Professional Documents
Culture Documents
http://forum.avast.com/index.php?PHPSESSID=rhgrp0bsj5le6e386lmvmi...
read blog
join us on facebook
forum.avast.com
Welcome, Guest. Please login or register. Did you miss your activation email?
Forever Login
Search
HOME
HELP
SEARCH
MY MESSAGES
LOGIN
REGISTER
avast!WEBforum viruses and worms viruses and worms (Moderators: Pavel, Maxx_original, misak) PLEASE HELP! I CANT DELETE A BITCOINMINER TROJAN
Author Zam1990
Newbie
Posts: 11
Here is the final log from zoek.exe My computer looks good, no virus or malware alert for the moment I think it is clean, Thank you so much for the help
Logged
magna86
Anti Malware Fighter avast! Evangelist Super Poster
Zam1990
Newbie
1 of 7
30-Jul-13 8:06 AM
http://forum.avast.com/index.php?PHPSESSID=rhgrp0bsj5le6e386lmvmi...
Posts: 11
magna86
Anti Malware Fighter avast! Evangelist Super Poster
Ok, you are clean. Just to kill some remains and we are done. Run zoek one last time with this script:
Code: [Select] C:\Windows\Prefetch\DWM.EXE-A2101CC8.pf;f C:\Windows\Prefetch\DWM.EXE-6FFD3DA8.pf;f emptytemp;
***************
Please download DelFix by "Xplode" to your Desktop. Run the tool and check the following boxes below; Remove disinfection tools Create registry backup Purge System Restore
Now click on "Run " button. Wait for the programme completes his work. All the tools we used should be gone. Tool will create and open an log report (DelFix.txt)
Note: The report will also be stored on C:\DelFix.txt
************************
I recommended to keep Malwarebytes and to use MCShield if you will. You may download MCShield from one of the following links:
MyCity - Official download link Softpedija - Mirror download link
It will prevent infection by computer via USB flash drive, mobile phone or any other memory card. And not only will prevent infection, but it will immediately clean flash drive, memory card or external HDD.
Logged
2 of 7
30-Jul-13 8:06 AM
http://forum.avast.com/index.php?PHPSESSID=rhgrp0bsj5le6e386lmvmi...
Zam1990
Newbie
Posts: 11
Finally it's over Thank you very much for helping me, for your time and effort, I'm glad there are people like you. keep it up guys greetings and best wishes
Logged
iv01
Newbie
Posts: 2
Same problem faced and same solution followed. Neither iswizard.rar nor wuaudit.exe are generated in my Temp directory now. Thank you for effective guidance!
Logged
ujec
Newbie
Posts: 1
also my problem. but in first step- scanning with malwarebytes anti-rootkit- maybe in mid of the process my system restarted. no window to continue scanning or report, nothing. what could it be ? im not expert so maybe the solution is easy, i dont know. thank you
Logged
magna86
Anti Malware Fighter avast! Evangelist Super Poster
@ iv01 ; @ujec Basically you follow the instructions that were written and made for the user who opened this topic. Following such instructions can even damage your system because of Zoek and MBAR ...well, they are not toys. You need to open a new topic following this guide: http://forum.avast.com/index.php?topic=53253.0 One of us will assist you with removing malware.
Logged
3 of 7
30-Jul-13 8:06 AM
http://forum.avast.com/index.php?PHPSESSID=rhgrp0bsj5le6e386lmvmi...
figlioecantero
Newbie
Posts: 3
Hi, i have executed the first step of this guide, i attach my zoek reports. Are neeed other step? BR
Logged
magna86
Anti Malware Fighter avast! Evangelist Super Poster
One more time: This is the topic of this user. You all feel free to open a new topic if you are looking assistance, set&attach the logs for review: Follow guide from here: http://forum.avast.com/index.php?topic=53253.0 AdwCleaner <-- cleening adware & junkware ... Malwarebytes <-- preventive & first step for malware removal OTL and aswMBR <-- primary system and antirootkit tool diagnostics.
Logged
4 of 7
30-Jul-13 8:06 AM
http://forum.avast.com/index.php?PHPSESSID=rhgrp0bsj5le6e386lmvmi...
Newbie
Posts: 3
BITCOINMINER TROJAN i have problem aswMBR, it will crashPM during scanning the directory c:\Windows Reply #25with on: June 01, 2013, 02:09:26 \asswmbly\GAC_MSIL. I tried to move the file tath cause the crash but without success because they are plentiful. the file are System.Security System.Security.resources system.servicemodel.install system.servicemodel.install.resources system.servicemodel.resources System.ServiceModel.WasHosting System.ServiceModel.Web System.ServiceModel.Web.resources System.ServiceProcess System.ServiceProcess.resources System.Speech System.Speech.resources System.Transactions.resources System.Web.Abstractions System.Web.Abstractions.resources System.Web.DynamicData System.Web.DynamicData.Design System.Web.DynamicData.Design.resources System.Web.DynamicData.resources System.Web.Entity System.Web.Entity.Design System.Web.Entity.Design.resources System.Web.Entity.resources System.Web.Extensions System.Web.Extensions.Design System.Web.Extensions.Design.resources System.Web.Extensions.resources System.Web.Mobile System.Web.Mobile.resources System.Web.RegularExpressions System.Web.resources System.Web.Routing System.Web.Routing.resources System.Web.Services System.Web.Services.resources System.Windows.Forms System.Windows.Forms.DataVisualization System.Windows.Forms.DataVisualization.Design System.Windows.Forms.DataVisualization.resources System.Windows.Forms.resources System.Windows.Presentation System.Windows.Presentation.resources System.Workflow.Activities system.workflow.activities.resources System.Workflow.ComponentModel system.workflow.componentmodel.resources System.Workflow.Runtime system.workflow.runtime.resources System.WorkflowServices System.WorkflowServices.resources System.Xml System.Xml.Linq System.XML.resources TaskScheduler TaskScheduler.Resources
5 of 7
30-Jul-13 8:06 AM
http://forum.avast.com/index.php?PHPSESSID=rhgrp0bsj5le6e386lmvmi...
UIAutomationClient UIAutomationClient.resources UIAutomationClientsideProviders UIAutomationClientsideProviders.resources UIAutomationProvider UIAutomationProvider.resources UiAutomationTypes UiAutomationTypes.resources VSTADTEProvider.Interop WindowsBase WindowsBase.resources WindowsFormsIntegration WindowsFormsIntegration.resources WsatConfig There is an alternative to the log of aswMbr? Many thanks
Logged
figlioecantero
Newbie
Posts: 3
I have try to explain this guide( http://forum.avast.com/index.php?topic=53253.0) but aswmbr crash. Have any solutions? Br
Logged
magna86
Anti Malware Fighter avast! Evangelist Super Poster
Quote from: figlioecantero on June 02, 2013, 02:15:54 PM I have try to explain this guide( http://forum.avast.com/index.php?topic=53253.0) but aswmbr crash. Have any solutions? Br
6 of 7
30-Jul-13 8:06 AM
http://forum.avast.com/index.php?PHPSESSID=rhgrp0bsj5le6e386lmvmi...
Pages: 1 [2]
Go Up
go
avast! on Twitter |
avast! on Facebook
SMF | SMF 2012, Simple Machines XHTML RSS WAP2 Page created in 0.038 seconds with 14 queries.
7 of 7
30-Jul-13 8:06 AM