<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://en.community.dell.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Virus &amp; Spyware Discussions</title><link>http://en.community.dell.com/forums/3522.aspx</link><description>Virus &amp; Spyware Sub-Board</description><dc:language /><generator>CommunityServer 2008.5 SP2 (Build: 40407.4157)</generator><item><title>Re: Please Help Rundll error and Virus</title><link>http://en.community.dell.com/forums/thread/19376895.aspx</link><pubDate>Mon, 24 Nov 2008 00:40:29 GMT</pubDate><guid isPermaLink="false">e3197daa-ef0d-4a70-8402-29215ff9a0f2:19376895</guid><dc:creator>ccteach</dc:creator><slash:comments>0</slash:comments><comments>http://en.community.dell.com/forums/thread/19376895.aspx</comments><wfw:commentRss>http://en.community.dell.com/forums/commentrss.aspx?SectionID=3522&amp;PostID=19376895</wfw:commentRss><description>&lt;p&gt;Hi! Thanks! Do you know how long it will take for assistance? My response hasn&amp;#39;t been replied to yet.&amp;nbsp; &lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Re: Please Help Rundll error and Virus</title><link>http://en.community.dell.com/forums/thread/19376759.aspx</link><pubDate>Sun, 23 Nov 2008 20:54:26 GMT</pubDate><guid isPermaLink="false">e3197daa-ef0d-4a70-8402-29215ff9a0f2:19376759</guid><dc:creator>Bugbatter</dc:creator><slash:comments>0</slash:comments><comments>http://en.community.dell.com/forums/thread/19376759.aspx</comments><wfw:commentRss>http://en.community.dell.com/forums/commentrss.aspx?SectionID=3522&amp;PostID=19376759</wfw:commentRss><description>&lt;p&gt;As long as you have posted both the MBAM log and the HJT log, one of the analysts will pick it as soon as possible.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Re: Please Help Rundll error and Virus</title><link>http://en.community.dell.com/forums/thread/19376732.aspx</link><pubDate>Sun, 23 Nov 2008 19:50:53 GMT</pubDate><guid isPermaLink="false">e3197daa-ef0d-4a70-8402-29215ff9a0f2:19376732</guid><dc:creator>ccteach</dc:creator><slash:comments>0</slash:comments><comments>http://en.community.dell.com/forums/thread/19376732.aspx</comments><wfw:commentRss>http://en.community.dell.com/forums/commentrss.aspx?SectionID=3522&amp;PostID=19376732</wfw:commentRss><description>&lt;p&gt;I did post earlier in the malware thread...do I need to do another Hijack scan?&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Re: Please Help Rundll error and Virus</title><link>http://en.community.dell.com/forums/thread/19376727.aspx</link><pubDate>Sun, 23 Nov 2008 19:30:06 GMT</pubDate><guid isPermaLink="false">e3197daa-ef0d-4a70-8402-29215ff9a0f2:19376727</guid><dc:creator>Bugbatter</dc:creator><slash:comments>0</slash:comments><comments>http://en.community.dell.com/forums/thread/19376727.aspx</comments><wfw:commentRss>http://en.community.dell.com/forums/commentrss.aspx?SectionID=3522&amp;PostID=19376727</wfw:commentRss><description>&lt;p&gt;Welcome&lt;img src="http://en.community.dell.com/emoticons/emotion-1.gif" alt="Smile" /&gt;&lt;/p&gt;
&lt;p&gt;Please post your logs on the Malware Removal forum.&lt;/p&gt;
&lt;li&gt;The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Copy and paste the entire report into a New Message on the Malware Removal forum. Also include a fresh HijackThis log.&lt;br /&gt;1. Just click the Start A New Thread button (upper right) in the Malware Removal forum here: &lt;/strong&gt;&lt;strong&gt;&lt;a href="http://en.community.dell.com/forums/3521.aspx%20"&gt;http://en.community.dell.com/forums/3521.aspx&lt;br /&gt;&lt;/a&gt;to start your own thread requesting assistance.&lt;br /&gt;2. In the discussion window that opens, simply Right-Click and select Paste.&lt;br /&gt;&lt;/strong&gt;&lt;/li&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Please Help Rundll error and Virus</title><link>http://en.community.dell.com/forums/thread/19376642.aspx</link><pubDate>Sun, 23 Nov 2008 17:13:00 GMT</pubDate><guid isPermaLink="false">e3197daa-ef0d-4a70-8402-29215ff9a0f2:19376642</guid><dc:creator>ccteach</dc:creator><slash:comments>0</slash:comments><comments>http://en.community.dell.com/forums/thread/19376642.aspx</comments><wfw:commentRss>http://en.community.dell.com/forums/commentrss.aspx?SectionID=3522&amp;PostID=19376642</wfw:commentRss><description>&lt;p&gt;Hi!&lt;/p&gt;
&lt;p&gt;&lt;br /&gt;When I start up my Windows I have a Rundll error that continues
to open.&amp;nbsp; I have Malwarebytes Anti-Malware installed on my system and
it has located an infected virus that doesn&amp;#39;t delete itself from my
system even after I reboot. The malware identified Trojan.agent HKEY
_local... Motovotuza.&amp;nbsp; Please Help! Thanks&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;O4 - HKLM\..\Run: [motovotuza] Rundll32.exe &amp;quot;C:\WINDOWS\system32\misogija.dll&amp;quot;,s&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;O4 - HKUS\S-1-5-19\..\Run: [motovotuza] Rundll32.exe &amp;quot;C:\WINDOWS\system32\misogija.dll&amp;quot;,s (User &amp;#39;LOCAL SERVICE&amp;#39;)&lt;br /&gt;
O4 - HKUS\S-1-5-20\..\Run: [motovotuza] Rundll32.exe &amp;quot;C:\WINDOWS\system32\misogija.dll&amp;quot;,s (User &amp;#39;NETWORK SERVICE&amp;#39;)&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Logfile of Trend Micro HijackThis v2.0.2&lt;br /&gt;Scan saved at 11:33:14 AM, on 11/23/2008&lt;br /&gt;Platform: Windows XP SP3 (WinNT 5.01.2600)&lt;br /&gt;MSIE: Internet Explorer v7.00 (7.00.6000.16735)&lt;br /&gt;Boot mode: Normal&lt;br /&gt;&lt;br /&gt;Running processes:&lt;br /&gt;C:\WINDOWS\System32\smss.exe&lt;br /&gt;C:\WINDOWS\system32\winlogon.exe&lt;br /&gt;C:\WINDOWS\system32\services.exe&lt;br /&gt;C:\WINDOWS\system32\lsass.exe&lt;br /&gt;C:\WINDOWS\system32\svchost.exe&lt;br /&gt;C:\WINDOWS\System32\svchost.exe&lt;br /&gt;C:\Program Files\Intel\Wireless\Bin\EvtEng.exe&lt;br /&gt;C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe&lt;br /&gt;C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe&lt;br /&gt;C:\WINDOWS\system32\spoolsv.exe&lt;br /&gt;C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe&lt;br /&gt;C:\Program Files\Bonjour\mDNSResponder.exe&lt;br /&gt;C:\Program Files\Java\jre6\bin\jqs.exe&lt;br /&gt;C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe&lt;br /&gt;C:\WINDOWS\Explorer.EXE&lt;br /&gt;C:\Program Files\Apoint\Apoint.exe&lt;br /&gt;C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe&lt;br /&gt;C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe&lt;br /&gt;C:\Program Files\Java\jre6\bin\jusched.exe&lt;br /&gt;C:\WINDOWS\system32\hkcmd.exe&lt;br /&gt;C:\WINDOWS\system32\igfxpers.exe&lt;br /&gt;C:\Program Files\Apoint\HidFind.exe&lt;br /&gt;C:\Program Files\Apoint\Apntex.exe&lt;br /&gt;C:\Program Files\iTunes\iTunesHelper.exe&lt;br /&gt;C:\WINDOWS\system32\ctfmon.exe&lt;br /&gt;C:\Program Files\Veoh Networks\Veoh\VeohClient.exe&lt;br /&gt;C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe&lt;br /&gt;C:\Program Files\iPod\bin\iPodService.exe&lt;br /&gt;C:\Program Files\Malwarebytes&amp;#39; Anti-Malware\mbam.exe&lt;br /&gt;C:\Program Files\Mozilla Firefox\firefox.exe&lt;br /&gt;C:\WINDOWS\system32\NOTEPAD.EXE&lt;br /&gt;C:\Program Files\Trend Micro\HijackThis\HijackThis.exe&lt;br /&gt;&lt;br /&gt;R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896&lt;br /&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157&lt;br /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157&lt;br /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896&lt;br /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896&lt;br /&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157&lt;br /&gt;R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/&lt;br /&gt;R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local&lt;br /&gt;O2
- BHO: Adobe PDF Reader Link Helper -
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common
Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll&lt;br /&gt;O2 - BHO: (no name) - {0e60fe57-f2c2-4b79-8af8-ec9eaa71b3d4} - C:\WINDOWS\system32\fumikowu.dll (file missing)&lt;br /&gt;O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll&lt;br /&gt;O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll&lt;br /&gt;O2
- BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C}
- C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll&lt;br /&gt;O3 -
Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263}
- C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll&lt;br /&gt;O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe&lt;br /&gt;O4 - HKLM\..\Run: [IntelZeroConfig] &amp;quot;C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [IntelWireless] &amp;quot;C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe&amp;quot; /tf Intel PROSet/Wireless&lt;br /&gt;O4 - HKLM\..\Run: [SunJavaUpdateSched] &amp;quot;C:\Program Files\Java\jre6\bin\jusched.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe&lt;br /&gt;O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe&lt;br /&gt;O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe&lt;br /&gt;O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] &amp;quot;C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [QuickTime Task] &amp;quot;C:\Program Files\QuickTime\QTTask.exe&amp;quot; -atboottime&lt;br /&gt;O4 - HKLM\..\Run: [iTunesHelper] &amp;quot;C:\Program Files\iTunes\iTunesHelper.exe&amp;quot;&lt;br /&gt;O4 - HKLM\..\Run: [motovotuza] Rundll32.exe &amp;quot;C:\WINDOWS\system32\misogija.dll&amp;quot;,s&lt;br /&gt;O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe&lt;br /&gt;O4 - HKCU\..\Run: [Veoh] &amp;quot;C:\Program Files\Veoh Networks\Veoh\VeohClient.exe&amp;quot; /VeohHide&lt;br /&gt;O4 - HKUS\S-1-5-19\..\Run: [motovotuza] Rundll32.exe &amp;quot;C:\WINDOWS\system32\misogija.dll&amp;quot;,s (User &amp;#39;LOCAL SERVICE&amp;#39;)&lt;br /&gt;O4 - HKUS\S-1-5-20\..\Run: [motovotuza] Rundll32.exe &amp;quot;C:\WINDOWS\system32\misogija.dll&amp;quot;,s (User &amp;#39;NETWORK SERVICE&amp;#39;)&lt;br /&gt;O8 - Extra context menu item: E&amp;amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000&lt;br /&gt;O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL&lt;br /&gt;O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;br /&gt;O9
- Extra &amp;#39;Tools&amp;#39; menuitem: @xpsp3res.dll,-20001 -
{e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network
Diagnostic\xpnetdiag.exe&lt;br /&gt;O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;br /&gt;O9 - Extra &amp;#39;Tools&amp;#39; menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;br /&gt;O20 - AppInit_DLLs: C:\WINDOWS\system32\poyejame.dll &lt;br /&gt;O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\480\G2AWinLogon.dll&lt;br /&gt;O23
- Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common
Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe&lt;br /&gt;O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe&lt;br /&gt;O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe&lt;br /&gt;O23
- Service: GoToAssist - Citrix Online, a division of Citrix Systems,
Inc. - C:\Program Files\Citrix\GoToAssist\480\g2aservice.exe&lt;br /&gt;O23 -
Service: InstallDriver Table Manager (IDriverT) - Macrovision
Corporation - C:\Program Files\Common
Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe&lt;br /&gt;O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe&lt;br /&gt;O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe&lt;br /&gt;O23
- Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel
Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe&lt;br /&gt;O23 -
Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel
Corporation&amp;nbsp; - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe&lt;br /&gt;O23
- Service: Intel(R) PROSet/Wireless SSO Service (WLANKEEPER) - Intel(R)
Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe&lt;br /&gt;&lt;br /&gt;--&lt;br /&gt;End of file - 6699 bytes&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>