hdd diagnostic malware

I just got this malware today and I need help to take it out asap, sorry for that question but I have no idea how to take out malware out manually so can someone help. Also I just got full version of Avast a couple of hour ago but they don’t detect it.

Not much info you gave…
what malware…name?
is it avast that have detected it ?
where ?
what OS are you using? 32bit/64bit

Well it this right here http://www.youtube.com/watch?v=3K7QrrQNi-M

No avast hasn’t detected it, and I’m running window 7 32-bit. Can someone please help me. Also I don’t know to that in the video so I haven’t try it out yet if someone can explain it easier to a noob I will appreciate it a lot thank you for the help.

Read the hole guide before you start

Remove Hard Drive Diagnostic (Uninstall Guide)
http://www.bleepingcomputer.com/virus-removal/remove-hard-drive-diagnostic

Thank you while it stop from launching when I start my computer is still here so is there anything else I can do to permanently remove it?

The guide i posted tell you how to permanetly remove it

or are you saying that you followed the guide and it is still there ?

Basically the second one :stuck_out_tongue: sorry if I wasn’t clear, I’m running a second full system malewarebyte to see if it remove.

post the scan log when done

Malwarebytes’ Anti-Malware 1.50
www.malwarebytes.org

Database version: 5262

Windows 6.1.7600
Internet Explorer 8.0.7600.16385

12/7/2010 1:42:50 PM
mbam-log-2010-12-07 (13-42-50).txt

Scan type: Full scan (C:|)
Objects scanned: 309844
Time elapsed: 1 hour(s), 1 minute(s), 14 second(s)

Memory Processes Infected: 1
Memory Modules Infected: 1
Registry Keys Infected: 0
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 2

Memory Processes Infected:
c:\Users\juan\AppData\Local\Temp\237854.exe (Rogue.HDDScan) → 5548 → Unloaded process successfully.

Memory Modules Infected:
c:\Users\juan\AppData\Local\Temp\qvgbqcmsas.dll (Rogue.HDDScan) → Delete on reboot.

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\237854 (Rogue.HDDScan) → Value: 237854 → Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
c:\Users\juan\AppData\Local\Temp\qvgbqcmsas.dll (Rogue.HDDScan) → Delete on reboot.
c:\Users\juan\AppData\Local\Temp\237854.exe (Rogue.HDDScan) → Quarantined and deleted successfully.

So is your problem solved ?

that the thing it still in my computer :frowning:

Follow this guide form our expert malware remover Essexboy and post the log`s here
http://forum.avast.com/index.php?topic=53253.0

To avoid using multiple post with copy and paste you have to attach the log`s
Lower left corner: Additional Options > Attach ( OTL.Txt and Extras.Txt. )

Essexboy is notified

Monitoring

Ok did it so should I post the olt.txt list here? Also I notice that everytime I run malwarebyte program It find the malware but everytime I try to remove them it tell me that some can’t be remove. So I restart my comp and run it again only to find out it still there all of them.

Attach the OTL log

On the reply page locate additional options - bottom left
Browse to the OTL file
Then post

Ok here my olt list k, hope it help

Run OTL

[*]Under the Custom Scans/Fixes box at the bottom, paste in the following

:OTL PRC - [2010/12/06 20:59:20 | 000,448,000 | ---- | M] (MEDIA Corporation) -- C:\Users\juan\AppData\Local\Temp\IGwqNKmplw.exe SRV - [2010/04/08 15:46:20 | 000,154,152 | ---- | M] (Authentium, Inc) [Auto | Running] -- C:\Program Files\Common Files\Authentium\AntiVirus5\vseqrts.exe -- (vseqrts) SRV - [2010/04/08 15:46:18 | 000,117,288 | R--- | M] (Authentium, Inc) [Auto | Running] -- C:\Program Files\Common Files\Authentium\AntiVirus5\vsedsps.exe -- (vsedsps) SRV - [2010/04/08 15:46:12 | 000,117,288 | R--- | M] (Authentium, Inc) [Auto | Running] -- C:\Program Files\Common Files\Authentium\AntiVirus5\vseamps.exe -- (vseamps) O3 - HKU\S-1-5-21-3104040009-1492376757-3879208002-1000\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found. O4 - HKLM..\Run: [RegistryQuick.exe] C:\Program Files\RegQuick\RegistryQuick.exe File not found O4 - HKU\S-1-5-21-3104040009-1492376757-3879208002-1000..\Run: [IGwqNKmplw.exe] C:\Users\juan\AppData\Local\Temp\IGwqNKmplw.exe (MEDIA Corporation) [2010/12/06 22:32:12 | 000,000,000 | ---D | C] -- C:\Program Files\RegQuick [2009/12/20 16:33:37 | 000,000,000 | ---D | M] -- C:\Users\juan\AppData\Roaming\com.doubleperfect.ggpo.0753AD3679DBFCA1E7F470171B7D0DB8B404A7EA.1

:Files
ipconfig /flushdns /c

:Commands
[purity]
[resethosts]
[emptytemp]
[EMPTYFLASH]
[CREATERESTOREPOINT]
[Reboot]

[*]Then click the Run Fix button at the top
[*]Let the program run unhindered, reboot the PC when it is done
[*]Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.

.
THEN

Download ComboFix from one of these locations:

Link 1
Link 2

* IMPORTANT !!! Save ComboFix.exe to your Desktop

[]Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
[
]Double click on ComboFix.exe & follow the prompts.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.