<?xml version="1.0" encoding="ISO-8859-1"?>

<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/">
	<channel>
		<title>Safer-Networking Forums</title>
		<link>http://forums.spybot.info/</link>
		<description><![CDATA[Support forums for Spybot-S&amp;D and other products by Safer-Networking Limited]]></description>
		<language>en</language>
		<lastBuildDate>Wed, 16 May 2012 14:53:51 GMT</lastBuildDate>
		<generator>vBulletin</generator>
		<ttl>60</ttl>
		<image>
			<url>http://forums.spybot.info/images/misc/rss.jpg</url>
			<title>Safer-Networking Forums</title>
			<link>http://forums.spybot.info/</link>
		</image>
		<item>
			<title>Manual Removal Guide for Win32.Yakes.adkv</title>
			<link>http://forums.spybot.info/showthread.php?t=65924&amp;goto=newpost</link>
			<pubDate>Wed, 16 May 2012 10:37:56 GMT</pubDate>
			<description><![CDATA[The following instructions have been created to help you to get rid of "Win32.Yakes.adkv" manually. 
Use this guide at your own risk; software should...]]></description>
			<content:encoded><![CDATA[<div>The following instructions have been created to help you to get rid of <i>&quot;Win32.Yakes.adkv&quot;</i> manually.<br />
Use this guide at your own risk; software <i>should</i> usually be better suited to remove malware, since it is able to look deeper.<br />
<br />
If this guide was helpful to you, please consider <a href="http://www.safer-networking.org/index.php?page=donate" target="_blank">donating towards this site</a>.<br />
<br />
<font size="5"><b><font color="Navy">Threat Details:</font></b></font><br />
<br />
<b>Categories:</b><ul><li>trojan</li>
</ul><b>Description:</b><blockquote>Win32.Yakes.adkv copies malicious files into the program directory, starts itself in autorun and connects to the Internet in background without giving the user a possibility to cancel that process.</blockquote><font size="5"><b><font color="Navy">Removal Instructions:</font></b></font><br />
<br />
<font size="3"><b><font color="Navy">Autorun:</font></b></font><br />
<br />
<b>Important:</b> There are more autorun entries that cannot be safely described in simple words. Please use <a href="http://www.safer-networking.org/index.php?page=spybotsd" target="_blank">Spybot-S&amp;D</a> to remove them.<br />
<br />
<font size="3"><b><font color="Navy">Files:</font></b></font><br />
<br />
<b>Important:</b> There are more files that cannot be safely described in simple words. Please use <a href="http://www.safer-networking.org/index.php?page=spybotsd" target="_blank">Spybot-S&amp;D</a> to remove them.<br />
<br />
<font size="3"><b><font color="Navy">Folders:</font></b></font><br />
<br />
Please use Windows Explorer or another file manager of your choice to locate and delete these folders.<ul><li>The directory at <i>&quot;&lt;$APPDATA&gt;\&lt;$ENV(Win32Yakes_Dir)&gt;&quot;</i>.</li>
</ul>Make sure you set your file manager to display hidden and system files. If Win32.Yakes.adkv uses rootkit technologies, use our <a href="http://forums.spybot.info/downloads.php?id=8" target="_blank">RootAlyzer</a> or our <a href="http://forums.spybot.info/downloads.php?id=3" target="_blank">Total Commander anti-rootkit plugins</a>.<br />
You will have to use a global search for files without a name specified. <b>Be extra careful</b>, because just the name might not be enough to identify folders!<br />
<br />
<font size="3"><b><font color="Navy">Registry:</font></b></font><br />
<br />
You can use <i>regedit.exe</i> (included in Windows) to locate and delete these registry entries.<ul><li>Delete the registry key <i>&quot;Yqyt&quot;</i> at <i>&quot;HKEY_CURRENT_USER\Software\Microsoft\&quot;</i>.</li>
<li>Delete the registry value <i>&quot;12033:TCP&quot;</i> at <i>&quot;HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List\&quot;</i>.</li>
<li>Delete the registry value <i>&quot;12033:TCP&quot;</i> at <i>&quot;HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List\&quot;</i>.</li>
<li>Delete the registry value <i>&quot;12033:TCP&quot;</i> at <i>&quot;HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List\&quot;</i>.</li>
<li>Delete the registry value <i>&quot;26693:UDP&quot;</i> at <i>&quot;HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List\&quot;</i>.</li>
<li>Delete the registry value <i>&quot;26693:UDP&quot;</i> at <i>&quot;HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List\&quot;</i>.</li>
<li>Delete the registry value <i>&quot;26693:UDP&quot;</i> at <i>&quot;HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List\&quot;</i>.</li>
</ul>If Win32.Yakes.adkv uses rootkit technologies, use our <a href="http://www.safer-networking.org/index.php?page=regalyzer" target="_blank">RegAlyzer</a>, <a href="http://forums.spybot.info/downloads.php?id=8" target="_blank">RootAlyzer</a> or our <a href="http://forums.spybot.info/downloads.php?id=3" target="_blank">Total Commander anti-rootkit plugins</a>.<br />
<br />
<font size="5"><b><font color="Navy">Final Words:</font></b></font><br />
<br />
If neither Spybot-S&amp;D nor self help did resolve the issue or you would prefer one on one help,<ol style="list-style-type: decimal"><li><a href="http://forums.spybot.info/showthread.php?t=288" target="_blank">Please read these instructions</a> <b>before</b> requesting assistance,</li>
<li>Then start your own thread in the <a href="http://forums.spybot.info/forumdisplay.php?f=22" target="_blank">Malware Removal Forum</a> where a volunteer analyst will advise you as soon as available.</li>
</ol><br />
There are more files or system entries belonging to this product that &lt;$SPYBOTSD&gt; can remove, but that cannot be easily described in text. Please use &lt;$SPYBOTSD&gt; to make sure &lt;$PRODUCTNAME&gt; gets completely removed.</div>

]]></content:encoded>
			<category domain="http://forums.spybot.info/forumdisplay.php?f=54">Malware Removal Guides</category>
			<dc:creator>Friday</dc:creator>
			<guid isPermaLink="true">http://forums.spybot.info/showthread.php?t=65924</guid>
		</item>
		<item>
			<title>Manual Removal Guide for Win32.OnLineGames.gen</title>
			<link>http://forums.spybot.info/showthread.php?t=65923&amp;goto=newpost</link>
			<pubDate>Wed, 16 May 2012 10:37:55 GMT</pubDate>
			<description><![CDATA[The following instructions have been created to help you to get rid of "Win32.OnLineGames.gen" manually. 
Use this guide at your own risk; software...]]></description>
			<content:encoded><![CDATA[<div>The following instructions have been created to help you to get rid of <i>&quot;Win32.OnLineGames.gen&quot;</i> manually.<br />
Use this guide at your own risk; software <i>should</i> usually be better suited to remove malware, since it is able to look deeper.<br />
<br />
If this guide was helpful to you, please consider <a href="http://www.safer-networking.org/index.php?page=donate" target="_blank">donating towards this site</a>.<br />
<br />
<font size="5"><b><font color="Navy">Threat Details:</font></b></font><br />
<br />
<b>Categories:</b><ul><li>trojan</li>
<li>passwordstealer</li>
</ul><b>Description:</b><blockquote>Win32.OnLineGames.gen tries to steal passwords for online games. The library files get injected into running processes in order to avoid detection and to be executed by system files.</blockquote><font size="5"><b><font color="Navy">Removal Instructions:</font></b></font><br />
<br />
<font size="3"><b><font color="Navy">Files:</font></b></font><br />
<br />
<b>Important:</b> There are more files that cannot be safely described in simple words. Please use <a href="http://www.safer-networking.org/index.php?page=spybotsd" target="_blank">Spybot-S&amp;D</a> to remove them.<br />
<br />
<font size="3"><b><font color="Navy">Registry:</font></b></font><br />
<br />
You can use <i>regedit.exe</i> (included in Windows) to locate and delete these registry entries.<ul><li>Delete the registry value <i>&quot;&lt;$ENV(OLG1)&gt;.dll&quot;</i> at <i>&quot;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\&quot;</i>.</li>
<li>Delete the registry value <i>&quot;&lt;$ENV(OLG1)&gt;&quot;</i> at <i>&quot;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\&quot;</i>.</li>
<li>Remove <i>&quot;&lt;$ENV(OLG1)&gt;.dll&quot;</i> from registry value <i>&quot;AppInit_DLLs&quot;</i> at <i>&quot;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\&quot;</i>.</li>
</ul>If Win32.OnLineGames.gen uses rootkit technologies, use our <a href="http://www.safer-networking.org/index.php?page=regalyzer" target="_blank">RegAlyzer</a>, <a href="http://forums.spybot.info/downloads.php?id=8" target="_blank">RootAlyzer</a> or our <a href="http://forums.spybot.info/downloads.php?id=3" target="_blank">Total Commander anti-rootkit plugins</a>.<br />
<br />
There are more registry entries that cannot be safely described in simple words. Please use <a href="http://www.safer-networking.org/index.php?page=spybotsd" target="_blank">Spybot-S&amp;D</a> to remove them.<br />
<br />
<font size="5"><b><font color="Navy">Final Words:</font></b></font><br />
<br />
If neither Spybot-S&amp;D nor self help did resolve the issue or you would prefer one on one help,<ol style="list-style-type: decimal"><li><a href="http://forums.spybot.info/showthread.php?t=288" target="_blank">Please read these instructions</a> <b>before</b> requesting assistance,</li>
<li>Then start your own thread in the <a href="http://forums.spybot.info/forumdisplay.php?f=22" target="_blank">Malware Removal Forum</a> where a volunteer analyst will advise you as soon as available.</li>
</ol><br />
There are more files or system entries belonging to this product that &lt;$SPYBOTSD&gt; can remove, but that cannot be easily described in text. Please use &lt;$SPYBOTSD&gt; to make sure &lt;$PRODUCTNAME&gt; gets completely removed.</div>

