Once the license is accepted, reset to 100%. ============================ Please post the Combofix.txt and the Kaspersky report in your next reply. Fromine WinPopup winpopup.exe N Instant Messenger program Generic Host Process for Win32 Services winsvc.exe X Added by the SDBOT-O WORM! I have not used the computer since posting, but here is a new DDS.txt file and thanks in advance for your help. Click View scan report at the bottom.
Windows System Manager winsystem.exe X Added by the RBOT-AN WORM! Available via Start -> Programs wfxsnt40 wfxsnt40.exe Y WinFax 10.0 and maybe earlier versions. Microsofts media winmplayd.exe X Added by an undidentified WORM or TROJAN! Read through the requirements and privacy statement and click on Accept button.
When installation has finished, make sure you leave both of these checked: Update Malwarebytes' Anti-Malware Launch Malwarebytes' Anti-Malware Then click Finish. winsecure winsecure.exe X Browser hijacker, redirecting to specificsearches.com WinServices WinServices.exe X Added by the YAHA.K or YAHA.M WORMS! Shell wmedia16.exe X Added by the GOLDUN TROJAN! Note - this is not the legitimate winlogon.exe process which should NOT appear in Msconfig/Startup!
Note for Internet Explorer 7 users: If at any time you have trouble viewing the accept button of the license, click on the Zoom tool located at the bottom right of Microsoft System Checkup Wnetlib.exe X Added by the DONK.C WORM! WinGuides Tweak Manager. Windows System Security winmp.exe X Added by the RBOT.IV WORM!
This has to be cleared at the same time as RegCompres (REGCPM32.EXE), atisrc2 (windfind.exe) and mmxrun (msosa.exe), otherwise they return MSUpdate wupd.exe X Added by the ALADINZ.M TROJAN! Available via Start -> Programs wind.exe wind.exe X Added by the MITGLIEDER.BD TROJAN! Windows Help File winhelper32.exe X Added by the SDBOT-QK TROJAN! Windll.exe Windll.exe X Added by the STEALER TROJAN!
Microsoft Update Machine winhost.exe X Added by the RBOT-GK WORM! http://gsdclb.org/general/troj-startpag-re.php Related to the Wacom Penabled driver on Acer Tablet PCs. run= wswpd.exe Y Used with some models of Panasonic, Epson and NEC printers - required for printer to work run= wmplayer.exe X CoolWebSearch parasite variant - Note: this is not the Configuration Default Wuxat.exe X Added by the SPYBOT-CA WORM!
Appears if you chose to have the program appear in the taskbar (System Tray) during installation and displays a yellow fax/telephone icon. Winsrv winsrv.exe X Added by the OPASERV.T WORM! WinSec winsec16.exe X Added by the AGOBOT.ZF WORM! http://gsdclb.org/general/troj-vb-fxh.php You should only think this file is an infection if you also have a Run entry containing the name listed in this page.
It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here win32_i ml097e win32_i.exe X Variant of the RapidBlaster parasite (in a "win32_i" folder in Program Files). Probably left as a result of a failed installation EbatesMoeMoneyMaker wjview ...Code N Ebates adware Eicon NetworksLAN_DAEMON watch.exe U Associated with an Eicon Networks ISDN or ADSL modem. Win32dll Win32dll.exe X Added by the BANPAES TROJAN!
Do NOT be alarmed by what you see in the report. WEATHER WEATHER.EXE N Weatherbug provides current outdoor temperature in the System Tray, also weather alerts. DDS (Version 1.1.0) - NTFSx86 Run by Owner at 9:01:52.07 on Sun 12/28/2008 Internet Explorer: 7.0.5730.11 BrowserJavaVersion: 1.6.0_11 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1023.322 [GMT -5:00] AV: Panda Internet Security 2009 *On-access won update WAPDATE.EXE X Added by the WIN32.RBOT.N WORM!
Microsoft media services winmplayer.exe X Added by the RBOT.ZO WORM! It will start downloading and installing the scanner and virus definitions. Note - this is NOT the Winamp Media Player WinampAgent WINAMPa.exe U Loads the System Tray icon for the WinAmp media player. navigate here Not only should you disable it from running, you should delete the thing altogether, as it, somehow can re-enable itself.
Upgrading Java: Download the latest version of Java Runtime Environment (JRE) 6 Update 7. Windows Video Acquisition (WVA) wvsvc.exe X Added by the AGOBOT.YM WORM! Skin application to change the appearence on Windows desktops. Advertisements do not imply our endorsement of that product or service.
Win32 Device Loader Win32ldr.exe X Added by a variant of the AGOBOT/GAOBOT WORM! The WatchDog check for registry changes caused by trojan's, viruses, etc Remote Procedure Call winrpc.exe X Added by the RBOT-KM WORM! Winmain winmain.exe X One of the first of a new breed of malware. a-winpoet-service winpppoverethernet.exe Y WinPoET is the industry's first Windows-based PPP over Ethernet client.
Win32 USB2 Driver wind32.exe X Added by the FORBOT-AH WORM! windir winrun.exe X Added by the WINBUR.B WORM! winroute winroute.exe N Win-Route 4.27. WinStart WinStart.pif X Added by the CONE
Sorry for the delayed response. winhlpp32.exe winhlpp32.exe X Added by the GAOBOT.SY WORM! Developed by iVasion, WinPoET is attractive to equipment providers, modem suppliers, RBOCs and ISPs. WebcamRT.exe WEBCAMRT.exe N For Logitech Web Cams.
Winad Client Winad.exe X WinAd adware by eXact Advertising winadm winadm.exe X Browser hijacker - redirecting to Search-World.net. Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup! Used to map out Windows key hotkey combinations. Video winamp32.exe X Added by the AGOBOT-NG WORM!
winocx32 winocx32.exe X Added by the PROTORIDE.I WORM!