So Avast keeps spamming me with this problem, something at C:Windows\assembly\tmp\U\80000032.@ is trying to do something to GoogleUpdate.exe and Chrome.exe. Not a great explanation, I know, either way Avast seems to block it but each time it does it wants me to perform a boot-time scan. I am also getting this type of warning:
URL: http: //50.7.245.170/RAI05SE6R5x1Tu1NDIxf…
Process: file://C:\Windows\System32\svchost.exe
Infection: al
Something is obviously trying to get me into more trouble here.
It seems to have disabled my Windows Firewall and it won’t let me start it up again, googled the hell out of that one but nothing I could find would solve my issue with that.
Now I tried the boot-time scan but it takes forever (The first 2% took an hour, didn’t feel like waiting that one out), so I let it sit over the night. When I woke up it was finished, it had found something called nye22.dll and it was asking me how to deal with it. I tried every option but the computer seemed to have frozen at some point, delete, repair, nothing worked. So today I’ve spent the day running Malwarebytes, SUPERAntiSpyware, CCleaner, Full system scan with Avast and TDSSKiller, yet I’m still having the issue. I’ve run out of ideas, there’s going back and running the boot-time scan and hoping that’ll do it, or randomly jumping into ComboFix which seems to be what all the pros use to fix this type of stuff. I figured I’d just come here and ask for some help before I break something. So, here’s the logs:
MBAM Log (I did a full scan rather than a quick scan, that should work out the same on your end I hope):
Malwarebytes’ Anti-Malware 1.51.2.1300
www.malwarebytes.org
Database version: 8024
Windows 6.1.7601 Service Pack 1
Internet Explorer 8.0.7601.17514
2011-10-26 23:12:19
mbam-log-2011-10-26 (23-12-18).txt
Scan type: Full scan (C:|F:|I:|)
Objects scanned: 886105
Time elapsed: 3 hour(s), 39 minute(s), 6 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AMService (Trojan.Agent) → Quarantined and deleted successfully.
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
c:\Windows\Temp\gjbtlq\setup.exe (Trojan.Agent) → Quarantined and deleted successfully.