Still checking
Still checking
Scanning. Will post results when it is done.
Ok.
Ok I ran kaspersky & it found an infected installation file. I know where it is & I renamed it to a txt file. Should I delete it? It is called InstallAVg_77090406.exe & it is in the "downloads" folder. I told the program to save the log but it never saved it. I tried several times in several locations but it never showed up in the folder even though the save as window showed it there.So I thought perhaps it created the file after the program is closed. I did do a scan of the file which it didn't.
So what now? What did you find out? Is it safe to delete the file?
Last edited by townsbg; 07-07-2010 at 04:03 AM.
If it's in downloads folder, it should be safe to delete.
I assume, it was the only file found by Kaspersky?
If so, I found another one through AVZ.
I'd like to deal with it, since you can't run any other security scans (Dr.Web, AVP, etc.)
CREATE FRESH RESTORE POINT!
- Close all windows then double click on AVZ.exe
- Click File > Custom scripts
- Running script window will open
- Copy & paste the contents of the following codebox in the Running script window
Code:begin SearchRootkit(true, true); SetAVZPMStatus(True); SetAVZGuardStatus(True); BC_DeleteFile('C:\Windows\system32\DRIVERS\ndisrd.sys'); BC_ImportDeletedList; ExecuteSysClean; BC_Activate; RebootWindows(true); end.- Note: When you run the script, your PC will be restarted
- Click Run
- Restart your PC if it doesn't do it automatically, and post back with a new AVZ and HijackThis logs.
All that did was to mess up my internet so I reverted to a restore point. Unfortunatly I had to revert to the RP before the second run of combofix since I forgot to create one before running your script. We really haven't done much since then. AVZ still didn't run in normal mode afterwords. I'm attaching the logs anyway. This is becoming a saga. I hope that there is in end in sight for you because I don't see one & I'm getting tired of it.
HJT:
Last edited by townsbg; 07-07-2010 at 03:53 AM.
OK. I'm not sure what's going on here.
HJT log looks perfectly clean, Kaspersky discovered just one item, which you renamed.
Are you having problems with running any other programs?
Well remember I had to revert to a restore point & that HJT is before I did that but you didn't see anything in the last one either. As for programs on this computer I've really only ran the scanners & IE because it isn't mine. I'll try other random programs and get back to you. Perhaps I should try an SFC. The installation files are on a secondary partition I think so will a retail Vista do if SFC needs it?
![]()
Usually Vista doesn't ask for DVD, so you can try it. Maybe, we're not dealing with any infection anymore, but there is something wrong with Windows itself.