Author Topic: Help!!!! 80000000.@ Popping Up......  (Read 7705 times)

0 Members and 1 Guest are viewing this topic.

catcatms

  • Guest
Help!!!! 80000000.@ Popping Up......
« on: August 14, 2012, 01:46:45 AM »
I got 80000000.@ and 00000001.@ popping up threat detected messages in every few minute for the past few days. I was ignoring the warnings for a while but now it's beginning to interfere with my internet browsing and word processing, any help would be appreciated.

I installed and running the malwarebytes anti-malware and avast free version, all  infected files were deleted by the problem still happen. Where can I find the log to post you or which program should I download to solve it?

Can anyone help me?

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89676
  • No support PMs thanks
Re: Help!!!! 80000000.@ Popping Up......
« Reply #1 on: August 14, 2012, 01:50:55 AM »
This needs further analysis by a malware removal specialist:
Go to this topic http://forum.avast.com/index.php?topic=53253.0 for information on Logs to assist in cleaning malware. Use the information about getting and using the tools and attach the logs here, not in the LOGS topic.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD - 27" external monitor 1440p 2560x1440 resolution - avast! free  24.9.6130 (build 24.9.9452.762) UI 1.0.818/ Firefox, uBlock Origin Lite, uMatrix/ MailWasher Pro/ Avast! Mobile Security

catcatms

  • Guest
Re: Help!!!! 80000000.@ Popping Up......
« Reply #2 on: August 14, 2012, 11:55:13 AM »
Thanks a lot, will start doing it

« Last Edit: August 14, 2012, 12:29:09 PM by catcatms »

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76014
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Help!!!! 80000000.@ Popping Up......
« Reply #3 on: August 14, 2012, 12:12:30 PM »
OTL log is coming in the next reply

Dont copy & paste..!! Please attach your logs..!!! Thanks. :)
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

catcatms

  • Guest
Re: Help!!!! 80000000.@ Popping Up......
« Reply #4 on: August 14, 2012, 12:28:23 PM »
will it takes long time to run OTL?
« Last Edit: August 14, 2012, 12:40:09 PM by catcatms »

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37699
Re: Help!!!! 80000000.@ Popping Up......
« Reply #5 on: August 14, 2012, 12:34:59 PM »
usually not.....give it an hour before you stop
you may try running it in safe mode

catcatms

  • Guest
Re: Help!!!! 80000000.@ Popping Up......
« Reply #6 on: August 14, 2012, 12:41:14 PM »
please find my OTL and MBAM log here
« Last Edit: August 14, 2012, 12:59:03 PM by catcatms »

catcatms

  • Guest
Re: Help!!!! 80000000.@ Popping Up......
« Reply #7 on: August 14, 2012, 05:12:47 PM »
usually not.....give it an hour before you stop
you may try running it in safe mode

Please find my logs as above

Offline magna86

  • Anti Malware Fighter
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4235
    • Ambulanta MyCity Forum - ASAP Member
Re: Help!!!! 80000000.@ Popping Up......
« Reply #8 on: August 14, 2012, 05:26:59 PM »
Monitoring  ;)

Offline magna86

  • Anti Malware Fighter
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4235
    • Ambulanta MyCity Forum - ASAP Member
Re: Help!!!! 80000000.@ Popping Up......
« Reply #9 on: August 14, 2012, 05:33:15 PM »
Hi,  :)
I will be working on your Malware issues



1. Please download TFC by OldTimer to your desktop
  • Please double-click TFC.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • It will close all programs when run, so make sure you have saved all your work before you begin.
  • Click the Start button to begin the process. Depending on how often you clean temp
    files, execution time should be anywhere from a few seconds to a minute
    or two. Let it run uninterrupted to completion.
  • Once it's finished it should reboot your machine. If it does not, please manually reboot the machine yourself to ensure a complete clean.
***********************


Step 2



> Download ComboFix from here and save it to your Desktop.
If you are unsure how ComboFix works please read this guide carefully.
note: ComboFix must be downloaded to your Desktop.

> Temporarily disable your AntiVirus program.
If you are unsure how to do this please read this Instruction.

How to disable avast:

  • Right-click on the avast! icon in the lower right corner of the screen and choose Open Avast! User Interface.
  • In the window that opens on the top right corner, click Settings.
  • In a new window that opens, choose the option Troubleshooting, Uncheck Enable avast! self-defense, and click OK.

  • Right-click on the avast! icon in the lower right corner of the screen and select avast! shield controls .
  • In the menu that appears, choose Disable Permanently. When you are prompted to turn off security, click Yes.
Note: Do not forget to turn on this option after the cleaning.



> Run ComboFix. Click on I Agree!
ComboFix will check if there is a newer version of ComboFix available.
Click Yes if prompted to download.

ComboFix will display DISCLAIMER OF WARRANTY ON SOFTWARE.
Click Yes to allow ComboFix to continue.

If Recovery Console is not installed, ComboFix will offer download & installation.
Click Yes to allow ComboFix to install Recovery Console.
Note:Do not mouse-click Combofix's window while it is running.


> When the tool is finished, it will produce a log report for you. (typical location: C:\ComboFix.txt )
  Attach log reports ( ComboFix.txt) back to topic.



If you fail to run Combofix, run it in safe mode.


catcatms

  • Guest
Re: Help!!!! 80000000.@ Popping Up......
« Reply #10 on: August 14, 2012, 08:57:49 PM »
Hi,  :)
I will be working on your Malware issues



1. Please download TFC by OldTimer to your desktop
  • Please double-click TFC.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • It will close all programs when run, so make sure you have saved all your work before you begin.
  • Click the Start button to begin the process. Depending on how often you clean temp
    files, execution time should be anywhere from a few seconds to a minute
    or two. Let it run uninterrupted to completion.
  • Once it's finished it should reboot your machine. If it does not, please manually reboot the machine yourself to ensure a complete clean.
***********************


Step 2



> Download ComboFix from here and save it to your Desktop.
If you are unsure how ComboFix works please read this guide carefully.
note: ComboFix must be downloaded to your Desktop.

