New Virus?

Ginmill

New member
Local time
7:36 PM
Messages
2
Got a message that I was running low on disk space. So I tried to run ccleaner and it looked like it locked up on some strange files at 33%. Tried to look at winderstat and that locked up too. Went back to ccleaner and it stopped at 33% again but looked where it locked up. c:\windows\temp inside there I had over 300,000 files with various sizes. Highlighted them and deleted it was over 200 gb of space they were taking up. The files started off with 7zip_open_ then with a 15 digit number after that. I check to see if I had 7zip installed but I didn't. After a day went by the files never came back. On the second day after removing the files 6 more appeared with the 7zip_open_ with about 15 digits after it. Ive ran malwarebytes, mse, and vipre av none of which found anything. Now I have been getting internet issues ie very slow downloading of youtube videos and complete drop from the internet. Oh also I have ran hijackthis and check a few places and everything is fine there too. Anyone know what else I can do?
 
Last edited:

My Computer

OS
windows 7 ultimate 64bit
CPU
Q8200
Motherboard
nvidia 790i ultra
Memory
8 gb
Graphics Card(s)
nvidia 9600 gt
Sound Card
none
Monitor(s) Displays
HP w2207
Hard Drives
500 gb wd
PSU
850 watt
Case
coolermaster 870?
Cooling
coolermaster
Got a message that I was running low on disk space. So I tried to run ccleaner and it looked like it locked up on some strange files at 33%. Tried to look at winderstat and that locked up too. Went back to ccleaner and it stopped at 33% again but looked where it locked up. c:\windows\temp inside there I had over 300,000 files with various sizes. Highlighted them and deleted it was over 200 gb of space they were taking up. The files started off with 7zip_open_ then with a 15 digit number after that. I check to see if I had 7zip installed but I didn't. After a day went by the files never came back. On the second day after removing the files 6 more appeared with the 7zip_open_ with about 15 digits after it. Ive ran malwarebytes, mse, and vipre av none of which found anything. Now I have been getting internet issues ie very slow downloading of youtube videos and complete drop from the internet. Oh also I have ran hijackthis and check a few places and everything is fine there too. Anyone know what else I can do?
Ginmill,
You might care to run SUPERAntiSpyware Online Safe Scan to see if it flushes anything out.
SUPERAntiSpyware.com - Online Scanner
 

My Computer

Computer Manufacturer/Model Number
LAPTOP. HP Pavilion dv7-4010TX .
OS
Win 7 Ultimate 64-bit. SP1.
CPU
Intel i7 -720QM.[1.6GHz Turbo Boost 2.8GHz. 6MB Cache.]
Memory
8 DDR 3 RAM. 1066MHZ
Graphics Card(s)
ATI 1024 MB. DDR3. Radeon HD5650
Monitor(s) Displays
17.3" High Definition Brightview LCD. LED Backlit.
Screen Resolution
1600 x 900.
Hard Drives
640GB
Case
Laptop / notebook.
Mouse
Logitech Anywhere mouse. MX.
Internet Speed
ADSL [ but too slow ]
That and download another anti-virus just to make sure Vipre isn't missing anything. MSE works well at detection, so does Avast, either should confirm no viruses. G-DATA is the best according to av-comparatives but it costs $.
 

My Computer

Computer Manufacturer/Model Number
Apple Macbook Pro (April 2009)
OS
W7 Ult. x64 | OS X
CPU
Intel Mobile Core 2 Duo 2.93Ghz [T9800 Penryn]
Motherboard
NVIDIA nForce 730i Rev. B1 [Mac-F2268EC8 (U2E1)]
Memory
4096MB Samsung DDR3 Dual Channel [PC3-8500F 1066Mhz]
Graphics Card(s)
NVIDIA GeForce 9600M GT 512MB [G96M Rev. C1]
Sound Card
SB X-Fi Surround 5.1 USB | Onboard Realtek (Disabled)
Monitor(s) Displays
Acer x223wbd 22" | Apple Anti-Glare 17" (Disabled)
Screen Resolution
{Current} 1440x900 {Acer} 1680x1050 {Apple} 1920x1200
Hard Drives
{Internal}
Seagate Momentus 320GB 2.5" 7200RPM [ST9320421AS]

{Externals}
LaCie 320GB USB 2.0 HDD [301284UR]
LaCie 750GB USB 2.0 FW400 eSATA HDD [301314U]
LaCie 1TB USB 2.0 HDD [301304UR]
PSU
Magsafe
Case
Aluminum/Unibody (MBP52)
Cooling
2 x 6000 RPM Fans
Keyboard
Logitech G-15v2 [PN 920-000379]
Mouse
Logitech G-9 [PN 910-000338]
Internet Speed
12Mbps/2.5Mbps w/ 24Mbps Speed Boost [Comcast]
Other Info
Logitech X-540 Speakers [PN 970223-0122]
Sennheiser PC-151 Headset
Malwarebytes' might work better than HT Pro but it's probably a toss up.
 

My Computer

Computer Manufacturer/Model Number
Apple Macbook Pro (April 2009)
OS
W7 Ult. x64 | OS X
CPU
Intel Mobile Core 2 Duo 2.93Ghz [T9800 Penryn]
Motherboard
NVIDIA nForce 730i Rev. B1 [Mac-F2268EC8 (U2E1)]
Memory
4096MB Samsung DDR3 Dual Channel [PC3-8500F 1066Mhz]
Graphics Card(s)
NVIDIA GeForce 9600M GT 512MB [G96M Rev. C1]
Sound Card
SB X-Fi Surround 5.1 USB | Onboard Realtek (Disabled)
Monitor(s) Displays
Acer x223wbd 22" | Apple Anti-Glare 17" (Disabled)
Screen Resolution
{Current} 1440x900 {Acer} 1680x1050 {Apple} 1920x1200
Hard Drives
{Internal}
Seagate Momentus 320GB 2.5" 7200RPM [ST9320421AS]

{Externals}
LaCie 320GB USB 2.0 HDD [301284UR]
LaCie 750GB USB 2.0 FW400 eSATA HDD [301314U]
LaCie 1TB USB 2.0 HDD [301304UR]
PSU
Magsafe
Case
Aluminum/Unibody (MBP52)
Cooling
2 x 6000 RPM Fans
Keyboard
Logitech G-15v2 [PN 920-000379]
Mouse
Logitech G-9 [PN 910-000338]
Internet Speed
12Mbps/2.5Mbps w/ 24Mbps Speed Boost [Comcast]
Other Info
Logitech X-540 Speakers [PN 970223-0122]
Sennheiser PC-151 Headset
They have already tried Malwarebytes.

Also, a-squared Free has a much better detection rate than Malwarebytes but its process (<1MB RAM) is always running even with the program shut down.
 

My Computer

OS
Arch Linux 64-bit
Hi, Ginmill.

You may want to start with a temp file cleaner. I suggest that you download ATF Cleaner by Atribune from ATF-Cleaner.exe - www.atribune.org . Save it to your Desktop.

Run ATF Cleaner
  • Double-click ATF-Cleaner.exe to run the program.
  • Click Select All found at the bottom of the list.
  • Click the Empty Selected button.
  • Click Exit on the Main menu to close the program.
  • Shutdown/restart the computer.

Next, I believe an online scan is in order. Instructions follow for both ESET and F-Secure. I suggest one or both.

Please go to Free ESET Online Antivirus Scanner to run an on-line scan from ESET.
  • Note: It is easiest if you use Internet explorer for this scan. (If you use an alternate browser, it will be necessary to download the ESET Smart Installer)
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Click Start
  • Make sure that the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • Use notepad to open the logfile located at C:\Program Files\Eset\Eset Online Scanner\log.txt
  • Copy and paste that log as a reply to this topic and also let me know how things are now.

Please go here and run an on-line scan with the F-Secure scanner .

  • Use IE (Internet Explorer), accept the license terms, and allow the Active-X controls to load.
  • Click Full System Scan and allow the components to download and the scan to complete.2
  • If malware is found during the scan, check Submit samples to F-Secure and Automatic cleaning.
  • When the scan has finished, click the Show Report button and copy and paste the entire report in your next reply.
Please let us know how you make out.
 

My Computer

OS
Windows 7 & Windows Vista Ultimate
A little spelunking of the files themselves might point to the cause. Someone the other day had some program he got that created something like a single 260 gig log file inthe temp folder.

SO it may not be virus related at all, just some out of control program you have onyour machine on purpose.
If a huge number of files all seem to have the same or very similar names, opening them in a binary editor or using "strings" on the file or even googling the name might point to the culprit.

Using the resource monitor on the task manager/performance tab can also catch programs that are writing to files frequently, though you may have to leve it open for a while watching it closely to catch the event in progress...
 

My Computer

Computer Manufacturer/Model Number
Scratch built
OS
Windows 7 x64 Ultimate
CPU
i7 960
Motherboard
Asus P6X58D
Memory
12 Gig Corsair Dominator
Graphics Card(s)
Nvidia 480
Sound Card
Maudio Delta 44 + breakout box
Monitor(s) Displays
Dell UltraSharp U2410 24in and Samsung 21 dual monitors
Screen Resolution
1920x1200 and 1280x1024
Hard Drives
Primary: Intel X-25M G2 160G SSD
Secondary: Segate baracuda 1.0 TB
HDs in AHCI mode.
PSU
Corasair TX850
Case
Cooler Master HAF
Cooling
Corsair H50
Keyboard
Logitech G15 + N52 game pad
Mouse
Logitech MX518
Internet Speed
15kbs down 4.5kbps up
Other Info
WEI 7.6
CPU & RAM 7.6
Graphics 7.9
Hard disk 7.7
Back
Top