This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Trojan virus x4 - need help

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi and welcome, sorry for the wait.

When Farbar Recovery Scan Tool was run it should had also created FRST.txt
Can you post this log please.
By chance can you copy the report from AVG to show me the file paths?


Start Farbar Recovery Scan Tool with Administrator privileges
(Right click on the FRST icon and select Run as administrator)

highlight on the text below and select Copy.
beginning with Start:: and finishing with End::


Start::
CloseProcesses:
CreateRestorePoint:
ShortcutWithArgument: C:\Users\Tami\Desktop\Whole30\Recipe Index - Bravo For Paleo.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> –profile-directory=Default –app-id=nbmjacjjhcghfhaifleccehpcankbibp
ShortcutWithArgument: C:\Users\Tami\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Recipe Index - Bravo For Paleo.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> –profile-directory=Default –app-id=nbmjacjjhcghfhaifleccehpcankbibp
CHR HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
SearchScopes: HKLM -> {2F1E335A-858A-4BE9-8F6B-D0AF1D018B53} URL = hxxp://www.bing.com/search?q={searchTerms}&form=DLCDF8&pc=MDDC&src=IE-SearchBox
SearchScopes: HKLM-x32 -> {2F1E335A-858A-4BE9-8F6B-D0AF1D018B53} URL = hxxp://www.bing.com/search?q={searchTerms}&form=DLCDF8&pc=MDDC&src=IE-SearchBox
SearchScopes: HKU\S-1-5-21-3101223633-2765994983-3815756064-1000 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-3101223633-2765994983-3815756064-1000 -> {95B7759C-8C7F-4BF1-B163-73684A933233} URL = hxxp://mysearch.avg.com/search?cid={E9BEEE79-422D-4C81-9DAD-9C6526426EA9}&mid=101fd56740d247d1a9759dc9d5a8ce9e-8fd091d8f95dfedd9a2ab6851ad36a7aee43e91f&lang=en&ds=AVG&pr=pr&d=2013-03-20 18:02:42&v=17.1.3.2&pid=safeguard&sg=0&sap=dsp&q={searchTerms}
BHO: AVG Safe Search -> {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} -> C:\Program Files (x86)\AVG\AVG2012\avgssiea.dll => No File
BHO: Javaâ„¢ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre6\bin\jp2ssv.dll [2011-12-14] (Sun Microsystems, Inc.)
BHO-x32: AVG Safe Search -> {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} -> C:\Program Files (x86)\AVG\AVG2012\avgssie.dll => No File
BHO-x32: Javaâ„¢ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2011-12-14] (Sun Microsystems, Inc.)
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll No File
FF Plugin: @java.com/JavaPlugin -> C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll [2011-12-14] (Sun Microsystems, Inc.)
FF Plugin-x32: @avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin -> C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\190.7.0\\npsitesafety.dll [No File]
FF Plugin-x32: @java.com/JavaPlugin -> C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll [2011-12-14] (Sun Microsystems, Inc.)
2015-04-23 19:12 - 2015-01-16 08:40 - 000089552 _____ (AVG Technologies CZ, s.r.o.) C:\Users\Tami\AppData\Local\Temp\avguirn_081054870176.exe
2016-08-24 08:40 - 2016-07-20 13:01 - 000186640 _____ (AVG Technologies CZ, s.r.o.) C:\Users\Tami\AppData\Local\Temp\avguirn_081717981843.exe
2016-06-24 14:49 - 2016-05-18 12:03 - 000186640 _____ (AVG Technologies CZ, s.r.o.) C:\Users\Tami\AppData\Local\Temp\avguirn_081722879209.exe
2015-08-24 17:36 - 2015-04-07 14:25 - 000089552 _____ (AVG Technologies CZ, s.r.o.) C:\Users\Tami\AppData\Local\Temp\avguirn_081733148651.exe
2016-05-31 16:52 - 2016-04-22 09:01 - 000186640 _____ (AVG Technologies CZ, s.r.o.) C:\Users\Tami\AppData\Local\Temp\avguirn_081996311200.exe
2015-09-16 16:48 - 2015-08-20 15:32 - 000091048 _____ (AVG Technologies CZ, s.r.o.) C:\Users\Tami\AppData\Local\Temp\avguirn_082048358536.exe
2016-07-29 16:51 - 2016-06-21 17:49 - 000186640 _____ (AVG Technologies CZ, s.r.o.) C:\Users\Tami\AppData\Local\Temp\avguirn_08398654403.exe
2015-11-19 20:12 - 2015-10-16 12:30 - 000091048 _____ (AVG Technologies CZ, s.r.o.) C:\Users\Tami\AppData\Local\Temp\avguirn_08480662370.exe
2016-05-19 10:08 - 2016-05-19 10:08 - 000205656 _____ (SlimWare Utilities, Inc.) C:\Users\Tami\AppData\Local\Temp\scpE65A.tmp.exe
Emptytemp:
End::


Press the Fix button.
If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
When finished FRST will generate a log on the Desktop (Fixlog.txt). Please post it to your reply.



******
[external image: zcMPezJ.png]AdwCleaner
  • Download AdwCleaner and move it to your Desktop
  • Right-click on AdwCleaner.exe and select [external image: Spcusrh.png]Run as Administrator (for Windows Vista, 7, 8, 8.1 and 10 users)
  • Accept the EULA (I accept), then click on Scan
  • Let the scan complete. Once it's done, make sure that every item listed in the different tabs is checked and click on the Clean button. This will kill all active processes
    🖼Click to load external image (V7SD4El.png)
  • Once the cleaning process is complete, AdwCleaner will ask to restart your computer, do it
  • After the restart, a log will open when logging in. Please copy/paste the content of that log in your next reply
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~`
[external image: RQKuhw1.png]RogueKiller
  • Download the right version of RogueKiller for your Windows version (32 or 64-bit)
  • or from Here
  • Once done, move the executable file to your Desktop, right-click on it and select [external image: Spcusrh.png]Run as Administrator (for Windows Vista, 7, 8, 8.1 and 10 users)
  • Click on the Start Scan button in the right panel, which will bring you to another tab, and click on it again (this time it'll be in the bottom right corner)
  • Wait for the scan to complete
  • On completion, the results will be displayed
  • Check every single entry (threat found), and click on the Remove Selected button
  • On completion, the results will be displayed. Click on the Open Report button in the bottom left corner, followed by the Open TXT button (also in the bottom left corner)
  • This will open the report in Notepad. Copy/paste its content in your next reply
created by Aura
 
please post
Fixlog.txt
AdwCleaner log
RogueKiller log
Fix result of Farbar Recovery Scan Tool (x64) Version: 14.01.2018
Ran by [removed] (15-01-2018 16:22:21) Run:1
Running from C:\Users\[removed]\Downloads
[removed]
Let's check for remnants

[external image: G0tu5D9.png]Emsisoft Emergency Kit
Follow the instructions below to run a scan using the Emsisoft Emergency Kit.
  • Download the Emsisoft Emergency Kit and execute it. From there, click on the Install button to extract the program in the EEK folder;
  • Once the extraction is complete, the EEK folder will open. Right-click on [external image: G0tu5D9.png]start emergency kit scanner.exe and select [external image: Spcusrh.png]Run as Administrator (for Windows Vista, 7, 8, 8.1 and 10 users);
  • EEK will suggest that you run an online update before using the program. Click on Yes to launch it.
  • After the update, click on Malware Scan under 2. Scan and accept to let EEK detect PUPs (click on Yes).
  • Once the scan is complete, make sure that every item in the list is checked, and click on the Quarantine selected button;
  • If it asks you for a reboot to delete some items, click on Ok to reboot automatically;
  • After the restart, open EEK again (in the C:\EEK folder);
  • This time, click on Logs;
  • From there, go under the Quarantine Log tab, and click on the Export button;
  • Save the log on your desktop, then open it, and copy/paste its content in your next reply;
created by Aura

How is the computer now?
Emsisoft Emergency Kit 2017.12.0.8334 stable [en-us]
OS: Windows 7 Service Pack 1 (Version 6.1, Build 7601, 64-bit Edition)

Forensics log

Date Component Action Details
1/17/2018 10:43:09 AM User TAMI-PC\TAMI Infection quarantined Malware "Application.AppInstall (A)" in "stronghold_llc".
1/17/2018 10:36:42 AM Scanner Scan finished Found 1 object , user to decide on further actions.
1/17/2018 10:28:37 AM Scanner Detection PUP "Application.AppInstall (A)" in "stronghold_llc"
1/17/2018 10:23:44 AM User TAMI-PC\Tami Scan started Malware Scan
1/17/2018 10:23:19 AM User TAMI-PC\Tami Setting modified "Detect PUPs" has been changed to "Enabled".
1/17/2018 10:22:25 AM User Update Downloaded and installed 84 files (10694 kb) (2 min. 15 sec.).
1/17/2018 10:20:10 AM Core Notification "Recommended Reading:What is a rootkit?".
1/17/2018 10:20:04 AM User Update Failed with error "Server returned error" (0 sec.).
It seems to be working much better. Thank you for your help!!
Any recommendations for my settings to prevent this from happening again?
Actually my computer is working terrible today. It takes forever for pages to load with the notation "waiting for cache"
Seems there is something running in the background bogging down the computer.
How can I fix this?
Good deal

DelFix
  • Please download DelFix or from Here and save the file to your Desktop.
  • Double-click DelFix.exe to run the programme.
  • Place a checkmark next to the following items:
  • Activate UAC
  • Remove disinfection tools
  • Click the Run button.
  • – This will remove the specialized tools we used to disinfect your system.
    Any leftover logs, files, folders or tools remaining on your Desktop which were not removed can be deleted manually (right-click the file + delete
    ).
***********
  • Answers to common security questions - Best Practices by quietman7, MVP
  • How Malware Spreads - How did I get infected? by quietman7, MVP
  • Simple and easy ways to keep your computer safe and secure on the Internet by Lawrence Abrams, MVP
  • How to Prevent Malware by miekiemoes, MVP
  • How to backup and restore your data using Cobian Backup by YourHighness
  • Slow Computer/browser? It May Not Be Malware by quietman7, MVP
  • AdBlock is a browser add-on that blocks annoying banners, pop-ups and video ads.
  • [external image: E8I37RF.png]CryptoPrevent places policy restrictions on loading points for ransomware (eg. CryptoWall), helping prevent the execution of malware.
  • [external image: EG85Vjt.png]Malwarebytes Anti-Exploit (MBAE) is designed to prevent zero-day malware from exploiting vulnerable software.
  • [external image: 6YRrgUC.png]Malwarebytes Anti-Malware Premium (MBAM) works in real-time along side your Anti-Virus to prevent malware execution.
  • [external image: jv4nhMJ.png]NoScript is a Firefox add-on that blocks the actions of malicious scripts by using whitelisting and other technology.
  • [external image: 3O8r9Uq.png] Sandboxie isolates programmes of your choice, preventing files from being written to your HDD unless approved by you.
  • [external image: DgW1XL2.png]Secunia PSI will scan your computer for vulnerable software that is outdated, and automatically find the latest update for you.
  • [external image: j1OLIec.png]SpywareBlaster is a form of passive protection, designed to block the actions of malicious websites and tracking cookies.
  • [external image: sHjS79L.png]Unchecky automatically removes checkmarks for bunlded software in programme installers; helping you avoid adware and PUPs.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI