<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>[Trojan] can not install any security apps, run any online scans in Security Cleanup</title>
<link>http://www.dslreports.com/forum/r22511091</link>
<description></description>
<language>en</language>
<pubDate>Wed, 02 Dec 2009 00:49:49 EDT</pubDate>
<lastBuildDate>Wed, 02 Dec 2009 00:49:49 EDT</lastBuildDate>

<item>
<title>Re: [Trojan] can not install any security apps, run any online s</title>
<link>http://www.dslreports.com/forum/remark,22625671</link>
<description><![CDATA[<A HREF="/useremail/u/728753"><b>File Quit</b></A> : I set the DNS statically to 4.2.2.2, so that HJT entry is fine. It's a valid Level 3 DNS server.<br><br>The Creative Labs driver and Viewpoint is not a huge issue for them, I am leaving it enabled just in case it ever becomes an issue in the future.<br><br>ComboFix has been uninstalled, MalwareBytes ran a scan and found no malware, and the BitDefender scan came up clean as well. I have installed Avast to protect them from future issues. <br><br>Thank you for your help!!<br><small>--<br>Apple. Switch to Mac. &raquo;<A HREF="http://www.apple.com/getamac" >www.apple.com/getamac</A></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22625671</guid>
<pubDate>Sun, 28 Jun 2009 21:10:54 EDT</pubDate>
</item>

<item>
<title>Re: [Trojan] can not install any security apps, run any online s</title>
<link>http://www.dslreports.com/forum/remark,22621808</link>
<description><![CDATA[<A HREF="/useremail/u/377471"><b>TheJoker</b></A> : Did you decide to keep <b>Viewpoint</b>, or did it fail to uninstall?<br><br>Please <b>disable your Windows Defender Real-time Protection</b> as it may interfere with the fixes that we need to make.<br><br>Open Windows Defender.<br>Click on Tools, General Settings.<br>Scroll down and uncheck Turn on real-time protection (recommended).<br>After you uncheck this, click on the Save button and close Windows Defender.<br>After all of the fixes are complete it is very important that you enable Real-time Protection again.<br><br>Reconfigure Windows XP to show hidden files:<br>Click Start. Open My Computer. <br>Select the Tools menu and click Folder Options. Select the View Tab. <br>Under the Hidden files and folders heading select "Show hidden files and folders". <br>Uncheck the "Hide protected operating system files (recommended)" option. <br>Uncheck the "Hide file extensions for known file types" option.<br>Click Yes to confirm. Click OK.<br><br>Using Windows Explorer, delete the following files:<br>c:\windows\system32\<b>jachfcwl.tmp</b><br>c:\windows\system32\<b>nqstv.tmp</b><br><br>Now you need to hide the files you un-hid earlier.<br>Double-click the My Computer icon on the Windows desktop.<br>Select the Tools menu and click Folder Options. Select the View Tab.  <br>Under the Hidden files and folders heading unselect "<b>Show hidden files and folders</b>". <br>Check the "<b>Hide protected operating system files (recommended)</b>" option. <br>Click Yes to confirm. Click OK.<br><br>Please Run Malwarebytes' Anti-Malware.<br>- Click the Update tab.<br>- Click Check for Updates.<br>- If an update is found, it will download and install.<br>- Click the Scanner tab.<br>- Select "<b>Perform Quick Scan</b>", then click <b>Scan</b>.<br>- The scan may take some time to finish,so please be patient.<br>- When the scan is complete, click OK, then Show Results to view the results.<br>- Make sure that <b>everything is checked</b>, and click <b>Remove Selected</b>.<br>- When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Note)<br>- The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.<br>- Copy & Paste the entire report in your next reply along with a fresh HijackThis log.<br><br>Note:<br><i>If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts.<br>Click OK to either and let MBAM proceed with the disinfection process.<br>If asked to restart the computer, please do so immediately.</i><br><br>Now you need to run HijackThis and click "<b>Do a system scan only</b>." Place a check next to the following entries (if they are still there):<br><br><b>O17 - HKLM\System\CCS\Services\Tcpip\..\{9558635E-9318-4CFB-AAA9-3C744258E07D}: NameServer = 4.2.2.2</b><br><br>You can <b>optionally</b> check the following entry. This is a reminder to register your Creative Labs SoundBlaster Live! Card, and not necessary to running your system:<br><b>O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE</b><br><br>Now close all browser and other windows except for HijackThis, and click "<b>Fix Checked</b>" to have HijackThis fix the entries you checked.<br><br>Go to start > run and copy and paste next command in the field:<br><b>ComboFix /u</b><br><br>Make sure there's a space between Combofix and /<br>Then hit enter.<br><br>This will uninstall Combofix, delete its related folders and files, reset your clock settings, hide file extensions, hide the system/hidden files and resets System Restore again.<br><br>Your version of Java is outdated and needs to be updated to take advantage of fixes that have eliminated security vulnerabilities.<br><b>Updating Java:</b><br>- Download the latest version of  <b><A HREF="http://java.sun.com/javase/downloads/index.jsp">Java Runtime Environment (JRE) 6</a></b>.<br>- Scroll down to where it says "<i>Java SE Runtime Environment (JRE), JRE 6 Update 14</i>".<br>- Click the "<b>Download</b>" button to the right.<br>- In the Window that opens, select Windows, and check the "agree" box and click "Continue".<br>- Click on the link to download <i>Windows Offline Installation</i> and save to your desktop.<br>- Close any programs you may have running - especially your web browser.<br>- Go to <b>Start</b> > <b>Control Panel</b> double-click on <b>Add or Remove Programs</b> and remove all older versions of Java.<br>- Check any item with Java Runtime Environment (JRE or J2SE) in the name.<br>- Examples of older versions in Add or Remove Programs:<br>-- Java 2 Runtime Environment, SE v1.4.2<br>-- J2SE Runtime Environment 5.0<br>-- J2SE Runtime Environment 5.0 Update 2<br>- Click the <b>Remove</b> or <b>Change/Remove</b> button.<br>- Repeat as many times as necessary to remove each Java versions.<br>- Reboot your computer once all Java components are removed.<br>- Then from your desktop double-click on <b>jre-6u14-windows-i586-p.exe</b> that you downloaded to install the newest version.<br><br>The installed verison of Adobe Acrobat is also outdated and should be updated to take advantage of security updates.<br><br>Go to Start > Control Panel > Add or Remove Programs and remove the following program:<br><b>Adobe Acrobat Reader</b><br><br>Then go to www.adobe.com and download the current verison of Acrobat Reader and install it.<br><br>There were a lot of infected files removed by ComboFix.<br>In Internet Explorer, please run the <b>BitDefender</b> online scan at <A HREF="http://www.bitdefender.com/scan8/ie.html">BitDefender.com</a><br>You will need to allow an ActiveX control to install for the scan to run.<br>Leave the scanning options at default and press "click here to scan"<br>When finished scanning, click on "click here to export the scan report"<br>Save it to your desktop, at "file name" type in "bdscan" then click save.<br>Please post the log in your next reply.<br><br>Please post a new HijackThis log, the log from MBAM, the log from BitDefender's online scan, and note any errors encountered.<br><small>--<br>Proud ASAP member since 2005</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22621808</guid>
<pubDate>Sat, 27 Jun 2009 20:27:31 EDT</pubDate>
</item>

<item>
<title>Re: [Trojan] can not install any security apps, run any online s</title>
<link>http://www.dslreports.com/forum/remark,22620987</link>
<description><![CDATA[<A HREF="/useremail/u/728753"><b>File Quit</b></A> : They use the Neopets Toolbar and IMVU, so I did not remove those per their request. Here are the logs:<br><br>ComboFix log:<br>ComboFix 09-06-26.02 - The Apples 06/27/2009 15:29.1 - NTFSx86<br>Microsoft Windows XP Home Edition  5.1.2600.2.1252.1.1033.18.255.14 [GMT -4:00]<br>Running from: c:\documents and settings\The Apples\Desktop\nonmae.exe<br>.<br><br>(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br><br>C:\-1393043815<br>c:\program files\Common Files\System\Uninstall<br>c:\windows\system32\akrnqdfk.ini<br>c:\windows\system32\apfahomx.ini<br>c:\windows\system32\avbeaeyd.ini<br>c:\windows\system32\awjkcdst.ini<br>c:\windows\system32\biueuiyc.ini<br>c:\windows\system32\bomljnfi.ini<br>c:\windows\system32\btmabkvl.ini<br>c:\windows\system32\chyqudkd.ini<br>c:\windows\system32\cjqqpwpa.ini<br>c:\windows\system32\cqzxdi.dll<br>c:\windows\system32\dfpbmsef.ini<br>c:\windows\system32\drivers\UACdulkrayx.sys<br>c:\windows\system32\eotbudeo.ini<br>c:\windows\system32\eqivnsdy.ini<br>c:\windows\system32\faadsono.ini<br>c:\windows\system32\fbtuxfpm.ini<br>c:\windows\system32\frvjsuww.ini<br>c:\windows\system32\gbaroplo.ini<br>c:\windows\system32\gelnwftg.ini<br>c:\windows\system32\gmfksgws.ini<br>c:\windows\system32\gubprrfu.ini<br>c:\windows\system32\ifaqdqbq.ini<br>c:\windows\system32\igwxitqm.ini<br>c:\windows\system32\itxvhelp.ini<br>c:\windows\system32\ivpjqvje.dll<br>c:\windows\system32\jachfcwl.ini<br>c:\windows\system32\jfnuri.dll<br>c:\windows\system32\jxqtqvkb.ini<br>c:\windows\system32\kfaeva.dll<br>c:\windows\system32\kplirpyp.dll<br>c:\windows\system32\ksiclctw.ini<br>c:\windows\system32\ktmvevhl.dll<br>c:\windows\system32\lcamuz.dll<br>c:\windows\system32\lgqybemg.ini<br>c:\windows\system32\lhcavplq.ini<br>c:\windows\system32\mgbpiebd.dll<br>c:\windows\system32\mrrsmecc.ini<br>c:\windows\system32\mrypscpe.ini<br>c:\windows\system32\mxqciiex.ini<br>c:\windows\system32\ndshrige.ini<br>c:\windows\system32\nfgqks.dll<br>c:\windows\system32\niolytiu.ini<br>c:\windows\system32\nkcsts.dll<br>c:\windows\system32\nlvhlaxd.dll<br>c:\windows\system32\nrlyoy.dll<br>c:\windows\system32\nsnergly.ini<br>c:\windows\system32\nttuww.dll<br>c:\windows\system32\nudoedvt.dll<br>c:\windows\system32\oadclqcx.ini<br>c:\windows\system32\oageuxdh.ini<br>c:\windows\system32\ojgjen.dll<br>c:\windows\system32\oqyrdwfw.ini<br>c:\windows\system32\osqukyxf.ini<br>c:\windows\system32\otwfhaaj.ini<br>c:\windows\system32\ovwwiueo.dll<br>c:\windows\system32\pdwylsxw.ini<br>c:\windows\system32\pigngjln.ini<br>c:\windows\system32\rgspjvec.ini<br>c:\windows\system32\rjihwpgk.ini<br>c:\windows\system32\rtvwa.bak1<br>c:\windows\system32\rtvwa.bak2<br>c:\windows\system32\rtvwa.ini<br>c:\windows\system32\rtvwa.ini2<br>c:\windows\system32\rtvwa.tmp<br>c:\windows\system32\rybwjgyj.ini<br>c:\windows\system32\sfhbvudd.dll<br>c:\windows\system32\skdkvgbh.ini<br>c:\windows\system32\srgcquff.ini<br>c:\windows\system32\svobtiok.ini<br>c:\windows\system32\thepdbhc.ini<br>c:\windows\system32\txuspccs.ini<br>c:\windows\system32\UACeexrboiv.dll<br>c:\windows\system32\UACflovdtvi.dll<br>c:\windows\system32\UACfvibkdip.dll<br>c:\windows\system32\uacinit.dll<br>c:\windows\system32\UACjxtafqww.dll<br>c:\windows\system32\UACmtkmwyem.log<br>c:\windows\system32\UACpielespw.dll<br>c:\windows\system32\UACrencbkyv.log<br>c:\windows\system32\UACxepxuvdn.log<br>c:\windows\system32\UACyynwxypf.dat<br>c:\windows\system32\unkfjbho.ini<br>c:\windows\system32\upjmvsey.ini<br>c:\windows\system32\vmmxqhbx.dll<br>c:\windows\system32\vrxntvhu.ini<br>c:\windows\system32\vwfpydwm.ini<br>c:\windows\system32\vyfqukys.ini<br>c:\windows\system32\whbyetho.ini<br>c:\windows\system32\wnpsgfve.ini<br>c:\windows\system32\wplxwdip.ini<br>c:\windows\system32\wuhwwiip.ini<br>c:\windows\system32\xdcxfbsi.ini<br>c:\windows\system32\xfyudwxp.ini<br>c:\windows\system32\yhyfcyox.dll<br>c:\windows\system32\yviwiyne.ini<br><br>.<br>(((((((((((((((((((((((((((((((((((((((   Drivers/Services   )))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br><br>-------\Service_UACd.sys<br>-------\Legacy_DOMAINSERVICE<br><br>(((((((((((((((((((((((((   Files Created from 2009-05-27 to 2009-06-27  )))))))))))))))))))))))))))))))<br>.<br><br>2009-06-08 19:35 . 2004-08-04 07:56&#9;221184&#9;----a-w-&#9;c:\windows\system32\wmpns.dll<br>2009-06-08 19:29 . 2009-06-08 19:29&#9;--------&#9;d-----w-&#9;C:\ProgramData<br>2009-06-08 19:29 . 2009-06-08 19:29&#9;--------&#9;d-----w-&#9;c:\documents and settings\All Users\Application Data\Electronic Arts<br>2009-06-08 17:36 . 2009-06-08 17:36&#9;10134&#9;----a-r-&#9;c:\documents and settings\The Apples\Application Data\Microsoft\Installer\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}\ARPPRODUCTICON.exe<br>2009-06-08 17:36 . 2009-06-08 17:36&#9;--------&#9;d-----w-&#9;c:\program files\Microsoft WSE<br>2009-06-08 17:24 . 2006-09-28 20:05&#9;2414360&#9;----a-w-&#9;c:\windows\system32\d3dx9_31.dll<br>2009-06-08 17:24 . 2009-06-08 17:24&#9;--------&#9;d-----w-&#9;c:\windows\Logs<br>2009-06-07 19:24 . 2009-06-07 19:24&#9;--------&#9;d-----w-&#9;c:\documents and settings\The Apples\Application Data\Malwarebytes<br>2009-06-07 18:52 . 2009-06-07 18:52&#9;--------&#9;d-----w-&#9;c:\documents and settings\Administrator\Application Data\Malwarebytes<br>2009-06-07 18:47 . 2009-04-06 19:32&#9;15504&#9;----a-w-&#9;c:\windows\system32\drivers\mbam.sys<br>2009-06-07 18:47 . 2009-04-06 19:32&#9;38496&#9;----a-w-&#9;c:\windows\system32\drivers\mbamswissarmy.sys<br>2009-06-07 18:47 . 2009-06-07 18:47&#9;--------&#9;d-----w-&#9;c:\documents and settings\All Users\Application Data\Malwarebytes<br>2009-06-07 18:47 . 2009-06-07 18:52&#9;--------&#9;d-----w-&#9;c:\program files\Malwarebytes' Anti-Malware<br>2009-06-07 18:08 . 2009-06-07 18:08&#9;--------&#9;d-----w-&#9;c:\program files\Trend Micro<br>2009-06-07 17:55 . 2009-06-07 17:55&#9;--------&#9;d-----w-&#9;c:\documents and settings\Administrator\Local Settings\Application Data\Mozilla<br><br>.<br>((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br>2009-06-27 18:53 . 2008-01-13 04:20&#9;--------&#9;d-----w-&#9;c:\documents and settings\All Users\Application Data\Google Updater<br>2009-06-26 06:22 . 2008-03-15 00:47&#9;--------&#9;d-----w-&#9;c:\program files\Electronic Arts<br>2009-06-08 20:02 . 2007-05-06 17:56&#9;--------&#9;d--h--w-&#9;c:\program files\InstallShield Installation Information<br>2009-06-08 19:57 . 2008-03-13 22:53&#9;--------&#9;d-----w-&#9;c:\program files\SimPE<br>2009-06-08 19:38 . 2008-03-12 23:46&#9;--------&#9;d-----w-&#9;c:\program files\Sims2Pack Clean Installer<br>2007-07-03 17:23 . 2007-07-03 17:23&#9;295&#9;--sha-w-&#9;c:\windows\system32\jachfcwl.tmp<br>2007-06-21 00:01 . 2007-06-21 00:01&#9;401&#9;--sha-w-&#9;c:\windows\system32\nqstv.tmp<br>.<br><br>(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br>.<br>*Note* empty entries & legit default entries are not shown <br>REGEDIT4<br><br>[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<br>"NvMediaCenter"="c:\windows\System32\NVMCTRAY.DLL" [2003-10-06 49152]<br>"MSMSGS"="c:\program files\Messenger\MSMSGS.EXE" [2004-10-13 1694208]<br>"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-08-12 68856]<br>"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]<br>"EA Core"="c:\program files\Electronic Arts\EADM\Core.exe" [2009-04-29 3338240]<br><br>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<br>"diagent"="c:\program files\Creative\SBLive\Diagnostics\diagent.exe" [2002-04-03 135264]<br>"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]<br>"HPDJ Taskbar Utility"="c:\windows\System32\spool\drivers\w32x86\3\hpztsb04.exe" [2006-01-13 196608]<br>"HPHmon03"="c:\windows\System32\hphmon03.exe" [2006-01-13 311296]<br>"AdaptecDirectCD"="c:\program files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" [2002-04-10 679936]<br>"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-07-19 78008]<br>"NvCplDaemon"="c:\windows\System32\NvCpl.dll" [2003-10-06 5058560]<br>"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 132496]<br>"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-12-11 286720]<br>"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2007-12-11 267048]<br>"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-12 39792]<br>"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2003-10-06 741376]<br><br>[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]<br>"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2006-10-26 434528]<br><br>c:\documents and settings\All Users\Start Menu\Programs\Startup\<br>Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]<br><br>[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]<br>@="Service"<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\security center]<br>"AntiVirusOverride"=dword:00000001<br>"FirewallOverride"=dword:00000001<br><br>[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]<br>"%windir%\\system32\\sessmgr.exe"=<br>"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=<br>"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=<br>"c:\\Program Files\\iTunes\\iTunes.exe"=<br>"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=<br>"c:\\Program Files\\Electronic Arts\\EADM\\Core.exe"=<br><br>[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]<br>"41883:TCP"= 41883:TCP:*:Disabled:SolidNetworkManager<br>"41883:UDP"= 41883:UDP:*:Disabled:SolidNetworkManager<br>"42663:TCP"= 42663:TCP:*:Disabled:SolidNetworkManager<br>"42663:UDP"= 42663:UDP:*:Disabled:SolidNetworkManager<br>"55845:TCP"= 55845:TCP:*:Disabled:SolidNetworkManager<br>"55845:UDP"= 55845:UDP:*:Disabled:SolidNetworkManager<br>"45101:TCP"= 45101:TCP:*:Disabled:SolidNetworkManager<br>"45101:UDP"= 45101:UDP:*:Disabled:SolidNetworkManager<br><br>R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [4/14/2008 9:55 PM 78416]<br>R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [4/14/2008 9:55 PM 20560]<br>R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [11/29/2007 8:57 PM 24652]<br>R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 6:19 PM 13592]<br>R3 Dot4Usb HPH09;Dot4Usb HPH09;c:\windows\system32\drivers\hphius09.sys [5/6/2007 2:05 PM 18864]<br>S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [6/7/2009 2:47 PM 38496]<br>.<br>Contents of the 'Scheduled Tasks' folder<br><br>2009-02-18 c:\windows\Tasks\AppleSoftwareUpdate.job<br>- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]<br><br>2009-06-27 c:\windows\Tasks\Google Software Updater.job<br>- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-08-10 07:17]<br><br>2009-06-27 c:\windows\Tasks\MP Scheduled Scan.job<br>- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 22:20]<br>.<br>.<br>------- Supplementary Scan -------<br>.<br>uStart Page = hxxp://my.yahoo.com/<br>uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8<br>uSearchURL,(Default) = hxxp://www.google.com/search?q=%s<br>IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000<br>IE: {{d9288080-1baa-4bc4-9cf8-a92d743db949} - c:\documents and settings\The Apples\Start Menu\Programs\Accessories\IMVU\Run IMVU.lnk<br>TCP: {9558635E-9318-4CFB-AAA9-3C744258E07D} = 4.2.2.2<br>DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab<br>DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab<br>FF - ProfilePath - c:\documents and settings\The Apples\Application Data\Mozilla\Firefox\Profiles\sp5ctm0p.default\<br>FF - prefs.js: browser.startup.homepage - hxxp://www.my.yahoo.com/<br>FF - prefs.js: keyword.URL - hxxp://www.ask.com/web?o=101447&l=dis&q=<br>FF - prefs.js: network.proxy.http - 63.149.98.96<br>FF - prefs.js: network.proxy.type - 1<br>FF - component: c:\documents and settings\The Apples\Application Data\Mozilla\Firefox\Profiles\sp5ctm0p.default\extensions\{7affbfae-c4e2-4915-8c0f-00fa3ec610a1}\components\WinampPlayer.dll<br>FF - plugin: c:\program files\Google\Google Updater\2.4.1508.6312\npCIDetect13.dll<br>FF - plugin: c:\program files\Mozilla Firefox\plugins\npmozax.dll<br>FF - plugin: c:\program files\Mozilla Firefox\plugins\npqtplugin8.dll<br>FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dll<br>FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint_.dll<br>FF - plugin: c:\program files\Mozilla Firefox\plugins\npvirtools.dll<br>FF - plugin: c:\program files\QuickTime\Plugins\npqtplugin8.dll<br>FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll<br>FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}<br>.<br><br>**************************************************************************<br><br>catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, &raquo;<A HREF="http://www.gmer.net" >www.gmer.net</A><br>Rootkit scan 2009-06-27 15:45<br>Windows 5.1.2600 Service Pack 2 NTFS<br><br>scanning hidden processes ...  <br><br>scanning hidden autostart entries ... <br><br>scanning hidden files ...  <br><br>scan completed successfully<br>hidden files: 0<br><br>**************************************************************************<br>.<br>------------------------ Other Running Processes ------------------------<br>.<br>c:\program files\Alwil Software\Avast4\aswUpdSv.exe<br>c:\program files\Alwil Software\Avast4\ashServ.exe<br>c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br>c:\windows\system32\CTsvcCDA.EXE<br>c:\windows\system32\nvsvc32.exe<br>c:\windows\system32\MsPMSPSv.exe<br>c:\windows\system32\rundll32.exe<br>c:\program files\iPod\bin\iPodService.exe<br>c:\windows\system32\taskmgr.exe<br>.<br>**************************************************************************<br>.<br>Completion time: 2009-06-27 15:56 - machine was rebooted<br>ComboFix-quarantined-files.txt  2009-06-27 19:56<br><br>Pre-Run: 34,343,313,408 bytes free<br>Post-Run: 36,981,579,776 bytes free<br><br>WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe<br>[boot loader]<br>timeout=2<br>default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS<br>[operating systems]<br>c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons<br>multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn<br><br>263&#9;--- E O F ---&#9;2009-06-27 19:55<br><br>HJT Log: <br><br>Logfile of Trend Micro HijackThis v2.0.2<br>Scan saved at 3:59:35 PM, on 6/27/2009<br>Platform: Windows XP SP2 (WinNT 5.01.2600)<br>MSIE: Internet Explorer v7.00 (7.00.6000.16674)<br>Boot mode: Normal<br><br>Running processes:<br>C:\WINDOWS\System32\smss.exe<br>C:\WINDOWS\system32\winlogon.exe<br>C:\WINDOWS\system32\services.exe<br>C:\WINDOWS\system32\lsass.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\Program Files\Windows Defender\MsMpEng.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe<br>C:\Program Files\Alwil Software\Avast4\ashServ.exe<br>C:\WINDOWS\system32\spoolsv.exe<br>C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br>C:\WINDOWS\System32\CTsvcCDA.exe<br>C:\WINDOWS\System32\nvsvc32.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\Program Files\Viewpoint\Common\ViewpointService.exe<br>C:\WINDOWS\System32\MsPMSPSv.exe<br>C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe<br>C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe<br>C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe<br>C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe<br>C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe<br>C:\Program Files\iTunes\iTunesHelper.exe<br>C:\WINDOWS\system32\RUNDLL32.EXE<br>C:\Program Files\Messenger\MSMSGS.EXE<br>C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe<br>C:\WINDOWS\system32\ctfmon.exe<br>C:\Program Files\Electronic Arts\EADM\Core.exe<br>C:\Program Files\iPod\bin\iPodService.exe<br>C:\WINDOWS\explorer.exe<br>C:\WINDOWS\system32\wuauclt.exe<br>C:\Program Files\Mozilla Firefox\firefox.exe<br>C:\WINDOWS\system32\wuauclt.exe<br>C:\Program Files\Alwil Software\Avast4\ashSimpl.exe<br>C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=69157" >go.microsoft.com/fwlink/?LinkId=69157</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=69157" >go.microsoft.com/fwlink/?LinkId=69157</A><br>O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll<br>O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll<br>O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll<br>O2 - BHO: Neopets - {CD292324-974F-4224-D074-CACA427AA030} - C:\PROGRA~1\Neopets\Toolbar\Toolbar.dll<br>O3 - Toolbar: Neopets - {CD292324-974F-4224-D074-CACA427AA030} - C:\PROGRA~1\Neopets\Toolbar\Toolbar.dll<br>O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll<br>O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup<br>O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE<br>O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe<br>O4 - HKLM\..\Run: [HPHmon03] C:\WINDOWS\System32\hphmon03.exe<br>O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"<br>O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe<br>O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup<br>O4 - HKLM\..\Run: [nwiz] nwiz.exe /install<br>O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"<br>O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime<br>O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"<br>O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"<br>O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit<br>O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background<br>O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe<br>O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br>O4 - HKCU\..\Run: [EA Core] "C:\Program Files\Electronic Arts\EADM\Core.exe" -silent<br>O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')<br>O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')<br>O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE<br>O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000<br>O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll<br>O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll<br>O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll<br>O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll<br>O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL<br>O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\The Apples\Start Menu\Programs\Accessories\IMVU\Run IMVU.lnk (file missing)<br>O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - &raquo;<A HREF="http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1178474503890" >update.microsoft.com/windowsupda&middot;&middot;&middot;74503890</A><br>O16 - DPF: {BD08A9D5-0E5C-4F42-99A3-C0CB5E860557} (CSolidBrowserObj Object) - &raquo;<A HREF="http://www.solidstatenetworks.com/demos/onrpg/solidstateion.cab" >www.solidstatenetworks.com/demos&middot;&middot;&middot;eion.cab</A><br>O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - &raquo;<small>https</small>://<A HREF="https://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab">fpdownload.macromedia.com/pub/sh&middot;&middot;&middot;lash.cab</A><br>O17 - HKLM\System\CCS\Services\Tcpip\..\{9558635E-9318-4CFB-AAA9-3C744258E07D}: NameServer = 4.2.2.2<br>O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br>O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe<br>O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe<br>O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe<br>O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe<br>O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe<br>O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br>O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br>O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe<br>O23 - Service: Pml Driver - HP - C:\WINDOWS\System32\HPHipm09.exe<br>O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe<br><br>--<br>End of file - 7552 bytes<br><br>Sorry for the delay.<br><small>--<br>Apple. Switch to Mac. &raquo;<A HREF="http://www.apple.com/getamac" >www.apple.com/getamac</A></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22620987</guid>
<pubDate>Sat, 27 Jun 2009 16:00:19 EDT</pubDate>
</item>

<item>
<title>Re: [Trojan] can not install any security apps, run any online s</title>
<link>http://www.dslreports.com/forum/remark,22517328</link>
<description><![CDATA[<A HREF="/useremail/u/377471"><b>TheJoker</b></A> : OK, and they may be able to continue the instructions themselves at that point also. :)<br><small>--<br>Proud ASAP member since 2005</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22517328</guid>
<pubDate>Mon, 08 Jun 2009 17:25:58 EDT</pubDate>
</item>

<item>
<title>Re: [Trojan] can not install any security apps, run any online s</title>
<link>http://www.dslreports.com/forum/remark,22514907</link>
<description><![CDATA[<A HREF="/useremail/u/728753"><b>File Quit</b></A> : The machine is a relative's machine that was brought to me. I already have returned it, but I will update you with the HijackThis and ComboFix log when I visit them in a few days.<br><br>Thank you for your help.<br><small>--<br>Apple. Switch to Mac. &raquo;<A HREF="http://www.apple.com/getamac" >www.apple.com/getamac</A></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22514907</guid>
<pubDate>Mon, 08 Jun 2009 10:46:20 EDT</pubDate>
</item>

<item>
<title>Re: [Trojan] can not install any security apps, run any online s</title>
<link>http://www.dslreports.com/forum/remark,22513938</link>
<description><![CDATA[<A HREF="/useremail/u/377471"><b>TheJoker</b></A> : File Quit, there will possibly be more to remove once you post the needed logs. Since the MBAM log was clean, you don't need to post that log, but I do need the HijackThis log and the ComboFix log. The ComboFix log may show other items that need to be removed, and afterward, it will need to be uninstalled, or anything it removed, although in quarantine, will still be on your system.<br><small>--<br>Proud ASAP member since 2005</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22513938</guid>
<pubDate>Mon, 08 Jun 2009 05:38:56 EDT</pubDate>
</item>

<item>
<title>Re: [Trojan] can not install any security apps, run any online s</title>
<link>http://www.dslreports.com/forum/remark,22513909</link>
<description><![CDATA[<A HREF="/useremail/u/751678"><b>lilhurricane</b></A> : you aren't done yet.... :)<br><br>/enter script<br><br>When you perform the guidelines here for pre-clean requirements, and start a help thread - you are embarking on a journey.<br><br>You're one part of the effort to confirm safe passage on the internet, and your "helper" is the other. It's teamwork at it's finest.<br><br>Our expectations - from start to finish are that we leave you safe and clean, and educated on how to prevent re-infection.<br>This is a free service we offer, and our volunteers are unpaid. They do it because they truly enjoy helping people.<br><br>Please follow all of the requests made by your Helper, including submitting to the Forum all log results.<br>This helps others who frequent this forum to learn or who are seeking answers as well, to see what is going on.<br><br>We need to ascertain that everything is truly "ok".<br><br>Note that many of the utilities utilized require a formal uninstall process to return your system to a normal operating state.<br><br>It's work - yes, but it's necessary.<br><br>Therefore, we ask you please see this through till your "helper" deems you "clean". You can do it!<br><small>--<br><b>~<A HREF="/forum/cleanup">Safe Hex</a>~<A HREF="/forum/disco"> Team Discovery</a></b> <b><A HREF="http://www.tdprojecthope.com/"> ~ Project Hope ~ </b><b><A HREF="http://www.azlyrics.com/lyrics/neilyoung/likeahurricane.html">Like A Hurricane~</a></b></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22513909</guid>
<pubDate>Mon, 08 Jun 2009 05:04:57 EDT</pubDate>
</item>

<item>
<title>Re: [Trojan] can not install any security apps, run any online s</title>
<link>http://www.dslreports.com/forum/remark,22513664</link>
<description><![CDATA[<A HREF="/useremail/u/728753"><b>File Quit</b></A> : After following these steps, Malwarebytes does not show anything malicious, and the computer is running MUCH quicker. Thank you both for your help!!<br><small>--<br>Apple. Switch to Mac. &raquo;<A HREF="http://www.apple.com/getamac" >www.apple.com/getamac</A></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22513664</guid>
<pubDate>Mon, 08 Jun 2009 01:56:31 EDT</pubDate>
</item>

<item>
<title>Re: [Trojan] can not install any security apps, run any online s</title>
<link>http://www.dslreports.com/forum/remark,22511938</link>
<description><![CDATA[<A HREF="/useremail/u/377471"><b>TheJoker</b></A> : Hi File Quit<br><br>I suggest printing out each set of instructions and reading the entire post before proceeding. It will make following them easier. Please follow the directions in the order listed.<br><br>Please <b>disable your Windows Defender Real-time Protection</b> as it may interfere with the fixes that we need to make.<br><br>Open Windows Defender.<br>Click on Tools, General Settings.<br>Scroll down and uncheck Turn on real-time protection (recommended).<br>After you uncheck this, click on the Save button and close Windows Defender.<br>After all of the fixes are complete it is very important that you enable Real-time Protection again.<br><br>Clean your Cache and Cookies in IE:<br>-Close all instances of Outlook Express and Internet Explorer <br>-Go to Control Panel > Internet Options > General tab<br>-Click the "Delete Cookies" button<br>-Next to it, Click the "Delete Files" button<br>-When prompted, place a check in: "Delete all offline content", click OK<br>Clean your Cache and Cookies in Firefox (In case you also have Firefox installed):<br>Go to Tools > Options.<br>Click Privacy in the menu on the left side of the Options window.<br>Click the Clear button located to the right of each option (History, Cookies, Private Data).<br>Click OK to close the Options window<br>Alternatively, you can clear all information stored while browsing by clicking Clear All. <br>A confirmation dialog box will be shown before clearing the information.<br>Clean other Temporary files + Recycle bin<br>-Go to start > run and type: <b>cleanmgr</b> and click ok.<br>-Let it scan your system for files to remove.<br>-Make sure Temporary Files, Temporary Internet Files, and Recycle Bin are the only things checked.<br>-Press OK to remove them.<br><br>I see you have Viewpoint installed...<br><b>Viewpoint Manager</b> is considered to be <b>foistware</b> instead of malware since it is installed without users approval, but doesn't spy or do anything "bad". This will change though, please read this article:<br>&raquo;<A HREF="http://www.clickz.com/news/article.php/3561546" >www.clickz.com/news/article.php/3561546</A><br>I suggest you remove the program now. Go to <b>Start</b> > <b>Settings</b> > <b>Control Panel</b> > <b>Add/Remove Programs</b> and remove the following programs if present:<b><br>- Viewpoint<br>- Viewpoint Manager<br>- Viewpoint Media Player</b><br>Reboot afterwards. -- <b>Important!</b><br><br>If you chose to uninstall Viewpoint, after rebooting, using Windows Explorer delete the following folder if still there:<br>C:\Program Files\<b>Viewpoint</b><br><br>Go to Start > Control Panel > Add or Remove Programs and remove the following programs, if found:<br><b>Neopets Toolbar</b><br><br>Then, using Windows Explorer, delete the following folder if still there:<br>C:\Program Files\Neopets\<b>Toolbar</b><br><br>IMVU 3D messenger has been known to cause problems and, unless it is something you really want to keep, I recommend optionally removing it using the Control Panel's Add or Remove Programs.<br><br>Please Run Malwarebytes' Anti-Malware.<br>- Click the Update tab.<br>- Click Check for Updates.<br>- If an update is found, it will download and install.<br>- Click the Scanner tab.<br>- Select "<b>Perform Quick Scan</b>", then click <b>Scan</b>.<br>- The scan may take some time to finish,so please be patient.<br>- When the scan is complete, click OK, then Show Results to view the results.<br>- Make sure that <b>everything is checked</b>, and click <b>Remove Selected</b>.<br>- When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Note)<br>- The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.<br>- Copy & Paste the entire report in your next reply along with a fresh HijackThis log.<br><br>Note:<br><i>If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts.<br>Click OK to either and let MBAM proceed with the disinfection process.<br>If asked to restart the computer, please do so immediately.</i><br><br>Now you need to run HijackThis and click "<b>Do a system scan only</b>." Place a check next to the following entries (if they are still there):<br><br><b>R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =<br>R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =<br>R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = &raquo;www.fulldotfinds.com/pubac/ac.ph&middot;&middot;&middot;sid=v300<br>R3 - Default URLSearchHook is missing<br>O4 - HKLM\..\Run: [runner1] C:\WINDOWS\retadpu2000352.exe 61A847B5BBF72810329B385577FB01F0B3E35B6638993F4661AA4EBD86D67C56389B284534F310<br>O4 - HKLM\..\Run: [SC2] C:\WINDOWS\system32\scchk32.exe<br>O4 - HKLM\..\Run: [GPLv3] rundll32.exe "C:\WINDOWS\system32\wwusjvrf.dll",realset<br>O22 - SharedTaskScheduler: ceroxylon - {c96395b8-ab09-46a4-b539-7ddf6e061808} - (no file)</b><br><br>If you uninstalled IMVU as recommended, also check (if still there):<br>O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\The Apples\Start Menu\Programs\Accessories\IMVU\Run IMVU.lnk (file missing)[/B]<br><br>You can <b>optionally</b> check the following entry. This is a reminder to register your Creative Labs SoundBlaster Live! Card, and not necessary to running your system:<br><b>O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE<br><br>Now close all browser and other windows except for HijackThis, and click "[B]Fix Checked</b>" to have HijackThis fix the entries you checked.<br><br>Reconfigure Windows XP to show hidden files:<br>Click Start. Open My Computer. <br>Select the Tools menu and click Folder Options. Select the View Tab. <br>Under the Hidden files and folders heading select "Show hidden files and folders". <br>Uncheck the "Hide protected operating system files (recommended)" option. <br>Uncheck the "Hide file extensions for known file types" option.<br>Click Yes to confirm. Click OK.<br><br>Using Windows Explorer, locate the following files, and delete them:<br>C:\WINDOWS\<b>retadpu2000352.exe</b> <br>C:\WINDOWS\system32\<b>scchk32.exe</b><br>C:\WINDOWS\system32\<b>wwusjvrf.dll</b><br><br>Now you need to hide the files you un-hid earlier:<br>Click Start. Open My Computer.<br>Select the Tools menu and click Folder Options. Select the View Tab. <br>Under the Hidden files and folders heading unselect "Show hidden files and folders". <br>Check the "Hide protected operating system files (recommended)" option. <br>Click Yes to confirm. Click OK.<br><br>Download <b>ComboFix&copy; by sUBs</b> from one of these locations:<br><br><textarea name="code" class="text" cols=50 rows=10>http://download.bleepingcomputer.com/sUBs/ComboFix.exe&#012;http://www.forospyware.com/sUBs/ComboFix.exe&#012;http://subs.geekstogo.com/ComboFix.exe&#012;</textarea><!--end code block--><br><b>* IMPORTANT !!! Save ComboFix.exe to your Desktop</b><br><br>Familiarize yourself with ComboFix before running it:<br>&raquo;<A HREF="http://www.bleepingcomputer.com/combofix/how-to-use-combofix" >www.bleepingcomputer.com/combofi&middot;&middot;&middot;combofix</A><br><br>- Disable your AntiVirus and any AntiSpyware programs you may be running (usually via a right click on the System Tray icon) to prevent them from interfering.<br><br>- Double click on ComboFix.exe & follow the prompts.<br><br>- As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal.  It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware. <br><br>- Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.<br><br>**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.<br><br> <IMG SRC="http://img.photobucket.com/albums/v706/ried7/RcAuto1.gif"> <br><br>Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:<br><br> <IMG SRC="http://img.photobucket.com/albums/v706/ried7/whatnext.png"> <br><br>Click on Yes, to continue scanning for malware. When finished, it will save a log. <br>Please include the contents of the log at <b>C:\ComboFix.txt</b> in your next reply.<br><br>Please post a new HijackThis log, the log from MBAM, the log from ComboFix (combofix.tst), and note any errors encountered.<br><br><small>--<br>Proud ASAP member since 2005</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22511938</guid>
<pubDate>Sun, 07 Jun 2009 18:06:07 EDT</pubDate>
</item>

<item>
<title>Re: [Trojan] can not install any security apps, run any online s</title>
<link>http://www.dslreports.com/forum/remark,22511509</link>
<description><![CDATA[<A HREF="/useremail/u/751678"><b>lilhurricane</b></A> : <div class="bquote"><small>said by  File Quit <A HREF="/useremail/u/728753"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>After talking with lilhurricane, I managed to get MBAM to work.  </div>Good job, FQ :)<br><br>Hang in there & we'll have you looked at as soon as possible]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22511509</guid>
<pubDate>Sun, 07 Jun 2009 16:05:59 EDT</pubDate>
</item>

<item>
<title>Re: [Trojan] can not install any security apps, run any online s</title>
<link>http://www.dslreports.com/forum/remark,22511346</link>
<description><![CDATA[<A HREF="/useremail/u/728753"><b>File Quit</b></A> : After talking with lilhurricane, I managed to get MBAM to work. Here is it's log and an updated HJT log:<br><br>MBAM:<br><br>Malwarebytes' Anti-Malware 1.36<br>Database version: 2162<br>Windows 5.1.2600 Service Pack 2<br><br>6/7/2009 3:12:59 PM<br>mbam-log-2009-06-07 (15-12-58).txt<br><br>Scan type: Quick Scan<br>Objects scanned: 100598<br>Time elapsed: 17 minute(s), 13 second(s)<br><br>Memory Processes Infected: 0<br>Memory Modules Infected: 2<br>Registry Keys Infected: 34<br>Registry Values Infected: 8<br>Registry Data Items Infected: 5<br>Folders Infected: 5<br>Files Infected: 161<br><br>Memory Processes Infected:<br>(No malicious items detected)<br><br>Memory Modules Infected:<br>C:\WINDOWS\system32\tuvstRjj.dll (Trojan.Vundo.H) -> Delete on reboot.<br>C:\WINDOWS\system32\nnnMDVLD.dll (Trojan.Vundo.H) -> Delete on reboot.<br><br>Registry Keys Infected:<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{49391a26-b1be-4187-a6d5-20fddd330d72} (Trojan.Vundo.H) -> Quarantined and deleted successfully.<br>HKEY_CLASSES_ROOT\CLSID\{49391a26-b1be-4187-a6d5-20fddd330d72} (Trojan.Vundo.H) -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8a61098d-612b-4ef2-943d-64e920684061} (Trojan.Vundo.H) -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\qommnop (Trojan.Vundo.H) -> Quarantined and deleted successfully.<br>HKEY_CLASSES_ROOT\CLSID\{8a61098d-612b-4ef2-943d-64e920684061} (Trojan.Vundo.H) -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{96db5e4e-14ff-452c-8562-35e1d1fda713} (Trojan.Vundo.H) -> Delete on reboot.<br>HKEY_CLASSES_ROOT\CLSID\{96db5e4e-14ff-452c-8562-35e1d1fda713} (Trojan.Vundo.H) -> Delete on reboot.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{ae55c7ec-82f8-46cb-8dc2-57bf42f025ff} (Trojan.Vundo.H) -> Delete on reboot.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\nnnmdvld (Trojan.Vundo.H) -> Delete on reboot.<br>HKEY_CLASSES_ROOT\CLSID\{ae55c7ec-82f8-46cb-8dc2-57bf42f025ff} (Trojan.Vundo.H) -> Delete on reboot.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{b05f76ec-1f5c-414c-bb66-1d5db39f7619} (Trojan.Vundo.H) -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\awvtr (Trojan.Vundo.H) -> Quarantined and deleted successfully.<br>HKEY_CLASSES_ROOT\CLSID\{b05f76ec-1f5c-414c-bb66-1d5db39f7619} (Trojan.Vundo.H) -> Quarantined and deleted successfully.<br>HKEY_CLASSES_ROOT\CLSID\{53b5f2b1-94dd-43e5-8187-eb4e31f00701} (Trojan.Vundo) -> Quarantined and deleted successfully.<br>HKEY_CLASSES_ROOT\CLSID\{d263fa6d-84cc-48a8-9af6-c664362b7a5b} (Trojan.BHO) -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d263fa6d-84cc-48a8-9af6-c664362b7a5b} (Trojan.BHO) -> Quarantined and deleted successfully.<br>HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{9034a523-d068-4be8-a284-9df278be776e} (Trojan.Zlob) -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{9034a523-d068-4be8-a284-9df278be776e} (Trojan.Zlob) -> Quarantined and deleted successfully.<br>HKEY_CLASSES_ROOT\CLSID\{995cad88-40af-482d-bff6-e1ad18f7ceec} (Trojan.Vundo.H) -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winccf32 (Dialer) -> Quarantined and deleted successfully.<br>HKEY_CLASSES_ROOT\WR (Malware.Trace) -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Track System (Trojan.Vundo) -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Windows Safety Alert (Trojan.Zlob) -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MSSMGR (Trojan.Downloader) -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\aoprndtws (Trojan.Vundo) -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PSRV (Trojan.Agent) -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DomainService (Trojan.Agent) -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DomainService (Trojan.Agent) -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SOFTWARE\UAC (Rootkit.Trace) -> Quarantined and deleted successfully.<br><br>Registry Values Infected:<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\acf7d636 (Trojan.Vundo.H) -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\11443754 (Rogue.Multiple.H) -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\91453746 (Rogue.Multiple.H) -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{8a61098d-612b-4ef2-943d-64e920684061} (Trojan.Vundo) -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{995cad88-40af-482d-bff6-e1ad18f7ceec} (Trojan.Vundo.H) -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{995cad88-40af-482d-bff6-e1ad18f7ceec} (Trojan.Vundo.H) -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{ae55c7ec-82f8-46cb-8dc2-57bf42f025ff} (Trojan.Vundo.H) -> Delete on reboot.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\some (Trojan.Zlob) -> Quarantined and deleted successfully.<br><br>Registry Data Items Infected:<br>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Notification Packages (Trojan.Vundo.H) -> Data: c:\windows\system32\tuvstrjj -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Authentication Packages (Trojan.Vundo.H) -> Data: c:\windows\system32\tuvstrjj  -> Delete on reboot.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.<br><br>Folders Infected:<br>C:\Documents and Settings\All Users\Application Data\11443754 (Rogue.Multiple.H) -> Quarantined and deleted successfully.<br>C:\Documents and Settings\All Users\Application Data\91453746 (Rogue.Multiple.H) -> Quarantined and deleted successfully.<br>C:\Program Files\InetGet2 (Trojan.Downloader) -> Quarantined and deleted successfully.<br>C:\Program Files\WinPop (Adware.WinPop) -> Quarantined and deleted successfully.<br>C:\Program Files\A360 (Rogue.A360Antivirus) -> Quarantined and deleted successfully.<br><br>Files Infected:<br>C:\WINDOWS\system32\kzhiwd.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\qommnop.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\tuvstRjj.dll (Trojan.Vundo.H) -> Delete on reboot.<br>C:\WINDOWS\system32\jjRtsvut.ini (Trojan.Vundo.H) -> Delete on reboot.<br>C:\WINDOWS\system32\jjRtsvut.ini2 (Trojan.Vundo.H) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\nnnMDVLD.dll (Trojan.Vundo.H) -> Delete on reboot.<br>C:\WINDOWS\system32\awvtr.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\bgefbxvy.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\yvxbfegb.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\bjecgiec.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\ceigcejb.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\gthooxhm.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\mhxoohtg.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\igctfbho.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\ohbftcgi.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\jkjceqqp.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\pqqecjkj.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\mooyeeve.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\eveeyoom.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\myxqcsvr.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\rvscqxym.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\opwjfkbx.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\xbkfjwpo.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\qwyoorma.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\amrooywq.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\ybedkgux.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\xugkdeby.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.<br>C:\Documents and Settings\All Users\Application Data\11443754\11443754.exe (Rogue.Multiple.H) -> Quarantined and deleted successfully.<br>C:\Documents and Settings\All Users\Application Data\11443754\11443754.glu (Rogue.Multiple.H) -> Quarantined and deleted successfully.<br>C:\Documents and Settings\All Users\Application Data\91453746\91453746.exe (Rogue.Multiple.H) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\winconfig.dll (Trojan.BHO) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\adulqwut.dll (Trojan.Vundo) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\aduxhumj.dll (Trojan.Vundo) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\afrnmdsd.dll (Trojan.Vundo) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\agfnrk.dll (Trojan.Vundo) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\amvsue.dll (Trojan.Vundo) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\auhpmchp.dll (Trojan.Vundo.V) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\bavglpge.dll (Trojan.Vundo) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\bbultr.dll (Trojan.Vundo.V) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\btcmrjlr.dll (Trojan.Vundo) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\cfopwb.dll (Trojan.Vundo) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\ciyukgfo.dll (Trojan.Vundo.V) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\clpxqx.dll (Trojan.Vundo) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\cmbrwf.dll (Trojan.Vundo) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\cmyxsp.dll (Trojan.Vundo) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\djrgqr.dll (Trojan.Vundo) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\dnnypc.dll (Trojan.Vundo) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\dqomjj.dll (Trojan.Vundo) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\dvlyjo.dll (Trojan.Vundo) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\easlfl.dll (Trojan.Vundo) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\ejyrtifk.dll (Trojan.Vundo) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\erfzuc.dll (Trojan.Vundo) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\fccYrqom.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\fdpmxeit.dll (Trojan.Vundo) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\fhduemdv.dll (Trojan.Vundo) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\fksdpsqq.dll (Trojan.Vundo) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\folpxw.dll (Trojan.Agent) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\forntwwa.dll (Trojan.Vundo) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\fsxqrvgv.dll (Trojan.Vundo) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\fyagqbbn.dll (Trojan.Agent) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\gdigdr.dll (Trojan.Vundo) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\gnhbweic.dll (Trojan.Vundo) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\gqhsnd.dll (Trojan.Vundo) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\gtaodoxx.dll (Trojan.Vundo.V) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\hklyhc.dll (Trojan.Vundo) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\hppmriox.dll (Trojan.Vundo) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\hsdnbaxe.dll (Trojan.Vundo) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\hysqrwwg.dll (Trojan.Vundo) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\iqupnsjt.dll (Trojan.Vundo) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\kkrfnyxu.dll (Trojan.Vundo) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\kyvlfo.dll (Trojan.Vundo) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\kzqpfr.dll (Trojan.Vundo.V) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\lacfxu.dll (Trojan.Vundo) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\lbinjrnv.dll (Trojan.Vundo) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\lbslrlda.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\luroas.dll (Trojan.Vundo) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\mgeiyhol.dll (Trojan.Vundo) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\mgpdcbaa.dll (Trojan.Vundo) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\mqublgea.dll (Trojan.Vundo) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\mxieynjj.dll (Trojan.Vundo) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\nnivtgmq.dll (Trojan.Vundo) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\ocxrdi.dll (Trojan.Vundo) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\oojwflmw.dll (Trojan.Vundo) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\opilxsxk.dll (Trojan.Vundo) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\owxzlg.dll (Trojan.Vundo) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\pfgjjgih.dll (Trojan.Vundo.V) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\pgnqwgau.dll (Trojan.Vundo) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\pkduwt.dll (Trojan.Vundo) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\porpuy.dll (Trojan.Vundo) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\prvtml.dll (Trojan.Vundo) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\psrhbh.dll (Trojan.Vundo) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\pvnoqctm.dll (Trojan.Vundo) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\pxomixmd.dll (Trojan.Vundo) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\pyfiprlo.dll (Trojan.Vundo) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\qftujksf.dll (Trojan.Vundo) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\qjlyelog.dll (Trojan.Vundo) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\qoiwbeev.dll (Trojan.Vundo) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\qrvyybkb.dll (Trojan.Vundo) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\rjuassxi.dll (Trojan.Vundo) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\rmjgpw.dll (Trojan.Vundo) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\rmqwao.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\ropinmoe.dll (Trojan.Vundo) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\rwwend.dll (Trojan.Vundo) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\sbkolxpo.dll (Trojan.Vundo) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\sbxxrgyo.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\sgmcuu.dll (Trojan.Vundo) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\sydqvydp.dll (Trojan.Vundo.V) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\tbpfre.dll (Trojan.Vundo.V) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\tdbvat.dll (Trojan.Vundo) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\towebo.dll (Trojan.Vundo) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\tpbdzo.dll (Trojan.Vundo.V) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\uawvpvqn.dll (Trojan.Vundo) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\udcwop.dll (Trojan.Vundo) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\ufldrx.dll (Trojan.Vundo) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\ugmonvou.dll (Trojan.Vundo) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\uipgslke.dll (Trojan.Vundo) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\uiytnp.dll (Trojan.Vundo) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\vdmyyc.dll (Trojan.Vundo) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\voskcwnn.dll (Trojan.Vundo) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\wfmgia.dll (Trojan.Vundo) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\wqaatywc.dll (Trojan.Vundo) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\wqmaakan.dll (Trojan.Vundo) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\wrinen.dll (Trojan.Vundo) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\wvklde.dll (Trojan.Vundo) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\wwnscq.dll (Trojan.Vundo) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\xounoetg.dll (Trojan.Vundo) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\xsnuxxhk.dll (Trojan.Vundo) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\xxibyx.dll (Trojan.Vundo.V) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\ycnenl.dll (Trojan.Vundo) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\ylgfwu.dll (Trojan.Vundo) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\yzbtoc.dll (Trojan.Vundo) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\zgtqsz.dll (Trojan.Vundo) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\zqfpva.dll (Trojan.Vundo) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\zvigwb.dll (Trojan.Vundo) -> Quarantined and deleted successfully.<br>C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\39DZCXH4\index[1] (Trojan.Vundo.H) -> Quarantined and deleted successfully.<br>C:\Documents and Settings\The Apples\Local Settings\Temporary Internet Files\Content.IE5\PWLRJGP5\index[1] (Trojan.Vundo.H) -> Quarantined and deleted successfully.<br>C:\Documents and Settings\The Apples\Local Settings\Temporary Internet Files\Content.IE5\Z0ZX5P1D\index[4] (Trojan.Vundo.V) -> Quarantined and deleted successfully.<br>C:\Program Files\A360\av360.exe (Rogue.A360Antivirus) -> Quarantined and deleted successfully.<br>C:\Documents and Settings\The Apples\Desktop\A360.lnk (Rogue.Antivirus360) -> Quarantined and deleted successfully.<br>C:\Documents and Settings\The Apples\Application Data\Microsoft\Internet Explorer\Quick Launch\A360.lnk (Rogue.Antivirus360) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\winccf32.dll (Dialer) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\uacinit.dll (Trojan.Agent) -> Delete on reboot.<br>C:\Documents and Settings\The Apples\Local Settings\Temp\lla1.exe (Trojan.Zlob) -> Quarantined and deleted successfully.<br>C:\Documents and Settings\The Apples\My Documents\My Music\My Music.url (Trojan.Zlob) -> Quarantined and deleted successfully.<br>C:\Documents and Settings\The Apples\My Documents\My Pictures\My Pictures.url (Trojan.Zlob) -> Quarantined and deleted successfully.<br>C:\Documents and Settings\The Apples\My Documents\My Videos\My Video.url (Trojan.Zlob) -> Quarantined and deleted successfully.<br>C:\Documents and Settings\The Apples\My Documents\My Documents.url (Trojan.Zlob) -> Quarantined and deleted successfully.<br>C:\WINDOWS\wr.txt (Malware.Trace) -> Quarantined and deleted successfully.<br>C:\Documents and Settings\The Apples\Local Settings\Temp\CD1.tmp (Heuristics.Malware) -> Quarantined and deleted successfully.<br>C:\Documents and Settings\All Users\Start Menu\Antivirus Scan.url (Trojan.Zlob) -> Quarantined and deleted successfully.<br>C:\Documents and Settings\All Users\Start Menu\Online Spyware Test.url (Trojan.Zlob) -> Quarantined and deleted successfully.<br>C:\Program Files\Applications\iebt.dll (Trojan.Zlob) -> Quarantined and deleted successfully.<br>C:\Program Files\Applications\iebtm.exe (Trojan.Zlob) -> Quarantined and deleted successfully.<br>C:\Program Files\Applications\iebtmm.exe (Trojan.Zlob) -> Quarantined and deleted successfully.<br>C:\Program Files\Applications\myd.ico (Trojan.Zlob) -> Quarantined and deleted successfully.<br>C:\Program Files\Applications\mym.ico (Trojan.Zlob) -> Quarantined and deleted successfully.<br>C:\Program Files\Applications\myp.ico (Trojan.Zlob) -> Quarantined and deleted successfully.<br>C:\Program Files\Applications\myv.ico (Trojan.Zlob) -> Quarantined and deleted successfully.<br>C:\Program Files\Applications\wcm.exe (Trojan.Zlob) -> Quarantined and deleted successfully.<br>C:\Documents and Settings\The Apples\Favorites\Antivirus Scan.url (Rogue.Link) -> Quarantined and deleted successfully.<br>C:\Program Files\Common Files\System\Uninstall\Uninstall A360.lnk (Rogue.av360) -> Quarantined and deleted successfully.<br><br>HJT:<br><br>Logfile of Trend Micro HijackThis v2.0.2<br>Scan saved at 3:19:11 PM, on 6/7/2009<br>Platform: Windows XP SP2 (WinNT 5.01.2600)<br>MSIE: Internet Explorer v7.00 (7.00.6000.16674)<br>Boot mode: Safe mode<br><br>Running processes:<br>C:\WINDOWS\System32\smss.exe<br>C:\WINDOWS\system32\winlogon.exe<br>C:\WINDOWS\system32\services.exe<br>C:\WINDOWS\system32\lsass.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\Program Files\Windows Defender\MsMpEng.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\WINDOWS\Explorer.EXE<br>C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br><br>R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=69157" >go.microsoft.com/fwlink/?LinkId=69157</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=69157" >go.microsoft.com/fwlink/?LinkId=69157</A><br>R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = <br>R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = &raquo;<A HREF="http://www.fulldotfinds.com/pubac/ac.php?aid=41&sid=v300" >www.fulldotfinds.com/pubac/ac.ph&middot;&middot;&middot;sid=v300</A><br>R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = <br>R3 - Default URLSearchHook is missing<br>O3 - Toolbar: Neopets - {CD292324-974F-4224-D074-CACA427AA030} - C:\PROGRA~1\Neopets\Toolbar\Toolbar.dll<br>O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll<br>O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup<br>O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE<br>O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe<br>O4 - HKLM\..\Run: [HPHmon03] C:\WINDOWS\System32\hphmon03.exe<br>O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"<br>O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe<br>O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup<br>O4 - HKLM\..\Run: [nwiz] nwiz.exe /install<br>O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide<br>O4 - HKLM\..\Run: [runner1] C:\WINDOWS\retadpu2000352.exe 61A847B5BBF72810329B385577FB01F0B3E35B6638993F4661AA4EBD86D67C56389B284534F310<br>O4 - HKLM\..\Run: [SC2] C:\WINDOWS\system32\scchk32.exe<br>O4 - HKLM\..\Run: [GPLv3] rundll32.exe "C:\WINDOWS\system32\wwusjvrf.dll",realset<br>O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"<br>O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime<br>O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"<br>O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"<br>O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u<br>O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent<br>O4 - HKLM\..\RunOnce: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\renamed.exe" /runcleanupscript<br>O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br>O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')<br>O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')<br>O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE<br>O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\npjpi160_02.dll<br>O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\npjpi160_02.dll<br>O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll<br>O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll<br>O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL<br>O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\The Apples\Start Menu\Programs\Accessories\IMVU\Run IMVU.lnk (file missing)<br>O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - &raquo;<A HREF="http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1178474503890" >update.microsoft.com/windowsupda&middot;&middot;&middot;74503890</A><br>O16 - DPF: {BD08A9D5-0E5C-4F42-99A3-C0CB5E860557} (CSolidBrowserObj Object) - &raquo;<A HREF="http://www.solidstatenetworks.com/demos/onrpg/solidstateion.cab" >www.solidstatenetworks.com/demos&middot;&middot;&middot;eion.cab</A><br>O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - &raquo;<small>https</small>://<A HREF="https://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab">fpdownload.macromedia.com/pub/sh&middot;&middot;&middot;lash.cab</A><br>O22 - SharedTaskScheduler: ceroxylon - {c96395b8-ab09-46a4-b539-7ddf6e061808} - (no file)<br>O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br>O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe<br>O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe<br>O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe<br>O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe<br>O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe<br>O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br>O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br>O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe<br>O23 - Service: Pml Driver - HP - C:\WINDOWS\System32\HPHipm09.exe<br>O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe<br><br>--<br>End of file - 6512 bytes<br><small>--<br>Apple. Switch to Mac. &raquo;<A HREF="http://www.apple.com/getamac" >www.apple.com/getamac</A></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22511346</guid>
<pubDate>Sun, 07 Jun 2009 15:21:25 EDT</pubDate>
</item>

<item>
<title>[Trojan] can not install any security apps, run any online scans</title>
<link>http://www.dslreports.com/forum/remark,22511091</link>
<description><![CDATA[<A HREF="/useremail/u/728753"><b>File Quit</b></A> : I am getting redirects to windowsclick.com for many of the security sites. It will not let me install Malwarebytes, or run House Call antivirus.  The HOSTS file is clean.<br><br>Here is my HijackThis logs: <br><br>Logfile of Trend Micro HijackThis v2.0.2<br>Scan saved at 2:09:35 PM, on 6/7/2009<br>Platform: Windows XP SP2 (WinNT 5.01.2600)<br>MSIE: Internet Explorer v7.00 (7.00.6000.16674)<br>Boot mode: Safe mode<br><br>Running processes:<br>C:\WINDOWS\System32\smss.exe<br>C:\WINDOWS\system32\winlogon.exe<br>C:\WINDOWS\system32\services.exe<br>C:\WINDOWS\system32\lsass.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\Program Files\Windows Defender\MsMpEng.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\WINDOWS\Explorer.EXE<br>C:\Program Files\Internet Explorer\Iexplore.exe<br>C:\WINDOWS\system32\ctfmon.exe<br>C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br><br>R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=69157" >go.microsoft.com/fwlink/?LinkId=69157</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=69157" >go.microsoft.com/fwlink/?LinkId=69157</A><br>R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = <br>R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = &raquo;<A HREF="http://www.fulldotfinds.com/pubac/ac.php?aid=41&sid=v300" >www.fulldotfinds.com/pubac/ac.ph&middot;&middot;&middot;sid=v300</A><br>R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = <br>R3 - Default URLSearchHook is missing<br>O3 - Toolbar: Neopets - {CD292324-974F-4224-D074-CACA427AA030} - C:\PROGRA~1\Neopets\Toolbar\Toolbar.dll<br>O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll<br>O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup<br>O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE<br>O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe<br>O4 - HKLM\..\Run: [HPHmon03] C:\WINDOWS\System32\hphmon03.exe<br>O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"<br>O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe<br>O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup<br>O4 - HKLM\..\Run: [nwiz] nwiz.exe /install<br>O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide<br>O4 - HKLM\..\Run: [runner1] C:\WINDOWS\retadpu2000352.exe 61A847B5BBF72810329B385577FB01F0B3E35B6638993F4661AA4EBD86D67C56389B284534F310<br>O4 - HKLM\..\Run: [SC2] C:\WINDOWS\system32\scchk32.exe<br>O4 - HKLM\..\Run: [GPLv3] rundll32.exe "C:\WINDOWS\system32\wwusjvrf.dll",realset<br>O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"<br>O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime<br>O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"<br>O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"<br>O4 - HKLM\..\Run: [acf7d636] rundll32.exe "C:\WINDOWS\system32\igctfbho.dll",b<br>O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u<br>O4 - HKLM\..\Run: [11443754] C:\Documents and Settings\All Users\Application Data\11443754\11443754.exe<br>O4 - HKLM\..\Run: [91453746] C:\Documents and Settings\All Users\Application Data\91453746\91453746.exe<br>O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br>O4 - HKLM\..\Policies\Explorer\Run: [some] C:\Program Files\Applications\wcs.exe<br>O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')<br>O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')<br>O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE<br>O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\npjpi160_02.dll<br>O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\npjpi160_02.dll<br>O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll<br>O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll<br>O9 - Extra button: (no name) - {9034A523-D068-4BE8-A284-9DF278BE776E} - &raquo;<A HREF="http://www.browseroption.com/redirect.php" >www.browseroption.com/redirect.php</A> (file missing)<br>O9 - Extra 'Tools' menuitem: IE Anti-Spyware - {9034A523-D068-4BE8-A284-9DF278BE776E} - &raquo;<A HREF="http://www.browseroption.com/redirect.php" >www.browseroption.com/redirect.php</A> (file missing)<br>O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL<br>O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\The Apples\Start Menu\Programs\Accessories\IMVU\Run IMVU.lnk (file missing)<br>O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - &raquo;<A HREF="http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1178474503890" >update.microsoft.com/windowsupda&middot;&middot;&middot;74503890</A><br>O16 - DPF: {BD08A9D5-0E5C-4F42-99A3-C0CB5E860557} (CSolidBrowserObj Object) - &raquo;<A HREF="http://www.solidstatenetworks.com/demos/onrpg/solidstateion.cab" >www.solidstatenetworks.com/demos&middot;&middot;&middot;eion.cab</A><br>O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - &raquo;<small>https</small>://<A HREF="https://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab">fpdownload.macromedia.com/pub/sh&middot;&middot;&middot;lash.cab</A><br>O22 - SharedTaskScheduler: ceroxylon - {c96395b8-ab09-46a4-b539-7ddf6e061808} - (no file)<br>O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br>O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe<br>O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe<br>O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe<br>O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe<br>O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe<br>O23 - Service: DomainService - Unknown owner - C:\WINDOWS\system32\xelpesgf.exe (file missing)<br>O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br>O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br>O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe<br>O23 - Service: Pml Driver - HP - C:\WINDOWS\System32\HPHipm09.exe<br>O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe<br><br>--<br>End of file - 7076 bytes<br><small>--<br>Apple. Switch to Mac. &raquo;<A HREF="http://www.apple.com/getamac" >www.apple.com/getamac</A></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22511091</guid>
<pubDate>Sun, 07 Jun 2009 14:11:00 EDT</pubDate>
</item>

</channel>
</rss>
