HELP... [Suspicious.Path|VT.Trojan.Siggen6.58323]

melen1717

Level 1
Verified
I have included various files:
No file for Malwarebytes.

Sometime it feels as if someone is on my PC. I received a pop-up notice from ESET on line scanner "use custom proxy settings" configure so wasn't able to scan. First time this has happened to me. I went to Firefox options and verified that my "configure proxies to access internet" is set to "use system proxies settings". I will appreciate your advice and help.

Thanks

George
 

Attachments

Hello,


Please download Zemana AntiMalware and save it to your Desktop.
  • Install the program and once the installation is complete it will start automatically.
  • Without changing any options, press Scan to begin.
  • After the short scan is finished, if threats are detected press Next to remove them.
Note: If restart is required to finish the cleaning process, you should click Reboot. If reboot isn't required, please restart your computer manually.​
  • Open Zemana AntiMalware again.
  • Click on
    4zu6vb.jpg
    icon and double click the latest report.
  • Now click File > Save As and choose your Desktop before pressing Save.
  • The only left thing is to attach saved report in your next message.



51a612a8b27e2-Zoek.png
Scan with ZOEK

Please download ZOEK by Smeenk and save it to your desktop.
Temporary disable your AntiVirus and AntiSpyware protection - instructions here.

  • Right-click on
    51a612a8b27e2-Zoek.png
    icon and select
    RunAsAdmin.jpg
    Run as Administrator to start the tool.
  • Wait patiently until the main console will appear, it may take a minute or two.
  • In the main box please paste in the following script:
    Code:
    createsrpoint;
    autoclean;
    emptyclsid;
    emptyalltemp;
    ipconfig /flushdns >>"%temp%\log.txt";b
  • Make sure that Scan All Users option is checked.
  • Push Run Script and wait patiently. The scan may take a couple of minutes.
  • When the scan completes, a zoek-results logfile should open in notepad.
  • If a reboot is needed, it will be opened after it. You may also find it at your main drive (usually C:\ drive)

Upload it in your next reply.
 
Hello,


Please download Zemana AntiMalware and save it to your Desktop.
  • Install the program and once the installation is complete it will start automatically.
  • Without changing any options, press Scan to begin.
  • After the short scan is finished, if threats are detected press Next to remove them.
Note: If restart is required to finish the cleaning process, you should click Reboot. If reboot isn't required, please restart your computer manually.​
  • Open Zemana AntiMalware again.
  • Click on
    4zu6vb.jpg
    icon and double click the latest report.
  • Now click File > Save As and choose your Desktop before pressing Save.
  • The only left thing is to attach saved report in your next message.


51a612a8b27e2-Zoek.png
Scan with ZOEK

Please download ZOEK by Smeenk and save it to your desktop.
Temporary disable your AntiVirus and AntiSpyware protection - instructions here.

  • Right-click on
    51a612a8b27e2-Zoek.png
    icon and select
    RunAsAdmin.jpg
    Run as Administrator to start the tool.
  • Wait patiently until the main console will appear, it may take a minute or two.
  • In the main box please paste in the following script:
    Code:
    createsrpoint;
    autoclean;
    emptyclsid;
    emptyalltemp;
    ipconfig /flushdns >>"%temp%\log.txt";b
  • Make sure that Scan All Users option is checked.
  • Push Run Script and wait patiently. The scan may take a couple of minutes.
  • When the scan completes, a zoek-results logfile should open in notepad.
  • If a reboot is needed, it will be opened after it. You may also find it at your main drive (usually C:\ drive)

Upload it in your next reply.
Hi...

Sorry it took me so long to get back. I was on a very long vacation and most needed vacation.

Their is no file for ZOEK. After it stopped it did not place any file.

I will run ZOEK again and what happens.

Thanks
George
 
Here again...

ZOEK has been running for over an hour. This is the scan report information:



Zoek.exe v5.0.0.1 Updated 31-December-2015
Tool run by melen on Sun 05/29/2016 at 16:01:21.18.
Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\melen\Downloads\zoek.exe [Scan all users] [Script inserted]

===== Runcheck 16:02:28.27 =====

--- Create Environment Variables 16:02:30.94
--- Create System Restore Point 16:02:43.14
--- Checking Input 16:03:02.89
--- AU AppData Check 16:03:48.71
--- Remove From Windows Installer 16:03:56.60
--- Empty Folders Check 16:07:10.43
--- Registry HKLM Software Check 16:07:10.46
--- Quick Launch Shortcut Check 16:07:48.97
--- IE Startpage Check 16:08:20.97
--- Program Files DB Check 16:09:11.85
--- C:\Users\Default\AppData\Roaming DB Check 16:10:48.46
--- C:\Users\Default User\AppData\Roaming DB Check 16:10:48.46
--- C:\Users\melen\AppData\Roaming DB Check 16:10:48.46
--- C:\windows\SysNative\config\systemprofile\AppData\Roaming DB Check 16:10:48.46
--- C:\windows\sysWoW64\config\systemprofile\AppData\Roaming DB Check 16:10:48.46
--- C:\windows\serviceprofiles\networkservice\AppData\Roaming DB Check 16:10:48.46
--- C:\windows\serviceprofiles\Localservice\AppData\Roaming DB Check 16:10:48.46
--- C:\Users\melen DB Check 16:15:46.68
--- C:\PROGRA~3 DB Check 16:16:22.59
--- C:\Users\ADMINI~1\AppData\Local DB Check 16:16:54.46
--- C:\Users\Default\AppData\Local DB Check 16:16:54.46
--- C:\Users\Default User\AppData\Local DB Check 16:16:54.46
--- C:\Users\melen\AppData\Local DB Check 16:16:54.46
--- C:\windows\SysNative\config\systemprofile\AppData\Local DB Check 16:16:54.46
--- C:\windows\sysWoW64\config\systemprofile\AppData\Local DB Check 16:16:54.46
--- C:\windows\serviceprofiles\networkservice\AppData\Local DB Check 16:16:54.46
--- C:\windows\serviceprofiles\Localservice\AppData\Local DB Check 16:16:54.46
--- C:\ProgramData\Microsoft\Windows\Start Menu\Programs DB Check 16:20:46.72
--- C:\Users\melen\AppData\Roaming\Microsoft\Windows\Start Menu\Programs DB Check 16:21:08.83
--- Tasks DB Check 16:21:22.76
--- Downloads DB Check 16:21:31.97
--- C:\Users\melen\AppData\LocalLow DB Check 16:21:40.34
--- C:\windows\SysNative\config\systemprofile\AppData\LocalLow DB Check 16:21:40.34
--- C:\windows\sysWoW64\config\systemprofile\AppData\LocalLow DB Check 16:21:40.34
--- C:\windows\serviceprofiles\networkservice\AppData\LocalLow DB Check 16:21:40.34
--- C:\windows\serviceprofiles\Localservice\AppData\LocalLow DB Check 16:21:40.34
--- Tasks2 DB Check 16:23:20.64
--- Documents DB Check 16:24:29.23
--- C:\Users\melen\AppData\Roaming\Mozilla\Firefox\Profiles\2O3gaW38.default DB Check 16:24:47.78
--- C:\Users\Public\Desktop DB Check 16:24:53.18
--- C:\Users\melen\Desktop DB Check 16:25:05.59
--- Services DB Check 16:25:25.28
--- FF prefs.js DB Check 16:26:24.09
--- Emptyclsid 16:27:54.00
--- Del by CLSID 16:28:00.47 <<<-------- and it seems that it is stuck here. What should I do???

George
 
Please restart your PC.


FRST.gif
Scan with Farbar Recovery Scan Tool

Please re-run Farbar Recovery Scan Tool to give me a fresh look at your system.
  • Right-click on
    FRST.gif
    icon and select
    RunAsAdmin.jpg
    Run as Administrator to start the tool.
    (XP users click run after receipt of Windows Security Warning - Open File).
  • Make sure that Addition.txt option is checked.

    2873ryc.png

  • Press Scan button and wait.
  • The tool will produce two logfiles on your desktop: FRST.txt and Addition.txt.
Please attach report into your next reply.
 

Recently browsing

Members who viewed this thread in the last 5 minutes

Back
Top