Avast Found: Win32:Malware-gen, Java:Malware-gen [Trj] & HTML:Agent-LH [Expl]

This is the 3rd system that is infected on a network .

Avast Found: Win32:Malware-gen, Java:Malware-gen [Trj] & HTML:Agent-LH [Expl]

In Avast, I tried to send them to chest, but the server chest was unavailable so I just had Avast delete them.
They were all temp internet files.

MBAM found 3 of the Java infections. I allowed them to be deleted.

Attached are the 4 log files.

Thank you,

Aguaazul

https://sites.google.com/site/cannedfixes/farbar-recovery-scan-tool/FRST.gif
Fix with Farbar Recovery Scan Tool

https://sites.google.com/site/cannedfixes/home/hosted-images-formatting/icon_exclaim.gif
[b] This fix was created for this user for use on that particular machine.
https://sites.google.com/site/cannedfixes/home/hosted-images-formatting/icon_exclaim.gif

https://sites.google.com/site/cannedfixes/home/hosted-images-formatting/icon_exclaim.gif
Running it on another one may cause damage and render the system unstable.
https://sites.google.com/site/cannedfixes/home/hosted-images-formatting/icon_exclaim.gif
[/b]
Download attached fixlist.txt file and save it to the Desktop:

Both files, FRST and fixlist.txt have to be in the same location or the fix will not work!

- Right-click on 

https://sites.google.com/site/cannedfixes/farbar-recovery-scan-tool/FRST.gif
icon and select
https://sites.google.com/site/cannedfixes/home/hosted-images-tools/RunAsAdmin.jpg
Run as Administrator to start the tool.
(XP users click run after receipt of Windows Security Warning - Open File).
- Press the Fix button just once and wait.
- If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
- When finished FRST will generate a log on the Desktop, called Fixlog.txt.
Please attach it to your reply.

How is the system running now? This was mainly cleaning some leftover bits and pieces.

Bomgar is the remote support solution. Your closing of the processes messed up the admin of this system.

I think you should know about: https://www.bomgar.com/ solutions. There is nothing malware in the Bomgar Solution.

I have lost connectivity to this system now. It’s now up to an ‘end user’ to get their system back into a working status.

I’m sorry I trusted this file without looking at it first. I accept full responsibility.

Start
CreateRestorePoint:
CloseProcesses:
HKU\S-1-5-21-73586283-1614895754-725345543-1029.…\Run: [Bomgar_Cleanup_AF312506198515] => cmd.exe /C del /Q “C:\Users\jjuri\AppData\Local\Z@!-296f8c67-f9d3-4fe4-a125-e2d47c87d0a6.tmp” & reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v Bomgar_Cleanup_AF312506198515 /f
HKU\S-1-5-21-73586283-1614895754-725345543-1029.…\Run: [Bomgar_Cleanup_ZD3125108714337] => cmd.exe /C rd /S /Q “C:\ProgramData\bomgar-scc-57843321” & reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v Bomgar_Cleanup_ZD3125108714337 /f
HKU\S-1-5-21-73586283-1614895754-725345543-1029.…\Run: [Bomgar_Cleanup_AF31339914638] => cmd.exe /C del /Q “C:\Users\jjuri\AppData\Local\Z@!-6d1a4b73-d68b-432f-95a5-378cfd83f672.tmp” & reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v Bomgar_Cleanup_AF31339914638 /f
HKU\S-1-5-21-73586283-1614895754-725345543-1029.…\Run: [Bomgar_Cleanup_ZD3134021029609] => cmd.exe /C rd /S /Q “C:\ProgramData\bomgar-scc-578433C2” & reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v Bomgar_Cleanup_ZD3134021029609 /f

I did research Bomgar before making the Fixlist script but did not see those files on the log as current files.

Depending on what actions have been taken on the system in question, there is a Restore Point made before any FRST actions were made (first step in all my scripts) so you should be able to restore the system to that state and have Remote Admin functionality restored.