PDA

View Full Version : Help, I seem to be experiencing a malware problem...



kyotoyoshi
2007-10-06, 01:21
I downloaded spybot which found some spy ware which I had to remove manually due to it being associated with Firefox.

Then, I ran Kaspersky Online, extended version, scanned archives and mail bases. It scanned my computer and found 1 dangerous file and 2 corrupted files (I don't know whether or not they're viruses or just ad ware). I saved the log but I'm not certain the virus scanner I used was able to scan everything (I'm running windows vista which has this insanely annoying user control function which I'm assuming is preventing access to certain files). I also saw some suspicious stuff but I didn't want to delete anything without an expert opinion.

Most of the files look like this (i.e. object is locked, skipped):

C:\Boot\BCD Object is locked skipped
C:\Boot\BCD.LOG Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\EENGINE\EPERSIST.DAT Object is locked skipped
C:\Program Files\InstallShield Installation Information\{1007F41F-7D69-468E-8017-3849A5A973C2}\setup.ilg Object is locked skipped
C:\Program Files\InstallShield Installation Information\{1297C681-92D7-40EF-93BF-03F66EC5105C}\setup.ilg Object is locked skipped
C:\Program Files\InstallShield Installation Information\{17CBC505-D1AE-459D-B445-3D2000A85842}\setup.ilg Object is locked skipped
C:\Program Files\InstallShield Installation Information\{65706020-7B6F-41F2-8047-FC69579E386A}\setup.ilg Object is locked skipped
C:\Program Files\InstallShield Installation Information\{7EB114D8-207F-45AE-BABD-1669715F2630}\setup.ilg Object is locked skipped
C:\Program Files\InstallShield Installation Information\{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}\setup.ilg Object is locked skipped
C:\Program Files\InstallShield Installation Information\{986F64DC-FF15-449D-998F-EE3BCEC6666A}\setup.ilg Object is locked skipped
C:\Program Files\InstallShield Installation Information\{C6FA39A7-26B1-480A-BC74-6D17531AC222}\setup.ilg Object is locked skipped
C:\Program Files\InstallShield Installation Information\{CF5737AF-8550-4546-A69B-0EA9EF5A9B55}\setup.ilg Object is locked skipped
C:\Program Files\InstallShield Installation Information\{D728E945-256D-4477-B377-6BBA693714AC}\setup.ilg Object is locked skipped
C:\Program Files\InstallShield Installation Information\{DAC01CEE-5BAE-42D5-81FC-B687E84E8405}\setup.ilg Object is locked skipped
C:\Program Files\InstallShield Installation Information\{DB71210F-8314-4AE3-B7A7-EBAF85BD30E9}\setup.ilg Object is locked skipped
C:\Program Files\InstallShield Installation Information\{E7E836B8-4BDD-454F-82E6-5FEA17C83AD4}\setup.ilg Object is locked skipped
C:\Program Files\PCDR5\pcd_cpp_gui.p5i Object is locked skipped

Then there are these two objects here which appear to be infected:

C:\Users\J\Documents\Pure Entertainment\Jonelle's Documents\LilBufBuf\DivXPro5GAINBundle.exe/Gain_Trickler.exe Infected: not-a-virus:AdWare.Win32.Gator.3102 skipped
C:\Users\J\Documents\Pure Entertainment\Jonelle's Documents\LilBufBuf\DivXPro5GAINBundle.exe Vise: infected - 1 skipped


What do I do...?

kyotoyoshi
2007-10-06, 01:24
I forgot to post this part:
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Friday, October 05, 2007 3:58:34 PM
Operating System: Microsoft Windows Vista Home Edition, (Build 6000)
Kaspersky Online Scanner version: 5.0.93.1
Kaspersky Anti-Virus database last update: 5/10/2007
Kaspersky Anti-Virus database records: 428024
-------------------------------------------------------------------------------

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
C:\
D:\
E:\

Scan Statistics:
Total number of scanned objects: 97195
Number of viruses found: 1
Number of infected objects: 2
Number of suspicious objects: 0
Duration of the scan process: 01:14:08


Sorry I didn't post the rest of the log file, I thought it was sort of long.

pskelley
2007-10-14, 01:28
Welcome to Safer Networking, I wish to be sure you have viewed and understand this information.
"BEFORE you POST" (READ this Procedure before Requesting Assistance)
http://forums.spybot.info/showthread.php?t=288
All advice given is taken at your own risk.
Please make sure you have read this information so we are on the same page.

The Waiting Room <<< looks like you missed this also.
http://forums.spybot.info/forumdisplay.php?f=37

If your issues are resolved, post to let me know so I can close the topic. If you still have problems, read the directions and post a HJT log. I will need to see the complete Kaspersky scan but you can wait on that. Please take the time to describe your problem.

Thanks

tashi
2007-10-19, 23:36
This topic has been moved to archives.

If you need the thread re-opened, please send me a private message (pm) and provide a link.

Applies only to the original poster, anyone else with similar problems please start your own topic.