Avast WEBforum

Other => Viruses and worms => Topic started by: na_wspak on August 10, 2012, 09:19:18 AM

Title: Issue with 800000cb.@ and 80000000.@
Post by: na_wspak on August 10, 2012, 09:19:18 AM
The issue is similar to http://forum.avast.com/index.php?topic=102817.msg823352#msg823352 (http://forum.avast.com/index.php?topic=102817.msg823352#msg823352). I attach an OTL report. I will aprecciate any help. Thanks in advance
Title: Re: Issue with 800000cb.@ and 80000000.@
Post by: magna86 on August 10, 2012, 11:08:23 AM

**********************


Step1


Re-run OTL.exe.

Code: [Select]
:files
C:\Windows\Installer\{f66e7bc2-dab8-71dc-5559-06500ad25542}
C:\Users\rceluch\AppData\Local\{f66e7bc2-dab8-71dc-5559-06500ad25542}

:commands
[CREATERESTOREPOINT]
[purity]
[EMPTYFLASH]
[EMPTYJAVA]
[emptytemp]
[Reboot]
**************************


Step2




> Download ComboFix from here (http://download.bleepingcomputer.com/sUBs/ComboFix.exe) and save it to your Desktop.
If you are unsure how ComboFix works please read this guide (http://www.bleepingcomputer.com/combofix/how-to-use-combofix) carefully.
note: ComboFix must be downloaded to your Desktop.

> Temporarily disable your AntiVirus program.
If you are unsure how to do this please read this Instruction. (http://www.bleepingcomputer.com/forums/topic114351.html)

How to disable avast:

Note: Do not forget to turn on this option after the cleaning.



> Run ComboFix. Click on I Agree!
ComboFix will check if there is a newer version of ComboFix available.
Click Yes if prompted to download.

ComboFix will display DISCLAIMER OF WARRANTY ON SOFTWARE.
Click Yes to allow ComboFix to continue.

If Recovery Console is not installed, ComboFix will offer download & installation.
Click Yes to allow ComboFix to install Recovery Console.
Note:Do not mouse-click Combofix's window while it is running.


> When the tool is finished, it will produce a log report for you. (typical location: C:\ComboFix.txt )
  Attach log reports ( ComboFix.txt) back to topic.
Title: Re: Issue with 800000cb.@ and 80000000.@
Post by: na_wspak on August 10, 2012, 01:43:46 PM
Thanks for your time. I did steps 1 and 2. I attach logs. Let me know if you have any problems with Polish logs.
Title: Re: Issue with 800000cb.@ and 80000000.@
Post by: magna86 on August 10, 2012, 04:21:49 PM
Let me know if you have any problems with Polish logs.

No Problem  ;)

Open notepad and copy/paste the text present inside the code box below:


Code: [Select]
Registry::
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager]
"BootExecute"=hex(7):61,00,75,00,74,00,6f,00,63,00,68,00,65,00,63,00,6b,00,20,\
  00,61,00,75,00,74,00,6f,00,63,00,68,00,6b,00,20,00,2a,00,00,00,00,00
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"Notification Packages"=hex(7):73,00,63,00,65,00,63,00,6c,00,69,00,00,00,00,00

FileLook::
C:\Qoobox\Quarantine\C\ProgramData\PCDr\5907\Downloads\f0fc9c9c-10ba-435b-8365-dadb523644ff.dll.vir



Save this as CFScript.txt

(http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif)

Close all browser windows and refering to the picture above.

Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
ComboFix will will re-run. When finished, it will produce a log for you.
Attach the contents of the log in your next reply. (typical location: C:\ComboFix.txt )
Title: Re: Issue with 800000cb.@ and 80000000.@
Post by: na_wspak on August 13, 2012, 08:50:55 AM
Here you can find the script attached.
Title: Re: Issue with 800000cb.@ and 80000000.@
Post by: magna86 on August 13, 2012, 12:59:34 PM
Combofix log is not complete but that part is missing is not what i need right now. 

How is your computer running now?
Title: Re: Issue with 800000cb.@ and 80000000.@
Post by: na_wspak on August 13, 2012, 01:35:39 PM
Thanks. Some system settings (like default browser) were changed to default but it's ok - I manage with it. Avast is quiet.  Emsisoft Emergency is quiet too. It seems to be alright. Thanks again for you time and effort.
Title: Re: Issue with 800000cb.@ and 80000000.@
Post by: magna86 on August 13, 2012, 02:05:42 PM

>>It is necessary to uninstall the ComboFix :
Code: [Select]
ComboFix /Uninstall Note that there is a space between "  ComboFix  " and "  /Uninstall  " .

Wait for the uninstall process is complete.



>> Re-run OTL and click on CleanUp! button



Be safe  ;)
Title: Re: Issue with 800000cb.@ and 80000000.@
Post by: na_wspak on August 13, 2012, 02:25:15 PM
Did what told to.

Big up!
Title: Re: Issue with 800000cb.@ and 80000000.@
Post by: magna86 on August 13, 2012, 02:26:28 PM
 ;)