Monday, November 23rd 2009, 2:33am UTC+1
You are not logged in.
Date of registration:
Oct 7th 2009
Version: none
Community member
Date of registration:
Apr 16th 2008
Version: AntiVir Personal
Operating System: Windows 7 build 7127 x64
Location: Bulgaria
Quoted
REGEDIT4
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog]
"Start"=dword:00000004

Quoted
@Win32kDiag -F -R
del %0
Date of registration:
Oct 7th 2009
Version: none
Date of registration:
Oct 7th 2009
Version: none
Date of registration:
Oct 7th 2009
Version: none
Date of registration:
Oct 7th 2009
Version: none
Date of registration:
Oct 7th 2009
Version: none
Date of registration:
Oct 7th 2009
Version: none
Date of registration:
Oct 7th 2009
Version: none
Date of registration:
Oct 7th 2009
Version: none
Date of registration:
Oct 7th 2009
Version: none
Community member
Date of registration:
Apr 16th 2008
Version: AntiVir Personal
Operating System: Windows 7 build 7127 x64
Location: Bulgaria
Quoted
Begin copying here:
Files to move:
C:\WINDOWS\system32\logevent.dll | C:\WINDOWS\system32\eventlog.dll
Date of registration:
Oct 7th 2009
Version: none
Quoted
Logfile of The Avenger Version 2.0, (c) by Swandog46
http://swandog46.geekstogo.com
Platform: Windows XP
*******************
Script file opened successfully.
Script file read successfully.
Backups directory opened successfully at C:\Avenger
*******************
Beginning to process script file:
Rootkit scan active.
No rootkits found!
File move operation "C:\WINDOWS\system32\logevent.dll|C:\WINDOWS\system32\eventlog.dll" completed successfully.
Completed script processing.
*******************
Finished! Terminate.
Community member
Date of registration:
Apr 16th 2008
Version: AntiVir Personal
Operating System: Windows 7 build 7127 x64
Location: Bulgaria
I could not run combofix as it would not launch
Community member
Date of registration:
Jan 31st 2006
Version: AntiVir Premium
AntiVir Personal Unix/Linux
Avira Prem. Security Suite
Operating System: Vista home basic SP2 / XP Home SP3 / Linux Fedora 11 XFCE spinoff
Location: UK / Suisse
The Brontok virus will make lots of changes to the system restrictions in order to hide itself from easy detection and also from easy cleaning.Community member
Date of registration:
Apr 16th 2008
Version: AntiVir Personal
Operating System: Windows 7 build 7127 x64
Location: Bulgaria
Quoted
Georgi hope you do not mind me jumping in as well, in my experience this problem is most commonly caused by the virus called “Brontok“.