Hello.
I am currently having virus problems with both my and my girlfriend’s laptops. This one I’d gladly attack first.
I ran the Malwarebyte, OTL and che aswMBR and the logs are attached. I’d appreciate the help with these problems. Thank you.
Hello.
I am currently having virus problems with both my and my girlfriend’s laptops. This one I’d gladly attack first.
I ran the Malwarebyte, OTL and che aswMBR and the logs are attached. I’d appreciate the help with these problems. Thank you.
Please attach the logs made by Malwarebytes and aswMBR.
Here you go. Didn’t notice that you could only upload one file at a time
Hi,
WARNINGUnfortunately one or more of the infections I have identified are Backdoor Trojans, IRCBots or other Malware capable of stealing very important information. You need to stop using all Internet Banking sites, change passwords to all sites with sensitive information from a clean computer and phone your bank to inform them that you may be a victim of identify theft. More often than not, we advise users that a full reinstallation of their Operating System is the only way to ensure that their computer will ever be 100% clean again.
Unfortunately I have found what is known as the ZeroAccess rootkit on your system. It is an especially nasty infection that can take quite some time to clean as well as may have damaged your system files itself. As a warning, during the cleaning (if you choose to do so) you may lose internet access with this computer and in the end we may need to reinstall the operating system anyway depending on the extent of the infection.
If you would like to format and reinstall your Operating System please let me know and we can assist you with that.
Run OTL.exe
[*]Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL
:Services
:Files
C:\Windows\Installer\{c60d1430-734f-fd1d-2598-d70c97516b7c}\
C:\Users\Karolina\AppData\Local\{c60d1430-734f-fd1d-2598-d70c97516b7c}\
:Commands
[purity]
[emptytemp]
[start explorer]
[Reboot]
[*]Then click the Run Fix button at the top
[*]Let the program run unhindered, reboot when it is done
[*]Then run a new scan and post a new OTL log ( don’t check the boxes beside LOP Check or Purity this time )
Download Combofix from either of the links below, and save it to your desktop.
Link 1
Link 2
Note: It is important that it is saved directly to your desktop
If you get a message saying “Illegal operation attempted on a registry key that has been marked for deletion”, please restart your computer.
IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
Right-Click and Run as Administrator on ComboFix.exe & follow the prompts.
When finished, it will produce a report for you.
[*]Please post the C:\ComboFix.txt for further review.
Hi. You’ll find the OTL log attached.
I downloaded ComboFix, shut down Avast and ran it. ComboFix is prompting me to shut down McAfee Anti-Virus and Anti-Spyware.
McAfee was installed on this computer until a few days ago until I uninstalled it via the windows tool. CCleaner can’t find it and I couldn’t recognize it in running processes either. Is it ok to run ComboFix nevertheless?
Yes go ahead to run ComboFix.
ComboFix log attached.
Hi,
I see you are working with Essexboy in another topic. Is it the same system we are working on or different? I will return with the next set of instructions as quickly as I can.
Hello. It’s a different system. We had the bad luck of having infections on both my and my gf’s laptops. My laptop got sorted out, but my gf’s laptop is the one you have been looking at.
Ok great!
Hello. I don’t want to rush you, but have you had time to look at the last logs already?
Thank you very much for your help.
Sorry for any delay…Work was busy yesterday and then we lost power due to a storm last night…
[*]Please open Notepad (Start → Run → type notepad in the Open field → OK) and copy and paste the text present inside the code box below:
ClearJavaCache::
RegLockDel::
[HKEY_USERS\S-1-5-21-3336650310-555936897-1426173112-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*h*'Ñ4]
[HKEY_USERS\S-1-5-21-3336650310-555936897-1426173112-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*h*'Ñ4\OpenWithList]
[*]Save this as CFScript.txt and change the “Save as type” to “All Files” and place it on your desktop.
http://img.photobucket.com/albums/v706/ried7/CFScriptB-4.gif
[*]Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause “unpredictable results”.
[*]Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
[*]ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
[*]When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
Hi. Didn’t want to rush you in any way, just thought to check that it wasn’t forgotten.
I ran ComboFix and the log’s too large to copy and paste. Find it attached as ComboFix2.txt
Hi,
Malwarebytes
Please run a free online scan with the ESET Online Scanner
[i]Note: You will need to use Internet Explorer for this scan[/i]
[*]Tick the box next to YES, I accept the Terms of Use
[*]Click Start
[*]When asked, allow the ActiveX control to install
[*]Click Start
[*]Make sure that the options Remove found threats is NOT selected and the option Scan unwanted applications is selected.
[*]Click Scan (This scan can take several hours, so please be patient)
[*]If there are threats that are found, please press List of found threats and then in the next window that opens press Export to text file…
[*]Copy and paste/or attach that log as a reply to this topic
The logs are attached. It’s still fighting us
Sorry for any delays…I has some technical difficulties on my end that I just got fixed.
Those entries that are listed are already quarantined so they are ok. How is your system running?
Hello. It seems that the only things found anymore are quarantined or OTL moved threats. Erunt is prompting error messages, but otherwise the system seems to run alright. I’ll use the laptop and see if anything pops up.
Thanks for the help and let’s hope it keeps healthy!