Virus double accent circonflexe "^^"
Solved
luc92
Posted messages
23
Registration date
Status
Member
Last intervention
-
Thomas -
Thomas -
Hello,
I am new to this forum
For a few days now, I think I might be infected by a virus.
I get the direct display of 2 accents "^^" when I press the key "^" only once
(the key next to p). The same behavior occurs for the Umlaut: ¨¨
For example, if I try to type an (ê) with the two successive keys "^" + "e," I get "^^e" on the screen instead of the expected character "ê"
(Note: all the accented characters "ê," "û," etc., present in my message come from other documents because I can no longer generate them from my keyboard.
It's really very annoying not to be able to type these characters directly.
But more seriously, I am especially concerned that it might be spyware capable of duplicating all the characters typed on the keyboard to capture personal information during entry (password, bank codes entered during online purchases, etc.).
I took the initiative by downloading and running ZHPDiag with a ZHPDiag report v2013.docx saved in Word to keep the layout and the colored characters (there are red lines)
Thank you in advance for your help and for letting me know how to send you this report
My configuration is Windows XP Pro version 35.1 service pack 3, and my computer is a Dell D630.
I use Internet Explorer 8.0 and Mozilla Firefox
Configuration: Windows XP / Internet Explorer 8.0
I am new to this forum
For a few days now, I think I might be infected by a virus.
I get the direct display of 2 accents "^^" when I press the key "^" only once
(the key next to p). The same behavior occurs for the Umlaut: ¨¨
For example, if I try to type an (ê) with the two successive keys "^" + "e," I get "^^e" on the screen instead of the expected character "ê"
(Note: all the accented characters "ê," "û," etc., present in my message come from other documents because I can no longer generate them from my keyboard.
It's really very annoying not to be able to type these characters directly.
But more seriously, I am especially concerned that it might be spyware capable of duplicating all the characters typed on the keyboard to capture personal information during entry (password, bank codes entered during online purchases, etc.).
I took the initiative by downloading and running ZHPDiag with a ZHPDiag report v2013.docx saved in Word to keep the layout and the colored characters (there are red lines)
Thank you in advance for your help and for letting me know how to send you this report
My configuration is Windows XP Pro version 35.1 service pack 3, and my computer is a Dell D630.
I use Internet Explorer 8.0 and Mozilla Firefox
Configuration: Windows XP / Internet Explorer 8.0
17 answers
ok thx
Attention !!! : Only these links are official, do not download the tool from other links !!
Attention !!! : this tool may be falsely detected as a virus
Attention !!! : this tool is powerful, follow the instructions below closely
all "non-vital Windows processes" will be terminated, save your work. There will be a shutdown of the desktop during the scan --> don't panic.
Disable all your protections if possible, antivirus, sandbox, firewalls, etc....: https://forum.pcastuces.com/default.asp
download and save Pre_Scan on your desktop:
http://services.service-webmaster.fr/cpt-clics/clics-30453-6820.html (rename to winlogon)
or, if the link is not working:
http://www.archive-host.com (rename to winlogon)
http://www.security-helpzone.com/Tools/g3n/winlogon.exe (rename to winlogon)
if the tool is restarted several times, it will offer you a menu and since no option is required, launch the "Scan|Kill" option
if the tool is blocked by the infection, use this version with these other extensions:
http://www.security-helpzone.com/Tools/g3n/Pre_Scan.scr
http://www.security-helpzone.com/Tools/g3n/Pre_Scan.pif
http://www.security-helpzone.com/Tools/g3n/Pre_Scan.com
if the tool detects a proxy and you have not installed one, click on "remove proxy"
It may happen that black windows flicker, let it work.
the tool will send to a server the viruses it has quarantined so I can improve it and study these infections more deeply.
Let the tool restart your pc.
Post Pre_Scan_the_date_and_time.txt which will appear at the root of your system disk (usually C:\)
DO NOT POST IT ON THE FORUM !!! (it is too long)
Host the report on https://www.cjoint.com/ and then provide the obtained link in exchange on the forum where you are getting help
--
¤¤¤¤¤¤¤¤¤¤_Pre_Scan_Concept_¤¤¤¤¤¤¤¤¤¤
Attention !!! : Only these links are official, do not download the tool from other links !!
Attention !!! : this tool may be falsely detected as a virus
Attention !!! : this tool is powerful, follow the instructions below closely
all "non-vital Windows processes" will be terminated, save your work. There will be a shutdown of the desktop during the scan --> don't panic.
Disable all your protections if possible, antivirus, sandbox, firewalls, etc....: https://forum.pcastuces.com/default.asp
download and save Pre_Scan on your desktop:
http://services.service-webmaster.fr/cpt-clics/clics-30453-6820.html (rename to winlogon)
or, if the link is not working:
http://www.archive-host.com (rename to winlogon)
http://www.security-helpzone.com/Tools/g3n/winlogon.exe (rename to winlogon)
if the tool is restarted several times, it will offer you a menu and since no option is required, launch the "Scan|Kill" option
if the tool is blocked by the infection, use this version with these other extensions:
http://www.security-helpzone.com/Tools/g3n/Pre_Scan.scr
http://www.security-helpzone.com/Tools/g3n/Pre_Scan.pif
http://www.security-helpzone.com/Tools/g3n/Pre_Scan.com
if the tool detects a proxy and you have not installed one, click on "remove proxy"
It may happen that black windows flicker, let it work.
the tool will send to a server the viruses it has quarantined so I can improve it and study these infections more deeply.
Let the tool restart your pc.
Post Pre_Scan_the_date_and_time.txt which will appear at the root of your system disk (usually C:\)
DO NOT POST IT ON THE FORUM !!! (it is too long)
Host the report on https://www.cjoint.com/ and then provide the obtained link in exchange on the forum where you are getting help
--
¤¤¤¤¤¤¤¤¤¤_Pre_Scan_Concept_¤¤¤¤¤¤¤¤¤¤
Good evening
Download AdwCleaner (by Xplode) to your desktop.
Run it, click on [Removal] then wait for the scan to complete.
When the message indicating that AdwCleaner has detected a specific variant of adware appears, click on [OK]
- The computer will restart by itself. Restart it in normal mode.
- AdwCleaner will normally open, with the only possible choice being [Removal]
- Click on it, then wait during the removal process.
- Once the removal is completed, AdwCleaner will prompt you to restart the computer
- Upon restart, a report will open. Post it on the forum.
Note: The report is also saved under C:\AdwCleaner[S1].txt
To read:
Toolbars are not mandatory (by Malekal): https://forum.malekal.com/viewtopic.php?t=6173&start=
Potentially unwanted programs:
https://forum.malekal.com/viewtopic.php?t=33776&start=
@+
--
--------Security Contributor---------
We have all been beginners at something at one time.
But knowledge is the reward of diligence.
Download AdwCleaner (by Xplode) to your desktop.
Run it, click on [Removal] then wait for the scan to complete.
When the message indicating that AdwCleaner has detected a specific variant of adware appears, click on [OK]
- The computer will restart by itself. Restart it in normal mode.
- AdwCleaner will normally open, with the only possible choice being [Removal]
- Click on it, then wait during the removal process.
- Once the removal is completed, AdwCleaner will prompt you to restart the computer
- Upon restart, a report will open. Post it on the forum.
Note: The report is also saved under C:\AdwCleaner[S1].txt
To read:
Toolbars are not mandatory (by Malekal): https://forum.malekal.com/viewtopic.php?t=6173&start=
Potentially unwanted programs:
https://forum.malekal.com/viewtopic.php?t=33776&start=
@+
--
--------Security Contributor---------
We have all been beginners at something at one time.
But knowledge is the reward of diligence.
# AdwCleaner v2.200 - Report created on 10/04/2013 at 20:57:10
# Updated on 02/04/2013 by Xplode
# Operating System: Microsoft Windows XP Service Pack 3 (32-bit)
# Username: lvidal - L-FR-11170
# Boot Mode: Normal
# Executed from: D:\documents and settings\lvidal\Desktop\adwcleaner.exe
# Option [Removal]
***** [Services] *****
***** [Files / Folders] *****
Folder Deleted: C:\Program Files\ICQ6Toolbar
Folder Deleted: C:\Program Files\Protected Search
Folder Deleted: C:\Program Files\Red Sky
Folder Deleted: D:\Documents and Settings\All Users\Application Data\ICQ\ICQToolbar
Folder Deleted: D:\Documents and Settings\lvidal\Local Settings\Application Data\DownTango
Folder Deleted: D:\Documents and Settings\lvidal\Local Settings\Application Data\OpenCandy
Folder Deleted: D:\Documents and Settings\lvidal\Local Settings\Application Data\simplytech
File Deleted: C:\WINDOWS\Tasks\Protected Search.job
File Deleted: D:\END
***** [Registry] *****
Key Deleted: HKCU\Software\AppDataLow\Software\SmartBar
Key Deleted: HKCU\Software\Conduit
Key Deleted: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}
Key Deleted: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Key Deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{855F3B16-6D32-4FE6-8A56-BBB695989046}
Key Deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{855F3B16-6D32-4FE6-8A56-BBB695989046}
Key Deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted: HKCU\Software\ProtectedSearch
Key Deleted: HKLM\SOFTWARE\Classes\AppID\{3FC27B34-0C19-49DA-875E-1875DDD4A6B2}
Key Deleted: HKLM\SOFTWARE\Classes\CLSID\{A928E66C-F501-4E66-9953-855C712F93B2}
Key Deleted: HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Key Deleted: HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Deleted: HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
Key Deleted: HKLM\SOFTWARE\Classes\Interface\{8DA8B89E-0C65-403B-8231-AB22ECFA0687}
Key Deleted: HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Deleted: HKLM\SOFTWARE\Classes\Interface\{A928E66C-F501-4E66-9953-855C712F93B2}
Key Deleted: HKLM\SOFTWARE\Classes\Interface\{B0E28FA0-DF07-44B6-95CE-48BE26DB9266}
Key Deleted: HKLM\SOFTWARE\Classes\Interface\{E6B4EE8F-C38E-4994-BE28-229A3F92262C}
Key Deleted: HKLM\SOFTWARE\Classes\Interface\{FCA8936E-403A-4487-A966-70F80F1D5A6A}
Key Deleted: HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Key Deleted: HKLM\SOFTWARE\Classes\wtb.Band
Key Deleted: HKLM\SOFTWARE\Classes\wtb.Band.1
Key Deleted: HKLM\SOFTWARE\Classes\wtb.NotificationSource
Key Deleted: HKLM\SOFTWARE\Classes\wtb.NotificationSource.1
Key Deleted: HKLM\SOFTWARE\Classes\wtb.SourceSinkImpl
Key Deleted: HKLM\SOFTWARE\Classes\wtb.SourceSinkImpl.1
Key Deleted: HKLM\SOFTWARE\Classes\wtb.ToolbarInfo
Key Deleted: HKLM\SOFTWARE\Classes\wtb.ToolbarInfo.1
Key Deleted: HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Key Deleted: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Protected Search_is1
Key Deleted: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Key Deleted: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\063A857434EDED11A893800002C0A966
Key Deleted: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Protected Search_is1
Key Deleted: HKLM\Software\pdfforge.org
Key Deleted: HKLM\Software\TENCENT
Value Deleted: HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}]
***** [Browsers] *****
-\\ Internet Explorer v8.0.6001.18702
Replaced: [HKCU\Software\Microsoft\Internet Explorer\Main - ICQ Search] = hxxp://www.icq.com/search/results.php?q={searchTerms}&ch_id=osd --> hxxp://www.google.com
Replaced: [HKCU\Software\Microsoft\Internet Explorer\Main - Start Default_Page_URL] = hxxp://search.certified-toolbar.com?si=41460&home=true&tid=2938 --> hxxp://www.google.com
Replaced: [HKCU\Software\Microsoft\Internet Explorer\Search - Start Page] = hxxp://search.certified-toolbar.com?si=41460&home=true&tid=2938 --> hxxp://www.google.com
Replaced: [HKCU\Software\Microsoft\Internet Explorer\Search - Start Default_Page_URL] = hxxp://search.certified-toolbar.com?si=41460&home=true&tid=2938 --> hxxp://www.google.com
Replaced: [HKCU\Software\Microsoft\Internet Explorer\Search - Search Bar] = hxxp://search.certified-toolbar.com?si=41460&tid=2938&bs=true&q= --> hxxp://www.google.com
Replaced: [HKCU\Software\Microsoft\Internet Explorer\Search - Search Page] = hxxp://search.certified-toolbar.com?si=41460&tid=2938&bs=true&q= --> hxxp://www.google.com
Replaced: [HKLM\SOFTWARE\Microsoft\Internet Explorer\Search - Start Page] = hxxp://search.certified-toolbar.com?si=41460&home=true&tid=2938 --> hxxp://www.google.com
Replaced: [HKLM\SOFTWARE\Microsoft\Internet Explorer\Search - Start Default_Page_URL] = hxxp://search.certified-toolbar.com?si=41460&home=true&tid=2938 --> hxxp://www.google.com
Replaced: [HKLM\SOFTWARE\Microsoft\Internet Explorer\Search - Search Bar] = hxxp://search.certified-toolbar.com?si=41460&tid=2938&bs=true&q= --> hxxp://www.google.com
Replaced: [HKLM\SOFTWARE\Microsoft\Internet Explorer\Search - Search Page] = hxxp://search.certified-toolbar.com?si=41460&tid=2938&bs=true&q= --> hxxp://www.google.com
Replaced: [HKCU\Software\Microsoft\Internet Explorer\SearchUrl - (Default)] = hxxp://search.certified-toolbar.com?si=41460&bs=true&tid=2938&q=%s --> hxxp://www.google.com
Replaced: [HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchUrl - (Default)] = hxxp://search.certified-toolbar.com?si=41460&bs=true&tid=2938&q=%s --> hxxp://www.google.com
Replaced: [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main - Start Default_Page_URL] = hxxp://search.certified-toolbar.com?si=41460&home=true&tid=2938 --> hxxp://www.google.com
-\\ Mozilla Firefox v19.0.2 (fr)
File: D:\Documents and Settings\lvidal\Application Data\Mozilla\Firefox\Profiles\j0utydbv.default\prefs.js
D:\Documents and Settings\lvidal\Application Data\Mozilla\Firefox\Profiles\j0utydbv.default\user.js ... Deleted!
[OK] The file does not contain any illegitimate entries.
*************************
AdwCleaner[S1].txt - [7297 bytes] - [10/04/2013 20:57:10]
########## EOF - D:\AdwCleaner[S1].txt - [7357 bytes] ##########
# Updated on 02/04/2013 by Xplode
# Operating System: Microsoft Windows XP Service Pack 3 (32-bit)
# Username: lvidal - L-FR-11170
# Boot Mode: Normal
# Executed from: D:\documents and settings\lvidal\Desktop\adwcleaner.exe
# Option [Removal]
***** [Services] *****
***** [Files / Folders] *****
Folder Deleted: C:\Program Files\ICQ6Toolbar
Folder Deleted: C:\Program Files\Protected Search
Folder Deleted: C:\Program Files\Red Sky
Folder Deleted: D:\Documents and Settings\All Users\Application Data\ICQ\ICQToolbar
Folder Deleted: D:\Documents and Settings\lvidal\Local Settings\Application Data\DownTango
Folder Deleted: D:\Documents and Settings\lvidal\Local Settings\Application Data\OpenCandy
Folder Deleted: D:\Documents and Settings\lvidal\Local Settings\Application Data\simplytech
File Deleted: C:\WINDOWS\Tasks\Protected Search.job
File Deleted: D:\END
***** [Registry] *****
Key Deleted: HKCU\Software\AppDataLow\Software\SmartBar
Key Deleted: HKCU\Software\Conduit
Key Deleted: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}
Key Deleted: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Key Deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{855F3B16-6D32-4FE6-8A56-BBB695989046}
Key Deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{855F3B16-6D32-4FE6-8A56-BBB695989046}
Key Deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted: HKCU\Software\ProtectedSearch
Key Deleted: HKLM\SOFTWARE\Classes\AppID\{3FC27B34-0C19-49DA-875E-1875DDD4A6B2}
Key Deleted: HKLM\SOFTWARE\Classes\CLSID\{A928E66C-F501-4E66-9953-855C712F93B2}
Key Deleted: HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Key Deleted: HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Deleted: HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
Key Deleted: HKLM\SOFTWARE\Classes\Interface\{8DA8B89E-0C65-403B-8231-AB22ECFA0687}
Key Deleted: HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Deleted: HKLM\SOFTWARE\Classes\Interface\{A928E66C-F501-4E66-9953-855C712F93B2}
Key Deleted: HKLM\SOFTWARE\Classes\Interface\{B0E28FA0-DF07-44B6-95CE-48BE26DB9266}
Key Deleted: HKLM\SOFTWARE\Classes\Interface\{E6B4EE8F-C38E-4994-BE28-229A3F92262C}
Key Deleted: HKLM\SOFTWARE\Classes\Interface\{FCA8936E-403A-4487-A966-70F80F1D5A6A}
Key Deleted: HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Key Deleted: HKLM\SOFTWARE\Classes\wtb.Band
Key Deleted: HKLM\SOFTWARE\Classes\wtb.Band.1
Key Deleted: HKLM\SOFTWARE\Classes\wtb.NotificationSource
Key Deleted: HKLM\SOFTWARE\Classes\wtb.NotificationSource.1
Key Deleted: HKLM\SOFTWARE\Classes\wtb.SourceSinkImpl
Key Deleted: HKLM\SOFTWARE\Classes\wtb.SourceSinkImpl.1
Key Deleted: HKLM\SOFTWARE\Classes\wtb.ToolbarInfo
Key Deleted: HKLM\SOFTWARE\Classes\wtb.ToolbarInfo.1
Key Deleted: HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Key Deleted: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Protected Search_is1
Key Deleted: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Key Deleted: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\063A857434EDED11A893800002C0A966
Key Deleted: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Protected Search_is1
Key Deleted: HKLM\Software\pdfforge.org
Key Deleted: HKLM\Software\TENCENT
Value Deleted: HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}]
***** [Browsers] *****
-\\ Internet Explorer v8.0.6001.18702
Replaced: [HKCU\Software\Microsoft\Internet Explorer\Main - ICQ Search] = hxxp://www.icq.com/search/results.php?q={searchTerms}&ch_id=osd --> hxxp://www.google.com
Replaced: [HKCU\Software\Microsoft\Internet Explorer\Main - Start Default_Page_URL] = hxxp://search.certified-toolbar.com?si=41460&home=true&tid=2938 --> hxxp://www.google.com
Replaced: [HKCU\Software\Microsoft\Internet Explorer\Search - Start Page] = hxxp://search.certified-toolbar.com?si=41460&home=true&tid=2938 --> hxxp://www.google.com
Replaced: [HKCU\Software\Microsoft\Internet Explorer\Search - Start Default_Page_URL] = hxxp://search.certified-toolbar.com?si=41460&home=true&tid=2938 --> hxxp://www.google.com
Replaced: [HKCU\Software\Microsoft\Internet Explorer\Search - Search Bar] = hxxp://search.certified-toolbar.com?si=41460&tid=2938&bs=true&q= --> hxxp://www.google.com
Replaced: [HKCU\Software\Microsoft\Internet Explorer\Search - Search Page] = hxxp://search.certified-toolbar.com?si=41460&tid=2938&bs=true&q= --> hxxp://www.google.com
Replaced: [HKLM\SOFTWARE\Microsoft\Internet Explorer\Search - Start Page] = hxxp://search.certified-toolbar.com?si=41460&home=true&tid=2938 --> hxxp://www.google.com
Replaced: [HKLM\SOFTWARE\Microsoft\Internet Explorer\Search - Start Default_Page_URL] = hxxp://search.certified-toolbar.com?si=41460&home=true&tid=2938 --> hxxp://www.google.com
Replaced: [HKLM\SOFTWARE\Microsoft\Internet Explorer\Search - Search Bar] = hxxp://search.certified-toolbar.com?si=41460&tid=2938&bs=true&q= --> hxxp://www.google.com
Replaced: [HKLM\SOFTWARE\Microsoft\Internet Explorer\Search - Search Page] = hxxp://search.certified-toolbar.com?si=41460&tid=2938&bs=true&q= --> hxxp://www.google.com
Replaced: [HKCU\Software\Microsoft\Internet Explorer\SearchUrl - (Default)] = hxxp://search.certified-toolbar.com?si=41460&bs=true&tid=2938&q=%s --> hxxp://www.google.com
Replaced: [HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchUrl - (Default)] = hxxp://search.certified-toolbar.com?si=41460&bs=true&tid=2938&q=%s --> hxxp://www.google.com
Replaced: [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main - Start Default_Page_URL] = hxxp://search.certified-toolbar.com?si=41460&home=true&tid=2938 --> hxxp://www.google.com
-\\ Mozilla Firefox v19.0.2 (fr)
File: D:\Documents and Settings\lvidal\Application Data\Mozilla\Firefox\Profiles\j0utydbv.default\prefs.js
D:\Documents and Settings\lvidal\Application Data\Mozilla\Firefox\Profiles\j0utydbv.default\user.js ... Deleted!
[OK] The file does not contain any illegitimate entries.
*************************
AdwCleaner[S1].txt - [7297 bytes] - [10/04/2013 20:57:10]
########## EOF - D:\AdwCleaner[S1].txt - [7357 bytes] ##########
I rebooted and restarted ADW for the second time, and it removed something again.
Here's the second report
# AdwCleaner v2.200 - Report created on 04/10/2013 at 21:23:41
# Updated on 04/02/2013 by Xplode
# Operating system: Microsoft Windows XP Service Pack 3 (32 bits)
# Username: lvidal - L-FR-11170
# Boot mode: Normal
# Executed from: D:\documents and settings\lvidal\Desktop\adwcleaner.exe
# Option [Removal]
***** [Services] *****
***** [Files / Folders] *****
Folder Deleted: D:\Documents and Settings\lvidal\Local Settings\Application Data\simplytech
***** [Registry] *****
***** [Browsers] *****
-\\ Internet Explorer v8.0.6001.18702
[OK] The registry does not contain any illegitimate entries.
-\\ Mozilla Firefox v19.0.2 (fr)
File: D:\Documents and Settings\lvidal\Application Data\Mozilla\Firefox\Profiles\j0utydbv.default\prefs.js
[OK] The file does not contain any illegitimate entries.
*************************
AdwCleaner[S1].txt - [7426 bytes] - [04/10/2013 20:57:10]
AdwCleaner[S2].txt - [965 bytes] - [04/10/2013 21:23:41]
########## EOF - D:\AdwCleaner[S2].txt - [1024 bytes] ##########
Here's the second report
# AdwCleaner v2.200 - Report created on 04/10/2013 at 21:23:41
# Updated on 04/02/2013 by Xplode
# Operating system: Microsoft Windows XP Service Pack 3 (32 bits)
# Username: lvidal - L-FR-11170
# Boot mode: Normal
# Executed from: D:\documents and settings\lvidal\Desktop\adwcleaner.exe
# Option [Removal]
***** [Services] *****
***** [Files / Folders] *****
Folder Deleted: D:\Documents and Settings\lvidal\Local Settings\Application Data\simplytech
***** [Registry] *****
***** [Browsers] *****
-\\ Internet Explorer v8.0.6001.18702
[OK] The registry does not contain any illegitimate entries.
-\\ Mozilla Firefox v19.0.2 (fr)
File: D:\Documents and Settings\lvidal\Application Data\Mozilla\Firefox\Profiles\j0utydbv.default\prefs.js
[OK] The file does not contain any illegitimate entries.
*************************
AdwCleaner[S1].txt - [7426 bytes] - [04/10/2013 20:57:10]
AdwCleaner[S2].txt - [965 bytes] - [04/10/2013 21:23:41]
########## EOF - D:\AdwCleaner[S2].txt - [1024 bytes] ##########
Re
Download Malwarebytes Anti-Malware here
https://www.malwarebytes.com/
* Install it (make sure to select "French"; do not change the installation settings) and update it.
* Go through the tutorial to get familiar with the program:
https://forum.pcastuces.com/sujet.asp?f=31&s=3
(that said, it is very easy to use).
Restart Malwarebytes by strictly following these instructions:
! Disconnect and close all running applications!
* Launch Malwarebytes. Under Vista, Seven, or Windows 8 (right-click the mouse “run as administrator”)
* Proceed to an update
* Do a so-called "Full" scan
--> Let the program work (and do not do anything else with the PC during the scan).
--> At the end, click on "Show results" .
--> Check that all infected items are confirmed, then click on "remove selected" .
Note: if you need to restart your PC to complete the cleaning, do it!
Post the saved report after removing the infected items (in the "report/log" tab of Malwarebytes, the most recent one)
@+
--
--------Security Contributor---------
We have all been beginners at something at one point.
But knowledge is the reward for diligence.
Download Malwarebytes Anti-Malware here
https://www.malwarebytes.com/
* Install it (make sure to select "French"; do not change the installation settings) and update it.
* Go through the tutorial to get familiar with the program:
https://forum.pcastuces.com/sujet.asp?f=31&s=3
(that said, it is very easy to use).
Restart Malwarebytes by strictly following these instructions:
! Disconnect and close all running applications!
* Launch Malwarebytes. Under Vista, Seven, or Windows 8 (right-click the mouse “run as administrator”)
* Proceed to an update
* Do a so-called "Full" scan
--> Let the program work (and do not do anything else with the PC during the scan).
--> At the end, click on "Show results" .
--> Check that all infected items are confirmed, then click on "remove selected" .
Note: if you need to restart your PC to complete the cleaning, do it!
Post the saved report after removing the infected items (in the "report/log" tab of Malwarebytes, the most recent one)
@+
--
--------Security Contributor---------
We have all been beginners at something at one point.
But knowledge is the reward for diligence.
Hello Guillaume
I can't connect to the site https://www.malwarebytes.com/
( I am temporarily redirected to the link [http://failsafe.fp.yahoo.com/404.html
which after a few seconds redirects me to http://failsafe.fp.yahoo.com/. )
However, I found it on a link http://www.pcastuces.com/logitheque/telechargement.asp?num=1358 the version is from 04/10/2013. On this page you will find the description and several servers: Name of the downloaded software:
<underline>Malwarebytes' Anti-Malware 1.75.0.1300 9.80 MB</underline>
I will install it and run it following your instructions and then I'll post the result
thanks again
I can't connect to the site https://www.malwarebytes.com/
( I am temporarily redirected to the link [http://failsafe.fp.yahoo.com/404.html
which after a few seconds redirects me to http://failsafe.fp.yahoo.com/. )
However, I found it on a link http://www.pcastuces.com/logitheque/telechargement.asp?num=1358 the version is from 04/10/2013. On this page you will find the description and several servers: Name of the downloaded software:
<underline>Malwarebytes' Anti-Malware 1.75.0.1300 9.80 MB</underline>
I will install it and run it following your instructions and then I'll post the result
thanks again
Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org
Database version: v2013.04.04.07
Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
lvidal :: L-FR-11170 [administrator]
04/11/2013 18:29:33
mbam-log-2013-04-11 (18-29-33).txt
Scan type: Full scan (C:\|D:\|)
Scan options enabled: Memory | Startup | Registry | File system | Heuristic/Extra | Heuristic/Shuriken | PUP | PUM | P2P
Scan options disabled:
Item(s) scanned: 501580
Elapsed time: 1 hour(s), 20 minute(s), 28 second(s)
Detected memory processes: 0
(No harmful items detected)
Detected memory modules: 0
(No harmful items detected)
Detected Registry key(s): 0
(No harmful items detected)
Detected Registry value(s): 0
(No harmful items detected)
Detected Registry data item(s): 0
(No harmful items detected)
Detected folder(s): 0
(No harmful items detected)
Detected file(s): 1
D:\lvidal\Clé 32_ancienne\soft\ultraedit\17.00\UltraEdit v17.00.0.1035.rar (RiskWare.Tool.HCK) -> Successfully quarantined and deleted.
(end)
www.malwarebytes.org
Database version: v2013.04.04.07
Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
lvidal :: L-FR-11170 [administrator]
04/11/2013 18:29:33
mbam-log-2013-04-11 (18-29-33).txt
Scan type: Full scan (C:\|D:\|)
Scan options enabled: Memory | Startup | Registry | File system | Heuristic/Extra | Heuristic/Shuriken | PUP | PUM | P2P
Scan options disabled:
Item(s) scanned: 501580
Elapsed time: 1 hour(s), 20 minute(s), 28 second(s)
Detected memory processes: 0
(No harmful items detected)
Detected memory modules: 0
(No harmful items detected)
Detected Registry key(s): 0
(No harmful items detected)
Detected Registry value(s): 0
(No harmful items detected)
Detected Registry data item(s): 0
(No harmful items detected)
Detected folder(s): 0
(No harmful items detected)
Detected file(s): 1
D:\lvidal\Clé 32_ancienne\soft\ultraedit\17.00\UltraEdit v17.00.0.1035.rar (RiskWare.Tool.HCK) -> Successfully quarantined and deleted.
(end)
Good evening Guillaume
I’m adding to my post above which was approved a bit quickly (with just a copy/paste of the Malwarebytes report).
This report indicates a file containing a RiskWare.Tool.HCK that it quarantined and eliminated.
Despite this, the double accent problem persists even after rebooting the machine.
This file had been lying around on my PC for several months (coming from a USB stick), so I could have been infected while trying to use it.
However, the use of this file dates back several months while my double accent issue appeared a few days ago at the end of March, beginning of April (at least that’s when I noticed it).
This means that it roughly coincides with the date I installed Mozilla Firefox in mid-March 2013 and some add-ons that triggered an update of my Java version.....
I also suspect Adobe 9.54, of which a recent update (03/28/2013) is titled "Adobe Reader 9.5.4-CPSID_83708" ???
This update is in the list of the control panel (add/remove programs) with the status "installed" and a note "this update cannot be uninstalled" on the line just below the current version Adobe Reader 9.5.4 (which does have the modify or remove option)
Another suspect is Flash Player, for which I see 2 lines in the program list of the control panel:
- 1 line Adobe Flash Player 11 Active X
- and 1 line Adobe Flash Player 11 plug-in
While I cannot find any command in the start menu to launch Flash Player
Perhaps I need to uninstall Adobe and Flash Player?
Thank you for your help.
I’m adding to my post above which was approved a bit quickly (with just a copy/paste of the Malwarebytes report).
This report indicates a file containing a RiskWare.Tool.HCK that it quarantined and eliminated.
Despite this, the double accent problem persists even after rebooting the machine.
This file had been lying around on my PC for several months (coming from a USB stick), so I could have been infected while trying to use it.
However, the use of this file dates back several months while my double accent issue appeared a few days ago at the end of March, beginning of April (at least that’s when I noticed it).
This means that it roughly coincides with the date I installed Mozilla Firefox in mid-March 2013 and some add-ons that triggered an update of my Java version.....
I also suspect Adobe 9.54, of which a recent update (03/28/2013) is titled "Adobe Reader 9.5.4-CPSID_83708" ???
This update is in the list of the control panel (add/remove programs) with the status "installed" and a note "this update cannot be uninstalled" on the line just below the current version Adobe Reader 9.5.4 (which does have the modify or remove option)
Another suspect is Flash Player, for which I see 2 lines in the program list of the control panel:
- 1 line Adobe Flash Player 11 Active X
- and 1 line Adobe Flash Player 11 plug-in
While I cannot find any command in the start menu to launch Flash Player
Perhaps I need to uninstall Adobe and Flash Player?
Thank you for your help.
Hello Guillaume
I have finally resolved my issue
I was infected by Trojan.Zbot.FS.
As a result: I no longer have duplication of inert characters (like accents and umlauts), and I am no longer redirected to Yahoo when I connect to https://www.malwarebytes.com/ as was the case yesterday.
Forget my previous report filed yesterday as this one executed in normal mode did not reflect reality.
I refer you to my discussion with H@ckm@n below (April 12, 2013 at 6:33 PM) where I detailed the difficulties encountered and the method implemented based on the elements you provided me
I particularly mention the difficulty in downloading Malwarebytes (the virus redirecting all browser connection attempts to https://www.malwarebytes.com/ to a 404 message from the Yahoo engine) and the workaround used to find a valid and fairly recent version on your tutorial site.
I also had to circumvent the fact that the virus prevents any updates proposed by the software on startup (by preventing connection to the download site and returning a falsified message "you have the latest database")
In safe mode everything changes: the software updates successfully and the search launched immediately resulted in the following discovery:
Trojan.Zbot.FS,
Key HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|Raqybeevqo
file D:\documents and settings\......\Application Data\Iwyw\asyks.exe (Trojan.Zbot.FS)
-> Successfully quarantined and deleted Thank you for all the relevant elements 100% that you provided me which allowed me to get through this
Here is the complete Malwarebytes report version BDD v2013.04.12 executed in safe mode this afternoon on my PC
Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org
Database Version: v2013.04.12.04
Windows XP Service Pack 3 x86 NTFS (Safe Mode/Network)
Internet Explorer 8.0.6001.18702
lvidal :: L-FR-11170 [administrator]
12/04/2013 15:14:35
mbam-log-2013-04-12 (15-14-35).txt
Scan Type: Full Scan (C:\|D:\|)
Scan Options Enabled: Memory | Startup | Registry | File System | Heuristic/Extra | Heuristic/Shuriken | PUP | PUM | P2P
Scan Options Disabled:
Item(s) Scanned: 502511
Time Elapsed: 33 minute(s), 35 second(s)
Memory Processes Detected: 0
(No harmful items detected)
Memory Modules Detected: 0
(No harmful items detected)
Registry Keys Detected: 0
(No harmful items detected)
Registry Value(s) Detected: 1
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|Raqybeevqo (Trojan.Zbot.FS) -> Data: "D:\Documents and Settings\lvidal\Application Data\Iwyw\asyks.exe" -> Successfully quarantined and deleted.
Data Items Detected in Registry: 0
(No harmful items detected)
Folder(s) Detected: 0
(No harmful items detected)
File(s) Detected: 1
D:\documents and settings\lvidal\Application Data\Iwyw\asyks.exe (Trojan.Zbot.FS) -> Successfully quarantined and deleted.(end)
I have finally resolved my issue
I was infected by Trojan.Zbot.FS.
As a result: I no longer have duplication of inert characters (like accents and umlauts), and I am no longer redirected to Yahoo when I connect to https://www.malwarebytes.com/ as was the case yesterday.
Forget my previous report filed yesterday as this one executed in normal mode did not reflect reality.
I refer you to my discussion with H@ckm@n below (April 12, 2013 at 6:33 PM) where I detailed the difficulties encountered and the method implemented based on the elements you provided me
I particularly mention the difficulty in downloading Malwarebytes (the virus redirecting all browser connection attempts to https://www.malwarebytes.com/ to a 404 message from the Yahoo engine) and the workaround used to find a valid and fairly recent version on your tutorial site.
I also had to circumvent the fact that the virus prevents any updates proposed by the software on startup (by preventing connection to the download site and returning a falsified message "you have the latest database")
In safe mode everything changes: the software updates successfully and the search launched immediately resulted in the following discovery:
Trojan.Zbot.FS,
Key HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|Raqybeevqo
file D:\documents and settings\......\Application Data\Iwyw\asyks.exe (Trojan.Zbot.FS)
-> Successfully quarantined and deleted Thank you for all the relevant elements 100% that you provided me which allowed me to get through this
Here is the complete Malwarebytes report version BDD v2013.04.12 executed in safe mode this afternoon on my PC
Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org
Database Version: v2013.04.12.04
Windows XP Service Pack 3 x86 NTFS (Safe Mode/Network)
Internet Explorer 8.0.6001.18702
lvidal :: L-FR-11170 [administrator]
12/04/2013 15:14:35
mbam-log-2013-04-12 (15-14-35).txt
Scan Type: Full Scan (C:\|D:\|)
Scan Options Enabled: Memory | Startup | Registry | File System | Heuristic/Extra | Heuristic/Shuriken | PUP | PUM | P2P
Scan Options Disabled:
Item(s) Scanned: 502511
Time Elapsed: 33 minute(s), 35 second(s)
Memory Processes Detected: 0
(No harmful items detected)
Memory Modules Detected: 0
(No harmful items detected)
Registry Keys Detected: 0
(No harmful items detected)
Registry Value(s) Detected: 1
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|Raqybeevqo (Trojan.Zbot.FS) -> Data: "D:\Documents and Settings\lvidal\Application Data\Iwyw\asyks.exe" -> Successfully quarantined and deleted.
Data Items Detected in Registry: 0
(No harmful items detected)
Folder(s) Detected: 0
(No harmful items detected)
File(s) Detected: 1
D:\documents and settings\lvidal\Application Data\Iwyw\asyks.exe (Trojan.Zbot.FS) -> Successfully quarantined and deleted.(end)
the story of the virus I'm more than doubtful that it's that :)
little keyboard issue to configure I think^^^ oops one too many!
Nothing ventured, nothing gained
little keyboard issue to configure I think^^^ oops one too many!
Nothing ventured, nothing gained
this problem has been addressed in another forum but does not provide real solutions: http://forum.bepo.fr/viewtopic.php?id=159
but also take a look here: http://forum.bepo.fr/viewtopic.php?pid=6
there is a good chance that it is the software configuration
but also take a look here: http://forum.bepo.fr/viewtopic.php?pid=6
there is a good chance that it is the software configuration
@Luc92
wait for Guillaume's return and don’t listen to anyone else please
--
¤¤¤¤¤¤¤¤¤¤_Pre_Scan_Concept_¤¤¤¤¤¤¤¤¤¤
wait for Guillaume's return and don’t listen to anyone else please
--
¤¤¤¤¤¤¤¤¤¤_Pre_Scan_Concept_¤¤¤¤¤¤¤¤¤¤
Thank you H@ckm@n
Understood.
However, I am still interested to know if you have any idea about the nature of the threat.
Because I already made an online purchase at the beginning of April when the problem was already there.
So far, at the beginning of this week, no abnormal behavior of my credit card has been reported by my banker. But I remain worried.
Furthermore, I need to book a flight soon using my online payment methods on the secure portal of a travel agency.
I will not do it without having a solution.
Thank you
Talk to you later
Understood.
However, I am still interested to know if you have any idea about the nature of the threat.
Because I already made an online purchase at the beginning of April when the problem was already there.
So far, at the beginning of this week, no abnormal behavior of my credit card has been reported by my banker. But I remain worried.
Furthermore, I need to book a flight soon using my online payment methods on the secure portal of a travel agency.
I will not do it without having a solution.
Thank you
Talk to you later
still make a driver update for your keyboard, it doesn't hurt to try :)
for online purchases, if the connection is secure, you really don't have to worry. You're more likely to be defrauded at Carrefour.
it's not impossible that you were infected by a keylogger, normally your antivirus would have found it (unless you made an exception). In that case, the best thing to do is to do nothing on your PC and reformat everything. But honestly, I don't know of any undetectable keyloggers.
for online purchases, if the connection is secure, you really don't have to worry. You're more likely to be defrauded at Carrefour.
it's not impossible that you were infected by a keylogger, normally your antivirus would have found it (unless you made an exception). In that case, the best thing to do is to do nothing on your PC and reformat everything. But honestly, I don't know of any undetectable keyloggers.
refactor a zhpdiag for Guillaume but leave it in txt and host it on https://www.cjoint.com/ and give the link he will tell you what to do
I cannot interrupt not knowing exactly what he has in mind
--
¤¤¤¤¤¤¤¤¤¤_Pre_Scan_Concept_¤¤¤¤¤¤¤¤¤¤
I cannot interrupt not knowing exactly what he has in mind
--
¤¤¤¤¤¤¤¤¤¤_Pre_Scan_Concept_¤¤¤¤¤¤¤¤¤¤
thank you H@ckm@n
Actually, I just solved the problem.
I was infected by Trojan.Zbot.FS, which I was able to eliminate this afternoon.
Result: I no longer have duplication of dead characters (like accents and umlauts), and I am no longer redirected to Yahoo when I connect to https://www.malwarebytes.com/ as was the case yesterday (see explanation below)
I'll summarize the history of the different issues and the solution that got me out of trouble in case it could help others
1) Guillaume asked me:
to post him the Malwarebytes analysis by first downloading this software from a link he provided https://www.malwarebytes.com/
Then to run Malwarebytes, update it, start the search for infected items, display and destroy these quarantined items, and finally post him the report on the Forum
2) my first difficulty was initially downloading Malwarebytes from the provided link: https://www.malwarebytes.com/
This link was inaccessible to me as if it were expired, automatically redirecting me first to the link http://failsafe.fp.yahoo.com/404.html and then after a few seconds to http://failsafe.fp.yahoo.com/.
3) However, thanks to the link to the tutorial https://forum.pcastuces.com/sujet.asp?f=31&s=3 that Guillaume also provided, I was able to find a valid Malwarebytes download link: https://www.pcastuces.com/logitheque/telechargement.asp?num=1358
in a very recent version: Malwarebytes V1.75.0.1300 that I was able to download, install, and run.
4) Then a new problem occurred: the software notified me upon opening that my version was already 7 days old and offered to proceed with an update, which I accepted. Immediately, a message appeared "you have the latest updated version" and no update occurred.
(In fact, I discovered that this message was caused by the Trojan and that it was also him who was redirecting my browser to the Yahoo 404 each time I tried to connect to https://www.malwarebytes.com/
5) I settled for this version and conducted the search for infected items.
Malwarebytes revealed that I had a .rar file infected with RiskWare.Tool.HCK but nothing else, no registry key for any running infected items...... It quarantined it and I deleted it. I also posted the report to Guillaume
6) I got in touch with totodu.net who suspected my keyboard configuration.
That's when you intervened to advise me to wait for Guillaume's return.
7) Today, to stay active I restarted my computer in safe mode. I immediately noticed in this mode the disappearance of the double accentuation. This was a good sign.
I relaunched Malwarebytes V1.75.0.1300, which immediately updated on the same message (your database is 7 days old) and unlike what happened yesterday in NORMAL mode, successfully completed the downloads and the update.
The search resulted in the following discovery:
I am infected by Trojan.Zbot.FS,
Key HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|Raqybeevqo
file D:\documents and settings\......\Application Data\Iwyw\asyks.exe (Trojan.Zbot.FS)
-> Successfully quarantined and deleted
Thank you for your good advice and the collective responsiveness on this Forum
PS I am posting the Malwarebytes report carried out in safe mode to Guillaume and the explanations I just gave you
Luc
Actually, I just solved the problem.
I was infected by Trojan.Zbot.FS, which I was able to eliminate this afternoon.
Result: I no longer have duplication of dead characters (like accents and umlauts), and I am no longer redirected to Yahoo when I connect to https://www.malwarebytes.com/ as was the case yesterday (see explanation below)
I'll summarize the history of the different issues and the solution that got me out of trouble in case it could help others
1) Guillaume asked me:
to post him the Malwarebytes analysis by first downloading this software from a link he provided https://www.malwarebytes.com/
Then to run Malwarebytes, update it, start the search for infected items, display and destroy these quarantined items, and finally post him the report on the Forum
2) my first difficulty was initially downloading Malwarebytes from the provided link: https://www.malwarebytes.com/
This link was inaccessible to me as if it were expired, automatically redirecting me first to the link http://failsafe.fp.yahoo.com/404.html and then after a few seconds to http://failsafe.fp.yahoo.com/.
3) However, thanks to the link to the tutorial https://forum.pcastuces.com/sujet.asp?f=31&s=3 that Guillaume also provided, I was able to find a valid Malwarebytes download link: https://www.pcastuces.com/logitheque/telechargement.asp?num=1358
in a very recent version: Malwarebytes V1.75.0.1300 that I was able to download, install, and run.
4) Then a new problem occurred: the software notified me upon opening that my version was already 7 days old and offered to proceed with an update, which I accepted. Immediately, a message appeared "you have the latest updated version" and no update occurred.
(In fact, I discovered that this message was caused by the Trojan and that it was also him who was redirecting my browser to the Yahoo 404 each time I tried to connect to https://www.malwarebytes.com/
5) I settled for this version and conducted the search for infected items.
Malwarebytes revealed that I had a .rar file infected with RiskWare.Tool.HCK but nothing else, no registry key for any running infected items...... It quarantined it and I deleted it. I also posted the report to Guillaume
6) I got in touch with totodu.net who suspected my keyboard configuration.
That's when you intervened to advise me to wait for Guillaume's return.
7) Today, to stay active I restarted my computer in safe mode. I immediately noticed in this mode the disappearance of the double accentuation. This was a good sign.
I relaunched Malwarebytes V1.75.0.1300, which immediately updated on the same message (your database is 7 days old) and unlike what happened yesterday in NORMAL mode, successfully completed the downloads and the update.
The search resulted in the following discovery:
I am infected by Trojan.Zbot.FS,
Key HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|Raqybeevqo
file D:\documents and settings\......\Application Data\Iwyw\asyks.exe (Trojan.Zbot.FS)
-> Successfully quarantined and deleted
Thank you for your good advice and the collective responsiveness on this Forum
PS I am posting the Malwarebytes report carried out in safe mode to Guillaume and the explanations I just gave you
Luc
Good evening luc92
Testing in safe mode is a good idea ;-))
Post this Malwarebytes report and then send me a new ZHPDiag report; thank you
@+
--
--------Security Contributor---------
We've all been beginners at something at some point.
But knowledge is the reward for diligence.
Testing in safe mode is a good idea ;-))
Post this Malwarebytes report and then send me a new ZHPDiag report; thank you
@+
--
--------Security Contributor---------
We've all been beginners at something at some point.
But knowledge is the reward for diligence.
https://forums.commentcamarche.net/forum/affich-27564553-virus-double-accent-circonflexe#21
he he ^^ go ahead with your keyboard driver ^^
he he ^^ go ahead with your keyboard driver ^^
Good evening Guillaume
Do you have a reliable site to download ZHPDiag?
Because my version (which I deleted) had an abnormal icon out of 3 (the one for mbr) with just a blue Windows border square instead of the original icon
Here is the MALWAREBYTES report
M A L W A R E B Y T E S R E P O R T
Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org
Database version: v2013.04.12.04
Windows XP Service Pack 3 x86 NTFS (Safe Mode/Network)
Internet Explorer 8.0.6001.18702
lvidal :: L-FR-11170 [administrator]
04/12/2013 15:14:35
mbam-log-2013-04-12 (15-14-35).txt
Scan type: Complete scan (C:\|D:\|)
Scan options enabled: Memory | Startup | Registry | File System | Heuristic/Extra | Heuristic/Shuriken | PUP | PUM | P2P
Scan options disabled:
Item(s) scanned: 502511
Time elapsed: 33 minute(s), 35 second(s)
Memory processes detected: 0
(No harmful items detected)
Memory modules detected: 0
(No harmful items detected)
Registry key(s) detected: 0
(No harmful items detected)
Registry value(s) detected: 1
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|Raqybeevqo (Trojan.Zbot.FS) -> Data: "D:\Documents and Settings\lvidal\Application Data\Iwyw\asyks.exe" -> Successfully quarantined and deleted.
Data item(s) detected in the Registry: 0
(No harmful items detected)
Folder(s) detected: 0
(No harmful items detected)
File(s) detected: 1
D:\documents and settings\lvidal\Application Data\Iwyw\asyks.exe (Trojan.Zbot.FS) -> Successfully quarantined and deleted.
(end)
Do you have a reliable site to download ZHPDiag?
Because my version (which I deleted) had an abnormal icon out of 3 (the one for mbr) with just a blue Windows border square instead of the original icon
Here is the MALWAREBYTES report
M A L W A R E B Y T E S R E P O R T
Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org
Database version: v2013.04.12.04
Windows XP Service Pack 3 x86 NTFS (Safe Mode/Network)
Internet Explorer 8.0.6001.18702
lvidal :: L-FR-11170 [administrator]
04/12/2013 15:14:35
mbam-log-2013-04-12 (15-14-35).txt
Scan type: Complete scan (C:\|D:\|)
Scan options enabled: Memory | Startup | Registry | File System | Heuristic/Extra | Heuristic/Shuriken | PUP | PUM | P2P
Scan options disabled:
Item(s) scanned: 502511
Time elapsed: 33 minute(s), 35 second(s)
Memory processes detected: 0
(No harmful items detected)
Memory modules detected: 0
(No harmful items detected)
Registry key(s) detected: 0
(No harmful items detected)
Registry value(s) detected: 1
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|Raqybeevqo (Trojan.Zbot.FS) -> Data: "D:\Documents and Settings\lvidal\Application Data\Iwyw\asyks.exe" -> Successfully quarantined and deleted.
Data item(s) detected in the Registry: 0
(No harmful items detected)
Folder(s) detected: 0
(No harmful items detected)
File(s) detected: 1
D:\documents and settings\lvidal\Application Data\Iwyw\asyks.exe (Trojan.Zbot.FS) -> Successfully quarantined and deleted.
(end)
Re
One of these links:
https://www.zebulon.fr/telechargements/securite/systeme/zhpdiag.html
Or
https://www.commentcamarche.net/telecharger/utilitaires/24803-zhpdiag/
@+
--------Security Contributor---------
We have all been beginners at something at some point.
But knowledge is the reward of diligence.
One of these links:
https://www.zebulon.fr/telechargements/securite/systeme/zhpdiag.html
Or
https://www.commentcamarche.net/telecharger/utilitaires/24803-zhpdiag/
@+
--------Security Contributor---------
We have all been beginners at something at some point.
But knowledge is the reward of diligence.
Hello Guillaume
Here is the link to the ZHP Diag report .txt: https://www.cjoint.com/?3DnlfslRK08
For your information, here is another link: https://www.cjoint.com/?3DnlD1hT2MD
WORD version of the same ZHPDiag report (copied/pasted from the display of the report by ZHPDiag) while keeping the colors and layout of the ZHPDiag display:
For me, the Word version is easier to visually scrutinize, for example
example ADWARE opencandy in red
[HKLM\Software\Martin Prikryl\OpenCandy] =>Adware.OpenCandy
or the item "asyks.exe" in blue (which MalwareBytes did not completely eliminate)
<strong>line o53 - SMSR:HKLM\...\startupreg\Raqybeevqo [Key] . (...) -- D:\Documents and Settings\lvidal\Application Data\Iwyw\asyks.exe (.not file.)
P.S.: "asyks.exe" is also present at line o45 - LFCP:[MD5.E9304AB1FE4B086ADEA9D5E8D88488B8] - 12/04/2013 - 14:04:24 ---A- - C:\WINDOWS\Prefetch\ASYKS.EXE-39065795.pf
Thank you and see you later
Luc
Here is the link to the ZHP Diag report .txt: https://www.cjoint.com/?3DnlfslRK08
For your information, here is another link: https://www.cjoint.com/?3DnlD1hT2MD
WORD version of the same ZHPDiag report (copied/pasted from the display of the report by ZHPDiag) while keeping the colors and layout of the ZHPDiag display:
For me, the Word version is easier to visually scrutinize, for example
example ADWARE opencandy in red
[HKLM\Software\Martin Prikryl\OpenCandy] =>Adware.OpenCandy
or the item "asyks.exe" in blue (which MalwareBytes did not completely eliminate)
<strong>line o53 - SMSR:HKLM\...\startupreg\Raqybeevqo [Key] . (...) -- D:\Documents and Settings\lvidal\Application Data\Iwyw\asyks.exe (.not file.)
P.S.: "asyks.exe" is also present at line o45 - LFCP:[MD5.E9304AB1FE4B086ADEA9D5E8D88488B8] - 12/04/2013 - 14:04:24 ---A- - C:\WINDOWS\Prefetch\ASYKS.EXE-39065795.pf
Thank you and see you later
Luc
Hello
I'll let you handle it then!!!
See you later
--
--------Security Contributor---------
We've all been a beginner at something at some point.
But knowledge is the reward of diligence.
I'll let you handle it then!!!
See you later
--
--------Security Contributor---------
We've all been a beginner at something at some point.
But knowledge is the reward of diligence.
Guillaume
I definitely want to continue benefiting from your insights because
- I don't know the next steps regarding the ZHPDiag tools and
- I can't tell if my ZHPDiag report is sufficient since it's run in user mode (with administrator privileges) but not strictly in administrator mode.
- In any case, I can only interpret bits and pieces and have no idea about the downstream actions from the report (Script to run ZHPFix ....)
But trust me for the few intermediate actions concerning the evolution of the situation
<bold>
I definitely want to continue benefiting from your insights because
- I don't know the next steps regarding the ZHPDiag tools and
- I can't tell if my ZHPDiag report is sufficient since it's run in user mode (with administrator privileges) but not strictly in administrator mode.
- In any case, I can only interpret bits and pieces and have no idea about the downstream actions from the report (Script to run ZHPFix ....)
But trust me for the few intermediate actions concerning the evolution of the situation
<bold>
(Suite)
For example, since my ZHPDiag report post this morning, I have 2 important events to report to you.
1) Thanks to the (possibly temporary) eradication of Zbot.FS, my Microsoft Forefront Client Security antivirus updated this morning.
Explanation: For the past 2-3 weeks, Forefront had been stating that its virus definition database needed to be updated. When I tried to perform the operation, I immediately received a message saying "no updates available" (similar issue to what I encountered with MalwareBytes).
2) my now-updated antivirus detected 2 threats:
a) Forefront confirms (like ZHPDiag) the detection of the ADWARE opencandy that was quarantined and which it offers to remove.
Information from Forefront about this element on the Microsoft site: https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?name=Adware%3aWin32%2fOpenCandy&threatid=159633
b) Forefront has detected another Trojan (not seen I believe by ZHPDiag this morning): TrojanClicker:Win32/Yabector.gen!B which was quarantined and which it offers to remove.
Information from Forefront about this element on the Microsoft site: https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?name=TrojanClicker%3aWin32%2fYabector.gen
I asked Forefront to remove these 2 items.
If you agree, I will do a new ZHP diag and count on your help to analyze it under your control.
1) the traces of Zbot.FS mentioned in this morning's report will surely still be there
2) we will see if opencandy (Adware) and TrojanClicker:Win32/Yabector.gen have disappeared due to Forefront's action.
And then you can proceed with the next steps for the countermeasures.
Hoping that you agree with this approach.
Thank you for all the results already achieved.
Luc
For example, since my ZHPDiag report post this morning, I have 2 important events to report to you.
1) Thanks to the (possibly temporary) eradication of Zbot.FS, my Microsoft Forefront Client Security antivirus updated this morning.
Explanation: For the past 2-3 weeks, Forefront had been stating that its virus definition database needed to be updated. When I tried to perform the operation, I immediately received a message saying "no updates available" (similar issue to what I encountered with MalwareBytes).
2) my now-updated antivirus detected 2 threats:
a) Forefront confirms (like ZHPDiag) the detection of the ADWARE opencandy that was quarantined and which it offers to remove.
Information from Forefront about this element on the Microsoft site: https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?name=Adware%3aWin32%2fOpenCandy&threatid=159633
b) Forefront has detected another Trojan (not seen I believe by ZHPDiag this morning): TrojanClicker:Win32/Yabector.gen!B which was quarantined and which it offers to remove.
Information from Forefront about this element on the Microsoft site: https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?name=TrojanClicker%3aWin32%2fYabector.gen
I asked Forefront to remove these 2 items.
If you agree, I will do a new ZHP diag and count on your help to analyze it under your control.
1) the traces of Zbot.FS mentioned in this morning's report will surely still be there
2) we will see if opencandy (Adware) and TrojanClicker:Win32/Yabector.gen have disappeared due to Forefront's action.
And then you can proceed with the next steps for the countermeasures.
Hoping that you agree with this approach.
Thank you for all the results already achieved.
Luc
Re
I suggest you contact the administrator of this PC
See you
--
--------Security Contributor---------
We have all been beginners at something at some point.
But knowledge is the reward for diligence.
I suggest you contact the administrator of this PC
See you
--
--------Security Contributor---------
We have all been beginners at something at some point.
But knowledge is the reward for diligence.
Hi Gen
You're welcome ;-)
See you soon
--
--------Security Contributor---------
We've all been a beginner at something at some point.
But knowledge is the reward for diligence.
You're welcome ;-)
See you soon
--
--------Security Contributor---------
We've all been a beginner at something at some point.
But knowledge is the reward for diligence.
Hello Guillaume
I can't call on the administrator because he can only reset my workstation as stated in the explanation below (and in my opinion, given the progress made on the issue at hand, I believe there's something else to try before we get to that point).
Indeed, I already contacted the administrator in February, that is to say, 2 months before I had this issue with the
double accent (which dates back to early April and motivated my registration on this forum).
I informed him that I could no longer update the Forefront antivirus from the internet as I used to. He recommended that I use the Intranet (which, due to the lack of VPN configuration, forced me to travel). But it worked, and the incident was closed.
The administrator also took the opportunity to advise me to use MalwareBytes to resolve threats that Forefront might not have detected due to being outdated.
He also mentioned that in case of unresolved issues (stubborn viruses) by updated Forefront and MalwareBytes, he wouldn't be able to do better than reset my workstation due to a lack of time for in-depth investigations.
Luc
I can't call on the administrator because he can only reset my workstation as stated in the explanation below (and in my opinion, given the progress made on the issue at hand, I believe there's something else to try before we get to that point).
Indeed, I already contacted the administrator in February, that is to say, 2 months before I had this issue with the
double accent (which dates back to early April and motivated my registration on this forum).
I informed him that I could no longer update the Forefront antivirus from the internet as I used to. He recommended that I use the Intranet (which, due to the lack of VPN configuration, forced me to travel). But it worked, and the incident was closed.
The administrator also took the opportunity to advise me to use MalwareBytes to resolve threats that Forefront might not have detected due to being outdated.
He also mentioned that in case of unresolved issues (stubborn viruses) by updated Forefront and MalwareBytes, he wouldn't be able to do better than reset my workstation due to a lack of time for in-depth investigations.
Luc
Suite
Regarding the double accent problem, I believe we are quite close to a solution and that there is something else to try before I call the administrator to reformat the PC
I am optimistic because:
1) The double accent behavior has already been resolved at least temporarily by neutralizing the runtime process of Trojan.Zbot.FS
2) We need to maintain this success as much as possible by eliminating the residual traces that the ZHPdiag report still detects.
I think things are off to a good start because neutralizing Zbot.FS has also allowed for an online update of Forefront
Once updated, Forefront is equipped with all the necessary privileges and has thus been able to eliminate the other infection TrojanClicker:Win32/Yabector.gen!B
(which ZHPDiag run in user mode may not be able to see).
The two approaches, Forefront and ZHPDiag, therefore complement each other somewhat like (MalwareByte + ZHPDiag)
After the work done by Forefront this morning, I propose to send you, if you agree, the new ZHPDiag report launched after the eradication work by Forefront
You could guide me in eliminating the elements (registry keys or others) related to Zbot.FS (asyks.exe), opencandy or any others if you see them indicated by ZHPDiag
There are also a number of blue lines (or orphan keys, not.file, ...) that may signal a possible optimization of the registry
Thank you again for your advice
Luc
Regarding the double accent problem, I believe we are quite close to a solution and that there is something else to try before I call the administrator to reformat the PC
I am optimistic because:
1) The double accent behavior has already been resolved at least temporarily by neutralizing the runtime process of Trojan.Zbot.FS
2) We need to maintain this success as much as possible by eliminating the residual traces that the ZHPdiag report still detects.
I think things are off to a good start because neutralizing Zbot.FS has also allowed for an online update of Forefront
Once updated, Forefront is equipped with all the necessary privileges and has thus been able to eliminate the other infection TrojanClicker:Win32/Yabector.gen!B
(which ZHPDiag run in user mode may not be able to see).
The two approaches, Forefront and ZHPDiag, therefore complement each other somewhat like (MalwareByte + ZHPDiag)
After the work done by Forefront this morning, I propose to send you, if you agree, the new ZHPDiag report launched after the eradication work by Forefront
You could guide me in eliminating the elements (registry keys or others) related to Zbot.FS (asyks.exe), opencandy or any others if you see them indicated by ZHPDiag
There are also a number of blue lines (or orphan keys, not.file, ...) that may signal a possible optimization of the registry
Thank you again for your advice
Luc
Hello Homerlulu
I have no doubt about this point.
Especially since I have received particularly good advice from G3n and Guillaume.
I have more doubts about my ability to make the right decisions regarding the execution of ZHPDiag (or P-s which seems even more invasive) for certain deletions.
Furthermore, you should know that I have a Dell computer on which it could be irreversible to touch, for example, the MBR as the ZHPdiag suite might do, preventing any return to the factory configuration.
However, it is only on this factory configuration that the master reset DVD for my system can operate.
I have a simple way to eliminate all viruses or suspicion of viruses, which is to reconfigure the system with the DVD.
Thank you for your message
@+
Luc
I have no doubt about this point.
Especially since I have received particularly good advice from G3n and Guillaume.
I have more doubts about my ability to make the right decisions regarding the execution of ZHPDiag (or P-s which seems even more invasive) for certain deletions.
Furthermore, you should know that I have a Dell computer on which it could be irreversible to touch, for example, the MBR as the ZHPdiag suite might do, preventing any return to the factory configuration.
However, it is only on this factory configuration that the master reset DVD for my system can operate.
I have a simple way to eliminate all viruses or suspicion of viruses, which is to reconfigure the system with the DVD.
Thank you for your message
@+
Luc
Thank you, I had been looking for months to remove malware without success, and it's now done!
# AdwCleaner v3.012 - Report created on 11/15/2013 at 18:16:15
# Updated on 11/11/2013 by Xplode
# Operating System: Windows 7 Home Premium Service Pack 1 (64 bits)
# Username: Marin - MARIN-TOSH
# Executed from: C:\Users\Marin\Desktop\adwcleaner.exe
# Option: Clean
***** [ Services ] *****
***** [ Files / Folders ] *****
Folder Deleted: C:\Program Files (x86)\Pass-Widget
Folder Deleted: C:\Users\Marin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pcfopijhanoceijcfpaileppfklbeggk
File Deleted: C:\Program Files (x86)\Mozilla Firefox\browser\nsprotector.js
File Deleted: C:\Users\Marin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.delta-search.com_0.localstorage-journal
***** [ Shortcuts ] *****
***** [ Registry ] *****
***** [ Browsers ] *****
-\\ Internet Explorer v10.0.9200.16736
*************************
AdwCleaner[R0].txt - [10444 bytes] - [10/14/2013 17:13:09]
AdwCleaner[R1].txt - [1195 bytes] - [11/15/2013 18:09:46]
AdwCleaner[S0].txt - [9757 bytes] - [10/14/2013 17:14:25]
AdwCleaner[S1].txt - [1123 bytes] - [11/15/2013 18:16:15]
########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [1183 bytes] ##########
# AdwCleaner v3.012 - Report created on 11/15/2013 at 18:16:15
# Updated on 11/11/2013 by Xplode
# Operating System: Windows 7 Home Premium Service Pack 1 (64 bits)
# Username: Marin - MARIN-TOSH
# Executed from: C:\Users\Marin\Desktop\adwcleaner.exe
# Option: Clean
***** [ Services ] *****
***** [ Files / Folders ] *****
Folder Deleted: C:\Program Files (x86)\Pass-Widget
Folder Deleted: C:\Users\Marin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pcfopijhanoceijcfpaileppfklbeggk
File Deleted: C:\Program Files (x86)\Mozilla Firefox\browser\nsprotector.js
File Deleted: C:\Users\Marin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.delta-search.com_0.localstorage-journal
***** [ Shortcuts ] *****
***** [ Registry ] *****
***** [ Browsers ] *****
-\\ Internet Explorer v10.0.9200.16736
*************************
AdwCleaner[R0].txt - [10444 bytes] - [10/14/2013 17:13:09]
AdwCleaner[R1].txt - [1195 bytes] - [11/15/2013 18:09:46]
AdwCleaner[S0].txt - [9757 bytes] - [10/14/2013 17:14:25]
AdwCleaner[S1].txt - [1123 bytes] - [11/15/2013 18:16:15]
########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [1183 bytes] ##########
Hello,
I'm back to your forum because I indeed downloaded AdwCleaner, but contrary to what I read in the link you sent me, the software does not immediately prompt to “remove.” So, I did “scan” then “clean” and tried to post the results of this work on your forum. However, the double umlaut ^^ is still there (when I press the key once, I get 2, and furthermore, they appear before the letter)!
Thank you for your help.
I'm back to your forum because I indeed downloaded AdwCleaner, but contrary to what I read in the link you sent me, the software does not immediately prompt to “remove.” So, I did “scan” then “clean” and tried to post the results of this work on your forum. However, the double umlaut ^^ is still there (when I press the key once, I get 2, and furthermore, they appear before the letter)!
Thank you for your help.
I don't dare to launch such software that could alter a system configuration I don't master.
For example, if I find a proxy, I won't be able to choose knowingly whether to keep it or delete it, not being the person who installed it.
For the moment, I have only done diagnostic reports and corrections with no impact on the system using software like MalwareBytes or my antivirus Forefront once updated.
Therefore, I haven't undertaken anything risky, and the result is at least apparently excellent since I no longer have any symptoms that motivated these investigations.
The problem is resolved for me as best as possible, and I simply plan to reset my computer for 100% security.
This will also allow for an update of my software
Thanking you for your dedication as well as Guillaume's
@+
Luc
it's important to know that P_s is just as dangerous as ZHPDiag or Malwarebytes....
so, it's safe.
Especially since G3n is the designer...........