Author Topic: New Virus/malware found  (Read 5215 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
Re: New Virus/malware found
« Reply #15 on: October 05, 2017, 05:25:58 PM »
here is the fixlog.txt you requested

Offline Sass Drake

  • MyCity AMF R2
  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 820
Re: New Virus/malware found
« Reply #16 on: October 06, 2017, 07:01:13 PM »
File seems to be clean according to VirusTotal result but follow Pondus isntruction  for uploading suspicious files to Avast.
https://forum.avast.com/index.php?topic=14433.msg1289438#msg1289438

REDACTED

  • Guest
Re: New Virus/malware found
« Reply #17 on: October 06, 2017, 08:38:40 PM »
File seems to be clean according to VirusTotal result but follow Pondus isntruction  for uploading suspicious files to Avast.
https://forum.avast.com/index.php?topic=14433.msg1289438#msg1289438

Thanks for the help. I have more info for you. I booted into safe mode and was then able to delete the sneiukpsvc.exe file as well as the c:\program files\mbcdhze directory. That directory appears after rebooting and is empty. Looking at the same directory a few minutes later it was full of dll's and other files as well as a LOCALE directory. Inside that directory are 2 language file dirs....us-en and zh-cn. I am not positive but I think zh-cn is a chinese language file. Seems odd that ONLY those 2 language files are there. Makes me think this is originally from China. Unfortunately, after rebooting from safe mode, the sneiukpsvc.exe and the mbcdhze have returned. My system seems fine after reboot but as time goes by I notice it slowing down. There are moments of total freeze, nothing crashes, everything freezes for a short time then back to normal. I have also noticed that programs that were running after reboot (i.e. checked my email with Thunderbird, firing up AVG PC Tuneup) will not start up. The task for that program is in the task manager but clicking on it gives a window saying the operation could not be completed. access denied. Since I am administrator (and the only one that uses this pc) it looks like this issue has changed my access as well. The only way I can start a program at that point is to reboot my system.

Anyway, I will follow the instructions to upload the suspect file as soon as I can. thanks again

REDACTED

  • Guest
Re: New Virus/malware found
« Reply #18 on: October 06, 2017, 08:49:57 PM »
File seems to be clean according to VirusTotal result but follow Pondus isntruction  for uploading suspicious files to Avast.
https://forum.avast.com/index.php?topic=14433.msg1289438#msg1289438


Need more help. I went to the thread you posted, found the submit a file section, click the BROWSE button, but when I surf to the location of the file, it is not listed. If I surf to the same directory going through my Computer/Program files the file is listed there. I have my system set to see hidden files. So how do I upload the alleged infected file? I also use Windows Commander (file manager application) and have that set to see hidden files but it also does not see this file. Can I drag & drop the file to your upload page? I can copy the suspect file to another firectory and upload that but I would think that is probably not a good idea. Please advise.

REDACTED

  • Guest
Re: New Virus/malware found
« Reply #19 on: October 06, 2017, 08:58:59 PM »
File seems to be clean according to VirusTotal result but follow Pondus isntruction  for uploading suspicious files to Avast.
https://forum.avast.com/index.php?topic=14433.msg1289438#msg1289438

Tried to upload infect file but had issues. See previous post. I did upload the file but it was the copied file so hopefully that will be ok. If not, I will need halp.

Offline Sass Drake

  • MyCity AMF R2
  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 820
Re: New Virus/malware found
« Reply #20 on: October 07, 2017, 12:53:08 AM »
Scan your PC with this:

http://media.kaspersky.com/utilities/VirusUtilities/EN/tdsskiller.exe

and attach C:\TDSSKiller_*.txt to your post.

REDACTED

  • Guest
Re: New Virus/malware found
« Reply #21 on: October 07, 2017, 05:03:16 PM »
Scan your PC with this:

http://media.kaspersky.com/utilities/VirusUtilities/EN/tdsskiller.exe

and attach C:\TDSSKiller_*.txt to your post.

I have downloaded the tdsskiller you suggested and all that happens when I click it is I get the run dialog. I click yes and nothing happens. I have search the directory the file ran from as well as looked for a c:\tdsskiller.txt you requested and cannot find it.

Offline Sass Drake

  • MyCity AMF R2
  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 820
Re: New Virus/malware found
« Reply #22 on: October 07, 2017, 10:04:25 PM »
Try running TDSSKiller in Safe Mode.

REDACTED

  • Guest
Re: New Virus/malware found
« Reply #23 on: October 08, 2017, 07:19:30 PM »
Try running TDSSKiller in Safe Mode.

Same results in safe mode as in normal mode.....2click the file, hour glass comes up for a second and disappears and doesn't run. I think it is time to format and reinstall. Besides, isn't Kaspersky part of the russian spyware or something liek that I keep hearing on the news.

Offline Sass Drake

  • MyCity AMF R2
  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 820
Re: New Virus/malware found
« Reply #24 on: October 08, 2017, 07:57:18 PM »
Try running TDSSKiller in Safe Mode.

Same results in safe mode as in normal mode.....2click the file, hour glass comes up for a second and disappears and doesn't run. I think it is time to format and reinstall. Besides, isn't Kaspersky part of the russian spyware or something liek that I keep hearing on the news.

Kaspersky is part of Russian spyware on the same level as Windows 10, Android and iOS are part of USA spyware.   ;D
Joke aside, FRST logs aren't showing traces of malware but you can also check your PC with:
- Emsisoft Emergency Kit : https://www.emsisoft.com/en/software/eek/
- Kaspersky Virus Removal Tool:  http://devbuilds.kaspersky-labs.com/devbuilds/KVRT/latest/full/KVRT.exe