Avast WEBforum

Consumer Products => Avast Free Antivirus / Premium Security (legacy Pro Antivirus, Internet Security, Premier) => Topic started by: balraj on February 23, 2014, 07:14:24 PM

Title: wscript.exe
Post by: balraj on February 23, 2014, 07:14:24 PM
Hi,
      I need help
      When i insert my pendrive iTunesHelper.vbe is automatically generated in it
     I found this is generated due to wscript.exe

       Please help in solving the issue.
Title: Re: wscript.exe
Post by: essexboy on February 23, 2014, 07:29:45 PM
Hi there we will need to clean all USBs and remove the bad boys

Download MCShield (http://www.mcshield.net/) to your desktop and install
It will initially run a scan and show the result as a toaster by the system clock
Then in the control centre select scanner and tick unhide items on flash drives
(https://dl.dropbox.com/u/73555776/mcshield%20unhide.JPG)
Plug in the drive and McShield will start a scan

Then get the log which will be here :

Start > all programs > MCShield > logs > all scans

And post that

THEN

Download  Anti VBS/VBE (http://www.mcshield.net/download/tools/Anti-VBSVBE/) to your desktop

Be aware this is a very new programme and as such is not recognised by any Antivirus or Windows, it is safe so allow it to run

FINALLY

Download OTL (http://oldtimer.geekstogo.com/OTL.exe)  to your Desktop
Secondary link (http://www.itxassociates.com/OT-Tools/OTL.exe)
(https://dl.dropboxusercontent.com/u/73555776/OTL_Main_Tutorial.gif)

netsvcs
BASESERVICES
%SYSTEMDRIVE%\*.exe
c:\program files (x86)\Google\Desktop
c:\program files\Google\Desktop
dir "%systemdrive%\*" /S /A:L /C
/md5start
rpcss.dll
/md5stop
CREATERESTOREPOINT


Title: Re: wscript.exe
Post by: balraj on February 23, 2014, 09:03:20 PM
Hai..

  As you have instructed i have attached the files.
Title: Re: wscript.exe
Post by: balraj on February 23, 2014, 09:07:26 PM
Hi.

    I have missed a file.
Title: Re: wscript.exe
Post by: essexboy on February 23, 2014, 10:20:09 PM
Could you confirm that the USB's are now OK

Warning This fix is only relevant for this system and no other, using on another computer may cause problems

Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot

Run OTL
Code: [Select]
:Commands
[CREATERESTOREPOINT]

:OTL
SRV - [2014/01/30 14:30:08 | 000,063,168 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\Mobogenie\MgAssist.exe -- (MgAssistService)
IE - HKU\S-1-5-21-1208941511-1268642884-337046589-1001\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://isearch.babylon.com/?q={searchTerms}&affID=120307&babsrc=SP_ss&mntrId=441929210000000000005a3e8eb35443
IE - HKU\S-1-5-21-1208941511-1268642884-337046589-1001\..\SearchScopes\{975E8216-47E6-473D-9735-56F2656E1B65}: "URL" = http://www.mysearchresults.com/search?c=2402&t=15&q={searchTerms}
O4 - HKLM..\Run: [mobilegeni daemon] C:\Program Files (x86)\Mobogenie\DaemonProcess.exe ()
[2014/02/23 16:52:42 | 000,000,000 | ---D | M] -- C:\Users\balraj\AppData\Roaming\newnext.me
[2013/10/08 22:19:56 | 000,000,000 | ---D | M] -- C:\Users\balraj\AppData\Roaming\OpenCandy
[2013/08/04 19:43:37 | 000,000,000 | ---D | M] -- C:\Users\balraj\AppData\Roaming\systweak

:Files
C:\Program Files (x86)\Mobogenie

:Commands
[resethosts]
[emptytemp]
[Reboot]
THEN

Please download AdwCleaner (http://www.bleepingcomputer.com/download/adwcleaner/) by Xplode onto your desktop.
Title: Re: wscript.exe
Post by: balraj on February 24, 2014, 06:51:59 AM
Hello...

     Thanks there is some improvement.
     by the help of mcshield the pendrive was blocked from that.
     But now too i should follow the last reply by you.
Title: Re: wscript.exe
Post by: essexboy on February 24, 2014, 02:42:08 PM
Yes continue the fixes to get you clean
Title: Re: wscript.exe
Post by: balraj on February 24, 2014, 07:13:10 PM
Hai..

  AS you have instructed i have attached
Title: Re: wscript.exe
Post by: essexboy on February 24, 2014, 07:22:44 PM
That looks better, how is the computer behaving now ?
Title: Re: wscript.exe
Post by: balraj on February 24, 2014, 07:28:42 PM
Hai..

       Thank a lot.....
       But the start menu icons (windows 8) are disabled it dosent matter i will get back.

      Thank you once again if i found any issue i will come back.
Thank you................