Something I found, malware related!

Gib

Level 3
Thread author
Verified
Well-known
May 23, 2014
113
I went to internet options
then down to where it says browsing history I hit the settings button and I was
taken aback to find this message, "The amount of disk space currently set aside
to store temporary internet files.....," After I had set the "disk space to use" at 250mb (which I read
is the default setting) someone changed it.When I clicked on cancel, I could see the
amount on "disk space to use." Its at a whopping 257024mb!



I'm just thinking that with the Farbar Recovery Scan Tool could zero in where the settings are being bothered with and thats where you go in internet options, then general tab, then browsing history where you see settings in browsing history, then click settings(then a pop-up message) then I would click the cancel button to see the amount displayed.
 

Attachments

  • FRST.txt
    29.5 KB · Views: 108
  • Addition.txt
    22 KB · Views: 74

argus

Former MalwareTips Staff
Verified
Apr 24, 2014
3,395
Helllo,

Before we begin, please note the following:
  • I will working be on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The logs can take some time to research, so please be patient with me.
  • Stay with the topic until I tell you that your system is clean. Missing symptoms does not mean that everything is okay.
  • Instructions that I give are for your system only!
  • Please do not run any tools until requested ! The reason for this is so I know what is going on with the machine at any time. Some programs can interfere with others and hamper the recovery process.
  • Please perform all steps in the order received. If you can't understand something don't hesitate to ask.
  • Again I would like to remind you to make no further changes to your computer unless I direct you to do so. I will not help you if you do not follow my instructions.




FRST.gif
Fix with Farbar Recovery Scan Tool

icon_exclaim.gif
This fix was created for this user for use on that particular machine.
icon_exclaim.gif

icon_exclaim.gif
Running it on another one may cause damage and render the system unstable.
icon_exclaim.gif
Download attached fixlist.txt file and save it to the Desktop:

Both files, FRST and fixlist.txt have to be in the same location or the fix will not work!

  • Right-click on
    FRST.gif
    icon and select
    RunAsAdmin.jpg
    Run as Administrator to start the tool.
    (XP users click run after receipt of Windows Security Warning - Open File).
  • Press the Fix button just once and wait.
  • If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
  • When finished FRST will generate a log on the Desktop, called Fixlog.txt.

Please attach it to your reply.
 

Attachments

  • fixlist.txt
    724 bytes · Views: 62

Gib

Level 3
Thread author
Verified
Well-known
May 23, 2014
113
Ok, here it is.
 

Attachments

  • Fixlog.txt
    1.4 KB · Views: 57

Gib

Level 3
Thread author
Verified
Well-known
May 23, 2014
113
I'm checking something often on my pc. Please leave this thread open, this may or may not become a long thread.
 

Gib

Level 3
Thread author
Verified
Well-known
May 23, 2014
113
I have a question. Do you see something called VPixel.swf when you look in your TIF folder?
c:\Users\Username\Appdata\Local\Microsoft\Windows\Temporary Internet Files

So far this I found is looking suspicious. Btw, I have ie11.
 

argus

Former MalwareTips Staff
Verified
Apr 24, 2014
3,395
51a612a8b27e2-Zoek.png
Scan with ZOEK

Please download ZOEK by Smeenk and save it to your desktop (preferred version is the *.exe one)
Temporary disable your AntiVirus and AntiSpyware protection - instructions here.

  • Right-click on
    51a612a8b27e2-Zoek.png
    icon and select
    RunAsAdmin.jpg
    Run as Administrator to start the tool.
  • Wait patiently until the main console will appear, it may take a minute or two.
  • In the main box please paste in the following script:
    Code:
    createsrpoint;
    autoclean;
    emptyalltemp;
    ipconfig /flushdns;b
  • Make sure that Scan All Users option is checked.
  • Push Run Script and wait patiently. The scan may take a couple of minutes.
  • When the scan completes, a zoek-results logfile should open in notepad.
  • If a reboot is needed, it will be opened after it. You may also find it at your main drive (usually C:\ drive)

Post its content into your next reply.
 

Gib

Level 3
Thread author
Verified
Well-known
May 23, 2014
113
Before I ran zoek, the file that I was mentioning about (VPixel.swf) had stopped producing. It would produce
everytime I would empty out the TIF folder, but ever since I posted in this topic about it, it vanished. That
particular file was one of many different files that's appearing in the folder. I forgot to mention that the problem with the internet options I had days ago might be corrected, but I am still looking to see if it is corrected for good. So far I only have 1 plan.
 

Attachments

  • zoek-results.log
    5.7 KB · Views: 222

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top