Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Two Windows 7 PCs Appear Infected


  • Please log in to reply

#1
galeha

galeha

    New Member

  • Member
  • Pip
  • 2 posts
I'm running Windows 7 Pro 32 bit on my laptop and 64 bit on my desktop. Recently I started losing access to webpages. Windows Update and Yahoo Mail are examples of two sites that worked correctly and then suddenly the browser just hangs when trying to access. I've scanned for Malware, but not sure where to go from here. Any help is definitely appreciated!!!

Gary

--- OTL Log from laptop ---

OTL Extras logfile created on: 4/21/2011 11:07:02 PM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\Gary\Desktop
An unknown product (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 70.00% Memory free
6.00 Gb Paging File | 5.00 Gb Available in Paging File | 84.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 220.58 Gb Total Space | 137.34 Gb Free Space | 62.26% Space Free | Partition Type: NTFS
Drive D: | 9.77 Gb Total Space | 5.57 Gb Free Space | 57.07% Space Free | Partition Type: NTFS

Computer Name: GARY-LAPTOP | User Name: Gary | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile [edit] -- Reg Error: Key error.
htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{4998FF95-709A-430A-B104-92A009ABB848}" = QuickConnect
"{685A56F8-75B6-44AD-B3DA-FB0A3266B47C}" = Adobe Flash Player 9 ActiveX
"{9692FD03-6662-4E62-B08C-30DFF51651E1}" = Actiontec Gateway
"{971B9FC4-84A4-4513-AAD0-E2898CBCD42E}" = QuickConnect
"{C96FF998-45BD-411E-9253-B7F2660FE280}" = Qwest Installer
"ARO 2011_is1" = ARO 2011
"Creative OEM002" = Laptop Integrated Webcam Driver (1.04.01.1011)
"HDMI" = Intel® Graphics Media Accelerator Driver
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"NAV" = Norton AntiVirus
"QwestQuickCare_is1" = Qwest Quickcare 2.7
"TVWiz" = Intel® TV Wizard

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 4/20/2011 9:43:59 PM | Computer Name = Gary-Laptop | Source = Software Protection Platform Service | ID = 1017
Description = Installation of the Proof of Purchase failed. 0xC004F050 Partial Pkey=CG7MR
ACID=?
Detailed
Error[?]

Error - 4/21/2011 9:54:11 PM | Computer Name = Gary-Laptop | Source = VSS | ID = 8194
Description =

[ System Events ]
Error - 4/20/2011 9:49:22 PM | Computer Name = Gary-Laptop | Source = Service Control Manager | ID = 7030
Description = The SupportSoft Sprocket Service (quickcare) service is marked as
an interactive service. However, the system is configured to not allow interactive
services. This service may not function properly.

Error - 4/20/2011 9:49:23 PM | Computer Name = Gary-Laptop | Source = Service Control Manager | ID = 7030
Description = The SupportSoft Repair Service (quickcare) service is marked as an
interactive service. However, the system is configured to not allow interactive
services. This service may not function properly.

Error - 4/21/2011 12:11:21 AM | Computer Name = Gary-Laptop | Source = Microsoft-Windows-HAL | ID = 12
Description = The platform firmware has corrupted memory across the previous system
power transition. Please check for updated firmware for your system.

Error - 4/21/2011 6:11:23 AM | Computer Name = Gary-Laptop | Source = Service Control Manager | ID = 7011
Description = A timeout (30000 milliseconds) was reached while waiting for a transaction
response from the NAV service.

Error - 4/21/2011 8:36:03 AM | Computer Name = Gary-Laptop | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x80070643: Security Update for Windows 7 (KB2385678).

Error - 4/21/2011 8:36:03 AM | Computer Name = Gary-Laptop | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x80070643: Security Update for Windows 7 (KB2286198).

Error - 4/21/2011 8:36:03 AM | Computer Name = Gary-Laptop | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x80070643: Security Update for Windows 7 (KB2483614).

Error - 4/21/2011 8:36:03 AM | Computer Name = Gary-Laptop | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x80070643: Update for Windows 7 (KB2454826).

Error - 4/21/2011 8:36:03 AM | Computer Name = Gary-Laptop | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x80070643: Update for Windows 7 (KB979538).

Error - 4/21/2011 9:37:38 PM | Computer Name = Gary-Laptop | Source = Service Control Manager | ID = 7023
Description = The Windows Modules Installer service terminated with the following
error: %%16405


< End of report >
  • 0

Advertisements


#2
galeha

galeha

    New Member

  • Topic Starter
  • Member
  • Pip
  • 2 posts
Formatted drives and reinstalled Windows. Virus gone for now.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP