also @ TechSpot: Apple's iOS 7 to be "black, white and flat all over"

\\.\PhysicalDrive0 Win7

Discussion in 'Virus and Malware Removal' started by jdiaz1998, Nov 26, 2010.

  1. jdiaz1998 Newcomer, in training Posts: 56

    Do I delete this:
    netsvcs
    drivers32
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lnk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Desktop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    %systemroot%\AppPatch\Custom\*.*
    %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x
    %PROGRAMFILES%\PC-Doctor\Downloads\*.*
    %PROGRAMFILES%\Internet Explorer\*.tmp
    %PROGRAMFILES%\Internet Explorer\*.dat
    %USERPROFILE%\My Documents\*.exe
    %USERPROFILE%\*.exe
    %systemroot%\ADDINS\*.*
    %systemroot%\assembly\*.bak2
    %systemroot%\Config\*.*
    %systemroot%\REPAIR\*.bak2
    %systemroot%\SECURITY\Database\*.sdb /x
    %systemroot%\SYSTEM\*.bak2
    %systemroot%\Web\*.bak2
    %systemroot%\Driver Cache\*.*
    %PROGRAMFILES%\Mozilla Firefox\0*.exe
    %ProgramFiles%\Microsoft Common\*.*
    %ProgramFiles%\TinyProxy.
    %USERPROFILE%\Favorites\*.url /x
    %systemroot%\system32\*.bk
    %systemroot%\*.te
    %systemroot%\system32\system32\*.*
    %ALLUSERSPROFILE%\*.dat /x
    %systemroot%\system32\drivers\*.rmv
    dir /b "%systemroot%\system32\*.exe" | find /i " " /c
    dir /b "%systemroot%\*.exe" | find /i " " /c
    %PROGRAMFILES%\Microsoft\*.*
    %systemroot%\System32\Wbem\proquota.exe
    %PROGRAMFILES%\Mozilla Firefox\*.dat
    %USERPROFILE%\Cookies\*.txt /x
    %SystemRoot%\system32\fonts\*.*
    %systemroot%\system32\winlog\*.*
    %systemroot%\system32\Language\*.*
    %systemroot%\system32\Settings\*.*
    %systemroot%\system32\*.quo
    %SYSTEMROOT%\AppPatch\*.exe
    %SYSTEMROOT%\inf\*.exe
    %SYSTEMROOT%\Installer\*.exe
    %systemroot%\system32\config\*.bak2
    %systemroot%\system32\Computers\*.*
    %SystemRoot%\system32\Sound\*.*
    %SystemRoot%\system32\SpecialImg\*.*
    %SystemRoot%\system32\code\*.*
    %SystemRoot%\system32\draft\*.*
    %SystemRoot%\system32\MSSSys\*.*
    %ProgramFiles%\Javascript\*.*
    %systemroot%\pchealth\helpctr\System\*.exe /s
    %systemroot%\Web\*.exe
    %systemroot%\system32\msn\*.*
    %systemroot%\system32\*.tro
    %AppData%\Microsoft\Installer\msupdates\*.*
    %ProgramFiles%\Messenger\*.*
    %systemroot%\system32\systhem32\*.*
    %systemroot%\system\*.exe
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\ Auto Update\Results\Install|LastSuccessTime /rs
    /md5start
    /md5stop
    and replace it with this?
    :OTL
    O3:64bit: - HKLM\..\Toolbar: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found.
    O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
    O3 - HKLM\..\Toolbar: (Tango) - {85BC0CB6-E967-4E2C-BE92-FEDD0A5D0A31} - C:\Windows\SysWow64\7b78.dll File not found
    O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
    O3 - HKCU\..\Toolbar\WebBrowser: (Tango) - {85BC0CB6-E967-4E2C-BE92-FEDD0A5D0A31} - C:\Windows\SysWow64\7b78.dll File not found
    O4 - HKCU..\Run: [AdobeBridge] File not found
    O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\SysWOW64\MPK\mpk.exe) - C:\Windows\SysWOW64\MPK\mpk.exe File not found
    O33 - MountPoints2\{0d29154f-92cc-11df-bb96-e0cb4e3a19e3}\Shell - "" = AutoRun
    O33 - MountPoints2\{0d29154f-92cc-11df-bb96-e0cb4e3a19e3}\Shell\AutoRun\command - "" = D:\WD SmartWare.exe -- File not found
    O33 - MountPoints2\{10b6f908-83c9-11df-8964-e0cb4e3a19e3}\Shell - "" = AutoRun
    O33 - MountPoints2\{10b6f908-83c9-11df-8964-e0cb4e3a19e3}\Shell\AutoRun\command - "" = F:\setup\rsrc\Autorun.exe -- File not found
    O33 - MountPoints2\{10b6f908-83c9-11df-8964-e0cb4e3a19e3}\Shell\dinstall\command - "" = F:\Directx\dxsetup.exe -- File not found
    O33 - MountPoints2\{2c4bbb22-a160-11df-8a04-e0cb4e3a19e3}\Shell - "" = AutoRun
    O33 - MountPoints2\{2c4bbb22-a160-11df-8a04-e0cb4e3a19e3}\Shell\AutoRun\command - "" = H:\HPLauncher.exe -- File not found
    [2010/10/06 16:43:59 | 000,000,088 | RHS- | C] () -- C:\ProgramData\BCAE6404D7.sys
    @Alternate Data Stream - 130 bytes -> C:\ProgramData\Temp:425D0709


