We’d like to remind Forumites to please avoid political debate on the Forum.

This is to keep it a safe and useful space for MoneySaving discussions. Threads that are – or become – political in nature may be removed in line with the Forum’s rules. Thank you for your understanding.

📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!
The Forum now has a brand new text editor, adding a bunch of handy features to use when creating posts. Read more in our how-to guide

Potential Virus - Help please

1246789

Comments

  • DCodd
    DCodd Posts: 8,187 Forumite
    Part of the Furniture Combo Breaker
    Hi waddler_8.

    Can't post the log again so e-mailed it if that's ok?

    Thanks
    Always get a Qualified opinion - My qualifications are that I am OLD and GRUMPY:p:p
  • waddler_8
    waddler_8 Posts: 3,588 Forumite
    Combofix has removed a whole host of stuff, but is struggling with a few. How's the computer actually running?

    Download Roguekiller from the link below.


    LINK
    • Double click roguekiller.exe to run it.
    • Wait for the prescan to finish.
    • Accept the EULA
    • Under Options, click the Scan button
    • When the Status reports Scan finished, click Report under Options

      If an infection is detected, do not delete anything yet!

    • Notepad will open. Copy & paste the contents of that report in a reply here (or email me it).
    • The log can also be found on your desktop entitled RKreport[**].txt
    • Close RogueKiller. Click Yes to the prompt
  • DCodd
    DCodd Posts: 8,187 Forumite
    Part of the Furniture Combo Breaker
    waddler_8 wrote: »
    Combofix has removed a whole host of stuff, but is struggling with a few. How's the computer actually running?

    Download Roguekiller from the link below.


    LINK
    • Double click roguekiller.exe to run it.
    • Wait for the prescan to finish.
    • Accept the EULA
    • Under Options, click the Scan button
    • When the Status reports Scan finished, click Report under Options

      If an infection is detected, do not delete anything yet!

    • Notepad will open. Copy & paste the contents of that report in a reply here (or email me it).
    • The log can also be found on your desktop entitled RKreport[**].txt
    • Close RogueKiller. Click Yes to the prompt

    Thanks, will do

    The laptop is slow and I'm still having to run Chrome as current user with the protection box unchecked.

    The other programs like IE, Malwarebytes etc still won't load. Avast still appears to run.
    Always get a Qualified opinion - My qualifications are that I am OLD and GRUMPY:p:p
  • waddler_8
    waddler_8 Posts: 3,588 Forumite
    It shouldn't take long to scan.
  • DCodd
    DCodd Posts: 8,187 Forumite
    Part of the Furniture Combo Breaker
    Hi waddler_8

    Had to e-mail the report as it wouldn't let me post it.

    Thanks
    Always get a Qualified opinion - My qualifications are that I am OLD and GRUMPY:p:p
  • waddler_8
    waddler_8 Posts: 3,588 Forumite
    Roguekiller log looks ok.

    download this and save it to your desktop.

    http://files.avast.com/files/rootkit-scanner/aswmbr.exe

    When you've downloaded it...
    • Double click aswMBR.exe to run it
    • With the AVscan set to Quick Scan, click the Scan button.
    • When the scan reports "Scan finished successfully", click Save log & save the log to your desktop.
    • Click OK when prompted. aswMBR.txt & MBR.dat will be appear on your desktop.
    • Click EXIT.
    • Copy & paste the contents of aswMBR.txt & post it here (or email me it).
    Don't click to fix anything yet, just post the log.
  • DCodd
    DCodd Posts: 8,187 Forumite
    Part of the Furniture Combo Breaker
    Hi waddler_8 do I do anything with rogue killer or just shut it down?
    Always get a Qualified opinion - My qualifications are that I am OLD and GRUMPY:p:p
  • waddler_8
    waddler_8 Posts: 3,588 Forumite
    Just close it.
  • DCodd
    DCodd Posts: 8,187 Forumite
    Part of the Furniture Combo Breaker
    Got an early start tomorrow. if it's ok I'll run the avast root-kit scanner tomorrow and post the log then?

    Thanks
    Always get a Qualified opinion - My qualifications are that I am OLD and GRUMPY:p:p
  • waddler_8
    waddler_8 Posts: 3,588 Forumite
    Yes, no worries. Things look ok at this stage. I'd also be interested to know if rkill still detects ZeroAccess. It creates a log at the root of your system drive, eg:

    C:\rkill.log
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 353.5K Banking & Borrowing
  • 254.1K Reduce Debt & Boost Income
  • 455K Spending & Discounts
  • 246.6K Work, Benefits & Business
  • 602.9K Mortgages, Homes & Bills
  • 178K Life & Family
  • 260.5K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16K Discuss & Feedback
  • 37.7K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.