Thank you in advance to anyone who can help me with my problem.
I'm running an HP Pavillion 725n with Windows XP Home Edition and Service Pack 3. This morning, my mother visited Facebook with MS Internet Explorer. She reported to me that her browser window suddenly disappered and up popped what looked like an authentic message from Windows Security warning her that this machine may be infected and needed to be scanned. She clicked "OK" and got a scary-looking page informing her that several drives were badly infected and needed to be cleaned. This site attempted to download an .exe file from "antivirus.scan.pro," or something like that. Fortunately, Windows Security stepped in and gave us the dialog box warning us that .exe files can be malicious and gave us the option of cancelling or proceeding with the download. I repeatedly clicked "Cancel," but the file kept trying to download itself. I finally used Ctrl-Alt-Del to exit IE entirely.
This sounds like the work of this infamous AntiVirus 2009 trojan. AntiVirus 2009 is showing in the Start > All Programs menu, nor in the Add/Delete Programs menu, nor in The Program Files folder. My browsers are functioning normally, and at present, no one is trying to force me to buy AV software. However, this morning, I was unable to initiate a full system scan with Norton AV 2009. (But otherwise, my computer is not misbehaving.)
Here's where I need help: For peace of mind, I downloaded and updated Malwarebytes and did a full system scan (with System Restore turned off). Here's the resulting log:
Malwarebytes' Anti-Malware 1.40
Database version: 2616
Windows 5.1.2600 Service Pack 3
8/13/2009 5:24:09 PM
mbam-log-2009-08-13 (17-24-09).txt
Scan type: Full Scan (C:\|D:\|)
Objects scanned: 199069
Time elapsed: 2 hour(s), 21 minute(s), 19 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 2
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Illysoft (Rogue.SpyNoMore) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Illysoft (Rogue.SpyNoMore) -> Quarantined and deleted successfully.
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
MB appears to have successfully caught and removed two bad registry keys. Once they were removed, I was able to launch a full system scan with Norton. I did not let the scan run all the way to completion, so I don't know if Norton would have caught anything.
I want to be certain that no traces of this threat (or any other) are still lurking on my machine, waiting to reinstall themselves and spring up later. Do I need to do anything more at this point? I'm ready to post HijackThis logs if needed.
Again, I'd appreciate any assistance, and thank you in advance.