Used unhide.exe and changed folder options so that hidden files can be viewed. Still receive a white screen, rundll message that says C:\Windows\vgromlo.dll module can not be found and I have concerns re: 'bogus' McAfee message/s. Here are the latest Malwarebytes and OTL results:
Scan type: Quick scan
Objects scanned: 176029
Time elapsed: 51 minute(s), 3 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 1
Registry Data Items Infected: 3
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\4E3E0230AEBB4E96 (Trojan.SpyEyes) -> Value: 4E3E0230AEBB4E96 -> Quarantined and deleted successfully.
Registry Data Items Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\NoChangingWallPaper (PUM.Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoDesktop (PUM.Hidden.Desktop) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr (PUM.Hijack.TaskManager) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
AND HERE ARE OTL RESULTS:
[2011/06/13 01:04:21 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2011/06/13 01:04:21 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2011/06/13 01:04:21 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2011/06/12 22:11:01 | 000,000,516 | ---- | C] () -- C:\WINDOWS\tasks\One-Click Tweak.job
[2011/06/12 20:11:30 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Mike\Local Settings\Application Data\{8D503413-07E2-49E7-8413-2DEC6DA98773}
[2011/06/12 20:11:30 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Mike\Local Settings\Application Data\{781A630D-D1A8-4D66-8BBA-7929DE625835}
[2011/06/11 09:47:46 | 000,000,795 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/06/10 18:33:58 | 000,000,000 | ---- | C] () -- C:\WINDOWS\Acirusudihosozi.bin
[2011/06/10 18:33:36 | 000,000,120 | ---- | C] () -- C:\WINDOWS\Ndesokoxe.dat
[2010/01/10 19:19:29 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ToDisc.INI
[2009/04/10 13:35:27 | 000,011,020 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\LUUnInstall.LiveUpdate
[2008/11/27 12:47:56 | 000,073,728 | ---- | C] () -- C:\WINDOWS\System32\RtNicProp32.dll
[2008/08/23 20:59:47 | 000,057,856 | ---- | C] () -- C:\Documents and Settings\Mike\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/07/21 00:37:34 | 000,103,535 | ---- | C] () -- C:\WINDOWS\hpoins04.dat
[2008/07/21 00:37:34 | 000,017,176 | ---- | C] () -- C:\WINDOWS\hpomdl04.dat
[2008/05/26 21:59:42 | 000,018,904 | ---- | C] () -- C:\WINDOWS\System32\structuredqueryschematrivial.bin
[2008/05/26 21:59:40 | 000,106,605 | ---- | C] () -- C:\WINDOWS\System32\structuredqueryschema.bin
[2008/04/16 21:44:45 | 000,000,300 | ---- | C] () -- C:\WINDOWS\EReg515.dat
[2008/04/16 21:42:59 | 000,010,240 | ---- | C] () -- C:\WINDOWS\System32\vidx16.dll
[2008/04/16 21:39:25 | 000,000,889 | ---- | C] () -- C:\WINDOWS\disney.ini
[2008/01/26 16:33:42 | 000,000,069 | ---- | C] () -- C:\WINDOWS\encore_launcher.ini
[2007/11/21 22:00:17 | 000,001,387 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2007/10/27 12:29:03 | 000,000,181 | ---- | C] () -- C:\WINDOWS\civ.ini
[2007/10/26 12:56:45 | 000,043,520 | ---- | C] () -- C:\WINDOWS\System32\CmdLineExt03.dll
[2007/10/09 14:15:50 | 000,000,002 | ---- | C] () -- C:\WINDOWS\msoffice.ini
[2007/09/28 21:31:49 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\YCRWin32.dll
[2007/09/27 10:51:02 | 000,020,698 | ---- | C] () -- C:\WINDOWS\System32\idxcntrs.ini
[2007/09/27 10:48:48 | 000,030,628 | ---- | C] () -- C:\WINDOWS\System32\gsrvctr.ini
[2007/09/27 10:48:28 | 000,031,698 | ---- | C] () -- C:\WINDOWS\System32\gthrctr.ini
[2007/08/13 16:24:12 | 000,000,067 | ---- | C] () -- C:\WINDOWS\swupdate.INI
[2007/03/05 13:34:28 | 000,676,224 | ---- | C] () -- C:\WINDOWS\System32\OGACheckControl.DLL
[2007/02/14 23:44:42 | 000,081,920 | ---- | C] () -- C:\WINDOWS\System32\usbicon.exe
[2006/12/25 11:38:03 | 000,245,760 | ---- | C] () -- C:\WINDOWS\System32\ControlWZCS.exe
[2006/12/25 11:38:00 | 000,036,864 | ---- | C] () -- C:\WINDOWS\System32\acs.exe
[2006/12/25 11:37:56 | 000,311,296 | ---- | C] () -- C:\WINDOWS\System32\AegisI5.exe
[2006/12/25 11:37:42 | 000,270,336 | ---- | C] () -- C:\WINDOWS\System32\PlugPlayPCIDevice.exe
[2006/09/09 14:29:20 | 000,204,800 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeW7.dll
[2006/09/09 14:29:20 | 000,200,704 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeA6.dll
[2006/09/09 14:29:20 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeP6.dll
[2006/09/09 14:29:20 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeM6.dll
[2006/09/09 14:29:20 | 000,188,416 | ---- | C] () -- C:\WINDOWS\System32\IVIresizePX.dll
[2006/09/09 14:29:20 | 000,020,480 | ---- | C] () -- C:\WINDOWS\System32\IVIresize.dll
[2006/09/09 14:28:14 | 000,128,113 | ---- | C] () -- C:\WINDOWS\System32\csellang.ini
[2006/09/09 14:28:14 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\csellang.dll
[2006/09/09 14:28:14 | 000,010,165 | ---- | C] () -- C:\WINDOWS\System32\tosmreg.ini
[2006/09/09 14:28:14 | 000,007,671 | ---- | C] () -- C:\WINDOWS\System32\cseltbl.ini
[2006/09/09 14:25:07 | 000,143,360 | ---- | C] () -- C:\WINDOWS\System32\RtlCPAPI.dll
[2006/09/09 14:25:07 | 000,049,152 | ---- | C] () -- C:\WINDOWS\System32\ChCfg.exe
[2006/08/21 18:44:11 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2006/08/21 14:08:28 | 000,000,335 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2006/08/21 13:54:33 | 000,000,000 | ---- | C] () -- C:\WINDOWS\NDSTray.INI
[2006/08/21 13:53:47 | 000,011,122 | ---- | C] () -- C:\WINDOWS\HWSetupStr.ini
[2006/08/21 13:53:47 | 000,002,036 | ---- | C] () -- C:\WINDOWS\SVPW32Str.ini
[2006/08/21 12:30:37 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2006/08/21 12:27:53 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2006/08/21 12:23:34 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2006/08/21 12:22:29 | 000,001,793 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini
[2006/08/21 12:06:11 | 000,000,341 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
[2006/08/21 12:03:21 | 000,755,200 | ---- | C] () -- C:\WINDOWS\System32\ir50_32.dll
[2006/08/21 12:03:21 | 000,338,432 | ---- | C] () -- C:\WINDOWS\System32\ir41_qcx.dll
[2006/08/21 12:03:21 | 000,200,192 | ---- | C] () -- C:\WINDOWS\System32\ir50_qc.dll
[2006/08/21 12:03:21 | 000,183,808 | ---- | C] () -- C:\WINDOWS\System32\ir50_qcx.dll
[2006/08/21 12:03:21 | 000,120,320 | ---- | C] () -- C:\WINDOWS\System32\ir41_qc.dll
[2006/08/21 12:02:50 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2006/08/21 12:02:46 | 000,561,972 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2006/08/21 12:02:46 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2006/08/21 12:02:46 | 000,104,796 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2006/08/21 12:02:46 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2006/08/21 12:02:44 | 000,004,688 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2006/08/21 12:02:42 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2006/08/21 12:02:39 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
[2006/08/21 12:02:31 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2006/08/21 12:02:30 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2006/08/21 12:02:18 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2006/08/21 12:02:05 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\dcache.bin
[2006/08/21 05:18:50 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2006/08/21 05:18:00 | 000,178,648 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2006/08/01 12:56:40 | 000,122,880 | ---- | C] () -- C:\WINDOWS\System32\TPeculiarity.dll
[2005/12/08 20:01:06 | 000,112,421 | ---- | C] () -- C:\WINDOWS\System32\atiicdxx.dat
[2005/12/08 13:56:50 | 000,151,552 | ---- | C] () -- C:\WINDOWS\System32\tsbwls.dll
[2005/08/24 17:20:28 | 000,009,472 | ---- | C] () -- C:\WINDOWS\System32\drivers\tbiosdrv.sys
[2004/05/15 05:50:52 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\MSRTEDIT.DLL
========== Alternate Data Streams ==========
@Alternate Data Stream - 163 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:98F0614F
@Alternate Data Stream - 104 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D1B5B4F1
< End of report >
This post has been edited by Sinikka: 13 June 2011 - 05:26 PM

Help
This topic is locked

Back to top
button.









