Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Infected with Trojan


  • Please log in to reply
1 reply to this topic

#1 AbihsotHelpie

AbihsotHelpie

  • Members
  • 1 posts
  • OFFLINE
  •  
  • Local time:07:03 PM

Posted 17 August 2009 - 12:09 PM

A friend used my computer to visit a site called "Mangafox.com", and afterwards a red circle with a white 'x' in it appeared on my icon bar stating that spyware had been detected in the computer system. I used Windows Defender, which detected a Trojan. After clicking the 'Remove All' button, the red icon disappears after a long while. However, after restarting the computer, it comes back and Windows Defender re-detects the Trojan (restarting the whole process). I have McAfee, but it does not detect anything.
Also, the malware from Mangafox had broken down one of my previous computers (too bad my friend didn't know that), and caused the screen to go blue.
Help would be much appreciated.

DDS (Ver_09-07-30.01) - NTFSx86
Run by Ma at 12:52:36.31 on Mon 08/17/2009
Internet Explorer: 7.0.5730.13
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.446.104 [GMT -7:00]

AV: McAfee VirusScan *On-access scanning enabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}

============== Running Processes ===============

C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\acs.exe
svchost.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\WINDOWS\system32\DVDRAMSV.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe
C:\WINDOWS\RTHDCPL.EXE
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
C:\Program Files\Toshiba\Tvs\TvsTray.exe
C:\Program Files\ltmoh\Ltmoh.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe
C:\WINDOWS\system32\TPSMain.exe
C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
C:\toshiba\ivp\ism\pinger.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\McAfee\MBK\McAfeeDataBackup.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\WINDOWS\system32\TPSBattM.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
C:\Program Files\Metamail Inc\Metamail Tray\Metamail Trust Manager.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hposol08.exe
C:\WINDOWS\system32\RAMASST.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\PROGRA~1\METAMA~1\METAMA~1\METAMA~2.EXE
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Documents and Settings\Ma\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uSearch Page = hxxp://www.google.com
mDefault_Search_URL = hxxp://www.google.com/ie
mSearch Page = hxxp://www.google.com
mStart Page = hxxp://www.google.com
mSearchAssistant = hxxp://www.google.com
TB: &Google: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\googletoolbar1.dll
EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [TOSCDSPD] c:\program files\toshiba\toscdspd\toscdspd.exe
uRun: [braviax] c:\windows\system32\braviax.exe
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [Alcmtr] ALCMTR.EXE
mRun: [ATIPTA] "c:\program files\ati technologies\ati control panel\atiptaxx.exe"
mRun: [SynTPLpr] c:\program files\synaptics\syntp\SynTPLpr.exe
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [THotkey] c:\program files\toshiba\toshiba applet\thotkey.exe
mRun: [NDSTray.exe] NDSTray.exe
mRun: [Tvs] c:\program files\toshiba\tvs\TvsTray.exe
mRun: [LtMoh] c:\program files\ltmoh\Ltmoh.exe
mRun: [AGRSMMSG] AGRSMMSG.exe
mRun: [DLA] c:\windows\system32\dla\DLACTRLW.EXE
mRun: [TFncKy] TFncKy.exe
mRun: [TPSMain] TPSMain.exe
mRun: [PadTouch] c:\program files\toshiba\touch and launch\PadExe.exe
mRun: [SmoothView] c:\program files\toshiba\toshiba zooming utility\SmoothView.exe
mRun: [Pinger] c:\toshiba\ivp\ism\pinger.exe /run
mRun: [mcagent_exe] "c:\program files\mcafee.com\agent\mcagent.exe" /runkey
mRun: [Share-to-Web Namespace Daemon] c:\program files\hewlett-packard\hp share-to-web\hpgs2wnd.exe
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [McAfee Backup] "c:\program files\mcafee\mbk\McAfeeDataBackup.exe"
mRun: [Windows Defender] "c:\program files\windows defender\MSASCui.exe" -hide
mRun: [MSConfig] c:\windows\pchealth\helpctr\binaries\MSConfig.exe /auto
StartupFolder: c:\docume~1\ma\startm~1\programs\startup\onenot~1.lnk - c:\program files\microsoft office\office12\ONENOTEM.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hppsc2~1.lnk - c:\program files\hewlett-packard\digital imaging\bin\hpobnz08.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\metama~1.lnk - c:\program files\metamail inc\metamail tray\Metamail Trust Manager.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\office~1.lnk - c:\program files\hewlett-packard\digital imaging\bin\hposol08.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\ramasst.lnk - c:\windows\system32\RAMASST.exe
IE: &Google Search - c:\program files\google\GoogleToolbar1.dll/cmsearch.html
IE: Backward Links - c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
IE: Cached Snapshot of Page - c:\program files\google\GoogleToolbar1.dll/cmcache.html
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: Similar Pages - c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
IE: Translate into English - c:\program files\google\GoogleToolbar1.dll/cmtrans.html
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0015-0000-0004-ABCDEFFEDCBC} - c:\program files\java\jre1.5.0_04\bin\npjpi150_04.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_04-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_04-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Notify: AtiExtEvent - Ati2evxx.dll
SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\window~4\MpShHook.dll

============= SERVICES / DRIVERS ===============

R1 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys [2009-5-13 214024]
R2 McProxy;McAfee Proxy Service;c:\progra~1\common~1\mcafee\mcproxy\mcproxy.exe [2009-8-11 359952]
R2 McShield;McAfee Real-time Scanner;c:\progra~1\mcafee\viruss~1\mcshield.exe [2009-8-11 144704]
R2 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592]
R3 McSysmon;McAfee SystemGuards;c:\progra~1\mcafee\viruss~1\mcsysmon.exe [2009-8-11 606736]
R3 mfeavfk;McAfee Inc. mfeavfk;c:\windows\system32\drivers\mfeavfk.sys [2009-8-11 79816]
R3 mfebopk;McAfee Inc. mfebopk;c:\windows\system32\drivers\mfebopk.sys [2009-8-11 35272]
R3 mfesmfk;McAfee Inc. mfesmfk;c:\windows\system32\drivers\mfesmfk.sys [2009-8-11 40552]
S3 mferkdk;McAfee Inc. mferkdk;c:\windows\system32\drivers\mferkdk.sys [2009-8-11 34248]

=============== Created Last 30 ================

2009-08-17 10:53 <DIR> --d----- c:\windows\pss
2009-08-17 10:48 <DIR> --d----- C:\Autoruns
2009-08-17 09:09 128,512 -c------ c:\windows\system32\dllcache\dhtmled.ocx
2009-08-17 09:08 1,315,328 -c------ c:\windows\system32\dllcache\msoe.dll
2009-08-17 08:13 208,744 a------- c:\windows\system32\muweb.dll
2009-08-17 08:13 27,496 a------- c:\windows\system32\mucltui.dll.mui
2009-08-17 08:13 268,648 a------- c:\windows\system32\mucltui.dll
2009-08-16 22:32 3,833 a------- c:\windows\machine.ver
2009-08-16 12:32 10,240 a------- c:\windows\system32\braviax.exe
2009-08-16 11:28 54,156 a---h--- c:\windows\QTFont.qfn
2009-08-16 11:28 1,409 a------- c:\windows\QTFont.for
2009-08-15 12:59 <DIR> --d----- c:\program files\iTunes
2009-08-15 12:58 38,229 -------- c:\windows\system32\drivers\StMp3Rec.sys
2009-08-15 12:57 <DIR> --d----- c:\program files\iPod
2009-08-15 12:55 <DIR> --d----- c:\windows\Downloaded Installations
2009-08-14 19:11 47 a------- c:\windows\NeroDigital.ini
2009-08-11 21:47 <DIR> --d----- c:\docume~1\ma\applic~1\ZoomBrowser EX
2009-08-11 21:46 5,632 a------- c:\windows\system32\ptpusb.dll
2009-08-11 21:46 159,232 a------- c:\windows\system32\ptpusd.dll
2009-08-11 07:07 158 a------- c:\windows\pagesuit.ini
2009-08-11 07:07 23,040 a------- c:\windows\system32\irisco32.dll
2009-08-11 07:07 <DIR> --d----- c:\program files\ReadIris
2009-08-11 06:51 <DIR> --d----- c:\program files\common files\Hewlett-Packard
2009-08-11 06:48 35,840 a------- c:\windows\system32\drivers\AFS2K.SYS
2009-08-11 06:45 106,496 a----r-- c:\windows\system32\HPZipt12.dll
2009-08-11 06:45 167,936 a----r-- c:\windows\system32\HPZipr12.dll
2009-08-11 06:45 81,920 a----r-- c:\windows\system32\HPZipm12.exe
2009-08-11 06:45 73,728 a----r-- c:\windows\system32\HPZinw12.exe
2009-08-11 06:45 69,632 a----r-- c:\windows\system32\HPZisn12.dll
2009-08-11 06:45 196,608 a----r-- c:\windows\system32\HPZidr12.dll
2009-08-11 06:45 16,112 a----r-- c:\windows\system32\drivers\HPZipr12.sys
2009-08-11 06:45 50,960 a----r-- c:\windows\system32\drivers\hpzid412.sys
2009-08-11 06:45 22,512 a----r-- c:\windows\system32\drivers\HPZius12.sys
2009-08-11 06:44 25,856 ac------ c:\windows\system32\dllcache\usbprint.sys
2009-08-11 06:44 25,856 a------- c:\windows\system32\drivers\usbprint.sys
2009-08-11 06:44 237,568 a----r-- c:\windows\system32\HPZc3212.dll
2009-08-11 06:44 77,824 a----r-- c:\windows\system32\hpovst08.dll
2009-08-11 06:44 552,960 a----r-- c:\windows\system32\hpotscl.dll
2009-08-11 06:44 262,144 a----r-- c:\windows\system32\hpgwiamd.dll
2009-08-11 06:43 15,104 ac------ c:\windows\system32\dllcache\usbscan.sys
2009-08-11 06:43 15,104 a------- c:\windows\system32\drivers\usbscan.sys
2009-08-11 06:42 32,128 ac------ c:\windows\system32\dllcache\usbccgp.sys
2009-08-11 06:42 32,128 a------- c:\windows\system32\drivers\usbccgp.sys
2009-08-11 06:42 7,765 -------- c:\windows\hpomdl01.dat
2009-08-11 06:42 27,801 -------- c:\windows\hpoins01.dat
2009-08-11 06:31 <DIR> --d----- c:\docume~1\alluse~1\applic~1\ZoomBrowser
2009-08-11 06:30 <DIR> --d----- c:\program files\Canon
2009-08-11 06:29 <DIR> --d----- c:\program files\common files\Canon
2009-08-11 06:14 <DIR> --d----- c:\windows\system32\LogFiles
2009-08-11 06:10 6,699 a------- c:\windows\system32\Config.MPF
2009-08-11 06:02 79,816 a------- c:\windows\system32\drivers\mfeavfk.sys
2009-08-11 06:02 40,552 a------- c:\windows\system32\drivers\mfesmfk.sys
2009-08-11 06:02 35,272 a------- c:\windows\system32\drivers\mfebopk.sys
2009-08-11 06:02 120,136 a------- c:\windows\system32\drivers\Mpfp.sys
2009-08-11 06:01 <DIR> --d----- c:\program files\common files\McAfee
2009-08-11 06:01 <DIR> --d----- c:\program files\McAfee.com
2009-08-11 06:01 <DIR> --d----- c:\program files\McAfee
2009-08-11 05:57 34,248 a------- c:\windows\system32\drivers\mferkdk.sys
2009-08-11 03:01 32,592 a------- c:\windows\system32\msonpmon.dll
2009-08-10 23:59 6,067,200 -c------ c:\windows\system32\dllcache\ieframe.dll
2009-08-10 23:59 2,452,872 -c------ c:\windows\system32\dllcache\ieapfltr.dat
2009-08-10 23:59 991,232 -c------ c:\windows\system32\dllcache\ieframe.dll.mui
2009-08-10 23:59 459,264 -c------ c:\windows\system32\dllcache\msfeeds.dll
2009-08-10 23:59 380,928 -c------ c:\windows\system32\dllcache\ieapfltr.dll
2009-08-10 23:59 268,288 -c------ c:\windows\system32\dllcache\iertutil.dll
2009-08-10 23:59 52,224 -c------ c:\windows\system32\dllcache\msfeedsbs.dll
2009-08-10 23:59 13,824 -c------ c:\windows\system32\dllcache\ieudinit.exe
2009-08-10 23:59 63,488 -c------ c:\windows\system32\dllcache\icardie.dll
2009-08-10 23:48 691,712 -c------ c:\windows\system32\dllcache\inetcomm.dll
2009-08-10 11:47 <DIR> --d----- c:\program files\MSXML 4.0
2009-08-10 11:37 <DIR> --d----- c:\windows\system32\scripting
2009-08-10 11:37 <DIR> --d----- c:\windows\l2schemas
2009-08-10 11:37 <DIR> --d----- c:\windows\system32\en
2009-08-10 11:37 <DIR> --d----- c:\windows\system32\bits
2009-08-10 11:32 <DIR> --d----- c:\windows\ServicePackFiles
2009-08-10 11:29 <DIR> --d----- c:\windows\network diagnostic
2009-08-10 11:25 <DIR> --d----- c:\windows\EHome
2009-08-10 11:18 327,040 -------- c:\windows\system32\drivers\ati2mtaa.sys
2009-08-10 11:09 272,128 -c------ c:\windows\system32\dllcache\bthport.sys
2009-08-10 11:07 247,326 -c------ c:\windows\system32\dllcache\strmdll.dll
2009-08-10 11:07 337,408 -c------ c:\windows\system32\dllcache\netapi32.dll
2009-08-10 11:07 1,106,944 -c------ c:\windows\system32\dllcache\msxml3.dll
2009-08-10 11:07 <DIR> --dsh--- c:\documents and settings\ma\UserData
2009-08-10 11:06 1,203,922 -c------ c:\windows\system32\dllcache\sysmain.sdb
2009-08-10 11:06 2,560 -------- c:\windows\system32\xpsp4res.dll
2009-08-10 11:06 215,552 -c------ c:\windows\system32\dllcache\wordpad.exe
2009-08-10 11:06 <DIR> --d----- c:\windows\system32\PreInstall
2009-08-09 22:27 <DIR> --d----- C:\sa105v230
2009-08-09 22:24 <DIR> --d----- c:\windows\system32\SoftwareDistribution
2009-08-09 21:20 221,184 a------- c:\windows\system32\wmpns.dll
2009-08-09 21:19 <DIR> --d----- c:\documents and settings\ma\WINDOWS
2009-08-09 21:19 <DIR> --d----- c:\docume~1\ma\applic~1\You've Got Pictures Screensaver
2009-08-09 21:19 <DIR> --d----- c:\docume~1\ma\applic~1\Intuit
2009-08-09 21:19 <DIR> --d----- c:\docume~1\ma\applic~1\AOL
2009-08-09 21:19 <DIR> --d----- c:\program files\Atheros
2009-08-09 21:03 8,192 a------- c:\windows\REGLOCS.OLD
2009-08-09 21:01 61 a------- c:\windows\smscfg.ini
2009-08-09 21:00 94,263 a------- c:\windows\DLA.EXE
2009-08-09 21:00 88,704 a------- c:\windows\system32\drivers\DRVMCDB.SYS
2009-08-09 21:00 61,500 a------- c:\windows\system32\DLAAPI_W.DLL
2009-08-09 21:00 40,544 a------- c:\windows\system32\drivers\DRVNDDM.SYS
2009-08-09 21:00 22,684 a------- c:\windows\system32\drivers\DLARTL_N.SYS
2009-08-09 21:00 5,628 a------- c:\windows\system32\drivers\DLACDBHM.SYS
2009-08-09 21:00 <DIR> --d----- c:\windows\system32\DLA
2009-08-09 21:00 192,512 a------- c:\windows\system32\AdavVideoDec.dll
2009-08-09 21:00 126,976 a------- c:\windows\system32\AdavAudioDec.dll
2009-08-09 21:00 110,592 a------- c:\windows\system32\ArcSpl.ax
2009-08-09 21:00 48,128 a------- c:\windows\system32\mpgvideo.ax
2009-08-09 21:00 47,616 a------- c:\windows\system32\mpgaudio.ax
2009-08-09 20:58 212,480 a------- c:\windows\PCDLIB32.DLL
2009-08-09 20:57 139,264 a------- c:\windows\system32\PhotoBase Screen Saver.scr
2009-08-05 02:01 204,800 -c------ c:\windows\system32\dllcache\mswebdvd.dll

==================== Find3M ====================

2009-08-10 11:39 77,607 a------- c:\windows\pchealth\helpctr\offlinecache\index.dat
2009-08-09 21:19 17,801 a------- c:\windows\system32\drivers\AegisP.sys
2009-08-05 02:01 204,800 a------- c:\windows\system32\mswebdvd.dll
2009-07-17 12:01 58,880 a------- c:\windows\system32\atl.dll
2009-07-13 10:08 286,720 a------- c:\windows\system32\wmpdxm.dll
2009-06-29 09:12 827,392 a------- c:\windows\system32\wininet.dll
2009-06-29 09:12 78,336 a------- c:\windows\system32\ieencode.dll
2009-06-29 09:12 17,408 a------- c:\windows\system32\corpol.dll
2009-06-16 07:36 119,808 a------- c:\windows\system32\t2embed.dll
2009-06-16 07:36 81,920 a------- c:\windows\system32\fontsub.dll
2009-06-12 05:31 76,288 a------- c:\windows\system32\telnet.exe
2009-06-10 09:19 2,066,432 a------- c:\windows\system32\mstscax.dll
2009-06-10 07:13 84,992 a------- c:\windows\system32\avifil32.dll
2009-06-09 23:14 132,096 a------- c:\windows\system32\wkssvc.dll
2009-06-03 12:09 1,291,264 a------- c:\windows\system32\quartz.dll

============= FINISH: 12:53:52.23 ===============

Attached Files



BC AdBot (Login to Remove)

 


#2 Buckeye_Sam

Buckeye_Sam

    Malware Expert


  • Members
  • 17,382 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Pickerington, Ohio
  • Local time:07:03 PM

Posted 18 August 2009 - 01:01 PM

Hello! :thumbup2:
My name is Sam and I will be helping you.

In order to see what's going on with your computer I will ask for you to post various logs from the tools that we will use to resolve your issue. Please also share with me any information about how your computer is reacting and behaving each step of the way as we work through this process.


Please download Malwarebytes Anti-Malware and save it to your desktop.
alternate download link 1
alternate download link 2
  • Make sure you are connected to the Internet.
  • Double-click on Download_mbam-setup.exe to install the application.
  • When the installation begins, follow the prompts and do not make any changes to default settings.
  • When installation has finished, make sure you leave both of these checked:
    • Update Malwarebytes' Anti-Malware
    • Launch Malwarebytes' Anti-Malware
  • Then click Finish.
  • MBAM will automatically start and you will be asked to update the program before performing a scan. If an update is found, the program will automatically update itself. Press the OK button to close that box and continue. If you encounter any problems while downloading the updates, manually download them from here and just double-click on mbam-rules.exe to install.
  • On the Scanner tab:
    • Make sure the "Perform Quick Scan" option is selected.
    • Then click on the Scan button.
  • If asked to select the drives to scan, leave all the drives selected and click on the Start Scan button.
  • The scan will begin and "Scan in progress" will show at the top. It may take some time to complete so please be patient.
  • When the scan is finished, a message box will say "The scan completed successfully. Click 'Show Results' to display all objects found".
  • Click OK to close the message box and continue with the removal process.
  • Back at the main Scanner screen, click on the Show Results button to see a list of any malware that was found.
  • Make sure that everything is checked, and click Remove Selected.
  • When removal is completed, a log report will open in Notepad and you may be prompted to restart your computer. (see Note below)
  • The log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
  • Copy and paste the contents of that report in your next reply and exit MBAM.
Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.




We need to create an OTL Report
  • Please download OTL from here
  • Save it to your desktop.
  • Double click on the icon on your desktop.
  • Click the "Scan All Users" checkbox.
  • Push the "Run Scan" button.
  • The scan should take just a few minutes.
  • Copy the log that opens up and paste it back here in your next reply.

Posted Image If I have helped you in any way, please consider a donation to help me continue the fight against malware.


Failing to respond back to the person that is giving up their own time to help you not only is insensitive and disrespectful, but it guarantees that you will never receive help from me again. Please thank your helpers and there will always be help here when you need it!


========================================================




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users