brainfreeze Posted July 8, 2009 ID:96678 Share Posted July 8, 2009 Hey there,I have been a MBAM user for some time now and I do as the forums tell me to do to remove the infected files, but there are still 2 items its can not remove even after restsrt.here is the log resault, but when i restart and run MBAM again there still there. Please help!Malwarebytes' Anti-Malware 1.38Database version: 2390Windows 6.0.6001 Service Pack 17/8/2009 8:13:17 AMmbam-log-2009-07-08 (08-13-17).txtScan type: Quick ScanObjects scanned: 5390Time elapsed: 13 second(s)Memory Processes Infected: 0Memory Modules Infected: 1Registry Keys Infected: 0Registry Values Infected: 0Registry Data Items Infected: 0Folders Infected: 0Files Infected: 1Memory Processes Infected:(No malicious items detected)Memory Modules Infected:\\?\globalroot\systemroot\System32\SKYNETeyieapyv.dll (Trojan.TDSS) -> Delete on reboot.Registry Keys Infected:(No malicious items detected)Registry Values Infected:(No malicious items detected)Registry Data Items Infected:(No malicious items detected)Folders Infected:(No malicious items detected)Files Infected:\\?\globalroot\systemroot\System32\SKYNETeyieapyv.dll (Trojan.TDSS) -> Quarantined and deleted successfully. Link to post Share on other sites More sharing options...
Fatdcuk Posted July 8, 2009 ID:96682 Share Posted July 8, 2009 Hi and welcome to the MBAM forums Please use the following walkthrough as a guide.http://www.malwarebytes.org/forums/index.php?showtopic=12709You have SKYNET variant onboard.Please post back the results of MBAM quick scan log after running that fix.Thanks in advance Link to post Share on other sites More sharing options...
brainfreeze Posted July 9, 2009 Author ID:96847 Share Posted July 9, 2009 Wow, that was awsome. There was 5 more infected that was found after I followed that walkthrough.thanks again!Malwarebytes' Anti-Malware 1.38Database version: 2397Windows 6.0.6001 Service Pack 17/8/2009 6:11:24 PMmbam-log-2009-07-08 (18-11-24).txtScan type: Quick ScanObjects scanned: 80731Time elapsed: 3 minute(s), 24 second(s)Memory Processes Infected: 0Memory Modules Infected: 0Registry Keys Infected: 0Registry Values Infected: 0Registry Data Items Infected: 0Folders Infected: 0Files Infected: 0Memory Processes Infected:(No malicious items detected)Memory Modules Infected:(No malicious items detected)Registry Keys Infected:(No malicious items detected)Registry Values Infected:(No malicious items detected)Registry Data Items Infected:(No malicious items detected)Folders Infected:(No malicious items detected)Files Infected:(No malicious items detected) Link to post Share on other sites More sharing options...
Fatdcuk Posted July 9, 2009 ID:96950 Share Posted July 9, 2009 Works like a charm if the instructions are followed correctly Right i will need to see a few more logs from you before i'm happy to sound the all clear.STEP 01Please visit this webpage for instructions for downloading ComboFix to your DESKTOP : how-to-use-combofixPlease ensure you read this guide carefully and install the Recovery Console first.NOTE!!: You must save and run ComboFix.exe on your DESKTOP and not from any other folder.Also, DO NOT click the mouse or launch any other applications while this is running or it may stall the programAdditional links to download the tool:ComboFix.exeComboFix.exeComboFix.exehttp://www.forospyware.com/sUBs/ComboFix.exe' rel="external nofollow">Note: The Windows Recovery Console will allow you to boot up into a special recovery (repair) mode. This allows us to more easily help you should your computer have a problem after an attempted removal of malware. It is a simple procedure that will only take a few moments of your time.Once installed, you should see a blue screen prompt that says:The Recovery Console was successfully installed.Please continue as follows:Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.Click Yes to allow ComboFix to continue scanning for malware.When the tool is finished, it will produce a report for you.Please post the C:\ComboFix.txt along with a new HijackThis log so we may continue cleaning the system. Link to post Share on other sites More sharing options...
Root Admin AdvancedSetup Posted July 14, 2009 Root Admin ID:98254 Share Posted July 14, 2009 Due to the lack of feedback this Topic is closed to prevent others from posting here. If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread.Other members who need assistance please start your own topic in a new thread. Thanks!The fixes and advice in this thread are for this machine only. Do not apply the instructions from this thread to your own machine. Please start a new thread describing your issue and someone will be along to assist you. Link to post Share on other sites More sharing options...
Recommended Posts