Forums
New posts
Search forums
News
Security News
Technology News
Giveaways
Giveaways, Promotions and Contests
Discounts & Deals
Reviews
Users Reviews
Video Reviews
Support
Windows Malware Removal Help & Support
Mac Malware Removal Help & Support
Mobile Malware Removal Help & Support
Blog
Log in
Register
What's new
Search
Search titles only
By:
Search titles only
By:
Reply to thread
Menu
Install the app
Install
JavaScript is disabled. For a better experience, please enable JavaScript in your browser before proceeding.
You are using an out of date browser. It may not display this or other websites correctly.
You should upgrade or use an
alternative browser
.
Forums
Support
Windows Malware Removal Help & Support
“Your computer has been blocked” virus (MoneyPak Scam)
Message
<blockquote data-quote="Kevin Forth" data-source="post: 314709" data-attributes="member: 31741"><p>Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 13-12-2014</p><p>Ran by SYSTEM on REATOGO on 13-12-2014 19:49:34</p><p>Running from D:\</p><p>Platform: Microsoft Windows XP (X86) OS Language: English (United States)</p><p>Internet Explorer Version 8</p><p>Boot Mode: Recovery</p><p>The current controlset is ControlSet002</p><p><strong>ATTENTION!:=====> If the system is bootable FRST must be run from normal or Safe mode to create a complete log.</strong></p><p>Tutorial for Farbar Recovery Scan Tool: <a href="http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/" target="_blank">http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/</a></p><p>==================== Registry (Whitelisted) ==================</p><p>(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)</p><p>HKLM\...\Run: [Apoint] => C:\Program Files\Apoint\Apoint.exe [159744 2007-01-25] (Alps Electric Co., Ltd.)</p><p>HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [254696 2011-04-08] (Sun Microsystems, Inc.)</p><p>HKLM\...\Run: [Dell QuickSet] => C:\Program Files\Dell\QuickSet\quickset.exe [1245184 2008-02-22] (Dell Inc.)</p><p>HKLM\...\Run: [Broadcom Wireless Manager UI] => C:\WINDOWS\system32\WLTRAY.exe [2220032 2008-06-29] (Dell Inc.)</p><p>HKLM\...\Run: [WavXMgr] => C:\Program Files\Wave Systems Corp\Services Manager\Docmgr\bin\WavXDocMgr.exe [92160 2007-09-10] (Wave Systems Corp.)</p><p>HKLM\...\Run: [SecureUpgrade] => C:\Program Files\Wave Systems Corp\SecureUpgrade.exe [218424 2007-09-14] (Wave Systems Corp.)</p><p>HKLM\...\Run: [SigmatelSysTrayApp] => C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe [405504 2007-12-05] (SigmaTel, Inc.)</p><p>HKLM\...\Run: [KADxMain] => C:\WINDOWS\system32\KADxMain.exe [282624 2006-11-02] (Knowles Acoustics)</p><p>HKLM\...\Run: [PDVDDXSrv] => C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe [128296 2008-02-26] (CyberLink Corp.)</p><p>HKLM\...\Run: [ConnectionCenter] => C:\Program Files\Citrix\ICA Client\concentr.exe [304568 2010-10-12] (Citrix Systems, Inc.)</p><p>HKLM\...\Run: [CanonMyPrinter] => C:\Program Files\Canon\MyPrinter\BJMyPrt.exe [1191936 2006-03-21] (CANON INC.)</p><p>HKLM\...\Run: [SSBkgdUpdate] => C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe [155648 2003-09-29] (Scansoft, Inc.)</p><p>HKLM\...\Run: [OpwareSE4] => C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe [69632 2006-03-21] (ScanSoft, Inc.)</p><p>HKLM\...\Run: [APSDaemon] => C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59240 2011-11-01] (Apple Inc.)</p><p>HKLM\...\Run: [QuickTime Task] => C:\Program Files\QuickTime\qttask.exe [421888 2011-10-24] (Apple Inc.)</p><p>HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [421736 2011-12-08] (Apple Inc.)</p><p>HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)</p><p>Winlogon\Notify\gemsafe: C:\Program Files\Gemplus\GemSafe Libraries\BIN\WLEventNotify.dll (Gemplus)</p><p>Winlogon\Notify\PCANotify: C:\Windows\system32\PCANotify.dll (Symantec Corporation)</p><p>HKLM\...\Policies\Explorer: [NoViewContextMenu] 1</p><p>HKLM\...\Policies\Explorer: [NoDesktop] 1 <===== ATTENTION</p><p>HKU\SIEMENS\...\Run: [MSMSGS] => C:\Program Files\Messenger\msmsgs.exe [1695232 2008-04-13] (Microsoft Corporation)</p><p>HKU\SIEMENS\...\Policies\system: [disableregistrytools] 1</p><p>HKU\SIEMENS\...\Policies\system: [DisableTaskMgr] 1</p><p>HKU\SIEMENS\...\Policies\Explorer: [NoViewContextMenu] 1</p><p>Lsa: [Authentication Packages] msv1_0 wvauth</p><p>Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk</p><p>ShortcutTarget: Digital Line Detect.lnk -> C:\Program Files\Digital Line Detect\DLG.exe (Avanquest Software )</p><p>Startup: C:\Documents and Settings\SIEMENS\Start Menu\Programs\Startup\AutoStarter.lnk</p><p>ShortcutTarget: AutoStarter.lnk -> B:\Documents and Settings\Default User\Application Data\autostarter.exe (No File)</p><p>Startup: C:\Documents and Settings\SIEMENS\Start Menu\Programs\Startup\ja.lnk</p><p>ShortcutTarget: ja.lnk -> B:\Documents and Settings\Default User\Application Data\loadit.exe (No File)</p><p>Startup: C:\Documents and Settings\SIEMENS\Start Menu\Programs\Startup\PMB Media Check Tool.lnk</p><p>ShortcutTarget: PMB Media Check Tool.lnk -> C:\Program Files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe (Sony Corporation)</p><p>========================== Services (Whitelisted) =================</p></blockquote><p></p>
[QUOTE="Kevin Forth, post: 314709, member: 31741"] Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 13-12-2014 Ran by SYSTEM on REATOGO on 13-12-2014 19:49:34 Running from D:\ Platform: Microsoft Windows XP (X86) OS Language: English (United States) Internet Explorer Version 8 Boot Mode: Recovery The current controlset is ControlSet002 [b]ATTENTION!:=====> If the system is bootable FRST must be run from normal or Safe mode to create a complete log.[/b] Tutorial for Farbar Recovery Scan Tool: [url]http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/[/url] ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [Apoint] => C:\Program Files\Apoint\Apoint.exe [159744 2007-01-25] (Alps Electric Co., Ltd.) HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [254696 2011-04-08] (Sun Microsystems, Inc.) HKLM\...\Run: [Dell QuickSet] => C:\Program Files\Dell\QuickSet\quickset.exe [1245184 2008-02-22] (Dell Inc.) HKLM\...\Run: [Broadcom Wireless Manager UI] => C:\WINDOWS\system32\WLTRAY.exe [2220032 2008-06-29] (Dell Inc.) HKLM\...\Run: [WavXMgr] => C:\Program Files\Wave Systems Corp\Services Manager\Docmgr\bin\WavXDocMgr.exe [92160 2007-09-10] (Wave Systems Corp.) HKLM\...\Run: [SecureUpgrade] => C:\Program Files\Wave Systems Corp\SecureUpgrade.exe [218424 2007-09-14] (Wave Systems Corp.) HKLM\...\Run: [SigmatelSysTrayApp] => C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe [405504 2007-12-05] (SigmaTel, Inc.) HKLM\...\Run: [KADxMain] => C:\WINDOWS\system32\KADxMain.exe [282624 2006-11-02] (Knowles Acoustics) HKLM\...\Run: [PDVDDXSrv] => C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe [128296 2008-02-26] (CyberLink Corp.) HKLM\...\Run: [ConnectionCenter] => C:\Program Files\Citrix\ICA Client\concentr.exe [304568 2010-10-12] (Citrix Systems, Inc.) HKLM\...\Run: [CanonMyPrinter] => C:\Program Files\Canon\MyPrinter\BJMyPrt.exe [1191936 2006-03-21] (CANON INC.) HKLM\...\Run: [SSBkgdUpdate] => C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe [155648 2003-09-29] (Scansoft, Inc.) HKLM\...\Run: [OpwareSE4] => C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe [69632 2006-03-21] (ScanSoft, Inc.) HKLM\...\Run: [APSDaemon] => C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59240 2011-11-01] (Apple Inc.) HKLM\...\Run: [QuickTime Task] => C:\Program Files\QuickTime\qttask.exe [421888 2011-10-24] (Apple Inc.) HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [421736 2011-12-08] (Apple Inc.) HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) Winlogon\Notify\gemsafe: C:\Program Files\Gemplus\GemSafe Libraries\BIN\WLEventNotify.dll (Gemplus) Winlogon\Notify\PCANotify: C:\Windows\system32\PCANotify.dll (Symantec Corporation) HKLM\...\Policies\Explorer: [NoViewContextMenu] 1 HKLM\...\Policies\Explorer: [NoDesktop] 1 <===== ATTENTION HKU\SIEMENS\...\Run: [MSMSGS] => C:\Program Files\Messenger\msmsgs.exe [1695232 2008-04-13] (Microsoft Corporation) HKU\SIEMENS\...\Policies\system: [disableregistrytools] 1 HKU\SIEMENS\...\Policies\system: [DisableTaskMgr] 1 HKU\SIEMENS\...\Policies\Explorer: [NoViewContextMenu] 1 Lsa: [Authentication Packages] msv1_0 wvauth Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk ShortcutTarget: Digital Line Detect.lnk -> C:\Program Files\Digital Line Detect\DLG.exe (Avanquest Software ) Startup: C:\Documents and Settings\SIEMENS\Start Menu\Programs\Startup\AutoStarter.lnk ShortcutTarget: AutoStarter.lnk -> B:\Documents and Settings\Default User\Application Data\autostarter.exe (No File) Startup: C:\Documents and Settings\SIEMENS\Start Menu\Programs\Startup\ja.lnk ShortcutTarget: ja.lnk -> B:\Documents and Settings\Default User\Application Data\loadit.exe (No File) Startup: C:\Documents and Settings\SIEMENS\Start Menu\Programs\Startup\PMB Media Check Tool.lnk ShortcutTarget: PMB Media Check Tool.lnk -> C:\Program Files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe (Sony Corporation) ========================== Services (Whitelisted) ================= [/QUOTE]
Insert quotes…
Verification
Post reply
Top