Hi!
This is the log from mbam
Kaspersky still scanning, and doesn't seem to end soon. I will post the results when finished
Cheers
Malwarebytes' Anti-Malware 1.26
Database version: 1110
Windows 5.1.2600 Service Pack 3, v.3300
3/9/2008 10:00:12 μμ
mbam-log-2008-09-03 (22-00-12).txt
Scan type: Quick Scan
Objects scanned: 51348
Time elapsed: 2 minute(s), 56 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 2
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CLASSES_ROOT\gksraemq.bgpd (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\gksraemq.toolbar.1 (Trojan.FakeAlert) -> Quarantined and deleted successfully.
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
Yea Kaspersky takes longer
Yea Kaspersky takes longer
After 2 hours is still on 1%! It could take days! So i will get some sleep, because I am so tired with all this virus fighting!
I will leave my pc scanning…
We will talk soon
Cheers!
One thing before i go to sleep..
After this infection that really scared me, what do you recommend for my safety and protection?
What are the best antivirus and firewall? What should I put to guard me better?
I would appreciate any suggestions on this subject!
I will recommend some stuff at the end
I will recommend some stuff at the end
Ok, thank you very much
P.S. Kaspersky is still on 2%…
Best leave it on over night
Best leave it on over night
Ooops just found an infected object…
Yes, I will leave it all night
I have turned off my Avast antivirus as kaspersky instructed. Is it safe for the night to leave it off?
Thanx
Bye for now
Yes perfectly safe
All the malware is gone pretty much, this will just find any left overs
Nearly done
It is now 60%. I left it for 20+ hours running. I hope it will soon be over and then I will post the results
Cheers
Oh my god!!! Am I still infected? So many viruses
I mean , I don't understand. Why some people want to heart us?
Here is the carspersky report
——————————————————————————–
KASPERSKY ONLINE SCANNER 7 REPORT
Friday, September 5, 2008
Operating System: Microsoft Windows XP Professional Service Pack 3, v.3300 (build 2600)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Wednesday, September 03, 2008 20:17:25
Records in database: 1188827
——————————————————————————–
Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes
Scan area - My Computer:
A:\
C:\
D:\
E:\
F:\
G:\
H:\
J:\
L:\
Scan statistics:
Files scanned: 865752
Threat name: 19
Infected objects: 270
Suspicious objects: 2
Duration of the scan: 35:59:21
File name / Threat name / Threats count
C:\DOWNLOADS\ALT\Networking Tools\MyShell-1.1.0.tar.gz Infected: Backdoor.PHP.PhpShell.n 1
C:\DOWNLOADS\ALT\Sp_Ra\RARPassGen.EXE Infected: Trojan-Downloader.Win32.Zlob.xnd 1
C:\DOWNLOADS\ALT\Sp_Ra\part02.rar Infected: Trojan-Downloader.Win32.Zlob.xnd 1
C:\DOWNLOADS\ALT\Sp_Ra\part04.rar Infected: Trojan-Downloader.Win32.Zlob.xnd 1
C:\DOWNLOADS\ALT\Sp_Ra\part06.rar Infected: Trojan-Downloader.Win32.Zlob.xnd 1
C:\DOWNLOADS\ALT\Sp_Ra\part08.rar Infected: Trojan-Downloader.Win32.Zlob.xnd 1
C:\DOWNLOADS\ALT\Sp_Ra\part11.rar Infected: Trojan-Downloader.Win32.Zlob.xnd 1
C:\DOWNLOADS\ALT\Sp_Ra\part13.rar Infected: Trojan-Downloader.Win32.Zlob.xnd 1
C:\DOWNLOADS\ALT\Sp_Ra\part15.rar Infected: Trojan-Downloader.Win32.Zlob.xnd 1
C:\DOWNLOADS\ALT\Sp_Ra\part18.rar Infected: Trojan-Downloader.Win32.Zlob.xnd 1
C:\DOWNLOADS\ALT\Sp_Ra\part20.rar Infected: Trojan-Downloader.Win32.Zlob.xnd 1
C:\DOWNLOADS\ALT\Sp_Ra\part22.rar Infected: Trojan-Downloader.Win32.Zlob.xnd 1
C:\DOWNLOADS\ALT\Sp_Ra\part24.rar Infected: Trojan-Downloader.Win32.Zlob.xnd 1
C:\DOWNLOADS\ALT\Sp_Ra\part27.rar Infected: Trojan-Downloader.Win32.Zlob.xnd 1
C:\DOWNLOADS\ALT\Sp_Ra\part29.rar Infected: Trojan-Downloader.Win32.Zlob.xnd 1
C:\DOWNLOADS\ALT\Sp_Ra\part31.rar Infected: Trojan-Downloader.Win32.Zlob.xnd 1
C:\DOWNLOADS\virusremoval\Fixes\SmitfraudFix.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f 1
C:\DOWNLOADS\virusremoval\rogueremoval.zip Infected: not-a-virus:RiskTool.Win32.Reboot.f 1
C:\E-MAILS\Inbox Infected: Email-Worm.Win32.NetSky.x 42
C:\SDFix\backups\backups.zip Infected: not-a-virus:FraudTool.Win32.Agent.bp 1
C:\SDFix\backups\backups.zip Infected: not-a-virus:FraudTool.Win32.Agent.bo 1
C:\SDFix\backups\backups.zip Infected: Trojan.Win32.Agent.abux 1
C:\SDFix\backups\backups.zip Infected: Trojan.Win32.Agent.abpr 1
C:\SDFix\backups\backups.zip Infected: not-a-virus:FraudTool.Win32.MSAntivirus.r 1
C:\SDFix\backups\backups.zip Infected: not-a-virus:FraudTool.Win32.MSAntivirus.t 1
C:\SDFix\backups\backups.zip Infected: Trojan-Downloader.Win32.Small.acri 1
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\UPW9P26M\ac[1].htm Infected: Trojan-Downloader.JS.Agent.cnn 1
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\UPW9P26M\ac[2].htm Infected: Trojan-Downloader.JS.Agent.cnn 1
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\UPW9P26M\ac[3].htm Infected: Trojan-Downloader.JS.Agent.cnn 1
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\UPW9P26M\ac[4].htm Infected: Trojan-Downloader.JS.Agent.cnn 1
D:\Users\Gro\Documents\gawret.rar Infected: not-a-virus:PSWTool.Win32.RAS.g 1
D:\Users\Gro\Documents\gawret.rar Infected: not-a-virus:PSWTool.Win32.RAS.a 1
D:\Users\Gro\Documents\wvbfgkgv.zip Infected: not-a-virus:PSWTool.Win32.RAS.g 1
D:\Users\Gro\Documents\wvbfgkgv.zip Infected: not-a-virus:PSWTool.Win32.RAS.a 1
D:\Users\Gro\Downloads\v9.1-TE.rar Infected: Backdoor.Win32.Kbot.by 1
D:\Users\Gro\Emails\RB\Inbox Infected: Email-Worm.Win32.NetSky.x 24
D:\Users\Gro\Emails\RM\Inbox Infected: Email-Worm.Win32.NetSky.x 53
D:\Users\Gro\Emails\RM\Trash Infected: Email-Worm.Win32.NetSky.x 24
D:\Users\Gro\Networking Tools\MyShell-1.1.0.tar.gz Infected: Backdoor.PHP.PhpShell.n 1
E:\DOWNLOADS\GAME.zip Infected: Trojan.BAT.Small.ai 1
E:\DOWNLOADS\GAME2.zip Infected: Trojan.BAT.Small.ai 1
E:\DOWNLOADS\card.zip Infected: Trojan.BAT.Small.ai 1
E:\DOWNLOADS\manual.zip Infected: Trojan.BAT.Small.ai 1
E:\DOWNLOADS\den_flix.zip Infected: Trojan.BAT.Small.ai 1
E:\DOWNLOADS\w22ft.zip Infected: Trojan.BAT.Small.ai 1
E:\DOWNLOADS\Networking Tools\MyShell-1.1.0.tar.gz Infected: Backdoor.PHP.PhpShell.n 1
E:\DOWNLOADS\downloads\EMAILBACKUP\Εισερχόμενα.dbx Suspicious: Exploit.HTML.Iframe.FileDownload 1
E:\DOWNLOADS\downloads\get.dbx Suspicious: Exploit.HTML.Iframe.FileDownload 1
E:\DOWNLOADS\LATESTDOWNLOADS\SiteGrinder.rar Infected: Trojan-Dropper.Win32.Delf.vt 1
L:\SATA\Emails\RB\Inbox Infected: Email-Worm.Win32.NetSky.x 24
L:\SATA\Emails\RM\Inbox Infected: Email-Worm.Win32.NetSky.x 43
L:\SATA\Emails\RM\Trash Infected: Email-Worm.Win32.NetSky.x 14
L:\ST\Ne_trial.exe Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm 1
L:\ST\ne_photos_setup.exe Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm 1
L:\ST\Ne\Toolbar.exe Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm 1
The selected area was scanned.
Hello
Please
download the
OTMoveIt2 by OldTimer .
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose
Yes.
1. Close any open browsers.
2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
3. Open
notepad and copy/paste the text in the quotebox below into it:
File::
DirLook::
C:\DOWNLOADS
D:\Users\Gro\Downloads
E:\DOWNLOADS
SkipFix::
Folder::
Registry::
Driver::
Save this as
CFScript.txt , in the same location as ComboFix.exe
[external image: Posted Image]
Refering to the picture above, drag CFScript into ComboFix.exe
When finished, it shall produce a log for you at
C:\ComboFix.txt which I will require in your next reply.
Hello and thanks a lot!
Before I continue this process, please tell me. When i will use this move it tool, it will move only the viruses or every folder from
my directory? For example in C:DOWNLOADS/ALT I have more other folders
Waiting for your reply
Do this instead, it wont delete the other folders
Please
download the
OTMoveIt2 by OldTimer .
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose
Yes.