Alcan a - how to remove? [CLOSED] |
![]() ![]() |
Alcan a - how to remove? [CLOSED] |
Jun 22 2005, 08:28 AM
Post
#1
|
|
|
New Member ![]() Posts: 4 OS: XP |
I'm a bit blonde when it comes to removing a worm and Alcan a is proving a real pain. I tried many of the posted solutions in the earlier thread without success. Like some of the other posters mentioned I can't see the /System32 folder but the most obvious problem is c:\program files\winupdates\winupdates.exe attempting to contact www.katz.ws on startup. Ad-aware spots the worm but NAV2005 fails to detect it. Safe mode is also proving troublesome on will only work if 'with networking' is selected. Any help would be much appreciated. |
|
|
| Guest_Andy_veal_* |
Jun 22 2005, 10:18 AM
Post
#2
|
|
|
In order to assist you, we need to see the log from an Ad-Aware SE 1.06r1 full system scan.
Important Note! Before performing a scan, be sure that you have the most recent definitions file by using WebUpdate. (Click on the Globe icon, Click connect, Click OK, Click Finish.) At this current point * SE1R51 21.06.2005 * is the most recent definition file. Ad-Aware SE comes preconfigured with default options so we need you to make only one change. Please deselect "Search for negligible risk entries" as negligible risk entries (MRU's) are not considered to be a threat. This option can be changed when choosing your scan type. Select "Perform Full System Scan" and press "Next". When the scan has completed, click "Show Logfile". Please copy/paste the complete log file here using the reply button. Don't quarantine or remove anything at this time, just post a complete logfile. This sometimes takes 2-3 posts to get it all posted. You will know you are at the end when you see the "Summary of this scan" information has been posted. When you have posted your log here, Team Lavasoft can advise on what to do next. Please post back if you have any questions or other problems. Good luck |
|
|
Jun 22 2005, 12:07 PM
Post
#3
|
|
|
New Member ![]() Posts: 4 OS: XP |
Cheers Andy.
Ad-Aware SE Build 1.06r1 Logfile Created on:22 June 2005 18:30:23 Created with Ad-Aware SE Personal, free for private use. Using definitions file:SE1R51 21.06.2005 »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» References detected during the scan: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Win32.P2P-Worm.Alcan.a(TAC index:8):9 total references »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Ad-Aware SE Settings =========================== Set : Safe mode (always request confirmation) Set : Scan active processes Set : Scan registry Set : Deep-scan registry Set : Scan my IE Favorites for banned URLs Set : Scan my Hosts file Extended Ad-Aware SE Settings =========================== Set : Unload recognized processes & modules during scan Set : Scan registry for all users instead of current user only Set : During removal, unload Explorer and IE if necessary Set : Let Windows remove files in use at next reboot Set : Delete quarantined objects after restoring Set : Include basic Ad-Aware settings in log file Set : Include additional Ad-Aware settings in log file Set : Include reference summary in log file Set : Include alternate data stream details in log file Set : Play sound at scan completion if scan locates critical objects 22-06-2005 18:30:23 - Scan started. (Full System Scan) Listing running processes »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» #:1 [smss.exe] FilePath : \SystemRoot\System32\ ProcessID : 616 ThreadCreationTime : 22-06-2005 17:26:40 BasePriority : Normal #:2 [csrss.exe] FilePath : \??