Jump to content

Recommended Posts

Hi,

I am infected with, I think, a trojan. Every time I run utorrent, after 10 minutes, my computer will completely freeze.

I used mbam to scan my computer and remove the virus, but it seems mbam could not see it. Then, after a complete scan, as per the post above, I had a similar error, so I clean mbam. I then reinstalled it and he found a virus, but my computer would still freeze.

I then installed Comodo Antivirus, and he found a list a virus. It cleaned my computer and I was OK for about 12 hours, but suddenly, the virus resurfaced and my computer continue to freeze when I use utorrent.

Below are the logs that I obtained after scanning with mbam and Comodo :

With Comodo :

TrojWare.Win32.TrojanDownloader.VB.vdm@104142806 C:\Windows\Installer\49b8c8.msi

UnclassifiedMalware@105769356 C:\Users\Martin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DA6JRUYV\jg[3].htm

UnclassifiedMalware@105769356 C:\Users\Martin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DA6JRUYV\jg[4].htm

UnclassifiedMalware@105769356 C:\Users\Martin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DA6JRUYV\jg[1].htm

UnclassifiedMalware@105624076 C:\Users\Martin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DA6JRUYV\mepeg[2].htm

UnclassifiedMalware@105624076 C:\Users\Martin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DA6JRUYV\mepeg[3].htm

UnclassifiedMalware@105769356 C:\Users\Martin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\KPEWHOGY\jg[5].htm

UnclassifiedMalware@105769356 C:\Users\Martin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\NC46AOKI\jg[2].htm

UnclassifiedMalware@105624076 C:\Users\Martin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\NC46AOKI\mepeg[2].htm

UnclassifiedMalware@105624076 C:\Users\Martin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\NC46AOKI\mepeg[3].htm

UnclassifiedMalware@105624076 C:\Users\Martin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\NC46AOKI\mepeg[4].htm

UnclassifiedMalware@105769356 C:\Users\Martin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\P1B861IS\jg[1].htm

UnclassifiedMalware@105769356 C:\Users\Martin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\P1B861IS\jg[2].htm

UnclassifiedMalware@105769356 C:\Users\Martin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\P1B861IS\jg[3].htm

UnclassifiedMalware@105624076 C:\Users\Martin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\P1B861IS\mepeg[5].htm

UnclassifiedMalware@104073789 C:\Users\Martin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\P1B861IS\of[1].htm

ApplicUnsaf.Win32.Hide.~AB@5325787 C:\Users\Martin\AppData\Local\Mozilla\Firefox\Profiles\dzr64bmp.default\Cache\1EF26877d01|hidec.exe

Heur.Dual.Extensions@-1 C:\Users\Martin\AppData\Local\Temp\utt9943.tmp.bat

Heur.Dual.Extensions@-1 C:\Users\Martin\AppData\Local\Temp\utt99CF.tmp.bat

Heur.Dual.Extensions@-1 C:\Users\Martin\AppData\Local\Temp\uttBCD8.tmp.bat

Heur.Dual.Extensions@-1 C:\Users\Martin\AppData\Local\Temp\uttBD65.tmp.bat

TrojWare.OSX.Exploit.Smid.b@95071901 C:\Users\Martin\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\41\b023ae9-42a3c6a0|AppletX.class

ApplicUnsaf.Win32.Hide.~AB@5325787 C:\Users\Martin\Downloads\ComboFix.exe|hidec.exe

Heur.Suspicious@22037684 C:\Users\Martin\Downloads\Netscape-Setup.exe|xpicleanup.exe

UnclassifiedMalware@89240523 C:\Program Files (x86)\Keygen\xpymep.exe

TrojWare.Win32.Qhost.SJ@28265172 C:\Program Files (x86)\Keygen\BannerBOMBHackYourNintendoWii.exe

ApplicUnsaf.Win32.Hide.~AB@5325787 C:\32788R22FWJFW\hidec.exe

See attachments for more details also.

Please note that I think the virus is : heur.dual.extensions@-1

Hope you can indicate how to get rid of it,

Thanks

mbam_log_2010_06_05__10_56_57_.txt

Link to post
Share on other sites

Hello ,Welcome to Malwarebytes Forum -

The uTorrents site you are visiting contains infections , so you will not remove them by revisiting the site -

Please follow these instructions as you need an expert to clean your system -

As we don't work on Malware removal or diagnostics in the general forums please follow these directions -

Please print out, read and follow the directions here, skipping any steps you are unable to complete. Then post a NEW topic here.

One of the expert helpers there will give you one-on-one assistance when one becomes available.

After posting your new post make sure under options that you select Track this topic and choose one of the Email options so that you're alerted when someone has replied to your post - Please allow at least 48 hours for a reply as the experts can get busy at times -

Also add a brief note to the experts as to your problems -

Alternatively, as a paying customer, you can contact the help desk at support@malwarebytes.org

Always use the ADD REPLY Tab at the bottom of the page when you reply -

Thank You - :P

EDIT - I hope you clicked to remove this infection -

Files Infected: C:\Windows\System32\mscyphel.dll.vir (Trojan.Vundo) -> No action taken.
Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.