Jump to content

Recommended Posts

MBAM detects Trojan.TDSS, but after rebooting it is not removed. The file in question is

\windows\system32\geyekrbwukcaqw.dll

I have tried running in safe mode to remove the file. The file is there but not findable by explorer.exe or the command prompt's dir. If I try to delete it by name, though, it says the file is locked by another process.

Here is MBAM's log:

Malwarebytes' Anti-Malware 1.39

Database version: 2429

Windows 5.1.2600 Service Pack 3

7/14/2009 12:44:10 PM

mbam-log-2009-07-14 (12-44-10).txt

Scan type: Quick Scan

Objects scanned: 94433

Time elapsed: 6 minute(s), 1 second(s)

Memory Processes Infected: 0

Memory Modules Infected: 1

Registry Keys Infected: 0

Registry Values Infected: 0

Registry Data Items Infected: 0

Folders Infected: 0

Files Infected: 1

Memory Processes Infected:

(No malicious items detected)

Memory Modules Infected:

\\?\globalroot\systemroot\SYSTEM32\geyekrbwukcaqw.dll (Trojan.TDSS) -> Delete on reboot.

Registry Keys Infected:

(No malicious items detected)

Registry Values Infected:

(No malicious items detected)

Registry Data Items Infected:

(No malicious items detected)

Folders Infected:

(No malicious items detected)

Files Infected:

\\?\globalroot\systemroot\SYSTEM32\geyekrbwukcaqw.dll (Trojan.TDSS) -> Quarantined and deleted successfully.

Link to post
Share on other sites

Greetings.

To get you fixed up please follow the instructions here:

I'm infected - What do I do now?

And post your logs in a new topic here:

Malware Removal - HijackThis Logs

Please be sure not to install any software or use any removal or scanning tools exept those that you are

instructed to by the expert who will be assisting you as doing so can make their job much more difficult.

note: if for some reason you are unable to run some or any of the tools in the first link, then skip that step and move on to the next one.

If you can't even run HijackThis, then just post here: Malware Removal - HijackThis Logs describing your issues and an expert will reply with further instructions.

I hope I was helpful. Good luck and safe surfing. :(

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.