Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Sony vaio laptop infected with malware [Solved]

Malware Baidu

  • This topic is locked This topic is locked

#16
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
ok lets try a different programme


Download AVZ tool from here to your desktop
Unzip all files to a folder on your desktop
Open the folder and double click the AVZ icon avz.JPG
When the tool opens select "File" > "Standards scripts"
avz1.jpg

Place a tick in :


5. Update signature database

Then press "Execute selected scripts"
avz2.JPG

Once that has execute then
select "File" > "Standards scripts"
Place a tick in :

3. Advanced System Analysis with malware removal mode enabled


When finished look in the folder AVZ4 on your desktop
Open the LOG folder
Attach virusinfo_syscure to your next post
vz3.JPG
  • 0

Advertisements


#17
Confused Dave

Confused Dave

    Member

  • Topic Starter
  • Member
  • PipPip
  • 25 posts

Hi,

 

The first step executed fine however the advanced systemarrow-10x10.png analysis appears to freeze before completion. A log folder is generated in the AVZ folder but it is empty. I tried running the process a few times and waiting for quite a while but nothing happens.

 

This is the point at which it seems to stop running

 

Screenshot AvZ.jpg

 

Cheers


  • 0

#18
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Hm it appears that this driver has taken a turn for the worse it even recognises rarely used tools

Download the latest version of TDSSKiller from here and save it to your Desktop.


  • Doubleclick on TDSSKiller.exe to run the application
    tdss%20start.JPG
  • Then click on Change parameters.

    tdss%20Change%20param.JPG
  • Check the boxes beside Verify Driver Digital Signature, Detect TDLFS file system and Use KSN to scan objects , then click OK.
  • Click the Start Scan button.

  • If a suspicious object is detected, the default action will be Skip, click on Continue.

    tdss%20threat.JPG
  • If malicious objects are found, they will show in the Scan results and offer three (3) options.
  • Ensure Cure is selected, then click Continue => Reboot now to finish the cleaning process.
  • Get the report by selecting Reports

    tdss%20report.JPG
  • Note: If Cure is not available, please choose Skip instead, do not choose Delete unless instructed.
Please copy and paste its contents on your next reply.
  • 0

#19
Confused Dave

Confused Dave

    Member

  • Topic Starter
  • Member
  • PipPip
  • 25 posts

Hi

 

The scan completed with no threats detected


  • 0

#20
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Since this procedure takes place outside of Windows, it is best that you print out the instructions or open it on another media while carrying out the disinfection.

Please read the instructions carefully before attempting the fix!

Fix with Farbar Recovery Scan Tool in Recovery Environment

- Download the attached fixlist.txt and save it to your Desktop <- IMPORTANT!
Attached File  fixlist.txt   536bytes   69 downloads
- Close all active applications.

- Hold down the Shift key and choose Restart on the restart menu to reboot into the Windows 10 Advanced Boot Options menu.

- Windows will reboot into a blue menu. Choose Troubleshoot.

- You will be offered 3 options: Refresh Your PC, Reset Your PC and Advanced options. Choose Advanced options.

==========

On the Advanced options menu you will get the following options:

System Restore
System Image Recovery
Automatic Repair
Command Prompt
Startup Settings

Select Command Prompt.

==========

Once in the Command Prompt:

In the Command Prompt window, type in C:\Users\Ellen\Desktop\FRST64.exe and press Enter. This will launch Farbar Recovery Scan Tool.
Press Fix just once and wait.
It will make a log named Fixlog.txt on the Desktop when the fixing process is finished.
Reboot into Windows when done.
Please copy and paste the contents of Fixlog.txt in your next reply.
  • 0

#21
Confused Dave

Confused Dave

    Member

  • Topic Starter
  • Member
  • PipPip
  • 25 posts

Hi

 

Attached File  Fixlog.txt   783bytes   87 downloads


  • 0

#22
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts

OK that killed it ..  Could you now try and install Kaspersky and let me know the result


  • 0

#23
Confused Dave

Confused Dave

    Member

  • Topic Starter
  • Member
  • PipPip
  • 25 posts

Started the install and it is interrupted by Baidu antivirus showing as incompatible software. It advises me to remove it through the control panel but it isn't among the programs?


  • 0

#24
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Could you run a fresh FRST scan please as I believe I moved all references to baidu
  • 0

#25
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Also is this the screen that Kaspersky shows ?


Capture.JPG
  • 0

Advertisements


#26
Confused Dave

Confused Dave

    Member

  • Topic Starter
  • Member
  • PipPip
  • 25 posts

Yes that's the screen, the remove option only allows a manual uninstall and I can't find the program

 

Attached File  FRST.txt   59.79KB   57 downloadsAttached File  Addition.txt   18.91KB   106 downloads


  • 0

#27
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Is the skip button present on the Kaspersky popup ? If so click that as I can see no running drivers or folders/files associated with baidu
  • 0

#28
Confused Dave

Confused Dave

    Member

  • Topic Starter
  • Member
  • PipPip
  • 25 posts

I tried skipping but the install was stopped by this screen

 

Kaspersky.png

 

The report said it could not install as viruses were present on the system


  • 0

#29
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
OK I am not seeing any viruses there myself

TDSSKiller cleared the MBR and drivers sectors

Click here and select the blue Run ESET Online Scanner button:
ESET1_zps23a5e840.png

If using Internet Explorer:
  • Accept the Terms of Use and click Start.
  • Allow the running of add-on.
If using Mozilla Firefox or Google Chrome:
  • A link to esetsmartinstaller_enu.exe will be provided. Make sure to download it to the desktop.
  • Double click esetsmartinstaller_enu.exe.
  • Allow the Terms of Use and click Start.
To perform the scan:
  • Make sure that Enable detection of potentially unwanted applications is checked.
  • In the Advanced Settings dropdown menu:
    • Make sure that Remove found threats is unchecked.
    • Scan archives is checked.
    • Scan for potentially unsafe applications and Enable Anti-Stealth technology are checked.
    • Use custom proxy settings is unchecked.
  • Now click on Start.
  • The virus signature database will begin to download. Be patient this make take some time depending on the speed of your Internet Connection.
  • When completed the Online Scan will begin automatically. The scan may take several hours.
  • Do not touch either the Mouse or keyboard during the scan otherwise it may stall.
  • Now click on Finish.
  • Use notepad to open the logfile located at C:\Program Files(x86)\ESET\EsetOnlineScanner\log.txt.
  • Copy and paste that log as a reply to this topic.

  • 0

#30
Confused Dave

Confused Dave

    Member

  • Topic Starter
  • Member
  • PipPip
  • 25 posts

Hi

 

It appears I can't get a connection to download the installer

 

[attachment=78619 ESETarrow-10x10.png.png]

 

Internet connection is fine for Edge

Attached Thumbnails

  • ESET.png

  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP