Welcome Guest ( Log In | Click here to Register a free account now! )
Welcome to Bleeping Computer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.When posting your problem, do not run and post a ComboFix logs. ComboFix is a tool that should only be run under the supervision of someone who has been trained in its use. Using it on your own can cause problems with your computer. Any posts containing CF Logs will be ignored.
To receive help, you should instead provide a detailed description of your problem, detailed word-for-word error messages that you are receiving, screenshots of strange behaviour, and your operating system. This information is much more useful to our helpers than a ComboFix log.
![]() ![]() |
Oct 17 2009, 10:23 AM
Post
#1
|
|
|
Member ![]() ![]() Group: Members Posts: 94 Joined: 10-July 08 From: Nevada Member No.: 221,655 |
OS is Microsoft XP Home Edition I am very frustrated right now. Please help me..... Kelly |
|
|
|
Oct 17 2009, 11:26 AM
Post
#2
|
|
![]() BC 1st Responder ![]() ![]() ![]() ![]() ![]() ![]() Group: Global Moderator Posts: 10,730 Joined: 21-October 04 From: South Carolina - USA Member No.: 3,905 |
HI Kelly and welcome to BC.
Let's try a program in safe mode. Please download ATF Cleaner by Atribune & save it to your desktop. alternate download link DO NOT use yet. Please download and install SUPERAntiSpyware Free
Double-click ATF-Cleaner.exe to run the program.
ATF-Cleaner must be "Run as an Administrator". Scan with SUPERAntiSpyware as follows:
-------------------- "In a world where you can be anything, be yourself." ~ unknown ![]() Become a BleepingComputer fan: Facebook |
|
|
|
Oct 18 2009, 09:48 AM
Post
#3
|
|
|
Member ![]() ![]() Group: Members Posts: 94 Joined: 10-July 08 From: Nevada Member No.: 221,655 |
Here is the log from the scan
SUPERAntiSpyware Scan Log http://www.superantispyware.com Generated 10/18/2009 at 03:41 AM Application Version : 4.29.1004 Core Rules Database Version : 4171 Trace Rules Database Version: 2093 Scan type : Complete Scan Total Scan Time : 04:43:46 Memory items scanned : 204 Memory threats detected : 0 Registry items scanned : 5198 Registry threats detected : 9 File items scanned : 100143 File threats detected : 44 Adware.Gamevance [Gamevance] C:\PROGRAM FILES\GAMEVANCE\GAMEVANCE32.EXE C:\PROGRAM FILES\GAMEVANCE\GAMEVANCE32.EXE HKLM\Software\Classes\CLSID\{0ED403E8-470A-4a8a-85A4-D7688CFE39A3} HKCR\CLSID\{0ED403E8-470A-4A8A-85A4-D7688CFE39A3} HKCR\CLSID\{0ED403E8-470A-4A8A-85A4-D7688CFE39A3} HKCR\CLSID\{0ED403E8-470A-4A8A-85A4-D7688CFE39A3}\InprocServer32 HKCR\CLSID\{0ED403E8-470A-4A8A-85A4-D7688CFE39A3}\InprocServer32#ThreadingModel C:\PROGRAM FILES\GAMEVANCE\GAMEVANCELIB32.DLL HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0ED403E8-470A-4a8a-85A4-D7688CFE39A3} HKU\S-1-5-21-4194836640-1754454779-3683679437-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0ED403E8-470A-4A8A-85A4-D7688CFE39A3} C:\Program Files\Gamevance\ars.cfg C:\Program Files\Gamevance\gvtl.dll C:\Program Files\Gamevance\icon.ico C:\Program Files\Gamevance HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run#Gamevance [ C:\Program Files\Gamevance\gamevance32.exe a ] Adware.Tracking Cookie C:\Documents and Settings\Owner\Cookies\owner@advertising[2].txt C:\Documents and