Jump to content

Trojan and Rootkit Party


Recommended Posts

MrCharlie,

It seems everything is clean now - nothing detected in MWB. Sending a big stern handshake and thanks your way. I'm on my way to your paypal site!

Could I trouble you to take a peak at my laptop's mbam log? - and would you recommend that I follow the same steps there?.......

Malwarebytes Anti-Malware 1.62.0.1300

www.malwarebytes.org

Database version: v2012.08.12.06

Windows 7 Service Pack 1 x86 FAT32

Internet Explorer 9.0.8112.16421

qxlocates :: A10782 [administrator]

Protection: Enabled

8/12/2012 9:15:30 PM

mbam-log-2012-08-12 (22-05-20).txt

Scan type: Full scan (C:\|E:\|H:\|)

Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM

Scan options disabled: P2P

Objects scanned: 371089

Time elapsed: 30 minute(s), 54 second(s)

Memory Processes Detected: 0

(No malicious items detected)

Memory Modules Detected: 1

C:\Windows\System32\diskexnt.dll (Trojan.Agent) -> No action taken.

Registry Keys Detected: 0

(No malicious items detected)

Registry Values Detected: 0

(No malicious items detected)

Registry Data Items Detected: 0

(No malicious items detected)

Folders Detected: 0

(No malicious items detected)

Files Detected: 12

C:\Windows\System32\diskexnt.dll (Trojan.Agent) -> No action taken.

C:\Users\Administrator.A10782\AppData\Local\tafyvp.exe (Trojan.LameShield) -> No action taken.

C:\Users\qxlocates\AppData\Local\nvfarle.exe (Trojan.LameShield) -> No action taken.

C:\Users\qxlocates\AppData\Local\Temp\sgwe3t.exe (Trojan.Inject) -> No action taken.

C:\Users\qxlocates\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\44\839df2c-6e687be5 (Trojan.Inject) -> No action taken.

C:\Users\qxlocates\Downloads\installer_plants_vs_zombies.exe (PUP.BundleInstaller.BT) -> No action taken.

C:\Windows\assembly\GAC\Desktop.ini (Trojan.0access) -> No action taken.

C:\Windows\Installer\{f935cc66-766e-6d60-1eaa-31aeda77fbc6}\U\00000004.@ (Rootkit.Zaccess) -> No action taken.

C:\Windows\Installer\{f935cc66-766e-6d60-1eaa-31aeda77fbc6}\U\00000008.@ (Trojan.Dropper.BCMiner) -> No action taken.

C:\Windows\Installer\{f935cc66-766e-6d60-1eaa-31aeda77fbc6}\U\000000cb.@ (Rootkit.0Access) -> No action taken.

C:\Windows\Installer\{f935cc66-766e-6d60-1eaa-31aeda77fbc6}\U\80000000.@ (Rootkit.0Access) -> No action taken.

C:\Windows\Installer\{f935cc66-766e-6d60-1eaa-31aeda77fbc6}\U\80000032.@ (Rootkit.0Access) -> No action taken.

(end)

Link to post
Share on other sites

Malwarebytes Anti-Malware 1.62.0.1300

www.malwarebytes.org

Database version: v2012.08.12.06

Windows 7 Service Pack 1 x86 FAT32

Internet Explorer 9.0.8112.16421

qxlocates :: A10782 [administrator]

Protection: Enabled

8/12/2012 11:05:22 PM

mbam-log-2012-08-12 (23-08-39).txt

Scan type: Quick scan

Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM

Scan options disabled: P2P

Objects scanned: 218891

Time elapsed: 3 minute(s), 5 second(s)

Memory Processes Detected: 0

(No malicious items detected)

Memory Modules Detected: 0

(No malicious items detected)

Registry Keys Detected: 0

(No malicious items detected)

Registry Values Detected: 0

(No malicious items detected)

Registry Data Items Detected: 0

(No malicious items detected)

Folders Detected: 0

(No malicious items detected)

Files Detected: 9

C:\Users\qxlocates\AppData\Local\Temp\sgwe3t.exe (Trojan.Inject) -> No action taken.

C:\Users\qxlocates\Downloads\installer_plants_vs_zombies.exe (PUP.BundleInstaller.BT) -> No action taken.

C:\Users\Administrator.A10782\Local Settings\Application Data\tafyvp.exe (Trojan.LameShield) -> No action taken.

C:\Windows\assembly\GAC\Desktop.ini (Trojan.0access) -> No action taken.

C:\Windows\Installer\{f935cc66-766e-6d60-1eaa-31aeda77fbc6}\U\00000004.@ (Rootkit.Zaccess) -> No action taken.

C:\Windows\Installer\{f935cc66-766e-6d60-1eaa-31aeda77fbc6}\U\00000008.@ (Trojan.Dropper.BCMiner) -> No action taken.

C:\Windows\Installer\{f935cc66-766e-6d60-1eaa-31aeda77fbc6}\U\000000cb.@ (Rootkit.0Access) -> No action taken.

C:\Windows\Installer\{f935cc66-766e-6d60-1eaa-31aeda77fbc6}\U\80000000.@ (Rootkit.0Access) -> No action taken.

C:\Windows\Installer\{f935cc66-766e-6d60-1eaa-31aeda77fbc6}\U\80000032.@ (Rootkit.0Access) -> No action taken.

(end)

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.