    :Services

    :Reg

    :Files

    :Commands
    [purity]
    [emptytemp]
    [emptyflash]
    [Reboot]
    ???????????
  2. jdiaz1998 Newcomer, in training Posts: 56

    All processes killed
    ========== OTL ==========
    64bit-Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{32099AAC-C132-4136-9E9A-4E364A424E17} deleted successfully.
    64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{32099AAC-C132-4136-9E9A-4E364A424E17}\ deleted successfully.
    64bit-Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully.
    Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{85BC0CB6-E967-4E2C-BE92-FEDD0A5D0A31} deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{85BC0CB6-E967-4E2C-BE92-FEDD0A5D0A31}\ deleted successfully.
    Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully.
    Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{21FA44EF-376D-4D53-9B0F-8A89D3229068} deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{21FA44EF-376D-4D53-9B0F-8A89D3229068}\ not found.
    Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{85BC0CB6-E967-4E2C-BE92-FEDD0A5D0A31} deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{85BC0CB6-E967-4E2C-BE92-FEDD0A5D0A31}\ not found.
    Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\AdobeBridge deleted successfully.
    64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Windows\SysWOW64\MPK\mpk.exe deleted successfully.
    Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0d29154f-92cc-11df-bb96-e0cb4e3a19e3}\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0d29154f-92cc-11df-bb96-e0cb4e3a19e3}\ not found.
    Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0d29154f-92cc-11df-bb96-e0cb4e3a19e3}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0d29154f-92cc-11df-bb96-e0cb4e3a19e3}\ not found.
    File D:\WD SmartWare.exe not found.
    Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{10b6f908-83c9-11df-8964-e0cb4e3a19e3}\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{10b6f908-83c9-11df-8964-e0cb4e3a19e3}\ not found.
    Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{10b6f908-83c9-11df-8964-e0cb4e3a19e3}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{10b6f908-83c9-11df-8964-e0cb4e3a19e3}\ not found.
    File F:\setup\rsrc\Autorun.exe not found.
    Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{10b6f908-83c9-11df-8964-e0cb4e3a19e3}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{10b6f908-83c9-11df-8964-e0cb4e3a19e3}\ not found.
    File F:\Directx\dxsetup.exe not found.
    Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2c4bbb22-a160-11df-8a04-e0cb4e3a19e3}\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2c4bbb22-a160-11df-8a04-e0cb4e3a19e3}\ not found.
    Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2c4bbb22-a160-11df-8a04-e0cb4e3a19e3}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2c4bbb22-a160-11df-8a04-e0cb4e3a19e3}\ not found.
    File H:\HPLauncher.exe not found.
    C:\ProgramData\BCAE6404D7.sys moved successfully.
    ADS C:\ProgramData\Temp:425D0709 deleted successfully.
    ========== SERVICES/DRIVERS ==========
    ========== REGISTRY ==========
    ========== FILES ==========
    ========== COMMANDS ==========

    [EMPTYTEMP]

    User: All Users

    User: Default
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes
    ->Flash cache emptied: 0 bytes

    User: Default User
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes
    ->Flash cache emptied: 0 bytes

    User: juan

    User: Juan Felipe
    ->Temp folder emptied: 547998 bytes
    ->Temporary Internet Files folder emptied: 6584055 bytes
    ->Java cache emptied: 0 bytes
    ->FireFox cache emptied: 4016183 bytes
    ->Google Chrome cache emptied: 57834910 bytes
    ->Apple Safari cache emptied: 0 bytes
    ->Flash cache emptied: 1438 bytes

    User: Public

    %systemdrive% .tmp files removed: 0 bytes
    %systemroot% .tmp files removed: 0 bytes
    %systemroot%\System32 .tmp files removed: 0 bytes
    %systemroot%\System32 (64bit) .tmp files removed: 0 bytes
    %systemroot%\System32\drivers .tmp files removed: 0 bytes
    Windows Temp folder emptied: 0 bytes
    %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 32902 bytes
    RecycleBin emptied: 626711 bytes

    Total Files Cleaned = 66.00 mb


    [EMPTYFLASH]

    User: All Users

    User: Default
    ->Flash cache emptied: 0 bytes

    User: Default User
    ->Flash cache emptied: 0 bytes

    User: juan

    User: Juan Felipe
    ->Flash cache emptied: 0 bytes

    User: Public

    Total Flash Files Cleaned = 0.00 mb


    OTL by OldTimer - Version 3.2.17.3 log created on 11272010_142259

    Files\Folders moved on Reboot...
    C:\Users\Juan Felipe\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.

    Registry entries deleted on Reboot...
  3. jdiaz1998 Newcomer, in training Posts: 56

    Results of screen317's Security Check version 0.99.5
    Windows 7 (UAC is enabled)
    ``````````````````````````````
    Antivirus/Firewall Check:

    Windows Firewall Enabled!
    McAfee Security Scan Plus
    WMI entry may not exist for antivirus; attempting automatic update.
    ```````````````````````````````
    Anti-malware/Other Utilities Check:

    Malwarebytes' Anti-Malware
    CCleaner
    Java(TM) 6 Update 22
    Out of date Java installed!
    Adobe Flash Player 10.0.32.18
    Adobe Reader 9.4.1 MUI
    ````````````````````````````````
    Process Check:
    objlist.exe by Laurent

    Webroot Security current plugins\antimalware\AEI.exe
    Webroot Security current plugins\antimalware\SSU.EXE
    ````````````````````````````````
    DNS Vulnerability Check:

    GREAT! (Not vulnerable to DNS cache poisoning)

    ``````````End of Log````````````
  4. jdiaz1998 Newcomer, in training Posts: 56

    It has spent A LOT of time in 73 & 74%
  5. Broni Malware Annihilator Posts: 39,437   +177

    You did well :)

    Eset scan please....
  6. Broni Malware Annihilator Posts: 39,437   +177

    Keep it going....
     
  7. jdiaz1998 Newcomer, in training Posts: 56

    99%, no viruses.
  8. jdiaz1998 Newcomer, in training Posts: 56

    It has been in 99% for 6 minutes now.
  9. jdiaz1998 Newcomer, in training Posts: 56

    I think it is stuck on a file. It has been on the same one for.....4 minutes now.
  10. jdiaz1998 Newcomer, in training Posts: 56

    still on the same file....
  11. Broni Malware Annihilator Posts: 39,437   +177

    Give it few more minutes.
  12. jdiaz1998 Newcomer, in training Posts: 56

    Finally moved on.
  13. jdiaz1998 Newcomer, in training Posts: 56

    Gonna wash the dishes..............................BRB.
  14. Broni Malware Annihilator Posts: 39,437   +177

    Let me know, when the scan is done.
  15. jdiaz1998 Newcomer, in training Posts: 56

    it has spent more than an hour on 99% and has found 6 threats.
  16. Broni Malware Annihilator Posts: 39,437   +177

    As long as it's moving along, let it run.
    Be patient.
  17. jdiaz1998 Newcomer, in training Posts: 56

    After I give you this scan's result, how long do you think will take for the virus to be in oblivion?
  18. Broni Malware Annihilator Posts: 39,437   +177

    Say again?
  19. jdiaz1998 Newcomer, in training Posts: 56

    After I post the scan log/result about how long will it take to remove the virus?
  20. Broni Malware Annihilator Posts: 39,437   +177

    No time. Most likely, some leftovers, which can be removed with one OTL script run.