Bullguard Antivirus Forum Download A Free Copy Of Bullguard Antivirus Software
Free Antivirus Forum - Learn about antivirus, firewalls and personal security Free Antivirus Forum - Learn about antivirus, firewalls and personal security
 HomeLog InRegisterCommunity CalendarSearch the ForumView The Member ListHelp
No-Subject
   
BullGuard Antivirus Forum > Virus Removal > Removal Help > No-Subject  
Forum Quick Jump
 
New Topic Post reply to : No-Subject Printable version of : No-Subject
[ << Previous Thread | Next Thread >> ]

anim8
New Member


Date Joined Nov 2004
Total Posts : 2
 
   Posted 11-12-2004 2:52 (GMT +1)    Quote: No-SubjectAlert an admin about: No-Subject
Hi, can anyone take a look at this, and let me know what to do.
AVG detected keenval.o but then doesn't find it when scanning.
S&D detects huntbar and something else but can't remove it.
Ad-aware shows everything o.k. now.
here's my hijack log.
thanks.
 
ok maybe not says I can't upload file that use mime type
help....
Back to Top
 

anim8
New Member


Date Joined Nov 2004
Total Posts : 2
 
   Posted 11-12-2004 2:55 (GMT +1)    Quote: No-SubjectAlert an admin about: No-Subject
duh! nevermind, here we go.
Logfile of HijackThis v1.98.0
Scan saved at 8:58:32 AM, on 12/11/2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG6\avgserv.exe
C:\WINNT\System32\DRIVERS\CDANTSRV.EXE
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\ZoneLabs\vsmon.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exe
C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe
C:\WINNT\system32\internat.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\3web\system\launcher.exe
C:\Program Files\3web\system\cydial95.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
C:\Program Files\HijackThis1.98\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.ca/
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\winnt\googlenav0.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\winnt\googlenav0.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [QBCD Autorun] D:\autorun.exe restart QB_SEQUENCE first
O4 - HKLM\..\Run: [NeroCheck] C:\WINNT\system32\\NeroCheck.exe
O4 - HKLM\..\Run: [Zone Labs Client] C:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exe
O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe /STARTUP
O4 - HKCU\..\Run: [internat.exe] internat.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {EE5CA45C-BFAC-48E6-BE6C-3C607620FF43} (IMViewerControl Class) - http://companion.logitech.com/companion/bin/imvid.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{908CC77D-ABA3-4EB5-AE6C-4CFAFAC01F75}: NameServer = 209.197.128.2 209.195.95.95


Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 14296
 
   Posted 11-12-2004 5:27 (GMT +1)    Quote: No-SubjectAlert an admin about: No-Subject
Heycool
http://securityresponse.symantec.com/avcenter/venc/data/adware.keenval.html
Scroll down to-removal instructions. Tell if it help;-)
Your log is cleansmilewinkgrin
Install these for safer surfing:
Check for updates for Windows and Internet Explorer every week or so. Download each critical update one by one, rebooting when necessary.. Repeat this until you get the message "no critical updates available"

http://windowsupdate.microsoft.com/



Touch
Back to Top
 
New Topic Post reply to : No-Subject Printable version of : No-Subject
 
Forum Information
Currently it is Wednesday, January 07, 2009 8:39 AM (GMT +1)
There are a total of 65.888 posts in 16.170 threads.
In the last 3 days there were 21 new threads and 93 reply posts. View Active Threads
Who's Online
This forum has 27768 registered members. Please welcome our newest member, Van_D.
44 Guest(s), 0 Registered Member(s) are currently online.  Details
5 Latest Threads
Slow laptop, odd files and ~60 processes (2)07-01-2009 06:17:36 (squid_liquor)
Slow computer;can't use restore (7)07-01-2009 01:46:51 (vandnbyriver)
~tmpa.exe + ~tmpb.exe problem! could you help? (3)07-01-2009 01:30:34 (Van_D)
Removal of explorer.exe virus (8)07-01-2009 00:58:14 (Georgia49)
Some nasty trojan (2)06-01-2009 22:46:49 (buioch)