So I ran some checks, and here is the security check log first of all.
SECURITY CHECK LOG
Results of screen317's Security Check version 0.99.7
Windows 7 Service Pack 1 (UAC is disabled!)
Internet Explorer 8
``````````````````````````````
Antivirus/Firewall Check:
Windows Security Center service is not running! This report may not be accurate!
Windows Firewall Enabled!
avast! Free Antivirus
WMI entry may not exist for antivirus; attempting automatic update.
```````````````````````````````
Anti-malware/Other Utilities Check:
Malwarebytes' Anti-Malware
CCleaner
Java 6 Update 23
Out of date Java installed!
Adobe Flash Player 10.0.42.34
````````````````````````````````
Process Check:
objlist.exe by Laurent
Malwarebytes' Anti-Malware mbam.exe
Alwil Software Avast5 AvastSvc.exe
Alwil Software Avast5 AvastUI.exe
``````````End of Log````````````
And here is the MBAM log.
MBAM LOG
Malwarebytes' Anti-Malware 1.51.1.1800
www.malwarebytes.org
Database version: 7576
Windows 6.1.7601 Service Pack 1
Internet Explorer 8.0.7601.17514
26/08/2011 17:15:29
mbam-log-2011-08-26 (17-15-29).txt
Scan type: Full scan (C:\|E:\|)
Objects scanned: 299772
Time elapsed: 1 hour(s), 45 minute(s), 21 second(s)
Memory Processes Infected: 2
Memory Modules Infected: 0
Registry Keys Infected: 15
Registry Values Infected: 2
Registry Data Items Infected: 0
Folders Infected: 3
Files Infected: 7
Memory Processes Infected:
c:\Users\Desie\AppData\Roaming\n4f9.exe (Trojan.LVBP) -> 3136 -> Unloaded process successfully.
c:\Users\Desie\AppData\Roaming\n4f9.exe (Trojan.LVBP) -> 3468 -> Unloaded process successfully.
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ShoppingReport2 (Adware.ShoppingReports2) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MouseDriver (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\ShoppingReport2.HbAx (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\ShoppingReport2.HbAx.1 (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\ShoppingReport2.HbInfoBand (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\ShoppingReport2.HbInfoBand.1 (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\ShoppingReport2.IEButton (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\ShoppingReport2.IEButton.1 (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\ShoppingReport2.IEButtonA (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\ShoppingReport2.IEButtonA.1 (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\ShoppingReport2.RprtCtrl (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\ShoppingReport2.RprtCtrl.1 (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\ShoppingReport2 (Adware.ShoppingReport2) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\ShoppingReport2 (Adware.ShoppingReport2) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\tgs90gv74r (Malware.Trace) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ej4ddor (Trojan.LVBP) -> Value: ej4ddor -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MouseDriver\ImagePath (Trojan.Agent) -> Value: ImagePath -> Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
c:\program files\shoppingreport2 (Adware.ShoppingReport2) -> Quarantined and deleted successfully.
c:\program files\shoppingreport2\Bin (Adware.ShoppingReport2) -> Quarantined and deleted successfully.
c:\program files\shoppingreport2\Bin\2.7.34 (Adware.ShoppingReport2) -> Quarantined and deleted successfully.
Files Infected:
c:\Users\Desie\AppData\Roaming\n4f9.exe (Trojan.LVBP) -> Quarantined and deleted successfully.
c:\Users\Desie\AppData\Local\Temp\mrecawnsxo.exe (Virus.Vampiro) -> Quarantined and deleted successfully.
c:\Users\Desie\AppData\Local\Temp\aewcrxonms.exe (Trojan.LVBP) -> Quarantined and deleted successfully.
c:\Users\Desie\AppData\Roaming\eovjja1j.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\Desie\AppData\Roaming\trz141C.tmp (Backdoor.Bot) -> Quarantined and deleted successfully.
c:\program files\shoppingreport2\Uninst.exe (Adware.ShoppingReports2) -> Quarantined and deleted successfully.
c:\Users\Desie\AppData\Roaming\mousedriver.bat (Trojan.Agent) -> Quarantined and deleted successfully.
So, where should we go from here? Is the computer still safe for use? How can he prevent this from happening again? Note, Windows Security Center still won't open.

Thanks for all/any help!
EDIT:: I forgot to note that with the MBAM scan, my Dad's external hard drive was also scanned. Avast did not scan the external hard drive.
This post has been edited by DJ-C: 26 August 2011 - 11:56 AM

Help

Back to top









