Author Topic: Problem with BProtect-D - external help needed  (Read 3760 times)

0 Members and 1 Guest are viewing this topic.

Tibbles

  • Guest
Problem with BProtect-D - external help needed
« on: April 16, 2014, 01:50:43 AM »
So I decided to perform a routine C: scan with Avast free, and it turns out it found two malicious files described as Win32:BProtect-D [Trj]:
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HA9PC1V5\pack[1].7z|>bprotect.exe
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HA9PC1V5\pack[1].7z|>protector.dll
I tried fixing them, then putting them under quarantine, then deleting them, but nothing worked, so I decided to start a topic here. I already used Malwarebytes' Anti-Malware as advised here: http://forum.avast.com/index.php?topic=53253.0 but from what I've understood, you don't use another program until after you post a log file and get a reply, so for now I'm just including the results of scanning with this one program. If anything more is needed just inform me. Thanks in advance for any help.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37534
  • Not a avast user
Re: Problem with BProtect-D - external help needed
« Reply #1 on: April 16, 2014, 02:03:42 AM »
Quote
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HA9PC1V5\pack[1].7z|>bprotect.exe
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HA9PC1V5\pack[1].7z|>protector.dll
Located in temp folders....

does this help.......or do they come back?
run TFC cleaner by OldTimer   http://www.geekstogo.com/forum/files/file/187-tfc-temp-file-cleaner-by-oldtimer/

from the guide you first used, run and attach OTL diagnostic log, a malware expert will check it when online

malware experts are in bed now so dont expect any reply until tomorrow   ;)





« Last Edit: April 16, 2014, 12:53:08 PM by Pondus »

Offline TwinHeadedEagle

  • Malware Removal Expert
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 2987
    • Zemana
Re: Problem with BProtect-D - external help needed
« Reply #2 on: April 16, 2014, 09:03:04 AM »
Hi,



Please download zoek.zip or zoek.rar by smeenk () from here or here and save it to your Desktop.
Unpack the archive...
  • Close any open browsers
  • Temporarily disable your AntiVirus program. (If necessary)
    If you are unsure how to do this please read this or this Instruction.

  • Double click on zoek.exe to run the tool .
    Please wait for the tool to start...

  • Copy the text present inside the code box below and paste it into the large window in the zoek tool:
Code: [Select]
createsrpoint;
gpt.ini;z
C:\Windows\System32\GroupPolicy;v
C:\Windows\SysWOW64\GroupPolicy;v
StandardSearch;
emptyfolderscheck;
installer-list;
installedprogs;
uninstall-list;
  • Click on button.
    Please wait until a logreport will open (this can be after reboot)

  • Save notepad to your Desktop and attach here zoek-results.log
    Note: It will also create a log in the C:\ directory named "zoek-results.log"
My help is free, however if you'd like to show your appreciation by leaving a donation, it will be much appreciated ------> DONATE

Tibbles

  • Guest
Re: Problem with BProtect-D - external help needed
« Reply #3 on: April 16, 2014, 08:07:29 PM »
Thank you so much for all the help so far, here's the log file:

Offline TwinHeadedEagle

  • Malware Removal Expert
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 2987
    • Zemana
Re: Problem with BProtect-D - external help needed
« Reply #4 on: April 16, 2014, 08:32:23 PM »
> Re-run zoek with the script below and attach here fresh zoek log results.
NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to the operating system


Code: [Select]
emptyalltemp;
emptyclsid;
autoclean;
ipconfig /flushdns;b
emptyfolderscheck;delete



Please download Farbar Recovery Scan Tool by Farbar and save it to your desktop.

Note: You need to run the version compatibale with your system. If you are not sure which version applies to your system download both of them and try to run them.
Only one of them will run on your system, that will be the right version.


  • Double-click to run it. When the tool opens click Yes to disclaimer.
  • Under Optional Scan ensure "List BCD" and "Driver MD5" are ticked.
  • Press Scan button.
  • It will make a log (FRST.txt) in the same directory the tool is run. Please attach it to your reply.
  • The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.
My help is free, however if you'd like to show your appreciation by leaving a donation, it will be much appreciated ------> DONATE

Tibbles

  • Guest
Re: Problem with BProtect-D - external help needed
« Reply #5 on: April 16, 2014, 10:33:35 PM »
I accidentally forgot to close Firefox before running the scan :-[ Do I have to run it again? Can I use the same script from above or do I need a new one this time? Or is this one okay? I'm so sorry...
« Last Edit: April 17, 2014, 12:54:35 AM by Tibbles »

Offline TwinHeadedEagle

  • Malware Removal Expert
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 2987
    • Zemana
Re: Problem with BProtect-D - external help needed
« Reply #6 on: April 17, 2014, 08:08:26 AM »
Doesn't matter. Procede with Farbar.
My help is free, however if you'd like to show your appreciation by leaving a donation, it will be much appreciated ------> DONATE

Tibbles

  • Guest
Re: Problem with BProtect-D - external help needed
« Reply #7 on: April 17, 2014, 07:16:35 PM »
Done :)

Offline TwinHeadedEagle

  • Malware Removal Expert
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 2987
    • Zemana
Re: Problem with BProtect-D - external help needed
« Reply #8 on: April 17, 2014, 09:51:08 PM »
Download attached fixlist.txt to your Desktop.
NOTE: => It's important that both files, FRST and fixlist.txt are in the same location or the fix will not work.


Run FRST/FRST64 and press the Fix button just once and wait.
If the tool needed a restart please make sure you let the system to restart normally and let the tool completes its run after restart.

The tool will make a log on the Desktop (Fixlog.txt). Please attach it to your reply.
Note: If the tool warned you about the outdated version please download and run the updated version.
My help is free, however if you'd like to show your appreciation by leaving a donation, it will be much appreciated ------> DONATE

Tibbles

  • Guest
Re: Problem with BProtect-D - external help needed
« Reply #9 on: April 18, 2014, 03:32:37 AM »
Okay, it's done:

Offline TwinHeadedEagle

  • Malware Removal Expert
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 2987
    • Zemana
Re: Problem with BProtect-D - external help needed
« Reply #10 on: April 18, 2014, 09:39:08 AM »
PC seems clean, how is the situation now?
My help is free, however if you'd like to show your appreciation by leaving a donation, it will be much appreciated ------> DONATE

Tibbles

  • Guest
Re: Problem with BProtect-D - external help needed
« Reply #11 on: April 19, 2014, 04:26:53 AM »
No more problems detected after latest scanning with both Avast and Malwarebytes, thank you so much for help, God bless.

Offline TwinHeadedEagle

  • Malware Removal Expert
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 2987
    • Zemana
Re: Problem with BProtect-D - external help needed
« Reply #12 on: April 21, 2014, 01:17:12 AM »
Very good :)


The following will implement some post-cleanup procedures:

=> Please download DelFix by Xplode to your Desktop.

Run the tool and check the following boxes below;
Remove disinfection tools
Create registry backup
Purge System Restore

Click Run button and wait a few seconds for the programme completes his work.
At this point all the tools we used here should be gone. Tool will create an report for you (C:\DelFix.txt)

The tool will also record healthy state of registry and make a backup using ERUNT program in %windir%\ERUNT\DelFix
Tool deletes old system restore points and create a fresh system restore point after cleaning.
My help is free, however if you'd like to show your appreciation by leaving a donation, it will be much appreciated ------> DONATE