We’d like to remind Forumites to please avoid political debate on the Forum.

This is to keep it a safe and useful space for MoneySaving discussions. Threads that are – or become – political in nature may be removed in line with the Forum’s rules. Thank you for your understanding.

The MSE Forum Team would like to wish you all a very Happy New Year. However, we know this time of year can be difficult for some. If you're struggling during the festive period, here's a list of organisations that might be able to help
📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!
Has MSE helped you to save or reclaim money this year? Share your 2025 MoneySaving success stories!

Malwarebytes Log-can anyone please check this?

13

Comments

  • aliEnRIK
    aliEnRIK Posts: 17,741 Forumite
    Part of the Furniture Combo Breaker
    id say your good to go now :)
    :idea:
  • beachlou
    beachlou Posts: 760 Forumite
    Thank you to everyone who's helped me! What should I do now with regards to security on my laptop?
  • aliEnRIK
    aliEnRIK Posts: 17,741 Forumite
    Part of the Furniture Combo Breaker
    beachlou wrote: »
    Thank you to everyone who's helped me! What should I do now with regards to security on my laptop?
    Download HIJACK THIS (Make sure you click 'DOWNLOAD LATEST VERSION')
    http://www.filehippo.com/download_hijackthis/
    Click MAIN MENU then DO A SYSTEM SCAN AND SAVE A LOGFILE(Takes seconds) then post the log so we can see whats running
    (do NOT do anything else with Hijack but scan and post the FULL log)
    If you get a message that you cant write to the hosts file then Press the SHIFT key, and whilst holding it RIGHT CLICK and select RUN AS (admin)
    :idea:
  • macman
    macman Posts: 53,129 Forumite
    Part of the Furniture 10,000 Posts Name Dropper
    Start by running Windows Updates and getting Vista SP2 and any subsequent updates.
    No free lunch, and no free laptop ;)
  • When trying to download Hijack, the system tool came back!
  • Ok, have ran malwarebytes again after the krill and this is the latest log:

    Malwarebytes' Anti-Malware 1.50.1.1100
    www.malwarebytes.org
    Database version: 5891
    Windows 6.0.6002 Service Pack 2
    Internet Explorer 8.0.6001.19019
    27/02/2011 22:17:09
    mbam-log-2011-02-27 (22-17-09).txt
    Scan type: Quick scan
    Objects scanned: 161606
    Time elapsed: 3 minute(s), 38 second(s)
    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 1
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 2
    Memory Processes Infected:
    (No malicious items detected)
    Memory Modules Infected:
    (No malicious items detected)
    Registry Keys Infected:
    (No malicious items detected)
    Registry Values Infected:
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\pCiCkIh06308 (Trojan.FakeAlert) -> Value: pCiCkIh06308 -> Quarantined and deleted successfully.
    Registry Data Items Infected:
    (No malicious items detected)
    Folders Infected:
    (No malicious items detected)
    Files Infected:
    c:\programdata\pcickih06308\pcickih06308.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    c:\Users\Louise\local settings\temporary internet files\Content.IE5\08PH2RX1\setup[1].exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.

    Any ideas???
  • aliEnRIK
    aliEnRIK Posts: 17,741 Forumite
    Part of the Furniture Combo Breaker
    Can you please explain exactly how the tool came back? (Im thinking your hosts been infected and so redirecting)
    :idea:
  • Narc0lepsy
    Narc0lepsy Posts: 2,918 Forumite
    Part of the Furniture 1,000 Posts Name Dropper Photogenic
    I've read this, and another thread with interest as I also have spent much of today getting rid of the System Tool thing. Mine popped up when I was on line looking at the Indian Visa application site. I have 2 observations:1. Although my preferred browser is Opera, it was only when in desperation I tried Internet Explorer that I managed to download Anti Malware as the ST kept hijacking it (and Avast). So I'll be looking on any threads which compare browser safety now!2. I got rid of the ST by following instructions on the bleepingcomputer site (safe mode, rkill, malwarebytes software). I stopped at about stage 21 as it was talking about the host and how to change something - have to say I lost my bottle then as I'm not very confident about anything much more than 'scan and press remove'.
    Remember...a layer of dust protects the wood beneath it.
  • beachlou
    beachlou Posts: 760 Forumite
    aliEnRIK wrote: »
    Can you please explain exactly how the tool came back? (Im thinking your hosts been infected and so redirecting)

    Hi,

    It made an apperance when I was trying to download Hijack. It's gone from my computer now (after running rkill & malwarebytes) but it no longer lets me on the internet.
  • aliEnRIK
    aliEnRIK Posts: 17,741 Forumite
    Part of the Furniture Combo Breaker
    Id follow this from 22 (try removing hosts before having to use another computer to download the 'bat' file)

    http://www.bleepingcomputer.com/virus-removal/remove-system-tool
    :idea:
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 352.9K Banking & Borrowing
  • 253.9K Reduce Debt & Boost Income
  • 454.8K Spending & Discounts
  • 246K Work, Benefits & Business
  • 602.1K Mortgages, Homes & Bills
  • 177.8K Life & Family
  • 260K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16K Discuss & Feedback
  • 37.7K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.