Author Topic: Win32:BProtect-J [Trj] virus encountered  (Read 4016 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
Win32:BProtect-J [Trj] virus encountered
« on: August 15, 2014, 05:52:36 AM »
I'm seeing multiple avast warnings of this virus.  Avast moves it to the chest but it keeps coming back.  Help!!  (Thanks-in-advance!)

System: Win7 Ultimate 64-bit

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76012
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Win32:BProtect-J [Trj] virus encountered
« Reply #1 on: August 15, 2014, 06:00:43 AM »
Attach your basic logs. (MBAM, FRST and aswMBR..!!)
Instructions: https://forum.avast.com/index.php?topic=53253.0
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

REDACTED

  • Guest
Re: Win32:BProtect-J [Trj] virus encountered
« Reply #2 on: August 15, 2014, 07:02:53 AM »
Requested logs are attached.

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76012
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Win32:BProtect-J [Trj] virus encountered
« Reply #3 on: August 15, 2014, 07:09:32 AM »
Good job, now you've to wait a bit...
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline magna86

  • Anti Malware Fighter
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4235
    • Ambulanta MyCity Forum - ASAP Member
Re: Win32:BProtect-J [Trj] virus encountered
« Reply #4 on: August 15, 2014, 02:11:26 PM »
Hello,

Posted FRST log does not show the PUP/Adware nor any other form of real malware presence.

We will preform the additional check via tool called Zoek. Zoek shall preform some fixes and examination at the same time.






Please download Zoek tool by Smeenk () from here and save it to your Desktop.
Unpack the archive...
  • Close any open browsers and temporarily disable your AntiVirus program. (if it is necessary)
    If you are unsure how to do this please read this or this Instruction.

  • Double click on zoek.exe to run the tool. Please wait while the tool does not start...
  • Copy the text present inside the code box below and paste it into the large window in the zoek tool:
Code: [Select]
Uninstall-List;
EmptyCLSID;
C:\Windows\System32\dkabcoms.exe;i
C:\Windows\system32\DKabcoms.exe;i
C:\Windows\SysWOW64\DKabcoms.exe;i
C:\ProgramData\374311380;vs
ResetHosts;
ResetIEProxy;
ipconfig /flushdns >> %temp%\log.txt;b
bitsadmin /reset /allusers >> %temp%\log.txt;b
EmptyFoldersCheck;Delete
StandardSearch;
AutoClean;
  • Click on button.
    Please wait until a logreport will open (this can be after reboot)

  • Save notepad to your Desktop and attach here zoek-results.log
    Note: It will also create a log in the C:\ directory named "zoek-results.log"

REDACTED

  • Guest
Re: Win32:BProtect-J [Trj] virus encountered
« Reply #5 on: August 15, 2014, 03:49:33 PM »
Zoek-results log attached.

Offline magna86

  • Anti Malware Fighter
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4235
    • Ambulanta MyCity Forum - ASAP Member
Re: Win32:BProtect-J [Trj] virus encountered
« Reply #6 on: August 15, 2014, 04:01:55 PM »
Cool. Zoek has done a few thing ... but still there is nothing dangerus here. Still, run zoek again with this script and tell me how is the computer running now?

Code: [Select]
EmptyAllTemp;
Notice: I do not need the fresh created zoek logreport.

REDACTED

  • Guest
Re: Win32:BProtect-J [Trj] virus encountered
« Reply #7 on: August 15, 2014, 04:12:44 PM »
Computer seems fine now.  The avast warning messages would pop up unexpectedly so I'll need a few days to be sure they're gone.

Thank to all involved for all your help!

Offline magna86

  • Anti Malware Fighter
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4235
    • Ambulanta MyCity Forum - ASAP Member
Re: Win32:BProtect-J [Trj] virus encountered
« Reply #8 on: August 15, 2014, 04:13:47 PM »
Monitor that please and if avast! throw a warning post the screenshot. I shall remove used tools now.


The following will implement some post-cleanup procedures:

=> Please download DelFix by Xplode to your Desktop.

Run the tool and check the following boxes below;
Remove disinfection tools
Create registry backup
Purge System Restore

Click Run button and wait a few seconds for the programme completes his work.
At this point all the tools we used here should be gone. Tool will create an report for you (C:\DelFix.txt)

The tool will also record healthy state of registry and make a backup using ERUNT program in %windir%\ERUNT\DelFix
Tool deletes old system restore points and create a fresh system restore point after cleaning.