
02-13-2012
06:31 PM
- last edited on
02-13-2012
06:35 PM
by
JSMO
In my security box- my web threats keeps escalating. It keeps scrolling up and up. It says the viruses and spyware have been stopped but the web threats keep going up and now are over 300,000. I can't get it 2 stop. I've tried everthing I can. My computer even has trouble when I use Google. It seems like something is running even when I am not on the internet. Any one else have the same problem?
02-13-2012 09:03 PM - edited 02-13-2012 09:27 PM
Welcome aboard! ![]()
I would need some logs to analyze first....
Please post:
All RKreport logs located on your desktop.
NEXT
Download OTL to your Desktop.
http://www.geekstogo.com/forum/files/file/398-otl-
netsvcs
%SYSTEMDRIVE%\*.exe
/md5start
consrv.dll
explorer.exe
netbt.sys
atapi.sys
volsnap.sys
redbook.sys
lsi_sas.sys
lsi_scsi.sys
cdrom*
tcpip.sys
winlogon.exe
Userinit.exe
svchost.exe
/md5stop
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\servic
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\servic
C:\Windows\assembly\tmp\U\*.* /s
C:\Program Files\Common Files\ComObjects\*.* /s
CREATERESTOREPOINT
NEXT
Download aswmbr.exe ( 1.8mb ) to your desktop.
http://public.avast.com/~gmerek/aswMBR.htm
Double click the aswMBR.exe to run it Click the "Scan" button to start scan.

Click the [Scan] button to start scan

On completion of the scan click [Save log], save it to your desktop and post in your next reply.
02-14-2012 09:19 AM
I will do when I get home from work. It is up to 370,000 and took off 3 more viruses/spyware. Should I take any thing off my computer before I do this?
02-14-2012 09:20 AM
No just follow my instructions directly.
02-14-2012 02:06 PM
02-14-2012 02:08 PM
02-14-2012 02:48 PM
OTL files
02-14-2012 03:05 PM
aswmbr file
This is the last 1 u need.
The web threats are at 450,000 now
02-14-2012 04:36 PM
The virus that keeps popping up is
TROJ_FAKEAV.SMUZ
The web threat that keeps coming up (every second) is
x-web.in/Y2x8MS42fGFIMGZINTQzZGI4O...
02-14-2012 04:53 PM
I Google some thing it brings me to GimmeAnswers
I hit the back arrow from there it goes to BestMarkStore? with the following:
Warning: mysql_connect() [function.mysql-connect]: Unknown MySQL server host 'localhos' (1) in /home/bestmarkstore.com/us/ss_usrii/results.php on line 78
I back arrow again it brings me to the page I clicked on the Google page
None of this makes sense
Copyright (c) 1989-2012 Trend Micro Incorporated. All rights reserved.
