Virus Help

Page 3 of 3 FirstFirst 123

  1. Posts : 21
    Windows 7 home premium 64 bit
    Thread Starter
       #21

    cottonball said:
    On the malware, please provide the latest avast! Scan Log.

    Will take a look at the above reports.

    Thanks!
    I don't think I have a latest Avast scan log. I never did a full system scan with it. Only with malwarebytes which came up with nothing bad.
      My Computer


  2. Posts : 6,830
    Windows 7 Ultimate 32-Bit & Windows 7 Ultimate 64-Bit
       #22

    Uninstall avast . That program causes a lot of BSODs . Download MSE instead
      My Computer


  3. Posts : 2,470
    Windows 7 Home Premium
       #23

    Hmmmm...so far, do not see what I expected.

    Please download: aswMBR
    http://public.avast.com/~gmerek/aswMBR.exe
    Save it to the Desktop.

    >>Make sure your AntiVirus is temporarily disabled!!<<
    For information on how to disable protective programs, refer to this Info:
    How To Temporarily Disable Your Anti-virus, Firewall And Anti-malware Programs - BleepingComputer.com

    Right-click aswMBR and select: Run as Administrator

    When promped with: This Application can use the Avast! Free AntiVirus for scanning...etc.
    Select: Yes

    The last line of the run in progress will provide the status of the Avast! scan.
    It will say: Downloading Avast! virus definitiond database, etc.

    When the Avast! scan is done, the last line changes to: Avast Engine definitions #####

    At this point, click the Scan button on the lower left of the aswMBR screen.
    The last line will now say "Scanning" while it is in progress.

    Upon completion of the scan, click >Save log< and save it to the Desktop.
    Note: Please do NOT attempt to fix anything!!

    Exit the program.

    Please post the new aswMBR log in your reply.


    Also, notice that another file is created on the Desktop.
    It is named MBR.dat.

    Please submit MBR.dat for analysis to VirusTotal:
    http://www.virustotal.com/

    https://www.sevenforums.com/tutorials/277740-online-scanners-scan-suspicious-files-your-pc.html

    If you get a message saying: 'File has already been analyzed', click: Reanalyze file

    Once scanned, and you see the full results page on your screen, go up to the address bar at the top of the browser, and copy the http:\\etc. address there.

    Then, provide the http:\\ address to the results page in your reply.
      My Computer


  4. Posts : 21
    Windows 7 home premium 64 bit
    Thread Starter
       #24

    Here:

    https://www.virustotal.com/en/file/1...is/1365824932/
    Virus Help Attached Files
      My Computer


  5. Posts : 2,470
    Windows 7 Home Premium
       #25

    Good job!! Now we have something.

    Let's see if the following will take care of the issue:

    Please download TDSSKiller.zip:
    http://www.bleepingcomputer.com/download/tdsskiller/
    Right-click the program and select: Extract to tdsskiller\


    A TDSSKiller folder is found on your Desktop.
    Open the folder, and double-click the TDSSKiller application.


    When the TDSSKiller console opens, click on: Change Parameters
    Under Additional Options, place a check in the box next to: Detect TDLFS File System
    Click: OK


    Press: Start Scan


    If a suspicious object is detected, the default action is Skip, leave it as is, and click on: Continue
    If malicious objects are found, they show in the Scan results.
    Ensure Cure (the default) is selected, then click: Continue > Reboot now, to finish the cleaning process.
    (Note: If Cure is not available, select Skip, >>Do not select: Delete<<)


    When done, the tool outputs its log to the disk with the Windows Operating System, normally C:\


    Logs have a name like:
    C:\TDSSKiller.X.X.X_12.04.2013_15.31.43_log.txt


    Please post the TDSSKiller log in your reply.
      My Computer


  6. Posts : 21
    Windows 7 home premium 64 bit
    Thread Starter
       #26

    Here you go:
    Virus Help Attached Files
      My Computer


  7. Posts : 2,470
    Windows 7 Home Premium
       #27

    Did you reboot?
      My Computer


  8. Posts : 21
    Windows 7 home premium 64 bit
    Thread Starter
       #28

    I posted the log, then rebooted. It's now gone! Thanks to everyone who helped.
      My Computer


  9. Posts : 6,830
    Windows 7 Ultimate 32-Bit & Windows 7 Ultimate 64-Bit
       #29

    You're welcome

    If you need to delete the windows.old folder

    Windows.old Folder - Delete
      My Computer


  10. Posts : 2,470
    Windows 7 Home Premium
       #30

    Glad to help, Breakyorself!

    It smelled like an MBR/Rootkit issue from the get go.
      My Computer


 
Page 3 of 3 FirstFirst 123

  Related Discussions
Our Sites
Site Links
About Us
Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 13:06.
Find Us