Nutcrackers virus?...

Discussion in 'Malware Help (A Specialist Will Reply)' started by Btxeize, Aug 21, 2009.

  1. Btxeize

    Btxeize Private E-2

    Hello to all,

    i'm new here, as i came to your forum looking for help in the first place. Today, opening pdf files in my computer, avast started showing windows of "Nutcracker family". I've sent it to quarantine.

    The next time i've moovend the files, the same happend, over and over again.

    I've read your cleaning procedures, installed and run all the programs, saved all the logs. My computer is a bit slow for some time now...

    I'll attach the logs in this post, can someone help me on this?

    PS: next post with the other logs
     

    Attached Files:

  2. Btxeize

    Btxeize Private E-2

    the other logs

    Thank you very much!
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    It's possible that this is just a false positive. Exactly where was this being detected? Attach a log from Avast.

    Did it have anything to do with the pdfforge Toolbar you have installed? Many people consider this to be malware since it hijacks settings without asking and sometimes can be difficult to remove.

    Or was it detecting the below file?
    C:\WINDOWS\system32\acovcnt.exe



    Uninstall the below old versions of software:
    Java(TM) 6 Update 7
    Java(TM) SE Runtime Environment 6 Update 1

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - URLSearchHook: (no name) - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - (no file)
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)

    After clicking Fix, exit HJT.

    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.


    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Aug 25, 2009
  4. Btxeize

    Btxeize Private E-2

    Hello chaslang,

    I've formated my pc as i needed it in a hury (although you've helped really fast) for my work purposes...

    I didn't even know i had a pdfforge Toolbar...

    Now after i've formate, i've installed a program called Mumutu and once again the SygatePersonalFirewall and avast again. Do you think i'm averagelly protected?

    acovcnt.exe is a file/process that in the past was suspicius to me but i've neved been able to delete it... In this new installation it apears again, should i delete it anyway?
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It came in when you installed PDFCreator without you realizing it which is why many people don't like it.

    Sygate firewall is an unsupported out of date firewall. You should read thru the below link:

    How to Protect yourself from malware!

    I suggest that you put a copy of this file into a ZIP file and attach it here so we can try to find out what it really is for. Perhaps it is valid.
     
  6. Btxeize

    Btxeize Private E-2

    Hello,

    Since our last post i've formated my pc and installed Avast and Outpost firewall and i've beem fine

    Some days ago, my internet started crashing and i could't even connect so i've formated again....

    Fine again this time with Panda Internet Security 2009.

    But now i've started having the same problem and i see acovcnt.exe again in system32 folder, i cant erase it not even with the script and program you've said... What ca i do? I'm only posting this as i've run GMER and HighJackThis and saw that in "libraries" there is this file, with the Rootkit definition.

    Panda doesn't see any virus, it's all fine for it....

    When I start Firefox my home page apears as "search.conduit.com" and i don't even know what that is, but still can't connect.

    I've killed the process with HighJackThis but i know it's going to be back...

    HELP PLEASE, what can i do? Format again??

    Thanks
     
  7. Btxeize

    Btxeize Private E-2

    Here is the zip of the file
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you have formatted and reinstalled, your problems are more than likely not related to malware..... that is unless you are reinstalling anything from backup files that are infected. However since even your original scans showed no malware, I suspect that you are having problems with either your hardware or software and you may want to post in the Software Forum.

    The acovcnt.exe file is just for your ASUS Chameleon mother board.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds