Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Rogue Antivirus
#14
  • Step 20

    Please run HijackThis as an administrator. Click Do a system scan only and place a check next to the following line(s) if present:

    F2 - REGConfusedystem.ini: UserInit=userinit.exe
    O4 - HKLM\..\Run: [cftmon] C:\Windows\system32\gvjhu.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKUS\S-1-5-18\..\Run: [D1T2EUR7FZ] C:\Windows\TEMP\Lbe.exe (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [D1T2EUR7FZ] C:\Windows\TEMP\Lbe.exe (User 'Default user')


    Then, close all other open windows and click Fix Checked. You are to reboot your system afterwards.

    If you are having a problem running HijackThis as an administrator (Windows Vista and Windows 7), please follow the steps below.
    • On your desktop, right-click the HijackThis icon and select Properties.
    • Navigate to the Compatibility tab and put a check on the Run this program as an administrator box.
    • Click Apply > OK.
    • HijackThis should prompt you to run it as an administrator every time you open it.
  • Step 21

    Please download the OldTimer's Move-It (OTM) from 'here'.
    • Save it to your desktop.
    • Please double-click OTM.exe to run it.
    • Copy the lines inside the Code box below to the Clipboard by highlighting all of the content and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

      Code:
      :Processes
      explorer.exe

      :Files
      c:\windows\system32\gvjhu.exe
      c:\windows\temp\Lbe.exe
      c:\users\tyler\appdata\roaming\8BD3CBF1A238C722473BB8C7B3E545D4
      c:\users\tyler\appdata\roaming\microsoft\installer\{45a66726-69bc-466b-a7a4-12fcba4883d7}\HiJackThis.exe
      c:\windows\system32\drivers\gkfgefdi.sys

      :Commands
      [purity]
      [emptytemp]
      [start explorer]
      [Reboot]
    • Return to OTM, right-click in the Paste Instructions for Items to be Moved window and choose Paste.
    • Click the red MoveIt! button.
    • Copy everything in the Results window to the Clipboard by highlighting all of the content and by pressing CTRL + C (or, after highlighting, right-click and choose Copy).
    • Paste it in your next reply.
    • Close OTM.

    Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the moving process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start > All Programs > Accessories > Notepad) and click File > Open. In the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest log file present. Copy and paste the contents of that document back here in your next post.
  • Step 22

    Please download OldTimer ListIt (OTL) from 'here'. Please click the Go (Arrow Button) or press Enter in the URL address bar to start the download.
    • Save it to your desktop.
    • Please double-click OTL.exe to run it.
    • Make sure all other windows are closed to let it run uninterrupted.
    • Under the Custom Scan box paste this in:

      Code:
      %systemroot%\*. /mp /s
      %systemroot%\system32\*.dll /lockedfiles
      %systemroot%\system32\*.exe /lockedfiles
      %systemroot%\Tasks\*.job /lockedfiles
      %systemroot%\system32\drivers\*.sys /lockedfiles
      %systemroot%\System32\config\*.sav
      %systemroot%\system32\*.sys
      %systemroot%\system32\drivers\*.dll
      %systemroot%\system32\drivers\*.ini
      %systemroot%\system32\drivers\*.exe
      %SYSTEMDRIVE%\*.*
      %PROGRAMFILES%\*.
      %appdata%\*.*
      netsvcs
      msconfig
      safebootminimal
      safebootnetwork
      activex
      drivers32
      /md5start
      eventlog.dll
      scecli.dll
      netlogon.dll
      cngaudit.dll
      sceclt.dll
      ntelogon.dll
      logevent.dll
      iaStor.sys
      nvstor.sys
      atapi.sys
      IdeChnDr.sys
      viasraid.sys
      AGP440.sys
      vaxscsi.sys
      nvatabus.sys
      viamraid.sys
      nvata.sys
      nvgts.sys
      iastorv.sys
      ViPrt.sys
      eNetHook.dll
      ahcix86.sys
      KR10N.sys
      disk.sys
      nvstor32.sys
      ahcix86s.sys
      nvrd32.sys
      symmpi.sys
      adp3132.sys
      mv61xx.sys
      usbstor.sys
      /md5stop
      CREATERESTOREPOINT
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs
    • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan won't take long.
    • When the scan completes, it will open two Notepad windows.
      • OTL.txt
      • Extras.txt
    • These are saved in the same location as OTL.
    • Please copy (Right-click > Select All > Copy) the contents of these files, one at a time, and post it with your next reply.
  • In your next post, please provide the following:
    • A Fresh HijackThis (HJT) Log
    • ComboFix Log
    • Doesn't Do Squat (DDS) Logs
      • DDS.txt
      • Attach.txt
    • OTL Log
    • OTM Log
  • Format of Response

    Code:
    [b]Step # [/b]
    [b]Problems Encountered: [/b]

    [b]Step # [/b]
    [b]Problems Encountered: [/b]

    [b]Step # [/b]
    [b]Problems Encountered: [/b]

    [b]Step # [/b]
    [b]Problems Encountered: [/b]

    [b]Link To Requested Logs: [/b]
  • Comments:
    • Try running ComboFix by running this in the Run prompt: "%userprofile%\desktop\combofix.exe"
    • If you get another BSOD, please do so in Safe Mode.


Messages In This Thread
Rogue Antivirus - by Deltron - 04-19-2011, 11:19 PM
RE: Rogue Antivirus - by Quintus - 04-20-2011, 07:39 AM
RE: Rogue Antivirus - by Quintus - 04-20-2011, 11:40 PM
RE: Rogue Antivirus - by AceInfinity - 04-21-2011, 01:36 AM
RE: Rogue Antivirus - by Deltron - 04-21-2011, 11:18 AM
RE: Rogue Antivirus - by Quintus - 04-22-2011, 04:14 AM
RE: Rogue Antivirus - by Deltron - 04-22-2011, 05:58 PM
RE: Rogue Antivirus - by Quintus - 04-23-2011, 07:02 AM
RE: Rogue Antivirus - by Deltron - 04-23-2011, 02:23 PM
RE: Rogue Antivirus - by Deltron - 04-23-2011, 06:05 PM
RE: Rogue Antivirus - by Quintus - 04-23-2011, 06:24 PM
RE: Rogue Antivirus - by Deltron - 04-23-2011, 06:46 PM
RE: Rogue Antivirus - by Quintus - 04-23-2011, 06:49 PM
RE: Rogue Antivirus - by Deltron - 04-23-2011, 07:01 PM
RE: Rogue Antivirus - by Quintus - 04-23-2011, 07:04 PM
RE: Rogue Antivirus - by Deltron - 04-23-2011, 07:09 PM
RE: Rogue Antivirus - by Quintus - 04-23-2011, 07:15 PM
RE: Rogue Antivirus - by Deltron - 04-23-2011, 07:22 PM
RE: Rogue Antivirus - by Quintus - 04-23-2011, 07:24 PM
RE: Rogue Antivirus - by Deltron - 04-23-2011, 07:31 PM
RE: Rogue Antivirus - by Quintus - 04-23-2011, 07:32 PM
RE: Rogue Antivirus - by Deltron - 04-23-2011, 07:34 PM
RE: Rogue Antivirus - by Quintus - 04-23-2011, 07:38 PM
RE: Rogue Antivirus - by Deltron - 04-23-2011, 07:38 PM
RE: Rogue Antivirus - by Quintus - 04-23-2011, 07:48 PM
RE: Rogue Antivirus - by Deltron - 04-23-2011, 07:51 PM
RE: Rogue Antivirus - by Quintus - 04-23-2011, 08:06 PM
RE: Rogue Antivirus - by Deltron - 04-23-2011, 08:15 PM
RE: Rogue Antivirus - by Quintus - 04-23-2011, 09:00 PM
RE: Rogue Antivirus - by Deltron - 04-23-2011, 09:16 PM
RE: Rogue Antivirus - by Quintus - 04-23-2011, 09:33 PM
RE: Rogue Antivirus - by Deltron - 04-23-2011, 09:35 PM
RE: Rogue Antivirus - by Quintus - 04-23-2011, 09:42 PM
RE: Rogue Antivirus - by Deltron - 04-23-2011, 09:43 PM
RE: Rogue Antivirus - by Quintus - 04-23-2011, 09:45 PM
RE: Rogue Antivirus - by Deltron - 04-23-2011, 09:47 PM
RE: Rogue Antivirus - by Quintus - 04-23-2011, 09:50 PM
RE: Rogue Antivirus - by Deltron - 04-23-2011, 09:52 PM
RE: Rogue Antivirus - by Quintus - 04-23-2011, 09:55 PM
RE: Rogue Antivirus - by Deltron - 04-23-2011, 09:56 PM
RE: Rogue Antivirus - by Quintus - 04-23-2011, 10:01 PM
RE: Rogue Antivirus - by Deltron - 04-23-2011, 10:08 PM
RE: Rogue Antivirus - by Quintus - 04-23-2011, 10:12 PM
RE: Rogue Antivirus - by Deltron - 04-23-2011, 10:19 PM
RE: Rogue Antivirus - by Quintus - 04-23-2011, 10:22 PM
RE: Rogue Antivirus - by Deltron - 04-23-2011, 10:24 PM
RE: Rogue Antivirus - by Quintus - 04-23-2011, 10:28 PM
RE: Rogue Antivirus - by Deltron - 04-23-2011, 10:30 PM
RE: Rogue Antivirus - by Quintus - 04-23-2011, 10:43 PM
RE: Rogue Antivirus - by Deltron - 04-23-2011, 10:51 PM
RE: Rogue Antivirus - by Quintus - 04-23-2011, 10:56 PM
RE: Rogue Antivirus - by Deltron - 04-23-2011, 10:57 PM
RE: Rogue Antivirus - by Quintus - 04-23-2011, 10:59 PM
RE: Rogue Antivirus - by Deltron - 04-23-2011, 11:00 PM
RE: Rogue Antivirus - by Quintus - 04-23-2011, 11:02 PM
RE: Rogue Antivirus - by Deltron - 04-23-2011, 11:10 PM
RE: Rogue Antivirus - by Quintus - 04-23-2011, 11:15 PM
RE: Rogue Antivirus - by Deltron - 04-23-2011, 11:17 PM
RE: Rogue Antivirus - by Quintus - 04-23-2011, 11:21 PM
RE: Rogue Antivirus - by Deltron - 04-23-2011, 11:28 PM
RE: Rogue Antivirus - by Deltron - 04-23-2011, 11:36 PM
RE: Rogue Antivirus - by Quintus - 04-23-2011, 11:36 PM
RE: Rogue Antivirus - by Deltron - 04-23-2011, 11:43 PM
RE: Rogue Antivirus - by Quintus - 04-24-2011, 12:06 AM
RE: Rogue Antivirus - by Deltron - 04-24-2011, 12:19 AM
RE: Rogue Antivirus - by Quintus - 04-24-2011, 12:30 AM
RE: Rogue Antivirus - by Deltron - 04-24-2011, 12:39 AM
RE: Rogue Antivirus - by Quintus - 04-24-2011, 12:43 AM
RE: Rogue Antivirus - by Deltron - 04-24-2011, 12:43 AM
RE: Rogue Antivirus - by Quintus - 04-24-2011, 12:46 AM
RE: Rogue Antivirus - by Deltron - 04-24-2011, 12:48 AM
RE: Rogue Antivirus - by Quintus - 04-24-2011, 12:50 AM
RE: Rogue Antivirus - by Deltron - 04-24-2011, 12:56 AM
RE: Rogue Antivirus - by Quintus - 04-24-2011, 12:58 AM
RE: Rogue Antivirus - by Deltron - 04-24-2011, 01:00 AM
RE: Rogue Antivirus - by Quintus - 04-24-2011, 01:02 AM
RE: Rogue Antivirus - by Deltron - 04-24-2011, 01:05 AM
RE: Rogue Antivirus - by Quintus - 04-24-2011, 04:03 AM
RE: Rogue Antivirus - by Deltron - 04-24-2011, 06:13 AM
RE: Rogue Antivirus - by Quintus - 04-24-2011, 06:29 AM
RE: Rogue Antivirus - by Deltron - 04-24-2011, 08:00 AM
RE: Rogue Antivirus - by Quintus - 04-24-2011, 08:17 AM
RE: Rogue Antivirus - by Deltron - 04-24-2011, 09:22 AM
RE: Rogue Antivirus - by Deltron - 04-24-2011, 11:16 AM
RE: Rogue Antivirus - by Quintus - 04-24-2011, 10:56 PM
RE: Rogue Antivirus - by Deltron - 04-25-2011, 08:50 AM
RE: Rogue Antivirus - by Quintus - 04-25-2011, 10:55 PM
RE: Rogue Antivirus - by Deltron - 04-25-2011, 11:06 PM
RE: Rogue Antivirus - by Quintus - 04-25-2011, 11:12 PM
RE: Rogue Antivirus - by Deltron - 04-25-2011, 11:13 PM
RE: Rogue Antivirus - by Quintus - 04-25-2011, 11:15 PM
RE: Rogue Antivirus - by Deltron - 04-25-2011, 11:16 PM
RE: Rogue Antivirus - by Quintus - 04-25-2011, 11:37 PM
RE: Rogue Antivirus - by Deltron - 04-26-2011, 07:05 PM
RE: Rogue Antivirus - by Quintus - 04-27-2011, 12:47 AM
RE: Rogue Antivirus - by Deltron - 04-27-2011, 01:13 AM
RE: Rogue Antivirus - by Quintus - 04-27-2011, 03:51 AM
RE: Rogue Antivirus - by Deltron - 04-27-2011, 07:00 AM
RE: Rogue Antivirus - by Quintus - 04-27-2011, 07:48 AM
RE: Rogue Antivirus - by Deltron - 04-27-2011, 07:53 AM
RE: Rogue Antivirus - by Quintus - 04-27-2011, 09:27 AM
RE: Rogue Antivirus - by Deltron - 04-27-2011, 10:58 AM
RE: Rogue Antivirus - by Quintus - 04-27-2011, 07:10 PM
RE: Rogue Antivirus - by Deltron - 04-27-2011, 07:33 PM
RE: Rogue Antivirus - by Quintus - 04-27-2011, 07:50 PM
RE: Rogue Antivirus - by Deltron - 04-27-2011, 07:54 PM
RE: Rogue Antivirus - by Deltron - 04-27-2011, 09:29 PM
RE: Rogue Antivirus - by Quintus - 04-27-2011, 10:10 PM
RE: Rogue Antivirus - by Deltron - 04-27-2011, 10:41 PM
RE: Rogue Antivirus - by Quintus - 04-27-2011, 10:51 PM
RE: Rogue Antivirus - by Deltron - 04-27-2011, 11:03 PM
RE: Rogue Antivirus - by Quintus - 04-27-2011, 11:07 PM
RE: Rogue Antivirus - by Deltron - 04-27-2011, 11:07 PM
RE: Rogue Antivirus - by Quintus - 04-27-2011, 11:23 PM
RE: Rogue Antivirus - by Deltron - 04-27-2011, 11:44 PM
RE: Rogue Antivirus - by Quintus - 04-28-2011, 12:21 AM
RE: Rogue Antivirus - by Deltron - 04-28-2011, 07:18 AM
RE: Rogue Antivirus - by Quintus - 04-28-2011, 07:33 AM
RE: Rogue Antivirus - by Deltron - 04-28-2011, 07:38 AM
RE: Rogue Antivirus - by Quintus - 04-28-2011, 08:09 AM
RE: Rogue Antivirus - by Deltron - 04-28-2011, 04:00 PM
RE: Rogue Antivirus - by AceInfinity - 04-28-2011, 04:06 PM
RE: Rogue Antivirus - by Deltron - 04-28-2011, 04:17 PM
RE: Rogue Antivirus - by AceInfinity - 04-28-2011, 04:30 PM
RE: Rogue Antivirus - by Deltron - 04-28-2011, 08:59 PM
RE: Rogue Antivirus - by Deltron - 04-29-2011, 12:21 AM
RE: Rogue Antivirus - by Quintus - 04-29-2011, 03:58 AM
RE: Rogue Antivirus - by Deltron - 04-29-2011, 07:35 AM
RE: Rogue Antivirus - by Quintus - 04-30-2011, 07:28 AM

Possibly Related Threads…
Thread Author Replies Views Last Post
  Vista security 2011 Rogue anti-virus help! Mr. Jewtastic 8 3,100 05-08-2011, 07:46 PM
Last Post: Quintus

Forum Jump:


Users browsing this thread: 2 Guest(s)