
03-02-2012 08:38 AM - edited 03-02-2012 09:15 AM
OK..lets get the reverse way.If combofix doesnt run even after many tries in safe mode please follow this
Download AVPTool from Here to your desktop
(You have to enter your e-mail address and click on Submit Form button. Please download latest English version of this tool)
Run the programme you have just downloaded to your desktop (it will be randomly named )
First we will run a virus scan
Click the cog in the upper right 
Select down to and including your main drive, once done select the Automatic scan tab and press Start Scan
(Please be patient as this scan can take a long long hours)
Allow AVP to disinfect all infections found [delete if disinfection not possible]
Once it has finished select report tab (last tab)
Select Detected threats report from the left and press Save button
Save it to your desktop and attach to your next post
Now the Analysis
Rerun VRT and select the Manual Disinfection tab and press Start Gathering System Information 
On completion click the link to locate the zip file to upload and attach to your next post 
03-02-2012 11:24 AM
Heres the Kaspersky scan...
03-02-2012
11:36 AM
- last edited on
03-02-2012
02:13 PM
by
ornahp
and final kaspersky zip log..
[Mod Note: .zip file removed - please see Trend Participation Guidelines]
03-02-2012 12:37 PM
just out of curiosity, is this going to take care of things? already seems better... also can i reinstall trend micro without infecting things again? just got it not that long ago.... also, any clue why my audio has dissappeared after all of this? none at all, not even standard bells and whistles...
03-02-2012 03:08 PM
any info. on how to get my audio back up and running? seems the scans for malware have rendered the drivers inoperable...
03-02-2012 09:17 PM - edited 03-02-2012 10:04 PM
Hi can u please try and run combofix in safe mode and attach the log as some important drivers are missing and combofix will replace them also please upload sysinfo zip file to www.mediafire.com and post the sharing link on next reply.
also see here: http://www.mediafire.com/faq.php
03-06-2012 03:08 PM
Back again, sorry for the delay...... heres the link...http://www.mediafire.com/?ezgp9fufpquxsk6... also I dont know what the deal with combo fix is... no matter how I use it (safe mode or not) it never finishes scanning.... just says it detects ROOTKIT... really would like to get this machine going again... works worse now than with the gremlins...
03-06-2012 09:17 PM - edited 03-06-2012 10:04 PM
Hi we have to kill whatever is alive anthen try combofix to get the infection out...
begin
SetAVZGuardStatus(True);
SearchRootkit(true, true);
DeleteFile('C:\WINDOWS\System32\Drivers\dump_atapi .sys');
DeleteFile('C:\WINDOWS\System32\Drivers\dump_WMILI B.SYS');
DeleteFile('C:\DOCUME~1\Bill\LOCALS~1\Temp\128.tmp ');
DeleteFile('C:\Documents and Settings\Bill\Local Settings\temp\_uninst_77177826.bat');
DeleteFile('C:\Documents and Settings\All Users\Application Data\privacy.exe');
DeleteFile('C:\WINDOWS\system32\savscan.dll');
DeleteFile('\SystemRoot\system32\DRIVERS\1081806dr v.sys');
end.NEXT
Please post:
All RKreport logs located on your desktop.
Delete the current combofix from desktop and download a fresh version from here
rename combofix to winlogon.exe and then try running it.
and attach the log
03-06-2012 10:46 PM - edited 03-06-2012 10:47 PM
If combofix again fails to run we will start it in special way...We will use force breach mode of combofix
Running Combofix from Run Command
--------------------
-> Run -> copy/paste in the following single line command into the run box and click OK.03-07-2012 06:20 AM
heres the updated scan...http://www.mediafire.com/?2acx8dmd8ox987b btw, rogue killer link doesnt work either..
Copyright (c) 1989-2012 Trend Micro Incorporated. All rights reserved.
