Author Topic: Loads of malware!!!  (Read 25134 times)

0 Members and 1 Guest are viewing this topic.

Offline Interista

  • Sr. Member
  • ****
  • Posts: 332
Re: Loads of malware!!!
« Reply #30 on: August 03, 2013, 09:16:55 AM »
You could try a Firefox reset  http://support.mozilla.org/en-US/kb/reset-firefox-easily-fix-most-problems
....
My only problem now would be that I know have problems with BitMeter2 and Webcake (I know what the first is and its very useful, the second I don't know). I tried to fix it myself and found a program called Advanced Fix but it found 1000s of errors so I thought it better to leave it alone and ask you what to do. It seems to be runtime errors.

...Also,
Advanced Fix, Advanced Care, etc,., generally cause more problems than they purport to solve.  Suggest using WOT (see my sig below) to preview trustworthiness and vendor reputation before visiting any site.  Link in sig is clickable.

I think you're 100% spot on. I'm massively reinfected again.

I left avast and malwarebytes running last night when I went to bed and avast found:
C:\WINDOWS\assembly\NativeImages\v2.050727_32\System.ServiceModel\256c29338ead8ec627fa32ff4fa881ef\System.ServiceModel.ni.dll - says its a high severity - and says its a Threat: Rootkit: hidden file

I chose to move it to the chest and avast won't allow me - it only allows me to delete which I have it set up to do - it tells me action postponed until the next reboot.

I'm letting malwarebytes run to conclusion before doing anything though because it says there are 31 infections - and its still not finished.

I will attach logs once done - either I am doing something very seriously wrong or there is something very seriously wrong with my computer.

Offline mchain

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 5616
  • Spartan Warrior
Re: Loads of malware!!!
« Reply #31 on: August 03, 2013, 10:06:12 AM »
First line of defence is YOU, not avast!, Malwarebytes, or any other malicious file protection/remover or program.

A review of posts here reveals a lot of adware cr*p, but not any real serious infections.  Now, I'm assuming Malwarebytes is finding stuff related to Advanced Fix, so that is to be expected, if so.  It's there because you likely put it there.  Stop doing that.  Free programs are not really free, as you have seen.

If you can, avoid rebooting your system until essexboy comes back in, and do not make any more changes to your system without checking with him first.  This would include downloading and running a program similar to Advanced Fix.  Makes the job of cleaning your system much easier and you will get there much faster.

Please post the mbam log after it is finished, and a screenshot of the avast! threat detection will help.   ;D

Wait for essexboy to come back.
Windows 10 Home 64-bit 22H2 Avast Premier Security version 24.1.6099 (build 24.1.88821.762)  UI version 1.0.797
 UI version 1.0.788.  Windows 11 Home 23H2 - Windows 11 Pro 23H2 Avast Premier Security version 24.2.6105 (build 24.1.8918.827) UI version 1.0.801

Offline Interista

  • Sr. Member
  • ****
  • Posts: 332
Re: Loads of malware!!!
« Reply #32 on: August 03, 2013, 10:45:27 AM »
Yeah, I accept the abject stupidity of having had problems with having downloaded free software, getting help to resolve the issue, and then going out and doing exactly the same thing again - for some reason when I saw the Advanced Fix icon I thought I recognised the icon as legitimate (it looked like something else) hence the mistake.

Sorry.

Unfortunately, I had already rebooted by the time I read your message but I will upload the relevant logs. I also promise to be very careful about adding free software in future (is there anyway of telling what is a legitimate free program though and what is not - for example I have never had problems with VLC).
« Last Edit: August 03, 2013, 03:59:10 PM by Interista »

Offline Interista

  • Sr. Member
  • ****
  • Posts: 332
Re: Loads of malware!!!
« Reply #33 on: August 03, 2013, 10:45:57 AM »
Malwarebytes log.

Offline Interista

  • Sr. Member
  • ****
  • Posts: 332
Re: Loads of malware!!!
« Reply #34 on: August 03, 2013, 11:17:15 AM »
Adware Cleaner log.

Btw, is there any way to reduce the sensitivity of Private Firewall? I couldn't get on the internet for a minute because it asked me about a program - I said "block" and the internet was gone.

Offline Interista

  • Sr. Member
  • ****
  • Posts: 332
Re: Loads of malware!!!
« Reply #35 on: August 03, 2013, 11:23:22 AM »
When I was running the OTL scan I hit run fix instead of run scan by accident.

I got this log.

I hope I haven't messed up.

Offline Interista

  • Sr. Member
  • ****
  • Posts: 332
Re: Loads of malware!!!
« Reply #36 on: August 03, 2013, 11:52:50 AM »
OTL scan

Offline Interista

  • Sr. Member
  • ****
  • Posts: 332
Re: Loads of malware!!!
« Reply #37 on: August 03, 2013, 01:57:33 PM »
Last log - asw - says pwipf6 is locked.

I'm really sorry about all this after getting loads of help to fix my system. I've learned my lesson with free programs now.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Loads of malware!!!
« Reply #38 on: August 03, 2013, 04:17:37 PM »
Not a problem, we live and learn.  If you are after a free programme then ask here someone may be able to help :)

Warning This fix is only relevant for this system and no other, using on another computer may cause problems

Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot

Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following


Code: [Select]
:Commands
[CREATERESTOREPOINT]

:OTL
SRV - File not found [Auto | Stopped] -- C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\15.4.0\ToolbarUpdater.exe -- (vToolbarUpdater15.4.0)
SRV - [2013/02/05 16:48:00 | 000,235,216 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- C:\Program Files\McAfee Security Scan\3.0.318\McCHSvc.exe -- (McComponentHostService)
DRV - [2013/08/02 21:45:29 | 000,037,664 | ---- | M] (AVG Technologies) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avgtpx86.sys -- (avgtp)
[2013/08/03 09:30:07 | 000,000,000 | ---D | C] -- C:\Avenger
[2013/08/02 21:46:32 | 000,037,664 | ---- | C] (AVG Technologies) -- C:\WINDOWS\System32\drivers\avgtpx86.sys
[2013/08/02 21:46:09 | 000,003,717 | ---- | C] () -- C:\Program Files\Mozilla Firefoxavg-secure-search.xml
[2013/08/03 10:38:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Bitmeter2
[2013/01/05 20:52:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Andrew\Application Data\Bitmeter2
[2013/01/05 20:53:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Guest\Application Data\AskToolbar
[2013/01/05 20:53:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Guest\Application Data\BitMeter2
[2013/01/05 20:53:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Emma\Application Data\BitMeter2

:Files
C:\Program Files\Common Files\AVG Secure Search
C:\Program Files\McAfee Security Scan

:Commands
[resethosts]
[emptytemp]
[Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done
  • Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.

Offline Interista

  • Sr. Member
  • ****
  • Posts: 332
Re: Loads of malware!!!
« Reply #39 on: August 03, 2013, 04:52:01 PM »
Fix log is here, thanks!

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Loads of malware!!!
« Reply #40 on: August 03, 2013, 05:01:28 PM »
How is the computer behaving now ?

Offline mchain

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 5616
  • Spartan Warrior
Re: Loads of malware!!!
« Reply #41 on: August 03, 2013, 06:25:15 PM »
... I also promise to be very careful about adding free software in future (is there anyway of telling what is a legitimate free program though and what is not - for example I have never had problems with VLC).
Use WOT, Google first about a program, use Adblock Plus, check here first...
Windows 10 Home 64-bit 22H2 Avast Premier Security version 24.1.6099 (build 24.1.88821.762)  UI version 1.0.797
 UI version 1.0.788.  Windows 11 Home 23H2 - Windows 11 Pro 23H2 Avast Premier Security version 24.2.6105 (build 24.1.8918.827) UI version 1.0.801

Offline Interista

  • Sr. Member
  • ****
  • Posts: 332
Re: Loads of malware!!!
« Reply #42 on: August 04, 2013, 09:36:21 PM »
It seems a little sluggish on first impressions.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Loads of malware!!!
« Reply #43 on: August 04, 2013, 10:28:32 PM »
OK could you run a fresh OTL scan for me to check, I may need to reset your net connections later

Offline Interista

  • Sr. Member
  • ****
  • Posts: 332
Re: Loads of malware!!!
« Reply #44 on: August 05, 2013, 10:43:12 AM »
Here's the OTL log.

Also, I have three other problems:

1. I downloaded NoScript from that page you recommended - but its causing all sorts of problems - I have to ok almost every page even if I know full well they're legitimate. Can I safely get rid of NoScript?

2. I downloaded ERUNT from that page you recommended - but its asking me all the time to back up - I've tried getting rid of it but I haven't been able to.

3. I downloaded Private Firewall (recommended) - but its extremely sensitive, it asks allow/block questions all the time. Can I go back to Windows Firewall or is there a more user friendly one?