Excal
Help! [RESOLVED]
#61
Posted 24 August 2005 - 09:54 PM
Excal
#62
Posted 24 August 2005 - 10:01 PM
thanks
#63
Posted 24 August 2005 - 10:09 PM
I would stick with this one for now.
Excal
#64
Posted 31 August 2005 - 03:06 PM
Lannie
#65
Posted 31 August 2005 - 03:20 PM
Excal
#66
Posted 31 August 2005 - 06:21 PM
Infection Name Location Risk
IBIS Toolbar HKLM\software\microsoft\windows\currentversion\run##viewmgr Medium
Advertising C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\159XJWSD\bins=1[1].gif Low
Tracking Cookie(s) C:\Documents and Settings\Owner\Cookies\owner@atwola[1].txt Medium
Overpro.com C:\Program Files\Common Files\SWF Studio High
Overpro.com C:\Program Files\Common Files\SWF Studio\FileSys.dll High
Overpro.com C:\Program Files\Common Files\SWF Studio\SysInfo.dll High
BookedSpace C:\WINDOWS\bsx32.ini Elevated
WildTangent C:\WINDOWS\System32\wtcpl.cpl
#67
Posted 31 August 2005 - 06:47 PM
Please remove the following folders using Windows Explorer (if present):
C:\Program Files\Common Files\SWF Studio
Please remove just the files from the following paths using Windows Explorer (if present):
C:\WINDOWS\System32\wtcpl.cpl
C:\WINDOWS\bsx32.ini
reboot to normal mode
go to start>run and copy and paste this in.
regedit /e C:\search.txt "HKEY_LOCAL_MACHINE\microsoft\windows\currentversion"
Paste the results in your next post (file will be C:\ search.txt)
I think we might be seeing the end of the tunnel!!
#68
Posted 31 August 2005 - 07:07 PM
Thanks!
#69
Posted 31 August 2005 - 07:33 PM
#70
Posted 31 August 2005 - 08:07 PM
first thing i need you to do is uninstall viewpoint manager. go to your control panel, then to add/remove programs.
after you are done that:
Launch Notepad, and copy/paste the box below into a new text file. Save it as rebuild.reg (make sure that Save as Type is set at "All Files") on your Desktop. Ensure there is no space at or above REGEDIT 4.
REGEDIT4
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv" = "c:\windows\system\hpsysdrv.exe"
"HotKeysCmds" = "C:\WINDOWS\System32\hkcmd.exe"
"CamMonitor" = "c:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe"
"Share-to-Web Namespace Daemon" = "c:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe"
"KBD" = "C:\HP\KBD\KBD.EXE" ["Hewlett-Packard Company"]
"StorageGuard" = ""C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r"
"Recguard" = "C:\WINDOWS\SMINST\RECGUARD.EXE"
"NvCplDaemon" = "RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup"
"PS2" = "C:\WINDOWS\system32\ps2.exe"
"EM_EXEC" = "C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE"
"tgcmd" = ""C:\Program Files\Support.com\bin\tgcmd.exe" /server"
"StatusClient" = "C:\Program Files\Hewlett-Packard\Toolbox2.0\Apache Tomcat 4.0\webapps\Toolbox\StatusClient\StatusClient.exe /auto"
"TomcatStartup" = "C:\Program Files\Hewlett-Packard\Toolbox2.0\hpbpsttp.exe"
"AVG7_CC" = "C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP"
"QuickTime Task" = ""C:\Program Files\QuickTime\qttask.exe" -atboottime"
"Zone Labs Client" = "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
"SunJavaUpdateSched" = "C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe"
"mmtask" = "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe"
"gcasServ" = ""C:\Program Files\Microsoft AntiSpyware\gcasServ.exe""
Locate rebuild.reg on your Desktop and double-click on it. You will receive a prompt similar to: "Do you wish to merge the information into the registry?". Answer "Yes" and wait for a message to appear similar to "Merged Successfully".
reboot your computer and lets run spyware dr again.
Thanks,
Excal
#71
Posted 01 September 2005 - 01:39 PM
Thanks for your help and for your time. What next?
Lannie
#72
Posted 01 September 2005 - 01:52 PM
you can delete the folder of viewpoint, should be in program files. (probally in safe mode) and when in safe mode, run ewido again.
you can go ahead with the second task after that.
Go ahead and delete that archive
Post a fresh HiJackthis log.
Excal
#73
Posted 01 September 2005 - 02:13 PM
#74
Posted 01 September 2005 - 10:20 PM
fingers are still crosses!
#75
Posted 01 September 2005 - 11:00 PM
Thanks a ton for all of your help.
Similar Topics
0 user(s) are reading this topic
0 members, 0 guests, 0 anonymous users