<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>[Vundo] Vundo Removal in Security Cleanup</title>
<link>http://www.dslreports.com/forum/r21158438</link>
<description></description>
<language>en</language>
<pubDate>Tue, 15 Dec 2009 04:00:08 EDT</pubDate>
<lastBuildDate>Tue, 15 Dec 2009 04:00:08 EDT</lastBuildDate>

<item>
<title>Re: [Vundo] Vundo Removal</title>
<link>http://www.dslreports.com/forum/remark,21200152</link>
<description><![CDATA[<A HREF="/useremail/u/555588"><b>LoPhatPhuud</b></A> : That looks good. The only remaining step is cleanup and temporary files and folders. Of course, if there are issue outstanding that are not reflected in the most recent log(s), please let me know.<br><br><b>First:</b><br>Click <b>Start</b>, then click <b>Run</b>.<br>Enter into the command box that opens:  <b>combofix /u and then click [b]OK</b>.<br> <IMG SRC="http://i78.photobucket.com/albums/j116/amateur_photos/CFuninstall.png"> <br><br><b><br>Second:</b><br>Please download ATF Cleaner by Atribune.Double-click <b>ATF-Cleaner.exe</b> to run the program.<br><textarea name="code" class="text" cols=50 rows=10>http://www.atribune.org/ccount/click.php?id=1&#012;</textarea><!--end code block--><br>Under <b>Main</b> choose: <b>Select All</b><br>Click the <b>Empty Selected</b> button.<br></ul>[u]If you use Firefox browser[/u]Click <b>Firefox</b> at the top and choose: <b>Select All</b><br>Click the <b>Empty Selected</b> button.<br><b>NOTE:</b> If you would like to keep your saved passwords, please click <b>No</b> at the prompt.<br></ul>[u]If you use Opera browser[/u]Click <b>Opera</b> at the top and choose: <b>Select All</b><br>Click the <b>Empty Selected</b> button.<br><b>NOTE:</b> If you would like to keep your saved passwords, please click <b>No</b> at the prompt.<br></ul>Click <b>Exit</b> on the Main menu to close the program.<br>For <b>Technical Support</b>, double-click the e-mail address located at the bottom of each menu.<br><br><small>--<br>When angry count four; when very angry, swear.<br><br>Microsoft MVP/Consumer Security 2005-2008<br><br><A HREF="http://forum.gladiator-antivirus.com">Gladiator Security Forum</a></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21200152</guid>
<pubDate>Wed, 01 Oct 2008 18:25:55 EDT</pubDate>
</item>

<item>
<title>Re: [Vundo] Vundo Removal</title>
<link>http://www.dslreports.com/forum/remark,21194850</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : here be the log, yyyaarrr<br>Thank you for your time and direction!<br><br>ComboFix 08-09-25.03 - HP_Owner 2008-09-29 22:13:04.2 - NTFSx86<br>Microsoft Windows XP Home Edition  5.1.2600.2.1252.1.1033.18.604 [GMT -4:00]<br>Running from: C:\Documents and Settings\HP_Owner\Desktop\ComboFix.exe<br>Command switches used :: C:\Documents and Settings\HP_Owner\Desktop\CFScript.txt<br> * Created a new restore point<br><br>FILE ::<br>C:\WINDOWS\system32\drivers\cmsslzfv.dat<br>C:\WINDOWS\system32\drmsto.dll<br>.<br><br>(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br><br>C:\WINDOWS\system32\drivers\cmsslzfv.dat<br>C:\WINDOWS\system32\drmsto.dll<br><br>.<br>(((((((((((((((((((((((((((((((((((((((   Drivers/Services   )))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br><br>-------\Legacy_ILJNVYLF<br>-------\Service_iljnvylf<br><br>(((((((((((((((((((((((((   Files Created from 2008-09-01 to 2008-10-01  )))))))))))))))))))))))))))))))<br>.<br><br>2008-09-25 20:06 . 2008-09-25 20:06&#9;&#9;d--------&#9;C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}<br>2008-09-25 20:05 . 2008-09-25 20:05&#9;&#9;d--------&#9;C:\Program Files\Bonjour<br>2008-09-25 17:02 . 2008-09-25 17:02&#9;&#9;d--------&#9;C:\Program Files\Trend Micro<br>2008-09-25 16:17 . 2008-09-25 16:17&#9;&#9;d--------&#9;C:\Documents and Settings\HP_Owner\Application Data\Malwarebytes<br>2008-09-25 16:17 . 2008-09-10 00:04&#9;38,528&#9;--a------&#9;C:\WINDOWS\system32\drivers\mbamswissarmy.sys<br>2008-09-25 16:17 . 2008-09-10 00:03&#9;17,200&#9;--a------&#9;C:\WINDOWS\system32\drivers\mbam.sys<br>2008-09-25 16:12 . 2008-09-25 16:17&#9;&#9;d--------&#9;C:\Program Files\Malwarebytes' Anti-Malware<br>2008-09-25 16:12 . 2008-09-25 16:12&#9;&#9;d--------&#9;C:\Documents and Settings\All Users\Application Data\Malwarebytes<br>2008-09-23 22:40 . 2008-09-23 22:43&#9;&#9;d--------&#9;C:\HJT<br>2008-09-23 22:06 . 2008-09-23 22:28&#9;&#9;d--------&#9;C:\VundoFix Backups<br>2008-09-15 16:49 . 2008-09-25 16:21&#9;&#9;d--------&#9;C:\WINDOWS\system32\CatRoot_bak<br>2008-09-06 15:09 . 2008-09-06 15:09&#9;90,112&#9;--a------&#9;C:\WINDOWS\system32\QuickTimeVR.qtx<br>2008-09-06 15:09 . 2008-09-06 15:09&#9;57,344&#9;--a------&#9;C:\WINDOWS\system32\QuickTime.qts<br><br>.<br>((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br>2008-09-29 21:36&#9;---------&#9;d-----w&#9;C:\Program Files\Common Files\Symantec Shared<br>2008-09-26 00:06&#9;---------&#9;d-----w&#9;C:\Program Files\iTunes<br>2008-09-26 00:06&#9;---------&#9;d-----w&#9;C:\Program Files\iPod<br>2008-09-26 00:04&#9;---------&#9;d-----w&#9;C:\Program Files\QuickTime<br>2008-09-26 00:02&#9;---------&#9;d-----w&#9;C:\Program Files\Apple Software Update<br>2008-09-10 20:45&#9;32,000&#9;----a-w&#9;C:\WINDOWS\system32\drivers\usbaapl.sys<br>2008-08-16 18:33&#9;---------&#9;d-----w&#9;C:\Program Files\Microsoft Silverlight<br>2008-03-10 20:18&#9;232,116&#9;--sh--w&#9;C:\WINDOWS\repair\sismco.bak1<br>2008-03-12 07:04&#9;243,366&#9;--sh--w&#9;C:\WINDOWS\repair\sismco.bak2<br>2008-03-12 10:10&#9;230,818&#9;--sh--w&#9;C:\WINDOWS\repair\sismco.ini2<br>.<br><br>(((((((((((((((((((((((((((((   snapshot@2008-09-25_16.52.24.06   )))))))))))))))))))))))))))))))))))))))))<br>.<br>+ 2005-10-21 00:02:28&#9;163,328&#9;----a-w&#9;C:\WINDOWS\erdnt\subs\ERDNT.EXE<br>+ 2008-09-26 00:07:14&#9;102,400&#9;----a-r&#9;C:\WINDOWS\Installer\{41B9E2CF-0B3F-442A-B5B3-592A4A355634}\iTunesIco.exe<br>+ 2008-09-26 00:02:35&#9;27,136&#9;----a-r&#9;C:\WINDOWS\Installer\{6956856F-B6B3-4BE0-BA0B-8F495BE32033}\AppleSoftwareUpdateIco.exe<br>+ 2008-09-26 00:05:20&#9;86,016&#9;----a-r&#9;C:\WINDOWS\Installer\{8A25392D-C5D2-4E79-A2BD-C15DDC5B0959}\PrntWzrdIco.exe<br>+ 2008-08-29 14:18:58&#9;87,336&#9;----a-w&#9;C:\WINDOWS\system32\dns-sd.exe<br>+ 2008-08-29 13:53:50&#9;61,440&#9;----a-w&#9;C:\WINDOWS\system32\dnssd.dll<br>- 2006-09-19 18:44:04&#9;15,664&#9;----a-w&#9;C:\WINDOWS\system32\drivers\GEARAspiWDM.sys<br>+ 2008-04-17 17:12:54&#9;15,464&#9;----a-w&#9;C:\WINDOWS\system32\drivers\GEARAspiWDM.sys<br>+ 2008-04-17 17:12:54&#9;107,368&#9;-c--a-w&#9;C:\WINDOWS\system32\DRVSTORE\GEARAspiWD_D213663B6381F01E45A131159A9DEFE018321CB3\x86\GEARAspi.dll<br>+ 2008-04-17 17:12:54&#9;15,464&#9;-c--a-w&#9;C:\WINDOWS\system32\DRVSTORE\GEARAspiWD_D213663B6381F01E45A131159A9DEFE018321CB3\x86\GEARAspiWDM.sys<br>+ 2008-09-10 20:45:18&#9;32,000&#9;-c--a-w&#9;C:\WINDOWS\system32\DRVSTORE\usbaapl_97B931EF204A3188AFFD15A9A5337268E8B6F312\usbaapl.sys<br>- 2006-10-03 23:47:52&#9;109,360&#9;----a-w&#9;C:\WINDOWS\system32\GEARAspi.dll<br>+ 2008-04-17 17:12:54&#9;107,368&#9;----a-w&#9;C:\WINDOWS\system32\GEARAspi.dll<br>.<br>(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br>.<br>*Note* empty entries & legit default entries are not shown <br>REGEDIT4<br><br>[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<br>"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 15360]<br>"Aim6"="C:\Program Files\AIM6\aim6.exe" [2007-10-04 50528]<br>"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 1694208]<br><br>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<br>"SunJavaUpdateSched"="C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe" [2004-10-21 32881]<br>"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 52736]<br>"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2004-08-21 118784]<br>"HPHUPD06"="c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe" [2004-06-07 49152]<br>"HPHmon06"="C:\WINDOWS\system32\hphmon06.exe" [2004-06-07 659456]<br>"KBD"="C:\HP\KBD\KBD.EXE" [2003-02-11 61440]<br>"UpdateManager"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-08-19 110592]<br>"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2004-10-21 180269]<br>"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2004-04-14 233472]<br>"ccApp"="c:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2005-03-23 58992]<br>"PS2"="C:\WINDOWS\system32\ps2.exe" [2002-10-16 81920]<br>"LSBWatcher"="c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe" [2004-10-15 253952]<br>"USB Storage Toolbox"="C:\Program Files\USBToolbox\Res.EXE" [2002-01-15 118784]<br>"Lexmark X74-X75"="C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe" [2002-10-14 57344]<br>"Symantec NetDriver Monitor"="C:\PROGRA~1\SYMNET~1\SNDMon.exe" [2005-11-18 100056]<br>"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 155648]<br>"Dell AIO Printer A920"="C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe" [2003-06-02 270336]<br>"mxomssmenu"="C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe" [2007-07-13 169264]<br>"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-09-06 413696]<br>"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-09-10 289576]<br>"AlcxMonitor"="ALCXMNTR.EXE" [2004-09-07 C:\WINDOWS\ALCXMNTR.EXE]<br>"AGRSMMSG"="AGRSMMSG.exe" [2005-03-04 C:\WINDOWS\AGRSMMSG.exe]<br>"SoundMan"="SOUNDMAN.EXE" [2005-04-06 C:\WINDOWS\SOUNDMAN.EXE]<br>"AlcWzrd"="ALCWZRD.EXE" [2005-04-06 C:\WINDOWS\ALCWZRD.EXE]<br><br>[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]<br>"RunNarrator"="Narrator.exe" [2004-08-04 C:\WINDOWS\system32\narrator.exe]<br><br>C:\Documents and Settings\HP_Owner\Start Menu\Programs\Startup\<br>VZAccess Manager.lnk - C:\Program Files\Verizon Wireless\VZAccess Manager\VZAccess Manager.exe [2008-03-07 1733936]<br><br>C:\Documents and Settings\All Users\Start Menu\Programs\Startup\<br>Adobe Gamma Loader.exe.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-10-06 113664]<br>HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2004-05-29 241664]<br>Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 65588]<br>SpySubtract.lnk - C:\Program Files\interMute\SpySubtract\SpySub.exe [2005-11-18 1187840]<br>Updates from HP.lnk - C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe [2004-10-21 45056]<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\security center]<br>"AntiVirusDisableNotify"=dword:00000001<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]<br>"DisableMonitoring"=dword:00000001<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]<br>"DisableMonitoring"=dword:00000001<br><br>[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]<br>"EnableFirewall"= 0 (0x0)<br><br>[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]<br>"%windir%\\system32\\sessmgr.exe"=<br>"C:\\Program Files\\Updates from HP\\309731\\Program\\Updates from HP.exe"=<br>"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"=<br>"C:\\WINDOWS\\system32\\LEXPPS.EXE"=<br>"C:\\Program Files\\interMute\\SpySubtract\\SpySub.exe"=<br>"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=<br>"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=<br>"C:\\Program Files\\iTunes\\iTunes.exe"=<br><br>R2 Maxtor Sync Service;Maxtor Service;C:\Program Files\Maxtor\Sync\SyncServices.exe [2007-07-13 156976]<br>R2 Viewpoint Manager Service;Viewpoint Manager Service;C:\Program Files\Viewpoint\Common\ViewpointService.exe [2007-01-04 24652]<br><br>[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{638618a6-8510-11d9-8530-806d6172696f}]<br>\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480<br><br>[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a550bec5-bd77-11dc-9cf8-0011d82263ce}]<br>\Shell\AutoRun\command - .\Encryption Tool\MaxtorEncryption.exe<br>.<br>Contents of the 'Scheduled Tasks' folder<br>.<br><br>**************************************************************************<br><br>catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, &raquo;<A HREF="http://www.gmer.net" >www.gmer.net</A><br>Rootkit scan 2008-09-30 20:04:29<br>Windows 5.1.2600 Service Pack 2 NTFS<br><br>scanning hidden processes ... <br><br>scanning hidden autostart entries ...<br><br>scanning hidden files ... <br><br>scan completed successfully<br>hidden files: 0<br><br>**************************************************************************<br>.<br>------------------------ Other Running Processes ------------------------<br>.<br>C:\Program Files\Common Files\Symantec Shared\CCPROXY.EXE<br>C:\Program Files\Common Files\Symantec Shared\CCSETMGR.EXE<br>C:\Program Files\Norton AntiVirus\NAVAPSVC.EXE<br>C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe<br>C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe<br>C:\Program Files\Common Files\Symantec Shared\CCEVTMGR.EXE<br>C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe<br>C:\WINDOWS\system32\LEXBCES.EXE<br>C:\WINDOWS\system32\LEXPPS.EXE<br>C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br>C:\Program Files\Bonjour\mDNSResponder.exe<br>C:\Program Files\Common Files\LightScribe\LSSrvc.exe<br>C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE<br>C:\WINDOWS\system32\wdfmgr.exe<br>C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WLService.exe<br>C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WUSB54GC.exe<br>C:\Program Files\Common Files\Symantec Shared\Security Center\symwsc.exe<br>C:\Program Files\Canon\CAL\CALMAIN.exe<br>C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe<br>C:\WINDOWS\system32\wscntfy.exe<br>C:\Program Files\Lexmark X74-X75\lxbbbmon.exe<br>C:\Program Files\Dell AIO Printer A920\dlbkbmon.exe<br>C:\Program Files\iPod\bin\iPodService.exe<br>C:\ComboFix\pv.cfexe<br>.<br>**************************************************************************<br>.<br>Completion time: 2008-09-30 20:12:27 - machine was rebooted<br>ComboFix-quarantined-files.txt  2008-10-01 00:12:22<br>ComboFix2.txt  2008-09-25 20:52:59<br><br>Pre-Run: 40,040,091,648 bytes free<br>Post-Run: 39,957,225,472 bytes free<br><br>178&#9;--- E O F ---&#9;2008-09-25 20:09:47]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21194850</guid>
<pubDate>Tue, 30 Sep 2008 20:14:40 EDT</pubDate>
</item>

<item>
<title>Re: [Vundo] Vundo Removal</title>
<link>http://www.dslreports.com/forum/remark,21182451</link>
<description><![CDATA[<A HREF="/useremail/u/555588"><b>LoPhatPhuud</b></A> : 1. Close any open browsers.<br><br>2. Open <b>notepad</b> and copy/paste the text in the quotebox below into it:<br><br> <blockquote><small>quote:</small><hr>KillAll::<br><br>File::<br>C:\WINDOWS\system32\drmsto.dll<br>C:\WINDOWS\system32\drivers\cmsslzfv.dat<br><br>Registry::<br>[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{338F763F-46ED-4BAC-B6DD-6DAD90D7ED60}]<br>Driver::<br>iljnvylf<br><br><hr></blockquote><br><br>Save this as <b>CFScript.txt</b>, in the same location as ComboFix.exe<br><br> <IMG SRC="http://users.pandora.be/bluepatchy/miekiemoes/images/CFScript.gif"> <br><br>Refering to the picture above, drag CFScript into ComboFix.exe<br><br>When finished, it shall produce a log for you at <b>"C:\ComboFix.txt"</b><br><br>[color=blue]Note:<br>Do not mouseclick combofix's window whilst it's running. That may cause it to stall[/color]<br><small>--<br>When angry count four; when very angry, swear.<br><br>Microsoft MVP/Consumer Security 2005-2008<br><br><A HREF="http://forum.gladiator-antivirus.com">Gladiator Security Forum</a></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21182451</guid>
<pubDate>Sun, 28 Sep 2008 16:09:50 EDT</pubDate>
</item>

<item>
<title>Re: [Vundo] Vundo Removal</title>
<link>http://www.dslreports.com/forum/remark,21168478</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Thanks a truckload! <br><br>Here's the C:\ComboFix.txt<br><br>ComboFix 08-09-25.03 - HP_Owner 2008-09-25 16:40:51.1 - NTFSx86<br>Microsoft Windows XP Home Edition  5.1.2600.2.1252.1.1033.18.591 [GMT -4:00]<br>Running from: C:\Documents and Settings\HP_Owner\Desktop\ComboFix.exe<br> * Created a new restore point<br>.<br><br>(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br><br>C:\WINDOWS\system32\ahibhguw.ini<br>C:\WINDOWS\system32\aytllhlc.ini<br>C:\WINDOWS\system32\cyhajndr.ini<br>C:\WINDOWS\system32\djwgqtos.ini<br>C:\WINDOWS\system32\doayogwh.ini<br>C:\WINDOWS\system32\drmsto.1<br>C:\WINDOWS\system32\feyxbfqg.ini<br>C:\WINDOWS\system32\fflomesv.ini<br>C:\WINDOWS\system32\fvemsgxj.ini<br>C:\WINDOWS\system32\iaenjcan.dll<br>C:\WINDOWS\system32\ivnxnuev.ini<br>C:\WINDOWS\system32\kooahsmd.ini<br>C:\WINDOWS\system32\lhpwrags.ini<br>C:\WINDOWS\system32\lpwejaic.ini<br>C:\WINDOWS\system32\lsvvhdqk.ini<br>C:\WINDOWS\system32\lubcrayv.ini<br>C:\WINDOWS\system32\pgnaveoy.ini<br>C:\WINDOWS\system32\qafebvds.ini<br>C:\WINDOWS\system32\qqtfoajx.ini<br>C:\WINDOWS\system32\rcuwjafa.ini<br>C:\WINDOWS\system32\savpfbis.ini<br>C:\WINDOWS\system32\sylyopya.ini<br>C:\WINDOWS\system32\tepglgqv.ini<br>C:\WINDOWS\system32\tnmuodwe.ini<br>C:\WINDOWS\system32\txxiyjbt.ini<br>C:\WINDOWS\system32\ucoyaodb.ini<br>C:\WINDOWS\system32\ueubepbd.ini<br>C:\WINDOWS\system32\vgklgvid.ini<br>C:\WINDOWS\system32\vmgmcgbp.ini<br>C:\WINDOWS\system32\vuwrbhfj.ini<br>C:\WINDOWS\system32\yjmlfdml.ini<br>C:\WINDOWS\system32\ykhxoabb.ini<br>C:\WINDOWS\system32\yvnmojjx.ini<br>H:\Autorun.inf<br>C:\WINDOWS\system32\drmsto.dll . . . . failed to delete<br><br>.<br>(((((((((((((((((((((((((   Files Created from 2008-08-25 to 2008-09-25  )))))))))))))))))))))))))))))))<br>.<br><br>2008-09-25 16:17 . 2008-09-25 16:17&#9;&#9;d--------&#9;C:\Documents and Settings\HP_Owner\Application Data\Malwarebytes<br>2008-09-25 16:17 . 2008-09-10 00:04&#9;38,528&#9;--a------&#9;C:\WINDOWS\system32\drivers\mbamswissarmy.sys<br>2008-09-25 16:17 . 2008-09-10 00:03&#9;17,200&#9;--a------&#9;C:\WINDOWS\system32\drivers\mbam.sys<br>2008-09-25 16:12 . 2008-09-25 16:17&#9;&#9;d--------&#9;C:\Program Files\Malwarebytes' Anti-Malware<br>2008-09-25 16:12 . 2008-09-25 16:12&#9;&#9;d--------&#9;C:\Documents and Settings\All Users\Application Data\Malwarebytes<br>2008-09-23 22:40 . 2008-09-23 22:43&#9;&#9;d--------&#9;C:\HJT<br>2008-09-23 22:06 . 2008-09-23 22:28&#9;&#9;d--------&#9;C:\VundoFix Backups<br>2008-09-15 16:49 . 2008-09-25 16:21&#9;&#9;d--------&#9;C:\WINDOWS\system32\CatRoot_bak<br><br>.<br>((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br>2008-09-25 20:43&#9;---------&#9;d-----w&#9;C:\Program Files\Common Files\Symantec Shared<br>2008-08-16 18:33&#9;---------&#9;d-----w&#9;C:\Program Files\Microsoft Silverlight<br>2008-07-28 18:53&#9;---------&#9;d-----w&#9;C:\Documents and Settings\HP_Owner\Application Data\AdobeUM<br>2008-03-10 20:18&#9;232,116&#9;--sh--w&#9;C:\WINDOWS\repair\sismco.bak1<br>2008-03-12 07:04&#9;243,366&#9;--sh--w&#9;C:\WINDOWS\repair\sismco.bak2<br>2008-03-12 10:10&#9;230,818&#9;--sh--w&#9;C:\WINDOWS\repair\sismco.ini2<br>.<br><br>(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br>.<br>*Note* empty entries & legit default entries are not shown <br>REGEDIT4<br><br>[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{338F763F-46ED-4BAC-B6DD-6DAD90D7ED60}]<br>2008-07-18 00:27&#9;101632&#9;--a------&#9;C:\WINDOWS\system32\drmsto.dll<br><br>[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<br>"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 15360]<br>"Aim6"="C:\Program Files\AIM6\aim6.exe" [2007-10-04 50528]<br>"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 1694208]<br><br>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<br>"SunJavaUpdateSched"="C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe" [2004-10-21 32881]<br>"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 52736]<br>"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2004-08-21 118784]<br>"HPHUPD06"="c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe" [2004-06-07 49152]<br>"HPHmon06"="C:\WINDOWS\system32\hphmon06.exe" [2004-06-07 659456]<br>"KBD"="C:\HP\KBD\KBD.EXE" [2003-02-11 61440]<br>"UpdateManager"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-08-19 110592]<br>"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2004-10-21 180269]<br>"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2004-04-14 233472]<br>"ccApp"="c:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2005-03-23 58992]<br>"PS2"="C:\WINDOWS\system32\ps2.exe" [2002-10-16 81920]<br>"LSBWatcher"="c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe" [2004-10-15 253952]<br>"USB Storage Toolbox"="C:\Program Files\USBToolbox\Res.EXE" [2002-01-15 118784]<br>"Lexmark X74-X75"="C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe" [2002-10-14 57344]<br>"Symantec NetDriver Monitor"="C:\PROGRA~1\SYMNET~1\SNDMon.exe" [2005-11-18 100056]<br>"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 155648]<br>"Dell AIO Printer A920"="C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe" [2003-06-02 270336]<br>"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-12-11 286720]<br>"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-12-11 267048]<br>"mxomssmenu"="C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe" [2007-07-13 169264]<br>"AlcxMonitor"="ALCXMNTR.EXE" [2004-09-07 C:\WINDOWS\ALCXMNTR.EXE]<br>"AGRSMMSG"="AGRSMMSG.exe" [2005-03-04 C:\WINDOWS\AGRSMMSG.exe]<br>"SoundMan"="SOUNDMAN.EXE" [2005-04-06 C:\WINDOWS\SOUNDMAN.EXE]<br>"AlcWzrd"="ALCWZRD.EXE" [2005-04-06 C:\WINDOWS\ALCWZRD.EXE]<br><br>[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]<br>"RunNarrator"="Narrator.exe" [2004-08-04 C:\WINDOWS\system32\narrator.exe]<br><br>C:\Documents and Settings\HP_Owner\Start Menu\Programs\Startup\<br>VZAccess Manager.lnk - C:\Program Files\Verizon Wireless\VZAccess Manager\VZAccess Manager.exe [2008-03-07 1733936]<br><br>C:\Documents and Settings\All Users\Start Menu\Programs\Startup\<br>Adobe Gamma Loader.exe.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-10-06 113664]<br>HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2004-05-29 241664]<br>Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 65588]<br>SpySubtract.lnk - C:\Program Files\interMute\SpySubtract\SpySub.exe [2005-11-18 1187840]<br>Updates from HP.lnk - C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe [2004-10-21 45056]<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\security center]<br>"AntiVirusDisableNotify"=dword:00000001<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]<br>"DisableMonitoring"=dword:00000001<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]<br>"DisableMonitoring"=dword:00000001<br><br>[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]<br>"EnableFirewall"= 0 (0x0)<br><br>[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]<br>"%windir%\\system32\\sessmgr.exe"=<br>"C:\\Program Files\\Updates from HP\\309731\\Program\\Updates from HP.exe"=<br>"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"=<br>"C:\\WINDOWS\\system32\\LEXPPS.EXE"=<br>"C:\\Program Files\\interMute\\SpySubtract\\SpySub.exe"=<br>"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=<br>"C:\\Program Files\\iTunes\\iTunes.exe"=<br><br>R0 iljnvylf;iljnvylf;C:\WINDOWS\system32\drivers\cmsslzfv.dat [ ]<br>R2 Maxtor Sync Service;Maxtor Service;C:\Program Files\Maxtor\Sync\SyncServices.exe [2007-07-13 156976]<br>R2 Viewpoint Manager Service;Viewpoint Manager Service;C:\Program Files\Viewpoint\Common\ViewpointService.exe [2007-01-04 24652]<br><br>[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{638618a6-8510-11d9-8530-806d6172696f}]<br>\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480<br><br>[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a550bec5-bd77-11dc-9cf8-0011d82263ce}]<br>\Shell\AutoRun\command - .\Encryption Tool\MaxtorEncryption.exe<br>.<br>Contents of the 'Scheduled Tasks' folder<br>.<br>- - - - ORPHANS REMOVED - - - -<br><br>BHO-{A9ACDAF2-6345-41EF-8E67-18D09AB619F8} - C:\WINDOWS\repair\ocmsis.dll<br>HKLM-Run-VTTimer - VTTimer.exe<br>ShellExecuteHooks-{FA010552-4A27-4cb1-A1BB-3E2D697F1639} - (no file)<br>Notify-ocmsis - C:\WINDOWS\repair\ocmsis.dll<br><br>.<br>------- Supplementary Scan -------<br>.<br>FireFox -: Profile - C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\k6tj05v1.default\<br>FireFox -: prefs.js - STARTUP.HOMEPAGE - www.google.com<br>FF -: plugin - C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\k6tj05v1.default\extensions\moveplayer@movenetworks.com\platform\WINNT_x86-msvc\plugins\npmnqmp07076007.dll<br>FF -: plugin - C:\Program Files\Adobe\Acrobat 6.0\Reader\browser\nppdf32.dll<br>FF -: plugin - C:\Program Files\DivX\DivX Content Uploader\npUpload.dll<br>FF -: plugin - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll<br>FF -: plugin - C:\Program Files\Java\j2re1.4.2_03\bin\NPJava11.dll<br>FF -: plugin - C:\Program Files\Java\j2re1.4.2_03\bin\NPJava12.dll<br>FF -: plugin - C:\Program Files\Java\j2re1.4.2_03\bin\NPJava13.dll<br>FF -: plugin - C:\Program Files\Java\j2re1.4.2_03\bin\NPJava14.dll<br>FF -: plugin - C:\Program Files\Java\j2re1.4.2_03\bin\NPJava32.dll<br>FF -: plugin - C:\Program Files\Java\j2re1.4.2_03\bin\NPJPI142_03.dll<br>FF -: plugin - C:\Program Files\Java\j2re1.4.2_03\bin\NPOJI610.dll<br>FF -: plugin - c:\Program Files\Microsoft Silverlight\2.0.30523.8\npctrl.dll<br>FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\NPAdbESD.dll<br>FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\NPJinit13122.dll<br>FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\npunagi2.dll<br>FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\NPUploader.dll<br>FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\npViewpoint.dll<br>FF -: plugin - C:\Program Files\Real\RhapsodyPlayerEngine\nprhapengine.dll<br>FF -: plugin - C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll<br>.<br><br>**************************************************************************<br><br>catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, &raquo;<A HREF="http://www.gmer.net" >www.gmer.net</A><br>Rootkit scan 2008-09-25 16:46:32<br>Windows 5.1.2600 Service Pack 2 NTFS<br><br>scanning hidden processes ... <br><br>scanning hidden autostart entries ...<br><br>scanning hidden files ... <br><br>scan completed successfully<br>hidden files: 0<br><br>**************************************************************************<br><br>[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\iljnvylf]<br>"ImagePath"="system32\drivers\cmsslzfv.dat"<br>.<br>------------------------ Other Running Processes ------------------------<br>.<br>C:\Program Files\Common Files\Symantec Shared\CCPROXY.EXE<br>C:\Program Files\Common Files\Symantec Shared\CCSETMGR.EXE<br>C:\Program Files\Norton AntiVirus\NAVAPSVC.EXE<br>C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe<br>C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe<br>C:\Program Files\Common Files\Symantec Shared\CCEVTMGR.EXE<br>C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe<br>C:\WINDOWS\system32\LEXBCES.EXE<br>C:\WINDOWS\system32\LEXPPS.EXE<br>C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br>C:\Program Files\Common Files\LightScribe\LSSrvc.exe<br>C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE<br>C:\WINDOWS\system32\wdfmgr.exe<br>C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WLService.exe<br>C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WUSB54GC.exe<br>C:\Program Files\Common Files\Symantec Shared\Security Center\symwsc.exe<br>C:\Program Files\Lexmark X74-X75\lxbbbmon.exe<br>C:\Program Files\Dell AIO Printer A920\dlbkbmon.exe<br>C:\Program Files\Canon\CAL\CALMAIN.exe<br>C:\Program Files\iPod\bin\iPodService.exe<br>C:\Program Files\AIM6\aolsoftware.exe<br>C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe<br>C:\WINDOWS\system32\wscntfy.exe<br>C:\Program Files\Internet Explorer\IEXPLORE.EXE<br>C:\Program Files\Internet Explorer\IEXPLORE.EXE<br>.<br>**************************************************************************<br>.<br>Completion time: 2008-09-25 16:52:57 - machine was rebooted<br>ComboFix-quarantined-files.txt  2008-09-25 20:52:51<br><br>Pre-Run: 39,411,294,208 bytes free<br>Post-Run: 39,518,363,648 bytes free<br><br>212&#9;--- E O F ---&#9;2008-09-25 20:09:47<br><br>Here is the HijackThis log after following, to the letter, your great instructions:<br><br>Logfile of Trend Micro HijackThis v2.0.2<br>Scan saved at 5:02:52 PM, on 9/25/2008<br>Platform: Windows XP SP2 (WinNT 5.01.2600)<br>MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)<br>Boot mode: Normal<br><br>Running processes:<br>C:\WINDOWS\System32\smss.exe<br>C:\WINDOWS\system32\winlogon.exe<br>C:\WINDOWS\system32\services.exe<br>C:\WINDOWS\system32\lsass.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\WINDOWS\System32\svchost.exe<br>c:\Program Files\Common Files\Symantec Shared\ccProxy.exe<br>c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe<br>c:\Program Files\Norton AntiVirus\navapsvc.exe<br>c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe<br>c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe<br>c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe<br>C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe<br>C:\WINDOWS\system32\LEXBCES.EXE<br>C:\WINDOWS\system32\LEXPPS.EXE<br>C:\WINDOWS\system32\spoolsv.exe<br>C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br>c:\Program Files\Common Files\LightScribe\LSSrvc.exe<br>C:\Program Files\Maxtor\Sync\SyncServices.exe<br>C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe<br>C:\windows\system\hpsysdrv.exe<br>C:\WINDOWS\system32\hkcmd.exe<br>C:\HP\KBD\KBD.EXE<br>C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE<br>C:\Program Files\Common Files\Real\Update_OB\realsched.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\Program Files\Common Files\Symantec Shared\ccApp.exe<br>C:\Program Files\Viewpoint\Common\ViewpointService.exe<br>C:\WINDOWS\AGRSMMSG.exe<br>C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WLService.exe<br>C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WUSB54GC.exe<br>c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe<br>C:\hp\drivers\hplsbwatcher\lsburnwatcher.exe<br>C:\WINDOWS\SOUNDMAN.EXE<br>C:\WINDOWS\ALCWZRD.EXE<br>C:\Program Files\USBToolbox\Res.EXE<br>C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe<br>C:\Program Files\Lexmark X74-X75\lxbbbmon.exe<br>C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe<br>C:\Program Files\Dell AIO Printer A920\dlbkbmon.exe<br>C:\Program Files\QuickTime\QTTask.exe<br>C:\Program Files\iTunes\iTunesHelper.exe<br>C:\WINDOWS\system32\ctfmon.exe<br>C:\Program Files\Messenger\msmsgs.exe<br>C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe<br>C:\Program Files\interMute\SpySubtract\SpySub.exe<br>C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe<br>C:\Program Files\Canon\CAL\CALMAIN.exe<br>C:\Program Files\iPod\bin\iPodService.exe<br>C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe<br>C:\WINDOWS\system32\wscntfy.exe<br>C:\WINDOWS\system32\wuauclt.exe<br>C:\WINDOWS\explorer.exe<br>C:\Program Files\Mozilla Firefox\firefox.exe<br>C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=69157" >go.microsoft.com/fwlink/?LinkId=69157</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = &raquo;<A HREF="http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=pavilion&pf=desktop" >ie.redirect.hp.com/svs/rdr?TYPE=&middot;&middot;&middot;=desktop</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q105&bd=pavilion&pf=desktop" >ie.redirect.hp.com/svs/rdr?TYPE=&middot;&middot;&middot;=desktop</A><br>R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = <br>O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll<br>O2 - BHO: (no name) - {338F763F-46ED-4BAC-B6DD-6DAD90D7ED60} - C:\WINDOWS\system32\drmsto.dll<br>O2 - BHO: Web assistant - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - c:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll<br>O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton AntiVirus\NavShExt.dll<br>O3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll<br>O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NavShExt.dll<br>O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe<br>O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe<br>O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe<br>O4 - HKLM\..\Run: [HPHUPD06] c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe<br>O4 - HKLM\..\Run: [HPHmon06] C:\WINDOWS\system32\hphmon06.exe<br>O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE<br>O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r<br>O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot<br>O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE<br>O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE<br>O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"<br>O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe<br>O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe<br>O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe<br>O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE<br>O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE<br>O4 - HKLM\..\Run: [USB Storage Toolbox] C:\Program Files\USBToolbox\Res.EXE<br>O4 - HKLM\..\Run: [Lexmark X74-X75] "C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe"<br>O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer<br>O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe<br>O4 - HKLM\..\Run: [Dell AIO Printer A920] "C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe"<br>O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime<br>O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"<br>O4 - HKLM\..\Run: [mxomssmenu] "C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe"<br>O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br>O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp<br>O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background<br>O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')<br>O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')<br>O4 - Startup: VZAccess Manager.lnk = C:\Program Files\Verizon Wireless\VZAccess Manager\VZAccess Manager.exe<br>O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe<br>O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe<br>O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE<br>O4 - Global Startup: SpySubtract.lnk = C:\Program Files\interMute\SpySubtract\SpySub.exe<br>O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe<br>O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000<br>O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll<br>O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll<br>O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O16 - DPF: {00C7C2A0-8B82-11D1-8B57-00A0C98CD92B} (ActiveReports Viewer) - &raquo;<A HREF="http://www.ncbrightideas.com/arviewer.cab" >www.ncbrightideas.com/arviewer.cab</A><br>O16 - DPF: {0D623637-DBA2-11D1-B5DF-0060976089D0} (True DBGrid 7  Control) - &raquo;<A HREF="http://www.ncbrightideas.com/tdbg7.cab" >www.ncbrightideas.com/tdbg7.cab</A><br>O16 - DPF: {0D6236AB-DBA2-11D1-B5DF-0060976089D0} (ComponentOne XArrayDB Object) - &raquo;<A HREF="http://www.ncbrightideas.com/xadb7.cab" >www.ncbrightideas.com/xadb7.cab</A><br>O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - &raquo;<A HREF="http://web1.shutterfly.com/downloads/Uploader.cab" >web1.shutterfly.com/downloads/Uploader.cab</A><br>O16 - DPF: {CAFECAFE-0013-0001-0022-ABCDEFABCDEF} (JInitiator 1.3.1.22) - &raquo;<small>https</small>://<A HREF="https://accessncwise.wcpss.net/forms/jinitiator/jinit.exe">accessncwise.wcpss.net/forms/jin&middot;&middot;&middot;init.exe</A><br>O16 - DPF: {CE74A05D-ED12-473A-97F8-85FB0E2F479F} (dlControl.UserControl1) - &raquo;<A HREF="http://web1.nugs.net/dev/dlControl.CAB" >web1.nugs.net/dev/dlControl.CAB</A><br>O16 - DPF: {E008A543-CEFB-4559-912F-C27C2B89F13B} (Domino Web Access 7 Control) - &raquo;<small>https</small>://<A HREF="https://domino5.wcpss.net/dwa7W.cab">domino5.wcpss.net/dwa7W.cab</A><br>O16 - DPF: {FA3662C3-B8E8-11D6-A667-0010B556D978} - &raquo;<A HREF="http://cdn.digitalcity.com/_media/dalaillama/ampx.cab" >cdn.digitalcity.com/_media/dalai&middot;&middot;&middot;ampx.cab</A><br>O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe<br>O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br>O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe<br>O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe<br>O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccProxy.exe<br>O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe<br>O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe<br>O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe<br>O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br>O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE<br>O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unknown owner - c:\Program Files\Common Files\LightScribe\LSSrvc.exe<br>O23 - Service: Maxtor Service (Maxtor Sync Service) - Seagate Technology LLC - C:\Program Files\Maxtor\Sync\SyncServices.exe<br>O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton AntiVirus\navapsvc.exe<br>O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - c:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe<br>O23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton AntiVirus\SAVScan.exe<br>O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe<br>O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe<br>O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe<br>O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe<br>O23 - Service: WUSB54GCSVC - GEMTEKS - C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WLService.exe<br><br>--<br>End of file - 11251 bytes]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21168478</guid>
<pubDate>Thu, 25 Sep 2008 17:05:53 EDT</pubDate>
</item>

<item>
<title>Re: [Vundo] Vundo Removal</title>
<link>http://www.dslreports.com/forum/remark,21161961</link>
<description><![CDATA[<A HREF="/useremail/u/555588"><b>LoPhatPhuud</b></A> : <b>First:</b><br>Please download Malwarebytes Anti-Malware</font></a></b> and save it to your desktop.<br><textarea name="code" class="text" cols=50 rows=10>http://www.besttechie.net/tools/mbam-setup.exe&#012;http://malwarebytes.gt500.org/mbam-setup.exe&#012;http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html&#012;</textarea><!--end code block--><ul><li>Make sure you are connected to the Internet.</li><li>Double-click on <b>Download_mbam-setup.exe</b> to install the application. <i>(If using Windows Vista, be sure to</font> "<A HREF="http://windowshelp.microsoft.com/Windows/en-US/Help/fb464905-31d5-4427-89a2-ed5322327fc21033.mspx">Run As Administrator</a>")</font></i></li><li>When the installation begins, follow the prompts and do not make any changes to default settings.</li><li>When installation has finished, make sure you leave both of these checked:<ul></li><li><b>Update Malwarebytes' Anti-Malware</b></li><li><b>Launch Malwarebytes' Anti-Malware</b></ul></li><li>Then click <b>Finish</b>.</li><li>MBAM will automatically start and you will be asked to update the program before performing a scan. If an update is found, the program will automatically update itself. Press the <b>OK</b> button to close that box and continue.</li><li><i>If you encounter any problems while downloading the updates, manually download them from</font> <A HREF="http://www.malwarebytes.org/mbam/database/mbam-rules.exe">here</font></a> and just double-click on mbam-rules.exe to install.</font></i></li><li>On the Scanner tab:<ul></li><li>Make sure the "<b>Perform Quick Acan</b>" option is selected.</li><li>Then click on the <b>Scan</b> button.</ul></li><li>The next screen will ask you to select the drives to scan. Leave <u>all the drives</u> selected and click on the <b>Start Scan</b> button.</li><li>The scan will begin and "<i>Scan in progress</font></i>" will show at the top. It may take some time to complete so please be patient.</li><li>When the scan is finished, a message box will say "<i>The scan completed successfully. Click 'Show Results' to display all objects found</font></i>".</li><li>Click <b>OK</b> to close the message box and continue with the removal process.</li><li>Back at the main Scanner screen, click on the <b>Show Results</b> button to see a list of any malware that was found.</li><li>Make sure that <b><i>everything is checked</font></i></b>, and click <b>Remove Selected</b>.</li><li>When removal is completed, a log report will open in Notepad and you may be prompted to restart your computer. <i>(see Note below)</font></i></li><li>The log is automatically saved and can be viewed by clicking the <b>Logs</b> tab in MBAM.</li><li>Copy and paste the contents of that report in your next reply and exit MBAM.</ul><i><b>Note</b>: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.</font></i></li><br><br><b>Second:</b><br>Download to your Desktop FixPolicies.exe, a self-extracting ZIP archive from here:<br>view plainprint?<br><textarea name="code" class="text" cols=50 rows=10> http://downloads.malwareremoval.com/BillCastner/FixPolicies.exe    &#012;</textarea><!--end code block-->http://downloads.malwareremoval.com/BillCastner/FixPolicies.exe<br>&#149; Double-click FixPolicies.exe<br>&#149; Click the "Install" button on the bottom toolbar of the box that will open.<br>&#149; The program will create a new Folder called FixPolicies,<br>&#149; Double-click to Open the new Folder, and then double-click the file within: Fix_Policies.cmd.<br>&#149; A black box will briefly appear and then close.<br><br><b>Third:</b><br>Download <b>Combofix</b> from any of the links below, and save it to your desktop.  For information regarding this download, please visit this webpage: &raquo;<A HREF="http://www.bleepingcomputer.com/combofix/how-to-use-combofix" >www.bleepingcomputer.com/combofi&middot;&middot;&middot;combofix</A><br><br><br><textarea name="code" class="text" cols=50 rows=10>http://download.bleepingcomputer.com/sUBs/ComboFix.exe&#012;http://www.forospyware.com/sUBs/ComboFix.exe&#012;http://subs.geekstogo.com/ComboFix.exe&#012;</textarea><!--end code block--><br><br><br>**Note:  It is important that it is saved directly to your desktop**</font><br><br>--------------------------------------------------------------------<br><br>1. Close any open browsers.<br><br>2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.<br><br>--------------------------------------------------------------------<br><br>Double click on <b>combofix.exe</b> & follow the prompts.<br><ul>When finished, it will produce a report for you. &#8226;Please post the <b>"C:\ComboFix.txt" </b>along with a <b>new HijackThis log</b> for further review.</ul></li><br>Note:<br>Do not mouseclick combofix's window while it's running. That may cause it to stall</font><br><br><br><small>--<br>When angry count four; when very angry, swear.<br><br>Microsoft MVP/Consumer Security 2005-2008<br><br><A HREF="http://forum.gladiator-antivirus.com">Gladiator Security Forum</a></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21161961</guid>
<pubDate>Wed, 24 Sep 2008 15:27:01 EDT</pubDate>
</item>

<item>
<title>[Vundo] Vundo Removal</title>
<link>http://www.dslreports.com/forum/remark,21158438</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Thanks for helping. I'm a complete newb and I am hoping to learn things from you all to help clean up my computer!<br><br>VundoFix V5.1.7<br><br>Checking Java version...<br><br>Java version is 1.4.2.3<br><br>Scan started at 1:01:28 PM 8/12/2006<br><br>Listing files found while scanning....<br><br>No infected files were found.<br><br>VundoFix V5.1.7<br><br>Checking Java version...<br><br>Java version is 1.4.2.3<br><br>Scan started at 7:44:53 PM 8/12/2006<br><br>Listing files found while scanning....<br><br>No infected files were found.<br><br>Beginning removal...<br><br>VundoFix V7.0.6<br><br>Scan started at 10:06:49 PM 9/23/2008<br><br>Listing files found while scanning....<br><br>C:\Documents and settings\HP_Owner\Application Data\SearchToolbarCorp\Toolbar Vision\PageHistory.txt<br>C:\Documents and settings\HP_Owner\Application Data\SearchToolbarCorp\Toolbar Vision\WebHistory.txt<br>C:\Windows\system32\ahlmufxl.dll<br>C:\Windows\system32\argvcmta.exe<br>C:\Windows\system32\bfveiddy.dll<br>C:\Windows\system32\bllrcemf.exe<br>C:\Windows\system32\bmkvqkix.exe<br>C:\windows\system32\bngwxdwl.exe<br>C:\Windows\system32\bowcndwk.exe<br>C:\Windows\system32\bvkevmao.dll<br>C:\Windows\system32\cbenkfwk.exe<br>C:\Windows\system32\cmsxwbrm.dll<br>C:\Windows\system32\crrgcoxc.dll<br>C:\Windows\system32\cuwladgu.dll<br>C:\windows\system32\cxraqjiv.exe<br>C:\Windows\system32\drdbkwrl.dll<br>C:\Windows\system32\dvwrwlkw.dll<br>C:\Windows\system32\dwkaqpke.dll<br>C:\Windows\system32\dxvtctvb.dll<br>C:\Windows\system32\eorynbbe.dll<br>C:\windows\system32\esofhduf.exe<br>C:\Windows\system32\fgitxqol.dll<br>C:\Windows\system32\fgtjkqyn.dll<br>C:\Windows\system32\fjnonsam.dll<br>C:\Windows\system32\fkeeobye.dll<br>C:\Windows\system32\fkkvajnv.dll<br>C:\Windows\system32\fmysfgre.dll<br>C:\Windows\system32\fnrdwdop.exe<br>C:\windows\system32\fqcngmkv.dll<br>C:\windows\system32\fqmydwlw.exe<br>C:\Windows\system32\ftlpgjch.dll<br>C:\Windows\system32\gayjhwec.exe<br>C:\Windows\system32\gquiuyrm.dll<br>C:\Windows\system32\gtwmlsaq.dll<br>C:\Windows\system32\hdvrtjvm.dll<br>C:\Windows\system32\hfuifism.exe<br>C:\Windows\system32\hgtocvjh.dll<br>C:\windows\system32\hhruywxe.exe<br>C:\Windows\system32\hjvcotgh.ini<br>C:\Windows\system32\hnscwlny.exe<br>C:\Windows\system32\hrirthfi.dll<br>C:\windows\system32\hwtkdqaf.exe<br>C:\Windows\system32\igngurcn.exe<br>C:\Windows\system32\ipxxsfsy.dll<br>C:\Windows\system32\isanwwhe.exe<br>C:\Windows\system32\jaxxikuw.dll<br>C:\Windows\system32\jdtparlx.dll<br>C:\windows\system32\jertmpel.exe<br>C:\windows\system32\jesxpvgn.exe<br>C:\Windows\system32\jhqsyoyt.dll<br>C:\windows\system32\jikwmmwl.exe<br>C:\Windows\system32\jovgbfed.dll<br>C:\windows\system32\jxtaykxq.exe<br>C:\Windows\system32\kgyrtdkg.dll<br>C:\Windows\system32\kjhvogjd.exe<br>C:\windows\system32\knulllcv.exe<br>C:\Windows\system32\kpusulkk.exe<br>C:\windows\system32\ksetclbd.exe<br>C:\Windows\system32\ktcievav.exe<br>C:\windows\system32\kudndjxe.exe<br>C:\windows\system32\kwpijugp.exe<br>C:\Windows\system32\lcntnbki.dll<br>C:\Windows\system32\ldppwxem.exe<br>C:\Windows\system32\lofcbmxd.exe<br>C:\windows\system32\lyseeljc.dll<br>C:\Windows\system32\mgxwihcr.dll<br>C:\Windows\system32\mlgnnygk.dll<br>C:\windows\system32\moplejme.exe<br>C:\Windows\system32\morngpto.exe<br>C:\Windows\system32\mqupasos.dll<br>C:\windows\system32\niqmlhdr.exe<br>C:\windows\system32\nudfcmba.exe<br>C:\Windows\system32\nvetdsad.exe<br>C:\Windows\system32\nxpovmri.exe<br>C:\Windows\system32\obilribv.dll<br>C:\windows\system32\ogogwmog.exe<br>C:\windows\system32\ohxqxqwk.exe<br>C:\windows\system32\olbihvnp.exe<br>C:\Windows\system32\oqicohqy.exe<br>C:\Windows\system32\pbgrrixo.dll<br>C:\Windows\system32\pdncvmek.exe<br>C:\Windows\system32\pehntmok.exe<br>C:\Windows\system32\pexbdpcn.dll<br>C:\Windows\system32\pgiqdovd.exe<br>C:\Windows\system32\pjtlxsnw.dll<br>C:\Windows\system32\pjtlyjol.exe<br>C:\Windows\system32\poasaedt.dll<br>C:\Windows\system32\pufxufbw.exe<br>C:\Windows\system32\pwrxwuae.dll<br>C:\Windows\system32\qdindaws.ini<br>C:\Windows\system32\qfbkgmhj.exe<br>C:\Windows\system32\qnigoetb.dll<br>C:\windows\system32\qslvukib.exe<br>C:\windows\system32\ravjxemy.exe<br>C:\Windows\system32\rcotnehn.exe<br>C:\Windows\system32\rdkmpudi.dll<br>C:\windows\system32\rkjldqvh.exe<br>C:\windows\system32\roltfvaw.exe<br>C:\windows\system32\rpbexshu.exe<br>C:\Windows\system32\rvlcalgo.dll<br>C:\windows\system32\rxfcvxja.exe<br>C:\Windows\system32\scsiauua.dll<br>C:\windows\system32\seqymkmx.exe<br>C:\Windows\system32\skibqsba.dll<br>C:\windows\system32\skppwdwp.exe<br>C:\windows\system32\ssqpp.dll<br>C:\Windows\system32\swadnidq.dll<br>C:\Windows\system32\tbpfslnx.dll<br>C:\Windows\system32\tgldyglh.exe<br>C:\Windows\system32\thkqovme.dll<br>C:\Windows\system32\tpojpgsl.dll<br>C:\windows\system32\trdebihg.exe<br>C:\windows\system32\trspcijf.exe<br>C:\Windows\system32\tskkhwnf.dll<br>C:\Windows\system32\tyknhjvh.dll<br>C:\Windows\system32\udtpuibv.exe<br>C:\Windows\system32\upyswunt.exe<br>C:\Windows\system32\uyfcapup.dll<br>C:\Windows\system32\veunxnvi.dll<br>C:\windows\system32\vhdslwmi.exe<br>C:\windows\system32\vidmqxbo.exe<br>C:\windows\system32\vpacgooo.exe<br>C:\windows\system32\vqswsahg.dll<br>C:\Windows\system32\vsiaflew.exe<br>C:\Windows\system32\vugfttkm.dll<br>C:\Windows\system32\vxkynvtx.exe<br>C:\Windows\system32\wfvsibyj.exe<br>C:\windows\system32\wimbfess.exe<br>C:\Windows\system32\wjkoiucj.exe<br>C:\Windows\system32\wkejvfxv.exe<br>C:\Windows\system32\wltwaxbt.dll<br>C:\Windows\system32\woiokpvs.dll<br>C:\Windows\system32\wqgikmxm.exe<br>C:\Windows\system32\wthneupr.dll<br>C:\Windows\system32\wukixxaj.ini<br>C:\windows\system32\wvlacvhw.exe<br>C:\windows\system32\wyrxkmbi.exe<br>C:\windows\system32\xbeoolec.exe<br>C:\Windows\system32\xmhtabtk.dll<br>C:\Windows\system32\xnwaeptk.dll<br>C:\windows\system32\xunjinmi.exe<br>C:\windows\system32\xutljpio.exe<br>C:\Windows\system32\xwlfmjvw.dll<br>C:\Windows\system32\xyugypss.dll<br>C:\Windows\system32\ybqfvfnm.exe<br>C:\windows\system32\ymhbfkie.exe<br>C:\Windows\system32\ynqrgiwg.dll<br>C:\Windows\system32\ysotqqah.exe<br>C:\windows\system32\yvwpictu.exe<br>C:\Windows\system32\yxtkgbqe.exe<br><br>Beginning removal...<br><br> Attempting to delete C:\Documents and settings\HP_Owner\Application Data\SearchToolbarCorp\Toolbar Vision\PageHistory.txt<br>C:\Documents and settings\HP_Owner\Application Data\SearchToolbarCorp\Toolbar Vision\PageHistory.txt Has been deleted!<br><br> Attempting to delete C:\Documents and settings\HP_Owner\Application Data\SearchToolbarCorp\Toolbar Vision\WebHistory.txt<br>C:\Documents and settings\HP_Owner\Application Data\SearchToolbarCorp\Toolbar Vision\WebHistory.txt Has been deleted!<br><br> Attempting to delete C:\Windows\system32\ahlmufxl.dll<br>C:\Windows\system32\ahlmufxl.dll Has been deleted!<br><br> Attempting to delete C:\Windows\system32\argvcmta.exe<br>C:\Windows\system32\argvcmta.exe Has been deleted!<br><br> Attempting to delete C:\Windows\system32\bfveiddy.dll<br>C:\Windows\system32\bfveiddy.dll Has been deleted!<br><br> Attempting to delete C:\Windows\system32\bllrcemf.exe<br>C:\Windows\system32\bllrcemf.exe Has been deleted!<br><br> Attempting to delete C:\Windows\system32\bmkvqkix.exe<br>C:\Windows\system32\bmkvqkix.exe Has been deleted!<br><br> Attempting to delete C:\windows\system32\bngwxdwl.exe<br>C:\windows\system32\bngwxdwl.exe Has been deleted!<br><br> Attempting to delete C:\Windows\system32\bowcndwk.exe<br>C:\Windows\system32\bowcndwk.exe Has been deleted!<br><br> Attempting to delete C:\Windows\system32\bvkevmao.dll<br>C:\Windows\system32\bvkevmao.dll Has been deleted!<br><br> Attempting to delete C:\Windows\system32\cbenkfwk.exe<br>C:\Windows\system32\cbenkfwk.exe Has been deleted!<br><br> Attempting to delete C:\Windows\system32\cmsxwbrm.dll<br>C:\Windows\system32\cmsxwbrm.dll Has been deleted!<br><br> Attempting to delete C:\Windows\system32\crrgcoxc.dll<br>C:\Windows\system32\crrgcoxc.dll Has been deleted!<br><br> Attempting to delete C:\Windows\system32\cuwladgu.dll<br>C:\Windows\system32\cuwladgu.dll Has been deleted!<br><br> Attempting to delete C:\windows\system32\cxraqjiv.exe<br>C:\windows\system32\cxraqjiv.exe Has been deleted!<br><br> Attempting to delete C:\Windows\system32\drdbkwrl.dll<br>C:\Windows\system32\drdbkwrl.dll Has been deleted!<br><br> Attempting to delete C:\Windows\system32\dvwrwlkw.dll<br>C:\Windows\system32\dvwrwlkw.dll Has been deleted!<br><br> Attempting to delete C:\Windows\system32\dwkaqpke.dll<br>C:\Windows\system32\dwkaqpke.dll Has been deleted!<br><br> Attempting to delete C:\Windows\system32\dxvtctvb.dll<br>C:\Windows\system32\dxvtctvb.dll Has been deleted!<br><br> Attempting to delete C:\Windows\system32\eorynbbe.dll<br>C:\Windows\system32\eorynbbe.dll Has been deleted!<br><br> Attempting to delete C:\windows\system32\esofhduf.exe<br>C:\windows\system32\esofhduf.exe Has been deleted!<br><br> Attempting to delete C:\Windows\system32\fgitxqol.dll<br>C:\Windows\system32\fgitxqol.dll Has been deleted!<br><br> Attempting to delete C:\Windows\system32\fgtjkqyn.dll<br>C:\Windows\system32\fgtjkqyn.dll Has been deleted!<br><br> Attempting to delete C:\Windows\system32\fjnonsam.dll<br>C:\Windows\system32\fjnonsam.dll Has been deleted!<br><br> Attempting to delete C:\Windows\system32\fkeeobye.dll<br>C:\Windows\system32\fkeeobye.dll Has been deleted!<br><br> Attempting to delete C:\Windows\system32\fkkvajnv.dll<br>C:\Windows\system32\fkkvajnv.dll Has been deleted!<br><br> Attempting to delete C:\Windows\system32\fmysfgre.dll<br>C:\Windows\system32\fmysfgre.dll Has been deleted!<br><br> Attempting to delete C:\Windows\system32\fnrdwdop.exe<br>C:\Windows\system32\fnrdwdop.exe Has been deleted!<br><br> Attempting to delete C:\windows\system32\fqcngmkv.dll<br>C:\windows\system32\fqcngmkv.dll Has been deleted!<br><br> Attempting to delete C:\windows\system32\fqmydwlw.exe<br>C:\windows\system32\fqmydwlw.exe Has been deleted!<br><br> Attempting to delete C:\Windows\system32\ftlpgjch.dll<br>C:\Windows\system32\ftlpgjch.dll Has been deleted!<br><br> Attempting to delete C:\Windows\system32\gayjhwec.exe<br>C:\Windows\system32\gayjhwec.exe Has been deleted!<br><br> Attempting to delete C:\Windows\system32\gquiuyrm.dll<br>C:\Windows\system32\gquiuyrm.dll Has been deleted!<br><br> Attempting to delete C:\Windows\system32\gtwmlsaq.dll<br>C:\Windows\system32\gtwmlsaq.dll Has been deleted!<br><br> Attempting to delete C:\Windows\system32\hdvrtjvm.dll<br>C:\Windows\system32\hdvrtjvm.dll Has been deleted!<br><br> Attempting to delete C:\Windows\system32\hfuifism.exe<br>C:\Windows\system32\hfuifism.exe Has been deleted!<br><br> Attempting to delete C:\Windows\system32\hgtocvjh.dll<br>C:\Windows\system32\hgtocvjh.dll Has been deleted!<br><br> Attempting to delete C:\windows\system32\hhruywxe.exe<br>C:\windows\system32\hhruywxe.exe Has been deleted!<br><br> Attempting to delete C:\Windows\system32\hjvcotgh.ini<br>C:\Windows\system32\hjvcotgh.ini Has been deleted!<br><br> Attempting to delete C:\Windows\system32\hnscwlny.exe<br>C:\Windows\system32\hnscwlny.exe Has been deleted!<br><br> Attempting to delete C:\Windows\system32\hrirthfi.dll<br>C:\Windows\system32\hrirthfi.dll Has been deleted!<br><br> Attempting to delete C:\windows\system32\hwtkdqaf.exe<br>C:\windows\system32\hwtkdqaf.exe Has been deleted!<br><br> Attempting to delete C:\Windows\system32\igngurcn.exe<br>C:\Windows\system32\igngurcn.exe Has been deleted!<br><br> Attempting to delete C:\Windows\system32\ipxxsfsy.dll<br>C:\Windows\system32\ipxxsfsy.dll Has been deleted!<br><br> Attempting to delete C:\Windows\system32\isanwwhe.exe<br>C:\Windows\system32\isanwwhe.exe Has been deleted!<br><br> Attempting to delete C:\Windows\system32\jaxxikuw.dll<br>C:\Windows\system32\jaxxikuw.dll Has been deleted!<br><br> Attempting to delete C:\Windows\system32\jdtparlx.dll<br>C:\Windows\system32\jdtparlx.dll Has been deleted!<br><br> Attempting to delete C:\windows\system32\jertmpel.exe<br>C:\windows\system32\jertmpel.exe Has been deleted!<br><br> Attempting to delete C:\windows\system32\jesxpvgn.exe<br>C:\windows\system32\jesxpvgn.exe Has been deleted!<br><br> Attempting to delete C:\Windows\system32\jhqsyoyt.dll<br>C:\Windows\system32\jhqsyoyt.dll Has been deleted!<br><br> Attempting to delete C:\windows\system32\jikwmmwl.exe<br>C:\windows\system32\jikwmmwl.exe Has been deleted!<br><br> Attempting to delete C:\Windows\system32\jovgbfed.dll<br>C:\Windows\system32\jovgbfed.dll Has been deleted!<br><br> Attempting to delete C:\windows\system32\jxtaykxq.exe<br>C:\windows\system32\jxtaykxq.exe Has been deleted!<br><br> Attempting to delete C:\Windows\system32\kgyrtdkg.dll<br>C:\Windows\system32\kgyrtdkg.dll Has been deleted!<br><br> Attempting to delete C:\Windows\system32\kjhvogjd.exe<br>C:\Windows\system32\kjhvogjd.exe Has been deleted!<br><br> Attempting to delete C:\windows\system32\knulllcv.exe<br>C:\windows\system32\knulllcv.exe Has been deleted!<br><br> Attempting to delete C:\Windows\system32\kpusulkk.exe<br>C:\Windows\system32\kpusulkk.exe Has been deleted!<br><br> Attempting to delete C:\windows\system32\ksetclbd.exe<br>C:\windows\system32\ksetclbd.exe Has been deleted!<br><br> Attempting to delete C:\Windows\system32\ktcievav.exe<br>C:\Windows\system32\ktcievav.exe Has been deleted!<br><br> Attempting to delete C:\windows\system32\kudndjxe.exe<br>C:\windows\system32\kudndjxe.exe Has been deleted!<br><br> Attempting to delete C:\windows\system32\kwpijugp.exe<br>C:\windows\system32\kwpijugp.exe Has been deleted!<br><br> Attempting to delete C:\Windows\system32\lcntnbki.dll<br>C:\Windows\system32\lcntnbki.dll Has been deleted!<br><br> Attempting to delete C:\Windows\system32\ldppwxem.exe<br>C:\Windows\system32\ldppwxem.exe Has been deleted!<br><br> Attempting to delete C:\Windows\system32\lofcbmxd.exe<br>C:\Windows\system32\lofcbmxd.exe Has been deleted!<br><br> Attempting to delete C:\windows\system32\lyseeljc.dll<br>C:\windows\system32\lyseeljc.dll Has been deleted!<br><br> Attempting to delete C:\Windows\system32\mgxwihcr.dll<br>C:\Windows\system32\mgxwihcr.dll Has been deleted!<br><br> Attempting to delete C:\Windows\system32\mlgnnygk.dll<br>C:\Windows\system32\mlgnnygk.dll Has been deleted!<br><br> Attempting to delete C:\windows\system32\moplejme.exe<br>C:\windows\system32\moplejme.exe Has been deleted!<br><br> Attempting to delete C:\Windows\system32\morngpto.exe<br>C:\Windows\system32\morngpto.exe Has been deleted!<br><br> Attempting to delete C:\Windows\system32\mqupasos.dll<br>C:\Windows\system32\mqupasos.dll Has been deleted!<br><br> Attempting to delete C:\windows\system32\niqmlhdr.exe<br>C:\windows\system32\niqmlhdr.exe Has been deleted!<br><br> Attempting to delete C:\windows\system32\nudfcmba.exe<br>C:\windows\system32\nudfcmba.exe Has been deleted!<br><br> Attempting to delete C:\Windows\system32\nvetdsad.exe<br>C:\Windows\system32\nvetdsad.exe Has been deleted!<br><br> Attempting to delete C:\Windows\system32\nxpovmri.exe<br>C:\Windows\system32\nxpovmri.exe Has been deleted!<br><br> Attempting to delete C:\Windows\system32\obilribv.dll<br>C:\Windows\system32\obilribv.dll Has been deleted!<br><br> Attempting to delete C:\windows\system32\ogogwmog.exe<br>C:\windows\system32\ogogwmog.exe Has been deleted!<br><br> Attempting to delete C:\windows\system32\ohxqxqwk.exe<br>C:\windows\system32\ohxqxqwk.exe Has been deleted!<br><br> Attempting to delete C:\windows\system32\olbihvnp.exe<br>C:\windows\system32\olbihvnp.exe Has been deleted!<br><br> Attempting to delete C:\Windows\system32\oqicohqy.exe<br>C:\Windows\system32\oqicohqy.exe Has been deleted!<br><br> Attempting to delete C:\Windows\system32\pbgrrixo.dll<br>C:\Windows\system32\pbgrrixo.dll Has been deleted!<br><br> Attempting to delete C:\Windows\system32\pdncvmek.exe<br>C:\Windows\system32\pdncvmek.exe Has been deleted!<br><br> Attempting to delete C:\Windows\system32\pehntmok.exe<br>C:\Windows\system32\pehntmok.exe Has been deleted!<br><br> Attempting to delete C:\Windows\system32\pexbdpcn.dll<br>C:\Windows\system32\pexbdpcn.dll Has been deleted!<br><br> Attempting to delete C:\Windows\system32\pgiqdovd.exe<br>C:\Windows\system32\pgiqdovd.exe Has been deleted!<br><br> Attempting to delete C:\Windows\system32\pjtlxsnw.dll<br>C:\Windows\system32\pjtlxsnw.dll Has been deleted!<br><br> Attempting to delete C:\Windows\system32\pjtlyjol.exe<br>C:\Windows\system32\pjtlyjol.exe Has been deleted!<br><br> Attempting to delete C:\Windows\system32\poasaedt.dll<br>C:\Windows\system32\poasaedt.dll Has been deleted!<br><br> Attempting to delete C:\Windows\system32\pufxufbw.exe<br>C:\Windows\system32\pufxufbw.exe Has been deleted!<br><br> Attempting to delete C:\Windows\system32\pwrxwuae.dll<br>C:\Windows\system32\pwrxwuae.dll Has been deleted!<br><br> Attempting to delete C:\Windows\system32\qdindaws.ini<br>C:\Windows\system32\qdindaws.ini Has been deleted!<br><br> Attempting to delete C:\Windows\system32\qfbkgmhj.exe<br>C:\Windows\system32\qfbkgmhj.exe Has been deleted!<br><br> Attempting to delete C:\Windows\system32\qnigoetb.dll<br>C:\Windows\system32\qnigoetb.dll Has been deleted!<br><br> Attempting to delete C:\windows\system32\qslvukib.exe<br>C:\windows\system32\qslvukib.exe Has been deleted!<br><br> Attempting to delete C:\windows\system32\ravjxemy.exe<br>C:\windows\system32\ravjxemy.exe Has been deleted!<br><br> Attempting to delete C:\Windows\system32\rcotnehn.exe<br>C:\Windows\system32\rcotnehn.exe Has been deleted!<br><br> Attempting to delete C:\Windows\system32\rdkmpudi.dll<br>C:\Windows\system32\rdkmpudi.dll Has been deleted!<br><br> Attempting to delete C:\windows\system32\rkjldqvh.exe<br>C:\windows\system32\rkjldqvh.exe Has been deleted!<br><br> Attempting to delete C:\windows\system32\roltfvaw.exe<br>C:\windows\system32\roltfvaw.exe Has been deleted!<br><br> Attempting to delete C:\windows\system32\rpbexshu.exe<br>C:\windows\system32\rpbexshu.exe Has been deleted!<br><br> Attempting to delete C:\Windows\system32\rvlcalgo.dll<br>C:\Windows\system32\rvlcalgo.dll Has been deleted!<br><br> Attempting to delete C:\windows\system32\rxfcvxja.exe<br>C:\windows\system32\rxfcvxja.exe Has been deleted!<br><br> Attempting to delete C:\Windows\system32\scsiauua.dll<br>C:\Windows\system32\scsiauua.dll Has been deleted!<br><br> Attempting to delete C:\windows\system32\seqymkmx.exe<br>C:\windows\system32\seqymkmx.exe Has been deleted!<br><br> Attempting to delete C:\Windows\system32\skibqsba.dll<br>C:\Windows\system32\skibqsba.dll Has been deleted!<br><br> Attempting to delete C:\windows\system32\skppwdwp.exe<br>C:\windows\system32\skppwdwp.exe Has been deleted!<br><br> Attempting to delete C:\windows\system32\ssqpp.dll<br>C:\windows\system32\ssqpp.dll Has been deleted!<br><br> Attempting to delete C:\Windows\system32\swadnidq.dll<br>C:\Windows\system32\swadnidq.dll Has been deleted!<br><br> Attempting to delete C:\Windows\system32\tbpfslnx.dll<br>C:\Windows\system32\tbpfslnx.dll Has been deleted!<br><br> Attempting to delete C:\Windows\system32\tgldyglh.exe<br>C:\Windows\system32\tgldyglh.exe Has been deleted!<br><br> Attempting to delete C:\Windows\system32\thkqovme.dll<br>C:\Windows\system32\thkqovme.dll Has been deleted!<br><br> Attempting to delete C:\Windows\system32\tpojpgsl.dll<br>C:\Windows\system32\tpojpgsl.dll Has been deleted!<br><br> Attempting to delete C:\windows\system32\trdebihg.exe<br>C:\windows\system32\trdebihg.exe Has been deleted!<br><br> Attempting to delete C:\windows\system32\trspcijf.exe<br>C:\windows\system32\trspcijf.exe Has been deleted!<br><br> Attempting to delete C:\Windows\system32\tskkhwnf.dll<br>C:\Windows\system32\tskkhwnf.dll Has been deleted!<br><br> Attempting to delete C:\Windows\system32\tyknhjvh.dll<br>C:\Windows\system32\tyknhjvh.dll Has been deleted!<br><br> Attempting to delete C:\Windows\system32\udtpuibv.exe<br>C:\Windows\system32\udtpuibv.exe Has been deleted!<br><br> Attempting to delete C:\Windows\system32\upyswunt.exe<br>C:\Windows\system32\upyswunt.exe Has been deleted!<br><br> Attempting to delete C:\Windows\system32\uyfcapup.dll<br>C:\Windows\system32\uyfcapup.dll Has been deleted!<br><br> Attempting to delete C:\Windows\system32\veunxnvi.dll<br>C:\Windows\system32\veunxnvi.dll Has been deleted!<br><br> Attempting to delete C:\windows\system32\vhdslwmi.exe<br>C:\windows\system32\vhdslwmi.exe Has been deleted!<br><br> Attempting to delete C:\windows\system32\vidmqxbo.exe<br>C:\windows\system32\vidmqxbo.exe Has been deleted!<br><br> Attempting to delete C:\windows\system32\vpacgooo.exe<br>C:\windows\system32\vpacgooo.exe Has been deleted!<br><br> Attempting to delete C:\windows\system32\vqswsahg.dll<br>C:\windows\system32\vqswsahg.dll Has been deleted!<br><br> Attempting to delete C:\Windows\system32\vsiaflew.exe<br>C:\Windows\system32\vsiaflew.exe Has been deleted!<br><br> Attempting to delete C:\Windows\system32\vugfttkm.dll<br>C:\Windows\system32\vugfttkm.dll Has been deleted!<br><br> Attempting to delete C:\Windows\system32\vxkynvtx.exe<br>C:\Windows\system32\vxkynvtx.exe Has been deleted!<br><br> Attempting to delete C:\Windows\system32\wfvsibyj.exe<br>C:\Windows\system32\wfvsibyj.exe Has been deleted!<br><br> Attempting to delete C:\windows\system32\wimbfess.exe<br>C:\windows\system32\wimbfess.exe Has been deleted!<br><br> Attempting to delete C:\Windows\system32\wjkoiucj.exe<br>C:\Windows\system32\wjkoiucj.exe Has been deleted!<br><br> Attempting to delete C:\Windows\system32\wkejvfxv.exe<br>C:\Windows\system32\wkejvfxv.exe Has been deleted!<br><br> Attempting to delete C:\Windows\system32\wltwaxbt.dll<br>C:\Windows\system32\wltwaxbt.dll Has been deleted!<br><br> Attempting to delete C:\Windows\system32\woiokpvs.dll<br>C:\Windows\system32\woiokpvs.dll Has been deleted!<br><br> Attempting to delete C:\Windows\system32\wqgikmxm.exe<br>C:\Windows\system32\wqgikmxm.exe Has been deleted!<br><br> Attempting to delete C:\Windows\system32\wthneupr.dll<br>C:\Windows\system32\wthneupr.dll Has been deleted!<br><br> Attempting to delete C:\Windows\system32\wukixxaj.ini<br>C:\Windows\system32\wukixxaj.ini Has been deleted!<br><br> Attempting to delete C:\windows\system32\wvlacvhw.exe<br>C:\windows\system32\wvlacvhw.exe Has been deleted!<br><br> Attempting to delete C:\windows\system32\wyrxkmbi.exe<br>C:\windows\system32\wyrxkmbi.exe Has been deleted!<br><br> Attempting to delete C:\windows\system32\xbeoolec.exe<br>C:\windows\system32\xbeoolec.exe Has been deleted!<br><br> Attempting to delete C:\Windows\system32\xmhtabtk.dll<br>C:\Windows\system32\xmhtabtk.dll Has been deleted!<br><br> Attempting to delete C:\Windows\system32\xnwaeptk.dll<br>C:\Windows\system32\xnwaeptk.dll Has been deleted!<br><br> Attempting to delete C:\windows\system32\xunjinmi.exe<br>C:\windows\system32\xunjinmi.exe Has been deleted!<br><br> Attempting to delete C:\windows\system32\xutljpio.exe<br>C:\windows\system32\xutljpio.exe Has been deleted!<br><br> Attempting to delete C:\Windows\system32\xwlfmjvw.dll<br>C:\Windows\system32\xwlfmjvw.dll Has been deleted!<br><br> Attempting to delete C:\Windows\system32\xyugypss.dll<br>C:\Windows\system32\xyugypss.dll Has been deleted!<br><br> Attempting to delete C:\Windows\system32\ybqfvfnm.exe<br>C:\Windows\system32\ybqfvfnm.exe Has been deleted!<br><br> Attempting to delete C:\windows\system32\ymhbfkie.exe<br>C:\windows\system32\ymhbfkie.exe Has been deleted!<br><br> Attempting to delete C:\Windows\system32\ynqrgiwg.dll<br>C:\Windows\system32\ynqrgiwg.dll Has been deleted!<br><br> Attempting to delete C:\Windows\system32\ysotqqah.exe<br>C:\Windows\system32\ysotqqah.exe Has been deleted!<br><br> Attempting to delete C:\windows\system32\yvwpictu.exe<br>C:\windows\system32\yvwpictu.exe Has been deleted!<br><br> Attempting to delete C:\Windows\system32\yxtkgbqe.exe<br>C:\Windows\system32\yxtkgbqe.exe Has been deleted!<br><br>Performing Repairs to the registry.<br>Done!<br><br>Here's my hijackthis log:<br><br>Logfile of HijackThis v1.99.1<br>Scan saved at 10:43:41 PM, on 9/23/2008<br>Platform: Windows XP SP2 (WinNT 5.01.2600)<br>MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)<br><br>Running processes:<br>C:\WINDOWS\System32\smss.exe<br>C:\WINDOWS\system32\winlogon.exe<br>C:\WINDOWS\system32\services.exe<br>C:\WINDOWS\system32\lsass.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\WINDOWS\System32\svchost.exe<br>c:\Program Files\Common Files\Symantec Shared\ccProxy.exe<br>c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe<br>c:\Program Files\Norton AntiVirus\navapsvc.exe<br>c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe<br>c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe<br>c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe<br>C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe<br>C:\WINDOWS\Explorer.EXE<br>C:\WINDOWS\system32\LEXBCES.EXE<br>C:\WINDOWS\system32\LEXPPS.EXE<br>C:\WINDOWS\system32\spoolsv.exe<br>C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe<br>C:\windows\system\hpsysdrv.exe<br>C:\WINDOWS\system32\hkcmd.exe<br>C:\WINDOWS\system32\hphmon06.exe<br>C:\HP\KBD\KBD.EXE<br>C:\Program Files\Common Files\Real\Update_OB\realsched.exe<br>C:\Program Files\Common Files\Symantec Shared\ccApp.exe<br>C:\WINDOWS\AGRSMMSG.exe<br>C:\WINDOWS\SOUNDMAN.EXE<br>C:\WINDOWS\ALCWZRD.EXE<br>C:\WINDOWS\ALCMTR.EXE<br>C:\Program Files\USBToolbox\Res.EXE<br>C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe<br>C:\Program Files\Lexmark X74-X75\lxbbbmon.exe<br>C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe<br>C:\Program Files\Dell AIO Printer A920\dlbkbmon.exe<br>C:\Program Files\QuickTime\QTTask.exe<br>C:\Program Files\iTunes\iTunesHelper.exe<br>C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe<br>C:\WINDOWS\system32\lphc5uej0e7dr.exe<br>C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br>C:\WINDOWS\system32\ctfmon.exe<br>C:\Program Files\AIM6\aim6.exe<br>c:\Program Files\Common Files\LightScribe\LSSrvc.exe<br>C:\Program Files\Maxtor\Sync\SyncServices.exe<br>C:\Program Files\Messenger\msmsgs.exe<br>C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe<br>C:\Program Files\interMute\SpySubtract\SpySub.exe<br>C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe<br>C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE<br>C:\WINDOWS\system32\svchost.exe<br>C:\Program Files\Viewpoint\Common\ViewpointService.exe<br>C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WLService.exe<br>C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WUSB54GC.exe<br>c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe<br>C:\Program Files\Canon\CAL\CALMAIN.exe<br>C:\Program Files\AIM6\aolsoftware.exe<br>C:\Program Files\iPod\bin\iPodService.exe<br>C:\Program Files\Mozilla Firefox\firefox.exe<br>C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe<br>C:\WINDOWS\system32\wuauclt.exe<br>C:\Program Files\AIM6\anotify.exe<br>C:\HJT\HijackThis.exe<br><br>R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &raquo;<A HREF="http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q105&bd=pavilion&pf=desktop" >ie.redirect.hp.com/svs/rdr?TYPE=&middot;&middot;&middot;=desktop</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &raquo;<A HREF="http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q105&bd=pavilion&pf=desktop" >ie.redirect.hp.com/svs/rdr?TYPE=&middot;&middot;&middot;=desktop</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = &raquo;<A HREF="http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=pavilion&pf=desktop" >ie.redirect.hp.com/svs/rdr?TYPE=&middot;&middot;&middot;=desktop</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &raquo;<A HREF="http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=pavilion&pf=desktop" >ie.redirect.hp.com/svs/rdr?TYPE=&middot;&middot;&middot;=desktop</A><br>R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q105&bd=pavilion&pf=desktop" >ie.redirect.hp.com/svs/rdr?TYPE=&middot;&middot;&middot;=desktop</A><br>R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = <br>O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll<br>O2 - BHO: (no name) - {338F763F-46ED-4BAC-B6DD-6DAD90D7ED60} - C:\WINDOWS\system32\drmsto.dll<br>O2 - BHO: (no name) - {6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} - C:\WINDOWS\system32\awtqpnk.dll (file missing)<br>O2 - BHO: Web assistant - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - c:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll<br>O2 - BHO: (no name) - {A9ACDAF2-6345-41EF-8E67-18D09AB619F8} - C:\WINDOWS\repair\ocmsis.dll (file missing)<br>O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton AntiVirus\NavShExt.dll<br>O3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll<br>O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NavShExt.dll<br>O3 - Toolbar: &VSToolBar - {821F87FF-8245-4972-9E28-732E92EC2F51} - C:\Program Files\VSToolbar\VSToolBar.dll<br>O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe<br>O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe<br>O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe<br>O4 - HKLM\..\Run: [HPHUPD06] c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe<br>O4 - HKLM\..\Run: [HPHmon06] C:\WINDOWS\system32\hphmon06.exe<br>O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE<br>O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r<br>O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot<br>O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE<br>O4 - HKLM\..\Run: [VTTimer] VTTimer.exe<br>O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE<br>O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"<br>O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe<br>O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe<br>O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe<br>O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE<br>O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE<br>O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE<br>O4 - HKLM\..\Run: [USB Storage Toolbox] C:\Program Files\USBToolbox\Res.EXE<br>O4 - HKLM\..\Run: [Lexmark X74-X75] "C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe"<br>O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer<br>O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe<br>O4 - HKLM\..\Run: [poolsv] "C:\WINDOWS\poolsv.exe"<br>O4 - HKLM\..\Run: [Dell AIO Printer A920] "C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe"<br>O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime<br>O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"<br>O4 - HKLM\..\Run: [mxomssmenu] "C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe"<br>O4 - HKLM\..\Run: [lphc5uej0e7dr] C:\WINDOWS\system32\lphc5uej0e7dr.exe<br>O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br>O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp<br>O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background<br>O4 - HKCU\..\Run: [MSI Configuration] msiconf.exe<br>O4 - Startup: VZAccess Manager.lnk = C:\Program Files\Verizon Wireless\VZAccess Manager\VZAccess Manager.exe<br>O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe<br>O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe<br>O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE<br>O4 - Global Startup: SpySubtract.lnk = C:\Program Files\interMute\SpySubtract\SpySub.exe<br>O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe<br>O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000<br>O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll<br>O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll<br>O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O16 - DPF: {00C7C2A0-8B82-11D1-8B57-00A0C98CD92B} (ActiveReports Viewer) - &raquo;<A HREF="http://www.ncbrightideas.com/arviewer.cab" >www.ncbrightideas.com/arviewer.cab</A><br>O16 - DPF: {0D623637-DBA2-11D1-B5DF-0060976089D0} (True DBGrid 7  Control) - &raquo;<A HREF="http://www.ncbrightideas.com/tdbg7.cab" >www.ncbrightideas.com/tdbg7.cab</A><br>O16 - DPF: {0D6236AB-DBA2-11D1-B5DF-0060976089D0} (ComponentOne XArrayDB Object) - &raquo;<A HREF="http://www.ncbrightideas.com/xadb7.cab" >www.ncbrightideas.com/xadb7.cab</A><br>O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - &raquo;<A HREF="http://web1.shutterfly.com/downloads/Uploader.cab" >web1.shutterfly.com/downloads/Uploader.cab</A><br>O16 - DPF: {CAFECAFE-0013-0001-0022-ABCDEFABCDEF} (JInitiator 1.3.1.22) - &raquo;<small>https</small>://<A HREF="https://accessncwise.wcpss.net/forms/jinitiator/jinit.exe">accessncwise.wcpss.net/forms/jin&middot;&middot;&middot;init.exe</A><br>O16 - DPF: {CE74A05D-ED12-473A-97F8-85FB0E2F479F} (dlControl.UserControl1) - &raquo;<A HREF="http://web1.nugs.net/dev/dlControl.CAB" >web1.nugs.net/dev/dlControl.CAB</A><br>O16 - DPF: {E008A543-CEFB-4559-912F-C27C2B89F13B} (Domino Web Access 7 Control) - &raquo;<small>https</small>://<A HREF="https://domino5.wcpss.net/dwa7W.cab">domino5.wcpss.net/dwa7W.cab</A><br>O16 - DPF: {FA3662C3-B8E8-11D6-A667-0010B556D978} - &raquo;<A HREF="http://cdn.digitalcity.com/_media/dalaillama/ampx.cab" >cdn.digitalcity.com/_media/dalai&middot;&middot;&middot;ampx.cab</A><br>O20 - Winlogon Notify: awtqpnk - awtqpnk.dll (file missing)<br>O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll<br>O20 - Winlogon Notify: ocmsis - C:\WINDOWS\repair\ocmsis.dll (file missing)<br>O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll<br>O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe<br>O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br>O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe<br>O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe<br>O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccProxy.exe<br>O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe<br>O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe<br>O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe<br>O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br>O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE<br>O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unknown owner - c:\Program Files\Common Files\LightScribe\LSSrvc.exe<br>O23 - Service: Maxtor Service (Maxtor Sync Service) - Seagate Technology LLC - C:\Program Files\Maxtor\Sync\SyncServices.exe<br>O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton AntiVirus\navapsvc.exe<br>O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - c:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe<br>O23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton AntiVirus\SAVScan.exe<br>O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe<br>O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe<br>O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe<br>O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe<br>O23 - Service: WUSB54GCSVC - Unknown owner - C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WLService.exe" "WUSB54GC.exe (file missing)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21158438</guid>
<pubDate>Tue, 23 Sep 2008 22:46:42 EDT</pubDate>
</item>

</channel>
</rss>
