Jump to content

helpsally

Members
  • Posts

    3
  • Joined

  • Last visited

Posts posted by helpsally

  1. Hi Sally,

    You can let malwarebytes delete this one:

    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{2d2bee6e-3c9a-4d58-b9ec-458edb28d0f6} (Rogue.DriveCleaner) -> No action taken.

    It's a leftover from an Activex you had installed once, pointing to drivecleaner. It's safe to delete that one.

    You can ignore the two other ones since they are set by your McAfee. :)

    Hi Mieke,

    Thank you so much for your help! I deleted that the above Registry key and ignored the other two items as you said. I appreciate your assistance very much. I will do a full scan of everything and get back you as soon as I can. How does my HijackThis log look to you? Is everything else ok?

    Hope I will be OK.

    Sincerely,

    Sally

  2. Hi,

    I am running Windows XP sp3 and McAfee Viruscan.

    Last week my pc was infected by 2 differnt trojans in 4 places at 2 different times (trojan: generic.dx!llk and Generic.dx!mvl) My antivirus has since quarantined them and I deleted 2 of them. I ran a few full system scans and deleted some items (I had an older version of Java that I deleted)as well as ran a scan in safe mode. All seemed ok, nothing showed up.

    I ran the latest version of spybot and that came out clean as well. I decided to uninstall spybot and try Malwarebytes and it found three items, I will post the log here. It found a rogue.drive cleaner on a registry key and I didn't take any action because I thought that I would ask first if it's ok to delete a registry key...could this harm my pc? Should I click the remove button when Malwarebytes detects it? I am sorry, I worry when it comes to the registry keys and windows.

    The other two findings in the registry data with microsoft security, as I said, I am running McAfee virus scan and read some posts that this might be the reason for these 2 data items..should I delete these as well or ignore them? My antivrus seems to be working as does my firewall. In any case, can someone please help me?

    I would appreciate it very much. Could I safely delete rogue.drive cleaner registry key finding? What about the other 2?

    BTW, there is no rogue drive cleaner program in my add/remove.

    Here is the Malwarebytes log:

    Malwarebytes' Anti-Malware 1.44

    Database version: 3718

    Windows 5.1.2600 Service Pack 3

    Internet Explorer 8.0.6001.18702

    2/10/2010 4:48:56 AM

    mbam-log-2010-02-10 (04-48-49).txt

    Scan type: Full Scan (C:\|)

    Objects scanned: 223897

    Time elapsed: 2 hour(s), 47 minute(s), 13 second(s)

    Memory Processes Infected: 0

    Memory Modules Infected: 0

    Registry Keys Infected: 1

    Registry Values Infected: 0

    Registry Data Items Infected: 2

    Folders Infected: 0

    Files Infected: 0

    Memory Processes Infected:

    (No malicious items detected)

    Memory Modules Infected:

    (No malicious items detected)

    Registry Keys Infected:

    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{2d2bee6e-3c9a-4d58-b9ec-458edb28d0f6} (Rogue.DriveCleaner) -> No action taken.

    Registry Values Infected:

    (No malicious items detected)

    Registry Data Items Infected:

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> No action taken.

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> No action taken.

    Folders Infected:

    (No malicious items detected)

    Files Infected:

    (No malicious items detected)

    Here is the HijackThis log as well: (I didn't do anything because I don't know what to do and need kindly advice.).

    Logfile of Trend Micro HijackThis v2.0.2

    Scan saved at 9:52:14 AM, on 2/11/2010

    Platform: Windows XP SP3 (WinNT 5.01.2600)

    MSIE: Internet Explorer v8.00 (8.00.6001.18702)

    Boot mode: Normal

    Running processes:

    C:\WINDOWS\System32\smss.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\system32\services.exe

    C:\WINDOWS\system32\lsass.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\System32\svchost.exe

    C:\WINDOWS\Explorer.EXE

    C:\WINDOWS\system32\spoolsv.exe

    C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe

    C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe

    C:\WINDOWS\System32\svchost.exe

    C:\Program Files\Java\jre6\bin\jqs.exe

    C:\Program Files\McAfee\SiteAdvisor\McSACore.exe

    C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe

    c:\program files\common files\mcafee\mna\mcnasvc.exe

    c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe

    C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe

    C:\Program Files\McAfee\MPF\MPFSrv.exe

    C:\WINDOWS\System32\svchost.exe

    c:\PROGRA~1\mcafee.com\agent\mcagent.exe

    C:\Program Files\Common Files\Logitech\QCDriver2\LVCOMS.EXE

    C:\HP\KBD\KBD.EXE

    C:\windows\system\hpsysdrv.exe

    C:\WINDOWS\LTMSG.exe

    C:\Program Files\QuickTime\qttask.exe

    C:\WINDOWS\system32\ctfmon.exe

    C:\Program Files\Windows Media Player\WMPNSCFG.exe

    C:\Program Files\hp center\137903\Shadow\ShadowBar.exe

    C:\Program Files\hp center\137903\Program\BackWeb-137903.exe

    C:\WINDOWS\System32\MsPMSPSv.exe

    C:\WINDOWS\system32\svchost.exe

    C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe

    C:\WINDOWS\system32\wuauclt.exe

    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.sympatico.ca/default.aspx?lang=en-CA

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost

    N3 - Netscape 7: # Mozilla User Preferences

    // This is a generated file!

    user_pref("aim.session.finishedwizard", true);

    user_pref("aim.session.firsttime", false);

    user_pref("aim.session.latestaimscreenname", "coco222cacan");

    user_pref("aim.session.screenname", "coco222cacan");

    user_pref("browser.bookmarks.added_static_root", true);

    user_pref("browser.download.dir", "C:\\Documents and Settings\\Owner\\My Documents\\My Pictures");

    user_pref("browser.history.last_page_visited", "http://cdn.netscape.com/a/a");

    user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src");

    user_pref("browser.startup.homepage_override.mstone", "rv:1.0.1");

    user_pref("browser.toolbars.showbutton.AimPT", false);

    user_pref("coco222cacan.aim.general.im.enterCR", false);

    user_pref("coco222cacan.aim.general.im.smilies", true);

    user_pref("coco222cacan.aim.general.im.tabKey", false);

    user_pref("coco222cacan.aim.general.im.timeStamp", false);

    user_pref("coco222cacan.aim.ge

    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll

    O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll

    O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll

    O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll

    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

    O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll

    O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE

    O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe

    O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Common Files\Logitech\QCDriver2\LVCOMS.EXE

    O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE

    O4 - HKLM\..\Run: [igfxTray] C:\WINDOWS\System32\igfxtray.exe

    O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe

    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe

    O4 - HKLM\..\Run: [PCLEPCI] C:\PROGRA~1\Pinnacle\PPE\ppe.exe

    O4 - HKLM\..\Run: [LTMSG] LTMSG.exe 7

    O4 - HKLM\..\Run: [siS KHooker] C:\WINDOWS\system32\khooker.exe

    O4 - HKLM\..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey

    O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg

    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"

    O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

    O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"

    O4 - HKCU\..\Run: [Microsoft Works Update Detection] c:\Program Files\Microsoft Works\WkDetect.exe

    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

    O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"

    O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe

    O4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\SYSTEM32\spool\drivers\w32x86\3\E_SRCV02.EXE

    O4 - Global Startup: hp center UI.lnk = C:\Program Files\hp center\137903\Shadow\ShadowBar.exe

    O4 - Global Startup: hp center.lnk = C:\Program Files\hp center\137903\Program\BackWeb-137903.exe

    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll

    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll

    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O15 - Trusted Zone: http://us.mcafee.com

    O15 - Trusted Zone: http://*.mcafee.com

    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu...b?1257519754687

    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab

    O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll

    O23 - Service: Adobe Active File Monitor V6 (AdobeActiveFileMonitor6.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe

    O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe

    O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe

    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

    O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe

    O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe

    O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe

    O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe

    O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe

    O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe

    O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe

    O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe

    --

    End of file - 8660 bytes

    Please help me, thanks!

    Sally

Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.