Thanks for responding:)
Heres the copy of my log:
Malwarebytes' Anti-Malware 1.41
Database version: 2977
Windows 6.1.7100
18/10/2009 3:09:46 AM
mbam-log-2009-10-18 (03-09-46).txt
Scan type: Quick Scan
Objects scanned: 98963
Time elapsed: 6 minute(s), 43 second(s)
Memory Processes Infected: 4
Memory Modules Infected: 0
Registry Keys Infected: 8
Registry Values Infected: 7
Registry Data Items Infected: 2
Folders Infected: 5
Files Infected: 29
Memory Processes Infected:
C:\Users\mrslippy\AppData\Local\Temp\lsass.exe (Trojan.Agent) -> Unloaded process successfully.
C:\Users\mrslippy\AppData\Local\Temp\services.exe (Password.Stealer) -> Unloaded process successfully.
C:\Users\mrslippy\AppData\Local\Temp\taskmgr.exe (Trojan.Downloader) -> Unloaded process successfully.
C:\Windows\msb.exe (Trojan.Agent) -> Unloaded process successfully.
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CLASSES_ROOT\CLSID\{48444dbe-0486-4a38-b803-413739dc584d} (Trojan.FakeAlert.H) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{014da6c1-189f-421a-88cd-07cfe51cff10} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{014da6c9-189f-421a-88cd-07cfe51cff10} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\NordBull (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\QuickyPlaeyrSoft (Trojan.DNSChanger) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\XML (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\MySearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\poprock (Trojan.Downloader) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\streambuffercomposerecordingobj (Trojan.FakeAlert.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\calc (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\WINID (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\poprock (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Login Software 2009 (Trojan.Agent) -> Delete on reboot.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Yjafosi8kdf98winmdkmnkmfnwe (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\calc (Trojan.Agent) -> Quarantined and deleted successfully.
Registry Data Items Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFolderOptions (Hijack.FolderOptions) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools (Hijack.Regedit) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
Folders Infected:
C:\Program Files\MySearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MySearch\bar (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MySearch\bar\History (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MySearch\bar\Settings (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Users\mrslippy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\QuickyPlaeyr (Trojan.DNSChanger) -> Quarantined and deleted successfully.
Files Infected:
C:\Program Files\Common Files\StreamBufferComposeRecordingObj\StreamBufferComposeRecordingObj.dll (Trojan.FakeAlert.H) -> Quarantined and deleted successfully.
C:\biabqjx.exe (Trojan.Zbot) -> Quarantined and deleted successfully.
C:\Users\mrslippy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\scandisk.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Windows\Temp\872934.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Windows\Temp\TMP000000A41FCAFF587307B877 (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\Windows\Temp\VRT708D.tmp (Malware.Tool) -> Quarantined and deleted successfully.
C:\Windows\Temp\VRT8D13.tmp (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Users\mrslippy\AppData\Local\Temp\rundll32.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Users\mrslippy\ntuser.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\MySearch\bar\History\search2 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MySearch\bar\Settings\prevcfg2.htm (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Users\mrslippy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\scandisk.lnk (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\System32\calc.dll (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Users\mrslippy\AppData\Local\Temp\csrss.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Users\mrslippy\AppData\Local\Temp\lsass.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Users\mrslippy\AppData\Local\Temp\nsrbgxod.bak (Trojan.Agent) -> Delete on reboot.
C:\Users\mrslippy\AppData\Local\Temp\services.exe (Password.Stealer) -> Quarantined and deleted successfully.
C:\Users\mrslippy\AppData\Local\Temp\svchost.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Users\mrslippy\AppData\Local\Temp\taskmgr.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Users\mrslippy\AppData\Local\Temp\win32.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Users\mrslippy\AppData\Local\Temp\winlogon.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Windows\msa.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Windows\msb.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Windows\Tasks\{7B02EF0B-A410-4938-8480-9BA26420A627}.job (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\Tasks\{BB65B0FB-5712-401b-B616-E69AC55E2757}.job (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Users\mrslippy\AppData\Local\Temp\d.exe (Trojan.Downloader) -> Delete on reboot.
C:\Users\mrslippy\AppData\Local\Temp\n1j9dg.exe (Trojan.Agent) -> Delete on reboot.
C:\Users\mrslippy\AppData\Local\Temp\drweb.exe (Trojan.Agent) -> Delete on reboot.
C:\Users\mrslippy\AppData\Local\Temp\jisfije9fjoiee.tmp (Trojan.Downloader) -> Quarantined and deleted successfully.
Not sure if its useful to report, but upon reboot, two dlls were prevented running 'ntuser.dll' and 'calc.dll'. Theres had a habit of setting Avast! off multiple times before, although the option recommended 'move to chest' would not get rid of it, as it would keep popping up the same notification until ignored. The infection there seemed to be the Win32:Trojan-gen. Avast! popped up and 'move to chest' was applied after reboot, this time they havent popped up again, but im not convinced its been completely removed. Also Avast has popped up once since with a different virus, but it seemed to successfully apply the 'move to chest' option. If it crops up again I will include it here.
Thanks in advance:)
Edited by mrslippy, 18 October 2009 - 02:25 AM.