Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Infection!


  • This topic is locked This topic is locked

#1
Zylocks

Zylocks

    Member

  • Member
  • PipPipPip
  • 182 posts
Hello.

I am posting this via my brothers computer. I've always thought there was something iffy about it, its fairly new and I've always sensed there was something 'up' with it. I built it myself, so maybe I did something wrong, so I've always kind of wanted to do one of these HIJACK this logs with you guys, BUT now it's actually infected. There are strange pop up ads in random places, ie throughour Facebook, Wikipedia, and even when visiting this website! Aaaapparently it happened through facebook.

Anyways, I got him to run Avast. He has no other malaware removal programs, ie Ad-aware, or superantispyware, and I tried looking throughout the multiple guides on this forum but I couldn't find any recomendations. So he ran Avast, and found nothing. I then ran a OTL and have the log.


OTL logfile created on: 5/20/2011 7:06:10 PM - Run 2
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\Christian Agueci\Downloads
Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 66.00% Memory free
6.00 Gb Paging File | 5.00 Gb Available in Paging File | 83.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 297.99 Gb Total Space | 194.52 Gb Free Space | 65.28% Space Free | Partition Type: NTFS
Drive D: | 3.43 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: CHRISTIANAGUECI | User Name: Christian Agueci | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/05/20 19:05:43 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Users\Christian Agueci\Downloads\OTL.com
PRC - [2011/05/10 08:10:58 | 003,459,712 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\AvastUI.exe
PRC - [2011/02/26 01:33:07 | 002,614,784 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2009/07/13 21:14:42 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe


========== Modules (SafeList) ==========

MOD - [2011/05/20 19:05:43 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Users\Christian Agueci\Downloads\OTL.com
MOD - [2011/05/10 08:10:55 | 000,199,792 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\snxhk.dll
MOD - [2010/08/21 01:21:32 | 001,680,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll


========== Win32 Services (SafeList) ==========

SRV - [2011/05/14 05:43:17 | 000,403,240 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2011/05/10 08:10:57 | 000,042,184 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Antivirus)
SRV - [2010/04/30 23:30:10 | 001,343,400 | ---- | M] (Microsoft Corporation) [Unknown | Stopped] -- C:\Windows\System32\Wat\WatAdminSvc.exe -- (WatAdminSvc)
SRV - [2009/08/18 02:36:08 | 000,176,128 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\System32\atiesrxx.exe -- (AMD External Events Utility)
SRV - [2009/07/13 21:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009/07/13 21:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)


========== Driver Services (SafeList) ==========

DRV - [2011/05/10 08:03:54 | 000,441,176 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\System32\drivers\aswSnx.sys -- (aswSnx)
DRV - [2011/05/10 08:03:44 | 000,307,928 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswSP.sys -- (aswSP)
DRV - [2011/05/10 08:02:37 | 000,049,240 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswTdi.sys -- (aswTdi)
DRV - [2011/05/10 07:59:56 | 000,025,432 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswRdr.sys -- (aswRdr)
DRV - [2011/05/10 07:59:44 | 000,053,592 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\System32\drivers\aswMonFlt.sys -- (aswMonFlt)
DRV - [2011/05/10 07:59:35 | 000,019,544 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\System32\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV - [2009/08/18 03:48:06 | 004,994,560 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\atikmdag.sys -- (atikmdag)
DRV - [2009/07/13 19:51:11 | 000,034,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (WinUsb)
DRV - [2009/07/13 18:02:53 | 000,311,296 | ---- | M] (Marvell) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\yk62x86.sys -- (yukonw7)
DRV - [2004/08/13 09:56:20 | 000,005,810 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ASACPI.sys -- (MTsensor)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.babylo....19&affID=17160
IE - HKLM\..\URLSearchHook: {657E195F-066D-435C-92DB-7C261E6FE832} - Reg Error: Key error. File not found

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.musicfrost.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://ca.msn.com/?rd=1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = FF 2A 55 60 3F 03 CC 01 [binary data]
IE - HKCU\..\URLSearchHook: {657E195F-066D-435C-92DB-7C261E6FE832} - Reg Error: Key error. File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

FF - HKLM\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/04/30 15:58:47 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\ShopperReports3\bin\3.0.517.0\firefox\firefoxtoolbar\extensions [2011/01/06 18:24:13 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\ClickPotatoLite\bin\10.0.634.0\firefox\extensions [2011/01/06 18:24:16 | 000,000,000 | ---D | M]

[2010/04/29 22:15:53 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Christian Agueci\AppData\Roaming\Mozilla\Extensions
[2010/04/29 22:15:53 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Christian Agueci\AppData\Roaming\Mozilla\Extensions\[email protected]
[2011/04/29 17:07:50 | 000,002,423 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\babylon.xml

O1 HOSTS File: ([2009/06/10 17:39:37 | 000,000,824 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [BabylonToolbar] C:\Program Files\BabylonToolbar\BabylonToolbar\1.4.19.19\BabylonToolbarsrv.exe (Babylon Ltd.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Se&nd to OneNote - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} https://h20436.www2....re/HPDEXAXO.cab (HP Download Manager)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.m...ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\tbr {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\Program Files\Crawler\ctbr.dll (Crawler.com)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 17:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/05/20 18:23:28 | 000,441,176 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswSnx.sys
[2011/05/20 18:23:14 | 000,000,000 | ---D | C] -- C:\Users\Christian Agueci\Desktop\Virus stuff
[2011/05/15 00:30:47 | 000,000,000 | ---D | C] -- C:\Users\Christian Agueci\AppData\Roaming\Apple Computer
[2011/05/15 00:30:47 | 000,000,000 | ---D | C] -- C:\Users\Christian Agueci\AppData\Local\Apple Computer
[2011/05/15 00:30:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2011/05/15 00:30:24 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2011/05/15 00:30:24 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2011/05/15 00:30:24 | 000,000,000 | ---D | C] -- C:\ProgramData\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2011/05/15 00:29:04 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
[2011/05/15 00:28:57 | 000,000,000 | ---D | C] -- C:\Program Files\QuickTime
[2011/05/15 00:28:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Apple Computer
[2011/05/15 00:28:50 | 000,000,000 | ---D | C] -- C:\Users\Christian Agueci\AppData\Local\Apple
[2011/05/15 00:28:47 | 000,000,000 | ---D | C] -- C:\Program Files\Apple Software Update
[2011/05/15 00:28:25 | 000,000,000 | ---D | C] -- C:\Program Files\Bonjour
[2011/05/15 00:28:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Apple
[2011/05/15 00:28:19 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Apple
[2011/05/14 17:30:55 | 000,000,000 | ---D | C] -- C:\Program Files\ProfileStylez
[2011/05/12 22:40:46 | 000,000,000 | ---D | C] -- C:\Users\Christian Agueci\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2011/05/12 21:37:49 | 000,000,000 | ---D | C] -- C:\Users\Christian Agueci\MusicFrost
[2011/05/12 21:30:35 | 000,000,000 | ---D | C] -- C:\Program Files\MusicFrost
[2011/05/03 16:25:48 | 000,000,000 | ---D | C] -- C:\Users\Christian Agueci\Desktop\519 661-3800
[2011/04/29 17:09:07 | 000,000,000 | ---D | C] -- C:\Users\Christian Agueci\FrostWire
[2011/04/29 17:09:00 | 000,000,000 | ---D | C] -- C:\Program Files\PC Speed Up
[2011/04/29 17:08:54 | 000,000,000 | ---D | C] -- C:\Users\Christian Agueci\AppData\Roaming\OpenCandy
[2011/04/29 17:08:54 | 000,000,000 | ---D | C] -- C:\Users\Christian Agueci\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FrostWire
[2011/04/29 17:07:50 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
[2011/04/29 17:07:49 | 000,000,000 | ---D | C] -- C:\Program Files\BabylonToolbar
[2011/04/29 17:07:48 | 000,000,000 | ---D | C] -- C:\Users\Christian Agueci\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FoxTab Video To MP3 Converter
[2011/04/29 17:07:45 | 000,000,000 | ---D | C] -- C:\Program Files\FoxTabVideo2Mp3Converter
[2011/04/27 13:56:36 | 000,000,000 | ---D | C] -- C:\Firefox
[2011/04/21 20:04:31 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Steam
[2011/04/21 20:04:30 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam
[2011/04/21 20:04:30 | 000,000,000 | ---D | C] -- C:\Program Files\Steam
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/05/20 18:40:45 | 000,014,832 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/05/20 18:40:45 | 000,014,832 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/05/20 18:37:07 | 000,628,024 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2011/05/20 18:37:07 | 000,110,208 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2011/05/20 18:31:22 | 000,000,902 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/05/20 18:31:00 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011/05/20 18:30:57 | 2616,549,376 | -HS- | M] () -- C:\hiberfil.sys
[2011/05/20 18:28:00 | 000,000,906 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/05/20 18:23:28 | 000,002,577 | ---- | M] () -- C:\Windows\System32\config.nt
[2011/05/20 18:19:00 | 000,000,952 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-341658862-1420411492-1201545900-1001UA.job
[2011/05/19 09:19:00 | 000,000,900 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-341658862-1420411492-1201545900-1001Core.job
[2011/05/17 17:51:40 | 000,271,200 | ---- | M] () -- C:\Windows\System32\PnkBstrB.xtr
[2011/05/17 17:35:29 | 000,103,736 | ---- | M] () -- C:\Windows\System32\PnkBstrB.ex0
[2011/05/15 00:30:44 | 000,001,753 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
[2011/05/15 00:29:04 | 000,001,815 | ---- | M] () -- C:\Users\Public\Desktop\QuickTime Player.lnk
[2011/05/12 22:40:48 | 000,002,374 | ---- | M] () -- C:\Users\Christian Agueci\Desktop\Google Chrome.lnk
[2011/05/11 17:40:02 | 000,001,933 | ---- | M] () -- C:\Users\Public\Desktop\avast! Free Antivirus.lnk
[2011/05/10 08:10:59 | 000,040,112 | ---- | M] (AVAST Software) -- C:\Windows\avastSS.scr
[2011/05/10 08:10:55 | 000,199,304 | ---- | M] (AVAST Software) -- C:\Windows\System32\aswBoot.exe
[2011/05/10 08:03:54 | 000,441,176 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswSnx.sys
[2011/05/10 08:03:44 | 000,307,928 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswSP.sys
[2011/05/10 08:02:37 | 000,049,240 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswTdi.sys
[2011/05/10 07:59:56 | 000,025,432 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswRdr.sys
[2011/05/10 07:59:44 | 000,053,592 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswMonFlt.sys
[2011/05/10 07:59:35 | 000,019,544 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswFsBlk.sys
[2011/05/09 16:07:59 | 000,022,328 | ---- | M] () -- C:\Windows\System32\drivers\PnkBstrK.sys
[2011/04/29 17:08:54 | 000,001,219 | ---- | M] () -- C:\Users\Christian Agueci\Application Data\Microsoft\Internet Explorer\Quick Launch\FrostWire 4.21.5.lnk
[2011/04/29 17:08:54 | 000,001,195 | ---- | M] () -- C:\Users\Christian Agueci\Desktop\FrostWire 4.21.5.lnk
[2011/04/29 17:07:48 | 000,001,089 | ---- | M] () -- C:\Users\Christian Agueci\Desktop\FoxTab Video To MP3 Converter.lnk
[2011/04/21 20:35:41 | 000,000,213 | ---- | M] () -- C:\Users\Christian Agueci\Desktop\Team Fortress 2.url
[2011/04/21 20:07:28 | 000,000,875 | ---- | M] () -- C:\Users\Public\Desktop\Steam.lnk
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/05/15 00:30:44 | 000,001,753 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk
[2011/05/15 00:29:04 | 000,001,815 | ---- | C] () -- C:\Users\Public\Desktop\QuickTime Player.lnk
[2011/05/15 00:28:48 | 000,002,519 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
[2011/05/12 22:40:47 | 000,002,374 | ---- | C] () -- C:\Users\Christian Agueci\Desktop\Google Chrome.lnk
[2011/05/11 17:40:02 | 000,001,933 | ---- | C] () -- C:\Users\Public\Desktop\avast! Free Antivirus.lnk
[2011/04/29 17:08:54 | 000,001,219 | ---- | C] () -- C:\Users\Christian Agueci\Application Data\Microsoft\Internet Explorer\Quick Launch\FrostWire 4.21.5.lnk
[2011/04/29 17:08:54 | 000,001,195 | ---- | C] () -- C:\Users\Christian Agueci\Desktop\FrostWire 4.21.5.lnk
[2011/04/29 17:07:48 | 000,001,089 | ---- | C] () -- C:\Users\Christian Agueci\Desktop\FoxTab Video To MP3 Converter.lnk
[2011/04/21 20:35:41 | 000,000,213 | ---- | C] () -- C:\Users\Christian Agueci\Desktop\Team Fortress 2.url
[2011/04/21 20:04:30 | 000,000,875 | ---- | C] () -- C:\Users\Public\Desktop\Steam.lnk
[2010/07/13 22:47:14 | 000,022,328 | ---- | C] () -- C:\Windows\System32\drivers\PnkBstrK.sys
[2010/07/13 22:47:14 | 000,022,328 | ---- | C] () -- C:\Users\Christian Agueci\AppData\Roaming\PnkBstrK.sys
[2010/07/13 22:46:43 | 000,271,200 | ---- | C] () -- C:\Windows\System32\PnkBstrB.exe
[2010/07/13 22:46:42 | 000,075,136 | ---- | C] () -- C:\Windows\System32\PnkBstrA.exe
[2010/07/13 22:46:41 | 000,000,319 | ---- | C] () -- C:\Windows\game.ini
[2010/07/13 21:07:26 | 000,176,128 | ---- | C] () -- C:\Users\Christian Agueci\AppData\Roaming\chrtmp
[2010/04/30 16:11:27 | 000,013,898 | ---- | C] () -- C:\Windows\hpomdl19.dat.temp
[2010/04/30 15:56:02 | 000,221,408 | ---- | C] () -- C:\Windows\hpoins19.dat
[2010/04/30 15:56:02 | 000,013,898 | ---- | C] () -- C:\Windows\hpomdl19.dat
[2010/04/29 21:54:09 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2009/07/14 00:57:37 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009/07/14 00:33:53 | 000,408,384 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2009/07/13 22:05:48 | 000,628,024 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2009/07/13 22:05:48 | 000,291,294 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2009/07/13 22:05:48 | 000,110,208 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2009/07/13 22:05:48 | 000,031,548 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2009/07/13 22:05:05 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2009/07/13 22:04:11 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2009/07/13 19:55:01 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009/07/13 19:51:43 | 000,073,728 | ---- | C] () -- C:\Windows\System32\BthpanContextHandler.dll
[2009/07/13 19:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\System32\BWContextHandler.dll
[2009/06/18 19:29:04 | 000,197,654 | ---- | C] () -- C:\Windows\System32\atiicdxx.dat
[2009/06/10 17:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
[2009/02/18 17:55:22 | 000,294,912 | ---- | C] () -- C:\Windows\System32\ATIODE.exe
[2009/02/03 20:52:04 | 000,045,056 | ---- | C] () -- C:\Windows\System32\ATIODCLI.exe
[2004/08/13 09:56:20 | 000,005,810 | ---- | C] () -- C:\Windows\System32\drivers\ASACPI.sys

========== LOP Check ==========

[2011/01/06 18:24:15 | 000,000,000 | ---D | M] -- C:\Users\Christian Agueci\AppData\Roaming\ClickPotatoLite
[2011/05/18 21:06:49 | 000,000,000 | ---D | M] -- C:\Users\Christian Agueci\AppData\Roaming\FrostWire
[2011/02/23 03:38:12 | 000,000,000 | ---D | M] -- C:\Users\Christian Agueci\AppData\Roaming\LimeWire
[2011/04/29 17:08:54 | 000,000,000 | ---D | M] -- C:\Users\Christian Agueci\AppData\Roaming\OpenCandy
[2011/01/06 18:24:10 | 000,000,000 | ---D | M] -- C:\Users\Christian Agueci\AppData\Roaming\ShopperReports3
[2010/05/02 08:32:59 | 000,000,000 | ---D | M] -- C:\Users\Christian Agueci\AppData\Roaming\SMART Technologies Inc
[2011/01/15 23:03:23 | 000,000,000 | ---D | M] -- C:\Users\Christian Agueci\AppData\Roaming\Uniblue
[2011/05/17 23:57:15 | 000,000,000 | ---D | M] -- C:\Users\Christian Agueci\AppData\Roaming\uTorrent
[2011/03/31 14:08:30 | 000,032,566 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:D1B5B4F1
@Alternate Data Stream - 116 bytes -> C:\ProgramData\TEMP:BEB15613

< End of report >


Thanks guys. If I'm missing anything, just let me know.

-Adam
  • 0

Advertisements


#2
maliprog

maliprog

    Trusted Helper

  • Malware Removal
  • 6,172 posts
Hello Zylocks and welcome to G2G! :)

My nick is maliprog and I'll will be your technical support on this issue. Before we start please read my notes carefully:

NOTE:
  • Malware removal is NOT instantaneous, most infections require several courses of action to completely eradicate.
  • Absence of symptoms does not always mean the computer is clean
  • Kindly follow my instructions in the order posted. Order is crucial in cleaning process.
  • Please DO NOT run any scans or fix on your own without my direction.
  • Please read all of my response through at least once before attempting to follow the procedures described.
  • If there's anything you don't understand or isn't totally clear, please come back to me for clarification.
  • Please do not attach any log files to your replies unless I specifically ask you. Instead please copy and paste so as to include the log in your reply.
  • You must reply within 3 days or your topic will be closed

Step 1

Please close all running programs and Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following

    :OTL
    IE - HKLM\..\URLSearchHook: {657E195F-066D-435C-92DB-7C261E6FE832} - Reg Error: Key error. File not found
    IE - HKCU\..\URLSearchHook: {657E195F-066D-435C-92DB-7C261E6FE832} - Reg Error: Key error. File not found

    :Files
    ipconfig /flushdns /c

    :Commands
    [purity]
    [emptytemp]
    [emptyflash]
    [Reboot]

  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done
  • Post the fix log it produces in your next reply.

Step 2

Please read carefully and follow these steps.

Download TDSSKiller.zip from Kaspersky and save it to your Desktop.
  • Extract the zip file to its own folder.
  • Double click TDSSKiller.exe to run the program (Run as Administrator for Vista/Windows 7).
  • Click Start scan to start scanning.
  • If infection is detected, the default setting for "action" should be Cure
    • (If suspicious file is detected please click on it and change it to Skip).
  • Click Continue button
  • It may ask you to reboot the computer to complete the process. Click on Reboot Now.
    • If a reboot is required, the report can also be found in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please copy and paste the contents of that file here.
  • If no reboot is require, click on Report. A log file should appear. Please copy and paste the contents of that file here.

Step 3

Download aswMBR.exe ( 511KB ) to your desktop.

  • Double click the aswMBR.exe to run it
  • Click the "Scan" button to start scan
  • On completion of the scan click save log, save it to your desktop and post in your next reply

Step 4

Please don't forget to include these items in your reply:

  • OTL fix log
  • TDSSKiller log
  • aswMBR log
It would be helpful if you could post each log in separate post
  • 0

#3
Zylocks

Zylocks

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 182 posts
Hey maliprog, thanks for replying and helping out :)

I started Step 1, and ran into a small problem already.. After running OTL like you told me to, it told me to restart the computer. I clicked OK and nothing happened. I waited for a while, and nothing was happening, so I restarted it myself, but no log popped up. Is there any way to look at previous logs? Should I continue onto the next steps?

thanks,

-Adam
  • 0

#4
maliprog

maliprog

    Trusted Helper

  • Malware Removal
  • 6,172 posts
Hi Zylocks,

OTL fix log is located in C:\_OTL\MovedFiles.

You can continue with the steps.
  • 0

#5
Zylocks

Zylocks

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 182 posts
Ok, I don't know what the dealio is. There is no location C:\_OTL\movedfiles. I tried it again, and again, it asked me if I wanted to reboot. I clicked OK, and the computer did not reboot. I then manually rebooted, and was not shown any log file.

An update though. The strange popups are gone! That's good. Should I continue onto the next steps? Or try to find the ever elusive OTL log file..
  • 0

#6
maliprog

maliprog

    Trusted Helper

  • Malware Removal
  • 6,172 posts
Hi Zylocks,

Yes please. Do all steps and post logs here for me.
  • 0

#7
maliprog

maliprog

    Trusted Helper

  • Malware Removal
  • 6,172 posts
Due to lack of feedback, this topic has been closed.

If you need this topic reopened, please contact a staff member. This applies only to the original topic starter. Everyone else please begin a New Topic.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP