Hijackthis Log --twunk 16 And Twunk 32

I have been trying to fix it, but with no success.

It allows the user to scan images or text directly from the scanner onto the application that will be used to manipulate the image or text. Hier der log : Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 15:55:36, on 02.09.2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal My PC Clinic ( - Windows PC Help ( - - FreeFixer ( Eve 02-13-2008 05:57 PM FreeFixer Freefixer I saw a link for this on Surferdudes C:\Program Files\Insider C:\Program Files\Insider\UnInstall.exe C:\Program Files\sstem~1 C:\Program Files\Temporary C:\temp\tn3 C:\WINDOWS\b111.exe C:\WINDOWS\b128.exe C:\WINDOWS\b138.exe C:\WINDOWS\b147.exe C:\WINDOWS\cookies.ini C:\WINDOWS\system32\aloypudt.exe C:\WINDOWS\system32\avpciaaj.ini C:\WINDOWS\system32\bbwqtfhf.ini C:\WINDOWS\system32\bhcltdrh.dll C:\WINDOWS\system32\ciggwrvo.dll C:\WINDOWS\system32\ddcyw.dll C:\WINDOWS\system32\drivers\core.cache.dsk C:\WINDOWS\system32\drivers\core.sys C:\WINDOWS\system32\ebfaheh.dll C:\WINDOWS\system32\fhftqwbb.dll C:\WINDOWS\system32\foitpdrv.dll C:\WINDOWS\system32\hknksokp.dll C:\WINDOWS\system32\ikopiivj.dll C:\WINDOWS\system32\jaaicpva.dll C:\WINDOWS\system32\jkkklmk.dll C:\WINDOWS\system32\kjvdisid.exe C:\WINDOWS\system32\olieakuq.exe

Note: Do not mouseclick combofix's window while it's running.

Here were my results, which were a little different:Logfile of HijackThis v1.99.1Scan saved at 7:03:15 PM, on 10/16/2007Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v7.00 (7.00.6000.16544)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\Program Files\Intel\Wireless\Bin\EvtEng.exeC:\Program Files\Intel\Wireless\Bin\S24EvMon.exeC:\Program Files\Common C:\WINDOWS\system32 No streams found. Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dllO2 - BHO: (no name) - H?07962-6F74-2D53-2644-206D7942484F} - (no file)O2 - BHO: (no name) - x?3D70E-1895-11CF-8E15-001234567890} - (no file)O2 - BHO: &Yahoo! Register now to gain access to all of our features, it's FREE and only takes one minute.

Hijackthis log --twunk 16 and twunk 32 I know I have twunk adware, but I can't get rid of it.

C:\SDFix\Report.txt SDFix: Version 1.118 Run by Bowdens on Sun 12/16/2007 at 05:26 PM Microsoft Windows XP [Version 5.1.2600] Running From: C:\SDFix Safe Mode: Checking Services: Restoring Windows Registry Values Restoring Windows That may cause it to stall

The word TWAIN is not an official acronym; however, it is widely known as "Technology Without An Interesting Name." The official website notes that "[this name] seems to haunt the standard. Please copy this page to Notepad and save to your desktop for reference as you will not have any browsers open while you are carrying out portions of these instructions.

Not Found The requested URL /news/How_to_Remove_Twunk_32,_twunk_32.exe_Manual_Removal_.html was not found on this server.

Dazu arbeite bitte diese Anleitung ab.

Please post the C:\ComboFix.txt along with a new HijackThis log so we can continue cleaning the system.

Final Check: catchme 0.3.1262.1 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, Rootkit scan 2007-12-16 17:33:10 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... Normal Mode: Checking Files: Trojan Files Found: C:\DOCUME~1\BOWDENS\APPLIC~1\MICROS~1\WINDOWS\FVNMM.EXE - Deleted C:\PROGRA~1\MESSEN~1\VINOFO~1.EXE - Deleted Removing Temp Files...

Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dllO4 - HKLM\..\Run: [Tvs] "C:\Program Files\Toshiba\Tvs\TvsTray.exe"O4 - HKLM\..\Run: [THotkey] "C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe"O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exeO4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exeO4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exeO4 - HKLM\..\Run: scan completed successfully hidden files: 0 ************************************************************************** . The time now is 02:54 PM. This one, while not on any "don't use" lists yet it isn't on any "highly recommended lists" either.

When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons. I don't know the specifics, but look up "twunk16.exe and twunk32.exe" here... With the above script, ComboFix will capture files to submit for analysis.Ensure you are connected to the internet and click OK on the message box.

Under MS Windows there are two TWAIN Data Source Manager modules, the 16-bit TWAIN.DLL and the 32-bit TWAIN_32.DLL. It's IMPORTANT to carry out the instructions in the sequence listed below. Download SDFix and save it to your Desktop.


