
02-22-2012 03:53 PM
Yes still have popups
02-22-2012 09:35 PM
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
TerminateProcessByName('c:\program files (x86)\conceiva\mezzmo\mezzmomediaserver.exe');
TerminateProcessByName('c:\program files (x86)\lexmark 8300 series\lxcjmon.exe');
TerminateProcessByName('lxcjcoms.exe');
TerminateProcessByName('c:\program files (x86)\outlook messenger\outlookmessenger.exe');
DeleteService('is3srv');
DeleteFile('c:\Program Files (x86)\Common Files\iS3\Anti-Spyware\SZServer.exe');
DeleteFile('C:\Users\Robert\AppData\Local\Temp\_un inst_87574724.bat');
end.
02-24-2012
02:54 PM
- last edited on
02-24-2012
05:26 PM
by
ornahp
Here is the log. Script did not run very smooth. It locked up the computer.
edited to remove .zip file.
02-24-2012 09:09 PM
Hi the zip file was removed by moderator can u please upload the zip file here:
and post the sharing link on next reply.
02-25-2012 10:48 AM
02-25-2012 08:46 PM
begin
SetAVZPMStatus(True);
SearchRootkit(true, true);
SetAVZGuardStatus(True);
QuarantineFile('c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe','');
QuarantineFile('HPHC_Service.exe','');
DeleteFile('c:\Program Files (x86)\Common Files\iS3\Anti-Spyware\SZServer.exe');
DeleteFile('C:\Users\Robert\AppData\Local\Temp\_un inst_91409298.bat');
end.02-28-2012 04:40 PM
Sorry it took so long to get back. Ran the script but still have popups.
02-28-2012 08:18 PM
Hi we need to run frst again....
Note: Please don't run any scanner or cleaner or making any change after the system booted or you may loose some files or folders.
Open notepad (Start =>All Programs => Accessories => Notepad). Please copy the entire contents of the code box below. (To do this highlight the contents of the box, right click on it and select copy. Right-click in the open notepad and select Paste). Save it on the flashdrive as fixlist.txt
Start HKU\daddy\...\Run: [SpywareTerminatorUpdate] "C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorUpdate.exe" [x] c:\Program Files (x86)\Common Files\iS3\Anti-Spyware\SZServer.exe end.
NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system
Now please enter System Recovery Options.
Run FRST and press the Fix button just once and wait.
The tool will make a log on the flashdrive (Fixlog.txt) please post it to your reply.
NEXT
Download OTL to your Desktop.
http://www.geekstogo.com/forum/files/file/398-otl-
netsvcs
%SYSTEMDRIVE%\*.exe
/md5start
consrv.dll
explorer.exe
winlogon.exe
Userinit.exe
svchost.exe
netbt.sys
atapi.sys
volsnap.sys
redbook.sys
lsi_sas.sys
lsi_scsi.sys
cdrom*
tcpip.sys
/md5stop
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\servic
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\servic
hklm\software\clients\startmenuinternet|command /rs
hklm\software\clients\startmenuinternet|command /64 /rs
C:\Windows\assembly\tmp\U\*.* /s
%Temp%\smtmp\1\*.*
%Temp%\smtmp\2\*.*
%Temp%\smtmp\3\*.*
%Temp%\smtmp\4\*.*
CREATERESTOREPOINT
02-29-2012 05:16 PM
These are the only logs the programs created.
02-29-2012 07:11 PM
I think I found it. I did a complete clean of Firefox. Took out all toolbars and have not had a cpv popup for an hour or so. Will keep trying to see if i can get a popup. This is very strange because I have not installed any toolbars for about a year.
Copyright (c) 1989-2012 Trend Micro Incorporated. All rights reserved.
