Subscribe to How-To Geek

Welcome to the How-To Geek Forums

We encourage you to register on our forums and post any questions you might have. The How-To Geeks monitor this forum and will respond to your question quickly.

How-To Geek Forums » Windows Vista

Unable to resolve Bloodhound.exploit.196 Virus. Arrgghh!

(3 posts)
  • Started 6 months ago by wolftab
  • Latest reply from wolftab
  • Topic Viewed 1020 times

wolftab
Posts: 18

For about a month Symantec has been finding thousands of temp files that it claims is infected with Bloodhound.exploit.196 . I have tried the following steps to resolve the issue:

Delete all temporary files in safe mode
Run an updated virus scan
Run spyware scans (ad-aware, windows defender, and spybot)
Examined hijack this scan
Installed the latest version of all adobe programs (I've read this can sometime be related to acrobat reader 8.0)

The files appear randomly. At times SAV can find several a minute. At other times it will be hours in-between detection. I have yet to detect one being created while in safe mode. When I go into the Local Temp Folder and try deleting all of these files, it shows that they do not exist, I have to manually click on each file that doesn't exist, at one point it was over a 100 and I am at my wits end. I am running Vista. Can someone help. Here is the message I receive from Symantec.
Scan type: Auto-Protect Scan
Event: Security Risk Found!
Risk: Bloodhound.Exploit.196
File: C:\Users\Owner\AppData\Local\Temp\DWH5539.tmp
Location: Quarantine
Computer: OWNER-84J1T8A8N
User: SYSTEM
Action taken: Quarantine succeeded : Access denied
Date found: Wednesday, May 06, 2009 9:53:43 PM

Thanks,
Tom

Posted 6 months ago #
Top
 
JadeEmperor
JadeEmperor
Posts: 244

hi wolftab,

can you run another scan using malwarebytes scanner? you might like to first update malwarebytes after installing then do a full system scan. it'll be better if you can do this from safemode.

since you mentioned hijack, i'd do a before and after hjt scan then compare.

let us know what happened.

Posted 6 months ago #
Top
 
wolftab
Posts: 18

Hi Jade,
I ran the scan and got this
Malwarebytes' Anti-Malware 1.36
Database version: 2086
Windows 6.0.6001 Service Pack 1

5/7/2009 1:28:42 AM
mbam-log-2009-05-07 (01-28-42).txt

Scan type: Quick Scan
Objects scanned: 72630
Time elapsed: 1 hour(s), 2 minute(s), 11 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 5
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\pmspl.video (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{d685b6db-1ed0-4345-8a86-674a4f0198ee} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\{ff5137b5-c506-4d9b-8682-e0be4675b899} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{ff5137b5-c506-4d9b-8682-e0be4675b899} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\pmspl.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Windows\System32\libmcl-3.1.1.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully.

Just more fake alerts and phantoms. I am still being attacked. I do not have Adobe Acrobat installed any longer as supposedly that could be where it orginated from. I just have no ideas where these attacks are coming from.

Posted 6 months ago #
Top
 

RSS feed for this topic

Reply

You must log in to post.

Our Friends
Getting Started


About How-To Geek
What Is That Process?
svchost.exe
jusched.exe
dwm.exe
ctfmon.exe
wmpnetwk.exe
mDNSResponder.exe
wmpnscfg.exe
rundll32.exe
wfcrun32.exe
Ipoint.exe
Itype.exe
Wfica32.exe
Mobsync.exe
conhost.exe
Dpupdchk.exe Adobe_Updater.exe

Copyright © 2006-2009 HowToGeek.com. All Rights Reserved.