This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

ınfected wıth several virus [Closed]

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

ı made a scan wıth eset online scanner and the result is below pls help me C:\Microgaming\Poker\Bets10PokerMPP\install.exe a variant of Win32/PrimeCasino application C:\Program Files\GoforFiles\uninstall.exe a variant of Win32/ExpressFiles.B application C:\Program Files\MyTools\searchInstaller.exe a variant of Win32/Toolbar.GadgetBox.C application C:\Users\erhan\AppData\Local\Temp\Rar$EX45.197\FlashPlayers.exe probably a variant of Win32/Downloader.VB.C application C:\Users\erhan\AppData\Roaming\DealPly\UpdateProc\UpdateTask.exe Win32/InstallCore.BM application C:\Users\erhan\Desktop\Bets10Poker.exe a variant of Win32/PrimeCasino application C:\Users\erhan\downloads\FlashPlayers.rar probably a variant of Win32/Downloader.VB.C application C:\Users\erhan\downloads\Compressed\photoshop\AdobePhotoshopLightroom 3.4.1Final.DepoDepo.DUNC4N.part1.rar a variant of Win32/Keygen.BH application C:\Users\erhan\downloads\Compressed\photoshop\AdobePhotoshopLightroom 3.4.1Final.DepoDepo.DUNC4N\Adobe Photoshop Lightroom 3.4.1 Final\keygen.exe a variant of Win32/Keygen.BH application C:\Users\erhan\downloads\Programs\DownloadSetup.exe Win32/Adware.1ClickDownload.C application C:\Users\erhan\downloads\Programs\Online-TV.exe a variant of Win32/Qhost.PEV trojan C:\Users\erhan\downloads\Programs\Total-Video-Converter-Tamindir.exe a variant of Win32/ELEX application C:\Users\erhan\downloads\Programs\vshare-plugin.exe Win32/TopMedia.A application C:\Windows.old\Documents and Settings\erhan\AppData\Local\Temp\Rar$EX45.197\FlashPlayers.exe probably a variant of Win32/Downloader.VB.C application C:\Windows.old\Documents and Settings\erhan\AppData\Roaming\DealPly\UpdateProc\UpdateTask.exe Win32/InstallCore.BM application C:\Windows.old\Documents and Settings\erhan\Desktop\Bets10Poker.exe a variant of Win32/PrimeCasino application C:\Windows.old\Documents and Settings\erhan\downloads\FlashPlayers.rar probably a variant of Win32/Downloader.VB.C application C:\Windows.old\Documents and Settings\erhan\downloads\Compressed\photoshop\AdobePhotoshopLightroom 3.4.1Final.DepoDepo.DUNC4N.part1.rar a variant of Win32/Keygen.BH application C:\Windows.old\Documents and Settings\erhan\downloads\Compressed\photoshop\AdobePhotoshopLightroom 3.4.1Final.DepoDepo.DUNC4N\Adobe Photoshop Lightroom 3.4.1 Final\keygen.exe a variant of Win32/Keygen.BH application C:\Windows.old\Documents and Settings\erhan\downloads\Programs\DownloadSetup.exe Win32/Adware.1ClickDownload.C application C:\Windows.old\Documents and Settings\erhan\downloads\Programs\Online-TV.exe a variant of Win32/Qhost.PEV trojan C:\Windows.old\Documents and Settings\erhan\downloads\Programs\Total-Video-Converter-Tamindir.exe a variant of Win32/ELEX application C:\Windows.old\Documents and Settings\erhan\downloads\Programs\vshare-plugin.exe Win32/TopMedia.A application C:\Windows.old\Users\erhan\AppData\Local\Application Data\Temp\Rar$EX45.197\FlashPlayers.exe probably a variant of Win32/Downloader.VB.C application C:\Windows.old\Users\erhan\Application Data\DealPly\UpdateProc\UpdateTask.exe Win32/InstallCore.BM application C:\Windows.old\Users\erhan\Desktop\desktop\Setup_FreeBurner.exe Win32/Toolbar.Widgi application C:\Windows.old\Users\erhan\Desktop\desktop\Ableton Live 7.0.2 Cracked Installer-AiR\setup.exe probably a variant of Win32/Agent.FGDSVNW trojan C:\Windows.old\Users\erhan\Local Settings\Temp\Rar$EX45.197\FlashPlayers.exe probably a variant of Win32/Downloader.VB.C application E:\Ableton Live 7.0.2 Cracked Installer-AiR\setup.exe probably a variant of Win32/Agent.FGDSVNW trojan
Hello erhan. Posted Image

My name is fbfbfb. I will gladly assist you with your concerns.

Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advice. This may cause a delay, but I will do my best to keep it as short as possible.

I am checking over your ESET log now, and I will post back shortly with instructions.

While working to resolve the issues with your machine, please follow these guidelines:
  • Please be patient. Logs are lengthy and can take time to analyze.
  • Read and follow my directions carefully, in the sequence they are posted.
  • If you are unsure about anything, please ask for clarification before continuing.
  • Use only those tools that you have been directed to use.
  • Do not install or uninstall any applications or run any other scans without being directed to do so.
  • Copy and Paste the log files inside your post. Do not send them as attachments unless otherwise instructed.
  • Stay with me until your machine has been deemed all clear.
  • Please reply within 3 days to avoid closing this topic.
Hello, erhan.

I apologize for the delay. I would like to take a closer look at your system.

Please run the following scans

Please download DDS from HERE and save it to your desktop.
  • Disable any script blocking protection. How to Disable your Security Programs, Antivirus/Firewalls/AntiMalware Programs ( http://forums.whatthetech.com/index.php?showtopic=96260)
  • Double click dds.scr to run the tool.
  • When done, DDS.txt will open.
  • Click Yes at the next prompt for Optional Scan.
  • When done, Attach.txt will open.
Please copy and paste the scan results of DDS.txt.

Please attach the second file: Attach.txt.

To attach a file, do the following:
  • Under the reply panel is the Attachments Panel.
  • Browse for the attachment file you want to upload, then click the green Upload button.
  • Once it has uploaded, click the Manage Current Attachments drop down box.
  • Click on [external image: Posted Image] to insert the attachment into your post.
2. aswMBR

Please download aswMBR from HERE.
  • Double click aswMBR.exe to run it.
  • When asked if you want to download Avast's virus definitions, please select Yes.
  • Click the Scan button to start the scan.
[external image: Posted Image]
  • On completion of the scan, click save log, save it to your desktop, and post in your next reply.
[external image: Posted Image]
Hello, erhan.

Thank you for the logs. Please run the following scan.

ComboFix

Note: Before you begin, please read through these instructions completely, noting all important messages and warnings.
  • Please download ComboFix from HERE or HERE.
Very Important! Save ComboFix.exe to to your Desktop.
  • Close all browsers.
  • Disable your AntiVirus and AntiSpyware applications as they can interfere with running ComboFix. To disable any security programs:

  • Right click on the System Tray icon, or
  • Refer to this link HERE for further assistance.

  • Double click on ComboFix.exe and follow the prompts.
  • When finished, ComboFix will produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Warnings:
  • Do not mouse-click on ComboFix's window while it is running. This may cause it to stall.
  • Do not re-run ComboFix. If problems occur with the installation or running of ComboFix, please reply back for further instructions.
  • Do not attempt to surf the internet while ComboFix is scanning.

Note: If there is no internet connection after running ComboFix, reboot your computer to restore the connection.

Very Important! Make sure you re-enable your security programs when ComboFix is finished.
Hello, erhan.

Thank you for the CF log. Please copy and paste your log reports into all future replies instead of attaching them.

Please run the following scans

1. ComboFix

Very Important!

Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix and can cause unpredictable results.

Please open Notepad:
  • Start > Run.
  • Type notepad in the Open field
  • Click OK.
  • Copy and paste the text inside the code box below:
KillAll::

ClearJavaCache::

File::
c:\program files\Hotspot_Shield\prxtbHots.dll

Registry::
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{c95a4e8e-816d-4655-8c79-d736da1adb6d}"=-

[-HKEY_CLASSES_ROOT\clsid\{c95a4e8e-816d-4655-8c79-d736da1adb6d}]

[-HKEY_LOCAL_MACHINE\SOFTWARE\~\Browser Helper Objects\{c95a4e8e-816d-4655-8c79-d736da1adb6d}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{c95a4e8e-816d-4655-8c79-d736da1adb6d}"=-

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{C95A4E8E-816D-4655-8C79-D736DA1ADB6D}"=-
  • Save this as CFScript.txt to your desktop and change the "Save as type" to All Files.
  • Drag the CFScript.txt into ComboFix.exe as shown in the screenshot below:

[external image: Posted Image]

  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, ComboFix will produce a log for you. Copy and paste the contents of the log in your next reply.
WARNING
  • Do not mouse-click ComboFix's window while it is running. This may cause it to stall.
  • Do not attempt to surf the internet while ComboFix is scanning.
Very Important! Make sure you re-enable your security programs when ComboFix is finished.

2. Junkware Removal Tool

Please download Junkware Removal Tool from HERE and save it to your desktop.
  • Shutdown your antivirus to avoid any potential conflicts.
  • Right-mouse click JRT.exe and select Run as Administrator.
  • JRTwill begin to backup your registry and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, the log JRT.txt is saved on your desktop and will automatically open.
Post the contents of JRT.txt into your next reply.

3. AdwCleaner

Please download AdwCleaner from HERE.
  • Close all open programs and internet browsers.
  • Double click on adwcleaner.exe to run the tool.
  • Click on the Delete button.
  • A logfile will automatically open after the scan has finished.
  • You can also find the logfile at C:\AdwCleaner[S1].txt.
Copy and paste the adwcleaner.txt report into your next reply.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI