Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Unknown malware [Solved]


  • This topic is locked This topic is locked

#31
diinovo

diinovo

    Member

  • Topic Starter
  • Member
  • PipPip
  • 28 posts
Dear CompCav
My Report

I did not want to wait 8 hours of scan with Malwarebytes and end up with no report.

I decided to use Kaspersky Security scan, I uninstalled Kaspersky Internet Security 2012 to run the scan.

It took me some 7 hour to clean and delete any files left from the uninstaller. When it finally appeared it was working, I left it to scan, 3 hours later it had not done any scan.

After several install / uninstall it started scanning, I left it overnight and thinking would be finished in the morning, it went for some hours, but I believe that the computer went to sleep after several hours and scan stopped.

I have changed setting not to go to sleep, at moment the scan is at only 42 % and going, I have 2 storage drivers that it may be the cause of the long scan


Task Scheduler (popup box)

Task
user_Feed_Synchronization-{BD292662-BO96-4D30-9F53-29269C
D276C7}: The task Image is corrupt or has been tampered with.

Thank You
  • 0

Advertisements


#32
CompCav

CompCav

    Member 5k

  • Expert
  • 12,448 posts
Thanks for the update :thumbsup:
  • 0

#33
diinovo

diinovo

    Member

  • Topic Starter
  • Member
  • PipPip
  • 28 posts
Can you Please re- sent page with Instructions to post scan

Thanks
  • 0

#34
CompCav

CompCav

    Member 5k

  • Expert
  • 12,448 posts

Well let's try this:

Either rerun MalwareBytes' or run this:

Notes to helper: KSS cannot be installed when other Kasperksy Lab applications are installed
Also KSS does not remove malicious objects or disinfect infected files

  • Go to here
  • Click the download button under Kaspersky Security Scan
  • Download and run the file
  • It will start to download the Kaspersky Security Scan program data
  • Once downloaded the installer will begin
  • Click Next
  • Accept the License Agreement
  • Click Install
  • The program will now install
  • Click Finish
  • Kaspersky Security Scan will now start

    Posted Image
  • Click the Full Scan button

    Posted Image
  • The scan will take about an hour or two depending on the amount of data on your hard drive
  • If the scan detects problems it will open a Problems found window (you can click Details to view the scan results)

    Posted Image
  • Once the scan is complete do the following:
    • For XP: Navigate to C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\KSS2\DataRoot
      For Vista/7: Navigate to C:\ProgramData\Kaspersky Lab\KSS2\DataRoot
    • Right-click on the HtmlReport folder --> Click Send to --> Click Compressed (zipped) folder
    • Attach the HtmlReport zipped folder to your next post
      Posted Image
      Posted Image
      Posted Image
  • You can now close Kaspersky Security Scan


  • 0

#35
diinovo

diinovo

    Member

  • Topic Starter
  • Member
  • PipPip
  • 28 posts
Well, Nothing works
the upload limit is 1MB, the zip file is 2,084 KB
Copy paste does not work, noting seems to work? Sorry

Thank You
  • 0

#36
CompCav

CompCav

    Member 5k

  • Expert
  • 12,448 posts
Go here

Set up an account then upload the file(s).

Then post me a link to the file(s)
  • 0

#37
diinovo

diinovo

    Member

  • Topic Starter
  • Member
  • PipPip
  • 28 posts
http://www.mediafire.com/myfiles.php#
  • 0

#38
CompCav

CompCav

    Member 5k

  • Expert
  • 12,448 posts
I need the link for the page your files are on. That link is to the website not your specific page.
  • 0

#39
diinovo

diinovo

    Member

  • Topic Starter
  • Member
  • PipPip
  • 28 posts
This may help I did not see or wasn’t there
Thank You

http://www.mediafire...um0aadzdz3070ja


Attached File  HtmlReport.zip   318.29KB   25 downloads
  • 0

#40
CompCav

CompCav

    Member 5k

  • Expert
  • 12,448 posts
If you have Malwarebytes 1.6 or better installed please disable it for the duration of this run
To disable MBAM
Open the scanner and select the protection tab
Remove the tick from "Start with Windows"
Reboot and then run OTL
Posted Image




  • Please reopen Posted Image on your desktop.
  • Copy and Paste the following code into the Posted Image textbox.

    :OTL
    
    
    :files
    ipconfig /flushdns /c
    F:\NEW PROGRAMS\CORELL\Corel PDF Fusion v1.0
    G:\Programs\Fax & Messaging\FaxMail
    G:\Programs\Kazaa
    G:\Programs\Kazaa Music
    G:\Programs\My Shared Folder (Kazaar )
    
    
    :reg
    
    
    :Commands
    [purity]
    [resethosts]
    [emptytemp]
    [createrestorepoint]
  • Push Posted Image
  • OTL may ask to reboot the machine. Please do so if asked.
  • Click the OK button.
  • A report will open. Copy and Paste that report in your next reply.
  • If the machine reboots, the log will be located at C:\_OTL\MovedFiles\mmddyyyy_hhmmss.log, where mmddyyyy_hhmmss is the date and the time of the tool run.



Please post the OTL fix log
  • 0

Advertisements


#41
diinovo

diinovo

    Member

  • Topic Starter
  • Member
  • PipPip
  • 28 posts
I disabled Malwarebytes and restarted, run OTL successful, it asked to restart, restart,
report on screen on restart, report attached
Thank You


All processes killed
========== OTL ==========
========== FILES ==========
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Users\Administrator\Desktop\cmd.bat deleted successfully.
C:\Users\Administrator\Desktop\cmd.txt deleted successfully.
File\Folder F:\NEW PROGRAMS\CORELL\Corel PDF Fusion v1.0 not found.
G:\Programs\Fax & Messaging\FaxMail folder moved successfully.
G:\Programs\Kazaa\Skins\Black Glass folder moved successfully.
G:\Programs\Kazaa\Skins folder moved successfully.
G:\Programs\Kazaa\My Shared Folder folder moved successfully.
G:\Programs\Kazaa folder moved successfully.
G:\Programs\Kazaa Music\Skins\Black Glass folder moved successfully.
G:\Programs\Kazaa Music\Skins folder moved successfully.
G:\Programs\Kazaa Music\Promotions folder moved successfully.
G:\Programs\Kazaa Music\My Shared Folder folder moved successfully.
G:\Programs\Kazaa Music\My Search Agents\Black Glass folder moved successfully.
G:\Programs\Kazaa Music\My Search Agents folder moved successfully.
G:\Programs\Kazaa Music\My Channels\Images folder moved successfully.
G:\Programs\Kazaa Music\My Channels\Bin folder moved successfully.
G:\Programs\Kazaa Music\My Channels folder moved successfully.
G:\Programs\Kazaa Music\licenses folder moved successfully.
G:\Programs\Kazaa Music\Html folder moved successfully.
G:\Programs\Kazaa Music\Help folder moved successfully.
G:\Programs\Kazaa Music\Db folder moved successfully.
G:\Programs\Kazaa Music\data folder moved successfully.
G:\Programs\Kazaa Music\BGP2P\plugins folder moved successfully.
G:\Programs\Kazaa Music\BGP2P folder moved successfully.
G:\Programs\Kazaa Music folder moved successfully.
G:\Programs\My Shared Folder (Kazaar ) folder moved successfully.
========== REGISTRY ==========
========== COMMANDS ==========
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 585386502 bytes
->Temporary Internet Files folder emptied: 189638468 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Flash cache emptied: 1951 bytes

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Public
->Temp folder emptied: 0 bytes

User: UpdatusUser
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 303790796 bytes
RecycleBin emptied: 149369 bytes

Total Files Cleaned = 1,029.00 mb

Restore point Set: OTL Restore Point

OTL by OldTimer - Version 3.2.54.1 log created on 08032012_100731

Files\Folders moved on Reboot...
C:\Users\Administrator\AppData\Local\Temp\BITFA07.tmp moved successfully.
C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\AntiPhishing\ED8654D5-B9F0-4DD9-B3E8-F8F560086FDF.dat moved successfully.
C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\U0Z974B0\st[8] moved successfully.
C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RVP2LRTP\fastbutton[1].htm moved successfully.
C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RVP2LRTP\fc[8].htm moved successfully.
C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\AMEG10XX\open[1].bmp moved successfully.
C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4GRABH2R\md[1].htm moved successfully.
C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4GRABH2R\st[3] moved successfully.
C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4GRABH2R\st[8] moved successfully.
File move failed. C:\Windows\temp\_avast_\Webshlock.txt scheduled to be moved on reboot.

PendingFileRenameOperations files...
File C:\Users\Administrator\AppData\Local\Temp\BITFA07.tmp not found!
File C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\AntiPhishing\ED8654D5-B9F0-4DD9-B3E8-F8F560086FDF.dat not found!
File C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\U0Z974B0\st[8] not found!
File C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RVP2LRTP\fastbutton[1].htm not found!
File C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RVP2LRTP\fc[8].htm not found!
File C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\AMEG10XX\open[1].bmp not found!
File C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4GRABH2R\md[1].htm not found!
File C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4GRABH2R\st[3] not found!
File C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4GRABH2R\st[8] not found!
[2012/08/03 10:12:41 | 000,000,000 | ---- | M] () C:\Windows\temp\_avast_\Webshlock.txt : Unable to obtain MD5

Registry entries deleted on Reboot...
  • 0

#42
CompCav

CompCav

    Member 5k

  • Expert
  • 12,448 posts
Now the big question..........How is your computer running?
  • 0

#43
diinovo

diinovo

    Member

  • Topic Starter
  • Member
  • PipPip
  • 28 posts
Dar CompCav

I can see no problems now everything seems to be working OK
I believe that you have cleaned it, and done a good job , now what is your opinion?
my knowledge is very limited in computing
Thank You
  • 0

#44
CompCav

CompCav

    Member 5k

  • Expert
  • 12,448 posts
Subject to no further problems :)

I will remove my tools now and give some recommendations, but, I would like you to run for 24 hours or so and come back if you have any problems

Your log now appears clean :thumbsup:

The following will implement some cleanup procedures as well as reset System Restore points:

Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following

    :Commands
    [resethosts]
    [emptytemp]
    [Reboot]

  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done

Remove ComboFix

  • Hold down the Windows key + R on your keyboard. This will display the Run dialogue box
  • In the Run box, type in ComboFix /Uninstall (Notice the space between the "x" and "/") then click OK

    Posted Image
  • Follow the prompts on the screen
  • A message should appear confirming that ComboFix was uninstalled

Run OTL and hit the Cleanup button. It will remove all the programs we have used plus itself.

We will now confirm that your hidden files are set to that, as some of the tools I use will change that
  • Click Start.
  • Open My Computer.
  • Select the Tools menu and click Folder Options.
  • Select the View Tab.
  • Under the Hidden files and folders heading select Do not show hidden files and folders.
  • Click Yes to confirm.
  • Click OK.

Posted Image
Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system.
Please follow these steps to remove older version of Java components and upgrade the application.

Upgrading Java:
  • Go to this site and click Do I have Java
  • It will check your current version and then offer to update to the latest version

SPRING CLEAN

To manually create a new Restore Point
  • Go to Control Panel and select System
  • Select System
  • On the left select System Protection and accept the warning if you get one
  • Select System Protection Tab
  • Select Create at the bottom
  • Type in a name i.e. Clean
  • Select Create

Now we can purge the infected ones
  • GoStart > All programs > Accessories > system tools
  • Right click Disc cleanup and select run as administrator
  • Select Your main drive and accept the warning if you get one
  • For a few moments the system will make some calculations
  • Select the More Options tab
  • In the System Restore and Shadow Backups select Clean up
  • Select Delete on the pop up
  • Select OK
  • Select Delete

Now that you are clean, to help protect your computer in the future I recommend that you get the following free programs:
Posted Image
Malwarebytes. Update and run weekly to keep your system clean

Download and install FileHippo update checker and run it monthly it will show you which programs on your system need updating and give a download link

It is critical to have both a firewall and anti virus to protect your system and to keep them updated. To keep your operating system up to date visit

To learn more about how to protect yourself while on the internet read our little guide How did I get infected in the first place ?

Also for free software so that you do not have to risk introducing malware to your computer, I suggest you check these locations online for the software you need/want:

osalt.com
alternativeTo




Keep safe :wave:
  • 0

#45
CompCav

CompCav

    Member 5k

  • Expert
  • 12,448 posts
Since this issue appears to be resolved ... this Topic has been closed. Glad we could help. :)

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP