Author Topic: Help in cleaning malware needed  (Read 3042 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
Help in cleaning malware needed
« on: January 11, 2018, 01:43:51 PM »
I followed all the steps in "logs to assist in cleaning malware". I attached these logs with this post. What should i do next?
Edit: I kept getting the popup for JS:Agent-EDB [Trj] before i did all the steps.
« Last Edit: January 11, 2018, 02:37:33 PM by aleks1 »

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Help in cleaning malware needed
« Reply #1 on: January 11, 2018, 01:50:29 PM »
What should i do next?
Now you've to wait for one of the malware experts...
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline Sass Drake

  • MyCity AMF R2
  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 820
Re: Help in cleaning malware needed
« Reply #2 on: January 11, 2018, 08:14:51 PM »
  • Open Notepad (click Start button -> type notepad.exe -> press Enter)
  • Copy text from code block below and paste it into Notepad
Code: [Select]
HKU\S-1-5-21-1089142947-2339947531-804550469-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.domaincentar.com
FF Homepage: Mozilla\Firefox\Profiles\08b4usov.default -> hxxp://search.domaincentar.com
FF NewTab: Mozilla\Firefox\Profiles\08b4usov.default -> hxxp://search.domaincentar.com
  • Go to File -> Save As
  • Make sure that  UTF-8 is selected as Encoding (left side of Save button)
  • Save it as fixlist.txt on Desktop
  • Open again FRST and click on button Fix
  • Wait until FRST finishes
  • fixlog.txt should be genereted and opened. Attach it your post and wait further instructions.

REDACTED

  • Guest
Re: Help in cleaning malware needed
« Reply #3 on: January 11, 2018, 09:18:32 PM »
FRST is telling me that the fixlist.txt should be in the same folder/directory the tool is created. So should i move the fixlist.txt file to the Logs folder?

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37533
  • Not a avast user
Re: Help in cleaning malware needed
« Reply #4 on: January 11, 2018, 10:03:54 PM »
FRST.exe and fixlist must be at the sampe place when run, if not FRST will not find it

if you have FRST.exe on your desktop (recomended) then you place fixlist on desktop
if FRST.exe is in your download folder then fixlist must be in your download folder

« Last Edit: January 11, 2018, 10:08:23 PM by Pondus »

REDACTED

  • Guest
Re: Help in cleaning malware needed
« Reply #5 on: January 11, 2018, 10:09:55 PM »
Thanks for clearing that up Pondus. The fixlog.txt is attached now.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37533
  • Not a avast user
Re: Help in cleaning malware needed
« Reply #6 on: January 11, 2018, 10:11:47 PM »
Sass Drake will check it when he is back online ...


Offline Sass Drake

  • MyCity AMF R2
  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 820
Re: Help in cleaning malware needed
« Reply #7 on: January 12, 2018, 12:49:10 AM »
What is the system status now?

REDACTED

  • Guest
Re: Help in cleaning malware needed
« Reply #8 on: January 12, 2018, 06:41:55 AM »
By that u mean is it working fine? It still keeps going to domaincentar.com or usa.bravo but it got blocked.
« Last Edit: January 12, 2018, 06:45:34 AM by aleks1 »

Offline Sass Drake

  • MyCity AMF R2
  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 820
Re: Help in cleaning malware needed
« Reply #9 on: January 12, 2018, 09:52:39 AM »
Can you make screenshot of that? Does redirection to those sites happens everywhere or only on certain websites?

REDACTED

  • Guest
Re: Help in cleaning malware needed
« Reply #10 on: January 12, 2018, 01:06:31 PM »
The redirections happen with firefox only, first when i open it and when i push the home button.The first screenshot is when firefox is first started. Home button redirects to the one shown in screenshot2. The chrome and edge open normally and their home button doesn't redirect somewhere.

REDACTED

  • Guest
Re: Help in cleaning malware needed
« Reply #11 on: January 12, 2018, 01:08:38 PM »
And now the popup started appearing again. Screenshot attached.

Offline Sass Drake

  • MyCity AMF R2
  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 820
Re: Help in cleaning malware needed
« Reply #12 on: January 12, 2018, 05:27:12 PM »
Please post, new FRST. txt and Addition.txt logs.

REDACTED

  • Guest
Re: Help in cleaning malware needed
« Reply #13 on: January 12, 2018, 09:04:36 PM »
Here they are.

Offline Sass Drake

  • MyCity AMF R2
  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 820
Re: Help in cleaning malware needed
« Reply #14 on: January 13, 2018, 02:04:30 AM »
Here we go again.

  • Open Notepad (click Start button -> type notepad.exe -> press Enter)
  • Copy text from code block below and paste it into Notepad
Code: [Select]
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Windows Startup.lnk [2017-07-07]
ShortcutTarget: Windows Startup.lnk -> C:\Windows\Windows_startup.bat ()
Tcpip\..\Interfaces\{d10abc88-f10c-49ed-a057-175822b0e656}: [DhcpNameServer] 85.253.0.130 85.253.0.2
HKU\S-1-5-21-1089142947-2339947531-804550469-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.domaincentar.com
FF Homepage: Mozilla\Firefox\Profiles\08b4usov.default -> hxxp://search.domaincentar.com
FF NewTab: Mozilla\Firefox\Profiles\08b4usov.default -> hxxp://search.domaincentar.com
  • Go to File -> Save As
  • Make sure that  UTF-8 is selected as Encoding (left side of Save button)
  • Save it as fixlist.txt on Desktop
  • Open again FRST and click on button Fix
  • Wait until FRST finishes
  • fixlog.txt should be genereted and opened. Attach it your post and wait further instructions.