This is a read-only archive of malwareremoval.com. No new posts or registrations. Privacy Page
Malware Removal Forums

I've Been Infected! "http://url[dot]urtbk[dot]com"

1 min read

This thread's last reply is from February 18, 2010, 5:30 AM UTC. Software, malware, and removal-tool advice below may be out of date — treat specific steps and download links with caution.

Hello Malware community,

My computer has recently been infected with spyware, I receive a warning from my third party security software (Trend Micro) when I search websites on firefox, The warning displays "http://url[dot]urtbk[dot]com" even tho I haven't been redirected to that site. I came here to hopefully get this problem resolved.
I did a scan with "Malwarebytes' Anti-Malware" results below,

Malwarebytes' Anti-Malware 1.44
Database version: 3753
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

2/18/2010 9:24:58 AM
mbam-log-2010-02-18 (09-24-54).txt

Scan type: Full Scan (C:\|F:\|)
Objects scanned: 224864
Time elapsed: 1 hour(s), 7 minute(s), 22 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 3
Registry Values Infected: 0
Registry Data Items Infected: 1
Folders Infected: 0
Files Infected: 5

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\CLSID\{fe5b2d9d-91b0-b04b-ac20-14a260769687} (Adware.ColorSoft) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\feym6ia (Adware.AdRotator) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\AppDataLow\HavingFunOnline (Adware.BHO.FL) -> No action taken.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
HKEY_CLASSES_ROOT\regfile\shell\open\command\(default) (Broken.OpenCommand) -> Bad: ("regedit.exe" "%1") Good: (regedit.exe "%1") -> No action taken.

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Documents and Settings\Shane Frazz\Desktop\keygen-Windows.exe (Malware.Tool) -> No action taken.
C:\Documents and Settings\Shane Frazz\Local Settings\Temp\ldm1.exe (Adware.Agent) -> No action taken.
C:\Documents and Settings\Shane Frazz\My Documents\My Music\TMPGEnc Authoring Works 4.0.2.14\keygen.exe (Malware.Packer.Gen) -> No action taken.
C:\WINDOWS\system32\FeyM6iA.exe (Adware.AdRotator) -> No action taken.
F:\TMPG DVD Maker\keygen.exe (Malware.Packer.Gen) -> No action taken.



Help would be greatly appreciated, thank you!
In order for us to help you it is necessary that you provide us with a HijackThis log. Please follow the guideline at the link below to start a new topic and post your HijackThis log by pasting it into your post. Do not utilize attachments.

This topic is now closed. Please start a new topic by following the HijackThis Guideline posted here: >Guideline for posting your HijackThis log<