I noticed that while in Internet Explorer I seem to have some slowing and a virus/malware has taken over somewhat.
Downloaded Avast was able to do a scan before booting and see that one file was infected: c:\WINDOWS\system32\eventlog.d11
Avast did not allow me to move it or put it in it's chest -bascially jsut identified the file. Seems that the virus disables AVAST and any other virus protection softward scanning.
I download the SystemLook with this in the codebox:
:filefind
scecli.dll
netlogon.dll
eventlog.dll
Below is the log it found:
SystemLook v1.0 by jpshortstuff (29.08.09)
Log created at 18:42 on 11/11/2009 by rcl (Administrator - Elevation successful)
========== filefind ==========
Searching for "scecli.dll"
C:\WINDOWS\$NtServicePackUninstall$\scecli.dll -----c 180224 bytes [20:54 08/05/2008] [10:00 04/08/2004] 0F78E27F563F2AAF74B91A49E2ABF19A
C:\WINDOWS\ServicePackFiles\i386\scecli.dll ------ 181248 bytes [00:12 14/04/2008] [00:12 14/04/2008] A86BB5E61BF3E39B62AB4C7E7085A084
C:\WINDOWS\system32\scecli.dll --a--- 181248 bytes [22:00 11/08/2004] [00:12 14/04/2008] A86BB5E61BF3E39B62AB4C7E7085A084
Searching for "netlogon.dll"
C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll -----c 407040 bytes [20:54 08/05/2008] [10:00 04/08/2004] 96353FCECBA774BB8DA74A1C6507015A
C:\WINDOWS\ServicePackFiles\i386\netlogon.dll ------ 407040 bytes [00:12 14/04/2008] [00:12 14/04/2008] 1B7F071C51B77C272875C3A23E1E4550
C:\WINDOWS\system32\netlogon.dll --a--- 407040 bytes [22:00 11/08/2004] [00:12 14/04/2008] 1B7F071C51B77C272875C3A23E1E4550
Searching for "eventlog.dll"
C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll -----c 55808 bytes [20:54 08/05/2008] [10:00 04/08/2004] 82B24CB70E5944E6E34662205A2A5B78
C:\WINDOWS\ServicePackFiles\i386\eventlog.dll ------ 56320 bytes [00:11 14/04/2008] [00:11 14/04/2008] 6D4FEB43EE538FC5428CC7F0565AA656
C:\WINDOWS\system32\eventlog.dll --a--- 61952 bytes [22:00 11/08/2004] [00:11 14/04/2008] (Unable to calculate MD5)
Searching for "cngaudit.dll"
No files found.
-=End Of File=-
I downloaded The Avenger by Swandog46
and put in:
Files to delete:
c:\WINDOWS\system32\eventlog.d11
hit the execute and when it restarted my computer it goes to a sark blue screen saying something is wrong and then I turn-off and on my computer and hit F8 had to start byt going back to an old configuration mode and then the Avenger log says this below:
//////////////////////////////////////////
Avenger Pre-Processor log
//////////////////////////////////////////
Platform: Windows XP (build 2600, Service Pack 3)
Wed Nov 11 15:15:34 2009
15:15:34: Error: Invalid script. A valid script must begin with a command directive.
Aborting execution!
//////////////////////////////////////////
//////////////////////////////////////////
Avenger Pre-Processor log
//////////////////////////////////////////
Platform: Windows XP (build 2600, Service Pack 3)
Wed Nov 11 15:15:50 2009
15:15:50: Error: Invalid script. A valid script must begin with a command directive.
Aborting execution!
//////////////////////////////////////////
//////////////////////////////////////////
Avenger Pre-Processor log
//////////////////////////////////////////
Platform: Windows XP (build 2600, Service Pack 3)
Wed Nov 11 15:17:56 2009
15:17:56: Error: Invalid script. A valid script must begin with a command directive.
Aborting execution!
//////////////////////////////////////////
Please help I know I have some kind of virus in the C:\WINDOWS\system32\eventlog.d11 and need to repair my registry.
Downloaded Hijackthis and the virus won't allow it to do a scan - just stops right after starting.
Any help is appreciated - and would be glad to donate to the site.
Thanks
Downloaded Avast was able to do a scan before booting and see that one file was infected: c:\WINDOWS\system32\eventlog.d11
Avast did not allow me to move it or put it in it's chest -bascially jsut identified the file. Seems that the virus disables AVAST and any other virus protection softward scanning.
I download the SystemLook with this in the codebox:
:filefind
scecli.dll
netlogon.dll
eventlog.dll
Below is the log it found:
SystemLook v1.0 by jpshortstuff (29.08.09)
Log created at 18:42 on 11/11/2009 by rcl (Administrator - Elevation successful)
========== filefind ==========
Searching for "scecli.dll"
C:\WINDOWS\$NtServicePackUninstall$\scecli.dll -----c 180224 bytes [20:54 08/05/2008] [10:00 04/08/2004] 0F78E27F563F2AAF74B91A49E2ABF19A
C:\WINDOWS\ServicePackFiles\i386\scecli.dll ------ 181248 bytes [00:12 14/04/2008] [00:12 14/04/2008] A86BB5E61BF3E39B62AB4C7E7085A084
C:\WINDOWS\system32\scecli.dll --a--- 181248 bytes [22:00 11/08/2004] [00:12 14/04/2008] A86BB5E61BF3E39B62AB4C7E7085A084
Searching for "netlogon.dll"
C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll -----c 407040 bytes [20:54 08/05/2008] [10:00 04/08/2004] 96353FCECBA774BB8DA74A1C6507015A
C:\WINDOWS\ServicePackFiles\i386\netlogon.dll ------ 407040 bytes [00:12 14/04/2008] [00:12 14/04/2008] 1B7F071C51B77C272875C3A23E1E4550
C:\WINDOWS\system32\netlogon.dll --a--- 407040 bytes [22:00 11/08/2004] [00:12 14/04/2008] 1B7F071C51B77C272875C3A23E1E4550
Searching for "eventlog.dll"
C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll -----c 55808 bytes [20:54 08/05/2008] [10:00 04/08/2004] 82B24CB70E5944E6E34662205A2A5B78
C:\WINDOWS\ServicePackFiles\i386\eventlog.dll ------ 56320 bytes [00:11 14/04/2008] [00:11 14/04/2008] 6D4FEB43EE538FC5428CC7F0565AA656
C:\WINDOWS\system32\eventlog.dll --a--- 61952 bytes [22:00 11/08/2004] [00:11 14/04/2008] (Unable to calculate MD5)
Searching for "cngaudit.dll"
No files found.
-=End Of File=-
I downloaded The Avenger by Swandog46
and put in:
Files to delete:
c:\WINDOWS\system32\eventlog.d11
hit the execute and when it restarted my computer it goes to a sark blue screen saying something is wrong and then I turn-off and on my computer and hit F8 had to start byt going back to an old configuration mode and then the Avenger log says this below:
//////////////////////////////////////////
Avenger Pre-Processor log
//////////////////////////////////////////
Platform: Windows XP (build 2600, Service Pack 3)
Wed Nov 11 15:15:34 2009
15:15:34: Error: Invalid script. A valid script must begin with a command directive.
Aborting execution!
//////////////////////////////////////////
//////////////////////////////////////////
Avenger Pre-Processor log
//////////////////////////////////////////
Platform: Windows XP (build 2600, Service Pack 3)
Wed Nov 11 15:15:50 2009
15:15:50: Error: Invalid script. A valid script must begin with a command directive.
Aborting execution!
//////////////////////////////////////////
//////////////////////////////////////////
Avenger Pre-Processor log
//////////////////////////////////////////
Platform: Windows XP (build 2600, Service Pack 3)
Wed Nov 11 15:17:56 2009
15:17:56: Error: Invalid script. A valid script must begin with a command directive.
Aborting execution!
//////////////////////////////////////////
Please help I know I have some kind of virus in the C:\WINDOWS\system32\eventlog.d11 and need to repair my registry.
Downloaded Hijackthis and the virus won't allow it to do a scan - just stops right after starting.
Any help is appreciated - and would be glad to donate to the site.
Thanks