system
February 22, 2010, 8:44pm
1
Avast! 5 doesn’t stop with the virus message its been over 400!! error messages it says Malware blocked
Object:C:\Users\L\Appdata\Roaming\iexplorer.exe\sony vegas.exe
Infection: Win32:Malware-gen
Action:Moved to Chest
Process: C:\Windows\SysWOW64\Explorer.exe :o :o
Im running vista 64 bits.
Iexplorer does not belong in that location - Avast is right - is it a crack or keygen ?
system
February 22, 2010, 9:03pm
3
I don’t know if its a crack or keygen i havent downloaded anything recently…
Pondus
February 22, 2010, 9:23pm
4
Check your computer for Malware with
Malwarebytes Antimalware http://filehippo.com/download_malwarebytes_anti_malware/
after install click UPDATE and run cuick scan, click on REMOVE SELECTED to quarantine anything found
SUPERAntiSpyware http://filehippo.com/download_superantispyware/
Are cookies really spyware and are they dangerous?
http://www.superantispyware.com/supportfaqdisplay.html?faq=26
If anything is found come back and post the scan logs here
system
February 23, 2010, 12:42am
5
Here’s Malwarebytes log first…
Pondus
February 23, 2010, 6:06am
6
Your log says " No action taken "
if you want to quarantine the infections you must scan again and click the REMOVE SELECTED button
system
February 23, 2010, 10:10pm
7
I did but it still won’t work.
Pondus
February 23, 2010, 10:12pm
8
You mean Malwarebytes can`t remove it?
Have you run SuperAntiSpyware?
system
February 23, 2010, 10:14pm
9
I am now running SUPERAntispyware I mean i already quarantined those threats but it seems to not work…
Pondus
February 23, 2010, 10:18pm
10
I mean i already quarantined those threats but it seems to not work...
Meaning they come back?.......a bit moore info would be nice.....so we don`t have to guess
system
February 23, 2010, 10:32pm
11
I’m gonna restart my computer to see if it comes back…
but first i have to finish the superantispyware scanning.
system
February 23, 2010, 11:32pm
13
yeah the cookies don’t matter, and that’s all what SAS shows, but your malwarebyte log gives info about serious infection.
Pondus
February 23, 2010, 11:39pm
14
jepp, after some googling the Backdoor.Bot seems difficult to remove, so i think you should follow this guide from essexboy and post the log HERE. You have already posted the MBAM log so just do the OTL. Essexboy will then take a look
http://forum.avast.com/index.php?topic=53253.0
First a question - did you copy the contents of your system32 folder to a roaming folder ?
If not then run this fix below, if you did then let me know before you run it
Run OTL
[*]Under the Custom Scans/Fixes box at the bottom, paste in the following
:OTL
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = 127.0.0.1:8080
[2010/02/17 21:49:47 | 000,000,000 | ---D | C] -- C:\Users\L\AppData\Local\_
[2009/11/12 17:21:25 | 000,135,168 | -H-- | C] () -- C:\Windows\SysWow64\q7Wbx8BXADB.dll
[2009/11/11 16:50:03 | 000,135,168 | -H-- | C] () -- C:\Windows\SysWow64\s92m8SWJ.dll
[2009/10/23 17:45:20 | 000,049,664 | -H-- | C] () -- C:\Windows\SysWow64\vOi2EuCI.dll
[2009/10/22 20:41:15 | 000,049,664 | -H-- | C] () -- C:\Windows\SysWow64\yDq7xLEgyE.dll
[2009/10/21 21:28:10 | 000,049,664 | -H-- | C] () -- C:\Windows\SysWow64\aNcNvhaL1y.dll
[2010/02/05 20:22:08 | 000,000,000 | RHSD | M] -- C:\Users\L\AppData\Roaming\system32
[2010/01/01 15:48:09 | 000,000,000 | ---D | M](C:\Users\L\AppData\Local\?) -- C:\Users\L\AppData\Local\?
[2010/01/01 15:48:09 | 000,000,000 | ---D | M](C:\Users\L\AppData\Local\?) -- C:\Users\L\AppData\Local\?
(C:\Users\L\AppData\Local\?) -- C:\Users\L\AppData\Local\?
:Commands
[purity]
[emptytemp]
[Reboot]
[*]Then click the Run Fix button at the top
[*]Let the program run unhindered, reboot the PC when it is done
[*]Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.
system
February 24, 2010, 11:07pm
17
No i did not copy my system32 folder into the roaming folder. Why would i do that ???
No idea but it is best to ask in case you did for some reason - as OTL will remove it when it runs
Could you now run OTL fix and let me know of any problems