<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>[Vundo] HJT Log - slow system/redirected in Security Cleanup</title>
<link>http://www.dslreports.com/forum/r22480757</link>
<description></description>
<language>en</language>
<pubDate>Wed, 02 Dec 2009 06:56:42 EDT</pubDate>
<lastBuildDate>Wed, 02 Dec 2009 06:56:42 EDT</lastBuildDate>

<item>
<title>Re: [Vundo] HJT Log - slow system/redirected</title>
<link>http://www.dslreports.com/forum/remark,22503695</link>
<description><![CDATA[<A HREF="/useremail/u/377471"><b>TheJoker</b></A> : I'm glad I was able to help. :)<br><small>--<br>Proud ASAP member since 2005</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22503695</guid>
<pubDate>Fri, 05 Jun 2009 18:20:47 EDT</pubDate>
</item>

<item>
<title>Re: [Vundo] HJT Log - slow system/redirected</title>
<link>http://www.dslreports.com/forum/remark,22502652</link>
<description><![CDATA[<A HREF="/useremail/u/1648047"><b>yeoco</b></A> : OK, updated to sp3, loaded online armor  and I will look into loading the other items you mention as preventitive measures.  I just don't want to slow down the system with memory overload.<br><br>I thank you very much for your help.<br><br>Thank you!]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22502652</guid>
<pubDate>Fri, 05 Jun 2009 15:29:40 EDT</pubDate>
</item>

<item>
<title>Re: [Vundo] HJT Log - slow system/redirected</title>
<link>http://www.dslreports.com/forum/remark,22498176</link>
<description><![CDATA[<A HREF="/useremail/u/377471"><b>TheJoker</b></A> :  <blockquote><small>quote:</small><hr>OK...all done. Nothing found with Kaspersky...hence no log.<hr></blockquote><br>And nothing else in your HijackThis log either. :D<br><br> <blockquote><small>quote:</small><hr>Ok, are we done? <hr></blockquote><br>From the removal of malware, yes. <br><br> <blockquote><small>quote:</small><hr>How do I prevent from happening again?<hr></blockquote><br>The first step is to install Windows XP Service PAck 3, and all the critical updates after that. Until you do, your system will remain unnecessarily vulnerable to may exploits that have long since been fixed.<br><br>After that, I recommend you install a software firewall (the XP firewall isn't sufficient protection, it only checks incoming data).  Two excellent free firewalls are <A HREF="http://free.agnitum.com/">Outpost Firewall Free</a> (I used to use the Pro version and it's an excellent firewall) or <A HREF="http://www.tallemu.com/free-firewall-protection-software.html">Online Armor Free</a>. Either one would be a good choice.<br><br> <blockquote><small>quote:</small><hr>Do I get rid of the windows recovery console option selected in combofix? or is it already gone when I remove combofix?<hr></blockquote><br>If you followed the instructions in my last reply, you already uninstalled ComboFix. I recommend you leave the recovery console. If your system were to become unbootable for some reason, the Recovery Console gives you the ability to boot to a limited capability mode where you have some capability to attempt to correct the problem. If you prefer to shorten the time before the default boot option is chosen, you can do that with MSCONFIG in the BOOT.INI tab (the Timeout option, but I don't recommend changing any other setting in there).<br><br> <blockquote><small>quote:</small><hr>I have another computer that my kids used for the same things as this laptop. Should I repeat these steps...or just post from square 1??<hr></blockquote><br>Is it experiencing symptoms? If you feel that you need assistance with it, I  would follow the same steps here, &raquo;<A HREF="/faq/seclean">Security Cleanup FAQ</A> &raquo;<A HREF="/faq/13616">Mandatory Steps Before  Requesting Assistance</A>, and then start a new topic, posting the logs (particularly from MBAM and an online scanner and of course HijackThis).<br><br>There are several free utilities you can use to help keep malware off your system: <br><br>A HOSTS file will prevent Internet Explorer from communicating with sites known to be associated with adware or spyware. A good regularly updated HOST file is MVPS HOSTS File, available at &raquo;<A HREF="http://www.mvps.org/winhelp2002/hosts.htm" >www.mvps.org/winhelp2002/hosts.htm</A>. <br><br>A free non-resident utility to prevent the installation of ActiveX-based malware is JavaCool's SpywareBlaster. For real-time protection, there is SpywareGuard. Both are available at &raquo;<A HREF="http://www.javacoolsoftware.com/products.html" >www.javacoolsoftware.com/products.html</A>. <br><br>I recommend reading Tony Klein's article <i>So How did I get Infected in the First Place?</i> at &raquo;<A HREF="http://www.spywareinfoforum.com/index.php?showtopic=60955" >www.spywareinfoforum.com/index.p&middot;&middot;&middot;ic=60955</A><br><br>Does your problem appear resolved?<br><small>--<br>Proud ASAP member since 2005</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22498176</guid>
<pubDate>Thu, 04 Jun 2009 20:40:03 EDT</pubDate>
</item>

<item>
<title>Re: [Vundo] HJT Log - slow system/redirected</title>
<link>http://www.dslreports.com/forum/remark,22496763</link>
<description><![CDATA[<A HREF="/useremail/u/1648047"><b>yeoco</b></A> : OK...all done.  Nothing found with Kaspersky...hence no log.<br><br>Logfile of Trend Micro HijackThis v2.0.2<br>Scan saved at 3:55:07 PM, on 6/4/2009<br>Platform: Windows XP SP2 (WinNT 5.01.2600)<br>MSIE: Internet Explorer v7.00 (7.00.6000.16827)<br>Boot mode: Normal<br><br>Running processes:<br>C:\WINDOWS\System32\smss.exe<br>C:\WINDOWS\system32\winlogon.exe<br>C:\WINDOWS\system32\services.exe<br>C:\WINDOWS\system32\lsass.exe<br>C:\WINDOWS\system32\Ati2evxx.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\Program Files\Windows Defender\MsMpEng.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\Program Files\Intel\Wireless\Bin\EvtEng.exe<br>C:\WINDOWS\system32\Ati2evxx.exe<br>C:\WINDOWS\Explorer.EXE<br>C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe<br>C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe<br>C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe<br>C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe<br>C:\Program Files\Alwil Software\Avast4\ashServ.exe<br>C:\WINDOWS\system32\spoolsv.exe<br>C:\Program Files\LeapFrog\LeapFrog Connect\CommandService.exe<br>C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe<br>C:\Program Files\Dell Support Center\bin\sprtsvc.exe<br>C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe<br>C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br>C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe<br>C:\WINDOWS\stsystra.exe<br>C:\Program Files\Dell\MediaDirect\PCMService.exe<br>C:\Program Files\LeapFrog\LeapFrog Connect\Monitor.exe<br>C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe<br>C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe<br>C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe<br>C:\WINDOWS\system32\dla\tfswctrl.exe<br>C:\Program Files\Dell Support Center\bin\sprtcmd.exe<br>C:\Program Files\Dell\QuickSet\quickset.exe<br>C:\Program Files\Corel\Corel Snapfire Plus\Corel Photo Downloader.exe<br>C:\Program Files\ATI Technologies\ATI.ACE\cli.exe<br>C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe<br>C:\WINDOWS\system32\ctfmon.exe<br>C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\Program Files\Messenger\msmsgs.exe<br>C:\Program Files\NetWaiting\netWaiting.exe<br>C:\Program Files\Dell Support\DSAgnt.exe<br>C:\Program Files\Digital Line Detect\DLG.exe<br>C:\Program Files\ATI Technologies\ATI.ACE\cli.exe<br>C:\Program Files\Java\jre1.6.0_03\bin\jucheck.exe<br>C:\WINDOWS\system32\wscntfy.exe<br>C:\WINDOWS\system32\wuauclt.exe<br>C:\WINDOWS\system32\wuauclt.exe<br>C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br><br>R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://www.yahoo.com/" >www.yahoo.com/</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=69157" >go.microsoft.com/fwlink/?LinkId=69157</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=4070403<br>R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll<br>O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll<br>O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br>O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll<br>O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll<br>O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe<br>O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br>O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"<br>O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe<br>O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime<br>O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe"<br>O4 - HKLM\..\Run: [Monitor] "C:\Program Files\LeapFrog\LeapFrog Connect\Monitor.exe"<br>O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start<br>O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup<br>O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"<br>O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless<br>O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"<br>O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe<br>O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter<br>O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe<br>O4 - HKLM\..\Run: [Corel Photo Downloader] C:\Program Files\Corel\Corel Snapfire Plus\Corel Photo Downloader.exe<br>O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay<br>O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe<br>O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br>O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe<br>O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background<br>O4 - HKCU\..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netWaiting.exe<br>O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup<br>O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe<br>O4 - Global Startup: Digital Line Detect.lnk = ?<br>O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe<br>O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000<br>O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll<br>O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll<br>O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL<br>O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br>O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br>O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br>O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br>O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - &raquo;<A HREF="http://support.dell.com/systemprofiler/SysPro.CAB" >support.dell.com/systemprofiler/SysPro.CAB</A><br>O16 - DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} (Citrix ICA Client) - &raquo;<A HREF="http://a516.g.akamai.net/f/516/25175/7d/runaware.download.akamai.com/25175/citrix/wficat-no-eula.cab" >a516.g.akamai.net/f/516/25175/7d&middot;&middot;&middot;eula.cab</A><br>O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll<br>O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe<br>O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe<br>O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe<br>O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe<br>O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe<br>O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe<br>O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br>O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe<br>O23 - Service: LeapFrog Connect Device Service - Unknown owner - C:\Program Files\LeapFrog\LeapFrog Connect\CommandService.exe<br>O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe<br>O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation  - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe<br>O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe<br>O23 - Service: Intel(R) PROSet/Wireless SSO Service (WLANKEEPER) - Intel(R) Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe<br><br>--<br>End of file - 9170 bytes<br><br>Ok, are we done?  How do I prevent from happening again?  Do I get rid of the windows recovery console option selected in combofix? or is it already gone when I remove combofix?<br><br>Thanks for all your help.  I have another computer that my kids used for the same things as this laptop.  Should I repeat these steps...or just post from square 1??]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22496763</guid>
<pubDate>Thu, 04 Jun 2009 16:00:53 EDT</pubDate>
</item>

<item>
<title>Re: [Vundo] HJT Log - slow system/redirected</title>
<link>http://www.dslreports.com/forum/remark,22494131</link>
<description><![CDATA[<A HREF="/useremail/u/377471"><b>TheJoker</b></A> :  <blockquote><small>quote:</small><hr>Ok, was I infected bad?? What is next?<hr></blockquote><br>Not nearly as bad as some I've seen. But let's see what an online scan with a different antivirus program finds. I expect it may not find much as you have an excellent antivirus (avira).<br><br>Go to start > run and copy and paste next command in the field:<br><b>ComboFix /u</b><br><br>Make sure there's a space between Combofix and /<br>Then hit enter.<br><br>This will uninstall Combofix, delete its related folders and files, reset your clock settings, hide file extensions, hide the system/hidden files and resets System Restore again.<br><br>Please do a scan with <A HREF="http://www.kaspersky.com/kos/eng/partner/default/kavwebscan.html">Kaspersky Online Scanner</a><br><br><i>Note: If you are using Windows Vista, open your browser by right-clicking on its icon and select 'Run as administrator' to perform this scan.</i><br><br>Click on the <b>Accept</b> button and install any components it needs.<br>- The program will install and then begin downloading the latest definition files.<br>- After the files have been downloaded on the left side of the page in the <b>Scan</b> section select <b>My Computer</b>.<br>- This will start the program and scan your system.<br>- The scan will take a while, so be patient and let it run.<br>- Once the scan is complete, click on <b>View scan report</b><br>- Now, click on the <b>Save Report as</b> button.<br>- In the drop down box labeled <b>Files of type</b> change the type to <b>Text file</b>.<br>- Save the file to your desktop.<br>- Copy and paste that information in your next post.<br><br>Please post  a new HijackThis log, the log from Kaspersky's online scan, and note any errors encountered.<br><small>--<br>Proud ASAP member since 2005</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22494131</guid>
<pubDate>Thu, 04 Jun 2009 05:40:08 EDT</pubDate>
</item>

<item>
<title>Re: [Vundo] HJT Log - slow system/redirected</title>
<link>http://www.dslreports.com/forum/remark,22492125</link>
<description><![CDATA[<A HREF="/useremail/u/1648047"><b>yeoco</b></A> : Ok, all steps followed.  No infections found in malwarebytes.  Here are the logs:<br><br>Logfile of Trend Micro HijackThis v2.0.2<br>Scan saved at 8:11:03 PM, on 6/3/2009<br>Platform: Windows XP SP2 (WinNT 5.01.2600)<br>MSIE: Internet Explorer v7.00 (7.00.6000.16827)<br>Boot mode: Normal<br><br>Running processes:<br>C:\WINDOWS\System32\smss.exe<br>C:\WINDOWS\system32\winlogon.exe<br>C:\WINDOWS\system32\services.exe<br>C:\WINDOWS\system32\lsass.exe<br>C:\WINDOWS\system32\Ati2evxx.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\Program Files\Windows Defender\MsMpEng.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\Program Files\Intel\Wireless\Bin\EvtEng.exe<br>C:\WINDOWS\system32\Ati2evxx.exe<br>C:\WINDOWS\Explorer.EXE<br>C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe<br>C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe<br>C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe<br>C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe<br>C:\Program Files\Alwil Software\Avast4\ashServ.exe<br>C:\WINDOWS\system32\spoolsv.exe<br>C:\Program Files\LeapFrog\LeapFrog Connect\CommandService.exe<br>C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe<br>C:\Program Files\Dell Support Center\bin\sprtsvc.exe<br>C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe<br>C:\Program Files\Alwil Software\Avast4\ashWebSv.exe<br>C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe<br>C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br>C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe<br>C:\WINDOWS\stsystra.exe<br>C:\Program Files\Dell\MediaDirect\PCMService.exe<br>C:\Program Files\LeapFrog\LeapFrog Connect\Monitor.exe<br>C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe<br>C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe<br>C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe<br>C:\WINDOWS\system32\dla\tfswctrl.exe<br>C:\Program Files\Dell Support Center\bin\sprtcmd.exe<br>C:\Program Files\Dell\QuickSet\quickset.exe<br>C:\Program Files\Corel\Corel Snapfire Plus\Corel Photo Downloader.exe<br>C:\Program Files\ATI Technologies\ATI.ACE\cli.exe<br>C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe<br>C:\WINDOWS\system32\ctfmon.exe<br>C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe<br>C:\Program Files\Messenger\msmsgs.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\Program Files\NetWaiting\netWaiting.exe<br>C:\Program Files\Dell Support\DSAgnt.exe<br>C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe<br>C:\Program Files\Digital Line Detect\DLG.exe<br>C:\WINDOWS\system32\wuauclt.exe<br>C:\Program Files\internet explorer\iexplore.exe<br>C:\WINDOWS\system32\wbem\wmiapsrv.exe<br>C:\Program Files\ATI Technologies\ATI.ACE\cli.exe<br>C:\WINDOWS\system32\wuauclt.exe<br>C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br><br>R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://www.yahoo.com/" >www.yahoo.com/</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=69157" >go.microsoft.com/fwlink/?LinkId=69157</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=4070403<br>R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll<br>O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll<br>O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br>O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll<br>O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll<br>O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe<br>O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br>O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"<br>O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe<br>O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime<br>O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe"<br>O4 - HKLM\..\Run: [Monitor] "C:\Program Files\LeapFrog\LeapFrog Connect\Monitor.exe"<br>O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start<br>O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup<br>O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"<br>O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless<br>O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"<br>O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe<br>O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter<br>O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe<br>O4 - HKLM\..\Run: [Corel Photo Downloader] C:\Program Files\Corel\Corel Snapfire Plus\Corel Photo Downloader.exe<br>O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay<br>O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe<br>O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br>O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe<br>O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background<br>O4 - HKCU\..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netWaiting.exe<br>O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup<br>O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe<br>O4 - Global Startup: Digital Line Detect.lnk = ?<br>O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe<br>O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000<br>O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll<br>O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll<br>O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL<br>O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br>O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br>O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br>O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br>O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - &raquo;<A HREF="http://support.dell.com/systemprofiler/SysPro.CAB" >support.dell.com/systemprofiler/SysPro.CAB</A><br>O16 - DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} (Citrix ICA Client) - &raquo;<A HREF="http://a516.g.akamai.net/f/516/25175/7d/runaware.download.akamai.com/25175/citrix/wficat-no-eula.cab" >a516.g.akamai.net/f/516/25175/7d&middot;&middot;&middot;eula.cab</A><br>O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll<br>O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe<br>O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe<br>O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe<br>O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe<br>O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe<br>O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe<br>O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br>O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe<br>O23 - Service: LeapFrog Connect Device Service - Unknown owner - C:\Program Files\LeapFrog\LeapFrog Connect\CommandService.exe<br>O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe<br>O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation  - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe<br>O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe<br>O23 - Service: Intel(R) PROSet/Wireless SSO Service (WLANKEEPER) - Intel(R) Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe<br><br>--<br>End of file - 9337 bytes<br><br>ComboFix 09-06-01.03 - Glenn 06/03/2009 19:41.1 - NTFSx86<br>Microsoft Windows XP Home Edition  5.1.2600.2.1252.1.1033.18.2046.1504 [GMT -4:00]<br>Running from: c:\documents and settings\Glenn\Desktop\Combo-Fix.exe<br>AV: avast! antivirus 4.8.1296 [VPS 090603-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}<br>FW: Norton Internet Worm Protection *disabled* {990F9400-4CEE-43EA-A83A-D013ADD8EA6E}<br>.<br><br>(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br><br>c:\windows\system32\_000009_.tmp.dll<br><br>.<br>(((((((((((((((((((((((((((((((((((((((   Drivers/Services   )))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br><br>-------\Legacy_MYWEBSEARCHSERVICE<br><br>(((((((((((((((((((((((((   Files Created from 2009-05-03 to 2009-06-03  )))))))))))))))))))))))))))))))<br>.<br><br>2009-06-02 14:37 . 2009-03-06 14:00&#9;284160&#9;------w-&#9;c:\windows\system32\dllcache\pdh.dll<br>2009-06-02 14:37 . 2009-02-06 09:54&#9;35328&#9;------w-&#9;c:\windows\system32\dllcache\sc.exe<br>2009-06-02 14:37 . 2005-07-26 04:20&#9;60416&#9;------w-&#9;c:\windows\system32\dllcache\colbact.dll<br>2009-06-02 14:37 . 2009-02-09 10:01&#9;401408&#9;------w-&#9;c:\windows\system32\dllcache\rpcss.dll<br>2009-06-02 14:37 . 2009-02-06 10:22&#9;110592&#9;------w-&#9;c:\windows\system32\dllcache\services.exe<br>2009-06-02 14:37 . 2009-02-09 10:01&#9;473088&#9;------w-&#9;c:\windows\system32\dllcache\fastprox.dll<br>2009-06-02 14:37 . 2009-02-06 09:41&#9;227840&#9;------w-&#9;c:\windows\system32\dllcache\wmiprvse.exe<br>2009-06-02 14:36 . 2009-02-09 10:01&#9;617984&#9;------w-&#9;c:\windows\system32\dllcache\advapi32.dll<br>2009-06-02 14:36 . 2009-02-09 10:01&#9;715264&#9;------w-&#9;c:\windows\system32\dllcache\ntdll.dll<br>2009-06-02 14:36 . 2008-04-21 10:02&#9;215552&#9;------w-&#9;c:\windows\system32\dllcache\wordpad.exe<br>2009-06-02 13:27 . 2009-06-02 13:27&#9;--------&#9;d-----w-&#9;C:\VundoFix Backups<br>2009-06-02 02:17 . 2009-06-02 01:37&#9;102664&#9;----a-w-&#9;c:\windows\system32\drivers\tmcomm.sys<br>2009-06-02 01:37 . 2009-06-02 02:19&#9;--------&#9;d-----w-&#9;c:\documents and settings\Glenn\.housecall6.6<br>2009-06-02 01:10 . 2009-06-02 01:10&#9;--------&#9;d-----w-&#9;c:\program files\Windows Defender<br>2009-06-02 01:02 . 2009-03-09 19:06&#9;15688&#9;----a-w-&#9;c:\windows\system32\lsdelete.exe<br>2009-06-02 00:48 . 2009-03-09 19:06&#9;64160&#9;----a-w-&#9;c:\windows\system32\drivers\Lbd.sys<br>2009-06-02 00:48 . 2009-06-02 00:48&#9;314200&#9;----a-w-&#9;c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\threatwork.exe<br>2009-06-02 00:48 . 2009-06-02 00:48&#9;25440&#9;----a-w-&#9;c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\savapibridge.dll<br>2009-06-02 00:48 . 2009-06-02 00:48&#9;15688&#9;----a-w-&#9;c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lsdelete.exe<br>2009-06-02 00:48 . 2009-06-02 00:48&#9;169312&#9;----a-w-&#9;c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lavamessage.dll<br>2009-06-02 00:48 . 2009-06-02 00:48&#9;348496&#9;----a-w-&#9;c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lavalicense.dll<br>2009-06-02 00:48 . 2009-06-02 00:48&#9;294240&#9;----a-w-&#9;c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\UpdateManager.dll<br>2009-06-02 00:47 . 2009-06-02 00:47&#9;83808&#9;----a-w-&#9;c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\ShellExt.dll<br>2009-06-02 00:45 . 2009-06-02 00:45&#9;1630048&#9;----a-w-&#9;c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Resources.dll<br>2009-06-02 00:44 . 2009-06-02 00:44&#9;212848&#9;----a-w-&#9;c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\RPAPI.dll<br>2009-06-02 00:44 . 2009-06-02 00:44&#9;64160&#9;----a-w-&#9;c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Drivers\32\lbd.sys<br>2009-06-02 00:44 . 2009-06-02 00:44&#9;40288&#9;----a-w-&#9;c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\PrivacyClean.dll<br>2009-06-02 00:44 . 2009-06-02 00:44&#9;640360&#9;----a-w-&#9;c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\CEAPI.dll<br>2009-06-02 00:44 . 2009-06-02 00:44&#9;540536&#9;----a-w-&#9;c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-AwareCommand.exe<br>2009-06-02 00:44 . 2009-06-02 00:44&#9;559464&#9;----a-w-&#9;c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-AwareAdmin.exe<br>2009-06-02 00:44 . 2009-06-02 00:44&#9;2324808&#9;----a-w-&#9;c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-Aware.exe<br>2009-06-02 00:44 . 2009-06-02 00:44&#9;627536&#9;----a-w-&#9;c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWWSC.exe<br>2009-06-02 00:43 . 2009-06-02 00:43&#9;518488&#9;----a-w-&#9;c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWTray.exe<br>2009-06-02 00:43 . 2009-06-02 00:43&#9;1005904&#9;----a-w-&#9;c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWService.exe<br>2009-06-02 00:40 . 2009-06-02 00:40&#9;--------&#9;dc-h--w-&#9;c:\documents and settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}<br>2009-06-02 00:40 . 2009-03-12 08:17&#9;2902048&#9;-c--a-w-&#9;c:\documents and settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}\Ad-AwareAE.exe<br>2009-06-02 00:40 . 2009-06-02 00:48&#9;--------&#9;d-----w-&#9;c:\documents and settings\All Users\Application Data\Lavasoft<br>2009-06-02 00:40 . 2009-06-02 00:40&#9;--------&#9;d-----w-&#9;c:\program files\Lavasoft<br>2009-06-02 00:27 . 2009-06-02 00:27&#9;--------&#9;d-----w-&#9;c:\documents and settings\Glenn\Application Data\Malwarebytes<br>2009-06-02 00:27 . 2009-05-26 17:20&#9;40160&#9;----a-w-&#9;c:\windows\system32\drivers\mbamswissarmy.sys<br>2009-06-02 00:27 . 2009-06-02 00:32&#9;--------&#9;d-----w-&#9;c:\program files\Malwarebytes' Anti-Malware<br>2009-06-02 00:27 . 2009-06-02 00:27&#9;--------&#9;d-----w-&#9;c:\documents and settings\All Users\Application Data\Malwarebytes<br>2009-06-02 00:27 . 2009-05-26 17:19&#9;19096&#9;----a-w-&#9;c:\windows\system32\drivers\mbam.sys<br><br>.<br>((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br>2009-06-03 23:02 . 2008-07-01 16:58&#9;--------&#9;d-----w-&#9;c:\documents and settings\All Users\Application Data\Google Updater<br>2009-06-01 01:52 . 2008-11-13 02:41&#9;--------&#9;d-----w-&#9;c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy<br>2009-05-30 21:35 . 2008-06-16 20:19&#9;--------&#9;d-----w-&#9;c:\program files\Kidzui<br>2009-04-29 23:55 . 2008-06-13 15:36&#9;5642&#9;--sha-w-&#9;c:\windows\system32\KGyGaAvL.sys<br>2009-04-29 23:55 . 2008-06-13 15:36&#9;168&#9;--sh--r-&#9;c:\windows\system32\149BF6A647.sys<br>2009-04-25 20:08 . 2009-04-25 20:08&#9;--------&#9;d-----w-&#9;c:\documents and settings\Glenn\Application Data\Sonic<br>2009-04-25 20:05 . 2009-04-25 20:05&#9;--------&#9;d-----w-&#9;c:\documents and settings\Glenn\Application Data\Leadertech<br>2009-03-06 14:00 . 2004-08-10 17:51&#9;284160&#9;----a-w-&#9;c:\windows\system32\pdh.dll<br>.<br><br>(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br>.<br>*Note* empty entries & legit default entries are not shown <br>REGEDIT4<br><br>[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<br>"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]<br>"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-08-10 68856]<br>"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]<br>"ModemOnHold"="c:\program files\NetWaiting\netWaiting.exe" [2003-09-10 20480]<br>"DellSupport"="c:\program files\Dell Support\DSAgnt.exe" [2006-08-29 395776]<br><br>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<br>"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-11-26 81000]<br>"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-08 761947]<br>"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 132496]<br>"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-05-27 413696]<br>"PCMService"="c:\program files\Dell\MediaDirect\PCMService.exe" [2007-05-02 184320]<br>"Monitor"="c:\program files\LeapFrog\LeapFrog Connect\Monitor.exe" [2008-06-25 237568]<br>"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 81920]<br>"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 221184]<br>"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2006-10-18 802816]<br>"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2006-10-18 696320]<br>"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 16384]<br>"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-12-06 127035]<br>"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064]<br>"Dell QuickSet"="c:\program files\Dell\QuickSet\quickset.exe" [2006-08-03 1032192]<br>"Corel Photo Downloader"="c:\program files\Corel\Corel Snapfire Plus\Corel Photo Downloader.exe" [2006-08-14 462336]<br>"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 45056]<br>"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-03-09 515416]<br>"SigmatelSysTrayApp"="stsystra.exe" - c:\windows\stsystra.exe [2006-03-24 282624]<br><br>c:\documents and settings\All Users\Start Menu\Programs\Startup\<br>Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]<br>Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2007-4-3 24576]<br>QuickBooks Update Agent.lnk - c:\program files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2007-4-18 663552]<br><br>[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]<br>@="Service"<br><br>[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]<br>@="Service"<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]<br>"DisableMonitoring"=dword:00000001<br><br>[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]<br>"%windir%\\system32\\sessmgr.exe"=<br>"c:\\Program Files\\Dell\\MediaDirect\\PCMService.exe"=<br>"%windir%\\Network Diagnostic\\xpnetdiag.exe"=<br>"c:\\Program Files\\Common Files\\Symantec Shared\\CCPD-LC\\symlcsvc.exe"=<br>"c:\\Program Files\\Intel\\Wireless\\Bin\\Dot1XCfg.exe"=<br><br>R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [6/1/2009 8:48 PM 64160]<br>R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [4/5/2008 6:42 PM 111184]<br>R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [4/5/2008 6:42 PM 20560]<br>R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [3/9/2009 3:06 PM 951632]<br>R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 7:19 PM 13592]<br>S3 FlyUsb;FLY Fusion;c:\windows\system32\drivers\FlyUsb.sys [6/29/2008 2:51 PM 18560]<br>.<br>Contents of the 'Scheduled Tasks' folder<br><br>2009-06-02 c:\windows\Tasks\Ad-Aware Update (Weekly).job<br>- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-09 19:06]<br><br>2009-02-14 c:\windows\Tasks\AppleSoftwareUpdate.job<br>- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 21:57]<br><br>2009-06-03 c:\windows\Tasks\Google Software Updater.job<br>- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-04-10 01:34]<br><br>2009-06-03 c:\windows\Tasks\MP Scheduled Scan.job<br>- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 23:20]<br>.<br>- - - - ORPHANS REMOVED - - - -<br><br>SafeBoot-procexp90.Sys<br><br>.<br>------- Supplementary Scan -------<br>.<br>uStart Page = hxxp://www.yahoo.com/<br>uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8<br>mStart Page = hxxp://www.google.com<br>uInternet Connection Wizard,ShellNext = iexplore<br>uSearchURL,(Default) = hxxp://www.google.com/keyword/%s<br>IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000<br>.<br><br>**************************************************************************<br><br>catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, &raquo;<A HREF="http://www.gmer.net" >www.gmer.net</A><br>Rootkit scan 2009-06-03 19:45<br>Windows 5.1.2600 Service Pack 2 NTFS<br><br>scanning hidden processes ...  <br><br>scanning hidden autostart entries ... <br><br>scanning hidden files ...  <br><br>scan completed successfully<br>hidden files: 0<br><br>**************************************************************************<br>.<br>--------------------- DLLs Loaded Under Running Processes ---------------------<br><br>- - - - - - - > 'winlogon.exe'(700)<br>c:\windows\system32\Ati2evxx.dll<br>.<br>------------------------ Other Running Processes ------------------------<br>.<br>c:\windows\system32\ati2evxx.exe<br>c:\program files\Intel\Wireless\Bin\EvtEng.exe<br>c:\windows\system32\ati2evxx.exe<br>c:\program files\Intel\Wireless\Bin\S24EvMon.exe<br>c:\program files\Intel\Wireless\Bin\WLKEEPER.exe<br>c:\program files\Alwil Software\Avast4\aswUpdSv.exe<br>c:\program files\Alwil Software\Avast4\ashServ.exe<br>c:\program files\Symantec\LiveUpdate\AluSchedulerSvc.exe<br>c:\program files\LeapFrog\LeapFrog Connect\CommandService.exe<br>c:\program files\Intel\Wireless\Bin\RegSrvc.exe<br>c:\program files\Dell Support Center\bin\sprtsvc.exe<br>c:\program files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe<br>c:\windows\system32\wdfmgr.exe<br>c:\windows\system32\wbem\unsecapp.exe<br>c:\windows\system32\wscntfy.exe<br>c:\program files\Symantec\LiveUpdate\AUPDATE.EXE<br>c:\progra~1\Symantec\LIVEUP~1\LUCOMS~1.EXE<br>c:\program files\Java\jre1.6.0_03\bin\jucheck.exe<br>.<br>**************************************************************************<br>.<br>Completion time: 2009-06-03 19:50 - machine was rebooted<br>ComboFix-quarantined-files.txt  2009-06-03 23:50<br><br>Pre-Run: 58,284,199,936 bytes free<br>Post-Run: 58,288,660,480 bytes free<br><br>WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe<br>[boot loader]<br>timeout=2<br>default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS<br>[operating systems]<br>c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons<br>multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect<br><br>194&#9;--- E O F ---&#9;2009-06-03 23:06<br><br>Malwarebytes' Anti-Malware 1.37<br>Database version: 2225<br>Windows 5.1.2600 Service Pack 2<br><br>6/3/2009 7:35:35 PM<br>mbam-log-2009-06-03 (19-35-35).txt<br><br>Scan type: Quick Scan<br>Objects scanned: 82471<br>Time elapsed: 2 minute(s), 57 second(s)<br><br>Memory Processes Infected: 0<br>Memory Modules Infected: 0<br>Registry Keys Infected: 0<br>Registry Values Infected: 0<br>Registry Data Items Infected: 0<br>Folders Infected: 0<br>Files Infected: 0<br><br>Memory Processes Infected:<br>(No malicious items detected)<br><br>Memory Modules Infected:<br>(No malicious items detected)<br><br>Registry Keys Infected:<br>(No malicious items detected)<br><br>Registry Values Infected:<br>(No malicious items detected)<br><br>Registry Data Items Infected:<br>(No malicious items detected)<br><br>Folders Infected:<br>(No malicious items detected)<br><br>Files Infected:<br>(No malicious items detected)<br><br>Ok, was I infected bad??  What is next?<br>Thanks for you help!]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22492125</guid>
<pubDate>Wed, 03 Jun 2009 20:17:35 EDT</pubDate>
</item>

<item>
<title>Re: [Vundo] HJT Log - slow system/redirected</title>
<link>http://www.dslreports.com/forum/remark,22488131</link>
<description><![CDATA[<A HREF="/useremail/u/377471"><b>TheJoker</b></A> : Hi yeoco<br><br>I suggest printing out each set of instructions and reading the entire post before proceeding. It will make following them easier. Please follow the directions in the order listed.<br><br>I notice that you have Spybot's TeaTimer running.  While this is normally a wonderful tool to protect against hijackers, it can also interfere with HijackThis fixes.  So please <b>disable TeaTimer</b> by doing the following:<br>1) Run Spybot-S&D<br>2) Go to the Mode menu, and make sure "Advanced Mode" is selected<br>3) On the left hand side, choose Tools -> Resident<br>4) Uncheck "Resident TeaTimer" and OK any prompts<br><br>When everything is done and your log is clean again, you can enable it again.<br>If teatimer gives you a warning afterwords that some changes were made, allow this instead of blocking it.<br><br>Please <b>disable your Windows Defender Real-time Protection</b> as it may interfere with the fixes that we need to make.<br><br>Open Windows Defender.<br>Click on Tools, General Settings.<br>Scroll down and uncheck Turn on real-time protection (recommended).<br>After you uncheck this, click on the Save button and close Windows Defender.<br>After all of the fixes are complete it is very important that you enable Real-time Protection again.<br><br>You weren't infected by MyWebSearch, you installed it at some point as a search tool. What it does, however, is it hijacks your searches and targets them against their own site.<br><br>Go to Start > Settings > Control Panel > Add or Remove Programs and remove any of the following programs, if found (they may already be gone):<br><br><b>My Search Bar<br>MyWay Speed Bar<br>My Web Search Bar<br>Fun Web Products Easy Installer</b><br><br>Please Run Malwarebytes' Anti-Malware.<br>- Click the Update tab.<br>- Click Check for Updates.<br>- If an update is found, it will download and install.<br>- Click the Scanner tab.<br>- Select "<b>Perform Quick Scan</b>", then click <b>Scan</b>.<br>- The scan may take some time to finish,so please be patient.<br>- When the scan is complete, click OK, then Show Results to view the results.<br>- Make sure that <b>everything is checked</b>, and click <b>Remove Selected</b>.<br>- When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Note)<br>- The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.<br>- Copy & Paste the <b>entire</b> report in your next reply (please don't cut off the top line that tells me what version it is).<br><br>Note:<br><i>If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts.<br>Click OK to either and let MBAM proceed with the disinfection process.<br>If asked to restart the computer, please do so immediately.</i><br><br>Now you need to run HijackThis and click "<b>Do a system scan only</b>." Place a check next to the following entries (if they are still there):<br><br><b>O8 - Extra context menu item: &Search - ?p=ZUzeb004YYUS_ZUxdm265YYUS<br>O20 - AppInit_DLLs: c:\windows\system32\puhafewu c:\windows\system32\,C:\WINDOWS\system32\kifezamo.dll</b><br><br>Now close all browser and other windows except for HijackThis, and click "<b>Fix Checked</b>" to have HijackThis fix the entries you checked.<br><br>Using Windows Explorer, locate the following files, and delete them (if still there):<br>c:\windows\system32\<b>puhafewu</b><br>C:\WINDOWS\system32\<b>kifezamo.dll</b><br><br>Download <b>ComboFix&copy; by sUBs</b> from one of these locations:<br><br><textarea name="code" class="text" cols=50 rows=10>http://download.bleepingcomputer.com/sUBs/ComboFix.exe&#012;http://www.forospyware.com/sUBs/ComboFix.exe&#012;http://subs.geekstogo.com/ComboFix.exe&#012;</textarea><!--end code block--><br><b>* IMPORTANT !!! Save ComboFix.exe to your Desktop</b><br><br>Familiarize yourself with ComboFix before running it:<br>&raquo;<A HREF="http://www.bleepingcomputer.com/combofix/how-to-use-combofix" >www.bleepingcomputer.com/combofi&middot;&middot;&middot;combofix</A><br><br>- Disable your AntiVirus and any AntiSpyware programs you may be running (usually via a right click on the System Tray icon) to prevent them from interfering.<br><br>- Double click on ComboFix.exe & follow the prompts.<br><br>- As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal.  It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware. <br><br>- Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.<br><br>**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.<br><br> <IMG SRC="http://img.photobucket.com/albums/v706/ried7/RcAuto1.gif"> <br><br>Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:<br><br> <IMG SRC="http://img.photobucket.com/albums/v706/ried7/whatnext.png"> <br><br>Click on Yes, to continue scanning for malware. When finished, it will save a log. <br>Please include the contents of the log at <b>C:\ComboFix.txt</b> in your next reply.<br><br>While avast! is your current antivirus program, I see a few Symantec files loading. Dell usually nas Norton AntiVirus installed as a trial on their systems. IF you uninstalled it, it was an incomplete uninstall.<br><br>To fully remove Norton AntiVirus, you should go here and download the files and print the instructions for removal, and follow them.<br>How to uninstall Norton AntiVirus 2003/2004/2005/2006/2007/2008:<br>- Vista/XP/2000 - <A HREF="http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2005033108162039?Open&docid=2005092709200113&nsf=sharedtech.nsf&view=docid">Click Here</a> (note: this removes ALL Norton 2003/2004/2005/2006/2007/2008 products and and Norton 360  from your computer)<br>- Me/98 - <A HREF="ftp://ftp.symantec.com/public/english_us_canada/removal_tools/Norton_Removal_Tool_9x.exe">Click Here</a><br><A HREF="http://service1.symantec.com/SUPPORT/sunset-c2002kb.nsf/docid/2001045512474266?Open&src=&docid=2001092114452606&nsf=nav.nsf&view=docid&dtype=&prod=&ver=&osv=&osv_lvl=&seg=">How to uninstall Norton AntiVirus 2000/2001/2002</a><br><br>Please post a new HijackThis log, the log from MBAM, the log from ComboFix (combofix.txt), and note any errors encountered.<br><br><small>--<br>Proud ASAP member since 2005</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22488131</guid>
<pubDate>Wed, 03 Jun 2009 10:00:30 EDT</pubDate>
</item>

<item>
<title>[Vundo] HJT Log - slow system/redirected</title>
<link>http://www.dslreports.com/forum/remark,22480757</link>
<description><![CDATA[<A HREF="/useremail/u/1648047"><b>yeoco</b></A> : I have been infected by Vundo V., mywebsearch, and Disabled.SecurityCenter.  <br><br>I have run spybot, malwarebytes(which appears to have found the malware and possibly deleted it), ad-aware, windows defender and malicious software tool and trend micro online virus scanner(it listed some cookies that it deleted but that is all...no log was available.<br><br>I still think my system might be a little slow and maybe some pieces of these remain.<br><br>After running malwarebytes...Vundo came up again in windows defender<br><br>Here is my log from malwarebytes and hijack this<br><br>Database version: 2210<br>Windows 5.1.2600 Service Pack 2<br><br>6/1/2009 8:33:21 PM<br>mbam-log-2009-06-01 (20-33-21).txt<br><br>Scan type: Quick Scan<br>Objects scanned: 80683<br>Time elapsed: 2 minute(s), 10 second(s)<br><br>Memory Processes Infected: 0<br>Memory Modules Infected: 1<br>Registry Keys Infected: 25<br>Registry Values Infected: 6<br>Registry Data Items Infected: 6<br>Folders Infected: 0<br>Files Infected: 4<br><br>Memory Processes Infected:<br>(No malicious items detected)<br><br>Memory Modules Infected:<br>C:\WINDOWS\system32\chtbrk.dll (Trojan.Downloader) -> Delete on reboot.<br><br>Registry Keys Infected:<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8233e326-991b-4ce5-8b2e-506d61c88c61} (Trojan.Vundo.H) -> Quarantined and deleted successfully.<br>HKEY_CLASSES_ROOT\CLSID\{8233e326-991b-4ce5-8b2e-506d61c88c61} (Trojan.Vundo.H) -> Quarantined and deleted successfully.<br>HKEY_CLASSES_ROOT\CLSID\{53408e2d-7f7e-4004-a2ef-c7e8d5738e7c} (Trojan.Downloader) -> Quarantined and deleted successfully.<br>HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{53408e2d-7f7e-4004-a2ef-c7e8d5738e7c} (Trojan.Downloader) -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53408e2d-7f7e-4004-a2ef-c7e8d5738e7c} (Trojan.Downloader) -> Quarantined and deleted successfully.<br>HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18ea9-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.<br>HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18eab-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.<br>HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{3dc201fb-e9c9-499c-a11f-23c360d7c3f8} (Adware.MyWebSearch) -> Quarantined and deleted successfully.<br>HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{9ff05104-b030-46fc-94b8-81276e4e27df} (Adware.MyWebSearch) -> Quarantined and deleted successfully.<br>HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{00a6faf1-072e-44cf-8957-5838f569a31d} (Adware.MyWebSearch) -> Quarantined and deleted successfully.<br>HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{25560540-9571-4d7b-9389-0f166788785a} (Adware.MyWebSearch) -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3dc201fb-e9c9-499c-a11f-23c360d7c3f8} (Adware.MyWebSearch) -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{63d0ed2c-b45b-4458-8b3b-60c69bbbd83c} (Adware.MyWebSearch) -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{98d9753d-d73b-42d5-8c85-4469cda897ab} (Adware.MyWebSearch) -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{9ff05104-b030-46fc-94b8-81276e4e27df} (Adware.MyWebSearch) -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59c7fc09-1c83-4648-b3e6-003d2bbc7481} (Adware.MyWebSearch) -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68af847f-6e91-45dd-9b68-d6a12c30e5d7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170b96c-28d4-4626-8358-27e6caeef907} (Adware.MyWebSearch) -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{d1a71fa0-ff48-48dd-9b6d-7a13a3e42127} (Adware.MyWebSearch) -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ddb1968e-ead6-40fd-8dae-ff14757f60c7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{f138d901-86f0-4383-99b6-9cdd406036da} (Adware.MyWebSearch) -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll (Adware.MyWay) -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\dslcnnct (Trojan.Vundo) -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.<br><br>Registry Values Infected:<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{ec43e3fd-5c60-46a6-97d7-e0b85dbdd6c4} (Trojan.BHO) -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\SSODL (Trojan.Agent) -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\bf (Trojan.Agent) -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\bk (Trojan.Agent) -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\iu (Trojan.Agent) -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\mu (Trojan.Agent) -> Quarantined and deleted successfully.<br><br>Registry Data Items Infected:<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.<br>HKEY_CURRENT_USER\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.<br>HKEY_CURRENT_USER\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.<br>HKEY_CURRENT_USER\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.<br><br>Folders Infected:<br>(No malicious items detected)<br><br>Files Infected:<br>C:\WINDOWS\system32\chtbrk.dll (Trojan.Downloader) -> Delete on reboot.<br>c:\WINDOWS\system32\jipilere.exe (Trojan.Vundo.V) -> Quarantined and deleted successfully.<br>c:\WINDOWS\system32\roruhore.exe (Trojan.Vundo.V) -> Quarantined and deleted successfully.<br>c:\WINDOWS\system32\bokodase.exe (Trojan.Vundo.V) -> Quarantined and deleted successfully.<br><br>Logfile of Trend Micro HijackThis v2.0.2<br>Scan saved at 11:14:19 PM, on 6/1/2009<br>Platform: Windows XP SP2 (WinNT 5.01.2600)<br>MSIE: Internet Explorer v7.00 (7.00.6000.16791)<br>Boot mode: Normal<br><br>Running processes:<br>C:\WINDOWS\System32\smss.exe<br>C:\WINDOWS\system32\winlogon.exe<br>C:\WINDOWS\system32\services.exe<br>C:\WINDOWS\system32\lsass.exe<br>C:\WINDOWS\system32\Ati2evxx.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\Program Files\Intel\Wireless\Bin\EvtEng.exe<br>C:\WINDOWS\system32\Ati2evxx.exe<br>C:\WINDOWS\Explorer.EXE<br>C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe<br>C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe<br>C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe<br>C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe<br>C:\Program Files\Alwil Software\Avast4\ashServ.exe<br>C:\WINDOWS\system32\spoolsv.exe<br>C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe<br>C:\Program Files\LeapFrog\LeapFrog Connect\CommandService.exe<br>C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe<br>C:\Program Files\Dell Support Center\bin\sprtsvc.exe<br>C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe<br>C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe<br>C:\Program Files\Alwil Software\Avast4\ashWebSv.exe<br>C:\WINDOWS\system32\wscntfy.exe<br>C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe<br>C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br>C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe<br>C:\WINDOWS\stsystra.exe<br>C:\Program Files\Dell\MediaDirect\PCMService.exe<br>C:\Program Files\LeapFrog\LeapFrog Connect\Monitor.exe<br>C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe<br>C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe<br>C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe<br>C:\WINDOWS\system32\dla\tfswctrl.exe<br>C:\Program Files\Dell Support Center\bin\sprtcmd.exe<br>C:\Program Files\Dell\QuickSet\quickset.exe<br>C:\Program Files\Corel\Corel Snapfire Plus\Corel Photo Downloader.exe<br>C:\Program Files\ATI Technologies\ATI.ACE\cli.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe<br>C:\WINDOWS\system32\ctfmon.exe<br>C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe<br>C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe<br>C:\Program Files\Messenger\msmsgs.exe<br>C:\Program Files\NetWaiting\netWaiting.exe<br>C:\Program Files\Dell Support\DSAgnt.exe<br>C:\Program Files\Digital Line Detect\DLG.exe<br>C:\Program Files\ATI Technologies\ATI.ACE\cli.exe<br>C:\Program Files\Java\jre1.6.0_03\bin\jucheck.exe<br>C:\Program Files\Windows Defender\MsMpEng.exe<br>C:\Program Files\Windows Defender\MSASCui.exe<br>C:\Program Files\Internet Explorer\IEXPLORE.EXE<br>C:\WINDOWS\system32\taskmgr.exe<br>C:\Documents and Settings\Glenn\.housecall6.6\tsc.exe<br>C:\Program Files\Internet Explorer\iexplore.exe<br>C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br><br>R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://www.yahoo.com/" >www.yahoo.com/</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=69157" >go.microsoft.com/fwlink/?LinkId=69157</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=4070403<br>R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll<br>O1 - Hosts: scanner.info<br>O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll<br>O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll<br>O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll<br>O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll<br>O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe<br>O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br>O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"<br>O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe<br>O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime<br>O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe"<br>O4 - HKLM\..\Run: [Monitor] "C:\Program Files\LeapFrog\LeapFrog Connect\Monitor.exe"<br>O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start<br>O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup<br>O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"<br>O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless<br>O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"<br>O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe<br>O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter<br>O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe<br>O4 - HKLM\..\Run: [Corel Photo Downloader] C:\Program Files\Corel\Corel Snapfire Plus\Corel Photo Downloader.exe<br>O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay<br>O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe<br>O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide<br>O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br>O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe<br>O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe<br>O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background<br>O4 - HKCU\..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netWaiting.exe<br>O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup<br>O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe<br>O4 - Global Startup: Digital Line Detect.lnk = ?<br>O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe<br>O8 - Extra context menu item: &Search - ?p=ZUzeb004YYUS_ZUxdm265YYUS<br>O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000<br>O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll<br>O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll<br>O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL<br>O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll<br>O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll<br>O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br>O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br>O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - &raquo;<A HREF="http://support.dell.com/systemprofiler/SysPro.CAB" >support.dell.com/systemprofiler/SysPro.CAB</A><br>O16 - DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} (Citrix ICA Client) - &raquo;<A HREF="http://a516.g.akamai.net/f/516/25175/7d/runaware.download.akamai.com/25175/citrix/wficat-no-eula.cab" >a516.g.akamai.net/f/516/25175/7d&middot;&middot;&middot;eula.cab</A><br>O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll<br>O20 - AppInit_DLLs: c:\windows\system32\puhafewu c:\windows\system32\,C:\WINDOWS\system32\kifezamo.dll<br>O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe<br>O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe<br>O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe<br>O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe<br>O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe<br>O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe<br>O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe<br>O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br>O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe<br>O23 - Service: LeapFrog Connect Device Service - Unknown owner - C:\Program Files\LeapFrog\LeapFrog Connect\CommandService.exe<br>O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE<br>O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe<br>O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation  - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe<br>O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe<br>O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe<br>O23 - Service: Intel(R) PROSet/Wireless SSO Service (WLANKEEPER) - Intel(R) Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe<br><br>--<br>End of file - 10192 bytes]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22480757</guid>
<pubDate>Mon, 01 Jun 2009 23:17:57 EDT</pubDate>
</item>

</channel>
</rss>