\C:\WINDOWS\system32\ ProcessID : 672 ThreadCreationTime : 22-06-2005 17:26:42 BasePriority : Normal #:3 [winlogon.exe] FilePath : \??\C:\WINDOWS\system32\ ProcessID : 696 ThreadCreationTime : 22-06-2005 17:26:43 BasePriority : High #:4 [services.exe] FilePath : C:\WINDOWS\system32\ ProcessID : 740 ThreadCreationTime : 22-06-2005 17:26:43 BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Services and Controller app InternalName : services.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : services.exe #:5 [lsass.exe] FilePath : C:\WINDOWS\system32\ ProcessID : 752 ThreadCreationTime : 22-06-2005 17:26:43 BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : LSA Shell (Export Version) InternalName : lsass.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : lsass.exe #:6 [svchost.exe] FilePath : C:\WINDOWS\system32\ ProcessID : 908 ThreadCreationTime : 22-06-2005 17:26:44 BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Generic Host Process for Win32 Services InternalName : svchost.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : svchost.exe #:7 [svchost.exe] FilePath : C:\WINDOWS\system32\ ProcessID : 956 ThreadCreationTime : 22-06-2005 17:26:44 BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Generic Host Process for Win32 Services InternalName : svchost.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : svchost.exe #:8 [svchost.exe] FilePath : C:\WINDOWS\System32\ ProcessID : 988 ThreadCreationTime : 22-06-2005 17:26:44 BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Generic Host Process for Win32 Services InternalName : svchost.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : svchost.exe #:9 [smc.exe] FilePath : C:\Program Files\Sygate\SPF\ ProcessID : 1036 ThreadCreationTime : 22-06-2005 17:26:44 BasePriority : Normal FileVersion : 5.5.00.2710 ProductVersion : 5.5.00.2710 ProductName : Sygate® Security Agent and Personal Firewall CompanyName : Sygate Technologies, Inc. FileDescription : Sygate Agent Firewall InternalName : Smc LegalCopyright : Copyright © 1999 - 2004 Sygate Technologies, Inc. All rights reserved. OriginalFilename : Smc.EXE #:10 [svchost.exe] FilePath : C:\WINDOWS\System32\ ProcessID : 1092 ThreadCreationTime : 22-06-2005 17:26:44 BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Generic Host Process for Win32 Services InternalName : svchost.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : svchost.exe #:11 [svchost.exe] FilePath : C:\WINDOWS\System32\ ProcessID : 1140 ThreadCreationTime : 22-06-2005 17:26:45 BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Generic Host Process for Win32 Services InternalName : svchost.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : svchost.exe #:12 [ccsetmgr.exe] FilePath : C:\Program Files\Common Files\Symantec Shared\ ProcessID : 1380 ThreadCreationTime : 22-06-2005 17:26:46 BasePriority : Normal FileVersion : 103.0.4.3 ProductVersion : 103.0.4.3 ProductName : Client and Host Security Platform CompanyName : Symantec Corporation FileDescription : Symantec Settings Manager Service InternalName : ccSetMgr LegalCopyright : Copyright © 2000-2004 Symantec Corporation. All rights reserved. OriginalFilename : ccSetMgr.exe #:13 [explorer.exe] FilePath : C:\WINDOWS\ ProcessID : 1464 ThreadCreationTime : 22-06-2005 17:26:46 BasePriority : Normal FileVersion : 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 6.00.2900.