This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

TR/Crypt/ZPACK Gen virus on my PC [Solved]

26 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, and welcome to our malware removal forum!

My name is Richard and I'll be happy to help you with your computer problems.

Please be advised that I am currently in training, so my responses will need to be approved by one of our experts before I post them. This is only to ensure you are receiving accurate instructions. It may cause a delay in my replies.

Please note the following:
  • The cleaning process is not instant as logs can take time to research. Sit tight and please be patient.
  • I will be working on your malware issues. This may or may not solve other issues you may have with your system.
  • While we are fixing your problems, do NOT install/re-install any programs or run any fixes or scanners unless told to do so.
  • Ensure that your anti-virus definitions are up-to-date.
  • I would advise backing up all your important documents, personal data files and photos to a CD or DVD drive.
  • Do not back up any Applications (programs). These should be re-installed from the original source CD(s) or website(s).
  • During the course of our cleanup, please do not do any additional online work or surfing until we have verified that your system is clean.
  • I suggest printing out each set of instructions and reading the entire post before proceeding. It will make following them easier.
  • Be sure to follow the directions and run tools/scans in the order listed.
  • If you do not reply to your topic, it will be closed after 3 days.
I will return as soon as possible with more instructions.



Regards,

Richard :wavey:
Could you post Avira's scan report? :)

Next

OTL
————-
  • Download OTL to your Desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Select All Users.
  • Under the Custom Scan box paste this in
    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    explorer.exe
    winlogon.exe
    Userinit.exe
    svchost.exe
    /md5stop
    %systemroot%\*. /rp /s
    DRIVES
    CREATERESTOREPOINT
  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
    Note:These logs can be located in the OTL. folder on your C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post both logs with your next reply. You may need two posts to fit them both in.
Next

GMER Rootkit Scanner
—————
Download GMER Rootkit Scanner from here to to your Desktop. It will be a randomly named executable.
  • Double click the exe file. If asked to allow gmer.sys driver to load, please consent.
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.
  • In the right panel, you will see several boxes that have been checked. uncheck the following:
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your Desktop, and attach it in reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


In your next reply, please provide the following:
  • Avira scan report.
  • OTL log.
  • GMER log.



Regards,

Richard :wavey:
I hope this is all correct. many thanks Avira AntiVir Personal Report file date: Friday, 27 April 2012 11:16 Scanning for 3714949 virus strains and unwanted programs. The program is running as an unrestricted full version. Online services are available: Licensee : Avira AntiVir Personal - Free Antivirus Serial number : 0000149996-ADJIE-0000001 Platform : Windows XP Windows version : (Service Pack 3) [5.1.2600] Boot mode : Normally booted Username : SYSTEM Computer name : TAYLOR Version information: BUILD.DAT : 10.2.0.707 36070 Bytes 25/01/2012 13:11:00 AVSCAN.EXE : 10.3.0.7 484008 Bytes 5/07/2011 23:26:51 AVSCAN.DLL : 10.0.5.0 47464 Bytes 5/07/2011 23:26:51 LUKE.DLL : 10.3.0.5 45416 Bytes 5/07/2011 23:26:52 LUKERES.DLL : 10.0.0.1 12648 Bytes 10/02/2010 16:40:49 AVSCPLR.DLL : 10.3.0.7 119656 Bytes 5/07/2011 23:26:53 AVREG.DLL : 10.3.0.9 88833 Bytes 4/08/2011 04:38:11 VBASE000.VDF : 7.10.0.0 19875328 Bytes 6/11/2009 04:50:27 VBASE001.VDF : 7.11.0.0 13342208 Bytes 14/12/2010 00:50:23 VBASE002.VDF : 7.11.19.170 14374912 Bytes 20/12/2011 00:29:20 VBASE003.VDF : 7.11.21.238 4472832 Bytes 1/02/2012 00:33:50 VBASE004.VDF : 7.11.26.44 4329472 Bytes 28/03/2012 10:16:27 VBASE005.VDF : 7.11.26.45 2048 Bytes 28/03/2012 10:16:28 VBASE006.VDF : 7.11.26.46 2048 Bytes 28/03/2012 10:16:28 VBASE007.VDF : 7.11.26.47 2048 Bytes 28/03/2012 10:16:29 VBASE008.VDF : 7.11.26.48 2048 Bytes 28/03/2012 10:16:34 VBASE009.VDF : 7.11.26.49 2048 Bytes 28/03/2012 10:16:34 VBASE010.VDF : 7.11.26.50 2048 Bytes 28/03/2012 10:16:35 VBASE011.VDF : 7.11.26.51 2048 Bytes 28/03/2012 10:16:35 VBASE012.VDF : 7.11.26.52 2048 Bytes 28/03/2012 10:16:36 VBASE013.VDF : 7.11.26.53 2048 Bytes 28/03/2012 10:16:36 VBASE014.VDF : 7.11.26.107 221696 Bytes 30/03/2012 10:16:49 VBASE015.VDF : 7.11.26.179 224768 Bytes 2/04/2012 23:24:42 VBASE016.VDF : 7.11.26.241 142336 Bytes 4/04/2012 23:34:42 VBASE017.VDF : 7.11.27.41 247808 Bytes 8/04/2012 23:55:55 VBASE018.VDF : 7.11.27.107 161280 Bytes 12/04/2012 23:56:01 VBASE019.VDF : 7.11.27.159 148992 Bytes 13/04/2012 23:56:06 VBASE020.VDF : 7.11.27.201 207360 Bytes 17/04/2012 23:56:12 VBASE021.VDF : 7.11.28.3 237568 Bytes 19/04/2012 00:34:38 VBASE022.VDF : 7.11.28.49 193536 Bytes 20/04/2012 23:56:06 VBASE023.VDF : 7.11.28.99 195072 Bytes 23/04/2012 23:56:12 VBASE024.VDF : 7.11.28.133 247808 Bytes 24/04/2012 02:25:48 VBASE025.VDF : 7.11.28.183 186880 Bytes 26/04/2012 02:25:53 VBASE026.VDF : 7.11.28.184 2048 Bytes 26/04/2012 02:25:54 VBASE027.VDF : 7.11.28.185 2048 Bytes 26/04/2012 02:25:55 VBASE028.VDF : 7.11.28.186 2048 Bytes 26/04/2012 02:25:56 VBASE029.VDF : 7.11.28.187 2048 Bytes 26/04/2012 02:25:57 VBASE030.VDF : 7.11.28.188 2048 Bytes 26/04/2012 02:25:58 VBASE031.VDF : 7.11.28.198 39424 Bytes 26/04/2012 02:26:00 Engineversion : 8.2.10.58 AEVDF.DLL : 8.1.2.2 106868 Bytes 3/11/2011 02:35:44 AESCRIPT.DLL : 8.1.4.18 455034 Bytes 27/04/2012 02:27:18 AESCN.DLL : 8.1.8.2 131444 Bytes 27/01/2012 13:51:41 AESBX.DLL : 8.2.5.5 606579 Bytes 30/03/2012 10:19:37 AERDL.DLL : 8.1.9.15 639348 Bytes 12/09/2011 23:49:47 AEPACK.DLL : 8.2.16.9 807287 Bytes 1/04/2012 02:02:10 AEOFFICE.DLL : 8.1.2.28 201082 Bytes 27/04/2012 02:27:13 AEHEUR.DLL : 8.1.4.21 4682102 Bytes 27/04/2012 02:27:09 AEHELP.DLL : 8.1.20.0 254326 Bytes 27/04/2012 02:26:11 AEGEN.DLL : 8.1.5.28 422260 Bytes 27/04/2012 02:26:07 AEEXP.DLL : 8.1.0.33 82293 Bytes 27/04/2012 02:27:20 AEEMU.DLL : 8.1.3.0 393589 Bytes 27/11/2010 00:25:15 AECORE.DLL : 8.1.25.6 201078 Bytes 30/03/2012 10:17:08 AEBB.DLL : 8.1.1.0 53618 Bytes 24/04/2010 05:04:29 AVWINLL.DLL : 10.0.0.0 19304 Bytes 2/08/2010 08:09:56 AVPREF.DLL : 10.0.3.2 44904 Bytes 5/07/2011 23:26:51 AVREP.DLL : 10.0.0.10 174120 Bytes 28/05/2011 23:56:10 AVARKT.DLL : 10.0.26.1 255336 Bytes 5/07/2011 23:26:51 AVEVTLOG.DLL : 10.0.0.9 203112 Bytes 5/07/2011 23:26:51 SQLITE3.DLL : 3.6.19.0 355688 Bytes 17/06/2010 07:27:22 AVSMTP.DLL : 10.0.0.17 63848 Bytes 2/08/2010 08:09:56 NETNT.DLL : 10.0.0.0 11624 Bytes 17/06/2010 07:27:21 RCIMAGE.DLL : 10.0.0.35 2589544 Bytes 5/07/2011 23:26:50 RCTEXT.DLL : 10.0.64.0 97640 Bytes 5/07/2011 23:26:51 Configuration settings for the scan: Jobname………………………..: Complete system scan Configuration file………………: C:\Program Files\Avira\AntiVir Desktop\sysscan.avp Logging………………………..: Default Primary action………………….: interactive Secondary action………………..: ignore Scan master boot sector………….: on Scan boot sector………………..: on Boot sectors……………………: C:, Process scan……………………: on Extended process scan……………: on Scan registry…………………..: on Search for rootkits……………..: on Integrity checking of system files..: off Scan all files………………….: All files Scan archives…………………..: on Recursion depth…………………: 20 Smart extensions………………..: on Macro heuristic…………………: on File heuristic………………….: Advanced Start of the scan: Friday, 27 April 2012 11:16 Starting search for hidden objects. The scan of running processes will be started Scan process 'rsmsink.exe' - '29' Module(s) have been scanned Scan process 'msdtc.exe' - '40' Module(s) have been scanned Scan process 'dllhost.exe' - '61' Module(s) have been scanned Scan process 'dllhost.exe' - '45' Module(s) have been scanned Scan process 'vssvc.exe' - '48' Module(s) have been scanned Scan process 'avscan.exe' - '70' Module(s) have been scanned Scan process 'avcenter.exe' - '63' Module(s) have been scanned Scan process 'msimn.exe' - '95' Module(s) have been scanned Scan process 'alg.exe' - '33' Module(s) have been scanned Scan process 'iPodService.exe' - '30' Module(s) have been scanned Scan process 'svchost.exe' - '47' Module(s) have been scanned Scan process 'RichVideo.exe' - '22' Module(s) have been scanned Scan process 'mdm.exe' - '20' Module(s) have been scanned Scan process 'COCIManager.exe' - '39' Module(s) have been scanned Scan process 'Skype.exe' - '123' Module(s) have been scanned Scan process 'lxdmcoms.exe' - '35' Module(s) have been scanned Scan process 'Vid.exe' - '123' Module(s) have been scanned Scan process 'CommandService.exe' - '23' Module(s) have been scanned Scan process 'ctfmon.exe' - '25' Module(s) have been scanned Scan process 'iTunesHelper.exe' - '64' Module(s) have been scanned Scan process 'jqs.exe' - '33' Module(s) have been scanned Scan process 'AirGCFG.exe' - '40' Module(s) have been scanned Scan process 'WZCSLDR2.exe' - '40' Module(s) have been scanned Scan process 'gcbrmon.exe' - '20' Module(s) have been scanned Scan process 'CameraHelperShell.exe' - '51' Module(s) have been scanned Scan process 'avshadow.exe' - '26' Module(s) have been scanned Scan process 'Updater.exe' - '32' Module(s) have been scanned Scan process 'jusched.exe' - '21' Module(s) have been scanned Scan process 'mDNSResponder.exe' - '28' Module(s) have been scanned Scan process 'Monitor.exe' - '31' Module(s) have been scanned Scan process 'LWS.exe' - '34' Module(s) have been scanned Scan process 'AppleMobileDeviceService.exe' - '60' Module(s) have been scanned Scan process 'lxdmamon.exe' - '51' Module(s) have been scanned Scan process 'lxdmmon.exe' - '32' Module(s) have been scanned Scan process 'avguard.exe' - '55' Module(s) have been scanned Scan process 'PDVDServ.exe' - '24' Module(s) have been scanned Scan process 'GoogleQuickSearchBox.exe' - '90' Module(s) have been scanned Scan process 'avgnt.exe' - '47' Module(s) have been scanned Scan process 'Explorer.EXE' - '115' Module(s) have been scanned Scan process 'svchost.exe' - '34' Module(s) have been scanned Scan process 'sched.exe' - '45' Module(s) have been scanned Scan process 'UMVPFSrv.exe' - '17' Module(s) have been scanned Scan process 'spoolsv.exe' - '72' Module(s) have been scanned Scan process 'svchost.exe' - '31' Module(s) have been scanned Scan process 'svchost.exe' - '32' Module(s) have been scanned Scan process 'svchost.exe' - '30' Module(s) have been scanned Scan process 'svchost.exe' - '167' Module(s) have been scanned Scan process 'svchost.exe' - '39' Module(s) have been scanned Scan process 'svchost.exe' - '53' Module(s) have been scanned Scan process 'lsass.exe' - '51' Module(s) have been scanned Scan process 'services.exe' - '27' Module(s) have been scanned Scan process 'winlogon.exe' - '67' Module(s) have been scanned Scan process 'csrss.exe' - '14' Module(s) have been scanned Scan process 'smss.exe' - '2' Module(s) have been scanned Starting master boot sector scan: Master boot sector HD0 [INFO] No virus was found! Master boot sector HD1 [INFO] No virus was found! Master boot sector HD2 [INFO] No virus was found! Master boot sector HD3 [INFO] No virus was found! Master boot sector HD4 [INFO] No virus was found! Master boot sector HD5 [INFO] No virus was found! Start scanning boot sectors: Boot sector 'C:\' [INFO] No virus was found! Starting to scan executable files (registry). The registry was scanned ( '1303' files ). Starting the file scan: Begin scan in 'C:\' C:\Documents and Settings\Jeff\Local Settings\temp\josw392583.exe [DETECTION] Is the TR/Crypt.ZPACK.Gen8 Trojan Beginning disinfection: C:\Documents and Settings\Jeff\Local Settings\temp\josw392583.exe [DETECTION] Is the TR/Crypt.ZPACK.Gen8 Trojan [NOTE] The file was moved to the quarantine directory under the name '5ab5befd.qua'. End of the scan: Friday, 27 April 2012 12:00 Used time: 41:53 Minute(s) The scan has been done completely. 12004 Scanned directories 296164 Files were scanned 1 Viruses and/or unwanted programs were found 0 Files were classified as suspicious 0 files were deleted 0 Viruses and unwanted programs were repaired 1 Files were moved to quarantine 0 Files were renamed 0 Files cannot be scanned 296163 Files not concerned 4130 Archives were scanned 0 Warnings 1 Notes 469834 Objects were scanned with rootkit scan 0 Hidden objects were found
josw392583.exe seems to be quarantined. Is Avira still reporting this infection? :)

Please post Extras.Txt as requested. :thumbup:

This log can be located in the OTL. folder on your C:\ drive. Please copy/paste the contents of the log in your next reply.

Next

Please download DeFogger to your Desktop.
  • Double-click DeFogger to run the tool.
  • The application window will appear.
  • Click the Disable button to disable your CD Emulation drivers.
  • Click Yes to continue.
  • A 'Finished!' message will appear.
  • Click OK.
  • DeFogger will now ask to reboot the machine - click OK.

IMPORTANT! If you receive an error message while running DeFogger, please post the log defogger_disable which will appear on your desktop.

Do not re-enable these drivers until otherwise instructed.

Next

Please go to VirusTotal.
  • Click Choose File and browse to the file listed below in bold and click Scan it!.

    C:\WINDOWS\System32\drivers\iKeyLFT2.dll

  • There might be a short wait.
  • Select Reanalyse file and post back with the results of the scan.
  • Do the same for:

    C:\WINDOWS\System32\JJAKEn.dll
In your next reply, please provide the following:
  • Extras log.
  • VirusTotal results.
  • Update on how your PC is running.



Regards,

Richard :wavey:
SHA256: 80b98c5c1adaa4e066158904a713225aa6e7a1892a2fd97f5c69439d08c2dc0d SHA1: 1763801f306f7f4753d68ba23233904c914b4d2b HI Richard. Thanks for the help. I hope the below is the correct info you need. After I ran the DeFogger it did not ask to reboot the machine. I shut down and restarted my computer and from then on the system began very very very slow. MD5: c14df20a1ce4246953d08511f277fc84 File size: 15.5 KB ( 15896 bytes ) File name: iKeyLFT2.dll File type: Win32 DLL Detection ratio: 0 / 42 Analysis date: 2012-05-01 02:16:06 UTC ( 0 minutes ago ) SHA256: f37ec3159500335e7d252993a5aab4843e482f76f73549f05bb670b8b3d4fc2b SHA1: 01d8908429d05246376e5583c4c3f9ecba54b31c MD5: b9fecd748f2d0096bcf1da11579eba13 File size: 48.0 KB ( 49152 bytes ) File name: JJAKEn.dll File type: Win32 DLL Detection ratio: 0 / 40 Analysis date: 2012-05-01 02:47:42 UTC ( 0 minutes ago

Attachments:

Is Avira still detecting the TR/Crypt.ZPACK.Gen8 Trojan? :)

Next

Before we start: The following steps involve modifying the registry. Modifying the registry can be dangerous (and can render your system unbootable) so it's advisable that you make a backup of the registry before proceeding.

First, please backup your Registry with ERUNT.
  • Please go here to download ERUNT.
  • For version with the Installer: Use the setup program to install ERUNT on your computer.
  • For the zipped version: Unzip all the files into a folder of your choice.
Run Erunt.exe to backup your registry to the folder of your choice.

Note: To restore your registry, go to the folder and start ERDNT.exe

Next

Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    O4 - HKLM..\Run: []  File not found
    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\S-1-5-21-1645522239-1972579041-682003330-1003\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    @Alternate Data Stream - 122 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:C039C6AC
    @Alternate Data Stream - 122 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:6401C7FF
    
    :Files
    ipconfig /flushdns /c
    
    :Commands
    [purity]
    [resethosts]
    [emptytemp]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done.
  • When the computer has rebooted, the log will be located at C:\_OTL\MovedFiles\mmddyyyy_hhmmss.log, where mmddyyyy_hhmmss is the date/time of the tool run.
  • Copy and paste the contents of that report in your next reply.

In your next reply, please provide the following:
  • OTL log.
  • Update on how your PC is running.



Regards,

Richard :wavey:
Hi, Ok.. on Friday I ran a Avira and Malwares scan and on detection on a virus came up, so I thought all was good. Today I turned on the computer and got a messages ANIWZCS was detected. I am having a problem with my external hard drive so I havent been able to back up, and I didnt want to proceed . I will have to get a new external hard drive and then ….. what . many thanks
Thanks for the information B)

ANIWZCS seems to be related to D-link wireless.

Could you post Avira's latest scan report? :)

Next

Please backup your registry with ERUNT and run the OTL fix as requested. :thumbup:

In your next reply, please provide the following:
  • Avira scan report.
  • OTL log.
  • Update on how your PC is running.



Regards,

Richard :wavey:
Hi, Attempted ERUNT .. but was unsure what to click … they had version1 , 2 or 3 with .de ( in german). As to OTL … when asked to RUN a warning box showed " Unknown Publisher " ( was I still to run the program). As I am a novice I dont want to take any risks. My PC is seems to be running fine Avira AntiVir Personal - Free Antivirus Updater Complete product update Creation time: Tue May 08 21:27:32 2012 Operating system: Windows XP (Service Pack 3) [5.1.2600] 32 bit Product information: Product version: 10.2.0.707 Updater: C:\Program Files\Avira\AntiVir Desktop\update.exe 10.0.0.39 Update resource: C:\Program Files\Avira\AntiVir Desktop\updaterc.dll 10.0.9.0 Library: C:\Program Files\Avira\AntiVir Desktop\update.dll 0.1.0.44 Plugin: C:\Program Files\Avira\AntiVir Desktop\updext.dll 10.0.0.10 GUI: C:\Program Files\Avira\AntiVir Desktop\updgui.dll 10.0.2.2 Temp Directory: C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\TEMP\UPDATE\ Backup folder: C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\BACKUP\ Installation Directory: C:\Program Files\Avira\AntiVir Desktop\ Updater folder: C:\Program Files\Avira\AntiVir Desktop\ AppData folder: C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\ Proxy settings: System settings used 21:27:33 [UPD] [INFO] Checking whether newer files are available. 21:27:33 [UPD] [INFO] Select update server 'http://117.121.253.254/update'. 21:27:33 [UPD] [INFO] Downloading of 'http://117.121.253.254/update/idx/master.idx' to 'C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\TEMP\UPDATE\idx\master.idx'. 21:27:34 [UPD] [INFO] Downloading of 'http://117.121.253.254/update/idx/wks_avira10-win32-en-pecl.idx' to 'C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\TEMP\UPDATE\idx\wks_avira10-win32-en-pecl.idx'. 21:27:34 [UPD] [INFO] Downloading of 'http://117.121.253.254/update/idx/wks_avira10-win32-en-pecl.info.gz' to 'C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\TEMP\UPDATE\idx\wks_avira10-win32-en-pecl.info.gz'. 21:27:34 [UPD] [INFO] Downloading of 'http://117.121.253.254/update/idx/webcat-common-int.info.gz' to 'C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\TEMP\UPDATE\idx\webcat-common-int.info.gz'. 21:27:34 [UPD] [INFO] Downloading of 'http://117.121.253.254/update/idx/vdf.info.gz' to 'C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\TEMP\UPDATE\idx\vdf.info.gz'. 21:27:34 [UPD] [INFO] Downloading of 'http://117.121.253.254/update/idx/rdf-common-int.info.gz' to 'C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\TEMP\UPDATE\idx\rdf-common-int.info.gz'. 21:27:35 [UPD] [INFO] Downloading of 'http://117.121.253.254/update/idx/ave2-win32-int.info.gz' to 'C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\TEMP\UPDATE\idx\ave2-win32-int.info.gz'. 21:27:35 [UPD] [INFO] Downloading of 'http://117.121.253.254/update/idx/wks_avira10-win32-en-pecl-info.info.gz' to 'C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\TEMP\UPDATE\idx\wks_avira10-win32-en-pecl-info.info.gz'. 21:27:36 [UPD] [INFO] Downloading of 'http://117.121.253.254/update/idx/hips-win32-int.info.gz' to 'C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\TEMP\UPDATE\idx\hips-win32-int.info.gz'. 21:27:37 [UPD] [INFO] Downloading of 'http://117.121.253.254/update/idx/detrep-win32-int.info.gz' to 'C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\TEMP\UPDATE\idx\detrep-win32-int.info.gz'. 21:27:37 [UPD] [INFO] Compare local files with status of update server 21:27:37 [UPD] [INFO] Checking module SELFUPDATE: 21:27:37 [UPD] [INFO] Checking module WEBCAT: 21:27:37 [UPD] [INFO] File 'webcat/common/int/webcat0.dat' (local, server): a348f751a04425bc8553a98a30e387fc != 52f78e18dba49fc77ad590f9958878bc 21:27:37 [UPD] [INFO] File 'webcat/common/int/webcat1.dat' (local, server): 1c1593e4c9cfd63fb86d67defcb25041 != 96e16c11ccf97a491b3c5199687af22a 21:27:37 [UPD] [INFO] File 'webcat/common/int/webcat2.dat' (local, server): 3b8d9af45aeb8ab594bad81f6768ea52 != ca79f97d31ab168dc1294d04cac1835f 21:27:37 [UPD] [INFO] File 'webcat/common/int/webcat3.dat' (local, server): 64314457276d58af115df325e82c05b0 != c99676b14622098955d18d0095af622a 21:27:37 [UPD] [INFO] File 'webcat/common/int/webcat4.dat' (local, server): ebab6c5c4994aa37e5d5a3e34e81cfe3 != 854b4ce8e8ec69e571fada41f62baae0 21:27:37 [UPD] [INFO] Checking module VDF: 21:27:37 [UPD] [INFO] File 'n_vdf/vbase028.vdf' (local, server): 7.11.29.38 < 7.11.29.75 21:27:37 [UPD] [INFO] File 'n_vdf/vbase029.vdf' (local, server): 7.11.29.39 < 7.11.29.76 21:27:37 [UPD] [INFO] File 'n_vdf/vbase030.vdf' (local, server): 7.11.29.40 < 7.11.29.77 21:27:37 [UPD] [INFO] File 'n_vdf/vbase031.vdf' (local, server): 7.11.29.70 < 7.11.29.100 21:27:37 [UPD] [INFO] File 'n_vdf/aevdf.dat' (local, server): 7.11.29.70 < 7.11.29.100 21:27:37 [UPD] [INFO] Checking module RDF: 21:27:37 [UPD] [INFO] Checking module AVE2: 21:27:37 [UPD] [INFO] Checking module MAIN: 21:27:37 [UPD] [INFO] File'wks_avira10/win32/en/pecl/ApnIC.dll' is already installed and is not being updated. 21:27:37 [UPD] [INFO] File'wks_avira10/win32/en/pecl/ApnStub.exe' is already installed and is not being updated. 21:27:37 [UPD] [INFO] File'wks_avira10/win32/en/pecl/ApnToolbarInstaller.exe' is already installed and is not being updated. 21:27:38 [UPD] [INFO] The IGNORE flag is set for the file 'wks_avira10/win32/en/pecl/filelist.ini'. The file will therefore not be taken into account. 21:27:38 [UPD] [INFO] The IGNORE flag is set for the file 'wks_avira10/win32/en/pecl/insthlp.exe'. The file will therefore not be taken into account. 21:27:38 [UPD] [INFO] The IGNORE flag is set for the file 'wks_avira10/win32/en/pecl/presetup.exe'. The file will therefore not be taken into account. 21:27:38 [UPD] [INFO] File'wks_avira10/win32/en/pecl/en-us/quicksysscan.avp' is already installed and is not being updated. 21:27:38 [UPD] [INFO] File'wks_avira10/win32/en/pecl/en-us/toolbar_eula.txt' is already installed and is not being updated. 21:27:38 [UPD] [INFO] The IGNORE flag is set for the file 'wks_avira10/win32/en/pecl/vcredist_x86.exe'. The file will therefore not be taken into account. 21:27:38 [UPD] [INFO] Checking module COMMAPPDATA_AV: 21:27:38 [UPD] [INFO] File'wks_avira10/win32/en/pecl/addr_file.html' is already installed and is not being updated. 21:27:38 [UPD] [INFO] Checking module COMMAPP: 21:27:38 [UPD] [INFO] File'wks_avira10/win32/en/pecl/en-us/produpd.avj' is already installed and is not being updated. 21:27:38 [UPD] [INFO] File'wks_avira10/win32/en/pecl/en-us/scanjob.avj' is already installed and is not being updated. 21:27:38 [UPD] [INFO] File'wks_avira10/win32/en/pecl/en-us/startupd.avj' is already installed and is not being updated. 21:27:38 [UPD] [INFO] File'wks_avira10/win32/en/pecl/en-us/updjob.avj' is already installed and is not being updated. 21:27:38 [UPD] [INFO] Checking module COMMAPDATA_AV_PROFILES: 21:27:38 [UPD] [INFO] File'wks_avira10/win32/en/pecl/en-us/folder.avp' is already installed and is not being updated. 21:27:38 [UPD] [INFO] Checking module TEXT: 21:27:38 [UPD] [INFO] The IGNORE flag is set for the file 'wks_avira10/win32/en/pecl/en-us/eula.txt'. The file will therefore not be taken into account. 21:27:38 [UPD] [INFO] Checking module DRV: 21:27:38 [UPD] [INFO] Checking module PRODINFO: 21:27:38 [UPD] [INFO] File 'wks_avira10/win32/en/pecl/en-us/prodinfo.dat' (local, server): 82a517c5064690f294032114ef1e0c6a != 30977a13af94dcbcc3b11efbd2f2e41b 21:27:38 [UPD] [INFO] Checking module HIPS: 21:27:38 [UPD] [INFO] Checking module DETREP: 21:27:38 [UPD] [INFO] 'C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\BACKUP\' requires 136704 bytes of free disk space. 21:27:38 [UPD] [INFO] 'C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\TEMP\UPDATE\' requires 507176 bytes of free disk space. 21:27:38 [UPD] [INFO] 'C:\Program Files\Avira\AntiVir Desktop\' requires 256092 bytes of free disk space. 21:27:38 [UPD] [INFO] Disk space OK. 21:27:38 [UPD] [INFO] Drive: C:\, free capacity: 1666424832 bytes. 21:27:38 [UPD] [INFO] New files are being downloaded… 21:27:39 [UPD] [INFO] Downloading of 'http://117.121.253.254/update/n_vdf/vbase028.vdf.gz' to 'C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\TEMP\UPDATE\n_vdf\vbase028.vdf.gz'. 21:27:41 [UPD] [INFO] Downloading of 'http://117.121.253.254/update/n_vdf/vbase029.vdf.gz' to 'C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\TEMP\UPDATE\n_vdf\vbase029.vdf.gz'. 21:27:41 [UPD] [INFO] Downloading of 'http://117.121.253.254/update/n_vdf/vbase030.vdf.gz' to 'C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\TEMP\UPDATE\n_vdf\vbase030.vdf.gz'. 21:27:41 [UPD] [INFO] Downloading of 'http://117.121.253.254/update/n_vdf/vbase031.vdf.gz' to 'C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\TEMP\UPDATE\n_vdf\vbase031.vdf.gz'. 21:27:42 [UPD] [INFO] Downloading of 'http://117.121.253.254/update/n_vdf/aevdf.dat.gz' to 'C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\TEMP\UPDATE\n_vdf\aevdf.dat.gz'. 21:27:42 [UPD] [INFO] Downloading of 'http://117.121.253.254/update/wks_avira10/win32/en/pecl/en-us/prodinfo.dat.gz' to 'C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\TEMP\UPDATE\wks_avira10\win32\en\pecl\en-us\prodinfo.dat.gz'. 21:27:42 [UPD] [INFO] The program is running as an unrestricted full version. 21:27:53 [UPD] [INFO] The engine was successfully validated. 21:27:53 [UPD] [INFO] 'C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\TEMP\UPDATE\.\n_vdf\vbase028.vdf' was copied to 'C:\Program Files\Avira\AntiVir Desktop\vbase028.vdf'. 21:27:53 [UPD] [INFO] 'C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\TEMP\UPDATE\.\n_vdf\vbase029.vdf' was copied to 'C:\Program Files\Avira\AntiVir Desktop\vbase029.vdf'. 21:27:53 [UPD] [INFO] 'C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\TEMP\UPDATE\.\n_vdf\vbase030.vdf' was copied to 'C:\Program Files\Avira\AntiVir Desktop\vbase030.vdf'. 21:27:53 [UPD] [INFO] 'C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\TEMP\UPDATE\.\n_vdf\vbase031.vdf' was copied to 'C:\Program Files\Avira\AntiVir Desktop\vbase031.vdf'. 21:27:53 [UPD] [INFO] 'C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\TEMP\UPDATE\.\n_vdf\aevdf.dat' was copied to 'C:\Program Files\Avira\AntiVir Desktop\aevdf.dat'. 21:27:53 [UPD] [INFO] 'C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\TEMP\UPDATE\.\wks_avira10\win32\en\pecl\en-us\prodinfo.dat' was copied to 'C:\Program Files\Avira\AntiVir Desktop\prodinfo.dat'. 21:28:03 [UPD] [INFO] Re-initialization of Avira AntiVir Guard was successful. Summary: ******** 6 Files downloaded 6 Files installed Downloaded file(s): vbase028.vdf 7.11.29.75; vbase029.vdf 7.11.29.76; vbase030.vdf 7.11.29.77; vbase031.vdf 7.11.29.100; aevdf.dat 7.11.29.100; prodinfo.dat; Tue May 08 21:28:09 2012 The update was carried out successfully!
Could you let me know whether or not ANIWZCS was detected by your Security software (for example Avira or Malwarebytes Anti-Malware)? :)

Please download erunt-setup.exe on the left column. Use the setup program to install ERUNT on your computer.

Then, run Erunt.exe to backup your registry to the folder of your choice.

Next

Please be aware that removing malware is not without risk, but the tools that I ask you to run are safe.

If prompted about the Unknown Publisher please click on Run and then run the OTL fix as requested. :thumbup:

In your next reply, please provide the following:
  • OTL log.
  • Update on how your PC is running.



Regards,

Richard :wavey:
Hi Richard.

ok … ANIWZCS was not detected by my Security softwarw.
Latest Avira scan showed 7 detections . one being EXP2011-3544.DL.I which I moved to quarantine .

PC is not running 100% .

many many thanks for ur help.



All processes killed
========== OTL ==========
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Restrictions\ not found.
Registry key HKEY_USERS\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel\ not found.
Registry key HKEY_USERS\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel\ not found.
Registry key HKEY_USERS\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel\ not found.
Registry key HKEY_USERS\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel\ not found.
Registry key HKEY_USERS\S-1-5-21-1645522239-1972579041-682003330-1003\Software\Policies\Microsoft\Internet Explorer\Control Panel\ not found.
Unable to delete ADS C:\Documents and Settings\All Users\Application Data\TEMP:C039C6AC .
Unable to delete ADS C:\Documents and Settings\All Users\Application Data\TEMP:6401C7FF .
========== FILES ==========
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Documents and Settings\Jeff\Desktop\cmd.bat deleted successfully.
C:\Documents and Settings\Jeff\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========
C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYTEMP]

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 0 bytes

User: Jeff
->Temp folder emptied: 24431360 bytes
->Temporary Internet Files folder emptied: 51958721 bytes
->Java cache emptied: 280 bytes
->Google Chrome cache emptied: 0 bytes
->Apple Safari cache emptied: 0 bytes
->Flash cache emptied: 3761 bytes

User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 0 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 26835 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 20101580 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 4644 bytes

Total Files Cleaned = 92.00 mb


OTL by OldTimer - Version 3.2.42.1 log created on 05132012_222755

Files\Folders moved on Reboot…
File\Folder C:\Documents and Settings\Jeff\Local Settings\Temp\~DF4A44.tmp not found!
File\Folder C:\Documents and Settings\Jeff\Local Settings\Temp\~DF4A5C.tmp not found!
File\Folder C:\Documents and Settings\Jeff\Local Settings\Temp\~DF4ACF.tmp not found!
File\Folder C:\Documents and Settings\Jeff\Local Settings\Temp\~DF4AE7.tmp not found!
File\Folder C:\Documents and Settings\Jeff\Local Settings\Temp\~DF4CB4.tmp not found!
File\Folder C:\Documents and Settings\Jeff\Local Settings\Temp\~DF4DDA.tmp not found!
C:\Documents and Settings\Jeff\Local Settings\Temporary Internet Files\Content.IE5\3QR8ZMEZ\index[1].htm moved successfully.
C:\Documents and Settings\Jeff\Local Settings\Temporary Internet Files\Content.IE5\3QR8ZMEZ\index[2].htm moved successfully.
C:\Documents and Settings\Jeff\Local Settings\Temporary Internet Files\Content.IE5\01H05V5O\iframe[2].htm moved successfully.

Registry entries deleted on Reboot…



AVIRA SCAN 12th MAY



Avira AntiVir Personal
Report file date: Sunday, 13 May 2012 21:36

Scanning for 3689413 virus strains and unwanted programs.

The program is running as an unrestricted full version.
Online services are available:

Licensee : Avira AntiVir Personal - Free Antivirus
Serial number : 0000149996-ADJIE-0000001
Platform : Windows XP
Windows version : (Service Pack 3) [5.1.2600]
Boot mode : Normally booted
Username : SYSTEM
Computer name : TAYLOR

Version information:
BUILD.DAT : 10.2.0.707 36070 Bytes 25/01/2012 13:11:00
AVSCAN.EXE : 10.3.0.7 484008 Bytes 5/07/2011 23:26:51
AVSCAN.DLL : 10.0.5.0 47464 Bytes 5/07/2011 23:26:51
LUKE.DLL : 10.3.0.5 45416 Bytes 5/07/2011 23:26:52
LUKERES.DLL : 10.0.0.1 12648 Bytes 10/02/2010 16:40:49
AVSCPLR.DLL : 10.3.0.7 119656 Bytes 5/07/2011 23:26:53
AVREG.DLL : 10.3.0.9 88833 Bytes 4/08/2011 04:38:11
VBASE000.VDF : 7.10.0.0 19875328 Bytes 6/11/2009 04:50:27
VBASE001.VDF : 7.11.0.0 13342208 Bytes 14/12/2010 00:50:23
VBASE002.VDF : 7.11.19.170 14374912 Bytes 20/12/2011 00:29:20
VBASE003.VDF : 7.11.21.238 4472832 Bytes 1/02/2012 00:33:50
VBASE004.VDF : 7.11.26.44 4329472 Bytes 28/03/2012 10:16:27
VBASE005.VDF : 7.11.29.136 2166272 Bytes 10/05/2012 01:23:37
VBASE006.VDF : 7.11.29.137 2048 Bytes 10/05/2012 01:23:38
VBASE007.VDF : 7.11.29.138 2048 Bytes 10/05/2012 01:23:38
VBASE008.VDF : 7.11.29.139 2048 Bytes 10/05/2012 01:23:38
VBASE009.VDF : 7.11.29.140 2048 Bytes 10/05/2012 01:23:39
VBASE010.VDF : 7.11.29.141 2048 Bytes 10/05/2012 01:23:39
VBASE011.VDF : 7.11.29.142 2048 Bytes 10/05/2012 01:23:40
VBASE012.VDF : 7.11.29.143 2048 Bytes 10/05/2012 01:23:40
VBASE013.VDF : 7.11.29.144 2048 Bytes 10/05/2012 01:23:41
VBASE014.VDF : 7.11.29.145 2048 Bytes 10/05/2012 01:23:41
VBASE015.VDF : 7.11.29.146 2048 Bytes 10/05/2012 01:23:42
VBASE016.VDF : 7.11.29.147 2048 Bytes 10/05/2012 01:23:42
VBASE017.VDF : 7.11.29.148 2048 Bytes 10/05/2012 01:23:43
VBASE018.VDF : 7.11.29.149 2048 Bytes 10/05/2012 01:23:43
VBASE019.VDF : 7.11.29.150 2048 Bytes 10/05/2012 01:23:43
VBASE020.VDF : 7.11.29.151 2048 Bytes 10/05/2012 01:23:44
VBASE021.VDF : 7.11.29.152 2048 Bytes 10/05/2012 01:23:44
VBASE022.VDF : 7.11.29.153 2048 Bytes 10/05/2012 01:23:45
VBASE023.VDF : 7.11.29.154 2048 Bytes 10/05/2012 01:23:45
VBASE024.VDF : 7.11.29.155 2048 Bytes 10/05/2012 01:23:46
VBASE025.VDF : 7.11.29.156 2048 Bytes 10/05/2012 01:23:49
VBASE026.VDF : 7.11.29.157 2048 Bytes 10/05/2012 01:23:49
VBASE027.VDF : 7.11.29.158 2048 Bytes 10/05/2012 01:23:50
VBASE028.VDF : 7.11.29.159 2048 Bytes 10/05/2012 01:23:50
VBASE029.VDF : 7.11.29.160 2048 Bytes 10/05/2012 01:23:51
VBASE030.VDF : 7.11.29.161 2048 Bytes 10/05/2012 01:23:51
VBASE031.VDF : 7.11.29.206 102912 Bytes 11/05/2012 01:23:56
Engineversion : 8.2.10.64
AEVDF.DLL : 8.1.2.2 106868 Bytes 3/11/2011 02:35:44
AESCRIPT.DLL : 8.1.4.19 455034 Bytes 13/05/2012 01:25:29
AESCN.DLL : 8.1.8.2 131444 Bytes 27/01/2012 13:51:41
AESBX.DLL : 8.2.5.5 606579 Bytes 30/03/2012 10:19:37
AERDL.DLL : 8.1.9.15 639348 Bytes 12/09/2011 23:49:47
AEPACK.DLL : 8.2.16.13 807287 Bytes 13/05/2012 01:25:24
AEOFFICE.DLL : 8.1.2.28 201082 Bytes 27/04/2012 02:27:13
AEHEUR.DLL : 8.1.4.25 4788598 Bytes 13/05/2012 01:25:10
AEHELP.DLL : 8.1.21.0 254326 Bytes 13/05/2012 01:24:06
AEGEN.DLL : 8.1.5.28 422260 Bytes 27/04/2012 02:26:07
AEEXP.DLL : 8.1.0.36 82292 Bytes 13/05/2012 01:25:30
AEEMU.DLL : 8.1.3.0 393589 Bytes 27/11/2010 00:25:15
AECORE.DLL : 8.1.25.6 201078 Bytes 30/03/2012 10:17:08
AEBB.DLL : 8.1.1.0 53618 Bytes 24/04/2010 05:04:29
AVWINLL.DLL : 10.0.0.0 19304 Bytes 2/08/2010 08:09:56
AVPREF.DLL : 10.0.3.2 44904 Bytes 5/07/2011 23:26:51
AVREP.DLL : 10.0.0.10 174120 Bytes 28/05/2011 23:56:10
AVARKT.DLL : 10.0.26.1 255336 Bytes 5/07/2011 23:26:51
AVEVTLOG.DLL : 10.0.0.9 203112 Bytes 5/07/2011 23:26:51
SQLITE3.DLL : 3.6.19.0 355688 Bytes 17/06/2010 07:27:22
AVSMTP.DLL : 10.0.0.17 63848 Bytes 2/08/2010 08:09:56
NETNT.DLL : 10.0.0.0 11624 Bytes 17/06/2010 07:27:21
RCIMAGE.DLL : 10.0.0.35 2589544 Bytes 5/07/2011 23:26:50
RCTEXT.DLL : 10.0.64.0 97640 Bytes 5/07/2011 23:26:51

Configuration settings for the scan:
Jobname………………………..: Complete system scan
Configuration file………………: c:\program files\avira\antivir desktop\sysscan.avp
Logging………………………..: Default
Primary action………………….: interactive
Secondary action………………..: ignore
Scan master boot sector………….: on
Scan boot sector………………..: on
Boot sectors……………………: C:,
Process scan……………………: on
Extended process scan……………: on
Scan registry…………………..: on
Search for rootkits……………..: on
Integrity checking of system files..: off
Scan all files………………….: All files
Scan archives…………………..: on
Recursion depth…………………: 20
Smart extensions………………..: on
Macro heuristic…………………: on
File heuristic………………….: Advanced

Start of the scan: Sunday, 13 May 2012 21:36

Starting search for hidden objects.

The scan of running processes will be started
Scan process 'rsmsink.exe' - '29' Module(s) have been scanned
Scan process 'msdtc.exe' - '40' Module(s) have been scanned
Scan process 'dllhost.exe' - '61' Module(s) have been scanned
Scan process 'dllhost.exe' - '45' Module(s) have been scanned
Scan process 'vssvc.exe' - '48' Module(s) have been scanned
Scan process 'avscan.exe' - '67' Module(s) have been scanned
Scan process 'avcenter.exe' - '63' Module(s) have been scanned
Scan process 'msimn.exe' - '90' Module(s) have been scanned
Scan process 'alg.exe' - '33' Module(s) have been scanned
Scan process 'iPodService.exe' - '30' Module(s) have been scanned
Scan process 'COCIManager.exe' - '39' Module(s) have been scanned
Scan process 'Skype.exe' - '117' Module(s) have been scanned
Scan process 'Vid.exe' - '123' Module(s) have been scanned
Scan process 'ctfmon.exe' - '25' Module(s) have been scanned
Scan process 'CameraHelperShell.exe' - '51' Module(s) have been scanned
Scan process 'iTunesHelper.exe' - '64' Module(s) have been scanned
Scan process 'AirGCFG.exe' - '40' Module(s) have been scanned
Scan process 'WZCSLDR2.exe' - '40' Module(s) have been scanned
Scan process 'gcbrmon.exe' - '20' Module(s) have been scanned
Scan process 'Updater.exe' - '32' Module(s) have been scanned
Scan process 'jusched.exe' - '21' Module(s) have been scanned
Scan process 'Monitor.exe' - '31' Module(s) have been scanned
Scan process 'LWS.exe' - '34' Module(s) have been scanned
Scan process 'lxdmamon.exe' - '51' Module(s) have been scanned
Scan process 'lxdmmon.exe' - '32' Module(s) have been scanned
Scan process 'svchost.exe' - '47' Module(s) have been scanned
Scan process 'PDVDServ.exe' - '24' Module(s) have been scanned
Scan process 'GoogleQuickSearchBox.exe' - '77' Module(s) have been scanned
Scan process 'avgnt.exe' - '54' Module(s) have been scanned
Scan process 'RichVideo.exe' - '22' Module(s) have been scanned
Scan process 'mdm.exe' - '20' Module(s) have been scanned
Scan process 'lxdmcoms.exe' - '35' Module(s) have been scanned
Scan process 'avshadow.exe' - '26' Module(s) have been scanned
Scan process 'CommandService.exe' - '23' Module(s) have been scanned
Scan process 'jqs.exe' - '33' Module(s) have been scanned
Scan process 'mDNSResponder.exe' - '28' Module(s) have been scanned
Scan process 'AppleMobileDeviceService.exe' - '60' Module(s) have been scanned
Scan process 'avguard.exe' - '55' Module(s) have been scanned
Scan process 'Explorer.EXE' - '104' Module(s) have been scanned
Scan process 'svchost.exe' - '34' Module(s) have been scanned
Scan process 'sched.exe' - '45' Module(s) have been scanned
Scan process 'UMVPFSrv.exe' - '17' Module(s) have been scanned
Scan process 'spoolsv.exe' - '72' Module(s) have been scanned
Scan process 'svchost.exe' - '31' Module(s) have been scanned
Scan process 'svchost.exe' - '32' Module(s) have been scanned
Scan process 'svchost.exe' - '30' Module(s) have been scanned
Scan process 'svchost.exe' - '162' Module(s) have been scanned
Scan process 'svchost.exe' - '39' Module(s) have been scanned
Scan process 'svchost.exe' - '53' Module(s) have been scanned
Scan process 'lsass.exe' - '51' Module(s) have been scanned
Scan process 'services.exe' - '27' Module(s) have been scanned
Scan process 'winlogon.exe' - '67' Module(s) have been scanned
Scan process 'csrss.exe' - '12' Module(s) have been scanned
Scan process 'smss.exe' - '2' Module(s) have been scanned

Starting master boot sector scan:
Master boot sector HD0
[INFO] No virus was found!
Master boot sector HD1
[INFO] No virus was found!
Master boot sector HD2
[INFO] No virus was found!
Master boot sector HD3
[INFO] No virus was found!
Master boot sector HD4
[INFO] No virus was found!
Master boot sector HD5
[INFO] No virus was found!

Start scanning boot sectors:
Boot sector 'C:\'
[INFO] No virus was found!

Starting to scan executable files (registry).
The registry was scanned ( '1306' files ).


Starting the file scan:

Begin scan in 'C:\'
C:\Documents and Settings\Jeff\Application Data\Sun\Java\Deployment\cache\6.0\56\28914178-737627e5
[0] Archive type: ZIP
–> rc.class
[DETECTION] Contains recognition pattern of the EXP/2011-3544.DI.1 exploit
–> Dot.class
[DETECTION] Contains recognition pattern of the EXP/2011-3544.DJ.1 exploit
–> ER.class
[DETECTION] Contains recognition pattern of the EXP/3544.CU.1.A exploit
–> rb.class
[DETECTION] Contains recognition pattern of the EXP/CVE-2011-3544.CB exploit
–> lz.class
[DETECTION] Contains recognition pattern of the EXP/2011-3544.DK.1 exploit
–> rd.class
[DETECTION] Contains recognition pattern of the EXP/2011-3544.CR exploit
–> ra.class
[DETECTION] Contains recognition pattern of the EXP/2011-3544.DL.1 exploit

Beginning disinfection:
C:\Documents and Settings\Jeff\Application Data\Sun\Java\Deployment\cache\6.0\56\28914178-737627e5
[DETECTION] Contains recognition pattern of the EXP/2011-3544.DL.1 exploit
[NOTE] The file was moved to the quarantine directory under the name '4465670f.qua'.


End of the scan: Sunday, 13 May 2012 22:21
Used time: 36:36 Minute(s)

The scan has been done completely.

10947 Scanned directories
277991 Files were scanned
7 Viruses and/or unwanted programs were found
0 Files were classified as suspicious
0 files were deleted
0 Viruses and unwanted programs were repaired
1 Files were moved to quarantine
0 Files were renamed
0 Files cannot be scanned
277984 Files not concerned
3954 Archives were scanned
0 Warnings
1 Notes
466928 Objects were scanned with rootkit scan
0 Hidden objects were found
Thanks for the information :thumbup:

The Avira detections are only warnings about vulnerabilities in an older version of Java that can be exploited. We will update to the newest version later. B)

Questionable Toolbar/Plugin Uninstall:

Do you use all those toolbars/browser plugins that are installed?

Ask Toolbar is an open to debate toolbar.

WeatherBlink is an Adware toolbar.

If you would like to remove the Toolbar(s)/Plugin(s), follow these steps:
  • Click on Start > Control Panel.
  • Click on Add or Remove Programs.
  • Select the following from the list:


    Ask Toolbar
    WeatherBlink

  • Click the Remove button.
Next

UPDATE MALWAREBYTES' ANTI-MALWARE
——————————————-
I see that you have Malwarebytes' Anti-Malware installed on your computer.
  • Open Malwarebytes' Anti-Malware.
  • Select the Update tab.
  • Click Check for Updates.
  • Once the updates have been completed, return to the Scanner tab.
  • Select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, and that they have been added to the delete on reboot list, please reboot.
The log can also be found by:
  • Selecting the Logs tab when the application is started.
  • Navigating to C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-date (time).txt
Next

ESET ONLINE SCANNER
—————————-
I'd like us to scan your machine with ESET OnlineScan
  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the green ESET Online Scanner button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps):
    • Click on Download to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the esetsmartinstaller_enu.exe icon on your desktop.
  • Check YES, I accept the Terms of Use.
  • Click the Start button.
  • Accept any security warnings from your browser.
  • Check Scan archives.
  • Ensure that the option "Remove found threats" is Unchecked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push List of found threats.
  • Push Export to text file…, and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
    Note - when ESET doesn't find any threats, no report will be created.
  • Push the Back button.
  • Push Finish.
In your next reply, please provide the following:
  • MBAM log.
  • ESET log.
  • Update on how your PC is running.



Regards,

Richard :wavey:
The files being flagged by ESET will be removed when we remove our tools and reset System Restore. ^_^

Please post a fresh OTL log so I can review it.

In your next reply, please provide the following:
  • OTL log.
  • Update on how your PC is running.



Regards,

Richard :wavey:

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI