Kendra Owen
Posts: 10 +0
ok here are the logs. (Note I will be starting another post on my own computer, mine is just sort of scheduled maintenance, this is my kids computer)
MBAM log:
Malwarebytes Anti-Malware (Trial) 1.61.0.1400
www.malwarebytes.org
Database version: v2012.06.20.05
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
Chattanooga ChooChoo :: CHATTANOOGACHOO [administrator]
Protection: Enabled
6/20/2012 1:30:37 PM
mbam-log-2012-06-20 (13-30-37).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 206789
Time elapsed: 3 minute(s), 1 second(s)
Memory Processes Detected: 1
C:\Users\Chattanooga ChooChoo\AppData\Roaming\KB00166847.exe (Trojan.Agent.Gen) -> 3644 -> Delete on reboot.
Memory Modules Detected: 1
C:\Users\Chattanooga ChooChoo\AppData\Local\Apple\Adobe\mgxtn.dll (Trojan.Happili.XGen) -> Delete on reboot.
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 2
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|Adobe (Trojan.Happili.XGen) -> Data: rundll32.exe "C:\Users\Chattanooga ChooChoo\AppData\Local\Apple\Adobe\mgxtn.dll",DllRegisterServer -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|KB00166847.exe (Trojan.Agent.Gen) -> Data: "C:\Users\Chattanooga ChooChoo\AppData\Roaming\KB00166847.exe" -> Quarantined and deleted successfully.
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 5
C:\Users\Chattanooga ChooChoo\AppData\Local\Apple\Adobe\mgxtn.dll (Trojan.Happili.XGen) -> Delete on reboot.
C:\Users\Chattanooga ChooChoo\AppData\Local\Temp\0.5048551764769318 (Trojan.Happili) -> Quarantined and deleted successfully.
C:\Users\Chattanooga ChooChoo\AppData\Local\Temp\nsy7572.tmp\mgxtn.dll (Trojan.Happili.XGen) -> Quarantined and deleted successfully.
C:\Users\Chattanooga ChooChoo\Local Settings\Temporary Internet Files\Content.IE5\DRNE1450\PDFReaderSetup_V3.exe (PUP.Adware.InstallCore) -> Quarantined and deleted successfully.
C:\Users\Chattanooga ChooChoo\AppData\Roaming\KB00166847.exe (Trojan.Agent.Gen) -> Delete on reboot.
(end)
MBAM log:
Malwarebytes Anti-Malware (Trial) 1.61.0.1400
www.malwarebytes.org
Database version: v2012.06.20.05
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
Chattanooga ChooChoo :: CHATTANOOGACHOO [administrator]
Protection: Enabled
6/20/2012 1:30:37 PM
mbam-log-2012-06-20 (13-30-37).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 206789
Time elapsed: 3 minute(s), 1 second(s)
Memory Processes Detected: 1
C:\Users\Chattanooga ChooChoo\AppData\Roaming\KB00166847.exe (Trojan.Agent.Gen) -> 3644 -> Delete on reboot.
Memory Modules Detected: 1
C:\Users\Chattanooga ChooChoo\AppData\Local\Apple\Adobe\mgxtn.dll (Trojan.Happili.XGen) -> Delete on reboot.
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 2
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|Adobe (Trojan.Happili.XGen) -> Data: rundll32.exe "C:\Users\Chattanooga ChooChoo\AppData\Local\Apple\Adobe\mgxtn.dll",DllRegisterServer -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|KB00166847.exe (Trojan.Agent.Gen) -> Data: "C:\Users\Chattanooga ChooChoo\AppData\Roaming\KB00166847.exe" -> Quarantined and deleted successfully.
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 5
C:\Users\Chattanooga ChooChoo\AppData\Local\Apple\Adobe\mgxtn.dll (Trojan.Happili.XGen) -> Delete on reboot.
C:\Users\Chattanooga ChooChoo\AppData\Local\Temp\0.5048551764769318 (Trojan.Happili) -> Quarantined and deleted successfully.
C:\Users\Chattanooga ChooChoo\AppData\Local\Temp\nsy7572.tmp\mgxtn.dll (Trojan.Happili.XGen) -> Quarantined and deleted successfully.
C:\Users\Chattanooga ChooChoo\Local Settings\Temporary Internet Files\Content.IE5\DRNE1450\PDFReaderSetup_V3.exe (PUP.Adware.InstallCore) -> Quarantined and deleted successfully.
C:\Users\Chattanooga ChooChoo\AppData\Roaming\KB00166847.exe (Trojan.Agent.Gen) -> Delete on reboot.
(end)