View Single Post

  #11  
Old 10-17-2005, 08:29 PM
ajrfman Offline
Registered User
 
Join Date: Oct 2005
Posts: 1
It seems you have the Keenvalue Adware. Symantec Security had a removal tool to download at the following URL:

http://securityresponse.symantec.com...e.keenval.html
ajrfman

Quote:
Originally Posted by cimon9999
sorry, couldn't find that link you were talking about.

Here's the scan from BitDefender


//-----------------------------------------------------------------
//
// Product: BitDefender 8 Standard
// Version: (no ver)
//
// Created on: 14/01/2005 22:48:50
//
//-----------------------------------------------------------------


Statistics

Scan path : C:\
Folders : 5181
Files : 723761
Archives : 4994
Packed files : 99994
Identified viruses : 12
Infected files : 13
Warnings : 0
Suspect files : 0
Disinfected files : 0
Deleted files : 2
Copied files : 0
Moved files : 10
Renamed files : 0
I/O errors : 33
Scan time : 01:33:21
Scan speed (files/sec) : 129

Virus definitions : 98195
Scan plugins : 13
Archive plugins : 38
Unpack plugins : 4
Mail plugins : 6
System plugins : 1

Scan options

Detection
[X] Scan boot sectors
[X] Scan archives
[X] Scan packed files
[X] Scan email

File mask
[ ] Programs
[X] All files
[ ] User defined extensions:
[ ] Exclude extensions: ;

Action

Infected objects
[ ] Ignore
[X] Disinfect
[ ] Delete
[ ] Copy to quarantine
[ ] Move to quarantine
[ ] Rename
[ ] Prompt user

Second action
[ ] Ignore
[ ] Delete
[ ] Copy to quarantine
[X] Move to quarantine
[ ] Rename
[ ] Prompt user

Scan options
[X] Enable warnings
[X] Enable heuristics
[ ] Show all files in log
[X] Report file: vscan.log
[ ] Append to existing report

Summary:

C:\Documents and Settings\Eamon Keane\Start Menu\Programs\Startup\PowerReg Scheduler V3.exe Detected: Application.Adware.PowerReg.3.0
C:\Documents and Settings\Eamon Keane\Start Menu\Programs\Startup\PowerReg Scheduler V3.exe Disinfection failed
C:\Documents and Settings\Eamon Keane\Start Menu\Programs\Startup\PowerReg Scheduler V3.exe Moved
C:\Program Files\Common Files\updmgr\rvupdmgr.exe Infected Trojan.Downloader.KeenValue.A
C:\Program Files\Common Files\updmgr\rvupdmgr.exe Disinfection failed
C:\Program Files\Common Files\updmgr\rvupdmgr.exe Moved
C:\Program Files\Common Files\updmgr\simgr.exe Infected Trojan.Downloader.KeenValue.C
C:\Program Files\Common Files\updmgr\simgr.exe Disinfection failed
C:\Program Files\Common Files\updmgr\simgr.exe Moved
C:\Program Files\Common Files\updmgr\updmgr.exe Infected Trojan.Downloader.Keenval.H
C:\Program Files\Common Files\updmgr\updmgr.exe Deleted
C:\Program Files\n-CASE\msbb.exe Detected: Application.Adware.180solutions.A
C:\Program Files\n-CASE\msbb.exe Disinfection failed
C:\Program Files\n-CASE\msbb.exe Moved
C:\updaterInstall_112.exe Infected Backdoor.Blarul.D
C:\updaterInstall_112.exe Disinfection failed
C:\updaterInstall_112.exe Moved
C:\WINDOWS\alchem.exe Infected Trojan.Downloader.Alchemic.A
C:\WINDOWS\alchem.exe Disinfection failed
C:\WINDOWS\alchem.exe Moved
C:\WINDOWS\iNetPal\m3tsp8.exe Infected Trojan.Dropper.Small.JH
C:\WINDOWS\iNetPal\m3tsp8.exe Disinfection failed
C:\WINDOWS\iNetPal\m3tsp8.exe Moved
C:\WINDOWS\preInsTT.exe Detected: Adware.Serchentrix.A
C:\WINDOWS\preInsTT.exe Disinfection failed
C:\WINDOWS\preInsTT.exe Moved
C:\WINDOWS\preInstTT.exe Detected: Adware.Serchentrix.A
C:\WINDOWS\preInstTT.exe Disinfection failed
C:\WINDOWS\preInstTT.exe Moved
C:\WINDOWS\satmat.exe Infected Trojan.Downloader.Stubby.D
C:\WINDOWS\satmat.exe Deleted
C:\WINDOWS\SYSTEM\WinStart001.EXE Detected: Application.BHO.Ignet.A
C:\WINDOWS\SYSTEM\WinStart001.EXE Disinfection failed
C:\WINDOWS\SYSTEM\WinStart001.EXE Moved
C:\WINDOWS\SYSTEM32\ss_msi1_setup.exe=>(NSIS o)=>zlib_nsis0003 Detected: Adware.SideSearch.A
C:\WINDOWS\SYSTEM32\ss_msi1_setup.exe=>(NSIS o)=>zlib_nsis0003 Disinfection failed
C:\WINDOWS\SYSTEM32\ss_msi1_setup.exe=>(NSIS o)=>zlib_nsis0003 Move failed



I dunno if "moved" means that it's been dealt with or not. Does it?
Are there any viruses there that might be causing the problem?
Reply With Quote