Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

PAK_GENERIC.005 virus


  • Please log in to reply

#1
LUISLAY

LUISLAY

    New Member

  • Member
  • Pip
  • 2 posts
Hi,

my pc have a PAK_GENERIC.005 virus, but i cant clean it.


I use your cleantibs.exe and it shows this:



Deckard's System Scanner v20071014.68
Run by lfcarvalho on 2008-03-11 14:33:48
Computer is in Normal Mode.
--------------------------------------------------------------------------------

-- System Restore --------------------------------------------------------------

System Restore is disabled; attempting to re-enable...failed; access is denied.


Backed up registry hives.
Performed disk cleanup.



-- HijackThis (run as lfcarvalho.exe) ------------------------------------------

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:35:42, on 11-03-2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\SYSTEM32\DNTUS26.EXE
C:\WINDOWS\SYSTEM32\DWRCS.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe
C:\oracle\ora92\bin\omtsreco.exe
C:\WINDOWS\system32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe
C:\PROGRAM FILES\WIBUKEY\SERVER\WkSvW32.exe
C:\WINDOWS\system32\CCM\CcmExec.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Program Files\Trend Micro\OfficeScan Client\CNTAoSMgr.exe
C:\WINDOWS\TEMP\JVB46F.EXE
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\PTHOSTTR.EXE
C:\Program Files\Trend Micro\OfficeScan Client\Pccntmon.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Google\Gmail Notifier\gnotify.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\system32\sysvers32.exe
C:\Program Files\NudgeMania\NudgeMania.exe
C:\WINDOWS\Temp\nsp1F7.tmp\NM.exe
C:\Program Files\SAP\FrontEnd\sapgui\saplogon.exe
C:\Program Files\Windows Live\Messenger\msvs.exe
C:\WINDOWS\Temp\86.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Documents and Settings\lfcarvalho\Desktop\BIROS LIMPA\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\lfcarvalho.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.babylon.com/home
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R3 - URLSearchHook: Barra de Ferramentas do Yahoo! com bloqueador de pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Acrobat3\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programa Auxiliar de Início de Sessão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [BGINFO] C:\WINDOWS\BGINFO.EXE C:\WINDOWS\BGINFO.BGI /TIMER:0
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [PTHOSTTR] C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\PTHOSTTR.EXE /Start
O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\Program Files\Trend Micro\OfficeScan Client\Pccntmon.exe" -HideWindow
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Windows Version Service] sysvers32.exe
O4 - HKLM\..\Run: [Babylon Client] C:\Program Files\Babylon\Babylon-Pro\Babylon.exe -AutoStart
O4 - HKLM\..\Run: [NvGraphicsInterface] C:\WINDOWS\Temp\86.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [NudgeMania] C:\Program Files\NudgeMania\NudgeMania.exe
O4 - Startup: OpenOffice.org 2.3.lnk = G:\winPenPack\Bin\OpenOffice\program\quickstart.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Acrobat3\Reader\reader_sl.exe
O4 - Global Startup: CLEAN TEMP.BAT
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://intrasonaecom/
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://appldnld.appl...ex/qtplugin.cab
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zon...kr.cab56986.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.mi...b?1194525290303
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.mi...b?1194525283678
O16 - DPF: {BD8667B7-38D8-4C77-B580-18C3E146372C} (Creative Toolbox Plug-in) - http://bmm.imgag.com.../crusher-us.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zon...nt.cab56907.cab
O16 - DPF: {CAFEEFAC-0014-0002-0002-ABCDEFFEDCBA} (Java Runtime Environment 1.4.2) - http://po1prdwit001/...dows-i586-p.exe
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = optimus.pt
O17 - HKLM\Software\..\Telephony: DomainName = optimus.pt
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = optimus.pt
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = optimus.pt
O23 - Service: DameWare NT Utilities 2.6 (DNTUS26) - DameWare Development LLC - C:\WINDOWS\SYSTEM32\DNTUS26.EXE
O23 - Service: DameWare Mini Remote Control (DWMRCS) - DameWare Development LLC - C:\WINDOWS\SYSTEM32\DWRCS.EXE
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: OfficeScanNT RealTime Scan (ntrtscan) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe
O23 - Service: OracleMTSRecoveryService - Oracle Corporation - C:\oracle\ora92\bin\omtsreco.exe
O23 - Service: OracleOraHome92ClientCache - Unknown owner - C:\oracle\ora92\bin\ONRSD.EXE
O23 - Service: OfficeScan NT Listener (tmlisten) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe
O23 - Service: OfficeScan NT Proxy Service (TmProxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\TmProxy.exe
O23 - Service: WIBU-KEY Server (WkSvW32.exe) - WIBU-SYSTEMS AG - C:\PROGRAM FILES\WIBUKEY\SERVER\WkSvW32.exe

--
End of file - 8434 bytes

-- File Associations -----------------------------------------------------------

All associations okay.


-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------

R2 WIBUKEY (WIBU-KEY Kernel Driver) - c:\windows\system32\drivers\wibukey.sys <Not Verified; WIBU-SYSTEMS AG; WIBU-KEY Software Protection System>

S3 Pcouffin (Low level access layer for CD devices) - c:\windows\system32\drivers\pcouffin.sys (file missing)


-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------

R2 DNTUS26 (DameWare NT Utilities 2.6) - c:\windows\system32\dntus26.exe <Not Verified; DameWare Development LLC; DameWare Development Remote Command Server>
R2 DWMRCS (DameWare Mini Remote Control) - c:\windows\system32\dwrcs.exe -service <Not Verified; DameWare Development LLC; DameWare Development DWRCS>
R2 OracleMTSRecoveryService - c:\oracle\ora92\bin\omtsreco.exe "oraclemtsrecoveryservice" <Not Verified; Oracle Corporation; Oracle MTS Recovery Service>
R2 WkSvW32.exe (WIBU-KEY Server) - c:\program files\wibukey\server\wksvw32.exe <Not Verified; WIBU-SYSTEMS AG; WIBU-KEY Software Protection & Licensing System>

S3 OracleOraHome92ClientCache - c:\oracle\ora92\bin\onrsd.exe


-- Device Manager: Disabled ----------------------------------------------------

No disabled devices found.


-- Files created between 2008-02-11 and 2008-03-11 -----------------------------

2008-03-11 14:33:40 0 d-------- H:\Deckard
2008-03-11 12:42:11 0 dr-h----- C:\Documents and Settings\lfcarvalho\Recent
2008-03-11 11:14:45 0 d-------- C:\WINDOWS\LastGood
2008-03-11 10:42:25 0 d-------- C:\Program Files\Dicionario da Lingua Inglesa
2008-03-10 13:16:40 0 d-------- C:\Program Files\Motorola Service Tools
2008-03-10 13:16:12 0 d-------- C:\Program Files\MotoTriage_1_44_2
2008-03-06 12:43:56 0 d-------- C:\Program Files\Babylon
2008-03-06 12:43:28 0 d-------- C:\Documents and Settings\lfcarvalho\Application Data\Babylon
2008-03-06 12:43:28 0 d-------- C:\Documents and Settings\All Users\Application Data\Babylon
2008-02-21 12:37:56 31232 --a------ C:\WINDOWS\system\WWND.DLL <Not Verified; Curlew Software; Zwindow DLL>
2008-02-21 12:37:52 188960 --a------ C:\WINDOWS\system\WINGDE.DLL <Not Verified; Microsoft Corporation; Microsoft® Windows™ Operating System>
2008-02-21 12:37:51 12800 --a------ C:\WINDOWS\system\WING32.DLL <Not Verified; Microsoft Corporation; WinG>
2008-02-21 12:37:49 92208 --a------ C:\WINDOWS\system\WING.DLL <Not Verified; Microsoft Corporation; WinG>
2008-02-21 12:36:40 273053 --a------ C:\WINDOWS\ACDC.SCR
2008-02-19 11:37:49 0 d-------- C:\Program Files\Intelore
2008-02-14 18:37:26 0 d-------- C:\Program Files\AIMP2
2008-02-13 17:40:21 0 d-------- C:\Documents and Settings\lfcarvalho\Application Data\Mozilla
2008-02-11 15:59:23 86528 -r-hs---- C:\WINDOWS\system32\sysvers32.exe


-- Find3M Report ---------------------------------------------------------------

2008-03-11 14:35:36 0 d-------- C:\Program Files\Trend Micro
2008-03-11 11:14:45 0 d-------- C:\Program Files\Windows Live Safety Center
2008-03-11 10:50:17 0 d-------- C:\Program Files\Data
2008-03-11 10:46:52 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-03-10 13:18:06 0 d-------- C:\Program Files\Service Tools
2008-03-07 10:28:51 0 d-------- C:\Program Files\Java
2008-02-26 17:31:42 0 d-------- C:\Program Files\Misc
2008-02-13 17:43:16 0 d-------- C:\Documents and Settings\lfcarvalho\Application Data\gtk-2.0
2008-02-11 16:03:15 0 d-------- C:\Program Files\MSNFans Live Winks
2008-02-01 15:32:46 0 d-------- C:\Program Files\Kanguru
2008-01-26 12:57:38 0 d-------- C:\Program Files\NudgeMania
2008-01-26 10:08:17 2482 --a------ C:\Program Files\OTSTT.osi
2008-01-26 10:08:17 0 d-------- C:\Program Files\OtsFiles
2008-01-26 10:08:17 0 d-------- C:\Program Files\Lists
2008-01-26 10:08:17 0 d-------- C:\Program Files\Help
2008-01-19 12:33:04 0 d-------- C:\Program Files\QuickTime
2008-01-19 12:32:42 0 d-------- C:\Program Files\Apple Software Update
2008-01-17 12:26:50 0 d-------- C:\Program Files\ChaosPro
2008-01-16 11:39:04 0 d-------- C:\Documents and Settings\lfcarvalho\Application Data\Cool Record Edit Pro
2008-01-16 11:22:26 0 d-------- C:\Program Files\Free Sound Recorder
2008-01-15 15:25:06 0 d-------- C:\Program Files\ocxlogin
2008-01-15 11:28:16 0 d-------- C:\Program Files\WinRima
2008-01-15 11:00:10 716 --a------ C:\Documents and Settings\lfcarvalho\Application Data\AtomicAlarmClock.ini
2008-01-15 11:00:03 0 d-------- C:\Program Files\Digital Talking Parrot
2008-01-15 11:00:00 506 --a------ C:\Documents and Settings\lfcarvalho\Application Data\alarms.ini
2008-01-15 10:58:35 73216 --a------ C:\WINDOWS\ST6UNST.EXE <Not Verified; Microsoft Corporation; Microsoft® Visual Basic for Windows>
2008-01-15 10:58:35 286720 -----n--- C:\WINDOWS\Setup1.exe <Not Verified; Microsoft Corporation; Microsoft Visual Basic for Windows>
2008-01-14 11:30:08 201728 --a------ C:\WINDOWS\system32\Opimus screensaver big.scr <Not Verified; ScreenTime Media; ScreenTime For Flash>


-- Registry Dump ---------------------------------------------------------------

*Note* empty entries & legit default entries are not shown


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [06-10-2006 11:11]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [06-10-2006 11:13]
"Persistence"="C:\WINDOWS\system32\igfxpers.exe" [06-10-2006 11:10]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [08-11-2004 10:17]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [08-11-2004 10:17]
"BGINFO"="C:\WINDOWS\BGINFO.exe" [22-09-2004 15:46]
"RTHDCPL"="RTHDCPL.EXE" [22-09-2005 13:36 C:\WINDOWS\RTHDCPL.EXE]
"Alcmtr"="ALCMTR.EXE" [03-05-2005 18:43 C:\WINDOWS\ALCMTR.EXE]
"PTHOSTTR"="C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\PTHOSTTR.exe" [08-06-2006 14:02]
"OfficeScanNT Monitor"="C:\Program Files\Trend Micro\OfficeScan Client\Pccntmon.exe" [07-06-2007 14:12]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [22-02-2008 04:25]
"{0228e555-4f9c-4e35-a3ec-b109a192b4c2}"="C:\Program Files\Google\Gmail Notifier\gnotify.exe" [15-07-2005 21:48]
"HP Software Update"="C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe" [08-05-2007 15:24]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [19-01-2008 12:29]
"Windows Version Service"="sysvers32.exe" [11-02-2008 15:57 C:\WINDOWS\system32\sysvers32.exe]
"Babylon Client"="C:\Program Files\Babylon\Babylon-Pro\Babylon.exe" [27-02-2008 11:19]
"NvGraphicsInterface"="C:\WINDOWS\Temp\86.exe" [11-03-2008 13:01]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [18-10-2007 11:34]
"NudgeMania"="C:\Program Files\NudgeMania\NudgeMania.exe" [25-02-2007 16:08]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableCAD"=0 (0x0)
"RunLogonScriptSync"=1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoWelcomeScreen"=1 (0x1)
"ForceClassicControlPanel"=1 (0x1)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSaveSettings"=0 (0x0)


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\G]
AutoRun\command- G:\AutoRun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{65f38b73-516a-11dc-addc-001b78862842}]
AutoRun\command- F:\AutoRun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{65f38b76-516a-11dc-addc-001b78862842}]
AutoRun\command- G:\AutoRun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7c5707d3-50cf-11dc-add8-001b78862842}]
Auto\command- AdobeR.exe e
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL AdobeR.exe e

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{bb5416bf-6cde-11dc-ade6-001b78862842}]
AutoRun\command- G:\winPenPack.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d0e5ffa2-554a-11dc-ade1-001b78862842}]
AutoRun\command- F:\AutoRun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d0e5ffa3-554a-11dc-ade1-001b78862842}]
AutoRun\command- F:\AutoRun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d8f47552-5160-11dc-add9-001b78862842}]
AutoRun\command- F:\LaunchU3.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f9a9b48d-9a82-11dc-adf3-001b78862842}]
AutoRun\command- F:\AutoRun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f9a9b4b4-9a82-11dc-adf3-001b78862842}]
AutoRun\command- F:\AutoRun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{fae6ddc7-9908-11dc-adf2-001b78862842}]
AutoRun\command- F:\AutoRun.exe

*Newly Created Service* - IDRIVERT
*Newly Created Service* - RDPWD



-- Hosts -----------------------------------------------------------------------

127.0.0.1 rad.msn.com
127.0.0.1 rad.live.com


-- End of Deckard's System Scanner: finished at 2008-03-11 14:36:48 ------------
  • 0

Advertisements


#2
LUISLAY

LUISLAY

    New Member

  • Topic Starter
  • Member
  • Pip
  • 2 posts

Hi,

my pc have a PAK_GENERIC.005 virus, but i cant clean it.


I use your cleantibs.exe and it shows this:



Deckard's System Scanner v20071014.68
Run by lfcarvalho on 2008-03-11 14:33:48
Computer is in Normal Mode.
--------------------------------------------------------------------------------

-- System Restore --------------------------------------------------------------

System Restore is disabled; attempting to re-enable...failed; access is denied.


Backed up registry hives.
Performed disk cleanup.



-- HijackThis (run as lfcarvalho.exe) ------------------------------------------

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:35:42, on 11-03-2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\SYSTEM32\DNTUS26.EXE
C:\WINDOWS\SYSTEM32\DWRCS.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe
C:\oracle\ora92\bin\omtsreco.exe
C:\WINDOWS\system32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe
C:\PROGRAM FILES\WIBUKEY\SERVER\WkSvW32.exe
C:\WINDOWS\system32\CCM\CcmExec.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Program Files\Trend Micro\OfficeScan Client\CNTAoSMgr.exe
C:\WINDOWS\TEMP\JVB46F.EXE
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\PTHOSTTR.EXE
C:\Program Files\Trend Micro\OfficeScan Client\Pccntmon.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Google\Gmail Notifier\gnotify.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\system32\sysvers32.exe
C:\Program Files\NudgeMania\NudgeMania.exe
C:\WINDOWS\Temp\nsp1F7.tmp\NM.exe
C:\Program Files\SAP\FrontEnd\sapgui\saplogon.exe
C:\Program Files\Windows Live\Messenger\msvs.exe
C:\WINDOWS\Temp\86.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Documents and Settings\lfcarvalho\Desktop\BIROS LIMPA\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\lfcarvalho.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.babylon.com/home
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R3 - URLSearchHook: Barra de Ferramentas do Yahoo! com bloqueador de pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Acrobat3\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programa Auxiliar de Início de Sessão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [BGINFO] C:\WINDOWS\BGINFO.EXE C:\WINDOWS\BGINFO.BGI /TIMER:0
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [PTHOSTTR] C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\PTHOSTTR.EXE /Start
O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\Program Files\Trend Micro\OfficeScan Client\Pccntmon.exe" -HideWindow
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Windows Version Service] sysvers32.exe
O4 - HKLM\..\Run: [Babylon Client] C:\Program Files\Babylon\Babylon-Pro\Babylon.exe -AutoStart
O4 - HKLM\..\Run: [NvGraphicsInterface] C:\WINDOWS\Temp\86.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [NudgeMania] C:\Program Files\NudgeMania\NudgeMania.exe
O4 - Startup: OpenOffice.org 2.3.lnk = G:\winPenPack\Bin\OpenOffice\program\quickstart.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Acrobat3\Reader\reader_sl.exe
O4 - Global Startup: CLEAN TEMP.BAT
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://intrasonaecom/
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://appldnld.appl...ex/qtplugin.cab
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zon...kr.cab56986.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.mi...b?1194525290303
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.mi...b?1194525283678
O16 - DPF: {BD8667B7-38D8-4C77-B580-18C3E146372C} (Creative Toolbox Plug-in) - http://bmm.imgag.com.../crusher-us.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zon...nt.cab56907.cab
O16 - DPF: {CAFEEFAC-0014-0002-0002-ABCDEFFEDCBA} (Java Runtime Environment 1.4.2) - http://po1prdwit001/...dows-i586-p.exe
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = optimus.pt
O17 - HKLM\Software\..\Telephony: DomainName = optimus.pt
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = optimus.pt
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = optimus.pt
O23 - Service: DameWare NT Utilities 2.6 (DNTUS26) - DameWare Development LLC - C:\WINDOWS\SYSTEM32\DNTUS26.EXE
O23 - Service: DameWare Mini Remote Control (DWMRCS) - DameWare Development LLC - C:\WINDOWS\SYSTEM32\DWRCS.EXE
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: OfficeScanNT RealTime Scan (ntrtscan) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe
O23 - Service: OracleMTSRecoveryService - Oracle Corporation - C:\oracle\ora92\bin\omtsreco.exe
O23 - Service: OracleOraHome92ClientCache - Unknown owner - C:\oracle\ora92\bin\ONRSD.EXE
O23 - Service: OfficeScan NT Listener (tmlisten) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe
O23 - Service: OfficeScan NT Proxy Service (TmProxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\TmProxy.exe
O23 - Service: WIBU-KEY Server (WkSvW32.exe) - WIBU-SYSTEMS AG - C:\PROGRAM FILES\WIBUKEY\SERVER\WkSvW32.exe

--
End of file - 8434 bytes

-- File Associations -----------------------------------------------------------

All associations okay.


-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------

R2 WIBUKEY (WIBU-KEY Kernel Driver) - c:\windows\system32\drivers\wibukey.sys <Not Verified; WIBU-SYSTEMS AG; WIBU-KEY Software Protection System>

S3 Pcouffin (Low level access layer for CD devices) - c:\windows\system32\drivers\pcouffin.sys (file missing)


-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------

R2 DNTUS26 (DameWare NT Utilities 2.6) - c:\windows\system32\dntus26.exe <Not Verified; DameWare Development LLC; DameWare Development Remote Command Server>
R2 DWMRCS (DameWare Mini Remote Control) - c:\windows\system32\dwrcs.exe -service <Not Verified; DameWare Development LLC; DameWare Development DWRCS>
R2 OracleMTSRecoveryService - c:\oracle\ora92\bin\omtsreco.exe "oraclemtsrecoveryservice" <Not Verified; Oracle Corporation; Oracle MTS Recovery Service>
R2 WkSvW32.exe (WIBU-KEY Server) - c:\program files\wibukey\server\wksvw32.exe <Not Verified; WIBU-SYSTEMS AG; WIBU-KEY Software Protection & Licensing System>

S3 OracleOraHome92ClientCache - c:\oracle\ora92\bin\onrsd.exe


-- Device Manager: Disabled ----------------------------------------------------

No disabled devices found.


-- Files created between 2008-02-11 and 2008-03-11 -----------------------------

2008-03-11 14:33:40 0 d-------- H:\Deckard
2008-03-11 12:42:11 0 dr-h----- C:\Documents and Settings\lfcarvalho\Recent
2008-03-11 11:14:45 0 d-------- C:\WINDOWS\LastGood
2008-03-11 10:42:25 0 d-------- C:\Program Files\Dicionario da Lingua Inglesa
2008-03-10 13:16:40 0 d-------- C:\Program Files\Motorola Service Tools
2008-03-10 13:16:12 0 d-------- C:\Program Files\MotoTriage_1_44_2
2008-03-06 12:43:56 0 d-------- C:\Program Files\Babylon
2008-03-06 12:43:28 0 d-------- C:\Documents and Settings\lfcarvalho\Application Data\Babylon
2008-03-06 12:43:28 0 d-------- C:\Documents and Settings\All Users\Application Data\Babylon
2008-02-21 12:37:56 31232 --a------ C:\WINDOWS\system\WWND.DLL <Not Verified; Curlew Software; Zwindow DLL>
2008-02-21 12:37:52 188960 --a------ C:\WINDOWS\system\WINGDE.DLL <Not Verified; Microsoft Corporation; Microsoft® Windows™ Operating System>
2008-02-21 12:37:51 12800 --a------ C:\WINDOWS\system\WING32.DLL <Not Verified; Microsoft Corporation; WinG>
2008-02-21 12:37:49 92208 --a------ C:\WINDOWS\system\WING.DLL <Not Verified; Microsoft Corporation; WinG>
2008-02-21 12:36:40 273053 --a------ C:\WINDOWS\ACDC.SCR
2008-02-19 11:37:49 0 d-------- C:\Program Files\Intelore
2008-02-14 18:37:26 0 d-------- C:\Program Files\AIMP2
2008-02-13 17:40:21 0 d-------- C:\Documents and Settings\lfcarvalho\Application Data\Mozilla
2008-02-11 15:59:23 86528 -r-hs---- C:\WINDOWS\system32\sysvers32.exe


-- Find3M Report ---------------------------------------------------------------

2008-03-11 14:35:36 0 d-------- C:\Program Files\Trend Micro
2008-03-11 11:14:45 0 d-------- C:\Program Files\Windows Live Safety Center
2008-03-11 10:50:17 0 d-------- C:\Program Files\Data
2008-03-11 10:46:52 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-03-10 13:18:06 0 d-------- C:\Program Files\Service Tools
2008-03-07 10:28:51 0 d-------- C:\Program Files\Java
2008-02-26 17:31:42 0 d-------- C:\Program Files\Misc
2008-02-13 17:43:16 0 d-------- C:\Documents and Settings\lfcarvalho\Application Data\gtk-2.0
2008-02-11 16:03:15 0 d-------- C:\Program Files\MSNFans Live Winks
2008-02-01 15:32:46 0 d-------- C:\Program Files\Kanguru
2008-01-26 12:57:38 0 d-------- C:\Program Files\NudgeMania
2008-01-26 10:08:17 2482 --a------ C:\Program Files\OTSTT.osi
2008-01-26 10:08:17 0 d-------- C:\Program Files\OtsFiles
2008-01-26 10:08:17 0 d-------- C:\Program Files\Lists
2008-01-26 10:08:17 0 d-------- C:\Program Files\Help
2008-01-19 12:33:04 0 d-------- C:\Program Files\QuickTime
2008-01-19 12:32:42 0 d-------- C:\Program Files\Apple Software Update
2008-01-17 12:26:50 0 d-------- C:\Program Files\ChaosPro
2008-01-16 11:39:04 0 d-------- C:\Documents and Settings\lfcarvalho\Application Data\Cool Record Edit Pro
2008-01-16 11:22:26 0 d-------- C:\Program Files\Free Sound Recorder
2008-01-15 15:25:06 0 d-------- C:\Program Files\ocxlogin
2008-01-15 11:28:16 0 d-------- C:\Program Files\WinRima
2008-01-15 11:00:10 716 --a------ C:\Documents and Settings\lfcarvalho\Application Data\AtomicAlarmClock.ini
2008-01-15 11:00:03 0 d-------- C:\Program Files\Digital Talking Parrot
2008-01-15 11:00:00 506 --a------ C:\Documents and Settings\lfcarvalho\Application Data\alarms.ini
2008-01-15 10:58:35 73216 --a------ C:\WINDOWS\ST6UNST.EXE <Not Verified; Microsoft Corporation; Microsoft® Visual Basic for Windows>
2008-01-15 10:58:35 286720 -----n--- C:\WINDOWS\Setup1.exe <Not Verified; Microsoft Corporation; Microsoft Visual Basic for Windows>
2008-01-14 11:30:08 201728 --a------ C:\WINDOWS\system32\Opimus screensaver big.scr <Not Verified; ScreenTime Media; ScreenTime For Flash>


-- Registry Dump ---------------------------------------------------------------

*Note* empty entries & legit default entries are not shown


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [06-10-2006 11:11]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [06-10-2006 11:13]
"Persistence"="C:\WINDOWS\system32\igfxpers.exe" [06-10-2006 11:10]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [08-11-2004 10:17]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [08-11-2004 10:17]
"BGINFO"="C:\WINDOWS\BGINFO.exe" [22-09-2004 15:46]
"RTHDCPL"="RTHDCPL.EXE" [22-09-2005 13:36 C:\WINDOWS\RTHDCPL.EXE]
"Alcmtr"="ALCMTR.EXE" [03-05-2005 18:43 C:\WINDOWS\ALCMTR.EXE]
"PTHOSTTR"="C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\PTHOSTTR.exe" [08-06-2006 14:02]
"OfficeScanNT Monitor"="C:\Program Files\Trend Micro\OfficeScan Client\Pccntmon.exe" [07-06-2007 14:12]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [22-02-2008 04:25]
"{0228e555-4f9c-4e35-a3ec-b109a192b4c2}"="C:\Program Files\Google\Gmail Notifier\gnotify.exe" [15-07-2005 21:48]
"HP Software Update"="C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe" [08-05-2007 15:24]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [19-01-2008 12:29]
"Windows Version Service"="sysvers32.exe" [11-02-2008 15:57 C:\WINDOWS\system32\sysvers32.exe]
"Babylon Client"="C:\Program Files\Babylon\Babylon-Pro\Babylon.exe" [27-02-2008 11:19]
"NvGraphicsInterface"="C:\WINDOWS\Temp\86.exe" [11-03-2008 13:01]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [18-10-2007 11:34]
"NudgeMania"="C:\Program Files\NudgeMania\NudgeMania.exe" [25-02-2007 16:08]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableCAD"=0 (0x0)
"RunLogonScriptSync"=1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoWelcomeScreen"=1 (0x1)
"ForceClassicControlPanel"=1 (0x1)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSaveSettings"=0 (0x0)


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\G]
AutoRun\command- G:\AutoRun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{65f38b73-516a-11dc-addc-001b78862842}]
AutoRun\command- F:\AutoRun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{65f38b76-516a-11dc-addc-001b78862842}]
AutoRun\command- G:\AutoRun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7c5707d3-50cf-11dc-add8-001b78862842}]
Auto\command- AdobeR.exe e
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL AdobeR.exe e

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{bb5416bf-6cde-11dc-ade6-001b78862842}]
AutoRun\command- G:\winPenPack.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d0e5ffa2-554a-11dc-ade1-001b78862842}]
AutoRun\command- F:\AutoRun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d0e5ffa3-554a-11dc-ade1-001b78862842}]
AutoRun\command- F:\AutoRun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d8f47552-5160-11dc-add9-001b78862842}]
AutoRun\command- F:\LaunchU3.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f9a9b48d-9a82-11dc-adf3-001b78862842}]
AutoRun\command- F:\AutoRun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f9a9b4b4-9a82-11dc-adf3-001b78862842}]
AutoRun\command- F:\AutoRun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{fae6ddc7-9908-11dc-adf2-001b78862842}]
AutoRun\command- F:\AutoRun.exe

*Newly Created Service* - IDRIVERT
*Newly Created Service* - RDPWD



-- Hosts -----------------------------------------------------------------------

127.0.0.1 rad.msn.com
127.0.0.1 rad.live.com


-- End of Deckard's System Scanner: finished at 2008-03-11 14:36:48 ------------





and :

Deckard's System Scanner v20071014.68
Extra logfile - please post this as an attachment with your post.
--------------------------------------------------------------------------------

-- System Information ----------------------------------------------------------

Microsoft Windows XP Professional (build 2600) SP 2.0
Architecture: X86; Language: English

CPU 0: Intel® Core™2 CPU 4300 @ 1.80GHz
CPU 1: Intel® Core™2 CPU 4300 @ 1.80GHz
Percentage of Memory in Use: 42%
Physical Memory (total/avail): 2023.23 MiB / 1164.97 MiB
Pagefile Memory (total/avail): 3380.48 MiB / 2669.63 MiB
Virtual Memory (total/avail): 2047.88 MiB / 1928.98 MiB

C: is Fixed (NTFS) - 15.01 GiB total, 5.63 GiB free.
D: is Fixed (NTFS) - 59.52 GiB total, 48.25 GiB free.
E: is CDROM (No Media)
H: is Network (NTFS)

\\.\PHYSICALDRIVE0 - WDC WD800JD-60LSA5 - 74.53 GiB - 2 partitions
\PARTITION0 (bootable) - Installable File System - 15.01 GiB - C:
\PARTITION1 - Extended w/Extended Int 13 - 59.52 GiB - D:



-- Security Center -------------------------------------------------------------

AUOptions is disabled.
Windows Internal Firewall is enabled.

FirstRunDisabled is set.
AntiVirusDisableNotify is set.
FirewallDisableNotify is set.
UpdatesDisableNotify is set.
AntivirusOverride is set.
FirewallOverride is set.

AV: Trend Micro OfficeScan Antivirus v8.0 (TrendAntiVirus) Disabled

[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"

[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\WINDOWS\\Temp\\47.exe"="C:\\WINDOWS\\Temp\\47.exe:*:Enabled:@xpsp2res.dll,-22005"
"C:\\WINDOWS\\Temp\\53.exe"="C:\\WINDOWS\\Temp\\53.exe:*:Enabled:@xpsp2res.dll,-22005"
"C:\\WINDOWS\\Temp\\08.exe"="C:\\WINDOWS\\Temp\\08.exe:*:Enabled:@xpsp2res.dll,-22005"
"C:\\WINDOWS\\Temp\\28.exe"="C:\\WINDOWS\\Temp\\28.exe:*:Enabled:@xpsp2res.dll,-22005"
"C:\\WINDOWS\\Temp\\57.exe"="C:\\WINDOWS\\Temp\\57.exe:*:Enabled:@xpsp2res.dll,-22005"
"C:\\WINDOWS\\Temp\\21.exe"="C:\\WINDOWS\\Temp\\21.exe:*:Enabled:@xpsp2res.dll,-22005"
"C:\\WINDOWS\\Temp\\85.exe"="C:\\WINDOWS\\Temp\\85.exe:*:Enabled:@xpsp2res.dll,-22005"
"C:\\WINDOWS\\Temp\\86.exe"="C:\\WINDOWS\\Temp\\86.exe:*:Enabled:@xpsp2res.dll,-22005"


-- Environment Variables -------------------------------------------------------

ALLUSERSPROFILE=C:\Documents and Settings\All Users
APPDATA=C:\Documents and Settings\lfcarvalho\Application Data
CLASSPATH=.;C:\Program Files\Java\jre1.6.0_03\lib\ext\QTJava.zip
CommonProgramFiles=C:\Program Files\Common Files
COMPUTERNAME=OPLX10DT0044
ComSpec=C:\WINDOWS\system32\cmd.exe
FP_NO_HOST_CHECK=NO
HOMEDRIVE=H:
HOMEPATH=\
HOMESHARE=\\lx1srv003\lfcarvalho$
LOGONSERVER=\\LX3DC002
NUMBER_OF_PROCESSORS=2
OS=Windows_NT
Path=C:\Program Files\Common Files\Microsoft Shared\MODI\11.0;C:\Program Files\ocxlogin\;C:\Program Files\Oracle\jre\1.1.8\bin\;C:\Program Files\Oracle\jre\1.3.1\bin\;C:\oracle\ora92\bin\;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\BSCS\exe;C:\centrun\;C:\SQL\;C:\Program Files\Common Files\Starbase\;C:\Program Files\QuickTime\QTSystem\;C:\PROGRA~1\COMMON~1\MICROS~1\MODI\11.0\
PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
PROCESSOR_ARCHITECTURE=x86
PROCESSOR_IDENTIFIER=x86 Family 6 Model 15 Stepping 2, GenuineIntel
PROCESSOR_LEVEL=6
PROCESSOR_REVISION=0f02
ProgramFiles=C:\Program Files
PROMPT=$P$G
QTJAVA=C:\Program Files\Java\jre1.6.0_03\lib\ext\QTJava.zip
SESSIONNAME=Console
SystemDrive=C:
SystemRoot=C:\WINDOWS
TEMP=C:\WINDOWS\Temp
TMP=C:\WINDOWS\Temp
TNS_ADMIN=C:\PROGRA~1\SONAECOM\HELPDESK\oracle
USERDNSDOMAIN=OPTIMUS.PT
USERDOMAIN=OPTIMUS
USERNAME=lfcarvalho
USERPROFILE=C:\Documents and Settings\lfcarvalho
windir=C:\WINDOWS
__COMPAT_LAYER=EnableNXShowUI


-- User Profiles ---------------------------------------------------------------

Teste (new local)
Administrator (admin)
lfcarvalho (admin)


-- Add/Remove Programs ---------------------------------------------------------

--> rundll32.exe "C:\Program Files\Synaptics\SynTP\SynISDLL.dll",standAloneUninstall
--> rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
Adobe Flash Player ActiveX --> C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Reader 7.0.9 --> MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A70900000002}
Adobe Shockwave Player --> C:\WINDOWS\system32\Macromed\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Macromed\SHOCKW~1\Install.log
Apple Software Update --> MsiExec.exe /I{B74F042E-E1B9-4A5B-8D46-387BB172F0A4}
Assistente de Início de Sessão do Windows Live --> MsiExec.exe /I{AFA4E5FD-ED70-4D92-99D0-162FD56DC986}
AviSynth 2.5 --> "C:\Program Files\AviSynth 2.5\Uninstall.exe"
Babylon --> C:\Program Files\Babylon\Babylon-Pro\Utils\uninstbb.exe
CCleaner (remove only) --> "C:\Program Files\CCleaner\uninst.exe"
Compatibility Pack for the 2007 Office system --> MsiExec.exe /X{90120000-0020-0409-0000-0000000FF1CE}
Dicionário da Língua Inglesa --> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\1050\INTEL3~1\IDriver.exe /M{667FC080-AE49-43B9-AF2D-FCF58996E2CB}
ExtractNow --> "C:\Program Files\ExtractNow\unins000.exe"
Free Sound Recorder v5.9.5 --> "C:\Program Files\Free Sound Recorder\unins000.exe"
Google Gmail Notifier --> "C:\Program Files\Google\Gmail Notifier\UninstallGmail.exe"
High Definition Audio Driver Package - KB888111 -->
Hotfix for Windows Media Format 11 SDK (KB929399) --> "C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
Hotfix for Windows Media Format SDK (KB902344) -->
HP ProtectTools Security Manager 2.00 D3 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{914E1AB1-DCA0-4A7D-935F-B58C4B887A2B}\setup.exe" -l0x9 -removeonly hpquninst
HP Update --> MsiExec.exe /X{25F6C900-C138-4888-A56C-91D3D063023A}
Intel® Graphics Media Accelerator Driver --> C:\WINDOWS\system32\igxpun.exe -uninstall
Intel® PRO Network Connections Drivers --> Prounstl.exe
Intranet Chat --> C:\PROGRA~1\IChat\UNWISE.EXE C:\PROGRA~1\IChat\INSTALL.LOG
Java 2 Runtime Environment, SE v1.4.2_02 --> MsiExec.exe /I{7148F0A8-6813-11D6-A77B-00B0D0142020}
Java 2 Runtime Environment, SE v1.4.2_10 --> MsiExec.exe /I{7148F0A8-6813-11D6-A77B-00B0D0142100}
Java™ 6 Update 2 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160020}
Java™ 6 Update 3 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160030}
Java™ 6 Update 5 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160050}
Kanguru --> C:\PROGRA~1\Kanguru\UNWISE.EXE C:\PROGRA~1\Kanguru\INSTALL.LOG
Microsoft Base Smart Card Cryptographic Service Provider Package -->
Microsoft Kernel-Mode Driver Framework Feature Pack 1.5 --> "C:\WINDOWS\$NtUninstallWdf01005$\spuninst\spuninst.exe"
Microsoft Office 2003 Proofing Tools --> MsiExec.exe /I{901F0409-6000-11D3-8CFE-0150048383C9}
Microsoft Office Professional Edition 2003 --> MsiExec.exe /I{90110409-6000-11D3-8CFE-0150048383C9}
Microsoft SOAP Toolkit 3.0 --> MsiExec.exe /I{BCB4C18A-ACA6-4383-8688-E19933A705DD}
Mobile Connect --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{3EAAC5FD-E209-4856-8C49-D4EA40F85032}\setup.exe" -l0x9 -removeonly
Motofunctional --> C:\PROGRA~1\DATAFA~1\MOTOFU~1\UNWISE.EXE C:\PROGRA~1\DATAFA~1\MOTOFU~1\INSTALL.LOG
Motorola Driver Installation --> MsiExec.exe /I{EF157183-801D-42E5-BDCD-F30DE13FC7EB}
Motorola PST --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{8CC5BF82-4DD4-11D4-A39F-00C04F05E3F0}\Setup.exe" -l0x9 anything
MotoTriage --> MsiExec.exe /I{2CD5D504-4B73-4224-BA3E-6E2F08E74EDD}
MotoTriage --> MsiExec.exe /I{74376B57-E824-4802-9485-902ED68FE80B}
NTP Software QM Inquiry Tool NT --> C:\WINDOWS\uninst.exe -f"C:\Program Files\NTPSoftware\qminq\DeIsL1.isu"
NudgeMania 4.0 for Messenger --> C:\Program Files\NudgeMania\uninstall.exe
Opimus screensaver big --> C:\WINDOWS\system32\Opimus screensaver big.scr /u
OtsTurntables Free 1.00.012 --> "C:\WINDOWS\OTS_UI.EXE" "C:\Program Files\OTSTT.osi"
QuickTime --> MsiExec.exe /I{6EC874C2-F950-4B7E-A5B7-B1066D6B74AA}
ratDVD 0.78.1444 --> C:\Program Files\ratDVD\uninst.exe
Realtek High Definition Audio Driver --> RtlUpd.exe -r
Rhapsody Player Engine --> MsiExec.exe /I{8A62A068-3FD6-495A-9F66-26FE94F32EC9}
RSD_LITE_3_4 --> MsiExec.exe /X{3ED95676-6761-4024-B115-A471F44597FF}
Service Center Application --> C:\WINDOWS\st6unst.exe -n "C:\Program Files\SCA\ST6UNST.LOG"
Service Tool Uninstaller --> "C:\Program Files\Service Tools\uninstall.exe"
SONAECOM Helpdesk (AR System User 5.1.0) --> MsiExec.exe /I{EDD7182A-D2EF-4E50-BB19-7B039913E46A}
SONAECOM Helpdesk (BSCS 1.0.0) --> MsiExec.exe /I{5281BBC1-285F-43C7-A2E0-3CB9A0CD75BD}
SONAECOM Helpdesk (Caliber RM 4.10.17.0084) --> MsiExec.exe /I{D9BAED1D-CBFF-4FE3-91AA-2CD15846D1B5}
SONAECOM Helpdesk (Centura Runtime 1.1) --> MsiExec.exe /I{057BAC0F-6E58-4275-84BE-9B28245F6DC6}
SONAECOM Helpdesk (Oracle Client 9.2.0.1.0) --> MsiExec.exe /I{633CE65F-8AA6-4DC5-8F43-A15783E122A9}
SONAECOM Helpdesk (Oracle Configuration 1.0.0) --> MsiExec.exe /I{234278E3-EE9D-49BB-931C-FAF3619D39CD}
SONAECOM Helpdesk (SAP 6.40) --> MsiExec.exe /I{4496BECF-4DB2-421D-A355-48F035DC8ED6}
SONAECOM Mobile LCD 2.0.0 --> MsiExec.exe /I{4D6684E0-2661-410F-8DF0-F5698451D990}
SONAECOM OCXLogin 2.0.1 --> MsiExec.exe /I{057AA7DF-906F-41BF-BF39-268D4C899E8F}
Time Adjuster STANDARD 3.1 --> "C:\Program Files\TimeAdjuster\Uninstall.exe"
Trend Micro OfficeScan Client --> "C:\Program Files\Trend Micro\OfficeScan Client\ntrmv.exe"
VobSub v2.23 (Remove Only) --> "C:\Program Files\Gabest\VobSub\uninstall.exe"
WIBU-KEY Setup (WIBU-KEY Remove) --> C:\Program Files\WIBUKEY\Setup\Setup32.exe /R:{00060000-0000-1004-8002-0000C06B5161}
Windows Live installer --> MsiExec.exe /X{3A417047-2E30-4D05-8977-F706D40BFF39}
Windows Live Messenger --> MsiExec.exe /X{8EADB73B-026D-4978-A8F0-1EEF5E1ECEC7}
Windows Live OneCare safety scanner --> RunDll32.exe "C:\Program Files\Windows Live Safety Center\wlscCore.dll",UninstallFunction WLSC_SCANNER_PRODUCT
Windows Media Connect -->
Windows Rights Management Client Backwards Compatibility SP2 --> MsiExec.exe /X{EC905264-BCFE-423B-9C42-C3A106266790}
Windows Rights Management Client with Service Pack 2 --> MsiExec.exe /X{BDCF27CA-BFC4-4F49-8D24-A925C9505AB8}
WinRima 2.0 --> C:\WINDOWS\st6unst.exe -n "C:\Program Files\WinRima\ST6UNST.LOG"
XP Codec Pack --> C:\Program Files\XP Codec Pack\Uninstall.exe
XviD MPEG4 Video Codec (remove only) --> "C:\WINDOWS\system32\xvid-uninstall.exe"


-- Application Event Log -------------------------------------------------------

Event Record #/Type6297 / Error
Event Submitted/Written: 03/11/2008 01:24:16 PM
Event ID/Source: 11706 / MsiInstaller
Event Description:
Product: Microsoft Office 2003 Proofing Tools -- Error 1706. Setup cannot find the required files. Check your connection to the network, or CD-ROM drive. For other potential solutions to this problem, see C:\Program Files\Microsoft Office\OFFICE11\1033\SETUP.CHM.

Event Record #/Type6296 / Warning
Event Submitted/Written: 03/11/2008 01:23:45 PM
Event ID/Source: 1001 / MsiInstaller
Event Description:
Detection of product '{901F0409-6000-11D3-8CFE-0150048383C9}', feature 'OCR_1046' failed during request for component '{AF9B0416-B0A1-43FB-BF87-318E1795CF46}'

Event Record #/Type6294 / Error
Event Submitted/Written: 03/11/2008 01:12:37 PM
Event ID/Source: 11706 / MsiInstaller
Event Description:
Product: Microsoft Office 2003 Proofing Tools -- Error 1706. Setup cannot find the required files. Check your connection to the network, or CD-ROM drive. For other potential solutions to this problem, see C:\Program Files\Microsoft Office\OFFICE11\1033\SETUP.CHM.

Event Record #/Type6293 / Warning
Event Submitted/Written: 03/11/2008 01:10:59 PM
Event ID/Source: 1001 / MsiInstaller
Event Description:
Detection of product '{901F0409-6000-11D3-8CFE-0150048383C9}', feature 'OCR_1046' failed during request for component '{AF9B0416-B0A1-43FB-BF87-318E1795CF46}'

Event Record #/Type6291 / Error
Event Submitted/Written: 03/11/2008 00:40:12 PM
Event ID/Source: 1000 / Windows Live Messenger
Event Description:
msnmsgr.exe8.5.1302.10184717a53bntdll.dll5.1.2600.2180411096b4000010f29



-- Security Event Log ----------------------------------------------------------

No Errors/Warnings found.


-- System Event Log ------------------------------------------------------------

Event Record #/Type611 / Warning
Event Submitted/Written: 03/11/2008 02:26:08 PM
Event ID/Source: 4226 / Tcpip
Event Description:
TCP/IP has reached the security limit imposed on the number of concurrent TCP connect attempts.

Event Record #/Type610 / Warning
Event Submitted/Written: 03/11/2008 01:44:04 PM
Event ID/Source: 4226 / Tcpip
Event Description:
TCP/IP has reached the security limit imposed on the number of concurrent TCP connect attempts.

Event Record #/Type606 / Error
Event Submitted/Written: 03/11/2008 01:23:17 PM
Event ID/Source: 10005 / DCOM
Event Description:
DCOM got error "%%1058" attempting to start the service usnjsvc with arguments ""
in order to run the server:
{98AC5C33-EE18-4EC2-BE25-3B16EE8F75F1}

Event Record #/Type605 / Error
Event Submitted/Written: 03/11/2008 01:23:07 PM
Event ID/Source: 10005 / DCOM
Event Description:
DCOM got error "%%1058" attempting to start the service usnjsvc with arguments ""
in order to run the server:
{98AC5C33-EE18-4EC2-BE25-3B16EE8F75F1}

Event Record #/Type604 / Error
Event Submitted/Written: 03/11/2008 01:22:56 PM
Event ID/Source: 10005 / DCOM
Event Description:
DCOM got error "%%1058" attempting to start the service usnjsvc with arguments ""
in order to run the server:
{98AC5C33-EE18-4EC2-BE25-3B16EE8F75F1}



-- End of Deckard's System Scanner: finished at 2008-03-11 14:36:48 ------------
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP