Jump to content

Help reading log. Do I have a virus?


Recommended Posts

Hello. I'm new to this program and site, please forgive any posting error on my part. This morning a fake UPS shipping email attachment was opened on my computer (Dell Inspiron, Windows Vista) The attachment was opened, and closed immediately. My Norton Av did not detect any problems after a full scan, but I was still not sure and was advised of Malwarebytes. I downloaded the program and I'm on day one of the trial. After running a full scan, the only thing detected was an adware from an old casino site. It was removed. Upon checking the protection log, I see a DETECTION, Quarantine of Trojan.ExeShell.Gen. then the very next entry says "Quarantine failed: SDKQuarantine failed with error code 2. Following that, there are six consecutive entries that read "DETECTION C:\ Users\" then the rest of the address, ending with " \Local 7za.exe Trojan.ExeShell.Gen" Then, below that "DENY" I can post the log if I need to (not sure how). Does this mean I have a virus? The full system scan shows nothing. Please let me know what this means. Repeated scans by Malwarebytes and Norton show nothing wrong. Please help.

Regards,

John

Link to post
Share on other sites

Hello homan49 and welcome to MalwareBytes forums,

Step 1

1. Go >> Here << and download ERUNT

(ERUNT (Emergency Recovery Utility NT) is a free program that allows you to keep a complete backup of your registry and restore it when needed.)

2. Install ERUNT by following the prompts

(use the default install settings but say no to the portion that asks you to add ERUNT to the start-up folder, if you like you can enable this option later)

3. Start ERUNT by doing a Right-Click on it & select Run As Admisnistrator

4. Choose a location for the backup

(the default location is C:\WINDOWS\ERDNT which is acceptable).

5. Make sure that at least the first two check boxes are ticked

6. Press OK

7. Press YES to create the folder.

Step 2

Show all files:

  • Click the Start button, and then click Computer.
  • On the Organize menu, click Folder and Search Options.
  • Click the View tab.
  • Locate and uncheck Hide file extensions for known file types.
  • Locate and uncheck Hide protected operating system files (Recommended).
  • Locate and click Show hidden files and folders.
  • Click Apply > OK.

Step 3

Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools

For directions on how, see How To Temporarily Disable Your Anti-virus, Firewall And Anti-malware Programs

Do NOT turn off the firewall

  1. Close any/all open internet browsers. Save any open documents you have open & close programs you started.
  2. Click on START>All Programs>Malwarebytes' Anti-Malware>Tools>Malwarebytes Anti-Malware Chameleon
    On Windows 7/Vista, press Windows-key, then start typing in text box
    Malwarebytes

    then select/click Malwarebytes Anti-Malware Chameleon

  3. Once the Help file opens, click on a Chameleon button (starting with #1)
  4. If running on Vista, Windows 7, press the Yes button when prompted at the UAC prompt to allow to run.
  5. You should see a black Command-prompt-window that remains open and says MBAM-chameleon ver. 1.6 at the top
  6. Press any key to continue as it says in the window {space-bar will do}
  7. If the Chameleon button you tried does not work, try the next Chameleon button shown. (There are 12 in all).
  8. Have infinite patience during this process
  9. Malwarebytes Chameleon will proceed to update Malwarebytes Anti-Malware, so ensure that you are connected to the internet if possible
  10. Once the update completes and it says your database is updated, click on OK button so that process can continue :excl:
  11. Malwarebytes Chameleon will then terminate any threats running in memory, which may take a while, so please be patient.
  12. After that, Malwarebytes Anti-Malware will open automatically and perform a Quick scan
  13. A quick scan will take a few minutes, possibly 5 or so minutes. Have infinite patience.
  14. Once the scan is complete, click on Show Results and remove any threats that are found by clicking Remove Selected
  15. If prompted to restart your computer to complete the removal process, click Yes :excl:
  16. If no threats are found, press OK button & press EXIT to end MBAM. Press the space-bar (or another key) to exit the command-prompt-window.
  17. After your computer restarts, open Malwarebytes Anti-Malware and perform one last Quick scan to verify that there are no remaining threats

Reply with copy of the MBAM scan log for review.

Link to post
Share on other sites

Due to the lack of feedback this topic is closed to prevent others from posting here. If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread.

Other members who need assistance please start your own topic in a new thread. Thanks!

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.