Author Topic: VBS:FlufferMiner-D [TRJ]  (Read 6596 times)

0 Members and 1 Guest are viewing this topic.

rogi10

  • Guest
VBS:FlufferMiner-D [TRJ]
« on: November 14, 2013, 07:48:35 PM »
Hello. It is my first time posting on this forum (though I have lurked over here for some time, trying to learn some things), so I am sorry if something isn't done as it should be, and I will try to fix it right away.

So, I tend to do a full scan every few days, to be on the safe side. I had one done yesterday, and it came out clean. I tried to do one today, and after it got to 37% it went back to 3%, and it reported one infected file. At this time, the scan speed dropped from 1 GB/s to around 80 MB/s, which is odd, considering my C: drive is a SSD. When it scanned my E: drive, the speed was unchanged.

I stopped the scan to see what the file was, since I have not downloaded anything between these 2 scans, nor have I visited any suspicious sites. The infected file was "C:\Windows\Prefetch\AgRobust.db" , and it was described as the malware in the thread title. I did a google search, and apparently this should be a safe file. Still, I tried moving it to chest from the scan log, but I was not able to. I got an error saying "Virus Server Chest is not running. RPC communication failed. (2147422219)".

I am currently running another full scan, and waiting for it to finish. It has currently been 1h 5 mins from the scan start, while it usually takes around 25 minutes, which is making me think there is indeed something going wrong. I would appreciate any help with this issue, or some kind of confirmation that it is a false positive. Also, would it be safe to delete this file?

Thanks in advance,

Rog
« Last Edit: November 14, 2013, 07:55:38 PM by rogi10 »

Offline TwinHeadedEagle

  • Malware Removal Expert
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 2987
    • Zemana
Re: VBS:FlufferMiner-D [TRJ]
« Reply #1 on: November 14, 2013, 07:58:24 PM »
Hi,


Please download AdwCleaner by Xplode and save to your Desktop.

Double click on AdwCleaner.exe to run the tool.
  • Click on the Scan button.
  • After the scan has finished click on the Clean button.
Press OK when asked to close all programs and follow the onscreen prompts.
Press OK again to allow AdwCleaner to restart the computer and complete the removal process.

  • After rebooting, a logfile report (AdwCleaner[S0].txt) will open automatically.
  • Post logfile will also be saved in the C:\AdwCleaner folder.
Please download aswMBR and save it to your desktop.

Double click aswMBR.exe to start the tool.
  • Select Yes if prompted to download the Avast database.
     
  • Click Scan
     
  • Upon completion of the scan ( Scan finished successfully ) click Save log and save it to your desktop, and post that log in your next reply for review.
    Note: do NOT attempt any Fix yet.
Please download Farbar Recovery Scan Tool by Farbar and save it to your desktop.

Note: You need to run the version compatibale with your system. If you are not sure which version applies to your system download both of them and try to run them.
Only one of them will run on your system, that will be the right version.


  • Double-click to run it. When the tool opens click Yes to disclaimer.
  • Under Optional Scan ensure "List BCD" and "Driver MD5" are ticked.
  • Press Scan button.
  • It will make a log (FRST.txt) in the same directory the tool is run. Please attach it to your reply.
  • The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.
My help is free, however if you'd like to show your appreciation by leaving a donation, it will be much appreciated ------> DONATE

rogi10

  • Guest
Re: VBS:FlufferMiner-D [TRJ]
« Reply #2 on: November 14, 2013, 08:05:18 PM »
Thanks for the reply. I'm already downloading the programs that you mentioned, but before running them, considering I am running a full scan with Avast!, should I wait for it to end, since it has been going for like a hour and a half and try to move it to chest again/delete the file, or should I stop it prematurely and run the programs you mentioned?
The scan has now finished, and the only threat detected was indeed the same file. So, should I attempt some sort of action with avast, or just skip it and go straight to the programs you mentioned? By the way, Avast flagged the second file as suspicious, even though it's clearly not. Just found it curious :p
« Last Edit: November 14, 2013, 08:20:27 PM by rogi10 »

rogi10

  • Guest
Re: VBS:FlufferMiner-D [TRJ]
« Reply #3 on: November 14, 2013, 08:41:14 PM »
So I ran the scans you asked me to, logs are attached as you asked.

Thanks for your patience,

Rog

Offline TwinHeadedEagle

  • Malware Removal Expert
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 2987
    • Zemana
Re: VBS:FlufferMiner-D [TRJ]
« Reply #4 on: November 14, 2013, 09:06:58 PM »
This is False Positive detection, your system is clean...



Please download DelFix by "Xplode" to your Desktop.

Run the tool and check the following boxes below;
  • Remove disinfection tools
  • Create registry backup
  • Purge System Restore

Now click on "Run" button. Wait for the programme completes his work.
All the tools we used should be gone.
Tool will create and open an log report (DelFix.txt)
Note: The report will also be stored on C:\DelFix.txt


> I don't need DelFix log report.
My help is free, however if you'd like to show your appreciation by leaving a donation, it will be much appreciated ------> DONATE

TIG3R3K

  • Guest
Re: VBS:FlufferMiner-D [TRJ]
« Reply #5 on: November 14, 2013, 09:14:14 PM »
same problem here,if i have this virus in quarantine is it good ? or i must restore it. I think avast is good antivirus so it know what is virus and what isnt. Sorry for my english but i come from Poland. but my PC was starting slower than yesterday so i think it iis virus.

rogi10

  • Guest
Re: VBS:FlufferMiner-D [TRJ]
« Reply #6 on: November 14, 2013, 09:16:35 PM »
Alrighty, thanks for the help! Could you just tell me how can I report this as a false positive, and where i can find a solution for the slow scans?

Thanks again,

Rog

Offline Secondmineboy

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3645
Re: VBS:FlufferMiner-D [TRJ]
« Reply #7 on: November 14, 2013, 09:18:07 PM »
@TIG3R3K:

These detections seem to be false positives after Windows Update.

If you want a malware check follow the logs in assist to clean malware topic on
top of this forum section.
Windows 10 1909, 4 GB DDR3 RAM, 500 GB 5400 RPM HDD, 1366 by 768 LCD Screen, Intel Core i3 5010U Dual Core, Intel HD Graphics 5500
HUAWEI P30 Pro. Android 10

rogi10

  • Guest
Re: VBS:FlufferMiner-D [TRJ]
« Reply #8 on: November 14, 2013, 09:21:11 PM »
I doubt it is because of windows updates, because I do not have windows updates turned on, and I still got this false positive.

TIG3R3K

  • Guest
Re: VBS:FlufferMiner-D [TRJ]
« Reply #9 on: November 14, 2013, 09:25:32 PM »
IF i will leave it in quarantaine and dont remove this file which isnt virus, can it slow my PC, FPS etc. ?

Offline Secondmineboy

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3645
Re: VBS:FlufferMiner-D [TRJ]
« Reply #10 on: November 14, 2013, 09:27:27 PM »
NO.

Quarantine is save.
Windows 10 1909, 4 GB DDR3 RAM, 500 GB 5400 RPM HDD, 1366 by 768 LCD Screen, Intel Core i3 5010U Dual Core, Intel HD Graphics 5500
HUAWEI P30 Pro. Android 10

Offline Secondmineboy

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3645
Re: VBS:FlufferMiner-D [TRJ]
« Reply #11 on: November 14, 2013, 09:30:14 PM »
This detection was added in the last VPS update so its really new.

http://www.avast.com/de-de/virus-update-history
Windows 10 1909, 4 GB DDR3 RAM, 500 GB 5400 RPM HDD, 1366 by 768 LCD Screen, Intel Core i3 5010U Dual Core, Intel HD Graphics 5500
HUAWEI P30 Pro. Android 10