<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>HJT Log: &#x22;System Security&#x22;, Vundo, Koobface in Security Cleanup</title>
<link>http://www.dslreports.com/forum/r22426484</link>
<description></description>
<language>en</language>
<pubDate>Mon, 30 Nov 2009 01:59:59 EDT</pubDate>
<lastBuildDate>Mon, 30 Nov 2009 01:59:59 EDT</lastBuildDate>

<item>
<title>Re: HJT Log: &#x22;System Security&#x22;, Vundo, Koobface</title>
<link>http://www.dslreports.com/forum/remark,22469882</link>
<description><![CDATA[<A HREF="/useremail/u/377471"><b>TheJoker</b></A> :  <blockquote><small>quote:</small><hr>Everything appears to be fine now. <hr></blockquote><br><br>Excellent! :)<br><br> <blockquote><small>quote:</small><hr>When I first received the computer from him, he told me that all his fonts were in bold, which is similar to this thread: &raquo;<A HREF="/forum/r22461909-HJT-LOG-Desktop-icons-changed-text-italicised">HJT LOG: Desktop icons changed, text italicised</A><hr></blockquote><br><br>I noticed that. Thanks for pointing it out.<br><br> <blockquote><small>quote:</small><hr>Thanks for your help Joker.<hr></blockquote><br><br>I'm glad to have been able to help.<br><small>--<br>Proud ASAP member since 2005</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22469882</guid>
<pubDate>Sat, 30 May 2009 18:01:27 EDT</pubDate>
</item>

<item>
<title>Re: HJT Log: &#x22;System Security&#x22;, Vundo, Koobface</title>
<link>http://www.dslreports.com/forum/remark,22466545</link>
<description><![CDATA[<A HREF="/useremail/u/1442410"><b>sMURF</b></A> : Note to mods: I'm the OP.<br><br>Hey Joker,<br><br>Everything appears to be fine now. I've tried explaining to the computer's owner that P2P programs are notorious for the spread of malware, but I suppose he just can't help himself sometimes. It's not the first time he's been infected, and I'm sure it won't be the last.<br><br>When I first received the computer from him, he told me that all his fonts were in bold, which is similar to this thread: &raquo;<A HREF="/forum/r22461909-HJT-LOG-Desktop-icons-changed-text-italicised">HJT LOG: Desktop icons changed, text italicised</A><br><br>I'm not sure if it was caused by the malware or not, but apparently the Tahoma.ttf file in C:\Windows\Fonts got corrupted, and I guess Windows was trying to use the closest match to it, which was Tahomabd.tff (bold).<br><br>To fix it, I went into Desktop Properties > Appearance > Advanced and changed the font for every item in the list that used Tahoma to something else ("System" for example) and applied the changes. I then deleted the Tahoma font file in C:\Windows\Fonts and quickly copied over a new Tahoma.ttf file (if it's not copied over fast enough, Windows seems to recreate the corrupted file again). After that I simply changed all the "System" fonts back to Tahoma.<br><br>Hopefully that can help you in the other thread, since it seems to have worked for me.<br><br>Thanks for your help Joker.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22466545</guid>
<pubDate>Fri, 29 May 2009 21:05:47 EDT</pubDate>
</item>

<item>
<title>Re: HJT Log: &#x22;System Security&#x22;, Vundo, Koobface</title>
<link>http://www.dslreports.com/forum/remark,22439744</link>
<description><![CDATA[<A HREF="/useremail/u/377471"><b>TheJoker</b></A> : Go to start > run and copy and paste next command in the field:<br><b>ComboFix /u</b><br><br>Make sure there's a space between Combofix and /<br>Then hit enter.<br><br>This will uninstall Combofix, delete its related folders and files, reset your clock settings, hide file extensions, hide the system/hidden files and resets System Restore again.<br><br>Create a <b>Restore Point</b> (XP ONLY)<br>&#8226;Go to Start > Programs > Accessories > System Tools > <b>System Restore</b><br>&#8226;Select <b>Cr<u>e</u>ate a Restore Point</b> and then <b>Next</b>. <br>&#8226;In the box for "Restore point description", enter a descriptive name and press <b>Create</b><br>&#8226;When the "Restore Point Created" window appears, click <b>Close</b><br><br>Run <b>Disk Cleanup</b><br>&#8226;Go to Start > Run and type the below line:<br><b>cleanmgr</b><br>&#8226;Click <b>OK</b><br>&#8226;If you have more than one drive, select the drive Windows is installed on<br>&#8226;Click <b>OK</b><br>&#8226;When Disk Cleanup opens, select the <b>More Options</b> tab<br>&#8226;In the System Restore section (bottom of window), click <b>Cleanup</b><br>&#8226;In the confirmation window that opens, click <b>Yes</b>[<br><br>Now click on the <b>Disk Cleanup</b> tab and select the following items:<br>&#8226;Downloaded Program Files<br>&#8226;Temporary Internet Files<br>&#8226;Recycle Bin<br>&#8226;Temporary Files<br>Click <b>OK</b><br>in the confirmation window, select <b>Yes</b> (Disk Cleanup will close).<br><br>I recommend installing a software firewall. I didn't see one in your HijackThis log (the XP firewall isn't sufficient protection, it only checks incoming data). Two free firewalls are Sunbelt Personal Firewall available from &raquo;<A HREF="http://www.sunbeltsoftware.com/Home-Home-Office/Sunbelt-Personal-Firewall" >www.sunbeltsoftware.com/Home-Hom&middot;&middot;&middot;Firewall</A>, and Zone Alarm available from  &raquo;<A HREF="http://www.zonealarm.com/security/en-us/zonealarm-pc-security-free-firewall.htm" >www.zonealarm.com/security/en-us&middot;&middot;&middot;wall.htm</A>. There is a tutorial on understanding firewalls at &raquo;<A HREF="http://www.bleepingcomputer.com/forums/tutorial60.html" >www.bleepingcomputer.com/forums/&middot;&middot;&middot;l60.html</A> and and a tutorial from Markus Jansson on setting up ZoneAlarm at &raquo;<A HREF="http://www.markusjansson.net/eza.html" >www.markusjansson.net/eza.html</A>. If you install ZoneAlarm (an excellent firewall), I recommend <b>NOT</b> installing the new optional feature <i>Spy Blocker</i>, as it's run by the questionable search engine Ask.com, and doesn't actually block any spyware. You can read more about Ask.com <A HREF="http://www.benedelman.org/spyware/installations/askjeeves-banner/"><b>here</b></a>. <br>There are several free utilities you can use to help keep malware off your system: <br><br>A HOSTS file will prevent Internet Explorer from communicating with sites known to be associated with adware or spyware. A good regularly updated HOST file is MVPS HOSTS File, available at &raquo;<A HREF="http://www.mvps.org/winhelp2002/hosts.htm" >www.mvps.org/winhelp2002/hosts.htm</A>. <br><br>A free non-resident utility to prevent the installation of ActiveX-based malware is JavaCool's SpywareBlaster. For real-time protection, there is SpywareGuard. Both are available at &raquo;<A HREF="http://www.javacoolsoftware.com/products.html" >www.javacoolsoftware.com/products.html</A>. <br><br>I recommend reading Tony Klein's article <i>So How did I get Infected in the First Place?</i> at &raquo;<A HREF="http://www.spywareinfoforum.com/index.php?showtopic=60955" >www.spywareinfoforum.com/index.p&middot;&middot;&middot;ic=60955</A><br><br>Does your problem appear resolved?<br><small>--<br>Proud ASAP member since 2005</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22439744</guid>
<pubDate>Mon, 25 May 2009 08:27:44 EDT</pubDate>
</item>

<item>
<title>Re: HJT Log: &#x22;System Security&#x22;, Vundo, Koobface</title>
<link>http://www.dslreports.com/forum/remark,22439059</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : <b>Kaspersky log:</b><br><br>--------------------------------------------------------------------------------<br>KASPERSKY ONLINE SCANNER 7.0 REPORT<br> Monday, May 25, 2009<br> Operating System: Microsoft Windows XP Professional Service Pack 3 (build 2600)<br> Kaspersky Online Scanner  version: 7.0.26.13<br> Program database last update: Monday, May 25, 2009 03:17:40<br> Records in database: 2237504<br>--------------------------------------------------------------------------------<br><br>Scan settings:<br>&#9;Scan using the following database: extended<br>&#9;Scan archives: yes<br>&#9;Scan mail databases: yes<br><br>Scan area - My Computer:<br>&#9;C:\<br>&#9;D:\<br>&#9;E:\<br><br>Scan statistics:<br>&#9;Files scanned: 175809<br>&#9;Threat name: 0<br>&#9;Infected objects: 0<br>&#9;Suspicious objects: 0<br>&#9;Duration of the scan: 02:12:13<br><br>No malware has been detected. The scan area is clean.<br><br>The selected area was scanned.<br><br><b>HijackThis log:</b><br><br>Logfile of Trend Micro HijackThis v2.0.2<br>Scan saved at 1:15:47 AM, on 5/25/2009<br>Platform: Windows XP SP3 (WinNT 5.01.2600)<br>MSIE: Internet Explorer v8.00 (8.00.6001.18702)<br>Boot mode: Normal<br><br>Running processes:<br>C:\WINDOWS\System32\smss.exe<br>C:\WINDOWS\system32\winlogon.exe<br>C:\WINDOWS\system32\services.exe<br>C:\WINDOWS\system32\lsass.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\WINDOWS\system32\spoolsv.exe<br>D:\AVG\AVG8\avgwdsvc.exe<br>C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe<br>C:\Program Files\Java\jre6\bin\jqs.exe<br>C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe<br>C:\PROGRA~1\COMMON~1\Stardock\SDMCP.exe<br>C:\WINDOWS\system32\nvsvc32.exe<br>C:\WINDOWS\system32\IoctlSvc.exe<br>C:\WINDOWS\system32\PnkBstrA.exe<br>C:\WINDOWS\system32\PnkBstrB.exe<br>C:\WINDOWS\Explorer.EXE<br>C:\WINDOWS\system32\svchost.exe<br>D:\AVG\AVG8\avgemc.exe<br>D:\AVG\AVG8\avgrsx.exe<br>D:\AVG\AVG8\avgnsx.exe<br>C:\WINDOWS\RTHDCPL.EXE<br>D:\AVG\AVG8\avgtray.exe<br>C:\WINDOWS\system32\RUNDLL32.EXE<br>C:\WINDOWS\vsnpstd2.exe<br>C:\Program Files\Logitech\GamePanel Software\LgDevAgt.exe<br>C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe<br>C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe<br>C:\Program Files\Java\jre6\bin\jusched.exe<br>C:\WINDOWS\system32\ctfmon.exe<br>C:\Program Files\Messenger\msmsgs.exe<br>C:\Program Files\Logitech\GamePanel Software\LCD Manager\Applets\LCDClock.exe<br>C:\Program Files\Logitech\GamePanel Software\Applets\LCDCountdown.exe<br>C:\Program Files\Logitech\GamePanel Software\Applets\LCDPop3.exe<br>C:\Program Files\Logitech\GamePanel Software\Applets\LCDRSS.exe<br>C:\Program Files\Logitech\GamePanel Software\Applets\LCDMedia.exe<br>D:\Logitech\SetPoint\SetPoint.exe<br>C:\Program Files\WiFiConnector\NintendoWFCReg.exe<br>D:\Program Files\Stardock\ObjectDock\ObjectDock.exe<br>D:\AVG\AVG8\avgcsrvx.exe<br>C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE<br>C:\WINDOWS\system32\wuauclt.exe<br>C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br><br>R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=69157" >go.microsoft.com/fwlink/?LinkId=69157</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=69157" >go.microsoft.com/fwlink/?LinkId=69157</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=69157" >go.microsoft.com/fwlink/?LinkId=69157</A><br>R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=74005" >go.microsoft.com/fwlink/?LinkId=74005</A><br>O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll<br>O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - D:\AVG\AVG8\avgssie.dll<br>O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br>O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br>O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br>O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE<br>O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE<br>O4 - HKLM\..\Run: [AVG8_TRAY] D:\AVG\AVG8\avgtray.exe<br>O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup<br>O4 - HKLM\..\Run: [nwiz] nwiz.exe /install<br>O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit<br>O4 - HKLM\..\Run: [SNPSTD2] C:\WINDOWS\vsnpstd2.exe<br>O4 - HKLM\..\Run: [Launch LgDevAgt] "C:\Program Files\Logitech\GamePanel Software\LgDevAgt.exe"<br>O4 - HKLM\..\Run: [Launch LCDMon] "C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe"<br>O4 - HKLM\..\Run: [Launch LGDCore] "C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe" /SHOWHIDE<br>O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"<br>O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br>O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background<br>O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')<br>O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')<br>O4 - Startup: Stardock ObjectDock.lnk = D:\Program Files\Stardock\ObjectDock\ObjectDock.exe<br>O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe<br>O4 - Global Startup: Logitech SetPoint.lnk = D:\Logitech\SetPoint\SetPoint.exe<br>O4 - Global Startup: Run Nintendo Wi-Fi USB Connector Registration Tool.lnk = C:\Program Files\WiFiConnector\NintendoWFCReg.exe<br>O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000<br>O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL<br>O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br>O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br>O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - &raquo;<A HREF="http://gfx2.hotmail.com/mail/w3/resources/MSNPUpld.cab" >gfx2.hotmail.com/mail/w3/resourc&middot;&middot;&middot;Upld.cab</A><br>O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - &raquo;<A HREF="http://download.eset.com/special/eos/OnlineScanner.cab" >download.eset.com/special/eos/On&middot;&middot;&middot;nner.cab</A><br>O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - D:\AVG\AVG8\avgpp.dll<br>O20 - Winlogon Notify: !SASWinLogon - D:\SUPERAntiSpyware\SASWINLO.dll<br>O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll<br>O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - D:\Ares\chatServer.exe<br>O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - D:\AVG\AVG8\avgemc.exe<br>O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - D:\AVG\AVG8\avgwdsvc.exe<br>O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe<br>O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br>O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe<br>O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe<br>O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe<br>O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe<br>O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe<br>O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe<br>O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe<br>O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe<br>O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe<br>O23 - Service: SonicStage Back-End Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SsBeSvc.exe<br>O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe<br>O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe<br><br>--<br>End of file - 8282 bytes]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22439059</guid>
<pubDate>Mon, 25 May 2009 01:18:46 EDT</pubDate>
</item>

<item>
<title>Re: HJT Log: &#x22;System Security&#x22;, Vundo, Koobface</title>
<link>http://www.dslreports.com/forum/remark,22438370</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Posting the log of Security Check while I wait the 2+ hours it'll take to scan with Kaspersky again...<br><br>Results of screen317's Security Check version 0.98.3 <br> Windows XP Service Pack 3  <br><b>`````````````````````````````` <br>Antivirus/Firewall Check:  <br>``````````````````````````````</b> <br> Windows Firewall Enabled!  <br> ESETOnlineScannerv3 <br> WindowsLiveOneCaresafetyscanner <br> AVGFree8.5 <br> Antivirus up to date!  <br><b>`````````````````````````````` <br>Anti-malware/Other Utilities Check:  <br>``````````````````````````````</b> <br> Spybot - Search & Destroy <br> SUPERAntiSpyware Free Edition   <br> Malwarebytes' Anti-Malware    <br> HijackThis 2.0.2    <br> Java(TM) 6 Update 13  <br><b>`````````````````````````````` <br>Process Check:  <br>objlist.exe by Laurent <br>``````````````````````````````</b> <br> AVG avgwdsvc.exe <br> AVG avgtray.exe <br> AVG avgrsx.exe <br> AVG avgnsx.exe <br> AVG avgemc.exe <br> AVG avgemc.exe <br> [color=red]<b>Spybot SDHelper is disabled!</b>[/color] <br> Microsoft Small Business Business Contact Manager BcmSqlStartupSvc.exe  <br><b>``````````````````````````````<br>DNS Vulnerability Check: <br>``````````````````````````````</b><br> GREAT! (Very random)<br><br>Scan took 18 seconds.<br><b>`````````End of Log```````````</b>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22438370</guid>
<pubDate>Sun, 24 May 2009 22:16:38 EDT</pubDate>
</item>

<item>
<title>Re: HJT Log: &#x22;System Security&#x22;, Vundo, Koobface</title>
<link>http://www.dslreports.com/forum/remark,22438213</link>
<description><![CDATA[<A HREF="/useremail/u/377471"><b>TheJoker</b></A> :  <blockquote><small>quote:</small><hr>The first URL for Security Check shows not found, while the second URL also shows not found, but gives me a link to a SecurityCheck.exe file.<hr></blockquote><br>The author changed the links to exe files rather than zip files, so the correct links should be:<br><textarea name="code" class="text" cols=50 rows=10>http://screen317.spywareinfoforum.org/SecurityCheck.exe&#012;http://screen317.changelog.fr/SecurityCheck.exe&#012;</textarea><!--end code block--><br>Please do a scan with <A HREF="http://www.kaspersky.com/kos/eng/partner/default/kavwebscan.html">Kaspersky Online Scanner</a><br><br><i>Note: If you are using Windows Vista, open your browser by right-clicking on its icon and select 'Run as administrator' to perform this scan.</i><br><br>Click on the <b>Accept</b> button and install any components it needs.<br>- The program will install and then begin downloading the latest definition files.<br>- After the files have been downloaded on the left side of the page in the <b>Scan</b> section select <b>My Computer</b>.<br>- This will start the program and scan your system.<br>- The scan will take a while, so be patient and let it run.<br>- Once the scan is complete, click on <b>View scan report</b><br>- Now, click on the <b>Save Report as</b> button.<br>- In the drop down box labeled <b>Files of type</b> change the type to <b>Text file</b>.<br>- Save the file to your desktop.<br>- Copy and paste that information in your next post.<br><br>Please post a new HijackThis log, the log from Security Check (checkup.txt), the log from Kaspersky's online scanner, and note any errors encountered.<br><br><small>--<br>Proud ASAP member since 2005</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22438213</guid>
<pubDate>Sun, 24 May 2009 21:32:35 EDT</pubDate>
</item>

<item>
<title>Re: HJT Log: &#x22;System Security&#x22;, Vundo, Koobface</title>
<link>http://www.dslreports.com/forum/remark,22437167</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Hm, I guess this computer wasn't completely clean like I thought.<br><br>Spybot isn't showing anything that can't be removed. The only things that show up again are tracking cookies (casalemedia, doubleclick, mediaplex, zedo).<br><br>The first URL for Security Check shows not found, while the second URL also shows not found, but gives me a link to a SecurityCheck.exe file. If I should download that file instead, please let me know.<br><br><b>HijackThis log:</b><br><br>Logfile of Trend Micro HijackThis v2.0.2<br>Scan saved at 3:44:03 PM, on 5/24/2009<br>Platform: Windows XP SP3 (WinNT 5.01.2600)<br>MSIE: Internet Explorer v8.00 (8.00.6001.18702)<br>Boot mode: Normal<br><br>Running processes:<br>C:\WINDOWS\System32\smss.exe<br>C:\WINDOWS\system32\winlogon.exe<br>C:\WINDOWS\system32\services.exe<br>C:\WINDOWS\system32\lsass.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\WINDOWS\system32\spoolsv.exe<br>D:\AVG\AVG8\avgwdsvc.exe<br>C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe<br>C:\Program Files\Java\jre6\bin\jqs.exe<br>C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe<br>C:\PROGRA~1\COMMON~1\Stardock\SDMCP.exe<br>C:\WINDOWS\system32\nvsvc32.exe<br>C:\WINDOWS\system32\IoctlSvc.exe<br>C:\WINDOWS\system32\PnkBstrA.exe<br>C:\WINDOWS\system32\PnkBstrB.exe<br>C:\WINDOWS\system32\svchost.exe<br>D:\AVG\AVG8\avgrsx.exe<br>D:\AVG\AVG8\avgemc.exe<br>D:\AVG\AVG8\avgnsx.exe<br>D:\AVG\AVG8\avgcsrvx.exe<br>C:\WINDOWS\RTHDCPL.EXE<br>D:\AVG\AVG8\avgtray.exe<br>C:\WINDOWS\system32\RUNDLL32.EXE<br>C:\Program Files\Logitech\GamePanel Software\LgDevAgt.exe<br>C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe<br>C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe<br>C:\Program Files\Java\jre6\bin\jusched.exe<br>C:\WINDOWS\system32\ctfmon.exe<br>C:\Program Files\Messenger\msmsgs.exe<br>C:\Program Files\Logitech\GamePanel Software\LCD Manager\Applets\LCDClock.exe<br>C:\Program Files\Logitech\GamePanel Software\Applets\LCDCountdown.exe<br>C:\Program Files\Logitech\GamePanel Software\Applets\LCDRSS.exe<br>D:\Logitech\SetPoint\SetPoint.exe<br>C:\Program Files\WiFiConnector\NintendoWFCReg.exe<br>D:\Program Files\Stardock\ObjectDock\ObjectDock.exe<br>C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE<br>C:\WINDOWS\explorer.exe<br>D:\Mozilla Firefox\firefox.exe<br>C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br><br>R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=69157" >go.microsoft.com/fwlink/?LinkId=69157</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=69157" >go.microsoft.com/fwlink/?LinkId=69157</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=69157" >go.microsoft.com/fwlink/?LinkId=69157</A><br>R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=74005" >go.microsoft.com/fwlink/?LinkId=74005</A><br>O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll<br>O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - D:\AVG\AVG8\avgssie.dll<br>O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br>O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br>O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br>O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE<br>O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE<br>O4 - HKLM\..\Run: [AVG8_TRAY] D:\AVG\AVG8\avgtray.exe<br>O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup<br>O4 - HKLM\..\Run: [nwiz] nwiz.exe /install<br>O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit<br>O4 - HKLM\..\Run: [SNPSTD2] C:\WINDOWS\vsnpstd2.exe<br>O4 - HKLM\..\Run: [Launch LgDevAgt] "C:\Program Files\Logitech\GamePanel Software\LgDevAgt.exe"<br>O4 - HKLM\..\Run: [Launch LCDMon] "C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe"<br>O4 - HKLM\..\Run: [Launch LGDCore] "C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe" /SHOWHIDE<br>O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"<br>O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br>O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background<br>O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')<br>O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')<br>O4 - Startup: Stardock ObjectDock.lnk = D:\Program Files\Stardock\ObjectDock\ObjectDock.exe<br>O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe<br>O4 - Global Startup: Logitech SetPoint.lnk = D:\Logitech\SetPoint\SetPoint.exe<br>O4 - Global Startup: Run Nintendo Wi-Fi USB Connector Registration Tool.lnk = C:\Program Files\WiFiConnector\NintendoWFCReg.exe<br>O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000<br>O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL<br>O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br>O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br>O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - &raquo;<A HREF="http://gfx2.hotmail.com/mail/w3/resources/MSNPUpld.cab" >gfx2.hotmail.com/mail/w3/resourc&middot;&middot;&middot;Upld.cab</A><br>O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - &raquo;<A HREF="http://download.eset.com/special/eos/OnlineScanner.cab" >download.eset.com/special/eos/On&middot;&middot;&middot;nner.cab</A><br>O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - D:\AVG\AVG8\avgpp.dll<br>O20 - Winlogon Notify: !SASWinLogon - D:\SUPERAntiSpyware\SASWINLO.dll<br>O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll<br>O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - D:\Ares\chatServer.exe<br>O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - D:\AVG\AVG8\avgemc.exe<br>O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - D:\AVG\AVG8\avgwdsvc.exe<br>O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe<br>O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br>O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe<br>O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe<br>O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe<br>O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe<br>O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe<br>O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe<br>O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe<br>O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe<br>O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe<br>O23 - Service: SonicStage Back-End Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SsBeSvc.exe<br>O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe<br>O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe<br><br>--<br>End of file - 8123 bytes<br><br><b>ComboFix log:</b><br><br>ComboFix 09-05-23.04 - GHOST 05/24/2009 15:25.1 - NTFSx86<br>Microsoft Windows XP Professional  5.1.2600.3.1252.1.1033.18.2046.1382 [GMT -4:00]<br>Running from: c:\documents and settings\GHOST\Desktop\ComboFix.exe<br>AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}<br> * Created a new restore point<br>.<br><br>(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br><br>c:\documents and settings\GHOST\Local Settings\Temporary Internet Files\fbk.sts<br>c:\program files\WinPCap<br>c:\program files\WinPCap\rpcapd.exe<br>c:\temp\FT62<br>c:\windows\system32\biyedepu.dll<br>c:\windows\system32\dPI19<br>c:\windows\system32\drivers\npf.sys<br>c:\windows\system32\nugebini.dll<br>c:\windows\system32\Packet.dll<br>c:\windows\system32\pthreadVC.dll<br>c:\windows\system32\WanPacket.dll<br>c:\windows\system32\wpcap.dll<br>c:\windows\system32\yilefaju.exe<br><br>.<br>(((((((((((((((((((((((((((((((((((((((   Drivers/Services   )))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br><br>-------\Legacy_NPF<br>-------\Service_npf<br><br>(((((((((((((((((((((((((   Files Created from 2009-04-24 to 2009-05-24  )))))))))))))))))))))))))))))))<br>.<br><br>2009-05-22 17:20 . 2009-05-22 17:20&#9;--------&#9;d-sh--w&#9;c:\documents and settings\Administrator\IETldCache<br>2009-05-22 04:52 . 2009-05-22 04:52&#9;--------&#9;d-----w&#9;c:\program files\ESET<br>2009-05-22 04:49 . 2009-05-22 04:49&#9;--------&#9;d-sh--w&#9;c:\documents and settings\GHOST\IECompatCache<br>2009-05-22 04:49 . 2009-05-22 04:49&#9;--------&#9;d-sh--w&#9;c:\documents and settings\GHOST\PrivacIE<br>2009-05-22 04:45 . 2009-05-22 04:45&#9;--------&#9;d-sh--w&#9;c:\documents and settings\GHOST\IETldCache<br>2009-05-22 04:42 . 2009-05-22 04:42&#9;--------&#9;d-----w&#9;c:\windows\ie8updates<br>2009-05-22 04:41 . 2009-05-22 04:42&#9;--------&#9;dc-h--w&#9;c:\windows\ie8<br>2009-05-22 04:39 . 2009-04-25 05:30&#9;102400&#9;-c----w&#9;c:\windows\system32\dllcache\iecompat.dll<br>2009-05-22 03:03 . 2009-05-22 03:03&#9;152576&#9;----a-w&#9;c:\documents and settings\GHOST\Application Data\Sun\Java\jre1.6.0_13\lzma.dll<br>2009-05-22 03:02 . 2008-04-14 00:12&#9;18944&#9;-c--a-w&#9;c:\windows\system32\dllcache\xrxscnui.dll<br>2009-05-22 03:02 . 2008-04-14 00:12&#9;116224&#9;-c--a-w&#9;c:\windows\system32\dllcache\xrxwiadr.dll<br>2009-05-22 03:02 . 2001-08-18 02:36&#9;23040&#9;-c--a-w&#9;c:\windows\system32\dllcache\xrxwbtmp.dll<br>2009-05-22 03:02 . 2001-08-18 02:37&#9;4608&#9;-c--a-w&#9;c:\windows\system32\dllcache\xrxflnch.exe<br>2009-05-22 03:02 . 2001-08-18 02:37&#9;27648&#9;-c--a-w&#9;c:\windows\system32\dllcache\xrxftplt.exe<br>2009-05-22 03:00 . 2001-08-17 17:28&#9;64605&#9;-c--a-w&#9;c:\windows\system32\dllcache\vvoice.sys<br>2009-05-22 02:59 . 2001-08-17 16:51&#9;58368&#9;-c--a-w&#9;c:\windows\system32\dllcache\smiminib.sys<br>2009-05-22 02:57 . 2001-08-17 17:51&#9;17280&#9;-c--a-w&#9;c:\windows\system32\dllcache\scr111.sys<br>2009-05-22 02:56 . 2001-08-18 02:36&#9;41472&#9;-c--a-w&#9;c:\windows\system32\dllcache\qvusd.dll<br>2009-05-22 02:55 . 2008-04-13 18:54&#9;22016&#9;-c--a-w&#9;c:\windows\system32\dllcache\msircomm.sys<br>2009-05-22 02:54 . 2001-08-18 02:36&#9;372824&#9;-c--a-w&#9;c:\windows\system32\dllcache\iconf32.dll<br>2009-05-22 02:53 . 2001-08-17 16:12&#9;24618&#9;-c--a-w&#9;c:\windows\system32\dllcache\fa410nd5.sys<br>2009-05-22 02:52 . 2001-08-17 17:52&#9;7680&#9;-c--a-w&#9;c:\windows\system32\dllcache\cd20xrnt.sys<br>2009-05-22 02:51 . 2001-08-17 18:07&#9;101888&#9;-c--a-w&#9;c:\windows\system32\dllcache\adpu160m.sys<br>2009-05-22 02:38 . 2009-05-22 02:43&#9;--------&#9;d-----w&#9;C:\1b3f0d8e1e3ecd0efc101d94<br>2009-05-22 02:16 . 2009-05-22 02:16&#9;--------&#9;d-----w&#9;C:\[u]0[/u]9453ea7dd3061594a2e<br>2009-05-21 23:56 . 2009-04-06 19:32&#9;15504&#9;----a-w&#9;c:\windows\system32\drivers\mbam.sys<br>2009-05-21 23:56 . 2009-04-06 19:32&#9;38496&#9;----a-w&#9;c:\windows\system32\drivers\mbamswissarmy.sys<br>2009-05-21 12:30 . 2009-05-21 12:30&#9;2&#9;---h--w&#9;c:\windows\sto452730.dat<br>2009-05-20 04:57 . 2009-05-20 04:57&#9;2&#9;---h--w&#9;c:\windows\sto453251.dat<br>2009-05-20 04:57 . 2009-05-20 04:57&#9;2&#9;---h--w&#9;c:\windows\sto453224.dat<br>2009-05-20 02:57 . 2009-05-20 02:57&#9;2&#9;---h--w&#9;c:\windows\sto453250.dat<br>2009-05-18 19:58 . 2008-09-05 00:22&#9;447752&#9;----a-r&#9;c:\windows\system32\vp6vfw.dll<br>2009-05-18 19:58 . 2009-05-18 19:58&#9;10134&#9;----a-r&#9;c:\documents and settings\GHOST\Application Data\Microsoft\Installer\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}\ARPPRODUCTICON.exe<br>2009-05-18 19:58 . 2009-05-18 19:58&#9;--------&#9;d-----w&#9;c:\program files\Microsoft WSE<br>2009-05-18 16:02 . 2009-05-15 20:43&#9;2051864&#9;----a-w&#9;c:\documents and settings\All Users\Application Data\avg8\update\backup\avgcorex.dll<br>2009-05-18 16:02 . 2009-05-15 20:43&#9;354584&#9;----a-w&#9;c:\documents and settings\All Users\Application Data\avg8\update\backup\avgxch32.dll<br>2009-05-18 16:02 . 2009-05-15 20:43&#9;3288344&#9;----a-w&#9;c:\documents and settings\All Users\Application Data\avg8\update\backup\setup.exe<br>2009-05-18 16:02 . 2009-05-15 20:43&#9;424472&#9;----a-w&#9;c:\documents and settings\All Users\Application Data\avg8\update\backup\avgwdwsc.dll<br>2009-05-18 16:02 . 2009-05-15 20:43&#9;312088&#9;----a-w&#9;c:\documents and settings\All Users\Application Data\avg8\update\backup\avglngx.dll<br>2009-05-18 16:02 . 2009-05-15 20:43&#9;177432&#9;----a-w&#9;c:\documents and settings\All Users\Application Data\avg8\update\backup\avgmail.dll<br>2009-05-18 16:02 . 2009-05-15 20:43&#9;486168&#9;----a-w&#9;c:\documents and settings\All Users\Application Data\avg8\update\backup\avgrsx.exe<br>2009-05-18 16:01 . 2009-05-15 20:42&#9;1437464&#9;----a-w&#9;c:\documents and settings\All Users\Application Data\avg8\update\backup\avgupd.dll<br>2009-05-18 16:01 . 2009-05-15 20:42&#9;755992&#9;----a-w&#9;c:\documents and settings\All Users\Application Data\avg8\update\backup\avginet.dll<br>2009-05-10 15:22 . 2009-05-10 15:22&#9;--------&#9;d-----w&#9;c:\program files\Logitech<br>2009-04-29 21:19 . 2009-04-29 21:19&#9;41808&#9;----a-w&#9;c:\windows\system32\xfcodec.dll<br>2009-04-25 15:42 . 2009-05-24 18:57&#9;117760&#9;----a-w&#9;c:\documents and settings\GHOST\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL<br><br>.<br>((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br>2009-05-22 23:16 . 2008-05-22 18:55&#9;75272&#9;----a-w&#9;c:\documents and settings\GHOST\Local Settings\Application Data\GDIPFONTCACHEV1.DAT<br>2009-05-22 03:04 . 2009-05-22 03:04&#9;57344&#9;----a-w&#9;c:\documents and settings\GHOST\Application Data\Sun\Java\Deployment\cache\6.0\50\5b902232-28a5d86d-n\Decora-SSE.dll<br>2009-05-22 03:04 . 2009-05-22 03:04&#9;24064&#9;----a-w&#9;c:\documents and settings\GHOST\Application Data\Sun\Java\Deployment\cache\6.0\15\4e09eacf-7ab017e2-n\Decora-D3D.dll<br>2009-05-22 03:04 . 2009-05-22 03:04&#9;315392&#9;----a-w&#9;c:\documents and settings\GHOST\Application Data\Sun\Java\Deployment\cache\6.0\62\6baea4fe-45bb53eb-n\jogl.dll<br>2009-05-22 03:04 . 