New
#11
Ok, here are the results from the re-scan with Rootkits scan. I have quarantined, removed and restarted again.
Malwarebytes Anti-Malware
www.malwarebytes.org
Scan Date: 11/6/2014
Scan Time: 2:39:11 PM
Logfile:
Administrator: Yes
Version: 2.00.3.1025
Malware Database: v2014.11.06.08
Rootkit Database: v2014.11.01.02
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Joe's Servicenter
Scan Type: Custom Scan
Result: Completed
Objects Scanned: 358078
Time Elapsed: 42 min, 26 sec
Memory: Enabled
Startup: Enabled
Filesystem: Disabled
Archives: Enabled
Rootkits: Enabled
Deep Rootkit Scan: Enabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
Processes: 1
Trojan.Agent, C:\Windows\svchost.exe, 3864, , [38631d192b51191d9b995934719224dc]
Modules: 0
(No malicious items detected)
Registry Keys: 0
(No malicious items detected)
Registry Values: 0
(No malicious items detected)
Registry Data: 0
(No malicious items detected)
Folders: 2
Backdoor.0Access, C:\Windows\Installer\{c9e709ff-f391-860c-25d7-5ea7dc9c281b}\L, , [3368360097e5bd7925afde22b44c2ad6],
Backdoor.0Access, C:\Windows\Installer\{c9e709ff-f391-860c-25d7-5ea7dc9c281b}\U, , [1586171fb2ca999de3f25da3748cf50b],
Files: 7
Trojan.Agent, C:\Windows\svchost.exe, , [38631d192b51191d9b995934719224dc],
Backdoor.0Access, C:\Windows\Installer\{c9e709ff-f391-860c-25d7-5ea7dc9c281b}\L\00000004.@, , [3368360097e5bd7925afde22b44c2ad6],
Backdoor.0Access, C:\Windows\Installer\{c9e709ff-f391-860c-25d7-5ea7dc9c281b}\L\201d3dde, , [3368360097e5bd7925afde22b44c2ad6],
Backdoor.0Access, C:\Windows\Installer\{c9e709ff-f391-860c-25d7-5ea7dc9c281b}\U\00000004.@, , [1586171fb2ca999de3f25da3748cf50b],
Backdoor.0Access, C:\Windows\Installer\{c9e709ff-f391-860c-25d7-5ea7dc9c281b}\U\80000000.@, , [1586171fb2ca999de3f25da3748cf50b],
Backdoor.0Access, C:\Windows\Installer\{c9e709ff-f391-860c-25d7-5ea7dc9c281b}\U\80000032.@, , [1586171fb2ca999de3f25da3748cf50b],
Backdoor.0Access, C:\Windows\Installer\{c9e709ff-f391-860c-25d7-5ea7dc9c281b}\U\80000064.@, , [1586171fb2ca999de3f25da3748cf50b],
Physical Sectors: 3
Rootkit.Pihar.c.MBR, Physical Sector #42 on Drive #0, , [53343e92f0bca61cfa4e7b2c1f3cac06],
Rootkit.Pihar.c.MBR, Master Boot Record on Drive #0, , [f0fa67cbefe31582e8cebc9310f7e781],
Forged physical sector, Physical Sector #625141392 on Drive #0, , [0d1cbf0c62511c1e46f08a019c927215],
(end)