August 15th, 2010, 10:33 PM
#31
Its to big for one post.
Settings\Pam\My Documents\campedit3newarrow[1].jpg
[2010/07/18 13:58:12 | 000,024,576 | ---- | C] () -- C:\Documents and Settings\Tim\My Documents\Dependable Astro AWD won.doc
[2010/07/17 15:50:59 | 000,020,610 | ---- | C] () -- C:\Documents and Settings\Pam\My Documents\GS Clip art.docm
[2010/07/17 15:44:54 | 000,000,553 | ---- | C] () -- C:\Documents and Settings\Pam\Desktop\Shortcut to GS Clip art.lnk
[2010/07/17 15:42:28 | 000,030,208 | ---- | C] () -- C:\Documents and Settings\Pam\My Documents\GS Clip art.doc
[2010/07/17 15:34:24 | 000,000,796 | ---- | C] () -- C:\Documents and Settings\Pam\Desktop\Shortcut to girl scout leader tent camping.lnk
[2010/07/17 15:34:13 | 000,000,696 | ---- | C] () -- C:\Documents and Settings\Pam\Desktop\Shortcut to GS promise.lnk
[2010/07/17 15:33:58 | 000,000,686 | ---- | C] () -- C:\Documents and Settings\Pam\Desktop\Shortcut to GS troop.lnk
[2010/07/06 07:19:37 | 000,008,192 | -H-- | C] () -- C:\WINDOWS\system32\config\systemprofile\ntuser.dat.LOG
[2010/06/25 08:13:09 | 003,932,160 | ---- | C] () -- C:\Documents and Settings\Tim\ntuser.dat
[2010/04/30 03:00:12 | 011,272,192 | ---- | C] () -- C:\Documents and Settings\Pam\ntuser.dat
[2010/04/30 03:00:12 | 000,327,680 | ---- | C] () -- C:\WINDOWS\system32\config\systemprofile\ntuser.dat
[2010/03/30 15:03:37 | 000,000,181 | ---- | C] () -- C:\Documents and Settings\Pam\Application Data\default.pls
[2010/03/01 06:46:23 | 000,000,170 | ---- | C] () -- C:\Documents and Settings\Tim\Application Data\default.pls
[2010/02/24 21:03:31 | 000,001,024 | ---- | C] () -- C:\Documents and Settings\Pam\.rnd
[2010/01/07 13:05:40 | 000,000,100 | ---- | C] () -- C:\WINDOWS\ka.ini
[2009/12/31 20:32:12 | 000,023,040 | ---- | C] () -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/12/27 21:02:51 | 000,087,552 | ---- | C] () -- C:\WINDOWS\System32\cpwmon2k.dll
[2009/11/09 12:32:04 | 000,000,330 | ---- | C] () -- C:\WINDOWS\RBuilder.ini
[2009/10/18 17:08:52 | 000,000,034 | ---- | C] () -- C:\WINDOWS\Sierra.ini
[2009/09/30 19:10:39 | 000,147,456 | ---- | C] () -- C:\WINDOWS\System32\lttls13n.dll
[2009/09/30 19:10:34 | 000,708,608 | ---- | C] () -- C:\WINDOWS\System32\ltcry13n.dll
[2009/09/30 19:10:29 | 000,118,784 | ---- | C] () -- C:\WINDOWS\System32\lfkodak.dll
[2009/09/30 19:10:28 | 000,338,944 | ---- | C] () -- C:\WINDOWS\System32\lffpx7.dll
[2009/08/28 10:58:31 | 000,177,664 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2009/08/03 15:07:42 | 000,403,816 | ---- | C] () -- C:\WINDOWS\System32\OGACheckControl.dll
[2009/07/24 23:15:31 | 000,004,096 | ---- | C] () -- C:\WINDOWS\System32\drivers\nocashio.sys
[2009/06/03 21:22:47 | 000,007,207 | R--- | C] () -- C:\WINDOWS\Disktool.INI
[2009/06/03 21:22:47 | 000,006,399 | R--- | C] () -- C:\WINDOWS\fwupgrade.ini
[2009/06/03 21:22:47 | 000,003,677 | R--- | C] () -- C:\WINDOWS\PlaySnd.INI
[2009/05/25 21:16:27 | 001,970,176 | ---- | C] () -- C:\WINDOWS\System32\d3dx9.dll
[2009/05/22 20:23:23 | 000,000,034 | ---- | C] () -- C:\Documents and Settings\Pam\jagex_runescape_preferences.dat
[2009/05/01 10:14:36 | 000,000,031 | ---- | C] () -- C:\WINDOWS\GunzLauncher.INI
[2009/04/02 05:34:28 | 000,000,038 | ---- | C] () -- C:\WINDOWS\AviSplitter.INI
[2009/03/12 05:38:23 | 002,788,800 | ---- | C] () -- C:\Program Files\FLV PlayerFCSetup.exe
[2009/03/12 05:34:47 | 021,011,904 | ---- | C] () -- C:\Program Files\FLV PlayerRCSetup.exe
[2009/02/12 21:01:22 | 000,884,736 | ---- | C] () -- C:\WINDOWS\gmer.dll
[2009/02/12 21:01:22 | 000,000,250 | ---- | C] () -- C:\WINDOWS\gmer.ini
[2009/02/08 13:50:23 | 000,000,178 | -HS- | C] () -- C:\Documents and Settings\Administrator\ntuser.ini
[2009/02/08 13:50:21 | 000,057,344 | -H-- | C] () -- C:\Documents and Settings\Administrator\NtUser.dat.LOG
[2009/02/08 13:50:20 | 000,786,432 | ---- | C] () -- C:\Documents and Settings\Administrator\ntuser.dat
[2009/01/05 15:44:10 | 000,000,453 | ---- | C] () -- C:\WINDOWS\bdoscandellang.ini
[2008/12/30 21:27:42 | 000,007,680 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2008/12/30 21:27:42 | 000,000,547 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll.manifest
[2008/12/30 21:27:40 | 000,348,160 | ---- | C] () -- C:\WINDOWS\System32\cdga.dll
[2008/10/29 13:49:29 | 000,000,094 | ---- | C] () -- C:\Documents and Settings\Pam\couponmanager.properties
[2008/10/16 03:02:03 | 000,000,118 | ---- | C] () -- C:\WINDOWS\System32\MRT.INI
[2008/10/14 18:01:39 | 000,002,528 | ---- | C] () -- C:\WINDOWS\FCIC.INI
[2008/10/08 20:07:09 | 000,000,034 | ---- | C] () -- C:\WINDOWS\cdplayer.ini
[2008/09/09 18:48:09 | 000,000,107 | ---- | C] () -- C:\Documents and Settings\Tim\default.pls
[2008/09/09 18:37:25 | 000,008,704 | ---- | C] () -- C:\Documents and Settings\Tim\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/09/09 18:24:17 | 000,000,126 | ---- | C] () -- C:\Documents and Settings\Tim\Local Settings\Application Data\fusioncache.dat
[2008/09/09 18:10:52 | 000,000,151 | ---- | C] () -- C:\WINDOWS\PhotoSnapViewer.INI
[2008/09/09 17:12:59 | 000,000,201 | ---- | C] () -- C:\Documents and Settings\Pam\default.pls
[2008/09/09 17:00:33 | 000,000,126 | ---- | C] () -- C:\Documents and Settings\Pam\Local Settings\Application Data\fusioncache.dat
[2008/09/07 08:37:32 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2008/09/06 21:12:27 | 000,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2008/09/06 17:09:39 | 000,038,912 | ---- | C] () -- C:\Documents and Settings\Pam\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/09/05 15:14:49 | 000,008,192 | -H-- | C] () -- C:\Documents and Settings\Tim\ntuser.dat.LOG
[2008/09/05 15:14:49 | 000,000,278 | -HS- | C] () -- C:\Documents and Settings\Tim\ntuser.ini
[2008/09/03 10:14:35 | 000,008,192 | -H-- | C] () -- C:\Documents and Settings\Pam\ntuser.dat.LOG
[2008/09/03 10:14:35 | 000,000,278 | -HS- | C] () -- C:\Documents and Settings\Pam\ntuser.ini
[2008/09/03 10:13:46 | 000,229,376 | ---- | C] () -- C:\Documents and Settings\LocalService\NTUSER.DAT
[2008/09/03 10:13:46 | 000,008,192 | -H-- | C] () -- C:\Documents and Settings\LocalService\ntuser.dat.LOG
[2008/09/03 10:13:46 | 000,000,020 | -HS- | C] () -- C:\Documents and Settings\NetworkService\ntuser.ini
[2008/09/03 10:13:46 | 000,000,020 | -HS- | C] () -- C:\Documents and Settings\LocalService\ntuser.ini
[2008/09/03 10:13:45 | 000,233,472 | ---- | C] () -- C:\Documents and Settings\NetworkService\NTUSER.DAT
[2008/09/03 10:13:45 | 000,008,192 | -H-- | C] () -- C:\Documents and Settings\NetworkService\ntuser.dat.LOG
[2008/03/04 19:52:34 | 000,286,720 | ---- | C] () -- C:\WINDOWS\System32\libcurl.dll
[2007/11/26 22:56:28 | 000,151,415 | ---- | C] () -- C:\WINDOWS\System32\xlive.dll.cat
[2007/10/31 10:39:54 | 000,059,904 | ---- | C] () -- C:\WINDOWS\System32\zlib1.dll
[2007/08/06 19:22:15 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini
[2007/06/28 06:54:10 | 000,180,224 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2007/06/28 06:52:18 | 000,765,952 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2007/05/17 14:58:10 | 000,143,360 | ---- | C] () -- C:\WINDOWS\System32\libexpatw.dll
[2006/09/16 23:36:50 | 000,520,192 | ---- | C] () -- C:\WINDOWS\System32\CddbPlaylist2Roxio.dll
[2006/09/16 23:36:50 | 000,204,800 | ---- | C] () -- C:\WINDOWS\System32\CddbFileTaggerRoxio.dll
[2004/09/16 13:26:40 | 000,012,634 | ---- | C] () -- C:\WINDOWS\System32\drivers\ADFUUD.SYS
[2004/09/16 13:26:40 | 000,012,634 | ---- | C] () -- C:\WINDOWS\ADFUUD.SYS
[2003/03/31 08:00:00 | 000,138,368 | ---- | C] () -- C:\WINDOWS\System32\drivers\afd.sys
========== LOP Check ==========
[2010/08/12 22:27:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Pam\Application Data\Abine
[2008/11/10 19:42:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Pam\Application Data\Acoustica
[2008/11/30 21:50:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Pam\Application Data\Advanced Browser
[2010/01/29 17:34:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Pam\Application Data\Amazon
[2009/04/06 15:34:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Pam\Application Data\Any DVD Converter Professional
[2010/07/07 22:21:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Pam\Application Data\Azureus
[2010/08/11 08:47:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Pam\Application Data\BitTorrent
[2010/03/04 17:01:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Pam\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2009/04/18 23:15:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Pam\Application Data\com.raptr.Raptr.848BBC53270CAC248E8FA0F339176201CDEB525F.1
[2010/08/14 15:01:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Pam\Application Data\DNA
[2009/12/10 18:38:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Pam\Application Data\E-centives
[2010/05/13 22:45:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Pam\Application Data\eMusic
[2009/01/07 17:55:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Pam\Application Data\FDRLab
[2008/10/14 18:01:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Pam\Application Data\FirstClass
[2009/01/07 18:14:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Pam\Application Data\FrostWire
[2009/08/06 13:10:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Pam\Application Data\funkitron
[2008/10/31 23:19:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Pam\Application Data\GetRightToGo
[2010/03/15 21:34:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Pam\Application Data\IDM
[2009/05/01 10:04:55 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Pam\Application Data\ijjigame
[2010/04/07 08:49:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Pam\Application Data\imeshmediabartb
[2008/11/21 07:08:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Pam\Application Data\Jeaks Music
[2008/12/22 12:14:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Pam\Application Data\Leadertech
[2010/05/10 21:14:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Pam\Application Data\MP3Rocket
[2010/07/30 19:29:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Pam\Application Data\NBC Direct
[2010/05/15 00:19:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Pam\Application Data\NCH Swift Sound
[2009/04/18 23:39:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Pam\Application Data\NPLUTO Corporation
[2008/12/07 23:50:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Pam\Application Data\OpenOffice.org
[2010/08/14 18:24:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Pam\Application Data\PCenter
[2009/07/24 07:30:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Pam\Application Data\Raptr
[2010/07/22 00:00:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Pam\Application Data\Red Kawa
[2009/12/30 16:42:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Pam\Application Data\Skinux
[2009/05/07 20:08:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Pam\Application Data\yoclient
[2008/11/11 06:29:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tim\Application Data\Acoustica
[2009/07/10 21:14:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tim\Application Data\BitTorrent
[2009/09/18 23:00:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tim\Application Data\NCH Swift Sound
[2009/12/31 09:37:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tim\Application Data\Skinux
[2010/02/13 19:42:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tim\Application Data\Uniblue
[2010/08/11 15:28:00 | 000,000,432 | ---- | M] () -- C:\WINDOWS\Tasks\EasyShare Registration Task.job
[2010/05/31 22:42:00 | 000,000,276 | ---- | M] () -- C:\WINDOWS\Tasks\videopadShakeIcon.job
[2010/08/08 21:42:23 | 000,000,278 | ---- | M] () -- C:\WINDOWS\Tasks\wavepadDowngrade.job
[2010/08/08 21:42:23 | 000,000,278 | ---- | M] () -- C:\WINDOWS\Tasks\wavepadShakeIcon.job
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\Tim\My Documents\My Music:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\Pam\My Documents\My Downloads:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\Pam\My Documents\FirstClass:Roxio EMC Stream
< End of report >
Windows 7 Ultimate, Service Pack 1
AMD FX-4170 Quad-Core Processor 4.2 Ghz
8.0 GB RAM
64-bit Operating System
August 15th, 2010, 11:01 PM
#32
Since you'll be using USB stick to move files between bad and good computer...
On good computer...
Download, and run Flash Disinfector , and save it to your desktop.
*Please disable any AV / ScriptBlockers as they might detect Flash Disinfector to be malicious and block it. Hence, the failure in executing. You can enable them back after the cleaning process*
Double-click Flash_Disinfector.exe to run it and follow any prompts that may appear. The utility may ask you to insert your flash drive and/or other removable drives. Please do so and allow the utility to clean up those drives as well. Hold down the Shift key when inserting the drive until Windows detects it to keep autorun.inf from executing if it is present. Wait until it has finished scanning and then exit the program. Reboot your computer when done.
Note: As part of its routine, Flash_Disinfector will create a hidden folder named autorun.inf in each partition and every USB drive that was plugged in when you ran it. Do not delete this folder...it will help protect your drives from future infection by keeping the autorun file from being installed on the root drive and running other malicious files.
================================================================
Uuuuugh.....there was a lot of baddies.
Hopefully, we got most of them.
Do this on the computer you are posting from :
Copy the text in the codebox below:
Code:
:OTL
SRV - [2010/08/14 14:49:08 | 000,059,904 | ---- | M] () [Auto] -- C:\Program Files\csrss.exe -- (QTUpdate)
DRV - File not found [Kernel | On_Demand] -- C:\DOCUME~1\Pam\LOCALS~1\Temp\mdxgthkn.sys -- (mdxgthkn)
DRV - File not found [Kernel | On_Demand] -- C:\WINDOWS\System32\drivers\EagleNT.sys -- (EagleNT)
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:5577
IE - HKU\Pam_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
IE - HKU\Pam_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:5577
IE - HKU\Pam_ON_C\..\URLSearchHook: {9927cacb-7863-42b4-95ab-7446332b7c59} - Reg Error: Key error. File not found
IE - HKU\Pam_ON_C\..\URLSearchHook: {9ee802e8-c931-47ab-b570-aa8f791598ca} - Reg Error: Key error. File not found
IE - HKU\Tim_ON_C\..\URLSearchHook: *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - Reg Error: Key error. File not found
IE - HKU\Tim_ON_C\..\URLSearchHook: *{EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key error. File not found
IE - HKU\Tim_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
IE - HKU\Tim_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:5577
O2 - BHO: (ADC PlugIn) - {19090308-636D-4e9b-A1CE-A647B6F794BF} - C:\Program Files\shk_v10.dll (Intsys)
O2 - BHO: (BrowserHelper Class) - {8A9D74F9-560B-4FE7-ABEB-3B2E638E5CD6} - C:\Program Files\SGPSA\SearchAssistant.dll (Make The Web Better, LLC)
O3 - HKU\Pam_ON_C\..\Toolbar\WebBrowser: (no name) - {0388BA0C-C7F1-4E6A-BD7A-B59623F33363} - No CLSID value found.
O3 - HKU\Pam_ON_C\..\Toolbar\WebBrowser: (no name) - {1BB22D38-A411-4B13-A746-C2A4F4EC7344} - No CLSID value found.
O3 - HKU\Pam_ON_C\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKU\Pam_ON_C\..\Toolbar\WebBrowser: (no name) - {9927CACB-7863-42B4-95AB-7446332B7C59} - No CLSID value found.
O3 - HKU\Pam_ON_C\..\Toolbar\WebBrowser: (no name) - {9EE802E8-C931-47AB-B570-AA8F791598CA} - No CLSID value found.
O3 - HKU\Tim_ON_C\..\Toolbar\WebBrowser: (no name) - {0388BA0C-C7F1-4E6A-BD7A-B59623F33363} - No CLSID value found.
O4 - HKU\Pam_ON_C..\Run: [ap.exe] C:\Documents and Settings\Pam\Application Data\PCenter\ap.exe ()
O4 - HKU\Pam_ON_C..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe File not found
O4 - HKU\Pam_ON_C..\Run: [DW6] C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe File not found
O4 - HKU\Pam_ON_C..\Run: [MalwareBot] C:\Program Files\MalwareBot\MalwareBot.exe File not found
O4 - HKU\Pam_ON_C..\Run: [MsnMsgr] C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe File not found
O4 - HKU\Tim_ON_C..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe File not found
O4 - HKU\Pam_ON_C..\RunOnce: [Shockwave Updater] C:\WINDOWS\System32\Adobe\SHOCKW~1\SWHELP~3.EXE -Update -1103472 -Mozilla\4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident\4.0; File not found
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O20 - AppInit_DLLs: (C:\PROGRA~1\IMESHA~1\MediaBar\DataMngr\datamngr.dll) - C:\PROGRA~1\IMESHA~1\MediaBar\DataMngr\datamngr.dll File not found
O20 - HKU\Pam_ON_C Winlogon: Shell - (C:\Documents and Settings\Pam\Application Data\PCenter\sp.exe) - C:\Documents and Settings\Pam\Application Data\PCenter\sp.exe ()
O35 - HKLM\..exefile [open] -- C:\Program Files\conhost.exe "%1" %* ()
O37 - HKLM\...exe [@ = exefile] -- C:\Program Files\conhost.exe "%1" %* ()
[2010/08/14 18:24:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Pam\Application Data\PCenter
[2010/08/14 14:49:10 | 000,372,224 | ---- | C] (Intsys) -- C:\Program Files\shk_v10.dll
[2010/08/14 14:49:05 | 000,000,000 | ---D | C] -- C:\Program Files\Wireshark Antivirus
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[23 C:\Documents and Settings\Pam\My Documents\*.tmp files -> C:\Documents and Settings\Pam\My Documents\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]
[2010/08/15 21:12:46 | 000,000,060 | ---- | M] () -- C:\Program Files\sh4.dat
[2010/08/15 21:12:46 | 000,000,004 | ---- | M] () -- C:\Program Files\sh3.dat
[2010/08/15 19:24:00 | 000,098,304 | ---- | M] () -- C:\Program Files\conhost.exe
[2010/08/15 19:23:59 | 000,372,224 | ---- | M] (Intsys) -- C:\Program Files\shk_v10.dll
[2010/08/15 19:23:57 | 000,001,550 | ---- | M] () -- C:\Wireshark Antivirus.lnk
[2010/08/14 14:49:09 | 000,000,009 | ---- | M] () -- C:\Program Files\nuar.old
[2010/08/14 14:49:08 | 000,059,904 | ---- | M] () -- C:\Program Files\csrss.exe
[2010/08/14 14:49:08 | 000,000,036 | ---- | M] () -- C:\Program Files\skynet.dat
[2010/08/14 14:49:07 | 000,001,684 | ---- | M] () -- C:\Documents and Settings\Pam\Desktop\Wireshark Antivirus.lnk
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\Tim\My Documents\My Music:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\Pam\My Documents\My Downloads:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\Pam\My Documents\FirstClass:Roxio EMC Stream
:Services
:Reg
:Files
:Commands
[purity]
[emptytemp]
Open Notepad and paste it.
Save the document as Fix.txt on to a USB flash drive
On the infected computer the following...
Run OTLPE
Insert USB stick and find the file Fix.txt . Drag the file Fix.txt and drop it under the Custom Scans/Fixes box at the bottom.
(The content of Fix.txt should appear in the box) Then click the Run Fix button at the top Let the program run unhindered, reboot the PC when it is done Post the log produced (you'll need to transfer it with USB stick) Attempt to reboot normally into windows.
August 15th, 2010, 11:27 PM
#33
The computer seems to have booted normally.
:OTL
SRV - [2010/08/14 14:49:08 | 000,059,904 | ---- | M] () [Auto] -- C:\Program Files\csrss.exe -- (QTUpdate)
DRV - File not found [Kernel | On_Demand] -- C:\DOCUME~1\Pam\LOCALS~1\Temp\mdxgthkn.sys -- (mdxgthkn)
DRV - File not found [Kernel | On_Demand] -- C:\WINDOWS\System32\drivers\EagleNT.sys -- (EagleNT)
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:5577
IE - HKU\Pam_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
IE - HKU\Pam_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:5577
IE - HKU\Pam_ON_C\..\URLSearchHook: {9927cacb-7863-42b4-95ab-7446332b7c59} - Reg Error: Key error. File not found
IE - HKU\Pam_ON_C\..\URLSearchHook: {9ee802e8-c931-47ab-b570-aa8f791598ca} - Reg Error: Key error. File not found
IE - HKU\Tim_ON_C\..\URLSearchHook: *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - Reg Error: Key error. File not found
IE - HKU\Tim_ON_C\..\URLSearchHook: *{EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key error. File not found
IE - HKU\Tim_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
IE - HKU\Tim_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:5577
O2 - BHO: (ADC PlugIn) - {19090308-636D-4e9b-A1CE-A647B6F794BF} - C:\Program Files\shk_v10.dll (Intsys)
O2 - BHO: (BrowserHelper Class) - {8A9D74F9-560B-4FE7-ABEB-3B2E638E5CD6} - C:\Program Files\SGPSA\SearchAssistant.dll (Make The Web Better, LLC)
O3 - HKU\Pam_ON_C\..\Toolbar\WebBrowser: (no name) - {0388BA0C-C7F1-4E6A-BD7A-B59623F33363} - No CLSID value found.
O3 - HKU\Pam_ON_C\..\Toolbar\WebBrowser: (no name) - {1BB22D38-A411-4B13-A746-C2A4F4EC7344} - No CLSID value found.
O3 - HKU\Pam_ON_C\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKU\Pam_ON_C\..\Toolbar\WebBrowser: (no name) - {9927CACB-7863-42B4-95AB-7446332B7C59} - No CLSID value found.
O3 - HKU\Pam_ON_C\..\Toolbar\WebBrowser: (no name) - {9EE802E8-C931-47AB-B570-AA8F791598CA} - No CLSID value found.
O3 - HKU\Tim_ON_C\..\Toolbar\WebBrowser: (no name) - {0388BA0C-C7F1-4E6A-BD7A-B59623F33363} - No CLSID value found.
O4 - HKU\Pam_ON_C..\Run: [ap.exe] C:\Documents and Settings\Pam\Application Data\PCenter\ap.exe ()
O4 - HKU\Pam_ON_C..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe File not found
O4 - HKU\Pam_ON_C..\Run: [DW6] C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe File not found
O4 - HKU\Pam_ON_C..\Run: [MalwareBot] C:\Program Files\MalwareBot\MalwareBot.exe File not found
O4 - HKU\Pam_ON_C..\Run: [MsnMsgr] C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe File not found
O4 - HKU\Tim_ON_C..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe File not found
O4 - HKU\Pam_ON_C..\RunOnce: [Shockwave Updater] C:\WINDOWS\System32\Adobe\SHOCKW~1\SWHELP~3.EXE -Update -1103472 -Mozilla\4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident\4.0; File not found
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O20 - AppInit_DLLs: (C:\PROGRA~1\IMESHA~1\MediaBar\DataMngr\datamngr.dll) - C:\PROGRA~1\IMESHA~1\MediaBar\DataMngr\datamngr.dll File not found
O20 - HKU\Pam_ON_C Winlogon: Shell - (C:\Documents and Settings\Pam\Application Data\PCenter\sp.exe) - C:\Documents and Settings\Pam\Application Data\PCenter\sp.exe ()
O35 - HKLM\..exefile [open] -- C:\Program Files\conhost.exe "%1" %* ()
O37 - HKLM\...exe [@ = exefile] -- C:\Program Files\conhost.exe "%1" %* ()
[2010/08/14 18:24:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Pam\Application Data\PCenter
[2010/08/14 14:49:10 | 000,372,224 | ---- | C] (Intsys) -- C:\Program Files\shk_v10.dll
[2010/08/14 14:49:05 | 000,000,000 | ---D | C] -- C:\Program Files\Wireshark Antivirus
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[23 C:\Documents and Settings\Pam\My Documents\*.tmp files -> C:\Documents and Settings\Pam\My Documents\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]
[2010/08/15 21:12:46 | 000,000,060 | ---- | M] () -- C:\Program Files\sh4.dat
[2010/08/15 21:12:46 | 000,000,004 | ---- | M] () -- C:\Program Files\sh3.dat
[2010/08/15 19:24:00 | 000,098,304 | ---- | M] () -- C:\Program Files\conhost.exe
[2010/08/15 19:23:59 | 000,372,224 | ---- | M] (Intsys) -- C:\Program Files\shk_v10.dll
[2010/08/15 19:23:57 | 000,001,550 | ---- | M] () -- C:\Wireshark Antivirus.lnk
[2010/08/14 14:49:09 | 000,000,009 | ---- | M] () -- C:\Program Files\nuar.old
[2010/08/14 14:49:08 | 000,059,904 | ---- | M] () -- C:\Program Files\csrss.exe
[2010/08/14 14:49:08 | 000,000,036 | ---- | M] () -- C:\Program Files\skynet.dat
[2010/08/14 14:49:07 | 000,001,684 | ---- | M] () -- C:\Documents and Settings\Pam\Desktop\Wireshark Antivirus.lnk
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\Tim\My Documents\My Music:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\Pam\My Documents\My Downloads:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\Pam\My Documents\FirstClass:Roxio EMC Stream
:Services
:Reg
:Files
:Commands
[purity]
[emptytemp]
Windows 7 Ultimate, Service Pack 1
AMD FX-4170 Quad-Core Processor 4.2 Ghz
8.0 GB RAM
64-bit Operating System
August 15th, 2010, 11:35 PM
#34
The above is my fix.
That fix was supposed to produce a log, which you're suppose to post back here.
Probably, I can live without it, as long as computer booted normally.
Let's double check....
On bad computer ......
Download OTL to your Desktop.
* Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
* Under the Custom Scan box paste this in:
netsvcs
drivers32 /all
%SYSTEMDRIVE%\*.*
%systemroot%\system32\Spool\prtprocs\w32x86\*.dll
%systemroot%\system32\*.wt
%systemroot%\system32\*.ruy
%systemroot%\Fonts\*.com
%systemroot%\Fonts\*.dll
%systemroot%\system32\spool\prtprocs\w32x86\*.tmp
%systemroot%\*. /mp /s
/md5start
/md5stop
CREATERESTOREPOINT
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\Tasks\*.job /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\system32\user32.dll /md5
%systemroot%\system32\ws2_32.dll /md5
%systemroot%\system32\ws2help.dll /md5
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs
* Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open two notepad windows: OTL.txt and Extras.txt . These are saved in the same location as OTL. Please copy (Edit->Select All, Edit->Copy ) the contents of these files, one at a time, and post them back here.
August 16th, 2010, 12:07 AM
#35
Sorry I accidentaly posted the wrong doc. Here is the correct one from the first fix. I am now preparing to run the second.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\QTUpdate deleted successfully.
C:\Program Files\csrss.exe moved successfully.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\mdxgthkn deleted successfully.
File C:\DOCUME~1\Pam\LOCALS~1\Temp\mdxgthkn.sys not found.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\EagleNT deleted successfully.
File C:\WINDOWS\System32\drivers\EagleNT.sys not found.
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyOverride| /E : value set successfully!
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer| /E : value set successfully!
HKU\Pam_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyOverride| /E : value set successfully!
HKU\Pam_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer| /E : value set successfully!
Registry value HKEY_USERS\Pam_ON_C\Software\Microsoft\Internet Explorer\URLSearchHooks\\{9927cacb-7863-42b4-95ab-7446332b7c59} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9927cacb-7863-42b4-95ab-7446332b7c59}\ not found.
Registry value HKEY_USERS\Pam_ON_C\Software\Microsoft\Internet Explorer\URLSearchHooks\\{9ee802e8-c931-47ab-b570-aa8f791598ca} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9ee802e8-c931-47ab-b570-aa8f791598ca}\ not found.
Registry value HKEY_USERS\Tim_ON_C\Software\Microsoft\Internet Explorer\URLSearchHooks\\*{CFBFAE00-17A6-11D0-99CB-00C04FD64497} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\*{CFBFAE00-17A6-11D0-99CB-00C04FD64497}\ not found.
Registry value HKEY_USERS\Tim_ON_C\Software\Microsoft\Internet Explorer\URLSearchHooks\\*{EF99BD32-C1FB-11D2-892F-0090271D4F88} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\*{EF99BD32-C1FB-11D2-892F-0090271D4F88}\ not found.
HKU\Tim_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyOverride| /E : value set successfully!
HKU\Tim_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer| /E : value set successfully!
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{19090308-636D-4e9b-A1CE-A647B6F794BF}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{19090308-636D-4e9b-A1CE-A647B6F794BF}\ deleted successfully.
C:\Program Files\shk_v10.dll moved successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8A9D74F9-560B-4FE7-ABEB-3B2E638E5CD6}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8A9D74F9-560B-4FE7-ABEB-3B2E638E5CD6}\ deleted successfully.
C:\Program Files\SGPSA\SearchAssistant.dll moved successfully.
Registry value HKEY_USERS\Pam_ON_C\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{0388BA0C-C7F1-4E6A-BD7A-B59623F33363} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0388BA0C-C7F1-4E6A-BD7A-B59623F33363}\ not found.
Registry value HKEY_USERS\Pam_ON_C\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{1BB22D38-A411-4B13-A746-C2A4F4EC7344} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1BB22D38-A411-4B13-A746-C2A4F4EC7344}\ not found.
Registry value HKEY_USERS\Pam_ON_C\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F}\ not found.
Registry value HKEY_USERS\Pam_ON_C\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{9927CACB-7863-42B4-95AB-7446332B7C59} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9927CACB-7863-42B4-95AB-7446332B7C59}\ not found.
Registry value HKEY_USERS\Pam_ON_C\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{9EE802E8-C931-47AB-B570-AA8F791598CA} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9EE802E8-C931-47AB-B570-AA8F791598CA}\ not found.
Registry value HKEY_USERS\Tim_ON_C\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{0388BA0C-C7F1-4E6A-BD7A-B59623F33363} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0388BA0C-C7F1-4E6A-BD7A-B59623F33363}\ not found.
Registry value HKEY_USERS\Pam_ON_C\Software\Microsoft\Windows\CurrentVersion\Run\\ap.exe deleted successfully.
C:\Documents and Settings\Pam\Application Data\PCenter\ap.exe moved successfully.
Registry value HKEY_USERS\Pam_ON_C\Software\Microsoft\Windows\CurrentVersion\Run\\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} deleted successfully.
Registry value HKEY_USERS\Pam_ON_C\Software\Microsoft\Windows\CurrentVersion\Run\\DW6 deleted successfully.
Registry value HKEY_USERS\Pam_ON_C\Software\Microsoft\Windows\CurrentVersion\Run\\MalwareBot deleted successfully.
Registry value HKEY_USERS\Pam_ON_C\Software\Microsoft\Windows\CurrentVersion\Run\\MsnMsgr deleted successfully.
Registry value HKEY_USERS\Tim_ON_C\Software\Microsoft\Windows\CurrentVersion\Run\\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} deleted successfully.
Registry value HKEY_USERS\Pam_ON_C\Software\Microsoft\Windows\CurrentVersion\RunOnce\\Shockwave Updater deleted successfully.
Starting removal of ActiveX control {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
C:\WINDOWS\Downloaded Program Files\gp.inf not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
Registry key HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Active Setup\Installed Components\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
Registry key HKEY_USERS\Administrator_ON_C\SOFTWARE\Microsoft\Active Setup\Installed Components\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
Registry key HKEY_USERS\LocalService_ON_C\SOFTWARE\Microsoft\Active Setup\Installed Components\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
Registry key HKEY_USERS\NetworkService_ON_C\SOFTWARE\Microsoft\Active Setup\Installed Components\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
Registry key HKEY_USERS\Pam_ON_C\SOFTWARE\Microsoft\Active Setup\Installed Components\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
Registry key HKEY_USERS\systemprofile_ON_C\SOFTWARE\Microsoft\Active Setup\Installed Components\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
Registry key HKEY_USERS\Tim_ON_C\SOFTWARE\Microsoft\Active Setup\Installed Components\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:C:\PROGRA~1\IMESHA~1\MediaBar\DataMngr\datamngr.dll deleted successfully.
Registry value HKEY_USERS\Pam_ON_C\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell:C:\Documents and Settings\Pam\Application Data\PCenter\sp.exe deleted successfully.
C:\Documents and Settings\Pam\Application Data\PCenter\sp.exe moved successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shell\open\command\\'' updated successfully.
C:\Program Files\conhost.exe moved successfully.
HKEY_LOCAL_MACHINE\Software\Classes\.exe\shell\open\command\\|"%1" %* /E : value set successfully!
HKEY_LOCAL_MACHINE\Software\Classes\.exe\\|exefile /E : value set successfully!
C:\Documents and Settings\Pam\Application Data\PCenter folder moved successfully.
File C:\Program Files\shk_v10.dll not found.
C:\Program Files\Wireshark Antivirus folder moved successfully.
C:\WINDOWS\System32\CONFIG.TMP deleted successfully.
C:\WINDOWS\System32\SET41.tmp deleted successfully.
C:\WINDOWS\System32\SET46.tmp deleted successfully.
C:\WINDOWS\System32\SET4D.tmp deleted successfully.
C:\WINDOWS\002217_.tmp deleted successfully.
C:\WINDOWS\SET3.tmp deleted successfully.
C:\WINDOWS\SET7.tmp deleted successfully.
C:\Documents and Settings\Pam\My Documents\~WRD3233.tmp deleted successfully.
C:\Documents and Settings\Pam\My Documents\~WRL0001.tmp deleted successfully.
C:\Documents and Settings\Pam\My Documents\~WRL0002.tmp deleted successfully.
C:\Documents and Settings\Pam\My Documents\~WRL0004.tmp deleted successfully.
C:\Documents and Settings\Pam\My Documents\~WRL0005.tmp deleted successfully.
C:\Documents and Settings\Pam\My Documents\~WRL0258.tmp deleted successfully.
C:\Documents and Settings\Pam\My Documents\~WRL0425.tmp deleted successfully.
C:\Documents and Settings\Pam\My Documents\~WRL0600.tmp deleted successfully.
C:\Documents and Settings\Pam\My Documents\~WRL0884.tmp deleted successfully.
C:\Documents and Settings\Pam\My Documents\~WRL0935.tmp deleted successfully.
C:\Documents and Settings\Pam\My Documents\~WRL1335.tmp deleted successfully.
C:\Documents and Settings\Pam\My Documents\~WRL1424.tmp deleted successfully.
C:\Documents and Settings\Pam\My Documents\~WRL1964.tmp deleted successfully.
C:\Documents and Settings\Pam\My Documents\~WRL2019.tmp deleted successfully.
C:\Documents and Settings\Pam\My Documents\~WRL2231.tmp deleted successfully.
C:\Documents and Settings\Pam\My Documents\~WRL2300.tmp deleted successfully.
C:\Documents and Settings\Pam\My Documents\~WRL2552.tmp deleted successfully.
C:\Documents and Settings\Pam\My Documents\~WRL3574.tmp deleted successfully.
C:\Documents and Settings\Pam\My Documents\~WRL3624.tmp deleted successfully.
C:\Documents and Settings\Pam\My Documents\~WRL3722.tmp deleted successfully.
C:\Documents and Settings\Pam\My Documents\~WRL3916.tmp deleted successfully.
C:\Documents and Settings\Pam\My Documents\~WRL3935.tmp deleted successfully.
C:\Documents and Settings\Pam\My Documents\~WRL3951.tmp deleted successfully.
C:\LOGA.tmp deleted successfully.
C:\Program Files\sh4.dat moved successfully.
C:\Program Files\sh3.dat moved successfully.
File C:\Program Files\conhost.exe not found.
File C:\Program Files\shk_v10.dll not found.
C:\Wireshark Antivirus.lnk moved successfully.
C:\Program Files\nuar.old moved successfully.
File C:\Program Files\csrss.exe not found.
C:\Program Files\skynet.dat moved successfully.
C:\Documents and Settings\Pam\Desktop\Wireshark Antivirus.lnk moved successfully.
Unable to delete ADS C:\Documents and Settings\Tim\My Documents\My Music:Roxio EMC Stream .
ADS C:\Documents and Settings\Pam\My Documents\My Downloads:Roxio EMC Stream deleted successfully.
ADS C:\Documents and Settings\Pam\My Documents\FirstClass:Roxio EMC Stream deleted successfully.
========== SERVICES/DRIVERS ==========
========== REGISTRY ==========
========== FILES ==========
========== COMMANDS ==========
[EMPTYTEMP]
User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 184978 bytes
->FireFox cache emptied: 3373644 bytes
User: All Users
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 56504 bytes
User: LocalService
->Temp folder emptied: 66016 bytes
->Temporary Internet Files folder emptied: 88061 bytes
User: NetworkService
->Temp folder emptied: 776917 bytes
->Temporary Internet Files folder emptied: 1442194 bytes
->Flash cache emptied: 31360 bytes
User: Pam
->Temp folder emptied: 5285696 bytes
->Temporary Internet Files folder emptied: 26284685 bytes
->Java cache emptied: 17286 bytes
->FireFox cache emptied: 39141761 bytes
->Google Chrome cache emptied: 0 bytes
->Flash cache emptied: 59855 bytes
User: Tim
->Temp folder emptied: 607240 bytes
->Temporary Internet Files folder emptied: 228392 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 40554844 bytes
->Google Chrome cache emptied: 819568 bytes
->Flash cache emptied: 3251 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 7062149 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 51705398 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
Total Files Cleaned = 170.00 mb
OTLPE by OldTimer - Version 3.1.40.0 log created on 08162010_001925
Windows 7 Ultimate, Service Pack 1
AMD FX-4170 Quad-Core Processor 4.2 Ghz
8.0 GB RAM
64-bit Operating System
August 16th, 2010, 12:23 AM
#36
Very good
Hold on with new OTL for now.
STEP 1. Download Malwarebytes' Anti-Malware (aka MBAM): http://www.malwarebytes.org/mbam.php to your desktop.
(Malwarebytes is free to use as a manual scanner. Payment is only required if you wish to have it run and update automatically which is not necessary for our purposes)
* Double-click mbam-setup.exe and follow the prompts to install the program.
* At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware , then click Finish .
* If an update is found, it will download and install the latest version.
* Once the program has loaded, select Perform Quick Scan , then click Scan .
* When the scan is complete, click OK, then Show Results to view the results.
* Be sure that everything is checked, and click Remove Selected .
* When completed, a log will open in Notepad.
* Post the log back here .
The log can also be found here:
C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt
STEP 2. Download GMER : http://www.gmer.net/files.php , by clicking on Download EXE button.
Alternative downloads:
- http://majorgeeks.com/GMER_d5198.html
- http://www.softpedia.com/get/Interne...ers/GMER.shtml
Double click on downloaded .exe file, select Rootkit tab and click the Scan button.
Do NOT use the computer while GMER is running!
When scan is completed, click Save button, and save the results as gmer.log
Warning ! Please, do not select the "Show all" checkbox during the scan.
Post the log to your next reply.
IMPORTANT! If for some reason GMER refuses to run, try again.
If it still fails, try to UN-check "Devices" in right pane.
If still no joy, try to run it from Safe Mode.
STEP 3. Download MBRCheck to your desktop
Double click MBRCheck.exe to run (Vista and Windows 7 users, right click and select Run as Administrator ).
It will show a black screen with some data on it.
A report called MBRcheckxxxx.txt will be on your desktop
Open this report and post its content in your next reply.
DO NOT make any other changes to your computer (like installing programs, using other cleaning tools, etc.), until it's officially declared clean!!!
August 16th, 2010, 12:40 AM
#37
Attached are the two results from the second OTL scan. I ran it before you posted back. Should I proceed with the Malware post when I continue. I will have to continue tomorrow though because I have to turn in because i have to get up early for golf practice. My dad should or I will continue with you tomorrow most likely.
Attached Files
Windows 7 Ultimate, Service Pack 1
AMD FX-4170 Quad-Core Processor 4.2 Ghz
8.0 GB RAM
64-bit Operating System
August 16th, 2010, 12:42 AM
#38
Yes, proceed with steps from my previous reply.
This computer shouldn't be used for now though.
August 16th, 2010, 10:02 PM
#39
Tim is in the house!
GMER scans but terminates after scan is complete before I can save anything! I've tried it twice with the same results. I am using the "bad" computer to connect with you so I can download fron your links. Is that OK? I know Samuel ran the MBAM and saved the log on a flash drive. I ran the MBRCheck program. The results are in a DOS window. I don't remember how to get it in a form I can send to you. Not sure what to do next.
Last edited by timmyb74; August 16th, 2010 at 10:07 PM .
Reason: aditional information added
Windows 7 Ultimate, Service Pack 1
AMD FX-4170 Quad-Core Processor 4.2 Ghz
8.0 GB RAM
64-bit Operating System
August 16th, 2010, 10:10 PM
#40
Yes, you should run all scans on bad computer.
IMPORTANT! If for some reason GMER refuses to run, try again.
If it still fails, try to UN-check "Devices" in right pane.
If still no joy, try to run it from Safe Mode.
If still problem, skip it.
You can simply re-run MBAM and MBRCheck. They won't take long.
August 16th, 2010, 10:15 PM
#41
GMER does run and there is a lot of stuff on the screen. I just can't save it for some reason. This scan takes quite a long time will I beable to save the results if I run it in safe mode?
What info are you looking for from the MBRCheck. I can type in the info you need manually?
Windows 7 Ultimate, Service Pack 1
AMD FX-4170 Quad-Core Processor 4.2 Ghz
8.0 GB RAM
64-bit Operating System
August 16th, 2010, 10:18 PM
#42
Skip GMER for now.
As for MBRCheck, follow instructions from my reply #36 and it'll create a log for you.
August 16th, 2010, 10:23 PM
#43
You can tell it's me and not Samuel can't you?
MBRCheck, version 1.2.3
(c) 2010, AD
Command-line:
Windows Version: Windows XP Professional
Windows Information: Service Pack 2 (build 2600)
Logical Drives Mask: 0x0000000d
Kernel Drivers (total 132):
0x804D7000 \WINDOWS\system32\ntkrnlpa.exe
0x806E2000 \WINDOWS\system32\hal.dll
0xBA5A8000 \WINDOWS\system32\KDCOM.DLL
0xBA4B8000 \WINDOWS\system32\BOOTVID.dll
0xB9F79000 ACPI.sys
0xBA5AA000 \WINDOWS\System32\DRIVERS\WMILIB.SYS
0xB9F68000 pci.sys
0xBA0A8000 isapnp.sys
0xBA670000 pciide.sys
0xBA328000 \WINDOWS\System32\DRIVERS\PCIIDEX.SYS
0xBA0B8000 MountMgr.sys
0xB9F49000 ftdisk.sys
0xBA5AC000 dmload.sys
0xB9F23000 dmio.sys
0xBA330000 PartMgr.sys
0xBA671000 amdide.sys
0xBA0C8000 VolSnap.sys
0xB9F0B000 atapi.sys
0xBA0D8000 disk.sys
0xBA0E8000 \WINDOWS\System32\DRIVERS\CLASSPNP.SYS
0xB9EEB000 fltmgr.sys
0xB9ED9000 sr.sys
0xBA0F8000 PxHelp20.sys
0xB9EC2000 KSecDD.sys
0xB9EAB000 WudfPf.sys
0xB9E1E000 Ntfs.sys
0xB9DF1000 NDIS.sys
0xB9DD6000 Mup.sys
0xB77C8000 \SystemRoot\System32\DRIVERS\processr.sys
0xB7315000 \SystemRoot\system32\DRIVERS\ati2mtag.sys
0xB7301000 \SystemRoot\system32\DRIVERS\VIDEOPRT.SYS
0xB72DC000 \SystemRoot\system32\DRIVERS\HDAudBus.sys
0xB72C2000 \SystemRoot\system32\DRIVERS\Rtenicxp.sys
0xB77B8000 \SystemRoot\System32\DRIVERS\imapi.sys
0xB77A8000 \SystemRoot\System32\Drivers\AFS2K.SYS
0xB7798000 \SystemRoot\System32\DRIVERS\cdrom.sys
0xB7788000 \SystemRoot\System32\DRIVERS\redbook.sys
0xB729F000 \SystemRoot\System32\DRIVERS\ks.sys
0xBA450000 \SystemRoot\system32\DRIVERS\GEARAspiWDM.sys
0xBA458000 \SystemRoot\System32\DRIVERS\usbohci.sys
0xB727C000 \SystemRoot\System32\DRIVERS\USBPORT.SYS
0xBA460000 \SystemRoot\System32\DRIVERS\usbehci.sys
0xB7778000 \SystemRoot\System32\DRIVERS\serial.sys
0xBA5A0000 \SystemRoot\System32\DRIVERS\serenum.sys
0xBA468000 \SystemRoot\System32\DRIVERS\fdc.sys
0xB7768000 \SystemRoot\System32\DRIVERS\i8042prt.sys
0xBA470000 \SystemRoot\System32\DRIVERS\kbdclass.sys
0xBA740000 \SystemRoot\System32\DRIVERS\audstub.sys
0xBA238000 \SystemRoot\System32\DRIVERS\rasl2tp.sys
0xB7DB2000 \SystemRoot\System32\DRIVERS\ndistapi.sys
0xB7265000 \SystemRoot\System32\DRIVERS\ndiswan.sys
0xBA248000 \SystemRoot\System32\DRIVERS\raspppoe.sys
0xBA258000 \SystemRoot\System32\DRIVERS\raspptp.sys
0xBA478000 \SystemRoot\System32\DRIVERS\TDI.SYS
0xB7254000 \SystemRoot\System32\DRIVERS\psched.sys
0xBA268000 \SystemRoot\System32\DRIVERS\msgpc.sys
0xBA480000 \SystemRoot\System32\DRIVERS\ptilink.sys
0xBA488000 \SystemRoot\System32\DRIVERS\raspti.sys
0xBA5DC000 \SystemRoot\System32\Drivers\RootMdm.sys
0xBA490000 \SystemRoot\System32\Drivers\Modem.SYS
0xB7223000 \SystemRoot\System32\DRIVERS\rdpdr.sys
0xBA278000 \SystemRoot\System32\DRIVERS\termdd.sys
0xBA498000 \SystemRoot\System32\DRIVERS\mouclass.sys
0xBA5DE000 \SystemRoot\System32\DRIVERS\swenum.sys
0xB71C7000 \SystemRoot\System32\DRIVERS\update.sys
0xB7D9A000 \SystemRoot\System32\DRIVERS\mssmbios.sys
0xBA288000 \SystemRoot\System32\DRIVERS\usbhub.sys
0xBA5E0000 \SystemRoot\System32\DRIVERS\USBD.SYS
0xBA298000 \SystemRoot\System32\Drivers\NDProxy.SYS
0xA708D000 \SystemRoot\system32\drivers\AtiHdmi.sys
0xA706B000 \SystemRoot\system32\drivers\portcls.sys
0xBA2C8000 \SystemRoot\system32\drivers\drmk.sys
0xBA2D8000 \SystemRoot\system32\DRIVERS\stdriver32.sys
0xA5E2F000 \SystemRoot\system32\drivers\sthda.sys
0xBA4A0000 \SystemRoot\System32\DRIVERS\flpydisk.sys
0xBA5EA000 \SystemRoot\System32\Drivers\Fs_Rec.SYS
0xBA69B000 \SystemRoot\System32\Drivers\Null.SYS
0xBA5EC000 \SystemRoot\System32\Drivers\Beep.SYS
0xBA4B0000 \SystemRoot\System32\drivers\vga.sys
0xBA5EE000 \SystemRoot\System32\Drivers\mnmdd.SYS
0xBA5F0000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0xBA340000 \SystemRoot\System32\Drivers\Msfs.SYS
0xBA370000 \SystemRoot\System32\Drivers\Npfs.SYS
0xBA570000 \SystemRoot\System32\DRIVERS\rasacd.sys
0xA5DFC000 \SystemRoot\System32\DRIVERS\ipsec.sys
0xA5DA3000 \SystemRoot\System32\DRIVERS\tcpip.sys
0xA5D41000 \SystemRoot\System32\Drivers\avgtdix.sys
0xBA2F8000 \SystemRoot\System32\DRIVERS\wanarp.sys
0xA5D20000 \SystemRoot\System32\DRIVERS\ipnat.sys
0xBA584000 \SystemRoot\System32\DRIVERS\hidusb.sys
0xBA308000 \SystemRoot\System32\DRIVERS\HIDCLASS.SYS
0xBA378000 \SystemRoot\System32\DRIVERS\HIDPARSE.SYS
0xBA380000 \SystemRoot\system32\DRIVERS\usbccgp.sys
0xBA590000 \SystemRoot\System32\DRIVERS\mouhid.sys
0xBA594000 \SystemRoot\system32\DRIVERS\usbscan.sys
0xBA388000 \SystemRoot\system32\DRIVERS\usbprint.sys
0xBA390000 \SystemRoot\system32\DRIVERS\HPZius12.sys
0xBA318000 \SystemRoot\system32\DRIVERS\HPZid412.sys
0xBA598000 \SystemRoot\system32\DRIVERS\HPZipr12.sys
0xA5C58000 \SystemRoot\System32\DRIVERS\netbt.sys
0xA5C36000 \SystemRoot\System32\drivers\afd.sys
0xBA138000 \SystemRoot\System32\DRIVERS\netbios.sys
0xA5C14000 \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys
0xBA3E0000 \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS
0xA5BE9000 \SystemRoot\System32\DRIVERS\rdbss.sys
0xA5B7A000 \SystemRoot\System32\DRIVERS\mrxsmb.sys
0xBA158000 \SystemRoot\System32\Drivers\Fips.SYS
0xBA3F0000 \SystemRoot\System32\Drivers\avgmfx86.sys
0xA5B46000 \SystemRoot\System32\Drivers\avgldx86.sys
0xB7748000 \SystemRoot\System32\Drivers\Cdfs.SYS
0xBF800000 \SystemRoot\System32\win32k.sys
0xB720F000 \SystemRoot\System32\drivers\Dxapi.sys
0xBA408000 \SystemRoot\System32\watchdog.sys
0xBF000000 \SystemRoot\System32\drivers\dxg.sys
0xBA772000 \SystemRoot\System32\drivers\dxgthk.sys
0xBF012000 \SystemRoot\System32\ati2dvag.dll
0xBF05F000 \SystemRoot\System32\ati2cqag.dll
0xBF0DE000 \SystemRoot\System32\atikvmag.dll
0xBF14E000 \SystemRoot\System32\atiok3x2.dll
0xBF17C000 \SystemRoot\System32\ati3duag.dll
0xBF484000 \SystemRoot\System32\ativvaxx.dll
0xBFFA0000 \SystemRoot\System32\ATMFD.DLL
0xA3114000 \SystemRoot\System32\DRIVERS\ndisuio.sys
0x9EB4B000 \SystemRoot\System32\DRIVERS\mrxdav.sys
0x9EA92000 \SystemRoot\System32\Drivers\HTTP.sys
0x9E9C3000 \SystemRoot\System32\DRIVERS\srv.sys
0x9E978000 \SystemRoot\System32\Drivers\Fastfat.SYS
0x9E873000 \SystemRoot\system32\drivers\wdmaud.sys
0xBA1F8000 \SystemRoot\system32\drivers\sysaudio.sys
0x9E571000 \SystemRoot\System32\DRIVERS\asyncmac.sys
0x9D590000 \SystemRoot\system32\drivers\kmixer.sys
0x7C900000 \WINDOWS\system32\ntdll.dll
Processes (total 57):
0 System Idle Process
4 System
416 C:\WINDOWS\system32\smss.exe
464 csrss.exe
496 C:\WINDOWS\system32\winlogon.exe
544 C:\WINDOWS\system32\services.exe
556 C:\WINDOWS\system32\lsass.exe
712 C:\WINDOWS\system32\ati2evxx.exe
744 C:\WINDOWS\system32\svchost.exe
812 svchost.exe
884 C:\WINDOWS\system32\svchost.exe
928 C:\WINDOWS\system32\svchost.exe
1060 svchost.exe
1108 C:\WINDOWS\system32\ati2evxx.exe
1116 C:\Program Files\AVG\AVG9\avgchsvx.exe
1124 C:\Program Files\AVG\AVG9\avgrsx.exe
1260 C:\Program Files\AVG\AVG9\avgcsrvx.exe
1268 svchost.exe
1584 C:\WINDOWS\system32\spoolsv.exe
1808 svchost.exe
1840 C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
1856 C:\Program Files\Amazon\Amazon Unbox Video\ADVWindowsClientService.exe
1932 C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
1988 C:\Program Files\AVG\AVG9\avgwdsvc.exe
2020 C:\Program Files\Bonjour\mDNSResponder.exe
460 C:\WINDOWS\system32\svchost.exe
852 C:\Program Files\Common Files\LightScribe\LSSrvc.exe
668 C:\Program Files\AVG\AVG9\avgnsx.exe
2144 C:\Program Files\IDT\ECSXPV_5762_010208\WDM\stacsv.exe
2356 C:\WINDOWS\system32\svchost.exe
2404 C:\WINDOWS\system32\UAService7.exe
2456 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
2520 wmpnetwk.exe
2916 alg.exe
3276 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
2004 C:\WINDOWS\system32\wscntfy.exe
3996 C:\WINDOWS\explorer.exe
2912 C:\Program Files\IDT\WDM\sttray.exe
732 C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\HpqCmon.exe
3196 C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
3316 C:\PROGRA~1\AVG\AVG9\avgtray.exe
3376 C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
3368 C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
3388 C:\Program Files\DivX\DivX Update\DivXUpdate.exe
2924 C:\Program Files\iTunes\iTunesHelper.exe
2840 C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
3472 C:\Program Files\DNA\btdna.exe
3104 C:\Program Files\NBC Direct\DirectPlayerCore.exe
3440 C:\WINDOWS\system32\wuauclt.exe
3448 C:\Program Files\Windows Media Player\wmpnscfg.exe
3404 C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
4056 C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
948 C:\Program Files\iPod\bin\iPodService.exe
2992 C:\Program Files\Internet Explorer\iexplore.exe
3096 C:\Program Files\Internet Explorer\iexplore.exe
5892 C:\Program Files\Internet Explorer\iexplore.exe
2684 C:\Documents and Settings\Pam\Desktop\MBRCheck.exe
\\.\C: --> \\.\PhysicalDrive0 at offset 0x00000000`00007e00 (NTFS)
PhysicalDrive0 Model Number: ST3320620A, Rev: 3.AAE
Size Device Name MBR Status
--------------------------------------------Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org
Database version: 4437
Windows 5.1.2600 Service Pack 2
Internet Explorer 8.0.6001.18372
8/16/2010 4:55:04 PM
mbam-log-2010-08-16 (16-55-04).txt
Scan type: Quick scan
Objects scanned: 152612
Time elapsed: 6 minute(s), 38 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 3
Registry Values Infected: 0
Registry Data Items Infected: 1
Folders Infected: 4
Files Infected: 30
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{19090308-636d-4e9b-a1ce-a647b6f794bf} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{19090308-636d-4e9b-a1ce-a647b6f794bf} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Wireshark Antivirus (Rogue.WiresharkAntivirus) -> Quarantined and deleted successfully.
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell (Hijack.Shell) -> Bad: (C:\Documents and Settings\Pam\Application Data\PCenter\sp.exe) Good: (Explorer.exe) -> Quarantined and deleted successfully.
Folders Infected:
C:\Program Files\scdata (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\Program Files\scdata\images (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\Documents and Settings\LocalService\Start Menu\Programs\Wireshark Antivirus (Rogue.WiresharkAntivirus) -> Quarantined and deleted successfully.
C:\Documents and Settings\Pam\Start Menu\Programs\Wireshark Antivirus (Rogue.WiresharkAntivirus) -> Quarantined and deleted successfully.
Files Infected:
C:\Program Files\scdata\wispex.html (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\Program Files\scdata\wskinn.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\Program Files\scdata\images\i1.gif (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\Program Files\scdata\images\i2.gif (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\Program Files\scdata\images\i3.gif (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\Program Files\scdata\images\j1.gif (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\Program Files\scdata\images\j2.gif (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\Program Files\scdata\images\j3.gif (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\Program Files\scdata\images\jj1.gif (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\Program Files\scdata\images\jj2.gif (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\Program Files\scdata\images\jj3.gif (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\Program Files\scdata\images\l1.gif (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\Program Files\scdata\images\l2.gif (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\Program Files\scdata\images\l3.gif (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\Program Files\scdata\images\pix.gif (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\Program Files\scdata\images\t1.gif (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\Program Files\scdata\images\t2.gif (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\Program Files\scdata\images\Thumbs.db (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\Program Files\scdata\images\up1.gif (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\Program Files\scdata\images\up2.gif (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\Program Files\scdata\images\w1.gif (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\Program Files\scdata\images\w11.gif (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\Program Files\scdata\images\w2.gif (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\Program Files\scdata\images\w3.jpg (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\Program Files\scdata\images\word.doc (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\Program Files\scdata\images\wt1.gif (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\Program Files\scdata\images\wt2.gif (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\Program Files\scdata\images\wt3.gif (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\Documents and Settings\LocalService\Start Menu\Programs\Wireshark Antivirus\Wireshark Antivirus.lnk (Rogue.WiresharkAntivirus) -> Quarantined and deleted successfully.
C:\Documents and Settings\Pam\Start Menu\Programs\Wireshark Antivirus\Wireshark Antivirus.lnk (Rogue.WiresharkAntivirus) -> Quarantined and deleted successfully.
298 GB \\.\PhysicalDrive0 Windows XP MBR code detected
SHA1: DA38B874B7713D1B51CBC449F4EF809B0DEC644A
Last edited by timmyb74; August 16th, 2010 at 10:25 PM .
Reason: Added information
Windows 7 Ultimate, Service Pack 1
AMD FX-4170 Quad-Core Processor 4.2 Ghz
8.0 GB RAM
64-bit Operating System
August 16th, 2010, 10:24 PM
#44
Looks good
MBAM please....
August 16th, 2010, 10:27 PM
#45
I added it to my previous post
Windows 7 Ultimate, Service Pack 1
AMD FX-4170 Quad-Core Processor 4.2 Ghz
8.0 GB RAM
64-bit Operating System
Thread Information
Users Browsing this Thread
There are currently 1 users browsing this thread. (0 members and 1 guests)
Posting Permissions
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
Forum Rules