Help and advise needed !

Hello Folks,

Recently I rather stupidly opened up a zip file that contain virus’s .Straight away the antivirus that came with my ISP kicked into action and scanned and apparently removed all the virus’s on my computer . I wasn’t fully certain so i downloaded avast and also bit defender. Bit defender found two infections and also avast found some . After this i ran another antivirus it told me my system was clean .

Here’s where the problems start .When i look on the fire wall service list that came with my ISP I am shown this

http://i49.tinypic.com/2i137m9.jpg

These are just some of the Trojans /Other viruses on the service list .(Please note ‘xz x’ is a rule i made for all of the viruses to be denied completely)

As-well on the avast services list they are not present at all . To find out which one of these ‘Services’ was trying to access my computer i put on a firewall warning popup and this is what is shown …

http://i46.tinypic.com/257f8sk.jpg

Each time it is exactly the same IP , Which would suggest to me there is one tricky virus left somewhere on the system . I have also noticed the internet is slightly slower which may just be a network problem , And also I get an error saying Windows security centre cannot be started .

Any help is greatly appreciated ,Thanks.

Follow this guide: http://forum.avast.com/index.php?topic=53253.0

and attach ( Do not copy/paste ) logs for malwarebytes’, OTL, and aswMBR.exe here:

Where an expert in the removal of malware will help you.

Monitoring

Some registry items when the virus’s were first found were changed,which i have now fixed . Do you think there could still be registry items remaining from the virus’s?

The registry is not really the problem it is the files

What program do you think would be able to locate and destroy them ? I have already scanned with SpyBot , Avast, TalkTalk and Bit Defender.

Follow the link I posted and attach log for MBAM, OTL and aswMBR

Without them Essexboy can not do anything.

I will follow the steps it seems like the last option :slight_smile: Just out of interest why are these virus services not showing up i avast and what is essexboy ? . Its been a while since i have encountered problems.

Essexboy is an expert and instructor in malware removal. He is monitoring your thread and waiting for the logs.

;D ;D ;D

i currently in the process of running malware bites .Will it give me the option to view the logs when the scan has finished ? :slight_smile:

Ok here is the log after running malware bites. Nothing special really…

Database version: v2012.07.15.10

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
David :: David [administrator]

15/07/2012 23:10:49
mbam-log-2012-07-15 (23-10-49).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 214388
Time elapsed: 10 minute(s), 36 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

Here are all the logs for OTL :slight_smile:

And finally MBR ,Please get back to me as soon as possible :slight_smile:

Dafssheaa

Essexboy is in bed by now. He lives in the UK. He will be with more instruction tomorrow. Nothing to do now but wait.

Ok no problem :slight_smile:

Is there any update on my problem yet? Thanks :slight_smile:

Hi you have three or four antivirus programmes running… You need to bring that down to one.

Is your firewall off ?

run farbar service scanner

http://i1224.photobucket.com/albums/ee362/Essexboy3/Farbar/FSS-1.jpg

Tick “All” options.
Press “Scan”.
It will create a log (FSS.txt) in the same directory the tool is run.

Please copy and paste the log to your reply.

I have now brought it down to 1single antivirus and wil run that program now :slight_smile:

Here is the log