Daily Recurring Infections on Vista

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by StephenT, Jun 21, 2009.

  1. StephenT

    StephenT Private E-2

    Hi,

    I would appreciate your assistance.

    On my Vista PC, around daily Avira AntiVir reports on 13 files as Sohanad threats.

    As per the 'First' SuperantiSpyware report attached these files are reported as Worm SSCVIHost threats. As per the 'Second' SuperantiSpyware report, after removal SuperautiSpyware runs are clean until the next episode.

    Following your Vista procedure, further attachments are from Malware, ComboFix and MGTools. RootRepeal failed to run.

    Thanks,
    Stephen
     

    Attached Files:

  2. StephenT

    StephenT Private E-2

    And the MGTools attachments
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please use windows explorer to find and delete:
    C:\aujasnkj.sys

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  4. StephenT

    StephenT Private E-2

    Thank you for your assistance.

    I have deleted C:\aujasnkj.sys

    I have attached the latest C:\MGlogs.zip file

    I will run the PC for a few days and then report back.

    Thanks again,
    Stephen
     
  5. StephenT

    StephenT Private E-2

    Here is the MGLogs attachment.
    Thanks,
    steve
     

    Attached Files:

  6. StephenT

    StephenT Private E-2

    Hi,

    Unfortunately, I had another recurrence today.

    The SuperantiSpyware report is attached reporting 8 files (as opposed to the 13 originally).

    Thanks,
    Steve
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Then SAS is doing it's job. If you think there is still some things that it may have missed, you need to re-run:
    MBAM
    ComboFix
    and then download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one. Run the exe and attach the new log.
     
  8. StephenT

    StephenT Private E-2

    Hi Tim,

    Just to reliterate,
    a) C:\aujasnkj.sys has been deleted (as requested).
    b) Almost daily Avira AntiVir still reports on files as Sohanad threats. SuperantiSpyware cleans them as reported Worm SSCVIHost threats.

    The requested logs are attached.

    Thanks,
    Steve
     

    Attached Files:

  9. StephenT

    StephenT Private E-2

    Hi Tim,

    And attached is latest recurrence (almost straight after those clean logs were collected!).

    Thanks,
    Steve
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I would suggest that you install a firewall and see if that stops it. I am not seeing anything in your logs. It could be coming from an infected email, bookmark or website that you are visiting.

    Please do this:
    Using BitDefender Online Scan.

    Please do this and download a firewall:
    How to Protect yourself from malware!

    Then tell me what happens.
     
    Last edited: Jun 28, 2009
  11. StephenT

    StephenT Private E-2

    Hi Tim,

    Just to report back.

    1. BitDefender found no issues.

    2. Installed Comodo Firewall but daily recurrences continued.

    Given my time commitments, I was forced to do rebuild Vista.

    No issues here for almost one week.

    Anyway thanks again for your efforts,
    Steve
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Thanks for letting me know.....safe surfing.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds