system
28
Mark, please be very carefull with the Avenger. It works at the API level - lower than Window’s protection. That’s its strength - it almost never fails to delete the specified files. But that’s also what brings the risk - if the script is written incorrectly it’s possible to wipe your drive with this tool and Window’s won’t be able to stop you. I’m not saying what you ran was wrong, but we’ll try a more targeted path in a bit.
Open WinPFind again and Copy/Paste the information in the quotebox below into the pane where it says “Paste fix here” and then click the Run Fix button.
[Registry - Non-Microsoft Only]
< Common Startup > -> C:\Documents and Settings\All Users\Start Menu\Programs\Startup
YN -> %AllUsersStartup%\WNSO.lnk -> %CommonProgramFiles%\RGGZS\WNSO.exe
< ShellExecuteHooks [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
YN -> {733E9132-53CA-4C97-9AC9-145C4502FA20} [HKLM] -> %System32%\rqrqomm.dll []
< Internet Explorer Settings > ->
YN -> HKLM: CustomizeSearch -> http://seek.3721.com/srchcust.htm
[Files/Folders - Created Within 30 days]
NY -> winshow.exe -> %SystemRoot%\winshow.exe
NY -> bcwhocfi.exe -> %System32%\bcwhocfi.exe
NY -> fnajvskc.ini -> %System32%\fnajvskc.ini
NY -> lrfqotyx.ini -> %System32%\lrfqotyx.ini
NY -> rrutv.bak2 -> %System32%\rrutv.bak2
NY -> xytoqfrl.dll -> %System32%\xytoqfrl.dll
[Files/Folders - Modified Within 30 days]
NY -> rrutv.ini -> %System32%\rrutv.ini
Post the results in your next response as you did before.
Now, having sufficiently scared you about the Avenger I’ll ask you to open it once again
Copy all the text contained in the code box below to your Clipboard by highlighting it and pressing (Ctrl+C):
Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.
- Now, start The Avenger program by clicking on its icon on your desktop.
Under “Script file to execute” choose “Input Script Manually”.
Now click on the Magnifying Glass icon which will open a new window titled “View/edit script”
Paste the text copied to clipboard into this window by pressing (Ctrl+V).
Then download ComboFix from Here or Here to your Desktop.
Double click combofix.exe and follow the prompts.
When finished, it shall produce a log for you. Post that log and a HiJackthis log in your next reply
Note: Do not mouseclick combofix’s window while its running. That may cause it to stall.