Anti-spyware problem

Closed
brandon - Mar 8, 2010 at 09:34 AM
Ambucias Posts 47356 Registration date Monday February 1, 2010 Status Moderator Last seen February 15, 2023 - Mar 8, 2010 at 04:52 PM
Hello,
everything I download something and want to "Run" the program on my laptop (like anti-spyware for example), I keep getting that "Launch Application" box that pops up after I click on "run". I'm pretty sure my computer is infected with something and would like to know if anyone knows what type of problem I have. I'm download the Anti-Spyware to get rid of whatever problem my laptop has, but I'm having problems running it b/c I don't know what to do when that "launch application" box shows up. I'd appreciate any help.
Related:

4 responses

Ambucias Posts 47356 Registration date Monday February 1, 2010 Status Moderator Last seen February 15, 2023 11,169
Mar 8, 2010 at 11:14 AM
Hello,

I am not sure what to prescribe to you until the virus if any is identified.

In order to help me, please download and install Hyjackthis;

Please request a scan and save log. Copy the log and post it here.

Here is the link to Hyjackthis:

http://free.antivirus.com/hijackthis/

Thank you
0
also i just finished performing a scan with Malwarebytes Anti-Malware and did a full scan but stopped the scan after 2 hours because it was taking too long. I'll put up the log I got which had 2 infected files. Would you suggest I run a quick scan or a full scan? like I said this is a full scan, not a quick scan, but it also isn't a complete full scan b/c i terminated the scan after 2 hours or so.

heres the log:

Malwarebytes' Anti-Malware 1.44
Database version: 3836
Windows 6.0.6001 Service Pack 1
Internet Explorer 8.0.6001.18882

3/8/2010 2:29:45 PM
mbam-log-2010-03-08 (14-29-45).txt

Scan type: Full Scan (C:\|D:\|E:\|)
Objects scanned: 204172
Time elapsed: 2 hour(s), 5 minute(s), 35 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 2

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\l21gcxkx.default\Cache\96490AAAd01 (Rogue.Installer) -> Quarantined and deleted successfully.
C:\Users\user\Downloads\setupxv.exe (Rogue.Installer) -> Quarantined and deleted successfully.
0
I just finished downloading hijackthis and now that im double clicking on it's icon I am getting a pop up labeled "C:\Pogram Files\Windows Defender\ MSASCui.exe" and it says: The version of this file is not compatible with the version of windows you are running. Check your computer's system information to see if you need an x86 (32 bit) or x64 (64 bit) version of the program, and then contact the software publisher". I keep getting this message for most of the icons i click on, even when i want to get on Mozilla Firefox. I have gone to my Program files and click on the "Windows Defender" icon to scan for spyware but the same pop up keeps coming up. What should I do now?
0
Ambucias Posts 47356 Registration date Monday February 1, 2010 Status Moderator Last seen February 15, 2023 11,169
Mar 8, 2010 at 04:43 PM
Hello Brandon,

Indeed a scan, depending on the size of your drives may take long.
If you do a short scan, Malwarebyte will check mostly system 32 which may help to stabalize your system but eventually you will need to make a Full system scan which will even go into your volume information restore.

I have noticed that a trojan installer was deleted.

I would like to know if the Horse is still running processes (no pun intended) (Horse running)

Could you please, before rerunning Malwarebyte, click alt+ctrl+del to open the task manager and click on the processes tab. Scrool and see in you spot any numeric processes or others which may be named security, personnal security, dr.guard, vista security. If so, please stop the processes but do not reboot your computer, and run a full scan with Malwarebyte.

Please let me know how you did.
0
Ambucias Posts 47356 Registration date Monday February 1, 2010 Status Moderator Last seen February 15, 2023 11,169
Mar 8, 2010 at 04:52 PM
Brandon, I forgot to tell you that the Horse in question is self protective and that is why it is preventing to run Hyjackthis and may conflict with Malwarebyte. That may be why it took so long.

I suggest that you delete Malwarebyte and download a fresh copy on your desktop. To fool the Trojan, rename MBAM to Explorer.exe

I do hope you have access to your task manager
0