1. Download The Avenger by Swandog46 from
HERE. Save it to your Desktop and extract it.
2. Open notepad and copy/paste the text in the quote box below into it (all except the word QUOTE):
Comments:
***IMPORTANT NOTE: DO NOT MODIFY ANY INFORMATION IN THIS FILE***
***ANY UNSUPERVISED CHANGES TO THIS FILE MAY POTENTIALLY DAMAGE THE WORKINGS OF THE SYSTEM WHEN AVENGER IS RUN***
Files to delete:
C:\WINDOWS\system32\dllcache\OLDE14.tmp
C:\WINDOWS\system32\dllcache\OLDD97.tmp
C:\WINDOWS\system32\dllcache\OLDD49.tmp
C:\WINDOWS\system32\dllcache\OLDCF7.tmp
C:\WINDOWS\system32\dllcache\OLDCA8.tmp
C:\WINDOWS\system32\dllcache\OLDC68.tmp
C:\WINDOWS\system32\dllcache\OLDC2B.tmp
C:\WINDOWS\system32\dllcache\OLDB9E.tmp
C:\WINDOWS\system32\dllcache\OLDB23.tmp
C:\WINDOWS\system32\dllcache\OLDACF.tmp
C:\WINDOWS\system32\dllcache\OLDA6F.tmp
C:\WINDOWS\system32\dllcache\OLDA2A.tmp
C:\WINDOWS\system32\dllcache\OLDA12.tmp
C:\WINDOWS\system32\dllcache\OLD995.tmp
C:\WINDOWS\system32\dllcache\OLD976.tmp
C:\WINDOWS\system32\dllcache\OLD915.tmp
C:\WINDOWS\system32\dllcache\OLD8CA.tmp
C:\WINDOWS\system32\dllcache\OLD87C.tmp
C:\WINDOWS\system32\dllcache\OLD780.tmp
C:\WINDOWS\system32\dllcache\OLD6E1.tmp
C:\WINDOWS\system32\dllcache\OLD6C7.tmp
C:\WINDOWS\system32\dllcache\OLD61D.tmp
C:\WINDOWS\system32\dllcache\OLD5BF.tmp
C:\WINDOWS\system32\dllcache\OLD53A.tmp
C:\WINDOWS\system32\dllcache\OLD4B7.tmp
C:\WINDOWS\system32\dllcache\OLD410.tmp
C:\WINDOWS\system32\dllcache\OLD328.tmp
C:\WINDOWS\system32\dllcache\OLD2B8.tmp
C:\WINDOWS\system32\dllcache\OLD9E.tmp
C:\WINDOWS\system32\dllcache\OLD5A.tmp
C:\Program Files\Uninstall Ask Toolbar.dll
C:\WINDOWS\system32\SSUBTMR6.DLL
Folders to delete:
C:\Program Files\AskTBar
Registry keys to delete:
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1ce47857-8582-11dc-a066-00508d9120a2}
Save this as "avengerscript.txt"
Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.
3. Now, start The Avenger program by double clicking on its icon on your desktop.
Under "Script file to execute" choose "Load script from file".
Now click on the folder icon which will open a new window titled "open Script File"
navigate to the file you have just created, click on it and press open
Now click on the Green Light to begin execution of the script
Answer "Yes" twice when prompted.
4. The Avenger will automatically do the following:
It will Restart your computer. ( In cases where the code to execute contains "Drivers to Unload", The Avenger will actually restart your system twice.)
On reboot, it will briefly open a black command window on your desktop, this is normal.
After the restart, it creates a log file that should open with the results of Avenger’s actions. This log file will be located at C:\avenger.txt
The Avenger will also have backed up all the files, etc., that you asked it to delete, and will have zipped them and moved the zip archives to C:\avenger\backup.zip.
5. Please attach the content of c:\avenger.txt into your reply, as well as a fresh HJT and Combofix log.
Regards,
Your friendly Momok =)