Security Center Alert [Solved] |
![]() ![]() |
Security Center Alert [Solved] |
Jul 1 2009, 10:00 AM
Post
#1
|
|
|
New Member ![]() Posts: 2 OS: Windows XP, service pack 3 |
Hello,
I've been a long time reader and this forum has helped me many times. However, this is the first time I have not been able to remove a virus/malware. So I am posting for some help. The malware will not allow Malewarebytes to update, nor will it allow superanispyware to update. I am getting false alerts as follows: "Warning: the media system on your computer is corrupt", "system alert: virus.win32.pgcode.ak - click balloon to install antivirus..." etc Both Malewarebytes and superantispware find issues but upon rebot, the maleware returns. mbam - Log Malwarebytes' Anti-Malware 1.38 Database version: 2353 Windows 5.1.2600 Service Pack 3 7/1/2009 11:14:13 AM mbam-log-2009-07-01 (11-14-13).txt Scan type: Quick Scan Objects scanned: 106358 Time elapsed: 3 minute(s), 1 second(s) Memory Processes Infected: 0 Memory Modules Infected: 2 Registry Keys Infected: 1 Registry Values Infected: 0 Registry Data Items Infected: 1 Folders Infected: 0 Files Infected: 4 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: \\?\globalroot\systemroot\system32\UACmgokkshxtlivjshys.dll (Trojan.TDSS) -> Delete on reboot. \\?\globalroot\systemroot\system32\UACjjqfrjtiqoqxlxjcb.dll (Trojan.TDSS) -> Delete on reboot. Registry Keys Infected: HKEY_LOCAL_MACHINE\SOFTWARE\UAC (Rootkit.Trace) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr (Hijack.TaskManager) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. Folders Infected: (No malicious items detected) Files Infected: \\?\globalroot\systemroot\system32\UACmgokkshxtlivjshys.dll (Trojan.TDSS) -> Quarantined and deleted successfully. \\?\globalroot\systemroot\system32\UACjjqfrjtiqoqxlxjcb.dll (Trojan.TDSS) -> Quarantined and deleted successfully. c:\documents and settings\Super\local settings\temporary internet files\Content.IE5\05CKESMV\load[1].exe (Trojan.Dropper) -> Quarantined and deleted successfully. C:\WINDOWS\system32\uacinit.dll (Trojan.Agent) -> Delete on reboot. SuperAntiSpyware Log SUPERAntiSpyware Scan Log http://www.superantispyware.com Generated 07/01/2009 at 11:39 AM Application Version : 4.26.1006 Core Rules Database Version : 3961 Trace Rules Database Version: 1902 Scan type : Quick Scan Total Scan Time : 00:17:39 Memory items scanned : 451 Memory threats detected : 2 Registry items scanned : 539 Registry threats detected : 0 File items scanned : 28476 File threats detected : 2 Rootkit.Agent/Gen-UACFake \?\GLOBALROOT\C:\WINDOWS\SYSTEM32\UACJJQFRJTIQOQXLXJCB.DLL \?\GLOBALROOT\C:\WINDOWS\SYSTEM32\UACJJQFRJTIQOQXLXJCB.DLL \?\GLOBALROOT\C:\WINDOWS\SYSTEM32\UACMGOKKSHXTLIVJSHYS.DLL \?\GLOBALROOT\C:\WINDOWS\SYSTEM32\UACMGOKKSHXTLIVJSHYS.DLL Thank you for your time and help, Sailerman |
|
|
Jul 1 2009, 11:16 AM
Post
#2
|
|
![]() Trusted Helper Posts: 3,384 From: Sweden OS: Windows XP SP3 |
Hello sailerman !
Welcome to the site! Before we proceed to clean your computer from malware, let's go over some points that will help both me and you, and prevent causing damage to your computer:
Please read my posts completely before following the instructions. It may be easier for you if you copy and paste a post to a new text document or print it for reference later. This is required when you won't have access to Internet. Step 1. ComboFix: Download ComboFix from one of these locations: Link 1 Link 2 Link 3 * IMPORTANT !!! Save ComboFix.exe to your Desktop
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures. ![]() Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message: ![]() Click on Yes, to continue scanning for malware. When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply. Step 2. OTL:
Step 3. Things I would like to see in your reply:
|
|
|
Jul 2 2009, 06:49 AM
Post
#3
|
|
|
New Member ![]() Posts: 2 OS: Windows XP, service pack 3 |
Heir,
Thank you for your timely response. I have "fixed" the issue... I have fixed it so well windows boots to blue screen of death and safe mode just locks up...LOL I "jacked" my drive and hooked it to a laptop, via USB, scanned the drive NAV, it removed several files, some of which I believe were *.sys files. This has rendered me unable to boot into windows. I will try and recover windows but it is not looking so good at this point. You may as well close this thread. If I happen to recover from my "genius" move, I will start a new post. Once again, thank you and all your help, keep up the great work, Sailerman |
|
|
Jul 3 2009, 02:20 PM
Post
#4
|
|
![]() Trusted Helper Posts: 3,384 From: Sweden OS: Windows XP SP3 |
Since this issue appears to be resolved ... this Topic has been closed. Glad we could help.
If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic. |
|
|
![]() ![]() |
Similar Topics
| Topic Title | Replies / Views | Topic Information | |||||
|---|---|---|---|---|---|---|---|
![]() |
10 / 673 | 17th December 2008 - 12:21 AM DazWolf started - last by emeraldnzl |
|||||
![]() |
9 / 313 | 17th February 2009 - 10:28 AM karonally started - last by fenzodahl512 |
|||||
![]() |
12 / 286 | 7th September 2009 - 03:52 PM citricrex started - last by kahdah |
|||||
![]() |
30 / 314 | 3rd November 2009 - 11:31 AM bitterbuck started - last by andrewuk |
|||||
|
Time is now: 8th November 2009 - 02:54 AM |
Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks mentioned on this page are the property of their respective owners.
© Geeks to Go, Inc. | All Rights Reserved | Privacy Policy | Advertising