Virus (Gen.Variant.Barys.397)
Solved
Hello,
Configuration: Windows 7 / Safari 535.19
I hope you’re doing well? You can imagine I’m not doing too great since I’m posting here.
My antivirus seems possessed I think because this is like the 20th alert I’ve had in the last half hour. I think I have a virus named Gen: Variant.Barys.397. My knowledge on virus removal is very basic and I don’t want or can’t reinstall my laptop. Could you please help me?
Thanks in advance
(If my language sounds weird to you sorry I’m Quebecois hihi)
I’m using Google Chrome, Windows 7 and a ton of coffee :P
Configuration: Windows 7 / Safari 535.19
I hope you’re doing well? You can imagine I’m not doing too great since I’m posting here.
My antivirus seems possessed I think because this is like the 20th alert I’ve had in the last half hour. I think I have a virus named Gen: Variant.Barys.397. My knowledge on virus removal is very basic and I don’t want or can’t reinstall my laptop. Could you please help me?
Thanks in advance
(If my language sounds weird to you sorry I’m Quebecois hihi)
I’m using Google Chrome, Windows 7 and a ton of coffee :P
44 answers
-
g3n-h@ckm@nHi
download and save Pre_Scan on your desktop:
http://forums-fec.be/gen-hackman/Pre_Scan.exe
Warning: There will be a desktop blackout during the scan --> don't panic.
once downloaded, run it, let the scan proceed until "Pre_scan_la_date_et_l'heure.txt" appears on the desktop.
if the tool is launched several times, it will offer a menu and if no option is selected, choose the "Kill" option
if the tool is blocked by the infection use this version with .pif extension:
http://forums-fec.be/gen-hackman/Pre_Scan.pif
or this renamed version winlogon.exe:
http://forums-fec.be/gen-hackman/winlogon.exe
if the tool detects a proxy and you haven't installed one, click "remove the proxy"
It may open a multitude of black windows flashing, let it work
Post the Pre_Scan_la_date_et_l'heure.txt that will appear on the desktop at the end of the scan
DO NOT POST IT ON THE FORUM!!! (it's too long)
Host the report at http://pjjoint.malekal.com then share the obtained link in exchange on the forum where you are being helped
--
¤¤¤¤¤¤¤¤¤¤_g3n-h@ckm@n_Developpement_¤¤¤¤¤¤¤¤¤¤
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤_Pre_Scan_¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ -
Mel (Les Amy de Sonic)Hello,
The three links I have an error from the very start of the scan
Line 16026 (File "C:\Users\User\Downloads\wilogon.exe
error: Variable used without being declared
It makes the security system of my Internet provider crash and if I continue I have a total black screen and nothing works
Another solution please,
Thank you very much for helping me, that's very kind -
g3n-h@ckm@n< b>
/!\ FOLLOW THESE INSTRUCTIONS TO THE LETTER /!\
__________________________________________________________
>This software is to be used only as prescribed by a qualified and trained helper of the tool.<
>>>>>>>>Do not use outside of this scenario: dangerous!<<<<<<<<
=====================================================
▶ Above all, remember to save with a renamed Combofix to "your first name.exe" before it is saved on your hard drive
Download here : Combofix
Before using ComboFix :
If you use AVG, YOU MUST UNINSTALL IT before using Combofix as it can cause damage when interacting with the tool, potentially leading to a total system reinstall.
Simply disabling resident protection is not enough.
Download the AVG remover at this link : https://www.avg.com/fr-fr/avg-remover
Choose the appropriate version (32 or 64 bits)/!\
CD emulation software like Daemon Tools can interfere with the disinfection tools. Use Defogger to temporarily disable them :
▶ Download Defogger (by jpshortstuff) on your Desktop
▶ Run the
A window will appear: click on "Disable"
▶ Reboot the computer if the tool asks you to
Note: When we have finished the disinfection, you can re-enable these software by relaunching Defogger and clicking on "Re-enable"
_________________________________________________________
>> close all program windows.
>> Temporarily disable, only during ComboFix usage,
>> your Antivirus and AntiSpyware real-time protection,
>> which can strongly hinder the search and cleaning procedure of the tool.
°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°
if you have XP => double-click
if you have Vista or Windows 7 => right-click "run as...."
on renamed combofix
¤¤¤¤¤¤¤¤¤¤ LET IT INSTALL, THE RECOVERY CONSOLE WILL ASK FOR IT ¤¤¤¤¤¤¤¤¤¤
▶ !!!!!DO NOT TOUCH ANYTHING DURING COMBOFIX OPERATION (MOUSE/KEYBOARD.....)!!!!!
▶ remember to re-enable your Antivirus and AntiSpyware protections before reconnecting to the internet.
▶▶ Return to the forum, and copy-paste the entire contents of C:\Combofix.txt in your next message.
▶▶▶ If, after your PC restarts from combofix, you have "Key marked for deletion" errors or internet connectivity issues, restart your computer again
--
--
¤¤¤¤¤¤¤¤¤¤_g3n-h@ckm@n_Development_¤¤¤¤¤¤¤¤¤¤
¤¤¤¤¤¤¤¤¤¤¤¤¤¤_Pre_Scan_¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ -
Mel (Les Amy de Sonic)Hello,
The download is very slow and slows down more and more (695 o/s the last time I checked), yet I have a very good internet connection. -
g3n-h@ckm@nyou have to be patient or try if it's not better in safe mode....
¤¤¤¤¤¤¤¤¤¤_g3n-h@ckm@n_Developpement_¤¤¤¤¤¤¤¤¤¤
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤_Pre_Scan_¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ -
Mel (Les Amy de Sonic)ComboFix 12-04-05.09 - User 2012-04-05 20:44:51.1.2 - x64
Microsoft Windows 7 Home Premium Edition 6.1.7600.0.1252.2.1036.18.3037.1517 [GMT -4:00]
Launched from: c:\users\User\Downloads\melanie.exe
AV: AntiVir Desktop *Disabled/Updated* {090F9C29-64CE-6C6F-379C-5901B49A85B7}
AV: Bell Internet Security Services Antivirus *Disabled/Updated* {A61154FD-4365-E00F-9A33-13A09AD54B56}
FW: Bell Internet Security Firewall *Disabled* {9E2AD5D8-090A-E157-B16C-BA9564060C2D}
SP: AntiVir Desktop *Disabled/Updated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A}
SP: Bell Internet Security Services Anti-spyware *Disabled/Updated* {1D70B519-655F-EF81-A083-28D2E15201EB}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\users\User\Desktop\Internet Explorer.lnk
.
.
((((((((((((((((((((((((((((( Created files from 2012-03-06 to 2012-04-06 ))))))))))))))))))))))))))))))))))))
.
.
2012-04-06 01:41 . 2012-04-06 01:41 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-04-05 23:48 . 2012-04-05 23:52 -------- d-----w- C:\ZHP
2012-04-05 23:46 . 2012-04-05 23:52 -------- d-----w- c:\program files (x86)\ZHPDiag
2012-04-05 22:49 . 2012-04-05 23:35 -------- d-----w- C:\Pre_Scan
2012-04-05 22:11 . 2011-06-21 04:09 200976 ----a-w- c:\windows\SysWow64\drivers\tmcomm.sys
2012-04-05 15:59 . 2012-04-05 16:00 8738464 ----a-w- c:\windows\SysWow64\FlashPlayerInstaller.exe
2012-04-05 15:39 . 2012-04-05 16:01 418464 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2012-04-05 11:37 . 2011-02-19 06:37 1135104 ----a-w- c:\windows\system32\FntCache.dll
2012-03-27 16:31 . 2012-03-27 16:31 -------- d-----w- c:\users\User\AppData\Local\Akamai
2012-03-27 16:30 . 2012-04-06 01:43 -------- d-----w- c:\program files (x86)\Common Files\Akamai
2012-03-14 10:42 . 2011-11-19 18:30 5504880 ----a-w- c:\windows\system32\ntoskrnl.exe
2012-03-14 10:42 . 2011-11-19 14:25 3957616 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe
2012-03-14 10:42 . 2011-11-19 14:25 3902320 ----a-w- c:\windows\SysWow64\ntoskrnl.exe
2012-03-13 23:45 . 2012-02-15 06:27 1031680 ----a-w- c:\windows\system32\rdpcore.dll
2012-03-13 23:45 . 2012-02-15 05:44 826368 ----a-w- c:\windows\SysWow64\rdpcore.dll
2012-03-13 23:45 . 2012-02-15 04:47 204800 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2012-03-13 23:45 . 2012-02-15 04:46 23552 ----a-w- c:\windows\system32\drivers\tdtcp.sys
.
.
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-04-05 23:39 . 2012-03-05 17:01 45056 ----a-w- c:\windows\system32\acovcnt.exe
2012-04-05 16:01 . 2011-10-19 04:19 70304 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
.
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty elements & initial legitimate elements are not listed
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ADSMOverlayIcon1]
@="{A8D448F4-0431-45AC-9F5E-E1B434AB2249}"
[HKEY_CLASSES_ROOT\CLSID\{A8D448F4-0431-45AC-9F5E-E1B434AB2249}]
2007-06-01 21:08 143360 ----a-w- c:\program files (x86)\asus\ASUS Data Security Manager\ShlExt\x86\OverlayIconShlExt1.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\VaultIcon1]
@="{B976888E-DC7B-456C-A62F-44EA07ED231F}"
[HKEY_CLASSES_ROOT\CLSID\{B976888E-DC7B-456C-A62F-44EA07ED231F}]
2010-01-17 22:50 503808 ----a-w- c:\program files (x86)\Gestionnaire de sauvegarde du Coffre-fort personnel\VaultClientMenu.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Facebook Update"="c:\users\User\AppData\Local\Facebook\Update\FacebookUpdate.exe" [2011-11-14 137536]
"Akamai NetSession Interface"="c:\users\User\AppData\Local\Akamai\netsession_win.exe" [2012-03-13 3331872]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"HControlUser"="c:\program files (x86)\ASUS\ATK Hotkey\HControlUser.exe" [2009-06-19 105016]
"ATKMEDIA"="c:\program files (x86)\ASUS\ATK Media\DMedia.exe" [2009-08-20 170624]
"ATKOSD2"="c:\program files (x86)\ASUS\ATKOSD2\ATKOSD2.exe" [2009-08-17 6859392]
"avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2011-04-21 281768]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
"ADSMTray"="c:\program files (x86)\ASUS\ASUS Data Security Manager\ADSMTray.exe" [2009-06-24 272952]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
.
c:\users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
FancyStart daemon.lnk - c:\users\User\AppData\Roaming\Microsoft\Installer\{F0DF4513-3C4C-4EB8-8012-2C5F70AF3988}\_A1DDD39913A1970387B7B3.exe [2011-10-14 12862]
OpenOffice.org 3.3.lnk - c:\program files (x86)\OpenOffice.org 3\program\quickstart.exe [2010-12-13 1198592]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2011-11-7 110592]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
"EnablELUA"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ PDBoot.exe\0autocheck autochk *
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\bdfsfltr]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Radialpoint Security Services]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\scan]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ServicepointService]
@="Service"
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Service Google Update (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-11-04 136176]
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-05 253600]
R3 AmUStor;AM USB Storage Driver;c:\windows\system32\drivers\AmUStor.SYS [x]
R3 gupdatem;Service Google Update (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-11-04 136176]
R3 ipswuio;ipswuio;c:\windows\system32\DRIVERS\ipswuio.sys [x]
R3 WatAdminSvc;Service Windows Activation Technologies;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]
S0 RadialpointIDSEH;RadialpointIDSEH;c:\windows\SysWOW64\drivers\AVGIDSEH.sys [2009-11-02 27144]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928]
S2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe [2009-07-14 27136]
S2 AntiVirSchedulerService;Avira AntiVir Planificateur;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [2011-04-21 136360]
S2 ASMMAP64;ASMMAP64;c:\program files\ATKGFNEX\ASMMAP64.sys [2007-07-24 14904]
S2 McciCMService64;McciCMService64;c:\program files\Common Files\Motive\McciCMService.exe [2010-01-27 517632]
S2 Radialpoint Security Services;Security Services Internet Bell;c:\program files (x86)\Bell\Services de sécurité Internet de Bell\RpsSecurityAwareR.exe [2011-10-19 166944]
S2 RadialpointIDSAgent;RadialpointIDSAgent;c:\program files (x86)\Bell\Services de sécurité Internet de Bell\AVG\Identity Protection\agent\Bin\AVGIDSAgent.exe RadialpointIDSAgent [x]
S2 ServicepointService;ServicepointService;c:\program files (x86)\Bell\Internet Service Advisor\ServicepointService.exe [2011-01-06 689464]
S2 VaultClientSRV;Gestionnaire de sauvegarde du Coffre-fort personnel : Service;c:\program files (x86)\Gestionnaire de sauvegarde du Coffre-fort personnel\VaultClientSRV.exe [2010-01-17 1051728]
S2 VaultClientUpgrade;Gestionnaire de sauvegarde du Coffre-fort personnel : Service de mise à niveau;c:\program files (x86)\Gestionnaire de sauvegarde du Coffre-fort personnel\VaultClientUpgrade.exe [2010-01-17 56400]
S3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\DRIVERS\ETD.sys [x]
S3 RadialpointIDSDriver;RadialpointIDSDriver;c:\program files (x86)\Bell\Services de sécurité Internet de Bell\AVG\Identity Protection\agent\drivers\AVGIDSDriver.sys [2009-11-02 132616]
S3 RadialpointIDSFilter;RadialpointIDSFilter;c:\program files (x86)\Bell\Services de sécurité Internet de Bell\AVG\Identity Protection\agent\drivers\AVGIDSFilter.sys [2009-11-02 35848]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
Akamai REG_MULTI_SZ Akamai
.
Scheduled Tasks Content
.
2012-04-06 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-05 16:01]
.
2012-04-05 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1644895072-118749312-2925343052-1000Core.job
- c:\users\User\AppData\Local\Facebook\Update\FacebookUpdate.exe [2011-11-14 17:16]
.
2012-04-06 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1644895072-118749312-2925343052-1000UA.job
- c:\users\User\AppData\Local\Facebook\Update\FacebookUpdate.exe [2011-11-14 17:16]
.
2012-04-06 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-11-04 16:05]
.
2012-04-06 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-11-04 16:05]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ADSMOverlayIcon1]
@="{A8D448F4-0431-45AC-9F5E-E1B434AB2249}"
[HKEY_CLASSES_ROOT\CLSID\{A8D448F4-0431-45AC-9F5E-E1B434AB2249}]
2007-06-01 20:52 159744 ----a-w- c:\program files (x86)\asus\ASUS Data Security Manager\ShlExt\x64\OverlayIconShlExt1_64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AmIcoSinglun64"="c:\program files (x86)\AmIcoSingLun\AmIcoSinglun64.exe" [2009-09-01 323584]
"ETDWare"="c:\program files\Elantech\ETDCtrl.exe" [2009-07-30 617856]
"BellCanada_McciTrayApp"="c:\program files\BellCanada\McciTrayApp.exe" [2010-01-19 3432448]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Examen supplémentaire -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = about:blank
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = <local>
IE: &Envoyer à OneNote - c:\progra~2\MICROS~4\Office14\ONBttnIE.dll/105
IE: E&xporter vers Microsoft Excel - c:\progra~2\MICROS~4\Office14\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.2.1
FF - ProfilePath - c:\users\User\AppData\Roaming\Mozilla\Firefox\Profiles\yagfxn8z.default\
.
- - - - ORPHELINS SUPPRIMES - - - -
.
URLSearchHooks-{05eeb91a-aef7-4f8a-978f-fb83e7b03f8e} - (no file)
WebBrowser-{05EEB91A-AEF7-4F8A-978F-FB83E7B03F8E} - (no file)
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Akamai]
"ServiceDll"="C:/Program Files (x86)/Common Files/Akamai/netsession_win_6c825ce.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Akamai]
"ServiceDll"="C:/Program Files (x86)/Common Files/Akamai/netsession_win_6c825ce.dll"
.
--------------------- BLOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-1644895072-118749312-2925343052-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WindowsLiveMail.Email.1"
.
[HKEY_USERS\S-1-5-21-1644895072-118749312-2925343052-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WindowsLiveMail.VCard.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_2_202_228_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_2_202_228_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_228.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_228.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_228.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_228.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Other active processes ------------------------
.
c:\program files (x86)\Bell\Services de sécurité Internet de Bell\Fws.exe
c:\program files (x86)\ASUS\ASUS Data Security Manager\ADSMSrv.exe
c:\program files (x86)\ASUS\ATK Hotkey\ASLDRSrv.exe
c:\program files\ATKGFNEX\GFNEXSrv.exe
c:\program files (x86)\Bell\Services de sécurité Internet de Bell\AVG\Identity Protection\agent\Bin\AVGIDSAgent.exe
c:\program files (x86)\ASUS\Net4Switch\Net4Switch.exe
c:\program files (x86)\ASUS\ControlDeck\ControlDeckStartUp.exe
c:\program files (x86)\ASUS\SmartLogon\sensorsrv.exe
c:\program files (x86)\Bell\Services de sécurité Internet de Bell\rps.exe
c:\program files (x86)\ASUS\ATK Hotkey\HControl.exe
c:\program files (x86)\Common Files\Motive\McciContextHookShim.exe
c:\program files (x86)\Avira\AntiVir Desktop\avguard.exe
c:\program files (x86)\Common Files\Motive\McciCMService.exe
c:\program files (x86)\asus\NB Probe\SPM\spmgr.exe
c:\program files (x86)\Bell\Internet Service Advisor\BISAComHandler.exe
c:\program files (x86)\ASUS\ATK Hotkey\ATKOSD.exe
c:\program files (x86)\ASUS\ATK Hotkey\WDC.exe
c:\program files (x86)\Bell\Services de sécurité Internet de Bell\AVG\Identity Protection\agent\Bin\AVGIDSMonitor.exe
c:\program files (x86)\Bell\Internet Service Advisor\BISA.exe
c:\program files (x86)\Common Files\Java\Java Update\jucheck.exe
.
**************************************************************************
.
Finish time: 2012-04-05 21:50:04 - The machine rebooted
ComboFix-quarantined-files.txt 2012-04-06 01:50
.
Before CF: 282 898 624 512 bytes free
After CF: 287 035 514 880 bytes free
.
- - End Of File - - F9F0741B57B24D53E0CA32332FEBE95E -
g3n-h@ckm@nyou have two antivirus...
--
¤¤¤¤¤¤¤¤¤¤_g3n-h@ckm@n_Developpement_¤¤¤¤¤¤¤¤¤¤
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤_Pre_Scan_¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ -
Mel (Les Amy de Sonic)Yeah, but that’s not the problem (I think). The two of them have been freaking out since yesterday, sending me alerts saying a virus was detected, but once the alerts start, they don’t stop (they’re doing nearly 20 of them). It took 20 hours to do the second one (the one tied to my internet provider). It found 168 infections (which I deleted, of course); the other found nothing. My computer is slow, it doesn’t make sense. I just had to download earlier in Safe Mode because otherwise I’d still be here.
Should I delete one of the two? If yes, which one would you recommend I keep?
EDIT: Do you see anything fishy in my report?
Thanks -
g3n-h@ckm@nI hope this isn’t what I think it is...
delete the winlogon you downloaded earlier, re-download it - and run it in Safe Mode to see if it passes....
on the menu that will appear, click on "Kill - Start the scan"
--
¤¤¤¤¤¤¤¤¤¤_g3n-h@ckm@n_Developpement_¤¤¤¤¤¤¤¤¤¤
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤_Pre_Scan_¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ -
Mel (Les Amy de Sonic)I’m in Safe Mode and I have the same error.
-
g3n-h@ckm@noh really...? I’d like to understand.. host the report located at c:\as indicated
--
¤¤¤¤¤¤¤¤¤¤_g3n-h@ckm@n_Developpement_¤¤¤¤¤¤¤¤¤¤
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤_Pre_Scan_¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ -
Mel (Les Amy de Sonic)http://pjjoint.malekal.com/files.php?id=20120406_z11v13f14s6n7
-
g3n-h@ckm@ndelete pre_scan all the versions you have re-download-them and restart it
--
¤¤¤¤¤¤¤¤¤¤_g3n-h@ckm@n_Developpement_¤¤¤¤¤¤¤¤¤¤
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤_Pre_Scan_¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ -
Mel (Les Amy de Sonic)It still doesn’t work; I tried in normal mode and in safe mode, and I still get the same error message.
-
g3n-h@ckm@nwell it's an old guy you rebooted
--
¤¤¤¤¤¤¤¤¤¤_g3n-h@ckm@n_Developpement_¤¤¤¤¤¤¤¤¤¤
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤_Pre_Scan_¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ -
Mel (Les Amy de Sonic)No, I had deleted them all and I re-downloaded them as you asked me to.
-
g3n-h@ckm@n- Download ZHPDiag (by Nicolas Coolman)
or :ZHPDiag
- Save it to your Desktop.
Once the download is complete,
- Install and launch ZHPDiag.exe
- Click the screwdriver and then Choose All to check all the option boxes.
- Click the magnifying glass to start the scan.
At the end of the scan,
- click the camera and save the report to your Desktop.
Host the report on https://www.cjoint.com/ and provide the obtained link
--
¤¤¤¤¤¤¤¤¤¤_g3n-h@ckm@n_Developpement_¤¤¤¤¤¤¤¤¤¤
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤_Pre_Scan_¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ -
Mel (Les Amy de Sonic)http://cjoint.com/?BDgvr017Kog
-
g3n-h@ckm@n▶ Download On this page: AdwCleaner (by Xplode)
▶ Click on Download and save the file to your Desktop
▶ Double-click the AdwCleaner0.exe icon to start the installation
==================================
▶▶▶ Under Vista and Windows 7 /!\ :
you must run the file by right-clicking -> Run as administrator
==================================
On the main menu:
▶ click on Removal and wait for the analysis
▶ post the contents of the report that you will find on your hard drive c:\ADwcleaner[Sx].txt or its contents if it opens.
--
¤¤¤¤¤¤¤¤¤¤_g3n-h@ckm@n_Developpement_¤¤¤¤¤¤¤¤¤¤
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤_Pre_Scan_¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ -
Mel (Les Amy de Sonic)# AdwCleaner v1.504 - Report created on 06/04/2012 at 16:26:28
# Updated on 01/04/2012 by Xplode
# Operating system: Windows 7 Home Premium (64-bit)
# Username: User - USER-PC
# Executed from: C:\Users\User\Downloads\adwcleaner.exe
# Option [Removal]
***** [Services] *****
***** [Files / Folders] *****
Deleted Folder: C:\ProgramData\Babylon
Deleted Folder: C:\Users\User\AppData\Roaming\Babylon
Deleted Folder: C:\Users\User\AppData\LocalLow\BabylonToolbar
Deleted Folder: C:\Users\User\AppData\LocalLow\Conduit
Deleted Folder: C:\Users\User\AppData\LocalLow\PriceGong
Deleted Folder: C:\Program Files (x86)\Conduit
***** [H. Navipromo] *****
***** [Registry] *****
[*] Key Deleted: HKLM\SOFTWARE\Classes\Toolbar.CT2851639
Deleted Key: HKCU\Software\AppDataLow\Software\Conduit
Deleted Key: HKCU\Software\AppDataLow\Software\PriceGong
Deleted Key: HKLM\SOFTWARE\Babylon
Deleted Key: HKLM\SOFTWARE\Conduit
Deleted Key: HKLM\SOFTWARE\Classes\AppID\escort.DLL
Deleted Key: HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4eaf-B541-F8DE92DD98DB}
Deleted Key: HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}
Deleted Key: HKLM\SOFTWARE\Classes\CLSID\{3c471948-f874-49f5-b338-4f214a2ee0b1}
Deleted Key: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}
Deleted Key: HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}
Deleted Key: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{97F2FF5B-260C-4ccf-834A-2DDA4E29E39E}
***** [Registry (x64)] *****
***** [Browsers] *****
-\\ Internet Explorer v9.0.8112.16421
[OK] The registry contains no illegitimate entries.
-\\ Mozilla Firefox v8.0 (fr)
Profile name: default
File: C:\Users\User\AppData\Roaming\Mozilla\FireFox\Profiles\yagfxn8z.default\prefs.js
[OK] The file does not contain any illegitimate entries.
*************************
AdwCleaner[S1].txt - [2054 octets] - [06/04/2012 16:26:28]
########## EOF - C:\AdwCleaner[S1].txt - [2182 octets] ########## -
- 1
- 2
- 3
Next