Author Topic: Virus/Malware/PUP and other good stuff...need help again.  (Read 14100 times)

0 Members and 1 Guest are viewing this topic.

Offline avastpandainc

  • Jr. Member
  • **
  • Posts: 35
Hello Avast community,
I seek your help again.
I am following the following instructions:
https://forum.avast.com/index.php?topic=53253.0

These darn annoying pop ups, leading to slow running PC.

Here attached are the following files:


Thanks in advance to the Malware Analyst that will be helping out this issue.
avastpandainc.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Virus/Malware/PUP and other good stuff...need help again.
« Reply #1 on: May 30, 2016, 09:12:05 PM »
Could you let me know what problems remain after this

CAUTION : This fix is only valid for this specific machine, using it on another may break your computer

Open notepad and copy/paste the text in the quotebox below into it:
 
Quote
CreateRestorePoint:
S2 BrowseForTheCause; "C:\Program Files (x86)\BrowseForTheCause\BrowseForTheCause.exe" [X]
R2 PrivoxyService; C:\Program Files (x86)\Techsmart Computer\privoxy.exe [371200 2016-05-19] (The Privoxy team - www.privoxy.org) [File not signed] <==== ATTENTION
C:\Program Files (x86)\Techsmart Computer
C:\Program Files (x86)\BrowseForTheCause
Reg: reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
Reg: reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
RemoveProxy:
EmptyTemp:
CMD: bitsadmin /reset /allusers

Save this as fixlist.txt, in the same location as FRST.exe

Run FRST and press Fix
On completion a log will be generated please post that

THEN

Please download AdwCleaner by Xplode onto your Desktop.
  • Close all open programs and internet browsers.[/*]
  • Double click on AdwCleaner.exe to run the tool.[/*]
  • Click the Scan button and wait for the process to complete.[/*]
  • Click the logfile button and the log will open in Notepad.[/*]
  • Click on the Clean button follow the prompts.[/*]
  • A log file will automatically open after the scan has finished and the PC has rebooted.[/*]
  • Please post the content of that log file with your next answer.[/*]
  • The report will be saved in the C:\AdwCleaner folder.

Offline avastpandainc

  • Jr. Member
  • **
  • Posts: 35
Re: Virus/Malware/PUP and other good stuff...need help again.
« Reply #2 on: May 31, 2016, 12:24:09 AM »
Thank you for your prompt reply,
here is the log after fixlist was generated: FixLog


Offline avastpandainc

  • Jr. Member
  • **
  • Posts: 35
Re: Virus/Malware/PUP and other good stuff...need help again.
« Reply #3 on: May 31, 2016, 02:06:02 PM »
here is the log after running adwcleaner_5.119:

I am going to predict that all is well now?


Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Virus/Malware/PUP and other good stuff...need help again.
« Reply #4 on: May 31, 2016, 03:41:05 PM »
Hmm privoxy does not appear to want to go

Could you run MBAM again please

Offline avastpandainc

  • Jr. Member
  • **
  • Posts: 35
Re: Virus/Malware/PUP and other good stuff...need help again.
« Reply #5 on: May 31, 2016, 04:54:27 PM »
Hi essexboy,
here are the four files from today's run.

The error could have been due to the fact that my first run of  FRST64, I did not (right click) and run as administrator.

thanks.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Virus/Malware/PUP and other good stuff...need help again.
« Reply #6 on: May 31, 2016, 06:43:45 PM »
Looks OK any problems ?

Offline avastpandainc

  • Jr. Member
  • **
  • Posts: 35
Re: Virus/Malware/PUP and other good stuff...need help again.
« Reply #7 on: May 31, 2016, 06:57:49 PM »
Honestly, it felt OK, even before the second run of MBAM.

Do you still want to proceed with a new fixlist.txt? (and subsequently adwcleaner)

Or should we conclude with Delfix?

I am content with the behaviour of this laptop after your help..

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Virus/Malware/PUP and other good stuff...need help again.
« Reply #8 on: May 31, 2016, 09:48:03 PM »
Nope tidy up as it looks clean


Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Virus/Malware/PUP and other good stuff...need help again.
« Reply #10 on: June 02, 2016, 03:25:58 PM »
What browser did they appear in Chrome ?

Offline avastpandainc

  • Jr. Member
  • **
  • Posts: 35
Re: Virus/Malware/PUP and other good stuff...need help again.
« Reply #11 on: June 02, 2016, 03:45:08 PM »
Yes, you are correct, Google Chrome browser
Here are the four files:

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Virus/Malware/PUP and other good stuff...need help again.
« Reply #12 on: June 02, 2016, 07:22:23 PM »
Personally I would get rid of Chrome as it is now becoming a risk

CAUTION : This fix is only valid for this specific machine, using it on another may break your computer

Open notepad and copy/paste the text in the quotebox below into it:
 
Quote
CreateRestorePoint:
CHR Extension: (04a647e8892acb00f8fea02167c03aff) - C:\Program Files (x86)\Google\Chrome\Application\04a647e8892acb00f8fea02167c03aff [2016-02-24]
CHR Extension: (04a647e8892acb00f8fea02167c03aff_2) - C:\Program Files (x86)\Google\Chrome\Application\04a647e8892acb00f8fea02167c03aff_2 [2016-06-01]
Reg: reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
Reg: reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
RemoveProxy:
EmptyTemp:
CMD: bitsadmin /reset /allusers

Save this as fixlist.txt, in the same location as FRST.exe

Run FRST and press Fix
On completion a log will be generated please post that

Offline avastpandainc

  • Jr. Member
  • **
  • Posts: 35
Re: Virus/Malware/PUP and other good stuff...need help again.
« Reply #13 on: June 02, 2016, 07:47:06 PM »
I do not have a good feeling with this fixlog.
As soon as this laptop rebooted, and I was logging on to this forum, it generated a pop-up/another page.
We use Chrome on three different devices.
If the solution is to curb our browser usage, then we will go that route as suggested.

Thank you.


Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Virus/Malware/PUP and other good stuff...need help again.
« Reply #14 on: June 02, 2016, 10:16:42 PM »
First off confirm as to whether this occurs in other browsers ..

If not then run Chrome in incognito mode, does that stop it  https://support.google.com/chrome/answer/95464?hl=en-GB

Let me know the result