Jump to content

Recommended Posts

Hello there,

I have tried to follow the steps in the 'I'm infected' post above but each time I run the GMER programme by computer shuts down before coming up with a log.

My latest Malware Bytes scan report is posted below. I have attached the DDS report in a .zip file

What should I do next?

Malwarebytes' Anti-Malware 1.50.1.1100

www.malwarebytes.org

Database version: 6674

Windows 6.0.6001 Service Pack 1

Internet Explorer 8.0.6001.19048

25/05/2011 21:39:45

mbam-log-2011-05-25 (21-39-45).txt

Scan type: Full scan (C:\|)

Objects scanned: 329032

Time elapsed: 4 hour(s), 1 minute(s), 30 second(s)

Memory Processes Infected: 0

Memory Modules Infected: 0

Registry Keys Infected: 2

Registry Values Infected: 0

Registry Data Items Infected: 0

Folders Infected: 2

Files Infected: 12

Memory Processes Infected:

(No malicious items detected)

Memory Modules Infected:

(No malicious items detected)

Registry Keys Infected:

HKEY_CURRENT_USER\SOFTWARE\CL2GFOKBC9 (Trojan.FakeAlert) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\ (Hijack.Zones) -> Quarantined and deleted successfully.

Registry Values Infected:

(No malicious items detected)

Registry Data Items Infected:

(No malicious items detected)

Folders Infected:

c:\Users\James\AppData\Roaming\desktop security 2010 (Rogue.DesktopSecurity2010) -> Quarantined and deleted successfully.

c:\Users\James\AppData\Roaming\microsoft\Windows\start menu\Programs\desktop security 2010 (Rogue.DesktopSecurity2010) -> Quarantined and deleted successfully.

Files Infected:

c:\Users\James\AppData\Roaming\microsoft\Windows\start menu\Programs\desktop security 2010.lnk (Rogue.DesktopSecurity2010) -> Quarantined and deleted successfully.

c:\Users\James\AppData\Roaming\microsoft\internet explorer\quick launch\desktop security 2010.lnk (Rogue.DesktopSecurity2010) -> Quarantined and deleted successfully.

c:\Users\James\AppData\Local\Temp\kilslmd.exex (Trojan.FakeAlert) -> Quarantined and deleted successfully.

c:\Users\James\AppData\Local\Temp\ppddfcfux.exxe (Trojan.FakeAlert) -> Quarantined and deleted successfully.

c:\Users\James\AppData\Roaming\desktop security 2010\mfc71.dll (Rogue.DesktopSecurity2010) -> Quarantined and deleted successfully.

c:\Users\James\AppData\Roaming\desktop security 2010\MFC71ENU.DLL (Rogue.DesktopSecurity2010) -> Quarantined and deleted successfully.

c:\Users\James\AppData\Roaming\desktop security 2010\msvcp71.dll (Rogue.DesktopSecurity2010) -> Quarantined and deleted successfully.

c:\Users\James\AppData\Roaming\desktop security 2010\msvcr71.dll (Rogue.DesktopSecurity2010) -> Quarantined and deleted successfully.

c:\Users\James\AppData\Roaming\microsoft\Windows\start menu\Programs\desktop security 2010\activate desktop security 2010.lnk (Rogue.DesktopSecurity2010) -> Quarantined and deleted successfully.

c:\Users\James\AppData\Roaming\microsoft\Windows\start menu\Programs\desktop security 2010\desktop security 2010.lnk (Rogue.DesktopSecurity2010) -> Quarantined and deleted successfully.

c:\Users\James\AppData\Roaming\microsoft\Windows\start menu\Programs\desktop security 2010\help desktop security 2010.lnk (Rogue.DesktopSecurity2010) -> Quarantined and deleted successfully.

c:\Users\James\AppData\Roaming\microsoft\Windows\start menu\Programs\desktop security 2010\how to activate desktop security 2010.lnk (Rogue.DesktopSecurity2010) -> Quarantined and deleted successfully.

Attach.zip

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.