UKASH Virus .....again :(

darrenj1471

Lets see what cottonball says . I don't see any virus files
 

My Computer

Computer Manufacturer/Model Number
Custom Built
OS
Windows 7 Ultimate 32-Bit & Windows 7 Ultimate 64-Bit
CPU
Intel Core i7 CPU 950 @ 3.07GHz
Motherboard
ASUS P6T DELUXE V2
Memory
OCZ 6GB (3 x 2GB) 240-Pin DDR3 SDRAM DDR3 1600 OCZ3X1600R2
Graphics Card(s)
ATI Radeon HD 5700 Series
Sound Card
OnBoard
Hard Drives
WD6400AACS-00M3B0 (640GB SATA )
PSU
CORSAIR 850w
Case
NZXT LEXA
Cooling
Intel Stock Heatsink Fan
Keyboard
Microsoft Wireless Laser Keyboard 7000
Mouse
Microsoft Wireless Laser Mouse 7000
As far as malware goes, do not see any on the RogueKiller report.

The following entries are, to my understanding, some type of AVG request to provide additional protection:
[TASK][SUSP PATH] ROC_REG_JAN_DELETE.job : C:\ProgramData\AVG January 2013 Campaign\ROC.exe /DELETE_FROM_SYSTEM=1 [7] -> FOUND
[TASK][SUSP PATH] ROC_REG_JAN_DELETE : C:\ProgramData\AVG January 2013 Campaign\ROC.exe /DELETE_FROM_SYSTEM=1 [7] -> FOUND

Looks as if you may have accepted it.
 

Attachments

  • Capture AVG Promo.PNG
    Capture AVG Promo.PNG
    28.1 KB · Views: 18

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
An ol' eMachines
OS
Windows 7 Home Premium
Internet Speed
Fine for me...I'm retired!
So....Im done? I shouldn't delete those 4 registry results found by RogueKiller? How on earth am I getting this over and over?

I will now use that tool to uninstall AVG and install MSE but Im paranoid about my internet banking etc so presume there is nothing lingering around on this machine which could be bad ??
 

My Computer

OS
windows 7 64 bit
The following program may show areas in which there are vulnerabilities.

Let’s check the Security status with the following: Security Check
http://screen317.spywareinfoforum.org/
Save to your Desktop.

Double-click SecurityCheck.exe
Follow the onscreen instructions inside the black box.

When done, a Notepad report opens automatically, called: checkup.txt

Please post the checkup.txt in your reply.

Note:
Please do not take any corrective actions!!
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
An ol' eMachines
OS
Windows 7 Home Premium
Internet Speed
Fine for me...I'm retired!
Still need to look at the results of Security Check, however, in any event, you may want to change all passwords, in particular to bank accounts and credit cards. Also include passwords used to access websites on the Internet.
Use a different and clean computer to do so, and use passwords that are difficult to figure out.

Download and install an AntiVirus program and an anti-malware program like Malwarebytes-AntiMalware, before connecting to the Internet again.

Use the Windows Firewall, or download a free one:

ZoneAlarm Free Firewall
Best Free Firewall

Outpost Firewall Free
Best Free Firewall

Online Armor Free
Best Free Firewall

A Firewall monitors your system's communication between your network and the Internet and helps stop intrusions and attacks.

If you do a Google search, there may be other free Firewalls available. Also, someone here might suggest one.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
An ol' eMachines
OS
Windows 7 Home Premium
Internet Speed
Fine for me...I'm retired!
Mate, now may be a good time to consider a clean install of the system, if you are able and willing: Installing and reinstalling Windows 7

Don't feel pressured, but it is a very good option to ensure that everything is ship-shape. back up important files first, and before putting them back on the computer, make sure you have an adaquat antivirus installed before-hand. I wouldn't use an extra firewall, because far too many times more problems are created by them, unless you are an advanced user. Besides, windows firewall does an adequate job itself, including the smartscreen filter.

EDIT: [If you prefer to keep the system, let me know, and I'll try to help you out in addition to anyone else.] Reading back, you've been helped by an excellent team.

Forgive me if I mentioned something already covered, as I have not yet read through this topic. Cheers!
 
Last edited:

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Asus Build
OS
Microsoft Windows 8.1 Pro 64-bit
CPU
Intel(R) Core(TM) i3-4130 CPU @ 3.40GHz
Motherboard
B85M-E
Memory
8.00 GB
Graphics Card(s)
None
Sound Card
Realtek High Definition Audio
Monitor(s) Displays
Asus 23.6" Monitor
Screen Resolution
1920 x 1080 x 32 bits (4294967296 colors) @ 60 Hz
Hard Drives
INTEL SSDSC2BW180A4
Samsung SSD 840 PRO Series
PSU
Seasonic S12II-380Bronze
Case
Lian Li
Cooling
Fan, Passive
Keyboard
Logitech K120
Mouse
Microsoft Touch Mouse
Internet Speed
4ms Ping, 19.0 Mbps Download, 19.0 Mbps Upload
Antivirus
Eset Endpoint
Browser
Internet Explorer, Chrome
please see my latest post where I mention I have the virus again for 3 rd time and this time its worse. I would happily reinstall windows once I can get access to back up some files
 

My Computer

OS
windows 7 64 bit
You are in good hands mate, give Cotton and friends some time to respond. He is still around
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Asus Build
OS
Microsoft Windows 8.1 Pro 64-bit
CPU
Intel(R) Core(TM) i3-4130 CPU @ 3.40GHz
Motherboard
B85M-E
Memory
8.00 GB
Graphics Card(s)
None
Sound Card
Realtek High Definition Audio
Monitor(s) Displays
Asus 23.6" Monitor
Screen Resolution
1920 x 1080 x 32 bits (4294967296 colors) @ 60 Hz
Hard Drives
INTEL SSDSC2BW180A4
Samsung SSD 840 PRO Series
PSU
Seasonic S12II-380Bronze
Case
Lian Li
Cooling
Fan, Passive
Keyboard
Logitech K120
Mouse
Microsoft Touch Mouse
Internet Speed
4ms Ping, 19.0 Mbps Download, 19.0 Mbps Upload
Antivirus
Eset Endpoint
Browser
Internet Explorer, Chrome
In post #68 Cottonball was still waiting for some results from Security Check.
I would advise you to avoid the Sports Event streaming site.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Home Built Desktop By DataTech
OS
Windows 7 Ultimate X64 SP1
CPU
Intel i5-2550K, Differing ~4.4-4.8GHz No built in GPU
Motherboard
ASUS P8Z68-V PRO/GEN3
Memory
16GB G.Skill Sniper 1866MHz @ 2133MHz 2x8GB
Graphics Card(s)
ASUS GTX650TIB-DC2OC-2GD5, (650TI Boost)
Sound Card
Onboard Realtek 5-1
Monitor(s) Displays
Samsung P2570HD
Screen Resolution
1920x1080
Hard Drives
Samsung 840 Pro 256GB SSD for OS, 500GB Seagate Constellation (Enterprise drive) for Data
PSU
Corsair HX650W
Case
Inwin Dragon Rider
Cooling
Hyper 212 EVO w/two Noctua fans, push-pull, @1300 RPM
Keyboard
E-Z Eyes, bright yellow keys with large characters
Mouse
steelseries SENSEI Laser Pro Gaming
Internet Speed
48-51Mbs Mbs down, 11 Mbs up Xfinity Cable
Antivirus
Norton Internet Security 2013
Browser
IE 10, Opera, Pale Moon if needed
Other Info
4 case fans, LG BluRay-RE, ASUS DVD-RW, Mr. Fusion power supply, 1.21 gigawatts.
darrenj1471,

If this infection has returned again, it is because all it takes to get infected is to visit a malicious website, click on a malicious advertisement/link, open a malicious attachment, or download a file which contains malware code. Security vulnerabilities on your computer's Operating System, or in a program like your web browser, can also be exploited.

This is the first time ever that I've had a third-timer!!


Regardless of what you plan to do, see if you can do what follows. You ran this program before, but it is continuously updated, so you need a new copy.

:info: Please go to the Farbar Recovery Scan Tool Download
Select the version that applies to your system.

Save it to your Desktop.http://www.sevenforums.com/
Double-click the downloaded file to run it.

When the tool opens click Yes to the disclaimer.
Press the Scan button.

FRST64 makes a log (FRST.txt) in the same directory from which the tool is run (Desktop).

Please provide the FRST.txt in your reply. <<---

The first time the tool is run, it also makes another log: Addition.txt
Also post the: Addition.txtin your reply.<<---
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
An ol' eMachines
OS
Windows 7 Home Premium
Internet Speed
Fine for me...I'm retired!
Just read your last post mentioning you have no access. The above will nor work...

:info: One option..go back to Post #2, and use HitmanPro.KickStart again. It should get you in.


:info: Other options:

1. Do you have an installation CD/DVD for Windows 7?

2. If not, when you start the computer, tap the F8 key. Does the Advanced Boot Options menu appear? Do you have access to the Repair your computer menu item?

3. If none of the above are options, do you have access to a computer with a Windows 7 64-bit system, to create a System Repair Disk?

:ar: What is the exact name of the ransomware this time?
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
An ol' eMachines
OS
Windows 7 Home Premium
Internet Speed
Fine for me...I'm retired!
Hi please could you review my other current thread where I have posted pics. I cannot get hitman to run as im now also having issues rendering things on screen ie the software loads up but all the buttons fail to show. get similar issue when trying to do rstrui through command prompt
 

My Computer

OS
windows 7 64 bit
Best to have one thread for the same issue.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Home Built Desktop By DataTech
OS
Windows 7 Ultimate X64 SP1
CPU
Intel i5-2550K, Differing ~4.4-4.8GHz No built in GPU
Motherboard
ASUS P8Z68-V PRO/GEN3
Memory
16GB G.Skill Sniper 1866MHz @ 2133MHz 2x8GB
Graphics Card(s)
ASUS GTX650TIB-DC2OC-2GD5, (650TI Boost)
Sound Card
Onboard Realtek 5-1
Monitor(s) Displays
Samsung P2570HD
Screen Resolution
1920x1080
Hard Drives
Samsung 840 Pro 256GB SSD for OS, 500GB Seagate Constellation (Enterprise drive) for Data
PSU
Corsair HX650W
Case
Inwin Dragon Rider
Cooling
Hyper 212 EVO w/two Noctua fans, push-pull, @1300 RPM
Keyboard
E-Z Eyes, bright yellow keys with large characters
Mouse
steelseries SENSEI Laser Pro Gaming
Internet Speed
48-51Mbs Mbs down, 11 Mbs up Xfinity Cable
Antivirus
Norton Internet Security 2013
Browser
IE 10, Opera, Pale Moon if needed
Other Info
4 case fans, LG BluRay-RE, ASUS DVD-RW, Mr. Fusion power supply, 1.21 gigawatts.
I agree but this time the issue is worse as blue screen is displayed shortly after UKASH takes over ie when it throws the white lock screen. Also PC is exhibiting strange things when hitman or system restore is attempted.

The thread is here: http://www.sevenforums.com/system-security/306023-ukash-3rd-time.html

I dont have the jpgs with me to replicate in this thread but could do later when at home.

Currently the only PC I have access to is a laptop running Vista so I cannot get 64 bit version of HitmanPro but it seems the 32 bit has a x64 file in it?
 

My Computer

OS
windows 7 64 bit
Back
Top