Jump to content

Assistance requested


DBAZ

Recommended Posts

Hello,

 

I started experiencing multiple popups from my Avast alert stating it had blocked harmful urls. I updated and ran Malwarebytes and Avast. Malwarebytes did detect files and quarantined them. However, shortly after I was receive popups from Avast and Malwarebytes. After a call to Avast I uninstalled Norton, but and re-ran the programs but it did not help. I found your forum and would greatly appreciate your assistance.

 

I downloaded Farbar (after I had to adjust settings in IE due to an alert received stating I couldn't download anything) and ran the program in Safe Mode. I had issues with the copy and paste function so I attached the files instead.

 

An example of the address that were coming up on the alert was: 31.184.192.80

 

Thank you for your time.   

 

 

 

 

 

FRST.txt

Addition.txt

Link to post
Share on other sites

Hello DBAZ, welcome to Malwarebytes' Malware Removal forum!

My username is LiquidTension, but you can call me Adam. I will be assisting you with your malware-related problems.
If you would allow me to call you by your first name I would prefer that. xsmile.png.pagespeed.ic.CwSpBGGvqN.png

General P2P/Piracy Notice: 
 

If you are using Peer to Peer (P2P) filesharing software such as uTorrent, BitTorrent or similar you must either fully uninstall or completely disable the programme(s) from running whilst receiving assistance at this forum. 
Failure to remove or disable such software will result in your topic being closed and no further assistance being provided.
If you have illegal/cracked/keygen or similar software on the computer, please remove/uninstall the software now and read the policy on Piracy. Failure to do so will also result in your topic being closed.

 
======================================================

Please read through the points below to ensure this process moves as quickly and efficiently as possible.

  • Please read through my instructions thoroughly, and ensure you carry out each step in the order specified.
  • Please do not post logs using the CODEQUOTE or ATTACHMENT format. Logs should be posted directly in plain text. If you receive an error whilst posting, please break the log in half and use multiple posts.
  • Please do not run any tools or take any steps other than those I provide for you. Independent efforts may make matters worse, and will affect my ability in ascertaining the current situation and providing the best set of instructions for you.
  • Please backup important files before proceeding with my instructions. Malware removal can be unpredictable.
  • If you come across any issues whilst following my instructions, please stop and inform me of the issue in as much detail as possible. Please do not hesitate to ask before proceeding.
  • Topics are locked if no response is made after 4 days. Please inform me if you will require additional time to complete my instructions.
  • Ensure you are following this topic. Click xetYzdbu.png.pagespeed.ic.U7AjmRUewW.png at the top of the page.

======================================================
 
Unfortunately, your computer is badly infected. I must ensure you are aware of the following. Please read the warning below, let me know what you think and how you wish to proceed. 
 

goGMWSt.gifBACKDOOR WARNING
 
------------------------------

One or more of the identified infections is known to use a backdoor, that allows attackers to remotely control your computer, download/execute files and steal critical system, financial and personal information.

If your computer was used for online banking, has credit card information or other sensitive data, using a non-infected computer/device you should immediately change all account information (including those used for banking, Email, eBay, Paypal, online forums, etc).

Banking and credit card institutions should be notified of the possible security breach immediately. Please read the following article for more information: How Do I Handle Possible Identify Theft, Internet Fraud and CC Fraud?

Whilst the identified infection(s) can be removed, there is no way to guarantee the trustworthiness of your computer unless you reformat your Hard Drive and reinstall your Operating System. This is due to the nature of the infection, which allows the attacker remote control over the machine. Many experts in the security community believe that once infected with this type of malware, the best course of action is to reformat/reinstall. Please read the following articles for more information.

You now have the choice between cleaning the infection(s) present or reformatting your computer. Ultimately, this decision is personal, and down to you and what you're most comfortable with. Please let me know how you wish to proceed, and if you have any questions.

 

Link to post
Share on other sites

Thank you for your quick response. That was unfortunate to read regarding the status of my computer. What would you suggest? Is there a way to take out the problem? I am hoping that I can continue to use that computer; it is my home computer and the only one I have. 

Link to post
Share on other sites

Hello, 

 

You have two options. We can either manually clean the machine now, or you can use your recovery partition to restore the machine to a factory image (how the machine was when first switched on). 

 

Both options will remove the identified infection, but only the second option can guarantee your machine will be trustworthy again. Most in this situation opt for the first option as they do not wish to go through the hassle of starting from scratch, reinstalling all their programmes, etc. 

 

Ultimately, it comes down to what you're most comfortable with.

Link to post
Share on other sites

Adam,

 

Thank you for your assistance. I took your advice and went with the second option (after backing up some files on an external; haven't reloaded any files back yet). I started the process last night and everything appears to be running well. 

Link to post
Share on other sites

  • Root Admin

Due to the lack of feedback this topic is closed to prevent others from posting here. If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread.

Other members who need assistance please start your own topic in a new thread. Thanks!

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.