Author Topic: PC denies all access to flashdrive "Specified Module cannot be found"  (Read 2676 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
I can't access my flash drive, probably from a virus, I checked the properties of the USB (trancent 8gb) I notice that the TARGET goes to "C:\Windows\system32\cmd.exe /c start rundll32  \caceeacceeeaeaeeaeceeccaaceaccceecacacaeeaaaaaeeaeccccaaaee.caceeacceeeaeaeeaeceeccaaceaccceecacacaeeaaaaaeeaeccccaaaee,IKuqmGuumaSOCqiG"

another usb's target is C:\Windows\system32\cmd.exe /c start rundll32  \(followed by another random long letters)

I can't change it even under administrator. please Help.

I already scan it with
AdwCleaner
Gmer
Farbar Recovery Scan Tool

here are the logs
I don't know what to do with them.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37582
  • Not a avast user
Malware expert is notified, check back tomorrow


see instructions here  >>  https://forum.avast.com/index.php?topic=194892.0
Scroll down to SPECIFIC INFECTIONS LOGS
Follow MCShield instructions. This log you copy paste here




REDACTED

  • Guest
Thank you very much Pondus! I think Mcshield did the trick. You are very helpful sir!

here the log

>>> MCShield AllScans.txt <<<

-----------------------------




MCShield ::Anti-Malware Tool:: http://www.mcshield.net/

>>> v 3.0.5.28 / DB: 2016.2.21.1 / Windows 7 <<<


7/13/2017 2:20:33 AM > Drive C: - scan started (no label ~466 GB, NTFS HDD )...



=> The drive is clean.


7/13/2017 2:20:33 AM > Drive E: - scan started (Transcend ~7444 MB, FAT32 flash drive )...


>>> E:\Transcend (8GB).lnk - Suspicious > Renamed. (MD5: 718bb6826e2f8bca0755ab0a11e90469)

> Resetting attributes: E:\  < Successful.


=> Suspicious files  : 1/1 renamed.
=> Hidden folders    : 1/1 unhidden.

____________________________________________

::::: Scan duration: 2sec ::::::::::::::::::
____________________________________________




MCShield ::Anti-Malware Tool:: http://www.mcshield.net/

>>> v 3.0.5.28 / DB: 2016.2.21.1 / Windows 7 <<<


7/13/2017 2:21:42 AM > Drive E: - scan started (Transcend ~7444 MB, FAT32 flash drive )...



=> The drive is clean.






Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37582
  • Not a avast user
Quote
Thank you very much Pondus! I think Mcshield did the trick. You are very helpful sir!
OK

Malware expert will check FRST logs when he is online tomorrow, so check back for result


Offline dbrisendine

  • Malware Fighter
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1258

FIRST >>>>

Fix with Farbar Recovery Scan Tool
This fix was created for this user for use on that particular machine.
Running it on another one may cause damage and render the system unstable.
Download attached fixlist.txt file and save it to the Desktop:

Both files, FRST and fixlist.txt have to be in the same location or the fix will not work!

  • Right-click on icon and select Run as Administrator to start the tool.
    (XP users click run after receipt of Windows Security Warning - Open File).
  • Press the Fix button just once and wait.
  • If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
  • When finished FRST will generate a log on the Desktop, called Fixlog.txt.
Please attach it to your reply.


SECOND >>>>

AdwCleaner by Xplode

Download AdwCleaner from here or from here. Save the file to the desktop.


NOTE: If you are using IE 8 or above you may get a warning that stops the program from downloading. Just click on the warning and allow the download to complete.

Close all open windows and browsers.

  • Vista/7/8 users: Right click the AdwCleaner icon on the desktop, click Run as administrator and accept the UAC prompt to run AdwCleaner.
    You will see the following console:
  • Click the Scan button and wait for the scan to finish.
  • After the Scan has finished the window may or may not show what it found and above, in the progress bar, you will see: Waiting for action. Please uncheck elements you don't want to remove.
  • Click the Clean button.
  • Everything checked will be deleted.
  • When the program has finished cleaning a report appears.
  • Once done it may ask to reboot, allow this

  • On reboot a log will be produced; please attach that in your next reply. This report is also saved to C:\AdwCleaner\AdwCleaner[C0].txt

    Optional:

    NOTE: If you see AVG Secure Search being targeted for deletion, Here's Why and Here. You can always Reinstall it.
Win7 x32 Ult. SP1, Brain 2.0 / Win10 x64, Brain2.5
My help is always free but if you would like to help encourage me or show your thanks -----> DONATE

REDACTED

  • Guest
Sorry I was busy this last few days, thank you very much sir for helping me. here's the logs.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37582
  • Not a avast user
Quote
RecycleBin => 20403274850 B
EmptyTemp: => 20.7 GB temporary data Removed.
Woow   ???

How is your computer now?


@dbrisendine will be back online tomorrow


Offline dbrisendine

  • Malware Fighter
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1258
Appearently Google is now the only one who can clean Chrome.  Chrome Cleanup tool ==>> https://www.google.com/chrome/cleanup-tool/  Please download this tool and run it to finish cleaning Chrome.

How is the system running now.
Win7 x32 Ult. SP1, Brain 2.0 / Win10 x64, Brain2.5
My help is always free but if you would like to help encourage me or show your thanks -----> DONATE