My name is Richard and I'll be happy to help you with your computer problems.
Please be advised that I am currently in training, so my responses will need to be approved by one of our experts before I post them. This is only to ensure you are receiving accurate instructions. It may cause a delay in my replies.
Please note the following:
The cleaning process is not instant as logs can take time to research. Sit tight and please be patient.
I will be working on your malware issues. This may or may not solve other issues you may have with your system.
While we are fixing your problems, do NOT install/re-install any programs or run any fixes or scanners unless told to do so.
Ensure that your anti-virus definitions are up-to-date.
I would advise backing up all your important documents, personal data files and photos to a CD or DVD drive.
Do not back up any Applications (programs). These should be re-installed from the original source CD(s) or website(s).
During the course of our cleanup, please do not do any additional online work or surfing until we have verified that your system is clean.
I suggest printing out each set of instructions and reading the entire post before proceeding. It will make following them easier.
Be sure to follow the directions and run tools/scans in the order listed.
If you do not reply to your topic, it will be closed after 3 days.
I will return as soon as possible with more instructions.
Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
Select All Users.
Under the Custom Scan box paste this in netsvcs
%SYSTEMDRIVE%\*.exe
/md5start
explorer.exe
winlogon.exe
Userinit.exe
svchost.exe
/md5stop
%systemroot%\*. /rp /s
DRIVES
CREATERESTOREPOINT
Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
Note:These logs can be located in the OTL. folder on your C:\ drive if they fail to open automatically.
Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post both logs with your next reply. You may need two posts to fit them both in.
Next
GMER Rootkit Scanner
—————
Download GMER Rootkit Scanner from here to to your Desktop. It will be a randomly named executable.
Double click the exe file. If asked to allow gmer.sys driver to load, please consent.
If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.
In the right panel, you will see several boxes that have been checked. uncheck the following:
IAT/EAT
Drives/Partition other than Systemdrive (typically C:\)
Show All (don't miss this one)
Then click the Scan button & wait for it to finish.
Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
Save it where you can easily find it, such as your Desktop, and attach it in reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
I hope this is all correct.
many thanks
Avira AntiVir Personal
Report file date: Friday, 27 April 2012 11:16
Scanning for 3714949 virus strains and unwanted programs.
The program is running as an unrestricted full version.
Online services are available:
Licensee : Avira AntiVir Personal - Free Antivirus
Serial number : 0000149996-ADJIE-0000001
Platform : Windows XP
Windows version : (Service Pack 3) [5.1.2600]
Boot mode : Normally booted
Username : SYSTEM
Computer name : TAYLOR
Version information:
BUILD.DAT : 10.2.0.707 36070 Bytes 25/01/2012 13:11:00
AVSCAN.EXE : 10.3.0.7 484008 Bytes 5/07/2011 23:26:51
AVSCAN.DLL : 10.0.5.0 47464 Bytes 5/07/2011 23:26:51
LUKE.DLL : 10.3.0.5 45416 Bytes 5/07/2011 23:26:52
LUKERES.DLL : 10.0.0.1 12648 Bytes 10/02/2010 16:40:49
AVSCPLR.DLL : 10.3.0.7 119656 Bytes 5/07/2011 23:26:53
AVREG.DLL : 10.3.0.9 88833 Bytes 4/08/2011 04:38:11
VBASE000.VDF : 7.10.0.0 19875328 Bytes 6/11/2009 04:50:27
VBASE001.VDF : 7.11.0.0 13342208 Bytes 14/12/2010 00:50:23
VBASE002.VDF : 7.11.19.170 14374912 Bytes 20/12/2011 00:29:20
VBASE003.VDF : 7.11.21.238 4472832 Bytes 1/02/2012 00:33:50
VBASE004.VDF : 7.11.26.44 4329472 Bytes 28/03/2012 10:16:27
VBASE005.VDF : 7.11.26.45 2048 Bytes 28/03/2012 10:16:28
VBASE006.VDF : 7.11.26.46 2048 Bytes 28/03/2012 10:16:28
VBASE007.VDF : 7.11.26.47 2048 Bytes 28/03/2012 10:16:29
VBASE008.VDF : 7.11.26.48 2048 Bytes 28/03/2012 10:16:34
VBASE009.VDF : 7.11.26.49 2048 Bytes 28/03/2012 10:16:34
VBASE010.VDF : 7.11.26.50 2048 Bytes 28/03/2012 10:16:35
VBASE011.VDF : 7.11.26.51 2048 Bytes 28/03/2012 10:16:35
VBASE012.VDF : 7.11.26.52 2048 Bytes 28/03/2012 10:16:36
VBASE013.VDF : 7.11.26.53 2048 Bytes 28/03/2012 10:16:36
VBASE014.VDF : 7.11.26.107 221696 Bytes 30/03/2012 10:16:49
VBASE015.VDF : 7.11.26.179 224768 Bytes 2/04/2012 23:24:42
VBASE016.VDF : 7.11.26.241 142336 Bytes 4/04/2012 23:34:42
VBASE017.VDF : 7.11.27.41 247808 Bytes 8/04/2012 23:55:55
VBASE018.VDF : 7.11.27.107 161280 Bytes 12/04/2012 23:56:01
VBASE019.VDF : 7.11.27.159 148992 Bytes 13/04/2012 23:56:06
VBASE020.VDF : 7.11.27.201 207360 Bytes 17/04/2012 23:56:12
VBASE021.VDF : 7.11.28.3 237568 Bytes 19/04/2012 00:34:38
VBASE022.VDF : 7.11.28.49 193536 Bytes 20/04/2012 23:56:06
VBASE023.VDF : 7.11.28.99 195072 Bytes 23/04/2012 23:56:12
VBASE024.VDF : 7.11.28.133 247808 Bytes 24/04/2012 02:25:48
VBASE025.VDF : 7.11.28.183 186880 Bytes 26/04/2012 02:25:53
VBASE026.VDF : 7.11.28.184 2048 Bytes 26/04/2012 02:25:54
VBASE027.VDF : 7.11.28.185 2048 Bytes 26/04/2012 02:25:55
VBASE028.VDF : 7.11.28.186 2048 Bytes 26/04/2012 02:25:56
VBASE029.VDF : 7.11.28.187 2048 Bytes 26/04/2012 02:25:57
VBASE030.VDF : 7.11.28.188 2048 Bytes 26/04/2012 02:25:58
VBASE031.VDF : 7.11.28.198 39424 Bytes 26/04/2012 02:26:00
Engineversion : 8.2.10.58
AEVDF.DLL : 8.1.2.2 106868 Bytes 3/11/2011 02:35:44
AESCRIPT.DLL : 8.1.4.18 455034 Bytes 27/04/2012 02:27:18
AESCN.DLL : 8.1.8.2 131444 Bytes 27/01/2012 13:51:41
AESBX.DLL : 8.2.5.5 606579 Bytes 30/03/2012 10:19:37
AERDL.DLL : 8.1.9.15 639348 Bytes 12/09/2011 23:49:47
AEPACK.DLL : 8.2.16.9 807287 Bytes 1/04/2012 02:02:10
AEOFFICE.DLL : 8.1.2.28 201082 Bytes 27/04/2012 02:27:13
AEHEUR.DLL : 8.1.4.21 4682102 Bytes 27/04/2012 02:27:09
AEHELP.DLL : 8.1.20.0 254326 Bytes 27/04/2012 02:26:11
AEGEN.DLL : 8.1.5.28 422260 Bytes 27/04/2012 02:26:07
AEEXP.DLL : 8.1.0.33 82293 Bytes 27/04/2012 02:27:20
AEEMU.DLL : 8.1.3.0 393589 Bytes 27/11/2010 00:25:15
AECORE.DLL : 8.1.25.6 201078 Bytes 30/03/2012 10:17:08
AEBB.DLL : 8.1.1.0 53618 Bytes 24/04/2010 05:04:29
AVWINLL.DLL : 10.0.0.0 19304 Bytes 2/08/2010 08:09:56
AVPREF.DLL : 10.0.3.2 44904 Bytes 5/07/2011 23:26:51
AVREP.DLL : 10.0.0.10 174120 Bytes 28/05/2011 23:56:10
AVARKT.DLL : 10.0.26.1 255336 Bytes 5/07/2011 23:26:51
AVEVTLOG.DLL : 10.0.0.9 203112 Bytes 5/07/2011 23:26:51
SQLITE3.DLL : 3.6.19.0 355688 Bytes 17/06/2010 07:27:22
AVSMTP.DLL : 10.0.0.17 63848 Bytes 2/08/2010 08:09:56
NETNT.DLL : 10.0.0.0 11624 Bytes 17/06/2010 07:27:21
RCIMAGE.DLL : 10.0.0.35 2589544 Bytes 5/07/2011 23:26:50
RCTEXT.DLL : 10.0.64.0 97640 Bytes 5/07/2011 23:26:51
Configuration settings for the scan:
Jobname………………………..: Complete system scan
Configuration file………………: C:\Program Files\Avira\AntiVir Desktop\sysscan.avp
Logging………………………..: Default
Primary action………………….: interactive
Secondary action………………..: ignore
Scan master boot sector………….: on
Scan boot sector………………..: on
Boot sectors……………………: C:,
Process scan……………………: on
Extended process scan……………: on
Scan registry…………………..: on
Search for rootkits……………..: on
Integrity checking of system files..: off
Scan all files………………….: All files
Scan archives…………………..: on
Recursion depth…………………: 20
Smart extensions………………..: on
Macro heuristic…………………: on
File heuristic………………….: Advanced
Start of the scan: Friday, 27 April 2012 11:16
Starting search for hidden objects.
The scan of running processes will be started
Scan process 'rsmsink.exe' - '29' Module(s) have been scanned
Scan process 'msdtc.exe' - '40' Module(s) have been scanned
Scan process 'dllhost.exe' - '61' Module(s) have been scanned
Scan process 'dllhost.exe' - '45' Module(s) have been scanned
Scan process 'vssvc.exe' - '48' Module(s) have been scanned
Scan process 'avscan.exe' - '70' Module(s) have been scanned
Scan process 'avcenter.exe' - '63' Module(s) have been scanned
Scan process 'msimn.exe' - '95' Module(s) have been scanned
Scan process 'alg.exe' - '33' Module(s) have been scanned
Scan process 'iPodService.exe' - '30' Module(s) have been scanned
Scan process 'svchost.exe' - '47' Module(s) have been scanned
Scan process 'RichVideo.exe' - '22' Module(s) have been scanned
Scan process 'mdm.exe' - '20' Module(s) have been scanned
Scan process 'COCIManager.exe' - '39' Module(s) have been scanned
Scan process 'Skype.exe' - '123' Module(s) have been scanned
Scan process 'lxdmcoms.exe' - '35' Module(s) have been scanned
Scan process 'Vid.exe' - '123' Module(s) have been scanned
Scan process 'CommandService.exe' - '23' Module(s) have been scanned
Scan process 'ctfmon.exe' - '25' Module(s) have been scanned
Scan process 'iTunesHelper.exe' - '64' Module(s) have been scanned
Scan process 'jqs.exe' - '33' Module(s) have been scanned
Scan process 'AirGCFG.exe' - '40' Module(s) have been scanned
Scan process 'WZCSLDR2.exe' - '40' Module(s) have been scanned
Scan process 'gcbrmon.exe' - '20' Module(s) have been scanned
Scan process 'CameraHelperShell.exe' - '51' Module(s) have been scanned
Scan process 'avshadow.exe' - '26' Module(s) have been scanned
Scan process 'Updater.exe' - '32' Module(s) have been scanned
Scan process 'jusched.exe' - '21' Module(s) have been scanned
Scan process 'mDNSResponder.exe' - '28' Module(s) have been scanned
Scan process 'Monitor.exe' - '31' Module(s) have been scanned
Scan process 'LWS.exe' - '34' Module(s) have been scanned
Scan process 'AppleMobileDeviceService.exe' - '60' Module(s) have been scanned
Scan process 'lxdmamon.exe' - '51' Module(s) have been scanned
Scan process 'lxdmmon.exe' - '32' Module(s) have been scanned
Scan process 'avguard.exe' - '55' Module(s) have been scanned
Scan process 'PDVDServ.exe' - '24' Module(s) have been scanned
Scan process 'GoogleQuickSearchBox.exe' - '90' Module(s) have been scanned
Scan process 'avgnt.exe' - '47' Module(s) have been scanned
Scan process 'Explorer.EXE' - '115' Module(s) have been scanned
Scan process 'svchost.exe' - '34' Module(s) have been scanned
Scan process 'sched.exe' - '45' Module(s) have been scanned
Scan process 'UMVPFSrv.exe' - '17' Module(s) have been scanned
Scan process 'spoolsv.exe' - '72' Module(s) have been scanned
Scan process 'svchost.exe' - '31' Module(s) have been scanned
Scan process 'svchost.exe' - '32' Module(s) have been scanned
Scan process 'svchost.exe' - '30' Module(s) have been scanned
Scan process 'svchost.exe' - '167' Module(s) have been scanned
Scan process 'svchost.exe' - '39' Module(s) have been scanned
Scan process 'svchost.exe' - '53' Module(s) have been scanned
Scan process 'lsass.exe' - '51' Module(s) have been scanned
Scan process 'services.exe' - '27' Module(s) have been scanned
Scan process 'winlogon.exe' - '67' Module(s) have been scanned
Scan process 'csrss.exe' - '14' Module(s) have been scanned
Scan process 'smss.exe' - '2' Module(s) have been scanned
Starting master boot sector scan:
Master boot sector HD0
[INFO] No virus was found!
Master boot sector HD1
[INFO] No virus was found!
Master boot sector HD2
[INFO] No virus was found!
Master boot sector HD3
[INFO] No virus was found!
Master boot sector HD4
[INFO] No virus was found!
Master boot sector HD5
[INFO] No virus was found!
Start scanning boot sectors:
Boot sector 'C:\'
[INFO] No virus was found!
Starting to scan executable files (registry).
The registry was scanned ( '1303' files ).
Starting the file scan:
Begin scan in 'C:\'
C:\Documents and Settings\Jeff\Local Settings\temp\josw392583.exe
[DETECTION] Is the TR/Crypt.ZPACK.Gen8 Trojan
Beginning disinfection:
C:\Documents and Settings\Jeff\Local Settings\temp\josw392583.exe
[DETECTION] Is the TR/Crypt.ZPACK.Gen8 Trojan
[NOTE] The file was moved to the quarantine directory under the name '5ab5befd.qua'.
End of the scan: Friday, 27 April 2012 12:00
Used time: 41:53 Minute(s)
The scan has been done completely.
12004 Scanned directories
296164 Files were scanned
1 Viruses and/or unwanted programs were found
0 Files were classified as suspicious
0 files were deleted
0 Viruses and unwanted programs were repaired
1 Files were moved to quarantine
0 Files were renamed
0 Files cannot be scanned
296163 Files not concerned
4130 Archives were scanned
0 Warnings
1 Notes
469834 Objects were scanned with rootkit scan
0 Hidden objects were found
SHA256: 80b98c5c1adaa4e066158904a713225aa6e7a1892a2fd97f5c69439d08c2dc0d
SHA1: 1763801f306f7f4753d68ba23233904c914b4d2b
HI Richard.
Thanks for the help. I hope the below is the correct info you need.
After I ran the DeFogger it did not ask to reboot the machine.
I shut down and restarted my computer and from then on the
system began very very very slow.
