Please help!
Please help!
The log you've made isnt the log we expect to see. Please, read the rules and follow the instructions there.
correct log attached. Thanks!
ugh. SORRY! Here they are!
Why you did not disable your symantec , zonealarm and other "anti" before making our logs? Moreover, using symantec internet security and zonealarm firewall simulteniusly it is too big pressure for the system. You should uninstall both, and choose something one.At least, disable in the symantec firewall completely
Why you did not update the avz itself and system restore is not disabled ? It is briefly explained in the rules...
Now, disable all your anti, and internet connection.
Run this script in avz:
Computer will reboot. This script will change nothing, it just for making a copy of some files.Код:begin SearchRootkit(true, true); SetAVZGuardStatus(True); Clearquarantine; QuarantineFile('D:\WINDOWS\system32\MyCleaner.exe',''); QuarantineFile('D:\WINDOWS\Temp\FrXlhqOR.sys',''); QuarantineFile('D:\WINDOWS\Temp\7s0a64Cc.sys',''); QuarantineFile('D:\Windows\system32\USER32.dll',''); BC_ImportAll; BC_Activate; RebootWindows(true); end.
Now, we need to see them. In order to do that, please execute this script right after reboot:
Upload file C:\quarantine.zip, by link Upload quarantined files in the top of this thread.Код:begin CreateQurantineArchive('C:\quarantine.zip'); end.
Let us know, when you will done!
Последний раз редактировалось drongo; 22.10.2009 в 18:51.
*Нажми и выполни, если хочешь чтобы помощь улучшилась и ускорилась
*MyFirefox Portable
special avz @ rapidshare.com
md5: 2091925798B7909E010E3F7E328C5F0D
alright. disabled antivirus and network connection and ran the scripts. here are the files.
I had installed a few AV programs in an attempt to remove this junk, should have uninstalled when done.
THANKS FOR THE HELP! Not getting anywhere on my own!
Последний раз редактировалось drongo; 22.10.2009 в 20:15.
Are you unable see a red color? Do it as i said, and do not like you want.
*Нажми и выполни, если хочешь чтобы помощь улучшилась и ускорилась
*MyFirefox Portable
special avz @ rapidshare.com
md5: 2091925798B7909E010E3F7E328C5F0D
My apologies. Corrected by uploading to the correct section. SORRY!
What junk do you want to remove? Please describe your problem.
A quarantine was send to antivirus lab. As long as we will get an answer, we will let you know.
Meantime, uninstall all your "anti" collection, because this collection can cause problems, and it is interfering into our detection process. We are hunting anti-virus modules, instead of real viruses.
Then, please make a set of fresh logs and do attach them to next post.
*Нажми и выполни, если хочешь чтобы помощь улучшилась и ускорилась
*MyFirefox Portable
special avz @ rapidshare.com
md5: 2091925798B7909E010E3F7E328C5F0D