Jump to content

Explanation for this Virus please.


Recommended Posts

So a couple of days ago I was on the web when suddenly I was infected by a virus. A fake anti-virus popped up telling me to remove threats and I got alot of pop-ups and messages. So I rebooted in safemode and did a full scan with Malwarebytes, it found a few threats and deleted them all. I booted again normally and everything seemed to be fine. To double check I upadated AVG 2012 and did a scan and root-kit scan, which both came up clean. I also downloaded SpyBot, Kaspersky Scanner, SuperAnti Spyware and Ad-Aware and scanned with all of them, which came up clean (Only some cookies and adware with were removed successfully).

So anyway I would like to know what type of virus it was, and if it was a severe one if my data is safe (keep in mind I didn't use or log in with the computer after all the scans and infections were deleted)

So yeah, I need some explanation as to what caused this, if it's still on my system and if my data is safe.

Here is the Malwarebytes log:

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\{F3FEE66E-E034-436A-86E4-9690573BEE8A} (PUP.Dealio.TB) -> Value: {F3FEE66E-E034-436A-86E4-9690573BEE8A} -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{F3FEE66E-E034-436A-86E4-9690573BEE8A} (PUP.Dealio.TB) -> Value: {F3FEE66E-E034-436A-86E4-9690573BEE8A} -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\PROGRAM FILES\COMMON FILES\SPIGOT\WTXPCOM\COMPONENTS\WIDGITOOLBARFF.DLL (Adware.WidgiToolbar) -> Value: WIDGITOOLBARFF.DLL -> Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_CLASSES_ROOT\regfile\shell\open\command\(default) (Broken.OpenCommand) -> Bad: ("regedit.exe" "%1") Good: (regedit.exe "%1") -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
c:\program files\youtube downloader toolbar\IE\4.5\youtubedownloadertoolbarie.dll (PUP.Dealio.TB) -> Quarantined and deleted successfully.
c:\program files\common files\Spigot\wtxpcom\components\widgitoolbarff.dll (Adware.WidgiToolbar) -> Quarantined and deleted successfully.
c:\program files\common files\Spigot\wtxpcom\components\widgitoolbarff.dll.5 (Adware.WidgiToolbar) -> Quarantined and deleted successfully.
c:\program files\common files\Spigot\wtxpcom\components\widgitoolbarff.dll.6 (Adware.WidgiToolbar) -> Quarantined and deleted successfully.
c:\system volume information\_restore{6aeace8e-ecca-421f-9ef5-cc7f48ca3919}\RP104\A0036422.rbf (PUP.Dealio.TB) -> Quarantined and deleted successfully.
c:\system volume information\_restore{6aeace8e-ecca-421f-9ef5-cc7f48ca3919}\RP104\A0036457.old (Adware.WidgiToolbar) -> Quarantined and deleted successfully.
c:\system volume information\_restore{6aeace8e-ecca-421f-9ef5-cc7f48ca3919}\RP143\A0094006.rbf (PUP.Dealio.TB) -> Quarantined and deleted successfully.
c:\system volume information\_restore{6aeace8e-ecca-421f-9ef5-cc7f48ca3919}\RP144\A0094025.old (Adware.WidgiToolbar) -> Quarantined and deleted successfully.
c:\system volume information\_restore{6aeace8e-ecca-421f-9ef5-cc7f48ca3919}\RP168\A0102178.dll (PUP.Dealio.TB) -> Quarantined and deleted successfully.
c:\system volume information\_restore{6aeace8e-ecca-421f-9ef5-cc7f48ca3919}\RP169\A0103006.dll (Adware.WidgiToolbar) -> Quarantined and deleted successfully.
c:\documents and settings\user\local settings\Temp\0.10114853446182437.exe (Exploit.Drop.2) -> Quarantined and deleted successfully.

Am I safe? Thanks.

Link to post
Share on other sites

Hi -

It seems that several infections were downloaded to your computer and Malwarebytes removed most of it -

If you are still concerned about chances of remaining infections (can always be a few left) then read on -

Please read ->>These Directions listed, and then post a new topic http://forums.malwarebytes.org/index.php?showforum=7 <<-Here

Thank You -

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.