This is a read-only archive of malwareremoval.com. No new posts or registrations. Privacy Page
Malware Removal Forums

Redirects and cannot run some programs

72 min read

This thread's last reply is from October 18, 2010, 10:39 AM UTC. Software, malware, and removal-tool advice below may be out of date — treat specific steps and download links with caution.

Hello.

I used my computer lightly yesterday, mainly to visit various gaming related sites. I had no problems during that time with any redirects, extra popups, or anything else that would raise a flag with me.
I haven't yet tried to reinstall malwarebytes, nor have I tried to use Superantispyware again, so I cannot comment on if they work yet. I would expect at this point they likely would, but I am not going to start installing new stuff on my own at this point until I get the ok to do so.

Thank you.
You will have to download and re-install Malwarebytes Anti-Malware to get it to run.
The rootkit infection frequently damages the original.

Super Anti-Spyware should work from Start > All Programs
If you reset Super Anti-Spyware (SAS) to run at startup, then only use the free version of Malwarebytes so that it stays as an on-demand scanner only (the paid one runs all the time and may conflict with SAS).

You can try any of the above, if you wish.
Hello.

I downloaded and installed Malwarebytes again. I updated it and ran a full system scan. It still flagged 2 items, both of which is said it was able to remove. This does give me some concern that something is still lurking though. Below is the log from that scan. Hopefully that is the end of it all, but I will let you be the judge of that. :)

Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4839

Windows 6.0.6002 Service Pack 2
Internet Explorer 8.0.6001.18975

10/15/2010 3:09:00 PM
mbam-log-2010-10-15 (15-09-00).txt

Scan type: Full scan (C:\|)
Objects scanned: 267197
Time elapsed: 58 minute(s), 6 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 2
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\KOO9RV9K4Z (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\SMH2B46TDP (Trojan.FakeAlert) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)


Thank you again for your continued help.
Patryn38,
Those are old registry entries where the rootkit registered the malware files with the system so they would run.
There is no evidence that the associated files are present, and the registry entries referring to them are now gone also.

Looks OK.
askey127
Hello.

Excellent. I know some of these are a real pain to get rid of, so they always worry me when something still shows up.

I thank you very much for all of your patient help. :)