system
1
i am having problems with these viruses while i see others are too. help would be greatly appreciated!
here is my Malwarebytes log:
Malwarebytes Anti-Malware (Trial) 1.62.0.1300
www.malwarebytes.org
Database version: v2012.07.13.01
Windows 7 x64 NTFS
Internet Explorer 9.0.8112.16421
alex :: ALEX-PC [administrator]
Protection: Enabled
7/13/2012 1:27:19 AM
mbam-log-2012-07-13 (01-27-19).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 216149
Time elapsed: 4 minute(s), 32 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 2
C:\Windows\Installer{57a22c58-5554-62a7-7cbe-7e74f84b2839}\U\00000008.@ (Trojan.Dropper.BCMiner) → Quarantined and deleted successfully.
C:\Users\alex\AppData\Local\Temp\services.exe.mui (Heuristics.Reserved.Word.Exploit) → Quarantined and deleted successfully.
(end)
welcome to the forum. this needs further investigation of a malware expert.
please follow this guide and attach your logs.
http://forum.avast.com/index.php?topic=53253.0
system
3
aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-07-13 00:46:06
00:46:06.737 OS Version: Windows x64 6.1.7600
00:46:06.737 Number of processors: 2 586 0x602
00:46:06.737 ComputerName: ALEX-PC UserName: alex
00:46:08.656 Initialize success
00:46:13.663 AVAST engine defs: 12071201
00:46:25.644 Disk 0 (boot) \Device\Harddisk0\DR0 → \Device\Ide\IdeDeviceP0T0L0-0
00:46:25.644 Disk 0 Vendor: WDC_WD5000AAKS-00UU3A0 01.03B01 Size: 476940MB BusType: 3
00:46:25.660 Disk 0 MBR read successfully
00:46:25.660 Disk 0 MBR scan
00:46:25.660 Disk 0 Windows 7 default MBR code
00:46:25.660 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 100 MB offset 2048
00:46:25.660 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 476838 MB offset 206848
00:46:25.691 Disk 0 scanning C:\Windows\system32\drivers
00:46:35.488 Service scanning
00:46:49.341 Modules scanning
00:46:49.341 Disk 0 trace - called modules:
00:46:49.356 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys ataport.SYS pciide.sys PCIIDEX.SYS hal.dll atapi.sys
00:46:49.356 1 nt!IofCallDriver → \Device\Harddisk0\DR0[0xfffffa80033db2d0]
00:46:49.871 3 CLASSPNP.SYS[fffff880011d043f] → nt!IofCallDriver → [0xfffffa8002f17520]
00:46:49.871 5 ACPI.sys[fffff88000e56781] → nt!IofCallDriver → \Device\Ide\IdeDeviceP0T0L0-0[0xfffffa8002f2d060]
00:46:50.557 AVAST engine scan C:\Windows
00:46:52.149 AVAST engine scan C:\Windows\system32
00:47:58.378 File: C:\Windows\assembly\GAC_32\Desktop.ini INFECTED Win32:Sirefef-PL [Rtk]
00:47:59.517 File: C:\Windows\assembly\GAC_64\Desktop.ini INFECTED Win32:Sirefef-PL [Rtk]
00:48:35.943 AVAST engine scan C:\Windows\system32\drivers
00:48:42.617 AVAST engine scan C:\Users\alex
00:51:54.567 Disk 0 MBR has been saved successfully to “C:\Users\alex\Documents\MBR.dat”
00:51:54.582 The log file has been saved successfully to “C:\Users\alex\Documents\aswMBR.txt”