Crosswords2 mins ago
Help please :)
7 Answers
I have run a virus scan on my PC and some of these couldn't be removed. im gonna post the log now..
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org
Database version: 6319
Windows 6.0.6000
Internet Explorer 7.0.6000.16982
09/04/2011 18:07:13
mbam-log-2011-04-09 (18-07-13).txt
Scan type: Full scan (C:\|)
Objects scanned: 243027
Time elapsed: 1 hour(s), 4 minute(s), 24 second(s)
Memory Processes Infected: 3
Memory Modules Infected: 0
Registry Keys Infected: 3
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 8
Memory Processes Infected:
c:\Windows\Hquvya.exe (Trojan.Downloader) -> 3308 -> Unloaded process successfully.
c:\Users\jake\AppData\Local\Temp\Hpz.exe (Trojan.Downloader) -> 2084 -> Unloaded process successfully.
c:\Users\jake\AppData\Local\Temp\Hp1.exe (Trojan.Downloader) -> 1372 -> Unloaded process successfully.
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\NtWqIVLZEWZU (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\W5E7SH31DG (Trojan.FakeAlert.SA) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\Windows\
CurrentVersion\Internet
Settings\Zones\ (Hijack.Zones) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\
CurrentVersion\Run\W5E7SH31DG
(Trojan.Downloader) -> Value: W5E7SH31DG -> Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org
Database version: 6319
Windows 6.0.6000
Internet Explorer 7.0.6000.16982
09/04/2011 18:07:13
mbam-log-2011-04-09 (18-07-13).txt
Scan type: Full scan (C:\|)
Objects scanned: 243027
Time elapsed: 1 hour(s), 4 minute(s), 24 second(s)
Memory Processes Infected: 3
Memory Modules Infected: 0
Registry Keys Infected: 3
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 8
Memory Processes Infected:
c:\Windows\Hquvya.exe (Trojan.Downloader) -> 3308 -> Unloaded process successfully.
c:\Users\jake\AppData\Local\Temp\Hpz.exe (Trojan.Downloader) -> 2084 -> Unloaded process successfully.
c:\Users\jake\AppData\Local\Temp\Hp1.exe (Trojan.Downloader) -> 1372 -> Unloaded process successfully.
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\NtWqIVLZEWZU (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\W5E7SH31DG (Trojan.FakeAlert.SA) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\Windows\
CurrentVersion\Internet
Settings\Zones\ (Hijack.Zones) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\
CurrentVersion\Run\W5E7SH31DG
(Trojan.Downloader) -> Value: W5E7SH31DG -> Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Answers
Best Answer
No best answer has yet been selected by JSIMMO. Once a best answer has been selected, it will be shown here.
For more on marking an answer as the "Best Answer", please visit our FAQ.and now the 2nd half...
Folders Infected:
(No malicious items detected)
Files Infected:
c:\Windows\Hquvya.exe (Trojan.Downloader) -> Delete on reboot.
c:\Users\jake\AppData\Local\Temp\Hpz.exe (Trojan.Downloader) -> Delete on reboot.
c:\Users\jake\AppData\Local\Temp\Hp1.exe (Trojan.Downloader) -> Delete on reboot.
c:\Users\jake\AppData\Local\Google\Chrome\use
r
data\Default\Cache\f_000b38 (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\Users\jake\AppData\Local\Temp\Hp0.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\Windows\Tasks\{22116563-108c-42c0-a7ce-601
61b75e508}.job
(Trojan.Downloader) -> Quarantined and deleted successfully.
c:\Windows\Tasks\{bbaeaeaf-1275-40e2-bd6c-bc8
f88bd114a}.job
(Trojan.Downloader) -> Quarantined and deleted successfully.
c:\Windows\Tasks\{810401e2-dde0-454e-b0e2-aa8
9c9e5967c}.job
(Trojan.FraudPack) -> Quarantined and deleted successfully.
Folders Infected:
(No malicious items detected)
Files Infected:
c:\Windows\Hquvya.exe (Trojan.Downloader) -> Delete on reboot.
c:\Users\jake\AppData\Local\Temp\Hpz.exe (Trojan.Downloader) -> Delete on reboot.
c:\Users\jake\AppData\Local\Temp\Hp1.exe (Trojan.Downloader) -> Delete on reboot.
c:\Users\jake\AppData\Local\Google\Chrome\use
r
data\Default\Cache\f_000b38 (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\Users\jake\AppData\Local\Temp\Hp0.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\Windows\Tasks\{22116563-108c-42c0-a7ce-601
61b75e508}.job
(Trojan.Downloader) -> Quarantined and deleted successfully.
c:\Windows\Tasks\{bbaeaeaf-1275-40e2-bd6c-bc8
f88bd114a}.job
(Trojan.Downloader) -> Quarantined and deleted successfully.
c:\Windows\Tasks\{810401e2-dde0-454e-b0e2-aa8
9c9e5967c}.job
(Trojan.FraudPack) -> Quarantined and deleted successfully.
-- answer removed --
-- answer removed --
-- answer removed --