lilbit13007
New Member
Hello. This is my first time needing help from a computerforum, and I would greatly appreciate any advice. My DELL is doing the same thing as the 03-22-2011, 11:29 AM post. Please could someone try to help me get this worm/trojan/mal-ware... off the computer?
I was able to run mal-ware bytes and rkill, but unsuccessful in running HijackThis.
The following are my 3 mal-ware bytes logs (I ran it twice, both times without restarting) (although as soon as I noticed something was awry I did shut down then turn on my computer... haven't turned it off since, not even to go into safe mode) and 1 rkill log.
Mal-ware bytes log 1st run -
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org
Database version: 6627
Windows 6.0.6002 Service Pack 2
Internet Explorer 8.0.6001.19048
5/24/2011 11:40:51 PM
mbam-log-2011-05-24 (23-40-51).txt
Scan type: Quick scan
Objects scanned: 148713
Time elapsed: 10 minute(s), 54 second(s)
Memory Processes Infected: 1
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 2
Memory Processes Infected:
c:\programdata\33152760.exe (Trojan.Agent) -> 2476 -> Unloaded process successfully.
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
c:\Windows\System32\drivers\117A0FC.sys (Rootkit.TDSS) -> Quarantined and deleted successfully.
c:\programdata\33152760.exe (Trojan.Agent) -> Quarantined and deleted successfully.
Mal-Ware Bytes 2nd run log -
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org
Database version: 6670
Windows 6.0.6002 Service Pack 2
Internet Explorer 8.0.6001.19048
5/24/2011 11:59:36 PM
mbam-log-2011-05-24 (23-59-36).txt
Scan type: Quick scan
Objects scanned: 149260
Time elapsed: 7 minute(s), 33 second(s)
Memory Processes Infected: 1
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 2
Memory Processes Infected:
c:\programdata\yimjvskpkyoa.exe (Trojan.FakeAlert) -> 2064 -> Unloaded process successfully.
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\yiMjvSkpKyOa (Trojan.FakeAlert) -> Value: yiMjvSkpKyOa -> Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
c:\programdata\yimjvskpkyoa.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\Users\User\AppData\Local\Temp\tmpA002.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully.
Mal-Ware Bytes 3rd log -
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org
Database version: 6670
Windows 6.0.6002 Service Pack 2
Internet Explorer 8.0.6001.19048
5/25/2011 12:03:48 AM
mbam-log-2011-05-25 (00-03-48).txt
Scan type: Quick scan
Objects scanned: 149452
Time elapsed: 3 minute(s), 59 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
RKill log -
This log file is located at C:\rkill.log.
Please post this only if requested to by the person helping you.
Otherwise you can close this log when you wish.
Rkill was run on 05/24/2011 at 23:47:15.
Operating System: Windows Vista (TM) Home Premium
Processes terminated by Rkill or while it was running:
C:\ProgramData\yiMjvSkpKyOa.exe
Rkill completed on 05/24/2011 at 23:47:55.
I was able to run mal-ware bytes and rkill, but unsuccessful in running HijackThis.
The following are my 3 mal-ware bytes logs (I ran it twice, both times without restarting) (although as soon as I noticed something was awry I did shut down then turn on my computer... haven't turned it off since, not even to go into safe mode) and 1 rkill log.
Mal-ware bytes log 1st run -
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org
Database version: 6627
Windows 6.0.6002 Service Pack 2
Internet Explorer 8.0.6001.19048
5/24/2011 11:40:51 PM
mbam-log-2011-05-24 (23-40-51).txt
Scan type: Quick scan
Objects scanned: 148713
Time elapsed: 10 minute(s), 54 second(s)
Memory Processes Infected: 1
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 2
Memory Processes Infected:
c:\programdata\33152760.exe (Trojan.Agent) -> 2476 -> Unloaded process successfully.
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
c:\Windows\System32\drivers\117A0FC.sys (Rootkit.TDSS) -> Quarantined and deleted successfully.
c:\programdata\33152760.exe (Trojan.Agent) -> Quarantined and deleted successfully.
Mal-Ware Bytes 2nd run log -
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org
Database version: 6670
Windows 6.0.6002 Service Pack 2
Internet Explorer 8.0.6001.19048
5/24/2011 11:59:36 PM
mbam-log-2011-05-24 (23-59-36).txt
Scan type: Quick scan
Objects scanned: 149260
Time elapsed: 7 minute(s), 33 second(s)
Memory Processes Infected: 1
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 2
Memory Processes Infected:
c:\programdata\yimjvskpkyoa.exe (Trojan.FakeAlert) -> 2064 -> Unloaded process successfully.
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\yiMjvSkpKyOa (Trojan.FakeAlert) -> Value: yiMjvSkpKyOa -> Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
c:\programdata\yimjvskpkyoa.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\Users\User\AppData\Local\Temp\tmpA002.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully.
Mal-Ware Bytes 3rd log -
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org
Database version: 6670
Windows 6.0.6002 Service Pack 2
Internet Explorer 8.0.6001.19048
5/25/2011 12:03:48 AM
mbam-log-2011-05-25 (00-03-48).txt
Scan type: Quick scan
Objects scanned: 149452
Time elapsed: 3 minute(s), 59 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
RKill log -
This log file is located at C:\rkill.log.
Please post this only if requested to by the person helping you.
Otherwise you can close this log when you wish.
Rkill was run on 05/24/2011 at 23:47:15.
Operating System: Windows Vista (TM) Home Premium
Processes terminated by Rkill or while it was running:
C:\ProgramData\yiMjvSkpKyOa.exe
Rkill completed on 05/24/2011 at 23:47:55.