Download issue Opera

Solved
lolomo1110 Posted messages 23 Status Member -  
 Anonymous user -
Hello

It has been over a month that I can no longer download files from any browser; for example with Opera the download starts and then, at the end, it shows the icon of my hard drive with the note: Virus scan failed

Thank you for your help

16 answers

  1. Anonymous user
     
    Re

    This is not finished!!!

    --
    --------Security Contributor---------
    We have all been beginners at something at some point.
    But knowledge is the reward of diligence.
    6
  2. lolomo1110 Posted messages 23 Status Member
     
    Good evening

    Even in safe mode with networking enabled it's the same problem, and even if I create another user it doesn't work
    1
  3. Anonymous user
     
    Re

    You follow up with Roguekiller and proceed to the deletion

    Then you post his report; thank you

    See you

    --
    --------Security Contributor---------
    We all were beginners at something one day.
    But knowledge is the reward of diligence.
    1
  4. Anonymous user
     
    Good evening

    How does the download go with another browser?

    See you later

    --

    --------Security Contributor---------
    We have all been beginners at something one day.
    But knowledge is the reward of diligence.
    0
  5. lolomo1110 Posted messages 23 Status Member
     
    Good evening

    It's exactly the same thing on Firefox Chrome and Safari
    0
  6. Anonymous user
     
    Good evening

    And in Safe Mode with network support?

    See you

    --
    --------Security Contributor---------
    We have all been beginners at something once.
    But knowledge is the reward of diligence.
    0
  7. Anonymous user
     
    Re

    But you still have access to Internet;only downloads are getting stuck?

    @+

    --
    --------Security Contributor---------
    We have all been beginners at some point.
    But knowledge is the reward of diligence.
    0
  8. lolomo1110 Posted messages 23 Status Member
     
    Yes, really everything works except the downloads
    0
  9. Anonymous user
     
    Good evening

    From another PC and with a USB drive do this:

    [*] Download on the desktop RogueKiller (by tigzy)

    put it on the PC with the issue and:

    [*] Quit all programs
    [*] Run RogueKiller.exe.
    [*] Wait for the Prescan to finish ...
    [*] Click Scan. Click Report and copy/paste the contents of the report using this same key

    See you later

    --
    --------Security Contributor---------
    We have all been beginners at something one day.
    But knowledge is the reward of diligence.
    0
  10. lolomo1110 Posted messages 23 Status Member
     
    RogueKiller V8.6.5 [Aug 5 2013] by Tigzy
    mail : tigzyRK<at>gmail<dot>com
    Remontees : http://www.adlice.com/forum/
    Site Web : https://www.luanagames.com/index.fr.html
    Blog : http://tigzyrk.blogspot.com/

    Systeme d'exploitation : Windows 7 (6.1.7600 ) 32 bits version
    Demarrage : Mode normal
    Utilisateur : admin [Droits d'admin]
    Mode : Recherche -- Date : 08/07/2013 17:20:02
    | ARK || FAK || MBR |

    ¤¤¤ Processus malicieux : 2 ¤¤¤
    [SUSP PATH] ContinueToSave.exe -- C:\ProgramData\Premium\ContinueToSave\ContinueToSave.exe [-] -> TUÉ [TermProc]
    [SUSP PATH] EasylifeGadget Updater.exe -- C:\ProgramData\BetterSoft\EasylifeGadget Updater\EasylifeGadget Updater.exe [-] -> TUÉ [TermProc]

    ¤¤¤ Entrees de registre : 16 ¤¤¤
    [RUN][HJNAME] HKCU\[...]\Run : 08f4dc96bbb7af09d1a37fe35c75a42f ("C:\Users\admin\AppData\Local\Temp\explorer.exe" .. [x][-]) -> TROUVÉ
    [RUN][SUSP PATH] HKCU\[...]\Run : Windows Live Messenger.exe (C:\Users\admin\AppData\Local\Temp\tmp5EA4.tmp.exe [-]) -> TROUVÉ
    [RUN][SUSP PATH] HKCU\[...]\Run : Xabjzrdlmfscdkwz.exe ("C:\Users\admin\AppData\Roaming\Xabjzrdlmfscdkwz.exe" [x]) -> TROUVÉ
    [RUN][SUSP PATH] HKCU\[...]\Run : Mhsmdxcnvzsnzrwq.exe ("C:\Users\admin\AppData\Roaming\Mhsmdxcnvzsnzrwq.exe" [x]) -> TROUVÉ
    [RUN][HJNAME] HKLM\[...]\Run : 08f4dc96bbb7af09d1a37fe35c75a42f ("C:\Users\admin\AppData\Local\Temp\explorer.exe" .. [x][-]) -> TROUVÉ
    [RUN][HJNAME] HKUS\S-1-5-21-3465505239-247864883-2392500668-1000\[...]\Run : 08f4dc96bbb7af09d1a37fe35c75a42f ("C:\Users\admin\AppData\Local\Temp\explorer.exe" .. [x][-]) -> TROUVÉ
    [RUN][SUSP PATH] HKUS\S-1-5-21-3465505239-247864883-2392500668-1000\[...]\Run : Windows Live Messenger.exe (C:\Users\admin\AppData\Local\Temp\tmp5EA4.tmp.exe [-]) -> TROUVÉ
    [RUN][SUSP PATH] HKUS\S-1-5-21-3465505239-247864883-2392500668-1000\[...]\Run : Xabjzrdlmfscdkwz.exe ("C:\Users\admin\AppData\Roaming\Xabjzrdlmfscdkwz.exe" [x]) -> TROUVÉ
    [RUN][SUSP PATH] HKUS\S-1-5-21-3465505239-247864883-2392500668-1000\[...]\Run : Mhsmdxcnvzsnzrwq.exe ("C:\Users\admin\AppData\Roaming\Mhsmdxcnvzsnzrwq.exe" [x]) -> TROUVÉ
    [PROXY IE] HKCU\[...]\Internet Settings : ProxyEnable (1) -> TROUVÉ
    [HJ POL] HKLM\[...]\System : ConsentPromptBehaviorAdmin (0) -> TROUVÉ
    [HJ POL] HKLM\[...]\System : EnableLUA (0) -> TROUVÉ
    [HJ DESK] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> TROUVÉ
    [HJ DESK] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> TROUVÉ
    [HJ INPROC][ZeroAccess] HKCR\[...]\InprocServer32 : (C:\$Recycle.Bin\S-1-5-18\$917d6a61a198bb81df06df30128c7fb4\n. [x]) -> TROUVÉ
    [HJ INPROC][ZeroAccess] HKLM\[...]\InprocServer32 : (C:\$Recycle.Bin\S-1-5-18\$917d6a61a198bb81df06df30128c7fb4\n. [x]) -> TROUVÉ

    ¤¤¤ Tâches planifiées : 3 ¤¤¤
    [V1][ROGUE ST] schedule!3425674635.job : C:\ProgramData\Premium\ContinueToSave\ContinueToSave.exe - /schedule /profile "c:\programdata\premium\continuetosave\3425674635.ini" [-][-] -> TROUVÉ
    [V1][ROGUE ST] schedule!2844174011.job : C:\ProgramData\BetterSoft\EasylifeGadget Updater\EasylifeGadget Updater.exe - /schedule /profile "c:\programdata\bettersoft\easylifegadget updater\2844174011.ini" [-][-] -> TROUVÉ
    [V2][SUSP PATH] Updater21810.exe : C:\Users\admin\AppData\Local\Updater21810\Updater21810.exe - /extensionid=21810 /extensionname="Giant Savings Extension" /chromeid=halffneccaebicfdfajnbfgpglahfgoe [-][x] -> TROUVÉ

    ¤¤¤ Entrées Startup : 0 ¤¤¤

    ¤¤¤ Navigateurs web : 1 ¤¤¤
    [FF][PROXY] 2nmp77d5.default : user_pref("network.proxy.type", 2); -> TROUVÉ

    ¤¤¤ Fichiers / Dossiers particuliers: ¤¤¤
    [ZeroAccess][Jonction] en-US : C:\Program Files\Windows Defender\en-US >> \systemroot\system32\config [-] --> TROUVÉ
    [ZeroAccess][Jonction] fr-FR : C:\Program Files\Windows Defender\fr-FR >> \systemroot\system32\config [-] --> TROUVÉ
    [ZeroAccess][Jonction] MpAsDesc.dll : C:\Program Files\Windows Defender\MpAsDesc.dll >> \systemroot\system32\config [-] --> TROUVÉ
    [ZeroAccess][Jonction] MpClient.dll : C:\Program Files\Windows Defender\MpClient.dll >> \systemroot\system32\config [-] --> TROUVÉ
    [ZeroAccess][Jonction] MpCmdRun.exe : C:\Program Files\Windows Defender\MpCmdRun.exe >> \systemroot\system32\config [-] --> TROUVÉ
    [ZeroAccess][Jonction] MpCommu.dll : C:\Program Files\Windows Defender\MpCommu.dll >> \systemroot\system32\config [-] --> TROUVÉ
    [ZeroAccess][Jonction] MpEvMsg.dll : C:\Program Files\Windows Defender\MpEvMsg.dll >> \systemroot\system32\config [-] --> TROUVÉ
    [ZeroAccess][Jonction] MpOAV.dll : C:\Program Files\Windows Defender\MpOAV.dll >> \systemroot\system32\config [-] --> TROUVÉ
    [ZeroAccess][Jonction] MpRTP.dll : C:\Program Files\Windows Defender\MpRTP.dll >> \systemroot\system32\config [-] --> TROUVÉ
    [ZeroAccess][Jonction] MpSvc.dll : C:\Program Files\Windows Defender\MpSvc.dll >> \systemroot\system32\config [-] --> TROUVÉ
    [ZeroAccess][Jonction] MSASCui.exe : C:\Program Files\Windows Defender\MSASCui.exe >> \systemroot\system32\config [-] --> TROUVÉ
    [ZeroAccess][Jonction] MsMpCom.dll : C:\Program Files\Windows Defender\MsMpCom.dll >> \systemroot\system32\config [-] --> TROUVÉ
    [ZeroAccess][Jonction] MsMpLics.dll : C:\Program Files\Windows Defender\MsMpLics.dll >> \systemroot\system32\config [-] --> TROUVÉ
    [ZeroAccess][Jonction] MsMpRes.dll : C:\Program Files\Windows Defender\MsMpRes.dll >> \systemroot\system32\config [-] --> TROUVÉ

    ¤¤¤ Driver : [CHARGE] ¤¤¤

    ¤¤¤ Ruches Externes: ¤¤¤

    ¤¤¤ Infection : ZeroAccess ¤¤¤

    ¤¤¤ Fichier HOSTS: ¤¤¤
    --> %SystemRoot%\System32\drivers\etc\hosts

    ¤¤¤ MBR Verif: ¤¤¤

    +++++ PhysicalDrive0: ST3160318AS +++++
    --- User ---
    [MBR] 9c230d5ff3c92bd4077babfd692941e3
    [BSP] b24a1f2095d0da4eb17141a3688a2513 : Windows 7/8 MBR Code
    Partition table:
    0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 100 Mo
    1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 206848 | Size: 76212 Mo
    2 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 156289024 | Size: 76313 Mo
    User = LL1 ... OK!
    User = LL2 ... OK!

    Termine : << RKreport[0]_S_08072013_172002.txt >>
    0
  11. lolomo1110 Posted messages 23 Status Member
     
    RogueKiller V8.6.5 [Aug 5 2013] by Tigzy
    mail : tigzyRK<at>gmail<dot>com
    Remontees : http://www.adlice.com/forum/
    Site Web : https://www.luanagames.com/index.fr.html
    Blog : http://tigzyrk.blogspot.com/

    Operating System : Windows 7 (6.1.7600) 32-bit version
    Startup : Normal mode
    User : admin [Admin rights]
    Mode : Deletion -- Date : 08/08/2013 00:50:34
    | ARK || FAK || MBR |

    ¤¤¤ Malicious processes : 2 ¤¤¤
    [SUSP PATH] ContinueToSave.exe -- C:\ProgramData\Premium\ContinueToSave\ContinueToSave.exe [-] -> KILLED [TermProc]
    [SUSP PATH] EasylifeGadget Updater.exe -- C:\ProgramData\BetterSoft\EasylifeGadget Updater\EasylifeGadget Updater.exe [-] -> KILLED [TermProc]

    ¤¤¤ Registry entries : 15 ¤¤¤
    [RUN][HJNAME] HKCU\[...]\Run : 08f4dc96bbb7af09d1a37fe35c75a42f ("C:\Users\admin\AppData\Local\Temp\explorer.exe" .. [x][-]) -> DELETED
    [RUN][SUSP PATH] HKCU\[...]\Run : Windows Live Messenger.exe (C:\Users\admin\AppData\Local\Temp\tmp5EA4.tmp.exe [-]) -> DELETED
    [RUN][SUSP PATH] HKCU\[...]\Run : Xabjzrdlmfscdkwz.exe ("C:\Users\admin\AppData\Roaming\Xabjzrdlmfscdkwz.exe" [x]) -> DELETED
    [RUN][SUSP PATH] HKCU\[...]\Run : Mhsmdxcnvzsnzrwq.exe ("C:\Users\admin\AppData\Roaming\Mhsmdxcnvzsnzrwq.exe" [x]) -> DELETED
    [RUN][HJNAME] HKLM\[...]\Run : 08f4dc96bbb7af09d1a37fe35c75a42f ("C:\Users\admin\AppData\Local\Temp\explorer.exe" .. [x][-]) -> DELETED
    [RUN][HJNAME] HKUS\S-1-5-21-3465505239-247864883-2392500668-1000\[...]\Run : 08f4dc96bbb7af09d1a37fe35c75a42f ("C:\Users\admin\AppData\Local\Temp\explorer.exe" .. [x][-]) -> [0x2] The specified file was not found.
    [RUN][SUSP PATH] HKUS\S-1-5-21-3465505239-247864883-2392500668-1000\[...]\Run : Windows Live Messenger.exe (C:\Users\admin\AppData\Local\Temp\tmp5EA4.tmp.exe [-]) -> [0x2] The specified file was not found.
    [RUN][SUSP PATH] HKUS\S-1-5-21-3465505239-247864883-2392500668-1000\[...]\Run : Xabjzrdlmfscdkwz.exe ("C:\Users\admin\AppData\Roaming\Xabjzrdlmfscdkwz.exe" [x]) -> [0x2] The specified file was not found.
    [RUN][SUSP PATH] HKUS\S-1-5-21-3465505239-247864883-2392500668-1000\[...]\Run : Mhsmdxcnvzsnzrwq.exe ("C:\Users\admin\AppData\Roaming\Mhsmdxcnvzsnzrwq.exe" [x]) -> [0x2] The specified file was not found.
    [HJ POL] HKLM\[...]\System : ConsentPromptBehaviorAdmin (0) -> REPLACED (2)
    [HJ POL] HKLM\[...]\System : EnableLUA (0) -> REPLACED (1)
    [HJ DESK] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> REPLACED (0)
    [HJ DESK] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0)
    [HJ INPROC][ZeroAccess] HKCR\[...]\InprocServer32 : (C:\$Recycle.Bin\S-1-5-18\$917d6a61a198bb81df06df30128c7fb4\n. [x]) -> REPLACED (C:\Windows\system32\wbem\fastprox.dll)
    [HJ INPROC][ZeroAccess] HKLM\[...]\InprocServer32 : (C:\$Recycle.Bin\S-1-5-18\$917d6a61a198bb81df06df30128c7fb4\n. [x]) -> REPLACED (C:\Windows\system32\wbem\fastprox.dll)

    ¤¤¤ Scheduled tasks : 3 ¤¤¤
    [V1][ROGUE ST] schedule!3425674635.job : C:\ProgramData\Premium\ContinueToSave\ContinueToSave.exe - /schedule /profile "c:\programdata\premium\continuetosave\3425674635.ini" [-][-] -> DELETED
    [V1][ROGUE ST] schedule!2844174011.job : C:\ProgramData\BetterSoft\EasylifeGadget Updater\EasylifeGadget Updater.exe - /schedule /profile "c:\programdata\bettersoft\easylifegadget updater\2844174011.ini" [-][-] -> DELETED
    [V2][SUSP PATH] Updater21810.exe : C:\Users\admin\AppData\Local\Updater21810\Updater21810.exe - /extensionid=21810 /extensionname="Giant Savings Extension" /chromeid=halffneccaebicfdfajnbfgpglahfgoe [-][x] -> DELETED

    ¤¤¤ Startup Entries : 0 ¤¤¤

    ¤¤¤ Web browsers : 1 ¤¤¤

    ¤¤¤ Folders / specific files: ¤¤¤
    [ZeroAccess][Jonction] en-US : C:\Program Files\Windows Defender\en-US >> \systemroot\system32\config [-] --> Junction DELETED
    [ZeroAccess][Jonction] fr-FR : C:\Program Files\Windows Defender\fr-FR >> \systemroot\system32\config [-] --> Junction DELETED
    [ZeroAccess][Jonction] MpAsDesc.dll : C:\Program Files\Windows Defender\MpAsDesc.dll >> \systemroot\system32\config [-] --> Junction DELETED
    [ZeroAccess][Jonction] MpClient.dll : C:\Program Files\Windows Defender\MpClient.dll >> \systemroot\system32\config [-] --> Junction DELETED
    [ZeroAccess][Jonction] MpCmdRun.exe : C:\Program Files\Windows Defender\MpCmdRun.exe >> \systemroot\system32\config [-] --> Junction DELETED
    [ZeroAccess][Jonction] MpCommu.dll : C:\Program Files\Windows Defender\MpCommu.dll >> \systemroot\system32\config [-] --> Junction DELETED
    [ZeroAccess][Jonction] MpEvMsg.dll : C:\Program Files\Windows Defender\MpEvMsg.dll >> \systemroot\system32\config [-] --> Junction DELETED
    [ZeroAccess][Jonction] MpOAV.dll : C:\Program Files\Windows Defender\MpOAV.dll >> \systemroot\system32\config [-] --> Junction DELETED
    [ZeroAccess][Jonction] MpRTP.dll : C:\Program Files\Windows Defender\MpRTP.dll >> \systemroot\system32\config [-] --> Junction DELETED
    [ZeroAccess][Jonction] MpSvc.dll : C:\Program Files\Windows Defender\MpSvc.dll >> \systemroot\system32\config [-] --> Junction DELETED
    [ZeroAccess][Jonction] MSASCui.exe : C:\Program Files\Windows Defender\MSASCui.exe >> \systemroot\system32\config [-] --> Junction DELETED
    [ZeroAccess][Jonction] MsMpCom.dll : C:\Program Files\Windows Defender\MsMpCom.dll >> \systemroot\system32\config [-] --> Junction DELETED
    [ZeroAccess][Jonction] MsMpLics.dll : C:\Program Files\Windows Defender\MsMpLics.dll >> \systemroot\system32\config [-] --> Junction DELETED
    [ZeroAccess][Jonction] MsMpRes.dll : C:\Program Files\Windows Defender\M sMpRes.dll >> \systemroot\system32\config [-] --> Junction DELETED

    ¤¤¤ Driver : [CHARGE] ¤¤¤

    ¤¤¤ External Drives: ¤¤¤

    ¤¤¤ Infection : ZeroAccess ¤¤¤

    ¤¤¤ Hosts file: ¤¤¤
    --> %SystemRoot%\System32\drivers\etc\hosts

    ¤¤¤ MBR Verif: ¤¤¤

    +++++ PhysicalDrive0: ST3160318AS +++++
    --- User ---
    [MBR] 9c230d5ff3c92bd4077babfd692941e3
    [BSP] b24a1f2095d0da4eb17141a3688a2513 : Windows 7/8 MBR Code
    Partition table:
    0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 100 MB
    1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 206848 | Size: 76212 MB
    2 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 156289024 | Size: 76313 MB
    User = LL1 ... OK!
    User = LL2 ... OK!

    End : << RKreport[0]_D_08082013_005034.txt >>
    RKreport[0]_S_08072013_172002.txt;RKreport[0]_S_08082013_004945.txt

    here is the report
    0
  12. Anonymous user
     
    Good evening

    Download Malwaresbytes Anti-Malware here
    https://www.malwarebytes.com/

    - Install it (choose "French" ; do not modify the installation settings) and update it.
    - Review the tutorial to familiarize yourself with the program:
    https://forum.pcastuces.com/sujet.asp?f=31&s=3

    (it is very simple to use).

    Relaunch Malwarebytes following these instructions precisely:

    - Disconnect yourself and close all running applications!
    - Run Malwarebytes. Under Vista, Seven or Windows 8 (right-click on the mouse "Run as administrator")
    - Perform an update
    - Do a so-called "Complete" scan
    - Let the program work and do nothing else with the PC during the scan.
    - At the end click on "Show results"
    - Verify that all infected objects are validated, then click on "Delete the selected"

    Note: if you need to restart your PC to finish the cleaning, do it!

    Post the saved report after deleting the infected objects (in the "Reports/Log" tab of Malwarebytes, the most recent one)

    @+

    -- Security Contributor
    We’ve all been beginners at some point.
    But knowledge is the reward of diligence.
    0
  13. lolomo1110 Posted messages 23 Status Member
     
    Since the deletion on Rogue Killer, downloads are working again thank you very much!!!!
    0
  14. lolomo1110 Posted messages 23 Status Member
     
    I prefer not to do anything since it works, but if it stops working I will do what you told me.
    0
  15. Anonymous user
     
    Hello

    I’m marking this topic as resolved

    @+

    --
    --------Security Contributor---------
    We’ve all been beginners at something at some point.
    But knowledge is the reward of diligence.
    0
  16. lolomo1110 Posted messages 23 Status Member
     
    Here is the report they gave me.
    -2