also @ TechSpot: First Qualcomm Snapdragon 800 benchmarks hit the web

System check virus and lost monitor signal

Discussion in 'Virus and Malware Removal' started by meadow, Jan 4, 2012.

Post New Reply
  1. meadow Newcomer, in training Posts: 83

    I got system check virus like others on 12/30/2011. I was browsing the internet and suddenly I got a bunch of pop-up windows saying somthing along the lines of "Failed to save all the components for the file \\System32\\########## ... This error may be caused by a PC hardware problem" then a program called system check opened up and ask me to scan my computer and I cannot closed it. then it give a list of error on my computer like # of harddisk error, # Ram error... I lost everything on my desktop, start up menu and menu bar. I disconnect my PC from network right way.
    I goggled and before I found this forum, followed a suggestion to unhide folders and files, then rename a .exe file under application folder. then restart the PC, but I would get the pop up windows ( more than 20 of them ), I can close them one by one, but they would show up again and system check up window would open up again. I click stop button to stop it "running", but I cannot close it, I repeated unhiding the file and folder and renaming .exe then restart the pc, no use, and after a while, my monitor went blank ( showing enter power saving mode), I think I lost monitor signal. I cannot bring it back by enter ctrl+alt+del. I have to shut down pc by push the power button. So I checked micorsoft site for help. It suggests to run Safety Scanner. so I download it to a USB memory stick. Today, I power up my pc, then did unhide, rename .exe file then I ran the Safety Scanner for full scan. But after a few minute, my monitor went blank again. I don't know what virus will do to my PC if i leave it running for long time, so I shut down the pc by push the button. I found this forum now. But it looks like I cannot run any scan software for a while. What can I do? Please help. I am totally new to this virus world.
  2. Broni Malware Annihilator Posts: 40,077   +187

    Welcome aboard [IMG]

    Please, observe following rules:
    • Read all of my instructions very carefully. Your mistakes during cleaning process may have very serious consequences, like unbootable computer.
    • If you're stuck, or you're not sure about certain step, always ask before doing anything else.
    • Please refrain from running tools or applying updates other than those I suggest.
    • Never run more than one scan at a time.
    • Keep updating me regarding your computer behavior, good, or bad.
    • The cleaning process, once started, has to be completed. Even if your computer appears to act better, it may still be infected. Once the computer is totally clean, I'll certainly let you know.
    • If you leave the topic without explanation in the middle of a cleaning process, you may not be eligible to receive any more help in malware removal forum.
    • I close my topics if you have not replied in 5 days. If you need more time, simply let me know. If I closed your topic and you need it to be reopened, simply PM me.

    ================================================================

    Start with following these instructions: http://www.bleepingcomputer.com/virus-removal/remove-system-check

    Let me know when done.
  3. meadow Newcomer, in training Posts: 83

    can I run Rkill, TDSSKiller, mbam-setup off line?

    I am really scared I guess.
    I download Rkill, tdssKiller and mbam-setup through another computer to a USB memory stick. Can I run them without connecting to network? I am afraid to bring the virus to the network. if yes, do I have to move them to my desktop to run?
    If I cannot finish all the steps in one day, should I start it? or I can stop at middle and continue the next day? then can I shut down the computer?
    Thank you so much for your help.
  4. Broni Malware Annihilator Posts: 40,077   +187

    Yes, you don't have to be connected.
    MBAM obviously won't update but that's fine for now.

    We can do this in a span of several days. Don't worry about it.
  5. meadow Newcomer, in training Posts: 83

    I started my computer in normal mode without connectting to network.
    I followed the instruction of "Automated removal instructions for system check using Malwarebytes' Anti-Malware", ran Rkill and TDSSKiller from USB flash drive. after reboot ( step 6), the system check was still running on my pc. but I continured to try step 9 to run mbam-setup.exe from USB flash drive. at Step 10, I get error message from Malwarebytes' Anti-Malware: "An error has occurred. Please report this error code to our support team. Program_Error_Update ( 11004,0, No address found). The requested name is valid & was found in database, but it doesnot have the correct associated data being resolved. "
    then another message box pop-up "database is 126 days out of date. want to update?" I click no, since I downloaded last night. then get another message window " you intrudued trial version of Anti-Malware..." I clicked No again. then it seemed did step 11-16 as instructions. But after it reboot by itself, and I logged in, the "system check" still running, and it seems MBAM is not running to continue the rest of the steps as mentioned at step 16.
    Did I do something wrong?
  6. Broni Malware Annihilator Posts: 40,077   +187

    Please download ComboFix from Here or Here to your Desktop.

