<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.3.3" -->
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>
<channel>
	<title>Comments on: Pest Trap - new rogue anti spyware</title>
	<link>http://www.myantispyware.com/2006/01/19/pest-trap-new-rogue-anti-spyware/</link>
	<description>Spyware news, discussions, forums, Anti Spyware Tools, Online Scanners, HowTOs, removal instructions about spyware, adware, trojans, worms.</description>
	<pubDate>Fri, 16 May 2008 04:08:45 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.3.3</generator>
		<item>
		<title>By: Patrik</title>
		<link>http://www.myantispyware.com/2006/01/19/pest-trap-new-rogue-anti-spyware/#comment-194</link>
		<dc:creator>Patrik</dc:creator>
		<pubDate>Mon, 06 Mar 2006 16:25:16 +0000</pubDate>
		<guid>http://www.myantispyware.com/2006/01/19/pest-trap-new-rogue-anti-spyware/#comment-194</guid>
		<description>ok, only please post your log to the &lt;a href="http://www.myantispyware.com/forum/viewforum.php?f=4" rel="nofollow"&gt;Forum - Spyware Removal&lt;/a&gt;</description>
		<content:encoded><![CDATA[<p>ok, only please post your log to the <a href="http://www.myantispyware.com/forum/viewforum.php?f=4" rel="nofollow">Forum - Spyware Removal</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: capt.pearl</title>
		<link>http://www.myantispyware.com/2006/01/19/pest-trap-new-rogue-anti-spyware/#comment-188</link>
		<dc:creator>capt.pearl</dc:creator>
		<pubDate>Mon, 06 Mar 2006 04:06:08 +0000</pubDate>
		<guid>http://www.myantispyware.com/2006/01/19/pest-trap-new-rogue-anti-spyware/#comment-188</guid>
		<description>pls excuse the "me too" post, but me too.

I ran smitRem and that seems to have helped a lot.

I ran Panda ActiveScan:
Panda ActiveScan5.52.00
Incident Status Location                                                                                                                                                                                                                                                        

Spyware:Cookie/2o7.net  Not disinfected  C:\Documents and Settings\Melissa\Cookies\melissa@2o7[2].txt                                                                                                                                                                                                    
Adware:Adware/PsGuard  Not disinfected C:\Documents and Settings\LocalService\Application Data\Microsoft\Internet Explorer\Desktop.htt                                                                                                                                                                 
Spyware:Cookie/2o7.net Not disinfected C:\Documents and Settings\Melissa\Cookies\melissa@2o7[2].txt                                                                                                                                                                                                    
Potentially unwanted tool:Application/Processor  Not disinfected C:\Documents and Settings\Melissa\Desktop\smitRem\Process.exe                                                                                                                                                                                                   
Potentially unwanted tool:Application/Processor  Not disinfected C:\Documents and Settings\Melissa\Desktop\smitRem.exe[Process.exe]                                                                                                                                                                                              
Virus:W32/Smitfraud.E  Not disinfected  C:\WINDOWS\$NtUninstallKB896727-IE6SP1-20050719.165959$\wininet.dll                                                                                                                                                                                             
Adware:Adware/PsGuard  Not disinfected  C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\Internet Explorer\Desktop.htt                                                                                                                                                               
Spyware:Spyware/Zhopa  Not disinfected  C:\~WRF0409.tmp                                                                                                                                                                                                                                                 
I also ran HijackThis:
Logfile of HijackThis v1.99.1
Scan saved at 9:27:39 PM, on 3/5/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\atievxx.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\mcshield.exe
C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Juno6\zCast.exe
C:\Program Files\Juno6\chkras.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Fix-It Programs\Hijack This\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://my.juno.com/s/search?r=minisearch
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://my.juno.com/s/search?r=minisearch
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = 
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://my.juno.com/s/search?r=minisearch
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://my.juno.com/s/search?r=minisearch
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://my.juno.com/s/search?r=minisearch
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://my.juno.com/s/search?r=minisearch
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = 
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://my.juno.com/s/sp?r=al&#38;cf=sp&#38;mem=geokp&#38;key=519c911024d1f2e25dfa8f014cd610b5&#38;ts=3fec9668&#38;A=264339310000729&#38;B=1049097600000&#38;C=1049097600000&#38;D=0&#38;I=6.1.4JU&#38;L=g%236&#38;M=1049097600000&#38;N=PLOC&#38;O=I
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = 
R3 - URLSearchHook: URLSearchHook Class - {37D2CDBF-2AF4-44AA-8113-BD0D2DA3C2B8} - C:\Program Files\JUSearch\SearchEnh1.dll
F2 - REG:system.ini: Shell=Explorer.exe, msmsgs.exe
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Fix-It Programs\Spybot - Search &#38; Destroy\SDHelper.dll
O3 - Toolbar: &#38;Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe"
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKCU\..\Run: [spc_w] "C:\Program Files\JUSearch\juspc.exe" -w
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &#38;Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{3DF42833-D7BF-4B3C-A222-9191CB1A8C70}: NameServer = 64.136.28.122 64.136.20.122
O17 - HKLM\System\CCS\Services\Tcpip\..\{CA0AF209-CB06-49E7-AED6-F1AA748CCCDC}: NameServer = 209.149.56.2,209.149.56.3
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\vstskmgr.exe



Any suggestions?

Thanks,

capt.pearl</description>
		<content:encoded><![CDATA[<p>pls excuse the &#8220;me too&#8221; post, but me too.</p>
<p>I ran smitRem and that seems to have helped a lot.</p>
<p>I ran Panda ActiveScan:<br />
Panda ActiveScan5.52.00<br />
Incident Status Location                                                                                                                                                                                                                                                        </p>
<p>Spyware:Cookie/2o7.net  Not disinfected  C:\Documents and Settings\Melissa\Cookies\melissa@2o7[2].txt<br />
Adware:Adware/PsGuard  Not disinfected C:\Documents and Settings\LocalService\Application Data\Microsoft\Internet Explorer\Desktop.htt<br />
Spyware:Cookie/2o7.net Not disinfected C:\Documents and Settings\Melissa\Cookies\melissa@2o7[2].txt<br />
Potentially unwanted tool:Application/Processor  Not disinfected C:\Documents and Settings\Melissa\Desktop\smitRem\Process.exe<br />
Potentially unwanted tool:Application/Processor  Not disinfected C:\Documents and Settings\Melissa\Desktop\smitRem.exe[Process.exe]<br />
Virus:W32/Smitfraud.E  Not disinfected  C:\WINDOWS\$NtUninstallKB896727-IE6SP1-20050719.165959$\wininet.dll<br />
Adware:Adware/PsGuard  Not disinfected  C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\Internet Explorer\Desktop.htt<br />
Spyware:Spyware/Zhopa  Not disinfected  C:\~WRF0409.tmp<br />
I also ran HijackThis:<br />
Logfile of HijackThis v1.99.1<br />
Scan saved at 9:27:39 PM, on 3/5/2006<br />
Platform: Windows XP SP1 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)</p>
<p>Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\WINDOWS\System32\atievxx.exe<br />
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe<br />
C:\Program Files\Network Associates\VirusScan\mcshield.exe<br />
C:\Program Files\Network Associates\VirusScan\vstskmgr.exe<br />
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE<br />
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe<br />
C:\Program Files\Apoint\Apoint.exe<br />
C:\Program Files\Apoint\Apntex.exe<br />
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe<br />
C:\Program Files\Juno6\zCast.exe<br />
C:\Program Files\Juno6\chkras.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\Program Files\Fix-It Programs\Hijack This\HijackThis.exe</p>
<p>R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = <a href="http://my.juno.com/s/search?r=minisearch" rel="nofollow">http://my.juno.com/s/search?r=minisearch</a><br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://my.juno.com/s/search?r=minisearch" rel="nofollow">http://my.juno.com/s/search?r=minisearch</a><br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =<br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://my.juno.com/s/search?r=minisearch" rel="nofollow">http://my.juno.com/s/search?r=minisearch</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://my.juno.com/s/search?r=minisearch" rel="nofollow">http://my.juno.com/s/search?r=minisearch</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = <a href="http://my.juno.com/s/search?r=minisearch" rel="nofollow">http://my.juno.com/s/search?r=minisearch</a><br />
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = <a href="http://my.juno.com/s/search?r=minisearch" rel="nofollow">http://my.juno.com/s/search?r=minisearch</a><br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =<br />
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = <a href="http://my.juno.com/s/sp?r=al&amp;cf=sp&amp;mem=geokp&amp;key=519c911024d1f2e25dfa8f014cd610b5&amp;ts=3fec9668&amp;A=264339310000729&amp;B=1049097600000&amp;C=1049097600000&amp;D=0&amp;I=6.1.4JU&amp;L=g%236&amp;M=1049097600000&amp;N=PLOC&amp;O=I" rel="nofollow">http://my.juno.com/s/sp?r=al&amp;cf=sp&amp;mem=geokp&amp;key=519c911024d1f2e25dfa8f014cd610b5&amp;ts=3fec9668&amp;A=264339310000729&amp;B=1049097600000&amp;C=1049097600000&amp;D=0&amp;I=6.1.4JU&amp;L=g%236&amp;M=1049097600000&amp;N=PLOC&amp;O=I</a><br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =<br />
R3 - URLSearchHook: URLSearchHook Class - {37D2CDBF-2AF4-44AA-8113-BD0D2DA3C2B8} - C:\Program Files\JUSearch\SearchEnh1.dll<br />
F2 - REG:system.ini: Shell=Explorer.exe, msmsgs.exe<br />
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Fix-It Programs\Spybot - Search &amp; Destroy\SDHelper.dll<br />
O3 - Toolbar: &amp;Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx<br />
O4 - HKLM\..\Run: [ShStatEXE] &#8220;C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE&#8221; /STANDALONE<br />
O4 - HKLM\..\Run: [McAfeeUpdaterUI] &#8220;C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe&#8221;<br />
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe<br />
O4 - HKLM\..\Run: [gcasServ] &#8220;C:\Program Files\Microsoft AntiSpyware\gcasServ.exe&#8221;<br />
O4 - HKCU\..\Run: [spc_w] &#8220;C:\Program Files\JUSearch\juspc.exe&#8221; -w<br />
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE<br />
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm<br />
O9 - Extra &#8216;Tools&#8217; menuitem: Show &amp;Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE<br />
O9 - Extra &#8216;Tools&#8217; menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE<br />
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - <a href="http://acs.pandasoftware.com/activescan/as5free/asinst.cab" rel="nofollow">http://acs.pandasoftware.com/activescan/as5free/asinst.cab</a><br />
O17 - HKLM\System\CCS\Services\Tcpip\..\{3DF42833-D7BF-4B3C-A222-9191CB1A8C70}: NameServer = 64.136.28.122 64.136.20.122<br />
O17 - HKLM\System\CCS\Services\Tcpip\..\{CA0AF209-CB06-49E7-AED6-F1AA748CCCDC}: NameServer = 209.149.56.2,209.149.56.3<br />
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe<br />
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\mcshield.exe<br />
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\vstskmgr.exe</p>
<p>Any suggestions?</p>
<p>Thanks,</p>
<p>capt.pearl</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Patrik</title>
		<link>http://www.myantispyware.com/2006/01/19/pest-trap-new-rogue-anti-spyware/#comment-143</link>
		<dc:creator>Patrik</dc:creator>
		<pubDate>Sat, 04 Feb 2006 11:16:27 +0000</pubDate>
		<guid>http://www.myantispyware.com/2006/01/19/pest-trap-new-rogue-anti-spyware/#comment-143</guid>
		<description>PandaScan found &lt;a href="http://www.myantispyware.com/2006/01/06/new-rogue-anti-spyware-spywarestrike/" &gt;SpywareStrike&lt;/a&gt;, for remove:
Download &lt;a href="http://www.myantispyware.com/2005/12/17/smitrem-remover-for-trojan-spyhtmlsmitfraudc-malware-infection-and-it%e2%80%99s-variants-antivirusgold-psguard-spyware-remover-spysheriff-spy-trooper-spyaxe-and-security-toolbar/" &gt;smitRem&lt;/a&gt; and save the file to your desktop.Double click on the file to extract it to it’s own folder on the desktop.

Reboot your computer in Safe Mode.

Open the smitRem folder, then double click the RunThis.bat file to start the tool. Follow the prompts on screen. Your desktop and icons will disappear and then reappear again — this is normal.
Wait for the tool to complete and Disk Cleanup to finish — this may take a while; please be patient.

Also install good &lt;a href="http://www.myantispyware.com/free-programs/"&gt;Free Anti Spyware Tools&lt;/a&gt;.</description>
		<content:encoded><![CDATA[<p>PandaScan found <a href="http://www.myantispyware.com/2006/01/06/new-rogue-anti-spyware-spywarestrike/" >SpywareStrike</a>, for remove:<br />
Download <a href="http://www.myantispyware.com/2005/12/17/smitrem-remover-for-trojan-spyhtmlsmitfraudc-malware-infection-and-it%e2%80%99s-variants-antivirusgold-psguard-spyware-remover-spysheriff-spy-trooper-spyaxe-and-security-toolbar/" >smitRem</a> and save the file to your desktop.Double click on the file to extract it to it’s own folder on the desktop.</p>
<p>Reboot your computer in Safe Mode.</p>
<p>Open the smitRem folder, then double click the RunThis.bat file to start the tool. Follow the prompts on screen. Your desktop and icons will disappear and then reappear again — this is normal.<br />
Wait for the tool to complete and Disk Cleanup to finish — this may take a while; please be patient.</p>
<p>Also install good <a href="http://www.myantispyware.com/free-programs/">Free Anti Spyware Tools</a>.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: jon</title>
		<link>http://www.myantispyware.com/2006/01/19/pest-trap-new-rogue-anti-spyware/#comment-142</link>
		<dc:creator>jon</dc:creator>
		<pubDate>Sat, 04 Feb 2006 05:44:18 +0000</pubDate>
		<guid>http://www.myantispyware.com/2006/01/19/pest-trap-new-rogue-anti-spyware/#comment-142</guid>
		<description>That fixed the stolen homepage problem, thanks. Yeah I installed most of those programs myself, except quicktime, which installed itself with itunes somehow. heres the panda scan. 

Incident                                                                        Status                        Location                                                                                                                                                                                                                                                        

Adware:adware/securityerror                                                     Not disinfected               C:\WINNT\system32\mscornet.exe                                                                                                                                                                                                                                  
Adware:Adware/SpywareStrike                                                     Not disinfected               C:\WINNT\system32\1024\ld6D.tmp                                                           
Spyware:Spyware/Smitfraud                                                       Not disinfected               C:\WINNT\Temp\SSLanguage.ini                                                                
Spyware:Cookie/go                                                               Not disinfected               C:\FOUND.005\FILE0000.CHK                                                                                  
Spyware:Cookie/2o7.net                                                          Not disinfected               C:\Documents and Settings\Administrator\Local Settings\Temp\Cookies\administrator@2o7[1].txt                                         

Spyware:Cookie/go                                                               Not disinfected               C:\Documents and Settings\Administrator\Local Settings\Temp\Cookies\administrator@go[1].txt                                                                                                                       
Spyware:Cookie/Overture                                                         Not disinfected               C:\Documents and Settings\Administrator\Local Settings\Temp\Cookies\administrator@perf.overture[1].txt                                                                        
Spyware:Cookie/QuestionMarket                                                   Not disinfected               C:\Documents and Settings\Administrator\Local Settings\Temp\Cookies\administrator@questionmarket[1].txt                                                                                                                                                         
Spyware:Cookie/PointRoll                                                        Not disinfected               C:\Documents and Settings\Administrator\Local Settings\Temp\Cookies\administrator@ads.pointroll[2].txt                                        
Spyware:Cookie/Bluestreak                                                       Not disinfected               C:\Documents and Settings\Administrator\Local Settings\Temp\Cookies\administrator@bluestreak[1].txt                                                                             
Spyware:Cookie/CentrPort                                                        Not disinfected               C:\Documents and Settings\Administrator\Local Settings\Temp\Cookies\administrator@centrport[1].txt                                                                                       
Spyware:Cookie/2o7.net                                                          Not disinfected               C:\Documents and Settings\Administrator\Local Settings\Temp\Cookies\administrator@2o7[2].txt                                                                                     
Spyware:Cookie/Ask                                                              Not disinfected               C:\Documents and Settings\Administrator\Local Settings\Temp\Cookies\administrator@ask[1].txt                                                                                         
Spyware:Cookie/RealMedia                                                        Not disinfected               C:\Documents and Settings\Administrator\Local Settings\Temp\Cookies\administrator@realmedia[1].txt                                                                          
Spyware:Cookie/Falkag                                                           Not disinfected               C:\Documents and Settings\Administrator\Local Settings\Temp\Cookies\administrator@as-us.falkag[1].txt                                                                          
Spyware:Cookie/QuestionMarket                                                   Not disinfected               C:\Documents and Settings\Administrator\Local Settings\Temp\Cookies\administrator@questionmarket[2].txt                                                                         
Spyware:Cookie/Belnk                                                            Not disinfected               C:\Documents and Settings\Administrator\Local Settings\Temp\Cookies\administrator@belnk[2].txt                                                                                    
Spyware:Cookie/Tribalfusion                                                     Not disinfected               C:\Documents and Settings\Administrator\Local Settings\Temp\Cookies\administrator@tribalfusion[1].txt                                                                                  
Spyware:Cookie/Traffic Marketplace                                              Not disinfected               C:\Documents and Settings\Administrator\Local Settings\Temp\Cookies\administrator@trafficmp[2].txt                                                                 
Spyware:Cookie/Apmebf                                                           Not disinfected               C:\Documents and Settings\Administrator\Local Settings\Temp\Cookies\administrator@apmebf[1].txt                                                                             
Spyware:Cookie/YieldManager                                                     Not disinfected               C:\Documents and Settings\Administrator\Local Settings\Temp\Cookies\administrator@ad.yieldmanager[1].txt                                                                                                                                                        
Spyware:Cookie/Belnk                                                            Not disinfected               C:\Documents and Settings\Administrator\Local Settings\Temp\Cookies\administrator@ath.belnk[1].txt                                                                                 
Spyware:Cookie/FastClick                                                        Not disinfected               C:\Documents and Settings\Administrator\Local Settings\Temp\Cookies\administrator@fastclick[2].txt                                                     
Spyware:Cookie/Belnk                                                            Not disinfected               C:\Documents and Settings\Administrator\Local Settings\Temp\Cookies\administrator@dist.belnk[1].txt                                           

Spyware:Cookie/go                                                               Not disinfected               C:\Documents and Settings\Administrator\Cookies\administrator@go[1].txt                                                                                                                         
Spyware:Cookie/go                                                               Not disinfected               C:\FOUND.006\FILE0000.CHK                                                              
Adware:Adware/SpywareStrike                                                     Not disinfected               C:\Recycled\Dc244\SpywareStrike.exe                                                                                                          
Spyware:Cookie/Com.com                                                          Not disinfected               C:\Recycled\Dc248.txt                                                                               
Spyware:Cookie/Statcounter                                                      Not disinfected               C:\Recycled\Dc254.txt                                                                                                                         
Spyware:Cookie/go                                                               Not disinfected               C:\Recycled\Dc264.txt</description>
		<content:encoded><![CDATA[<p>That fixed the stolen homepage problem, thanks. Yeah I installed most of those programs myself, except quicktime, which installed itself with itunes somehow. heres the panda scan. </p>
<p>Incident                                                                        Status                        Location                                                                                                                                                                                                                                                        </p>
<p>Adware:adware/securityerror                                                     Not disinfected               C:\WINNT\system32\mscornet.exe<br />
Adware:Adware/SpywareStrike                                                     Not disinfected               C:\WINNT\system32\1024\ld6D.tmp<br />
Spyware:Spyware/Smitfraud                                                       Not disinfected               C:\WINNT\Temp\SSLanguage.ini<br />
Spyware:Cookie/go                                                               Not disinfected               C:\FOUND.005\FILE0000.CHK<br />
Spyware:Cookie/2o7.net                                                          Not disinfected               C:\Documents and Settings\Administrator\Local Settings\Temp\Cookies\administrator@2o7[1].txt                                         </p>
<p>Spyware:Cookie/go                                                               Not disinfected               C:\Documents and Settings\Administrator\Local Settings\Temp\Cookies\administrator@go[1].txt<br />
Spyware:Cookie/Overture                                                         Not disinfected               C:\Documents and Settings\Administrator\Local Settings\Temp\Cookies\administrator@perf.overture[1].txt<br />
Spyware:Cookie/QuestionMarket                                                   Not disinfected               C:\Documents and Settings\Administrator\Local Settings\Temp\Cookies\administrator@questionmarket[1].txt<br />
Spyware:Cookie/PointRoll                                                        Not disinfected               C:\Documents and Settings\Administrator\Local Settings\Temp\Cookies\administrator@ads.pointroll[2].txt<br />
Spyware:Cookie/Bluestreak                                                       Not disinfected               C:\Documents and Settings\Administrator\Local Settings\Temp\Cookies\administrator@bluestreak[1].txt<br />
Spyware:Cookie/CentrPort                                                        Not disinfected               C:\Documents and Settings\Administrator\Local Settings\Temp\Cookies\administrator@centrport[1].txt<br />
Spyware:Cookie/2o7.net                                                          Not disinfected               C:\Documents and Settings\Administrator\Local Settings\Temp\Cookies\administrator@2o7[2].txt<br />
Spyware:Cookie/Ask                                                              Not disinfected               C:\Documents and Settings\Administrator\Local Settings\Temp\Cookies\administrator@ask[1].txt<br />
Spyware:Cookie/RealMedia                                                        Not disinfected               C:\Documents and Settings\Administrator\Local Settings\Temp\Cookies\administrator@realmedia[1].txt<br />
Spyware:Cookie/Falkag                                                           Not disinfected               C:\Documents and Settings\Administrator\Local Settings\Temp\Cookies\administrator@as-us.falkag[1].txt<br />
Spyware:Cookie/QuestionMarket                                                   Not disinfected               C:\Documents and Settings\Administrator\Local Settings\Temp\Cookies\administrator@questionmarket[2].txt<br />
Spyware:Cookie/Belnk                                                            Not disinfected               C:\Documents and Settings\Administrator\Local Settings\Temp\Cookies\administrator@belnk[2].txt<br />
Spyware:Cookie/Tribalfusion                                                     Not disinfected               C:\Documents and Settings\Administrator\Local Settings\Temp\Cookies\administrator@tribalfusion[1].txt<br />
Spyware:Cookie/Traffic Marketplace                                              Not disinfected               C:\Documents and Settings\Administrator\Local Settings\Temp\Cookies\administrator@trafficmp[2].txt<br />
Spyware:Cookie/Apmebf                                                           Not disinfected               C:\Documents and Settings\Administrator\Local Settings\Temp\Cookies\administrator@apmebf[1].txt<br />
Spyware:Cookie/YieldManager                                                     Not disinfected               C:\Documents and Settings\Administrator\Local Settings\Temp\Cookies\administrator@ad.yieldmanager[1].txt<br />
Spyware:Cookie/Belnk                                                            Not disinfected               C:\Documents and Settings\Administrator\Local Settings\Temp\Cookies\administrator@ath.belnk[1].txt<br />
Spyware:Cookie/FastClick                                                        Not disinfected               C:\Documents and Settings\Administrator\Local Settings\Temp\Cookies\administrator@fastclick[2].txt<br />
Spyware:Cookie/Belnk                                                            Not disinfected               C:\Documents and Settings\Administrator\Local Settings\Temp\Cookies\administrator@dist.belnk[1].txt                                           </p>
<p>Spyware:Cookie/go                                                               Not disinfected               C:\Documents and Settings\Administrator\Cookies\administrator@go[1].txt<br />
Spyware:Cookie/go                                                               Not disinfected               C:\FOUND.006\FILE0000.CHK<br />
Adware:Adware/SpywareStrike                                                     Not disinfected               C:\Recycled\Dc244\SpywareStrike.exe<br />
Spyware:Cookie/Com.com                                                          Not disinfected               C:\Recycled\Dc248.txt<br />
Spyware:Cookie/Statcounter                                                      Not disinfected               C:\Recycled\Dc254.txt<br />
Spyware:Cookie/go                                                               Not disinfected               C:\Recycled\Dc264.txt</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Patrik</title>
		<link>http://www.myantispyware.com/2006/01/19/pest-trap-new-rogue-anti-spyware/#comment-141</link>
		<dc:creator>Patrik</dc:creator>
		<pubDate>Sat, 04 Feb 2006 04:26:16 +0000</pubDate>
		<guid>http://www.myantispyware.com/2006/01/19/pest-trap-new-rogue-anti-spyware/#comment-141</guid>
		<description>Go to Start &#62; Control Panel &#62; Add or Remove Programs and remove the following programs, if found: PestTrap

Then using Windows Explorer, delete the following folder: C:\Program Files\PestTrap

please reboot your computer in Safe Mode by doing the following:

1. Restart your computer
2. After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
3. Instead of Windows loading as normal, a menu should appear
4. Select the first option, to run Windows in Safe Mode.

Now you need to run HijackThis and click “Do a system scan only”
Place a check next to the following entries (if they are still there):

&lt;b&gt;O2 - BHO: HomepageBHO - {4da4616d-7e6e-4fd9-a2d5-b6c535733e22} - C:\WINNT\System32\hp8E65.tmp&lt;/b&gt;

Click Fix Checked
Restart your computer in normal mode.

Run the &lt;a href="http://www.myantispyware.com/2005/12/15/panda-software-active-scan/" rel="nofollow"&gt;Panda online virus scan&lt;/a&gt;, after scan post log there.

And one question, These programs AIM, Itunes, QuickTime  installed by you ??</description>
		<content:encoded><![CDATA[<p>Go to Start &gt; Control Panel &gt; Add or Remove Programs and remove the following programs, if found: PestTrap</p>
<p>Then using Windows Explorer, delete the following folder: C:\Program Files\PestTrap</p>
<p>please reboot your computer in Safe Mode by doing the following:</p>
<p>1. Restart your computer<br />
2. After hearing your computer beep once during startup, but before the Windows icon appears, press F8.<br />
3. Instead of Windows loading as normal, a menu should appear<br />
4. Select the first option, to run Windows in Safe Mode.</p>
<p>Now you need to run HijackThis and click “Do a system scan only”<br />
Place a check next to the following entries (if they are still there):</p>
<p><b>O2 - BHO: HomepageBHO - {4da4616d-7e6e-4fd9-a2d5-b6c535733e22} - C:\WINNT\System32\hp8E65.tmp</b></p>
<p>Click Fix Checked<br />
Restart your computer in normal mode.</p>
<p>Run the <a href="http://www.myantispyware.com/2005/12/15/panda-software-active-scan/" rel="nofollow">Panda online virus scan</a>, after scan post log there.</p>
<p>And one question, These programs AIM, Itunes, QuickTime  installed by you ??</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: jon</title>
		<link>http://www.myantispyware.com/2006/01/19/pest-trap-new-rogue-anti-spyware/#comment-140</link>
		<dc:creator>jon</dc:creator>
		<pubDate>Sat, 04 Feb 2006 03:31:02 +0000</pubDate>
		<guid>http://www.myantispyware.com/2006/01/19/pest-trap-new-rogue-anti-spyware/#comment-140</guid>
		<description>Thank you Patrik, here it is:

Logfile of HijackThis v1.99.1
Scan saved at 7:20:43 PM, on 2/3/2006
Platform: Windows XP  (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\AMD\Cool'n'Quiet\GemServ.exe
C:\Program Files\AMD\Cool'n'Quiet\gemback.exe
C:\WINNT\System32\nvsvc32.exe
C:\WINNT\system32\ZONELABS\vsmon.exe
C:\WINNT\System32\ZoneLabs\isafe.exe
C:\WINNT\Explorer.EXE
C:\WINNT\System32\nvraidservice.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINNT\System32\wbem\unsecapp.exe
C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\WINNT\System32\DeltTray.exe
C:\Program Files\DIGStream\digstream.exe
C:\Program Files\ESPNRunTime\DIGServices.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINNT\System32\wuauclt.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Administrator\Desktop\HijackThis.exe
C:\WINNT\system32\NOTEPAD.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
O2 - BHO: HomepageBHO - {4da4616d-7e6e-4fd9-a2d5-b6c535733e22} - C:\WINNT\System32\hp8E65.tmp
O3 - Toolbar: &#38;Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: &#38;Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [NVRaidService] C:\WINNT\System32\nvraidservice.exe
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINNT\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [DeltTray] DeltTray.exe
O4 - HKLM\..\Run: [DIGStream] C:\Program Files\DIGStream\digstream.exe
O4 - HKLM\..\Run: [DIGServices] C:\Program Files\ESPNRunTime\DIGServices.exe   /brand=ESPN   /priority=0   /poll=24
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: &#38;Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &#38;Translate English Word - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&#38;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O23 - Service: CA ISafe (CAISafe) - Computer Associates International, Inc. - C:\WINNT\System32\ZoneLabs\isafe.exe
O23 - Service: AMD PowerNow! (tm) Technology Service (GemServ) - Advanced Micro Devices - C:\Program Files\AMD\Cool'n'Quiet\GemServ.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Macromedia Licensing Service - Macromedia - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINNT\System32\nvsvc32.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINNT\system32\ZONELABS\vsmon.exe</description>
		<content:encoded><![CDATA[<p>Thank you Patrik, here it is:</p>
<p>Logfile of HijackThis v1.99.1<br />
Scan saved at 7:20:43 PM, on 2/3/2006<br />
Platform: Windows XP  (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v6.00 (6.00.2600.0000)</p>
<p>Running processes:<br />
C:\WINNT\System32\smss.exe<br />
C:\WINNT\system32\winlogon.exe<br />
C:\WINNT\system32\services.exe<br />
C:\WINNT\system32\lsass.exe<br />
C:\WINNT\system32\svchost.exe<br />
C:\WINNT\System32\svchost.exe<br />
C:\WINNT\system32\spoolsv.exe<br />
C:\Program Files\AMD\Cool&#8217;n'Quiet\GemServ.exe<br />
C:\Program Files\AMD\Cool&#8217;n'Quiet\gemback.exe<br />
C:\WINNT\System32\nvsvc32.exe<br />
C:\WINNT\system32\ZONELABS\vsmon.exe<br />
C:\WINNT\System32\ZoneLabs\isafe.exe<br />
C:\WINNT\Explorer.EXE<br />
C:\WINNT\System32\nvraidservice.exe<br />
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe<br />
C:\WINNT\System32\wbem\unsecapp.exe<br />
C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe<br />
C:\WINNT\System32\DeltTray.exe<br />
C:\Program Files\DIGStream\digstream.exe<br />
C:\Program Files\ESPNRunTime\DIGServices.exe<br />
C:\Program Files\iTunes\iTunesHelper.exe<br />
C:\Program Files\iPod\bin\iPodService.exe<br />
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe<br />
C:\WINNT\System32\wuauclt.exe<br />
C:\Program Files\Internet Explorer\IEXPLORE.EXE<br />
C:\Program Files\Internet Explorer\IEXPLORE.EXE<br />
C:\Documents and Settings\Administrator\Desktop\HijackThis.exe<br />
C:\WINNT\system32\NOTEPAD.EXE</p>
<p>R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://www.yahoo.com/" rel="nofollow">http://www.yahoo.com/</a><br />
O2 - BHO: HomepageBHO - {4da4616d-7e6e-4fd9-a2d5-b6c535733e22} - C:\WINNT\System32\hp8E65.tmp<br />
O3 - Toolbar: &amp;Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx<br />
O3 - Toolbar: &amp;Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll<br />
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon<br />
O4 - HKLM\..\Run: [NVRaidService] C:\WINNT\System32\nvraidservice.exe<br />
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe<br />
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\System32\NvCpl.dll,NvStartup<br />
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install<br />
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINNT\System32\NvMcTray.dll,NvTaskbarInit<br />
O4 - HKLM\..\Run: [AdaptecDirectCD] &#8220;C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe&#8221;<br />
O4 - HKLM\..\Run: [DeltTray] DeltTray.exe<br />
O4 - HKLM\..\Run: [DIGStream] C:\Program Files\DIGStream\digstream.exe<br />
O4 - HKLM\..\Run: [DIGServices] C:\Program Files\ESPNRunTime\DIGServices.exe   /brand=ESPN   /priority=0   /poll=24<br />
O4 - HKLM\..\Run: [iTunesHelper] &#8220;C:\Program Files\iTunes\iTunesHelper.exe&#8221;<br />
O4 - HKLM\..\Run: [QuickTime Task] &#8220;C:\Program Files\QuickTime\qttask.exe&#8221; -atboottime<br />
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe<br />
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl<br />
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE<br />
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe<br />
O8 - Extra context menu item: &amp;Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html<br />
O8 - Extra context menu item: &amp;Translate English Word - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html<br />
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html<br />
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000<br />
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html<br />
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html<br />
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe<br />
O23 - Service: CA ISafe (CAISafe) - Computer Associates International, Inc. - C:\WINNT\System32\ZoneLabs\isafe.exe<br />
O23 - Service: AMD PowerNow! &#8482; Technology Service (GemServ) - Advanced Micro Devices - C:\Program Files\AMD\Cool&#8217;n'Quiet\GemServ.exe<br />
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe<br />
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: Macromedia Licensing Service - Macromedia - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe<br />
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINNT\System32\nvsvc32.exe<br />
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINNT\system32\ZONELABS\vsmon.exe</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Patrik</title>
		<link>http://www.myantispyware.com/2006/01/19/pest-trap-new-rogue-anti-spyware/#comment-139</link>
		<dc:creator>Patrik</dc:creator>
		<pubDate>Sat, 04 Feb 2006 03:14:36 +0000</pubDate>
		<guid>http://www.myantispyware.com/2006/01/19/pest-trap-new-rogue-anti-spyware/#comment-139</guid>
		<description>to jon
Make &lt;a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/" rel="nofollow"&gt;HijackThis &lt;/a&gt;log and post there</description>
		<content:encoded><![CDATA[<p>to jon<br />
Make <a href="http://www.myantispyware.com/2005/12/05/hijackthis-your-first-tool-for-remove-homepage-hijackers/" rel="nofollow">HijackThis </a>log and post there</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: jon</title>
		<link>http://www.myantispyware.com/2006/01/19/pest-trap-new-rogue-anti-spyware/#comment-138</link>
		<dc:creator>jon</dc:creator>
		<pubDate>Sat, 04 Feb 2006 01:54:45 +0000</pubDate>
		<guid>http://www.myantispyware.com/2006/01/19/pest-trap-new-rogue-anti-spyware/#comment-138</guid>
		<description>Any idea on how to get rid of pest trap/malewarewipe?</description>
		<content:encoded><![CDATA[<p>Any idea on how to get rid of pest trap/malewarewipe?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mike</title>
		<link>http://www.myantispyware.com/2006/01/19/pest-trap-new-rogue-anti-spyware/#comment-115</link>
		<dc:creator>Mike</dc:creator>
		<pubDate>Thu, 26 Jan 2006 23:34:06 +0000</pubDate>
		<guid>http://www.myantispyware.com/2006/01/19/pest-trap-new-rogue-anti-spyware/#comment-115</guid>
		<description>Another fake security center.  Googling for Pest Trap info brought the following:

Security CenterRecommended Anti-Spyware Software: Pest Trap, Malware Wipe, Spy Guard, Online Security. Pest Trap Most popular spyware/adware cleaner software all over the ...
securitycaution.com/ - 9k - Jan 24, 2006 - Cached - Similar pages</description>
		<content:encoded><![CDATA[<p>Another fake security center.  Googling for Pest Trap info brought the following:</p>
<p>Security CenterRecommended Anti-Spyware Software: Pest Trap, Malware Wipe, Spy Guard, Online Security. Pest Trap Most popular spyware/adware cleaner software all over the &#8230;<br />
securitycaution.com/ - 9k - Jan 24, 2006 - Cached - Similar pages</p>
]]></content:encoded>
	</item>
</channel>
</rss>
