This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Norton scan finds Trojan.Kotver!gm2 - can't remove

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Norton scans find this item.  They say it has been removed and a restart is required to resolve the threat.  It does not get resolved with a restart and keeps turning up in subsequent scans.

 

My internet usage has recently  been 2X to 3X more than my normal daily highs.  I have not been using the internet any more than normal.  I suspect this Trojan is impacting my internet usage.

 

Requested logs are attached.

 

****************************************************************************

Norton has now found a new virus Kotver!bat

Hi and welcome

Can you give me any information for the items listed below?
 
Startup: C:\Users\Steve\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\68661.lnk [2016-10-08]
ShortcutTarget: 68661.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation)
Shortcut: C:\Users\Steve\AppData\Local\f2bd4\2fe07.lnk -> C:\Users\Steve\AppData\Local\f2bd4\79050.bat ()

I can't find any info on what they might be.
 
~~~
We need to uninstall this version of Java, later you can download the most current version.
Java 8 Update 101 (HKLM-x32\…\{26A24AE4-039D-4CA4-87B4-2F32180101F0}) (Version: 8.0.1010.13 - Oracle Corporation

~~~~~~~~~~~
Please print out or make a copy in notepad of any instructions given, as sometimes it is necessary to go offline and you will lose access to them.

Running from C:\Users\Steve\Downloads

It's best we move Farbar's to desktop.

Please go to your downloads folder, locate Farbar Recovery Scan Tool, right click and select CUT
Go to an open spot on your desktop, right click and select PASTE
You should now have Farbar Recovery Scan Tool on your desktop.


Please open Notepad *Do Not Use Wordpad!* or use any other text editor than Notepad or the script will fail. (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the quote box below:
To do this highlight the contents of the box and right click on it and select copy.
Paste this into the open notepad. save it to the Desktop as fixlist.txt
NOTE. It's important that both files, FRST/FRST64 and fixlist.txt are in the same location or the fix will not work.
It needs to be saved Next to the "Farbar Recovery Scan Tool" (If asked to overwrite existing one please allow)


[external image: FRSTfix.JPG]

 

start
CreateRestorePoint:
CloseProcesses:
HKLM-x32\…\Run: [] => [X]
HKU\S-1-5-21-670222586-3481561059-2212162056-1004\…\Run: [**srqpfrdrsr<*>] => "C:\Users\Steve\AppData\Local\f2bd4\2fe07.lnk" <===== ATTENTION (Value Name with invalid characters)
C:\Users\Steve\AppData\Local\f2bd4\2fe07.lnk
BHO-x32: No Name -> {02478D38-C3F9-4efb-9B51-7695ECA05670} -> No File
BHO-x32: ArcadeGiant Games -> {4FD3B33A-372C-439E-BB87-017365EC693C} -> C:\Users\Steve\AppData\Local\ArcadeGiant\agiantie.dll => No File
BHO-x32: Javaâ„¢ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_101\bin\ssv.dll [2016-07-22] (Oracle Corporation)
BHO-x32: Javaâ„¢ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_101\bin\jp2ssv.dll [2016-07-22] (Oracle Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.101.2 -> C:\Program Files (x86)\Java\jre1.8.0_101\bin\dtplugin\npDeployJava1.dll [2016-07-22] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.101.2 -> C:\Program Files (x86)\Java\jre1.8.0_101\bin\plugin2\npjp2.dll [2016-07-22] (Oracle Corporation)
CHR HKLM-x32\…\Chrome\Extension: [ihenkjeihefokohmemphikjnjbmegdik] - "C:\Program Files (x86)\Sony\Media Go\MediaGoDetector.crx"


Open FRST/FRST64 and press the > Fix < button just once and wait.
If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
When finished FRST will generate a log on the Desktop (Fixlog.txt). Please post it to your reply.

~~~~~~~~~~~~``

[external image: BY4dvz9.png]AdwCleaner
  • Please download AdwCleaner and save the file to your Desktop.
    In order to use AdwCleaner, you have to agree the Eula:
  • Right-click AdwCleaner.exe and select [external image: AVOiBNU.jpg] Run as administrator to run the programme.
  • Follow the prompts.
  • Click [external image: A49sxPr.png]Scan.
  • Upon completion, click [external image: 6cyn5v5.png]Logfile. A log (AdwCleaner[S1].txt) will open. Briefly check the log for anything you know to be legitimate.
  • Return to AdwCleaner. Ensure anything you know to be legitimate does not have a checkmark under the corresponding tab.
  • Click [external image: MqHawIb.png]Clean.
  • Follow the prompts and allow your computer to reboot.
  • After the reboot, a log (AdwCleaner[C1].txt) will open. Copy the contents of the log and paste in your next reply.
– File and folder backups are made for items removed using this programme. Should a legitimate file or folder be removed (otherwise known as a 'false-positive'), simple steps can be taken to restore the item. Please do not overly concern yourself with the contents of AdwCleaner[C1].txt.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Please download Junkware Removal Tool
or from here http://downloads.malwarebytes.org/file/jrt
to your desktop.
  • Shut down your protection software now to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.
~~
please post
Fixlog.txt
AdwCleaner[C1].txt
JRT.txt

Startup: C:\Users\Steve\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\68661.lnk [2016-10-08]
ShortcutTarget: 68661.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation)

 

This shortcut was created on the day my internet usage dramatically increased.  I don't know how it got created.  it points to a CMD.exe file that was created 11/20/2010.

 

Shortcut: C:\Users\Steve\AppData\Local\f2bd4\2fe07.lnk -> C:\Users\Steve\AppData\Local\f2bd4\79050.bat ()
 

I can't find it.  I believe one of the removal programs deleted it.

 

I ran the programs you indicated below.  Logs are attached.  On restart, I got a "windows can't open this file" error for file "bfb50.af8881".  I presume it had been removed by one of the programs.

 

 

 

 

Please download the Malwarebytes Anti-Malware setup file to your Desktop.

OR from this location Malwarebytes' Anti-Malware
  • Open mbam-setup.x.x.xxxx.exe (x represents the version #) and follow the prompts to install the programme.
  • On the Dashboard click on Update Now
  • Go to the Setting Tab
  • Under Setting go to Detection and Protection
  • Under PUP and PUM make sure both are set to show Treat Detections as Malware
  • Go to Advanced setting and make sure Automatically Quarantine Detected Items is checked
  • Then on the Dashboard click on Scan
  • Make sure to select THREAT SCAN
  • Then click on Scan
  • Note: You may see the following message, "Could not load DDA driver". Click Yes, allow your PC to reboot and continue afterwards.
  • If threats are detected, click Remove Selected. If you are prompted to reboot, click Yes.
  • Upon completion of the scan (or after the reboot), click the History tab.
  • Click Application Logs, followed by the first Scan Log.
  • Click Export, followed by Copy to Clipboard. Paste the log in your next reply.

~~~~~

The settings I suggest will also show us items located in quarantine folders so don't be alarmed with this, also, in case of a false positive I ask that you not allow it to delete what it does find.
This scanner can take quite a bit of time to run, depending of course how full your computer is.


Please download Emsisoft Emergency Kit and save it to your desktop.
Double click on the EmsisoftEmergencyKit file you downloaded to extract its contents and create a shortcut on the desktop.
  • Leave all settings as they are and click the Extract button at the bottom.
  • A folder named EEK will be created in the root of the drive (usually c:\).
  • After extraction please double-click on the new Start Emsisoft Emergency Kit icon on your desktop.
  • The first time you launch it, Emsisoft Emergency Kit will recommend that you allow it to download updates.
  • Please click Yes so that it downloads the latest database updates.
  • When the update process is complete, a new button will appear in the lower-left corner that says Back. Click on this button to return to the Overview screen.
  • Click on Scan to be taken to the scan options.
  • If you are asked if you want the scanner to scan for Potentially Unwanted Programs, then click Yes.
  • Click on the Malware Scan button to start the scan.
  • When the scan is completed click the View report button in the lower-right corner, and the scan log will be opened in Notepad.
  • Please save the log in Notepad on your desktop, and copy it to your next reply.
  • When you close Emsisoft Emergency Kit, it will give you an option to sign up for a newsletter. This is optional, and is not necessary for the malware removal process.
Let's see if we can find info on this file. My thoughts are it needs to be removed.

Please go to one of the below sites to scan the following files:
Virus Total (Recommended)
jotti.org
VirScan
click on Browse, and upload the following file for analysis:

C:\Users\Steve\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\68661.lnk


Then click Submit. Allow the file to be scanned, and then please copy and paste the results link (for Virus Total) here for me to see.
If it says already scanned – click "reanalyze now"
Please post the results in your next reply.

Malwarebytes Anti-Malware
www.malwarebytes.org

Scan Date: 10/13/2016
Scan Time: 3:12 PM
Logfile:
Administrator: Yes

Version: 2.2.1.1043
Malware Database: v2016.10.13.10
Rootkit Database: v2016.09.26.02
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled

OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Steve

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 341268
Time Elapsed: 7 min, 24 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 0
(No malicious items detected)

Registry Values: 1
PUP.Optional.VulnerableDellSystemDetect, HKU\S-1-5-21-670222586-3481561059-2212162056-1004\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|DellSystemDetect, C:\Users\Steve\AppData\Local\Apps\2.0\VLAE3XQW.Z60\C0NGL4EP.AW5\dell..tion_6d0a76327dca4869_0007.0009_d84bde3ab35e468d\DellSystemDetect.exe 4zZn5oeQk9WMM5ZBt7fsYA==, Quarantined, [38869afe9cfe0a2cb8966175a65d0000]

Registry Data: 0
(No malicious items detected)

Folders: 0
(No malicious items detected)

Files: 135
PUP.Optional.InstallCore, C:\Users\Steve\AppData\Roaming\FlvtoConverter\FlvtoConverterSetupV0.7.4.exe, Quarantined, [9d212573277362d40bc55adde71a7789],
Trojan.Agent.ENM, C:\Program Files (x86)\Internet Explorer\00000761.tmp, Quarantined, [f2ccf2a6b5e5dd59ec97cab7e021ea16],
Trojan.Agent.ENM, C:\Program Files (x86)\Internet Explorer\00000904.tmp, Quarantined, [ba043e5a405a1323b2d1eb9642bf619f],
Trojan.Agent.ENM, C:\Program Files (x86)\Internet Explorer\00001817.tmp, Quarantined, [d3ebc6d259415dd972115928669b4db3],
Trojan.Agent.ENM, C:\Program Files (x86)\Internet Explorer\00001945.tmp, Quarantined, [7a447e1a4f4b40f6b3d011708f723fc1],
Trojan.Agent.ENM, C:\Program Files (x86)\Internet Explorer\00001965.tmp, Quarantined, [06b8adeb4654ba7c6d16abd655ac6b95],
Trojan.Agent.ENM, C:\Program Files (x86)\Internet Explorer\00002052.tmp, Quarantined, [e5d9dfb9574340f6bcc7443d34cdb44c],
Trojan.Agent.ENM, C:\Program Files (x86)\Internet Explorer\00002110.tmp, Quarantined, [526cdeba237739fdb0d3661b9b66f60a],
Trojan.Agent.ENM, C:\Program Files (x86)\Internet Explorer\00005718.tmp, Quarantined, [09b5fc9c0b8f3ef89ce70879a160da26],
Trojan.Agent.ENM, C:\Program Files (x86)\Internet Explorer\00005909.tmp, Quarantined, [b905d3c5acee96a0fc87d2af8d7411ef],
Trojan.Agent.ENM, C:\Program Files (x86)\Internet Explorer\00006013.tmp, Quarantined, [12acfd9b45553006f192e39eaf52cb35],
Trojan.Agent.ENM, C:\Program Files (x86)\Internet Explorer\00007382.tmp, Quarantined, [8737bfd91c7e171f7e05c9b8bb46e31d],
Trojan.Agent.ENM, C:\Program Files (x86)\Internet Explorer\00009160.tmp, Quarantined, [dee09ff97a2094a2dfa4ee93639e41bf],
Trojan.Agent.ENM, C:\Program Files (x86)\Internet Explorer\00009477.tmp, Quarantined, [8f2f2c6cdac04bebc1c2bdc4748d04fc],
Trojan.Agent.ENM, C:\Program Files (x86)\Internet Explorer\00010515.tmp, Quarantined, [6a54bcdc4f4b3cfa3f445d2438c9bc44],
Trojan.Agent.ENM, C:\Program Files (x86)\Internet Explorer\00010697.tmp, Quarantined, [cdf18e0a396186b0c7bca2dfd22ff808],
Trojan.Agent.ENM, C:\Program Files (x86)\Internet Explorer\00010946.tmp, Quarantined, [a41a42564a50d85e671c84fd1fe2966a],
Trojan.Agent.ENM, C:\Program Files (x86)\Internet Explorer\00011271.tmp, Quarantined, [dce2dbbd1387df57b7cc720f728fbb45],
Trojan.Agent.ENM, C:\Program Files (x86)\Internet Explorer\00011532.tmp, Quarantined, [03bbc3d56f2b7fb7ec97e79af70a48b8],
Trojan.Agent.ENM, C:\Program Files (x86)\Internet Explorer\00011955.tmp, Quarantined, [823c0d8bedad95a19ee5b7caba47ac54],
Trojan.Agent.ENM, C:\Program Files (x86)\Internet Explorer\00012554.tmp, Quarantined, [ead44454a4f6b77f8cf7730eeb1636ca],
Trojan.Agent.ENM, C:\Program Files (x86)\Internet Explorer\00013519.tmp, Quarantined, [14aa1c7c4753f442087b0a77b64bf20e],
Trojan.Agent.ENM, C:\Program Files (x86)\Internet Explorer\00014268.tmp, Quarantined, [a31bddbb7228082ea2e15e23c9382bd5],
Trojan.Agent.ENM, C:\Program Files (x86)\Internet Explorer\00015222.tmp, Quarantined, [3985c3d59efcb086c4bf364b2fd228d8],
Trojan.Agent.ENM, C:\Program Files (x86)\Internet Explorer\00016379.tmp, Quarantined, [813df6a2475339fd364db4cd6d94f010],
Trojan.Agent.ENM, C:\Program Files (x86)\Internet Explorer\00016614.tmp, Quarantined, [13abc2d647531521a9daa4dd7f82de22],
Trojan.Agent.ENM, C:\Program Files (x86)\Internet Explorer\00016689.tmp, Quarantined, [fec06a2e62389b9b9ae91e63eb168b75],
Trojan.Agent.ENM, C:\Program Files (x86)\Internet Explorer\00016882.tmp, Quarantined, [be003a5e0991d1654043453cad5422de],
Trojan.Agent.ENM, C:\Program Files (x86)\Internet Explorer\00016973.tmp, Quarantined, [b40a22768e0ce25488fbbdc499689c64],
Trojan.Agent.ENM, C:\Program Files (x86)\Internet Explorer\00017393.tmp, Quarantined, [803e9dfb9cfebe7884fffb8603feb44c],
Trojan.Agent.ENM, C:\Program Files (x86)\Internet Explorer\00017852.tmp, Quarantined, [59654b4df0aa63d37310473ad03139c7],
Trojan.Agent.ENM, C:\Program Files (x86)\Internet Explorer\00017970.tmp, Quarantined, [edd1bcdcb1e91323cbb8f091b24fca36],
Trojan.Agent.ENM, C:\Program Files (x86)\Internet Explorer\00018243.tmp, Quarantined, [3e809cfc9dfd5adc84fffc85a55c2ed2],
Trojan.Agent.ENM, C:\Program Files (x86)\Internet Explorer\00022171.tmp, Quarantined, [45792771b6e41e187c0789f8da276997],
Trojan.Agent.ENM, C:\Program Files (x86)\Internet Explorer\00022934.tmp, Quarantined, [08b67f190b8ff2446b184e330ef32bd5],
Trojan.Agent.ENM, C:\Program Files (x86)\Internet Explorer\00023701.tmp, Quarantined, [17a77523cad0999ddea598e97190df21],
Trojan.Agent.ENM, C:\Program Files (x86)\Internet Explorer\00025797.tmp, Quarantined, [13abcace900a270fb5cea9d847bade22],
Trojan.Agent.ENM, C:\Program Files (x86)\Internet Explorer\00025852.tmp, Quarantined, [338b98008f0bb87eb5ce99e8917022de],
Trojan.Agent.ENM, C:\Program Files (x86)\Internet Explorer\00025866.tmp, Quarantined, [c1fddeba57435bdbd6ad30519b66fc04],
Trojan.Agent.ENM, C:\Program Files (x86)\Internet Explorer\00026392.tmp, Quarantined, [5f5f3860dcbe6fc71a69760b956c629e],
Trojan.Agent.ENM, C:\Program Files (x86)\Internet Explorer\00028148.tmp, Quarantined, [8f2f52469109280e265dfb86d9289070],
Trojan.Agent.ENM, C:\Program Files (x86)\Internet Explorer\00028403.tmp, Quarantined, [4c72d0c8edadb185166d90f1966b3ac6],
Trojan.Agent.ENM, C:\Program Files (x86)\Internet Explorer\00029507.tmp, Quarantined, [734bbcdc1684d462e59e3d44946d0cf4],
Trojan.Agent.ENM, C:\Program Files (x86)\Internet Explorer\00031387.tmp, Quarantined, [8b339afe900a4beb770c334e41c0ab55],
Trojan.Agent.ENM, C:\Program Files (x86)\Internet Explorer\00031643.tmp, Quarantined, [ac12afe98b0f4ee8bdc6552c788915eb],
Trojan.Agent.ENM, C:\Program Files (x86)\Internet Explorer\00014476.tmp, Quarantined, [d4eaa7f18d0d62d4c9ba4140c63bf40c],
Trojan.Agent.ENM, C:\Program Files (x86)\Internet Explorer\00023851.tmp, Quarantined, [f6c899ff970337ff6a195031936e837d],
Trojan.Agent.ENM, C:\Windows\SysWOW64\00028987.tmp, Quarantined, [536b0b8d45553bfbb1d2760b53ae649c],
Trojan.Agent.ENM, C:\Windows\SysWOW64\00029169.tmp, Quarantined, [ecd240587a20e155fd86d8a9d62bcf31],
Trojan.Agent.ENM, C:\Windows\SysWOW64\00029552.tmp, Quarantined, [fdc1ddbb4a5083b36e15b3ce669b22de],
Trojan.Agent.ENM, C:\Windows\SysWOW64\00030161.tmp, Quarantined, [ab136c2ccbcf2115aed51c654db405fb],
Trojan.Agent.ENM, C:\Windows\SysWOW64\00030403.tmp, Quarantined, [04baeaaec7d3c175d9aa7809c1407e82],
Trojan.Agent.ENM, C:\Windows\SysWOW64\00031523.tmp, Quarantined, [4f6f2b6d58420b2b562dcbb6ef120df3],
Trojan.Agent.ENM, C:\Windows\SysWOW64\00031778.tmp, Quarantined, [883622769efc1c1a285b8100f110768a],
Trojan.Agent.ENM, C:\Windows\SysWOW64\00032267.tmp, Quarantined, [536bc5d3bfdb14224e358af7d031c33d],
Trojan.Agent.ENM, C:\Windows\SysWOW64\00032694.tmp, Quarantined, [8a34b2e6009a62d45330e0a10df48e72],
Trojan.Agent.ENM, C:\Windows\SysWOW64\00013703.tmp, Quarantined, [3e809305e2b81a1c0b78f9882dd4b24e],
Trojan.Agent.ENM, C:\Windows\SysWOW64\00019933.tmp, Quarantined, [843a5c3cb0ea2016cdb60f7247ba42be],
Trojan.Agent.ENM, C:\Windows\SysWOW64\00028686.tmp, Quarantined, [8f2f6434d6c4a690c8bbc4bdb24f38c8],
Trojan.Agent.ENM, C:\Windows\SysWOW64\00000882.tmp, Quarantined, [2f8fdbbdbae0dc5a88fbe59ce71ad52b],
Trojan.Agent.ENM, C:\Windows\SysWOW64\00001052.tmp, Quarantined, [13ab791f128856e0aed5c0c19170629e],
Trojan.Agent.ENM, C:\Windows\SysWOW64\00001344.tmp, Quarantined, [5d61eeaac9d132044241f38eab5628d8],
Trojan.Agent.ENM, C:\Windows\SysWOW64\00001869.tmp, Quarantined, [b20cd1c76733fd39d1b22f5260a1b64a],
Trojan.Agent.ENM, C:\Windows\SysWOW64\00001995.tmp, Quarantined, [18a633654d4de74f9fe4c4bd70919967],
Trojan.Agent.ENM, C:\Windows\SysWOW64\00002029.tmp, Quarantined, [08b61d7be2b8092d8bf83a47e31e8e72],
Trojan.Agent.ENM, C:\Windows\SysWOW64\00002154.tmp, Quarantined, [dce27028128884b2572c156c0df4fa06],
Trojan.Agent.ENM, C:\Windows\SysWOW64\00002285.tmp, Quarantined, [59659602d5c53ef8c2c1f091bd44d828],
Trojan.Agent.ENM, C:\Windows\SysWOW64\00002380.tmp, Quarantined, [8e3040588614d660d6ad661b12ef2cd4],
Trojan.Agent.ENM, C:\Windows\SysWOW64\00002724.tmp, Quarantined, [f6c8d5c3f2a8ee48b1d2fe833ec3728e],
Trojan.Agent.ENM, C:\Windows\SysWOW64\00002945.tmp, Quarantined, [a41a60389dfda096374c2f5229d8a65a],
Trojan.Agent.ENM, C:\Windows\SysWOW64\00003032.tmp, Quarantined, [d7e7a8f0c6d483b35033cab7cf32bb45],
Trojan.Agent.ENM, C:\Windows\SysWOW64\00003054.tmp, Quarantined, [d9e55b3d6139a19570138df4e51cba46],
Trojan.Agent.ENM, C:\Windows\SysWOW64\00003793.tmp, Quarantined, [caf43e5abedc2c0a463df190c73a7987],
Trojan.Agent.ENM, C:\Windows\SysWOW64\00004681.tmp, Quarantined, [1da17b1d0e8c37ff245ffe83c43d7789],
Trojan.Agent.ENM, C:\Windows\SysWOW64\00005537.tmp, Quarantined, [e6d8a8f00f8b082e384bec95bf424fb1],
Trojan.Agent.ENM, C:\Windows\SysWOW64\00005708.tmp, Quarantined, [8638cdcb2b6f9a9c275c7d0491709f61],
Trojan.Agent.ENM, C:\Windows\SysWOW64\00006158.tmp, Quarantined, [7b43d2c6d7c3af875e25e59c2ad743bd],
Trojan.Agent.ENM, C:\Windows\SysWOW64\00006172.tmp, Quarantined, [12acb7e1722885b1c8bbea97e021f60a],
Trojan.Agent.ENM, C:\Windows\SysWOW64\00006658.tmp, Quarantined, [6757158309912d09f48fb7caa25fc53b],
Trojan.Agent.ENM, C:\Windows\SysWOW64\00006682.tmp, Quarantined, [07b75642821869cd2c57c5bca75a58a8],
Trojan.Agent.ENM, C:\Windows\SysWOW64\00007048.tmp, Quarantined, [4a740890fc9e81b5a7dc1d64c73adf21],
Trojan.Agent.ENM, C:\Windows\SysWOW64\00007755.tmp, Quarantined, [4b73395fc2d8a195d2b1c7bacb36a858],
Trojan.Agent.ENM, C:\Windows\SysWOW64\00007791.tmp, Quarantined, [d4ea4751fb9f1c1adda6067b17ea8878],
Trojan.Agent.ENM, C:\Windows\SysWOW64\00008285.tmp, Quarantined, [516d84149a0092a40380ff82cb36f907],
Trojan.Agent.ENM, C:\Windows\SysWOW64\00008780.tmp, Quarantined, [d3eb66327822a98de79c6e13ae53e41c],
Trojan.Agent.ENM, C:\Windows\SysWOW64\00008875.tmp, Quarantined, [dbe33563c0da0f276e15e8998c75b947],
Trojan.Agent.ENM, C:\Windows\SysWOW64\00009508.tmp, Quarantined, [c7f79107f1a90135cbb89fe290718c74],
Trojan.Agent.ENM, C:\Windows\SysWOW64\00009650.tmp, Quarantined, [3d81b5e3b1e9ff37cdb6750cd031e61a],
Trojan.Agent.ENM, C:\Windows\SysWOW64\00012047.tmp, Quarantined, [8c3287115e3cbd793053c6bb956c8e72],
Trojan.Agent.ENM, C:\Windows\SysWOW64\00012271.tmp, Quarantined, [1ba3aeea1882ef47552ebac716eb6799],
Trojan.Agent.ENM, C:\Windows\SysWOW64\00012906.tmp, Quarantined, [dce22d6b9cfe092dbbc8b6cb7a87738d],
Trojan.Agent.ENM, C:\Windows\SysWOW64\00013194.tmp, Quarantined, [932b76220c8e4de9661d3849cb36ff01],
Trojan.Agent.ENM, C:\Windows\SysWOW64\00013331.tmp, Quarantined, [239b0197188266d0592a334e09f844bc],
Trojan.Agent.ENM, C:\Windows\SysWOW64\00013389.tmp, Quarantined, [a01e8e0a851551e5542f295849b825db],
Trojan.Agent.ENM, C:\Windows\SysWOW64\00013735.tmp, Quarantined, [bb031d7bcad0989e9be8ed946a977c84],
Trojan.Agent.ENM, C:\Windows\SysWOW64\00013744.tmp, Quarantined, [02bc7a1e178353e3c3c00b7668995da3],
Trojan.Agent.ENM, C:\Windows\SysWOW64\00015031.tmp, Quarantined, [dbe31484f2a838fe7c07d5ac54ad4bb5],
Trojan.Agent.ENM, C:\Windows\SysWOW64\00015109.tmp, Quarantined, [07b747516d2dba7c91f2780956ab4fb1],
Trojan.Agent.ENM, C:\Windows\SysWOW64\00015414.tmp, Quarantined, [417df4a4d3c7c175b4cf7908b948ae52],
Trojan.Agent.ENM, C:\Windows\SysWOW64\00015444.tmp, Quarantined, [b10dafe9a5f559dd2360bfc28a7749b7],
Trojan.Agent.ENM, C:\Windows\SysWOW64\00015580.tmp, Quarantined, [3f7fb5e34d4d71c5ee952f52aa57a759],
Trojan.Agent.ENM, C:\Windows\SysWOW64\00015879.tmp, Quarantined, [e2dc4652ccce89ad6221d2afbe4337c9],
Trojan.Agent.ENM, C:\Windows\SysWOW64\00016177.tmp, Quarantined, [f9c5ecac7822ba7c7e05dda4b9482ed2],
Trojan.Agent.ENM, C:\Windows\SysWOW64\00016213.tmp, Quarantined, [635b2375b2e8a690562db0d1d9288f71],
Trojan.Agent.ENM, C:\Windows\SysWOW64\00017365.tmp, Quarantined, [03bbd4c4e6b4fc3af48f087931d0a858],
Trojan.Agent.ENM, C:\Windows\SysWOW64\00017729.tmp, Quarantined, [a519b1e70b8f52e4add6641d2cd5a25e],
Trojan.Agent.ENM, C:\Windows\SysWOW64\00018072.tmp, Quarantined, [59655642f1a92115d2b1235e758c41bf],
Trojan.Agent.ENM, C:\Windows\SysWOW64\00018279.tmp, Quarantined, [cfefafe9c6d464d2dda63e43778a29d7],
Trojan.Agent.ENM, C:\Windows\SysWOW64\00018741.tmp, Quarantined, [8d319404bddd979fc9bad5aca9589e62],
Trojan.Agent.ENM, C:\Windows\SysWOW64\00018953.tmp, Quarantined, [615d8b0dbfdb7eb8255e85fc29d89b65],
Trojan.Agent.ENM, C:\Windows\SysWOW64\00019027.tmp, Quarantined, [5b63b3e5d1c93501245f532e877af010],
Trojan.Agent.ENM, C:\Windows\SysWOW64\00019534.tmp, Quarantined, [774718806a3090a67112126fee1357a9],
Trojan.Agent.ENM, C:\Windows\SysWOW64\00019854.tmp, Quarantined, [b10d6038f2a8072facd7eb96e61b55ab],
Trojan.Agent.ENM, C:\Windows\SysWOW64\00019906.tmp, Quarantined, [4d710890f5a50036a3e06e1309f87090],
Trojan.Agent.ENM, C:\Windows\SysWOW64\00020154.tmp, Quarantined, [c8f6e4b42f6bef47d2b1e79a3dc4c13f],
Trojan.Agent.ENM, C:\Windows\SysWOW64\00020367.tmp, Quarantined, [823c514706940a2c7f04047db150629e],
Trojan.Agent.ENM, C:\Windows\SysWOW64\00021042.tmp, Quarantined, [cfef2d6b1c7eea4cc6bda1e0cc35b24e],
Trojan.Agent.ENM, C:\Windows\SysWOW64\00021878.tmp, Quarantined, [c6f82672158589addba8f0914fb27c84],
Trojan.Agent.ENM, C:\Windows\SysWOW64\00022020.tmp, Quarantined, [8c32d2c64b4f1422d7ac057c9f62ba46],
Trojan.Agent.ENM, C:\Windows\SysWOW64\00024106.tmp, Quarantined, [d8e6930527731a1c84ff4140d62b28d8],
Trojan.Agent.ENM, C:\Windows\SysWOW64\00024268.tmp, Quarantined, [04ba3f596f2ba78f8201414006fb2bd5],
Trojan.Agent.ENM, C:\Windows\SysWOW64\00024434.tmp, Quarantined, [8d31f0a821791026315208799e638c74],
Trojan.Agent.ENM, C:\Windows\SysWOW64\00024681.tmp, Quarantined, [b6082771e2b87eb8bcc74a37a55cf50b],
Trojan.Agent.ENM, C:\Windows\SysWOW64\00024930.tmp, Quarantined, [b608fd9b6d2d4fe7dfa4fb865ea316ea],
Trojan.Agent.ENM, C:\Windows\SysWOW64\00024975.tmp, Quarantined, [fec011876238989e711293ee15ec36ca],
Trojan.Agent.ENM, C:\Windows\SysWOW64\00025198.tmp, Quarantined, [02bc5c3c2179ab8bf291bbc6c1408779],
Trojan.Agent.ENM, C:\Windows\SysWOW64\00025329.tmp, Quarantined, [249a5642f1a9181ebfc44041a16020e0],
Trojan.Agent.ENM, C:\Windows\SysWOW64\00025589.tmp, Quarantined, [eed0d2c66a30d6608ef53948ac55ad53],
Trojan.Agent.ENM, C:\Windows\SysWOW64\00025883.tmp, Quarantined, [4d717b1d0199ce68cdb6d1b06998d62a],
Trojan.Agent.ENM, C:\Windows\SysWOW64\00026391.tmp, Quarantined, [249a6c2cb3e7b77fb6cdfb8628d942be],
Trojan.Agent.ENM, C:\Windows\SysWOW64\00026527.tmp, Quarantined, [f6c87e1a06940b2b72110180e21f7888],
Trojan.Agent.ENM, C:\Windows\SysWOW64\00026789.tmp, Quarantined, [c9f5f1a794067db9aad9b6cb12eff60a],
Trojan.Agent.ENM, C:\Windows\SysWOW64\00028427.tmp, Quarantined, [2a94b4e48a1088ae7e05ceb37190dc24],
PUP.Optional.InstallCore, C:\Users\Steve\AppData\Local\Flvto Youtube Downloader\FlvtoConverterSetupV0.7.2.exe, Quarantined, [e5d9f6a2bfdbe254d3fd2d0a45bc27d9],
Trojan.Agent, C:\Users\Steve\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\68661.lnk, Quarantined, [407e7820900a3bfb9bf60116867d7888],

Physical Sectors: 0
(No malicious items detected)

(end)

*************************************************************************************************************************

 

Emsisoft Emergency Kit - Version 11.9
Last update: 10/13/2016 3:41:30 PM
User account: MININT-UVO9P79\Steve
Computer name: MININT-UVO9P79
OS version: Windows 7x64 Service Pack 1

Scan settings:

Scan type: Malware Scan
Objects: Rootkits, Memory, Traces, Files

Detect PUPs: On
Scan archives: Off
ADS Scan: On
File extension filter: Off
Advanced caching: On
Direct disk access: Off

Scan start: 10/13/2016 3:43:44 PM
C:\ProgramData\free youtube downloader  detected: Application.AppInstall (A)
Key: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432NODE\FREE YOUTUBE DOWNLOADER  detected: Application.InstallAd (A)

Scanned 75613
Found 2

Scan end: 10/13/2016 3:47:21 PM
Scan time: 0:03:37

The computer seems to be OK now.  I can't check yesterdays internet usage until my provider updates his usage charts.  I'll check that over the weekend. 

 

Can I reload Java?

 

Your help was timely, very effective and not as difficult to execute as I had feared.  The comprehensive detail of your instructions were great.  Thank you very much. 

 

I use Norton anti-virus.  This is the first virus I have had in a long time.  Which of the products that you had me use would you recommend that I use whenever Norton can't resolve a problem. 

We're glad to help.

As for Norton's….sometimes it's a matter of what you get used to and happy with. I know in the past people were unhappy about the resources it hogged to update and monitor a computer and, at times it's detection rate was poor.
If it has improved it's services, then it's up to the user at that time.
 
Also, I can supply you with a list of antivirus that work along with Windows 7 to show you available options.
 
*****
When we remove tools and quarantine folders I'll also post tips of other tools (layered protection which includes Malwarebytes Anti-Malware) you can use along with your antivirus to help secure your computer.
~~~~~~~~~~

I would recommend that you disable Java in your browsers until you need it for that software and then enable it. (See How to disable Java in your web browser and How to unplug Java from the browser)

If you do need to keep Java then download JavaRa
Run the programme and select Remove Java Runtime. Uninstall all versions of Java present
Once done then run it again and select Update Java runtime then Download and install Latest version.

If the latest version is not available through JavaRa
  • Click here then click Verify Java version
  • If you are notified your Java version is out of date click Update (recommended)
  • Click Agree and Start Free Java Download
  • Save jxpiinstall.exe to your desktop
  • Double click the icon then click Install
  • Uncheck all optional offers
  • Click Next
  • Once completed you should be notified You have successfully installed Java
  • If Java notifies you older versions of the program need to be removed check each of the versions and click Uninstall
  • Verify the older version(s) was uninstalled then click Next
  • Click Close
  • Please download DelFix or from Here and save the file to your Desktop.
  • Double-click DelFix.exe to run the programme.
  • Place a checkmark next to the following items:
  • Activate UAC
  • Remove disinfection tools
  • Click the Run button.
  • – This will remove the specialized tools we used to disinfect your system.
    Any leftover logs, files, folders or tools remaining on your Desktop which were not removed can be deleted manually (right-click the file + delete
    ).
***************
  • Answers to common security questions - Best Practices by quietman7, MVP
  • How Malware Spreads - How did I get infected? by quietman7, MVP
  • Simple and easy ways to keep your computer safe and secure on the Internet by Lawrence Abrams, MVP
  • How to Prevent Malware by miekiemoes, MVP
  • How to backup and restore your data using Cobian Backup by YourHighness
  • Slow Computer/browser? It May Not Be Malware by quietman7, MVP
  • AdBlock is a browser add-on that blocks annoying banners, pop-ups and video ads.
  • [external image: E8I37RF.png]CryptoPrevent places policy restrictions on loading points for ransomware (eg. CryptoWall), helping prevent the execution of malware.
  • [external image: EG85Vjt.png]Malwarebytes Anti-Exploit (MBAE) is designed to prevent zero-day malware from exploiting vulnerable software.
  • [external image: 6YRrgUC.png]Malwarebytes Anti-Malware Premium (MBAM) works in real-time along side your Anti-Virus to prevent malware execution.
  • [external image: jv4nhMJ.png]NoScript is a Firefox add-on that blocks the actions of malicious scripts by using whitelisting and other technology.
  • [external image: 3O8r9Uq.png] Sandboxie isolates programmes of your choice, preventing files from being written to your HDD unless approved by you.
  • [external image: DgW1XL2.png]Secunia PSI will scan your computer for vulnerable software that is outdated, and automatically find the latest update for you.
  • [external image: j1OLIec.png]SpywareBlaster is a form of passive protection, designed to block the actions of malicious websites and tracking cookies.
  • [external image: sHjS79L.png]Unchecky automatically removes checkmarks for bunlded software in programme installers; helping you avoid adware and PUPs.
  • [external image: JEP5iWI.png]Web of Trust (WOT) is a browser add-on designed to alert you before interacting with a potentially malicious website.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI