<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>[Trojan] Trojan Removal? in Security Cleanup</title>
<link>http://www.dslreports.com/forum/r22530270</link>
<description></description>
<language>en</language>
<pubDate>Fri, 27 Nov 2009 16:31:03 EDT</pubDate>
<lastBuildDate>Fri, 27 Nov 2009 16:31:03 EDT</lastBuildDate>

<item>
<title>Re: [Trojan] Trojan Removal?</title>
<link>http://www.dslreports.com/forum/remark,22545307</link>
<description><![CDATA[<A HREF="/useremail/u/377471"><b>TheJoker</b></A> : Not a problem. Remember though that even if symptoms are gone, you still need to post the logs as there will be more to do. We just don't know how much to do until the logs are reviewed.<br><small>--<br>Proud ASAP member since 2005</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22545307</guid>
<pubDate>Sat, 13 Jun 2009 11:25:59 EDT</pubDate>
</item>

<item>
<title>Re: [Trojan] Trojan Removal?</title>
<link>http://www.dslreports.com/forum/remark,22543096</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Thank you, in the process of doing this now, you must have taken ages doing this for me, really appreciate it.<br><br>:)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22543096</guid>
<pubDate>Fri, 12 Jun 2009 20:40:44 EDT</pubDate>
</item>

<item>
<title>Re: [Trojan] Trojan Removal?</title>
<link>http://www.dslreports.com/forum/remark,22537454</link>
<description><![CDATA[<A HREF="/useremail/u/377471"><b>TheJoker</b></A> :  <blockquote><small>quote:</small><hr>C:\Program Files\HijackThis\peanutbutter.exe<hr></blockquote><br>How appropriate, after I used some on a mousetrap this morning. :) :)<br><br>Your version of HijackThis is outdated. <br>Please download the current version of 'Hijack This!:<br>&raquo;<A HREF="http://www.trendsecure.com/portal/en-US/threat_analytics/hijackthis.php?page=download" >www.trendsecure.com/portal/en-US&middot;&middot;&middot;download</A><br>Please save it in a convenient <b>permanent</b> folder such as C:\HJT\, <br>and be sure the next log is with the newer version.<br>If it won't run (you may find that it will run now), rename it as last time.<br><br>Please <b>disable your Windows Defender Real-time Protection</b> as it may interfere with the fixes that we need to make.<br><br>Open Windows Defender.<br>Click on Tools, General Settings.<br>Scroll down and uncheck Turn on real-time protection (recommended).<br>After you uncheck this, click on the Save button and close Windows Defender.<br>After all of the fixes are complete it is very important that you enable Real-time Protection again.<br><br><b>You need to run an antivirus program</b> and keep it up-to-date.  I don't see one in your HijackThis log, although I see en entry that shows you had AVG 8 installed at one time. I recommend you go to Control Panel's Add or Remove Programs, and uninstall AVG 8 if there is still an entry for it. Then you need to reinstall an antivirus program. You can re-install AVG 8, but I would recommend that for now you try Avira AntiVir PersonalEdition Classic available at <A HREF="http://www.free-av.com">http://www.free-av.com</a>. It's an excellent scanner, and it will give a log to post, and there is a tutorial available on it's installation here:<br>&raquo;<A HREF="http://www.free-av.com/en/pages/20/Installing%20Avira%20AntiVir.html" >www.free-av.com/en/pages/20/Inst&middot;&middot;&middot;Vir.html</A>.<br><br>After installing AntiVir and updating it, perform a full system scan and clean everything found.<br>When the system scan completes, reboot.<br>After rebooting, open your Avira AntiVir and select "Reports".<br>Double-click the report from the full scan you just completed. Click the "Report File" button and copy and paste this report in your next reply.<br><br>Now you need to run HijackThis and click "<b>Do a system scan only</b>." Place a check next to the following entries (if they are still there):<br><br><b>O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (file missing)<br>O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)<br>O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)<br>O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)<br>O17 - HKLM\System\CCS\Services\Tcpip\..\{334D1067-913A-46B0-B67B-37FCBB2476C0}: NameServer = 85.255.112.24,85.255.112.118<br>O17 - HKLM\System\CCS\Services\Tcpip\..\{7F4D6420-A3C8-4AEE-A256-013B68992699}: NameServer = 85.255.112.24,85.255.112.118<br>O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.112.24,85.255.112.118<br>O17 - HKLM\System\CS1\Services\Tcpip\..\{334D1067-913A-46B0-B67B-37FCBB2476C0}: NameServer = 85.255.112.24,85.255.112.118<br>O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.112.24,85.255.112.118<br>O17 - HKLM\System\CS2\Services\Tcpip\..\{334D1067-913A-46B0-B67B-37FCBB2476C0}: NameServer = 85.255.112.24,85.255.112.118<br>O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.112.24,85.255.112.118</b><br><br>Now close all browser and other windows except for HijackThis, and click "<b>Fix Checked</b>" to have HijackThis fix the entries you checked.<br><br>Please Run Malwarebytes' Anti-Malware.<br>- Click the Update tab.<br>- <b>Click Check for Updates</b>, your database version is outdated.<br>- If an update is found, it will download and install.<br>- Click the Scanner tab.<br>- Select "<b>Perform Quick Scan</b>", then click <b>Scan</b>.<br>- The scan may take some time to finish,so please be patient.<br>- When the scan is complete, click OK, then Show Results to view the results.<br>- Make sure that <b>everything is checked</b>, and click <b>Remove Selected</b>.<br>- When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Note)<br>- The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.<br>- Copy & Paste the entire report in your next reply along with a fresh HijackThis log.<br><br>Note:<br><i>If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts.<br>Click OK to either and let MBAM proceed with the disinfection process.<br>If asked to restart the computer, please do so immediately.</i><br><br>Download <b>ComboFix&copy; by sUBs</b> from one of these locations:<br><br><textarea name="code" class="text" cols=50 rows=10>http://download.bleepingcomputer.com/sUBs/ComboFix.exe&#012;http://www.forospyware.com/sUBs/ComboFix.exe&#012;http://subs.geekstogo.com/ComboFix.exe&#012;</textarea><!--end code block--><br><b>* IMPORTANT !!! Save ComboFix.exe to your Desktop</b><br><br>Familiarize yourself with ComboFix before running it:<br>&raquo;<A HREF="http://www.bleepingcomputer.com/combofix/how-to-use-combofix" >www.bleepingcomputer.com/combofi&middot;&middot;&middot;combofix</A><br><br>- Disable your AntiVirus and any AntiSpyware programs you may be running (usually via a right click on the System Tray icon) to prevent them from interfering.<br><br>- Double click on ComboFix.exe & follow the prompts.<br><br>- As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal.  It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware. <br><br>- Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.<br><br>**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.<br><br> <IMG SRC="http://img.photobucket.com/albums/v706/ried7/RcAuto1.gif"> <br><br>Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:<br><br> <IMG SRC="http://img.photobucket.com/albums/v706/ried7/whatnext.png"> <br><br>Click on Yes, to continue scanning for malware. When finished, it will save a log. <br>Please include the contents of the log at <b>C:\ComboFix.txt</b> in your next reply.<br><br>Please post a new HijackThis log, the log from MBAM, the log from Avira, and in a second reply as it could get too long, the log from ComboFix (combofix.txt), and note any errors encountered.<br><br><small>--<br>Proud ASAP member since 2005</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22537454</guid>
<pubDate>Thu, 11 Jun 2009 21:52:55 EDT</pubDate>
</item>

<item>
<title>Re: [Trojan] Trojan Removal?</title>
<link>http://www.dslreports.com/forum/remark,22535864</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Malwarebytes' Anti-Malware 1.37<br>Database version: 2182<br>Windows 6.0.6001 Service Pack 1<br><br>11/06/2009 22:05:03<br>mbam-log-2009-06-11 (22-05-02).txt<br><br>Scan type: Full Scan (C:\|D:\|K:\|)<br>Objects scanned: 330014<br>Time elapsed: 59 minute(s), 57 second(s)<br><br>Memory Processes Infected: 0<br>Memory Modules Infected: 0<br>Registry Keys Infected: 1<br>Registry Values Infected: 0<br>Registry Data Items Infected: 9<br>Folders Infected: 0<br>Files Infected: 1<br><br>Memory Processes Infected:<br>(No malicious items detected)<br><br>Memory Modules Infected:<br>(No malicious items detected)<br><br>Registry Keys Infected:<br>HKEY_CURRENT_USER\SOFTWARE\ColdWare (Malware.Trace) -> Quarantined and deleted successfully.<br><br>Registry Values Infected:<br>(No malicious items detected)<br><br>Registry Data Items Infected:<br>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.24,85.255.112.118 -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{334d1067-913a-46b0-b67b-37fcbb2476c0}\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.24,85.255.112.118 -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{7f4d6420-a3c8-4aee-a256-013b68992699}\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.24,85.255.112.118 -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.24,85.255.112.118 -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{334d1067-913a-46b0-b67b-37fcbb2476c0}\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.24,85.255.112.118 -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{7f4d6420-a3c8-4aee-a256-013b68992699}\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.24,85.255.112.118 -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Tcpip\Parameters\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.24,85.255.112.118 -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Tcpip\Parameters\Interfaces\{334d1067-913a-46b0-b67b-37fcbb2476c0}\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.24,85.255.112.118 -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Tcpip\Parameters\Interfaces\{7f4d6420-a3c8-4aee-a256-013b68992699}\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.24,85.255.112.118 -> Quarantined and deleted successfully.<br><br>Folders Infected:<br>(No malicious items detected)<br><br>Files Infected:<br>c:\Windows\Tasks\{5B57CF47-0BFA-43c6-ACF9-3B3653DCADBA}.job (Trojan.FakeAlert) -> Quarantined and deleted successfully.<br><br><b>Logfile of HijackThis v1.99.1</b><br>Scan saved at 21:05:03, on 11/06/2009<br>Platform: Unknown Windows (WinNT 6.00.1905 SP1)<br>MSIE: Internet Explorer v7.00 (7.00.6001.18226)<br><br>Running processes:<br>C:\Windows\SYSTEM32\taskeng.exe<br>C:\Windows\system32\Dwm.exe<br>C:\Windows\Explorer.EXE<br>C:\Program Files\Windows Defender\MSASCui.exe<br>C:\Windows\RtHDVCpl.exe<br>C:\hp\support\hpsysdrv.exe<br>C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe<br>C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer.exe<br>C:\Program Files\HP\HP Software Update\hpwuSchd2.exe<br>C:\Program Files\Common Files\Real\Update_OB\realsched.exe<br>C:\Program Files\Java\jre6\bin\jusched.exe<br>C:\Windows\System32\rundll32.exe<br>C:\Program Files\iTunes\iTunesHelper.exe<br>C:\Program Files\Windows Sidebar\sidebar.exe<br>C:\Windows\ehome\ehtray.exe<br>C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE<br>C:\Program Files\Windows Media Player\wmpnscfg.exe<br>C:\Windows\system32\schtasks.exe<br>c:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE<br>C:\Windows\ehome\ehmsas.exe<br>C:\Program Files\Windows Sidebar\sidebar.exe<br>C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe<br>C:\hp\kbd\kbd.exe<br>C:\Program Files\HijackThis\peanutbutter.exe<br>C:\Program Files\Mozilla Firefox\firefox.exe<br><br>R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = &raquo;go.microsoft.com/fwlink/?LinkId=54896<br>R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;forum.videoediting.ru/<br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &raquo;ie.redirect.hp.com/svs/rdr?TYPE=&middot;&middot;&middot;=desktop<br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &raquo;go.microsoft.com/fwlink/?LinkId=54896<br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &raquo;go.microsoft.com/fwlink/?LinkId=54896<br>R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;ie.redirect.hp.com/svs/rdr?TYPE=&middot;&middot;&middot;=desktop<br>R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =<br>R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =<br>R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =<br>O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll<br>O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (file missing)<br>O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)<br>O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)<br>O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll<br>O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll<br>O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br>O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br>O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll<br>O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)<br>O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll<br>O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll<br>O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide<br>O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe<br>O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe<br>O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KbdStub.EXE<br>O4 - HKLM\..\Run: [OsdMaestro] "C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe"<br>O4 - HKLM\..\Run: [StartCCC] "c:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"<br>O4 - HKLM\..\Run: [HP Health Check Scheduler] [ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe<br>O4 - HKLM\..\Run: [SunJavaUpdateReg] "C:\Windows\system32\jureg.exe"<br>O4 - HKLM\..\Run: [NokiaMServer] C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer /watchfiles<br>O4 - HKLM\..\Run: [DigidesignMMERefresh] C:\Program Files\Digidesign\Drivers\MMERefresh.exe<br>O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe<br>O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot<br>O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"<br>O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"<br>O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup<br>O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit<br>O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime<br>O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"<br>O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe<br>O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun<br>O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe<br>O4 - HKCU\..\Run: [Steam] C:\Program Files\Valve\Steam\\Steam.exe -silent<br>O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe<br>O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE<br>O4 - Startup: OneNote Table Of Contents.onetoc2<br>O4 - Global Startup: Nokia Nseries PC Suite.lnk = C:\Program Files\Nokia\NNPCS\RunLauncher.exe<br>O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 5.0\resources\en-GB\local\search.html<br>O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000<br>O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll<br>O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll<br>O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll<br>O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll<br>O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll<br>O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL<br>O10 - Unknown file in Winsock LSP: c:\windows\system32\nlaapi.dll<br>O10 - Unknown file in Winsock LSP: c:\windows\system32\napinsp.dll<br>O11 - Options group: [INTERNATIONAL] International*<br>O13 - Gopher Prefix:<br>O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - &raquo;messenger.zone.msn.com/binary/ms&middot;&middot;&middot;6986.cab<br>O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - &raquo;gfx1.hotmail.com/mail/w3/resourc&middot;&middot;&middot;n-gb.cab<br>O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - &raquo;messenger.zone.msn.com/binary/Me&middot;&middot;&middot;6907.cab<br>O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - &raquo;fpdownload2.macromedia.com/get/s&middot;&middot;&middot;lash.cab<br>O17 - HKLM\System\CCS\Services\Tcpip\..\{334D1067-913A-46B0-B67B-37FCBB2476C0}: NameServer = 85.255.112.24,85.255.112.118<br>O17 - HKLM\System\CCS\Services\Tcpip\..\{7F4D6420-A3C8-4AEE-A256-013B68992699}: NameServer = 85.255.112.24,85.255.112.118<br>O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.112.24,85.255.112.118<br>O17 - HKLM\System\CS1\Services\Tcpip\..\{334D1067-913A-46B0-B67B-37FCBB2476C0}: NameServer = 85.255.112.24,85.255.112.118<br>O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.112.24,85.255.112.118<br>O17 - HKLM\System\CS2\Services\Tcpip\..\{334D1067-913A-46B0-B67B-37FCBB2476C0}: NameServer = 85.255.112.24,85.255.112.118<br>O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.112.24,85.255.112.118<br>O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (file missing)<br>O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL<br>O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll<br>O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL<br>O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL<br>O18 - Protocol: wlmailhtml - {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll<br>O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL<br>O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br>O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe<br>O23 - Service: Avid SDM Service (AvidSDMService) - Avid Technology, Inc. - C:\Windows\system32\AvidSDMService.exe<br>O23 - Service: Avid Startup (AvidStartup) - Unknown owner - C:\Windows\system32\AvidStartup.exe<br>O23 - Service: Digidesign MME Refresh Service (DigiRefresh) - Digidesign, A Division of Avid Technology, Inc. - C:\Program Files\Digidesign\Drivers\MMERefresh.exe<br>O23 - Service: @%SystemRoot%\ehome\ehstart.dll,-101 (ehstart) - Unknown owner - %windir%\system32\svchost.exe (file missing)<br>O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe<br>O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe<br>O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br>O23 - Service: Lavasoft Ad-Aware Service - Unknown owner - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (file missing)<br>O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe<br>O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\Windows\system32\GameMon.des.exe (file missing)<br>O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe<br>O23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - %windir%\system32\svchost.exe (file missing)<br>O23 - Service: @%SystemRoot%\system32\seclogon.dll,-7001 (seclogon) - Unknown owner - %windir%\system32\svchost.exe (file missing)<br>O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Nokia\PC Connectivity Solution\ServiceLayer.exe<br>O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe<br>O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - %ProgramFiles%\Windows Media Player\wmpnetwk.exe (file missing)<br><br>Do we think thats that? :)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22535864</guid>
<pubDate>Thu, 11 Jun 2009 17:05:52 EDT</pubDate>
</item>

<item>
<title>Re: [Trojan] Trojan Removal?</title>
<link>http://www.dslreports.com/forum/remark,22532459</link>
<description><![CDATA[<A HREF="/useremail/u/377471"><b>TheJoker</b></A> : Hi JonS1983<br><br>Please read &raquo;<A HREF="/faq/seclean">Security Cleanup FAQ</A> &raquo;<A HREF="/faq/13616">Mandatory Steps Before  Requesting Assistance</A> and follow the instructions for running Malwarebytes' Anti-Malware. If it won't run after installation, go to it's program folder at C:\Program Files\Malwarebytes' Anti-Malware and rename mbam.exe to a randon name (such as myprogram.exe), and double-click on the file to run it. If it won't install, do the same thing to the installer file, renaming it to a random name.<br><br>After that, if HijackThis still doesn't work, rename it to a random name and run it, and then post the logs for both HijackThis and MBAM.<br><small>--<br>Proud ASAP member since 2005</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22532459</guid>
<pubDate>Thu, 11 Jun 2009 06:11:53 EDT</pubDate>
</item>

<item>
<title>[Trojan] Trojan Removal?</title>
<link>http://www.dslreports.com/forum/remark,22530270</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Hey guys, <br>Please see this <br><br>[att=1]<br><br>So I have a Win32 Trojan Downloader, and would very much like to know how to get rid of it. Windows defender finds it, but then it seems to come back each time, almost exactly every hour on the hour it returns (whether this is when Windows Defender is searching or just when it is re-created I don't know).<br>Other programs don't seem to find the Trojan, again I'm not sure whether this is because of conflicts with Windows Defender?<br><br>I tried Hijack this, but every time I launch it, I get the error message "...has stopped responding".<br>Whilst using firefox and google, when clicking on a search entry it redirects me to a completely different page altogether.<br><br>Thanks to anyone that has read this, special thanks to anyone that can help! :)<div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/22530270?c=1438128&ret=L2ZvcnVtL3IyMjUzMDI3MC54bWw%3D"><IMG class="apic" BORDER=0 TITLE="101602 bytes" WIDTH=600 HEIGHT=375 SRC="/r0/download/1438128.thumb600~6edcfd6c78d8e1281d6e125113037b32/trojan.jpg/thumb.jpg" ALT="Click for full size"></A><br>click to enlarge</TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22530270</guid>
<pubDate>Wed, 10 Jun 2009 19:11:05 EDT</pubDate>
</item>

</channel>
</rss>
