Threat Blocked: wolfhack.no-ip.biz/skype from wscript.exe

So my hard drive died last week and I just got my computer back today. I tried to download NookStudy, which you can’t get from BN anymore and I assume that’s where I got this bug, whatever it was. Computer was working find yesterday after I started putting programs back on it. This morning I tried to put the nook program and the threat detected thing popped up shortly thereafter, I think.

The object blocked is listed as wolfhack.no-ip.biz/skype (I don’t have Skype on my computer, so I assume this is just the name they chose to use). And the process is listed as windows\system32\wscript.exe.

I ran the scans with Avast, Malwarebytes and Spybot and Spybot was the only thing that detected any issues, though none appeared to pertain to this issue. I did a system restore, which didn’t work at first, I had to go back a bit later and that worked, but I’m still getting this constant pop-up that a threat was blocked.

I should mention that I’ve also been having a hell of a time trying to install .Net Framework 4. I had to have it for a program to get my music back from my ipod (now removed with the system restore) onto my computer, and no matter how many times I try or how long I wait, it seems to make no progress on installing. I don’t plan on using that program anymore, so that isn’t an issue anymore, but I figured it might be related.

Can someone help, please?

Attach your basic diagnostic logs. (MBAM, FRST and aswMBR)
Instructions: https://forum.avast.com/index.php?topic=53253

Sorry, had to run to the store. Here’s MBAM. I don’t have the other two programs, do you have to have those logs as well?

Malwarebytes Anti-Malware
www.malwarebytes.org

Scan Date: 8/6/2016
Scan Time: 9:36 AM
Logfile: MBAM.txt
Administrator: Yes

Version: 2.2.1.1043
Malware Database: v2016.08.06.08
Rootkit Database: v2016.05.27.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled

OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Ashley

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 289010
Time Elapsed: 11 min, 40 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 0
(No malicious items detected)

Registry Values: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Folders: 0
(No malicious items detected)

Files: 0
(No malicious items detected)

Physical Sectors: 0
(No malicious items detected)

(end)

Reread the instructions, it’s all explained there.

https://www.virustotal.com/en/domain/wolfhack.no-ip.biz/information/

I understood the instructions, I just wanted to make sure they were all necessary. I don’t like loading my computer up with a ton of programs and I know nothing about those.

OK, now you’ve to wait a bit…

No problem.

Understand about “loading the system with programs” but we do try and remove the tools used to clean your system (when we are finished).

Open notepad by pressing the Windows Key + R Key, typing in Notepad in the Run dialog and then pressing Enter. Please copy the contents of the Code box below. To do this highlight the contents of the box by clicking [Select] next to Code: , then right click on any of the highlighted text and select copy. Paste this into the open notepad. Save it to your desktop as fixlist.txt


Start
CreateRestorePoint:
CloseProcesses:
Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X]
Startup: C:\Users\Ashley\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\winscript.wsh [2016-08-04] ()
C:\Users\Ashley\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\winscript.wsh
2016-08-06 10:45 - 2016-08-06 10:45 - 00369459 _____ C:\unp30535665731195696.mdmp
2016-08-06 10:45 - 2016-08-06 10:45 - 00369175 _____ C:\unp30535665737747707.mdmp
2016-08-06 10:45 - 2016-08-06 10:45 - 00367998 _____ C:\unp30535665734939702.mdmp
2016-08-06 10:45 - 2016-08-06 10:45 - 00367837 _____ C:\unp30535665736499705.mdmp
2016-08-06 10:45 - 2016-08-06 10:45 - 00367648 _____ C:\unp30535665728855692.mdmp
2016-08-06 10:45 - 2016-08-06 10:45 - 00366991 _____ C:\unp30535665730415694.mdmp
2016-08-06 10:45 - 2016-08-06 10:45 - 00366339 _____ C:\unp30535665733223699.mdmp
2016-08-06 10:45 - 2016-08-06 10:45 - 00365896 _____ C:\unp30535665729635693.mdmp
2016-08-06 10:45 - 2016-08-06 10:45 - 00365845 _____ C:\unp30535665738527709.mdmp
2016-08-06 10:45 - 2016-08-06 10:45 - 00365668 _____ C:\unp30535665735719704.mdmp
2016-08-06 10:45 - 2016-08-06 10:45 - 00365386 _____ C:\unp30535665917616023.mdmp
2016-08-06 10:45 - 2016-08-06 10:45 - 00365348 _____ C:\unp30535665734003701.mdmp
2016-08-06 10:45 - 2016-08-06 10:45 - 00364344 _____ C:\unp30535665732443698.mdmp
2016-08-06 10:45 - 2016-08-06 10:45 - 00361504 _____ C:\unp30535665918396025.mdmp
2016-08-06 10:45 - 2016-08-06 10:45 - 00358799 _____ C:\unp30535665723707683.mdmp
2016-08-06 10:45 - 2016-08-06 10:45 - 00357580 _____ C:\unp30535665725267685.mdmp
2016-08-06 10:45 - 2016-08-06 10:45 - 00356783 _____ C:\unp30535665724487684.mdmp
2016-08-06 10:45 - 2016-08-06 10:45 - 00356755 _____ C:\unp30535665726047687.mdmp
2016-08-06 10:45 - 2016-08-06 10:45 - 00356394 _____ C:\unp30535665619187499.mdmp
2016-08-06 10:45 - 2016-08-06 10:45 - 00354692 _____ C:\unp30535665618563498.mdmp
2016-08-06 10:45 - 2016-08-06 10:45 - 00353546 _____ C:\unp30535665570203413.mdmp
2016-08-06 08:11 - 2016-08-06 08:11 - 00000000 ____D C:\d3fd39ee1945ca08b451e78d
2016-08-05 20:14 - 2016-08-05 20:14 - 00000000 ____D C:\c34d4b543cb385bd793b33d6
2016-08-05 19:54 - 2016-08-06 10:39 - 00000000 ____D C:\Program Files (x86)\QuickTime
2016-08-05 17:50 - 2016-08-05 17:50 - 00000000 ____D C:\72927cbc48bab9788dffba
2016-08-05 09:03 - 2016-08-05 09:03 - 00000000 ____D C:\Users\Ashley\AppData\Roaming\AVG
2016-08-05 09:02 - 2016-08-05 09:02 - 00000000 ____D C:\Users\Ashley\AppData\Roaming\TuneUp Software
2016-08-05 07:59 - 2016-08-05 09:29 - 00000000 ____D C:\Users\Ashley\AppData\Local\AvgSetupLog
2016-08-05 07:59 - 2016-08-05 09:29 - 00000000 ____D C:\ProgramData\Avg
2016-08-05 07:59 - 2016-08-05 09:27 - 00000000 ____D C:\Users\Ashley\AppData\Local\Avg
2016-08-05 07:59 - 2016-08-05 07:59 - 03143504 _____ (AVG Technologies CZ, s.r.o.) C:\Users\Ashley\Downloads\AVG_Protection_Free_1606.exe
2016-08-04 16:30 - 2016-08-04 16:53 - 00000000 ____D C:\ProgramData\ProductData
2016-08-04 16:30 - 2016-08-04 16:31 - 00000000 ____D C:\Users\Ashley\AppData\LocalLow\IObit
2016-08-04 16:30 - 2016-08-04 16:30 - 00000000 ____D C:\Windows\IObit
2016-08-04 16:30 - 2016-08-04 16:30 - 00000000 ____D C:\Users\Ashley\AppData\Roaming\IObit
2016-08-04 16:30 - 2016-08-04 16:30 - 00000000 ____D C:\ProgramData\IObit
2016-08-03 18:27 - 2016-08-03 18:27 - 00000000 __SHD C:\Users\Ashley\AppData\Local\EmieUserList
2016-08-03 18:27 - 2016-08-03 18:27 - 00000000 __SHD C:\Users\Ashley\AppData\Local\EmieSiteList
2016-08-03 18:27 - 2016-08-03 18:27 - 00000000 __SHD C:\Users\Ashley\AppData\Local\EmieBrowserModeList
C:\Users\Ashley\AppData\Local\Temp\Uninstall.exe
Hosts:
cmd: ipconfig /flushdns
cmd: netsh advfirewall reset
cmd: netsh advfirewall set allprofiles state on
Reg: reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
Reg: reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
CMD: bitsadmin /reset /allusers
RemoveProxy:
EmptyTemp:
Reboot:
end

NOTE. It’s important that both files, FRST64 and fixlist.txt are in the same location or the fix will not work.

NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

Run FRST64 by right clicking on the FRST64.exe file, selecting “Run as Administrator…”. The User Account Control may open up; if it does, select Yes to continue to let FRST open and load.

The tool will check for an updated version of itself every time it loads; please allow it to do this and the program will either inform you it is downloading an updated copy (and to wait until it is safe to continue) or show nothing (meaning there is no update found) and you can continue on. Press the Fix button just once and wait. The tool will create a restore point, process the script and ask for a restart of your system.

http://i1351.photobucket.com/albums/p785/dbreeze2/just%20stuff/Press%20the%20FIX%20button_zpsdd5zi3mt.png

If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.

When finished FRST will generate a log on the Desktop (Fixlog.txt). Please attach it to your reply post. Also, tell me how your system is running now.

Quick question. I ran FRST from the downloads folder, not the desktop. When I clicked the download it started right up and I clicked run before I realized it wasn’t saved on the desktop. I can move it to the desktop now, or would it be better for me to just save the fixlist file to my downloads folder and run the fix from the same place I ran the scan? Or did I completely screw up and now need to re-run the scan?

Also, Avast appears to have stopped alerting me to the threat blocked for no apparent reason. It is malware, right?

Saved fixlist to the desktop and moved the program there. Ran the fix from the desktop, and attached the log below. Computer appears to be fine. Like I noted above though, I haven’t observed a notification from Avast like I originally posted in at least a couple hours. Maybe since I originally ran the programs.

Let me know if there’s anything else I need to do and thank you very, very much for your help.

Looks like that took care of it (possibly Avast removed what I had on the Fixlist first). Let’s get the tools off your system and you on your way …

Clean up of Malware Removal Tools
Now that we are through using these tools, let’s clean them off your system so that should you ever need to have malware removed again (we hope not) fresh, updated copies will be downloaded.

[]Download Delfix from here to your desktop and double click it to start the program
[*]Ensure Remove disinfection tools is ticked
Also tick:
[
]Activate UAC
[]Create registry backup
[
]Purge system restore
[*]Reset system settings

http://i1351.photobucket.com/albums/p785/dbreeze2/just%20stuff/DelFixSelectall_zps0f04cec4.png

[*]Click Run
[*]The program will run for a few moments and then notepad will open with a log. Note: Please save this log first before rebooting your system (if asked to); DelFix does not save the log as it is trying to remove all traces of our work on your system. Please attach the log in your next reply.

You can delete any log files left on your desktop as these are no longer needed.

Program ran without any problems. Delfix is attached. Thanks!