Author Topic: Malware infection and following the guide.  (Read 19271 times)

0 Members and 1 Guest are viewing this topic.

warnolo

  • Guest
Malware infection and following the guide.
« on: December 22, 2011, 01:30:56 AM »
Hi. I think i have some infection on my computer and i'm following the guide.

Here is my log after the first scan with MBAM

Malwarebytes' Anti-Malware 1.51.2.1300
www.malwarebytes.org

Versión de la Base de Datos: 911122201

Windows 6.1.7600
Internet Explorer 8.0.7600.16385

22/12/2011 1:24:59
mbam-log-2011-12-22 (01-24-59).txt

Tipos de Análisis: Análisis Rápido
Objetos examinados: 183832
Tiempo transcurrido: 3 minuto(s), 6 segundo(s)

Procesos en Memoria Infectados: 0
Módulos de Memoria Infectados: 0
Claves del Registro Infectadas: 0
Valores del Registro Infectados: 0
Elementos de Datos del Registro Infectados: 0
Carpetas Infectadas: 0
Archivos Infectados: 1

Procesos en Memoria Infectados:
(No se han detectado elementos maliciosos)

Módulos de Memoria Infectados:
(No se han detectado elementos maliciosos)

Claves del Registro Infectadas:
(No se han detectado elementos maliciosos)

Valores del Registro Infectados:
(No se han detectado elementos maliciosos)

Elementos de Datos del Registro Infectados:
(No se han detectado elementos maliciosos)

Carpetas Infectadas:
(No se han detectado elementos maliciosos)

Archivos Infectados:
c:\Users\Usuario\AppData\Roaming\microsoft\Windows\start menu\Programs\Startup\dxdiag.exe (Trojan.Downloader) -> Quarantined and deleted successfully.


Sorry for the language, i'm spanish

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user
Re: Malware infection and following the guide.
« Reply #1 on: December 22, 2011, 01:39:15 AM »
attch the rest of the logs...read the guide

lower left corner > additional options > attach

warnolo

  • Guest
Re: Malware infection and following the guide.
« Reply #2 on: December 22, 2011, 01:42:15 AM »
Ok, now getting to the next step.

Edit: wrong format, now is the right one.

Also, after getting into the disk manager what should i do?

Edit 2: sorry, too stupid to read.
« Last Edit: December 22, 2011, 01:52:44 AM by warnolo »

warnolo

  • Guest
Re: Malware infection and following the guide.
« Reply #3 on: December 22, 2011, 01:56:58 AM »
Now the log of the aswMBR

Getting to the last step.

warnolo

  • Guest
Re: Malware infection and following the guide.
« Reply #4 on: December 22, 2011, 02:01:55 AM »
Ok, last step.

so after this everything should work well?

warnolo

  • Guest
Re: Malware infection and following the guide.
« Reply #5 on: December 22, 2011, 02:14:38 AM »
Damn it, i'm still infected.

Should i repeat all the process?

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user
Re: Malware infection and following the guide.
« Reply #6 on: December 22, 2011, 02:18:02 AM »
Damn it, i'm still infected.

Should i repeat all the process?
now you go to sleep....then come back tomorrow when essexboy have looked at the log...
Then the removal begins   ;)

he is usually in here around 08:00pm - 11:59pm UK time

warnolo

  • Guest
Re: Malware infection and following the guide.
« Reply #7 on: December 22, 2011, 02:20:37 AM »
ok, i'll try to sleep, i'm nervious and not knowing what is going to be.

warnolo

  • Guest
Re: Malware infection and following the guide.
« Reply #8 on: December 22, 2011, 02:32:59 AM »
Also the infected file that gives me problems looks like is called dxdiag.exe and i can't disable it.

Well, anyway, i'll go to sleep.

warnolo

  • Guest
Re: Malware infection and following the guide.
« Reply #9 on: December 22, 2011, 11:42:52 AM »
Here i am again, panicing like crazy and i can't really relax.

I changed all my important passwords on another computer and now i'm just waiting.

I could just format the disk and leave it like comming from the factory, but still i'm waiting an awnser about this. Now i just need any tip to relax because I'm still too nervious to do anything.

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Malware infection and following the guide.
« Reply #10 on: December 22, 2011, 11:45:35 AM »
Now i just need any tip to relax because I'm still too nervious to do anything.

Don't panic..! ;)
And wait for essexboy...
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

warnolo

  • Guest
Re: Malware infection and following the guide.
« Reply #11 on: December 22, 2011, 12:00:58 PM »
worst think is that now i see viruses anywere everywere and now i don't even dare to use my email account even in this computer.

I would be happy if just anyone could tell me "Nah, is just a bothering thing but nothing serious, so don't be scared about a machine taking your whole life from the net" but well, i don't want to lie to myself.

Also, sorry if i talk too much, i just need to express myself or i would feel worse.

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Malware infection and following the guide.
« Reply #12 on: December 22, 2011, 12:06:05 PM »
Also, sorry if i talk too much, i just need to express myself or i would feel worse.

NP at all, still you have to be patient. ;)
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Malware infection and following the guide.
« Reply #13 on: December 22, 2011, 08:48:04 PM »
Hi on completion could you let me know what problems you are experiencing

Warning This fix is only relevant for this system and no other, using on another computer may cause problems

Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot

Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
    Quote
    :OTL
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://start.facemoods.com/?a=ddrnw&s={searchTerms}&f=4
    IE - HKU\S-1-5-21-1389257832-4104621990-2468260417-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://start.facemoods.com/?a=ddrnw
    O3 - HKU\S-1-5-21-1389257832-4104621990-2468260417-1000\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
    O3 - HKU\S-1-5-21-1389257832-4104621990-2468260417-1000\..\Toolbar\WebBrowser: (no name) - {472734EA-242A-422B-ADF8-83D1E48CC825} - No CLSID value found.
    O3 - HKU\S-1-5-21-1389257832-4104621990-2468260417-1000\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
    O4 - Startup: C:\Users\Usuario\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\dxdiag.exe ()

    :Files
    ipconfig /flushdns /c
    xcopy %Temp%\smtmp\1 "%AllUsersProfile%\Start Menu" /H /I /S /Y /C
    xcopy %Temp%\smtmp\2 "%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch" /H /I /S /Y /C
    xcopy %Temp%\smtmp\3 "%AppData%\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar" /H /I /S /Y /C
    xcopy %Temp%\smtmp\4 "%AllUsersProfile%\Desktop" /H /I /S /Y /C

    :Commands
    [purity]
    [resethosts]
    [emptytemp]
    [CREATERESTOREPOINT]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done
  • Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.

warnolo

  • Guest
Re: Malware infection and following the guide.
« Reply #14 on: December 22, 2011, 09:27:51 PM »
I posted it on Unicode because it says that some characters would be lost in ansi, but i still have the log open.

Also i have to run the problem mode (don't really know how is called in english) because now my screen gets black except the cursor.

So is something serious?