greggacunn
Posts: 11 +0
I have completed the 8 steps and am attaching the appropriate logs. This was on my wife's computer. I would like to know if it is now clean.
Thanks a ton.
Gregg
Thanks a ton.
Gregg
File::
c:\windows\SYSTEM32\7F0D9A8BE7.sys
c:\windows\SYSTEM32\E78B9A0D7F.sys
Folder::
c:\documents and settings\Pat Cunningham\Local Settings\Application Data\Trend Micro
c:\documents and settings\All Users\Application Data\McAfee.com
c:\program files\McAfee.com
Registry::
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=-
Hahaha....I'm sorry for your losssort of like a bad hand of blackjack where I'm sitting pretty with a 20 and the dealer draws into a 5 card 21.
:OTL
SRV - File not found [Disabled | Stopped] -- -- (Iomega Activity Disk2)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\DRIVERS\wanatw4.sys -- (wanatw) WAN Miniport (ATW)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\DRIVERS\wATV03nt.sys -- (iAimTV2)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\Drivers\CBPMp50.sys -- (CBPMp50)
DRV - File not found [Kernel | On_Demand | Running] -- C:\DOCUME~1\PATCUN~1\LOCALS~1\Temp\catchme.sys -- (catchme)
O16 - DPF: {640B39C1-D713-464F-92C3-75BD972B95EE} http://sidestep.com/get/k00719/sb02a.cab (Reg Error: Key error.)
O16 - DPF: {31435657-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/e/2/f/e2fcec4b-6c8b-48b7-adab-ab9c403a978f/wvc1dmo.cab (Reg Error: Key error.)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
[2010/07/01 13:13:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\RegSERVO
[2010/07/01 13:13:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\RegSERVO
[2005/10/09 14:47:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Viewpoint
:Services
:Reg
:Files
:Commands
[purity]
[emptytemp]
[emptyflash]
[resethosts]
[Reboot]
Just read at my link.Any last words of wisdom on how to not get hit again?