydz.exe<br>C:\WINDOWS\Explorer.EXE<br>C:\Programme\Launch Manager\LaunchAp.exe<br>C:\Programme\Launch Manager\HotkeyApp.exe<br>C:\Programme\Launch Manager\OSD.exe<br>C:\Programme\Launch Manager\Wbutton.exe<br>C:\Programme\Synaptics\SynTP\SynTPEnh.exe<br>C:\WINDOWS\RTHDCPL.EXE<br>C:\Programme\Synaptics\SynTP\SynMedion.exe<br>C:\PROGRA~1\Grisoft\AVG7\avgcc.exe<br>C:\windows\system32\rswnw64m.exe<br>C:\WINDOWS\mrofinu572.exe<br>C:\WINDOWS\system32\lcntktdm.exe<br>C:\WINDOWS\system32\rundll32.exe<br>C:\WINDOWS\system32\ctfmon.exe<br>C:\Programme\Gemeinsame Dateien\Ahead\Lib\NMBgMonitor.exe<br>C:\Programme\Gemeinsame Dateien\Ahead\Lib\NMIndexStoreSvr.exe<br>C:\Programme\Internet Explorer\iexplore.exe<br>C:\Programme\Trend Micro\HijackThis\HijackThis.exe<br><br>F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\uoyzsydz.exe,<br>O4 - HKLM\..\Run: [LaunchAp] "C:\Programme\Launch Manager\LaunchAp.exe"<br>O4 - HKLM\..\Run: [HotkeyApp] "C:\Programme\Launch Manager\HotkeyApp.exe"<br>O4 - HKLM\..\Run: [LMgrOSD] "C:\Programme\Launch Manager\OSD.exe"<br>O4 - HKLM\..\Run: [Wbutton] "C:\Programme\Launch Manager\Wbutton.exe"<br>O4 - HKLM\..\Run: [SynTPEnh] C:\Programme\Synaptics\SynTP\SynTPEnh.exe<br>O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE<br>O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE<br>O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup<br>O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP<br>O4 - HKLM\..\Run: [CorelDRAW Graphics Suite 11b] C:\Programme\Corel\Corel Graphics 12\Languages\DE\Programs\Registration.exe /title="CorelDRAW Graphics Suite 12" /date=072308 serial=DR12WEX-1502297-EBB lang=DE<br>O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k<br>O4 - HKLM\..\Run: [{2C-CD-D7-73-DW}] C:\windows\system32\rswnw64m.exe DWram02FF<br>O4 - HKLM\..\Run: [runner1] C:\WINDOWS\mrofinu572.exe 61A847B5BBF728173599284503996897C881250221C8670836AC4FA7C8833201749139<br>O4 - HKLM\..\Run: [ExploreUpdSched] C:\WINDOWS\system32\lcntktdm.exe DWram02FF<br>O4 - HKLM\..\Run: [18a2cddc] rundll32.exe "C:\WINDOWS\system32\ulrofafb.dll",b<br>O4 - HKLM\..\Run: [CtrlVol] C:\Programme\Launch Manager\CtrlVol.exe<br>O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe<br>O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Programme\Gemeinsame Dateien\Ahead\Lib\NMBgMonitor.exe"<br>O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKALER DIENST')<br>O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOKALER DIENST')<br>O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETZWERKDIENST')<br>O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')<br>O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')<br>O4 - Startup: Deewoo.lnk = C:\WINDOWS\system32\lcntktdm.exe<br>O4 - Startup: DW_Start.lnk = C:\WINDOWS\system32\rswnw64m.exe<br>O8 - Extra context menu item: Ausgew&auml;hlte Verkn&uuml;pfungen in Adobe PDF konvertieren - res://C:\Programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html<br>O8 - Extra context menu item: Ausgew&auml;hlte Verkn&uuml;pfungen in vorhandene PDF-Datei konvertieren - res://C:\Programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html<br>O8 - Extra context menu item: Auswahl in Adobe PDF konvertieren - res://C:\Programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html<br>O8 - Extra context menu item: Auswahl in vorhandene PDF-Datei konvertieren - res://C:\Programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html<br>O8 - Extra context menu item: In Adobe PDF konvertieren - res://C:\Programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html<br>O8 - Extra context menu item: In vorhandene PDF-Datei konvertieren - res://C:\Programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html<br>O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000<br>O8 - Extra context menu item: Verkn&uuml;pfungsziel in Adobe PDF konvertieren - res://C:\Programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html<br>O8 - Extra context menu item: Verkn&uuml;pfungsziel in vorhandene PDF-Datei konvertieren - res://C:\Programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html<br>O9 - Extra button: Recherchieren - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL<br>O15 - Trusted Zone: *.amaena.com<br>O15 - Trusted Zone: *.avsystemcare.com<br>O15 - Trusted Zone: *.gomyhit.com<br>O15 - Trusted Zone: *.imageservr.com<br>O15 - Trusted Zone: *.imagesrvr.com<br>O15 - Trusted Zone: *.onerateld.com<br>O15 - Trusted Zone: *.safetydownload.com<br>O15 - Trusted Zone: *.storageguardsoft.com<br>O15 - Trusted Zone: *.trustedantivirus.com<br>O15 - Trusted Zone: *.virusschlacht.com<br>O15 - Trusted Zone: *.amaena.com (HKLM)<br>O15 - Trusted Zone: *.avsystemcare.com (HKLM)<br>O15 - Trusted Zone: *.gomyhit.com (HKLM)<br>O15 - Trusted Zone: *.imageservr.com (HKLM)<br>O15 - Trusted Zone: *.imagesrvr.com (HKLM)<br>O15 - Trusted Zone: *.onerateld.com (HKLM)<br>O15 - Trusted Zone: *.safetydownload.com (HKLM)<br>O15 - Trusted Zone: *.storageguardsoft.com (HKLM)<br>O15 - Trusted Zone: *.trustedantivirus.com (HKLM)<br>O15 - Trusted Zone: *.virusschlacht.com (HKLM)<br>O23 - Service: Adobe LM Service - Adobe Systems - C:\Programme\Gemeinsame Dateien\Adobe Systems Shared\Service\Adobelmsvc.exe<br>O23 - Service: Adobe Version Cue CS2 - Adobe Systems Incorporated - C:\Programme\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe<br>O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe<br>O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe<br>O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programme\Gemeinsame Dateien\InstallShield\Driver\1050\Intel 32\IDriverT.exe<br>O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Programme\Gemeinsame Dateien\Macromedia Shared\Service\Macromedia Licensing.exe<br>O23 - Service: MsSecurity Updated (MsSecurity1.209.4) - Unknown owner - C:\WINDOWS\444.470.exe (file missing)<br>O23 - Service: NBService - Nero AG - C:\Programme\Nero\Nero 7\Nero BackItUp\NBService.exe<br>O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe<br>O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc) - TuneUp Software GmbH - C:\Programme\TuneUpUtilities2004\WinStylerThemeSvc.exe<br><br>--<br>End of file - 7211 bytes<br><br>Thanks for helping me!!!!!!]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20762617</guid>
<pubDate>Wed, 09 Jul 2008 04:53:24 EDT</pubDate>
</item>

</channel>
</rss>
