Author Topic: PUP.bProtector  (Read 13221 times)

0 Members and 1 Guest are viewing this topic.

argus

  • Guest
Re: PUP.bProtector
« Reply #30 on: August 27, 2013, 11:59:54 PM »
Ok, but I'm not on the forum tomorrow, but you certainly do this.
I'll see when I'm online.

MattiieG

  • Guest
Re: PUP.bProtector
« Reply #31 on: August 28, 2013, 12:04:27 AM »
I do not know if you will know what this is, but on my TaskManager, it shows a svchost with 233 k
in it there is
AudioEndpointBuilder
HomegroupListener
PcaSvc
SysMain
TrkWks
UxSms
Wlansvc
and wudfsvc

Do you know why this is taking up so much memory?

argus

  • Guest
Re: PUP.bProtector
« Reply #32 on: August 28, 2013, 12:08:54 AM »
These are services within Svchost containers, are all legitimate.

MattiieG

  • Guest
Re: PUP.bProtector
« Reply #33 on: August 28, 2013, 12:10:28 AM »
okok, I ended it, then all of a sudden it came back, what's going on? do you know?

argus

  • Guest
Re: PUP.bProtector
« Reply #34 on: August 28, 2013, 12:12:21 AM »
Quote
I ended it, then all of a sudden it came back

I do not understand what, Combofix?

MattiieG

  • Guest
Re: PUP.bProtector
« Reply #35 on: August 28, 2013, 12:18:52 AM »
there are also p2p programs running on my laptop, are these regular? (p2pimsvc, p2psvc)
and, the avast! icons have gone missing from my system tray thing - the big where the internet strength and sound is.
how can I get the icons back?
and I meant svchost

MattiieG

  • Guest
Re: PUP.bProtector
« Reply #36 on: August 28, 2013, 12:19:31 AM »
and, therefore, due to there being no avast! icons, I cannot use combofix

argus

  • Guest
Re: PUP.bProtector
« Reply #37 on: August 28, 2013, 12:21:31 AM »
Reboot the machine and it will be fine.

MattiieG

  • Guest
Re: PUP.bProtector
« Reply #38 on: August 28, 2013, 12:22:04 AM »
ahh, ty :)

argus

  • Guest
Re: PUP.bProtector
« Reply #39 on: August 28, 2013, 12:25:21 AM »
Don't panic  ;D

MattiieG

  • Guest
Re: PUP.bProtector
« Reply #40 on: August 28, 2013, 12:55:52 AM »
ok, here it is...
alas, the svchost thing has gone back up to 180,000 k

MattiieG

  • Guest
Re: PUP.bProtector
« Reply #41 on: August 28, 2013, 01:01:20 AM »
* it seems that it goes up after using ComboFixer

argus

  • Guest
Re: PUP.bProtector
« Reply #42 on: August 28, 2013, 01:08:46 AM »
Open notepad and copy/paste the text present inside the code box below:


Code: [Select]

Driver::
ccSet_NST

File::
c:\windows\SYSNATIVE\drivers\NSTx64\7DD02010.005\ccSetx64.sys
c:\windows\system32\drivers\25337890.sys

Folder::
C:\TDSSKiller_Quarantine

Save this as CFScript.txt



Close all browser windows and refering to the picture above.

Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
ComboFix will will re-run. When finished, it will produce a log for you.
Attach the contents of the log in your next reply. (typical location: C:\ComboFix.txt )

MattiieG

  • Guest
Re: PUP.bProtector
« Reply #43 on: August 28, 2013, 01:36:21 AM »
done

argus

  • Guest
Re: PUP.bProtector
« Reply #44 on: August 28, 2013, 09:22:02 AM »
I see no present or active malware.



It is necessary to uninstall ComboFix :
  • Click Start (or ) then Run.


    On Windows7 or Vista you may use Start Search field if Run is not available.

  • In the line of text type in (Copy) the following:
Code: [Select]
ComboFix /Uninstall
    Note that there is a space between " ComboFix " and " /Uninstall " .

    • then click OK (or press Enter ).
    Wait for the uninstall process is complete.


    Next >

    Please download DelFix by "Xplode" to your Desktop.

    Run the tool and check the following boxes below;
    • Remove disinfection tools
    • Create registry backup
    • Purge System Restore

    Now click on "Run" button. Wait for the programme completes his work.
    All the tools we used should be gone.
    Tool will create and open an log report (DelFix.txt)
    Note: The report will also be stored on C:\DelFix.txt


    > I don't need DelFix log report.



    How is your computer behaving now ?