Author Topic: Infection:Filerepmalware  (Read 29507 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
Infection:Filerepmalware
« on: November 11, 2014, 09:06:21 PM »
Hello!

My Avast pop-up is consistently reporting multiple Windows key files as malware, most notably; Rundll32.exe/scvhost.exe, WWAhost.exe and Agent.exe (Not a Windows file, but a battle.net installer)

Once opening Task manager, no suspicious programs appear open, however the system task(Ntoskrnl.exe) uses 100% disk majority of the time, running a Mbam scan revealed no virus's, and Avast scans also yielded no results.



I've used Virustotal to scan these files, no threat was reported; are these false positives?

Thank you.

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31079
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: Infection:Filerepmalware
« Reply #1 on: November 11, 2014, 09:07:50 PM »

REDACTED

  • Guest
Re: Infection:Filerepmalware
« Reply #2 on: November 11, 2014, 10:04:30 PM »
http://pastebin.com/BdzMsyvb    Addition.txt
http://pastebin.com/AvnBesPX     FRST.txt
http://pastebin.com/6MT8Sk7j     aswMBR.txt


---Mbam No results----
« Last Edit: November 11, 2014, 10:06:13 PM by Isisariey »

REDACTED

  • Guest
Re: Infection:Filerepmalware
« Reply #3 on: November 11, 2014, 10:19:14 PM »
Now it's reporting Svchost.exe at every CMD.exe command.

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31079
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: Infection:Filerepmalware
« Reply #4 on: November 11, 2014, 11:14:33 PM »
Isisariey, the instructions clearly say to attach the log files here.

REDACTED

  • Guest
Re: Infection:Filerepmalware
« Reply #5 on: November 11, 2014, 11:30:52 PM »
Its not letting me attach them, or else I would; I cannot see any problem with using a pastebin.

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31079
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: Infection:Filerepmalware
« Reply #6 on: November 11, 2014, 11:38:11 PM »
Just click on " Attachments and other options"

REDACTED

  • Guest
Re: Infection:Filerepmalware
« Reply #7 on: November 12, 2014, 09:14:47 AM »
Attached.
« Last Edit: November 12, 2014, 05:44:50 PM by Isisariey »

REDACTED

  • Guest
Re: Infection:Filerepmalware
« Reply #8 on: November 12, 2014, 02:58:01 PM »
hi  I'm having this same problem
my system is a gateway nv59c laptop running windows ten preview build 9860
 

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: Infection:Filerepmalware
« Reply #9 on: November 12, 2014, 03:06:35 PM »
hi  I'm having this same problem
my system is a gateway nv59c laptop running windows ten preview build 9860
 

1) Start your own thread.
2) Why did you install Windows 10 Tech Preview as your main OS? I found the beta to be extremely unstable, and they even tell you NOT to install it as a main OS. I tried a dualboot. Mind you, it failed, but, Windows 10 belongs in a Virtual Machine until formally released to the public as Finished and not Beta.
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Infection:Filerepmalware
« Reply #10 on: November 12, 2014, 04:35:07 PM »
Could you let me know if this stops the alerts

CAUTION :  This fix is only valid for this specific machine, using it on another may break your computer

Open notepad and copy/paste the text in the quotebox below into it:
 
Quote
HKLM-x32\...\RunOnce: [wextract_cleanup0] => rundll32.exe C:\WINDOWS\system32\advpack.dll,DelNodeRunDLL32 "C:\Users\Joey\AppData\Local\Temp\IXP000.TMP\"
HKLM-x32\...\RunOnce: [wextract_cleanup1] => rundll32.exe C:\WINDOWS\system32\advpack.dll,DelNodeRunDLL32 "C:\Users\Joey\AppData\Local\Temp\IXP001.TMP\"
HKLM-x32\...\RunOnce: [wextract_cleanup2] => rundll32.exe C:\WINDOWS\system32\advpack.dll,DelNodeRunDLL32 "C:\Users\Joey\AppData\Local\Temp\IXP002.TMP\"
C:\Users\Joey\jagex_cl_runescape_LIVE.dat
C:\Users\Joey\random.dat
EmptyTemp:
CMD: bitsadmin /reset /allusers

 
Save this as fixlist.txt, in the same location as FRST.exe
Run FRST and press Fix
On completion a log will be generated please post that

REDACTED

  • Guest
Re: Infection:Filerepmalware
« Reply #11 on: November 12, 2014, 05:51:56 PM »
Attached.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Infection:Filerepmalware
« Reply #12 on: November 12, 2014, 06:21:00 PM »
Are you still getting the alerts ?

If so :

Download and Install Combofix
 
Download ComboFix from one of the following locations:
Link 1
Link 2
 
VERY IMPORTANT !!! Save ComboFix.exe to your Desktop
 
* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
  • Accept the disclaimer and allow to update if it asks




  • When finished, it shall produce a log for you.
  • Please include the C:\ComboFix.txt in your next reply.[/b]
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.

3.  If after the reboot you get errors about programmes being marked for deletion then reboot, that will cure it.


Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now

REDACTED

  • Guest
Re: Infection:Filerepmalware
« Reply #13 on: November 12, 2014, 06:22:43 PM »
The alerts have stopped, I will repost here if they happen again? Or create a new thread?

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Infection:Filerepmalware
« Reply #14 on: November 12, 2014, 06:25:12 PM »
No just let me know when you are happy and I will tidy up