User User name Password  
   
Friday 29.8.2025 / 13:37
Search AfterDawn Forums:        In English   Suomeksi   På svenska
afterdawn.com > forums > software, operating systems and more > windows - virus and spyware problems > help!
Show topics
 
Forums
Forums
HELP!
  Jump to:
 
Posted Message
AfterDawn Addict
_
26. November 2006 @ 08:01 _ Link to this message    Send private message to this user   
ok my bitdefender keeps saying that it has prevented some win32.PMF virus or osmn and that i havent been infected?!?! can some take a look...

Logfile of HijackThis v1.99.1
Scan saved at 18:00:40, on 26/11/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\ewido anti-malware\ewidoguard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\tcpsvcs.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe
C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe
C:\Program Files\Common Files\Softwin\BitDefender Update Service\livesrv.exe
C:\Program Files\Softwin\BitDefender9\vsserv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Softwin\BitDefender9\bdmcon.exe
C:\Program Files\Common Files\AOL\1135879776\ee\AOLHostManager.exe
C:\Program Files\Common Files\AOL\1135879776\ee\AOLServiceHost.exe
C:\Program Files\Softwin\BitDefender9\bdoesrv.exe
C:\Program Files\Softwin\BitDefender9\bdnagent.exe
C:\Program Files\Softwin\BitDefender9\bdswitch.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
c:\program files\common files\aol\1135879776\ee\services\antiSpywareApp\ver2_0_12\AOLSP Scheduler.exe
C:\Program Files\Common Files\AOL\1135879776\ee\AOLServiceHost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\AOL 9.0\aoltray.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\HJT\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://search.aol.co.uk/web?isinit=true&query=%s
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1135879776\ee\AOLHostManager.exe
O4 - HKLM\..\Run: [BDMCon] "C:\Program Files\Softwin\BitDefender9\bdmcon.exe"
O4 - HKLM\..\Run: [BDOESRV] "C:\Program Files\Softwin\BitDefender9\bdoesrv.exe"
O4 - HKLM\..\Run: [BDNewsAgent] "C:\Program Files\Softwin\BitDefender9\bdnagent.exe"
O4 - HKLM\..\Run: [BDSwitchAgent] "C:\Program Files\Softwin\BitDefender9\bdswitch.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: AOL 9.0 Tray Icon.lnk = C:\Program Files\AOL 9.0\aoltray.exe
O4 - Global Startup: FreelineSchedule.lnk = C:\Freeline\FreelineSchedule.exe
O8 - Extra context menu item: Add to Kaspersky Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\\ie_banner_deny.htm
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=48835
O16 - DPF: {17D72920-7A15-11D4-921E-0080C8DA7A5E} (AimSp32 Class) - http://makeover.ivillage.co.uk/save/makeover.cab
O16 - DPF: {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} (Cult3D ActiveX Player) - http://www.cult3d.com/download/cult.cab
O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) - http://aolcc.aolsvc.aol.co.uk/computercheckup/qdiagcc.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.com//PhotoUpload/MsnPUpld.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupd...b?1130184847234
O16 - DPF: {90F7E144-984F-4FA6-83A7-C9C8DCB9974C} (RSActiveXObj Control) - http://go.radarsync.com/RSActiveX.ocx
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://driveragent.com/files/driveragent.cab
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logmein.com/activex/ractrl.cab?lmi=100
O17 - HKLM\System\CCS\Services\Tcpip\..\{CA6B6D3D-F481-4DB0-8581-7C5BFF0F6B58}: NameServer = 192.168.0.1
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: talkto - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: klogon - C:\WINDOWS\system32\klogon.dll
O20 - Winlogon Notify: WB - C:\PROGRA~1\Stardock\OBJECT~1\WINDOW~1\fastload.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe" /service (file missing)
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Update Service\livesrv.exe" /service (file missing)
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: BitDefender Virus Shield (VSSERV) - Unknown owner - C:\Program Files\Softwin\BitDefender9\vsserv.exe" /service (file missing)
O23 - Service: BitDefender Communicator (XCOMM) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe" /service (file missing)

psp life = 2.6-1.5 > Custom Firmware Harley G's > 2.0 > 1.5 > C/FW XxPSPmadxX > 2.0 > 1.5 > 2.71 SE-C>swapped 2.5>2.6>1.5>2.0>1.5>3.03 OE-A>3.03OE-B/3.03OE-C
2.80 downgrading guide... http://forums.afterdawn.com/thread_view.cfm/439978
TA-082 downgrading guide.. http://forums.afterdawn.com/thread_view.cfm/441460
TA-082 2.80 downgrading guide.. http://forums.afterdawn.com/thread_view.cfm/444992
Advertisement
_
__
Senior Member
_
27. November 2006 @ 16:59 _ Link to this message    Send private message to this user   
Hello touran22, log is clean. :)

Might want to run an online scan just to be certain.

Run ActiveScan and post back with the log if anything other than cookies is found.

AfterDawn Addict
_
29. November 2006 @ 09:14 _ Link to this message    Send private message to this user   
thanks for checking the log! :) maybe its picking up a blocked virus or osmn from another antivirus? i dunno i dnt really like bitdefender! which one do u recommend? i dnt mind paying!

psp life = 2.6-1.5 > Custom Firmware Harley G's > 2.0 > 1.5 > C/FW XxPSPmadxX > 2.0 > 1.5 > 2.71 SE-C>swapped 2.5>2.6>1.5>2.0>1.5>3.03 OE-A>3.03OE-B/3.03OE-C
2.80 downgrading guide... http://forums.afterdawn.com/thread_view.cfm/439978
TA-082 downgrading guide.. http://forums.afterdawn.com/thread_view.cfm/441460
TA-082 2.80 downgrading guide.. http://forums.afterdawn.com/thread_view.cfm/444992
Senior Member
_
29. November 2006 @ 09:39 _ Link to this message    Send private message to this user   
Quote:
maybe its picking up a blocked virus or osmn from another antivirus?
Not sure I understand that. Do you mean BitDefender is detecting a virus? If so, what is the name?

Quote:
which one do u recommend? i dnt mind paying!
If you want to pay for one, I'd prefer NOD32 or Kaspersky.

NOD32 has the best heuristic scanning of any AV. Kaspersky has the best detection and removal, but it has the slowest scanning engine.

AfterDawn Addict
_
30. November 2006 @ 08:52 _ Link to this message    Send private message to this user   
bitdefender is finding somn like win32.PMF or somn...and also if kaspersky i used kaspersky but it was krapp!! what do you use? i just download stuff of da net and all that crap so i need somn to keep me clean! which one?

psp life = 2.6-1.5 > Custom Firmware Harley G's > 2.0 > 1.5 > C/FW XxPSPmadxX > 2.0 > 1.5 > 2.71 SE-C>swapped 2.5>2.6>1.5>2.0>1.5>3.03 OE-A>3.03OE-B/3.03OE-C
2.80 downgrading guide... http://forums.afterdawn.com/thread_view.cfm/439978
TA-082 downgrading guide.. http://forums.afterdawn.com/thread_view.cfm/441460
TA-082 2.80 downgrading guide.. http://forums.afterdawn.com/thread_view.cfm/444992
Senior Member
_
30. November 2006 @ 14:30 _ Link to this message    Send private message to this user   
Does BitDefender give a file path for this 'win32.PMF'?


I use AVG Anti-virus Pro, AVG Anti-spyware, Spybot Search and Destroy, Ad-Aware, HijackThis, Zone Alarm firewall Pro among many others, but they really aren't necessary for the normal user. Most of them are for specific infections.

Senior Member
_
30. November 2006 @ 14:33 _ Link to this message    Send private message to this user   
dang niobis, you're loaded with programs.
Senior Member
_
30. November 2006 @ 14:41 _ Link to this message    Send private message to this user   
That's only about half my arsenal. I fight unfairly. :D

This message has been edited since posting. Last time this message was edited on 30. November 2006 @ 14:42

AfterDawn Addict
_
2. December 2006 @ 06:32 _ Link to this message    Send private message to this user   
i dunno if it does? when ever it searches it finds that and then it says you havent been infected..

psp life = 2.6-1.5 > Custom Firmware Harley G's > 2.0 > 1.5 > C/FW XxPSPmadxX > 2.0 > 1.5 > 2.71 SE-C>swapped 2.5>2.6>1.5>2.0>1.5>3.03 OE-A>3.03OE-B/3.03OE-C
2.80 downgrading guide... http://forums.afterdawn.com/thread_view.cfm/439978
TA-082 downgrading guide.. http://forums.afterdawn.com/thread_view.cfm/441460
TA-082 2.80 downgrading guide.. http://forums.afterdawn.com/thread_view.cfm/444992
Senior Member
_
2. December 2006 @ 14:26 _ Link to this message    Send private message to this user   
Run the Kaspersky Online Scan to see if it will pick up that file or any others. Save and post the log here.

This message has been edited since posting. Last time this message was edited on 2. December 2006 @ 14:27

AfterDawn Addict
_
3. December 2006 @ 11:54 _ Link to this message    Send private message to this user   
yo man if HijackThis dnt find nutin then im sure its nothin.... what does all those numbers in your sig mean?

psp life = 2.6-1.5 > Custom Firmware Harley G's > 2.0 > 1.5 > C/FW XxPSPmadxX > 2.0 > 1.5 > 2.71 SE-C>swapped 2.5>2.6>1.5>2.0>1.5>3.03 OE-A>3.03OE-B/3.03OE-C
2.80 downgrading guide... http://forums.afterdawn.com/thread_view.cfm/439978
TA-082 downgrading guide.. http://forums.afterdawn.com/thread_view.cfm/441460
TA-082 2.80 downgrading guide.. http://forums.afterdawn.com/thread_view.cfm/444992
Senior Member
_
3. December 2006 @ 12:29 _ Link to this message    Send private message to this user   
Quote:
if HijackThis dnt find nutin then im sure its nothin
That's completely untrue. HijackThis cannot find everything. It only lists what's running, not what is on the computer.

Quote:
what does all those numbers in your sig mean?
:-D It's coded so people don't know, lol.

AfterDawn Addict
_
8. December 2006 @ 05:50 _ Link to this message    Send private message to this user   
ok so what scan shall i do to check if i have a virus if HijackThis doestn pick it up?

psp life = 2.6-1.5 > Custom Firmware Harley G's > 2.0 > 1.5 > C/FW XxPSPmadxX > 2.0 > 1.5 > 2.71 SE-C>swapped 2.5>2.6>1.5>2.0>1.5>3.03 OE-A>3.03OE-B/3.03OE-C
2.80 downgrading guide... http://forums.afterdawn.com/thread_view.cfm/439978
TA-082 downgrading guide.. http://forums.afterdawn.com/thread_view.cfm/441460
TA-082 2.80 downgrading guide.. http://forums.afterdawn.com/thread_view.cfm/444992
Advertisement
_
__
 
_
Senior Member
_
8. December 2006 @ 13:15 _ Link to this message    Send private message to this user   
ActiveScan will work, link in my first post.

afterdawn.com > forums > software, operating systems and more > windows - virus and spyware problems > help!
 

Digital video: AfterDawn.com | AfterDawn Forums
Music: MP3Lizard.com
Gaming: Blasteroids.com | Blasteroids Forums | Compare game prices
Software: Software downloads
Blogs: User profile pages
RSS feeds: AfterDawn.com News | Software updates | AfterDawn Forums
International: AfterDawn in Finnish | AfterDawn in Swedish | AfterDawn in Norwegian | download.fi
Navigate: Search | Site map
About us: About AfterDawn Ltd | Advertise on our sites | Rules, Restrictions, Legal disclaimer & Privacy policy
Contact us: Send feedback | Contact our media sales team
 
  © 1999-2025 by AfterDawn Ltd.

  IDG TechNetwork