Jump to content

sbruton

Members
  • Posts

    5
  • Joined

  • Last visited

Everything posted by sbruton

  1. Looking better! Thanks for your help! mbar-log-2013-02-19 (15-55-26).txt mbar-log-2013-02-19 (21-48-38).txt system-log.txt
  2. Hi Charlie, it started earlier today when I sent a coworker an email. He replied and said he immediately received a spam email with my name on it. I started digging around. Microsoft Security Essentials said nothing. I downloaded Malwarebytes, and while it was scanning, MS Essentials started quarantining trojans in my AppData\Local\Temp folder. I then cleared the Temp folder, with the exception of a file Malwarebytes was apparently using. I reran Malwarebytes, and it identified svchost.exe as being a trojan. That is when I started the current process. Thanks for your help.
  3. RogueKiller V8.5.1 _x64_ [Feb 19 2013] by Tigzy mail : tigzyRK<at>gmail<dot>com Feedback : http://www.geekstogo.com/forum/files/file/413-roguekiller/ Website : http://tigzy.geekstogo.com/roguekiller.php Blog : http://tigzyrk.blogspot.com/ Operating System : Windows 7 (6.1.7601 Service Pack 1) 64 bits version Started in : Normal mode User : sbruton [Admin rights] Mode : Scan -- Date : 02/19/2013 14:25:25 | ARK || FAK || MBR | ¤¤¤ Bad processes : 1 ¤¤¤ [sUSP PATH] ssh-agent.exe -- C:\Users\sbruton.CTU\AppData\Local\GitHub\PortableGit_64179092f39f5dacb60dcab147fb4d04266c0eae\bin\ssh-agent.exe [-] -> KILLED [TermProc] ¤¤¤ Registry Entries : 7 ¤¤¤ [HJ] HKLM\[...]\System : ConsentPromptBehaviorAdmin (0) -> FOUND [HJ] HKLM\[...]\Wow6432Node\System : ConsentPromptBehaviorAdmin (0) -> FOUND [HJ] HKLM\[...]\System : EnableLUA (0) -> FOUND [HJ] HKLM\[...]\Wow6432Node\System : EnableLUA (0) -> FOUND [HJ SMENU] HKCU\[...]\Advanced : Start_ShowMyGames (0) -> FOUND [HJ DESK] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> FOUND [HJ DESK] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND ¤¤¤ Particular Files / Folders: ¤¤¤ ¤¤¤ Driver : [NOT LOADED] ¤¤¤ ¤¤¤ HOSTS File: ¤¤¤ --> C:\Windows\system32\drivers\etc\hosts 10.0.0.2 snmail 10.0.0.14 snw2k3sql 10.0.0.15 sndevsvr 10.0.0.16 snintsvr 10.10.10.22 pons 10.10.10.14 cerebrum 10.10.10.41 leftbrain ¤¤¤ MBR Check: ¤¤¤ +++++ PhysicalDrive0: TOSHIBA MK3261GSY +++++ --- User --- [MBR] b9ebb829bfb7051404d19e611c407d7a [bSP] dea9defa67a18cc486b8c709b2ee22f0 : Windows Vista MBR Code Partition table: 0 - [XXXXXX] DELL-UTIL (0xde) [VISIBLE] Offset (sectors): 63 | Size: 101 Mo 1 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 212992 | Size: 21900 Mo 2 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 45064192 | Size: 283240 Mo User = LL1 ... OK! User = LL2 ... OK! Finished : << RKreport[1]_S_02192013_02d1425.txt >> RKreport[1]_S_02192013_02d1425.txt
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.