Status
Not open for further replies.
Operating System
Windows 8
Infection date and initial symptoms
March 9th
flash drive data are moved to .trash folder (hidden) and with a new folder in it (sequance number) containing java script
i had kaspersky IS 2015 installed it detected Heur:trojan.WinLNK.Generic and removed it only to appear again
Current issues and symptoms
denied some administrative rights like
- cant run msconfig
- when try to run FRST64 it immediately close
- tried to install mbam-setup-2.0.4.1028 but denied
- cant get into safemode by the Shift+restart Method
- Hidden Item gets unchecked in the view options in explorer
- cant run Adwcleaner too
Steps taken in order to remove the infection
- downloaded "smadav10" scaned and found some errors, fixed the errors but didnt remove the trojan... removed
- downloaded "EmsisoftAntiMalwareSetup" update and scaned... found
Emsisoft Anti-Malware - Version 9.0
Quarantine log

Date Source Event Detection
3/11/2015 11:13:31 AM C:\ProgramData\Kaspersky Lab\AVP15.0.1\QB\b24902c3f6273f76.klq Deleted infection Trojan.LNK.Gen (B)
3/11/2015 10:45:13 AM I:\System Volume Information.lnk Moved to quarantine Trojan.LNK.Gen (B)
3/11/2015 10:44:58 AM I:\System Volume Information.lnk Moved to quarantine Trojan.LNK.Gen (B)
3/11/2015 10:44:43 AM I:\System Volume Information.lnk Moved to quarantine Trojan.LNK.Gen (B)
3/11/2015 10:44:28 AM I:\System Volume Information.lnk Moved to quarantine Trojan.LNK.Gen (B)

- Ran Norton Power Eraser... one of the risks he couldnt fix was a number.sy
- installed BitDefender and it didnt recognize anything

Belal Kelany

New Member
when starting to get into safe mode it works untill the step where i choose the safemode option (networking, command prompt....) then it is as if the keyboard isnt working at all (connected through wireless keyboard)
 

Attachments

Belal Kelany

New Member
when i try to run FRST or AdwCleaner as adminstrator it gets immediately closed
i saw a fellow member post having the same problem and could resolve it by going into safe mode only i cant
when starting to get into safe mode it works untill the step where i choose the safemode option (networking, command prompt....) then it is as if the keyboard isnt working at all (connected through wireless keyboard)
 

argus

Former MalwareTips Staff
Do you have a different keyboard?
Try double-clicking on Farbar.

Uninstall antivirus and download new FRST.
 
Status
Not open for further replies.