Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Cannot run any .exe to get rid of virus


  • This topic is locked This topic is locked

#16
p.ave

p.ave

    Member

  • Topic Starter
  • Member
  • PipPip
  • 27 posts
Here it isAttached File  mbrcheck811.txt   512bytes   308 downloads
  • 0

Advertisements


#17
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
It appears to be legitimate but, with the browsers opening it is still suspect, what is the make of your system ? i.e. Dell, HP or whatever

Download AVPTool from Here to your desktop

Run the programme you have just downloaded to your desktop (it will be randomly named )

First we will run a virus scan

Click the cog in the upper right
Posted Image


Select down to and including your main drive, once done select the Automatic scan tab and press Start Scan
Posted Image

Allow AVP to delete all infections found
Once it has finished select report tab (last tab)
Select Automatic Scan report from the left and press Save button
Save it to your desktop and attach to your next post


Now the Analysis

Rerun AVP and select the Manual Disinfection tab and press Start Gathering System Information

Posted Image

On completion click the link to locate the zip file to upload and attach to your next post

Posted Image
  • 0

#18
p.ave

p.ave

    Member

  • Topic Starter
  • Member
  • PipPip
  • 27 posts
the computer is an hp that is currently running slow. Kasp virus scan running.
  • 0

#19
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
OK that may explain the unknown MBR part - but the lack of access is concerning
  • 0

#20
p.ave

p.ave

    Member

  • Topic Starter
  • Member
  • PipPip
  • 27 posts
Tried to run Kasp twice, it finds things but then gets bogged down and stuck. Had to restart computer.
  • 0

#21
p.ave

p.ave

    Member

  • Topic Starter
  • Member
  • PipPip
  • 27 posts
Fake security protection is back...
  • 0

#22
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
OK lets replace the MBR and run another check

Re-Run aswMBR

Click Scan

On completion of the scan
Click the FIXMBR Button

Posted Image

Save the log as before and post in your next reply

THEN

Re-run Combofix and allow it to update, posting the log on completion
  • 0

#23
p.ave

p.ave

    Member

  • Topic Starter
  • Member
  • PipPip
  • 27 posts
I actually had restarted kasp. (its about 50% complete, but has taken 5+ hours) it detected 6 threats. Should i stop that to run MBR?
  • 0

#24
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
No continue with the AVP run and if possible run the analysis scan as well

If AVP finds the MBR infected and cleans it then there is no requirement for aswMBR. However, if AVP does not do anything to the MBR then run aswMBR
  • 0

#25
p.ave

p.ave

    Member

  • Topic Starter
  • Member
  • PipPip
  • 27 posts
Here is the AVP manual scan results. I zipped the auto scan results but it wouldn't attach.

Attached Files


  • 0

Advertisements


#26
p.ave

p.ave

    Member

  • Topic Starter
  • Member
  • PipPip
  • 27 posts
I'm guessing that its too big even zipped (~5 MB)
  • 0

#27
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
OK could you open AVP and on the manual disinfection tab click the link to avptool sysinfo.zip as that will be small enough to attach and contains the analysis run that I wil need to look at
  • 0

#28
p.ave

p.ave

    Member

  • Topic Starter
  • Member
  • PipPip
  • 27 posts
Here is the zip

Attached Files


  • 0

#29
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
OK I can now see the name of the driver, but not yet the location

  • Re-run AVPTool
  • Select the Manual Disinfection tab and press Script execution
    Posted Image
  • Where it states Insert text script in the following box copy the below script and press Run script
    Copy from Begin until End
    Posted Image
    begin
    SetAVZPMStatus(True);
    SetAVZGuardStatus(True);
    SearchRootkit(true, true);
     DeleteFile('C:\Documents and Settings\TEST\Local Settings\Temp\_uninst_43665347.bat');
     BC_DeleteFile('C:\Documents and Settings\TEST\Local Settings\Temp\_uninst_43665347.bat');
     DeleteFile('C:\WINDOWS\TEMP\12.tmp');
     BC_DeleteFile('C:\WINDOWS\TEMP\12.tmp');
     DeleteFile('C:\WINDOWS\TEMP\20.tmp');
     BC_DeleteFile('C:\WINDOWS\TEMP\20.tmp');
    BC_ImportDeletedList;
    BC_ImportAll;
    ExecuteSysClean;
    BC_Activate;
    RebootWindows(true);
    end.

  • Your system will reboot on completion, if it does not please do so yourself
  • On completion please run another analysis scan and attach the zip file

THEN

Re-run Combofix, allowing it to update if it asks
  • 0

#30
p.ave

p.ave

    Member

  • Topic Starter
  • Member
  • PipPip
  • 27 posts
here's the updated avp

Attached Files


  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP