<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>[Trojan or Vundo] HJT Log - Tdsserv HELP in Security Cleanup</title>
<link>http://www.dslreports.com/forum/r21121671</link>
<description></description>
<language>en</language>
<pubDate>Wed, 11 Nov 2009 09:30:42 EDT</pubDate>
<lastBuildDate>Wed, 11 Nov 2009 09:30:42 EDT</lastBuildDate>

<item>
<title>Re: [Trojan or Vundo] HJT Log - Tdsserv HELP</title>
<link>http://www.dslreports.com/forum/remark,21146546</link>
<description><![CDATA[<A HREF="/useremail/u/751678"><b>lilhurricane</b></A> : I love a<br><br> <IMG SRC="http://www.dslreports.com/r0/download/956087~d7b19b46b0639a8f53469fe701384b0a/happy.gif">   :)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21146546</guid>
<pubDate>Sun, 21 Sep 2008 18:43:48 EDT</pubDate>
</item>

<item>
<title>Re: [Trojan or Vundo] HJT Log - Tdsserv HELP</title>
<link>http://www.dslreports.com/forum/remark,21146488</link>
<description><![CDATA[<A HREF="/useremail/u/1582066"><b>PPL</b></A> : Thanks for your time and Support!]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21146488</guid>
<pubDate>Sun, 21 Sep 2008 18:27:07 EDT</pubDate>
</item>

<item>
<title>Re: [Trojan or Vundo] HJT Log - Tdsserv HELP</title>
<link>http://www.dslreports.com/forum/remark,21145504</link>
<description><![CDATA[<A HREF="/useremail/u/555588"><b>LoPhatPhuud</b></A> : The last HJT log is clean too, so we are finished.<br><br>You can enable the Spyware Doctor realtime protection and see see if using it affects your response.<br><br>Yes, Zone Alarm is your firewall.<br><small>--<br>When angry count four; when very angry, swear.<br><br>Microsoft MVP/Consumer Security 2005-2008<br><br><A HREF="http://forum.gladiator-antivirus.com">Gladiator Security Forum</a></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21145504</guid>
<pubDate>Sun, 21 Sep 2008 14:02:13 EDT</pubDate>
</item>

<item>
<title>Re: [Trojan or Vundo] HJT Log - Tdsserv HELP</title>
<link>http://www.dslreports.com/forum/remark,21143359</link>
<description><![CDATA[<A HREF="/useremail/u/1582066"><b>PPL</b></A> : This is the hijackthis log for the other account on the same computer.<br><br>Logfile of Trend Micro HijackThis v2.0.2<br>Scan saved at 8:22:16 PM, on 9/20/2008<br>Platform: Windows XP SP2 (WinNT 5.01.2600)<br>MSIE: Internet Explorer v8.00 (8.00.6001.18241)<br>Boot mode: Normal<br><br>Running processes:<br>C:\WINDOWS\System32\smss.exe<br>C:\WINDOWS\system32\winlogon.exe<br>C:\WINDOWS\system32\services.exe<br>C:\WINDOWS\system32\lsass.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\Program Files\Windows Defender\MsMpEng.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe<br>C:\Program Files\Alwil Software\Avast4\ashServ.exe<br>C:\WINDOWS\system32\brsvc01a.exe<br>C:\WINDOWS\system32\brss01a.exe<br>C:\WINDOWS\system32\spoolsv.exe<br>C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br>C:\Program Files\Bonjour\mDNSResponder.exe<br>C:\Program Files\DLink\Bluetooth Software\bin\btwdins.exe<br>C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe<br>C:\Program Files\Java\jre6\bin\jqs.exe<br>C:\WINDOWS\system32\nvsvc32.exe<br>C:\WINDOWS\system32\PnkBstrA.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\WINDOWS\system32\ZoneLabs\vsmon.exe<br>C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe<br>C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe<br>C:\Program Files\Alwil Software\Avast4\ashWebSv.exe<br>C:\Program Files\iPod\bin\iPodService.exe<br>C:\WINDOWS\system32\winlogon.exe<br>C:\WINDOWS\Explorer.EXE<br>C:\WINDOWS\system32\ctfmon.exe<br>C:\Program Files\Common Files\Real\Update_OB\realsched.exe<br>C:\WINDOWS\system32\rundll32.exe<br>C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe<br>C:\Program Files\iTunes\iTunesHelper.exe<br>C:\WINDOWS\system32\RUNDLL32.EXE<br>C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe<br>C:\Program Files\Java\jre6\bin\jusched.exe<br>C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe<br>C:\Program Files\DLink\Bluetooth Software\BTTray.exe<br>C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe<br>C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkCalRem.exe<br>C:\Program Files\SBC Self Support Tool\bin\mpbtn.exe<br>C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br><br>R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &raquo;<A HREF="http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q304&bd=presario&pf=desktop" >ie.redirect.hp.com/svs/rdr?TYPE=&middot;&middot;&middot;=desktop</A><br>R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &raquo;<A HREF="http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q304&bd=presario&pf=desktop" >ie.redirect.hp.com/svs/rdr?TYPE=&middot;&middot;&middot;=desktop</A><br>R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.yahoo.com<br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=69157" >go.microsoft.com/fwlink/?LinkId=69157</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = &raquo;<A HREF="http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q304&bd=presario&pf=desktop" >ie.redirect.hp.com/svs/rdr?TYPE=&middot;&middot;&middot;=desktop</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q304&bd=presario&pf=desktop" >ie.redirect.hp.com/svs/rdr?TYPE=&middot;&middot;&middot;=desktop</A><br>R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = &raquo;<A HREF="http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q304&bd=presario&pf=desktop" >ie.redirect.hp.com/svs/rdr?TYPE=&middot;&middot;&middot;=desktop</A><br>R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)<br>O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)<br>O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll<br>O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\FlashGet\jccatch.dll<br>O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll<br>O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll<br>O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll<br>O2 - BHO: (no name) - {A7327C09-B521-4EDB-8509-7D2660C9EC98} - (no file)<br>O2 - BHO: (no name) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - (no file)<br>O2 - BHO: IE DOM Explorer - {CC7E636D-39AA-49b6-B511-65413DA137A1} - C:\Program Files\Internet Explorer Developer Toolbar\IEDevToolbar.dll<br>O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br>O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br>O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\FlashGet\getflash.dll<br>O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll<br>O3 - Toolbar: Developer Toolbar - {CC962137-2E78-4f94-975E-FC0C07DBD78F} - C:\Program Files\Internet Explorer Developer Toolbar\IEDevToolbar.dll<br>O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe<br>O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup<br>O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot<br>O4 - HKLM\..\Run: [nwiz] nwiz.exe /install<br>O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe<br>O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime<br>O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"<br>O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32<br>O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC<br>O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC<br>O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName<br>O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit<br>O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"<br>O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"<br>O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br>O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"<br>O4 - HKCU\..\Run: [Yahoo! Pager] 1<br>O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe<br>O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe<br>O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe<br>O4 - HKUS\S-1-5-21-1444666018-1835601529-2086350918-1009\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe" (User 'Jonathan')<br>O4 - HKUS\S-1-5-21-1444666018-1835601529-2086350918-1009\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime (User 'Jonathan')<br>O4 - HKUS\S-1-5-21-1444666018-1835601529-2086350918-1009\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'Jonathan')<br>O4 - Startup: wkcalrem.LNK = C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkCalRem.exe<br>O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe<br>O4 - Global Startup: AT&T Self Support Tool.lnk = C:\Program Files\SBC Self Support Tool\bin\matcli.exe<br>O4 - Global Startup: BTTray.lnk = ?<br>O4 - Global Startup: EPSON Status Monitor 3 Environment Check.lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV03.EXE<br>O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE<br>O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe<br>O4 - Global Startup: VPN Client.lnk = ?<br>O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm<br>O8 - Extra context menu item: Add To Compaq Organize... - C:\PROGRA~1\HEWLET~1\COMPAQ~1\bin\core.hp.main\SendTo.html<br>O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000<br>O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\DLink\Bluetooth Software\btsendto_ie_ctx.htm<br>O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm<br>O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm<br>O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm<br>O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll<br>O9 - Extra 'Tools' menuitem: &7 Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll<br>O9 - Extra button: Fill Id - {320AF880-6646-11D3-ABEE-C5DBF3571F47} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll<br>O9 - Extra 'Tools' menuitem: &5 Fill from Identity - {320AF880-6646-11D3-ABEE-C5DBF3571F47} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll<br>O9 - Extra button: Fill Pass - {320AF880-6646-11D3-ABEE-C5DBF3571F48} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll<br>O9 - Extra 'Tools' menuitem: &6 Fill from Passcard - {320AF880-6646-11D3-ABEE-C5DBF3571F48} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll<br>O9 - Extra button: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll<br>O9 - Extra 'Tools' menuitem: &8 Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll<br>O9 - Extra button: Go Fill - {320AF880-6646-11D3-ABEE-C5DBF3571F4A} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll<br>O9 - Extra 'Tools' menuitem: &Go && Fill from Passcard - {320AF880-6646-11D3-ABEE-C5DBF3571F4A} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll<br>O9 - Extra button: Login - {320AF880-6646-11D3-ABEE-C5DBF3571F4B} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll<br>O9 - Extra 'Tools' menuitem: &Login (Go, Fill, Submit) - {320AF880-6646-11D3-ABEE-C5DBF3571F4B} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll<br>O9 - Extra button: Options - {320AF880-6646-11D3-ABEE-C5DBF3571F4C} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll<br>O9 - Extra 'Tools' menuitem: &Options - {320AF880-6646-11D3-ABEE-C5DBF3571F4C} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll<br>O9 - Extra button: Identities - {45DB34C3-955C-11D3-ABEF-444553540000} - C:\Program Files\Siber Systems\AI RoboForm\Identities.exe<br>O9 - Extra 'Tools' menuitem: &3 Edit Identities - {45DB34C3-955C-11D3-ABEF-444553540000} - C:\Program Files\Siber Systems\AI RoboForm\Identities.exe<br>O9 - Extra button: Passcards - {45DB34C3-955C-11D3-ABEF-444553540001} - C:\Program Files\Siber Systems\AI RoboForm\Passcards.exe<br>O9 - Extra 'Tools' menuitem: &4 Edit Passcards - {45DB34C3-955C-11D3-ABEF-444553540001} - C:\Program Files\Siber Systems\AI RoboForm\Passcards.exe<br>O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll<br>O9 - Extra button: RF toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll<br>O9 - Extra 'Tools' menuitem: &9 Robo Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll<br>O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL<br>O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\DLink\Bluetooth Software\btsendto_ie.htm<br>O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\DLink\Bluetooth Software\btsendto_ie.htm<br>O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe<br>O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe<br>O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - &raquo;<A HREF="http://go.microsoft.com/fwlink/?linkid=39204" >go.microsoft.com/fwlink/?linkid=39204</A><br>O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll<br>O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - &raquo;<A HREF="http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1093039999628" >v5.windowsupdate.microsoft.com/v&middot;&middot;&middot;39999628</A><br>O16 - DPF: {69EF49E5-FE46-4B92-B5FA-2193AB7A6B8A} (GameLauncher Control) - &raquo;<A HREF="http://www.acclaim.com/cabs/acclaim_v4.cab" >www.acclaim.com/cabs/acclaim_v4.cab</A><br>O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br>O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe<br>O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe<br>O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe<br>O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe<br>O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br>O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe<br>O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - C:\Program Files\DLink\Bluetooth Software\bin\btwdins.exe<br>O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe<br>O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe<br>O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br>O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br>O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe<br>O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe<br>O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - C:\Program Files\WinPcap\rpcapd.exe<br>O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe<br>O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe<br>O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe<br>O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe<br>O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe<br><br>--<br>End of file - 15255 bytes<br><br>P.S. I have Spyware Doctor downloaded and I was wondering if I should enable its Intelli-guard. A real time protection from Spyware Doctor, because some reviews says that spyware doctor lags the computer up. Right now I have Avast on access protection and zone labs running. Zone Labs counts as a firewall right?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21143359</guid>
<pubDate>Sat, 20 Sep 2008 21:29:48 EDT</pubDate>
</item>

<item>
<title>Re: [Trojan or Vundo] HJT Log - Tdsserv HELP</title>
<link>http://www.dslreports.com/forum/remark,21143299</link>
<description><![CDATA[<A HREF="/useremail/u/555588"><b>LoPhatPhuud</b></A> : There may be nothing to do on the other logon. Log into it, run HiJackThis and post that log in this thread. Be sure to indicate that this is a different logon for the same computer.<br><br>You can remove MBAM, FixPolicies, and ATF that we installed as part of the cleaning process. You may want to retain MBAM and ATF. They are excellent programs and MBAM is one of the very few programs that can entirely rmeove the tds variation of Vundo. After the trial period expires, MBAM will become the free version without the realtime protection.<br><br>YOu will have to decide whether to remove programs installed prior to this infection. THere is nothing wrong with running more than one AntiSpyware program that offer realtime protection.<br><br>Just be sure you only have one AV and one firewall active.<br><small>--<br>When angry count four; when very angry, swear.<br><br>Microsoft MVP/Consumer Security 2005-2008<br><br><A HREF="http://forum.gladiator-antivirus.com">Gladiator Security Forum</a></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21143299</guid>
<pubDate>Sat, 20 Sep 2008 21:12:51 EDT</pubDate>
</item>

<item>
<title>Re: [Trojan or Vundo] HJT Log - Tdsserv HELP</title>
<link>http://www.dslreports.com/forum/remark,21142453</link>
<description><![CDATA[<A HREF="/useremail/u/1582066"><b>PPL</b></A> : Thanks for you time and support, and Just a couple questions. should I do all the steps before for the other account on the computer too? And I have a couple anti spyware and virus things installed, should I just unistall it all and just have one? Last question, can I delete ATF-Cleaner, MBAM and the other stuff like spybot?<br><br>P.S. I use Avast and ZoneLabs<br> DO you exactly know what virus/vundo/trojan I had?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21142453</guid>
<pubDate>Sat, 20 Sep 2008 16:55:56 EDT</pubDate>
</item>

<item>
<title>Re: [Trojan or Vundo] HJT Log - Tdsserv HELP</title>
<link>http://www.dslreports.com/forum/remark,21142352</link>
<description><![CDATA[<A HREF="/useremail/u/555588"><b>LoPhatPhuud</b></A> : Your system appears clean. Just a bit of cleanup left.<br><br><b>First:</b><br>Click <b>Start</b>, then click <b>Run</b>.<br>Enter into the command box that opens:  <b>combofix /u</b> and then click <b>OK</b>.<br> <IMG SRC="http://i78.photobucket.com/albums/j116/amateur_photos/CFuninstall.png"> <br><br><b>Second:</b><br>Please download ATF Cleaner by Atribune.<br><br><textarea name="code" class="text" cols=50 rows=10>http://www.atribune.org/ccount/click.php?id=1&#012;</textarea><!--end code block-->Double-click <b>ATF-Cleaner.exe</b> to run the program.<br><br>Under <b>Main</b> choose: <b>Select All</b><br>Click the <b>Empty Selected</b> button.<br></ul>[u]If you use Firefox browser[/u]Click <b>Firefox</b> at the top and choose: <b>Select All</b><br>Click the <b>Empty Selected</b> button.<br><b>NOTE:</b> If you would like to keep your saved passwords, please click <b>No</b> at the prompt.<br></ul>[u]If you use Opera browser[/u]Click <b>Opera</b> at the top and choose: <b>Select All</b><br>Click the <b>Empty Selected</b> button.<br><b>NOTE:</b> If you would like to keep your saved passwords, please click <b>No</b> at the prompt.<br></ul>Click <b>Exit</b> on the Main menu to close the program.<br>For <b>Technical Support</b>, double-click the e-mail address located at the bottom of each menu.<br><br><small>--<br>When angry count four; when very angry, swear.<br><br>Microsoft MVP/Consumer Security 2005-2008<br><br><A HREF="http://forum.gladiator-antivirus.com">Gladiator Security Forum</a></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21142352</guid>
<pubDate>Sat, 20 Sep 2008 16:29:18 EDT</pubDate>
</item>

<item>
<title>Re: [Trojan or Vundo] HJT Log - Tdsserv HELP</title>
<link>http://www.dslreports.com/forum/remark,21140035</link>
<description><![CDATA[<A HREF="/useremail/u/1582066"><b>PPL</b></A> : Okay, I did the ComboFix, HiJackThis, and MBAM but when I did MBAM, it didn't ask for what drives to scan for unless I do full scan. So i just went ahead and did a full scan. Anyways, here are the logs. Lets start with the MBAM log:<br><br>Malwarebytes' Anti-Malware 1.28<br>Database version: 1179<br>Windows 5.1.2600 Service Pack 2<br><br>9/19/2008 9:51:24 PM<br>mbam-log-2008-09-19 (21-51-24).txt<br><br>Scan type: Full Scan (A:\|C:\|D:\|E:\|F:\|)<br>Objects scanned: 183317<br>Time elapsed: 53 minute(s), 13 second(s)<br><br>Memory Processes Infected: 0<br>Memory Modules Infected: 0<br>Registry Keys Infected: 0<br>Registry Values Infected: 0<br>Registry Data Items Infected: 0<br>Folders Infected: 0<br>Files Infected: 5<br><br>Memory Processes Infected:<br>(No malicious items detected)<br><br>Memory Modules Infected:<br>(No malicious items detected)<br><br>Registry Keys Infected:<br>(No malicious items detected)<br><br>Registry Values Infected:<br>(No malicious items detected)<br><br>Registry Data Items Infected:<br>(No malicious items detected)<br><br>Folders Infected:<br>(No malicious items detected)<br><br>Files Infected:<br>C:\System Volume Information\_restore{B06C75F0-9FCC-4D32-A4A4-58CDE7C44A50}\RP3\A0000137.sys (Trojan.FakeAlert) -> Quarantined and deleted successfully.<br>C:\Documents and Settings\Jonathan\Local Settings\Temp\????.doc (Trojan.Extension.Exploit) -> Quarantined and deleted successfully.<br>C:\Documents and Settings\Jonathan\Local Settings\Temp\??.doc (Trojan.Extension.Exploit) -> Quarantined and deleted successfully.<br>C:\Documents and Settings\Owner\Desktop\???.doc (Trojan.Extension.Exploit) -> Quarantined and deleted successfully.<br>C:\Documents and Settings\Jonathan\Desktop\????.doc (Trojan.Extension.Exploit) -> Quarantined and deleted successfully.<br><br>Here is the ComboFix LOG:<br><br>ComboFix 08-09-19.06 - Jonathan 2008-09-19 21:56:51.1 - NTFSx86<br>Microsoft Windows XP Home Edition  5.1.2600.2.1252.1.1033.18.354 [GMT -5:00]<br>Running from: C:\Documents and Settings\Jonathan\Desktop\ComboFix.exe<br> * Created a new restore point<br>.<br><br>(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br><br>C:\Documents and Settings\All Users\Application Data\p4p<br>C:\Documents and Settings\All Users\Application Data\p4p\Downloaded\3620_3660PCSuite.exe.lnk<br>C:\Documents and Settings\All Users\Application Data\p4p\Downloaded\avg6762fu_free.exe.lnk<br>C:\Documents and Settings\All Users\Application Data\p4p\Downloaded\avi_mpg_splitter.exe.lnk<br>C:\Documents and Settings\All Users\Application Data\p4p\Downloaded\dvtool053.exe.lnk<br>C:\Documents and Settings\All Users\Application Data\p4p\Downloaded\DXX13.exe.lnk<br>C:\Documents and Settings\All Users\Application Data\p4p\Downloaded\DXX22.exe.lnk<br>C:\Documents and Settings\All Users\Application Data\p4p\Downloaded\DXX23.exe.lnk<br>C:\Documents and Settings\All Users\Application Data\p4p\Downloaded\Epson660PrinterDriver.EXE.lnk<br>C:\Documents and Settings\All Users\Application Data\p4p\Downloaded\microsoftofficekeygenrb.zip.lnk<br>C:\Documents and Settings\All Users\Application Data\p4p\Downloaded\zweifull.exe.lnk<br>C:\Documents and Settings\All Users\Application Data\p4p\metafile.dat<br>C:\Documents and Settings\Jonathan\Application Data\inst.exe<br>C:\WINDOWS\system32\drivers\npf.sys<br>C:\WINDOWS\system32\MSINET.oca<br>C:\WINDOWS\system32\packet.dll<br>C:\WINDOWS\system32\pthreadVC.dll<br>C:\WINDOWS\system32\wpcap.dll<br>D:\Autorun.inf<br><br>.<br>(((((((((((((((((((((((((((((((((((((((   Drivers/Services   )))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br><br>-------\Service_NPF<br><br>(((((((((((((((((((((((((   Files Created from 2008-08-20 to 2008-09-20  )))))))))))))))))))))))))))))))<br>.<br><br>2008-09-19 20:47 . 2008-09-19 20:48&#9;&#9;d--------&#9;C:\Program Files\Malwarebytes' Anti-Malware<br>2008-09-19 20:47 . 2008-09-10 00:04&#9;38,528&#9;--a------&#9;C:\WINDOWS\system32\drivers\mbamswissarmy.sys<br>2008-09-19 20:47 . 2008-09-10 00:03&#9;17,200&#9;--a------&#9;C:\WINDOWS\system32\drivers\mbam.sys<br>2008-09-18 19:47 . 2008-09-18 19:47&#9;410,976&#9;--a------&#9;C:\WINDOWS\system32\deploytk.dll<br>2008-09-18 19:47 . 2008-09-18 19:47&#9;73,728&#9;--a------&#9;C:\WINDOWS\system32\javacpl.cpl<br>2008-09-18 19:01 . 2008-09-18 19:01&#9;&#9;d--hs----&#9;C:\Documents and Settings\Jonathan\PrivacIE<br>2008-09-18 18:15 . 2008-09-18 18:16&#9;&#9;d--h-c---&#9;C:\WINDOWS\ie8<br>2008-09-16 18:24 . 2008-09-16 18:24&#9;&#9;d--------&#9;C:\Program Files\Windows Defender<br>2008-09-15 20:37 . 2008-09-15 20:37&#9;110&#9;--a------&#9;C:\Documents and Settings\Jonathan\Application Data\netstat.bat<br>2008-09-15 19:22 . 2008-09-15 19:22&#9;&#9;d--------&#9;C:\Documents and Settings\All Users\Application Data\Sunbelt<br>2008-09-11 17:55 . 2008-06-10 21:22&#9;81,288&#9;--a------&#9;C:\WINDOWS\system32\drivers\iksyssec.sys<br>2008-09-11 17:55 . 2008-06-02 15:19&#9;66,952&#9;--a------&#9;C:\WINDOWS\system32\drivers\iksysflt.sys<br>2008-09-11 17:55 . 2008-06-02 15:19&#9;42,376&#9;--a------&#9;C:\WINDOWS\system32\drivers\ikfilesec.sys<br>2008-09-11 17:55 . 2008-06-02 15:19&#9;29,576&#9;--a------&#9;C:\WINDOWS\system32\drivers\kcom.sys<br>2008-09-11 17:54 . 2008-09-11 20:14&#9;&#9;d--------&#9;C:\Program Files\Spyware Doctor<br>2008-09-11 17:54 . 2008-09-11 17:54&#9;&#9;d--------&#9;C:\Documents and Settings\Jonathan\Application Data\PC Tools<br>2008-09-11 17:35 . 2008-09-11 17:46&#9;&#9;d--------&#9;C:\Program Files\Spybot - Search & Destroy<br>2008-09-09 20:16 . 2008-09-09 20:16&#9;&#9;d--------&#9;C:\Documents and Settings\Jonathan\Application Data\SUPERAntiSpyware.com<br>2008-09-09 20:15 . 2008-09-09 20:15&#9;&#9;d--------&#9;C:\Documents and Settings\Jonathan\Application Data\Malwarebytes<br>2008-09-09 16:47 . 2008-09-09 16:47&#9;&#9;d--------&#9;C:\Program Files\SUPERAntiSpyware<br>2008-09-09 16:47 . 2008-09-09 16:47&#9;&#9;d--------&#9;C:\Documents and Settings\Owner\Application Data\SUPERAntiSpyware.com<br>2008-09-09 16:47 . 2008-09-09 16:47&#9;&#9;d--------&#9;C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com<br>2008-09-08 21:42 . 2008-09-08 21:42&#9;&#9;d--------&#9;C:\Documents and Settings\Owner\Application Data\Malwarebytes<br>2008-09-08 21:41 . 2008-09-08 21:41&#9;&#9;d--------&#9;C:\Documents and Settings\All Users\Application Data\Malwarebytes<br>2008-09-08 19:16 . 2008-09-09 16:45&#9;&#9;d--------&#9;C:\Program Files\Common Files\Wise Installation Wizard<br>2008-09-07 10:32 . 2008-09-16 18:54&#9;&#9;d--------&#9;C:\Documents and Settings\Jonathan\.housecall6.6<br>2008-09-06 22:47 . 2008-09-06 22:47&#9;&#9;d--------&#9;C:\Program Files\CCleaner<br>2008-09-06 13:21 . 2008-09-16 16:16&#9;&#9;d-a------&#9;C:\Documents and Settings\All Users\Application Data\TEMP<br>2008-09-06 13:06 . 2008-09-11 17:54&#9;&#9;d--------&#9;C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy<br>2008-09-05 19:29 . 2008-09-08 19:19&#9;&#9;d--------&#9;C:\Documents and Settings\All Users\Application Data\Lavasoft<br>2008-09-05 18:51 . 2004-05-12 22:57&#9;&#9;d--------&#9;C:\Documents and Settings\Administrator\WINDOWS<br>2008-09-05 18:51 . 2004-05-15 06:16&#9;&#9;d--------&#9;C:\Documents and Settings\Administrator\Application Data\Symantec<br>2008-09-05 18:51 . 2004-05-13 00:19&#9;&#9;d--------&#9;C:\Documents and Settings\Administrator\Application Data\SampleView<br>2008-09-05 18:51 . 2008-09-05 18:51&#9;&#9;d--------&#9;C:\Documents and Settings\Administrator<br>2008-09-04 19:48 . 2008-09-16 19:22&#9;&#9;d--------&#9;C:\Program Files\Trend Micro<br>2008-09-01 21:14 . 2008-09-01 21:14&#9;18&#9;--ah-----&#9;C:\SYSREST<br>2008-09-01 14:20 . 2008-09-01 14:20&#9;&#9;d--------&#9;C:\Documents and Settings\All Users\Application Data\Trend Micro<br>2008-09-01 11:05 . 2008-09-12 17:43&#9;&#9;d--------&#9;C:\Program Files\Enigma Software Group<br>2008-08-31 09:33 . 2008-08-31 09:33&#9;123&#9;--a------&#9;C:\WINDOWS\system32\msexcr.ini<br>2008-08-30 21:44 . 2008-09-07 10:19&#9;174&#9;--a------&#9;C:\Documents and Settings\Jonathan\xrt_log.dat<br>2008-08-28 17:32 . 2008-08-28 17:32&#9;&#9;d--------&#9;C:\Documents and Settings\Jonathan\Application Data\iolo<br>2008-08-28 17:32 . 2008-08-28 17:32&#9;&#9;d--------&#9;C:\Documents and Settings\All Users\Application Data\iolo<br>2008-08-28 17:32 . 2008-08-28 17:32&#9;406&#9;--a------&#9;C:\WINDOWS\system32\ioloBootDefrag.cfg<br>2008-08-26 17:20 . 2008-08-26 17:20&#9;59,176&#9;--a------&#9;C:\WINDOWS\system32\sbbd.exe<br>2008-08-25 11:45 . 2008-09-06 13:04&#9;&#9;d--------&#9;C:\Documents and Settings\Owner\Application Data\U3<br>2008-08-24 09:33 . 2008-08-24 09:33&#9;&#9;d--------&#9;C:\Documents and Settings\Jonathan\Application Data\Syntrillium<br>2008-08-24 09:10 . 2008-08-24 09:10&#9;&#9;d--------&#9;C:\Program Files\MP3 Recorder 2008<br>2008-08-22 10:39 . 2008-09-05 18:26&#9;&#9;d--------&#9;C:\WINDOWS\system32\scripting<br>2008-08-22 10:39 . 2008-09-05 18:26&#9;&#9;d--------&#9;C:\WINDOWS\system32\en<br>2008-08-22 10:39 . 2008-09-05 18:26&#9;&#9;d--------&#9;C:\WINDOWS\l2schemas<br>2008-08-22 10:29 . 2008-08-22 03:09&#9;5,699,584&#9;--a--c---&#9;C:\WINDOWS\system32\dllcache\mshtml.dll<br>2008-08-22 10:28 . 2007-10-25 22:36&#9;8,454,656&#9;--a------&#9;C:\WINDOWS\system32\dllcache\shell32.dll<br>2008-08-22 09:19 . 2008-05-19 18:16&#9;186,407&#9;--a------&#9;C:\WINDOWS\system32\nvapps.nvb<br>2008-08-22 03:16 . 2008-08-22 03:16&#9;637,984&#9;-----c---&#9;C:\WINDOWS\system32\dllcache\iexplore.exe<br>2008-08-22 03:15 . 2008-08-22 03:15&#9;1,216,512&#9;---------&#9;C:\WINDOWS\system32\ieframe.dll.mui<br>2008-08-22 03:14 . 2008-08-22 03:14&#9;10,240&#9;---------&#9;C:\WINDOWS\system32\advpack.dll.mui<br>2008-08-22 03:08 . 2008-08-22 03:08&#9;1,415,680&#9;-----c---&#9;C:\WINDOWS\system32\dllcache\inetcpl.cpl<br>2008-08-22 03:08 . 2008-08-22 03:08&#9;236,544&#9;-----c---&#9;C:\WINDOWS\system32\dllcache\webcheck.dll<br>2008-08-22 03:08 . 2008-08-22 03:08&#9;43,008&#9;-----c---&#9;C:\WINDOWS\system32\dllcache\licmgr10.dll<br>2008-08-22 03:07 . 2008-08-22 03:07&#9;116,224&#9;-----c---&#9;C:\WINDOWS\system32\dllcache\occache.dll<br>2008-08-22 03:07 . 2008-08-22 03:07&#9;105,984&#9;-----c---&#9;C:\WINDOWS\system32\dllcache\url.dll<br>2008-08-22 03:07 . 2008-08-22 03:07&#9;18,944&#9;-----c---&#9;C:\WINDOWS\system32\dllcache\corpol.dll<br>2008-08-22 03:06 . 2008-08-22 03:06&#9;385,024&#9;-----c---&#9;C:\WINDOWS\system32\dllcache\iedkcs32.dll<br>2008-08-22 03:06 . 2008-08-22 03:06&#9;228,864&#9;-----c---&#9;C:\WINDOWS\system32\dllcache\ieaksie.dll<br>2008-08-22 03:06 . 2008-08-22 03:06&#9;162,304&#9;-----c---&#9;C:\WINDOWS\system32\dllcache\ie4uinit.exe<br>2008-08-22 03:06 . 2008-08-22 03:06&#9;128,512&#9;-----c---&#9;C:\WINDOWS\system32\dllcache\advpack.dll<br>2008-08-22 03:06 . 2008-08-22 03:06&#9;124,928&#9;-----c---&#9;C:\WINDOWS\system32\dllcache\ieakeng.dll<br>2008-08-22 03:06 . 2008-08-22 03:06&#9;72,704&#9;-----c---&#9;C:\WINDOWS\system32\dllcache\admparse.dll<br>2008-08-22 03:06 . 2008-08-22 03:06&#9;71,680&#9;-----c---&#9;C:\WINDOWS\system32\dllcache\iesetup.dll<br>2008-08-22 03:06 . 2008-08-22 03:06&#9;55,808&#9;-----c---&#9;C:\WINDOWS\system32\dllcache\iernonce.dll<br>2008-08-22 03:05 . 2008-08-22 03:05&#9;48,640&#9;---------&#9;C:\WINDOWS\system32\PrivacIE.dll<br>2008-08-22 03:05 . 2008-08-22 03:05&#9;48,128&#9;-----c---&#9;C:\WINDOWS\system32\dllcache\mshtmler.dll<br>2008-08-22 03:05 . 2008-08-22 03:05&#9;35,840&#9;-----c---&#9;C:\WINDOWS\system32\dllcache\imgutil.dll<br>2008-08-22 03:04 . 2008-08-22 03:04&#9;1,659,392&#9;-----c---&#9;C:\WINDOWS\system32\dllcache\mshtml.tlb<br>2008-08-22 03:04 . 2008-08-22 03:04&#9;66,560&#9;-----c---&#9;C:\WINDOWS\system32\dllcache\tdc.ocx<br>2008-08-22 03:04 . 2008-08-22 03:04&#9;45,568&#9;-----c---&#9;C:\WINDOWS\system32\dllcache\mshta.exe<br>2008-08-22 03:00 . 2008-08-22 03:00&#9;68,608&#9;-----c---&#9;C:\WINDOWS\system32\dllcache\hmmapi.dll<br>2008-08-21 20:45 . 2008-08-21 20:45&#9;2,645&#9;--ah-----&#9;C:\WINDOWS\SwSys2.bmp<br>2008-08-21 20:45 . 2008-08-21 20:45&#9;2,645&#9;--ah-----&#9;C:\WINDOWS\SwSys1.bmp<br>2008-08-21 18:44 . 2006-12-28 14:01&#9;19,569&#9;--a------&#9;C:\WINDOWS\[u]0[/u]05857_.tmp<br>2008-08-21 16:26 . 2008-08-21 16:27&#9;&#9;d--------&#9;C:\Program Files\SystemRequirementsLab<br>2008-08-21 16:26 . 2008-08-21 16:26&#9;&#9;d--------&#9;C:\Documents and Settings\Jonathan\Application Data\SystemRequirementsLab<br>2008-08-21 01:17 . 2008-08-21 01:17&#9;&#9;d--------&#9;C:\Documents and Settings\Jonathan\Application Data\Reallusion<br>2008-08-21 01:16 . 2008-08-21 01:16&#9;&#9;d--------&#9;C:\Program Files\Common Files\Reallusion<br>2008-08-21 00:20 . 2008-09-17 21:26&#9;&#9;d--------&#9;C:\Program Files\FlashGet<br>2008-08-20 08:10 . &#9;&#9;&#9;C:\Program Files\E&#155;'&cent;IoA&#135;<br>2008-08-20 07:42 . 2008-08-20 07:42&#9;&#9;d--------&#9;C:\Documents and Settings\Jonathan\Application Data\QQUpdate<br>2008-08-20 07:32 . 2008-08-20 07:32&#9;&#9;d--------&#9;C:\WINDOWS\system32\qqedit<br>2008-08-20 07:32 . 2008-08-20 07:32&#9;&#9;d--------&#9;C:\Program Files\QQMusic<br>2008-08-20 07:32 . 2008-08-20 07:43&#9;&#9;d--------&#9;C:\Program Files\QQGame<br>2008-08-20 07:32 . 2008-08-20 07:43&#9;&#9;d--------&#9;C:\Documents and Settings\Jonathan\Application Data\QQ<br>2008-08-20 07:31 . 2008-08-20 07:43&#9;&#9;d--------&#9;C:\Program Files\QQ<br>2008-08-20 06:53 . 2008-08-20 06:53&#9;&#9;d--------&#9;C:\Program Files\XAudioTools<br>2008-08-20 06:22 . 2008-08-20 06:22&#9;&#9;d--------&#9;C:\Documents and Settings\All Users\Application Data\McAfee<br>2008-08-20 05:46 . 2008-08-20 22:59&#9;&#9;d--------&#9;C:\Program Files\eMule<br>2008-08-20 05:29 . 2008-08-21 00:20&#9;&#9;d--------&#9;C:\Downloads<br>2008-08-20 05:02 . 2008-05-01 09:30&#9;331,776&#9;--a------&#9;C:\WINDOWS\system32\dllcache\msadce.dll<br><br>.<br>((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br>2008-09-19 23:21&#9;---------&#9;d-----w&#9;C:\Documents and Settings\Jonathan\Application Data\Viewpoint<br>2008-09-19 23:20&#9;---------&#9;d-----w&#9;C:\Program Files\Viewpoint<br>2008-09-19 23:20&#9;---------&#9;d-----w&#9;C:\Documents and Settings\All Users\Application Data\Viewpoint<br>2008-09-19 00:47&#9;---------&#9;d-----w&#9;C:\Program Files\Java<br>2008-09-19 00:34&#9;---------&#9;d-----w&#9;C:\Program Files\Yahoo!<br>2008-09-13 13:47&#9;47,866&#9;----a-w&#9;C:\WINDOWS\Internet Logs\zlclient_2nd_2008_09_13_08_44_23_small.dmp.zip<br>2008-09-12 00:41&#9;---------&#9;d-----w&#9;C:\Program Files\Google<br>2008-09-09 00:07&#9;---------&#9;d-----w&#9;C:\Program Files\Lavasoft<br>2008-09-09 00:06&#9;---------&#9;d-----w&#9;C:\Documents and Settings\Owner\Application Data\Lavasoft<br>2008-08-31 02:39&#9;---------&#9;d-----w&#9;C:\Documents and Settings\Jonathan\Application Data\DNA<br>2008-08-31 02:30&#9;---------&#9;d-----w&#9;C:\Documents and Settings\Jonathan\Application Data\Hamachi<br>2008-08-31 00:32&#9;---------&#9;d-----w&#9;C:\Program Files\DNA<br>2008-08-30 17:37&#9;25,280&#9;----a-w&#9;C:\WINDOWS\system32\drivers\hamachi.sys<br>2008-08-29 19:05&#9;---------&#9;d-----w&#9;C:\Documents and Settings\Jonathan\Application Data\U3<br>2008-08-28 23:45&#9;---------&#9;d--h--w&#9;C:\Documents and Settings\Jonathan\Application Data\ijjigame<br>2008-08-28 22:57&#9;---------&#9;d-----w&#9;C:\Program Files\Winamp<br>2008-08-28 22:53&#9;---------&#9;d-----w&#9;C:\Documents and Settings\Jonathan\Application Data\Winamp<br>2008-08-28 21:59&#9;---------&#9;d-----w&#9;C:\Program Files\Common Files\Adobe<br>2008-08-28 21:57&#9;---------&#9;d-----w&#9;C:\Documents and Settings\Jonathan\Application Data\AdobeUM<br>2008-08-25 13:53&#9;23,771,837&#9;----a-w&#9;C:\WINDOWS\Internet Logs\tvDebug.zip<br>2008-08-21 08:42&#9;---------&#9;d--h--w&#9;C:\Program Files\InstallShield Installation Information<br>2008-08-21 06:20&#9;---------&#9;d-----w&#9;C:\Documents and Settings\Jonathan\Application Data\InstallShield<br>2008-08-21 05:01&#9;---------&#9;d-----w&#9;C:\Program Files\BitComet<br>2008-08-21 04:05&#9;---------&#9;d-----w&#9;C:\Program Files\LimeWire<br>2008-08-20 16:27&#9;---------&#9;d-----w&#9;C:\Documents and Settings\All Users\Application Data\NexonUS<br>2008-08-20 13:24&#9;---------&#9;d-----w&#9;C:\Program Files\&Ecirc;&cent;&acute;&oacute;&Iacute;&oslash;&Acirc;&ccedil;<br>2008-08-20 10:41&#9;---------&#9;d-----w&#9;C:\Program Files\Skype<br>2008-08-20 10:41&#9;---------&#9;d-----w&#9;C:\Documents and Settings\All Users\Application Data\Skype<br>2008-08-20 10:13&#9;---------&#9;d-----w&#9;C:\Documents and Settings\Jonathan\Application Data\InstallShield Installation Information<br>2008-03-19 17:24&#9;32&#9;----a-w&#9;C:\Documents and Settings\All Users\Application Data\ezsid.dat<br>2008-02-07 22:09&#9;47,360&#9;----a-w&#9;C:\Documents and Settings\Jonathan\Application Data\pcouffin.sys<br>2008-01-22 15:45&#9;32&#9;----a-r&#9;C:\Documents and Settings\All Users\hash.dat<br>2005-06-12 23:02&#9;58,956&#9;----a-w&#9;C:\Documents and Settings\Jonathan\UninstallFW.exe<br>2004-08-16 17:22&#9;905,216&#9;----a-w&#9;C:\Documents and Settings\Jonathan\Rival Ball.exe<br>2001-12-15 03:08&#9;81,920&#9;----a-w&#9;C:\Documents and Settings\Jonathan\audiow32.dll<br>1998-12-01 03:36&#9;816,640&#9;----a-w&#9;C:\Program Files\i_view32.exe<br>2006-06-16 01:33&#9;233,472&#9;----a-w&#9;C:\Program Files\mozilla firefox\plugins\CrazyTalk4Native.dll<br>2006-05-25 23:43&#9;204,895&#9;----a-w&#9;C:\Program Files\mozilla firefox\plugins\ctdomemhelper.dll<br>2005-09-29 19:41&#9;77,824&#9;----a-w&#9;C:\Program Files\mozilla firefox\plugins\ctframeplayerobject.dll<br>2006-06-19 18:10&#9;426,081&#9;----a-w&#9;C:\Program Files\mozilla firefox\plugins\ctplayerobject.dll<br>2005-02-02 17:19&#9;458,752&#9;----a-w&#9;C:\Program Files\mozilla firefox\plugins\imagickrt.dll<br>2006-04-10 23:35&#9;139,264&#9;----a-w&#9;C:\Program Files\mozilla firefox\plugins\rlcontentclass.dll<br>2005-11-09 16:10&#9;204,800&#9;----a-w&#9;C:\Program Files\mozilla firefox\plugins\RLMusicPacker.dll<br>2005-11-09 16:42&#9;106,496&#9;----a-w&#9;C:\Program Files\mozilla firefox\plugins\RLMusicUnpacker.dll<br>2006-01-04 16:22&#9;212,992&#9;----a-w&#9;C:\Program Files\mozilla firefox\plugins\RLVoicePacker.dll<br>2006-01-04 16:21&#9;167,936&#9;----a-w&#9;C:\Program Files\mozilla firefox\plugins\RLVoiceUnpacker.dll<br>2004-10-08 05:17&#9;0&#9;--sha-w&#9;C:\WINDOWS\SMINST\HPCD.sys<br>.<br><br>(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br>.<br>*Note* empty entries & legit default entries are not shown <br>REGEDIT4<br><br>[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<br>"MoneyAgent"="C:\Program Files\Microsoft Money\System\mnyexpr.exe" [2003-06-18 200704]<br>"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-02-01 385024]<br>"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 15360]<br>"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-08-18 1832272]<br><br>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<br>"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 155648]<br>"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2008-05-16 13529088]<br>"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2004-10-29 180269]<br>"Motive SmartBridge"="C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe" [2005-08-24 442455]<br>"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-02-01 385024]<br>"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-02-19 267048]<br>"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 208952]<br>"MSPY2002"="C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [2004-04-02 59392]<br>"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-04-02 455168]<br>"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-04-02 455168]<br>"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2008-05-16 86016]<br>"Zone Labs Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2005-11-15 755472]<br>"SunJavaUpdateSched"="C:\Program Files\Java\jre6\bin\jusched.exe" [2008-09-18 144792]<br>"nwiz"="nwiz.exe" [2008-05-16 C:\WINDOWS\system32\nwiz.exe]<br><br>C:\Documents and Settings\Owner\Start Menu\Programs\Startup\<br>wkcalrem.LNK - C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkCalRem.exe [2002-07-11 24651]<br><br>C:\Documents and Settings\All Users\Start Menu\Programs\Startup\<br>Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-04-23 29696]<br>AT&T Self Support Tool.lnk - C:\Program Files\SBC Self Support Tool\bin\matcli.exe [2007-12-15 217088]<br>BTTray.lnk - C:\Program Files\DLink\Bluetooth Software\BTTray.exe [2003-10-29 503875]<br>EPSON Status Monitor 3 Environment Check.lnk - C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV03.EXE [1999-10-22 217600]<br>Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 65588]<br>QuickBooks Update Agent.lnk - C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2004-10-30 724992]<br>VPN Client.lnk - C:\WINDOWS\Installer\{B8221906-224A-4494-BB97-55FC63740019}\Icon3E5562ED7.ico [2005-02-16 6144]<br><br>[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]<br>"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]<br>2008-07-23 16:28 352256 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]<br>"vidc.DIV3"= DivXc32.dll<br>"vidc.DIV4"= DivXc32f.dll<br>"vidc.3ivx"= 3ivxVfWCodec.dll<br>"vidc.3iv2"= 3ivxVfWCodec.dll<br>"msacm.divxa32"= divxa32.acm<br>"VIDC.HFYU"= huffyuv.dll<br>"VIDC.i263"= i263_32.drv<br>"msacm.imc"= imc32.acm<br>"VIDC.VP31"= vp31vfw.dll<br><br>[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SBAMSvc]<br>@=""<br><br>[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TDSSserv.sys]<br>@=""<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]<br>"DisableMonitoring"=dword:00000001<br><br>[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]<br>"EnableFirewall"= 0 (0x0)<br><br>[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]<br>"C:\\Program Files\\Messenger\\msmsgs.exe"=<br>"C:\\WINDOWS\\system32\\sessmgr.exe"=<br>"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=<br>"C:\\Program Files\\xerox\\nwwia\\XrxFTPLt.exe"=<br>"C:\\Program Files\\LimeWire\\LimeWire.exe"=<br>"C:\\Program Files\\DNA\\btdna.exe"=<br>"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=<br>"C:\\Program Files\\iTunes\\iTunes.exe"=<br>"C:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"=<br>"C:\\Nexon\\Combat Arms\\NMService.exe"=<br>"C:\\Program Files\\FlashGet\\flashget.exe"=<br>"%windir%\\system32\\sessmgr.exe"=<br><br>[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]<br>"10418:TCP"= 10418:TCP:BitComet 10418 TCP<br>"10418:UDP"= 10418:UDP:BitComet 10418 UDP<br><br>R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-07-19 78416]<br>R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-07-19 20560]<br>R2 JavaQuickStarterService;Java Quick Starter;C:\Program Files\Java\jre6\bin\jqs.exe [2008-09-18 147456]<br>S2 UMAXPCLS;Print Port Scanner Driver;C:\WINDOWS\system32\DRIVERS\umaxpcls.sys [2001-08-17 22912]<br>S3 pmxscan;USB ScanModule V5.1 Driver;C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-04 15104]<br>S3 SBRE;SBRE;C:\WINDOWS\system32\drivers\SBREdrv.sys [ ]<br><br>[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\I]<br>\Shell\AutoRun\command - I:\LaunchU3.exe -a<br><br>[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0dd712dc-2d27-11dd-b7e2-000f3d058a67}]<br>\Shell\AutoRun\command - H:\LaunchU3.exe -a<br><br>[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{26940dc6-72c5-11dd-b7fa-000f3d058a67}]<br>\Shell\AutoRun\command - G:\LaunchU3.exe<br><br>[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2c196dea-6ea2-11dd-b7ed-000f3d058a67}]<br>\Shell\AutoRun\command - I:\LaunchU3.exe -a<br><br>[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8e27ff7c-a2ba-11dc-b796-000f3d058a67}]<br>\Shell\AutoRun\command - G:\Installer.exe<br>.<br>Contents of the 'Scheduled Tasks' folder<br><br>2008-09-11 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job<br>- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 15:57]<br><br>2008-09-20 C:\WINDOWS\Tasks\GoogleUpdateTaskUser.job<br>- C:\Documents and Settings\Jonathan\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-09-18 19:35]<br><br>2008-09-20 C:\WINDOWS\Tasks\MP Scheduled Scan.job<br>- C:\Program Files\Windows Defender\MpCmdRun.exe [2006-11-03 19:20]<br><br>2006-08-16 C:\WINDOWS\Tasks\Symantec NetDetect.job<br>- C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE [2003-08-13 18:38]<br>.<br>- - - - ORPHANS REMOVED - - - -<br><br>Notify-dimsntfy - (no file)<br><br>.<br>------- Supplementary Scan -------<br>.<br>FireFox -: Profile - C:\Documents and Settings\Jonathan\Application Data\Mozilla\Firefox\Profiles\p7y17xam.default\<br>FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.yahoo.com/<br>FF -: plugin - C:\Documents and Settings\All Users\Application Data\NexonUS\NGM\npNxGameUS.dll<br>FF -: plugin - C:\Documents and Settings\Jonathan\Local Settings\Application Data\Google\Update\1.2.131.11\npGoogleOneClick5.dll<br>FF -: plugin - C:\Program Files\Adobe\Acrobat 7.0\Reader\browser\nppdf32.dll<br>FF -: plugin - C:\Program Files\DNA\plugins\npbtdna.dll<br>FF -: plugin - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll<br>FF -: plugin - C:\Program Files\Java\jre6\bin\new_plugin\npdeploytk.dll<br>FF -: plugin - C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll<br>FF -: plugin - c:\Program Files\Microsoft Silverlight\npctrl.1.0.20926.0.dll<br>FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\npdeploytk.dll<br>FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\npff_gdm.dll<br>FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\npGoogleGadgetPluginFirefoxWin.dll<br>FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\npRLCT4Player.dll<br>FF -: plugin - C:\Program Files\Real\RealOne Player\Netscape6\nppl3260.dll<br>FF -: plugin - C:\Program Files\Real\RealOne Player\Netscape6\nprjplug.dll<br>FF -: plugin - C:\Program Files\Real\RealOne Player\Netscape6\nprpjplug.dll<br>FF -: plugin - C:\Program Files\Viewpoint\Viewpoint Media Player\npViewpoint.dll<br>FF -: plugin - C:\Program Files\Yahoo!\Shared\npYState.dll<br>FF -: plugin - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll<br>.<br><br>**************************************************************************<br><br>catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, &raquo;<A HREF="http://www.gmer.net" >www.gmer.net</A><br>Rootkit scan 2008-09-19 22:06:15<br>Windows 5.1.2600 Service Pack 2 NTFS<br><br>scanning hidden processes ... <br><br>scanning hidden autostart entries ...<br><br>scanning hidden files ... <br><br>scan completed successfully<br>hidden files: 0<br><br>**************************************************************************<br>.<br>------------------------ Other Running Processes ------------------------<br>.<br>C:\Program Files\Windows Defender\MsMpEng.exe<br>C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe<br>C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe<br>C:\Program Files\Alwil Software\Avast4\ashServ.exe<br>C:\WINDOWS\system32\BRSS01A.EXE<br>C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br>C:\Program Files\Bonjour\mDNSResponder.exe<br>C:\Program Files\DLink\Bluetooth Software\bin\btwdins.exe<br>C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe<br>C:\WINDOWS\system32\nvsvc32.exe<br>C:\WINDOWS\system32\PnkBstrA.exe<br>C:\WINDOWS\system32\wdfmgr.exe<br>C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe<br>C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe<br>C:\Program Files\Alwil Software\Avast4\ashWebSv.exe<br>C:\Program Files\iPod\bin\iPodService.exe<br>C:\WINDOWS\system32\wscntfy.exe<br>.<br>**************************************************************************<br>.<br>Completion time: 2008-09-19 22:18:24 - machine was rebooted [Jonathan]<br>ComboFix-quarantined-files.txt  2008-09-20 03:18:07<br><br>Pre-Run: 28,113,469,440 bytes free<br>Post-Run: 28,344,246,272 bytes free<br><br>343&#9;--- E O F ---&#9;2008-08-21 23:11:08<br><br>Here is the HIJACKTHIS LOG:<br><br>Logfile of Trend Micro HijackThis v2.0.2<br>Scan saved at 10:29:06 PM, on 9/19/2008<br>Platform: Windows XP SP2 (WinNT 5.01.2600)<br>MSIE: Internet Explorer v8.00 (8.00.6001.18241)<br>Boot mode: Normal<br><br>Running processes:<br>C:\WINDOWS\System32\smss.exe<br>C:\WINDOWS\system32\winlogon.exe<br>C:\WINDOWS\system32\services.exe<br>C:\WINDOWS\system32\lsass.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\Program Files\Windows Defender\MsMpEng.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe<br>C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe<br>C:\Program Files\Alwil Software\Avast4\ashServ.exe<br>C:\WINDOWS\system32\ctfmon.exe<br>C:\WINDOWS\system32\spoolsv.exe<br>C:\WINDOWS\system32\brss01a.exe<br>C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br>C:\Program Files\Bonjour\mDNSResponder.exe<br>C:\Program Files\DLink\Bluetooth Software\bin\btwdins.exe<br>C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe<br>C:\Program Files\Java\jre6\bin\jqs.exe<br>C:\WINDOWS\system32\nvsvc32.exe<br>C:\WINDOWS\system32\PnkBstrA.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe<br>C:\Program Files\Common Files\Real\Update_OB\realsched.exe<br>C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe<br>C:\Program Files\iTunes\iTunesHelper.exe<br>C:\Program Files\Java\jre6\bin\jusched.exe<br>C:\Documents and Settings\Jonathan\Local Settings\Application Data\Google\Update\GoogleUpdate.exe<br>C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe<br>C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe<br>C:\Program Files\Alwil Software\Avast4\ashWebSv.exe<br>C:\Program Files\iPod\bin\iPodService.exe<br>C:\WINDOWS\system32\wuauclt.exe<br>C:\WINDOWS\system32\wscntfy.exe<br>C:\WINDOWS\explorer.exe<br>C:\WINDOWS\system32\notepad.exe<br>C:\Program Files\Mozilla Firefox\firefox.exe<br>C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br><br>R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.yahoo.com<br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=69157" >go.microsoft.com/fwlink/?LinkId=69157</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = &raquo;<A HREF="http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q304&bd=presario&pf=desktop" >ie.redirect.hp.com/svs/rdr?TYPE=&middot;&middot;&middot;=desktop</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q304&bd=presario&pf=desktop" >ie.redirect.hp.com/svs/rdr?TYPE=&middot;&middot;&middot;=desktop</A><br>R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 127.0.0.1:12080<br>R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost;*.local;<br>R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)<br>O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)<br>O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll<br>O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\FlashGet\jccatch.dll<br>O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll<br>O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll<br>O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll<br>O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll<br>O2 - BHO: (no name) - {A7327C09-B521-4EDB-8509-7D2660C9EC98} - (no file)<br>O2 - BHO: (no name) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - (no file)<br>O2 - BHO: IE DOM Explorer - {CC7E636D-39AA-49b6-B511-65413DA137A1} - C:\Program Files\Internet Explorer Developer Toolbar\IEDevToolbar.dll<br>O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br>O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br>O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\FlashGet\getflash.dll<br>O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll<br>O3 - Toolbar: Developer Toolbar - {CC962137-2E78-4f94-975E-FC0C07DBD78F} - C:\Program Files\Internet Explorer Developer Toolbar\IEDevToolbar.dll<br>O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe<br>O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup<br>O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot<br>O4 - HKLM\..\Run: [nwiz] nwiz.exe /install<br>O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe<br>O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime<br>O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"<br>O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32<br>O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC<br>O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC<br>O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName<br>O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit<br>O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"<br>O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"<br>O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"<br>O4 - HKCU\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime<br>O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br>O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe<br>O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe<br>O4 - Global Startup: AT&T Self Support Tool.lnk = C:\Program Files\SBC Self Support Tool\bin\matcli.exe<br>O4 - Global Startup: BTTray.lnk = ?<br>O4 - Global Startup: EPSON Status Monitor 3 Environment Check.lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV03.EXE<br>O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE<br>O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe<br>O4 - Global Startup: VPN Client.lnk = ?<br>O8 - Extra context menu item: &Download All with FlashGet - C:\Program Files\FlashGet\jc_all.htm<br>O8 - Extra context menu item: &Download with FlashGet - C:\Program Files\FlashGet\jc_link.htm<br>O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000<br>O8 - Extra context menu item: &Igrave;&iacute;&frac14;&Oacute;&micro;&frac12;QQ&plusmn;&iacute;&Ccedil;&eacute; - C:\Program Files\QQ\AddEmotion.htm<br>O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll<br>O9 - Extra 'Tools' menuitem: &7 Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll<br>O9 - Extra button: Fill Id - {320AF880-6646-11D3-ABEE-C5DBF3571F47} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll<br>O9 - Extra 'Tools' menuitem: &5 Fill from Identity - {320AF880-6646-11D3-ABEE-C5DBF3571F47} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll<br>O9 - Extra button: Fill Pass - {320AF880-6646-11D3-ABEE-C5DBF3571F48} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll<br>O9 - Extra 'Tools' menuitem: &6 Fill from Passcard - {320AF880-6646-11D3-ABEE-C5DBF3571F48} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll<br>O9 - Extra button: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll<br>O9 - Extra 'Tools' menuitem: &8 Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll<br>O9 - Extra button: Go Fill - {320AF880-6646-11D3-ABEE-C5DBF3571F4A} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll<br>O9 - Extra 'Tools' menuitem: &Go && Fill from Passcard - {320AF880-6646-11D3-ABEE-C5DBF3571F4A} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll<br>O9 - Extra button: Login - {320AF880-6646-11D3-ABEE-C5DBF3571F4B} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll<br>O9 - Extra 'Tools' menuitem: &Login (Go, Fill, Submit) - {320AF880-6646-11D3-ABEE-C5DBF3571F4B} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll<br>O9 - Extra button: Options - {320AF880-6646-11D3-ABEE-C5DBF3571F4C} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll<br>O9 - Extra 'Tools' menuitem: &Options - {320AF880-6646-11D3-ABEE-C5DBF3571F4C} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll<br>O9 - Extra button: Identities - {45DB34C3-955C-11D3-ABEF-444553540000} - C:\Program Files\Siber Systems\AI RoboForm\Identities.exe<br>O9 - Extra 'Tools' menuitem: &3 Edit Identities - {45DB34C3-955C-11D3-ABEF-444553540000} - C:\Program Files\Siber Systems\AI RoboForm\Identities.exe<br>O9 - Extra button: Passcards - {45DB34C3-955C-11D3-ABEF-444553540001} - C:\Program Files\Siber Systems\AI RoboForm\Passcards.exe<br>O9 - Extra 'Tools' menuitem: &4 Edit Passcards - {45DB34C3-955C-11D3-ABEF-444553540001} - C:\Program Files\Siber Systems\AI RoboForm\Passcards.exe<br>O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll<br>O9 - Extra button: RF toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll<br>O9 - Extra 'Tools' menuitem: &9 Robo Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll<br>O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL<br>O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\DLink\Bluetooth Software\btsendto_ie.htm<br>O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\DLink\Bluetooth Software\btsendto_ie.htm<br>O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe<br>O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe<br>O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll<br>O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll<br>O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O15 - Trusted Zone: *.att.net<br>O15 - Trusted Zone: &raquo;<A HREF="http://*.att.net" >*.att.net</A><br>O15 - Trusted Zone: *.sbcglobal.net<br>O15 - Trusted Zone: &raquo;<A HREF="http://*.sbcglobal.net" >*.sbcglobal.net</A><br>O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - &raquo;<A HREF="http://go.microsoft.com/fwlink/?linkid=39204" >go.microsoft.com/fwlink/?linkid=39204</A><br>O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll<br>O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - &raquo;<A HREF="http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1093039999628" >v5.windowsupdate.microsoft.com/v&middot;&middot;&middot;39999628</A><br>O16 - DPF: {69EF49E5-FE46-4B92-B5FA-2193AB7A6B8A} (GameLauncher Control) - &raquo;<A HREF="http://www.acclaim.com/cabs/acclaim_v4.cab" >www.acclaim.com/cabs/acclaim_v4.cab</A><br>O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll<br>O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe<br>O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br>O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe<br>O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe<br>O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe<br>O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe<br>O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br>O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe<br>O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - C:\Program Files\DLink\Bluetooth Software\bin\btwdins.exe<br>O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe<br>O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe<br>O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br>O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br>O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe<br>O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe<br>O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - C:\Program Files\WinPcap\rpcapd.exe<br>O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe<br>O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe<br>O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe<br>O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe<br><br>--<br>End of file - 14483 bytes]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21140035</guid>
<pubDate>Fri, 19 Sep 2008 23:34:21 EDT</pubDate>
</item>

<item>
<title>Re: [Trojan or Vundo] HJT Log - Tdsserv HELP</title>
<link>http://www.dslreports.com/forum/remark,21139146</link>
<description><![CDATA[<A HREF="/useremail/u/555588"><b>LoPhatPhuud</b></A> : <b>First:</b><br>Please download Malwarebytes Anti-Malware</font></a></b> and save it to your desktop.<br><textarea name="code" class="text" cols=50 rows=10>http://www.besttechie.net/tools/mbam-setup.exe&#012;http://malwarebytes.gt500.org/mbam-setup.exe&#012;http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html&#012;</textarea><!--end code block--><ul><li>Make sure you are connected to the Internet.</li><li>Double-click on <b>Download_mbam-setup.exe</b> to install the application. <i>(If using Windows Vista, be sure to</font> "<A HREF="http://windowshelp.microsoft.com/Windows/en-US/Help/fb464905-31d5-4427-89a2-ed5322327fc21033.mspx">Run As Administrator</a>")</font></i></li><li>When the installation begins, follow the prompts and do not make any changes to default settings.</li><li>When installation has finished, make sure you leave both of these checked:<ul></li><li><b>Update Malwarebytes' Anti-Malware</b></li><li><b>Launch Malwarebytes' Anti-Malware</b></ul></li><li>Then click <b>Finish</b>.</li><li>MBAM will automatically start and you will be asked to update the program before performing a scan. If an update is found, the program will automatically update itself. Press the <b>OK</b> button to close that box and continue.</li><li><i>If you encounter any problems while downloading the updates, manually download them from</font> <A HREF="http://www.malwarebytes.org/mbam/database/mbam-rules.exe">here</font></a> and just double-click on mbam-rules.exe to install.</font></i></li><li>On the Scanner tab:<ul></li><li>Make sure the "<b>Perform Quick Acan</b>" option is selected.</li><li>Then click on the <b>Scan</b> button.</ul></li><li>The next screen will ask you to select the drives to scan. Leave <u>all the drives</u> selected and click on the <b>Start Scan</b> button.</li><li>The scan will begin and "<i>Scan in progress</font></i>" will show at the top. It may take some time to complete so please be patient.</li><li>When the scan is finished, a message box will say "<i>The scan completed successfully. Click 'Show Results' to display all objects found</font></i>".</li><li>Click <b>OK</b> to close the message box and continue with the removal process.</li><li>Back at the main Scanner screen, click on the <b>Show Results</b> button to see a list of any malware that was found.</li><li>Make sure that <b><i>everything is checked</font></i></b>, and click <b>Remove Selected</b>.</li><li>When removal is completed, a log report will open in Notepad and you may be prompted to restart your computer. <i>(see Note below)</font></i></li><li>The log is automatically saved and can be viewed by clicking the <b>Logs</b> tab in MBAM.</li><li>Copy and paste the contents of that report in your next reply and exit MBAM.</ul><i><b>Note</b>: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.</font></i></li><br><br><b>Second:</b><br>Download to your Desktop FixPolicies.exe, a self-extracting ZIP archive from here:<br>view plainprint?<br><textarea name="code" class="text" cols=50 rows=10> http://downloads.malwareremoval.com/BillCastner/FixPolicies.exe    &#012;</textarea><!--end code block-->http://downloads.malwareremoval.com/BillCastner/FixPolicies.exe<br>&#149; Double-click FixPolicies.exe<br>&#149; Click the "Install" button on the bottom toolbar of the box that will open.<br>&#149; The program will create a new Folder called FixPolicies,<br>&#149; Double-click to Open the new Folder, and then double-click the file within: Fix_Policies.cmd.<br>&#149; A black box will briefly appear and then close.<br><br><b>Third:</b><br>Download <b>Combofix</b> from any of the links below, and save it to your desktop.  For information regarding this download, please visit this webpage: &raquo;<A HREF="http://www.bleepingcomputer.com/combofix/how-to-use-combofix" >www.bleepingcomputer.com/combofi&middot;&middot;&middot;combofix</A><br><br><br><textarea name="code" class="text" cols=50 rows=10>http://download.bleepingcomputer.com/sUBs/ComboFix.exe&#012;http://www.forospyware.com/sUBs/ComboFix.exe&#012;http://subs.geekstogo.com/ComboFix.exe&#012;</textarea><!--end code block--><br><br><br>**Note:  It is important that it is saved directly to your desktop**</font><br><br>--------------------------------------------------------------------<br><br>1. Close any open browsers.<br><br>2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.<br><br>--------------------------------------------------------------------<br><br>Double click on <b>combofix.exe</b> & follow the prompts.<br><ul>When finished, it will produce a report for you. &#8226;Please post the <b>"C:\ComboFix.txt" </b>along with a <b>new HijackThis log</b> for further review.</ul></li><br>Note:<br>Do not mouseclick combofix's window while it's running. That may cause it to stall</font><br><br><br>Your next post should contain the logs from MBAM, ComboFix and a new HiJackThis log. Use more than one post if needed.<br><br><small>--<br>When angry count four; when very angry, swear.<br><br>Microsoft MVP/Consumer Security 2005-2008<br><br><A HREF="http://forum.gladiator-antivirus.com">Gladiator Security Forum</a></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21139146</guid>
<pubDate>Fri, 19 Sep 2008 20:04:50 EDT</pubDate>
</item>

<item>
<title>[Trojan or Vundo] HJT Log - Tdsserv HELP</title>
<link>http://www.dslreports.com/forum/remark,21121671</link>
<description><![CDATA[<A HREF="/useremail/u/1582066"><b>PPL</b></A> : Hi all,<br><br>First of all thanks to whoever is going to help me. My problem started 1 week ago, I had this background problem with "win32 virtumonde and privacy remover" thing. I forgot the name. I later installed some anti virus programs to delete it and it worked! But it also found some other viruses. Here is the main problem. I downloaded spyware doctor and scanned my computer, it found something called. "trojan.tdsserv" I don't know what it is. But of course, I deleted it. But it keeps coming back after every restart of my computer. I am not sure if the win32 virtumonde thing was fully removed. Or if this problem was the tojan or the vundo. I just put trojan because the virus said :"trojan.tdsserv"<br><br>Now, I followed most of the steps you gave us. I downloaded spybot and scanned. It found a couple of new stuff. I removed it. But it just couldn't get rid of the tdsserv. Adaware deleted some cookies but other than that, it didn't really do much. I downloaded Windows Defender and Malacious Software removal tool but nothing was detected. I couldn't do the www.eset.eu/online-scanner because my internet explorer was really slow. Firefox works way better. I finished the Trend Micro scan and it deleted some malware and grayware etc. <br><br>Here is my HiJackThis log:<br><br>Logfile of Trend Micro HijackThis v2.0.2<br>Scan saved at 7:23:11 PM, on 9/16/2008<br>Platform: Windows XP SP2 (WinNT 5.01.2600)<br>MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)<br>Boot mode: Normal<br><br>Running processes:<br>C:\WINDOWS\System32\smss.exe<br>C:\WINDOWS\system32\winlogon.exe<br>C:\WINDOWS\system32\services.exe<br>C:\WINDOWS\system32\lsass.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe<br>C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe<br>C:\Program Files\Alwil Software\Avast4\ashServ.exe<br>C:\WINDOWS\Explorer.EXE<br>C:\WINDOWS\system32\ctfmon.exe<br>C:\WINDOWS\system32\brsvc01a.exe<br>C:\WINDOWS\system32\spoolsv.exe<br>C:\WINDOWS\system32\brss01a.exe<br>C:\Program Files\Common Files\Real\Update_OB\realsched.exe<br>C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe<br>C:\Program Files\iTunes\iTunesHelper.exe<br>C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe<br>C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe<br>C:\Program Files\Windows Defender\MSASCui.exe<br>C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe<br>C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br>C:\Program Files\Bonjour\mDNSResponder.exe<br>C:\Program Files\DLink\Bluetooth Software\bin\btwdins.exe<br>C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe<br>C:\WINDOWS\system32\nvsvc32.exe<br>C:\WINDOWS\system32\PnkBstrA.exe<br>C:\Program Files\Sunbelt Software\VIPRE\SBAMSvc.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\Program Files\Viewpoint\Common\ViewpointService.exe<br>C:\WINDOWS\system32\ZoneLabs\vsmon.exe<br>C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe<br>C:\Program Files\Sunbelt Software\VIPRE\SBAMTray.exe<br>C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe<br>C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe<br>C:\Program Files\Alwil Software\Avast4\ashWebSv.exe<br>C:\Program Files\iPod\bin\iPodService.exe<br>C:\WINDOWS\system32\wuauclt.exe<br>C:\Program Files\Mozilla Firefox\firefox.exe<br>C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br><br>R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.yahoo.com<br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &raquo;<A HREF="http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q304&bd=presario&pf=desktop" >ie.redirect.hp.com/svs/rdr?TYPE=&middot;&middot;&middot;=desktop</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = &raquo;<A HREF="http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q304&bd=presario&pf=desktop" >ie.redirect.hp.com/svs/rdr?TYPE=&middot;&middot;&middot;=desktop</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &raquo;<A HREF="http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q304&bd=presario&pf=desktop" >ie.redirect.hp.com/svs/rdr?TYPE=&middot;&middot;&middot;=desktop</A><br>R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q304&bd=presario&pf=desktop" >ie.redirect.hp.com/svs/rdr?TYPE=&middot;&middot;&middot;=desktop</A><br>R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 127.0.0.1:12080<br>R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost;*.local;<br>R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll<br>O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll<br>O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll<br>O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\FlashGet\jccatch.dll<br>O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll<br>O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll<br>O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll<br>O2 - BHO: Viewpoint Toolbar BHO - {A7327C09-B521-4EDB-8509-7D2660C9EC98} - C:\Program Files\Viewpoint\Viewpoint Toolbar\3.8.0\ViewBarBHO.dll<br>O2 - BHO: (no name) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - (no file)<br>O2 - BHO: IE DOM Explorer - {CC7E636D-39AA-49b6-B511-65413DA137A1} - C:\Program Files\Internet Explorer Developer Toolbar\IEDevToolbar.dll<br>O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\FlashGet\getflash.dll<br>O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll<br>O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll<br>O3 - Toolbar: Developer Toolbar - {CC962137-2E78-4f94-975E-FC0C07DBD78F} - C:\Program Files\Internet Explorer Developer Toolbar\IEDevToolbar.dll<br>O3 - Toolbar: Viewpoint Toolbar - {F8AD5AA5-D966-4667-9DAF-2561D68B2012} - C:\Program Files\Common Files\Viewpoint\Toolbar Runtime\3.8.0\IEViewBar.dll<br>O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe<br>O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup<br>O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot<br>O4 - HKLM\..\Run: [nwiz] nwiz.exe /install<br>O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe<br>O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime<br>O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"<br>O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32<br>O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC<br>O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC<br>O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName<br>O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit<br>O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe<br>O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"<br>O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide<br>O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"<br>O4 - HKCU\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime<br>O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br>O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe<br>O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe<br>O4 - Global Startup: AT&T Self Support Tool.lnk = C:\Program Files\SBC Self Support Tool\bin\matcli.exe<br>O4 - Global Startup: BTTray.lnk = ?<br>O4 - Global Startup: EPSON Status Monitor 3 Environment Check.lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV03.EXE<br>O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE<br>O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe<br>O4 - Global Startup: VPN Client.lnk = ?<br>O8 - Extra context menu item: &Download All with FlashGet - C:\Program Files\FlashGet\jc_all.htm<br>O8 - Extra context menu item: &Download with FlashGet - C:\Program Files\FlashGet\jc_link.htm<br>O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000<br>O8 - Extra context menu item: &Igrave;&iacute;&frac14;&Oacute;&micro;&frac12;QQ&plusmn;&iacute;&Ccedil;&eacute; - C:\Program Files\QQ\AddEmotion.htm<br>O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll<br>O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll<br>O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll<br>O9 - Extra 'Tools' menuitem: &7 Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll<br>O9 - Extra button: Fill Id - {320AF880-6646-11D3-ABEE-C5DBF3571F47} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll<br>O9 - Extra 'Tools' menuitem: &5 Fill from Identity - {320AF880-6646-11D3-ABEE-C5DBF3571F47} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll<br>O9 - Extra button: Fill Pass - {320AF880-6646-11D3-ABEE-C5DBF3571F48} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll<br>O9 - Extra 'Tools' menuitem: &6 Fill from Passcard - {320AF880-6646-11D3-ABEE-C5DBF3571F48} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll<br>O9 - Extra button: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll<br>O9 - Extra 'Tools' menuitem: &8 Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll<br>O9 - Extra button: Go Fill - {320AF880-6646-11D3-ABEE-C5DBF3571F4A} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll<br>O9 - Extra 'Tools' menuitem: &Go && Fill from Passcard - {320AF880-6646-11D3-ABEE-C5DBF3571F4A} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll<br>O9 - Extra button: Login - {320AF880-6646-11D3-ABEE-C5DBF3571F4B} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll<br>O9 - Extra 'Tools' menuitem: &Login (Go, Fill, Submit) - {320AF880-6646-11D3-ABEE-C5DBF3571F4B} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll<br>O9 - Extra button: Options - {320AF880-6646-11D3-ABEE-C5DBF3571F4C} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll<br>O9 - Extra 'Tools' menuitem: &Options - {320AF880-6646-11D3-ABEE-C5DBF3571F4C} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll<br>O9 - Extra button: Identities - {45DB34C3-955C-11D3-ABEF-444553540000} - C:\Program Files\Siber Systems\AI RoboForm\Identities.exe<br>O9 - Extra 'Tools' menuitem: &3 Edit Identities - {45DB34C3-955C-11D3-ABEF-444553540000} - C:\Program Files\Siber Systems\AI RoboForm\Identities.exe<br>O9 - Extra button: Passcards - {45DB34C3-955C-11D3-ABEF-444553540001} - C:\Program Files\Siber Systems\AI RoboForm\Passcards.exe<br>O9 - Extra 'Tools' menuitem: &4 Edit Passcards - {45DB34C3-955C-11D3-ABEF-444553540001} - C:\Program Files\Siber Systems\AI RoboForm\Passcards.exe<br>O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll<br>O9 - Extra button: RF toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll<br>O9 - Extra 'Tools' menuitem: &9 Robo Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll<br>O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL<br>O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\DLink\Bluetooth Software\btsendto_ie.htm<br>O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\DLink\Bluetooth Software\btsendto_ie.htm<br>O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe<br>O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe<br>O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll<br>O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll<br>O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O15 - Trusted Zone: *.att.net<br>O15 - Trusted Zone: &raquo;<A HREF="http://*.att.net" >*.att.net</A><br>O15 - Trusted Zone: *.sbcglobal.net<br>O15 - Trusted Zone: &raquo;<A HREF="http://*.sbcglobal.net" >*.sbcglobal.net</A><br>O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - &raquo;<A HREF="http://go.microsoft.com/fwlink/?linkid=39204" >go.microsoft.com/fwlink/?linkid=39204</A><br>O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll<br>O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - &raquo;<A HREF="http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1093039999628" >v5.windowsupdate.microsoft.com/v&middot;&middot;&middot;39999628</A><br>O16 - DPF: {69EF49E5-FE46-4B92-B5FA-2193AB7A6B8A} (GameLauncher Control) - &raquo;<A HREF="http://www.acclaim.com/cabs/acclaim_v4.cab" >www.acclaim.com/cabs/acclaim_v4.cab</A><br>O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll<br>O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe<br>O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br>O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe<br>O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe<br>O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe<br>O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe<br>O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br>O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe<br>O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - C:\Program Files\DLink\Bluetooth Software\bin\btwdins.exe<br>O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe<br>O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe<br>O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br>O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe<br>O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe<br>O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - C:\Program Files\WinPcap\rpcapd.exe<br>O23 - Service: Sunbelt VIPRE Antivirus Service (SBAMSvc) - Sunbelt Software - C:\Program Files\Sunbelt Software\VIPRE\SBAMSvc.exe<br>O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe<br>O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe<br>O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe<br>O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe<br>O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe<br><br>--<br>End of file - 15131 bytes<br><br>P.S. I did not fix the stuff in the hijackthis. Just incase it was something good.. :huh:<br><br>Thanks Again!<br><br>PPL]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21121671</guid>
<pubDate>Tue, 16 Sep 2008 20:25:41 EDT</pubDate>
</item>

</channel>
</rss>
