Win32/Powessere.D ???

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by idssteve, Feb 22, 2015.

  1. idssteve

    idssteve Private E-2

    MSE reports Win32/Powessere.D. RogueKiller pre-scan flags half dozen "suspicious paths" and then stops and disappears before a log file can be saved. The suspicious paths seemed to be mostly to OneDrive but that's all i remember during the brief time before RogueKiller disappears.

    Right or wrong, i have windows pagefile and firefox cache on a small physical hard disk "W" to minimize write wear on the SSD main drive. Not sure if attached scans included that disk or if they need to...??? Just a heads up.

    Thanks.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    There are no problems showing in your logs. There is a good chance that you just have false detections from MSE. And RogueKiller reports lots of non-issues which is why our instructions say to just scan with it and give us a log.

    Are you actually having any real problems?


    But let's run the below just to be safe as some infections will not show up in the normal logs ( like the one I'm scanning for with the below. :) )

    Please download the latest version of FRST the below link.
    Farbar Recovery Scan Tool and save it to your Desktop.

    Note: Make sure you download the proper version ( 32 bit or 64 bit ) for your PC. Only one will run, the correct one. So it you make a mistake and download the wrong one, go back and get the other.
    • Double-click to run it. When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) in the same directory the tool is run. Please attach it to your next reply.
    • The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.
     
  3. idssteve

    idssteve Private E-2

    Thanks, scan logs attached. I guess MSE successfully removed the Win32/Powessere.D? Also, RK refuses to complete a run without abruptly shutting down and "disappearing" before a log file can be saved. Can you tell if its malware or just software issues?
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.
    Not completely.


    Download this >> View attachment fixlist.txt

    Save fixlist.txt on your Desktop. Make sure you save it as a txt file.
    • You should now have both fixlist.txt and FRST64.exe on your Desktop.
    • Now I want you to disconnect your PC connection to the internet by unplugging the cable ( if it is wireless then temporarily shutdown the wireless network ).
    • Run FRST64.exe by right clicking on it and selecting Run As Adminstrator
    • Click the Fix button just once and wait.
    • Your computer should reboot after the fix runs.
    • Reconnect your internet connection after reboot so you can come back here to continue.
    • The tool will make a log on the Desktop (Fixlog.txt) please attach this new log to your next reply (attach or paste)
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • Fixlog.txt
    • C:\MGlogs.zip
    How are things working now? I'm not too concerned about RogueKiller.
     
  5. idssteve

    idssteve Private E-2

    Thanks Chaslang, As requested with just a few notes.

    I couldn't find FRST64.exe but found and used FRST.exe. My system is 32bit Win7. If that makes a difference?

    I stupidly ran GetLogs.bat with a simple double click and then, later ran again as administrator. I've included the log result of both. Admin version is MGlogs(2).zip Sorry for the mixup.

    I didn't adequately explain my concern with RogueKiller. Every time RK killed itself, MSE immediately popped up informing "Detected threats are being cleaned". Checking MSE's quarantine history indicated "Win32/Powessere.D" coinciding with the time RK vanished. Also, simultaneously, another msg pops up center screen: "Windows Explorer has stopped working and needs to close..." Desktop icons disappear and then re-appear and then RK disappears. The events seem related?? Just tried it again and the same sequence still reliably repeats. RK itself doesn't concern me much either but i just thought the symptoms might indicate some kind of malware activity?? FWIW.

    Thanks again.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay this is just MSE getting in your way of malware removal. RogueKiller is not malware so this is just a false detection and it is why we frequently have people disable or even uninstall protection software during this process. We even mentioned possible problems like this in the READ & RUN ME FIRST.

    Are you having any remaining problems?
     
  7. idssteve

    idssteve Private E-2

    Well, that's why i asked THE expert! :) No other discernible troubles. Many thanks to you and your site!
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore points:
      • Refer to the instructions for your WIndows version in this link: Disable And Enable System Restore
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds