Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Can't open Add/Remove Programs


  • Please log in to reply

#1
TheJackal

TheJackal

    New Member

  • Member
  • Pip
  • 3 posts
Every time I try to open Add/REmove programs, I get the following error in my event viewer..
"Faulting application rundll32.exe, version 5.1.2600.2180, faulting module appwiz.cpl, version 5.1.2600.2180, fault address 0x000105fd."





This is my HIJACKTHIS log:

Logfile of HijackThis v1.99.1
Scan saved at 9:47:01 AM, on 6/23/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Symantec AntiVirus\SavRoam.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\system32\ltcm000c.exe
C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\Program Files\2Wire HomePortal Monitor\2portalmon.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\hpoopm07.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\WINDOWS\system32\PELMICED.EXE
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\WINDOWS\system32\hphmon04.exe
C:\WINDOWS\system32\dll\csrss.exe
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~2\VPTray.exe
C:\Program Files\Netopia\C3kWepN.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\America Online 9.0\waol.exe
C:\PROGRA~1\COMMON~1\AOL\110295~1\EE\AOLHOS~1.EXE
C:\PROGRA~1\COMMON~1\AOL\110295~1\EE\AOLServiceHost.exe
C:\Program Files\America Online 9.0\shellmon.exe
C:\WINDOWS\nvsvc32.exe
C:\Program Files\Microsoft AntiSpyware\GIANTAntiSpywareMain.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\WINDOWS\system32\Restore\rstrui.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\vicky\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.bellsouth.net/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll (file missing)
O4 - HKLM\..\Run: [XircWinModem4] ltcm000c.exe 9
O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
O4 - HKLM\..\Run: [2wSysTray] C:\Program Files\2Wire HomePortal Monitor\2portalmon.exe
O4 - HKLM\..\Run: [HPAIO_PrintFolderMgr] C:\WINDOWS\System32\spool\DRIVERS\W32X86\hpoopm07.exe
O4 - HKLM\..\Run: [SetupType] Portable
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [CamMonitor] C:\Program Files\Hewlett-Packard\Digital Imaging\\Unload\hpqcmon.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] PELMICED.EXE
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe
O4 - HKLM\..\Run: [HPHmon04] C:\WINDOWS\system32\hphmon04.exe
O4 - HKLM\..\Run: [HPHUPD04] "C:\Program Files\HP Photosmart 11\hphinstall\UniPatch\hphupd04.exe"
O4 - HKLM\..\Run: [NAV] C:\WINDOWS\system32\dll\csrss.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1102958538\EE\AOLHostManager.exe
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [Pure Networks Port Magic] "C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe" -Run
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~2\VPTray.exe
O4 - HKLM\..\Run: [C2kWep] C:\Program Files\Netopia\C3kWepN.exe
O4 - HKLM\..\Run: [winsvc] c:\windows\system32\winsvc.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AOLCC] "C:\Program Files\AOL Computer Check-Up\ACCAgnt.exe" /startup
O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\America Online 9.0\AOL.EXE" -b
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: VPN Client.lnk = ?
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll (file missing)
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll (file missing)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .aif: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin2.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....467&clcid=0x409
O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) - http://aolcc.aol.com...kup/qdiagcc.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupd...b?1099058751640
O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30043.www3.h.../qdiagh.cab?325
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: AOL Spyware Protection Service (AOLService) - Unknown owner - C:\Program Files\Common Files\AOL\AOL Spyware Protection\\aolserv.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Pml Driver HPH11 - HP - C:\WINDOWS\system32\HPHipm11.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
  • 0

Advertisements


#2
miekiemoes

miekiemoes

    Malware Expert

  • Member
  • PipPipPipPipPipPipPipPip
  • 5,503 posts
  • MVP
User being helped in chat..

Create a folder on your desktop called Sysclean.
Go to http://www.trendmicr...ownload/dcs.asp and download sysclean package to the folder you made.
Go to http://www.trendmicr...oad/pattern.asp and download the Official Pattern Release for windows to your desktop.
This file will be called lptXXX.zip (XXX represents the version number)
Unzip lptXXX.zip and you'll get the file lpt$vpn.XXX.
Move the lpt$vpn.XXX to that Sysclean-folder you created on your desktop.

Turn off your antivirus which is installed on your system because it can interfere with the Sysclean-scan.

Open the sysclean-folder and doubleclick sysclean.com.
Check: Automatically clean or delete detected files.
Click scan.
When the scan is finished, select: 'view log'.
Copy and paste this log in your next reply.
  • 0

#3
TheJackal

TheJackal

    New Member

  • Topic Starter
  • Member
  • Pip
  • 3 posts
Here it is .. my log..




/--------------------------------------------------------------\
| Trend Micro Sysclean Package |
| Copyright 2002, Trend Micro, Inc. |
| http://www.trendmicro.com |
\--------------------------------------------------------------/


2005-06-23, 10:01:19, Auto-clean mode specified.
2005-06-23, 10:01:19, Running scanner "C:\Documents and Settings\vicky\Desktop\Sysclean\TSC.BIN"...
2005-06-23, 10:07:51, Scanner "C:\Documents and Settings\vicky\Desktop\Sysclean\TSC.BIN" has finished running.
2005-06-23, 10:07:51, TSC Log:

Damage Cleanup Engine (DCE) 3.9(Build 1020)
Windows XP(Build 2600: Service Pack 2)

Start time : Thu Jun 23 2005 10:01:24

Load Damage Cleanup Template (DCT) "C:\Documents and Settings\vicky\Desktop\Sysclean\tsc.ptn" (version 618) [success]
WORM_MUGLY.I[virus clean failed]
-->delete registry key("HKEY_CLASSES_ROOT","ANSMTP.MassSender","") success
-->delete registry key("HKEY_CLASSES_ROOT","ANSMTP.MassSender.1","") success
-->delete registry key("HKEY_CLASSES_ROOT","CLSID\{887A577B-406B-48FF-80CB-70752BFCD7B4}","") success
-->delete registry key("HKEY_CLASSES_ROOT","Interface\{1E98666F-6260-42C9-B846-32B20FDEFE7B}","") success
-->delete registry key("HKEY_CLASSES_ROOT","Interface\{B13281CF-8778-4C98-AE23-ABBA4637A33D}","") success
-->modify registry value("HKEY_LOCAL_MACHINE","SOFTWARE\Microsoft\Ole","EnableDCOM") success
-->delete file("C:\WINDOWS\system32\ANSMTP.DLL","","") success
-->delete file("C:\WINDOWS\system32\uglym.jpg","","") fail
-->delete file("C:\WINDOWS\system32\xxz.tmp","","") fail
-->delete file("C:\WINDOWS\system32\attached.zip","","") fail

Complete time : Thu Jun 23 2005 10:02:21
Execute pattern count(3678), Virus found count(1), Virus clean count(0), Clean failed count(1)

2005-06-23, 10:08:07, An error occurred while scanning file "C:\Documents and Settings\All Users\Application Data\AOL\C_America Online 9.0\idb\SNMaster.idx": Access is denied.
2005-06-23, 10:08:08, An error occurred while scanning file "C:\Documents and Settings\All Users\Application Data\AOL\C_America Online 9.0\idb\vfay1\MyDB.idx": Access is denied.
2005-06-23, 10:08:08, An error occurred while scanning file "C:\Documents and Settings\All Users\Application Data\AOL\C_America Online 9.0\idb\vfay1\toolbar.lst": Access is denied.
2005-06-23, 10:08:08, An error occurred while scanning file "C:\Documents and Settings\All Users\Application Data\AOL\C_America Online 9.0\organize\vfay1": Access is denied.
2005-06-23, 10:08:08, An error occurred while scanning file "C:\Documents and Settings\All Users\Application Data\AOL\C_America Online 9.0\organize\CACHE\vfa00": Access is denied.
2005-06-23, 10:10:20, An error occurred while scanning file "C:\Documents and Settings\LocalService\NTUSER.DAT": Access is denied.
2005-06-23, 10:10:20, An error occurred while scanning file "C:\Documents and Settings\LocalService\ntuser.dat.LOG": Access is denied.
2005-06-23, 10:10:22, An error occurred while scanning file "C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat": Access is denied.
2005-06-23, 10:10:22, An error occurred while scanning file "C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG": Access is denied.
2005-06-23, 10:10:23, An error occurred while scanning file "C:\Documents and Settings\NetworkService\NTUSER.DAT": Access is denied.
2005-06-23, 10:10:23, An error occurred while scanning file "C:\Documents and Settings\NetworkService\ntuser.dat.LOG": Access is denied.
2005-06-23, 10:10:23, An error occurred while scanning file "C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat": Access is denied.
2005-06-23, 10:10:23, An error occurred while scanning file "C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG": Access is denied.
2005-06-23, 10:10:24, An error occurred while scanning file "C:\Documents and Settings\vicky\NTUSER.DAT": Access is denied.
2005-06-23, 10:10:24, An error occurred while scanning file "C:\Documents and Settings\vicky\NTUSER.DAT.LOG": Access is denied.
2005-06-23, 10:10:30, An error occurred while scanning file "C:\Documents and Settings\vicky\Application Data\AOL\C_America Online 9.0\IDB\Apps.Lst": Access is denied.
2005-06-23, 10:10:30, An error occurred while scanning file "C:\Documents and Settings\vicky\Application Data\AOL\C_America Online 9.0\IDB\art.idx": Access is denied.
2005-06-23, 10:10:31, An error occurred while scanning file "C:\Documents and Settings\vicky\Application Data\AOL\C_America Online 9.0\IDB\spool.lst": Access is denied.
2005-06-23, 10:10:31, An error occurred while scanning file "C:\Documents and Settings\vicky\Application Data\AOL\C_America Online 9.0\IDB\sysnews.lst": Access is denied.
2005-06-23, 10:10:48, An error occurred while scanning file "C:\Documents and Settings\vicky\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat": Access is denied.
2005-06-23, 10:10:48, An error occurred while scanning file "C:\Documents and Settings\vicky\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG": Access is denied.
2005-06-23, 10:53:41, The user stopped the operation.


/--------------------------------------------------------------\
| Trend Micro Sysclean Package |
| Copyright 2002, Trend Micro, Inc. |
| http://www.trendmicro.com |
\--------------------------------------------------------------/


2005-06-23, 11:29:55, Auto-clean mode specified.
2005-06-23, 11:29:55, Running scanner "C:\Documents and Settings\vicky\Desktop\Sysclean\TSC.BIN"...
2005-06-23, 11:30:54, Scanner "C:\Documents and Settings\vicky\Desktop\Sysclean\TSC.BIN" has finished running.
2005-06-23, 11:30:54, TSC Log:

Damage Cleanup Engine (DCE) 3.9(Build 1020)
Windows XP(Build 2600: Service Pack 2)

Start time : Thu Jun 23 2005 11:29:59

Load Damage Cleanup Template (DCT) "C:\Documents and Settings\vicky\Desktop\Sysclean\tsc.ptn" (version 618) [success]

Complete time : Thu Jun 23 2005 11:30:52
Execute pattern count(3678), Virus found count(0), Virus clean count(0), Clean failed count(0)

2005-06-23, 11:31:04, An error occurred while scanning file "C:\Documents and Settings\All Users\Application Data\AOL\C_America Online 9.0\idb\SNMaster.idx": Access is denied.
2005-06-23, 11:31:04, An error occurred while scanning file "C:\Documents and Settings\All Users\Application Data\AOL\C_America Online 9.0\idb\vfay1\MyDB.idx": Access is denied.
2005-06-23, 11:31:04, An error occurred while scanning file "C:\Documents and Settings\All Users\Application Data\AOL\C_America Online 9.0\idb\vfay1\toolbar.lst": Access is denied.
2005-06-23, 11:31:05, An error occurred while scanning file "C:\Documents and Settings\All Users\Application Data\AOL\C_America Online 9.0\organize\vfay1": Access is denied.
2005-06-23, 11:31:05, An error occurred while scanning file "C:\Documents and Settings\All Users\Application Data\AOL\C_America Online 9.0\organize\CACHE\vfa00": Access is denied.
2005-06-23, 11:32:23, An error occurred while scanning file "C:\Documents and Settings\LocalService\NTUSER.DAT": Access is denied.
2005-06-23, 11:32:23, An error occurred while scanning file "C:\Documents and Settings\LocalService\ntuser.dat.LOG": Access is denied.
2005-06-23, 11:32:23, An error occurred while scanning file "C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat": Access is denied.
2005-06-23, 11:32:23, An error occurred while scanning file "C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG": Access is denied.
2005-06-23, 11:32:23, An error occurred while scanning file "C:\Documents and Settings\NetworkService\NTUSER.DAT": Access is denied.
2005-06-23, 11:32:23, An error occurred while scanning file "C:\Documents and Settings\NetworkService\ntuser.dat.LOG": Access is denied.
2005-06-23, 11:32:23, An error occurred while scanning file "C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat": Access is denied.
2005-06-23, 11:32:23, An error occurred while scanning file "C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG": Access is denied.
2005-06-23, 11:32:23, An error occurred while scanning file "C:\Documents and Settings\vicky\NTUSER.DAT": Access is denied.
2005-06-23, 11:32:23, An error occurred while scanning file "C:\Documents and Settings\vicky\NTUSER.DAT.LOG": Access is denied.
2005-06-23, 11:32:27, An error occurred while scanning file "C:\Documents and Settings\vicky\Application Data\AOL\C_America Online 9.0\IDB\Apps.Lst": Access is denied.
2005-06-23, 11:32:27, An error occurred while scanning file "C:\Documents and Settings\vicky\Application Data\AOL\C_America Online 9.0\IDB\art.idx": Access is denied.
2005-06-23, 11:32:28, An error occurred while scanning file "C:\Documents and Settings\vicky\Application Data\AOL\C_America Online 9.0\IDB\spool.lst": Access is denied.
2005-06-23, 11:32:28, An error occurred while scanning file "C:\Documents and Settings\vicky\Application Data\AOL\C_America Online 9.0\IDB\sysnews.lst": Access is denied.
2005-06-23, 11:32:38, An error occurred while scanning file "C:\Documents and Settings\vicky\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat": Access is denied.
2005-06-23, 11:32:38, An error occurred while scanning file "C:\Documents and Settings\vicky\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG": Access is denied.
2005-06-23, 11:43:37, An error occurred while scanning file "C:\Program Files\RemoteSpy2\RS.dat": Access is denied.
2005-06-23, 11:45:26, An error was detected on "C:\System Volume Information\*.*": Access is denied.
2005-06-23, 11:51:34, Could not set file for reading on "C:\WINDOWS\PCHEALTH\ErrorRep\UserDumps\svchost.exe.20050317-024432-00.hdmp": Access is denied.
2005-06-23, 11:51:57, Could not set file for reading on "C:\WINDOWS\Prefetch\2PORTALMON.EXE-206F221D.pf": Access is denied.
2005-06-23, 11:51:57, Could not set file for reading on "C:\WINDOWS\Prefetch\ACRORD32.EXE-13285B88.pf": Access is denied.
2005-06-23, 11:51:57, Could not set file for reading on "C:\WINDOWS\Prefetch\AGENTSVR.EXE-002E45AB.pf": Access is denied.
2005-06-23, 11:51:57, Could not set file for reading on "C:\WINDOWS\Prefetch\ALARMAPP.EXE-37DD84C2.pf": Access is denied.
2005-06-23, 11:51:57, Could not set file for reading on "C:\WINDOWS\Prefetch\ALG.EXE-0F138680.pf": Access is denied.
2005-06-23, 11:51:57, Could not set file for reading on "C:\WINDOWS\Prefetch\AOL.EXE-2A55E94E.pf": Access is denied.
2005-06-23, 11:51:57, Could not set file for reading on "C:\WINDOWS\Prefetch\AOL.EXE-37F91595.pf": Access is denied.
2005-06-23, 11:51:57, Could not set file for reading on "C:\WINDOWS\Prefetch\AOL.EXE-3A5039E6.pf": Access is denied.
2005-06-23, 11:51:57, Could not set file for reading on "C:\WINDOWS\Prefetch\AOLDACL.EXE-2AC827B3.pf": Access is denied.
2005-06-23, 11:51:57, Could not set file for reading on "C:\WINDOWS\Prefetch\AOLDIAL.EXE-13C23121.pf": Access is denied.
2005-06-23, 11:51:57, Could not set file for reading on "C:\WINDOWS\Prefetch\AOLHOSTMANAGER.EXE-03787B69.pf": Access is denied.
2005-06-23, 11:51:57, Could not set file for reading on "C:\WINDOWS\Prefetch\AOLMED~1.EXE-052DDBA6.pf": Access is denied.
2005-06-23, 11:51:57, Could not set file for reading on "C:\WINDOWS\Prefetch\AOLNYSEV.EXE-2317E7D8.pf": Access is denied.
2005-06-23, 11:51:57, Could not set file for reading on "C:\WINDOWS\Prefetch\AOLPHX.EXE-18BCC52C.pf": Access is denied.
2005-06-23, 11:51:57, Could not set file for reading on "C:\WINDOWS\Prefetch\AOLSERVICEHOST.EXE-03CB7F9F.pf": Access is denied.
2005-06-23, 11:51:57, Could not set file for reading on "C:\WINDOWS\Prefetch\AOLSP SCHEDULER.EXE-21D17D2F.pf": Access is denied.
2005-06-23, 11:51:57, Could not set file for reading on "C:\WINDOWS\Prefetch\AOLSPS~1.EXE-149DBB13.pf": Access is denied.
2005-06-23, 11:51:57, Could not set file for reading on "C:\WINDOWS\Prefetch\APCONFIG.EXE-0355EE9B.pf": Access is denied.
2005-06-23, 11:51:57, Could not set file for reading on "C:\WINDOWS\Prefetch\APLAUNCH.EXE-12F4BEC8.pf": Access is denied.
2005-06-23, 11:51:57, Could not set file for reading on "C:\WINDOWS\Prefetch\APLAUNCH.EXE-25CE6C28.pf": Access is denied.
2005-06-23, 11:51:57, Could not set file for reading on "C:\WINDOWS\Prefetch\ASP.EXE-06B08E61.pf": Access is denied.
2005-06-23, 11:51:57, Could not set file for reading on "C:\WINDOWS\Prefetch\ASPUPDATE_US.EXE-23F83AF1.pf": Access is denied.
2005-06-23, 11:51:57, Could not set file for reading on "C:\WINDOWS\Prefetch\AUTORUN.EXE-055703AF.pf": Access is denied.
2005-06-23, 11:51:57, Could not set file for reading on "C:\WINDOWS\Prefetch\C3KWEPN.EXE-02AB0545.pf": Access is denied.
2005-06-23, 11:51:57, Could not set file for reading on "C:\WINDOWS\Prefetch\CCAPP.EXE-1207B2A5.pf": Access is denied.
2005-06-23, 11:51:57, Could not set file for reading on "C:\WINDOWS\Prefetch\CFD.EXE-3580EFD4.pf": Access is denied.
2005-06-23, 11:51:57, Could not set file for reading on "C:\WINDOWS\Prefetch\CTFMON.EXE-0E17969B.pf": Access is denied.
2005-06-23, 11:51:57, Could not set file for reading on "C:\WINDOWS\Prefetch\DEFRAG.EXE-273F131E.pf": Access is denied.
2005-06-23, 11:51:57, Could not set file for reading on "C:\WINDOWS\Prefetch\DFRGNTFS.EXE-269967DF.pf": Access is denied.
2005-06-23, 11:51:57, Could not set file for reading on "C:\WINDOWS\Prefetch\DRVWUNIN.EXE-078C3DFF.pf": Access is denied.
2005-06-23, 11:51:57, Could not set file for reading on "C:\WINDOWS\Prefetch\DRWTSN32.EXE-2B4B52AC.pf": Access is denied.
2005-06-23, 11:51:57, Could not set file for reading on "C:\WINDOWS\Prefetch\DUMPREP.EXE-1B46F901.pf": Access is denied.
2005-06-23, 11:51:57, Could not set file for reading on "C:\WINDOWS\Prefetch\DWWIN.EXE-30875ADC.pf": Access is denied.
2005-06-23, 11:51:57, Could not set file for reading on "C:\WINDOWS\Prefetch\EM_EXEC.EXE-31F56C86.pf": Access is denied.
2005-06-23, 11:51:57, Could not set file for reading on "C:\WINDOWS\Prefetch\EXCEL.EXE-2C971FD7.pf": Access is denied.
2005-06-23, 11:51:57, Could not set file for reading on "C:\WINDOWS\Prefetch\EXPLORER.EXE-082F38A9.pf": Access is denied.
2005-06-23, 11:51:57, Could not set file for reading on "C:\WINDOWS\Prefetch\HCENTER.EXE-0F8C169E.pf": Access is denied.
2005-06-23, 11:51:57, Could not set file for reading on "C:\WINDOWS\Prefetch\HELPSVC.EXE-2878DDA2.pf": Access is denied.
2005-06-23, 11:51:57, Could not set file for reading on "C:\WINDOWS\Prefetch\HPGS2WND.EXE-06AC8C27.pf": Access is denied.
2005-06-23, 11:51:57, Could not set file for reading on "C:\WINDOWS\Prefetch\HPGS2WNF.EXE-0E86C34B.pf": Access is denied.
2005-06-23, 11:51:57, Could not set file for reading on "C:\WINDOWS\Prefetch\HPHIPM11.EXE-25D93894.pf": Access is denied.
2005-06-23, 11:51:57, Could not set file for reading on "C:\WINDOWS\Prefetch\HPOOPM07.EXE-132BD289.pf": Access is denied.
2005-06-23, 11:51:57, Could not set file for reading on "C:\WINDOWS\Prefetch\HPQCMON.EXE-31EA0A33.pf": Access is denied.
2005-06-23, 11:51:57, Could not set file for reading on "C:\WINDOWS\Prefetch\HPQFRU07.EXE-297DB19F.pf": Access is denied.
2005-06-23, 11:51:57, Could not set file for reading on "C:\WINDOWS\Prefetch\HPQPHUNL.EXE-2D46A420.pf": Access is denied.
2005-06-23, 11:51:57, Could not set file for reading on "C:\WINDOWS\Prefetch\HPQTHB08.EXE-345161DC.pf": Access is denied.
2005-06-23, 11:51:57, Could not set file for reading on "C:\WINDOWS\Prefetch\HPQVWR08.EXE-0C288093.pf": Access is denied.
2005-06-23, 11:51:57, Could not set file for reading on "C:\WINDOWS\Prefetch\IEDW.EXE-1880380E.pf": Access is denied.
2005-06-23, 11:51:57, Could not set file for reading on "C:\WINDOWS\Prefetch\IEXPLORE.EXE-27122324.pf": Access is denied.
2005-06-23, 11:51:57, Could not set file for reading on "C:\WINDOWS\Prefetch\IPCONFIG.EXE-2395F30B.pf": Access is denied.
2005-06-23, 11:51:57, Could not set file for reading on "C:\WINDOWS\Prefetch\IPE.EXE-317ED937.pf": Access is denied.
2005-06-23, 11:51:58, Could not set file for reading on "C:\WINDOWS\Prefetch\IPSECDIALER.EXE-2DE32DB2.pf": Access is denied.
2005-06-23, 11:51:58, Could not set file for reading on "C:\WINDOWS\Prefetch\JOBCHECK.EXE-3866F94B.pf": Access is denied.
2005-06-23, 11:51:58, Could not set file for reading on "C:\WINDOWS\Prefetch\Layout.ini": Access is denied.
2005-06-23, 11:51:58, Could not set file for reading on "C:\WINDOWS\Prefetch\LOGON.SCR-151EFAEA.pf": Access is denied.
2005-06-23, 11:51:58, Could not set file for reading on "C:\WINDOWS\Prefetch\LOGONUI.EXE-0AF22957.pf": Access is denied.
2005-06-23, 11:51:58, Could not set file for reading on "C:\WINDOWS\Prefetch\LTCM000C.EXE-0145588A.pf": Access is denied.
2005-06-23, 11:51:58, Could not set file for reading on "C:\WINDOWS\Prefetch\LUCOMS~1.EXE-02DB5950.pf": Access is denied.
2005-06-23, 11:51:58, Could not set file for reading on "C:\WINDOWS\Prefetch\MRT.EXE-13F298AF.pf": Access is denied.
2005-06-23, 11:51:58, Could not set file for reading on "C:\WINDOWS\Prefetch\MRT.EXE-1B4A8D49.pf": Access is denied.
2005-06-23, 11:51:58, Could not set file for reading on "C:\WINDOWS\Prefetch\MRTSTUB.EXE-06DA72AB.pf": Access is denied.
2005-06-23, 11:51:58, Could not set file for reading on "C:\WINDOWS\Prefetch\MSMSGS.EXE-2B6052DE.pf": Access is denied.
2005-06-23, 11:51:58, Could not set file for reading on "C:\WINDOWS\Prefetch\MSOHELP.EXE-06826F09.pf": Access is denied.
2005-06-23, 11:51:58, Could not set file for reading on "C:\WINDOWS\Prefetch\NTOSBOOT-B00DFAAD.pf": Access is denied.
2005-06-23, 11:51:58, Could not set file for reading on "C:\WINDOWS\Prefetch\NTSVC32.EXE-39CF1309.pf": Access is denied.
2005-06-23, 11:51:58, Could not set file for reading on "C:\WINDOWS\Prefetch\NVSVC32.EXE-2C59DD6B.pf": Access is denied.
2005-06-23, 11:51:58, Could not set file for reading on "C:\WINDOWS\Prefetch\OPTSCAN.EXE-062DE052.pf": Access is denied.
2005-06-23, 11:51:58, Could not set file for reading on "C:\WINDOWS\Prefetch\OSA.EXE-2CD63980.pf": Access is denied.
2005-06-23, 11:51:58, Could not set file for reading on "C:\WINDOWS\Prefetch\OUTLOOK.EXE-27D5965C.pf": Access is denied.
2005-06-23, 11:51:58, Could not set file for reading on "C:\WINDOWS\Prefetch\P2P NETWORKING.EXE-2D369395.pf": Access is denied.
2005-06-23, 11:51:58, Could not set file for reading on "C:\WINDOWS\Prefetch\PALM.EXE-363B71EA.pf": Access is denied.
2005-06-23, 11:51:58, Could not set file for reading on "C:\WINDOWS\Prefetch\PELMICED.EXE-0F6C2BE0.pf": Access is denied.
2005-06-23, 11:51:58, Could not set file for reading on "C:\WINDOWS\Prefetch\PHOTOED.EXE-0F3CAA01.pf": Access is denied.
2005-06-23, 11:51:58, Could not set file for reading on "C:\WINDOWS\Prefetch\PNPNINST.EXE-0A617BA3.pf": Access is denied.
2005-06-23, 11:51:58, Could not set file for reading on "C:\WINDOWS\Prefetch\QUICKINSTALL.EXE-37629AA1.pf": Access is denied.
2005-06-23, 11:51:58, Could not set file for reading on "C:\WINDOWS\Prefetch\READER_SL.EXE-3614FA6E.pf": Access is denied.
2005-06-23, 11:51:58, Could not set file for reading on "C:\WINDOWS\Prefetch\REGEDIT.EXE-1B606482.pf": Access is denied.
2005-06-23, 11:51:58, Could not set file for reading on "C:\WINDOWS\Prefetch\ROUTE.EXE-371D32DE.pf": Access is denied.
2005-06-23, 11:51:58, Could not set file for reading on "C:\WINDOWS\Prefetch\RUNDLL32.EXE-17D51176.pf": Access is denied.
2005-06-23, 11:51:58, Could not set file for reading on "C:\WINDOWS\Prefetch\RUNDLL32.EXE-24DBE541.pf": Access is denied.
2005-06-23, 11:51:58, Could not set file for reading on "C:\WINDOWS\Prefetch\RUNDLL32.EXE-26193580.pf": Access is denied.
2005-06-23, 11:51:58, Could not set file for reading on "C:\WINDOWS\Prefetch\RUNDLL32.EXE-2CD85FD3.pf": Access is denied.
2005-06-23, 11:51:58, Could not set file for reading on "C:\WINDOWS\Prefetch\RUNDLL32.EXE-34A1FC07.pf": Access is denied.
2005-06-23, 11:51:58, Could not set file for reading on "C:\WINDOWS\Prefetch\RUNDLL32.EXE-451FC2C0.pf": Access is denied.
2005-06-23, 11:51:58, Could not set file for reading on "C:\WINDOWS\Prefetch\SAPISVR.EXE-3241C9C4.pf": Access is denied.
2005-06-23, 11:51:58, Could not set file for reading on "C:\WINDOWS\Prefetch\SBWIN32.EXE-07A47CC5.pf": Access is denied.
2005-06-23, 11:51:58, Could not set file for reading on "C:\WINDOWS\Prefetch\SETUP_WM.EXE-3135CBD6.pf": Access is denied.
2005-06-23, 11:51:58, Could not set file for reading on "C:\WINDOWS\Prefetch\SHELLMON.EXE-3302A29E.pf": Access is denied.
2005-06-23, 11:51:58, Could not set file for reading on "C:\WINDOWS\Prefetch\SHELLMON.EXE-34C03540.pf": Access is denied.
2005-06-23, 11:51:58, Could not set file for reading on "C:\WINDOWS\Prefetch\SHELLRESTART.EXE-287DD434.pf": Access is denied.
2005-06-23, 11:51:58, Could not set file for reading on "C:\WINDOWS\Prefetch\SHUT2WIRE.EXE-03325520.pf": Access is denied.
2005-06-23, 11:51:58, Could not set file for reading on "C:\WINDOWS\Prefetch\SINF.EXE-0FF8C91B.pf": Access is denied.
2005-06-23, 11:51:58, Could not set file for reading on "C:\WINDOWS\Prefetch\SPOOLSV.EXE-282F76A7.pf": Access is denied.
2005-06-23, 11:51:58, Could not set file for reading on "C:\WINDOWS\Prefetch\SSSTARS.SCR-2D6FC20D.pf": Access is denied.
2005-06-23, 11:51:58, Could not set file for reading on "C:\WINDOWS\Prefetch\TASKMGR.EXE-20256C55.pf": Access is denied.
2005-06-23, 11:51:58, Could not set file for reading on "C:\WINDOWS\Prefetch\TGCMD.EXE-0009DEB8.pf": Access is denied.
2005-06-23, 11:51:58, Could not set file for reading on "C:\WINDOWS\Prefetch\TGSHELL.EXE-03775A2D.pf": Access is denied.
2005-06-23, 11:51:58, Could not set file for reading on "C:\WINDOWS\Prefetch\UPDATE.EXE-0024572D.pf": Access is denied.
2005-06-23, 11:51:58, Could not set file for reading on "C:\WINDOWS\Prefetch\UPDATE.EXE-00B99D22.pf": Access is denied.
2005-06-23, 11:51:58, Could not set file for reading on "C:\WINDOWS\Prefetch\UPDATE.EXE-044F6A7C.pf": Access is denied.
2005-06-23, 11:51:58, Could not set file for reading on "C:\WINDOWS\Prefetch\UPDATE.EXE-05DFA40B.pf": Access is denied.
2005-06-23, 11:51:58, Could not set file for reading on "C:\WINDOWS\Prefetch\UPDATE.EXE-0D68F1F0.pf": Access is denied.
2005-06-23, 11:51:58, Could not set file for reading on "C:\WINDOWS\Prefetch\UPDATE.EXE-0FDC9C85.pf": Access is denied.
2005-06-23, 11:51:58, Could not set file for reading on "C:\WINDOWS\Prefetch\UPDATE.EXE-1528CD5E.pf": Access is denied.
2005-06-23, 11:51:58, Could not set file for reading on "C:\WINDOWS\Prefetch\UPDATE.EXE-17130C96.pf": Access is denied.
2005-06-23, 11:51:58, Could not set file for reading on "C:\WINDOWS\Prefetch\UPDATE.EXE-1CD2465C.pf": Access is denied.
2005-06-23, 11:51:58, Could not set file for reading on "C:\WINDOWS\Prefetch\UPDATE.EXE-2308C9A8.pf": Access is denied.
2005-06-23, 11:51:58, Could not set file for reading on "C:\WINDOWS\Prefetch\UPDATE.EXE-2FAD4F8C.pf": Access is denied.
2005-06-23, 11:51:58, Could not set file for reading on "C:\WINDOWS\Prefetch\UPDATE.EXE-30170FD0.pf": Access is denied.
2005-06-23, 11:51:58, Could not set file for reading on "C:\WINDOWS\Prefetch\UPDATE.EXE-3594B9C6.pf": Access is denied.
2005-06-23, 11:51:58, Could not set file for reading on "C:\WINDOWS\Prefetch\UPDATE.EXE-36489281.pf": Access is denied.
2005-06-23, 11:51:58, Could not set file for reading on "C:\WINDOWS\Prefetch\UPDATE.EXE-370FF70C.pf": Access is denied.
2005-06-23, 11:51:58, Could not set file for reading on "C:\WINDOWS\Prefetch\UPDATE.EXE-3AE543F3.pf": Access is denied.
2005-06-23, 11:51:58, Could not set file for reading on "C:\WINDOWS\Prefetch\USERINIT.EXE-30B18140.pf": Access is denied.
2005-06-23, 11:51:58, Could not set file for reading on "C:\WINDOWS\Prefetch\VERCOPY.EXE-3278B8D0.pf": Access is denied.
2005-06-23, 11:51:58, Could not set file for reading on "C:\WINDOWS\Prefetch\VPNGUI.EXE-168321AE.pf": Access is denied.
2005-06-23, 11:51:58, Could not set file for reading on "C:\WINDOWS\Prefetch\VPTRAY.EXE-278D4F36.pf": Access is denied.
2005-06-23, 11:51:58, Could not set file for reading on "C:\WINDOWS\Prefetch\WAOL.EXE-1659B5EC.pf": Access is denied.
2005-06-23, 11:51:58, Could not set file for reading on "C:\WINDOWS\Prefetch\WAOL.EXE-1BFEB52A.pf": Access is denied.
2005-06-23, 11:51:58, Could not set file for reading on "C:\WINDOWS\Prefetch\WINDOWS-KB890830-V1.3-ENU.EXE-094D4E70.pf": Access is denied.
2005-06-23, 11:51:58, Could not set file for reading on "C:\WINDOWS\Prefetch\WINDOWS-KB890830-V1.4-ENU.EXE-09C3BA09.pf": Access is denied.
2005-06-23, 11:51:58, Could not set file for reading on "C:\WINDOWS\Prefetch\WINDOWSINSTALLER-KB893803-V2--1613DE28.pf": Access is denied.
2005-06-23, 11:51:58, Could not set file for reading on "C:\WINDOWS\Prefetch\WINDOWSINSTALLER-KB893803-X86-2D612682.pf": Access is denied.
2005-06-23, 11:51:58, Could not set file for reading on "C:\WINDOWS\Prefetch\WINSVC.EXE-14464717.pf": Access is denied.
2005-06-23, 11:51:58, Could not set file for reading on "C:\WINDOWS\Prefetch\WINWORD.EXE-29F5CB89.pf": Access is denied.
2005-06-23, 11:51:58, Could not set file for reading on "C:\WINDOWS\Prefetch\WMIPRVSE.EXE-28F301A9.pf": Access is denied.
2005-06-23, 11:51:58, Could not set file for reading on "C:\WINDOWS\Prefetch\WMPLAYER.EXE-18DDEFA6.pf": Access is denied.
2005-06-23, 11:51:58, Could not set file for reading on "C:\WINDOWS\Prefetch\WSCNTFY.EXE-1B24F5EB.pf": Access is denied.
2005-06-23, 11:51:58, Could not set file for reading on "C:\WINDOWS\Prefetch\WSCRIPT.EXE-32960AB9.pf": Access is denied.
2005-06-23, 11:51:58, Could not set file for reading on "C:\WINDOWS\Prefetch\WUAUCLT.EXE-399A8E72.pf": Access is denied.
2005-06-23, 11:55:52, An error occurred while scanning file "C:\WINDOWS\SoftwareDistribution\DataStore\DataStore.edb": Access is denied.
2005-06-23, 11:55:52, An error occurred while scanning file "C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.log": Access is denied.
2005-06-23, 11:55:52, An error occurred while scanning file "C:\WINDOWS\SoftwareDistribution\DataStore\Logs\tmp.edb": Access is denied.
2005-06-23, 11:58:24, An error occurred while scanning file "C:\WINDOWS\system32\CatRoot2\edb.log": Access is denied.
2005-06-23, 11:58:24, An error occurred while scanning file "C:\WINDOWS\system32\CatRoot2\tmp.edb": Access is denied.
2005-06-23, 11:58:25, An error occurred while scanning file "C:\WINDOWS\system32\config\default": Access is denied.
2005-06-23, 11:58:25, An error occurred while scanning file "C:\WINDOWS\system32\config\default.LOG": Access is denied.
2005-06-23, 11:58:25, An error occurred while scanning file "C:\WINDOWS\system32\config\SAM": Access is denied.
2005-06-23, 11:58:25, An error occurred while scanning file "C:\WINDOWS\system32\config\SAM.LOG": Access is denied.
2005-06-23, 11:58:25, An error occurred while scanning file "C:\WINDOWS\system32\config\SECURITY": Access is denied.
2005-06-23, 11:58:25, An error occurred while scanning file "C:\WINDOWS\system32\config\SECURITY.LOG": Access is denied.
2005-06-23, 11:58:25, An error occurred while scanning file "C:\WINDOWS\system32\config\software": Access is denied.
2005-06-23, 11:58:25, An error occurred while scanning file "C:\WINDOWS\system32\config\software.LOG": Access is denied.
2005-06-23, 11:58:26, An error occurred while scanning file "C:\WINDOWS\system32\config\system": Access is denied.
2005-06-23, 11:58:26, An error occurred while scanning file "C:\WINDOWS\system32\config\system.LOG": Access is denied.
2005-06-23, 12:00:38, Running scanner "C:\Documents and Settings\vicky\Desktop\Sysclean\VSCANTM.BIN"...
2005-06-23, 12:22:29, Files Detected:
Copyright © 1990 - 2004 Trend Micro Inc.
Report Date : 6/23/2005 12:00:39
VSAPI Engine Version : 7.510-1002
VSCANTM Version : 1.1-1001
Virus Pattern Version : 699 (103723 Patterns) (2005/06/21) (269900)
Command Line: C:\Documents and Settings\vicky\Desktop\Sysclean\VSCANTM.BIN /NBPM /S /CLEANALL /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 C:\*.* /P=C:\Documents and Settings\vicky\Desktop\Sysclean

33541 files have been read.
33541 files have been checked.
24749 files have been scanned.
37951 files have been scanned. (including files in archived)
0 files containing viruses.
Found 0 viruses totally.
Maybe 0 viruses totally.
Stop At : 6/23/2005 12:22:28
---------*---------*---------*---------*---------*---------*---------*---------*
2005-06-23, 12:22:29, Files Clean:
Copyright © 1990 - 2004 Trend Micro Inc.
Report Date : 6/23/2005 12:00:39
VSAPI Engine Version : 7.510-1002
VSCANTM Version : 1.1-1001
Virus Pattern Version : 699 (103723 Patterns) (2005/06/21) (269900)
Command Line: C:\Documents and Settings\vicky\Desktop\Sysclean\VSCANTM.BIN /NBPM /S /CLEANALL /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 C:\*.* /P=C:\Documents and Settings\vicky\Desktop\Sysclean

33541 files have been read.
33541 files have been checked.
24749 files have been scanned.
37951 files have been scanned. (including files in archived)
0 files containing viruses.
Found 0 viruses totally.
Maybe 0 viruses totally.
Stop At : 6/23/2005 12:22:28 21 minutes 48 seconds (1307.78 seconds) has elapsed.

---------*---------*---------*---------*---------*---------*---------*---------*
2005-06-23, 12:22:29, Clean Fail:
Copyright © 1990 - 2004 Trend Micro Inc.
Report Date : 6/23/2005 12:00:39
VSAPI Engine Version : 7.510-1002
VSCANTM Version : 1.1-1001
Virus Pattern Version : 699 (103723 Patterns) (2005/06/21) (269900)
Command Line: C:\Documents and Settings\vicky\Desktop\Sysclean\VSCANTM.BIN /NBPM /S /CLEANALL /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 C:\*.* /P=C:\Documents and Settings\vicky\Desktop\Sysclean

33541 files have been read.
33541 files have been checked.
24749 files have been scanned.
37951 files have been scanned. (including files in archived)
0 files containing viruses.
Found 0 viruses totally.
Maybe 0 viruses totally.
Stop At : 6/23/2005 12:22:28 21 minutes 48 seconds (1307.78 seconds) has elapsed.

---------*---------*---------*---------*---------*---------*---------*---------*
2005-06-23, 12:22:29, Scanner "C:\Documents and Settings\vicky\Desktop\Sysclean\VSCANTM.BIN" has finished running.
  • 0

#4
miekiemoes

miekiemoes

    Malware Expert

  • Member
  • PipPipPipPipPipPipPipPip
  • 5,503 posts
  • MVP
Hello,

First let's cleanup a bit..

* Please set your system to show all files; please see here if you're unsure how to do this.

* Start HijackThis, close all open windows leaving only HijackThis running. Place a check against each of the following:

O4 - HKLM\..\Run: [SetupType] Portable
O4 - HKLM\..\Run: [NAV] C:\WINDOWS\system32\dll\csrss.exe
O4 - HKLM\..\Run: [winsvc] c:\windows\system32\winsvc.exe


* Click on Fix Checked when finished and exit HijackThis.

* Reboot into Safe Mode`: ( without networking support !)
°To get into the Safe mode as the computer is booting press and hold your "F8 Key". Use your arrow keys to move to "Safe Mode" and press your Enter key.


* Using Windows Explorer, locate the following files/folders, and delete them if still present:

c:\windows\system32\winsvc.exe
C:\WINDOWS\system32\attached.zip
C:\WINDOWS\system32\xxz.tmp
C:\WINDOWS\system32\uglym.jpg
C:\WINDOWS\Prefetch <== delete the contents of this folder!

* Still in safe mode Run Ccleaner and click Run Cleaner (bottom right)

* Reboot your system back to normal mode.

I want to know what it is, so can you go to next site:
http://virusscan.jotti.org/

On top you'll find: File to upload and scan.
Now browse to the next files:

C:\WINDOWS\system32\dll\csrss.exe
C:\Windows\nvsvc32.exe

(normally that last one belongs to NVIDIA graphics card drivers, but normally it must be present in the system32-folder)

Click submit and let it scan.
Post the results in your next reply.

Post back a fresh HijackThis log and I'll take another look.
  • 0

#5
TheJackal

TheJackal

    New Member

  • Topic Starter
  • Member
  • Pip
  • 3 posts
Thank you Miek.. I reinstalled windows .. Thank you for all your help!
  • 0

#6
miekiemoes

miekiemoes

    Malware Expert

  • Member
  • PipPipPipPipPipPipPipPip
  • 5,503 posts
  • MVP
Ok, no problem. :tazz:
Sometimes it wont hurt to start from scratch. ;)
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP