
02-24-2012 11:31 PM - edited 02-24-2012 11:33 PM
Did u disinfect or delete whenever AVP Asked?
OK.can u run the manual disinfection process and upload the zip file to www.mediafire.com
Then post sharing link on next reply.
02-24-2012 11:35 PM
I was choosing disinfect but all of them were saying it could not be done and I was unsure what had to be done and I was deleting.
02-24-2012 11:37 PM
thats fine.just run manual disinfection and upload the zip file to www.mediafire.com and post the sharing link on next reply.
02-25-2012 12:34 AM - edited 02-25-2012 12:38 AM
Heres link to log
02-25-2012 12:40 AM
begin
RegKeyIntParamWrite('HKEY_LOCAL_MACHINE', 'System\CurrentControlSet\Services\CDROM','AutoRun ', 0);
SetServiceStart('SSDPSRV', 4);
SetServiceStart('TlntSvr', 4);
SetServiceStart('TermService', 4);
SetServiceStart('RemoteRegistry', 4);
SetAVZGuardStatus(True);
SearchRootkit(true, true);
DeleteFile('C:\Documents and Settings\Administrator\Local Settings\temp\_uninst_25531443.bat');
DeleteFile('C:\WINDOWS\system32\DRIVERS\2845243drv .sys');
DeleteFile('\SystemRoot\system32\DRIVERS\2845243dr v.sys');
RebootWindows(true);
end.
02-25-2012 12:52 AM
I still haven't closed AVP program since it finished running the other scan, do I close the program and re open to do the script execution you told me or it doesnt matter?
02-25-2012 12:59 AM
Doesnt matter at all...Better to re run
02-25-2012 01:25 AM - edited 02-25-2012 01:29 AM
Link to log, By the way Thank you so much for the time you are dedicating to my problem ![]()
02-25-2012 01:32 AM
Monitoring..will be back in 5 minutes.
02-25-2012 01:38 AM
begin
SetAVZGuardStatus(True);
SearchRootkit(true, true);
DeleteFile('C:\Documents and Settings\Administrator\Local Settings\temp\_uninst_01428593.bat');
DeleteFile('\SystemRoot\system32\DRIVERS\2845243dr v.sys');
DeleteFile('C:\WINDOWS\system32\DRIVERS\2845243drv .sys');
end.NEXT
Please download Malwarebytes' Anti-Malware from Here
Double Click mbam-setup.exe to install the application.
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediately.
NEXT
•Hold down Control and click on the following link to open ESET OnlineScan in a new window.
ESET OnlineScan
•Click the
button.
•For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
•Check ![]()
•Click the
button.
•Accept any security warnings from your browser.
•Check ![]()
•Push the Start button.
•ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
•When the scan completes, push ![]()
•Push
, and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
•Push the
button.
•Push ![]()
A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt
Copyright (c) 1989-2012 Trend Micro Incorporated. All rights reserved.
