also @ TechSpot: Metro: Last Light Performance, Benchmarked

Res://C:\Windows\system32\shdoclc.dll/navcancl.htm Internet Explorer Issue

Discussion in 'Virus and Malware Removal' started by dozzyo9080, May 8, 2011.

  1. dozzyo9080 Newcomer, in training Posts: 118

    I should not be talking because the log isn't ready yet. It has been going for 3 1/2 hours now
  2. dozzyo9080 Newcomer, in training Posts: 118

    Part of ESET 1

    C:\Qoobox\Quarantine\C\Program Files\Search Toolbar\SearchToolbar.dll.vir Win32/Toolbar.Zugo application
    C:\Users\Austin ROCKS\Downloads\Dr_Mario.zip probably a variant of Win32/Rbot.MOUFPZM trojan
    C:\Users\Austin ROCKS\Downloads\WyzoSetup-3.6.4.exe Win32/Toolbar.Zugo application


    G2G Sorry bye. This is ESET
  3. Broni Malware Annihilator Posts: 39,313   +175

    What do you mean by "part 1"?
  4. Broni Malware Annihilator Posts: 39,313   +175

    Are you still out there?
  5. Broni Malware Annihilator Posts: 39,313   +175

    The issue seems to be resolved.
  6. dozzyo9080 Newcomer, in training Posts: 118

    its back

    It was good for a while but suddenly it just came back again today. The issue apparently was only temporarily solved.
     
  7. Broni Malware Annihilator Posts: 39,313   +175

    Give me more details about it.

    BTW, you never returned to this topic to run final steps....hmmm
  8. dozzyo9080 Newcomer, in training Posts: 118

    It was working fine until i experienced some lag on flash stuff. Fixing that is not important. In my attempt to fix it, i tried to clear temp files with that program. But after that, pages were looking strange. So i decided to delete chrome and reinstall it. But then the original about:blank error came up again. The one at the beginning of this thread.
  9. Broni Malware Annihilator Posts: 39,313   +175

    That's in IE?
  10. dozzyo9080 Newcomer, in training Posts: 118

    I use chrome. The reason i said IE is because it showed a file location.Chrome says about:blank.
  11. dozzyo9080 Newcomer, in training Posts: 118

    res://C:\Windows\system32\shdoclc.dll/navcancl.htm
    for IE
  12. Broni Malware Annihilator Posts: 39,313   +175

    Update MBAM, run FULL scan and post the log.
  13. dozzyo9080 Newcomer, in training Posts: 118

    will it bring the same results with a flash scan?
  14. Broni Malware Annihilator Posts: 39,313   +175

    What do you mean by flash scan?
  15. dozzyo9080 Newcomer, in training Posts: 118

    Never Mind. Its a reg and memory scanner in newer version of MBAM. I thought it was a quick, full scan

    I'm still trying to leave the computer on for it to complete but it is very hard to leave the computer running for so long.
  16. dozzyo9080 Newcomer, in training Posts: 118

    scan is not looking very good...
  17. Broni Malware Annihilator Posts: 39,313   +175

    What scan?
  18. dozzyo9080 Newcomer, in training Posts: 118

  19. Broni Malware Annihilator Posts: 39,313   +175

    Please reply using full sentence to let me know what doesn't look good.
    Unfortunately I'm not there, so I can't see what you see.
  20. dozzyo9080 Newcomer, in training Posts: 118

    mbam 7/24

    Malwarebytes' Anti-Malware 1.51.1.1800
    www.malwarebytes.org

    Database version: 7265

    Windows 6.0.6002 Service Pack 2
    Internet Explorer 9.0.8112.16421

    7/24/2011 7:59:53 PM
    mbam-log-2011-07-24 (19-59-09).txt

    Scan type: Full scan (C:\|D:\|F:\|G:\|)
    Objects scanned: 206976
    Time elapsed: 4 hour(s), 41 minute(s), 10 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 4
    Registry Values Infected: 2
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 1

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    HKEY_CLASSES_ROOT\CLSID\{0BDA0769-FD72-49F4-9266-E1FB004F4D8F} (PUP.Dealio.TB) -> No action taken.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0BDA0769-FD72-49F4-9266-E1FB004F4D8F} (PUP.Dealio.TB) -> No action taken.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{0BDA0769-FD72-49F4-9266-E1FB004F4D8F} (PUP.Dealio.TB) -> No action taken.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{0BDA0769-FD72-49F4-9266-E1FB004F4D8F} (PUP.Dealio.TB) -> No action taken.

    Registry Values Infected:
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\{0BDA0769-FD72-49F4-9266-E1FB004F4D8F} (PUP.Dealio.TB) -> Value: {0BDA0769-FD72-49F4-9266-E1FB004F4D8F} -> No action taken.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{0BDA0769-FD72-49F4-9266-E1FB004F4D8F} (PUP.Dealio.TB) -> Value: {0BDA0769-FD72-49F4-9266-E1FB004F4D8F} -> No action taken.

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    c:\program files\iobit toolbar\IE\4.5\iobittoolbarie.dll (PUP.Dealio.TB) -> No action taken.