UDS:DangerousObject.Multi.Generic detected on my computer
Hello,
Suspecting my computer to be infected because my internet connection was very slow, and several programs would stop for no reason (Skype), I wanted to scan it with Malwarebytes Anti-Malware without success, as it kept freezing at around 14 minutes into the scan (no response).
So I did an online scan with Kaspersky which detected a malicious program:
Kaspersky recommends UDS:DangerousObject.Multi.Generic
ContactSetup.lng
C:\Program Files (x86)\Sony\Sony PC Companion\Languages\RUS
Antivir detected nothing
I would like to be able to reuse my Malwarebytes which is probably blocked by this malicious object.
I don’t know how to make my connection normal again and resolve this issue.
Can you help me, thank you in advance
Configuration: Windows 7 / Internet Explorer 9.0
Suspecting my computer to be infected because my internet connection was very slow, and several programs would stop for no reason (Skype), I wanted to scan it with Malwarebytes Anti-Malware without success, as it kept freezing at around 14 minutes into the scan (no response).
So I did an online scan with Kaspersky which detected a malicious program:
Kaspersky recommends UDS:DangerousObject.Multi.Generic
ContactSetup.lng
C:\Program Files (x86)\Sony\Sony PC Companion\Languages\RUS
Antivir detected nothing
I would like to be able to reuse my Malwarebytes which is probably blocked by this malicious object.
I don’t know how to make my connection normal again and resolve this issue.
Can you help me, thank you in advance
Configuration: Windows 7 / Internet Explorer 9.0
33 answers
-
Hello! Yes, I uninstalled and reinstalled it several times.
-
Security ContributorVery strange this problem. Even after reinstallation?
--
"Impossible is nothing" -
hello
for Pinnacle it doesn't work if I end the process and it also disables my Avira...
However, if I open Pinnacle, go to task managers and close within the application: pinnacle, at that moment I can reopen it without any problem.
If there are no other solutions, this method is still better than restarting the PC. -
Security ContributorOk.
For Pinnacle, try something.
(Don't forget to back up your projects on external drives (USB..HDD...).
Open the software.
Close it.
In the task manager, processes tab, end the AvidCloudManager.exe process.
Try to relaunch Pinnacle?
--
"Impossible is nothing" -
Yes, it’s really curious, especially since my sister had no connection issues with her laptop on WIFI but the main thing is that it works.
For MBAM, it got stuck again at 12mn24
C:\Users\Julien\AppData\Local\Temp\FXSAPIDebuglogFile.txt
Process 65 UC 0% Physical Memory 22%
It’s not always the same file, but always in AppData\Local\....
And I checked in Temp, and these 2 files are still there and impossible to delete even with SFT
ARCConvert (folder) keeps telling me too large to be moved
FXSAPUDebuglogFile.txt (text file) tells me it’s in use and I can’t find it anywhere
Regarding PINNACLE 16
I start it up, work on it, save my project, close it (everything is fine)
I want to reopen it a little later ... and then nothing happens as if I didn't have PINNACLE
I go to the task manager and there’s nothing in running applications but in processes I see it under the name AvidCloudManager.exe
To access my PINNACLE program, I have to restart my PC and then it works again. It’s very annoying because if it bugs somewhere I lose my whole project and have to start over. -
Security ContributorVery curious. First time I see this :-)
It's possible that restarting the box allowed for an increase in speed, that can happen.
For MBAM, run a scan and let us know where it gets stuck.
However, before running it, restart your PC and do not launch any other applications.
For Ccleaner, you can delete the registry errors. Remember to create a restore point beforehand.
For Pinnacle, what do you mean?
--
"Impossible is nothing" -
Hello Regis
The question you asked me about the connection made me think of something!
So I disconnected everything. Turned off my router, unplugged my ethernet cable, and then I saw that my cable was all twisted. I took another cable and reconnected everything. And there it is, MIRACLE! My connection seems normal again. I will do several tests, but I already opened Skype and it works. EUREKA
I really didn't think about that damn cable because MBAM was freezing (It still freezes in normal mode), I immediately thought it was a virus.
In any case, a thousand thank you for your time spent on me, and I'm really sorry for not checking that cable first.
But before marking this question as resolved, since I still have issues with MBAM and PINNACLE, I checked CCleaner for registry errors, and there are an impressive number of errors. I don't dare to touch it
How can I tell which ones can be deleted, and could that make MBAM work again? Or PINNACLE (which still bugs after opening and closing it)? -
Security ContributorNothing to worry about.
No particular sign...
Is your internet connection still slow? What makes you say that?
Which provider are you with?
--
"Impossible is nothing" -
Hello!
Below is the link for the ZHPDiag report.
https://www.cjoint.com/?3BviiUhuy8U
Just for your info, I had a lot of trouble downloading and running ZHPDiag because my PC said it was an unsigned program from an unknown publisher that could harm the computer. (the first link wouldn't open, I used the second one)
Is this a sign? -
hello Lili and Régis
Here is what I did.
1- I deleted the temp files in safe mode: the ARCConvert folder and the FXSAPIDebugLogFile text file, it says they no longer exist.
2- I used Lili's link to delete the temp files and I have the report.
3- I restarted the PC and used MBAM which this time got stuck at 7mn34 on:
Julien\AppDat\Local\Sony\MediaGo\Video playback...
4- By doing Ctrl Alt Del: MBAM is not responding Process 67 CPU 23 then 0
And still the same problems. -
Security ContributorHello roulio
We will use a tool that allows you to delete temporary files, similar to CCleaner.
Download this tool http://www.archive-host.com
Once you have downloaded it, move it to your desktop (a copy-paste will do the trick).
Run it as an admin if you are on Vista/Seven/8.
Then click on go.
Be patient, a report will appear.
That's it.
--
If there's a problem, there is always a solution.
Don't forget to mark your topic as resolved :) -
Security ContributorOk.
You can try to remove them in safe mode.
When it crashes, press CTRL + ALT + DELETE
How much is the CPU at the bottom?
--
"Impossible is nothing" -
Re-hello
I regularly use CCleaner.
But when I went to run %temp%, I saw that there were some files and folders. So I deleted them. But I can't seem to delete ARCCconvert (folder) and FXSAPIDebugLogFile (file).
Even after deleting the rest, the problem is still there. -
Security ContributorOk.
Do you know how to delete temporary files?
--
"Impossible is nothing" -
Re- Thank you Lili, I will look at the link
diagnosis
there is still a problem
MBAM freezes at 12 minutes on the file
C:\Users\Julien\AppData\Local\Temp\~DFE)FF632862372537.TMP
it's not always the same, but it's always in AppData
My Hotmail inbox always opens with a 2nd E (instead of one on top of the other) in the taskbar and is very slow to open. If I want to open a second tab, it doesn't open the first time and says IE cannot display this page
And my Pinnacle software opens the first time and to reopen it a second time, I have to restart my computer.
And since I uninstalled SKYPE, I can't check if it works. (that's how I discovered there was a problem.
Thank you for your patience -
Security ContributorHello roulio
Here is a little article to read :)
https://forum.malekal.com/viewtopic.php?t=6173&start=
Thanks again regis :)
Good luck to both of you
--
If there is a problem, there is always a solution
Don't forget to mark your topic as resolved :) -
Security ContributorOk cool.
Good thing.
Can you check if MBAM is still blocking?
And if your programs are crashing?
--
"Impossible is nothing" -
re-hello yes I will be careful I understood the lesson
there it is done
# AdwCleaner v2.112 - Report created on 19/02/2013 at 15:56:16
# Updated on 10/02/2013 by Xplode
# Operating system: Windows 7 Home Premium Service Pack 1 (64 bits)
# Username: Julien - JULIEN-PC
# Startup mode: Normal
# Run from: C:\Users\Julien\Desktop\AdwCleaner-2.112.exe
# Option [Removal]
***** [Services] *****
***** [Files / Folders] *****
Folder Deleted: C:\Program Files (x86)\Agence-Exclusive
Folder Deleted: C:\Program Files (x86)\Conduit
Folder Deleted: C:\Program Files (x86)\v-Grabber
Folder Deleted: C:\ProgramData\Ask
Folder Deleted: C:\ProgramData\Babylon
Folder Deleted: C:\ProgramData\InstallMate
Folder Deleted: C:\ProgramData\Premium
Folder Deleted: C:\Users\Julien\AppData\Local\Agence-Exclusive
Folder Deleted: C:\Users\Julien\AppData\Local\Conduit
Folder Deleted: C:\Users\Julien\AppData\Local\Google\Chrome\User Data\Default\Extensions\paoponfhfdfnjgddpnpjkambkcgdaaib
Folder Deleted: C:\Users\Julien\AppData\LocalLow\Conduit
Folder Deleted: C:\Users\Julien\AppData\LocalLow\PriceGong
Folder Deleted: C:\Users\Julien\AppData\Roaming\Agence-Exclusive
Folder Deleted: C:\Users\Julien\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\vGrabber
File Deleted: C:\user.js
***** [Registry] *****
Key Deleted: HKCU\Software\Agence-Exclusive
Key Deleted: HKCU\Software\AppDataLow\Software\Conduit
Key Deleted: HKCU\Software\AppDataLow\Software\ConduitSearchScopes
Key Deleted: HKCU\Software\AppDataLow\Software\Crossrider
Key Deleted: HKCU\Software\AppDataLow\Software\PriceGong
Key Deleted: HKCU\Software\AppDataLow\Software\SmartBar
Key Deleted: HKCU\Software\DataMngr
Key Deleted: HKCU\Software\Google\Chrome\Extensions\paoponfhfdfnjgddpnpjkambkcgdaaib
Key Deleted: HKCU\Software\ilivid
Key Deleted: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
Key Deleted: HKLM\Software\Agence-Exclusive
Key Deleted: HKLM\Software\Babylon
Key Deleted: HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}
Key Deleted: HKLM\SOFTWARE\Classes\AppID\{759F1421-4D31-4C1F-8C51-E4956A037676}
Key Deleted: HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}
Key Deleted: HKLM\SOFTWARE\Classes\AppID\escort.DLL
Key Deleted: HKLM\SOFTWARE\Classes\AppID\PCTutoBHO.DLL
Key Deleted: HKLM\SOFTWARE\Classes\Applications\ilividsetupv1.exe
Key Deleted: HKLM\SOFTWARE\Classes\Prod.cap
Key Deleted: HKLM\Software\Conduit
Key Deleted: HKLM\SOFTWARE\Microsoft\Tracing\iLivid_RASAPI32
Key Deleted: HKLM\SOFTWARE\Microsoft\Tracing\iLivid_RASMANCS
Key Deleted: HKLM\SOFTWARE\Microsoft\Tracing\iLividSetupV1_RASAPI32
Key Deleted: HKLM\SOFTWARE\Microsoft\Tracing\iLividSetupV1_RASMANCS
Key Deleted: HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASAPI32
Key Deleted: HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASMANCS
Key Deleted: HKLM\SOFTWARE\Microsoft\Tracing\SearchquMediaBar_RASAPI32
Key Deleted: HKLM\SOFTWARE\Microsoft\Tracing\SearchquMediaBar_RASMANCS
Key Deleted: HKLM\SOFTWARE\Microsoft\Tracing\SetupDataMngr_Searchqu_RASAPI32
Key Deleted: HKLM\SOFTWARE\Microsoft\Tracing\SetupDataMngr_Searchqu_RASMANCS
Key Deleted: HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Deleted: HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\paoponfhfdfnjgddpnpjkambkcgdaaib
Key Deleted: HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
Key Deleted: HKLM\SOFTWARE\DataMngr
Key Deleted: HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
Value Deleted: HKCU\Software\Microsoft\Internet Explorer\New Windows\Allow [*.crossrider.com]
Value Deleted: HKLM\SOFTWARE\Microsoft\Internet Explorer\New Windows\Allow [*.crossrider.com]
Value Deleted: HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [10]
Value Deleted: HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [10]
***** [Browsers] *****
-\\ Internet Explorer v9.0.8112.16464
[OK] The registry does not contain any illegitimate entries.
-\\ Google Chrome v [Unable to obtain version]
File: C:\Users\Julien\AppData\Local\Google\Chrome\User Data\Default\Preferences
[OK] The file does not contain any illegitimate entries.
*************************
AdwCleaner[R1].txt - [4738 bytes] - [19/02/2013 15:46:26]
AdwCleaner[R2].txt - [4798 bytes] - [19/02/2013 15:55:58]
AdwCleaner[S1].txt - [4639 bytes] - [19/02/2013 15:56:16]
########## EOF - C:\AdwCleaner[S1].txt - [4699 bytes] ########## -
Security ContributorRe,
Can you do the delete option and put the report?
However, be careful with what you download. When you install free software, watch out for the pre-checked boxes that install a lot of crap.
Apparently, you have been on streaming sites, and you must have clicked on iLivid...be careful, it's useless...and it clutters up your PC ;-)
Lili should find you a link to explain this and avoid this junk. Take 15 minutes to read to avoid this kind of stuff. A friend's advice ;-)
--
"Impossible is nothing" -
re-hello!
here is the report:
AdwCleaner v2.112 - Report created on 19/02/2013 at 15:46:26
# Updated on 10/02/2013 by Xplode
# Operating system: Windows 7 Home Premium Service Pack 1 (64 bits)
# Username: Julien - JULIEN-PC
# Boot mode: Normal
# Executed from: C:\Users\Julien\Desktop\AdwCleaner-2.112.exe
# Option [Search]
***** [Services] *****
***** [Files / Folders] *****
Folder Present: C:\Program Files (x86)\Agence-Exclusive
Folder Present: C:\Program Files (x86)\Conduit
Folder Present: C:\Program Files (x86)\v-Grabber
Folder Present: C:\ProgramData\Ask
Folder Present: C:\ProgramData\Babylon
Folder Present: C:\ProgramData\InstallMate
Folder Present: C:\ProgramData\Premium
Folder Present: C:\Users\Julien\AppData\Local\Agence-Exclusive
Folder Present: C:\Users\Julien\AppData\Local\Conduit
Folder Present: C:\Users\Julien\AppData\Local\Google\Chrome\User Data\Default\Extensions\paoponfhfdfnjgddpnpjkambkcgdaaib
Folder Present: C:\Users\Julien\AppData\LocalLow\Conduit
Folder Present: C:\Users\Julien\AppData\LocalLow\PriceGong
Folder Present: C:\Users\Julien\AppData\Roaming\Agence-Exclusive
Folder Present: C:\Users\Julien\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\vGrabber
File Present: C:\user.js
***** [Registry] *****
Key Present: HKCU\Software\Agence-Exclusive
Key Present: HKCU\Software\AppDataLow\Software\Conduit
Key Present: HKCU\Software\AppDataLow\Software\ConduitSearchScopes
Key Present: HKCU\Software\AppDataLow\Software\Crossrider
Key Present: HKCU\Software\AppDataLow\Software\PriceGong
Key Present: HKCU\Software\AppDataLow\Software\SmartBar
Key Present: HKCU\Software\DataMngr
Key Present: HKCU\Software\Google\Chrome\Extensions\paoponfhfdfnjgddpnpjkambkcgdaaib
Key Present: HKCU\Software\ilivid
Key Present: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
Key Present: HKLM\Software\Agence-Exclusive
Key Present: HKLM\Software\Babylon
Key Present: HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}
Key Present: HKLM\SOFTWARE\Classes\AppID\{759F1421-4D31-4C1F-8C51-E4956A037676}
Key Present: HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}
Key Present: HKLM\SOFTWARE\Classes\AppID\escort.DLL
Key Present: HKLM\SOFTWARE\Classes\AppID\PCTutoBHO.DLL
Key Present: HKLM\SOFTWARE\Classes\Applications\ilividsetupv1.exe
Key Present: HKLM\SOFTWARE\Classes\Prod.cap
Key Present: HKLM\Software\Conduit
Key Present: HKLM\SOFTWARE\Microsoft\Tracing\iLivid_RASAPI32
Key Present: HKLM\SOFTWARE\Microsoft\Tracing\iLivid_RASMANCS
Key Present: HKLM\SOFTWARE\Microsoft\Tracing\iLividSetupV1_RASAPI32
Key Present: HKLM\SOFTWARE\Microsoft\Tracing\iLividSetupV1_RASMANCS
Key Present: HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASAPI32
Key Present: HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASMANCS
Key Present: HKLM\SOFTWARE\Microsoft\Tracing\SearchquMediaBar_RASAPI32
Key Present: HKLM\SOFTWARE\Microsoft\Tracing\SearchquMediaBar_RASMANCS
Key Present: HKLM\SOFTWARE\Microsoft\Tracing\SetupDataMngr_Searchqu_RASAPI32
Key Present: HKLM\SOFTWARE\Microsoft\Tracing\SetupDataMngr_Searchqu_RASMANCS
Key Present: HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Present: HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\paoponfhfdfnjgddpnpjkambkcgdaaib
Key Present: HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
Key Present: HKLM\SOFTWARE\DataMngr
Key Present: HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
Key Present: HKU\S-1-5-21-709892753-828266104-2070350981-1000\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
Value Present: HKCU\Software\Microsoft\Internet Explorer\New Windows\Allow [*.crossrider.com]
Value Present: HKLM\SOFTWARE\Microsoft\Internet Explorer\New Windows\Allow [*.crossrider.com]
Value Present: HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [10]
Value Present: HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [10]
***** [Browsers] *****
-\\ Internet Explorer v9.0.8112.16464
[OK] The registry does not contain any illegitimate entries.
-\\ Google Chrome v [Unable to obtain version]
File: C:\Users\Julien\AppData\Local\Google\Chrome\User Data\Default\Preferences
[OK] The file does not contain any illegitimate entries.
*************************
AdwCleaner[R1].txt - [4617 bytes] - [19/02/2013 15:46:26]
########## EOF - C:\AdwCleaner[R1].txt - [4677 bytes] ##########
- 1
- 2
Next