Avast WEBforum

Other => Viruses and worms => Topic started by: Gullymar on January 19, 2014, 05:29:46 PM

Title: Win32:bprotect-d trj
Post by: Gullymar on January 19, 2014, 05:29:46 PM
Hey guys,

I recently had a scan via Avast where Win32:bprotect-d trj was detected. I wasn't able to remove it nor to block or repair.

Attached I have the mbam, OTL and aswMBR-Logs. Can you help me? Do you need further information?

Best regards beforehand!
Title: Re: Win32:bprotect-d trj
Post by: TwinHeadedEagle on January 19, 2014, 05:44:51 PM
Please download Farbar Recovery Scan Tool (http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/) ((http://www.mcshield.net/personal/magna86/Images/FRST_canned.png)) by Farbar and save it to your desktop.

Note: You need to run the version compatibale with your system. If you are not sure which version applies to your system download both of them and try to run them.
Only one of them will run on your system, that will be the right version.


Title: Re: Win32:bprotect-d trj
Post by: Gullymar on January 19, 2014, 06:19:12 PM
Hi thanks, see attached the FRST.txt.

Best regards
Title: Re: Win32:bprotect-d trj
Post by: TwinHeadedEagle on January 19, 2014, 08:03:10 PM
Download attached fixlist.txt to your Desktop.
NOTE: => It's important that both files, FRST and fixlist.txt are in the same location or the fix will not work.


Run FRST/FRST64 and press the Fix button just once and wait.
If the tool needed a restart please make sure you let the system to restart normally and let the tool completes its run after restart.

The tool will make a log on the Desktop (Fixlog.txt). Please attach it to your reply.
Note: If the tool warned you about the outdated version please download and run the updated version.


====================================================================


Please download AdwCleaner (http://www.bleepingcomputer.com/download/adwcleaner/) by Xplode and save to your Desktop.

Double click on AdwCleaner.exe to run the tool.
Press OK when asked to close all programs and follow the onscreen prompts.
Press OK again to allow AdwCleaner to restart the computer and complete the removal process.

=============================================================


Download TDSSKiller (http://media.kaspersky.com/utilities/VirusUtilities/EN/tdsskiller.exe)  and save it to your desktop

  Execute TDSSKiller.exe by doubleclicking on it.
Confirm "End user Licence Agreement" and "KSN Statement" dialog box by clicking on Accept button.
Once complete, a log will be produced at the root drive which is typically C:\ ,for example, C:\TDSSKiller.<version_date_time>log.txt


Please post the contents of that log in your next reply.
Title: Re: Win32:bprotect-d trj
Post by: Gullymar on January 20, 2014, 10:02:40 PM
Hey,

thanks for the quick reply. Have done it all, please see the attached logs.

Best regards
Title: Re: Win32:bprotect-d trj
Post by: TwinHeadedEagle on January 20, 2014, 10:07:27 PM
Run FRST and attach fresh report. Tell me how is the situation now?
Title: Re: Win32:bprotect-d trj
Post by: Gullymar on January 21, 2014, 08:52:05 PM
Hey,

I made a scan with FRST, attached you find the log. Anything unusual?

Best regards
Title: Re: Win32:bprotect-d trj
Post by: TwinHeadedEagle on January 21, 2014, 09:01:39 PM
Report looks clean, do you still have a warning?
Title: Re: Win32:bprotect-d trj
Post by: Gullymar on January 21, 2014, 09:18:16 PM
Hey,

thanks no don't have a warning anymore. If it looks clear I'll now wait and see and if the problem seems to continue I'll catch up with you. Thank you very much for the help.

Best regards
Title: Re: Win32:bprotect-d trj
Post by: TwinHeadedEagle on January 22, 2014, 08:58:51 AM
Please download  DelFix (http://general-changelog-team.fr/fr/downloads/finish/20-outils-de-xplode/9-delfix) by "Xplode" to your Desktop.

Run the tool and check the following boxes below;

Now click on "Run" button. Wait for the programme completes his work.
All the tools we used should be gone.
Tool will create and open an log report (DelFix.txt)
Note: The report will also be stored on C:\DelFix.txt


> I don't need DelFix log report.
Title: Re: Win32:bprotect-d trj
Post by: m3wh on February 13, 2014, 06:36:41 PM
I too have this virus and have been following your instructions, here are my log reports but the TDSSKiller didnt produce a log file for me to attach, it did say that no threats were found however.
Title: Re: Win32:bprotect-d trj
Post by: m3wh on February 13, 2014, 06:47:24 PM
Attached are the second reports after following the instructions
Title: Re: Win32:bprotect-d trj
Post by: TwinHeadedEagle on February 13, 2014, 07:01:40 PM
Hi,



Please download zoek.zip or zoek.rar by smeenk ((http://www.mcshield.net/personal/magna86/Images/Zoek_icon.png)) from here (http://'http://hijackthis.nl/smeenk') or here (http://'http://home.kpn.nl/stefsmeenk/zoek.exe') and save it to your Desktop.
Unpack the archive...
Code: [Select]
StandardSearch;
Title: Re: Win32:bprotect-d trj
Post by: m3wh on February 13, 2014, 07:27:20 PM
its saying web page not available, none of those links work
Title: Re: Win32:bprotect-d trj
Post by: TwinHeadedEagle on February 13, 2014, 08:07:55 PM
Try here

http://hijackthis.nl/smeenk/
Title: Re: Win32:bprotect-d trj
Post by: m3wh on February 13, 2014, 08:29:15 PM
Ok thats completed attached is the report
Title: Re: Win32:bprotect-d trj
Post by: TwinHeadedEagle on February 13, 2014, 08:39:38 PM
Re-run Zoek with this script


Code: [Select]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows];r
"AppInit_DLLs"=-;r
c:\\progra~3\\browse~1;fs
autoclean;
emptyalltemp;
Title: Re: Win32:bprotect-d trj
Post by: m3wh on February 13, 2014, 10:20:48 PM
ok thats completed
Title: Re: Win32:bprotect-d trj
Post by: m3wh on February 13, 2014, 10:48:29 PM
what do i need to do now?
Title: Re: Win32:bprotect-d trj
Post by: TwinHeadedEagle on February 13, 2014, 10:58:44 PM
Does the problem still persist
Title: Re: Win32:bprotect-d trj
Post by: m3wh on February 13, 2014, 11:09:13 PM
the problem was when I was running a boot scan using avast, it came up with the infected file but wouldnt allow me to do anything but abort the boot scan, shall i try that again? If so it should take about 20 mins to get to the 9% complete before it reaches where the problem was
Title: Re: Win32:bprotect-d trj
Post by: TwinHeadedEagle on February 13, 2014, 11:19:11 PM
You can try if you wish :)
Title: Re: Win32:bprotect-d trj
Post by: m3wh on February 14, 2014, 11:08:52 AM
Hi, i ran the scan and that was fine, it did flag up some other malware but that was able to be quarantined, so it worked, however i did try to run a system restore this morning from system image and it came up with the error (see attached).
I dont know if that is because of the said Virus this whole post is about or not
Title: Re: Win32:bprotect-d trj
Post by: TwinHeadedEagle on February 14, 2014, 11:12:38 AM
Good, let's fix System Restore


Please download Farbar Service Scanner (http://www.bleepingcomputer.com/download/farbar-service-scanner/dl/62/) and run it on the computer with the issue.
Title: Re: Win32:bprotect-d trj
Post by: m3wh on February 14, 2014, 11:25:01 AM
heres the log
Title: Re: Win32:bprotect-d trj
Post by: TwinHeadedEagle on February 14, 2014, 11:28:18 AM
System Restore looks good, can you take the picture of message that appears when you run System Restore.
Title: Re: Win32:bprotect-d trj
Post by: m3wh on February 14, 2014, 11:52:29 AM
am having issues with the screen shot being too large a file to attach, but the attached document is a copy of the exact wording from the error.
 This is followed by directions to try and restore again but to a different point or go to advanced recovery
Title: Re: Win32:bprotect-d trj
Post by: TwinHeadedEagle on February 14, 2014, 12:00:43 PM
Why would you do System Restore?
Title: Re: Win32:bprotect-d trj
Post by: m3wh on February 14, 2014, 12:03:57 PM
to see if the problem has resolved, as in did that virus cause this issue for it not to restore?
How can I tell if my computer is ok to use again for sensitive info?
Would it be easier to just create a new point if all traces of that virus has gone?
Title: Re: Win32:bprotect-d trj
Post by: TwinHeadedEagle on February 14, 2014, 12:21:20 PM
We can do it by following procedure. It will remove previous restore points and will create new one.


The following will implement some post-cleanup procedures:

=> Please download DelFix (http://general-changelog-team.fr/fr/downloads/finish/20-outils-de-xplode/9-delfix) by Xplode to your Desktop.

Run the tool and check the following boxes below;
(http://www.mcshield.net/personal/magna86/Images/checkmark.png) Remove disinfection tools
(http://www.mcshield.net/personal/magna86/Images/checkmark.png) Create registry backup
(http://www.mcshield.net/personal/magna86/Images/checkmark.png) Purge System Restore

Click Run button and wait a few seconds for the programme completes his work.
At this point all the tools we used here should be gone. Tool will create an report for you (C:\DelFix.txt)

The tool will also record healthy state of registry and make a backup using ERUNT program in %windir%\ERUNT\DelFix
Tool deletes old system restore points and create a fresh system restore point after cleaning.
Title: Re: Win32:bprotect-d trj
Post by: m3wh on February 14, 2014, 12:40:22 PM
Excellent. I really really appreciate your help over the last 24 hours. You have been great (an patient i must add given my novice knowledge of computer software).

Thank you so much

 :D

Mark
Title: Re: Win32:bprotect-d trj
Post by: gustavoberlin on March 03, 2014, 12:31:58 PM
Can you help me  TwinHeadedEagle with the  Win32:bprotect-d trj please?
 
I attached both files : FRST.txt and Adittion.txt

best regards
Title: Re: Win32:bprotect-d trj
Post by: Asyn on March 03, 2014, 12:33:29 PM
Please start a new topic. Thanks.
Title: Re: Win32:bprotect-d trj
Post by: Asyn on March 03, 2014, 02:20:42 PM
Can you help me  TwinHeadedEagle with the  Win32:bprotect-d trj please?

See: http://forum.avast.com/index.php?topic=147121.0
Title: Re: Win32:bprotect-d trj
Post by: REDACTED on February 12, 2015, 04:29:01 AM
Hi!
Unfortunately, I have a problem - after following the instructions, Avast boot scanning still finds the same Bprotect-D virus :(
So, please, help me.
Here are the FRST logs after the last scan with the still-existing virus.
Title: Re: Win32:bprotect-d trj
Post by: Asyn on February 12, 2015, 06:11:51 AM
Start a new topic in V&W and post your logs there: https://forum.avast.com/index.php?action=post;board=4.0