    **Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**
    1. Please, never rename Combofix unless instructed.
    2. Close any open browsers.
    3. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
      • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
      • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
      NOTE1. If Combofix asks you to install Recovery Console, please allow it.
      NOTE 2. If Combofix asks you to update the program, always do so.
      • Close any open browsers.
      • WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
      • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
      • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.
    4. Double click on combofix.exe & follow the prompts.
    5. When finished, it will produce a report for you.
    6. Please post the "C:\ComboFix.txt"
    **Note 1: Do not mouseclick combofix's window while it's running. That may cause it to stall
    **Note 2 for AVG and CA Internet Security users: ComboFix will not run until AVG/CA Internet Security is uninstalled as a protective measure against the anti-virus. This is because AVG/CA Internet Security "falsely" detects ComboFix (or its embedded files) as a threat and may remove them resulting in the tool not working correctly which in turn can cause "unpredictable results". Since AVG/CA Internet Security cannot be effectively disabled before running ComboFix, the author recommends you to uninstall AVG/CA Internet Security first.
    Use AppRemover to uninstall it: http://www.appremover.com/
    We can reinstall it when we're done with CF.

    **Note 3: If you receive an error "Illegal operation attempted on a registery key that has been marked for deletion", restart computer to fix the issue.



    Make sure, you re-enable your security programs, when you're done with Combofix.

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

    NOTE.
    If, for some reason, Combofix refuses to run, try one of the following:

    1. Run Combofix from Safe Mode (How to...)

    2. Delete Combofix file, download fresh one, but rename combofix.exe to yourname.exe BEFORE saving it to your desktop.
    Do NOT run it yet.

    Please download and run the below tool named Rkill (courtesy of BleepingComputer.com) which may help allow other programs to run.

    There are 4 different versions. If one of them won't run then download and try to run the other one.

    Vista and Win7 users need to right click Rkill and choose Run as Administrator

    You only need to get one of these to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.

    Rkill.com
    Rkill.scr
    Rkill.exe

    • Double-click on the Rkill desktop icon to run the tool.
    • If using Vista or Windows 7 right-click on it and choose Run As Administrator.
    • A black DOS box will briefly flash and then disappear. This is normal and indicates the tool ran successfully.
    • If not, delete the file, then download and use the one provided in Link 2.
    • If it does not work, repeat the process and attempt to use one of the remaining links until the tool runs.
    • Do not reboot until instructed.
    • If the tool does not run from any of the links provided, please let me know.

    Once you've gotten one of them to run, immediately run your_name.exe by double clicking on it.

    If normal mode still doesn't work, run BOTH tools from safe mode.

    In case #2, please post BOTH logs, rKill and Combofix.

    DO NOT make any other changes to your computer (like installing programs, using other cleaning tools, etc.), until it's officially declared clean!!!
     
  7. meadow Newcomer, in training Posts: 83

    How can I find out if there is anti virus or anti malware programs running on my computer? I didn't install / config my pc, I have no idea what was installed on it and I cannot see task manager now.
    Thanks.
  8. Broni Malware Annihilator Posts: 40,077   +187

    Run Combofix from safe mode and disregard any Combofix warnings.
  9. meadow Newcomer, in training Posts: 83

    post log files.

    Here is c:\rkill.log:
    This log file is located at C:\rkill.log.
    Please post this only if requested to by the person helping you.
    Otherwise you can close this log when you wish.

    Rkill was run on 01/05/2012 at 10:41:46.
    Operating System: Microsoft Windows XP


    Processes terminated by Rkill or while it was running:

    C:\WINDOWS\system32\userinit.exe
    C:\Documents and Settings\All Users\Application Data\gyjAEPulVY.exe
    C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe
    C:\Documents and Settings\All Users\Application Data\3Tit7aJpHkTsZk.exe


    Rkill completed on 01/05/2012 at 10:43:00.
    Please post this only if requested to by the person helping you.
    Otherwise you can close this log when you wish.

    Rkill was run on 01/06/2012 at 10:11:48.
    Operating System: Microsoft Windows XP


    Processes terminated by Rkill or while it was running:


    Rkill completed on 01/06/2012 at 10:11:50.

    -----------------------------------
    Here is log c:\Combofix.txt
    -----------------------------------

    ComboFix 12-01-05.04 - ip0xc3 01/06/2012 10:32:32.1.2 - x86
    Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2014.1607 [GMT -5:00]
    Running from: c:\documents and settings\IP0XC3\Desktop\ComboFix.exe
    .
    .
    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    c:\documents and settings\Administrator\WINDOWS
    c:\documents and settings\All Users\Application Data\3Tit7aJpHkTsZk
    c:\documents and settings\All Users\Application Data\3Tit7aJpHkTsZk.exe
    c:\documents and settings\All Users\Application Data\c6qkZh1pW4u7fP
    c:\documents and settings\All Users\Application Data\c6qkZh1pW4u7fP.vir
    c:\documents and settings\All Users\Application Data\gyjAEPulVY.exe
    c:\documents and settings\All Users\Application Data\ysEPkrxEHeHk2n
    c:\documents and settings\All Users\Application Data\ysEPkrxEHeHk2n.vir
    c:\documents and settings\IP0XC3\Desktop\System Check.lnk
    c:\documents and settings\IP0XC3\Start Menu\Programs\System Check\System Check.lnk
    c:\documents and settings\IP0XC3\Start Menu\Programs\System Check\Uninstall System Check.lnk
    c:\windows\$NtUninstallKB30827$
    c:\windows\$NtUninstallKB30827$\1756827868\@
    c:\windows\$NtUninstallKB30827$\1756827868\cfg.ini
    c:\windows\$NtUninstallKB30827$\1756827868\Desktop.ini
    c:\windows\$NtUninstallKB30827$\1756827868\L\qyjlhyes
    c:\windows\$NtUninstallKB30827$\2951771945
    c:\windows\AutoRun.ini
    .
    .
    ((((((((((((((((((((((((( Files Created from 2011-12-06 to 2012-01-06 )))))))))))))))))))))))))))))))
    .
    .
    2012-01-05 16:01 . 2012-01-05 16:01 -------- d-----w- c:\documents and settings\IP0XC3\Application Data\Malwarebytes
    2012-01-05 16:00 . 2012-01-05 16:00 -------- d--h--w- c:\documents and settings\All Users\Application Data\Malwarebytes
    2012-01-05 16:00 . 2012-01-05 16:46 -------- d--h--w- c:\program files\Malwarebytes' Anti-Malware
    2012-01-05 16:00 . 2011-08-31 22:00 22216 ---ha-w- c:\windows\system32\drivers\mbam.sys
    .
    .
    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2012-01-05 15:52 . 2011-05-02 16:52 456320 ---ha-w- c:\windows\system32\drivers\mrxsmb.sys
    .
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "SetGrammaticaLicense"="c:\windows\system32\gl.vbs" [2009-08-03 486]
    "PinAInfo"="c:\windows\system32\ai.vbs" [2009-09-04 922]
    "SetDefaultPrinter"="c:\windows\system32\dp.vbs" [2010-09-20 398]
    "SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2010-01-08 1044480]
    "GPUpdate"="c:\windows\system32\gpupdate.exe" [2008-08-11 57344]
    "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
    "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-04-08 254696]
    "McAfeeUpdaterUI"="c:\program files\McAfee\Common Framework\udaterui.exe" [2011-06-08 333120]
    .
    c:\documents and settings\All Users\Start Menu\Programs\Startup\
    VPN Client.lnk - c:\windows\Installer\{51FB15F4-AD27-43BC-AD4B-DD0354FB6BBD}\Icon3E5562ED7.ico [2011-9-15 6144]
    Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "dontdisplaylockeduserid"= 1 (0x1)
    .
    [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
    "{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-436374069-789336058-682003330-538188\Scripts\Logon\0\0]
    "Script"=firefox_login.vbs
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-436374069-789336058-682003330-538189\Scripts\Logon\0\0]
    "Script"=firefox_login.vbs
    .
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
    "EnableFirewall"= 0 (0x0)
    .
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "%windir%\\system32\\sessmgr.exe"=
    "c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
    "c:\\Program Files\\McAfee\\Common Framework\\FrameworkService.exe"=
    "c:\\EVN\\BIN\\evn.exe"=
    .
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "5985:TCP"= 5985:TCP:*:Disabled:Windows Remote Management
    .
    R0 megasas;megasas;c:\windows\system32\drivers\megasas.sys [5/2/2011 10:23 AM 17664]
    R0 vmscsi;vmscsi;c:\windows\system32\drivers\vmscsi.sys [5/2/2011 10:23 AM 10880]
    R2 iftlsnr;InfraTools Remote Control Listener;c:\progra~1\PEREGR~1\INFRAT~1\bin\iftlsnr.exe -svc --> c:\progra~1\PEREGR~1\INFRAT~1\bin\iftlsnr.exe -svc [?]
    R2 JuniperAccessService;Juniper Unified Network Service;c:\program files\Common Files\Juniper Networks\JUNS\dsAccessService.exe [11/12/2009 8:59 PM 132392]
    R2 ldlcserv6;IBM Enterprise Extender (IPv6);c:\windows\system32\drivers\ldlcserv6.exe [3/3/2011 10:57 AM 40960]
    R2 pdlndldl6;IBM Enterprise Extender (HPR/IPv6);c:\windows\system32\drivers\pdlndldl6.sys [3/3/2011 10:57 AM 72704]
    S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [3/18/2010 12:16 PM 130384]
    S3 csrcmds;csrcmds;c:\program files\IBM\Personal Communications\csrcmds.exe [3/3/2011 10:54 AM 49152]
    S3 cstrcser;IBM Command Line Trace;c:\windows\system32\drivers\cstrcser.exe [3/3/2011 10:57 AM 36864]
    S3 e1kexpress;Intel(R) PRO/1000 PCI Express Network Connection Driver K;c:\windows\system32\drivers\e1k5132.sys [5/2/2011 11:49 AM 168616]
    S3 iftrcdrv;InfraTools Remote Control Driver;c:\progra~1\PEREGR~1\INFRAT~1\bin\iftrcdrv.sys [5/2/2011 9:41 AM 6097]
    S3 MBAMSwissArmy;MBAMSwissArmy;\??\c:\windows\system32\drivers\mbamswissarmy.sys --> c:\windows\system32\drivers\mbamswissarmy.sys [?]
    S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [5/2/2011 11:52 AM 14336]
    S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [3/18/2010 12:16 PM 753504]
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
    WINRM REG_MULTI_SZ WINRM
    .
    .
    ------- Supplementary Scan -------
    .
    uStart Page = hxxp://www.google.com/
    mStart Page = hxxp://sdolintranet:81/
    IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
    TCP: DhcpNameServer = 10.72.126.59 10.72.126.26
    .
    - - - - ORPHANS REMOVED - - - -
    .
    HKLM-Run-gyjAEPulVY.exe - c:\documents and settings\All Users\Application Data\gyjAEPulVY.exe
    SafeBoot-23570721.sys
    .
    .
    .
    **************************************************************************
    .
    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2012-01-06 10:36
    Windows 5.1.2600 Service Pack 3 NTFS
    .
    scanning hidden processes ...
    .
    scanning hidden autostart entries ...
    .
    scanning hidden files ...
    .
    scan completed successfully
    hidden files: 0
    .
    **************************************************************************
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------
    .
    - - - - - - - > 'winlogon.exe'(956)
    c:\windows\system32\Ati2evxx.dll
    c:\windows\system32\atiadlxx.dll
    .
    - - - - - - - > 'explorer.exe'(2660)
    c:\windows\system32\WININET.dll
    c:\program files\Windows Desktop Search\deskbar.dll
    c:\program files\Windows Desktop Search\en-us\dbres.dll.mui
    c:\program files\Windows Desktop Search\dbres.dll
    c:\program files\Windows Desktop Search\wordwheel.dll
    c:\program files\Windows Desktop Search\en-us\msnlExtRes.dll.mui
    c:\program files\Windows Desktop Search\msnlExtRes.dll
    c:\windows\system32\msi.dll
    c:\windows\system32\ieframe.dll
    c:\program files\McAfee\Common Framework\McTrayLegacySupportPlugin.dll
    c:\program files\McAfee\Common Framework\McTrayInterfaceLib.dll
    c:\program files\McAfee\Common Framework\McAfeeWin32GUISupportDLL.dll
    c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.3053_x-ww_b80fa8ca\MSVCR80.dll
    c:\windows\system32\WPDShServiceObj.dll
    c:\windows\system32\PortableDeviceTypes.dll
    c:\windows\system32\PortableDeviceApi.dll
    .
    ------------------------ Other Running Processes ------------------------
    .
    c:\windows\system32\Ati2evxx.exe
    c:\windows\system32\Ati2evxx.exe
    c:\windows\system32\Drivers\trcboot.exe
    c:\program files\IBM\Personal Communications\PCS_AGNT.EXE
    c:\program files\Cisco Systems\VPN Client\cvpnd.exe
    c:\progra~1\PEREGR~1\INFRAT~1\bin\iftlsnr.exe
    c:\program files\Java\jre6\bin\jqs.exe
    c:\program files\McAfee\Common Framework\FrameworkService.exe
    c:\program files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
    c:\program files\CDBurnerXP\NMSAccessU.exe
    c:\windows\system32\Drivers\ldlcserv.exe
    c:\windows\system32\SearchIndexer.exe
    c:\windows\system32\CCM\CcmExec.exe
    c:\program files\McAfee\Common Framework\naPrdMgr.exe
    c:\program files\IBM\Personal Communications\tpam.exe
    c:\windows\system32\msiexec.exe
    c:\program files\McAfee\Common Framework\McTray.exe
    c:\windows\system32\SearchProtocolHost.exe
    c:\windows\system32\SearchFilterHost.exe
    .
    **************************************************************************
    .
    Completion time: 2012-01-06 10:38:20 - machine was rebooted
    ComboFix-quarantined-files.txt 2012-01-06 15:38
    .
    Pre-Run: 144,637,313,024 bytes free
    Post-Run: 144,797,515,776 bytes free
    .
    WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
    [boot loader]
    timeout=2
    default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
    [operating systems]
    c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
    UnsupportedDebug="do not select this" /debug
    multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows" /noexecute=optin /fastdetect
    .
    - - End Of File - - 50FEE7748A23CB9FF2B5ACCAB67B7292


    Thank you very much.
  10. Broni Malware Annihilator Posts: 40,077   +187

    Good.

    Restart in normal mode.
    See if you can update and run Malwarebytes.
  11. meadow Newcomer, in training Posts: 83

    No.
    I ran twice. 1st time from the icon on my desktop ( which was created yesterday). I got two message box, "access denied" then " set up was not completed".
    2nd time I run from the USB flash drive, I got "the data base updated to V2012.01.06.03", then continue to install, and I got the "access denied" and "set up was not completed" like 1st time..
  12. Broni Malware Annihilator Posts: 40,077   +187

    Download aswMBR to your desktop.
    Double click the aswMBR.exe to run it.
    If you see this question: Would you like to download latest Avast! virus definitions?" say "Yes".
    Click the "Scan" button to start scan.
    On completion of the scan click "Save log", save it to your desktop and post in your next reply.

    NOTE. aswMBR will create MBR.dat file on your desktop. This is a copy of your MBR. Do NOT delete it.
  13. meadow Newcomer, in training Posts: 83

    I forgot to mention that the "system check" icon reappread on Quick Launch bar again.
  14. meadow Newcomer, in training Posts: 83

    Here is the log after run aswMBR.exe

    aswMBR version 0.9.9.1156 Copyright(c) 2011 AVAST Software
    Run date: 2012-01-06 12:27:04
    -----------------------------
    12:27:04.367 OS Version: Windows 5.1.2600 Service Pack 3
    12:27:04.367 Number of processors: 2 586 0xF0B
    12:27:04.367 ComputerName: SHERRYG12PC UserName: ip0xc3
    12:27:06.458 Initialize success
    12:29:51.403 AVAST engine defs: 12010600
    12:30:01.086 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-7
    12:30:01.086 Disk 0 Vendor: ST3160318AS CC45 Size: 152587MB BusType: 3
    12:30:01.101 Disk 0 MBR read successfully
    12:30:01.101 Disk 0 MBR scan
    12:30:01.133 Disk 0 Windows 7 default MBR code
    12:30:01.148 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 152578 MB offset 16065
    12:30:01.148 Disk 0 scanning sectors +312496380
    12:30:01.211 Disk 0 scanning C:\WINDOWS\system32\drivers
    12:30:07.860 Service scanning
    12:30:09.008 Modules scanning
    12:30:13.566 Disk 0 trace - called modules:
    12:30:13.582 ntkrnlpa.exe CLASSPNP.SYS disk.sys atapi.sys hal.dll pciide.sys PCIIDEX.SYS
    12:30:13.582 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8a3dbab8]
    12:30:13.582 3 CLASSPNP.SYS[ba178fd7] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP2T0L0-7[0x8a381b00]
    12:30:15.248 AVAST engine scan C:\WINDOWS
    12:30:22.541 AVAST engine scan C:\WINDOWS\system32
    12:31:29.157 AVAST engine scan C:\WINDOWS\system32\drivers
    12:31:38.035 AVAST engine scan C:\Documents and Settings\IP0XC3
    12:31:41.950 File: C:\Documents and Settings\IP0XC3\Application Data\Sun\Java\Deployment\cache\6.0\63\7748147f-47c4410e **INFECTED** Win32:Karagany-EJ [Trj]
    12:31:56.928 AVAST engine scan C:\Documents and Settings\All Users
    12:32:03.991 Scan finished successfully
    12:32:25.053 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\IP0XC3\My Documents\MBR.dat"
    12:32:25.053 The log file has been saved successfully to "C:\Documents and Settings\IP0XC3\My Documents\aswMBR.txt"
    --------------------------
    the end of then report.


    and MBR.dat is under c:\Documents and Settings\IP0XC3\My Documents should I move it to desktop?
  15. Broni Malware Annihilator Posts: 40,077   +187

    You can delete that file. MBR looks good.

    1. Uninstall Malwarebytes' Anti-Malware using Add/Remove programs in the control panel.
    2. Restart your computer (very important).
    3. Download and run this utility.
    4. It will ask to restart your computer (please allow it to).
    5. After the computer restarts, install the latest version from here.

    See, if it'll update and run now.
  16. meadow Newcomer, in training Posts: 83

    I was asked "You have introducted a trial of full version of the product, would you like to start the trial". should I click "decline" or "start trial" while doing step 5
  17. Broni Malware Annihilator Posts: 40,077   +187

    Start trial.
  18. meadow Newcomer, in training Posts: 83

    It runs. Here is the log file:

    Malwarebytes Anti-Malware (Trial) 1.60.0.1800
    www.malwarebytes.org

    Database version: v2012.01.06.03

    Windows XP Service Pack 3 x86 NTFS
    Internet Explorer 7.0.5730.13
    ip0xc3 :: SHERRYG12PC [administrator]

    Protection: Enabled

    1/6/2012 1:32:11 PM
    mbam-log-2012-01-06 (13-32-11).txt

    Scan type: Full scan
    Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
    Scan options disabled: P2P
    Objects scanned: 236940
    Time elapsed: 20 minute(s), 28 second(s)

    Memory Processes Detected: 0
    (No malicious items detected)

    Memory Modules Detected: 0
    (No malicious items detected)

    Registry Keys Detected: 0
    (No malicious items detected)

    Registry Values Detected: 0
    (No malicious items detected)

    Registry Data Items Detected: 0
    (No malicious items detected)

    Folders Detected: 0
    (No malicious items detected)

    Files Detected: 6
    C:\Qoobox\Quarantine\C\Documents and Settings\All Users\Application Data\3Tit7aJpHkTsZk.exe.vir (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    C:\Qoobox\Quarantine\C\Documents and Settings\All Users\Application Data\c6qkZh1pW4u7fP.vir.vir (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    C:\Qoobox\Quarantine\C\Documents and Settings\All Users\Application Data\gyjAEPulVY.exe.vir (Rogue.FakeHDD) -> Quarantined and deleted successfully.
    C:\Qoobox\Quarantine\C\Documents and Settings\All Users\Application Data\ysEPkrxEHeHk2n.vir.vir (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{5DFDFB86-31DD-4E93-854D-670000144448}\RP1\A0000086.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{5DFDFB86-31DD-4E93-854D-670000144448}\RP1\A0000087.exe (Rogue.FakeHDD) -> Quarantined and deleted successfully.

    (end)

    but the infected file mentioned in aswMBR log file is not deleted:
    -------------------
    12:31:41.950 File: C:\Documents and Settings\IP0XC3\Application Data\Sun\Java\Deployment\cache\6.0\63\7748147f-47c4410e **INFECTED** Win32:Karagany-EJ [Trj]
    -------------------
  19. Broni Malware Annihilator Posts: 40,077   +187

    How is computer doing at the moment?

    1. Please open Notepad (Start>All Programs>Accessories>Notepad).

    2. Now copy/paste the entire content of the codebox below into the Notepad window:

    Code:
    File::
    C:\Documents and Settings\IP0XC3\Application Data\Sun\Java\Deployment\cache\6.0\63\7748147f-47c4410e
    
    ClearJavaCache::
    

    3. Save the above as CFScript.txt

    4. Close/disable all anti virus and anti malware programs again, so they do not interfere with the running of ComboFix.

    5. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

    [IMG]


    6. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
    • Combofix.txt
  20. meadow Newcomer, in training Posts: 83

    My computer looks much better now. I haven't really try it yet, some menu itms still look "not right".
    I will not be able to work on it for a couple of days. I will report back once I have something new.
    Thank you.