Can't access AV servers or do Win Restore

Hi,

Re-run MBRCheck again.
When prompted, enter Y
Then enter 1 to dump the MBR to physical disk
Name the dumped file as Dump.dat

Enter -1 to exit

A log file named dump.dat will be located in the same folder as MBRCheck was saved, please zip it up and upload here.

Kindly include a link to this topic in the message.
 
Hi, I dumped the data into the attached zip file dumpdata.zip. The process was a little different than you instructed, but I think I reached the same result. Please let me know if it doesn't contain the info you need.
 
Hi,

If you haven't tested Antivir yet then please ignore it and follow the instructions below.

Please follow steps guided here. The location where to upload requested "TRK0_DMP" file(s) is location behind this link. Kindly include a link to this forum topic there.
 
Hi, I didn't run antivir as you asked and tried to do the other process but it failed to produce the results you requested. I looked at dump.bat and saw that it called MBRTOOL, which I don't have anywhere on my PC? I suspect that's the reason for the failure.

So I went out to http://www.diydatarecovery.nl/mbrtool.htm and downloaded mbrtool. Is this the program that you want me to run in dump.bat?
 
Hi,

I didn't run antivir as you asked and tried to do the other process but it failed to produce the results you requested.
Could you describe what step failed there (any error messages)?
 
Here's the output from running dump.bat:

Dumping Track 0 of all disks to 'trk0.dmp', please wait...
Error reading from drive A: DOS area: unknown command given to driver (A)bort, (I)gnore, (R)etry, (F)ail?
[repeats 7 times, then]
Bad command or filename - "MBRTOOL".
Done! Please reboot the computer now and upload "TRK0_DMP"

Both the beginning and ending sentences are echoed from dump.bat. My PC shows the C:\ prompt not A:\ as shown in the instructions; however the DIR command lists the files on the flash drive and no other drive is available? I don't know if that has anything to do with the failure, just thought I'd mention it. Here's the contents of dump.bat:

@ECHO OFF

ECHO Dumping Track 0 of all disks to 'trk0.dmp', please wait...

MBRTOOL /ST0 /DSK:A /FIL:TRK0_DMP

ECHO Done! Please reboot the computer now, and upload "TRK0_DMP"
 
Hi,

Did you create bootable usb or floppy? Want to make sure you followed instructions as described in that link I posted.
 
Hi, yes, I did as instructed and created a bootable flash drive. However, the exe used to create the bootable drive only put two files on it: command.com and kernel.sys. So when I booted with it, dump.bat was not found. So I copied all of the files from the dos directory it provided onto the flash drive. This included dump.bat. After loading all this onto the flash drive the process was as described in the instructions, except for dump.bat, which failed to read track0 of any disk? Here is a list of the files on the flash drive:

Volume in drive F is LEXAR MEDIA
Volume Serial Number is 7C0E-1AD6

Directory of F:\

11/27/2002 03:39 PM 30,802 subst.exe
08/17/2006 09:57 PM 14,561 sys.com
08/30/2006 10:26 AM 2,009 tickle.com
07/07/2001 05:33 AM 9,893 tree.com
05/26/2004 06:14 PM 49,286 unzip.exe
02/08/2006 02:02 AM 3,745 XCDROM.SYS
08/02/2006 06:40 AM 15,543 xcopy.exe
02/15/2006 08:03 AM 2,535 xdma.sys
12/24/1999 07:37 AM 51,295 zip.exe
01/23/2006 11:14 PM 3,115 append.exe
01/26/1997 05:46 PM 13,867 assign.com
06/30/2003 07:10 PM 5,044 attrib.com
05/12/2004 08:03 PM 4,595 cdrcache.sys
07/03/2006 04:14 AM 35,380 chkdsk.exe
09/19/2003 07:08 PM 5,219 choice.exe
08/05/2003 04:27 PM 1,764 comp.com
06/29/2006 03:16 PM 27,780 country.sys
05/31/2003 06:09 PM 5,722 ctmouse.exe
08/31/2006 04:26 PM 33,767 cwsdpmi.exe
04/19/2004 09:38 AM 20,650 debug.com
08/03/2006 03:11 PM 46,607 defrag.exe
07/02/2006 04:37 AM 5,292 defrag.hlp
07/24/2006 03:22 AM 3,099 deltree.com
11/04/2005 07:19 AM 3,058 devload.com
06/05/2003 09:05 PM 6,490 diskcomp.com
08/06/2004 04:32 AM 24,505 diskcopy.exe
03/19/2003 11:10 AM 512 diskcopy.ini
08/06/2006 01:54 PM 62,535 display.exe
04/15/2006 12:19 AM 58,364 dosfsck.exe
06/29/2005 01:00 PM 16 drvon.com
08/23/2010 10:50 PM 184 dump.bat
07/24/2006 05:29 AM 59,743 edit.exe
05/14/2005 12:39 AM 30,189 edit.hlp
08/19/2006 05:43 AM 23,022 edlin.exe
08/25/2006 08:09 AM 16,799 emm386.exe
01/09/2005 08:03 PM 14,835 fc.exe
05/22/2005 11:16 PM 6,344 fdapm.com
09/04/2006 08:33 PM 881 fdconfig.sys
07/24/2006 06:56 AM 35,880 fdisk.exe
11/30/2002 05:14 AM 8,447 fdisk.ini
07/23/2002 03:04 PM 21,232 fdiskpt.ini
08/30/2006 12:22 PM 4,044 fdshield.com
05/28/2005 03:42 PM 4,620 FDXMS286.SYS
05/30/2003 10:57 AM 4,870 find.com
01/14/2006 04:15 AM 31,216 format.exe
06/11/2003 05:31 AM 2,498 graph-hp.com
06/09/2003 09:17 AM 2,423 graphpin.com
06/09/2003 09:17 AM 2,468 graph-ps.com
08/25/2006 07:53 AM 8,058 himem.exe
08/28/2006 03:49 PM 10,809 keyb.exe
08/25/2006 07:50 PM 33,196 keyboard.sys
08/25/2006 07:50 PM 25,431 keybrd2.sys
05/23/2003 03:38 PM 4,129 label.exe
08/30/2006 09:30 AM 7,443 lbacache.com
09/04/2006 08:29 PM 1,653 loadcd.bat
08/25/2006 10:26 PM 14,941 mem.exe
05/12/2005 01:05 PM 16,254 mode.com
07/15/2003 02:39 AM 5,658 more.exe
08/30/2006 04:20 AM 15,340 move.exe
06/29/2006 12:01 PM 4,291 nansi.sys
08/22/2006 08:40 AM 2,839 nlsfunc.exe
03/12/2005 10:53 AM 4,088 pcisleep.com
03/25/2001 04:10 AM 21,234 replace.exe
09/14/2005 03:09 AM 6,320 share.com
12/21/2005 10:31 AM 15,705 shrdrv86.exe
05/30/2005 05:18 AM 2,423 shsucdhd.exe
12/26/2005 05:00 AM 5,612 shsucdx.com
67 File(s) 1,022,169 bytes
0 Dir(s) 127,455,232 bytes free

When I first ran dump.bat I thought there was a problem running at the C:\ prompt because the dump.bat said that it was reading drive A:\? I even tried modifying the batch file, changing the "/DSK:A" to "DSK:C" for diagnosis purposes; the end result was the same error. This notebook has an unusal set of boot choices in the BIOS. I think that I made the correct choice because it does boot on the flash drive, but the fact that it is identified as drive C: is confusing to me. Again, I haven't installed MBRTOOL on the computer yet. I don't know why it wasn't part of the installation package that created the bootable flash drive?
 
Hi,

Please clear your web browser cache and re-download the zip packet. Then follow instructions related to boot disk creation and using again.
 
Hi, OK I did it from scratch again, but this time it worked and produced two files: TRK0_DMP.128 and TRK0_DMP.129. I submitted both to the link you provided. I hope this leads to a solution:thanks:
 
Yes, I believe so. It's a Lenovo Thinkpad Z60m. I believe that the only way I can access it is with the ThinkVantage software provided with the notebook.
 
Ok, thanks for the info. Let's get back to that Avast updating issue. Please uninstall the program and try Antivir to see if it updates properly.
 
Hi, I uninstalled AVAST and another AV program I had (but not sure it was running). I installed Antivir as requested and updated it. No problem. I then did a scan using it. It found several viruses, which were quarantined. Here's the scan report it produced:

Avira AntiVir Personal
Report file date: Thursday, August 26, 2010 16:46

Scanning for 2754421 virus strains and unwanted programs.

The program is running as an unrestricted full version.
Online services are available:

Licensee : Avira AntiVir Personal - FREE Antivirus
Serial number : 0000149996-ADJIE-0000001
Platform : Windows XP
Windows version : (Service Pack 3) [5.1.2600]
Boot mode : Normally booted
Username : SYSTEM
Computer name : USCMOBILE

Version information:
BUILD.DAT : 10.0.0.567 32097 Bytes 4/19/2010 15:07:00
AVSCAN.EXE : 10.0.3.0 433832 Bytes 4/1/2010 17:37:38
AVSCAN.DLL : 10.0.3.0 46440 Bytes 4/1/2010 17:57:04
LUKE.DLL : 10.0.2.3 104296 Bytes 3/7/2010 23:33:04
LUKERES.DLL : 10.0.0.1 12648 Bytes 2/11/2010 04:40:49
VBASE000.VDF : 7.10.0.0 19875328 Bytes 11/6/2009 14:05:36
VBASE001.VDF : 7.10.1.0 1372672 Bytes 11/19/2009 00:27:49
VBASE002.VDF : 7.10.3.1 3143680 Bytes 1/20/2010 22:37:42
VBASE003.VDF : 7.10.3.75 996864 Bytes 1/26/2010 21:37:42
VBASE004.VDF : 7.10.4.203 1579008 Bytes 3/5/2010 16:29:03
VBASE005.VDF : 7.10.6.82 2494464 Bytes 4/15/2010 20:41:47
VBASE006.VDF : 7.10.7.218 2294784 Bytes 6/2/2010 20:42:22
VBASE007.VDF : 7.10.9.165 4840960 Bytes 7/23/2010 20:43:33
VBASE008.VDF : 7.10.9.166 2048 Bytes 7/23/2010 20:43:33
VBASE009.VDF : 7.10.9.167 2048 Bytes 7/23/2010 20:43:33
VBASE010.VDF : 7.10.9.168 2048 Bytes 7/23/2010 20:43:33
VBASE011.VDF : 7.10.9.169 2048 Bytes 7/23/2010 20:43:34
VBASE012.VDF : 7.10.9.170 2048 Bytes 7/23/2010 20:43:34
VBASE013.VDF : 7.10.9.198 157696 Bytes 7/26/2010 20:43:36
VBASE014.VDF : 7.10.9.255 997888 Bytes 7/29/2010 20:43:50
VBASE015.VDF : 7.10.10.28 139264 Bytes 8/2/2010 20:43:52
VBASE016.VDF : 7.10.10.52 127488 Bytes 8/3/2010 20:43:54
VBASE017.VDF : 7.10.10.84 137728 Bytes 8/6/2010 20:43:56
VBASE018.VDF : 7.10.10.107 176640 Bytes 8/9/2010 20:43:59
VBASE019.VDF : 7.10.10.130 132608 Bytes 8/10/2010 20:44:01
VBASE020.VDF : 7.10.10.158 131072 Bytes 8/12/2010 20:44:03
VBASE021.VDF : 7.10.10.190 136704 Bytes 8/16/2010 20:44:05
VBASE022.VDF : 7.10.10.217 118272 Bytes 8/19/2010 20:44:07
VBASE023.VDF : 7.10.10.246 130048 Bytes 8/23/2010 20:44:11
VBASE024.VDF : 7.10.11.11 144896 Bytes 8/25/2010 20:44:14
VBASE025.VDF : 7.10.11.12 2048 Bytes 8/25/2010 20:44:14
VBASE026.VDF : 7.10.11.13 2048 Bytes 8/25/2010 20:44:14
VBASE027.VDF : 7.10.11.14 2048 Bytes 8/25/2010 20:44:14
VBASE028.VDF : 7.10.11.15 2048 Bytes 8/25/2010 20:44:14
VBASE029.VDF : 7.10.11.16 2048 Bytes 8/25/2010 20:44:15
VBASE030.VDF : 7.10.11.17 2048 Bytes 8/25/2010 20:44:15
VBASE031.VDF : 7.10.11.28 107520 Bytes 8/26/2010 20:44:16
Engineversion : 8.2.4.46
AEVDF.DLL : 8.1.2.1 106868 Bytes 8/26/2010 20:45:02
AESCRIPT.DLL : 8.1.3.44 1364346 Bytes 8/26/2010 20:45:02
AESCN.DLL : 8.1.6.1 127347 Bytes 8/26/2010 20:44:56
AESBX.DLL : 8.1.3.1 254324 Bytes 8/26/2010 20:45:04
AERDL.DLL : 8.1.8.2 614772 Bytes 8/26/2010 20:44:55
AEPACK.DLL : 8.2.3.5 471412 Bytes 8/26/2010 20:44:50
AEOFFICE.DLL : 8.1.1.8 201081 Bytes 8/26/2010 20:44:47
AEHEUR.DLL : 8.1.2.19 2867574 Bytes 8/26/2010 20:44:45
AEHELP.DLL : 8.1.13.3 242038 Bytes 8/26/2010 20:44:28
AEGEN.DLL : 8.1.3.20 397684 Bytes 8/26/2010 20:44:26
AEEMU.DLL : 8.1.2.0 393588 Bytes 8/26/2010 20:44:24
AECORE.DLL : 8.1.16.2 192887 Bytes 8/26/2010 20:44:22
AEBB.DLL : 8.1.1.0 53618 Bytes 8/26/2010 20:44:20
AVWINLL.DLL : 10.0.0.0 19304 Bytes 1/14/2010 17:03:38
AVPREF.DLL : 10.0.0.0 44904 Bytes 1/14/2010 17:03:35
AVREP.DLL : 10.0.0.8 62209 Bytes 2/18/2010 21:47:40
AVREG.DLL : 10.0.3.0 53096 Bytes 4/1/2010 17:35:46
AVSCPLR.DLL : 10.0.3.0 83816 Bytes 4/1/2010 17:39:51
AVARKT.DLL : 10.0.0.14 227176 Bytes 4/1/2010 17:22:13
AVEVTLOG.DLL : 10.0.0.8 203112 Bytes 1/26/2010 14:53:30
SQLITE3.DLL : 3.6.19.0 355688 Bytes 1/28/2010 17:57:58
AVSMTP.DLL : 10.0.0.17 63848 Bytes 3/16/2010 20:38:56
NETNT.DLL : 10.0.0.0 11624 Bytes 2/19/2010 19:41:00
RCIMAGE.DLL : 10.0.0.26 2550120 Bytes 1/28/2010 18:10:20
RCTEXT.DLL : 10.0.53.0 97128 Bytes 4/9/2010 19:14:29

Configuration settings for the scan:
Jobname.............................: Complete system scan
Configuration file..................: c:\program files\avira\antivir desktop\sysscan.avp
Logging.............................: low
Primary action......................: interactive
Secondary action....................: ignore
Scan master boot sector.............: on
Scan boot sector....................: on
Boot sectors........................: C:, E:,
Process scan........................: on
Extended process scan...............: on
Scan registry.......................: on
Search for rootkits.................: on
Integrity checking of system files..: off
Scan all files......................: All files
Scan archives.......................: on
Recursion depth.....................: 20
Smart extensions....................: on
Macro heuristic.....................: on
File heuristic......................: medium

Start of the scan: Thursday, August 26, 2010 16:46

Starting search for hidden objects.
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\RNG\seed
[NOTE] The registry entry is invisible.
SynTPLpr.exe
[NOTE] The process is not visible.
c:\program files\thinkpad\connectutilities\acfnf5.exe
c:\Program Files\ThinkPad\ConnectUtilities\AcFnF5.exe
[NOTE] The process is not visible.
c:\program files\ibm thinkvantage\client security solution\cssplanarswap.exe
c:\Program Files\IBM ThinkVantage\Client Security Solution\cssplanarswap.exe
[NOTE] The process is not visible.

The scan of running processes will be started
Scan process 'rsmsink.exe' - '29' Module(s) have been scanned
Scan process 'msdtc.exe' - '40' Module(s) have been scanned
Scan process 'dllhost.exe' - '61' Module(s) have been scanned
Scan process 'dllhost.exe' - '45' Module(s) have been scanned
Scan process 'vssvc.exe' - '48' Module(s) have been scanned
Scan process 'avscan.exe' - '70' Module(s) have been scanned
Scan process 'avcenter.exe' - '63' Module(s) have been scanned
Scan process 'IzyMail.exe' - '21' Module(s) have been scanned
Scan process 'SPUVolumeWatcher.exe' - '24' Module(s) have been scanned
Scan process 'Ding.exe' - '68' Module(s) have been scanned
Scan process 'CCC.exe' - '42' Module(s) have been scanned
Scan process 'apcsystray.exe' - '29' Module(s) have been scanned
Scan process 'WindowsSearch.exe' - '67' Module(s) have been scanned
Scan process 'SvcGuiHlpr.exe' - '60' Module(s) have been scanned
Scan process 'BTSTAC~1.EXE' - '52' Module(s) have been scanned
Scan process 'DLG.exe' - '25' Module(s) have been scanned
Scan process 'BTTray.exe' - '49' Module(s) have been scanned
Scan process 'ccc.exe' - '156' Module(s) have been scanned
Scan process 'alg.exe' - '33' Module(s) have been scanned
Scan process 'ChoiceMail.exe' - '83' Module(s) have been scanned
Scan process 'AcMurocHlpr.exe' - '62' Module(s) have been scanned
Scan process 'ctfmon.exe' - '26' Module(s) have been scanned
Scan process 'WMPNSCFG.exe' - '27' Module(s) have been scanned
Scan process 'Eraser.exe' - '38' Module(s) have been scanned
Scan process 'ChoiceMail.exe' - '15' Module(s) have been scanned
Scan process 'avgnt.exe' - '54' Module(s) have been scanned
Scan process 'jusched.exe' - '22' Module(s) have been scanned
Scan process 'MOM.EXE' - '52' Module(s) have been scanned
Scan process 'ZuneLauncher.exe' - '22' Module(s) have been scanned
Scan process 'smax4pnp.exe' - '32' Module(s) have been scanned
Scan process 'AwaySch.EXE' - '21' Module(s) have been scanned
Scan process 'DLACTRLW.EXE' - '30' Module(s) have been scanned
Scan process 'scheduler_proxy.exe' - '21' Module(s) have been scanned
Scan process 'rundll32.exe' - '35' Module(s) have been scanned
Scan process 'ipoint.exe' - '47' Module(s) have been scanned
Scan process 'SetIcon.exe' - '19' Module(s) have been scanned
Scan process 'rundll32.exe' - '53' Module(s) have been scanned
Scan process 'ACWLIcon.exe' - '31' Module(s) have been scanned
Scan process 'pdservice.exe' - '24' Module(s) have been scanned
Scan process 'cssauth.exe' - '50' Module(s) have been scanned
Scan process 'issch.exe' - '11' Module(s) have been scanned
Scan process 'LPMGR.exe' - '40' Module(s) have been scanned
Scan process 'TpScrex.exe' - '19' Module(s) have been scanned
Scan process 'TPONSCR.exe' - '18' Module(s) have been scanned
Scan process 'TPHKMGR.exe' - '41' Module(s) have been scanned
Scan process 'EzEjMnAp.Exe' - '24' Module(s) have been scanned
Scan process 'TpShocks.exe' - '18' Module(s) have been scanned
Scan process 'SynTPEnh.exe' - '33' Module(s) have been scanned
Scan process 'SynTPLpr.exe' - '15' Module(s) have been scanned
Scan process 'Explorer.EXE' - '106' Module(s) have been scanned
Scan process 'logmon.exe' - '13' Module(s) have been scanned
Scan process 'WMPNetwk.exe' - '53' Module(s) have been scanned
Scan process 'AcSvc.exe' - '68' Module(s) have been scanned
Scan process 'ZuneBusEnum.exe' - '26' Module(s) have been scanned
Scan process 'SearchIndexer.exe' - '58' Module(s) have been scanned
Scan process 'tvtsched.exe' - '42' Module(s) have been scanned
Scan process 'avshadow.exe' - '25' Module(s) have been scanned
Scan process 'rrservice.exe' - '48' Module(s) have been scanned
Scan process 'ibmtcsd.exe' - '16' Module(s) have been scanned
Scan process 'TpKmpSVC.exe' - '9' Module(s) have been scanned
Scan process 'TPHDEXLG.exe' - '15' Module(s) have been scanned
Scan process 'suservice.exe' - '54' Module(s) have been scanned
Scan process 'svchost.exe' - '38' Module(s) have been scanned
Scan process 'RegSrvc.exe' - '21' Module(s) have been scanned
Scan process 'jqs.exe' - '33' Module(s) have been scanned
Scan process 'IntuitUpdateService.exe' - '60' Module(s) have been scanned
Scan process 'svchost.exe' - '34' Module(s) have been scanned
Scan process 'btwdins.exe' - '21' Module(s) have been scanned
Scan process 'svchost.exe' - '34' Module(s) have been scanned
Scan process 'mainserv.exe' - '33' Module(s) have been scanned
Scan process 'avguard.exe' - '56' Module(s) have been scanned
Scan process 'AcPrfMgrSvc.exe' - '51' Module(s) have been scanned
Scan process 'IPSSVC.EXE' - '14' Module(s) have been scanned
Scan process 'svchost.exe' - '34' Module(s) have been scanned
Scan process 'sched.exe' - '48' Module(s) have been scanned
Scan process 'spoolsv.exe' - '71' Module(s) have been scanned
Scan process 'svchost.exe' - '44' Module(s) have been scanned
Scan process 'svchost.exe' - '32' Module(s) have been scanned
Scan process 'S24EvMon.exe' - '28' Module(s) have been scanned
Scan process 'EvtEng.exe' - '55' Module(s) have been scanned
Scan process 'Ati2evxx.exe' - '31' Module(s) have been scanned
Scan process 'svchost.exe' - '30' Module(s) have been scanned
Scan process 'svchost.exe' - '172' Module(s) have been scanned
Scan process 'svchost.exe' - '41' Module(s) have been scanned
Scan process 'svchost.exe' - '54' Module(s) have been scanned
Scan process 'Ati2evxx.exe' - '28' Module(s) have been scanned
Scan process 'ibmpmsvc.exe' - '11' Module(s) have been scanned
Scan process 'vtserver.exe' - '30' Module(s) have been scanned
Scan process 'lsass.exe' - '58' Module(s) have been scanned
Scan process 'services.exe' - '35' Module(s) have been scanned
Scan process 'winlogon.exe' - '81' Module(s) have been scanned
Scan process 'csrss.exe' - '14' Module(s) have been scanned
Scan process 'smss.exe' - '2' Module(s) have been scanned

Starting master boot sector scan:
Master boot sector HD0
[INFO] No virus was found!

Start scanning boot sectors:
Boot sector 'C:\'
[INFO] No virus was found!
Boot sector 'E:\'
[INFO] No virus was found!

Starting to scan executable files (registry).
The registry was scanned ( '1859' files ).


Starting the file scan:

Begin scan in 'C:\' <IBM_PRELOAD>
C:\Program Files\Digiportal Software\ChoiceMail.zip
[0] Archive type: ZIP
[DETECTION] Contains recognition pattern of the WORM/SdBot.352768.1 worm
--> ChoiceMail/coach.exe
[DETECTION] Contains recognition pattern of the WORM/SdBot.352768.1 worm
[WARNING] This file is a mailbox. To avoid damaging your emails this file will not be repaired or deleted.
C:\System Volume Information\_restore{5D527826-05BD-4A83-8416-28ACDDA14001}\RP706\A0067284.exe
[DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
C:\System Volume Information\_restore{5D527826-05BD-4A83-8416-28ACDDA14001}\RP710\A0068373.exe
[DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
C:\System Volume Information\_restore{5D527826-05BD-4A83-8416-28ACDDA14001}\RP724\A0069438.exe
[DETECTION] Is the TR/FraudPack.bbsu Trojan
C:\System Volume Information\_restore{5D527826-05BD-4A83-8416-28ACDDA14001}\RP724\A0069511.exe
[DETECTION] Is the TR/FraudPack.bbsu Trojan
C:\System Volume Information\_restore{5D527826-05BD-4A83-8416-28ACDDA14001}\RP737\A0071554.exe
[DETECTION] Contains recognition pattern of the WORM/SdBot.352768.1 worm
C:\System Volume Information\_restore{5D527826-05BD-4A83-8416-28ACDDA14001}\RP755\A0074223.exe
[DETECTION] Contains recognition pattern of the WORM/SdBot.352768.1 worm
Begin scan in 'E:\' <Data>
E:\Richard's Documents\Downloads\More of MY DOWNLOADS\Products\ChoiceMail-FInstaller.exe
[0] Archive type: ZIP SFX (self extracting)
[DETECTION] Contains recognition pattern of the WORM/SdBot.352768.E worm
--> CMFREEINSTALL265.EXE
[1] Archive type: ZIP SFX (self extracting)
--> COACH.EXE
[DETECTION] Contains recognition pattern of the WORM/SdBot.352768.E worm
E:\Richard's Documents\Downloads\More of MY DOWNLOADS\Software\Choice Mail Free v265 Installer.exe
[0] Archive type: ZIP SFX (self extracting)
[DETECTION] Contains recognition pattern of the WORM/SdBot.352768 worm
--> CMFREEINSTALL26.EXE
[1] Archive type: ZIP SFX (self extracting)
--> COACH.EXE
[DETECTION] Contains recognition pattern of the WORM/SdBot.352768 worm
E:\Richard's Documents\Downloads\My Old Downloads\ChoiceMail\CMO3.0-Installer.exe
[0] Archive type: ZIP SFX (self extracting)
[DETECTION] Contains recognition pattern of the WORM/SdBot.352768.1 worm
--> CMWSINGLEUSERINSTALL31.EXE
[1] Archive type: ZIP SFX (self extracting)
--> COACH.EXE
[DETECTION] Contains recognition pattern of the WORM/SdBot.352768.1 worm
E:\Richard's Documents\Downloads\My Old Downloads\ZDNet\datacd.zip
[0] Archive type: ZIP
[DETECTION] Is the TR/Agent.127249.A Trojan
--> DATACD.EXE
[DETECTION] Is the TR/Agent.127249.A Trojan
E:\System Volume Information\_restore{5D527826-05BD-4A83-8416-28ACDDA14001}\RP737\A0071660.com
[DETECTION] Is the TR/Hijacker.Gen Trojan
--> Object
[DETECTION] Is the TR/Hijacker.Gen Trojan
E:\WINWORD\VIRUSFIX\SCAN.DOC
[DETECTION] Contains HEUR/Macro.Word95 suspicious code

Beginning disinfection:
E:\WINWORD\VIRUSFIX\SCAN.DOC
[DETECTION] Contains HEUR/Macro.Word95 suspicious code
[NOTE] The detection was classified as suspicious.
[NOTE] The file was moved to the quarantine directory under the name '4f124887.qua'.
E:\System Volume Information\_restore{5D527826-05BD-4A83-8416-28ACDDA14001}\RP737\A0071660.com
[DETECTION] Is the TR/Hijacker.Gen Trojan
[NOTE] The file was moved to the quarantine directory under the name '579460cd.qua'.
E:\Richard's Documents\Downloads\My Old Downloads\ZDNet\datacd.zip
[DETECTION] Is the TR/Agent.127249.A Trojan
[NOTE] The file was moved to the quarantine directory under the name '05873df6.qua'.
E:\Richard's Documents\Downloads\My Old Downloads\ChoiceMail\CMO3.0-Installer.exe
[DETECTION] Contains recognition pattern of the WORM/SdBot.352768.1 worm
[NOTE] The file was moved to the quarantine directory under the name '639f7200.qua'.
E:\Richard's Documents\Downloads\More of MY DOWNLOADS\Software\Choice Mail Free v265 Installer.exe
[DETECTION] Contains recognition pattern of the WORM/SdBot.352768 worm
[NOTE] The file was moved to the quarantine directory under the name '263b5f13.qua'.
E:\Richard's Documents\Downloads\More of MY DOWNLOADS\Products\ChoiceMail-FInstaller.exe
[DETECTION] Contains recognition pattern of the WORM/SdBot.352768.E worm
[NOTE] The file was moved to the quarantine directory under the name '59206d7c.qua'.
C:\System Volume Information\_restore{5D527826-05BD-4A83-8416-28ACDDA14001}\RP755\A0074223.exe
[DETECTION] Contains recognition pattern of the WORM/SdBot.352768.1 worm
[NOTE] The file was moved to the quarantine directory under the name '15db410e.qua'.
C:\System Volume Information\_restore{5D527826-05BD-4A83-8416-28ACDDA14001}\RP737\A0071554.exe
[DETECTION] Contains recognition pattern of the WORM/SdBot.352768.1 worm
[NOTE] The file was moved to the quarantine directory under the name '69c3015e.qua'.
C:\System Volume Information\_restore{5D527826-05BD-4A83-8416-28ACDDA14001}\RP724\A0069511.exe
[DETECTION] Is the TR/FraudPack.bbsu Trojan
[NOTE] The file was moved to the quarantine directory under the name '44992e13.qua'.
C:\System Volume Information\_restore{5D527826-05BD-4A83-8416-28ACDDA14001}\RP724\A0069438.exe
[DETECTION] Is the TR/FraudPack.bbsu Trojan
[NOTE] The file was moved to the quarantine directory under the name '5df1158a.qua'.
C:\System Volume Information\_restore{5D527826-05BD-4A83-8416-28ACDDA14001}\RP710\A0068373.exe
[DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
[NOTE] The file was moved to the quarantine directory under the name '31ad39bb.qua'.
C:\System Volume Information\_restore{5D527826-05BD-4A83-8416-28ACDDA14001}\RP706\A0067284.exe
[DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
[NOTE] The file was moved to the quarantine directory under the name '40140029.qua'.
C:\Program Files\Digiportal Software\ChoiceMail.zip
[DETECTION] Contains recognition pattern of the WORM/SdBot.352768.1 worm
[WARNING] The file was ignored!


End of the scan: Thursday, August 26, 2010 18:33
Used time: 1:45:24 Hour(s)

The scan has been done completely.

12686 Scanned directories
562445 Files were scanned
12 Viruses and/or unwanted programs were found
1 Files were classified as suspicious
0 files were deleted
0 Viruses and unwanted programs were repaired
12 Files were moved to quarantine
0 Files were renamed
0 Files cannot be scanned
562432 Files not concerned
13087 Archives were scanned
1 Warnings
12 Notes
703314 Objects were scanned with rootkit scan
4 Hidden objects were found

So now what? I don't know if it found all of the infection or just some of it. I won't feel like it's gone until other AV software, like AVAST, says that I'm clean.
 
Hi,

Those ChoiceMail related findings look like possible false positives. To me your system looks ok. If it was AV updates blocking infection there then it would likely affect other AV than Avast too.
 
I agree. That Choicemail zip file has been around for years. It was part of the original installation package so I tend to believe that it's OK.

I'm going to uninstall Antivir and reinstall AVAST and see if it works OK now. I'll let you know what happens.:)
 
Well, I was able to install and update AVAST. I then ran a complete scan of the computer. I came up clean. Then I ran spybot search & destroy. It found two MalwareC entries in the registry:

--- Search result list ---
Fraud.AVSecuritySuite: [SBI $5587D6DE] Settings (Registry value, fixed)
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyServer=...http=127.0.0.1:5643...

Fraud.AVSecuritySuite: [SBI $5587D6DE] Settings (Registry value, fixed)
HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyServer=...http=127.0.0.1:5643...

Right Media: Tracking cookie (Internet Explorer: Richard) (Cookie, fixed)

I'm not sure if this is a real virus issue. ChoiceMail, an email spam removal program I've been using for many years, required that I set both incoming and outgoing mail servers to this value (127.0.0.1) in Outlook. However, it doesn't specify a port (5643)??? So I don't know if I still have a problem or not?
 
Back
Top