Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Trojan Avkill


  • Please log in to reply
6 replies to this topic

#1 Raf_MacDonald

Raf_MacDonald

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:10:08 PM

Posted 28 October 2007 - 01:55 PM

Hi, I was recommended to these forums by a friend who said I may be able to get some help.

About a week and a half ago I started noticing a weird pop-up that would say I needed to buy spy ware and would send me to a website called avsystemcare, when I went to my control panel to remove the program I noticed that it was missing. I mean I couldn't access it and it wasn't there. I tried the other accounts on my computer to no avail and came to the conclusion that I had a nasty virus that has taken away my admin powers. I ran norton and it identified it but was unable to remove it. I searched some websites for some help and had a few suggestions to try going into safe mode and removing it from there. I did go into safe mode but again couldn't access my control panel, beyond that I'm not the most computer savvy so I decided to search out help instead of ruining my computer anymore. if someone could possibly help me that would be great

thanks in advance

-Raf MacDonald

BC AdBot (Login to Remove)

 


#2 buddy215

buddy215

  • Moderator
  • 13,196 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:West Tennessee
  • Local time:08:08 PM

Posted 28 October 2007 - 05:11 PM

Rogue Remover lists AVSystemCare as one of the programs it will remove.
http://www.malwarebytes.org/index.php

Follow up with Super Antispyware Free
Install Super Antispyware free. Run it in safe mode. Allow it to quarantine whatever it finds.
http://www.superantispyware.com/

This program may come in handy, too.
http://www.sergiwa.com/en/modules/mydownlo...cid=2&lid=1

Post a Hijack This Log in the Hijack This Forum by following the directions in the link below if the programs above have not removed ALL malware. DO NOT post a log in this forum. http://www.bleepingcomputer.com/forums/t/34773/preparation-guide-for-use-before-using-malware-removal-tools-and-requesting-help/

How to Start Windows in Safe Mode:
http://www.bleepingcomputer.com/tutorials/how-to-start-windows-in-safe-mode/

Edited by buddy215, 28 October 2007 - 06:31 PM.

“Every atom in your body came from a star that exploded and the atoms in your left hand probably came from a different star than your right hand. It really is the most poetic thing I know about physics...you are all stardust.”Lawrence M. Krauss
A 1792 U.S. penny, designed in part by Thomas Jefferson and George Washington, reads “Liberty Parent of Science & Industry.”

#3 quietman7

quietman7

    Bleepin' Janitor


  • Global Moderator
  • 51,485 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:09:08 PM

Posted 28 October 2007 - 06:06 PM

It appears you may be dealing with more than one infection here. After running RogueRemover and SUPERAntispyware do this:

Download RatsCheddar.zip and save it to your desktop. It is a Policy Controller program written by Rathat to remove certain restrictions on XP systems often disabled by malware.
  • Extract (unzip) the file to the desktop. (Click here for information on how to do this if not sure.)
  • Double-click on RatsCheddar.exe to launch the tool.
  • Select Enable for everything listed, then click Exit.
  • Restart your computer.
Warning: This program was developed for Windows XP ONLY. Do not run this program in any other Operating System.

Please download ATF Cleaner by Atribune & save it to your desktop. DO NOT use yet.
Please download Dr.Web CureIt & save it to your desktop. DO NOT perform a scan yet.

Reboot your computer in SAFE MODE" using the F8 method. To do this, restart your computer and after hearing your computer beep once during startup (but before the Windows icon appears) press the F8 key repeatedly. A menu will appear with several options. Use the arrow keys to navigate and select the option to run Windows in "Safe Mode".

Double-click ATF-Cleaner.exe to run the program.
  • Under Main "Select Files to Delete" choose: Select All.
  • Click the Empty Selected button.
  • If you use Firefox browser click Firefox at the top and choose: Select All
  • Click the Empty Selected button.
    If you would like to keep your saved passwords, please click No at the prompt.
  • If you use Opera browser click Opera at the top and choose: Select All
  • Click the Empty Selected button.
    If you would like to keep your saved passwords, please click No at the prompt.
  • Click Exit on the Main menu to close the program.
Note: On Vista, "Windows Temp" is disabled. To empty "Windows Temp" ATF-Cleaner must be "Run as an Administrator".

Scan with Dr.Web CureIt as follows:
  • Double-click on cureit.exe to start the program. (ignore any prompts to update or check for a new version)
  • When the Dr.Web opens, an "Express Scan of your PC" notice will appear.
  • Under "Start the Express Scan Now", Click "OK" to start. This is a short scan that will scan the files currently running in memory and when something is found, click the Yes button when it asks you if you want to cure it.
  • Once the short scan has finished, Click Options > Change settings
  • Choose the "Scan tab" and UNcheck "Heuristic analysis"
  • Back at the main window, click "Select drives" (a red dot will show which drives have been chosen)
  • Then click the "Start/Stop Scanning" button (green arrow on the right) and the scan will start.
  • When done, a message will be displayed at the bottom advising if any viruses were found.
  • Click "Yes to all" if it asks if you want to cure/move the file.
  • When the scan has finished, look if you can see the icon next to the files found. If so, click it, then click the next icon right below and select "Move incurable".
    (This will move it to the C:\Documents and Settings\userprofile\DoctorWeb\Quarantine folder if it can't be cured)
  • Next, in the Dr.Web CureIt menu on top, click file and choose save report list.
  • Save the DrWeb.csv report to your desktop. (You can use Notepad to open the DrWeb.cvs report)
  • Exit Dr.Web Cureit when done.
  • Important! Reboot your computer because it could be possible that files in use will be moved/deleted during reboot.
  • After reboot, post the contents of the log from Dr.Web in your next reply.

.
.
Windows Insider MVP 2017-2018
Microsoft MVP Reconnect 2016
Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif

#4 Raf_MacDonald

Raf_MacDonald
  • Topic Starter

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:10:08 PM

Posted 01 November 2007 - 05:50 PM

Hi, sorry I took so long in a reply its been a busy week.

I managed to do everything you suggested, my computer still seems to have problem with my access but I'll try rats cheddar again.

heres the file report.

autorun.exe;c:\documents and settings\all users\start menu\programs\startup;Trojan.Fakealert.357 - read error;Deleted.;
system.exe;c:\documents and settings\rafael\start menu\programs\startup;Trojan.Fakealert.357 - read error;Deleted.;
printer.exe;c:\windows\system32;Trojan.Fakealert.357 - read error;Deleted.;
winavxx.exe;c:\windows\system32;Trojan.Fakealert.357 - read error;Deleted.;
105B24D8.IE5;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Trojan.Click.666;Deleted.;
130323FC.exe;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Trojan.Fakealert.305;Deleted.;
18303A49.exe;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Trojan.Fakealert.305;Deleted.;
20871DEF.exe;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Trojan.Fakealert.357;Deleted.;
258273A2.exe;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Trojan.Fakealert.305;Deleted.;
2B087F1A;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Trojan.DownLoader.26660;Deleted.;
2B2578F9.exe;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Trojan.DownLoader.26660;Deleted.;
4F042981.exe;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Trojan.Fakealert.357;Deleted.;
5B0A393D.DLL;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Trojan.Click.666;Deleted.;
60455851.exe;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Trojan.Fakealert.357;Deleted.;
6A024F5E.exe;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Trojan.Fakealert.357;Deleted.;
system.exe;C:\Documents and Settings\Cam\Start Menu\Programs\Startup;Trojan.Fakealert.357 - read error;Deleted.;
system.exe;C:\Documents and Settings\Clyde\Start Menu\Programs\Startup;Trojan.Fakealert.357 - read error;Deleted.;
NSWBE06901.exe;C:\Documents and Settings\Rafael\Desktop;Trojan.PWS.Gamania.5413;Deleted.;
Setup.exe\data001;C:\Documents and Settings\Rafael\Desktop\Setup.exe;Adware.Zango;;
Setup.exe;C:\Documents and Settings\Rafael\Desktop;Archive contains infected objects;Moved.;
itunes setup2.exe;C:\Documents and Settings\Rafael\Desktop\Raf's Folder;Trojan.PWS.Gamania.5413;Deleted.;
KillWind.exe;C:\hp\bin;Tool.ProcessKill;;
data001\data001;C:\Program Files\Morpheus\morpheustoolbar.exe\data001;Adware.Msearch;;
data001\data004;C:\Program Files\Morpheus\morpheustoolbar.exe\data001;Adware.Msearch;;
data001;C:\Program Files\Morpheus\morpheustoolbar.exe;Archive contains infected objects;;
morpheustoolbar.exe;C:\Program Files\Morpheus;Archive contains infected objects;Moved.;
data001\data001;C:\Program Files\Morpheus\mymorpheusToolbar.exe\data001;Adware.Msearch;;
data001\data004;C:\Program Files\Morpheus\mymorpheusToolbar.exe\data001;Adware.Msearch;;
data001;C:\Program Files\Morpheus\mymorpheusToolbar.exe;Archive contains infected objects;;
mymorpheusToolbar.exe;C:\Program Files\Morpheus;Archive contains infected objects;Moved.;
A0105884.dll;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP338;Adware.Zango;;
A0111148.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP353;Trojan.Packed.140;Deleted.;
A0111153.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP353;Trojan.Fakealert.357 - read error;Deleted.;
A0111154.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP353;Trojan.Fakealert.357 - read error;Deleted.;
A0111155.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP353;Trojan.Fakealert.357 - read error;Deleted.;
A0111162.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP353;Trojan.Fakealert.305;Deleted.;
A0112148.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP353;Trojan.Fakealert.357 - read error;Deleted.;
A0112153.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP353;Trojan.Fakealert.357 - read error;Deleted.;
A0112154.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP353;Trojan.Fakealert.357 - read error;Deleted.;
A0112155.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP353;Trojan.Fakealert.357 - read error;Deleted.;
A0112168.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP353;Trojan.Fakealert.357 - read error;Deleted.;
A0112169.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP353;Trojan.Fakealert.357 - read error;Deleted.;
A0112183.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP353;Trojan.Fakealert.357 - read error;Deleted.;
A0112184.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP353;Trojan.Fakealert.357 - read error;Deleted.;
A0112185.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP353;Trojan.Fakealert.357 - read error;Deleted.;
A0112198.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP353;Trojan.Fakealert.357 - read error;Deleted.;
A0112199.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP353;Trojan.Fakealert.357 - read error;Deleted.;
A0112200.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP353;Trojan.Fakealert.357 - read error;Deleted.;
A0112221.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP353;Trojan.Fakealert.357 - read error;Deleted.;
A0112222.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP353;Trojan.Fakealert.357 - read error;Deleted.;
A0112223.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP353;Trojan.Fakealert.357 - read error;Deleted.;
A0112239.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP354;Trojan.Fakealert.357 - read error;Deleted.;
A0112240.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP354;Trojan.Fakealert.357 - read error;Deleted.;
A0112241.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP354;Trojan.Fakealert.357 - read error;Deleted.;
A0112289.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP354;Trojan.Fakealert.357 - read error;Deleted.;
A0112290.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP354;Trojan.Fakealert.357 - read error;Deleted.;
A0112291.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP354;Trojan.Fakealert.357 - read error;Deleted.;
A0112313.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP355;Trojan.Fakealert.357 - read error;Deleted.;
A0112314.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP355;Trojan.Fakealert.357 - read error;Deleted.;
A0112315.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP355;Trojan.Fakealert.357 - read error;Deleted.;
A0112325.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP355;Trojan.Fakealert.357 - read error;Deleted.;
A0112326.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP355;Trojan.Fakealert.357 - read error;Deleted.;
A0112327.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP355;Trojan.Fakealert.357 - read error;Deleted.;
A0112434.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP357;Trojan.Fakealert.357 - read error;Deleted.;
A0112435.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP357;Trojan.Fakealert.357 - read error;Deleted.;
A0112436.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP357;Trojan.Fakealert.357 - read error;Deleted.;
A0112449.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP357;Trojan.Fakealert.357 - read error;Deleted.;
A0112450.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP357;Trojan.Fakealert.357 - read error;Deleted.;
A0112451.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP357;Trojan.Fakealert.357 - read error;Deleted.;
A0112464.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP357;Trojan.Fakealert.357 - read error;Deleted.;
A0112465.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP357;Trojan.Fakealert.357 - read error;Deleted.;
A0112466.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP357;Trojan.Fakealert.357 - read error;Deleted.;
A0112479.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP357;Trojan.Fakealert.357 - read error;Deleted.;
A0112480.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP357;Trojan.Fakealert.357 - read error;Deleted.;
A0112481.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP357;Trojan.Fakealert.357 - read error;Deleted.;
A0112501.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP357;Trojan.Fakealert.357 - read error;Deleted.;
A0112502.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP357;Trojan.Fakealert.357 - read error;Deleted.;
A0112503.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP357;Trojan.Fakealert.357 - read error;Deleted.;
A0112517.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP357;Trojan.Fakealert.357 - read error;Deleted.;
A0112518.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP357;Trojan.Fakealert.357 - read error;Deleted.;
A0112519.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP357;Trojan.Fakealert.357 - read error;Deleted.;
A0112531.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP357;Trojan.Fakealert.357 - read error;Deleted.;
A0112532.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP357;Trojan.Fakealert.357 - read error;Deleted.;
A0112533.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP357;Trojan.Fakealert.357 - read error;Deleted.;
A0112548.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP357;Trojan.Fakealert.357 - read error;Deleted.;
A0112549.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP357;Trojan.Fakealert.357 - read error;Deleted.;
A0112550.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP357;Trojan.Fakealert.357 - read error;Deleted.;
A0112563.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP357;Trojan.Fakealert.357 - read error;Deleted.;
A0112564.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP357;Trojan.Fakealert.357 - read error;Deleted.;
A0112565.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP357;Trojan.Fakealert.357 - read error;Deleted.;
A0112578.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP357;Trojan.Fakealert.357 - read error;Deleted.;
A0112579.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP357;Trojan.Fakealert.357 - read error;Deleted.;
A0112580.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP357;Trojan.Fakealert.357 - read error;Deleted.;
A0112594.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP357;Trojan.Fakealert.357 - read error;Deleted.;
A0112595.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP357;Trojan.Fakealert.357 - read error;Deleted.;
A0112596.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP357;Trojan.Fakealert.357 - read error;Deleted.;
A0112609.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP357;Trojan.Fakealert.357 - read error;Deleted.;
A0112610.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP357;Trojan.Fakealert.357 - read error;Deleted.;
A0112611.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP357;Trojan.Fakealert.357 - read error;Deleted.;
A0112624.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP357;Trojan.Fakealert.357 - read error;Deleted.;
A0112625.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP357;Trojan.Fakealert.357 - read error;Deleted.;
A0112626.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP357;Trojan.Fakealert.357 - read error;Deleted.;
A0112639.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP357;Trojan.Fakealert.357 - read error;Deleted.;
A0112640.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP357;Trojan.Fakealert.357 - read error;Deleted.;
A0112641.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP357;Trojan.Fakealert.357 - read error;Deleted.;
A0112704.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP358;Trojan.Fakealert.357 - read error;Deleted.;
A0112705.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP358;Trojan.Fakealert.357 - read error;Deleted.;
A0112706.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP358;Trojan.Fakealert.357 - read error;Deleted.;
A0112747.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP358;Trojan.Fakealert.357 - read error;Deleted.;
A0112748.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP358;Trojan.Fakealert.357 - read error;Deleted.;
A0112749.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP358;Trojan.Fakealert.357 - read error;Deleted.;
A0112762.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP358;Trojan.Fakealert.357 - read error;Deleted.;
A0112763.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP358;Trojan.Fakealert.357 - read error;Deleted.;
A0112764.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP358;Trojan.Fakealert.357 - read error;Deleted.;
A0112777.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP358;Trojan.Fakealert.357 - read error;Deleted.;
A0112778.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP358;Trojan.Fakealert.357 - read error;Deleted.;
A0112779.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP358;Trojan.Fakealert.357 - read error;Deleted.;
A0112792.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP358;Trojan.Fakealert.357 - read error;Deleted.;
A0112793.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP358;Trojan.Fakealert.357 - read error;Deleted.;
A0112794.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP358;Trojan.Fakealert.357 - read error;Deleted.;
A0112847.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP358;Trojan.Fakealert.357 - read error;Deleted.;
A0112848.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP358;Trojan.Fakealert.357 - read error;Deleted.;
A0112849.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP358;Trojan.Fakealert.357 - read error;Deleted.;
A0112872.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP358;Trojan.Fakealert.357 - read error;Deleted.;
A0112873.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP358;Trojan.Fakealert.357 - read error;Deleted.;
A0112874.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP358;Trojan.Fakealert.357 - read error;Deleted.;
A0112887.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP358;Trojan.Fakealert.357 - read error;Deleted.;
A0112888.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP358;Trojan.Fakealert.357 - read error;Deleted.;
A0112889.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP358;Trojan.Fakealert.357 - read error;Deleted.;
A0113244.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP359;Trojan.Fakealert.357 - read error;Deleted.;
A0113245.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP359;Trojan.Fakealert.357 - read error;Deleted.;
A0113246.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP359;Trojan.Fakealert.357 - read error;Deleted.;
A0113259.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP359;Trojan.Fakealert.357 - read error;Deleted.;
A0113260.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP359;Trojan.Fakealert.357 - read error;Deleted.;
A0113261.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP359;Trojan.Fakealert.357 - read error;Deleted.;
A0113274.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP359;Trojan.Fakealert.357 - read error;Deleted.;
A0113275.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP359;Trojan.Fakealert.357 - read error;Deleted.;
A0113276.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP359;Trojan.Fakealert.357 - read error;Deleted.;
A0113289.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP359;Trojan.Fakealert.357 - read error;Deleted.;
A0113290.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP359;Trojan.Fakealert.357 - read error;Deleted.;
A0113291.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP359;Trojan.Fakealert.357 - read error;Deleted.;
A0113304.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP359;Trojan.Fakealert.357 - read error;Deleted.;
A0113305.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP359;Trojan.Fakealert.357 - read error;Deleted.;
A0113306.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP359;Trojan.Fakealert.357 - read error;Deleted.;
A0113359.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP360;Trojan.Fakealert.357 - read error;Deleted.;
A0113360.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP360;Trojan.Fakealert.357 - read error;Deleted.;
A0113361.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP360;Trojan.Fakealert.357 - read error;Deleted.;
A0113374.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP360;Trojan.Fakealert.357 - read error;Deleted.;
A0113375.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP360;Trojan.Fakealert.357 - read error;Deleted.;
A0113376.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP360;Trojan.Fakealert.357 - read error;Deleted.;
A0113389.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP360;Trojan.Fakealert.357 - read error;Deleted.;
A0113390.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP360;Trojan.Fakealert.357 - read error;Deleted.;
A0113391.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP360;Trojan.Fakealert.357 - read error;Deleted.;
A0113404.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP360;Trojan.Fakealert.357 - read error;Deleted.;
A0113405.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP360;Trojan.Fakealert.357 - read error;Deleted.;
A0113406.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP360;Trojan.Fakealert.357 - read error;Deleted.;
A0113420.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP360;Trojan.Fakealert.357 - read error;Deleted.;
A0113421.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP360;Trojan.Fakealert.357 - read error;Deleted.;
A0113422.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP360;Trojan.Fakealert.357 - read error;Deleted.;
A0113435.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP361;Trojan.Fakealert.357 - read error;Deleted.;
A0113436.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP361;Trojan.Fakealert.357 - read error;Deleted.;
A0113437.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP361;Trojan.Fakealert.357 - read error;Deleted.;
A0113448.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP361;Trojan.Fakealert.357 - read error;Deleted.;
A0113449.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP361;Trojan.Fakealert.357 - read error;Deleted.;
A0113450.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP361;Trojan.Fakealert.357 - read error;Deleted.;
A0113456.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP361;Trojan.Fakealert.357 - read error;Deleted.;
A0113457.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP361;Trojan.Fakealert.357 - read error;Deleted.;
A0113458.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP361;Trojan.Fakealert.357 - read error;Deleted.;
A0113473.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP361;Trojan.Fakealert.357 - read error;Deleted.;
A0113474.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP361;Trojan.Fakealert.357 - read error;Deleted.;
A0113475.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP361;Trojan.Fakealert.357 - read error;Deleted.;
A0113489.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP361;Trojan.Fakealert.357 - read error;Deleted.;
A0113490.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP361;Trojan.Fakealert.357 - read error;Deleted.;
A0113491.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP361;Trojan.Fakealert.357 - read error;Deleted.;
A0113505.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP361;Trojan.Fakealert.357 - read error;Deleted.;
A0113506.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP361;Trojan.Fakealert.357 - read error;Deleted.;
A0113507.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP361;Trojan.Fakealert.357 - read error;Deleted.;
A0113524.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP362;Trojan.Fakealert.357 - read error;Deleted.;
A0113525.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP362;Trojan.Fakealert.357 - read error;Deleted.;
A0113526.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP362;Trojan.Fakealert.357 - read error;Deleted.;
A0113539.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP362;Trojan.Fakealert.357 - read error;Deleted.;
A0113540.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP362;Trojan.Fakealert.357 - read error;Deleted.;
A0113541.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP362;Trojan.Fakealert.357 - read error;Deleted.;
A0113586.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP363;Trojan.Fakealert.357 - read error;Deleted.;
A0113587.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP363;Trojan.Fakealert.357 - read error;Deleted.;
A0113588.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP363;Trojan.Fakealert.357 - read error;Deleted.;
A0113589.exe\data001;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP363\A0113589.exe;Adware.Zango;;
A0113589.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP363;Archive contains infected objects;Moved.;
A0113592.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP363;Trojan.Fakealert.357 - read error;Deleted.;
A0113593.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP363;Trojan.Fakealert.305;Deleted.;
A0113594.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP363;Trojan.Fakealert.305;Deleted.;
A0113595.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP363;Trojan.Fakealert.357;Deleted.;
A0113596.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP363;Trojan.Fakealert.305;Deleted.;
A0113597.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP363;Trojan.DownLoader.26660;Deleted.;
A0113598.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP363;Trojan.Fakealert.357;Deleted.;
A0113599.DLL;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP363;Trojan.Click.666;Deleted.;
A0113600.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP363;Trojan.Fakealert.357;Deleted.;
A0113601.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP363;Trojan.Fakealert.357;Deleted.;
A0113602.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP363;Trojan.Fakealert.357 - read error;Deleted.;
A0113603.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP363;Trojan.Fakealert.357 - read error;Deleted.;
A0113604.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP363;Trojan.PWS.Gamania.5413;Deleted.;
A0113605.exe\data001;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP363\A0113605.exe;Adware.Zango;;
A0113605.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP363;Archive contains infected objects;Moved.;
A0113606.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP363;Trojan.PWS.Gamania.5413;Deleted.;
data001\data001;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP363\A0113607.exe\data001;Adware.Msearch;;
data001\data004;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP363\A0113607.exe\data001;Adware.Msearch;;
data001;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP363\A0113607.exe;Archive contains infected objects;;
A0113607.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP363;Archive contains infected objects;Moved.;
data001\data001;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP363\A0113608.exe\data001;Adware.Msearch;;
data001\data004;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP363\A0113608.exe\data001;Adware.Msearch;;
data001;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP363\A0113608.exe;Archive contains infected objects;;
A0113608.exe;C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP363;Archive contains infected objects;Moved.;


Again thanks a lot for the help I really appreciate it.

#5 quietman7

quietman7

    Bleepin' Janitor


  • Global Moderator
  • 51,485 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:09:08 PM

Posted 01 November 2007 - 08:44 PM

my computer still seems to have problem with my access

What specific access? Is is still Control Panel?

Please print out and follow the generic instructions for using SmitfraudFix in BC's self-help tutorial "How to remove the Smitfraud/Generic Zlob".
(scroll down to where it says Removal Instructions; ignore the part that shows symptoms in a HijackThis log as they will not apply your case.)
If you have downloaded SmitfraudFix previously, please delete that version and download it again as the tool is frequently updated!
.
.
Windows Insider MVP 2017-2018
Microsoft MVP Reconnect 2016
Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif

#6 Raf_MacDonald

Raf_MacDonald
  • Topic Starter

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:10:08 PM

Posted 02 November 2007 - 03:51 PM

I just logged on my computer and everything seems to be working completely normal.

I really cant express how much I appreciate your help and the dollars you've saved my by not having to have my computer serviced by a professional. thanks so much for your time and energy.

-Raf MacDonald

Edited by Raf_MacDonald, 02 November 2007 - 03:51 PM.


#7 quietman7

quietman7

    Bleepin' Janitor


  • Global Moderator
  • 51,485 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:09:08 PM

Posted 02 November 2007 - 08:09 PM

Your welcome.

Now you should Set a New Restore Point to prevent possible reinfection from an old one. Some of the malware you picked up could have been saved in System Restore. Since this is a protected directory your tools cannot access to delete these files, they sometimes can reinfect your system if you accidentally use an old restore point. Setting a new restore point AFTER cleaning your system will help prevent this and enable your computer to "roll-back" to a clean working state.

The easiest and safest way to do this is:
  • Go to Start > Programs > Accessories > System Tools and click "System Restore".
  • Choose the radio button marked "Create a Restore Point" on the first screen then click "Next". Give the R.P. a name, then click "Create". The new point will be stamped with the current date and time. Keep a log of this so you can find it easily should you need to use System Restore.
  • Then use Disk Cleanup to remove all but the most recent Restore Point.
  • Go to Start > Run and type: Cleanmgr
  • Click "OK".
  • Click the "More Options" Tab.
  • Click "Clean Up" in the System Restore section to remove all previous restore points except the newly created one.

.
.
Windows Insider MVP 2017-2018
Microsoft MVP Reconnect 2016
Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users