Author Topic: Virus Injected msg  (Read 2810 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
Virus Injected msg
« on: November 11, 2015, 08:54:25 AM »
Received msg stating "virus injected into computer ring 1-800..... to have release. Avast Boot Scan doesn't locate anything???
Do I worry,
Help please
Chris

Thanks, attached logs
MBR saved as .dat??
« Last Edit: November 11, 2015, 11:57:46 AM by chriskelly2526 »

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76014
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Virus Injected msg
« Reply #1 on: November 11, 2015, 09:24:15 AM »
Attach your basic diagnostic logs. (MBAM, FRST and aswMBR)
Instructions: https://forum.avast.com/index.php?topic=53253.0
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

REDACTED

  • Guest
Re: Virus Injected msg
« Reply #2 on: November 11, 2015, 12:00:39 PM »
Thank you.
I've attached logs

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31072
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: Virus Injected msg
« Reply #3 on: November 11, 2015, 12:06:18 PM »
The malwarebytes log is missing.

Please do not change the logfile names.
The date a log is created is already in the log files.
« Last Edit: November 11, 2015, 12:09:40 PM by Eddy »

REDACTED

  • Guest
Re: Virus Injected msg
« Reply #4 on: November 11, 2015, 12:15:11 PM »
Sorry, won't change names

Scan log attached

Chris

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76014
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Virus Injected msg
« Reply #5 on: November 11, 2015, 01:56:09 PM »
OK, now you've to wait a bit...
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Virus Injected msg
« Reply #6 on: November 11, 2015, 03:54:55 PM »
Did this appear on a web site ?  If you clicked nothing you are safe it was a scam

CAUTION :  This fix is only valid for this specific machine, using it on another may break your computer

Open notepad and copy/paste the text in the quotebox below into it:
 
Quote
CreateRestorePoint:
Toolbar: HKLM - No Name - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} -  No File
Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} -  No File
2013-12-20 10:02 - 2013-12-20 10:20 - 0000040 _____ () C:\Users\Chris\AppData\Roaming\Opusbext.dat
Reg: reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
Reg: reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
RemoveProxy:
EmptyTemp:
CMD: bitsadmin /reset /allusers

 
Save this as fixlist.txt, in the same location as FRST.exe

Run FRST and press Fix
On completion a log will be generated please post that

REDACTED

  • Guest
Re: Virus Injected msg
« Reply #7 on: November 11, 2015, 09:33:44 PM »
THANK YOU!
When pop-up appeared on web site, I pressed "x" then "leave page", then turned off modem, computer, uninstalled Chrome, ran Avast boot-time scan, ran "clean-up". reinstalled Chrome, re-ran boot-time scan. Posted msg to you.
Really appreciate your help.

DO I NEED TO WORRY ABOUT OTHER LAPTOPS, TABLETS, PS4, on home Network?
Sons doing final year 12+10 exams, so have been using internet for study, last exam tomorrow.

regards
Chris (full 12 hour day at work, home 8pm Aust EST)

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Virus Injected msg
« Reply #8 on: November 11, 2015, 10:11:13 PM »
No, nothing should have been affected as it was popup  on the web page, which would only activate if you had clicked through and I am sure Avast would have blocked it then

REDACTED

  • Guest
Re: Virus Injected msg
« Reply #9 on: November 12, 2015, 09:59:34 AM »
Thanks Heaps for your assistance! :) :) :)

regards
Chris
P.S. Do I owe you guys anything or donations etc?

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76014
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Virus Injected msg
« Reply #10 on: November 12, 2015, 10:03:00 AM »
P.S. Do I owe you guys anything or donations etc?
Nope, our help is free. 8)
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0