Every 10 seconds, it pops up with some shit about and infected file. HELP, I need answers fast and I made this fast because I need help..
PHEW:
Malwarebytes' Anti-Malware 1.46
[url]www.malwarebytes.org[/url]
Database version: 4147
Windows 6.1.7600 (Safe Mode)
Internet Explorer 8.0.7600.16385
5/27/2010 12:00:38 AM
mbam-log-2010-05-27 (00-00-38).txt
Scan type: Full scan (C:\|)
Objects scanned: 206989
Time elapsed: 24 minute(s), 34 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 2
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 6
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CURRENT_USER\Software\avsoft (Trojan.Fraudpack) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\avsuite (Rogue.AntivirusSuite) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\bexqfyqn (Rogue.AntivirusSuite.Gen) -> Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
C:\Users\Linux\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VGJ7QI0W\n00a102318801r0409J0e000601R3b20de50W160c5afaXc2de61adY8923c8d8Z03003f361[1] (Rootkit.TDSS.Gen) -> Quarantined and deleted successfully.
C:\Users\Linux\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VGJ7QI0W\n00a102318801r0409J0e000601Rcf271e96W160c5afaXc2df9e00Y8923c8d8Z03003f361[1] (Rootkit.TDSS.Gen) -> Quarantined and deleted successfully.
C:\Users\Linux\AppData\Local\Temp\ydHH.exe (Rootkit.TDSS.Gen) -> Quarantined and deleted successfully.
C:\Users\Linux\AppData\Local\Temp\Ysch.exe (Rootkit.TDSS.Gen) -> Quarantined and deleted successfully.
C:\Users\Linux\AppData\Local\Temp\Rar$EX00.604\penis.exe (Backdoor.Sdbot) -> Quarantined and deleted successfully.
C:\Users\Linux\AppData\Local\lpgekdpye\mptkqrptssd.exe (Rogue.AntivirusSuite.Gen) -> Quarantined and deleted successfully.
Microsoft Security Essentials
[url]http://lmgtfy.com/?q=Microsoft+Security+%20Essentials&l=1[/url]
Now if switching isn't an option well then best of luck.
LOL, it says I have 34 threats.
[editline]11:17PM[/editline]
[QUOTE=GWMCOCD;22188862]Microsoft Security Essentials
[url]http://*********com/2w6ruat[/url]
Now if switching isn't an option well then best of luck.[/QUOTE]
I already got MSE
[editline]11:20PM[/editline]
MSE doesn't detect it...
[editline]11:22PM[/editline]
Oh my god it opened up ie and opened viagra.com o_o
Malwarebytes anti malware
Rebooted in safe mode, doing a scan as we speak
Oh shit, my brother has exactly the same virus except it hasn't opened viagra.com as far as I know. Not yet anyway. Trying to get him to run spybot, spyware doctor, malwarebytes, and ad-aware in safe mode but hes not too bright on computers and I know he is relying on me too much. His comp is cluttered and slow as fuck and he can be an impatient bitch. Anyway, if we get the problem fixed I'll reply back here.
Thanks Garry for glorious malware :rant:
as a last resort, use combo-fix
it's for rootkits
I got this virus from paheal.net (a 'friend' linked me)
I think you have a plethora of infections - because the notorious Antispyware Soft rubbish basically hijacks the operating system and prevents all but one or two programs from opening - any attempt to "get in there" and end it are stopped. I've never seen it open any adverts before.
"Nope, you're not opening taskmgr.exe. It's a virus."
"Nope, you're not opening Control Panel. It's infected."
The best way is to restart into safe mode, try to remove it by hand (you'll find it sitting in your temporary files somewhere), and install and run Spybot S&D. This was the method I used to clean a neighbour's computer from the bastard. The viagra pop-ups are probably being caused by some other malware. Spybot should be able to find this as well, because Microsoft Security Essentials will likely refuse to install in safe mode.
I had this, System Restore in Safe Mode w/ Networking killed it. Haven't run into it since.
Sorry, you need to Log In to post a reply to this thread.