LNK:Runner! Over and over again!

Please someone, anybody… Have headache because off that…

???

My avast (free edition) notice me constatly about detecting infection LNK Runner… If anyone has a solution…

Which shield…?
Can you post a screenshot…?

Possibly a stuxnet infection. This happens if you have not updated your windows.

First use this tool: http://www.malwarecity.com/community/index.php?app=downloads&showfile=12 and click options > select full system scan and remove the malware found, if required restart.

Do a full system scan using avast. If anything is found, move it to chest.

Then, update your windows by going to http://windowsupdate.microsoft.com/

tnx… will try.

Didn’t help…
Avast constatly notice me : “Malwere blocked”… Infection: LNK:Runner…
Full scan in safe mode detected win32.sality.gr, moved in chest…
But again, there is notification :“Malwere blocked”… Infection: LNK:Runner…

But, thanks anyway… :wink:
I’ve had enough of this
Seems that format is only option

If someone have idea for resolve my problem, before i start formating? Realy hate that…

Avast version…??
OS…??
Did you run a boot time scan with avast! yet…??

Yes, I did… Nothing detect… But first, i had run full scan with avast in the safe mode… Found over 90 Win32.Sality-gr, moved to chest and after that i was run boot time scan and found nothing… i hoped that is it…
But no… When I started windows in normal mode, after few minutes, avast blocked malwer…Again! Show infection LNK:Runner…

Sorry, my english is so bad… :slight_smile:

Do you want to dig deeper…??
If so, I’ll ask essexboy to join this topic.

ok

Ok, he is informed.
Good luck…!

OK lets see what is hiding

To ensure that I get all the information this log will need to be attached (instructions at the end) if it is to large to attach then upload to Mediafire and post the sharing link.

Download OTS to your Desktop

[*]Close ALL OTHER PROGRAMS.
[*]Double-click on OTS.exe to start the program.
[*]Check the box that says Scan All Users
[*]Under Additional Scans check the following:

Reg - Disabled MS Config Items
Reg - Drivers32
Reg - NetSvcs
Reg - SafeBoot Minimal
Reg - Shell Spawning
Evnt - EventViewer Logs (Last 10 Errors)
File - Lop Check

[*]Under the Custom Scan box paste this in


%USERPROFILE%..|smtmp;true;true;true /FP
%SYSTEMDRIVE%*.exe
/md5start
volsnap.*
explorer.exe
winlogon.exe
Userinit.exe
svchost.exe
/md5stop
%systemroot%*. /mp /s
hklm\software\clients\startmenuinternet|command /rs
hklm\software\clients\startmenuinternet|command /64 /rs
CREATERESTOREPOINT

[*]Now click the Run Scan button on the toolbar.
[*]Let it run unhindered until it finishes.
[*]When the scan is complete Notepad will open with the report file loaded in it.
[*]Click the Format menu and make sure that Wordwrap is not checked. If it is then click on it to uncheck it.

Please attach the log in your next post.

THEN

Download aswMBR.exe ( 567KB ) to your desktop.

Double click the aswMBR.exe to run it

Click the “Scan” button to start scan

http://public.avast.com/~gmerek/aswMBR1.png

On completion of the scan click save log, save it to your desktop and post in your next reply

http://public.avast.com/~gmerek/aswMBR2.png

???

Ex, Spammer on forum spam listing, will be history shortly.

Sorry, I was busy…

If it isn’t to late… But i’ll be very happy if it is…:slight_smile:

aswMBR version 0.9.7.777 Copyright(c) 2011 AVAST Software
Run date: 2011-07-18 08:09:48

08:09:48.296 OS Version: Windows 5.1.2600 Service Pack 3
08:09:48.296 Number of processors: 2 586 0x605
08:09:48.296 ComputerName: RUDNIK UserName:
08:09:48.781 Initialize success
08:09:49.515 AVAST engine defs: 11071702
08:10:00.812 Disk 0 (boot) \Device\Harddisk0\DR0 → \Device\Ide\IdeDeviceP2T0L0-e
08:10:00.812 Disk 0 Vendor: WDC_WD2500KS-00MJB0 02.01C03 Size: 238475MB BusType: 3
08:10:00.828 Disk 0 MBR read successfully
08:10:00.828 Disk 0 MBR scan
08:10:00.828 Disk 0 Windows XP default MBR code
08:10:00.828 Disk 0 scanning sectors +488376000
08:10:00.906 Disk 0 scanning C:\WINDOWS\system32\drivers
08:10:11.234 Service scanning
08:10:12.281 Disk 0 trace - called modules:
08:10:12.296 ntoskrnl.exe CLASSPNP.SYS disk.sys atapi.sys hal.dll pciide.sys PCIIDEX.SYS
08:10:12.296 1 nt!IofCallDriver → \Device\Harddisk0\DR0[0x87307ab8]
08:10:12.296 3 CLASSPNP.SYS[f74effd7] → nt!IofCallDriver → \Device\Ide\IdeDeviceP2T0L0-e[0x87309b00]
08:10:12.468 AVAST engine scan C:\WINDOWS
08:10:15.203 AVAST engine scan C:\WINDOWS\system32
08:11:11.484 AVAST engine scan C:\WINDOWS\system32\drivers
08:11:18.796 AVAST engine scan C:\Documents and Settings\Administrator
08:14:40.531 AVAST engine scan C:\Documents and Settings\All Users
08:15:06.265 Scan finished successfully
08:15:33.703 Disk 0 MBR has been saved successfully to “C:\Documents and Settings\Administrator\Desktop\MBR.dat”
08:15:33.703 The log file has been saved successfully to “C:\Documents and Settings\Administrator\Desktop\aswMBR.txt”

Here we go again!
Avast just detected LNK infection…

one for example…

Infection Details
URL: file://C:\Documents and Settings\All Users\Documents\DIREKTNI SPORAZUM-ROBE.rtf.lnk
Process: PID 4
Infection: lnk:Runner