Hi,
I have had several warnings from avast advising that suspected malware has been found, and others warning my memory may have been infected, I re-booted and ran a full scan, all infected files found were put in the chest.
After still having problems with warnings (rootkits found) and infected files I followed the advice on other posts and installed Malwarebytes’ Anti-Malware, performed a quick scan, and removed all files/folders shown in the results. Restarted and am now posting the log (below).
I’d be grateful if somone could advise on what to do next to clean up my computer. I’m still getting messages that Rootkits have been found as I’m posting this, and don’t know what to do!
Thanks very much
Malwarebytes’ Anti-Malware 1.44
Database version: 3510
Windows 5.1.2600 Service Pack 2
Internet Explorer 6.0.2900.2180
10/03/2010 20:28:12
mbam-log-2010-03-10 (20-28-12).txt
Scan type: Quick Scan
Objects scanned: 139468
Time elapsed: 30 minute(s), 48 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 28
Registry Values Infected: 1
Registry Data Items Infected: 2
Folders Infected: 16
Files Infected: 9
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CLASSES_ROOT\seekmo.desktopflash (Adware.Seekmo) → Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\seekmo.desktopflash.1 (Adware.Seekmo) → Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\seekmoax.clientdetector (Adware.Seekmo) → Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\seekmoax.clientdetector.1 (Adware.Seekmo) → Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\seekmoax.userprofiles (Adware.Seekmo) → Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\seekmoax.userprofiles.1 (Adware.Seekmo) → Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface{bd5258af-20ae-4bd3-b748-b2851aca7335} (Adware.Seekmo) → Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID{4a40e8fc-c7e4-4f57-9fa4-85dd77402897} (Adware.Seekmo) → Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID{2b96d5cc-c5b5-49a5-a69d-cc0a30f9028c} (Adware.Minibug) → Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID{1f158a1e-a687-4a11-9679-b3ac64b86a1c} (Adware.Seekmo) → Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID{914a8f99-38e4-47ec-b875-2b0653516030} (Adware.Seekmo) → Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID{e313f5dc-cfe7-4568-84a4-c76653547571} (Adware.Seekmo) → Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib{995e885e-3ff5-4f66-a107-8bfb3a0f8f12} (Adware.Seekmo) → Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib{fbb40fdf-b715-4342-ab82-244ecc66e979} (Adware.Seekmo) → Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Installer\Features\9ee2330ae5f4470cac801baac83818c9 (Adware.Zango) → Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Installer\Products\568267acfc5644dab06f058006ddbae3 (Adware.Zango) → Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy{914a8f99-38e4-47ec-b875-2b0653516030} (Adware.Seekmo) → Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved{1f158a1e-a687-4a11-9679-b3ac64b86a1c} (Adware.Seekmo) → Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved{914a8f99-38e4-47ec-b875-2b0653516030} (Adware.Seekmo) → Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved{e313f5dc-cfe7-4568-84a4-c76653547571} (Adware.Seekmo) → Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\seekmo.desktopflash (Adware.Seekmo) → Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\seekmo.desktopflash.1 (Adware.Seekmo) → Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\seekmoax.clientdetector (Adware.Seekmo) → Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\seekmoax.clientdetector.1 (Adware.Seekmo) → Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\seekmoax.userprofiles (Adware.Seekmo) → Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\seekmoax.userprofiles.1 (Adware.Seekmo) → Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\seekmo (Adware.Seekmo) → Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\seekmosa (Adware.Seekmo) → Quarantined and deleted successfully.
Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\ShellBrowser{07aa283a-43d7-4cbe-a064-32a21112d94d} (Adware.Zango) → Quarantined and deleted successfully.
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) → Bad: (1) Good: (0) → Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) → Bad: (1) Good: (0) → Quarantined and deleted successfully.
Folders Infected:
C:\Documents and Settings\All Users\Application Data\2ACA5CC3-0F83-453D-A079-1076FE1A8B65 (Adware.Seekmo) → Quarantined and deleted successfully.
C:\Documents and Settings\mani\Application Data\Seekmo (Trojan.Agent) → Quarantined and deleted successfully.
C:\Documents and Settings\mani\Application Data\Seekmo\IESkins (Trojan.Agent) → Quarantined and deleted successfully.
C:\Documents and Settings\mani\Application Data\Seekmo\v3.0 (Trojan.Agent) → Quarantined and deleted successfully.
C:\Documents and Settings\mani\Application Data\Seekmo\v3.0\Seekmo (Trojan.Agent) → Quarantined and deleted successfully.
C:\Documents and Settings\mani\Application Data\Seekmo\v3.0\Seekmo\static (Trojan.Agent) → Quarantined and deleted successfully.
C:\Documents and Settings\mani\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad (Trojan.Agent) → Quarantined and deleted successfully.
C:\Documents and Settings\mani\Application Data\Seekmo\v3.0\Seekmo\static\1 (Trojan.Agent) → Quarantined and deleted successfully.
C:\Documents and Settings\mani\Application Data\Seekmo\v3.0\Seekmo\static\2 (Trojan.Agent) → Quarantined and deleted successfully.
C:\Documents and Settings\mani\Application Data\Seekmo\v3.0\Seekmo\dynamic (Trojan.Agent) → Quarantined and deleted successfully.
C:\Documents and Settings\mani\Application Data\Seekmo\v3.0\HostOL (Trojan.Agent) → Quarantined and deleted successfully.
C:\Documents and Settings\mani\Application Data\Seekmo\v3.0\HostOL\dynamic (Trojan.Agent) → Quarantined and deleted successfully.
C:\Documents and Settings\mani\Application Data\Seekmo\v3.0\HostOI (Trojan.Agent) → Quarantined and deleted successfully.
C:\Documents and Settings\mani\Application Data\Seekmo\v3.0\HostOI\dynamic (Trojan.Agent) → Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\SeekmoSA (Adware.Seekmo) → Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Start Menu\Programs\Seekmo (Adware.Seekmo) → Quarantined and deleted successfully.
Files Infected:
C:\Documents and Settings\All Users\Application Data\SeekmoSA\SeekmoSAAbout.mht (Adware.Seekmo) → Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\SeekmoSA\SeekmoSAEULA.mht (Adware.Seekmo) → Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\SeekmoSA\SeekmoSA.dat (Adware.Seekmo) → Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\SeekmoSA\SeekmoSAau.dat (Adware.Seekmo) → Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\SeekmoSA\SeekmoSA_kyf.dat (Adware.Seekmo) → Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Start Menu\Programs\Seekmo\Reset Cursor.lnk (Adware.Seekmo) → Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Start Menu\Programs\Seekmo\Seekmo Customer Support Center.lnk (Adware.Seekmo) → Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Start Menu\Programs\Seekmo\Seekmo Uninstall Instructions.lnk (Adware.Seekmo) → Quarantined and deleted successfully.
C:\Documents and Settings\mani\Application Data\avdrn.dat (Malware.Trace) → Quarantined and deleted successfully.