Here is the Log contents:
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org
Database version: 6788
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
6/6/2011 12:45:52 PM
mbam-log-2011-06-06 (12-45-32).txt
Scan type: Full scan (C:\|)
Objects scanned: 340495
Time elapsed: 1 hour(s), 17 minute(s), 27 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 1
Folders Infected: 0
Files Infected: 3
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr (PUM.Hijack.TaskManager) -> Bad: (1) Good: (0) -> No action taken.
Folders Infected:
(No malicious items detected)
Files Infected:
c:\documents and settings\all users\application data\17948452.exe (Trojan.FakeMS) -> No action taken.
c:\documents and settings\all users\application data\vyuamrmefielc.exe (Trojan.FakeMS) -> No action taken.
c:\documents and settings\ecarey.themissouribank\local settings\Temp\pdfupd.exe (Trojan.FakeAlert) -> No action taken.
End of Log
I have been through so many posts about trying to get rid of this my head has started to go in circles.
I had then seen the Remove Windows Recovery (Uninstall Guide) on this site under the Spyware Removal tab. http://www.bleepingcomputer.com/virus-removal/remove-windows-recovery
When I tried to download and run the RKill program I get a message about it not being a Valid Win32 application.
I did the Unhide and it worked, now I have my desktop Icons back and I can right click on the desktop and can even get to the task manager. However I still have (empty) in all my Items in Start|All Programs| except the ones I have installed since like the newer version of Malwarebytes and Spybot S&D.
After fixing the above I did a Spybot S&D also and it found another version of the FakeAlert|grb so I then did a search on that and found the stinger from MCaffee and downloaded that and run it. Here is the log for that:
McAfee® Labs Stinger Version 10.1.0.1629 built on May 27 2011
Copyright © 2011 McAfee, Inc. All Rights Reserved.
Virus data file v1000.0000 created on May 27 2011.
Ready to scan for 2422 viruses, trojans and variants.
Scan initiated on Tue Jun 07 12:32:44 2011
C:\Documents and Settings\All Users\Application Data\16441124
Found the FakeAlert!grb trojan !!!
C:\Documents and Settings\All Users\Application Data\16441124 is infected with the FakeAlert!grb virus !!!
C:\Documents and Settings\All Users\Application Data\16441124 has been deleted.
C:\Documents and Settings\All Users\Application Data\~16441124
Found the FakeAlert!grb trojan !!!
C:\Documents and Settings\All Users\Application Data\~16441124 is infected with the FakeAlert!grb virus !!!
C:\Documents and Settings\All Users\Application Data\~16441124 has been deleted.
C:\Documents and Settings\All Users\Application Data\~16441124r
Found the FakeAlert!grb trojan !!!
C:\Documents and Settings\All Users\Application Data\~16441124r is infected with the FakeAlert!grb virus !!!
C:\Documents and Settings\All Users\Application Data\~16441124r has been deleted.
C:\WINDOWS\Downloaded Program Files\FP_AX_CAB_INSTALLER.exe
Found the FakeAlert!fakealert-REP trojan !!!
C:\WINDOWS\Downloaded Program Files\FP_AX_CAB_INSTALLER.exe is infected with the FakeAlert!fakealert-REP virus !!!
C:\WINDOWS\Downloaded Program Files\FP_AX_CAB_INSTALLER.exe has been deleted.
Number of clean files: 314840
Number of infected files: 4
Number of files cleaned: 4
End of Log.
I have Symantec EndPoint Protection for the Antivirus, and I also have Watchgaurd Firebox for my Firewall along with my cisco 2811.
Any thoughts on anything else I need or could do to recover anything in the Start|All Programs Items? or to make sure that all good and back to normal.
This post has been edited by hamluis: 07 June 2011 - 03:50 PM
Reason for edit: No logs, moved from MRL to AII.

Help
This topic is locked


Back to top











