<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>[Vundo] cannot get rid of virtumonde/vundo trojan in Security Cleanup</title>
<link>http://www.dslreports.com/forum/r22545478</link>
<description></description>
<language>en</language>
<pubDate>Sun, 29 Nov 2009 10:21:53 EDT</pubDate>
<lastBuildDate>Sun, 29 Nov 2009 10:21:53 EDT</lastBuildDate>

<item>
<title>Re: [Vundo] cannot get rid of virtumonde/vundo trojan</title>
<link>http://www.dslreports.com/forum/remark,22582729</link>
<description><![CDATA[<A HREF="/useremail/u/377471"><b>TheJoker</b></A> : Thanks for the info and best of luck keeping the system clean. :)<br><small>--<br>Proud ASAP member since 2005</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22582729</guid>
<pubDate>Sat, 20 Jun 2009 11:46:24 EDT</pubDate>
</item>

<item>
<title>Re: [Vundo] cannot get rid of virtumonde/vundo trojan</title>
<link>http://www.dslreports.com/forum/remark,22564927</link>
<description><![CDATA[<A HREF="/useremail/u/1650439"><b>azraders</b></A> : yes, I do not seem to have the  trojans I first reported.  thank you for all you've done.  <br><br>I do have spywareblaster.<br><br>The math program I use on the internet is Aleks.com.  It is the program that the community college requires me to use for school.<br><br>azraders]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22564927</guid>
<pubDate>Wed, 17 Jun 2009 09:45:45 EDT</pubDate>
</item>

<item>
<title>Re: [Vundo] cannot get rid of virtumonde/vundo trojan</title>
<link>http://www.dslreports.com/forum/remark,22562812</link>
<description><![CDATA[<A HREF="/useremail/u/377471"><b>TheJoker</b></A> : You can leave them, as their being there won't cause a problem. <br>What was the math program that needed them?<br><br>There are several free utilities you can use to help keep malware off your system: <br><br>A HOSTS file will prevent Internet Explorer from communicating with sites known to be associated with adware or spyware. A good regularly updated HOST file is MVPS HOSTS File, available at &raquo;<A HREF="http://www.mvps.org/winhelp2002/hosts.htm" >www.mvps.org/winhelp2002/hosts.htm</A>. <br><br>A free non-resident utility to prevent the installation of ActiveX-based malware is JavaCool's SpywareBlaster. For real-time protection, there is SpywareGuard. Both are available at &raquo;<A HREF="http://www.javacoolsoftware.com/products.html" >www.javacoolsoftware.com/products.html</A>. <br><br>I recommend reading Tony Klein's article <i>So How did I get Infected in the First Place?</i> at &raquo;<A HREF="http://www.spywareinfoforum.com/index.php?showtopic=60955" >www.spywareinfoforum.com/index.p&middot;&middot;&middot;ic=60955</A><br><br>Does your problem appear resolved?<br><small>--<br>Proud ASAP member since 2005</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22562812</guid>
<pubDate>Tue, 16 Jun 2009 20:52:07 EDT</pubDate>
</item>

<item>
<title>Re: [Vundo] cannot get rid of virtumonde/vundo trojan</title>
<link>http://www.dslreports.com/forum/remark,22562433</link>
<description><![CDATA[<A HREF="/useremail/u/1650439"><b>azraders</b></A> : O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} -<br>O16 - DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} (Java Plug-in 1.4.2_03) -<br>O16 - DPF: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} (Java Plug-in 1.6.0_12) -<br><br>I originally deleted these but I had to re install java because after the last hijackthis and reboot, my math program wouldn't work.  It told me I needed the plug in for Java.  So I downloaded it again.  I am not sure but think the bottom two are related to running the program.   The top one may be related because I deleted it initially and I saw it back in the hijackthis log.  <br><br>I'm not sure what to do now.  If you are positive  they have nothing to do with the java I need for my math program, I'll delete them again.  <br><br>Let me know.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22562433</guid>
<pubDate>Tue, 16 Jun 2009 19:37:19 EDT</pubDate>
</item>

<item>
<title>Re: [Vundo] cannot get rid of virtumonde/vundo trojan</title>
<link>http://www.dslreports.com/forum/remark,22562285</link>
<description><![CDATA[<A HREF="/useremail/u/377471"><b>TheJoker</b></A> : You have more empty entries to remove.<br><br>Please <b>disable TeaTimer</b> by doing the following:<br>1) Run Spybot-S&D<br>2) Go to the Mode menu, and make sure "Advanced Mode" is selected<br>3) On the left hand side, choose Tools -> Resident<br>4) Uncheck "Resident TeaTimer" and OK any prompts<br><br>When everything is done and your log is clean again, you can enable it again.<br>If teatimer gives you a warning afterwords that some changes were made, allow this instead of blocking it.<br>Please don't forget this step to disable teatimer.<br><br>Please <b>disable your Windows Defender Real-time Protection</b> as it may interfere with the fixes that we need to make.<br><br>Open Windows Defender.<br>Click on Tools, General Settings.<br>Scroll down and uncheck Turn on real-time protection (recommended).<br>After you uncheck this, click on the Save button and close Windows Defender.<br>After all of the fixes are complete it is very important that you enable Real-time Protection again.<br><br>Now you need to run HijackThis and click "<b>Do a system scan only</b>." Place a check next to the following entries (if they are still there):<br><br><b>O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} -<br>O16 - DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} (Java Plug-in 1.4.2_03) -<br>O16 - DPF: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} (Java Plug-in 1.6.0_12) -</b><br><br>Now close all browser and other windows except for HijackThis, and click "<b>Fix Checked</b>" to have HijackThis fix the entries you checked.<br><br> <blockquote><small>quote:</small><hr>Some times I can browse from page to page in a few seconds and that has improved. what I notice is it takes my browsers about 20-30 seconds to load.<hr></blockquote><br><br>Did you follow the recommendation to use StartupLite to disable the entries that you had previously disabled with MSCONFIG? That may help once you do that.<br><br>You are also still running Internet Explorer 6. I would update to at least version 7, and then any adidtional security updates found at Windows Update after you do that. If you find IE7 slower, you can Google "speedup IE7" and you will find sites like &raquo;<A HREF="http://reliancepc.com/menu/tips/IE7tuning/index.php" >reliancepc.com/menu/tips/IE7tuning/index.php</A> and &raquo;<A HREF="http://www.consumingexperience.com/2007/05/how-to-speed-up-internet-explorer-7.html" >www.consumingexperience.com/2007&middot;&middot;&middot;r-7.html</A> that help with attempting to speed up IE7. <br><br>Please post a new HijackThis log and note any errors encountered.<br><small>--<br>Proud ASAP member since 2005</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22562285</guid>
<pubDate>Tue, 16 Jun 2009 19:11:51 EDT</pubDate>
</item>

<item>
<title>Re: [Vundo] cannot get rid of virtumonde/vundo trojan</title>
<link>http://www.dslreports.com/forum/remark,22559146</link>
<description><![CDATA[<A HREF="/useremail/u/1650439"><b>azraders</b></A> : Hi there.  I did the clean up.  It is a toss up.  Some times I can browse from page to page in a few seconds and that has improved.  what I notice is it takes my browsers about 20-30 seconds to load.  Maybe this will work itself out.<br><br>thanks for all the help.  It was much appreciated!!<br><br>Logfile of Trend Micro HijackThis v2.0.2<br>Scan saved at 7:17:20 AM, on 6/16/2009<br>Platform: Windows XP SP3 (WinNT 5.01.2600)<br>MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)<br>Boot mode: Normal<br><br>Running processes:<br>C:\WINDOWS\System32\smss.exe<br>C:\WINDOWS\system32\winlogon.exe<br>C:\WINDOWS\system32\services.exe<br>C:\WINDOWS\system32\lsass.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\WINDOWS\Explorer.EXE<br>C:\WINDOWS\system32\spoolsv.exe<br>C:\Program Files\Google\Update\GoogleUpdate.exe<br>C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br>C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe<br>C:\Program Files\Bonjour\mDNSResponder.exe<br>C:\Program Files\Java\jre6\bin\jqs.exe<br>C:\Program Files\Common Files\Motive\McciCMService.exe<br>C:\PROGRA~1\AVG\AVG8\avgtray.exe<br>C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe<br>C:\Program Files\Analog Devices\Core\smax4pnp.exe<br>C:\Program Files\Real\RealPlayer\RealPlay.exe<br>C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe<br>C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe<br>C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\WINDOWS\system32\hkcmd.exe<br>C:\Program Files\Dell\Media Experience\DMXLauncher.exe<br>C:\WINDOWS\system32\dla\tfswctrl.exe<br>C:\dell\bldbubg.exe<br>C:\Program Files\Java\jre6\bin\jusched.exe<br>C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\Program Files\Messenger\msmsgs.exe<br>C:\Program Files\Dell Support\DSAgnt.exe<br>C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe<br>C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe<br>C:\PROGRA~1\AVG\AVG8\avgemc.exe<br>C:\Program Files\OpenOffice.org 3\program\soffice.exe<br>C:\PROGRA~1\AVG\AVG8\avgrsx.exe<br>C:\PROGRA~1\AVG\AVG8\avgnsx.exe<br>C:\Program Files\OpenOffice.org 3\program\soffice.bin<br>C:\Program Files\AVG\AVG8\avgcsrvx.exe<br>C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe<br>C:\WINDOWS\system32\wuauclt.exe<br>C:\Documents and Settings\Drader\Desktop\HiJackThis.exe<br><br>R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://www.lds.org/" >www.lds.org/</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=69157" >go.microsoft.com/fwlink/?LinkId=69157</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://www.dell4me.com/myway" >www.dell4me.com/myway</A><br>R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local<br>R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll<br>O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)<br>O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll<br>O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll<br>O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br>O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll<br>O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll<br>O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll<br>O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br>O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br>O2 - BHO: (no name) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - (no file)<br>O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll<br>O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe<br>O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide<br>O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r<br>O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe<br>O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER<br>O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime<br>O4 - HKLM\..\Run: [QBReminderFlash] "C:\Program Files\Intuit\QuickBooks 2005\Atom\QBReminder.exe"<br>O4 - HKLM\..\Run: [MMTray] C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe<br>O4 - HKLM\..\Run: [mmtask] C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe<br>O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k<br>O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe<br>O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe<br>O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe<br>O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe<br>O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe<br>O4 - HKLM\..\Run: [BuildBU] c:\dell\bldbubg.exe<br>O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"<br>O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe<br>O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background<br>O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet<br>O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup<br>O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe<br>O4 - Startup: OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe<br>O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe<br>O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe<br>O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe<br>O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll<br>O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br>O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br>O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br>O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br>O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O15 - Trusted Zone: &raquo;<A HREF="http://*.mcafee.com" >*.mcafee.com</A><br>O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - &raquo;<A HREF="http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab" >upload.facebook.com/controls/200&middot;&middot;&middot;der5.cab</A><br>O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - &raquo;<A HREF="http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab" >housecall65.trendmicro.com/house&middot;&middot;&middot;Impl.cab</A><br>O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - <br>O16 - DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} (Java Plug-in 1.4.2_03) - <br>O16 - DPF: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} (Java Plug-in 1.6.0_12) - <br>O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - &raquo;<A HREF="http://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab" >wwwimages.adobe.com/www.adobe.co&middot;&middot;&middot;s/gp.cab</A><br>O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll<br>O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll<br>O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br>O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe<br>O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe<br>O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br>O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe<br>O23 - Service: Google Update Service (gupdate1c99dc76a3bc708) (gupdate1c99dc76a3bc708) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe<br>O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br>O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br>O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br>O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Common Files\Motive\McciCMService.exe<br><br>--<br>End of file - 9405 bytes]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22559146</guid>
<pubDate>Tue, 16 Jun 2009 10:26:25 EDT</pubDate>
</item>

<item>
<title>Re: [Vundo] cannot get rid of virtumonde/vundo trojan</title>
<link>http://www.dslreports.com/forum/remark,22555930</link>
<description><![CDATA[<A HREF="/useremail/u/377471"><b>TheJoker</b></A> : You have quite a few items that you had previously disabled with MSCONFIG. You can disable them again, but they needed to be viewable to be able to delete the bad items.<br><br>There are other ways to get rid of several of them, and one that still isn't gone.<br><br>Please <b>disable TeaTimer</b> by doing the following:<br>1) Run Spybot-S&D<br>2) Go to the Mode menu, and make sure "Advanced Mode" is selected<br>3) On the left hand side, choose Tools -> Resident<br>4) Uncheck "Resident TeaTimer" and OK any prompts<br><br>When everything is done and your log is clean again, you can enable it again.<br>If teatimer gives you a warning afterwords that some changes were made, allow this instead of blocking it.<br><br>Please <b>disable your Windows Defender Real-time Protection</b> as it may interfere with the fixes that we need to make.<br><br>Open Windows Defender.<br>Click on Tools, General Settings.<br>Scroll down and uncheck Turn on real-time protection (recommended).<br>After you uncheck this, click on the Save button and close Windows Defender.<br>After all of the fixes are complete it is very important that you enable Real-time Protection again.<br><br>Now you need to run HijackThis and click "<b>Do a system scan only</b>." Place a check next to the following entries:<br><br><b>O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} -</b><br><br>You can <b>optionally</b> check the following entry. This entry is used in connection with memory dumps - you can disable these by - right clicking on My Computer, selecting Properties and then the Advanced tab. Click on the Settings button in 'Startup and Recovery'. In the bottom pane - under 'Write debugging information' - click on the down arrow and then select 'None' - OK your way out:<br><b>O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k</b><br><br>Now close all browser and other windows except for HijackThis, and click "<b>Fix Checked</b>" to have HijackThis fix the entries you checked.<br><br>That takes care of that one.<br><br>You were disabling Ad-Watch with MSCONFIG. Instead, just turn it off in the program, and it won't be running as an item that you may want to disable. However, you already have Spybot Search & Destroy, and Windows Defender. I would simply uninstall Ad-Aware as redundant<br><br>You are running both Google Toolbar, and Yahoo! Toolbar. I would uninstall one of them. Do you really use either? Uninstall the one you use the least (uninstalling the Yahoo! software will probably give the biggest effect).<br><br>For the rest, instead of using MSCONFIG, You might want to take a look at this page created by miekiemoes, one of the Global Moderators here, on slow systems, and some things you can try to do to try to improve it:<br>&raquo;<A HREF="http://users.telenet.be/bluepatchy/miekiemoes/slowcomputer.html" >users.telenet.be/bluepatchy/miek&middot;&middot;&middot;ter.html</A><br>I would particularly look at using RubberDucky's <A HREF="http://www.malwarebytes.org/startuplite.php">StartUpLite</a> (from the same people that brought you MBAM). This will display all unnecessary startup entries - so actually, everything it displays there is not necessary to start up with Windows.<br><br>Create a <b>Restore Point</b><br>&#8226;Go to Start > Programs > Accessories > System Tools > <b>System Restore</b><br>&#8226;Select <b>Cr<u>e</u>ate a Restore Point</b> and then <b>Next</b>. <br>&#8226;In the box for "Restore point description", enter a descriptive name and press <b>Create</b><br>&#8226;When the "Restore Point Created" window appears, click <b>Close</b><br><br>Run <b>Disk Cleanup</b><br>&#8226;Go to Start > Run and type the below line:<br><b>cleanmgr</b><br>&#8226;Click <b>OK</b><br>&#8226;If you have more than one drive, select the drive Windows is installed on<br>&#8226;Click <b>OK</b><br>&#8226;When Disk Cleanup opens, select the <b>More Options</b> tab<br>&#8226;In the System Restore section (bottom of window), click <b>Cleanup</b><br>&#8226;In the confirmation window that opens, click <b>Yes</b>[<br><br>Now click on the <b>Disk Cleanup</b> tab and select the following items:<br>&#8226;Downloaded Program Files<br>&#8226;Temporary Internet Files<br>&#8226;Recycle Bin<br>&#8226;Temporary Files<br>Click <b>OK</b><br>in the confirmation window, select <b>Yes</b> (Disk Cleanup will close).<br><br>Please post a new HijackThis log. <br>How is the system running now?<br><small>--<br>Proud ASAP member since 2005</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22555930</guid>
<pubDate>Mon, 15 Jun 2009 18:45:23 EDT</pubDate>
</item>

<item>
<title>Re: [Vundo] cannot get rid of virtumonde/vundo trojan</title>
<link>http://www.dslreports.com/forum/remark,22554470</link>
<description><![CDATA[<A HREF="/useremail/u/1650439"><b>azraders</b></A> : Thanks for the help!    <br><br>Logfile of Trend Micro HijackThis v2.0.2<br>Scan saved at 11:06:02 AM, on 6/15/2009<br>Platform: Windows XP SP3 (WinNT 5.01.2600)<br>MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)<br>Boot mode: Normal<br><br>Running processes:<br>C:\WINDOWS\System32\smss.exe<br>C:\WINDOWS\system32\winlogon.exe<br>C:\WINDOWS\system32\services.exe<br>C:\WINDOWS\system32\lsass.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\WINDOWS\system32\spoolsv.exe<br>C:\WINDOWS\Explorer.EXE<br>C:\Program Files\Google\Update\GoogleUpdate.exe<br>C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br>C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe<br>C:\Program Files\Bonjour\mDNSResponder.exe<br>C:\Program Files\Java\jre6\bin\jqs.exe<br>C:\Program Files\Common Files\Motive\McciCMService.exe<br>C:\PROGRA~1\AVG\AVG8\avgtray.exe<br>C:\Program Files\Java\jre6\bin\jusched.exe<br>C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\Program Files\Analog Devices\Core\smax4pnp.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\Program Files\Real\RealPlayer\RealPlay.exe<br>C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe<br>C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe<br>C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe<br>C:\PROGRA~1\AVG\AVG8\avgemc.exe<br>C:\WINDOWS\system32\hkcmd.exe<br>C:\Program Files\Dell\Media Experience\DMXLauncher.exe<br>C:\PROGRA~1\AVG\AVG8\avgrsx.exe<br>C:\PROGRA~1\AVG\AVG8\avgnsx.exe<br>C:\WINDOWS\system32\dla\tfswctrl.exe<br>C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe<br>C:\Program Files\Messenger\msmsgs.exe<br>C:\Program Files\Dell Support\DSAgnt.exe<br>C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe<br>C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe<br>C:\Program Files\OpenOffice.org 3\program\soffice.exe<br>C:\Program Files\OpenOffice.org 3\program\soffice.bin<br>C:\Program Files\AVG\AVG8\avgcsrvx.exe<br>C:\WINDOWS\system32\wuauclt.exe<br>C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe<br>C:\Documents and Settings\Drader\Desktop\HiJackThis.exe<br><br>R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://www.lds.org/" >www.lds.org/</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=69157" >go.microsoft.com/fwlink/?LinkId=69157</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://www.dell4me.com/myway" >www.dell4me.com/myway</A><br>R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local<br>R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll<br>R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll<br>O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll<br>O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll<br>O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll<br>O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br>O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll<br>O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll<br>O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll<br>O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br>O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br>O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll<br>O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll<br>O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll<br>O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe<br>O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"<br>O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide<br>O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r<br>O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe<br>O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER<br>O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime<br>O4 - HKLM\..\Run: [QBReminderFlash] "C:\Program Files\Intuit\QuickBooks 2005\Atom\QBReminder.exe"<br>O4 - HKLM\..\Run: [MMTray] C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe<br>O4 - HKLM\..\Run: [mmtask] C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe<br>O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k<br>O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe<br>O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe<br>O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe<br>O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe<br>O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe<br>O4 - HKLM\..\Run: [BuildBU] c:\dell\bldbubg.exe<br>O4 - HKLM\..\Run: [Ad-Watch] "C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe"<br>O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe<br>O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background<br>O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet<br>O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup<br>O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe<br>O4 - Startup: OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe<br>O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe<br>O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe<br>O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe<br>O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll<br>O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br>O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br>O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br>O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br>O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O15 - Trusted Zone: &raquo;<A HREF="http://*.mcafee.com" >*.mcafee.com</A><br>O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - &raquo;<A HREF="http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab" >upload.facebook.com/controls/200&middot;&middot;&middot;der5.cab</A><br>O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - &raquo;<A HREF="http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab" >housecall65.trendmicro.com/house&middot;&middot;&middot;Impl.cab</A><br>O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - <br>O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - &raquo;<A HREF="http://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab" >wwwimages.adobe.com/www.adobe.co&middot;&middot;&middot;s/gp.cab</A><br>O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll<br>O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll<br>O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br>O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe<br>O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe<br>O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br>O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe<br>O23 - Service: Google Update Service (gupdate1c99dc76a3bc708) (gupdate1c99dc76a3bc708) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe<br>O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br>O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br>O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br>O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe<br>O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Common Files\Motive\McciCMService.exe<br><br>--<br>End of file - 9799 bytes<br><br>I'm glad to see the files finally deleted alltogether.  <br><br>One last thing if I may?  Since I've done these last few steps, the computer is running slower.  Is that because we put the msconfig on normal startup?  I think everything is running now. OR do I have other problems that need addressing regarding cleaning up of files?  <br><br>If it the latter, please direct me to a forum where I can learn how to better optimize the drive and speed.  <br>thanks so much for your time.  I  really appreciate the help you have rendered.  My computer thanks you too! :)<br>After a week and a half dealing with this junk... I'm ready for a vacation!  :)<br><br>azraders]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22554470</guid>
<pubDate>Mon, 15 Jun 2009 14:14:03 EDT</pubDate>
</item>

<item>
<title>Re: [Vundo] cannot get rid of virtumonde/vundo trojan</title>
<link>http://www.dslreports.com/forum/remark,22554243</link>
<description><![CDATA[<A HREF="/useremail/u/377471"><b>TheJoker</b></A> : I notice that you have Spybot's TeaTimer running.  While this is normally a wonderful tool to protect against hijackers, it can also interfere with HijackThis fixes.  So please <b>disable TeaTimer</b> by doing the following:<br>1) Run Spybot-S&D<br>2) Go to the Mode menu, and make sure "Advanced Mode" is selected<br>3) On the left hand side, choose Tools -> Resident<br>4) Uncheck "Resident TeaTimer" and OK any prompts<br><br>When everything is done and your log is clean again, you can enable it again.<br>If teatimer gives you a warning afterwords that some changes were made, allow this instead of blocking it.<br><br>Please <b>disable your Windows Defender Real-time Protection</b> as it may interfere with the fixes that we need to make.<br><br>Open Windows Defender.<br>Click on Tools, General Settings.<br>Scroll down and uncheck Turn on real-time protection (recommended).<br>After you uncheck this, click on the Save button and close Windows Defender.<br>After all of the fixes are complete it is very important that you enable Real-time Protection again.<br><br>Now you need to run HijackThis and click "<b>Do a system scan only</b>." Place a check next to the following entries (if they are still there):<br><br><b>O4 - HKLM\..\Run: [goyapipemu] Rundll32.exe "C:\WINDOWS\system32\viyorawi.dll",s<br>O4 - HKLM\..\Run: [CPM57421bb4] Rundll32.exe "c:\windows\system32\mimegepa.dll",a<br>O4 - HKLM\..\Run: [54712828] rundll32.exe "C:\WINDOWS\system32\kuwokilo.dll",b<br>O16 - DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} (Java Plug-in 1.4.2_03) -<br>O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} (Java Plug-in 1.6.0_07) -<br>O16 - DPF: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} (Java Plug-in 1.6.0_12) -</b><br><br>Now close all browser and other windows except for HijackThis, and click "<b>Fix Checked</b>" to have HijackThis fix the entries you checked.<br><br>Reconfigure Windows XP to show hidden files:<br>Click Start. Open My Computer. <br>Select the Tools menu and click Folder Options. Select the View Tab. <br>Under the Hidden files and folders heading select "Show hidden files and folders". <br>Uncheck the "Hide protected operating system files (recommended)" option. <br>Uncheck the "Hide file extensions for known file types" option.<br>Click Yes to confirm. Click OK.<br><br>Using Windows Explorer, locate the following files, and delete them if still there (they are probably gone):<br>C:\WINDOWS\system32\viyorawi.dll<br>c:\windows\system32\mimegepa.dll<br>C:\WINDOWS\system32\kuwokilo.dll<br><br>Now you need to hide the files you un-hid earlier:<br>Click Start. Open My Computer.<br>Select the Tools menu and click Folder Options. Select the View Tab. <br>Under the Hidden files and folders heading unselect "Show hidden files and folders". <br>Check the "Hide protected operating system files (recommended)" option. <br>Click Yes to confirm. Click OK.<br><br>You appear to possibly have disabled your installation of McAfee rather than uninstalled it. It needs to be uninstalled as you have AVG also installed.<br><br>If you have uninstalled it, you should run this uninstaller to remove leftover entries.<br>Download and run the <b>McAfee Consumer Products Removal tool</b> (MCPR.exe).<br>Running the McAfee Consumer Product Removal tool (MCPR.exe) removes all 2005, 2006, and 2007 and 2008 versions of McAfee consumer products.<br>- McAfee Security Center<br>- McAfee VirusScan<br>- McAfee Personal Firewall Plus<br>- McAfee Privacy Service<br>- McAfee SpamKiller<br>- McAfee Wireless Network Security<br>- McAfee SiteAdvisor<br>- McAfee Data Backup <br>- McAfee Network Manager <br>- McAfee Easy Network <br>- McAfee AntiSpyware[/list]<br><br>Download the removal tool from &raquo;<A HREF="http://download.mcafee.com/products/licensed/cust_support_patches/MCPR.exe" >download.mcafee.com/products/lic&middot;&middot;&middot;MCPR.exe</A><br>- Click Save and save the file to any folder on the computer. <br>- Navigate to the folder where the file is saved. <br>- Double-click <b>MCPR.exe</b>. <br><br><b>Note</b>: Windows Vista users must right-click <b>MCPR.exe</b> and select <b>Run as Administrator</b>. <br><br>- Click <b>Run</b>. A Command Line window will be displayed, and then close automatically. Wait for a second Command Line window to be displayed. <br><b>Note</b>: Do not double-click MCPR.exe again, you may have to wait up to 1 minute for the next window to appear.<br>After the second window appears, the program will begin the cleanup. <br>- Observe the installation, which could take several minutes. The following message will be displayed in the Command Line window: <br><b>The machine must reboot to complete the un-installation. Reboot now? [y.n]</b><br>  <br>- Press <b>Y</b> on the keyboard. <br>- Wait for the computer to restart.<br>All McAfee products are now removed from your computer.<br>These McAfee removal instructions can be found at &raquo;<A HREF="http://service.mcafee.com/FAQDocument.aspx?lc=1033&id=TS100507" >service.mcafee.com/FAQDocument.a&middot;&middot;&middot;TS100507</A><br><br>Please post a new HijackThis log and note any errors encountered.<br><small>--<br>Proud ASAP member since 2005</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22554243</guid>
<pubDate>Mon, 15 Jun 2009 13:29:41 EDT</pubDate>
</item>

<item>
<title>Re: [Vundo] cannot get rid of virtumonde/vundo trojan</title>
<link>http://www.dslreports.com/forum/remark,22553331</link>
<description><![CDATA[<A HREF="/useremail/u/1650439"><b>azraders</b></A> : Here is the last hijackthis after running a msconfig in normal start up.<br><br>Logfile of Trend Micro HijackThis v2.0.2<br>Scan saved at 7:45:16 AM, on 6/15/2009<br>Platform: Windows XP SP3 (WinNT 5.01.2600)<br>MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)<br>Boot mode: Normal<br><br>Running processes:<br>C:\WINDOWS\System32\smss.exe<br>C:\WINDOWS\system32\winlogon.exe<br>C:\WINDOWS\system32\services.exe<br>C:\WINDOWS\system32\lsass.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\Program Files\Windows Defender\MsMpEng.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\WINDOWS\Explorer.EXE<br>C:\WINDOWS\system32\spoolsv.exe<br>C:\PROGRA~1\AVG\AVG8\avgtray.exe<br>C:\Program Files\Google\Update\GoogleUpdate.exe<br>C:\Program Files\Java\jre6\bin\jusched.exe<br>C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe<br>C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br>C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe<br>C:\Program Files\Bonjour\mDNSResponder.exe<br>C:\Program Files\Java\jre6\bin\jqs.exe<br>C:\Program Files\Common Files\Motive\McciCMService.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\PROGRA~1\AVG\AVG8\avgrsx.exe<br>C:\PROGRA~1\AVG\AVG8\avgemc.exe<br>C:\PROGRA~1\AVG\AVG8\avgnsx.exe<br>C:\Program Files\AVG\AVG8\avgcsrvx.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe<br>C:\Program Files\Mozilla Firefox\firefox.exe<br>C:\WINDOWS\system32\wuauclt.exe<br>C:\Documents and Settings\Drader\Desktop\HiJackThis.exe<br><br>R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://www.lds.org/" >www.lds.org/</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=69157" >go.microsoft.com/fwlink/?LinkId=69157</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://www.dell4me.com/myway" >www.dell4me.com/myway</A><br>R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local<br>R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll<br>R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll<br>O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll<br>O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll<br>O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll<br>O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br>O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll<br>O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll<br>O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll<br>O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br>O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br>O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll<br>O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll<br>O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll<br>O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe<br>O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"<br>O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide<br>O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask<br>O4 - HKLM\..\Run: [VirusScan Online] c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe<br>O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r<br>O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe<br>O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER<br>O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime<br>O4 - HKLM\..\Run: [QBReminderFlash] "C:\Program Files\Intuit\QuickBooks 2005\Atom\QBReminder.exe"<br>O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe<br>O4 - HKLM\..\Run: [MMTray] C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe<br>O4 - HKLM\..\Run: [mmtask] C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe<br>O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe<br>O4 - HKLM\..\Run: [McRegWiz] C:\PROGRA~1\mcafee.com\agent\mcregwiz.exe /autorun<br>O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe<br>O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k<br>O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"<br>O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe<br>O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe<br>O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe<br>O4 - HKLM\..\Run: [goyapipemu] Rundll32.exe "C:\WINDOWS\system32\viyorawi.dll",s<br>O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe<br>O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe<br>O4 - HKLM\..\Run: [CPM57421bb4] Rundll32.exe "c:\windows\system32\mimegepa.dll",a<br>O4 - HKLM\..\Run: [BuildBU] c:\dell\bldbubg.exe<br>O4 - HKLM\..\Run: [Ad-Watch] "C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe"<br>O4 - HKLM\..\Run: [54712828] rundll32.exe "C:\WINDOWS\system32\kuwokilo.dll",b<br>O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"<br>O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe<br>O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background<br>O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet<br>O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup<br>O4 - Startup: OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe<br>O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe<br>O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe<br>O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe<br>O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll<br>O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br>O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br>O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br>O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br>O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O15 - Trusted Zone: &raquo;<A HREF="http://*.mcafee.com" >*.mcafee.com</A><br>O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - &raquo;<A HREF="http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab" >upload.facebook.com/controls/200&middot;&middot;&middot;der5.cab</A><br>O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - &raquo;<A HREF="http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab" >housecall65.trendmicro.com/house&middot;&middot;&middot;Impl.cab</A><br>O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - &raquo;<A HREF="http://download.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,90/mcinsctl.cab" >download.mcafee.com/molbin/share&middot;&middot;&middot;sctl.cab</A><br>O16 - DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} (Java Plug-in 1.4.2_03) - <br>O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} (Java Plug-in 1.6.0_07) - <br>O16 - DPF: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} (Java Plug-in 1.6.0_12) - <br>O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - &raquo;<A HREF="http://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab" >wwwimages.adobe.com/www.adobe.co&middot;&middot;&middot;s/gp.cab</A><br>O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll<br>O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll<br>O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br>O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe<br>O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe<br>O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br>O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe<br>O23 - Service: Google Update Service (gupdate1c99dc76a3bc708) (gupdate1c99dc76a3bc708) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe<br>O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br>O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br>O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br>O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe<br>O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Common Files\Motive\McciCMService.exe<br><br>--<br>End of file - 10255 bytes]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22553331</guid>
<pubDate>Mon, 15 Jun 2009 10:47:30 EDT</pubDate>
</item>

<item>
<title>Re: [Vundo] cannot get rid of virtumonde/vundo trojan</title>
<link>http://www.dslreports.com/forum/remark,22552532</link>
<description><![CDATA[<A HREF="/useremail/u/377471"><b>TheJoker</b></A> : <div class="bquote"><small>said by  azraders <A HREF="/useremail/u/1650439"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>I was referring to the System configuration utility in the startup menu.  Maybe it won't affect anything though.<br></div>Oh, you mean with the MSCONFIG utility. Go to Start > Run, and in the run line type <b>MSCONFIG</b>, and when it starts, click the General tab, click Normal Startup, and click OK. When prompted, do not reboot.<br><br>Please post a new HijackThis log.<br><div class="bquote">How did you get to be someone that helps people with stuff like this?<br></div>I learned at Spywareinfoforum. You can sign up for Boot Camp there through the link I left above.<br><small>--<br>Proud ASAP member since 2005</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22552532</guid>
<pubDate>Mon, 15 Jun 2009 05:36:04 EDT</pubDate>
</item>

<item>
<title>Re: [Vundo] cannot get rid of virtumonde/vundo trojan</title>
<link>http://www.dslreports.com/forum/remark,22551386</link>
<description><![CDATA[<A HREF="/useremail/u/1650439"><b>azraders</b></A> : Last Hijackthislog:<br><br>Logfile of Trend Micro HijackThis v2.0.2<br>Scan saved at 6:48:50 PM, on 6/14/2009<br>Platform: Windows XP SP3 (WinNT 5.01.2600)<br>MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)<br>Boot mode: Normal<br><br>Running processes:<br>C:\WINDOWS\System32\smss.exe<br>C:\WINDOWS\system32\winlogon.exe<br>C:\WINDOWS\system32\services.exe<br>C:\WINDOWS\system32\lsass.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\Program Files\Windows Defender\MsMpEng.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\WINDOWS\Explorer.EXE<br>C:\WINDOWS\system32\spoolsv.exe<br>C:\PROGRA~1\AVG\AVG8\avgtray.exe<br>C:\Program Files\Google\Update\GoogleUpdate.exe<br>C:\Program Files\Java\jre6\bin\jusched.exe<br>C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe<br>C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br>C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe<br>C:\Program Files\Bonjour\mDNSResponder.exe<br>C:\Program Files\Java\jre6\bin\jqs.exe<br>C:\Program Files\Common Files\Motive\McciCMService.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\PROGRA~1\AVG\AVG8\avgrsx.exe<br>C:\PROGRA~1\AVG\AVG8\avgemc.exe<br>C:\PROGRA~1\AVG\AVG8\avgnsx.exe<br>C:\Program Files\AVG\AVG8\avgcsrvx.exe<br>C:\WINDOWS\system32\wscntfy.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\WINDOWS\system32\wuauclt.exe<br>C:\Documents and Settings\Drader\Desktop\HiJackThis.exe<br><br>R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://www.lds.org/" >www.lds.org/</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=69157" >go.microsoft.com/fwlink/?LinkId=69157</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://www.dell4me.com/myway" >www.dell4me.com/myway</A><br>R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local<br>R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll<br>R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll<br>O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll<br>O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll<br>O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll<br>O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll<br>O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll<br>O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll<br>O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br>O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br>O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll<br>O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll<br>O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll<br>O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\pchealth\helpctr\Binaries\MSCONFIG.EXE /auto<br>O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe<br>O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"<br>O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe<br>O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll<br>O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br>O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br>O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O15 - Trusted Zone: &raquo;<A HREF="http://*.mcafee.com" >*.mcafee.com</A><br>O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - &raquo;<A HREF="http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab" >upload.facebook.com/controls/200&middot;&middot;&middot;der5.cab</A><br>O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - &raquo;<A HREF="http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab" >housecall65.trendmicro.com/house&middot;&middot;&middot;Impl.cab</A><br>O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - &raquo;<A HREF="http://download.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,90/mcinsctl.cab" >download.mcafee.com/molbin/share&middot;&middot;&middot;sctl.cab</A><br>O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - &raquo;<A HREF="http://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab" >wwwimages.adobe.com/www.adobe.co&middot;&middot;&middot;s/gp.cab</A><br>O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll<br>O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll<br>O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br>O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe<br>O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe<br>O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br>O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe<br>O23 - Service: Google Update Service (gupdate1c99dc76a3bc708) (gupdate1c99dc76a3bc708) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe<br>O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br>O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br>O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br>O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe<br>O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Common Files\Motive\McciCMService.exe<br><br>--<br>End of file - 6778 bytes<br><br>Quote:<br>"I rebooted after all of the above. I did not find any pop ups, although i did still see those trojan type files like goyapipmu , Unchecked, in the startup menu. Is there a way to get rid of these or does it even mean anything."<br><br>I was referring to the System configuration utility in the startup menu.  Maybe it won't affect anything though.<br><br>Thanks for everything. Especially the answers to all the questions.  That was awesome! How did you get to be someone that helps people with stuff like this?  Do you go to school in computers.  I have wondered if I need to go learn this stuff and how I would do it. <br><br>Thanks again,<br>AZraders]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22551386</guid>
<pubDate>Sun, 14 Jun 2009 21:54:12 EDT</pubDate>
</item>

<item>
<title>Re: [Vundo] cannot get rid of virtumonde/vundo trojan</title>
<link>http://www.dslreports.com/forum/remark,22551211</link>
<description><![CDATA[<A HREF="/useremail/u/377471"><b>TheJoker</b></A> :  <blockquote><small>quote:</small><hr>I rebooted after all of the above. I did not find any pop ups, although i did still see those trojan type files like goyapipmu , Unchecked, in the startup menu. Is there a way to get rid of these or does it even mean anything.<hr></blockquote><br>I'm not sure where you mean you see it. I no longer see the entries in any of your logs.<br><br> <blockquote><small>quote:</small><hr>I am a little worried about starting up spybot. Im afraid it will ask about those files.<hr></blockquote><br>If you mean TeaTimer, when you start it back up, if it says there were changes, tell it to allow the changes.<br><br> <blockquote><small>quote:</small><hr>Also, you asked me to delete all files related to bigfishgames. I'm okay with getting rid of it. My son downloaded it and was playing it.<br>Tell me about it if you can and why it is bad.<hr></blockquote><br>I've seen it apparently associated with adware.<br><br> <blockquote><small>quote:</small><hr>My daughter likes the pbs.org games as well as barbie.com. Is there harm in these?<hr></blockquote><br>They should be fine.<br><br> <blockquote><small>quote:</small><hr>I have also heard facebook is bad all the way around.<hr></blockquote><br><br>Facebook isn't bad in itself, it's just that there's a lot of malware that targets it. If there is a graphic or video that tries to load but can't, and tells you that it needs to download a CODEC to view it, don't do that, and I would be very wary of instant messaging there or at any social networking site, and don't open URL's that are sent in an IM. I would also be careful about posting personal information there or at any social networking site. Any site that's popular (not just social networking sites) can end up being targeted to be compromized because it brings more potential victims, and malware is all about the money. <br><br> <blockquote><small>quote:</small><hr>Let me know if it is safe to start up all my malware/ antivirus when you can. So far this has been helpful.<hr></blockquote><br><br>You can start TeaTimer back up now if you want, and your antivirus should be running as I see it in your last log.<br><br> <blockquote><small>quote:</small><hr>It would be nice for you to recommend a link that I can visit that will teach me what is safe and what is not.<hr></blockquote><br><br>There are several help forums that also teach people how to remove malware. Two forums that do that are <A HREF="http://forums.spywareinfo.com/index.php?showtopic=148">Spywareinfoforum.com</a> and <A HREF="http://www.bleepingcomputer.com/forums/topic86678.html">BleepingComputer</a>.<br><br>Go to start > run and copy and paste next command in the field:<br><b>ComboFix /u</b><br><br>Make sure there's a space between Combofix and /<br>Then hit enter.<br><br>This will uninstall Combofix, delete its related folders and files, reset your clock settings, hide file extensions, hide the system/hidden files and resets System Restore again.<br><br>Please post a new HijackThis log.<br><small>--<br>Proud ASAP member since 2005</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22551211</guid>
<pubDate>Sun, 14 Jun 2009 21:15:50 EDT</pubDate>
</item>

<item>
<title>Re: [Vundo] cannot get rid of virtumonde/vundo trojan</title>
<link>http://www.dslreports.com/forum/remark,22550205</link>
<description><![CDATA[<A HREF="/useremail/u/1650439"><b>azraders</b></A> : <br><br>Hello there,<br>I followed the instructions per your last post. Here are the scans:<br><br>hijackthissafemode:<br><br>Logfile of Trend Micro HijackThis v2.0.2<br>Scan saved at 10:39:18 AM, on 6/14/2009<br>Platform: Windows XP SP3 (WinNT 5.01.2600)<br>MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)<br>Boot mode: Safe mode<br><br>Running processes:<br>C:\WINDOWS\System32\smss.exe<br>C:\WINDOWS\system32\winlogon.exe<br>C:\WINDOWS\system32\services.exe<br>C:\WINDOWS\system32\lsass.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\Program Files\Windows Defender\MsMpEng.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\WINDOWS\Explorer.EXE<br>C:\Documents and Settings\Drader\Desktop\HiJackThis.exe<br><br>R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &raquo;www.dell4me.com/myway<br>R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = &raquo;bfc.myway.com/search/de_srchlft.html<br>R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;www.dell4me.com/myway<br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &raquo;go.microsoft.com/fwlink/?LinkId=69157<br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &raquo;go.microsoft.com/fwlink/?LinkId=54896<br>R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;www.dell4me.com/myway<br>R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = &raquo;www.dell.com<br>O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll<br>O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll<br>O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll<br>O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll<br>O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll<br>O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll<br>O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br>O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br>O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll<br>O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll<br>O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll<br>O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\pchealth\helpctr\Binaries\MSCONFIG.EXE /auto<br>O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe<br>O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"<br>O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup<br>O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll<br>O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br>O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br>O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - &raquo;upload.facebook.com/controls/200&middot;&middot;&middot;der5.cab<br>O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - &raquo;housecall65.trendmicro.com/house&middot;&middot;&middot;Impl.cab<br>O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - &raquo;download.mcafee.com/molbin/share&middot;&middot;&middot;sctl.cab<br>O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - &raquo;wwwimages.adobe.com/www.adobe.co&middot;&middot;&middot;s/gp.cab<br>O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll<br>O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll<br>O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br>O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe<br>O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe<br>O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br>O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe<br>O23 - Service: Google Update Service (gupdate1c99dc76a3bc708) (gupdate1c99dc76a3bc708) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe<br>O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br>O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br>O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br>O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe<br>O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Common Files\Motive\McciCMService.exe<br><br>--<br>End of file - 5752 bytes<br><br>*****************************<br><br>Combofix<br><br>ComboFix 09-06-13.09 - Drader 06/14/2009 11:19.2 - NTFSx86<br>Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.510.193 [GMT -7:00]<br>Running from: c:\documents and settings\Drader\Desktop\ComboFix.exe<br>AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}<br>.<br><br>((((((((((((((((((((((((( Files Created from 2009-05-14 to 2009-06-14 )))))))))))))))))))))))))))))))<br>.<br><br>2009-06-14 17:15 . 2009-06-14 17:15 152576 ----a-w- c:\documents and settings\Drader\Application Data\Sun\Java\jre1.6.0_14\lzma.dll<br>2009-06-11 23:25 . 2009-06-11 23:34 -------- d-----w- c:\program files\SpywareBlaster<br>2009-06-11 23:25 . 2005-08-26 02:18 118784 ----a-w- c:\windows\system32\MSSTDFMT.DLL<br>2009-06-11 19:59 . 2009-06-11 19:59 -------- d-----w- C:\VundoFix Backups<br>2009-06-11 19:16 . 2009-05-26 20:20 40160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys<br>2009-06-11 19:16 . 2009-06-11 19:17 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware<br>2009-06-11 19:16 . 2009-05-26 20:19 19096 ----a-w- c:\windows\system32\drivers\mbam.sys<br>2009-06-11 04:23 . 2009-06-02 20:37 1004800 ----a-w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar\IEToolbar.dll<br>2009-06-11 01:12 . 2009-06-14 14:59 -------- d--h--w- C:\$AVG8.VAULT$<br>2009-06-11 00:28 . 2009-06-11 00:28 -------- d-----w- c:\documents and settings\Drader\Local Settings\Application Data\AVG Security Toolbar<br>2009-06-11 00:20 . 2009-06-11 00:20 11952 ----a-w- c:\windows\system32\avgrsstx.dll<br>2009-06-11 00:20 . 2009-06-11 00:20 108552 ----a-w- c:\windows\system32\drivers\avgtdix.sys<br>2009-06-11 00:20 . 2009-06-11 00:20 327688 ----a-w- c:\windows\system32\drivers\avgldx86.sys<br>2009-06-11 00:20 . 2009-06-11 00:20 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys<br>2009-06-11 00:19 . 2009-06-14 14:23 -------- d-----w- c:\windows\system32\drivers\Avg<br>2009-06-11 00:19 . 2009-06-11 04:24 -------- d-----w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar<br>2009-06-11 00:19 . 2009-06-11 00:19 -------- d-----w- c:\program files\AVG<br>2009-06-11 00:19 . 2009-06-11 00:19 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8<br>2009-06-11 00:03 . 2009-06-11 00:03 -------- d-----w- c:\documents and settings\Drader\Application Data\AVG8<br>2009-06-10 15:17 . 2009-06-10 15:17 310640 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT<br>2009-06-10 15:02 . 2009-06-10 15:02 -------- d-----w- c:\documents and settings\Administrator\Application Data\Malwarebytes<br>2009-06-10 00:58 . 2009-06-10 00:58 -------- d-----w- c:\program files\Windows Defender<br>2009-06-09 17:08 . 2009-06-09 17:08 -------- d-----w- c:\documents and settings\Drader\Application Data\Malwarebytes<br>2009-06-09 17:07 . 2009-06-09 17:07 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes<br>2009-06-08 23:10 . 2009-06-08 23:10 -------- d-----w- c:\documents and settings\Drader\Local Settings\Application Data\WMTools Downloaded Files<br>2009-06-04 14:22 . 2009-06-04 04:10 15688 ----a-w- c:\windows\system32\lsdelete.exe<br>2009-06-04 04:05 . 2009-06-14 02:20 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}<br>2009-06-04 04:05 . 2009-03-12 08:17 2902048 -c--a-w- c:\documents and settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}\Ad-AwareAE.exe<br>2009-05-27 02:28 . 2009-05-27 02:28 -------- d-----w- c:\program files\Musicnotes<br>2009-05-27 02:25 . 2009-06-08 23:07 -------- d-----w- c:\documents and settings\All Users\Application Data\Musicnotes<br>2009-05-22 02:49 . 2009-05-22 02:49 -------- d-----w- c:\documents and settings\Drader\Application Data\KodakCredentialStore<br><br>.<br>(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br>2009-06-14 18:06 . 2009-01-29 18:18 1 ----a-w- c:\documents and settings\Drader\Application Data\OpenOffice.org\3\user\uno_packages\cache\stamp.sys<br>2009-06-14 17:20 . 2009-02-24 19:30 410984 ----a-w- c:\windows\system32\deploytk.dll<br>2009-06-14 17:15 . 2008-12-24 23:23 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee<br>2009-06-14 02:49 . 2009-05-04 21:44 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP<br>2009-06-14 01:59 . 2008-12-28 17:56 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater<br>2009-06-11 02:08 . 2008-12-26 17:48 -------- d-----w- c:\documents and settings\Drader\Application Data\AdobeUM<br>2009-06-08 23:11 . 2008-12-25 00:35 -------- d-----w- c:\documents and settings\LocalService\Application Data\SACore<br>2009-06-08 23:10 . 2008-12-28 17:56 -------- d-----w- c:\program files\Google<br>2009-06-08 23:10 . 2008-12-24 17:44 -------- d-----w- c:\documents and settings\Drader\Application Data\Sonic<br>2009-06-04 04:05 . 2009-01-27 23:16 -------- d-----w- c:\program files\Lavasoft<br>2009-06-04 04:05 . 2008-12-26 18:03 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft<br>2009-05-27 14:36 . 2008-12-24 22:54 310640 ----a-w- c:\documents and settings\Drader\Local Settings\Application Data\GDIPFONTCACHEV1.DAT<br>2009-05-22 16:51 . 2009-03-04 04:14 848 --sha-w- c:\windows\system32\KGyGaAvL.sys<br>2009-05-12 01:50 . 2009-05-12 01:50 -------- d-----w- c:\documents and settings\Drader\Application Data\Leadertech<br>2009-05-07 15:32 . 2004-08-04 10:00 345600 ----a-w- c:\windows\system32\localspl.dll<br>2009-05-04 17:25 . 2009-05-04 17:25 -------- d-----w- c:\documents and settings\Drader\Application Data\Skinux<br>2009-05-04 16:57 . 2009-05-04 16:06 -------- d-----w- c:\documents and settings\All Users\Application Data\Kodak<br>2009-05-04 16:52 . 2009-05-04 16:48 -------- d-----w- c:\program files\Common Files\Kodak<br>2009-05-04 16:31 . 2009-05-04 16:29 -------- d-----w- c:\program files\Kodak<br>2009-05-04 16:20 . 2009-05-04 16:20 77824 ----a-w- c:\documents and settings\All Users\Application Data\Kodak\EasyShareSetup\ess\bindbins\bindbins.exe<br>2009-05-04 16:18 . 2009-05-04 16:13 23510720 ----a-w- c:\documents and settings\All Users\Application Data\Kodak\EasyShareSetup\fwork\dotnetfx.exe<br>2009-05-04 16:17 . 2009-05-04 16:17 30720 ----a-w- c:\documents and settings\All Users\Application Data\Kodak\EasyShareSetup\fwork\netfw.exe<br>2009-05-04 16:13 . 2009-05-04 16:13 45056 ----a-w- c:\documents and settings\All Users\Application Data\Kodak\EasyShareSetup\sysfiles\kb945060\kb945060.exe<br>2009-05-04 16:08 . 2009-05-04 16:08 1187840 ----a-w- c:\documents and settings\All Users\Application Data\Kodak\EasyShareSetup\$SETUP_140001_a031e62\EasyShrx.Dll<br>2009-05-04 16:07 . 2009-05-04 16:07 114688 ----a-w- c:\documents and settings\All Users\Application Data\Kodak\EasyShareSetup\$Registration\KodakCameraAPI_7.9.20.1.dll<br>2009-05-04 16:07 . 2009-05-04 16:08 2499984 ----a-w- c:\documents and settings\All Users\Application Data\Kodak\EasyShareSetup\$SETUP_140001_a031e62\Setup.exe<br>2009-05-04 16:06 . 2009-05-04 16:06 114688 ----a-w- c:\documents and settings\All Users\Application Data\Kodak\EasyShareSetup\$Registration\KodakCameraAPI_7.2.25.1.dll<br>2009-04-29 04:46 . 2004-08-04 10:00 666624 ----a-w- c:\windows\system32\wininet.dll<br>2009-04-29 04:46 . 2004-08-04 10:00 81920 ----a-w- c:\windows\system32\ieencode.dll<br>2009-04-26 19:27 . 2009-04-26 06:41 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy<br>2009-04-26 15:00 . 2009-04-26 06:41 -------- d-----w- c:\program files\Spybot - Search & Destroy<br>2009-04-17 12:26 . 2004-08-04 10:00 1847168 ----a-w- c:\windows\system32\win32k.sys<br>2009-04-15 14:51 . 2004-08-04 10:00 585216 ----a-w- c:\windows\system32\rpcrt4.dll<br>2009-04-13 21:54 . 2009-04-13 21:54 1878984 ----a-w- c:\documents and settings\Drader\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\fpupdatepl\fpupdatepl.exe<br>2009-03-29 15:25 . 2004-08-10 18:13 78199 ----a-w- c:\windows\PCHEALTH\HELPCTR\OfflineCache\index.dat<br>2009-03-19 16:56 . 2009-03-19 16:56 129 ----a-w- c:\documents and settings\Drader\Local Settings\Application Data\fusioncache.dat<br>2009-03-19 16:51 . 2009-03-19 16:51 164 ----a-w- c:\windows\install.dat<br>.<br><br>((((((((((((((((((((((((((((( SnapShot@2009-06-14_03.34.25 )))))))))))))))))))))))))))))))))))))))))<br>.<br>+ 2009-06-14 17:43 . 2009-06-14 17:43 16384 c:\windows\Temp\Perflib_Perfdata_1e0.dat<br>- 2009-03-18 00:42 . 2009-03-18 00:41 148888 c:\windows\SYSTEM32\javaws.exe<br>+ 2009-06-14 17:20 . 2009-06-14 17:20 148888 c:\windows\SYSTEM32\javaws.exe<br>+ 2009-06-14 17:20 . 2009-06-14 17:20 144792 c:\windows\SYSTEM32\javaw.exe<br>- 2009-03-18 00:42 . 2009-03-18 00:41 144792 c:\windows\SYSTEM32\javaw.exe<br>+ 2009-06-14 17:20 . 2009-06-14 17:20 144792 c:\windows\SYSTEM32\java.exe<br>- 2009-03-18 00:42 . 2009-03-18 00:41 144792 c:\windows\SYSTEM32\java.exe<br>.<br>((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br>.<br>*Note* empty entries & legit default entries are not shown<br>REGEDIT4<br><br>[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]<br>2009-06-02 20:37 1004800 ----a-w- c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll<br><br>[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<br>"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-12-28 39408]<br><br>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<br>"MSConfig"="c:\windows\pchealth\helpctr\Binaries\MSCONFIG.EXE" [2008-04-14 169984]<br>"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-06-11 1948440]<br>"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-06-14 148888]<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]<br>2009-06-11 00:20 11952 ----a-w- c:\windows\SYSTEM32\avgrsstx.dll<br><br>[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]<br>@="Service"<br><br>[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]<br>@="Service"<br><br>[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^America Online 9.0 Tray Icon.lnk]<br>path=c:\documents and settings\All Users\Start Menu\Programs\Startup\America Online 9.0 Tray Icon.lnk<br>backup=c:\windows\pss\America Online 9.0 Tray Icon.lnkCommon Startup<br><br>[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk]<br>path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk<br>backup=c:\windows\pss\Kodak EasyShare software.lnkCommon Startup<br><br>[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^QuickBooks Update Agent.lnk]<br>path=c:\documents and settings\All Users\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk<br>backup=c:\windows\pss\QuickBooks Update Agent.lnkCommon Startup<br><br>[HKLM\~\startupfolder\C:^Documents and Settings^Drader^Start Menu^Programs^Startup^OpenOffice.org 3.0.lnk]<br>path=c:\documents and settings\Drader\Start Menu\Programs\Startup\OpenOffice.org 3.0.lnk<br>backup=c:\windows\pss\OpenOffice.org 3.0.lnkStartup<br><br>[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]<br>"EnableFirewall"= 0 (0x0)<br><br>[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]<br>"%windir%\\system32\\sessmgr.exe"=<br>"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=<br>"c:\\Program Files\\iTunes\\iTunes.exe"=<br>"%windir%\\Network Diagnostic\\xpnetdiag.exe"=<br>"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=<br>"c:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=<br>"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=<br>"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=<br>"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=<br><br>R0 Lbd;Lbd;c:\windows\SYSTEM32\DRIVERS\Lbd.sys [1/27/2009 4:22 PM 64160]<br>R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\SYSTEM32\DRIVERS\avgldx86.sys [6/10/2009 5:20 PM 327688]<br>R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\SYSTEM32\DRIVERS\avgtdix.sys [6/10/2009 5:20 PM 108552]<br>R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [6/10/2009 5:19 PM 908568]<br>R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [6/10/2009 5:19 PM 298776]<br>R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 7:19 PM 13592]<br>S2 gupdate1c99dc76a3bc708;Google Update Service (gupdate1c99dc76a3bc708);c:\program files\Google\Update\GoogleUpdate.exe [3/5/2009 12:20 PM 133104]<br>S3 getPlus(R) Helper;getPlus(R) Helper;c:\program files\NOS\bin\getPlus_HelperSvc.exe [1/4/2009 12:00 PM 33752]<br>S3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [3/9/2009 12:06 PM 1005904]<br>.<br>Contents of the 'Scheduled Tasks' folder<br><br>2009-06-11 c:\windows\Tasks\Ad-Aware Update (Weekly).job<br>- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-09 04:10]<br><br>2009-06-05 c:\windows\Tasks\AppleSoftwareUpdate.job<br>- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 20:34]<br><br>2009-06-14 c:\windows\Tasks\Google Software Updater.job<br>- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-12-28 21:58]<br><br>2009-06-14 c:\windows\Tasks\GoogleUpdateTaskMachine.job<br>- c:\program files\Google\Update\GoogleUpdate.exe [2009-03-05 19:19]<br><br>2009-06-14 c:\windows\Tasks\MP Scheduled Scan.job<br>- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-04 02:20]<br>.<br>.<br>------- Supplementary Scan -------<br>.<br>uStart Page = hxxp://www.lds.org/<br>uSearch Page = hxxp://www.google.com<br>uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7<br>uSearch Bar = hxxp://www.google.com/ie<br>mStart Page = hxxp://www.dell4me.com/myway<br>uInternet Connection Wizard,ShellNext = iexplore<br>uInternet Settings,ProxyOverride = *.local<br>uSearchURL,(Default) = hxxp://www.google.com/search?q=%s<br>Trusted Zone: internet<br>Trusted Zone: mcafee.com<br>FF - ProfilePath - c:\documents and settings\Drader\Application Data\Mozilla\Firefox\Profiles\jrslb912.default\<br>FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll<br>FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll<br>FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll<br>FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll<br>FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\xpavgtbapi.dll<br>FF - plugin: c:\documents and settings\Drader\Application Data\Mozilla\Firefox\Profiles\jrslb912.default\extensions\moveplayer@movenetworks.com\platform\WINNT_x86-msvc\plugins\npmnqmp071303000006.dll<br>FF - plugin: c:\program files\Google\Google Earth Plugin\npgeplugin.dll<br>FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll<br>FF - plugin: c:\program files\Google\Update\1.2.145.5\npGoogleOneClick8.dll<br>FF - plugin: c:\program files\Mozilla Firefox\plugins\npmusicn.dll<br>.<br><br>**********************************************<br><br>catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, &raquo;www.gmer.net<br>Rootkit scan 2009-06-14 11:25<br>Windows 5.1.2600 Service Pack 3 NTFS<br><br>scanning hidden processes ...<br><br>scanning hidden autostart entries ...<br><br>scanning hidden files ...<br><br>scan completed successfully<br>hidden files: 0<br><br>**************************************************************************<br>.<br>--------------------- DLLs Loaded Under Running Processes ---------------------<br><br>- - - - - - - > 'explorer.exe'(3812)<br>c:\windows\system32\WPDShServiceObj.dll<br>c:\windows\system32\PortableDeviceTypes.dll<br>c:\windows\system32\PortableDeviceApi.dll<br>.<br>Completion time: 2009-06-14 11:29<br>ComboFix-quarantined-files.txt 2009-06-14 18:28<br>ComboFix2.txt 2009-06-14 03:38<br><br>Pre-Run: 23,446,327,296 bytes free<br>Post-Run: 23,438,544,896 bytes free<br><br>201 --- E O F --- 2009-06-13 09:19<br><br>************************************<br><br>MBAM after combo fix<br><br>Malwarebytes' Anti-Malware 1.37<br>Database version: 2277<br>Windows 5.1.2600 Service Pack 3<br><br>6/14/2009 11:46:09 AM<br>mbam-log-2009-06-14 (11-46-09).txt<br><br>Scan type: Quick Scan<br>Objects scanned: 60954<br>Time elapsed: 3 minute(s), 40 second(s)<br><br>Memory Processes Infected: 0<br>Memory Modules Infected: 0<br>Registry Keys Infected: 0<br>Registry Values Infected: 0<br>Registry Data Items Infected: 0<br>Folders Infected: 0<br>Files Infected: 0<br><br>Memory Processes Infected:<br>(No malicious items detected)<br><br>Memory Modules Infected:<br>(No malicious items detected)<br><br>Registry Keys Infected:<br>(No malicious items detected)<br><br>Registry Values Infected:<br>(No malicious items detected)<br><br>Registry Data Items Infected:<br>(No malicious items detected)<br><br>**************************************<br><br>Hijackthis post combo fix<br><br>Logfile of Trend Micro HijackThis v2.0.2<br>Scan saved at 11:48:46 AM, on 6/14/2009<br>Platform: Windows XP SP3 (WinNT 5.01.2600)<br>MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)<br>Boot mode: Normal<br><br>Running processes:<br>C:\WINDOWS\System32\smss.exe<br>C:\WINDOWS\system32\winlogon.exe<br>C:\WINDOWS\system32\services.exe<br>C:\WINDOWS\system32\lsass.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\Program Files\Windows Defender\MsMpEng.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\WINDOWS\system32\spoolsv.exe<br>C:\Program Files\Google\Update\GoogleUpdate.exe<br>C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br>C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe<br>C:\Program Files\Bonjour\mDNSResponder.exe<br>C:\Program Files\Java\jre6\bin\jqs.exe<br>C:\Program Files\Common Files\Motive\McciCMService.exe<br>C:\Program Files\Java\jre6\bin\jusched.exe<br>C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\PROGRA~1\AVG\AVG8\avgemc.exe<br>C:\PROGRA~1\AVG\AVG8\avgrsx.exe<br>C:\PROGRA~1\AVG\AVG8\avgnsx.exe<br>C:\Program Files\AVG\AVG8\avgcsrvx.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\WINDOWS\system32\wscntfy.exe<br>C:\WINDOWS\explorer.exe<br>C:\WINDOWS\system32\wuauclt.exe<br>C:\Documents and Settings\Drader\Desktop\HiJackThis.exe<br><br>R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;www.lds.org/<br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &raquo;go.microsoft.com/fwlink/?LinkId=69157<br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &raquo;go.microsoft.com/fwlink/?LinkId=54896<br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &raquo;go.microsoft.com/fwlink/?LinkId=54896<br>R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;www.dell4me.com/myway<br>R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local<br>R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll<br>R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll<br>O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll<br>O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll<br>O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll<br>O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll<br>O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll<br>O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll<br>O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br>O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br>O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll<br>O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll<br>O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll<br>O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\pchealth\helpctr\Binaries\MSCONFIG.EXE /auto<br>O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe<br>O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"<br>O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe<br>O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll<br>O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br>O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br>O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O15 - Trusted Zone: &raquo;*.mcafee.com<br>O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - &raquo;upload.facebook.com/controls/200&middot;&middot;&middot;der5.cab<br>O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - &raquo;housecall65.trendmicro.com/house&middot;&middot;&middot;Impl.cab<br>O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - &raquo;download.mcafee.com/molbin/share&middot;&middot;&middot;sctl.cab<br>O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - &raquo;wwwimages.adobe.com/www.adobe.co&middot;&middot;&middot;s/gp.cab<br>O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll<br>O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll<br>O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br>O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe<br>O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe<br>O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br>O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe<br>O23 - Service: Google Update Service (gupdate1c99dc76a3bc708) (gupdate1c99dc76a3bc708) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe<br>O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br>O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br>O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br>O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe<br>O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Common Files\Motive\McciCMService.exe<br><br>--<br>End of file - 6745 bytes<br><br>*****************************************<br>virustotal<br><br>File MSSTDFMT.DLL received on 2009.06.14 19:03:15 (UTC)<br>Current status: Loading ... queued waiting scanning finished NOT FOUND STOPPED<br><br>Result: 0/40 (0%)<br>Loading server information...<br>Your file is queued in position: 1.<br>Estimated start time is between 43 and 62 seconds.<br>Do not close the window until scan is complete.<br>The scanner that was processing your file is stopped at this moment, we are going to wait a few seconds to try to recover your result.<br>If you are waiting for more than five minutes you have to resend your file.<br>Your file is being scanned by VirusTotal in this moment,<br>results will be shown as they're generated.<br>Compact Print results<br>Your file has expired or does not exists.<br>Service is stopped in this moments, your file is waiting to be scanned (position: ) for an undefined time.<br><br>You can wait for web response (automatic reload) or type your email in the form below and click "request" so the system sends you a notification when the scan is finished.<br>Email:<br><br>Antivirus Version Last Update Result<br>a-squared 4.5.0.18 2009.06.14 -<br>AhnLab-V3 5.0.0.2 2009.06.14 -<br>AntiVir 7.9.0.187 2009.06.14 -<br>Antiy-AVL 2.0.3.1 2009.06.12 -<br>Authentium 5.1.2.4 2009.06.13 -<br>Avast 4.8.1335.0 2009.06.14 -<br>AVG 8.5.0.339 2009.06.14 -<br>BitDefender 7.2 2009.06.14 -<br>CAT-QuickHeal 10.00 2009.06.13 -<br>ClamAV 0.94.1 2009.06.14 -<br>Comodo 1328 2009.06.14 -<br>DrWeb 5.0.0.12182 2009.06.14 -<br>eSafe 7.0.17.0 2009.06.11 -<br>eTrust-Vet 31.6.6556 2009.06.12 -<br>F-Prot 4.4.4.56 2009.06.13 -<br>F-Secure 8.0.14470.0 2009.06.13 -<br>Fortinet 3.117.0.0 2009.06.14 -<br>GData 19 2009.06.14 -<br>Ikarus T3.1.1.59.0 2009.06.14 -<br>K7AntiVirus 7.10.762 2009.06.12 -<br>Kaspersky 7.0.0.125 2009.06.14 -<br>McAfee 5646 2009.06.14 -<br>McAfee+Artemis 5646 2009.06.14 -<br>McAfee-GW-Edition 6.7.6 2009.06.14 -<br>Microsoft 1.4701 2009.06.14 -<br>NOD32 4153 2009.06.14 -<br>Norman 6.01.09 2009.06.12 -<br>nProtect 2009.1.8.0 2009.06.14 -<br>Panda 10.0.0.14 2009.06.14 -<br>PCTools 4.4.2.0 2009.06.12 -<br>Prevx 3.0 2009.06.14 -<br>Rising 21.33.62.00 2009.06.14 -<br>Sophos 4.42.0 2009.06.14 -<br>Sunbelt 3.2.1858.2 2009.06.14 -<br>Symantec 1.4.4.12 2009.06.14 -<br>TheHacker 6.3.4.3.345 2009.06.13 -<br>TrendMicro 8.950.0.1092 2009.06.12 -<br>VBA32 3.12.10.7 2009.06.14 -<br>ViRobot 2009.6.13.1785 2009.06.13 -<br>VirusBuster 4.6.5.0 2009.06.14 -<br><br>I rebooted after all of the above. I did not find any pop ups, although i did still see those trojan type files like goyapipmu , Unchecked, in the startup menu. Is there a way to get rid of these or does it even mean anything. I am a little worried about starting up spybot. Im afraid it will ask about those files.<br><br>Also, you asked me to delete all files related to bigfishgames. I'm okay with getting rid of it. My son downloaded it and was playing it.<br>Tell me about it if you can and why it is bad.<br>How do I know which games my kids can play? I have told him not to play any games at this point.<br><br>My daughter likes the pbs.org games as well as barbie.com. Is there harm in these?<br><br>I have also heard facebook is bad all the way around. My other daughter likes that. is there a safe way to do that or should I ban her on facebook alltogether as well?<br><br>I would appreciate all your help with those questions. It would be nice for you to recommend a link that I can visit that will teach me what is safe and what is not.<br><br>Let me know if it is safe to start up all my malware/ antivirus when you can. So far this has been helpful.<br><br>azraders <br> <br> ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22550205</guid>
<pubDate>Sun, 14 Jun 2009 16:59:44 EDT</pubDate>
</item>

<item>
<title>Re: [Vundo] cannot get rid of virtumonde/vundo trojan</title>
<link>http://www.dslreports.com/forum/remark,22548868</link>
<description><![CDATA[<A HREF="/useremail/u/377471"><b>TheJoker</b></A> : I'm not so sure that the actual infection is still there, or if it's simply that there was a problem removing the related registry keys. It appears that the files related to the vundo infection are gone.<br><br>Please follow the below instructions in the order listed.<br><br>To clear the Java Runtime Environment (JRE) cache:<br>- Click Start > Control Panel. <br>- Double-click the Java icon in the control panel. <br>-The Java Control Panel appears. <br>- Click Settings under Temporary Internet Files. <br>-The Temporary Files Settings dialog box appears.<br>- Click Delete Files. <br>-The Delete Temporary Files dialog box appears.<br>-There are two options on this window to clear the cache.<br>- Applications and Applets<br>- Trace and Log Files<br>- Click OK on Delete Temporary Files window. <br>-Note: This deletes all the Downloaded Applications and Applets from the cache. <br>- Click OK on Temporary Files Settings window. <br>- Close the Java Control Panel<br><br>Your version of Java is outdated and needs to be updated to take advantage of fixes that have eliminated security vulnerabilities.<br><b>Updating Java:</b><br>- Download the latest version of  <b><A HREF="http://java.sun.com/javase/downloads/index.jsp">Java Runtime Environment (JRE) 6</a></b>.<br>- Scroll down to where it says "<i>Java SE Runtime Environment (JRE), JRE 6 Update 14</i>".<br>- Click the "<b>Download</b>" button to the right.<br>- In the Window that opens, select Windows, and check the "agree" box and click "Continue".<br>- Click on the link to download <i>Windows Offline Installation</i> and save to your desktop.<br>- Close any programs you may have running - especially your web browser.<br>- Go to <b>Start</b> > <b>Control Panel</b> double-click on <b>Add or Remove Programs</b> and remove all older versions of Java.<br>- Check any item with Java Runtime Environment (JRE or J2SE) in the name.<br>- Examples of older versions in Add or Remove Programs:<br>-- Java 2 Runtime Environment, SE v1.4.2<br>-- J2SE Runtime Environment 5.0<br>-- J2SE Runtime Environment 5.0 Update 2<br>- Click the <b>Remove</b> or <b>Change/Remove</b> button.<br>- Repeat as many times as necessary to remove each Java versions.<br>- Reboot your computer once all Java components are removed.<br>- Then from your desktop double-click on <b>jre-6u14-windows-i586-p.exe</b> that you downloaded to install the newest version.<br><br>I recommend going to Control Panel's Add or Remove Programs and uninstalling anything connected to <b>Big Fish Games</b><br><br>If you uninstall it as recommended, then delete the following two folders if still there:<br><br>Reconfigure Windows XP to show hidden files:<br>Click Start. Open My Computer. <br>Select the Tools menu and click Folder Options. Select the View Tab. <br>Under the Hidden files and folders heading select "Show hidden files and folders". <br>Uncheck the "Hide protected operating system files (recommended)" option. <br>Uncheck the "Hide file extensions for known file types" option.<br>Click Yes to confirm. Click OK.<br><br>Using Windows Explorer, delete the following folders if still there:<br>c:\documents and settings\All Users\Application Data\<b>BigFishGamesCache</b><br>c:\program files\<b>bfgclient</b><br><br>Now you need to hide the files you un-hid earlier:<br>Click Start. Open My Computer.<br>Select the Tools menu and click Folder Options. Select the View Tab. <br>Under the Hidden files and folders heading unselect "Show hidden files and folders". <br>Check the "Hide protected operating system files (recommended)" option. <br>Click Yes to confirm. Click OK.<br><br>Now <b>reboot to Safe Mode</b> - Restart your computer and begin tapping the F8 key on your keyboard. <br>If done right a Windows Advanced Options menu will appear. Select the Safe Mode option and press Enter.<br>To return to normal mode just restart your computer as you normally would.<br><br>Now you need to run HijackThis and click "<b>Do a system scan only</b>." Place a check next to the following entries (if they are still there):<br><br><b>O4 - HKLM\..\Run: [goyapipemu] Rundll32.exe "C:\WINDOWS\system32\viyorawi.dll",s<br>O4 - HKLM\..\Run: [54712828] rundll32.exe "C:\WINDOWS\system32\kuwokilo.dll",b</b><br><br>Now close all browser and other windows except for HijackThis, and click "<b>Fix Checked</b>" to have HijackThis fix the entries you checked.<br><br>Restart your system.<br><br>We need to make sure you have the most recent version of ComboFix.<br><b>Delete</b> your current copy of ComboFix.exe.<br>Download <b>ComboFix&copy; by sUBs</b> from one of these links:<br><br><textarea name="code" class="text" cols=50 rows=10>http://download.bleepingcomputer.com/sUBs/ComboFix.exe&#012;http://www.forospyware.com/sUBs/ComboFix.exe&#012;http://subs.geekstogo.com/ComboFix.exe&#012;</textarea><!--end code block--><br>Save the file to your Desktop.<br>- Close any open browsers.<br>- Disable your AntiVirus and any AntiSpyware programs you may be running (usually via a right click on the System Tray icon) to prevent them from interfering.<br><br>- Double click on ComboFix.exe & follow the prompts.<br><br> <IMG SRC="http://img.photobucket.com/albums/v706/ried7/RcAuto1.gif"> <br><br>Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:<br><br> <IMG SRC="http://img.photobucket.com/albums/v706/ried7/whatnext.png"> <br><br>Click on Yes, to continue scanning for malware. When finished, it will save a log. <br>Please include the contents of the log at <b>C:\ComboFix.txt</b> in your next reply.<br><br>Please Run Malwarebytes' Anti-Malware.<br>- Click the Update tab.<br>- Click Check for Updates.<br>- If an update is found, it will download and install.<br>- Click the Scanner tab.<br>- Select "<b>Perform Quick Scan</b>", then click <b>Scan</b>.<br>- The scan may take some time to finish,so please be patient.<br>- When the scan is complete, click OK, then Show Results to view the results.<br>- Make sure that <b>everything is checked</b>, and click <b>Remove Selected</b>.<br>- When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Note)<br>- The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.<br>- Copy & Paste the entire report in your next reply along with a fresh HijackThis log.<br><br>Note:<br><i>If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts.<br>Click OK to either and let MBAM proceed with the disinfection process.<br>If asked to restart the computer, please do so immediately.</i><br><br>Please go to <A HREF="http://www.virustotal.com">VirusTotal</a> and submit the following file for a scan and post the detection results (I don't need the "additional information") in your next reply:<br>c:\windows\system32\<b>MSSTDFMT.DLL</b><br><br>Please post a new HijackThis log, the log from ComboFix (combofix.txt), the log from MBAM, the results of scanning the file at VirusTotal, and note any errors encountered.<br><br><small>--<br>Proud ASAP member since 2005</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22548868</guid>
<pubDate>Sun, 14 Jun 2009 10:44:25 EDT</pubDate>
</item>

<item>
<title>Re: [Vundo] cannot get rid of virtumonde/vundo trojan</title>
<link>http://www.dslreports.com/forum/remark,22548174</link>
<description><![CDATA[<A HREF="/useremail/u/1650439"><b>azraders</b></A> : I have done a reboot and the following were found:<br><br>Hijackthis:<br><br>Logfile of Trend Micro HijackThis v2.0.2<br>Scan saved at 10:01:22 PM, on 6/13/2009<br>Platform: Windows XP SP3 (WinNT 5.01.2600)<br>MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)<br>Boot mode: Normal<br><br>Running processes:<br>C:\WINDOWS\System32\smss.exe<br>C:\WINDOWS\system32\winlogon.exe<br>C:\WINDOWS\system32\services.exe<br>C:\WINDOWS\system32\lsass.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\Program Files\Windows Defender\MsMpEng.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\WINDOWS\system32\spoolsv.exe<br>C:\WINDOWS\Explorer.EXE<br>C:\Program Files\Google\Update\GoogleUpdate.exe<br>C:\Program Files\Java\jre6\bin\jusched.exe<br>C:\PROGRA~1\AVG\AVG8\avgtray.exe<br>C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br>C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe<br>C:\Program Files\Bonjour\mDNSResponder.exe<br>C:\Program Files\Java\jre6\bin\jqs.exe<br>C:\Program Files\Common Files\Motive\McciCMService.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\PROGRA~1\AVG\AVG8\avgrsx.exe<br>C:\PROGRA~1\AVG\AVG8\avgemc.exe<br>C:\PROGRA~1\AVG\AVG8\avgnsx.exe<br>C:\Program Files\AVG\AVG8\avgcsrvx.exe<br>C:\WINDOWS\system32\wscntfy.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe<br>C:\Documents and Settings\Drader\Desktop\HiJackThis.exe<br><br>R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://www.lds.org/" >www.lds.org/</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=69157" >go.microsoft.com/fwlink/?LinkId=69157</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://www.dell4me.com/myway" >www.dell4me.com/myway</A><br>R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local<br>R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll<br>R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll<br>O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll<br>O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll<br>O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll<br>O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll<br>O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll<br>O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll<br>O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br>O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br>O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll<br>O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll<br>O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll<br>O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\pchealth\helpctr\Binaries\MSCONFIG.EXE /auto<br>O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"<br>O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe<br>O4 - HKLM\..\Run: [goyapipemu] Rundll32.exe "C:\WINDOWS\system32\viyorawi.dll",s<br>O4 - HKLM\..\Run: [54712828] rundll32.exe "C:\WINDOWS\system32\kuwokilo.dll",b<br>O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll<br>O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br>O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br>O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O15 - Trusted Zone: &raquo;<A HREF="http://*.mcafee.com" >*.mcafee.com</A><br>O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - &raquo;<A HREF="http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab" >upload.facebook.com/controls/200&middot;&middot;&middot;der5.cab</A><br>O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - &raquo;<A HREF="http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab" >housecall65.trendmicro.com/house&middot;&middot;&middot;Impl.cab</A><br>O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - &raquo;<A HREF="http://download.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,90/mcinsctl.cab" >download.mcafee.com/molbin/share&middot;&middot;&middot;sctl.cab</A><br>O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - &raquo;<A HREF="http://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab" >wwwimages.adobe.com/www.adobe.co&middot;&middot;&middot;s/gp.cab</A><br>O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll<br>O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll<br>O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br>O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe<br>O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe<br>O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br>O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe<br>O23 - Service: Google Update Service (gupdate1c99dc76a3bc708) (gupdate1c99dc76a3bc708) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe<br>O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br>O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br>O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br>O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe<br>O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Common Files\Motive\McciCMService.exe<br><br>--<br>End of file - 6792 bytes<br><br>MBAM<br><br>Malwarebytes' Anti-Malware 1.37<br>Database version: 2273<br>Windows 5.1.2600 Service Pack 3<br><br>6/13/2009 10:00:38 PM<br>mbam-log-2009-06-13 (21-59-52).txt  after reboot<br><br>Scan type: Quick Scan<br>Objects scanned: 85890<br>Time elapsed: 4 minute(s), 8 second(s)<br><br>Memory Processes Infected: 0<br>Memory Modules Infected: 0<br>Registry Keys Infected: 0<br>Registry Values Infected: 2<br>Registry Data Items Infected: 0<br>Folders Infected: 0<br>Files Infected: 0<br><br>Memory Processes Infected:<br>(No malicious items detected)<br><br>Memory Modules Infected:<br>(No malicious items detected)<br><br>Registry Keys Infected:<br>(No malicious items detected)<br><br>Registry Values Infected:<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\goyapipemu (Trojan.Vundo.H) -> No action taken.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\54712828 (Trojan.Vundo.H) -> No action taken.<br><br>Registry Data Items Infected:<br>(No malicious items detected)<br><br>                                I think it is still there :(]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22548174</guid>
<pubDate>Sun, 14 Jun 2009 01:28:56 EDT</pubDate>
</item>

<item>
<title>Re: [Vundo] cannot get rid of virtumonde/vundo trojan</title>
<link>http://www.dslreports.com/forum/remark,22548078</link>
<description><![CDATA[<A HREF="/useremail/u/1650439"><b>azraders</b></A> : I have done as directed per your post.  I have included post scans as well as the pre-scan you requested with MBAM.  Let me know what I need to do next.<br><br>COMBOFIX:<br><br>ComboFix 09-06-13.05 - Drader 06/13/2009 20:26.1 - NTFSx86<br>Microsoft Windows XP Home Edition  5.1.2600.3.1252.1.1033.18.510.201 [GMT -7:00]<br>Running from: c:\documents and settings\Drader\Desktop\ComboFix.exe<br>AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}<br>.<br><br>(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br><br>c:\windows\system32\bszip.dll<br>c:\windows\system32\drivers\fad.sys<br><br>.<br>(((((((((((((((((((((((((   Files Created from 2009-05-14 to 2009-06-14  )))))))))))))))))))))))))))))))<br>.<br><br>2009-06-11 23:25 . 2009-06-11 23:34&#9;--------&#9;d-----w-&#9;c:\program files\SpywareBlaster<br>2009-06-11 23:25 . 2005-08-26 02:18&#9;118784&#9;----a-w-&#9;c:\windows\system32\MSSTDFMT.DLL<br>2009-06-11 19:59 . 2009-06-11 19:59&#9;--------&#9;d-----w-&#9;C:\VundoFix Backups<br>2009-06-11 19:16 . 2009-05-26 20:20&#9;40160&#9;----a-w-&#9;c:\windows\system32\drivers\mbamswissarmy.sys<br>2009-06-11 19:16 . 2009-06-11 19:17&#9;--------&#9;d-----w-&#9;c:\program files\Malwarebytes' Anti-Malware<br>2009-06-11 19:16 . 2009-05-26 20:19&#9;19096&#9;----a-w-&#9;c:\windows\system32\drivers\mbam.sys<br>2009-06-11 04:23 . 2009-06-02 20:37&#9;1004800&#9;----a-w-&#9;c:\documents and settings\All Users\Application Data\AVG Security Toolbar\IEToolbar.dll<br>2009-06-11 01:12 . 2009-06-13 19:39&#9;--------&#9;d--h--w-&#9;C:\$AVG8.VAULT$<br>2009-06-11 00:28 . 2009-06-11 00:28&#9;--------&#9;d-----w-&#9;c:\documents and settings\Drader\Local Settings\Application Data\AVG Security Toolbar<br>2009-06-11 00:20 . 2009-06-11 00:20&#9;11952&#9;----a-w-&#9;c:\windows\system32\avgrsstx.dll<br>2009-06-11 00:20 . 2009-06-11 00:20&#9;108552&#9;----a-w-&#9;c:\windows\system32\drivers\avgtdix.sys<br>2009-06-11 00:20 . 2009-06-11 00:20&#9;327688&#9;----a-w-&#9;c:\windows\system32\drivers\avgldx86.sys<br>2009-06-11 00:20 . 2009-06-11 00:20&#9;27784&#9;----a-w-&#9;c:\windows\system32\drivers\avgmfx86.sys<br>2009-06-11 00:19 . 2009-06-14 00:31&#9;--------&#9;d-----w-&#9;c:\windows\system32\drivers\Avg<br>2009-06-11 00:19 . 2009-06-11 04:24&#9;--------&#9;d-----w-&#9;c:\documents and settings\All Users\Application Data\AVG Security Toolbar<br>2009-06-11 00:19 . 2009-06-11 00:19&#9;--------&#9;d-----w-&#9;c:\program files\AVG<br>2009-06-11 00:19 . 2009-06-11 00:19&#9;--------&#9;d-----w-&#9;c:\documents and settings\All Users\Application Data\avg8<br>2009-06-11 00:03 . 2009-06-11 00:03&#9;--------&#9;d-----w-&#9;c:\documents and settings\Drader\Application Data\AVG8<br>2009-06-10 15:17 . 2009-06-10 15:17&#9;310640&#9;----a-w-&#9;c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT<br>2009-06-10 15:02 . 2009-06-10 15:02&#9;--------&#9;d-----w-&#9;c:\documents and settings\Administrator\Application Data\Malwarebytes<br>2009-06-10 00:58 . 2009-06-10 00:58&#9;--------&#9;d-----w-&#9;c:\program files\Windows Defender<br>2009-06-09 17:08 . 2009-06-09 17:08&#9;--------&#9;d-----w-&#9;c:\documents and settings\Drader\Application Data\Malwarebytes<br>2009-06-09 17:07 . 2009-06-09 17:07&#9;--------&#9;d-----w-&#9;c:\documents and settings\All Users\Application Data\Malwarebytes<br>2009-06-08 23:10 . 2009-06-08 23:10&#9;--------&#9;d-----w-&#9;c:\documents and settings\Drader\Local Settings\Application Data\WMTools Downloaded Files<br>2009-06-04 14:22 . 2009-06-04 04:10&#9;15688&#9;----a-w-&#9;c:\windows\system32\lsdelete.exe<br>2009-06-04 04:05 . 2009-06-14 02:20&#9;--------&#9;dc-h--w-&#9;c:\documents and settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}<br>2009-06-04 04:05 . 2009-03-12 08:17&#9;2902048&#9;-c--a-w-&#9;c:\documents and settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}\Ad-AwareAE.exe<br>2009-05-27 02:28 . 2009-05-27 02:28&#9;--------&#9;d-----w-&#9;c:\program files\Musicnotes<br>2009-05-27 02:25 . 2009-06-08 23:07&#9;--------&#9;d-----w-&#9;c:\documents and settings\All Users\Application Data\Musicnotes<br>2009-05-22 02:49 . 2009-05-22 02:49&#9;--------&#9;d-----w-&#9;c:\documents and settings\Drader\Application Data\KodakCredentialStore<br><br>.<br>((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br>2009-06-14 02:49 . 2009-05-04 21:44&#9;--------&#9;d---a-w-&#9;c:\documents and settings\All Users\Application Data\TEMP<br>2009-06-14 01:59 . 2008-12-28 17:56&#9;--------&#9;d-----w-&#9;c:\documents and settings\All Users\Application Data\Google Updater<br>2009-06-12 05:57 . 2009-01-29 18:18&#9;1&#9;----a-w-&#9;c:\documents and settings\Drader\Application Data\OpenOffice.org\3\user\uno_packages\cache\stamp.sys<br>2009-06-11 02:08 . 2008-12-26 17:48&#9;--------&#9;d-----w-&#9;c:\documents and settings\Drader\Application Data\AdobeUM<br>2009-06-09 02:07 . 2008-12-24 23:23&#9;--------&#9;d-----w-&#9;c:\documents and settings\All Users\Application Data\McAfee<br>2009-06-08 23:11 . 2008-12-25 00:35&#9;--------&#9;d-----w-&#9;c:\documents and settings\LocalService\Application Data\SACore<br>2009-06-08 23:10 . 2008-12-28 17:56&#9;--------&#9;d-----w-&#9;c:\program files\Google<br>2009-06-08 23:10 . 2008-12-24 17:44&#9;--------&#9;d-----w-&#9;c:\documents and settings\Drader\Application Data\Sonic<br>2009-06-04 04:05 . 2009-01-27 23:16&#9;--------&#9;d-----w-&#9;c:\program files\Lavasoft<br>2009-06-04 04:05 . 2008-12-26 18:03&#9;--------&#9;d-----w-&#9;c:\documents and settings\All Users\Application Data\Lavasoft<br>2009-05-27 14:36 . 2008-12-24 22:54&#9;310640&#9;----a-w-&#9;c:\documents and settings\Drader\Local Settings\Application Data\GDIPFONTCACHEV1.DAT<br>2009-05-22 16:51 . 2009-03-04 04:14&#9;848&#9;--sha-w-&#9;c:\windows\system32\KGyGaAvL.sys<br>2009-05-12 01:50 . 2009-05-12 01:50&#9;--------&#9;d-----w-&#9;c:\documents and settings\Drader\Application Data\Leadertech<br>2009-05-07 15:32 . 2004-08-04 10:00&#9;345600&#9;----a-w-&#9;c:\windows\system32\localspl.dll<br>2009-05-05 02:11 . 2009-05-04 21:36&#9;--------&#9;d-----w-&#9;c:\documents and settings\All Users\Application Data\BigFishGamesCache<br>2009-05-04 21:38 . 2009-05-04 21:38&#9;--------&#9;d-----w-&#9;c:\program files\bfgclient<br>2009-05-04 17:25 . 2009-05-04 17:25&#9;--------&#9;d-----w-&#9;c:\documents and settings\Drader\Application Data\Skinux<br>2009-05-04 16:57 . 2009-05-04 16:06&#9;--------&#9;d-----w-&#9;c:\documents and settings\All Users\Application Data\Kodak<br>2009-05-04 16:52 . 2009-05-04 16:48&#9;--------&#9;d-----w-&#9;c:\program files\Common Files\Kodak<br>2009-05-04 16:31 . 2009-05-04 16:29&#9;--------&#9;d-----w-&#9;c:\program files\Kodak<br>2009-05-04 16:20 . 2009-05-04 16:20&#9;77824&#9;----a-w-&#9;c:\documents and settings\All Users\Application Data\Kodak\EasyShareSetup\ess\bindbins\bindbins.exe<br>2009-05-04 16:18 . 2009-05-04 16:13&#9;23510720&#9;----a-w-&#9;c:\documents and settings\All Users\Application Data\Kodak\EasyShareSetup\fwork\dotnetfx.exe<br>2009-05-04 16:17 . 2009-05-04 16:17&#9;30720&#9;----a-w-&#9;c:\documents and settings\All Users\Application Data\Kodak\EasyShareSetup\fwork\netfw.exe<br>2009-05-04 16:13 . 2009-05-04 16:13&#9;45056&#9;----a-w-&#9;c:\documents and settings\All Users\Application Data\Kodak\EasyShareSetup\sysfiles\kb945060\kb945060.exe<br>2009-05-04 16:08 . 2009-05-04 16:08&#9;1187840&#9;----a-w-&#9;c:\documents and settings\All Users\Application Data\Kodak\EasyShareSetup\$SETUP_140001_a031e62\EasyShrx.Dll<br>2009-05-04 16:07 . 2009-05-04 16:07&#9;114688&#9;----a-w-&#9;c:\documents and settings\All Users\Application Data\Kodak\EasyShareSetup\$Registration\KodakCameraAPI_7.9.20.1.dll<br>2009-05-04 16:07 . 2009-05-04 16:08&#9;2499984&#9;----a-w-&#9;c:\documents and settings\All Users\Application Data\Kodak\EasyShareSetup\$SETUP_140001_a031e62\Setup.exe<br>2009-05-04 16:06 . 2009-05-04 16:06&#9;114688&#9;----a-w-&#9;c:\documents and settings\All Users\Application Data\Kodak\EasyShareSetup\$Registration\KodakCameraAPI_7.2.25.1.dll<br>2009-04-29 04:46 . 2004-08-04 10:00&#9;666624&#9;----a-w-&#9;c:\windows\system32\wininet.dll<br>2009-04-29 04:46 . 2004-08-04 10:00&#9;81920&#9;----a-w-&#9;c:\windows\system32\ieencode.dll<br>2009-04-26 19:27 . 2009-04-26 06:41&#9;--------&#9;d-----w-&#9;c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy<br>2009-04-26 15:00 . 2009-04-26 06:41&#9;--------&#9;d-----w-&#9;c:\program files\Spybot - Search & Destroy<br>2009-04-17 12:26 . 2004-08-04 10:00&#9;1847168&#9;----a-w-&#9;c:\windows\system32\win32k.sys<br>2009-04-15 14:51 . 2004-08-04 10:00&#9;585216&#9;----a-w-&#9;c:\windows\system32\rpcrt4.dll<br>2009-04-13 21:54 . 2009-04-13 21:54&#9;1878984&#9;----a-w-&#9;c:\documents and settings\Drader\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\fpupdatepl\fpupdatepl.exe<br>2009-03-29 15:25 . 2004-08-10 18:13&#9;78199&#9;----a-w-&#9;c:\windows\PCHEALTH\HELPCTR\OfflineCache\index.dat<br>2009-03-19 16:56 . 2009-03-19 16:56&#9;129&#9;----a-w-&#9;c:\documents and settings\Drader\Local Settings\Application Data\fusioncache.dat<br>2009-03-19 16:51 . 2009-03-19 16:51&#9;164&#9;----a-w-&#9;c:\windows\install.dat<br>2009-03-18 00:42 . 2009-03-18 00:42&#9;503808&#9;----a-w-&#9;c:\documents and settings\Drader\Application Data\Sun\Java\Deployment\cache\6.0\38\39ba6e6-70d9f237-n\msvcp71.dll<br>2009-03-18 00:42 . 2009-03-18 00:42&#9;499712&#9;----a-w-&#9;c:\documents and settings\Drader\Application Data\Sun\Java\Deployment\cache\6.0\38\39ba6e6-70d9f237-n\jmc.dll<br>2009-03-18 00:42 . 2009-03-18 00:42&#9;348160&#9;----a-w-&#9;c:\documents and settings\Drader\Application Data\Sun\Java\Deployment\cache\6.0\38\39ba6e6-70d9f237-n\msvcr71.dll<br>2009-03-18 00:41 . 2009-02-24 19:30&#9;410984&#9;----a-w-&#9;c:\windows\system32\deploytk.dll<br>2009-03-18 00:37 . 2009-03-18 00:37&#9;152576&#9;----a-w-&#9;c:\documents and settings\Drader\Application Data\Sun\Java\jre1.6.0_12\lzma.dll<br>.<br><br>(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br>.<br>*Note* empty entries & legit default entries are not shown <br>REGEDIT4<br><br>[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]<br>2009-06-02 20:37&#9;1004800&#9;----a-w-&#9;c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll<br><br>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<br>"MSConfig"="c:\windows\PCHealth\HelpCtr\Binaries\MSConfig.exe" [2008-04-14 169984]<br>"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-18 148888]<br>"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-06-11 1948440]<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]<br>2009-06-11 00:20&#9;11952&#9;----a-w-&#9;c:\windows\SYSTEM32\avgrsstx.dll<br><br>[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]<br>@="Service"<br><br>[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]<br>@="Service"<br><br>[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^America Online 9.0 Tray Icon.lnk]<br>path=c:\documents and settings\All Users\Start Menu\Programs\Startup\America Online 9.0 Tray Icon.lnk<br>backup=c:\windows\pss\America Online 9.0 Tray Icon.lnkCommon Startup<br><br>[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk]<br>path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk<br>backup=c:\windows\pss\Kodak EasyShare software.lnkCommon Startup<br><br>[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^QuickBooks Update Agent.lnk]<br>path=c:\documents and settings\All Users\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk<br>backup=c:\windows\pss\QuickBooks Update Agent.lnkCommon Startup<br><br>[HKLM\~\startupfolder\C:^Documents and Settings^Drader^Start Menu^Programs^Startup^OpenOffice.org 3.0.lnk]<br>path=c:\documents and settings\Drader\Start Menu\Programs\Startup\OpenOffice.org 3.0.lnk<br>backup=c:\windows\pss\OpenOffice.org 3.0.lnkStartup<br><br>[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]<br>"EnableFirewall"= 0 (0x0)<br><br>[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]<br>"%windir%\\system32\\sessmgr.exe"=<br>"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=<br>"c:\\Program Files\\iTunes\\iTunes.exe"=<br>"%windir%\\Network Diagnostic\\xpnetdiag.exe"=<br>"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=<br>"c:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=<br>"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=<br>"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=<br>"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=<br><br>R0 Lbd;Lbd;c:\windows\SYSTEM32\DRIVERS\Lbd.sys [1/27/2009 4:22 PM 64160]<br>R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\SYSTEM32\DRIVERS\avgldx86.sys [6/10/2009 5:20 PM 327688]<br>R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\SYSTEM32\DRIVERS\avgtdix.sys [6/10/2009 5:20 PM 108552]<br>R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [6/10/2009 5:19 PM 908568]<br>R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [6/10/2009 5:19 PM 298776]<br>R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 7:19 PM 13592]<br>S2 gupdate1c99dc76a3bc708;Google Update Service (gupdate1c99dc76a3bc708);c:\program files\Google\Update\GoogleUpdate.exe [3/5/2009 12:20 PM 133104]<br>S3 getPlus(R) Helper;getPlus(R) Helper;c:\program files\NOS\bin\getPlus_HelperSvc.exe [1/4/2009 12:00 PM 33752]<br>S3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [3/9/2009 12:06 PM 1005904]<br>.<br>Contents of the 'Scheduled Tasks' folder<br><br>2009-06-11 c:\windows\Tasks\Ad-Aware Update (Weekly).job<br>- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-09 04:10]<br><br>2009-06-05 c:\windows\Tasks\AppleSoftwareUpdate.job<br>- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 20:34]<br><br>2009-06-14 c:\windows\Tasks\Google Software Updater.job<br>- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-12-28 21:58]<br><br>2009-06-14 c:\windows\Tasks\GoogleUpdateTaskMachine.job<br>- c:\program files\Google\Update\GoogleUpdate.exe [2009-03-05 19:19]<br><br>2009-06-14 c:\windows\Tasks\MP Scheduled Scan.job<br>- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-04 02:20]<br>.<br>- - - - ORPHANS REMOVED - - - -<br><br>HKLM-Run-goyapipemu - c:\windows\system32\viyorawi.dll<br>HKLM-Run-54712828 - c:\windows\system32\kuwokilo.dll<br><br>.<br>------- Supplementary Scan -------<br>.<br>uStart Page = hxxp://www.lds.org/<br>uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7<br>mStart Page = hxxp://www.dell4me.com/myway<br>uInternet Connection Wizard,ShellNext = iexplore<br>uInternet Settings,ProxyOverride = *.local<br>uSearchURL,(Default) = hxxp://www.google.com/search?q=%s<br>Trusted Zone: internet<br>Trusted Zone: mcafee.com<br>FF - ProfilePath - <br>.<br><br>**************************************************************************<br><br>catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, &raquo;<A HREF="http://www.gmer.net" >www.gmer.net</A><br>Rootkit scan 2009-06-13 20:34<br>Windows 5.1.2600 Service Pack 3 NTFS<br><br>scanning hidden processes ...  <br><br>scanning hidden autostart entries ... <br><br>scanning hidden files ...  <br><br>scan completed successfully<br>hidden files: 0<br><br>**************************************************************************<br>.<br>--------------------- DLLs Loaded Under Running Processes ---------------------<br><br>- - - - - - - > 'explorer.exe'(1464)<br>c:\windows\system32\WPDShServiceObj.dll<br>c:\windows\system32\PortableDeviceTypes.dll<br>c:\windows\system32\PortableDeviceApi.dll<br>.<br>------------------------ Other Running Processes ------------------------<br>.<br>c:\windows\SYSTEM32\CF21898.exe<br>c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br>c:\program files\Bonjour\mDNSResponder.exe<br>c:\program files\Java\jre6\bin\jqs.exe<br>c:\program files\Common Files\Motive\McciCMService.exe<br>c:\program files\AVG\AVG8\avgrsx.exe<br>c:\progra~1\AVG\AVG8\avgnsx.exe<br>c:\program files\AVG\AVG8\avgcsrvx.exe<br>c:\windows\SYSTEM32\wscntfy.exe<br>.<br>**************************************************************************<br>.<br>Completion time: 2009-06-14 20:38 - machine was rebooted<br>ComboFix-quarantined-files.txt  2009-06-14 03:38<br><br>Pre-Run: 23,424,643,072 bytes free<br>Post-Run: 23,421,034,496 bytes free<br><br>WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe<br>[boot loader]<br>timeout=2<br>default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS<br>[operating systems]<br>c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons<br>multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect<br><br>210&#9;--- E O F ---&#9;2009-06-13 09:19<br><br>MBAM POST SCAN<br><br>Malwarebytes' Anti-Malware 1.37<br>Database version: 2273<br>Windows 5.1.2600 Service Pack 3<br><br>6/13/2009 9:20:25 PM<br>mbam-log-2009-06-13 (21-20-25).txt<br><br>Scan type: Quick Scan<br>Objects scanned: 85940<br>Time elapsed: 4 minute(s), 24 second(s)<br><br>Memory Processes Infected: 0<br>Memory Modules Infected: 0<br>Registry Keys Infected: 0<br>Registry Values Infected: 0<br>Registry Data Items Infected: 0<br>Folders Infected: 0<br>Files Infected: 0<br><br>Memory Processes Infected:<br>(No malicious items detected)<br><br>Memory Modules Infected:<br>(No malicious items detected)<br><br>Registry Keys Infected:<br>(No malicious items detected)<br><br>Registry Values Infected:<br>(No malicious items detected)<br><br>Registry Data Items Infected:<br>(No malicious items detected)<br><br>Folders Infected:<br>(No malicious items detected)<br><br>Files Infected:<br>(No malicious items detected)<br><br>HIJACKTHIS POST SCAN<br><br>Logfile of Trend Micro HijackThis v2.0.2<br>Scan saved at 8:51:48 PM, on 6/13/2009<br>Platform: Windows XP SP3 (WinNT 5.01.2600)<br>MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)<br>Boot mode: Normal<br><br>Running processes:<br>C:\WINDOWS\System32\smss.exe<br>C:\WINDOWS\system32\winlogon.exe<br>C:\WINDOWS\system32\services.exe<br>C:\WINDOWS\system32\lsass.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\Program Files\Windows Defender\MsMpEng.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\WINDOWS\system32\spoolsv.exe<br>C:\Program Files\Google\Update\GoogleUpdate.exe<br>C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br>C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe<br>C:\Program Files\Bonjour\mDNSResponder.exe<br>C:\Program Files\Java\jre6\bin\jqs.exe<br>C:\Program Files\Common Files\Motive\McciCMService.exe<br>C:\Program Files\Java\jre6\bin\jusched.exe<br>C:\PROGRA~1\AVG\AVG8\avgtray.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\PROGRA~1\AVG\AVG8\avgrsx.exe<br>C:\PROGRA~1\AVG\AVG8\avgnsx.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\PROGRA~1\AVG\AVG8\avgemc.exe<br>C:\Program Files\AVG\AVG8\avgcsrvx.exe<br>C:\WINDOWS\system32\wscntfy.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\WINDOWS\explorer.exe<br>C:\WINDOWS\system32\notepad.exe<br>C:\Documents and Settings\Drader\Desktop\HiJackThis.exe<br><br>R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://www.lds.org/" >www.lds.org/</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=69157" >go.microsoft.com/fwlink/?LinkId=69157</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://www.dell4me.com/myway" >www.dell4me.com/myway</A><br>R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local<br>R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll<br>R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll<br>O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll<br>O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll<br>O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll<br>O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll<br>O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll<br>O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll<br>O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br>O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br>O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll<br>O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll<br>O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll<br>O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto<br>O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"<br>O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe<br>O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll<br>O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br>O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br>O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O15 - Trusted Zone: &raquo;<A HREF="http://*.mcafee.com" >*.mcafee.com</A><br>O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - &raquo;<A HREF="http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab" >upload.facebook.com/controls/200&middot;&middot;&middot;der5.cab</A><br>O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - &raquo;<A HREF="http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab" >housecall65.trendmicro.com/house&middot;&middot;&middot;Impl.cab</A><br>O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - &raquo;<A HREF="http://download.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,90/mcinsctl.cab" >download.mcafee.com/molbin/share&middot;&middot;&middot;sctl.cab</A><br>O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - &raquo;<A HREF="http://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab" >wwwimages.adobe.com/www.adobe.co&middot;&middot;&middot;s/gp.cab</A><br>O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll<br>O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll<br>O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br>O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe<br>O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe<br>O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br>O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe<br>O23 - Service: Google Update Service (gupdate1c99dc76a3bc708) (gupdate1c99dc76a3bc708) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe<br>O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br>O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br>O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br>O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe<br>O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Common Files\Motive\McciCMService.exe<br><br>--<br>End of file - 6608 bytes<br><br>MBAM PRE-SCAN (BEFORE COMBO FIX)<br><br>Malwarebytes' Anti-Malware 1.37<br>Database version: 2273<br>Windows 5.1.2600 Service Pack 3<br><br>6/13/2009 4:57:41 PM<br>mbam-log-2009-06-13 (16-57-41).txt<br><br>Scan type: Quick Scan<br>Objects scanned: 88078<br>Time elapsed: 10 minute(s), 7 second(s)<br><br>Memory Processes Infected: 0<br>Memory Modules Infected: 0<br>Registry Keys Infected: 0<br>Registry Values Infected: 2<br>Registry Data Items Infected: 0<br>Folders Infected: 0<br>Files Infected: 0<br><br>Memory Processes Infected:<br>(No malicious items detected)<br><br>Memory Modules Infected:<br>(No malicious items detected)<br><br>Registry Keys Infected:<br>(No malicious items detected)<br><br>Registry Values Infected:<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\goyapipemu (Trojan.Vundo.H) -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\54712828 (Trojan.Vundo.H) -> Quarantined and deleted successfully.<br><br>Registry Data Items Infected:<br>(No malicious items detected)<br><br>Folders Infected:<br>(No malicious items detected)<br><br>Files Infected:<br>(No malicious items detected)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22548078</guid>
<pubDate>Sun, 14 Jun 2009 00:49:05 EDT</pubDate>
</item>

<item>
<title>Re: [Vundo] cannot get rid of virtumonde/vundo trojan</title>
<link>http://www.dslreports.com/forum/remark,22548039</link>
<description><![CDATA[<A HREF="/useremail/u/1650439"><b>azraders</b></A> : There are some suggestions for cleanup at the top of the thread.  I thought they were for those people and not for me.  I'm really confused.  Can I do those suggestions then to clean up those files I am no longer using?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22548039</guid>
<pubDate>Sun, 14 Jun 2009 00:33:48 EDT</pubDate>
</item>

<item>
<title>Re: [Vundo] cannot get rid of virtumonde/vundo trojan</title>
<link>http://www.dslreports.com/forum/remark,22546295</link>
<description><![CDATA[<A HREF="/useremail/u/377471"><b>TheJoker</b></A> : Hi azraders<br><br>I suggest printing out each set of instructions and reading the entire post before proceeding. It will make following them easier. Please follow the directions in the order listed.<br><br> <blockquote><small>quote:</small><hr>With broadbands suggestion, I have tried to use previous threads to solve my problem but the threads all say: This is ONLY for the person that we are helping in the thread. So now I am afraid to do anything. Can you help?<br><br>One of the threads did ask to check for viewpoint- &raquo;Re: HJT Log: Virtumonde.prx??<br>it was indeed on my computer. I uninstalled it but could not merge the suggested file to the registery. It said, Cannot import fixreg. the specified file is not a registry script<br><hr></blockquote><br><br>That's why we say that fixes are only for the person that it was posted for. There were really two errors there, one was an error in the .reg file because the board inserted extra characters in the text when you copied it. That's why we now use quote boxes for copied text (it could have been copied properly using the "view plain" option in the code box), but that registry fix was specific to the user in that topic, and unrelated to the Viewpoint removal and should <b>not</b> be done on your system. You should delete the fix.reg file that you created.<br><br>I notice that you have Spybot's TeaTimer running.  While this is normally a wonderful tool to protect against hijackers, it can also interfere with HijackThis fixes.  So please <b>disable TeaTimer</b> by doing the following:<br>1) Run Spybot-S&D<br>2) Go to the Mode menu, and make sure "Advanced Mode" is selected<br>3) On the left hand side, choose Tools -> Resident<br>4) Uncheck "Resident TeaTimer" and OK any prompts<br><br>When everything is done and your log is clean again, you can enable it again (but leave it <b>off</b> for now).<br>If after we are completely through (that won't be after these instructions) you turn it back on, if teatimer gives you a warning afterwords that some changes were made, allow this instead of blocking it.<br><br>Please Run Malwarebytes' Anti-Malware.<br>- Click the <b>Update</b> tab.<br>- Click Check for Updates.<br>- If an update is found, it will download and install.<br>- Click the Scanner tab.<br>- Select "<b>Perform Quick Scan</b>", then click <b>Scan</b>.<br>- The scan may take some time to finish,so please be patient.<br>- When the scan is complete, click OK, then Show Results to view the results.<br>- Make sure that <b>everything is checked</b>, and click <b>Remove Selected</b>.<br>- When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Note)<br>- The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.<br>- Copy & Paste the entire report in your next reply along with a fresh HijackThis log.<br><br>Note:<br><i>If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts.<br>Click OK to either and let MBAM proceed with the disinfection process.<br>If asked to restart the computer, please do so immediately.</i><br><br>Now you need to run HijackThis and click "<b>Do a system scan only</b>." Place a check next to the following entries (if they are still there):<br><br><b>O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)<br>O4 - HKLM\..\Run: [goyapipemu] Rundll32.exe "C:\WINDOWS\system32\viyorawi.dll",s<br>O4 - HKLM\..\Run: [54712828] rundll32.exe "C:\WINDOWS\system32\kuwokilo.dll",b<br>O20 - AppInit_DLLs: C:\WINDOWS\system32\ C:\WINDOWS\system32\kawokame.dll c:\windows\system32\mimegepa.dll</b><br><br>Now close all browser and other windows except for HijackThis, and click "<b>Fix Checked</b>" to have HijackThis fix the entries you checked.<br><br>Reconfigure Windows XP to show hidden files:<br>Click Start. Open My Computer. <br>Select the Tools menu and click Folder Options. Select the View Tab. <br>Under the Hidden files and folders heading select "Show hidden files and folders". <br>Uncheck the "Hide protected operating system files (recommended)" option. <br>Uncheck the "Hide file extensions for known file types" option.<br>Click Yes to confirm. Click OK.<br><br>Using Windows Explorer, locate the following file, and delete them (if still there):<br>C:\WINDOWS\system32\<b>kuwokilo.dll</b><br>C:\WINDOWS\system32\<b>viyorawi.dll</b><br>C:\WINDOWS\system32\<b>kawokame.dll </b><br>c:\windows\system32\<b>mimegepa.dll</b><br><br>Now you need to hide the files you un-hid earlier:<br>Click Start. Open My Computer.<br>Select the Tools menu and click Folder Options. Select the View Tab. <br>Under the Hidden files and folders heading unselect "Show hidden files and folders". <br>Check the "Hide protected operating system files (recommended)" option. <br>Click Yes to confirm. Click OK.<br><br>Download <b>ComboFix&copy; by sUBs</b> from one of these locations:<br><br><textarea name="code" class="text" cols=50 rows=10>http://download.bleepingcomputer.com/sUBs/ComboFix.exe&#012;http://www.forospyware.com/sUBs/ComboFix.exe&#012;http://subs.geekstogo.com/ComboFix.exe&#012;</textarea><!--end code block--><br><b>* IMPORTANT !!! Save ComboFix.exe to your Desktop</b><br><br>Familiarize yourself with ComboFix before running it:<br>&raquo;<A HREF="http://www.bleepingcomputer.com/combofix/how-to-use-combofix" >www.bleepingcomputer.com/combofi&middot;&middot;&middot;combofix</A><br><br>- Disable your AntiVirus and any AntiSpyware programs you may be running (usually via a right click on the System Tray icon) to prevent them from interfering.<br><br>- Double click on ComboFix.exe & follow the prompts.<br><br>- As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal.  It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware. There are some difficult to remove infections that will only be fixed if you have the Recovery Console installed.<br><br>- Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.<br><br>**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.<br><br> <IMG SRC="http://img.photobucket.com/albums/v706/ried7/RcAuto1.gif"> <br><br>Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:<br><br> <IMG SRC="http://img.photobucket.com/albums/v706/ried7/whatnext.png"> <br><br>Click on Yes, to continue scanning for malware. When finished, it will save a log. <br>Please include the contents of the log at <b>C:\ComboFix.txt</b> in your next reply.<br><br>Please post a new HijackThis log, the log from MBAM, the log from ComboFix (combofix.txt), and note any errors encountered.<br><br><small>--<br>Proud ASAP member since 2005</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22546295</guid>
<pubDate>Sat, 13 Jun 2009 16:01:02 EDT</pubDate>
</item>

<item>
<title>[Vundo] cannot get rid of virtumonde/vundo trojan</title>
<link>http://www.dslreports.com/forum/remark,22545478</link>
<description><![CDATA[<A HREF="/useremail/u/1650439"><b>azraders</b></A> : I have run spybot- it shows 2 trojans- virtumonde.prx.  MBam shows  Trojan Vundo.  I have deleted them but they seem to keep rewriting to my computer.  I have downloaded all you have required: Spybot, mbam, hijack this, windows def. adaware.     Mbam and spybot are the only ones that show I have the trojans.  I have run in safemode and it will get rid of them , but they reappear with future scans.  With all of the scans, my computer runs more quickly except for the initial load up of a browser which is unusually slow. <br><br>With broadbands suggestion, I have tried to use previous threads to solve my problem but the threads all say:  This is ONLY for the person that we are helping in the thread.  So now I am afraid to do anything.  Can you help?  <br><br>One of the threads did ask to check for viewpoint- &raquo;<A HREF="/forum/remark,21761011?hilite=remove+virtumonde+prx">Re: HJT Log: Virtumonde.prx??</A><br> it was indeed on my computer.   I uninstalled it but could not merge the suggested file to the registery.  It said, Cannot import fixreg. the specified file is not a registry script .  You can only import binary  reg files from with the reg. editor.  Needless to say, i cannot merge this file.  <br><br>here are the logs:  <br><br>Spybot:<br><br>--- Search result list ---<br>Virtumonde.prx: [SBI $3F9F40D4] Autorun settings (54712828) (Registry value, nothing done)<br>  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\54712828<br><br>Virtumonde.prx: [SBI $85112C1D] Autorun settings (goyapipemu) (Registry value, nothing done)<br>  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\goyapipemu<br><br>Right Media: Tracking cookie (Internet Explorer: Drader) (Cookie, nothing done)<br>  <br><br>--- Spybot - Search & Destroy version: 1.6.2  (build: 20090126) ---<br><br>2009-01-26 blindman.exe (1.0.0.8)<br>2009-01-26 SDFiles.exe (1.6.1.7)<br>2009-01-26 SDMain.exe (1.0.0.6)<br>2009-01-26 SDUpdate.exe (1.6.0.12)<br>2009-01-26 SpybotSD.exe (1.6.2.46)<br>2009-01-26 TeaTimer.exe (1.6.4.26)<br>2009-04-25 unins000.exe (51.49.0.0)<br>2009-01-26 Update.exe (1.6.0.7)<br>2009-01-26 advcheck.dll (1.6.2.15)<br>2007-04-02 aports.dll (2.1.0.0)<br>2008-06-14 DelZip179.dll (1.79.11.1)<br>2009-01-26 SDHelper.dll (1.6.2.14)<br>2008-06-19 sqlite3.dll<br>2009-01-26 Tools.dll (2.1.6.10)<br>2009-01-16 UninsSrv.dll (1.0.0.0)<br>2009-05-19 Includes\Adware.sbi (*)<br>2009-06-02 Includes\AdwareC.sbi (*)<br>2009-01-22 Includes\Cookies.sbi (*)<br>2009-05-19 Includes\Dialer.sbi (*)<br>2009-06-02 Includes\DialerC.sbi (*)<br>2009-01-22 Includes\HeavyDuty.sbi (*)<br>2009-05-26 Includes\Hijackers.sbi (*)<br>2009-06-02 Includes\HijackersC.sbi (*)<br>2009-05-06 Includes\Keyloggers.sbi (*)<br>2009-06-02 Includes\KeyloggersC.sbi (*)<br>2004-11-29 Includes\LSP.sbi (*)<br>2009-05-12 Includes\Malware.sbi (*)<br>2009-06-02 Includes\MalwareC.sbi (*)<br>2009-03-25 Includes\PUPS.sbi (*)<br>2009-06-02 Includes\PUPSC.sbi (*)<br>2009-01-22 Includes\Revision.sbi (*)<br>2009-01-13 Includes\Security.sbi (*)<br>2009-06-02 Includes\SecurityC.sbi (*)<br>2008-06-03 Includes\Spybots.sbi (*)<br>2008-06-03 Includes\SpybotsC.sbi (*)<br>2009-04-07 Includes\Spyware.sbi (*)<br>2009-06-02 Includes\SpywareC.sbi (*)<br>2009-04-07 Includes\Tracks.uti<br>2009-06-02 Includes\Trojans.sbi (*)<br>2009-06-02 Includes\TrojansC.sbi (*)<br>2008-03-04 Plugins\Chai.dll<br>2008-03-05 Plugins\Fennel.dll<br>2008-02-26 Plugins\Mate.dll<br>2007-12-24 Plugins\TCPIPAddress.dll<br><br>--- System information ---<br>Windows XP (Build: 2600) Service Pack 3 (5.1.2600)<br> / .NETFramework / 1.1: Microsoft .NET Framework 1.1 Hotfix (KB928366)<br> / .NETFramework / 1.1: Microsoft .NET Framework 1.1 Service Pack 1 (KB867460)<br> / MSXML4SP2: Security update for MSXML4 SP2 (KB954430)<br> / Step By Step Interactive Training / SP2: Security Update for Step By Step Interactive Training (KB923723)<br> / Windows / SP1: Microsoft Internationalized Domain Names Mitigation APIs<br> / Windows / SP1: Microsoft National Language Support Downlevel APIs<br> / Windows Media Format 11 SDK: Hotfix for Windows Media Format 11 SDK (KB929399)<br> / Windows Media Player: Security Update for Windows Media Player (KB952069)<br> / Windows Media Player 10: Security Update for Windows Media Player 10 (KB936782)<br> / Windows Media Player 11: Security Update for Windows Media Player 11 (KB936782)<br> / Windows Media Player 11: Hotfix for Windows Media Player 11 (KB939683)<br> / Windows Media Player 11: Security Update for Windows Media Player 11 (KB954154)<br> / Windows Media Player 11: Critical Update for Windows Media Player 11 (KB959772)<br> / Windows XP: Security Update for Windows XP (KB923689)<br> / Windows XP: Security Update for Windows XP (KB941569)<br> / Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB938127-v2)<br> / Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB958215)<br> / Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB961260)<br> / Windows XP / SP10: Microsoft Compression Client Pack 1.0 for Windows XP<br> / Windows XP / SP3: Windows XP Service Pack 3<br> / Windows XP / SP4: Security Update for Windows XP (KB923561)<br> / Windows XP / SP4: Hotfix for Windows XP (KB932716-v2)<br> / Windows XP / SP4: Security Update for Windows XP (KB938464)<br> / Windows XP / SP4: Security Update for Windows XP (KB938464-v2)<br> / Windows XP / SP4: Hotfix for Windows XP (KB945060-v3)<br> / Windows XP / SP4: Security Update for Windows XP (KB946648)<br> / Windows XP / SP4: Security Update for Windows XP (KB950762)<br> / Windows XP / SP4: Security Update for Windows XP (KB950974)<br> / Windows XP / SP4: Security Update for Windows XP (KB951066)<br> / Windows XP / SP4: Security Update for Windows XP (KB951376-v2)<br> / Windows XP / SP4: Security Update for Windows XP (KB951698)<br> / Windows XP / SP4: Security Update for Windows XP (KB951748)<br> / Windows XP / SP4: Update for Windows XP (KB951978)<br> / Windows XP / SP4: Security Update for Windows XP (KB952004)<br> / Windows XP / SP4: Hotfix for Windows XP (KB952287)<br> / Windows XP / SP4: Security Update for Windows XP (KB952954)<br> / Windows XP / SP4: Security Update for Windows XP (KB954211)<br> / Windows XP / SP4: Security Update for Windows XP (KB954459)<br> / Windows XP / SP4: Security Update for Windows XP (KB954600)<br> / Windows XP / SP4: Security Update for Windows XP (KB955069)<br> / Windows XP / SP4: Update for Windows XP (KB955839)<br> / Windows XP / SP4: Security Update for Windows XP (KB956391)<br> / Windows XP / SP4: Security Update for Windows XP (KB956572)<br> / Windows XP / SP4: Security Update for Windows XP (KB956802)<br> / Windows XP / SP4: Security Update for Windows XP (KB956803)<br> / Windows XP / SP4: Security Update for Windows XP (KB956841)<br> / Windows XP / SP4: Security Update for Windows XP (KB957095)<br> / Windows XP / SP4: Security Update for Windows XP (KB957097)<br> / Windows XP / SP4: Security Update for Windows XP (KB958215)<br> / Windows XP / SP4: Security Update for Windows XP (KB958644)<br> / Windows XP / SP4: Security Update for Windows XP (KB958687)<br> / Windows XP / SP4: Security Update for Windows XP (KB958690)<br> / Windows XP / SP4: Security Update for Windows XP (KB959426)<br> / Windows XP / SP4: Security Update for Windows XP (KB960225)<br> / Windows XP / SP4: Security Update for Windows XP (KB960714)<br> / Windows XP / SP4: Security Update for Windows XP (KB960715)<br> / Windows XP / SP4: Security Update for Windows XP (KB960803)<br> / Windows XP / SP4: Security Update for Windows XP (KB961373)<br> / Windows XP / SP4: Security Update for Windows XP (KB961501)<br> / Windows XP / SP4: Security Update for Windows XP (KB963027)<br> / Windows XP / SP4: Update for Windows XP (KB967715)<br> / Windows XP / SP4: Security Update for Windows XP (KB968537)<br> / Windows XP / SP4: Security Update for Windows XP (KB969897)<br> / Windows XP / SP4: Security Update for Windows XP (KB969898)<br> / Windows XP / SP4: Security Update for Windows XP (KB970238)<br><br>--- Startup entries list ---<br>Located: HK_LM:Run, 54712828<br>command: rundll32.exe "C:\WINDOWS\system32\kuwokilo.dll",b<br>   file: C:\WINDOWS\system32\kuwokilo.dll<br>   size: 0<br>    MD5: D41D8CD98F00B204E9800998ECF8427E<br>         Warning: if the file is actually larger than 0 bytes,<br>         the checksum could not be properly calculated!<br><br>Located: HK_LM:Run, Ad-Watch<br>command: "C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe"<br>   file: C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe<br>   size: 518488<br>    MD5: 12761AC7AAAFDC75860F9905068056FF<br><br>Located: HK_LM:Run, AVG8_TRAY<br>command: C:\PROGRA~1\AVG\AVG8\avgtray.exe<br>   file: C:\PROGRA~1\AVG\AVG8\avgtray.exe<br>   size: 1948440<br>    MD5: 2588B441E5B22691E0610CF710865441<br><br>Located: HK_LM:Run, goyapipemu<br>command: Rundll32.exe "C:\WINDOWS\system32\viyorawi.dll",s<br>   file: C:\WINDOWS\system32\viyorawi.dll<br>   size: 0<br>    MD5: D41D8CD98F00B204E9800998ECF8427E<br>         Warning: if the file is actually larger than 0 bytes,<br>         the checksum could not be properly calculated!<br><br>Located: HK_LM:Run, MSConfig<br>command: C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto<br>   file: C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe<br>   size: 169984<br>    MD5: A81135541C9D4EBCE43EFA8AD31395B4<br><br>Located: HK_LM:Run, SunJavaUpdateSched<br>command: "C:\Program Files\Java\jre6\bin\jusched.exe"<br>   file: C:\Program Files\Java\jre6\bin\jusched.exe<br>   size: 148888<br>    MD5: 3237A58DC79C051004CD3A67C8FBC781<br><br>Located: HK_LM:Run, Windows Defender<br>command: "C:\Program Files\Windows Defender\MSASCui.exe" -hide<br>   file: C:\Program Files\Windows Defender\MSASCui.exe<br>   size: 866584<br>    MD5: 77C03BF23AE56B0A31AE4D5BB4B3D0AC<br><br>Located: HK_LM:RunOnce, Malwarebytes' Anti-Malware<br>command: "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe\mbamgui.exe" /install /silent<br>   file: C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe\mbamgui.exe<br>   size: 414480<br>    MD5: 7C5A2D12400C54E9BD97E90AEFB26C8D<br><br>Located: HK_CU:Run, SpybotSD TeaTimer<br>  where: S-1-5-21-479348682-3771094307-2254394609-1006...<br>command: "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe"<br>   file: C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe<br>   size: 2144088<br>    MD5: 896A1DB9A972AD2339C2E8569EC926D1<br><br>Located: HK_CU:Run, DellSupport<br>  where: S-1-5-21-479348682-3771094307-2254394609-500...<br>command: "C:\Program Files\Dell Support\DSAgnt.exe" /startup<br>   file: C:\Program Files\Dell Support\DSAgnt.exe<br>   size: 306688<br>    MD5: CEA4715092CB7984420DBC9F51FB4C35<br>*****<br>MBAM<br>Malwarebytes' Anti-Malware 1.37<br>Database version: 2263<br>Windows 5.1.2600 Service Pack 3<br><br>6/12/2009 8:08:22 AM<br>mbam-log-2009-06-12 (08-08-16).txt<br><br>Scan type: Quick Scan<br>Objects scanned: 87517<br>Time elapsed: 9 minute(s), 27 second(s)<br><br>Memory Processes Infected: 0<br>Memory Modules Infected: 0<br>Registry Keys Infected: 0<br>Registry Values Infected: 2<br>Registry Data Items Infected: 0<br>Folders Infected: 0<br>Files Infected: 0<br><br>Memory Processes Infected:<br>(No malicious items detected)<br><br>Memory Modules Infected:<br>(No malicious items detected)<br><br>Registry Keys Infected:<br>(No malicious items detected)<br><br>Registry Values Infected:<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\goyapipemu (Trojan.Vundo.H) -> No action taken.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\54712828 (Trojan.Vundo.H) -> No action taken.<br><br>Registry Data Items Infected:<br>(No malicious items detected)<br><br>Folders Infected:<br>(No malicious items detected)<br><br>Files Infected:<br>(No malicious items detected)<br>*****<br>Hijackthis<br><br>Logfile of Trend Micro HijackThis v2.0.2<br>Scan saved at 9:10:41 AM, on 6/13/2009<br>Platform: Windows XP SP3 (WinNT 5.01.2600)<br>MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)<br>Boot mode: Normal<br><br>Running processes:<br>C:\WINDOWS\System32\smss.exe<br>C:\WINDOWS\system32\winlogon.exe<br>C:\WINDOWS\system32\services.exe<br>C:\WINDOWS\system32\lsass.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\Program Files\Windows Defender\MsMpEng.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe<br>C:\WINDOWS\system32\spoolsv.exe<br>C:\WINDOWS\Explorer.EXE<br>C:\Program Files\Google\Update\GoogleUpdate.exe<br>C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br>C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe<br>C:\Program Files\Bonjour\mDNSResponder.exe<br>C:\Program Files\Java\jre6\bin\jqs.exe<br>C:\Program Files\Common Files\Motive\McciCMService.exe<br>C:\Program Files\Java\jre6\bin\jusched.exe<br>C:\PROGRA~1\AVG\AVG8\avgtray.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\PROGRA~1\AVG\AVG8\avgrsx.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\PROGRA~1\AVG\AVG8\avgnsx.exe<br>C:\PROGRA~1\AVG\AVG8\avgemc.exe<br>C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe<br>C:\Program Files\AVG\AVG8\avgcsrvx.exe<br>C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe<br>C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe<br>C:\Program Files\iPod\bin\iPodService.exe<br>C:\Program Files\Mozilla Firefox\firefox.exe<br>C:\Documents and Settings\Drader\Desktop\HiJackThis.exe<br><br>R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &raquo;<A HREF="http://www.dell4me.com/myway" >www.dell4me.com/myway</A><br>R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://www.lds.org/" >www.lds.org/</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &raquo;<A HREF="http://www.dell4me.com/myway" >www.dell4me.com/myway</A><br>R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://www.dell4me.com/myway" >www.dell4me.com/myway</A><br>R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local<br>R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll<br>R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll<br>O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll<br>O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll<br>O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll<br>O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br>O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll<br>O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll<br>O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll<br>O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br>O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br>O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll<br>O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)<br>O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll<br>O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll<br>O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto<br>O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"<br>O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe<br>O4 - HKLM\..\Run: [goyapipemu] Rundll32.exe "C:\WINDOWS\system32\viyorawi.dll",s<br>O4 - HKLM\..\Run: [54712828] rundll32.exe "C:\WINDOWS\system32\kuwokilo.dll",b<br>O4 - HKCU\..\Run: [SpybotSD TeaTimer] "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe"<br>O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll<br>O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br>O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br>O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br>O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br>O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O15 - Trusted Zone: &raquo;<A HREF="http://*.mcafee.com" >*.mcafee.com</A><br>O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - &raquo;<A HREF="http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab" >upload.facebook.com/controls/200&middot;&middot;&middot;der5.cab</A><br>O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - &raquo;<A HREF="http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab" >housecall65.trendmicro.com/house&middot;&middot;&middot;Impl.cab</A><br>O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - &raquo;<A HREF="http://download.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,90/mcinsctl.cab" >download.mcafee.com/molbin/share&middot;&middot;&middot;sctl.cab</A><br>O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - &raquo;<A HREF="http://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab" >wwwimages.adobe.com/www.adobe.co&middot;&middot;&middot;s/gp.cab</A><br>O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll<br>O20 - AppInit_DLLs: C:\WINDOWS\system32\ C:\WINDOWS\system32\kawokame.dll c:\windows\system32\mimegepa.dll<br>O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll<br>O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br>O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe<br>O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe<br>O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br>O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe<br>O23 - Service: Google Update Service (gupdate1c99dc76a3bc708) (gupdate1c99dc76a3bc708) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe<br>O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br>O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br>O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br>O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe<br>O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Common Files\Motive\McciCMService.exe<br><br>--<br>End of file - 7493 bytes<br><br>***<br>Previous Hi Jack this record:<br><br>Logfile of Trend Micro HijackThis v2.0.2<br>Scan saved at 8:49:32 PM, on 6/9/2009<br>Platform: Windows XP SP3 (WinNT 5.01.2600)<br>MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)<br>Boot mode: Normal<br><br>Running processes:<br>C:\WINDOWS\System32\smss.exe<br>C:\WINDOWS\system32\winlogon.exe<br>C:\WINDOWS\system32\services.exe<br>C:\WINDOWS\system32\lsass.exe<br>C:\Program Files\Webroot\WebrootSecurity\WRConsumerService.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\Program Files\Windows Defender\MsMpEng.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe<br>C:\WINDOWS\Explorer.EXE<br>C:\WINDOWS\system32\spoolsv.exe<br>C:\Program Files\Google\Update\GoogleUpdate.exe<br>C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br>C:\Program Files\Bonjour\mDNSResponder.exe<br>C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe<br>C:\Program Files\Java\jre6\bin\jqs.exe<br>C:\Program Files\Java\jre6\bin\jusched.exe<br>C:\Program Files\Webroot\WebrootSecurity\SpySweeperUI.exe<br>C:\Program Files\Common Files\Motive\McciCMService.exe<br>C:\Program Files\Windows Defender\MSASCui.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\Program Files\Webroot\WebrootSecurity\SpySweeper.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\Program Files\Mozilla Firefox\firefox.exe<br>C:\Documents and Settings\Drader\Desktop\HiJackThis.exe<br><br>R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &raquo;<A HREF="http://www.dell4me.com/myway" >www.dell4me.com/myway</A><br>R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://www.lds.org/" >www.lds.org/</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &raquo;<A HREF="http://www.dell4me.com/myway" >www.dell4me.com/myway</A><br>R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://www.dell4me.com/myway" >www.dell4me.com/myway</A><br>R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local<br>R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll<br>O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll<br>O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll<br>O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br>O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll<br>O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll<br>O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br>O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br>O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll<br>O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)<br>O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll<br>O4 - HKLM\..\Run: [MSConfig] "C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe" /auto<br>O4 - HKLM\..\Run: [Ad-Watch] "C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe"<br>O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"<br>O4 - HKLM\..\Run: [goyapipemu] "Rundll32.exe" "C:\WINDOWS\system32\viyorawi.dll",s<br>O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide<br>O4 - HKLM\..\Run: [54712828] "rundll32.exe" "C:\WINDOWS\system32\kuwokilo.dll",b<br>O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\WebrootSecurity\SpySweeperUI.exe" /startintray<br>O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll<br>O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br>O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br>O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br>O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br>O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O15 - Trusted Zone: &raquo;<A HREF="http://*.mcafee.com" >*.mcafee.com</A><br>O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - &raquo;<A HREF="http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab" >upload.facebook.com/controls/200&middot;&middot;&middot;der5.cab</A><br>O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - &raquo;<A HREF="http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab" >housecall65.trendmicro.com/house&middot;&middot;&middot;Impl.cab</A><br>O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - &raquo;<A HREF="http://download.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,90/mcinsctl.cab" >download.mcafee.com/molbin/share&middot;&middot;&middot;sctl.cab</A><br>O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - &raquo;<A HREF="http://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab" >wwwimages.adobe.com/www.adobe.co&middot;&middot;&middot;s/gp.cab</A><br>O20 - AppInit_DLLs: C:\WINDOWS\system32\ C:\WINDOWS\system32\kawokame.dll c:\windows\system32\mimegepa.dll<br>O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br>O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br>O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe<br>O23 - Service: Google Update Service (gupdate1c99dc76a3bc708) (gupdate1c99dc76a3bc708) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe<br>O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br>O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br>O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br>O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe<br>O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Common Files\Motive\McciCMService.exe<br>O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. (www.webroot.com) - C:\Program Files\Webroot\WebrootSecurity\SpySweeper.exe<br>O23 - Service: Webroot Client Service (WRConsumerService) - Webroot Software, Inc.  - C:\Program Files\Webroot\WebrootSecurity\WRConsumerService.exe<br><br>--<br>End of file - 6854 bytes<br><br>Can you help?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22545478</guid>
<pubDate>Sat, 13 Jun 2009 12:17:31 EDT</pubDate>
</item>

</channel>
</rss>
