1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Inactive Help with trojan virus

Discussion in 'Malware and Virus Removal Archive' started by born2golf, 2010/04/25.

  1. 2010/04/25
    born2golf

    born2golf Inactive Thread Starter

    Joined:
    2009/02/18
    Messages:
    144
    Likes Received:
    0
    [Inactive] Help with trojan virus

    I woke up this morning to download nVidia driver for GeForce 8500 and all went well. Then I went to Seven Forum to review several cusomazation threads and up pops WARNING for Security Tools(?) telling me about 40+ trojan infection in C aMalwarebytes' Anti-Malware 1.45
    www.malwarebytes.org

    Database version: 4034

    Windows 6.1.7600
    Internet Explorer 8.0.7600.16385

    4/25/2010 7:24:17 AM
    mbam-log-2010-04-25 (07-24-17).txt

    Scan type: Quick scan
    Objects scanned: 104510
    Time elapsed: 3 minute(s), 8 second(s)

    Memory Processes Infected: 1
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 1
    Registry Data Items Infected: 0
    Folders Infected: 1
    Files Infected: 3

    Memory Processes Infected:
    C:\ProgramData\96447131\96447131.exe (Rogue.SecurityTool) -> No action taken.

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    (No malicious items detected)

    Registry Values Infected:
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\96447131 (Trojan.FakeAlert.H) -> No action taken.

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    C:\ProgramData\96447131 (Rogue.Multiple) -> No action taken.

    Files Infected:
    C:\ProgramData\96447131\96447131.exe (Trojan.FakeAlert.H) -> No action taken.
    C:\Users\Dennis\downloads\inst virus trojans.exe (Rogue.SecurityTool) -> No action taken.
    C:\Users\Dennis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Security Tool.LNK (Rogue.SecurityTool) -> No action taken.
    nd D drive.






    1. Updated MBAM and ran scan and found 4 (see attached) I removed them and rebooted.
    2. Updated MSE and ran scan and found 0 files infected
    3. Updated SuperAntiSpywared and ran scan and found 0 files infected
    How did this happen and was it a pop up promo by Security Tools as they wanted $49.00 for their program?
     
  2. 2010/04/25
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    If we knew EXACTLY, how people's computers got infected, there would be no malwares out there. There may be number of way, how YOUR computer got infected.

    If you still need help, please post required DDS logs.
     

  3. to hide this advert.

  4. 2010/04/25
    born2golf

    born2golf Inactive Thread Starter

    Joined:
    2009/02/18
    Messages:
    144
    Likes Received:
    0
    Did a full scan with MBAM from safe mode and everything is clean and free of malicious bugs.
    Thanks for the info and I will close this thread down.
     
  5. 2010/04/25
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    If you need any further help, please, let me know :)
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.