Do you recognize this file?
C:\Program Files\kri060RWL_174801004.jpg
No, but it is, umm, interesting!
Results of file scan:
ERROR: Can't find upload file!
Results of file scan:
- C:\Program Files\kri060RWL_174801004.jpg
VirSCAN.org Scanned Report :
Scanned time : 2010/09/17 09:00:44 (CDT)
Scanner results: Scanners did not find malware!
File Name : kri060RWL_174801004.jpg
File Size : 251073 byte
File Type : JPEG image data, JFIF standard 1.02
MD5 : 51d56816cb93675849d8c84ec9c1f990
SHA1 : e1701b393d0c6ed185ffc31f2094e89a776acc4a
Online report :
http://virscan.org/r...f616c56d9c.htmlScanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 5.0.0.19 20100917005258 2010-09-17 40.10 -
AhnLab V3 2010.09.16.01 2010.09.16 2010-09-16 40.09 -
AntiVir 8.2.4.52 7.10.11.200 2010-09-17 0.33 -
Antiy 2.0.18 20100917.5185283 2010-09-17 0.13 -
Arcavir 2009 201006281601 2010-06-28 0.02 -
Authentium 5.1.1 201009170229 2010-09-17 1.32 -
AVAST! 4.7.4 100917-0 2010-09-17 0.02 -
AVG 8.5.850 271.1.1/3140 2010-09-17 0.24 -
BitDefender 7.90123.6387732 7.33928 2010-09-17 4.62 -
ClamAV 0.96.1 11953 2010-09-17 0.02 -
Comodo 4.0 6103 2010-09-16 40.09 -
CP Secure 1.3.0.5 2010.09.17 2010-09-17 0.01 -
Dr.Web 5.0.2.3300 2010.09.17 2010-09-17 11.00 -
F-Prot 4.4.4.56 20100916 2010-09-16 1.27 -
F-Secure 7.02.73807 2010.09.17.06 2010-09-17 10.75 -
Fortinet 4.1.143 12.359 2010-09-16 27.57 -
GData 21.852/21.338 20100917 2010-09-17 40.09 -
ViRobot 20100916 2010.09.16 2010-09-16 37.43 -
Ikarus T3.1.32.15.0 2010.09.17.76748 2010-09-17 7.76 -
JiangMin 13.0.900 2010.08.30 2010-08-30 27.55 -
Kaspersky 5.5.10 2010.09.17 2010-09-17 0.12 -
KingSoft 2009.2.5.15 2010.9.17.18 2010-09-17 40.09 -
McAfee 5400.1158 6108 2010-09-16 18.42 -
Microsoft 1.6201 2010.09.17 2010-09-17 40.09 -
Norman 6.06.05 6.06.00 2010-09-17 8.02 -
Panda 9.05.01 2010.09.16 2010-09-16 40.11 -
Trend Micro 9.120-1004 7.468.07 2010-09-17 0.02 -
Quick Heal 11.00 2010.09.17 2010-09-17 40.09 -
Rising 20.0 22.65.03.04 2010-09-16 40.10 -
Sophos 3.11.2 4.57 2010-09-17 4.12 -
Sunbelt 3.9.2447.2 6884 2010-09-16 40.09 -
Symantec 1.3.0.24 20100916.002 2010-09-16 0.05 -
nProtect 20100916.02 9122264 2010-09-16 40.09 -
The Hacker 6.7.0.0 v00020 2010-09-16 40.09 -
VBA32 3.12.14.0 20100917.0843 2010-09-17 3.39 -
VirusBuster 4.5.11.10 10.128.4/2050751 2010-09-17 2.44 -
The content of the fixlog from OTLin step 2. All processes killed
========== OTL ==========
HKU\S-1-5-21-682003330-1004336348-2146735463-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyOverride| /E : value set successfully!
HKU\S-1-5-21-682003330-1004336348-2146735463-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer| /E : value set successfully!
Registry value HKEY_USERS\S-1-5-21-682003330-1004336348-2146735463-1003\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\\{A057A204-BACC-4D26-9990-79A187E2698E} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A057A204-BACC-4D26-9990-79A187E2698E}\ not found.
Registry value HKEY_USERS\S-1-5-21-682003330-1004336348-2146735463-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\\ deleted successfully.
C:\Documents and Settings\Owner.JEFF-UFSIEVRDBX\Application Data\fljmkcfvq folder moved successfully.
C:\Documents and Settings\Owner.JEFF-UFSIEVRDBX\Application Data\uTorrent folder moved successfully.
========== COMMANDS ==========
[EMPTYTEMP]
User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: All Users
User: All Users.WINDOWS
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Default User.WINDOWS
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
User: Jeff
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Jeff Carlson
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: LocalService.NT AUTHORITY
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32902 bytes
->Flash cache emptied: 0 bytes
User: log
User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: NetworkService.NT AUTHORITY
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32902 bytes
User: Owner
User: Owner.JEFF-UFSIEVRDBX
->Temp folder emptied: 4356167 bytes
->Temporary Internet Files folder emptied: 1538278 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 95127797 bytes
->Google Chrome cache emptied: 0 bytes
->Flash cache emptied: 3816 bytes
User: OWNER~1~JEF
User: Pat Franz
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Temporary Internet Files
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 664 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 96.00 mb
[EMPTYFLASH]
User: Administrator
User: All Users
User: All Users.WINDOWS
User: Default User
User: Default User.WINDOWS
User: Jeff
User: Jeff Carlson
->Flash cache emptied: 0 bytes
User: LocalService
->Flash cache emptied: 0 bytes
User: LocalService.NT AUTHORITY
->Flash cache emptied: 0 bytes
User: log
User: NetworkService
User: NetworkService.NT AUTHORITY
User: Owner
User: Owner.JEFF-UFSIEVRDBX
->Flash cache emptied: 0 bytes
User: OWNER~1~JEF
User: Pat Franz
User: Temporary Internet Files
Total Flash Files Cleaned = 0.00 mb
OTL by OldTimer - Version 3.2.12.1 log created on 09172010_092627
Files\Folders moved on Reboot...
Registry entries deleted on Reboot...
The content of the report from MBAM in step 3.Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org
Database version: 4639
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
9/17/2010 9:38:07 AM
mbam-log-2010-09-17 (09-38-07).txt
Scan type: Quick scan
Objects scanned: 213997
Time elapsed: 7 minute(s), 41 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)