|
Department of Justice Block
|
|
01-23-2013, 01:06 PM
|
|||
|
|||
|
Department of Justice Block
Operating system: windows 7
Architecture: 64 bit Antivirus software and on-demand scanners on this system : None Date and how issue started: This started the 22nd (last night) while I was online. Current issues and symptoms: Well, now I have no background (everything is just black) and I have to use the Task manager to do anything. Steps taken in order to remove the infection: Hitmanpro (3? maybe? I don't know but it did something) REQUESTED LOGS: OTL LOGaswMBR LOG There was a similar thread here that was having the same exact probem as me for the same reasons so I followed the instructions given to him and it has all been going accordingly but I cannot proceed with a script written for him so here I am. I did the OTL and aswMBR logs. I only hope I've done them right so I can figure out what to do from here. Any guidance would be much appreciated! |
|||
|
01-23-2013, 02:21 PM
|
|||
|
|||
|
RE: Department of Justice Block
Hi and welcome to the MalwareTips.com forums!
I'm Kuttus and I am going to try to assist you with your problem. Please take note of the below:
Before we start: Please be aware that removing malware is a potentially hazardous undertaking. I will take care not to knowingly suggest courses of action that might damage your computer. However it is impossible for me to foresee all interactions that may happen between the software on your computer and those we'll use to clear you of infection, and I cannot guarantee the safety of your system. It is possible that we might encounter situations where the only recourse is to re-format and re-install your operating system, or to necessitate you taking your computer to a repair shop. Because of this, I advise you to backup any personal files and folders before you start. Please don't use the steps give to other users. Those steps are strictly for that user only.. Trying those steps in your computer may crash your computer... STEP 1: Repair your Windows Registry from this infection malicious changes. This infection has changed your Windows registry settings so that when you try to start the computer it will load the infections instead of your Windows Desktop.
Now restart the computer and check if you are able to start the computer normally. You should be able to run both scans while in Normal mode... STEP 2: Run a scan with Malwarebytes Anti-Malware in Chamelon mode
What's next? Add the following logs to your next post (You can find here details on how to use the Attachment System): 1. MalwareBytes log 2. Let me know if you had any problems with the above instructions and also let me know how things are running now! Bulild up Your Malware Defenses in Security Configuration Wizard Forum. | | | Learn How to Avoid Malware!!! Here
|
|||
|
01-23-2013, 02:31 PM
|
|||
|
|||
|
RE: Department of Justice Block
The first link you gave me, "REGISTRYFIX.REG DOWNLOAD LINK" would just open up Windows Media Player. So I'm not sure what to do.
|
|||
|
01-23-2013, 06:49 PM
|
|||
|
|||
RE: Department of Justice Block
(01-23-2013 02:31 PM)Nonnie wrote: The first link you gave me, "REGISTRYFIX.REG DOWNLOAD LINK" would just open up Windows Media Player. So I'm not sure what to do. Please right click on that link and select Save Link as... After that save it on your computer. Then open the file... Bulild up Your Malware Defenses in Security Configuration Wizard Forum. | | | Learn How to Avoid Malware!!! Here
|
|||
|
01-24-2013, 09:35 AM
|
|||
|
|||
|
RE: Department of Justice Block
Well I did as instructed and everything seems to be working perfectly! My desktop is back and the scans showed that everything is okay. I attached to logs anyway though, just in case.
|
|||
|
01-24-2013, 10:27 AM
|
|||
|
|||
|
RE: Department of Justice Block
It is nice to see your desktop is back...
There is some more infected files showing in your last OTL log... Try the following steps to remove them.. ![]() STEP 1: Run the below OTL fix
Bulild up Your Malware Defenses in Security Configuration Wizard Forum. | | | Learn How to Avoid Malware!!! Here
|
|||
|
01-24-2013, 12:18 PM
(This post was last modified: 01-24-2013 12:18 PM by Nonnie.)
|
|||
|
|||
|
RE: Department of Justice Block
All processes killed
========== FILES ========== C:\ProgramData\dsgsdgdsgdsgw.js moved successfully. C:\windows\tasks\ROC_JAN2013_TB_rmv.job moved successfully. C:\ProgramData\KGyGaAvL.sys moved successfully. C:\Users\Nikita\AppData\Local\recently-used.xbel moved successfully. C:\Users\Nikita\AppData\Roaming\.freeciv-client-rc-2.3 moved successfully. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 56466 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Nikita ->Temp folder emptied: 2952843201 bytes ->Temporary Internet Files folder emptied: 1476935945 bytes ->Java cache emptied: 18161 bytes ->Google Chrome cache emptied: 6473344 bytes ->Flash cache emptied: 8067488 bytes User: Public %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 390730623 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 67429 bytes RecycleBin emptied: 492274374 bytes Total Files Cleaned = 5,081.00 mb [EMPTYFLASH] User: All Users User: Default ->Flash cache emptied: 0 bytes User: Default User ->Flash cache emptied: 0 bytes User: Nikita ->Flash cache emptied: 0 bytes User: Public Total Flash Files Cleaned = 0.00 mb [EMPTYJAVA] User: All Users User: Default User: Default User User: Nikita ->Java cache emptied: 0 bytes User: Public Total Java Files Cleaned = 0.00 mb OTL by OldTimer - Version 3.2.69.0 log created on 01242013_070314 Files\Folders moved on Reboot... C:\Users\Nikita\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully. C:\Users\Nikita\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\YG7ZJEC2\search[5].htm moved successfully. C:\Users\Nikita\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PSV9RVME\1[1].gif moved successfully. C:\Users\Nikita\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PSV9RVME\1[2].gif moved successfully. C:\Users\Nikita\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PSV9RVME\1[3].gif moved successfully. C:\Users\Nikita\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PSV9RVME\1[4].gif moved successfully. C:\Users\Nikita\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\C1FSY0O0\fastbutton[1].htm moved successfully. C:\Users\Nikita\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\C1FSY0O0\processInputRequest[1].htm moved successfully. C:\Users\Nikita\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\C1FSY0O0\Thread-Department-of-Justice-Block[1] moved successfully. C:\Users\Nikita\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B3E6Y67H\1[1].gif moved successfully. C:\Users\Nikita\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B3E6Y67H\1[2].gif moved successfully. C:\Users\Nikita\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B3E6Y67H\fastbutton[1].htm moved successfully. C:\Users\Nikita\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B3E6Y67H\Thread-Department-of-justice-block-malware-help[1] moved successfully. C:\Users\Nikita\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B3E6Y67H\tweet_button.1359007731[1].htm moved successfully. PendingFileRenameOperations files... Registry entries deleted on Reboot... Sorry, it wouldn't let me attach it. I hope that's okay. |
|||
|
01-25-2013, 01:01 AM
|
|||
|
|||
|
RE: Department of Justice Block
No problem...
![]() Please run the following tools and send me the logfiles..... STEP 1: Run Temp File Cleaner by OldTimer
STEP 2: Run a scan with AdwCleaner
STEP 3: Run a scan with ESET Online Scanner
Bulild up Your Malware Defenses in Security Configuration Wizard Forum. | | | Learn How to Avoid Malware!!! Here
|
|||
|
01-25-2013, 03:32 AM
|
|||
|
|||
|
RE: Department of Justice Block
These are the results.
|
|||
|
01-25-2013, 03:35 AM
|
|||
|
|||
|
RE: Department of Justice Block
Okay Cool... That one seems Fine... Are you facing any other issues on the computer now??
STEP 1 : Run a scan with Kaspersky TDSSKiller
Can you please run again HitmanPro and save a log. STEP 2: Run a HitmanPro scan
Bulild up Your Malware Defenses in Security Configuration Wizard Forum. | | | Learn How to Avoid Malware!!! Here
|
|||
|
« Next Oldest | Next Newest »
|
| Possibly Related Threads... | |||||
| Thread: | Author | Replies: | Views: | Last Post | |
| Dept of Justice/FBI Virus | bquinn89 | 1 | 78 |
05-23-2013 11:46 PM Last Post: Fiery |
|
| Department of Justice - MoneyPak Virus | altaf | 1 | 488 |
04-22-2013 11:32 PM Last Post: Fiery |
|
| Dept of Justice MoneyPak Virus | great_mazinga | 25 | 869 |
04-21-2013 11:21 PM Last Post: Fiery |
|
| Dept of Justice | yoyobratt | 3 | 245 |
04-14-2013 10:03 PM Last Post: kuttus |
|
| department of justice malware | deathwing78 | 3 | 237 |
04-02-2013 03:28 AM Last Post: Fiery |
|
User(s) browsing this thread: 1 Guest(s)
Contact Us |
Privacy policy |
Return to Top |
Return to Content |
Lite (Archive) Mode |
RSS Syndication |
Members List |
Forum Team
MalwareTips.com is an independent website.All trademarks mentioned on this page are the property of their respective owners.





There is some more infected files showing in your last OTL log... Try the following steps to remove them.. 






![[Image: wK6vI.png]](http://i.imgur.com/wK6vI.png)
![[Image: fQZ30.png]](http://i.imgur.com/fQZ30.png)