My husbands (newly reformatted) computer has become plagued by virus after virus within the last day or two. I've run an updated version of Malwarebytes, and this is my log:
I removed everything it found, ran it again, and it came up clean. Then I ran Spy Bot, removed what it found. Then I ran adaware, and removed what it found. However, while Adaware was running a message from AVG popped up saying that a threat (Trojan Horse Crypt.CJI) was detected. I moved it to the vault. I later opened the vault and it says that the files are in system restore and program files. I left the files in the vault.
Now I'm not sure what to do with the computer. Sometimes it takes a good 2 minutes before Firefox will even boot up. Sure its 8yrs old, but it was never this slow.
Quote
Malwarebytes' Anti-Malware 1.40
Database version: 2626
Windows 5.1.2600 Service Pack 3
8/14/2009 4:20:13 PM
mbam-log-2009-08-14 (16-19-59).txt
Scan type: Quick Scan
Objects scanned: 88912
Time elapsed: 32 minute(s), 22 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 5
Registry Values Infected: 4
Registry Data Items Infected: 0
Folders Infected: 3
Files Infected: 6
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CLASSES_ROOT\CLSID\{a77d3539-581d-450c-9e44-a84c415a6172} (Trojan.FakeAlert) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{a77d3539-581d-450c-9e44-a84c415a6172} (Trojan.FakeAlert) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{a77d3539-581d-450c-9e44-a84c415a6172} (Trojan.FakeAlert) -> No action taken.
HKEY_CLASSES_ROOT\urlsearchhook.toolbarurlsearchhook (Trojan.BHO) -> No action taken.
HKEY_CLASSES_ROOT\urlsearchhook.toolbarurlsearchhook.1 (Trojan.BHO) -> No action taken.
Registry Values Infected:
HKEY_CURRENT_USER\Environment\avapp (Rogue.PersonalAntiVirus) -> No action taken.
HKEY_CURRENT_USER\Environment\avuninst (Rogue.PersonalAntiVirus) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\msdrv (Trojan.Agent) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\personalav (Rogue.PersonalAntiVirus) -> No action taken.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
C:\Program Files\Common Files\Uninstall\PersonalAV (Rogue.PersonalAntiVirus) -> No action taken.
C:\Program Files\PersonalAV (Rogue.PersonalAntiVirus) -> No action taken.
C:\Documents and Settings\All Users\Start Menu\PersonalAV (Rogue.PersonalAntiVirus) -> No action taken.
Files Infected:
C:\WINDOWS\system32\NetFilter.exe (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\msxmlm.dll (Trojan.FakeAlert) -> No action taken.
C:\Documents and Settings\Joe\Local Settings\Temporary Internet Files\Content.IE5\N07M3SXB\Driver[1].exe (Trojan.Dropper) -> No action taken.
C:\Program Files\Common Files\Uninstall\PersonalAV\Uninstall.lnk (Rogue.PersonalAntiVirus) -> No action taken.
C:\Documents and Settings\All Users\Start Menu\PersonalAV\Personal Antivirus.lnk (Rogue.PersonalAntiVirus) -> No action taken.
C:\Documents and Settings\All Users\Start Menu\PersonalAV\Uninstall.lnk (Rogue.PersonalAntiVirus) -> No action taken.
--------------------------------------------------------------------------------
No virus found in this incoming message.
Checked by AVG - www.avg.com
Version: 8.5.392 / Virus Database: 270.13.56/2302 - Release Date: 08/14/09 06:10:00
Database version: 2626
Windows 5.1.2600 Service Pack 3
8/14/2009 4:20:13 PM
mbam-log-2009-08-14 (16-19-59).txt
Scan type: Quick Scan
Objects scanned: 88912
Time elapsed: 32 minute(s), 22 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 5
Registry Values Infected: 4
Registry Data Items Infected: 0
Folders Infected: 3
Files Infected: 6
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CLASSES_ROOT\CLSID\{a77d3539-581d-450c-9e44-a84c415a6172} (Trojan.FakeAlert) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{a77d3539-581d-450c-9e44-a84c415a6172} (Trojan.FakeAlert) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{a77d3539-581d-450c-9e44-a84c415a6172} (Trojan.FakeAlert) -> No action taken.
HKEY_CLASSES_ROOT\urlsearchhook.toolbarurlsearchhook (Trojan.BHO) -> No action taken.
HKEY_CLASSES_ROOT\urlsearchhook.toolbarurlsearchhook.1 (Trojan.BHO) -> No action taken.
Registry Values Infected:
HKEY_CURRENT_USER\Environment\avapp (Rogue.PersonalAntiVirus) -> No action taken.
HKEY_CURRENT_USER\Environment\avuninst (Rogue.PersonalAntiVirus) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\msdrv (Trojan.Agent) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\personalav (Rogue.PersonalAntiVirus) -> No action taken.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
C:\Program Files\Common Files\Uninstall\PersonalAV (Rogue.PersonalAntiVirus) -> No action taken.
C:\Program Files\PersonalAV (Rogue.PersonalAntiVirus) -> No action taken.
C:\Documents and Settings\All Users\Start Menu\PersonalAV (Rogue.PersonalAntiVirus) -> No action taken.
Files Infected:
C:\WINDOWS\system32\NetFilter.exe (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\msxmlm.dll (Trojan.FakeAlert) -> No action taken.
C:\Documents and Settings\Joe\Local Settings\Temporary Internet Files\Content.IE5\N07M3SXB\Driver[1].exe (Trojan.Dropper) -> No action taken.
C:\Program Files\Common Files\Uninstall\PersonalAV\Uninstall.lnk (Rogue.PersonalAntiVirus) -> No action taken.
C:\Documents and Settings\All Users\Start Menu\PersonalAV\Personal Antivirus.lnk (Rogue.PersonalAntiVirus) -> No action taken.
C:\Documents and Settings\All Users\Start Menu\PersonalAV\Uninstall.lnk (Rogue.PersonalAntiVirus) -> No action taken.
--------------------------------------------------------------------------------
No virus found in this incoming message.
Checked by AVG - www.avg.com
Version: 8.5.392 / Virus Database: 270.13.56/2302 - Release Date: 08/14/09 06:10:00
I removed everything it found, ran it again, and it came up clean. Then I ran Spy Bot, removed what it found. Then I ran adaware, and removed what it found. However, while Adaware was running a message from AVG popped up saying that a threat (Trojan Horse Crypt.CJI) was detected. I moved it to the vault. I later opened the vault and it says that the files are in system restore and program files. I left the files in the vault.
Now I'm not sure what to do with the computer. Sometimes it takes a good 2 minutes before Firefox will even boot up. Sure its 8yrs old, but it was never this slow.

Help
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Back to top










