Hi,
I’m not sure how I wound up with this virus, but it took control of my computer for a short while with a series of pop-up windows and it hid all files and programs on my computer. I was able to locate a download that helped to restore my computer to normal, or at least it appeared to be. However, when I run the Avast scan it keeps telling me I still have infected files and one of them I cannot move to the chest or remove from my computer. The file is MBR:\.\PHYSICALDRIVE0\Partition2. When I try to move it to the chest, it gives me the following error message: Error: The request is not supported (50). I have followed the steps I found at the following link http://forum.avast.com/index.php?PHPSESSID=3n2bh0aj9s4babirvdv1djf7t1&topic=53253.0, only the download aswMBR.exe does nothing when I double-click on it so I wasn’t able to run that scan. Below, and attached, are the results of my scans…please help!!!:
Malwarebytes Anti-Malware 1.61.0.1400
www.malwarebytes.org
Database version: v2012.07.07.07
Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
hp :: HP-C84EB1F7E3CD [administrator]
7/8/2012 12:20:06 AM
mbam-log-2012-07-08 (00-20-06).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 204608
Time elapsed: 15 minute(s), 51 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 6
HKCR\CLSID\MADOWN (Worm.Magania) → Quarantined and deleted successfully.
HKCU\SOFTWARE\IJKUK66HMN (Trojan.FakeAlert) → Quarantined and deleted successfully.
HKCU\SOFTWARE\NtWqIVLZEWZU (Trojan.FakeAlert) → Quarantined and deleted successfully.
HKCU\SOFTWARE\SMH2B46TDP (Trojan.FakeAlert) → Quarantined and deleted successfully.
HKCU\SOFTWARE\XML (Trojan.FakeAlert) → Quarantined and deleted successfully.
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\ (Hijack.Zones) → Quarantined and deleted successfully.
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL|CheckedValue (PUM.Hijack.System.Hidden) → Bad: (0) Good: (1) → Quarantined and repaired successfully.
Folders Detected: 0
(No malicious items detected)
Files Detected: 1
C:\Documents and Settings\hp\Local Settings\Application Data\yzmaequzru.exe (Trojan.Lameshield) → Quarantined and deleted successfully.