Avast WEBforum

Other => Viruses and worms => Topic started by: gallegoj on September 29, 2013, 02:42:25 PM

Title: wuaudit.exe virus
Post by: gallegoj on September 29, 2013, 02:42:25 PM
Hello everyone, I need some help to remove a trojan that is detected with avast. It is detected as wuaudit.exe virus. I run all the software described in http://forum.avast.com/index.php?topic=53253.0 but it is still there.

I do not know what else  to do and I loosing my patience with this Trojan.
Please, can someone help me?

Here are the LOGs

Thanks
Title: Re: wuaudit.exe virus
Post by: Eddy on September 29, 2013, 02:47:00 PM
Run a bootscan with avast and run Malwarebytes. That should take care of the problem.

And please search this webboard before posting.
http://forum.avast.com/index.php?topic=130078.0 (http://forum.avast.com/index.php?topic=130078.0)
Title: Re: wuaudit.exe virus
Post by: magna86 on September 29, 2013, 02:54:51 PM
@gallegoj

I will look at your logs.

This fix shall fix your problem:
Re-run OTL.exe.

Code: [Select]
:FILES
ipconfig /flushdns /c
C:\Users\Jonathan\AppData\Local\Temp\tsiVi032.dll
C:\Users\Jonathan\AppData\Local\Temp\iswizard
C:\Users\Jonathan\AppData\Local\Google\Chrome\User Data\Default\Extensions\agoenciogemlojlhccbcpcfflicgnaak
C:\Users\Jonathan\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf
C:\Users\Jonathan\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo
C:\Users\Jonathan\AppData\Local\Google\Chrome\User Data\Default\Extensions\chmimgmjdabgiilljdjfbonifbhiglao
C:\Users\Jonathan\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf
C:\Users\Jonathan\AppData\Local\Google\Chrome\User Data\Default\Extensions\eimhlfnbjllicocigjdalpodkokffbmm
C:\Users\Jonathan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejjicmeblgpmajnghnpcppodonldlgfn
C:\Users\Jonathan\AppData\Local\Google\Chrome\User Data\Default\Extensions\enadeelnincmhhilgbiphjbjnnagnhmh
C:\Users\Jonathan\AppData\Local\Google\Chrome\User Data\Default\Extensions\fbpifhknilaflibiifjhhofddbbchmhh
C:\Users\Jonathan\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho
C:\Users\Jonathan\AppData\Local\Google\Chrome\User Data\Default\Extensions\flogpfmjdekjoilcnmmchanikomlidie
C:\Users\Jonathan\AppData\Local\Google\Chrome\User Data\Default\Extensions\gdbabpaggdgcakhjllleobffeghmhjme
C:\Users\Jonathan\AppData\Local\Google\Chrome\User Data\Default\Extensions\gdbabpaggdgcakhjllleobffeghmhjme
C:\Users\Jonathan\AppData\Local\Google\Chrome\User Data\Default\Extensions\gdkjifoifglkpcdffkenpinlbjgephlo
C:\Users\Jonathan\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom
C:\Users\Jonathan\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmbgaklkmjakoegficnlkhebmhkjfich
C:\Users\Jonathan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ijecamokjmiajijbajfnlbkfknpplkdf
C:\Users\Jonathan\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfdckejfnkaemompfjhecfmhjgnchmjg
C:\Users\Jonathan\AppData\Local\Google\Chrome\User Data\Default\Extensions\lgdfnbpkmkkdhgidgcpdkgpdlfjcgnnh
C:\Users\Jonathan\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl
C:\Users\Jonathan\AppData\Local\Google\Chrome\User Data\Default\Extensions\loamdenijebhollnjgehcfbnpeelfhlk
C:\Users\Jonathan\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjocghlclkpgheifflemilcnblodjohg
C:\Users\Jonathan\AppData\Local\Google\Chrome\User Data\Default\Extensions\okboeogmnhjpgbeaokfogelclpblaemo
C:\Users\Jonathan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ooagbcohbmlpkfkdnodbomgphbcecalj
C:\Users\Jonathan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ooagbcohbmlpkfkdnodbomgphbcecalj
C:\Users\Jonathan\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia

:OTL
O3:[b]64bit:[/b] - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4 - HKU\S-1-5-21-1365072474-943141896-2643588273-1000..\Run: [tsiVideo] C:\Users\Jonathan\AppData\Local\Temp\tsiVi032.dll ()

:COMMANDS
[CREATERESTOREPOINT]
[EMPTYTEMP]
If the log doesn't appear, it can be found here:

c:\_OTL\MovedFiles\mmddyyyy_hhmmss.log


---- Next -----


aswMBR shows traces of posible TDL rootkit. We shall re-check that.




Download TDSSKiller (http://media.kaspersky.com/utilities/VirusUtilities/EN/tdsskiller.exe)  and save it to your desktop

    Execute TDSSKiller.exe by doubleclicking on it, accept all pop-up on start.

Once complete, a log will be produced at the root drive which is typically C:\ ,for example, C:\TDSSKiller.<version_date_time>log.txt


Please post the contents of that log in your next reply.
Title: Re: wuaudit.exe virus
Post by: gallegoj on September 30, 2013, 01:28:12 AM
@Eddy: Thanks for your advice. I run a bootscan with avast and run Malwarebytes but the threat was still there. I read the other posts before creating this one and they always suggest to start a new post. that is why I opened a new post

@magna86: I run OTL with the  script you gave me and also I run the TDSSkiller. the TDSSkiller didn't find anything.
I am sending the two logs. It seems the problem is solved until now.

should I check something more? should I delete any of the software I've installed?

Thanks,

gallegoj
Title: Re: wuaudit.exe virus
Post by: Pondus on September 30, 2013, 02:38:18 AM
Quote
should I check something more? should I delete any of the software I've installed?
magna86 is in bed now, check back tomorrow   ;)

Title: Re: wuaudit.exe virus
Post by: magna86 on September 30, 2013, 12:02:37 PM

@magna86: I run OTL with the  script you gave me and also I run the TDSSkiller. the TDSSkiller didn't find anything.
I am sending the two logs. It seems the problem is solved until now.

should I check something more? should I delete any of the software I've installed?


I shall need both OTL and TDSSK logs. Please post them here.
Title: Re: wuaudit.exe virus
Post by: gallegoj on September 30, 2013, 03:02:48 PM
Hi,

I forgot to attach the logs in the last reply, sorry for that.
Title: Re: wuaudit.exe virus
Post by: magna86 on September 30, 2013, 03:59:06 PM
Let's check with TDSSKiller a little deeper.




Note:It will also create a log in the C:\ directory.


==========================


How's youir computer running now?
Title: Re: wuaudit.exe virus
Post by: gallegoj on October 01, 2013, 04:00:10 AM
Hi Magna,

Sorry for answering late, but it is difficult for me to get access to my laptop during working time.
I run the TDSSkiller again with the parameters that you suggested. It didn't detect any threat. I am attaching the LOG.
Title: Re: wuaudit.exe virus
Post by: magna86 on October 01, 2013, 10:58:44 AM
That's it.  :)

> Re-run OTL and click on CleanUp! button.

You will be asked to reboot the machine to finish the cleanup process, choose Yes.
After the reboot all the tools we used should be gone.
Note: Some more recently created tools may not yet be removed by OTL. Feel free to manually delete any tools it leaves behind.




I recommended to use MCShield if you will.
You may download MCShield from one of the following links:

MyCity -  Official download link (http://www.mcshield.net)
Softpedija - Mirror download link (http://www.softpedia.com/get/Antivirus/MCShield.shtml)

It will prevent infection by computer via USB flash drive, mobile phone or any other memory card.
And not only will prevent infection, but it will immediately clean flash drive, memory card or external HDD.