I do have some of my shortcuts on the start bar, but all my recent programs are cleared and my files are NOT hidden. I can access them because I still have shortcuts on my desktop to certain folders and they are visible. As soon as I realized I had a problem (the System Check Dialog box appeared) I shut the computer down and ran in safe mode.
I installed Rkill ran as System Administrator. This is what I received:
This log file is located at C:\rkill.log.
Please post this only if requested to by the person helping you.
Otherwise you can close this log when you wish.
Rkill was run on 01/25/2012 at 22:28:37.
Operating System: Windows 7 Professional
Processes terminated by Rkill or while it was running:
Rkill completed on 01/25/2012 at 22:29:52.
Then I ran MBytes. I already had it on my computer and I am able to update to the current database. I have run it several times. Each time I am in safe mode and also I run rKill before each scan.
Here is the first log:
Malwarebytes Anti-Malware 1.60.0.1800
www.malwarebytes.org
Database version: v2012.01.25.04
Windows 7 Service Pack 1 x64 NTFS (Safe Mode/Networking)
Internet Explorer 8.0.7601.17514
Xuan XPS :: XUANXPS-PC [administrator]
1/25/2012 12:36:11 PM
mbam-log-2012-01-25 (12-36-11).txt
Scan type: Full scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 521370
Time elapsed: 1 hour(s), 32 minute(s), 10 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 3
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced|Start_ShowMyComputer (PUM.Hijack.StartMenu) -> Bad: (0) Good: (1) -> Quarantined and repaired successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced|Start_ShowSearch (PUM.Hijack.StartMenu) -> Bad: (0) Good: (1) -> Quarantined and repaired successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System|DisableTaskMgr (PUM.Hijack.TaskManager) -> Bad: (1) Good: (0) -> Quarantined and repaired successfully.
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
(end)
I removed the virus and deleted the items from quarantine. Then when I restarted the computer the System Check icon was still on the desktop. Then System Check restarted (the Dialog Box appeared). I restarted the computer and ran rKill again and Malware Bytes, all in safe mode. This is the 2nd Log from the Malware Bytes scan:
Malwarebytes Anti-Malware 1.60.0.1800
www.malwarebytes.org
Database version: v2012.01.25.04
Windows 7 Service Pack 1 x64 NTFS (Safe Mode)
Internet Explorer 8.0.7601.17514
Xuan XPS :: XUANXPS-PC [administrator]
1/25/2012 3:17:05 PM
mbam-log-2012-01-25 (15-17-05).txt
Scan type: Full scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 517816
Time elapsed: 1 hour(s), 31 minute(s), 34 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 2
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced|Start_ShowMyComputer (PUM.Hijack.StartMenu) -> Bad: (0) Good: (1) -> Quarantined and repaired successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced|Start_ShowSearch (PUM.Hijack.StartMenu) -> Bad: (0) Good: (1) -> Quarantined and repaired successfully.
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
(end)
Then I quarantined the items and deleted them from quarantine. I restarted the computer again immediately in safe mode to run a MBytes scan to make sure it was deleted. I received this log:
Malwarebytes Anti-Malware 1.60.0.1800
www.malwarebytes.org
Database version: v2012.01.25.06
Windows 7 Service Pack 1 x64 NTFS (Safe Mode/Networking)
Internet Explorer 8.0.7601.17514
Xuan XPS :: XUANXPS-PC [administrator]
1/25/2012 6:40:48 PM
mbam-log-2012-01-25 (18-40-48).txt
Scan type: Full scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 518504
Time elapsed: 1 hour(s), 34 minute(s), 59 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
(end)
Now that there was a clean scan, I restarted computer as normal and then System Check started up again! I am about to run another MBytes scan, but would greatly appreciate any advice or help on the problem. Thanks so much

Help
This topic is locked

Back to top
















