[Resolved] Personal Antivirus

  1. #61
    broni is offline Senior Member

    re: [Resolved] Personal Antivirus

    Still checking


  2. #62
    townsbg is offline Senior Member
    Scanning. Will post results when it is done.

  3. #63
    broni is offline Senior Member
    Ok.

  4. #64
    townsbg is offline Senior Member
    Ok I ran kaspersky & it found an infected installation file. I know where it is & I renamed it to a txt file. Should I delete it? It is called InstallAVg_77090406.exe & it is in the "downloads" folder. I told the program to save the log but it never saved it. I tried several times in several locations but it never showed up in the folder even though the save as window showed it there. So I thought perhaps it created the file after the program is closed. I did do a scan of the file which it didn't. So what now? What did you find out? Is it safe to delete the file?
    Last edited by townsbg; 07-07-2010 at 04:03 AM.

  5. #65
    broni is offline Senior Member
    If it's in downloads folder, it should be safe to delete.
    I assume, it was the only file found by Kaspersky?
    If so, I found another one through AVZ.
    I'd like to deal with it, since you can't run any other security scans (Dr.Web, AVP, etc.)

    CREATE FRESH RESTORE POINT!

    • Close all windows then double click on AVZ.exe
    • Click File > Custom scripts
    • Running script window will open
    • Copy & paste the contents of the following codebox in the Running script window

      Code:
      begin
      SearchRootkit(true, true);
      SetAVZPMStatus(True);
      SetAVZGuardStatus(True);
       BC_DeleteFile('C:\Windows\system32\DRIVERS\ndisrd.sys');
      BC_ImportDeletedList;
      ExecuteSysClean;
      BC_Activate;
      RebootWindows(true);
      end.
    • Note: When you run the script, your PC will be restarted
    • Click Run
    • Restart your PC if it doesn't do it automatically, and post back with a new AVZ and HijackThis logs.

  6. #66
    townsbg is offline Senior Member
    All that did was to mess up my internet so I reverted to a restore point. Unfortunatly I had to revert to the RP before the second run of combofix since I forgot to create one before running your script. We really haven't done much since then. AVZ still didn't run in normal mode afterwords. I'm attaching the logs anyway. This is becoming a saga. I hope that there is in end in sight for you because I don't see one & I'm getting tired of it.
    HJT:
    Last edited by townsbg; 07-07-2010 at 03:53 AM.

  7. #67
    broni is offline Senior Member
    OK. I'm not sure what's going on here.
    HJT log looks perfectly clean, Kaspersky discovered just one item, which you renamed.
    Are you having problems with running any other programs?

  8. #68
    townsbg is offline Senior Member
    Well remember I had to revert to a restore point & that HJT is before I did that but you didn't see anything in the last one either. As for programs on this computer I've really only ran the scanners & IE because it isn't mine. I'll try other random programs and get back to you. Perhaps I should try an SFC. The installation files are on a secondary partition I think so will a retail Vista do if SFC needs it?

  9. #69
    broni is offline Senior Member
    Usually Vista doesn't ask for DVD, so you can try it. Maybe, we're not dealing with any infection anymore, but there is something wrong with Windows itself.

  10. #70
    broni is offline Senior Member
    Save 20% on AVG Internet Security 2012 Suite!
    I'm ready to go to bed. My schedule for tomorrow is pretty much same as for today.

+ Reply to Thread
Page 7 of 9 FirstFirst 1 2 3 4 5 6 7 8 9 LastLast