Kaspersky online virus scan - result

Kaspersky online virus scan - result

Secure Home | Search | About
 Microsoft Antivirus Discussions    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Kaspersky online virus scan - result BoaterDave 12-09-2006
Posted by BoaterDave on December 9, 2006, 7:43 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Do you mean this info, Dave?

C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
______________________________________________________

>
> | Whilst with you, Dave,
> |
> | When I've used HijackThis, I get two entries, thus:-
> |
> | O4 - Global Startup: hp psc 1000 series.lnk = ?
> | O4 - Global Startup: hpoddt01.exe.lnk = ?
> |
> | I've experimented quite a lot with the HJT facility, just out of
> interest.
> | When I have selected to delete *these* entries, I receive a message
> which
> | says that it
> | is an unexpected result and to report same to Merijn (something I've
> tried
> | to do and failed!).
> |
> | Do you know if these entries are 'legitimate'? (I do have an HP psc
> | 1215)
> |
> | David.
>
> While not 100% certain, I believe them to be legit.
>
> What is MORE important is is the fully qualified name and path of the file
> being loaded in
> eacj LNK file.
>
> --
> Dave
> http://www.claymania.com/removal-trojan-adware.html
> http://www.ik-cs.com/got-a-virus.htm
>
>




Posted by David H. Lipman on December 9, 2006, 9:00 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

| Do you mean this info, Dave?
|
| C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe

Bingo !

However, that was one of two links (.LNK).

I am sure the second is similar.

--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm



Posted by BoaterDave on December 10, 2006, 8:46 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Hi Dave.

I hope you won't mind having a look at the whole log, posted later (below)
(this PC is virtually empty anyway!)
I've have (for now!) removed the two 04 entries relating to the HP link:-

This is the message I received:-
_______________________________________

Unexpected error occurred!
Error #52 (Bad file name or number) in Sub GetLongPath(?.exe).

Please send a report to merijn@spywareinfo.com, mentioning what you were
doing, and what version of Windows you have.

This message has been copied to your clipboard.

______________________________________________

I've experimented over the last 12 months with deleting just about
everything found by HijackThis - NO other such warning message has ever been
received - *just* when removing the HP links! I find that strange .... but
then I'm no expert!

I'd appreciate your further thoughts on this. One other small point. Windows
Defender has reported that there has been a 'Services and Driver'change viz:
C:\Windows\System32\ZDBRGSYS.SYS (PCAUSA NDIS 5.0 Protocol Driver) but so
far I haveen't permitted (or denied) the change.

TIA

David
________________________________________________________________


Logfile of HijackThis v1.99.1
Scan saved at 23:51:48, on 09/12/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\System32\GEARSec.exe
C:\Program Files\Norton Ghost\Agent\VProSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Norton Ghost\Agent\GhostTray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\WLAN2.11b+g USB WLAN\ZDWlan.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\WINDOWS\System32\dllhost.exe
C:\WINDOWS\System32\vssvc.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\Program Files\Windows Defender\MSASCui.exe
D:\HiJackThis\hijackthis\HijackThis.exe

O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec
Shared\ccApp.exe"
O4 - HKLM\..\Run: [Norton Ghost 10.0] "C:\Program Files\Norton
Ghost\Agent\GhostTray.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows
Defender\MSASCui.exe" -hide
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe"
/background
O4 - HKCU\..\Run: [dlmMgr] "C:\Program Files\Common
Files\Adobe\ESD\AdobeDownloadManager.exe" restart=1
O4 - Global Startup: hp psc 1000 series.lnk = ?
O4 - Global Startup: hpoddt01.exe.lnk = ?
O9 - Extra button: Messenger - -
C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger -
- C:\Program
Files\Messenger\msmsgs.exe
O16 - DPF: (CKAVWebScan Object) -
http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: (Windows Genuine Advantage
Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation -
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec
Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation -
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: GEARSecurity - GEAR Software -
C:\WINDOWS\System32\GEARSec.exe
O23 - Service: Norton Ghost - Symantec Corporation - C:\Program Files\Norton
Ghost\Agent\VProSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program
Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe




>
> | Do you mean this info, Dave?
> |
> | C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
>
> Bingo !
>
> However, that was one of two links (.LNK).
>
> I am sure the second is similar.
>
> --
> Dave
> http://www.claymania.com/removal-trojan-adware.html
> http://www.ik-cs.com/got-a-virus.htm
>
>



Posted by David H. Lipman on December 10, 2006, 11:17 am
If you were  Registered and logged in, you could reply and use other advanced thread options

| Hi Dave.
|
| I hope you won't mind having a look at the whole log, posted later (below)
| (this PC is virtually empty anyway!)
| I've have (for now!) removed the two 04 entries relating to the HP link:-
|
| This is the message I received:-
| _______________________________________


Yes, I do mind.

News Groups don't allow the posting of HJT Logs. You should have asked first !

Forums where you can get expert advice for HiJack This! (HJT) logs.

NOTE: Registration is not required in the below before posting a log
http://www.thespykiller.co.uk/forum/?action=forum


NOTE: Registration is REQUIRED in any of the below before posting a log
http://www.bleepingcomputer.com/forums/forum22.html
http://castlecops.com/forum67.html
http://www.dslreports.com/forum/cleanup
http://www.cybertechhelp.com/forums/forumdisplay.php?f=25
http://www.atribune.org/forums/index.php?showforum=9
http://www.geekstogo.com/forum/Malware_Removal_HiJackThis_Logs_Go_Here-f37.html
http://gladiator-antivirus.com/forum/index.php?showforum=170
http://forum.networktechs.com/forumdisplay.php?f=130
http://forums.maddoktor2.com/index.php?showforum=17
http://www.spywarewarrior.com/viewforum.php?f=5
http://forums.spywareinfo.com/index.php?showforum=18
http://forums.techguy.org/f54-s.html
http://forums.tomcoyote.org/index.php?showforum=27
http://forums.subratam.org/index.php?showforum=7
http://www.5starsupport.com/ipboard/index.php?showforum=18
http://www.malwarebytes.org/forums/index.php?showforum=7
http://makephpbb.com/phpbb/viewforum.php?f=2
http://forums.techguy.org/54-security/
http://forums.security-central.us/forumdisplay.php?f=13


--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm



Posted by BoaterDave on December 10, 2006, 1:04 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
<grovelling!> I apologise. I had no wish to offend.

You stated in your previous post:
"However, that was one of two links (.LNK). I am sure the second is
similar".

I couldn't identify "a similar" pathway, which was why I thought it might be
best to show you the whole scan (especially as it is so short). I now
recognise that I should have asked first. All I can say, Dave, is - I'm
sorry.

This PC has been troubling me for over 12 months now. I started out trying
to discover just how someone had been able to steal my identity in the
summer of 2005 (via eBay/PayPal) It's a long story; suffice to say that I
*did* have my money refunded. I was slightly mystified, though, as I'd been
following security advice for years. I have since been trying to identify a
culprit. I've learnt much yet have still to identify just how it was done.

I'm aware that you have an excellent reputation in this field and, as you
had responded to my initial query here, I had hoped that you, too, might
have been interested in helping me with the unusual (to me) message received
on HJT.

FWIW

David
________________________________________________________


>
> | Hi Dave.
> |
> | I hope you won't mind having a look at the whole log, posted later
> (below)
> | (this PC is virtually empty anyway!)
> | I've have (for now!) removed the two 04 entries relating to the HP
> link:-
> |
> | This is the message I received:-
> | _______________________________________
>
>
> Yes, I do mind.
>
> News Groups don't allow the posting of HJT Logs. You should have asked
> first !
>
> Forums where you can get expert advice for HiJack This! (HJT) logs.
>
> NOTE: Registration is not required in the below before posting a log
> http://www.thespykiller.co.uk/forum/?action=forum
>
>
> NOTE: Registration is REQUIRED in any of the below before posting a log
> http://www.bleepingcomputer.com/forums/forum22.html
> http://castlecops.com/forum67.html
> http://www.dslreports.com/forum/cleanup
> http://www.cybertechhelp.com/forums/forumdisplay.php?f=25
> http://www.atribune.org/forums/index.php?showforum=9
> http://www.geekstogo.com/forum/Malware_Removal_HiJackThis_Logs_Go_Here-f37.html
> http://gladiator-antivirus.com/forum/index.php?showforum=170
> http://forum.networktechs.com/forumdisplay.php?f=130
> http://forums.maddoktor2.com/index.php?showforum=17
> http://www.spywarewarrior.com/viewforum.php?f=5
> http://forums.spywareinfo.com/index.php?showforum=18
> http://forums.techguy.org/f54-s.html
> http://forums.tomcoyote.org/index.php?showforum=27
> http://forums.subratam.org/index.php?showforum=7
> http://www.5starsupport.com/ipboard/index.php?showforum=18
> http://www.malwarebytes.org/forums/index.php?showforum=7
> http://makephpbb.com/phpbb/viewforum.php?f=2
> http://forums.techguy.org/54-security/
> http://forums.security-central.us/forumdisplay.php?f=13
>
>
> --
> Dave
> http://www.claymania.com/removal-trojan-adware.html
> http://www.ik-cs.com/got-a-virus.htm
>
>



Similar ThreadsPosted
Can't run online scan November 19, 2005, 3:46 pm
PC shuts off on Virus Scan September 23, 2005, 7:22 pm
McAfee Virus Scan Lock Up July 2, 2006, 3:09 pm
Does MS Anti-Virus scan while downloading? December 16, 2006, 9:59 am
Unable to complete virus scan November 24, 2008, 2:07 pm
Virus Scan SCSI HDD for Server HP ML370 Series G4 Series October 13, 2008, 10:06 am
Kaspersky AV July 29, 2006, 8:37 am
I like using Kaspersky January 5, 2007, 4:45 pm
AVG conflict with Kaspersky? July 13, 2007, 12:47 am
Kaspersky flags dmocy.exe as trojan? April 21, 2006, 1:36 am

The site map in XML format XML site map

Contact Us | Privacy Policy