MD5: c14df20a1ce4246953d08511f277fc84
File size: 15.5 KB ( 15896 bytes )
File name: iKeyLFT2.dll
File type: Win32 DLL
Detection ratio: 0 / 42
Analysis date: 2012-05-01 02:16:06 UTC ( 0 minutes ago )
SHA256: f37ec3159500335e7d252993a5aab4843e482f76f73549f05bb670b8b3d4fc2b
SHA1: 01d8908429d05246376e5583c4c3f9ecba54b31c
MD5: b9fecd748f2d0096bcf1da11579eba13
File size: 48.0 KB ( 49152 bytes )
File name: JJAKEn.dll
File type: Win32 DLL
Detection ratio: 0 / 40
Analysis date: 2012-05-01 02:47:42 UTC ( 0 minutes ago
Is Avira still detecting the TR/Crypt.ZPACK.Gen8 Trojan?
Next
Before we start: The following steps involve modifying the registry. Modifying the registry can be dangerous (and can render your system unbootable) so it's advisable that you make a backup of the registry before proceeding.
Let the program run unhindered, reboot when it is done.
When the computer has rebooted, the log will be located at C:\_OTL\MovedFiles\mmddyyyy_hhmmss.log, where mmddyyyy_hhmmss is the date/time of the tool run.
Copy and paste the contents of that report in your next reply.
Hi,
Ok.. on Friday I ran a Avira and Malwares scan and on detection on a virus came up, so I thought all was good.
Today I turned on the computer and got a messages ANIWZCS was detected. I am having a problem with my external hard drive so I havent been able to back up, and I didnt want to proceed . I will have to get a new external hard drive and then ….. what .
many thanks
Hi,
Attempted ERUNT .. but was unsure what to click … they had version1 , 2 or 3 with .de ( in german).
As to OTL … when asked to RUN a warning box showed " Unknown Publisher " ( was I still to run the program).
As I am a novice I dont want to take any risks.
My PC is seems to be running fine
Avira AntiVir Personal - Free Antivirus Updater
Complete product update
Creation time: Tue May 08 21:27:32 2012
Operating system:
Windows XP (Service Pack 3) [5.1.2600] 32 bit
Product information:
Product version: 10.2.0.707
Updater: C:\Program Files\Avira\AntiVir Desktop\update.exe 10.0.0.39
Update resource: C:\Program Files\Avira\AntiVir Desktop\updaterc.dll 10.0.9.0
Library: C:\Program Files\Avira\AntiVir Desktop\update.dll 0.1.0.44
Plugin: C:\Program Files\Avira\AntiVir Desktop\updext.dll 10.0.0.10
GUI: C:\Program Files\Avira\AntiVir Desktop\updgui.dll 10.0.2.2
Temp Directory: C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\TEMP\UPDATE\
Backup folder: C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\BACKUP\
Installation Directory: C:\Program Files\Avira\AntiVir Desktop\
Updater folder: C:\Program Files\Avira\AntiVir Desktop\
AppData folder: C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\
Proxy settings:
System settings used
21:27:33 [UPD] [INFO] Checking whether newer files are available.
21:27:33 [UPD] [INFO] Select update server 'http://117.121.253.254/update'.
21:27:33 [UPD] [INFO] Downloading of 'http://117.121.253.254/update/idx/master.idx' to 'C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\TEMP\UPDATE\idx\master.idx'.
21:27:34 [UPD] [INFO] Downloading of 'http://117.121.253.254/update/idx/wks_avira10-win32-en-pecl.idx' to 'C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\TEMP\UPDATE\idx\wks_avira10-win32-en-pecl.idx'.
21:27:34 [UPD] [INFO] Downloading of 'http://117.121.253.254/update/idx/wks_avira10-win32-en-pecl.info.gz' to 'C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\TEMP\UPDATE\idx\wks_avira10-win32-en-pecl.info.gz'.
21:27:34 [UPD] [INFO] Downloading of 'http://117.121.253.254/update/idx/webcat-common-int.info.gz' to 'C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\TEMP\UPDATE\idx\webcat-common-int.info.gz'.
21:27:34 [UPD] [INFO] Downloading of 'http://117.121.253.254/update/idx/vdf.info.gz' to 'C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\TEMP\UPDATE\idx\vdf.info.gz'.
21:27:34 [UPD] [INFO] Downloading of 'http://117.121.253.254/update/idx/rdf-common-int.info.gz' to 'C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\TEMP\UPDATE\idx\rdf-common-int.info.gz'.
21:27:35 [UPD] [INFO] Downloading of 'http://117.121.253.254/update/idx/ave2-win32-int.info.gz' to 'C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\TEMP\UPDATE\idx\ave2-win32-int.info.gz'.
21:27:35 [UPD] [INFO] Downloading of 'http://117.121.253.254/update/idx/wks_avira10-win32-en-pecl-info.info.gz' to 'C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\TEMP\UPDATE\idx\wks_avira10-win32-en-pecl-info.info.gz'.
21:27:36 [UPD] [INFO] Downloading of 'http://117.121.253.254/update/idx/hips-win32-int.info.gz' to 'C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\TEMP\UPDATE\idx\hips-win32-int.info.gz'.
21:27:37 [UPD] [INFO] Downloading of 'http://117.121.253.254/update/idx/detrep-win32-int.info.gz' to 'C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\TEMP\UPDATE\idx\detrep-win32-int.info.gz'.
21:27:37 [UPD] [INFO] Compare local files with status of update server
21:27:37 [UPD] [INFO] Checking module SELFUPDATE:
21:27:37 [UPD] [INFO] Checking module WEBCAT:
21:27:37 [UPD] [INFO] File 'webcat/common/int/webcat0.dat' (local, server): a348f751a04425bc8553a98a30e387fc != 52f78e18dba49fc77ad590f9958878bc
21:27:37 [UPD] [INFO] File 'webcat/common/int/webcat1.dat' (local, server): 1c1593e4c9cfd63fb86d67defcb25041 != 96e16c11ccf97a491b3c5199687af22a
21:27:37 [UPD] [INFO] File 'webcat/common/int/webcat2.dat' (local, server): 3b8d9af45aeb8ab594bad81f6768ea52 != ca79f97d31ab168dc1294d04cac1835f
21:27:37 [UPD] [INFO] File 'webcat/common/int/webcat3.dat' (local, server): 64314457276d58af115df325e82c05b0 != c99676b14622098955d18d0095af622a
21:27:37 [UPD] [INFO] File 'webcat/common/int/webcat4.dat' (local, server): ebab6c5c4994aa37e5d5a3e34e81cfe3 != 854b4ce8e8ec69e571fada41f62baae0
21:27:37 [UPD] [INFO] Checking module VDF:
21:27:37 [UPD] [INFO] File 'n_vdf/vbase028.vdf' (local, server): 7.11.29.38 < 7.11.29.75
21:27:37 [UPD] [INFO] File 'n_vdf/vbase029.vdf' (local, server): 7.11.29.39 < 7.11.29.76
21:27:37 [UPD] [INFO] File 'n_vdf/vbase030.vdf' (local, server): 7.11.29.40 < 7.11.29.77
21:27:37 [UPD] [INFO] File 'n_vdf/vbase031.vdf' (local, server): 7.11.29.70 < 7.11.29.100
21:27:37 [UPD] [INFO] File 'n_vdf/aevdf.dat' (local, server): 7.11.29.70 < 7.11.29.100
21:27:37 [UPD] [INFO] Checking module RDF:
21:27:37 [UPD] [INFO] Checking module AVE2:
21:27:37 [UPD] [INFO] Checking module MAIN:
21:27:37 [UPD] [INFO] File'wks_avira10/win32/en/pecl/ApnIC.dll' is already installed and is not being updated.
21:27:37 [UPD] [INFO] File'wks_avira10/win32/en/pecl/ApnStub.exe' is already installed and is not being updated.
21:27:37 [UPD] [INFO] File'wks_avira10/win32/en/pecl/ApnToolbarInstaller.exe' is already installed and is not being updated.
21:27:38 [UPD] [INFO] The IGNORE flag is set for the file 'wks_avira10/win32/en/pecl/filelist.ini'. The file will therefore not be taken into account.
21:27:38 [UPD] [INFO] The IGNORE flag is set for the file 'wks_avira10/win32/en/pecl/insthlp.exe'. The file will therefore not be taken into account.
21:27:38 [UPD] [INFO] The IGNORE flag is set for the file 'wks_avira10/win32/en/pecl/presetup.exe'. The file will therefore not be taken into account.
21:27:38 [UPD] [INFO] File'wks_avira10/win32/en/pecl/en-us/quicksysscan.avp' is already installed and is not being updated.
21:27:38 [UPD] [INFO] File'wks_avira10/win32/en/pecl/en-us/toolbar_eula.txt' is already installed and is not being updated.
21:27:38 [UPD] [INFO] The IGNORE flag is set for the file 'wks_avira10/win32/en/pecl/vcredist_x86.exe'. The file will therefore not be taken into account.
21:27:38 [UPD] [INFO] Checking module COMMAPPDATA_AV:
21:27:38 [UPD] [INFO] File'wks_avira10/win32/en/pecl/addr_file.html' is already installed and is not being updated.
21:27:38 [UPD] [INFO] Checking module COMMAPP:
21:27:38 [UPD] [INFO] File'wks_avira10/win32/en/pecl/en-us/produpd.avj' is already installed and is not being updated.
21:27:38 [UPD] [INFO] File'wks_avira10/win32/en/pecl/en-us/scanjob.avj' is already installed and is not being updated.
21:27:38 [UPD] [INFO] File'wks_avira10/win32/en/pecl/en-us/startupd.avj' is already installed and is not being updated.
21:27:38 [UPD] [INFO] File'wks_avira10/win32/en/pecl/en-us/updjob.avj' is already installed and is not being updated.
21:27:38 [UPD] [INFO] Checking module COMMAPDATA_AV_PROFILES:
21:27:38 [UPD] [INFO] File'wks_avira10/win32/en/pecl/en-us/folder.avp' is already installed and is not being updated.
21:27:38 [UPD] [INFO] Checking module TEXT:
21:27:38 [UPD] [INFO] The IGNORE flag is set for the file 'wks_avira10/win32/en/pecl/en-us/eula.txt'. The file will therefore not be taken into account.
21:27:38 [UPD] [INFO] Checking module DRV:
21:27:38 [UPD] [INFO] Checking module PRODINFO:
21:27:38 [UPD] [INFO] File 'wks_avira10/win32/en/pecl/en-us/prodinfo.dat' (local, server): 82a517c5064690f294032114ef1e0c6a != 30977a13af94dcbcc3b11efbd2f2e41b
21:27:38 [UPD] [INFO] Checking module HIPS:
21:27:38 [UPD] [INFO] Checking module DETREP:
21:27:38 [UPD] [INFO] 'C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\BACKUP\' requires 136704 bytes of free disk space.
21:27:38 [UPD] [INFO] 'C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\TEMP\UPDATE\' requires 507176 bytes of free disk space.
21:27:38 [UPD] [INFO] 'C:\Program Files\Avira\AntiVir Desktop\' requires 256092 bytes of free disk space.
21:27:38 [UPD] [INFO] Disk space OK.
21:27:38 [UPD] [INFO] Drive: C:\, free capacity: 1666424832 bytes.
21:27:38 [UPD] [INFO] New files are being downloaded…
21:27:39 [UPD] [INFO] Downloading of 'http://117.121.253.254/update/n_vdf/vbase028.vdf.gz' to 'C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\TEMP\UPDATE\n_vdf\vbase028.vdf.gz'.
21:27:41 [UPD] [INFO] Downloading of 'http://117.121.253.254/update/n_vdf/vbase029.vdf.gz' to 'C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\TEMP\UPDATE\n_vdf\vbase029.vdf.gz'.
21:27:41 [UPD] [INFO] Downloading of 'http://117.121.253.254/update/n_vdf/vbase030.vdf.gz' to 'C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\TEMP\UPDATE\n_vdf\vbase030.vdf.gz'.
21:27:41 [UPD] [INFO] Downloading of 'http://117.121.253.254/update/n_vdf/vbase031.vdf.gz' to 'C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\TEMP\UPDATE\n_vdf\vbase031.vdf.gz'.
21:27:42 [UPD] [INFO] Downloading of 'http://117.121.253.254/update/n_vdf/aevdf.dat.gz' to 'C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\TEMP\UPDATE\n_vdf\aevdf.dat.gz'.
21:27:42 [UPD] [INFO] Downloading of 'http://117.121.253.254/update/wks_avira10/win32/en/pecl/en-us/prodinfo.dat.gz' to 'C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\TEMP\UPDATE\wks_avira10\win32\en\pecl\en-us\prodinfo.dat.gz'.
21:27:42 [UPD] [INFO] The program is running as an unrestricted full version.
21:27:53 [UPD] [INFO] The engine was successfully validated.
21:27:53 [UPD] [INFO] 'C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\TEMP\UPDATE\.\n_vdf\vbase028.vdf' was copied to 'C:\Program Files\Avira\AntiVir Desktop\vbase028.vdf'.
21:27:53 [UPD] [INFO] 'C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\TEMP\UPDATE\.\n_vdf\vbase029.vdf' was copied to 'C:\Program Files\Avira\AntiVir Desktop\vbase029.vdf'.
21:27:53 [UPD] [INFO] 'C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\TEMP\UPDATE\.\n_vdf\vbase030.vdf' was copied to 'C:\Program Files\Avira\AntiVir Desktop\vbase030.vdf'.
21:27:53 [UPD] [INFO] 'C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\TEMP\UPDATE\.\n_vdf\vbase031.vdf' was copied to 'C:\Program Files\Avira\AntiVir Desktop\vbase031.vdf'.
21:27:53 [UPD] [INFO] 'C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\TEMP\UPDATE\.\n_vdf\aevdf.dat' was copied to 'C:\Program Files\Avira\AntiVir Desktop\aevdf.dat'.
21:27:53 [UPD] [INFO] 'C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\TEMP\UPDATE\.\wks_avira10\win32\en\pecl\en-us\prodinfo.dat' was copied to 'C:\Program Files\Avira\AntiVir Desktop\prodinfo.dat'.
21:28:03 [UPD] [INFO] Re-initialization of Avira AntiVir Guard was successful.
Summary:
********
6 Files downloaded
6 Files installed
Downloaded file(s): vbase028.vdf 7.11.29.75; vbase029.vdf 7.11.29.76; vbase030.vdf 7.11.29.77; vbase031.vdf 7.11.29.100; aevdf.dat 7.11.29.100; prodinfo.dat;
Tue May 08 21:28:09 2012
The update was carried out successfully!
ok … ANIWZCS was not detected by my Security softwarw.
Latest Avira scan showed 7 detections . one being EXP2011-3544.DL.I which I moved to quarantine .
PC is not running 100% .
many many thanks for ur help.
All processes killed
========== OTL ==========
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Restrictions\ not found.
Registry key HKEY_USERS\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel\ not found.
Registry key HKEY_USERS\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel\ not found.
Registry key HKEY_USERS\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel\ not found.
Registry key HKEY_USERS\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel\ not found.
Registry key HKEY_USERS\S-1-5-21-1645522239-1972579041-682003330-1003\Software\Policies\Microsoft\Internet Explorer\Control Panel\ not found.
Unable to delete ADS C:\Documents and Settings\All Users\Application Data\TEMP:C039C6AC .
Unable to delete ADS C:\Documents and Settings\All Users\Application Data\TEMP:6401C7FF .
========== FILES ========== < ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Documents and Settings\Jeff\Desktop\cmd.bat deleted successfully.
C:\Documents and Settings\Jeff\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========
C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
[EMPTYTEMP]
User: All Users
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 0 bytes
OTL by OldTimer - Version 3.2.42.1 log created on 05132012_222755
Files\Folders moved on Reboot…
File\Folder C:\Documents and Settings\Jeff\Local Settings\Temp\~DF4A44.tmp not found!
File\Folder C:\Documents and Settings\Jeff\Local Settings\Temp\~DF4A5C.tmp not found!
File\Folder C:\Documents and Settings\Jeff\Local Settings\Temp\~DF4ACF.tmp not found!
File\Folder C:\Documents and Settings\Jeff\Local Settings\Temp\~DF4AE7.tmp not found!
File\Folder C:\Documents and Settings\Jeff\Local Settings\Temp\~DF4CB4.tmp not found!
File\Folder C:\Documents and Settings\Jeff\Local Settings\Temp\~DF4DDA.tmp not found!
C:\Documents and Settings\Jeff\Local Settings\Temporary Internet Files\Content.IE5\3QR8ZMEZ\index[1].htm moved successfully.
C:\Documents and Settings\Jeff\Local Settings\Temporary Internet Files\Content.IE5\3QR8ZMEZ\index[2].htm moved successfully.
C:\Documents and Settings\Jeff\Local Settings\Temporary Internet Files\Content.IE5\01H05V5O\iframe[2].htm moved successfully.
Registry entries deleted on Reboot…
AVIRA SCAN 12th MAY
Avira AntiVir Personal
Report file date: Sunday, 13 May 2012 21:36
Scanning for 3689413 virus strains and unwanted programs.
The program is running as an unrestricted full version.
Online services are available:
Licensee : Avira AntiVir Personal - Free Antivirus
Serial number : 0000149996-ADJIE-0000001
Platform : Windows XP
Windows version : (Service Pack 3) [5.1.2600]
Boot mode : Normally booted
Username : SYSTEM
Computer name : TAYLOR
Configuration settings for the scan:
Jobname………………………..: Complete system scan
Configuration file………………: c:\program files\avira\antivir desktop\sysscan.avp
Logging………………………..: Default
Primary action………………….: interactive
Secondary action………………..: ignore
Scan master boot sector………….: on
Scan boot sector………………..: on
Boot sectors……………………: C:,
Process scan……………………: on
Extended process scan……………: on
Scan registry…………………..: on
Search for rootkits……………..: on
Integrity checking of system files..: off
Scan all files………………….: All files
Scan archives…………………..: on
Recursion depth…………………: 20
Smart extensions………………..: on
Macro heuristic…………………: on
File heuristic………………….: Advanced
Start of the scan: Sunday, 13 May 2012 21:36
Starting search for hidden objects.
The scan of running processes will be started
Scan process 'rsmsink.exe' - '29' Module(s) have been scanned
Scan process 'msdtc.exe' - '40' Module(s) have been scanned
Scan process 'dllhost.exe' - '61' Module(s) have been scanned
Scan process 'dllhost.exe' - '45' Module(s) have been scanned
Scan process 'vssvc.exe' - '48' Module(s) have been scanned
Scan process 'avscan.exe' - '67' Module(s) have been scanned
Scan process 'avcenter.exe' - '63' Module(s) have been scanned
Scan process 'msimn.exe' - '90' Module(s) have been scanned
Scan process 'alg.exe' - '33' Module(s) have been scanned
Scan process 'iPodService.exe' - '30' Module(s) have been scanned
Scan process 'COCIManager.exe' - '39' Module(s) have been scanned
Scan process 'Skype.exe' - '117' Module(s) have been scanned
Scan process 'Vid.exe' - '123' Module(s) have been scanned
Scan process 'ctfmon.exe' - '25' Module(s) have been scanned
Scan process 'CameraHelperShell.exe' - '51' Module(s) have been scanned
Scan process 'iTunesHelper.exe' - '64' Module(s) have been scanned
Scan process 'AirGCFG.exe' - '40' Module(s) have been scanned
Scan process 'WZCSLDR2.exe' - '40' Module(s) have been scanned
Scan process 'gcbrmon.exe' - '20' Module(s) have been scanned
Scan process 'Updater.exe' - '32' Module(s) have been scanned
Scan process 'jusched.exe' - '21' Module(s) have been scanned
Scan process 'Monitor.exe' - '31' Module(s) have been scanned
Scan process 'LWS.exe' - '34' Module(s) have been scanned
Scan process 'lxdmamon.exe' - '51' Module(s) have been scanned
Scan process 'lxdmmon.exe' - '32' Module(s) have been scanned
Scan process 'svchost.exe' - '47' Module(s) have been scanned
Scan process 'PDVDServ.exe' - '24' Module(s) have been scanned
Scan process 'GoogleQuickSearchBox.exe' - '77' Module(s) have been scanned
Scan process 'avgnt.exe' - '54' Module(s) have been scanned
Scan process 'RichVideo.exe' - '22' Module(s) have been scanned
Scan process 'mdm.exe' - '20' Module(s) have been scanned
Scan process 'lxdmcoms.exe' - '35' Module(s) have been scanned
Scan process 'avshadow.exe' - '26' Module(s) have been scanned
Scan process 'CommandService.exe' - '23' Module(s) have been scanned
Scan process 'jqs.exe' - '33' Module(s) have been scanned
Scan process 'mDNSResponder.exe' - '28' Module(s) have been scanned
Scan process 'AppleMobileDeviceService.exe' - '60' Module(s) have been scanned
Scan process 'avguard.exe' - '55' Module(s) have been scanned
Scan process 'Explorer.EXE' - '104' Module(s) have been scanned
Scan process 'svchost.exe' - '34' Module(s) have been scanned
Scan process 'sched.exe' - '45' Module(s) have been scanned
Scan process 'UMVPFSrv.exe' - '17' Module(s) have been scanned
Scan process 'spoolsv.exe' - '72' Module(s) have been scanned
Scan process 'svchost.exe' - '31' Module(s) have been scanned
Scan process 'svchost.exe' - '32' Module(s) have been scanned
Scan process 'svchost.exe' - '30' Module(s) have been scanned
Scan process 'svchost.exe' - '162' Module(s) have been scanned
Scan process 'svchost.exe' - '39' Module(s) have been scanned
Scan process 'svchost.exe' - '53' Module(s) have been scanned
Scan process 'lsass.exe' - '51' Module(s) have been scanned
Scan process 'services.exe' - '27' Module(s) have been scanned
Scan process 'winlogon.exe' - '67' Module(s) have been scanned
Scan process 'csrss.exe' - '12' Module(s) have been scanned
Scan process 'smss.exe' - '2' Module(s) have been scanned
Starting master boot sector scan:
Master boot sector HD0
[INFO] No virus was found!
Master boot sector HD1
[INFO] No virus was found!
Master boot sector HD2
[INFO] No virus was found!
Master boot sector HD3
[INFO] No virus was found!
Master boot sector HD4
[INFO] No virus was found!
Master boot sector HD5
[INFO] No virus was found!
Start scanning boot sectors:
Boot sector 'C:\'
[INFO] No virus was found!
Starting to scan executable files (registry).
The registry was scanned ( '1306' files ).
Starting the file scan:
Begin scan in 'C:\'
C:\Documents and Settings\Jeff\Application Data\Sun\Java\Deployment\cache\6.0\56\28914178-737627e5
[0] Archive type: ZIP
–> rc.class
[DETECTION] Contains recognition pattern of the EXP/2011-3544.DI.1 exploit
–> Dot.class
[DETECTION] Contains recognition pattern of the EXP/2011-3544.DJ.1 exploit
–> ER.class
[DETECTION] Contains recognition pattern of the EXP/3544.CU.1.A exploit
–> rb.class
[DETECTION] Contains recognition pattern of the EXP/CVE-2011-3544.CB exploit
–> lz.class
[DETECTION] Contains recognition pattern of the EXP/2011-3544.DK.1 exploit
–> rd.class
[DETECTION] Contains recognition pattern of the EXP/2011-3544.CR exploit
–> ra.class
[DETECTION] Contains recognition pattern of the EXP/2011-3544.DL.1 exploit
Beginning disinfection:
C:\Documents and Settings\Jeff\Application Data\Sun\Java\Deployment\cache\6.0\56\28914178-737627e5
[DETECTION] Contains recognition pattern of the EXP/2011-3544.DL.1 exploit
[NOTE] The file was moved to the quarantine directory under the name '4465670f.qua'.
End of the scan: Sunday, 13 May 2012 22:21
Used time: 36:36 Minute(s)
The scan has been done completely.
10947 Scanned directories
277991 Files were scanned
7 Viruses and/or unwanted programs were found
0 Files were classified as suspicious
0 files were deleted
0 Viruses and unwanted programs were repaired
1 Files were moved to quarantine
0 Files were renamed
0 Files cannot be scanned
277984 Files not concerned
3954 Archives were scanned
0 Warnings
1 Notes
466928 Objects were scanned with rootkit scan
0 Hidden objects were found
The Avira detections are only warnings about vulnerabilities in an older version of Java that can be exploited. We will update to the newest version later.
Questionable Toolbar/Plugin Uninstall:
Do you use all those toolbars/browser plugins that are installed?
If you would like to remove the Toolbar(s)/Plugin(s), follow these steps:
Click on Start > Control Panel.
Click on Add or Remove Programs.
Select the following from the list:
Ask Toolbar
WeatherBlink
Click the Remove button.
Next
UPDATE MALWAREBYTES' ANTI-MALWARE
——————————————-
I see that you have Malwarebytes' Anti-Malware installed on your computer.
Open Malwarebytes' Anti-Malware.
Select the Update tab.
Click Check for Updates.
Once the updates have been completed, return to the Scanner tab.
Select Perform quick scan, then click Scan.
When the scan is complete, click OK, then Show Results to view the results.
Be sure that everything is checked, and click Remove Selected.
When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
Note: If you receive a notice that some of the items couldn't be removed, and that they have been added to the delete on reboot list, please reboot.
The log can also be found by:
Selecting the Logs tab when the application is started.
Navigating to C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-date (time).txt
Next
ESET ONLINE SCANNER
—————————- I'd like us to scan your machine with ESET OnlineScan
Hold down Control and click on the following link to open ESET OnlineScan in a new window.
ESET OnlineScan
Click the green ESET Online Scanner button.
For alternate browsers only: (Microsoft Internet Explorer users can skip these steps):
Click on Download to download the ESET Smart Installer. Save it to your desktop.
Double click on the esetsmartinstaller_enu.exe icon on your desktop.
Check YES, I accept the Terms of Use.
Click the Start button.
Accept any security warnings from your browser.
Check Scan archives.
Ensure that the option "Remove found threats" is Unchecked.
Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
Push the Start button.
ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
When the scan completes, push List of found threats.
Push Export to text file…, and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply. Note - when ESET doesn't find any threats, no report will be created.