Please download Malwarebytes' Anti-Malware from Here or Here
Double Click mbam-setup.exe to install the application.
Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish. If an update is found, it will download and install the latest version. Once the program has loaded, select " Perform Quick Scan", then click Scan. The scan may take some time to finish,so please be patient. When the scan is complete, click OK, then Show Results to view the results. Make sure that everything is checked, and click Remove Selected. When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note) The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM. Copy&Paste the entire report in your next reply.
Extra Note: If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.
bamajim
10.4K Posts
0
September 2nd, 2008 23:00
Please download Malwarebytes' Anti-Malware from Here or Here
Double Click mbam-setup.exe to install the application.
If an update is found, it will download and install the latest version.
Once the program has loaded, select " Perform Quick Scan", then click Scan.
The scan may take some time to finish,so please be patient.
When the scan is complete, click OK, then Show Results to view the results.
Make sure that everything is checked, and click Remove Selected.
When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.
"The world is what you make of it"
picaro12
3 Posts
0
September 3rd, 2008 01:00
looks like it is gone. Thanks for hte help, should have come here first.
Thanks a million!
Picaro12
picaro12
3 Posts
0
September 3rd, 2008 01:00
Here it is. Apparantly some of the software I had was also somewhat rogue (Adware alert, etc)
Am going to restart and see how it goes
Picaro12
Malwarebytes' Anti-Malware 1.26
Database version: 1106
Windows 6.0.6000
9/2/2008 7:20:31 PM
mbam-log-2008-09-02 (19-20-30).txt
Scan type: Quick Scan
Objects scanned: 42090
Time elapsed: 3 minute(s), 5 second(s)
Memory Processes Infected: 4
Memory Modules Infected: 6
Registry Keys Infected: 10
Registry Values Infected: 8
Registry Data Items Infected: 0
Folders Infected: 12
Files Infected: 41
Memory Processes Infected:
C:\Windows\System32\VIEAA19.exe (Trojan.FakeAlert) -> Unloaded process successfully.
C:\Program Files\AdwareAlert\AdwareAlert.exe (Rogue.AdwareAlert) -> Unloaded process successfully.
C:\Program Files\AdwareAlert\AdwareAlert.srv.exe (Rogue.AdwareAlert) -> Unloaded process successfully.
C:\Program Files\ErrorKiller\ErrorKiller.exe (Rogue.ErrorKiller) -> Unloaded process successfully.
Memory Modules Infected:
C:\Program Files\AdwareAlert\SpyCleaner.dll (Rogue.AdwareAlert) -> Delete on reboot.
C:\Program Files\AdwareAlert\TCL.dll (Rogue.AdwareAlert) -> Delete on reboot.
C:\Program Files\AdwareAlert\zlib.dll (Rogue.AdwareAlert) -> Delete on reboot.
C:\Program Files\ErrorKiller\RegCleaner.dll (Rogue.ErrorKiller) -> Delete on reboot.
C:\Program Files\ErrorKiller\TCL.dll (Rogue.ErrorKiller) -> Delete on reboot.
C:\Program Files\ErrorKiller\zlib.dll (Rogue.ErrorKiller) -> Delete on reboot.
Registry Keys Infected:
HKEY_CLASSES_ROOT\Installer\UpgradeCodes\0bb69e0c8f7404d4b92477b0f0bd1845 (Rogue.ErrorKiller) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Installer\UpgradeCodes\7c673a5b871b8cd419f47dd0de5a6d18 (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\0bb69e0c8f7404d4b92477b0f0bd1845 (Rogue.ErrorKiller) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\7c673a5b871b8cd419f47dd0de5a6d18 (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\adwarealertsrv (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\adwarealertsrv (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\adwarealertsrv (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\ErrorKiller (Rogue.ErrorKiller) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\ErrorKiller (Rogue.ErrorKiller) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\AdwareAlert (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\vieaa19.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\vieaa19.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\errorkiller (Rogue.ErrorKiller) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\c:\program files\errorkiller\ (Rogue.ErrorKiller) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\c:\programdata\microsoft\windows\start menu\programs\errorkiller\ (Rogue.ErrorKiller) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\AdwareAlert (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\c:\program files\adwarealert\ (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\c:\programdata\microsoft\windows\start menu\programs\adwarealert\ (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
C:\Program Files\AdwareAlert (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
C:\Program Files\ErrorKiller (Rogue.ErrorKiller) -> Quarantined and deleted successfully.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AdwareAlert (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
C:\Users\Matt\AppData\Roaming\AdwareAlert (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
C:\Users\Matt\AppData\Roaming\AdwareAlert\Log (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
C:\Users\Matt\AppData\Roaming\AdwareAlert\Quarantine (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
C:\Users\Matt\AppData\Roaming\AdwareAlert\Quarantine\02-09-2008-19-15-26 (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
C:\Users\Matt\AppData\Roaming\AdwareAlert\Settings (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ErrorKiller (Rogue.ErrorKiller) -> Quarantined and deleted successfully.
C:\Users\Matt\AppData\Roaming\ErrorKiller (Rogue.ErrorKiller) -> Quarantined and deleted successfully.
C:\Users\Matt\AppData\Roaming\ErrorKiller\Log (Rogue.ErrorKiller) -> Quarantined and deleted successfully.
C:\Users\Matt\AppData\Roaming\ErrorKiller\Registry Backups (Rogue.ErrorKiller) -> Quarantined and deleted successfully.
