Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Got rid of virus, but Windows Security won't let Explorer run


  • Please log in to reply
No replies to this topic

#1 laprincessa

laprincessa

  • Members
  • 1 posts
  • OFFLINE
  •  
  • Local time:09:13 AM

Posted 29 January 2010 - 12:02 PM

Yesterday Norton 2010 let fakealert trojan in. I downloaded mbam to a thumb drive with another computer and got rid of it but now Windows Security says my Norton is out of date and won't let Explorer open (except for one window of the Norton site) and only downloads the text in Outlook Express. (I'm writing this on Firefox.) It doesn't help to click I'll self-monitor virus protection. I'm running Windows XP.

Here's the mbam report.

Malwarebytes' Anti-Malware 1.44
Database version: 3510
Windows 5.1.2600 Service Pack 2 (Safe Mode)
Internet Explorer 7.0.5730.13

1/28/2010 5:54:21 PM
mbam-log-2010-01-28 (17-54-21).txt

Scan type: Full Scan (C:\|)
Objects scanned: 198415
Time elapsed: 34 minute(s), 59 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 2
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\AvScan (Trojan.FakeAlert) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\wgpqxake (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\wgpqxake (Trojan.FakeAlert) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Documents and Settings\Administrator\Local Settings\Application Data\prcgit\trwisysguard.

Thanks.

Edited by laprincessa, 29 January 2010 - 12:18 PM.


BC AdBot (Login to Remove)

 





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users