Author Topic: Multiple viruses on boot scan  (Read 5791 times)

0 Members and 2 Guests are viewing this topic.

HairLost

  • Guest
Multiple viruses on boot scan
« on: February 16, 2014, 09:45:42 PM »
I scanned my computer for viruses and 1 was found, I was then recommended to do a boot scan, so I did. Multiple viruses were found including somoto-J and Agent.fxx. They have been quarantined.

I decided to go through the steps shown on these forums using MBAM, OTL and aswMBR. Although aswMBR consistently paused through the scan, I was able to get reports from MBAM and OTL.

Can someone with more knowledge have a look through and see if everything checks out?

Thanks.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37700
Re: Multiple viruses on boot scan
« Reply #1 on: February 16, 2014, 10:26:33 PM »
Quote
Multiple viruses were found including somoto-J and Agent.fxx.
where they detected as PUP ?
PUP = not virus / Possible Unwanted Programs  (also shown in your Malwarebytes log) usually crap that comes bundled with freeware downloads
avast PUP scan is default off...exept for in BootScan

Malware removers are notified and will check your logs .....if they dont reply today, check back tomorrow


« Last Edit: February 16, 2014, 10:28:46 PM by Pondus »

HairLost

  • Guest
Re: Multiple viruses on boot scan
« Reply #2 on: February 16, 2014, 10:29:43 PM »
Somoto-J was defined as PUP but the agent.fxx one was not.

argus

  • Guest
Re: Multiple viruses on boot scan
« Reply #3 on: February 17, 2014, 11:12:21 AM »
Hi,


Re-run OTL.exe.

  • Copy and paste the following text written inside of the quote box into the Custom Scans/Fixes box.

Code: [Select]

:OTL
IE - HKU\S-1-5-21-4284712627-3684625917-91187178-1001\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://www.delta-search.com/?q={searchTerms}&affID=119816&tt=gc_&babsrc=SP_ss&mntrId=7477001CC07EEA62
[2013/05/23 23:04:38 | 000,006,503 | ---- | M] () -- C:\Users\Paul\AppData\Roaming\Mozilla\Firefox\Profiles\26j1np08.default\searchplugins\babylon.xml
[2013/05/23 23:04:54 | 000,001,294 | ---- | M] () -- C:\Users\Paul\AppData\Roaming\Mozilla\Firefox\Profiles\26j1np08.default\searchplugins\delta.xml
CHR - homepage: http://www.delta-search.com/?affID=119816&tt=gc_&babsrc=HP_ss&mntrId=7477001CC07EEA62
O33 - MountPoints2\{c08ecd13-c3f0-11e2-9aed-001cc07eea62}\Shell - "" = AutoRun
O33 - MountPoints2\{c08ecd13-c3f0-11e2-9aed-001cc07eea62}\Shell\AutoRun\command - "" = I:\ALLIANCE.EXE -- [1999/03/02 16:32:04 | 000,598,016 | R--- | M] (LucasArts Entertainment Company LLC)
O33 - MountPoints2\{f6b736eb-d1ae-11e1-8276-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{f6b736eb-d1ae-11e1-8276-806e6f6e6963}\Shell\AutoRun\command - "" = D:\autorun.exe -- [2005/09/16 19:51:12 | 000,999,424 | R--- | M] (Microsoft Corporation)
O33 - MountPoints2\{f6b736eb-d1ae-11e1-8276-806e6f6e6963}\Shell\directx\command - "" = D:\directx9\DXSETUP.exe -- [2005/05/26 22:34:41 | 000,482,000 | R--- | M] (Microsoft Corporation)
O33 - MountPoints2\{f6b736eb-d1ae-11e1-8276-806e6f6e6963}\Shell\setup\command - "" = D:\setup.exe -- [2005/09/19 22:04:52 | 000,253,952 | R--- | M] (Microsoft Game Studios 

:files
C:\$Recycle.Bin\S-1-5-18\$bed9894c2ef6f57584f78c6bce23f8c6

:commands
[CREATERESTOREPOINT]
[emptytemp]


  • Then click the Run Fix button at the top.
  • Let the program run unhindered; it will reboot the system when it is done and open notepad with logreport. Attach here that logreport.
If the log doesn't appear, it can be found here:

c:\_OTL\MovedFiles\mmddyyyy_hhmmss.log
.





**************************






Please download Farbar Recovery Scan Tool () by Farbar and save it to your desktop.

Note: You need to run the version compatibale with your system. If you are not sure which version applies to your system download both of them and try to run them.
Only one of them will run on your system, that will be the right version.


  • Double-click to run it. When the tool opens click Yes to disclaimer.
  • Press Scan button.
  • It will make a log (FRST.txt) in the same directory the tool is run. Please attach it to your reply.
  • The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.

HairLost

  • Guest
Re: Multiple viruses on boot scan
« Reply #4 on: February 17, 2014, 02:56:29 PM »
Scans run and logs attached.


argus

  • Guest
Re: Multiple viruses on boot scan
« Reply #5 on: February 17, 2014, 04:46:50 PM »

1. Open notepad and copy/paste the text present inside the code box below.
To do this highlight the contents of the box and right click on it. Paste this into the open notepad.
NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to the operating system

Code: [Select]
Start
HKLM\...D6A79037F57F\InprocServer32: [Default-fastprox]  ATTENTION! ====> ZeroAccess?
HKU\S-1-5-21-4284712627-3684625917-91187178-1001\...\MountPoints2: {c08ecd13-c3f0-11e2-9aed-001cc07eea62} - I:\alliance.exe
CHR HomePage: hxxp://www.delta-search.com/?affID=119816&tt=gc_&babsrc=HP_ss&mntrId=7477001CC07EEA62
C:\$Recycle.Bin\S-1-5-21-4284712627-3684625917-91187178-1001\$bed9894c2ef6f57584f78c6bce23f8c6
End
2. Save notepad as fixlist.txt to your Desktop.
NOTE: => It's important that both files, FRST and fixlist.txt are in the same location or the fix will not work.


3. Run FRST/FRST64 and press the Fix button just once and wait.
If the tool needed a restart please make sure you let the system to restart normally and let the tool completes its run after restart.

The tool will make a log on the Desktop (Fixlog.txt). Please attach it to your reply.
Note: If the tool warned you about the outdated version please download and run the updated version.

HairLost

  • Guest
Re: Multiple viruses on boot scan
« Reply #6 on: February 17, 2014, 05:00:25 PM »
Tasks followed, log attached.

Thanks

argus

  • Guest
Re: Multiple viruses on boot scan
« Reply #7 on: February 17, 2014, 05:05:38 PM »
Re-run FRST and click scan.

Please attach here log.

HairLost

  • Guest
Re: Multiple viruses on boot scan
« Reply #8 on: February 17, 2014, 05:10:59 PM »
Log attached

argus

  • Guest
Re: Multiple viruses on boot scan
« Reply #9 on: February 17, 2014, 05:15:53 PM »
Please download zoek.zip or zoek.rar by smeenk () from here or here and save it to your Desktop.
Unpack the archive...
  • Close any open browsers
  • Temporarily disable your AntiVirus program. (If necessary)
    If you are unsure how to do this please read this or this Instruction.

  • Double click on zoek.exe to run the tool .
    Please wait while the tool does not start...

  • Copy the text present inside the code box below and paste it into the large window in the zoek tool:
Code: [Select]
filesrcm;
startupall;
skipfix-iedefaults;
firefoxlook;
chromelook;
  • Click on button.
    Please wait until a logreport will open (this can be after reboot)

  • Save notepad to your Desktop and attach here zoek-results.log
    Note: It will also create a log in the C:\ directory named "zoek-results.log"

HairLost

  • Guest
Re: Multiple viruses on boot scan
« Reply #10 on: February 17, 2014, 05:36:44 PM »
Run script. Log attached

argus

  • Guest
Re: Multiple viruses on boot scan
« Reply #11 on: February 17, 2014, 05:43:59 PM »
Posted logs are now appear cleans and show no signs of active infection.

How's your computer behaving now?

HairLost

  • Guest
Re: Multiple viruses on boot scan
« Reply #12 on: February 17, 2014, 05:54:43 PM »
Performance seems to have improved slightly.

Thanks for the help Argus :)

argus

  • Guest
Re: Multiple viruses on boot scan
« Reply #13 on: February 17, 2014, 05:56:53 PM »
Good workman always cleans up after himself.
The following will implement some post-cleanup procedures:

=> Please download DelFix by Xplode to your Desktop.

Run the tool and check the following boxes below;
Remove disinfection tools
Create registry backup
Purge System Restore

Click Run button and wait a few seconds for the programme completes his work.
At this point all the tools we used here should be gone. Tool will create an report for you (C:\DelFix.txt)

The tool will also record healthy state of registry and make a backup using ERUNT program in %windir%\ERUNT\DelFix
Tool deletes old system restore points and create a fresh system restore point after cleaning.



---    ---    ---    ---    ---    ---    ---    ---    ---    ---    ---


To help AntiVirus to protect your computer and speed it up, I recommend that you download, install and keep the following free programs:
1. Keep Malwarebytes Anti-Malware, update it regularly or from time to time and run a Quick Scan weekly.
Malwarebytes will detect and remove all traces of known malware. MBAM isn't AntiVirus and it can NOT replace it.

2. Keep MCShield Anti-Malware, the tool will be updated regularly and perform auto-checking for malware to each attached USB memory device.
MCShield, has been designed as a lightweight scanner that's smart enough to catch even new worms and work in fully automatic removal mode.

3. It’s recommended to delete Temporary Files every once in a while. Run the tool and click on the Start button and TFC will begin to clean. Then restart the computer.
Temp File Cleaner aka TFC by OldTimer
TFC is small & usefull utility that shall clean up temp files from all userprofiles and system folders.


edit.



How to protect yourself?
-  I recommend that you use one of the fantastic opportunities provided by avast! 2014.

1. Adjust avast! to target PUP software:
Run avast! 2014 by clicking the system tray icon in the lower right corner of the screen.
Click on Settings, in the new window that opens, click on Active Protection, then under File System Shield click on gear wheel...
Under Sensitivity part of option check box for Scan for potentialy unwanted programs PUP.


2. avast! Software Updater. Run avast!, click on Tools > Software Updater.
For security reasons, make sure you do update your browser(s), Java, Flash Player, and basically every software you use often.

3. avast! Browser Cleanup.  Run avast!, click on Tools > BrowserCleanup.
Browser Cleanup tool is an integrated tool in avast! AV that allows you the control on browsers unwanted addons.

4. avast! Malware Scan. Run avast!, click on Scan and preform QuickScan by clicking on Start button.
Every once in a whilere, it's recommended to preform virus scan with avast! 2014.

Windows Updates, beeing up to date is very important. Please be sure to activate automatic updates in your control panel.
Widnows XP; Windows Vista; Windows 7 and Windows 8
« Last Edit: February 17, 2014, 05:59:16 PM by argus »

HairLost

  • Guest
Re: Multiple viruses on boot scan
« Reply #14 on: February 17, 2014, 05:59:43 PM »
I manually deleted all disinfection tools after your last post, will I need to use delfix anyway?