> Temporarily disable your AntiVirus program.
If you are unsure how to do this please read this Instruction.

How to disable avast:

  • Right-click on the avast! icon in the lower right corner of the screen and choose Open Avast! User Interface.
  • In the window that opens on the top right corner, click Settings.
  • In a new window that opens, choose the option Troubleshooting, Uncheck Enable avast! self-defense, and click OK.

  • Right-click on the avast! icon in the lower right corner of the screen and select avast! shield controls .
  • In the menu that appears, choose Disable Permanently. When you are prompted to turn off security, click Yes.
Note: Do not forget to turn on this option after the cleaning.



> Run ComboFix. Click on I Agree!
ComboFix will check if there is a newer version of ComboFix available.
Click Yes if prompted to download.

ComboFix will display DISCLAIMER OF WARRANTY ON SOFTWARE.
Click Yes to allow ComboFix to continue.

If Recovery Console is not installed, ComboFix will offer download & installation.
Click Yes to allow ComboFix to install Recovery Console.
Note:Do not mouse-click Combofix's window while it is running.


> When the tool is finished, it will produce a log report for you. (typical location: C:\ComboFix.txt )
  Attach log reports ( ComboFix.txt) back to topic.



If you fail to run Combofix, run it in safe mode.

Please find the log report as attached :)

Offline magna86

  • Anti Malware Fighter
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4235
    • Ambulanta MyCity Forum - ASAP Member
Re: Help!!!! 80000000.@ Popping Up......
« Reply #11 on: August 15, 2012, 01:03:53 AM »
Open notepad and copy/paste the text present inside the code box below:


Code: [Select]

Folder::
c:\windows\Installer\{00b4e2c7-6edb-d884-b334-5eef3a884c97}

KillAll::

ClearJavaCache::

RegLock::
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)



Save this as CFScript.txt



Close all browser windows and refering to the picture above.

Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
ComboFix will will re-run. When finished, it will produce a log for you.
Attach the contents of the log in your next reply. (typical location: C:\ComboFix.txt )

catcatms

  • Guest
Re: Help!!!! 80000000.@ Popping Up......
« Reply #12 on: August 15, 2012, 02:06:12 PM »
Open notepad and copy/paste the text present inside the code box below:


Code: [Select]

Folder::
c:\windows\Installer\{00b4e2c7-6edb-d884-b334-5eef3a884c97}

KillAll::

ClearJavaCache::

RegLock::
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)



Save this as CFScript.txt



Close all browser windows and refering to the picture above.

Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
ComboFix will will re-run. When finished, it will produce a log for you.
Attach the contents of the log in your next reply. (typical location: C:\ComboFix.txt )

Hi, i followed your instruction, turn off the Avast and doing the CFScript.txt dragging into ComboFix.exe. After that, CombiFix run automatically and after a few minutes the computer reboot, a pop up said the windows cannot start up normally and i followed the recommended step from Windows to restart my computer

After it restart, the ComboFix.exe icon located in desktop is disappeared and no scanning by ComboFix after reboot. and the Avast enable automatically. What should i do now???

For your information, after i use combofix.exe yesterday and posted my logs to you, pop up seems no more exists, but I don't know is it totally cleared the trojan or not.

Offline magna86

  • Anti Malware Fighter
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4235
    • Ambulanta MyCity Forum - ASAP Member
Re: Help!!!! 80000000.@ Popping Up......
« Reply #13 on: August 16, 2012, 02:02:56 PM »

Hi, i followed your instruction, turn off the Avast and doing the CFScript.txt dragging into ComboFix.exe. After that, CombiFix run automatically and after a few minutes the computer reboot, a pop up said the windows cannot start up normally and i followed the recommended step from Windows to restart my computer

After it restart, the ComboFix.exe icon located in desktop is disappeared and no scanning by ComboFix after reboot. and the Avast enable automatically. What should i do now???

There is no reason to worry abaut, just classic pop-up error has prevented Combofix to finish scanning.
OK, let's see what happened and what is the current situation.

Download DDS and save it to your Desktop from here:
http://download.bleepingcomputer.com/sUBs/dds.scr

Double click dds to run the tool.

    * When done, DDS will open two (2) logs:
        1. DDS.txt
        2. Attach.txt

Save both reports to your desktop. DDS.txt and Attach.txt attach back to topic.


« Last Edit: August 16, 2012, 02:04:30 PM by magna86 »

catcatms

  • Guest
Re: Help!!!! 80000000.@ Popping Up......
« Reply #14 on: August 21, 2012, 12:28:18 PM »

Hi, i followed your instruction, turn off the Avast and doing the CFScript.txt dragging into ComboFix.exe. After that, CombiFix run automatically and after a few minutes the computer reboot, a pop up said the windows cannot start up normally and i followed the recommended step from Windows to restart my computer

After it restart, the ComboFix.exe icon located in desktop is disappeared and no scanning by ComboFix after reboot. and the Avast enable automatically. What should i do now???

There is no reason to worry abaut, just classic pop-up error has prevented Combofix to finish scanning.
OK, let's see what happened and what is the current situation.

Download DDS and save it to your Desktop from here:
http://download.bleepingcomputer.com/sUBs/dds.scr

Double click dds to run the tool.

    * When done, DDS will open two (2) logs:
        1. DDS.txt
        2. Attach.txt

Save both reports to your desktop. DDS.txt and Attach.txt attach back to topic.

Hi, here is the log from DDS