Please check this link i downloaded a .EXE file and as soon as i opened it , it was disappeared and avast never caught it or warned
Please remove the download link. I have sendt sample to avast!
always test file(s) you download at VirusTotal before you run them. If you run that file, you have now installed malware on your PC
Serial.IDM_5.19_Build_4.45303.exe - 15/43
http://www.virustotal.com/file-scan/report.html?id=a6acae9eb444ad1ecbf0d1f077b57f47673581dba456832ccb75d8ad429c7314-1288766451
Malwarebytes detect it as Trojan.Downloader so you can use it to remove the infection
Malwarebytes Anti-Malware 1.46 http://filehippo.com/download_malwarebytes_anti_malware/
always run update before you scan so you have the latest database
click on the remove selected button to quarantine anything found
please post the scan log here
Thank you very much for your co-operation and here is the log
Malwarebytes’ Anti-Malware 1.46
www.malwarebytes.org
Database version: 5037
Windows 6.1.7600
Internet Explorer 8.0.7600.16385
04/11/10 12:55:58 Õ
mbam-log-2010-11-04 (00-55-58).txt
Scan type: Full scan (C:|D:|E:|)
Objects scanned: 327564
Time elapsed: 1 hour(s), 19 minute(s), 10 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 1
Registry Keys Infected: 4
Registry Values Infected: 2
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 10
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
C:\Windows\System32\sshnas21.dll (Trojan.Downloader) → No action taken.
Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\C8H1KKCTZV (Trojan.FakeAlert) → No action taken.
HKEY_CURRENT_USER\SOFTWARE\U36VRSFLG6 (Trojan.FakeAlert) → No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Handle (Malware.Trace) → No action taken.
HKEY_CURRENT_USER\SOFTWARE\XML (Trojan.FakeAlert) → No action taken.
Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\metropolis (Trojan.Downloader) → No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\u36vrsflg6 (Trojan.FakeAlert) → No action taken.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
C:\Windows\System32\sshnas21.dll (Trojan.Downloader) → No action taken.
C:\Users\T\AppData\Local\Mozilla\Firefox\Profiles\k9rr55hr.default\Cache\5AD8DF5Cd01 (Trojan.Downloader) → No action taken.
C:\Users\T\AppData\Local\Mozilla\Firefox\Profiles\k9rr55hr.default\Cache\D9A73AC9d01 (Trojan.Downloader) → No action taken.
C:\Users\T\AppData\Local\Temp\Gxf.exe (Trojan.Downloader) → No action taken.
C:\Users\T\AppData\Local\Temp\Gxg.exe (Trojan.Downloader) → No action taken.
C:\Users\T\AppData\Local\Temp\wz2a3b\Internet.Download.Manager.v5.17.WinALL.Incl.Keygen.and.Patch-BRD\Patch\Patch.exe (Trojan.Bumat) → No action taken.
C:\Users\T\AppData\Local\Temp\wz3006\Internet Download Manager 5.17\Patch\Patch 5.xx (2008-12-06).exe (Trojan.Agent) → No action taken.
C:\Windows\Gqezoa.exe (Trojan.Downloader) → No action taken.
D:\ÊÍÑíÑ\ÇáãÔÊÇÞæä Çáì ÇáÌäå\llll\Internet.Download.Manager.v5.18.Build.5\Patch 5.xx.exe (Trojan.Agent) → No action taken.
C:\Windows\Tasks{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job (Trojan.Downloader) → No action taken.
your log say " NO ACTION TAKEN " did you click the remove selected button after the scan ?
if not scan again and do, so the infection is quarantined…
have this solved your problem ?
Yes i didnt yet confirm the removal am aware to remove anything maybe if u can tell me which to delete or delete all that would be great
Thanks
let Malwarebytes quarantine everything.
it will stay in MBAM quarantine so you can restor if somethings goes wrong. Something that is very rare with MBAM
after 30 days you delete it from quarantine
OBS: there have been updates since you scanned so remeber to update before you scan again…
Pretty Great … Lots of Thank
Malwarebytes’ Anti-Malware 1.46
www.malwarebytes.org
Database version: 5037
Windows 6.1.7600
Internet Explorer 8.0.7600.16385
04/11/10 01:47:49 Õ
mbam-log-2010-11-04 (01-47-49).txt
Scan type: Full scan (C:|D:|E:|)
Objects scanned: 327564
Time elapsed: 1 hour(s), 19 minute(s), 10 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 1
Registry Keys Infected: 4
Registry Values Infected: 2
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 10
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
C:\Windows\System32\sshnas21.dll (Trojan.Downloader) → Delete on reboot.
Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Handle (Malware.Trace) → Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\XML (Trojan.FakeAlert) → Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\U36VRSFLG6 (Trojan.FakeAlert) → Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\C8H1KKCTZV (Trojan.FakeAlert) → Quarantined and deleted successfully.
Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\metropolis (Trojan.Downloader) → Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\u36vrsflg6 (Trojan.FakeAlert) → Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
C:\Users\T\AppData\Local\Temp\wz3006\Internet Download Manager 5.17\Patch\Patch 5.xx (2008-12-06).exe (Trojan.Agent) → Quarantined and deleted successfully.
D:\ÊÍÑíÑ\ÇáãÔÊÇÞæä Çáì ÇáÌäå\llll\Internet.Download.Manager.v5.18.Build.5\Patch 5.xx.exe (Trojan.Agent) → Quarantined and deleted successfully.
C:\Users\T\AppData\Local\Temp\wz2a3b\Internet.Download.Manager.v5.17.WinALL.Incl.Keygen.and.Patch-BRD\Patch\Patch.exe (Trojan.Bumat) → Quarantined and deleted successfully.
C:\Windows\System32\sshnas21.dll (Trojan.Downloader) → Delete on reboot.
C:\Users\T\AppData\Local\Temp\Gxf.exe (Trojan.Downloader) → Quarantined and deleted successfully.
C:\Users\T\AppData\Local\Mozilla\Firefox\Profiles\k9rr55hr.default\Cache\5AD8DF5Cd01 (Trojan.Downloader) → Quarantined and deleted successfully.
C:\Users\T\AppData\Local\Mozilla\Firefox\Profiles\k9rr55hr.default\Cache\D9A73AC9d01 (Trojan.Downloader) → Quarantined and deleted successfully.
C:\Windows\Gqezoa.exe (Trojan.Downloader) → Delete on reboot.
C:\Users\T\AppData\Local\Temp\Gxg.exe (Trojan.Downloader) → Quarantined and deleted successfully.
C:\Windows\Tasks{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job (Trojan.Downloader) → Quarantined and deleted successfully.
your welcome…