Avast WEBforum

Other => Viruses and worms => Topic started by: Zyla on July 24, 2013, 12:17:26 AM

Title: Am i infected with anything?
Post by: Zyla on July 24, 2013, 12:17:26 AM
Been a little sluggish on computer, so wondering if there is anything:

Title: Re: Am i infected with anything?
Post by: mikaelrask on July 24, 2013, 08:43:59 AM
hey and welcome to the forum. please also attach the logs from adwclener and mbam from this log.

http://forum.avast.com/index.php?topic=53253.0

a malware expert will help you from there  ;)
Title: Re: Am i infected with anything?
Post by: jeffce on July 24, 2013, 01:31:14 PM
Hi and Welcome!!   

My name is Jeff. I would be more than happy to take a look at your malware results logs and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:

IMPORTANT NOTE : Please do not delete, download or install anything unless instructed to do so.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision. Doing so could make your system inoperable and could require a full reinstall of your operating system and losing all your programs and data.

Having said that....   (http://i1224.photobucket.com/albums/ee380/jeffce74/vegeta_zps7f4345cf.gif)   Let's get going!! 
----------

(http://i1224.photobucket.com/albums/ee380/jeffce74/adwcleaner.jpg) AdwCleaner (http://www.bleepingcomputer.com/download/adwcleaner/dl/125/)
----------
Title: Re: Am i infected with anything?
Post by: Zyla on July 24, 2013, 08:00:18 PM
Here are the MBAM and adwcleaner logs
Title: Re: Am i infected with anything?
Post by: jeffce on July 25, 2013, 02:01:47 AM
(http://i1224.photobucket.com/albums/ee380/jeffce74/ckscannericon_zpsafea984c.jpg)  Download CKScanner by askey127 from Here (http://downloads.malwareremoval.com/CKScanner.exe) & save it to your Desktop.
Title: Re: Am i infected with anything?
Post by: Zyla on July 25, 2013, 02:43:39 AM
This is what it had:

CKScanner 2.3 - Additional Security Risks - These are not necessarily bad
scanner sequence 3.MN.11.UJAPRG
 ----- EOF -----
Title: Re: Am i infected with anything?
Post by: jeffce on July 26, 2013, 03:45:01 AM
Sorry for any delay...I had a long work day and also my son's football practice to coach. 

(http://i1224.photobucket.com/albums/ee380/jeffce74/RegistryIcon_zps289d6da1.png) Tweaking.com Registry Backup
------------------------

Run OTL.exe
Code: [Select]
:Services

:OTL
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O3 - HKU\S-1-5-21-3473907442-2693749499-135434744-1000\..\Toolbar\WebBrowser: (no name) - {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No CLSID value found.
O15 - HKU\S-1-5-21-3473907442-2693749499-135434744-1000\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
O15 - HKU\S-1-5-21-3473907442-2693749499-135434744-1000\..Trusted Domains: freerealms.com ([]* in Trusted sites)
O15 - HKU\S-1-5-21-3473907442-2693749499-135434744-1000\..Trusted Domains: soe.com ([]* in Trusted sites)
O15 - HKU\S-1-5-21-3473907442-2693749499-135434744-1000\..Trusted Domains: sony.com ([]* in Trusted sites)
O33 - MountPoints2\{dff56e7e-6b22-11e2-a1a3-7071bc1112d5}\Shell - "" = AutoRun
O33 - MountPoints2\{dff56e7e-6b22-11e2-a1a3-7071bc1112d5}\Shell\AutoRun\command - "" = F:\ToolLauncher-Bootstrap.exe
[1 C:\Windows\SysNative\drivers\*.tmp files -> C:\Windows\SysNative\drivers\*.tmp -> ]

:Files
ipconfig /flushdns /c

:Commands
[emptytemp]
[resethosts]
[start explorer]
[Reboot]
Attach the new OTL log and let me know how your system is running now.  :)
Title: Re: Am i infected with anything?
Post by: Zyla on July 26, 2013, 10:17:17 AM
Actually i dont think anything else is needed to be done, things seem to be running fine.
Title: Re: Am i infected with anything?
Post by: Pondus on July 26, 2013, 01:17:26 PM
Actually i dont think anything else is needed to be done, things seem to be running fine.
one more thing....when all is ok, jeffce will remove the tools used

Title: Re: Am i infected with anything?
Post by: jeffce on July 26, 2013, 01:40:08 PM
Glad to hear that things seems to be running well now.  Is that before or after you ran the last set of instructions with OTL?  If it was before, please run the last set of instructions.  An absence of symptoms does not mean an absence of the infection.  :)
Title: Re: Am i infected with anything?
Post by: Zyla on July 26, 2013, 08:23:15 PM
Here is the new OTL log
Title: Re: Am i infected with anything?
Post by: jeffce on July 26, 2013, 09:14:05 PM
Good...when you ran OTL the first time did it create a log named Extras.txt?  If so could you attach that please?  If not please do the following...

Please open OTL.

When the scan completes, it will open 2 notepad windows, OTL.Txt and Extra.txt. Please attach the Extra.txt.
----------
Title: Re: Am i infected with anything?
Post by: Zyla on July 26, 2013, 09:38:41 PM
This is the extras it made when i first ran it:
Title: Re: Am i infected with anything?
Post by: jeffce on July 26, 2013, 09:41:19 PM
(http://i1224.photobucket.com/albums/ee380/jeffce74/mbam-3.jpg) Malwarebytes

Please open Malwarebytes, update it and then run a Quick Scan.  Save the log that is created for your next reply.
----------

ESET Online Scanner

Go here (http://go.eset.com/us/online-scanner) to run an online scannner from ESET.  Windows Vista/Windows 7 users will need to right click on their Internet Explorer shortcut, and select Run as Administrator----------
Title: Re: Am i infected with anything?
Post by: Zyla on July 26, 2013, 11:21:16 PM
Here they are, dont know if ESET uninstalled correctly though (still have the ESET folder with only the uninstall in it)
Title: Re: Am i infected with anything?
Post by: jeffce on July 27, 2013, 03:34:10 AM
Hi,

First open an elevated command prompt > Click Start and type cmd in Start Search.
When cmd.exe populates above, right click it and select Run as Administrator to open an elevated command prompt.

Copy the contents of the code box > right click in the command window and select paste
Code: [Select]
del C:\Users\james\mirc715.exe
Press Enter (you won't actually see anything happen)
Close the Command Prompt window.

Let me know what remaining malware problems you are having now.  :)
Title: Re: Am i infected with anything?
Post by: Zyla on July 27, 2013, 05:01:18 AM
Does not appear there are any issues
Title: Re: Am i infected with anything?
Post by: jeffce on July 27, 2013, 03:51:39 PM
Ok sounds good.  :)

Providing there are no other malware related problems...

IT APPEARS THAT THE LOGS WE HAVE NOW ARE NOW CLEAN!  GREAT JOB!! 

This infection appears to have been cleared, but I can not give you any absolute guarantees.  As a precaution, I would go ahead and change all of your passwords as this is especially important after an infection.
----------

(http://i1224.photobucket.com/albums/ee380/jeffce74/OTL.jpg)  Clean up with OTL:
----------

Any of the logs that you created for use in the forums or remaining tools that have not yet been removed can be deleted so they aren't cluttering up your desktop. If you did not have Malwarebytes Antimalware before, I would keep it and run it weekly.
----------

Here are some tips to reduce the potential for spyware infection in the future:

1. Make your Internet Explorer more secure - This can be done by following these simple instructions:
2. FireFox  If you use Firefox, I recommend installing the following add-ons to help make your Firefox browser more secure:
NoScript (https://addons.mozilla.org/en-US/firefox/addon/noscript/)
AdBlock Plus (https://addons.mozilla.org/en-US/firefox/addon/adblock-plus/?src=ss)

3. Use and update an anti-virus software - I can not overemphasize the need for you to use and update your anti-virus application on a regular basis.  With the ever increasing number of new variants of malware arriving on the scene daily, you become very susceptible to an attack without updated protection.

4. Firewall
Using a third-party firewall will allow you to give/deny access for applications that want to go online. Without a firewall your computer is susceptible to being hacked and taken over. Simply using a firewall in its default configuration can lower your risk greatly.   **There are firewalls that could be downloaded and used but I would personally only recommend using one of the following two below:
Online Armor Free (http://download.cnet.com/Online-Armor-Free/3000-10435_4-10426782.html)
Agnitum Outpost Firewall Free (http://download.cnet.com/Agnitum-Outpost-Firewall-Free/3000-10435_4-10913746.html)

5. Make sure you keep your Windows OS currentWindows XP users can visit Windows update  (http://v4.windowsupdate.microsoft.com/en/default.asp)  regularly to download and install any critical updates and service packs. Windows Vista/7 users can open the Start menu > All Programs > Windows Update > Check for Updates (in left hand task pane) to update these systems.  Without these you are leaving the back door open.

6.   WOT   (http://www.mywot.com/) (Web of Trust) As "Googling" is such an integral part of internet life, this free browser add on warns you about risky websites that try to scam visitors, deliver malware or send spam. It is especially helpful when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites.  WOT has an add-on available for Firefox, Internet Explorer as well as Google Chrome.

7. Finally, I strongly recommend that you read Miekiemoes' great advice How to prevent malware.  (http://users.telenet.be/bluepatchy/miekiemoes/prevention.html)

Please reply to this thread once more if you are satisfied so that we can mark the problem as resolved.
----------
Title: Re: Am i infected with anything?
Post by: Zyla on July 27, 2013, 10:06:02 PM
Things are running good so no more issues it seems.
Title: Re: Am i infected with anything?
Post by: jeffce on July 27, 2013, 10:11:56 PM
Sounds great!  Glad that I could help!!  :)
Title: Re: Am i infected with anything?
Post by: jeffce on July 28, 2013, 03:31:40 PM
Since this issue appears to be resolved ... I will discontinue monitoring. Glad we could be of assistance.
----------