Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » Do you trust the uninstaller?
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
(topic move) Hard drive space disappearing, reappearing »
« (topic move) couldnt open disk multi(0)disk(0)rdisk(0). . .  

vamps

@as9105.c

Re: Do you trust the uninstaller?

All I can say is massive thanks...worked a treat.

Log of AproposFix v1

************

Running from directory:
C:\Documents and Settings\James\Desktop\aproposfix

************

Registry entries found:

[HKEY_LOCAL_MACHINE\Software\CqXloAxofS65]
@="ZWSKZKThiihiiji38eaPnVhiihxkiD:4y5D9iZfZaLToniKYPcLYZiUaMaWVYajZfZ"
"Device"="\\\\.\\MRxti2o"
"DriverPath"="C:\\WINDOWS\\system32\\drivers\\ntftport.sys"
"DriverName"="spldsdm"
"HideUninstallerName"="C:\\Program Files\\Hipnero\\irmstcln.exe"
"UninstallerPath"="C:\\WINDOWS\\system32\\shadivx.exe"
"UninstallerRegKey"="HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\{46C70C10-D287-4E45-A8B9-0CF3A8D7B719}"
"UninstallerParams"="/CTUN"
"HDll"="C:\\WINDOWS\\system32\\qapbdlv1.dll"
"ServerAddress"="adchannel.contextplus.net"
"LegalNote"="http://adchannel.contextplus.net/legal-note/nonbranded.html"
"PartnerId"="CP.IST2"
"InstallationId"="{Xbbc7a89-27dd-04bb-000a-1f4b14ec79f1}"
"PageFiltering"=dword:00000002
"CrMnTmt"=dword:0036ee80

************

Removing hidden service:
Service spldsdm removed.

Removing hidden folder:
Deletion of folder Hipnero succeeded!

Deleting files:

Deletion of file C:\WINDOWS\system32\drivers\ntftport.sys succeeded!
Deletion of file C:\WINDOWS\system32\conmshta.exe succeeded!
Deletion of file C:\WINDOWS\system32\qapbdlv1.dll succeeded!
Deletion of file C:\WINDOWS\system32\shadivx.exe succeeded!

Backing up files:
Done!

Removing registry entries:

REGEDIT4

[-HKEY_CURRENT_USER\Software\CqXloAxofS65]
[-HKEY_LOCAL_MACHINE\Software\CqXloAxofS65]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{46C70C10-D287-4E45-A8B9-0CF3A8D7B719}]

Done!

Finished!

Ktulu07



Re: Do you trust the uninstaller?

Worked like a charm. Thanks very much

Log of AproposFix v1

************

Running from directory:
C:\Documents and Settings\Administrator.THEONENESS\Desktop\aproposfix

************

Registry entries found:

[HKEY_LOCAL_MACHINE\Software\CyXR7AB3KUE5]
"Device"="\\\\.\\bastsvc"
"DriverPath"="C:\\WINDOWS\\system32\\drivers\\nik1btxx.sys"
"DriverName"="PDFSDDD"
"UninstallerPath"="C:\\WINDOWS\\system32\\ahqtheme.exe"
"HDll"="C:\\WINDOWS\\system32\\typuname.dll"
"ServerAddress"="adchannel.contextplus.net"
"LegalNote"="http://adchannel.contextplus.net/legal-note/nonbranded.html"
"PartnerId"="CP.ANT2"
"InstallationId"="{X5ccc894-532d-7dbd-03c6-b7d897a23f14}"
"PageFiltering"=dword:00000001
"ClientName"="C:\\Program Files\\Lognikon\\finbatt.exe"
"AutoUpdater"="C:\\WINDOWS\\system32\\wiadimap.exe"
"Version"="2.0.128"
"HideUninstallerName"="C:\\Program Files\\Lognikon\\jdbupnp.exe"
"LastAURestoreMsgTS"="2005:11:18-13:48:18:109"
--
[HKEY_LOCAL_MACHINE\Software\Aprps]

[HKEY_LOCAL_MACHINE\Software\Aprps\Client]
"PartnerId"="WB.VER2"

************

Removing hidden service:
Service PDFSDDD removed.

Removing hidden folder:
Deletion of folder Lognikon succeeded!

Deleting files:

Deletion of file C:\WINDOWS\system32\drivers\nik1btxx.sys succeeded!
Deletion of file C:\WINDOWS\system32\wiadimap.exe succeeded!
Deletion of file C:\WINDOWS\system32\typuname.dll succeeded!
Deletion of file C:\WINDOWS\system32\ahqtheme.exe succeeded!

Backing up files:
Done!

Removing registry entries:

REGEDIT4

[-HKEY_CURRENT_USER\Software\CyXR7AB3KUE5]
[-HKEY_CURRENT_USER\Software\Aprps]
[-HKEY_LOCAL_MACHINE\Software\CyXR7AB3KUE5]
[-HKEY_LOCAL_MACHINE\Software\Aprps]

Done!

Finished!

grateful guest

@rr.com

Re: Do you trust the uninstaller?

thank you so much, i have been trying to fix this problem the entire day.... the world could definitely use more people like you

Log of AproposFix v1

************

Running from directory:
C:\Documents and Settings\Josh\Desktop\aproposfix

************

Registry entries found:

[HKEY_LOCAL_MACHINE\Software\CpPiEAH8dl9D]
@="5xz8GLKghhghhih2UaZ2MXghhgwjhC.3x4C8hYeYZKSnmhJXObKXYhGMVJGYaViYeY"
"Device"="\\\\.\\MoutMgr"
"DriverPath"="C:\\WINDOWS\\system32\\drivers\\agpdasup.sys"
"DriverName"="PDFSafe"
"HideUninstallerName"="C:\\Program Files\\Halreal\\iyusrv32.exe"
"UninstallerPath"="C:\\WINDOWS\\system32\\nbtntvwr.exe"
"UninstallerRegKey"="HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\{238E64E5-5F97-4A0C-9CD4-32997B9FA557}"
"UninstallerParams"="/CTUN"
"HDll"="C:\\WINDOWS\\system32\\paumsnap.dll"
"ServerAddress"="adchannel.contextplus.net"
"LegalNote"="http://adchannel.contextplus.net/legal-note/nonbranded.html"
"PartnerId"="CP.IST2"
"InstallationId"="{X93c43e1-85af-5cca-f475-8ceb4c34f7ad}"
"PageFiltering"=dword:00000001
"ClientName"="C:\\Program Files\\Halreal\\cnvinfax.exe"

************

Removing hidden service:
Service PDFSafe removed.

Removing hidden folder:
BarneyBadAss
Badasses Fight For Freedom
Premium
join:2004-05-07
00001

Re: Do you trust the uninstaller?

The real question is how do you know you are infected in the 1st place?
--
---Barney
(topic locked)
Forums » Up and Running » Security » Security(topic move) Hard drive space disappearing, reappearing »
« (topic move) couldnt open disk multi(0)disk(0)rdisk(0). . .  


Wednesday, 02-Dec 21:15:07 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [161] Comcast Releasing Promised Usage Meter
· [93] Graduate Student Unveils Sprint's GPS Sharing With Feds
· [79] Latest Consumer Reports Survey Not Kind To AT&T
· [70] Baltimore To Ban Lazy Cable Installs
· [62] Broadband Killed The Game Console
· [54] Rogers Unveils The ISP Dream Model
· [46] ACTA: Global Three Strikes
· [41] Rural Carriers Quickly Embracing Fiber
· [38] Charter Exits Chapter 11
· [38] AT&T, Verizon Drop 3G Ad Dispute
Most people now reading
· False positive in Avast! or is it real? [Security]
· IMG 1.7 (IMG Updates and Discussion) [Verizon FIOS TV]
· MS admits Windows Updates principally created to annoy [Security]
· Quality/longevity of 15A 120V receptacles [Home Repair & Improvement]
· [Newsgroups] Newzleech down? [Filesharing Software]
· Ooma changing features [VOIP Tech Chat]
· Windows 7 boot manager editing questions [Microsoft Help]
· Poll: Have you ever been charged an overage fee since ... [TekSavvy]
· 16% packet loss. damn dsl. los angeles [AT&T West]
· Microsoft actively urges IE 6 users to upgrade [Security]