Home > I Have > I Have A Problem With BCG3.tmp

I Have A Problem With BCG3.tmp

help, please! Please enter your name, your eMail and the subject: Unknown Files for Derek Enter your threadnumber on our board: Code: http://www.hijackthis-forum.de/showthread.php?t=18573 Now you need to Attach the file from your system. O4 - HKLM\..\Run: [winlog] winlog.exe O4 - HKLM\..\Run: [defender] C:\\dfndrac_6.exe O4 - HKLM\..\RunServices: [winlog] winlog.exe O20 - Winlogon Notify: ShellServiceObjectDelayLoad - C:\WINDOWS\system32\dn6s01j7e.dll (file missing) neustarten 1. File C:\Dokumente und Einstellungen\Tim\Lokale Einstellungen\Temp\GLB6.tmp deleted successfully. http://flashcodehacks.com/i-have/i-have-a-problem-meaning.html

Volume Serial Number is C421-F010 Directory of C:\DOCUME~1\m******\LOCALS~1\Temp 09/11/2006 03:34p 2,086,185 jar_cache27291.tmp 09/11/2006 03:34p 0 BCG8.tmp 09/11/2006 03:33p 222 TB2OverwriteHandler.log 09/11/2006 03:33p 110 newtb1handler.log 09/11/2006 03:31p 3,596 ExchangePerflog_8484fa31e78ac7a5cfcccd43.dat 09/11/2006 03:28p 58 Could not open file C:\Programme\Gemeinsame Dateien\{E043B8CF-0708-1031-0827-040403110031}\services.dll for deletion Deletion of file C:\Programme\Gemeinsame Dateien\{E043B8CF-0708-1031-0827-040403110031}\services.dll failed! A temporary file created with tmpfile is deleted automatically when the program exits or the file is closed. Volume Serial Number is C421-F010 Directory of C:\WINNT\tasks 09/11/2006 03:32p 6 SA.DAT 09/11/2006 03:08p 330 MP Scheduled Scan.job 12/07/1999 04:30p 65 desktop.ini 3 File(s) 401 bytes 0 Dir(s) 9,624,285,184 bytes free http://www.pcadvisor.co.uk/forum/helproom-1/bcg2-bcg3-jetc5d2tmp-eventlog-problem-170885/

Please add this information: Code: Result of scan File: sccfg.sys Status: OK MD5 bbeecb7a743251c5781f9664b0bf6251 Packers detected: - Scanner results AntiVir Found nothing ArcaVir Found nothing Avast Found nothing AVG Antivirus Found Help BleepingComputer Defend Freedom of Speech Back to top #3 cuzinwhitebread cuzinwhitebread Topic Starter Members 102 posts OFFLINE Gender:Male Location:Gainesville, Tx Local time:08:41 PM Posted 09 February 2008 - 10:31 However this member is being helped in the HJT forum and does in fact have a malware problem. Your cache administrator is webmaster.

If you're sure that you don't need them, then feel free to delete them.It depends upon who installed the Browser Address Error Redirector - and if the Windows one is still This can happen because the program crashed or the developer of the program simply forgot to add the code needed to delete the temporary files after the program is done with hahaha The coolest thing since sliced bread Back to top #7 cuzinwhitebread cuzinwhitebread Topic Starter Members 102 posts OFFLINE Gender:Male Location:Gainesville, Tx Local time:08:41 PM Posted 09 February 2008 - Attempting to delete: C:\WINDOWS\System32\guard.tmp C:\WINDOWS\System32\guard.tmp Deleted successfully!

Username Forum Password I've forgotten my password Remember me This is not recommended for shared computers Sign in anonymously Don't add me to the active users list Privacy Policy

Jump Take a deep breath ""C:\Program Files\Winamp Remote\bin\Orb.exe"="C:\Program Files\Winamp Remote\bin\Orb.exe:*:Disabled:Orb""C:\Program Files\Winamp Remote\bin\OrbStreamerClient.exe"="C:\Program Files\Winamp Remote\bin\OrbStreamerClient.exe:*:Disabled:Orb Stream Client""C:\Program Files\Winamp Remote\bin\OrbTray.exe"="C:\Program Files\Winamp Remote\bin\OrbTray.exe:*:Disabled:OrbTray""C:\Program Files\Pinnacle\VideoSpin\Programs\umi.exe"="C:\Program Files\Pinnacle\VideoSpin\Programs\umi.exe:*:Disabled:umi""C:\Program Files\MSN Messenger\msnmsgr.exe"="C:\Program Files\MSN Messenger\msnmsgr.exe:*:Disabled:Windows Live Messenger 8.1""C:\Program Files\MSN Messenger\livecall.exe"="C:\Program Files\MSN Inter-process communication[edit] Most operating systems offer primitives such as pipes, sockets or shared memory to pass data among programs, but often the simplest way (especially for programs that follow the Unix http://www.bleepingcomputer.com/forums/t/185058/ntosexevundovirtumondewinspoem-and-mirar-infection-cleared/ thank you sir.

Deletion of file C:\Dokumente und Einstellungen\Tim\Lokale Einstellungen\Temp\BCG3.tmp failed! DavidM4 14:52 12 Nov 04 Just tried it in safe mode and they weren't there but when I started back in normal mode the 2 BCG's had gone and the JET You may want to visit this URL: http://www.thespykiller.co.uk/forum/index.php?board=1.0 You don't need to register. or read our Welcome Guide to learn how to use this site.

Just had another message from Antivir that TR/Vundo.Gen was found in the file "ARK2A.tmp" , which cannot be deleted. https://malwr.com/analysis/MWY2ZTAwYmY0ZTVmNDA1MWI1NTNjNGM4ZWIxYTY2ZWQ/ Removing: HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ShellServiceObjectDelayLoad Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{AB5C59F8-6375-4406-967C-3973F0FF50DD}" HKCR\Clsid\{AB5C59F8-6375-4406-967C-3973F0FF50DD} Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{A1286AD0-41ED-46C1-9506-186CB48413D4}" HKCR\Clsid\{A1286AD0-41ED-46C1-9506-186CB48413D4} Restoring Windows certificates. PLS HELPHijackthis-Log - ProblemeProbleme beim boot - HiJackThis LogPlötzlich neuer Eintrag in HijackThis!Sonderbare Einträge im HiJackThis-LogHIJACKTHIS verursachte einen FehlerWas genau macht 'HIJACKTHIS' ??? Completed script processing. ******************* Finished!

In the case that it's malware the producers of Antivirus thus get a chance to actualize their signatures. my link on the spykiller is: http://www.thespykiller.co.uk/forum/...p?topic=2554.0 Thank you again Seite 1 von 2 12 Letzte Gehe zu Seite: « Vorheriges Thema | Nächstes Thema » Aktive Benutzer Aktive Benutzer Aktive File C:\warebundlenewer.exe deleted successfully. Text is available under the Creative Commons Attribution-ShareAlike License; additional terms may apply.

Volumeseriennummer: CCDC-703F Verzeichnis von C:\Programme 19.07.2006 19:29

. 19.07.2006 19:29 .. 21.06.2006 20:35 Ahead 12.06.2006 19:33 AOpen 12.06.2006 19:45 AvRack 12.06.2006 19:22 ComPlus Applications 18.07.2006 This thread is now locked and can not be replied to. Locate these files: c:\sccfg.sys C:\WINNT\system32\suppdll.dll C:\WINNT\system32\87E37FA660.sys C:\DOCUME~1\m******\LOCALS~1\Temp\101234.exe Use your mouse, right click onto each file, read the properties > version > I need to know the Company name, the file version, http://flashcodehacks.com/i-have/i-have-the-dreaded-search-engine-redirect-problem-need-help-please.html Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.

I have the Knack. ** If I haven't replied in 48 hours, please send me a message. Volumeseriennummer: CCDC-703F Verzeichnis von C:\Dokumente und Einstellungen\Tim 20.07.2006 01:14

. 20.07.2006 01:14 .. 10.07.2006 00:53 Contacts 20.07.2006 14:41 Desktop 18.07.2006 15:05 Eigene Dateien 18.07.2006 15:05 File C:\drsmartload1.exe deleted successfully.

Scan started at 20.07.2006 14:04:39 Infected!

Attempting to delete: C:\System Volume Information\_restore{8093A7D8-6C6E-47B1-9CEE-D4131C47A0E0}\RP61\A0088969.dll C:\System Volume Information\_restore{8093A7D8-6C6E-47B1-9CEE-D4131C47A0E0}\RP61\A0088969.dll Deleted successfully! The coolest thing since sliced bread Back to top BC AdBot (Login to Remove) BleepingComputer.com Register to remove ads #2 usasma usasma Still visually handicapped (avatar is memory developed by Issues[edit] Some programs create temporary files and then leave them behind - they do not delete them. Ran "Malwarebytes' Anti-Malware".

Registriert seit 25.01.2005 Ort The Netherlands Beiträge 20.038 AW: trojan cliker Thanks for your HJT Logfile @ Mohah May we please see the other results too? Site Changelog Community Forum Software by IP.Board Sign In Use Facebook Use Twitter Need an account? Registriert seit 25.01.2005 Ort The Netherlands Beiträge 20.038 AW: trojan cliker Hello again Mohah The mess doesn't matter We will load these files up for manually analyse. Also, uninstall MyWebSearch, it is known adware (even though you do get the crappy cursors that you wanted).

Register now! In my case, and what drove me to find this forum page today and spend 10 minutes of my life signing up so that I can help you, BCG3.tmp was running Back to top #6 cuzinwhitebread cuzinwhitebread Topic Starter Members 102 posts OFFLINE Gender:Male Location:Gainesville, Tx Local time:08:41 PM Posted 09 February 2008 - 11:06 AM this time that moveonboot worked. Back to top #12 Animal Animal Bleepin' Animinion Site Admin 32,832 posts OFFLINE Gender:Male Location:Where You Least Expect Me To Be Local time:05:41 PM Posted 17 May 2008 - 06:40

looks like its going to be a battle. und jetzt wollte ich mal wissen ob alles in ordnung ist..!? 20.07.2006, 12:20 Uhr von Nikita Re: hijackthis fixe mit dem HijackThis. I can not speak germany and I do not know hoe to modify my posts. I do applogize and thank you very much for taking care of problem 12.09.2006,01:01 #9 Ruby Supermod a.D.

The system returned: (22) Invalid argument The remote host or network may be down. Register a free account to unlock additional features at BleepingComputer.com Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. thanks for the info....don't know why it didn't work before but as long as it did. File C:\drsmartload.exe deleted successfully.

That's it. The coolest thing since sliced bread Back to top #4 cuzinwhitebread cuzinwhitebread Topic Starter Members 102 posts OFFLINE Gender:Male Location:Gainesville, Tx Local time:08:41 PM Posted 09 February 2008 - 10:39 Attempting to delete: C:\System Volume Information\_restore{8093A7D8-6C6E-47B1-9CEE-D4131C47A0E0}\RP61\A0088974.dll C:\System Volume Information\_restore{8093A7D8-6C6E-47B1-9CEE-D4131C47A0E0}\RP61\A0088974.dll Deleted successfully! To generate a temporary file name that will survive past the lifespan of the creating program, tmpnam (POSIX) or GetTempFileName(...) (Windows) can be used.

I am posting the Hijackthis and RSIT log after all these procedures.Can also post the logs of the above mentioned tools if necessary.Maybe someone can help with the following:1. File C:\WINDOWS\system32\setup.exe.tmp deleted successfully. PC Advisor Phones Smartphone reviews Best smartphones Smartphone tips Smartphone buying advice Smartphone deals Laptops Laptops reviews Laptops tips Best laptops Laptops buying advice Tablets Tablet reviews Best tablets Tablet tips All I want to know if it is a harmful file.