I accidently downloaded False security spyware "Windows 7 Recovery". Immediately afterwards, all icons on the desktop disappeared, could not access any programs or files. Could not see transfered files/folders on the desktop. Ran rkill, then malwarebytes, then superantispyware free (in safe mode), then gmer. Many files were found, quarantined, and removed. However, still no files, programs on desktop or in start-up menu. In Firefox does not open pages to appropriate link. please help. thanks in advance.
Below are the available logs in order - Malwarebytes, Super antispyware free; the gmer log is incomplete, as it was too long to post the entire log when I tried, but the log appeared to have thousands of files listed, that appear to possibly be a bunch of normal files and programs.
thanks again
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org
Database version: 6688
Windows 6.1.7600
Internet Explorer 8.0.7600.16385
5/26/2011 8:15:01 PM
mbam-log-2011-05-26 (20-15-01).txt
Scan type: Full scan (C:\|D:\|E:\|F:\|Q:\|)
Objects scanned: 282629
Time elapsed: 45 minute(s), 29 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 6
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\gODYLqGmtHs (Trojan.FakeMS) -> Value: gODYLqGmtHs -> Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
c:\programdata\godylqgmths.exe (Trojan.FakeMS) -> Quarantined and deleted successfully.
c:\programdata\39116536.exe (Rogue.FakeHDD) -> Quarantined and deleted successfully.
c:\Users\Krina\AppData\Local\Temp\adobe_flash_player.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\Krina\AppData\Local\Temp\ldrf9d5.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\Krina\AppData\Local\Temp\tmpF9C6.tmp (Trojan.FakeMS) -> Quarantined and deleted successfully.
c:\Users\Krina\Desktop\virus cure\rkill.com (Trojan.BankerBot.Gen) -> Quarantined and deleted successfully.
SUPERAntiSpyware Scan Log
http://www.superantispyware.com
Generated 05/26/2011 at 09:23 PM
Application Version : 4.52.1000
Core Rules Database Version : 7151
Trace Rules Database Version: 4963
Scan type : Complete Scan
Total Scan Time : 00:52:13
Memory items scanned : 334
Memory threats detected : 0
Registry items scanned : 11881
Registry threats detected : 0
File items scanned : 134635
File threats detected : 116
Adware.Tracking Cookie
C:\Users\Krina\AppData\Roaming\Microsoft\Windows\Cookies\krina@msnportal.112.2o7[1].txt
C:\Users\Krina\AppData\Roaming\Microsoft\Windows\Cookies\krina@atdmt[2].txt
C:\Users\Krina\AppData\Roaming\Microsoft\Windows\Cookies\krina@insightexpressai[1].txt
a.ads2.msads.net [ C:\Users\Krina\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\2Y8QRY2D ]
ia.media-imdb.com [ C:\Users\Krina\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\2Y8QRY2D ]
media.mtvnservices.com [ C:\Users\Krina\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\2Y8QRY2D ]
msnbcmedia.msn.com [ C:\Users\Krina\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\2Y8QRY2D ]
s0.2mdn.net [ C:\Users\Krina\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\2Y8QRY2D ]
C:\Users\Krina\AppData\Roaming\Microsoft\Windows\Cookies\Low\krina@2o7[2].txt
C:\Users\Krina\AppData\Roaming\Microsoft\Windows\Cookies\Low\krina@a.intentmedia[2].txt
C:\Users\Krina\AppData\Roaming\Microsoft\Windows\Cookies\Low\krina@a1.interclick[2].txt
C:\Users\Krina\AppData\Roaming\Microsoft\Windows\Cookies\Low\krina@ad.crwdcntrl[1].txt
C:\Users\Krina\AppData\Roaming\Microsoft\Windows\Cookies\Low\krina@ad.wsod[2].txt
C:\Users\Krina\AppData\Roaming\Microsoft\Windows\Cookies\Low\krina@ad.yieldmanager[1].txt
C:\Users\Krina\AppData\Roaming\Microsoft\Windows\Cookies\Low\krina@ad.yieldmanager[3].txt
C:\Users\Krina\AppData\Roaming\Microsoft\Windows\Cookies\Low\krina@adbrite[1].txt
C:\Users\Krina\AppData\Roaming\Microsoft\Windows\Cookies\Low\krina@adecn[1].txt
C:\Users\Krina\AppData\Roaming\Microsoft\Windows\Cookies\Low\krina@adinterax[1].txt
C:\Users\Krina\AppData\Roaming\Microsoft\Windows\Cookies\Low\krina@adinterax[2].txt
C:\Users\Krina\AppData\Roaming\Microsoft\Windows\Cookies\Low\krina@adinterax[3].txt
C:\Users\Krina\AppData\Roaming\Microsoft\Windows\Cookies\Low\krina@ads.pointroll[1].txt
C:\Users\Krina\AppData\Roaming\Microsoft\Windows\Cookies\Low\krina@ads.undertone[2].txt
C:\Users\Krina\AppData\Roaming\Microsoft\Windows\Cookies\Low\krina@adserver.adreactor[1].txt
C:\Users\Krina\AppData\Roaming\Microsoft\Windows\Cookies\Low\krina@adserver.adtechus[2].txt
C:\Users\Krina\AppData\Roaming\Microsoft\Windows\Cookies\Low\krina@advertising[1].txt
C:\Users\Krina\AppData\Roaming\Microsoft\Windows\Cookies\Low\krina@advertising[2].txt
C:\Users\Krina\AppData\Roaming\Microsoft\Windows\Cookies\Low\krina@adxpose[1].txt
C:\Users\Krina\AppData\Roaming\Microsoft\Windows\Cookies\Low\krina@apmebf[2].txt
C:\Users\Krina\AppData\Roaming\Microsoft\Windows\Cookies\Low\krina@apmebf[3].txt
C:\Users\Krina\AppData\Roaming\Microsoft\Windows\Cookies\Low\krina@ar.atwola[1].txt
C:\Users\Krina\AppData\Roaming\Microsoft\Windows\Cookies\Low\krina@atdmt[1].txt
C:\Users\Krina\AppData\Roaming\Microsoft\Windows\Cookies\Low\krina@atdmt[3].txt
C:\Users\Krina\AppData\Roaming\Microsoft\Windows\Cookies\Low\krina@beacon.dmsinsights[2].txt
C:\Users\Krina\AppData\Roaming\Microsoft\Windows\Cookies\Low\krina@bizrate[2].txt
C:\Users\Krina\AppData\Roaming\Microsoft\Windows\Cookies\Low\krina@casalemedia[2].txt
C:\Users\Krina\AppData\Roaming\Microsoft\Windows\Cookies\Low\krina@clickfuse[1].txt
C:\Users\Krina\AppData\Roaming\Microsoft\Windows\Cookies\Low\krina@collective-media[1].txt
C:\Users\Krina\AppData\Roaming\Microsoft\Windows\Cookies\Low\krina@content.yieldmanager[1].txt
C:\Users\Krina\AppData\Roaming\Microsoft\Windows\Cookies\Low\krina@content.yieldmanager[2].txt
C:\Users\Krina\AppData\Roaming\Microsoft\Windows\Cookies\Low\krina@content.yieldmanager[5].txt
C:\Users\Krina\AppData\Roaming\Microsoft\Windows\Cookies\Low\krina@data.coremetrics[1].txt
C:\Users\Krina\AppData\Roaming\Microsoft\Windows\Cookies\Low\krina@dealtime[1].txt
C:\Users\Krina\AppData\Roaming\Microsoft\Windows\Cookies\Low\krina@dmtracker[1].txt
C:\Users\Krina\AppData\Roaming\Microsoft\Windows\Cookies\Low\krina@dmtracker[2].txt
C:\Users\Krina\AppData\Roaming\Microsoft\Windows\Cookies\Low\krina@doubleclick[1].txt
C:\Users\Krina\AppData\Roaming\Microsoft\Windows\Cookies\Low\krina@e-2dj6walisjcpwkp.stats.esomniture[1].txt
C:\Users\Krina\AppData\Roaming\Microsoft\Windows\Cookies\Low\krina@e-2dj6wck4ugd5abq.stats.esomniture[1].txt
C:\Users\Krina\AppData\Roaming\Microsoft\Windows\Cookies\Low\krina@e-2dj6wclycgazeaq.stats.esomniture[2].txt
C:\Users\Krina\AppData\Roaming\Microsoft\Windows\Cookies\Low\krina@e-2dj6wfmysocjklo.stats.esomniture[2].txt
C:\Users\Krina\AppData\Roaming\Microsoft\Windows\Cookies\Low\krina@fastclick[1].txt
C:\Users\Krina\AppData\Roaming\Microsoft\Windows\Cookies\Low\krina@fastclick[2].txt
C:\Users\Krina\AppData\Roaming\Microsoft\Windows\Cookies\Low\krina@imrworldwide[2].txt
C:\Users\Krina\AppData\Roaming\Microsoft\Windows\Cookies\Low\krina@in.getclicky[1].txt
C:\Users\Krina\AppData\Roaming\Microsoft\Windows\Cookies\Low\krina@insightexpressai[2].txt
C:\Users\Krina\AppData\Roaming\Microsoft\Windows\Cookies\Low\krina@interclick[1].txt
C:\Users\Krina\AppData\Roaming\Microsoft\Windows\Cookies\Low\krina@invitemedia[1].txt
C:\Users\Krina\AppData\Roaming\Microsoft\Windows\Cookies\Low\krina@invitemedia[3].txt
C:\Users\Krina\AppData\Roaming\Microsoft\Windows\Cookies\Low\krina@jobinterviewquestions[1].txt
C:\Users\Krina\AppData\Roaming\Microsoft\Windows\Cookies\Low\krina@kontera[2].txt
C:\Users\Krina\AppData\Roaming\Microsoft\Windows\Cookies\Low\krina@lfstmedia[2].txt
C:\Users\Krina\AppData\Roaming\Microsoft\Windows\Cookies\Low\krina@limaconsulting.112.2o7[1].txt
C:\Users\Krina\AppData\Roaming\Microsoft\Windows\Cookies\Low\krina@linksynergy.walmart[2].txt
C:\Users\Krina\AppData\Roaming\Microsoft\Windows\Cookies\Low\krina@liveperson[1].txt
C:\Users\Krina\AppData\Roaming\Microsoft\Windows\Cookies\Low\krina@liveperson[2].txt
C:\Users\Krina\AppData\Roaming\Microsoft\Windows\Cookies\Low\krina@liveperson[3].txt
C:\Users\Krina\AppData\Roaming\Microsoft\Windows\Cookies\Low\krina@liveperson[4].txt
C:\Users\Krina\AppData\Roaming\Microsoft\Windows\Cookies\Low\krina@liveperson[5].txt
C:\Users\Krina\AppData\Roaming\Microsoft\Windows\Cookies\Low\krina@liveperson[6].txt
C:\Users\Krina\AppData\Roaming\Microsoft\Windows\Cookies\Low\krina@liveperson[8].txt
C:\Users\Krina\AppData\Roaming\Microsoft\Windows\Cookies\Low\krina@liveperson[9].txt
C:\Users\Krina\AppData\Roaming\Microsoft\Windows\Cookies\Low\krina@lucidmedia[1].txt
C:\Users\Krina\AppData\Roaming\Microsoft\Windows\Cookies\Low\krina@media.adfrontiers[1].txt
C:\Users\Krina\AppData\Roaming\Microsoft\Windows\Cookies\Low\krina@media6degrees[1].txt
C:\Users\Krina\AppData\Roaming\Microsoft\Windows\Cookies\Low\krina@mediabrandsww[2].txt
C:\Users\Krina\AppData\Roaming\Microsoft\Windows\Cookies\Low\krina@mediaplex[1].txt
C:\Users\Krina\AppData\Roaming\Microsoft\Windows\Cookies\Low\krina@mediaplex[3].txt
C:\Users\Krina\AppData\Roaming\Microsoft\Windows\Cookies\Low\krina@mediaplex[4].txt
C:\Users\Krina\AppData\Roaming\Microsoft\Windows\Cookies\Low\krina@mm.chitika[1].txt
C:\Users\Krina\AppData\Roaming\Microsoft\Windows\Cookies\Low\krina@myaccount.mudomaha[2].txt
C:\Users\Krina\AppData\Roaming\Microsoft\Windows\Cookies\Low\krina@overture[1].txt
C:\Users\Krina\AppData\Roaming\Microsoft\Windows\Cookies\Low\krina@paypal.112.2o7[1].txt
C:\Users\Krina\AppData\Roaming\Microsoft\Windows\Cookies\Low\krina@petfinder[2].txt
C:\Users\Krina\AppData\Roaming\Microsoft\Windows\Cookies\Low\krina@pointroll[2].txt
C:\Users\Krina\AppData\Roaming\Microsoft\Windows\Cookies\Low\krina@pro-market[2].txt
C:\Users\Krina\AppData\Roaming\Microsoft\Windows\Cookies\Low\krina@pro-market[3].txt
C:\Users\Krina\AppData\Roaming\Microsoft\Windows\Cookies\Low\krina@questionmarket[2].txt
C:\Users\Krina\AppData\Roaming\Microsoft\Windows\Cookies\Low\krina@questionmarket[3].txt
C:\Users\Krina\AppData\Roaming\Microsoft\Windows\Cookies\Low\krina@r1-ads.ace.advertising[2].txt
C:\Users\Krina\AppData\Roaming\Microsoft\Windows\Cookies\Low\krina@rcci.122.2o7[1].txt
C:\Users\Krina\AppData\Roaming\Microsoft\Windows\Cookies\Low\krina@realmedia[1].txt
C:\Users\Krina\AppData\Roaming\Microsoft\Windows\Cookies\Low\krina@revsci[1].txt
C:\Users\Krina\AppData\Roaming\Microsoft\Windows\Cookies\Low\krina@ru4[1].txt
C:\Users\Krina\AppData\Roaming\Microsoft\Windows\Cookies\Low\krina@ru4[3].txt
C:\Users\Krina\AppData\Roaming\Microsoft\Windows\Cookies\Low\krina@samsclub.112.2o7[1].txt
C:\Users\Krina\AppData\Roaming\Microsoft\Windows\Cookies\Low\krina@serving-sys[1].txt
C:\Users\Krina\AppData\Roaming\Microsoft\Windows\Cookies\Low\krina@serving-sys[2].txt
C:\Users\Krina\AppData\Roaming\Microsoft\Windows\Cookies\Low\krina@serving-sys[3].txt
C:\Users\Krina\AppData\Roaming\Microsoft\Windows\Cookies\Low\krina@specificclick[1].txt
C:\Users\Krina\AppData\Roaming\Microsoft\Windows\Cookies\Low\krina@specificclick[2].txt
C:\Users\Krina\AppData\Roaming\Microsoft\Windows\Cookies\Low\krina@specificmedia[2].txt
C:\Users\Krina\AppData\Roaming\Microsoft\Windows\Cookies\Low\krina@stampscom.112.2o7[1].txt
C:\Users\Krina\AppData\Roaming\Microsoft\Windows\Cookies\Low\krina@stat.dealtime[1].txt
C:\Users\Krina\AppData\Roaming\Microsoft\Windows\Cookies\Low\krina@stats.exph.net.re.getclicky[1].txt
C:\Users\Krina\AppData\Roaming\Microsoft\Windows\Cookies\Low\krina@statse.webtrendslive[2].txt
C:\Users\Krina\AppData\Roaming\Microsoft\Windows\Cookies\Low\krina@tacoda.at.atwola[1].txt
C:\Users\Krina\AppData\Roaming\Microsoft\Windows\Cookies\Low\krina@tacoda.at.atwola[2].txt
C:\Users\Krina\AppData\Roaming\Microsoft\Windows\Cookies\Low\krina@tacoda.at.atwola[4].txt
C:\Users\Krina\AppData\Roaming\Microsoft\Windows\Cookies\Low\krina@trafficmp[1].txt
C:\Users\Krina\AppData\Roaming\Microsoft\Windows\Cookies\Low\krina@traveladvertising[1].txt
C:\Users\Krina\AppData\Roaming\Microsoft\Windows\Cookies\Low\krina@tribalfusion[1].txt
C:\Users\Krina\AppData\Roaming\Microsoft\Windows\Cookies\Low\krina@user.lucidmedia[1].txt
C:\Users\Krina\AppData\Roaming\Microsoft\Windows\Cookies\Low\krina@walmart.112.2o7[1].txt
C:\Users\Krina\AppData\Roaming\Microsoft\Windows\Cookies\Low\krina@www.burstnet[1].txt
C:\Users\Krina\AppData\Roaming\Microsoft\Windows\Cookies\Low\krina@yieldmanager[1].txt
C:\Users\Krina\AppData\Roaming\Microsoft\Windows\Cookies\Low\krina@zedo[1].txt
C:\Users\Krina\AppData\Roaming\Microsoft\Windows\Cookies\Low\krina@zedo[2].txt
GMER 1.0.15.15627 - http://www.gmer.net
Rootkit scan 2011-05-26 22:37:18
Windows 6.1.7600
Running: c535mv8u.exe
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\002269ec2d88
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\70f3953e5c87
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\002269ec2d88 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\70f3953e5c87 (not active ControlSet)
---- Files - GMER 1.0.15 ----
File Q:\$RECYCLE.BIN 0 bytes
File Q:\$RECYCLE.BIN\S-1-5-21-2833784658-2284975252-4144577734-1000 0 bytes
File Q:\$RECYCLE.BIN\S-1-5-21-2833784658-2284975252-4144577734-1000\desktop.ini 129 bytes
File Q:\$RECYCLE.BIN\S-1-5-21-2833784658-2284975252-4144577734-500 0 bytes
File Q:\$RECYCLE.BIN\S-1-5-21-2833784658-2284975252-4144577734-500\desktop.ini 129 bytes
File Q:\drivers 0 bytes
File Q:\drivers\AHCI 0 bytes
File Q:\drivers\AHCI\data1.cab 2183918 bytes
File Q:\drivers\AHCI\data1.hdr 54802 bytes
File Q:\drivers\AHCI\data2.cab 7370673 bytes
File Q:\drivers\AHCI\ISSetup.dll 552214 bytes executable
File Q:\drivers\AHCI\layout.bin 473 bytes
File Q:\drivers\AHCI\setup.exe 455600 bytes
File Q:\drivers\AHCI\setup.ini 781 bytes


Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.
Back to top








