1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Inactive What virus is on my computer !?!

Discussion in 'Malware and Virus Removal Archive' started by bgirl323, 2011/01/11.

Thread Status:
Not open for further replies.
  1. 2011/01/11
    bgirl323

    bgirl323 Inactive Thread Starter

    Joined:
    2011/01/11
    Messages:
    1
    Likes Received:
    0
    [Inactive] What virus is on my computer !?!

    I keep hearing audio ads without the internet browser even open! And for some reason only IE will start up -- Google Chrome (my default browser) won't even load a page!

    Before reading about your process of steps, I had tried to do a scan with my normal McAfee -- it said it was scanning but looked like it wasn't making progress.. which leads me to believe it wasn't really McAfee! can the virus also take over my anti-virus software so that it becomes fake or ineffective?

    I have started your process below: Please help!!



    Malwarebytes' Anti-Malware 1.50.1.1100
    www.malwarebytes.org

    Database version: 5502

    Windows 5.1.2600 Service Pack 3
    Internet Explorer 8.0.6001.18702

    1/11/2011 10:02:20 AM
    mbam-log-2011-01-11 (10-02-20).txt

    Scan type: Full scan (C:\|E:\|)
    Objects scanned: 337952
    Time elapsed: 2 hour(s), 17 minute(s), 8 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 5
    Registry Values Infected: 0
    Registry Data Items Infected: 2
    Folders Infected: 0
    Files Infected: 4

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    HKEY_CURRENT_USER\SOFTWARE\JP595IR86O (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\NtWqIVLZEWZU (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\XML (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\ (Hijack.Zones) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MSSMGR (Trojan.Downloader) -> Quarantined and deleted successfully.

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    c:\program files\X1\Stellent\filts832p1.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
    c:\WINDOWS\Tnizua.exe (Trojan.FraudPack.Gen) -> Delete on reboot.
    c:\WINDOWS\Tasks\{62c40aa6-4406-467a-a5a5-dfdf1b559b7a}.job (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    c:\WINDOWS\Tasks\{bbaeaeaf-1275-40e2-bd6c-bc8f88bd114a}.job (Trojan.Downloader) -> Quarantined and deleted successfully.


    Malwarebytes' Anti-Malware 1.50.1.1100
    www.malwarebytes.org

    Database version: 5502

    Windows 5.1.2600 Service Pack 3
    Internet Explorer 8.0.6001.18702

    1/11/2011 10:24:41 AM
    mbam-log-2011-01-11 (10-24-41).txt

    Scan type: Quick scan
    Objects scanned: 160264
    Time elapsed: 5 minute(s), 14 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 1
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 1

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MSSMGR (Trojan.Downloader) -> Quarantined and deleted successfully.

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    c:\WINDOWS\Temp\2F.tmp (Roootkit.TDSS) -> Delete on reboot.





    (I would post the GMER but says I already have too many characters, and I see no way to attach a doc in a post)
     
  2. 2011/01/11
    PeteC

    PeteC SuperGeek Staff

    Joined:
    2002/05/10
    Messages:
    28,896
    Likes Received:
    389
    Welcome to WindowsBBS :)

    Please post the logs in as many posts as it takes.
     

  3. to hide this advert.

Thread Status:
Not open for further replies.

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.