Settings\Owner\Cookies\owner@atdmt[2].txt C:\Documents and Settings\Owner\Cookies\owner@doubleclick[1].txt .insightexpressai.com [ C:\Documents and Settings\Clay\Application Data\Mozilla\Firefox\Profiles\n7pbv6q0.default\cookies.txt ] .stats.crayola.com [ C:\Documents and Settings\Clay\Application Data\Mozilla\Firefox\Profiles\n7pbv6q0.default\cookies.txt ] .adopt.specificclick.net [ C:\Documents and Settings\Clay\Application Data\Mozilla\Firefox\Profiles\n7pbv6q0.default\cookies.txt ] .adopt.specificclick.net [ C:\Documents and Settings\Clay\Application Data\Mozilla\Firefox\Profiles\n7pbv6q0.default\cookies.txt ] .gamefinder.disney.go.com [ C:\Documents and Settings\Clay\Application Data\Mozilla\Firefox\Profiles\n7pbv6q0.default\cookies.txt ] .roiservice.com [ C:\Documents and Settings\Clay\Application Data\Mozilla\Firefox\Profiles\n7pbv6q0.default\cookies.txt ] .adlegend.com [ C:\Documents and Settings\Clay\Application Data\Mozilla\Firefox\Profiles\n7pbv6q0.default\cookies.txt ] .adecn.com [ C:\Documents and Settings\Clay\Application Data\Mozilla\Firefox\Profiles\n7pbv6q0.default\cookies.txt ] .account.toontown.com [ C:\Documents and Settings\Clay\Application Data\Mozilla\Firefox\Profiles\n7pbv6q0.default\cookies.txt ] .imrworldwide.com [ C:\Documents and Settings\Clay\Application Data\Mozilla\Firefox\Profiles\n7pbv6q0.default\cookies.txt ] .imrworldwide.com [ C:\Documents and Settings\Clay\Application Data\Mozilla\Firefox\Profiles\n7pbv6q0.default\cookies.txt ] .specificclick.net [ C:\Documents and Settings\Clay\Application Data\Mozilla\Firefox\Profiles\n7pbv6q0.default\cookies.txt ] .specificclick.net [ C:\Documents and Settings\Clay\Application Data\Mozilla\Firefox\Profiles\n7pbv6q0.default\cookies.txt ] .specificclick.net [ C:\Documents and Settings\Clay\Application Data\Mozilla\Firefox\Profiles\n7pbv6q0.default\cookies.txt ] .specificclick.net [ C:\Documents and Settings\Clay\Application Data\Mozilla\Firefox\Profiles\n7pbv6q0.default\cookies.txt ] .specificclick.net [ C:\Documents and Settings\Clay\Application Data\Mozilla\Firefox\Profiles\n7pbv6q0.default\cookies.txt ] .specificclick.net [ C:\Documents and Settings\Clay\Application Data\Mozilla\Firefox\Profiles\n7pbv6q0.default\cookies.txt ] .ads.gamesbannernet.com [ C:\Documents and Settings\Clay\Application Data\Mozilla\Firefox\Profiles\n7pbv6q0.default\cookies.txt ] .ads.gamesbannernet.com [ C:\Documents and Settings\Clay\Application Data\Mozilla\Firefox\Profiles\n7pbv6q0.default\cookies.txt ] .insightexpressai.com [ C:\Documents and Settings\Clay\Application Data\Mozilla\Firefox\Profiles\n7pbv6q0.default\cookies.txt ] .insightexpressai.com [ C:\Documents and Settings\Clay\Application Data\Mozilla\Firefox\Profiles\n7pbv6q0.default\cookies.txt ] .insightexpressai.com [ C:\Documents and Settings\Clay\Application Data\Mozilla\Firefox\Profiles\n7pbv6q0.default\cookies.txt ] .insightexpressai.com [ C:\Documents and Settings\Clay\Application Data\Mozilla\Firefox\Profiles\n7pbv6q0.default\cookies.txt ] .insightexpressai.com [ C:\Documents and Settings\Clay\Application Data\Mozilla\Firefox\Profiles\n7pbv6q0.default\cookies.txt ] .insightexpressai.com [ C:\Documents and Settings\Clay\Application Data\Mozilla\Firefox\Profiles\n7pbv6q0.default\cookies.txt ] .insightexpressai.com [ C:\Documents and Settings\Clay\Application Data\Mozilla\Firefox\Profiles\n7pbv6q0.default\cookies.txt ] .insightexpressai.com [ C:\Documents and Settings\Clay\Application Data\Mozilla\Firefox\Profiles\n7pbv6q0.default\cookies.txt ] .insightexpressai.com [ C:\Documents and Settings\Clay\Application Data\Mozilla\Firefox\Profiles\n7pbv6q0.default\cookies.txt ] .insightexpressai.com [ C:\Documents and Settings\Clay\Application Data\Mozilla\Firefox\Profiles\n7pbv6q0.default\cookies.txt ] .insightexpressai.com [ C:\Documents and Settings\Clay\Application Data\Mozilla\Firefox\Profiles\n7pbv6q0.default\cookies.txt ] .insightexpressai.com [ C:\Documents and Settings\Clay\Application Data\Mozilla\Firefox\Profiles\n7pbv6q0.default\cookies.txt ] .insightexpressai.com [ C:\Documents and Settings\Clay\Application Data\Mozilla\Firefox\Profiles\n7pbv6q0.default\cookies.txt ] .insightexpressai.com [ C:\Documents and Settings\Clay\Application Data\Mozilla\Firefox\Profiles\n7pbv6q0.default\cookies.txt ] Adware.MyWebSearch/FunWebProducts C:\PROGRAM FILES\WINDOWS LIVE\MESSENGER\MSIMG32.DLL C:\QOOBOX\QUARANTINE\C\PROGRAM FILES\INTERNET EXPLORER\MSIMG32.DLL.VIR |
|
|
|
Oct 19 2009, 05:29 PM
Post
#4
|
|
![]() BC 1st Responder ![]() ![]() ![]() ![]() ![]() ![]() Group: Global Moderator Posts: 10,730 Joined: 21-October 04 From: South Carolina - USA Member No.: 3,905 |
I'd like us to scan your machine with ESET OnlineScan
-------------------- "In a world where you can be anything, be yourself." ~ unknown ![]() Become a BleepingComputer fan: Facebook |
|
|
|
Oct 19 2009, 07:14 PM
Post
#5
|
|
|
Member ![]() ![]() Group: Members Posts: 94 Joined: 10-July 08 From: Nevada Member No.: 221,655 |
C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\AutoPlay.exe Win32/Agent.NVP trojan
C:\Documents and Settings\Administrator.BUBBLES\Start Menu\Programs\Startup\AutoPlay.exe Win32/Agent.NVP trojan |
|
|
|
Oct 21 2009, 06:37 AM
Post
#6
|
|
![]() BC 1st Responder ![]() ![]() ![]() ![]() ![]() ![]() Group: Global Moderator Posts: 10,730 Joined: 21-October 04 From: South Carolina - USA Member No.: 3,905 |
Please download Malwarebytes Anti-Malware and save it to your desktop.
alternate download link 1 alternate download link 2
-- If MBAM encounters a file that is difficult to remove, you may be asked to reboot your computer so it can proceed with the disinfection process. Regardless if prompted to restart the computer or not, please do so immediately. Failure to reboot normally (not into safe mode) will prevent MBAM from removing all the malware. Note 2: -- MBAM may make changes to your registry as part of its disinfection routine. If you're using other security programs that detect registry changes (like Spybot's Teatimer), they may interfere with the fix or alert you after scanning with MBAM. Please disable such programs until disinfection is complete or permit them to allow the changes. To disable these programs, please view this topic: How To Temporarily Disable Your Anti-virus, Firewall And Anti-malware Programs -------------------- "In a world where you can be anything, be yourself." ~ unknown ![]() Become a BleepingComputer fan: Facebook |
|
|
|
Oct 21 2009, 04:57 PM
Post
#7
|
|
|
Member ![]() ![]() Group: Members Posts: 94 Joined: 10-July 08 From: Nevada Member No.: 221,655 |
Here is the log from the scan...
Malwarebytes' Anti-Malware 1.41 Database version: 3005 Windows 5.1.2600 Service Pack 3 10/21/2009 11:44:44 AM mbam-log-2009-10-21 (11-44-44).txt Scan type: Full Scan (A:\|C:\|D:\|E:\|G:\|) Objects scanned: 255079 Time elapsed: 2 hour(s), 54 minute(s), 13 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 1 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Also, when I start up my computer I get a message... lxddamon.exe- .NET Framework Initialization Error Please set regestry key HKLM\Software\Microsoft\.NETFramework\InstallRoot to point to the .NET Framework install location |
|
|
|
Nov 4 2009, 12:54 AM
Post
#8
|
|
|
Member ![]() ![]() Group: Members Posts: 94 Joined: 10-July 08 From: Nevada Member No.: 221,655 |
Hello.... is anybody out there! my computer is still acting wierd. It has many broken internet connections and I belive there are a few viruses on it. The pointer is still moving on its own and it is really bogged down and slow. Please help.
|
|
|
|
Nov 4 2009, 08:27 AM
Post
#9
|
|
![]() BC 1st Responder ![]() ![]() ![]() ![]() ![]() ![]() Group: Global Moderator Posts: 10,730 Joined: 21-October 04 From: South Carolina - USA Member No.: 3,905 |
Sorry about that..
alternate download link
Link #1
Scan with SUPERAntiSpyware as follows:
-------------------- "In a world where you can be anything, be yourself." ~ unknown ![]() Become a BleepingComputer fan: Facebook |
|
|
|
Nov 4 2009, 04:56 PM
Post
#10
|
|
|
Member ![]() ![]() Group: Members Posts: 94 Joined: 10-July 08 From: Nevada Member No.: 221,655 |
Here is the malwarebytes log....
Time elapsed: 2 hour(s), 12 minute(s), 9 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 3 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CLASSES_ROOT\CLSID\{0ed403e8-470a-4a8a-85a4-d7688cfe39a3} (Adware.Gamevance) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\gvtl (Malware.Trace) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Gamevance (Adware.Gamevance) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) |
|
|
|
Nov 4 2009, 07:19 PM
Post
#11
|
|
![]() BC 1st Responder ![]() ![]() ![]() ![]() ![]() ![]() Group: Global Moderator Posts: 10,730 Joined: 21-October 04 From: South Carolina - USA Member No.: 3,905 |
Good, it cleaned a few registry keys. Let's get a look at the SAS log and we can go from there...
Also let's make sure we don't have a rootkit lurking. Please download gmer.zip and save to your desktop.
-------------------- "In a world where you can be anything, be yourself." ~ unknown ![]() Become a BleepingComputer fan: Facebook |
|
|
|
Nov 5 2009, 10:01 AM
Post
#12
|
|
|
Member ![]() ![]() Group: Members Posts: 94 Joined: 10-July 08 From: Nevada Member No.: 221,655 |
SAS log...
SUPERAntiSpyware Scan Log http://www.superantispyware.com Generated 11/05/2009 at 03:39 AM Application Version : 4.29.1004 Core Rules Database Version : 4232 Trace Rules Database Version: 2129 Scan type : Complete Scan Total Scan Time : 05:08:05 Memory items scanned : 248 Memory threats detected : 0 Registry items scanned : 5220 Registry threats detected : 0 File items scanned : 104158 File threats detected : 50 Adware.Tracking Cookie C:\Documents and Settings\Owner\Cookies\owner@iacas.adbureau[2].txt C:\Documents and Settings\Owner\Cookies\owner@cdn4.specificclick[1].txt C:\Documents and Settings\Owner\Cookies\owner@content.yieldmanager[2].txt C:\Documents and Settings\Owner\Cookies\owner@advertising[2].txt C:\Documents and Settings\Owner\Cookies\owner@myxer.adbureau[1].txt C:\Documents and Settings\Owner\Cookies\owner@oasn04.247realmedia[1].txt C:\Documents and Settings\Owner\Cookies\owner@imrworldwide[2].txt C:\Documents and Settings\Owner\Cookies\owner@247realmedia[1].txt C:\Documents and Settings\Owner\Cookies\owner@azjmp[1].txt C:\Documents and Settings\Owner\Cookies\owner@bs.serving-sys[2].txt C:\Documents and Settings\Owner\Cookies\owner@kontera[2].txt C:\Documents and Settings\Owner\Cookies\owner@lfstmedia[1].txt C:\Documents and Settings\Owner\Cookies\owner@ads.undertone[2].txt C:\Documents and Settings\Owner\Cookies\owner@questionmarket[1].txt C:\Documents and Settings\Owner\Cookies\owner@media6degrees[1].txt C:\Documents and Settings\Owner\Cookies\owner@realmedia[1].txt C:\Documents and Settings\Owner\Cookies\owner@tacoda[2].txt C:\Documents and Settings\Owner\Cookies\owner@tribalfusion[1].txt C:\Documents and Settings\Owner\Cookies\owner@2o7[1].txt C:\Documents and Settings\Owner\Cookies\owner@specificclick[1].txt C:\Documents and Settings\Owner\Cookies\owner@zedo[2].txt C:\Documents and Settings\Owner\Cookies\owner@apmebf[2].txt C:\Documents and Settings\Owner\Cookies\owner@fastclick[2].txt C:\Documents and Settings\Owner\Cookies\owner@adserver.adtechus[1].txt C:\Documents and Settings\Owner\Cookies\owner@interclick[1].txt C:\Documents and Settings\Owner\Cookies\owner@a1.interclick[1].txt C:\Documents and Settings\Owner\Cookies\owner@revsci[1].txt C:\Documents and Settings\Owner\Cookies\owner@at.atwola[2].txt C:\Documents and Settings\Owner\Cookies\owner@atdmt[1].txt C:\Documents and Settings\Owner\Cookies\owner@collective-media[1].txt C:\Documents and Settings\Owner\Cookies\owner@pointroll[1].txt C:\Documents and Settings\Owner\Cookies\owner@ads.bridgetrack[2].txt C:\Documents and Settings\Owner\Cookies\owner@content.yieldmanager[3].txt C:\Documents and Settings\Owner\Cookies\owner@insightexpressai[2].txt C:\Documents and Settings\Owner\Cookies\owner@adinterax[2].txt C:\Documents and Settings\Owner\Cookies\owner@viacom.adbureau[2].txt C:\Documents and Settings\Owner\Cookies\owner@specificmedia[2].txt C:\Documents and Settings\Owner\Cookies\owner@network.realmedia[1].txt C:\Documents and Settings\Owner\Cookies\owner@trafficmp[2].txt C:\Documents and Settings\Owner\Cookies\owner@lsftmedia[2].txt C:\Documents and Settings\Owner\Cookies\owner@ads.pointroll[2].txt C:\Documents and Settings\Owner\Cookies\owner@mediaplex[1].txt C:\Documents and Settings\Owner\Cookies\owner@casalemedia[2].txt C:\Documents and Settings\Owner\Cookies\owner@popcapgames.122.2o7[1].txt C:\Documents and Settings\Owner\Cookies\owner@overture[1].txt C:\Documents and Settings\Owner\Cookies\owner@doubleclick[1].txt C:\Documents and Settings\Owner\Cookies\owner@ad.yieldmanager[2].txt C:\Documents and Settings\Owner\Cookies\owner@serving-sys[2].txt C:\Documents and Settings\Owner\Cookies\owner@invitemedia[2].txt C:\Documents and Settings\Owner\Cookies\owner@media.mtvnservices[2].txt |
|
|
|
Nov 5 2009, 10:18 AM
Post
#13
|
|
|
Member ![]() ![]() Group: Members Posts: 94 Joined: 10-July 08 From: Nevada Member No.: 221,655 |
GMER log....
GMER 1.0.15.15163 - http://www.gmer.net Rootkit scan 2009-11-05 08:16:31 Windows 5.1.2600 Service Pack 3 Running: gmer.exe; Driver: C:\DOCUME~1\Owner\LOCALS~1\Temp\uwtdqpoc.sys ---- System - GMER 1.0.15 ---- SSDT F7A88B76 ZwCreateKey SSDT F7A88B6C ZwCreateThread SSDT F7A88B7B ZwDeleteKey SSDT F7A88B85 ZwDeleteValueKey SSDT F7A88B8A ZwLoadKey SSDT F7A88B58 ZwOpenProcess SSDT F7A88B5D ZwOpenThread SSDT F7A88B94 ZwReplaceKey SSDT F7A88B8F ZwRestoreKey SSDT F7A88B80 ZwSetValueKey SSDT \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys (SASKUTIL.SYS/SUPERAdBlocker.com and SUPERAntiSpyware.com) ZwTerminateProcess [0xB08A30B0] ---- Kernel code sections - GMER 1.0.15 ---- .text ntoskrnl.exe!_abnormal_termination + 451 804E2AAD 3 Bytes [30, 8A, B0] ---- Devices - GMER 1.0.15 ---- Device \FileSystem\Fastfat \FatCdrom tfsnifs.sys (Direct Access Component/VERITAS Software, Inc.) ---- Registry - GMER 1.0.15 ---- Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL@Installed 1 Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI@Installed 1 Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI@NoChange 1 Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS@Installed 1 ---- Disk sectors - GMER 1.0.15 ---- Disk \Device\Harddisk0\DR0 sector 01: copy of MBR Disk \Device\Harddisk0\DR0 sector 02: copy of MBR Disk \Device\Harddisk0\DR0 sector 03: copy of MBR Disk \Device\Harddisk0\DR0 sector 04: copy of MBR Disk \Device\Harddisk0\DR0 sector 05: copy of MBR Disk \Device\Harddisk0\DR0 sector 06: copy of MBR Disk \Device\Harddisk0\DR0 sector 07: copy of MBR Disk \Device\Harddisk0\DR0 sector 08: copy of MBR Disk \Device\Harddisk0\DR0 sector 09: copy of MBR Disk \Device\Harddisk0\DR0 sector 10: copy of MBR Disk \Device\Harddisk0\DR0 sector 11: copy of MBR Disk \Device\Harddisk0\DR0 sector 12: copy of MBR Disk \Device\Harddisk0\DR0 sector 13: copy of MBR Disk \Device\Harddisk0\DR0 sector 14: copy of MBR Disk \Device\Harddisk0\DR0 sector 15: copy of MBR Disk \Device\Harddisk0\DR0 sector 16: copy of MBR Disk \Device\Harddisk0\DR0 sector 17: copy of MBR Disk \Device\Harddisk0\DR0 sector 18: copy of MBR Disk \Device\Harddisk0\DR0 sector 19: copy of MBR Disk \Device\Harddisk0\DR0 sector 20: copy of MBR Disk \Device\Harddisk0\DR0 sector 21: copy of MBR Disk \Device\Harddisk0\DR0 sector 22: copy of MBR Disk \Device\Harddisk0\DR0 sector 23: copy of MBR Disk \Device\Harddisk0\DR0 sector 24: copy of MBR Disk \Device\Harddisk0\DR0 sector 25: copy of MBR Disk \Device\Harddisk0\DR0 sector 26: copy of MBR Disk \Device\Harddisk0\DR0 sector 27: copy of MBR Disk \Device\Harddisk0\DR0 sector 28: copy of MBR Disk \Device\Harddisk0\DR0 sector 29: copy of MBR Disk \Device\Harddisk0\DR0 sector 30: copy of MBR Disk \Device\Harddisk0\DR0 sector 31: copy of MBR Disk \Device\Harddisk0\DR0 sector 32: rootkit-like behavior; copy of MBR Disk \Device\Harddisk0\DR0 sector 33: copy of MBR Disk \Device\Harddisk0\DR0 sector 34: copy of MBR Disk \Device\Harddisk0\DR0 sector 35: copy of MBR Disk \Device\Harddisk0\DR0 sector 36: copy of MBR Disk \Device\Harddisk0\DR0 sector 37: copy of MBR Disk \Device\Harddisk0\DR0 sector 38: copy of MBR Disk \Device\Harddisk0\DR0 sector 39: copy of MBR Disk \Device\Harddisk0\DR0 sector 40: copy of MBR Disk \Device\Harddisk0\DR0 sector 41: copy of MBR Disk \Device\Harddisk0\DR0 sector 42: copy of MBR Disk \Device\Harddisk0\DR0 sector 43: copy of MBR Disk \Device\Harddisk0\DR0 sector 44: copy of MBR Disk \Device\Harddisk0\DR0 sector 45: copy of MBR Disk \Device\Harddisk0\DR0 sector 46: copy of MBR Disk \Device\Harddisk0\DR0 sector 47: copy of MBR Disk \Device\Harddisk0\DR0 sector 48: copy of MBR Disk \Device\Harddisk0\DR0 sector 49: copy of MBR Disk \Device\Harddisk0\DR0 sector 50: copy of MBR Disk \Device\Harddisk0\DR0 sector 51: copy of MBR Disk \Device\Harddisk0\DR0 sector 52: copy of MBR Disk \Device\Harddisk0\DR0 sector 53: copy of MBR Disk \Device\Harddisk0\DR0 sector 54: copy of MBR Disk \Device\Harddisk0\DR0 sector 55: copy of MBR Disk \Device\Harddisk0\DR0 sector 56: copy of MBR Disk \Device\Harddisk0\DR0 sector 57: copy of MBR Disk \Device\Harddisk0\DR0 sector 58: copy of MBR Disk \Device\Harddisk0\DR0 sector 59: copy of MBR Disk \Device\Harddisk0\DR0 sector 60: copy of MBR Disk \Device\Harddisk0\DR0 sector 61: copy of MBR Disk \Device\Harddisk0\DR0 sector 62: rootkit-like behavior; copy of MBR Disk \Device\Harddisk0\DR0 sector 63: rootkit-like behavior; copy of MBR |
|
|
|
Nov 5 2009, 05:27 PM
Post
#14
|
|
![]() BC 1st Responder ![]() ![]() ![]() ![]() ![]() ![]() Group: Global Moderator Posts: 10,730 Joined: 21-October 04 From: South Carolina - USA Member No.: 3,905 |
This looks like a Master Boot Record virus. We need to get you transferred to the HJT forum.
Please follow this guide from step (6). Post a HJT log to the HJT forum and a Team member will be along to help you as soon as possible. You may wish to post a link back to this topic to see what was discussed thus far. If you need any help with the guide, please let me know. One note, the HJT forums are very busy, please be patient and I promise you will not be disappointed. -------------------- "In a world where you can be anything, be yourself." ~ unknown ![]() Become a BleepingComputer fan: Facebook |
|
|
|
Nov 6 2009, 09:48 PM
Post
#15
|
|
|
Member ![]() ![]() Group: Members Posts: 94 Joined: 10-July 08 From: Nevada Member No.: 221,655 |
HOw do I link this to the new post?
|
|
|
|
![]() ![]() |
| Lo-Fi Version | Time is now: 19th March 2010 - 09:44 AM |