Every few minutes avast is notifying me that I have several viruses. They are Win32:Malware-gen, Win32:Siref-Aoo, and Win32:Trojan-gen. They are all in the System32\services process and from objects in the ‘installer’ directory.
I have run MBAM several times, each time it finds and reports a successful cleaning of Trojan.Dropper.BCMiner.
Below is the MBAM log. In the next post I will attach the OTL logs.
(I appologize if this is a double post, it didn’t look like it went through last time because of a captcha problem)
Edit: forgot to post the MBAM log - the most recent one was clean.
[*] I will be working on your Malware issues this may or may not solve other issues you have with your machine.
[*] The fixes are specific to your problem and should only be used for this issue on this machine.
[*] If you don’t know or understand something, please don’t hesitate to ask.
[*]Please refrain from making any further changes to your computer (Install/Uninstall programs, delete files, edit the registry, etc…)
[*] Please DO NOT run any other tools or scans whilst I am helping you.
[*] It is important that you reply to this thread. Do not start a new topic.
[*] Your security programs may give warnings for some of the tools I will ask you to use. Be assured, any links I give are safe.
[*] Absence of symptoms does not mean that everything is clear.
[*] Unzip/unrar MBAR in a folder to your Desktop
[*] Open the folder where the contents were unzipped to run mbar.exe
[*] Click on Next > then on Update button to download fresh definitions.
[*] When database updates click Next
[*] In the following window ensure “Targets” scan for Drivers; Sectors; System are ticked. Then select “Scan button”
[*] If an infection/s are found ensure “Create Restore Point” is checked, then select the “Cleanup Button” to remove threats.
Or if you are sure any entries should not be kept, just untick them. A list of infected files will be listed.
[*] The Clean up procedure will be Scheduled for process.
[*] When complete pop-up will show you. Select the Yes button and the system should re-boot to complete the cleaning process.
Please attach the two following logs from the mbar folder:
system-log.txt
and mbar-log-year-month-day (hour-minute-second).txt.
Step#3
Re-run OTL.exe.
[*]Copy and paste the following text written inside of the quote box into the Custom Scans/Fixes box.
CREATERESTOREPOINT
/md5start
services.exe
/md5stop
dir /s /a "C:\Windows\Installer\{777e5fe8-7921-a813-271b-0a6078b396d9}" /c
[*]Then click the RunScan button at the top.
[*]Attach here freh OTL.txt logreport.
Magna, thanks for getting back to me. In between my last post and your suggestions, I ran RogueKiller. It seems to have taken care of the problem. I am no longer getting the messages from avast. Also, an avast scan, the mbam scan, and the aswMBR are all showing up clean. Is there anything I should run or upload to verify that my machine is clean now?
[*]Then click the Run Fix button at the top.
[*]Let the program run unhindered; it will reboot the system when it is done and open notepad with logreport. Attach here that logreport.[/list]
Running OTL Custom Scan
Re-run OTL.exe.
[list][*]Copy and paste the following text written inside of the quote box into the Custom Scans/Fixes box.
CREATERESTOREPOINT
dir /s /a "C:\Windows\Installer\{777e5fe8-7921-a813-271b-0a6078b396d9}" /c
[*]Then click the RunScan button at the top.
[*]Attach here fresh OTL.txt logreport.
[*] Double click MCShield-Setup to install the application.
[*] Wait a few seconds to MCShield finish initial scan.
Recommendation to under General and Scanner tab you click on Defaults button to choose recommended options.
[*] Connect your USB storage devices to the computer one at a time. Scanning will be done automatically.
When all scanning is done, you need to attach a logreport that has made MCShield.
Start → All Programs → MCShield → Logs
Attach here → AllScans.txt
Explanation: USB storage devices are all the USB devices that get their own partition letter at connecting to the PC,
e.g. flash drives (thumb/pen drives, USB sticks), external HDDs, MP3/MP4 players, digital cameras,
memory cards (SD cards, Sony Memory Stick, MultiMedia Cards etc.), some mobile phones, some GPS navigation devices etc.
I’m sorry, I ran combofix before you started working on my case. I didn’t realize how dangerous it was. That said, something I’ve done along the way seems to have deleted the log file. I saw it there last night, but now it is gone. I’m attaching the other files you requested.
Does that mean 0 of the 255 malicious files deleted? I’m also wondering what all the stuff in the ‘c:\restore’ directory is. It looks a little strange with all the directory nesting.
Hi,
Don’t worry, nothing is deleted.
=> Malicious files : 0/255 deleted.
=> Malicious folders : 0/83 deleted.
zero files hase been deleted
Folder hase been created by some software for data recovery.
That folder name and location is often used by malware, and therefore is targeted by name.
Detection hase beed ejected from the base, and MCS database upgraded.
Remove used tools.
Re-run OTL and click on CleanUp! button.
You will be asked to reboot the machine to finish the cleanup process, choose Yes.
After the reboot all the tools we used should be gone. Note: Some more recently created tools may not yet be removed by OTL. Feel free to manually delete any tools it leaves behind.
I recommended to keep Malwarebytes if you will. You may remove Malwarebytes via control panel > programs and features
I recommended to use MCShield if you will. You also may remove MCShield via control panel > programs via features.
MCShield will prevent infection by computer via USB flash drive, mobile phone or any other memory card.
And not only will prevent infection, but it will immediately clean flash drive, memory card or external HDD.