Virus Pen Drive - Please Help
Closed
hgimenez
Posts
5
Registration date
Wednesday September 21, 2011
Status
Member
Last seen
September 23, 2011
-
Sep 21, 2011 at 02:39 PM
Ambucias Posts 47310 Registration date Monday February 1, 2010 Status Moderator Last seen February 15, 2023 - Sep 23, 2011 at 04:03 PM
Ambucias Posts 47310 Registration date Monday February 1, 2010 Status Moderator Last seen February 15, 2023 - Sep 23, 2011 at 04:03 PM
Related:
- Virus Pen Drive - Please Help
- Goose virus - Download - Other
- Wd drive unlock - Guide
- Ntuser.dat virus - Guide
- How to remove write protection from pen drive - Guide
- Flash drive/card tester - Download - Backup and recovery
4 responses
Ambucias
Posts
47310
Registration date
Monday February 1, 2010
Status
Moderator
Last seen
February 15, 2023
11,163
Sep 21, 2011 at 04:10 PM
Sep 21, 2011 at 04:10 PM
Hi
Your Hjt log does not show any infection. HJT I no longer use because it's a primitive tool.
To help you, I must make a diagnostic and to do so, I require a log.
Open this link and download ZHPDiag :
https://www.zebulon.fr/telechargements/securite/systeme/zhpdiag.html
Register the file on your Desktop.
Double click on ZHPDiag.exe and follow the instructions.
the tool created two icons ZHPDiag and ZHPFix (we will use ZHPFix at the next step).
Double click on the short cut ZHPDiag on your Destktop.
Click on the Magnifying glass and run the analysys.
Wait for the tool to finished (maybe a long time)
Close ZHPDiag.
To transmit the report, click on this link :
https://authentification.site
Click on Parcourir and search the directory where you installed ZHPDiag (usually C:\Program Files\ZHPDiag).
Select the file ZHPDiag.txt.
Click on "upload »
Copy the url and post it here
Your Hjt log does not show any infection. HJT I no longer use because it's a primitive tool.
To help you, I must make a diagnostic and to do so, I require a log.
Open this link and download ZHPDiag :
https://www.zebulon.fr/telechargements/securite/systeme/zhpdiag.html
Register the file on your Desktop.
Double click on ZHPDiag.exe and follow the instructions.
the tool created two icons ZHPDiag and ZHPFix (we will use ZHPFix at the next step).
Double click on the short cut ZHPDiag on your Destktop.
Click on the Magnifying glass and run the analysys.
Wait for the tool to finished (maybe a long time)
Close ZHPDiag.
To transmit the report, click on this link :
https://authentification.site
Click on Parcourir and search the directory where you installed ZHPDiag (usually C:\Program Files\ZHPDiag).
Select the file ZHPDiag.txt.
Click on "upload »
Copy the url and post it here
Ambucias
Posts
47310
Registration date
Monday February 1, 2010
Status
Moderator
Last seen
February 15, 2023
11,163
Sep 22, 2011 at 04:10 PM
Sep 22, 2011 at 04:10 PM
Hello,
The link you have given me does not contain the uploaded file.
Please try again.
The link you have given me does not contain the uploaded file.
Please try again.
hgimenez
Posts
5
Registration date
Wednesday September 21, 2011
Status
Member
Last seen
September 23, 2011
Sep 22, 2011 at 04:16 PM
Sep 22, 2011 at 04:16 PM
https://authentification.site/files/30435219/ZHPDiag.txt
I've just uploaded again, let me know if it works.
best,
I've just uploaded again, let me know if it works.
best,
Ambucias
Posts
47310
Registration date
Monday February 1, 2010
Status
Moderator
Last seen
February 15, 2023
11,163
Sep 22, 2011 at 04:44 PM
Sep 22, 2011 at 04:44 PM
Hello,
Thanks for the log.
Your system is indeed infected mainly adware like "ask.com", "Hotbar", "PUP Dealo"
What I have seen:
SBI: SearchScopes [HKCU] {CF739809-1C6C-47C0-85B9-569DBB141420} - (Ask Search) - http://toolbar.ask.com => Infection BT (AskBarDis.Adw)
[HKLM\Software\Classes\TypeLib\{2D5E2D34-BED5-4B9F-9793-A31E26E6806E}] =>Adware.Hotbar => Infection BT (Adware.Hotbar)
[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}] =>PUP.Dealio => Infection BT (PUP.Dealio)
[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}] =>PUP.Dealio => Infection BT (PUP.Dealio)
I recommend that you delete the tool bars associated with the viruses and...
Download, install and run Malwarebyte which you can find on this site:
https://ccm.net/downloads/security-and-maintenance/4621-malwarebytes-anti-malware/ es-anti-malware
Ensure you make an update.
Boot your computer in safemode
Please request a FULL system scan, which may take from 20 minutes to hours. Do not interfere no matter how long in takes. The creators of Malwarebyte recommend that while the tool is running that you go do something else, such as watching a rerun of Gone with the Wind or read Tolstoy's War and Peace.
If Malwarebyte restarts your system, launch it again to finish the Full scan.
When the scan is completed, delete all items found.
Once your computer is clean and working normally just to be on the safe side
*Turn off system restore and wait 30 seconds,
*Turn it back on and create a new restore point.
This way it gets rid of anything bad that might have gotten saved in a restore point and you have a clean restore point to use in the near future if needed.
Do not turn it off until your computer is clean and working normally because you might need to use it if something goes wrong during the clean-up process.
It is better to go back to an infected restore point if something goes wrong then to not be able to undo changes that were damaging.
Please let me know the results and good luck
Thanks for the log.
Your system is indeed infected mainly adware like "ask.com", "Hotbar", "PUP Dealo"
What I have seen:
SBI: SearchScopes [HKCU] {CF739809-1C6C-47C0-85B9-569DBB141420} - (Ask Search) - http://toolbar.ask.com => Infection BT (AskBarDis.Adw)
[HKLM\Software\Classes\TypeLib\{2D5E2D34-BED5-4B9F-9793-A31E26E6806E}] =>Adware.Hotbar => Infection BT (Adware.Hotbar)
[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}] =>PUP.Dealio => Infection BT (PUP.Dealio)
[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}] =>PUP.Dealio => Infection BT (PUP.Dealio)
I recommend that you delete the tool bars associated with the viruses and...
Download, install and run Malwarebyte which you can find on this site:
https://ccm.net/downloads/security-and-maintenance/4621-malwarebytes-anti-malware/ es-anti-malware
Ensure you make an update.
Boot your computer in safemode
Please request a FULL system scan, which may take from 20 minutes to hours. Do not interfere no matter how long in takes. The creators of Malwarebyte recommend that while the tool is running that you go do something else, such as watching a rerun of Gone with the Wind or read Tolstoy's War and Peace.
If Malwarebyte restarts your system, launch it again to finish the Full scan.
When the scan is completed, delete all items found.
Once your computer is clean and working normally just to be on the safe side
*Turn off system restore and wait 30 seconds,
*Turn it back on and create a new restore point.
This way it gets rid of anything bad that might have gotten saved in a restore point and you have a clean restore point to use in the near future if needed.
Do not turn it off until your computer is clean and working normally because you might need to use it if something goes wrong during the clean-up process.
It is better to go back to an infected restore point if something goes wrong then to not be able to undo changes that were damaging.
Please let me know the results and good luck
hgimenez
Posts
5
Registration date
Wednesday September 21, 2011
Status
Member
Last seen
September 23, 2011
Sep 23, 2011 at 10:57 AM
Sep 23, 2011 at 10:57 AM
Ambucias,
Thanks for you email, however Malwarebyte did not find any problem.
Besides I could not remove ask.com, hotbar and pub dealo, since they are no longer appearing on the list of programs.
Question: Is there any way i can get rid of them manually?
best,
Hugo
Thanks for you email, however Malwarebyte did not find any problem.
Besides I could not remove ask.com, hotbar and pub dealo, since they are no longer appearing on the list of programs.
Question: Is there any way i can get rid of them manually?
best,
Hugo
Ambucias
Posts
47310
Registration date
Monday February 1, 2010
Status
Moderator
Last seen
February 15, 2023
11,163
Sep 23, 2011 at 04:03 PM
Sep 23, 2011 at 04:03 PM
Hola Hugo,
Yes you can get rid of them manually.
1. Click on start and then on search. Click on all files and type ask.com and then search. After the search is terminated, delete all files refering to ask.com. Close that Window.
2. Click on start and then on run. Type regedit. Your registry editor will open. Press F3 and copy exactly and press the keys I have indicated and once the key has been found press del
CF739809-1C6C-47C0-85B9-569DBB141420
2D5E2D34-BED5-4B9F-9793-A31E26E6806E
E312764E-7706-43F1-8DAB-FCDD2B1E416D (After this last key, press F3 to continue the search as there are two with the same digits)
Once you are done, please let me know as we may have to go on further to clean your flash drive.
Good luck
Yes you can get rid of them manually.
1. Click on start and then on search. Click on all files and type ask.com and then search. After the search is terminated, delete all files refering to ask.com. Close that Window.
2. Click on start and then on run. Type regedit. Your registry editor will open. Press F3 and copy exactly and press the keys I have indicated and once the key has been found press del
CF739809-1C6C-47C0-85B9-569DBB141420
2D5E2D34-BED5-4B9F-9793-A31E26E6806E
E312764E-7706-43F1-8DAB-FCDD2B1E416D (After this last key, press F3 to continue the search as there are two with the same digits)
Once you are done, please let me know as we may have to go on further to clean your flash drive.
Good luck
Sep 22, 2011 at 07:35 AM
Thanks, above is the file url
best,