Process 2888 [mbam.exe] Memory Block ...Threat:Win32:Win32:Tedroo-D[Trj] Ahhh:-

Greetings Again !

Thanks To All Of You That Helped Me With The RootKit Problem…Since Then Reinstalled Windows Vista 64 Bit H/Premium ( Formatted The Drive While Doing So) Then Did An Upgrade To Win 7 64 Bit H/Premium …

Sooooooooo I Just Ran A Custom Scan And Attached A Screenshot Of The Report…
Listing All These …??? Am I In Serious Trouble ??

Process 2888[mbam.exe] memory block 0x000000005470000, Block Size Is 4194304 Threat:Win32:Win32:Tedroo-D[Trj]

Same With These But Different Hex Addresses…
Threat:Win32:Jifas-ED[Trj]
Threat:Win32:FakeAlert-NT[Trj]
Threat:Win32:FakeAlert-NF[Trj]
Threat:Win32:FakeAlert-KG[Trj]
Threat:Win32:AutoRun-BHW[Wrm]
Threat:Win32:Agent-QC[Trj]
Threat:Win32:Agent-AIXG[Trj]
(Please See Screenshot)

Thank You In Advance, You Have ALL Been Great Helping Me !!
Take Care,
Blessings,
Wild Wizard

Sorry If This Is Posted Twice, I cannot See The Same Post, But It Had No Attachment, Too Large…This One Does

Will get our qualified malware removal expert essexboy to this topic soon…

Please follow this guide and post logs here on next reply.

http://forum.avast.com/index.php?topic=53253.0

Essexboy notified…

Thanks A Lot ! I Really Appreciate Your Help !

Take Care,
Blessings,
Wild Wizard

@wildwizzard
Please follow this guide and post logs here on next reply.

http://forum.avast.com/index.php?topic=53253.0

Thank You !
Blessings,
Wild Wizard

attach AswMBR,rouguekiller,Malwarebytes logs also…

Sorry But Both Files Would Not Fit They Are 207KB Together Sorry For Posting Them Seperatly…

Thank You !

Blessings,
Wild Wizard

attach aswmbr and rouguekiller logs ;D

Ok Here They Are…

Thanks Again Sooooo Much !
Best Wishes,
Blessings
Wild Wizard
Have A Nice Afternoon And Nice Day True Indian !

@ wildwizard

  • Detections in Memory:
    My guess is that you are doing a Custom scan in which you have elected to scan Memory and that all these detections are in memory or are listings of files that can’t be scanned. Since they aren’t physical files they can’t be moved to the chest, deleted, etc. so there is no action that can be taken, hence the Apply button being greyed out.

The detections in memory are frequently other security applications loading unencrypted virus signatures into memory. Having set off a scan of memory by an antivirus application looking for virus signatures, don’t be too surprised if it finds some in memory.

@ true indian
There is no need to contact essexboy as your problem is running the custom scan and scanning memory.

Time to stop jumping in with both feet and offering advice when you have no idea what the problem is. All you have achieved is to scar the pants of this user, had you used the forum search function you would have found many such topics.

Process 2888[mbam.exe] memory block 0x000000005470000, Block Size Is 4194304 Threat:Win32:Win32:Tedroo-D[Trj]
Yup concur it is a memory scan detection MBAM definitions