Hi, having some issues with my laptop this morning, avast is going crazy with blocking errors and I’m having trouble trying to get rid of the infection that has latched onto my machine. Boot scanning does nothing; while it sees the viruses it can’t do anything with them due to a “Bad Image” error. Here is the log provided by MBAM, and the other logs are attached. Any assistance will be appreciated, as the blocked spam while assuring is driving me a tad insane.
Malwarebytes Anti-Malware 1.62.0.1300
www.malwarebytes.org
Database version: v2012.07.12.05
Windows Vista Service Pack 2 x86 NTFS
Internet Explorer 9.0.8112.16421
CrAzY :: JW-LAPTOP [administrator]
12/07/2012 11:47:42
mbam-log-2012-07-12 (11-47-42).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 205518
Time elapsed: 9 minute(s), 32 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 1
HKCU\SOFTWARE\CLASSES\CLSID{42AEDC87-2188-41FD-B9A3-0C966FEABEC1}\INPROCSERVER32 (Trojan.Zaccess) → Quarantined and deleted successfully.
Registry Values Detected: 1
HKCU\SOFTWARE\CLASSES\CLSID{42aedc87-2188-41fd-b9a3-0c966feabec1}\InprocServer32| (Trojan.Zaccess) → Data: C:\Users\CrAzY\AppData\Local{32967460-b40a-4a54-56b2-794bcc02e45c}\n. → Quarantined and deleted successfully.
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 9
C:\Windows\assembly\GAC\Desktop.ini (Trojan.0access) → Delete on reboot.
C:\Windows\Installer{32967460-b40a-4a54-56b2-794bcc02e45c}\U\00000004.@ (Rootkit.0Access) → Quarantined and deleted successfully.
C:\Windows\Installer{32967460-b40a-4a54-56b2-794bcc02e45c}\U\00000008.@ (Trojan.Dropper.BCMiner) → Quarantined and deleted successfully.
C:\Windows\Installer{32967460-b40a-4a54-56b2-794bcc02e45c}\U\trz2FAE.tmp (Rootkit.0Access) → Quarantined and deleted successfully.
C:\Windows\Installer{32967460-b40a-4a54-56b2-794bcc02e45c}\U\trz3A5A.tmp (Trojan.Sirefef) → Quarantined and deleted successfully.
C:\Windows\Installer{32967460-b40a-4a54-56b2-794bcc02e45c}\U\trz4637.tmp (Rootkit.0Access) → Quarantined and deleted successfully.
C:\Windows\Installer{32967460-b40a-4a54-56b2-794bcc02e45c}\U\trz4DB4.tmp (Trojan.Sirefef) → Quarantined and deleted successfully.
C:\Windows\Installer{32967460-b40a-4a54-56b2-794bcc02e45c}\U\trz9C01.tmp (Rootkit.0Access) → Quarantined and deleted successfully.
C:\Windows\Installer{32967460-b40a-4a54-56b2-794bcc02e45c}\U\trzA71D.tmp (Trojan.Sirefef) → Quarantined and deleted successfully.
(end)