mistertonmick Posted August 25, 2015 ID:985352 Share Posted August 25, 2015 got ukash virus this afternoon on firefox,ran MBAM premium and it showed nothing,antiexploit neither,restarted computer and virus still on firefox,ran MBAM again with rootkit again nothing,decided to do system restore and for quickness did it with cortana,but instead of ukash page it went straight to system restore options on yahoo,i then tried one of my normal websites and they worked fine,i did another restart and computer is working perfectly but you still have doubts about virus left on computer,have run MBAM again and no problems so still decided to get advice from you guys whether there is anything to check.but at the moment the ukash page has gone. i have attached farbar files has requestedAddition.txtFRST.txt Link to post Share on other sites More sharing options...
mistertonmick Posted August 25, 2015 Author ID:985354 Share Posted August 25, 2015 i meant i put system restore on cortana toolbar for quickness but instead of taking me to control panel it went online on firefox. Link to post Share on other sites More sharing options...
kevinf80 Posted August 25, 2015 ID:985383 Share Posted August 25, 2015 Download attached fixlist.txt file (end of reply) and save it to the Desktop, or the folder you saved FRST into.NOTE. It's important that both FRST and fixlist.txt are in the same location or the fix will not work.Run FRST and press the Fix button just once and wait.The tool will make a log on the Desktop (Fixlog.txt) or the folder it was ran from. Please post it to your reply. Next, Please open Malwarebytes Anti-Malware. On the Settings tab > Detection and Protection sub tab, Detection Options, tick the box "Scan for rootkits". Under Non-Malware Protection sub tab Change PUP and PUM entries to Treat detections as Malware Click on the Scan tab, then click on Scan Now >> . If an update is available, click the Update Now button. A Threat Scan will begin. With some infections, you may or may not see this message box. 'Could not load DDA driver' Click 'Yes' to this message, to allow the driver to load after a restart. Allow the computer to restart. Continue with the rest of these instructions. When the scan is complete, click Apply Actions. Wait for the prompt to restart the computer to appear, then click on Yes. After the restart once you are back at your desktop, open MBAM once more.To get the log from Malwarebytes do the following: Click on the History tab > Application Logs. Double click on the scan log which shows the Date and time of the scan just performed. Click Export > From export you have three options: Copy to Clipboard - if seleted right click to your reply and select "Paste" log will be pasted to your reply Text file (*.txt) - if selected you will have to name the file and save to a place of choice, recommend "Desktop" then attach to reply XML file (*.xml) - if selected you will have to name the file and save to a place of choice, recommend "Desktop" then attach to reply. Please do not use XML file..... Please use "Copy to Clipboard, then Right click to your reply > select "Paste" that will copy the log to your reply…If Malwarebytes is not installed follow these instructions first:Download Malwarebytes Anti-Malware to your desktop.Double-click mbam-setup and follow the prompts to install the program. At the end, be sure a checkmark is placed next to the following: Launch Malwarebytes Anti-Malware A 14 day trial of the Premium features is pre-selected. You may deselect this if you wish, and it will not diminish the scanning and removal capabilities of the program. Click Finish. Follow the instructions above.... Next, Download AdwCleaner by Xplode onto your Desktop. Double click on Adwcleaner.exe to run the tool. Click on the Scan in the Actions box Please wait fot the scan to finish.. When "Waiting for action.Please uncheck elements you want to keep" shows in top line.. Click on the Cleaning box. Next click OK on the "Closing Programs" pop up box. Click OK on the Information box & again OK to allow the necessary reboot After restart the AdwCleaner(C*)-Notepad log will appear, please copy/paste it in your next reply. Where * is the number relative to list of scans completed... Next, Please download Junkware Removal Tool to your desktop.Shut down your protection software now to avoid potential conflicts. (re-enable when done) Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator". The tool will open and start scanning your system. Please be patient as this can take a while to complete depending on your system's specifications. On completion, a log (JRT.txt) is saved to your desktop and will automatically open. Post the contents of JRT.txt into your next message. Next, Download Microsoft's " Malicious Software Removal Tool" and save direct to the desktopEnsure to get the correct version for your system....32 Bit version:https://www.microsoft.com/downloads/en/confirmation.aspx?FamilyId=AD724AE0-E72D-4F54-9AB3-75B8EB148356&displaylang=en64 Bit version:https://www.microsoft.com/downloads/en/confirmation.aspx?FamilyId=585D2BDE-367F-495E-94E7-6349F4EFFC74&displaylang=enRight click on the Tool, select “Run as Administrator” the tool will expand to the options WindowIn the "Scan Type" window, select Quick ScanPerform a scan and Click Finish when the scan is done.Retrieve the MSRT log as follows, and post it in your next reply:1) Select the Windows key and R key together to open the "Run" function2) Type or Copy/Paste the following command to the "Run Line" and Press Enter:notepad c:\windows\debug\mrt.log Let me see those logs, also give an update on any remaining issues or concerns... Thank you, Kevin... Fixlist.txt Link to post Share on other sites More sharing options...
