Suspected of Malwares

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by vacat, Sep 5, 2013.

  1. vacat

    vacat Private E-2

    hi.
    I followed all the steps you showed. Yesterday I downloaded 2 keybinders. I run the Chaos samp key binder. it didnt work in anyways.
    I downloaded another one. it was in a .rar file. I right clicked and performed an avast scan.
    this is what i get from avast.
    computer slowed down. cpu usage was like 0%. this made me quite paranoid.
    Also in other account(not admin standart one) avast fails each time. Wow after scans and steps you suggest this fail didnt happen(it was related with visual studio 9)

    Avast seems bugged. AVG cant be installed anymore getting errors...
    here avast SS and Logs you want.
    scan bug:
    http://u1309.hizliresim.com/1f/5/sb2q8.png
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Before we continue I would like for you to use MSConfig to put this machine back into normal start up mode. Thanks. :)


    Please use Revo Uninstaller to remove Avast.



    [​IMG] Fix items using RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab (Or fix proxy) and locate this 1 detection:

    • [PROXY IE] HKCU\[...]\Internet Settings : ProxyServer (175.139.234.30:3128) -> FOUND
    Place a checkmark each of these items, leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Reboot the machine.


    Re run Hitman Pro and have it delete Potential Unwanted Programs.


    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    • R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://kl.startnow.com/?src=startpage&provider=
    • O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    • O2 - BHO: (no name) - {95B7759C-8C7F-4BF1-B163-73684A933233} - (no file)
    • O3 - Toolbar: (no name) - {95B7759C-8C7F-4BF1-B163-73684A933233} - (no file)
    • O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - (no file)
    After clicking Fix exit HJT.

    ........................................

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.



    [​IMG] Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  3. vacat

    vacat Private E-2

    i cant go on normal startup.
    a failed format on disk F. in order to avoid it i use selective start up.
    here if i select normal start up http://k1309.hizliresim.com/1f/5/sb97k.png
    even i delete the F disk one.
     
  4. vacat

    vacat Private E-2

    shit shit shit
    i adad
    omgggg
    i mistakenly deleted all in raogue killer -.-
    i didnt restar nor close the program. can i get em back? :( :( :cry:cry:cry
     
  5. vacat

    vacat Private E-2

    okay. whatever. instead of deleting the proxy... i deleted em all. i didnt think that the Delete button would delete the other tabs.
    i feel like a total nab.
    ty
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    OK, no problem, just continue on with the other steps now please. :)
     
  7. vacat

    vacat Private E-2

    well. i dont have an AV for now.
    hitman is done.
    now rebooting
     

    Attached Files:

  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yep, if it's broken, it's gotta come out. ;)
     
  9. vacat

    vacat Private E-2

    i received the success key reg. :) thanks.

    now. am i gonna go on JRT.exe ? :cool
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes, carry on with all the steps that I outlined, please.
     
  11. vacat

    vacat Private E-2

    okey. everything is done! :) :)
     

    Attached Files:

  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    OK, explain how things are running at this point, please.
     
  13. vacat

    vacat Private E-2

    hi sir. Everything seems ok. some apps icons are gone like format factory, internet explorer (on start menu)

    the 5th step. UAC. never messed with them. UAC was always off. shall i open it?
    shall i install and AV?
    things seems ok. no freeze no problems :)
     
  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    That's madam (and no offence taken ;))

    You can easily add them back.

    If you do not like to use UAC then there is no need for you to turn it back on(

    Yes indeed and let me know how the process of that goes.
    Very good to know. :)
     
  15. vacat

    vacat Private E-2

    :) wow madam, you are very supportive thanks. What free Av u suggest?
     
  16. vacat

    vacat Private E-2

    thank you for being so supportive madam :)

    Ill go on avast but i think it will only fail,
    Any Av u suggest :)

    sorry fur bump i thought opera mini bugged :O
     
    Last edited: Sep 5, 2013
  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please DO try to install Avast from fresh. There shouldn't be a problem; and if there is I will do all that I can towards helping, however I may refer you onto the software forum. :)
     
  18. vacat

    vacat Private E-2

    i downloaded avira avast and avg.
    now as u said im going on AVAST.

    can we figure why keybinder does not work :)
    this dialog oopens if i click on continue the app seems run but on each command the same dialog opens os i quite
    http://r1309.hizliresim.com/1f/6/scb9t.png
    http://t1309.hizliresim.com/1f/6/scb9m.png

    avast failed :(
    http://t1309.hizliresim.com/1f/6/scbc2.png
    ill reboot now
     
  19. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I do not know about the keybinders, you are going to have to ask about that in another area of the forum.

    What exact error did avast give during the attempted installation, can you roughly translate for me please? :confused
     
  20. vacat

    vacat Private E-2

    hi ;)
    the translation;
    The installation is not completed.(yükleme tamamlanmadı)

    While the installation was being completed an error occured(yükleme tamamlanırken bir hata oluştu)


    Reboot(yeniden başlat)
    reboot later(daha sonra yeniden başlat)

    If you dont restart now some compenets migth not work properly and this migth cause system errors(bilgisayarınızı şimdi yeniden başlatmazsanız....)

    Show the installation diary(logs)
    (yükleme günlüğünü göster)
    I didnt look at the installation logs. I think I should go on different avs
     
  21. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    It's an option yes, but then what if the other anti virus had issues installing too? We may need to figure this one out. Can you run the avast removal tool please.

    Reboot the machine if the process does not involve one.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.

    I will review the logs, and check nothing remains of avast. You can have one more try at installing from fresh and if that fails, you will have to try another anti virus for now. I would very much like to get this solved though.
     
  22. vacat

    vacat Private E-2

    okay. but a mistake by me.

    it's saying the installation is completed.
    sorry :-o


    btw later the avast failed and i rebooted. i uninstalled some apps like adobe master c5. lots of free space now :)

    I once tried to install VStudio 9 and the setup was failed. and i think later the packages caused problems.

    now running avast cleaner.
     
  23. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Are you saying Avast is installed and fully functional now?
     
  24. vacat

    vacat Private E-2

    nope.
    avast didnt install. it was getting installed and at the end this it failed. it said the installation is complete


    so there s no AV fow now. nvm what Avast setup said :)

    i used the avast cleaner here logs

    all the translations are correct. except this one
    The installation is not completed.(yükleme tamamlanmadı)
    the correct one is: The installation iscompleted.(yükleme tamamlandı)

    the others are correct
     

    Attached Files:

  25. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Okay... try to install another anti virus please as I can't have you keep surfing without one. Let me know how it goes. We will have to abandon trying to work out the Avast thing.
     
  26. vacat

    vacat Private E-2

    :) installing avira . i think ill perform a virus test

    update: avira installed it performs quick scan. Ill make a big one scan

    No problems so far ;)
     
    Last edited: Sep 6, 2013
  27. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes let it run a complete full system scan and let me know the results. If you do ever wish to further investigate the avast issue you would have to post in the software forum regarding that. :)
     
  28. vacat

    vacat Private E-2

    here the logs of AV.

    it wanted a reboot and a further scan. its scanning again. i think it is a kind of feed back thing.
     

    Attached Files:

  29. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Keep scanning then and let me know later on today how things are. :)
     
  30. vacat

    vacat Private E-2

    this 2nd scan took 13 hours . says 4.9m files had been scanned and only 49 percent is scanned. i think progress bar is bugged. its quite slow and for like 10 hours the option was selected"allow to stop scan" it is like i think sleep kinda think. i set the mouse clicker for each 5 seconds it clicks on desktop.

    i hope the AV scan is not on loop. and i hope it will be finished till moring. its 21:53 here.
     
  31. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    And what is it doing now?
     
  32. vacat

    vacat Private E-2

    still scanning. Its been 24 hours. Says the app, 8.5m files and so on, progress bar is %78. I'll left it on, let it scan, 56 detections, and in first scan it was 82. Dont know why so slow, maybe some configs i changed.... Didnt know my pc was this stable. Ill post the logs. U r probably sleeping i guess.

    And the thing i observed the umbrella was not opened in the system tray the little icon on taskbar, for like 14th hours of scan it was off, and now i see its an opened umbrella.
    A config i remember i cant find now, secure boot of the av, i think it wasnt necessary.

    Take care.
     
  33. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    That's taking it's time for sure. But we might as well let it finish now. Do update me again later on today. :)
     
  34. vacat

    vacat Private E-2

    hi. it was the 29th hour of the scan. i realized it was on loop. i stopped it. here logs.

    and i disabled the option follow symbolic links and i added and exception to my game file.

    btw system lags little on avira even not scanning. this did not happen on avast nor avg
     

    Attached Files:

  35. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    So this seems tobe the only item it cannot delete?
    • D:\WINDOWS\system32\blphcnvvj0en91.scr


    This is why! :)
    Your machine needs more RAM.
     
  36. vacat

    vacat Private E-2

    my post didnt get post lol.
    Yes how Can I delete it.
     
  37. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Should be able to just navigate to it's location, and right click and delete the blphcnvvj0en91.scr file. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds