-
im having trouble getting rid of the iexplore.exe virus, ive found some other threads in various places trying to get rid of the virus and none of them have worked for me, my lasat suggestion was to download the kaspersky virus removal tool, which i did, and i ran the autoscan feature, but half way through each time it freezes up and i have wait for nearly an hour for it to come back with no success, so i guess ill ask you guysto gimme a hand in trying to get rid of the virus, the problem itself is in my task manager it is always running iexplore.exe even when i am not and it has seemed to block my malware and virus protection programs. and the methods i have tried from the internet have not picked it up
thank you for your time
i forgot to attach my log file, here it is
-
Execute this script in AVPTool:
[CODE]begin
SetAVZPMStatus(True);
RebootWindows(true);
end.[/CODE]
Make a new log of AVPTool.
-
i did what you told me to now here is my new log
-
Switch off/Disable:
- Antivirus and and, if you have - Firewall.
- System Restore
- [URL="http://virusinfo.info/showthread.php?t=9207"]Execute following script[/URL] in Manual Cure
[CODE]begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
ClearQuarantine;
QuarantineFile('C:\DOCUME~1\HANDSO~1\LOCALS~1\Temp\twunk_32x.exe','');
QuarantineFile('\systemroot\system32\drivers\H8SRTwnnpyrdscn.sys','');
DeleteFileMask('\systemroot\system32\drivers\','H8SRT*.sys',true);
DeleteFileMask('C:\DOCUME~1\HANDSO~1\LOCALS~1\Temp\','*.*',true);
RegKeyParamDel('HKEY_USERS','S-1-5-21-3764035220-1479113233-1939366156-1006\Software\Microsoft\Windows\CurrentVersion\Run','twunk_32x.exe');
BC_ImportAll;
ExecuteSysClean;
BC_Activate;
SetAVZPMStatus(True);
RebootWindows(true);
end.[/CODE]
After reboot [URL="http://virusinfo.info/showthread.php?t=9207"]execute following script[/URL] in Manual Cure
[code]begin
CreateQurantineArchive('C:\quarantine.zip');
end.
[/code]and upload the C:\quarantine.zip over the link [COLOR="Red"][B]Upload quarantined files[/B][/COLOR] on the top of this page.
- Clean Temp-Maps, Cache of Browsers, Recycler. Use Windows service tool [URL="http://support.microsoft.com/?scid=kb%3Ben-us%3B315246&x=17&y=6"]cleanmgr[/URL] or [URL="http://www.ccleaner.com/"]CCleaner[/URL] or [URL="http://www.clearprog.de/"]ClearProg[/URL]
- Close all the programs and start only Internet Explorer!!!
- Repeat a log file of AVPTool.
- Make a log file with Hijackthis ([URL="http://virusinfo.info/showthread.php?t=9184"] Analysis, p.3 [/URL] for further informations).
- Make a log file with GMER ([URL="http://virusinfo.info/showthread.php?t=51878"] read here [/URL] for further informations).
- Switch Antivirus and, if you have - Firewall, on.
- Go On-Line
- Attach 3 logs to your new post..
-
Hope this is what you needed
-
1. Please, disable System Restore and antivirus (if you have).
2. Execute this script in AVPTool:
[CODE]begin
SetAVZGuardStatus(True);
DeleteFileMask(GetAVZDirectory+'Quarantine', '*.*', true);
DelBHO('{710EB7A1-45ED-11D0-924A-0020AFC7AC4D}');
QuarantineFile('C:\WINDOWS\system32\gebyv.dll','');
DeleteFile('C:\WINDOWS\system32\gebyv.dll');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\gebyv','DLLName');
BC_ImportDeletedList;
ExecuteSysClean;
ExecuteRepair(1);
BC_Activate;
RebootWindows(true);
end.[/CODE]
3. After reboot execute this script in AVPTool:
[CODE]begin
CreateQurantineArchive('C:\quarantine.zip');
end.[/CODE]
Upload file C:\quarantine.zip, by link [url]http://virusinfo.info/upload_virus.php?tid=67150[/url]
4. [URL="http://virusinfo.info/showpost.php?p=512824&postcount=2"]Execute commands in Gmer:[/URL]
[CODE]8uxvwmjx.exe -del service H8SRTd.sys
8uxvwmjx.exe -del file "c:\windows\system32\drivers\H8SRTwnnpyrdscn.sys"
8uxvwmjx.exe -del file "c:\windows\system32\H8SRToxkaritmkj.dll"
8uxvwmjx.exe -del file "c:\windows\system32\H8SRTarunsofxon.dat"
8uxvwmjx.exe -del file "c:\windows\system32\H8SRTqolkbtghmj.dll"
8uxvwmjx.exe -del file "c:\windows\system32\H8SRTauulsqbqly.dll"
8uxvwmjx.exe -del file "c:\windows\system32\H8SRTvmrohkqfix.dll"
8uxvwmjx.exe -del reg "HKLM\SYSTEM\CurrentControlSet\Services\H8SRTd.sys"
8uxvwmjx.exe -del reg "HKLM\SYSTEM\ControlSet004\Services\H8SRTd.sys"
8uxvwmjx.exe -reboot[/CODE]
5. [URL="http://virusinfo.info/showthread.php?t=9206"]Fix in HijackThis:[/URL]
[QUOTE]O20 - Winlogon Notify: gebyv - C:\WINDOWS\system32\gebyv.dll (file missing)[/QUOTE]
6. Make new logs: avptool_sysinfo, hijackthis + gmer.
-
Вложений: 2
heres what you asked for, since ive been trying to fix this ive gotten a few fatal error blue screens now and i can only run in safe mode
-
[QUOTE]GMER 1.0.15.15281 - [url]http://www.gmer.net[/url]
[COLOR="SeaGreen"]Rootkit scan 2010-01-15 13:53:46[/COLOR]
Windows 5.1.2600 Service Pack 3
Running: 8uxvwmjx.exe; Driver: C:\DOCUME~1\HANDSO~1\LOCALS~1\Temp\ugldypow.sys[/QUOTE]
[QUOTE]GMER 1.0.15.15281 - [url]http://www.gmer.net[/url]
[COLOR="Red"]Rootkit quick scan 2010-01-19 00:34:15[/COLOR]
Windows 5.1.2600 Service Pack 3
Running: jlr69xws.exe; Driver: C:\DOCUME~1\HANDSO~1\LOCALS~1\Temp\ugldypow.sys[/QUOTE]
It's not correct. Make a full scan with Gmer.
-
Итог лечения
Статистика проведенного лечения:
[LIST][*]Получено карантинов: [B]2[/B][*]Обработано файлов: [B]7[/B][*]В ходе лечения обнаружены вредоносные программы:
[LIST=1][*] c:\windows\system32\drivers\h8srtwnnpyrdscn.sys - [B]Packed.Win32.TDSS.aa[/B][/LIST][/LIST]
Page generated in 0.00820 seconds with 10 queries