WiredWX Hobby Weather ToolsLog in

 


antivirus system pro and a few other problems

2 posters

descriptionantivirus system pro and a few other problems - Page 2 EmptyRe: antivirus system pro and a few other problems

more_horiz
Ok I'm going to have to backtrack a little bit. I was having trouble installing Dr.Web CureIt so I restarted my computer and now I'm able to run malwarebyte. I ran through the steps from your previous post and these are the results on the mbam log.

Malwarebytes' Anti-Malware 1.37
Database version: 2262
Windows 5.1.2600 Service Pack 2

6/11/2009 2:10:39 PM
mbam-log-2009-06-11 (14-10-39).txt

Scan type: Quick Scan
Objects scanned: 125922
Time elapsed: 6 minute(s), 9 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 21
Registry Values Infected: 1
Registry Data Items Infected: 1
Folders Infected: 5
Files Infected: 81

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\testcpv6.bho (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\testcpv6.bho.1 (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{2e4a04a1-a24d-45ae-aca4-949778400813} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\{ff46f4ab-a85f-487e-b399-3f191ac0fe23} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{5b1d95a2-f547-4e5e-8902-622b08354622} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{5cc2f638-99ff-45d2-97c7-e30e83cf04d2} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\xpreapp (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\testCPV6.DLL (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SpeedRunner (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\tdssdata (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\tdss (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\xpre (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\instkey (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\dslcnnct (Trojan.Vundo) -> Quarantined and deleted successfully.

descriptionantivirus system pro and a few other problems - Page 2 EmptyRe: antivirus system pro and a few other problems

more_horiz
Wow, long log or what, 81 files? wow.

See if that made any difference now, try running Combofix again.

descriptionantivirus system pro and a few other problems - Page 2 EmptyRe: antivirus system pro and a few other problems

more_horiz
Well I restarted and am now running in regular mode.

The first thing I noticed is that the computer started up much quicker.

antivirus system pro is no longer showing its face anywhere.

I've typed a few searches using my google toolbar and I'm no longer being redirected to other sites.

I successfully got Dr.Web to download but I still get the same error message on the combofix links.

descriptionantivirus system pro and a few other problems - Page 2 EmptyRe: antivirus system pro and a few other problems

more_horiz
Okay, use Dr.Web instead and see if that will run.

descriptionantivirus system pro and a few other problems - Page 2 EmptyRe: antivirus system pro and a few other problems

more_horiz
Did the scan and it said no viruses found.
Am I in the clear yet or is there still some more things I should run?

descriptionantivirus system pro and a few other problems - Page 2 EmptyRe: antivirus system pro and a few other problems

more_horiz
Update the MBAM and run a new scan, we'll see what that says.

descriptionantivirus system pro and a few other problems - Page 2 EmptyRe: antivirus system pro and a few other problems

more_horiz
Malwarebytes' Anti-Malware 1.37
Database version: 2263
Windows 5.1.2600 Service Pack 2

6/11/2009 4:15:01 PM
mbam-log-2009-06-11 (16-15-01).txt

Scan type: Quick Scan
Objects scanned: 126688
Time elapsed: 26 minute(s), 4 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINDOWS\system32\drivers\str.sys (Rootkit.Agent) -> Delete on reboot.

descriptionantivirus system pro and a few other problems - Page 2 EmptyRe: antivirus system pro and a few other problems

more_horiz
I still think we should run Combofix.
Do you have another machine and a USB stick you can download to? and transport Combo-Fix to the infected machine.

descriptionantivirus system pro and a few other problems - Page 2 EmptyRe: antivirus system pro and a few other problems

more_horiz
Yes I can get access to one later today. I'll post the results after I run everything. Thanks for the help so far.

descriptionantivirus system pro and a few other problems - Page 2 EmptyRe: antivirus system pro and a few other problems

more_horiz
Okay, standing by.

descriptionantivirus system pro and a few other problems - Page 2 EmptyRe: antivirus system pro and a few other problems

more_horiz
privacy_tip Permissions in this forum:
You cannot reply to topics in this forum