Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

msclock32.dll [CLOSED]


  • This topic is locked This topic is locked

#1
modi5mind

modi5mind

    New Member

  • Member
  • Pip
  • 6 posts
This is my logfile, l tried deleting msclock32.dll with AntiVir but without luck, l downloaded yahoo toolbar to block the PUP, what a waste of time, l tried Ad annihilator, the same problem. I have my little brother who 11 years who uses my pc to do work, this pornographic PUP isn't appropriate, plz help

Logfile of HijackThis v1.99.1
Scan saved at 11:36:54 PM, on 10/7/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AVPersonal\AVGUARD.EXE
C:\Program Files\Executive Software\DiskeeperLite\DKService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\ups.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\VIAudioi\SBADeck\ADeck.exe
C:\WINDOWS\System32\VTTimer.exe
C:\Program Files\Classic PhoneTools\CapFax.EXE
C:\Program Files\ahead\InCD\InCD.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\AVPersonal\AVGNT.EXE
C:\windows\system32\yrkcnh.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\Program Files\Microsoft Office\Office\OSA.EXE
C:\Program Files\Microsoft Office\Office10\msoffice.exe
C:\Program Files\HijackThis.exe

O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_6_0_0.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Ad Annihilator Kernel - {D880FC15-AF5D-4929-9FB5-F06D01CDF70C} - C:\PROGRA~1\ADANNI~1\ADANNI~1.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_6_0_0.dll
O3 - Toolbar: &Ad Annihilator - {B2A8E0D7-5764-433D-A89B-2332B9D9BE00} - C:\PROGRA~1\ADANNI~1\ADANNI~1.DLL
O4 - HKLM\..\Run: [AudioDeck] C:\Program Files\VIAudioi\SBADeck\ADeck.exe
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [CapFax] C:\Program Files\Classic PhoneTools\CapFax.EXE
O4 - HKLM\..\Run: [CorelDRAW Graphics Suite 11b] C:\Program Files\Corel\Corel Graphics 12\Languages\EN\Programs\Registration.exe /title="CorelDRAW Graphics Suite 12" /date=102105 serial=DR12CUS-5188071-KJB lang=EN
O4 - HKLM\..\Run: [InCD] C:\Program Files\ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AnyDVD] C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [AVGCtrl] C:\Program Files\AVPersonal\AVGNT.EXE /min
O4 - HKLM\..\Run: [yrkcnh] c:\windows\system32\yrkcnh.exe -start
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - Startup: Ad-Watch SE Plus.lnk = C:\Program Files\Lavasoft\Ad-Aware SE Plus\Ad-Watch.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
O8 - Extra context menu item: + &Download Express: download this file - C:\Program Files\Download Express\Add_Url.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: [Add to organizer] - res://C:\Program Files\Ad Annihilator\AdAnnihilator.dll/3250
O8 - Extra context menu item: [Block this banner] Ctrl+Alt+B - res://C:\Program Files\Ad Annihilator\AdAnnihilator.dll/3245
O8 - Extra context menu item: [Block this popup] Ctrl+Alt+K - res://C:\Program Files\Ad Annihilator\AdAnnihilator.dll/3256
O8 - Extra context menu item: [Find blocking filter] Ctrl+Alt+F - res://C:\Program Files\Ad Annihilator\AdAnnihilator.dll/3254
O8 - Extra context menu item: [Find this resource in resource list] Ctrl+Alt+L - res://C:\Program Files\Ad Annihilator\AdAnnihilator.dll/3253
O8 - Extra context menu item: [Locate target document] - res://C:\Program Files\Ad Annihilator\AdAnnihilator.dll/3255
O8 - Extra context menu item: [Open all links] - res://C:\Program Files\Ad Annihilator\AdAnnihilator.dll/3247
O8 - Extra context menu item: [Resume resource loading] Ctrl+Alt+R - res://C:\Program Files\Ad Annihilator\AdAnnihilator.dll/3251
O8 - Extra context menu item: [Show/hide menu and toolbars] Ctrl+Alt+M - res://C:\Program Files\Ad Annihilator\AdAnnihilator.dll/3252
O8 - Extra context menu item: [Unblock this banner] Ctrl+Alt+U - res://C:\Program Files\Ad Annihilator\AdAnnihilator.dll/3246
O8 - Extra context menu item: [Unblock this popup] Ctrl+Alt+A - res://C:\Program Files\Ad Annihilator\AdAnnihilator.dll/3257
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra button: (no name) - {5300D45F-2512-49DB-80D2-804A75E65664} - C:\PROGRA~1\ADANNI~1\ADANNI~1.DLL
O9 - Extra 'Tools' menuitem: Ad Annihilator Toolbar - {5300D45F-2512-49DB-80D2-804A75E65664} - C:\PROGRA~1\ADANNI~1\ADANNI~1.DLL
O9 - Extra button: Ad Annihilator Options - {8131EDD7-9F34-4F7E-8B18-708D21B32888} - C:\PROGRA~1\ADANNI~1\ADANNI~1.DLL
O9 - Extra 'Tools' menuitem: Ad Annihilator Options - {8131EDD7-9F34-4F7E-8B18-708D21B32888} - C:\PROGRA~1\ADANNI~1\ADANNI~1.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE (file missing)
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE (file missing)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: Yahoo! Chat - http://us.chat1.yimg...t/c381/chat.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai...all/xscan53.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn...pDownloader.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/...s/msnchat45.cab
O23 - Service: AntiVir Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\Program Files\AVPersonal\AVGUARD.EXE
O23 - Service: AntiVir Update (AVWUpSrv) - Unknown owner - C:\Program Files\AVPersonal\AVWUPSRV.EXE (file missing)
O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Program Files\Executive Software\DiskeeperLite\DKService.exe
  • 0

Advertisements


#2
Trevuren

Trevuren

    Old Dog

  • Retired Staff
  • 18,699 posts
Hi modi5mind and welcome to the Geeks to Go Forums.

My name is Trevuren and I will be helping you with your log.

1. Please DELETE your current HJT program from its present location.

2. Download and run the following HijackThis autoinstall program from Here . Please choose the default location of C:\Program Files\ as the destination. HJT needs to be in its own folder so that the program itself isn't deleted by accident. Having the backups could be VITAL to restoring your system if something went wrong in the FIX process!
  • Run HijackThis
  • Click SCAN and SAVE LOG. (a notepad window will open with the log in it when you click Save Log) (Ctrl-A to'select all', Ctrl-C to 'copy')
  • POST the log into this thread using 'Add Reply' (Ctrl-V to 'paste')

DO NOT MAKE ANY CHANGES OR CLICK "FIX CHECKED" UNTIL WE CHECK THE LOG, AS MOST OF THE FILES ARE LEGIT AND VITAL TO THE FUNCTION OF YOUR COMPUTER


Regards,

Trevuren

  • 0

#3
modi5mind

modi5mind

    New Member

  • Topic Starter
  • Member
  • Pip
  • 6 posts
Logfile of HijackThis v1.99.1
Scan saved at 8:32:37 AM, on 10/9/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AVPersonal\AVGUARD.EXE
C:\Program Files\Executive Software\DiskeeperLite\DKService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\ups.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\VIAudioi\SBADeck\ADeck.exe
C:\WINDOWS\System32\VTTimer.exe
C:\Program Files\Classic PhoneTools\CapFax.EXE
C:\Program Files\ahead\InCD\InCD.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\AVPersonal\AVGNT.EXE
C:\windows\system32\yrkcnh.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\Program Files\Microsoft Office\Office\OSA.EXE
C:\Program Files\Microsoft Office\Office10\msoffice.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Yahoo!\Messenger\YPager.exe
C:\Program Files\Hijackthis\HijackThis.exe

O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_6_0_0.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Ad Annihilator Kernel - {D880FC15-AF5D-4929-9FB5-F06D01CDF70C} - C:\PROGRA~1\ADANNI~1\ADANNI~1.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_6_0_0.dll
O3 - Toolbar: &Ad Annihilator - {B2A8E0D7-5764-433D-A89B-2332B9D9BE00} - C:\PROGRA~1\ADANNI~1\ADANNI~1.DLL
O4 - HKLM\..\Run: [AudioDeck] C:\Program Files\VIAudioi\SBADeck\ADeck.exe
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [CapFax] C:\Program Files\Classic PhoneTools\CapFax.EXE
O4 - HKLM\..\Run: [CorelDRAW Graphics Suite 11b] C:\Program Files\Corel\Corel Graphics 12\Languages\EN\Programs\Registration.exe /title="CorelDRAW Graphics Suite 12" /date=102105 serial=DR12CUS-5188071-KJB lang=EN
O4 - HKLM\..\Run: [InCD] C:\Program Files\ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AnyDVD] C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [AVGCtrl] C:\Program Files\AVPersonal\AVGNT.EXE /min
O4 - HKLM\..\Run: [yrkcnh] c:\windows\system32\yrkcnh.exe -start
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - Startup: Ad-Watch SE Plus.lnk = C:\Program Files\Lavasoft\Ad-Aware SE Plus\Ad-Watch.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
O8 - Extra context menu item: + &Download Express: download this file - C:\Program Files\Download Express\Add_Url.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: [Add to organizer] - res://C:\Program Files\Ad Annihilator\AdAnnihilator.dll/3250
O8 - Extra context menu item: [Block this banner] Ctrl+Alt+B - res://C:\Program Files\Ad Annihilator\AdAnnihilator.dll/3245
O8 - Extra context menu item: [Block this popup] Ctrl+Alt+K - res://C:\Program Files\Ad Annihilator\AdAnnihilator.dll/3256
O8 - Extra context menu item: [Find blocking filter] Ctrl+Alt+F - res://C:\Program Files\Ad Annihilator\AdAnnihilator.dll/3254
O8 - Extra context menu item: [Find this resource in resource list] Ctrl+Alt+L - res://C:\Program Files\Ad Annihilator\AdAnnihilator.dll/3253
O8 - Extra context menu item: [Locate target document] - res://C:\Program Files\Ad Annihilator\AdAnnihilator.dll/3255
O8 - Extra context menu item: [Open all links] - res://C:\Program Files\Ad Annihilator\AdAnnihilator.dll/3247
O8 - Extra context menu item: [Resume resource loading] Ctrl+Alt+R - res://C:\Program Files\Ad Annihilator\AdAnnihilator.dll/3251
O8 - Extra context menu item: [Show/hide menu and toolbars] Ctrl+Alt+M - res://C:\Program Files\Ad Annihilator\AdAnnihilator.dll/3252
O8 - Extra context menu item: [Unblock this banner] Ctrl+Alt+U - res://C:\Program Files\Ad Annihilator\AdAnnihilator.dll/3246
O8 - Extra context menu item: [Unblock this popup] Ctrl+Alt+A - res://C:\Program Files\Ad Annihilator\AdAnnihilator.dll/3257
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra button: (no name) - {5300D45F-2512-49DB-80D2-804A75E65664} - C:\PROGRA~1\ADANNI~1\ADANNI~1.DLL
O9 - Extra 'Tools' menuitem: Ad Annihilator Toolbar - {5300D45F-2512-49DB-80D2-804A75E65664} - C:\PROGRA~1\ADANNI~1\ADANNI~1.DLL
O9 - Extra button: Ad Annihilator Options - {8131EDD7-9F34-4F7E-8B18-708D21B32888} - C:\PROGRA~1\ADANNI~1\ADANNI~1.DLL
O9 - Extra 'Tools' menuitem: Ad Annihilator Options - {8131EDD7-9F34-4F7E-8B18-708D21B32888} - C:\PROGRA~1\ADANNI~1\ADANNI~1.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE (file missing)
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE (file missing)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: Yahoo! Chat - http://us.chat1.yimg...t/c381/chat.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai...all/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoft...free/asinst.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn...pDownloader.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/...s/msnchat45.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{FF049981-926C-4712-BFC5-EBA90E42865C}: NameServer = 196.3.132.1 196.3.132.4
O23 - Service: AntiVir Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\Program Files\AVPersonal\AVGUARD.EXE
O23 - Service: AntiVir Update (AVWUpSrv) - Unknown owner - C:\Program Files\AVPersonal\AVWUPSRV.EXE (file missing)
O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Program Files\Executive Software\DiskeeperLite\DKService.exe



That was the latest hijack log and l dont know if this may help, but l did an online virus scan using panda.com but l got no detected or disinfected files. The antivir keeps asking if to allow, deny, delete, etc. No matter how many times l try to delete it, when l come online l still get PUP, sadly ad annihilator is no help because its the same window, l tried adding the key words on lavasoft adaware program, nothing is helping, l hope l get a solution through this forum, thanks for ur cooperation thus far
  • 0

#4
modi5mind

modi5mind

    New Member

  • Topic Starter
  • Member
  • Pip
  • 6 posts
Hey Trevuren

I made an error, this is the scan report from www.panda.com


Incident Status Location

Dialer:Dialer.DFF No disinfected C:\Documents and Settings\Richardson\Local Settings\Temp\temp.frBD6B
Dialer:Dialer.CPS No disinfected C:\Documents and Settings\Richardson\Local Settings\Temp\temp.frCC7F
Possible Virus. No disinfected C:\Documents and Settings\Richardson\Local Settings\Temporary Internet Files\Content.IE5\A5CREHE5\EGDACCESS_1066_XP[1].cab[EGDACCESS_1066.dll]
Adware:Adware/NaviPromo No disinfected C:\Program Files\AVPersonal\INFECTED\A0025302.DLL.VIR
Adware:Adware/NaviPromo No disinfected C:\Program Files\AVPersonal\INFECTED\A0025313.DLL.VIR
Adware:Adware/NaviPromo No disinfected C:\Program Files\AVPersonal\INFECTED\A0025335.DLL.VIR
Adware:Adware/NaviPromo No disinfected C:\Program Files\AVPersonal\INFECTED\A0025357.DLL.VIR
Adware:Adware/NaviPromo No disinfected C:\Program Files\AVPersonal\INFECTED\A0025365.DLL.VIR
Adware:Adware/NaviPromo No disinfected C:\Program Files\AVPersonal\INFECTED\A0025388.DLL.VIR
Adware:Adware/NaviPromo No disinfected C:\Program Files\AVPersonal\INFECTED\A0025406.DLL.VIR
Adware:Adware/NaviPromo No disinfected C:\Program Files\AVPersonal\INFECTED\A0025422.DLL.VIR
Adware:Adware/NaviPromo No disinfected C:\Program Files\AVPersonal\INFECTED\A0025432.DLL.VIR
Adware:Adware/NaviPromo No disinfected C:\Program Files\AVPersonal\INFECTED\A0025460.DLL.VIR
Adware:Adware/NaviPromo No disinfected C:\Program Files\AVPersonal\INFECTED\A0025469.DLL.VIR
Dialer:Dialer.CPS No disinfected C:\Program Files\AVPersonal\INFECTED\A0025511.DLL.VIR
Adware:Adware/NaviPromo No disinfected C:\Program Files\AVPersonal\INFECTED\A0025517.DLL.VIR
Adware:Adware/NaviPromo No disinfected C:\Program Files\AVPersonal\INFECTED\A0025552.DLL.VIR
Adware:Adware/NaviPromo No disinfected C:\Program Files\AVPersonal\INFECTED\A0025569.DLL.VIR
Adware:Adware/NaviPromo No disinfected C:\Program Files\AVPersonal\INFECTED\A0025575.DLL.VIR
Adware:Adware/NaviPromo No disinfected C:\Program Files\AVPersonal\INFECTED\A0025584.DLL.VIR
Adware:Adware/NaviPromo No disinfected C:\Program Files\AVPersonal\INFECTED\A0025596.DLL.VIR
Adware:Adware/NaviPromo No disinfected C:\Program Files\AVPersonal\INFECTED\A0025624.DLL.VIR
Adware:Adware/NaviPromo No disinfected C:\Program Files\AVPersonal\INFECTED\A0025631.DLL.VIR
Adware:Adware/NaviPromo No disinfected C:\Program Files\AVPersonal\INFECTED\A0025647.DLL.VIR
Adware:Adware/NaviPromo No disinfected C:\Program Files\AVPersonal\INFECTED\A0025654.DLL.VIR
Adware:Adware/NaviPromo No disinfected C:\Program Files\AVPersonal\INFECTED\A0025662.DLL.VIR
Adware:Adware/NaviPromo No disinfected C:\Program Files\AVPersonal\INFECTED\A0025672.DLL.VIR
Adware:Adware/NaviPromo No disinfected C:\Program Files\AVPersonal\INFECTED\MSCLOCK32.DLL.VIR
Dialer:Dialer.DFF No disinfected C:\Program Files\backups\backup-20051007-094553-709.dll
Adware:adware/navipromo No disinfected C:\WINDOWS\system32\msegcompid.dll
dont mind lf l can get a little intrepetation. may be it make make ur job a lot easier : )
  • 0

#5
Trevuren

Trevuren

    Old Dog

  • Retired Staff
  • 18,699 posts
1. . Please download the 30-day free trial of Kaspersky anti virus

. Install the program
. Run the definition update module.
. Scan your whole system and let the program remove anything it wants.
. Keep a copy of any report/log generated
. When finished, REBOOT your system

2. Please post log


Regards,

Trevuren

  • 0

#6
modi5mind

modi5mind

    New Member

  • Topic Starter
  • Member
  • Pip
  • 6 posts
hi trevuren

I did download the kaspersky anti-virus software but sadly it did not pick up anything. It did not recognize the dialer malware programs that panda online can detected. The following is what it detected.


Incident Status Location

Dialer:Dialer.DFF No disinfected C:\Documents and Settings\Richardson\Local Settings\Temp\temp.frBD6B
Dialer:Dialer.CPS No disinfected C:\Documents and Settings\Richardson\Local Settings\Temp\temp.frCC7F
Possible Virus. No disinfected C:\Documents and Settings\Richardson\Local Settings\Temporary Internet Files\Content.IE5\A5CREHE5\EGDACCESS_1066_XP[1].cab[EGDACCESS_1066.dll]
Adware:Adware/NaviPromo No disinfected C:\Program Files\AVPersonal\INFECTED\A0025302.DLL.VIR
Adware:Adware/NaviPromo No disinfected C:\Program Files\AVPersonal\INFECTED\A0025313.DLL.VIR
Adware:Adware/NaviPromo No disinfected C:\Program Files\AVPersonal\INFECTED\A0025335.DLL.VIR
Adware:Adware/NaviPromo No disinfected C:\Program Files\AVPersonal\INFECTED\A0025357.DLL.VIR
Adware:Adware/NaviPromo No disinfected C:\Program Files\AVPersonal\INFECTED\A0025365.DLL.VIR
Adware:Adware/NaviPromo No disinfected C:\Program Files\AVPersonal\INFECTED\A0025388.DLL.VIR
Adware:Adware/NaviPromo No disinfected C:\Program Files\AVPersonal\INFECTED\A0025406.DLL.VIR
Adware:Adware/NaviPromo No disinfected C:\Program Files\AVPersonal\INFECTED\A0025422.DLL.VIR
Adware:Adware/NaviPromo No disinfected C:\Program Files\AVPersonal\INFECTED\A0025432.DLL.VIR
Adware:Adware/NaviPromo No disinfected C:\Program Files\AVPersonal\INFECTED\A0025460.DLL.VIR
Adware:Adware/NaviPromo No disinfected C:\Program Files\AVPersonal\INFECTED\A0025469.DLL.VIR
Dialer:Dialer.CPS No disinfected C:\Program Files\AVPersonal\INFECTED\A0025511.DLL.VIR
Adware:Adware/NaviPromo No disinfected C:\Program Files\AVPersonal\INFECTED\A0025517.DLL.VIR
Adware:Adware/NaviPromo No disinfected C:\Program Files\AVPersonal\INFECTED\A0025552.DLL.VIR
Adware:Adware/NaviPromo No disinfected C:\Program Files\AVPersonal\INFECTED\A0025569.DLL.VIR
Adware:Adware/NaviPromo No disinfected C:\Program Files\AVPersonal\INFECTED\A0025575.DLL.VIR
Adware:Adware/NaviPromo No disinfected C:\Program Files\AVPersonal\INFECTED\A0025584.DLL.VIR
Adware:Adware/NaviPromo No disinfected C:\Program Files\AVPersonal\INFECTED\A0025596.DLL.VIR
Adware:Adware/NaviPromo No disinfected C:\Program Files\AVPersonal\INFECTED\A0025624.DLL.VIR
Adware:Adware/NaviPromo No disinfected C:\Program Files\AVPersonal\INFECTED\A0025631.DLL.VIR
Adware:Adware/NaviPromo No disinfected C:\Program Files\AVPersonal\INFECTED\A0025647.DLL.VIR
Adware:Adware/NaviPromo No disinfected C:\Program Files\AVPersonal\INFECTED\A0025654.DLL.VIR
Adware:Adware/NaviPromo No disinfected C:\Program Files\AVPersonal\INFECTED\A0025662.DLL.VIR
Adware:Adware/NaviPromo No disinfected C:\Program Files\AVPersonal\INFECTED\A0025672.DLL.VIR
Adware:Adware/NaviPromo No disinfected C:\Program Files\AVPersonal\INFECTED\MSCLOCK32.DLL.VIR
Dialer:Dialer.DFF No disinfected C:\Program Files\backups\backup-20051007-094553-709.dll
Adware:adware/navipromo No disinfected C:\WINDOWS\system32\msegcompid.dll Since that time, l have uninstalled antivir, used CleanUp to clean up the temporary folders and yet still the pop up windows keep appearing. Got any more solutions.
  • 0

#7
Trevuren

Trevuren

    Old Dog

  • Retired Staff
  • 18,699 posts
1. Please download the Killbox by Option^Explicit.

Note:In the event you already have Killbox, this is a new version that I need you to download.
  • Save it to your desktop.
  • Please double-click Killbox.exe to run it.
  • Select
    • "Delete on Reboot".
    • "End Explorer Shell While Killing File"
  • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C

    C:\Documents and Settings\Richardson\Local Settings\Temp\temp.frBD6B
    C:\Documents and Settings\Richardson\Local Settings\Temp\temp.frCC7F
    C:\Documents and Settings\Richardson\Local Settings\Temporary Internet Files\Content.IE5\A5CREHE5\EGDACCESS_1066_XP[1].cab
    C:\Program Files\backups\backup-20051007-094553-709.dll
    C:\WINDOWS\system32\msegcompid.dll

  • Return to Killbox, go to the File menu, and choose "Paste from Clipboard".
  • Click the red-and-white "Delete File" button. Click "Yes" at the Delete on Reboot prompt. Click "No" at the Pending Operations prompt.
If your computer does not restart automatically, please restart it manually.

2. I'll be sending you something else in a couple of minutes. Please do this first.


Regards,

Trevuren

  • 0

#8
Trevuren

Trevuren

    Old Dog

  • Retired Staff
  • 18,699 posts
This is your dialer: EGDACCESS_1066

It is new, I have just advised our extraordinary development personnel of this one.

I'll get back to you!!


Trevuren
  • 0

#9
Metallica

Metallica

    Spyware Veteran

  • GeekU Moderator
  • 33,101 posts
Hi modi5mind,

Can you please surf to:
http://www.thespykil...x.php?topic=5.0
Follow the instructions there to upload:
c:\windows\system32\yrkcnh.exe

After doing so click Start > Run > and copy this command:
c:\windows\system32\yrkcnh.exe -uninstall
and click OK

You should get a prompt if you really want to uninstall the dialer. You do. :tazz:

Post back with a new HijackThis log.

Regards,
  • 0

#10
Trevuren

Trevuren

    Old Dog

  • Retired Staff
  • 18,699 posts
Due to lack of feedback, this topic has been closed.

If you need this topic reopened, please contact a staff member. This applies only to the original topic starter. Everyone else please begin a New Topic.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP