04-16-2012 07:45 PM
Process
PRC - [2012/04/16 13:55:57 | 000,132,608 | -H-- | M] () -- C:\Documents and Settings\admin\Datos de programa\WMPRWISE.EXE
04-16-2012 07:47 PM
Mmmm, i paste that at OTL and click FIX red button?
04-16-2012 07:53 PM
In OTL you would have to copy all between the lines below as the script
:OTL
PRC - [2012/04/16 13:55:57 | 000,132,608 | -H-- | M] () -- C:\Documents and Settings\admin\Datos de programa\WMPRWISE.EXE
[2012/04/16 13:55:57 | 000,132,608 | -H-- | M] () -- C:\Documents and Settings\admin\Datos de programa\WMPRWISE.EXE
[2012/04/16 02:59:20 | 000,141,312 | ---- | M] () -- C:\Documents and Settings\admin\Configuración local\Datos de programa\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
:Services
:Files
:Reg
:Commands
Or you can just end the process in task manager and just delete the file to the recycle bin.
Quads
04-16-2012 07:59 PM
I will do the OTL stuff, paste that and the question is, then i clic the FIX red button??
thanks.
04-16-2012 08:56 PM
I did that, here's the log.
What's next?
04-17-2012 03:17 AM
You are still not getting any redirects or problems like when you were infected??
Did a Full Scan with Malwarebytes find anything, with updated definitions??
Quads
04-18-2012 06:15 AM
Since i did that process with the OTL the computer is working fine. But malaware discovered some threats and suposusely eliminated them. Here's the last log.
04-18-2012 03:19 PM
I did another full scan with malawarebytes and it didn't find any threats, so it appears to be that it made the action that i show you on the post above.
04-18-2012 04:08 PM
Over the next few days just run scans with Symantec and Malwarebytes ( Malwarebytes Free has to have definitions updated manually)
See if anything new gets detected.
You might want to not use that Flash drive again, if it has malware that auto loads on it.
Quads
04-18-2012 09:35 PM
What's the name of that flash drive in order to unistall it? Or it was deleted?
Oh, by the way, system restore is still OFF.
