0 Members and 1 Guest are viewing this topic.
I apologize ahead of time for doing attachemtns,
I have the same malware on my computer an can not get rid of it? I did not see a fix on this post?
:OTLDRV - File not found [Kernel | On_Demand | Unknown] -- -- (.mrxsmb)DRV - File not found [Kernel | On_Demand | Unknown] -- -- (.i8042prt)O2 - BHO: (no name) - {9D425283-D487-4337-BAB6-AB8354A81457} - No CLSID value found.O3 - HKLM\..\Toolbar: (no name) - {9D425283-D487-4337-BAB6-AB8354A81457} - No CLSID value found.O3 - HKU\S-1-5-21-1547161642-1647877149-839522115-1004\..\Toolbar\WebBrowser: (no name) - {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No CLSID value found.O3 - HKU\S-1-5-21-1547161642-1647877149-839522115-1004\..\Toolbar\WebBrowser: (no name) - {9D425283-D487-4337-BAB6-AB8354A81457} - No CLSID value found.O3 - HKU\S-1-5-21-1547161642-1647877149-839522115-1004\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.O4 - HKU\.DEFAULT..\Run: [Apple] C:\Documents and Settings\Wayne and Marge\Local Settings\Application Data\Apple Computer\Apple\bjvavobwb.dll ()O4 - HKU\S-1-5-18..\Run: [Apple] C:\Documents and Settings\Wayne and Marge\Local Settings\Application Data\Apple Computer\Apple\bjvavobwb.dll ()O4 - HKU\S-1-5-19..\Run: [Apple] C:\Documents and Settings\Wayne and Marge\Local Settings\Application Data\Apple Computer\Apple\bjvavobwb.dll ()O4 - HKU\S-1-5-20..\Run: [Apple] C:\Documents and Settings\Wayne and Marge\Local Settings\Application Data\Apple Computer\Apple\bjvavobwb.dll ()O4 - HKU\S-1-5-21-1547161642-1647877149-839522115-1004..\Run: [Apple] C:\Documents and Settings\Wayne and Marge\Local Settings\Application Data\Apple Computer\Apple\bjvavobwb.dll ()O33 - MountPoints2\{1cbd9bd0-b399-11de-a4f2-806d6172696f}\Shell\AutoRun\command - "" = G:\Info.exe folder.htt 480 480:Filesipconfig /flushdns /c:Commands[purity][resethosts][emptytemp][CREATERESTOREPOINT][Reboot]
:OTL[2011/12/04 18:01:54 | 000,000,469 | ---- | C] () -- C:\Program Files\1204201117015432.bat[2011/11/09 10:14:22 | 000,002,048 | -HS- | C] () -- C:\Documents and Settings\Wayne and Marge\Local Settings\Application Data\075d3cf2\@[2011/11/20 15:15:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Wayne and Marge\Application Data\58CF0[2008/12/06 23:44:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Wayne and Marge\Application Data\Artogon[2011/11/20 14:39:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Wayne and Marge\Application Data\AS2ibD3pn5Q6W8R[2011/11/20 14:37:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Wayne and Marge\Application Data\avD3onG4aH[2011/11/08 14:17:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Wayne and Marge\Application Data\Awem[2011/11/20 15:19:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Wayne and Marge\Application Data\BaQH6dWK7R9TqUe[2011/11/20 14:23:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Wayne and Marge\Application Data\gqjYCekIVzN[2011/11/20 14:25:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Wayne and Marge\Application Data\I3onG4aQHsKfLgX[2011/11/20 14:23:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Wayne and Marge\Application Data\N6dEK8fRZhXjVlB[2011/11/20 15:24:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Wayne and Marge\Application Data\NK7fRL9gTqUeIrP[2011/11/20 14:23:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Wayne and Marge\Application Data\nYCwkUVrlNx0c2b[2011/11/20 14:39:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Wayne and Marge\Application Data\OL8gRZqhYwUrOtP[2011/11/20 14:25:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Wayne and Marge\Application Data\QF4pmH5sQ7E[2011/11/20 14:23:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Wayne and Marge\Application Data\qSibFmG5a[2011/11/20 14:37:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Wayne and Marge\Application Data\thYXwjUVeOtPy[2011/11/20 15:19:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Wayne and Marge\Application Data\xIBrzPNyc1v2n4[2011/11/20 15:24:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Wayne and Marge\Application Data\Y3onG4aQHs:Filesipconfig /flushdns /cC:\Documents and Settings\Wayne and Marge\Local Settings\Application Data\075d3cf2:Commands[purity][resethosts][emptytemp][CREATERESTOREPOINT][Reboot]