Author Topic: Short cut virus  (Read 2672 times)

0 Members and 2 Guests are viewing this topic.

REDACTED

  • Guest
Short cut virus
« on: August 02, 2014, 03:39:43 PM »
Hello,
My laptop is infected with this shortcut forming virus. Each time I insert a pen drive, it changes the files into shortcuts. I want to remove this virus permanently from my system.
Please help.

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31072
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: Short cut virus
« Reply #1 on: August 02, 2014, 03:41:28 PM »
Follow the instructions and ATTACH the logs to your next post:
https://forum.avast.com/index.php?topic=53253.0

Offline TwinHeadedEagle

  • Malware Removal Expert
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 2987
    • Zemana
Re: Short cut virus
« Reply #2 on: August 02, 2014, 03:46:10 PM »
Monitoring...
My help is free, however if you'd like to show your appreciation by leaving a donation, it will be much appreciated ------> DONATE

REDACTED

  • Guest
Re: Short cut virus
« Reply #3 on: August 02, 2014, 04:28:24 PM »
Thanks for the prompt reply.
Attached below are the log files generated from various scans

Offline TwinHeadedEagle

  • Malware Removal Expert
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 2987
    • Zemana
Re: Short cut virus
« Reply #4 on: August 02, 2014, 04:35:35 PM »
Hello,

You still need to attach Addition.txt report.
My help is free, however if you'd like to show your appreciation by leaving a donation, it will be much appreciated ------> DONATE

REDACTED

  • Guest
Re: Short cut virus
« Reply #5 on: August 02, 2014, 04:44:54 PM »
hello sir,
here is the addition.txt file attached

Offline TwinHeadedEagle

  • Malware Removal Expert
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 2987
    • Zemana
Re: Short cut virus
« Reply #6 on: August 02, 2014, 04:55:31 PM »
Please disconnect all USB drives from your PC and do not use them until I tell you.

Did you set proxy server?



Fix with Farbar Recovery Scan Tool

This fix was created for this user for use on that particular machine.
Running it on another one may cause damage and render the system unstable.

Download attached fixlist.txt file and save it to the Desktop:

Both files, FRST and fixlist.txt have to be in the same location or the fix will not work!

  • Right-click on icon and select Run as Administrator to start the tool.
    (XP users click run after receipt of Windows Security Warning - Open File).
  • Press the Fix button just once and wait.
  • If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
  • When finished FRST will generate a log on the Desktop, called Fixlog.txt.
Please attach it to your reply.



Please download MCShield from one of the following links:

MCShield -Official download link
  • Double click on MCShield-Setup to install the application.
    Next => I Agree => Next => Install ... per installation click on Run! button.
  • Wait a few seconds to MCShield finish initial HDD scan...
  • Connect all your USB storage devices to the computer one at a time. Scanning will be done automatically.
  • When all scanning is done, you need to post a logreport that MCShield has created.
Under Logs tab (in Control Center) for AllScans.txt log section click on Save button. AllScanst.txt report shall be located on your Desktop.

=> Post here AllScanst.txt


Explanation: USB storage devices are all the USB devices that get their own partition letter at connecting to the PC,
e.g. flash drives (thumb/pen drives, USB sticks), external HDDs, MP3/MP4 players, digital cameras,
memory cards (SD cards, Sony Memory Stick, MultiMedia Cards etc.), some mobile phones, some GPS navigation devices etc.
My help is free, however if you'd like to show your appreciation by leaving a donation, it will be much appreciated ------> DONATE

REDACTED

  • Guest
Re: Short cut virus
« Reply #7 on: August 02, 2014, 05:15:29 PM »
Sir,
Yes, I am using a proxy server. Attached below are the reports.

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31072
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: Short cut virus
« Reply #8 on: August 02, 2014, 05:20:27 PM »
TwinHeadedEagle,

the proxy IP is a local IP.
unless there is a very specific reason, it should not be used other than e.g. connecting to a local network or software like BOINC.

Edit:
port 8080 = HTTP Alternate (see port 80) : RingZero : Brow Orrifice : RemoteConChuba : Revers WWW Tunnel Backdoor
« Last Edit: August 02, 2014, 05:25:27 PM by Eddy »

Offline TwinHeadedEagle

  • Malware Removal Expert
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 2987
    • Zemana
Re: Short cut virus
« Reply #9 on: August 02, 2014, 05:46:40 PM »
Can you upload AllScans.txt here and attach download link

http://zippyshare.com/
My help is free, however if you'd like to show your appreciation by leaving a donation, it will be much appreciated ------> DONATE