Author Topic: DEVASTATION!  (Read 12921 times)

0 Members and 1 Guest are viewing this topic.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: DEVASTATION!
« Reply #30 on: June 18, 2011, 09:05:38 PM »
What did it find ? as that is the setup and self check log

tanzanos

  • Guest
Re: DEVASTATION!
« Reply #31 on: June 19, 2011, 07:08:27 AM »
I don't know as it did not mention them. All it said was "Attention, viruses have been found during the scan RC (......". Also it does not complete in order to reach the point where a scan log is made. The report I posted is all that is generated and there are no other folders in the C/USERS/..../DR Web folder apart from the report I attached.  ??? Dr Web only runs after normal boot; It does not run properly in Safe boot mode.

I run tdsskiller and it found the following:

2011/06/19 09:22:19.0679 4196   Detected object count: 1
2011/06/19 09:22:19.0679 4196   Actual detected object count: 1
2011/06/19 09:22:40.0193 4196   sptd            (34f974f8b3c86de03a30dcbe79091c97) C:\Windows\system32\Drivers\sptd.sys
2011/06/19 09:22:40.0193 4196   Suspicious file (NoAccess): C:\Windows\system32\Drivers\sptd.sys. md5: 34f974f8b3c86de03a30dcbe79091c97
2011/06/19 09:22:40.0193 4196   C:\Windows\system32\Drivers\sptd.sys - copied to quarantine
2011/06/19 09:22:40.0208 4196   LockedFile.Multi.Generic(sptd) - User select action: Quarantine
« Last Edit: June 19, 2011, 08:25:47 AM by tanzanos »

tanzanos

  • Guest
Re: DEVASTATION!
« Reply #32 on: June 19, 2011, 09:07:55 AM »
I tried Dr web once more in safe mode and this time it completed the scan and found nothing? Before it had found viruses but could not complete the scan? This is very weird. Something is disabling security center. Something is hiding the Avast icon in the toolbar and only when I run Avast again does it show up. Something is redirecting on both web browsers?

I really need to kill this bug(s). A reformat is almost out of the question!

Someone must know how to find and DESTROY this bug?

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: DEVASTATION!
« Reply #33 on: June 19, 2011, 11:36:13 AM »
Lets review all your start up elements

Please RIGHT-CLICK HERE and Save As (in IE it's "Save Target As", in FF it's "Save Link As") to download Silent Runners.
  • Save it to the desktop.
  • Run Silent Runner's by doubleclicking the "Silent Runners" icon on your desktop.
  • You will receive a prompt:
    Do you want to skip supplementary searches?
    click NO
    [/list]
    • If you receive an error just click OK and double-click it to run it again - sometimes it won't run as it's supposed to the first time but will in subsequent runs.
    • You will see a text file appear on the desktop - it's not done, let it run (it won't appear to be doing anything!)
    • Once you receive the prompt All Done!, open the text file on the desktop, copy that entire log, and attach it here.
    *NOTE* If you receive any warning message about scripts, please choose to allow the script to run.

    tanzanos

    • Guest
    Re: DEVASTATION!
    « Reply #34 on: June 19, 2011, 02:25:27 PM »
    I went to the registry that was pointed out by spybot and changed START from 3(manual start) to 2(automatic start) Then I uninstalled, rebooted and reinstalled Avast. now it seems that I no longer have a problem. Security centre is working. Avast is working, and I do not see any redirects in my browsers. I hope that this is not a temporary situation.

    Please find attached the report you requested. EB, I truly wish to thank you for all the time and effort you have put into helping resolve my problem. Something must have worked!  ;D

    Offline essexboy

    • Malware removal instructor
    • Avast Überevangelist
    • Probably Bot
    • *****
    • Posts: 40589
    • Dragons by Sasha
      • Malware fixes
    Re: DEVASTATION!
    « Reply #35 on: June 19, 2011, 03:22:31 PM »
    Sometimes that happens - the blindingly obvious is missed

    That will be a permanent solution, but at least now you can be fairly confident that nothing is lurking

    Leave it run for a day or so before I remove my tools just to be sure 

    tanzanos

    • Guest
    Re: DEVASTATION!
    « Reply #36 on: June 20, 2011, 06:57:06 AM »
    Thanks a million mate ;D I shall wait and will let you know if this bug returns! And now for some Government virus cleaning (we are cleaning our parliament off corrupt MPs)This is the worst type of virus! It corrupts all of society!

    Once more thank you!

    tanzanos

    • Guest
    Re: DEVASTATION!
    « Reply #37 on: June 21, 2011, 07:52:10 AM »
    Something is not right! EB, this bug must have done something to my system; when I go to this link and scroll down to the bottom I see html code?????
    http://www.icrass.com/component/content/article/34-demo-category/58-international-center-for-robotics-and-advanced-space-studies.html

    Offline DavidR

    • Avast Überevangelist
    • Certainly Bot
    • *****
    • Posts: 89154
    • No support PMs thanks
    Re: DEVASTATION!
    « Reply #38 on: June 21, 2011, 01:55:39 PM »
    You can see it in firefox also, so it is more to do with botched code on the page not hiding that.
    Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

    Offline Asyn

    • Avast Überevangelist
    • Certainly Bot
    • *****
    • Posts: 76035
      • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
    Re: DEVASTATION!
    « Reply #39 on: June 21, 2011, 02:03:15 PM »
    You can see it in firefox also, so it is more to do with botched code on the page not hiding that.

    Confirming this.
    No idea, if it's bad coding or for purpose - no time to analyse.
    But it is not related to your prior problem. ;)
    W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
    Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
    Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

    tanzanos

    • Guest
    Re: DEVASTATION!
    « Reply #40 on: June 26, 2011, 03:06:48 PM »
    TDSSKILLER has quarantined the following file:
    [InfectedFile]
    Type: Raw image
    Src: C:\Windows\system32\Drivers\sptd.sys
    md5: 34f974f8b3c86de03a30dcbe79091c97

    Is this a false positive? If yes then how do I un-quarantine it?

    Offline essexboy

    • Malware removal instructor
    • Avast Überevangelist
    • Probably Bot
    • *****
    • Posts: 40589
    • Dragons by Sasha
      • Malware fixes
    Re: DEVASTATION!
    « Reply #41 on: June 26, 2011, 03:57:38 PM »
    Do you use daemon tolls ?  If not then ignore it

    Dch48

    • Guest
    Re: DEVASTATION!
    « Reply #42 on: June 26, 2011, 08:22:17 PM »
    You can see it in firefox also, so it is more to do with botched code on the page not hiding that.
    It's like that in Chrome too.

    tanzanos

    • Guest
    Re: DEVASTATION!
    « Reply #43 on: June 27, 2011, 03:06:27 PM »
    Do you use daemon tolls ?  If not then ignore it
    Yes I use Daemon tools. Some progs don't work now. How can I un quarantine the file?

    Offline essexboy

    • Malware removal instructor
    • Avast Überevangelist
    • Probably Bot
    • *****
    • Posts: 40589
    • Dragons by Sasha
      • Malware fixes
    Re: DEVASTATION!
    « Reply #44 on: June 27, 2011, 07:12:02 PM »
    I would download a fresh copy from here to be on the safe side
    http://www.duplexsecure.com/downloads