Articles

Replicating virus

January 23, 2010 at 10:37:40
Specs: Windows 7

So I have this virus. It doesn't really do much
except start upon log in, and I think it keylogs
me, because I found a file called
xxxyyyzzz.dat that contains my emails and
passwords for Live Messenger.

Log from MBAM:
Malwarebytes' Anti-Malware 1.44
Database version: 3289
Windows 6.1.7600
Internet Explorer 8.0.7600.16385

1/22/2010 10:35:50 PM
mbam-log-2010-01-22 (22-35-50).txt

Scan type: Quick Scan
Objects scanned: 96397
Time elapsed: 3 minute(s), 11 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 4

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Micro
soft\Active Setup\Installed
Components\{iel5a414-71e2-a06e-4h52-
f1syuoi5o1rw} (Generic.Bot.H) -> Quarantined
and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Program Files
(x86)\SNdebugger\SNdebugger.exe
(Generic.Bot.H) -> Quarantined and deleted
successfully.
C:\Users\Jacob\AppData\Roaming\logs.dat
(Bifrose.Trace) -> Quarantined and deleted
successfully.
C:\Users\Jacob\AppData\Local\Temp\UuU.uUu

(Malware.Trace) -> Quarantined and deleted
successfully.
C:\Users\Jacob\AppData\Local\Temp\XxX.xXx
(Malware.Trace) -> Quarantined and deleted
successfully.


See More: Replicating virus

Report •


#1
January 24, 2010 at 08:19:53

Try Trojan remover and unhackme and run them untill the infections are gone.
Use the unhackme beginners guide and just follow the instructions carefully, that should remove the keylogger and any other rootkits that may be embedded on the PC.

Some HELP in posting on Computing.net plus free progs and instructions Cheers


Report •
Related Solutions


Ask Question