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Windows Explorer InternalName : explorer LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : EXPLORER.EXE #:14 [sndsrvc.exe] FilePath : C:\Program Files\Common Files\Symantec Shared\ ProcessID : 1524 ThreadCreationTime : 22-06-2005 17:26:47 BasePriority : Normal FileVersion : 5.5.1.6 ProductVersion : 5.5 ProductName : Symantec Security Drivers CompanyName : Symantec Corporation FileDescription : Network Driver Service InternalName : SndSrvc LegalCopyright : Copyright 2002, 2003, 2004 Symantec Corporation OriginalFilename : SndSrvc.exe #:15 [spbbcsvc.exe] FilePath : C:\Program Files\Common Files\Symantec Shared\SPBBC\ ProcessID : 1544 ThreadCreationTime : 22-06-2005 17:26:47 BasePriority : Normal FileVersion : 1,0,1,47 ProductVersion : 1,0,1,47 ProductName : SPBBC CompanyName : Symantec Corporation FileDescription : SPBBC Service InternalName : SPBBCSvc LegalCopyright : Copyright © 2004 Symantec Corporation. All rights reserved. OriginalFilename : SPBBCSvc.exe #:16 [ccevtmgr.exe] FilePath : C:\Program Files\Common Files\Symantec Shared\ ProcessID : 1584 ThreadCreationTime : 22-06-2005 17:26:48 BasePriority : Normal FileVersion : 103.0.4.3 ProductVersion : 103.0.4.3 ProductName : Client and Host Security Platform CompanyName : Symantec Corporation FileDescription : Symantec Event Manager Service InternalName : ccEvtMgr LegalCopyright : Copyright © 2000-2004 Symantec Corporation. All rights reserved. OriginalFilename : ccEvtMgr.exe #:17 [spoolsv.exe] FilePath : C:\WINDOWS\system32\ ProcessID : 1760 ThreadCreationTime : 22-06-2005 17:26:49 BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Spooler SubSystem App InternalName : spoolsv.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : spoolsv.exe #:18 [ctsvccda.exe] FilePath : C:\WINDOWS\System32\ ProcessID : 1888 ThreadCreationTime : 22-06-2005 17:26:49 BasePriority : Normal FileVersion : 1.0.1.0 ProductVersion : 1.0.0.0 ProductName : Creative Service for CDROM Access CompanyName : Creative Technology Ltd FileDescription : Creative Service for CDROM Access InternalName : CTsvcCDAEXE LegalCopyright : Copyright © Creative Technology Ltd., 1999. All rights reserved. OriginalFilename : CTsvcCDA.EXE #:19 [msdtc.exe] FilePath : C:\WINDOWS\System32\ ProcessID : 1932 ThreadCreationTime : 22-06-2005 17:26:49 BasePriority : Normal FileVersion : 2001.12.4414.258 ProductVersion : 03.01.00.4414 ProductName : Microsoft Distributed Transaction Coordinator CompanyName : Microsoft Corporation FileDescription : MS DTC console program InternalName : MSDTC.EXE LegalCopyright : Copyright © Microsoft Corp. 1995-1998 LegalTrademarks : Microsoft® is a registered trademark of Microsoft Corporation. Windows is a trademark of Microsoft Corporation #:20 [navapsvc.exe] FilePath : C:\Program Files\Norton AntiVirus\ ProcessID : 1952 ThreadCreationTime : 22-06-2005 17:26:49 BasePriority : Normal FileVersion : 11.0.9.16 ProductVersion : 11.0.9 ProductName : Norton AntiVirus CompanyName : Symantec Corporation FileDescription : Norton AntiVirus Auto-Protect Service InternalName : NAVAPSVC LegalCopyright : Norton AntiVirus 2005 for Windows 98/ME/2000/XP Copyright © 2004 Symantec Corporation. All rights reserved. OriginalFilename : NAVAPSVC.EXE #:21 [npfmntor.exe] FilePath : C:\Program Files\Norton AntiVirus\IWP\ ProcessID : 156 ThreadCreationTime : 22-06-2005 17:26:52 BasePriority : Normal FileVersion : 11.0.9.16 ProductVersion : 11.0.9 ProductName : Norton AntiVirus CompanyName : Symantec Corporation FileDescription : Norton AntiVirus Firewall Install Monitor InternalName : NPFMonitor LegalCopyright : Norton AntiVirus 2005 for Windows 98/ME/2000/XP Copyright © 2004 Symantec Corporation. All rights reserved. OriginalFilename : NPFMonitor.EXE #:22 [nvsvc32.exe] FilePath : C:\WINDOWS\System32\ ProcessID : 164 ThreadCreationTime : 22-06-2005 17:26:52 BasePriority : Normal FileVersion : 6.14.10.4502 ProductVersion : 6.14.10.4502 ProductName : NVIDIA Driver Helper Service, Version 45.02 CompanyName : NVIDIA Corporation FileDescription : NVIDIA Driver Helper Service, Version 45.02 InternalName : NVSVC LegalCopyright : © NVIDIA Corporation. All rights reserved. OriginalFilename : nvsvc32.exe #:23 [svchost.exe] FilePath : C:\WINDOWS\System32\ ProcessID : 328 ThreadCreationTime : 22-06-2005 17:26:52 BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Generic Host Process for Win32 Services InternalName : svchost.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : svchost.exe #:24 [symlcsvc.exe] FilePath : C:\Program Files\Common Files\Symantec Shared\CCPD-LC\ ProcessID : 352 ThreadCreationTime : 22-06-2005 17:26:52 BasePriority : Normal FileVersion : 1.8.54.841 ProductVersion : 1.8.54.841 ProductName : Symantec Core Component CompanyName : Symantec Corporation FileDescription : Symantec Core Component InternalName : symlcsvc LegalCopyright : Copyright © 2003 OriginalFilename : symlcsvc.exe #:25 [wdfmgr.exe] FilePath : C:\WINDOWS\system32\ ProcessID : 448 ThreadCreationTime : 22-06-2005 17:26:53 BasePriority : Normal FileVersion : 5.2.3790.1230 built by: DNSRV(bld4act) ProductVersion : 5.2.3790.1230 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Windows User Mode Driver Manager InternalName : WdfMgr LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : WdfMgr.exe #:26 [mspmspsv.exe] FilePath : C:\WINDOWS\System32\ ProcessID : 504 ThreadCreationTime : 22-06-2005 17:26:53 BasePriority : Normal FileVersion : 7.00.00.1954 ProductVersion : 7.00.00.1954 ProductName : Microsoft ® DRM CompanyName : Microsoft Corporation FileDescription : WMDM PMSP Service InternalName : MSPMSPSV.EXE LegalCopyright : Copyright © Microsoft Corp. 1981-2000 OriginalFilename : MSPMSPSV.EXE #:27 [alg.exe] FilePath : C:\WINDOWS\System32\ ProcessID : 1440 ThreadCreationTime : 22-06-2005 17:26:56 BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Application Layer Gateway Service InternalName : ALG.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : ALG.exe #:28 [opware12.exe] FilePath : C:\Program Files\ScanSoft\OmniPagePro12.0\ ProcessID : 2064 ThreadCreationTime : 22-06-2005 17:26:58 BasePriority : Normal FileVersion : 12.0 ProductVersion : 12.0 ProductName : OmniPage Pro CompanyName : ScanSoft, Inc. FileDescription : OCR Aware (32-bit) InternalName : OPWARE12.EXE LegalCopyright : Copyright © 1995-2002 ScanSoft, Inc. LegalTrademarks : ScanSoft, OmniPage and OmniPage Pro are registered trademarks of ScanSoft, Inc. in the United States and/or other countries. OriginalFilename : OPWARE12.EXE #:29 [msgplus.exe] FilePath : C:\Program Files\MessengerPlus! 3\ ProcessID : 2120 ThreadCreationTime : 22-06-2005 17:26:59 BasePriority : Normal #:30 [winupdates.exe] FilePath : C:\Program Files\winupdates\ ProcessID : 2136 ThreadCreationTime : 22-06-2005 17:26:59 BasePriority : Normal FileVersion : 3.06 ProductVersion : 3.06 ProductName : inno setup CompanyName : inno setup FileDescription : inno setup InternalName : Setup LegalCopyright : inno setup LegalTrademarks : inno setup OriginalFilename : Setup.exe Comments : inno setup #:31 [ccapp.exe] FilePath : C:\Program Files\Common Files\Symantec Shared\ ProcessID : 2144 ThreadCreationTime : 22-06-2005 17:26:59 BasePriority : Normal FileVersion : 103.0.4.3 ProductVersion : 103.0.4.3 ProductName : Client and Host Security Platform CompanyName : Symantec Corporation FileDescription : Symantec User Session InternalName : ccApp LegalCopyright : Copyright © 2000-2004 Symantec Corporation. All rights reserved. OriginalFilename : ccApp.exe #:32 [ctfmon.exe] FilePath : C:\WINDOWS\system32\ ProcessID : 2160 ThreadCreationTime : 22-06-2005 17:26:59 BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : CTF Loader InternalName : CTFMON LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : CTFMON.EXE #:33 [atidtct.exe] FilePath : C:\Program Files\ATI Multimedia\main\ ProcessID : 2180 ThreadCreationTime : 22-06-2005 17:26:59 BasePriority : Normal FileVersion : 9.02.004 ProductVersion : 9.02 ProductName : ATI Multimedia Center CompanyName : ATI Technologies Inc. FileDescription : ATI Device Detection Application InternalName : AtiDtct LegalCopyright : Copyright © 2003 ATI Technologies Inc. OriginalFilename : AtiDtct.EXE #:34 [diagent.exe] FilePath : C:\Program Files\Creative\SBLive\Diagnostics\ ProcessID : 2248 ThreadCreationTime : 22-06-2005 17:27:00 BasePriority : Normal FileVersion : 1, 1, 4, 0 ProductVersion : 1.01.04 ProductName : Creative Diagnostics Agent CompanyName : Creative Technology Ltd FileDescription : Creative Diagnostics Agent InternalName : Creative Diagnostics Agent LegalCopyright : Copyright © 2002 Creative Technology Ltd OriginalFilename : diagent.exe #:35 [dlg.exe] FilePath : C:\Program Files\Digital Line Detect\ ProcessID : 2272 ThreadCreationTime : 22-06-2005 17:27:00 BasePriority : Normal FileVersion : 1, 0, 0, 1 ProductVersion : 1, 0, 0, 1 ProductName : BVRP Software TestLine CompanyName : BVRP Software FileDescription : Digital Line Detection InternalName : TestLine LegalCopyright : Copyright © 2003 OriginalFilename : TestLine.exe #:36 [wuauclt.exe] FilePath : C:\WINDOWS\system32\ ProcessID : 3056 ThreadCreationTime : 22-06-2005 17:27:40 BasePriority : Normal FileVersion : 5.8.0.2469 built by: lab01_n(wmbla) ProductVersion : 5.8.0.2469 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Automatic Updates InternalName : wuauclt.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : wuauclt.exe #:37 [ad-aware.exe] FilePath : C:\Program Files\Lavasoft\Ad-Aware SE Personal\ ProcessID : 3128 ThreadCreationTime : 22-06-2005 17:28:14 BasePriority : Normal FileVersion : 6.2.0.236 ProductVersion : SE 106 ProductName : Lavasoft Ad-Aware SE CompanyName : Lavasoft Sweden FileDescription : Ad-Aware SE Core application InternalName : Ad-Aware.exe LegalCopyright : Copyright © Lavasoft AB Sweden OriginalFilename : Ad-Aware.exe Comments : All Rights Reserved #:38 [proxomitron.exe] FilePath : C:\Program Files\Proxomitron Naoko-4\ ProcessID : 3148 ThreadCreationTime : 22-06-2005 17:28:25 BasePriority : Normal FileVersion : 4, 5, 0, 4 ProductVersion : Naoko-4.5 2003-6-1 ProductName : Proxomitron CompanyName : Groom-A-Zebu FileDescription : The Proxomitron InternalName : Pancreas frappe' LegalCopyright : Copyright © 1999 - 2003 By Scott R. Lemmon LegalTrademarks : Proxomitron, The, and the letters A-Z OriginalFilename : Proxomitron.exe Comments : The following info, including this line, is incorrect. #:39 [iexplore.exe] FilePath : C:\Program Files\Internet Explorer\ ProcessID : 3320 ThreadCreationTime : 22-06-2005 17:28:44 BasePriority : Normal FileVersion : 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 6.00.2900.