2009-05-22 03:04&#9;20480&#9;----a-w&#9;c:\documents and settings\GHOST\Application Data\Sun\Java\Deployment\cache\6.0\62\6baea4fe-45bb53eb-n\jogl_awt.dll<br>2009-05-22 03:04 . 2009-05-22 03:04&#9;114688&#9;----a-w&#9;c:\documents and settings\GHOST\Application Data\Sun\Java\Deployment\cache\6.0\62\6baea4fe-45bb53eb-n\jogl_cg.dll<br>2009-05-22 03:04 . 2009-05-22 03:04&#9;499712&#9;----a-w&#9;c:\documents and settings\GHOST\Application Data\Sun\Java\Deployment\cache\6.0\33\258cea61-7f83bb7b-n\msvcp71.dll<br>2009-05-22 03:04 . 2009-05-22 03:04&#9;499712&#9;----a-w&#9;c:\documents and settings\GHOST\Application Data\Sun\Java\Deployment\cache\6.0\33\258cea61-7f83bb7b-n\jmc.dll<br>2009-05-22 03:04 . 2009-05-22 03:04&#9;348160&#9;----a-w&#9;c:\documents and settings\GHOST\Application Data\Sun\Java\Deployment\cache\6.0\33\258cea61-7f83bb7b-n\msvcr71.dll<br>2009-05-22 03:04 . 2009-05-22 03:04&#9;20480&#9;----a-w&#9;c:\documents and settings\GHOST\Application Data\Sun\Java\Deployment\cache\6.0\45\4f710eed-520ec009-n\gluegen-rt.dll<br>2009-05-22 03:04 . 2009-05-22 03:04&#9;410984&#9;----a-w&#9;c:\windows\system32\deploytk.dll<br>2009-05-22 03:04 . 2008-05-22 19:56&#9;--------&#9;d-----w&#9;c:\program files\Java<br>2009-05-22 02:47 . 2008-12-14 00:45&#9;--------&#9;d-----w&#9;c:\documents and settings\All Users\Application Data\Microsoft Help<br>2009-05-22 00:46 . 2008-07-16 18:09&#9;--------&#9;d-----w&#9;c:\program files\Common Files\Wise Installation Wizard<br>2009-05-22 00:45 . 2008-06-07 20:10&#9;--------&#9;d-----w&#9;c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy<br>2009-05-21 23:17 . 2008-05-23 02:10&#9;--------&#9;d-----w&#9;c:\documents and settings\GHOST\Application Data\Xfire<br>2009-05-20 02:09 . 2008-05-23 23:18&#9;--------&#9;d-----w&#9;c:\documents and settings\All Users\Application Data\avg8<br>2009-05-18 19:43 . 2008-05-22 06:26&#9;--------&#9;d--h--w&#9;c:\program files\InstallShield Installation Information<br>2009-05-18 18:43 . 2008-05-24 00:40&#9;189496&#9;----a-w&#9;c:\windows\system32\PnkBstrB.exe<br>2009-05-18 18:20 . 2008-05-24 00:40&#9;139984&#9;----a-w&#9;c:\windows\system32\drivers\PnkBstrK.sys<br>2009-05-15 20:43 . 2008-05-23 23:18&#9;11952&#9;----a-w&#9;c:\windows\system32\avgrsstx.dll<br>2009-05-15 20:43 . 2008-05-23 23:18&#9;325896&#9;----a-w&#9;c:\windows\system32\drivers\avgldx86.sys<br>2009-05-15 20:43 . 2008-05-23 23:18&#9;27784&#9;----a-w&#9;c:\windows\system32\drivers\avgmfx86.sys<br>2009-05-15 20:43 . 2008-05-23 23:18&#9;108552&#9;----a-w&#9;c:\windows\system32\drivers\avgtdix.sys<br>2009-05-13 03:27 . 2008-06-12 00:58&#9;--------&#9;d---a-w&#9;c:\documents and settings\All Users\Application Data\TEMP<br>2009-05-10 15:22 . 2008-05-22 23:01&#9;--------&#9;d-----w&#9;c:\documents and settings\All Users\Application Data\Logitech<br>2009-04-22 04:20 . 2009-04-22 04:20&#9;14311680&#9;----a-w&#9;c:\windows\system32\xlive.dll<br>2009-04-22 04:20 . 2009-04-22 04:20&#9;13642496&#9;----a-w&#9;c:\windows\system32\xlivefnt.dll<br>2009-04-19 01:43 . 2009-04-19 01:43&#9;--------&#9;d-----w&#9;c:\program files\Common Files\snpstd2<br>2009-04-19 01:22 . 2009-04-19 01:22&#9;--------&#9;d-----w&#9;c:\program files\Windows Live Safety Center<br>2009-04-15 19:31 . 2009-04-23 00:06&#9;1099128&#9;----a-w&#9;c:\documents and settings\GHOST\Application Data\Mozilla\Firefox\Profiles\1nrtpfvv.default\extensions\battlefieldheroespatcher@ea.com\platform\WINNT_x86-msvc\plugins\BFHUpdater.exe<br>2009-04-15 19:31 . 2009-04-23 00:06&#9;729088&#9;----a-w&#9;c:\documents and settings\GHOST\Application Data\Mozilla\Firefox\Profiles\1nrtpfvv.default\extensions\battlefieldheroespatcher@ea.com\platform\WINNT_x86-msvc\plugins\npBFHUpdater.dll<br>2009-04-11 04:24 . 2009-04-11 04:24&#9;--------&#9;d-----w&#9;c:\program files\Common Files\Digidesign<br>2009-03-14 06:10 . 2008-06-12 00:42&#9;905776&#9;----a-w&#9;c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat<br>2009-03-13 22:32 . 2008-05-24 00:40&#9;75064&#9;----a-w&#9;c:\windows\system32\PnkBstrA.exe<br>2009-03-08 08:34 . 2007-12-07 02:01&#9;914944&#9;----a-w&#9;c:\windows\system32\wininet.dll<br>2009-03-08 08:34 . 2007-12-12 09:51&#9;43008&#9;----a-w&#9;c:\windows\system32\licmgr10.dll<br>2009-03-08 08:33 . 2007-12-12 09:51&#9;18944&#9;----a-w&#9;c:\windows\system32\corpol.dll<br>2009-03-08 08:33 . 2007-12-12 09:51&#9;420352&#9;----a-w&#9;c:\windows\system32\vbscript.dll<br>2009-03-08 08:32 . 2007-12-12 09:51&#9;72704&#9;----a-w&#9;c:\windows\system32\admparse.dll<br>2009-03-08 08:32 . 2007-12-12 09:51&#9;71680&#9;----a-w&#9;c:\windows\system32\iesetup.dll<br>2009-03-08 08:31 . 2007-05-11 04:54&#9;34816&#9;----a-w&#9;c:\windows\system32\imgutil.dll<br>2009-03-08 08:31 . 2007-12-12 09:51&#9;48128&#9;----a-w&#9;c:\windows\system32\mshtmler.dll<br>2009-03-08 08:31 . 2007-12-12 09:51&#9;45568&#9;----a-w&#9;c:\windows\system32\mshta.exe<br>2009-03-08 08:22 . 2007-12-12 09:51&#9;156160&#9;----a-w&#9;c:\windows\system32\msls31.dll<br>2009-03-06 14:22 . 2004-08-04 12:00&#9;284160&#9;----a-w&#9;c:\windows\system32\pdh.dll<br>.<br><br>(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br>.<br>*Note* empty entries & legit default entries are not shown <br>REGEDIT4<br><br>[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<br>"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]<br>"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]<br><br>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<br>"AVG8_TRAY"="d:\avg\AVG8\avgtray.exe" [2009-05-15 1947928]<br>"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-03 13529088]<br>"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-03 86016]<br>"SNPSTD2"="c:\windows\vsnpstd2.exe" [2004-01-05 40960]<br>"Launch LgDevAgt"="c:\program files\Logitech\GamePanel Software\LgDevAgt.exe" [2008-11-06 358920]<br>"Launch LCDMon"="c:\program files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe" [2008-11-06 1548296]<br>"Launch LGDCore"="c:\program files\Logitech\GamePanel Software\G-series Software\LGDCore.exe" [2008-11-06 2816520]<br>"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-05-22 148888]<br>"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2008-02-13 16857600]<br>"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" - c:\windows\KHALMNPR.Exe [2008-02-29 76304]<br>"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2008-05-03 1630208]<br><br>[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]<br>"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-08-24 437160]<br><br>c:\documents and settings\GHOST\Start Menu\Programs\Startup\<br>Stardock ObjectDock.lnk - d:\program files\Stardock\ObjectDock\ObjectDock.exe [2008-6-11 2860792]<br><br>c:\documents and settings\All Users\Start Menu\Programs\Startup\<br>Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-5-23 113664]<br>Logitech SetPoint.lnk - d:\logitech\SetPoint\SetPoint.exe [2008-5-22 805392]<br>Run Nintendo Wi-Fi USB Connector Registration Tool.lnk - c:\program files\WiFiConnector\NintendoWFCReg.exe [2008-7-15 1073152]<br><br>[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]<br>"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "d:\superantispyware\SASSEH.DLL" [2008-05-13 77824]<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]<br>2008-12-22 16:05&#9;356352&#9;----a-w&#9;d:\superantispyware\SASWINLO.dll<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]<br>2008-05-02 06:42&#9;72208&#9;----a-w&#9;c:\program files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\MCPClient]<br>2005-01-31 18:13&#9;49152&#9;----a-w&#9;c:\progra~1\COMMON~1\Stardock\MCPStub.dll<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]<br>2009-05-15 20:43&#9;11952&#9;----a-w&#9;c:\windows\system32\avgrsstx.dll<br><br>[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]<br>@=""<br><br>[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Belkin Wireless G Desktop Card Client Utility.lnk]<br>path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Belkin Wireless G Desktop Card Client Utility.lnk<br>backup=c:\windows\pss\Belkin Wireless G Desktop Card Client Utility.lnkCommon Startup<br><br>[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]<br>"%windir%\\Network Diagnostic\\xpnetdiag.exe"=<br>"%windir%\\system32\\sessmgr.exe"=<br>"d:\\Crysis\\Bin32\\Crysis.exe"=<br>"d:\\Crysis\\Bin32\\CrysisDedicatedServer.exe"=<br>"d:\\Xfire\\xfire.exe"=<br>"d:\\AVG\\AVG8\\avgupd.exe"=<br>"d:\\AVG\\AVG8\\avgemc.exe"=<br>"d:\\Ares\\Ares.exe"=<br>"d:\\Battlefield2\\BF2.exe"=<br>"c:\\WINDOWS\\system32\\PnkBstrA.exe"=<br>"c:\\WINDOWS\\system32\\PnkBstrB.exe"=<br>"d:\\Grid\\GRID.exe"=<br>"c:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"=<br>"d:\nexon\Combat Arms\CombatArms.exe"= d:\nexon\Combat Arms\CombatArms.exe:*Enabled:CombatArms.exe<br>"d:\nexon\Combat Arms\Engine.exe"= d:\nexon\Combat Arms\Engine.exe:*Enabled:Engine.exe<br>"d:\\Nexon\\Combat Arms\\NMService.exe"=<br>"d:\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=<br>"d:\\StarWarsBattlefront2\\GameData\\BattlefrontII.exe"=<br>"c:\\Program Files\\Electronic Arts\\EADM\\Core.exe"=<br>"d:\\Battlefield2142\\BF2142.exe"=<br>"c:\\Program Files\\WiFiConnector\\NintendoWFCReg.exe"=<br>"d:\\Unreal Tournament 3\\Binaries\\UT3.exe"=<br>"d:\\Kane and Lynch\\kaneandlynch.exe"=<br>"d:\\Pure\\Pure.exe"=<br>"d:\\FarCry2\\Far Cry 2\\bin\\FarCry2.exe"=<br>"d:\\FarCry2\\Far Cry 2\\bin\\FC2Launcher.exe"=<br>"d:\\FarCry2\\Far Cry 2\\bin\\FC2Editor.exe"=<br>"d:\\Dead Space\\Dead Space.exe"=<br>"d:\\[u]0[/u]07 -Quantum of Solace\\JB_LiveEngine_s.exe"=<br>"c:\\Documents and Settings\\GHOST\\Local Settings\\Application Data\\Dyyno Receiver\\DPPM.exe"=<br>"d:\\Mozilla Firefox\\firefox.exe"=<br>"d:\\GTAIV\\Rockstar Games Social Club\\RGSCLauncher.exe"=<br>"d:\\GTAIV\\Grand Theft Auto IV\\LaunchGTAIV.exe"=<br>"d:\\GTAIV\\Grand Theft Auto IV\\GTAIV.exe"=<br>"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=<br>"d:\\Saints Row 2\\SR2_pc.exe"=<br>"d:\\Burnout Paradise\\BurnoutLauncher.exe"=<br>"d:\\Burnout Paradise\\BurnoutConfigTool.exe"=<br>"d:\\Burnout Paradise\\BurnoutParadise.exe"=<br>"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=<br>"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=<br>"d:\\TomClancy's HAWX\\HAWX.exe"=<br>"d:\\Call Of Duty - WAW\\CoDWaW.exe"=<br>"d:\\Call Of Duty - WAW\\CoDWaWmp.exe"=<br>"d:\\VLC Player\\VLC\\vlc.exe"=<br>"c:\\WINDOWS\\system32\\dwwin.exe"=<br>"c:\\Program Files\\Common Files\\Logishrd\\KHAL2\\KHALMNPR.exe"=<br>"d:\\AVG\\AVG8\\avgnsx.exe"=<br><br>R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [5/23/2008 7:18 PM 325896]<br>R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [5/23/2008 7:18 PM 108552]<br>R1 SASDIFSV;SASDIFSV;d:\superantispyware\sasdifsv.sys [5/14/2009 2:22 PM 9968]<br>R1 SASKUTIL;SASKUTIL;d:\superantispyware\SASKUTIL.SYS [5/14/2009 2:22 PM 72944]<br>R2 avg8emc;AVG8 E-mail Scanner;d:\avg\AVG8\avgemc.exe [7/4/2008 12:17 PM 908568]<br>R2 avg8wd;AVG8 WatchDog;d:\avg\AVG8\avgwdsvc.exe [7/4/2008 12:17 PM 298776]<br>R2 BcmSqlStartupSvc;Business Contact Manager SQL Server Startup Service;c:\program files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe [1/11/2008 6:50 PM 30312]<br>R3 MSSQL$MSSMLBIZ;SQL Server (MSSMLBIZ);c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [8/5/2008 6:58 PM 29184016]<br>S3 Belkin700F;Belkin Wireless G Desktop Card Service v7;c:\windows\system32\drivers\BLKWGDv7.sys [6/7/2008 3:46 PM 303616]<br>S3 DJUSB;DMM Controller;c:\windows\system32\drivers\DM2.sys [6/1/2001 7:26 PM 10758]<br>S3 MBAMCatchMe;MBAMCatchMe;\??\c:\windows\system32\drivers\mbamcatchme.sys --> c:\windows\system32\drivers\mbamcatchme.sys [?]<br>S3 PLCMP532;PLCMP532 NDIS Protocol Driver;c:\windows\system32\Drivers\PLCMP532.sys --> c:\windows\system32\Drivers\PLCMP532.sys [?]<br>S3 PLCND532;PLCND532 NDIS Protocol Driver;c:\windows\system32\drivers\PLCND532.sys [8/8/2007 11:40 AM 26656]<br>S3 SASENUM;SASENUM;d:\superantispyware\SASENUM.SYS [5/14/2009 2:22 PM 7408]<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]<br>"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP<br>.<br>Contents of the 'Scheduled Tasks' folder<br><br>2009-05-21 c:\windows\Tasks\AppleSoftwareUpdate.job<br>- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]<br>.<br>- - - - ORPHANS REMOVED - - - -<br><br>SafeBoot-procexp90.Sys<br><br>.<br>------- Supplementary Scan -------<br>.<br>IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000<br>DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab<br>FF - ProfilePath - c:\documents and settings\GHOST\Application Data\Mozilla\Firefox\Profiles\1nrtpfvv.default\<br>FF - prefs.js: browser.startup.homepage - hxxp://www.google.ca/<br>FF - component: d:\avg\AVG8\Firefox\components\avgssff.dll<br>FF - plugin: c:\documents and settings\All Users\Application Data\NexonUS\NGM\npNxGameUS.dll<br>FF - plugin: c:\documents and settings\GHOST\Application Data\Mozilla\Firefox\Profiles\1nrtpfvv.default\extensions\battlefieldheroespatcher@ea.com\platform\WINNT_x86-msvc\plugins\npBFHUpdater.dll<br>FF - plugin: c:\documents and settings\GHOST\Application Data\Mozilla\Firefox\Profiles\1nrtpfvv.default\extensions\NPDyyno@dyyno.com\plugins\npDyyno.dll<br>FF - plugin: c:\program files\Dyyno\Dyyno Player\npvlc.dll<br>FF - plugin: d:\divx\DivX Player\npDivxPlayerPlugin.dll<br>FF - plugin: d:\divx\DivX Web Player\npdivx32.dll<br>FF - plugin: d:\mozilla firefox\plugins\npff_gdm.dll<br>FF - plugin: d:\quicktime\Plugins\npqtplugin.dll<br>FF - plugin: d:\quicktime\Plugins\npqtplugin2.dll<br>FF - plugin: d:\quicktime\Plugins\npqtplugin3.dll<br>FF - plugin: d:\quicktime\Plugins\npqtplugin4.dll<br>FF - plugin: d:\quicktime\Plugins\npqtplugin5.dll<br>FF - plugin: d:\quicktime\Plugins\npqtplugin6.dll<br>FF - plugin: d:\quicktime\Plugins\npqtplugin7.dll<br>.<br><br>**************************************************************************<br><br>catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, &raquo;<A HREF="http://www.gmer.net" >www.gmer.net</A><br>Rootkit scan 2009-05-24 15:28<br>Windows 5.1.2600 Service Pack 3 NTFS<br><br>scanning hidden processes ...  <br><br>scanning hidden autostart entries ... <br><br>scanning hidden files ...  <br><br>scan completed successfully<br>hidden files: 0<br><br>**************************************************************************<br>.<br>--------------------- LOCKED REGISTRY KEYS ---------------------<br><br>[HKEY_USERS\S-1-5-21-1547161642-725345543-691866490-1003\Software\SecuROM\License information*]<br>"datasecu"=hex:18,f0,3f,fa,d3,bd,37,26,32,b5,57,94,95,cd,b4,61,62,2a,98,0f,ce,<br>   83,51,75,e8,36,00,dc,9e,f8,e9,be,9c,cd,c2,0c,1a,d6,59,7e,a1,67,7c,b4,6a,a9,\<br>"rkeysecu"=hex:c6,86,bc,a9,69,07,42,42,5b,31,fd,9b,ee,e1,ef,04<br>.<br>--------------------- DLLs Loaded Under Running Processes ---------------------<br><br>- - - - - - - > 'winlogon.exe'(716)<br>d:\superantispyware\SASWINLO.dll<br>c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll<br>c:\progra~1\COMMON~1\Stardock\mcpstub.dll<br>c:\program files\common files\logishrd\bluetooth\LBTServ.dll<br><br>- - - - - - - > 'explorer.exe'(2400)<br>d:\program files\Stardock\ObjectDock\DockShellHook.dll<br>d:\logitech\SetPoint\GameHook.dll<br>d:\logitech\SetPoint\lgscroll.dll<br>c:\progra~1\WINDOW~2\wmpband.dll<br>c:\windows\system32\msi.dll<br>c:\windows\system32\ieframe.dll<br>c:\windows\system32\OneX.DLL<br>c:\windows\system32\eappprxy.dll<br>c:\progra~1\COMMON~1\Stardock\MCPCore.dll<br>c:\windows\system32\webcheck.dll<br>c:\windows\system32\WPDShServiceObj.dll<br>c:\windows\system32\PortableDeviceTypes.dll<br>c:\windows\system32\PortableDeviceApi.dll<br>.<br>------------------------ Other Running Processes ------------------------<br>.<br>c:\program files\Java\jre6\bin\jqs.exe<br>c:\program files\Nero\Nero8\Nero BackItUp\NBService.exe<br>c:\progra~1\COMMON~1\Stardock\SDMCP.exe<br>c:\windows\system32\nvsvc32.exe<br>c:\windows\system32\IoctlSvc.exe<br>c:\windows\system32\PnkBstrA.exe<br>c:\windows\system32\PnkBstrB.exe<br>d:\avg\AVG8\avgrsx.exe<br>d:\avg\AVG8\avgnsx.exe<br>d:\avg\AVG8\avgcsrvx.exe<br>c:\windows\system32\wscntfy.exe<br>c:\windows\system32\rundll32.exe<br>c:\program files\Logitech\GamePanel Software\LCD Manager\Applets\LCDClock.exe<br>c:\program files\Logitech\GamePanel Software\Applets\LCDCountdown.exe<br>c:\program files\Logitech\GamePanel Software\Applets\LCDRSS.exe<br>c:\program files\Common Files\Logishrd\KHAL2\KHALMNPR.exe<br>.<br>**************************************************************************<br>.<br>Completion time: 2009-05-24 15:30 - machine was rebooted<br>ComboFix-quarantined-files.txt  2009-05-24 19:30<br><br>Pre-Run: 6,800,150,528 bytes free<br>Post-Run: 7,068,229,632 bytes free<br><br>WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe<br>[boot loader]<br>timeout=2<br>default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS<br>[operating systems]<br>c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons<br>multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect<br><br>332&#9;--- E O F ---&#9;2009-05-22 02:48]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22437167</guid>
<pubDate>Sun, 24 May 2009 16:29:47 EDT</pubDate>
</item>

<item>
<title>Re: HJT Log: &#x22;System Security&#x22;, Vundo, Koobface</title>
<link>http://www.dslreports.com/forum/remark,22432409</link>
<description><![CDATA[<A HREF="/useremail/u/377471"><b>TheJoker</b></A> : Everything looks good in those two logs, but I'd like to see the results of two other utilities before we declare success.<br><br>Download <b>ComboFix&copy; by sUBs</b> from one of these locations:<br><br><textarea name="code" class="text" cols=50 rows=10>http://download.bleepingcomputer.com/sUBs/ComboFix.exe&#012;http://www.forospyware.com/sUBs/ComboFix.exe&#012;http://subs.geekstogo.com/ComboFix.exe&#012;</textarea><!--end code block--><br><b>* IMPORTANT !!! Save ComboFix.exe to your Desktop</b><br><br>Familiarize yourself with ComboFix before running it:<br>&raquo;<A HREF="http://www.bleepingcomputer.com/combofix/how-to-use-combofix" >www.bleepingcomputer.com/combofi&middot;&middot;&middot;combofix</A><br><br>- Disable your AntiVirus and any AntiSpyware programs you may be running (usually via a right click on the System Tray icon) to prevent them from interfering.<br><br>- Double click on ComboFix.exe & follow the prompts.<br><br>- As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal.  It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware. <br><br>- Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.<br><br>**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.<br><br> <IMG SRC="http://img.photobucket.com/albums/v706/ried7/RcAuto1.gif"> <br><br>Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:<br><br> <IMG SRC="http://img.photobucket.com/albums/v706/ried7/whatnext.png"> <br><br>Click on Yes, to continue scanning for malware. When finished, it will save a log. <br>Please include the contents of the log at <b>C:\ComboFix.txt</b> in your next reply.<br><br>Download <b>Security Check</b> by screen317 and save it to your Desktop:<br><textarea name="code" class="text" cols=50 rows=10>http://screen317.spywareinfoforum.org/SecurityCheck.zip&#012;http://screen317.changelog.fr/SecurityCheck.zip&#012;</textarea><!--end code block-->- Unzip <b>SecurityCheck.zip</b> and a folder named <b>Security Check</b> should appear.<br> Open the <b>Security Check</b> folder and double-click <b>Security Check.bat</b><br> Follow the onscreen instructions inside of the black box.<br>- A Notepad document should open automatically called  <b>checkup.txt</b>; please post the contents of that  document.<br><br>In the beginning of your topic you posted contents from a Spybot Search & Destroy log. When you scan with that now (after checking for updates), is there anything detected that's in red that cannot be fixed?<br><br>Please post a new HijackThis log, the contents of the log from Security Check (checkup.txt), the log from ComboFix (combofix.txt), and note any errors encountered.<br><br><small>--<br>Proud ASAP member since 2005</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22432409</guid>
<pubDate>Sat, 23 May 2009 08:22:27 EDT</pubDate>
</item>

<item>
<title>Re: HJT Log: &#x22;System Security&#x22;, Vundo, Koobface</title>
<link>http://www.dslreports.com/forum/remark,22431418</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : I was unable to locate any of the files or folders you mentioned, I believe they may have been there during a previous infection.<br><br><b>HijackThis log:</b><br><br>Logfile of Trend Micro HijackThis v2.0.2<br>Scan saved at 10:21:48 PM, on 5/22/2009<br>Platform: Windows XP SP3 (WinNT 5.01.2600)<br>MSIE: Internet Explorer v8.00 (8.00.6001.18702)<br>Boot mode: Normal<br><br>Running processes:<br>C:\WINDOWS\System32\smss.exe<br>C:\WINDOWS\system32\winlogon.exe<br>C:\WINDOWS\system32\services.exe<br>C:\WINDOWS\system32\lsass.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\WINDOWS\system32\spoolsv.exe<br>D:\AVG\AVG8\avgwdsvc.exe<br>C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe<br>C:\Program Files\Java\jre6\bin\jqs.exe<br>C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe<br>C:\PROGRA~1\COMMON~1\Stardock\SDMCP.exe<br>C:\WINDOWS\system32\nvsvc32.exe<br>C:\WINDOWS\system32\IoctlSvc.exe<br>C:\WINDOWS\system32\PnkBstrA.exe<br>C:\WINDOWS\system32\PnkBstrB.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\WINDOWS\Explorer.EXE<br>D:\AVG\AVG8\avgemc.exe<br>D:\AVG\AVG8\avgrsx.exe<br>D:\AVG\AVG8\avgnsx.exe<br>C:\WINDOWS\RTHDCPL.EXE<br>D:\AVG\AVG8\avgtray.exe<br>C:\WINDOWS\system32\RUNDLL32.EXE<br>C:\WINDOWS\vsnpstd2.exe<br>C:\Program Files\Logitech\GamePanel Software\LgDevAgt.exe<br>C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe<br>C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe<br>C:\Program Files\Java\jre6\bin\jusched.exe<br>C:\WINDOWS\system32\ctfmon.exe<br>C:\Program Files\Messenger\msmsgs.exe<br>C:\Program Files\Logitech\GamePanel Software\LCD Manager\Applets\LCDClock.exe<br>C:\Program Files\Logitech\GamePanel Software\Applets\LCDCountdown.exe<br>D:\Logitech\SetPoint\SetPoint.exe<br>C:\Program Files\Logitech\GamePanel Software\Applets\LCDPop3.exe<br>C:\Program Files\Logitech\GamePanel Software\Applets\LCDRSS.exe<br>C:\Program Files\WiFiConnector\NintendoWFCReg.exe<br>C:\Program Files\Logitech\GamePanel Software\Applets\LCDMedia.exe<br>D:\AVG\AVG8\avgcsrvx.exe<br>D:\Program Files\Stardock\ObjectDock\ObjectDock.exe<br>C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE<br>C:\WINDOWS\system32\wuauclt.exe<br>D:\Mozilla Firefox\firefox.exe<br>C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br><br>R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=69157" >go.microsoft.com/fwlink/?LinkId=69157</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=69157" >go.microsoft.com/fwlink/?LinkId=69157</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=69157" >go.microsoft.com/fwlink/?LinkId=69157</A><br>R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=74005" >go.microsoft.com/fwlink/?LinkId=74005</A><br>O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll<br>O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - D:\AVG\AVG8\avgssie.dll<br>O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br>O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br>O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br>O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE<br>O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE<br>O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE<br>O4 - HKLM\..\Run: [AVG8_TRAY] D:\AVG\AVG8\avgtray.exe<br>O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup<br>O4 - HKLM\..\Run: [nwiz] nwiz.exe /install<br>O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit<br>O4 - HKLM\..\Run: [SNPSTD2] C:\WINDOWS\vsnpstd2.exe<br>O4 - HKLM\..\Run: [Launch LgDevAgt] "C:\Program Files\Logitech\GamePanel Software\LgDevAgt.exe"<br>O4 - HKLM\..\Run: [Launch LCDMon] "C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe"<br>O4 - HKLM\..\Run: [Launch LGDCore] "C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe" /SHOWHIDE<br>O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"<br>O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br>O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background<br>O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')<br>O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')<br>O4 - Startup: Stardock ObjectDock.lnk = D:\Program Files\Stardock\ObjectDock\ObjectDock.exe<br>O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe<br>O4 - Global Startup: Logitech SetPoint.lnk = D:\Logitech\SetPoint\SetPoint.exe<br>O4 - Global Startup: Run Nintendo Wi-Fi USB Connector Registration Tool.lnk = C:\Program Files\WiFiConnector\NintendoWFCReg.exe<br>O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000<br>O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL<br>O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br>O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br>O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - &raquo;<A HREF="http://gfx2.hotmail.com/mail/w3/resources/MSNPUpld.cab" >gfx2.hotmail.com/mail/w3/resourc&middot;&middot;&middot;Upld.cab</A><br>O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - &raquo;<A HREF="http://download.eset.com/special/eos/OnlineScanner.cab" >download.eset.com/special/eos/On&middot;&middot;&middot;nner.cab</A><br>O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - D:\AVG\AVG8\avgpp.dll<br>O20 - Winlogon Notify: !SASWinLogon - D:\SUPERAntiSpyware\SASWINLO.dll<br>O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll<br>O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - D:\Ares\chatServer.exe<br>O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - D:\AVG\AVG8\avgemc.exe<br>O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - D:\AVG\AVG8\avgwdsvc.exe<br>O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe<br>O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br>O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe<br>O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe<br>O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe<br>O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe<br>O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe<br>O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe<br>O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe<br>O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe<br>O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe<br>O23 - Service: SonicStage Back-End Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SsBeSvc.exe<br>O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe<br>O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe<br><br>--<br>End of file - 8466 bytes<br><br><b>MBAM log:</b><br><br>Malwarebytes' Anti-Malware 1.36<br>Database version: 2168<br>Windows 5.1.2600 Service Pack 3<br><br>5/22/2009 7:08:04 PM<br>mbam-log-2009-05-22 (19-08-04).txt<br><br>Scan type: Quick Scan<br>Objects scanned: 87541<br>Time elapsed: 2 minute(s), 42 second(s)<br><br>Memory Processes Infected: 0<br>Memory Modules Infected: 0<br>Registry Keys Infected: 0<br>Registry Values Infected: 0<br>Registry Data Items Infected: 0<br>Folders Infected: 0<br>Files Infected: 0<br><br>Memory Processes Infected:<br>(No malicious items detected)<br><br>Memory Modules Infected:<br>(No malicious items detected)<br><br>Registry Keys Infected:<br>(No malicious items detected)<br><br>Registry Values Infected:<br>(No malicious items detected)<br><br>Registry Data Items Infected:<br>(No malicious items detected)<br><br>Folders Infected:<br>(No malicious items detected)<br><br>Files Infected:<br>(No malicious items detected)<br><br><b>Kaspersky log:</b><br><br>--------------------------------------------------------------------------------<br>KASPERSKY ONLINE SCANNER 7.0 REPORT<br> Friday, May 22, 2009<br> Operating System: Microsoft Windows XP Professional Service Pack 3 (build 2600)<br> Kaspersky Online Scanner  version: 7.0.26.13<br> Program database last update: Friday, May 22, 2009 22:24:12<br> Records in database: 2219720<br>--------------------------------------------------------------------------------<br><br>Scan settings:<br>&#9;Scan using the following database: extended<br>&#9;Scan archives: yes<br>&#9;Scan mail databases: yes<br><br>Scan area - My Computer:<br>&#9;C:\<br>&#9;D:\<br>&#9;E:\<br><br>Scan statistics:<br>&#9;Files scanned: 176310<br>&#9;Threat name: 0<br>&#9;Infected objects: 0<br>&#9;Suspicious objects: 0<br>&#9;Duration of the scan: 02:15:56<br><br>No malware has been detected. The scan area is clean.<br><br>The selected area was scanned.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22431418</guid>
<pubDate>Fri, 22 May 2009 22:26:25 EDT</pubDate>
</item>

<item>
<title>Re: HJT Log: &#x22;System Security&#x22;, Vundo, Koobface</title>
<link>http://www.dslreports.com/forum/remark,22430518</link>
<description><![CDATA[<A HREF="/useremail/u/377471"><b>TheJoker</b></A> : Hi trhgbtrh4<br><br>I suggest printing out each set of instructions and reading the entire post before proceeding. It will make following them easier. Please follow the directions in the order listed.<br><br>Clean your Cache and Cookies in IE:<br>-Close all instances of Outlook Express and Internet Explorer <br>-Go to Control Panel > Internet Options > General tab<br>-Click the "Delete Cookies" button<br>-Next to it, Click the "Delete Files" button<br>-When prompted, place a check in: "Delete all offline content", click OK<br>Clean your Cache and Cookies in Firefox (In case you also have Firefox installed):<br>Go to Tools > Options.<br>Click Privacy in the menu on the left side of the Options window.<br>Click the Clear button located to the right of each option (History, Cookies, Private Data).<br>Click OK to close the Options window<br>Alternatively, you can clear all information stored while browsing by clicking Clear All. <br>A confirmation dialog box will be shown before clearing the information.<br>Clean other Temporary files + Recycle bin<br>-Go to start > run and type: <b>cleanmgr</b> and click ok.<br>-Let it scan your system for files to remove.<br>-Make sure Temporary Files, Temporary Internet Files, and Recycle Bin are the only things checked.<br>-Press OK to remove them.<br><br>Please Run Malwarebytes' Anti-Malware.<br>- Click the Update tab.<br>- Click Check for Updates.<br>- If an update is found, it will download and install.<br>- Click the Scanner tab.<br>- Select "<b>Perform Quick Scan</b>", then click <b>Scan</b>.<br>- The scan may take some time to finish,so please be patient.<br>- When the scan is complete, click OK, then Show Results to view the results.<br>- Make sure that <b>everything is checked</b>, and click <b>Remove Selected</b>.<br>- When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Note)<br>- The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.<br>- Copy & Paste the entire report in your next reply along with a fresh HijackThis log.<br><br>Note:<br><i>If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts.<br>Click OK to either and let MBAM proceed with the disinfection process.<br>If asked to restart the computer, please do so immediately.</i><br><br>Now you need to run HijackThis and click "<b>Do a system scan only</b>." Place a check next to the following entries (if they are still there):<br><br><b>O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)<br>O2 - BHO: (no name) - {D8EC463F-89ED-468C-B146-97FE78C47EFF} - C:\WINDOWS\system32\qoMDUmLe.dll (file missing)<br>O20 - AppInit_DLLs: avgrsstx.dll tplszf.dll vfmypf.dll c:\windows\system32\pidokobo.dll c:\windows\system32\subiwizu.dll c:\windows\system32\sihosido.dll c:\windows\system32\yinuyoni.dll c:\windows\system32\bozujeyi.dll c:\windows\system32\biruwuta.dll c:\windows\system32\favogupo.dll c:\windows\system32\rugolara.dll c:\windows\system32\filokinu.dll C:\WINDOWS\system32\pafikiwu.dll c:\windows\system32\wuratapa.dll c:\windows\system32\fesusipa.dll c:\windows\system32\ c:\windows\system32\nawowami.dll c:\windows\system32\ c:\windows\system32\vinabino.dll c:\windows\system32\duzileru.dll c:\windows\system32\doyifari.dll c:\windows\system32\ledanozo.dll c:\windows\system32\vopereso.dll<br>O20 - Winlogon Notify: xxyXPihg - xxyXPihg.dll (file missing)</b><br><br>Now close all browser and other windows except for HijackThis, and click "<b>Fix Checked</b>" to have HijackThis fix the entries you checked.<br><br>Reconfigure Windows XP to show hidden files:<br>Click Start. Open My Computer. <br>Select the Tools menu and click Folder Options. Select the View Tab. <br>Under the Hidden files and folders heading select "Show hidden files and folders". <br>Uncheck the "Hide protected operating system files (recommended)" option. <br>Uncheck the "Hide file extensions for known file types" option.<br>Click Yes to confirm. Click OK.<br><br>Using Windows Explorer, locate the following files/folders, and delete them:<br>C:\WINDOWS\system32\<b>qoMDUmLe.dll</b><br>c:\windows\system32\<b>pidokobo.dll</b><br>c:\windows\system32\<b>subiwizu.dll</b><br>c:\windows\system32\<b>sihosido.dll</b><br>c:\windows\system32\<b>yinuyoni.dll</b><br>c:\windows\system32\<b>bozujeyi.dll</b><br>c:\windows\system32\<b>biruwuta.dll</b><br>c:\windows\system32\<b>favogupo.dll</b><br>c:\windows\system32\<b>rugolara.dll</b><br>c:\windows\system32\<b>filokinu.dll</b><br>C:\WINDOWS\system32\<b>pafikiwu.dll</b><br>c:\windows\system32\<b>wuratapa.dll</b><br>c:\windows\system32\<b>fesusipa.dll</b><br>c:\windows\system32\<b>nawowami.dll</b><br>c:\windows\system32\<b>vinabino.dll</b><br>c:\windows\system32\<b>duzileru.dll</b><br>c:\windows\system32\<b>doyifari.dll</b><br>c:\windows\system32\<b>ledanozo.dll</b><br>c:\windows\system32\<b>vopereso.dll</b><br>c:\windows\system32\<b>xxyXPihg.dll</b><br>C:\Windows\<b>fmark2.dat</b><br>And any executable files in the Windows folder that start with kenny (C:\Windows\<b>kenny*.exe</b>)<br><br>Also delete the following folders if found:<br>C:\Program Files\<b>TinyProxy</b><br>C:\Program Files\<b>ProtectService</b><br><br>Now you need to hide the files you un-hid earlier:<br>Click Start. Open My Computer.<br>Select the Tools menu and click Folder Options. Select the View Tab. <br>Under the Hidden files and folders heading unselect "Show hidden files and folders". <br>Check the "Hide protected operating system files (recommended)" option. <br>Click Yes to confirm. Click OK.<br><br>Please do a scan with <A HREF="http://www.kaspersky.com/kos/eng/partner/default/kavwebscan.html">Kaspersky Online Scanner</a><br><br><i>Note: If you are using Windows Vista, open your browser by right-clicking on its icon and select 'Run as administrator' to perform this scan.</i><br><br>Click on the <b>Accept</b> button and install any components it needs.<br>- The program will install and then begin downloading the latest definition files.<br>- After the files have been downloaded on the left side of the page in the <b>Scan</b> section select <b>My Computer</b>.<br>- This will start the program and scan your system.<br>- The scan will take a while, so be patient and let it run.<br>- Once the scan is complete, click on <b>View scan report</b><br>- Now, click on the <b>Save Report as</b> button.<br>- In the drop down box labeled <b>Files of type</b> change the type to <b>Text file</b>.<br>- Save the file to your desktop.<br>- Copy and paste that information in your next post.<br><br>Please post a new HijackThis log, the log from MBAM, the log from Kaspersky's online scan, and note any errors encountered.<br><small>--<br>Proud ASAP member since 2005</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22430518</guid>
<pubDate>Fri, 22 May 2009 18:51:32 EDT</pubDate>
</item>

<item>
<title>HJT Log: &#x22;System Security&#x22;, Vundo, Koobface</title>
<link>http://www.dslreports.com/forum/remark,22426484</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Rogue program "System Security" WAS running at startup, but it seems to be gone now. No other visible signs of further infection.<br><br><b>MBAM in safe mode, full scan, log:</b><br><br>Malwarebytes' Anti-Malware 1.36<br>Database version: 2162<br>Windows 5.1.2600 Service Pack 3<br><br>5/21/2009 8:41:48 PM<br>mbam-log-2009-05-21 (20-41-48).txt<br><br>Scan type: Full Scan (C:\|)<br>Objects scanned: 162908<br>Time elapsed: 41 minute(s), 27 second(s)<br><br>Memory Processes Infected: 0<br>Memory Modules Infected: 0<br>Registry Keys Infected: 10<br>Registry Values Infected: 7<br>Registry Data Items Infected: 1<br>Folders Infected: 6<br>Files Infected: 17<br><br>Memory Processes Infected:<br>(No malicious items detected)<br><br>Memory Modules Infected:<br>(No malicious items detected)<br><br>Registry Keys Infected:<br>HKEY_CLASSES_ROOT\Interface\{f7d09218-46d7-4d3d-9b7f-315204cd0836} (Trojan.BHO) -> Quarantined and deleted successfully.<br>HKEY_CLASSES_ROOT\CLSID\{ec43e3fd-5c60-46a6-97d7-e0b85dbdd6c4} (Trojan.BHO) -> Quarantined and deleted successfully.<br>HKEY_CLASSES_ROOT\Typelib\{e63648f7-3933-440e-b4f6-a8584dd7b7eb} (Trojan.BHO) -> Quarantined and deleted successfully.<br>HKEY_CLASSES_ROOT\CLSID\{9e263d08-4127-4b99-9043-4fb044e6fcbc} (Trojan.BHO) -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9e263d08-4127-4b99-9043-4fb044e6fcbc} (Trojan.BHO) -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\systemsecurity2009 (Rogue.SystemSecurity) -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SOFTWARE\xpreapp (Malware.Trace) -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\dslcnnct (Trojan.Vundo) -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully.<br>KHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\prnet (Trojan.Downloader) -> Quarantined and deleted successfully.<br><br>Registry Values Infected:<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\10560784 (Rogue.Multiple.H) -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\90570776 (Rogue.Multiple.H) -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\sysldtray (Worm.Koobface) -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{ec43e3fd-5c60-46a6-97d7-e0b85dbdd6c4} (Trojan.BHO) -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\ssodl (Trojan.BHO) -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\PromoReg (Trojan.Agent) -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\prnet (Trojan.Downloader) -> Quarantined and deleted successfully.<br><br>Registry Data Items Infected:<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.<br><br>Folders Infected:<br>C:\Documents and Settings\All Users\Application Data\10560784 (Rogue.Multiple.H) -> Quarantined and deleted successfully.<br>C:\Documents and Settings\All Users\Application Data\90570776 (Rogue.Multiple.H) -> Quarantined and deleted successfully.<br>C:\Documents and Settings\GHOST\Application Data\digifast (Trojan.Agent) -> Quarantined and deleted successfully.<br>C:\Documents and Settings\GHOST\Application Data\pidle (Trojan.Agent) -> Quarantined and deleted successfully.<br>C:\Documents and Settings\GHOST\Start Menu\Programs\System Security (Rogue.SystemSecurity) -> Quarantined and deleted successfully.<br>C:\Documents and Settings\GHOST\Application Data\Twain (Trojan.Matcash) -> Quarantined and deleted successfully.<br><br>Files Infected:<br>C:\Documents and Settings\All Users\Application Data\10560784\10560784.exe (Rogue.Multiple.H) -> Quarantined and deleted successfully.<br>C:\Documents and Settings\All Users\Application Data\10560784\10560784.glu (Rogue.Multiple.H) -> Quarantined and deleted successfully.<br>C:\Documents and Settings\All Users\Application Data\10560784\pc10560784cnf (Rogue.Multiple.H) -> Quarantined and deleted successfully.<br>C:\Documents and Settings\All Users\Application Data\10560784\pc10560784ins (Rogue.Multiple.H) -> Quarantined and deleted successfully.<br>C:\Documents and Settings\All Users\Application Data\90570776\90570776.exe (Rogue.Multiple.H) -> Quarantined and deleted successfully.<br>C:\WINDOWS\ld08.exe (Worm.Koobface) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\870159\870159.dll (Trojan.BHO) -> Quarantined and deleted successfully.<br>C:\Documents and Settings\GHOST\Local Settings\Temporary Internet Files\Content.IE5\KE70ZUQL\n1[1].exe (Rogue.Installer) -> Quarantined and deleted successfully.<br>C:\Documents and Settings\GHOST\Local Settings\Temporary Internet Files\Content.IE5\KE70ZUQL\nfr[1].exe (Trojan.KoobFace) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\MSINET.oca (Rogue.Trace) -> Quarantined and deleted successfully.<br>C:\Documents and Settings\GHOST\Application Data\digifast\config.cfg (Trojan.Agent) -> Quarantined and deleted successfully.<br>C:\Documents and Settings\GHOST\Start Menu\Programs\System Security\System Security 2009 Support.lnk (Rogue.SystemSecurity) -> Quarantined and deleted successfully.<br>C:\Documents and Settings\GHOST\Start Menu\Programs\System Security\System Security 2009.lnk (Rogue.SystemSecurity) -> Quarantined and deleted successfully.<br>C:\Documents and Settings\GHOST\Desktop\System Security 2009.lnk (Rogue.SystemSecurity) -> Quarantined and deleted successfully.<br>C:\WINDOWS\Temp\wpv761242765100.exe (Trojan.Agent) -> Quarantined and deleted successfully.<br>C:\WINDOWS\st_1242788278.exe (Backdoor.Bot) -> Quarantined and deleted successfully.<br>C:\WINDOWS\st_1242806706.exe (Backdoor.Bot) -> Quarantined and deleted successfully.<br><br><b>MBAM in normal boot, quick scan, truncated log</b><br><br>Registry Keys Infected:<br>HKEY_CURRENT_USER\SOFTWARE\Microsoft\cs41275 (Malware.Trace) -> Quarantined and deleted successfully.<br><br>Registry Values Infected:<br>HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\DigiFast (Trojan.Agent) -> Quarantined and deleted successfully.<br>HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\pidle (Trojan.Agent) -> Quarantined and deleted successfully.<br><br><b>MBAM in normal boot, quick scan, truncated log:</b><br><br>Registry Keys Infected:<br>HKEY_CLASSES_ROOT\ju495.ju495mgr (Trojan.FakeAlert) -> Quarantined and deleted successfully.<br>HKEY_CLASSES_ROOT\ju495.ju495mgr.1 (Trojan.FakeAlert) -> Quarantined and deleted successfully.<br>HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{9e263d08-4127-4b99-9043-4fb044e6fcbc} (Trojan.FakeAlert) -> Quarantined and deleted successfully.<br><br>Folders Infected:<br>C:\WINDOWS\system32\870159 (Trojan.FakeAlert) -> Quarantined and deleted successfully.<br><br><b>Spybot in safe mode, truncated log:</b><br><br>--- Report generated: 2009-05-21 20:59 ---<br><br>Fake.SecurityAlert: [SBI $1CEE4DC2] Root class (Registry key, fixed)<br>  HKEY_LOCAL_MACHINE\SOFTWARE\Classes\zip.plugin<br><br>Fraud.VirusDoctor: [SBI $0C71C5B8] Redirected host (Redirected host, fixed)<br>  url.adtrgt.com=82.98.231.89<br><br>Fraud.VirusDoctor: [SBI $0C71C5B8] Redirected host (Redirected host, fixed)<br>  googleads2.gdoubleclick.net=82.98.231.89<br><br>Virtumonde: [SBI $1D86E0B2]  Configuration file (File, fixed)<br>  C:\WINDOWS\Tasks\cgqzdpmz.job<br>  Properties.size=0<br>  Properties.md5=D41D8CD98F00B204E9800998ECF8427E<br><br>Virtumonde.Dll: [SBI $93929F73]  Library (File, fixed)<br>  C:\WINDOWS\system32\bojigenu.dll.tmp<br>  Properties.size=0<br>  Properties.md5=D41D8CD98F00B204E9800998ECF8427E<br><br>Virtumonde.Dll: [SBI $93929F73]  Library (File, fixed)<br>  C:\WINDOWS\system32\yetogusu.dll.tmp<br>  Properties.size=0<br>  Properties.md5=D41D8CD98F00B204E9800998ECF8427E<br><br>Virtumonde.sdn: [SBI $76125955] Settings (Registry value, fixed)<br>  HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs=...doguvuvo.dll...<br><br>Virtumonde.sdn: [SBI $70056CE6]  Data (File, fixed)<br>  C:\WINDOWS\system32\vefevoyi<br>  Properties.size=0<br>  Properties.md5=D41D8CD98F00B204E9800998ECF8427E<br><br>Virtumonde.sdn: [SBI $0C71C5B8] Redirected host (Redirected host, fixed)<br>  url.adtrgt.com=82.98.231.89<br><br>Virtumonde.sdn: [SBI $0C71C5B8] Redirected host (Redirected host, fixed)<br>  googleads2.gdoubleclick.net=82.98.231.89<br><br><b>Spybot in normal boot, truncated log:</b><br><br>--- Report generated: 2009-05-21 21:59 ---<br><br>Speedrunner: [SBI $9B490B89] Settings (Registry key, fixed)<br>  HKEY_USERS\S-1-5-21-1547161642-725345543-691866490-1003\Software\Microsoft\Internet Explorer\Explorer Bars\{CAFB2180-BA09-11DC-95FF-0800200C9A66}<br><br>Win32.Iksmas.ai: [SBI $06907D50] Settings (Registry value, fixed)<br>  HKEY_USERS\S-1-5-21-1547161642-725345543-691866490-1003\Software\Microsoft\Windows\CurrentVersion\FWDone<br><br>Win32.Iksmas.ai: [SBI $426323A7] Settings (Registry value, fixed)<br>  HKEY_USERS\S-1-5-21-1547161642-725345543-691866490-1003\Software\Microsoft\Windows\CurrentVersion\MyID<br><br>Win32.Iksmas.ai: [SBI $B924DA40] Settings (Registry value, fixed)<br>  HKEY_USERS\S-1-5-21-1547161642-725345543-691866490-1003\Software\Microsoft\Windows\CurrentVersion\RList<br><br>Virtumonde.sdn: [SBI $B981553F] Settings (Registry value, fixed)<br>  HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs=...feyiloto.dll...<br><br><b>ESET log:</b><br><br>C:\Documents and Settings\GHOST\Local Settings\Application Data\Microsoft\Messenger\REMOVED\Sharing Folders\REMOVED\N.E.R.D - Seeing Sounds (2008)\N.E.R.D. - Windows.mp3&#9;a variant of WMA/TrojanDownloader.GetCodec.gen trojan&#9;cleaned - quarantined<br>C:\Documents and Settings\GHOST\Local Settings\Temporary Internet Files\Content.IE5\P60V88MD\pp.10[1].exe&#9;probably a variant of Win32/Genetik trojan&#9;cleaned by deleting - quarantined<br>D:\Ares\Music\Gym Class Heroes - The Quilt\06-gym_class_heroes-catch_me_if_you_can.mp3&#9;a variant of WMA/TrojanDownloader.GetCodec.gen trojan&#9;cleaned - quarantined<br>D:\Ares\Music\N.E.R.D - Seeing Sounds (2008)\N.E.R.D. - Windows.mp3&#9;a variant of WMA/TrojanDownloader.GetCodec.gen trojan&#9;cleaned - quarantined<br>D:\FLStudio8\FL.Studio.8.0.0.XXL.Producer.Edition\setup\flstudio_8.0_install.exe&#9;probably a variant of Win32/Delf trojan&#9;deleted - quarantined<br>D:\FLStudio8\Plugins\Fruity\Generators\Toxic Biohazard\Toxic Biohazard.dll&#9;probably a variant of Win32/Delf trojan&#9;cleaned by deleting - quarantined<br><br><b>HijackThis log:</b><br><br>Logfile of Trend Micro HijackThis v2.0.2<br>Scan saved at 2:59:15 AM, on 5/22/2009<br>Platform: Windows XP SP3 (WinNT 5.01.2600)<br>MSIE: Internet Explorer v8.00 (8.00.6001.18702)<br>Boot mode: Normal<br><br>Running processes:<br>C:\WINDOWS\System32\smss.exe<br>C:\WINDOWS\system32\winlogon.exe<br>C:\WINDOWS\system32\services.exe<br>C:\WINDOWS\system32\lsass.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\WINDOWS\system32\spoolsv.exe<br>D:\AVG\AVG8\avgwdsvc.exe<br>C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe<br>C:\PROGRA~1\COMMON~1\Stardock\SDMCP.exe<br>C:\Program Files\Java\jre6\bin\jqs.exe<br>D:\AVG\AVG8\avgrsx.exe<br>D:\AVG\AVG8\avgnsx.exe<br>C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe<br>C:\WINDOWS\Explorer.EXE<br>C:\WINDOWS\system32\nvsvc32.exe<br>C:\WINDOWS\system32\IoctlSvc.exe<br>C:\WINDOWS\system32\PnkBstrA.exe<br>C:\WINDOWS\system32\PnkBstrB.exe<br>C:\WINDOWS\system32\svchost.exe<br>D:\AVG\AVG8\avgemc.exe<br>D:\AVG\AVG8\avgcsrvx.exe<br>C:\WINDOWS\RTHDCPL.EXE<br>D:\AVG\AVG8\avgtray.exe<br>C:\WINDOWS\system32\RUNDLL32.EXE<br>C:\WINDOWS\vsnpstd2.exe<br>C:\Program Files\Logitech\GamePanel Software\LgDevAgt.exe<br>C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe<br>C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe<br>C:\Program Files\Java\jre6\bin\jusched.exe<br>C:\WINDOWS\system32\ctfmon.exe<br>C:\Program Files\Messenger\msmsgs.exe<br>C:\Program Files\Logitech\GamePanel Software\LCD Manager\Applets\LCDClock.exe<br>C:\Program Files\Logitech\GamePanel Software\Applets\LCDCountdown.exe<br>C:\Program Files\Logitech\GamePanel Software\Applets\LCDPop3.exe<br>D:\Logitech\SetPoint\SetPoint.exe<br>C:\Program Files\Logitech\GamePanel Software\Applets\LCDRSS.exe<br>C:\Program Files\Logitech\GamePanel Software\Applets\LCDMedia.exe<br>C:\Program Files\WiFiConnector\NintendoWFCReg.exe<br>D:\Program Files\Stardock\ObjectDock\ObjectDock.exe<br>C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE<br>D:\Mozilla Firefox\firefox.exe<br>C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br><br>R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=69157" >go.microsoft.com/fwlink/?LinkId=69157</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=69157" >go.microsoft.com/fwlink/?LinkId=69157</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=69157" >go.microsoft.com/fwlink/?LinkId=69157</A><br>R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=74005" >go.microsoft.com/fwlink/?LinkId=74005</A><br>O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll<br>O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - D:\AVG\AVG8\avgssie.dll<br>O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)<br>O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br>O2 - BHO: (no name) - {D8EC463F-89ED-468C-B146-97FE78C47EFF} - C:\WINDOWS\system32\qoMDUmLe.dll (file missing)<br>O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br>O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br>O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE<br>O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE<br>O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE<br>O4 - HKLM\..\Run: [AVG8_TRAY] D:\AVG\AVG8\avgtray.exe<br>O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup<br>O4 - HKLM\..\Run: [nwiz] nwiz.exe /install<br>O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit<br>O4 - HKLM\..\Run: [SNPSTD2] C:\WINDOWS\vsnpstd2.exe<br>O4 - HKLM\..\Run: [Launch LgDevAgt] "C:\Program Files\Logitech\GamePanel Software\LgDevAgt.exe"<br>O4 - HKLM\..\Run: [Launch LCDMon] "C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe"<br>O4 - HKLM\..\Run: [Launch LGDCore] "C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe" /SHOWHIDE<br>O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"<br>O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br>O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background<br>O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')<br>O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')<br>O4 - Startup: Stardock ObjectDock.lnk = D:\Program Files\Stardock\ObjectDock\ObjectDock.exe<br>O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe<br>O4 - Global Startup: Logitech SetPoint.lnk = D:\Logitech\SetPoint\SetPoint.exe<br>O4 - Global Startup: Run Nintendo Wi-Fi USB Connector Registration Tool.lnk = C:\Program Files\WiFiConnector\NintendoWFCReg.exe<br>O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000<br>O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL<br>O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br>O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br>O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - &raquo;<A HREF="http://gfx2.hotmail.com/mail/w3/resources/MSNPUpld.cab" >gfx2.hotmail.com/mail/w3/resourc&middot;&middot;&middot;Upld.cab</A><br>O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - &raquo;<A HREF="http://download.eset.com/special/eos/OnlineScanner.cab" >download.eset.com/special/eos/On&middot;&middot;&middot;nner.cab</A><br>O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - D:\AVG\AVG8\avgpp.dll<br>O20 - AppInit_DLLs: avgrsstx.dll tplszf.dll vfmypf.dll c:\windows\system32\pidokobo.dll c:\windows\system32\subiwizu.dll c:\windows\system32\sihosido.dll c:\windows\system32\yinuyoni.dll c:\windows\system32\bozujeyi.dll c:\windows\system32\biruwuta.dll c:\windows\system32\favogupo.dll c:\windows\system32\rugolara.dll c:\windows\system32\filokinu.dll C:\WINDOWS\system32\pafikiwu.dll c:\windows\system32\wuratapa.dll c:\windows\system32\fesusipa.dll c:\windows\system32\ c:\windows\system32\nawowami.dll c:\windows\system32\ c:\windows\system32\vinabino.dll c:\windows\system32\duzileru.dll c:\windows\system32\doyifari.dll c:\windows\system32\ledanozo.dll c:\windows\system32\vopereso.dll<br>O20 - Winlogon Notify: !SASWinLogon - D:\SUPERAntiSpyware\SASWINLO.dll<br>O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll<br>O20 - Winlogon Notify: xxyXPihg - xxyXPihg.dll (file missing)<br>O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - D:\Ares\chatServer.exe<br>O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - D:\AVG\AVG8\avgemc.exe<br>O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - D:\AVG\AVG8\avgwdsvc.exe<br>O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe<br>O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br>O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe<br>O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe<br>O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe<br>O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe<br>O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe<br>O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe<br>O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe<br>O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe<br>O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe<br>O23 - Service: SonicStage Back-End Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SsBeSvc.exe<br>O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe<br>O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe<br><br>--<br>End of file - 9373 bytes]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22426484</guid>
<pubDate>Fri, 22 May 2009 03:05:12 EDT</pubDate>
</item>

</channel>
</rss>
