Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

bazooka


  • This topic is locked This topic is locked
5 replies to this topic

#1 daxx

daxx

  • Members
  • 26 posts
  • OFFLINE
  •  
  • Local time:01:10 AM

Posted 24 May 2004 - 01:51 PM

this is not a very serious matter (althought i could be wrong)


has anyone had any problems with bazooka bringing up things that you know for a fact are not there? ever since i had the program it has said that i have cometcursor. i have completely cleaned out my system and it still says that i have cometcursor, mysearchbarb, and internet optimizer. i am 99% sure that i do not have any of these because of the regedit and none of the files are present anywhere im my system. could i be wrong or is this a normal problem people are having with bazooka spyware scanner?

BC AdBot (Login to Remove)

 


#2 Grinler

Grinler

    Lawrence Abrams


  • Admin
  • 43,592 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:02:10 AM

Posted 24 May 2004 - 01:55 PM

Quite honestly I do not know much about bazooka other than their online database of files.

If you want to post a hijackthis log though, we can see pretty quickly if any of these files are are found in the registry entiries HJT checks

#3 daxx

daxx
  • Topic Starter

  • Members
  • 26 posts
  • OFFLINE
  •  
  • Local time:01:10 AM

Posted 24 May 2004 - 05:07 PM

Logfile of HijackThis v1.97.7
Scan saved at 6:06:13 PM, on 5/24/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
c:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Softex\OmniPass\Omniserv.exe
C:\Program Files\WZCBDL Service\WZCBDLS.exe
C:\Program Files\Softex\OmniPass\OPXPApp.exe
C:\WINDOWS\Explorer.EXE
C:\windows\system\hpsysdrv.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
C:\Program Files\D-Link\Air USB Utility\AirCFG.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\interMute\SpamSubtract\SpamSubtract.exe
C:\Program Files\HP\hpcoretech\comp\hptskmgr.exe
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\teamspeak2_RC2\TeamSpeak.exe
C:\Program Files\ICQLite\ICQLite.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\Owner\My Documents\HJT\HijackThis.exe
C:\Program Files\HP\hpcoretech\soln\HPOSM.exe

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,Shellnext = http://qus9.hpwis.com/
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "c:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [DeviceDiscovery] C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [D-Link Air USB Utility] C:\Program Files\D-Link\Air USB Utility\AirCFG.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\RunOnce: [ICQ Lite] C:\Program Files\ICQLite\ICQLite.exe -trayboot
O4 - Startup: spamsubtract.lnk = C:\Program Files\interMute\SpamSubtract\SpamSubtract.exe
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: ICQ Lite (HKLM)
O9 - Extra 'Tools' menuitem: ICQ Lite (HKLM)
O9 - Extra button: MoneySide (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Messenger (HKLM)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwa...director/sw.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/7d90ae0...all/xscan53.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload.macromedia.com/pub/shock...ash/swflash.cab







like i said im pretty sure that i dont have any of these , this log doesnt seem to have anything in it that is not supposed to be there , that i can see atleast. but who knows , i suppose i need a second opinion :thumbsup:

#4 Grinler

Grinler

    Lawrence Abrams


  • Admin
  • 43,592 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:02:10 AM

Posted 24 May 2004 - 10:55 PM

According to this log your clean.

Maybe its stuck in your system restore. Disable and enable system restore to wipe out the existing restore points.

#5 Papakid

Papakid

    Guru at being a Newbie


  • Malware Response Team
  • 6,614 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:01:10 AM

Posted 24 May 2004 - 11:51 PM

daxx, I would say if AdAware & Spybot S&D don't find those items and Bazooka does, then it's a false positive on Bazooka's part. It's trying to develope it's data base and welcomes input, so I think you should contact them.

I've not run their scanner either, but I thought hard about it. Since it scans only then gives instructions for manual removal, I didn't think it was worth bothering with. Plus its database of known malware isn't as big as the others. But it is still trying to catch up and develope further so contacting them would probably help them out.

The thing about people

is they change

when they walk away.--Mipso


#6 daxx

daxx
  • Topic Starter

  • Members
  • 26 posts
  • OFFLINE
  •  
  • Local time:01:10 AM

Posted 25 May 2004 - 10:29 AM

alllright guys , i will contact them and let them know the problems. thanks a lot guys. your donations will be on their way at some point.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users