I am getting so many notifications about malware and rootkit, by Avast!. It says the location is in the C:\Windows\explorer.exe. Help me get rid of it plzzzzzz. Its really annoying…
follow the guide here and attach the logs
Malwarebytes’ Anti-Malware 1.51.2.1300
www.malwarebytes.org
Database version: 8036
Windows 6.1.7601 Service Pack 1
Internet Explorer 9.0.8112.16421
10/28/2011 11:28:55 PM
mbam-log-2011-10-28 (23-28-55).txt
Scan type: Quick scan
Objects scanned: 153594
Time elapsed: 4 minute(s), 50 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell (Backdoor.Agent) → Value: Shell → Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
can you attach aswMBR and OTL logs ?
:-\ Don’t even know what that is. Please guide me through it, I am new to this stuff. I’ll appreciate it.
it is all in the guide i gave you the link to above…
click the red OTL in the guide, download and save to desktop…just follow Essexboy instruction
same thing with aswMBR
then in you attach the logs here
see lower left corner > additional options > attach
Visit the first link Pondus gave, that gives information on the tools and how to use them.
Once you have run the tools - To attach a file, when you reply click on the Additional Options, that allows you to attach the log files.
Here are the logs.
Essexboy is notified…check back tomorrow ![]()
Thanx alot Pondus & DavidR…
You’re welcome
From my limited experience, the aswMBR scan indicates that you have either the zero access or conserv infection and will need essexboy to analyse your OTL.txt log and compile a fix
Whilst this is a bit of a pain with the alerts, avast appears to be stopping its spread.
Winlogon has been replaced so lets reset that first
Warning This fix is only relevant for this system and no other, using on another computer may cause problems
Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot
Run OTL
[*]Under the Custom Scans/Fixes box at the bottom, paste in the following
:OTL O20 - HKCU Winlogon: Shell - (C:\Users\RAJA Umair Javed\AppData\Local\62073343\X) -C:\Users\RAJA Umair Javed\AppData\Local\62073343\X () [2011/10/28 03:27:44 | 000,227,328 | ---- | C] (Microsoft Corporation) -- C:\Users\RAJA Umair Javed\taskmgr.exe [2011/10/28 03:27:42 | 000,000,000 | -HSD | C] -- C:\Users\RAJA Umair Javed\AppData\Local\62073343:Files
ipconfig /flushdns /c:Commands
[purity]
[resethosts]
[emptytemp]
[EMPTYFLASH]
[CREATERESTOREPOINT]
[Reboot]
[*]Then click the Run Fix button at the top
[*]Let the program run unhindered, reboot the PC when it is done
[*]Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.
.
THEN
Download and Install Combofix
Download ComboFix from one of the following locations:
Link 1
Link 2
VERY IMPORTANT !!! Save ComboFix.exe to your Desktop
- IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
[*]Double click on ComboFix.exe & follow the prompts.
[*]Double click on ComboFix.exe & follow the prompts.
[*]Accept the disclaimer and allow to update if it asks
http://img.photobucket.com/albums/v706/ried7/NSIS_disclaimer_ENG.png
http://img.photobucket.com/albums/v706/ried7/NSIS_extraction.png
[*]When finished, it shall produce a log for you.
[*]Please include the C:\ComboFix.txt in your next reply.
Notes:
- Do not mouse-click Combofix’s window while it is running. That may cause it to stall.
- Do not “re-run” Combofix. If you have a problem, reply back for further instructions.
Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now
Here is the log.
Could you attach the combofix log please
Combofix is not showing any log. I ran it like 5 times and nothing shows up. Why is that happening??
When you ran it could you confirm that Avast did not sandbox it
Are you still getting the alerts ?
By the way there are no more annoying notifications. ;D
What other problems are you experiencing ?