Avast antivirus detecting a lot of viruses. Help

Discussion in 'Malware Help (A Specialist Will Reply)' started by B0uchb, Sep 2, 2008.

  1. B0uchb

    B0uchb Private E-2

    While surfing the internet about two to three weeks ago my avast antivirus program was flooded with malware and viruses. Everytime I would try to go on line a new virues would pop up and it avast would not allow me to place them into the virus chest. I also ran ad aware, and it would find viruses but would never stop them. My computers screen background changed to a fake anti virus removal scheme, and a red ball with a white x on it appeared in the tray. It said i was infected with winfsbanker amoung others. A lot of small text boxes keep appearing to, saying that my system had crashed. I have since then run your Win xp cleanup procedures and it appears to be better now. My clock is still reading 01:30 at 1:30 and so on and it appears to be running slower. The computer is a compaq presario, operating windows xp with service pack 3 which I recently downloaded. I think my computer still may be infected, can you please help me.
     

    Attached Files:

    Last edited: Sep 2, 2008
  2. B0uchb

    B0uchb Private E-2

    additional logs
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I need the full MGLogs.zip...not the individual logs.....and I am assuming that you made the agreement to run HJT which would be part of that log.
     
  4. B0uchb

    B0uchb Private E-2

    This should do it, Sorry.
     

    Attached Files:

  5. B0uchb

    B0uchb Private E-2

    I ran my avast antivirus last night and it once again picked up a ton of infected files such as MFEX-104.dat and A0067550.dll in C:system volume information_restore. I also downloaded a new firewall and it says that a trojan program is trying to download. Does that mean that Avast is infected? I can send you my avast logs too if need be.
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I don't know what your fire wall was reporting or if you have it set to allow Avast to update.

    And the files Avast is frporting are in your system restore folder which we will deal with when we finish getting you clean.

    Please use add/remove programs to uninstall:
    J2SE Runtime Environment 5.0 Update 11"
    J2SE Runtime Environment 5.0 Update 8"
    Java(TM) 6 Update 2"
    Java(TM) 6 Update 3"
    Java(TM) SE Runtime Environment 6 Update 1

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\%username%\Local Settings\Temp

    Now download and install:
    Java Runtime 6

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Be sure to tell us how things are running.
     
  7. B0uchb

    B0uchb Private E-2

    Hey sorry it took so long for me to get back to you. I got rid of all the runtime programs. I then ran analyse.exe, and none of the quoted scripts were on my list except line 021 - ssodle. What do you want me to do now.
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please do that next. :)
     
  9. B0uchb

    B0uchb Private E-2

    Ok Im starting to show my computer illiteracy, kind of getting lost on what you want me to do. So Im just going to run down what I think you want me to do. First off I deleted all Java stuff, then ran analyse this and only found line 021 - ssodl. So what we are doing now with new MGlogs.exe and avenger is to help this, or should i have checked 021 and clicked fix and moved on. I am going to send you the new MGlogs file and avenger info and wait for your post. Sorry about this don't lose patience with me.
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What part of the instructions I gave you are you having problems with?

    Yes you should have checked fix and moved on to the next set of instructions.

    Is there a problem doing that part?

    What about this part:
     
  11. B0uchb

    B0uchb Private E-2

    Ok I think I finally did everything that you wanted me to do. Attached is the new avenger log, because I don't think I did the steps right last time around. I am still having problems with my computer clock. It is reading on a 24 hour clock period instead of 12. It reads 01:30 at 1:30 a.m. I am also having a problem downloading adobe flash player. I go to download it and nothing happens, just a small little box with a red x inside. I was also wondering now that everything appears to be back to noraml, what programs that you had me download should I keep around and which should I get rid of. Lastly my Avast anti virus program no longer boots up when I turn on the computer. Should I just delete it along with all logs and re-download it?
     

    Attached Files:

  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The last part of my instructions were:
     
  13. B0uchb

    B0uchb Private E-2

    Ok whatever I did today really screwed things up. When I click on start and find programs or when I click on my computer to rum MGtools my computer freezes. Today I ran fix on line 021 - ssodl:cfgComApi and then I merged Regedit4 with the registry like you asked. I then deleted files in Windows and now I can't send you anything because I can't get to anything.
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Can you boot into safe mode?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds