Hello all,
e
I have Norton 360 and it keeps telling me I have two viruses One of them being graybird? Anyhow, it says it gets rid of them, but they keep showing up sometimes multiple times per day. I dowloaded Malwareybytes with the latest version and it found 5 threats, so i got rid of them. Now my internet doesn't work. I can't connect via Firefox, Internet Explorer or Google. My outlook works, sending and receiving messages. When I try to connect to the internet it says "the proxy server is refusing connections".
I am assuming this is due to the viruses? Does anyone know how to fix this? I am attaching the logs from Malwarebytes. A great big thanks to everyone who can help.
Malwarebytes' Anti-Malware 1.46
Malwarebytes
Database version: 4948
Windows 6.1.7600
Internet Explorer 8.0.7600.16385
10/25/2010 6:29:39 PM
mbam-log-2010-10-25 (18-29-39).txt
Scan type: Quick scan
Objects scanned: 141712
Time elapsed: 5 minute(s), 10 second(s)
Memory Processes Infected: 2
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 2
Registry Data Items Infected: 1
Folders Infected: 0
Files Infected: 2
Memory Processes Infected:
C:\Users\Kim Herlache\AppData\Roaming\Microsoft\svchost.exe (Trojan.Agent) -> Unloaded process successfully.
C:\Users\Kim Herlache\AppData\Roaming\Microsoft\Windows\shell.exe (Trojan.Shell) -> Unloaded process successfully.
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\svchost (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\load (Trojan.Agent) -> Quarantined and deleted successfully.
Registry Data Items Infected:
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell (Hijack.Shell) -> Bad: (explorer.exe,C:\Users\Kim Herlache\AppData\Roaming\Microsoft\Windows\shell.exe) Good: (Explorer.exe) -> Quarantined and deleted successfully.
Folders Infected:
(No malicious items detected)
Files Infected:
C:\Users\Kim Herlache\AppData\Roaming\Microsoft\svchost.exe (Trojan.Agent) -> Delete on reboot.
C:\Users\Kim Herlache\AppData\Roaming\Microsoft\Windows\shell.exe (Trojan.Shell) -> Quarantined and deleted successfullycond
second one....
Malwarebytes' Anti-Malware 1.46
Malwarebytes
Database version: 4948
Windows 6.1.7600
Internet Explorer 8.0.7600.16385
10/25/2010 6:55:44 PM
mbam-log-2010-10-25 (18-55-44).txt
Scan type: Quick scan
Objects scanned: 141159
Time elapsed: 4 minute(s), 55 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 2
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
C:\Users\Kim Herlache\AppData\Roaming\Microsoft\svchost.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\Users\Kim Herlache\AppData\Roaming\Microsoft\Windows\shell.exe (Trojan.Shell) -> Quarantined and deleted successfully.