We're aware that some users are experiencing technical issues which the team are working to resolve. See the Community Noticeboard for more info. Thank you for your patience.
📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!

I have a serious infection

Options
1235714

Comments

  • samdd
    samdd Posts: 1,344 Forumite
    samdd wrote: »
    Iv'e run the sacn 3 times but the infection hasnt been removed. Even though there is an infection its telling me that the system is clean, As below.

    Snapshot_3.jpg

    E2A> I noticed something wasnt being found at the start of the scan so i did a pause break and saw this.
    Snapshot_1-1.jpg
  • TakeThis
    TakeThis Posts: 2,909 Forumite
    Did you reboot?
  • jamespir
    jamespir Posts: 21,456 Forumite
    stick that prog on a usb pen
    Replies to posts are always welcome, If I have made a mistake in the post, I am human, tell me nicely and it will be corrected. If your reply cannot be nice, has an underlying issue, or you believe that you are God, please post in another forum. Thank you
  • samdd
    samdd Posts: 1,344 Forumite
    TakeThis wrote: »
    Did you reboot?

    Here is what i did. I done 3 scans in Safe Mode but nothing was removed. I then rebooted into normal mode and did another scan. It found and removed the infection (posted above) but then found this and didnt remove it. My system then crashed (bsod) so now im back in safe mode. this is the results of the scan in normal mode.

    Snapshot_4.jpg
  • samdd
    samdd Posts: 1,344 Forumite
    jamespir wrote: »
    stick that prog on a usb pen

    OK, Ill do it now and run a scan
  • samdd
    samdd Posts: 1,344 Forumite
    jamespir wrote: »
    stick that prog on a usb pen

    I downloaded the prog again direct to my USB. rebooted into normal mode and ran a scan. as below. after the scan it Blue screened so im noe back in safe mode.

    Snapshot_4.jpg
  • samdd
    samdd Posts: 1,344 Forumite
    TakeThis wrote: »
    Did you reboot?

    yes i did...
  • TakeThis
    TakeThis Posts: 2,909 Forumite
    May be time to get those blank discs.
  • samdd
    samdd Posts: 1,344 Forumite
    OK Guys.. soz to have been slow in updating.. i think i now have a clean system but with a whole new set of issues..

    Webroot Killed and removed the infection ' System disk class driver state' but not the second infection, found on the second scan, 'cdrom.sys'. So thought id give Mbam one more try before formatting the Hdd.

    I rebooted into Safe mode and then downloaded Mbam onto the desktop, installed, updated, (until it said that i had the latest database) and then run a quick scan.

    Scan completed sucessfully, :T as below.
    Malwarebytes' Anti-Malware 1.51.2.1300
    www.malwarebytes.org

    Database version: 7807

    Windows 6.1.7601 Service Pack 1 (Safe Mode)
    Internet Explorer 8.0.7601.17514

    27/09/2011 12:28:23
    mbam-log-2011-09-27 (12-28-23).txt

    Scan type: Quick scan
    Objects scanned: 159942
    Time elapsed: 5 minute(s), 48 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 42

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    (No malicious items detected)

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    c:\Users\***\AppData\Local\Temp\3302.tmp (Rootkit.TDSS) -> Quarantined and deleted successfully.
    c:\Users\***\AppData\Local\Temp\4F48.tmp (Rootkit.TDSS) -> Quarantined and deleted successfully.
    c:\Users\***\AppData\Local\Temp\603C.tmp (Rootkit.TDSS) -> Quarantined and deleted successfully.
    c:\Users\***\AppData\Local\Temp\B877.tmp (Rootkit.TDSS) -> Quarantined and deleted successfully.
    c:\Users\***\AppData\Local\Temp\setup1075510072.exe (Rootkit.TDSS) -> Quarantined and deleted successfully.
    c:\Users\***\AppData\Local\Temp\setup1251691884.exe (Rootkit.TDSS) -> Quarantined and deleted successfully.
    c:\Users\***\AppData\Local\Temp\setup1285643104.exe (Rootkit.TDSS) -> Quarantined and deleted successfully.
    c:\Users\***\AppData\Local\Temp\setup1314234476.exe (Rootkit.TDSS) -> Quarantined and deleted successfully.
    c:\Users\***\AppData\Local\Temp\setup1317369352.exe (Rootkit.TDSS) -> Quarantined and deleted successfully.
    c:\Users\***\AppData\Local\Temp\setup1322444416.exe (Rootkit.TDSS) -> Quarantined and deleted successfully.
    c:\Users\***\AppData\Local\Temp\setup1354789264.exe (Rootkit.TDSS) -> Quarantined and deleted successfully.
    c:\Users\***\AppData\Local\Temp\setup1485891576.exe (Rootkit.TDSS) -> Quarantined and deleted successfully.
    c:\Users\***\AppData\Local\Temp\setup1745214080.exe (Rootkit.TDSS) -> Quarantined and deleted successfully.
    c:\Users\***\AppData\Local\Temp\setup1948188304.exe (Rootkit.TDSS) -> Quarantined and deleted successfully.
    c:\Users\***\AppData\Local\Temp\setup2189639948.exe (Rootkit.TDSS) -> Quarantined and deleted successfully.
    c:\Users\***\AppData\Local\Temp\setup2228263968.exe (Rootkit.TDSS) -> Quarantined and deleted successfully.
    c:\Users\***\AppData\Local\Temp\setup2347215488.exe (Rootkit.TDSS) -> Quarantined and deleted successfully.
    c:\Users\***\AppData\Local\Temp\setup2356543816.exe (Rootkit.TDSS) -> Quarantined and deleted successfully.
    c:\Users\***\AppData\Local\Temp\setup2450512424.exe (Rootkit.TDSS) -> Quarantined and deleted successfully.
    c:\Users\***\AppData\Local\Temp\setup2532194504.exe (Rootkit.TDSS) -> Quarantined and deleted successfully.
    c:\Users\***\AppData\Local\Temp\setup2680283804.exe (Rootkit.TDSS) -> Quarantined and deleted successfully.
    c:\Users\***\AppData\Local\Temp\setup309882472.exe (Rootkit.TDSS) -> Quarantined and deleted successfully.
    c:\Users\***\AppData\Local\Temp\setup3120854532.exe (Rootkit.TDSS) -> Quarantined and deleted successfully.
    c:\Users\***\AppData\Local\Temp\setup3213415248.exe (Rootkit.TDSS) -> Quarantined and deleted successfully.
    c:\Users\***\AppData\Local\Temp\setup3458551580.exe (Rootkit.TDSS) -> Quarantined and deleted successfully.
    c:\Users\***\AppData\Local\Temp\setup3488323112.exe (Rootkit.TDSS) -> Quarantined and deleted successfully.
    c:\Users\***\AppData\Local\Temp\setup3722520600.exe (Rootkit.TDSS) -> Quarantined and deleted successfully.
    c:\Users\***\AppData\Local\Temp\setup3903296424.exe (Rootkit.TDSS) -> Quarantined and deleted successfully.
    c:\Users\***\AppData\Local\Temp\setup4024210016.exe (Rootkit.TDSS) -> Quarantined and deleted successfully.
    c:\Users\***\AppData\Local\Temp\setup4092782816.exe (Rootkit.TDSS) -> Quarantined and deleted successfully.
    c:\Users\***\AppData\Local\Temp\setup415768400.exe (Rootkit.TDSS) -> Quarantined and deleted successfully.
    c:\Users\***\AppData\Local\Temp\setup4166016548.exe (Rootkit.TDSS) -> Quarantined and deleted successfully.
    c:\Users\***\AppData\Local\Temp\setup4206739620.exe (Rootkit.TDSS) -> Quarantined and deleted successfully.
    c:\Users\***\AppData\Local\Temp\setup44818332.exe (Rootkit.TDSS) -> Quarantined and deleted successfully.
    c:\Users\***\AppData\Local\Temp\setup54375280.exe (Rootkit.TDSS) -> Quarantined and deleted successfully.
    c:\Users\***\AppData\Local\Temp\setup563330540.exe (Rootkit.TDSS) -> Quarantined and deleted successfully.
    c:\Users\***\AppData\Local\Temp\setup790038544.exe (Rootkit.TDSS) -> Quarantined and deleted successfully.
    c:\Users\***\AppData\Local\Temp\setup811643864.exe (Rootkit.TDSS) -> Quarantined and deleted successfully.
    c:\Users\***\AppData\Local\Temp\setup894888688.exe (Rootkit.TDSS) -> Quarantined and deleted successfully.
    c:\Users\***\AppData\Local\Temp\setup935700148.exe (Rootkit.TDSS) -> Quarantined and deleted successfully.
    c:\Users\***\fen.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
    c:\Users\***\gen.exe (Rootkit.TDSS) -> Quarantined and deleted successfully.
    I then ran another scan but this time a full scan:
    Malwarebytes' Anti-Malware 1.51.2.1300
    www.malwarebytes.org

    Database version: 7807

    Windows 6.1.7601 Service Pack 1 (Safe Mode)
    Internet Explorer 8.0.7601.17514

    27/09/2011 13:23:03
    mbam-log-2011-09-27 (13-23-02).txt

    Scan type: Full scan (C:\|D:\|F:\|)
    Objects scanned: 180005
    Time elapsed: 53 minute(s), 55 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 1

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    (No malicious items detected)

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    c:\Users\***\AppData\Roaming\thinstall\adobe audition 3.0\4800000097500002i\Audition.exe (Trojan.IRCBot) -> Quarantined and deleted successfully.
    Im not sure how Adobe Audition could have become infected as its a legal copy. So I then ran another scan:
    Malwarebytes' Anti-Malware 1.51.2.1300
    www.malwarebytes.org

    Database version: 7808

    Windows 6.1.7601 Service Pack 1 (Safe Mode)
    Internet Explorer 8.0.7601.17514

    27/09/2011 15:15:50
    mbam-log-2011-09-27 (15-15-50).txt

    Scan type: Full scan (C:\|D:\|)
    Objects scanned: 507210
    Time elapsed: 1 hour(s), 35 minute(s), 31 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 0

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    (No malicious items detected)

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    (No malicious items detected)

    So now to give the laptop a hard boot. Left it off for a couple of minutes and then booted into Normal mode.

    The slow load process made me think that something wasnt right. Within a minute in normal mode it BSOD and rebooted.. it did this three times, so now im back in in Safe mode with a clean system but blue screening.. lol

    Anyone any idea's how i can fix this or what may be causing the BSOD?

    Thanks..



    Would i be right in thinking that my system is now clean?
  • GunJack
    GunJack Posts: 11,836 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    ......Gettin' There, Wherever There is......

    I have a dodgy "i" key, so ignore spelling errors due to "i" issues, ...I blame Apple :D
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 350.9K Banking & Borrowing
  • 253.1K Reduce Debt & Boost Income
  • 453.5K Spending & Discounts
  • 243.9K Work, Benefits & Business
  • 598.8K Mortgages, Homes & Bills
  • 176.9K Life & Family
  • 257.2K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16.1K Discuss & Feedback
  • 37.6K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.