We’d like to remind Forumites to please avoid political debate on the Forum.

This is to keep it a safe and useful space for MoneySaving discussions. Threads that are – or become – political in nature may be removed in line with the Forum’s rules. Thank you for your understanding.

📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!
The Forum now has a brand new text editor, adding a bunch of handy features to use when creating posts. Read more in our how-to guide

Trojan Possibly Crashing Avira?

1456810

Comments

  • Fire_Fox
    Fire_Fox Posts: 26,026 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Combo Breaker
    edited 28 February 2010 at 2:29AM
    Soooo I surfed a little and found several references to people unable to turn on their FS wireless using the Function F1 combo. Possible cure might be to reinstall the launch manager from the FS website. Sounded safe enough so went to FS, can't find a launch manager, but found "DeskUpdate is an application for automatically software installation (drivers and utilities)."
    Sounded good so installed that and ran it. This was downloading some updates when ... the laptop turned itself off again! :(

    I have also found the network connections area, and whether the wireless network connection is enabled or disabled it doesn't connect wirelessly to the router. I have tried turning the router on and off, also tried diagnosing and it tells me to turn the wireless capability on.

    So I did this and it now works automatically!
    http://forum.ts.fujitsu.com/forum/viewtopic.php?f=89&t=31866
    Declutterbug-in-progress.⭐️⭐️⭐️ ⭐️⭐️
  • aliEnRIK
    aliEnRIK Posts: 17,741 Forumite
    Part of the Furniture Combo Breaker
    Did you run a full Avira scan?
    :idea:
  • Fire_Fox
    Fire_Fox Posts: 26,026 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Combo Breaker
    Hi aliEnRIK, Avira just found the same EICAR test signature - but laptop turned itself off randomly twice more last night neither time was I running any scans or downloading anything sensitive. :( Other than that it seems to be starting up fairly slowly but loading net pages faster!
    Declutterbug-in-progress.⭐️⭐️⭐️ ⭐️⭐️
  • aliEnRIK
    aliEnRIK Posts: 17,741 Forumite
    Part of the Furniture Combo Breaker
    Run hijack and combofix again ~ im intrigued as to whats still running
    :idea:
  • Fire_Fox
    Fire_Fox Posts: 26,026 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Combo Breaker
    edited 28 March 2010 at 3:30AM
    Xxxxxxxxxxxxxx
    Declutterbug-in-progress.⭐️⭐️⭐️ ⭐️⭐️
  • Fire_Fox
    Fire_Fox Posts: 26,026 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Combo Breaker
    edited 28 March 2010 at 3:30AM
    Xxxxxxxxxxxxxxxxx
    Declutterbug-in-progress.⭐️⭐️⭐️ ⭐️⭐️
  • Fire_Fox
    Fire_Fox Posts: 26,026 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Combo Breaker
    edited 28 March 2010 at 3:30AM
    Xxxxxxxxxxxxxxxx
    Declutterbug-in-progress.⭐️⭐️⭐️ ⭐️⭐️
  • Fire_Fox
    Fire_Fox Posts: 26,026 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Combo Breaker
    aliEnRIK wrote: »
    Run hijack and combofix again ~ im intrigued as to whats still running

    Thanks so much for still being interested! That is all of the Combofix log, it isn't anything like the last one I ran which would have been ten or fifteen posts had I posted it all. :huh: Avira is definitely switched off, and so is Defender as far as I can tell even tho it does say Defender is enabled in the log!
    Declutterbug-in-progress.⭐️⭐️⭐️ ⭐️⭐️
  • aliEnRIK
    aliEnRIK Posts: 17,741 Forumite
    Part of the Furniture Combo Breaker
    This is what Bleeping Computer (makers of combofix amongst other things) think of Nielson ~
    http://www.bleepingcomputer.com/startups/NielsenOnline.exe-13539.html

    Heres what prevX think of panelapp.exe ~
    http://www.prevx.com/filenames/X3844902891725498344-X1/PANELAPP.EXE.html

    When we started I wanted to remove them, and that certainly hasnt changed

    I would seriously recommend you remove EVERYTHING to do with them

    Anyways ~
    Rerun ccleaner to remove all temp files


    Open notepad and copy/paste the text in RED below

    File::
    c:\windows\system32\RMActivate_isv.exe
    c:\windows\system32\RMActivate.exe
    c:\windows\system32\secproc_isv.dll
    c:\windows\system32\secproc_ssp_isv.dll
    c:\windows\system32\secproc_ssp.dll
    c:\windows\system32\secproc.dll
    c:\windows\system32\msdrm.dll
    c:\windows\system32\RMActivate_ssp_isv.exe
    c:\windows\system32\RMActivate_ssp.ex




    Save this as "CFScript" (FULL file will be 'CFScript.txt' EXACTLY as shown)

    Then drag the CFScript into ComboFix.exe as you see in the screenshot below.

    CFScript.gif


    This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply

    Combofix should never take more that 30 minutes including the reboot if malware is detected.
    If it does, open Task Manager then Processes tab (press ctrl, alt and del at the same time) and end any processes of findstr, find, sed or swreg, then combofix should continue.


    Then run this Kaspersky scanner ~
    http://devbuilds.kaspersky-labs.com/devbuilds/AVPTool/

    ***DO NOT PLUG ANY EXTERNAL DEVICES IN UNTIL WE 'BELIEVE' ITS CLEAN'***
    :idea:
  • Fire_Fox
    Fire_Fox Posts: 26,026 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Combo Breaker
    I ran Combofix but forgot to turn off Avira and it got a bit upset and there were loads of pop ups about worms. Carried on right up to the point of producing a log and then the computer turned off. Started again from scratch (with Avira off) and it got most of the way through before saying it couldn't find some files and the computer turned off again. I think this problem my fault ...very sorry. :(

    I read those two links about Nielsen but it went right over my head. I know Nielsen is spying on me, TBH I really need the money coming in as I am unemployed. :o Are the links saying that the Nielsen software is easily hijacked and will allow trojans/ viruses in or is are the links saying that Nielsen themselves are spying on more than I realise? If you think there the trojans are hiding in the Nielsen software then I need to remove it and (perhaps) reinstall a clean version later?

    Thanks again!
    Declutterbug-in-progress.⭐️⭐️⭐️ ⭐️⭐️
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 354.4K Banking & Borrowing
  • 254.4K Reduce Debt & Boost Income
  • 455.4K Spending & Discounts
  • 247.3K Work, Benefits & Business
  • 604.1K Mortgages, Homes & Bills
  • 178.4K Life & Family
  • 261.6K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16K Discuss & Feedback
  • 37.7K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.