Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

please help me! i have adware.CDN and my norton cant remove it!


  • This topic is locked This topic is locked

#181
dvk01

dvk01

    Malware Expert

  • Visiting Consultant
  • 201 posts
  • MVP
when avenger deletes a driver or service it reboots itself twice so don't do anything until it has rebooted itself for the second time
  • 0

Advertisements


#182
playsoldier3

playsoldier3

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 110 posts
Logfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Services\bqfetkrf

*******************

Script file located at: \??\C:\Documents and Settings\knxedefw.txt
Script file opened successfully.

Script file read successfully

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

Driver WinSSL unloaded successfully.
File C:\WINDOWS\System32\WinSSLRun.dll deleted successfully.
File C:\WINDOWS\System32\WinSSLCore.dll deleted successfully.


File C:\WINDOWS\loadssl.exe not found!
Deletion of file C:\WINDOWS\loadssl.exe failed!

Could not process line:
C:\WINDOWS\loadssl.exe
Status: 0xc0000034


Completed script processing.

*******************

Finished! Terminate.
  • 0

#183
dvk01

dvk01

    Malware Expert

  • Visiting Consultant
  • 201 posts
  • MVP
were there any other zip files in teh avenger folder

if so please upload them to spykiller

the one you uploaded was the previous deletions

the latest one is always just called backup.zip

earlier ones are backup_time & date.zip
  • 0

#184
playsoldier3

playsoldier3

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 110 posts
ok i posted the backup.zip :whistling:
  • 0

#185
dvk01

dvk01

    Malware Expert

  • Visiting Consultant
  • 201 posts
  • MVP
thanks got it

all the files are being submitted to all teh antivirus & antispyware companies to hopefuly stop it

some know some of it as trojan flood ads
  • 0

#186
playsoldier3

playsoldier3

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 110 posts
so what does trojan flood ads do?
i recently in the past few days made purchases online, does that mean credit card will be stolen?
  • 0

#187
dvk01

dvk01

    Malware Expert

  • Visiting Consultant
  • 201 posts
  • MVP
from waht I can see it isn't a password stealer or anything just floods you with adverts


teh analysis hasn't shown any info going out just more junk being downloaded

so you should be safe

it's always wise in these cases though to change all passwords & keep a close eye on bank or credit card & inform teh company if anything suspicious occurs
  • 0

#188
JSntgRvr

JSntgRvr

    Global Moderator

  • Global Moderator
  • 11,579 posts
Since this issue appears to be resolved ... this Topic has been closed. Glad we could help. :whistling:

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP