<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: VirtuMonde</title>
	<atom:link href="http://www.anti-spyware-101.com/remove-virtumonde/feed" rel="self" type="application/rss+xml" />
	<link>http://www.anti-spyware-101.com/remove-virtumonde</link>
	<description>Anti-Spyware Guide. Remove, Delete and Uninstall Spyware from your PC.</description>
	<lastBuildDate>Tue, 10 Nov 2009 18:52:33 -0500</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: vincenzo</title>
		<link>http://www.anti-spyware-101.com/remove-virtumonde/comment-page-1#comment-133020</link>
		<dc:creator>vincenzo</dc:creator>
		<pubDate>Sat, 24 Jan 2009 21:17:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.anti-spyware-101.com/remove-virtumonde#comment-133020</guid>
		<description>PLEASE HELP ME ! what shall i delete?

Logfile of HijackThis v1.99.0
Scan saved at 21.43.47, on 24/01/2009
Platform: Unknown Windows (WinNT 6.00.1905 SP1)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe
C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe
C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Synaptics\SynTP\SynToshiba.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
C:\Program Files\TOSHIBA\Toshiba Online Product Information\TOPI.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\TOSHIBA\Registration\ToshibaRegistration.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Windows\V0400Mon.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Creative\Creative Live! Cam\Live! Cam Manager\CTLCMgr.exe
C:\Program Files\Spybot - Search &amp; Destroy\TeaTimer.exe
C:\Users\Vincenzo\AppData\Local\qswsgiu.exe
C:\Program Files\WIBUKEY\Server\WkSvMgr.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe
C:\Program Files\eMule\emule.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Program Files\uTorrent\uTorrent.exe
C:\Windows\system32\WgaTray.exe
C:\Program Files\Mozilla Firefox 3.1 Beta 2\firefox.exe
C:\Users\Vincenzo\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://it.msn.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = 
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = 
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = 
R3 - URLSearchHook: P2P Max IT Toolbar - {d22b76bb-abbd-4eb6-9bbb-f387bf27f76b} - C:\Program Files\P2P_Max_IT\tbP2P_.dll
R3 - URLSearchHook: Softonic Italia Toolbar - {4edd5c14-2d22-4d7a-9748-c975a7fd933b} - C:\Program Files\Softonic_Italia\tbSoft.dll
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Softonic Italia Toolbar - {4edd5c14-2d22-4d7a-9748-c975a7fd933b} - C:\Program Files\Softonic_Italia\tbSoft.dll
O2 - BHO: Spybot-S&amp;D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Guida per l&#039;accesso a Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: P2P Max IT Toolbar - {d22b76bb-abbd-4eb6-9bbb-f387bf27f76b} - C:\Program Files\P2P_Max_IT\tbP2P_.dll
O3 - Toolbar: P2P Max IT Toolbar - {d22b76bb-abbd-4eb6-9bbb-f387bf27f76b} - C:\Program Files\P2P_Max_IT\tbP2P_.dll
O3 - Toolbar: Softonic Italia Toolbar - {4edd5c14-2d22-4d7a-9748-c975a7fd933b} - C:\Program Files\Softonic_Italia\tbSoft.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
O4 - HKLM\..\Run: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON.exe
O4 - HKLM\..\Run: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
O4 - HKLM\..\Run: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
O4 - HKLM\..\Run: [topi] C:\Program Files\TOSHIBA\Toshiba Online Product Information\topi.exe -startup
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [Toshiba Registration] C:\Program Files\Toshiba\Registration\ToshibaRegistration.exe
O4 - HKLM\..\Run: [GrooveMonitor] &quot;C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe&quot;
O4 - HKLM\..\Run: [V0400Mon.exe] C:\Windows\V0400Mon.exe
O4 - HKLM\..\Run: [QuickTime Task] &quot;C:\Program Files\QuickTime\QTTask.exe&quot; -atboottime
O4 - HKLM\..\Run: [C:\Windows\system32\V0400Cvw.dll] C:\Windows\system32\RegSvr32.exe /s C:\Windows\system32\V0400Cvw.dll
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] &quot;C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe&quot;
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
O4 - HKCU\..\Run: [MsnMsgr] &quot;C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe&quot; /background
O4 - HKCU\..\Run: [Creative Live! Cam Manager] &quot;C:\Program Files\Creative\Creative Live! Cam\Live! Cam Manager\CTLCMgr.exe&quot;
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search &amp; Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [qswsgiu] &quot;c:\users\vincenzo\appdata\local\qswsgiu.exe&quot; qswsgiu
O4 - Global Startup: Server di rete.lnk = C:\Program Files\WIBUKEY\Server\WkSvMgr.exe
O8 - Extra context menu item: E&amp;sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
O9 - Extra &#039;Tools&#039; menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
O9 - Extra button: Inserisci blog - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra &#039;Tools&#039; menuitem: Inserisci &amp;blog in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Invia a OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra &#039;Tools&#039; menuitem: I&amp;nvia a OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: eBay - {C08CAF1D-C0A3-40D5-9970-06D067EAC017} - http://www.webtip.ch/cgi-bin/toshiba/tracker_url.pl?IT (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra &#039;Tools&#039; menuitem: Spybot - Search &amp; Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nlaapi.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\napinsp.dll
O11 - Options group: [INTERNATIONAL] International*
O13 - Gopher Prefix: 
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: wlmailhtml - {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O23 - Service: Agere Modem Call Progress Audio - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: avast! iAVS4 Control Service - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: ConfigFree Service - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: Symantec Lic NetConnect service - Unknown - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: @%SystemRoot%\ehome\ehstart.dll,-101 - Unknown - %windir%\system32\svchost.exe (file missing)
O23 - Service: InstallDriver Table Manager - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: @%SystemRoot%\system32\qwave.dll,-1 - Unknown - %windir%\system32\svchost.exe (file missing)
O23 - Service: @%SystemRoot%\system32\seclogon.dll,-7001 - Unknown - %windir%\system32\svchost.exe (file missing)
O23 - Service: TOSHIBA Optical Disc Drive Service - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe
O23 - Service: TOSHIBA Power Saver - TOSHIBA Corporation - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
O23 - Service: Ulead Burning Helper - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 - Unknown - %ProgramFiles%\Windows Media Player\wmpnetwk.exe (file missing)</description>
		<content:encoded><![CDATA[<p>PLEASE HELP ME ! what shall i delete?</p>
<p>Logfile of HijackThis v1.99.0<br />
Scan saved at 21.43.47, on 24/01/2009<br />
Platform: Unknown Windows (WinNT 6.00.1905 SP1)<br />
MSIE: Internet Explorer v7.00 (7.00.6001.18000)</p>
<p>Running processes:<br />
C:\Windows\system32\Dwm.exe<br />
C:\Windows\system32\taskeng.exe<br />
C:\Windows\Explorer.EXE<br />
C:\Program Files\Windows Defender\MSASCui.exe<br />
C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe<br />
C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe<br />
C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe<br />
C:\Windows\System32\rundll32.exe<br />
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br />
C:\Program Files\Synaptics\SynTP\SynToshiba.exe<br />
C:\Windows\RtHDVCpl.exe<br />
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe<br />
C:\Program Files\TOSHIBA\Toshiba Online Product Information\TOPI.exe<br />
C:\Windows\System32\igfxtray.exe<br />
C:\Windows\System32\hkcmd.exe<br />
C:\Windows\System32\igfxpers.exe<br />
C:\Program Files\TOSHIBA\Registration\ToshibaRegistration.exe<br />
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe<br />
C:\Windows\V0400Mon.exe<br />
C:\Program Files\Alwil Software\Avast4\ashDisp.exe<br />
C:\Program Files\Windows Sidebar\sidebar.exe<br />
C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe<br />
C:\Program Files\Windows Live\Messenger\msnmsgr.exe<br />
C:\Program Files\Creative\Creative Live! Cam\Live! Cam Manager\CTLCMgr.exe<br />
C:\Program Files\Spybot &#8211; Search &amp; Destroy\TeaTimer.exe<br />
C:\Users\Vincenzo\AppData\Local\qswsgiu.exe<br />
C:\Program Files\WIBUKEY\Server\WkSvMgr.exe<br />
C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe<br />
C:\Program Files\eMule\emule.exe<br />
C:\Program Files\Windows Media Player\wmpnscfg.exe<br />
C:\Program Files\Windows Media Player\wmplayer.exe<br />
C:\Program Files\uTorrent\uTorrent.exe<br />
C:\Windows\system32\WgaTray.exe<br />
C:\Program Files\Mozilla Firefox 3.1 Beta 2\firefox.exe<br />
C:\Users\Vincenzo\Desktop\HijackThis.exe</p>
<p>R1 &#8211; HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" rel="nofollow">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 &#8211; HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://it.msn.com" rel="nofollow">http://it.msn.com</a><br />
R1 &#8211; HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" rel="nofollow">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R1 &#8211; HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" rel="nofollow">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 &#8211; HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" rel="nofollow">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 &#8211; HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://go.microsoft.com/fwlink/?LinkId=69157" rel="nofollow">http://go.microsoft.com/fwlink/?LinkId=69157</a><br />
R0 &#8211; HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =<br />
R0 &#8211; HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =<br />
R0 &#8211; HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =<br />
R3 &#8211; URLSearchHook: P2P Max IT Toolbar &#8211; {d22b76bb-abbd-4eb6-9bbb-f387bf27f76b} &#8211; C:\Program Files\P2P_Max_IT\tbP2P_.dll<br />
R3 &#8211; URLSearchHook: Softonic Italia Toolbar &#8211; {4edd5c14-2d22-4d7a-9748-c975a7fd933b} &#8211; C:\Program Files\Softonic_Italia\tbSoft.dll<br />
O1 &#8211; Hosts: ::1 localhost<br />
O2 &#8211; BHO: AcroIEHelperStub &#8211; {18DF081C-E8AD-4283-A596-FA578C2EBDC3} &#8211; C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll<br />
O2 &#8211; BHO: Softonic Italia Toolbar &#8211; {4edd5c14-2d22-4d7a-9748-c975a7fd933b} &#8211; C:\Program Files\Softonic_Italia\tbSoft.dll<br />
O2 &#8211; BHO: Spybot-S&amp;D IE Protection &#8211; {53707962-6F74-2D53-2644-206D7942484F} &#8211; C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O2 &#8211; BHO: Groove GFS Browser Helper &#8211; {72853161-30C5-4D22-B7F9-0BBC1D38A37E} &#8211; C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll<br />
O2 &#8211; BHO: SSVHelper Class &#8211; {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} &#8211; C:\Program Files\Java\jre1.6.0\bin\ssv.dll<br />
O2 &#8211; BHO: (no name) &#8211; {7E853D72-626A-48EC-A868-BA8D5E23E045} &#8211; (no file)<br />
O2 &#8211; BHO: Guida per l&#8217;accesso a Windows Live &#8211; {9030D464-4C02-4ABF-8ECC-5164760863C6} &#8211; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
O2 &#8211; BHO: P2P Max IT Toolbar &#8211; {d22b76bb-abbd-4eb6-9bbb-f387bf27f76b} &#8211; C:\Program Files\P2P_Max_IT\tbP2P_.dll<br />
O3 &#8211; Toolbar: P2P Max IT Toolbar &#8211; {d22b76bb-abbd-4eb6-9bbb-f387bf27f76b} &#8211; C:\Program Files\P2P_Max_IT\tbP2P_.dll<br />
O3 &#8211; Toolbar: Softonic Italia Toolbar &#8211; {4edd5c14-2d22-4d7a-9748-c975a7fd933b} &#8211; C:\Program Files\Softonic_Italia\tbSoft.dll<br />
O4 &#8211; HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide<br />
O4 &#8211; HKLM\..\Run: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE<br />
O4 &#8211; HKLM\..\Run: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON.exe<br />
O4 &#8211; HKLM\..\Run: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe<br />
O4 &#8211; HKLM\..\Run: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe<br />
O4 &#8211; HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart<br />
O4 &#8211; HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup<br />
O4 &#8211; HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit<br />
O4 &#8211; HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br />
O4 &#8211; HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe<br />
O4 &#8211; HKLM\..\Run: [NDSTray.exe] NDSTray.exe<br />
O4 &#8211; HKLM\..\Run: [topi] C:\Program Files\TOSHIBA\Toshiba Online Product Information\topi.exe -startup<br />
O4 &#8211; HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe<br />
O4 &#8211; HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe<br />
O4 &#8211; HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe<br />
O4 &#8211; HKLM\..\Run: [Toshiba Registration] C:\Program Files\Toshiba\Registration\ToshibaRegistration.exe<br />
O4 &#8211; HKLM\..\Run: [GrooveMonitor] &#8220;C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe&#8221;<br />
O4 &#8211; HKLM\..\Run: [V0400Mon.exe] C:\Windows\V0400Mon.exe<br />
O4 &#8211; HKLM\..\Run: [QuickTime Task] &#8220;C:\Program Files\QuickTime\QTTask.exe&#8221; -atboottime<br />
O4 &#8211; HKLM\..\Run: [C:\Windows\system32\V0400Cvw.dll] C:\Windows\system32\RegSvr32.exe /s C:\Windows\system32\V0400Cvw.dll<br />
O4 &#8211; HKLM\..\Run: [Adobe Reader Speed Launcher] &#8220;C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe&#8221;<br />
O4 &#8211; HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe<br />
O4 &#8211; HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe<br />
O4 &#8211; HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun<br />
O4 &#8211; HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter<br />
O4 &#8211; HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe<br />
O4 &#8211; HKCU\..\Run: [MsnMsgr] &#8220;C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe&#8221; /background<br />
O4 &#8211; HKCU\..\Run: [Creative Live! Cam Manager] &#8220;C:\Program Files\Creative\Creative Live! Cam\Live! Cam Manager\CTLCMgr.exe&#8221;<br />
O4 &#8211; HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot &#8211; Search &amp; Destroy\TeaTimer.exe<br />
O4 &#8211; HKCU\..\Run: [qswsgiu] &#8220;c:\users\vincenzo\appdata\local\qswsgiu.exe&#8221; qswsgiu<br />
O4 &#8211; Global Startup: Server di rete.lnk = C:\Program Files\WIBUKEY\Server\WkSvMgr.exe<br />
O8 &#8211; Extra context menu item: E&amp;sporta in Microsoft Excel &#8211; res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000<br />
O9 &#8211; Extra button: (no name) &#8211; {08B0E5C0-4FCB-11CF-AAA5-00401C608501} &#8211; C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll<br />
O9 &#8211; Extra &#8216;Tools&#8217; menuitem: Sun Java Console &#8211; {08B0E5C0-4FCB-11CF-AAA5-00401C608501} &#8211; C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll<br />
O9 &#8211; Extra button: Inserisci blog &#8211; {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} &#8211; C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll<br />
O9 &#8211; Extra &#8216;Tools&#8217; menuitem: Inserisci &amp;blog in Windows Live Writer &#8211; {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} &#8211; C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll<br />
O9 &#8211; Extra button: Invia a OneNote &#8211; {2670000A-7350-4f3c-8081-5663EE0C6C49} &#8211; C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll<br />
O9 &#8211; Extra &#8216;Tools&#8217; menuitem: I&amp;nvia a OneNote &#8211; {2670000A-7350-4f3c-8081-5663EE0C6C49} &#8211; C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll<br />
O9 &#8211; Extra button: Research &#8211; {92780B25-18CC-41C8-B9BE-3C9C571A8263} &#8211; C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL<br />
O9 &#8211; Extra button: eBay &#8211; {C08CAF1D-C0A3-40D5-9970-06D067EAC017} &#8211; <a href="http://www.webtip.ch/cgi-bin/toshiba/tracker_url.pl?IT" rel="nofollow">http://www.webtip.ch/cgi-bin/toshiba/tracker_url.pl?IT</a> (file missing)<br />
O9 &#8211; Extra button: (no name) &#8211; {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} &#8211; C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O9 &#8211; Extra &#8216;Tools&#8217; menuitem: Spybot &#8211; Search &amp; Destroy Configuration &#8211; {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} &#8211; C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />
O10 &#8211; Unknown file in Winsock LSP: c:\windows\system32\nlaapi.dll<br />
O10 &#8211; Unknown file in Winsock LSP: c:\windows\system32\napinsp.dll<br />
O11 &#8211; Options group: [INTERNATIONAL] International*<br />
O13 &#8211; Gopher Prefix:<br />
O16 &#8211; DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) &#8211; <a href="http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab" rel="nofollow">http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab</a><br />
O16 &#8211; DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) &#8211; <a href="http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab" rel="nofollow">http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab</a><br />
O18 &#8211; Protocol: grooveLocalGWS &#8211; {88FED34C-F0CA-4636-A375-3CB6248B04CD} &#8211; C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll<br />
O18 &#8211; Protocol: livecall &#8211; {828030A1-22C1-4009-854F-8E305202313F} &#8211; C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL<br />
O18 &#8211; Protocol: ms-help &#8211; {314111C7-A502-11D2-BBCA-00C04F8EC294} &#8211; C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll<br />
O18 &#8211; Protocol: msnim &#8211; {828030A1-22C1-4009-854F-8E305202313F} &#8211; C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL<br />
O18 &#8211; Protocol: wlmailhtml &#8211; {03C514A3-1EFB-4856-9F99-10D7BE1653C0} &#8211; C:\Program Files\Windows Live\Mail\mailcomm.dll<br />
O18 &#8211; Filter hijack: text/xml &#8211; {807563E5-5146-11D5-A672-00B0D022E945} &#8211; C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL<br />
O23 &#8211; Service: Agere Modem Call Progress Audio &#8211; Agere Systems &#8211; C:\Windows\system32\agrsmsvc.exe<br />
O23 &#8211; Service: avast! iAVS4 Control Service &#8211; ALWIL Software &#8211; C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe<br />
O23 &#8211; Service: avast! Antivirus &#8211; ALWIL Software &#8211; C:\Program Files\Alwil Software\Avast4\ashServ.exe<br />
O23 &#8211; Service: avast! Mail Scanner &#8211; ALWIL Software &#8211; C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe<br />
O23 &#8211; Service: avast! Web Scanner &#8211; ALWIL Software &#8211; C:\Program Files\Alwil Software\Avast4\ashWebSv.exe<br />
O23 &#8211; Service: ConfigFree Service &#8211; TOSHIBA CORPORATION &#8211; C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe<br />
O23 &#8211; Service: Symantec Lic NetConnect service &#8211; Unknown &#8211; C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)<br />
O23 &#8211; Service: @%SystemRoot%\ehome\ehstart.dll,-101 &#8211; Unknown &#8211; %windir%\system32\svchost.exe (file missing)<br />
O23 &#8211; Service: InstallDriver Table Manager &#8211; Macrovision Corporation &#8211; C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe<br />
O23 &#8211; Service: NBService &#8211; Nero AG &#8211; C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe<br />
O23 &#8211; Service: @%SystemRoot%\system32\qwave.dll,-1 &#8211; Unknown &#8211; %windir%\system32\svchost.exe (file missing)<br />
O23 &#8211; Service: @%SystemRoot%\system32\seclogon.dll,-7001 &#8211; Unknown &#8211; %windir%\system32\svchost.exe (file missing)<br />
O23 &#8211; Service: TOSHIBA Optical Disc Drive Service &#8211; TOSHIBA Corporation &#8211; C:\Windows\system32\TODDSrv.exe<br />
O23 &#8211; Service: TOSHIBA Power Saver &#8211; TOSHIBA Corporation &#8211; C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe<br />
O23 &#8211; Service: TOSHIBA Bluetooth Service &#8211; TOSHIBA CORPORATION &#8211; c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe<br />
O23 &#8211; Service: Ulead Burning Helper &#8211; Ulead Systems, Inc. &#8211; C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe<br />
O23 &#8211; Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 &#8211; Unknown &#8211; %ProgramFiles%\Windows Media Player\wmpnetwk.exe (file missing)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: colin reese</title>
		<link>http://www.anti-spyware-101.com/remove-virtumonde/comment-page-1#comment-29858</link>
		<dc:creator>colin reese</dc:creator>
		<pubDate>Tue, 23 Sep 2008 22:19:35 +0000</pubDate>
		<guid isPermaLink="false">http://www.anti-spyware-101.com/remove-virtumonde#comment-29858</guid>
		<description>hi

when running spybot it spends hours going through &quot;virtumonde&quot;   but does not list the files as problems to be solved at the end of the analysis.

does this mean that the virtumonde is benign or should I remove it anyway ...   ?

Thanks

Colin</description>
		<content:encoded><![CDATA[<p>hi</p>
<p>when running spybot it spends hours going through &#8220;virtumonde&#8221;   but does not list the files as problems to be solved at the end of the analysis.</p>
<p>does this mean that the virtumonde is benign or should I remove it anyway &#8230;   ?</p>
<p>Thanks</p>
<p>Colin</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: david</title>
		<link>http://www.anti-spyware-101.com/remove-virtumonde/comment-page-1#comment-17691</link>
		<dc:creator>david</dc:creator>
		<pubDate>Tue, 25 Sep 2007 03:51:37 +0000</pubDate>
		<guid isPermaLink="false">http://www.anti-spyware-101.com/remove-virtumonde#comment-17691</guid>
		<description>thank you</description>
		<content:encoded><![CDATA[<p>thank you</p>
]]></content:encoded>
	</item>
</channel>
</rss>
