Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.
Posted 15 April 2012 - 01:30 PM
Edited by Budapest, 15 April 2012 - 03:03 PM.
Moved from Virus, Trojan, Spyware, and Malware Removal Logs ~Budapest
Posted 15 April 2012 - 07:50 PM
button.
to download the ESET Smart Installer. Save it to your desktop.
button.
and check Remove found threats 
, and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
button.
Posted 17 April 2012 - 09:19 PM
Posted 17 April 2012 - 09:27 PM
Edited by boopme, 17 April 2012 - 09:27 PM.
Posted 17 April 2012 - 09:33 PM
Posted 17 April 2012 - 09:47 PM
17:02:29.0796 2760 Detected object count: 3
17:02:29.0796 2760 Actual detected object count: 3
17:03:06.0968 2760 C:\WINDOWS\system32\g400.dll - copied to quarantine
17:03:06.0984 2760 HKLM\SYSTEM\ControlSet001\services\atiavaiw - will be deleted on reboot
17:03:07.0015 2760 HKLM\SYSTEM\ControlSet002\services\atiavaiw - will be deleted on reboot
17:03:07.0062 2760 C:\WINDOWS\system32\g400.dll - will be deleted on reboot
17:03:07.0062 2760 atiavaiw ( Backdoor.Multi.ZAccess.gen ) - User select action: Delete
17:03:07.0390 2760 C:\WINDOWS\system32\DRIVERS\netbt.sys - copied to quarantine
17:03:07.0687 2760 C:\WINDOWS\$NtUninstallKB17157$\745893744\@ - copied to quarantine
17:03:07.0687 2760 C:\WINDOWS\$NtUninstallKB17157$\745893744\cfg.ini - copied to quarantine
17:03:07.0687 2760 C:\WINDOWS\$NtUninstallKB17157$\745893744\Desktop.ini - copied to quarantine
17:03:07.0734 2760 C:\WINDOWS\$NtUninstallKB17157$\745893744\L\gsdjoqpu - copied to quarantine
17:03:07.0734 2760 C:\WINDOWS\$NtUninstallKB17157$\745893744\oemid - copied to quarantine
17:03:07.0734 2760 C:\WINDOWS\$NtUninstallKB17157$\745893744\U\00000001.@ - copied to quarantine
17:03:07.0828 2760 C:\WINDOWS\$NtUninstallKB17157$\745893744\U\00000002.@ - copied to quarantine
17:03:07.0843 2760 C:\WINDOWS\$NtUninstallKB17157$\745893744\U\00000004.@ - copied to quarantine
17:03:07.0921 2760 C:\WINDOWS\$NtUninstallKB17157$\745893744\U\80000000.@ - copied to quarantine
17:03:07.0937 2760 C:\WINDOWS\$NtUninstallKB17157$\745893744\U\80000004.@ - copied to quarantine
17:03:07.0953 2760 C:\WINDOWS\$NtUninstallKB17157$\745893744\U\80000032.@ - copied to quarantine
17:03:07.0968 2760 C:\WINDOWS\$NtUninstallKB17157$\745893744\version - copied to quarantine
17:03:12.0921 2760 Backup copy found, using it..
17:03:13.0046 2760 C:\WINDOWS\system32\DRIVERS\netbt.sys - will be cured on reboot
17:03:30.0906 2760 C:\WINDOWS\$NtUninstallKB17157$\4118572428 - will be deleted on reboot
17:03:30.0906 2760 C:\WINDOWS\$NtUninstallKB17157$\745893744\@ - will be deleted on reboot
17:03:30.0906 2760 C:\WINDOWS\$NtUninstallKB17157$\745893744\cfg.ini - will be deleted on reboot
17:03:30.0906 2760 C:\WINDOWS\$NtUninstallKB17157$\745893744\Desktop.ini - will be deleted on reboot
17:03:30.0921 2760 C:\WINDOWS\$NtUninstallKB17157$\745893744\oemid - will be deleted on reboot
17:03:30.0921 2760 C:\WINDOWS\$NtUninstallKB17157$\745893744\U\00000001.@ - will be deleted on reboot
17:03:30.0921 2760 C:\WINDOWS\$NtUninstallKB17157$\745893744\U\00000002.@ - will be deleted on reboot
17:03:30.0921 2760 C:\WINDOWS\$NtUninstallKB17157$\745893744\U\00000004.@ - will be deleted on reboot
17:03:30.0921 2760 C:\WINDOWS\$NtUninstallKB17157$\745893744\U\80000000.@ - will be deleted on reboot
17:03:30.0921 2760 C:\WINDOWS\$NtUninstallKB17157$\745893744\U\80000004.@ - will be deleted on reboot
17:03:30.0921 2760 C:\WINDOWS\$NtUninstallKB17157$\745893744\U\80000032.@ - will be deleted on reboot
17:03:30.0921 2760 C:\WINDOWS\$NtUninstallKB17157$\745893744\version - will be deleted on reboot
17:03:30.0921 2760 NetBT ( Virus.Win32.ZAccess.k ) - User select action: Cure
17:03:30.0984 2760 C:\WINDOWS\system32\Pnp680r.dll - copied to quarantine
17:03:30.0984 2760 HKLM\SYSTEM\ControlSet001\services\oracle_load_balancer_60_client-forms6ip9 - will be deleted on reboot
17:03:31.0000 2760 HKLM\SYSTEM\ControlSet002\services\oracle_load_balancer_60_client-forms6ip9 - will be deleted on reboot
17:03:31.0859 2760 C:\WINDOWS\system32\Pnp680r.dll - will be deleted on reboot
17:03:31.0859 2760 oracle_load_balancer_60_client-forms6ip9 ( Backdoor.Multi.ZAccess.gen ) - User select action: Delete
17:04:51.0562 2704 Deinitialize success
Posted 17 April 2012 - 10:51 PM
Posted 17 April 2012 - 10:54 PM
Posted 18 April 2012 - 07:50 PM
> Control Panel, double-click on Add/Remove Programs or Programs and Features in Vista/Windows 7 and remove all older versions of Java.0 members, 0 guests, 0 anonymous users