<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>HJT Log Virtumonde in Security</title>
<link>http://www.dslreports.com/forum/r14791668</link>
<description></description>
<language>en</language>
<pubDate>Wed, 25 Nov 2009 07:37:30 EDT</pubDate>
<lastBuildDate>Wed, 25 Nov 2009 07:37:30 EDT</lastBuildDate>

<item>
<title>Re: HJT Log Virtumonde</title>
<link>http://www.dslreports.com/forum/remark,14792205</link>
<description><![CDATA[<A HREF="/useremail/u/679515"><b>CalamityJane</b></A> : Well, on the Vundo infection alone...you have already seen this thread:<br>&raquo;<A HREF="/forum/remark,14738046">Potential Vulnerability with Sun Java auto update</A><br><br>Follow the instructions in the first post about updating Sun Java and <B>remove old versions</B><br><br>Then, our general advice here I linked above:<br>&raquo;<A HREF="/faq/security">Security</A> &raquo;<A HREF="/faq/10002">How do I prevent browser hijacks and spyware?</A><br><SMALL>--<br>It takes a disaster to make a woman out of a female<BR>Microsoft MVP/Windows Security 2003-2006<BR>Proud Member of <A HREF="http://asap.maddoktor2.com/">ASAP </A> (Alliance of Security Analysis Professionals)</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14792205</guid>
<pubDate>Sat, 12 Nov 2005 20:16:59 EDT</pubDate>
</item>

<item>
<title>Re: HJT Log Virtumonde</title>
<link>http://www.dslreports.com/forum/remark,14792165</link>
<description><![CDATA[<A HREF="/useremail/u/1288776"><b>angel_ve</b></A> : Thanks a lot! I followed all the instructions, it seems that the problem is solved. I'll keep you posted.<br><br>Question, what can I advise friends and family to avoid this problem? I want to post something in my personal webpage for non tech people. Any advise??]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14792165</guid>
<pubDate>Sat, 12 Nov 2005 20:11:35 EDT</pubDate>
</item>

<item>
<title>Re: HJT Log Virtumonde</title>
<link>http://www.dslreports.com/forum/remark,14792123</link>
<description><![CDATA[<A HREF="/useremail/u/679515"><b>CalamityJane</b></A> : Well Done and good job! :)<br><br>This is OK and legitimate:   C:\WINDOWS\SYSTEM32\igfxsrvc.dll<br>........................<br>Now that your PC is clean, make sure all programs are running properly and then you'll need to reset your restore point in Windows XP.......why?<br><br>One of the best features of Windows ME or XP is the System Restore option, however if a malware infects a computer with this operating system it can be backed up in the System Restore folder.  Therefore, clearing the restore points is necessary after malware removal.<br><br>To reset your restore points, please note that you will need to log into your computer with an account which has full administrator access. You will know if the account has administrator access because you will be able to see the System Restore tab. If the tab is missing, you are logged in under a limited account. <br><br>(winXP)<br><br>1.  Turn off System Restore.<br>Go to Start > Run, click on *My Computer*.<br>Click Properties.<br>Click the System Restore tab.<br>Check Turn off System Restore.<br>Click Apply, and then click OK.<br><br>2.  Reboot.<br><br>3.  Turn ON System Restore.<br>Go to Start > Run, click on *My Computer*.<br>Click Properties.<br>Click the System Restore tab.<br>UN-Check *Turn off System Restore*.<br>Click Apply, and then click OK.<br><br>How to Turn On and Turn Off System Restore in Windows XP<br>&raquo;<A HREF="http://support.microsoft.com/default.aspx?scid=kb;en-us;310405" >support.microsoft.com/default.as&middot;&middot;&middot;s;310405</A><br><br>Next, I highly recommend you get some extra protection to prevent future infections.  Here are some things you can do and some free programs to help :).<br>&raquo;<A HREF="/faq/security">Security</A> &raquo;<A HREF="/faq/10002">How do I prevent browser hijacks and spyware?</A><br><br>I'm happy to see you have SP2 installed.  That will address numerous security issues in your Operating System and IE <br>Make sure that you keep your Operating System and IE updated with the latest Critical Security Updates from Microsoft...they usually come out once a month, on the 2nd Tuesday of each month.  This is the first step in malware prevention, as many nasties now take advantage of new exploits and if not patched, you are vulnerable!<br>Windows Update<br>&raquo;<A HREF="http://v4.windowsupdate.microsoft.com/en/default.asp" >v4.windowsupdate.microsoft.com/e&middot;&middot;&middot;ault.asp</A><br><br>And see this link for instructions on how to configure the enhanced security features in SP2:<br>&raquo;<A HREF="http://www.microsoft.com/technet/security/smallbusiness/prodtech/windowsxp/iesecxp.mspx" >www.microsoft.com/technet/securi&middot;&middot;&middot;cxp.mspx</A><br><br>I also highly recommend to get the free tool, Microsoft Baseline Security Analyzer (MBSA) from Microsoft to analyze your PC security for prevention purposes. <br><br>MBSA Version 2.0  will scan for common system misconfigurations on Windows 2000, Windows XP, and Windows Server 2003 systems.  This program will identify the system security weaknesses in your browser and operating system and provides easy instructions to correct them.  This includes any missing critical Windows security updates, system vulnerabilities and your IE Browser security settings.  Get the download here:<br>Microsoft Baseline Security Analyzer <br>&raquo;<A HREF="http://www.microsoft.com/technet/security/tools/mbsahome.mspx" >www.microsoft.com/technet/securi&middot;&middot;&middot;ome.mspx</A><br>Choose MBSAsetup-EN.msi = (English Version) or the language appropriate for you.<br><br>Microsoft also has a free Antispyware program that offers resident protection to prevent infections as well. I do recommend it as an extra layer of protection for you.<br>&raquo;<A HREF="http://www.microsoft.com/athome/security/spyware/software/default.mspx" >www.microsoft.com/athome/securit&middot;&middot;&middot;ult.mspx</A> <br><SMALL>--<br>It takes a disaster to make a woman out of a female<BR>Microsoft MVP/Windows Security 2003-2006<BR>Proud Member of <A HREF="http://asap.maddoktor2.com/">ASAP </A> (Alliance of Security Analysis Professionals)</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14792123</guid>
<pubDate>Sat, 12 Nov 2005 20:05:06 EDT</pubDate>
</item>

<item>
<title>Re: HJT Log Virtumonde</title>
<link>http://www.dslreports.com/forum/remark,14792108</link>
<description><![CDATA[<A HREF="/useremail/u/855835"><b>CajunTek</b></A> : No:<br>O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\<br><br>is fine.. Itis a library belonging to the Intel(R) Graphics Accelerator Helper <br><SMALL>--<br>Lost in Texas</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14792108</guid>
<pubDate>Sat, 12 Nov 2005 20:02:37 EDT</pubDate>
</item>

<item>
<title>Re: HJT Log Virtumonde</title>
<link>http://www.dslreports.com/forum/remark,14792095</link>
<description><![CDATA[<A HREF="/useremail/u/1288776"><b>angel_ve</b></A> : "No Viruses or other malicious software has been found!"]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14792095</guid>
<pubDate>Sat, 12 Nov 2005 19:59:36 EDT</pubDate>
</item>

<item>
<title>Re: HJT Log Virtumonde</title>
<link>http://www.dslreports.com/forum/remark,14792087</link>
<description><![CDATA[<A HREF="/useremail/u/1288776"><b>angel_ve</b></A> : Yes, I am still scanning with panda, (posting from a different box) I was wondering, <br>O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll<br><br>is no problem?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14792087</guid>
<pubDate>Sat, 12 Nov 2005 19:58:20 EDT</pubDate>
</item>

<item>
<title>Re: HJT Log Virtumonde</title>
<link>http://www.dslreports.com/forum/remark,14792019</link>
<description><![CDATA[<A HREF="/useremail/u/679515"><b>CalamityJane</b></A> : Looking good so far! :)<br><br>I assume you're still scanning with Panda.<br><br>When done with that, post the Panda log.<br><br>Then scan with HijackThis and checkmark these (now orphaned) entries and press the *fix checked* button:<br><br>O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)<br><br>O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)<br><br>O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)<br><SMALL>--<br>It takes a disaster to make a woman out of a female<BR>Microsoft MVP/Windows Security 2003-2006<BR>Proud Member of <A HREF="http://asap.maddoktor2.com/">ASAP </A> (Alliance of Security Analysis Professionals)</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14792019</guid>
<pubDate>Sat, 12 Nov 2005 19:46:06 EDT</pubDate>
</item>

<item>
<title>Re: HJT Log Virtumonde</title>
<link>http://www.dslreports.com/forum/remark,14791991</link>
<description><![CDATA[<A HREF="/useremail/u/1288776"><b>angel_ve</b></A> : VundoFix V2.15 by Atri<br>----------------------------------------------------------------------------------        ----<br> <br>Listing files contained in the vundofix folder.<br>----------------------------------------------------------------------------------        ----<br> <br>killvundo.bat<br>process.exe<br>ReadMe.txt<br>vundo.reg<br>vundofix.txt<br> <br>----------------------------------------------------------------------------------        ----<br> <br>Filepaths entered<br>----------------------------------------------------------------------------------        ----<br> <br>The filepath entered was C:\WINDOWS\system32\pmkhg.dll<br> <br>The second filepath entered was C:\WINDOWS\system32\ghkmp.*<br> <br>----------------------------------------------------------------------------------        ----<br> <br>Log from Process<br>----------------------------------------------------------------------------------        ----<br> <br><br>Killing PID 148 'smss.exe'<br><br>Killing PID 732 'explorer.exe'<br>Killing PID 732 'explorer.exe'<br><br>Killing PID 228 'winlogon.exe'<br>----------------------------------------------------------------------------------        ----<br> <br>C:\WINDOWS\system32\pmkhg.dll Deleted sucessfully.<br>C:\WINDOWS\system32\ghkmp.* Deleted sucessfully.<br> <br>Fixing Registry<br>----------------------------------------------------------------------------------        ----<br> ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14791991</guid>
<pubDate>Sat, 12 Nov 2005 19:40:45 EDT</pubDate>
</item>

<item>
<title>Re: HJT Log Virtumonde</title>
<link>http://www.dslreports.com/forum/remark,14791985</link>
<description><![CDATA[<A HREF="/useremail/u/1288776"><b>angel_ve</b></A> : Logfile of HijackThis v1.99.1<br>Scan saved at 7:28:04 PM, on 11/12/2005<br>Platform: Windows XP SP2 (WinNT 5.01.2600)<br>MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)<br><br>Running processes:<br>C:\WINDOWS\system32\services.exe<br>C:\WINDOWS\system32\lsass.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\WINDOWS\system32\cmd.exe<br>C:\Documents and Settings\Owner\Desktop\hijackthis.exe<br><br>R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &raquo;<A HREF="http://us6.hpwis.com/" >us6.hpwis.com/</A><br>R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &raquo;<A HREF="http://srch-us6.hpwis.com/" >srch-us6.hpwis.com/</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &raquo;<A HREF="http://us6.hpwis.com/" >us6.hpwis.com/</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &raquo;<A HREF="http://srch-us6.hpwis.com/" >srch-us6.hpwis.com/</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = &raquo;<A HREF="http://srch-us6.hpwis.com/" >srch-us6.hpwis.com/</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &raquo;<A HREF="http://srch-us6.hpwis.com/" >srch-us6.hpwis.com/</A><br>R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://us6.hpwis.com/" >us6.hpwis.com/</A><br>R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = &raquo;<A HREF="http://srch-us6.hpwis.com/" >srch-us6.hpwis.com/</A><br>R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost<br>O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)<br>O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)<br>O2 - BHO: Google Desktop Search Capture - {7c1ce531-09e9-4fc5-9803-1c2956615786} - C:\Program Files\Google\Google Desktop Search\GoogleDesktopIE.dll<br>O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll<br>O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton AntiVirus\NavShExt.dll (file missing)<br>O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)<br>O3 - Toolbar: hp toolkit - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\HP\EXPLOREBAR\HPTOOLKT.DLL<br>O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll<br>O3 - Toolbar: A9 &Toolbar - {200488FD-C76C-47cd-BDE5-FC2571261B63} - C:\Program Files\A9\A9Toolbar2.dll<br>O3 - Toolbar: A9 &Diary - {5FE96BC0-E89F-409d-9B68-6D3693E1BA83} - C:\Program Files\A9\A9Toolbar2.dll<br>O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe<br>O4 - HKLM\..\Run: [CamMonitor] c:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe<br>O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE<br>O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE<br>O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe<br>O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe<br>O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup<br>O4 - HKLM\..\Run: [nwiz] nwiz.exe /install<br>O4 - HKLM\..\Run: [WinFast Schedule] C:\Program Files\WinFast\WFTVFM\WFWIZ.exe<br>O4 - HKLM\..\Run: [LWBMOUSE] C:\PROGRA~1\APWARE~1\V2.16\SYS43MOU.EXE<br>O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe<br>O4 - HKLM\..\Run: [Iomega Drive Icons] C:\Program Files\Iomega\DriveIcons\ImgIcon.exe<br>O4 - HKLM\..\Run: [Deskup] C:\Program Files\Iomega\DriveIcons\deskup.exe /IMGSTART<br>O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe<br>O4 - HKLM\..\Run: [Gene USB Monitor] C:\WINDOWS\system32\UMonit2K.exe<br>O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"<br>O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE<br>O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP<br>O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1104944703\ee\AOLHostManager.exe<br>O4 - HKLM\..\Run: [KK Loader] C:\WINDOWS\system32\loadkk.exe<br>O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime<br>O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"<br>O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup<br>O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto<br>O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br>O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\ypager.exe" -quiet<br>O4 - Startup: Konfabulator.lnk = C:\Program Files\Pixoria\Konfabulator\Konfabulator.exe<br>O4 - Global Startup: Loadout Manager.lnk = C:\Program Files\Belkin\Nostromo\nost_LM.exe<br>O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML<br>O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar3.dll/cmsearch.html<br>O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar3.dll/cmwordtrans.html<br>O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar3.dll/cmbacklinks.html<br>O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar3.dll/cmcache.html<br>O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000<br>O8 - Extra context menu item: Search the web with &A9.com - res://C:\Program Files\A9\A9Toolbar2.dll/SCONTEXT.HTML<br>O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar3.dll/cmsimilar.html<br>O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar3.dll/cmtrans.html<br>O9 - Extra button: ATI TV - {44226DFF-747E-4edc-B30C-78752E50CD0C} - C:\Program Files\ATI Multimedia\TV\EXPLBAR.DLL<br>O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll<br>O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll<br>O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL<br>O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe<br>O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll<br>O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - &raquo;<A HREF="http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB" >www.pcpitstop.com/pcpitstop/PCPitStop.CAB</A><br>O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage) - &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=39204&clcid=0x409" >go.microsoft.com/fwlink/?LinkId=&middot;&middot;&middot;id=0x409</A><br>O16 - DPF: {230C3D02-DA27-11D2-8612-00A0C93EEA3C} (SAXFile FileUpload ActiveX Control) - &raquo;<A HREF="http://www.winkflash.com/photo/loaders/SAXFile.cab" >www.winkflash.com/photo/loaders/SAXFile.cab</A><br>O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - &raquo;<A HREF="http://a1408.g.akamai.net/7/1408/9955/20031218/akamai.info.apple.com/iTunes4/WW/win/019-0123.20031218.zes4d/iTunesSetup.exe" >a1408.g.akamai.net/7/1408/9955/2&middot;&middot;&middot;etup.exe</A><br>O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) - &raquo;<A HREF="http://aolcc.aol.com/computercheckup/qdiagcc.cab" >aolcc.aol.com/computercheckup/qdiagcc.cab</A><br>O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - &raquo;<A HREF="http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab" >a840.g.akamai.net/7/840/537/2004&middot;&middot;&middot;an53.cab</A><br>O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - &raquo;<A HREF="http://web1.shutterfly.com/downloads/Uploader.cab" >web1.shutterfly.com/downloads/Uploader.cab</A><br>O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - &raquo;<A HREF="http://www.pandasoftware.com/activescan/as5/asinst.cab" >www.pandasoftware.com/activescan&middot;&middot;&middot;inst.cab</A><br>O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - &raquo;<A HREF="http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab" >messenger.msn.com/download/MsnMe&middot;&middot;&middot;ader.cab</A><br>O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - &raquo;<A HREF="http://by9fd.bay9.hotmail.msn.com/activex/HMAtchmt.ocx" >by9fd.bay9.hotmail.msn.com/activ&middot;&middot;&middot;chmt.ocx</A><br>O16 - DPF: {F229AB32-7BF9-4225-B78F-B4680AE6FC23} (Snapfish File Upload ActiveX Control) - &raquo;<A HREF="http://www.snapfish.com/SnapfishUpload.cab" >www.snapfish.com/SnapfishUpload.cab</A><br>O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll<br>O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe<br>O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe<br>O23 - Service: Gear Security Service (GEARSecurity) - GEAR Software - C:\WINDOWS\system32\gearsec.exe<br>O23 - Service: Imapi Helper - Alex Feinman - C:\Program Files\Alex Feinman\ISO Recorder\ImapiHelper.exe<br>O23 - Service: Iomega App Services - Iomega Corporation - C:\PROGRA~1\Iomega\System32\AppServices.exe<br>O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe<br>O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe<br>O23 - Service: X10 Device Network Service (x10nets) - Unknown owner - C:\PROGRA~1\ATIMUL~1\RemCtrl\x10nets.exe (file missing)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14791985</guid>
<pubDate>Sat, 12 Nov 2005 19:39:58 EDT</pubDate>
</item>

<item>
<title>Re: HJT Log Virtumonde</title>
<link>http://www.dslreports.com/forum/remark,14791824</link>
<description><![CDATA[<A HREF="/useremail/u/679515"><b>CalamityJane</b></A> : Make a copy of these instructions so that you have them handy as the next steps require you to be in safe mode and offline.<br><br>1.  Please download VundoFix by Atribune from here:<br><br>www.atribune.org/downloads/VundoFix.exe<br><br>Save it to your desktop <br>Double-click <B>VundoFix.exe</B> to extract the files<br>This will create a folder named VundoFix on your desktop.<br><br>2.  After the files are extracted, please reboot your computer into <B>Safe Mode</B>. You can do this by restarting your computer and continually tapping the F8 key until a menu appears. Use your up arrow key to highlight Safe Mode then hit enter.<br><br>3.  Once in safe mode open the <B>VundoFix</B> folder and doubleclick on <B>KillVundo.bat</B><br><br>4.  You will first be presented with a warning.<br>It should look like this<br> <BLOCKQUOTE><SMALL>quote:</SMALL><HR>VundoFix V2.15 by Atri<br>By using VundoFix you agree that you are doing so at your own risk.<br>Press enter to continue....<br><HR></BLOCKQUOTE><br><br>5.  At this point press enter one time.<br>Next you will see:<br> <BLOCKQUOTE><SMALL>quote:</SMALL><HR>Please Type in the filepath as instructed by the forum staff<br>and then press enter:<HR></BLOCKQUOTE><br>At this point please copy and paste in the following file path (make sure to enter it exactly as below!):<br><br><B> C:\WINDOWS\system32\pmkhg.dll</B><br><br>6.  Press *Enter*to continue with the fix.<br><br>7.  Next you will see:<br> <BLOCKQUOTE><SMALL>quote:</SMALL><HR>Please type in the second file path as instructed by the forum<br>staff then press enter: <HR></BLOCKQUOTE><br>At this point please copy and paste in the following file path (make sure to enter it exactly as below!):<br><br><B>C:\WINDOWS\system32\ghkmp.* </B><br><br>8.  Press *Enter* to continue with the fix.<br>The fix will run then HijackThis will open, if it does not open automatically please open it manually.<br><br>9.  Scan with HijackThis, and place a checkmark next to the following items and click *FIX CHECKED* button<br><br><B> O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)<br><br>O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)<br><br>O2 - BHO: MSEvents Object - {B313D637-F405-4052-AC37-E2119AB3C8F8} &#150; <br>C:\WINDOWS\system32\pmkhg.dll<br><br>O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE<br><br>O20 - Winlogon Notify: pmkhg - C:\WINDOWS\system32\pmkhg.dll</B><br><br>After you have fixed these items, close Hijackthis.<br><br>10.  Press enter to exit the program then manually reboot your computer.<br><br>11.  Once your machine reboots please Scan once more with HijackThis and post a fresh HJTlog.<br>and the <B>vundofix.txt</B> file from the vundofix folder into this topic<br><br>12.  Go to Panda ActiveScan and do a complete system scan (use IE and enable ActiveX)<br><br>Panda's Active Scan<br>&raquo;<A HREF="http://www.pandasoftware.com/products/activescan.htm" >www.pandasoftware.com/products/a&middot;&middot;&middot;scan.htm</A><br><br>Do a full system scan and save the report at the end and copy it back here as well<br><SMALL>--<br>It takes a disaster to make a woman out of a female<BR>Microsoft MVP/Windows Security 2003-2006<BR>Proud Member of <A HREF="http://asap.maddoktor2.com/">ASAP </A> (Alliance of Security Analysis Professionals)</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14791824</guid>
<pubDate>Sat, 12 Nov 2005 19:12:52 EDT</pubDate>
</item>

<item>
<title>Re: HJT Log Virtumonde</title>
<link>http://www.dslreports.com/forum/remark,14791755</link>
<description><![CDATA[<A HREF="/useremail/u/679515"><b>CalamityJane</b></A> : We can fix this one.  You have the version that the Symantec tool doesn't find.  It will take a few minutes to write up the steps.  I'll be back in a few :)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14791755</guid>
<pubDate>Sat, 12 Nov 2005 18:58:24 EDT</pubDate>
</item>

<item>
<title>HJT Log Virtumonde</title>
<link>http://www.dslreports.com/forum/remark,14791668</link>
<description><![CDATA[<A HREF="/useremail/u/1288776"><b>angel_ve</b></A> : I have run adaware, spybot, Microsoft antivirus, FixVundo (from Symantec) unistaled old versions of java, deleted temporary internet files, NOTHING WORKS. I believe that I practice safe computing How come this is not in the NEWS!?!?!?! this is really bad nothing seems to solve it I have spend two days working on it> basically I believe that the easiest way is to reinstal everything in the computer!! Anyway just because I believe tht this may be helpful to other victims I'll try to fix it thr hard way.<br>Question, If I do a backup of my files is there a chance I will be doing a backup of the infected one as as well ? I backup everything under daocuments settings and in my desktop<br><br>Here is the log from HJT:<br><br>Logfile of HijackThis v1.99.1<br>Scan saved at 6:31:23 PM, on 11/12/2005<br>Platform: Windows XP SP2 (WinNT 5.01.2600)<br>MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)<br><br>Running processes:<br>C:\WINDOWS\System32\smss.exe<br>C:\WINDOWS\system32\winlogon.exe<br>C:\WINDOWS\system32\services.exe<br>C:\WINDOWS\system32\lsass.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\WINDOWS\system32\spoolsv.exe<br>C:\WINDOWS\Explorer.EXE<br>C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe<br>C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe<br>C:\WINDOWS\system32\gearsec.exe<br>C:\PROGRA~1\Iomega\System32\AppServices.exe<br>C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe<br>C:\WINDOWS\System32\nvsvc32.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\WINDOWS\system32\fxssvc.exe<br>C:\windows\system\hpsysdrv.exe<br>C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe<br>C:\HP\KBD\KBD.EXE<br>C:\Program Files\WinFast\WFTVFM\WFWIZ.exe<br>C:\PROGRA~1\APWARE~1\V2.16\SYS43MOU.EXE<br>C:\Program Files\Iomega\DriveIcons\ImgIcon.exe<br>C:\WINDOWS\system32\UMonit2K.exe<br>C:\Program Files\Microsoft IntelliPoint\point32.exe<br>C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe<br>C:\WINDOWS\system32\loadkk.exe<br>C:\Program Files\Common Files\AOL\1104944703\ee\AOLHostManager.exe<br>C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe<br>C:\Program Files\Common Files\AOL\1104944703\ee\AOLServiceHost.exe<br>C:\WINDOWS\system32\ctfmon.exe<br>C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe<br>C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe<br>C:\Program Files\Belkin\Nostromo\nost_LM.exe<br>C:\Program Files\Pixoria\Konfabulator\Konfabulator.exe<br>C:\Program Files\Google\Google Desktop Search\GoogleDesktopDisplay.exe<br>C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.exe<br>C:\Program Files\Pixoria\Konfabulator\Konfabulator.exe<br>C:\Program Files\Pixoria\Konfabulator\Konfabulator.exe<br>C:\Program Files\Pixoria\Konfabulator\Konfabulator.exe<br>C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe<br>C:\WINDOWS\system32\wuauclt.exe<br>C:\Documents and Settings\Owner\Desktop\HijackThis.exe<br><br>R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &raquo;<A HREF="http://us6.hpwis.com/" >us6.hpwis.com/</A><br>R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &raquo;<A HREF="http://srch-us6.hpwis.com/" >srch-us6.hpwis.com/</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &raquo;<A HREF="http://us6.hpwis.com/" >us6.hpwis.com/</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &raquo;<A HREF="http://srch-us6.hpwis.com/" >srch-us6.hpwis.com/</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = &raquo;<A HREF="http://srch-us6.hpwis.com/" >srch-us6.hpwis.com/</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &raquo;<A HREF="http://srch-us6.hpwis.com/" >srch-us6.hpwis.com/</A><br>R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://us6.hpwis.com/" >us6.hpwis.com/</A><br>R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = &raquo;<A HREF="http://srch-us6.hpwis.com/" >srch-us6.hpwis.com/</A><br>R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost<br>O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)<br>O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)<br>O2 - BHO: Google Desktop Search Capture - {7c1ce531-09e9-4fc5-9803-1c2956615786} - C:\Program Files\Google\Google Desktop Search\GoogleDesktopIE.dll<br>O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll<br>O2 - BHO: MSEvents Object - {B313D637-F405-4052-AC37-E2119AB3C8F8} - C:\WINDOWS\system32\pmkhg.dll<br>O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton AntiVirus\NavShExt.dll (file missing)<br>O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)<br>O3 - Toolbar: hp toolkit - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\HP\EXPLOREBAR\HPTOOLKT.DLL<br>O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll<br>O3 - Toolbar: A9 &Toolbar - {200488FD-C76C-47cd-BDE5-FC2571261B63} - C:\Program Files\A9\A9Toolbar2.dll<br>O3 - Toolbar: A9 &Diary - {5FE96BC0-E89F-409d-9B68-6D3693E1BA83} - C:\Program Files\A9\A9Toolbar2.dll<br>O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe<br>O4 - HKLM\..\Run: [CamMonitor] c:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe<br>O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE<br>O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE<br>O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe<br>O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe<br>O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup<br>O4 - HKLM\..\Run: [nwiz] nwiz.exe /install<br>O4 - HKLM\..\Run: [WinFast Schedule] C:\Program Files\WinFast\WFTVFM\WFWIZ.exe<br>O4 - HKLM\..\Run: [LWBMOUSE] C:\PROGRA~1\APWARE~1\V2.16\SYS43MOU.EXE<br>O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe<br>O4 - HKLM\..\Run: [Iomega Drive Icons] C:\Program Files\Iomega\DriveIcons\ImgIcon.exe<br>O4 - HKLM\..\Run: [Deskup] C:\Program Files\Iomega\DriveIcons\deskup.exe /IMGSTART<br>O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe<br>O4 - HKLM\..\Run: [Gene USB Monitor] C:\WINDOWS\system32\UMonit2K.exe<br>O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"<br>O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE<br>O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP<br>O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1104944703\ee\AOLHostManager.exe<br>O4 - HKLM\..\Run: [KK Loader] C:\WINDOWS\system32\loadkk.exe<br>O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime<br>O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"<br>O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup<br>O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto<br>O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br>O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\ypager.exe" -quiet<br>O4 - Startup: Konfabulator.lnk = C:\Program Files\Pixoria\Konfabulator\Konfabulator.exe<br>O4 - Global Startup: Loadout Manager.lnk = C:\Program Files\Belkin\Nostromo\nost_LM.exe<br>O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML<br>O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar3.dll/cmsearch.html<br>O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar3.dll/cmwordtrans.html<br>O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar3.dll/cmbacklinks.html<br>O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar3.dll/cmcache.html<br>O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000<br>O8 - Extra context menu item: Search the web with &A9.com - res://C:\Program Files\A9\A9Toolbar2.dll/SCONTEXT.HTML<br>O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar3.dll/cmsimilar.html<br>O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar3.dll/cmtrans.html<br>O9 - Extra button: ATI TV - {44226DFF-747E-4edc-B30C-78752E50CD0C} - C:\Program Files\ATI Multimedia\TV\EXPLBAR.DLL<br>O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll<br>O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll<br>O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL<br>O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe<br>O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll<br>O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - &raquo;<A HREF="http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB" >www.pcpitstop.com/pcpitstop/PCPitStop.CAB</A><br>O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage) - &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=39204&clcid=0x409" >go.microsoft.com/fwlink/?LinkId=&middot;&middot;&middot;id=0x409</A><br>O16 - DPF: {230C3D02-DA27-11D2-8612-00A0C93EEA3C} (SAXFile FileUpload ActiveX Control) - &raquo;<A HREF="http://www.winkflash.com/photo/loaders/SAXFile.cab" >www.winkflash.com/photo/loaders/SAXFile.cab</A><br>O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - &raquo;<A HREF="http://a1408.g.akamai.net/7/1408/9955/20031218/akamai.info.apple.com/iTunes4/WW/win/019-0123.20031218.zes4d/iTunesSetup.exe" >a1408.g.akamai.net/7/1408/9955/2&middot;&middot;&middot;etup.exe</A><br>O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) - &raquo;<A HREF="http://aolcc.aol.com/computercheckup/qdiagcc.cab" >aolcc.aol.com/computercheckup/qdiagcc.cab</A><br>O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - &raquo;<A HREF="http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab" >a840.g.akamai.net/7/840/537/2004&middot;&middot;&middot;an53.cab</A><br>O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - &raquo;<A HREF="http://web1.shutterfly.com/downloads/Uploader.cab" >web1.shutterfly.com/downloads/Uploader.cab</A><br>O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - &raquo;<A HREF="http://www.pandasoftware.com/activescan/as5/asinst.cab" >www.pandasoftware.com/activescan&middot;&middot;&middot;inst.cab</A><br>O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - &raquo;<A HREF="http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab" >messenger.msn.com/download/MsnMe&middot;&middot;&middot;ader.cab</A><br>O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - &raquo;<A HREF="http://by9fd.bay9.hotmail.msn.com/activex/HMAtchmt.ocx" >by9fd.bay9.hotmail.msn.com/activ&middot;&middot;&middot;chmt.ocx</A><br>O16 - DPF: {F229AB32-7BF9-4225-B78F-B4680AE6FC23} (Snapfish File Upload ActiveX Control) - &raquo;<A HREF="http://www.snapfish.com/SnapfishUpload.cab" >www.snapfish.com/SnapfishUpload.cab</A><br>O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll<br>O20 - Winlogon Notify: pmkhg - C:\WINDOWS\system32\pmkhg.dll<br>O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe<br>O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe<br>O23 - Service: Gear Security Service (GEARSecurity) - GEAR Software - C:\WINDOWS\system32\gearsec.exe<br>O23 - Service: Imapi Helper - Alex Feinman - C:\Program Files\Alex Feinman\ISO Recorder\ImapiHelper.exe<br>O23 - Service: Iomega App Services - Iomega Corporation - C:\PROGRA~1\Iomega\System32\AppServices.exe<br>O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe<br>O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe<br>O23 - Service: X10 Device Network Service (x10nets) - Unknown owner - C:\PROGRA~1\ATIMUL~1\RemCtrl\x10nets.exe (file missing)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14791668</guid>
<pubDate>Sat, 12 Nov 2005 18:44:51 EDT</pubDate>
</item>

</channel>
</rss>
