Donate SIGN UP

Help please :)

Avatar Image
JSIMMO | 18:11 Sat 09th Apr 2011 | Technology
7 Answers
I have run a virus scan on my PC and some of these couldn't be removed. im gonna post the log now..
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Database version: 6319

Windows 6.0.6000
Internet Explorer 7.0.6000.16982

09/04/2011 18:07:13
mbam-log-2011-04-09 (18-07-13).txt

Scan type: Full scan (C:\|)
Objects scanned: 243027
Time elapsed: 1 hour(s), 4 minute(s), 24 second(s)

Memory Processes Infected: 3
Memory Modules Infected: 0
Registry Keys Infected: 3
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 8

Memory Processes Infected:
c:\Windows\Hquvya.exe (Trojan.Downloader) -> 3308 -> Unloaded process successfully.
c:\Users\jake\AppData\Local\Temp\Hpz.exe (Trojan.Downloader) -> 2084 -> Unloaded process successfully.
c:\Users\jake\AppData\Local\Temp\Hp1.exe (Trojan.Downloader) -> 1372 -> Unloaded process successfully.

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\NtWqIVLZEWZU (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\W5E7SH31DG (Trojan.FakeAlert.SA) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\Windows\
CurrentVersion\Internet
Settings\Zones\ (Hijack.Zones) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\
CurrentVersion\Run\W5E7SH31DG
(Trojan.Downloader) -> Value: W5E7SH31DG -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)
Gravatar

Answers

1 to 7 of 7rss feed

Best Answer

No best answer has yet been selected by JSIMMO. Once a best answer has been selected, it will be shown here.

For more on marking an answer as the "Best Answer", please visit our FAQ.
Question Author
and now the 2nd half...

Folders Infected:
(No malicious items detected)

Files Infected:
c:\Windows\Hquvya.exe (Trojan.Downloader) -> Delete on reboot.
c:\Users\jake\AppData\Local\Temp\Hpz.exe (Trojan.Downloader) -> Delete on reboot.
c:\Users\jake\AppData\Local\Temp\Hp1.exe (Trojan.Downloader) -> Delete on reboot.
c:\Users\jake\AppData\Local\Google\Chrome\use
r
data\Default\Cache\f_000b38 (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\Users\jake\AppData\Local\Temp\Hp0.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\Windows\Tasks\{22116563-108c-42c0-a7ce-601
61b75e508}.job
(Trojan.Downloader) -> Quarantined and deleted successfully.
c:\Windows\Tasks\{bbaeaeaf-1275-40e2-bd6c-bc8
f88bd114a}.job
(Trojan.Downloader) -> Quarantined and deleted successfully.
c:\Windows\Tasks\{810401e2-dde0-454e-b0e2-aa8
9c9e5967c}.job
(Trojan.FraudPack) -> Quarantined and deleted successfully.
-- answer removed --
Question Author
how do i delete the temp files??

i've got a good idea for Hquvya.exe, just search for it aha :)
Question Author
i cannot find the Hquvya.exe, or any of the other files that are in temp :/
-- answer removed --
-- answer removed --
Question Author
thanks mate =D

1 to 7 of 7rss feed

Do you know the answer?

Help please :)

Answer Question >>