<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Vex Star &#187; Messenger</title>
	<atom:link href="http://www.vexstar.com/tag/messenger/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.vexstar.com</link>
	<description>Computers and Programming</description>
	<lastBuildDate>Tue, 21 Jun 2011 01:52:16 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>I have some very interesting spyware/malware&#8230;&#8230;</title>
		<link>http://www.vexstar.com/i-have-some-very-interesting-spywaremalware/</link>
		<comments>http://www.vexstar.com/i-have-some-very-interesting-spywaremalware/#comments</comments>
		<pubDate>Sun, 02 Nov 2008 13:20:00 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[general]]></category>
		<category><![CDATA[ActiveX]]></category>
		<category><![CDATA[Adobe]]></category>
		<category><![CDATA[Analog Devices Inc.]]></category>
		<category><![CDATA[Apple Computer Inc.]]></category>
		<category><![CDATA[Apple Mobile Device - Apple Inc.]]></category>
		<category><![CDATA[Bonjour Service]]></category>
		<category><![CDATA[Ebay]]></category>
		<category><![CDATA[FLEXnet Licensing Service - Macrovision Europe Ltd.]]></category>
		<category><![CDATA[html]]></category>
		<category><![CDATA[Internet Explorer]]></category>
		<category><![CDATA[Java]]></category>
		<category><![CDATA[Lavasoft Ad-Aware Service]]></category>
		<category><![CDATA[Messenger]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Microsoft Windows]]></category>
		<category><![CDATA[MySpace]]></category>
		<category><![CDATA[PCtel Inc.]]></category>
		<category><![CDATA[pdf]]></category>
		<category><![CDATA[SoundMAX Agent Service]]></category>
		<category><![CDATA[speaker]]></category>
		<category><![CDATA[spy]]></category>
		<category><![CDATA[Symantec AntiVirus - Symantec Corporation]]></category>
		<category><![CDATA[Symantec Corporation]]></category>
		<category><![CDATA[Windows XP]]></category>

		<guid isPermaLink="false">http://www.vexstar.com/i-have-some-very-interesting-spywaremalware/</guid>
		<description><![CDATA[Never seen or heard of it before. 
Take for instance, OT. Look at the top of this page&#8230;&#8230;&#8230;you see the two side by side banners for advertisors? This spy/mal-ware actually replaces those with spamming banners. Some make noises and talk&#8230;&#8230;like those ads we all hate. I can refresh the screen&#8230;&#8230;and it will randomly show the [...]


No related posts.]]></description>
			<content:encoded><![CDATA[<p>Never seen or heard of it before. </p>
<p>Take for instance, OT. Look at the top of this page&#8230;&#8230;&#8230;you see the two side by side banners for advertisors? This spy/mal-ware actually replaces those with spamming banners. Some make noises and talk&#8230;&#8230;like those ads we all hate. I can refresh the screen&#8230;&#8230;and it will randomly show the correct banners (paying advertisors). Its pretty much hit or miss on which one shows up though. </p>
<p>Anyone heard or seen this before? I am not sure if it is a vBulletin thing or what, but since the majority of the boards I frequent are vB, I have noticed it on all of them. <br /><span id="more-275"></span></p>
<p>TIA for any help/advice. If anyone would like to help, let me know if you would like to see a HJT file. <br />have you tried adaware or any other spyware/malware scanners?  how about anti-virus?  avast and avg are free.<br />Get Spybot.</p>
<p>The site looks a bit unpro but its a damn good free program.<br />I downloaded and ran the newest version of Spybot, and it found 3 significant items that required a reboot with a full scan during startup. The scan took about an hour, and it said it fixed the problems. </p>
<p>Now, IE is <b>REALLY</b> slow&#8230;&#8230;.and the problems I started with are still there as well. I know most of you will praise Firefox, but I prefer IE so save the replies.  </p>
<p>Anyone have any other suggestions?<br />try others.  no one scanner is perfect.  sometimes one will catch/repair something that another misses.  try avast and avg as well as adaware.<br />run superantispyware</p>
<p>i see this catch a lot of shit  <br />buying a sub will also fix the problem.  i see no ads.</p>
<p>just kidding, run hijackthis and post the outcome here
<div style="5px;">
<table cellpadding="6" cellspacing="0" border="0" width="100%">
<tr>
<td class="alt2" style="1px inset">
<div></div>
</td>
</tr>
</table>
</div>
<p>Well executed joke. I actually chuckled. </p>
<p>Here ya go&#8230;.</p>
<p>Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 9:23:53 PM, on 7/15/2008<br />
Platform: Windows XP SP2 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)<br />
Boot mode: Normal<br />
Running processes:<br />
C:WINDOWSSystem32smss.exe<br />
C:WINDOWSsystem32winlogon.exe<br />
C:WINDOWSsystem32services.exe<br />
C:WINDOWSsystem32lsass.exe<br />
C:WINDOWSsystem32svchost.exe<br />
C:WINDOWSSystem32svchost.exe<br />
C:Program FilesCommon FilesSymantec SharedccSetMgr.exe<br />
C:Program FilesCommon FilesSymantec SharedccEvtMgr.exe<br />
C:Program FilesLavasoftAd-Awareaawservice.exe<br />
C:WINDOWSsystem32spoolsv.exe<br />
C:WINDOWSExplorer.EXE<br />
C:Program FilesAnalog DevicesSoundMAXSMax4PNP.exe<br />
C:Program FilesJavajre1.6.0_05binjusched.exe<br />
C:Program FilesCommon FilesRealUpdate_OBrealsched.exe<br />
C:Program FilesAIMaim.exe<br />
C:Program FilesCommon FilesAppleMobile Device SupportbinAppleMobileDeviceService.exe<br />
C:Program FilesBonjourmDNSResponder.exe<br />
C:Program FilesSymantec AntiVirusDefWatch.exe<br />
C:WINDOWSsystem32pctspk.exe<br />
C:Program FilesSymantec AntiVirusSavRoam.exe<br />
C:Program FilesAnalog DevicesSoundMAXSMAgent.exe<br />
C:WINDOWSsystem32svchost.exe<br />
C:Program FilesSymantec AntiVirusRtvscan.exe<br />
C:Program FilesInternet Exploreriexplore.exe<br />
C:Program FilesInternet Exploreriexplore.exe<br />
C:Program FilesTrend MicroHijackThisHijackThis.exe<br />
R1 &#8211; HKCUSoftwareMicrosoftWindowsCurrentVersionInt  ernet Settings,ProxyOverride = *.local<br />
O2 &#8211; BHO: Adobe PDF Reader Link Helper &#8211; {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} &#8211; C:Program FilesAdobeAcrobat 7.0ActiveXAcroIEHelper.dll<br />
O2 &#8211; BHO: RealPlayer Download and Record Plugin for Internet Explorer &#8211; {3049C3E9-B461-4BC5-8870-4C09146192CA} &#8211; C:Program FilesRealRealPlayerrpbrowserrecordplugin.dll<br />
O2 &#8211; BHO: Spybot-S&amp;D IE Protection &#8211; {53707962-6F74-2D53-2644-206D7942484F} &#8211; C:PROGRA~1SPYBOT~1SDHelper.dll<br />
O2 &#8211; BHO: SSVHelper Class &#8211; {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} &#8211; C:Program FilesJavajre1.6.0_05binssv.dll<br />
O2 &#8211; BHO: Browser Helper Object &#8211; {AFD4AD01-58C1-47DB-A404-FBE00A6C5486} &#8211; C:Program FilesCommonhelper.dll<br />
O4 &#8211; HKLM..Run: [SoundMAXPnP] C:Program FilesAnalog DevicesSoundMAXSMax4PNP.exe<br />
O4 &#8211; HKLM..Run: [SoundMAX] &quot;C:Program FilesAnalog DevicesSoundMAXSmax4.exe&quot; /tray<br />
O4 &#8211; HKLM..Run: [SunJavaUpdateSched] &quot;C:Program FilesJavajre1.6.0_05binjusched.exe&quot;<br />
O4 &#8211; HKLM..Run: [QuickTime Task] &quot;C:Program FilesQuickTimeqttask.exe&quot; -atboottime<br />
O4 &#8211; HKLM..Run: [WinampAgent] &quot;C:Program FilesWinampwinampa.exe&quot;<br />
O4 &#8211; HKLM..Run: [TkBellExe] &quot;C:Program FilesCommon FilesRealUpdate_OBrealsched.exe&quot;  -osboot<br />
O4 &#8211; HKCU..Run: [AIM] C:Program FilesAIMaim.exe -cnetwait.odl<br />
O4 &#8211; HKCU..Run: [EasyLinkAdvisor] &quot;C:Program FilesLinksys EasyLink AdvisorLinksysAgent.exe&quot; /startup<br />
O4 &#8211; HKCU..Run: [SpybotSD TeaTimer] C:Program FilesSpybot &#8211; Search &amp; DestroyTeaTimer.exe<br />
O8 &#8211; Extra context menu item: &amp;eBay Search &#8211; res://C:Program FileseBayeBay Toolbar2eBayTb.dll/RCSearch.html<br />
O8 &#8211; Extra context menu item: E&amp;xport to Microsoft Excel &#8211; res://C:PROGRA~1MICROS~2Office10EXCEL.EXE/3000<br />
O9 &#8211; Extra button: (no name) &#8211; {08B0E5C0-4FCB-11CF-AAA5-00401C608501} &#8211; C:Program FilesJavajre1.6.0_05binssv.dll<br />
O9 &#8211; Extra &#8216;Tools&#8217; menuitem: Sun Java Console &#8211; {08B0E5C0-4FCB-11CF-AAA5-00401C608501} &#8211; C:Program FilesJavajre1.6.0_05binssv.dll<br />
O9 &#8211; Extra button: AIM &#8211; {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} &#8211; C:Program FilesAIMaim.exe<br />
O9 &#8211; Extra button: (no name) &#8211; {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} &#8211; C:PROGRA~1SPYBOT~1SDHelper.dll<br />
O9 &#8211; Extra &#8216;Tools&#8217; menuitem: Spybot &#8211; Search &amp; Destroy Configuration &#8211; {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} &#8211; C:PROGRA~1SPYBOT~1SDHelper.dll<br />
O9 &#8211; Extra button: Messenger &#8211; {FB5F1910-F110-11d2-BB9E-00C04F795683} &#8211; C:Program FilesMessengermsmsgs.exe<br />
O9 &#8211; Extra &#8216;Tools&#8217; menuitem: Windows Messenger &#8211; {FB5F1910-F110-11d2-BB9E-00C04F795683} &#8211; C:Program FilesMessengermsmsgs.exe<br />
O16 &#8211; DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) &#8211; <br />
O16 &#8211; DPF: {2E12FB00-546B-4EE3-9CC2-057BF02E1C17} (Webshots Multiple Media Uploader &#8211; Container) &#8211; <br />
O16 &#8211; DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) &#8211; <br />
O18 &#8211; Filter hijack: text/html &#8211; {ae4ef06c-ecd9-4366-858e-82fa2f8b11aa} &#8211; C:WINDOWSsystem32iehlpr32.dll<br />
O23 &#8211; Service: Lavasoft Ad-Aware Service (aawservice) &#8211; Lavasoft &#8211; C:Program FilesLavasoftAd-Awareaawservice.exe<br />
O23 &#8211; Service: Apple Mobile Device &#8211; Apple, Inc. &#8211; C:Program FilesCommon FilesAppleMobile Device SupportbinAppleMobileDeviceService.exe<br />
O23 &#8211; Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762#  # (Bonjour Service) &#8211; Apple Computer, Inc. &#8211; C:Program FilesBonjourmDNSResponder.exe<br />
O23 &#8211; Service: Symantec Event Manager (ccEvtMgr) &#8211; Symantec Corporation &#8211; C:Program FilesCommon FilesSymantec SharedccEvtMgr.exe<br />
O23 &#8211; Service: Symantec Password Validation (ccPwdSvc) &#8211; Symantec Corporation &#8211; C:Program FilesCommon FilesSymantec SharedccPwdSvc.exe<br />
O23 &#8211; Service: Symantec Settings Manager (ccSetMgr) &#8211; Symantec Corporation &#8211; C:Program FilesCommon FilesSymantec SharedccSetMgr.exe<br />
O23 &#8211; Service: Symantec AntiVirus Definition Watcher (DefWatch) &#8211; Symantec Corporation &#8211; C:Program FilesSymantec AntiVirusDefWatch.exe<br />
O23 &#8211; Service: FLEXnet Licensing Service &#8211; Macrovision Europe Ltd. &#8211; C:Program FilesCommon FilesMacrovision SharedFLEXnet PublisherFNPLicensingService.exe<br />
O23 &#8211; Service: PCTEL Speaker Phone (Pctspk) &#8211; PCtel, Inc. &#8211; C:WINDOWSsystem32pctspk.exe<br />
O23 &#8211; Service: SAVRoam (SavRoam) &#8211; symantec &#8211; C:Program FilesSymantec AntiVirusSavRoam.exe<br />
O23 &#8211; Service: Symantec Network Drivers Service (SNDSrvc) &#8211; Symantec Corporation &#8211; C:Program FilesCommon FilesSymantec SharedSNDSrvc.exe<br />
O23 &#8211; Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) &#8211; Analog Devices, Inc. &#8211; C:Program FilesAnalog DevicesSoundMAXSMAgent.exe<br />
O23 &#8211; Service: Symantec AntiVirus &#8211; Symantec Corporation &#8211; C:Program FilesSymantec AntiVirusRtvscan.exe<br />
&#8211;<br />
End of file &#8211; 6342 bytes<br />TTT</p>
<p>Anyone heard of this yet? I&#8217;ve now got them on about every message board I go to that has advertisement banners. I even got one of the spam ad&#8217;s in someone signature&#8230;&#8230;the picture was hosted by Photobucket FWIW. </p>
<p>FWIW, whenever I get one of these spam ad&#8217;s&#8230;&#8230;..it is some sort of flash. I can right click on a &#8216;normal&#8217; advertisement banner&#8230;&#8230;and actually see the properties and such, but when I try to right click on a spam banner&#8230;&#8230;it has the flash menu options&#8230;</p>
<p>question&#8230;  what exactly have you done thus far?  all you say you&#8217;ve done is run spybot and hijackthis.  have you run adaware?  how about installing and running a full scan with avast or AVG virus scans?</p>
<p>eventually you&#8217;ll probably have to wipe your system and fresh install.<br />Yup did Ad-Aware also. I am prolly just gonna reformat&#8230;&#8230;.this shit is a PITA.
<div style="5px;">
<table cellpadding="6" cellspacing="0" border="0" width="100%">
<tr>
<td class="alt2" style="1px inset">
<div></div>
<div style="italic">Well executed joke. I actually chuckled. </p>
<p>Here ya go&#8230;.</p>
<p>Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 9:23:53 PM, on 7/15/2008<br />
Platform: Windows XP SP2 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)<br />
Boot mode: Normal<br />
Running processes:<br />
C:WINDOWSSystem32smss.exe<br />
C:WINDOWSsystem32winlogon.exe<br />
C:WINDOWSsystem32services.exe<br />
C:WINDOWSsystem32lsass.exe<br />
C:WINDOWSsystem32svchost.exe<br />
C:WINDOWSSystem32svchost.exe<br />
C:Program FilesCommon FilesSymantec SharedccSetMgr.exe<br />
C:Program FilesCommon FilesSymantec SharedccEvtMgr.exe<br />
C:Program FilesLavasoftAd-Awareaawservice.exe<br />
C:WINDOWSsystem32spoolsv.exe<br />
C:WINDOWSExplorer.EXE<br />
C:Program FilesAnalog DevicesSoundMAXSMax4PNP.exe<br />
C:Program FilesJavajre1.6.0_05binjusched.exe<br />
C:Program FilesCommon FilesRealUpdate_OBrealsched.exe<br />
C:Program FilesAIMaim.exe<br />
C:Program FilesCommon FilesAppleMobile Device SupportbinAppleMobileDeviceService.exe<br />
C:Program FilesBonjourmDNSResponder.exe<br />
C:Program FilesSymantec AntiVirusDefWatch.exe<br />
C:WINDOWSsystem32pctspk.exe<br />
C:Program FilesSymantec AntiVirusSavRoam.exe<br />
C:Program FilesAnalog DevicesSoundMAXSMAgent.exe<br />
C:WINDOWSsystem32svchost.exe<br />
C:Program FilesSymantec AntiVirusRtvscan.exe<br />
C:Program FilesInternet Exploreriexplore.exe<br />
C:Program FilesInternet Exploreriexplore.exe<br />
C:Program FilesTrend MicroHijackThisHijackThis.exe<br />
R1 &#8211; HKCUSoftwareMicrosoftWindowsCurrentVersionInt  ernet Settings,ProxyOverride = *.local<br />
O2 &#8211; BHO: Adobe PDF Reader Link Helper &#8211; {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} &#8211; C:Program FilesAdobeAcrobat 7.0ActiveXAcroIEHelper.dll<br />
O2 &#8211; BHO: RealPlayer Download and Record Plugin for Internet Explorer &#8211; {3049C3E9-B461-4BC5-8870-4C09146192CA} &#8211; C:Program FilesRealRealPlayerrpbrowserrecordplugin.dll<br />
O2 &#8211; BHO: Spybot-S&amp;D IE Protection &#8211; {53707962-6F74-2D53-2644-206D7942484F} &#8211; C:PROGRA~1SPYBOT~1SDHelper.dll<br />
O2 &#8211; BHO: SSVHelper Class &#8211; {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} &#8211; C:Program FilesJavajre1.6.0_05binssv.dll<br />
<b></b><br />
O4 &#8211; HKLM..Run: [SoundMAXPnP] C:Program FilesAnalog DevicesSoundMAXSMax4PNP.exe<br />
O4 &#8211; HKLM..Run: [SoundMAX] &quot;C:Program FilesAnalog DevicesSoundMAXSmax4.exe&quot; /tray<br />
O4 &#8211; HKLM..Run: [SunJavaUpdateSched] &quot;C:Program FilesJavajre1.6.0_05binjusched.exe&quot;<br />
O4 &#8211; HKLM..Run: [QuickTime Task] &quot;C:Program FilesQuickTimeqttask.exe&quot; -atboottime<br />
O4 &#8211; HKLM..Run: [WinampAgent] &quot;C:Program FilesWinampwinampa.exe&quot;<br />
O4 &#8211; HKLM..Run: [TkBellExe] &quot;C:Program FilesCommon FilesRealUpdate_OBrealsched.exe&quot;  -osboot<br />
O4 &#8211; HKCU..Run: [AIM] C:Program FilesAIMaim.exe -cnetwait.odl<br />
O4 &#8211; HKCU..Run: [EasyLinkAdvisor] &quot;C:Program FilesLinksys EasyLink AdvisorLinksysAgent.exe&quot; /startup<br />
O4 &#8211; HKCU..Run: [SpybotSD TeaTimer] C:Program FilesSpybot &#8211; Search &amp; DestroyTeaTimer.exe<br />
O8 &#8211; Extra context menu item: &amp;eBay Search &#8211; res://C:Program FileseBayeBay Toolbar2eBayTb.dll/RCSearch.html<br />
O8 &#8211; Extra context menu item: E&amp;xport to Microsoft Excel &#8211; res://C:PROGRA~1MICROS~2Office10EXCEL.EXE/3000<br />
O9 &#8211; Extra button: (no name) &#8211; {08B0E5C0-4FCB-11CF-AAA5-00401C608501} &#8211; C:Program FilesJavajre1.6.0_05binssv.dll<br />
O9 &#8211; Extra &#8216;Tools&#8217; menuitem: Sun Java Console &#8211; {08B0E5C0-4FCB-11CF-AAA5-00401C608501} &#8211; C:Program FilesJavajre1.6.0_05binssv.dll<br />
O9 &#8211; Extra button: AIM &#8211; {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} &#8211; C:Program FilesAIMaim.exe<br />
O9 &#8211; Extra button: (no name) &#8211; {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} &#8211; C:PROGRA~1SPYBOT~1SDHelper.dll<br />
O9 &#8211; Extra &#8216;Tools&#8217; menuitem: Spybot &#8211; Search &amp; Destroy Configuration &#8211; {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} &#8211; C:PROGRA~1SPYBOT~1SDHelper.dll<br />
O9 &#8211; Extra button: Messenger &#8211; {FB5F1910-F110-11d2-BB9E-00C04F795683} &#8211; C:Program FilesMessengermsmsgs.exe<br />
O9 &#8211; Extra &#8216;Tools&#8217; menuitem: Windows Messenger &#8211; {FB5F1910-F110-11d2-BB9E-00C04F795683} &#8211; C:Program FilesMessengermsmsgs.exe<br />
O16 &#8211; DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) &#8211; <br />
O16 &#8211; DPF: {2E12FB00-546B-4EE3-9CC2-057BF02E1C17} (Webshots Multiple Media Uploader &#8211; Container) &#8211; <br />
O16 &#8211; DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) &#8211; <br />
<b></b><br />
O23 &#8211; Service: Lavasoft Ad-Aware Service (aawservice) &#8211; Lavasoft &#8211; C:Program FilesLavasoftAd-Awareaawservice.exe<br />
O23 &#8211; Service: Apple Mobile Device &#8211; Apple, Inc. &#8211; C:Program FilesCommon FilesAppleMobile Device SupportbinAppleMobileDeviceService.exe<br />
O23 &#8211; Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762#  # (Bonjour Service) &#8211; Apple Computer, Inc. &#8211; C:Program FilesBonjourmDNSResponder.exe<br />
O23 &#8211; Service: Symantec Event Manager (ccEvtMgr) &#8211; Symantec Corporation &#8211; C:Program FilesCommon FilesSymantec SharedccEvtMgr.exe<br />
O23 &#8211; Service: Symantec Password Validation (ccPwdSvc) &#8211; Symantec Corporation &#8211; C:Program FilesCommon FilesSymantec SharedccPwdSvc.exe<br />
O23 &#8211; Service: Symantec Settings Manager (ccSetMgr) &#8211; Symantec Corporation &#8211; C:Program FilesCommon FilesSymantec SharedccSetMgr.exe<br />
O23 &#8211; Service: Symantec AntiVirus Definition Watcher (DefWatch) &#8211; Symantec Corporation &#8211; C:Program FilesSymantec AntiVirusDefWatch.exe<br />
O23 &#8211; Service: FLEXnet Licensing Service &#8211; Macrovision Europe Ltd. &#8211; C:Program FilesCommon FilesMacrovision SharedFLEXnet PublisherFNPLicensingService.exe<br />
O23 &#8211; Service: PCTEL Speaker Phone (Pctspk) &#8211; PCtel, Inc. &#8211; C:WINDOWSsystem32pctspk.exe<br />
O23 &#8211; Service: SAVRoam (SavRoam) &#8211; symantec &#8211; C:Program FilesSymantec AntiVirusSavRoam.exe<br />
O23 &#8211; Service: Symantec Network Drivers Service (SNDSrvc) &#8211; Symantec Corporation &#8211; C:Program FilesCommon FilesSymantec SharedSNDSrvc.exe<br />
O23 &#8211; Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) &#8211; Analog Devices, Inc. &#8211; C:Program FilesAnalog DevicesSoundMAXSMAgent.exe<br />
O23 &#8211; Service: Symantec AntiVirus &#8211; Symantec Corporation &#8211; C:Program FilesSymantec AntiVirusRtvscan.exe<br />
&#8211;<br />
End of file &#8211; 6342 bytes</div>
</td>
</tr>
</table>
</div>
<p>those are the nasties
<div style="5px;">
<table cellpadding="6" cellspacing="0" border="0" width="100%">
<tr>
<td class="alt2" style="1px inset">
<div></div>
</td>
</tr>
</table>
</div>
<p>Deleted and fixed.</p>
<p>Thanks a ton&#8230;..you don&#8217;t even know. </p>
<p></p>


<p>No related posts.</p>]]></content:encoded>
			<wfw:commentRss>http://www.vexstar.com/i-have-some-very-interesting-spywaremalware/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

