Results 1 to 10 of 14

Thread: Vista Antivirus 2011 Infected

Hybrid View

  1. #1
    Join Date
    Mar 2008
    Location
    London England
    Posts
    103
    Hi check suggestions here - once you have posted all the logs required, our security expert can then help you.
    Read Me First Before Requesting Help
    http://forum.networktechs.com/showth...equesting-Help

    Your post may be then moved to the Spyware Central Forum.

  2. #2
    Join Date
    May 2011
    Location
    Jacksonville Fl
    Posts
    10

    Red face

    Thank you, I will read that and post what is necessary..I really do appreciate you guys and gals being available.

  3. #3
    Join Date
    May 2011
    Location
    Jacksonville Fl
    Posts
    10
    I am not sure you got the info that I did a restore date to prior when this Vista Antivius attached itself and I was able to get rid of it that way and then installed the drivers that you suggested..

    I guess all I need now is to know if you know anything about this Vista Antivirus 2012 and this supposed company that drew the funds from my account, Monstrov TV.com, so that I can see about getting my money back that I was stupid enough to give and then had to cancel my card, etc., etc...

  4. #4
    Join Date
    May 2011
    Location
    Jacksonville Fl
    Posts
    10
    Malwarebytes Anti-Malware 1.60.0.1800
    www.malwarebytes.org

    Database version: v2012.01.02.04

    Windows Vista Service Pack 2 x86 NTFS
    Internet Explorer 9.0.8112.16421
    User :: USER-PC [limited]

    1/2/2012 1:38:10 PM
    mbam-log-2012-01-02 (13-38-10).txt

    Scan type: Full scan
    Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
    Scan options disabled: P2P
    Objects scanned: 311268
    Time elapsed: 45 minute(s), 16 second(s)

    Memory Processes Detected: 0
    (No malicious items detected)

    Memory Modules Detected: 0
    (No malicious items detected)

    Registry Keys Detected: 0
    (No malicious items detected)

    Registry Values Detected: 0
    (No malicious items detected)

    Registry Data Items Detected: 0
    (No malicious items detected)

    Folders Detected: 0
    (No malicious items detected)

    Files Detected: 0
    (No malicious items detected)

    (end)


