basically this how it goes:
i realised i have loads of viruses,
downloaded avast
did some scans and deleted/chested all files.
but! some which i dont remember their name as avast shortens it keep not getting deleted, and many files are directed at/infected my win32:malware-gen. i saw many people have the problem that they cant delete it and this is really depressing…
i saw many many many threads about this, and i followed one which told me to download malwarebytes, and scan. i did and it detected some files that avast has not detected…
it said it could not delete some of them and here is the log (people said to post the log to see whats in it or something):
Objects scanned: 179421 Time elapsed: 17 minute(s), 6 second(s)Memory Processes Infected: 0
Memory Modules Infected: 1
Registry Keys Infected: 2
Registry Values Infected: 6
Registry Data Items Infected: 2
Folders Infected: 1
Files Infected: 6Memory Processes Infected:
(No malicious items detected)Memory Modules Infected:
c:\WINDOWS\uluyoyulid.dll (Trojan.Hiloti) → Delete on reboot.Registry Keys Infected:
HKEY_CLASSES_ROOT\CLSID{b1d77eea-6c3e-ce81-389f-ec99fc48ec8c} (Trojan.Hiloti) → Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects{B1D77EEA-6C3E-CE81-389F-EC99FC48EC8C} (Trojan.Hiloti) → Quarantined and deleted successfully.Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Kxureneqehexopa (Trojan.Hiloti) → Value: Kxureneqehexopa → Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\New Windows\Allow\host-domain-lookup.com (Malware.Trace) → Value: host-domain-lookup.com → Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\New Windows\Allow\www.host-domain-lookup.com (Malware.Trace) → Value: www.host-domain-lookup.com → Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\New Windows\Allow\mysearchnow.com (Malware.Trace) → Value: mysearchnow.com → Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\New Windows\Allow\www.mysearchnow.com (Malware.Trace) → Value: www.mysearchnow.com → Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\2B5BEEEC4E692BCD (Trojan.SpyEyes) → Value: 2B5BEEEC4E692BCD → Quarantined and deleted successfully.Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (PUM.Disabled.SecurityCenter) → Bad: (1) Good: (0) → Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (PUM.Disabled.SecurityCenter) → Bad: (1) Good: (0) → Quarantined and deleted successfully.Folders Infected:
c:\winntse.bin (Trojan.SpyEyes) → Quarantined and deleted successfully.Files Infected:
c:\WINDOWS\uluyoyulid.dll (Trojan.Hiloti) → Delete on reboot.
c:\documents and settings\re’em\local settings\temporary internet files\content.ie5\n068ymcz\bg_altcup_brightvale[1].gif (Extension.Mismatch) → Quarantined and deleted successfully.
c:\documents and settings\re’em\local settings\temporary internet files\content.ie5\n068ymcz\bg_altcup_darigan[1].gif (Extension.Mismatch) → Quarantined and deleted successfully.
c:\documents and settings\re’em\local settings\temporary internet files\content.ie5\n068ymcz\bg_dd_underwaterblur[1].gif (Extension.Mismatch) → Quarantined and deleted successfully.
c:\documents and settings\re’em\local settings\temporary internet files\content.ie5\n068ymcz\bg_greyday[1].gif (Extension.Mismatch) → Quarantined and deleted successfully.
c:\winntse.bin\config.bin (Trojan.SpyEyes) → Quarantined and deleted successfully.
i have experienced some problems similar to keylogging … and when i click on links on wikipedia it sometimes redirects me to other random websites… PLEASE HELP ME THIS IS GETTING UNBEARABLE…
and i dont want a keylogger to get all my personal details…
there have also been files that were suspected to be infected by physical drive or something/MRB.
and the windows debugger has been popping up continuously for the last few days, i dont know whats going on…
ALL help appreciated.
thanks in advance.