]]></content:encoded>
			<category domain="http://forums.spybot.info/forumdisplay.php?f=54">Malware Removal Guides</category>
			<dc:creator>Friday</dc:creator>
			<guid isPermaLink="true">http://forums.spybot.info/showthread.php?t=65923</guid>
		</item>
		<item>
			<title>Manual Removal Guide for Win32.Mabezat</title>
			<link>http://forums.spybot.info/showthread.php?t=65922&amp;goto=newpost</link>
			<pubDate>Wed, 16 May 2012 10:37:54 GMT</pubDate>
			<description><![CDATA[The following instructions have been created to help you to get rid of "Win32.Mabezat" manually. 
Use this guide at your own risk; software should...]]></description>
			<content:encoded><![CDATA[<div>The following instructions have been created to help you to get rid of <i>&quot;Win32.Mabezat&quot;</i> manually.<br />
Use this guide at your own risk; software <i>should</i> usually be better suited to remove malware, since it is able to look deeper.<br />
<br />
If this guide was helpful to you, please consider <a href="http://www.safer-networking.org/index.php?page=donate" target="_blank">donating towards this site</a>.<br />
<br />
<font size="5"><b><font color="Navy">Threat Details:</font></b></font><br />
<br />
<b>Categories:</b><ul><li>trojan</li>
<li>worm</li>
</ul><b>Description:</b><blockquote>Win32.Mabezat is a Worm with file infecting ability. It cloaks itself as a 3rd party installer or uses a document icon to mislead the user. Once installed it copies itself to all removable drives or network shares and creates an autorun entry for these files.</blockquote><font size="5"><b><font color="Navy">Removal Instructions:</font></b></font><br />
<br />
<font size="3"><b><font color="Navy">Files:</font></b></font><br />
<br />
Please use Windows Explorer or another file manager of your choice to locate and delete these files.<ul><li>A file with an unknown location named <i>&quot;InstallMSN11En.exe&quot;</i>.</li>
<li>A file with an unknown location named <i>&quot;KasperSky6.0 Key.doc.exe&quot;</i>.</li>
<li>A file with an unknown location named <i>&quot;Make Windows Original.exe&quot;</i>.</li>
<li>A file with an unknown location named <i>&quot;Office2007 Serial.txt.exe&quot;</i>.</li>
<li>A file with an unknown location named <i>&quot;WinrRarSerialInstall.exe&quot;</i>.</li>
<li>The file at <i>&quot;&lt;$APPDATA&gt;\Tazebama\tazebama.log&quot;</i>.</li>
<li>The file at <i>&quot;&lt;$FIXEDDRIVES&gt;\InstallMSN11En.exe&quot;</i>.</li>
<li>The file at <i>&quot;&lt;$FIXEDDRIVES&gt;\KasperSky6.0 Key.doc.exe&quot;</i>.</li>
<li>The file at <i>&quot;&lt;$FIXEDDRIVES&gt;\Make Windows Original.exe&quot;</i>.</li>
<li>The file at <i>&quot;&lt;$FIXEDDRIVES&gt;\Office2007 Serial.txt.exe&quot;</i>.</li>
<li>The file at <i>&quot;&lt;$FIXEDDRIVES&gt;\WinrRarSerialInstall.exe&quot;</i>.</li>
<li>The file at <i>&quot;&lt;$PROFILES&gt;\hook.dl_&quot;</i>.</li>
<li>The file at <i>&quot;&lt;$PROFILES&gt;\tazebama.dl_&quot;</i>.</li>
</ul>Make sure you set your file manager to display hidden and system files. If Win32.Mabezat uses rootkit technologies, use our <a href="http://forums.spybot.info/downloads.php?id=8" target="_blank">RootAlyzer</a> or our <a href="http://forums.spybot.info/downloads.php?id=3" target="_blank">Total Commander anti-rootkit plugins</a>.<br />
You will have to use a global search for files without a name specified. <b>Be extra careful</b>, because just the name might not be enough to identify files!<br />
<br />
<b>Important:</b> There are more files that cannot be safely described in simple words. Please use <a href="http://www.safer-networking.org/index.php?page=spybotsd" target="_blank">Spybot-S&amp;D</a> to remove them.<br />
<br />
<font size="3"><b><font color="Navy">Folders:</font></b></font><br />
<br />
Please use Windows Explorer or another file manager of your choice to locate and delete these folders.<ul><li>The directory at <i>&quot;&lt;$APPDATA&gt;\tazebama&quot;</i>.</li>
</ul>Make sure you set your file manager to display hidden and system files. If Win32.Mabezat uses rootkit technologies, use our <a href="http://forums.spybot.info/downloads.php?id=8" target="_blank">RootAlyzer</a> or our <a href="http://forums.spybot.info/downloads.php?id=3" target="_blank">Total Commander anti-rootkit plugins</a>.<br />
You will have to use a global search for files without a name specified. <b>Be extra careful</b>, because just the name might not be enough to identify folders!<br />
<br />
<font size="5"><b><font color="Navy">Final Words:</font></b></font><br />
<br />
If neither Spybot-S&amp;D nor self help did resolve the issue or you would prefer one on one help,<ol style="list-style-type: decimal"><li><a href="http://forums.spybot.info/showthread.php?t=288" target="_blank">Please read these instructions</a> <b>before</b> requesting assistance,</li>
<li>Then start your own thread in the <a href="http://forums.spybot.info/forumdisplay.php?f=22" target="_blank">Malware Removal Forum</a> where a volunteer analyst will advise you as soon as available.</li>
</ol></div>

]]></content:encoded>
			<category domain="http://forums.spybot.info/forumdisplay.php?f=54">Malware Removal Guides</category>
			<dc:creator>Friday</dc:creator>
			<guid isPermaLink="true">http://forums.spybot.info/showthread.php?t=65922</guid>
		</item>
		<item>
			<title>Manual Removal Guide for Win32.IRCBot</title>
			<link>http://forums.spybot.info/showthread.php?t=65921&amp;goto=newpost</link>
			<pubDate>Wed, 16 May 2012 10:37:52 GMT</pubDate>
			<description><![CDATA[The following instructions have been created to help you to get rid of "Win32.IRCBot" manually. 
Use this guide at your own risk; software should...]]></description>
			<content:encoded><![CDATA[<div>The following instructions have been created to help you to get rid of <i>&quot;Win32.IRCBot&quot;</i> manually.<br />
Use this guide at your own risk; software <i>should</i> usually be better suited to remove malware, since it is able to look deeper.<br />
<br />
If this guide was helpful to you, please consider <a href="http://www.safer-networking.org/index.php?page=donate" target="_blank">donating towards this site</a>.<br />
<br />
<font size="5"><b><font color="Navy">Threat Details:</font></b></font><br />
<br />
<b>Categories:</b><ul><li>trojan</li>
</ul><b>Description:</b><blockquote>Win32.IRCBot installs a file into the local temp directory. Variants create a subfolder within recycler and drop the copy into it. This malware is run via autorun and establishes a connection with a remote IRC Server. Win32.IRCbot installer pretends to be a cracking or other keygen tool.<br />
</blockquote><font size="5"><b><font color="Navy">Removal Instructions:</font></b></font><br />
<br />
<font size="3"><b><font color="Navy">Folders:</font></b></font><br />
<br />
Please use Windows Explorer or another file manager of your choice to locate and delete these folders.<ul><li>The directory at <i>&quot;c:\Windows\temp\mama&quot;</i>.</li>
</ul>Make sure you set your file manager to display hidden and system files. If Win32.IRCBot uses rootkit technologies, use our <a href="http://forums.spybot.info/downloads.php?id=8" target="_blank">RootAlyzer</a> or our <a href="http://forums.spybot.info/downloads.php?id=3" target="_blank">Total Commander anti-rootkit plugins</a>.<br />
You will have to use a global search for files without a name specified. <b>Be extra careful</b>, because just the name might not be enough to identify folders!<br />
<br />
<font size="5"><b><font color="Navy">Final Words:</font></b></font><br />
<br />
If neither Spybot-S&amp;D nor self help did resolve the issue or you would prefer one on one help,<ol style="list-style-type: decimal"><li><a href="http://forums.spybot.info/showthread.php?t=288" target="_blank">Please read these instructions</a> <b>before</b> requesting assistance,</li>
<li>Then start your own thread in the <a href="http://forums.spybot.info/forumdisplay.php?f=22" target="_blank">Malware Removal Forum</a> where a volunteer analyst will advise you as soon as available.</li>
</ol></div>

]]></content:encoded>
			<category domain="http://forums.spybot.info/forumdisplay.php?f=54">Malware Removal Guides</category>
			<dc:creator>Friday</dc:creator>
			<guid isPermaLink="true">http://forums.spybot.info/showthread.php?t=65921</guid>
		</item>
		<item>
			<title>Manual Removal Guide for Win32.Graftor.6078</title>
			<link>http://forums.spybot.info/showthread.php?t=65920&amp;goto=newpost</link>
			<pubDate>Wed, 16 May 2012 10:37:51 GMT</pubDate>
			<description><![CDATA[The following instructions have been created to help you to get rid of "Win32.Graftor.6078" manually. 
Use this guide at your own risk; software...]]></description>
			<content:encoded><![CDATA[<div>The following instructions have been created to help you to get rid of <i>&quot;Win32.Graftor.6078&quot;</i> manually.<br />
Use this guide at your own risk; software <i>should</i> usually be better suited to remove malware, since it is able to look deeper.<br />
<br />
If this guide was helpful to you, please consider <a href="http://www.safer-networking.org/index.php?page=donate" target="_blank">donating towards this site</a>.<br />
<br />
<font size="5"><b><font color="Navy">Threat Details:</font></b></font><br />
<br />
<b>Categories:</b><ul><li>trojan</li>
</ul><b>Description:</b><blockquote>Win32.Graftor.6078 installs malicious files into the Program files and root directories and makes DoS-attack on 58.221.41.56-address.</blockquote><font size="5"><b><font color="Navy">Removal Instructions:</font></b></font><br />
<br />
<font size="3"><b><font color="Navy">Files:</font></b></font><br />
<br />
<b>Important:</b> There are more files that cannot be safely described in simple words. Please use <a href="http://www.safer-networking.org/index.php?page=spybotsd" target="_blank">Spybot-S&amp;D</a> to remove them.<br />
<br />
<font size="3"><b><font color="Navy">Folders:</font></b></font><br />
<br />
Please use Windows Explorer or another file manager of your choice to locate and delete these folders.<ul><li>The directory at <i>&quot;&lt;$PROGRAMFILES&gt;\&lt;$ENV(Win32Graftor6078_Dir)&gt;&quot;</i>.</li>
</ul>Make sure you set your file manager to display hidden and system files. If Win32.Graftor.6078 uses rootkit technologies, use our <a href="http://forums.spybot.info/downloads.php?id=8" target="_blank">RootAlyzer</a> or our <a href="http://forums.spybot.info/downloads.php?id=3" target="_blank">Total Commander anti-rootkit plugins</a>.<br />
You will have to use a global search for files without a name specified. <b>Be extra careful</b>, because just the name might not be enough to identify folders!<br />
<br />
<font size="3"><b><font color="Navy">Registry:</font></b></font><br />
<br />
You can use <i>regedit.exe</i> (included in Windows) to locate and delete these registry entries.<ul><li>Delete the registry key <i>&quot;Ghijkl Nopqrstu Wxy&quot;</i> at <i>&quot;HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\&quot;</i>.</li>
<li>Delete the registry key <i>&quot;Ghijkl Nopqrstu Wxy&quot;</i> at <i>&quot;HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\&quot;</i>.</li>
<li>Delete the registry key <i>&quot;Ghijkl Nopqrstu Wxy&quot;</i> at <i>&quot;HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\&quot;</i>.</li>
<li>Delete the registry key <i>&quot;Ghijkl Nopqrstu Wxy&quot;</i> at <i>&quot;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\&quot;</i>.</li>
<li>Remove <i>&quot;&lt;$ENV(Win32Graftor6078_path)&gt;&quot;</i> from registry value <i>&quot;DLLPath&quot;</i> at <i>&quot;HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\RemoteAccess\RouterManagers\Ip\&quot;</i>.</li>
<li>Remove <i>&quot;&lt;$ENV(Win32Graftor6078_path)&gt;&quot;</i> from registry value <i>&quot;DLLPath&quot;</i> at <i>&quot;HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\RemoteAccess\RouterManagers\Ip\&quot;</i>.</li>
<li>Remove <i>&quot;&lt;$ENV(Win32Graftor6078_path)&gt;&quot;</i> from registry value <i>&quot;DLLPath&quot;</i> at <i>&quot;HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\RemoteAccess\RouterManagers\Ip\&quot;</i>.</li>
<li>Remove <i>&quot;&lt;$ENV(Win32Graftor6078_path)&gt;&quot;</i> from registry value <i>&quot;DLLPath&quot;</i> at <i>&quot;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess\RouterManagers\Ip\&quot;</i>.</li>
</ul>If Win32.Graftor.6078 uses rootkit technologies, use our <a href="http://www.safer-networking.org/index.php?page=regalyzer" target="_blank">RegAlyzer</a>, <a href="http://forums.spybot.info/downloads.php?id=8" target="_blank">RootAlyzer</a> or our <a href="http://forums.spybot.info/downloads.php?id=3" target="_blank">Total Commander anti-rootkit plugins</a>.<br />
<br />
There are more registry entries that cannot be safely described in simple words. Please use <a href="http://www.safer-networking.org/index.php?page=spybotsd" target="_blank">Spybot-S&amp;D</a> to remove them.<br />
<br />
<font size="5"><b><font color="Navy">Final Words:</font></b></font><br />
<br />
If neither Spybot-S&amp;D nor self help did resolve the issue or you would prefer one on one help,<ol style="list-style-type: decimal"><li><a href="http://forums.spybot.info/showthread.php?t=288" target="_blank">Please read these instructions</a> <b>before</b> requesting assistance,</li>
<li>Then start your own thread in the <a href="http://forums.spybot.info/forumdisplay.php?f=22" target="_blank">Malware Removal Forum</a> where a volunteer analyst will advise you as soon as available.</li>
</ol><br />
There are more files or system entries belonging to this product that &lt;$SPYBOTSD&gt; can remove, but that cannot be easily described in text. Please use &lt;$SPYBOTSD&gt; to make sure &lt;$PRODUCTNAME&gt; gets completely removed.</div>

]]></content:encoded>
			<category domain="http://forums.spybot.info/forumdisplay.php?f=54">Malware Removal Guides</category>
			<dc:creator>Friday</dc:creator>
			<guid isPermaLink="true">http://forums.spybot.info/showthread.php?t=65920</guid>
		</item>
		<item>
			<title>Manual Removal Guide for Win32.Downloader.bdld</title>
			<link>http://forums.spybot.info/showthread.php?t=65919&amp;goto=newpost</link>
			<pubDate>Wed, 16 May 2012 10:37:50 GMT</pubDate>
			<description><![CDATA[The following instructions have been created to help you to get rid of "Win32.Downloader.bdld" manually. 
Use this guide at your own risk; software...]]></description>
			<content:encoded><![CDATA[<div>The following instructions have been created to help you to get rid of <i>&quot;Win32.Downloader.bdld&quot;</i> manually.<br />
Use this guide at your own risk; software <i>should</i> usually be better suited to remove malware, since it is able to look deeper.<br />
<br />
If this guide was helpful to you, please consider <a href="http://www.safer-networking.org/index.php?page=donate" target="_blank">donating towards this site</a>.<br />
<br />
<font size="5"><b><font color="Navy">Threat Details:</font></b></font><br />
<br />
<b>Categories:</b><ul><li>malware</li>
</ul><b>Description:</b><blockquote>Win32.Downloader.bdld copies malicious files into the Windows directory and itself via an userinit entry.</blockquote><font size="5"><b><font color="Navy">Removal Instructions:</font></b></font><br />
<br />
<font size="3"><b><font color="Navy">Files:</font></b></font><br />
<br />
<b>Important:</b> There are more files that cannot be safely described in simple words. Please use <a href="http://www.safer-networking.org/index.php?page=spybotsd" target="_blank">Spybot-S&amp;D</a> to remove them.<br />
<br />
<font size="3"><b><font color="Navy">Registry:</font></b></font><br />
<br />
You can use <i>regedit.exe</i> (included in Windows) to locate and delete these registry entries.<ul><li>Remove <i>&quot;&lt;$ENV(Win32DownloaderBdld_Dir)&gt;&quot;</i> from registry value <i>&quot;Userinit&quot;</i> at <i>&quot;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\&quot;</i>.</li>
</ul>If Win32.Downloader.bdld uses rootkit technologies, use our <a href="http://www.safer-networking.org/index.php?page=regalyzer" target="_blank">RegAlyzer</a>, <a href="http://forums.spybot.info/downloads.php?id=8" target="_blank">RootAlyzer</a> or our <a href="http://forums.spybot.info/downloads.php?id=3" target="_blank">Total Commander anti-rootkit plugins</a>.<br />
<br />
<font size="5"><b><font color="Navy">Final Words:</font></b></font><br />
<br />
If neither Spybot-S&amp;D nor self help did resolve the issue or you would prefer one on one help,<ol style="list-style-type: decimal"><li><a href="http://forums.spybot.info/showthread.php?t=288" target="_blank">Please read these instructions</a> <b>before</b> requesting assistance,</li>
<li>Then start your own thread in the <a href="http://forums.spybot.info/forumdisplay.php?f=22" target="_blank">Malware Removal Forum</a> where a volunteer analyst will advise you as soon as available.</li>
</ol><br />
There are more files or system entries belonging to this product that &lt;$SPYBOTSD&gt; can remove, but that cannot be easily described in text. Please use &lt;$SPYBOTSD&gt; to make sure &lt;$PRODUCTNAME&gt; gets completely removed.</div>

]]></content:encoded>
			<category domain="http://forums.spybot.info/forumdisplay.php?f=54">Malware Removal Guides</category>
			<dc:creator>Friday</dc:creator>
			<guid isPermaLink="true">http://forums.spybot.info/showthread.php?t=65919</guid>
		</item>
		<item>
			<title>Manual Removal Guide for Win32.Autorun.ie</title>
			<link>http://forums.spybot.info/showthread.php?t=65918&amp;goto=newpost</link>
			<pubDate>Wed, 16 May 2012 10:37:49 GMT</pubDate>
			<description><![CDATA[The following instructions have been created to help you to get rid of "Win32.Autorun.ie" manually. 
Use this guide at your own risk; software should...]]></description>
			<content:encoded><![CDATA[<div>The following instructions have been created to help you to get rid of <i>&quot;Win32.Autorun.ie&quot;</i> manually.<br />
Use this guide at your own risk; software <i>should</i> usually be better suited to remove malware, since it is able to look deeper.<br />
<br />
If this guide was helpful to you, please consider <a href="http://www.safer-networking.org/index.php?page=donate" target="_blank">donating towards this site</a>.<br />
<br />
<font size="5"><b><font color="Navy">Threat Details:</font></b></font><br />
<br />
<b>Categories:</b><ul><li>malware</li>
</ul><b>Description:</b><blockquote>Win32.Autorun.ie tries to start itself in autorun as &quot;iexplorer&quot; to get started without raising suspicion.</blockquote><font size="5"><b><font color="Navy">Removal Instructions:</font></b></font><br />
<br />
<font size="3"><b><font color="Navy">Autorun:</font></b></font><br />
<br />
Please use <a href="http://www.safer-networking.org/index.php?page=spybotsd" target="_blank">Spybot-S&amp;D</a>, <a href="http://www.safer-networking.org/index.php?page=runalyzer" target="_blank">RunAlyzer</a> or <i>msconfig.exe</i> to remove the following autorun entries.<ul><li>Entries named <i>&quot;iexplorer&quot;</i> and pointing to <i>&quot;&lt;$SYSDIR&gt;\iexplorer32.exe&quot;</i>.</li>
<li>Entries named <i>&quot;msnmsggr&quot;</i> and pointing to <i>&quot;&lt;$SYSDIR&gt;\msnmsggr2.exe&quot;</i>.</li>
</ul><font size="3"><b><font color="Navy">Files:</font></b></font><br />
<br />
<b>Important:</b> There are more files that cannot be safely described in simple words. Please use <a href="http://www.safer-networking.org/index.php?page=spybotsd" target="_blank">Spybot-S&amp;D</a> to remove them.<br />
<br />
<font size="5"><b><font color="Navy">Final Words:</font></b></font><br />
<br />
If neither Spybot-S&amp;D nor self help did resolve the issue or you would prefer one on one help,<ol style="list-style-type: decimal"><li><a href="http://forums.spybot.info/showthread.php?t=288" target="_blank">Please read these instructions</a> <b>before</b> requesting assistance,</li>
<li>Then start your own thread in the <a href="http://forums.spybot.info/forumdisplay.php?f=22" target="_blank">Malware Removal Forum</a> where a volunteer analyst will advise you as soon as available.</li>
</ol></div>

]]></content:encoded>
			<category domain="http://forums.spybot.info/forumdisplay.php?f=54">Malware Removal Guides</category>
			<dc:creator>Friday</dc:creator>
			<guid isPermaLink="true">http://forums.spybot.info/showthread.php?t=65918</guid>
		</item>
		<item>
			<title>Manual Removal Guide for Conficker.rtk</title>
			<link>http://forums.spybot.info/showthread.php?t=65917&amp;goto=newpost</link>
			<pubDate>Wed, 16 May 2012 10:37:48 GMT</pubDate>
			<description><![CDATA[The following instructions have been created to help you to get rid of "Conficker.rtk" manually. 
Use this guide at your own risk; software should...]]></description>
			<content:encoded><![CDATA[<div>The following instructions have been created to help you to get rid of <i>&quot;Conficker.rtk&quot;</i> manually.<br />
Use this guide at your own risk; software <i>should</i> usually be better suited to remove malware, since it is able to look deeper.<br />
<br />
If this guide was helpful to you, please consider <a href="http://www.safer-networking.org/index.php?page=donate" target="_blank">donating towards this site</a>.<br />
<br />
<font size="5"><b><font color="Navy">Threat Details:</font></b></font><br />
<br />
<b>Categories:</b><ul><li>trojan</li>
<li>rootkit</li>
</ul><b>Description:</b><blockquote>Conficker.rtk is a Trojan horse that gets installed in background and can spread to the local network. It compromises the system security and uses rootkit functions to hide itself and stay persistent.</blockquote><font size="5"><b><font color="Navy">Removal Instructions:</font></b></font><br />
<br />
<font size="3"><b><font color="Navy">Files:</font></b></font><br />
<br />
Please use Windows Explorer or another file manager of your choice to locate and delete these files.<ul><li>The file at <i>&quot;&lt;$PROGRAMFILES&gt;\Internet Explorer\mzeky.dll&quot;</i>.</li>
<li>The file at <i>&quot;&lt;$SYSDIR&gt;\mzeky.dll&quot;</i>.</li>
</ul>Make sure you set your file manager to display hidden and system files. If Conficker.rtk uses rootkit technologies, use our <a href="http://forums.spybot.info/downloads.php?id=8" target="_blank">RootAlyzer</a> or our <a href="http://forums.spybot.info/downloads.php?id=3" target="_blank">Total Commander anti-rootkit plugins</a>.<br />
You will have to use a global search for files without a name specified. <b>Be extra careful</b>, because just the name might not be enough to identify files!<br />
<br />
<b>Important:</b> There are more files that cannot be safely described in simple words. Please use <a href="http://www.safer-networking.org/index.php?page=spybotsd" target="_blank">Spybot-S&amp;D</a> to remove them.<br />
<br />
<font size="3"><b><font color="Navy">Registry:</font></b></font><br />
<br />
You can use <i>regedit.exe</i> (included in Windows) to locate and delete these registry entries.<ul><li>Delete the registry value <i>&quot;6628:TCP&quot;</i> at <i>&quot;HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List\&quot;</i>.</li>
<li>Delete the registry value <i>&quot;6628:TCP&quot;</i> at <i>&quot;HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List\&quot;</i>.</li>
<li>Delete the registry value <i>&quot;6628:TCP&quot;</i> at <i>&quot;HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List\&quot;</i>.</li>
<li>Delete the registry value <i>&quot;Start=W=2&quot;</i> at <i>&quot;HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\wuauserv\&quot;</i>.</li>
<li>Delete the registry value <i>&quot;Start=W=2&quot;</i> at <i>&quot;HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\wuauserv\&quot;</i>.</li>
<li>Delete the registry value <i>&quot;Start=W=2&quot;</i> at <i>&quot;HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\wuauserv\&quot;</i>.</li>
<li>Delete the registry value <i>&quot;Start=W=2&quot;</i> at <i>&quot;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\&quot;</i>.</li>
</ul>If Conficker.rtk uses rootkit technologies, use our <a href="http://www.safer-networking.org/index.php?page=regalyzer" target="_blank">RegAlyzer</a>, <a href="http://forums.spybot.info/downloads.php?id=8" target="_blank">RootAlyzer</a> or our <a href="http://forums.spybot.info/downloads.php?id=3" target="_blank">Total Commander anti-rootkit plugins</a>.<br />
<br />
There are more registry entries that cannot be safely described in simple words. Please use <a href="http://www.safer-networking.org/index.php?page=spybotsd" target="_blank">Spybot-S&amp;D</a> to remove them.<br />
<br />
<font size="5"><b><font color="Navy">Final Words:</font></b></font><br />
<br />
If neither Spybot-S&amp;D nor self help did resolve the issue or you would prefer one on one help,<ol style="list-style-type: decimal"><li><a href="http://forums.spybot.info/showthread.php?t=288" target="_blank">Please read these instructions</a> <b>before</b> requesting assistance,</li>
<li>Then start your own thread in the <a href="http://forums.spybot.info/forumdisplay.php?f=22" target="_blank">Malware Removal Forum</a> where a volunteer analyst will advise you as soon as available.</li>
</ol></div>

]]></content:encoded>
			<category domain="http://forums.spybot.info/forumdisplay.php?f=54">Malware Removal Guides</category>
			<dc:creator>Friday</dc:creator>
			<guid isPermaLink="true">http://forums.spybot.info/showthread.php?t=65917</guid>
		</item>
		<item>
			<title>Manual Removal Guide for ClaroMultimedia</title>
			<link>http://forums.spybot.info/showthread.php?t=65916&amp;goto=newpost</link>
			<pubDate>Wed, 16 May 2012 10:37:46 GMT</pubDate>
			<description><![CDATA[The following instructions have been created to help you to get rid of "ClaroMultimedia" manually. 
Use this guide at your own risk; software should...]]></description>
			<content:encoded><![CDATA[<div>The following instructions have been created to help you to get rid of <i>&quot;ClaroMultimedia&quot;</i> manually.<br />
Use this guide at your own risk; software <i>should</i> usually be better suited to remove malware, since it is able to look deeper.<br />
<br />
If this guide was helpful to you, please consider <a href="http://www.safer-networking.org/index.php?page=donate" target="_blank">donating towards this site</a>.<br />
<br />
<font size="5"><b><font color="Navy">Threat Details:</font></b></font><br />
<br />
<b>Categories:</b><ul><li>malware</li>
</ul><b>Description:</b><blockquote>ClaroMultimedia tries to start a malicious executable file from the system directory via Autorun as &quot;Windows Defender&quot; or &quot;Winlogon&quot; without giving the user a possibility to cancel that process.</blockquote><font size="5"><b><font color="Navy">Removal Instructions:</font></b></font><br />
<br />
<font size="3"><b><font color="Navy">Autorun:</font></b></font><br />
<br />
Please use <a href="http://www.safer-networking.org/index.php?page=spybotsd" target="_blank">Spybot-S&amp;D</a>, <a href="http://www.safer-networking.org/index.php?page=runalyzer" target="_blank">RunAlyzer</a> or <i>msconfig.exe</i> to remove the following autorun entries.<ul><li>Entries named <i>&quot;Winlogon&quot;</i> and pointing to <i>&quot;&lt;$WINDIR&gt;\scssrr.exe&quot;</i>.</li>
</ul><font size="3"><b><font color="Navy">Files:</font></b></font><br />
<br />
<b>Important:</b> There are more files that cannot be safely described in simple words. Please use <a href="http://www.safer-networking.org/index.php?page=spybotsd" target="_blank">Spybot-S&amp;D</a> to remove them.<br />
<br />
<font size="5"><b><font color="Navy">Final Words:</font></b></font><br />
<br />
If neither Spybot-S&amp;D nor self help did resolve the issue or you would prefer one on one help,<ol style="list-style-type: decimal"><li><a href="http://forums.spybot.info/showthread.php?t=288" target="_blank">Please read these instructions</a> <b>before</b> requesting assistance,</li>
<li>Then start your own thread in the <a href="http://forums.spybot.info/forumdisplay.php?f=22" target="_blank">Malware Removal Forum</a> where a volunteer analyst will advise you as soon as available.</li>
</ol></div>

]]></content:encoded>
			<category domain="http://forums.spybot.info/forumdisplay.php?f=54">Malware Removal Guides</category>
			<dc:creator>Friday</dc:creator>
			<guid isPermaLink="true">http://forums.spybot.info/showthread.php?t=65916</guid>
		</item>
		<item>
			<title>Updates: 2012-05-16</title>
			<link>http://forums.spybot.info/showthread.php?t=65915&amp;goto=newpost</link>
			<pubDate>Wed, 16 May 2012 09:50:05 GMT</pubDate>
			<description>*_2012-05-16_* 
*Malware* 
+ ClaroMultimedia+ Win32.Autorun.ie++ Win32.Downloader.bdld+ Win32.FraudLoad.edt+ Win32.Renos 
*Trojans* 
++...</description>
			<content:encoded><![CDATA[<div><font size="-1"><b><u>2012-05-16</u></b><br />
<b>Malware</b><br />
+ ClaroMultimedia+ Win32.Autorun.ie++ Win32.Downloader.bdld+ Win32.FraudLoad.edt+ Win32.Renos<br />
<b>Trojans</b><br />
++ Conficker.rtk++ Win32.Graftor.6078+ Win32.IRCBot+ Win32.Mabezat+ Win32.OnLineGames.down+ Win32.OnLineGames.gen+ Win32.SpyEye++ Win32.Yakes.adkv+ Win32.ZBot<br />
<b>Total: 2541129</b> fingerprints in 792248 rules for 6655 products.</font><br />
<br />
<br />
<br />
<a href="http://www.spybot.info/en/updatehistory/2012-05-16.html" target="_blank">More...</a></div>

]]></content:encoded>
			<category domain="http://forums.spybot.info/forumdisplay.php?f=2">Announcements</category>
			<dc:creator>PepiMK</dc:creator>
			<guid isPermaLink="true">http://forums.spybot.info/showthread.php?t=65915</guid>
		</item>
		<item>
			<title>Hoping this works :)</title>
			<link>http://forums.spybot.info/showthread.php?t=65914&amp;goto=newpost</link>
			<pubDate>Wed, 16 May 2012 02:04:01 GMT</pubDate>
			<description>Hi guys, 
 
I know its busy and I am not trying to be pushy, but it says to post here if your post has gone by the way side so here I am!! :) 
...</description>
			<content:encoded><![CDATA[<div>Hi guys,<br />
<br />
I know its busy and I am not trying to be pushy, but it says to post here if your post has gone by the way side so here I am!! :)<br />
<br />
<a href="http://forums.spybot.info/showthread.php?t=65886" target="_blank">http://forums.spybot.info/showthread.php?t=65886</a><br />
<br />
That is my orginal thread.<br />
<br />
Thank you<br />
<br />
Spamman</div>

]]></content:encoded>
			<category domain="http://forums.spybot.info/forumdisplay.php?f=37">The Waiting Room</category>
			<dc:creator>spamman</dc:creator>
			<guid isPermaLink="true">http://forums.spybot.info/showthread.php?t=65914</guid>
		</item>
		<item>
			<title>Need help - bad image error</title>
			<link>http://forums.spybot.info/showthread.php?t=65913&amp;goto=newpost</link>
			<pubDate>Wed, 16 May 2012 00:38:13 GMT</pubDate>
			<description>Hi, 
My laptop is currently having an issue whenever I try to access the internet (from either Google Chrome or Internet Explorer).  I receive an...</description>
			<content:encoded><![CDATA[<div>Hi,<br />
My laptop is currently having an issue whenever I try to access the internet (from either Google Chrome or Internet Explorer).  I receive an error such as &quot;chrome.exe - bad image&quot; &quot;C:\windows\system32\WRusr.dll is either not designed to run on Windows or it contains an error.  Try installing the program again using the original installation media or contact your system administrator or the software vendor for support.&quot; <br />
<br />
I believe this is some type of malware but I ran Malwarebytes Anti-Malware and CCleaner with nothing found.  I am posting from another PC since I cannot get onto the internet from my laptop.  Because of this I'm not able to download and post the DDS log. I would appreciate any help with this situation, as I hope it can be resolved fairly quickly<br />
<br />
Thanks,<br />
John</div>

]]></content:encoded>
			<category domain="http://forums.spybot.info/forumdisplay.php?f=22">Malware Removal</category>
			<dc:creator>johnp30</dc:creator>
			<guid isPermaLink="true">http://forums.spybot.info/showthread.php?t=65913</guid>
		</item>
		<item>
			<title>Help please..</title>
			<link>http://forums.spybot.info/showthread.php?t=65912&amp;goto=newpost</link>
			<pubDate>Tue, 15 May 2012 21:35:52 GMT</pubDate>
			<description>Hi, 
I think I am at my wits end...so I would really appreciate help. 
I think my laptop (as well as every other computer in the house is infected by...</description>
			<content:encoded><![CDATA[<div>Hi,<br />
I think I am at my wits end...so I would really appreciate help.<br />
I think my laptop (as well as every other computer in the house is infected by the recycler virus...but it does not appear to get picked up by much. And after numerous reformats and Ubuntu installations i still return to the virus. It creates another recycle.bin folder within the recycle bin which then contains a folder names s-1-15- and the rest filled with SID- however having all the hhidden files enabled this folder contains temp files- which are $name.zip files... and numerous others. The temp folders contain hidden files as well as numerous other palces appear to be affected initially- the virus does not like you trying to fight it and appears to get anstier and slow down and affect more the more you fight it. I think I have tried most applications- but maybe I just need some proper expertise to help this one out... really appreciate your help in advance...<br />
<br />
Below are scan results from <font color="red">DDS</font>:<br />
<br />
.<br />
DDS (Ver_2011-08-26.01) - NTFSx86 <br />
Internet Explorer: 8.0.7600.16385<br />
Run by Administrator at 7:21:58 on 2012-05-16<br />
Microsoft Windows 7 Ultimate   6.1.7600.0.1252.1.1033.18.2038.1069 [GMT 10:00]<br />
.<br />
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}<br />
.<br />
============== Running Processes ===============<br />
.<br />
C:\Windows\system32\wininit.exe<br />
C:\Windows\system32\lsm.exe<br />
C:\Windows\system32\svchost.exe -k DcomLaunch<br />
C:\Windows\system32\svchost.exe -k RPCSS<br />
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted<br />
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted<br />
C:\Windows\system32\svchost.exe -k netsvcs<br />
C:\Windows\system32\svchost.exe -k LocalService<br />
C:\Windows\system32\svchost.exe -k NetworkService<br />
C:\Windows\System32\spoolsv.exe<br />
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork<br />
C:\Windows\system32\taskhost.exe<br />
C:\Windows\system32\Dwm.exe<br />
C:\Windows\Explorer.EXE<br />
C:\Windows\system32\SearchIndexer.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation<br />
C:\Windows\System32\svchost.exe -k secsvcs<br />
C:\Windows\system32\mmc.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Windows\system32\SearchProtocolHost.exe<br />
C:\Windows\system32\taskhost.exe<br />
C:\Windows\system32\Dwm.exe<br />
C:\Windows\Explorer.EXE<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Users\Administrator\Desktop\aswclnr.exe<br />
C:\Users\Administrator\Desktop\aswclnr.tmp<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Windows\system32\SearchProtocolHost.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Windows\system32\SearchFilterHost.exe<br />
C:\Windows\system32\conhost.exe<br />
C:\Windows\system32\wbem\wmiprvse.exe<br />
.<br />
============== Pseudo HJT Report ===============<br />
.<br />
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)<br />
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)<br />
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)<br />
DPF: {4B54A9DE-EF1C-4EBE-A328-7C28EA3B433A} - hxxp://quickscan.bitdefender.com/qsax/qsax.cab<br />
TCP: DhcpNameServer = 211.31.138.11 211.29.132.12<br />
TCP: Interfaces\{3D72DF1A-BFFD-4967-876E-FA70843E5A51} : DhcpNameServer = 211.31.138.11 211.29.132.12<br />
TCP: Interfaces\{92D38CD7-718A-489E-808C-1F2B07643433} : DhcpNameServer = 211.31.138.11 211.29.132.12<br />
.<br />
============= SERVICES / DRIVERS ===============<br />
.<br />
R1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\drivers\vwififlt.sys [2009-7-14 48128]<br />
R3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-14 229888]<br />
.<br />
=============== Created Last 30 ================<br />
.<br />
2012-05-16 09:56:57	--------	d-----w-	c:\windows\Panther<br />
2012-05-16 03:58:34	--------	d---a-w-	C:\Kaspersky Rescue Disk 10.0<br />
2012-05-15 16:59:03	6734704	----a-w-	c:\programdata\microsoft\windows defender\definition updates\{7e42ef2b-76a9-412a-a091-5f1d78e0c5e0}\mpengine.dll<br />
2012-05-15 16:59:02	237072	------w-	c:\windows\system32\MpSigStub.exe<br />
2012-05-15 16:11:41	--------	d-----w-	c:\windows\system32\wbem\Performance<br />
2012-05-15 16:04:58	--------	d-sh--w-	C:\Recovery<br />
.<br />
==================== Find3M  ====================<br />
.<br />
.<br />
============= FINISH:  7:22:22.71 ===============<br />
<br />
<br />
<br />
<br />
This scan was run by <font color="Red">Avast cleaner</font>- which appears to not be able to scan the affected files- yet does nto detect anything:<br />
<br />
5/16/2012, 7:15:38 AM<br />
Memory scanning started...<br />
No virus body found in memory.<br />
Memory scanning finished (4.7s).<br />
----------<br />
Files scanning started...<br />
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log... file could not be scanned!<br />
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSStmp.log... file could not be scanned!<br />
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\tmp.edb... file could not be scanned!<br />
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Windows.edb... file could not be scanned!<br />
C:\System Volume Information\Syscache.hve... file could not be scanned!<br />
C:\System Volume Information\Syscache.hve.LOG1... file could not be scanned!<br />
C:\System Volume Information\{3808876b-c176-4e48-b7ae-04046e6cc752}... file could not be scanned!<br />
C:\System Volume Information\{b3189e81-9eac-11e1-be4d-001eec4d38c8}{3808876b-c176-4e48-b7ae-04046e6cc752}... file could not be scanned!<br />
C:\Users\Administrator\ntuser.dat.LOG1... file could not be scanned!<br />
C:\Users\Administrator\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{F9E58EB7-9ED2-11E1-8777-001EEC4D38C8}.dat... file could not be scanned!<br />
C:\Users\Administrator\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{F9E58EB8-9ED2-11E1-8777-001EEC4D38C8}.dat... file could not be scanned!<br />
C:\Users\Administrator\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{FFF58FEE-9ED2-11E1-8777-001EEC4D38C8}.dat... file could not be scanned!<br />
C:\Users\Administrator\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG1... file could not be scanned!<br />
C:\Users\Administrator\AppData\Local\Temp\~DF16D1F91CBFE1775D.TMP... file could not be scanned!<br />
C:\Users\Administrator\AppData\Local\Temp\~DF293E448F155F5AC5.TMP... file could not be scanned!<br />
C:\Users\Administrator\AppData\Local\Temp\~DF2FDBDCB019E06B78.TMP... file could not be scanned!<br />
C:\Users\Administrator\AppData\Local\Temp\~DF377C24F81A7B4FA8.TMP... file could not be scanned!<br />
C:\Users\Administrator\AppData\Local\Temp\~DF9475B4386A730BD2.TMP... file could not be scanned!<br />
C:\Users\Administrator\AppData\Local\Temp\~DFA886D8E71384127F.TMP... file could not be scanned!<br />
C:\Users\Administrator\AppData\Local\Temp\~DFAA2A475524D38DEF.TMP... file could not be scanned!<br />
C:\Users\Administrator\AppData\Local\Temp\~DFE752C5EC14C0576A.TMP... file could not be scanned!<br />
C:\Users\Iw\ntuser.dat.LOG1... file could not be scanned!<br />
C:\Users\Iw\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{FACA7D59-9ED0-11E1-8777-001EEC4D38C8}.dat... file could not be scanned!<br />
C:\Users\Iw\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\{9106B47A-9ED2-11E1-8777-001EEC4D38C8}.dat... file could not be scanned!<br />
C:\Users\Iw\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\{FACA7D5A-9ED0-11E1-8777-001EEC4D38C8}.dat... file could not be scanned!<br />
C:\Users\Iw\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG1... file could not be scanned!<br />
C:\Users\Iw\AppData\Local\Temp\~DF0665EEB7AD2F3AA2.TMP... file could not be scanned!<br />
C:\Users\Iw\AppData\Local\Temp\~DF41D5B22DDAD5B358.TMP... file could not be scanned!<br />
C:\Users\Iw\AppData\Local\Temp\~DF86AB446AFC8E7BBD.TMP... file could not be scanned!<br />
C:\Users\Iw\AppData\Local\Temp\~DFBE34C682CC01B195.TMP... file could not be scanned!<br />
C:\Users\Iw\AppData\Local\Temp\~DFEB687E87222F158E.TMP... file could not be scanned!<br />
C:\Users\Iw\AppData\Local\Temp\~DFFC3DD41038B55227.TMP... file could not be scanned!<br />
C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT.LOG1... file could not be scanned!<br />
C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat... file could not be scanned!<br />
C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat... file could not be scanned!<br />
C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT.LOG1... file could not be scanned!<br />
C:\Windows\System32\catroot2\edb.log... file could not be scanned!<br />
C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\catdb... file could not be scanned!<br />
C:\Windows\System32\catroot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb... file could not be scanned!<br />
C:\Windows\System32\config\DEFAULT.LOG1... file could not be scanned!<br />
C:\Windows\System32\config\SAM.LOG1... file could not be scanned!<br />
C:\Windows\System32\config\SECURITY.LOG1... file could not be scanned!<br />
C:\Windows\System32\config\SOFTWARE.LOG1... file could not be scanned!<br />
C:\Windows\System32\config\SYSTEM.LOG1... file could not be scanned!<br />
No virus body found.<br />
Files scanning finished  (52060 files, 0 infected, 267.8s).<br />
Drives scanned: C:<br />
----------</div>

]]></content:encoded>
			<category domain="http://forums.spybot.info/forumdisplay.php?f=22">Malware Removal</category>
			<dc:creator>effe2012</dc:creator>
			<guid isPermaLink="true">http://forums.spybot.info/showthread.php?t=65912</guid>
		</item>
		<item>
			<title><![CDATA[Sirefef 's]]></title>
			<link>http://forums.spybot.info/showthread.php?t=65911&amp;goto=newpost</link>
			<pubDate>Tue, 15 May 2012 20:25:35 GMT</pubDate>
			<description><![CDATA[Hi. 
Today my computer started freezing when i was tryin to play with my friends, and i noticed that my virus detection programs were shut down. 
I'm...]]></description>
			<content:encoded><![CDATA[<div>Hi.<br />
Today my computer started freezing when i was tryin to play with my friends, and i noticed that my virus detection programs were shut down.<br />
I'm currently using Spybot SD and Microsoft Security Essentials.<br />
MSE just keeps on tellin that the computer has Trojan:Win32/Sirefef.AB and Trojan:Win64/Sirefef.P and i cannot remove them.<br />
I Noticed another post about the similiar case, and saw that u guys gave him excellent help, thought u could help me out aswell.<br />
<br />
Heres the DDS log and the other file<br />
.<br />
DDS (Ver_2011-08-26.01) - NTFSAMD64 <br />
Internet Explorer: 8.0.7601.17514  BrowserJavaVersion: 1.6.0_31<br />
Run by Mikke at 23:01:39 on 2012-05-15<br />
Microsoft Windows 7 Home Premium   6.1.7601.1.1252.358.1033.18.8169.5317 [GMT 3:00]<br />
.<br />
AV: Microsoft Security Essentials *Disabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}<br />
AV: Microsoft Security Essentials *Enabled/Updated* {9765EA51-0D3C-7DFB-6091-10E4E1F341F6}<br />
SP: Microsoft Security Essentials *Disabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}<br />
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}<br />
SP: Microsoft Security Essentials *Enabled/Updated* {2C040BB5-2B06-7275-5A21-2B969A740B4B}<br />
.<br />
============== Running Processes ===============<br />
.<br />
C:\Windows\system32\wininit.exe<br />
C:\Windows\system32\lsm.exe<br />
C:\Windows\system32\svchost.exe -k DcomLaunch<br />
C:\Windows\system32\nvvsvc.exe<br />
C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe<br />
C:\Windows\system32\svchost.exe -k RPCSS<br />
c:\Program Files\Microsoft Security Client\MsMpEng.exe<br />
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted<br />
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted<br />
C:\Windows\system32\svchost.exe -k netsvcs<br />
C:\Windows\system32\svchost.exe -k LocalService<br />
C:\Windows\system32\svchost.exe -k NetworkService<br />
C:\Windows\System32\spoolsv.exe<br />
C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareService.exe<br />
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe<br />
C:\Windows\system32\nvvsvc.exe<br />
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe<br />
C:\Windows\system32\taskhost.exe<br />
C:\Windows\system32\Dwm.exe<br />
C:\Windows\Explorer.EXE<br />
C:\Program Files\Bonjour\mDNSResponder.exe<br />
C:\Program Files (x86)\Samsung\USB Drivers\26_VIA_driver2\amd64\VIAService.exe<br />
C:\Program Files (x86)\Dokan\DokanLibrary\mounter.exe<br />
C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork<br />
C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe<br />
C:\PROGRA~2\AD-AWA~1\AdAware.exe<br />
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe<br />
C:\Windows\system32\IProsetMonitor.exe<br />
C:\Windows\SysWOW64\PnkBstrA.exe<br />
C:\Windows\system32\svchost.exe -k imgsvc<br />
c:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE<br />
C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe<br />
c:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe<br />
C:\Windows\system32\SearchIndexer.exe<br />
C:\Program Files (x86)\Ad-Aware Antivirus\SBAMSvc.exe<br />
C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe<br />
C:\Program Files\Microsoft Security Client\msseces.exe<br />
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe<br />
C:\Program Files (x86)\Steam\Steam.exe<br />
C:\Windows\System32\spool\drivers\x64\3\E_IATIGEE.EXE<br />
C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe<br />
C:\Program Files (x86)\Spotify\Data\SpotifyWebHelper.exe<br />
C:\Users\Mikke\AppData\Roaming\googleoez.exe<br />
C:\Users\Mikke\AppData\Local\Apps\2.0\5JXPDZ2O.O2J\Y67VH46T.DBJ\curs..tion_eee711038731a406_0004.0000_2bd39706d04e72c8\CurseClient.exe<br />
C:\Program Files (x86)\Razer\DeathAdder\razerhid.exe<br />
C:\Program Files (x86)\Razer\DeathAdder\razertra.exe<br />
C:\Program Files (x86)\Razer\DeathAdder\razerofa.exe<br />
C:\Program Files (x86)\Razer\DeathAdder\vdDaemon.exe<br />
C:\Program Files (x86)\iTunes\iTunesHelper.exe<br />
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe<br />
C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe<br />
C:\Program Files\iPod\bin\iPodService.exe<br />
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation<br />
C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe<br />
C:\Program Files (x86)\Spybot - Search &amp; Destroy\TeaTimer.exe<br />
C:\Program Files (x86)\Mozilla Firefox\firefox.exe<br />
c:\Program Files\Microsoft Security Client\MpCmdRun.exe<br />
C:\Windows\system32\SearchProtocolHost.exe<br />
C:\Windows\system32\SearchFilterHost.exe<br />
C:\Windows\SysWOW64\cmd.exe<br />
C:\Windows\system32\conhost.exe<br />
C:\Windows\SysWOW64\cscript.exe<br />
C:\Windows\system32\wbem\wmiprvse.exe<br />
.<br />
============== Pseudo HJT Report ===============<br />
.<br />
uInternet Settings,ProxyOverride = *.local<br />
uInternet Settings,ProxyServer = 210.107.100.251:8080<br />
uURLSearchHooks: uTorrentBar Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files (x86)\uTorrentBar\prxtbuTo2.dll<br />
mURLSearchHooks: uTorrentBar Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files (x86)\uTorrentBar\prxtbuTo2.dll<br />
mWinlogon: Userinit=userinit.exe<br />
BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll<br />
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
BHO: uTorrentBar Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files (x86)\uTorrentBar\prxtbuTo2.dll<br />
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll<br />
TB: uTorrentBar Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files (x86)\uTorrentBar\prxtbuTo2.dll<br />
uRun: [Steam] &quot;C:\Program Files (x86)\Steam\steam.exe&quot; -silent<br />
uRun: [EPSON S22 Series] C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIGEE.EXE /FU &quot;C:\Windows\TEMP\E_S42DB.tmp&quot; /EF &quot;HKCU&quot;<br />
uRun: [KiesPDLR] C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe<br />
uRun: [KiesHelper] C:\Program Files (x86)\Samsung\Kies\KiesHelper.exe /s<br />
uRun: [Xvid] C:\Program Files (x86)\Xvid\CheckUpdate.exe<br />
uRun: [Spotify Web Helper] &quot;C:\Program Files (x86)\Spotify\Data\SpotifyWebHelper.exe&quot;<br />
uRun: [Google] C:\Users\Mikke\AppData\Roaming\googleoez.exe<br />
uRun: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search &amp; Destroy\TeaTimer.exe<br />
mRun: [DeathAdder] C:\Program Files (x86)\Razer\DeathAdder\razerhid.exe<br />
mRun: [APSDaemon] &quot;C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe&quot;<br />
mRun: [iTunesHelper] &quot;C:\Program Files (x86)\iTunes\iTunesHelper.exe&quot;<br />
mRun: [AdobeCS5.5ServiceManager] &quot;C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe&quot; -launchedbylogin<br />
mRun: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe<br />
mRun: [QuickTime Task] &quot;C:\Program Files (x86)\QuickTime\QTTask.exe&quot; -atboottime<br />
mRun: [SunJavaUpdateSched] &quot;C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe&quot;<br />
mRun: [Ad-Aware Antivirus] &quot;C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareLauncher&quot; --windows-run<br />
mRun: [Ad-Aware Browsing Protection] &quot;C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe&quot;<br />
StartupFolder: C:\Users\Mikke\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CurseClientStartup.ccip<br />
StartupFolder: C:\Users\Mikke\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\Dropbox.lnk - C:\Users\Mikke\AppData\Roaming\Dropbox\bin\Dropbox.exe<br />
mPolicies-explorer: NoActiveDesktop = 1 (0x1)<br />
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)<br />
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)<br />
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)<br />
mPolicies-system: EnableLUA = 0 (0x0)<br />
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)<br />
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)<br />
LSP: mswsock.dll<br />
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab<br />
DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab<br />
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab<br />
TCP: DhcpNameServer = 192.168.100.1<br />
TCP: Interfaces\{D328A896-B3CA-4B83-B490-3D57EC7574BB} : DhcpNameServer = 192.168.100.1<br />
BHO-X64: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll<br />
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - c:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
BHO-X64: uTorrentBar Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files (x86)\uTorrentBar\prxtbuTo2.dll<br />
BHO-X64:     uTorrentBar - No File<br />
BHO-X64: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll<br />
TB-X64: uTorrentBar Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files (x86)\uTorrentBar\prxtbuTo2.dll<br />
mRun-x64: [DeathAdder] C:\Program Files (x86)\Razer\DeathAdder\razerhid.exe<br />
mRun-x64: [APSDaemon] &quot;C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe&quot;<br />
mRun-x64: [iTunesHelper] &quot;C:\Program Files (x86)\iTunes\iTunesHelper.exe&quot;<br />
mRun-x64: [AdobeCS5.5ServiceManager] &quot;C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe&quot; -launchedbylogin<br />
mRun-x64: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe<br />
mRun-x64: [QuickTime Task] &quot;C:\Program Files (x86)\QuickTime\QTTask.exe&quot; -atboottime<br />
mRun-x64: [SunJavaUpdateSched] &quot;C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe&quot;<br />
mRun-x64: [Ad-Aware Antivirus] &quot;C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareLauncher&quot; --windows-run<br />
mRun-x64: [Ad-Aware Browsing Protection] &quot;C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe&quot;<br />
Hosts: 127.0.0.1	<a href="http://www.spywareinfo.com" target="_blank">www.spywareinfo.com</a><br />
.<br />
================= FIREFOX ===================<br />
.<br />
FF - ProfilePath - C:\Users\Mikke\AppData\Roaming\Mozilla\Firefox\Profiles\iixr6ws3.default\<br />
FF - prefs.js: network.proxy.type - 0<br />
FF - plugin: C:\Program Files (x86)\Battlelog Web Plugins\1.110.0\npesnlaunch.dll<br />
FF - plugin: C:\Program Files (x86)\Battlelog Web Plugins\1.118.0\npesnlaunch.dll<br />
FF - plugin: C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll<br />
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npdeployJava1.dll<br />
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll<br />
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrlui.dll<br />
FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll<br />
FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll<br />
FF - plugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll<br />
FF - plugin: C:\ProgramData\id Software\QuakeLive\npquakezero.dll<br />
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_2_202_233.dll<br />
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_2_202_235.dll<br />
.<br />
============= SERVICES / DRIVERS ===============<br />
.<br />
R0 MpFilter;Microsoft Malware Protection Driver;C:\Windows\system32\DRIVERS\MpFilter.sys --&gt; C:\Windows\system32\DRIVERS\MpFilter.sys [?]<br />
R0 mv91xx;mv91xx;C:\Windows\system32\DRIVERS\mv91xx.sys --&gt; C:\Windows\system32\DRIVERS\mv91xx.sys [?]<br />
R1 SbFw;SbFw;C:\Windows\system32\drivers\SbFw.sys --&gt; C:\Windows\system32\drivers\SbFw.sys [?]<br />
R1 SBRE;SBRE;C:\Windows\System32\drivers\SBREDrv.sys [2011-10-26 101112]<br />
R2 Dokan;Dokan;\??\C:\Windows\system32\drivers\dokan.sys --&gt; C:\Windows\system32\drivers\dokan.sys [?]<br />
R2 sbapifs;sbapifs;C:\Windows\system32\DRIVERS\sbapifs.sys --&gt; C:\Windows\system32\DRIVERS\sbapifs.sys [?]<br />
R3 danewFltr;NewDeathAdder Mouse;C:\Windows\system32\drivers\danew.sys --&gt; C:\Windows\system32\drivers\danew.sys [?]<br />
R3 e1cexpress;Intel(R) PRO/1000 PCI Express Network Connection Driver C;C:\Windows\system32\DRIVERS\e1c62x64.sys --&gt; C:\Windows\system32\DRIVERS\e1c62x64.sys [?]<br />
R3 Lycosa;Lycosa Keyboard;C:\Windows\system32\drivers\Lycosa.sys --&gt; C:\Windows\system32\drivers\Lycosa.sys [?]<br />
R3 MEIx64;Intel(R) Management Engine Interface;C:\Windows\system32\DRIVERS\HECIx64.sys --&gt; C:\Windows\system32\DRIVERS\HECIx64.sys [?]<br />
R3 NVHDA;Service for NVIDIA High Definition Audio Driver;C:\Windows\system32\drivers\nvhda64v.sys --&gt; C:\Windows\system32\drivers\nvhda64v.sys [?]<br />
R3 SBFWIMCLMP;GFI Software Firewall NDIS IM Filter Miniport;C:\Windows\system32\DRIVERS\SBFWIM.sys --&gt; C:\Windows\system32\DRIVERS\SBFWIM.sys [?]<br />
R3 sbhips;sbhips;C:\Windows\system32\drivers\sbhips.sys --&gt; C:\Windows\system32\drivers\sbhips.sys [?]<br />
R3 VKbms;Virtual HID Minidriver;C:\Windows\system32\DRIVERS\VKbms.sys --&gt; C:\Windows\system32\DRIVERS\VKbms.sys [?]<br />
S1 acsfzwys;acsfzwys;\??\C:\Windows\system32\drivers\acsfzwys.sys --&gt; C:\Windows\system32\drivers\acsfzwys.sys [?]<br />
S1 bmrptbji;bmrptbji;\??\C:\Windows\system32\drivers\bmrptbji.sys --&gt; C:\Windows\system32\drivers\bmrptbji.sys [?]<br />
S1 brwsynan;brwsynan;\??\C:\Windows\system32\drivers\brwsynan.sys --&gt; C:\Windows\system32\drivers\brwsynan.sys [?]<br />
S1 bzzxpcce;bzzxpcce;\??\C:\Windows\system32\drivers\bzzxpcce.sys --&gt; C:\Windows\system32\drivers\bzzxpcce.sys [?]<br />
S1 dlmgqunb;dlmgqunb;\??\C:\Windows\system32\drivers\dlmgqunb.sys --&gt; C:\Windows\system32\drivers\dlmgqunb.sys [?]<br />
S1 fzkqogiu;fzkqogiu;\??\C:\Windows\system32\drivers\fzkqogiu.sys --&gt; C:\Windows\system32\drivers\fzkqogiu.sys [?]<br />
S1 gnjwejcv;gnjwejcv;\??\C:\Windows\system32\drivers\gnjwejcv.sys --&gt; C:\Windows\system32\drivers\gnjwejcv.sys [?]<br />
S1 gpozhnjo;gpozhnjo;\??\C:\Windows\system32\drivers\gpozhnjo.sys --&gt; C:\Windows\system32\drivers\gpozhnjo.sys [?]<br />
S1 ivvnfbjz;ivvnfbjz;\??\C:\Windows\system32\drivers\ivvnfbjz.sys --&gt; C:\Windows\system32\drivers\ivvnfbjz.sys [?]<br />
S1 jcmbymue;jcmbymue;\??\C:\Windows\system32\drivers\jcmbymue.sys --&gt; C:\Windows\system32\drivers\jcmbymue.sys [?]<br />
S1 jhrdxeqa;jhrdxeqa;\??\C:\Windows\system32\drivers\jhrdxeqa.sys --&gt; C:\Windows\system32\drivers\jhrdxeqa.sys [?]<br />
S1 kfuugwzq;kfuugwzq;\??\C:\Windows\system32\drivers\kfuugwzq.sys --&gt; C:\Windows\system32\drivers\kfuugwzq.sys [?]<br />
S1 kgjoxunp;kgjoxunp;\??\C:\Windows\system32\drivers\kgjoxunp.sys --&gt; C:\Windows\system32\drivers\kgjoxunp.sys [?]<br />
S1 knhfhpok;knhfhpok;\??\C:\Windows\system32\drivers\knhfhpok.sys --&gt; C:\Windows\system32\drivers\knhfhpok.sys [?]<br />
S1 lddhrghn;lddhrghn;\??\C:\Windows\system32\drivers\lddhrghn.sys --&gt; C:\Windows\system32\drivers\lddhrghn.sys [?]<br />
S1 lisllgpv;lisllgpv;\??\C:\Windows\system32\drivers\lisllgpv.sys --&gt; C:\Windows\system32\drivers\lisllgpv.sys [?]<br />
S1 mifpixnm;mifpixnm;\??\C:\Windows\system32\drivers\mifpixnm.sys --&gt; C:\Windows\system32\drivers\mifpixnm.sys [?]<br />
S1 owaqcfnb;owaqcfnb;\??\C:\Windows\system32\drivers\owaqcfnb.sys --&gt; C:\Windows\system32\drivers\owaqcfnb.sys [?]<br />
S1 ovifneok;ovifneok;\??\C:\Windows\system32\drivers\ovifneok.sys --&gt; C:\Windows\system32\drivers\ovifneok.sys [?]<br />
S1 qrerckbl;qrerckbl;\??\C:\Windows\system32\drivers\qrerckbl.sys --&gt; C:\Windows\system32\drivers\qrerckbl.sys [?]<br />
S1 updtfadc;updtfadc;\??\C:\Windows\system32\drivers\updtfadc.sys --&gt; C:\Windows\system32\drivers\updtfadc.sys [?]<br />
S1 utphuhhd;utphuhhd;\??\C:\Windows\system32\drivers\utphuhhd.sys --&gt; C:\Windows\system32\drivers\utphuhhd.sys [?]<br />
S1 wbwoewcm;wbwoewcm;\??\C:\Windows\system32\drivers\wbwoewcm.sys --&gt; C:\Windows\system32\drivers\wbwoewcm.sys [?]<br />
S1 wkxqvxqr;wkxqvxqr;\??\C:\Windows\system32\drivers\wkxqvxqr.sys --&gt; C:\Windows\system32\drivers\wkxqvxqr.sys [?]<br />
S1 wvdaqubb;wvdaqubb;\??\C:\Windows\system32\drivers\wvdaqubb.sys --&gt; C:\Windows\system32\drivers\wvdaqubb.sys [?]<br />
S1 wzaqtwxl;wzaqtwxl;\??\C:\Windows\system32\drivers\wzaqtwxl.sys --&gt; C:\Windows\system32\drivers\wzaqtwxl.sys [?]<br />
S1 xgcrftet;xgcrftet;\??\C:\Windows\system32\drivers\xgcrftet.sys --&gt; C:\Windows\system32\drivers\xgcrftet.sys [?]<br />
S1 yaupckzz;yaupckzz;\??\C:\Windows\system32\drivers\yaupckzz.sys --&gt; C:\Windows\system32\drivers\yaupckzz.sys [?]<br />
S3 CYUSB;Cypress Generic USB Driver;C:\Windows\system32\Drivers\CYUSB.sys --&gt; C:\Windows\system32\Drivers\CYUSB.sys [?]<br />
S3 NisDrv;Microsoft Network Inspection System;C:\Windows\system32\DRIVERS\NisDrvWFP.sys --&gt; C:\Windows\system32\DRIVERS\NisDrvWFP.sys [?]<br />
S3 SBFWIMCL;GFI Software Firewall NDIS IM Filter Service;C:\Windows\system32\DRIVERS\sbfwim.sys --&gt; C:\Windows\system32\DRIVERS\sbfwim.sys [?]<br />
S3 sbwtis;sbwtis;C:\Windows\system32\DRIVERS\sbwtis.sys --&gt; C:\Windows\system32\DRIVERS\sbwtis.sys [?]<br />
S3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);C:\Windows\system32\DRIVERS\ssadbus.sys --&gt; C:\Windows\system32\DRIVERS\ssadbus.sys [?]<br />
S3 ssadmdfl;SAMSUNG Android USB Modem (Filter);C:\Windows\system32\DRIVERS\ssadmdfl.sys --&gt; C:\Windows\system32\DRIVERS\ssadmdfl.sys [?]<br />
S3 ssadmdm;SAMSUNG Android USB Modem Drivers;C:\Windows\system32\DRIVERS\ssadmdm.sys --&gt; C:\Windows\system32\DRIVERS\ssadmdm.sys [?]<br />
S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --&gt; C:\Windows\system32\drivers\tsusbflt.sys [?]<br />
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\system32\Drivers\usbaapl64.sys --&gt; C:\Windows\system32\Drivers\usbaapl64.sys [?]<br />
SUnknown jhbcafgk;jhbcafgk; [x]<br />
SUnknown kqedmhwk;kqedmhwk; [x]<br />
SUnknown olpjpgvt;olpjpgvt; [x]<br />
SUnknown uqidycgt;uqidycgt; [x]<br />
.<br />
=============== Created Last 30 ================<br />
.<br />
2012-05-15 18:55:32	50000	----a-w-	C:\Windows\System32\drivers\knhfhpok.sys<br />
2012-05-15 18:29:30	50000	----a-w-	C:\Windows\System32\drivers\mifpixnm.sys<br />
2012-05-15 18:29:08	50000	----a-w-	C:\Windows\System32\drivers\qrerckbl.sys<br />
2012-05-15 18:28:38	50000	----a-w-	C:\Windows\System32\drivers\kfuugwzq.sys<br />
2012-05-15 18:28:15	50000	----a-w-	C:\Windows\System32\drivers\bzzxpcce.sys<br />
2012-05-15 18:27:43	50000	----a-w-	C:\Windows\System32\drivers\brwsynan.sys<br />
2012-05-15 18:27:17	50000	----a-w-	C:\Windows\System32\drivers\lisllgpv.sys<br />
2012-05-15 18:25:40	50000	----a-w-	C:\Windows\System32\drivers\ovifneok.sys<br />
2012-05-15 18:25:19	50000	----a-w-	C:\Windows\System32\drivers\yaupckzz.sys<br />
2012-05-15 18:24:46	50000	----a-w-	C:\Windows\System32\drivers\gnjwejcv.sys<br />
2012-05-15 18:24:25	50000	----a-w-	C:\Windows\System32\drivers\utphuhhd.sys<br />
2012-05-15 18:23:55	50000	----a-w-	C:\Windows\System32\drivers\updtfadc.sys<br />
2012-05-15 18:23:33	50000	----a-w-	C:\Windows\System32\drivers\wkxqvxqr.sys<br />
2012-05-15 18:19:34	--------	d-----w-	C:\ProgramData\Spybot - Search &amp; Destroy<br />
2012-05-15 18:19:34	--------	d-----w-	C:\Program Files (x86)\Spybot - Search &amp; Destroy<br />
2012-05-15 18:18:54	50000	----a-w-	C:\Windows\System32\drivers\jcmbymue.sys<br />
2012-05-15 18:18:27	50000	----a-w-	C:\Windows\System32\drivers\xgcrftet.sys<br />
2012-05-15 18:06:00	50000	----a-w-	C:\Windows\System32\drivers\wzaqtwxl.sys<br />
2012-05-15 18:05:34	50000	----a-w-	C:\Windows\System32\drivers\kgjoxunp.sys<br />
2012-05-15 18:02:35	50000	----a-w-	C:\Windows\System32\drivers\gpozhnjo.sys<br />
2012-05-15 18:01:52	50000	----a-w-	C:\Windows\System32\drivers\lddhrghn.sys<br />
2012-05-15 17:57:55	50000	----a-w-	C:\Windows\System32\drivers\fzkqogiu.sys<br />
2012-05-15 17:57:50	50000	----a-w-	C:\Windows\System32\drivers\acsfzwys.sys<br />
2012-05-15 17:57:17	50000	----a-w-	C:\Windows\System32\drivers\bmrptbji.sys<br />
2012-05-15 17:56:32	50000	----a-w-	C:\Windows\System32\drivers\wbwoewcm.sys<br />
2012-05-15 17:56:05	50000	----a-w-	C:\Windows\System32\drivers\dlmgqunb.sys<br />
2012-05-15 17:52:53	50000	----a-w-	C:\Windows\System32\drivers\jhrdxeqa.sys<br />
2012-05-15 17:52:26	50000	----a-w-	C:\Windows\System32\drivers\ivvnfbjz.sys<br />
2012-05-15 17:44:36	50000	----a-w-	C:\Windows\System32\drivers\wvdaqubb.sys<br />
2012-05-15 17:44:14	50000	----a-w-	C:\Windows\System32\drivers\owaqcfnb.sys<br />
2012-05-15 17:43:57	69000	----a-w-	C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{5CE86D19-96E5-47DC-8D5F-D512B9BA6B08}\offreg.dll<br />
2012-05-15 16:45:09	927800	----a-w-	C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{6436F758-9839-4EA0-999D-982F3085CC18}\gapaengine.dll<br />
2012-05-15 16:45:06	8917360	----a-w-	C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{5CE86D19-96E5-47DC-8D5F-D512B9BA6B08}\mpengine.dll<br />
2012-05-15 16:42:59	--------	d-----w-	C:\Program Files (x86)\Microsoft Security Client<br />
2012-05-15 16:42:56	--------	d-----w-	C:\Program Files\Microsoft Security Client<br />
2012-05-15 16:33:50	--------	d-----w-	C:\Users\Mikke\AppData\Local\adaware<br />
2012-05-15 16:33:48	--------	d-----w-	C:\ProgramData\Ad-Aware Browsing Protection<br />
2012-05-15 16:33:30	60536	----a-w-	C:\Windows\System32\drivers\sbhips.sys<br />
2012-05-15 16:33:13	119416	----a-w-	C:\Windows\System32\drivers\SbFwIm.sys<br />
2012-05-15 16:33:11	57976	----a-w-	C:\Windows\System32\drivers\sbredrv.sys<br />
2012-05-15 16:33:11	45936	----a-w-	C:\Windows\System32\sbbd.exe<br />
2012-05-15 16:33:11	256632	----a-w-	C:\Windows\System32\drivers\SbFw.sys<br />
2012-05-15 16:33:10	--------	d-----w-	C:\Program Files (x86)\Ad-Aware Antivirus<br />
2012-05-15 16:32:09	--------	d-----w-	C:\Users\Mikke\AppData\Roaming\Ad-Aware Antivirus<br />
2012-05-09 03:32:30	1544704	----a-w-	C:\Windows\System32\DWrite.dll<br />
2012-05-09 03:32:29	1077248	----a-w-	C:\Windows\SysWow64\DWrite.dll<br />
2012-05-09 03:32:24	5559664	----a-w-	C:\Windows\System32\ntoskrnl.exe<br />
2012-05-09 03:32:23	3146240	----a-w-	C:\Windows\System32\win32k.sys<br />
2012-05-09 03:32:22	3968368	----a-w-	C:\Windows\SysWow64\ntkrnlpa.exe<br />
2012-05-09 03:32:22	3913072	----a-w-	C:\Windows\SysWow64\ntoskrnl.exe<br />
2012-05-09 03:32:02	75120	----a-w-	C:\Windows\System32\drivers\partmgr.sys<br />
2012-05-09 03:31:53	1918320	----a-w-	C:\Windows\System32\drivers\tcpip.sys<br />
2012-05-09 03:31:50	936960	----a-w-	C:\Program Files (x86)\Common Files\Microsoft Shared\ink\journal.dll<br />
2012-05-09 03:31:50	1732096	----a-w-	C:\Program Files\Windows Journal\NBDoc.DLL<br />
2012-05-09 03:31:50	1402880	----a-w-	C:\Program Files\Windows Journal\JNWDRV.dll<br />
2012-05-09 03:31:50	1393664	----a-w-	C:\Program Files\Windows Journal\JNTFiltr.dll<br />
2012-05-09 03:31:50	1367552	----a-w-	C:\Program Files\Common Files\Microsoft Shared\ink\journal.dll<br />
2012-05-06 05:04:23	--------	d-----w-	C:\Users\Mikke\AppData\Local\SniperV2<br />
2012-05-06 04:36:08	102400	------w-	C:\Users\Mikke\AppData\Roaming\googleoez.exe<br />
2012-05-02 17:01:48	--------	d-----w-	C:\ProgramData\id Software<br />
2012-04-26 08:19:34	--------	d-----w-	C:\Program Files (x86)\Mozilla Maintenance Service<br />
2012-04-26 08:19:30	157352	----a-w-	C:\Program Files (x86)\Mozilla Firefox\maintenanceservice_installer.exe<br />
2012-04-26 08:19:30	129976	----a-w-	C:\Program Files (x86)\Mozilla Firefox\maintenanceservice.exe<br />
2012-04-24 22:43:33	715038	----a-w-	C:\Windows\unins000.exe<br />
2012-04-19 20:04:20	90112	----a-w-	C:\Windows\unvise32.exe<br />
2012-04-19 20:04:17	--------	d-----w-	C:\Program Files (x86)\LooksBuilder<br />
2012-04-19 12:47:47	77824	----a-w-	C:\Program Files (x86)\Common Files\InstallShield\engine\6\Intel 32\ctor.dll<br />
2012-04-19 12:47:47	32768	------w-	C:\Program Files (x86)\Common Files\InstallShield\engine\6\Intel 32\objectps.dll<br />
2012-04-19 12:47:47	221184	------w-	C:\Program Files (x86)\Common Files\InstallShield\IScript\IScript.dll<br />
2012-04-19 12:47:47	221184	------w-	C:\Program Files (x86)\Common Files\InstallShield\engine\6\Intel 32\iuser.dll<br />
2012-04-19 12:47:47	212992	----a-w-	C:\Program Files (x86)\Common Files\InstallShield\engine\6\Intel 32\ILog.dll<br />
.<br />
==================== Find3M  ====================<br />
.<br />
2012-05-15 18:25:40	50000	----a-w-	C:\Windows\System32\drivers\ovifneok.sys<br />
2012-05-13 21:43:22	283304	----a-w-	C:\Windows\SysWow64\PnkBstrB.xtr<br />
2012-05-13 21:43:22	283304	----a-w-	C:\Windows\SysWow64\PnkBstrB.exe<br />
2012-05-13 21:42:55	280904	----a-w-	C:\Windows\SysWow64\PnkBstrB.ex0<br />
2012-05-09 04:26:50	419488	----a-w-	C:\Windows\SysWow64\FlashPlayerApp.exe<br />
2012-05-09 04:26:49	70304	----a-w-	C:\Windows\SysWow64\FlashPlayerCPLApp.cpl<br />
2012-05-05 10:28:11	8744608	----a-w-	C:\Windows\SysWow64\FlashPlayerInstaller.exe<br />
2012-03-20 17:44:12	98688	----a-w-	C:\Windows\System32\drivers\NisDrvWFP.sys<br />
2012-03-20 17:44:12	203888	----a-w-	C:\Windows\System32\drivers\MpFilter.sys<br />
2012-03-07 13:49:40	472808	----a-w-	C:\Windows\SysWow64\deployJava1.dll<br />
2012-03-01 06:46:16	23408	----a-w-	C:\Windows\System32\drivers\fs_rec.sys<br />
2012-03-01 06:38:27	220672	----a-w-	C:\Windows\System32\wintrust.dll<br />
2012-03-01 06:33:50	81408	----a-w-	C:\Windows\System32\imagehlp.dll<br />
2012-03-01 06:28:47	5120	----a-w-	C:\Windows\System32\wmi.dll<br />
2012-03-01 05:37:41	172544	----a-w-	C:\Windows\SysWow64\wintrust.dll<br />
2012-03-01 05:33:23	159232	----a-w-	C:\Windows\SysWow64\imagehlp.dll<br />
2012-03-01 05:29:16	5120	----a-w-	C:\Windows\SysWow64\wmi.dll<br />
2012-02-29 21:00:22	3089728	----a-w-	C:\Windows\System32\nvsvc64.dll<br />
2012-02-29 21:00:09	6074176	----a-w-	C:\Windows\System32\nvcpl.dll<br />
2012-02-29 20:59:47	889664	----a-w-	C:\Windows\System32\nvvsvc.exe<br />
2012-02-29 20:59:47	63296	----a-w-	C:\Windows\System32\nvshext.dll<br />
2012-02-29 20:59:47	118080	----a-w-	C:\Windows\System32\nvmctray.dll<br />
2012-02-29 20:59:29	2515790	----a-w-	C:\Windows\System32\nvcoproc.bin<br />
2012-02-29 10:26:56	416064	----a-w-	C:\Windows\SysWow64\nvStreaming.exe<br />
2012-02-28 06:39:37	1188864	----a-w-	C:\Windows\System32\wininet.dll<br />
2012-02-28 05:38:52	981504	----a-w-	C:\Windows\SysWow64\wininet.dll<br />
2012-02-28 04:31:38	1638912	----a-w-	C:\Windows\System32\mshtml.tlb<br />
2012-02-28 03:52:27	1638912	----a-w-	C:\Windows\SysWow64\mshtml.tlb<br />
2012-02-19 05:26:00	76888	----a-w-	C:\Windows\SysWow64\PnkBstrA.exe<br />
2012-02-17 06:38:26	1031680	----a-w-	C:\Windows\System32\rdpcore.dll<br />
2012-02-17 05:34:22	826880	----a-w-	C:\Windows\SysWow64\rdpcore.dll<br />
2012-02-17 04:58:24	210944	----a-w-	C:\Windows\System32\drivers\rdpwd.sys<br />
2012-02-17 04:57:32	23552	----a-w-	C:\Windows\System32\drivers\tdtcp.sys<br />
.<br />
============= FINISH: 23:03:11,07 ===============</div>


