I was scanning my friend's computer with Malwarebytes' anti-malware and quarantined 2 items. I removed using anti-malware but every time I open IE, the 2 items appears on the quarintine list again in anti-malware. Please help me remove them completely. Thanks in advance.
The two items:
Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\ShellBrowser\{b580cf65-e151-49c3-b73f-70b13fca8e86} (Trojan.Cinmus) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser\{b580cf65-e151-49c3-b73f-70b13fca8e86} (Trojan.Cinmus) -> Quarantined and deleted successfully.
We're going to need some more detailed logs, so please run the following two tools so that we can find out what the problem is.
Please download DDS and save it to your desktop.
Disable any script blocking protection
Double click dds.scr to run the tool.
When done two logs should open:
DDS.txt
Attach.txt
Save both reports to your desktop.
—————————————————
Post the contents of the DDS.txt report in your next reply
Attach the Attach.txt report to your post by scrolling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.
We Need to check for Rootkits with RootRepeal
Download RootRepeal from one of the following locations and save it to your desktop.
Open [external image: Posted Image] on your desktop.
Click the [external image: Posted Image] tab.
Click the [external image: Posted Image] button.
In the Select Scan dialog, check [external image: Posted Image]
Push Ok
Check the box for your main system drive (Usually C:), and press Ok.
Allow RootRepeal to run a scan of your system. This may take some time.
Once the scan completes, push the [external image: Posted Image] button. Save the log to your desktop, using a distinctive name, such as RootRepeal.txt. Please post this log in your next reply.