I need help to analyze my actual FreeFixer's scan result

118 views
Skip to first unread message

Arnold Mwamba

unread,
Jun 6, 2012, 1:43:09 AM6/6/12
to FreeFixer User Forum
I had a virus. Thought I had gotten it all off, but computer is having
pop ups saying this program and that program isn't working, when they
are. I know something is not right. I did the scan from freefixer, and
it is below.

Thanks for any help.

FreeFixer v0.62 log
http://www.freefixer.com/
Operating system: Windows 7 Service Pack 1
Log dated 2012-06-06 07:31


AppInit_DLLs
C:\PROGRA~2\IMESHA~1\MediaBar\Datamngr\x64\datamngr.dll
C:\PROGRA~2\IMESHA~1\MediaBar\Datamngr\x64\IEBHO.dll

Browser Helper Objects (3 whitelisted)
{336D0C35-8A85-403a-B9D2-65C292C39087}, Protector by IB, C:\Program
Files\Protector by IB\Extension64.dll
{474597C5-AB09-49d6-A4D5-2E8D7341384E}, UrlHelper Class, C:
\PROGRA~2\IMESHA~1\MediaBar\Datamngr\x64\IEBHO.dll

Internet Explorer toolbars (2 whitelisted)
HKLM\..\Toolbar\Locked - - (no file specified)
HKLM\..\Toolbar\10 - - (no file specified)
HKCU\..\Toolbar\WebBrowser\{CD90BF73-20F6-44EF-993D-BB920303BD2E} - -
(no file specified)
HKCU\..\Toolbar\WebBrowser\{64EAD72B-FFD4-4E01-AA3A-4C71665D73E4} - -
(no file specified)
HKCU\..\Toolbar\WebBrowser\{CC05A3E3-64C3-4AF2-BFC1-AF0D66B69065} - -
(no file specified)
HKCU\..\Toolbar\WebBrowser\{30F9B915-B755-4826-820B-08FBA6BD249D} - -
(no file specified)
HKCU\..\Toolbar\WebBrowser\{872B5B88-9DB5-4310-BDD0-AC189557E5F5} - -
(no file specified)
HKCU\..\Toolbar\WebBrowser\{D4027C7F-154A-4066-A1AD-4243D8127440} - -
(no file specified)

Basic Internet Explorer settings
HKLM\..\Main, Start Page =
http://homepage.emachines.com/rdr.aspx?b=ACEW&l=0407&m=el1850&r=17360910q806pe465v1m5r56n2s262
HKLM\..\Main, Default_Page_URL =
http://homepage.emachines.com/rdr.aspx?b=ACEW&l=0407&m=el1850&r=17360910q806pe465v1m5r56n2s262

Registry Startups (4 whitelisted)
HKCU\..\Run, RocketDock = "C:\Program Files (x86)\RocketDock
\RocketDock.exe"
HKCU\..\Run, Sony Ericsson PC Companion = "C:\Program Files (x86)\Sony
Ericsson\Sony Ericsson PC Companion\PCCompanion.exe" /Background
HKCU\..\Run, VeohPlugin = "C:\Program Files (x86)\Veoh Networks
\VeohWebPlayer\veohwebplayer.exe"
HKCU\..\Run, MediaGet2 = C:\Users\Arnold\AppData\Local
\MediaGet2\mediaget.exe --minimized (file is missing)
HKCU\..\Run, Spiele Post = C:\Program Files (x86)\OXXOGames\GPlayer
\GameCenterNotifier.exe
HKCU\..\Run, SpybotSD TeaTimer = C:\Program Files (x86)\Spybot -
Search & Destroy\TeaTimer.exe
HKCU\..\RunOnce, SpybotDeletingB7009 = command.com /c del "C:
\ProgramData\Babylon\sqlite3.dll" (file is missing)

Autostart shortcuts (1 whitelisted)
HP Digital Imaging Monitor.lnk, , C:\Program Files (x86)\HP\Digital
Imaging\bin\hpqtra08.exe

Processes (50 whitelisted)
C:\Program Files (x86)\Giraffic\Veoh_GirafficWatchdog.exe
C:\Program Files\Protector by IB\ExtensionUpdaterService.exe
C:\Program Files (x86)\Giraffic\Veoh_Giraffic.exe
C:\Program Files (x86)\RocketDock\RocketDock.exe
C:\Program Files (x86)\Veoh Networks\VeohWebPlayer\VeohWebPlayer.exe
C:\Program Files (x86)\OXXOGames\GPlayer\GameCenterNotifier.exe
C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files (x86)\Winamp\winampa.exe
C:\Program Files (x86)\Ask.com\Updater\Updater.exe
C:\Program Files (x86)\iMesh Applications\MediaBar\Datamngr
\datamngrUI.exe
C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqste08.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files (x86)\HotVirtualKeyboard\hvk.exe
C:\Program Files\FreeFixer\freefixer.exe

Services (60 whitelisted)
Giraffic, Veoh Giraffic Video Accelerator, c:\program files
(x86)\giraffic\veoh_girafficwatchdog.exe
Protector by IB Updater, Protector by IB Updater, c:\program files
\protector by ib\extensionupdaterservice.exe

Svchost.exe Modules (242 whitelisted)
c:\windows\system32\hpzinw12.dll
c:\windows\system32\hpzipm12.dll

Csrss.exe virtual memory files (208 whitelisted)
c:\program files (x86)\hp\digital imaging\bin\hpqcxs08.dll
c:\program files (x86)\hp\digital imaging\bin\hpqddsvc.dll
c:\program files (x86)\hp\digital imaging\bin\hpqddcmn.dll
C:\PROGRA~2\IMESHA~1\MediaBar\Datamngr\x64\datamngr.dll
C:\Program Files\Alwil Software\Avast5\Setup\SetIFace.dll
Failed to calculate hash for 'C:\Program Files\Alwil Software
\Avast5\Setup\SetIFace.dll' using
'CryptCATAdminCalcHashFromFileHandle' while verifying trust. System
error message: %1 ist keine zulässige Win32-Anwendung. Error code:
-2147024703.
C:\Users\Arnold\Downloads\Set-Ups\freefixersetup.exe
C:\Program Files (x86)\Giraffic\Veoh_GirafficWatchdog.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpocxi08.dll
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqcob08.dll
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqbam08.exe
C:\PROGRA~2\IMESHA~1\MediaBar\Datamngr\datamngr.dll
C:\Program Files\Protector by IB\ExtensionUpdaterService.exe
C:\Program Files (x86)\Giraffic\Veoh_Giraffic.exe
C:\Program Files (x86)\HotVirtualKeyboard\hvk.exe
C:\Program Files (x86)\Sony Ericsson\Sony Ericsson PC Companion
\PCCompanionInfo.exe
C:\Program Files (x86)\Veoh Networks\VeohWebPlayer\LIBEAY32.dll
c:\program files (x86)\real\realplayer\lang\upgrade_de.dll
c:\program files (x86)\adobe\reader 9.0\reader\rdlang32.deu
C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Chrome\Hook
\rpchrome150browserrecordhelper.dll
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqstp08.dll
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtao08.dll
C:\Program Files (x86)\Real\RealUpgrade\plugins\upgrade.dll
C:\Program Files (x86)\HP\Digital Imaging\bin\hpotradd.dll
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpotra08.rsc
C:\Program Files (x86)\HP\Digital Imaging\bin\HpqSRmon.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpb01.dll
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.rsc
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqusg.dll
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqmif08.dll
C:\Program Files (x86)\HP\Digital Imaging\bin\hpquio08.dll
C:\Program Files (x86)\DivX\DivX Update\DivXUpdateCheck.dll
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqrif08.dll
C:\Program Files (x86)\HP\Digital Imaging\bin\hpotra08.dll
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqddusr.dll
C:\Program Files (x86)\Adobe\Reader 9.0\Reader\BIB.dll
C:\Program Files (x86)\HP\Digital Imaging\bin\HpqSRTA.dll
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqsem08.rsc
C:\Program Files (x86)\HP\Digital Imaging\bin\hpodio08.dll
C:\Program Files (x86)\RocketDock\RocketDock.dll
C:\Program Files (x86)\RocketDock\RocketDock.exe
C:\Program Files (x86)\Opera\gstreamer\plugins\gstcoreplugins.dll
C:\Program Files (x86)\Opera\gstreamer\plugins\gstwavparse.dll
C:\Program Files (x86)\Veoh Networks\VeohWebPlayer\ssleay32.DLL
C:\Program Files (x86)\Opera\gstreamer\plugins\gstdecodebin2.dll
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files (x86)\Opera\gstreamer\plugins\gstdirectsound.dll
C:\Program Files (x86)\Opera\gstreamer\plugins\gstaudioresample.dll
C:\Program Files (x86)\Opera\gstreamer\plugins\gstwaveform.dll
C:\Program Files (x86)\Opera\gstreamer\plugins\gstautodetect.dll
C:\Program Files (x86)\Opera\gstreamer\plugins\gstoggdec.dll
C:\Program Files (x86)\Opera\gstreamer\plugins\gstaudioconvert.dll
C:\Program Files (x86)\Opera\gstreamer\plugins\gstwebmdec.dll
C:\Program Files (x86)\Ask.com\SaUpdate.exe
C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AGM.dll
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqste08.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqxml2.dll
C:\Program Files (x86)\Adobe\Reader 9.0\Reader\ACE.dll
C:\Program Files (x86)\Veoh Networks\VeohWebPlayer\phonon4.dll
C:\Program Files (x86)\Real\RealUpgrade\common\hxmedpltfm.dll
C:\Program Files (x86)\Veoh Networks\VeohWebPlayer\QtCore4.dll
C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files (x86)\Veoh Networks\VeohWebPlayer\IPCClient.EXE
C:\Program Files (x86)\Veoh Networks\VeohWebPlayer\QtGui4.dll
C:\Program Files (x86)\OXXOGames\GPlayer\GameCenterNotifier.exe
C:\Program Files (x86)\Veoh Networks\VeohWebPlayer\QtWebKit4.dll
C:\Program Files (x86)\Veoh Networks\VeohWebPlayer\QtNetwork4.dll
C:\Program Files (x86)\Veoh Networks\VeohWebPlayer\QtScript4.dll
C:\Program Files (x86)\Ask.com\UpdateTask.exe
C:\Program Files (x86)\Sony Ericsson\Sony Ericsson PC Companion
\PluginManager.dll
C:\Program Files (x86)\Sony Ericsson\Sony Ericsson PC Companion
\bvrpctln.dll
C:\Program Files (x86)\Sony Ericsson\Sony Ericsson PC Companion
\TMonitorAPI.dll
C:\Program Files (x86)\Sony Ericsson\Sony Ericsson PC Companion
\PCCompanion.exe
C:\Program Files (x86)\Sony Ericsson\Sony Ericsson PC Companion
\BackupRestore.dll
C:\Program Files (x86)\Sony Ericsson\Sony Ericsson PC Companion
\PCCompanion.dll
C:\Program Files (x86)\Sony Ericsson\Sony Ericsson PC Companion
\WUNPACLN.dll
C:\Program Files (x86)\Sony Ericsson\Sony Ericsson PC Companion
\DownloadManager.dll
C:\Program Files (x86)\Sony Ericsson\Sony Ericsson PC Companion
\Statistics.dll
C:\Program Files (x86)\HP\Digital Imaging\Product Assistant\bin
\hprbevst.dll
C:\Program Files (x86)\Sony Ericsson\Sony Ericsson PC Companion
\PhoneUpdate.dll
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static
\CLIStart.exe
C:\Program Files (x86)\Veoh Networks\VeohWebPlayer\VeohWebPlayer.exe
C:\Program Files (x86)\iMesh Applications\MediaBar\Datamngr
\datamngrUI.exe
C:\Program Files (x86)\Sony Ericsson\Sony Ericsson PC Companion
\Device.dll
C:\Program Files (x86)\Sony Ericsson\Sony Ericsson PC Companion
\Report.dll
C:\Program Files (x86)\Veoh Networks\VeohWebPlayer\imageformats
\qjpeg4.dll
C:\Program Files (x86)\Veoh Networks\VeohWebPlayer\imageformats
\qgif4.dll
C:\Program Files (x86)\Opera\gstreamer\plugins\gstffmpegcolorspace.dll
C:\Program Files (x86)\Opera\gstreamer\plugins
\gsttypefindfunctions.dll
C:\Program Files\Common Files\ATI Technologies\Multimedia
\atixcode64.dll
C:\Program Files\Common Files\ATI Technologies\Multimedia
\atimpenc64.dll
C:\Program Files (x86)\QuickTime\QTTask.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqsti08.dll
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqwso08.dll
C:\Program Files (x86)\Adobe\Reader 9.0\Reader\CoolType.dll
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpreh.dll
C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\HpqCPTA.dll
C:\Program Files (x86)\Adobe\Reader 9.0\Reader\sqlite.dll
C:\Program Files (x86)\Opera\gstreamer\gstreamer.dll
C:\Program Files\FreeFixer\freefixer.exe
C:\Users\Arnold\Downloads\unlocker1.9.1.exe
C:\Program Files (x86)\Ask.com\Updater\Updater.exe

The following errors occurred during the scan:
An unexpected exception occurred in the Recently Modified Files
Plugin:
Failed to duplicate handle using 'DuplicateHandle'. System error
message: Zugriff verweigert. Error code: 5.

End of FreeFixer log

Roger Karlsson

unread,
Jun 8, 2012, 2:32:33 AM6/8/12
to freefix...@googlegroups.com
> Search& Destroy\TeaTimer.exe
> HKCU\..\RunOnce, SpybotDeletingB7009 = command.com /c del "C:
> \ProgramData\Babylon\sqlite3.dll" (file is missing)
>
> Autostart shortcuts (1 whitelisted)
> HP Digital Imaging Monitor.lnk, , C:\Program Files (x86)\HP\Digital
> Imaging\bin\hpqtra08.exe
>
> Processes (50 whitelisted)
> C:\Program Files (x86)\Giraffic\Veoh_GirafficWatchdog.exe
> C:\Program Files\Protector by IB\ExtensionUpdaterService.exe
> C:\Program Files (x86)\Giraffic\Veoh_Giraffic.exe
> C:\Program Files (x86)\RocketDock\RocketDock.exe
> C:\Program Files (x86)\Veoh Networks\VeohWebPlayer\VeohWebPlayer.exe
> C:\Program Files (x86)\OXXOGames\GPlayer\GameCenterNotifier.exe
> C:\Program Files (x86)\Spybot - Search& Destroy\TeaTimer.exe
> C:\Program Files (x86)\Spybot - Search& Destroy\TeaTimer.exe
Hello,

I've examined the log and could not find any malware.

You might also want to try MalwareBytes scanner to have a look at your
system.

/Roger
Reply all
Reply to author
Forward
0 new messages