We’d like to remind Forumites to please avoid political debate on the Forum.

This is to keep it a safe and useful space for MoneySaving discussions. Threads that are – or become – political in nature may be removed in line with the Forum’s rules. Thank you for your understanding.

📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!

HELP! PLEASE! Win 7 anti spyware con has infected & taken over my laptop!

13567

Comments

  • dalek
    dalek Posts: 9,386 Forumite
    This is the second scans log............


    05/04/2011 20:24:41
    mbam-log-2011-04-05 (20-24-40).txt

    Scan type: Full scan (C:\|D:\|E:\|F:\|)
    Objects scanned: 263202
    Time elapsed: 17 minute(s), 17 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 0

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    (No malicious items detected)

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    (No malicious items detected)
    The Daleks Reign Supreme, All Hail The Daleks!
  • karatepet
    karatepet Posts: 231 Forumite
    Part of the Furniture 100 Posts
    Looks like malwarebytes got rid of it.Is the laptop running ok.?
  • Browntoa
    Browntoa Posts: 49,612 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    dalek , now run this

    http://www.bleepingcomputer.com/combofix/how-to-use-combofix

    and post the log file
    Ex forum ambassador

    Long term forum member
  • dalek
    dalek Posts: 9,386 Forumite
    I am using it now, yes.

    It seems to be ok.

    Is there anything else i should scan with?
    The Daleks Reign Supreme, All Hail The Daleks!
  • dalek
    dalek Posts: 9,386 Forumite
    Browntoa wrote: »
    dalek , now run this

    http://www.bleepingcomputer.com/combofix/how-to-use-combofix

    and post the log file

    Thankyou.

    I will do it now.
    The Daleks Reign Supreme, All Hail The Daleks!
  • dalek
    dalek Posts: 9,386 Forumite
    Hmm windows defender doesn't seem to work - its telling me to re start my computer, so i will try again.
    The Daleks Reign Supreme, All Hail The Daleks!
  • Browntoa
    Browntoa Posts: 49,612 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    wait for AlienRik to take a read of the combofix log (he's the expert on these) , its removed a couple of extra bits
    Ex forum ambassador

    Long term forum member
  • dalek
    dalek Posts: 9,386 Forumite
    Okey dokes.
    The Daleks Reign Supreme, All Hail The Daleks!
  • dalek
    dalek Posts: 9,386 Forumite
    YIKES - A NEW infected file found by malaware!

    It didnt find it on the 2nd scan.

    Just restarting pc
    The Daleks Reign Supreme, All Hail The Daleks!
  • dalek
    dalek Posts: 9,386 Forumite
    The new log file

    Malwarebytes' Anti-Malware 1.50.1.1100
    www.malwarebytes.org

    Database version: 6281

    Windows 6.1.7600
    Internet Explorer 8.0.7600.16385

    05/04/2011 21:21:18
    mbam-log-2011-04-05 (21-21-18).txt

    Scan type: Full scan (C:\|D:\|E:\|G:\|)
    Objects scanned: 266399
    Time elapsed: 21 minute(s), 49 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 1
    Folders Infected: 0
    Files Infected: 0

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    (No malicious items detected)

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode\command\(default) (Hijack.StartMenuInternet) -> Bad: ("C:\Users\******\AppData\Local\fnv.exe" -a "C:\Program Files (x86)\Mozilla Firefox\firefox.exe" -safe-mode) Good: (firefox.exe -safe-mode) -> Quarantined and deleted successfully.

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    (No malicious items detected)
    The Daleks Reign Supreme, All Hail The Daleks!
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 352.1K Banking & Borrowing
  • 253.6K Reduce Debt & Boost Income
  • 454.2K Spending & Discounts
  • 245.2K Work, Benefits & Business
  • 600.8K Mortgages, Homes & Bills
  • 177.5K Life & Family
  • 259K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16K Discuss & Feedback
  • 37.7K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.