Hello,
During a background scan i was notified from avast about filescout.exe. i decided to do a scan at startup where even though several bprotect files were discovered the only option available was ignore. I used the tools recommended in topic http://forum.avast.com/index.php?topic=53253.0 (Logs to assist in cleaning malware) and have attached the logs. Thank you in advance for your assistance
Looking at your logs right now …
Bprotect is a PUP = not virus / Possible Unwanted Program…usually crapware that comes bundled with free programs
seems Malwarebytes removed it… magna86 will see from OTL log
Please download [b]zoek tool by smeenk (
http://www.mcshield.net/personal/magna86/Images/Zoek_icon.png
) from here or here and save it to your Desktop.
Unpack the archive…
[*]Close any open browsers
[*] Temporarily disable your AntiVirus program. (If necessary)
If you are unsure how to do this please read this or this Instruction.
[*]Double click on zoek.exe to run the tool .
Please wait while the tool does not start…
[*]Copy the text present inside the code box below and paste it into the large window in the zoek tool:
EmptyAllTemp;
IEDefaults;
nmmhkkegccagdldgiimedpiccmgmieda;chr
c:\progra~2\bitguard;fs
C:\Users\TOYRNAS EYΘ\AppData\Roaming\Babylon;fs
EmptyFoldersCheck;Delete
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows];r
"AppInit_DLLs"=-;r
EmptyCLSID;
[-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{79a3d284-8733-11e3-89e1-bcaec5957625}];r
[-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{79a3d284-8733-11e3-89e1-bcaec5957625}];r
[-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{bbbab6e0-da76-11e2-8c41-bcaec5957625}];r
[-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{bbbab6e0-da76-11e2-8c41-bcaec5957625}];r
Uninstall-List;
Reboot;
[*] Click on
http://www.mcshield.net/personal/magna86/Images/Run%20Script%20by%20zoek.png
button.
Please wait until a logreport will open (this can be after reboot)
[*]Save notepad to your Desktop and attach here zoek-results.log
Note: It will also create a log in the C:\ directory named “zoek-results.log”
Just finished with zoek. Anything else I should do?
Yes mandy, we still have some work to do. Re-run zoek as you did before but this time with this script:
cflheckfmhopnialghigdlggahiomebp;chr
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes];r
"{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}"=-;r
AutoClean;
Press RunScript button and wait for zoek to ask for reboot. Then, post me the fresh created zoek logreport.
Then I would like to re-check everything with fresh OTL > QuickScan log. So, re-run OTL, just press QuickScan button and post me fresh OTL.txt logreprot.
ok, this is the new zoek file…
…and the new otl file
Hi,
Press the Windows “logo” key and “R” key (
http://www.mcshield.net/personal/magna86/Images/Windows_Logo_key.gif
- R) then copy/paste the following single-line command into the Run box and click OK:
cmd /c rd /s /q "C:\Users\TOYRNAS EYΘ\AppData\Roaming\Babylon"
A DOS window will open and close again, this is normal.
Tell me, how is the computer behavior now?
As you wrote, the window open and closed and nothing happened. The computer seems fine but I will do another scan just to be safe. Thank you very much for your help and your time!
Feel free to do another scan if you will.
Tell me when you wish to remove used tools here. These tools drops some operational files/folders plus quarantine and we have to remove them at the end.
Note: avast! in his scan may report some of these files or quarantine files itself as malware. That’s normal. Just be aware of that fact.