I'm having trouble with an incredibly persistent virus on my wife's computer. The virus is a fake AV, is very aggressive and will not let you launch nearly any countermeasure, including rkill, unless you launch rkill before the system is done loading. I've run Malwarebytes, HijackThis (with a log analyzer), and Avast! several times upon the computer over the last few weeks and it keeps returning. I need to get this taken care of first, and then I guess I'll be going over computer security with her. Again. After I have the system clean. Again.
This is the log from rkill:
Processes terminated by Rkill or while it was running:
C:\WINDOWS\system32\userinit.exe
C:\Program Files\Brother\ControlCenter3\brctrcen.exe
C:\Documents and Settings\NetworkService\Local Settings\Application Data\cxbrkrjao\fpggjultssd.exe
C:\Documents and Settings\Mel\Desktop\pwn nubs\rkill.com
C:\Documents and Settings\Mel\Application Data\Smilebox\SmileboxTray.exe
C:\Program Files\LimeWire\LimeWire.exe
C:\Program Files\Alwil Software\Avast5\defs\10070301\Sf.bin
Rkill completed on 07/04/2010 at 7:41:37.
After running rkill, I launched HijackThis, and have pastebinned the log in case anyone wishes to peruse it.
http://hijackthis.pastebin.com/iCihHZ8T
After this I will run Malwarebytes in an attempt to clear the system, I've done all this before and -thought- I had fixed it but the virus keeps returning. Any help with this would be greatly appreciated.
This is the log from rkill:
Processes terminated by Rkill or while it was running:
C:\WINDOWS\system32\userinit.exe
C:\Program Files\Brother\ControlCenter3\brctrcen.exe
C:\Documents and Settings\NetworkService\Local Settings\Application Data\cxbrkrjao\fpggjultssd.exe
C:\Documents and Settings\Mel\Desktop\pwn nubs\rkill.com
C:\Documents and Settings\Mel\Application Data\Smilebox\SmileboxTray.exe
C:\Program Files\LimeWire\LimeWire.exe
C:\Program Files\Alwil Software\Avast5\defs\10070301\Sf.bin
Rkill completed on 07/04/2010 at 7:41:37.
After running rkill, I launched HijackThis, and have pastebinned the log in case anyone wishes to peruse it.
http://hijackthis.pastebin.com/iCihHZ8T
After this I will run Malwarebytes in an attempt to clear the system, I've done all this before and -thought- I had fixed it but the virus keeps returning. Any help with this would be greatly appreciated.