New Trojans (AVCare) has disabled internet and everything el

Page 1 of 2 1, 2  Next

View previous topic View next topic Go down

Re: New Trojans (AVCare) has disabled internet and everything el

Post by reeldeel on 10th August 2009, 6:58 pm

How do I do this, I have no idea.

reeldeel
Intermediate
Intermediate

Posts Posts : 50
Joined Joined : 2009-07-20
OS OS : XP
Points Points : 27036
# Likes # Likes : 0

View user profile

Back to top Go down

Re: New Trojans (AVCare) has disabled internet and everything el

Post by reeldeel on 10th August 2009, 6:59 pm

How do I find them on his computer?

reeldeel
Intermediate
Intermediate

Posts Posts : 50
Joined Joined : 2009-07-20
OS OS : XP
Points Points : 27036
# Likes # Likes : 0

View user profile

Back to top Go down

Re: New Trojans (AVCare) has disabled internet and everything el

Post by Belahzur on 10th August 2009, 8:54 pm

Using Windows Explorer (Windows key + E] Navigate to the Tasks folder following the past given.

First C:\ drive, then into the Windows folder. Now find the Tasks folder. Go inside the Tasks folder and the two malicious files I pointed out are there.

Delete them, let me know how it goes.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34918
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : 7 Home Premium x64
Points Points : 245091
# Likes # Likes : 1

View user profile

Back to top Go down

Re: New Trojans (AVCare) has disabled internet and everything el

Post by reeldeel on 10th August 2009, 10:00 pm

I deleted the two files and still cannot run anything. When I try to connect to the internet, windows doesn't have permission to connect to the router. Without connecting to the internet this seems doomed. When I download something on my computer and try to put it on a cd it says all of the file can't be copied and then it doesn't run on my sons computer. I'm getting desperate, been stuck with this since Friday.

reeldeel
Intermediate
Intermediate

Posts Posts : 50
Joined Joined : 2009-07-20
OS OS : XP
Points Points : 27036
# Likes # Likes : 0

View user profile

Back to top Go down

Re: New Trojans (AVCare) has disabled internet and everything el

Post by Belahzur on 11th August 2009, 4:05 pm

Please download SystemLook from one of the links below and save it to your Desktop.
[You must be registered and logged in to see this link.]
[You must be registered and logged in to see this link.]

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:
    Code:

    :filefind
    scecli.dll
    netlogon.dll

  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34918
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : 7 Home Premium x64
Points Points : 245091
# Likes # Likes : 1

View user profile

Back to top Go down

Re: New Trojans (AVCare) has disabled internet and everything el

Post by reeldeel on 11th August 2009, 4:40 pm

Here it is:

SystemLook v1.0 by jpshortstuff (22.05.09)
Log created at 12:31 on 11/08/2009 by Mike (Administrator - Elevation successful)

========== filefind ==========

Searching for "scecli.dll"
C:\i386\scecli.dll --a--- 180224 bytes [15:16 01/10/2006] [09:00 10/08/2004] 0F78E27F563F2AAF74B91A49E2ABF19A
C:\WINDOWS\$NtServicePackUninstall$\scecli.dll -----c 180224 bytes [17:44 22/08/2008] [09:00 10/08/2004] 0F78E27F563F2AAF74B91A49E2ABF19A
C:\WINDOWS\ServicePackFiles\i386\scecli.dll ------ 181248 bytes [06:36 22/08/2008] [00:12 14/04/2008] A86BB5E61BF3E39B62AB4C7E7085A084
C:\WINDOWS\system32\scecli.dll --a--- 60928 bytes [08:18 16/08/2005] [00:12 14/04/2008] (Unable to calculate MD5)

Searching for "netlogon.dll"
C:\i386\netlogon.dll --a--- 407040 bytes [15:15 01/10/2006] [09:00 10/08/2004] 96353FCECBA774BB8DA74A1C6507015A
C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll -----c 407040 bytes [17:44 22/08/2008] [09:00 10/08/2004] 96353FCECBA774BB8DA74A1C6507015A
C:\WINDOWS\ServicePackFiles\i386\netlogon.dll ------ 407040 bytes [06:34 22/08/2008] [00:12 14/04/2008] 1B7F071C51B77C272875C3A23E1E4550
C:\WINDOWS\system32\netlogon.dll --a--- 407040 bytes [08:18 16/08/2005] [00:12 14/04/2008] 1B7F071C51B77C272875C3A23E1E4550

-=End Of File=-

reeldeel
Intermediate
Intermediate

Posts Posts : 50
Joined Joined : 2009-07-20
OS OS : XP
Points Points : 27036
# Likes # Likes : 0

View user profile

Back to top Go down

Re: New Trojans (AVCare) has disabled internet and everything el

Post by Belahzur on 11th August 2009, 4:52 pm

1. Please download The Avenger by Swandog46 to your Desktop
Link: [You must be registered and logged in to see this link.]

  • Click on Avenger.zip to open the file
  • Extract avenger.exe to your desktop
2. Copy all the text contained in the code box below to your Clipboard by highlighting it and pressing (Ctrl+CCrying


Files to delete:
C:\WINDOWS\system32\scecli.dll

Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.


3. Now, start The Avenger program by clicking on its icon on your desktop.

  • Under "Input script here:", paste in the script from the quote box above.
  • Leave the ticked box "Scan for rootkit" ticked.
  • Then tick "Disable any rootkits found"
  • Now click on the Execute to begin execution of the script.
  • Answer "Yes" twice when prompted.

    The Avenger will automatically do the following:

  • It will Restart your computer.
  • On reboot, it will briefly open a black command window on your desktop, this is normal.
  • After the restart, it creates a log file that should open with the results of Avengerís actions. This log file will be located at C:\avenger.txt
  • The Avenger will also have backed up all the files, etc., that you asked it to delete, and will have zipped them and moved the zip archives to C:\avenger\backup.zip.
4. Please copy/paste the content of c:\avenger.txt into your reply.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34918
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : 7 Home Premium x64
Points Points : 245091
# Likes # Likes : 1

View user profile

Back to top Go down

Re: New Trojans (AVCare) has disabled internet and everything el

Post by reeldeel on 11th August 2009, 5:20 pm

Here it is:

Logfile of The Avenger Version 2.0, (c) by Swandog46
[You must be registered and logged in to see this link.]

Platform: Windows XP

*******************

Script file opened successfully.
Script file read successfully.

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

Rootkit scan active.
No rootkits found!

File "c:\windows\system32\scecli.dll" deleted successfully.

Completed script processing.

*******************

Finished! Terminate.

Just wanted to add that nothing changed Evil or enraged I am so angry, this is go

reeldeel
Intermediate
Intermediate

Posts Posts : 50
Joined Joined : 2009-07-20
OS OS : XP
Points Points : 27036
# Likes # Likes : 0

View user profile

Back to top Go down

Re: New Trojans (AVCare) has disabled internet and everything el

Post by Belahzur on 11th August 2009, 5:33 pm

Hello.
I know nothing has changed, that's because the avenger script wasn't mean to fix it, it just deleted a patched file that was causing all the programs to fail running.

Now it's gone, we can really give it the hammer.
Please download Hijack This from here:
[You must be registered and logged in to see this link.]

Download and run. Do a system scan with logfile, copy/paste the log back here.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34918
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : 7 Home Premium x64
Points Points : 245091
# Likes # Likes : 1

View user profile

Back to top Go down

Re: New Trojans (AVCare) has disabled internet and everything el

Post by reeldeel on 11th August 2009, 5:59 pm

Okay couldn't run HT as winlogon but instead got MBAB to run renamed as winlogon. Running a full scan now, I am soooo sick of this.

reeldeel
Intermediate
Intermediate

Posts Posts : 50
Joined Joined : 2009-07-20
OS OS : XP
Points Points : 27036
# Likes # Likes : 0

View user profile

Back to top Go down

Re: New Trojans (AVCare) has disabled internet and everything el

Post by Belahzur on 11th August 2009, 6:10 pm

Your not the only one, this malware is brand new from the bad guys factory, took me nearly 4 days to figure out what it was and how to kill it with a little help.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34918
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : 7 Home Premium x64
Points Points : 245091
# Likes # Likes : 1

View user profile

Back to top Go down

Re: New Trojans (AVCare) has disabled internet and everything el

Post by reeldeel on 11th August 2009, 7:12 pm

Finally got hijack this to run...here is the logfile:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:02:55 PM, on 8/11/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\acs.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\dllhost.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\stsystra.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\Veoh Networks\Veoh\VeohClient.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\IObit\Advanced SystemCare 3\Awc.exe
C:\WINDOWS\system32\ctfmon.exe
D:\winlogon.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = [You must be registered and logged in to see this link.]
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = [You must be registered and logged in to see this link.]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = [You must be registered and logged in to see this link.]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = [You must be registered and logged in to see this link.]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = [You must be registered and logged in to see this link.]
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = [You must be registered and logged in to see this link.]
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = [You must be registered and logged in to see this link.]
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = [You must be registered and logged in to see this link.]
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {15418036-6DF1-3427-A9CA-15A3E0FCAC9E} - (no file)
O2 - BHO: (no name) - {636EEDCA-5100-0AD9-5165-2F00CACD8DC9} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: (no name) - {BAA68C48-6589-3A5B-DA58-4CE604840E94} - (no file)
O2 - BHO: (no name) - {C18B4EDC-F543-A590-17E4-D78F72092994} - (no file)
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Veoh] "C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" /VeohHide
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [Advanced SystemCare 3] "C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe" /startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: NETGEAR WPN311 Wireless Assistant.lnk = C:\Program Files\NETGEAR\WPN311\wlancfg5.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - [You must be registered and logged in to see this link.]
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - [You must be registered and logged in to see this link.]
O16 - DPF: {77538FC7-CE52-4704-9865-494FE92BC320} (LaunchUBO.Ulit) - [You must be registered and logged in to see this link.]
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\acs.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\system32\GameMon.des.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

--
End of file - 9516 bytes

reeldeel
Intermediate
Intermediate

Posts Posts : 50
Joined Joined : 2009-07-20
OS OS : XP
Points Points : 27036
# Likes # Likes : 0

View user profile

Back to top Go down

Re: New Trojans (AVCare) has disabled internet and everything el

Post by Belahzur on 11th August 2009, 7:17 pm

Hello.

  • Download combofix from here
    [You must be registered and logged in to see this link.]
    [You must be registered and logged in to see this link.]

    1. If you are using Firefox, make sure that your download settings are as follows:

    * Tools->Options->Main tab
    * Set to "Always ask me where to Save the files".

    2. During the download, rename Combofix to Combo-Fix as follows:





    3. It is important you rename Combofix during the download, but not after.
    4. Please do not rename Combofix to other names, but only to the one indicated.
    5. Close any open browsers.
    6. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

  • We need to disable your local AV (Anti-virus) before running Combofix.
  • See [You must be registered and logged in to see this link.] for how to disable your AV.
  • Double click on ComboFix.exe.
  • Follow the prompts. NOTE:
  • ComboFix will check to see if the Microsoft Windows Recovery Console is installed.
    ***It's strongly recommended to have the Recovery Console installed before doing any malware removal.***

    **Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will automatically proceed with its scan.


  • The Recovery Console provides a recovery/repair mode should a problem occur during a Combofix run.



  • Allow ComboFix to download the Recovery Console.
  • Accept the End-User License Agreement.
  • The Recovery Console will be installed.
  • You will then get this next prompt that asks if you want to continue the malware scan, select yes



  • Allow combofix to run
  • Post C:\combofix.txt back here.

    Note:
    Do not mouseclick combofix's window whilst it's running. That may cause it to stall.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34918
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : 7 Home Premium x64
Points Points : 245091
# Likes # Likes : 1

View user profile

Back to top Go down

Re: New Trojans (AVCare) has disabled internet and everything el

Post by reeldeel on 11th August 2009, 7:20 pm

I did a combo-fix about an hour ago and it found nothing!!!! Is this a new version?

reeldeel
Intermediate
Intermediate

Posts Posts : 50
Joined Joined : 2009-07-20
OS OS : XP
Points Points : 27036
# Likes # Likes : 0

View user profile

Back to top Go down

Re: New Trojans (AVCare) has disabled internet and everything el

Post by Belahzur on 11th August 2009, 7:24 pm

Hello.
Yes, we tried it before but the malware was corrupting it. The infected file was also a legit file and needs replacing, that's why we need Combofix.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34918
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : 7 Home Premium x64
Points Points : 245091
# Likes # Likes : 1

View user profile

Back to top Go down

Re: New Trojans (AVCare) has disabled internet and everything el

Post by reeldeel on 11th August 2009, 8:45 pm

Here is a combo-fix logfile. Still can't do anything, MBAB found nothing.

ComboFix 09-08-10.06 - Mike 08/11/2009 15:31.6.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1470.842 [GMT -4:00]
Running from: D:\Combo-Fix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\docume~1\Mike\LOCALS~1\Temp\catchme.dll
c:\documents and settings\Mike\Local Settings\temp\catchme.dll
.
---- Previous Run -------
.
c:\docume~1\Mike\LOCALS~1\Temp\catchme.dll
c:\documents and settings\Mike\Local Settings\temp\catchme.dll

Infected copy of c:\windows\system32\scecli.dll was found and disinfected
Restored copy from - c:\windows\ServicePackFiles\i386\scecli.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226ED}
-------\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226EE}


((((((((((((((((((((((((( Files Created from 2009-07-11 to 2009-08-11 )))))))))))))))))))))))))))))))
.

2009-08-11 19:35 . 2008-04-14 00:12 181248 ----a-w- c:\windows\system32\scecli.dll
2009-08-11 18:57 . 2009-08-11 18:57 -------- d-----w- c:\program files\Yahoo!
2009-08-11 18:37 . 2009-03-17 17:26 65320 ----a-w- c:\windows\system32\sbbd.exe
2009-08-11 18:37 . 2008-10-22 21:08 92464 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2009-08-11 18:36 . 2009-08-11 18:52 -------- d-----w- C:\VIPRERESCUE
2009-08-11 15:31 . 2009-08-11 15:31 -------- d-----w- c:\documents and settings\Mike\Application Data\IObit
2009-08-11 15:31 . 2009-08-11 15:31 -------- d-----w- c:\program files\IObit
2009-08-11 14:09 . 2009-08-11 18:54 -------- d-----w- c:\program files\Wise Registry Cleaner
2009-07-22 21:01 . 2009-08-11 14:16 -------- d-----w- c:\program files\Free Window Registry Repair
2009-07-14 05:52 . 2009-07-14 05:52 45056 --sha-r- c:\windows\system32\flashd.dll
2009-07-14 05:51 . 2009-07-14 05:51 -------- d-sh--w- c:\windows\System Volume Information

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-11 17:41 . 2009-06-16 19:11 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-08-08 21:25 . 2007-12-06 18:43 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-08-08 21:25 . 2007-12-04 22:57 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-08-07 02:23 . 2009-08-07 02:22 96147 ----a-w- c:\windows\system32\xa.tmp
2009-08-06 16:39 . 2009-07-10 14:14 3942048 ----a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-07-29 01:09 . 2009-06-17 00:12 335752 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-07-15 16:56 . 2009-08-07 02:42 178482 ----a-w- c:\windows\pchealth\helpctr\Config\Cache\Professional_32_1033.dat
2009-07-01 20:27 . 2009-06-17 00:12 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-06-26 16:50 . 2005-08-16 08:18 666624 ----a-w- c:\windows\system32\wininet.dll
2009-06-26 16:50 . 2005-08-16 08:18 81920 ----a-w- c:\windows\system32\ieencode.dll
2009-06-18 21:34 . 2009-06-18 21:34 -------- d-----w- c:\documents and settings\Mike\Application Data\Malwarebytes
2009-06-18 20:13 . 2006-09-26 22:53 -------- d-----w- c:\documents and settings\All Users\Application Data\Viewpoint
2009-06-18 20:13 . 2006-09-26 22:53 -------- d-----w- c:\program files\Viewpoint
2009-06-18 14:00 . 2009-06-17 00:12 -------- d-----w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar
2009-06-17 02:05 . 2005-08-17 00:54 -------- d-----w- c:\program files\DIGStream
2009-06-17 01:11 . 2007-12-01 18:42 -------- d-----w- c:\documents and settings\Mike\Application Data\??mbols
2009-06-17 00:12 . 2009-06-17 00:12 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-06-17 00:12 . 2009-06-17 00:12 108552 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-06-17 00:12 . 2009-06-17 00:12 -------- d-----w- c:\program files\AVG
2009-06-17 00:12 . 2009-06-17 00:12 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
2009-06-16 19:41 . 2009-06-16 19:41 -------- d-----w- c:\documents and settings\Mike\Application Data\Safer Networking
2009-06-16 19:40 . 2009-06-16 19:40 -------- d-----w- c:\program files\Safer Networking
2009-06-16 19:11 . 2009-06-16 19:11 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-06-16 14:36 . 2005-08-16 08:18 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-06-16 14:36 . 2005-08-16 08:18 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-06-16 02:37 . 2009-06-13 03:13 664 ----a-w- c:\windows\system32\d3d9caps.dat
2009-06-08 01:23 . 2006-11-08 19:02 2772 --sha-w- c:\windows\system32\KGyGaAvL.sys
2009-06-03 19:09 . 2005-08-16 08:18 1291264 ----a-w- c:\windows\system32\quartz.dll
2009-06-02 17:37 . 2009-06-18 14:00 1004800 ----a-w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar\IEToolbar.dll
2009-05-26 17:20 . 2009-06-16 19:11 40160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-05-26 17:19 . 2009-06-16 19:11 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2007-01-20 21:15 . 2006-11-08 19:02 88 --sh--r- c:\windows\system32\94BCC40415.sys
2007-01-27 12:21 . 2007-01-27 12:21 8 --sh--r- c:\windows\system32\E3956F3170.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-06-16 1004800]

[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-06-16 13:29 1004800 ----a-w- c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-06-16 1004800]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-06-16 1004800]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-04 68856]
"Veoh"="c:\program files\Veoh Networks\Veoh\VeohClient.exe" [2007-12-03 3461120]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"DellSupport"="c:\program files\Dell Support\DSAgnt.exe" [2006-07-17 389120]
"Advanced SystemCare 3"="c:\program files\IObit\Advanced SystemCare 3\AWC.exe" [2009-06-30 2329224]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-06-17 1948440]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-03-29 413696]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-08-23 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-08-23 7630848]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-03-30 267048]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-08-11 81920]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-08-11 249856]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-09-29 67584]
"DMXLauncher"="c:\program files\Dell\Media Experience\DMXLauncher.exe" [2005-10-05 94208]
"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2005-09-08 122940]
"SigmatelSysTrayApp"="stsystra.exe" - c:\windows\stsystra.exe [2006-08-15 282624]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2006-08-23 1617920]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2006-9-26 24576]
NETGEAR WPN311 Wireless Assistant.lnk - c:\program files\NETGEAR\WPN311\wlancfg5.exe [2005-4-19 4521984]
WinZip Quick Pick.lnk - c:\program files\WinZip\WZQKPICK.EXE [2007-4-11 394856]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoPopUpsOnBoot"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-06-17 00:12 11952 ----a-w- c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal

reeldeel
Intermediate
Intermediate

Posts Posts : 50
Joined Joined : 2009-07-20
OS OS : XP
Points Points : 27036
# Likes # Likes : 0

View user profile

Back to top Go down

Re: New Trojans (AVCare) has disabled internet and everything el

Post by reeldeel on 11th August 2009, 8:45 pm

Part 2

\aawservice]
@="Service"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"c:\\Program Files\\America Online 9.0\\waol.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Veoh Networks\\Veoh\\VeohClient.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\NCsoft\\Exteel\\System\\Exteel.exe"=
"c:\\StubInstaller.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\My Music\\World of Warcraft\\BackgroundDownloader.exe"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"c:\\My Music\\World of Warcraft\\WoW-3.0.8.9506-to-3.0.9.9551-enUS-downloader.exe"=
"c:\\My Music\\World of Warcraft\\WoW-3.0.9.9551-to-3.1.0.9767-enUS-downloader.exe"=
"c:\\My Music\\World of Warcraft\\Launcher.exe"=
"c:\\My Music\\World of Warcraft\\WoW-3.1.0.9767-to-3.1.1.9806-enUS-downloader.exe"=
"c:\\My Music\\World of Warcraft\\WoW-3.1.1.9835-to-3.1.2.9901-enUS-downloader.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\My Music\\World of Warcraft\\WoW-3.1.3.9947-to-3.2.0.10192-enUS-downloader.exe"=
"%windir%\\system32\\drivers\\svchost.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [6/16/2009 8:12 PM 335752]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [6/16/2009 8:12 PM 108552]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [6/16/2009 8:12 PM 298776]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service --> c:\windows\system32\GameMon.des -service [?]
S3 SBRE;SBRE;c:\windows\system32\drivers\SBREDrv.sys [8/11/2009 2:37 PM 92464]
.
Contents of the 'Scheduled Tasks' folder

2009-07-25 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 21:57]
.
- - - - ORPHANS REMOVED - - - -

BHO-{15418036-6DF1-3427-A9CA-15A3E0FCAC9E} - (no file)
BHO-{636EEDCA-5100-0AD9-5165-2F00CACD8DC9} - (no file)
BHO-{BAA68C48-6589-3A5B-DA58-4CE604840E94} - (no file)
BHO-{C18B4EDC-F543-A590-17E4-D78F72092994} - (no file)


.
------- Supplementary Scan -------
.
mStart Page = [You must be registered and logged in to see this link.]
uSearchURL,(Default) = [You must be registered and logged in to see this link.]
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
Trusted Zone: musicmatch.com\online
DPF: {77538FC7-CE52-4704-9865-494FE92BC320} - [You must be registered and logged in to see this link.]
FF - ProfilePath - c:\documents and settings\Mike\Application Data\Mozilla\Firefox\Profiles\nblphn3z.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo! Search
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\xpavgtbapi.dll
FF - plugin: c:\documents and settings\All Users\Application Data\NexonUS\NGM\npNxGameUS.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava11.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava12.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava13.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava14.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava32.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJPI150_06.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPOJI610.dll
FF - plugin: c:\program files\Veoh Networks\Veoh\Plugins\noreg\NPVeohVersion.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [You must be registered and logged in to see this link.]
Rootkit scan 2009-08-11 15:41
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Lavasoft\Ad-Aware 2007\aawservice.exe
c:\windows\system32\acs.exe
c:\progra~1\COMMON~1\AOL\ACS\AOLacsd.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\ehome\ehrecvr.exe
c:\windows\ehome\ehSched.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\nvsvc32.exe
c:\windows\ehome\mcrdsvc.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\windows\system32\dllhost.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\rundll32.exe
c:\windows\ehome\ehmsas.exe
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2009-08-11 15:44 - machine was rebooted
ComboFix-quarantined-files.txt 2009-08-11 19:44

Pre-Run: 26,635,407,360 bytes free
Post-Run: 26,600,960,000 bytes free

225 --- E O F --- 2009-07-29 06:18

reeldeel
Intermediate
Intermediate

Posts Posts : 50
Joined Joined : 2009-07-20
OS OS : XP
Points Points : 27036
# Likes # Likes : 0

View user profile

Back to top Go down

Re: New Trojans (AVCare) has disabled internet and everything el

Post by reeldeel on 11th August 2009, 8:47 pm

There is something hiding somewhere that won't let me access my router or a bunch of other files. Windows still does not have permission. This is crazy.

reeldeel
Intermediate
Intermediate

Posts Posts : 50
Joined Joined : 2009-07-20
OS OS : XP
Points Points : 27036
# Likes # Likes : 0

View user profile

Back to top Go down

Re: New Trojans (AVCare) has disabled internet and everything el

Post by Belahzur on 11th August 2009, 8:51 pm

Now open a new notepad file.
Input this into the notepad file:

File::
c:\windows\system32\flashd.dll
c:\windows\system32\xa.tmp

Driver::
npggsvc

Registry::
[-HKEY_LOCAL_MACHINE\System\ControlSet002\Services\npggsvc]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\StubInstaller.exe"=-
"%windir%\\system32\\drivers\\svchost.exe"=-

Save this as CFScript.txt, save it to your desktop also.
Then drag and drop CFScript.txt into combofix as seen below:


This will open combofix again, agree to it's terms and allow it to run.
It may want to reboot after it's done. (It will warn you if it wants to)
Post the resulting log back here.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34918
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : 7 Home Premium x64
Points Points : 245091
# Likes # Likes : 1

View user profile

Back to top Go down

Re: New Trojans (AVCare) has disabled internet and everything el

Post by reeldeel on 11th August 2009, 9:08 pm

IT'S TELLING ME that CFScript.txt IS INCORRECTLY SPELT AND CANNOT RUN> I GIVE UP!!!!!!!

reeldeel
Intermediate
Intermediate

Posts Posts : 50
Joined Joined : 2009-07-20
OS OS : XP
Points Points : 27036
# Likes # Likes : 0

View user profile

Back to top Go down

Re: New Trojans (AVCare) has disabled internet and everything el

Post by Belahzur on 11th August 2009, 9:11 pm

Hello.
Don't give up just yet, we have other tools we can use.

Please download the [You must be registered and logged in to see this link.].

  • Save it to your desktop.
  • Please double-click OTM.exe to run it.
  • Copy the bolded text below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose CopyCrying


    :services
    npggsvc

    :files
    c:\windows\system32\flashd.dll
    c:\windows\system32\xa.tmp

    :reg
    [-HKEY_LOCAL_MACHINE\System\ControlSet002\Services\npggsvc]
    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "c:\\StubInstaller.exe"=-
    "%windir%\\system32\\drivers\\svchost.exe"=-


  • Return to OTMoveIt, right click in the "Paste instructions for items to be Moved" window (under the light blue bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.

Please post the OTMoveIt log.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34918
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : 7 Home Premium x64
Points Points : 245091
# Likes # Likes : 1

View user profile

Back to top Go down

Re: New Trojans (AVCare) has disabled internet and everything el

Post by reeldeel on 11th August 2009, 9:15 pm

all lower case letters on cfscript works....running new combofix

reeldeel
Intermediate
Intermediate

Posts Posts : 50
Joined Joined : 2009-07-20
OS OS : XP
Points Points : 27036
# Likes # Likes : 0

View user profile

Back to top Go down

Re: New Trojans (AVCare) has disabled internet and everything el

Post by reeldeel on 11th August 2009, 9:21 pm

ran combofix....still can't do anything. will try otm. In have to put it on a cd.

reeldeel
Intermediate
Intermediate

Posts Posts : 50
Joined Joined : 2009-07-20
OS OS : XP
Points Points : 27036
# Likes # Likes : 0

View user profile

Back to top Go down

Re: New Trojans (AVCare) has disabled internet and everything el

Post by reeldeel on 11th August 2009, 9:38 pm

Tried OTM....all of the files were not found....every last one.

reeldeel
Intermediate
Intermediate

Posts Posts : 50
Joined Joined : 2009-07-20
OS OS : XP
Points Points : 27036
# Likes # Likes : 0

View user profile

Back to top Go down

Re: New Trojans (AVCare) has disabled internet and everything el

Post by reeldeel on 12th August 2009, 1:33 am

I forgot to add that even after all of these fixes, AVG is still disabled. No scan button and MBAM finds nothing.

reeldeel
Intermediate
Intermediate

Posts Posts : 50
Joined Joined : 2009-07-20
OS OS : XP
Points Points : 27036
# Likes # Likes : 0

View user profile

Back to top Go down

Re: New Trojans (AVCare) has disabled internet and everything el

Post by Belahzur on 12th August 2009, 5:19 pm

Hello.
AVG is corrupted by this malware, you'll need to uninstall, then re-install it. Probably have to download the new version too.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34918
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : 7 Home Premium x64
Points Points : 245091
# Likes # Likes : 1

View user profile

Back to top Go down

Re: New Trojans (AVCare) has disabled internet and everything el

Post by reeldeel on 12th August 2009, 7:36 pm

Can I put it on a CD from my mom's computer because once again, I don't have internet access si can't download anything.

reeldeel
Intermediate
Intermediate

Posts Posts : 50
Joined Joined : 2009-07-20
OS OS : XP
Points Points : 27036
# Likes # Likes : 0

View user profile

Back to top Go down

Re: New Trojans (AVCare) has disabled internet and everything el

Post by reeldeel on 12th August 2009, 8:28 pm

Cannot uninstall AVG. I get an error message about a file called avgrexs.exe or something close to that. I get 3 error messages and warnings when trying to uninstall and it just stops. OTM did not work, could not find the files I had input. Are there any other tools or is this irreparable?
By the way thanks for the help and I will donate on payday.

reeldeel
Intermediate
Intermediate

Posts Posts : 50
Joined Joined : 2009-07-20
OS OS : XP
Points Points : 27036
# Likes # Likes : 0

View user profile

Back to top Go down

Re: New Trojans (AVCare) has disabled internet and everything el

Post by Belahzur on 12th August 2009, 9:23 pm

Hello.
Please do not use our tools without me watching over you or giving you instructions to, OTM is a powerful program and can result in damage to the machine.

As I said, AVG is corrupted that's why it's refusing to go away, so we'll use this external AVG uninstall:

Completely Uninstall AVG software

Download and run avgremover.exe

For 32-Bit, Download: [You must be registered and logged in to see this link.]

After running that, we'll need to replace your AVG with something else.

Please install Avira antivirus otherwise you won't be protected.

1) [You must be registered and logged in to see this link.]
-Free anti-virus software for Windows.
-Detects and removes more than 50,000 viruses. Free support.

It is strongly recommended that you run only one antivirus program at a time. Having more than one antivirus program active in memory uses additional resources and can result in program conflicts and false virus alerts.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34918
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : 7 Home Premium x64
Points Points : 245091
# Likes # Likes : 1

View user profile

Back to top Go down

Re: New Trojans (AVCare) has disabled internet and everything el

Post by reeldeel on 12th August 2009, 9:43 pm

I STARTED THE AVG REMOVER AND IT REBOOTED THE COMPUTER AND NOTHING HAPPENED AFTER REBOOT. I TRIED TO RUN AGAIN AND THE BLACK SCREEN DISAPPEARS AFTER 2 SECONDS. IT CAUGHT ON TO WHAT I'M TRYING TO DO. MAYBE IT IS HIDING IN AVG SOMEWHERE. ANY OTHER SUGGESTIONS. I'M ABOUT TO CRY!!!!!!!!!

reeldeel
Intermediate
Intermediate

Posts Posts : 50
Joined Joined : 2009-07-20
OS OS : XP
Points Points : 27036
# Likes # Likes : 0

View user profile

Back to top Go down

Re: New Trojans (AVCare) has disabled internet and everything el

Post by Belahzur on 12th August 2009, 9:54 pm

Dont' give up, because I haven't given up.


  • Please download DDS by sUBs to your Desktop (Important!!) from one of these locations:
    [You must be registered and logged in to see this link.]
    [You must be registered and logged in to see this link.]
  • Double click DDS.scr to run.
  • When complete, two logs will open. Save both of the report to your Desktop.
  • Copy and paste DDS.txt back here, I don't need to see attach.txt.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34918
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : 7 Home Premium x64
Points Points : 245091
# Likes # Likes : 1

View user profile

Back to top Go down

Re: New Trojans (AVCare) has disabled internet and everything el

Post by reeldeel on 12th August 2009, 10:14 pm

Here is the dds.txt:

DDS (Ver_09-07-30.01) - NTFSx86
Run by Mike at 18:10:04.92 on Wed 08/12/2009
Internet Explorer: 6.0.2900.5512
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1470.1032 [GMT -4:00]


============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\acs.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\stsystra.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\Veoh Networks\Veoh\VeohClient.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\WinZip\WZQKPICK.EXE
svchost.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\eHome\ehmsas.exe
D:\dds.scr

============== Pseudo HJT Report ===============

mStart Page = [You must be registered and logged in to see this link.]
uSearchURL,(Default) = [You must be registered and logged in to see this link.]
uURLSearchHooks: H - No File
uURLSearchHooks: H - No File
uURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg8\toolbar\IEToolbar.dll
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.5.0_06\bin\ssv.dll
BHO: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg8\toolbar\IEToolbar.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.3572\swg.dll
BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_219B3E1547538286.dll
TB: &Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar.dll
TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - c:\program files\avg\avg8\toolbar\IEToolbar.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe
uRun: [Veoh] "c:\program files\veoh networks\veoh\VeohClient.exe" /VeohHide
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [DellSupport] "c:\program files\dell support\DSAgnt.exe" /startup
uRun: [Advanced SystemCare 3] "c:\program files\iobit\advanced systemcare 3\AWC.exe" /startup
mRun: [SigmatelSysTrayApp] stsystra.exe
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [nwiz] nwiz.exe /install
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [ISUSPM Startup] "c:\program files\common files\installshield\updateservice\isuspm.exe" -startup
mRun: [ehTray] c:\windows\ehome\ehtray.exe
mRun: [DMXLauncher] c:\program files\dell\media experience\DMXLauncher.exe
mRun: [DLA] c:\windows\system32\dla\DLACTRLW.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\netgea~1.lnk - c:\program files\netgear\wpn311\wlancfg5.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\winzip~1.lnk - c:\program files\winzip\WZQKPICK.EXE
mPolicies-explorer: NoPopUpsOnBoot = 1 (0x1)
IE: E&xport to Microsoft Excel - c:\progra~1\mi1933~1\office11\EXCEL.EXE/3000
IE: {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - c:\program files\aim\aim.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBC} - c:\program files\java\jre1.5.0_06\bin\ssv.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\mi1933~1\office11\REFIEBAR.DLL
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
Trusted Zone: musicmatch.com\online
DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - [You must be registered and logged in to see this link.]
DPF: {77538FC7-CE52-4704-9865-494FE92BC320} - [You must be registered and logged in to see this link.]
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - [You must be registered and logged in to see this link.]
DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - [You must be registered and logged in to see this link.]
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - [You must be registered and logged in to see this link.]
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - [You must be registered and logged in to see this link.]
Notify: avgrsstarter - avgrsstx.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\mike\applic~1\mozilla\firefox\profiles\nblphn3z.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo! Search
FF - component: c:\program files\avg\avg8\firefox\components\avgssff.dll
FF - component: c:\program files\avg\avg8\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\avg\avg8\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\avg\avg8\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\avg\avg8\toolbar\firefox\avg@igeared\components\xpavgtbapi.dll
FF - plugin: c:\documents and settings\all users\application data\nexonus\ngm\npNxGameUS.dll
FF - plugin: c:\program files\java\jre1.5.0_06\bin\NPJava11.dll
FF - plugin: c:\program files\java\jre1.5.0_06\bin\NPJava12.dll
FF - plugin: c:\program files\java\jre1.5.0_06\bin\NPJava13.dll
FF - plugin: c:\program files\java\jre1.5.0_06\bin\NPJava14.dll
FF - plugin: c:\program files\java\jre1.5.0_06\bin\NPJava32.dll
FF - plugin: c:\program files\java\jre1.5.0_06\bin\NPJPI150_06.dll
FF - plugin: c:\program files\java\jre1.5.0_06\bin\NPOJI610.dll
FF - plugin: c:\program files\veoh networks\veoh\plugins\noreg\NPVeohVersion.dll

============= SERVICES / DRIVERS ===============

R2 aawservice;Ad-Aware 2007 Service;c:\program files\lavasoft\ad-aware 2007\aawservice.exe [2007-7-6 561152]
R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328]
S2 PEVSystemStart;PEVSystemStart;cmd /k start /i "/dC:" "c:\combo-fix\hidec.exe" "c:\windows\system32\cf26555.exe" /c rd /s/q \$recycle.bin \recycler \RECYCLED --> cmd [?]
S3 SBRE;SBRE;c:\windows\system32\drivers\SBREDrv.sys [2009-8-11 92464]

=============== Created Last 30 ================

2009-08-12 16:00 --d----- c:\docume~1\alluse~1\applic~1\AVG Security Toolbar
2009-08-11 15:35 181,248 a------- c:\windows\system32\scecli.dll
2009-08-11 14:57 --d----- c:\program files\Yahoo!
2009-08-11 14:37 92,464 a------- c:\windows\system32\drivers\SBREDrv.sys
2009-08-11 14:37 65,320 a------- c:\windows\system32\sbbd.exe
2009-08-11 14:36 --d----- C:\VIPRERESCUE
2009-08-11 14:24 161,792 a------- c:\windows\SWREG.exe
2009-08-11 14:24 98,816 a------- c:\windows\sed.exe
2009-08-11 12:35 54,156 a---h--- c:\windows\QTFont.qfn
2009-08-11 12:35 1,409 a------- c:\windows\QTFont.for
2009-08-11 11:31 --d----- c:\docume~1\mike\applic~1\IObit
2009-08-11 11:31 --d----- c:\program files\IObit
2009-08-11 10:09 --d----- c:\program files\Wise Registry Cleaner
2009-07-22 17:01 --d----- c:\program files\Free Window Registry Repair
2009-07-14 08:07 --d----- c:\windows\system32\dllcache\cache
2009-07-14 07:51 a-dshr-- C:\cmdcons
2009-07-14 07:46 216,064 a------- c:\windows\PEV.exe
2009-07-14 01:51 --dsh--- c:\windows\System Volume Information
2009-07-14 01:51 2 a------- C:\1552315473

==================== Find3M ====================

2009-07-18 12:05 3,069,440 a------- c:\windows\system32\dllcache\cache\mshtml.dll
2009-07-18 12:05 3,069,440 -------- c:\windows\system32\dllcache\mshtml.dll
2009-07-18 12:05 1,509,888 -------- c:\windows\system32\dllcache\shdocvw.dll
2009-07-15 12:56 178,482 a------- c:\windows\pchealth\helpctr\config\cache\Professional_32_1033.dat
2009-06-26 12:50 666,624 a------- c:\windows\system32\wininet.dll
2009-06-26 12:50 666,624 a------- c:\windows\system32\dllcache\cache\wininet.dll
2009-06-26 12:50 666,624 -------- c:\windows\system32\dllcache\wininet.dll
2009-06-26 12:50 620,032 -------- c:\windows\system32\dllcache\urlmon.dll
2009-06-26 12:50 81,920 a------- c:\windows\system32\ieencode.dll
2009-06-26 12:50 81,920 -------- c:\windows\system32\dllcache\ieencode.dll
2009-06-16 10:36 119,808 a------- c:\windows\system32\t2embed.dll
2009-06-16 10:36 81,920 a------- c:\windows\system32\fontsub.dll
2009-06-16 10:36 119,808 -------- c:\windows\system32\dllcache\t2embed.dll
2009-06-16 10:36 81,920 -------- c:\windows\system32\dllcache\fontsub.dll
2009-06-07 21:23 2,772 a--sh--- c:\windows\system32\KGyGaAvL.sys
2009-06-03 15:09 1,291,264 a------- c:\windows\system32\quartz.dll
2009-06-03 15:09 1,291,264 -------- c:\windows\system32\dllcache\quartz.dll
2005-03-29 14:37 456,384 a------- c:\windows\inf\wpn311\WPN311.sys
2005-01-27 10:59 35,232 a------- c:\windows\inf\wpn311\ME_INST.EXE
2005-01-27 10:59 26,112 a------- c:\windows\inf\wpn311\install.exe

============= FINISH: 18:10:26.50 ===============

reeldeel
Intermediate
Intermediate

Posts Posts : 50
Joined Joined : 2009-07-20
OS OS : XP
Points Points : 27036
# Likes # Likes : 0

View user profile

Back to top Go down

Re: New Trojans (AVCare) has disabled internet and everything el

Post by Belahzur on 13th August 2009, 12:04 am

Please download the [You must be registered and logged in to see this link.].

  • Save it to your desktop.
  • Please double-click OTM.exe to run it.
  • Copy the bolded text below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose CopyCrying


    :services
    PEVSystemStart

    :files
    c:\program files\avg
    c:\docume~1\alluse~1\applic~1\AVG Security Toolbar
    C:\1552315473

    :reg
    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
    "{a3bc75a2-1f87-4686-aa43-5347d756017c}"=-
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{a3bc75a2-1f87-4686-aa43-5347d756017c}]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    "{ccc7a320-b3ca-4199-b1a6-9f516dd69829}"=-
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\avgrsstarter]


  • Return to OTMoveIt, right click in the "Paste instructions for items to be Moved" window (under the light blue bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.

Please post the OTMoveIt log.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34918
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : 7 Home Premium x64
Points Points : 245091
# Likes # Likes : 1

View user profile

Back to top Go down

Re: New Trojans (AVCare) has disabled internet and everything el

Post by reeldeel on 13th August 2009, 12:32 pm

OTM log: I rebooted and all of the icons for AVG are still there.

========== SERVICES/DRIVERS ==========

Service\Driver PEVSystemStart deleted successfully.
========== FILES ==========
Folder move failed. c:\program files\AVG\AVG8\ToolbarIEcache scheduled to be moved on reboot.
Folder move failed. c:\program files\AVG\AVG8\ToolbarFF\Components scheduled to be moved on reboot.
Folder move failed. c:\program files\AVG\AVG8\ToolbarFF\Chrome\Cache scheduled to be moved on reboot.
Folder move failed. c:\program files\AVG\AVG8\ToolbarFF\Chrome scheduled to be moved on reboot.
Folder move failed. c:\program files\AVG\AVG8\ToolbarFF scheduled to be moved on reboot.
Folder move failed. c:\program files\AVG\AVG8\Toolbar.old scheduled to be moved on reboot.
Folder move failed. c:\program files\AVG\AVG8\Toolbar\Update scheduled to be moved on reboot.
Folder move failed. c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components scheduled to be moved on reboot.
Folder move failed. c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\chrome\skin scheduled to be moved on reboot.
Folder move failed. c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\chrome\icons\default scheduled to be moved on reboot.
Folder move failed. c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\chrome\icons scheduled to be moved on reboot.
Folder move failed. c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\chrome\content\libsex scheduled to be moved on reboot.
Folder move failed. c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\chrome\content\libs scheduled to be moved on reboot.
Folder move failed. c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\chrome\content\Languages scheduled to be moved on reboot.
Folder move failed. c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\chrome\content\html scheduled to be moved on reboot.
Folder move failed. c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\chrome\content\ex scheduled to be moved on reboot.
Folder move failed. c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\chrome\content\avg scheduled to be moved on reboot.
Folder move failed. c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\chrome\content scheduled to be moved on reboot.
Folder move failed. c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\chrome scheduled to be moved on reboot.
Folder move failed. c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared scheduled to be moved on reboot.
Folder move failed. c:\program files\AVG\AVG8\Toolbar\Firefox scheduled to be moved on reboot.
Folder move failed. c:\program files\AVG\AVG8\Toolbar scheduled to be moved on reboot.
Folder move failed. c:\program files\AVG\AVG8\Notification scheduled to be moved on reboot.
Folder move failed. c:\program files\AVG\AVG8\log scheduled to be moved on reboot.
Folder move failed. c:\program files\AVG\AVG8\IdentityProtection\agent\quarantine scheduled to be moved on reboot.
Folder move failed. c:\program files\AVG\AVG8\IdentityProtection\agent\profile scheduled to be moved on reboot.
Folder move failed. c:\program files\AVG\AVG8\IdentityProtection\agent\outbox\9 scheduled to be moved on reboot.
Folder move failed. c:\program files\AVG\AVG8\IdentityProtection\agent\outbox\8 scheduled to be moved on reboot.
Folder move failed. c:\program files\AVG\AVG8\IdentityProtection\agent\outbox\7 scheduled to be moved on reboot.
Folder move failed. c:\program files\AVG\AVG8\IdentityProtection\agent\outbox\6 scheduled to be moved on reboot.
Folder move failed. c:\program files\AVG\AVG8\IdentityProtection\agent\outbox\5 scheduled to be moved on reboot.
Folder move failed. c:\program files\AVG\AVG8\IdentityProtection\agent\outbox\4 scheduled to be moved on reboot.
Folder move failed. c:\program files\AVG\AVG8\IdentityProtection\agent\outbox\3 scheduled to be moved on reboot.
Folder move failed. c:\program files\AVG\AVG8\IdentityProtection\agent\outbox\2 scheduled to be moved on reboot.
Folder move failed. c:\program files\AVG\AVG8\IdentityProtection\agent\outbox\1 scheduled to be moved on reboot.
Folder move failed. c:\program files\AVG\AVG8\IdentityProtection\agent\outbox\0 scheduled to be moved on reboot.
Folder move failed. c:\program files\AVG\AVG8\IdentityProtection\agent\outbox scheduled to be moved on reboot.
Folder move failed. c:\program files\AVG\AVG8\IdentityProtection\agent\malwareprofile scheduled to be moved on reboot.
Folder move failed. c:\program files\AVG\AVG8\IdentityProtection\agent\log scheduled to be moved on reboot.
Folder move failed. c:\program files\AVG\AVG8\IdentityProtection\agent\driver\platform_XP scheduled to be moved on reboot.
Folder move failed. c:\program files\AVG\AVG8\IdentityProtection\agent\driver\platform_VISTA64 scheduled to be moved on reboot.
Folder move failed. c:\program files\AVG\AVG8\IdentityProtection\agent\driver\platform_VISTA scheduled to be moved on reboot.
Folder move failed. c:\program files\AVG\AVG8\IdentityProtection\agent\driver scheduled to be moved on reboot.
Folder move failed. c:\program files\AVG\AVG8\IdentityProtection\agent\download scheduled to be moved on reboot.
Folder move failed. c:\program files\AVG\AVG8\IdentityProtection\agent\config\EN_US scheduled to be moved on reboot.
Folder move failed. c:\program files\AVG\AVG8\IdentityProtection\agent\config scheduled to be moved on reboot.
Folder move failed. c:\program files\AVG\AVG8\IdentityProtection\agent\Bin\EN_US scheduled to be moved on reboot.
Folder move failed. c:\program files\AVG\AVG8\IdentityProtection\agent\Bin scheduled to be moved on reboot.
Folder move failed. c:\program files\AVG\AVG8\IdentityProtection\agent scheduled to be moved on reboot.
Folder move failed. c:\program files\AVG\AVG8\IdentityProtection scheduled to be moved on reboot.
Folder move failed. c:\program files\AVG\AVG8\Icons scheduled to be moved on reboot.
Folder move failed. c:\program files\AVG\AVG8\Firefox\Components scheduled to be moved on reboot.
Folder move failed. c:\program files\AVG\AVG8\Firefox\Chrome scheduled to be moved on reboot.
Folder move failed. c:\program files\AVG\AVG8\Firefox scheduled to be moved on reboot.
Folder move failed. c:\program files\AVG\AVG8\Drivers\avgfwd scheduled to be moved on reboot.
Folder move failed. c:\program files\AVG\AVG8\Drivers scheduled to be moved on reboot.
Folder move failed. c:\program files\AVG\AVG8 scheduled to be moved on reboot.
Folder move failed. c:\program files\AVG scheduled to be moved on reboot.
Folder move failed. c:\docume~1\alluse~1\applic~1\AVG Security Toolbar\Languages scheduled to be moved on reboot.
Folder move failed. c:\docume~1\alluse~1\applic~1\AVG Security Toolbar scheduled to be moved on reboot.
File move failed. C:\1552315473 scheduled to be moved on reboot.
========== REGISTRY ==========
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks\\{a3bc75a2-1f87-4686-aa43-5347d756017c} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{a3bc75a2-1f87-4686-aa43-5347d756017c}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{a3bc75a2-1f87-4686-aa43-5347d756017c}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{a3bc75a2-1f87-4686-aa43-5347d756017c}\ not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{ccc7a320-b3ca-4199-b1a6-9f516dd69829} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\avgrsstarter\ deleted successfully.

OTM by OldTimer - Version 3.0.0.6 log created on 08132009_081948

reeldeel
Intermediate
Intermediate

Posts Posts : 50
Joined Joined : 2009-07-20
OS OS : XP
Points Points : 27036
# Likes # Likes : 0

View user profile

Back to top Go down

Re: New Trojans (AVCare) has disabled internet and everything el

Post by Belahzur on 13th August 2009, 4:16 pm

Hello.
Can you install Avira anyhow, because AVG isn't active anymore and you are currently running without any AV.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34918
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : 7 Home Premium x64
Points Points : 245091
# Likes # Likes : 1

View user profile

Back to top Go down

Re: New Trojans (AVCare) has disabled internet and everything el

Post by reeldeel on 13th August 2009, 4:43 pm

I'll try now.

reeldeel
Intermediate
Intermediate

Posts Posts : 50
Joined Joined : 2009-07-20
OS OS : XP
Points Points : 27036
# Likes # Likes : 0

View user profile

Back to top Go down

Re: New Trojans (AVCare) has disabled internet and everything el

Post by reeldeel on 13th August 2009, 6:04 pm

Tried to install Avira but it would not install, error message : setup cannot find the proper directory. Anything else. Still can't do anything. My mom put an updated malewarebytes on a cd for me. On her computer it reads as a malewarebytes icon, on mine the cd reads as a blank file shortcut. This thing has my hands tied from every angle. Anything that might possibly remove it is not allowed to run. What can I do now. Tonight is a full 7 days without my computer, nothing has worked! Especially frustrating is no internet access. My mom has put a crapload of stuff on a few cd's for me and none have worked, if only I could download them myself. Running back and forth from computer to computer is maddening.

reeldeel
Intermediate
Intermediate

Posts Posts : 50
Joined Joined : 2009-07-20
OS OS : XP
Points Points : 27036
# Likes # Likes : 0

View user profile

Back to top Go down

Re: New Trojans (AVCare) has disabled internet and everything el

Post by reeldeel on 14th August 2009, 1:37 am

Was able to install antivir and run it. Did so 3 times , took out tons of trojan and malware generators. Here is the last log with things that could not be removed because they are in locked files. Netgear is my wireless modem so that is why I can't get online. Is there any way to kill these files or unlock them and kill the bugs. If you need the other 2 logs let me know.

reeldeel
Intermediate
Intermediate

Posts Posts : 50
Joined Joined : 2009-07-20
OS OS : XP
Points Points : 27036
# Likes # Likes : 0

View user profile

Back to top Go down

Re: New Trojans (AVCare) has disabled internet and everything el

Post by Belahzur on 14th August 2009, 6:48 pm

Avira shows locked files, but they are locked for a reason, doesn't mean they are malicious however.
Can you post the Avira log?


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34918
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : 7 Home Premium x64
Points Points : 245091
# Likes # Likes : 1

View user profile

Back to top Go down

Re: New Trojans (AVCare) has disabled internet and everything el

Post by reeldeel on 14th August 2009, 7:20 pm

here it is:

Avira AntiVir Personal
Report file date: Thursday, August 13, 2009 18:58

Scanning for 1562564 virus strains and unwanted programs.

Licensee : Avira AntiVir Personal - FREE Antivirus
Serial number : 0000149996-ADJIE-0000001
Platform : Windows XP
Windows version : (Service Pack 3) [5.1.2600]
Boot mode : Normally booted
Username : SYSTEM
Computer name : THEDEEL

Version information:
BUILD.DAT : 9.0.0.407 17961 Bytes 7/29/2009 10:34:00
AVSCAN.EXE : 9.0.3.7 466689 Bytes 7/21/2009 18:36:14
AVSCAN.DLL : 9.0.3.0 40705 Bytes 2/27/2009 15:58:24
LUKE.DLL : 9.0.3.2 209665 Bytes 2/20/2009 16:35:49
LUKERES.DLL : 9.0.2.0 12033 Bytes 2/27/2009 15:58:52
ANTIVIR0.VDF : 7.1.0.0 15603712 Bytes 10/27/2008 17:30:36
ANTIVIR1.VDF : 7.1.4.132 5707264 Bytes 6/24/2009 14:21:42
ANTIVIR2.VDF : 7.1.4.253 1779200 Bytes 7/19/2009 03:08:01
ANTIVIR3.VDF : 7.1.5.19 139776 Bytes 7/23/2009 12:36:13
Engineversion : 8.2.0.228
AEVDF.DLL : 8.1.1.1 106868 Bytes 7/28/2009 18:31:50
AESCRIPT.DLL : 8.1.2.18 442746 Bytes 7/23/2009 14:59:39
AESCN.DLL : 8.1.2.4 127348 Bytes 7/23/2009 14:59:39
AERDL.DLL : 8.1.2.4 430452 Bytes 7/23/2009 14:59:39
AEPACK.DLL : 8.1.3.18 401783 Bytes 7/28/2009 18:31:50
AEOFFICE.DLL : 8.1.0.38 196987 Bytes 7/23/2009 14:59:39
AEHEUR.DLL : 8.1.0.143 1864055 Bytes 7/23/2009 14:59:39
AEHELP.DLL : 8.1.5.3 233846 Bytes 7/23/2009 14:59:39
AEGEN.DLL : 8.1.1.50 352629 Bytes 7/23/2009 14:59:39
AEEMU.DLL : 8.1.0.9 393588 Bytes 10/9/2008 19:32:40
AECORE.DLL : 8.1.7.6 184694 Bytes 7/23/2009 14:59:39
AEBB.DLL : 8.1.0.3 53618 Bytes 10/9/2008 19:32:40
AVWINLL.DLL : 9.0.0.3 18177 Bytes 12/12/2008 13:47:59
AVPREF.DLL : 9.0.0.1 43777 Bytes 12/5/2008 15:32:15
AVREP.DLL : 8.0.0.3 155905 Bytes 1/20/2009 19:34:28
AVREG.DLL : 9.0.0.0 36609 Bytes 12/5/2008 15:32:09
AVARKT.DLL : 9.0.0.3 292609 Bytes 3/24/2009 20:05:41
AVEVTLOG.DLL : 9.0.0.7 167169 Bytes 1/30/2009 15:37:08
SQLITE3.DLL : 3.6.1.0 326401 Bytes 1/28/2009 20:03:49
SMTPLIB.DLL : 9.2.0.25 28417 Bytes 2/2/2009 13:21:33
NETNT.DLL : 9.0.0.0 11521 Bytes 12/5/2008 15:32:10
RCIMAGE.DLL : 9.0.0.25 2438913 Bytes 5/15/2009 20:39:58
RCTEXT.DLL : 9.0.37.0 86785 Bytes 4/17/2009 15:19:48

Configuration settings for the scan:
Jobname.............................: Complete system scan
Configuration file..................: c:\program files\avira\antivir desktop\sysscan.avp
Logging.............................: low
Primary action......................: interactive
Secondary action....................: ignore
Scan master boot sector.............: on
Scan boot sector....................: on
Boot sectors........................: C:,
Process scan........................: on
Scan registry.......................: on
Search for rootkits.................: on
Integrity checking of system files..: off
Scan all files......................: All files
Scan archives.......................: on
Recursion depth.....................: 20
Smart extensions....................: on
Macro heuristic.....................: on
File heuristic......................: medium

Start of the scan: Thursday, August 13, 2009 18:58

Starting search for hidden objects.
'53378' objects were checked, '0' hidden objects were found.

The scan of running processes will be started
Scan process 'avscan.exe' - '1' Module(s) have been scanned
Scan process 'avcenter.exe' - '1' Module(s) have been scanned
Scan process 'avgnt.exe' - '1' Module(s) have been scanned
Scan process 'sched.exe' - '1' Module(s) have been scanned
Scan process 'avguard.exe' - '1' Module(s) have been scanned
Scan process 'SUPERAntiSpyware.exe' - '1' Module(s) have been scanned
Scan process 'iPodService.exe' - '1' Module(s) have been scanned
Scan process 'ehmsas.exe' - '1' Module(s) have been scanned
Scan process 'ctfmon.exe' - '1' Module(s) have been scanned
Scan process 'AWC.exe' - '1' Module(s) have been scanned
Scan process 'DSAgnt.exe' - '1' Module(s) have been scanned
Scan process 'msmsgs.exe' - '1' Module(s) have been scanned
Scan process 'VeohClient.exe' - '1' Module(s) have been scanned
Scan process 'AVGIDSUI.exe' - '1' Module(s) have been scanned
Scan process 'DLACTRLW.EXE' - '1' Module(s) have been scanned
Scan process 'DMXLauncher.exe' - '1' Module(s) have been scanned
Scan process 'ehtray.exe' - '1' Module(s) have been scanned
Scan process 'issch.exe' - '1' Module(s) have been scanned
Scan process 'iTunesHelper.exe' - '1' Module(s) have been scanned
Scan process 'rundll32.exe' - '1' Module(s) have been scanned
Scan process 'stsystra.exe' - '1' Module(s) have been scanned
Scan process 'explorer.exe' - '1' Module(s) have been scanned
Scan process 'wscntfy.exe' - '1' Module(s) have been scanned
Scan process 'alg.exe' - '1' Module(s) have been scanned
Scan process 'dllhost.exe' - '1' Module(s) have been scanned
Scan process 'mcrdsvc.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'nvsvc32.exe' - '1' Module(s) have been scanned
Scan process 'MDM.EXE' - '1' Module(s) have been scanned
Scan process 'ehSched.exe' - '1' Module(s) have been scanned
Scan process 'ehrecvr.exe' - '1' Module(s) have been scanned
Scan process 'mDNSResponder.exe' - '1' Module(s) have been scanned
Scan process 'AVGIDSWatcher.exe' - '1' Module(s) have been scanned
Scan process 'AppleMobileDeviceService.exe' - '1' Module(s) have been scanned
Scan process 'AOLacsd.exe' - '1' Module(s) have been scanned
Scan process 'acs.exe' - '1' Module(s) have been scanned
Scan process 'aawservice.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'lsass.exe' - '1' Module(s) have been scanned
Scan process 'services.exe' - '1' Module(s) have been scanned
Scan process 'winlogon.exe' - '1' Module(s) have been scanned
Scan process 'csrss.exe' - '1' Module(s) have been scanned
Scan process 'smss.exe' - '1' Module(s) have been scanned
49 processes with 49 modules were scanned

Starting master boot sector scan:
Master boot sector HD0
[INFO] No virus was found!

Start scanning boot sectors:
Boot sector 'C:\'
[INFO] No virus was found!

Starting to scan executable files (registry).
The registry was scanned ( '65' files ).


Starting the file scan:

Begin scan in 'C:\'
C:\hiberfil.sys
[WARNING] The file could not be opened!
[NOTE] This file is a Windows system file.
[NOTE] This file cannot be opened for scanning.
C:\pagefile.sys
[WARNING] The file could not be opened!
[NOTE] This file is a Windows system file.
[NOTE] This file cannot be opened for scanning.
C:\Program Files\NETGEAR\WPN311\wlancfg5.exe
[WARNING] The file could not be opened!
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
[WARNING] The file could not be opened!
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
[WARNING] The file could not be opened!
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP765\A0116607.exe
[DETECTION] Contains recognition pattern of the ADSPY/BetterInternet.YC adware or spyware
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP765\A0116608.exe
[DETECTION] Contains recognition pattern of the ADSPY/BetterInternet.YC adware or spyware
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP765\A0116609.exe
[DETECTION] Contains recognition pattern of the ADSPY/BetterInternet.YC adware or spyware
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP765\A0116610.exe
[DETECTION] Contains recognition pattern of the ADSPY/BetterInternet.YC adware or spyware
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP765\A0116611.exe
[DETECTION] Contains recognition pattern of the ADSPY/BetterInternet.YC adware or spyware
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP765\A0116612.exe
[DETECTION] Contains recognition pattern of the ADSPY/BetterInternet.YC adware or spyware
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP765\A0116613.exe
[DETECTION] Contains recognition pattern of the ADSPY/BetterInternet.YC adware or spyware
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP765\A0116614.exe
[DETECTION] Contains recognition pattern of the ADSPY/BetterInternet.YC adware or spyware
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP765\A0116615.exe
[DETECTION] Contains recognition pattern of the ADSPY/BetterInternet.YC adware or spyware

Beginning disinfection:
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP765\A0116607.exe
[DETECTION] Contains recognition pattern of the ADSPY/BetterInternet.YC adware or spyware
[NOTE] The file was moved to '4ab5a35c.qua'!
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP765\A0116608.exe
[DETECTION] Contains recognition pattern of the ADSPY/BetterInternet.YC adware or spyware
[NOTE] The file was moved to '4b37de1d.qua'!
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP765\A0116609.exe
[DETECTION] Contains recognition pattern of the ADSPY/BetterInternet.YC adware or spyware
[NOTE] The file was moved to '4bcbfd7d.qua'!
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP765\A0116610.exe
[DETECTION] Contains recognition pattern of the ADSPY/BetterInternet.YC adware or spyware
[NOTE] The file was moved to '4bc40f05.qua'!
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP765\A0116611.exe
[DETECTION] Contains recognition pattern of the ADSPY/BetterInternet.YC adware or spyware
[NOTE] The file was moved to '4ab5a35d.qua'!
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP765\A0116612.exe
[DETECTION] Contains recognition pattern of the ADSPY/BetterInternet.YC adware or spyware
[NOTE] The file was moved to '4b34d626.qua'!
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP765\A0116613.exe
[DETECTION] Contains recognition pattern of the ADSPY/BetterInternet.YC adware or spyware
[NOTE] The file was moved to '4bc9edce.qua'!
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP765\A0116614.exe
[DETECTION] Contains recognition pattern of the ADSPY/BetterInternet.YC adware or spyware
[NOTE] The file was moved to '4b35ceee.qua'!
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP765\A0116615.exe
[DETECTION] Contains recognition pattern of the ADSPY/BetterInternet.YC adware or spyware
[NOTE] The file was moved to '4b362656.qua'!


End of the scan: Thursday, August 13, 2009 19:35
Used time: 36:25 Minute(s)

The scan has been done completely.

8646 Scanned directories
289604 Files were scanned
9 Viruses and/or unwanted programs were found
0 Files were classified as suspicious
0 files were deleted
0 Viruses and unwanted programs were repaired
9 Files were moved to quarantine
0 Files were renamed
5 Files cannot be scanned
289590 Files not concerned
3882 Archives were scanned
5 Warnings
11 Notes
53378 Objects were scanned with rootkit scan
0 Hidden objects were found

reeldeel
Intermediate
Intermediate

Posts Posts : 50
Joined Joined : 2009-07-20
OS OS : XP
Points Points : 27036
# Likes # Likes : 0

View user profile

Back to top Go down

Re: New Trojans (AVCare) has disabled internet and everything el

Post by reeldeel on 14th August 2009, 7:24 pm

here is the first one:
Avira AntiVir Personal
Report file date: Thursday, August 13, 2009 18:12

Scanning for 1562564 virus strains and unwanted programs.

Licensee : Avira AntiVir Personal - FREE Antivirus
Serial number : 0000149996-ADJIE-0000001
Platform : Windows XP
Windows version : (Service Pack 3) [5.1.2600]
Boot mode : Normally booted
Username : SYSTEM
Computer name : THEDEEL

Version information:
BUILD.DAT : 9.0.0.407 17961 Bytes 7/29/2009 10:34:00
AVSCAN.EXE : 9.0.3.7 466689 Bytes 7/21/2009 18:36:14
AVSCAN.DLL : 9.0.3.0 40705 Bytes 2/27/2009 15:58:24
LUKE.DLL : 9.0.3.2 209665 Bytes 2/20/2009 16:35:49
LUKERES.DLL : 9.0.2.0 12033 Bytes 2/27/2009 15:58:52
ANTIVIR0.VDF : 7.1.0.0 15603712 Bytes 10/27/2008 17:30:36
ANTIVIR1.VDF : 7.1.4.132 5707264 Bytes 6/24/2009 14:21:42
ANTIVIR2.VDF : 7.1.4.253 1779200 Bytes 7/19/2009 03:08:01
ANTIVIR3.VDF : 7.1.5.19 139776 Bytes 7/23/2009 12:36:13
Engineversion : 8.2.0.228
AEVDF.DLL : 8.1.1.1 106868 Bytes 7/28/2009 18:31:50
AESCRIPT.DLL : 8.1.2.18 442746 Bytes 7/23/2009 14:59:39
AESCN.DLL : 8.1.2.4 127348 Bytes 7/23/2009 14:59:39
AERDL.DLL : 8.1.2.4 430452 Bytes 7/23/2009 14:59:39
AEPACK.DLL : 8.1.3.18 401783 Bytes 7/28/2009 18:31:50
AEOFFICE.DLL : 8.1.0.38 196987 Bytes 7/23/2009 14:59:39
AEHEUR.DLL : 8.1.0.143 1864055 Bytes 7/23/2009 14:59:39
AEHELP.DLL : 8.1.5.3 233846 Bytes 7/23/2009 14:59:39
AEGEN.DLL : 8.1.1.50 352629 Bytes 7/23/2009 14:59:39
AEEMU.DLL : 8.1.0.9 393588 Bytes 10/9/2008 19:32:40
AECORE.DLL : 8.1.7.6 184694 Bytes 7/23/2009 14:59:39
AEBB.DLL : 8.1.0.3 53618 Bytes 10/9/2008 19:32:40
AVWINLL.DLL : 9.0.0.3 18177 Bytes 12/12/2008 13:47:59
AVPREF.DLL : 9.0.0.1 43777 Bytes 12/5/2008 15:32:15
AVREP.DLL : 8.0.0.3 155905 Bytes 1/20/2009 19:34:28
AVREG.DLL : 9.0.0.0 36609 Bytes 12/5/2008 15:32:09
AVARKT.DLL : 9.0.0.3 292609 Bytes 3/24/2009 20:05:41
AVEVTLOG.DLL : 9.0.0.7 167169 Bytes 1/30/2009 15:37:08
SQLITE3.DLL : 3.6.1.0 326401 Bytes 1/28/2009 20:03:49
SMTPLIB.DLL : 9.2.0.25 28417 Bytes 2/2/2009 13:21:33
NETNT.DLL : 9.0.0.0 11521 Bytes 12/5/2008 15:32:10
RCIMAGE.DLL : 9.0.0.25 2438913 Bytes 5/15/2009 20:39:58
RCTEXT.DLL : 9.0.37.0 86785 Bytes 4/17/2009 15:19:48

Configuration settings for the scan:
Jobname.............................: Complete system scan
Configuration file..................: c:\program files\avira\antivir desktop\sysscan.avp
Logging.............................: low
Primary action......................: interactive
Secondary action....................: ignore
Scan master boot sector.............: on
Scan boot sector....................: on
Boot sectors........................: C:,
Process scan........................: on
Scan registry.......................: on
Search for rootkits.................: on
Integrity checking of system files..: off
Scan all files......................: All files
Scan archives.......................: on
Recursion depth.....................: 20
Smart extensions....................: on
Macro heuristic.....................: on
File heuristic......................: medium

Start of the scan: Thursday, August 13, 2009 18:12

Starting search for hidden objects.
'53363' objects were checked, '0' hidden objects were found.

The scan of running processes will be started
Scan process 'avscan.exe' - '1' Module(s) have been scanned
Scan process 'avcenter.exe' - '1' Module(s) have been scanned
Scan process 'avcenter.exe' - '1' Module(s) have been scanned
Scan process 'avgnt.exe' - '1' Module(s) have been scanned
Scan process 'sched.exe' - '1' Module(s) have been scanned
Scan process 'avguard.exe' - '1' Module(s) have been scanned
Scan process 'msiexec.exe' - '1' Module(s) have been scanned
Scan process 'SUPERAntiSpyware.exe' - '1' Module(s) have been scanned
Scan process 'iPodService.exe' - '1' Module(s) have been scanned
Scan process 'ehmsas.exe' - '1' Module(s) have been scanned
Scan process 'ctfmon.exe' - '1' Module(s) have been scanned
Scan process 'AWC.exe' - '1' Module(s) have been scanned
Scan process 'DSAgnt.exe' - '1' Module(s) have been scanned
Scan process 'msmsgs.exe' - '1' Module(s) have been scanned
Scan process 'VeohClient.exe' - '1' Module(s) have been scanned
Scan process 'AVGIDSUI.exe' - '1' Module(s) have been scanned
Scan process 'DLACTRLW.EXE' - '1' Module(s) have been scanned
Scan process 'DMXLauncher.exe' - '1' Module(s) have been scanned
Scan process 'ehtray.exe' - '1' Module(s) have been scanned
Scan process 'issch.exe' - '1' Module(s) have been scanned
Scan process 'iTunesHelper.exe' - '1' Module(s) have been scanned
Scan process 'rundll32.exe' - '1' Module(s) have been scanned
Scan process 'stsystra.exe' - '1' Module(s) have been scanned
Scan process 'explorer.exe' - '1' Module(s) have been scanned
Scan process 'wscntfy.exe' - '1' Module(s) have been scanned
Scan process 'alg.exe' - '1' Module(s) have been scanned
Scan process 'dllhost.exe' - '1' Module(s) have been scanned
Scan process 'mcrdsvc.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'nvsvc32.exe' - '1' Module(s) have been scanned
Scan process 'MDM.EXE' - '1' Module(s) have been scanned
Scan process 'ehSched.exe' - '1' Module(s) have been scanned
Scan process 'ehrecvr.exe' - '1' Module(s) have been scanned
Scan process 'mDNSResponder.exe' - '1' Module(s) have been scanned
Scan process 'AVGIDSWatcher.exe' - '1' Module(s) have been scanned
Scan process 'AppleMobileDeviceService.exe' - '1' Module(s) have been scanned
Scan process 'AOLacsd.exe' - '1' Module(s) have been scanned
Scan process 'acs.exe' - '1' Module(s) have been scanned
Scan process 'aawservice.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'lsass.exe' - '1' Module(s) have been scanned
Scan process 'services.exe' - '1' Module(s) have been scanned
Scan process 'winlogon.exe' - '1' Module(s) have been scanned
Scan process 'csrss.exe' - '1' Module(s) have been scanned
Scan process 'smss.exe' - '1' Module(s) have been scanned
51 processes with 51 modules were scanned

Starting master boot sector scan:
Master boot sector HD0
[INFO] No virus was found!

Start scanning boot sectors:
Boot sector 'C:\'
[INFO] No virus was found!

reeldeel
Intermediate
Intermediate

Posts Posts : 50
Joined Joined : 2009-07-20
OS OS : XP
Points Points : 27036
# Likes # Likes : 0

View user profile

Back to top Go down

Re: New Trojans (AVCare) has disabled internet and everything el

Post by reeldeel on 14th August 2009, 7:24 pm

continued:
Starting to scan executable files (registry).
The registry was scanned ( '65' files ).


Starting the file scan:

Begin scan in 'C:\'
C:\hiberfil.sys
[WARNING] The file could not be opened!
[NOTE] This file is a Windows system file.
[NOTE] This file cannot be opened for scanning.
C:\pagefile.sys
[WARNING] The file could not be opened!
[NOTE] This file is a Windows system file.
[NOTE] This file cannot be opened for scanning.
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommandService.zip
[DETECTION] Contains suspicious code GEN/PwdZIP
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NetworkMonitor1.zip
[DETECTION] Contains suspicious code GEN/PwdZIP
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC.zip
[DETECTION] Contains suspicious code GEN/PwdZIP
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinSmallazl.zip
[DETECTION] Contains suspicious code GEN/PwdZIP
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinSmallazl4.zip
[DETECTION] Contains suspicious code GEN/PwdZIP
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Yazzle.zip
[DETECTION] Contains suspicious code GEN/PwdZIP
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Yazzle1.zip
[DETECTION] Contains suspicious code GEN/PwdZIP
C:\Documents and Settings\Mike\Local Settings\Application Data\Mozilla\Firefox\Profiles\nblphn3z.default\Cache(2)\EF845749d01
[DETECTION] Contains recognition pattern of the HTML/Infected.WebPage.Gen HTML script virus
C:\Program Files\NETGEAR\WPN311\wlancfg5.exe
[WARNING] The file could not be opened!
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
[WARNING] The file could not be opened!
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
[WARNING] The file could not be opened!
C:\Program Files\WildTangent\Apps\GameChannel\Games\26D2C2C3-CF14-4ED7-B1FC-0BE64AFBA3B3\DMXGameLaunch.exe
[DETECTION] Contains recognition pattern of the ADSPY/BetterInternet.YC adware or spyware
C:\Program Files\WildTangent\Apps\GameChannel\Games\3C48F877-A164-45E9-B9DA-26A049FFC207\DMXGameLaunch.exe
[DETECTION] Contains recognition pattern of the ADSPY/BetterInternet.YC adware or spyware
C:\Program Files\WildTangent\Apps\GameChannel\Games\6293BC00-4EB8-4C65-8548-53E2FC3BF937\DMXGameLaunch.exe
[DETECTION] Contains recognition pattern of the ADSPY/BetterInternet.YC adware or spyware
C:\Program Files\WildTangent\Apps\GameChannel\Games\651956B7-1969-42AA-9453-E0B813019D54\DMXGameLaunch.exe
[DETECTION] Contains recognition pattern of the ADSPY/BetterInternet.YC adware or spyware
C:\Program Files\WildTangent\Apps\GameChannel\Games\989E4C3B-B2C9-4486-9A09-D5A8F953837C\DMXGameLaunch.exe
[DETECTION] Contains recognition pattern of the ADSPY/BetterInternet.YC adware or spyware
C:\Program Files\WildTangent\Apps\GameChannel\Games\C0A0AA4D-C79B-48CA-8843-2B02B626C9E6\DMXGameLaunch.exe
[DETECTION] Contains recognition pattern of the ADSPY/BetterInternet.YC adware or spyware
C:\Program Files\WildTangent\Apps\GameChannel\Games\C2D8F0E2-6978-4409-8351-BA8785DA11EE\DMXGameLaunch.exe
[DETECTION] Contains recognition pattern of the ADSPY/BetterInternet.YC adware or spyware
C:\Program Files\WildTangent\Apps\GameChannel\Games\D1A6F3FD-7B40-443F-8767-BADB25A0D222\DMXGameLaunch.exe
[DETECTION] Contains recognition pattern of the ADSPY/BetterInternet.YC adware or spyware
C:\Program Files\WildTangent\Apps\GameChannel\Games\E0814F95-5380-4892-B8C8-7FA4B349EF46\DMXGameLaunch.exe
[DETECTION] Contains recognition pattern of the ADSPY/BetterInternet.YC adware or spyware
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP720\A0098394.vbs
[DETECTION] Is the TR/Dldr.Agent.104 Trojan
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP720\A0098561.dll
[DETECTION] Is the TR/Drop.Softomat.AN Trojan
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP720\A0098562.exe
[DETECTION] Is the TR/Trash.Gen Trojan
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP720\A0098563.exe
[DETECTION] Is the TR/Trash.Gen Trojan
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP720\A0098564.exe
[DETECTION] Is the TR/Trash.Gen Trojan
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP720\A0098565.exe
[DETECTION] Is the TR/Trash.Gen Trojan
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP720\A0098566.exe
[DETECTION] Is the TR/Trash.Gen Trojan
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP720\A0098567.dll
[DETECTION] Is the TR/Trash.Gen Trojan
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP720\A0098568.exe
[DETECTION] Is the TR/Trash.Gen Trojan
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP720\A0098569.exe
[DETECTION] Is the TR/Drop.Softomat.AN Trojan
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP720\A0098570.exe
[DETECTION] Is the TR/Trash.Gen Trojan
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP720\A0098571.exe
[DETECTION] Is the TR/Drop.Softomat.AN Trojan
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP741\A0106618.dll
[DETECTION] Is the TR/TDss.yux Trojan
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP741\A0106620.dll
[DETECTION] Is the TR/Trash.Gen Trojan
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP755\A0108875.sys:1
[DETECTION] Is the TR/Rootkit.Gen Trojan
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP755\A0109853.sys:1
[DETECTION] Is the TR/Rootkit.Gen Trojan
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP756\A0109901.sys:1
[DETECTION] Is the TR/Rootkit.Gen Trojan
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP757\A0109926.sys:1
[DETECTION] Is the TR/Rootkit.Gen Trojan
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP757\A0109930.sys:1
[DETECTION] Is the TR/Rootkit.Gen Trojan
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP757\A0109947.sys:1
[DETECTION] Is the TR/Rootkit.Gen Trojan
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP758\A0110063.sys:1
[DETECTION] Is the TR/Rootkit.Gen Trojan
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP758\A0110136.sys:1
[DETECTION] Is the TR/Rootkit.Gen Trojan
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP758\A0110141.sys:1
[DETECTION] Is the TR/Rootkit.Gen Trojan
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP758\A0110206.sys:1
[DETECTION] Is the TR/Rootkit.Gen Trojan
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP758\A0110227.sys:1
[DETECTION] Is the TR/Rootkit.Gen Trojan
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP758\A0111227.sys:1
[DETECTION] Is the TR/Rootkit.Gen Trojan
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP758\A0111231.sys:1
[DETECTION] Is the TR/Rootkit.Gen Trojan
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP758\A0111235.sys:1
[DETECTION] Is the TR/Rootkit.Gen Trojan
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP758\A0111312.sys:1
[DETECTION] Is the TR/Rootkit.Gen Trojan
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP758\A0111347.sys:1
[DETECTION] Is the TR/Rootkit.Gen Trojan
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP758\A0111366.sys:1
[DETECTION] Is the TR/Rootkit.Gen Trojan
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP758\A0111371.sys:1
[DETECTION] Is the TR/Rootkit.Gen Trojan
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP758\A0111457.sys:1
[DETECTION] Is the TR/Rootkit.Gen Trojan
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP758\A0111461.sys:1
[DETECTION] Is the TR/Rootkit.Gen Trojan
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP758\A0111465.sys:1
[DETECTION] Is the TR/Rootkit.Gen Trojan
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP758\A0111475.sys:1
[DETECTION] Is the TR/Rootkit.Gen Trojan
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP758\A0111498.sys:1
[DETECTION] Is the TR/Rootkit.Gen Trojan
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP758\A0111513.sys:1
[DETECTION] Is the TR/Rootkit.Gen Trojan
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP758\A0111592.sys:1
[DETECTION] Is the TR/Rootkit.Gen Trojan
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP758\A0111614.sys:1
[DETECTION] Is the TR/Rootkit.Gen Trojan
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP758\A0111732.sys:1
[DETECTION] Is the TR/Rootkit.Gen Trojan
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP758\A0111756.sys:1
[DETECTION] Is the TR/Rootkit.Gen Trojan
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP758\A0111828.sys:1
[DETECTION] Is the TR/Rootkit.Gen Trojan
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP758\A0111839.sys:1
[DETECTION] Is the TR/Rootkit.Gen Trojan
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP758\A0111849.sys:1
[DETECTION] Is the TR/Rootkit.Gen Trojan
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP758\A0111853.sys:1
[DETECTION] Is the TR/Rootkit.Gen Trojan
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP758\A0111857.sys:1
[DETECTION] Is the TR/Rootkit.Gen Trojan
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP758\A0111871.sys:1
[DETECTION] Is the TR/Rootkit.Gen Trojan
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP758\A0111877.sys:1
[DETECTION] Is the TR/Rootkit.Gen Trojan
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP759\A0111971.sys:1
[DETECTION] Is the TR/Rootkit.Gen Trojan
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP759\A0111976.sys:1
[DETECTION] Is the TR/Rootkit.Gen Trojan
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP759\A0111986.sys:1
[DETECTION] Is the TR/Rootkit.Gen Trojan
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP759\A0112009.sys:1
[DETECTION] Is the TR/Rootkit.Gen Trojan
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP760\A0112024.sys:1
[DETECTION] Is the TR/Rootkit.Gen Trojan
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP760\A0112030.sys:1
[DETECTION] Is the TR/Rootkit.Gen Trojan
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP760\A0112041.sys:1
[DETECTION] Is the TR/Rootkit.Gen Trojan
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP760\A0112066.exe
[DETECTION] Is the TR/Trash.Gen Trojan
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP760\A0112067.exe
[DETECTION] Is the TR/Trash.Gen Trojan

reeldeel
Intermediate
Intermediate

Posts Posts : 50
Joined Joined : 2009-07-20
OS OS : XP
Points Points : 27036
# Likes # Likes : 0

View user profile

Back to top Go down

Re: New Trojans (AVCare) has disabled internet and everything el

Post by Belahzur on 14th August 2009, 8:47 pm

Hello.
Lets adress what it found. Smile

Navigate to this folder in bold:

C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery

Go inside it and delete everything.

We need to make a new restore point.

To turn off System Restore, follow these steps:
1. Click Start, right-click My Computer, and then click Properties.
2. Click the System Restore tab.
3. Click the Turn off System Restore check box (or the Turn off System Restore on all drives check box), and then click OK.
4. Click Yes when you receive the prompt to the turn off System Restore.

Now we need to make a new restore point.
To turn on System Restore, follow these steps:
1. Click Start, right-click My Computer, and then click Properties.
2. Click the System Restore tab.
3. Click the Turn off System Restore check box (To turn on System Restore), and then click OK.

Now the last item.

C:\Program Files\WildTangent

WildTangent is known to include adware, please read here for more information about [You must be registered and logged in to see this link.]. Your choice if you want to remove it or not.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34918
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : 7 Home Premium x64
Points Points : 245091
# Likes # Likes : 1

View user profile

Back to top Go down

Re: New Trojans (AVCare) has disabled internet and everything el

Post by reeldeel on 15th August 2009, 1:21 am

I did what you said. How do I create a new restore point, I followed all of the steps. It still does not work. Windows does not have permission to open my Netgear which is my router. I cannot connect. Something is still wrong. Sorry, I 'm just so pissed that nothing works.

reeldeel
Intermediate
Intermediate

Posts Posts : 50
Joined Joined : 2009-07-20
OS OS : XP
Points Points : 27036
# Likes # Likes : 0

View user profile

Back to top Go down

Re: New Trojans (AVCare) has disabled internet and everything el

Post by reeldeel on 15th August 2009, 3:20 pm

Uninstalled and reinstalled Netgear. Problem solved. Comp back! Donation coming on Monday! You guys are amazing!!!!! Thank you!!!!!!

reeldeel
Intermediate
Intermediate

Posts Posts : 50
Joined Joined : 2009-07-20
OS OS : XP
Points Points : 27036
# Likes # Likes : 0

View user profile

Back to top Go down

Page 1 of 2 1, 2  Next

View previous topic View next topic Back to top

- Similar topics

 
Permissions in this forum:
You cannot reply to topics in this forum