<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Information about Trojan Virus File,Vcrt80.exe (Vcrt80)</title>
	<atom:link href="http://www.virusremovalscan.com/information-about-trojan-virus-filevcrt80exe-vcrt80.htm/feed" rel="self" type="application/rss+xml" />
	<link>http://www.virusremovalscan.com/information-about-trojan-virus-filevcrt80exe-vcrt80.htm</link>
	<description></description>
	<lastBuildDate>Thu, 18 Jun 2009 20:01:02 -0600</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Marcos</title>
		<link>http://www.virusremovalscan.com/information-about-trojan-virus-filevcrt80exe-vcrt80.htm/comment-page-1#comment-1500</link>
		<dc:creator>Marcos</dc:creator>
		<pubDate>Tue, 21 Apr 2009 17:39:51 +0000</pubDate>
		<guid isPermaLink="false">http://www.virusremovalscan.com/?p=342#comment-1500</guid>
		<description>My PC got infected with this virus on 18/04/2009.
This is the HijackThis Log file:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:57:32, on 20/04/2002
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\Archivos de programa\Lavasoft\Ad-Aware 2007\aawservice.exe
D:\WINDOWS\Explorer.EXE
D:\WINDOWS\RTHDCPL.EXE
D:\WINDOWS\system32\RUNDLL32.EXE
D:\WINDOWS\system32\ctfmon.exe
D:\Archivos de programa\REALTEK Semiconductor Corp\REALTEK RTL8185 Wireless LAN Driver and Utility\RtlWake.exe
D:\WINDOWS\system32\spoolsv.exe
D:\Archivos de programa\Prevx\prevx.exe
D:\WINDOWS\system32\nvsvc32.exe
D:\Archivos de programa\Prevx\prevx.exe
C:\explorer.exe
D:\Archivos de programa\Internet Explorer\iexplore.exe
D:\Documents and Settings\admin\Escritorio\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Vínculos
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE D:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE D:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\RunOnce: [Malwarebytes Anti-Malware (reboot)] &quot;D:\Archivos de programa\Malwarebytes&#039; Anti-Malware\mbam.exe&quot; /runcleanupscript
O4 - HKCU\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User &#039;SERVICIO LOCAL&#039;)
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User &#039;Servicio de red&#039;)
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User &#039;SYSTEM&#039;)
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User &#039;Default user&#039;)
O4 - Global Startup: Realtek Wireless LAN Utility.lnk = ?
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra &#039;Tools&#039; menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Archivos de programa\Messenger\msmsgs.exe
O9 - Extra &#039;Tools&#039; menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Archivos de programa\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{9D4618D3-60D8-4AF1-9AAB-F72B1DE9AD12}: NameServer = 192.168.2.100
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - D:\Archivos de programa\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: CSIScanner - Prevx - D:\Archivos de programa\Prevx\prevx.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - D:\WINDOWS\system32\nvsvc32.exe

--
End of file - 3009 bytes

I´ve already re-installled Windows XP, and it still keeps appearing.
I hope you could help me. Thanks in advance.</description>
		<content:encoded><![CDATA[<p>My PC got infected with this virus on 18/04/2009.<br />
This is the HijackThis Log file:<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 20:57:32, on 20/04/2002<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)<br />
Boot mode: Normal</p>
<p>Running processes:<br />
D:\WINDOWS\System32\smss.exe<br />
D:\WINDOWS\system32\winlogon.exe<br />
D:\WINDOWS\system32\services.exe<br />
D:\WINDOWS\system32\lsass.exe<br />
D:\WINDOWS\system32\svchost.exe<br />
D:\WINDOWS\System32\svchost.exe<br />
D:\Archivos de programa\Lavasoft\Ad-Aware 2007\aawservice.exe<br />
D:\WINDOWS\Explorer.EXE<br />
D:\WINDOWS\RTHDCPL.EXE<br />
D:\WINDOWS\system32\RUNDLL32.EXE<br />
D:\WINDOWS\system32\ctfmon.exe<br />
D:\Archivos de programa\REALTEK Semiconductor Corp\REALTEK RTL8185 Wireless LAN Driver and Utility\RtlWake.exe<br />
D:\WINDOWS\system32\spoolsv.exe<br />
D:\Archivos de programa\Prevx\prevx.exe<br />
D:\WINDOWS\system32\nvsvc32.exe<br />
D:\Archivos de programa\Prevx\prevx.exe<br />
C:\explorer.exe<br />
D:\Archivos de programa\Internet Explorer\iexplore.exe<br />
D:\Documents and Settings\admin\Escritorio\HiJackThis.exe</p>
<p>R0 &#8211; HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Vínculos<br />
O4 &#8211; HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE<br />
O4 &#8211; HKLM\..\Run: [SkyTel] SkyTel.EXE<br />
O4 &#8211; HKLM\..\Run: [Alcmtr] ALCMTR.EXE<br />
O4 &#8211; HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE D:\WINDOWS\system32\NvCpl.dll,NvStartup<br />
O4 &#8211; HKLM\..\Run: [nwiz] nwiz.exe /install<br />
O4 &#8211; HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE D:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit<br />
O4 &#8211; HKLM\..\RunOnce: [Malwarebytes Anti-Malware (reboot)] &#8220;D:\Archivos de programa\Malwarebytes&#8217; Anti-Malware\mbam.exe&#8221; /runcleanupscript<br />
O4 &#8211; HKCU\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\ctfmon.exe<br />
O4 &#8211; HKUS\S-1-5-19\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User &#8216;SERVICIO LOCAL&#8217;)<br />
O4 &#8211; HKUS\S-1-5-20\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User &#8216;Servicio de red&#8217;)<br />
O4 &#8211; HKUS\S-1-5-18\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User &#8216;SYSTEM&#8217;)<br />
O4 &#8211; HKUS\.DEFAULT\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User &#8216;Default user&#8217;)<br />
O4 &#8211; Global Startup: Realtek Wireless LAN Utility.lnk = ?<br />
O9 &#8211; Extra button: (no name) &#8211; {e2e2dd38-d088-4134-82b7-f2ba38496583} &#8211; D:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 &#8211; Extra &#8216;Tools&#8217; menuitem: @xpsp3res.dll,-20001 &#8211; {e2e2dd38-d088-4134-82b7-f2ba38496583} &#8211; D:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 &#8211; Extra button: Messenger &#8211; {FB5F1910-F110-11d2-BB9E-00C04F795683} &#8211; D:\Archivos de programa\Messenger\msmsgs.exe<br />
O9 &#8211; Extra &#8216;Tools&#8217; menuitem: Windows Messenger &#8211; {FB5F1910-F110-11d2-BB9E-00C04F795683} &#8211; D:\Archivos de programa\Messenger\msmsgs.exe<br />
O17 &#8211; HKLM\System\CCS\Services\Tcpip\..\{9D4618D3-60D8-4AF1-9AAB-F72B1DE9AD12}: NameServer = 192.168.2.100<br />
O23 &#8211; Service: Ad-Aware 2007 Service (aawservice) &#8211; Lavasoft &#8211; D:\Archivos de programa\Lavasoft\Ad-Aware 2007\aawservice.exe<br />
O23 &#8211; Service: CSIScanner &#8211; Prevx &#8211; D:\Archivos de programa\Prevx\prevx.exe<br />
O23 &#8211; Service: NVIDIA Display Driver Service (NVSvc) &#8211; NVIDIA Corporation &#8211; D:\WINDOWS\system32\nvsvc32.exe</p>
<p>&#8211;<br />
End of file &#8211; 3009 bytes</p>
<p>I´ve already re-installled Windows XP, and it still keeps appearing.<br />
I hope you could help me. Thanks in advance.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
