Topic for peelfeen

new topic … Grey button in top right corner of evry forum section. :wink: You dont see it if inside a topic

@Peelfeen Click reply and attach your logs here

OK got it Pondus :slight_smile:

A different USB infection

Download the attached Fixlist.txt to the same location as FRST
Run FRST and press Fix
On completion a log will be generated please post that

THEN

Download MCShield to your desktop and install
It will initially run a scan and show the result as a toaster by the system clock
Then in the control centre select scanner and tick unhide items on flash drives

https://dl.dropbox.com/u/73555776/mcshield%20unhide.JPG

Plug in the drive and McShield will start a scan

Then get the log which will be located under the logs tab on the main page

And post that

FINALLY

Download OTL to your Desktop
Secondary link

[*]Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.

https://dl.dropboxusercontent.com/u/73555776/OTL_Main_Tutorial.gif

[*]Select All Users
[]Select LOP and Purity
[
]Under the Custom Scan box paste this in

netsvcs
BASESERVICES
%SYSTEMDRIVE%*.exe
c:\program files (x86)\Google\Desktop
c:\program files\Google\Desktop
dir “%systemdrive%*” /S /A:L /C
/md5start
rpcss.dll
/md5stop
CREATERESTOREPOINT

[*]Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
[*]When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
[*]Attach both logs

thanks pondus to start a new topic for me. thanks essexboy. actually I followed the steps TwinHeadedEagle showed RunaLlena. Then I have kept shut down my pc for hours. should I follow the steps again from first and should i download the softs again? Here is my .txts that I had yesterday…

Run the fixes that I posted please and then let me know how the computer is behaving

thank you essexboy. well i see improvements. after (shift+deleting) the shortcuts they are not coming back. but while opening the pc 2 black screens from system 32 just peeped for seconds before. now they vanish more quickly so i cant read where they are from. and some problems like selection of texts spreads much, opening drives are belated, internet network fluctuates to not found connection, happen yet. and while shutting down i get command to force shut down.

more .txt files. 1 thing i did in FRST… i checked list bcd, drivers md5 under optional scan. was it ok?

It just gives MD5’s for certain files. (rpcss.dll, explorer.exe etc) The MD5 is fine.

Download the attached Fixlist.txt to the same location as FRST
Run FRST and press Fix
On completion a log will be generated please post that

here it is

What problems remain ?

C:\windows\system32\cmd.exe black popup windows flash at startup… is it for virus ? sometimes i need to force shutdown for a programme running behind. yet these are happening. but no shortcuts are generating now. can i connect other portable hardisks to this pc now?

Let me know if your keyboard still works on completion of this run, it should stop the command box

Yes connect the other drives but ensure that MCShield is running

Warning This fix is only relevant for this system and no other, using on another computer may cause problems

Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot

Run OTL

[*]Under the Custom Scans/Fixes box at the bottom, paste in the following

https://dl.dropbox.com/u/73555776/OTL_Fix.GIF


:Commands
[CREATERESTOREPOINT]

:OTL
O4 - HKLM..\Run: [AMD AVT] C:\Windows\SysWow64\cmd.exe (Microsoft Corporation)

:Commands
[resethosts]
[emptytemp]
[Reboot]

[*]Then click the Run Fix button at the top
[*]Let the program run unhindered, reboot the PC when it is done
[*]Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.

here it is

yeah the start up stops flashing though it takes lil long to open the window, and while shutting a white window flashes for a second. thanks a lot essexboy. you have done a lot for me. Hope i will get help again if i get trouble. thanks a lot. what should i do to be safe from these malwares? do you recommend to format the C drive and reinstall the windows within one month?

You might want to stop these starting with windows

O4 - HKLM..\Run: [Acrobat Assistant 8.0] C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe (Adobe Systems Inc.) O4 - HKLM..\Run: [Adobe Acrobat Speed Launcher] C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe (Adobe Systems Incorporated) O4 - HKLM..\Run: [AdobeCS6ServiceManager] C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe (Adobe Systems Incorporated) O4 - HKLM..\Run: [PWRISOVM.EXE] C:\Program Files (x86)\PowerISO\PWRISOVM.EXE (Power Software Ltd) O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.) O4 - HKLM..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated) O4 - HKCU..\Run: [AdobeBridge] File not found O4 - HKCU..\Run: [IDMan] C:\Program Files (x86)\Internet Download Manager\IDMan.exe (Tonec Inc.) O4 - HKCU..\Run: [uTorrent] C:\Users\Saif\AppData\Roaming\uTorrent\uTorrent.exe (BitTorrent Inc.)