You can safely delete Config.Msi
Haha....it's just my signatureNot clear on the purpose of the "My Home Page" link.![]()
You can safely delete Config.Msi
Haha....it's just my signatureNot clear on the purpose of the "My Home Page" link.![]()
Well ... that took a while.
Here are the Kaspersky results:
Objects scanned 397720
Threats found 3
Infected objects found 5
Suspicious objects found 0
Scan duration 05:14:38
E:\Downloads\Kaspersky Internet Security 2009 + Life Time Serial Key\Kaspersky Internet Security 2009 + Life Time Serial Key.exe Infected: Trojan- Downloader.Win32.Agent.cfmy 1
E:\Downloads\OneClickDvdCopy\OneClickDvdCopy5.rar Infected: Trojan.Win32.VBKrypt.cw 1
E:\Installers\BLMInstall265.exe Infected: not-a-virus:NetTool.Win32.Portscan.c 1
E:\Installers\Kaspersky Internet Security 2009 + Life Time Serial Key\Kaspersky Internet Security 2009
+ Life Time Serial Key.exe Infected: Trojan-Downloader.Win32.Agent.cfmy 1
E:\Installers\OneClickDvdCopy5.rar Infected: Trojan.Win32.VBKrypt.cw 1
So five items detected as either threats or infected items.
Some of those items I have no recollection of downloading, and none have been installed. Must have been a case of "seemed like a good idea at the time," but then thought better of it. I don't know what BLMInstall is!And as I have said I am done with warez. I am quite impressed with Kaspersky and one year is $40, so if I want it, that is the way I will get it.
Tempted as I am, I will wait to here from you prior to deletion.
Interesting that none are the detections are Win32: Malware-gen earlier detected by Avast, (which must remember to turn back on.) Plus these are not the same folders. But then these critters can go by many names, and I recall reading that different apps will use different names for the same thing.
Thanks, looking forward to your next post.
Last edited by xero; 06-02-2010 at 12:41 AM.
Please download OTM
- Save it to your desktop.
- Please double-click OTM to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
- Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):
Code::Processes :Services :Reg :Files E:\Downloads\Kaspersky Internet Security 2009 + Life Time Serial Key\Kaspersky Internet Security 2009 + Life Time Serial Key.exe E:\Downloads\OneClickDvdCopy\OneClickDvdCopy5.rar E:\Installers\BLMInstall265.exe E:\Installers\Kaspersky Internet Security 2009 + Life Time Serial Key\Kaspersky Internet Security 2009 + Life Time Serial Key.exe E:\Installers\OneClickDvdCopy5.rar :Commands [purity] [resethosts] [emptytemp] [Reboot]
- Return to OTM, right click in the Paste Instructions for Items to be Movedwindow (under the yellow bar) and choose Paste.
- Click the red Moveit! button.
- Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
- Close OTM and reboot your PC.
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.
Okay, ran OTE and it rebooted the computer.
I could not find the log by either method that you suggested, this is what I did find:
All processes killed
========== PROCESSES ==========
========== SERVICES/DRIVERS ==========
========== REGISTRY ==========
========== FILES ==========
E:\Downloads\Kaspersky Internet Security 2009 + Life Time Serial Key\Kaspersky Internet Security 2009 + Life Time Serial Key.exe moved successfully.
E:\Downloads\OneClickDvdCopy\OneClickDvdCopy5.rar moved successfully.
E:\Installers\BLMInstall265.exe moved successfully.
File/Folder E:\Installers\Kaspersky Internet Security 2009 + Life Time Serial Key\Kaspersky Internet Security 2009 not found.
File/Folder + Life Time Serial Key.exe not found.
E:\Installers\OneClickDvdCopy5.rar moved successfully.
========== COMMANDS ==========
C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
[EMPTYTEMP]
User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: All Users
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: LocalService
->Temp folder emptied: 66016 bytes
->Temporary Internet Files folder emptied: 33170 bytes
User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Russell Chapman
->Temp folder emptied: 93747101 bytes
->Temporary Internet Files folder emptied: 1798344 bytes
->Java cache emptied: 128013 bytes
->FireFox cache emptied: 53572885 bytes
->Google Chrome cache emptied: 0 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 16384 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 197960 bytes
Total Files Cleaned = 143.00 mb
OTM by OldTimer - Version 3.1.8.0 log created on 02062010_092755
Files moved on Reboot...
File move failed. C:\WINDOWS\temp\_avast4_\Webshlock.txt scheduled to be moved on reboot.
C:\WINDOWS\temp\Perflib_Perfdata_638.dat moved successfully.
Registry entries deleted on Reboot...
As you can see it was unable to find the Kaspersky folder in the Installers folder.
And I still cannot drag the Junk folder into the Recycle Bin.
What do you suggest?
Last edited by xero; 06-02-2010 at 02:49 AM. Reason: Grammar
Somehow, the code got broken into two lines. That's why.As you can see it was unable to find the Kaspersky folder in the Installers folder.
Please, remove it manually. Let me know, if any problem. Make sure to empty Recycle Bin afterwards.
What issue are you referring to?And I still cannot drag the Junk folder into the Recycle Bin.
Please, give me fresh HJT log.
Hi Broni,
The Junk file I am referring to is the remnants of the Program Folder that I cannot remove, it is the issue which started this particular ball rolling.
It started with a thread in XP help called Add/Remove blues. You know the usual, "Windows deleted part of the file the rest can be removed manually."
I was able to drag it onto the desktop and every time I try Eraser/Unlocker the folder within it changes name. I have renamed the the folder that used to be a Program Folder as Junk, which I thought appropriate, and reflected how I felt about the thing.
It was in that thread that I mentioned the, what I still consider to be, false positives found by Avast.
Recently Spybot had a similar issue, files would scan fine for malware but show positive for Heuristic. I thought wtf and googled the "malware." First hit was Safer Networking forum where others had queried similar results, and the advice given was there was a glitch and just wait for the next update.
All the places Avast found Win32:Malware-gen were places that had been scanned many times with no result, so my thoughts were that Avast was having a similar "false positive." I think the rest you know, but see the other thread if I have confused you here.
Here is the latest HijackThis:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:45:15 PM, on 2/6/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\ABBYY\FineReader\9.00\Licensing\PE\NetworkLi censeServer.exe
C:\WINDOWS\system32\CNAB3RPK.EXE
C:\WINDOWS\system32\bgsvcgen.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\WinFast\WFDTV\DTVSchdl.exe
C:\Program Files\WinFast\WFDTV\WFWIZ.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Microsoft IntelliPoint\dpupdchk.exe
C:\Program Files\COMODO\COMODO Internet Security\cfp.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Documents and Settings\Russell Chapman\Desktop\utorrent.exe
C:\Program Files\Spybot - Search & Destroy\SDFiles.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
--
End of file - 2151 bytes
Cheers![]()
What's the link to your other thread?
Link: http://www.d-a-l.com/help/windows-xp...ove-blues.html
If you read that thread, just out of interest I somehow happened on this http://usageagent.sourceforge.net/download.htm at Sourceforge. Appears to do the same thing without logging you in, however when I click on the download link all I get is gobbledygook, source code perhaps?
Last edited by xero; 06-02-2010 at 07:07 AM. Reason: Additional information
Is this the folder, you're trying to remove?
C:\Program Files\Westnet Usage Grabber
Well yes and no.
As you would have seen in the other thread I had to delete quite a bit of the file manually. There was one file the app had generated itself that I had to use either Eraser or Unlocker to get rid of. After that I was able to remove most of the contents of the folder manually, either by selecting and deleting, or using Eraser or Unlocker.
What remained was a folder, which when I moused over it, gave a message "Folder is Empty."
Out of, frustration I suppose, I tried dragging it from Program Files on to the Desktop, which worked. All further attempts to remove it have failed. If I drag it into the Recycle Bin I get an error message, "Cannot delete 8BF0TA (this is the folder within what remains of Westnet Usage Grabber, now labelled Junk), the directory is not empty". I can't remember what this folder was originally called, every time I use Eraser or Unlocker the name changes. The folder 8BFOTA, or whatever it was called, behaved in this same manner when it was inside the Program File "Westnet Usage Grabber."
Does that clarify the situation?![]()