Hello,
I use Malware Bytes to get rid of antimalware doctor in both regular and safe mode. Below are the last couple of logs from Malware Bytes. I had a vicious virus on this computer before (not this computer I am currently on, but the infected one which is also xp) and had to use the recovery discs. Its about a year later and I had periodical viruses that were easily taken care of by Malware Bytes, but I need help for this particular virus.
Thanks for your time.
Files Infected:
C:\My Backup -- 25-06-09 1924\Documents and Settings\LocalService\Application Data\1458931097.exe (Trojan.MailFinder) -> Quarantined and deleted successfully.
C:\My Backup -- 25-06-09 1924\Documents and Settings\ryan.wade\Ryan.Wade.exe (Trojan.Rabbit) -> Quarantined and deleted successfully.
C:\My Backup -- 25-06-09 1924\Documents and Settings\ryan.wade\Local Settings\Temp\148.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\My Backup -- 25-06-09 1924\Documents and Settings\ryan.wade\Local Settings\Temp\BNA.tmp (Rogue.Installer) -> Quarantined and deleted successfully.
C:\My Backup -- 25-06-09 1924\Documents and Settings\ryan.wade\Local Settings\Temp\install[1].exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\My Backup -- 25-06-09 1924\Documents and Settings\ryan.wade\Local Settings\Temp\~TM1D.tmp (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\My Backup -- 25-06-09 1924\Documents and Settings\ryan.wade\Local Settings\Temp\~TM2F.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\My Backup -- 25-06-09 1924\Documents and Settings\ryan.wade\Local Settings\Temp\~TMFB3.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\My Backup -- 25-06-09 1924\Documents and Settings\ryan.wade\Start Menu\Programs\Startup\asgupd32.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\My Backup -- 25-06-09 1924\Documents and Settings\ryan.wade\Start Menu\Programs\Startup\fmnupd32.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\My Backup -- 25-06-09 1924\WINDOWS\system32\avast!AVSControlService.exe (Trojan.MailFinder) -> Quarantined and deleted successfully.
C:\My Backup -- 25-06-09 1924\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\2S6ZZKBS\167[1].exe (Rogue.SystemSecurity) -> Quarantined and deleted successfully.
C:\My Backup -- 25-06-09 1924\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\BS0OE4AJ\test2[1].exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\My Backup -- 25-06-09 1924\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\G5D1PHAR\install[1].exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\My Backup -- 25-06-09 1924\WINDOWS\Temp\BN143F.tmp (Trojan.Rabbit) -> Quarantined and deleted successfully.
C:\My Backup -- 25-06-09 1924\WINDOWS\Temp\BN1440.tmp (Rogue.Installer) -> Quarantined and deleted successfully.
C:\My Backup -- 25-06-09 1924\WINDOWS\Temp\BN1441.tmp (Trojan.Rabbit) -> Quarantined and deleted successfully.
C:\My Backup -- 25-06-09 1924\WINDOWS\Temp\BN1442.tmp (Rogue.Installer) -> Quarantined and deleted successfully.
C:\My Backup -- 25-06-09 1924\WINDOWS\Temp\BN1443.tmp (Trojan.Rabbit) -> Quarantined and deleted successfully.
C:\My Backup -- 25-06-09 1924\WINDOWS\Temp\BN1444.tmp (Rogue.Installer) -> Quarantined and deleted successfully.
C:\My Backup -- 25-06-09 1924\WINDOWS\Temp\BN434.tmp (Rogue.Installer) -> Quarantined and deleted successfully.
C:\My Backup -- 25-06-09 1924\WINDOWS\Temp\rdl29.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\My Backup -- 25-06-09 1924\WINDOWS\Temp\rdl71.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\My Backup -- 25-06-09 1924\WINDOWS\Temp\~TM54EA3A.TMP (Trojan.Agent) -> Quarantined and deleted successfully.
C:\My Backup -- 25-06-09 1924\WINDOWS\Temp\~TME.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\My Backup -- 25-06-09 1924\WINDOWS\Temp\Temporary Internet Files\Content.IE5\57S41HQ2\ccsuper2[1].htm (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\My Backup -- 25-06-09 1924\WINDOWS\Temp\Temporary Internet Files\Content.IE5\6DUB3U6O\ccsuper3[1].htm (Worm.Koobface) -> Quarantined and deleted successfully.
C:\My Backup -- 25-06-09 1924\WINDOWS\Temp\Temporary Internet Files\Content.IE5\6DUB3U6O\ibcpduuv[1].htm (Worm.Koobface) -> Quarantined and deleted successfully.
C:\My Backup -- 25-06-09 1924\WINDOWS\Temp\Temporary Internet Files\Content.IE5\IDJUGRR1\ccsuper1[1].htm (Trojan.Agent) -> Quarantined and deleted successfully.
C:\My Backup -- 25-06-09 1924\WINDOWS\Temp\Temporary Internet Files\Content.IE5\VOC97G7Q\rbbsg[1].txt (Trojan.Dropper) -> Quarantined and deleted successfully.
Files Infected:
C:\System Volume Information\_restore{8BC79291-E322-403F-8E40-1FBD3FCA0EBD}\RP3\A0005114.exe (Trojan.MailFinder) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{8BC79291-E322-403F-8E40-1FBD3FCA0EBD}\RP3\A0005115.exe (Trojan.Rabbit) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{8BC79291-E322-403F-8E40-1FBD3FCA0EBD}\RP3\A0005116.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{8BC79291-E322-403F-8E40-1FBD3FCA0EBD}\RP3\A0005117.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{8BC79291-E322-403F-8E40-1FBD3FCA0EBD}\RP3\A0005118.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{8BC79291-E322-403F-8E40-1FBD3FCA0EBD}\RP3\A0005119.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{8BC79291-E322-403F-8E40-1FBD3FCA0EBD}\RP3\A0005120.exe (Trojan.MailFinder) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{8BC79291-E322-403F-8E40-1FBD3FCA0EBD}\RP3\A0005121.exe (Rogue.SystemSecurity) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{8BC79291-E322-403F-8E40-1FBD3FCA0EBD}\RP3\A0005122.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{8BC79291-E322-403F-8E40-1FBD3FCA0EBD}\RP3\A0005123.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
I use Malware Bytes to get rid of antimalware doctor in both regular and safe mode. Below are the last couple of logs from Malware Bytes. I had a vicious virus on this computer before (not this computer I am currently on, but the infected one which is also xp) and had to use the recovery discs. Its about a year later and I had periodical viruses that were easily taken care of by Malware Bytes, but I need help for this particular virus.
Thanks for your time.
Files Infected:
C:\My Backup -- 25-06-09 1924\Documents and Settings\LocalService\Application Data\1458931097.exe (Trojan.MailFinder) -> Quarantined and deleted successfully.
C:\My Backup -- 25-06-09 1924\Documents and Settings\ryan.wade\Ryan.Wade.exe (Trojan.Rabbit) -> Quarantined and deleted successfully.
C:\My Backup -- 25-06-09 1924\Documents and Settings\ryan.wade\Local Settings\Temp\148.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\My Backup -- 25-06-09 1924\Documents and Settings\ryan.wade\Local Settings\Temp\BNA.tmp (Rogue.Installer) -> Quarantined and deleted successfully.
C:\My Backup -- 25-06-09 1924\Documents and Settings\ryan.wade\Local Settings\Temp\install[1].exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\My Backup -- 25-06-09 1924\Documents and Settings\ryan.wade\Local Settings\Temp\~TM1D.tmp (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\My Backup -- 25-06-09 1924\Documents and Settings\ryan.wade\Local Settings\Temp\~TM2F.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\My Backup -- 25-06-09 1924\Documents and Settings\ryan.wade\Local Settings\Temp\~TMFB3.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\My Backup -- 25-06-09 1924\Documents and Settings\ryan.wade\Start Menu\Programs\Startup\asgupd32.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\My Backup -- 25-06-09 1924\Documents and Settings\ryan.wade\Start Menu\Programs\Startup\fmnupd32.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\My Backup -- 25-06-09 1924\WINDOWS\system32\avast!AVSControlService.exe (Trojan.MailFinder) -> Quarantined and deleted successfully.
C:\My Backup -- 25-06-09 1924\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\2S6ZZKBS\167[1].exe (Rogue.SystemSecurity) -> Quarantined and deleted successfully.
C:\My Backup -- 25-06-09 1924\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\BS0OE4AJ\test2[1].exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\My Backup -- 25-06-09 1924\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\G5D1PHAR\install[1].exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\My Backup -- 25-06-09 1924\WINDOWS\Temp\BN143F.tmp (Trojan.Rabbit) -> Quarantined and deleted successfully.
C:\My Backup -- 25-06-09 1924\WINDOWS\Temp\BN1440.tmp (Rogue.Installer) -> Quarantined and deleted successfully.
C:\My Backup -- 25-06-09 1924\WINDOWS\Temp\BN1441.tmp (Trojan.Rabbit) -> Quarantined and deleted successfully.
C:\My Backup -- 25-06-09 1924\WINDOWS\Temp\BN1442.tmp (Rogue.Installer) -> Quarantined and deleted successfully.
C:\My Backup -- 25-06-09 1924\WINDOWS\Temp\BN1443.tmp (Trojan.Rabbit) -> Quarantined and deleted successfully.
C:\My Backup -- 25-06-09 1924\WINDOWS\Temp\BN1444.tmp (Rogue.Installer) -> Quarantined and deleted successfully.
C:\My Backup -- 25-06-09 1924\WINDOWS\Temp\BN434.tmp (Rogue.Installer) -> Quarantined and deleted successfully.
C:\My Backup -- 25-06-09 1924\WINDOWS\Temp\rdl29.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\My Backup -- 25-06-09 1924\WINDOWS\Temp\rdl71.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\My Backup -- 25-06-09 1924\WINDOWS\Temp\~TM54EA3A.TMP (Trojan.Agent) -> Quarantined and deleted successfully.
C:\My Backup -- 25-06-09 1924\WINDOWS\Temp\~TME.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\My Backup -- 25-06-09 1924\WINDOWS\Temp\Temporary Internet Files\Content.IE5\57S41HQ2\ccsuper2[1].htm (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\My Backup -- 25-06-09 1924\WINDOWS\Temp\Temporary Internet Files\Content.IE5\6DUB3U6O\ccsuper3[1].htm (Worm.Koobface) -> Quarantined and deleted successfully.
C:\My Backup -- 25-06-09 1924\WINDOWS\Temp\Temporary Internet Files\Content.IE5\6DUB3U6O\ibcpduuv[1].htm (Worm.Koobface) -> Quarantined and deleted successfully.
C:\My Backup -- 25-06-09 1924\WINDOWS\Temp\Temporary Internet Files\Content.IE5\IDJUGRR1\ccsuper1[1].htm (Trojan.Agent) -> Quarantined and deleted successfully.
C:\My Backup -- 25-06-09 1924\WINDOWS\Temp\Temporary Internet Files\Content.IE5\VOC97G7Q\rbbsg[1].txt (Trojan.Dropper) -> Quarantined and deleted successfully.
Files Infected:
C:\System Volume Information\_restore{8BC79291-E322-403F-8E40-1FBD3FCA0EBD}\RP3\A0005114.exe (Trojan.MailFinder) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{8BC79291-E322-403F-8E40-1FBD3FCA0EBD}\RP3\A0005115.exe (Trojan.Rabbit) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{8BC79291-E322-403F-8E40-1FBD3FCA0EBD}\RP3\A0005116.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{8BC79291-E322-403F-8E40-1FBD3FCA0EBD}\RP3\A0005117.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{8BC79291-E322-403F-8E40-1FBD3FCA0EBD}\RP3\A0005118.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{8BC79291-E322-403F-8E40-1FBD3FCA0EBD}\RP3\A0005119.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{8BC79291-E322-403F-8E40-1FBD3FCA0EBD}\RP3\A0005120.exe (Trojan.MailFinder) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{8BC79291-E322-403F-8E40-1FBD3FCA0EBD}\RP3\A0005121.exe (Rogue.SystemSecurity) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{8BC79291-E322-403F-8E40-1FBD3FCA0EBD}\RP3\A0005122.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{8BC79291-E322-403F-8E40-1FBD3FCA0EBD}\RP3\A0005123.exe (Trojan.Downloader) -> Quarantined and deleted successfully.