Greetings,
Roughly a week ago, my wife had a run-in with "MS Antivirus" while doing some shopping on-line. Not being particularly computer savvy -- even less savvy than me, and that's saying something -- she mistook the faked warning page for real, and proceeded to download some associated malware. (She didn't purchase anything, but there was still an associated ".exe" (which I'm pretty sure she didn't run) on the desktop when I got home from work to check things out. She was running Firefox when she encountered this junk. Maybe that helped minimize the effects...) I wasn't present when this happened; details are fuzzy.
That same evening, I deleted the executable that was left on the desktop, and proceeded to update and run a full MBAM scan, which turned up no apparent issues. I felt OK about it, and shut off the computer for the evening.
The next day, the AVG 8.0 resident was complaining about something related to this "MS Antivirus" malware. (I've since forgotten exactly what it said.) I ran a full AVG 8.0 scan, and allowed it to remove five executables that it referred to as "Trojan horse Crypt.BQI". These executables were scattered about in "Documents and Settings" and "System Volume Information". (I think I can find the log if it turns out to be important.)
Since then, I've looked through the Add/Remove Programs listing and run scans with the Windows malicious software removal tool, AVG 8.0, MBAM, and ESET, none of which have shown anything that I can see as terribly bad or that appears to be associated with "MS Antivirus".
Perhaps I'm being overly anal-retentive about this, but the updated MBAM scan not finding anything the day of the malicious download threw me for a loop. I'm hoping that someone far more knowledgeable than me can look at the logs below and tell me if I'm missing anything obvious, or if there are any other actions I should take that would make me feel safer about using banking websites and the like once again from this computer.
Thanks,
Pete
MBAM log, ESET log, and HJT uninstall list follow:
---------------------------------------------------------------------
Malwarebytes' Anti-Malware 1.33
Database version: 1686
Windows 5.1.2600 Service Pack 3
1/24/2009 9:56:07 AM
mbam-log-2009-01-24 (09-56-06).txt
Scan type: Full Scan (C:\|)
Objects scanned: 134744
Time elapsed: 1 hour(s), 17 minute(s), 31 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
---------------------------------------------------------------------
# version=4
# OnlineScanner.ocx=1.0.0.635
# OnlineScannerDLLA.dll=1, 0, 0, 79
# OnlineScannerDLLW.dll=1, 0, 0, 78
# OnlineScannerUninstaller.exe=1, 0, 0, 49
# vers_standard_module=3795 (20090123)
# vers_arch_module=1.064 (20080214)
# vers_adv_heur_module=1.066 (20070917)
# EOSSerial=cb7d5368d940f947a215fa159ab96aec
# end=finished
# remove_checked=false
# unwanted_checked=true
# utc_time=2009-01-24 03:43:29
# local_time=2009-01-24 10:43:29 (-0500, Eastern Standard Time)
# country="United States"
# osver=5.1.2600 NT Service Pack 3
# scanned=238573
# found=0
# scan_time=2436
---------------------------------------------------------------------
Ad-Aware
Adobe Acrobat 5.0
Adobe Flash Player 10 Plugin
Adobe Flash Player ActiveX
Adobe Reader 7.0.9
Adobe Shockwave Player
Adventures in Typing with Timon and Pumbaa
AnswerWorks 4.0 Runtime - English
AOL Uninstaller (Choose which Products to Remove)
AOL You've Got Pictures Screensaver
AVG Free 8.0
BCM V.92 56K Modem
Blues Clues School
Caillou(R) Birthday Party(TM)
Canon Camera Access Library
Canon Camera Support Core Library
Canon G.726 WMP-Decoder
CANON iMAGE GATEWAY Task for ZoomBrowser EX
Canon Internet Library for ZoomBrowser EX
Canon MovieEdit Task for ZoomBrowser EX
Canon RAW Image Task for ZoomBrowser EX
Canon Utilities CameraWindow
Canon Utilities CameraWindow DC
Canon Utilities CameraWindow DC_DV 5 for ZoomBrowser EX
Canon Utilities CameraWindow DC_DV 6 for ZoomBrowser EX
Canon Utilities EOS Utility
Canon Utilities MyCamera
Canon Utilities MyCamera DC
Canon Utilities PhotoStitch
Canon Utilities RemoteCapture DC
Canon Utilities RemoteCapture Task for ZoomBrowser EX
Canon Utilities ZoomBrowser EX
Canon ZoomBrowser EX Memory Card Utility
Cars - Radiator Springs Adventures
Classic PhoneTools
Clifford Learning Activities
Clifford Phonics
Clifford Thinking Adventures
Comcast Universal Installer v1.2
Compatibility Pack for the 2007 Office system
Dell Modem-On-Hold
Dell Picture Studio - Dell Image Expert
Dell Solution Center
DellSupport
Digital Line Detect
Dragon Tales
DVDSentry
ESET Online Scanner
Google Earth
Google Updater
G-Police
Half-Life
HijackThis 2.0.2
Hotfix for Windows Internet Explorer 7 (KB947864)
Hotfix for Windows XP (KB952287)
hp instant support
HP Memories Disc
HP Photo and Imaging 2.0 - All-in-One
HP Photo and Imaging 2.0 - All-in-One Drivers
HP Photo and Imaging 2.0 - hp psc 2100 series
hp psc 2100 series
Intel(R) PRO Ethernet Adapter and Software
Intel(R) PROSet II
John Deere American Farmer TM v1.0
JumpStart Spanish
Malwarebytes' Anti-Malware
Microsoft .NET Framework (English)
Microsoft .NET Framework (English) v1.0.3705
Microsoft .NET Framework 1.0 Hotfix (KB928367)
Microsoft .NET Framework 2.0 Service Pack 1
Microsoft Data Access Components KB870669
Microsoft Encarta Encyclopedia Standard 2003
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft Money 2003
Microsoft Money 2003 System Pack
Microsoft National Language Support Downlevel APIs
Microsoft Office 2000 SR-1 Disc 2
Microsoft Office 2000 SR-1 Premium
Microsoft PhotoDraw 2000 V2
Microsoft Picture It! Photo 7.0
Microsoft Visual C++ 2005 Redistributable
Microsoft Word 2002
Microsoft Works 2003 Setup Launcher
Microsoft Works 7.0
Microsoft Works Suite Add-in for Microsoft Word
Modem Helper
Mozilla Firefox (3.0.5)
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
MUSICMATCH Jukebox
NVIDIA Display Driver
NVIDIA Windows 2000/XP Display Drivers
Paint Shop Pro 7
Personalized Learning Center
PowerDVD
Pure Networks Port Magic
QuickTime
QuickTime for Windows (32-bit)
Reader Rabbit Personalized 1st Grade
RealPlayer
Savings Bond Wizard
Scholastic's I SPY Junior
Scholastic's I SPY School Days
Security Update for Step By Step Interactive Training (KB898458)
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Internet Explorer 7 (KB928090)
Security Update for Windows Internet Explorer 7 (KB929969)
Security Update for Windows Internet Explorer 7 (KB931768)
Security Update for Windows Internet Explorer 7 (KB933566)
Security Update for Windows Internet Explorer 7 (KB937143)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB939653)
Security Update for Windows Internet Explorer 7 (KB942615)
Security Update for Windows Internet Explorer 7 (KB944533)
Security Update for Windows Internet Explorer 7 (KB950759)
Security Update for Windows Internet Explorer 7 (KB953838)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Internet Explorer 7 (KB958215)
Security Update for Windows Internet Explorer 7 (KB960714)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player 9 (KB911565)
Security Update for Windows Media Player 9 (KB917734)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Sesame Street (R) Music Maker(TM)
Shockwave
Sierra Utilities
Spybot - Search & Destroy
SpywareBlaster 4.1
Thomas & Friends - Trouble on the Tracks
TurboTax Basic 2005
TurboTax Basic 2006
TurboTax Basic 2007
TurboTax ItsDeductible 2005
TurboTax ItsDeductible 2006
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB951978)
Update for Windows XP (KB955839)
Viewpoint Media Player
WexTech AnswerWorks
Wiggly Party
Windows Live OneCare safety scanner
Windows XP Junglebook Compatiblity Fix
Windows XP Service Pack 3