Welcome! Register for a free account (or login) > How does it work?
|
|


Jan 31 2010, 12:53 PM
Post
#1
|
|
|
Authentic Member ![]() ![]() Group: Authentic Member Posts: 26 Joined: 30-January 10 Member No.: 90,415 Operating System: Windows XP |
Hi. Trying to fix my ex's computer. AVG reports Trojan Horse BackDoor.Generic 12 AAVT detected every time I run Spybot or Spyware Doctor or Adaware, it deletes it but it comes back next time. AVG updates every day but the log said all updates failed for the past two weeks. Firefox and IE will not start. Have gone through the "Are You Infected" topic and followed it. Malwarebytes' Anti-Malware was able to update and run and produced a log, GMER had to run several times before I was successful in making a copy of the log, DDS gave me a log. I have put those logs on a CD, how do I get them in to this forum? Is there any danger of transferring problems into my computer, I am running AVG which is updated and Spybot with Tea timer. Thank you for your help, just not sure about getting the three logs and one attachment to you. Thank you Ian
|
|
|
|
Bikerider [Closed] Trojan Horse BackDoor.Generic 12 AAVT Jan 31 2010, 12:53 PM
CatByte The text documents burned to a CD will not infect ... Feb 6 2010, 08:53 AM
Bikerider Thank you CatByte
Here are the logs
Malwarebyt... Feb 6 2010, 03:36 PM
CatByte The machine has a nasty rootkit infection.
This c... Feb 6 2010, 05:26 PM
Bikerider Thank You
Here is the log from maxhandle
Run fr... Feb 6 2010, 08:57 PM
CatByte Hi,
I need to make sure the recovery console is i... Feb 6 2010, 09:39 PM
Bikerider Hi Good question, This is an "E Machines... Feb 6 2010, 10:27 PM
CatByte No,
We are just looking for the recovery console.... Feb 7 2010, 06:49 AM
Bikerider Hi
I half to work today (Sun.) will work throug... Feb 7 2010, 07:43 AM
CatByte RE: [Closed] Trojan Horse BackDoor.Generic 12 AAVT Feb 7 2010, 08:11 AM
CatByte Please run this scan as well
Download OTL to you... Feb 7 2010, 09:44 AM
CatByte It's been a few days
Are you having any diffi... Feb 10 2010, 06:18 PM
Bikerider Hi
Sorry it took so long. Don't have much tim... Feb 10 2010, 10:36 PM
CatByte Hi,
Please do the following:
Next, please downlo... Feb 11 2010, 01:49 AM
Bikerider Hi
I have a problem.
I followed the instructions o... Feb 11 2010, 10:55 PM
CatByte usually there is no password, so you should be abl... Feb 11 2010, 10:58 PM
Bikerider OK here we go looklog.txt
Run from C:\Docume... Feb 12 2010, 10:01 PM
CatByte Hi,
Please do the following:
Download ComboFix f... Feb 13 2010, 12:22 AM
Bikerider Hi
Here is the combofix log
Thank You
ComboFi... Feb 13 2010, 03:46 PM
CatByte Hi,
Please do the following:
Very Important... Feb 13 2010, 03:52 PM
Bikerider Hi
Question
the first time I ran combofix it dete... Feb 13 2010, 04:28 PM
CatByte look in task manager and see if there are any proc... Feb 13 2010, 04:30 PM
Bikerider Does combofix need a dialup connection to run? Nu... Feb 13 2010, 04:38 PM
CatByte Did you reboot Feb 13 2010, 04:41 PM
Bikerider OK
I rebooted and combofix ran on its own, it fin... Feb 13 2010, 04:58 PM
CatByte We need to replace a driver so you can reboot norm... Feb 13 2010, 05:20 PM
Bikerider OK Success
Combofix finished and produced a log,... Feb 13 2010, 05:47 PM
Bikerider Hi
Here is the TDSSKiller log
17:56:29:906 3808 ... Feb 13 2010, 06:08 PM
CatByte Hi,
Please do the following:
please open a run b... Feb 13 2010, 06:08 PM
Bikerider OK here is the looklog
CODERun from C:\D... Feb 13 2010, 06:40 PM
CatByte Hi,
Please do the following:
Please open a comma... Feb 13 2010, 06:50 PM
Bikerider Not shure what happened with this
Quote
Go to St... Feb 13 2010, 07:17 PM
CatByte OK,
I'll get back to you on that one.
For no... Feb 13 2010, 07:31 PM
Bikerider OK
Here is the GMER log
GMER 1.0.15.15281 - http... Feb 13 2010, 10:35 PM
CatByte Hi,
Please do the following:
Please open your Ma... Feb 13 2010, 10:42 PM
CatByte Hi,
Please make sure you press enter after pastin... Feb 14 2010, 10:49 AM
Bikerider Hi
Here are the MABM and Kaspersky logs will try... Feb 14 2010, 12:41 PM
Bikerider I copied the cmd box as it appears after entering ... Feb 14 2010, 01:05 PM
CatByte OK
I'm thinking that means that the file stil... Feb 14 2010, 01:54 PM
Bikerider Hi I tried this but don't know if it created ... Feb 14 2010, 02:21 PM
CatByte Hi,
It should have created a new one in the folde... Feb 14 2010, 02:26 PM
Bikerider OK I am not sure we are doing the same thing so h... Feb 14 2010, 02:45 PM
Bikerider OK now I figured out to view the extensions and f... Feb 14 2010, 03:00 PM
CatByte OK,
show the file extensions, that will make it e... Feb 14 2010, 03:02 PM
CatByte sorry we cross posted...
so it looks like a new f... Feb 14 2010, 03:03 PM
CatByte Actually > do it again just to make sure... ren... Feb 14 2010, 03:05 PM
Bikerider well same result, I half to go to work, will come ... Feb 14 2010, 03:11 PM
CatByte OK
as long as you have a raspppoe.sys file create... Feb 14 2010, 03:16 PM
Bikerider Hi
Here are the DDS log and Attach log
Mozilla w... Feb 14 2010, 10:53 PM
CatByte Hi,
Look at the information under the title ... Feb 15 2010, 04:51 AM
ken545 Hello Bikerider,
Catbyte is away for a week or so... Feb 17 2010, 06:28 AM
Bikerider Hi
Yes I am still working on the cleanup of this ... Feb 17 2010, 10:15 PM
Bikerider Hi
A question
I have opened Eudora and in both the... Feb 20 2010, 01:56 PM
CatByte It may not actually be an email with an attachment... Feb 20 2010, 02:11 PM
CatByte Due to inactivity this topic will be closed.
If yo... Feb 28 2010, 08:12 AM![]() ![]() |
Similar Topics
| Topic Title | Replies | Topic Starter | Views | Last Action | |||
|---|---|---|---|---|---|---|---|
![]() |
19 | HHHisthegame | 152 | Today, 03:20 PM Last post by: Dakeyras |
|||
![]() |
12 | JoHawk | 193 | Today, 03:02 PM Last post by: schrauber |
|||
![]() |
5 | ArtemusGordon | 119 | Yesterday, 08:14 PM Last post by: LDTate |
|||
![]() |
3 | copiusdazes | 102 | Yesterday, 02:24 PM Last post by: schrauber |
|||
|
Time is now: 13th March 2010 - 05:41 PM |