I have Malwarebytes
I Have spybot
I have CC cleaner
Left my computer on overnight, this morning any .exe I attempt cannot be executed because .exe infected.
Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!
Edited by duke0466, 20 February 2010 - 11:22 AM.
Edited by duke0466, 20 February 2010 - 11:28 AM.
Edited by duke0466, 20 February 2010 - 12:26 PM.
[Unregister Dlls] [Processes - Safe List] YY -> fcvlsftav.exe -> C:\Documents and Settings\NetworkService\Local Settings\Application Data\sqnypu\fcvlsftav.exe [Registry - Safe List] < Internet Explorer Settings [HKEY_USERS\.DEFAULT\] > -> YN -> HKEY_USERS\.DEFAULT\: "ProxyEnable" -> 1 YN -> HKEY_USERS\.DEFAULT\: "ProxyServer" -> http=127.0.0.1:5555 < Internet Explorer Settings [HKEY_USERS\S-1-5-18\] > -> YN -> HKEY_USERS\S-1-5-18\: "ProxyEnable" -> 1 YN -> HKEY_USERS\S-1-5-18\: "ProxyServer" -> http=127.0.0.1:5555 < HOSTS File > ([2009/11/16 18:50:05 | 000,351,393 | R--- | M] - 12096 lines) -> C:\WINDOWS\system32\drivers\etc\hosts YN -> 91.212.127.226 osguard-pro.microsoft.com -> YN -> 91.212.127.226 osguard-pro.com -> YN -> 91.212.127.226 www.osguard-pro.com -> < Internet Explorer ToolBars [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar YN -> "Locked" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] < Run [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run YY -> "gekjxsuu" -> C:\Documents and Settings\NetworkService\Local Settings\Application Data\sqnypu\fcvlsftav.exe [C:\Documents and Settings\NetworkService\Local Settings\Application Data\sqnypu\fcvlsftav.exe] YY -> "Tzibidetay" -> C:\WINDOWS\uduxivuxeruxile.DLL [rundll32.exe "C:\WINDOWS\uduxivuxeruxile.dll",Startup] < Run [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run YY -> "gekjxsuu" -> C:\Documents and Settings\NetworkService\Local Settings\Application Data\sqnypu\fcvlsftav.exe [C:\Documents and Settings\NetworkService\Local Settings\Application Data\sqnypu\fcvlsftav.exe] < Run [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run YY -> "gekjxsuu" -> C:\Documents and Settings\NetworkService\Local Settings\Application Data\sqnypu\fcvlsftav.exe [C:\Documents and Settings\NetworkService\Local Settings\Application Data\sqnypu\fcvlsftav.exe] < Trusted Sites Domains [HKEY_USERS\S-1-5-21-1446883429-823023976-1181295350-1008\] > -> HKEY_USERS\S-1-5-21-1446883429-823023976-1181295350-1008\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ YN -> www.update_microsoft.com [https] -> Trusted sites < Name Servers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\ YN -> NameServer -> 93.188.165.99,93.188.161.88 < Name Servers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\ YN -> {2DE162A0-1EFE-4005-AC32-A42AE97CE852}\\NameServer -> 93.188.165.99,93.188.161.88 (Dell Wireless 1390 WLAN Mini-Card) YN -> {6CA486CD-7FC2-434D-903C-92E78AF4E34B}\\NameServer -> 93.188.165.99,93.188.161.88 (Broadcom 440x 10/100 Integrated Controller) < Winlogon settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon *UserInit* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit YY -> C:\WINDOWS\system32\sdra64.exe -> C:\WINDOWS\system32\sdra64.exe < Winlogon settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon < SSODL [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad YN -> "{fbeb8a05-beee-4442-804e-409d6c4515e9}" [HKLM] -> Reg Error: Key error. [CDBurn] [Files/Folders - Created Within 30 Days] NY -> sqnypu -> C:\Documents and Settings\NetworkService\Local Settings\Application Data\sqnypu NY -> cshost.dll -> C:\WINDOWS\System32\cshost.dll NY -> 93 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp NY -> 86 C:\WINDOWS\System32\dllcache\*.tmp files -> C:\WINDOWS\System32\dllcache\*.tmp [Files/Folders - Modified Within 30 Days] NY -> Bpudevevukovik.dat -> C:\WINDOWS\Bpudevevukovik.dat NY -> Wtuxejefifinoh.bin -> C:\WINDOWS\Wtuxejefifinoh.bin NY -> wklnhst.dat -> C:\Documents and Settings\earl.DDZQW8F1\Application Data\wklnhst.dat NY -> 93 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp NY -> 86 C:\WINDOWS\System32\dllcache\*.tmp files -> C:\WINDOWS\System32\dllcache\*.tmp NY -> 400 C:\Documents and Settings\earl.DDZQW8F1\Local Settings\Temp\*.tmp files -> C:\Documents and Settings\earl.DDZQW8F1\Local Settings\Temp\*.tmp NY -> 381 C:\WINDOWS\Temp\*.tmp files -> C:\WINDOWS\Temp\*.tmp NY -> 1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp [Empty Temp Folders]
0 members, 0 guests, 0 anonymous users
Community Forum Software by IP.Board
Licensed to: Geeks to Go, Inc.