Try this as well Malwarebyte:
www.malwarebytes.org/mbam.
Main Topics
Browse All TopicsI have an infected computer. The virus got by the antivirus (Trend Micro). Any anti-virus program I run get immediately shutdown after I launch a scan. The virus them immediately removes my file permissions and I cannot run the file again. I can go into security and tell the file to inherit permissions...this fixes it. But as soon as I run the program again....the same thing happens.
I cannot get Hijack this or any other program to run. Even if I rename the file. The same thing happens.
I don't know what to do. Help Gurus!
This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.
Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.
If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.
Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.
Access the answers to your technology questions today.
30-day free trial. Register in 60 seconds.
Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Try it out and discover for yourself.
30-day free trial. Register in 60 seconds.
Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.
Try this as well Malwarebyte:
www.malwarebytes.org/mbam.
have you tried repermissoning files reboot in safe mode then running or try microsofts online scanner?
http://onecare.live.com/si
Did you rename MalwareBytes or Combofix also before saving the files to the desktop? It needs to be rename bafore saving(not after)
http://www.bleepingc
Also run this diagnostic tool please.
Please download this tool and run it.
http://ad13.geekstogo.c
Dou
A black command prompt window shall appear.
It will now begin to scan. This may take a while, please be paitent until the scan is complete.
Once it's done, in the black screen it will say "Finished! Press any key to exit....
A log file called Win32KDiag.txt will be created on your desktop.
Please copy and paste the contents of that log file here in your next reply please.
Thanks for the log.. it is the new infection there as well that patches legit system files.
Step 1:
Open notepad and copy/paste the bolded text below into it.
Save this text as "Fix.bat" Make sure the "Save as type:" is "All Files (*.*)" and save it to your desktop.
Then, double-click on the "Fix.bat". You may see a window flashes it's normal.
@echo off
copy C:\WINDOWS\system32\dllcac
Exit
Step 2:
Please download The Avenger by Swandog46 to your Desktop.
http://swandog46.g
* Right click on the Avenger.zip folder and select "Extract All..."
* Follow the prompts and extract the avenger folder to your desktop
* Start up Avenger.
In the "Input script here:" box that opens, copy, then paste the following text(all text inside the lines below):
-------------------
Fil
C:\eventlog.dll | C:\WINDOWS\system32\eventl
----
Then
Then press OK at the prompt to reboot your PC.
Plea
Step 3:
Click on Start->Run, and copy-paste the following command into the "Open:" box, and click OK.
"%userprofile%\desktop\
When it's finished, there will be a log called Win32kDiag.txt on your desktop. Please open it with notepad and post the contents here.
Step 4:
Run a renamed MBAM and renamed Combofix and attach the logs.
Check to make sure that after you doubleclicked the Fix.bat, a file C:\eventlog.dll exists
If the above copy from DLLCache won't work there's another good copy at --> C:\WINDOWS\system32\logeve
then batchfile would then be like this below:
@echo off
copy C:\WINDOWS\system32\logeve
Exit
Malwarebytes Log
Malwarebytes' Anti-Malware 1.40
Database version: 2747
Windows 5.1.2600 Service Pack 3
9/6/2009 1:55:49 AM
mbam-log-2009-09-06 (01-55-49).txt
Scan type: Full Scan (C:\|)
Objects scanned: 175175
Time elapsed: 26 minute(s), 14 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 1
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
C:\Program Files\PersonalAV (Rogue.PersonalAntiVirus) -> Quarantined and deleted successfully.
Files Infected:
(No malicious items detected)
Glad to know it's resolved.
You can also run either one of these temp cleaners:
CCleaner:
http://w
Downl
http://oldtimer.ge
C
Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two. Let it run uninterrupted to completion.
Once it's finished it should reboot your machine. If it does not, please manually reboot the machine yourself to ensure a complete clean.
To uninstall Combofix:
Go to Start > Run and 'copy and paste' next command in the field:
ComboFix /u
Thanks!
Business Accounts
Answer for Membership
by: PriceDPosted on 2009-09-05 at 06:06:28ID: 25266124
Have you tried rootkit buster from trend. www.trendmicro.com go to free tools and download the rootkit buster.