is this a virus? vbc.exe?

Maxheadroom

New member
Power User
VIP
Local time
1:21 PM
Messages
246
MSE has started to pick this file up in the last few days and asks me to send a sample off each time my pc starts because its not recognised.

C:\Users\MY PC \AppData\Local\Temp\temp_fMKebUffFwkUuXw\vbc.exe

ive looked about for info on this file but there seems to be a lot of disagreement on wether this a virus or not,
i find it odd that a MS virus scanner wouldnt recognise a file that is supposed to be a process belonging to Microsoft Visual Studio
 

My Computer My Computer

Computer Manufacturer/Model Number
home built
OS
windows 7 64bit build 7600
CPU
Intel I7 920
Motherboard
ASUS P6T Deluxe V2
Memory
Corsair 6GB (3x2GB) 1600MHz Triple Channel i7
Graphics Card(s)
XFX RADEON HD 5870
Sound Card
Creative Xfi Elite pro
Monitor(s) Displays
Hyundai W240D 24" Samsung Syncmaster 930
Screen Resolution
1920x1200 and 1280x1024
Hard Drives
WD Velociraptor 150gb
Western Digital WD7502ABYS 750GB Raid Edition
PSU
Corsair 850W TX Series PSU
Case
Coolermaster HAF 932 Full Tower
Cooling
Noctua NH-U12P
Keyboard
logitech G15 orange
Mouse
logitech mx revolution
Internet Speed
13mb
As you've already discovered, the legitimate vbc.exe is a file associated with Visual Studio/Visual Basic. The file is usually found in C:\Windows\Microsoft.NET\Framework\v2.0.50727 folder. If you find it anywhere else, please note that vbc.exe could be a virus, trojan, worm, or spyware.

What is Vbc.exe - Fix vbc.exe Errors Microsoft Corporation

Since MSE is questioning its authenticity (probably because it's not following the usual file path) you could try renaming the .exe extension to something else, like .xxe just as an example. Run your computer to see if anything breaks. If something stops working you can always change the extension back to the original .exe.

Rename a file

You could also submit the file to VirusTotal for another opinion. FWIW, the vbc.exe file on my machine (7 Pro x64) is in the folder referenced above.

https://www.virustotal.com/
 

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
Sony Vaio VPCEB47GM Laptop
OS
Win 7 Pro 64-bit
CPU
Intel i5 2.4 Ghz
Memory
8GB DDR3
Graphics Card(s)
Intel HD 3000
Sound Card
IDT High Definition
Monitor(s) Displays
15.6 WGXA Anti-Glare LED
Screen Resolution
1280x800
Hard Drives
640Gb 7200rpm
Antivirus
MSE
Browser
Opera (primary) with IE9 backup
thanks marsmimar i have renamed the file like youve suggested but if this is a virus its not as simple as just renaming the executive file is it?

i had already done a virustotal scan but it came up with zero out of 43 but it also says its been voted 36 to 6 as being harmful also says the file name is usenet.exe
some comments

This is not a malware : description..............: Visual Basic Command Line Compiler

This file is used by malware (especially Microsoft .NET RAT) to compile and load payload.

----


Indeed. This doesn't show up as malicious in any AV but malware does detect this... This is a threat, look through your windows startup and look for any suspicious file, which you will most likely find.
----

listed in registry as sn0zZ's Bot

The following files have been added to the system:


%APPDATA%\winlogon.exe


%TEMP%\data.dat

%TEMP%\TWQI3P64Z4.exe


The following registry elements have been created:


HKEY_CURRENT_USER\SOFTWARE\VB AND VBA PROGRAM SETTINGS\


HKEY_CURRENT_USER\SOFTWARE\VB AND VBA PROGRAM SETTINGS\INSTALL\

HKEY_CURRENT_USER\SOFTWARE\VB AND VBA PROGRAM SETTINGS\INSTALL\DATE\

HKEY_CURRENT_USER\SOFTWARE\VB AND VBA PROGRAM SETTINGS\SRVID\

HKEY_CURRENT_USER\SOFTWARE\VB AND VBA PROGRAM SETTINGS\SRVID\ID\


The following registry elements have been changed:


HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\PUEDBRM = "%APPDATA%\winlogon.exe"


HKEY_CURRENT_USER\SOFTWARE\VB AND VBA PROGRAM SETTINGS\INSTALL\DATE\S62KNP0C3G = June 10, 2010

HKEY_CURRENT_USER\SOFTWARE\VB AND VBA PROGRAM SETTINGS\SRVID\ID\S62KNP0C3G = sn0zZ's Bot

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet\SERVICES\SHAREDACCESS\PARAMETERS\FIREWALLPOLICY\STANDARDPROFILE\DONOTALLOWEXCEPTIONS = 0

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet\SERVICES\SHAREDACCESS\PARAMETERS\FIREWALLPOLICY\STANDARDPROFILE\AUTHORIZEDAPPLICATIONS\LIST\%TEMP%\TWQI3P64Z4.EXE = %TEMP%\TWQI3P64Z4.exe:*:Enabled:Windows Messanger

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet\SERVICES\SHAREDACCESS\PARAMETERS\FIREWALLPOLICY\STANDARDPROFILE\AUTHORIZEDAPPLICATIONS\LIST\%WINDIR%\MICROSOFT.NET\FRAMEWORK\V2.0.50727\VBC.EXE = %WINDIR%\Microsoft.NET\Framework\v2.0.50727\vbc.exe:*:Enabled:Windows Messanger
#malware

----


ive checked my startup list it all looks normal except for 2 entries

startup item
371384756 and 1827221171

manufacturer
both unknown

command
C:\users\MY PC\Appdata\local\temp\tmp59FB.tmp.exe and
C:\users\MY PC\Appdata\local\temp\tmpC480.tmp.exe

location
both HKCU\SOFTWARE\Microsofft\Windows\CurrentVersion\Run

i have no idea what these are as it gives no information


it seems i should be concerned over this file even though none of the scanners at virustool has picked it up
 

My Computer My Computer

Computer Manufacturer/Model Number
home built
OS
windows 7 64bit build 7600
CPU
Intel I7 920
Motherboard
ASUS P6T Deluxe V2
Memory
Corsair 6GB (3x2GB) 1600MHz Triple Channel i7
Graphics Card(s)
XFX RADEON HD 5870
Sound Card
Creative Xfi Elite pro
Monitor(s) Displays
Hyundai W240D 24" Samsung Syncmaster 930
Screen Resolution
1920x1200 and 1280x1024
Hard Drives
WD Velociraptor 150gb
Western Digital WD7502ABYS 750GB Raid Edition
PSU
Corsair 850W TX Series PSU
Case
Coolermaster HAF 932 Full Tower
Cooling
Noctua NH-U12P
Keyboard
logitech G15 orange
Mouse
logitech mx revolution
Internet Speed
13mb

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Home made Desktop
OS
Windows 10 Pro. 64/ version 1709 Windows 7 Pro/64
CPU
Intel i7-6800K @ 4.3
Motherboard
ASUS X-99 Deluxe II
Memory
Corsair Platinum 16 gig @2400
Graphics Card(s)
EVGA GTX 1070 OC
Monitor(s) Displays
Asus 27" LED LCD/VE278Q
Screen Resolution
1920-1080 or 1280-720 HDMI
Hard Drives
INTEL SSD 730-240 Gb Sata 3.0/
PSU
EVGA Platium 1200W
Case
Phanteks Luxe Tempered Glass 8 fans/ one radiator
Cooling
XSPC/ Water Cooled CPU
Keyboard
Das 4 Professional
Mouse
Logitech M705/MX Anywhere 2-S
Internet Speed
100 mbits
Antivirus
Microsoft Security Essentials/ Malwarebytes Premium 3.0/ SAS
Browser
I.E. 11 default/Firefox/ ISP Time Warner Cable/Spectrum
Other Info
LG BluRay Burner/
Sound system-KLipsch-THX/
Icy Dock ssd Hot Swap bays.
thank you Layback bear, i ran that but it didnt pick up anything, when my pc restarted MSE once again picked up the vbc.exe in AppData\Local\Temp which i figure that it has recreated its self as i had renamed the .exe
having a look in the temp folder ive found another 12 instances of vbc.exe all in folders with names like temp_tFPKODjsvYKwDpI, i went through and renamed all the .exe's
restarted my pc and rechecked the temp folder and found 2 more newley created folders both containing vbc.exe.
 

My Computer My Computer

Computer Manufacturer/Model Number
home built
OS
windows 7 64bit build 7600
CPU
Intel I7 920
Motherboard
ASUS P6T Deluxe V2
Memory
Corsair 6GB (3x2GB) 1600MHz Triple Channel i7
Graphics Card(s)
XFX RADEON HD 5870
Sound Card
Creative Xfi Elite pro
Monitor(s) Displays
Hyundai W240D 24" Samsung Syncmaster 930
Screen Resolution
1920x1200 and 1280x1024
Hard Drives
WD Velociraptor 150gb
Western Digital WD7502ABYS 750GB Raid Edition
PSU
Corsair 850W TX Series PSU
Case
Coolermaster HAF 932 Full Tower
Cooling
Noctua NH-U12P
Keyboard
logitech G15 orange
Mouse
logitech mx revolution
Internet Speed
13mb
In my opinion I wouldn't worry about them. I have several all the time. Windows Defender Offline indicated no problem I would believe it. vbc.exe can be a virus but not all vbc.exe are a virus.
Happy computing.
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Home made Desktop
OS
Windows 10 Pro. 64/ version 1709 Windows 7 Pro/64
CPU
Intel i7-6800K @ 4.3
Motherboard
ASUS X-99 Deluxe II
Memory
Corsair Platinum 16 gig @2400
Graphics Card(s)
EVGA GTX 1070 OC
Monitor(s) Displays
Asus 27" LED LCD/VE278Q
Screen Resolution
1920-1080 or 1280-720 HDMI
Hard Drives
INTEL SSD 730-240 Gb Sata 3.0/
PSU
EVGA Platium 1200W
Case
Phanteks Luxe Tempered Glass 8 fans/ one radiator
Cooling
XSPC/ Water Cooled CPU
Keyboard
Das 4 Professional
Mouse
Logitech M705/MX Anywhere 2-S
Internet Speed
100 mbits
Antivirus
Microsoft Security Essentials/ Malwarebytes Premium 3.0/ SAS
Browser
I.E. 11 default/Firefox/ ISP Time Warner Cable/Spectrum
Other Info
LG BluRay Burner/
Sound system-KLipsch-THX/
Icy Dock ssd Hot Swap bays.
All the traces you've told here indicate that it IS A VIRUS.

First off, there is a legitimate file in the system named "vbc.exe", it's the Visual Basic command line compiler, and is located under c:\windows\microsft.net\someotherfolder. That said, normally when you see exe processes spawning on it's own on strange locations, you have all reasons to doubt.

The folders are located under TEMP, a location normally reserved for temporary data files, or maybe for temporary programs that delete themselves afterwards. The folder name is also strange, probably random, which seems suspicious too. Moreover, if it's running on its own at system startup without your knowledge, and using the very same filename of a well known system executable, you have all reasons to doubt.

Look at msconfig from where it autoruns, delete those and all instances you find of the exe. And just in case, enable your firewall to block outgoing connections. This time I think MSE got it right and you're effectively infected.
 

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
Toshiba Sattelite A665-S6092
OS
Windows 7 Ultimate x64
CPU
Intel Core i7-740QM
Memory
8 GB DDR3
Graphics Card(s)
NVIDIA GeForce 330GT
Screen Resolution
1366x768
Hard Drives
Samsung 840 SSD 500GB
1TB USB3 external HD
Cooling
Coolermaster Notepal U3 notebook cooling pad
Internet Speed
3mbps ASDL
Antivirus
ClamWin 0.98.7
Browser
Opera 12.17 x86 (main), Firefox 38 (sec), IE11 (last resort)
I've asked for one of the Forum's malware experts to take a look and give an opinion. I trust her judgement completely.
 

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
Sony Vaio VPCEB47GM Laptop
OS
Win 7 Pro 64-bit
CPU
Intel i5 2.4 Ghz
Memory
8GB DDR3
Graphics Card(s)
Intel HD 3000
Sound Card
IDT High Definition
Monitor(s) Displays
15.6 WGXA Anti-Glare LED
Screen Resolution
1280x800
Hard Drives
640Gb 7200rpm
Antivirus
MSE
Browser
Opera (primary) with IE9 backup
any news from the malware expert marsmimar?
 

My Computer My Computer

Computer Manufacturer/Model Number
home built
OS
windows 7 64bit build 7600
CPU
Intel I7 920
Motherboard
ASUS P6T Deluxe V2
Memory
Corsair 6GB (3x2GB) 1600MHz Triple Channel i7
Graphics Card(s)
XFX RADEON HD 5870
Sound Card
Creative Xfi Elite pro
Monitor(s) Displays
Hyundai W240D 24" Samsung Syncmaster 930
Screen Resolution
1920x1200 and 1280x1024
Hard Drives
WD Velociraptor 150gb
Western Digital WD7502ABYS 750GB Raid Edition
PSU
Corsair 850W TX Series PSU
Case
Coolermaster HAF 932 Full Tower
Cooling
Noctua NH-U12P
Keyboard
logitech G15 orange
Mouse
logitech mx revolution
Internet Speed
13mb
There's a few hours time difference so I'm hoping we'll hear something real soon.
 

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
Sony Vaio VPCEB47GM Laptop
OS
Win 7 Pro 64-bit
CPU
Intel i5 2.4 Ghz
Memory
8GB DDR3
Graphics Card(s)
Intel HD 3000
Sound Card
IDT High Definition
Monitor(s) Displays
15.6 WGXA Anti-Glare LED
Screen Resolution
1280x800
Hard Drives
640Gb 7200rpm
Antivirus
MSE
Browser
Opera (primary) with IE9 backup
ok thanks
 

My Computer My Computer

Computer Manufacturer/Model Number
home built
OS
windows 7 64bit build 7600
CPU
Intel I7 920
Motherboard
ASUS P6T Deluxe V2
Memory
Corsair 6GB (3x2GB) 1600MHz Triple Channel i7
Graphics Card(s)
XFX RADEON HD 5870
Sound Card
Creative Xfi Elite pro
Monitor(s) Displays
Hyundai W240D 24" Samsung Syncmaster 930
Screen Resolution
1920x1200 and 1280x1024
Hard Drives
WD Velociraptor 150gb
Western Digital WD7502ABYS 750GB Raid Edition
PSU
Corsair 850W TX Series PSU
Case
Coolermaster HAF 932 Full Tower
Cooling
Noctua NH-U12P
Keyboard
logitech G15 orange
Mouse
logitech mx revolution
Internet Speed
13mb
Max, yes you are in fected ... read about the infection here: Generic.bfr!09E9EAAFB04E | Virus Profile & Definition | McAfee Inc.

You are going to have to use a known 'clean' computer to change all your passwords. Do not use the infected one.

Now, download TFC by Old Timer TFC - Temp File Cleaner by OldTimer - Geeks to Go Forums and save it to your desktop.
Save any unsaved work. TFC will close ALL open programs including your browser!
Double-click on TFC.exe to run it. If you are using Vista/Windows 7 right-click on the file and choose Run As Administrator.
Click the Start button to begin the cleaning process and let it run uninterrupted to completion.
Important! If TFC prompts you to reboot, please do so immediately. If not prompted, manually reboot the machine anyway to ensure a complete clean.

TFC (Temp File Cleaner) will clear out all temp folders for all user accounts (temp, IE temp, java, FF, Opera, Chrome, Safari), including Administrator, All Users, LocalService, NetworkService, and any other accounts in the user folder. It also cleans out the %systemroot%\temp folder and checks for .tmp files in the %systemdrive% root folder, %systemroot%, and the system32 folder (both 32bit and 64bit on 64bit OSs). It shows the amount removed for each location found (in bytes) and the total removed (in MB). Before running, it will stop Explorer and all other running apps. When finished, if a reboot is required the user must reboot to finish clearing any in-use temp files.
TFC only cleans temp folders. TFC will not clean URL history, prefetch, or cookies. Depending on how often someone cleans their temp folders, their system hardware, and how many accounts are present, it can take anywhere from a few seconds to a minute or more. TFC will completely clear all temp files where other temp file cleaners may fail. TFC requires a reboot immediately after running. Be sure to save any unsaved work before running TFC.

After rebooting, let's flush the bad DNS cache and restore MS's Hosts file:
Copy and paste these lines in Note pad.

@Echo on
pushd\windows\system32\drivers\etc
attrib -h -s -r hosts
echo 127.0.0.1 localhost>HOSTS
attrib +r +h +s hosts
popd
ipconfig /release
ipconfig /renew
ipconfig /flushdns
netsh winsock reset all
netsh int ip reset all
shutdown -r -t 1
del %0


Save as flush.bat to your desktop.
Double click on the flush.bat file to run it.Vista and Windows 7... right click the .bat file and choose to run as Administrator. *Your computer will reboot itself*.

Now, I'd like you to scan your machine with ESET OnlineScan
  1. Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  2. Click the
    esetOnline.png
    button.
  3. For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    1. Click on
      esetSmartInstall.png
      to download the ESET Smart Installer. Save it to your desktop.
    2. Double click on the
      esetSmartInstallDesktopIcon.png
      icon on your desktop.
  4. Check
    esetAcceptTerms.png
  5. Click the
    esetStart.png
    button.
  6. Accept any security warnings from your browser.
  7. Check
    esetScanArchives.png
  8. Push the Start button.
  9. ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  10. When the scan completes, push
    esetListThreats.png
  11. Push
    esetExport.png
    , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
  12. Push the
    esetBack.png
    button.
  13. Push
    esetFinish.png
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
thank you Jacee i will do this asap, can i just ask
you mention changing my passwords does it matter if the clean computer is networked and do i need to change all my passwords as this virus may have copied them?
 

My Computer My Computer

Computer Manufacturer/Model Number
home built
OS
windows 7 64bit build 7600
CPU
Intel I7 920
Motherboard
ASUS P6T Deluxe V2
Memory
Corsair 6GB (3x2GB) 1600MHz Triple Channel i7
Graphics Card(s)
XFX RADEON HD 5870
Sound Card
Creative Xfi Elite pro
Monitor(s) Displays
Hyundai W240D 24" Samsung Syncmaster 930
Screen Resolution
1920x1200 and 1280x1024
Hard Drives
WD Velociraptor 150gb
Western Digital WD7502ABYS 750GB Raid Edition
PSU
Corsair 850W TX Series PSU
Case
Coolermaster HAF 932 Full Tower
Cooling
Noctua NH-U12P
Keyboard
logitech G15 orange
Mouse
logitech mx revolution
Internet Speed
13mb
Thank you Jacce for coming to the rescue. I will watch and learn.
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Home made Desktop
OS
Windows 10 Pro. 64/ version 1709 Windows 7 Pro/64
CPU
Intel i7-6800K @ 4.3
Motherboard
ASUS X-99 Deluxe II
Memory
Corsair Platinum 16 gig @2400
Graphics Card(s)
EVGA GTX 1070 OC
Monitor(s) Displays
Asus 27" LED LCD/VE278Q
Screen Resolution
1920-1080 or 1280-720 HDMI
Hard Drives
INTEL SSD 730-240 Gb Sata 3.0/
PSU
EVGA Platium 1200W
Case
Phanteks Luxe Tempered Glass 8 fans/ one radiator
Cooling
XSPC/ Water Cooled CPU
Keyboard
Das 4 Professional
Mouse
Logitech M705/MX Anywhere 2-S
Internet Speed
100 mbits
Antivirus
Microsoft Security Essentials/ Malwarebytes Premium 3.0/ SAS
Browser
I.E. 11 default/Firefox/ ISP Time Warner Cable/Spectrum
Other Info
LG BluRay Burner/
Sound system-KLipsch-THX/
Icy Dock ssd Hot Swap bays.
thank you Jacee i will do this asap, can i just ask
you mention changing my passwords does it matter if the clean computer is networked and do i need to change all my passwords as this virus may have copied them?
You have a 'trojan' ... it's better to change all passwords that may have been compromised, rather than be sorry later.
If the 'networked' computer is clean, then you can use it.
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
C:\Users\KandC\Downloads\SoftonicDownloader_for_windows-live-movie-maker.exe Win32/SoftonicDownloader.D application cleaned by deleting - quarantine

F:\FireFox\DTLite4454-0315.exe Win32/OpenCandy application cleaned by deleting - quarantined

J:\Audio\audio.rar probably a variant of Win32/TrojanProxy.Agent.IIIVZSY trojan deleted - quarantined

J:\Galaxy S2\Rom Flashing\Roms\DlevROM2_3.0_KI4.zip multiple threats deleted - quarantined

J:\Galaxy S2\Rom Flashing\Roms\DlevROM2_3.1_KI4(1).zip Android/MTracker.A application deleted - quarantined

J:\Galaxy S2\Rom Flashing\Roms\Hyperdroid_Androidmeda-XDXD9-signed.zip a variant of Android/MTracker.A application deleted - quarantined

J:\Galaxy S2\Rom Flashing\Roms\DlevROM 1.3\DlevROM2_1.3.zip Android/MTracker.A application deleted - quarantined

J:\Galaxy S2\Rom Flashing\SuperOneClickv1.9.5\Exploits\psneuter Android/Exploit.Lotoor.AK trojan cleaned by deleting - quarantined

J:\STUFF\GAZ'S\from desktop\Rom Flashing\DlevROM 1.3\DlevROM2_1.3.zip Android/MTracker.A application deleted - quarantined

J:\STUFF\GAZ'S\from desktop\Rom Flashing\SuperOneClickv1.9.5\Exploits\psneuter Android/Exploit.Lotoor.AK trojan cleaned by deleting - quarantined
 

My Computer My Computer

Computer Manufacturer/Model Number
home built
OS
windows 7 64bit build 7600
CPU
Intel I7 920
Motherboard
ASUS P6T Deluxe V2
Memory
Corsair 6GB (3x2GB) 1600MHz Triple Channel i7
Graphics Card(s)
XFX RADEON HD 5870
Sound Card
Creative Xfi Elite pro
Monitor(s) Displays
Hyundai W240D 24" Samsung Syncmaster 930
Screen Resolution
1920x1200 and 1280x1024
Hard Drives
WD Velociraptor 150gb
Western Digital WD7502ABYS 750GB Raid Edition
PSU
Corsair 850W TX Series PSU
Case
Coolermaster HAF 932 Full Tower
Cooling
Noctua NH-U12P
Keyboard
logitech G15 orange
Mouse
logitech mx revolution
Internet Speed
13mb
after i restarted the pc theres no more MSE warnings and no dodgy looking files in the temp folder, thank you Jacee looks like its gone.

Do you class ESET/nod32 as a better virus scanner than MSE and is it possible to use both or not necessary?
 

My Computer My Computer

Computer Manufacturer/Model Number
home built
OS
windows 7 64bit build 7600
CPU
Intel I7 920
Motherboard
ASUS P6T Deluxe V2
Memory
Corsair 6GB (3x2GB) 1600MHz Triple Channel i7
Graphics Card(s)
XFX RADEON HD 5870
Sound Card
Creative Xfi Elite pro
Monitor(s) Displays
Hyundai W240D 24" Samsung Syncmaster 930
Screen Resolution
1920x1200 and 1280x1024
Hard Drives
WD Velociraptor 150gb
Western Digital WD7502ABYS 750GB Raid Edition
PSU
Corsair 850W TX Series PSU
Case
Coolermaster HAF 932 Full Tower
Cooling
Noctua NH-U12P
Keyboard
logitech G15 orange
Mouse
logitech mx revolution
Internet Speed
13mb

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
thanks for the help Jacee
 

My Computer My Computer

Computer Manufacturer/Model Number
home built
OS
windows 7 64bit build 7600
CPU
Intel I7 920
Motherboard
ASUS P6T Deluxe V2
Memory
Corsair 6GB (3x2GB) 1600MHz Triple Channel i7
Graphics Card(s)
XFX RADEON HD 5870
Sound Card
Creative Xfi Elite pro
Monitor(s) Displays
Hyundai W240D 24" Samsung Syncmaster 930
Screen Resolution
1920x1200 and 1280x1024
Hard Drives
WD Velociraptor 150gb
Western Digital WD7502ABYS 750GB Raid Edition
PSU
Corsair 850W TX Series PSU
Case
Coolermaster HAF 932 Full Tower
Cooling
Noctua NH-U12P
Keyboard
logitech G15 orange
Mouse
logitech mx revolution
Internet Speed
13mb
Back
Top