[CLOSED]Avast keeps finding win32.brontok-CE

Are the alerts still appearing ?

they did while the scan was running…

Regards
John B.

So the alerts are still apparent

Once this programme has completed could you upload the entire zip file to a sharing site like mediafire and post the sharing link so that I can analyse it

Download AVPTool from Here to your desktop

Run the programme you have just downloaded to your desktop (it will be randomly named )

First we will run a virus scan

Click the cog in the upper right

http://i1224.photobucket.com/albums/ee362/Essexboy3/AVP%20shots/AVPfront.gif

Select down to and including your main drive, once done select the Automatic scan tab and press Start Scan

http://i1224.photobucket.com/albums/ee362/Essexboy3/AVP%20shots/avpsettings.gif

Allow AVP to delete all infections found
Once it has finished select report tab (last tab)
Select Detected threats report from the left and press Save button
Save it to your desktop and attach to your next post

Now the Analysis

Rerun AVP and select the Manual Disinfection tab and press Start Gathering System Information

http://i1224.photobucket.com/albums/ee362/Essexboy3/AVP%20shots/AVPAnalysis.gif

On completion click the link to locate the zip file to upload and attach to your next post

http://i1224.photobucket.com/albums/ee362/Essexboy3/AVP%20shots/AVPZiplocation.gif

screen dump of avast virus vault…

regards
John B.

Continue with AVP please and I will see what that shows me

here are the sysinfo from avptool. it did not find any treats.
http://www.mediafire.com/?gpvjsgcsedccl9j

@adotd: I can’t find this task.

regards
John B.

All the same, can I ask you to check any file from the quarantine which is defined as Win32.Brontok-CE

https://www.virustotal.com/

And the result is shown here, It is very interesting from a vendor who still identifies with the virus.

@Dim@rik:

https://www.virustotal.com/file/1dffcd38475e6d27daae0e381464db5df8aaa7b8fb2b20780a6d123edbedac62/analysis/1333261655/

result fomr one of the files in the chest…

regards
John B.

That shows clean as well

Lets look in those folders - the log may be large so it may need to be uploaded to mediafire

[*]Run OTL.
[*]Select All Users
[*]Under the Custom Scan box paste this in

c:\users\public /s

[*]Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.

this is the latest log from OTL.exe
we wasen’t home today, so we haven’t seen the warning today yet.

did just run a new quick scan in Avast, and now it found 14 treats, that I could delete without problems.
Avast suggested me to make an boot-time scan, and I said Yes.

I’m sorry all the text on the pictures are danish, hope you understand anyway.

dammm, right after the boot-scan, the 44 warnings did popup again.

regards
John B.

Let me know if you do please as OTL did not find those folders

sorry, I don’t understand.

regards
John B.

Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2

[*]Double-click SystemLook.exe to run it.
[*]Copy the content of the following codebox into the main textfield:

:dir 
C:\users\public  /s

[*]Click the Look button to start the scan.
[*]When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt

log file from systemlock…

regards
John B.

Again not showing there

Have you allowed shared access to your public folders ?

no, there is no shares on the labtop…

I’m thinking about making a backup and run a recover off the whole labtop.

Regards.’
John B.

That might be your best option as I cannot see where it is being generated from

ok, thanks anyway for the help trying to locate the problem.
will do the recovery tomorrow.

Regards
John B.