abricru, on 07 February 2012 - 03:40 AM, said:
cryptodan, on 07 February 2012 - 03:10 AM, said:
Can you post the logs and or screenshots of the virus it is detecting?
I only know how to see the results of the latest scan in F-Secure and I aborted the latest scan, so I am scanning again and will post the results when it finishes. Thank you
It just keeps getting worse and worse. Everything takes ten times longer than it usually does. The F-Secure scan completed and said it found nothing, but when I tried to browse I got the same message that it found something in system 32. I read that I should disable system restore to keep it from happening over and over but that has not stopped it. I also got some message about tfun.exe when I tried to reboot. The yellow security shield icon keeps appearing in my systray even though I have automatic updates turned off.
This is what MBAM said a few days ago:
Objects scanned: 208359
Time elapsed: 7 minute(s), 49 second(s)
Memory Processes Detected: 1
C:\WINDOWS\Temp\tue0.5531846137295523.exe (Trojan.FakeMS) -> 652 -> Delete on reboot.
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 3
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|configremote (Trojan.FakeMS) -> Data: C:\Documents and Settings\All Users\configremote.exe -> Quarantined and deleted successfully.
HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|configremote (Trojan.FakeMS) -> Data: C:\Documents and Settings\All Users\configremote.exe -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|dplaysvr (Trojan.QHost.BG) -> Data: %APPDATA%\dplaysvr.exe -> Quarantined and deleted successfully.
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 7
C:\WINDOWS\Temp\tue0.5531846137295523.exe (Trojan.FakeMS) -> Delete on reboot.
C:\Documents and Settings\All Users\configremote.exe (Trojan.FakeMS) -> Quarantined and deleted successfully.
C:\Documents and Settings\Anne\Local Settings\Temp\sxramcowen.exe (Trojan.FakeMS) -> Quarantined and deleted successfully.
C:\WINDOWS\Temp\deviceauto.exe (Trojan.FakeMS) -> Quarantined and deleted successfully.
C:\WINDOWS\Temp\ikixzkz.exe (Trojan.FakeMS) -> Quarantined and deleted successfully.
C:\WINDOWS\Temp\tue0.20171454731763705.exe (Trojan.FakeMS) -> Quarantined and deleted successfully.
C:\WINDOWS\Temp\tue0.8112219785613592.exe (Trojan.FakeMS) -> Quarantined and deleted successfully.
(end)
What should I do?