andrbea

CLOSED Pc infected with trk.cp20.com virus

Recommended Posts

anonymous said:

Hello andrbea, I'd love to help you rid yourself of this problem.

Since you're already on the emsisoft forums, I'm just going to guess that you already tried Emsisoft Emergency Kit?

Sometimes Hitmanpro's free trial does a good job of cleaning new malware, you can give it a shot by clicking

http://get.hitmanpro.com

Let me know if you have any luck with that.

 

hitman scan done, but no threats found

Seems that hitman doesn't know 

the trk.cp20.com virus

Share this post


Link to post
Share on other sites

Hello Andrbea,

Copy the below code to Notepad; Save As fixlist.txt to your Desktop.

HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
SearchScopes: HKLM-x32 -> DefaultScope {ielnksrch} URL =
SearchScopes: HKLM-x32 -> ielnksrch URL = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBPxn5dJ8gs0DGDT2ORdjS92mcaFxvbjXS4-o1TY1RDrGU-Hg3HEJmeEJfXjsjBtRgVDScsRFvYqy5KT5XIEdL9x-9YexEfTbNTawQ08DvTu_dmcaqtxo9219Z9VZgzYRDVKP7ExkP8bfq-CFCNuhR7nlxaNrinsEbOAolTYWF6ZXJFl9L__6K6SQ,,&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2948970751-1063722766-1516861716-1000 -> {ielnksrch} URL = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBPxn5dJ8gs0DGDT2ORdjS92mcaFxvbjXS4-o1TY1RDrGU-Hg3HEJmeEJfXjsjBtRgVDScsRFvYqy5KT5XIEdL9x-9YexEfTbNTawQ08DvTu_dmcaqtxo9219Z9VZgzYRDVKP7ExkP8bfq-CFCNuhR7nlxaNrinsEbOAolTYWF6ZXJFl9L__6K6SQ,,&q={searchTerms}
BHO-x32: Geen Naam -> {13D67BB7-DB5F-48AA-884D-7A5D94168509} -> Geen bestand
S2 Quotenamron; C:\ProgramData\\Quotenamron\\Quotenamron.exe shuz -f "C:\ProgramData\\Quotenamron\\Quotenamron.dat" -l -a
2017-11-09 15:02 - 2017-11-09 15:02 - 000049152 ____N () C:\Users\Beheerder\AppData\Local\Temp\nativelibrary3998897473555275030.dll
C:\ProgramData\Quotenamron\Quotenamron.exe
C:\ProgramData\Quotenamron\Quotenamron.dat
C:\ProgramData\Quotenamron
Task: {95A6D293-0734-4DB2-A24A-D2C02404B5F9} - \LaunchPreSignup -> Geen bestand <==== AANDACHT
Task: C:\Windows\Tasks\FreeFileViewerUpdateChecker.job => C:\Program Files (x86)\FreeFileViewer\FFVCheckForUpdates.exe <==== AANDACHT

Close Notepad.

NOTE: It's important that both files, FRST64 and fixlist.txt are in the same location or the fix will not work.

NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

Run FRST64 and press the Fix button just once and wait.

If the tool needed a restart please make sure you let the system restart normally and let the tool complete its run after restart.

The tool will make a log on the Desktop (Fixlog.txt). Attach it to your reply.

Note: If the tool warns you about an outdated version please download and run the updated version.

Share this post


Link to post
Share on other sites

Let's take a fresh look.

Run fresh scans with Emsisoft Emergency Kit (EEK) and FRST, attach the new EEK and FRST scans to your reply.

Be sure to let me know how things are running.

Share this post


Link to post
Share on other sites

here are the logs

system running normally

Rgds

a-w

 

In the meantime, I got another answer saying that the virus may not be a virus, after all?

 

Answer from another organization said:

 

According to the information on the Internet, this address belongs to a legitimate email service. If you have received an email with such link from a website you subscribed to, then it means that the website is using their services to send and track emails.

 

If you have any other questions or concerns, please don't hesitate to contact us.

 

All the best, and thanks again!

 

Kevin K.

Technical Support Department

 

Unremoved Parasite

I get an email from a domestic site which I used to trust. If I click on a browser link to a news story instead of going to their site I get an error message that trk.cp20.com can't be opened. This is not the normal site name (normal site name has to do with football). I think that a virus called trk.cp20.com virus is taking me to its parent site (or trying too). It has corrupted the call to a brower to visit an original site, always taking me to trk.cp20.com instead

FRST_15-11-2017 09.54.35.txt

logs.db3

Share this post


Link to post
Share on other sites

Unless you are having problems, it is time to do the final steps.

Now to remove most of the tools that we have used in fixing your machine:

Download Delfix from https://toolslib.net/downloads/viewdownload/2-delfix/
• Ensure "Remove disinfection tools" is checked.
• Also place a checkmark next to:
• Create registry backup
• Purge system restore
• Click the "Run" button.

When the tool is finished, a log will open in notepad. I do not need the log. You can close Notepad.

Empty the Recycle Bin

You can delete and uninstall any programs I had you download, that you do not wish to keep on the system.

Run Windows Update and update your Windows Operating System.

Articles to read:
How to Protect Your Computer From Malware http://www.malwareteks.com/Protect.php
How to keep you and your Windows PC happy http://www.malwareteks.com/HappyPC.php
Web, email, chat, password and kids safety http://www.malwareteks.com/WebSafety.php
10 Sources of Malware Infections https://zolltech.com/how-did-i-get-infected/

That should take care of everything.

Safe Surfing!

Share this post


Link to post
Share on other sites

Thread Closed

Reason: Resolved

The procedures contained in this thread are for this user and this user only. Attempting to use the instructions in this thread on your system could result in damaging the Operating System beyond repair. Do Not use any of the tools mentioned in this thread without the supervision of a Malware Removal Specialist.

All posters requesting Malware Removal assistance are required to follow all procedures in the thread titled START HERE if you don't we are just going to send you back to this thread.

Share this post


Link to post
Share on other sites
Guest
This topic is now closed to further replies.

  • Recently Browsing   0 members

    No registered users viewing this page.