Help!

Discussion in 'Malware Help (A Specialist Will Reply)' started by Cruecial, Apr 17, 2013.

  1. Cruecial

    Cruecial Private E-2

    When I booted up my computer today, it asked me to allow the computer to do three updates, when I did this, it started up normally. However, I ran a scan that found something wrong with a system entry. I'm sorry I didn't save it, but it had something to do with software/wow6432node/ArcSoft Connection Service. Anyway, I downloaded the RogueKiller, and this is what it found. I know two entries have to do with my Kodak Shareware. Now, is the rest of this bad? Do I have more to worry about? I'm a newbie when it comes to malware, so this is what RogueKiller found. If I violated any rules, I apologize in advance. I am, after all, a newbie. Be kind! ;) Do I need to delete this stuff? Thanks!

    RogueKiller V8.5.4 [Mar 18 2013] by Tigzy
    mail : tigzyRK<at>gmail<dot>com
    Feedback : http://www.geekstogo.com/forum/files/file/413-roguekiller/
    Website : http://tigzy.geekstogo.com/roguekiller.php
    Blog : http://tigzyrk.blogspot.com/

    Operating System : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
    Started in : Normal mode
    User : aaron [Admin rights]
    Mode : Scan -- Date : 04/17/2013 14:24:13
    | ARK || FAK || MBR |

    ¤¤¤ Bad processes : 0 ¤¤¤

    ¤¤¤ Registry Entries : 7 ¤¤¤
    [TASK][SUSP PATH] EasyShare Registration Task.job : C:\Windows\System32\rundll32.exe C:\ProgramData\Kodak\EasyShareSetup\$Registration\Registration_8.2.30.1.sxt _RegistrationOffer@16 [7] -> FOUND
    [TASK][SUSP PATH] EasyShare Registration Task : C:\Windows\System32\rundll32.exe C:\ProgramData\Kodak\EasyShareSetup\$Registration\Registration_8.2.30.1.sxt _RegistrationOffer@16 [7] -> FOUND
    [HJ DESK] HKCU\[...]\ClassicStartMenu : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND
    [HJ DESK] HKCU\[...]\ClassicStartMenu : {645FF040-5081-101B-9F08-00AA002F954E} (1) -> FOUND
    [HJ DESK] HKCU\[...]\NewStartPanel : {645FF040-5081-101B-9F08-00AA002F954E} (1) -> FOUND
    [HJ DESK] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> FOUND
    [HJ DESK] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND

    ¤¤¤ Particular Files / Folders: ¤¤¤

    ¤¤¤ Driver : [NOT LOADED] ¤¤¤

    ¤¤¤ HOSTS File: ¤¤¤
    --> C:\Windows\system32\drivers\etc\hosts



    ¤¤¤ MBR Check: ¤¤¤

    +++++ PhysicalDrive0: WDC WD6400AAKS-75A7B2 ATA Device +++++
    --- User ---
    [MBR] 3dc404aaced5b53fd166d85958610d33
    [BSP] 0a645e63219305ed118bef021952b6fc : Windows Vista MBR Code
    Partition table:
    0 - [XXXXXX] DELL-UTIL (0xde) [VISIBLE] Offset (sectors): 63 | Size: 39 Mo
    1 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 81920 | Size: 15000 Mo
    2 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 30801920 | Size: 595439 Mo
    User = LL1 ... OK!
    User = LL2 ... OK!

    Finished : << RKreport[1]_S_04172013_02d1424.txt >>
    RKreport[1]_S_04172013_02d1424.txt
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your log is fine.
     
  3. Cruecial

    Cruecial Private E-2

    Thank you so much. Does anyone think I was a dopey victim of some kind of malware? I am very gullible, and I know I shouldn't have let something fool me. And thanks so much for your quick reply. Makes me feel so much better.
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds