Can't Delete Trojan Agent3.CKJE or Trojan PSW.Generic10.AIXT from Steam

Posted 11/21/2012 8:53 AM
#94703
User avatar

flameofthewest Member

Date Joined Nov 2016
Total Posts: 5
Hi there, <br/> <br/>I just scanned my computer for viruses with AVG's Anti-Virus software. Unfortunately, AVG was unable to delete these trojans and after uninstalling Steam, which I don't use anymore anyway, the file remains in my Program Files folder and won't let me delete it. My computer is running much slower. <br/> <br/>Any deletion/fix help would be appreciated. <br/> <br/>Thanks, <br/> <br/>Sean
Posted 11/21/2012 10:12 AM
#94709
User avatar

Touch Advanced member

Date Joined Nov 2016
Total Posts: 12976
Hi Sean :smile: <br/> <br/> <br/> <br/> <br/>Please download Combofix from here: http://download.bleepingcomputer.com/sUBs/ComboFix.exe <br/> <br/> And save to the desktop. <br/> <br/>After the download is complete, perform the following tasks before using the ComboFix tool to scan your PC: <br/>Exit all windows that are currently open on your computer. <br/>To prevent interference, temporarily disable your antivirus, antispyware, firewall and other security tools that may be running on your computer. <br/> <br/> <br/>Double-click on the combofix icon found on your desktop. <br/> <br/>Please note, that once you start combofix you should not click anywhere on the combofix window as it can cause the program to stall. In fact, when combofix is running, do not touch your computer at all and just take a break as it may take a while for it to complete. <br/> <br/> When finished, it will produce a logfile located at C:\combofix.txt. <br/> <br/> <br/>Post the contents of that log in your next reply <br/> <br/>The logs will be reasonably large so you may have to divide them into sections and make several posts to post them.

[color=black face="Courier New" sab="311">[2]Click here: Before-posting-a-log[/2][/url]

<?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" />
[/color]
Do not PM me with logfiles. They will be deleted.


Posted 11/22/2012 6:35 AM
#94715
User avatar

flameofthewest Member

Date Joined Nov 2016
Total Posts: 5
ComboFix 12-11-21.01 - Sean 11/21/2012 12:27:35.2.2 - x86 <br/>Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3062.2428 [GMT -7:00] <br/>Running from: c:\documents and settings\Sean\My Documents\Downloads\ComboFix.exe <br/>AV: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF} <br/>. <br/>. <br/>((((((((((((((((((((((((( Files Created from 2012-10-21 to 2012-11-21 ))))))))))))))))))))))))))))))) <br/>. <br/>. <br/>2012-11-20 07:28 . 2008-04-14 07:17 25856 -c--a-w- c:\windows\system32\dllcache\usbprint.sys <br/>2012-11-20 07:28 . 2008-04-14 07:17 25856 ----a-w- c:\windows\system32\drivers\usbprint.sys <br/>2012-11-13 06:23 . 2012-11-13 06:23 -------- d-----w- c:\program files\iPod <br/>2012-11-13 06:23 . 2012-11-13 06:24 -------- d-----w- c:\documents and settings\All Users\Application Data\188F1432-103A-4ffb-80F1-36B633C5C9E1 <br/>2012-11-13 06:23 . 2012-11-13 06:24 -------- d-----w- c:\program files\iTunes <br/>2012-10-25 10:12 . 2012-10-25 10:12 94208 ----a-w- c:\windows\system32\QuickTimeVR.qtx <br/>2012-10-25 10:12 . 2012-10-25 10:12 69632 ----a-w- c:\windows\system32\QuickTime.qts <br/>. <br/>. <br/>. <br/>(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) <br/>. <br/>2012-10-22 08:37 . 2008-04-14 06:00 1866368 ----a-w- c:\windows\system32\win32k.sys <br/>2012-10-09 05:15 . 2012-04-02 08:28 696760 ----a-w- c:\windows\system32\FlashPlayerApp.exe <br/>2012-10-09 05:15 . 2011-06-08 19:08 73656 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl <br/>2012-10-02 18:04 . 2008-04-14 10:42 58368 ----a-w- c:\windows\system32\synceng.dll <br/>2012-09-24 21:32 . 2012-09-26 20:47 477168 ----a-w- c:\windows\system32\npdeployJava1.dll <br/>2012-09-24 21:32 . 2010-05-07 06:28 473072 ----a-w- c:\windows\system32\deployJava1.dll <br/>2012-09-24 19:51 . 2012-09-26 20:47 73728 ----a-w- c:\windows\system32\javacpl.cpl <br/>2012-08-28 15:14 . 2008-04-14 10:42 916992 ----a-w- c:\windows\system32\wininet.dll <br/>2012-08-28 15:14 . 2008-04-14 10:41 43520 ----a-w- c:\windows\system32\licmgr10.dll <br/>2012-08-28 15:14 . 2008-04-14 10:42 1469440 ------w- c:\windows\system32\inetcpl.cpl <br/>2012-08-28 12:07 . 2008-04-14 05:07 385024 ----a-w- c:\windows\system32\html.iec <br/>2012-08-24 21:43 . 2010-09-07 09:49 301920 ----a-w- c:\windows\system32\drivers\avgtdix.sys <br/>2012-08-24 13:53 . 2008-04-14 10:42 177664 ----a-w- c:\windows\system32\wintrust.dll <br/>2012-03-25 23:18 . 2011-12-17 04:27 97208 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll <br/>. <br/>. <br/>------- Sigcheck ------- <br/>Note: Unsigned files aren't necessarily malware. <br/>. <br/>[-] 2009-08-28 . BA3D691CBA9DFDB3D50C16F6AA62F18B . 1614848 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll <br/>. <br/>((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) <br/>. <br/>. <br/>*Note* empty entries & legit default entries are not shown <br/>REGEDIT4 <br/>. <br/>[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks] <br/>"{00000000-6E41-4FD3-8538-502F5495E5FC}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2012-01-03 1514152] <br/>. <br/>[HKEY_CLASSES_ROOT\clsid\{00000000-6e41-4fd3-8538-502f5495e5fc}] <br/>. <br/>[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}] <br/>2012-01-03 22:31 1514152 ----a-w- c:\program files\Ask.com\GenericAskToolbar.dll <br/>. <br/>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] <br/>"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2012-01-03 1514152] <br/>. <br/>[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}] <br/>[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1] <br/>[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}] <br/>[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd] <br/>. <br/>[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] <br/>@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" <br/>[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] <br/>2011-02-18 05:12 94208 ----a-w- c:\documents and settings\Sean\Application Data\Dropbox\bin\DropboxExt.14.dll <br/>. <br/>[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] <br/>@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" <br/>[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] <br/>2011-02-18 05:12 94208 ----a-w- c:\documents and settings\Sean\Application Data\Dropbox\bin\DropboxExt.14.dll <br/>. <br/>[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] <br/>@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" <br/>[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] <br/>2011-02-18 05:12 94208 ----a-w- c:\documents and settings\Sean\Application Data\Dropbox\bin\DropboxExt.14.dll <br/>. <br/>[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4] <br/>@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}" <br/>[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}] <br/>2011-02-18 05:12 94208 ----a-w- c:\documents and settings\Sean\Application Data\Dropbox\bin\DropboxExt.14.dll <br/>. <br/>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] <br/>"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-10-03 178712] <br/>"QlbCtrl.exe"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2008-08-01 202032] <br/>"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-01-21 134656] <br/>"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-01-21 166912] <br/>"Persistence"="c:\windows\system32\igfxpers.exe" [2009-01-21 134656] <br/>"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2006-07-19 102400] <br/>"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-27 30040] <br/>"AVG_TRAY"="c:\program files\AVG\AVG2012\avgtray.exe" [2012-07-31 2596984] <br/>"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Elements 6.0\apdproxy.exe" [2007-09-11 67488] <br/>"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-10-12 59280] <br/>"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-09-17 254896] <br/>"ApnUpdater"="c:\program files\Ask.com\Updater\Updater.exe" [2012-01-03 1391272] <br/>"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-09-24 926896] <br/>"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2012-10-25 421888] <br/>"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2012-09-10 421776] <br/>. <br/>[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce] <br/>"_nltide_3"="advpack.dll" [2009-03-08 128512] <br/>. <br/>c:\documents and settings\Sean\Start Menu\Programs\Startup\ <br/>Dropbox.lnk - c:\documents and settings\Sean\Application Data\Dropbox\bin\Dropbox.exe [2012-5-24 27112840] <br/>OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680] <br/>. <br/>[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] <br/>BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~1\AVG\AVG2012\avgrsx.exe /sync /restart <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys] <br/>@="Driver" <br/>. <br/>[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] <br/>"EnableFirewall"= 0 (0x0) <br/>. <br/>[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] <br/>"%windir%\\Network Diagnostic\\xpnetdiag.exe"= <br/>"%windir%\\system32\\sessmgr.exe"= <br/>"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"= <br/>"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"= <br/>"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"= <br/>"c:\\Documents and Settings\\Sean\\My Documents\\Neverwinter Nights\\NWN\\nwmain.exe"= <br/>"c:\\Program Files\\SPSSInc\\Statistics17\\SPSSWinWrapIDE.exe"= <br/>"c:\\Program Files\\SPSSInc\\Statistics17\\statistics.exe"= <br/>"c:\\Program Files\\SPSSInc\\Statistics17\\statistics.com"= <br/>"c:\\Documents and Settings\\Sean\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.dll"= <br/>"c:\\Documents and Settings\\Sean\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"= <br/>"c:\\Documents and Settings\\Sean\\Application Data\\Dropbox\\bin\\Dropbox.exe"= <br/>"c:\\Program Files\\Google\\Google Earth\\plugin\\geplugin.exe"= <br/>"c:\\Program Files\\Spotify\\spotify.exe"= <br/>"c:\\Program Files\\Bonjour\\mDNSResponder.exe"= <br/>"c:\\Program Files\\AVG\\AVG2012\\avgmfapx.exe"= <br/>"c:\\Program Files\\Skype\\Phone\\Skype.exe"= <br/>"c:\\Program Files\\AVG\\AVG2012\\avgnsx.exe"= <br/>"c:\\Program Files\\AVG\\AVG2012\\avgdiagex.exe"= <br/>"c:\\Program Files\\AVG\\AVG2012\\avgemcx.exe"= <br/>"c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"= <br/>"c:\\Program Files\\iTunes\\iTunes.exe"= <br/>. <br/>R0 AVGIDSHX;AVGIDSHX;c:\windows\system32\drivers\avgidshx.sys [4/19/2012 3:50 AM 24896] <br/>R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [9/7/2010 2:48 AM 31952] <br/>R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [9/7/2010 2:48 AM 237408] <br/>R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [9/7/2010 2:49 AM 301920] <br/>R2 avgwd;AVG WatchDog;c:\program files\AVG\AVG2012\avgwdsvc.exe [2/14/2012 3:53 AM 193288] <br/>R2 SWIHPWMI;SWIHPWMI;c:\program files\HPQ\Shared\Sierra Wireless\Win32\Unicode\SWIHPWMI.exe [12/4/2006 2:13 PM 292384] <br/>R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\avgidsdriverx.sys [12/23/2011 12:32 PM 139856] <br/>R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\avgidsfilterx.sys [12/23/2011 12:32 PM 24144] <br/>R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\avgidsshimx.sys [12/23/2011 12:32 PM 17232] <br/>R3 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [8/28/2009 2:51 PM 193840] <br/>S2 AVGIDSAgent;AVGIDSAgent;c:\program files\AVG\AVG2012\avgidsagent.exe [8/13/2012 2:24 AM 5167736] <br/>S2 Skype C2C Service;Skype C2C Service;c:\documents and settings\All Users\Application Data\Skype\Toolbars\Skype C2C Service\c2c_service.exe [10/2/2012 12:13 PM 3064000] <br/>S2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [7/13/2012 12:28 PM 160944] <br/>. <br/>[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}] <br/>2007-10-18 20:25 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe <br/>. <br/>Contents of the 'Scheduled Tasks' folder <br/>. <br/>2012-11-21 c:\windows\Tasks\Adobe Flash Player Updater.job <br/>- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-02 05:15] <br/>. <br/>2011-11-07 c:\windows\Tasks\AppleSoftwareUpdate.job <br/>- c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 23:57] <br/>. <br/>2012-11-21 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job <br/>- c:\program files\Google\Update\GoogleUpdate.exe [2011-04-21 06:38] <br/>. <br/>2012-11-21 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job <br/>- c:\program files\Google\Update\GoogleUpdate.exe [2011-04-21 06:38] <br/>. <br/>2012-11-20 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-823518204-1757981266-1177238915-1003Core.job <br/>- c:\documents and settings\Sean\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-06-30 21:48] <br/>. <br/>2012-11-21 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-823518204-1757981266-1177238915-1003UA.job <br/>- c:\documents and settings\Sean\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-06-30 21:48] <br/>. <br/>2012-11-21 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job <br/>- c:\program files\Ask.com\UpdateTask.exe [2012-01-03 22:31] <br/>. <br/>. <br/>------- Supplementary Scan ------- <br/>. <br/>uStart Page = hxxp://www.google.com/ <br/>uInternet Settings,ProxyServer = 206.107.155.137:8080 <br/>uInternet Settings,ProxyOverride = *.local <br/>IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200 <br/>IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000 <br/>TCP: DhcpNameServer = 24.116.2.50 24.116.2.34 <br/>FF - ProfilePath - c:\documents and settings\Sean\Application Data\Mozilla\Firefox\Profiles\04gqyuft.default\ <br/>FF - prefs.js: browser.search.selectedEngine - Ask.com <br/>FF - ExtSQL: 2012-09-26 14:47; {CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}; c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} <br/>FF - ExtSQL: 2012-10-21 17:39; {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}; c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} <br/>FF - ExtSQL: 2012-10-21 17:50; toolbar@ask.com; c:\documents and settings\Sean\Application Data\Mozilla\Firefox\Profiles\04gqyuft.default\extensions\toolbar@ask.com <br/>FF - ExtSQL: !HIDDEN! 2009-09-02 20:53; {20a82645-c095-46ed-80e3-08825760534b}; c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension <br/>. <br/>. <br/>************************************************************************** <br/>. <br/>catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net <br/>Rootkit scan 2012-11-21 12:31 <br/>Windows 5.1.2600 Service Pack 3 NTFS <br/>. <br/>scanning hidden processes ... <br/>. <br/>scanning hidden autostart entries ... <br/>. <br/>scanning hidden files ... <br/>. <br/>scan completed successfully <br/>hidden files: 0 <br/>. <br/>************************************************************************** <br/>. <br/>Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net <br/>Windows 5.1.2600 <br/>. <br/>CreateFile("\\.\PHYSICALDRIVE0"): The process cannot access the file because it is being used by another process. <br/>device: opened successfully <br/>user: error reading MBR <br/>kernel: MBR read successfully <br/>user != kernel MBR !!! <br/>. <br/>************************************************************************** <br/>. <br/>--------------------- LOCKED REGISTRY KEYS --------------------- <br/>. <br/>[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] <br/>@Denied: (A 2) (Everyone) <br/>@="FlashBroker" <br/>"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_4_402_287_ActiveX.exe,-101" <br/>. <br/>[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] <br/>"Enabled"=dword:00000001 <br/>. <br/>[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] <br/>@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_4_402_287_ActiveX.exe" <br/>. <br/>[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] <br/>@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" <br/>. <br/>[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] <br/>@Denied: (A 2) (Everyone) <br/>@="IFlashBroker5" <br/>. <br/>[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] <br/>@="{00020424-0000-0000-C000-000000000046}" <br/>. <br/>[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] <br/>@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" <br/>"Version"="1.0" <br/>. <br/>--------------------- DLLs Loaded Under Running Processes --------------------- <br/>. <br/>- - - - - - - > 'explorer.exe'(2164) <br/>c:\windows\system32\WININET.dll <br/>c:\documents and settings\Sean\Application Data\Dropbox\bin\DropboxExt.14.dll <br/>c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_44262b86\MSVCR80.dll <br/>c:\windows\system32\ieframe.dll <br/>c:\windows\system32\webcheck.dll <br/>. <br/>Completion time: 2012-11-21 12:33:21 <br/>ComboFix-quarantined-files.txt 2012-11-21 19:33 <br/>ComboFix2.txt 2012-11-21 19:25 <br/>. <br/>Pre-Run: 60,575,047,680 bytes free <br/>Post-Run: 60,572,164,096 bytes free <br/>. <br/>- - End Of File - - 7BA7775A0A038B6A00AD16B7794158CF
Posted 11/22/2012 2:53 PM
#94720
User avatar

Touch Advanced member

Date Joined Nov 2016
Total Posts: 12976
[red] CreateFile("\\.\PHYSICALDRIVE0"): The process cannot access the file because it is being used by another process. <br/>device: opened successfully <br/>user: error reading MBR <br/>kernel: MBR read successfully <br/>user != kernel MBR !!! <br/> [/red] <br/> <br/>That needs investigation.....i will ask you to run a tool that will provide me with the required info <br/> <br/>download MbrScan to your desktop: <br/>[url] http://eric71.geekstogo.com/tools/MbrScan.exe[/url] <br/> <br/>Run MbrScan <br/>Place a tick in the asm Code box just below the report button <br/>Press the scan button <br/> <br/>Once it has completed then press the report button. <br/> <br/> <br/>Please post the log in next reply.

[color=black face="Courier New" sab="311">[2]Click here: Before-posting-a-log[/2][/url]

<?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" />
[/color]
Do not PM me with logfiles. They will be deleted.


Posted 11/22/2012 7:53 PM
#94721
User avatar

flameofthewest Member

Date Joined Nov 2016
Total Posts: 5
Hi Touch, <br/> <br/>Unfortunately, the link to MbrScan did not work. Is there another recommended download location? <br/> <br/>Thanks, <br/> <br/>Sean
Posted 11/22/2012 10:23 PM
#94723
User avatar

Touch Advanced member

Date Joined Nov 2016
Total Posts: 12976
Seems to be a poor Forum code, sorry. <br/> <br/> <br/> <br/>Copy and paste the link into the adress bar <br/>http://eric71.geekstogo.com/tools/MbrScan.exe

[color=black face="Courier New" sab="311">[2]Click here: Before-posting-a-log[/2][/url]

<?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" />
[/color]
Do not PM me with logfiles. They will be deleted.


Posted 11/23/2012 2:44 AM
#94724
User avatar

flameofthewest Member

Date Joined Nov 2016
Total Posts: 5
[code] <br/>MBRScan v1.1.1 <br/> <br/>OS : Windows XP Home Service Pack 3 (32 bit) <br/>PROCESSOR : x86 Family 6 Model 15 Stepping 13, GenuineIntel <br/>BOOT : Normal Boot <br/>DATE : 2012/11/22 (ISO 8601) at 19:43:43 <br/>________________________________________________________________________________ <br/> <br/>Device\Harddisk0\DR0 232.9 Go [Fixed] ==> XP MBR Code ==> PARTITION TABLE FAKED !! <br/> <br/>MBR_MD5 : 7946FDF7C6B478005B5568899FCEFAFE <br/>MBR_SHA1 : 2BCC29C5666811EFC11C6EA3F6A93C2B536B8CD0 <br/> <br/>Device\Harddisk0\Partition1 221.2 Go 0x07 NTFS / HPFS <br/>Device\Harddisk0\Partition2 11.68 Go 0x07 NTFS / HPFS __ BOOTABLE __ <br/>________________________________________________________________________________ <br/> <br/>############################### Additional scan ################################ <br/> <br/>DRIVER : C:\WINDOWS\System32\Drivers\dump_iaStor.sys => Invisible on the disk <br/>ADDRESS : 0x95559000 <br/>SIZE : 800.0 Ko <br/> <br/>SystemStartOptions : NOEXECUTE=OPTIN FASTDETECT <br/> <br/>________________________________________________________________________________ <br/> <br/>_______MBR \Device\Harddisk0\DR0 <br/> <br/>0x00000000 33 C0 8E D0 BC 00 7C FB 50 07 50 1F FC BE 1B 7C 3À.м.|ûP.P.ü¾.| <br/>0x00000010 BF 1B 06 50 57 B9 E5 01 F3 A4 CB BD BE 07 B1 04 ¿..PW¹å.ó¤Ë½¾.±. <br/>0x00000020 38 6E 00 7C 09 75 13 83 C5 10 E2 F4 CD 18 8B F5 8n.|.u..Å.âôÍ..õ <br/>0x00000030 83 C6 10 49 74 19 38 2C 74 F6 A0 B5 07 B4 07 8B .Æ.It.8,tö.µ.´.. <br/>0x00000040 F0 AC 3C 00 74 FC BB 07 00 B4 0E CD 10 EB F2 88 ð¬<.tü»..´.Í.ëò. <br/>0x00000050 4E 10 E8 46 00 73 2A FE 46 10 80 7E 04 0B 74 0B N.èF.s*þF..~..t. <br/>0x00000060 80 7E 04 0C 74 05 A0 B6 07 75 D2 80 46 02 06 83 .~..t..¶.uÒ.F... <br/>0x00000070 46 08 06 83 56 0A 00 E8 21 00 73 05 A0 B6 07 EB F...V..è!.s..¶.ë <br/>0x00000080 BC 81 3E FE 7D 55 AA 74 0B 80 7E 10 00 74 C8 A0 ¼.>þ}Uªt..~..tÈ. <br/>0x00000090 B7 07 EB A9 8B FC 1E 57 8B F5 CB BF 05 00 8A 56 ·.ë©.ü.W.õË¿...V <br/>0x000000A0 00 B4 08 CD 13 72 23 8A C1 24 3F 98 8A DE 8A FC .´.Í.r#.Á$?..Þ.ü <br/>0x000000B0 43 F7 E3 8B D1 86 D6 B1 06 D2 EE 42 F7 E2 39 56 C÷ã.Ñ.Ö±.ÒîB÷â9V <br/>0x000000C0 0A 77 23 72 05 39 46 08 73 1C B8 01 02 BB 00 7C .w#r.9F.s.¸..».| <br/>0x000000D0 8B 4E 02 8B 56 00 CD 13 73 51 4F 74 4E 32 E4 8A .N..V.Í.sQOtN2ä. <br/>0x000000E0 56 00 CD 13 EB E4 8A 56 00 60 BB AA 55 B4 41 CD V.Í.ëä.V.`»ªU´AÍ <br/>0x000000F0 13 72 36 81 FB 55 AA 75 30 F6 C1 01 74 2B 61 60 .r6.ûUªu0öÁ.t+a` <br/>0x00000100 6A 00 6A 00 FF 76 0A FF 76 08 6A 00 68 00 7C 6A j.j..v..v.j.h.|j <br/>0x00000110 01 6A 10 B4 42 8B F4 CD 13 61 61 73 0E 4F 74 0B .j.´B.ôÍ.aas.Ot. <br/>0x00000120 32 E4 8A 56 00 CD 13 EB D6 61 F9 C3 49 6E 76 61 2ä.V.Í.ëÖaùÃInva <br/>0x00000130 6C 69 64 20 70 61 72 74 69 74 69 6F 6E 20 74 61 lid partition ta <br/>0x00000140 62 6C 65 00 45 72 72 6F 72 20 6C 6F 61 64 69 6E ble.Error loadin <br/>0x00000150 67 20 6F 70 65 72 61 74 69 6E 67 20 73 79 73 74 g operating syst <br/>0x00000160 65 6D 00 4D 69 73 73 69 6E 67 20 6F 70 65 72 61 em.Missing opera <br/>0x00000170 74 69 6E 67 20 73 79 73 74 65 6D 00 00 00 00 00 ting system..... <br/>0x00000180 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ <br/>0x00000190 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ <br/>0x000001A0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ <br/>0x000001B0 00 00 00 00 00 2C 44 63 E4 E2 AC 04 00 00 00 01 .....,Dcäâ¬..... <br/>0x000001C0 01 00 07 FE FF FF 3F 00 00 00 8D 71 A6 1B 80 FE ...þ..?....q¦..þ <br/>0x000001D0 FF FF 07 FE FF FF CC 71 A6 1B B5 D3 75 01 00 00 ...þ..Ìq¦.µÓu... <br/>0x000001E0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ <br/>0x000001F0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 55 AA ..............Uª <br/> <br/>__________________________16_BIT_ASM_CODE <br/> <br/>0x0000 33c0 XOR AX, AX <br/>0x0002 8ed0 MOV SS, AX <br/>0x0004 bc 007c MOV SP, 0x7c00 <br/>0x0007 fb STI <br/>0x0008 50 PUSH AX <br/>0x0009 07 POP ES <br/>0x000A 50 PUSH AX <br/>0x000B 1f POP DS <br/>0x000C fc CLD <br/>0x000D be 1b7c MOV SI, 0x7c1b <br/>0x0010 bf 1b06 MOV DI, 0x61b <br/>0x0013 50 PUSH AX <br/>0x0014 57 PUSH DI <br/>0x0015 b9 e501 MOV CX, 0x1e5 <br/>0x0018 f3 a4 REP MOVSB <br/>0x001A cb RETF <br/>0x001B bd be07 MOV BP, 0x7be <br/>0x001E b1 04 MOV CL, 0x4 <br/>0x0020 386e 00 CMP [BP+0x0], CH <br/>0x0023 7c 09 JL 0x2e <br/>0x0025 75 13 JNZ 0x3a <br/>0x0027 83c5 10 ADD BP, 0x10 <br/>0x002A e2 f4 LOOP 0x20 <br/>0x002C cd 18 INT 0x18 <br/>0x002E 8bf5 MOV SI, BP <br/>0x0030 83c6 10 ADD SI, 0x10 <br/>0x0033 49 DEC CX <br/>0x0034 74 19 JZ 0x4f <br/>0x0036 382c CMP [SI], CH <br/>0x0038 74 f6 JZ 0x30 <br/>0x003A a0 b507 MOV AL, [0x7b5] <br/>0x003D b4 07 MOV AH, 0x7 <br/>0x003F 8bf0 MOV SI, AX <br/>0x0041 ac LODSB <br/>0x0042 3c 00 CMP AL, 0x0 <br/>0x0044 74 fc JZ 0x42 <br/>0x0046 bb 0700 MOV BX, 0x7 <br/>0x0049 b4 0e MOV AH, 0xe <br/>0x004B cd 10 INT 0x10 <br/>0x004D eb f2 JMP 0x41 <br/>0x004F 884e 10 MOV [BP+0x10], CL <br/>0x0052 e8 4600 CALL 0x9b <br/>0x0055 73 2a JAE 0x81 <br/>0x0057 fe46 10 INC BYTE [BP+0x10] <br/>0x005A 807e 04 0b CMP BYTE [BP+0x4], 0xb <br/>0x005E 74 0b JZ 0x6b <br/>0x0060 807e 04 0c CMP BYTE [BP+0x4], 0xc <br/>0x0064 74 05 JZ 0x6b <br/>0x0066 a0 b607 MOV AL, [0x7b6] <br/>0x0069 75 d2 JNZ 0x3d <br/>0x006B 8046 02 06 ADD BYTE [BP+0x2], 0x6 <br/>0x006F 8346 08 06 ADD WORD [BP+0x8], 0x6 <br/>0x0073 8356 0a 00 ADC WORD [BP+0xa], 0x0 <br/>0x0077 e8 2100 CALL 0x9b <br/>0x007A 73 05 JAE 0x81 <br/>0x007C a0 b607 MOV AL, [0x7b6] <br/>0x007F eb bc JMP 0x3d <br/>0x0081 813e fe7d 55aa CMP WORD [0x7dfe], 0xaa55 <br/>0x0087 74 0b JZ 0x94 <br/>0x0089 807e 10 00 CMP BYTE [BP+0x10], 0x0 <br/>0x008D 74 c8 JZ 0x57 <br/>0x008F a0 b707 MOV AL, [0x7b7] <br/>0x0092 eb a9 JMP 0x3d <br/>0x0094 8bfc MOV DI, SP <br/>0x0096 1e PUSH DS <br/>0x0097 57 PUSH DI <br/>0x0098 8bf5 MOV SI, BP <br/>0x009A cb RETF <br/>0x009B bf 0500 MOV DI, 0x5 <br/>0x009E 8a56 00 MOV DL, [BP+0x0] <br/>0x00A1 b4 08 MOV AH, 0x8 <br/>0x00A3 cd 13 INT 0x13 <br/>0x00A5 72 23 JB 0xca <br/>0x00A7 8ac1 MOV AL, CL <br/>0x00A9 24 3f AND AL, 0x3f <br/>0x00AB 98 CBW <br/>0x00AC 8ade MOV BL, DH <br/>0x00AE 8afc MOV BH, AH <br/>0x00B0 43 INC BX <br/>0x00B1 f7e3 MUL BX <br/>0x00B3 8bd1 MOV DX, CX <br/>0x00B5 86d6 XCHG DH, DL <br/>0x00B7 b1 06 MOV CL, 0x6 <br/>0x00B9 d2ee SHR DH, CL <br/>0x00BB 42 INC DX <br/>0x00BC f7e2 MUL DX <br/>0x00BE 3956 0a CMP [BP+0xa], DX <br/>0x00C1 77 23 JA 0xe6 <br/>0x00C3 72 05 JB 0xca <br/>0x00C5 3946 08 CMP [BP+0x8], AX <br/>0x00C8 73 1c JAE 0xe6 <br/>0x00CA b8 0102 MOV AX, 0x201 <br/>0x00CD bb 007c MOV BX, 0x7c00 <br/>0x00D0 8b4e 02 MOV CX, [BP+0x2] <br/>0x00D3 8b56 00 MOV DX, [BP+0x0] <br/>0x00D6 cd 13 INT 0x13 <br/>0x00D8 73 51 JAE 0x12b <br/>0x00DA 4f DEC DI <br/>0x00DB 74 4e JZ 0x12b <br/>0x00DD 32e4 XOR AH, AH <br/>0x00DF 8a56 00 MOV DL, [BP+0x0] <br/>0x00E2 cd 13 INT 0x13 <br/>0x00E4 eb e4 JMP 0xca <br/>0x00E6 8a56 00 MOV DL, [BP+0x0] <br/>0x00E9 60 PUSHA <br/>0x00EA bb aa55 MOV BX, 0x55aa <br/>0x00ED b4 41 MOV AH, 0x41 <br/>0x00EF cd 13 INT 0x13 <br/>0x00F1 72 36 JB 0x129 <br/>0x00F3 81fb 55aa CMP BX, 0xaa55 <br/>0x00F7 75 30 JNZ 0x129 <br/>0x00F9 f6c1 01 TEST CL, 0x1 <br/>0x00FC 74 2b JZ 0x129 <br/>0x00FE 61 POPA <br/>0x00FF 60 PUSHA <br/>0x0100 6a 00 PUSH 0x0 <br/>0x0102 6a 00 PUSH 0x0 <br/>0x0104 ff76 0a PUSH WORD [BP+0xa] <br/>0x0107 ff76 08 PUSH WORD [BP+0x8] <br/>0x010A 6a 00 PUSH 0x0 <br/>0x010C 68 007c PUSH 0x7c00 <br/>0x010F 6a 01 PUSH 0x1 <br/>0x0111 6a 10 PUSH 0x10 <br/>0x0113 b4 42 MOV AH, 0x42 <br/>0x0115 8bf4 MOV SI, SP <br/>0x0117 cd 13 INT 0x13 <br/>0x0119 61 POPA <br/>0x011A 61 POPA <br/>0x011B 73 0e JAE 0x12b <br/>0x011D 4f DEC DI <br/>0x011E 74 0b JZ 0x12b <br/>0x0120 32e4 XOR AH, AH <br/>0x0122 8a56 00 MOV DL, [BP+0x0] <br/>0x0125 cd 13 INT 0x13 <br/>0x0127 eb d6 JMP 0xff <br/>0x0129 61 POPA <br/>0x012A f9 STC <br/>0x012B c3 RET <br/>0x012C 49 DEC CX <br/>0x012D 6e OUTSB <br/>0x012E 76 61 JBE 0x191 <br/>0x0130 6c INSB <br/>0x0131 6964 20 7061 IMUL SP, [SI+0x20], 0x6170 <br/>0x0136 72 74 JB 0x1ac <br/>0x0138 6974 69 6f6e IMUL SI, [SI+0x69], 0x6e6f <br/>0x013D 2074 61 AND [SI+0x61], DH <br/>0x0140 626c 65 BOUND BP, [SI+0x65] <br/>0x0143 0045 72 ADD [DI+0x72], AL <br/>0x0146 72 6f JB 0x1b7 <br/>0x0148 72 20 JB 0x16a <br/>0x014A 6c INSB <br/>0x014B 6f OUTSW <br/>0x014C 61 POPA <br/>0x014D 64 696e 67 206f IMUL BP, FS:[BP+0x67], 0x6f20 <br/>0x0153 70 65 JO 0x1ba <br/>0x0155 72 61 JB 0x1b8 <br/>0x0157 74 69 JZ 0x1c2 <br/>0x0159 6e OUTSB <br/>0x015A 67 2073 79 AND [EBX+0x79], DH <br/>0x015E 73 74 JAE 0x1d4 <br/>0x0160 65 6d INS WORD GS:[DI], DX <br/>0x0162 004d 69 ADD [DI+0x69], CL <br/>0x0165 73 73 JAE 0x1da <br/>0x0167 696e 67 206f IMUL BP, [BP+0x67], 0x6f20 <br/>0x016C 70 65 JO 0x1d3 <br/>0x016E 72 61 JB 0x1d1 <br/>0x0170 74 69 JZ 0x1db <br/>0x0172 6e OUTSB <br/>0x0173 67 2073 79 AND [EBX+0x79], DH <br/>0x0177 73 74 JAE 0x1ed <br/>0x0179 65 6d INS WORD GS:[DI], DX <br/>0x017B 0000 ADD [BX+SI], AL <br/>0x017D 0000 ADD [BX+SI], AL <br/>0x017F 0000 ADD [BX+SI], AL <br/>0x0181 0000 ADD [BX+SI], AL <br/>0x0183 0000 ADD [BX+SI], AL <br/>0x0185 0000 ADD [BX+SI], AL <br/>0x0187 0000 ADD [BX+SI], AL <br/>0x0189 0000 ADD [BX+SI], AL <br/>0x018B 0000 ADD [BX+SI], AL <br/>0x018D 0000 ADD [BX+SI], AL <br/>0x018F 0000 ADD [BX+SI], AL <br/>0x0191 0000 ADD [BX+SI], AL <br/>0x0193 0000 ADD [BX+SI], AL <br/>0x0195 0000 ADD [BX+SI], AL <br/>0x0197 0000 ADD [BX+SI], AL <br/>0x0199 0000 ADD [BX+SI], AL <br/>0x019B 0000 ADD [BX+SI], AL <br/>0x019D 0000 ADD [BX+SI], AL <br/>0x019F 0000 ADD [BX+SI], AL <br/>0x01A1 0000 ADD [BX+SI], AL <br/>0x01A3 0000 ADD [BX+SI], AL <br/>0x01A5 0000 ADD [BX+SI], AL <br/>0x01A7 0000 ADD [BX+SI], AL <br/>0x01A9 0000 ADD [BX+SI], AL <br/>0x01AB 0000 ADD [BX+SI], AL <br/>0x01AD 0000 ADD [BX+SI], AL <br/>0x01AF 0000 ADD [BX+SI], AL <br/>0x01B1 0000 ADD [BX+SI], AL <br/>0x01B3 0000 ADD [BX+SI], AL <br/>0x01B5 2c 44 SUB AL, 0x44 <br/>0x01B7 63e4 ARPL SP, SP <br/>0x01B9 e2 ac LOOP 0x167 <br/>0x01BB 04 00 ADD AL, 0x0 <br/>0x01BD 0000 ADD [BX+SI], AL <br/>0x01BF 0101 ADD [BX+DI], AX <br/>0x01C1 0007 ADD [BX], AL <br/>0x01C3 fe DB 0xfe <br/>0x01C4 ff DB 0xff <br/>0x01C5 ff DB 0xff <br/>0x01C6 3f AAS <br/>0x01C7 0000 ADD [BX+SI], AL <br/>0x01C9 008d 71a6 ADD [DI-0x598f], CL <br/>0x01CD 1b80 feff SBB AX, [BX+SI-0x2] <br/>0x01D1 ff07 INC WORD [BX] <br/>0x01D3 fe DB 0xfe <br/>0x01D4 ff DB 0xff <br/>0x01D5 ffcc DEC SP <br/>0x01D7 71 a6 JNO 0x17f <br/>0x01D9 1bb5 d375 SBB SI, [DI+0x75d3] <br/>0x01DD 0100 ADD [BX+SI], AX <br/>0x01DF 0000 ADD [BX+SI], AL <br/>0x01E1 0000 ADD [BX+SI], AL <br/>0x01E3 0000 ADD [BX+SI], AL <br/>0x01E5 0000 ADD [BX+SI], AL <br/>0x01E7 0000 ADD [BX+SI], AL <br/>0x01E9 0000 ADD [BX+SI], AL <br/>0x01EB 0000 ADD [BX+SI], AL <br/>0x01ED 0000 ADD [BX+SI], AL <br/>0x01EF 0000 ADD [BX+SI], AL <br/>0x01F1 0000 ADD [BX+SI], AL <br/>0x01F3 0000 ADD [BX+SI], AL <br/>0x01F5 0000 ADD [BX+SI], AL <br/>0x01F7 0000 ADD [BX+SI], AL <br/>0x01F9 0000 ADD [BX+SI], AL <br/>0x01FB 0000 ADD [BX+SI], AL <br/>0x01FD 0055 aa ADD [DI-0x56], DL <br/> <br/>[/code]
Posted 11/23/2012 2:37 PM
#94734
User avatar

Touch Advanced member

Date Joined Nov 2016
Total Posts: 12976
Please download and follow this guide: <br/> <br/> <br/>http://www.malwarebytes.org/products/mbar/ <br/> <br/> <br/>When the scan is finished, and possibly restarted, open the folder and find System - Log file. <br/> <br/>Please Post the log in next reply

[color=black face="Courier New" sab="311">[2]Click here: Before-posting-a-log[/2][/url]

<?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" />
[/color]
Do not PM me with logfiles. They will be deleted.


Posted 11/23/2012 11:59 PM
#94737
User avatar

russ4570 Member

Date Joined Nov 2016
Total Posts: 5
High gurus. Not sure of forum etiquette so hello as new user. I have exact same virus in same location. Should I start a new thread or post here. Don't want to hijack someone elses thread. I have done usual things. updated all virus patterns. ran combofix and still finds virus in Steam exe. <br/>Advice please. Regards <br/>Russ
Posted 11/24/2012 3:58 AM
#94738
User avatar

Touch Advanced member

Date Joined Nov 2016
Total Posts: 12976
Hi Russ :-) <br/> <br/> <br/> <br/> >>>>>Should I start a new thread or post here. <<<<< <br/> <br/> <br/>Please start a new thread, and post combofix log.

[color=black face="Courier New" sab="311">[2]Click here: Before-posting-a-log[/2][/url]

<?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" />
[/color]
Do not PM me with logfiles. They will be deleted.


Posted 11/28/2012 4:21 AM
#94767
User avatar

flameofthewest Member

Date Joined Nov 2016
Total Posts: 5
Hi Touch, <br/> <br/>Sorry for the response delay. Holidays and all. <br/> <br/>The program won't run, stating that I need to have an administrative account to run it. Not only is my account the admin account, it's the only account on the computer. <br/> <br/>What shall I do? <br/> <br/>Thanks, <br/> <br/>Sean
Posted 11/28/2012 5:57 AM
#94768
User avatar

Advanced member

I apologize for my intervention but this seems more an more like a false positive detection. <br/> <br/>I think it's better if you all contact AVG Support and see what they have to say about this. <br/> <br/>Cheers!
Andreea-Luciana Ostache
Support Team Leader
[url]support@bullguard.com[/url]
www.bullguard.com

Download the Free Trial version of BullGuard Internet Security 16

You have a BullGuard related problem? Post your question on these forums, contact Support or contact me on Twitter!
  • Unread posts or replies
  • No unread posts or replies
  • Unread Posts (Read Only Forum)
  • No Unread Posts (Read Only Forum)

Forum Information

Currently it is Thursday, December 8, 2016, 5:17 PM (GMT +1)
There are a total of 61,163 posts in 13,450 threads.
In the last 3 days there were 1 new threads and 3 reply posts.

Who's online

This forum has 37,968 registered members. Please welcome our newest member, Crawlerz.
There are currently no users on-line.