ttanin Posted October 2, 2015 ID:993234 Share Posted October 2, 2015 Malware bytes finds this after each reboot and it keeps coming back. Addition.txtFRST.txt Link to post Share on other sites More sharing options...
TwinHeadedEagle Posted October 2, 2015 ID:993257 Share Posted October 2, 2015 Hello, You asked for help 3 times so far and in all of them there was a different PC. Are these all your machines or you're fixing it for someone? Do you have MalwareBytes subscription? Link to post Share on other sites More sharing options...
ttanin Posted October 2, 2015 Author ID:993289 Share Posted October 2, 2015 I have malware bytes subsription for all the 3 PC. The first one was for my wife, the last 2 are mine. I use 2 laptops, one in my office and travelling, the other one sits at home. Link to post Share on other sites More sharing options...
TwinHeadedEagle Posted October 2, 2015 ID:993297 Share Posted October 2, 2015 Okay, that's fine. Please re-run Malwarebytes' Anti-Malware.Click the History tab.Click Application Logs and click on the newest Scan Log.At the bottom click Export and choose Text file.Save the file to your desktop and attach it in your next reply. Link to post Share on other sites More sharing options...
ttanin Posted October 2, 2015 Author ID:993320 Share Posted October 2, 2015 Here it is.malware.txt Link to post Share on other sites More sharing options...
TwinHeadedEagle Posted October 2, 2015 ID:993349 Share Posted October 2, 2015 I don't see malware you mentioned in this log? Link to post Share on other sites More sharing options...
ttanin Posted October 3, 2015 Author ID:993519 Share Posted October 3, 2015 here is the one for today. It does not come back after each reboot but iI know it is hidden somewhere. Sometimes malware bytes finds 4, today it found only onemalware.txt Link to post Share on other sites More sharing options...
TwinHeadedEagle Posted October 4, 2015 ID:993563 Share Posted October 4, 2015 This log is still empty. Can you just make a picture of MalwareBytes findings? Link to post Share on other sites More sharing options...
ttanin Posted October 4, 2015 Author ID:993624 Share Posted October 4, 2015 Malwarebytes Anti-Malwarewww.malwarebytes.orgScan Date: 10/1/2015Scan Time: 8:29 AMLogfile: malware.txtAdministrator: YesVersion: 2.1.8.1057Malware Database: v2015.09.30.09Rootkit Database: v2015.09.22.01License: PremiumMalware Protection: EnabledMalicious Website Protection: EnabledSelf-protection: DisabledOS: Windows 10CPU: x64File System: NTFSUser: HPScan Type: Threat ScanResult: CompletedObjects Scanned: 407565Time Elapsed: 25 min, 38 secMemory: EnabledStartup: EnabledFilesystem: EnabledArchives: EnabledRootkits: DisabledHeuristics: EnabledPUP: EnabledPUM: EnabledProcesses: 0(No malicious items detected)Modules: 0(No malicious items detected)Registry Keys: 3PUP.Optional.Cassiopessa, HKLM\SOFTWARE\CLASSES\APPID\{ef494946-9425-4a5c-b373-74ccd38e8c48}, Quarantined, [bd5438fe5635d75ff402b6407f835ea2],PUP.Optional.Cassiopessa, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{EF494946-9425-4A5C-B373-74CCD38E8C48}, Quarantined, [bd5438fe5635d75ff402b6407f835ea2],PUP.Optional.Cassiopessa, HKLM\SOFTWARE\CLASSES\WOW6432NODE\APPID\{EF494946-9425-4A5C-B373-74CCD38E8C48}, Quarantined, [bd5438fe5635d75ff402b6407f835ea2],Registry Values: 0(No malicious items detected)Registry Data: 0(No malicious items detected)Folders: 0(No malicious items detected)Files: 1PUP.Optional.Cassiopessa, C:\Program Files (x86)\Mozilla Firefox\browser\components\lmn.js, Quarantined, [5db450e6e4a77bbb703722bc34d032ce],Physical Sectors: 0(No malicious items detected)(end)malware.txt Link to post Share on other sites More sharing options...
TwinHeadedEagle Posted October 4, 2015 ID:993649 Share Posted October 4, 2015 Thanks. Scan with Farbar Recovery Scan Tool Please re-run Farbar Recovery Scan Tool to give me a fresh look at your system.Right-click on icon and select Run as Administrator to start the tool. (XP users click run after receipt of Windows Security Warning - Open File).Make sure that Addition option is checked.Press Scan button and wait.The tool will produce two logfiles on your desktop: FRST.txt and Addition.txt.Please upload them into your next reply. Link to post Share on other sites More sharing options...
ttanin Posted October 5, 2015 Author ID:993743 Share Posted October 5, 2015 This morning when I started Malwarebytes anti exploit gave me a message saying that malware bytes was not turned on, so I did a scan and found one more. I removed that and then Followed your instructions.FRST.txtAddition.txtmalwarebytesdiscovery1052015.txt Link to post Share on other sites More sharing options...
TwinHeadedEagle Posted October 5, 2015 ID:993823 Share Posted October 5, 2015 Fix with Farbar Recovery Scan Tool This fix was created for this user for use on that particular machine. Running it on another one may cause damage and render the system unstable. Download attached fixlist.txt file and save it to the Desktop: Both files, FRST and fixlist.txt have to be in the same location or the fix will not work!Right-click on icon and select Run as Administrator to start the tool.(XP users click run after receipt of Windows Security Warning - Open File).Press the Fix button just once and wait.If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.When finished FRST will generate a log on the Desktop, called Fixlog.txt.Please upload it to your reply.fixlist.txt Link to post Share on other sites More sharing options...
ttanin Posted October 5, 2015 Author ID:993835 Share Posted October 5, 2015 Here it isFixlog.txt Link to post Share on other sites More sharing options...
TwinHeadedEagle Posted October 6, 2015 ID:993877 Share Posted October 6, 2015 Very good. How is the situation now? Link to post Share on other sites More sharing options...
ttanin Posted October 6, 2015 Author ID:993960 Share Posted October 6, 2015 So far so good. I rebooted few times and it has not re-appeared yet. Link to post Share on other sites More sharing options...
ttanin Posted October 6, 2015 Author ID:994003 Share Posted October 6, 2015 It was fine for 6 hours then my browser crashed, when I rebooted my firefox had a russian webpage as homepage. So something is still there. I ran the same files again.FRST.txt Link to post Share on other sites More sharing options...
TwinHeadedEagle Posted October 7, 2015 ID:994050 Share Posted October 7, 2015 Can you reinstall Firefox? - Uninstall Firefox (Programs and Features) Then Click Start, copy in search %appdata%\ Then delete folder Mozilla Click Start, copy in search %LOCALAPPDATA%\ delete folder Mozilla Then delete following folders: C:\Program Files (x86)\mozilla firefox C:\Program Files (x86)\Mozilla Maintenance Service Restart your PC. Then install Firefox again. https://www.mozilla.org/en-US/firefox/new/ Link to post Share on other sites More sharing options...
ttanin Posted October 7, 2015 Author ID:994117 Share Posted October 7, 2015 DOne. Much better now. My laptop had stated blinking occassionally last week so I thought I needed a new battery. Now the blinking is completely gone. Link to post Share on other sites More sharing options...
ttanin Posted October 7, 2015 Author ID:994143 Share Posted October 7, 2015 I found this on my bookmarks on microsoft edge I dont use this browser so I left it there. Obviously related to malware https://mail.yandex.ru/?win=197&clid=2100778-002 Link to post Share on other sites More sharing options...
TwinHeadedEagle Posted October 7, 2015 ID:994221 Share Posted October 7, 2015 Did you remove this? Link to post Share on other sites More sharing options...
ttanin Posted October 7, 2015 Author ID:994225 Share Posted October 7, 2015 Yes, I removed it by right clicking the mouse over top of it, but I am not sure that will make it permanently go away Link to post Share on other sites More sharing options...
TwinHeadedEagle Posted October 7, 2015 ID:994227 Share Posted October 7, 2015 Okay. How is your PC behaving now? Link to post Share on other sites More sharing options...
ttanin Posted October 7, 2015 Author ID:994228 Share Posted October 7, 2015 No issues Link to post Share on other sites More sharing options...
TwinHeadedEagle Posted October 7, 2015 ID:994231 Share Posted October 7, 2015 Can we then consider this as solved? Link to post Share on other sites More sharing options...
ttanin Posted October 7, 2015 Author ID:994233 Share Posted October 7, 2015 yes, one question. The malware bytes scanning history log has self protection as disabled in the report. Also whatever happened I dont have the anti exploit youhad recommended earlier. I may have mistakenly uninstalled it when I found out I have malware Link to post Share on other sites More sharing options...
Recommended Posts