	<br />
	<div style="padding:6px">

	

	

	

	
		<fieldset class="fieldset">
			<legend>Attached Files</legend>
			<table cellpadding="0" cellspacing="3" border="0">
			<tr>
	<td><img class="inlineimg" src="http://forums.spybot.info/images/attach/txt.gif" alt="File Type: txt" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://forums.spybot.info/attachment.php?attachmentid=9541&amp;d=1337113484">Attach.txt</a> (7.7 KB)</td>
</tr>
			</table>
		</fieldset>
	

	</div>
]]></content:encoded>
			<category domain="http://forums.spybot.info/forumdisplay.php?f=22">Malware Removal</category>
			<dc:creator>dEgzi</dc:creator>
			<guid isPermaLink="true">http://forums.spybot.info/showthread.php?t=65911</guid>
		</item>
		<item>
			<title>Hi, just a heads up!  =)</title>
			<link>http://forums.spybot.info/showthread.php?t=65909&amp;goto=newpost</link>
			<pubDate>Mon, 14 May 2012 22:53:22 GMT</pubDate>
			<description>No rush or anything, I am pretty sure the volunteers are busy/swamped.  
So to avoid being archived, I just wanted to make a post here!  ^_^ 
...</description>
			<content:encoded><![CDATA[<div>No rush or anything, I am pretty sure the volunteers are busy/swamped. <br />
So to avoid being archived, I just wanted to make a post here!  ^_^<br />
<br />
<a href="http://forums.spybot.info/showthread.php?t=65885" target="_blank">http://forums.spybot.info/showthread.php?t=65885</a></div>

]]></content:encoded>
			<category domain="http://forums.spybot.info/forumdisplay.php?f=37">The Waiting Room</category>
			<dc:creator>Leprkon</dc:creator>
			<guid isPermaLink="true">http://forums.spybot.info/showthread.php?t=65909</guid>
		</item>
	</channel>
</rss>

