PDA

View Full Version : Help with CnsMin



ericyung88
2006-10-05, 22:04
Dear all,

I am new here. Please kindly help : Spybot found that I am infected with cnsmin. I searched the posts here and found some experts suggested using ewido and I've installed the software and tried running it under save mode. But ewido says it cannot remove the cnsmin. Moreover, since the screen display is 640x480 under save mode and ewido uses higher resolution, I can barely quit with ctrl-alt-del.

I am posting my ewido report below and anybody please kindly help::sad:

Best regards and many thanks,
Eric

AVG Anti-Spyware - Scan Report
---------------------------------------------------------

+ Created at: 上午 02:30:41 2006/10/6

+ Scan result:



HKLM\SOFTWARE\Classes\CLSID\{CE439C63-384A-747A-A357-23D96B5D652B} -> Adware.ALiBaBar : Ignored.
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CE439C63-384A-747A-A357-23D96B5D652B} -> Adware.ALiBaBar : Ignored.
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CE439C63-384A-747A-A357-23D96B5D652B} -> Adware.ALiBaBar : Ignored.
HKU\S-1-5-21-823518204-1326574676-839522115-500\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CE439C63-384A-747A-A357-23D96B5D652B} -> Adware.ALiBaBar : Ignored.
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\654FQLK1\scrblkup[1].cab/ScrBlock.dll -> Adware.Cdn : Ignored.
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\654FQLK1\yaswiper[1].cab/yaswiper.dll -> Adware.Cdn : Ignored.
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\654FQLK1\yieacore3[1].cab/yieacore.dll/cdnaux.dll -> Adware.Cdn : Ignored.
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OL6VMZ8P\scrblkup[1].cab/ScrBlock.dll -> Adware.Cdn : Ignored.
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OL6VMZ8P\yieacore3[1].cab/yieacore.dll/cdnaux.dll -> Adware.Cdn : Ignored.
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OZUF21YH\keepmainM[1].cab/cns1.exe -> Adware.Cdn : Ignored.
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OZUF21YH\liveexup[1].cab/alliveex.dll -> Adware.Cdn : Ignored.
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\YFSNAT4R\keepmainM[1].cab/cns1.exe -> Adware.Cdn : Ignored.
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\YFSNAT4R\liveexup[1].cab/alliveex.dll -> Adware.Cdn : Ignored.
C:\Program Files\3721\__delete_on_reboot__a_l_L_i_v_e_E_x_._d_l_l_ -> Adware.Cdn : Ignored.
C:\Program Files\3721\__delete_on_reboot__s_c_r_b_l_o_c_k_._d_l_l_ -> Adware.Cdn : Ignored.
C:\Program Files\3721\alliveex.dll_tobedeleted -> Adware.Cdn : Ignored.
C:\Program Files\3721\scrblock.dll_tobedeleted -> Adware.Cdn : Ignored.
C:\WINDOWS\Downloaded Program Files\keepmainM.cab/cns1.exe -> Adware.Cdn : Ignored.
C:\WINDOWS\system32\cns.exe -> Adware.Cdn : Ignored.
C:\WINDOWS\system32\drivers\84593.sys -> Adware.Cdn : Ignored.
[1736] C:\PROGRA~1\3721\alLiveEx.dll -> Adware.Cdn : Ignored.
[388] C:\PROGRA~1\3721\alLiveEx.dll -> Adware.Cdn : Ignored.
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2L1H6780\helperup[1].cab/helper.dll -> Adware.Cnshel : Ignored.
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\DHXV8XAW\helperup[1].cab/helper.dll -> Adware.Cnshel : Ignored.
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OL6VMZ8P\helperup[1].cab/helper.dll -> Adware.Cnshel : Ignored.
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OZUF21YH\CnsMinAL[1].cab/AutoLive.dll/helper.dll -> Adware.Cnshel : Ignored.
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OZUF21YH\helperup[1].cab/helper.dll -> Adware.Cnshel : Ignored.
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\YFSNAT4R\CnsMinAL[1].cab/AutoLive.dll/helper.dll -> Adware.Cnshel : Ignored.
C:\Program Files\3721\3721\helper.dll -> Adware.Cnshel : Ignored.
C:\Program Files\3721\__delete_on_reboot__h_e_l_p_e_r_._d_l_l_ -> Adware.Cnshel : Ignored.
C:\Program Files\3721\autolive.dll/helper.dll -> Adware.Cnshel : Ignored.
C:\Program Files\3721\autolive.dll_tobedeleted/helper.dll -> Adware.Cnshel : Ignored.
C:\Program Files\3721\helper.dll_tobedeleted -> Adware.Cnshel : Ignored.
C:\WINDOWS\Downloaded Program Files\CnsMinAL.cab/AutoLive.dll/helper.dll -> Adware.Cnshel : Ignored.
C:\WINDOWS\Downloaded Program Files\autolive.dll/helper.dll -> Adware.Cnshel : Ignored.
[1956] C:\PROGRA~1\3721\helper.dll -> Adware.Cnshel : Ignored.
[284] C:\PROGRA~1\3721\helper.dll -> Adware.Cnshel : Ignored.
[3172] C:\PROGRA~1\3721\helper.dll -> Adware.Cnshel : Ignored.
[3692] C:\PROGRA~1\3721\helper.dll -> Adware.Cnshel : Ignored.
[472] C:\PROGRA~1\3721\helper.dll -> Adware.Cnshel : Ignored.
HKLM\SOFTWARE\3721 -> Adware.CnsMin : Ignored.
HKLM\SOFTWARE\3721\Assist -> Adware.CnsMin : Ignored.
HKLM\SOFTWARE\3721\Assist\Modules -> Adware.CnsMin : Ignored.
HKLM\SOFTWARE\3721\AutoLive -> Adware.CnsMin : Ignored.
HKLM\SOFTWARE\3721\AutoLive\scrblock -> Adware.CnsMin : Ignored.
HKLM\SOFTWARE\3721\CnsMin -> Adware.CnsMin : Ignored.
HKLM\SOFTWARE\3721\CnsMinCg -> Adware.CnsMin : Ignored.
HKLM\SOFTWARE\3721\CnsMin\CnsMinEx -> Adware.CnsMin : Ignored.
HKLM\SOFTWARE\Classes\AutoLive.Live -> Adware.CnsMin : Ignored.
HKLM\SOFTWARE\Classes\AutoLive.Live.1 -> Adware.CnsMin : Ignored.
HKLM\SOFTWARE\Classes\AutoLive.Live\CLSID -> Adware.CnsMin : Ignored.
HKLM\SOFTWARE\Classes\AutoLive.Live\CurVer -> Adware.CnsMin : Ignored.
HKLM\SOFTWARE\Classes\CnsHelper.CH -> Adware.CnsMin : Ignored.
HKLM\SOFTWARE\Classes\CnsHelper.CH.1 -> Adware.CnsMin : Ignored.
HKLM\SOFTWARE\Classes\CnsHelper.CH\CLSID -> Adware.CnsMin : Ignored.
HKLM\SOFTWARE\Classes\CnsHelper.CH\CurVer -> Adware.CnsMin : Ignored.
HKLM\SOFTWARE\Microsoft\Internet Explorer\AdvancedOptions\!CNS -> Adware.CnsMin : Ignored.
HKLM\SOFTWARE\Microsoft\Internet Explorer\AdvancedOptions\!CNS\AutoUpdate -> Adware.CnsMin : Ignored.
HKLM\SOFTWARE\Microsoft\Internet Explorer\AdvancedOptions\!CNS\Enable -> Adware.CnsMin : Ignored.
HKLM\SOFTWARE\Microsoft\Internet Explorer\AdvancedOptions\!CNS\Hint -> Adware.CnsMin : Ignored.
HKLM\SOFTWARE\Microsoft\Internet Explorer\AdvancedOptions\!CNS\List -> Adware.CnsMin : Ignored.
HKLM\SOFTWARE\Microsoft\Internet Explorer\AdvancedOptions\!CNS\Reset -> Adware.CnsMin : Ignored.
HKLM\SOFTWARE\Microsoft\Internet Explorer\AdvancedOptions\!CNS\ResetCatch -> Adware.CnsMin : Ignored.
HKLM\SOFTWARE\Microsoft\Internet Explorer\AdvancedOptions\!CNS\Tips -> Adware.CnsMin : Ignored.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CnsMin -> Adware.CnsMin : Ignored.
HKU\S-1-5-21-823518204-1326574676-839522115-500\Software\3721 -> Adware.CnsMin : Ignored.
HKU\S-1-5-21-823518204-1326574676-839522115-500\Software\3721\CnsMin -> Adware.CnsMin : Ignored.
HKU\S-1-5-21-823518204-1326574676-839522115-500\Software\3721\CnsMin\Variant -> Adware.CnsMin : Ignored.
HKU\S-1-5-21-823518204-1326574676-839522115-500\Software\3721\CnsUrl -> Adware.CnsMin : Ignored.
HKU\S-1-5-21-823518204-1326574676-839522115-500\Software\3721\InputCns -> Adware.CnsMin : Ignored.
HKU\S-1-5-21-823518204-1326574676-839522115-500\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{38928D50-8A48-44C2-945F-D2F23F771410} -> Adware.CnsMin : Ignored.
C:\Sorted document\Gammon-doc\abc\Target Architecture Project\Working\Chung\vnc-3.3.3r9_x86_win32.zip/vnc_x86_win32/vncviewer/vncviewer.exe -> Not-A-Virus.RemoteAdmin.Win32.WinVNC.333 : Ignored.
C:\Documents and Settings\Administrator\Cookies\administrator@cnetasiapacific.122.2o7[2].txt -> TrackingCookie.2o7 : Ignored.
C:\Documents and Settings\Administrator\Cookies\administrator@microsoftwga.112.2o7[1].txt -> TrackingCookie.2o7 : Ignored.
C:\Documents and Settings\Administrator\Cookies\administrator@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Ignored.
C:\Documents and Settings\Administrator\Cookies\administrator@msnportal.112.2o7[2].txt -> TrackingCookie.2o7 : Ignored.
C:\Documents and Settings\Administrator\Cookies\administrator@admarketplace[1].txt -> TrackingCookie.Admarketplace : Ignored.
C:\Documents and Settings\Administrator\Cookies\administrator@admarketplace[2].txt -> TrackingCookie.Admarketplace : Ignored.
C:\Documents and Settings\Administrator\Cookies\administrator@adtech[2].txt -> TrackingCookie.Adtech : Ignored.
C:\Documents and Settings\Administrator\Cookies\administrator@com[2].txt -> TrackingCookie.Com : Ignored.
C:\Documents and Settings\Administrator\Cookies\administrator@e-2dj6wfkiahajccq.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Ignored.
C:\Documents and Settings\Administrator\Cookies\administrator@e-2dj6wfkickdjolo.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Ignored.
C:\Documents and Settings\Administrator\Cookies\administrator@e-2dj6wfkieic5gbo.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Ignored.
C:\Documents and Settings\Administrator\Cookies\administrator@e-2dj6wfkoqkcjkgp.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Ignored.
C:\Documents and Settings\Administrator\Cookies\administrator@e-2dj6wfkyamajako.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Ignored.
C:\Documents and Settings\Administrator\Cookies\administrator@e-2dj6wfl4uodpkfo.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Ignored.
C:\Documents and Settings\Administrator\Cookies\administrator@e-2dj6wfmigjcjafq.stats.esomniture[1].txt -> TrackingCookie.Esomniture : Ignored.
C:\Documents and Settings\Administrator\Cookies\administrator@e-2dj6wfmyklazagp.stats.esomniture[1].txt -> TrackingCookie.Esomniture : Ignored.
C:\Documents and Settings\Administrator\Cookies\administrator@e-2dj6wjk4oncpkfq.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Ignored.
C:\Documents and Settings\Administrator\Cookies\administrator@e-2dj6wjkyeldpwkp.stats.esomniture[1].txt -> TrackingCookie.Esomniture : Ignored.
C:\Documents and Settings\Administrator\Cookies\administrator@e-2dj6wjkyolazkho.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Ignored.
C:\Documents and Settings\Administrator\Cookies\administrator@e-2dj6wjloalcpofo.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Ignored.
C:\Documents and Settings\Administrator\Cookies\administrator@e-2dj6wjloogcjcgp.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Ignored.
C:\Documents and Settings\Administrator\Cookies\administrator@e-2dj6wjmyeicjiap.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Ignored.
C:\Documents and Settings\Administrator\Cookies\administrator@e-2dj6wjny-1kcjia.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Ignored.
C:\Documents and Settings\Administrator\Cookies\administrator@e-2dj6wjnygkcpgfo.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Ignored.
C:\Documents and Settings\Administrator\Cookies\administrator@e-2dj6wjnygmdjogo.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Ignored.
C:\Documents and Settings\Administrator\Cookies\administrator@e-2dj6wjnyogazido.stats.esomniture[1].txt -> TrackingCookie.Esomniture : Ignored.
C:\Documents and Settings\Administrator\Cookies\administrator@e-2dj6wjnyukd5eco.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Ignored.
C:\Documents and Settings\Administrator\Cookies\administrator@adopt.euroclick[2].txt -> TrackingCookie.Euroclick : Ignored.
C:\Documents and Settings\Administrator\Cookies\administrator@www.myaffiliateprogram[1].txt -> TrackingCookie.Myaffiliateprogram : Ignored.
C:\Documents and Settings\Administrator\Cookies\administrator@starware[2].txt -> TrackingCookie.Starware : Ignored.
C:\Documents and Settings\Administrator\Cookies\administrator@ad.yieldmanager[2].txt -> TrackingCookie.Yieldmanager : Ignored.


::Report end

tashi
2006-10-05, 22:20
Hello, please follow the instructions in our 'sticky' topic to produce a HJT log.
BEFORE you post and who will advise you. Preliminary Steps (http://forums.spybot.info/showthread.php?t=288)

Then a helper will assist you as soon as available to do so. :)

tashi
2006-10-12, 02:26
This topic has been closed to prevent others with similar issues posting in it.
If you need it re-opened please send me or your helper a private message (pm) and provide a link to the thread.

Applies only to the original topic starter.