Explorer killed successfully
[Registry - Non-Microsoft Only]
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\BearFlix not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\HP Health Check Scheduler not found.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\36d04495 not found.
File C:\Users\problemseed\AppData\Local\Temp\juqsebmf.dll not found.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\BM35e37709 deleted successfully.
File C:\Users\problemseed\AppData\Local\Temp\jwsqroru.dll not found.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\cmds deleted successfully.
File C:\Users\problemseed\AppData\Local\Temp\fccaWnkl.dll not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{02478D38-C3F9-4efb-9B51-7695ECA05670}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}\ not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar\\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}\ not found.
[Files Created - Additional Folder Scans - Non-Microsoft Only]
C:\ProgramData\BM35e37709.xml moved successfully.
C:\ProgramData\pskt.ini moved successfully.
[Files/Folders - Modified Within 30 days]
File move failed. C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 scheduled to be moved on reboot.
File move failed. C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 scheduled to be moved on reboot.
File C:\Users\problemseed\AppData\Local\Temp\fccaWnkl.dll not found!
File C:\Users\problemseed\AppData\Local\Temp\juqsebmf.dll not found!
File C:\Users\problemseed\AppData\Local\Temp\jwsqroru.dll not found!
C:\Users\problemseed\AppData\Local\Temp\fmbesquj.ini moved successfully.
C:\Users\problemseed\AppData\Local\Temp\lknWaccf.ini moved successfully.
C:\Users\problemseed\AppData\Local\Temp\lknWaccf.ini2 moved successfully.
[Files Modified - Additional Folder Scans - Non-Microsoft Only]
File C:\ProgramData\BM35e37709.xml not found!
File C:\ProgramData\pskt.ini not found!
C:\Users\problemseed\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini moved successfully.
C:\Users\problemseed\AppData\Local\GDIPFONTCACHEV1.DAT moved successfully.
[Empty Temp Folders]
File delete failed. C:\Users\problemseed\AppData\Local\Temp\etilqs_R1eIp1yuV5XFhJd6wUgs scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Temporary Internet Files folder emptied.
User's Internet Explorer cache folder emptied.
Local Service Temp folder emptied.
Local Service Temporary Internet Files folder emptied.
File delete failed. C:\Windows\temp\mcafee_NptqUOxAKEyZpd6 scheduled to be deleted on reboot.
File delete failed. C:\Windows\temp\mcmsc_4kgScBFBMCFm0Jv scheduled to be deleted on reboot.
File delete failed. C:\Windows\temp\mcmsc_HNM0XUvELYKIrG1 scheduled to be deleted on reboot.
File delete failed. C:\Windows\temp\mcmsc_i2AzePOBEsvZwa5 scheduled to be deleted on reboot.
File delete failed. C:\Windows\temp\mcmsc_nVmR6I8gIT4MJOc scheduled to be deleted on reboot.
Windows Temp folder emptied.
File delete failed. C:\Users\problemseed\AppData\Local\Mozilla\Firefox\Profiles\59ddzqol.default\Cache\_CACHE_001_ scheduled to be deleted on reboot.
File delete failed. C:\Users\problemseed\AppData\Local\Mozilla\Firefox\Profiles\59ddzqol.default\Cache\_CACHE_002_ scheduled to be deleted on reboot.
File delete failed. C:\Users\problemseed\AppData\Local\Mozilla\Firefox\Profiles\59ddzqol.default\Cache\_CACHE_003_ scheduled to be deleted on reboot.
File delete failed. C:\Users\problemseed\AppData\Local\Mozilla\Firefox\Profiles\59ddzqol.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot.
File delete failed. C:\Users\problemseed\AppData\Local\Mozilla\Firefox\Profiles\59ddzqol.default\urlclassifier3.sqlite scheduled to be deleted on reboot.
File delete failed. C:\Users\problemseed\AppData\Local\Mozilla\Firefox\Profiles\59ddzqol.default\XUL.mfl scheduled to be deleted on reboot.
FireFox cache emptied.
RecycleBin -> emptied.
Explorer started successfully
< End of fix log >
OTScanIt by OldTimer - Version 1.0.16.2 fix logfile created on 07212008_205442
Files moved on Reboot...
File move failed. C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 scheduled to be moved on reboot.
File move failed. C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 scheduled to be moved on reboot.
File C:\Users\problemseed\AppData\Local\Temp\etilqs_R1eIp1yuV5XFhJd6wUgs not found!
File C:\Windows\temp\mcafee_NptqUOxAKEyZpd6 not found!
File C:\Windows\temp\mcmsc_4kgScBFBMCFm0Jv not found!
File C:\Windows\temp\mcmsc_HNM0XUvELYKIrG1 not found!
File C:\Windows\temp\mcmsc_i2AzePOBEsvZwa5 not found!
File C:\Windows\temp\mcmsc_nVmR6I8gIT4MJOc not found!
C:\Users\problemseed\AppData\Local\Mozilla\Firefox\Profiles\59ddzqol.default\Cache\_CACHE_001_ moved successfully.
C:\Users\problemseed\AppData\Local\Mozilla\Firefox\Profiles\59ddzqol.default\Cache\_CACHE_002_ moved successfully.
C:\Users\problemseed\AppData\Local\Mozilla\Firefox\Profiles\59ddzqol.default\Cache\_CACHE_003_ moved successfully.
C:\Users\problemseed\AppData\Local\Mozilla\Firefox\Profiles\59ddzqol.default\Cache\_CACHE_MAP_ moved successfully.
C:\Users\problemseed\AppData\Local\Mozilla\Firefox\Profiles\59ddzqol.default\urlclassifier3.sqlite moved successfully.
C:\Users\problemseed\AppData\Local\Mozilla\Firefox\Profiles\59ddzqol.default\XUL.mfl moved successfully.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:57:06 AM, on 7/22/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16681)
Boot mode: Normal
Running processes:
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://comcast.net/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
O2 - BHO: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~1\COMCAS~1.DLL
O3 - Toolbar: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~1\COMCAS~1.DLL
O4 - HKUS\S-1-5-20\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'NETWORK SERVICE')
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
--
End of file - 2082 bytes
Malwarebytes' Anti-Malware 1.22
Database version: 977
Windows 6.0.6000
9:12:43 PM 7/21/2008
mbam-log-7-21-2008 (21-12-43).txt
Scan type: Quick Scan
Objects scanned: 34355
Time elapsed: 4 minute(s), 23 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 2
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\MS Juan (Trojan.Vundo) -> Quarantined and deleted successfully.
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)