My computer is infected with some sort of malware called AntiMalware Doctor. This is like a scanning program that appears to pop up and scan my computer. It also has a windows security logo that pops up on my taskbar. Aside from getting scan popups, the main problem is that I am unable to open any .exe files as it states that I may not have permission to open them. The exact error is as follows:
"Windows cannot access the specific file. You may not have permission to access the item."
This means that I cannot run atfcleaner, the GMER tool or DDS. I can only run Malwarebytes Antimalware as this was already installed on my computer. I did a full scan with Malwarebytes and it detected the trojans and rogue softwares. I selected remove all and restarted the computer. However, upon restart the popups etc. returned.
I would appreciate any help...thanks
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org
Database version: 4052
Windows 5.1.2600 Service Pack 2
Internet Explorer 8.0.6001.18702
7/15/2010 8:42:07 AM
mbam-log-2010-07-15 (08-42-07).txt
Scan type: Full scan (C:\|D:\|)
Objects scanned: 318258
Time elapsed: 3 hour(s), 54 minute(s), 17 second(s)
Memory Processes Infected: 2
Memory Modules Infected: 0
Registry Keys Infected: 6
Registry Values Infected: 5
Registry Data Items Infected: 2
Folders Infected: 0
Files Infected: 14
Memory Processes Infected:
C:\WINDOWS\system32\net.net (Trojan.Downloader) -> Unloaded process successfully.
C:\Documents and Settings\HP_Owner.HP\Local Settings\Temp\iexplorer.exe (Malware.Packer.Gen) -> Unloaded process successfully.
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CLASSES_ROOT\CLSID\{fe5b2d9d-91b0-b04b-ac20-14a260769687} (Adware.ColorSoft) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\tddkki (Adware.AdRotator) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\AGprotect (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\net (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Antimalware Doctor (Rogue.AntimalwareDoctor) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Antimalware Doctor Inc (Rogue.AntimalwareDoctor) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\net (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mcexecwin (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\idstrf (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\winid (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\nofolderoptions (Hijack.FolderOptions) -> Delete on reboot.
Registry Data Items Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFolderOptions (Hijack.FolderOptions) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools (Hijack.Regedit) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
Folders Infected:
(No malicious items detected)
Files Infected:
C:\WINDOWS\system32\net.net (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner.HP\Local Settings\Temp\iexplorer.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner.HP\Local Settings\Temp\cwaoxsemrn.tmp (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Program Files\Mozilla Firefox\extensions\{a3108a80-e87c-fb53-f541-fd59cd03b63a}\components\49RNyXkQxtZj7_y.dll (Adware.BHO) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\TDdKkI.exe (Adware.AdRotator) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner.HP\Local Settings\Temp\k0w3o.dll (Trojan.Agent) -> Delete on reboot.
C:\Documents and Settings\HP_Owner.HP\Start Menu\Programs\Startup\Antimalware Doctor.lnk (Rogue.AntiMalwareDoctor) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner.HP\Application Data\Microsoft\Internet Explorer\Quick Launch\Antimalware Doctor.lnk (Rogue.AntimalwareDoctor) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner.HP\Start Menu\Antimalware Doctor.lnk (Rogue.AntimalwareDoctor) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\service.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner.HP\Local Settings\Temp\lsass.exe (Trojan.Agent) -> Delete on reboot.
C:\Documents and Settings\HP_Owner.HP\Local Settings\Temp\svchost.exe (Trojan.Agent) -> Delete on reboot.
C:\Documents and Settings\HP_Owner.HP\Local Settings\Temp\taskmgr.exe (Trojan.Downloader) -> Delete on reboot.
C:\Documents and Settings\HP_Owner.HP\Local Settings\Temp\win32.exe (Trojan.Downloader) -> Delete on reboot.