BleepingComputer.com: Suspect computer is infected

Jump to content

Forum Guidelines

Posted Image Read the following topic before creating a new topic in this forum. It contains instructions on the what we would like you to post, which will enable us to help you more quickly.

Preparation Guide For Use Before Using Malware Removal Tools and Requesting Help


Posted Image Unfortunately, with the amount of logs we receive per day, the average response time is 5 days. I want to assure you, though, that your topic will be looked at and responded to. So please be patient.


Posted Image DO NOT RUN ComboFix unless requested to.


Posted Image Only members of the Malware Response Team or Moderators are allowed to help people with logs. Anyone else should refrain from posting to another user's log.


Posted Image When posting a log please put the type of infection you have in the topic title. IE: Winfixer, Virtumonde, WinTools, WebSearch, Home Search Assistant, etc.


Posted Image Do not bump your topic. We try to resolve logs on a first come/first served basis. By bumping your log you will be pushed back in line due to the new date of your bump.
  • 2 Pages +
  • 1
  • 2
  • You cannot start a new topic
  • This topic is locked

Suspect computer is infected Do not know how to read logs!

#16 User is offline   nasdaq 

  • Forum Addict
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Team
  • Posts: 5,053
  • Joined: 16-June 06
  • Gender:Male
  • Location:Montreal, QC. Canada

Posted 11 October 2011 - 01:08 PM

Could be anything.

Lets check your boot record.


Download http://public.avast.com/~gmerek/aswMBR.exe (aswMBR.exe) ( 511KB ) to your desktop. Double click the aswMBR.exe to run it

  • Click the "Scan" button to start scan.
  • Upon completion of the scan, click Save log, and save it to your desktop. (Note - do not select any Fix at this time) <- IMPORTANT
  • Please post the contents of that log in your next reply.
There shall also be a file on your desktop named MBR.dat. Right click that file and select Send To>Compressed (zipped) folder. Please attach that zipped file in your next reply.

===

#17 User is offline   babas87 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 60
  • Joined: 04-September 11

Posted 11 October 2011 - 02:07 PM

Hello. here are the logs, Thanks:

aswMBR logs:


aswMBR version 0.9.8.986 Copyright© 2011 AVAST Software
Run date: 2011-10-12 02:54:35
-----------------------------
02:54:35.217 OS Version: Windows 6.1.7601 Service Pack 1
02:54:35.217 Number of processors: 4 586 0x2502
02:54:35.219 ComputerName: SEBASTIEN-PC UserName: Sebastien
02:54:40.846 Initialize success
02:54:41.431 AVAST engine defs: 11101101
02:55:24.292 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
02:55:24.296 Disk 0 Vendor: Hitachi_ PC3O Size: 305245MB BusType: 3
02:55:24.317 Disk 0 MBR read successfully
02:55:24.323 Disk 0 MBR scan
02:55:24.328 Disk 0 Windows 7 default MBR code
02:55:24.334 Disk 0 scanning sectors +625140400
02:55:24.418 Disk 0 scanning C:\Windows\system32\drivers
02:55:34.894 Service scanning
02:55:36.418 Modules scanning
02:55:45.688 Disk 0 trace - called modules:
02:55:45.701 ntkrnlpa.exe CLASSPNP.SYS disk.sys hpdskflt.sys halmacpi.dll iaStor.sys
02:55:45.707 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x88a2d030]
02:55:45.712 3 CLASSPNP.SYS[8a1bb59e] -> nt!IofCallDriver -> [0x88a2c5f8]
02:55:45.719 5 hpdskflt.sys[8a16cf92] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0x86ea9028]
02:55:46.979 AVAST engine scan C:\Windows
02:55:50.123 AVAST engine scan C:\Windows\system32
02:57:16.919 AVAST engine scan C:\Windows\system32\drivers
02:57:33.010 AVAST engine scan C:\Users\Sebastien
03:04:15.554 AVAST engine scan C:\ProgramData
03:04:49.208 Scan finished successfully
03:05:57.705 Disk 0 MBR has been saved successfully to "C:\Users\Sebastien\Desktop\MBR.dat"
03:05:57.711 The log file has been saved successfully to "C:\Users\Sebastien\Desktop\aswMBR.txt"

Attached File(s)

  • Attached File  MBR.zip (580bytes)
    Number of downloads: 0


#18 User is offline   nasdaq 

  • Forum Addict
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Team
  • Posts: 5,053
  • Joined: 16-June 06
  • Gender:Male
  • Location:Montreal, QC. Canada

Posted 11 October 2011 - 06:28 PM

The Boot sector is good.

After a few restart is the issue still the same?

#19 User is offline   babas87 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 60
  • Joined: 04-September 11

Posted 11 October 2011 - 07:13 PM

There are no more issues. The computer restarts normally. But that was really weird cause it's the first time I get this from this computer...

#20 User is offline   nasdaq 

  • Forum Addict
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Team
  • Posts: 5,053
  • Joined: 16-June 06
  • Gender:Male
  • Location:Montreal, QC. Canada

Posted 12 October 2011 - 07:45 AM

Unexplainable.

#21 User is offline   nasdaq 

  • Forum Addict
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Team
  • Posts: 5,053
  • Joined: 16-June 06
  • Gender:Male
  • Location:Montreal, QC. Canada

Posted 17 October 2011 - 10:07 AM

It appears that this issue is resolved, therefore I am closing the topic. If that is not the case and you need or wish to continue with this topic, please send me or any Moderator a Personal Message (PM) that you would like this topic re-opened.

Share this topic:


  • 2 Pages +
  • 1
  • 2
  • You cannot start a new topic
  • This topic is locked

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users