Files Infected:
C:\Windows\System32\VIEAA19.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Program Files\AdwareAlert\AdwareAlert.exe (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
C:\Program Files\AdwareAlert\AdwareAlert.srv.exe (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
C:\Program Files\AdwareAlert\AdwareAlert.url (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
C:\Program Files\AdwareAlert\DataBase.ref (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
C:\Program Files\AdwareAlert\SpyCleaner.dll (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
C:\Program Files\AdwareAlert\TCL.dll (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
C:\Program Files\AdwareAlert\vistaCPtasks.xml (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
C:\Program Files\AdwareAlert\zlib.dll (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
C:\Program Files\ErrorKiller\DataBase.ref (Rogue.ErrorKiller) -> Quarantined and deleted successfully.
C:\Program Files\ErrorKiller\ErrorKiller.exe (Rogue.ErrorKiller) -> Quarantined and deleted successfully.
C:\Program Files\ErrorKiller\ErrorKiller.url (Rogue.ErrorKiller) -> Quarantined and deleted successfully.
C:\Program Files\ErrorKiller\RegCleaner.dll (Rogue.ErrorKiller) -> Quarantined and deleted successfully.
C:\Program Files\ErrorKiller\TCL.dll (Rogue.ErrorKiller) -> Quarantined and deleted successfully.
C:\Program Files\ErrorKiller\zlib.dll (Rogue.ErrorKiller) -> Quarantined and deleted successfully.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AdwareAlert\AdwareAlert on the Web.lnk (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AdwareAlert\AdwareAlert.lnk (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
C:\Users\Matt\AppData\Roaming\AdwareAlert\Log\2008 Sep 02 - 03_17_29 PM_005.log (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
C:\Users\Matt\AppData\Roaming\AdwareAlert\Log\2008 Sep 02 - 04_00_52 PM_183.log (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
C:\Users\Matt\AppData\Roaming\AdwareAlert\Log\2008 Sep 02 - 04_01_15 PM_112.log (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
C:\Users\Matt\AppData\Roaming\AdwareAlert\Log\2008 Sep 02 - 04_42_12 PM_295.log (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
C:\Users\Matt\AppData\Roaming\AdwareAlert\Log\2008 Sep 02 - 04_47_04 PM_015.log (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
C:\Users\Matt\AppData\Roaming\AdwareAlert\Quarantine\02-09-2008-19-15-26\0.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
C:\Users\Matt\AppData\Roaming\AdwareAlert\Quarantine\02-09-2008-19-15-26\0.qnf (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
C:\Users\Matt\AppData\Roaming\AdwareAlert\Quarantine\02-09-2008-19-15-26\1.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
C:\Users\Matt\AppData\Roaming\AdwareAlert\Quarantine\02-09-2008-19-15-26\1.qnf (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
C:\Users\Matt\AppData\Roaming\AdwareAlert\Quarantine\02-09-2008-19-15-26\2.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
C:\Users\Matt\AppData\Roaming\AdwareAlert\Quarantine\02-09-2008-19-15-26\2.qnf (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
C:\Users\Matt\AppData\Roaming\AdwareAlert\Quarantine\02-09-2008-19-15-26\3.qit (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
C:\Users\Matt\AppData\Roaming\AdwareAlert\Quarantine\02-09-2008-19-15-26\3.qnf (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ErrorKiller\ErrorKiller on the Web.lnk (Rogue.ErrorKiller) -> Quarantined and deleted successfully.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ErrorKiller\ErrorKiller.lnk (Rogue.ErrorKiller) -> Quarantined and deleted successfully.
C:\Users\Matt\AppData\Roaming\ErrorKiller\Log\2008 Sep 02 - 03_51_55 PM_462.log (Rogue.ErrorKiller) -> Quarantined and deleted successfully.
C:\Users\Matt\AppData\Roaming\ErrorKiller\Log\2008 Sep 02 - 04_00_43 PM_679.log (Rogue.ErrorKiller) -> Quarantined and deleted successfully.
C:\Users\Matt\AppData\Roaming\ErrorKiller\Log\2008 Sep 02 - 04_44_09 PM_189.log (Rogue.ErrorKiller) -> Quarantined and deleted successfully.
C:\Users\Matt\AppData\Roaming\ErrorKiller\Registry Backups\2008-09-02_15-54-08.reg (Rogue.ErrorKiller) -> Quarantined and deleted successfully.
C:\Users\Matt\AppData\Roaming\ErrorKiller\Registry Backups\2008-09-02_15-57-36.reg (Rogue.ErrorKiller) -> Quarantined and deleted successfully.
C:\Users\Matt\AppData\Roaming\ErrorKiller\Registry Backups\2008-09-02_16-24-54.reg (Rogue.ErrorKiller) -> Quarantined and deleted successfully.
C:\Users\Matt\AppData\Roaming\ErrorKiller\Registry Backups\2008-09-02_16-45-38.reg (Rogue.ErrorKiller) -> Quarantined and deleted successfully.
C:\Windows\Tasks\AdwareAlert Scheduled Scan.job (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Users\Matt\AppData\Local\Temp\lwpwer.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
bamajim
10.4K Posts
0
September 3rd, 2008 13:00
picaro12
You are most welcome. Please post a fresh Hiajckthis log so I can see that we got it all
"The world is what you make of it"