Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

pokapoka70.exe and other problems


  • Please log in to reply

#1
Shadout Mapes

Shadout Mapes

    New Member

  • Member
  • Pip
  • 8 posts
I have several problems with my computer, from some strange process called pokapoka70.exe which quickly hides itself whenever I bring up my processes list in the task manager, to several iexplore.exe processes running at once eating up my RAM, and a few other problems, I think. I went through the whole Ad-Aware, CleanUp!, Spybot, TrojanHunter, etc. steps, and I've gotten rid of several problems, but these just won't go.

Also, when I ran Spybot after restarting, it still wouldn't let me clean out the Gator files, despite it being before my profile began opening programs.

Here's my HiJackThis log, thanks in advance to anyone who can help me out.


Logfile of HijackThis v1.99.1
Scan saved at 11:21:52 PM, on 9/23/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\McAfee\McAfee VirusScan\Avsynmgr.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\McAfee\McAfee VirusScan\VsStat.exe
C:\Program Files\McAfee\McAfee VirusScan\Vshwin32.exe
C:\Program Files\Common Files\Network Associates\McShield\Mcshield.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\McAfee\McAfee VirusScan\Webscanx.exe
C:\Program Files\McAfee\McAfee VirusScan\Avconsol.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Microsoft Hardware\Keyboard\type32.exe
C:\WINDOWS\system32\ICO.EXE
C:\Program Files\McAfee\McAfee VirusScan\alogserv.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\system32\Pelmiced.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\etb\pokapoka70.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Seth\Hijackthis\HijackThis.exe
C:\Program Files\Internet Explorer\iexplore.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.ezwebsearching.com/sp2.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.ezwebsearching.com/sp2.php
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {18518FD1-A36A-10F5-38DE-0C190F8B1ABE} - C:\WINDOWS\system32\vtedasam.dll
O2 - BHO: (no name) - {2D2AA631-C67D-F8D1-A29E-A87B259D8D4E} - C:\WINDOWS\system32\dsnzrrwl.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {64C76680-233E-9C0B-8CA1-E2F10E6C4850} - C:\WINDOWS\system32\gglbarwl.dll
O4 - HKLM\..\Run: [ConMgr.exe] "C:\Program Files\EarthLink 5.0\ConMgr.exe"
O4 - HKLM\..\Run: [IntelliType] "C:\Program Files\Microsoft Hardware\Keyboard\type32.exe"
O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE
O4 - HKLM\..\Run: [unvxkowq] C:\WINDOWS\erqfyjfy.exe
O4 - HKLM\..\Run: [Alogserv] C:\Program Files\McAfee\McAfee VirusScan\alogserv.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Visualware Security Suite] "C:\Program Files\Visualware Security Suite\tscore.exe" -autostartup
O4 - HKLM\..\Run: [System service66] C:\WINDOWS\etb\pokapoka66.exe
O4 - HKLM\..\Run: [System service67] C:\WINDOWS\etb\pokapoka69.exe
O4 - HKLM\..\Run: [System service69] C:\WINDOWS\\etb\pokapoka69.exe
O4 - HKLM\..\Run: [System service70] C:\WINDOWS\etb\pokapoka70.exe
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.2\THGuard.exe"
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM95\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE
O8 - Extra context menu item: Download with GetRight - C:\Program Files\GetRight\GRdownload.htm
O8 - Extra context menu item: LimeShop Preferences - file://C:\Program Files\LimeShop\System\Temp\limeshop_script0.htm
O8 - Extra context menu item: Open with GetRight Browser - C:\Program Files\GetRight\GRbrowse.htm
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.t...all/xscan60.cab
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnote...ad/mnviewer.cab
O16 - DPF: {34805D32-AD89-469E-8503-A5666AEE4333} - http://207.188.7.150...etzip/RdxIE.cab
O16 - DPF: {40D61F04-59E4-4C8D-BF6E-697AB9C21F43} (InstantChess) - http://www.instantch...et/chessbar.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai...all/xscan53.cab
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius....tiveXPlugin.cab
O16 - DPF: {BF4FC0C7-4387-4D18-AD86-DF33DDDE33C7} - http://hot.activebud...ld/websetup.cab
O16 - DPF: {EE5CA45C-BFAC-48E6-BE6C-3C607620FF43} (IMViewerControl Class) - http://companion.log...3/bin/imvid.cab
O23 - Service: AVSync Manager (AvSynMgr) - Networks Associates Technologies, Inc. - C:\Program Files\McAfee\McAfee VirusScan\Avsynmgr.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McShield - Unknown owner - C:\Program Files\Common Files\Network Associates\McShield\Mcshield.exe
O23 - Service: satxpsyrviqn (wsesnrmx6) - Unknown owner - C:\WINDOWS\system32\jfgnohct6.exe (file missing)
  • 0

Advertisements


#2
didom

didom

    Member 1K

  • Member
  • PipPipPipPip
  • 1,919 posts
click Start> Run> type in CMD tap enter. Copy/Paste the following into command prompt:

sc delete wsesnrmx6

At the command prompt: type exit.

Open C:\WINDOWS\system32\jfgnohct6.exe <--Delete file if listed.

---------------------------------------------------------

Please download miekiemoes' LQfix batch here:
http://users.telenet...tools/LQfix.zip
Unzip it to the desktop but do NOT run it yet.

Next, please reboot your computer in Safe Mode by doing the following:
1) Restart your computer
2) After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
3) Instead of Windows loading as normal, a menu should appear
4) Select the first option, to run Windows in Safe Mode.

For additional help in booting into Safe Mode, see the following site:
http://www.pchell.co.../safemode.shtml

Once in Safe Mode, please run LQfix.bat. When finished, scan again with HijackThis and check the following items:

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.ezwebsearching.com/sp2.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.ezwebsearching.com/sp2.php
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {18518FD1-A36A-10F5-38DE-0C190F8B1ABE} - C:\WINDOWS\system32\vtedasam.dll
O2 - BHO: (no name) - {2D2AA631-C67D-F8D1-A29E-A87B259D8D4E} - C:\WINDOWS\system32\dsnzrrwl.dll (file missing)
O2 - BHO: (no name) - {64C76680-233E-9C0B-8CA1-E2F10E6C4850} - C:\WINDOWS\system32\gglbarwl.dll
O4 - HKLM\..\Run: [unvxkowq] C:\WINDOWS\erqfyjfy.exe
O16 - DPF: {34805D32-AD89-469E-8503-A5666AEE4333} - http://207.188.7.150...etzip/RdxIE.cab
O23 - Service: satxpsyrviqn (wsesnrmx6) - Unknown owner - C:\WINDOWS\system32\jfgnohct6.exe (file missing)

After checking these items, close all browser windows except HijackThis and click "Fix checked".

Make sure all hidden files and folders are visible (Instructions )
Reboot your computer into safe mode (Instructions)

Find and delete this file (if they are still there):
C:\WINDOWS\erqfyjfy.exe <= this file


Reboot your computer back into normal mode.

Run Panda's online virus scan and perform a full system scan: Panda ActiveScan

Save the scan log and post it along with a new HijackThis Log in your next reply.
  • 0

#3
Shadout Mapes

Shadout Mapes

    New Member

  • Topic Starter
  • Member
  • Pip
  • 8 posts
Sorry for the late reply, I live in Houston, and Rita killed the cable in my area for the last few days.

Thanks for the help, my computer's already doing a lot better.

First off, I did not find jfgnohct6.exe in the specified folder. I did go into safe mode and run the LQfix.bat file, and HijackThis, but when scanning with HijackThis, I could not find the following items:

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.ezwebsearching.com/sp2.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.ezwebsearching.com/sp2.php
R3 - Default URLSearchHook is missing
O23 - Service: satxpsyrviqn (wsesnrmx6) - Unknown owner - C:\WINDOWS\system32\jfgnohct6.exe (file missing)

This is strange, because when in normal mode, all but one of these do show up on the log (see below). Should I fix them in normal mode, or try again in safe mode?

I also could not find erqfyjfy.exe in the specified folder under safe mode.

Panda and HijackThis logs:

ActiveScan Log:
Incident                                Status                      Location
Spyware:spyware/betterinet    No disinfected    C:\WINDOWS\SYSTEM32\in10b6s.dll
Adware:adware/favoriteman    No disinfected                C:\WINDOWS\DOWNLOADED PROGRAM FILES\ATPartners.inf
Adware:adware/quicksearch    No disinfected                C:\WINDOWS\DOWNLOADED PROGRAM FILES\install.inf
Adware:adware/tvmedia        No disinfected                C:\Documents and Settings\Seth\Application Data\tvmknwrd.dll
Adware:adware/gator          No disinfected                C:\GatorPatch.log
Adware:adware/comedy-planet  No disinfected                Windows Registry
Virus:W32/Sdbot.EFG.worm      Disinfected                  C:\a.bat
Adware:Adware/Iagold          No disinfected                C:\Program Files\Hijackthis\backups\backup-20050926-162142-213.dll
Virus:Trj/Agent.FN            Disinfected                  C:\Program Files\Hijackthis\backups\backup-20050926-162142-224.dll
Adware:Adware/NetPals        No disinfected                C:\WINDOWS\Downloaded Program Files\ATPartners.inf
Adware:Adware/TalkStocks      No disinfected                C:\WINDOWS\ovvhxhff.dll.tcf
Virus:Trj/Agent.GD            Disinfected                  C:\WINDOWS\system32\drivers\.sys
Virus:Trj/Agent.GD            Disinfected                  C:\WINDOWS\system32\drivers\blgfwanc.sys
Adware:Adware/Iagold          No disinfected                C:\WINDOWS\system32\dsnzrrwl.dll.tcf
Virus:Trj/Clicker.HY          Disinfected                  C:\WINDOWS\system32\gvkljrqs.exe.tcf
Virus:Trj/Clicker.HY          Disinfected                  C:\WINDOWS\system32\watgnwnf.exe.tcf
Virus:Trj/Agent.FN            Disinfected                  C:\WINDOWS\system32\zadjcyqn.dll
Virus:W32/Sdbot.EFG.worm      Disinfected                  C:\xz.bat


HijackThis Log

Logfile of HijackThis v1.99.1
Scan saved at 6:11:32 PM, on 9/26/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Microsoft Hardware\Keyboard\type32.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\WINDOWS\system32\ICO.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\Pelmiced.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.ezwebsearching.com/sp2.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.ezwebsearching.com/sp2.php
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {18518FD1-A36A-10F5-38DE-0C190F8B1ABE} - (no file)
O2 - BHO: (no name) - {2D2AA631-C67D-F8D1-A29E-A87B259D8D4E} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {64C76680-233E-9C0B-8CA1-E2F10E6C4850} - (no file)
O4 - HKLM\..\Run: [ConMgr.exe] "C:\Program Files\EarthLink 5.0\ConMgr.exe"
O4 - HKLM\..\Run: [IntelliType] "C:\Program Files\Microsoft Hardware\Keyboard\type32.exe"
O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Visualware Security Suite] "C:\Program Files\Visualware Security Suite\tscore.exe" -autostartup
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.2\THGuard.exe"
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM95\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE
O8 - Extra context menu item: Download with GetRight - C:\Program Files\GetRight\GRdownload.htm
O8 - Extra context menu item: LimeShop Preferences - file://C:\Program Files\LimeShop\System\Temp\limeshop_script0.htm
O8 - Extra context menu item: Open with GetRight Browser - C:\Program Files\GetRight\GRbrowse.htm
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.t...all/xscan60.cab
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnote...ad/mnviewer.cab
O16 - DPF: {40D61F04-59E4-4C8D-BF6E-697AB9C21F43} (InstantChess) - http://www.instantch...et/chessbar.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai...all/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoft...free/asinst.cab
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius....tiveXPlugin.cab
O16 - DPF: {BF4FC0C7-4387-4D18-AD86-DF33DDDE33C7} - http://hot.activebud...ld/websetup.cab
O16 - DPF: {EE5CA45C-BFAC-48E6-BE6C-3C607620FF43} (IMViewerControl Class) - http://companion.log...3/bin/imvid.cab
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe


  • 0

#4
didom

didom

    Member 1K

  • Member
  • PipPipPipPip
  • 1,919 posts
Scan again with HijackThis and check the following items:

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.ezwebsearching.com/sp2.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.ezwebsearching.com/sp2.php
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {18518FD1-A36A-10F5-38DE-0C190F8B1ABE} - (no file)
O2 - BHO: (no name) - {2D2AA631-C67D-F8D1-A29E-A87B259D8D4E} - (no file)
O2 - BHO: (no name) - {64C76680-233E-9C0B-8CA1-E2F10E6C4850} - (no file)

After checking these items, close all browser windows except HijackThis and click "Fix checked".

Then reboot your computer.

Please download the Killbox.
Please do NOT run it yet.
  • Then please reboot into Safe Mode by restarting your computer and pressing F8 as your computer is booting up. Then select the Safe Mode option.
  • Once in Safe Mode, please run Killbox.
  • Select "Delete on Reboot".
  • Open the text file with these instructions in it, and copy the file names below to the clipboard by highlighting them and pressing Control-C:

    C:\WINDOWS\SYSTEM32\in10b6s.dll
    C:\WINDOWS\DOWNLOADED PROGRAM FILES\ATPartners.inf
    C:\WINDOWS\DOWNLOADED PROGRAM FILES\install.inf
    C:\Documents and Settings\Seth\Application Data\tvmknwrd.dll
    C:\GatorPatch.log
    C:\a.bat
    C:\Program Files\Hijackthis\backups\backup-20050926-162142-213.dll
    C:\Program Files\Hijackthis\backups\backup-20050926-162142-224.dll
    C:\WINDOWS\Downloaded Program Files\ATPartners.inf
    C:\WINDOWS\ovvhxhff.dll.tcf
    C:\WINDOWS\system32\drivers\.sys
    C:\WINDOWS\system32\drivers\blgfwanc.sys
    C:\WINDOWS\system32\dsnzrrwl.dll.tcf
    C:\WINDOWS\system32\gvkljrqs.exe.tcf
    C:\WINDOWS\system32\watgnwnf.exe.tcf
    C:\WINDOWS\system32\zadjcyqn.dll
    C:\xz.bat


  • Return to Killbox, go to the File menu, and choose "Paste from Clipboard".
  • Click the red-and-white "Delete File" button. Click "Yes" at the Delete on Reboot prompt. Click "No" at the Pending Operations prompt.

    If you receive a message such as: "Component 'MsComCtl.ocx' or one of its dependencies not correctly registered: a file is missing or invalid." when trying to run TheKillbox, click here to download and run missingfilesetup.exe. Then try TheKillbox again..

  • Let the system reboot.
Find and delete this folders :
C:\!Submit <= this folder

Go to start > run and type: cleanmgr and click ok.
Let it scan your system for files to remove.
Make sure Temporary Files, Temporary Internet Files, and Recycle Bin are the only things checked.
Press OK to remove them.

Run Panda's online virus scan and perform a full system scan: Panda ActiveScan

Save the scan log and post it along with a new HijackThis Log in your next reply.
  • 0

#5
Shadout Mapes

Shadout Mapes

    New Member

  • Topic Starter
  • Member
  • Pip
  • 8 posts
Logfile of HijackThis v1.99.1
Scan saved at 4:43:18 AM, on 9/28/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Microsoft Hardware\Keyboard\type32.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\WINDOWS\system32\ICO.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\AIM95\aim.exe
C:\WINDOWS\system32\Pelmiced.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
O2 - BHO: (no name) - {18518FD1-A36A-10F5-38DE-0C190F8B1ABE} - (no file)
O2 - BHO: (no name) - {2D2AA631-C67D-F8D1-A29E-A87B259D8D4E} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {64C76680-233E-9C0B-8CA1-E2F10E6C4850} - (no file)
O4 - HKLM\..\Run: [ConMgr.exe] "C:\Program Files\EarthLink 5.0\ConMgr.exe"
O4 - HKLM\..\Run: [IntelliType] "C:\Program Files\Microsoft Hardware\Keyboard\type32.exe"
O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Visualware Security Suite] "C:\Program Files\Visualware Security Suite\tscore.exe" -autostartup
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.2\THGuard.exe"
O4 - HKLM\..\RunOnce: [DELDIR0.EXE] "C:\DOCUME~1\Seth\LOCALS~1\Temp\DELDIR0.EXE" "C:\Program Files\McAfee\McAfee Shared Components\Guardian\"
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM95\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE
O8 - Extra context menu item: Download with GetRight - C:\Program Files\GetRight\GRdownload.htm
O8 - Extra context menu item: LimeShop Preferences - file://C:\Program Files\LimeShop\System\Temp\limeshop_script0.htm
O8 - Extra context menu item: Open with GetRight Browser - C:\Program Files\GetRight\GRbrowse.htm
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.t...all/xscan60.cab
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnote...ad/mnviewer.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {40D61F04-59E4-4C8D-BF6E-697AB9C21F43} (InstantChess) - http://www.instantch...et/chessbar.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai...all/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoft...free/asinst.cab
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius....tiveXPlugin.cab
O16 - DPF: {BF4FC0C7-4387-4D18-AD86-DF33DDDE33C7} - http://hot.activebud...ld/websetup.cab
O16 - DPF: {EE5CA45C-BFAC-48E6-BE6C-3C607620FF43} (IMViewerControl Class) - http://companion.log...3/bin/imvid.cab
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe


Incident Status Location
Adware:adware/tvmedia No disinfected C:\Documents and Settings\Seth\Application Data\tvmknwrd.dll
Adware:adware/comedy-planet No disinfected Windows Registry
  • 0

#6
didom

didom

    Member 1K

  • Member
  • PipPipPipPip
  • 1,919 posts
Please go to start -> run -> type: regedit , Navigate to:

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]

Right-click on the subkey {18518FD1-A36A-10F5-38DE-0C190F8B1ABE} Select: Permissions
If the field under Group or user names is empty click Add
In the box titled "Enter the object names to select" type Administrators
click OK
With Administrators highlighted in the top part of the window check the Allow box next to Full Control
Click Apply and OK
Delete the key

Please do the same for these subkeys:
{64C76680-233E-9C0B-8CA1-E2F10E6C4850}

{2D2AA631-C67D-F8D1-A29E-A87B259D8D4E}


-----------------------------------------------------

Please download ewido security suite it is a free version of the program.
  • Install ewido security suite
  • When installing, under "Additional Options" uncheck..
    • Install background guard
    • Install scan via context menu
  • Launch ewido, there should be an icon on your desktop, double-click it.
  • The program will now open to the main screen.
  • When you run ewido for the first time, you may get a warning "Database could not be found!". Click OK. We will fix this in a moment.
  • You will need to update ewido to the latest definition files.
    • On the left hand side of the main screen click update.
    • Then click on Start Update.
  • The update will start and a progress bar will show the updates being installed.
    (the status bar at the bottom will display ("Update successful")
If you are having problems with the updater, you can use this link to manually update ewido.
ewido manual updates

Make sure all hidden files and folders are visible (Instructions )
Reboot your computer into safe mode (Instructions)

Find and delete this file:
C:\Documents and Settings\Seth\Application Data\tvmknwrd.dll <= this file

Run Ewido:
  • Click on scanner
  • Click on Complete System Scan and the scan will begin.
  • You will be prompted to clean the first infection.
  • Select "Perform action on all infections", then proceed.
  • Once the scan has completed, there will be a button located on the bottom of the screen named Save report
  • Click Save report.
  • Save the report .txt file to your desktop or a location where you can find it easily.
Close ewido security suite.

Reboot into normal mode.

Then, please run this online virus scan: Panda ActiveScan

Save the scan log and post it along with a new HijackThis Log and the Ewido log in your next reply.

Edited by didom, 28 September 2005 - 04:13 AM.

  • 0

#7
Shadout Mapes

Shadout Mapes

    New Member

  • Topic Starter
  • Member
  • Pip
  • 8 posts
Incident Status Location
Adware:adware/tvmedia No disinfected C:\Documents and Settings\Seth\Application Data\tvmuknwrd.dll

Adware:adware/gator No disinfected C:\WINDOWS\GatorPatch.log

Adware:adware/comedy-planet No disinfected Windows Registry



Logfile of HijackThis v1.99.1
Scan saved at 5:43:29 PM, on 9/29/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Microsoft Hardware\Keyboard\type32.exe
C:\WINDOWS\system32\ICO.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\system32\Pelmiced.exe
C:\Program Files\AIM95\aim.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O4 - HKLM\..\Run: [ConMgr.exe] "C:\Program Files\EarthLink 5.0\ConMgr.exe"
O4 - HKLM\..\Run: [IntelliType] "C:\Program Files\Microsoft Hardware\Keyboard\type32.exe"
O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Visualware Security Suite] "C:\Program Files\Visualware Security Suite\tscore.exe" -autostartup
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.2\THGuard.exe"
O4 - HKLM\..\RunOnce: [DELDIR0.EXE] "C:\DOCUME~1\Seth\LOCALS~1\Temp\DELDIR0.EXE" "C:\Program Files\McAfee\McAfee Shared Components\Guardian\"
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM95\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE
O8 - Extra context menu item: Download with GetRight - C:\Program Files\GetRight\GRdownload.htm
O8 - Extra context menu item: LimeShop Preferences - file://C:\Program Files\LimeShop\System\Temp\limeshop_script0.htm
O8 - Extra context menu item: Open with GetRight Browser - C:\Program Files\GetRight\GRbrowse.htm
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.t...all/xscan60.cab
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnote...ad/mnviewer.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {40D61F04-59E4-4C8D-BF6E-697AB9C21F43} (InstantChess) - http://www.instantch...et/chessbar.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai...all/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoft...free/asinst.cab
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius....tiveXPlugin.cab
O16 - DPF: {BF4FC0C7-4387-4D18-AD86-DF33DDDE33C7} - http://hot.activebud...ld/websetup.cab
O16 - DPF: {EE5CA45C-BFAC-48E6-BE6C-3C607620FF43} (IMViewerControl Class) - http://companion.log...3/bin/imvid.cab
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe


---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------

+ Created on: 4:42:46 PM, 9/29/2005
+ Report-Checksum: F9609E8A

+ Scan result:

HKLM\SOFTWARE\Classes\CLSID\{2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} -> Spyware.MiniBug : Cleaned with backup
HKLM\SOFTWARE\Classes\MiniBugTransporter.MiniBugTransporterX\CLSID\\ -> Spyware.MiniBug : Cleaned with backup
HKLM\SOFTWARE\Classes\MiniBugTransporter.MiniBugTransporterX.1\CLSID\\ -> Spyware.MiniBug : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/gsda.dll\\.Owner -> Spyware.GameSpyArcade : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/gsda.dll\\{70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} -> Spyware.GameSpyArcade : Cleaned with backup
C:\Documents and Settings\Liz\Cookies\liz@doubleclick[1].txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
C:\Documents and Settings\Seth\Cookies\seth@2o7[2].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Seth\Cookies\seth@ad.yieldmanager[1].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Seth\Cookies\seth@ads.pointroll[1].txt -> Spyware.Cookie.Pointroll : Cleaned with backup
C:\Documents and Settings\Seth\Cookies\seth@advertising[2].txt -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Documents and Settings\Seth\Cookies\seth@atdmt[2].txt -> Spyware.Cookie.Atdmt : Cleaned with backup
C:\Documents and Settings\Seth\Cookies\seth@burstnet[1].txt -> Spyware.Cookie.Burstnet : Cleaned with backup
C:\Documents and Settings\Seth\Cookies\seth@casalemedia[1].txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
C:\Documents and Settings\Seth\Cookies\seth@centrport[1].txt -> Spyware.Cookie.Centrport : Cleaned with backup
C:\Documents and Settings\Seth\Cookies\seth@citi.bridgetrack[2].txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup
C:\Documents and Settings\Seth\Cookies\seth@com[2].txt -> Spyware.Cookie.Com : Cleaned with backup
C:\Documents and Settings\Seth\Cookies\seth@counter10.sextracker[2].txt -> Spyware.Cookie.Sextracker : Cleaned with backup
C:\Documents and Settings\Seth\Cookies\seth@counter3.sextracker[1].txt -> Spyware.Cookie.Sextracker : Cleaned with backup
C:\Documents and Settings\Seth\Cookies\seth@counter4.sextracker[2].txt -> Spyware.Cookie.Sextracker : Cleaned with backup
C:\Documents and Settings\Seth\Cookies\seth@counter5.sextracker[2].txt -> Spyware.Cookie.Sextracker : Cleaned with backup
C:\Documents and Settings\Seth\Cookies\seth@counter9.sextracker[1].txt -> Spyware.Cookie.Sextracker : Cleaned with backup
C:\Documents and Settings\Seth\Cookies\seth@cs.sexcounter[2].txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
C:\Documents and Settings\Seth\Cookies\seth@doubleclick[1].txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
C:\Documents and Settings\Seth\Cookies\seth@fastclick[1].txt -> Spyware.Cookie.Fastclick : Cleaned with backup
C:\Documents and Settings\Seth\Cookies\seth@mediaplex[2].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Documents and Settings\Seth\Cookies\seth@paycounter[1].txt -> Spyware.Cookie.Paycounter : Cleaned with backup
C:\Documents and Settings\Seth\Cookies\seth@questionmarket[1].txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
C:\Documents and Settings\Seth\Cookies\seth@servedby.advertising[2].txt -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Documents and Settings\Seth\Cookies\seth@sexlist[2].txt -> Spyware.Cookie.Sexlist : Cleaned with backup
C:\Documents and Settings\Seth\Cookies\seth@sextracker[2].txt -> Spyware.Cookie.Sextracker : Cleaned with backup
C:\Documents and Settings\Seth\Cookies\seth@targetnet[1].txt -> Spyware.Cookie.Targetnet : Cleaned with backup
C:\Documents and Settings\Seth\Cookies\seth@trafficmp[1].txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
C:\Documents and Settings\Seth\Cookies\seth@www.burstbeacon[1].txt -> Spyware.Cookie.Burstbeacon : Cleaned with backup
C:\Documents and Settings\Seth\Cookies\seth@www.myaffiliateprogram[1].txt -> Spyware.Cookie.Myaffiliateprogram : Cleaned with backup
C:\Documents and Settings\Seth\Cookies\seth@z1.adserver[1].txt -> Spyware.Cookie.Adserver : Cleaned with backup
C:\Program Files\AWS\WeatherBug\MiniBugTransporter.dll.tcf -> Spyware.Wheaterbug : Cleaned with backup
C:\WINDOWS\system32\cp.exe -> TrojanDownloader.Agent.ic : Cleaned with backup


::Report End
  • 0

#8
didom

didom

    Member 1K

  • Member
  • PipPipPipPip
  • 1,919 posts
Please run this tool:
http://www.microsoft...&DisplayLang=en

Then reboot your computer.

Make sure all hidden files and folders are visible (Instructions )
Reboot your computer into safe mode (Instructions)

Find and delete this file :
C:\WINDOWS\GatorPatch.log <= this file

Reboot your computer back into normal mode.

Run Panda's online virus scan and perform a full system scan: Panda ActiveScan

Save the scan log and post it along with a new HijackThis Log in your next reply.

Let me know if any problems persist.
  • 0

#9
Shadout Mapes

Shadout Mapes

    New Member

  • Topic Starter
  • Member
  • Pip
  • 8 posts
Strangely enough, the TV Removal Tool told me that no TV Media is installed.


Incident Status Location
Adware:adware/tvmedia No disinfected C:\Documents and Settings\Seth\Application Data\tvmuknwrd.dll

Adware:adware/comedy-planet No disinfected Windows Registry


Logfile of HijackThis v1.99.1
Scan saved at 3:15:27 AM, on 10/2/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Microsoft Hardware\Keyboard\type32.exe
C:\WINDOWS\system32\ICO.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Visualware Security Suite\tscore.exe
C:\WINDOWS\system32\Pelmiced.exe
C:\Program Files\AIM95\aim.exe
C:\WINDOWS\system32\jview.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O4 - HKLM\..\Run: [ConMgr.exe] "C:\Program Files\EarthLink 5.0\ConMgr.exe"
O4 - HKLM\..\Run: [IntelliType] "C:\Program Files\Microsoft Hardware\Keyboard\type32.exe"
O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Visualware Security Suite] "C:\Program Files\Visualware Security Suite\tscore.exe" -autostartup
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.2\THGuard.exe"
O4 - HKLM\..\RunOnce: [DELDIR0.EXE] "C:\DOCUME~1\Seth\LOCALS~1\Temp\DELDIR0.EXE" "C:\Program Files\McAfee\McAfee Shared Components\Guardian\"
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM95\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE
O8 - Extra context menu item: Download with GetRight - C:\Program Files\GetRight\GRdownload.htm
O8 - Extra context menu item: LimeShop Preferences - file://C:\Program Files\LimeShop\System\Temp\limeshop_script0.htm
O8 - Extra context menu item: Open with GetRight Browser - C:\Program Files\GetRight\GRbrowse.htm
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.t...all/xscan60.cab
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnote...ad/mnviewer.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {40D61F04-59E4-4C8D-BF6E-697AB9C21F43} (InstantChess) - http://www.instantch...et/chessbar.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai...all/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoft...free/asinst.cab
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius....tiveXPlugin.cab
O16 - DPF: {BF4FC0C7-4387-4D18-AD86-DF33DDDE33C7} - http://hot.activebud...ld/websetup.cab
O16 - DPF: {EE5CA45C-BFAC-48E6-BE6C-3C607620FF43} (IMViewerControl Class) - http://companion.log...3/bin/imvid.cab
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
  • 0

#10
didom

didom

    Member 1K

  • Member
  • PipPipPipPip
  • 1,919 posts
Please do this:

Please download the Killbox.
Please do NOT run it yet.
  • Then please reboot into Safe Mode by restarting your computer and pressing F8 as your computer is booting up. Then select the Safe Mode option.
  • Once in Safe Mode, please run Killbox.
  • Select "Delete on Reboot".
  • Open the text file with these instructions in it, and copy the file names below to the clipboard by highlighting them and pressing Control-C:

    C:\Program Files\tv media
    C:\Documents and Settings\Seth\Application Data\tvmuknwrd.dll


  • Return to Killbox, go to the File menu, and choose "Paste from Clipboard".
  • Click the red-and-white "Delete File" button. Click "Yes" at the Delete on Reboot prompt. Click "No" at the Pending Operations prompt.

    If you receive a message such as: "Component 'MsComCtl.ocx' or one of its dependencies not correctly registered: a file is missing or invalid." when trying to run TheKillbox, click here to download and run missingfilesetup.exe. Then try TheKillbox again..

  • Let the system reboot.
Find and delete this folders :
C:\!Submit <= this folder

Go to start > run and type: cleanmgr and click ok.
Let it scan your system for files to remove.
Make sure Temporary Files, Temporary Internet Files, and Recycle Bin are the only things checked.
Press OK to remove them.

--------------------------------------------------

Go to next site: Trend Micro Anti-Spyware-scan
Click the Scan and Clean your PC and save it to your desktop.

* Doubleclick tmas-web-scan.exe-icon on your desktop
* Click agree to accept the terms of the license.
* After loading the definitions, click Start Scan
* When the scan is done, click Scan Results
* Check every item that was found (normally they are checked by default, so make sure they are all checked) and click Clean Threats Now
* A confirmation prompt will appear. Click OK
* Click Exit.

Reboot your computer.
After reboot, you'll see that the tmas-web-scan.exe-icon on your desktop will be gone, but there will be an Antispywarelog instead. It's a textfile.
Copy and paste the entire content of it in your next reply.

Edited by didom, 02 October 2005 - 05:32 AM.

  • 0

Advertisements


#11
Shadout Mapes

Shadout Mapes

    New Member

  • Topic Starter
  • Member
  • Pip
  • 8 posts
Started Scanning
Internet Cookies
Found 'paycounter.com' in 'Internet Explorer Cache'
Found 'advertising.com' in 'Internet Explorer Cache'
Found 'questionmarket.com' in 'Internet Explorer Cache'
Found 'www.burstbeacon.com' in 'Internet Explorer Cache'
Found 'realmedia.com' in 'Internet Explorer Cache'
Found 'centrport.net' in 'Internet Explorer Cache'
Found 'maxserving.com' in 'Internet Explorer Cache'
Found 'com.com' in 'Internet Explorer Cache'
Found 'ads.pointroll.com' in 'Internet Explorer Cache'
Found 'citi.bridgetrack.com' in 'Internet Explorer Cache'
Found 'z1.adserver.com' in 'Internet Explorer Cache'
Found 'doubleclick.net' in 'Internet Explorer Cache'
Found 'mediaplex.com' in 'Internet Explorer Cache'
Found 'targetnet.com' in 'Internet Explorer Cache'
Found '2o7.net' in 'Internet Explorer Cache'
Found 'about.com' in 'Internet Explorer Cache'
Found 'ad.yieldmanager.com' in 'Internet Explorer Cache'
Found 'ehg.hitbox.com' in 'Internet Explorer Cache'
Found 'hitbox.com' in 'Internet Explorer Cache'
Found 'atwola.com' in 'Internet Explorer Cache'
Found 'trafficmp.com' in 'Internet Explorer Cache'
Found 'servedby.advertising.com' in 'Internet Explorer Cache'
Found 'atdmt.com' in 'Internet Explorer Cache'
Found 'insightexpressai.com' in 'Internet Explorer Cache'
Found 'fastclick.net' in 'Internet Explorer Cache'
Found 'adknowledge.com' in 'Internet Explorer Cache'
Found 'casalemedia.com' in 'Internet Explorer Cache'
Found 'spylog.com' in 'Internet Explorer Cache'
Programs in Memory
Windows Registry
Found '' in 'Software\Kazaa'
Found '' in 'Software\Kazaa\KaZaA Media Desktop\Settings'
Found '' in 'Software\Kazaa\ResultsFilter'
Found '' in 'Software\Kazaa\Settings'
Found '' in 'Software\Kazaa\Transfer'
Found '' in 'Software\KaZaA\CloudLoad'
Found '' in 'Software\KaZaA\ConnectionInfo'
Found '' in 'Software\KaZaA\LocalContent'
Found '' in 'Software\SpeedBit\Download Accelerator\IEBar'
Found '' in 'Software\Kazaa'
Found '' in 'Software\Kazaa\Advanced'
Found '' in 'Software\Kazaa\LocalContent'
Found '' in 'Software\Kazaa\Promotions\Broadband'
Found '' in 'Software\Kazaa\Skins'
Found '' in 'Software\Kazaa\UserDetails'
Found '' in 'SOFTWARE\Kazaa\Bandwidth\in'
Found '' in 'SOFTWARE\Kazaa\Bandwidth\LastEstimate'
Found '' in 'SOFTWARE\Kazaa\Bandwidth\out'
Found '' in 'SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\D:\InstallShield\Kazaa\kazaa.exe'
Found 'LastSearchHash' in 'Software\Kazaa'
Found 'Tmp' in 'Software\Kazaa'
Found 'ScanFolder' in 'Software\Kazaa\Advanced'
Found 'BBDbLoc' in 'Software\Kazaa\Promotions\Broadband'
Found 'NullImageLoc' in 'Software\Kazaa\Promotions\Broadband'
Found '' in 'Software\Kazaa\Search'
Found 'adult_filter_level' in 'Software\Kazaa\ResultsFilter'
Found 'b' in 'SOFTWARE\Kazaa\Bandwidth\LastEstimate'
Found 'b0' in 'SOFTWARE\Kazaa\Bandwidth\in'
Found 'b0' in 'SOFTWARE\Kazaa\Bandwidth\out'
Found 'b0seconds' in 'SOFTWARE\Kazaa\Bandwidth\in'
Found 'b0seconds' in 'SOFTWARE\Kazaa\Bandwidth\out'
Found 'b1' in 'SOFTWARE\Kazaa\Bandwidth\in'
Found 'b1' in 'SOFTWARE\Kazaa\Bandwidth\out'
Found 'CacheDiscoveryTime' in 'Software\Kazaa\Transfer'
Found 'CacheHost' in 'Software\Kazaa\Transfer'
Found 'CachePort' in 'Software\Kazaa\Transfer'
Found 'CountryCode' in 'Software\Kazaa\UserDetails'
Found 'DatabaseDir' in 'SOFTWARE\Kazaa\LocalContent'
Found 'Date' in 'Software\Kazaa\Settings'
Found 'DlDir0' in 'Software\Kazaa\Transfer'
Found 'DownloadDir' in 'SOFTWARE\Kazaa\LocalContent'
Found 'AutoConnected' in 'Software\Kazaa\UserDetails'
Found 'firewall_filter' in 'Software\Kazaa\ResultsFilter'
Found 'HelpDir' in 'Software\Kazaa\Settings'
Found 'Quarantine' in 'Software\Kazaa\Settings'
Found 'UseCount' in 'Software\Kazaa\Settings'
Found 'SkinsDir' in 'Software\Kazaa\Skins'
Found 'NoUploadLimitWhenIdle' in 'Software\Kazaa\Transfer'
Found 'UserName' in 'Software\Kazaa\UserDetails'
Found 'FirewallStatus' in 'SOFTWARE\Kazaa'
Found 'ListenPort' in 'SOFTWARE\Kazaa'
Found 'my_ip_address' in 'SOFTWARE\Kazaa'
Found 'network_config' in 'SOFTWARE\Kazaa'
Found 'UDP_probe_successes' in 'SOFTWARE\Kazaa'
Found 'UDP_receive_status' in 'SOFTWARE\Kazaa'
Found 'time' in 'SOFTWARE\Kazaa\Bandwidth\LastEstimate'
Found 'KazaaNet' in 'SOFTWARE\Kazaa\ConnectionInfo'
Found '' in 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\Range1'
Internet URL Shortcuts
Files and Directories
Found '' in 'C:\Documents and Settings\Seth\Start Menu\Programs\KaZaA Media Desktop'
Found '' in 'C:\Program Files\Common Files\CMEII'
Found '' in 'C:\Program Files\KaZaA'
Found '' in 'C:\Program Files\KaZaA\My Shared Folder'
Found 'kmd171_en.exe' in 'C:\Program Files\My Shared Folder'
Found 'kazaa.exe' in 'C:\RECYCLER\S-1-5-21-2969962186-1445258045-4160758333-1005\Dc34'
Finished Scanning
Started Backup
Unable to backup the item 'C:\Program Files\Common Files\CMEII\gui\svcsap\applist.htm'. [SCANMODS] FCIAddFile failed. FCI Error=1, 'File not found'.
Unable to backup the item 'C:\Program Files\Common Files\CMEII\gui\svcsap\applist.xsl'. [SCANMODS] FCIAddFile failed. FCI Error=1, 'File not found'.
Unable to backup the item 'C:\Program Files\Common Files\CMEII\gui\svcsap\blank.txt'. [SCANMODS] FCIAddFile failed. FCI Error=1, 'File not found'.
Finished Backup
Started Cleaning
Checking for 'C:\Documents and Settings\Seth\Start Menu\Programs\KaZaA Media Desktop' in shortcut areas.
Checking for 'C:\Documents and Settings\Seth\Start Menu\Programs\KaZaA Media Desktop' in startup areas.
Cleaning 'C:\Documents and Settings\Seth\Start Menu\Programs\KaZaA Media Desktop'
Checking for 'C:\Documents and Settings\Seth\Start Menu\Programs\KaZaA Media Desktop\KaZaA Media Desktop.lnk' in shortcut areas.
Checking for 'C:\Documents and Settings\Seth\Start Menu\Programs\KaZaA Media Desktop\KaZaA Media Desktop.lnk' in startup areas.
Cleaning 'C:\Documents and Settings\Seth\Start Menu\Programs\KaZaA Media Desktop\KaZaA Media Desktop.lnk'
Checking for 'C:\Documents and Settings\Seth\Start Menu\Programs\KaZaA Media Desktop\Kazaa Website.url' in shortcut areas.
Checking for 'C:\Documents and Settings\Seth\Start Menu\Programs\KaZaA Media Desktop\Kazaa Website.url' in startup areas.
Cleaning 'C:\Documents and Settings\Seth\Start Menu\Programs\KaZaA Media Desktop\Kazaa Website.url'
Checking for 'C:\Program Files\Common Files\CMEII' in shortcut areas.
Checking for 'C:\Program Files\Common Files\CMEII' in startup areas.
Cleaning 'C:\Program Files\Common Files\CMEII'
Checking for 'C:\Program Files\Common Files\CMEII\gui\svcsap\applist.xsl' in shortcut areas.
Checking for 'C:\Program Files\Common Files\CMEII\gui\svcsap\applist.xsl' in startup areas.
Cleaning 'C:\Program Files\Common Files\CMEII\gui\svcsap\applist.xsl'
[SCANMODS] WARNING: Deletion of the file 'C:\Program Files\Common Files\CMEII\gui\svcsap\applist.xsl' requires a reboot.
Checking for 'C:\Program Files\Common Files\CMEII\gui\svcsap\blank.txt' in shortcut areas.
Checking for 'C:\Program Files\Common Files\CMEII\gui\svcsap\blank.txt' in startup areas.
Cleaning 'C:\Program Files\Common Files\CMEII\gui\svcsap\blank.txt'
[SCANMODS] WARNING: Deletion of the file 'C:\Program Files\Common Files\CMEII\gui\svcsap\blank.txt' requires a reboot.
[SCANMODS] WARNING: Deletion of the file 'C:\Program Files\Common Files\CMEII' requires a reboot.
Checking for 'C:\Program Files\KaZaA' in shortcut areas.
Checking for 'C:\Program Files\KaZaA' in startup areas.
Cleaning 'C:\Program Files\KaZaA'
Checking for 'C:\Program Files\KaZaA\My Shared Folder\1 - Moonshadow.mp3' in shortcut areas.
Checking for 'C:\Program Files\KaZaA\My Shared Folder\1 - Moonshadow.mp3' in startup areas.
Cleaning 'C:\Program Files\KaZaA\My Shared Folder\1 - Moonshadow.mp3'
Checking for 'C:\Program Files\KaZaA\My Shared Folder\10 Wild World.mp3' in shortcut areas.
Checking for 'C:\Program Files\KaZaA\My Shared Folder\10 Wild World.mp3' in startup areas.
Cleaning 'C:\Program Files\KaZaA\My Shared Folder\10 Wild World.mp3'
Checking for 'C:\Program Files\KaZaA\My Shared Folder\2 Pac Thugs Mansion.mp3' in shortcut areas.
Checking for 'C:\Program Files\KaZaA\My Shared Folder\2 Pac Thugs Mansion.mp3' in startup areas.
Cleaning 'C:\Program Files\KaZaA\My Shared Folder\2 Pac Thugs Mansion.mp3'
Checking for 'C:\Program Files\KaZaA\My Shared Folder\311-LoveSong.mp3' in shortcut areas.
Checking for 'C:\Program Files\KaZaA\My Shared Folder\311-LoveSong.mp3' in startup areas.
Cleaning 'C:\Program Files\KaZaA\My Shared Folder\311-LoveSong.mp3'
Checking for 'C:\Program Files\KaZaA\My Shared Folder\Boston Pops - Star Trek Theme Song.mp3' in shortcut areas.
Checking for 'C:\Program Files\KaZaA\My Shared Folder\Boston Pops - Star Trek Theme Song.mp3' in startup areas.
Cleaning 'C:\Program Files\KaZaA\My Shared Folder\Boston Pops - Star Trek Theme Song.mp3'
Checking for 'C:\Program Files\KaZaA\My Shared Folder\David Bowie - Rebel Rebel.mp3' in shortcut areas.
Checking for 'C:\Program Files\KaZaA\My Shared Folder\David Bowie - Rebel Rebel.mp3' in startup areas.
Cleaning 'C:\Program Files\KaZaA\My Shared Folder\David Bowie - Rebel Rebel.mp3'
Checking for 'C:\Program Files\KaZaA\My Shared Folder\download111492488927018828.dat' in shortcut areas.
Checking for 'C:\Program Files\KaZaA\My Shared Folder\download111492488927018828.dat' in startup areas.
Cleaning 'C:\Program Files\KaZaA\My Shared Folder\download111492488927018828.dat'
Checking for 'C:\Program Files\KaZaA\My Shared Folder\download11202572705700562.dat' in shortcut areas.
Checking for 'C:\Program Files\KaZaA\My Shared Folder\download11202572705700562.dat' in startup areas.
Cleaning 'C:\Program Files\KaZaA\My Shared Folder\download11202572705700562.dat'
Checking for 'C:\Program Files\KaZaA\My Shared Folder\download112060426228528750.dat' in shortcut areas.
Checking for 'C:\Program Files\KaZaA\My Shared Folder\download112060426228528750.dat' in startup areas.
Cleaning 'C:\Program Files\KaZaA\My Shared Folder\download112060426228528750.dat'
Checking for 'C:\Program Files\KaZaA\My Shared Folder\download112605738443052046.dat' in shortcut areas.
Checking for 'C:\Program Files\KaZaA\My Shared Folder\download112605738443052046.dat' in startup areas.
Cleaning 'C:\Program Files\KaZaA\My Shared Folder\download112605738443052046.dat'
Checking for 'C:\Program Files\KaZaA\My Shared Folder\download112605762143288875.dat' in shortcut areas.
Checking for 'C:\Program Files\KaZaA\My Shared Folder\download112605762143288875.dat' in startup areas.
Cleaning 'C:\Program Files\KaZaA\My Shared Folder\download112605762143288875.dat'
Checking for 'C:\Program Files\KaZaA\My Shared Folder\Glenn Miller I Got Rhythm 3.mp3' in shortcut areas.
Checking for 'C:\Program Files\KaZaA\My Shared Folder\Glenn Miller I Got Rhythm 3.mp3' in startup areas.
Cleaning 'C:\Program Files\KaZaA\My Shared Folder\Glenn Miller I Got Rhythm 3.mp3'
Checking for 'C:\Program Files\KaZaA\My Shared Folder\Ice T - Colors.mp3' in shortcut areas.
Checking for 'C:\Program Files\KaZaA\My Shared Folder\Ice T - Colors.mp3' in startup areas.
Cleaning 'C:\Program Files\KaZaA\My Shared Folder\Ice T - Colors.mp3'
Checking for 'C:\Program Files\KaZaA\My Shared Folder\Ice Tea - Body Count (1).mp3' in shortcut areas.
Checking for 'C:\Program Files\KaZaA\My Shared Folder\Ice Tea - Body Count (1).mp3' in startup areas.
Cleaning 'C:\Program Files\KaZaA\My Shared Folder\Ice Tea - Body Count (1).mp3'
Checking for 'C:\Program Files\KaZaA\My Shared Folder\Musicals - Josh Groban - West Side Story - Somewhere (Josh Groban and Charlotte Church Live).mp3' in shortcut areas.
Checking for 'C:\Program Files\KaZaA\My Shared Folder\Musicals - Josh Groban - West Side Story - Somewhere (Josh Groban and Charlotte Church Live).mp3' in startup areas.
Cleaning 'C:\Program Files\KaZaA\My Shared Folder\Musicals - Josh Groban - West Side Story - Somewhere (Josh Groban and Charlotte Church Live).mp3'
Checking for 'C:\Program Files\KaZaA\My Shared Folder\Neil Hamburger - Graduate of Yaoo.mp3' in shortcut areas.
Checking for 'C:\Program Files\KaZaA\My Shared Folder\Neil Hamburger - Graduate of Yaoo.mp3' in startup areas.
Cleaning 'C:\Program Files\KaZaA\My Shared Folder\Neil Hamburger - Graduate of Yaoo.mp3'
Checking for 'C:\Program Files\KaZaA\My Shared Folder\Neil Hamburger - You're Not Good Enough.mp3' in shortcut areas.
Checking for 'C:\Program Files\KaZaA\My Shared Folder\Neil Hamburger - You're Not Good Enough.mp3' in startup areas.
Cleaning 'C:\Program Files\KaZaA\My Shared Folder\Neil Hamburger - You're Not Good Enough.mp3'
Checking for 'C:\Program Files\KaZaA\My Shared Folder\NWA - Straight Outta Compton.mp3' in shortcut areas.
Checking for 'C:\Program Files\KaZaA\My Shared Folder\NWA - Straight Outta Compton.mp3' in startup areas.
Cleaning 'C:\Program Files\KaZaA\My Shared Folder\NWA - Straight Outta Compton.mp3'
Checking for 'C:\Program Files\KaZaA\My Shared Folder\The Cure - Close To Me.wav' in shortcut areas.
Checking for 'C:\Program Files\KaZaA\My Shared Folder\The Cure - Close To Me.wav' in startup areas.
Cleaning 'C:\Program Files\KaZaA\My Shared Folder\The Cure - Close To Me.wav'
Checking for 'C:\Program Files\KaZaA\My Shared Folder\The Postal Service - Such Great Heights.mp3' in shortcut areas.
Checking for 'C:\Program Files\KaZaA\My Shared Folder\The Postal Service - Such Great Heights.mp3' in startup areas.
Cleaning 'C:\Program Files\KaZaA\My Shared Folder\The Postal Service - Such Great Heights.mp3'
Checking for 'C:\Program Files\KaZaA\My Shared Folder\When i fall in love.mp3' in shortcut areas.
Checking for 'C:\Program Files\KaZaA\My Shared Folder\When i fall in love.mp3' in startup areas.
Cleaning 'C:\Program Files\KaZaA\My Shared Folder\When i fall in love.mp3'
Checking for 'C:\Program Files\KaZaA\My Shared Folder' in shortcut areas.
Checking for 'C:\Program Files\KaZaA\My Shared Folder' in startup areas.
Cleaning 'C:\Program Files\KaZaA\My Shared Folder'
[SCANMODS] The file 'C:\Program Files\KaZaA\My Shared Folder' was not found. Most likely already cleaned by another scanner module.
Checking for 'C:\Program Files\My Shared Folder\kmd171_en.exe' in shortcut areas.
Checking for 'C:\Program Files\My Shared Folder\kmd171_en.exe' in startup areas.
Cleaning 'C:\Program Files\My Shared Folder\kmd171_en.exe'
Checking for 'C:\RECYCLER\S-1-5-21-2969962186-1445258045-4160758333-1005\Dc34\kazaa.exe' in shortcut areas.
Checking for 'C:\RECYCLER\S-1-5-21-2969962186-1445258045-4160758333-1005\Dc34\kazaa.exe' in startup areas.
Cleaning 'C:\RECYCLER\S-1-5-21-2969962186-1445258045-4160758333-1005\Dc34\kazaa.exe'
Finished Cleaning
  • 0

#12
didom

didom

    Member 1K

  • Member
  • PipPipPipPip
  • 1,919 posts
Run Panda's online virus scan and perform a full system scan: Panda ActiveScan

Save the scan log and post it along with a new HijackThis Log in your next reply.
  • 0

#13
Shadout Mapes

Shadout Mapes

    New Member

  • Topic Starter
  • Member
  • Pip
  • 8 posts
Incident Status Location
Adware:adware/comedy-planet No disinfected Windows Registry


Logfile of HijackThis v1.99.1
Scan saved at 1:41:32 AM, on 10/5/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Microsoft Hardware\Keyboard\type32.exe
C:\WINDOWS\system32\ICO.EXE
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Visualware Security Suite\tscore.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINDOWS\system32\Pelmiced.exe
C:\Program Files\AIM95\aim.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\jview.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O4 - HKLM\..\Run: [ConMgr.exe] "C:\Program Files\EarthLink 5.0\ConMgr.exe"
O4 - HKLM\..\Run: [IntelliType] "C:\Program Files\Microsoft Hardware\Keyboard\type32.exe"
O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Visualware Security Suite] "C:\Program Files\Visualware Security Suite\tscore.exe" -autostartup
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.2\THGuard.exe"
O4 - HKLM\..\RunOnce: [DELDIR0.EXE] "C:\DOCUME~1\Seth\LOCALS~1\Temp\DELDIR0.EXE" "C:\Program Files\McAfee\McAfee Shared Components\Guardian\"
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM95\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE
O8 - Extra context menu item: Download with GetRight - C:\Program Files\GetRight\GRdownload.htm
O8 - Extra context menu item: LimeShop Preferences - file://C:\Program Files\LimeShop\System\Temp\limeshop_script0.htm
O8 - Extra context menu item: Open with GetRight Browser - C:\Program Files\GetRight\GRbrowse.htm
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.t...all/xscan60.cab
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnote...ad/mnviewer.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {40D61F04-59E4-4C8D-BF6E-697AB9C21F43} (InstantChess) - http://www.instantch...et/chessbar.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai...all/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoft...free/asinst.cab
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius....tiveXPlugin.cab
O16 - DPF: {BF4FC0C7-4387-4D18-AD86-DF33DDDE33C7} - http://hot.activebud...ld/websetup.cab
O16 - DPF: {EE5CA45C-BFAC-48E6-BE6C-3C607620FF43} (IMViewerControl Class) - http://companion.log...3/bin/imvid.cab
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
  • 0

#14
didom

didom

    Member 1K

  • Member
  • PipPipPipPip
  • 1,919 posts
Create a folder on your desktop called Sysclean.
Go to http://www.trendmicr...ownload/dcs.asp and download sysclean package to the folder you made.
Go to http://www.trendmicr...oad/pattern.asp and download the Official Pattern Release for windows to your desktop.
This file will be called lptXXX.zip (XXX represents the version number)
Unzip lptXXX.zip and you'll get the file lpt$vpn.XXX.
Move the lpt$vpn.XXX to that Sysclean-folder you created on your desktop.

Turn off your antivirus which is installed on your system because it can interfere with the Sysclean-scan.

Open the sysclean-folder and doubleclick sysclean.com.
Check: Automatically clean or delete detected files.
Click scan.
When the scan is finished, open your sysclean-folder and copy and paste the contents of sysclean.log in your next reply.
  • 0

#15
Shadout Mapes

Shadout Mapes

    New Member

  • Topic Starter
  • Member
  • Pip
  • 8 posts
/--------------------------------------------------------------\
| Trend Micro Sysclean Package |
| Copyright 2002, Trend Micro, Inc. |
| http://www.trendmicro.com |
\--------------------------------------------------------------/


2005-10-06, 16:31:27, Auto-clean mode specified.
2005-10-06, 16:31:27, Running scanner "C:\Documents and Settings\Seth\Desktop\sysclean\TSC.BIN"...
2005-10-06, 16:31:41, Scanner "C:\Documents and Settings\Seth\Desktop\sysclean\TSC.BIN" has finished running.
2005-10-06, 16:31:41, TSC Log:

Damage Cleanup Engine (DCE) 3.9(Build 1020)
Windows XP(Build 2600: Service Pack 2)

Start time : Thu Oct 06 2005 16:31:27

Load Damage Cleanup Template (DCT) "C:\Documents and Settings\Seth\Desktop\sysclean\tsc.ptn" (version 660) [success]

Complete time : Thu Oct 06 2005 16:31:41
Execute pattern count(4419), Virus found count(0), Virus clean count(0), Clean failed count(0)

2005-10-06, 16:33:53, Could not set file for reading on "C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\517ada203c94d1987426abc536917ded_8bb36488-858f-4e76-884d-a818f90e4cef": Access is denied.
2005-10-06, 16:33:58, Could not set file for reading on "C:\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson\user.dmp": Access is denied.
2005-10-06, 16:36:46, An error was detected on "C:\Documents and Settings\John\*.*": Access is denied.
2005-10-06, 16:37:18, An error occurred while scanning file "C:\Documents and Settings\LocalService\NTUSER.DAT": Access is denied.
2005-10-06, 16:37:18, An error occurred while scanning file "C:\Documents and Settings\LocalService\ntuser.dat.LOG": Access is denied.
2005-10-06, 16:37:18, An error occurred while scanning file "C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat": Access is denied.
2005-10-06, 16:37:18, An error occurred while scanning file "C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG": Access is denied.
2005-10-06, 16:37:19, An error occurred while scanning file "C:\Documents and Settings\NetworkService\NTUSER.DAT": Access is denied.
2005-10-06, 16:37:19, An error occurred while scanning file "C:\Documents and Settings\NetworkService\ntuser.dat.LOG": Access is denied.
2005-10-06, 16:37:19, An error occurred while scanning file "C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat": Access is denied.
2005-10-06, 16:37:19, An error occurred while scanning file "C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG": Access is denied.
2005-10-06, 16:37:23, An error occurred while scanning file "C:\Documents and Settings\Seth\NTUSER.DAT": Access is denied.
2005-10-06, 16:37:23, An error occurred while scanning file "C:\Documents and Settings\Seth\ntuser.dat.LOG": Access is denied.
2005-10-06, 16:38:37, An error occurred while scanning file "C:\Documents and Settings\Seth\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat": Access is denied.
2005-10-06, 16:38:37, An error occurred while scanning file "C:\Documents and Settings\Seth\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG": Access is denied.
2005-10-06, 16:48:56, An error was detected on "C:\Documents and Settings\Tara\*.*": Access is denied.
2005-10-06, 16:49:21, Could not set file for reading on "C:\Drivers\SonyUSB\sonyhc.cat": Access is denied.
2005-10-06, 16:49:21, Could not set file for reading on "C:\Drivers\SonyUSB\sonyhc2kdisk.inf": Access is denied.
2005-10-06, 16:49:21, Could not set file for reading on "C:\Drivers\SonyUSB\sonyhcaudio2k.inf": Access is denied.
2005-10-06, 16:49:21, Could not set file for reading on "C:\Drivers\SonyUSB\sonyhcusb2k.inf": Access is denied.
2005-10-06, 16:52:04, An error was detected on "C:\Program Files\Common Files\CMEII\gui\svcsap\*.*": Access is denied.
2005-10-06, 16:59:12, Could not set file for reading on "C:\RECYCLER\S-1-5-21-2969962186-1445258045-4160758333-1006\Dc13.tdb": Access is denied.
2005-10-06, 16:59:12, Could not set file for reading on "C:\RECYCLER\S-1-5-21-2969962186-1445258045-4160758333-1006\Dc14.tdb": Access is denied.
2005-10-06, 16:59:12, Could not set file for reading on "C:\RECYCLER\S-1-5-21-2969962186-1445258045-4160758333-1006\Dc15.tdb": Access is denied.
2005-10-06, 16:59:12, Could not set file for reading on "C:\RECYCLER\S-1-5-21-2969962186-1445258045-4160758333-1006\Dc16.tdb": Access is denied.
2005-10-06, 16:59:12, Could not set file for reading on "C:\RECYCLER\S-1-5-21-2969962186-1445258045-4160758333-1006\Dc17.tdb": Access is denied.
2005-10-06, 16:59:12, Could not set file for reading on "C:\RECYCLER\S-1-5-21-2969962186-1445258045-4160758333-1006\Dc18.tdb": Access is denied.
2005-10-06, 16:59:12, Could not set file for reading on "C:\RECYCLER\S-1-5-21-2969962186-1445258045-4160758333-1006\Dc19.tdb": Access is denied.
2005-10-06, 16:59:12, Could not set file for reading on "C:\RECYCLER\S-1-5-21-2969962186-1445258045-4160758333-1006\Dc20.tdb": Access is denied.
2005-10-06, 16:59:12, Could not set file for reading on "C:\RECYCLER\S-1-5-21-2969962186-1445258045-4160758333-1006\Dc21.ddb": Access is denied.
2005-10-06, 16:59:12, An error was detected on "C:\RECYCLER\S-1-5-21-2969962186-1445258045-4160758333-1006\Dc22\*.*": Access is denied.
2005-10-06, 17:05:31, An error was detected on "C:\System Volume Information\*.*": Access is denied.
2005-10-06, 17:07:52, Could not set file for reading on "C:\WINDOWS\$NtUninstallQ308387$\autolfn.exe": Access is denied.
2005-10-06, 17:07:52, Could not set file for reading on "C:\WINDOWS\$NtUninstallQ308387$\spuninst\spuninst.exe": Access is denied.
2005-10-06, 17:07:52, Could not set file for reading on "C:\WINDOWS\$NtUninstallQ308387$\spuninst\spuninst.inf": Access is denied.
2005-10-06, 17:07:52, Could not set file for reading on "C:\WINDOWS\$NtUninstallQ308677$\userenv.dll": Access is denied.
2005-10-06, 17:07:52, Could not set file for reading on "C:\WINDOWS\$NtUninstallQ308677$\spuninst\spuninst.exe": Access is denied.
2005-10-06, 17:07:52, Could not set file for reading on "C:\WINDOWS\$NtUninstallQ308677$\spuninst\spuninst.inf": Access is denied.
2005-10-06, 17:07:52, Could not set file for reading on "C:\WINDOWS\$NtUninstallQ311889$\termsrv.dll": Access is denied.
2005-10-06, 17:07:52, Could not set file for reading on "C:\WINDOWS\$NtUninstallQ311889$\spuninst\spuninst.exe": Access is denied.
2005-10-06, 17:07:52, Could not set file for reading on "C:\WINDOWS\$NtUninstallQ311889$\spuninst\spuninst.inf": Access is denied.
2005-10-06, 17:07:52, Could not set file for reading on "C:\WINDOWS\$NtUninstallQ312368$\syssetup.dll": Access is denied.
2005-10-06, 17:07:52, Could not set file for reading on "C:\WINDOWS\$NtUninstallQ312368$\spuninst\spuninst.exe": Access is denied.
2005-10-06, 17:07:52, Could not set file for reading on "C:\WINDOWS\$NtUninstallQ312368$\spuninst\spuninst.inf": Access is denied.
2005-10-06, 17:07:53, Could not set file for reading on "C:\WINDOWS\$NtUninstallQ314293$\usbohci.sys": Access is denied.
2005-10-06, 17:07:53, Could not set file for reading on "C:\WINDOWS\$NtUninstallQ314293$\spuninst\spuninst.exe": Access is denied.
2005-10-06, 17:07:53, Could not set file for reading on "C:\WINDOWS\$NtUninstallQ314293$\spuninst\spuninst.inf": Access is denied.
2005-10-06, 17:07:53, Could not set file for reading on "C:\WINDOWS\$NtUninstallQ315000$\netsetup.exe": Access is denied.
2005-10-06, 17:07:53, Could not set file for reading on "C:\WINDOWS\$NtUninstallQ315000$\ssdpapi.dll": Access is denied.
2005-10-06, 17:07:53, Could not set file for reading on "C:\WINDOWS\$NtUninstallQ315000$\ssdpsrv.dll": Access is denied.
2005-10-06, 17:07:53, Could not set file for reading on "C:\WINDOWS\$NtUninstallQ315000$\upnp.dll": Access is denied.
2005-10-06, 17:07:53, Could not set file for reading on "C:\WINDOWS\$NtUninstallQ315000$\spuninst\spuninst.exe": Access is denied.
2005-10-06, 17:07:53, Could not set file for reading on "C:\WINDOWS\$NtUninstallQ315000$\spuninst\spuninst.inf": Access is denied.
2005-10-06, 17:10:47, Could not set file for reading on "C:\WINDOWS\Prefetch\ACRORD32.EXE-20C463C1.pf": Access is denied.
2005-10-06, 17:10:47, Could not set file for reading on "C:\WINDOWS\Prefetch\ADOBE GAMMA LOADER.EXE-1DBD7BA3.pf": Access is denied.
2005-10-06, 17:10:47, Could not set file for reading on "C:\WINDOWS\Prefetch\AIM.EXE-16BDDDF3.pf": Access is denied.
2005-10-06, 17:10:47, Could not set file for reading on "C:\WINDOWS\Prefetch\ALOGSERV.EXE-00FDB330.pf": Access is denied.
2005-10-06, 17:10:47, Could not set file for reading on "C:\WINDOWS\Prefetch\AMAZING.EXE-24725BE9.pf": Access is denied.
2005-10-06, 17:10:47, Could not set file for reading on "C:\WINDOWS\Prefetch\AUPATCH.DAT-0400B02D.pf": Access is denied.
2005-10-06, 17:10:47, Could not set file for reading on "C:\WINDOWS\Prefetch\AUUNZIP.DAT-282D0C3F.pf": Access is denied.
2005-10-06, 17:10:47, Could not set file for reading on "C:\WINDOWS\Prefetch\AUUPDATE.DAT-2BA1E7A6.pf": Access is denied.
2005-10-06, 17:10:47, Could not set file for reading on "C:\WINDOWS\Prefetch\AVCONSOL.EXE-2009B46B.pf": Access is denied.
2005-10-06, 17:10:47, Could not set file for reading on "C:\WINDOWS\Prefetch\CALC.EXE-02CD573A.pf": Access is denied.
2005-10-06, 17:10:47, Could not set file for reading on "C:\WINDOWS\Prefetch\CLEANMGR.EXE-1F86EA8E.pf": Access is denied.
2005-10-06, 17:10:47, Could not set file for reading on "C:\WINDOWS\Prefetch\CLEANUP.EXE-1B0F5664.pf": Access is denied.
2005-10-06, 17:10:47, Could not set file for reading on "C:\WINDOWS\Prefetch\CMD.EXE-087B4001.pf": Access is denied.
2005-10-06, 17:10:47, Could not set file for reading on "C:\WINDOWS\Prefetch\CONTROL.EXE-013DBFB5.pf": Access is denied.
2005-10-06, 17:10:47, Could not set file for reading on "C:\WINDOWS\Prefetch\CPD.EXE-1ABCD154.pf": Access is denied.
2005-10-06, 17:10:47, Could not set file for reading on "C:\WINDOWS\Prefetch\CWSHREDDER.EXE-02ADA3BC.pf": Access is denied.
2005-10-06, 17:10:47, Could not set file for reading on "C:\WINDOWS\Prefetch\DEFRAG.EXE-273F131E.pf": Access is denied.
2005-10-06, 17:10:47, Could not set file for reading on "C:\WINDOWS\Prefetch\DFRGNTFS.EXE-269967DF.pf": Access is denied.
2005-10-06, 17:10:47, Could not set file for reading on "C:\WINDOWS\Prefetch\DRWTSN32.EXE-2B4B52AC.pf": Access is denied.
2005-10-06, 17:10:47, Could not set file for reading on "C:\WINDOWS\Prefetch\DUMPREP.EXE-1B46F901.pf": Access is denied.
2005-10-06, 17:10:47, Could not set file for reading on "C:\WINDOWS\Prefetch\DWWIN.EXE-30875ADC.pf": Access is denied.
2005-10-06, 17:10:47, Could not set file for reading on "C:\WINDOWS\Prefetch\ERQFYJFY.EXE-03DF259B.pf": Access is denied.
2005-10-06, 17:10:47, Could not set file for reading on "C:\WINDOWS\Prefetch\EWIDO-SETUP[1].EXE-2EC6971F.pf": Access is denied.
2005-10-06, 17:10:47, Could not set file for reading on "C:\WINDOWS\Prefetch\EWIDOCTRL.EXE-32A93A8D.pf": Access is denied.
2005-10-06, 17:10:47, Could not set file for reading on "C:\WINDOWS\Prefetch\EXCEL.EXE-1C75F8D6.pf": Access is denied.
2005-10-06, 17:10:47, Could not set file for reading on "C:\WINDOWS\Prefetch\EXPLORER.EXE-082F38A9.pf": Access is denied.
2005-10-06, 17:10:47, Could not set file for reading on "C:\WINDOWS\Prefetch\E_SRCV02.EXE-38296430.pf": Access is denied.
2005-10-06, 17:10:47, Could not set file for reading on "C:\WINDOWS\Prefetch\FINDFAST.EXE-201E95F4.pf": Access is denied.
2005-10-06, 17:10:47, Could not set file for reading on "C:\WINDOWS\Prefetch\GRPCONV.EXE-111CD845.pf": Access is denied.
2005-10-06, 17:10:47, Could not set file for reading on "C:\WINDOWS\Prefetch\HELPCTR.EXE-3862B6F5.pf": Access is denied.
2005-10-06, 17:10:47, Could not set file for reading on "C:\WINDOWS\Prefetch\HELPHOST.EXE-247D2792.pf": Access is denied.
2005-10-06, 17:10:47, Could not set file for reading on "C:\WINDOWS\Prefetch\HELPSVC.EXE-2878DDA2.pf": Access is denied.
2005-10-06, 17:10:47, Could not set file for reading on "C:\WINDOWS\Prefetch\HIJACKTHIS.EXE-0F150040.pf": Access is denied.
2005-10-06, 17:10:47, Could not set file for reading on "C:\WINDOWS\Prefetch\HIJACKTHIS.EXE-2AF68D7A.pf": Access is denied.
2005-10-06, 17:10:47, Could not set file for reading on "C:\WINDOWS\Prefetch\ICO.EXE-2A655EB7.pf": Access is denied.
2005-10-06, 17:10:47, Could not set file for reading on "C:\WINDOWS\Prefetch\IDRIVER.EXE-3B6DD980.pf": Access is denied.
2005-10-06, 17:10:47, Could not set file for reading on "C:\WINDOWS\Prefetch\IEDW.EXE-1880380E.pf": Access is denied.
2005-10-06, 17:10:47, Could not set file for reading on "C:\WINDOWS\Prefetch\IEXPLORE.EXE-27122324.pf": Access is denied.
2005-10-06, 17:10:47, Could not set file for reading on "C:\WINDOWS\Prefetch\IMAPI.EXE-0BF740A4.pf": Access is denied.
2005-10-06, 17:10:47, Could not set file for reading on "C:\WINDOWS\Prefetch\INSTTIMEUPDATER.EXE-02D71536.pf": Access is denied.
2005-10-06, 17:10:47, Could not set file for reading on "C:\WINDOWS\Prefetch\IPODSERVICE.EXE-3192DE38.pf": Access is denied.
2005-10-06, 17:10:47, Could not set file for reading on "C:\WINDOWS\Prefetch\IS-53R05.TMP-2823BC0B.pf": Access is denied.
2005-10-06, 17:10:47, Could not set file for reading on "C:\WINDOWS\Prefetch\IS-72LCK.TMP-2925C5CD.pf": Access is denied.
2005-10-06, 17:10:47, Could not set file for reading on "C:\WINDOWS\Prefetch\ITUNES.EXE-1A268432.pf": Access is denied.
2005-10-06, 17:10:47, Could not set file for reading on "C:\WINDOWS\Prefetch\ITUNESHELPER.EXE-15823303.pf": Access is denied.
2005-10-06, 17:10:47, Could not set file for reading on "C:\WINDOWS\Prefetch\JVIEW.EXE-3B678988.pf": Access is denied.
2005-10-06, 17:10:47, Could not set file for reading on "C:\WINDOWS\Prefetch\Layout.ini": Access is denied.
2005-10-06, 17:10:47, Could not set file for reading on "C:\WINDOWS\Prefetch\LOGON.SCR-151EFAEA.pf": Access is denied.
2005-10-06, 17:10:47, Could not set file for reading on "C:\WINDOWS\Prefetch\LOGONUI.EXE-0AF22957.pf": Access is denied.
2005-10-06, 17:10:47, Could not set file for reading on "C:\WINDOWS\Prefetch\MAPISP32.EXE-1A7449A4.pf": Access is denied.
2005-10-06, 17:10:47, Could not set file for reading on "C:\WINDOWS\Prefetch\MSHTA.EXE-331DF029.pf": Access is denied.
2005-10-06, 17:10:47, Could not set file for reading on "C:\WINDOWS\Prefetch\MSI10.TMP-361B9A6A.pf": Access is denied.
2005-10-06, 17:10:47, Could not set file for reading on "C:\WINDOWS\Prefetch\MSI11.TMP-03AFF3D6.pf": Access is denied.
2005-10-06, 17:10:47, Could not set file for reading on "C:\WINDOWS\Prefetch\MSIEXEC.EXE-2F8A8CAE.pf": Access is denied.
2005-10-06, 17:10:47, Could not set file for reading on "C:\WINDOWS\Prefetch\MSIF.TMP-31ACFBC2.pf": Access is denied.
2005-10-06, 17:10:47, Could not set file for reading on "C:\WINDOWS\Prefetch\MSMSGS.EXE-2B6052DE.pf": Access is denied.
2005-10-06, 17:10:47, Could not set file for reading on "C:\WINDOWS\Prefetch\MSPAINT.EXE-11CBB631.pf": Access is denied.
2005-10-06, 17:10:47, Could not set file for reading on "C:\WINDOWS\Prefetch\NESTEN.EXE-35392B31.pf": Access is denied.
2005-10-06, 17:10:48, Could not set file for reading on "C:\WINDOWS\Prefetch\NOTEPAD.EXE-336351A9.pf": Access is denied.
2005-10-06, 17:10:48, Could not set file for reading on "C:\WINDOWS\Prefetch\NTOSBOOT-B00DFAAD.pf": Access is denied.
2005-10-06, 17:10:48, Could not set file for reading on "C:\WINDOWS\Prefetch\OGGCODECS_0.69.8924[1].EXE-369E467B.pf": Access is denied.
2005-10-06, 17:10:48, Could not set file for reading on "C:\WINDOWS\Prefetch\OSA.EXE-33CE5E8A.pf": Access is denied.
2005-10-06, 17:10:48, Could not set file for reading on "C:\WINDOWS\Prefetch\PATCH.EXE-1DE617D3.pf": Access is denied.
2005-10-06, 17:10:48, Could not set file for reading on "C:\WINDOWS\Prefetch\PELMICED.EXE-0F6C2BE0.pf": Access is denied.
2005-10-06, 17:10:48, Could not set file for reading on "C:\WINDOWS\Prefetch\POKAPOKA70.EXE-2F30B5EF.pf": Access is denied.
2005-10-06, 17:10:48, Could not set file for reading on "C:\WINDOWS\Prefetch\POWERPNT.EXE-17CE3F4E.pf": Access is denied.
2005-10-06, 17:10:48, Could not set file for reading on "C:\WINDOWS\Prefetch\QTTASK.EXE-342507FB.pf": Access is denied.
2005-10-06, 17:10:48, Could not set file for reading on "C:\WINDOWS\Prefetch\REALPLAY.EXE-1BF219BD.pf": Access is denied.
2005-10-06, 17:10:48, Could not set file for reading on "C:\WINDOWS\Prefetch\REALSCHED.EXE-3282FD31.pf": Access is denied.
2005-10-06, 17:10:48, Could not set file for reading on "C:\WINDOWS\Prefetch\REGDLL.EXE-08EDA35D.pf": Access is denied.
2005-10-06, 17:10:48, Could not set file for reading on "C:\WINDOWS\Prefetch\REGEDIT.EXE-1B606482.pf": Access is denied.
2005-10-06, 17:10:48, Could not set file for reading on "C:\WINDOWS\Prefetch\REGSVR32.EXE-25EEFE2F.pf": Access is denied.
2005-10-06, 17:10:48, Could not set file for reading on "C:\WINDOWS\Prefetch\RUNDLL32.EXE-13CC3015.pf": Access is denied.
2005-10-06, 17:10:48, Could not set file for reading on "C:\WINDOWS\Prefetch\RUNDLL32.EXE-1831A4F3.pf": Access is denied.
2005-10-06, 17:10:48, Could not set file for reading on "C:\WINDOWS\Prefetch\RUNDLL32.EXE-2CD85FD3.pf": Access is denied.
2005-10-06, 17:10:48, Could not set file for reading on "C:\WINDOWS\Prefetch\RUNDLL32.EXE-451FC2C0.pf": Access is denied.
2005-10-06, 17:10:48, Could not set file for reading on "C:\WINDOWS\Prefetch\RUNDLL32.EXE-487B646E.pf": Access is denied.
2005-10-06, 17:10:48, Could not set file for reading on "C:\WINDOWS\Prefetch\RUNDLL32.EXE-4B5B5B9E.pf": Access is denied.
2005-10-06, 17:10:48, Could not set file for reading on "C:\WINDOWS\Prefetch\RUNONCE.EXE-2803F297.pf": Access is denied.
2005-10-06, 17:10:48, Could not set file for reading on "C:\WINDOWS\Prefetch\SC.EXE-012262AF.pf": Access is denied.
2005-10-06, 17:10:48, Could not set file for reading on "C:\WINDOWS\Prefetch\SECURITYSUITE.EXE-2F8634CB.pf": Access is denied.
2005-10-06, 17:10:48, Could not set file for reading on "C:\WINDOWS\Prefetch\SETUP.EXE-01FC6DB9.pf": Access is denied.
2005-10-06, 17:10:48, Could not set file for reading on "C:\WINDOWS\Prefetch\SETUP_WM.EXE-3135CBD6.pf": Access is denied.
2005-10-06, 17:10:48, Could not set file for reading on "C:\WINDOWS\Prefetch\SPYBOTSD.EXE-1344276B.pf": Access is denied.
2005-10-06, 17:10:48, Could not set file for reading on "C:\WINDOWS\Prefetch\SPYBOTSD14[1].EXE-325D5AF1.pf": Access is denied.
2005-10-06, 17:10:48, Could not set file for reading on "C:\WINDOWS\Prefetch\SPYBOTSD_INCLUDES.EXE-132116C6.pf": Access is denied.
2005-10-06, 17:10:48, Could not set file for reading on "C:\WINDOWS\Prefetch\SSSTARS.SCR-2D6FC20D.pf": Access is denied.
2005-10-06, 17:10:48, Could not set file for reading on "C:\WINDOWS\Prefetch\SYSCLEAN.COM-34425DDC.pf": Access is denied.
2005-10-06, 17:10:48, Could not set file for reading on "C:\WINDOWS\Prefetch\SYSCLEAN.EXE-21862912.pf": Access is denied.
2005-10-06, 17:10:48, Could not set file for reading on "C:\WINDOWS\Prefetch\TABIT.EXE-03072D3F.pf": Access is denied.
2005-10-06, 17:10:48, Could not set file for reading on "C:\WINDOWS\Prefetch\TASKMGR.EXE-20256C55.pf": Access is denied.
2005-10-06, 17:10:48, Could not set file for reading on "C:\WINDOWS\Prefetch\TCVCDTJG.EXE-10546576.pf": Access is denied.
2005-10-06, 17:10:48, Could not set file for reading on "C:\WINDOWS\Prefetch\THGUARD.EXE-1F492078.pf": Access is denied.
2005-10-06, 17:10:48, Could not set file for reading on "C:\WINDOWS\Prefetch\TMAS-WEB-SCAN.EXE-269CFF58.pf": Access is denied.
2005-10-06, 17:10:48, Could not set file for reading on "C:\WINDOWS\Prefetch\TROJANHUNTER.EXE-2953146E.pf": Access is denied.
2005-10-06, 17:10:48, Could not set file for reading on "C:\WINDOWS\Prefetch\TROJANHUNTER[1].EXE-1F09DF4B.pf": Access is denied.
2005-10-06, 17:10:48, Could not set file for reading on "C:\WINDOWS\Prefetch\TSC.BIN-1339DC72.pf": Access is denied.
2005-10-06, 17:10:48, Could not set file for reading on "C:\WINDOWS\Prefetch\TSC.EXE-2B4C0858.pf": Access is denied.
2005-10-06, 17:10:48, Could not set file for reading on "C:\WINDOWS\Prefetch\TSCORE.EXE-3755FFB0.pf": Access is denied.
2005-10-06, 17:10:48, Could not set file for reading on "C:\WINDOWS\Prefetch\TVMCLN.EXE-29D241F3.pf": Access is denied.
2005-10-06, 17:10:48, Could not set file for reading on "C:\WINDOWS\Prefetch\TYPE32.EXE-281B80FA.pf": Access is denied.
2005-10-06, 17:10:48, Could not set file for reading on "C:\WINDOWS\Prefetch\USERINIT.EXE-30B18140.pf": Access is denied.
2005-10-06, 17:10:48, Could not set file for reading on "C:\WINDOWS\Prefetch\VIEWMGR.EXE-1E800BBC.pf": Access is denied.
2005-10-06, 17:10:48, Could not set file for reading on "C:\WINDOWS\Prefetch\VISUALIPTRACE.EXE-050F298B.pf": Access is denied.
2005-10-06, 17:10:48, Could not set file for reading on "C:\WINDOWS\Prefetch\VSSTAT.EXE-270F4533.pf": Access is denied.
2005-10-06, 17:10:48, Could not set file for reading on "C:\WINDOWS\Prefetch\WATGNWNF.EXE-195A3DA0.pf": Access is denied.
2005-10-06, 17:10:48, Could not set file for reading on "C:\WINDOWS\Prefetch\WGAINSTALL.EXE-2554CF47.pf": Access is denied.
2005-10-06, 17:10:48, Could not set file for reading on "C:\WINDOWS\Prefetch\WINDOWS-KB886590-ENU-V1.1[1].-32AE57F8.pf": Access is denied.
2005-10-06, 17:10:48, Could not set file for reading on "C:\WINDOWS\Prefetch\WINHLP32.EXE-2C18E975.pf": Access is denied.
2005-10-06, 17:10:48, Could not set file for reading on "C:\WINDOWS\Prefetch\WINWORD.EXE-10D55173.pf": Access is denied.
2005-10-06, 17:10:48, Could not set file for reading on "C:\WINDOWS\Prefetch\WINZIP32.EXE-335422C1.pf": Access is denied.
2005-10-06, 17:10:48, Could not set file for reading on "C:\WINDOWS\Prefetch\WMIPRVSE.EXE-28F301A9.pf": Access is denied.
2005-10-06, 17:10:48, Could not set file for reading on "C:\WINDOWS\Prefetch\WMPLAYER.EXE-18DDEF9C.pf": Access is denied.
2005-10-06, 17:10:48, Could not set file for reading on "C:\WINDOWS\Prefetch\WMPLAYER.EXE-18DDEF9D.pf": Access is denied.
2005-10-06, 17:10:48, Could not set file for reading on "C:\WINDOWS\Prefetch\WMPLAYER.EXE-18DDEF9F.pf": Access is denied.
2005-10-06, 17:10:48, Could not set file for reading on "C:\WINDOWS\Prefetch\WMPLAYER.EXE-18DDEFA1.pf": Access is denied.
2005-10-06, 17:10:48, Could not set file for reading on "C:\WINDOWS\Prefetch\WMPLAYER.EXE-18DDEFA2.pf": Access is denied.
2005-10-06, 17:10:48, Could not set file for reading on "C:\WINDOWS\Prefetch\WMPLAYER.EXE-18DDEFA3.pf": Access is denied.
2005-10-06, 17:10:48, Could not set file for reading on "C:\WINDOWS\Prefetch\WMPLAYER.EXE-18DDEFA6.pf": Access is denied.
2005-10-06, 17:10:48, Could not set file for reading on "C:\WINDOWS\Prefetch\WSCNTFY.EXE-1B24F5EB.pf": Access is denied.
2005-10-06, 17:10:48, Could not set file for reading on "C:\WINDOWS\Prefetch\WUAUCLT.EXE-399A8E72.pf": Access is denied.
2005-10-06, 17:13:31, Could not set file for reading on "C:\WINDOWS\system32\SONYHCY.DLL": Access is denied.
2005-10-06, 17:13:52, An error occurred while scanning file "C:\WINDOWS\system32\config\default": Access is denied.
2005-10-06, 17:13:52, An error occurred while scanning file "C:\WINDOWS\system32\config\default.LOG": Access is denied.
2005-10-06, 17:13:52, An error occurred while scanning file "C:\WINDOWS\system32\config\SAM": Access is denied.
2005-10-06, 17:13:52, An error occurred while scanning file "C:\WINDOWS\system32\config\SAM.LOG": Access is denied.
2005-10-06, 17:13:52, An error occurred while scanning file "C:\WINDOWS\system32\config\SECURITY": Access is denied.
2005-10-06, 17:13:52, An error occurred while scanning file "C:\WINDOWS\system32\config\SECURITY.LOG": Access is denied.
2005-10-06, 17:13:52, An error occurred while scanning file "C:\WINDOWS\system32\config\software": Access is denied.
2005-10-06, 17:13:52, An error occurred while scanning file "C:\WINDOWS\system32\config\software.LOG": Access is denied.
2005-10-06, 17:13:52, An error occurred while scanning file "C:\WINDOWS\system32\config\system": Access is denied.
2005-10-06, 17:13:52, An error occurred while scanning file "C:\WINDOWS\system32\config\system.LOG": Access is denied.
2005-10-06, 17:14:56, Could not set file for reading on "C:\WINDOWS\system32\drivers\sonyhcb.sys": Access is denied.
2005-10-06, 17:14:56, Could not set file for reading on "C:\WINDOWS\system32\drivers\sonyhcc.sys": Access is denied.
2005-10-06, 17:14:56, Could not set file for reading on "C:\WINDOWS\system32\drivers\Sonyhcp.dll": Access is denied.
2005-10-06, 17:14:56, Could not set file for reading on "C:\WINDOWS\system32\drivers\sonyhcs.sys": Access is denied.
2005-10-06, 17:15:27, Running scanner "C:\Documents and Settings\Seth\Desktop\sysclean\VSCANTM.BIN"...
2005-10-06, 17:52:25, Files Detected:
Copyright © 1990 - 2004 Trend Micro Inc.
Report Date : 10/6/2005 17:15:28
VSAPI Engine Version : 7.510-1002
VSCANTM Version : 1.1-1001
Virus Pattern Version : 879 (109716 Patterns) (2005/10/06) (287900)
Command Line: C:\Documents and Settings\Seth\Desktop\sysclean\VSCANTM.BIN /NBPM /S /CLEANALL /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 C:\*.* /P=C:\Documents and Settings\Seth\Desktop\sysclean

68776 files have been read.
68776 files have been checked.
54052 files have been scanned.
88513 files have been scanned. (including files in archived)
0 files containing viruses.
Found 0 viruses totally.
Maybe 0 viruses totally.
Stop At : 10/6/2005 17:52:24
---------*---------*---------*---------*---------*---------*---------*---------*
2005-10-06, 17:52:25, Files Clean:
Copyright © 1990 - 2004 Trend Micro Inc.
Report Date : 10/6/2005 17:15:28
VSAPI Engine Version : 7.510-1002
VSCANTM Version : 1.1-1001
Virus Pattern Version : 879 (109716 Patterns) (2005/10/06) (287900)
Command Line: C:\Documents and Settings\Seth\Desktop\sysclean\VSCANTM.BIN /NBPM /S /CLEANALL /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 C:\*.* /P=C:\Documents and Settings\Seth\Desktop\sysclean

68776 files have been read.
68776 files have been checked.
54052 files have been scanned.
88513 files have been scanned. (including files in archived)
0 files containing viruses.
Found 0 viruses totally.
Maybe 0 viruses totally.
Stop At : 10/6/2005 17:52:24 36 minutes 54 seconds (2214.94 seconds) has elapsed.

---------*---------*---------*---------*---------*---------*---------*---------*
2005-10-06, 17:52:25, Clean Fail:
Copyright © 1990 - 2004 Trend Micro Inc.
Report Date : 10/6/2005 17:15:28
VSAPI Engine Version : 7.510-1002
VSCANTM Version : 1.1-1001
Virus Pattern Version : 879 (109716 Patterns) (2005/10/06) (287900)
Command Line: C:\Documents and Settings\Seth\Desktop\sysclean\VSCANTM.BIN /NBPM /S /CLEANALL /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 C:\*.* /P=C:\Documents and Settings\Seth\Desktop\sysclean

68776 files have been read.
68776 files have been checked.
54052 files have been scanned.
88513 files have been scanned. (including files in archived)
0 files containing viruses.
Found 0 viruses totally.
Maybe 0 viruses totally.
Stop At : 10/6/2005 17:52:24 36 minutes 54 seconds (2214.94 seconds) has elapsed.

---------*---------*---------*---------*---------*---------*---------*---------*
2005-10-06, 17:52:25, Scanner "C:\Documents and Settings\Seth\Desktop\sysclean\VSCANTM.BIN" has finished running.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP