Sorry!
Computer is doing great at the moment, just gonna remove AVG now!
Blue screen of death-Simple Fix?
#17
Posted 24 September 2011 - 06:35 PM
alwarebytes' Anti-Malware 1.51.2.1300
www.malwarebytes.org
Database version: 7792
Windows 6.0.6002 Service Pack 2
Internet Explorer 8.0.6001.19048
25/09/2011 00:35:10
mbam-log-2011-09-25 (00-35-10).txt
Scan type: Quick scan
Objects scanned: 191647
Time elapsed: 5 minute(s), 39 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 2
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 1
Files Infected: 3
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\$XNTUninstall643$ (Adware.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MICORSOFT_WINDOWS_SERVICE (Trojan.Agent) -> Quarantined and deleted successfully.
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
c:\Windows\$xntuninstall643$ (Adware.AdRotator) -> Quarantined and deleted successfully.
Files Infected:
c:\Windows\Temp\wpbt0.dll (Exploit.Drop) -> Quarantined and deleted successfully.
c:\Windows\$xntuninstall643$\apuninstall.exe (Adware.AdRotator) -> Quarantined and deleted successfully.
c:\Windows\$xntuninstall643$\zrpt.xml (Adware.AdRotator) -> Quarantined and deleted successfully.
www.malwarebytes.org
Database version: 7792
Windows 6.0.6002 Service Pack 2
Internet Explorer 8.0.6001.19048
25/09/2011 00:35:10
mbam-log-2011-09-25 (00-35-10).txt
Scan type: Quick scan
Objects scanned: 191647
Time elapsed: 5 minute(s), 39 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 2
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 1
Files Infected: 3
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\$XNTUninstall643$ (Adware.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MICORSOFT_WINDOWS_SERVICE (Trojan.Agent) -> Quarantined and deleted successfully.
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
c:\Windows\$xntuninstall643$ (Adware.AdRotator) -> Quarantined and deleted successfully.
Files Infected:
c:\Windows\Temp\wpbt0.dll (Exploit.Drop) -> Quarantined and deleted successfully.
c:\Windows\$xntuninstall643$\apuninstall.exe (Adware.AdRotator) -> Quarantined and deleted successfully.
c:\Windows\$xntuninstall643$\zrpt.xml (Adware.AdRotator) -> Quarantined and deleted successfully.
#18
Posted 24 September 2011 - 08:19 PM
Good news then 
Last scans...
Download Temp File Cleaner (TFC)
Double click on TFC.exe to run the program.
Click on Start button to begin cleaning process.
TFC will close all running programs, and it may ask you to restart computer.
=============================================================================
Please run a free online scan with the ESET Online Scanner
Last scans...
Download Temp File Cleaner (TFC)
Double click on TFC.exe to run the program.
Click on Start button to begin cleaning process.
TFC will close all running programs, and it may ask you to restart computer.
=============================================================================
Please run a free online scan with the ESET Online Scanner
- Disable your antivirus program
- Tick the box next to YES, I accept the Terms of Use
- Click Start
- Accept any security warnings from your browser.
- Check Scan archives
- Click Start
- ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
- When the scan completes, push List of found threats
- Click on Export to text file , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
#19
Posted 25 September 2011 - 08:02 AM
Hi
I am doing the ESET scan, it is 1 hour 40 mins in at the moment, already found 5 trojans. Will post here when the scan is complete!
I am doing the ESET scan, it is 1 hour 40 mins in at the moment, already found 5 trojans. Will post here when the scan is complete!
#20
Posted 25 September 2011 - 08:30 AM
Ok here is the ESET log
C:\Users\John\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\54\5945d2f6-495ed5ca Java/TrojanDownloader.Agent.NBU trojan deleted - quarantined
C:\Users\John\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\63\2fbb37bf-33ff7365 Java/Exploit.CVE-2009-2843.B trojan deleted - quarantined
C:\Users\John\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\7\589e5d87-7878f7f6 multiple threats deleted - quarantined
C:\Windows\System32\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\33\21d74661-5ff30f39 a variant of Java/Agent.DO trojan deleted - quarantined
C:\Windows\Temp\eeedmy\setup.exe a variant of Win32/Kryptik.TDZ trojan cleaned by deleting (after the next restart) - quarantined
C:\Users\John\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\54\5945d2f6-495ed5ca Java/TrojanDownloader.Agent.NBU trojan deleted - quarantined
C:\Users\John\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\63\2fbb37bf-33ff7365 Java/Exploit.CVE-2009-2843.B trojan deleted - quarantined
C:\Users\John\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\7\589e5d87-7878f7f6 multiple threats deleted - quarantined
C:\Windows\System32\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\33\21d74661-5ff30f39 a variant of Java/Agent.DO trojan deleted - quarantined
C:\Windows\Temp\eeedmy\setup.exe a variant of Win32/Kryptik.TDZ trojan cleaned by deleting (after the next restart) - quarantined
#21
Posted 25 September 2011 - 10:12 AM
Your computer is clean 
1. We need to reset system restore to prevent your computer from being accidentally reinfected by using some old restore point(s). We'll remove all old restore points and create fresh, clean restore point.
Turn system restore off.
Restart computer.
Turn system restore back on.
If you don't know how to do it...
Windows XP: http://support.microsoft.com/kb/310405
Vista and Windows 7: http://www.howtogeek.com/howto/windows-vista/disable-system-restore-in-windows-vista/
2. Make sure, Windows Updates are current.
3. Download, and install WOT (Web OF Trust): http://www.mywot.com/. It'll warn you (in most cases) about dangerous web sites.
4. Run Malwarebytes "Quick scan" once in a while to assure safety of your computer.
5. Run Temporary File Cleaner (TFC) weekly.
6. Download and install Secunia Personal Software Inspector (PSI): http://secunia.com/vulnerability_scanning/personal/. The Secunia PSI is a FREE security tool designed to detect vulnerable and out-dated programs and plug-ins which expose your PC to attacks. Run it weekly.
7. (optional) If you want to keep all your programs up to date, download and install FileHippo Update Checker.
The Update Checker will scan your computer for installed software, check the versions and then send this information to FileHippo.com to see if there are any newer releases.
8. When installing\updating ANY program, make sure you always select "Custom " installation, so you can UN-check any possible "drive-by-install" (foistware), like toolbars etc., which may try to install along with the legitimate program. Do NOT click "Next" button without looking at any given page.
9. Read How did I get infected?, With steps so it does not happen again!: http://www.bleepingcomputer.com/forums/topic2520.html
10. Except for MBAM and TFC, which are keepers you can simply delete all other tools we used as they don't install.

1. We need to reset system restore to prevent your computer from being accidentally reinfected by using some old restore point(s). We'll remove all old restore points and create fresh, clean restore point.
Turn system restore off.
Restart computer.
Turn system restore back on.
If you don't know how to do it...
Windows XP: http://support.microsoft.com/kb/310405
Vista and Windows 7: http://www.howtogeek.com/howto/windows-vista/disable-system-restore-in-windows-vista/
2. Make sure, Windows Updates are current.
3. Download, and install WOT (Web OF Trust): http://www.mywot.com/. It'll warn you (in most cases) about dangerous web sites.
4. Run Malwarebytes "Quick scan" once in a while to assure safety of your computer.
5. Run Temporary File Cleaner (TFC) weekly.
6. Download and install Secunia Personal Software Inspector (PSI): http://secunia.com/vulnerability_scanning/personal/. The Secunia PSI is a FREE security tool designed to detect vulnerable and out-dated programs and plug-ins which expose your PC to attacks. Run it weekly.
7. (optional) If you want to keep all your programs up to date, download and install FileHippo Update Checker.
The Update Checker will scan your computer for installed software, check the versions and then send this information to FileHippo.com to see if there are any newer releases.
8. When installing\updating ANY program, make sure you always select "Custom " installation, so you can UN-check any possible "drive-by-install" (foistware), like toolbars etc., which may try to install along with the legitimate program. Do NOT click "Next" button without looking at any given page.
9. Read How did I get infected?, With steps so it does not happen again!: http://www.bleepingcomputer.com/forums/topic2520.html
10. Except for MBAM and TFC, which are keepers you can simply delete all other tools we used as they don't install.
#22
Posted 25 September 2011 - 03:50 PM
Thank you very much for your help has saved me £50!
Thanks ever so much!
Thanks ever so much!
#23
Posted 25 September 2011 - 04:15 PM
You're very welcome

Help


Back to top










