BleepingComputer.com: Help Are these virus?

Jump to content

Forum Rules

When posting your problem, do not run and post a ComboFix log. ComboFix is a tool that should only be run under the supervision of someone who has been trained in its use. Using it on your own can cause problems with your computer. Any posts containing CF Logs will be ignored.

To receive help, you should instead provide a detailed description of your problem, detailed word-for-word error messages that you are receiving, screenshots of strange behaviour, and your operating system. This information is much more useful to our helpers than a ComboFix log.


If you have not received help after three days, please post a link to your topic HERE.
  • 2 Pages +
  • 1
  • 2
  • You cannot start a new topic
  • You cannot reply to this topic

Help Are these virus? Trying to clean my PC

#16 User is offline   Broni 

  • The Coolest BC Computer
  • PipPipPipPipPipPip
  • Find Topics
  • Group: BC Advisor
  • Posts: 22,167
  • Joined: 01-February 08
  • Gender:Male
  • Location:Daly City, CA

Posted 06 January 2012 - 12:08 PM

Did you run SafeBootKeyRepair?
Did it help?

Download Autoruns for Windows: http://technet.microsoft.com/en-us/sysinternals/bb963902.aspx
No installation required.
Simply unzip Autoruns.zip file, and double click on autoruns.exe file to run the program.
Go File>Save, and save it as AutoRuns.txt file to know location.
You must select Text from drop-down menu as a file type:

Posted Image

Upload the file(s) here: http://www.filedropper.com/
Post download link (copy URL: link):
Posted Image
My Website

Posted Image

My help doesn't cost a penny, but if you'd like to consider a donation, click Posted Image




#17 User is offline   bivels 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 39
  • Joined: 21-December 11

Posted 06 January 2012 - 12:26 PM

I ran SafeBootKeyRepair, but it didn't help.

Here is the Autoruns link: http://www.filedropper.com/autoruns_4

#18 User is offline   Broni 

  • The Coolest BC Computer
  • PipPipPipPipPipPip
  • Find Topics
  • Group: BC Advisor
  • Posts: 22,167
  • Joined: 01-February 08
  • Gender:Male
  • Location:Daly City, CA

Posted 06 January 2012 - 12:31 PM

Download aswMBR to your desktop.
Double click the aswMBR.exe to run it.
If you see this question: Would you like to download latest Avast! virus definitions?" say "Yes".
Click the "Scan" button to start scan.
On completion of the scan click "Save log", save it to your desktop and post in your next reply.

NOTE. aswMBR will create MBR.dat file on your desktop. This is a copy of your MBR. Do NOT delete it.
My Website

Posted Image

My help doesn't cost a penny, but if you'd like to consider a donation, click Posted Image




#19 User is offline   bivels 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 39
  • Joined: 21-December 11

Posted 06 January 2012 - 01:18 PM

Here is the log:

aswMBR version 0.9.9.1156 Copyright© 2011 AVAST Software
Run date: 2012-01-06 18:51:30
-----------------------------
18:51:30.234 OS Version: Windows 5.1.2600 Service Pack 3
18:51:30.234 Number of processors: 2 586 0x407
18:51:30.234 ComputerName: MEDION UserName: Botel
18:51:30.656 Initialize success
18:51:30.796 AVAST engine defs: 12010600
18:51:39.218 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-17
18:51:39.218 Disk 0 Vendor: SAMSUNG_HD502IJ 1AA01113 Size: 476940MB BusType: 3
18:51:39.234 Disk 0 MBR read successfully
18:51:39.234 Disk 0 MBR scan
18:51:39.281 Disk 0 unknown MBR code
18:51:39.281 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 100000 MB offset 63
18:51:39.281 Disk 0 Partition - 00 05 Extended 100000 MB offset 204800400
18:51:39.296 Disk 0 Partition 2 00 0C FAT32 LBA MSWIN4.1 10000 MB offset 409600800
18:51:39.312 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 266939 MB offset 430081344
18:51:39.328 Disk 0 Partition 4 00 07 HPFS/NTFS NTFS 100000 MB offset 204800463
18:51:39.328 Disk 0 scanning sectors +976773168
18:51:39.343 Disk 0 scanning C:\WINDOWS\system32\drivers
18:51:47.531 Service scanning
18:51:48.453 Modules scanning
18:51:53.437 Disk 0 trace - called modules:
18:51:53.453 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys pciide.sys PCIIDEX.SYS
18:51:53.453 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8a42c348]
18:51:53.453 3 CLASSPNP.SYS[b8118fd7] -> nt!IofCallDriver -> \Device\0000006c[0x8a41d9e8]
18:51:53.453 5 ACPI.sys[b7f7e620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP1T0L0-17[0x8a41f940]
18:51:53.843 AVAST engine scan C:\WINDOWS
18:51:59.921 AVAST engine scan C:\WINDOWS\system32
18:53:13.906 AVAST engine scan C:\WINDOWS\system32\drivers
18:53:24.578 AVAST engine scan C:\Dokumente und Einstellungen\Botel
19:06:13.328 AVAST engine scan C:\Dokumente und Einstellungen\All Users
19:15:57.015 Disk 0 MBR has been saved successfully to "C:\Dokumente und Einstellungen\Botel\Desktop\MBR.dat"
19:15:57.031 The log file has been saved successfully to "C:\Dokumente und Einstellungen\Botel\Desktop\aswMBR.txt"

#20 User is offline   Broni 

  • The Coolest BC Computer
  • PipPipPipPipPipPip
  • Find Topics
  • Group: BC Advisor
  • Posts: 22,167
  • Joined: 01-February 08
  • Gender:Male
  • Location:Daly City, CA

Posted 06 January 2012 - 01:29 PM

I don't see much there.
You'll need more advanced help.

Please follow the instructions in ==>This Guide<== starting at Step 6. If you cannot complete a step, skip it and continue.

Once the proper logs are created, then make a NEW TOPIC and post it ==>HERE<== Please include a description of your computer issues, what you have done to resolve them, and a link to this topic.

If you can produce at least some of the logs, then please create the new topic and explain what happens when you try to create the log(s) that you couldn't get. If you cannot produce any of the logs, then still post the topic and explain that you followed the Prep. Guide, were unable to create the logs, and describe what happens when you try to create the logs.

It would be helpful if you post a note here once you have completed the steps in the guide and have started your topic in malware removal. Good luck and be patient.

If HelpBot replies to your topic, PLEASE follow Step One so it will report your topic to the team members.
My Website

Posted Image

My help doesn't cost a penny, but if you'd like to consider a donation, click Posted Image




#21 User is offline   bivels 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 39
  • Joined: 21-December 11

Posted 07 January 2012 - 11:28 AM

Thanks, Broni,

Is this for the black screen at start up or the speed of the machine?

#22 User is offline   Broni 

  • The Coolest BC Computer
  • PipPipPipPipPipPip
  • Find Topics
  • Group: BC Advisor
  • Posts: 22,167
  • Joined: 01-February 08
  • Gender:Male
  • Location:Daly City, CA

Posted 07 January 2012 - 12:38 PM

They'll check everything.
My Website

Posted Image

My help doesn't cost a penny, but if you'd like to consider a donation, click Posted Image




Share this topic:


  • 2 Pages +
  • 1
  • 2
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users