fgr.exe - dissables all programmes including avast

OK lets go for a real deep look - this can be run from safe mode

Download AVPTool from Here to your desktop

Run the programme you have just downloaded to your desktop (it will be randomly named )

First we will run a virus scan

On the first tab select all elements down to and includingComputer and then select start scan
Once it has finished select report and post that.

http://i1224.photobucket.com/albums/ee362/Essexboy3/avpfront.jpg

Do not close AVPTool or it will self uninstall, if it does uninstall - then just rerun the setup file on your desktop

Now an analysis scan

Select the Manual Disinfection tab
Press the Gather System Information button
Once done Open the last report saved folder then attach the zip file to your next post zip
The file is located at C:\Users[i]your name[/i]\Desktop\Virus Removal Tool\setup_9.0.0.722_05.01.2011_20-34\LOG\avptool_sysinfo.zip

http://i1224.photobucket.com/albums/ee362/Essexboy3/avpmanual.jpg

It said it couldnt be runin safe mode so have re-started the pc and am running normally now…looks like its going to take a long time.

Also…I started googling .exe files that are running in task manager that i didnt recognise and nsvc32.exe comes up as linked to the Panddos Trojan. Does this change anything or shall I just conitnue running the kaspersky tool for now?

Ok I ran the scan and it found a number of infections and recommended to delete them, but as you didn’t mention this I just skipped them. I’ve attatched the log notepad but it’s saying you can’t upload .zip files when I try to attach that too. Do you want me to unzip it or something?

Awaiting your advice! Cheers.

Have unzipped…but it doesnt like those file either! Plan c?

I keep forgetting that this forum will not allow zip files, upload it to Mediafire and post the sharing link.

The file Kaspersky found were either in quarantine or system restore ;D

Never used this so hope I have the right link… http://www.mediafire.com/?nx4dy8mj871ck3p hows that?

Hmm I am seeing no sign of fgr.exe in any log at all

Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2

[*]Double-click SystemLook.exe to run it.
[*]Copy the content of the following codebox into the main textfield:

:filefind
fgr.*  

[*]Click the Look button to start the scan.
[*]When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt

Ok will run that now, incidently I noticed nsvc32.exe running in task manager before, which is apparently malware related? will post that log shortly…

Is that the correct file name ? As that file is detected by Kaspersky - Avast - Combofix and MBAM

nvsvc32.exe is a legitimate file

Sorry I’d written it down wrong :s - was nvsvc32.exe…

I’ve installed System look and pasted the text but clicking look seems to do nothing… Any tips?

It will be searching you entire hard drive for a file with that characteristic, so it may take a few minutes

Do you still see the file running ?

Ok, managed to run as administrator. Log is attatched… back to you sir.

No when I tried to run it normally clicking the button did nothing…when i ran as administrator it came up “scanning system” - log attatched in previous post

No sign at all of fgr.exe do you still see it in task manager ?

If so what is the path and I will remove it prior to windows boot

Nope, can’t see it there… don’t know if it’s any use but I’ve attached a hijackthis log to this post.

Is it still interfering ?

If so lets look at all startup, HJT is pretty useless for this

Please RIGHT-CLICK HERE and Save As (in IE it’s “Save Target As”, in FF it’s “Save Link As”) to download Silent Runners.

[*]Save it to the desktop.
[*]Run Silent Runner’s by doubleclicking the “Silent Runners” icon on your desktop.
[*]You will receive a prompt:
[b]Do you want to skip supplementary searches?
click NO
[*]If you receive an error just click OK and double-click it to run it again - sometimes it won’t run as it’s supposed to the first time but will in subsequent runs.
[*]You will see a text file appear on the desktop - it’s not done, let it run (it won’t appear to be doing anything!)
[*]Once you receive the prompt All Done!, open the text file on the desktop, copy that entire log, and paste it here.
NOTE If you receive any warning message about scripts, please choose to allow the script to run.

It won’t let me paste it because it’s over 10000 characters so i’ve attatched it in its original notepad.

I don’t know if it’s fgr.exe that’s interfering but something definitely isn’t right. The pop ups stopped after the first fix two fixes you recommended but now everything runs VERY slowely…like…double click, wait 5 minutes etc… And when I try to open a program it asks me to choose a program to open it with?!

Also, if it’s relevent, In the start menu I notice firefox appears as “Firefox (Safemode)”

OK found it

Start OTS. Copy/Paste the information in the quotebox below into the panel where it says “Paste fix here” and then click the Run Fix button.

[Unregister Dlls]
[Custom Items]
:Reg
[-HKCU\Software\Classes\exefile]
[-HKCU\Software\Classes\.exe]
:Files
C:\Documents and Settings\Ollie\Local Settings\Application Data\fgr.exe
:end
[Empty Temp Folders]
[EmptyFlash]
[CreateRestorePoint]
  

The fix should only take a very short time. When the fix is completed a message box will popup telling you that it is finished. Click the Ok button and Notepad will open with a log of actions taken during the fix. Post that information back here

I will review the information when it comes back in.

Thanks. Attached is the log… If it makes any difference it asked me to re-start when it finished, which I did. When I logged back on it obviously tried to start OTS again and asked me which program to open it with…had to right click run as administrator again.

Anyway, log attached. Thanks

OK OTS did not find those registry keys

Lets use OTL as it will look in a different area - just attach the resultant log please

Download OTL to your Desktop

[*]Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
[*]Select All Users
[*]Under the Custom Scan box paste this in

netsvcs
%SYSTEMDRIVE%*.exe
/md5start
explorer.exe
winlogon.exe
Userinit.exe
svchost.exe
/md5stop
%systemroot%*. /mp /s
CREATERESTOREPOINT

[*]Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.

[*]When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
[*]Post both logs