Hey guys. Well I’ve been trying to fix up my cousins computer for a while now and haven’t been able to get past a few hurdles. It started out with some fake anti virus which I cleared, and it also has the redirect virus (when clicking on search result links it redirects to someplace other than where you intended to go!) And I haven’t been able to kick it.
aswMBR BSOD’d on me so I don’t have a log for that, but I attached the dump log. Also AVAST keeps throwing up a blocked attempt by: c:\windows\assembly\tmp\u\800000cb.@ which comes up as Win32:Malware-gen from csrss.exe. It always gets moved to the vault however it never fixes it. I also can’t install the next windows update without me getting stuck in a reboot loop, can get more info on that if you like.
I’ve yet to run a full Avast scan (will do so tomorrow when I get up) but here are the current logs if you can pick anything out of it.
(this is a previous MBAM scan that cleared something before my most recent clean scan)
Malwarebytes’ Anti-Malware 1.51.1.1800
www.malwarebytes.org
Database version: 7035
Windows 6.0.6001 Service Pack 1 (Safe Mode)
Internet Explorer 8.0.6001.19019
9/6/2011 5:01:34 PM
mbam-log-2011-09-06 (17-01-34).txt
Scan type: Quick scan
Objects scanned: 163030
Time elapsed: 2 minute(s), 12 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 1
Files Infected: 1
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CLASSES_ROOT.fsharproj (Trojan.BHO) → Quarantined and deleted successfully.
Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Security Protection (Trojan.FakeAlert) → Value: Security Protection → Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
c:\Users\jessica kufs\AppData\Roaming\Mozilla\extensions{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\textlinks@gamevance.com (Adware.GamesVance) → Quarantined and deleted successfully.
Files Infected:
c:\Users\jessica kufs\AppData\Roaming\defender.exe (Trojan.FakeAlert) → Quarantined and deleted successfully.