MBAM results are in
Malwarebytes’ Anti-Malware 1.28
Database version: 1253
Windows 5.1.2600 Service Pack 2
11/10/2008 12:11:59
mbam-log-2008-10-11 (12-11-59).txt
Scan type: Full Scan (C:|)
Objects scanned: 133609
Time elapsed: 48 minute(s), 49 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 38
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 10
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CLASSES_ROOT\retro64_loader.r64loader (Trojan.Downloader) → Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\retro64_loader.r64loader.1 (Trojan.Downloader) → Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\videoegg.activexloader (Adware.VideoEgg) → Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\videoegg.activexloader.1 (Adware.VideoEgg) → Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface{339d8aff-0b42-4260-ad82-78ce605a9543} (Trojan.BHO) → Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface{450b9e4d-4014-4de3-b34e-014a81468293} (Trojan.Downloader) → Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface{7b178417-3cda-444f-94ff-312c0a3a78a8} (Adware.180Solutions) → Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface{a36a5936-cfd9-4b41-86bd-319a1931887f} (Trojan.BHO) → Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface{aa4939c3-deca-4a48-a454-97cd587c0ef5} (Adware.NetOptimizer) → Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface{eee4a2e5-9f56-432f-a6ed-f6f625b551e0} (Adware.NetOptimizer) → Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID{e282c728-189d-419e-8ee2-1601f4b39ba5} (Adware.VideoEgg) → Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID{e1a63484-a022-4d42-830a-fbd411514440} (Adware.VideoEgg) → Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID{dc3a04ee-cdd7-4407-915c-a5502f97eecd} (Adware.VideoEgg) → Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID{db8cce99-59c6-4552-8bfc-058feb38d6ce} (Adware.VideoEgg) → Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID{d17726cc-d4dd-4c4a-9671-471d56e413b5} (Adware.VideoEgg) → Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID{c5041fd9-4819-4dc4-b20e-c950b5b03d2a} (Adware.VideoEgg) → Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID{bb187c0d-6f53-4f3e-9590-98fd3a7364a2} (Adware.VideoEgg) → Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID{af2e62b6-f9e1-4d4f-a10a-9dc8e6dcbcc0} (Adware.VideoEgg) → Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID{ad5915ea-b61a-4dba-b5c8-ef4b2df0a3c7} (Adware.VideoEgg) → Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID{ad0a3058-fd49-4f98-a514-fd055201835e} (Adware.VideoEgg) → Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID{a58c497b-3ee2-45e7-9594-daca6be2a0d0} (Adware.VideoEgg) → Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID{a3d06987-c35e-49e4-8fe2-ac67b9fbfb4c} (Adware.VideoEgg) → Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID{9856e2d8-ffb2-4fe5-8cad-d5ad6a35a804} (Adware.VideoEgg) → Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID{8f6a82a2-d7b1-443e-bb9f-f7dc887dd618} (Adware.VideoEgg) → Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID{88d6cf0e-cf70-4c24-bf6e-e4e414bc649c} (Adware.VideoEgg) → Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID{83dfb6ee-ab18-41b5-86d4-b544a141d67e} (Adware.VideoEgg) → Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID{5c29c7e4-5321-4cad-be2e-877666bed5df} (Adware.VideoEgg) → Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID{3f91eb90-ef62-44ee-a685-fac29af111cd} (Adware.VideoEgg) → Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID{1a8642f1-dc80-4edc-a39d-0fb62a58b455} (Adware.VideoEgg) → Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID{168dc258-1455-4e61-8590-9dac2f27b675} (Adware.VideoEgg) → Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID{288c5f13-7e52-4ada-a32e-f5bf9d125f99} (Trojan.Downloader) → Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib{c7f00a9a-f1bc-436e-82c7-e8cae6fd67f7} (Trojan.Downloader) → Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units{af2e62b6-f9e1-4d4f-a10a-9dc8e6dcbcc0} (Adware.VideoEgg) → Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units{b64f4a7c-97c9-11da-8bde-f66bad1e3f3a} (Rogue.WinAntivirus) → Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units{288c5f13-7e52-4ada-a32e-f5bf9d125f99} (Trojan.Downloader) → Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\VideoEgg (Adware.VideoEgg) → Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins@videoegg.com/publisher,version=1.5 (Adware.VideoEgg) → Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\IMAdvertiser (Adware.SearchTwo) → Quarantined and deleted successfully.
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mapouquoo (Trojan.FakeAlert.H) → Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
C:\WINDOWS\system32\hojyr.exe (Trojan.FakeAlert.H) → Delete on reboot.
C:\WINDOWS\system32\h@tkeysh@@k.dll (Trojan.Agent) → Quarantined and deleted successfully.
C:\WINDOWS\system32\cmd.com (Worm.Alcra) → Quarantined and deleted successfully.
C:\WINDOWS\system32\netstat.com (Worm.Alcra) → Quarantined and deleted successfully.
C:\WINDOWS\system32\ping.com (Worm.Alcra) → Quarantined and deleted successfully.
C:\WINDOWS\system32\regedit.com (Worm.Alcra) → Quarantined and deleted successfully.
C:\WINDOWS\system32\tasklist.com (Worm.Alcra) → Quarantined and deleted successfully.
C:\WINDOWS\system32\tracert.com (Worm.Alcra) → Quarantined and deleted successfully.
C:\WINDOWS\system32\ClickToFindandFixErrors_Intl.ico (Malware.Trace) → Quarantined and deleted successfully.
C:\Documents and Settings\martin keohane\Desktop\Internet Security Suite.url (Rogue.Link) → Quarantined and deleted successfully.
One file could not be quarantined, don’t know why but will be deleted on reboot
C:\WINDOWS\system32\hojyr.exe
It is the file I originally thought was the virus
I can now see the contents of the system32 folder so somethings going right
Good call on MBAM wyrmrider Thanks!!