Jump to content

AV Security Suite


Recommended Posts

Yesterday my PC was infected with AV security suite. I followed the directions in this thread ( http://forums.malwarebytes.org/index.php?showtopic=56600 ) by running rkill.exe and performing a MB quickscan. After the quickscan I updated malwarebytes and ran a full scan and removed found infections both times. The AV popups are gone but the PC will not connect to the internet, when I try to open firefox it displays "The proxy server is refusing connections".

Please help. I will post both MB logs below.

From the quickscan:

Malwarebytes' Anti-Malware 1.46

www.malwarebytes.org

Database version: 4052

Windows 5.1.2600 Service Pack 3

Internet Explorer 7.0.5730.11

7/6/2010 9:54:36 PM

mbam-log-2010-07-06 (21-54-36).txt

Scan type: Quick scan

Objects scanned: 143364

Time elapsed: 8 minute(s), 17 second(s)

Memory Processes Infected: 0

Memory Modules Infected: 0

Registry Keys Infected: 4

Registry Values Infected: 2

Registry Data Items Infected: 0

Folders Infected: 0

Files Infected: 2

Memory Processes Infected:

(No malicious items detected)

Memory Modules Infected:

(No malicious items detected)

Registry Keys Infected:

HKEY_LOCAL_MACHINE\SOFTWARE\avsuite (Rogue.AntivirusSuite) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\Software\avsuite (Rogue.AntivirusSuite) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\avsoft (Trojan.Fraudpack) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\Software\avsoft (Trojan.Fraudpack) -> Quarantined and deleted successfully.

Registry Values Infected:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ejhclrmw (Rogue.AntivirusSuite.Gen) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ejhclrmw (Rogue.AntivirusSuite.Gen) -> Quarantined and deleted successfully.

Registry Data Items Infected:

(No malicious items detected)

Folders Infected:

(No malicious items detected)

Files Infected:

C:\Documents and Settings\Owner.YOUR-34EFF17BD0\Local Settings\Application Data\nscgdrpmr\ncnmbnttssd.exe (Rogue.AntivirusSuite.Gen) -> Quarantined and deleted successfully.

C:\Documents and Settings\Owner.YOUR-34EFF17BD0\Local Settings\Temp\e.exe (Trojan.Dropper) -> Quarantined and deleted successfully.

From the full scan

Malwarebytes' Anti-Malware 1.46

www.malwarebytes.org

Database version: 4286

Windows 5.1.2600 Service Pack 3

Internet Explorer 7.0.5730.11

7/7/2010 10:16:50 AM

mbam-log-2010-07-07 (10-16-50).txt

Scan type: Full scan (C:\|D:\|E:\|F:\|G:\|H:\|I:\|J:\|K:\|)

Objects scanned: 270104

Time elapsed: 1 hour(s), 1 minute(s), 14 second(s)

Memory Processes Infected: 0

Memory Modules Infected: 0

Registry Keys Infected: 0

Registry Values Infected: 0

Registry Data Items Infected: 0

Folders Infected: 0

Files Infected: 1

Memory Processes Infected:

(No malicious items detected)

Memory Modules Infected:

(No malicious items detected)

Registry Keys Infected:

(No malicious items detected)

Registry Values Infected:

(No malicious items detected)

Registry Data Items Infected:

(No malicious items detected)

Folders Infected:

(No malicious items detected)

Files Infected:

C:\Documents and Settings\Owner.YOUR-34EFF17BD0\Local Settings\Temporary Internet Files\Content.IE5\PJNT8VYP\bc93ad[1].exe (Trojan.Downloader) -> Quarantined and deleted successfully.

Link to post
Share on other sites

I found these directions from MrCharlie in this thread ( http://forums.malwarebytes.org/index.php?s...hl=proxy+server ) and they seem to have worked.

Try this: Go to your Start button > Settings > Control Panel > Internet Options > open it up

* Now click on the Connections

* Now click on the Lan Settings

* Under the Proxy Server section, please uncheck the checkbox labeled Use a proxy server for your LAN. Then press the OK button to close this screen.

Check to see if any of the other boxes are checked, Automatically detect settings and Use auto configuration,

if so try it with them unchecked

Then press the OK button to close the Internet Options screen. (There's no apply)

* Now that you have disabled the proxy server you will be able to browse the web again with Internet Explorer

Let me know, MrC

I will most definitely be purchasing the full version of MB now. This is the third or fourth time your software and forums have saved me.

Thank you,

Digitalcaveman

Link to post
Share on other sites

  • 3 weeks later...
  • Staff

Due to the lack of feedback this topic is closed to prevent others from posting here. If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread.

Other members who need assistance please start your own topic in a new thread. Thanks!

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.