AV Suite Strikes

Today I learned a painful lesson, and continue learning it.

Before I begin, I'd like to introduce my self. My name is James, I'm a rooky when it comes to computers at the moment, but am advancing my career in Cyber Security, Criminal Justice.

That being said, I made one of the worst mistakes in my life. In order to fix my computer the right way, I have to first admit that I was using a pirating program in order to download a game. The game key generator didnt work so I googled the maker of the game maker, and clicked the link. After the link, the AV Suit Virus program automatically kicked in.

[For reference, this is Vista 32bit]

After which I tried doing anything, It locked me out of msn, wouldn't allow me to run any programs, wouldn't allow me to click my mouse all without an error bubble popping up.

I restarted in safe-mode because I couldn't and can't start the PC Up or it will BSOD, and was given guidance by my friend Reid. I was guided to AVAST First, which I downloaded and given a guide to delete HKEY Files within the regedit area of using windows+r. After full scan and eliminating four threats, and erasing all the guided files I was instructed to erase. I tried rebooting again, it still BSOD's. So I downloaded Malwarebytes which my friend directed me to next, and am currently running a scan for malware. Through 100,000 files it has found 16 malware infections thus far.

That being said, I will continue to keep this updated. But seriously... all of my stupidity aside, would somebody please help me in any way possible.

Update: 21 file infections detected.

Malwarebytes' Anti-Malware 1.46


Database version: 4219

Windows 6.0.6002 Service Pack 2 (Safe Mode)

Internet Explorer 8.0.6001.18928

6/20/2010 6:56:08 PM

mbam-log-2010-06-20 (18-56-08).txt

Scan type: Full scan (C:\|D:\|E:\|F:\|G:\|H:\|I:\|)

Objects scanned: 280060

Time elapsed: 45 minute(s), 5 second(s)

Memory Processes Infected: 0

Memory Modules Infected: 0

Registry Keys Infected: 26

Registry Values Infected: 5

Registry Data Items Infected: 0

Folders Infected: 2

Files Infected: 13

Memory Processes Infected:

(No malicious items detected)

Memory Modules Infected:

(No malicious items detected)

Registry Keys Infected:

HKEY_CLASSES_ROOT\cscrptxt.cscrptxt (Adware.EZlife) -> No action taken.

HKEY_CLASSES_ROOT\CLSID\{1c69777c-5312-4c0c-94ab-73daaaa5700c} (Adware.EZlife) -> No action taken.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{1c69777c-5312-4c0c-94ab-73daaaa5700c} (Adware.EZlife) -> No action taken.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1c69777c-5312-4c0c-94ab-73daaaa5700c} (Adware.EZlife) -> No action taken.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1c69777c-5312-4c0c-94ab-73daaaa5700c} (Adware.EZlife) -> No action taken.

HKEY_CLASSES_ROOT\CLSID\{e0ec6fba-f009-3535-95d6-b6390db27da1} (Adware.EZlife) -> No action taken.

HKEY_CLASSES_ROOT\cscrptxt.cscrptxt.1.0 (Adware.EZlife) -> No action taken.

HKEY_CLASSES_ROOT\AppID\{84c3c236-f588-4c93-84f4-147b2abbe67b} (Adware.Adrotator) -> No action taken.

HKEY_CLASSES_ROOT\AppID\{38061edc-40bb-4618-a8da-e56353347e6d} (Adware.EZlife) -> No action taken.

HKEY_CLASSES_ROOT\AppID\{7b6a2552-e65b-4a9e-add4-c45577ffd8fd} (Adware.EZLife) -> No action taken.

HKEY_CLASSES_ROOT\CLSID\{4173f7fb-9f8e-4b40-8e5b-24dd06eeacf9} (Trojan.BHO) -> No action taken.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{4173f7fb-9f8e-4b40-8e5b-24dd06eeacf9} (Trojan.BHO) -> No action taken.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{4173f7fb-9f8e-4b40-8e5b-24dd06eeacf9} (Trojan.BHO) -> No action taken.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4173f7fb-9f8e-4b40-8e5b-24dd06eeacf9} (Trojan.BHO) -> No action taken.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\$NtUninstallMTF1011$ (Adware.Adrotator) -> No action taken.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\$NtUninstallWTF1012$ (Adware.Adrotator) -> No action taken.

HKEY_LOCAL_MACHINE\SOFTWARE\Sky-Banners (Adware.Adrotator) -> No action taken.

HKEY_CURRENT_USER\SOFTWARE\Sky-Banners (Adware.Adrotator) -> No action taken.

HKEY_CLASSES_ROOT\adgj.aghlp (Adware.EZLife) -> No action taken.

HKEY_CLASSES_ROOT\adgj.aghlp.1 (Adware.EZLife) -> No action taken.

HKEY_CLASSES_ROOT\adshothlpr.adshothlpr (Adware.Adrotator) -> No action taken.

HKEY_CLASSES_ROOT\adshothlpr.adshothlpr.1.0 (Adware.Adrotator) -> No action taken.

HKEY_CURRENT_USER\Software\avsoft (Trojan.Fraudpack) -> No action taken.

HKEY_CURRENT_USER\Software\avsuite (Rogue.AntivirusSuite) -> No action taken.

HKEY_CURRENT_USER\Software\Street-Ads (Adware.Adrotator) -> No action taken.

HKEY_LOCAL_MACHINE\SOFTWARE\Street-Ads (Adware.Adrotator) -> No action taken.

Registry Values Infected:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\skb (Trojan.Agent.Gen) -> No action taken.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mchk (Trojan.Agent.Gen) -> No action taken.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\vetwbqms (Rogue.AntivirusSuite.Gen) -> No action taken.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\hforeqeluwenuqav (Trojan.Agent.U) -> No action taken.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\apupuqicacepep (Trojan.Agent.U) -> No action taken.

Registry Data Items Infected:

(No malicious items detected)

Folders Infected:

C:\Program Files\$NtUninstallWTF1012$ (Adware.EZLife) -> No action taken.

C:\Windows\$NtUninstallMTF1011$ (Adware.Adrotator) -> No action taken.

Files Infected:

C:\Windows\System32\vdhpt.dll (Adware.EZlife) -> No action taken.

C:\Users\Bart\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\2B1UA2TC\id2[1].htm (Trojan.Dropper) -> No action taken.

C:\Users\Bart\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\2B1UA2TC\jjaiqxsq[1].htm (Trojan.Dropper) -> No action taken.

C:\Users\Bart\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7I42PYT3\gkbjdlwqlt[1].htm (Trojan.Hiloti) -> No action taken.

C:\Users\Bart\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QABTK3TO\kksahc[1].htm (Trojan.Dropper) -> No action taken.

C:\Users\Bart\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QABTK3TO\kksaupwr[1].htm (Trojan.Ransom) -> No action taken.

C:\Windows\System32\rdhpt.dll (Trojan.BHO) -> No action taken.

C:\Program Files\$NtUninstallWTF1012$\elUninstall.exe (Adware.EZLife) -> No action taken.

C:\Windows\$NtUninstallMTF1011$\apUninstall.exe (Adware.Adrotator) -> No action taken.

C:\Windows\System32\idhpt.exe (Trojan.Agent.Gen) -> No action taken.

C:\Users\Bart\AppData\Local\bwlkoaynx\ajyvmxatssd.exe (Rogue.AntivirusSuite.Gen) -> No action taken.

C:\Users\Bart\AppData\Local\WMEnswut.dll (Trojan.Agent.U) -> No action taken.

C:\Users\Bart\AppData\Local\ewunufuqo.dll (Trojan.Agent.U) -> No action taken.

The MBAM saved log of all the infections Malware detected.

In Normal Mode,

Please run another scan with MBAM, make sure you check for updates first.

Download GMER Antirootkit Here, click on Download EXE and save to your Desktop

  • Disconnect from the internet and disable all active protection so your security program drivers will not conflict with gmer's driver
  • Double-click Gmer.exe to run the program.
  • When the program opens, click the "Rootkit" Tab
  • On the right-side, check all the items to be scanned, but leave "Show All" unchecked
  • Select all drives that are connected to your system to be scanned
  • Click the Scan button
  • When the scan is finished, click Copy to save the scan log to the Windows clipboard
  • Open Notepad or a similar text editor
  • Paste the clipboard contents into a text file by clicking Edit | Paste or Ctl V
  • Save the gmer scan log and post it in your next reply.
  • Close Gmer
  • Open a command prompt (Start | run |type cmd and hit Enter)
    • Type or paste the following to unload the gmer driver:
    • net stop gmer
    • Hit Enter
    • Exit the command prompt.

    [*]Re-enable all active protection.


  • Download OTL.exe to your desktop.
  • Double-Click on OTL to run it.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Under the Standard Registry box change it to All.
  • Under Custom scan's and fixes section paste in the below in bold



%systemroot%\*. /mp /s


%systemroot%\system32\*.dll /lockedfiles

%systemroot%\Tasks\*.job /lockedfiles


%systemroot%\system32\drivers\*.sys /90

  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan won't take long.

  • When the scan completes, it will open two notepad windows. OTL.txt and Extras.txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.