    .
    DDS (Ver_2011-08-26.01) - NTFSx86
    Internet Explorer: 9.0.8112.16421
    Run by User at 13:30:29 on 2012-01-02
    Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.2942.1185 [GMT -5:00]
    .
    SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    .
    ============== Running Processes ===============
    .
    C:\Windows\system32\wininit.exe
    C:\Windows\system32\lsm.exe
    C:\Windows\system32\svchost.exe -k DcomLaunch
    C:\Windows\system32\nvvsvc.exe
    C:\Windows\system32\svchost.exe -k rpcss
    C:\Windows\System32\svchost.exe -k secsvcs
    C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
    C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
    C:\Windows\system32\svchost.exe -k netsvcs
    C:\Windows\system32\svchost.exe -k GPSvcGroup
    C:\Windows\system32\SLsvc.exe
    C:\Windows\system32\svchost.exe -k LocalService
    C:\Windows\system32\rundll32.exe
    C:\Windows\system32\svchost.exe -k NetworkService
    C:\Windows\System32\spoolsv.exe
    C:\Windows\system32\taskeng.exe
    C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
    C:\Windows\system32\Dwm.exe
    C:\Windows\system32\taskeng.exe
    C:\Windows\Explorer.EXE
    C:\Program Files\Windows Defender\MSASCui.exe
    C:\hp\support\hpsysdrv.exe
    C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
    C:\WINDOWS\RtHDVCpl.exe
    C:\Windows\system32\schtasks.exe
    C:\Windows\system32\jusched.exe
    C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
    C:\WINDOWS\System32\rundll32.exe
    C:\Program Files\Microsoft Office Communicator\communicator.exe
    C:\Program Files\Citrix\ICA Client\concentr.exe
    C:\Program Files\Common Files\Java\Java Update\jusched.exe
    C:\Program Files\Ask.com\Updater\Updater.exe
    C:\Program Files\SFT\GuardedID\GIDD.exe
    C:\Program Files\Windows Sidebar\sidebar.exe
    C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier.exe
    C:\Program Files\Common Files\SupportSoft\bin\bcont.exe
    C:\Program Files\comcasttb\ComcastSpywareScan\ComcastAntiSpy. exe
    C:\Program Files\W3i\InstallIQUpdater\InstallIQUpdater.exe
    C:\Program Files\Windows Media Player\wmpnscfg.exe
    C:\WINDOWS\ehome\ehtray.exe
    C:\Program Files\Constant Guard Protection Suite\IDVault.exe
    C:\Program Files\Citrix\ICA Client\wfcrun32.exe
    C:\Windows\ehome\ehmsas.exe
    C:\Program Files\comcasttb\ComcastSpywareScan\ComcastAntiSpyS ervice.exe
    C:\Program Files\CA\PPRT\bin\ITMRTSVC.exe
    c:\Program Files\Common Files\LightScribe\LSSrvc.exe
    C:\Program Files\Common Files\Motive\McciCMService.exe
    C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
    C:\Windows\system32\svchost.exe -k imgsvc
    C:\Windows\System32\svchost.exe -k WerSvcGroup
    C:\Windows\system32\SearchIndexer.exe
    C:\Windows\system32\WUDFHost.exe
    C:\Windows\system32\DRIVERS\xaudio.exe
    C:\Program Files\Constant Guard Protection Suite\IDVaultSvc.exe
    C:\Program Files\Windows Media Player\wmpnetwk.exe
    C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
    C:\Windows\Microsoft.Net\Framework\v3.0\WPF\Presen tationFontCache.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe
    C:\hp\kbd\kbd.exe
    c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Users\User\AppData\Local\Google\Update\GoogleUp date.exe
    C:\Program Files\Google\Update\GoogleUpdate.exe
    C:\Windows\system32\taskeng.exe
    C:\Windows\system32\taskeng.exe
    C:\Windows\System32\mobsync.exe
    C:\Windows\System32\svchost.exe -k swprv
    c:\program files\windows defender\MpCmdRun.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Windows\system32\SearchProtocolHost.exe
    C:\Windows\system32\SearchFilterHost.exe
    C:\Windows\system32\SearchProtocolHost.exe
    C:\Windows\system32\wbem\wmiprvse.exe
    .
    ============== Pseudo HJT Report ===============
    .
    mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=74&bd=Pavilion &pf=desktop
    mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=74&bd=Pavilion &pf=desktop
    uURLSearchHooks: UrlSearchHook Class: {00000000-6e41-4fd3-8538-502f5495e5fc} - c:\program files\ask.com\GenericAskToolbar.dll
    BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
    BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
    BHO: XFINITY Toolbar: {4b9bcce8-a70b-402a-a7e1-db96831ee26f} - c:\program files\xfin_portal\comcastdx.dll
    BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
    BHO: Constant Guard Protection Suite (COM): {b84cdbe7-1b46-494b-a188-01d4c52deb61} - c:\program files\constant guard protection suite\NativeBHO.dll
    BHO: Updater For XFIN_PORTAL: {bb46be07-13eb-4c49-b0f0-fc78b9ea4983} - c:\program files\xfin_portal\auxi\comcastAu.dll
    BHO: Ask Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll
    BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
    TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
    TB: XFINITY Toolbar: {4b9bcce8-a70b-402a-a7e1-db96831ee26f} - c:\program files\xfin_portal\comcastdx.dll
    TB: Ask Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll
    TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
    uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
    uRun: [HPAdvisor] c:\program files\hewlett-packard\hp advisor\HPAdvisor.exe autoRun
    uRun: [Google Update] "c:\users\user\appdata\local\google\update\GoogleU pdate.exe" /c
    uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNo tifier.exe"
    uRun: [Desktop Software] "c:\program files\common files\supportsoft\bin\bcont.exe" /ini "c:\program files\comcastui\desktop software\uinstaller.ini" /fromrun /starthidden
    uRun: [ComcastAntispyClient] "c:\program files\comcasttb\comcastspywarescan\ComcastAntispy. exe" /hide
    uRun: [InstallIQUpdater] "c:\program files\w3i\installiqupdater\InstallIQUpdater.exe" /silent /autorun
    uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
    uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
    mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
    mRun: [hpsysdrv] c:\hp\support\hpsysdrv.exe
    mRun: [KBD] c:\hp\kbd\KbdStub.EXE
    mRun: [OsdMaestro] "c:\program files\hewlett-packard\on-screen osd indicator\OSD.exe"
    mRun: [RtHDVCpl] RtHDVCpl.exe
    mRun: [HP Health Check Scheduler] c:\program files\hewlett-packard\hp health check\HPHC_Scheduler.exe
    mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
    mRun: [SunJavaUpdateReg] "c:\windows\system32\jureg.exe"
    mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
    mRun: [<NO NAME>]
    mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
    mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
    mRun: [Communicator] "c:\program files\microsoft office communicator\communicator.exe" /fromrunkey
    mRun: [ConnectionCenter] "c:\program files\citrix\ica client\concentr.exe" /startup
    mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
    mRun: [ApnUpdater] "c:\program files\ask.com\updater\Updater.exe"
    mRun: [GIDDesktop] c:\program files\sft\guardedid\gidd.exe /s
    mRunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
    StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\sta rtup\consta~1.lnk - c:\program files\constant guard protection suite\IDVault.exe
    mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
    mPolicies-system: EnableLUA = 0 (0x0)
    mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
    IE: {76c5fb99-dd0a-4186-9e75-65d1bf3da283} - c:\program files\amazon\add to wish list ie extension\run.htm
    Trusted Zone: newcorp.com
    Trusted Zone: rhapsody.com\rhap-app-4-0
    Trusted Zone: rhapsody.com\rhapreg
    DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\Yinsthelper.dll
    DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
    TCP: DhcpNameServer = 192.168.2.1
    TCP: Interfaces\{44E91E31-CEE2-44E4-BA85-05163E882258} : DhcpNameServer = 192.168.2.1
    TCP: Interfaces\{646B8FC8-6C74-49F7-8E62-DCF8F8BF72EB} : DhcpNameServer = 192.168.99.12
    Filter: application/x-ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
    Filter: application/x-ica; charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
    Filter: application/x-ica; charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
    Filter: application/x-ica; charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
    Filter: application/x-ica; charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
    Filter: application/x-ica; charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
    Filter: application/x-ica; charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
    Filter: application/x-ica; charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
    Filter: application/x-ica;charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
    Filter: application/x-ica;charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
    Filter: application/x-ica;charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
    Filter: application/x-ica;charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
    Filter: application/x-ica;charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
    Filter: application/x-ica;charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
    Filter: application/x-ica;charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
    Filter: ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
    mASetup: {9191979D-821C-4EA8-B021-2DA1D859A7C5}-3Reg - c:\program files\sft\guardedid\gidi.exe /v
    .
    ============= SERVICES / DRIVERS ===============
    .
    R1 ctxusbm;Citrix USB Monitor Driver;c:\windows\system32\drivers\ctxusbm.sys [2010-7-14 65584]
    R1 GIDv2;GIDv2;c:\windows\system32\drivers\gidv2.sys [2011-11-2 25232]
    R2 AntiSpywareService;Comcast AntiSpyware;c:\program files\comcasttb\comcastspywarescan\ComcastAntiSpyS ervice.exe [2009-6-17 616408]
    R2 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2011-8-2 21504]
    R2 IDVaultSvc;CGPS Service;c:\program files\constant guard protection suite\IDVaultSvc.exe [2011-12-17 63048]
    S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\ v4.0.30319\mscorsvw.exe [2010-3-18 130384]
    S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2011-8-14 136176]
    S3 ADM8511;ADMtek ADM8511 USB To Fast Ethernet Converter;c:\windows\system32\drivers\NET8511.SYS [2011-7-29 24459]
    S3 androidusb;SAMSUNG Android Composite ADB Interface Driver;c:\windows\system32\drivers\ssadadb.sys [2011-5-13 30312]
    S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2011-8-14 136176]
    S3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);c:\windows\system32\drivers\ssadbus.sys [2011-5-13 121064]
    S3 ssadmdfl;SAMSUNG Android USB Modem (Filter);c:\windows\system32\drivers\ssadmdfl.sys [2011-5-13 12776]
    S3 ssadmdm;SAMSUNG Android USB Modem Drivers;c:\windows\system32\drivers\ssadmdm.sys [2011-5-13 136808]
    S3 ssmirrdr;ssmirrdr;c:\windows\system32\drivers\ssmi rrdr.sys [2011-10-3 10112]
    S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30 319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
    .
    =============== Created Last 30 ================
    .
    2012-01-02 18:29:27 -------- d-----w- C:\rei
    2012-01-02 18:29:22 -------- d-----w- c:\program files\Reimage
    2012-01-01 00:04:24 56200 ----a-w- c:\programdata\microsoft\windows defender\definition updates\{699f728a-5b63-46c0-8679-f48aa5de8b84}\offreg.dll
    2012-01-01 00:04:22 6823496 ----a-w- c:\programdata\microsoft\windows defender\definition updates\{699f728a-5b63-46c0-8679-f48aa5de8b84}\mpengine.dll
    2011-12-31 06:24:44 -------- d-----w- c:\program files\ESET
    2011-12-31 06:18:52 -------- d-----w- c:\users\user\appdata\roaming\Malwarebytes
    2011-12-31 06:18:47 -------- d-----w- c:\programdata\Malwarebytes
    2011-12-31 06:18:46 20464 ----a-w- c:\windows\system32\drivers\mbam.sys
    2011-12-31 06:18:46 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
    2011-12-30 20:41:48 -------- d-----w- c:\program files\Microsoft Security Client
    2011-12-25 15:49:05 -------- d-----w- c:\users\user\appdata\local\HP
    2011-12-17 01:50:46 652296 ----a-w- c:\programdata\microsoft\ehome\packages\sportstemp late\sportstemplatecore\Microsoft.MediaCenter.Spor ts.UI.dll
    2011-12-17 01:50:33 677136 ----a-w- c:\programdata\microsoft\ehome\packages\mcespotlig ht\mcespotlight\SpotlightResources.dll
    2011-12-17 01:50:21 416128 ----a-w- c:\programdata\microsoft\ehome\packages\nettv\brow se\NetTVResources.dll
    2011-12-16 08:01:02 2382848 ----a-w- c:\windows\system32\mshtml.tlb
    2011-12-16 08:01:01 194048 ----a-w- c:\program files\internet explorer\IEShims.dll
    2011-12-16 08:01:01 141112 ----a-w- c:\program files\internet explorer\sqmapi.dll
    2011-12-16 08:01:00 1798144 ----a-w- c:\windows\system32\jscript9.dll
    2011-12-16 08:01:00 1127424 ----a-w- c:\windows\system32\wininet.dll
    2011-12-16 08:00:59 678912 ----a-w- c:\program files\internet explorer\iedvtool.dll
    2011-12-16 08:00:57 1427456 ----a-w- c:\windows\system32\inetcpl.cpl
    2011-12-15 18:11:07 429056 ----a-w- c:\windows\system32\EncDec.dll
    2011-12-15 18:11:07 3602816 ----a-w- c:\windows\system32\ntkrnlpa.exe
    2011-12-15 18:11:06 3550080 ----a-w- c:\windows\system32\ntoskrnl.exe
    2011-12-15 18:11:05 2043904 ----a-w- c:\windows\system32\win32k.sys
    2011-12-15 18:11:04 2409784 ----a-w- c:\program files\windows mail\OESpamFilter.dat
    2011-12-15 18:11:03 49152 ----a-w- c:\windows\system32\csrsrv.dll
    2011-12-15 18:10:35 2048 ----a-w- c:\windows\system32\tzres.dll
    2011-12-11 08:03:08 -------- d-----w- c:\program files\Microsoft CAPICOM 2.1.0.2
    .
    ==================== Find3M ====================
    .
    2011-11-16 14:18:36 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
    2011-11-15 19:29:56 222080 ------w- c:\windows\system32\MpSigStub.exe
    .
    =================== ROOTKIT ====================
    .
    Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
    Windows 6.0.6002
    .
    CreateFile("\\.\PHYSICALDRIVE0"): The process cannot access the file because it is being used by another process.
    device: opened successfully
    user: error reading MBR
    .
    Disk trace:
    called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll storport.sys nvstor32.sys
    c:\windows\system32\drivers\nvstor32.sys NVIDIA Corporation NVIDIA nForce(TM) SATA Driver
    1 ntkrnlpa!IofCallDriver[0x81E5B912] -> \Device\Harddisk0\DR0[0x862B1278]
    3 CLASSPNP[0x8A3AB8B3] -> ntkrnlpa!IofCallDriver[0x81E5B912] -> [0x852364A0]
    5 acpi[0x89C0F6BC] -> ntkrnlpa!IofCallDriver[0x81E5B912] -> \Device\0000004b[0x84888C90]
    kernel: MBR read successfully
    _asm { XOR DI, DI; MOV SI, 0x200; MOV SS, DI; MOV SP, 0x7a00; MOV BX, 0x7a0; MOV CX, SI; MOV DS, BX; MOV ES, BX; REP MOVSB ; JMP FAR 0x7a0:0x5d; }
    user != kernel MBR !!!
    .
    ============= FINISH: 13:31:12.83 ===============

  5. #5
    David H. Lipman Guest

    Re: Vista Antivirus 2011 Infected

    From: "td1harris" <td1harris.55s2w9@no-mx.forum.networktechs.com>

    vBulletin USENET gateway

    --
    Dave
    Multi-AV Scanning Tool - http://multi-av.thespykiller.co.uk
    http://www.pctipp.ch/downloads/dl/35905.asp



  6. #6
    FromTheRafters Guest

    Re: Vista Antivirus 2011 Infected

    David H. Lipman wrote:
    > From: "td1harris"<td1harris.55s2w9@no-mx.forum.networktechs.com>
    >
    > vBulletin USENET gateway
    >

    Apparently (and thankfully) truncated at the 'dot'.

    http://forum.networktechs.com/showth...-2011-Infected

    They can't even do NNTP right. LOL



  7. #7
    David H. Lipman Guest

    Re: Vista Antivirus 2011 Infected

    From: "FromTheRafters" <erratic@nomail.afraid.org>

    > David H. Lipman wrote:
    >> From: "td1harris"<td1harris.55s2w9@no-mx.forum.networktechs.com>
    >>
    >> vBulletin USENET gateway
    >>

    > Apparently (and thankfully) truncated at the 'dot'.
    >
    > http://forum.networktechs.com/showth...-2011-Infected
    >
    > They can't even do NNTP right. LOL
    >


    Yepper.



    --
    Dave
    Multi-AV Scanning Tool - http://multi-av.thespykiller.co.uk
    http://www.pctipp.ch/downloads/dl/35905.asp



  8. #8
    G. Morgan Guest

    Re: Vista Antivirus 2011 Infected

    David H. Lipman wrote:


    >vBulletin USENET gateway


    You don't like those?


  9. #9
    David H. Lipman Guest

    Re: Vista Antivirus 2011 Infected

    From: "G. Morgan" <sealteam6@osama-is-dead.net>

    > David H. Lipman wrote:
    >
    >
    >> vBulletin USENET gateway

    >
    > You don't like those?


    No. They suck.

    They are used by web sites that make believe they have forums when in reality they are
    using Usenet news groups.


    --
    Dave
    Multi-AV Scanning Tool - http://multi-av.thespykiller.co.uk
    http://www.pctipp.ch/downloads/dl/35905.asp



  10. #10
    G. Morgan Guest

    Re: Vista Antivirus 2011 Infected

    David H. Lipman wrote:

    >From: "G. Morgan" <sealteam6@osama-is-dead.net>
    >
    >> David H. Lipman wrote:
    >>
    >>
    >>> vBulletin USENET gateway

    >>
    >> You don't like those?

    >
    >No. They suck.
    >
    >They are used by web sites that make believe they have forums when in reality they are
    >using Usenet news groups.


    I was thinking about setting one up @ alt-comp-freeware.info. It would
    be heavily filtered to just show relevant articles. The S/N ratio there
    is something like 25/75, but the 25% is nice content.






Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •