Hi there, I have Windows Vista Home and AVG internet Security 2012 plus other spyware tools, Spybot S&D and Spywareguard but still I found using external tool that I had malware issue (Z-Access) in the machine. I went to make that check seeing that the system is being slower, usually is not very noisy and only sounds like using the coolers when handling a very heavy program (3d Application with real time etc). But these days it sounds a lot and freezes even when using just internet browser or even browsing a folder content. Very often it turns into black squares or all white for a little while and when I turn on the machine it takes longer than usual to reach desktop then flashes to black and white twice (sometimes it happened too that i couldnt enter the desktop and once it even remain blue with just the mouse), then if I reach desktop it goes more or less but not perfect and the continues freezes it suffers make my whole workflow delay a lot. I made a OTL scan and can post its results if needed, but I can try any other stuff you suggest me.
Thank you very much in advance for any help =).
PS I forgot to mention that lastly AVG declares a lot of potential menaces that seem to be the packages that Spybot downloads when updating so its very strange and Im unsure about removing them or not
My name is Satchfan and I would be glad to help you with your computer problem.
Please read the following guidelines which will help to make cleaning your machine easier:
please follow all instructions in the order posted
please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear
all logs/reports, etc. must be posted in Notepad. Please ensure that word wrap is unchecked. In Notepad click Format, uncheck Word wrap if it is checked
if you don't understand something, please don't hesitate to ask for clarification before proceeding
the fixes are specific to your problem and should only be used for this issue on this machine.
please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!
IMPORTANT:
Please DO NOT install/uninstall any programs unless asked to.
Please DO NOT run any scans other than those requested
Hello Satchfan, and thanks you very much for your reply and guides.
Here I attached the files needed and I await your next instructions regarding this trouble. I know I can totally trust the WTT Staff but worrying about the people from outside… could I ask you to remove these files from public view once the problems are fixed? many thanks and if its not possible its fine, this is a great dutty you all are doing helping us to maintain computers clean and safe.
worrying about the people from outside… could I ask you to remove these files from public view once the problems are fixed?
As this is a public forum we only remove or hide inappropriate or dangerous content from posts.
Your information in the logs cannot be used for anything that could affect you or your computer. However, if you have named documents that you are concerned about being seen publically I suggest you remove them temporarily to a flash drive.
I have looked at your logs and unfortunately one or more of the identified infections is known to use a backdoor trojan.
This allows hackers to remotely control your computer, steal critical system information and download and execute files.
I would advice you to disconnect this PC from the Internet immediately. If you do any banking or other financial transactions on the PC or if it should contain any other sensitive information, please get to a known clean computer and change all passwords where applicable, and it would be wise to contact those same financial institutions to apprise them of your situation.
Though the infection has been identified and because of it's backdoor functionality, your PC is very likely compromised and there is no way to be sure your computer can ever again be trusted. Many experts in the security community believe that once infected with this type of trojan, the best course of action would be a reformat and reinstall of the OS.
Please read these for more information:
How Do I Handle Possible Identify Theft, Internet Fraud and CC Fraud? http://www.dslreports.com/faq/10451
When Should I Format, How Should I Reinstall http://www.dslreports.com/faq/10063
These infections can possibly be cleaned, but it will be impossible to be 100% sure that the machine is clean, if this is unacceptable to you then you should consider reformatting both system partitions and reinstalling Windows as this is the only 100% sure answer.
If you wish to reformat then please let me know in your next response, If you decide to go through with the cleanup, please proceed with the following steps:
Download and run ComboFix
Download ComboFix from the following location:
Link
* IMPORTANT !!! Save ComboFix.exe to your Desktop
Disable your AntiVirus and AntiSpyware applications, as they may otherwise interfere with our tools. See here for programs that need to be disabled and instruction on how to disable them.
Remember to re-enable them when we're done.
Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue its malware removal procedures.
Hi,
Im sorry but I can't format the system if there is another option even if its not 100% secure, I will try to fix this if you don't mind, the trouble is the ammount of sofware installed with all the configuration settings and plugins that I had to set up plus all the data I generated so while its not impossible to format I will try to avoid if you help me and if in the end its not totally fixed I will be very thanked anyway.
Here is the Combofix report, however there was a trouble, after Combofix rebooted the system the firewall blocked (probably) a request from Combofix and I wasnt in front of the machine to allow the request (took some hours to complete) so in the Combofix screen I could read "access denied" in the end just before launching the report. Should I re-run the Combofix?
I'm sorry I can't edit the previous post, if you tell me how then I will do next time.
I forgot to mention that I rejected to remove the "Home page" and "default search engine" from browser settings, so I think the "access denied" could be due to that.
I need as much information as possible to help with this so let’s take it a few steps at a time.
Please make sure that ALL your security is disabled, including your firewall and then run ComboFix again.
I also notice that you have run TDSSKiller. Please send a copy of the log: a copy of the log will be saved automatically to the root of the drive (typically C:) called TDSSKiller_*** - (*** denotes version & date)
Hi Satchfan, thank you for your patience and efforts in cleaning this machine. Here are the requested files, this time the Combofix didnt reboot the system but it was impossible to open anything after it finished as it was saying all elements were marked for deletion so I needed to reboot. Also I had to retry 3 times as in this scan the AVG was not willing to deactiivate and crashed twice, also a certain media player crashed before the scan, just in case anything is reflected in the logs.
The TDSSKiller log is not new, just from a couple of days ago if you need new one just let me know.
P2P - I see you have various P2P programs installed on your machine.
We are not here to pass judgment on file-sharing as a concept but we will warn you that engaging in this activity will always make your computer very susceptible to infection and re-infection. As your computer is infected, it almost certainly contributed to your current situation.
If your computer is infected, it almost certainly contributed to your current situation.
Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are more often than not, infected. Those who write malware use P2P file-sharing as a major vehicle to spread their wares.
Please see this topic for more information:
Perils of P2P File Sharing.
I would strongly recommend that you uninstall them now. You can do so via Control Panel, Programs, and then Programs and Features.
Should you decide to keep them, please don’t use them until we have finished up here.
Hi Satchfan, thanks for your advice regarding P2P, I know it can be dangerous and I never download ilegal or unsafe content, and if by any chance I get unexpected filetype or size (exe instead of pdf chm etc) I never run them and inmediatly delete them.
I have run the two scans as you suggested and here are the logs, however as I feel it could take you a lot of time and effort in cleaning the whole machine, today I bought Kaspersky Internet Security 2013, I haven't installed yet awaiting your advice regarding this, and I hope we manage to make this faster and easier for you this way, as said I won't install as probably it will break part of your plan or something, well, I hope this way its better for you =).
Please don’t install Kaspersky yet. Installing and running it does not cure all malware problems. Although Kaspersky is probably, (IMHO), the best AV around, it cannot detect everything - there isn;t one around that can.
I would suggest however that you uninstall Ad-Aware as the professional version has Ad-Watch which is an antivirus and means that you have 2 currently working against each other. Ad_Aware is also less effective than the one I’m going to ask you to run now.
Download and run AdwCleaner
Download AdwCleaner from here and save it to your desktop.
run AdwCleaner and select Delete
when it has finished it will ask to reboot - allow the reboot
on reboot a log will be produced; please attach the content of the log to your next reply
================================================
Please also run RogueKiller again and send a new log.
Can you tell me the current position with your computer.
BTW, you are still attaching the results of logs instead of copying/pasting them. Please don’t attach these logs.
Hi, I'm sorry I haven't run the AdwCleaner yet, I have been having troubles connecting to the internet, the computer very easily get disconnected and unable to reconnect not even after reboot, for some reason, I'm not saying this is due to the fixes you have recommended, perhaps its a side effect of removing certain menace from the system (so if I don't reply in a day or two its maybe due to that)
Also I'm sorry I have attached the files instead of copying-pasting the content, I thought that this way it uses less space rather than making 4 consecutive posts or so to include the whole logs content, I will do as you say next time.
Additionally I got a trouble getting the AdwCleaner as AVG keeps on saying it has a potential risk and clasify it as trojan menace. is this normal?
Hello Satchfan,
The current status of the machine is better, I think, can't say if its perfect or not as of course it won't run as fast as first day or reboot as fast with all the programs that load on startup. One fact that clearly was improved is that I no longer hear the computer noise as if it was handling a heavy program with almost no windows open so I think if its not fixed its almost done =).
The AdwCleaner was closed as we lost the power in the middle but it seems it managed to generate a report then after that i re-run the process and it finished well this time, so I have two reports from that. Also I'm sorry, I noticed the reports have parts in spanish, but I'm sure you know the reports sections quite well, so I hope its not a trouble and if you need anything about it just tell me.
Also one fact that happeend is that I had the Ask & Record bar installed in Firefox and as you will see in the reports it was uninstalled, I wonder if that was potentially risky, because this one has a tool for web audio recording that I need for my job… of course I think there should be a replacement but just wondering if I can go back to it or better avoid that.
One last thing is that, as you surely know, on the process end it suggests to enable the PUP and LIP detection on the antivirus program, I haven't done that on AVG as I'm uninstalling it after all is done or when you suggest that, so I think I will do that in Kaspersky instead, I hope its correct that way, but also AdwCleaner suggests that pressing the "?" on the main screen it will install hosts to handle that, is that needed?
Here is the first report, interrupted but managed to create the log:AdwCleaner[S1].txt
# AdwCleaner v2.009 - Fichero creado el 29/11/2012 a 20:44:53
# Actualizado el 24/11/2012 por Xplode
# Sistema operativo : Windows Vista ™ Home Premium (32 bits)
# Usuario : ASD-MASTER - ASD
# Modo de inicio : Normal
# Ejecutado desde : C:\d\adwcleaner.exe
# Opción [Supresión]
***** [Servicios] *****
***** [Ficheros / Carpetas] *****
Carpeta Suprimido : C:\Program Files\AskBarDis
Carpeta Suprimido : C:\Program Files\AVG Secure Search
Carpeta Suprimido : C:\Program Files\Common Files\AVG Secure Search
Carpeta Suprimido : C:\Program Files\Viewpoint
Carpeta Suprimido : C:\ProgramData\AVG Secure Search
Carpeta Suprimido : C:\ProgramData\Trymedia
Carpeta Suprimido : C:\ProgramData\Viewpoint
Carpeta Suprimido : C:\Users\ASD-MASTER\AppData\Local\AVG Secure Search
Carpeta Suprimido : C:\Users\ASD-MASTER\AppData\LocalLow\AVG Secure Search
Carpeta Suprimido : C:\Users\ASD-MASTER\AppData\Roaming\Mozilla\Firefox\Profiles\u4qruwye.default\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D}
Fichero Suprimido : C:\Program Files\Mozilla Firefox\.autoreg
Fichero Suprimido : C:\Program Files\Mozilla Firefox\searchplugins\avg-secure-search.xml
***** [Registro] *****
Clave Supprimida : HKCU\Software\APN PIP
Clave Supprimida : HKCU\Software\AppDataLow\AskBarDis
Clave Supprimida : HKCU\Software\Ask&Record
Clave Supprimida : HKCU\Software\AVG Secure Search
Clave Supprimida : HKCU\Software\Headlight
Clave Supprimida : HKCU\Software\IGearSettings
Clave Supprimida : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Ask Toolbar_is1
Clave Supprimida : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\ViewpointMediaPlayer
Clave Supprimida : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{201F27D4-3704-41D6-89C1-AA35E39143ED}
Clave Supprimida : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0702A2B6-13AA-4090-9E01-BCDC85DD933F}
Clave Supprimida : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{201F27D4-3704-41D6-89C1-AA35E39143ED}
Clave Supprimida : HKLM\Software\AVG Secure Search
Clave Supprimida : HKLM\SOFTWARE\Classes\AppID\{1FDFF5A2-7BB1-48E1-8081-7236812B12B2}
Clave Supprimida : HKLM\SOFTWARE\Classes\AppID\ScriptHelper.EXE
Clave Supprimida : HKLM\SOFTWARE\Classes\AppID\ViProtocol.DLL
Clave Supprimida : HKLM\SOFTWARE\Classes\AVG Secure Search.BrowserWndAPI
Clave Supprimida : HKLM\SOFTWARE\Classes\AVG Secure Search.BrowserWndAPI.1
Clave Supprimida : HKLM\SOFTWARE\Classes\AVG Secure Search.PugiObj
Clave Supprimida : HKLM\SOFTWARE\Classes\AVG Secure Search.PugiObj.1
Clave Supprimida : HKLM\SOFTWARE\Classes\AxMetaStream.MetaStreamCtl
Clave Supprimida : HKLM\SOFTWARE\Classes\AxMetaStream.MetaStreamCtl.1
Clave Supprimida : HKLM\SOFTWARE\Classes\AxMetaStream.MetaStreamCtlSecondary
Clave Supprimida : HKLM\SOFTWARE\Classes\AxMetaStream.MetaStreamCtlSecondary.1
Clave Supprimida : HKLM\SOFTWARE\Classes\CLSID\{03F998B2-0E00-11D3-A498-00104B6EB52E}
Clave Supprimida : HKLM\SOFTWARE\Classes\CLSID\{0702A2B6-13AA-4090-9E01-BCDC85DD933F}
Clave Supprimida : HKLM\SOFTWARE\Classes\CLSID\{08993A7C-E764-4172-9627-BFB5EA6897B2}
Clave Supprimida : HKLM\SOFTWARE\Classes\CLSID\{128A6C66-AC6A-4617-8268-AB7F47B7215E}
Clave Supprimida : HKLM\SOFTWARE\Classes\CLSID\{1B00725B-C455-4DE6-BFB6-AD540AD427CD}
Clave Supprimida : HKLM\SOFTWARE\Classes\CLSID\{201F27D4-3704-41D6-89C1-AA35E39143ED}
Clave Supprimida : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Clave Supprimida : HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\viprotocol
Clave Supprimida : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi
Clave Supprimida : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi.1
Clave Supprimida : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE
Clave Supprimida : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE.1
Clave Supprimida : HKLM\Software\Headlight
Clave Supprimida : HKLM\Software\MetaStream
Clave Supprimida : HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{03F998B2-0E00-11D3-A498-00104B6EB52E}
Clave Supprimida : HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{1B00725B-C455-4DE6-BFB6-AD540AD427CD}
Clave Supprimida : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{201F27D4-3704-41D6-89C1-AA35E39143ED}
Clave Supprimida : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Ask Toolbar_is1
Clave Supprimida : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ViewpointMediaPlayer
Clave Supprimida : HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin
Clave Supprimida : HKLM\SOFTWARE\MozillaPlugins\@viewpoint.com/VMP
Clave Supprimida : HKLM\Software\PIP
Clave Supprimida : HKLM\Software\Viewpoint
***** [Navegadores] *****
-\\ Internet Explorer v7.0.6000.16757
[OK] El registro no contiene ninguna entrada ilegítima.
-\\ Mozilla Firefox v3.0.8 (es-ES)
Nombre del perfil : default
Fichero : C:\Users\ASD-MASTER\AppData\Roaming\Mozilla\Firefox\Profiles\u4qruwye.default\prefs.js
Supprimida : user_pref("SothinkWebVideoDownloaderWebVideoDownloader.DownloadedArray_1516.url", "http://veoh-097.v[…]
Supprimida : user_pref("SothinkWebVideoDownloaderWebVideoDownloader.DownloadedArray_1557.url", "http://veoh-106.v[…]
Second report, this one finished succesfully and took some time to complete:AdwCleaner[S2].txt
# AdwCleaner v2.009 - Fichero creado el 29/11/2012 a 21:20:40
# Actualizado el 24/11/2012 por Xplode
# Sistema operativo : Windows Vista ™ Home Premium (32 bits)
# Usuario : ASD-MASTER - ASD
# Modo de inicio : Normal
# Ejecutado desde : C:\d\adwcleaner.exe
# Opción [Supresión]
***** [Servicios] *****
***** [Ficheros / Carpetas] *****
***** [Registro] *****
***** [Navegadores] *****
-\\ Internet Explorer v7.0.6000.16757
[OK] El registro no contiene ninguna entrada ilegítima.
-\\ Mozilla Firefox v3.0.8 (es-ES)
Nombre del perfil : default
Fichero : C:\Users\ASD-MASTER\AppData\Roaming\Mozilla\Firefox\Profiles\u4qruwye.default\prefs.js
Supprimida : user_pref("SothinkWebVideoDownloaderWebVideoDownloader.DownloadedArray_1516.url", "hxxp://veoh-097.v[…]
Supprimida : user_pref("SothinkWebVideoDownloaderWebVideoDownloader.DownloadedArray_1557.url", "hxxp://veoh-106.v[…]
Supprimida : user_pref("extensions.snipit.askTbInstalled", true);
-\\ Opera v11.62.1347.0
Fichero : C:\Users\ASD-MASTER\AppData\Roaming\Opera\Opera\operaprefs.ini
[OK] El fichero no contiene ninguna entrada ilegítima.
*************************
AdwCleaner[S1].txt - [5351 octets] - [29/11/2012 20:44:53]
AdwCleaner[S2].txt - [1245 octets] - [29/11/2012 21:20:40]
########## EOF - C:\AdwCleaner[S2].txt - [1305 octets] ##########
✨ Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI