Yes a reboot is required
OK, there goes the new log…
But can’t still open Avast page nor Microsoft’s.
PS. Could enter internet indeed.
OK the file did not want to leave so I will use a bigger hammer
Download ComboFix from one of these locations:
* IMPORTANT !!! Save ComboFix.exe to your Desktop
[*]Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
[*]Double click on ComboFix.exe & follow the prompts.
[*]As part of it’s process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it’s strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
[*]Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it’s malware removal procedures.
http://img.photobucket.com/albums/v706/ried7/RcAuto1.gif
Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:
http://img.photobucket.com/albums/v706/ried7/whatnext.png
Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Should I cancel Avast momentarily? I cannot suspend it. Or I leave it as it is now?
(Win. Firewall was and is off now.)
Firefox and IE ?
TK u
Suspend Avast by right clicking the icon and selecting pause all shields - then run CF. If Combofix complains still let it run
When I right click on the Avast icon appears nothing similar to ‘pause all shields’ (it’s in italian).
When I try to open the AV it claims for a new license code. Otherwise it disappears.
It is Stop On-Access Protection, the first option (easier on the translation), see image.
Once you have completed the scan don’t forget to Start On-Access Protection again.
Thanks David I am using 5 now
Have no icon there where it should be.
Have tried in my netbook and it goes as you say, but in my PC i don’t find that movin’ icon on the bar. All other Avast icons give a different menù.
OK run with Avast active - combofix may complain but ignore it
I was so happy… ‘cause I could load Avast page and enter the forum…
But each time the responses were slower and slower…
Tried to load Microsoft page and couldn’t do it (always says that it is not to find the server)
I newly reloaded the browser (I always clean all before closing it), but this time couldn’t even charge the Avast page… :’(
Am attaching the log as you asked.
Thanks for your help and patience Essexboy.
OK next lets clear all the caches and flush your DNS
Download TFC to your desktop
[*]Open the file and close any other windows.
[*]It will close all programs itself when run, make sure to let it run uninterrupted.
[*]Click the Start button to begin the process. The program should not take long to finish its job
[*]Once its finished it should reboot your machine, if not, do this yourself to ensure a complete clean
Lets check some settings on your system:
[*]Enter your Control Panel and double-click on Network Connections
[*]Then right click on your Default Connection
[*]Usually Local Area Connection for Cable and DSL, or AOL Connection.
[*]Left click on Properties
[*]Double-Click on the Internet Protocol (TCP/IP) item
[*]Select the radio dial that says Obtain DNS Servers Automatically
[]Press OK twice to get out of the properties screen
[]Restart the computer
Go to Start → Run->Type CMD and click Ok. The MSDOS Window will be displayed. At the command prompt, type the following and press Enter after each line:
ipconfig /flushdns (The space between g and / is needed)
regsvr32 netshell.dll
regsvr32 netcfgx.dll
regsvr32 netman.dll
Exit
Restart the computer.
Have tried twice to run TFC and PC reboots without letting the TFC run completely.
The first time the reboot was too fast. The second time it let 2 seconds the TFC running and rebooted.
Maybe I continue trying?
About that rebooting, sometimes my PC used to do it, don’t know why. Thought it was the antivirus (had AVG). With Avast it happened rarely.
OK, I have repeated it 5 times. Always appears a small window saying something about the system (?) and dissappears all, followed by reboot.
Then I have done what you asked (DNS was already in ‘automatic’).
When I went in MSDOS and wrote those lines in red, after ENTER, said in all that it was not recognized as any internal or external command, nor an executable program nor a batch file.
Anyway, the problem persists…, cannot load Avast nor Microsoft pages (always ‘server not found’ message appears).
I think you have got Kido(Conficker).You should install these 3 patches from Microsoft:
http://www.microsoft.com/technet/security/Bulletin/MS08-067.mspx
http://www.microsoft.com/technet/security/bulletin/ms08-068.mspx
http://www.microsoft.com/technet/security/bulletin/ms09-001.mspx
Furthermore,you should disconnect from Internet and launch this tool from Kaspersky Lab:
http://www.kaspersky.ru/support/downloads/utils/kk.zip
Unzip the folder and run KK.exe
Regards,
Onix
Onix, I said the same thing back in my post:
http://forum.avast.com/index.php?topic=53205.msg451115#msg451115
Then essexboy took over.
Thanks for your help, but how can I load those patches from Microsoft when I cannot open even the Microsoft page?
May I only load that executable file and try it without loading first those patches?
As I understand, i must run it offline, is that OK?
Tks again.
Yeah,but i offer KidoKiller
You’re right
Download the attached log file and rename the extension to .ZIP then extract the files to your destop run KK.exe and let me know the result
Hello Essexboy
Have done as you said. Appeared a window in black with a list of eliminated files. Have closed immediately internet and zip prog.
It continued and after a while it rebooted the PC.
Then tried to enter internet and Avast page: same problem. Also with Microsoft page: always says server not found…
Tried to run it again but seems 'it ’ has detected KK.
Have been trying to see why there is always a growing quantity of files to compress when I clean the disk. Found a file in System32 modified in the future (?) and a zip file with the same name.
Going to TEMP in Windows found 4 or 5 files (and it should be empty, cause I had just run the disk cleaning prog. and it was 0KB) (?) Have sent them to the bin. One of them says it’s in use…(?)
I am also having problems with the clock. It gets back. Yesterday night left it OK, and now it was 10 hours back (!!).
Note. After loading KK. as you said, have tried to load KK from the link Onix gave, but couldn’t open the page (same ‘server not found’).
So confiker removed some stuff but did not cure the problem ?
I have a fair size armoury of tools each a bit stronger than the previous one
Download AVZ from here http://www.mediafire.com/file/nnz111y252r/avz4.zip then follow the instructions below for usage ignore the dowload and update links as they are for Kaspersky and will probably not work
[*]Unzip it to your desktop to a folder named avz4
[*]Double click on AVZ.exe to run it.
[*]Run an update by clicking the Auto Update button on the Right of the Log window:
http://i768.photobucket.com/albums/xx326/perplexus13/malware/avz-update-button.png
[*]Click Start to begin the update
Note: If you recieve an error message, chose a different source, then click Start again
[*] Start AVZ.
[*] Choose from the menu “File” => "Standard scripts " and mark the "Advanced System Analysis with Malware removal mode enabled " check box.
http://perplexus.geekstogo.com/avz-standardscripts-asa-removal.png
[*] Click on the “Execute selected scripts”.
[*] Automatic scanning, healing and system check will be executed.
[*] A logfile (avz_sysinfo.htm) will be created and saved in the LOG folder in the AVZ directory as virusinfo_syscure.zip.
[] It is necessary to reboot your machine, because AVZ might disturb some program operations (like antiviruses and firewall) during the system scan.
[] All applications will work properly after the system restart.
When restarted
[*] Start AVZ.
[*] Choose from the menu “File” => "Standard scripts " and mark the “Advanced System Analysis " check box.
http://i768.photobucket.com/albums/xx326/perplexus13/malware/avz-standardscripts.png
[*] Click on the “Execute selected scripts”.
[*] A system check will be automatically performed, and the created logfile (avz_sysinfo.htm) will be saved in the LOG folder in the AVZ directory as virusinfo_syscheck.zip.
Attach both virusinfo_syscure.zip and virusinfo_syscheck.zip to your next post Rename the zip extension to txt to enable an upload