mmehdi, on 26 July 2011 - 08:25 PM, said:
I know, it's so incredibly annoying! Hope you manage to get rid of it.
jntkwx, on 25 July 2011 - 04:07 PM, said:
Hi Jason, thanks for replying so speedily. I followed your instructions and after updating MBAM (hadn't realised it wasn't updated) and running the quick scan it
seems to have got rid of it, but not sure. Logs are below.
Security Check log:
Results of screen317's Security Check version 0.99.18
Windows 7 (UAC is enabled)
Internet Explorer 8
``````````````````````````````
Antivirus/Firewall Check:
Windows Firewall Enabled!
avast! Free Antivirus
WMI entry may not exist for antivirus; attempting automatic update.
```````````````````````````````
Anti-malware/Other Utilities Check:
Malwarebytes' Anti-Malware
Java 6 Update 18
Out of date Java installed!
Flash Player Out of Date!
Adobe Flash Player 10.2.159.1
Mozilla Firefox (3.6.18)
Firefox Out of Date!
````````````````````````````````
Process Check:
objlist.exe by Laurent
Mozilla Firefox AvastSvc.exe -?-
AVAST Software Avast AvastUI.exe
``````````End of Log````````````
MalwareBytes log:
Malwarebytes' Anti-Malware 1.51.1.1800
www.malwarebytes.org
Database version: 7296
Windows 6.1.7600
Internet Explorer 8.0.7600.16385
27/07/2011 15:50:54
mbam-log-2011-07-27 (15-50-54).txt
Scan type: Quick scan
Objects scanned: 177386
Time elapsed: 2 minute(s), 51 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 2
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 20
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\cachestreammgr.exe (Trojan.FakeAlert) -> Value: cachestreammgr.exe -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\*cachestreammgr.exe (Trojan.FakeAlert) -> Value: *cachestreammgr.exe -> Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
c:\programdata\cachestreammgr.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\Users\Lucy\AppData\Local\Temp\5514.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\Lucy\AppData\Local\Temp\amowxrscne.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\Users\Lucy\AppData\Local\Temp\setup1040052412.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\Lucy\AppData\Local\Temp\setup1281702528.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\Lucy\AppData\Local\Temp\setup1321723232.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\Lucy\AppData\Local\Temp\setup1475935976.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\Lucy\AppData\Local\Temp\setup165509120.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\Lucy\AppData\Local\Temp\setup1842927628.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\Lucy\AppData\Local\Temp\setup2097129688.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\Lucy\AppData\Local\Temp\setup2143009344.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\Lucy\AppData\Local\Temp\setup2828042824.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\Lucy\AppData\Local\Temp\setup2908854436.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\Lucy\AppData\Local\Temp\setup3121470268.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\Lucy\AppData\Local\Temp\setup336979164.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\Lucy\AppData\Local\Temp\setup3556402292.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\Lucy\AppData\Local\Temp\setup607713408.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\Lucy\AppData\Local\Temp\setup686889320.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\Lucy\AppData\Roaming\Adobe\plugs\kb7233142.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\Lucy\local settings\application data\windows server\admin.txt (Malware.Trace) -> Quarantined and deleted successfully.
GMER 1.0.15.15641 -
http://www.gmer.net
Rootkit scan 2011-07-27 16:31:52
Windows 6.1.7600
Running: ecf8uxcq.exe
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\001f81000250
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\001f81000250@a0079837a552 0x20 0x14 0x45 0xB8 ...
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\001f81000250 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\001f81000250@a0079837a552 0x20 0x14 0x45 0xB8 ...
---- EOF - GMER 1.0.15 ----