I have a rootkit popup coming on, asking for reboot and after reboot “MBR://./PHYSICALDRIVE0” still appears again and prompt for reboot immediately for removing the rootkit, which avast! wont delete later.
In boot-time scan - the disk 0 master boot record virus will be shown in the very beginning of scan but wont show the options to delete it or to move to chest (no options shown) but it rather continues to scan other files.
I use avast internet security along with Malwarebytes(updated regularly) i have posted the scan result of malwarebytes also.
I read other similar posts about this and downloaded OTS.exe and aswMBR.exe
i have posted the scan result of both below.
(The virus is sort of taming Mozilla firefox, i can’t login to gmail, shows password incorrect and sometimes redirects to trouble shooting page which tells how to fix the cookies problem. now i’m using chrome)
Save the log as before and post in your next reply
THEN
Download OTS to your Desktop and double-click on it to run it
[*]Make sure you close all other programs and don’t use the PC while the scan runs.
[*]Select All Users
[*]Under additional scans select the following Reg - Disabled MS Config Items
Reg - Drivers32
Reg - NetSvcs
Reg - SafeBoot Minimal
Reg - Shell Spawning
Evnt - EventViewer Logs (Last 10 Errors)
File - Lop Check
[*]Now click the Run Scan button on the toolbar. Make sure not to use the PC while the program is running or it will freeze.
[*]When the scan is complete Notepad will open with the report file loaded in it.
[*]Please attach the log in your next post.
See here for what a HOSTS file is. http://www.mvps.org/winhelp2002/hosts.htm
(and you may want to go to profile, account related settings and hide your e-mail address from public.)
What the import of that is - everytime you put paypal in the address bar of your browser you will get redirected to that site… I will clear it along with the AVG/Norton drivers left behind
Start OTS. Copy/Paste the information in the quotebox below into the panel where it says “Paste fix here” and then click the Run Fix button.
[Unregister Dlls]
[Driver Services - Safe List]
YY -> (Avgfwfd) AVG network filter service [Kernel | On_Demand | Stopped] -> C:\WINDOWS\system32\drivers\avgfwdx.sys
YY -> (Avgfwdx) Avgfwdx [Kernel | On_Demand | Stopped] -> C:\WINDOWS\system32\drivers\avgfwdx.sys
[Registry - Safe List]
< Internet Explorer Settings [HKEY_LOCAL_MACHINE\] > ->
YN -> HKEY_LOCAL_MACHINE\: Main\\"Search Page" -> ${URL_SEARCHPAGE}
< Internet Explorer Settings [HKEY_USERS\S-1-5-21-1417001333-436374069-1547161642-500\] > ->
YN -> HKEY_USERS\S-1-5-21-1417001333-436374069-1547161642-500\: Main\\"Search Page" -> ${URL_SEARCHPAGE}
YN -> HKEY_USERS\S-1-5-21-1417001333-436374069-1547161642-500\: Main\\"Start Page" -> http://home.mywebsearch.com/index.jhtml?n=77C09F4F&ptnrS=ZRxdm799YYIN&ptb=1er2NixDstrHMMyGHHkSTw
YN -> HKEY_USERS\S-1-5-21-1417001333-436374069-1547161642-500\: "ProxyOverride" -> 127.0.0.1;*.local
< FireFox Settings [Prefs.js] > -> C:\Documents and Settings\Administrator\Application Data\Mozilla\FireFox\Profiles\0cuetjsl.default\prefs.js
YN -> keyword.URL -> "http://search.mywebsearch.com/mywebsearch/GGmain.jhtml?id=ZRxdm799YYIN&ptb=1er2NixDstrHMMyGHHkSTw&ind=2011021408&ptnrS=ZRxdm799YYIN&si=&n=77ddc060&psa=&st=kwd&searchfor="
< FireFox SearchPlugins [User Folders] > ->
YY -> mywebsearch.xml -> C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\0cuetjsl.default\searchplugins\mywebsearch.xml
< HOSTS File > ([2010/04/14 20:30:24 | 000,000,738 | ---- | M] - 19 lines) -> C:\WINDOWS\system32\drivers\etc\hosts
YN -> Reset Hosts ->
< BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
YN -> {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} [HKLM] -> Reg Error: Key error. [AVG Safe Search]
< Internet Explorer ToolBars [HKEY_USERS\S-1-5-21-1417001333-436374069-1547161642-500\] > -> HKEY_USERS\S-1-5-21-1417001333-436374069-1547161642-500\Software\Microsoft\Internet Explorer\Toolbar\
YN -> WebBrowser\\"{D4027C7F-154A-4066-A1AD-4243D8127440}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.]
< Internet Explorer Extensions [HKEY_USERS\S-1-5-21-1417001333-436374069-1547161642-500\] > -> HKEY_USERS\S-1-5-21-1417001333-436374069-1547161642-500\Software\Microsoft\Internet Explorer\Extensions\
YN -> CmdMapping\\"{4248FE82-7FCB-46AC-B270-339F08212110}" [HKLM] -> [Reg Error: Key error.]
YN -> CmdMapping\\"{CCF151D8-D089-449F-A5A4-D9909053F20F}" [HKLM] -> [Reg Error: Key error.]
YN -> CmdMapping\\"{DFB852A3-47F8-48C4-A200-58CAB36FD2A2}" [HKLM] -> [Reg Error: Key error.]
[Files/Folders - Created Within 30 Days]
NY -> qwqewr -> C:\Documents and Settings\Administrator\Desktop\qwqewr
NY -> Symantec Shared -> C:\Program Files\Common Files\Symantec Shared
NY -> Norton -> C:\Documents and Settings\All Users\Application Data\Norton
NY -> NortonInstaller -> C:\Documents and Settings\All Users\Application Data\NortonInstaller
[Files - No Company Name]
NY -> man8.exe -> C:\WINDOWS\System32\man8.exe
[File - Lop Check]
NY -> PriceGong -> C:\Documents and Settings\Administrator\Application Data\PriceGong
NY -> avg9 -> C:\Documents and Settings\All Users\Application Data\avg9
[Custom Items]
:Files
ipconfig /flushdns /c
:end
[Empty Temp Folders]
[EmptyFlash]
[CreateRestorePoint]
[ClearAllRestorePoints]
The fix should only take a very short time. When the fix is completed a message box will popup telling you that it is finished. Click the Ok button and Notepad will open with a log of actions taken during the fix. Post that information back here
I will review the information when it comes back in.
actually after finishing it asked for reboot and i Click ok to reboot the pc.
All Processes Killed
[Driver Services - Safe List]
Service Avgfwfd stopped successfully!
Service Avgfwfd deleted successfully!
C:\WINDOWS\system32\drivers\avgfwdx.sys moved successfully.
Service Avgfwdx stopped successfully!
Service Avgfwdx deleted successfully!
File C:\WINDOWS\system32\drivers\avgfwdx.sys not found.
[Registry - Safe List]
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Main not found.
Registry key HKEY_USERS\S-1-5-21-1417001333-436374069-1547161642-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Main not found.
Registry key HKEY_USERS\S-1-5-21-1417001333-436374069-1547161642-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Main not found.
Registry value HKEY_USERS\S-1-5-21-1417001333-436374069-1547161642-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyOverride deleted successfully.
Prefs.js: “http://search.mywebsearch.com/mywebsearch/GGmain.jhtml?id=ZRxdm799YYIN&ptb=1er2NixDstrHMMyGHHkSTw&ind=2011021408&ptnrS=ZRxdm799YYIN&si=&n=77ddc060&psa=&st=kwd&searchfor=” removed from keyword.URL
C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\0cuetjsl.default\searchplugins\mywebsearch.xml moved successfully.
HOSTS file reset successfully!
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}\ deleted successfully.
Registry value HKEY_USERS\S-1-5-21-1417001333-436374069-1547161642-500\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{D4027C7F-154A-4066-A1AD-4243D8127440} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID{D4027C7F-154A-4066-A1AD-4243D8127440}\ not found.
Registry value HKEY_USERS\S-1-5-21-1417001333-436374069-1547161642-500\Software\Microsoft\Internet Explorer\Extensions\CmdMapping\{4248FE82-7FCB-46AC-B270-339F08212110} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID{4248FE82-7FCB-46AC-B270-339F08212110}\ not found.
Registry value HKEY_USERS\S-1-5-21-1417001333-436374069-1547161642-500\Software\Microsoft\Internet Explorer\Extensions\CmdMapping\{CCF151D8-D089-449F-A5A4-D9909053F20F} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID{CCF151D8-D089-449F-A5A4-D9909053F20F}\ not found.
Registry value HKEY_USERS\S-1-5-21-1417001333-436374069-1547161642-500\Software\Microsoft\Internet Explorer\Extensions\CmdMapping\{DFB852A3-47F8-48C4-A200-58CAB36FD2A2} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID{DFB852A3-47F8-48C4-A200-58CAB36FD2A2}\ not found.
[Files/Folders - Created Within 30 Days]
C:\Documents and Settings\Administrator\Desktop\qwqewr\psp\MP_ROOT\100MNV01 folder moved successfully.
C:\Documents and Settings\Administrator\Desktop\qwqewr\psp\MP_ROOT folder moved successfully.
C:\Documents and Settings\Administrator\Desktop\qwqewr\psp folder moved successfully.
C:\Documents and Settings\Administrator\Desktop\qwqewr folder moved successfully.
C:\Program Files\Common Files\Symantec Shared\SymcData\VirusDefs-2.5-E\newdefs-trigger folder moved successfully.
C:\Program Files\Common Files\Symantec Shared\SymcData\VirusDefs-2.5-E folder moved successfully.
C:\Program Files\Common Files\Symantec Shared\SymcData folder moved successfully.
C:\Program Files\Common Files\Symantec Shared folder moved successfully.
C:\Documents and Settings\All Users\Application Data\Norton{086A63F0-6B13-4F29-9695-134E7A01E963} folder moved successfully.
C:\Documents and Settings\All Users\Application Data\Norton folder moved successfully.
C:\Documents and Settings\All Users\Application Data\NortonInstaller\Logs\2011-03-09-17h03m42s folder moved successfully.
C:\Documents and Settings\All Users\Application Data\NortonInstaller\Logs\2011-03-09-17h02m04s folder moved successfully.
C:\Documents and Settings\All Users\Application Data\NortonInstaller\Logs folder moved successfully.
C:\Documents and Settings\All Users\Application Data\NortonInstaller folder moved successfully.
[Files - No Company Name]
C:\WINDOWS\System32\man8.exe moved successfully.
[File - Lop Check]
C:\Documents and Settings\Administrator\Application Data\PriceGong\Data folder moved successfully.
C:\Documents and Settings\Administrator\Application Data\PriceGong folder moved successfully.
C:\Documents and Settings\All Users\Application Data\avg9\Log folder moved successfully.
C:\Documents and Settings\All Users\Application Data\avg9 folder moved successfully.
[Custom Items]
========== FILES ==========
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Documents and Settings\Administrator\Desktop\cmd.bat deleted successfully.
C:\Documents and Settings\Administrator\Desktop\cmd.txt deleted successfully.
[Empty Temp Folders]
:
even after constantly cleaning the temporary file with TuneUp Utilities 2009 and CCleaner
this softwares couldn’t clean 534.00 mb, that’s some great work u just did!!!
That is an inactive sector now and of no great import. So is it running OK ?
Use this instead of CC it goes a lot deeper - made by the same author ;D
Clear Cache/Temp Files
Download TFC by OldTimer to your desktop
[*] Please double-click TFC.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
[*]It will close all programs when run, so make sure you have saved all your work before you begin.
[*]Click the Start button to begin the process. Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two. Let it run uninterrupted to completion.
[*]Once it’s finished it should reboot your machine. If it does not, please manually reboot the machine yourself to ensure a complete clean.
well it looks alright for the movement, i should appreciate u for fast & constant help provided by you, that’s a great thing. 8)
there is one thing boggles my mind is number of processes happen in my task manager, lot of unknown processes eats up memory.
as i work on animation heavy files, it makes my pc temperature rise but at the time of brand new OS installation i have been working for 18 hours or so .
so now i have to stop my work for few hours.
is there any process to kill unwanted processes permanently or if u get me some solution.
i will be very thankful if you could help.