Need a geek? Geeks to Go offers free, quality tech support -- in terms anyone can understand. Volunteers are waiting to help, friendly, technology experts who have knowledge to share, and enjoy helping others. Feel free to browse the site as a guest. However, you must log in to reply to existing topics, or to start a new topic of your own. Other benefits of joining include richer forum features, and removal of all advertising. Learn more in our Welcome Guide Infected? Malware and Spyware Cleaning Guide. What are you waiting for? Click here to join for free today!
Security Center Alert [Solved]
sailerman
post Jul 1 2009, 10:00 AM
Post #1


New Member
*
Posts: 2
OS: Windows XP, service pack 3



Hello,

I've been a long time reader and this forum has helped me many times. However, this is the first time I have not been able to remove a virus/malware. So I am posting for some help.

The malware will not allow Malewarebytes to update, nor will it allow superanispyware to update. I am getting false alerts as follows: "Warning: the media system on your computer is corrupt", "system alert: virus.win32.pgcode.ak - click balloon to install antivirus..." etc

Both Malewarebytes and superantispware find issues but upon rebot, the maleware returns.

mbam - Log

Malwarebytes' Anti-Malware 1.38
Database version: 2353
Windows 5.1.2600 Service Pack 3

7/1/2009 11:14:13 AM
mbam-log-2009-07-01 (11-14-13).txt

Scan type: Quick Scan
Objects scanned: 106358
Time elapsed: 3 minute(s), 1 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 2
Registry Keys Infected: 1
Registry Values Infected: 0
Registry Data Items Infected: 1
Folders Infected: 0
Files Infected: 4

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
\\?\globalroot\systemroot\system32\UACmgokkshxtlivjshys.dll (Trojan.TDSS) -> Delete on reboot.
\\?\globalroot\systemroot\system32\UACjjqfrjtiqoqxlxjcb.dll (Trojan.TDSS) -> Delete on reboot.

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\UAC (Rootkit.Trace) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr (Hijack.TaskManager) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
\\?\globalroot\systemroot\system32\UACmgokkshxtlivjshys.dll (Trojan.TDSS) -> Quarantined and deleted successfully.
\\?\globalroot\systemroot\system32\UACjjqfrjtiqoqxlxjcb.dll (Trojan.TDSS) -> Quarantined and deleted successfully.
c:\documents and settings\Super\local settings\temporary internet files\Content.IE5\05CKESMV\load[1].exe (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\uacinit.dll (Trojan.Agent) -> Delete on reboot.


SuperAntiSpyware Log

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 07/01/2009 at 11:39 AM

Application Version : 4.26.1006

Core Rules Database Version : 3961
Trace Rules Database Version: 1902

Scan type : Quick Scan
Total Scan Time : 00:17:39

Memory items scanned : 451
Memory threats detected : 2
Registry items scanned : 539
Registry threats detected : 0
File items scanned : 28476
File threats detected : 2

Rootkit.Agent/Gen-UACFake
\?\GLOBALROOT\C:\WINDOWS\SYSTEM32\UACJJQFRJTIQOQXLXJCB.DLL
\?\GLOBALROOT\C:\WINDOWS\SYSTEM32\UACJJQFRJTIQOQXLXJCB.DLL
\?\GLOBALROOT\C:\WINDOWS\SYSTEM32\UACMGOKKSHXTLIVJSHYS.DLL
\?\GLOBALROOT\C:\WINDOWS\SYSTEM32\UACMGOKKSHXTLIVJSHYS.DLL

Thank you for your time and help,

Sailerman
Go to the top of the page
 
+Quote Post

Posts in this topic


Closed TopicStart new topic
1 User(s) are reading this topic (1 Guests and 0 Anonymous Users)
0 Members:

 

RSS Time is now: 22nd November 2009 - 12:03 AM

Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks mentioned on this page are the property of their respective owners.

© Geeks to Go, Inc. | All Rights Reserved | Privacy Policy | Advertising