This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Virus keeps showing up on Avast

30 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hey J&J, I have had no further problems. :thumbup: Here's the log file: All processes killed ========== OTL ========== Registry value HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\URLSearchHooks\\{A3BC75A2-1F87-4686-AA43-5347D756017C} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A3BC75A2-1F87-4686-AA43-5347D756017C}\ not found. Registry value HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\URLSearchHooks\\{A3BC75A2-1F87-4686-AA43-5347D756017C} not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A3BC75A2-1F87-4686-AA43-5347D756017C}\ not found. Prefs.js: {31c7d459-9cc3-44f2-9dca-fc11795309b4}:2.5.6.0 removed from extensions.enabledItems Prefs.js: {52a69273-25f5-4cb9-a0a3-4f97c4b0fb60}:1.0 removed from extensions.enabledItems C:\Documents and Settings\Kevin Lenertz\Application Data\Mozilla\Firefox\Profiles\0zynv3mo.default\extensions\{31c7d459-9cc3-44f2-9dca-fc11795309b4}\searchplugin folder moved successfully. C:\Documents and Settings\Kevin Lenertz\Application Data\Mozilla\Firefox\Profiles\0zynv3mo.default\extensions\{31c7d459-9cc3-44f2-9dca-fc11795309b4}\META-INF folder moved successfully. C:\Documents and Settings\Kevin Lenertz\Application Data\Mozilla\Firefox\Profiles\0zynv3mo.default\extensions\{31c7d459-9cc3-44f2-9dca-fc11795309b4}\lib folder moved successfully. C:\Documents and Settings\Kevin Lenertz\Application Data\Mozilla\Firefox\Profiles\0zynv3mo.default\extensions\{31c7d459-9cc3-44f2-9dca-fc11795309b4}\defaults folder moved successfully. C:\Documents and Settings\Kevin Lenertz\Application Data\Mozilla\Firefox\Profiles\0zynv3mo.default\extensions\{31c7d459-9cc3-44f2-9dca-fc11795309b4}\components folder moved successfully. C:\Documents and Settings\Kevin Lenertz\Application Data\Mozilla\Firefox\Profiles\0zynv3mo.default\extensions\{31c7d459-9cc3-44f2-9dca-fc11795309b4}\chrome folder moved successfully. C:\Documents and Settings\Kevin Lenertz\Application Data\Mozilla\Firefox\Profiles\0zynv3mo.default\extensions\{31c7d459-9cc3-44f2-9dca-fc11795309b4} folder moved successfully. C:\Documents and Settings\Kevin Lenertz\Application Data\Mozilla\Firefox\Profiles\0zynv3mo.default\extensions\{52a69273-25f5-4cb9-a0a3-4f97c4b0fb60}\defaults\preferences folder moved successfully. C:\Documents and Settings\Kevin Lenertz\Application Data\Mozilla\Firefox\Profiles\0zynv3mo.default\extensions\{52a69273-25f5-4cb9-a0a3-4f97c4b0fb60}\defaults folder moved successfully. C:\Documents and Settings\Kevin Lenertz\Application Data\Mozilla\Firefox\Profiles\0zynv3mo.default\extensions\{52a69273-25f5-4cb9-a0a3-4f97c4b0fb60}\chrome folder moved successfully. C:\Documents and Settings\Kevin Lenertz\Application Data\Mozilla\Firefox\Profiles\0zynv3mo.default\extensions\{52a69273-25f5-4cb9-a0a3-4f97c4b0fb60} folder moved successfully. C:\Documents and Settings\Kevin Lenertz\Application Data\Mozilla\Firefox\Profiles\0zynv3mo.default\searchplugins\ask.xml moved successfully. Registry value HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{CCC7A320-B3CA-4199-B1A6-9F516DD69829} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}\ not found. Registry value HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{CCC7A320-B3CA-4199-B1A6-9F516DD69829} not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}\ not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\Cmaudio deleted successfully. Registry key HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Control Panel\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Infodelivery\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Restrictions\ deleted successfully. Starting removal of ActiveX control {515DA9EC-7B03-3F80-D87E-3DB976424323} Registry error reading value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{515DA9EC-7B03-3F80-D87E-3DB976424323}\DownloadInformation\\INF . Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{515DA9EC-7B03-3F80-D87E-3DB976424323}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{515DA9EC-7B03-3F80-D87E-3DB976424323}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{515DA9EC-7B03-3F80-D87E-3DB976424323}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{515DA9EC-7B03-3F80-D87E-3DB976424323}\ not found. Starting removal of ActiveX control {7440672B-1B25-7D3F-E4E5-495D702279D7} Registry error reading value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{7440672B-1B25-7D3F-E4E5-495D702279D7}\DownloadInformation\\INF . Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{7440672B-1B25-7D3F-E4E5-495D702279D7}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7440672B-1B25-7D3F-E4E5-495D702279D7}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7440672B-1B25-7D3F-E4E5-495D702279D7}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7440672B-1B25-7D3F-E4E5-495D702279D7}\ not found. C:\WINDOWS\tasks\COMODO System Cleaner Update.job moved successfully. File C:\WINDOWS\System32\comuid32.dllcht1532.dll21lsrykyexn6gcx32.dlllyyhn62q32.dll not found. File C:\WINDOWS\uccspecb.sys not found. C:\Documents and Settings\Kevin Lenertz\Application Data\IObit\IObit SmartDefrag folder moved successfully. C:\Documents and Settings\Kevin Lenertz\Application Data\IObit\DiskCleaner\backup folder moved successfully. C:\Documents and Settings\Kevin Lenertz\Application Data\IObit\DiskCleaner folder moved successfully. C:\Documents and Settings\Kevin Lenertz\Application Data\IObit\Common folder moved successfully. C:\Documents and Settings\Kevin Lenertz\Application Data\IObit\Advanced SystemCare\Backup\Registry folder moved successfully. C:\Documents and Settings\Kevin Lenertz\Application Data\IObit\Advanced SystemCare\Backup folder moved successfully. C:\Documents and Settings\Kevin Lenertz\Application Data\IObit\Advanced SystemCare folder moved successfully. C:\Documents and Settings\Kevin Lenertz\Application Data\IObit folder moved successfully. C:\WINDOWS\Tasks\Ad-Aware Update (Daily 1).job moved successfully. C:\WINDOWS\Tasks\Ad-Aware Update (Daily 2).job moved successfully. C:\WINDOWS\Tasks\Ad-Aware Update (Daily 3).job moved successfully. C:\WINDOWS\Tasks\Ad-Aware Update (Daily 4).job moved successfully. C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job moved successfully. ADS C:\Documents and Settings\All Users\Application Data\TEMP:5B132D3E deleted successfully. ADS C:\Documents and Settings\All Users\Application Data\TEMP:288A91F8 deleted successfully. ADS C:\Documents and Settings\All Users\Application Data\TEMP:D1B5B4F1 deleted successfully. ========== COMMANDS ========== Restore point Set: OTL Restore Point (0) [EMPTYFLASH] User: Administrator User: All Users User: Default User User: Guest ->Flash cache emptied: 348 bytes User: Kevin User: Kevin Lenertz ->Flash cache emptied: 22309 bytes User: LocalService User: NetworkService User: Sophea ->Flash cache emptied: 1854 bytes Total Flash Files Cleaned = 0.00 mb [EMPTYTEMP] User: Administrator User: All Users User: Default User User: Guest ->Flash cache emptied: 0 bytes User: Kevin User: Kevin Lenertz ->Java cache emptied: 0 bytes ->Flash cache emptied: 0 bytes User: LocalService User: NetworkService User: Sophea ->Flash cache emptied: 0 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 743375 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 1732307 bytes RecycleBin emptied: 32441648 bytes Total Files Cleaned = 33.00 mb OTL by OldTimer - Version 3.2.6.0 log created on 07052010_145216 Files\Folders moved on Reboot… File\Folder C:\WINDOWS\temp\Perflib_Perfdata_664.dat not found! Registry entries deleted on Reboot… What do you think? See anything else? How do you know what to look for?
Hello cklenertz :),

What do you think? See anything else?
How do you know what to look for?

You are good to go.

Malware removal is not easy, thus we need to go through some specialized and intensive training to be able to help people like you safely and effectively. If you are interested to learn, please visit one of these pages:
http://forums.whatthetech.com/index.php?showtopic=80368
http://www.malwareremoval.com/

——————–

Congratulations, you are All Clear to go. Glad to hear everything is good and running :). If you have any more problems, please let me know.

Now we need to clear out the programs we have been using to clean up your computer. They are not suitable for general malware removal and could cause damage if used inappropriately.
  • Run OTL by double clicking on OTL.exe. Click on CleanUp at the upper right corner, proceed to reboot if prompted.
  • Delete the GMER file(lto777vq.exe) and CKScanner.exe on your desktop.
  • Delete any logs on the desktop.
  • Uninstall HijackThis via the Add/Remove Programs at the Control Panel.
Some tips to help you stay clean and safe:

1. Keep your Windows up to date. Enable Automatic Updates to always update the latest security patches from Microsoft, or you can download from the Microsoft website. Otherwise, your computer will be vulnerable to new exploits or malwares.

2. Purge System Restore. A recovery feature will only be useful if it is clean from malwares. See Windows XP System Restore Guide for some detail explanations.

3. Update your Antivirus program regularly, it is a must for constant protection against viruses. If you do not have one, Microsoft Security Essentials, Avast and Avira are some great and free antivirus programs that you can try. For paid versions, Avast, ESET NOD32 and Kaspersky are some good options. Please keep only one AV installed.

4. Install Malwarebytes' Anti-Malware if you haven't and use it occasionally. It is a new and powerful anti-malware tool, totally free but for real-time protection you will have to pay a small one-time fee.

5. Install WinPatrol, a great protection program that helps you monitor for unwanted files or applications.

6. Use a hosts file to block the access of bad sites from your computer. Get yourself a MVPS Hosts for this purpose.

7. Install Web of Trust (WOT). WOT keeps you from dangerous websites with warnings and blockings.

8. Protect your computer from removable or USB drive infections with Panda USB Vaccine, an effective method to prevent malware from spreading.

9. Keep all your softwares updated. Visit Secunia Software Inspector to find out if any updates required.

10. If you have been a victim of malware before, Stand Up and Be Counted —> Malware Complaints <— where you can make difference!

11. Also look up How to prevent malware: By miekiemoes and So how did I get infected in the first place? By Tony Klein.

Stay safe.

If you have been helped and wish to donate to support this volunteer site, go to Donations For What The Tech.
Thank you Jack&Jill. Your expertise and your time were greatly appreciated. I am much obliged to you and your fellow AntiViral brethren.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI