Hi guys, I have seen a thread that has the same problem as mine right now and johnb35 had helped those in trouble and I hope I can get help with this problem as well.
in the last thread I saw people were asked to download and post the log from the malwarebyte's software and hijackthis. so these are mine:
Malwarebytes' Anti-Malware 1.51.1.1800
www.malwarebytes.org
Database version: 7468
Windows 6.1.7600 (Safe Mode)
Internet Explorer 8.0.7600.16385
8/15/2011 5:44:22 AM
mbam-log-2011-08-15 (05-44-22).txt
Scan type: Quick scan
Objects scanned: 193763
Time elapsed: 4 minute(s), 58 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 12
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A078F691-9C07-4AF2-BF43-35E79EECF8B7} (Adware.Softomate) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\PbXLTBUktOat (Trojan.FakeAlert) -> Value: PbXLTBUktOat -> Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
c:\programdata\pbxltbuktoat.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\programdata\33480440.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\Users\guest.russ-pc\AppData\Local\Temp\0.6787490821956315.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\Users\guest.russ-pc\AppData\Local\Temp\setup4190682400.exe (Rootkit.TDSS) -> Quarantined and deleted successfully.
c:\Users\russ\AppData\Local\Temp\jar_cache5177583152910683363.tmp (VirTool.Obfuscator) -> Quarantined and deleted successfully.
c:\Users\russ\AppData\Local\Temp\tmp9EC8.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\Users\guest.russ-pc\local settings\wmplstas.dll (Trojan.Hiloti) -> Quarantined and deleted successfully.
c:\Users\guest.russ-pc\local settings\application data\wmplstas.dll (Trojan.Hiloti) -> Quarantined and deleted successfully.
c:\Users\guest.russ-pc\AppData\Roaming\Adobe\shed\thr1.chm (Malware.Trace) -> Quarantined and deleted successfully.
c:\Users\guest.russ-pc\AppData\Roaming\Adobe\plugs\mmc140.exe (Trojan.Agent.Gen) -> Quarantined and deleted successfully.
c:\Users\guest.russ-pc\AppData\Roaming\Adobe\plugs\mmc429442422.txt (Trojan.Agent.Gen) -> Quarantined and deleted successfully.
c:\Users\guest.russ-pc\AppData\Roaming\Adobe\plugs\mmc429483310.txt (Trojan.Agent.Gen) -> Quarantined and deleted successfully.
in the last thread I saw people were asked to download and post the log from the malwarebyte's software and hijackthis. so these are mine:
Malwarebytes' Anti-Malware 1.51.1.1800
www.malwarebytes.org
Database version: 7468
Windows 6.1.7600 (Safe Mode)
Internet Explorer 8.0.7600.16385
8/15/2011 5:44:22 AM
mbam-log-2011-08-15 (05-44-22).txt
Scan type: Quick scan
Objects scanned: 193763
Time elapsed: 4 minute(s), 58 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 12
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A078F691-9C07-4AF2-BF43-35E79EECF8B7} (Adware.Softomate) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\PbXLTBUktOat (Trojan.FakeAlert) -> Value: PbXLTBUktOat -> Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
c:\programdata\pbxltbuktoat.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\programdata\33480440.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\Users\guest.russ-pc\AppData\Local\Temp\0.6787490821956315.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\Users\guest.russ-pc\AppData\Local\Temp\setup4190682400.exe (Rootkit.TDSS) -> Quarantined and deleted successfully.
c:\Users\russ\AppData\Local\Temp\jar_cache5177583152910683363.tmp (VirTool.Obfuscator) -> Quarantined and deleted successfully.
c:\Users\russ\AppData\Local\Temp\tmp9EC8.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\Users\guest.russ-pc\local settings\wmplstas.dll (Trojan.Hiloti) -> Quarantined and deleted successfully.
c:\Users\guest.russ-pc\local settings\application data\wmplstas.dll (Trojan.Hiloti) -> Quarantined and deleted successfully.
c:\Users\guest.russ-pc\AppData\Roaming\Adobe\shed\thr1.chm (Malware.Trace) -> Quarantined and deleted successfully.
c:\Users\guest.russ-pc\AppData\Roaming\Adobe\plugs\mmc140.exe (Trojan.Agent.Gen) -> Quarantined and deleted successfully.
c:\Users\guest.russ-pc\AppData\Roaming\Adobe\plugs\mmc429442422.txt (Trojan.Agent.Gen) -> Quarantined and deleted successfully.
c:\Users\guest.russ-pc\AppData\Roaming\Adobe\plugs\mmc429483310.txt (Trojan.Agent.Gen) -> Quarantined and deleted successfully.