Prompt kept taking me to download PurityScan

Thread Solved

Join Date: Feb 2004
Posts: 10,099
Reputation: crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold 
Solved Threads: 766
Moderator
Featured Poster
crunchie's Avatar
crunchie crunchie is offline Offline
Spyware Killer

Re: Prompt kept taking me to download PurityScan

 
0
  #11
May 10th, 2004
Hang on a while as I am going to try to get some higher help on this one for you. It probably came back because it needs to be deleted manually from the folder. Just leave it at the moment & I will get back.
Reply With Quote Quick reply to this message  
Join Date: Feb 2004
Posts: 10,099
Reputation: crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold 
Solved Threads: 766
Moderator
Featured Poster
crunchie's Avatar
crunchie crunchie is offline Offline
Spyware Killer

Re: Prompt kept taking me to download PurityScan

 
0
  #12
May 11th, 2004
Web-Based EnterpriseManagement (WBEM)

I checked this clsid {357AA41A-B7A8-4632-A27D-5B980B25CF43}

and found StripPlayer http://www.pestpatrol.com/pestinfo/s/stripplayer.asp

It's a dialer/downloader. May also include WinMgts, a trojan.

If you have *stripplayer* in program files or add remove programs, uninstall it. If you cannot then you will have to do it manually, possibly in safe mode. The WBEM folder has to go too, again, possibly in safe mode.
Reply With Quote Quick reply to this message  
Join Date: May 2004
Posts: 9
Reputation: lctsay is an unknown quantity at this point 
Solved Threads: 0
lctsay lctsay is offline Offline
Newbie Poster

Re: Prompt kept taking me to download PurityScan

 
0
  #13
May 11th, 2004
You mean the whole WEBM folder? What about the other files inside that folder?
I don't think I have *stripplayer*, but I will double check. So basically I need to remove O4 - HKLM\..\Run: [{357AA41A-B7A8-4632-A27D-5B980B25CF43}] C:\WINNT\system32\wbem\svchost.exe? I have already try it once but again it will just replicated itself after I reboot.
Reply With Quote Quick reply to this message  
Join Date: Feb 2004
Posts: 10,099
Reputation: crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold 
Solved Threads: 766
Moderator
Featured Poster
crunchie's Avatar
crunchie crunchie is offline Offline
Spyware Killer

Re: Prompt kept taking me to download PurityScan

 
0
  #14
May 11th, 2004
Instructions are to fix this with hijackthis:

O4 - HKLM\..\Run: [{357AA41A-B7A8-4632-A27D-5B980B25CF43}] C:\WINNT\system32\wbem\svchost.exe

Boot into safe mode & navigate to the WBEM folder, find the svchost.exe file there & delete it manually. Empty the recycle bin, TempIntFiles, & Windows\Temp folder contents. Do not delete the WBEM folder. Sorry, glad you checked back.
Reply With Quote Quick reply to this message  
Join Date: May 2004
Posts: 9
Reputation: lctsay is an unknown quantity at this point 
Solved Threads: 0
lctsay lctsay is offline Offline
Newbie Poster

Re: Prompt kept taking me to download PurityScan

 
0
  #15
May 11th, 2004
So basically you are saying to use Hijackthis to fix this file by check it from the list after I do another scan and then click fix? Then I re-boot my comp in safe mode and go into my hard drive to remove everything that shows O4 - HKLM\..\Run: [{357AA41A-B7A8-4632-A27D-5B980B25CF43}] C:\WINNT\system32\wbem\svchost.exe? How about the backup file that Hijackthis will save when I use it to clean in the first place?

So are you saying that this file is definitely the cause of my problme? Also I see this file get start up from the msconfig's System Configuration Utility. How can I delete that from this start-up? I don't want just uncheck it from the list. I want it to be delete from the option. How can I do that?

Thanks for your help!!
Reply With Quote Quick reply to this message  
Join Date: Feb 2004
Posts: 10,099
Reputation: crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold 
Solved Threads: 766
Moderator
Featured Poster
crunchie's Avatar
crunchie crunchie is offline Offline
Spyware Killer

Re: Prompt kept taking me to download PurityScan

 
0
  #16
May 11th, 2004
Yes to most of what you are asking. Once in safe mode go to the WBEM folder & remove the svchost.exe file from there. I recommend that no backups be removed for a few days to be certain that your comp runs ok.
The ONLY place on your machine where that file should be is directly in the system32 folder, nowhere else.
Are you still getting the original problem?
Reply With Quote Quick reply to this message  
Join Date: Feb 2004
Posts: 10,099
Reputation: crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold 
Solved Threads: 766
Moderator
Featured Poster
crunchie's Avatar
crunchie crunchie is offline Offline
Spyware Killer

Re: Prompt kept taking me to download PurityScan

 
0
  #17
May 11th, 2004
From answers that work:

Many viruses masquerade themselves as SVCHOST to escape detection. Some have names that are similar, such as SCCHOST, others actually drop a program file called SVCHOST in the Windows folder or a Windows sub‑folder.

Recommendation :
The first recommendation is a simple one : always have a good antivirus product which is regularly updated (automatically preferably) and always renew your updates subscription when it expires. To detect if you have a virus that calls itself SVCHOST, first see if its full path shows up in The Ultimate Troubleshooter as either C:\WinNT\System32\Svchost.exe or C:\Windows\System32\Svchost.exe – if it does not, then it is almost certain you have a virus. Secondly, if you have Windows 95/98/ME rather than Win2000/XP/2003, then it is also almost certain you have a virus. Thirdly, go to the Services tab of The Ultimate Troubleshooter and look for the following service – if you find it then you probably have a virus too :
Reply With Quote Quick reply to this message  
Join Date: May 2004
Posts: 9
Reputation: lctsay is an unknown quantity at this point 
Solved Threads: 0
lctsay lctsay is offline Offline
Newbie Poster

Re: Prompt kept taking me to download PurityScan

 
0
  #18
May 12th, 2004
I just try everything and it still doesn't work.

I reboot my comp to safe mode and then going thru everywhere to delete all the files contained svchost.exe, with the exception of the "real" one in
C:\WinNT\System32\, I deleted everything. The prompt still comes up every 10 minutes or so.
Reply With Quote Quick reply to this message  
Join Date: May 2004
Posts: 9
Reputation: lctsay is an unknown quantity at this point 
Solved Threads: 0
lctsay lctsay is offline Offline
Newbie Poster

Re: Prompt kept taking me to download PurityScan

 
0
  #19
May 12th, 2004
By the way, after I deleted all the svchost.exe in safe mode, I reboot my comp and svchost come back again in both C:\Windows\System32\webm\Svchost.exe and in the registry. Something is replicating this over and over again whenever I try to delete the file.
Reply With Quote Quick reply to this message  
Join Date: Feb 2004
Posts: 10,099
Reputation: crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold 
Solved Threads: 766
Moderator
Featured Poster
crunchie's Avatar
crunchie crunchie is offline Offline
Spyware Killer

Re: Prompt kept taking me to download PurityScan

 
0
  #20
May 12th, 2004
Ok. What is the exact words of the prompt?
Delete your temp internet files. Delete the contents of all temp folders. You may have to show hidden folders. Empty the recycle bin. Disable system restore temporarily.
Go & have another online scan please. We will set a new system restore point later. Note that all previous restore points will be lost.
Reply With Quote Quick reply to this message  
Reply

This thread has been marked solved.
Perhaps start a new thread instead?
Message:



Other Threads in the Viruses, Spyware and other Nasties Forum
Thread Tools Search this Thread



Tag cloud for Viruses, Spyware and other Nasties
About Us | Contact Us | Advertise | DaniWeb | Acceptable Use Policy | RSS Feed

©2003 - 2009 DaniWeb® LLC