Tech Problem Aggregator

# HPDM Agent Checkin's from Legacy Clients

Q: HPDM Agent Checkin's from Legacy Clients

Hi guys.. looking for some support if possible. Pretty much a noob to HPDM but I'm learning fast!! I have a new deployment of HPDM 4.7 SP3 installed which has an agent version of 4.7.3660.23743. I've inhertied a Thin Client estate which mostly has a 4yr old version of the client out there, ver 4.4.3660.12990. These clients are mainly t610s. Ive tried to import 10 or so of these clients manually, but they arent checking in and remain in the Unidentified tab. Ive found some newer thin clients, t620s, running clients around 4.6, and they check in no problem and i can upgrade them via the _Upgrade Agent job, no problems. If i try to manually point these older agents to my DM server, I get "Error of writing gateway address, please retry it", i guess the agent software is corrupted in some way. These are all WES7 32bit clients so there appears to be no MSI or method for me to deploy this manually. Willing to set a GPO to upgrade these agents if need be.. is there any manual method for upgrading 32bit OS agents? Tried to pick apart the _Upgrade Agent task also, to see if i can script this manually, but I'm having no luck with this. Any help appreciated with a way to upgrade my agents!! ThanksAndy

More replies

Previously using HPDM 4.6 with t5740e and T5740 Thin Clients.  Decided to upgrade HPDM to 4.7 SP4, installed HPDM 4.7 and then installed SP4, did not install SP1, SP2, SP3 thinking SP4 would be inclusive.  After trying to shadow, and a few other Task Templates, the Thin Clients that we tried using the _Update Agent on devices, the task completed but the Thin Client is no longer rescognized by the HPDM 4.7, it is listed but shows "OFF" when it is on the network. After checking the folders for the Agents, under 4.6 and 4.7, the 4.7 does not have the WES7E_32 Bit version only the WES7E_64 bit version.  Checking SP2 for HPDM 4.7 shows the 32 bit Agent.  Should we have installed each SP1 through SP4 to get all of the Agents in both versions installed? If that is the solution, can we just install those SPs or should we un-install HPDM 4.7 SP4, then install each successive SP to build up the folders with all of the Agents to SP4? We are also now receiving a message when trying to re-image a Thin Client using the Import Images using a FLASH.IBR file with Agnet Version 4.5.3660.19746, the message appears after it has almost finished the imaging Message:Title Bar:  HPDMAgent.exe - Ordinal Not FoundBody: The Ordinal 4445 could not be located in the dynamic Link Library LIBEAY32.dll. Thank you for your help

More replies

I have gotten an assignment to pull out the information about which DNS that the Thin Clients are using in HPDM.I have been able to capture the entire image of a thin client and checking DNS server that way but it is not efficient.I was hoping there was a way to get the DNS information of all the clients in one quick way that presentet the information in a good way via HPDM? There are different models of the thin clients but most are T620 models. Appreciate all help with the issue.

More replies

A few months ago I setup an HPDM server on Win 2012r2 along with 12 HP thin clients, Mainly mt245. I could see all of the thin clients with HPDM, I even used it to Image all of them. Yesterday, I went to add a new mt245 abd image it. All of the TCs are gone from HPDM and it doesnt find this new one. I've tried walking the range. I've tried adding it manually as well as telling it to walk the range of the exact IP that the TC has. I can ping the TC from the server and vice-versa. Windows firewall is completly off. Any thoughts? Thanks,Travis

More replies

Hi, How do I change the default agent pull interval? I know I can do it manually from the control panel on the client, or directly from HPDM, but since i can't send tasks to the client the latter won't work. I tried changing it on the client to 30 minutes, then caputring an image and deploying it to a new client, but the pull interval reset itself to 1 day.

More replies

Recently upgraded HPDM 4.7 SP4 to HPDM 4.7 SP5 - a new HPDM Gateway was created with the install, the previous HPDM Gateway was listed also, but the devices are now listed as "Broken" and the HPDM Gateway icon is grayed out in color.  This Gateway was created when we upgraded from HPDM 4.6 to HPDM 4.7, and then to HPDM 4.7 SP4.  The HPDM Gateway ID assigned was (00:00:1A:1A:5A:A8) and the previous HPDM Gateway ID for HPDM 4.6 was (00:00:1A:1A:5A:A7). We switched over to the new HPDM Gateway for HPDM 4.7 SP4 and discovered the devices, the HPDM Gateway worked correctly. After the upgrade of HPDM 4.7 SP4 to HPDM SP5, the new HPDM Gateway ID has reverted back to the previous ID of (00:00:1A:1A:A5:A7) not a squential ID such as (00:00:1A:1A:A5:A9) for the new install of 4.7 SP5. Is the install limited to these two ID's (00:00:1A:1A:A5:A7 and 00:00:1A:1A:A5:A8) depending on which one it finds at the time of install, it use the other?  The install was successful, but before switching to this HPDM Gateway i wanted to make sure this is the correct HPDM Gateway to use.  The icon is currently Green with the following information: HPDM Gateway ID: 00:00:1A:1A:5A:A7Hostname: Darifair-SupportMAC Address: 00:00:1A:1A:5A:A8IP Address: 192.168.0.73Subnet Address: 192.168.0.0Subnet Mask: 255.255.255.0HPDM Gateway Version: 4.7.3630.25570Active Status: onAuthentication: unknownOperating System: Windows Ser... Read more

More replies

Outlook
Search Outlook
Search Folder

The client contact email is from another email address ([email protected]) that can be pop and smtp access, but it is so large, I will not download all emails from that email address, cause me 1.5 G space

I have a gmail email address, I want to forward this client email to my gmail email account.

Gmail (POP3)： pop.gmail.com; (SMTP)：smtp.gmail.com

So, [email protected] I click the email in [email protected] then forward to [email protected]

If I have a new client email, I should see all emails from and to this client, how to create a "search folder" to search email that apply for this client in Outlook folder?

Outlook provide a library with 13 "search folders"
I can "create user define search folder"

Outlook File/New/search folder
In "search folder", roll down to "user define", click "create user define search file folder"
Input name of the "search folder", because the position title is "Client 1234", so input "Client 1234" in this textbox.

Click "conditions"

In "search folder", click "mail" option, input "Client Mail.56" in "search text" textbox.

So, I ask the Client to send all his email to [email protected]
So, I also can forward all this client's email to [email protected] and input Client Mail.56 in any emails about this position.

In "location" drop down list, choose "on... Read more

A:How Can I Use Ms Outlook Contacts Track Clients Emails And Clients Information?

So, I ask the Client to send all his email to [email protected]
So, I also can forward (but waste time) all this client's email to [email protected] and

I will create a folder in Outlook email, business and personal
Then seperate the emails to these 2 email folders.
Then I add each contact to Outlook, group them to same company first, then make folders, business and personal contact folders.

For each client activity, use Project Software to manage the activity.
So I must Forward email to Gmail address or other Pop email address, then use Pop to download to Outlook, but when I open the email, I can not find "Action/Link" button in the "Action" Tab, I need to save this email to a folder, and from Contact Tab, link this file?
In Contact Tab, every documents can link to Contact, click "Action/Link", choose file.
But I need to better organize my documents, I search Google Directory, directory.google.com for the file content, use google directory as my file directory, save them in the correct folder.
Then link to Outlook Contact, then in Contact Tab/Activities/, there have a field title (folder name), folder location: diary

If I group many messges in folders, 100 clients have 100 folders, too confuse!

Is this right?

I must use project to manage all activities about the client?

5 more replies

had a virus and think I took care of everything. Please check out my hijackthis log and see if everything looks ok, if not, Please, HELP ME!
Logfile of HijackThis v1.99.1
Scan saved at 7:10:34 AM, on 12/27/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\Program Files\Analog Devices\SoundMAX\spkrmon.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\Dell AIO Printer A940\dlbabmgr.exe
C:\Program Files\Dell AIO Printer A940\dlbabmon.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\McAfee.com\VSO\mcvsshld.exe
C:\Program Files\McAfee.com\VSO\oasclnt.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\Program Files\Yahoo!\Messenger\ypager.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe

A:just checkin'

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R3 - Default URLSearchHook is missing

O4 - HKLM\..\Run: [8.tmp] C:\DOCUME~1\Owner\LOCALS~1\Temp\8.tmp.exe
O4 - HKLM\..\Run: [9.tmp] C:\DOCUME~1\Owner\LOCALS~1\Temp\9.tmp.exe
O4 - HKLM\..\Run: [8.tmp.exe] C:\DOCUME~1\Owner\LOCALS~1\Temp\8.tmp.exe
O4 - HKLM\..\Run: [9.tmp.exe] C:\DOCUME~1\Owner\LOCALS~1\Temp\9.tmp.exe

O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O23 - Service: Remote Procedure Call (RPC) Helper ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\system32\netfk.exe (file missing)

just ad a very quick look but id remove these

1 more replies

seeing as how you people are just amazing with these things i thought i would just check to see if i am doing all the right things and keeping out all the bad guys so here goes with my latest and in advane as always THANKS lance
Logfile of HijackThis v1.98.2
Scan saved at 12:05:27 PM, on 28/08/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\ISS\BlackICE\blackd.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\htpatch.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Free Surfer\fs20.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\WheresJames\StartupMgr\StartupMgr.exe
C:\Program Files\ISS\BlackICE\blackice.exe
C:\PROGRA~1\Grisoft\AVG7\avgw.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_SICN03.EXE

A:just checkin thanks

Looks good to me!! Nothing suspicious in it.

2 more replies

Hi, thought I'd see if all is well on the folk's PC, since I'm not up close and personal with it like this often. For one thing I think the google toolbar entries are different than they are on other machines I have it on. (Mainly want to make sure nothing sinister is going on, but would also be interested in shutting off everything that can be. For example I did install Windows Messenger and enable Remote Assistance since we are going to try that when the need arises after I leave again, but assume I should figure out how to keep Windows Messenger from being on all the time. It's not enabled in msconfig or anything.)

Here's their log. We all thank you!

