
Well that question was unexpected! As far as I know i only have one user account, although it is not outside the realm of possibility that i have been here before a long time ago. Because of your question I looked at member names and see there are 2 others that are similar. Is that why you asked? I could see myself using 'Balfie', but I know that one isn't me because I've never gotten one of those hi-jack logs done. The other just didn't look familiar at all and isn't something I would come up with. I am not that creative - I took this nick directly from an email address and even that was not named by me (I inherited the email account because he wasn't using it anymore, it was already set up on Outlook and by using it for registrations I protect my daily one from spam).
Boy, I do not even remember what happened with either MalwareBytes or SUPERAntiSpyware.. I will look for those logs and post them. I saw above that I did not run it on D - should I have? I did run AVG right after rebooting following the Dr.Web CureIt and it found tracking cookies. But I was not even online (was in safe mode the entire time until rebooting) so can't understand how i got them.
Every time I try to open the Dr Web log a pre-installed program I haven't paid for tries to open :then can't so I used 'open with' but the log is barely readable in this form. I only see one log and I think it is from the long scan. i do not remember what happened with the short scan. They both took a long time.
MBAM (I thought I had run it more than once and that it came up clean but I only saw this in My Documents)
Malwarebytes' Anti-Malware 1.44
Database version: 3584
Windows 5.1.2600 Service Pack 3
Internet Explorer 7.0.5730.11
1/17/2010 12:36:44 PM
mbam-log-2010-01-17 (12-36-34).txt
Scan type: Full Scan (C:\|D:\|)
Objects s0000000000000000canned: 350529
Time elapsed: 1 hour(s), 30 minute(s), 51 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 12
Registry Values Infected: 1
Registry Data Items Infected: 1
Folders Infected: 1
Files Infected: 2
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{19127ad2-394b-70f5-c650-b97867baa1f7} (Backdoor.Bot) -> No action taken.
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{43bf8cd1-c5d5-2230-7bb2-98f22c2b7dc6} (Backdoor.Bot) -> No action taken.
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{494e6cec-7483-a4ee-0938-895519a84bc7} (Backdoor.Bot) -> No action taken.
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{c48635ad-d6b5-3ee4-aaa2-540d5a173658} (Backdoor.Bot) -> No action taken.
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{3446af26-b8d7-199b-4cfc-6fd764ca5c9f} (Backdoor.Bot) -> No action taken.
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{4776c4dc-e894-7c06-2148-5d73cef5f905} (Backdoor.Bot) -> No action taken.
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{19127ad2-394b-70f5-c650-b97867baa1f7} (Backdoor.Bot) -> No action taken.
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{43bf8cd1-c5d5-2230-7bb2-98f22c2b7dc6} (Backdoor.Bot) -> No action taken.
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{494e6cec-7483-a4ee-0938-895519a84bc7} (Backdoor.Bot) -> No action taken.
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{c48635ad-d6b5-3ee4-aaa2-540d5a173658} (Backdoor.Bot) -> No action taken.
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{3446af26-b8d7-199b-4cfc-6fd764ca5c9f} (Backdoor.Bot) -> No action taken.
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{4776c4dc-e894-7c06-2148-5d73cef5f905} (Backdoor.Bot) -> No action taken.
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Network\uid (Malware.Trace) -> No action taken.
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Hijack.Userinit) -> Bad: (C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\sdra64.exe,) Good: (Userinit.exe) -> No action taken.
Folders Infected:
C:\WINDOWS\system32\lowsec (Stolen.data) -> No action taken.
Files Infected:
C:\WINDOWS\system32\lowsec\local.ds (Stolen.data) -> No action taken.
C:\WINDOWS\system32\lowsec\user.ds (Stolen.data) -> No action taken.
Malwarebytes' Anti-Malware 1.44
Database version: 3584
Windows 5.1.2600 Service Pack 3
Internet Explorer 7.0.5730.11
1/17/2010 2:23:44 PM
mbam-log-2010-01-17 (14-23-44).txt
Scan type: Full Scan (C:\|D:\|)
Objects scanned: 350529
Time elapsed: 1 hour(s), 30 minute(s), 51 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 12
Registry Values Infected: 1
Registry Data Items Infected: 1
Folders Infected: 1
Files Infected: 2
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{19127ad2-394b-70f5-c650-b97867baa1f7} (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{43bf8cd1-c5d5-2230-7bb2-98f22c2b7dc6} (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{494e6cec-7483-a4ee-0938-895519a84bc7} (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{c48635ad-d6b5-3ee4-aaa2-540d5a173658} (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{3446af26-b8d7-199b-4cfc-6fd764ca5c9f} (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{4776c4dc-e894-7c06-2148-5d73cef5f905} (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{19127ad2-394b-70f5-c650-b97867baa1f7} (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{43bf8cd1-c5d5-2230-7bb2-98f22c2b7dc6} (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{494e6cec-7483-a4ee-0938-895519a84bc7} (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{c48635ad-d6b5-3ee4-aaa2-540d5a173658} (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{3446af26-b8d7-199b-4cfc-6fd764ca5c9f} (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{4776c4dc-e894-7c06-2148-5d73cef5f905} (Backdoor.Bot) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Network\uid (Malware.Trace) -> Quarantined and deleted successfully.
