This is the first time I have posted so please bear with me.
I am using Windows Vista 32 bit. On March 18th, 2011, a message popped up and I accidentally clicked it off before I could read it. I ran Malwarebyes and here was the log as follows:
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org
Database version: 6103
Windows 6.0.6002 Service Pack 2
Internet Explorer 8.0.6001.19019
3/18/2011 10:33:36 PM
mbam-log-2011-03-18 (22-33-36).txt
Scan type: Quick scan
Objects scanned: 166712
Time elapsed: 20 minute(s), 6 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 1
Registry Data Items Infected: 1
Folders Infected: 0
Files Infected: 4
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\QiffIeqXNyJn (Trojan.FakeAlert) -> Value: QiffIeqXNyJn -> Quarantined and deleted successfully.
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr (PUM.Hijack.TaskManager) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
Folders Infected:
(No malicious items detected)
Files Infected:
c:\programdata\qiffieqxnyjn.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\Users\Owner\AppData\Local\Temp\tmp2500.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\Users\Owner\AppData\Local\Temp\-213E8.tmp (Trojan.FakeAlert.Gen) -> Quarantined and deleted successfully.
c:\Users\Owner\AppData\Local\Temp\1363E8.tmp (Trojan.Agent) -> Delete on reboot.
Malwarebytes then stated that 2 of the infections were not deleted. I rebooted and was unable to access any of my personal files, such as photos, music, etc. It says that all of my folders are empty. I received another message upon reboot:
CCPLG.XML:
Unable to find file (C:Program Files\Avira\AntiVir Desktop\ccplg.xml).
I cannot turn on my antivirus software.
I tried to update Malwarebytes and received this message:
An error has occured. Please report this error code to our support team.
PROGRAM_ERROR_UPDATING (5,0, CreateFile)
Access is denied.
I also ran RKill and here is what popped up:
This log file is located at C:\rkill.log.
Please post this only if requested to by the person helping you.
Otherwise you can close this log when you wish.
Rkill was run on 03/18/2011 at 22:09:59.
Operating System: Windows Vista Home Premium
Processes terminated by Rkill or while it was running:
C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE
C:\ProgramData\QiffIeqXNyJn.exe
C:\Program Files\Real\RealUpgrade\RealUpgrade.exe
Rkill completed on 03/18/2011 at 22:10:57.
Please post this only if requested to by the person helping you.
Otherwise you can close this log when you wish.
Rkill was run on 03/18/2011 at 22:58:58.
Operating System: Windows Vista Home Premium
Processes terminated by Rkill or while it was running:
Rkill completed on 03/18/2011 at 22:59:07.
Please post this only if requested to by the person helping you.
Otherwise you can close this log when you wish.
Ran as Owner on 03/18/2011 at 23:12:10.
Processes terminated by Rkill or while it was running:
c:\Users\Owner\Desktop\My Documents\Support\rkill.exe
Rkill completed on 03/18/2011 at 23:12:15.
Please post this only if requested to by the person helping you.
Otherwise you can close this log when you wish.
Rkill was run on 03/19/2011 at 8:29:04.
Operating System: Windows Vista Home Premium
Processes terminated by Rkill or while it was running:
C:\Windows\System32\grpconv.exe
Rkill completed on 03/19/2011 at 8:29:10.
Please post this only if requested to by the person helping you.
Otherwise you can close this log when you wish.
Rkill was run on 03/19/2011 at 17:37:45.
Operating System: Windows Vista Home Premium
Processes terminated by Rkill or while it was running:
Rkill completed on 03/19/2011 at 17:37:53.
Please post this only if requested to by the person helping you.
Otherwise you can close this log when you wish.
Rkill was run on 03/19/2011 at 18:41:03.
Operating System: Windows Vista Home Premium
Processes terminated by Rkill or while it was running:
--- ATTENTION ---
Windows was configured to use a proxy! Proxy settings have been removed.
The Proxy Server that was configured is:
If this was a valid setting, please double-click on the rk-proxy.reg file on your desktop and allow the data to be merged to restore your proxy settings.
Rkill completed on 03/19/2011 at 18:41:09.
Other than that, the computer starts up fine, I am able to get online and open certain programs such as Word and Photoshop. I ran another scan on Malwarebytes and it is scanning all of my files that the computer says aren't there so I don't know what to do, I also have not lost any gigabytes on my C drive.
Please help! Any suggestions would be greatly appreciated!
Thank you!
This post has been edited by boopme: 19 March 2011 - 07:49 PM
Reason for edit: Moved from Vista to Am I Infected~~boopme

Help
This topic is locked


Back to top









