Jump to content

CMur

Members
  • Posts

    1
  • Joined

  • Last visited

Reputation

0 Neutral
  1. So I came across this virus yesterday night looking around streaming video sites. Malwarebytes seems to find the program but it wont remove it for some reason. Also the virus wont allow me to access the internet for some reason. Also everytime i run a scan it finds more and different crap then before. It keeps saying it "deletes" the program but it continues to reappear. This is the Malawarebytes log after the scan. Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Database version: 4052 Windows 5.1.2600 Service Pack 2 Internet Explorer 6.0.2900.2180 5/31/2010 12:04:01 AM mbam-log-2010-05-31 (00-04-01).txt Scan type: Quick scan Objects scanned: 150815 Time elapsed: 12 minute(s), 29 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 3 Registry Values Infected: 4 Registry Data Items Infected: 6 Folders Infected: 1 Files Infected: 2 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CURRENT_USER\SOFTWARE\XML (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Antimalware Doctor (Rogue.AntimalwareDoctor) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\Software\Antimalware Doctor Inc (Rogue.AntimalwareDoctor) -> Quarantined and deleted successfully. Registry Values Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\rthdbpl (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\idstrf (Malware.Trace) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\winid (Malware.Trace) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\nofolderoptions (Hijack.FolderOptions) -> Delete on reboot. Registry Data Items Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFolderOptions (Hijack.FolderOptions) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools (Hijack.Regedit) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\NameServer (Trojan.DNSChanger) -> Data: 93.188.163.50,93.188.161.245 -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{d104548d-5ba7-4178-aac7-714a5343802a}\DhcpNameServer (Trojan.DNSChanger) -> Data: 93.188.163.50,93.188.161.245 -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{d104548d-5ba7-4178-aac7-714a5343802a}\NameServer (Trojan.DNSChanger) -> Data: 93.188.163.50,93.188.161.245 -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{de590958-0235-4f49-a8b7-025c7806d8cd}\NameServer (Trojan.DNSChanger) -> Data: 93.188.163.50,93.188.161.245 -> Quarantined and deleted successfully. Folders Infected: C:\Documents and Settings\Chas\Application Data\SystemProc (Trojan.Agent) -> Quarantined and deleted successfully. Files Infected: C:\Documents and Settings\Chas\Local Settings\Temp\9.tmp (Trojan.Agent) -> Quarantined and deleted successfully. C:\Documents and Settings\Chas\Local Settings\Temp\jisfije9fjoiee.tmp (Trojan.Downloader) -> Quarantined and deleted successfully. Thanks!!!!!!!
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.