Solved suspect a virus need help removing....please

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
ASUS
OS
Microsoft Windows 7 Home Premium 64-bit 7601 Multiprocessor Free Service Pack 1
CPU
AMD C-60 APU with Radeon(tm) HD Graphics
Motherboard
ASUSTeK COMPUTER INC. X501U
Memory
4.00 GB
Graphics Card(s)
AMD Radeon HD 6290 Graphics
Sound Card
(1) AMD High Definition Audio Device (2) Realtek High Defi
Screen Resolution
1366 x 768 x 32 bits (4294967296 colors) @ 60 Hz
Hard Drives
Hitachi HTS545050A7E380 SATA Disk Device
Antivirus
Comodo CIS & FW, SecureAplus App Whitelisting, Threatfire
Browser
Cyberfox 64bit, Opera 64bit, Airfox
Other Info
Spy-The-Spy, HitmanPro.Alert, Norton Connect Safe, MJRegWatcher, BitDefender TrafficLight, Voodoo Shield, Zemana AntiMalware
Thx Callender! I will wait for more advice......
 
Last edited:

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
Toshiba Satellite c855-s5214
OS
windows 7 professional 64 bit Version 6.1.7601 Service Pack 1 Build 7601
CPU
Intel(R) Pentium(R) CPU B970 @ 2.30GHz, 2300 Mhz, 2 cores
Motherboard
Toshiba Portable BIOS Insyde Corp Version 1.60 Date 4/20/12
Memory
8Gb
Graphics Card(s)
Intel HD Graphics Driver Vers 9.17.10.3347 Date 10/31/20
Hard Drives
SanDisk Extreme Pro SSD 480 Gb (approx. 381gb free)
Firmware Version X21200RL
Migrated and Installed 4/3/2015
Antivirus
BitDefender AntiVirus Free Edition Version 1.0.21.1099
Browser
Internet Explorer 11 update version 11.0.16
Other Info
Additional Systems:

Samsung NP-QX410 Laptop Windows 7 Home Premium SP1
Samsung 850 EVO 250G 4G ram
Avast! Free 2015

Toshiba A205-S7468 Laptop Windows 7 Ultimate
WD 320G HDD 4G ram
AVG free 2015
@ Jacee

Please delete:
C:\Windows\SysWOW64\Adobe\Shockwave 12\gt.exe found by Eset ---->Win32/Bundled.Toolbar.Google.D potentially unsafe application


Will do!
 

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
Toshiba Satellite c855-s5214
OS
windows 7 professional 64 bit Version 6.1.7601 Service Pack 1 Build 7601
CPU
Intel(R) Pentium(R) CPU B970 @ 2.30GHz, 2300 Mhz, 2 cores
Motherboard
Toshiba Portable BIOS Insyde Corp Version 1.60 Date 4/20/12
Memory
8Gb
Graphics Card(s)
Intel HD Graphics Driver Vers 9.17.10.3347 Date 10/31/20
Hard Drives
SanDisk Extreme Pro SSD 480 Gb (approx. 381gb free)
Firmware Version X21200RL
Migrated and Installed 4/3/2015
Antivirus
BitDefender AntiVirus Free Edition Version 1.0.21.1099
Browser
Internet Explorer 11 update version 11.0.16
Other Info
Additional Systems:

Samsung NP-QX410 Laptop Windows 7 Home Premium SP1
Samsung 850 EVO 250G 4G ram
Avast! Free 2015

Toshiba A205-S7468 Laptop Windows 7 Ultimate
WD 320G HDD 4G ram
AVG free 2015

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
Toshiba Satellite c855-s5214
OS
windows 7 professional 64 bit Version 6.1.7601 Service Pack 1 Build 7601
CPU
Intel(R) Pentium(R) CPU B970 @ 2.30GHz, 2300 Mhz, 2 cores
Motherboard
Toshiba Portable BIOS Insyde Corp Version 1.60 Date 4/20/12
Memory
8Gb
Graphics Card(s)
Intel HD Graphics Driver Vers 9.17.10.3347 Date 10/31/20
Hard Drives
SanDisk Extreme Pro SSD 480 Gb (approx. 381gb free)
Firmware Version X21200RL
Migrated and Installed 4/3/2015
Antivirus
BitDefender AntiVirus Free Edition Version 1.0.21.1099
Browser
Internet Explorer 11 update version 11.0.16
Other Info
Additional Systems:

Samsung NP-QX410 Laptop Windows 7 Home Premium SP1
Samsung 850 EVO 250G 4G ram
Avast! Free 2015

Toshiba A205-S7468 Laptop Windows 7 Ultimate
WD 320G HDD 4G ram
AVG free 2015
@ Jacee @ Callender

Thx for all the advice and help!

As I wait for advice on this suspicious UVK information, I wondered if, when you have a moment, either of you could glance at another thread I posted 2 days ago in the "back up and restore forum" ? At the risk of feeling and sounding greedy for your expert help, my college son gave us his comatose Samsung NP-QX410 laptop a few months back. He said HDD issue failure, so they purchased a new one and said if I could fix it I could have it. I'm trying to resurrect it and need some advice evaluating if it is possible without major investment. We'd like to give it to our 10 yr. old this June as a 5th grade graduation gift and his first computer.

Here is the thread:

http://www.sevenforums.com/backup-restore/363103-need-help-recovering-hdd-samsung-np-qx410.html

If you get a chance to check it out Thank you. If not, I truly appreciate your valuable time and especially what you've already done to help me here!!!
 

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
Toshiba Satellite c855-s5214
OS
windows 7 professional 64 bit Version 6.1.7601 Service Pack 1 Build 7601
CPU
Intel(R) Pentium(R) CPU B970 @ 2.30GHz, 2300 Mhz, 2 cores
Motherboard
Toshiba Portable BIOS Insyde Corp Version 1.60 Date 4/20/12
Memory
8Gb
Graphics Card(s)
Intel HD Graphics Driver Vers 9.17.10.3347 Date 10/31/20
Hard Drives
SanDisk Extreme Pro SSD 480 Gb (approx. 381gb free)
Firmware Version X21200RL
Migrated and Installed 4/3/2015
Antivirus
BitDefender AntiVirus Free Edition Version 1.0.21.1099
Browser
Internet Explorer 11 update version 11.0.16
Other Info
Additional Systems:

Samsung NP-QX410 Laptop Windows 7 Home Premium SP1
Samsung 850 EVO 250G 4G ram
Avast! Free 2015

Toshiba A205-S7468 Laptop Windows 7 Ultimate
WD 320G HDD 4G ram
AVG free 2015

Attachments

  • 2015-03-06_112642.jpg
    2015-03-06_112642.jpg
    17.2 KB · Views: 18

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
Jacee,

the GEARDIFx.exe is ok then?

If so, then thank you for all your help!!! I will be more careful in my future internet travels....and now much wiser!!
 

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
Toshiba Satellite c855-s5214
OS
windows 7 professional 64 bit Version 6.1.7601 Service Pack 1 Build 7601
CPU
Intel(R) Pentium(R) CPU B970 @ 2.30GHz, 2300 Mhz, 2 cores
Motherboard
Toshiba Portable BIOS Insyde Corp Version 1.60 Date 4/20/12
Memory
8Gb
Graphics Card(s)
Intel HD Graphics Driver Vers 9.17.10.3347 Date 10/31/20
Hard Drives
SanDisk Extreme Pro SSD 480 Gb (approx. 381gb free)
Firmware Version X21200RL
Migrated and Installed 4/3/2015
Antivirus
BitDefender AntiVirus Free Edition Version 1.0.21.1099
Browser
Internet Explorer 11 update version 11.0.16
Other Info
Additional Systems:

Samsung NP-QX410 Laptop Windows 7 Home Premium SP1
Samsung 850 EVO 250G 4G ram
Avast! Free 2015

Toshiba A205-S7468 Laptop Windows 7 Ultimate
WD 320G HDD 4G ram
AVG free 2015
Note: GEARDIFx.exe (Jacee's link is okay) but what shows up in your log:

<ContentsCommonAppData> | E1864A66-75E3-486a-BD95-D1B7D99A84A7

That's files in this location:


C:\ProgramData\application data\e1864a66-75e3-486a-bd95-d1b7d99a84a7\geardifx.exe

Well, that's (possibly) not okay.

So you need to check what's in that folder.

Suggest: Run UVK again - right click and "Run as Admin"

Choose "Misc Tools" then "File To Manage" > Browse

Navigate to C:\ProgramData\application data\e1864a66-75e3-486a-bd95-d1b7d99a84a7\geardifx.exe and select it.

Click "File Infromation" and in the window that opens up if you see:

MD5 Hash: b2a4f900050713c5099dba2910723a03

then it's okay.

If you see:

MD5 Hash: 63fbf80e79285b166d106f155c461cf6

then it's suspect.

Thanks Jacee!
 
Last edited:

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
ASUS
OS
Microsoft Windows 7 Home Premium 64-bit 7601 Multiprocessor Free Service Pack 1
CPU
AMD C-60 APU with Radeon(tm) HD Graphics
Motherboard
ASUSTeK COMPUTER INC. X501U
Memory
4.00 GB
Graphics Card(s)
AMD Radeon HD 6290 Graphics
Sound Card
(1) AMD High Definition Audio Device (2) Realtek High Defi
Screen Resolution
1366 x 768 x 32 bits (4294967296 colors) @ 60 Hz
Hard Drives
Hitachi HTS545050A7E380 SATA Disk Device
Antivirus
Comodo CIS & FW, SecureAplus App Whitelisting, Threatfire
Browser
Cyberfox 64bit, Opera 64bit, Airfox
Other Info
Spy-The-Spy, HitmanPro.Alert, Norton Connect Safe, MJRegWatcher, BitDefender TrafficLight, Voodoo Shield, Zemana AntiMalware
Jacee,

the GEARDIFx.exe is ok then?

If so, then thank you for all your help!!! I will be more careful in my future internet travels....and now much wiser!!

It appears okay to me.

@ callender see this image ... regarding "6ff8b4d7212e45c74e4c85236953e26fb9b49b9c"
in the UVK log
 

Attachments

  • cannot find.jpg
    cannot find.jpg
    48.9 KB · Views: 1

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
RE: MD5 hash in log.

Now why didn't I search for that!

Anyway the dodgy version of the file looks like it would have been picked up by the other scans. Apologies for the confusion.
 

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
ASUS
OS
Microsoft Windows 7 Home Premium 64-bit 7601 Multiprocessor Free Service Pack 1
CPU
AMD C-60 APU with Radeon(tm) HD Graphics
Motherboard
ASUSTeK COMPUTER INC. X501U
Memory
4.00 GB
Graphics Card(s)
AMD Radeon HD 6290 Graphics
Sound Card
(1) AMD High Definition Audio Device (2) Realtek High Defi
Screen Resolution
1366 x 768 x 32 bits (4294967296 colors) @ 60 Hz
Hard Drives
Hitachi HTS545050A7E380 SATA Disk Device
Antivirus
Comodo CIS & FW, SecureAplus App Whitelisting, Threatfire
Browser
Cyberfox 64bit, Opera 64bit, Airfox
Other Info
Spy-The-Spy, HitmanPro.Alert, Norton Connect Safe, MJRegWatcher, BitDefender TrafficLight, Voodoo Shield, Zemana AntiMalware
That's not a problem callender :D
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
Jacee,

only thing of note is this file (found by ESET online, post #19, 3 days ago) seems to be gone from laptop without anything I did.

C:\Windows\SysWOW64\Adobe\Shockwave 12\gt.exe

I searched entire computer for it (including hidden files) and no results found.

Not sure what happened to it. Maybe ESET did remove it? or was removed when uninstalling System Mechanic? or updating version of Adobe Shockwave?

I am running ESET online again. I'll see if it comes up with anything and if so try to remove. I'll post my findings.

Also, I bought subscription for Malwarebytes Premium.
 

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
Toshiba Satellite c855-s5214
OS
windows 7 professional 64 bit Version 6.1.7601 Service Pack 1 Build 7601
CPU
Intel(R) Pentium(R) CPU B970 @ 2.30GHz, 2300 Mhz, 2 cores
Motherboard
Toshiba Portable BIOS Insyde Corp Version 1.60 Date 4/20/12
Memory
8Gb
Graphics Card(s)
Intel HD Graphics Driver Vers 9.17.10.3347 Date 10/31/20
Hard Drives
SanDisk Extreme Pro SSD 480 Gb (approx. 381gb free)
Firmware Version X21200RL
Migrated and Installed 4/3/2015
Antivirus
BitDefender AntiVirus Free Edition Version 1.0.21.1099
Browser
Internet Explorer 11 update version 11.0.16
Other Info
Additional Systems:

Samsung NP-QX410 Laptop Windows 7 Home Premium SP1
Samsung 850 EVO 250G 4G ram
Avast! Free 2015

Toshiba A205-S7468 Laptop Windows 7 Ultimate
WD 320G HDD 4G ram
AVG free 2015
@ Jacee

I ran ESET online. NO C:\Windows\SysWOW64\Adobe\Shockwave 12\gt.exe .... In fact, I got NO THREATS detected.

THANK YOU! THANK YOU! Both you and Callender!!!!

and thank you for the education! Take care!!
 

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
Toshiba Satellite c855-s5214
OS
windows 7 professional 64 bit Version 6.1.7601 Service Pack 1 Build 7601
CPU
Intel(R) Pentium(R) CPU B970 @ 2.30GHz, 2300 Mhz, 2 cores
Motherboard
Toshiba Portable BIOS Insyde Corp Version 1.60 Date 4/20/12
Memory
8Gb
Graphics Card(s)
Intel HD Graphics Driver Vers 9.17.10.3347 Date 10/31/20
Hard Drives
SanDisk Extreme Pro SSD 480 Gb (approx. 381gb free)
Firmware Version X21200RL
Migrated and Installed 4/3/2015
Antivirus
BitDefender AntiVirus Free Edition Version 1.0.21.1099
Browser
Internet Explorer 11 update version 11.0.16
Other Info
Additional Systems:

Samsung NP-QX410 Laptop Windows 7 Home Premium SP1
Samsung 850 EVO 250G 4G ram
Avast! Free 2015

Toshiba A205-S7468 Laptop Windows 7 Ultimate
WD 320G HDD 4G ram
AVG free 2015
Good to know!! :)
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
Back
Top