UDS:DangerousObject.Multi.Generic detected on my computer

Hello,

Suspecting my computer to be infected because my internet connection was very slow, and several programs would stop for no reason (Skype), I wanted to scan it with Malwarebytes Anti-Malware without success, as it kept freezing at around 14 minutes into the scan (no response).
So I did an online scan with Kaspersky which detected a malicious program:

Kaspersky recommends UDS:DangerousObject.Multi.Generic
ContactSetup.lng
C:\Program Files (x86)\Sony\Sony PC Companion\Languages\RUS

Antivir detected nothing

I would like to be able to reuse my Malwarebytes which is probably blocked by this malicious object.

I don’t know how to make my connection normal again and resolve this issue.

Can you help me, thank you in advance

Configuration: Windows 7 / Internet Explorer 9.0

33 answers

  1. Hello! Yes, I uninstalled and reinstalled it several times.
    0
    1. Security Contributor
      Very strange this problem. Even after reinstallation?

      --
      "Impossible is nothing"
      0
      1. hello
        for Pinnacle it doesn't work if I end the process and it also disables my Avira...
        However, if I open Pinnacle, go to task managers and close within the application: pinnacle, at that moment I can reopen it without any problem.

        If there are no other solutions, this method is still better than restarting the PC.
        0
        1. Security Contributor
          Ok.
          For Pinnacle, try something.
          (Don't forget to back up your projects on external drives (USB..HDD...).
          Open the software.
          Close it.
          In the task manager, processes tab, end the AvidCloudManager.exe process.
          Try to relaunch Pinnacle?

          --
          "Impossible is nothing"
          0
          1. Yes, it’s really curious, especially since my sister had no connection issues with her laptop on WIFI but the main thing is that it works.

            For MBAM, it got stuck again at 12mn24
            C:\Users\Julien\AppData\Local\Temp\FXSAPIDebuglogFile.txt
            Process 65 UC 0% Physical Memory 22%

            It’s not always the same file, but always in AppData\Local\....

            And I checked in Temp, and these 2 files are still there and impossible to delete even with SFT

            ARCConvert (folder) keeps telling me too large to be moved
            FXSAPUDebuglogFile.txt (text file) tells me it’s in use and I can’t find it anywhere

            Regarding PINNACLE 16
            I start it up, work on it, save my project, close it (everything is fine)
            I want to reopen it a little later ... and then nothing happens as if I didn't have PINNACLE

            I go to the task manager and there’s nothing in running applications but in processes I see it under the name AvidCloudManager.exe

            To access my PINNACLE program, I have to restart my PC and then it works again. It’s very annoying because if it bugs somewhere I lose my whole project and have to start over.
            0
            1. Security Contributor
              Very curious. First time I see this :-)
              It's possible that restarting the box allowed for an increase in speed, that can happen.

              For MBAM, run a scan and let us know where it gets stuck.
              However, before running it, restart your PC and do not launch any other applications.
              For Ccleaner, you can delete the registry errors. Remember to create a restore point beforehand.
              For Pinnacle, what do you mean?
              --
              "Impossible is nothing"
              0
              1. Hello Regis
                The question you asked me about the connection made me think of something!
                So I disconnected everything. Turned off my router, unplugged my ethernet cable, and then I saw that my cable was all twisted. I took another cable and reconnected everything. And there it is, MIRACLE! My connection seems normal again. I will do several tests, but I already opened Skype and it works. EUREKA
                I really didn't think about that damn cable because MBAM was freezing (It still freezes in normal mode), I immediately thought it was a virus.
                In any case, a thousand thank you for your time spent on me, and I'm really sorry for not checking that cable first.
                But before marking this question as resolved, since I still have issues with MBAM and PINNACLE, I checked CCleaner for registry errors, and there are an impressive number of errors. I don't dare to touch it
                How can I tell which ones can be deleted, and could that make MBAM work again? Or PINNACLE (which still bugs after opening and closing it)?
                0
                1. Security Contributor
                  Nothing to worry about.
                  No particular sign...

                  Is your internet connection still slow? What makes you say that?
                  Which provider are you with?

                  --
                  "Impossible is nothing"
                  0
                  1. Hello!
                    Below is the link for the ZHPDiag report.

                    https://www.cjoint.com/?3BviiUhuy8U

                    Just for your info, I had a lot of trouble downloading and running ZHPDiag because my PC said it was an unsigned program from an unknown publisher that could harm the computer. (the first link wouldn't open, I used the second one)

                    Is this a sign?
                    0
                    1. hello Lili and Régis

                      Here is what I did.

                      1- I deleted the temp files in safe mode: the ARCConvert folder and the FXSAPIDebugLogFile text file, it says they no longer exist.

                      2- I used Lili's link to delete the temp files and I have the report.

                      3- I restarted the PC and used MBAM which this time got stuck at 7mn34 on:
                      Julien\AppDat\Local\Sony\MediaGo\Video playback...
                      4- By doing Ctrl Alt Del: MBAM is not responding Process 67 CPU 23 then 0

                      And still the same problems.
                      0
                      1. To complete the information, in the meantime these 2 files are still there and I still cannot delete them in normal mode.
                        0
                      2. Security Contributor
                        Perfect this
                        What do you think of the software I proposed to you?
                        Waiting for Régis' feedback :)
                        0
                      3. It seems more effective for the temp files than CCleaner (which I may not have configured well)
                        thank you again
                        0
                      4. Security Contributor
                        No configuration needed :)
                        It's a complement you can use both, the advantage is that it doesn't delete your passwords.
                        0
                      5. Ok, I learned something else, but unfortunately it hasn't solved my problem. I'm trying to think about everything I've done, but I still don't see what could have put my PC in this state!
                        Could installing and uninstalling Skype and Pinnacle, which weren't working well, have damaged something?
                        0
                    2. Security Contributor
                      Hello roulio

                      We will use a tool that allows you to delete temporary files, similar to CCleaner.
                      Download this tool http://www.archive-host.com

                      Once you have downloaded it, move it to your desktop (a copy-paste will do the trick).
                      Run it as an admin if you are on Vista/Seven/8.
                      Then click on go.
                      Be patient, a report will appear.

                      That's it.

                      --
                      If there's a problem, there is always a solution.
                      Don't forget to mark your topic as resolved :)
                      0
                      1. Security Contributor
                        Ok.
                        You can try to remove them in safe mode.

                        When it crashes, press CTRL + ALT + DELETE
                        How much is the CPU at the bottom?

                        --
                        "Impossible is nothing"
                        0
                        1. Security Contributor
                          Regis, I have an idea but only you continue
                          I was thinking of a pretty cool utility (Pierre13's) to remove the tenses
                          What do you think?
                          0
                        2. Security Contributor
                          Yes, also.
                          Put it in the canned. ;-)
                          0
                        3. Security Contributor
                          Sure
                          However, the only issue is that it's SFT that is available
                          For the canned, I know how to do it!
                          After that, I'm afraid it might be considered as disinfection, I'm not too sure :(
                          At worst, I'll give it to you in private message :)
                          0
                        4. Security Contributor
                          <canned>Put the canned directly, it's like I was posting it myself.
                          But I don't have any canned stuff on hand, nor my passwords to go get them, so it would be helpful. Don't worry, I got you covered :-)</canned>
                          0
                        5. Security Contributor
                          Sure, thanks (anyway, deleting temporary files is within everyone's reach).
                          0
                      2. Re-hello

                        I regularly use CCleaner.

                        But when I went to run %temp%, I saw that there were some files and folders. So I deleted them. But I can't seem to delete ARCCconvert (folder) and FXSAPIDebugLogFile (file).

                        Even after deleting the rest, the problem is still there.
                        0
                        1. Security Contributor
                          Ok.
                          Do you know how to delete temporary files?

                          --
                          "Impossible is nothing"
                          0
                          1. Re- Thank you Lili, I will look at the link

                            diagnosis
                            there is still a problem

                            MBAM freezes at 12 minutes on the file
                            C:\Users\Julien\AppData\Local\Temp\~DFE)FF632862372537.TMP
                            it's not always the same, but it's always in AppData

                            My Hotmail inbox always opens with a 2nd E (instead of one on top of the other) in the taskbar and is very slow to open. If I want to open a second tab, it doesn't open the first time and says IE cannot display this page

                            And my Pinnacle software opens the first time and to reopen it a second time, I have to restart my computer.

                            And since I uninstalled SKYPE, I can't check if it works. (that's how I discovered there was a problem.

                            Thank you for your patience
                            0
                            1. Security Contributor
                              Ok cool.
                              Good thing.

                              Can you check if MBAM is still blocking?
                              And if your programs are crashing?
                              --
                              "Impossible is nothing"
                              0
                              1. re-hello yes I will be careful I understood the lesson
                                there it is done

                                # AdwCleaner v2.112 - Report created on 19/02/2013 at 15:56:16
                                # Updated on 10/02/2013 by Xplode
                                # Operating system: Windows 7 Home Premium Service Pack 1 (64 bits)
                                # Username: Julien - JULIEN-PC
                                # Startup mode: Normal
                                # Run from: C:\Users\Julien\Desktop\AdwCleaner-2.112.exe
                                # Option [Removal]

                                ***** [Services] *****

                                ***** [Files / Folders] *****

                                Folder Deleted: C:\Program Files (x86)\Agence-Exclusive
                                Folder Deleted: C:\Program Files (x86)\Conduit
                                Folder Deleted: C:\Program Files (x86)\v-Grabber
                                Folder Deleted: C:\ProgramData\Ask
                                Folder Deleted: C:\ProgramData\Babylon
                                Folder Deleted: C:\ProgramData\InstallMate
                                Folder Deleted: C:\ProgramData\Premium
                                Folder Deleted: C:\Users\Julien\AppData\Local\Agence-Exclusive
                                Folder Deleted: C:\Users\Julien\AppData\Local\Conduit
                                Folder Deleted: C:\Users\Julien\AppData\Local\Google\Chrome\User Data\Default\Extensions\paoponfhfdfnjgddpnpjkambkcgdaaib
                                Folder Deleted: C:\Users\Julien\AppData\LocalLow\Conduit
                                Folder Deleted: C:\Users\Julien\AppData\LocalLow\PriceGong
                                Folder Deleted: C:\Users\Julien\AppData\Roaming\Agence-Exclusive
                                Folder Deleted: C:\Users\Julien\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\vGrabber
                                File Deleted: C:\user.js

                                ***** [Registry] *****

                                Key Deleted: HKCU\Software\Agence-Exclusive
                                Key Deleted: HKCU\Software\AppDataLow\Software\Conduit
                                Key Deleted: HKCU\Software\AppDataLow\Software\ConduitSearchScopes
                                Key Deleted: HKCU\Software\AppDataLow\Software\Crossrider
                                Key Deleted: HKCU\Software\AppDataLow\Software\PriceGong
                                Key Deleted: HKCU\Software\AppDataLow\Software\SmartBar
                                Key Deleted: HKCU\Software\DataMngr
                                Key Deleted: HKCU\Software\Google\Chrome\Extensions\paoponfhfdfnjgddpnpjkambkcgdaaib
                                Key Deleted: HKCU\Software\ilivid
                                Key Deleted: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
                                Key Deleted: HKLM\Software\Agence-Exclusive
                                Key Deleted: HKLM\Software\Babylon
                                Key Deleted: HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}
                                Key Deleted: HKLM\SOFTWARE\Classes\AppID\{759F1421-4D31-4C1F-8C51-E4956A037676}
                                Key Deleted: HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}
                                Key Deleted: HKLM\SOFTWARE\Classes\AppID\escort.DLL
                                Key Deleted: HKLM\SOFTWARE\Classes\AppID\PCTutoBHO.DLL
                                Key Deleted: HKLM\SOFTWARE\Classes\Applications\ilividsetupv1.exe
                                Key Deleted: HKLM\SOFTWARE\Classes\Prod.cap
                                Key Deleted: HKLM\Software\Conduit
                                Key Deleted: HKLM\SOFTWARE\Microsoft\Tracing\iLivid_RASAPI32
                                Key Deleted: HKLM\SOFTWARE\Microsoft\Tracing\iLivid_RASMANCS
                                Key Deleted: HKLM\SOFTWARE\Microsoft\Tracing\iLividSetupV1_RASAPI32
                                Key Deleted: HKLM\SOFTWARE\Microsoft\Tracing\iLividSetupV1_RASMANCS
                                Key Deleted: HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASAPI32
                                Key Deleted: HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASMANCS
                                Key Deleted: HKLM\SOFTWARE\Microsoft\Tracing\SearchquMediaBar_RASAPI32
                                Key Deleted: HKLM\SOFTWARE\Microsoft\Tracing\SearchquMediaBar_RASMANCS
                                Key Deleted: HKLM\SOFTWARE\Microsoft\Tracing\SetupDataMngr_Searchqu_RASAPI32
                                Key Deleted: HKLM\SOFTWARE\Microsoft\Tracing\SetupDataMngr_Searchqu_RASMANCS
                                Key Deleted: HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
                                Key Deleted: HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\paoponfhfdfnjgddpnpjkambkcgdaaib
                                Key Deleted: HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
                                Key Deleted: HKLM\SOFTWARE\DataMngr
                                Key Deleted: HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
                                Value Deleted: HKCU\Software\Microsoft\Internet Explorer\New Windows\Allow [*.crossrider.com]
                                Value Deleted: HKLM\SOFTWARE\Microsoft\Internet Explorer\New Windows\Allow [*.crossrider.com]
                                Value Deleted: HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [10]
                                Value Deleted: HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [10]

                                ***** [Browsers] *****

                                -\\ Internet Explorer v9.0.8112.16464

                                [OK] The registry does not contain any illegitimate entries.

                                -\\ Google Chrome v [Unable to obtain version]

                                File: C:\Users\Julien\AppData\Local\Google\Chrome\User Data\Default\Preferences

                                [OK] The file does not contain any illegitimate entries.

                                *************************

                                AdwCleaner[R1].txt - [4738 bytes] - [19/02/2013 15:46:26]
                                AdwCleaner[R2].txt - [4798 bytes] - [19/02/2013 15:55:58]
                                AdwCleaner[S1].txt - [4639 bytes] - [19/02/2013 15:56:16]

                                ########## EOF - C:\AdwCleaner[S1].txt - [4699 bytes] ##########
                                0
                                1. Security Contributor
                                  Re,

                                  Can you do the delete option and put the report?

                                  However, be careful with what you download. When you install free software, watch out for the pre-checked boxes that install a lot of crap.
                                  Apparently, you have been on streaming sites, and you must have clicked on iLivid...be careful, it's useless...and it clutters up your PC ;-)

                                  Lili should find you a link to explain this and avoid this junk. Take 15 minutes to read to avoid this kind of stuff. A friend's advice ;-)

                                  --
                                  "Impossible is nothing"
                                  0
                                  1. re-hello!

                                    here is the report:

                                    AdwCleaner v2.112 - Report created on 19/02/2013 at 15:46:26
                                    # Updated on 10/02/2013 by Xplode
                                    # Operating system: Windows 7 Home Premium Service Pack 1 (64 bits)
                                    # Username: Julien - JULIEN-PC
                                    # Boot mode: Normal
                                    # Executed from: C:\Users\Julien\Desktop\AdwCleaner-2.112.exe
                                    # Option [Search]

                                    ***** [Services] *****

                                    ***** [Files / Folders] *****

                                    Folder Present: C:\Program Files (x86)\Agence-Exclusive
                                    Folder Present: C:\Program Files (x86)\Conduit
                                    Folder Present: C:\Program Files (x86)\v-Grabber
                                    Folder Present: C:\ProgramData\Ask
                                    Folder Present: C:\ProgramData\Babylon
                                    Folder Present: C:\ProgramData\InstallMate
                                    Folder Present: C:\ProgramData\Premium
                                    Folder Present: C:\Users\Julien\AppData\Local\Agence-Exclusive
                                    Folder Present: C:\Users\Julien\AppData\Local\Conduit
                                    Folder Present: C:\Users\Julien\AppData\Local\Google\Chrome\User Data\Default\Extensions\paoponfhfdfnjgddpnpjkambkcgdaaib
                                    Folder Present: C:\Users\Julien\AppData\LocalLow\Conduit
                                    Folder Present: C:\Users\Julien\AppData\LocalLow\PriceGong
                                    Folder Present: C:\Users\Julien\AppData\Roaming\Agence-Exclusive
                                    Folder Present: C:\Users\Julien\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\vGrabber
                                    File Present: C:\user.js

                                    ***** [Registry] *****

                                    Key Present: HKCU\Software\Agence-Exclusive
                                    Key Present: HKCU\Software\AppDataLow\Software\Conduit
                                    Key Present: HKCU\Software\AppDataLow\Software\ConduitSearchScopes
                                    Key Present: HKCU\Software\AppDataLow\Software\Crossrider
                                    Key Present: HKCU\Software\AppDataLow\Software\PriceGong
                                    Key Present: HKCU\Software\AppDataLow\Software\SmartBar
                                    Key Present: HKCU\Software\DataMngr
                                    Key Present: HKCU\Software\Google\Chrome\Extensions\paoponfhfdfnjgddpnpjkambkcgdaaib
                                    Key Present: HKCU\Software\ilivid
                                    Key Present: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
                                    Key Present: HKLM\Software\Agence-Exclusive
                                    Key Present: HKLM\Software\Babylon
                                    Key Present: HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}
                                    Key Present: HKLM\SOFTWARE\Classes\AppID\{759F1421-4D31-4C1F-8C51-E4956A037676}
                                    Key Present: HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}
                                    Key Present: HKLM\SOFTWARE\Classes\AppID\escort.DLL
                                    Key Present: HKLM\SOFTWARE\Classes\AppID\PCTutoBHO.DLL
                                    Key Present: HKLM\SOFTWARE\Classes\Applications\ilividsetupv1.exe
                                    Key Present: HKLM\SOFTWARE\Classes\Prod.cap
                                    Key Present: HKLM\Software\Conduit
                                    Key Present: HKLM\SOFTWARE\Microsoft\Tracing\iLivid_RASAPI32
                                    Key Present: HKLM\SOFTWARE\Microsoft\Tracing\iLivid_RASMANCS
                                    Key Present: HKLM\SOFTWARE\Microsoft\Tracing\iLividSetupV1_RASAPI32
                                    Key Present: HKLM\SOFTWARE\Microsoft\Tracing\iLividSetupV1_RASMANCS
                                    Key Present: HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASAPI32
                                    Key Present: HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASMANCS
                                    Key Present: HKLM\SOFTWARE\Microsoft\Tracing\SearchquMediaBar_RASAPI32
                                    Key Present: HKLM\SOFTWARE\Microsoft\Tracing\SearchquMediaBar_RASMANCS
                                    Key Present: HKLM\SOFTWARE\Microsoft\Tracing\SetupDataMngr_Searchqu_RASAPI32
                                    Key Present: HKLM\SOFTWARE\Microsoft\Tracing\SetupDataMngr_Searchqu_RASMANCS
                                    Key Present: HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
                                    Key Present: HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\paoponfhfdfnjgddpnpjkambkcgdaaib
                                    Key Present: HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
                                    Key Present: HKLM\SOFTWARE\DataMngr
                                    Key Present: HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
                                    Key Present: HKU\S-1-5-21-709892753-828266104-2070350981-1000\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
                                    Value Present: HKCU\Software\Microsoft\Internet Explorer\New Windows\Allow [*.crossrider.com]
                                    Value Present: HKLM\SOFTWARE\Microsoft\Internet Explorer\New Windows\Allow [*.crossrider.com]
                                    Value Present: HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [10]
                                    Value Present: HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [10]

                                    ***** [Browsers] *****

                                    -\\ Internet Explorer v9.0.8112.16464

                                    [OK] The registry does not contain any illegitimate entries.

                                    -\\ Google Chrome v [Unable to obtain version]

                                    File: C:\Users\Julien\AppData\Local\Google\Chrome\User Data\Default\Preferences

                                    [OK] The file does not contain any illegitimate entries.

                                    *************************

                                    AdwCleaner[R1].txt - [4617 bytes] - [19/02/2013 15:46:26]

                                    ########## EOF - C:\AdwCleaner[R1].txt - [4677 bytes] ##########
                                    0
                                    • 1
                                    • 2