Author Topic: Post Live Security Platinum clean up errors  (Read 5004 times)

0 Members and 1 Guest are viewing this topic.

Osato

  • Guest
Post Live Security Platinum clean up errors
« on: July 23, 2012, 07:54:36 PM »
Hi from a new one.

My PC became infected with the Live Security Platform malware over the weekend. I downloaded the Malwarebytes to remove it and then installed Avast and ran the boot scan and cleared all the issues there. Since then I'm receiving 2 errors on start up in the Appdata folder

\Roaming\dsapsi.dll
\Local\Temp\msfefo3264.dll

Also getting regular pop ups from Avast regarding both 80000000.@ and 800000cb.@ with the Win32:Malware-gen infection error. Any help appreciated thanks.

Online DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89271
  • No support PMs thanks
Re: Post Live Security Platinum clean up errors
« Reply #1 on: July 23, 2012, 08:49:00 PM »
Given what it is, I rather doubt that it was completely cleared. Avast is effectively preventing the underlying infection from getting worse.

This needs further analysis by a malware removal specialist:
Go to this topic http://forum.avast.com/index.php?topic=53253.0 for information on Logs to assist in cleaning malware. Use the information about getting and using the tools and attach the logs here, not in the LOGS topic.

What was your previous AV and how did you remove it before installing avast ?
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.5.6116 (build 24.5.9153.762) UI 1.0.808/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Osato

  • Guest
Re: Post Live Security Platinum clean up errors
« Reply #2 on: July 23, 2012, 09:26:12 PM »
I only used the Windows anti-virus security before, not exactly great. To remove it initially I ran Windows in safe mode and downloaded Malwarebytes and ran the scans and removed all the infections it registered and rebooted normally before installing Avast.

Logs included

Offline magna86

  • Anti Malware Fighter
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4235
    • Ambulanta MyCity Forum - ASAP Member
Re: Post Live Security Platinum clean up errors
« Reply #3 on: July 23, 2012, 09:28:47 PM »
Monitoring  ;)

Offline magna86

  • Anti Malware Fighter
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4235
    • Ambulanta MyCity Forum - ASAP Member
Re: Post Live Security Platinum clean up errors
« Reply #4 on: July 23, 2012, 09:32:55 PM »
Hello,  :)

Step 1


Re-run OTL.exe.

  • Copy and paste the following text written inside of the quote box into the Custom Scans/Fixes box.

Code: [Select]
:Files
ipconfig /flushdns /c
C:\Windows\Installer\{b1f4a788-4bcd-3704-654e-6a6247226301}
C:\Users\Osato\AppData\Local\{b1f4a788-4bcd-3704-654e-6a6247226301}

:OTL
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

:Commands
[emptytemp]
  • Then click the Run Fix button at the top.
  • Let the program run unhindered; it will reboot the system when it is done and open notepad with logreport. Attach here that logreport.
********************


Step 2

> Download ComboFix from here and save it to your Desktop.
If you are unsure how ComboFix works please read this guide carefully.
note: ComboFix must be downloaded to your Desktop.

> Temporarily disable your AntiVirus program.
If you are unsure how to do this please read this Instruction.

> Run ComboFix. Click on I Agree!
ComboFix will check if there is a newer version of ComboFix available.
Click Yes if prompted to download.

ComboFix will display DISCLAIMER OF WARRANTY ON SOFTWARE.
Click Yes to allow ComboFix to continue.

If Recovery Console is not installed, ComboFix will offer download & installation.
Click Yes to allow ComboFix to install Recovery Console.


> When the tool is finished, it will produce a log report for you. (typical location: C:\ComboFix.txt )
  Attach log reports ( ComboFix.txt) back to topic.

Osato

  • Guest
Re: Post Live Security Platinum clean up errors
« Reply #5 on: July 23, 2012, 10:14:14 PM »
Followed both your steps. However since the reboot that combofix created I'm unable to use programs on the PC getting an error with

C:\ (any program location)
Illegal operation attempted on a registry key that has been marked for deletion

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37599
  • Not a avast user
Re: Post Live Security Platinum clean up errors
« Reply #6 on: July 23, 2012, 10:33:17 PM »
reboot one more time   ;)

Osato

  • Guest
Re: Post Live Security Platinum clean up errors
« Reply #7 on: July 23, 2012, 10:40:34 PM »
Cheers for that I didn't want to do something that would cause any issues  ;)

Both logs attatched

Offline magna86

  • Anti Malware Fighter
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4235
    • Ambulanta MyCity Forum - ASAP Member
Re: Post Live Security Platinum clean up errors
« Reply #8 on: July 23, 2012, 11:28:24 PM »
Thanks Pondus  :D

@Osato
Do the CFScript.
>Then tell me how yours computer running now and do you still have have a malware detection?



CFScript

Open notepad and copy/paste the text present inside the code box below:


Code: [Select]
DirLook::
c:\windows\system32\%APPDATA%
c:\programdata\225932DF0053EE4E00077666F875F002

ClearJavaCache::

RegLock::
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_257_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_257_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_257.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_257.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_257.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_257.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)


Save this as CFScript.txt



Close all browser windows and refering to the picture above.

Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
ComboFix will will re-run. When finished, it will produce a log for you.
Attach the contents of the log in your next reply. (typical location: C:\ComboFix.txt )

Osato

  • Guest
Re: Post Live Security Platinum clean up errors
« Reply #9 on: July 23, 2012, 11:48:30 PM »
Latest log. Haven't had any new Avast alerts so far

Offline magna86

  • Anti Malware Fighter
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4235
    • Ambulanta MyCity Forum - ASAP Member
Re: Post Live Security Platinum clean up errors
« Reply #10 on: July 24, 2012, 01:21:27 AM »
You are clean.  :)

It is necessary to uninstall Combofix


>Start ()  >>  Run

Code: [Select]
Combofix /Uninstall
Enter


> Re-run OTL and click CleanUp!


 ;)

Osato

  • Guest
Re: Post Live Security Platinum clean up errors
« Reply #11 on: July 24, 2012, 08:09:39 AM »
All uninstalled and cleaned. Thanks a lot for the help  :)

miro8

  • Guest
Re: Post Live Security Platinum clean up errors
« Reply #12 on: July 24, 2012, 08:19:39 AM »
that shit is crazy! I cleared my before few days, I'm almost 100% shure it came from website, not installation

Good luck with cleaning ;)