Right click the orange blob, select shield control, disable for one hour and then run Combofix and ignore the warnings. Do not let Avast sandbox any files during the run
Combo completed and made a log file. But the two problems still persist: security center disables and my browsers keep redirecting me to various shoddy sites?
Could you post the log please as combofix does not recognise all malware
This must some nasty bug! I hope you can help me get rid of it I also included the spybot log but in previous logs it found: Babylon toolbar, and 2 registry entries that disable the security center, and Funwebproducts.
OK now thionking MBR infection, more specifically volsnap - but lets see
Download aswMBR.exe ( 567KB ) to your desktop.
Double click the aswMBR.exe to run it
Click the “Scan” button to start scan
http://public.avast.com/~gmerek/aswMBR1.png
On completion of the scan click save log, save it to your desktop and post in your next reply
Hope a solution can be found. I appreciate immensely your help. Also Avast icon keeps disappearing from the toolbar and both my web brousers keep redirecting me to various sites like UNIBLUE, Casinos etc.
aswMBR version 0.9.6.399 Copyright(c) 2011 AVAST Software
Run date: 2011-06-18 19:00:40
19:00:40.428 OS Version: Windows x64 6.1.7601 Service Pack 1
19:00:40.428 Number of processors: 8 586 0x1A04
19:00:40.428 ComputerName: YIANNIS-PC UserName: yiannis
19:00:41.130 AVAST engine 6.0.1125 defs: 11061800
19:00:41.130 Initialize success
19:00:44.500 Disk 0 (boot) \Device\Harddisk0\DR0 → \Device\Ide\IdeDeviceP2T0L0-2
19:00:44.500 Disk 0 Vendor: WDC_WD6400AAKS-22A7B2 01.03B01 Size: 610480MB BusType: 3
19:00:44.516 Disk 1 \Device\Harddisk1\DR1 → \Device\Ide\IdeDeviceP3T1L0-7
19:00:44.516 Disk 1 Vendor: WDC_WD6400AAKS-22A7B2 01.03B01 Size: 610480MB BusType: 3
19:00:44.531 Disk 0 MBR read successfully
19:00:44.531 Disk 0 MBR scan
19:00:44.531 Disk 0 Windows 7 default MBR code
19:00:44.531 Service scanning
19:00:45.623 Disk 0 trace - called modules:
19:00:45.623 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys >>UNKNOWN [0xfffffa80055b12c0]<<
19:00:45.623 1 nt!IofCallDriver → \Device\Harddisk0\DR0[0xfffffa80065b5790]
19:00:45.623 3 CLASSPNP.SYS[fffff8800167243f] → nt!IofCallDriver → [0xfffffa8006396520]
19:00:45.623 5 ACPI.sys[fffff88000f067a1] → nt!IofCallDriver → \Device\Ide\IdeDeviceP2T0L0-2[0xfffffa800637e680]
19:00:45.623 \Driver\atapi[0xfffffa8006343730] → IRP_MJ_CREATE → 0xfffffa80055b12c0
19:00:45.639 AVAST engine scan C:\Windows\system32
19:01:47.805 Scan finished successfully
19:01:55.979 Disk 0 MBR has been saved successfully to “C:\Users\yiannis\Desktop\MBR.dat”
19:01:55.979 The log file has been saved successfully to “C:\Users\yiannis\Desktop\aswMBR.txt”
Yep the unknown is there, this may not run - so could you let me know as I have a reserve tool if needed
Please read carefully and follow these steps.
[*]Download TDSSKiller and save it to your Desktop.
[*]Extract its contents to your desktop.
[*]Once extracted, open the TDSSKiller folder and doubleclick on TDSSKiller.exe to run the application, then on Start Scan.
http://i466.photobucket.com/albums/rr21/JSntgRvr/TDSSKillermain.png
[*]If an infected file is detected, the default action will be Cure, click on Continue.
http://i466.photobucket.com/albums/rr21/JSntgRvr/TDSSKillerMal-1.png
[*]If a suspicious file is detected, the default action will be Skip, click on Continue.
http://i466.photobucket.com/albums/rr21/JSntgRvr/TDSSKillerSuspicious.png
[*]It may ask you to reboot the computer to complete the process. Click on Reboot Now.
http://i466.photobucket.com/albums/rr21/JSntgRvr/TDSSKillerCompleted.png
[*]If no reboot is require, click on Report. A log file should appear. Please copy and paste the contents of that file here.
[*]If a reboot is required, the report can also be found in your root directory, (usually C:\ folder) in the form of “TDSSKiller.[Version][Date][Time]_log.txt”. Please copy and paste the contents of that file here.
It found nothing? The Security centre is still being disabled and I still have this very annoying redirecting bug in my browsers. See attached report.
Once again thank you for your assistance.
Are the redirects in Firefox, IE or both ?
Also does anyone else using your router experience the same problem ?
Download Dr Web from here Fill in the small form and download
It will download as an 8 digit file save it to your desktop
Restart in safe mode and run
Accept the enhanced version
Then run the quick scan
About halfway through you will be prompted to buy - just X the box closed
Once finished it will generate a log please attach that
Both browsers.
DRWeb reported after scanning that viruses were found. I have attached the report.
What did it find ? as that is the setup and self check log
I don’t know as it did not mention them. All it said was “Attention, viruses have been found during the scan RC (…”. Also it does not complete in order to reach the point where a scan log is made. The report I posted is all that is generated and there are no other folders in the C/USERS/…/DR Web folder apart from the report I attached. ??? Dr Web only runs after normal boot; It does not run properly in Safe boot mode.
I run tdsskiller and it found the following:
2011/06/19 09:22:19.0679 4196 Detected object count: 1
2011/06/19 09:22:19.0679 4196 Actual detected object count: 1
2011/06/19 09:22:40.0193 4196 sptd (34f974f8b3c86de03a30dcbe79091c97) C:\Windows\system32\Drivers\sptd.sys
2011/06/19 09:22:40.0193 4196 Suspicious file (NoAccess): C:\Windows\system32\Drivers\sptd.sys. md5: 34f974f8b3c86de03a30dcbe79091c97
2011/06/19 09:22:40.0193 4196 C:\Windows\system32\Drivers\sptd.sys - copied to quarantine
2011/06/19 09:22:40.0208 4196 LockedFile.Multi.Generic(sptd) - User select action: Quarantine
I tried Dr web once more in safe mode and this time it completed the scan and found nothing? Before it had found viruses but could not complete the scan? This is very weird. Something is disabling security center. Something is hiding the Avast icon in the toolbar and only when I run Avast again does it show up. Something is redirecting on both web browsers?
I really need to kill this bug(s). A reformat is almost out of the question!
Someone must know how to find and DESTROY this bug?
Lets review all your start up elements
Please RIGHT-CLICK HERE and Save As (in IE it’s “Save Target As”, in FF it’s “Save Link As”) to download Silent Runners.
[*]Save it to the desktop.
[*]Run Silent Runner’s by doubleclicking the “Silent Runners” icon on your desktop.
[*]You will receive a prompt:
Do you want to skip supplementary searches?
click NO
[*]If you receive an error just click OK and double-click it to run it again - sometimes it won’t run as it’s supposed to the first time but will in subsequent runs.
[*]You will see a text file appear on the desktop - it’s not done, let it run (it won’t appear to be doing anything!)
[*]Once you receive the prompt All Done!, open the text file on the desktop, copy that entire log, and attach it here.
NOTE If you receive any warning message about scripts, please choose to allow the script to run.
I went to the registry that was pointed out by spybot and changed START from 3(manual start) to 2(automatic start) Then I uninstalled, rebooted and reinstalled Avast. now it seems that I no longer have a problem. Security centre is working. Avast is working, and I do not see any redirects in my browsers. I hope that this is not a temporary situation.
Please find attached the report you requested. EB, I truly wish to thank you for all the time and effort you have put into helping resolve my problem. Something must have worked! ;D
Sometimes that happens - the blindingly obvious is missed
That will be a permanent solution, but at least now you can be fairly confident that nothing is lurking
Leave it run for a day or so before I remove my tools just to be sure
Thanks a million mate ;D I shall wait and will let you know if this bug returns! And now for some Government virus cleaning (we are cleaning our parliament off corrupt MPs)This is the worst type of virus! It corrupts all of society!
Once more thank you!
Something is not right! EB, this bug must have done something to my system; when I go to this link and scroll down to the bottom I see html code???
http://www.icrass.com/component/content/article/34-demo-category/58-international-center-for-robotics-and-advanced-space-studies.html
You can see it in firefox also, so it is more to do with botched code on the page not hiding that.
Confirming this.
No idea, if it’s bad coding or for purpose - no time to analyse.
But it is not related to your prior problem.