09-11-2010, 04:08 PM
Ok here we go:
It seems to have worked. Hope it has.
Spoiler (Click to View)
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org
Database version: 4595
Windows 6.1.7600
Internet Explorer 8.0.7600.16385
11/09/2010 23:57:26
mbam-log-2010-09-11 (23-57-26).txt
Scan type: Full scan (C:\|Q:\|)
Objects scanned: 293033
Time elapsed: 52 minute(s), 53 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 3
Registry Values Infected: 3
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 17
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\OTGV1DNWQQ (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\XML (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\YXE7DXCQ37 (Trojan.FakeAlert) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mediafix70700en02.exe (Rogue.Installer) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\{499de96b-3e13-7efb-e0c3-14c2227ccf07} (Trojan.ZbotR.Gen) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\yxe7dxcq37 (Trojan.FakeAlert) -> Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
C:\Users\Peter\AppData\Roaming\2E6C5AEB0A74A68919A38810C4B77857\mediafix70700en02.exe (Rogue.Installer) -> Quarantined and deleted successfully.
C:\Users\Peter\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XRW71MNW\mediafix70700en02[1].exe (Rogue.Installer) -> Quarantined and deleted successfully.
C:\Users\Peter\AppData\Local\Temp\1biq.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Users\Peter\AppData\Local\Temp\Dhb.exe (Spyware.Zbot.SI) -> Quarantined and deleted successfully.
C:\Users\Peter\AppData\Local\Temp\Dhc.exe (Spyware.Zbot.SI) -> Quarantined and deleted successfully.
C:\Users\Peter\AppData\Local\Temp\Dhd.exe (Spyware.Zbot.SI) -> Quarantined and deleted successfully.
C:\Users\Peter\AppData\Local\Temp\Dhe.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Users\Peter\AppData\Local\Temp\Dhf.exe (Trojan.Downloader) -> Delete on reboot.
C:\Users\Peter\AppData\Local\Temp\Dhg.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Users\Peter\AppData\Local\Temp\onxwrcmsea.exe (Rootkit.Dropper) -> Quarantined and deleted successfully.
C:\Users\Public\Documents\Server\sphlp.dll (Spyware.Passwords) -> Quarantined and deleted successfully.
C:\Users\Peter\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Antimalware Doctor.lnk (Rogue.AntimalwareDoctor) -> Quarantined and deleted successfully.
C:\Users\Peter\AppData\Local\Temp\0.5303293974979855.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\Windows\Tasks\{22116563-108C-42c0-A7CE-60161B75E508}.job (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Users\Peter\AppData\Roaming\Huga\ovse.exe (Trojan.ZbotR.Gen) -> Quarantined and deleted successfully.
C:\Users\Peter\AppData\Local\Temp\Dhh.exe (Trojan.FakeAlert) -> Delete on reboot.
www.malwarebytes.org
Database version: 4595
Windows 6.1.7600
Internet Explorer 8.0.7600.16385
11/09/2010 23:57:26
mbam-log-2010-09-11 (23-57-26).txt
Scan type: Full scan (C:\|Q:\|)
Objects scanned: 293033
Time elapsed: 52 minute(s), 53 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 3
Registry Values Infected: 3
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 17
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\OTGV1DNWQQ (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\XML (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\YXE7DXCQ37 (Trojan.FakeAlert) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mediafix70700en02.exe (Rogue.Installer) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\{499de96b-3e13-7efb-e0c3-14c2227ccf07} (Trojan.ZbotR.Gen) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\yxe7dxcq37 (Trojan.FakeAlert) -> Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
C:\Users\Peter\AppData\Roaming\2E6C5AEB0A74A68919A38810C4B77857\mediafix70700en02.exe (Rogue.Installer) -> Quarantined and deleted successfully.
C:\Users\Peter\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XRW71MNW\mediafix70700en02[1].exe (Rogue.Installer) -> Quarantined and deleted successfully.
C:\Users\Peter\AppData\Local\Temp\1biq.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Users\Peter\AppData\Local\Temp\Dhb.exe (Spyware.Zbot.SI) -> Quarantined and deleted successfully.
C:\Users\Peter\AppData\Local\Temp\Dhc.exe (Spyware.Zbot.SI) -> Quarantined and deleted successfully.
C:\Users\Peter\AppData\Local\Temp\Dhd.exe (Spyware.Zbot.SI) -> Quarantined and deleted successfully.
C:\Users\Peter\AppData\Local\Temp\Dhe.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Users\Peter\AppData\Local\Temp\Dhf.exe (Trojan.Downloader) -> Delete on reboot.
C:\Users\Peter\AppData\Local\Temp\Dhg.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Users\Peter\AppData\Local\Temp\onxwrcmsea.exe (Rootkit.Dropper) -> Quarantined and deleted successfully.
C:\Users\Public\Documents\Server\sphlp.dll (Spyware.Passwords) -> Quarantined and deleted successfully.
C:\Users\Peter\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Antimalware Doctor.lnk (Rogue.AntimalwareDoctor) -> Quarantined and deleted successfully.
C:\Users\Peter\AppData\Local\Temp\0.5303293974979855.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\Windows\Tasks\{22116563-108C-42c0-A7CE-60161B75E508}.job (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Users\Peter\AppData\Roaming\Huga\ovse.exe (Trojan.ZbotR.Gen) -> Quarantined and deleted successfully.
C:\Users\Peter\AppData\Local\Temp\Dhh.exe (Trojan.FakeAlert) -> Delete on reboot.
It seems to have worked. Hope it has.