Jump to content


  • Posts

  • Joined

  • Last visited


0 Neutral

Profile Information

  • Gender

Recent Profile Visitors

The recent visitors block is disabled and is not being shown to other users.

  1. Hi! Finally we've got it, I think I should say you've got it!! There are no threats on emsisoft antimalware and the system is running ok after a pair of reboots. Thank you very (x10000) much for your help! Izzy
  2. Hi, It's all OK here the only issue was after running combofix that everything was very slow, but the next time I started the PC it was back to normality. Izzy
  3. Hi again, I ran EAM and it seems that 22 posts were too much for that infection... The only file infected has been found in C:\Qoobox\Quarantine\[4]-Submit_2013-02-14_17.40.16.zip -> csc.sys So it may mean that we're finishing the process, aren't we? Izzy
  4. Hi Jeffce! The upload was successful according to Combofix. Here's the log created. Thanks Izzy
  5. Hi! Here's the link https://www.virustotal.com/ca/file/960c118332bc5e83434e19468428a77b45c4effffc4b23bdbe5617a68a08b1db/analysis/1360784906/ Thanks Izzy
  6. Hi Jeffce, I've done what you said in last post. There's the log attached. After a deep scan with emsisoft it detects the same virus in two files: C:\Qoobox\Quarantine\C\Windows\system32\Drivers\csc.sys.vir C:\Windows\winsxs\x86_microsoft-windows-offlinefiles-core_31bf3856ad364e35_6.1.7601.17514_none_a04fb2d2ba296321\csc.sys Thank you Izzy
  7. Hi! Here's what you requested. Malwarebytes found no threats so I skipped the "show results" and "Remove selected" steps. Eset Online Scanner says this: C:\Qoobox\Quarantine\C\Users\Tuka-Izzy\AppData\Local\TempDIR\BetterInstaller.exe.vir a variant of Win32/Somoto.A application C:\Qoobox\Quarantine\C\Windows\system32\Drivers\csc.sys.vir a variant of Win32/Rootkit.Kryptik.ST trojan C:\Windows\AutoKMS\AutoKMS.exe a variant of Win32/HackKMS.B application C:\Windows\winsxs\x86_microsoft-windows-offlinefiles-core_31bf3856ad364e35_6.1.7601.17514_none_a04fb2d2ba296321\csc.sys a variant of Win32/Rootkit.Kryptik.ST trojan D:\Documents and Settings\Izzy\Downloads\Guitar_Building-All-Albums-(Special-Edition).exe Win32/Adware.1ClickDownload.J application D:\Documents and Settings\Izzy\Downloads\Make_Your_Own_Electric_Guitar_Melvyn_Hiscock_CV_pdf.exe Win32/Adware.1ClickDownload.J application D:\Documents and Settings\Izzy\Downloads\Make_Your_Own_Electric_Guitar_Melvyn_Hiscock_pdf.exe Win32/Adware.1ClickDownload.J application D:\Documents and Settings\Izzy\Downloads\Martin_Koch_Building_Electric_Guitars_pdf (1).exe Win32/Adware.1ClickDownload.J application D:\Documents and Settings\Izzy\Downloads\Martin_Koch_Building_Electric_Guitars_pdf.exe Win32/Adware.1ClickDownload.J application D:\Documents and Settings\Izzy\Downloads\SaveAs (1).exe Win32/InstalleRex.E.Gen application D:\Documents and Settings\Izzy\Downloads\SaveAs (2).exe Win32/InstalleRex.E.Gen application D:\Documents and Settings\Izzy\Downloads\SaveAs.exe Win32/InstalleRex.E.Gen application D:\Documents and Settings\Izzy\Downloads\SoftonicDownloader_para_free-mp3-wma-converter.exe a variant of Win32/SoftonicDownloader.D application D:\Documents and Settings\Izzy\Downloads\SoftonicDownloader_para_happy-note-clave-de-sol-y-fa.exe a variant of Win32/SoftonicDownloader.E application D:\Documents and Settings\Izzy\Downloads\SoftonicDownloader_para_k-lite-codec-pack.exe a variant of Win32/SoftonicDownloader.E application D:\Documents and Settings\Izzy\Downloads\SoftonicDownloader_para_winrar.exe Win32/SoftonicDownloader application My antivirus software found the same infection running a deep scan but in the same file as the second line of ESET results. Thank you!! Izzy
  8. Hi, Here's what you requested. https://www.virustotal.com/file/98575cbd0664586e6211d02e71bdd52cbaa149a1658573550e29e74e5f7b1553/analysis/1360611702/ Thanks Izzy
  9. Hi! I have done the homework and there's the log attached. I ran a full scan and the PC is still infected and as I write this post I realise the tiping is too slow and it wasn't this morning or yesterday. I don't know if this may be caused by the infection. I have a question for you if you don't mind. This infection will afect the other partitions in my hard drive or only C: (The OS one) Thanks Izzy
  10. Hi, Bad news... at least you are helping me, thank you very much Izzy
  11. Hi Jeffce and thanks for helping!! I had problems running aswMBR. After 2 minutes of scanning it stops and a window appears saying "Avast! Rootkit stopped working". I attach the error info (w7error.txt), maybe it's useful for you. I changed the "QuickScan" option for "none" and then it worked well. I attach the aswMBR.txt saved. DDS had no problems. Thank you! Israel
  12. Hello, Can someone help me with my infected PC? Thanks in advance. Here are the log files requested. Izzy
  • Create New...