Author Topic: virus on my sons computer  (Read 6660 times)

0 Members and 1 Guest are viewing this topic.

December 03, 2014, 03:20:10 pm

blankenship.shawna@gmail.

  • Newbie

  • Offline
  • *

  • 3
  • Reputation:
    0
    • View Profile
virus on my sons computer
« on: December 03, 2014, 03:20:10 pm »
This is my sons computer it is a gateway with windows 8. I have been having problems with my internet connection on all the computers in the home and I believe that this computer is what is causing the problem. I downloaded rouge killer and it found all kinds of things. But I am not very familiar with this scanner and was hoping someone would look at it and advise me on what I should do. Thanks in advance for any help offered. Shawn


I tried to post the log but it gave me an error so I thought i would copy/paste it here. I hope that is OK



RogueKiller V10.0.8.0 (x64) [Nov 20 2014] by Adlice Software
mail : http://www.adlice.com/contact/
Feedback : http://forum.adlice.com
Website : http://www.adlice.com/softwares/roguekiller/
Blog : http://www.adlice.com

Operating System : Windows 8.1 (6.3.9200 ) 64 bits version
Started in : Normal mode
User : Tyler [Administrator]
Mode : Scan -- Date : 12/03/2014  08:59:18

Processes : 1
[PUP] (SVC) vToolbarUpdater18.1.10 -- C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.10\ToolbarUpdater.exe[7] -> Stopped

Registry : 41
[PUP] (X64) HKEY_CLASSES_ROOT\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23} -> Found
[PUP] (X64) HKEY_CLASSES_ROOT\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52} -> Found
[PUP] (X64) HKEY_CLASSES_ROOT\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233} -> Found
[PUP] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233} -> Found
[PUP] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233} -> Found
[PUP] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run | vProt : "C:\Program Files (x86)\AVG Web TuneUp\vprot.exe"  -> Found
[PUP] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\70e6ca8c -> Found
[Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MediaDevSrv ("C:\ProgramData\MediaDev\1403317883\mediadev.exe") -> Found
[PUP] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\SPPD -> Found
[PUP] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\vToolbarUpdater18.1.10 (C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.10\ToolbarUpdater.exe) -> Found
[Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\WinDevSrv ("C:\ProgramData\Online\sv.exe") -> Found
[PUP] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\70e6ca8c -> Found
[Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MediaDevSrv ("C:\ProgramData\MediaDev\1403317883\mediadev.exe") -> Found
[PUP] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SPPD -> Found
[PUP] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\vToolbarUpdater18.1.10 (C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.10\ToolbarUpdater.exe) -> Found
[Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WinDevSrv ("C:\ProgramData\Online\sv.exe") -> Found
[PUM.Proxy] (X64) HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings | ProxyEnable : 1  -> Found
[PUM.Proxy] (X86) HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings | ProxyEnable : 1  -> Found
[PUM.Proxy] (X64) HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings | ProxyEnable : 1  -> Found
[PUM.Proxy] (X86) HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings | ProxyEnable : 1  -> Found
[PUM.Proxy] (X64) HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings | ProxyEnable : 1  -> Found
[PUM.Proxy] (X86) HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings | ProxyEnable : 1  -> Found
[PUM.Proxy] (X64) HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings | ProxyEnable : 1  -> Found
[PUM.Proxy] (X86) HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings | ProxyEnable : 1  -> Found
[PUM.Proxy] (X64) HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings | ProxyServer : http=127.0.0.1:8118;https=127.0.0.1:8118  -> Found
[PUM.Proxy] (X86) HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings | ProxyServer : http=127.0.0.1:8118;https=127.0.0.1:8118  -> Found
[PUM.Proxy] (X64) HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings | ProxyServer : http=127.0.0.1:8118;https=127.0.0.1:8118  -> Found
[PUM.Proxy] (X86) HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings | ProxyServer : http=127.0.0.1:8118;https=127.0.0.1:8118  -> Found
[PUM.HomePage] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main | Start Page : http://www.v9.com/?type=hp&ts=1403388892&from=ymb&uid=ST500DM002-1BD142_W2AYD4W7XXXXW2AYD4W7&i=psd&t=3447c269e  -> Found
[PUM.HomePage] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main | Start Page : auto:blank  -> Found
[PUM.HomePage] (X64) HKEY_USERS\S-1-5-21-313167939-755004142-3105939643-1001\Software\Microsoft\Internet Explorer\Main | Start Page : https://search.yahoo.com/?type=198484&fr=spigot-yhp-ie  -> Found
[PUM.HomePage] (X86) HKEY_USERS\S-1-5-21-313167939-755004142-3105939643-1001\Software\Microsoft\Internet Explorer\Main | Start Page : https://search.yahoo.com/?type=198484&fr=spigot-yhp-ie  -> Found
[PUM.HomePage] (X64) HKEY_USERS\S-1-5-21-313167939-755004142-3105939643-501\Software\Microsoft\Internet Explorer\Main | Start Page : http://acer13.msn.com  -> Found
[PUM.HomePage] (X86) HKEY_USERS\S-1-5-21-313167939-755004142-3105939643-501\Software\Microsoft\Internet Explorer\Main | Start Page : http://acer13.msn.com  -> Found
[PUM.SearchPage] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main | Search Page : http://search.v9.com/web/?type=ds&ts=1403388892&from=ymb&uid=ST500DM002-1BD142_W2AYD4W7XXXXW2AYD4W7&i=psd&t=3447c269e&q={searchTerms}  -> Found
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{B5B6E80B-A4BF-4B04-90ED-573BA531BD03} | NameServer : 76.73.6.108,50.7.75.28  -> Found
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{B5B6E80B-A4BF-4B04-90ED-573BA531BD03} | NameServer : 76.73.6.108,50.7.75.28  -> Found
[PUM.DesktopIcons] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1  -> Found
[PUM.DesktopIcons] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1  -> Found
[PUM.DesktopIcons] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1  -> Found
[PUM.DesktopIcons] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1  -> Found

Tasks : 0

Files : 0

Hosts File : 0

Antirootkit : 1 (Driver: Loaded)
[IAT:Inl] (explorer.exe @ KERNELBASE.dll) ntdll.dll - NtWriteVirtualMemory : C:\Program Files (x86)\AVG\AVG2015\avghooka.dll @ 0x7ffd46151000 (jmp 0xfffffffff3d6f5f0)

Web browsers : 0

MBR Check :
+++++ PhysicalDrive0: ST500DM002-1BD142 +++++
--- User ---
[MBR] 5070e5b05174ff88dc4a8982e4bbcc09
[BSP] 5b026720ad3d5c823ef69be945742788 : Empty MBR Code
Partition table:
0 - [XXXXXX] UNKNOWN (0x0) [VISIBLE] Offset (sectors): 1 | Size: 2097152 MB
User = LL1 ... OK
User = LL2 ... OK


Reply #1December 04, 2014, 10:35:37 am

Tigzy

  • Administrator
  • Hero Member

  • Offline
  • *****

  • 809
  • Reputation:
    91
  • Personal Text
    Owner, Adlice Software
    • View Profile
    • Adlice Software
Re: virus on my sons computer
« Reply #1 on: December 04, 2014, 10:35:37 am »
Hello
I only see PUPs and PUMs, so not critical.

Reply #2December 04, 2014, 05:03:47 pm

blankenship.shawna@gmail.

  • Newbie

  • Offline
  • *

  • 3
  • Reputation:
    0
    • View Profile
Re: virus on my sons computer
« Reply #2 on: December 04, 2014, 05:03:47 pm »
Thanks for replying Tigzy. So is it OK to delete everything that was found? Also, every time I click on a link or just the page I get a new popup window telling my computer is infected, and i was wondering if I do delete those items will that behavior stop?

Reply #3December 04, 2014, 05:10:17 pm

Tigzy

  • Administrator
  • Hero Member

  • Offline
  • *****

  • 809
  • Reputation:
    91
  • Personal Text
    Owner, Adlice Software
    • View Profile
    • Adlice Software
Re: virus on my sons computer
« Reply #3 on: December 04, 2014, 05:10:17 pm »
Yeah, remove everything, can't hurt

Reply #4December 07, 2014, 05:52:21 pm

blankenship.shawna@gmail.

  • Newbie

  • Offline
  • *

  • 3
  • Reputation:
    0
    • View Profile
Re: virus on my sons computer
« Reply #4 on: December 07, 2014, 05:52:21 pm »
Thank you very much