mistertonmick Posted August 25, 2015 Author ID:985389 Share Posted August 25, 2015 sorry kevin,i have done it once before but i cannot remember how you combine the two to make the fix list work. Link to post Share on other sites More sharing options...
kevinf80 Posted August 25, 2015 ID:985395 Share Posted August 25, 2015 Download attached fixlist.txt file (end of reply) and save it to the Desktop, or the folder you saved FRST into.NOTE. It's important that both FRST and fixlist.txt are in the same location or the fix will not work.Run FRST and press the Fix button just once and wait.The tool will make a log on the Desktop (Fixlog.txt) or the folder it was ran from. Please post it to your reply. Can you not follow those instructions, FRST was saved here: C:\Users\owners-pc\Downloads Therefore fixlist.txt must be saved direct to that very same folder, do not open the file.... So you now run FRST once again, when FRST is open you select the "Fix" button (Tab) and patiently wait, when complete let me see the produced log... Thank you, Kevin... Link to post Share on other sites More sharing options...
mistertonmick Posted August 25, 2015 Author ID:985403 Share Posted August 25, 2015 i have had them in same location,but when i press fix it says that there is no fixlist file in location.anyway going to leave it until tomorrow. Link to post Share on other sites More sharing options...
mistertonmick Posted August 25, 2015 Author ID:985404 Share Posted August 25, 2015 just a quick one,the frst tool,frst folder and fixit files are all in download folder,but if you press fix it says that the fixit folder is in a different location,i am baffled i have done it once before and did it first time. Link to post Share on other sites More sharing options...
mistertonmick Posted August 25, 2015 Author ID:985409 Share Posted August 25, 2015 am i right in thinking that you copy and paste the fixlist to the frst,if so i can copy but not paste,i am baffled. Link to post Share on other sites More sharing options...
mistertonmick Posted August 26, 2015 Author ID:985451 Share Posted August 26, 2015 # AdwCleaner v5.003 - Logfile created 26/08/2015 at 09:33:13# Updated 20/08/2015 by Xplode# Database : 2015-08-25.1 [server]# Operating system : Windows 10 Home (x64)# Username : owners-pc - OWNERS-PC-PC# Running from : C:\Users\owners-pc\Downloads\AdwCleaner.exe# Option : Cleaning***** [ Services ] ********** [ Folders ] *****[-] Folder Deleted : C:\Users\owners-pc\AppData\Roaming\UpdaterEX[-] Folder Deleted : C:\WINDOWS\Sysnative\Store***** [ Files ] ********** [ Shortcuts ] ********** [ Scheduled tasks ] ********** [ Registry ] *****[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\esrv.EXE[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\GenericAskToolbar.DLL[-] Key Deleted : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd[-] Key Deleted : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd.1[-] Key Deleted : HKLM\SOFTWARE\Classes\Prod.cap[-] Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.protectorbho[-] Key Deleted : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WajamUpdater[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\REI_AxControl.DLL[-] Key Deleted : HKLM\SOFTWARE\Classes\REI_AxControl.ReiEngine.1[-] Key Deleted : HKLM\SOFTWARE\Classes\REI_AxControl.ReiEngine[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874}[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\{C007DADD-132A-624C-088E-59EE6CF0711F}[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\{C292AD0A-C11F-479B-B8DB-743E72D283B0}[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\{28FF42B8-A0DA-4BE5-9B81-E26DD59B350A}[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D}[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{10DE7085-6A1E-4D41-A7BF-9AF93E351401}[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{1AD27395-1659-4DFF-A319-2CFA243861A5}[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456}[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92}[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E}[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9BB31AD8-5DB2-459E-A901-DEA536F23BA4}[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{BD51A48E-EB5F-4454-8774-EF962DF64546}[-] Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{FA6468D2-FAA4-4951-A53B-2A5CF9CC0A36}[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{10ECCE17-29B5-4880-A8F5-EAD298611484}[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{10ECCE17-29B5-4880-A8F5-EAD298611484}[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{801B440B-1EE3-49B0-B05D-2AB076D4E8CB}[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456}[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92}[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E}[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{9BB31AD8-5DB2-459E-A901-DEA536F23BA4}[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{BD51A48E-EB5F-4454-8774-EF962DF64546}[-] Key Deleted : HKCU\Software\UpdaterEX[-] Key Deleted : HKCU\Software\Reimage[-] Key Deleted : HKLM\SOFTWARE\Babylon[!] Key Not Deleted : [x64] HKCU\Software\UpdaterEX[!] Key Not Deleted : [x64] HKCU\Software\Reimage[-] Key Deleted : [x64] HKLM\SOFTWARE\Tarma Installer***** [ Web browsers ] ******************************:: Proxy settings cleared:: Winsock settings cleared########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [3652 bytes] ##########Junkware Removal Tool (JRT) by MalwarebytesVersion: 7.5.7 (08.18.2015:1)OS: Windows 10 Home x64Ran by owners-pc on 26/08/2015 at 9:44:08.53~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Services~~~ Tasks~~~ Registry Values~~~ Registry KeysSuccessfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{4858E7D9-8E12-45a3-B6A3-1CD128C9D403}Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\shell\TuneUp UndeleteSuccessfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Directory\shellex\ContextMenuHandlers\TuneUp Disk Space Explorer Shell ExtensionSuccessfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Directory\shellex\ContextMenuHandlers\TuneUp Shredder Shell ExtensionSuccessfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{FBDB0CA6-E41C-404F-9469-1CE4F4A5B0B1}~~~ FilesSuccessfully deleted: [File] C:\Users\owners-pc\desktop\tuneup utilities 2014.lnk~~~ FoldersSuccessfully deleted: [Folder] C:\ProgramData\googleSuccessfully deleted: [Folder] C:\ProgramData\Microsoft\Windows\Start Menu\Programs\tuneup utilities 2014~~~ FireFoxSuccessfully deleted the following from C:\Users\owners-pc\AppData\Roaming\mozilla\firefox\profiles\sqeluau5.default-1435916386606\prefs.jsuser_pref(browser.search.defaultenginename, Secure Search);user_pref(browser.search.order.1, Secure Search);user_pref(browser.search.selectedEngine, Secure Search);~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~Scan was completed on 26/08/2015 at 9:50:32.02End of JRT log~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Fixlog.txt Link to post Share on other sites More sharing options...
mistertonmick Posted August 26, 2015 Author ID:985454 Share Posted August 26, 2015 i hope this is right,pressed the clipboard option several times but cann ot find clipboard anywhere to copy and paste it.scan log.txt Link to post Share on other sites More sharing options...
mistertonmick Posted August 26, 2015 Author ID:985459 Share Posted August 26, 2015 Malwarebytes Anti-Malware www.malwarebytes.org Scan Date: 26/08/2015 Scan Time: 07:56 Logfile: scan log.txt Administrator: Yes Version: 2.1.8.1057 Malware Database: v2015.08.26.03 Rootkit Database: v2015.08.16.01 License: Premium Malware Protection: Enabled Malicious Website Protection: Enabled Self-protection: Disabled OS: Windows 10 CPU: x64 File System: NTFS User: owners-pc Scan Type: Threat Scan Result: Completed Objects Scanned: 449146 Time Elapsed: 33 min, 53 sec Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Enabled Heuristics: Enabled PUP: Enabled PUM: Enabled Processes: 0 (No malicious items detected) Modules: 0 (No malicious items detected) Registry Keys: 0 (No malicious items detected) Registry Values: 0 (No malicious items detected) Registry Data: 0 (No malicious items detected) Folders: 0 (No malicious items detected) Files: 0 (No malicious items detected) Physical Sectors: 0 (No malicious items detected) (end) i had to download clipboard,not on windows 10, Link to post Share on other sites More sharing options...
kevinf80 Posted August 26, 2015 ID:985519 Share Posted August 26, 2015 There is no clipboard to see, when you select "copy to clipboard" the data is copied and saved. Right click into your reply and select "Paste" I`m running Windows 10 and it works ok for me.... Post remaining log when you`re ready... Thank you, Kevin... Link to post Share on other sites More sharing options...
mistertonmick Posted August 26, 2015 Author ID:985537 Share Posted August 26, 2015 Microsoft Windows Malicious Software Removal Tool v5.27, August 2015 (build 5.27.11700.0) Started On Mon Aug 17 16:06:30 2015 Engine: 1.1.11903.0 Signatures: 1.203.693.0 Results Summary: ---------------- No infection found. Microsoft Windows Malicious Software Removal Tool Finished On Mon Aug 17 16:22:09 2015 Return code: 0 (0x0) --------------------------------------------------------------------------------------- Microsoft Windows Malicious Software Removal Tool v5.27, August 2015 (build 5.27.11700.0) Started On Wed Aug 26 19:25:08 2015 Engine: 1.1.11903.0 Signatures: 1.203.693.0 Results Summary: ---------------- No infection found. Microsoft Windows Malicious Software Removal Tool Finished On Wed Aug 26 19:33:19 2015 Return code: 0 (0x0) sorry about that kevin,i had missed that one. Link to post Share on other sites More sharing options...
kevinf80 Posted August 26, 2015 ID:985553 Share Posted August 26, 2015 Hey don`t be sorry, no need for that... We work together, if you need an answer for anything is best to stop and ask.. What is the current status of your system, do you have any remaining issues or concerns.. Thank you, Kevin.. Link to post Share on other sites More sharing options...
mistertonmick Posted August 26, 2015 Author ID:985593 Share Posted August 26, 2015 no it is working fine,just disapeared off firefox when cortana searched for system restore on web instead of computer. i intended after looking up the virus to put it back a few days. but then you wonder if it had left a virus on computer,mcafee and MBAM showed nothing and i dont believe adwcleaner did either looking at the scan result, but the other log files i have not got a clue what they come up with. will now see what happens tomorrow and your conclusions,anyway are you having nice weather in the NE,been very erratic in Notts. Link to post Share on other sites More sharing options...
kevinf80 Posted August 26, 2015 ID:985599 Share Posted August 26, 2015 Thanks for the update, post back whenever you`re ready... let me know if all is ok and we can clean up... Thank you, Kevin.. Link to post Share on other sites More sharing options...
mistertonmick Posted August 27, 2015 Author ID:985815 Share Posted August 27, 2015 there has been no problems today Kevin,so i presume the virus has been removed,did any of the logs show anything. and are you confident it is sorted. Link to post Share on other sites More sharing options...
kevinf80 Posted August 27, 2015 ID:985824 Share Posted August 27, 2015 Yes Fire fox was hijacked with a false user account, there was other infection entries and remnants.. FF user.js: detected! => C:\Users\owners-pc\AppData\Roaming\Mozilla\Firefox\Profiles\sqeluau5.default-1435916386606\user.js [2015-07-04] We remove majority of infection with FRST... Run the following to clean up: Download "Delfix by Xplode" and save it to your desktop.Or use the following if first link is down:"Delfix link mirror"Double Click to start the program. If you are using Vista or higher, please right-click and choose run as administratorMake Sure the following items are checked: Remove disinfection tools Purge System Restore <--- this will remove all previous and possibly exploited restore points, a new point relative to system status at present will be created. Reset system settingsNow click on "Run" and wait patiently until the tool has completed.The tool will create a log when it has completed. We don't need you to post this.Any remnant files/logs from tools we have used can be deleted… Next, Read the following link to fully understand PC security and best practices, you may find it useful....http://www.bleepingcomputer.com/forums/t/407147/answers-to-common-security-questions-best-practices/#entry2316629 Let me know if we are ok to close out... Thanks, Kevin... Link to post Share on other sites More sharing options...
mistertonmick Posted August 28, 2015 Author ID:985894 Share Posted August 28, 2015 yes i have used the Delfix tool,would you advise me not to use firefox on this computer. anyway thanks for your help and a beer will be on the way to you. Link to post Share on other sites More sharing options...
kevinf80 Posted August 28, 2015 ID:985923 Share Posted August 28, 2015 There is nothing wrong with Firefox, I use it myself. I use the following Addons: AdBlock PlusAdBlock Plus Pop-up AddonFlashBlock.Web of Trust (WOT) Select these keys together when FireFox is running Ctrl - Shift - A that opens Addons Manager, from there you can search, add, disable or delete addons. I also have Website protection with my security program Kaspersky 2015. I also use Malwarebytes Premium... If your security apps do not give any browser protection, download and install the free version of Malwarebytes Anti Exploit... https://www.malwarebytes.org/antiexploit/index.html Thanks for the donation, very much appreciated... regards, Kevin. Link to post Share on other sites More sharing options...
mistertonmick Posted August 29, 2015 Author ID:986064 Share Posted August 29, 2015 i have got adblock plus,use mcafee total protection, mcafee web adviser and have have malwarebytes premium and and anti exploit premium.but this virus still managed to get through without any warning,on a website that I have used many times before and is ticked green on webadviser has being safe,and I have had it before with simple sites that when I tried to open a page webadviser usually gives a warning not to go there,but for some reason this did not happen on this occasion and anti exploit did not stop it either,also antivirus and Malwarebytes scans did not find it either.you then start to think will it have also got onto my laptop seeing it is the same email address and in sync with this computer,i like the new edge browser but myself and a lot of other people will be put off by the fact there is no addons available at the moment for extra protection,i had problems with my laptop with anti exploit on windows 10, and had plenty of online chats with Pedro,but again there is no protection for edge though it is hoped to be in next update.anyway thanks for your help and I presume it is safe to use firefox on this computer again. thanks mistertonmick. Link to post Share on other sites More sharing options...
kevinf80 Posted August 31, 2015 ID:986434 Share Posted August 31, 2015 Yes Firefox is ok to use.... Link to post Share on other sites More sharing options...
Root Admin AdvancedSetup Posted September 8, 2015 Root Admin ID:987899 Share Posted September 8, 2015 Glad we could help. If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread. Other members who need assistance please start your own topic in a new thread. Thanks! Link to post Share on other sites More sharing options...
Recommended Posts