done done and done!
thank you very much man those are some well written and detailed instructions
cleaned with atf and it seemed to be successful
then i used your sas method and here is my log:
SUPERAntiSpyware Scan Log
http://www.superantispyware.comGenerated 09/17/2009 at 07:52 PM
Application Version : 4.29.1002
Core Rules Database Version : 4108
Trace Rules Database Version: 2048
Scan type : Complete Scan
Total Scan Time : 01:44:47
Memory items scanned : 194
Memory threats detected : 0
Registry items scanned : 4882
Registry threats detected : 7
File items scanned : 43449
File threats detected : 15
Trojan.Dropper/Win-NV
[mset] C:\WINDOWS\SYSTEM32\MSET.EXE
C:\WINDOWS\SYSTEM32\MSET.EXE
Trojan.Dropper/Gen-NV
[braviax] C:\WINDOWS\SYSTEM32\BRAVIAX.EXE
C:\WINDOWS\SYSTEM32\BRAVIAX.EXE
C:\!KILLBOX\BRAVIAX.EXE
C:\WINDOWS\BRAVIAX.EXE
Trojan.Unclassified/BraviaX
HKU\S-1-5-21-1547161642-1409082233-839522115-1005\Software\Microsoft\Windows\CurrentVersion\Run#braviax [ X ]
HKLM\Software\Microsoft\Windows\CurrentVersion\Run#braviax [ braviax.exe ]
Rogue.XP AntiSpyware2009-Trace
C:\WINDOWS\system32\_scui.cpl
Rogue.XP AntiSpyware 2009
HKU\S-1-5-21-1547161642-1409082233-839522115-1005\Control Panel\don't load#wscui.cpl [ No ]
Rogue.PCAntiSpyware2010
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run#PC Antispyware 2010 [ "C:\Program Files\PC_Antispyware2010\PC_Antispyware2010.exe" /hide ]
Rogue.AntiVirusPro2010
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run#Antivirus Pro 2010 [ "C:\Program Files\AntivirusPro_2010\AntivirusPro_2010.exe" /hide ]
Trojan.Downloader-Gen/Win
C:\!KILLBOX\CRU629.DAT
C:\!KILLBOX\CRU629.DAT( 4)
C:\WINDOWS\CRU629.DAT
C:\WINDOWS\SYSTEM32\CRU629.DAT
Trojan.Dropper/Sys-NV
C:\!KILLBOX\SYS32_NOV.EXE
Rootkit.BraviaX-Installer
C:\WINDOWS\DRIVERS\BEEP.SYS
C:\WINDOWS\SYSTEM32\DLLCACHE\BEEP.SYS
C:\WINDOWS\SYSTEM32\DRIVERS\BEEP.SYS
Unclassified.Unknown Origin
C:\WINDOWS\SYSTEM32\SYS32_~1.EXE
Trojan.Agent/Gen-FraudTool
C:\WINDOWS\SYSTEM32\WISDSTR.EXE
and lastly scanned using dr. web. here is the log for that:
autorun.inf;e:;Probably Win32.HLLW.Autoruner.corrupted;Moved.;
ikowin32.exe;c:\documents and settings\bryan_2\start menu\programs\startup;Trojan.Botnetlog.11;Deleted.;
braviax.exe( 1);C:\!KillBox;Trojan.Fakealert.5013;Deleted.;
braviax.exe( 2);C:\!KillBox;Trojan.Fakealert.5013;Deleted.;
braviax.exe( 3);C:\!KillBox;Trojan.Fakealert.5013;Deleted.;
wisdstr.exe;C:\!KillBox;Trojan.Fakealert.4747;Incurable.Moved.;
SDFix2.exe\SDFix\apps\Process.exe;C:\Program Files\SDFix2.exe;Tool.Prockill;;
SDFix2.exe;C:\Program Files;Archive contains infected objects;Moved.;
Process.exe;C:\SDFix\apps;Tool.Prockill;Incurable.Moved.;
A0006160.sys;C:\System Volume Information\_restore{759F4DAB-9385-406C-AB9B-D278CFD8BCAB}\RP10;Trojan.NtRootKit.3206;Deleted.;
A0006162.sys;C:\System Volume Information\_restore{759F4DAB-9385-406C-AB9B-D278CFD8BCAB}\RP10;Trojan.NtRootKit.3206;Deleted.;
A0006171.sys;C:\System Volume Information\_restore{759F4DAB-9385-406C-AB9B-D278CFD8BCAB}\RP10;Trojan.NtRootKit.3206;Deleted.;
A0006173.exe;C:\System Volume Information\_restore{759F4DAB-9385-406C-AB9B-D278CFD8BCAB}\RP10;Trojan.Fakealert.5013;Deleted.;
A0006174.sys;C:\System Volume Information\_restore{759F4DAB-9385-406C-AB9B-D278CFD8BCAB}\RP10;Trojan.NtRootKit.3206;Deleted.;
A0006179.sys;C:\System Volume Information\_restore{759F4DAB-9385-406C-AB9B-D278CFD8BCAB}\RP10;Trojan.NtRootKit.3206;Deleted.;
A0006180.sys;C:\System Volume Information\_restore{759F4DAB-9385-406C-AB9B-D278CFD8BCAB}\RP10;Trojan.NtRootKit.3206;Deleted.;
A0006181.sys;C:\System Volume Information\_restore{759F4DAB-9385-406C-AB9B-D278CFD8BCAB}\RP10;Trojan.NtRootKit.3206;Deleted.;
A0006183.exe;C:\System Volume Information\_restore{759F4DAB-9385-406C-AB9B-D278CFD8BCAB}\RP10;Trojan.Fakealert.5013;Deleted.;
A0006184.exe;C:\System Volume Information\_restore{759F4DAB-9385-406C-AB9B-D278CFD8BCAB}\RP10;Trojan.Fakealert.5013;Deleted.;
A0006185.sys;C:\System Volume Information\_restore{759F4DAB-9385-406C-AB9B-D278CFD8BCAB}\RP10;Trojan.NtRootKit.3206;Deleted.;
A0006190.sys;C:\System Volume Information\_restore{759F4DAB-9385-406C-AB9B-D278CFD8BCAB}\RP10;Trojan.NtRootKit.3206;Deleted.;
A0006191.sys;C:\System Volume Information\_restore{759F4DAB-9385-406C-AB9B-D278CFD8BCAB}\RP10;Trojan.NtRootKit.3206;Deleted.;
A0006192.sys;C:\System Volume Information\_restore{759F4DAB-9385-406C-AB9B-D278CFD8BCAB}\RP10;Trojan.NtRootKit.3206;Deleted.;
MFEX-1.DAT;C:\System Volume Information\_restore{759F4DAB-9385-406C-AB9B-D278CFD8BCAB}\RP10\snapshot;Trojan.NtRootKit.3206;Deleted.;
A0006389.exe;C:\System Volume Information\_restore{759F4DAB-9385-406C-AB9B-D278CFD8BCAB}\RP11;Trojan.Fakealert.5013;Deleted.;
A0006390.exe;C:\System Volume Information\_restore{759F4DAB-9385-406C-AB9B-D278CFD8BCAB}\RP11;Trojan.Fakealert.5013;Deleted.;
A0006391.sys;C:\System Volume Information\_restore{759F4DAB-9385-406C-AB9B-D278CFD8BCAB}\RP11;Trojan.NtRootKit.3206;Deleted.;
A0006403.sys;C:\System Volume Information\_restore{759F4DAB-9385-406C-AB9B-D278CFD8BCAB}\RP11;Trojan.NtRootKit.3206;Deleted.;
A0006414.sys;C:\System Volume Information\_restore{759F4DAB-9385-406C-AB9B-D278CFD8BCAB}\RP11;Trojan.NtRootKit.3206;Deleted.;
A0006415.exe;C:\System Volume Information\_restore{759F4DAB-9385-406C-AB9B-D278CFD8BCAB}\RP11;Trojan.Fakealert.5013;Deleted.;
A0006451.sys;C:\System Volume Information\_restore{759F4DAB-9385-406C-AB9B-D278CFD8BCAB}\RP11;Trojan.NtRootKit.3206;Deleted.;
A0006458.exe;C:\System Volume Information\_restore{759F4DAB-9385-406C-AB9B-D278CFD8BCAB}\RP11;Trojan.Fakealert.5013;Deleted.;
A0006459.sys;C:\System Volume Information\_restore{759F4DAB-9385-406C-AB9B-D278CFD8BCAB}\RP11;Trojan.NtRootKit.3206;Deleted.;
A0006464.sys;C:\System Volume Information\_restore{759F4DAB-9385-406C-AB9B-D278CFD8BCAB}\RP11;Trojan.NtRootKit.3206;Deleted.;
A0006465.sys;C:\System Volume Information\_restore{759F4DAB-9385-406C-AB9B-D278CFD8BCAB}\RP11;Trojan.NtRootKit.3206;Deleted.;
A0006466.sys;C:\System Volume Information\_restore{759F4DAB-9385-406C-AB9B-D278CFD8BCAB}\RP11;Trojan.NtRootKit.3206;Deleted.;
A0006468.exe;C:\System Volume Information\_restore{759F4DAB-9385-406C-AB9B-D278CFD8BCAB}\RP11;Trojan.Fakealert.5013;Deleted.;
A0006469.exe;C:\System Volume Information\_restore{759F4DAB-9385-406C-AB9B-D278CFD8BCAB}\RP11;Trojan.Fakealert.5013;Deleted.;
A0006470.sys;C:\System Volume Information\_restore{759F4DAB-9385-406C-AB9B-D278CFD8BCAB}\RP11;Trojan.NtRootKit.3206;Deleted.;
A0006471.exe;C:\System Volume Information\_restore{759F4DAB-9385-406C-AB9B-D278CFD8BCAB}\RP11;Trojan.DownLoad.41506;Deleted.;
A0006477.exe;C:\System Volume Information\_restore{759F4DAB-9385-406C-AB9B-D278CFD8BCAB}\RP11;Trojan.Fakealert.5013;Deleted.;
A0006478.exe;C:\System Volume Information\_restore{759F4DAB-9385-406C-AB9B-D278CFD8BCAB}\RP11;Trojan.Fakealert.5013;Deleted.;
A0006479.exe;C:\System Volume Information\_restore{759F4DAB-9385-406C-AB9B-D278CFD8BCAB}\RP11;Trojan.Fakealert.4747;Incurable.Moved.;
A0006485.exe;C:\System Volume Information\_restore{759F4DAB-9385-406C-AB9B-D278CFD8BCAB}\RP11;Trojan.Fakealert.5013;Deleted.;
A0006486.exe;C:\System Volume Information\_restore{759F4DAB-9385-406C-AB9B-D278CFD8BCAB}\RP11;Trojan.Fakealert.5013;Deleted.;
A0006514.exe;C:\System Volume Information\_restore{759F4DAB-9385-406C-AB9B-D278CFD8BCAB}\RP11;Trojan.Fakealert.5013;Deleted.;
A0006515.exe;C:\System Volume Information\_restore{759F4DAB-9385-406C-AB9B-D278CFD8BCAB}\RP11;Trojan.Fakealert.5013;Deleted.;
MFEX-1.DAT;C:\System Volume Information\_restore{759F4DAB-9385-406C-AB9B-D278CFD8BCAB}\RP11\snapshot;Trojan.NtRootKit.3206;Deleted.;
A0006540.exe;C:\System Volume Information\_restore{759F4DAB-9385-406C-AB9B-D278CFD8BCAB}\RP12;Trojan.Fakealert.5013;Deleted.;
A0006541.exe;C:\System Volume Information\_restore{759F4DAB-9385-406C-AB9B-D278CFD8BCAB}\RP12;Trojan.Fakealert.5013;Deleted.;
A0006566.exe;C:\System Volume Information\_restore{759F4DAB-9385-406C-AB9B-D278CFD8BCAB}\RP12;Trojan.Fakealert.5013;Deleted.;
A0006567.exe;C:\System Volume Information\_restore{759F4DAB-9385-406C-AB9B-D278CFD8BCAB}\RP12;Trojan.Fakealert.5013;Deleted.;
A0006596.exe;C:\System Volume Information\_restore{759F4DAB-9385-406C-AB9B-D278CFD8BCAB}\RP14;Trojan.Fakealert.5013;Deleted.;
A0006597.exe;C:\System Volume Information\_restore{759F4DAB-9385-406C-AB9B-D278CFD8BCAB}\RP14;Trojan.Fakealert.5013;Deleted.;
A0006602.cpl;C:\System Volume Information\_restore{759F4DAB-9385-406C-AB9B-D278CFD8BCAB}\RP14;Trojan.Fakealert.5006;Deleted.;
A0006629.exe;C:\System Volume Information\_restore{759F4DAB-9385-406C-AB9B-D278CFD8BCAB}\RP15;Trojan.Fakealert.5013;Deleted.;
A0006630.exe;C:\System Volume Information\_restore{759F4DAB-9385-406C-AB9B-D278CFD8BCAB}\RP15;Trojan.Fakealert.5013;Deleted.;
A0006635.exe;C:\System Volume Information\_restore{759F4DAB-9385-406C-AB9B-D278CFD8BCAB}\RP15;Trojan.DownLoad.41506;Deleted.;
A0006636.exe;C:\System Volume Information\_restore{759F4DAB-9385-406C-AB9B-D278CFD8BCAB}\RP15;Trojan.Fakealert.5013;Deleted.;
A0006638.exe;C:\System Volume Information\_restore{759F4DAB-9385-406C-AB9B-D278CFD8BCAB}\RP15;Trojan.DownLoad.41506;Deleted.;
A0006639.sys;C:\System Volume Information\_restore{759F4DAB-9385-406C-AB9B-D278CFD8BCAB}\RP15;Trojan.NtRootKit.3206;Deleted.;
A0006640.sys;C:\System Volume Information\_restore{759F4DAB-9385-406C-AB9B-D278CFD8BCAB}\RP15;Trojan.NtRootKit.3206;Deleted.;
A0006641.sys;C:\System Volume Information\_restore{759F4DAB-9385-406C-AB9B-D278CFD8BCAB}\RP15;Trojan.NtRootKit.3206;Deleted.;
A0006643.exe;C:\System Volume Information\_restore{759F4DAB-9385-406C-AB9B-D278CFD8BCAB}\RP15;Trojan.Fakealert.5015;Deleted.;
A0006655.exe;C:\System Volume Information\_restore{759F4DAB-9385-406C-AB9B-D278CFD8BCAB}\RP15;Trojan.Botnetlog.11;Deleted.;
A0006656.exe;C:\System Volume Information\_restore{759F4DAB-9385-406C-AB9B-D278CFD8BCAB}\RP15;Trojan.Fakealert.4747;Incurable.Moved.;
A0006657.exe\SDFix\apps\Process.exe;C:\System Volume Information\_restore{759F4DAB-9385-406C-AB9B-D278CFD8BCAB}\RP15\A0006657.exe;Tool.Prockill;;
A0006657.exe;C:\System Volume Information\_restore{759F4DAB-9385-406C-AB9B-D278CFD8BCAB}\RP15;Archive contains infected objects;Moved.;
A0004113.exe;C:\System Volume Information\_restore{759F4DAB-9385-406C-AB9B-D278CFD8BCAB}\RP8;Trojan.PWS.Haiuy.28;Deleted.;
A0004116.exe;C:\System Volume Information\_restore{759F4DAB-9385-406C-AB9B-D278CFD8BCAB}\RP8;Trojan.Fakealert.4960;Deleted.;
A0004124.dll;C:\System Volume Information\_restore{759F4DAB-9385-406C-AB9B-D278CFD8BCAB}\RP8;Trojan.DownLoad.45065;Deleted.;
A0004139.exe;C:\System Volume Information\_restore{759F4DAB-9385-406C-AB9B-D278CFD8BCAB}\RP8;Trojan.Fakealert.4511;Deleted.;
A0004140.exe;C:\System Volume Information\_restore{759F4DAB-9385-406C-AB9B-D278CFD8BCAB}\RP8;Trojan.DownLoad.41506;Deleted.;
A0004146.sys;C:\System Volume Information\_restore{759F4DAB-9385-406C-AB9B-D278CFD8BCAB}\RP8;Trojan.NtRootKit.3206;Deleted.;
A0005142.exe;C:\System Volume Information\_restore{759F4DAB-9385-406C-AB9B-D278CFD8BCAB}\RP9;Trojan.Fakealert.5013;Deleted.;
A0005143.sys;C:\System Volume Information\_restore{759F4DAB-9385-406C-AB9B-D278CFD8BCAB}\RP9;Trojan.NtRootKit.3206;Deleted.;
A0005147.sys;C:\System Volume Information\_restore{759F4DAB-9385-406C-AB9B-D278CFD8BCAB}\RP9;Trojan.NtRootKit.3206;Deleted.;
A0005149.sys;C:\System Volume Information\_restore{759F4DAB-9385-406C-AB9B-D278CFD8BCAB}\RP9;Trojan.NtRootKit.3206;Deleted.;
A0005150.sys;C:\System Volume Information\_restore{759F4DAB-9385-406C-AB9B-D278CFD8BCAB}\RP9;Trojan.NtRootKit.3206;Deleted.;
A0005154.exe;C:\System Volume Information\_restore{759F4DAB-9385-406C-AB9B-D278CFD8BCAB}\RP9;Trojan.Fakealert.5013;Deleted.;
A0005155.exe;C:\System Volume Information\_restore{759F4DAB-9385-406C-AB9B-D278CFD8BCAB}\RP9;Trojan.Fakealert.5013;Deleted.;
A0005156.sys;C:\System Volume Information\_restore{759F4DAB-9385-406C-AB9B-D278CFD8BCAB}\RP9;Trojan.NtRootKit.3206;Deleted.;
A0005161.sys;C:\System Volume Information\_restore{759F4DAB-9385-406C-AB9B-D278CFD8BCAB}\RP9;Trojan.NtRootKit.3206;Deleted.;
A0005162.sys;C:\System Volume Information\_restore{759F4DAB-9385-406C-AB9B-D278CFD8BCAB}\RP9;Trojan.NtRootKit.3206;Deleted.;
A0005163.sys;C:\System Volume Information\_restore{759F4DAB-9385-406C-AB9B-D278CFD8BCAB}\RP9;Trojan.NtRootKit.3206;Deleted.;
A0005164.exe;C:\System Volume Information\_restore{759F4DAB-9385-406C-AB9B-D278CFD8BCAB}\RP9;Trojan.DownLoad.41506;Deleted.;
A0005165.exe;C:\System Volume Information\_restore{759F4DAB-9385-406C-AB9B-D278CFD8BCAB}\RP9;Trojan.DownLoad.41506;Deleted.;
A0006157.sys;C:\System Volume Information\_restore{759F4DAB-9385-406C-AB9B-D278CFD8BCAB}\RP9;Trojan.NtRootKit.3206;Deleted.;
MFEX-1.DAT;C:\System Volume Information\_restore{759F4DAB-9385-406C-AB9B-D278CFD8BCAB}\RP9\snapshot;Trojan.NtRootKit.3206;Deleted.;
A0093913.exe/file.exe\data003;E:\System Volume Information\_restore{759F4DAB-9385-406C-AB9B-D278CFD8BCAB}\RP624\A0093913.exe/file.exe;Trojan.Popuper.14493;;
A0093913.exe/file.exe\data004;E:\System Volume Information\_restore{759F4DAB-9385-406C-AB9B-D278CFD8BCAB}\RP624\A0093913.exe/file.exe;Trojan.Virtumod.based.21;;
file.exe;E:\System Volume Information\_restore{759F4DAB-9385-406C-AB9B-D278CFD8BCAB}\RP624;Archive contains infected objects;;
A0093913.exe;E:\System Volume Information\_restore{759F4DAB-9385-406C-AB9B-D278CFD8BCAB}\RP624;Archive contains infected objects;Moved.;
tt.exe;E:\Games\torus trooper\tt;Win32.HLLM.Limar.2683;Deleted.;
and that is that. thanks again!