8 steps and still some problems

Status
Not open for further replies.

vexon13

Posts: 10   +0
So about 2 days ago it was discovered that there was a trojan running around my home network infecting my computer and that of my siblings.

so we all cleaned out our machines, all of them got cleaned accept mine.

the program that I (we actually) started using before I found this site was the old Avg Free rootkit software. Ive included its log file as an attachment

unfortunately it was unable to remove the rootkit on my machine. it finds a "hidden driver file " type root kit and after a reboot claims to of gotten rid of it but it just shows up again in the search.

none of the other malware or anti virus programs seem to pick it up, Although malwarebytes picked up another virus I had on my machine.

ive run all the software numerous times now but it still shows up.

the only weird thing that ive noticed is that there are a few files I am finding in places I did not leave them. And they are rather large files.

I would really like to not format this machine its used for video rendering/editing and other stuff.
Gaming is on hold until I can get this thing clean.
So yah.

P.s. First post
 

Attachments

  • hijackthis.log
    8.9 KB · Views: 6
  • mbam-log-2009-04-20 (21-50-21).txt
    861 bytes · Views: 5
Hi vexon13

I recommend you uninstall your AVG Free8 Antivirus
Run the AVGRemove Tool

"AVG Free does not contain Anti-Rootkit protection so rootkits may be hidden in your system."

Reboot.

Install Avira Free AntiVirus, from here ->
Avira

Or: Avast

Install, update it, run a complete systemscan.

Reboot.

Please download Combofix:
http://subs.geekstogo.com/ComboFix.exe

And save to the desktop.

Open notepad and copy/paste the text in the quotebox below into it:
Name the file as CFScript
and Save it on the desktop

Killall::

Snapshot::

File::
C:\WINDOWS\System32\Drivers\awffbxva.SYS
C:\WINDOWS\System32\Drivers\agkwxi3d.SYS
C:\WINDOWS\System32\Drivers\ar75akbg.SYS

http://www.fromsej.saknet.dk/billeder/cfscript.gif

Once saved, refering to the picture above, drag CFScript.txt into ComboFix.exe, Combofix will create a logfile and display it after your computer has rebooted. Usually located in c:\combofix.txt, please attach it to your next post

Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall
 
Touch, first thanks for the reply but i did not use the removal tool for Avg.

Should i be ok if i uninstalled Avg using the uninstall that came with the installation or should i use that app as well. Because yesterday i uninstalled avg and loaded Avira.

?? ?
P.s. im currently waiting on the complete scan because i forgot to do it so combo fix is going to have to wait a bit. actually im probably going to get back to you later today i have to go to work : ' ( .
 
If you have Avg8 in add/remove programs in controlpanel, it should okay to uninstall it from there, because I don´t trust their own uninstaller :(
 
Status
Not open for further replies.
Back