Wireshark virus - Page 3
Page 3 of 6 FirstFirst 12345 ... LastLast
Results 31 to 45 of 90

Thread: Wireshark virus

  1. #31
    Join Date
    Nov 2000
    Location
    Hollansburg, OH, USA
    Posts
    272

    Its to big for one post.

    Settings\Pam\My Documents\campedit3newarrow[1].jpg
    [2010/07/18 13:58:12 | 000,024,576 | ---- | C] () -- C:\Documents and Settings\Tim\My Documents\Dependable Astro AWD won.doc
    [2010/07/17 15:50:59 | 000,020,610 | ---- | C] () -- C:\Documents and Settings\Pam\My Documents\GS Clip art.docm
    [2010/07/17 15:44:54 | 000,000,553 | ---- | C] () -- C:\Documents and Settings\Pam\Desktop\Shortcut to GS Clip art.lnk
    [2010/07/17 15:42:28 | 000,030,208 | ---- | C] () -- C:\Documents and Settings\Pam\My Documents\GS Clip art.doc
    [2010/07/17 15:34:24 | 000,000,796 | ---- | C] () -- C:\Documents and Settings\Pam\Desktop\Shortcut to girl scout leader tent camping.lnk
    [2010/07/17 15:34:13 | 000,000,696 | ---- | C] () -- C:\Documents and Settings\Pam\Desktop\Shortcut to GS promise.lnk
    [2010/07/17 15:33:58 | 000,000,686 | ---- | C] () -- C:\Documents and Settings\Pam\Desktop\Shortcut to GS troop.lnk
    [2010/07/06 07:19:37 | 000,008,192 | -H-- | C] () -- C:\WINDOWS\system32\config\systemprofile\ntuser.dat.LOG
    [2010/06/25 08:13:09 | 003,932,160 | ---- | C] () -- C:\Documents and Settings\Tim\ntuser.dat
    [2010/04/30 03:00:12 | 011,272,192 | ---- | C] () -- C:\Documents and Settings\Pam\ntuser.dat
    [2010/04/30 03:00:12 | 000,327,680 | ---- | C] () -- C:\WINDOWS\system32\config\systemprofile\ntuser.dat
    [2010/03/30 15:03:37 | 000,000,181 | ---- | C] () -- C:\Documents and Settings\Pam\Application Data\default.pls
    [2010/03/01 06:46:23 | 000,000,170 | ---- | C] () -- C:\Documents and Settings\Tim\Application Data\default.pls
    [2010/02/24 21:03:31 | 000,001,024 | ---- | C] () -- C:\Documents and Settings\Pam\.rnd
    [2010/01/07 13:05:40 | 000,000,100 | ---- | C] () -- C:\WINDOWS\ka.ini
    [2009/12/31 20:32:12 | 000,023,040 | ---- | C] () -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    [2009/12/27 21:02:51 | 000,087,552 | ---- | C] () -- C:\WINDOWS\System32\cpwmon2k.dll
    [2009/11/09 12:32:04 | 000,000,330 | ---- | C] () -- C:\WINDOWS\RBuilder.ini
    [2009/10/18 17:08:52 | 000,000,034 | ---- | C] () -- C:\WINDOWS\Sierra.ini
    [2009/09/30 19:10:39 | 000,147,456 | ---- | C] () -- C:\WINDOWS\System32\lttls13n.dll
    [2009/09/30 19:10:34 | 000,708,608 | ---- | C] () -- C:\WINDOWS\System32\ltcry13n.dll
    [2009/09/30 19:10:29 | 000,118,784 | ---- | C] () -- C:\WINDOWS\System32\lfkodak.dll
    [2009/09/30 19:10:28 | 000,338,944 | ---- | C] () -- C:\WINDOWS\System32\lffpx7.dll
    [2009/08/28 10:58:31 | 000,177,664 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
    [2009/08/03 15:07:42 | 000,403,816 | ---- | C] () -- C:\WINDOWS\System32\OGACheckControl.dll
    [2009/07/24 23:15:31 | 000,004,096 | ---- | C] () -- C:\WINDOWS\System32\drivers\nocashio.sys
    [2009/06/03 21:22:47 | 000,007,207 | R--- | C] () -- C:\WINDOWS\Disktool.INI
    [2009/06/03 21:22:47 | 000,006,399 | R--- | C] () -- C:\WINDOWS\fwupgrade.ini
    [2009/06/03 21:22:47 | 000,003,677 | R--- | C] () -- C:\WINDOWS\PlaySnd.INI
    [2009/05/25 21:16:27 | 001,970,176 | ---- | C] () -- C:\WINDOWS\System32\d3dx9.dll
    [2009/05/22 20:23:23 | 000,000,034 | ---- | C] () -- C:\Documents and Settings\Pam\jagex_runescape_preferences.dat
    [2009/05/01 10:14:36 | 000,000,031 | ---- | C] () -- C:\WINDOWS\GunzLauncher.INI
    [2009/04/02 05:34:28 | 000,000,038 | ---- | C] () -- C:\WINDOWS\AviSplitter.INI
    [2009/03/12 05:38:23 | 002,788,800 | ---- | C] () -- C:\Program Files\FLV PlayerFCSetup.exe
    [2009/03/12 05:34:47 | 021,011,904 | ---- | C] () -- C:\Program Files\FLV PlayerRCSetup.exe
    [2009/02/12 21:01:22 | 000,884,736 | ---- | C] () -- C:\WINDOWS\gmer.dll
    [2009/02/12 21:01:22 | 000,000,250 | ---- | C] () -- C:\WINDOWS\gmer.ini
    [2009/02/08 13:50:23 | 000,000,178 | -HS- | C] () -- C:\Documents and Settings\Administrator\ntuser.ini
    [2009/02/08 13:50:21 | 000,057,344 | -H-- | C] () -- C:\Documents and Settings\Administrator\NtUser.dat.LOG
    [2009/02/08 13:50:20 | 000,786,432 | ---- | C] () -- C:\Documents and Settings\Administrator\ntuser.dat
    [2009/01/05 15:44:10 | 000,000,453 | ---- | C] () -- C:\WINDOWS\bdoscandellang.ini
    [2008/12/30 21:27:42 | 000,007,680 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
    [2008/12/30 21:27:42 | 000,000,547 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll.manifest
    [2008/12/30 21:27:40 | 000,348,160 | ---- | C] () -- C:\WINDOWS\System32\cdga.dll
    [2008/10/29 13:49:29 | 000,000,094 | ---- | C] () -- C:\Documents and Settings\Pam\couponmanager.properties
    [2008/10/16 03:02:03 | 000,000,118 | ---- | C] () -- C:\WINDOWS\System32\MRT.INI
    [2008/10/14 18:01:39 | 000,002,528 | ---- | C] () -- C:\WINDOWS\FCIC.INI
    [2008/10/08 20:07:09 | 000,000,034 | ---- | C] () -- C:\WINDOWS\cdplayer.ini
    [2008/09/09 18:48:09 | 000,000,107 | ---- | C] () -- C:\Documents and Settings\Tim\default.pls
    [2008/09/09 18:37:25 | 000,008,704 | ---- | C] () -- C:\Documents and Settings\Tim\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    [2008/09/09 18:24:17 | 000,000,126 | ---- | C] () -- C:\Documents and Settings\Tim\Local Settings\Application Data\fusioncache.dat
    [2008/09/09 18:10:52 | 000,000,151 | ---- | C] () -- C:\WINDOWS\PhotoSnapViewer.INI
    [2008/09/09 17:12:59 | 000,000,201 | ---- | C] () -- C:\Documents and Settings\Pam\default.pls
    [2008/09/09 17:00:33 | 000,000,126 | ---- | C] () -- C:\Documents and Settings\Pam\Local Settings\Application Data\fusioncache.dat
    [2008/09/07 08:37:32 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
    [2008/09/06 21:12:27 | 000,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
    [2008/09/06 17:09:39 | 000,038,912 | ---- | C] () -- C:\Documents and Settings\Pam\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    [2008/09/05 15:14:49 | 000,008,192 | -H-- | C] () -- C:\Documents and Settings\Tim\ntuser.dat.LOG
    [2008/09/05 15:14:49 | 000,000,278 | -HS- | C] () -- C:\Documents and Settings\Tim\ntuser.ini
    [2008/09/03 10:14:35 | 000,008,192 | -H-- | C] () -- C:\Documents and Settings\Pam\ntuser.dat.LOG
    [2008/09/03 10:14:35 | 000,000,278 | -HS- | C] () -- C:\Documents and Settings\Pam\ntuser.ini
    [2008/09/03 10:13:46 | 000,229,376 | ---- | C] () -- C:\Documents and Settings\LocalService\NTUSER.DAT
    [2008/09/03 10:13:46 | 000,008,192 | -H-- | C] () -- C:\Documents and Settings\LocalService\ntuser.dat.LOG
    [2008/09/03 10:13:46 | 000,000,020 | -HS- | C] () -- C:\Documents and Settings\NetworkService\ntuser.ini
    [2008/09/03 10:13:46 | 000,000,020 | -HS- | C] () -- C:\Documents and Settings\LocalService\ntuser.ini
    [2008/09/03 10:13:45 | 000,233,472 | ---- | C] () -- C:\Documents and Settings\NetworkService\NTUSER.DAT
    [2008/09/03 10:13:45 | 000,008,192 | -H-- | C] () -- C:\Documents and Settings\NetworkService\ntuser.dat.LOG
    [2008/03/04 19:52:34 | 000,286,720 | ---- | C] () -- C:\WINDOWS\System32\libcurl.dll
    [2007/11/26 22:56:28 | 000,151,415 | ---- | C] () -- C:\WINDOWS\System32\xlive.dll.cat
    [2007/10/31 10:39:54 | 000,059,904 | ---- | C] () -- C:\WINDOWS\System32\zlib1.dll
    [2007/08/06 19:22:15 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini
    [2007/06/28 06:54:10 | 000,180,224 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
    [2007/06/28 06:52:18 | 000,765,952 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
    [2007/05/17 14:58:10 | 000,143,360 | ---- | C] () -- C:\WINDOWS\System32\libexpatw.dll
    [2006/09/16 23:36:50 | 000,520,192 | ---- | C] () -- C:\WINDOWS\System32\CddbPlaylist2Roxio.dll
    [2006/09/16 23:36:50 | 000,204,800 | ---- | C] () -- C:\WINDOWS\System32\CddbFileTaggerRoxio.dll
    [2004/09/16 13:26:40 | 000,012,634 | ---- | C] () -- C:\WINDOWS\System32\drivers\ADFUUD.SYS
    [2004/09/16 13:26:40 | 000,012,634 | ---- | C] () -- C:\WINDOWS\ADFUUD.SYS
    [2003/03/31 08:00:00 | 000,138,368 | ---- | C] () -- C:\WINDOWS\System32\drivers\afd.sys

    ========== LOP Check ==========

    [2010/08/12 22:27:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Pam\Application Data\Abine
    [2008/11/10 19:42:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Pam\Application Data\Acoustica
    [2008/11/30 21:50:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Pam\Application Data\Advanced Browser
    [2010/01/29 17:34:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Pam\Application Data\Amazon
    [2009/04/06 15:34:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Pam\Application Data\Any DVD Converter Professional
    [2010/07/07 22:21:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Pam\Application Data\Azureus
    [2010/08/11 08:47:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Pam\Application Data\BitTorrent
    [2010/03/04 17:01:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Pam\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
    [2009/04/18 23:15:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Pam\Application Data\com.raptr.Raptr.848BBC53270CAC248E8FA0F339176201CDEB525F.1
    [2010/08/14 15:01:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Pam\Application Data\DNA
    [2009/12/10 18:38:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Pam\Application Data\E-centives
    [2010/05/13 22:45:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Pam\Application Data\eMusic
    [2009/01/07 17:55:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Pam\Application Data\FDRLab
    [2008/10/14 18:01:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Pam\Application Data\FirstClass
    [2009/01/07 18:14:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Pam\Application Data\FrostWire
    [2009/08/06 13:10:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Pam\Application Data\funkitron
    [2008/10/31 23:19:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Pam\Application Data\GetRightToGo
    [2010/03/15 21:34:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Pam\Application Data\IDM
    [2009/05/01 10:04:55 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Pam\Application Data\ijjigame
    [2010/04/07 08:49:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Pam\Application Data\imeshmediabartb
    [2008/11/21 07:08:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Pam\Application Data\Jeaks Music
    [2008/12/22 12:14:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Pam\Application Data\Leadertech
    [2010/05/10 21:14:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Pam\Application Data\MP3Rocket
    [2010/07/30 19:29:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Pam\Application Data\NBC Direct
    [2010/05/15 00:19:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Pam\Application Data\NCH Swift Sound
    [2009/04/18 23:39:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Pam\Application Data\NPLUTO Corporation
    [2008/12/07 23:50:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Pam\Application Data\OpenOffice.org
    [2010/08/14 18:24:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Pam\Application Data\PCenter
    [2009/07/24 07:30:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Pam\Application Data\Raptr
    [2010/07/22 00:00:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Pam\Application Data\Red Kawa
    [2009/12/30 16:42:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Pam\Application Data\Skinux
    [2009/05/07 20:08:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Pam\Application Data\yoclient
    [2008/11/11 06:29:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tim\Application Data\Acoustica
    [2009/07/10 21:14:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tim\Application Data\BitTorrent
    [2009/09/18 23:00:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tim\Application Data\NCH Swift Sound
    [2009/12/31 09:37:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tim\Application Data\Skinux
    [2010/02/13 19:42:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tim\Application Data\Uniblue
    [2010/08/11 15:28:00 | 000,000,432 | ---- | M] () -- C:\WINDOWS\Tasks\EasyShare Registration Task.job
    [2010/05/31 22:42:00 | 000,000,276 | ---- | M] () -- C:\WINDOWS\Tasks\videopadShakeIcon.job
    [2010/08/08 21:42:23 | 000,000,278 | ---- | M] () -- C:\WINDOWS\Tasks\wavepadDowngrade.job
    [2010/08/08 21:42:23 | 000,000,278 | ---- | M] () -- C:\WINDOWS\Tasks\wavepadShakeIcon.job

    ========== Purity Check ==========



    ========== Alternate Data Streams ==========

    @Alternate Data Stream - 76 bytes -> C:\Documents and Settings\Tim\My Documents\My Music:Roxio EMC Stream
    @Alternate Data Stream - 76 bytes -> C:\Documents and Settings\Pam\My Documents\My Downloads:Roxio EMC Stream
    @Alternate Data Stream - 76 bytes -> C:\Documents and Settings\Pam\My Documents\FirstClass:Roxio EMC Stream
    < End of report >
    Windows 7 Ultimate, Service Pack 1

    AMD FX-4170 Quad-Core Processor 4.2 Ghz

    8.0 GB RAM

    64-bit Operating System

  2. #32
    Join Date
    Dec 2007
    Location
    Daly City, CA
    Posts
    22,550
    Since you'll be using USB stick to move files between bad and good computer...
    On good computer...
    Download, and run Flash Disinfector, and save it to your desktop.

    *Please disable any AV / ScriptBlockers as they might detect Flash Disinfector to be malicious and block it. Hence, the failure in executing. You can enable them back after the cleaning process*

    • Double-click Flash_Disinfector.exe to run it and follow any prompts that may appear.
    • The utility may ask you to insert your flash drive and/or other removable drives. Please do so and allow the utility to clean up those drives as well.
    • Hold down the Shift key when inserting the drive until Windows detects it to keep autorun.inf from executing if it is present.
    • Wait until it has finished scanning and then exit the program.
    • Reboot your computer when done.

    Note: As part of its routine, Flash_Disinfector will create a hidden folder named autorun.inf in each partition and every USB drive that was plugged in when you ran it. Do not delete this folder...it will help protect your drives from future infection by keeping the autorun file from being installed on the root drive and running other malicious files.

    ================================================================

    Uuuuugh.....there was a lot of baddies.
    Hopefully, we got most of them.


    Do this on the computer you are posting from:
    Copy the text in the codebox below:


    Code:
    :OTL
    SRV - [2010/08/14 14:49:08 | 000,059,904 | ---- | M] () [Auto] -- C:\Program Files\csrss.exe -- (QTUpdate)
    DRV - File not found [Kernel | On_Demand] -- C:\DOCUME~1\Pam\LOCALS~1\Temp\mdxgthkn.sys -- (mdxgthkn)
    DRV - File not found [Kernel | On_Demand] -- C:\WINDOWS\System32\drivers\EagleNT.sys -- (EagleNT)
    IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
    IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:5577
    IE - HKU\Pam_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
    IE - HKU\Pam_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:5577
    IE - HKU\Pam_ON_C\..\URLSearchHook: {9927cacb-7863-42b4-95ab-7446332b7c59} - Reg Error: Key error. File not found
    IE - HKU\Pam_ON_C\..\URLSearchHook: {9ee802e8-c931-47ab-b570-aa8f791598ca} - Reg Error: Key error. File not found
    IE - HKU\Tim_ON_C\..\URLSearchHook: *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - Reg Error: Key error. File not found
    IE - HKU\Tim_ON_C\..\URLSearchHook: *{EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key error. File not found
    IE - HKU\Tim_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
    IE - HKU\Tim_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:5577
    O2 - BHO: (ADC PlugIn) - {19090308-636D-4e9b-A1CE-A647B6F794BF} - C:\Program Files\shk_v10.dll (Intsys)
    O2 - BHO: (BrowserHelper Class) - {8A9D74F9-560B-4FE7-ABEB-3B2E638E5CD6} - C:\Program Files\SGPSA\SearchAssistant.dll (Make The Web Better, LLC)
    O3 - HKU\Pam_ON_C\..\Toolbar\WebBrowser: (no name) - {0388BA0C-C7F1-4E6A-BD7A-B59623F33363} - No CLSID value found.
    O3 - HKU\Pam_ON_C\..\Toolbar\WebBrowser: (no name) - {1BB22D38-A411-4B13-A746-C2A4F4EC7344} - No CLSID value found.
    O3 - HKU\Pam_ON_C\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
    O3 - HKU\Pam_ON_C\..\Toolbar\WebBrowser: (no name) - {9927CACB-7863-42B4-95AB-7446332B7C59} - No CLSID value found.
    O3 - HKU\Pam_ON_C\..\Toolbar\WebBrowser: (no name) - {9EE802E8-C931-47AB-B570-AA8F791598CA} - No CLSID value found.
    O3 - HKU\Tim_ON_C\..\Toolbar\WebBrowser: (no name) - {0388BA0C-C7F1-4E6A-BD7A-B59623F33363} - No CLSID value found.
    O4 - HKU\Pam_ON_C..\Run: [ap.exe] C:\Documents and Settings\Pam\Application Data\PCenter\ap.exe ()
    O4 - HKU\Pam_ON_C..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe File not found
    O4 - HKU\Pam_ON_C..\Run: [DW6] C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe File not found
    O4 - HKU\Pam_ON_C..\Run: [MalwareBot] C:\Program Files\MalwareBot\MalwareBot.exe File not found
    O4 - HKU\Pam_ON_C..\Run: [MsnMsgr] C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe File not found
    O4 - HKU\Tim_ON_C..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe File not found 
    O4 - HKU\Pam_ON_C..\RunOnce: [Shockwave Updater] C:\WINDOWS\System32\Adobe\SHOCKW~1\SWHELP~3.EXE -Update -1103472 -Mozilla\4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident\4.0; File not found
    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
    O20 - AppInit_DLLs: (C:\PROGRA~1\IMESHA~1\MediaBar\DataMngr\datamngr.dll) - C:\PROGRA~1\IMESHA~1\MediaBar\DataMngr\datamngr.dll File not found
    O20 - HKU\Pam_ON_C Winlogon: Shell - (C:\Documents and Settings\Pam\Application Data\PCenter\sp.exe) - C:\Documents and Settings\Pam\Application Data\PCenter\sp.exe ()
    O35 - HKLM\..exefile [open] -- C:\Program Files\conhost.exe "&#37;1" %* ()
    O37 - HKLM\...exe [@ = exefile] -- C:\Program Files\conhost.exe "%1" %* ()
    [2010/08/14 18:24:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Pam\Application Data\PCenter
    [2010/08/14 14:49:10 | 000,372,224 | ---- | C] (Intsys) -- C:\Program Files\shk_v10.dll
    [2010/08/14 14:49:05 | 000,000,000 | ---D | C] -- C:\Program Files\Wireshark Antivirus
    [4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
    [3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
    [23 C:\Documents and Settings\Pam\My Documents\*.tmp files -> C:\Documents and Settings\Pam\My Documents\*.tmp -> ]
    [1 C:\*.tmp files -> C:\*.tmp -> ]
    [2010/08/15 21:12:46 | 000,000,060 | ---- | M] () -- C:\Program Files\sh4.dat
    [2010/08/15 21:12:46 | 000,000,004 | ---- | M] () -- C:\Program Files\sh3.dat
    [2010/08/15 19:24:00 | 000,098,304 | ---- | M] () -- C:\Program Files\conhost.exe
    [2010/08/15 19:23:59 | 000,372,224 | ---- | M] (Intsys) -- C:\Program Files\shk_v10.dll
    [2010/08/15 19:23:57 | 000,001,550 | ---- | M] () -- C:\Wireshark Antivirus.lnk
    [2010/08/14 14:49:09 | 000,000,009 | ---- | M] () -- C:\Program Files\nuar.old
    [2010/08/14 14:49:08 | 000,059,904 | ---- | M] () -- C:\Program Files\csrss.exe
    [2010/08/14 14:49:08 | 000,000,036 | ---- | M] () -- C:\Program Files\skynet.dat
    [2010/08/14 14:49:07 | 000,001,684 | ---- | M] () -- C:\Documents and Settings\Pam\Desktop\Wireshark Antivirus.lnk
    @Alternate Data Stream - 76 bytes -> C:\Documents and Settings\Tim\My Documents\My Music:Roxio EMC Stream
    @Alternate Data Stream - 76 bytes -> C:\Documents and Settings\Pam\My Documents\My Downloads:Roxio EMC Stream
    @Alternate Data Stream - 76 bytes -> C:\Documents and Settings\Pam\My Documents\FirstClass:Roxio EMC Stream
    
    :Services
    
    :Reg
    
    :Files
    
    :Commands
    [purity]
    [emptytemp]
    Open Notepad and paste it.
    Save the document as Fix.txt on to a USB flash drive


    On the infected computer the following...

    Run OTLPE

    • Insert USB stick and find the file Fix.txt. Drag the file Fix.txt and drop it under the Custom Scans/Fixes box at the bottom.

      • (The content of Fix.txt should appear in the box)

    • Then click the Run Fix button at the top
    • Let the program run unhindered, reboot the PC when it is done
    • Post the log produced (you'll need to transfer it with USB stick)
    • Attempt to reboot normally into windows.

  3. #33
    Join Date
    Nov 2000
    Location
    Hollansburg, OH, USA
    Posts
    272

    The computer seems to have booted normally.

    :OTL
    SRV - [2010/08/14 14:49:08 | 000,059,904 | ---- | M] () [Auto] -- C:\Program Files\csrss.exe -- (QTUpdate)
    DRV - File not found [Kernel | On_Demand] -- C:\DOCUME~1\Pam\LOCALS~1\Temp\mdxgthkn.sys -- (mdxgthkn)
    DRV - File not found [Kernel | On_Demand] -- C:\WINDOWS\System32\drivers\EagleNT.sys -- (EagleNT)
    IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
    IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:5577
    IE - HKU\Pam_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
    IE - HKU\Pam_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:5577
    IE - HKU\Pam_ON_C\..\URLSearchHook: {9927cacb-7863-42b4-95ab-7446332b7c59} - Reg Error: Key error. File not found
    IE - HKU\Pam_ON_C\..\URLSearchHook: {9ee802e8-c931-47ab-b570-aa8f791598ca} - Reg Error: Key error. File not found
    IE - HKU\Tim_ON_C\..\URLSearchHook: *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - Reg Error: Key error. File not found
    IE - HKU\Tim_ON_C\..\URLSearchHook: *{EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key error. File not found
    IE - HKU\Tim_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
    IE - HKU\Tim_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:5577
    O2 - BHO: (ADC PlugIn) - {19090308-636D-4e9b-A1CE-A647B6F794BF} - C:\Program Files\shk_v10.dll (Intsys)
    O2 - BHO: (BrowserHelper Class) - {8A9D74F9-560B-4FE7-ABEB-3B2E638E5CD6} - C:\Program Files\SGPSA\SearchAssistant.dll (Make The Web Better, LLC)
    O3 - HKU\Pam_ON_C\..\Toolbar\WebBrowser: (no name) - {0388BA0C-C7F1-4E6A-BD7A-B59623F33363} - No CLSID value found.
    O3 - HKU\Pam_ON_C\..\Toolbar\WebBrowser: (no name) - {1BB22D38-A411-4B13-A746-C2A4F4EC7344} - No CLSID value found.
    O3 - HKU\Pam_ON_C\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
    O3 - HKU\Pam_ON_C\..\Toolbar\WebBrowser: (no name) - {9927CACB-7863-42B4-95AB-7446332B7C59} - No CLSID value found.
    O3 - HKU\Pam_ON_C\..\Toolbar\WebBrowser: (no name) - {9EE802E8-C931-47AB-B570-AA8F791598CA} - No CLSID value found.
    O3 - HKU\Tim_ON_C\..\Toolbar\WebBrowser: (no name) - {0388BA0C-C7F1-4E6A-BD7A-B59623F33363} - No CLSID value found.
    O4 - HKU\Pam_ON_C..\Run: [ap.exe] C:\Documents and Settings\Pam\Application Data\PCenter\ap.exe ()
    O4 - HKU\Pam_ON_C..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe File not found
    O4 - HKU\Pam_ON_C..\Run: [DW6] C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe File not found
    O4 - HKU\Pam_ON_C..\Run: [MalwareBot] C:\Program Files\MalwareBot\MalwareBot.exe File not found
    O4 - HKU\Pam_ON_C..\Run: [MsnMsgr] C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe File not found
    O4 - HKU\Tim_ON_C..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe File not found
    O4 - HKU\Pam_ON_C..\RunOnce: [Shockwave Updater] C:\WINDOWS\System32\Adobe\SHOCKW~1\SWHELP~3.EXE -Update -1103472 -Mozilla\4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident\4.0; File not found
    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
    O20 - AppInit_DLLs: (C:\PROGRA~1\IMESHA~1\MediaBar\DataMngr\datamngr.dll) - C:\PROGRA~1\IMESHA~1\MediaBar\DataMngr\datamngr.dll File not found
    O20 - HKU\Pam_ON_C Winlogon: Shell - (C:\Documents and Settings\Pam\Application Data\PCenter\sp.exe) - C:\Documents and Settings\Pam\Application Data\PCenter\sp.exe ()
    O35 - HKLM\..exefile [open] -- C:\Program Files\conhost.exe "%1" %* ()
    O37 - HKLM\...exe [@ = exefile] -- C:\Program Files\conhost.exe "%1" %* ()
    [2010/08/14 18:24:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Pam\Application Data\PCenter
    [2010/08/14 14:49:10 | 000,372,224 | ---- | C] (Intsys) -- C:\Program Files\shk_v10.dll
    [2010/08/14 14:49:05 | 000,000,000 | ---D | C] -- C:\Program Files\Wireshark Antivirus
    [4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
    [3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
    [23 C:\Documents and Settings\Pam\My Documents\*.tmp files -> C:\Documents and Settings\Pam\My Documents\*.tmp -> ]
    [1 C:\*.tmp files -> C:\*.tmp -> ]
    [2010/08/15 21:12:46 | 000,000,060 | ---- | M] () -- C:\Program Files\sh4.dat
    [2010/08/15 21:12:46 | 000,000,004 | ---- | M] () -- C:\Program Files\sh3.dat
    [2010/08/15 19:24:00 | 000,098,304 | ---- | M] () -- C:\Program Files\conhost.exe
    [2010/08/15 19:23:59 | 000,372,224 | ---- | M] (Intsys) -- C:\Program Files\shk_v10.dll
    [2010/08/15 19:23:57 | 000,001,550 | ---- | M] () -- C:\Wireshark Antivirus.lnk
    [2010/08/14 14:49:09 | 000,000,009 | ---- | M] () -- C:\Program Files\nuar.old
    [2010/08/14 14:49:08 | 000,059,904 | ---- | M] () -- C:\Program Files\csrss.exe
    [2010/08/14 14:49:08 | 000,000,036 | ---- | M] () -- C:\Program Files\skynet.dat
    [2010/08/14 14:49:07 | 000,001,684 | ---- | M] () -- C:\Documents and Settings\Pam\Desktop\Wireshark Antivirus.lnk
    @Alternate Data Stream - 76 bytes -> C:\Documents and Settings\Tim\My Documents\My Music:Roxio EMC Stream
    @Alternate Data Stream - 76 bytes -> C:\Documents and Settings\Pam\My Documents\My Downloads:Roxio EMC Stream
    @Alternate Data Stream - 76 bytes -> C:\Documents and Settings\Pam\My Documents\FirstClass:Roxio EMC Stream

    :Services

    :Reg

    :Files

    :Commands
    [purity]
    [emptytemp]
    Windows 7 Ultimate, Service Pack 1

    AMD FX-4170 Quad-Core Processor 4.2 Ghz

    8.0 GB RAM

    64-bit Operating System

  4. #34
    Join Date
    Dec 2007
    Location
    Daly City, CA
    Posts
    22,550
    The above is my fix.
    That fix was supposed to produce a log, which you're suppose to post back here.
    Probably, I can live without it, as long as computer booted normally.

    Let's double check....

    On bad computer......

    Download OTL to your Desktop.

    * Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    * Under the Custom Scan box paste this in:



    netsvcs
    drivers32 /all
    &#37;SYSTEMDRIVE%\*.*
    %systemroot%\system32\Spool\prtprocs\w32x86\*.dll
    %systemroot%\system32\*.wt
    %systemroot%\system32\*.ruy
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\system32\spool\prtprocs\w32x86\*.tmp
    %systemroot%\*. /mp /s
    /md5start
    /md5stop
    CREATERESTOREPOINT
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\System32\config\*.sav
    %systemroot%\system32\user32.dll /md5
    %systemroot%\system32\ws2_32.dll /md5
    %systemroot%\system32\ws2help.dll /md5
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs



    * Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
    • When the scan completes, it will open two notepad windows: OTL.txt and Extras.txt. These are saved in the same location as OTL.
    • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post them back here.

  5. #35
    Join Date
    Nov 2000
    Location
    Hollansburg, OH, USA
    Posts
    272
    Sorry I accidentaly posted the wrong doc. Here is the correct one from the first fix. I am now preparing to run the second.


    Registry key HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\QTUpdate deleted successfully.
    C:\Program Files\csrss.exe moved successfully.
    Registry key HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\mdxgthkn deleted successfully.
    File C:\DOCUME~1\Pam\LOCALS~1\Temp\mdxgthkn.sys not found.
    Registry key HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\EagleNT deleted successfully.
    File C:\WINDOWS\System32\drivers\EagleNT.sys not found.
    HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyOverride| /E : value set successfully!
    HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer| /E : value set successfully!
    HKU\Pam_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyOverride| /E : value set successfully!
    HKU\Pam_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer| /E : value set successfully!
    Registry value HKEY_USERS\Pam_ON_C\Software\Microsoft\Internet Explorer\URLSearchHooks\\{9927cacb-7863-42b4-95ab-7446332b7c59} deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9927cacb-7863-42b4-95ab-7446332b7c59}\ not found.
    Registry value HKEY_USERS\Pam_ON_C\Software\Microsoft\Internet Explorer\URLSearchHooks\\{9ee802e8-c931-47ab-b570-aa8f791598ca} deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9ee802e8-c931-47ab-b570-aa8f791598ca}\ not found.
    Registry value HKEY_USERS\Tim_ON_C\Software\Microsoft\Internet Explorer\URLSearchHooks\\*{CFBFAE00-17A6-11D0-99CB-00C04FD64497} deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\*{CFBFAE00-17A6-11D0-99CB-00C04FD64497}\ not found.
    Registry value HKEY_USERS\Tim_ON_C\Software\Microsoft\Internet Explorer\URLSearchHooks\\*{EF99BD32-C1FB-11D2-892F-0090271D4F88} deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\*{EF99BD32-C1FB-11D2-892F-0090271D4F88}\ not found.
    HKU\Tim_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyOverride| /E : value set successfully!
    HKU\Tim_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer| /E : value set successfully!
    Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{19090308-636D-4e9b-A1CE-A647B6F794BF}\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{19090308-636D-4e9b-A1CE-A647B6F794BF}\ deleted successfully.
    C:\Program Files\shk_v10.dll moved successfully.
    Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8A9D74F9-560B-4FE7-ABEB-3B2E638E5CD6}\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8A9D74F9-560B-4FE7-ABEB-3B2E638E5CD6}\ deleted successfully.
    C:\Program Files\SGPSA\SearchAssistant.dll moved successfully.
    Registry value HKEY_USERS\Pam_ON_C\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{0388BA0C-C7F1-4E6A-BD7A-B59623F33363} deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0388BA0C-C7F1-4E6A-BD7A-B59623F33363}\ not found.
    Registry value HKEY_USERS\Pam_ON_C\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{1BB22D38-A411-4B13-A746-C2A4F4EC7344} deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1BB22D38-A411-4B13-A746-C2A4F4EC7344}\ not found.
    Registry value HKEY_USERS\Pam_ON_C\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F}\ not found.
    Registry value HKEY_USERS\Pam_ON_C\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{9927CACB-7863-42B4-95AB-7446332B7C59} deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9927CACB-7863-42B4-95AB-7446332B7C59}\ not found.
    Registry value HKEY_USERS\Pam_ON_C\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{9EE802E8-C931-47AB-B570-AA8F791598CA} deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9EE802E8-C931-47AB-B570-AA8F791598CA}\ not found.
    Registry value HKEY_USERS\Tim_ON_C\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{0388BA0C-C7F1-4E6A-BD7A-B59623F33363} deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0388BA0C-C7F1-4E6A-BD7A-B59623F33363}\ not found.
    Registry value HKEY_USERS\Pam_ON_C\Software\Microsoft\Windows\CurrentVersion\Run\\ap.exe deleted successfully.
    C:\Documents and Settings\Pam\Application Data\PCenter\ap.exe moved successfully.
    Registry value HKEY_USERS\Pam_ON_C\Software\Microsoft\Windows\CurrentVersion\Run\\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} deleted successfully.
    Registry value HKEY_USERS\Pam_ON_C\Software\Microsoft\Windows\CurrentVersion\Run\\DW6 deleted successfully.
    Registry value HKEY_USERS\Pam_ON_C\Software\Microsoft\Windows\CurrentVersion\Run\\MalwareBot deleted successfully.
    Registry value HKEY_USERS\Pam_ON_C\Software\Microsoft\Windows\CurrentVersion\Run\\MsnMsgr deleted successfully.
    Registry value HKEY_USERS\Tim_ON_C\Software\Microsoft\Windows\CurrentVersion\Run\\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} deleted successfully.
    Registry value HKEY_USERS\Pam_ON_C\Software\Microsoft\Windows\CurrentVersion\RunOnce\\Shockwave Updater deleted successfully.
    Starting removal of ActiveX control {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
    C:\WINDOWS\Downloaded Program Files\gp.inf not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
    Registry key HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Active Setup\Installed Components\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
    Registry key HKEY_USERS\Administrator_ON_C\SOFTWARE\Microsoft\Active Setup\Installed Components\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
    Registry key HKEY_USERS\LocalService_ON_C\SOFTWARE\Microsoft\Active Setup\Installed Components\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
    Registry key HKEY_USERS\NetworkService_ON_C\SOFTWARE\Microsoft\Active Setup\Installed Components\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
    Registry key HKEY_USERS\Pam_ON_C\SOFTWARE\Microsoft\Active Setup\Installed Components\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
    Registry key HKEY_USERS\systemprofile_ON_C\SOFTWARE\Microsoft\Active Setup\Installed Components\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
    Registry key HKEY_USERS\Tim_ON_C\SOFTWARE\Microsoft\Active Setup\Installed Components\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
    Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:C:\PROGRA~1\IMESHA~1\MediaBar\DataMngr\datamngr.dll deleted successfully.
    Registry value HKEY_USERS\Pam_ON_C\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell:C:\Documents and Settings\Pam\Application Data\PCenter\sp.exe deleted successfully.
    C:\Documents and Settings\Pam\Application Data\PCenter\sp.exe moved successfully.
    Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shell\open\command\\'' updated successfully.
    C:\Program Files\conhost.exe moved successfully.
    HKEY_LOCAL_MACHINE\Software\Classes\.exe\shell\open\command\\|"%1" %* /E : value set successfully!
    HKEY_LOCAL_MACHINE\Software\Classes\.exe\\|exefile /E : value set successfully!
    C:\Documents and Settings\Pam\Application Data\PCenter folder moved successfully.
    File C:\Program Files\shk_v10.dll not found.
    C:\Program Files\Wireshark Antivirus folder moved successfully.
    C:\WINDOWS\System32\CONFIG.TMP deleted successfully.
    C:\WINDOWS\System32\SET41.tmp deleted successfully.
    C:\WINDOWS\System32\SET46.tmp deleted successfully.
    C:\WINDOWS\System32\SET4D.tmp deleted successfully.
    C:\WINDOWS\002217_.tmp deleted successfully.
    C:\WINDOWS\SET3.tmp deleted successfully.
    C:\WINDOWS\SET7.tmp deleted successfully.
    C:\Documents and Settings\Pam\My Documents\~WRD3233.tmp deleted successfully.
    C:\Documents and Settings\Pam\My Documents\~WRL0001.tmp deleted successfully.
    C:\Documents and Settings\Pam\My Documents\~WRL0002.tmp deleted successfully.
    C:\Documents and Settings\Pam\My Documents\~WRL0004.tmp deleted successfully.
    C:\Documents and Settings\Pam\My Documents\~WRL0005.tmp deleted successfully.
    C:\Documents and Settings\Pam\My Documents\~WRL0258.tmp deleted successfully.
    C:\Documents and Settings\Pam\My Documents\~WRL0425.tmp deleted successfully.
    C:\Documents and Settings\Pam\My Documents\~WRL0600.tmp deleted successfully.
    C:\Documents and Settings\Pam\My Documents\~WRL0884.tmp deleted successfully.
    C:\Documents and Settings\Pam\My Documents\~WRL0935.tmp deleted successfully.
    C:\Documents and Settings\Pam\My Documents\~WRL1335.tmp deleted successfully.
    C:\Documents and Settings\Pam\My Documents\~WRL1424.tmp deleted successfully.
    C:\Documents and Settings\Pam\My Documents\~WRL1964.tmp deleted successfully.
    C:\Documents and Settings\Pam\My Documents\~WRL2019.tmp deleted successfully.
    C:\Documents and Settings\Pam\My Documents\~WRL2231.tmp deleted successfully.
    C:\Documents and Settings\Pam\My Documents\~WRL2300.tmp deleted successfully.
    C:\Documents and Settings\Pam\My Documents\~WRL2552.tmp deleted successfully.
    C:\Documents and Settings\Pam\My Documents\~WRL3574.tmp deleted successfully.
    C:\Documents and Settings\Pam\My Documents\~WRL3624.tmp deleted successfully.
    C:\Documents and Settings\Pam\My Documents\~WRL3722.tmp deleted successfully.
    C:\Documents and Settings\Pam\My Documents\~WRL3916.tmp deleted successfully.
    C:\Documents and Settings\Pam\My Documents\~WRL3935.tmp deleted successfully.
    C:\Documents and Settings\Pam\My Documents\~WRL3951.tmp deleted successfully.
    C:\LOGA.tmp deleted successfully.
    C:\Program Files\sh4.dat moved successfully.
    C:\Program Files\sh3.dat moved successfully.
    File C:\Program Files\conhost.exe not found.
    File C:\Program Files\shk_v10.dll not found.
    C:\Wireshark Antivirus.lnk moved successfully.
    C:\Program Files\nuar.old moved successfully.
    File C:\Program Files\csrss.exe not found.
    C:\Program Files\skynet.dat moved successfully.
    C:\Documents and Settings\Pam\Desktop\Wireshark Antivirus.lnk moved successfully.
    Unable to delete ADS C:\Documents and Settings\Tim\My Documents\My Music:Roxio EMC Stream .
    ADS C:\Documents and Settings\Pam\My Documents\My Downloads:Roxio EMC Stream deleted successfully.
    ADS C:\Documents and Settings\Pam\My Documents\FirstClass:Roxio EMC Stream deleted successfully.
    ========== SERVICES/DRIVERS ==========
    ========== REGISTRY ==========
    ========== FILES ==========
    ========== COMMANDS ==========

    [EMPTYTEMP]

    User: Administrator
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 184978 bytes
    ->FireFox cache emptied: 3373644 bytes

    User: All Users

    User: Default User
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 33170 bytes
    ->Flash cache emptied: 56504 bytes

    User: LocalService
    ->Temp folder emptied: 66016 bytes
    ->Temporary Internet Files folder emptied: 88061 bytes

    User: NetworkService
    ->Temp folder emptied: 776917 bytes
    ->Temporary Internet Files folder emptied: 1442194 bytes
    ->Flash cache emptied: 31360 bytes

    User: Pam
    ->Temp folder emptied: 5285696 bytes
    ->Temporary Internet Files folder emptied: 26284685 bytes
    ->Java cache emptied: 17286 bytes
    ->FireFox cache emptied: 39141761 bytes
    ->Google Chrome cache emptied: 0 bytes
    ->Flash cache emptied: 59855 bytes

    User: Tim
    ->Temp folder emptied: 607240 bytes
    ->Temporary Internet Files folder emptied: 228392 bytes
    ->Java cache emptied: 0 bytes
    ->FireFox cache emptied: 40554844 bytes
    ->Google Chrome cache emptied: 819568 bytes
    ->Flash cache emptied: 3251 bytes

    %systemdrive% .tmp files removed: 0 bytes
    %systemroot% .tmp files removed: 0 bytes
    %systemroot%\System32 .tmp files removed: 0 bytes
    %systemroot%\System32\dllcache .tmp files removed: 0 bytes
    %systemroot%\System32\drivers .tmp files removed: 0 bytes
    Windows Temp folder emptied: 7062149 bytes
    %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 51705398 bytes
    %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes

    Total Files Cleaned = 170.00 mb


    OTLPE by OldTimer - Version 3.1.40.0 log created on 08162010_001925
    Windows 7 Ultimate, Service Pack 1

    AMD FX-4170 Quad-Core Processor 4.2 Ghz

    8.0 GB RAM

    64-bit Operating System

  6. #36
    Join Date
    Dec 2007
    Location
    Daly City, CA
    Posts
    22,550
    Very good

    Hold on with new OTL for now.

    STEP 1. Download Malwarebytes' Anti-Malware (aka MBAM): http://www.malwarebytes.org/mbam.php to your desktop.
    (Malwarebytes is free to use as a manual scanner. Payment is only required if you wish to have it run and update automatically which is not necessary for our purposes)

    * Double-click mbam-setup.exe and follow the prompts to install the program.
    * At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
    * If an update is found, it will download and install the latest version.
    * Once the program has loaded, select Perform Quick Scan, then click Scan.
    * When the scan is complete, click OK, then Show Results to view the results.
    * Be sure that everything is checked, and click Remove Selected.
    * When completed, a log will open in Notepad.
    * Post the log back here.

    The log can also be found here:
    C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
    Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt


    STEP 2. Download GMER: http://www.gmer.net/files.php, by clicking on Download EXE button.
    Alternative downloads:
    - http://majorgeeks.com/GMER_d5198.html
    - http://www.softpedia.com/get/Interne...ers/GMER.shtml
    Double click on downloaded .exe file, select Rootkit tab and click the Scan button.
    Do NOT use the computer while GMER is running!
    When scan is completed, click Save button, and save the results as gmer.log
    Warning ! Please, do not select the "Show all" checkbox during the scan.
    Post the log to your next reply.

    IMPORTANT! If for some reason GMER refuses to run, try again.
    If it still fails, try to UN-check "Devices" in right pane.
    If still no joy, try to run it from Safe Mode.


    STEP 3. Download MBRCheck to your desktop

    Double click MBRCheck.exe to run (Vista and Windows 7 users, right click and select Run as Administrator).
    It will show a black screen with some data on it.
    A report called MBRcheckxxxx.txt will be on your desktop
    Open this report and post its content in your next reply.



    DO NOT make any other changes to your computer (like installing programs, using other cleaning tools, etc.), until it's officially declared clean!!!

  7. #37
    Join Date
    Nov 2000
    Location
    Hollansburg, OH, USA
    Posts
    272
    Attached are the two results from the second OTL scan. I ran it before you posted back. Should I proceed with the Malware post when I continue. I will have to continue tomorrow though because I have to turn in because i have to get up early for golf practice. My dad should or I will continue with you tomorrow most likely.
    Attached Files Attached Files
    Windows 7 Ultimate, Service Pack 1

    AMD FX-4170 Quad-Core Processor 4.2 Ghz

    8.0 GB RAM

    64-bit Operating System

  8. #38
    Join Date
    Dec 2007
    Location
    Daly City, CA
    Posts
    22,550
    Yes, proceed with steps from my previous reply.
    This computer shouldn't be used for now though.

  9. #39
    Join Date
    Nov 2000
    Location
    Hollansburg, OH, USA
    Posts
    272

    Tim is in the house!
    GMER scans but terminates after scan is complete before I can save anything! I've tried it twice with the same results. I am using the "bad" computer to connect with you so I can download fron your links. Is that OK? I know Samuel ran the MBAM and saved the log on a flash drive. I ran the MBRCheck program. The results are in a DOS window. I don't remember how to get it in a form I can send to you. Not sure what to do next.
    Last edited by timmyb74; August 16th, 2010 at 10:07 PM. Reason: aditional information added
    Windows 7 Ultimate, Service Pack 1

    AMD FX-4170 Quad-Core Processor 4.2 Ghz

    8.0 GB RAM

    64-bit Operating System

  10. #40
    Join Date
    Dec 2007
    Location
    Daly City, CA
    Posts
    22,550
    Yes, you should run all scans on bad computer.

    IMPORTANT! If for some reason GMER refuses to run, try again.
    If it still fails, try to UN-check "Devices" in right pane.
    If still no joy, try to run it from Safe Mode.
    If still problem, skip it.

    You can simply re-run MBAM and MBRCheck. They won't take long.

  11. #41
    Join Date
    Nov 2000
    Location
    Hollansburg, OH, USA
    Posts
    272
    GMER does run and there is a lot of stuff on the screen. I just can't save it for some reason. This scan takes quite a long time will I beable to save the results if I run it in safe mode?

    What info are you looking for from the MBRCheck. I can type in the info you need manually?
    Windows 7 Ultimate, Service Pack 1

    AMD FX-4170 Quad-Core Processor 4.2 Ghz

    8.0 GB RAM

    64-bit Operating System

  12. #42
    Join Date
    Dec 2007
    Location
    Daly City, CA
    Posts
    22,550
    Skip GMER for now.

    As for MBRCheck, follow instructions from my reply #36 and it'll create a log for you.

  13. #43
    Join Date
    Nov 2000
    Location
    Hollansburg, OH, USA
    Posts
    272
    You can tell it's me and not Samuel can't you?

    MBRCheck, version 1.2.3
    (c) 2010, AD

    Command-line:
    Windows Version: Windows XP Professional
    Windows Information: Service Pack 2 (build 2600)
    Logical Drives Mask: 0x0000000d

    Kernel Drivers (total 132):
    0x804D7000 \WINDOWS\system32\ntkrnlpa.exe
    0x806E2000 \WINDOWS\system32\hal.dll
    0xBA5A8000 \WINDOWS\system32\KDCOM.DLL
    0xBA4B8000 \WINDOWS\system32\BOOTVID.dll
    0xB9F79000 ACPI.sys
    0xBA5AA000 \WINDOWS\System32\DRIVERS\WMILIB.SYS
    0xB9F68000 pci.sys
    0xBA0A8000 isapnp.sys
    0xBA670000 pciide.sys
    0xBA328000 \WINDOWS\System32\DRIVERS\PCIIDEX.SYS
    0xBA0B8000 MountMgr.sys
    0xB9F49000 ftdisk.sys
    0xBA5AC000 dmload.sys
    0xB9F23000 dmio.sys
    0xBA330000 PartMgr.sys
    0xBA671000 amdide.sys
    0xBA0C8000 VolSnap.sys
    0xB9F0B000 atapi.sys
    0xBA0D8000 disk.sys
    0xBA0E8000 \WINDOWS\System32\DRIVERS\CLASSPNP.SYS
    0xB9EEB000 fltmgr.sys
    0xB9ED9000 sr.sys
    0xBA0F8000 PxHelp20.sys
    0xB9EC2000 KSecDD.sys
    0xB9EAB000 WudfPf.sys
    0xB9E1E000 Ntfs.sys
    0xB9DF1000 NDIS.sys
    0xB9DD6000 Mup.sys
    0xB77C8000 \SystemRoot\System32\DRIVERS\processr.sys
    0xB7315000 \SystemRoot\system32\DRIVERS\ati2mtag.sys
    0xB7301000 \SystemRoot\system32\DRIVERS\VIDEOPRT.SYS
    0xB72DC000 \SystemRoot\system32\DRIVERS\HDAudBus.sys
    0xB72C2000 \SystemRoot\system32\DRIVERS\Rtenicxp.sys
    0xB77B8000 \SystemRoot\System32\DRIVERS\imapi.sys
    0xB77A8000 \SystemRoot\System32\Drivers\AFS2K.SYS
    0xB7798000 \SystemRoot\System32\DRIVERS\cdrom.sys
    0xB7788000 \SystemRoot\System32\DRIVERS\redbook.sys
    0xB729F000 \SystemRoot\System32\DRIVERS\ks.sys
    0xBA450000 \SystemRoot\system32\DRIVERS\GEARAspiWDM.sys
    0xBA458000 \SystemRoot\System32\DRIVERS\usbohci.sys
    0xB727C000 \SystemRoot\System32\DRIVERS\USBPORT.SYS
    0xBA460000 \SystemRoot\System32\DRIVERS\usbehci.sys
    0xB7778000 \SystemRoot\System32\DRIVERS\serial.sys
    0xBA5A0000 \SystemRoot\System32\DRIVERS\serenum.sys
    0xBA468000 \SystemRoot\System32\DRIVERS\fdc.sys
    0xB7768000 \SystemRoot\System32\DRIVERS\i8042prt.sys
    0xBA470000 \SystemRoot\System32\DRIVERS\kbdclass.sys
    0xBA740000 \SystemRoot\System32\DRIVERS\audstub.sys
    0xBA238000 \SystemRoot\System32\DRIVERS\rasl2tp.sys
    0xB7DB2000 \SystemRoot\System32\DRIVERS\ndistapi.sys
    0xB7265000 \SystemRoot\System32\DRIVERS\ndiswan.sys
    0xBA248000 \SystemRoot\System32\DRIVERS\raspppoe.sys
    0xBA258000 \SystemRoot\System32\DRIVERS\raspptp.sys
    0xBA478000 \SystemRoot\System32\DRIVERS\TDI.SYS
    0xB7254000 \SystemRoot\System32\DRIVERS\psched.sys
    0xBA268000 \SystemRoot\System32\DRIVERS\msgpc.sys
    0xBA480000 \SystemRoot\System32\DRIVERS\ptilink.sys
    0xBA488000 \SystemRoot\System32\DRIVERS\raspti.sys
    0xBA5DC000 \SystemRoot\System32\Drivers\RootMdm.sys
    0xBA490000 \SystemRoot\System32\Drivers\Modem.SYS
    0xB7223000 \SystemRoot\System32\DRIVERS\rdpdr.sys
    0xBA278000 \SystemRoot\System32\DRIVERS\termdd.sys
    0xBA498000 \SystemRoot\System32\DRIVERS\mouclass.sys
    0xBA5DE000 \SystemRoot\System32\DRIVERS\swenum.sys
    0xB71C7000 \SystemRoot\System32\DRIVERS\update.sys
    0xB7D9A000 \SystemRoot\System32\DRIVERS\mssmbios.sys
    0xBA288000 \SystemRoot\System32\DRIVERS\usbhub.sys
    0xBA5E0000 \SystemRoot\System32\DRIVERS\USBD.SYS
    0xBA298000 \SystemRoot\System32\Drivers\NDProxy.SYS
    0xA708D000 \SystemRoot\system32\drivers\AtiHdmi.sys
    0xA706B000 \SystemRoot\system32\drivers\portcls.sys
    0xBA2C8000 \SystemRoot\system32\drivers\drmk.sys
    0xBA2D8000 \SystemRoot\system32\DRIVERS\stdriver32.sys
    0xA5E2F000 \SystemRoot\system32\drivers\sthda.sys
    0xBA4A0000 \SystemRoot\System32\DRIVERS\flpydisk.sys
    0xBA5EA000 \SystemRoot\System32\Drivers\Fs_Rec.SYS
    0xBA69B000 \SystemRoot\System32\Drivers\Null.SYS
    0xBA5EC000 \SystemRoot\System32\Drivers\Beep.SYS
    0xBA4B0000 \SystemRoot\System32\drivers\vga.sys
    0xBA5EE000 \SystemRoot\System32\Drivers\mnmdd.SYS
    0xBA5F0000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
    0xBA340000 \SystemRoot\System32\Drivers\Msfs.SYS
    0xBA370000 \SystemRoot\System32\Drivers\Npfs.SYS
    0xBA570000 \SystemRoot\System32\DRIVERS\rasacd.sys
    0xA5DFC000 \SystemRoot\System32\DRIVERS\ipsec.sys
    0xA5DA3000 \SystemRoot\System32\DRIVERS\tcpip.sys
    0xA5D41000 \SystemRoot\System32\Drivers\avgtdix.sys
    0xBA2F8000 \SystemRoot\System32\DRIVERS\wanarp.sys
    0xA5D20000 \SystemRoot\System32\DRIVERS\ipnat.sys
    0xBA584000 \SystemRoot\System32\DRIVERS\hidusb.sys
    0xBA308000 \SystemRoot\System32\DRIVERS\HIDCLASS.SYS
    0xBA378000 \SystemRoot\System32\DRIVERS\HIDPARSE.SYS
    0xBA380000 \SystemRoot\system32\DRIVERS\usbccgp.sys
    0xBA590000 \SystemRoot\System32\DRIVERS\mouhid.sys
    0xBA594000 \SystemRoot\system32\DRIVERS\usbscan.sys
    0xBA388000 \SystemRoot\system32\DRIVERS\usbprint.sys
    0xBA390000 \SystemRoot\system32\DRIVERS\HPZius12.sys
    0xBA318000 \SystemRoot\system32\DRIVERS\HPZid412.sys
    0xBA598000 \SystemRoot\system32\DRIVERS\HPZipr12.sys
    0xA5C58000 \SystemRoot\System32\DRIVERS\netbt.sys
    0xA5C36000 \SystemRoot\System32\drivers\afd.sys
    0xBA138000 \SystemRoot\System32\DRIVERS\netbios.sys
    0xA5C14000 \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys
    0xBA3E0000 \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS
    0xA5BE9000 \SystemRoot\System32\DRIVERS\rdbss.sys
    0xA5B7A000 \SystemRoot\System32\DRIVERS\mrxsmb.sys
    0xBA158000 \SystemRoot\System32\Drivers\Fips.SYS
    0xBA3F0000 \SystemRoot\System32\Drivers\avgmfx86.sys
    0xA5B46000 \SystemRoot\System32\Drivers\avgldx86.sys
    0xB7748000 \SystemRoot\System32\Drivers\Cdfs.SYS
    0xBF800000 \SystemRoot\System32\win32k.sys
    0xB720F000 \SystemRoot\System32\drivers\Dxapi.sys
    0xBA408000 \SystemRoot\System32\watchdog.sys
    0xBF000000 \SystemRoot\System32\drivers\dxg.sys
    0xBA772000 \SystemRoot\System32\drivers\dxgthk.sys
    0xBF012000 \SystemRoot\System32\ati2dvag.dll
    0xBF05F000 \SystemRoot\System32\ati2cqag.dll
    0xBF0DE000 \SystemRoot\System32\atikvmag.dll
    0xBF14E000 \SystemRoot\System32\atiok3x2.dll
    0xBF17C000 \SystemRoot\System32\ati3duag.dll
    0xBF484000 \SystemRoot\System32\ativvaxx.dll
    0xBFFA0000 \SystemRoot\System32\ATMFD.DLL
    0xA3114000 \SystemRoot\System32\DRIVERS\ndisuio.sys
    0x9EB4B000 \SystemRoot\System32\DRIVERS\mrxdav.sys
    0x9EA92000 \SystemRoot\System32\Drivers\HTTP.sys
    0x9E9C3000 \SystemRoot\System32\DRIVERS\srv.sys
    0x9E978000 \SystemRoot\System32\Drivers\Fastfat.SYS
    0x9E873000 \SystemRoot\system32\drivers\wdmaud.sys
    0xBA1F8000 \SystemRoot\system32\drivers\sysaudio.sys
    0x9E571000 \SystemRoot\System32\DRIVERS\asyncmac.sys
    0x9D590000 \SystemRoot\system32\drivers\kmixer.sys
    0x7C900000 \WINDOWS\system32\ntdll.dll

    Processes (total 57):
    0 System Idle Process
    4 System
    416 C:\WINDOWS\system32\smss.exe
    464 csrss.exe
    496 C:\WINDOWS\system32\winlogon.exe
    544 C:\WINDOWS\system32\services.exe
    556 C:\WINDOWS\system32\lsass.exe
    712 C:\WINDOWS\system32\ati2evxx.exe
    744 C:\WINDOWS\system32\svchost.exe
    812 svchost.exe
    884 C:\WINDOWS\system32\svchost.exe
    928 C:\WINDOWS\system32\svchost.exe
    1060 svchost.exe
    1108 C:\WINDOWS\system32\ati2evxx.exe
    1116 C:\Program Files\AVG\AVG9\avgchsvx.exe
    1124 C:\Program Files\AVG\AVG9\avgrsx.exe
    1260 C:\Program Files\AVG\AVG9\avgcsrvx.exe
    1268 svchost.exe
    1584 C:\WINDOWS\system32\spoolsv.exe
    1808 svchost.exe
    1840 C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
    1856 C:\Program Files\Amazon\Amazon Unbox Video\ADVWindowsClientService.exe
    1932 C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    1988 C:\Program Files\AVG\AVG9\avgwdsvc.exe
    2020 C:\Program Files\Bonjour\mDNSResponder.exe
    460 C:\WINDOWS\system32\svchost.exe
    852 C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    668 C:\Program Files\AVG\AVG9\avgnsx.exe
    2144 C:\Program Files\IDT\ECSXPV_5762_010208\WDM\stacsv.exe
    2356 C:\WINDOWS\system32\svchost.exe
    2404 C:\WINDOWS\system32\UAService7.exe
    2456 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
    2520 wmpnetwk.exe
    2916 alg.exe
    3276 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
    2004 C:\WINDOWS\system32\wscntfy.exe
    3996 C:\WINDOWS\explorer.exe
    2912 C:\Program Files\IDT\WDM\sttray.exe
    732 C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\HpqCmon.exe
    3196 C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
    3316 C:\PROGRA~1\AVG\AVG9\avgtray.exe
    3376 C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
    3368 C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
    3388 C:\Program Files\DivX\DivX Update\DivXUpdate.exe
    2924 C:\Program Files\iTunes\iTunesHelper.exe
    2840 C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
    3472 C:\Program Files\DNA\btdna.exe
    3104 C:\Program Files\NBC Direct\DirectPlayerCore.exe
    3440 C:\WINDOWS\system32\wuauclt.exe
    3448 C:\Program Files\Windows Media Player\wmpnscfg.exe
    3404 C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
    4056 C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
    948 C:\Program Files\iPod\bin\iPodService.exe
    2992 C:\Program Files\Internet Explorer\iexplore.exe
    3096 C:\Program Files\Internet Explorer\iexplore.exe
    5892 C:\Program Files\Internet Explorer\iexplore.exe
    2684 C:\Documents and Settings\Pam\Desktop\MBRCheck.exe

    \\.\C: --> \\.\PhysicalDrive0 at offset 0x00000000`00007e00 (NTFS)

    PhysicalDrive0 Model Number: ST3320620A, Rev: 3.AAE

    Size Device Name MBR Status
    --------------------------------------------Malwarebytes' Anti-Malware 1.46
    www.malwarebytes.org

    Database version: 4437

    Windows 5.1.2600 Service Pack 2
    Internet Explorer 8.0.6001.18372

    8/16/2010 4:55:04 PM
    mbam-log-2010-08-16 (16-55-04).txt

    Scan type: Quick scan
    Objects scanned: 152612
    Time elapsed: 6 minute(s), 38 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 3
    Registry Values Infected: 0
    Registry Data Items Infected: 1
    Folders Infected: 4
    Files Infected: 30

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{19090308-636d-4e9b-a1ce-a647b6f794bf} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{19090308-636d-4e9b-a1ce-a647b6f794bf} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\Software\Wireshark Antivirus (Rogue.WiresharkAntivirus) -> Quarantined and deleted successfully.

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell (Hijack.Shell) -> Bad: (C:\Documents and Settings\Pam\Application Data\PCenter\sp.exe) Good: (Explorer.exe) -> Quarantined and deleted successfully.

    Folders Infected:
    C:\Program Files\scdata (Trojan.Dropper) -> Quarantined and deleted successfully.
    C:\Program Files\scdata\images (Trojan.Dropper) -> Quarantined and deleted successfully.
    C:\Documents and Settings\LocalService\Start Menu\Programs\Wireshark Antivirus (Rogue.WiresharkAntivirus) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Pam\Start Menu\Programs\Wireshark Antivirus (Rogue.WiresharkAntivirus) -> Quarantined and deleted successfully.

    Files Infected:
    C:\Program Files\scdata\wispex.html (Trojan.Dropper) -> Quarantined and deleted successfully.
    C:\Program Files\scdata\wskinn.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
    C:\Program Files\scdata\images\i1.gif (Trojan.Dropper) -> Quarantined and deleted successfully.
    C:\Program Files\scdata\images\i2.gif (Trojan.Dropper) -> Quarantined and deleted successfully.
    C:\Program Files\scdata\images\i3.gif (Trojan.Dropper) -> Quarantined and deleted successfully.
    C:\Program Files\scdata\images\j1.gif (Trojan.Dropper) -> Quarantined and deleted successfully.
    C:\Program Files\scdata\images\j2.gif (Trojan.Dropper) -> Quarantined and deleted successfully.
    C:\Program Files\scdata\images\j3.gif (Trojan.Dropper) -> Quarantined and deleted successfully.
    C:\Program Files\scdata\images\jj1.gif (Trojan.Dropper) -> Quarantined and deleted successfully.
    C:\Program Files\scdata\images\jj2.gif (Trojan.Dropper) -> Quarantined and deleted successfully.
    C:\Program Files\scdata\images\jj3.gif (Trojan.Dropper) -> Quarantined and deleted successfully.
    C:\Program Files\scdata\images\l1.gif (Trojan.Dropper) -> Quarantined and deleted successfully.
    C:\Program Files\scdata\images\l2.gif (Trojan.Dropper) -> Quarantined and deleted successfully.
    C:\Program Files\scdata\images\l3.gif (Trojan.Dropper) -> Quarantined and deleted successfully.
    C:\Program Files\scdata\images\pix.gif (Trojan.Dropper) -> Quarantined and deleted successfully.
    C:\Program Files\scdata\images\t1.gif (Trojan.Dropper) -> Quarantined and deleted successfully.
    C:\Program Files\scdata\images\t2.gif (Trojan.Dropper) -> Quarantined and deleted successfully.
    C:\Program Files\scdata\images\Thumbs.db (Trojan.Dropper) -> Quarantined and deleted successfully.
    C:\Program Files\scdata\images\up1.gif (Trojan.Dropper) -> Quarantined and deleted successfully.
    C:\Program Files\scdata\images\up2.gif (Trojan.Dropper) -> Quarantined and deleted successfully.
    C:\Program Files\scdata\images\w1.gif (Trojan.Dropper) -> Quarantined and deleted successfully.
    C:\Program Files\scdata\images\w11.gif (Trojan.Dropper) -> Quarantined and deleted successfully.
    C:\Program Files\scdata\images\w2.gif (Trojan.Dropper) -> Quarantined and deleted successfully.
    C:\Program Files\scdata\images\w3.jpg (Trojan.Dropper) -> Quarantined and deleted successfully.
    C:\Program Files\scdata\images\word.doc (Trojan.Dropper) -> Quarantined and deleted successfully.
    C:\Program Files\scdata\images\wt1.gif (Trojan.Dropper) -> Quarantined and deleted successfully.
    C:\Program Files\scdata\images\wt2.gif (Trojan.Dropper) -> Quarantined and deleted successfully.
    C:\Program Files\scdata\images\wt3.gif (Trojan.Dropper) -> Quarantined and deleted successfully.
    C:\Documents and Settings\LocalService\Start Menu\Programs\Wireshark Antivirus\Wireshark Antivirus.lnk (Rogue.WiresharkAntivirus) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Pam\Start Menu\Programs\Wireshark Antivirus\Wireshark Antivirus.lnk (Rogue.WiresharkAntivirus) -> Quarantined and deleted successfully.

    298 GB \\.\PhysicalDrive0 Windows XP MBR code detected
    SHA1: DA38B874B7713D1B51CBC449F4EF809B0DEC644A
    Last edited by timmyb74; August 16th, 2010 at 10:25 PM. Reason: Added information
    Windows 7 Ultimate, Service Pack 1

    AMD FX-4170 Quad-Core Processor 4.2 Ghz

    8.0 GB RAM

    64-bit Operating System

  14. #44
    Join Date
    Dec 2007
    Location
    Daly City, CA
    Posts
    22,550
    Looks good

    MBAM please....

  15. #45
    Join Date
    Nov 2000
    Location
    Hollansburg, OH, USA
    Posts
    272
    I added it to my previous post
    Windows 7 Ultimate, Service Pack 1

    AMD FX-4170 Quad-Core Processor 4.2 Ghz

    8.0 GB RAM

    64-bit Operating System

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •