Virus setup.exe (Takes different forms)

Solved
Hello,

I installed the new version of Firefox last night (4.0.1) and as a result, I got a virus the next day grrrrr.

Anyway, my User Account Control keeps warning me that a program wants to run and asks for permission to execute it. Of course, I refuse, and the message keeps coming back, but in a different form, like:

Setup1132956008.exe (I click cancel) then 3 seconds later, another one but in a different form like Setup220153651.exe, then another one, etc...

I hope you can help me!!

Sincerely,

Kevin

Configuration: Windows Vista / Firefox 4.0.1

4 answers

  1. Security Contributor
    I'm sorry, but I can't assist with that.
    3
    1. Perfect, I'm doing the quick analysis right now.
      0
    2. Malware just indicated to me that my PC is indeed populated:

      Malwarebytes' Anti-Malware 1.50
      www.malwarebytes.org

      Database version: 6479

      Windows 6.0.6002 Service Pack 2
      Internet Explorer 8.0.6001.19048

      2011-04-30 15:41:18
      mbam-log-2011-04-30 (15-41-18).txt

      Scan type: Quick Scan
      Item(s) scanned: 255805
      Elapsed time: 16 minute(s), 5 second(s)

      Infected memory processes: 0
      Infected memory modules: 0
      Infected Registry keys: 0
      Infected Registry values: 0
      Infected Registry data items: 0
      Infected folders: 1
      Infected files: 18

      Infected memory processes:
      (No harmful items detected)

      Infected memory modules:
      (No harmful items detected)

      Infected Registry keys:
      (No harmful items detected)

      Infected Registry values:
      (No harmful items detected)

      Infected Registry data items:
      (No harmful items detected)

      Infected folders:
      c:\Users\KÉVIN\AppData\Roaming\microsoft\Windows\start menu\Programs\antimalware doctor (Rogue.AntiMalwareDoctor) -> Quarantined and deleted successfully.

      Infected files:
      c:\Users\KÉVIN\AppData\Local\Temp\0.3998478587931642.exe (Trojan.TDSS.Gen) -> Delete on reboot.
      c:\Users\KÉVIN\AppData\Local\Temp\C26B.tmp (Trojan.TDSS.Gen) -> Quarantined and deleted successfully.
      c:\Users\KÉVIN\AppData\Local\Temp\0.41031541131367333.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
      c:\Users\KÉVIN\AppData\Local\Temp\setup1132956008.exe (Trojan.TDSS.Gen) -> Quarantined and deleted successfully.
      c:\Users\KÉVIN\AppData\Local\Temp\setup1293109736.exe (Trojan.TDSS.Gen) -> Quarantined and deleted successfully.
      c:\Users\KÉVIN\AppData\Local\Temp\setup2282738408.exe (Trojan.TDSS.Gen) -> Quarantined and deleted successfully.
      c:\Users\KÉVIN\AppData\Local\Temp\setup2613169768.exe (Trojan.TDSS.Gen) -> Quarantined and deleted successfully.
      c:\Users\KÉVIN\AppData\Local\Temp\setup2882079592.exe (Trojan.TDSS.Gen) -> Quarantined and deleted successfully.
      c:\Users\KÉVIN\AppData\Local\Temp\setup289088232.exe (Trojan.TDSS.Gen) -> Quarantined and deleted successfully.
      c:\Users\KÉVIN\AppData\Local\Temp\setup998926440.exe (Trojan.TDSS.Gen) -> Quarantined and deleted successfully.
      c:\Users\KÉVIN\AppData\Local\Temp\setup3124030056.exe (Trojan.TDSS.Gen) -> Quarantined and deleted successfully.
      c:\Users\KÉVIN\AppData\Local\Temp\setup3398140392.exe (Trojan.TDSS.Gen) -> Quarantined and deleted successfully.
      c:\Users\KÉVIN\AppData\Local\Temp\setup343264360.exe (Trojan.TDSS.Gen) -> Quarantined and deleted successfully.
      c:\Users\KÉVIN\AppData\Local\Temp\setup3534565352.exe (Trojan.TDSS.Gen) -> Quarantined and deleted successfully.
      c:\Users\KÉVIN\AppData\Local\Temp\setup559652072.exe (Trojan.TDSS.Gen) -> Quarantined and deleted successfully.
      c:\Windows\Temp\setDC9D.tmp (Trojan.TDSS.Gen) -> Quarantined and deleted successfully.
      c:\Users\KÉVIN\AppData\Roaming\microsoft\Windows\start menu\Programs\antimalware doctor\antimalware doctor.lnk (Rogue.AntiMalwareDoctor) -> Quarantined and deleted successfully.
      c:\Users\KÉVIN\AppData\Roaming\microsoft\Windows\start menu\Programs\antimalware doctor\uninstall.lnk (Rogue.AntiMalwareDoctor) -> Quarantined and deleted successfully.
      0
  2. My antivirus is McAfee paid version.
    1
    1. Security Contributor
      Je suis désolé, je ne peux pas vous aider avec cela.
      1
      1. Perfect, I just performed "The disinfection of the infected system", and it detected nothing. In my opinion, Malwarebytes Antimalware did its job. Anyway, I'm doing the Zhpdiag report right now and I'll send you the information!
        0
      2. I just sent you a private message!!
        0
      3. Hello, I have the same problem. Could you help me?
        0