also @ TechSpot: Exploit allows command prompt to launch at Windows 7 login screen

TechSpot

[Solved] Internet speed painfully slow. Other computers in house are much faster

Discussion in 'Virus and Malware Removal' started by michael311, Jan 1, 2012.

  1. Broni Malware Annihilator

  2. michael311 Newcomer, in training

    ComboFix kept warning me that AVG was running even though we have uninstalled it. I have also seen it in other programs. For example, Network Magic reports that I am running AVG.
  3. Broni Malware Annihilator

    Please download SystemLook from one of the links below and save it to your Desktop.
    Download Mirror #1
    Download Mirror #2

    64-bit users go HERE
    • Double-click SystemLook.exe to run it.
    • Vista\Win 7 users:: Right click on SystemLook.exe, click Run As Administrator
    • Copy the content of the following box and paste it into the main textfield:
      Code:
      :filefind
      avg*
      :folderfind
      avg*
      
    • Click the Look button to start the scan.
    • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
    Note: The log can also be found on your Desktop entitled SystemLook.txt
  4. michael311 Newcomer, in training

    Run as Administrator was not an option. I could only run it as current user (emachind/Mom). Here is the log:

    SystemLook 30.07.11 by jpshortstuff
    Log created at 22:41 on 12/01/2012 by Mom
    Administrator - Elevation successful

    ========== filefind ==========

    Searching for "avg*"
    C:\Documents and Settings\Administrator\Desktop\avgrep.txt --a---- 2887 bytes [01:58 12/04/2011] [03:40 12/04/2011] 21A4783DCE47ECDFF18FF0783E709713
    C:\Flash Drive Backup 10-27-2006\McCauley\Visual Basic\Ch 3, 4, and 6 grade program\Avg Score 1.frm --a---- 3898 bytes [13:47 28/10/2006] [16:29 16/10/1997] 0D3F48829F191C585E6E9BD1F5F02C52

    ========== folderfind ==========

    Searching for "avg*"
    No folders found.

    -= EOF =-
  5. Broni Malware Annihilator

    Not much there.

    Possibly some registry leftovers but they're not active so we won't dig there.