Yet Another MSN Virus.

If you need more time, simply let me know.

Please refrain from running any tools, fixes or applying any changes to your computer other than those I suggest.

Calvet and ESET later obtained the malware payloads and determined that Casper was a "discreet" reconnaissance tool designed to profile its victims and send a detailed report back to the attackers. Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 12 HKLM\SYSTEM\CurrentControlSet\Services\WSearch (Trojan.FakeMS) -> Quarantined and deleted successfully. The process will initiate multiple ip connections and uses obscene amounts of bandwidth (2.5 GB one day). It has done this 35 time(s). 02/01/2013 7:13:48 PM, Error: Service Control Manager [7034] - The McAfee McShield service terminated unexpectedly.

C:\Windows\Microsoft.NET\Framework\v2.0.50727\ngen.exe (Trojan.FakeMS) -> Quarantined and deleted successfully. Physical Sector Size: 0 Drive: 1, DevicePointer: 0xfffffa8005e24060, DeviceName: \Device\Harddisk1\DR1\, DriverName: \Driver\Disk\ --------- Disk Stack ------ DevicePointer: 0xfffffa8005e24b90, DeviceName: Unknown, DriverName: \Driver\partmgr\ DevicePointer: 0xfffffa8005e24060, DeviceName: \Device\Harddisk1\DR1\, DriverName: \Driver\Disk\ DevicePointer: 0xfffffa8005e02150, DeviceName: C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k RPCSS C:\Windows\system32\atiesrxx.exe C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k LocalService C:\Program Files\Dell\DellDock\DockLogin.exe C:\Windows\system32\atieclxx.exe C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\System32\spoolsv.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files Lots of Trojans.

It has done this 2 time(s). 02/01/2013 7:01:54 PM, Error: Service Control Manager [7034] - The McAfee McShield service terminated unexpectedly. HKCR\TypeLib\{00A40DB9-D8B4-40B3-8E0C-A8E8C6B3B720} (Trojan.FakeMS) -> Delete on reboot. C:\Windows\System32\regini.exe (Trojan.FakeMS) -> Quarantined and deleted successfully. It has done this 33 time(s). 02/01/2013 7:13:37 PM, Error: Service Control Manager [7034] - The McAfee McShield service terminated unexpectedly.

Partition starts at LBA: 0 Numsec = 0 Disk Size: 500107862016 bytes Sector size: 512 bytes Scanning physical sectors of unpartitioned space on drive 0 (1-62-976753168-976773168)... C:\Windows\System32\msfeedssync.exe (Trojan.FakeMS) -> Quarantined and deleted successfully. A 2013 effort to rehabilitate his image and get back into politics by running for New York City mayor was derailed by a second sexting scandal. C:\Windows\System32\dpnsvr.exe (Trojan.FakeMS) -> Quarantined and deleted successfully.

AV: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {86355677-4064-3EA7-ABB3-1B136EB04637} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} SP: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {3D54B793-665E-3129-9103-206115370C8A} FW: McAfee Firewall *Enabled* {BE0ED752-0A0B-3FFF-80EC-B2269063014C} . ============== Running Processes =============== . this contact form If they do, then click Cleanup once more and repeat the process. I disconnected our webtv about a year ago when we got our new PC. Due to the issues associated with actually allowing network traffic on my PCs I may prefer to d/l some of the recommended tools to a memory stick and then transfer them.

Once the quarnatining starts, it won't run. Done! C:\Windows\System32\mfpmp.exe (Trojan.FakeMS) -> Quarantined and deleted successfully.

It has done this 38 time(s). 02/01/2013 7:14:04 PM, Error: Service Control Manager [7034] - The McAfee McShield service terminated unexpectedly.

If you're stuck, or you're not sure about certain step, always ask before doing anything else. It has done this 34 time(s). 02/01/2013 7:13:42 PM, Error: Service Control Manager [7034] - The McAfee McShield service terminated unexpectedly. It has done this 30 time(s). 02/01/2013 7:13:22 PM, Error: Service Control Manager [7034] - The McAfee McShield service terminated unexpectedly. C:\Windows\System32\efsui.exe (Trojan.FakeMS) -> Quarantined and deleted successfully.

C:\Windows\System32\credwiz.exe (Trojan.FakeMS) -> Quarantined and deleted successfully. The time now is 07:32 AM. Partition starts at LBA: 81920 Numsec = 30720000 Partition file system is NTFS Partition is bootable Partition 2 type is Primary (0x7) Partition is NOT ACTIVE. O/T: This friend of mine kept spamming me the same link over and over for a year that I finally deleted and blocked him.

fuck'n have broken glass for teeth! C:\Windows\System32\com\comrepl.exe (Trojan.FakeMS) -> Quarantined and deleted successfully.