possible virus, which forum to go to for help

Hello and thx for following up. Will do this in the morning after some shut eye. :)
 

My Computer My Computer

At a glance

W7 premium 64amd a8-38508G g-skillasus gt-520 silent
OS
W7 premium 64
CPU
amd a8-3850
Motherboard
asus f1-a75v pro
Memory
8G g-skill
Graphics Card(s)
asus gt-520 silent
Monitor(s) Displays
LED viewsonic 24"
Hard Drives
seagate sata 120
wd 2T green
PSU
cool master 600W silent pro (80+bronze)
No problem, drmax.

Going to get some Zzzzsss also.

Might not het back to you until tomorrow afternoon. Having lunch with a couple of friends.
 

My Computer My Computer

At a glance

Windows 7 Home Premium
Computer type
PC/Desktop
Computer Manufacturer/Model Number
An ol' eMachines
OS
Windows 7 Home Premium
Internet Speed
Fine for me...I'm retired!
Here you go. Does this ck more than just the operating systems drive? I have another storage drive that pretty big. I'd like this looked over.
 

Attachments

My Computer My Computer

At a glance

W7 premium 64amd a8-38508G g-skillasus gt-520 silent
OS
W7 premium 64
CPU
amd a8-3850
Motherboard
asus f1-a75v pro
Memory
8G g-skill
Graphics Card(s)
asus gt-520 silent
Monitor(s) Displays
LED viewsonic 24"
Hard Drives
seagate sata 120
wd 2T green
PSU
cool master 600W silent pro (80+bronze)
drmax,

Let’s check the Master Boot Record; another location where Rootkits hide.

In the clean computer with the USB flash drive plugged in...

Please download MBRFix:
Download MBRFix 1.3.0.0 Free - Fix or create Master Boot Record (MBR) on harddisks - Softpedia
Save to the Desktop.

Right-click the file and select: Extract here…

Once extracted, there are three files in the folder that is created.

Copy only the MBRFix64 application to the USB drive.


Now, open Notepad: (Start > All Programs > Accessories > Notepad).
Copy the entire contents of the code box below.

Code:
HKLM\...D6A79037F57F\InprocServer32: [Default-fastprox]  ATTENTION! ====> ZeroAccess
SaveMbr: Drive=0

Save this info on the flashdrive as fixlist.txt
 

Once again, please enter System Recovery Options and select: Command Prompt

Run FRST and press the Fix button just once, and wait.

When done, the tool makes a log on the flashdrive called Fixlog.txt.

Please post its contents in your reply.

Another file, MBRDUMP.txt also appear on the flash drive.
It may look a text file, but it is not. It is a hex file! (Don't open it, it will be all gibberish.)

Please attach the MBRDUMP.txt in your reply.
 
Last edited:

My Computer My Computer

At a glance

Windows 7 Home Premium
Computer type
PC/Desktop
Computer Manufacturer/Model Number
An ol' eMachines
OS
Windows 7 Home Premium
Internet Speed
Fine for me...I'm retired!
will get to this asap, hopefully within an hour or 2
 

My Computer My Computer

At a glance

W7 premium 64amd a8-38508G g-skillasus gt-520 silent
OS
W7 premium 64
CPU
amd a8-3850
Motherboard
asus f1-a75v pro
Memory
8G g-skill
Graphics Card(s)
asus gt-520 silent
Monitor(s) Displays
LED viewsonic 24"
Hard Drives
seagate sata 120
wd 2T green
PSU
cool master 600W silent pro (80+bronze)
?

2 of the 3 app files are mbrfix and mbrfix64? my machine is a 64 bit. you asked me to use the mbrfix. double checking before you ask me to do over. thx dm
 

My Computer My Computer

At a glance

W7 premium 64amd a8-38508G g-skillasus gt-520 silent
OS
W7 premium 64
CPU
amd a8-3850
Motherboard
asus f1-a75v pro
Memory
8G g-skill
Graphics Card(s)
asus gt-520 silent
Monitor(s) Displays
LED viewsonic 24"
Hard Drives
seagate sata 120
wd 2T green
PSU
cool master 600W silent pro (80+bronze)
That one went right over my head, my apology! :confused:

You are correct. It is: mbrfix64
 

My Computer My Computer

At a glance

Windows 7 Home Premium
Computer type
PC/Desktop
Computer Manufacturer/Model Number
An ol' eMachines
OS
Windows 7 Home Premium
Internet Speed
Fine for me...I'm retired!
last one

Here you go...and also, I thought since mbrfix64 is an exe program, i would have type that at comand prompt, rather that the frst64? (unless those too work together in frst64) Anyway's I did what you asked.
I gotta go work now. Thx for all your help....DM
 

Attachments

My Computer My Computer

At a glance

W7 premium 64amd a8-38508G g-skillasus gt-520 silent
OS
W7 premium 64
CPU
amd a8-3850
Motherboard
asus f1-a75v pro
Memory
8G g-skill
Graphics Card(s)
asus gt-520 silent
Monitor(s) Displays
LED viewsonic 24"
Hard Drives
seagate sata 120
wd 2T green
PSU
cool master 600W silent pro (80+bronze)
Got the MBRDump.txt, and will be looking at it.

Also provide the last Fixlog.txt

FRST64 produced it also on the USB flash drive.
 

My Computer My Computer

At a glance

Windows 7 Home Premium
Computer type
PC/Desktop
Computer Manufacturer/Model Number
An ol' eMachines
OS
Windows 7 Home Premium
Internet Speed
Fine for me...I'm retired!
ok

ok didn't catch that....
 

Attachments

My Computer My Computer

At a glance

W7 premium 64amd a8-38508G g-skillasus gt-520 silent
OS
W7 premium 64
CPU
amd a8-3850
Motherboard
asus f1-a75v pro
Memory
8G g-skill
Graphics Card(s)
asus gt-520 silent
Monitor(s) Displays
LED viewsonic 24"
Hard Drives
seagate sata 120
wd 2T green
PSU
cool master 600W silent pro (80+bronze)
There is no malware on the MBR, and the MBR code is also clean.

Good news!

FRST64 got things under control.

Please run RogueKiller once again, and let's see what it shows.
(RogueKiller instructions in Post #2)

Also, provide an update on how the system is running.
 

My Computer My Computer

At a glance

Windows 7 Home Premium
Computer type
PC/Desktop
Computer Manufacturer/Model Number
An ol' eMachines
OS
Windows 7 Home Premium
Internet Speed
Fine for me...I'm retired!
Also, let’s check the Security status with the following:

Download Security Check:
http://screen317.spywareinfoforum.org/
Save to your Desktop.

Double-click SecurityCheck.exe

Follow the onscreen instructions inside the black box.

When done, a Notepad report opens automatically, called: checkup.txt

Please post its contents in your reply.

Note:
SecurityCheck may produce some false warning(s). Please do not take any corrective actions!
 

My Computer My Computer

At a glance

Windows 7 Home Premium
Computer type
PC/Desktop
Computer Manufacturer/Model Number
An ol' eMachines
OS
Windows 7 Home Premium
Internet Speed
Fine for me...I'm retired!
here you are

Was my drive "D" scanned with any of what we did? If not, how would I go about this, as I swap info between master drive "C" and storage device "D"?

Thank you very much. You provided me with alot of help.
 

Attachments

My Computer My Computer

At a glance

W7 premium 64amd a8-38508G g-skillasus gt-520 silent
OS
W7 premium 64
CPU
amd a8-3850
Motherboard
asus f1-a75v pro
Memory
8G g-skill
Graphics Card(s)
asus gt-520 silent
Monitor(s) Displays
LED viewsonic 24"
Hard Drives
seagate sata 120
wd 2T green
PSU
cool master 600W silent pro (80+bronze)
When you go to the Microsoft Security Essentials (MSE) console, click the Settings tab.
On the left side, go to: Advanced
Select: Scan removable drives
 
Next, go to the Home tab
Select: Custom
Press: Scan now

A prompt appears with the drives on the machine.

Select the drives you want MSE to scan, and do a Full scan.

Post back on any issues.
 

My Computer My Computer

At a glance

Windows 7 Home Premium
Computer type
PC/Desktop
Computer Manufacturer/Model Number
An ol' eMachines
OS
Windows 7 Home Premium
Internet Speed
Fine for me...I'm retired!
ok

I will do just that and have a look on my other drive. Say, are you primarily in the virus section, or do you help out elsewhere? I created a post in the "windows updates" section entitled "error code 66A" earlier this morning and have not had a nibble, with 170 views.
 

My Computer My Computer

At a glance

W7 premium 64amd a8-38508G g-skillasus gt-520 silent
OS
W7 premium 64
CPU
amd a8-3850
Motherboard
asus f1-a75v pro
Memory
8G g-skill
Graphics Card(s)
asus gt-520 silent
Monitor(s) Displays
LED viewsonic 24"
Hard Drives
seagate sata 120
wd 2T green
PSU
cool master 600W silent pro (80+bronze)
This old brain has enough to handle in the malware area. It keeps me totally confused!! :D

Hang in there, someone will show up to help.

Don't forget to post a new RogueKiller report. We need to see if it shows any more ZeroAccess.
 

My Computer My Computer

At a glance

Windows 7 Home Premium
Computer type
PC/Desktop
Computer Manufacturer/Model Number
An ol' eMachines
OS
Windows 7 Home Premium
Internet Speed
Fine for me...I'm retired!
missed that

I missed that request for another RK report. You're keeping me busy...;)
I'll do this in the morning when I get off from work...dm
 

My Computer My Computer

At a glance

W7 premium 64amd a8-38508G g-skillasus gt-520 silent
OS
W7 premium 64
CPU
amd a8-3850
Motherboard
asus f1-a75v pro
Memory
8G g-skill
Graphics Card(s)
asus gt-520 silent
Monitor(s) Displays
LED viewsonic 24"
Hard Drives
seagate sata 120
wd 2T green
PSU
cool master 600W silent pro (80+bronze)
I know I said I was going to purchase a plan from malwarebytes, and I intend to do so.
What is your take on that, cottonball? Or do you prefer another? I'll most likely keep MSE
as the primary A/V progy. Thx for your input.

PS, due to my habits and what I download, I pretty much need full time protection on both drives...
 

My Computer My Computer

At a glance

W7 premium 64amd a8-38508G g-skillasus gt-520 silent
OS
W7 premium 64
CPU
amd a8-3850
Motherboard
asus f1-a75v pro
Memory
8G g-skill
Graphics Card(s)
asus gt-520 silent
Monitor(s) Displays
LED viewsonic 24"
Hard Drives
seagate sata 120
wd 2T green
PSU
cool master 600W silent pro (80+bronze)
PS, due to my habits and what I download, I pretty much need full time protection on both drives...
Nothing is going to protect you from bad habits and doubtful/harmful downloads.

Don't expect "FREE" help to continue for your negligence in abiding by the security rules of the net!! :shock:
 

My Computer My Computer

At a glance

Windows 7 Ultimate 32bit SP1Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz4 GBATI Radeon HD 2600 Pro
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
due to my habits and what I download, I pretty much need full time protection on both drives...


You really need to invest in a virtualization program like Sandboxie as well as an anti-executable like EXE Radar Pro . . . . . . . No AV alone will protect you with your usage habits.
 

My Computer My Computer

At a glance

Windows 7 Home Premium x64 SP1
OS
Windows 7 Home Premium x64 SP1
Back
Top