View Full Version : WhatsApp virus?

2016-10-21, 00:06

As a WhatsApp user, yesterday I instinctively clicked on an email which informed me that my free use of the service had expired, and that I had to pay £0.99 subscription per year to continue to use the app. The link took me to an office-like page, which then immediately closed. I checked on Google, and it seems it was a virus scam. Only last week I patched up all my computers with the latest Windows updates, and my anti-virus scans have subsequently found nothing. However, I am worried I may have a sophisticated virus on board.

I would very much appreciate some help. My logs are below.


aswMBR version Copyright(c) 2014 AVAST Software
Run date: 2016-10-20 20:55:38
20:55:38.526 OS Version: Windows x64 6.1.7601 Service Pack 1
20:55:38.526 Number of processors: 4 586 0x3C03
20:55:38.526 ComputerName: USER-PC UserName: USER
20:55:39.321 Initialize success
20:55:39.353 VM: initialized successfully
20:55:39.353 VM: Intel CPU BiosDisabled
20:55:58.505 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0
20:55:58.505 Disk 0 Vendor: WDC_WD5003AZEX-00MK2A0 01.01A01 Size: 476940MB BusType: 11
20:55:58.693 Disk 0 MBR read successfully
20:55:58.708 Disk 0 MBR scan
20:55:58.708 Disk 0 Windows 7 default MBR code
20:55:58.739 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 100 MB offset 2048
20:55:58.755 Disk 0 default boot code
20:55:58.755 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 476838 MB offset 206848
20:55:58.786 Disk 0 scanning C:\Windows\system32\drivers
20:56:02.593 Service scanning
20:56:09.769 Modules scanning
20:56:09.784 Disk 0 trace - called modules:
20:56:09.815 ntoskrnl.exe CLASSPNP.SYS disk.sys iaStorF.sys ataport.SYS PCIIDEX.SYS hal.dll msahci.sys
20:56:09.815 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa80078ed060]
20:56:09.831 3 CLASSPNP.SYS[fffff880017b043f] -> nt!IofCallDriver -> [0xfffffa800772fc50]
20:56:09.831 5 iaStorF.sys[fffff880018b5a84] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0xfffffa800733a060]
20:56:09.847 Disk 0 statistics 96488/0/0 @ 12.57 MB/s
20:56:09.847 Scan finished successfully
20:56:27.678 Disk 0 MBR has been saved successfully to "C:\Users\USER\Desktop\MBR.dat"
20:56:27.678 The log file has been saved successfully to "C:\Users\USER\Desktop\aswMBR.txt"

2016-10-21, 14:40
I did read this is a scam.

No visible signs of infection but we will take a few safeguards.

Please open Notepad *Do Not Use Wordpad!* or use any other text editor than Notepad or the script will fail. (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the quote box below:
To do this highlight the contents of the box and right click on it and select copy.
Paste this into the open notepad. save it to the Desktop as fixlist.txt
NOTE. It's important that both files, FRST/FRST64 and fixlist.txt are in the same location or the fix will not work.
It needs to be saved Next to the "Farbar Recovery Scan Tool" (If asked to overwrite existing one please allow)


C:\Users\USER 2\AppData\Local\Temp\avgnt.exe
Reg: reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
Reg: reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f

Open FRST/FRST64 and press the > Fix < button just once and wait.
If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
When finished FRST will generate a log on the Desktop (Fixlog.txt). Please post it to your reply.


http://i.imgur.com/BY4dvz9.png AdwCleaner

Please download AdwCleaner (http://www.bleepingcomputer.com/download/adwcleaner/dl/125/) and save the file to your Desktop.
In order to use AdwCleaner, you have to agree the Eula:
Right-click AdwCleaner.exe and select http://i.imgur.com/AVOiBNU.jpg Run as administrator to run the programme.
Follow the prompts.
Click http://i.imgur.com/A49sxPr.png Scan.
Upon completion, click http://i.imgur.com/6cyn5v5.png Logfile. A log (AdwCleaner[S1].txt) will open. Briefly check the log for anything you know to be legitimate.
Return to AdwCleaner. Ensure anything you know to be legitimate does not have a checkmark under the corresponding tab.
Click http://i.imgur.com/MqHawIb.png Clean.
Follow the prompts and allow your computer to reboot.
After the reboot, a log (AdwCleaner[C1].txt) will open. Copy the contents of the log and paste in your next reply.

-- File and folder backups are made for items removed using this programme. Should a legitimate file or folder be removed (otherwise known as a 'false-positive'), simple steps can be taken to restore the item. Please do not overly concern yourself with the contents of AdwCleaner[C1].txt.


Please download Junkware Removal Tool (http://www.bleepingcomputer.com/download/junkware-removal-tool/)
or from here http://downloads.malwarebytes.org/file/jrt
to your desktop.

Shut down your protection software now to avoid potential conflicts.
Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
The tool will open and start scanning your system.
Please be patient as this can take a while to complete depending on your system's specifications.
On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
Post the contents of JRT.txt into your next message.

please post

2016-10-22, 16:19
Hi Juliet

Thanks for your help. The instructed logs are below-

Fix result of Farbar Recovery Scan Tool (x64) Version: 17-10-2016
Ran by USER (22-10-2016 12:47:00) Run:1
Running from C:\Users\USER\Desktop
Loaded Profiles: USER (Available Profiles: USER & USER 2)
Boot Mode: Normal

fixlist content:
C:\Users\USER 2\AppData\Local\Temp\avgnt.exe
Reg: reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
Reg: reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f

Restore point was successfully created.
Processes closed successfully.
C:\Users\USER\AppData\Local\Temp\avgnt.exe => moved successfully
C:\Users\USER\AppData\Local\Temp\FoxitUpdater.exe => moved successfully
C:\Users\USER 2\AppData\Local\Temp\avgnt.exe => moved successfully

========= reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f =========

The operation completed successfully.

========= End of Reg: =========

========= reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f =========

The operation completed successfully.

========= End of Reg: =========

=========== EmptyTemp: ==========

BITS transfer queue => 8388608 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 6151551 B
Java, Flash, Steam htmlcache => 291 B
Windows/system/drivers => 79598663 B
Edge => 0 B
Chrome => 0 B
Firefox => 0 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Default => 0 B
Public => 0 B
ProgramData => 0 B
systemprofile => 55425096 B
systemprofile32 => 66356 B
LocalService => 66228 B
NetworkService => 0 B
USER => 19434707 B
USER 2 => 11429137 B

RecycleBin => 0 B
EmptyTemp: => 172.2 MB temporary data Removed.


The system needed a reboot.

==== End of Fixlog 12:47:12 ====

# AdwCleaner v6.030 - Logfile created 22/10/2016 at 13:04:13
# Updated on 19/10/2016 by Malwarebytes
# Database : 2016-10-18.1 [Local]
# Operating System : Windows 7 Home Premium Service Pack 1 (X64)
# Username : USER - USER-PC
# Running from : C:\Users\USER\Desktop\AdwCleaner.exe
# Mode: Clean
# Support : hxxps://www.malwarebytes.com/support

***** [ Services ] *****

***** [ Folders ] *****

***** [ Files ] *****

***** [ DLL ] *****

***** [ WMI ] *****

***** [ Shortcuts ] *****

***** [ Scheduled Tasks ] *****

***** [ Registry ] *****

***** [ Web browsers ] *****


:: "Tracing" keys deleted
:: Winsock settings cleared


C:\AdwCleaner\AdwCleaner[C0].txt - [761 Bytes] - [22/10/2016 13:04:13]
C:\AdwCleaner\AdwCleaner[S0].txt - [1153 Bytes] - [22/10/2016 13:01:07]

########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt - [906 Bytes] ##########

Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.0.9 (09.30.2016)
Operating System: Windows 7 Home Premium x64
Ran by USER (Administrator) on 22/10/2016 at 13:15:29.56

File System: 8

Successfully deleted: C:\Users\USER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\3T20Y99M (Temporary Internet Files Folder)
Successfully deleted: C:\Users\USER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7KKUX6D8 (Temporary Internet Files Folder)
Successfully deleted: C:\Users\USER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FP5CXLOP (Temporary Internet Files Folder)
Successfully deleted: C:\Users\USER\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TS21YDXV (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\3T20Y99M (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7KKUX6D8 (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FP5CXLOP (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TS21YDXV (Temporary Internet Files Folder)

Registry: 0

Scan was completed on 22/10/2016 at 13:16:14.86
End of JRT log

2016-10-22, 22:50
Since you already have Malwarebytes Anti-Malware on board, let's update and run a scan with this first.

Malwarebytes Anti-Malware

On the Dashboard click on Update Now

Go to the Setting Tab

Under Setting go to Detection and Protection

Under PUP and PUM make sure both are set to show Treat Detections as Malware

Go to Advanced setting and make sure Automatically Quarantine Detected Items is checked

Then on the Dashboard click on Scan

Make sure to select THREAT SCAN

Then click on Scan

Note: You may see the following message, "Could not load DDA driver". Click Yes, allow your PC to reboot and continue afterwards.
If threats are detected, click Remove Selected. If you are prompted to reboot, click Yes.
Upon completion of the scan (or after the reboot), click the History tab.
Click Application Logs, followed by the first Scan Log.
Click Export, followed by Copy to Clipboard. Paste the log in your next reply.


Please download Emsisoft Emergency Kit (http://dl.emsisoft.com/EmsisoftEmergencyKit.exe) and save it to your desktop.
Double click on the EmsisoftEmergencyKit file you downloaded to extract its contents and create a shortcut on the desktop.

Leave all settings as they are and click the Extract button at the bottom.
A folder named EEK will be created in the root of the drive (usually c:\).

After extraction please double-click on the new Start Emsisoft Emergency Kit icon on your desktop.
The first time you launch it, Emsisoft Emergency Kit will recommend that you allow it to download updates.
Please click Yes so that it downloads the latest database updates.
When the update process is complete, a new button will appear in the lower-left corner that says Back. Click on this button to return to the Overview screen.
Click on Scan to be taken to the scan options.
If you are asked if you want the scanner to scan for Potentially Unwanted Programs, then click Yes.
Click on the Malware Scan button to start the scan.
When the scan is completed click the View report button in the lower-right corner, and the scan log will be opened in Notepad.
Please save the log in Notepad on your desktop, and copy it to your next reply.
When you close Emsisoft Emergency Kit, it will give you an option to sign up for a newsletter. This is optional, and is not necessary for the malware removal process.

Please post these 2 logs when finished along with comments on how the computer is now.

2016-10-23, 03:57
Hi Juliet

The logs are below. My resident scanner Avira crashed momentarily after I installed Emsisoft but recovered after a reboot. I quite like the Emsisoft and would like to replace SuperAntiSpyware with it, but it may clash with Avira. What would you advise? Also, how to remove the other cleaning materials?

Malwarebytes Anti-Malware

Scan Date: 22/10/2016
Scan Time: 22:45
Administrator: Yes

Malware Database: v2016.10.22.05
Rootkit Database: v2016.09.26.02
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled

OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: USER

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 320640
Time Elapsed: 4 min, 38 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 0
(No malicious items detected)

Registry Values: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Folders: 0
(No malicious items detected)

Files: 0
(No malicious items detected)

Physical Sectors: 0
(No malicious items detected)


Emsisoft Emergency Kit - Version 11.9
Last update: 23/10/2016 00:12:20
User account: USER-PC\USER
Computer name: USER-PC
OS version: Windows 7x64 Service Pack 1

Scan settings:

Scan type: Malware Scan
Objects: Rootkits, Memory, Traces, Files

Detect PUPs: On
Scan archives: Off
ADS Scan: On
File extension filter: Off
Advanced caching: On
Direct disk access: Off

Scan start: 23/10/2016 00:12:58

Scanned 70178
Found 0

Scan end: 23/10/2016 00:15:09
Scan time: 0:02:11

2016-10-23, 15:06
Hi Juliet

The logs are below. My resident scanner Avira crashed momentarily after I installed Emsisoft but recovered after a reboot. I quite like the Emsisoft and would like to replace SuperAntiSpyware with it, but it may clash with Avira. What would you advise? Also, how to remove the other cleaning materials?
You can Temporarily Disable Your Anti-virus. The link below supplies info, scroll down to your antivirus

Scans came back clean, are we ready to remove tools and quarantine folders?

2016-10-23, 19:15
Thanks for the link. So very relieved that the PC's clean. Yes I am ready for the final clean-up.

2016-10-23, 21:59

Please download DelFix (http://general-changelog-team.fr/en/downloads/finish/20-outils-de-xplode/9-delfix) or from Here (http://www.bleepingcomputer.com/download/delfix/) and save the file to your Desktop.
Double-click DelFix.exe to run the programme.
Place a checkmark next to the following items:
Activate UAC
Remove disinfection tools
Click the Run button.
-- This will remove the specialized tools we used to disinfect your system.
Any leftover logs, files, folders or tools remaining on your Desktop which were not removed can be deleted manually (right-click the file + delete).


Answers to common security questions - Best Practices (http://www.bleepingcomputer.com/forums/t/407147/answers-to-common-security-questions-best-practices/) by quietman7, MVP
How Malware Spreads - How did I get infected? (http://www.bleepingcomputer.com/forums/t/287710/how-malware-spreads-how-did-i-get-infected/) by quietman7, MVP
Simple and easy ways to keep your computer safe and secure on the Internet (http://www.bleepingcomputer.com/tutorials/keep-your-computer-safe-online/) by Lawrence Abrams, MVP
How to Prevent Malware (http://users.telenet.be/bluepatchy/miekiemoes/prevention.html) by miekiemoes, MVP
How to backup and restore your data using Cobian Backup (http://www.bleepingcomputer.com/tutorials/backup-and-restore-data-with-cobian-backup/) by YourHighness
Slow Computer/browser? It May Not Be Malware (http://www.bleepingcomputer.com/forums/t/87058/slow-computerbrowser-check-here-first;-it-may-not-be-malware/) by quietman7, MVP

AdBlock (https://adblockplus.org/en/firefox) is a browser add-on that blocks annoying banners, pop-ups and video ads.
http://i.imgur.com/E8I37RF.pngCryptoPrevent (https://www.foolishit.com/) places policy restrictions on loading points for ransomware (eg. CryptoWall), helping prevent the execution of malware.
http://i.imgur.com/EG85Vjt.png Malwarebytes Anti-Exploit (https://www.malwarebytes.org/antiexploit/) (MBAE) is designed to prevent zero-day malware from exploiting vulnerable software.
http://i.imgur.com/6YRrgUC.png Malwarebytes Anti-Malware Premium (https://www.malwarebytes.org/) (MBAM) works in real-time along side your Anti-Virus to prevent malware execution.
http://i.imgur.com/jv4nhMJ.png NoScript (http://noscript.net/) is a Firefox add-on that blocks the actions of malicious scripts by using whitelisting and other technology.
http://i.imgur.com/3O8r9Uq.png (http://www.sandboxie.com/) Sandboxie (http://www.sandboxie.com/) isolates programmes of your choice, preventing files from being written to your HDD unless approved by you.
http://i.imgur.com/DgW1XL2.png Secunia PSI (http://secunia.com/vulnerability_scanning/personal/) will scan your computer for vulnerable software that is outdated, and automatically find the latest update for you.
http://i.imgur.com/j1OLIec.png SpywareBlaster (https://www.brightfort.com/spywareblaster.html) is a form of passive protection, designed to block the actions of malicious websites and tracking cookies.
http://i.imgur.com/sHjS79L.png Unchecky (http://unchecky.com/) automatically removes checkmarks for bunlded software in programme installers; helping you avoid adware and PUPs.
http://i.imgur.com/JEP5iWI.png Web of Trust (https://www.mywot.com/) (WOT) is a browser add-on designed to alert you before interacting with a potentially malicious website.

2016-10-23, 23:57

Its all done now. Many thanks for your help.

# DelFix v1.010 - Logfile created 23/10/2016 at 20:33:53
# Updated 26/04/2015 by Xplode
# Username : USER - USER-PC
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)

~ Activating UAC ... OK

~ Removing disinfection tools ...

Deleted : C:\FRST
Deleted : C:\AdwCleaner
Deleted : C:\Users\USER\Desktop\AdwCleaner.exe
Deleted : C:\Users\USER\Desktop\AdwCleaner_results.txt
Deleted : C:\Users\USER\Desktop\aswMBR.exe
Deleted : C:\Users\USER\Desktop\Fixlog.txt
Deleted : C:\Users\USER\Desktop\FRST64.exe
Deleted : C:\Users\USER\Desktop\JRT.exe
Deleted : C:\Users\USER\Desktop\JRT.txt
Deleted : C:\Users\USER\Desktop\JRT2.txt
Deleted : HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ASWMBR

########## - EOF - ##########

2016-10-24, 12:09
We're glad to help, safe surfing.

2016-10-24, 17:22
Glad we could help. :)http://i204.photobucket.com/albums/bb106/Juliet702/sparkle.gif

Since this issue appears resolved ... this Topic is closed.