I just got this malware today and I need help to take it out asap, sorry for that question but I have no idea how to take out malware out manually so can someone help. Also I just got full version of Avast a couple of hour ago but they don’t detect it.
Not much info you gave…
what malware…name?
is it avast that have detected it ?
where ?
what OS are you using? 32bit/64bit
Well it this right here http://www.youtube.com/watch?v=3K7QrrQNi-M
No avast hasn’t detected it, and I’m running window 7 32-bit. Can someone please help me. Also I don’t know to that in the video so I haven’t try it out yet if someone can explain it easier to a noob I will appreciate it a lot thank you for the help.
Read the hole guide before you start
Remove Hard Drive Diagnostic (Uninstall Guide)
http://www.bleepingcomputer.com/virus-removal/remove-hard-drive-diagnostic
Thank you while it stop from launching when I start my computer is still here so is there anything else I can do to permanently remove it?
The guide i posted tell you how to permanetly remove it
or are you saying that you followed the guide and it is still there ?
Basically the second one sorry if I wasn’t clear, I’m running a second full system malewarebyte to see if it remove.
post the scan log when done
Malwarebytes’ Anti-Malware 1.50
www.malwarebytes.org
Database version: 5262
Windows 6.1.7600
Internet Explorer 8.0.7600.16385
12/7/2010 1:42:50 PM
mbam-log-2010-12-07 (13-42-50).txt
Scan type: Full scan (C:|)
Objects scanned: 309844
Time elapsed: 1 hour(s), 1 minute(s), 14 second(s)
Memory Processes Infected: 1
Memory Modules Infected: 1
Registry Keys Infected: 0
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 2
Memory Processes Infected:
c:\Users\juan\AppData\Local\Temp\237854.exe (Rogue.HDDScan) → 5548 → Unloaded process successfully.
Memory Modules Infected:
c:\Users\juan\AppData\Local\Temp\qvgbqcmsas.dll (Rogue.HDDScan) → Delete on reboot.
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\237854 (Rogue.HDDScan) → Value: 237854 → Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
c:\Users\juan\AppData\Local\Temp\qvgbqcmsas.dll (Rogue.HDDScan) → Delete on reboot.
c:\Users\juan\AppData\Local\Temp\237854.exe (Rogue.HDDScan) → Quarantined and deleted successfully.
So is your problem solved ?
that the thing it still in my computer
Follow this guide form our expert malware remover Essexboy and post the log`s here
http://forum.avast.com/index.php?topic=53253.0
To avoid using multiple post with copy and paste you have to attach the log`s
Lower left corner: Additional Options > Attach ( OTL.Txt and Extras.Txt. )
Essexboy is notified
Monitoring
Ok did it so should I post the olt.txt list here? Also I notice that everytime I run malwarebyte program It find the malware but everytime I try to remove them it tell me that some can’t be remove. So I restart my comp and run it again only to find out it still there all of them.
Attach the OTL log
On the reply page locate additional options - bottom left
Browse to the OTL file
Then post
Ok here my olt list k, hope it help
Run OTL
[*]Under the Custom Scans/Fixes box at the bottom, paste in the following
:OTL PRC - [2010/12/06 20:59:20 | 000,448,000 | ---- | M] (MEDIA Corporation) -- C:\Users\juan\AppData\Local\Temp\IGwqNKmplw.exe SRV - [2010/04/08 15:46:20 | 000,154,152 | ---- | M] (Authentium, Inc) [Auto | Running] -- C:\Program Files\Common Files\Authentium\AntiVirus5\vseqrts.exe -- (vseqrts) SRV - [2010/04/08 15:46:18 | 000,117,288 | R--- | M] (Authentium, Inc) [Auto | Running] -- C:\Program Files\Common Files\Authentium\AntiVirus5\vsedsps.exe -- (vsedsps) SRV - [2010/04/08 15:46:12 | 000,117,288 | R--- | M] (Authentium, Inc) [Auto | Running] -- C:\Program Files\Common Files\Authentium\AntiVirus5\vseamps.exe -- (vseamps) O3 - HKU\S-1-5-21-3104040009-1492376757-3879208002-1000\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found. O4 - HKLM..\Run: [RegistryQuick.exe] C:\Program Files\RegQuick\RegistryQuick.exe File not found O4 - HKU\S-1-5-21-3104040009-1492376757-3879208002-1000..\Run: [IGwqNKmplw.exe] C:\Users\juan\AppData\Local\Temp\IGwqNKmplw.exe (MEDIA Corporation) [2010/12/06 22:32:12 | 000,000,000 | ---D | C] -- C:\Program Files\RegQuick [2009/12/20 16:33:37 | 000,000,000 | ---D | M] -- C:\Users\juan\AppData\Roaming\com.doubleperfect.ggpo.0753AD3679DBFCA1E7F470171B7D0DB8B404A7EA.1:Files
ipconfig /flushdns /c:Commands
[purity]
[resethosts]
[emptytemp]
[EMPTYFLASH]
[CREATERESTOREPOINT]
[Reboot]
[*]Then click the Run Fix button at the top
[*]Let the program run unhindered, reboot the PC when it is done
[*]Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.
.
THEN
Download ComboFix from one of these locations:
* IMPORTANT !!! Save ComboFix.exe to your Desktop
[]Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
[]Double click on ComboFix.exe & follow the prompts.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.