MALWARE! - Geeks to Go Forums

Jump to content

Log in Register Register Malware removal guide How it works

MALWARE! INFECTED

#1 zoranm

  • Group: Member
  • Posts: 2
  • Joined: 25-January 08

Posted 25 January 2008 - 05:18 PM

Please

C:\Program Files\MalwareAlarm\MalwareAlarm0.ma -> Adware.DrAntispy : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{3BF78311-7D56-4E06-A88E-3AF1E4CAB983}\RP31\A0007115.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{3BF78311-7D56-4E06-A88E-3AF1E4CAB983}\RP31\A0007180.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{3BF78311-7D56-4E06-A88E-3AF1E4CAB983}\RP31\A0007505.EXe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{3BF78311-7D56-4E06-A88E-3AF1E4CAB983}\RP31\A0007506.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\Documents and Settings\Katarina\Local Settings\Temp\removalfile.bat -> Not-A-Virus.Adware.Virtumonde : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{3BF78311-7D56-4E06-A88E-3AF1E4CAB983}\RP31\A0007836.dll -> Not-A-Virus.Adware.Virtumonde : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{3BF78311-7D56-4E06-A88E-3AF1E4CAB983}\RP31\A0007837.dll -> Not-A-Virus.Adware.Virtumonde : Cleaned with backup (quarantined).
C:\Documents and Settings\Katarina\Application Data\setup_en[1].exe -> Not-A-Virus.Downloader.Win32.WinFixer.ba : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{3BF78311-7D56-4E06-A88E-3AF1E4CAB983}\RP31\A0006444.exe -> Not-A-Virus.Downloader.Win32.WinFixer.ba : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{3BF78311-7D56-4E06-A88E-3AF1E4CAB983}\RP31\A0007618.exe -> Not-A-Virus.Downloader.Win32.WinFixer.ba : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{3BF78311-7D56-4E06-A88E-3AF1E4CAB983}\RP31\A0007679.exe -> Not-A-Virus.Downloader.Win32.WinFixer.ba : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{3BF78311-7D56-4E06-A88E-3AF1E4CAB983}\RP31\A0007029.exe -> Not-A-Virus.Downloader.Win32.WinFixer.bt : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{3BF78311-7D56-4E06-A88E-3AF1E4CAB983}\RP31\A0007507.exe -> Not-A-Virus.Downloader.Win32.WinFixer.cv : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{3BF78311-7D56-4E06-A88E-3AF1E4CAB983}\RP25\A0004727.exe -> Trojan.Dialer.yz : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{3BF78311-7D56-4E06-A88E-3AF1E4CAB983}\RP25\A0004809.exe -> Trojan.Dialer.yz : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{3BF78311-7D56-4E06-A88E-3AF1E4CAB983}\RP25\A0004812.exe -> Trojan.Dialer.yz : Cleaned with backup (quarantined).
D:\System Volume Information\_restore{D6A63B2C-73EE-4604-9F4A-21EBB3DFD3FD}\RP199\A0029108.exe -> Trojan.Inject.ks : Cleaned with backup (quarantined).
somebody help, my comp is infected by malware, I don't know what to do

#2 kahdah

  • Group: GeekU Moderator
  • Posts: 15,822
  • Joined: 13-April 06

Posted 25 January 2008 - 05:39 PM

Hello zoranm

Welcome to G2Go. :)
====================
* Click here to download HJTsetup.exe
  • Save HJTsetup.exe to your desktop.
  • Doubleclick on the HJTsetup.exe icon on your desktop.
  • By default it will install to C:\Program Files\Trend Micro\Hijack This.
  • Click on I agree
  • Then Click on the Do a system scan and save a logfile button. It will scan and the log should open in notepad.
  • Click on "Edit > Select All" then click on "Edit > Copy" to copy the entire contents of the log.
  • Come back here to this thread and Paste the log in your next reply.
  • DO NOT have Hijack This fix anything yet. Most of what it finds will be harmless or even required.


#3 kahdah

  • Group: GeekU Moderator
  • Posts: 15,822
  • Joined: 13-April 06

Posted 07 February 2009 - 09:41 AM

Due to lack of feedback, this topic has been closed.

If you need this topic reopened, please contact a staff member with address of this thread. This applies only to the original topic starter. Everyone else please begin a New Topic.

Share this topic: