Hello and welcome to Techspot.
It appears you`re not running any antivirus or firewall software and your system is badly infected.
All items in your AVG Antispyware log say "No Action Taken". That`s because you haven`t told AVG Antispyware to quarantine it`s results as per the instructions.
See this pictorial guide.
Make sure you follow all the instructions below exactly.
Go to add remove programmes in your control panel and uninstall anything to do with(
if there).
viewpoint
viewpoint toolbar
viewpoint manager
QdrModule
QdrDrive
DriveCleaner 2006 Free
Buffy Engine
Close control panel.
Click start/run and type services.msc into the run box and press the enter key.
When the window appears, maximise it. Double click on the following services(
if there) and select stop if they are running. Set the startup type to disabled. Click apply/ok for each service you disable.
Viewpoint Manager Service
Close the services window.
Open notepad and copy/paste the text in the quote box below into it:
NOTE* make sure to only highlight and copy what is inside the quote box nothing out side of it.
Also ..
Pay particular attention to this :-
Make sure the word File:: is on the first line of the text file you save (no blank line above it, & no space in front of it)
Code:
File::
C:\WINDOWS\system32\sruusxm.dll,nsrxhv
C:\WINDOWS\system32\sruusxm.dll
C:\WINDOWS\system32\ClickToFindandFixErrors_US.ico
C:\WINDOWS\mrofinu72.exe
C:\Program Files\.autoreg
C:\WINDOWS\bwUnin-8.1.1.50-8876480SL.exe
C:\Program Files\ManagedDX.CAB
C:\Program Files\BDANT.cab
C:\Program Files\BDAXP.cab
C:\Program Files\dxnt.cab
C:\Program Files\BDA.cab
C:\Program Files\DirectX.cab
C:\Program Files\dxsetup.exe
C:\Program Files\dsetup32.dll
C:\Program Files\DSETUP.dll
C:\WINDOWS\system32\tvvwa.bak1
C:\WINDOWS\system32\tvvwa.bak2
C:\WINDOWS\system32\tvvwa.ini2
C:\WINDOWS\system32\xcrfsys.dat
C:\WINDOWS\system32\sruusxm.dll
D:\NTGLM7X.sys
C:\DOCUME~1\Owner\LOCALS~1\Temp\Rar$EX00.313
c:\docume~1\0x1af46\applic~1\elsekn~1
Folder::
C:\Program Files\Viewpoint
C:\Program Files\Common Files\{CC8D24A4-044E-1033-0905-030310080001}
C:\Documents and Settings\All Users\Application Data\flag ace stupid data
C:\VundoFix Backups
C:\qoobox
C:\ijji
C:\Program Files\QdrModule
C:\Program Files\QdrDrive
C:\Documents and Settings\Owner\Application Data\ijjigame
C:\Documents and Settings\0x2c9\Application Data\Viewpoint
C:\Documents and Settings\Jest\Application Data\Viewpoint
C:\Program Files\DriveCleaner 2006 Free
C:\Program Files\Common Files\DriveCleaner 2006 Free
C:\Documents and Settings\Owner\Desktop\CheatEngine
C:\Documents and Settings\Owner\Desktop\Ultra_Noob
C:\Program Files\Buffy Engine
C:\Documents and Settings\13\My Documents\Moonlight Engine 1083 + v46 ct + DXWnd
C:\Documents and Settings\Owner\Desktop\Kaspersky_Engine_5[1].3.309
C:\Documents and Settings\Owner\Desktop\Vicious_Engine_5.1
C:\Documents and Settings\Owner\Desktop\JMS Engine
C:\Documents and Settings\Owner\Desktop\Revolution_Engine_6.2_By_SHAK3
C:\Documents and Settings\Owner\Desktop\Akuma Engine
C:\Documents and Settings\Owner\Desktop\SPUCE 2.0
Registry::
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"sruusxm.dll"=-
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"=-
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\awvvt]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\sysfrcx]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\winzdn32]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DriveCleaner 2006 Free]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PAS_Check]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SDR6_Check]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UDC6cw]
Save this as
CFScript.txt
Then drag the CFScript.txt into ComboFix.exe as you see in the screenshot below.
This will start ComboFix again. After reboot, (in case it asks to reboot).
Download and install one antivirus and one firewall programme from the choices below.
AVG free or
Avast antivirus programmes.
Zonealarm Kerio or
Comodo free firewall programmes.
Run the antivirus updates and do a full system scan. Delete whatever is found, including anything placed in the Virus vault/Quarantine.
Post the contents of Combofix.txt in your next reply together with a fresh HJT log and a fresh AVG Antispyware log.
Regards Howard :wave: :wave:
This thread is for the use of iDKMyyBFFJiill only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.