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Hijack.Userinit) -> Bad: (C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\sdra64.exe,) Good: (Userinit.exe) -> Quarantined and deleted successfully.
Folders Infected:
C:\WINDOWS\system32\lowsec (Stolen.data) -> Quarantined and deleted successfully.
Files Infected:
C:\WINDOWS\system32\lowsec\local.ds (Stolen.data) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\lowsec\user.ds (Stolen.data) -> Quarantined and deleted successfully.
Malwarebytes' Anti-Malware 1.44
Database version: 3584
Windows 5.1.2600 Service Pack 3
Internet Explorer 7.0.5730.11
1/17/2010 5:39:46 PM
mbam-log-2010-01-17 (17-39-46).txt
Scan type: Quick Scan
Objects scanned: 146129
Time elapsed: 6 minute(s), 49 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
Malwarebytes' Anti-Malware 1.44
Database version: 3586
Windows 5.1.2600 Service Pack 3
Internet Explorer 7.0.5730.11
1/17/2010 7:46:15 PM
mbam-log-2010-01-17 (19-46-15).txt
Scan type: Quick Scan
Objects scanned: 129758
Time elapsed: 4 minute(s), 18 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
Dr.Web CureIt (created at Today, January 19, 2010, 9:44:21 AM according to fiile properties so it was the result of the long scan)
MeMediaSetupInst.exe\MeMediaSetup.exe;C:\Documents and Settings\Owner\My Documents\Set Up Files\card gaMes\freecellsetup.exe/data002/{app}\MeMediaSetupInst.exe;Adware.SaveNow.origin;;
{app}\MeMediaSetupInst.exe;C:\Documents and Settings\Owner\My Documents\Set Up Files\card gaMes\freecellsetup.exe/data002/{app};Archive contains infected objects;;
data002;C:\Documents and Settings\Owner\My Documents\Set Up Files\card gaMes;Archive contains infected objects;;
freecellsetup.exe;C:\Documents and Settings\Owner\My Documents\Set Up Files\card gaMes;Container contains infected objects;Moved.;
zlsSetup_70_470_000_en.exe/Z4BARSPINSTALL.EXE/data001\data001;C:\Documents and Settings\Owner\My Documents\Set Up Files\zone alarm\zlsSetup_70_470_000_en.exe/Z4BARSPINSTALL.EXE/data001;Adware.MyWebSearch.22;;
data001;C:\Documents and Settings\Owner\My Documents\Set Up Files\zone alarm;Container contains infected objects;;
Z4BARSPINSTALL.EXE;C:\Documents and Settings\Owner\My Documents\Set Up Files\zone alarm;Container contains infected objects;;
zlsSetup_70_470_000_en.exe;C:\Documents and Settings\Owner\My Documents\Set Up Files\zone alarm;Archive contains infected objects;Moved.;
zlsSetup_70_483_000_en.exe/Z4BARSPINSTALL.EXE/data001\data001;C:\Documents and Settings\Owner\My Documents\Set Up Files\zone alarm\zlsSetup_70_483_000_en.exe/Z4BARSPINSTALL.EXE/data001;Adware.MyWebSearch.22;;
data001;C:\Documents and Settings\Owner\My Documents\Set Up Files\zone alarm;Container contains infected objects;;
Z4BARSPINSTALL.EXE;C:\Documents and Settings\Owner\My Documents\Set Up Files\zone alarm;Container contains infected objects;;
zlsSetup_70_483_000_en.exe;C:\Documents and Settings\Owner\My Documents\Set Up Files\zone alarm;Archive contains infected objects;Moved.;
NPZoneSB.dll;C:\Program Files\Mozilla Firefox\plugins;Adware.MyWebSearch.22;Moved.;
NPZONESB.DLL;C:\Program Files\ZoneAlarmSB\bar\1.bin;Adware.MyWebSearch.22;Moved.;
aolcinst.exe\core.cab\GTDOWNAO_106.ocx;D:\i386\Apps\App13914\comps\coach\aolcinst.exe;Adware.Gdown;;
aolcinst.exe;D:\i386\Apps\App13914\comps\coach;Archive contains infected objects;Moved.;
The this afternoon AVG scan found tracking cookies. The pc was off line - I had unplugged it and the only thing I did on that computer was run AVG after rebooting from the DrWeb scan.
P.S. I might have been mistaken and did re-hook up my pc to the internet sometime today after dr web finished and before i ran the avg scan.. I do not remember doing so or using the browser or anything and am pretty sure i didn't, but i am not positive..
P.S.S. Sorry i forgot to post the MalwareBytes logs before.