Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Virus Scan Continuously Showing the Same Virus Every Day


  • This topic is locked This topic is locked
2 replies to this topic

#1 DJAkari

DJAkari

  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:03:22 AM

Posted 21 January 2014 - 12:47 PM

Hello, My name is Meghan and I have been having problems finding out where these viruses are coming from. I have done a virus scan from Malwarebytes Anti-Malware(pro) in the past with no problems in which it always deleted the viruses and they were gone, but for a week now I have done scans and it keeps showing a large number of viruses in this certain folder in the AppData. Some days it can be 104 or up to 66, and they are all under the same folder. I keep doing scans to try and get rid of them, but they keep popping up every day, and I am afraid it will do something to my computer. 
--Here is the folder they are coming from (all the viruses look the same and are coming from the same folder)
--Files Detected: 42
C:\Users\Meghan\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\96ZERUNW\Flvto_Converter_7428[1].exe (PUP.Optional.InstallMonetizer.A) -> Quarantined and deleted successfully.
C:\Users\Meghan\AppData\Local\Temp\GC\Profiles\{05EF319E-6581-42A1-8E4A-2E69012E378B}\Default\Extensions\ogccgbmabaphcakpiclgcnmcnimhokcj\1.3.0.3_0\mgHelperGC.dll (PUP.Optional.SweetIM) -> Quarantined and deleted successfully.
C:\Users\Meghan\AppData\Local\Temp\GC\Profiles\{069FDE16-AA04-4E29-838B-DC40F958D7DB}\Default\Extensions\ogccgbmabaphcakpiclgcnmcnimhokcj\1.3.0.3_0\mgHelperGC.dll (PUP.Optional.SweetIM) -> Quarantined and deleted successfully.
C:\Users\Meghan\AppData\Local\Temp\GC\Profiles\{08897F91-DC9F-4294-B484-44707EE7859B}\Default\Extensions\ogccgbmabaphcakpiclgcnmcnimhokcj\1.3.0.3_0\mgHelperGC.dll (PUP.Optional.SweetIM) -> Quarantined and deleted successfully.
C:\Users\Meghan\AppData\Local\Temp\GC\Profiles\{24EADDB1-CA09-4B4F-8DA3-48335E64D0D6}\Default\Extensions\ogccgbmabaphcakpiclgcnmcnimhokcj\1.3.0.3_0\mgHelperGC.dll (PUP.Optional.SweetIM) -> Quarantined and deleted successfully.
C:\Users\Meghan\AppData\Local\Temp\GC\Profiles\{27E3B354-A4D1-49ED-BBAB-C25DF13673DC}\Default\Extensions\ogccgbmabaphcakpiclgcnmcnimhokcj\1.3.0.3_0\mgHelperGC.dll (PUP.Optional.SweetIM) -> Quarantined and deleted successfully.
C:\Users\Meghan\AppData\Local\Temp\GC\Profiles\{2B130F4B-E0E3-40A6-AA9B-4FE60A24D895}\Default\Extensions\ogccgbmabaphcakpiclgcnmcnimhokcj\1.3.0.3_0\mgHelperGC.dll (PUP.Optional.SweetIM) -> Quarantined and deleted successfully.
C:\Users\Meghan\AppData\Local\Temp\GC\Profiles\{3C8BB3C7-4EDB-4434-BD07-5926ACD03886}\Default\Extensions\ogccgbmabaphcakpiclgcnmcnimhokcj\1.3.0.3_0\mgHelperGC.dll (PUP.Optional.SweetIM) -> Quarantined and deleted successfully.
C:\Users\Meghan\AppData\Local\Temp\GC\Profiles\{42C1BC6D-A5CD-442F-9C3A-9C7406E157BF}\Default\Extensions\ogccgbmabaphcakpiclgcnmcnimhokcj\1.3.0.3_0\mgHelperGC.dll (PUP.Optional.SweetIM) -> Quarantined and deleted successfully.
C:\Users\Meghan\AppData\Local\Temp\GC\Profiles\{4889D7D5-8410-4E34-BBAA-0D9B8E421ED3}\Default\Extensions\ogccgbmabaphcakpiclgcnmcnimhokcj\1.3.0.3_0\mgHelperGC.dll (PUP.Optional.SweetIM) -> Quarantined and deleted successfully.
C:\Users\Meghan\AppData\Local\Temp\GC\Profiles\{4E23CD21-9FE6-4BC7-BDE0-B2FE15C240C6}\Default\Extensions\ogccgbmabaphcakpiclgcnmcnimhokcj\1.3.0.3_0\mgHelperGC.dll (PUP.Optional.SweetIM) -> Quarantined and deleted successfully.
C:\Users\Meghan\AppData\Local\Temp\GC\Profiles\{50568D18-8E52-4F05-89B7-DEB382EA9FAE}\Default\Extensions\ogccgbmabaphcakpiclgcnmcnimhokcj\1.3.0.3_0\mgHelperGC.dll (PUP.Optional.SweetIM) -> Quarantined and deleted successfully.
C:\Users\Meghan\AppData\Local\Temp\GC\Profiles\{5074EDCE-3A24-44E9-8BFA-8ED5017F7078}\Default\Extensions\ogccgbmabaphcakpiclgcnmcnimhokcj\1.3.0.3_0\mgHelperGC.dll (PUP.Optional.SweetIM) -> Quarantined and deleted successfully.
C:\Users\Meghan\AppData\Local\Temp\GC\Profiles\{5EB86699-BF28-42A6-835A-0A57B1A20455}\Default\Extensions\ogccgbmabaphcakpiclgcnmcnimhokcj\1.3.0.3_0\mgHelperGC.dll (PUP.Optional.SweetIM) -> Quarantined and deleted successfully.
C:\Users\Meghan\AppData\Local\Temp\GC\Profiles\{69FB23E1-E62B-4D9A-A518-E7599AE6FA20}\Default\Extensions\ogccgbmabaphcakpiclgcnmcnimhokcj\1.3.0.3_0\mgHelperGC.dll (PUP.Optional.SweetIM) -> Quarantined and deleted successfully.
C:\Users\Meghan\AppData\Local\Temp\GC\Profiles\{6C8A4133-A425-4565-9F6E-C7A09A993791}\Default\Extensions\ogccgbmabaphcakpiclgcnmcnimhokcj\1.3.0.3_0\mgHelperGC.dll (PUP.Optional.SweetIM) -> Quarantined and deleted successfully.
C:\Users\Meghan\AppData\Local\Temp\GC\Profiles\{76D20E18-D8DD-41BB-8C88-A88F69DC78C2}\Default\Extensions\ogccgbmabaphcakpiclgcnmcnimhokcj\1.3.0.3_0\mgHelperGC.dll (PUP.Optional.SweetIM) -> Quarantined and deleted successfully.
C:\Users\Meghan\AppData\Local\Temp\GC\Profiles\{77F1FCE3-7AAA-4DCD-AFD0-3EAECBFB3724}\Default\Extensions\ogccgbmabaphcakpiclgcnmcnimhokcj\1.3.0.3_0\mgHelperGC.dll (PUP.Optional.SweetIM) -> Quarantined and deleted successfully.
C:\Users\Meghan\AppData\Local\Temp\GC\Profiles\{79049881-D2B9-4207-BB9C-19579573EFD6}\Default\Extensions\ogccgbmabaphcakpiclgcnmcnimhokcj\1.3.0.3_0\mgHelperGC.dll (PUP.Optional.SweetIM) -> Quarantined and deleted successfully.
C:\Users\Meghan\AppData\Local\Temp\GC\Profiles\{7BF42022-ADB4-4F07-A9F8-FBD7E572C837}\Default\Extensions\ogccgbmabaphcakpiclgcnmcnimhokcj\1.3.0.3_0\mgHelperGC.dll (PUP.Optional.SweetIM) -> Quarantined and deleted successfully.
C:\Users\Meghan\AppData\Local\Temp\GC\Profiles\{7F55C7E5-A4CC-4C9B-A972-8DDD0E8E9671}\Default\Extensions\ogccgbmabaphcakpiclgcnmcnimhokcj\1.3.0.3_0\mgHelperGC.dll (PUP.Optional.SweetIM) -> Quarantined and deleted successfully.
C:\Users\Meghan\AppData\Local\Temp\GC\Profiles\{80C839EF-D9AD-4B51-9F64-2E09F9B21493}\Default\Extensions\ogccgbmabaphcakpiclgcnmcnimhokcj\1.3.0.3_0\mgHelperGC.dll (PUP.Optional.SweetIM) -> Quarantined and deleted successfully.
C:\Users\Meghan\AppData\Local\Temp\GC\Profiles\{84AA799D-9994-4FFE-A90B-E58AC9B883FF}\Default\Extensions\ogccgbmabaphcakpiclgcnmcnimhokcj\1.3.0.3_0\mgHelperGC.dll (PUP.Optional.SweetIM) -> Quarantined and deleted successfully.
C:\Users\Meghan\AppData\Local\Temp\GC\Profiles\{8C7BEE2D-8FDF-4E0B-B4B5-7A15B042E018}\Default\Extensions\ogccgbmabaphcakpiclgcnmcnimhokcj\1.3.0.3_0\mgHelperGC.dll (PUP.Optional.SweetIM) -> Quarantined and deleted successfully.
C:\Users\Meghan\AppData\Local\Temp\GC\Profiles\{8DF4D95C-7540-44D0-B728-E6BCE9EE0305}\Default\Extensions\ogccgbmabaphcakpiclgcnmcnimhokcj\1.3.0.3_0\mgHelperGC.dll (PUP.Optional.SweetIM) -> Quarantined and deleted successfully.
C:\Users\Meghan\AppData\Local\Temp\GC\Profiles\{96DF6ABC-1DC9-4779-ACC2-5AFCF160FB84}\Default\Extensions\ogccgbmabaphcakpiclgcnmcnimhokcj\1.3.0.3_0\mgHelperGC.dll (PUP.Optional.SweetIM) -> Quarantined and deleted successfully.
C:\Users\Meghan\AppData\Local\Temp\GC\Profiles\{996B0CD8-38E6-467D-B2FA-55F98CB7F0C2}\Default\Extensions\ogccgbmabaphcakpiclgcnmcnimhokcj\1.3.0.3_0\mgHelperGC.dll (PUP.Optional.SweetIM) -> Quarantined and deleted successfully.
C:\Users\Meghan\AppData\Local\Temp\GC\Profiles\{9A60E046-0C3B-4508-AB3B-0E0AEC035DC4}\Default\Extensions\ogccgbmabaphcakpiclgcnmcnimhokcj\1.3.0.3_0\mgHelperGC.dll (PUP.Optional.SweetIM) -> Quarantined and deleted successfully.
C:\Users\Meghan\AppData\Local\Temp\GC\Profiles\{A66DAF9F-1640-44B2-990A-2E4B2F55790F}\Default\Extensions\ogccgbmabaphcakpiclgcnmcnimhokcj\1.3.0.3_0\mgHelperGC.dll (PUP.Optional.SweetIM) -> Quarantined and deleted successfully.
C:\Users\Meghan\AppData\Local\Temp\GC\Profiles\{AA82D220-0FDB-44F1-90D0-FCA5D1A4FE35}\Default\Extensions\ogccgbmabaphcakpiclgcnmcnimhokcj\1.3.0.3_0\mgHelperGC.dll (PUP.Optional.SweetIM) -> Quarantined and deleted successfully.
C:\Users\Meghan\AppData\Local\Temp\GC\Profiles\{ADBBDEE0-DD50-4426-A73F-019A6A201114}\Default\Extensions\ogccgbmabaphcakpiclgcnmcnimhokcj\1.3.0.3_0\mgHelperGC.dll (PUP.Optional.SweetIM) -> Quarantined and deleted successfully.
C:\Users\Meghan\AppData\Local\Temp\GC\Profiles\{BCC261B1-8446-49B5-AD04-8F97E6D10378}\Default\Extensions\ogccgbmabaphcakpiclgcnmcnimhokcj\1.3.0.3_0\mgHelperGC.dll (PUP.Optional.SweetIM) -> Quarantined and deleted successfully.
C:\Users\Meghan\AppData\Local\Temp\GC\Profiles\{BE6A2804-EF6A-421C-8380-D317B1AE15FE}\Default\Extensions\ogccgbmabaphcakpiclgcnmcnimhokcj\1.3.0.3_0\mgHelperGC.dll (PUP.Optional.SweetIM) -> Quarantined and deleted successfully.
C:\Users\Meghan\AppData\Local\Temp\GC\Profiles\{C9F9BB70-7984-4732-8808-13EE0B33B8C8}\Default\Extensions\ogccgbmabaphcakpiclgcnmcnimhokcj\1.3.0.3_0\mgHelperGC.dll (PUP.Optional.SweetIM) -> Quarantined and deleted successfully.
C:\Users\Meghan\AppData\Local\Temp\GC\Profiles\{D0984524-A6DD-4F44-88FE-664AF85F555E}\Default\Extensions\ogccgbmabaphcakpiclgcnmcnimhokcj\1.3.0.3_0\mgHelperGC.dll (PUP.Optional.SweetIM) -> Quarantined and deleted successfully.
C:\Users\Meghan\AppData\Local\Temp\GC\Profiles\{D5729421-090B-4DEC-84AD-32A7B61C0B7F}\Default\Extensions\ogccgbmabaphcakpiclgcnmcnimhokcj\1.3.0.3_0\mgHelperGC.dll (PUP.Optional.SweetIM) -> Quarantined and deleted successfully.
C:\Users\Meghan\AppData\Local\Temp\GC\Profiles\{D9C94B17-3361-4B7F-96A9-4CAD54EF5122}\Default\Extensions\ogccgbmabaphcakpiclgcnmcnimhokcj\1.3.0.3_0\mgHelperGC.dll (PUP.Optional.SweetIM) -> Quarantined and deleted successfully.
C:\Users\Meghan\AppData\Local\Temp\GC\Profiles\{DA480358-D8B5-413B-A230-17D5F7059665}\Default\Extensions\ogccgbmabaphcakpiclgcnmcnimhokcj\1.3.0.3_0\mgHelperGC.dll (PUP.Optional.SweetIM) -> Quarantined and deleted successfully.
C:\Users\Meghan\AppData\Local\Temp\GC\Profiles\{DB46BA86-68A0-49C2-99EF-9FC022FCC307}\Default\Extensions\ogccgbmabaphcakpiclgcnmcnimhokcj\1.3.0.3_0\mgHelperGC.dll (PUP.Optional.SweetIM) -> Quarantined and deleted successfully.
C:\Users\Meghan\AppData\Local\Temp\GC\Profiles\{F4B44D97-515F-4BDF-B3FF-1DE975F18A78}\Default\Extensions\ogccgbmabaphcakpiclgcnmcnimhokcj\1.3.0.3_0\mgHelperGC.dll (PUP.Optional.SweetIM) -> Quarantined and deleted successfully.
C:\Users\Meghan\AppData\Local\Temp\GC\Profiles\{F836DB3F-1F73-4A6A-AED4-5BFC0E4F5332}\Default\Extensions\ogccgbmabaphcakpiclgcnmcnimhokcj\1.3.0.3_0\mgHelperGC.dll (PUP.Optional.SweetIM) -> Quarantined and deleted successfully.
C:\Users\Meghan\AppData\Local\Temp\nsk48C6.tmp\InstallManager.exe (PUP.Optional.InstallMonetizer.A) -> Quarantined and deleted successfully.
 
(end)
 
--I just want to know why I keep getting these everyday.


BC AdBot (Login to Remove)

 


#2 Noviciate

Noviciate

  • Malware Response Team
  • 5,277 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Numpty HQ
  • Local time:07:22 AM

Posted 21 January 2014 - 03:33 PM

Good evening. :)

Please go here, follow step six, and then post accordingly into this thread.
 


So long, and thanks for all the fish.

 

 


#3 Noviciate

Noviciate

  • Malware Response Team
  • 5,277 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Numpty HQ
  • Local time:07:22 AM

Posted 26 January 2014 - 02:40 PM

Helpers are limited in the number of logs they can take by the time they have available and having threads sit idle means that somebody else who could be being helped has to wait.
Given that there has been no response for at least five days, and I have no way of knowing when there will be one, this thread is now closed.

When you are able to free up some time to work on your PC problem, feel free to start a fresh thread and somebody will be along as soon as to help.


So long, and thanks for all the fish.

 

 





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users