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Internet Explorer InternalName : iexplore LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : IEXPLORE.EXE Memory scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 0 Objects found so far: 0 Started registry scan »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Registry Scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 0 Objects found so far: 0 Started deep registry scan »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Deep registry scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 0 Objects found so far: 0 Started Tracking Cookie scan »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Tracking cookie scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 0 Objects found so far: 0 Deep scanning and examining files (C:) »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Win32.P2P-Worm.Alcan.a Object Recognized! Type : File Data : A0000037.dll TAC Rating : 8 Category : Worm Comment : Object : C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1\ FileVersion : 3.0.2.0 ProductVersion : 3.02 ProductName : BigSpeed Zip DLL CompanyName : BigSpeedSoft InternalName : bszip.dll LegalCopyright : © BigSpeedSoft LegalTrademarks : BigSpeed is a trademark of BigSpeedSoft OriginalFilename : bszip.dll Win32.P2P-Worm.Alcan.a Object Recognized! Type : File Data : bszip.dll TAC Rating : 8 Category : Worm Comment : Object : C:\WINDOWS\SYSTEM32\ FileVersion : 3.0.2.0 ProductVersion : 3.02 ProductName : BigSpeed Zip DLL CompanyName : BigSpeedSoft InternalName : bszip.dll LegalCopyright : © BigSpeedSoft LegalTrademarks : BigSpeed is a trademark of BigSpeedSoft OriginalFilename : bszip.dll Disk Scan Result for C:\ »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 0 Objects found so far: 2 Scanning Hosts file...... Hosts file location:"C:\WINDOWS\system32\drivers\etc\hosts". »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Hosts file scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» 4683 entries scanned. New critical objects:0 Objects found so far: 2 Performing conditional scans... »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Win32.P2P-Worm.Alcan.a Object Recognized! Type : File Data : cmd.com TAC Rating : 8 Category : Worm Comment : Object : C:\WINDOWS\system32\ Win32.P2P-Worm.Alcan.a Object Recognized! Type : File Data : netstat.com TAC Rating : 8 Category : Worm Comment : Object : C:\WINDOWS\system32\ Win32.P2P-Worm.Alcan.a Object Recognized! Type : File Data : ping.com TAC Rating : 8 Category : Worm Comment : Object : C:\WINDOWS\system32\ Win32.P2P-Worm.Alcan.a Object Recognized! Type : File Data : regedit.com TAC Rating : 8 Category : Worm Comment : Object : C:\WINDOWS\system32\ Win32.P2P-Worm.Alcan.a Object Recognized! Type : File Data : taskkill.com TAC Rating : 8 Category : Worm Comment : Object : C:\WINDOWS\system32\ Win32.P2P-Worm.Alcan.a Object Recognized! Type : File Data : tasklist.com TAC Rating : 8 Category : Worm Comment : Object : C:\WINDOWS\system32\ Win32.P2P-Worm.Alcan.a Object Recognized! Type : File Data : tracert.com TAC Rating : 8 Category : Worm Comment : Object : C:\WINDOWS\system32\ Conditional scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 7 Objects found so far: 9 18:52:51 Scan Complete Summary Of This Scan »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Total scanning time:00:22:27.250 Objects scanned:185919 Objects identified:9 Objects ignored:0 New critical objects:9 |
|
|
Jun 23 2005, 09:09 PM
Post
#4
|
|
![]() Member ![]() ![]() Posts: 16 From: Illinois OS: Windows XP SP2 |
Hi! I just answered this question for someone else, and wanted to bump yours up as well.
Do you have an anti-virus program running? If so, update it and run a scan. If not, I recommend going to Cnet Downloads and grabbing a free copy of AVG antivirus. Here are the directions for removal from Symantec. Please do not mess around in the registry , unless you are sure you know what you are doing Advice removed This post has been edited by Andy_veal: Jun 26 2005, 01:30 PM |
|
|
| Guest_Andy_veal_* |
Jun 26 2005, 01:32 PM
Post
#5
|
|
|
Thank you for your suggestions guymontech,
Though I have removed your advice from your above post. This is only because of the safety of the victim. As you said, you should not mess around with the registry unless you know what you are doing. Hopefully Ad-aware can help resolve this problem. I hope you understand. |
|
|
| Guest_Andy_veal_* |
Jun 26 2005, 01:33 PM
Post
#6
|
|
|
Hello and Welcome
Ad-aware has found objects on your computer If you chose to clean your computer from what Ad-aware found please follow these instructions below… Please make sure that you are using the * SE1R51 21.06.2005 * definition file. Please launch Ad-Aware SE and click on the gear to access the Configuration Menu. Please make sure that this setting is applied. Click on Tweak > Cleaning Engine > UNcheck "Always try to unload modules before deletion". Disconnect from the internet (for broadband/cable users, it is recommended that you disconnect the cable connection) and close all open browsers or other programs you have running. Please then boot into Safe Mode To clean your machine, it is highly recommended that you clean the following directory contents (but not the directory folder): Please run CCleaner to assist in this process. Download CCleaner (Setup: go to >options > settings > Uncheck "Only delete files in Windows Temp folders older than 48 hours" for cleaning malware files!) * C:\Windows\Temp\ * C:\Documents and Settings\<Your Profile>\Local Settings\Temporary Internet Files\ <- This will delete all your cached internet content including cookies. * C:\Documents and Settings\<Your Profile>\Local Settings\Temp\ * C:\Documents and Settings\<Any other users Profile>\Local Settings\Temporary Internet Files\ * C:\Documents and Settings\<Any other users Profile>\Local Settings\Temp\ * Empty your "Recycle Bin". Please run Ad-Aware SE from the command lines shown in the instructions shown below. Click "Start" > select "Run" > type the text shown in bold below (including the quotation marks and with the same spacing as shown) "C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Aware.exe" /full +procnuke (For the Professional version) "C:\Program Files\Lavasoft\Ad-Aware SE Plus\Ad-Aware.exe" /full +procnuke (For the Plus version) "C:\Program Files\Lavasoft\Ad-Aware SE Personal\Ad-Aware.exe" +procnuke (For the Personal version) Click OK. Please note that the path above is of the default installion location for Ad-aware SE, if this is different, please adjust it to the location that you have installed it to. When the scan has completed, select Next. In the Scanning Results window, select the "Scan Summary" tab. Check the box next to each "target family" you wish to remove. Click next, Click OK. If problems are caused by deleting a family, please leave it. Please shutdown/restart your computer after removal, run a new full scan and post the results as a reply. Do not launch any programs or connect to the internet at this time. Please then copy & paste the complete log file here. Don't quarantine or remove anything at this time, just post a complete logfile. This can sometimes takes 2-3 posts to get it all posted, once the "Summary of this scan" information is shown, you have posted all of your logfile. Please remember when posting another logfile keep "Search for negligible risk entries" deselected as negligible risk entries (MRU's) are not considered to be a threat. This option can be changed when choosing your scan type. Please post back here Good luck Andy |
|
|
Jun 29 2005, 04:11 AM
Post
#7
|
|
|
New Member ![]() Posts: 9 OS: XP |
Hi,
edited for content. Cheers, Ste. This post has been edited by coachwife6: Jun 29 2005, 06:51 AM |
|
|
Jul 5 2005, 07:55 PM
Post
#8
|
|
![]() Malware Expert Posts: 18,682 From: Boston Ma. OS: XP Pro,ME, 98 |
Due to lack of feedback, this topic has been closed.
If you need this topic reopened, please contact a staff member with address of this thread. This applies only to the original topic starter. Everyone else please begin a New Topic. |
|
|
![]() ![]() |
Similar Topics
| Topic Title | Replies / Views | Topic Information | |||||
|---|---|---|---|---|---|---|---|
![]() |
50 / 10,530 | 2nd October 2005 - 07:52 PM bulaklak_01 started - last by Trevuren |
|||||
![]() |
2 / 24,379 | 5th September 2005 - 06:56 AM talon0775 started - last by Buckeye_Sam |
|||||
![]() |
2 / 1,229 | 28th June 2007 - 11:41 PM litodreamerboi4u started - last by __RiP_ChAiN_ |
|||||
![]() |
5 / 1,152 | 30th August 2008 - 05:40 PM red mug started - last by Rorschach112 |
|||||
|
Time is now: 2nd December 2008 - 02:17 AM |
| Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. |