?Malicious? files in C:\Users\MYUSER\AppData\LocalLow\Adobe.


  1. Posts : 5
    Windows 7 64 bit
       #1

    ?Malicious? files in C:\Users\MYUSER\AppData\LocalLow\Adobe.


    So, when I'm in my normal computer, a file kept trying to download .gif files and stuff and Avast! kept marking it as malware and stopping it from downloading, so I tried to figure out when it was from, and it led me to my Adobe folder in LocalLow, and I see 3 folders, named a bunch of random letters that have files that are ALSO named things completely random, a .exe file keeps executing itself while I'm using the computer and using 90kb of RAM and opens MANY of them, however, Avast! and MalwareBytes have had no luck removing it, I'm in safe mode with networking right now and still, nothing. I'd really appreciate some help.

    The file that kept auto executing was
    gyizacobfkwx.exe
    it seems to be masquerading itself as google chrome.

    Inside my adobe folder, one of the gibberish folders is filled with stuff that looks like a /users folder merged with my windows folder, except none of the inside folders contain any files.

    In my normal computer use, I also tried running rkill, but rkill didn't do anything at all. I don't know what I'm dealing with right now.

    I tried to run Avast! but it seemed to have disabled avast somehow? I don't know how. It tells me that it can't run the scan because of missing endpoints.
      My Computer


  2. Posts : 1,049
    Windows 7 Pro 32
       #2

    Try checking the file on virustotal.com and see what anti-virus products pick up something and to find out what kind of malware it is. Then see if any of the well known AV's that detected something have a free online scanner you can try.

    You can try Autoruns to perhaps stop the program from starting after boot. Autoruns for Windows
      My Computer


  3. Posts : 1
    Windows 7 Home Premium 32bit
       #3

    Any luck?


    I am experiencing the exact same issue, with different file names of course.
    Was there ever a solution offered that was NOT an advertisement for antivirus software?
      My Computer


  4. Posts : 1,049
    Windows 7 Pro 32
       #4

    Autoruns was released in a new version a few days ago, now with VirusTotal support. So give that a try to try and find any malicious startup items:

    https://technet.microsoft.com/en-us/.../bb963902.aspx

    If you need more info here's a review: Startup Manager Autoruns 13 introduces Virustotal integration - gHacks Tech News
      My Computer


  5. Posts : 2,470
    Windows 7 Home Premium
       #5

    Let's see what the following detects...

    Please use the Farbar Recovery Scan Tool Download
    Select the version that applies to your system.
    Save it to your Desktop.
    Double-click the downloaded file to run it.
    When the tool opens, click Yes to the disclaimer.

    Press the Scan button.

    When done, the tool makes a log, FRST.txt, in the same directory from which the tool is run (Desktop).

    Please provide the FRST.txt in your reply.
    The first time the tool is run, it also creates another log: Addition.txt

    Also post the Addition.txt in your reply.
    Last edited by cottonball; 03 Feb 2015 at 08:41.
      My Computer


 

  Related Discussions
Our Sites
Site Links
About Us
Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 19:07.
Find Us