Raven_55
-
Posts
2 -
Joined
-
Last visited
Content Type
Events
Profiles
Forums
Posts posted by Raven_55
-
-
hi
i was just recently infected with the fbi moneypak virus. I think i managed get rid of it (it doesn't show up on startup anymore). Is there a way to make shore it's completely gone?
imjpmig.exe
in File Detections
Posted
While i'm not sure what the file does, it has never before been flagged.
My log file is as follows;
Malwarebytes Anti-Malware (PRO) 1.75.0.1300
www.malwarebytes.org
Database version: v2014.03.04.11
Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
User :: USER-345DD9889D [administrator]
Protection: Enabled
5/03/2014 4:36:51 p.m.
MBAM-log-2014-03-05 (16-46-44).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 216278
Time elapsed: 9 minute(s), 11 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 2
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|IMJPMIG8.1 (Trojan.Agent.GN) -> Data: "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32 -> No action taken. [e962ad52c8b2a4922d984360010001ff]
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|SystweakASP (PUP.Optional.RegCleanPro) -> Data: "C:\Program Files\RegClean Pro\SystweakASP.exe" /verysilent -> No action taken. [2d1e8e714d2da78f1bead4b8bc4634cc]
Registry Data Items Detected: 1
HKLM\SOFTWARE\Microsoft\Security Center|AntiVirusDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> No action taken. [1e2ddb245f1b89ad57e7af7b4aba936d]
Folders Detected: 0
(No malicious items detected)
Files Detected: 3
C:\WINDOWS\ime\imjp8_1\imjpmig.exe (Trojan.Agent.GN) -> No action taken. [e962ad52c8b2a4922d984360010001ff]
C:\Documents and Settings\User\Desktop\imjpmig.exe (Trojan.Agent.GN) -> No action taken. [79d2c738cdad60d63d886142de2322de]
C:\Documents and Settings\User\Desktop\imjpmig.rar (Trojan.Agent.GN) -> No action taken. [9ab104fbe595350192332380a35e0ff1]
(end)
the file highlighted is the file i'm talking about, the other two are just copies i made to prepare to upload it to this.
imjpmig.rar