Jump to content

Recommended Posts

  • Staff

Hi and welcome to Malwarebytes.

Please update MBAM, run a Quick Scan, and post its log.

Next, download DDS by sUBs and save it to your Desktop.

Double-click on the DDS icon and let the scan run. When it has run two logs will be produced, please post DDS.txt and attach.txt directly into your reply.

Link to post
Share on other sites

Here is my Updated Log: the quarantine now shows the original 5 Broken-open command entries dated 4-9-2011, but now also shows an additional 5 entries dated 5-19-2011! By the way, I had to copy this file as I cannot save any documents or files to my computer, it won't let me.

Malwarebytes' Anti-Malware 1.50.1.1100

www.malwarebytes.org

Database version: 6647

Windows 6.0.6002 Service Pack 2

Internet Explorer 9.0.8112.16421

5/23/2011 12:45:05 AM

mbam-log-2011-05-23 (00-45-05).txt

Scan type: Quick scan

Objects scanned: 204015

Time elapsed: 7 minute(s), 48 second(s)

Memory Processes Infected: 0

Memory Modules Infected: 0

Registry Keys Infected: 0

Registry Values Infected: 0

Registry Data Items Infected: 0

Folders Infected: 0

Files Infected: 0

Memory Processes Infected:

(No malicious items detected)

Memory Modules Infected:

(No malicious items detected)

Registry Keys Infected:

(No malicious items detected)

Registry Values Infected:

(No malicious items detected)

Registry Data Items Infected:

(No malicious items detected)

Folders Infected:

(No malicious items detected)

Files Infected:

(No malicious items detected)

Link to post
Share on other sites

I downloaded DDS to USB then moved it to my Desktop and double clicked to open and this is the result:

.

DDS (Ver_11-05-19.01) - NTFSx86

Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_11

Run by Magic at 13:26:30 on 2011-05-24

Microsoft

Link to post
Share on other sites

How do I attach the other file to my post? I am using a different computer to correspond with you as the one we are fixing will not save any documents. I don't know how to attach the attach.txt file to the USB drive. Do I copy it or move it or ??? Sorry I don't mean to be so dense, just haven't done this before.

Link to post
Share on other sites

Here is a previous log. It keeps coming back and I don't know how.

Malwarebytes' Anti-Malware 1.50.1.1100

www.malwarebytes.org

Database version: 6620

Windows 6.0.6002 Service Pack 2

Internet Explorer 9.0.8112.16421

5/19/2011 6:18:14 PM

mbam-log-2011-05-19 (18-18-14).txt

Scan type: Full scan (C:\|)

Objects scanned: 374628

Time elapsed: 1 hour(s), 4 minute(s), 55 second(s)

Memory Processes Infected: 0

Memory Modules Infected: 0

Registry Keys Infected: 0

Registry Values Infected: 0

Registry Data Items Infected: 5

Folders Infected: 0

Files Infected: 0

Memory Processes Infected:

(No malicious items detected)

Memory Modules Infected:

(No malicious items detected)

Registry Keys Infected:

(No malicious items detected)

Registry Values Infected:

(No malicious items detected)

Registry Data Items Infected:

HKEY_CLASSES_ROOT\batfile\shell\open\command\(default) (Broken.OpenCommand) -> Bad: (NOTEPAD.EXE %1) Good: ("%1" %*) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\comfile\shell\open\command\(default) (Broken.OpenCommand) -> Bad: (NOTEPAD.EXE %1) Good: ("%1" %*) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\piffile\shell\open\command\(default) (Broken.OpenCommand) -> Bad: (NOTEPAD.EXE %1) Good: ("%1" %*) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\scrfile\shell\open\command\(default) (Broken.OpenCommand) -> Bad: (NOTEPAD.EXE %1) Good: ("%1" /S) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\regfile\shell\open\command\(default) (Broken.OpenCommand) -> Bad: (NOTEPAD.EXE %1) Good: (regedit.exe "%1") -> Quarantined and deleted successfully.

Folders Infected:

(No malicious items detected)

Files Infected:

(No malicious items detected)

Link to post
Share on other sites

  • 2 weeks later...
  • Staff

Due to the lack of feedback this topic is closed to prevent others from posting here. If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread.

Other members who need assistance please start your own topic in a new thread. Thanks!

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.