[QUOTE=crunchie;766359]Download
Malwarebytes' Anti-Malware (
http://www.majorgeeks.com/Malwarebyt...are_d5756.html) to your desktop.
Thank you Crunchie for your help and instructions. The process worked perfectly. I'm rid of that nasty thing.
Dan
Malwarebytes' Anti-Malware 1.31
Database version: 1580
Windows 6.0.6001 Service Pack 1
12/31/2008 5:55:05 PM
mbam-log-2008-12-31 (17-55-05).txt
Scan type: Full Scan (C:\|D:\|L:\|N:\|)
Objects scanned: 217056
Time elapsed: 1 hour(s), 36 minute(s), 19 second(s)
Memory Processes Infected: 2
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 2
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 6
Memory Processes Infected:
C:\Users\Dan\AppData\Local\Temp\~tmpb.exe (Trojan.FakeAlert) -> Unloaded process successfully.
C:\Users\Dan\AppData\Local\Temp\~tmpc.exe (Trojan.FakeAlert) -> Unloaded process successfully.
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\MSFox (Trojan.Agent) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\cognac (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\MSFox (Trojan.FakeAlert) -> Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
C:\Users\Dan\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KJNOIPKG\VirusRemover2008_Setup_Free_en[1].exe (Rogue.Installer) -> Quarantined and deleted successfully.
C:\Users\Dan\AppData\Local\Temp\~tmpa.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Users\Dan\AppData\Local\Temp\~tmpb.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Users\Dan\AppData\Local\Temp\~tmpc.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Users\Dan\AppData\Local\Temp\~tmpd.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Users\Dan\AppData\Local\Temp\yyy6901.exe (Trojan.FakeAlert) -> Delete on reboot.