Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Laptop infected with Win32.LocalInfect.2 [Solved]


  • This topic is locked This topic is locked

#31
brh0303

brh0303

    Member

  • Topic Starter
  • Member
  • PipPip
  • 33 posts

I have a BRILLIANT idea! I should just throw this laptop out and buy a new one! :smashcomp: :spoton:


  • 0

Advertisements


#32
pystryker

pystryker

    Trusted Helper

  • Malware Removal
  • 3,912 posts

I have a BRILLIANT idea! I should just throw this laptop out and buy a new one!

Hi :)

:lol: Hang in there, we'll get it. :)

Please run FRST again using this fixlist.

Start
RestoreQuarantine: C:\FRST\Quarantine\C\Users\Bonita\cnmss Canon MX410 series Printer WS (Local).dll
End

Once the fix has run, please reboot the machine. Please post the fixlog.txt log and let me know if the error happens. :thumbsup:
  • 0

#33
brh0303

brh0303

    Member

  • Topic Starter
  • Member
  • PipPip
  • 33 posts

The error did not coe up when I rebooted.  Here is the new fixlog:

 

Fix result of Farbar Recovery Scan Tool (x64) Version:28-06-2015 01
Ran by Bonita at 2015-07-09 12:56:34 Run:9
Running from C:\Users\Bonita\Desktop
Loaded Profiles: Bonita (Available Profiles: Bonita)
Boot Mode: Normal
==============================================

fixlist content:
*****************
Start
RestoreQuarantine: C:\FRST\Quarantine\C\Users\Bonita\cnmss Canon MX410 series Printer WS (Local).dll
End
*****************

"C:\FRST\Quarantine\C\Users\Bonita\cnmss Canon MX410 series Printer WS (Local).dll"=> path not found.

==== End of Fixlog 12:56:34 ====


  • 0

#34
pystryker

pystryker

    Trusted Helper

  • Malware Removal
  • 3,912 posts
Hmm..I have a feeling it will come back. That fixlog is not showing me what I want to see just yet. Let me verify that I have the right folder.

Please run FRST using the fixlist below. No need to reboot after running it, just post the log. :thumbsup:
 

Start
Folder: C:\FRST\Quarantine
End


  • 0

#35
brh0303

brh0303

    Member

  • Topic Starter
  • Member
  • PipPip
  • 33 posts

Fix result of Farbar Recovery Scan Tool (x64) Version:28-06-2015 01
Ran by Bonita at 2015-07-09 17:34:12 Run:10
Running from C:\Users\Bonita\Desktop
Loaded Profiles: Bonita (Available Profiles: Bonita)
Boot Mode: Normal
==============================================

fixlist content:
*****************
Start
Folder: C:\FRST\Quarantine
End
*****************


========================= Folder: C:\FRST\Quarantine ========================

2015-07-04 11:12 - 2015-07-04 11:12 - 0000000 ____D () C:\FRST\Quarantine\C
2015-07-04 11:12 - 2015-07-04 11:12 - 0000000 ____D () C:\FRST\Quarantine\C\ProgramData
2015-05-31 14:31 - 2015-05-31 14:31 - 0006958 _____ () C:\FRST\Quarantine\C\ProgramData\SMRResults430.dat.xBAD
2015-07-04 11:12 - 2015-07-04 11:12 - 0000000 ____D () C:\FRST\Quarantine\C\Users
2015-07-04 11:12 - 2015-07-04 11:12 - 0000000 ____D () C:\FRST\Quarantine\C\Users\Bonita
2015-01-11 21:34 - 2010-09-20 05:00 - 0104960 _____ (CANON INC.) C:\FRST\Quarantine\C\Users\Bonita\cnmss Canon MX410 series Printer WS (Local).dll.xBAD
2015-07-04 11:12 - 2015-07-04 11:12 - 0000000 ____D () C:\FRST\Quarantine\C\Windows
2015-07-04 11:12 - 2015-07-04 11:12 - 0000000 ____D () C:\FRST\Quarantine\C\Windows\System32
2015-07-04 11:12 - 2015-07-04 11:12 - 0000000 ____D () C:\FRST\Quarantine\C\Windows\System32\Drivers
2015-07-04 11:12 - 2015-07-04 11:12 - 0000000 ____D () C:\FRST\Quarantine\C\Windows\System32\Drivers\etc
2013-08-22 06:25 - 2013-08-22 06:25 - 0000824 _____ () C:\FRST\Quarantine\C\Windows\System32\Drivers\etc\hosts.xBAD

====== End of Folder: ======


==== End of Fixlog 17:34:12 ====


  • 0

#36
pystryker

pystryker

    Trusted Helper

  • Malware Removal
  • 3,912 posts
There's the one I was looking for. :thumbsup:

Please run the fix below and post the fixlog. No reboot needed.
 

Start
RestoreQuarantine: C:\FRST\Quarantine\C\Users\Bonita\cnmss Canon MX410 series Printer WS (Local).dll.xBAD
End


  • 0

#37
brh0303

brh0303

    Member

  • Topic Starter
  • Member
  • PipPip
  • 33 posts

Fix result of Farbar Recovery Scan Tool (x64) Version:28-06-2015 01
Ran by Bonita at 2015-07-09 17:39:24 Run:11
Running from C:\Users\Bonita\Desktop
Loaded Profiles: Bonita (Available Profiles: Bonita)
Boot Mode: Normal
==============================================

fixlist content:
*****************
Start
RestoreQuarantine: C:\FRST\Quarantine\C\Users\Bonita\cnmss Canon MX410 series Printer WS (Local).dll.xBAD
End
*****************

RestoreQuarantine: C:\FRST\Quarantine\C\Users\Bonita\cnmss Canon MX410 series Printer WS (Local).dll.xBAD=> Restoring from Quarantine completed.

==== End of Fixlog 17:39:24 ====


  • 0

#38
pystryker

pystryker

    Trusted Helper

  • Malware Removal
  • 3,912 posts
Ok, that looks good. :) That should eliminate the error. Let me get a fresh look with FRST to make sure everything looks good, and then we'll have some cleanup procedures to go through. :thumbsup:

Start FRST and check the Addition.txt box.

Press the Scan button. FRST will scan your machine and produce 2 logs. Please post them in your next reply.
  • 0

#39
brh0303

brh0303

    Member

  • Topic Starter
  • Member
  • PipPip
  • 33 posts

I attached the two logs

Attached Files


  • 0

#40
pystryker

pystryker

    Trusted Helper

  • Malware Removal
  • 3,912 posts
Hi :)

The addition log looks great, however, you attached a copy of the fixlog instead of the new FRST.txt log.
  • 0

Advertisements


#41
brh0303

brh0303

    Member

  • Topic Starter
  • Member
  • PipPip
  • 33 posts

oops sorry

Attached Files

  • Attached File  FRST.txt   44.43KB   219 downloads

  • 0

#42
pystryker

pystryker

    Trusted Helper

  • Malware Removal
  • 3,912 posts
No worries. :)

Excellent, nothing showing in the log. :)

Let's create a clean restore point, and remove my tools. I also have some information on how to stay safe while surfing. :thumbsup:


Step 1: Tool Removal with Delfix and Creation of a clean restore point
  • Download Delfix from here
  • Ensure Remove disinfection tools is ticked
    Also tick:
    • Create registry backup
    • Purge system restore
    • Reset System Settings
    delfix.jpg
  • Click Run
The program will run for a few moments and then notepad will open with a log. Please paste the log in your next reply.
  • You can uninstall ESET Online Scanner at this time.
  • I recommend keeping Malwarebytes Anti-Malware installed. Make sure to update it and run it at least once a week. If it finds things such as PUP's (Potentially Unwanted Programs) you can delete those with no worries. However, if it finds something like a trojan, come see us.
Step 2: Tips, Information, and Optional Installation of Unchecky
  • Watch what you open in your emails. If you get an email from an unknown source with any attached files, do not open it.
  • Install and keep only one anti-virus on your machine. Update it and scan your machine with it at least once a week.
  • Be careful of the websites you visit.
  • When installing new programs, don't be "click happy" and click through the screens. Many programs come with adware in them and are set to install them by default. Several programs require that you uncheck or select no to prevent the installation. Take your time and read each screen as you go. :)
To help protect yourself while on the web, I recommend you read How did I get infected in the first place?


Installation of Unchecky

This is a very good little program that will automatically uncheck any boxes during a software installation. This helps prevent the software from installing any malware that is by default checked while the program is being installed.
  • Click here to be taken to Unchecky.com
  • Click the very large Download button.
  • Click Save
  • Once downloaded, double click the program (Vista, Win 7, and 8, right click and Run as Administrator)
  • Once open, click the Install button.
unchecky1_zps667e512d.jpg


Then click Finish

unchecky2_zpsca4e7d0d.jpg


Unchecky is now installed and will help you keep unwanted check boxes unchecked. :thumbsup:


Step 3: Protection Against CryptoLocker


CryptoLocker is a ransomware program that was released around the beginning of September 2013 that targets all versions of Windows including Windows XP, Windows Vista, Windows 7, and Windows 8. This ransomware will encrypt certain files using a mixture of RSA & AES encryption. When it has finished encrypting your files, it will display a CryptoLocker payment program that prompts you to send a ransom of either $100 or $300 in order to decrypt the files. This screen will also display a timer stating that you have 72 hours, or 4 days, to pay the ransom or it will delete your encryption key and you will not have any way to decrypt your files. This ransom must be paid using MoneyPak vouchers or Bitcoins. Once you send the payment and it is verified, the program will decrypt the files that it encrypted.

Please download and install CryptoPrevent to lock your machine down from this infection.

CryptoPrevent_zps1a3866db.jpg


Things I need to see in your next post

Delfix Log

  • 0

#43
brh0303

brh0303

    Member

  • Topic Starter
  • Member
  • PipPip
  • 33 posts

Which antivirus programshould I use? I thought this laptop already had one in place when I bought it.

 

here is the log:

 

# DelFix v10.8 - Logfile created 09/07/2015 at 18:57:11
# Updated 29/07/2014 by Xplode
# Username : Bonita - BONITAZ
# Operating System : Windows 8 Pro  (64 bits)

~ Removing disinfection tools ...

Deleted : C:\FRST
Deleted : C:\AdwCleaner
Deleted : C:\TDSSKiller.3.0.0.44_05.07.2015_14.01.49_log.txt
Deleted : C:\Users\Bonita\Desktop\Addition.txt
Deleted : C:\Users\Bonita\Desktop\AdwCleaner.exe
Deleted : C:\Users\Bonita\Desktop\Fixlog.txt
Deleted : C:\Users\Bonita\Desktop\FRST.txt
Deleted : C:\Users\Bonita\Desktop\FRST64.exe
Deleted : C:\Users\Bonita\Desktop\JRT.exe
Deleted : C:\Users\Bonita\Desktop\SecurityCheck - Shortcut.lnk
Deleted : C:\Users\Bonita\Desktop\SecurityCheck Log.txt
Deleted : C:\Users\Bonita\Desktop\TDSSKiller.3.0.0.44_05.07.2015_14.01.49_log.txt
Deleted : C:\Users\Bonita\Desktop\tdsskiller.exe
Deleted : C:\Users\Bonita\Downloads\Addition.txt
Deleted : C:\Users\Bonita\Downloads\FRST.txt
Deleted : C:\Users\Bonita\Downloads\FRST64.exe
Deleted : C:\Users\Bonita\Downloads\SecurityCheck.exe
Deleted : HKLM\SOFTWARE\AdwCleaner

~ Creating registry backup ... OK

~ Cleaning system restore ...

Deleted : RP #46 [Scheduled Checkpoint | 06/21/2015 18:29:22]
Deleted : RP #47 [Windows Update | 06/25/2015 20:40:26]
Deleted : RP #48 [Scheduled Checkpoint | 07/02/2015 21:00:13]
Deleted : RP #50 [Restore Point Created by FRST | 07/04/2015 18:11:32]
Deleted : RP #51 [Windows Update | 07/09/2015 19:10:41]

New restore point created !

~ Resetting system settings ... OK

########## - EOF - ##########
 


  • 0

#44
brh0303

brh0303

    Member

  • Topic Starter
  • Member
  • PipPip
  • 33 posts

ok.....i did everythingyou listed


  • 0

#45
pystryker

pystryker

    Trusted Helper

  • Malware Removal
  • 3,912 posts

Which antivirus programshould I use? I thought this laptop already had one in place when I bought it.


It does have an anti-virus already installed, Webroot SecureAnywhere is installed on the machine and it's up to date. I would run a scan with it in conjunction with Malwarebytes at least once a week. This one looks like it's a paid subscription that came with the laptop, so I'd keep that until the subscription runs out. :thumbsup:
  • 0






Similar Topics

1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP