Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

MyFunCards[1].exe


  • Please log in to reply
No replies to this topic

#1 sr8031

sr8031

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:CA
  • Local time:08:59 AM

Posted 06 November 2010 - 03:33 PM

My operating system is Windows Xp Professionnal. At start up, I am getting a Pop up message "Server Busy"...! This action cannot be completed because the other program is busy. Choose "Switch To" to activate the busy program and correct the problem. When I click on 'switch to" or "retry" buttons, nothing happens plus I can't close the pop up message unless I right click on task bar icon for Norton Internet Security. I googled this problem and someone suggested a malaware scan by Malwarebytes. A quick scan showed 3 infections (2 Broken.Open registry data and 1 file called MyFyncards[1].exe) and I am attaching that log plus a screen capture. I chose to have the infections removed. When I rebooted, the aforementioned "server busy" pop up message appeared again. I did a full scan which produced no further infections.

Am I still inefected? I did visit the website "myfuncards.com" on Wednesday, 11/3/10 and started having aforementioned problem yesterday, Friday, 11/5/10.

Here is the Malwarebytes quick scan log...11/5/2010 10:54:49 PM
mbam-log-2010-11-05 (22-54-49).txt

Scan type: Quick scan
Objects scanned: 163165
Time elapsed: 11 minute(s), 58 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 2
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
HKEY_CLASSES_ROOT\scrfile\shell\open\command\(default) (Broken.OpenCommand) -> Bad: (NOTEPAD.EXE %1) Good: ("%1" /S) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\regfile\shell\open\command\(default) (Broken.OpenCommand) -> Bad: (NOTEPAD.EXE %1) Good: (regedit.exe "%1") -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
H:\Documents and Settings\XXXXX\Local Settings\Temporary Internet Files\Content.IE5\2QV2L5LI\MyFunCards[1].exe (PUP.FunWebProducts) -> Quarantined and deleted successfully.

Edited by Blade Zephon, 07 April 2011 - 03:40 PM.


BC AdBot (Login to Remove)

 





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users