Avast!doesn't stop with the messages!

Avast! 5 doesn’t stop with the virus message its been over 400!! :cry: error messages it says Malware blocked
Object:C:\Users\L\Appdata\Roaming\iexplorer.exe\sony vegas.exe
Infection: Win32:Malware-gen
Action:Moved to Chest
Process: C:\Windows\SysWOW64\Explorer.exe :o :o

Im running vista 64 bits.

Iexplorer does not belong in that location - Avast is right - is it a crack or keygen ?

I don’t know if its a crack or keygen i havent downloaded anything recently…

Check your computer for Malware with

Malwarebytes Antimalware http://filehippo.com/download_malwarebytes_anti_malware/
after install click UPDATE and run cuick scan, click on REMOVE SELECTED to quarantine anything found

SUPERAntiSpyware http://filehippo.com/download_superantispyware/
Are cookies really spyware and are they dangerous?
http://www.superantispyware.com/supportfaqdisplay.html?faq=26

If anything is found come back and post the scan logs here

Here’s Malwarebytes log first…

Your log says " No action taken "
if you want to quarantine the infections you must scan again and click the REMOVE SELECTED button

I did but it still won’t work.

You mean Malwarebytes can`t remove it?
Have you run SuperAntiSpyware?

I am now running SUPERAntispyware I mean i already quarantined those threats but it seems to not work…

I mean i already quarantined those threats but it seems to not work...
Meaning they come back?.......a bit moore info would be nice.....so we don`t have to guess

I’m gonna restart my computer to see if it comes back…

but first i have to finish the superantispyware scanning.

And here is the log.

yeah the cookies don’t matter, and that’s all what SAS shows, but your malwarebyte log gives info about serious infection.

jepp, after some googling the Backdoor.Bot seems difficult to remove, so i think you should follow this guide from essexboy and post the log HERE. You have already posted the MBAM log so just do the OTL. Essexboy will then take a look

http://forum.avast.com/index.php?topic=53253.0

the OTL

First a question - did you copy the contents of your system32 folder to a roaming folder ?

If not then run this fix below, if you did then let me know before you run it

Run OTL

[*]Under the Custom Scans/Fixes box at the bottom, paste in the following

:OTL
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = 127.0.0.1:8080
[2010/02/17 21:49:47 | 000,000,000 | ---D | C] -- C:\Users\L\AppData\Local\_
[2009/11/12 17:21:25 | 000,135,168 | -H-- | C] () -- C:\Windows\SysWow64\q7Wbx8BXADB.dll
[2009/11/11 16:50:03 | 000,135,168 | -H-- | C] () -- C:\Windows\SysWow64\s92m8SWJ.dll
[2009/10/23 17:45:20 | 000,049,664 | -H-- | C] () -- C:\Windows\SysWow64\vOi2EuCI.dll
[2009/10/22 20:41:15 | 000,049,664 | -H-- | C] () -- C:\Windows\SysWow64\yDq7xLEgyE.dll
[2009/10/21 21:28:10 | 000,049,664 | -H-- | C] () -- C:\Windows\SysWow64\aNcNvhaL1y.dll
[2010/02/05 20:22:08 | 000,000,000 | RHSD | M] -- C:\Users\L\AppData\Roaming\system32
[2010/01/01 15:48:09 | 000,000,000 | ---D | M](C:\Users\L\AppData\Local\?) -- C:\Users\L\AppData\Local\?
[2010/01/01 15:48:09 | 000,000,000 | ---D | M](C:\Users\L\AppData\Local\?) -- C:\Users\L\AppData\Local\?
(C:\Users\L\AppData\Local\?) -- C:\Users\L\AppData\Local\?

:Commands
[purity]
[emptytemp]
[Reboot]

[*]Then click the Run Fix button at the top
[*]Let the program run unhindered, reboot the PC when it is done
[*]Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.

No i did not copy my system32 folder into the roaming folder. Why would i do that ???

No idea but it is best to ask in case you did for some reason - as OTL will remove it when it runs

Could you now run OTL fix and let me know of any problems