Author Topic: Win32:Agent-APRIK [Trj] virus  (Read 4229 times)

0 Members and 1 Guest are viewing this topic.

manueldel99

  • Guest
Win32:Agent-APRIK [Trj] virus
« on: April 09, 2014, 05:25:10 PM »
My old antivirus suscription expired a week ago so I downloaded avast. After installing it, it started detecting all my processes as infected or something. The virus was always Win32:Agent-APRIK [Trj] and it was located on C:\ProgramData\RazorU0\iuznffnsd.exe    but that folder doesn't exist!! There isn't any RazorU0 folder. If I delete the virus chest the antivirus starts detecting all the processes again and sending them to the virus chest. I don't know what to do. Please anyone help.

Offline TwinHeadedEagle

  • Malware Removal Expert
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 2987
    • Zemana
Re: Win32:Agent-APRIK [Trj] virus
« Reply #1 on: April 09, 2014, 05:47:16 PM »
Hi,



Please download Farbar Recovery Scan Tool by Farbar and save it to your desktop.

Note: You need to run the version compatibale with your system. If you are not sure which version applies to your system download both of them and try to run them.
Only one of them will run on your system, that will be the right version.


  • Double-click to run it. When the tool opens click Yes to disclaimer.
  • Under Optional Scan ensure "List BCD" and "Driver MD5" are ticked.
  • Press Scan button.
  • It will make a log (FRST.txt) in the same directory the tool is run. Please attach it to your reply.
  • The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.
My help is free, however if you'd like to show your appreciation by leaving a donation, it will be much appreciated ------> DONATE

manueldel99

  • Guest
Re: Win32:Agent-APRIK [Trj] virus
« Reply #2 on: April 09, 2014, 06:08:12 PM »
These are the files

Offline TwinHeadedEagle

  • Malware Removal Expert
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 2987
    • Zemana
Re: Win32:Agent-APRIK [Trj] virus
« Reply #3 on: April 09, 2014, 06:31:38 PM »
Your PC is Adware city  ???

Do you watch what you install and how you do it?



Please download AdwCleaner by Xplode and save to your Desktop.

Double click on AdwCleaner.exe to run the tool.
  • Click on the Scan button.
  • After the scan has finished click on the Clean button.
Press OK when asked to close all programs and follow the onscreen prompts.
Press OK again to allow AdwCleaner to restart the computer and complete the removal process.

  • After rebooting, a logfile report (AdwCleaner[S0].txt) will open automatically.
  • Post logfile will also be saved in the C:\AdwCleaner folder.
*****  NEXT  *****



Please download zoek.zip or zoek.rar by smeenk () from here or here and save it to your Desktop.
Unpack the archive...
  • Close any open browsers
  • Temporarily disable your AntiVirus program. (If necessary)
    If you are unsure how to do this please read this or this Instruction.

  • Double click on zoek.exe to run the tool .
    Please wait for the tool to start...

  • Copy the text present inside the code box below and paste it into the large window in the zoek tool:
Code: [Select]
createsrpoint;
gpt.ini;z
C:\Windows\System32\GroupPolicy;v
C:\Windows\SysWOW64\GroupPolicy;v
StandardSearch;
emptyfolderscheck;
installer-list;
installedprogs;
uninstall-list;
  • Click on button.
    Please wait until a logreport will open (this can be after reboot)

  • Save notepad to your Desktop and attach here zoek-results.log
    Note: It will also create a log in the C:\ directory named "zoek-results.log"
My help is free, however if you'd like to show your appreciation by leaving a donation, it will be much appreciated ------> DONATE

manueldel99

  • Guest
Re: Win32:Agent-APRIK [Trj] virus
« Reply #4 on: April 09, 2014, 07:20:01 PM »
This is the file

Offline TwinHeadedEagle

  • Malware Removal Expert
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 2987
    • Zemana
Re: Win32:Agent-APRIK [Trj] virus
« Reply #5 on: April 09, 2014, 07:46:04 PM »
Did you run Adwcleaner before Zoek? What about report?
My help is free, however if you'd like to show your appreciation by leaving a donation, it will be much appreciated ------> DONATE

manueldel99

  • Guest
Re: Win32:Agent-APRIK [Trj] virus
« Reply #6 on: April 09, 2014, 08:01:09 PM »
Oh, I had to post it too. Sorry. Here it is.

Offline TwinHeadedEagle

  • Malware Removal Expert
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 2987
    • Zemana
Re: Win32:Agent-APRIK [Trj] virus
« Reply #7 on: April 09, 2014, 08:47:40 PM »
> Re-run zoek with the script below and attach here fresh zoek log results.
NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to the operating system


Code: [Select]
Ask Toolbar;u
C:\Windows\System32\GroupPolicy\Machine;fs
C:\Windows\System32\GroupPolicy\User;fs
C:\Windows\System32\GroupPolicy\gpt.ini;f
[HKEY_USERS\S-1-5-21-2943374727-3930821536-709027394-1001\Software\Microsoft\Windows\CurrentVersion\Run];r
"RazorU"=-;r
C:\ProgramData\RazorU0;fs
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run];r
"RazorU"=-;r
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run-];r
"Browser Infrastructure Helper"=-;r
C:\\Users\\Usuario\\AppData\\Local\\Smartbar;fs
bmiabdepfhhiieiipmeecdmeljggmfee;chr
bbjciahceamgodcoidkjpchnokgfpphh;chr
jpmbfleldcgkldadpdinhjjopdfpjfjp;chr
dcillohgikpecbmgioknapdpcjofaafl;chr
autoclean;
emptyalltemp;
emptyclsid;
ipconfig /flushdns;b
emptyfolderscheck;delete
My help is free, however if you'd like to show your appreciation by leaving a donation, it will be much appreciated ------> DONATE

manueldel99

  • Guest
Re: Win32:Agent-APRIK [Trj] virus
« Reply #8 on: April 09, 2014, 11:07:14 PM »
here it is

Offline TwinHeadedEagle

  • Malware Removal Expert
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 2987
    • Zemana
Re: Win32:Agent-APRIK [Trj] virus
« Reply #9 on: April 10, 2014, 07:55:24 AM »
How is the situation now?
My help is free, however if you'd like to show your appreciation by leaving a donation, it will be much appreciated ------> DONATE

manueldel99

  • Guest
Re: Win32:Agent-APRIK [Trj] virus
« Reply #10 on: April 10, 2014, 03:30:26 PM »
Everyting is perfect now now. Thanks!!!

Offline TwinHeadedEagle

  • Malware Removal Expert
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 2987
    • Zemana
Re: Win32:Agent-APRIK [Trj] virus
« Reply #11 on: April 11, 2014, 08:13:20 PM »
Good :)


The following will implement some post-cleanup procedures:

=> Please download DelFix by Xplode to your Desktop.

Run the tool and check the following boxes below;
Remove disinfection tools
Create registry backup
Purge System Restore

Click Run button and wait a few seconds for the programme completes his work.
At this point all the tools we used here should be gone. Tool will create an report for you (C:\DelFix.txt)

The tool will also record healthy state of registry and make a backup using ERUNT program in %windir%\ERUNT\DelFix
Tool deletes old system restore points and create a fresh system restore point after cleaning.
`
My help is free, however if you'd like to show your appreciation by leaving a donation, it will be much appreciated ------> DONATE