Download TrojanHunter Now
Free 30-day trial!
Latest TrojanHunter Version:
TrojanHunter 5.0
Order Now
License file delivered within minutes.
Welcome, Guest. Please Login or Register.
Oct 13th, 2008, 11:47am
   Mischel Internet Security Forum
   TrojanHunter
   TrojanHunter Scanner
(Moderators: Helena, Gavin_Coe, Magnus)
   Error
« Previous topic | Next topic »
Pages: 1 2  Reply Reply  Notify of replies Notify of replies   Send Topic Send Topic   Print Print
   Author  Topic: Error  (Read 905 times)
Hokie1
Newbie
*






   


Posts: 20
Error
« on: May 16th, 2008, 6:12pm »
Quote Quote  Modify Modify

Started receiving this error today when trying to load the scanner; Exception Processing Message c0000013 Parameters 75b6bf9c 4 75b6bf9c 75b6bf9c.
 
Have uninstalled and re-installed three times, nothing changed.
IP Logged

Never, ever approach a computer saying or even thinking "I will just do this quickly".
siliconman01
Global Moderator
*****



Trojans! Chew 'em Up, Spit 'em Out...

   


Gender: male
Posts: 5671
Re: Error
« Reply #1 on: May 16th, 2008, 11:56pm »
Quote Quote  Modify Modify

What Windows operating system are you running (with service pack number)?  
 
Will TH load if you are rebooted into SAFE MODE?
 
Have you recently added any new programs or service packs to your system?  
 
Try putting a CD/DVD in your CD/DVD drives and a floppy in your floppy drive (blanks okay) and see if you can open TH without the getting the error.  
 
Next, be sure THGuard and TrojanHunter scanner are closed.  Locate the file named TreeState.dat and delete it.  Then open TH scanner which will rebuild the TreeState.dat file.
« Last Edit: May 17th, 2008, 12:06am by siliconman01 » IP Logged

______
TrojanHunter V5.0.962...No. 1 AT in my Book and on my Box!
Hokie1
Newbie
*






   


Posts: 20
Re: Error
« Reply #2 on: May 19th, 2008, 4:33pm »
Quote Quote  Modify Modify

Windows XP Pro SP2.
 
The top of the error reads; Windows-No Disk.
 
Error displays with CD and Floppy.
 
Removing .DAT file didn't change anything.
 
This started after both TH and McAfee reported a Trojan. Couldn't get TH to scan so I ended up removing it with McAfee. McAfee defined the Trojan as Adware-ZangoSA.
 
Trojan Guard appears to load and run ok, only affects the scanner.
« Last Edit: May 19th, 2008, 4:37pm by Hokie1 » IP Logged

Never, ever approach a computer saying or even thinking "I will just do this quickly".
siliconman01
Global Moderator
*****



Trojans! Chew 'em Up, Spit 'em Out...

   


Gender: male
Posts: 5671
Re: Error
« Reply #3 on: May 20th, 2008, 2:11am »
Quote Quote  Modify Modify

Hmmm... It appears that something has become misconfigured in your registery...caused by adware-ZangoSA probably.
 
-  Would you please download/install/run CCleaner from the website below.  This will clean out junk and temp files from your system.  DO NOT run the Registry cleaning component of CCleaner.  
 
http://www.ccleaner.com
 
-  Would you please download/install Hijackthis from the link below.  Then run a scan and post the scan log back here.  I would like to see if anything malicious is showing in your HJT log.
 
http://www.misec.net/forum/board/FAQ/1163329424
 
-  Do you already have any registry cleaning programs on your system?  
 
-  Also, upgrading your XP-Pro SP2 to XP-Pro SP3 will probably straighten things out too.  IF you are running an AMD CPU, do not upgrade to SP3 as there is a problem with SP3 and AMD CPU systems.  
« Last Edit: May 20th, 2008, 2:40am by siliconman01 » IP Logged

______
TrojanHunter V5.0.962...No. 1 AT in my Book and on my Box!
Hokie1
Newbie
*






   


Posts: 20
Re: Error
« Reply #4 on: May 20th, 2008, 6:45pm »
Quote Quote  Modify Modify

Hi again,
 
The error pops up in Safe Mode but the scanner runs without freezing up. The scan didn't find any Trojans.  
 
Neither Spy Sweeper or McAfee found any problems droning their scans.
 
I use cCleaner all the time, with the Registry cleaner and SAVE the Back-ups. I also use Registry Smoker, have run both Safe Scan and Deep Scan, it removed a lot of TH Guard items.  
 
I uninstalled/reinstalled again, this makes four times, nothing changed.  
 
I also run the paid version of Info Task and I don't see any thing unusual running in the back ground.  
 
I also use Anonymizer Total Net Shield.  
 
I have no other problems.  
 
This computer has an AMD CPU.  
 
Will run Hijackthis, I have a copy.
 
Thanks and make it a great day!
 
IP Logged

Never, ever approach a computer saying or even thinking "I will just do this quickly".
Hokie1
Newbie
*






   


Posts: 20
Re: Error
« Reply #5 on: May 20th, 2008, 7:33pm »
Quote Quote  Modify Modify

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:09:41 PM, on 5/20/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal
 
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
C:\Program Files\Olympus\DeviceDetector\DM1Service.exe
C:\PROGRA~1\Iomega\System32\AppServices.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\WINDOWS\Explorer.EXE
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\PROGRA~1\McAfee\MPS\mps.exe
C:\Program Files\Startup Faster 2004\sfAgent.exe
C:\Program Files\McAfee\MPS\mpsevh.exe
C:\WINDOWS\system32\PGPserv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Griffin Technology\PowerMate\PowerMate.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\A4Tech\Keyboard\Ikeymain.exe
C:\Program Files\PC Magazine Utilities\InstaBack 2\InstaBack.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\PC Magazine Utilities\NoteWhen\NoteWhen.exe
C:\Program Files\Say the Time\SayTime.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Say the Time\SayTime.exe
C:\Program Files\WinRoll\winroll.exe
C:\Program Files\Iconoid\iconoid.exe
C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\YPOPs\YPOPs.exe
C:\Program Files\Fanix\As-U-Type\AsutypeFull.exe
C:\Program Files\Anonymizer TNS\AnonTns.exe
C:\Program Files\XNeat Windows Manager\xnViewer.exe
C:\Program Files\XNeat Windows Manager\XNeatWM.exe
C:\Program Files\Olympus\DeviceDetector\DevDtct2.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\JGsoft\EditPadPro5\EditPadPro.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
 
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer powerd by Woodshed
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 127.0.0.1:80
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localxp.jungledisk.com;*.local;<local>
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: btorbit.com - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files\Orbitdownloader\orbitcth.dll
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptcl.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O3 - Toolbar: &Netcraft Toolbar - {D554D8FC-B36D-4BB4-93DB-4A3394D505E3} - C:\Program Files\Netcraft Toolbar\nctb.dll
O3 - Toolbar: 1-Click Answers - {7754C418-F62E-44aa-B169-E719E718BCFD} - C:\PROGRA~1\1-CLIC~1\IEToolbar\AnswersToolbarU.dll
O4 - HKLM\..\Run: [StartupFaster] "C:\Program Files\Startup Faster 2004\StrpFstCfg.exe" -run SFAURUN SFCURUN SFAUSTARTUP SFCUSTARTUP
O4 - Startup: StartupFaster
O4 - Global Startup: StartupFaster
O8 - Extra context menu item: &Download by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/201
O8 - Extra context menu item: &Grab video by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/204
O8 - Extra context menu item: Answers... - file://C:\Program Files\1-Click Answers\Html\atiemenu.htm
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: Do&wnload selected by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/203
O8 - Extra context menu item: Down&load all by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/202
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: Open with Scansoft PDF Converter 3.0 - res://C:\Program Files\ScanSoft\PDF Professional 3.0\IEShellExt.dll /100
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: Movies Extractor Scout - {08883BD3-6422-4C13-BC44-F023CE6A3E70} - C:\Program Files\Bytescout Movies Extractor Scout\flashextract.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {FF1CD9A3-00CD-45C1-8182-4EEC229A182D} (Plaxo Auto-Import Utility) - https://www.plaxo.com/activex/plx_upldr-2k-xp.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{FF4C7FC8-65F9-414F-81B2-67A265868723} : NameServer = 208.67.222.222,208.67.220.220
O20 - AppInit_DLLs: PGPmapih.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: DM1Service - OLYMPUS IMAGING CORP. - C:\Program Files\Olympus\DeviceDetector\DM1Service.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Iomega App Services - Iomega Corporation - C:\PROGRA~1\Iomega\System32\AppServices.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Privacy Service (MPS9) - McAfee, Inc. - C:\PROGRA~1\McAfee\MPS\mps.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PGPserv - PGP Corporation - C:\WINDOWS\system32\PGPserv.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
 
--
End of file - 11161 bytes
IP Logged

Never, ever approach a computer saying or even thinking "I will just do this quickly".
siliconman01
Global Moderator
*****



Trojans! Chew 'em Up, Spit 'em Out...

   


Gender: male
Posts: 5671
Re: Error
« Reply #6 on: May 20th, 2008, 11:44pm »
Quote Quote  Modify Modify

Hmmm,
 
The only thing I see in your HJT log is that your Java is out-of-date.  Update 6 is available.
 
http://www.java.com
 
or the Java Runtime Environment (JRE) 6 Update 6 download at  
 
http://java.sun.com/javase/downloads/index.jsp  
 
After you update, be sure to remove older versions of Java via Add or Remove Programs in the Control Panel.
 
I have e-mailed Magnus concerning your post and asked him to step in.  I honestly do not see anything that could be causing your problem with TH scanner.  You can also e-mail him for support at support@misec.net
IP Logged

______
TrojanHunter V5.0.962...No. 1 AT in my Book and on my Box!
Magnus
Administrator
*****



Ad astra per aspera.

   
WWW  

Posts: 4107
Re: Error
« Reply #7 on: May 21st, 2008, 2:02am »
Quote Quote  Modify Modify

Are you running something called nVidia/nView Desktop Manager? If so, that's what's causing the problem and you need to either deactivate it, or add TrojanHunter scanner to its exclusion list.
IP Logged
Hokie1
Newbie
*






   


Posts: 20
Re: Error
« Reply #8 on: May 21st, 2008, 7:20pm »
Quote Quote  Modify Modify

I finally was able to disabled nView Desktop Manager, adding TH to the ignore list didn't help. I still get the error but the scanner now works in normal mode without freezing up.  
 
Will up date Java.
 
Thanks again.
IP Logged

Never, ever approach a computer saying or even thinking "I will just do this quickly".
Hokie1
Newbie
*






   


Posts: 20
Re: Error
« Reply #9 on: May 24th, 2008, 1:07pm »
Quote Quote  Modify Modify

What is happening now.  
 
The scanner runs without freezing up, but nothing ever appears in the log.
The scanner loads without the error.
Clicking on the slide bar in Scan / Select Folders to Scan creates the error.
After closing the error message the scanner blinks as if it were refreshing.  
I receive the same error with PCMag's InstaBack2, it has a similar looking window for selecting which files to backup. It also blinks as if refreshing after closing the error message.  
Disabling Dr Watson Debugging has eliminated a number of issues for me. The error message stopped appearing when the scanner loads after disabling Dr Watson Debugging.
IP Logged

Never, ever approach a computer saying or even thinking "I will just do this quickly".
siliconman01
Global Moderator
*****



Trojans! Chew 'em Up, Spit 'em Out...

   


Gender: male
Posts: 5671
Re: Error
« Reply #10 on: May 24th, 2008, 2:38pm »
Quote Quote  Modify Modify

Quote:
Disabling Dr Watson Debugging has eliminated a number of issues for me. The error message stopped appearing when the scanner loads after disabling Dr Watson Debugging.

 
Does the FULL scan run to completion with Dr. Watson Debugging turned off?
 
How many files/items does it show it has scanned?  
 
If nothing malicious or suspicious is found, there will be nothing in the log.
IP Logged

______
TrojanHunter V5.0.962...No. 1 AT in my Book and on my Box!
Hokie1
Newbie
*






   


Posts: 20
Re: Error
« Reply #11 on: May 25th, 2008, 9:56am »
Quote Quote  Modify Modify

Don't remember how many files/items were scanned on the C drive, several hundred thousands, took over an hour and never froze up. Same thing when I scanned the H drive. Quick Scan scanned over 6,400 files/items in one or two minutes, always list port 9999 which is used by Anonymizer proxy, nothing listed in the log though.  
 
I'm not sure of the relationship, if any, between the Error, Trojan found, Dr Watson and the Select Folder Window problem that now creates the error, but my whole system runs great since Dr Watson was disabled, especially Firefox. The suggestion to disable it came from Microsoft with links to article, after I decided to send the error via their auto error reporting tool. I was getting to many errors and the PC was locking up.  
 
As before, the error is now created by using the slider or scrolling from within the Select Folder window. It will happen twice before not appearing again. If I don't scroll, no error. As I said before, both InstaBack and TH blink as if refreshing each time I close the error.  
 
I'm fairly sure there was some conflict between Trojan Hunter, McAfee, and Spy Sweeper when the Trojan was identified.  
 
I don't know were the Trojan came from, first I've ever had if over fifteen years. Never had a virus or spyware installed and get very little spam. Something must be working right.  
 
You may be prompted to send an error report for the Drwtsn32.exe debugger in Windows XP
View products that this article applies to.
 
Article ID : 949820
Last Review : March 11, 2008
Revision : 1.0
 
Method 1: Disable the debugger by using the DisableDrWatson.reg file
Method 2: Disable the debugger by manually changing the registry
MORE INFORMATION
SYMPTOMS
In Windows XP, you may be prompted to send an error report for the Drwtsn32.exe debugger.
 
CAUSE
This issue occurs because of an exception in the Drwtsn32.exe program.
 
RESOLUTION
Important This section, method, or task contains steps that tell you how to modify the registry. However, serious problems might occur if you modify the registry incorrectly. Therefore, make sure that you follow these steps carefully. For added protection, back up the registry before you modify it. Then, you can restore the registry if a problem occurs. For more information about how to back up and restore the registry, click the following article number to view the article in the Microsoft Knowledge Base:
322756 (http://support.microsoft.com/kb/322756/) How to back up and restore the registry in Windows XP and Windows Vista
To resolve this problem, use one of the following methods.
 
Method 1: Disable the debugger by using the DisableDrWatson.reg file
1. Download the DisableDrWatson.reg file.
 
The following file is available for download from the Microsoft Download Center:
 
DownloadDownload the DisableDrWatson.reg package now. (http://download.microsoft.com/download/7/5/1/751c3454-ffc4-418a-8320-510 66f4ee4ce/DisableDrWatson.reg)
 
For more information about how to download Microsoft support files, click the following article number to view the article in the Microsoft Knowledge Base:
119591 (http://support.microsoft.com/kb/119591/) How to obtain Microsoft support files from online services
Microsoft scanned this file for viruses. Microsoft used the most current virus-detection software that was available on the date that the file was posted. The file is stored on security-enhanced servers that help prevent any unauthorized changes to the file.
2. Double-click the DisableDrWatson.reg file to import the registry entry.
 
Thanks and make it a great day!
« Last Edit: May 25th, 2008, 10:15am by Hokie1 » IP Logged

Never, ever approach a computer saying or even thinking "I will just do this quickly".
Hokie1
Newbie
*






   


Posts: 20
Re: Error
« Reply #12 on: May 26th, 2008, 8:26am »
Quote Quote  Modify Modify

I ran another Full Scan, here are the results. Still no info logged under the Log Tab.
 
116,561 file/items scanned, no time given.
 
I added double extensions, so this is the first time they showed up. They appear to be legit.  
 
Port 9999 is used by Anonymizer Proxy  
Port 33333 is used by PGP Desktop
Settings\Woodshed\Desktop\BluesPortScan.exe (NetTool.Delf.100) is a legit port scanning tool
 
 
TrojanHunter Scan Report - Saved 2008-05-26 09:06
 
Port 33333/TCP is open (matches Blackharaz.100)
Port 9999/TCP is open (matches ForcedEntry.100)
Port 9999/TCP is open (matches Infra.100)
Port 9999/TCP is open (matches Prayer.120)
Port 9999/TCP is open (matches Prayer.130)
Port 33333/TCP is open (matches Prosiak.047)
Port 9999/TCP is open (matches Skipper.100)
Port 9999/TCP is open (matches SpadeAce.100)
Port 33333/TCP is open (matches SubSeven.214)
Port 9999/TCP is open (matches TakeOver.200)
Port 9999/TCP is open (matches TakeOver.300)
Found trojan file: C:\Documents and Settings\Woodshed\Desktop\BluesPortScan.exe (NetTool.Delf.100)
Warning: Executable file with double extensions found: C:\Documents and Settings\Woodshed\Application Data\Google\GoogleEarth\myplaces.kml.tmp
Found trojan file: C:\Documents and Settings\Woodshed\Desktop\BluesPortScan.exe (NetTool.Delf.100)
Warning: Executable file with double extensions found: C:\Program Files\Microsoft Office\Office12\Microsoft.Office.Interop.InfoPath.Xml.dll
Warning: Executable file with double extensions found: C:\Program Files\Reference Assemblies\Microsoft\Framework\v3.0\System.IO.Log.dll
Warning: Executable file with double extensions found: C:\WINDOWS\assembly\GAC\Microsoft.Office.Interop.Access.Dao\12.0.0.0__71 e9bce111e9429c\Microsoft.Office.interop.access.dao.dll
Warning: Executable file with double extensions found: C:\WINDOWS\assembly\GAC\Microsoft.Office.Interop.InfoPath.Xml\12.0.0.0__ 71e9bce111e9429c\Microsoft.Office.Interop.InfoPath.Xml.dll
Warning: Executable file with double extensions found: C:\WINDOWS\assembly\GAC\Microsoft.VisualBasic.Vsa\7.0.5000.0__b03f5f7f11 d50a3a\Microsoft.VisualBasic.Vsa.dll
Warning: Executable file with double extensions found: C:\WINDOWS\assembly\GAC\Microsoft.Vsa\7.0.5000.0__b03f5f7f11d50a3a\Micro soft.Vsa.dll
Warning: Executable file with double extensions found: C:\WINDOWS\assembly\GAC\Policy.11.0.Microsoft.Office.Interop.InfoPath.Xm l\12.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.InfoPa th.Xml.dll
Warning: Executable file with double extensions found: C:\WINDOWS\assembly\GAC\System.Web\1.0.5000.0__b03f5f7f11d50a3a\System.W eb.dll
Warning: Executable file with double extensions found: C:\WINDOWS\assembly\GAC\System.Xml\1.0.5000.0__b77a5c561934e089\System.X ML.dll
Warning: Executable file with double extensions found: C:\WINDOWS\assembly\GAC_32\Microsoft.Transactions.Bridge.Dtc\3.0.0.0__b0 3f5f7f11d50a3a\Microsoft.Transactions.Bridge.Dtc.dll
Warning: Executable file with double extensions found: C:\WINDOWS\assembly\GAC_32\System.Web\2.0.0.0__b03f5f7f11d50a3a\System.W eb.dll
Warning: Executable file with double extensions found: C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualBasic.Vsa\8.0.0.0__b03f5f7f 11d50a3a\Microsoft.VisualBasic.Vsa.dll
Warning: Executable file with double extensions found: C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Vsa\8.0.0.0__b03f5f7f11d50a3a\Mic rosoft.Vsa.dll
Warning: Executable file with double extensions found: C:\WINDOWS\assembly\GAC_MSIL\System.IO.Log\3.0.0.0__b03f5f7f11d50a3a\Sys tem.IO.Log.dll
Warning: Executable file with double extensions found: C:\WINDOWS\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System .XML.dll
Warning: Executable file with double extensions found: C:\WINDOWS\assembly\NativeImages1_v1.1.4322\System.Xml\1.0.5000.0__b77a5 c561934e089_135f0004\System.Xml.dll
Warning: Executable file with double extensions found: C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Microsoft.VisualBasic.Vsa.d ll
Warning: Executable file with double extensions found: C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Microsoft.Vsa.dll
Warning: Executable file with double extensions found: C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\System.Web.dll
Warning: Executable file with double extensions found: C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\System.XML.dll
Warning: Executable file with double extensions found: C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualBasic.Vsa. dll
Warning: Executable file with double extensions found: C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.Vsa.dll
Warning: Executable file with double extensions found: C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Web.dll
Warning: Executable file with double extensions found: C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.XML.dll
Warning: Executable file with double extensions found: C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\Microsoft.Transactions.Bridge.Dtc.dll
Warning: Executable file with double extensions found: C:\WINDOWS\ServicePackFiles\i386\mscorrc.chs.dll
Warning: Executable file with double extensions found: C:\WINDOWS\ServicePackFiles\i386\mscorrc.cht.dll
Warning: Executable file with double extensions found: C:\WINDOWS\ServicePackFiles\i386\mscorrc.ger.dll
Warning: Executable file with double extensions found: C:\WINDOWS\ServicePackFiles\i386\mscorrc.kor.dll
Warning: Executable file with double extensions found: C:\WINDOWS\ServicePackFiles\i386\system.web.dll
Warning: Executable file with double extensions found: C:\WINDOWS\ServicePackFiles\i386\system.xml.dll
Warning: Executable file with double extensions found: C:\WINDOWS\ServicePackFiles\i386\vbc7ui.chs.dll
Warning: Executable file with double extensions found: C:\WINDOWS\ServicePackFiles\i386\vbc7ui.cht.dll
Warning: Executable file with double extensions found: C:\WINDOWS\ServicePackFiles\i386\vbc7ui.ger.dll
Warning: Executable file with double extensions found: C:\WINDOWS\ServicePackFiles\i386\vbc7ui.kor.dll
Warning: Executable file with double extensions found: C:\WINDOWS\system32\nv4_disp.dll.tmp
IP Logged

Never, ever approach a computer saying or even thinking "I will just do this quickly".
siliconman01
Global Moderator
*****



Trojans! Chew 'em Up, Spit 'em Out...

   


Gender: male
Posts: 5671
Re: Error
« Reply #13 on: May 26th, 2008, 1:48pm »
Quote Quote  Modify Modify

Quote:
Found trojan file: C:\Documents and Settings\Woodshed\Desktop\BluesPortScan.exe (NetTool.Delf.100)

 
I'm confident too that this is a False Positive.  I've e-mailed Gavin about it.  If you would please zip and submit the file BluesPortScan.exe to Mischel Internet Security, it would be appreciated.  The link below describes how to submit a file.
 
http://www.misec.net/forum/board/FAQ/1139308293
 
The other messages are all about double extensions.  I've gone through them and they all look okay.  The link below describes double extensions.
 
http://www.misec.net/forum/board/FAQ/1139255660
 
I recommend that you uncheck the option in TH scanner's option list "Warn on executable files with double extensions".  TH will still scan the files for infections; it just will not print out the warning over and over.
 
All the scanner info is under the Scan Report tab.  I've never seen anything show up in on the Log tab since the very first version of TH 5.0 beta.  I think Magnus has that tab neutralized now.
 
You should find logs in the folder Scan Report located at C:\Program Files\TrojanHunter 5.0\Scan Reports.  
 
IP Logged

______
TrojanHunter V5.0.962...No. 1 AT in my Book and on my Box!
Hokie1
Newbie
*






   


Posts: 20
Re: Error
« Reply #14 on: May 26th, 2008, 6:16pm »
Quote Quote  Modify Modify

Done
 
It would be my opinion that the scanner is working correctly, even with the error inconvenience, since I'm not seeing any negative replies.  
 
Thanks for your help and your timely reply!
 
« Last Edit: May 26th, 2008, 6:25pm by Hokie1 » IP Logged

Never, ever approach a computer saying or even thinking "I will just do this quickly".
Pages: 1 2  Reply Reply  Notify of replies Notify of replies   Send Topic Send Topic   Print Print

« Previous topic | Next topic »
Search
Members
Login
Register