Author Topic: C:\WINDOWS\Installer - In Virus Chest, Now What?  (Read 11918 times)

0 Members and 2 Guests are viewing this topic.

RobinSaysHi

  • Guest
Re: C:\WINDOWS\Installer - In Virus Chest, Now What?
« Reply #15 on: July 09, 2012, 08:15:35 PM »
Okay, here's the ComboFix log...

Offline magna86

  • Anti Malware Fighter
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4235
    • Ambulanta MyCity Forum - ASAP Member
Re: C:\WINDOWS\Installer - In Virus Chest, Now What?
« Reply #16 on: July 09, 2012, 10:06:06 PM »
Step 1


Open notepad and copy/paste the text present inside the code box below:

Code: [Select]
ClearJavaCache::

DDS::
uStart Page = hxxp://search.babylon.com/?affID=112463&babsrc=HP_ss&mntrId=e0d9c9e8000000000000001b7752c556

Firefox::
FF - ProfilePath - c:\documents and settings\Robin\Application Data\Mozilla\Firefox\Profiles\3eavm3ir.default\
FF - prefs.js: keyword.URL - hxxp://search.babylon.com/?affID=112463&babsrc=KW_ss&mntrId=e0d9c9e8000000000000001b7752c556&q=
FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=112463
FF - user.js: extensions.BabylonToolbar_i.babExt -
FF - user.js: extensions.BabylonToolbar_i.srcExt - ss
FF - user.js: extensions.BabylonToolbar_i.id - e0d9c9e8000000000000001b7752c556
FF - user.js: extensions.BabylonToolbar_i.hardId - e0d9c9e8000000000000001b7752c556
FF - user.js: extensions.BabylonToolbar_i.instlDay - 15457
FF - user.js: extensions.BabylonToolbar_i.vrsn - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsni - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.5.3.170:46
FF - user.js: extensions.BabylonToolbar_i.prtnrId - babylon
FF - user.js: extensions.BabylonToolbar_i.prdct - BabylonToolbar
FF - user.js: extensions.BabylonToolbar_i.aflt - babsst
FF - user.js: extensions.BabylonToolbar_i.smplGrp - none
FF - user.js: extensions.BabylonToolbar_i.tlbrId - base
FF - user.js: extensions.BabylonToolbar_i.instlRef - sst

Save this as CFScript.



Close all browser windows and refering to the picture above.

Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
ComboFix will will re-run. When finished, it will produce a log for you.
Attach the contents of the log in your next reply. (typical location: C:\ComboFix.txt )





Step 2

> Check USB storage devices / removable drives


Download MCShield.
Official site

  • Double click MCShield-Setup to install the application.
  • Wait a few seconds to MCShield finish initial scan.
Recommendation to under General and Scanner tab you click on Defaults button to choose recommended options.
  • Connect your USB storage devices to the computer one at a time. Scanning will be done automatically.
When all scanning is done, you need to attach a logreport that has made MCShield.

Start -> All Programs -> MCShield -> Logs

Attach here -> AllScans.txt

Explanation: USB storage devices are all the USB devices that get their own partition letter at connecting to the PC,
e.g. flash drives (thumb/pen drives, USB sticks), external HDDs, MP3/MP4 players, digital cameras,
memory cards (SD cards, Sony Memory Stick, MultiMedia Cards etc.), some mobile phones, some GPS navigation devices etc.

RobinSaysHi

  • Guest
Re: C:\WINDOWS\Installer - In Virus Chest, Now What?
« Reply #17 on: July 09, 2012, 11:15:45 PM »
Here you go...

Offline magna86

  • Anti Malware Fighter
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4235
    • Ambulanta MyCity Forum - ASAP Member
Re: C:\WINDOWS\Installer - In Virus Chest, Now What?
« Reply #18 on: July 09, 2012, 11:24:50 PM »
Logs are clean and no signs of active malware.

It is necessary to uninstall Combofix


Start >> Run

Code: [Select]
Combofix /Uninstall
Enter



I recommend you to keep MCShield.
This light program will protect your system from any malware that can spread via USB devices.




RobinSaysHi

  • Guest
Re: C:\WINDOWS\Installer - In Virus Chest, Now What?
« Reply #19 on: July 09, 2012, 11:44:12 PM »
ComboFix has been uninstalled, and I've kept MCShield.

Thank you so much to everyone on this thread who helped me out! :) I like the Avast! program, but it's especially comforting to know that there are people in the Avast! forum who go the extra mile to help solve problems like these!

Offline magna86

  • Anti Malware Fighter
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4235
    • Ambulanta MyCity Forum - ASAP Member
Re: C:\WINDOWS\Installer - In Virus Chest, Now What?
« Reply #20 on: July 09, 2012, 11:45:03 PM »
np  ;)

me happy to  ;D