Author Topic: virus problem on thumb drive  (Read 4739 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
virus problem on thumb drive
« on: January 26, 2018, 02:24:02 AM »
hope this can be help. my thumb drive won't open and there is a pop up saying G:\>start /d ".\System Volume Information\Kaspersky Internet Security 2017" taskhosts.exe

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user
Re: virus problem on thumb drive
« Reply #1 on: January 26, 2018, 08:30:17 AM »
See here   https://forum.avast.com/index.php?topic=194892.0

Scroll all the way down to Specific Infection Logs ... follow instructions for MCShield

This log you copy and paste here ... not attach ( only MCSield logs)

« Last Edit: February 05, 2018, 03:28:57 PM by Pondus »

Offline Sass Drake

  • MyCity AMF R2
  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 820
Re: virus problem on thumb drive
« Reply #2 on: January 26, 2018, 11:26:53 AM »
Do not plug thumb drive until you install MCShield but first do this.

  • Open Notepad (click Start button -> type notepad.exe -> press Enter)
  • Copy text from code block below and paste it into Notepad
Code: [Select]
VirusTotal: C:\Users\User\AppData\Roaming\Kaspersky Internet Security 2017\spoolsvc.exe;C:\Users\User\AppData\Local\Temp\jow2dzfa.dll
Startup: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\spoolsvc.lnk [2017-12-04]
ShortcutTarget: spoolsvc.lnk -> C:\Users\User\AppData\Roaming\Kaspersky Internet Security 2017\spoolsvc.exe (No File)
Task: {DEB54F2F-08A7-4B1C-B63C-7C4845FA1934} - System32\Tasks\App Explorer => C:\Users\User\AppData\Local\Host App Service\Engine\HostAppServiceUpdater.exe [2017-12-22] (SweetLabs, Inc) <==== ATTENTION
HKU\S-1-5-21-176347147-2586957089-2691104427-1001\...\MountPoints2: {2ae92697-92cb-11e7-8180-ccb0dad6d454} - "G:\AutoRun.exe"
HKU\S-1-5-21-176347147-2586957089-2691104427-1001\...\MountPoints2: {5dc65b0b-3086-11e7-8029-ccb0dad6d454} - "F:\AutoRun.exe"
HKU\S-1-5-21-176347147-2586957089-2691104427-1001\...\MountPoints2: {68be13b2-14f3-11e7-bfbc-ccb0dad6d454} - "F:\StartUse.exe"
HKU\S-1-5-21-176347147-2586957089-2691104427-1001\...\MountPoints2: {ce574921-2505-11e7-bff5-ccb0dad6d454} - "F:\Setup.exe" /s
  • Go to File -> Save As
  • Make sure that  UTF-8 is selected as Encoding (left side of Save button)
  • Save it as fixlist.txt on Desktop
  • Open again FRST and click on button Fix
  • Wait until FRST finishes
  • fixlog.txt should be genereted and opened. Attach it your post and wait further instructions.
« Last Edit: January 26, 2018, 11:32:38 AM by Sass Drake »

REDACTED

  • Guest
Re: virus problem on thumb drive
« Reply #3 on: January 29, 2018, 08:52:14 AM »
Fix result of Farbar Recovery Scan Tool (x64) Version: 27.01.2018
Ran by User (29-01-2018 15:48:53) Run:1
Running from D:\Users\Desktop
Loaded Profiles: User (Available Profiles: User)
Boot Mode: Normal
==============================================

fixlist content:
*****************
VirusTotal: C:\Users\User\AppData\Roaming\Kaspersky Internet Security 2017\spoolsvc.exe;C:\Users\User\AppData\Local\Temp\jow2dzfa.dll
Startup: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\spoolsvc.lnk [2017-12-04]
ShortcutTarget: spoolsvc.lnk -> C:\Users\User\AppData\Roaming\Kaspersky Internet Security 2017\spoolsvc.exe (No File)
Task: {DEB54F2F-08A7-4B1C-B63C-7C4845FA1934} - System32\Tasks\App Explorer => C:\Users\User\AppData\Local\Host App Service\Engine\HostAppServiceUpdater.exe [2017-12-22] (SweetLabs, Inc) <==== ATTENTION
HKU\S-1-5-21-176347147-2586957089-2691104427-1001\...\MountPoints2: {2ae92697-92cb-11e7-8180-ccb0dad6d454} - "G:\AutoRun.exe"
HKU\S-1-5-21-176347147-2586957089-2691104427-1001\...\MountPoints2: {5dc65b0b-3086-11e7-8029-ccb0dad6d454} - "F:\AutoRun.exe"
HKU\S-1-5-21-176347147-2586957089-2691104427-1001\...\MountPoints2: {68be13b2-14f3-11e7-bfbc-ccb0dad6d454} - "F:\StartUse.exe"
HKU\S-1-5-21-176347147-2586957089-2691104427-1001\...\MountPoints2: {ce574921-2505-11e7-bff5-ccb0dad6d454} - "F:\Setup.exe" /s
*****************

VirusTotal: C:\Users\User\AppData\Roaming\Kaspersky Internet Security 2017\spoolsvc.exe => https://www.virustotal.com/file/c1a248a1227900a11c1a2c32a80af50f1482b18099374f3e7464ddc216ec345f/analysis/1516973612/
VirusTotal: C:\Users\User\AppData\Local\Temp\jow2dzfa.dll => https://www.virustotal.com/file/e423663fdd4cfce9ed88fd4c7a9c6a754271ae1c8a7c59b173e1065ffbc9c8b5/analysis/1517212137/
C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\spoolsvc.lnk => moved successfully
C:\Users\User\AppData\Roaming\Kaspersky Internet Security 2017\spoolsvc.exe => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{DEB54F2F-08A7-4B1C-B63C-7C4845FA1934} => could not remove key. ErrorCode1: 0x00000002
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DEB54F2F-08A7-4B1C-B63C-7C4845FA1934}" => removed successfully
C:\Windows\System32\Tasks\App Explorer => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\App Explorer" => removed successfully
"HKU\S-1-5-21-176347147-2586957089-2691104427-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2ae92697-92cb-11e7-8180-ccb0dad6d454}" => removed successfully
HKLM\Software\Classes\CLSID\{2ae92697-92cb-11e7-8180-ccb0dad6d454} => key not found
"HKU\S-1-5-21-176347147-2586957089-2691104427-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{5dc65b0b-3086-11e7-8029-ccb0dad6d454}" => removed successfully
HKLM\Software\Classes\CLSID\{5dc65b0b-3086-11e7-8029-ccb0dad6d454} => key not found
"HKU\S-1-5-21-176347147-2586957089-2691104427-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{68be13b2-14f3-11e7-bfbc-ccb0dad6d454}" => removed successfully
HKLM\Software\Classes\CLSID\{68be13b2-14f3-11e7-bfbc-ccb0dad6d454} => key not found
"HKU\S-1-5-21-176347147-2586957089-2691104427-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{ce574921-2505-11e7-bff5-ccb0dad6d454}" => removed successfully
HKLM\Software\Classes\CLSID\{ce574921-2505-11e7-bff5-ccb0dad6d454} => key not found

==== End of Fixlog 15:49:07 ====

Offline Sass Drake

  • MyCity AMF R2
  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 820
Re: virus problem on thumb drive
« Reply #4 on: January 29, 2018, 08:43:33 PM »
Now install MCShield and follow instructions for it in:

https://forum.avast.com/index.php?topic=194892.0

REDACTED

  • Guest
Re: virus problem on thumb drive
« Reply #5 on: February 05, 2018, 07:16:23 AM »
What to do next?

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user
Re: virus problem on thumb drive
« Reply #6 on: February 05, 2018, 07:24:20 AM »
What to do next?
Have you done MCShield  instructions?


REDACTED

  • Guest
Re: virus problem on thumb drive
« Reply #7 on: February 05, 2018, 08:40:51 AM »
this?

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: virus problem on thumb drive
« Reply #8 on: February 05, 2018, 08:48:28 AM »
this?
Nope, see Reply #4 and follow instructions.
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user
Re: virus problem on thumb drive
« Reply #9 on: February 05, 2018, 09:45:24 AM »

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: virus problem on thumb drive
« Reply #10 on: February 05, 2018, 05:05:54 PM »
this?
Nope, see Reply #4 and follow instructions.

Just to help clear this up as OP seems confused.

SPECIFIC INFECTIONS LOGS
==============================


# additional programme to run and install if you have used an infected USB stick


Please download installation for MCShield and save to your desktop and install the tool;
( installation is a classic "Next > Next > I Agree > ...> Finish" way )
Please wait for a sec. it will initially run a scan and show the result as a toaster by the system clock;
Then in the control centre select scanner and tick Always unhide items on flash drives;

Plug in the drive and MCShield will start the malware scan ...
Get the log which will be in Logs menu, AllScans.txt tab. Just click Save button and log will be located at your Desktop.
[/quote]
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

REDACTED

  • Guest
Re: virus problem on thumb drive
« Reply #11 on: February 06, 2018, 01:21:16 PM »
this one?

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user
Re: virus problem on thumb drive
« Reply #12 on: February 06, 2018, 01:50:41 PM »
this one?
NO, that log belongs to malwarebytes. Have you downloaded and installed MCShield ?   

See my first post above, also see picture in post by Michael (alan1998) above

alternative you can download it from here  >>  http://www.mcshield.net/download.html
when installed, you plug in your USB thumb drive. MCShield will then popup and scan the drive and a log will be created
This log you COPY / PASTE here






« Last Edit: February 06, 2018, 01:54:36 PM by Pondus »

REDACTED

  • Guest
Re: virus problem on thumb drive
« Reply #13 on: February 06, 2018, 02:54:05 PM »
sory got confuse..LoL

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user
Re: virus problem on thumb drive
« Reply #14 on: February 06, 2018, 03:11:32 PM »
I said copy paste log .... NOT ATTACH

a forum issue make the MCShield log look like chinese when attached