Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Desktop Wallpaper Is Blank


  • Please log in to reply
7 replies to this topic

#1 wds

wds

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:10:57 PM

Posted 22 December 2005 - 06:39 PM

This is on a Win XP Pro machine. I have run virus scans and spyware scans. I have installed the latest Windows Updates. On boot up, the normal desktop wallpaper is displayed briefly but in the end is replaced with blank white wallpaper. HJT log is below.
WDS

Logfile of HijackThis v1.99.1
Scan saved at 5:31:03 PM, on 12/22/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
C:\WINDOWS\System32\ScsiAccess.EXE
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Intel\Intel® Active Monitor\imonnt.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Hewlett-Packard\Toolbox2.0\Apache Tomcat 4.0\webapps\Toolbox\StatusClient\StatusClient.exe
C:\Program Files\Analog Devices\SoundMAX\Smtray.exe
C:\Program Files\Intel\Intel® Active Monitor\imontray.exe
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Yahoo!\Messenger\ypager.exe
C:\WINDOWS\system32\??rss.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\backWeb-7288971.exe
C:\Program Files\Common Files\Sikeston Desktop Alert\TrueWeather.exe
C:\Program Files\Hewlett-Packard\Toolbox2.0\Javasoft\JRE\1.3.1\bin\javaw.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\WINDOWS\explorer.exe
C:\HiJack this\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost;<local>
R3 - Default URLSearchHook is missing
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_3_12_0.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\program files\Adobe\Acrobat Reader 5\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {21B72288-6A76-4187-BB56-5072A2EDBAD2} - C:\WINDOWS\system32\pmmg.dll (file missing)
O2 - BHO: REALBAR - {4E7BD74F-2B8D-469E-C0FF-FD60B590A87D} - C:\PROGRA~1\COMMON~1\Real\Toolbar\realbar.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: REALBAR - {4E7BD74F-2B8D-469E-C0FF-FD60B590A87D} - C:\PROGRA~1\COMMON~1\Real\Toolbar\realbar.dll
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_3_12_0.dll
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
O4 - HKLM\..\Run: [TomcatStartup] C:\Program Files\Hewlett-Packard\Toolbox2.0\hpbpsttp.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [StatusClient] C:\Program Files\Hewlett-Packard\Toolbox2.0\Apache Tomcat 4.0\webapps\Toolbox\StatusClient\StatusClient.exe /auto
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\Smtray.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\\NeroCheck.exe
O4 - HKLM\..\Run: [IMONTRAY] C:\Program Files\Intel\Intel® Active Monitor\imontray.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [alij] C:\WINDOWS\system32\run804.exe dummy
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [OkUcU.exe] C:\WINDOWS\system32\OkUcU.exe
O4 - HKLM\..\Run: [apihh.exe] C:\WINDOWS\system32\apihh.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [Vtgtfs] C:\WINDOWS\system32\??rss.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: KODAK Software Updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\backWeb-7288971.exe
O4 - Global Startup: Sikeston Desktop Alert.lnk = C:\Program Files\Common Files\Sikeston Desktop Alert\TrueWeather.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .mid: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin2.dll
O12 - Plugin for .mov: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: SwiftWebInstall Class - http://media.affinitymedia.com/offer/insta...tWebInstall.cab
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) - http://us.dl1.yimg.com/download.yahoo.com/.../ymmapi_416.dll
O16 - DPF: {B1826A9F-4AA0-4510-BA77-9013E74E4B9B} - http://www.trendmicro.com/spyware-scan/as4web.cab
O16 - DPF: {F919FBD3-A96B-4679-AF26-F551439BB5FD} - http://download.winfixer.com/files/install...nnerInstall.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{E12FB3AF-40D0-4956-B24F-FBEC4DF90ED3}: NameServer = 69.151.44.9,69.60.160.196
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: msupdate - C:\WINDOWS\SYSTEM32\msupdate32.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
O23 - Service: Intel® Active Monitor (imonNT) - Intel Corp. - C:\Program Files\Intel\Intel® Active Monitor\imonnt.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: ScsiAccess - Unknown owner - C:\WINDOWS\System32\ScsiAccess.EXE
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

BC AdBot (Login to Remove)

 


#2 MFDnSC

MFDnSC

    Ret. Director I/T


  • Members
  • 4,310 posts
  • OFFLINE
  •  
  • Local time:10:57 PM

Posted 23 December 2005 - 10:17 PM

This fix is only for XP & Windows 2000

Download and Save Cleandesktop to your computer from this link: http://www.thespykiller.co.uk/files/cleandesktop.exe and double click on the cleandesktop.exe

It will automatically extract to c:\desktopclean where it needs to be to run and will automatically run the cleandesktop.vbs script

If it doesn't open then go to c:\desktopclean and double click on the cleandesktop.vbs Do not run any other file from there please unless asked to

If you have script blocking enabled you will get a warning about a malicious script wanting to run. Please allow this script to run. It is not malicious.

If you get a message when you first run it "Can not find script file "blah blah blah" then don't worry just doubleclick the cleandesktop.vbs script again you sometimes get that message when a script blocker blocks the script

It will then kill Explorer. You will lose your taskbar and desktop. It will repair the registry entries returning your normal desktop and context menu functions.

It will restart Explorer.

Once you have performed the big cleanup, each of the other Users on the System needs to be signed in to clean up their desktop and regain the right click.

I have included another vbs to do this. It is named Other Profiles Regfix.vbs

Have each User sign in and run Other Profiles Regfix.vbs
Open C:\ (Go to Start>Run and type C: Press enter) and Open the c:\desktopclean folder. Double click on Other Profiles Regfix.vbs

Explorer will be ended and that user's active desktop registry entries will be repaired. Explorer will be restarted.

To restore the desktop to whatever picture you normally have right click on a blank part of desktop & select properties/desktop & select your prefered picture press apply & then ok to exit and then press F5

You will need to do this step for every user account
==============

Download the trial version of Ewido Security Suite http://www.ewido.net/en/download/ (W2K/XP Only)
· Install ewido.
· During the installation, under "Additional Options" uncheck "Install background guard" and "Install scan via context menu".
· Launch ewido
· It will prompt you to update click the OK button and it will go to the main screen
· On the left side of the main screen click update
· Click on Start and let it update.
· DO NOT run a scan yet. You will do that later in safe mode.

Restart your computer into safe mode now. Perform the following steps in safe mode:
(Start tapping F8 at the first black screen after power up)

Run Ewido:
· Click on scanner
· Click Complete System Scan and the scan will begin.
· During the scan it will prompt you to clean files, click OK
· When the scan is finished, look at the bottom of the screen and click the Save report button.
· Save the report to your C: Drive
This will take some time to run!
Boot to normal mode
Post that log and a new HiJack log
"Nothing could be finer than to be in South Carolina ............"

Member ASAP

#3 wds

wds
  • Topic Starter

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:10:57 PM

Posted 30 December 2005 - 11:37 AM

MFDnSC,

I followed your suggestions in your last post. cleandesktop.vbs ran as you said it should but when I tried to restore the original picture to my desktop it went right back to the blank white desktop. I have run several virus scans and spyware scans. My Symantec Antivirus keeps detecting a trojan.Zlob and a trojan.Zlob.D. I am not sure if I have successfully cleaned up these trojans or not. I am posting the HJT log and logs from Ewido. Thanks for the help.

WDS

Logfile of HijackThis v1.99.1
Scan saved at 10:23:59 AM, on 12/30/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
C:\WINDOWS\System32\ScsiAccess.EXE
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Intel\Intel® Active Monitor\imonnt.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\backWeb-7288971.exe
C:\Program Files\Common Files\Sikeston Desktop Alert\TrueWeather.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\WINDOWS\system32\nvctrl.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\explorer.exe
C:\HiJack this\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost;<local>
R3 - Default URLSearchHook is missing
O2 - BHO: HomepageBHO - {e0103cd4-d1ce-411a-b75b-4fec072867f4} - C:\WINDOWS\system32\hpECEF.tmp (file missing)
O3 - Toolbar: REALBAR - {4E7BD74F-2B8D-469E-C0FF-FD60B590A87D} - C:\PROGRA~1\COMMON~1\Real\Toolbar\realbar.dll (file missing)
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_3_12_0.dll (file missing)
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: KODAK Software Updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\backWeb-7288971.exe
O4 - Global Startup: Sikeston Desktop Alert.lnk = C:\Program Files\Common Files\Sikeston Desktop Alert\TrueWeather.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .mid: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin2.dll
O12 - Plugin for .mov: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: SwiftWebInstall Class - http://media.affinitymedia.com/offer/insta...tWebInstall.cab
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) - http://us.dl1.yimg.com/download.yahoo.com/.../ymmapi_416.dll
O16 - DPF: {B1826A9F-4AA0-4510-BA77-9013E74E4B9B} - http://www.trendmicro.com/spyware-scan/as4web.cab
O16 - DPF: {F919FBD3-A96B-4679-AF26-F551439BB5FD} - http://download.winfixer.com/files/install...nnerInstall.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{E12FB3AF-40D0-4956-B24F-FBEC4DF90ED3}: NameServer = 69.151.44.9,69.60.160.196
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: msupdate - msupdate32.dll (file missing)
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: Intel® Active Monitor (imonNT) - Intel Corp. - C:\Program Files\Intel\Intel® Active Monitor\imonnt.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: ScsiAccess - Unknown owner - C:\WINDOWS\System32\ScsiAccess.EXE
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

---------------------------------------------------------
ewido anti-malware - Scan report
---------------------------------------------------------

+ Created on: 3:05:51 PM, 12/29/2005
+ Report-Checksum: 1B7FC355

+ Scan result:

HKLM\SOFTWARE\Classes\TypeLib\{ECB25A48-E6E0-49AF-99AF-07C763E31389} -> Spyware.MidAddle : Cleaned with backup
HKLM\SOFTWARE\iGlobalMedia -> Spyware.AceClubCasino : Cleaned with backup
HKLM\SOFTWARE\iGlobalMedia\Installer -> Spyware.AceClubCasino : Cleaned with backup
HKLM\SOFTWARE\iGlobalMedia\starluckcasino -> Spyware.AceClubCasino : Cleaned with backup
HKLM\SOFTWARE\iGlobalMedia\starluckcasino\casino -> Spyware.AceClubCasino : Cleaned with backup
HKLM\SOFTWARE\iGlobalMedia\starluckcasino\casino\upgrades -> Spyware.AceClubCasino : Cleaned with backup
HKLM\SOFTWARE\iGlobalMedia\starluckcasino\casino\version -> Spyware.AceClubCasino : Cleaned with backup
HKLM\SOFTWARE\iGlobalMedia\starluckcasino\casino\version\blackjack -> Spyware.AceClubCasino : Cleaned with backup
HKLM\SOFTWARE\iGlobalMedia\starluckcasino\casino\version\boardbabe -> Spyware.AceClubCasino : Cleaned with backup
HKLM\SOFTWARE\iGlobalMedia\starluckcasino\casino\version\caribbeanpoker -> Spyware.AceClubCasino : Cleaned with backup
HKLM\SOFTWARE\iGlobalMedia\starluckcasino\casino\version\client -> Spyware.AceClubCasino : Cleaned with backup
HKLM\SOFTWARE\iGlobalMedia\starluckcasino\casino\version\coolbananas -> Spyware.AceClubCasino : Cleaned with backup
HKLM\SOFTWARE\iGlobalMedia\starluckcasino\casino\version\flamingo -> Spyware.AceClubCasino : Cleaned with backup
HKLM\SOFTWARE\iGlobalMedia\starluckcasino\casino\version\funkychicken -> Spyware.AceClubCasino : Cleaned with backup
HKLM\SOFTWARE\iGlobalMedia\starluckcasino\casino\version\games -> Spyware.AceClubCasino : Cleaned with backup
HKLM\SOFTWARE\iGlobalMedia\starluckcasino\casino\version\goannagold -> Spyware.AceClubCasino : Cleaned with backup
HKLM\SOFTWARE\iGlobalMedia\starluckcasino\casino\version\goldeneagle -> Spyware.AceClubCasino : Cleaned with backup
HKLM\SOFTWARE\iGlobalMedia\starluckcasino\casino\version\goldengopher -> Spyware.AceClubCasino : Cleaned with backup
HKLM\SOFTWARE\iGlobalMedia\starluckcasino\casino\version\highlimitblackjack -> Spyware.AceClubCasino : Cleaned with backup
HKLM\SOFTWARE\iGlobalMedia\starluckcasino\casino\version\hotroller -> Spyware.AceClubCasino : Cleaned with backup
HKLM\SOFTWARE\iGlobalMedia\starluckcasino\casino\version\junglerumble -> Spyware.AceClubCasino : Cleaned with backup
HKLM\SOFTWARE\iGlobalMedia\starluckcasino\casino\version\kangacash -> Spyware.AceClubCasino : Cleaned with backup
HKLM\SOFTWARE\iGlobalMedia\starluckcasino\casino\version\kookakeno -> Spyware.AceClubCasino : Cleaned with backup
HKLM\SOFTWARE\iGlobalMedia\starluckcasino\casino\version\letitride -> Spyware.AceClubCasino : Cleaned with backup
HKLM\SOFTWARE\iGlobalMedia\starluckcasino\casino\version\magicmanslot -> Spyware.AceClubCasino : Cleaned with backup
HKLM\SOFTWARE\iGlobalMedia\starluckcasino\casino\version\megaeuropeanroulette -> Spyware.AceClubCasino : Cleaned with backup
HKLM\SOFTWARE\iGlobalMedia\starluckcasino\casino\version\metropolis -> Spyware.AceClubCasino : Cleaned with backup
HKLM\SOFTWARE\iGlobalMedia\starluckcasino\casino\version\multiplayerblackjack -> Spyware.AceClubCasino : Cleaned with backup
HKLM\SOFTWARE\iGlobalMedia\starluckcasino\casino\version\piggypayback -> Spyware.AceClubCasino : Cleaned with backup
HKLM\SOFTWARE\iGlobalMedia\starluckcasino\casino\version\predatorslot -> Spyware.AceClubCasino : Cleaned with backup
HKLM\SOFTWARE\iGlobalMedia\starluckcasino\casino\version\safecrackerkeno -> Spyware.AceClubCasino : Cleaned with backup
HKLM\SOFTWARE\iGlobalMedia\starluckcasino\casino\version\silvercity -> Spyware.AceClubCasino : Cleaned with backup
HKLM\SOFTWARE\iGlobalMedia\starluckcasino\casino\version\threecardpoker -> Spyware.AceClubCasino : Cleaned with backup
HKLM\SOFTWARE\iGlobalMedia\starluckcasino\casino\version\tod -> Spyware.AceClubCasino : Cleaned with backup
HKLM\SOFTWARE\iGlobalMedia\starluckcasino\casino\version\upgrader -> Spyware.AceClubCasino : Cleaned with backup
HKLM\SOFTWARE\iGlobalMedia\starluckcasino\casino\version\vegasclub -> Spyware.AceClubCasino : Cleaned with backup
HKLM\SOFTWARE\iGlobalMedia\starluckcasino\casino\version\vpokerdw -> Spyware.AceClubCasino : Cleaned with backup
HKLM\SOFTWARE\iGlobalMedia\starluckcasino\casino\version\vpokerjob -> Spyware.AceClubCasino : Cleaned with backup
HKLM\SOFTWARE\iGlobalMedia\starluckcasino\casino\version\vpokerjp -> Spyware.AceClubCasino : Cleaned with backup
HKU\S-1-5-21-155205007-959584664-697575874-1003\Software\Classes\CLSID\{A2C8F6B1-7C2A-3D1C-A3C6-A1FDA113B43F} -> Downloader.SpyAxe : Cleaned with backup
HKU\S-1-5-21-155205007-959584664-697575874-1003_Classes\CLSID\{A2C8F6B1-7C2A-3D1C-A3C6-A1FDA113B43F} -> Downloader.SpyAxe : Cleaned with backup
[684] C:\WINDOWS\system32\msupdate32.dll -> Downloader.Agent.abe : Cleaned with backup
[1440] C:\WINDOWS\system32\wbeconm.dll -> Downloader.SpyAxe : Cleaned with backup
C:\Documents and Settings\Administrator\Local Settings\Temp\0W9DGM0.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\Administrator\Local Settings\Temp\tFLIVc.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\Ed\Local Settings\Temp\BoQcJiN.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\Ed\Local Settings\Temp\VAfDi.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\Ed.DOMAIN\Cookies\ed@ad.yieldmanager[2].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Ed.DOMAIN\Cookies\ed@atdmt[2].txt -> Spyware.Cookie.Atdmt : Cleaned with backup
C:\Documents and Settings\Ed.DOMAIN\Cookies\ed@cnn.122.2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Ed.DOMAIN\Cookies\ed@doubleclick[1].txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
C:\Documents and Settings\Ed.DOMAIN\Cookies\ed@e-2dj6wfkoskazwbp.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Ed.DOMAIN\Cookies\ed@e-2dj6wflicndjahp.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Ed.DOMAIN\Cookies\ed@e-2dj6wfligoczalo.stats.esomniture[1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Ed.DOMAIN\Cookies\ed@e-2dj6wflokjcpoco.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Ed.DOMAIN\Cookies\ed@e-2dj6wgkycpdjclq.stats.esomniture[1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Ed.DOMAIN\Cookies\ed@e-2dj6wjk4wndjako.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Ed.DOMAIN\Cookies\ed@e-2dj6wjkoanajmfo.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Ed.DOMAIN\Cookies\ed@e-2dj6wjkychdpgcp.stats.esomniture[1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Ed.DOMAIN\Cookies\ed@e-2dj6wjkysmcjslq.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Ed.DOMAIN\Cookies\ed@e-2dj6wjloujd5geq.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Ed.DOMAIN\Cookies\ed@e-2dj6wjlywlajmhp.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Ed.DOMAIN\Cookies\ed@e-2dj6wjmighajgbo.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Ed.DOMAIN\Cookies\ed@e-2dj6wjnycodpscp.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Ed.DOMAIN\Cookies\ed@e-2dj6wjnyojdzeco.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Ed.DOMAIN\Cookies\ed@e-2dj6wjnyujdpiap.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Ed.DOMAIN\Cookies\ed@fastclick[2].txt -> Spyware.Cookie.Fastclick : Cleaned with backup
C:\Documents and Settings\Ed.DOMAIN\Cookies\ed@hypertracker[1].txt -> Spyware.Cookie.Hypertracker : Cleaned with backup
C:\Documents and Settings\Ed.DOMAIN\Cookies\ed@image.masterstats[1].txt -> Spyware.Cookie.Masterstats : Cleaned with backup
C:\Documents and Settings\Ed.DOMAIN\Cookies\ed@paypopup[2].txt -> Spyware.Cookie.Paypopup : Cleaned with backup
C:\Documents and Settings\Ed.DOMAIN\Cookies\ed@revenue[1].txt -> Spyware.Cookie.Revenue : Cleaned with backup
C:\Documents and Settings\Ed.DOMAIN\Cookies\ed@sales.liveperson[2].txt -> Spyware.Cookie.Liveperson : Cleaned with backup
C:\Documents and Settings\Ed.DOMAIN\Cookies\ed@trafficmp[2].txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
C:\Documents and Settings\Ed.DOMAIN\Cookies\ed@vip.clickzs[2].txt -> Spyware.Cookie.Clickzs : Cleaned with backup
C:\Documents and Settings\Ed.DOMAIN\Cookies\ed@yieldmanager[1].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Ed.DOMAIN\Cookies\ed@z1.adserver[1].txt -> Spyware.Cookie.Adserver : Cleaned with backup
C:\Documents and Settings\Ed.DOMAIN\Local Settings\Temp\0uHi.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\Ed.DOMAIN\Local Settings\Temp\0wza.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\Ed.DOMAIN\Local Settings\Temp\0XYT1V.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\Ed.DOMAIN\Local Settings\Temp\123.456 -> Trojan.Dialer.ay : Cleaned with backup
C:\Documents and Settings\Ed.DOMAIN\Local Settings\Temp\13F.tmp -> Trojan.Small.ga : Cleaned with backup
C:\Documents and Settings\Ed.DOMAIN\Local Settings\Temp\13F.tmp.exe -> Trojan.Small.ga : Cleaned with backup
C:\Documents and Settings\Ed.DOMAIN\Local Settings\Temp\158.tmp -> Trojan.Small : Cleaned with backup
C:\Documents and Settings\Ed.DOMAIN\Local Settings\Temp\15C.tmp -> Trojan.Small.ga : Cleaned with backup
C:\Documents and Settings\Ed.DOMAIN\Local Settings\Temp\15C.tmp.exe -> Trojan.Small.ga : Cleaned with backup
C:\Documents and Settings\Ed.DOMAIN\Local Settings\Temp\2wRVz.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\Ed.DOMAIN\Local Settings\Temp\51.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\Ed.DOMAIN\Local Settings\Temp\a.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\Ed.DOMAIN\Local Settings\Temp\aCQhwR3W8.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\Ed.DOMAIN\Local Settings\Temp\BaFRKx.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\Ed.DOMAIN\Local Settings\Temp\CePGEbOlD.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\Ed.DOMAIN\Local Settings\Temp\dk.dial -> Trojan.Dialer.ay : Cleaned with backup
C:\Documents and Settings\Ed.DOMAIN\Local Settings\Temp\F.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\Ed.DOMAIN\Local Settings\Temp\hG6nw5.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\Ed.DOMAIN\Local Settings\Temp\ihbbjpmd.exe -> Trojan.Dialer.ay : Cleaned with backup
C:\Documents and Settings\Ed.DOMAIN\Local Settings\Temp\jEMHr6N1.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\Ed.DOMAIN\Local Settings\Temp\jYs.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\Ed.DOMAIN\Local Settings\Temp\k4qj7DHN.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\Ed.DOMAIN\Local Settings\Temp\kDBl1kH.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\Ed.DOMAIN\Local Settings\Temp\l2qBYDy9.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\Ed.DOMAIN\Local Settings\Temp\libk.exe -> Downloader.Small.bwr : Cleaned with backup
C:\Documents and Settings\Ed.DOMAIN\Local Settings\Temp\lvwlyn.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\Ed.DOMAIN\Local Settings\Temp\pmgi.exe -> Downloader.Small.bwr : Cleaned with backup
C:\Documents and Settings\Ed.DOMAIN\Local Settings\Temp\pRnC1o3UQ.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\Ed.DOMAIN\Local Settings\Temp\v0wkjoWLB.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\Ed.DOMAIN\Local Settings\Temp\VsA.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\Ed.DOMAIN\Local Settings\Temporary Internet Files\Content.IE5\3ACBZLKH\ioo[1].exe -> Downloader.Small.cat : Cleaned with backup
C:\Documents and Settings\Ed.DOMAIN\Local Settings\Temporary Internet Files\Content.IE5\61WFAH65\prepare[1].htm -> Not-A-Virus.Exploit.JS.CVE20051790.a : Cleaned with backup
C:\Documents and Settings\Ed.DOMAIN\Local Settings\Temporary Internet Files\Content.IE5\BYK7RXC5\mm[2].js -> Spyware.Chitika : Cleaned with backup
C:\Documents and Settings\Ed.DOMAIN\Local Settings\Temporary Internet Files\Content.IE5\G50LAF0H\prepare[1].htm -> Not-A-Virus.Exploit.JS.CVE20051790.a : Cleaned with backup
C:\Documents and Settings\Ed.DOMAIN\Local Settings\Temporary Internet Files\Content.IE5\GLEQ1Z2I\gdnUS2297[1].exe -> Downloader.Small.ayl : Cleaned with backup
C:\Documents and Settings\Ed.DOMAIN\Local Settings\Temporary Internet Files\Content.IE5\GLEQ1Z2I\loader75[1].exe -> Trojan.Small.ev : Cleaned with backup
C:\Documents and Settings\Ed.DOMAIN\Local Settings\Temporary Internet Files\Content.IE5\IQYTD1WU\prepare[1].htm -> Not-A-Virus.Exploit.JS.CVE20051790.a : Cleaned with backup
C:\Documents and Settings\Ed.DOMAIN\Local Settings\Temporary Internet Files\Content.IE5\N3P9P5DM\prepare[1].htm -> Not-A-Virus.Exploit.JS.CVE20051790.a : Cleaned with backup
C:\Documents and Settings\Ed.DOMAIN\Local Settings\Temporary Internet Files\Content.IE5\VPT7K0UV\win[1].exe -> Downloader.Small.bwr : Cleaned with backup
C:\Documents and Settings\Ed.DOMAIN\Local Settings\Temporary Internet Files\Content.IE5\WLWBWV8F\1001[1].exe -> Downloader.Small.awa : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\08809CB7-97E9-48CE-AD50-9C9539\C62729A9-D274-405F-B284-CE0190 -> Adware.Spyaxe : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\0D71B8AB-7E82-497B-9293-61F1C0\A36906F4-7937-41C3-BC11-53D8BE -> Adware.Spyaxe : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\46B61751-DC8B-48A2-8546-5DA832\FE95B192-2336-4CC5-A6DA-B74896 -> Spyware.FindSpy : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\D47F11E5-EA8C-466E-A644-D3DF16\D82764FA-8939-4B5F-8811-39A266 -> Adware.Spyaxe : Cleaned with backup
C:\RECYCLER\S-1-5-21-155205007-959584664-697575874-1003\Dc14.dat -> Downloader.Small.awa : Cleaned with backup
C:\WINDOWS\addas.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3fu32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\Gone Fishing.bmp:tziuw -> Downloader.Agent.td : Cleaned with backup
C:\WINDOWS\sdkyd.dll -> Downloader.Agent.bc : Cleaned with backup
C:\WINDOWS\system32\addlu.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\dial32.exe -> Trojan.Dialer.ay : Cleaned with backup
C:\WINDOWS\system32\ldr120.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINDOWS\system32\ldr223.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINDOWS\system32\ldr255.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINDOWS\system32\ldr262.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINDOWS\system32\ldr333.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINDOWS\system32\ldr344.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINDOWS\system32\ldr353.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINDOWS\system32\ldr374.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINDOWS\system32\ldr406.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINDOWS\system32\ldr407.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINDOWS\system32\ldr467.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINDOWS\system32\ldr498.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINDOWS\system32\ldr569.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINDOWS\system32\ldr621.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINDOWS\system32\ldr682.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINDOWS\system32\ldr692.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINDOWS\system32\ldr756.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINDOWS\system32\ldr764.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINDOWS\system32\ldr775.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINDOWS\system32\ldr78.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINDOWS\system32\ldr803.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINDOWS\system32\ldr850.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINDOWS\system32\ldr875.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINDOWS\system32\ldr916.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINDOWS\system32\ldr927.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINDOWS\system32\ldr936.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINDOWS\system32\ldr97.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINDOWS\system32\msupdate32.dll -> Downloader.Agent.abe : Cleaned with backup
C:\WINDOWS\system32\oleext.dll -> Trojan.Small.ev : Cleaned with backup
C:\WINDOWS\system32\run804.exe -> Downloader.Small.cat : Cleaned with backup
C:\WINDOWS\system32\sdfdil.exe -> Trojan.Dialer.ay : Cleaned with backup
C:\WINDOWS\system32\srpcsrv32.dll -> Downloader.Adload.g : Cleaned with backup
C:\WINDOWS\system32\txfdb32.dll -> Downloader.Adload.g : Cleaned with backup
C:\WINDOWS\system32\upd46.exe -> Dropper.Agent.ii : Cleaned with backup
C:\WINDOWS\system32\upd726.exe -> Downloader.Agent.zx : Cleaned with backup
C:\WINDOWS\system32\upd753.exe -> Downloader.Agent.zx : Cleaned with backup
C:\WINDOWS\system32\upd783.exe -> Downloader.Small.bpz : Cleaned with backup
C:\WINDOWS\system32\upd949.exe -> Downloader.Small.bpz : Cleaned with backup
C:\WINDOWS\system32\wbeconm.dll -> Downloader.SpyAxe : Cleaned with backup
C:\WINDOWS\system32\winctrl64.exe -> Downloader.Small.awa : Cleaned with backup
C:\WINDOWS\system32\сѕrss.exe -> Dropper.Purityscan.I : Cleaned with backup
C:\WINDOWS\vb.ini:ocpol -> Downloader.Agent.bc : Cleaned with backup
C:\WINDOWS\_default.pif:tcfyh -> Downloader.Agent.td : Cleaned with backup


::Report End

---------------------------------------------------------
ewido anti-malware - Scan report
---------------------------------------------------------

+ Created on: 10:17:48 AM, 12/30/2005
+ Report-Checksum: 8435E20C

+ Scan result:

No infected objects found.


::Report End

#4 MFDnSC

MFDnSC

    Ret. Director I/T


  • Members
  • 4,310 posts
  • OFFLINE
  •  
  • Local time:10:57 PM

Posted 30 December 2005 - 03:24 PM

* Click here to download smitRem.exe.
  • Save the file to your desktop.
  • It is a self extracting file.
  • Doubleclick the smitRem.exe and it will extract the files to a smitRem folder on your desktop.
  • Do not do anything with it yet. You will run the RunThis.bat file later in safe mode.
* Download the trial version of Ewido Security Suite here.
  • Install ewido.
  • During the installation, under "Additional Options" uncheck "Install background guard" and "Install scan via context menu".
  • Launch ewido
  • It will prompt you to update click the OK button and it will go to the main screen
  • On the left side of the main screen click update
  • Click on Start and let it update.
  • DO NOT run a scan yet. You will do that later in safe mode.
* Click here for info on how to boot to safe mode if you don't already know how.


* Now copy these instructions to notepad and save them to your desktop. You will need them to refer to in safe mode.


* Restart your computer into safe mode now. Perform the following steps in safe mode:


* Open the smitRem folder, then double click the RunThis.bat file to start the tool. Follow the prompts on screen.
Wait for the tool to complete and disk cleanup to finish.


* Run Ewido:
  • Click on scanner
  • Click Complete System Scan and the scan will begin.
  • During the scan it will prompt you to clean files, click OK
  • When the scan is finished, look at the bottom of the screen and click the Save report button.
  • Save the report to your desktop
* Go to Control Panel > Internet Options. Click on the Programs tab then click the "Reset Web Settings" button. Click Apply then OK.


* Next go to Control Panel > Display. Click on the "Desktop" tab then click the "Customize Desktop" button. Click on the "Web" tab. Under "Web Pages" you should see an entry checked called something like "Security info" or similar. If it is there, select that entry and click the "Delete" button. Click OK then Apply and OK.


* Restart back into Windows normally now.


* Run ActiveScan online virus scan here

When the scan is finished, anything that it cannot clean have it delete it. Make a note of the file location of anything that cannot be deleted so you can delete it yourself.
- Save the results from the scan!

Post a new HiJackThis log along with the results from ActiveScan


=============
DownLoad EasyCleaner http://www.majorgeeks.com/download414.html

Use the clear files and Unnecessary files buttons – I do not recommend
using the Duplicates files button
as many dupes are there on purpose.

Not all files will delete – that is normal.

In the unnecessary button I check the top 4 entries
"Nothing could be finer than to be in South Carolina ............"

Member ASAP

#5 wds

wds
  • Topic Starter

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:10:57 PM

Posted 01 January 2006 - 05:39 PM

Still no luck getting the desktop back. HJT and ActiveScan results below. Thanks again for the help.
WDS

Logfile of HijackThis v1.99.1
Scan saved at 4:16:19 PM, on 1/1/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
C:\WINDOWS\System32\ScsiAccess.EXE
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Intel\Intel® Active Monitor\imonnt.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\backWeb-7288971.exe
C:\Program Files\Common Files\Sikeston Desktop Alert\TrueWeather.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\explorer.exe
C:\HiJack this\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost;<local>
R3 - Default URLSearchHook is missing
O3 - Toolbar: REALBAR - {4E7BD74F-2B8D-469E-C0FF-FD60B590A87D} - C:\PROGRA~1\COMMON~1\Real\Toolbar\realbar.dll (file missing)
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_3_12_0.dll (file missing)
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: KODAK Software Updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\backWeb-7288971.exe
O4 - Global Startup: Sikeston Desktop Alert.lnk = C:\Program Files\Common Files\Sikeston Desktop Alert\TrueWeather.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .mid: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin2.dll
O12 - Plugin for .mov: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: SwiftWebInstall Class - http://media.affinitymedia.com/offer/insta...tWebInstall.cab
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) - http://us.dl1.yimg.com/download.yahoo.com/.../ymmapi_416.dll
O16 - DPF: {B1826A9F-4AA0-4510-BA77-9013E74E4B9B} - http://www.trendmicro.com/spyware-scan/as4web.cab
O16 - DPF: {F919FBD3-A96B-4679-AF26-F551439BB5FD} - http://download.winfixer.com/files/install...nnerInstall.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{E12FB3AF-40D0-4956-B24F-FBEC4DF90ED3}: NameServer = 69.151.44.9,69.60.160.196
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: msupdate - msupdate32.dll (file missing)
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: Intel® Active Monitor (imonNT) - Intel Corp. - C:\Program Files\Intel\Intel® Active Monitor\imonnt.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: ScsiAccess - Unknown owner - C:\WINDOWS\System32\ScsiAccess.EXE
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe


Incident Status Location

Adware:adware/dloader Not disinfected C:\WINDOWS\SYSTEM32\msblank.html
Adware:adware/securityerror Not disinfected C:\Documents and Settings\Ed.DOMAIN\Favorites\Antivirus Test Online.url
Virus:Trj/Downloader.GJV Not disinfected C:\Documents and Settings\Ed.DOMAIN\Local Settings\Temp\ckij.exe
Virus:Trj/Downloader.GJV Not disinfected C:\Documents and Settings\Ed.DOMAIN\Local Settings\Temp\mcjk.exe
Virus:W97M/Smac.D Not disinfected Personal Folders\Sent Items\FW: YEAR 2000 SPP COMPLIANCE PROGRAM\Southwest Power Pool Compliance Program Contact.doc
Virus:W97M/Smac.D Not disinfected Personal Folders\Sent Items\FW: YEAR 2000 SPP COMPLIANCE PROGRAM\Worshop Announcement.doc
Virus:W97M/Smac.D Not disinfected Personal Folders\Sent Items\FW: SPP/MISO Combination\sppmisoletteremail.doc
Virus:JS/Kak.Worm Not disinfected Personal Folders\Sent Items\FW: \ATT00000.html
Virus:W97M/Smac.D Not disinfected Personal Folders\Sent Items\FW: YEAR 2000 SPP COMPLIANCE PROGRAM\Southwest Power Pool Compliance Program Contact.doc
Virus:W97M/Smac.D Not disinfected Personal Folders\Sent Items\FW: YEAR 2000 SPP COMPLIANCE PROGRAM\Worshop Announcement.doc
Virus:W97M/Smac.D Not disinfected Personal Folders\Sent Items\FW: SPP/MISO Combination\sppmisoletteremail.doc
Virus:JS/Kak.Worm Not disinfected Personal Folders\Sent Items\FW: \ATT00000.html

#6 MFDnSC

MFDnSC

    Ret. Director I/T


  • Members
  • 4,310 posts
  • OFFLINE
  •  
  • Local time:10:57 PM

Posted 01 January 2006 - 05:51 PM

Fix these with HJT – mark them, close IE, click fix checked

R3 - Default URLSearchHook is missing

O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto

O16 - DPF: SwiftWebInstall Class - http://media.affinitymedia.com/offer/insta...tWebInstall.cab

O16 - DPF: {F919FBD3-A96B-4679-AF26-F551439BB5FD} - http://download.winfixer.com/files/install...nnerInstall.cab

O20 - Winlogon Notify: msupdate - msupdate32.dll (file missing)

DownLoad http://www.downloads.subratam.org/KillBox.zip

Restart your computer into safe mode now. (Tapping F8 at the first black screen) Perform the following steps in safe mode:

Double-click on Killbox.exe to run it. Now put a tick by Standard File Kill. In the "Full Path of File to Delete" box, copy and paste each of the following lines one at a time then click on the button that has the red circle with the X in the middle after you enter each file. It will ask for confimation to delete the file. Click Yes. Continue with that same procedure until you have copied and pasted all of these in the "Paste Full Path of File to Delete" box.

C:\WINDOWS\SYSTEM32\msblank.html
C:\Documents and Settings\Ed.DOMAIN\Favorites\Antivirus Test Online.url


Note: It is possible that Killbox will tell you that one or more files do not exist. If that happens, just continue on with all the files. Be sure you don't miss any.

START – RUN – type in %temp% OK - Edit – Select all – File – Delete

Delete everything in the C:\Windows\Temp folder or C:\WINNT\temp

Empty the recycle bin
Boot and post a new log from normal NOT safe mode

Please give feedback on what worked/didn’t work and the current status of your system

=====

These appear to be in your E-Mail and should be purged

Personal Folders\Sent Items\FW: YEAR 2000 SPP COMPLIANCE PROGRAM\Southwest Power Pool Compliance Program Contact.doc

Personal Folders\Sent Items\FW: YEAR 2000 SPP COMPLIANCE PROGRAM\Worshop Announcement.doc

Personal Folders\Sent Items\FW: SPP/MISO Combination\sppmisoletteremail.doc

Personal Folders\Sent Items\FW: \ATT00000.html

Personal Folders\Sent Items\FW: YEAR 2000 SPP COMPLIANCE PROGRAM\Southwest Power Pool Compliance Program Contact.doc

Personal Folders\Sent Items\FW: YEAR 2000 SPP COMPLIANCE PROGRAM\Worshop Announcement.doc

Personal Folders\Sent Items\FW: SPP/MISO Combination\sppmisoletteremail.doc

Personal Folders\Sent Items\FW: \ATT00000.html
"Nothing could be finer than to be in South Carolina ............"

Member ASAP

#7 wds

wds
  • Topic Starter

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:10:57 PM

Posted 02 January 2006 - 05:57 PM

I did all the suggested items in your last post. Item 04 - HKLM\..\Run: [MSConfig]..... was not present. I fixed the others with HJT. I deleted the two items you indicated with Killbox. I deleted the temp items and emptied the recycle bin. I have not yet located the Personal Folders items you listed. I will delete them when I find them. I still do not have my desktop back. The desktop background is a solid color, sometimes white sometimes a light blue. It seems to change as you move the mouse across the desktop. HJT Log is posted below. Thanks for the help.
WDS

Logfile of HijackThis v1.99.1
Scan saved at 4:44:11 PM, on 1/2/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
C:\WINDOWS\System32\ScsiAccess.EXE
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Intel\Intel® Active Monitor\imonnt.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\backWeb-7288971.exe
C:\Program Files\Common Files\Sikeston Desktop Alert\TrueWeather.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\HiJack this\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost;<local>
O3 - Toolbar: REALBAR - {4E7BD74F-2B8D-469E-C0FF-FD60B590A87D} - C:\PROGRA~1\COMMON~1\Real\Toolbar\realbar.dll (file missing)
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_3_12_0.dll (file missing)
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: KODAK Software Updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\backWeb-7288971.exe
O4 - Global Startup: Sikeston Desktop Alert.lnk = C:\Program Files\Common Files\Sikeston Desktop Alert\TrueWeather.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .mid: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin2.dll
O12 - Plugin for .mov: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) - http://us.dl1.yimg.com/download.yahoo.com/.../ymmapi_416.dll
O16 - DPF: {B1826A9F-4AA0-4510-BA77-9013E74E4B9B} - http://www.trendmicro.com/spyware-scan/as4web.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{E12FB3AF-40D0-4956-B24F-FBEC4DF90ED3}: NameServer = 69.151.44.9,69.60.160.196
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: Intel® Active Monitor (imonNT) - Intel Corp. - C:\Program Files\Intel\Intel® Active Monitor\imonnt.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: ScsiAccess - Unknown owner - C:\WINDOWS\System32\ScsiAccess.EXE
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

#8 MFDnSC

MFDnSC

    Ret. Director I/T


  • Members
  • 4,310 posts
  • OFFLINE
  •  
  • Local time:10:57 PM

Posted 03 January 2006 - 04:22 PM

Go to post #8

http://forums.techguy.org/security/345137-...blem-fixes.html
"Nothing could be finer than to be in South Carolina ............"

Member ASAP




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users