Vista Home Premium-Service Pack 2
I've had some experience removing things in the past, but just picked up a bug that won't seem to go away. The good news is I have internet access, access to most antivirus software functioning, but the thing keeps coming back on reload, so I'm in need of some expert help.
I first notice the problem 2 days ago when my MSE went red and when you try and update it, a program attempts to install itself. When you click cancel, it keeps coming back up. I would have to rkill it to get it to go away. I can't recall the exact *.exe as it was a mix mash of letters, and my cleaning since then has at least gotten rid of that. The virus has shut down my ability to activate MSE and I get error messages when I try. So that was my trigger that I was infected. I've run malwarebytes, quick and full scans, MS safety scanner quick and full, and things are found. But upon reload, I run again and still not clean.
Let me know what else you need to know, and special thanks in advance to anyone taking their personal time to help out.
My most recent malwarebytes log:
Malwarebytes Anti-Malware 1.61.0.1400
www.malwarebytes.org
Database version: v2012.06.16.05
Windows Vista Service Pack 2 x86 NTFS
Internet Explorer 9.0.8112.16421
Geoff :: HOME [administrator]
6/18/2012 4:07:06 PM
mbam-log-2012-06-18 (16-07-06).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 262015
Time elapsed: 13 minute(s), 32 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 3
C:\Windows\Installer\{ae5877c1-20eb-7c5e-2e56-57be7c22be80}\U\00000001.@ (Trojan.Small) -> Quarantined and deleted successfully.
C:\Windows\Installer\{ae5877c1-20eb-7c5e-2e56-57be7c22be80}\U\80000000.@ (Trojan.Sirefef) -> Quarantined and deleted successfully.
C:\Windows\Installer\{ae5877c1-20eb-7c5e-2e56-57be7c22be80}\U\800000cb.@ (Rootkit.0Access) -> Quarantined and deleted successfully.
(end)


Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.
This topic is locked
Back to top