Logfile of HijackThis v1.99.1
Scan saved at 3:19:25 PM, on 9/3/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\devldr32.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\CA\eTrust PestPatrol\PPActiveDetection.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe

A:Mom & dad's HJT ok? Good kid checkin up while visiting! :)

P.S., I don't know if peop can tell when you've chosen about:blank as your IE start page on purpose, but I did. Although I wouldn't know how to tell if there was also a bad about:blank present. I did run Housecall, just a couple tribalfusion thingies found.

1 more replies

I had a lot of problems a month back. Could you please check this log to see if clean? Thanks.Logfile of HijackThis v1.98.2Scan saved at 8:29:53 PM, on 2/17/2005Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\spoolsv.exeC:\WINDOWS\system32\cisvc.exeC:\WINDOWS\System32\CTsvcCDA.exec:\PROGRA~1\mcafee.com\vso\mcvsrte.exeC:\WINDOWS\wanmpsvc.exeC:\WINDOWS\System32\MsPMSPSv.exec:\PROGRA~1\mcafee.com\vso\mcshield.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\cidaemon.exeC:\WINDOWS\system32\cidaemon.exeC:\WINDOWS\Explorer.EXEC:\Program Files\Common Files\Dell\EUSW\Support.exeC:\Program Files\Winamp\Winampa.exeC:\Program Files\Common Files\Real\Update_OB\realsched.exeC:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exeC:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exeC:\PROGRA~1\mcafee.com\agent\mcagent.exeC:\WINDOWS\S... Read more

A:Checkin & cleanup after fixes

Spotless!

1 more replies

Hi,
I would like to surpress the CheckOut and/or CheckIn notification when I open a file on a SharePoint share for editing and saving

I have some macros working that correctly do the CheckOut and CheckIn of a file on SharePoint.

However, like the command Application . DispalyAlters = False to avoid the confirmation prompts when deleting or overwriting a file I was wondering if there is an option when addressing an Excel file which I open to modify or add a record to avoid getting the Prompt, it reduces the click moments for a user and also avoids the mistake if somebody places a check-mark and the file remains checked out for all others.
I hope I was able to explain my requirement

More replies

Logfile of HijackThis v1.99.1Scan saved at 7:04:47 PM, on 8/17/2006Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\spoolsv.exeC:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exeC:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exeC:\Program Files\ewido anti-spyware 4.0\guard.exeC:\WINDOWS\system32\GEARSEC.EXEC:\WINDOWS\System32\svchost.exec:\Program Files\Common Files\LightScribe\LSSrvc.exeC:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXEC:\WINDOWS\Explorer.EXEc:\Program Files\Common Files\Symantec Shared\SNDSrvc.exeC:\WINDOWS\system32\svchost.exeC:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exeC:\Program Files\Mozilla Firefox\firefox.exeC:\Program Files\HijackThis\HijackThis.exeR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://start.earthlink.netR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.myspace.com/R1 - HKLM&#... Read more

A:Just Checkin To Make Sure Everthin Is Cool

1 more replies

Hello -

A group that I am associated with is evaluating a Sharepoint 3 site, and I have been having problems with testing Windows 7 configurations.

Specifically, I have a Windows 7 system using IE8 and Office 2007 student. I can check out, edit and check in a document using Word, but when I reopen the modified file from the Sharepoint 3 site, my changes are not visible.

Does anybody have experience with a problem like this, and if so, were you able to find a solution?

Many thanks for any help or suggestions.

Bob

More replies

if you could plz check this logfile i'd appreciate it.

Logfile of HijackThis v1.98.2
Scan saved at 8:07:03 PM, on 11/5/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Gateway Utilities\GWInkMonitor.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Common Files\Lanovation\PrismXL\PRISMXL.SYS
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\System32\svchost.exe
C:\DOCUME~1\Owner\LOCALS~1\Temp\~e5d141.tmp

A:internet is kinda slow.. just checkin up on my comp

6 more replies

Dear All,

I want to know, how to checkin the clearcase file with ccaecadm previlages. I have a command which I used in perl with system command. It works fine there. Don't know, how to do that in VB.net 2008. Could you please help me for this. Plz find the command as below,

echo $password | sudo -u ccaecadm -S /usr/atria/bin/cleartool ci -nc$file"
Regards,
Mustafa

More replies

Hello,  I am having issues with my HPDM 4.5 login,  I am able to login using the console when I am on the server side, but I can not do it from my laptop. The only change we made is that we added another NIC card with a different subnet.  In this case what would be the right settings to login to the console? Thanks!

More replies

Receiving the following error code on this particular TC. Cannot run any tasks. HPDM is configured properly and works fine with ever other TC. This is the only TC of this model we have. 2016-06-22 09:54:04    Map repository to: Master Repository2016-06-22 09:54:04    Successfully sent task to the Device Management Gateway2016-06-22 09:54:09    Task has been retrieved by the Agent.2016-06-22 09:55:04    Copy files using repository Master Repository.2016-06-22 09:55:04    Failure deploying update.exe to c:\windows\xpeagent from /Repository/Agents/HPXPe.2016-06-22 09:55:04    Failure deploying HPDMAgent.exe to c:\windows\temp from /Repository/Agents/HPXPe.2016-06-22 09:55:04    Failed to execute Copyfile task.2016-06-22 09:55:04    ErrorCode: -1409, Error Detail: Failed to list directory.2016-06-22 09:55:04    Failed to execute UpdateAgent task.2016-06-22 09:55:04    ErrorCode: -1409, Error Detail: Failed to list directory.2016-06-22 09:55:04    Failed to execute common task.2016-06-22 09:55:04    ErrorCode: -1409, Error Detail: Failed to list directory.

More replies

Hi I was wondering if it's possible to schedule hpdm Walking With IP scan. Thanks Hans Petter

More replies

Hello, I have a HPDM server setup on a virtual machine. I have about 40 HPt520 thin clients as well. I disabled USB drives on all of the thin clients when I initially imaged them and it appears that I missed a few. I want to disable them for security reasons obviously. I know that I can do this in the registry. I changed the Start value to 4 (disabled) and the changes do not commit in HPDM. I tried using HPDM to create a task and modify the registry directly and this did not work. I also created another task that deploys the registry file on the local drive of the thin client and the executes it as a script with the command prompt. This did not work either. What I suspect is happening is that the thin client is executing the task and then windows overwrites the registry and none of the changes apply. How can I fix this? Thanks! [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\USBSTOR]"Type"=dword:00000001"Start"=dword:00000004"ErrorControl"=dword:00000001"ImagePath"=hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\52,00,49,00,56,00,45,00,52,00,53,00,5c,00,55,00,53,00,42,00,53,00,54,00,4f,\00,52,00,2e,00,53,00,59,00,53,00,00,00"DisplayName"="USB Mass Storage Driver""BootFlags"=dword:00000004

More replies

Hi.How do I import for example a new Citrix Receiver from HP Support into HP device Manager ? I cannot find it under Template - Import - HP FTP Software Component BrowserOf cause I can deploy the file manually, but isnt there some way to import the package into HPDM correctly? I am running HPDM 4.6.3610.21251Thx

A:importing WES update into HPDM

You cannot import it directly if the package is not available on HP FTP software Component Browser. You may try using File & Registry task to deploy file and execute script to install it.

I am an HP Employee.My opinions are my own, and do not express those of HP.**Click the White Thumbs Up Button on the right to say Thanks**

3 more replies

I'm having problems finding correct syntax for the _set domain .What is the correct format for Domain Name, Username, OU?In advanced thanks

More replies

I have Win XP Media Edition....Today my computer started shutting down by itself. So, I remebered a friend advising me the MSSE was not really up to date on its protections. Not sure...so downloaded Malwarebytes and ran a full scan.

I found SpamTool.Agent, Trojan.Agent, and 2 Rootkit.Agent infections.

My research lead me to this site to get rkille.exe, rkill.com, etc.

How do I find this and then the tdss killer?

Other sites mention this and want you to sign on with them. But, I heard this was a free download from bleeping computer? Where can I find it?
Bill

A:Rootkit.Agent, Trojan.Agent, SpamTool.Agent Removal???????

Please follow the instructions in ==>This Guide<==.Once the proper logs are created, then make a NEW TOPIC and post it ==>HERE<== Please include the link to this topic in your new topic and a description of your computer issues and what you have done to resolve them.If you can produce at least some of the logs, then please create the new topic and explain what happens when you try to create the log(s) that you couldn't get. If you cannot produce any of the logs, then still post the topic and explain that you followed the Prep. Guide, were unable to create the logs, and describe what happens when you try to create the logs.Once you have created the new topic, please reply back here with a link to the new topic.

1 more replies

Hi there, I am trying to upgrade from 4.7 to 4.7SP1 and I am getting the following error in the upgradeCheckError log 2016-10-04 12:40:29.182  Retry to execute:  ../pgsql_945/bin/pg_upgrade -b "..\pgsql/bin" -d "..\pgsql/data" -B "../pgsql_945/bin" -D "../pgsql_945/data" -U postgres -c Any idea on what needs to be done to resolve it?

More replies

I have updated a T620 to ThinPro 5.2 and made all the setting and configuration changes to it that I need. I thin use HP Device Manager to capture the image. And now I want to update my other T620's with this captured image. I push it into a T620 and it goes narmaly without errors and When Thinpro gets started, I get the following. Starting ThinPro ...mount: mounting /dev /disk/by-lablel/ROOT on /root failed: Invalid argumentmount: mounting /dev on /root/dev failed: No such file or directorymount: mounting /sys on /root/sys failed: No such file or directorymount: mounting /proc on /root/proc failed: No such file or directoryTarget filesystem doesn't have requested /sbin/init No init found. Try passing init=bootarg. It just sits there and I can not use my keyboard to do anything.  regards..

More replies

More replies

Hi All, I'm finding a difficulty integrating HP Device Manager with Active Directory.I've seatched the forum and tried the solutions mentioned but without any success.the Active Directory is reachable from the server using Ping below is the screenshot of the error message i get while testing the integration   my configuration is as below... I've just hidden the domain name with x.x.x.x   If you require any further information, do let me know so I can reach to a resolution...

More replies

Hello,  We have recently upgraded from 4.6SP5 to 4.7, and are now trying to apply the 4.7 service packs. When attempting to upgrade to 4.7 SP1 from 4.7, the installation fails. Below is what was found in the logs, can anyone shed some light on what may be causing this? We are using PostgreSQL, that was installed /w the previous 4.6 install of HPDM.   **START LOG FILE***5-25-2016 16:16:14   |   INFO   |   No command-line parameters is set. Install HPDM with interactive UI.5-25-2016 16:16:14   |   INFO   |   Start HPDM Service Pack installation/uninstallation...5-25-2016 16:16:22   |   INFO   |   Successfully execute: C:\Users\ADMINI~1\AppData\Local\Temp\{424B6EF8-6B37-4B0E-91A9-ECC22987C513}\QueryLogonUser.cmd5-25-2016 16:16:22   |   WARN   |   The Key SOFTWARE\Classes\Installer\Products\D968638153E86B5419E7014A00EA7E5C is not existed. return=-15-25-2016 16:16:22   |   WARN   |   The Key SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\D968638153E86B5419E7014A00EA7E5C is not existed. return=-15-25-2016 16:16:22   |   WARN   |   The Key SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\11ED253BDEE67AF4AA70978B68F09C65 is not existed. return=-15-25-2016 16:16:22... Read more

More replies

Looking for information (ie. Instructions) for deploying Bios Updates for 100 Thin Client T620 on HPDM 4.7

A:HPDM 4.7 Update BIOS on T620

Basically you have to use File & Registry template to deploy some files to the device, then execute command to remotely update BIOS. For different platforms (ThinPro5, WES7, WES8, etc), you have to use different tools, you can download them all from t620 product site. Here are some pics used to update t620 BIOS to 2.08 (NOT the latest one), just for your reference. For t620 with ThinPro5  For T620 with WES7 image

I am an HP Employee.My opinions are my own, and do not express those of HP.**Click the White Thumbs Up Button on the right to say Thanks**

9 more replies

Upon attempting to free up space on our HPDM server a massive log file was found.  It is the PxeService.log file which resides in c:\Program Files (x86)\Hewlett-Packard\HP Device Manager\Gateway\PxeServer.  It is over 10gb in size so it appears it doesn't overwrite and just snowballs.  Most the lines in the file are repetetive failures. We do not use PXE in any sense, we do not network book and image from there.  We boot up the Thin Client and locate it in the console and send the imaging task.  Our SCCM server already owns the one and only pxe service point.  Can I simply disable the service and call it good?

More replies

Hi, we've recently bought a few hundred t520 thin clients and whilst I have been able to use Device Manager 4.7 to lock most things down and image the clients I now need to lockdown the BIOS. Is this possible using Device Manager or do we have to do it on a client by client basis?

More replies

A:1065984 during install from HPDM version - 4.6 SP2

Looks like the repository is not well configured. Can you please let me know the "repospath" in the controller.conf, you should be able to find it at ..\HP Device Manager\MasterRepositoryContoller and the screenshot of repository configuration dialog?

I am an HP Employee.My opinions are my own, and do not express those of HP.**Click the White Thumbs Up Button on the right to say Thanks**

1 more replies

Hello, I have the HPDM gateway role installed on 3100 hosts.  I created a script to install the role, but I don't see a switch to uninstall the role.  Any Suggestions? John

More replies

We have about 20 Thinclients and a win 2012 R2 server with HPDM 4.7.2610.23043 installed on it, i already found all clients and i can shut them down and WOL them how i like but the status task status stays blue even if the task is already finished like a restart and i cant capture images there the task status stays blue too.The clients are t620 thinclients with thinpro 5.2 installed The Version of the agent is 2.6.3670.22274.

A:HPDM cant complete some Tasks and cant capture images

The HPDM Agent version on the units is older than your HPDM 4.7 Server. Have you tried update the Agent? How long does the status stay blue? Will it ever end by itself? When the status issue even is with "easy" tasks like a restart or "Get Device Asset Information" I would think this might be a port forward issue. Have you opened all neccessary ports between as shown in the Admin Guide?ftp://ftp.hp.com/pub/hpdm/Documentation/AdminGuide/4.7/

I am an HP Employee.My opinions are my own and do not express those of HP.**Click the Thumps Up Button on the right to say Thanks**

3 more replies

Hi Everyone We run 200 + T5730 Thin Clients, they run Windows XP.   We have a project to replace them with over the next 2 years with  T520's I have setup a new HPDM server, and the t520 image "up" and "down" fine.  I cannot grab a T5730 image, nor write to them. I have updated the t5730's to run the latest agent (4.7.3660.23051), but same error. The error is Error 1083392 (modual :  Agent) - Category: Other HPDM workflow errorCapture image to the master repository.  Failing capturing 5730.ibr to /repository/images/5730.  Failed to execute CaptureImage task ..\..\task\wins\imagetask_XPE.cpp:106: Failed to check image package existance..\..\task\common\imagecommon.cpp:900: image package alreasy exists  FYIServer firewalls  DISABLED (getting deperate!)Image path is c:\inetpub\ftproot\hpdm\repository\images.  In that folder is a folder containingg the T520 Image, but just an empty folder called "t5730" I have tried renaming the 5730 imaging job - no change and same errorI can rerun/create a new imaging job for the 520's and they work everytime - same user/managemnt console. Any ideas?

A:HPDM 4.7 - the New HP T520 Image OK, but the T5730 Fail - 10...

Can you please let me know the image version on t5730 unit? Is this only happen on single t5730 or all of your t5730 units? Please change the log level to 'Information' - through Configure Agent task and resend the capture image task, once the error occurr, bring me the agent.log and Child.log on the ThinClient.

I am an HP Employee.My opinions are my own, and do not express those of HP.**Click the White Thumbs Up Button on the right to say Thanks**

8 more replies

After updating to HP Devicemanager 4.7 SP3 (and also SP4) it appears that the update agent task is broken. It reports that the update is successfull, but the client don't connect to Device Manager anymore. When using the HPDM Agent controlpanel applet it reports no version number. When viewing the services applet it appears that the HPDM Agent service is gone. Looks like the update task is seriously broken. Worse is that it doesn't include a full agent install, so how do I reinstall the agent now on the ThinClients? Frank

More replies

I'm beginning a switch over to use t520 thin clients with Windows 10 IoT and have a HPDM enviroment for imaging the thin clients.  Every time I pull/push an image from/to the thin client the start menu breaks for the User and Administrator accounts. Nothing comes up when left clicking on the windows button in the start menu and the Window button on the keyboard does nothing also. Everything else works fine. The BIOS and agent are up to date and I'm able to fix the issue by deleting and remaking the User account after the imaging process but don't see this as a viable solution when deploying thin clients en mass.  Is there anything I can do to fix this?

More replies

Hi all, I have an issue with a HP T520 with HP Device Manager 4.7 SP4 running on Server 2012R2, trying to capture an image from a HP T520 with ThinPro 6, agent version 4.7.3671.25484.Capturing profile and settings worked. Server and device are in the same subnet. Manual ftp from thin client to server works. There is no activity in the ftp server log when I start the image process. Windows firewall is disabled. Enabling cached mode doesn't work because it is not yet supported for ThinPro 6.  2016-09-19 12:04:43 [Fehlercode: 34603008] [Modul: Agent] [Kategorie: 0] 2016-09-19 12:04:43 [Fehlerdetails]: Erfassen Sie das Image in das Master-Repository. Fehler beim Erfassen von Spegg_T520_ThinPro6.dd.gz auf /Repository/Images/Spegg_T520_ThinPro6. Ausführen von CaptureImage-Task fehlgeschlagen. Fehlercode: 34603008, Fehlerinfo: ../../Task/common/[email protected]: Failed to handle post image. ../../Task/linux/[email protected]: Imaging operating failed. ../../Task/common/[email protected]: Failed to obtain return code from returned update file.  This issue has been reported a couple of times for older versions of hpdm but I was unable to find a solution. Greetings

A:Error Code 34603008 / Imaging with HPDM 4.7

Are you using ThinPro 6.0?The t520 is not supported with ThinPro 6.0 and needs the newer ThinPro 6.1 version instead.Is the unit wired or wireless? Does it work wired?

I am an HP Employee.My opinions are my own and do not express those of HP.**Click the Thumps Up Button on the right to say Thanks**

2 more replies

Hi everybody, I'm facing a problem with a fresh installation of HPDM v4.6 (which already gaves me some trouble during installation but is now running "quite" fine). When i try to capture a thin client image (T5545 / T5565 //// T5X33009 or T5X31012), it works fine until the thin client reboots, just after having sent the image, "dd.gz" based, to the FTP repository. The error is reported like this in the LOG (HPDM french language was installed, GRRRRRR) :2014-04-15 10:05:44Envoi de la tâche à la passerelle de gestion des périphériques réussi2014-04-15 10:05:46La tâche a été récupérée par l'agent.2014-04-15 10:12:51La tâche a été récupérée par l'agent.2014-04-15 10:13:28[Code derreur : {0}] [Module : {1}] [Catégorie : {2}]2014-04-15 10:07:23[Détails de l'erreur]: ../../Task/linux/[email protected]:Failed to handle post image.../../Task/linux/[email protected]:Imaging operating failed.../../Task/common/[email protected]:Upload file error.../../Task/common/[email protected]:;socket select timeout.2014-04-15 10:13:28Impossible d'exécuter la tâche common. Hope someone can help me because i don't know what the problem is related to.  Thanks !

A:HPDM 4.6 - Unable to capture image (error 34603008)

More information : i tried to add a template to deploy an image to a thin client and i got an error which was : 2014-04-15 11:19:48Mappage du référentiel vers : Référentiel principal2014-04-15 11:19:48Mappage du référentiel vers : Référentiel principal2014-04-15 11:19:48Envoi de la tâche à la passerelle de gestion des périphériques réussi2014-04-15 11:19:50La tâche a été récupérée par l'agent.2014-04-15 11:23:12La tâche a été récupérée par l'agent.2014-04-15 11:23:19[Code derreur : {0}] [Module : {1}] [Catégorie : {2}]2014-04-15 11:23:19[Détails de l'erreur]: ../../Task/linux/[email protected]:Imaging Operating Failed.../../Task/common/[email protected] file error.../../Task/common/[email protected]:;socket select timeout.2014-04-15 11:23:19Impossible d'exécuter la tâche common.

9 more replies

I am trying to replace the auto generated self-signed (Issued to DM, issued by DM) certificates for the HDPM Server and Master Repository.  I am NOT refereeing to FTPS, the HPDM Embedded HTTPS Server, or the Thin Client Agent certs.   I have already setup certs from our own domain internal CA for FTPS in IIS and the Apache Embedded HTTPS server.  These are working fine and Repository tests pass for both protocols.  I have also issues to the Thin Clients from our internal CA just fine. I'm interested in the actual HPDM Server cert and Master repository cert. These are self-generated when the two services start up.  They use a very weak MD5 hash and RSA 1024 key.  I cannot find any documentation around this except for troubleshooting in which you can delete these certs restart the services and they will be regenerated.   Here are the certs\key paths%HPDM Install Path%\MasterRepositoryController\Controller.crt (Repository Cert)%HPDM Install Path%\MasterRepositoryController\Controller.key (Repository Key)%HPDM Install Path%\MasterRepositoryController\Client.crt (HPDM Server Cert)%HPDM Install Path%\Server\Bin\hpdmskey.keystore (Both HPDM Server and Repository Certs and Keys)(Not sure the format it is in.  It's not PEM and ok P12 as far as I can tell) There is also %HPDM Install Path%\Server\bin\hpdmcert.key.  Not sure what this is.  Think it?s the HPDM Server key but deleting it does nothing and it is ne... Read more

More replies

Hello! I've recently set up HP Device Manager 4.5 with Service Pack 4.It's actually working quite nicely. I can configure the thin clients, upload the image to the HPDM server.I see every single thin client. But, when I deploy thin client image to any client, I get Error Code 14000072, and Failed. I need to get this fixed. I got a million thin clients (mild over exaggeration), and don't want to do this manually. Any advice on what to do? I am stuck here. I've been all over the Internet searching for a solution.

A:T510, HPDM, trying to deploy, get Error Code 14000072, Child...

Are you able to se what version the client agents are? If they are below 4.5 update them using the builtin template.

3 more replies

Hi Everyone We have not deployed any TC520 images for a few months.  I have been trying for a few days now and we are getting an error. NOTHING has changed (as far as I can see) in the past few months.The repositories are still there and can connect on the TEST page. Images are still there....and have not been changed.TC520 are the same TC520 machinesVersion numbers of the HPDM and the client match....I can reboot/update etc the clients...just the imaging thats failing So basically nothing has changed. But when I deploy an image I get  Failure to execute DeployImage Task.  2016-08-15 16:20:44 [Error Details]: Deploy image using repository Master Repository.Failure deploying T520_Vanilla_2k7.ibr from /Repository/Images/T520_Vanilla.Failed to execute DeployImage task.ErrorCode: 1080320, Error Info: ..\..\Task\wins\[email protected]: Failed to run wes repack script...\..\Task\wins\[email protected]: Error running repack script..\..\Task\wins\[email protected]: Run process return code = -200. Command = C:\repack\Wes7ImageTool\bin\ImageTool.exe -f C:\repack\Wes7ImageTool\Config.ini Any ideas?  TIA Craig

More replies

Keep getting FTPS error when configuring the master repository.Windows server 2012 64XInstalled IIS 8.0 with FTP and FTP extensibility Created shared folder called HPDM_RepositoryC:\inetpub\ftproot\HPDM_Repositorygranted my local user full access to folderThen installed HPDM 4.7Pointed to correct repository pathLogin and tried to configure repository with FTPS on port 990 (firewall is configured but currently turned off)All port check ok during install Error: Upload of test package to reposotry failed.Insuficient privilege on repository Master Repository with protocol FTPS Looked under C:\programData and there is a folder being created called HPDM_TempThe test package apears there with teh description file but it cannot copy \ move to to master repository C:\inetpub\ftproot\HPDM_Repository (only the folder is created) After searching this forum I found an instance where the user was expericing the same issue and mentioned he renamed the HPDM_Temp folder and everything started working. Unforutnalty that's not the case. Works fine for the shared folder.... Any ideas??

A:hpdm 4.7 ftps error upload of test package to repository fai...

Hello HP support guys?? Some assitance would be greatly appreciated.....I have over 400 DTU's in the field.....

8 more replies

I have a t620 Thin Client running WES8/64 which won't reimage from HPDM. After reboot, before the deployment actually starts, it halts at a WinPE screen with a command prompt window and indicates "Failed to find the file explorer.ini", and waits for commands at x:\windows\system32 where I can do the following: ipconfig shows a valid IP address.ping the HPDM server OKEntered a net use command to the HPDM Repository share, and can view the Repository folders OK.I captured this image a few days ago from this same TC, made some customizations, then captured another image of the customizations. I was able to deploy both the original out of box image, and my customized one.  I tried the latest version of the USB HP ThinUpdate utility, copying the IBR files from HDP Repository, and both images cause an error, "System does not have license for the image OS". I have updated the BIOS on the this client after getting this error, and that didn't work either. Not sure what to do. It's as if this TC just won't take any image now.

More replies

JAVA/Dldr.Agent.W; JAVA/Agent.M.1; JAVA/Agent.AN; HTML/Infected.WebPage.Gen were detected separately between 2 scans from Anti Avira, however, Malwarebyte scans have shown nothing. Thanks for the helpDDS (Ver_10-03-17.01) - NTFSx86 Run by user at 0:02:07.42 on 09/01/2010 WedInternet Explorer: 8.0.7600.16385 BrowserJavaVersion: 1.6.0_21Microsoft Windows 7 Home Premium 6.1.7600.0.950.852.1033.18.3037.1732 [GMT -7:00]============== Running Processes ===============C:\Windows\system32\wininit.exeC:\Windows\system32\lsm.exeC:\Windows\system32\svchost.exe -k DcomLaunchC:\Windows\system32\nvvsvc.exeC:\Windows\system32\svchost.exe -k RPCSSC:\Windows\System32\svchost.exe -k LocalServiceNetworkRestrictedC:\Windows\System32\svchost.exe -k LocalSystemNetworkRestrictedC:\Windows\system32\svchost.exe -k netsvcsC:\Windows\system32\svchost.exe -k LocalServiceC:\Windows\system32\svchost.exe -k NetworkServiceC:\Windows\System32\spoolsv.exeC:\Program Files\Avira\AntiVir Desktop\sched.exeC:\Windows\system32\svchost.exe -k LocalServiceNoNetworkC:\Windows\system32\nvvsvc.exeC:\Program Files\Avira\AntiVir Desktop\avguard.exeC:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exeC:\Program Files\Lenovo&#... Read more

A:JAVA/Dldr.Agent.W; JAVA/Agent.M.1; JAVA/Agent.AN; HTML/Infected.WebPage.Gen detected by AntiAvira

18 more replies

Hi Boopme
Are you here?
Do I need to post everything that I have already posted to you here?: http://www.bleepingcomputer.com/forums/forum103.html
or is someone else going to help me? if so please let me know and I will give details to them.
By the way - this morning before work - I deleted my quarentine folders from SuperAntiSpyware and the logs from my desktop and ran a scan and it didn't pick anything up! But my Malwarbytes will not load again from the task bar when I click on it - it would not let me stop it by right clicking either so hoping it wasn't running a script for the DDS scan? - so I'm afraid my trojans might be back! I was going to run the Rkill one more time - but I didn't
I couldn't run GMER - I have Windows 7 64 bit and it would run but it didn't give me any options to check mark. I was using the 34 bit explorer (does that matter?)
Also the defogger - I'm not sure it worked as it didn't come up for me to click the finish button - it just went back to the little box that says disable? But I did get the DDS logs.
Here is my DDS Log:

DDS (Ver_10-12-12.02) - NTFS_AMD64
Run by tamhbrih at 18:15:58.57 on Mon 02/14/2011
Internet Explorer: 8.0.7600.16385
Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.1788.802 [GMT -7:00]

AV: AntiVir Desktop *Disabled/Updated* {090F9C29-64CE-6C6F-379C-5901B49A85B7}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: AntiVir Desktop *Disabled/... Read more

A:Infected with Trojan.Agent/Gen-IEFake, Trojan.Agent/Gen-IExplorer[Fake] &Trojan.Agent/Gen-PEC

Hello and welcome to Bleeping ComputerWe apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.Please take note:If you have since resolved the original problem you were having, we would appreciate you letting us know. If you are unable to create a log because your computer cannot start up successfully please provide detailed information about your installed Windows Operating System including the Version, Edition and if it is a 32bit or a 64bit system.

23 more replies

This virus was unknowingly attached to a game that was downloaded on my pc. I am using a different pc to post here as the virus prevents me from launching websites that offer support for its removal. Other posts that I have read recommend running an online scanner from eset. Unfortunately, for me, this would be one of the many sites the virus prohibits me from accessing. If I attempt to locate a help site from a search engine, I am redirected to other random sites. If I manually type the URL of a help site in the address bar, the site is blocked.I was able to run HijackThis and am providing this log. Any assistance that you can offer will be greatly appreciated.Logfile of Trend Micro HijackThis v2.0.2Scan saved at 4:59:04 PM, on 9/9/2008Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v7.00 (7.00.6000.16705)Boot mode: NormalRunning processes:C:\WINNT\System32\smss.exeC:\WINNT\system32\winlogon.exeC:\WINNT\system32\services.exeC:\WINNT\system32\lsass.exeC:\WINNT\system32\svchost.exeC:\WINNT\System32\svchost.exeC:\WINNT\system32\svchost.exeC:\WINNT\system32\spoolsv.exeC:\WINNT\system32\basfipm.exeC:\Program Files\Common Files\Symantec Shared\ccSetMgr.exeC:\Program Files\Cisco Systems\VPN Client\cvpnd.exeC:\WINNT\Explorer.EXEC:\Program Files\Symantec AntiVirus\... Read more

A:Trouble With Virus: Win32.agent.gvu / Trojan.downlader.agent.aejp

I apologize for the very long delay. We have a huge backlog of HijackThis Logs to handle and it has been taking us greater time than normal to get caught up. If you are still having a problem, and want us to analyze your information, please reply to this topic stating that you still need help and I will work with you on resolving your computer problems. If your problem has been resolved, please post a reply letting us know so we can close your topic.

Unfortunately, if I do not hear back from you within 5 days, I will be forced to close your topic. If you still need help after I have closed your topic, feel free to create a new one.

Once again, I apologize for the delay in responding to this topic.

1 more replies

When I restarted my Vista 64bit Gateway Desktop PC 5 days ago, I recieved a BSOD stating Driver Power State Failure 0x0000009F. Ever since I have rebooted, I am getting constant freeze ups and extremely slow start ups rendering the function of most programs useless. I have tried running normal Avast scans in regular mode without success, but in safe mode, I was able to run a complete Avast scan in safe mode which no major results, and after running Superantispyware free edition scan it located and quarantined:

Rogue.Agent/Gen-Nullo [dll]
Trojan.Agent/Gen-Autorun
Heur.Agent/Gen-whitebox

I then proceeded to run a Malwarebytes Full Scan but the scan always gets stuck on: File C:\windows\syswow64\sql..... srv32.rll,  wid.dll, woa.dll
I have run these scans for over 12 hours but most of the time it freezes up at 6hrs 53 mins... There are 37 infected files detected, but I cannot fix them since the scan never finishes.

I also had a 'not a genuine windows' issue pop up in the bottom right corner which cant be correct because this desktop has not been modified in anyway and it came with a certified Vista 64bit OS pre-installed by Gateway. I seemed to have remedied the pop up from appearing, but I suspect this has something to do with the other issues I am having.

I have tried using an earlier system restore point, but it did not remedy the problem

.I've also recieved a pop-up in the middle of the screen a few times now that sta... Read more

A:Rogue.Agent/Gen-Nullo & Trojan.Agent/Gen-Autorun Viruses Detected Need Help!

3 more replies

My computer runs slow at times, so I started a boot scan with Avast Free Home Edition. Scan results showed Java: Agent-TB and Java:Agent-WY. Boot Scan didn't complete due to a brownout in our neighborhood. I had to use System Restore to reboot computer.

I'm running Windows 7 Home Edition on a Toshiba A665-S6090 64-bit laptops
Avast Free Edition version 6.0.1289 Update Engine and Virus Definitions version 111016-1 COMODO Firewall Free Edition version 5.5.195786.1383
Malwarebytes' Anti-Malware 1.51.2.1300, Database version 7962
SuperAntiSpyware Free Edition 4.33.1000, Database Definition Version Core: 7801, Trace 5613
Glary Utilities Free Edition 2.38.0.1288, Database 2011-09-30.

I primarily use Firefox 7.0.1 and Opera 11.51.

Ad-Aware and CCleaner don't seem to complete there scans recently.

DDS Log File

DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_26
Run by bondzephyr at 22:52:43 on 2011-10-16
Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.3891.1630 [GMT -4:00]
.
AV: Lavasoft Ad-Watch Live! Anti-Virus *Disabled/Updated* {9FF26384-70D4-CE6B-3ECB-E759A6A40116}
AV: avast! Antivirus *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

A:Avast Boot Scan found Java: Agent-TB and Jave: Agent-WY

17 more replies

old sony laptop with windows xp pro sp3 intel pentium 3 with 640 MB rami've got some nasty bugs on my laptop. i can remove them with spybot or malwarebytes, but they come back every time i restart the pc. they are able to turn off windows firewall and symantec anti-virus autoprotect. my laptop got infected after my desktop, so both are only in safemode and off the network for now. any help would be greatly appreciated.from spybot:win32.delf.ucfrom malwarebytes:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\llpinit_dlls (Spyware.Agent.H) -> Quarantined and deleted successfully.C:\WINDOWS\system32\nvtpm32.dll (Spyware.Agent.H) -> Delete on reboot.C:\WINDOWS\system32\D.tmp (Trojan.Agent) -> Quarantined and deleted successfully.C:\WINDOWS\system32\E.tmp (Trojan.Agent) -> Quarantined and deleted successfully.C:\WINDOWS\system32\F.tmp (Trojan.Agent) -> Quarantined and deleted successfully.C:\WINDOWS\system32\azton.mt (Trojan.Agent) -> Quarantined and deleted successfully.Here is my log from HijackThis:Logfile of Trend Micro HijackThis v2.0.2Scan saved at 7:41:32 AM, on 3/2/2009Platform: Windows XP SP3 (WinNT 5.01.2600)MSIE: Internet Explorer v7.00 (7.00.6000.16791)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.ex... Read more

A:Laptop infected with win32.delf.uc, Spyware.Agent.H, and Trojan.Agent

you can close this out as i actually just did a clean reinstall of the OS. however, if anyone can help me with my other PC i'd prefer to not reinstall it as well:http://www.bleepingcomputer.com/forums/t/207842/desktop-infected-with-trojanagent-more/it has:trojan.agentadware.cometadware.starwaretrojan.dnschangerthanks!

2 more replies

Hi

My Neighbour has asked me to have a look at her laptop as all her programs, desktop icons and desktop background have disappeared and I have exhausted all avenues to try and fix it for her. Below is a list of what i have done and found.

Acer Aspire 7540 series Laptop running windows 7 home premium 64bit operating sysytem

1 Mc affee full scan found nothing

2 Ran Rkill then maleware bytes and it found 10 infections and removed them.

3 Ran Rkill then SAS and SAS found tracking cookies and two trojans which are Trojan.Agent/Gen-IExplorer[Fake] and Trojan.Agent/Gen-PEC. SAS managed to delete all the tracking cookies however these aforementioned trojans are persistent and SAS reports as removing them but on a re scan with SAS the are still there. I can see from the logs that It is IExplorer.exe that is the issue here but i am now at a loss as to what to do.

4 Ran unhide.exe which brought back most of the files however the program files from the start menu still show as being empty.

I think that the problem is the fake Iexplorer starts and runs at startup and cant be stopped by rkill but am unsure as I am a hardware diagnostic engineer with limited experience on software issues and people keep asking me to have a look at there computers for them and i like to try and help people as much as i can but am stumped on this one.

Any assistance that you can give me would be greatly appreciated

Many thanks

More replies

I want to start by saying this is my third time here and you guys have been absolutely FABULOUS the other two times. (I say that not by way of pressure! but appreciation for all you all do!).I have run McAfee, Adaware, Malwarebytes, and superantispyware, and got the above items quarantined, but am still having non-stop popups, and I can type in a URL but if I click a link who knows where I'll end up. Looks like most of the required stats are in the dds file, so here it is. If you need anything else, just let me know. Oh, and I'm attaching my attach.txt but can't attach the ark file, as gmer gives me a BSOD every time I try to run it. No error codes, just "your computer has encountered blah blah and has to shut down." If you need the precise text of that I'll recreate it for you.Also, the date on these files is 7/31, but they should still be current since the PC's been sitting turned off and disconnected from the internet since then, but if I should run updated files, again, just let me know.Thanks in advance!LynnDDS (Ver_10-03-17.01) - NTFSx86 Run by Lynn Springle at 15:56:45.03 on Sat 07/31/2010Internet Explorer: 8.0.6001.18702Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2046.1007 [GMT -4:00]AV: McAfee VirusScan *On-access scanning enabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}============== Running Processes ===========... Read more

27 more replies

I had noticed recently that my pc hard drive would by spinning up nad my hd activity light would be on like constant flickering red even when i wasnt using it at all. I did an online scan with eset online scanner just to see if i could tarck down the problem. Unfortunately for whatever reason when i looked at the log it was supposed to save of the scan it had not saved anything that would describe what it found and removed. I do know it was something about Agent.nbl & Agent.nbs And to do with possible java something or other. I am including the logs from Hijack This and other reqested items Although as I have 64 bit system i cannot use Gmer.

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 18:55:54, on 16/07/2012
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16447)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe
C:\Windows\vVX1000.exe
C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe
C:\Program Files (x86)\Vtune\TBPANEL.exe
C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe
C:\Users\user\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
C:\Program Files (x86)\Samsung\Kies\Kies.exe
C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe

A:eset online scanner found Agent.nbl & Agent.nbs

8 more replies

I was getting popup windows saying "MSVideo.dll is not a valid Windows image". (See previous discussion in link). Norton Internet Security 2011 and Malbyteware found nothing. SuperAntiSpyware found the above viruses and removed them. I continued to see popup windows after doing this. To see if everything is gone I was instructed to create log files with DDS and GMER. The dds.txt file is pasted below. The attach.txt and ark.txt files are attached. I just tried to run SuperAntiSpyware and got the same error page about msvideo (see attached image). So something is still wrong.DDS (Ver_10-12-12.02) - NTFSx86 Run by Les at 11:48:20.37 on Fri 02/25/2011Internet Explorer: 8.0.6001.18702Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2038.1331 [GMT -8:00]============== Running Processes ===============C:\WINDOWS\system32\svchost -k DcomLaunchsvchost.exeC:\WINDOWS\System32\svchost.exe -k netsvcssvchost.exesvchost.exeC:\WINDOWS\system32\spoolsv.exesvchost.exeC:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exeC:\Program Files\Verizon\IHA_MessageCenter\Bin\Verizon_IHAMessageCenter.exeC:\WINDOWS\Explorer.EXEC:\Program Files\Nero\Nero 7\InCD\InCDsrv.exeC:\Program Files\Java\jre6\bin\jqs.exeC:\Program Files\Common Files\LightScribe\LSSrvc.exeC:\Program Files\Common Files\Motive&#... Read more

A:Rogue Agent and Trojan Agent/Popup windows

Hi,Welcome to Bleeping Computer. My name is m0le and I will be helping you with your log.Please subscribe to this topic, if you haven't already. Click the Watch This Topic button at the top on the right.

Please avoid installing/uninstalling or updating any programs and attempting any unsupervised fixes or scans. This can make helping you impossible.

Please reply to this post so I know you are there.The forum is busy and we need to have replies as soon as possible. If I haven't had a reply after 3 days I will bump the topic and if you do not reply by the following day after that then I will close the topic.Once I receive a reply then I will return with your first instructions.Thanks

32 more replies

I believe it is time to find the perfect accomplice (Analyst) to get me out of a gap between the rock and a hard place. you see, not only the agent trojan infected my computer, but several others. No popups after I have remove the infection with ewido and tried to uninstall MyWaySearch Toolbar, but it has been set to where my mouse is acting strangely like a keylogger has been lurking on my system. Here is my log. Are you in for the challenge?

Logfile of HijackThis v1.99.1
Scan saved at 7:56:54 AM, on 7/31/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Sunbelt Software\CounterSpy\Consumer\SunServer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\aarons\Desktop\Misc\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/mywaybiz
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://securityresponse.symantec.com.../fix_homepage/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.verizon.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = htt... Read more

A:Help!!! Agent Trojan et.al trapped this secret agent (jspygone007)

New log... IN NORMAL MODE!!!

Logfile of HijackThis v1.99.1
Scan saved at 11:14:55 AM, on 7/31/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton Internet Security\ISSVC.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Yahoo!\Antivirus\ISafe.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\Sunbelt Software\CounterSpy\Consumer\sunThreatEngine.exe
C:\Program Files\Sunbelt Software\CounterSpy\Consumer\SunProtectionServer.exe
C:\Program Files\Sunbelt Software\CounterSpy\Consumer\sunserver.exe
C:\PROGRA~1\Yahoo!\YOP\yop.exe
C:\Program Files\Yahoo!\Yahoo! Music Engine\ymetray.exe
C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe

13 more replies

A:Recurring Pop-up; Trojan.agent.afhf; Possibly Agent.100

31 more replies

A:Backdoor.bot, Trojan.agent, Rootkit.agent, and others on my Comp

Hello aNimosity1 and welcome to Bleeping Computer,I'm afraid I have bad news for you I see you're dealing with Virut on top of the other nasty malware on your system. In that case, it's unfortunately a lost cause - Game over situation and a format and reinstall is the fastest and especially the safest solution.You may want to read this why:Virut and other File infectors - Throwing in the Towel? So, I suggest you to start backup all of your valuable data/documents/pictures/movies/songs/etc.. Do NOT backup any applications/installers and Do NOT backup any .exe/.scr/.htm/.html/.xml/.zip/.rar files...This because these files may be infected as well. If you back them up and replace them afterwards, it will infect your computer again.Read here for instructions how to format and reinstall Windows: http://web.mit.edu/ist/products/winxp/adva...all-format.htmlGreetings,Thunder

7 more replies

Hi I'm brand new any sort of forum - so don't really know the form. What I know is that my daughter's laptop has the above Trojan Horse viruses that have knocked out the AVG control centre, any internet connection and the C drive (probably lots more as well). So I'm doing this on my PC. The HijackThis log file follows - very grateful for your help to recover things: Logfile of Trend Micro HijackThis v2.0.2Scan saved at 20:50:28, on 21/01/2008Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\spoolsv.exeC:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exeC:\PROGRA~1\Grisoft\AVG7\avgamsvr.exeC:\PROGRA~1\Grisoft\AVG7\avgupsvc.exeC:\PROGRA~1\Grisoft\AVG7\avgemc.exeC:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exeC:\Program Files\Network Associates\Common Framework\FrameworkService.exeC:\Program Files\Network Associates\VirusScan\Mcshield.exeC:\Program Files\Network Associates\VirusScan\VsTskMgr.exeC:\WINDOWS\SYSTEM32�... Read more

A:Trojan Horse Dropper.agent.git & Backdoor.agent.pta

49 more replies

Hello,

I am new to the forum and just learning my way around. What a great resource! Thanks.

I am running AVG, and it informs me (threat detected!) that I have some trojan horses:
tojan horse agent.AABY and trojan horse agent.AACL

I have tried to heal the files to no avail. I have tried deleting the files and nothing.

I downloaded and ran Malwarebytes Anti-Malware and it found 6 affected files which I deleted, and I am still getting the message from AVG...

-Cynthia

A:Trojan Horse Agent.aaby And Agent.aacl

Did AVG provide a specific file name associated with this malware threat and if so, where is it located (full file path) at on your system?

7 more replies

Hello-

My Malwarebytes Antimalware scan shows these infections:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\bf (Trojan.Agent)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\bk (Trojan.Agent)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\iu (Trojan.Agent)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\mu (Trojan.Agent)
C:\Documents and Settings\MH\Local Settings\Temp\dgankqeo.dat (Rootkit.Agent)

My Avira scan shows: Trash.gen

Both programs say that these infections are locked and will be removed when I restart the computer, but they are still there when I recheck. I've tried turning off system restore, but this doesn't seem to make a difference. I've run SuperAntispyware, Adaware, SpywareBlaster, and CCcleaner, but nothing gets rid of them.

Here's the DDS.txt:
DDS (Ver_09-03-16.01) - NTFSx86
Run by MH at 11:11:16.46 on Sun 04/19/2009
Internet Explorer: 6.0.2900.5512 BrowserJavaVersion: 1.6.0_13
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1023.542 [GMT -4:00]

AV: AntiVir Desktop *On-access scanning enabled* (Updated)
FW: Online Armor Firewall *enabled*

============== Running Processes ===============

A:Infected with Trojan.Agent, Trash.gen and Rootkit.Agent

2 more replies

I am working on my fiance's laptop. She gave it to me after seeing AVG Resident Shield warnings last night. AVG scan (free) identified Trojan PSW.Agent.AGLY and AVG Resident Shield identified Rootkit-Agent.EG, Virus BAT/Deleter & Exploit. AVG could not clean or heal the infections saying object is inaccessible. The Resident Shield found the Trojan horse Rootkit-Agent.EG under C:\Windows\system32\drivers\asyncmac.sys and said "Object is white-listed (critical/system file that should not be removed).I do not get a dialog/Open box to attach the attach.txt and ark.txt files. Please let me know if these can be pasted or why I possibly cannot get the box to open. It appears the Browse button is depressing, but I do not get a dialog box to select the files.Please help! DDS.txt:DDS (Ver_10-03-17.01) - FAT32x86 Run by Suzanne at 13:03:07.71 on Fri 05/21/2010Internet Explorer: 8.0.6001.18702Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1279.632 [GMT -4:00]AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}============== Running Processes ===============C:\WINDOWS\System32\Ati2evxx.exeC:\WINDOWS\system32\svchost -k DcomLaunchC:\WINDOWS\system32\svchost -k rpcssC:\WINDOWS\System32\svchost.exe -k netsvcsC:\WINDOWS\System32\S24EvMon.exeC:\Program Files\AVG\AVG9\avgchsvx.exeC:\Program Fi... Read more

A:Infected with Trojan PSW.Agent.AGLY & Rootkit-Agent.EG

13 more replies

KASPERSKY ONLINE SCANNER 7 REPORTSaturday, November 29, 2008Operating System: Microsoft Windows XP Professional Service Pack 3 (build 2600)Kaspersky Online Scanner 7 version: 7.0.25.0Program database last update: Friday, November 28, 2008 18:35:48Records in database: 1424124Scan settingsScan using the following database extendedScan archives yesScan mail databases yesScan area My ComputerC:\D:\E:\F:\Scan statisticsFiles scanned 94300Threat name 4Infected objects 4Suspicious objects 0Duration of the scan 02:45:29File name Threat name Threats countC:\Documents and Settings\All Users\Application Data\FreeApp.exe Infected: Trojan.Win32.Agent.arng 1 C:\Qoobox\Quarantine\C\Program Files\tinyproxy\tinyproxy.exe.vir Infected: Trojan-Proxy.Win32.Agent.bcw 1 C:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\winse32.exe Infected: IRC-Worm.Win32.Small.x 1 C:\WINDOWS\bolivar24.exe Infected: Backdoor.Win32.Agent.ubx 1 The selected area was scanned.----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------Logfile of random's system information tool 1.04 (written by random/random... Read more

A:Infected: Trojan.Win32.Agent.arng, Trojan-Proxy.Win32.Agent.bcw, IRC-Worm.Win32.Small.x, Backdoor.Win32.Agent.ubx

4 more replies

I can't post a log because when I run MalwareBytes and Copy the log to clipboard it comes up empty.  But Malwarebytes keeps finding three persistent malware that it keeps saying it quarantined and I try to delete, but they show up after every single scan.

I've posted the image above and attached it to this post.  Help me get rid of these please.

Trojan.Agent   Malwarebytes Anti-Malware
www.malwarebytes.org

Scan Date: 2/5/2015
Scan Time: 11:31:39 PM
Logfile:

Version: 0.00.0.0000
Malware Database: v2015.02.06.03
Rootkit Database: v2015.02.03.01
Malware Protection: Enabled
Malicious Website Protection: Enabled
Self-protection: Disabled

OS: Windows 8.1
CPU: x64
File System: NTFS
User: SillyTilly

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 373147
Time Elapsed: 22 min, 24 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 0
(No malicious items detected)

Registry Values: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Folders: 0
(No malicious items detected)

Files: 0
(No malicious items detected)

Physical Sectors: 0
(No malicious items detected)

(end)

A:Trojan.Agent, Backdoor.Agent.CHGen, & Backdoor.Agent.E

36 more replies

Hi,

I currently am running windows xp and performed a virus scan using avira antivirus. The scan came back with two different viruses showing up. One was TR/agent.66048.153 and the other was adware/agent.180224.a. These both showed as being unppc.exe and ppal3ppc.exe. I have people pc files still on my computer but i thought i had deleted the program and the files ages ago. Am i infected with viruses?

Thanks.

8 more replies

I am running Windows 7, 32-bit.  I use AVG and Spybot S&D as antivirus, and haven't had an issue in over 10 years that I wasn't able to clear up myself with these antivirus programs and by reading through these forums ;)   My computer has been running very slow for several months, but I haven't bothered to mess with it much.  With the introduction of smartphones and tablets, my family doesn't use our desktop as often.  Long story short, I haven't kept up on updating and scanning my computer.  I finally decided to look into it, and I seem to have something that is being extremely deceptive that I have never dealt with before.  I ran my normal antivirus and was told on top of several PUPS, I had Trojan.Agent/Gen-Agent and exploit:js/axpergle.  These were found by different antivirus software, I cannot tell you which ones as I've run so many since then I can't remember.  Anyway, the programs say they've taken care of the issue, but clearly I am still harboring a Trojan. Problems I've encountered since "removing" these Trojans: unable to start command prompt - I received an error.  Unable to turn on Windows Defender - error.  Unable to update other antivirus programs - error.  With some antivirus programs I get an error saying it can't update, then it says it was updated.  Then I run it, it finds issues, it says it has deleted them, but it hasn't done anything.  I have run all of these things in s... Read more

A:Trojan.Agent/Gen-Agent and exploit:js/axpergle

67 more replies

Like everyone else who writes, I need HELP. Last week I ended up with Trojan.Agent on my computer but was able to get rid of it with Malwarebytes and several other programs. A couple of days ago I noticed I have no sound on my computer. I ran Malwarebytes again and it found and quarantined CrackTool.Agent. I went ahead and deleted it thinking that would solve my problem. Nope. I have read other fixes for this on your site but am not savvy enough to feel comfortable just executing without some hand holding. Can you help?

A:Trojan.Agent last week, now CrackTool.agent

18 more replies

I can't get rid of those trojans here is the hjt log plus the files emplacements PLEASE HELP.

A:I'm stuck with 4 trojans.agent.fd and a backdoor agent.ahj

16 more replies

Trojan appears to be gone but computer doesnt function normally. I have tried several malware removal tools, forum solutions of somilar issues, and restore to a previous time with no luck.
.
DDS (Ver_11-03-05.01) - NTFS_AMD64
Run by carol at 13:57:24.79 on Fri 03/18/2011
Internet Explorer: 8.0.7600.16385
Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.4056.2500 [GMT -7:00]
.
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_afc3018f8cfedd20\STacSV64.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRYSVC.EXE
C:\Windows\system32\WLANExt.exe
C:\Windows\system32\conhost.exe

A:trojan.agent/Gen-iefake trogjan.agent/Gen-PEC

Hello and welcome to Bleeping Computer We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here. Please take note: If you have since resolved the original problem you were having, we would appreciate you letting us know. If you are unable to create a log because your computer cannot start up successfully please provide detailed information about your installed Windows Operating System including the Version, Edition and if it is a 32bit or a 64bit system.

4 more replies

Looking through my BIOS settings and noticed a setting called "Legacy USB" and it is enabled. I noticed that according to the latest BIOS upgrade that the default for this setting was "disabled"

Currently my printer, my digital camera and an external hard drive are connected to USB ports. Should this setting be enabled or not?

A:Legacy: Yes or No

Probably not. You usually need it enabled if you have a USB Keyboard or USB mouse that you need to use during a boot up (befor you get to windows). Enabling it can cause some problems with USB printers and other USB devices on some systems.

1 more replies

My computer keeps prompting me to run a legacy! What is a legacy? and when I run it I get a screen showing what looks like a series of jack locations ????

A:What is a legacy?

Can you post a screen shot of this message?

2 more replies

Currently, I'm capturing a shared printer in a batch file using:

net use lpt1: \\servername\sharename

We use the batch file in a legacy report writing app called RR which is completely DOS based. We've been having problems with the server share and want to eliminate it. The printer does have an IP address and we'd like to capture it using that. I have tried all kinds of captures. I believe the closest I have gotten is:

Please bear in mind that this legacy app is running on Win9x as well as XP so the DOS command must work in both versions of the OS. RR requires the logical printer port (lpt1) to be used so I cannot create a port and set it to print to that. I have been successful in creating Standard TCP/IP Ports on 9x machines using an HP app. Is there a way to setup a port on the machine I'm printing from and capture that port? Thanks.

A:Legacy App RR

1 more replies

Is there an AIM client that takes up very little CPU out there?

I would look myself, but i have no clue what I could search for.

A:Low CPU AIM Clients?

6 more replies

I have been using ICQ for some time now but I do not like the new google ad features etc - i just dont want nor need such bloat. I tried to load an older version of the client but it just loaded up the new one instead !

Is there a messenger out there (not Trillian or Odigo as ive tried these and they dont work too good) that can incorporate my ICQ contacts. Id use yahoo messenger but i dont think it allows messages from ICQ.

A:IM clients

i dont chat much but this is what i use GAIM

it is compatable with icq,yahoo,and aim. it was compatible with msn but not sure any more. and you always need to update because the chat services do not like the use of programs like these. and try to block them. but the writers of these programs find ways to counter this.

1 more replies

Can someone recommend a good ssh client?

A:ssh clients

I've only used putty with no probs.

1 more replies

Anyone have any success trying to get VPN working successfuly? The only client I am aware of is this one by NCP Software I would rather get a free version than pay what they are asking for.

A:VPN clients fow W7

I am also looking for a 64 bit VPN client. The prior cisco one I was using does not work with 64 bit OS.

2 more replies

HI,

I have a problem that my VPN Clients connecting to Microsoft TMG are able to connect to network but than when they try to connect to a computer by its name it is not connecting, but are able to connect with the IP address. When I am seeing the logs it is saying that they are being denied from using port 137 (Netbios Name Service) and Port 5355.

This could be done by a change in the system policy rules of TMG.

Any help which can be the rules affected?

Thanks.

More replies

I saw an ATA demo where clients were used instead of a gateway. I can't seem to find any documentation on where to get the DC client or the deployment guide. Anyone have info or a link?

More replies

From: Eric

I received a computer running XP Media Center Edition from a friend. Its desktop was being hidden automatically unless I told it to "show desktop". I ran SuperAntiSpyware and MBAM on it. They seemed to have removed the viruses. In preparation of this topic I ran GMER, which would not run so I ran TDSSkiller. TDSSkiller got rid of a rookit virus. What I need now is to make sure that the computer is completely clean. Here are the DDS and GMER reports.

Thank you

DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 8.0.6001.18702
Run by sherri cordry at 20:08:08 on 2011-11-05
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2550.1770 [GMT -5:00]
.
AV: McAfee Anti-Virus and Anti-Spyware *Enabled/Updated* {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Firewall *Enabled*
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
C:\Program Files\Common Files\Apple\Mobile Device S... Read more

A:Comp was infected with Trojan.Agent/Gen-Fake AV, Trojan.Agent/Gen-Hullo[short], Rootkit virus

26 more replies

I believe I was infected last night when a website somehow redirected me to liteautogreatest{dot}cn.I'm running XP Home SP3 and the ZoneAlarm Internet Security Suite (just updated earlier today).ZoneAlarm continually finds a couple of problems and hibernates them but they do not go completely away after a reboot.The ZoneAlarm active monitor scan shows the following...Trojan-Dropper.Win32.Agent.amzh was found in C:\Documents and Settings\Don\Local Settings\Temp\BNB.tmp on 4/20/2009 13:29:22Trojan-Dropper.Win32.Agent.amzh was found in C:\Documents and Settings\Don\Local Settings\Temp\BNA.tmp on 4/20/2009 13:23:26Trojan-Dropper.Win32.Agent.amzh was found in C:\Documents and Settings\Don\Local Settings\Temp\BN9.tmp on 4/20/2009 13:17:40Trojan-Dropper.Win32.Agent.amzh was found in C:\Documents and Settings\Don\Local Settings\Temp\BN8.tmp on 4/20/2009 13:14:30Trojan-Dropper.Win32.Agent.amzh was found in C:\Documents and Settings\Don\Local Settings\Temp\BN7.tmp on 4/20/2009 13:07:26Trojan-Dropper.Win32.Agent.amzh was found in C:\Documents and Settings\Don\Local Settings\Temp\BN6.tmp on 4/20/2009 13:02:40Rootkit.Win32.Agent.ikz was found in C:\WINDOWS\system32\drivers\systemntmi.sys on 4/20/2009 12:57:48Trojan-Dropper.Win32.Agent.amzh was found in C:\Documents and Settings\Don\Local Settings\T... Read more

A:Infected with Rootkit.Win32.Agent.ikz, Trojan-Dropper.Win32.Agent.amzh, Trojans? Malware?

3 more replies

Hi,

I'm bringing in my girlfriend's laptop, she downloaded something which harmed her laptop. I can't connect to the internet, whatever it is seems to halt any connection. I did an Avira boot up scan because there was no way anything could run once windows vista would start running. Please help, I would like to remove whatever it is that was downloaded.

Thank you!

Julio.
DDS (Ver_10-11-10.01) - NTFS_AMD64
Run by Erika at 21:31:31.35 on Sun 11/21/2010
Internet Explorer: 8.0.6001.18975
Microsoft? Windows Vista? Home Premium 6.0.6001.1.1252.1.1033.18.4062.2671 [GMT -5:00]

SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}

============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\system32\Ati2evxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService

A:Infected with Meredrop/Agent HY/Agent AH

Hi,Welcome to Bleeping Computer. My name is m0le and I will be helping you with your log.Please subscribe to this topic, if you haven't already. You can subscribe by clicking the Options box to the right of your topic title and selecting Track This Topic.

Please avoid installing/uninstalling or updating any programs and attempting any unsupervised fixes or scans. This can make helping you impossible.

Please reply to this post so I know you are there.The forum is busy and we need to have replies as soon as possible. If I haven't had a reply after 3 days I will bump the topic and if you do not reply by the following day after that then I will close the topic.Once I receive a reply then I will return with your first instructions.Thanks

2 more replies

Was trying to open internet explorer and a virus popup occurred. Stated that I had multiple viruses and started scanning my computer.
This popup was not from my anti virus program, so I closed the program and and my virus program scanned and these items appeared. Now
every time I look up a website, I get redirected,especially when I was looking for help from your site and others. I could not click on the
main web page site, I would have to click on on of the forum feeds in order to not be redirected.
DDS (Ver_10-12-12.02) - NTFSx86
Run by Brenda at 20:01:56.59 on Fri 12/17/2010
Internet Explorer: 8.0.7600.16385
Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.3062.1468 [GMT -5:00]

AV: Lavasoft Ad-Watch Live! Anti-Virus *Enabled/Updated* {DAAC1C79-1A96-9DFE-FC4C-6940214C33E6}
AV: AntiVir Desktop *Enabled/Updated* {090F9C29-64CE-6C6F-379C-5901B49A85B7}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Lavasoft Ad-Watch Live! *Enabled/Updated* {61CDFD9D-3CAC-9270-C6FC-52325ACB795B}
SP: AntiVir Desktop *Enabled/Updated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A}

============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted

A:TR/Agent.163840.A, TR/Agent.awz & TR/Spy.24064.7

Hi,Welcome to Bleeping Computer. My name is m0le and I will be helping you with your log.Please subscribe to this topic, if you haven't already. You can subscribe by clicking the Options box to the right of your topic title and selecting Track This Topic.

Please avoid installing/uninstalling or updating any programs and attempting any unsupervised fixes or scans. This can make helping you impossible.

Please reply to this post so I know you are there.The forum is busy and we need to have replies as soon as possible. If I haven't had a reply after 3 days I will bump the topic and if you do not reply by the following day after that then I will close the topic.----------------------------------------------Download TDSSKiller and save it to your Desktop.

Extract its contents to your desktop and make sure TDSSKiller.exe (the contents of the zipped file) is on the Desktop itself, not within a folder on the desktop.

Go to Start > Run (Or you can hold down your Windows key and press R) and copy and paste the following into the text field. (make sure you include the quote marks) Then press OK.

"%userprofile%\Desktop\TDSSKiller.exe" -l report.txt

Now click Start Scan.
If Malicious objects are found, ensure Cure is selected then click Continue > Reboot now.
Click Close
Finally press Report and copy and paste the contents into your next reply. If you've rebooted then the log will be found at C:\

19 more replies

Whenever I join a Gunz game, i see at the bottom left

Agent Error:Agent Not Available.

This is usually a port-forwarding issue, but mine are fine. I have played this game fine before with max settings, and it ran smooth. Now its just acting up. I have re-installed and still nothing. I can walk around but shows everyone lagging(which means I am).

More replies

Samsung NC10 notebook running Windows XP, Avast (free), Zonealarm, Spywareblaster, Firefox & Opera are favoured browsers. It is my usual practice to run at least one of Avast/SuperAntiSpyware/Malwarebytes daily.~~~~~~~~~~A few days ago a full scan with SuperAntiSpyware found and removed two Trojans: Agent/Gen-Siggen and Agent/Gen-AgentSmall. A second scan immediately after restarting the computer was clear, as was a scan with Malwarebytes for a second opinion. The problem since then is with Avast, it seems to have been disabled.The 'Fix now' button does nothing and the 'Start program' link does nothing. It is the free version and the current registration is valid until 25 January 2013.I tried System Restore for two dates well before the infection but they both failed.I have tried to install AVG for some protection in the meantime but get a message saying that an administrator needs to perform the installation - I am the sole user of this computer which makes me think that some setting has been tampered with.I have run either Malwarebytes or SAS (or both) daily since the Trojan removal and they have been clear every time.So my main question, is it likely that I am still infected?If not, how do I reinstate Avast?Any advice appreciated, thanks in advance.~~~~~~~~~The scan log for the Trojans:SUPERAntiSpyware Scan Loghttp://www.superantispyware.comGenerated 12/21/2012 at 05:47 PMApplication Version : 5.6.1014Core Rules Database Version : 9776Trace Rules Dat... Read more

A:Agent/Gen-Siggen and Agent/Gen-AgentSmall

Hello, these are new False Possitives and shoud not be Removed. This should be fixed in the next update.
Easiest way to fix this is to Uninstall Avast and Reinstall it.

Until the update uncheck these so they will not be removed
https://www.dropbox.com/s/jxeqimsbatm7y4f/SAS%20issue.png

3 more replies

Greetings,I seem to have gotten infected with the Rootkit.Agent.H and Trojan.Agent malwares.I have: run disk cleaners CCleaner manually emptied the IE (which I don't use) and Firefox caches and cookies cleaned all my temp files emptied my recycle bin run Trend Officescan, which didn't find anything run SUPERAntiSpyware, which didn't find anything. run MalwareByte's Anti-Malware, which found the two dealies above and said it was going to fix them on reboot, but didn't (log below). run Combofix, which said that it found and deleted the two dealies above, but didn't (log below). have a HijackThis log. I don't know what to do from this point. The only two things that actually find these infections are mbam and combofix, but neither of them seem to be able to clean them from my system.HELP!!!Pax Dominus-------------------------------------------MalwareByte's Anti-Malware LogMalwarebytes' Anti-Malware 1.34Database version: 1801Windows 5.1.2600 Service Pack 32/25/2009 8:23:51 AMmbam-log-2009-02-25 (08-23-32).txtScan type: Quick ScanObjects scanned: 82083Time elapsed: 4 minute(s), 7 second(s)Memory Processes Infected: 0Memory Modules Infected: 0Registry Keys Infected: 0Registry Values Infected: 0Registry Data Items Infected: 0Folders Infected: 0Files Infected: 2Memory Processes Infected:(No malicious items detected)Memory Modules Infected:(No malicious items detected)Registry Keys Infected:(No malicious items detected)Registry Values Infected:(No malicious items detected)... Read more

A:Rootkit.Agent.H and Trojan.Agent

22 more replies

Hi there, thanks for the help in advance.

I have the following problems: I reinstalled vista and several programs a few days ago, probably my computer got infected in some way. I started having a black screen after windows logon (I needed to run taskmgr and then run explorer for windows vista to finish the startup). Just today I noticed my date was changed to 2088, an error of svchost trying to run TDSScrrx.dll, my Windows Security Center could not be turned on. Then I removed Norton, after it did not work at all, I installed Malwarebytes and it detected and quarantined several files. The TDSScrrx.dll error at startup stopped happening. I also got into regedit Computer\HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon and altered "Shell" from "Explorer.exe "C:\Windows\mchost.exe" to "Explorer.exe", this seemed to correct the Black screen at startup problem but unfortunately every time I restart the Shell is changed back to "Explorer.exe "C:\Windows\mchost.exe"". What can I do to correct this forever? Also I have ran services.msc and trying to enable automatically the Security Center service (only successfully after changing "shell" at registry as previously commented) but once again, after booting my windows Security Center appears disabled every time. I just reinstalled NAV 08 but it seems I still have the problem with my registry changin... Read more

A:Trojan.Agent and Rootkit.Agent

Hi

If you still have above mentioned problem post a fresh dds log, please.

2 more replies

Hi guys,

Here it is in a nutshell. I have a legacy camera ricoh rdc-300 I am using on winxp pro. Now I used to be able to connect my camera to a rs-232 com1 port on my pc and I used to download files off of my camera using the Photosuite lite software. This worked for a month then I strated recieving the error message when I would download my files "Can't connect to ricoh camera" usually after 30 seconds so it is trying to connect. Thereafter, I decided to use a rs-232 serial to usb adapter, it worked for another month and now I started getting the same error message.

Trobleshooting

I have uninstalled and re-installed the software drivers, etc. and even turned the firewall off, all to no avail. I really don't want to sell my Ricoh camera because the macro focus is manual.

Also, I downloaded the patch off the Ricoh site and tried its software for xp and get the same message "Can't connect to ricoh..." Does anyone have any ideas? I really love my camera and my wife uses it for her online business. Even any advice for who I can call for help would be appreciated.

Tim Dupuis

More replies

Running IPISB-CU (Carmel2) MOBO chipset. Got the new MSI GTX 750 ti with legacy switch.  Manufacturer: PegatronForm factor: uATX - 24.4 cm (9.6 inches) x 24.4 cm (9.6 inches)Chipset: Intel H61  (Video integrated)Both switch settings will not work. I am unable to update the video hardware using this card. Will not boot. Just wanted others to be aware that this chipset configuration (Carmel2) may not work even with the legacy switch.My Bio's is fully updated to the most recent one.

More replies

I'm not sure what to post this under but I need help!

Some time ago we were running a 5 workstation peer to peer network running Windows 98 on a 10 base T network. We used a program called CEI which is a healthcare application. It ran fine on this setup. We upgraded our network to a 20 workstation client / server based network running Windows 2000 Professional on the workstations and Windows 2000 Server on a 100 Base TX network. The problem were having is the speed of CEI. It went from going a few seconds between screen redraws to 1.5 mins at it's worst. I can not figure out why! When I attached a Win98 machine to the new server it runs fine. Any suggestions? The server (just for reference) is running DHCP, DNS, and Active Directory.

Jnar

A:Legacy Problems

closing duplicate, please don't post the topic more than once. You can always ask a moderator to move it to another forum if you don't get any responses.

1 more replies

Is it safe to disable it? Some tech on the logitech forums told me to cause my mouse would sometimes crap out on restart, just with the light blinking and i would have to unplug it and re plug it.

So im wondering is it safe to disable usb legacy mode in bios? do i need it?

A:USB Legacy Mode

Hello Soto,

I would just leave it enabled in case you need it. It will not harm anything to do so, or use any additional resources.

5 more replies

I found this article interesting, although topic matter has been discussed here.

One thing perhaps new is that we can add Photo Shop 3 to the list of programs that run under Win 8.

Exploring legacy tools in Windows 8

A:Legacy programs in Win 8

I love that line:

if you’re concerned about where Windows 8′s flashy new approach leaves users of legacy systems

Man, if we're still concerned about legacy programs and systems, it's no wonder people are so aversive to change. Frankly I'm surprised we still manage to innovate with all this focus on legacy.

16 more replies