Additional Problems

After following the Guide suggested by Pondus: Follow this guide from essexboy and post the logs
http://forum.avast.com/index.php?topic=53253.0

I followed the guide and got to the “Perform Quick Scan” place, I then clicked Scan, it scanned just find, it completed and then said “No Malicious Items Found”.

I have some kind of virus and was disappointed to see the above results. My computer runs fine, but I either cannot install any new virus protection, eliminator or cleaner or if I can install one, it will not complete a scan, then stops and locks up the computer. This includes the original McAfee that I had. I also installed an Avast Anti-Virus download and it also would not complete a scan. It went about 1/4 of the way, stopped and locked up again. Even tho it didn’t go far, it did find many errors tho, but I am puzzled why the above Guide would not detect any.

Any help sure would be appreciated.

Thanks

I followed the guide and got to the "Perform Quick Scan" place, I then clicked Scan, it scanned just find, it completed and then said "No Malicious Items Found".
You did not produce the OTL log from the guide? This is the log essexboy is using to see what the problem is

Afther you removed McAfee, have you run the McAfee removal tool ?
You will fiend it here as Nr.19a http://uninstallers.blogspot.com/

I never got that far as I didn’t have anything to “Check” and no chance to “Remove Selected” therefore had no opportunity to proceed to the last 3 steps of the first part.

But if eveything is OK and I can proceed to OTL I will do that next step. (If anyone could just verify that it is OK to now proceed, it would be appreciated)

Also I have a Un-Install download from McAfee with an icon that I used. I already had it un-installed, but I ran it again just to make sure. I had believed that that was good enough, but I will run the Removal Tool if necessary.

Thanks

yes, run the removal tool and restart, this vill remove any leftovers fro McAfee that can make problems for avast

And then run OTL

OK, Thanks.

Update: The McAfee Removal Tool is the same exact one I have and is the one that I have already used.

But now another problem. I followed the directions for OTL and clicked on “Run Scan”. It went only a little bit and I got this pop-up block:

Access Violation at address 00402903 in module ‘OTL.exe’ Read of address 001D4000

Also, I still have a “MemTurbo” icon on the bottom right of my screen. Is that interferring anything?

Have sendt PM to essexboy so he can have a look at it when he arrives

Thanks, I sure do appreciate the help.

Lets try with the bigger brother

To ensure that I get all the information this log will need to be attached (instructions at the end) if it is to large to attach then upload to Mediafire and post the sharing link.

Download OTS to your Desktop

[*]Close ALL OTHER PROGRAMS.
[*]Double-click on OTS.exe to start the program.
[*]Check the box that says Scan All Users
[*]Under Additional Scans check the following:
[*]Reg - Shell Spawning
[*]File - Lop Check
[*]File - Purity Scan
[*]Evnt - EvtViewer (last 10)
[*]Under the Custom Scan box paste this in
netsvcs
%SYSTEMDRIVE%*.exe
/md5start
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
sceclt.dll
ntelogon.dll
logevent.dll
iaStor.sys
nvstor.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
ahcix86.sys
KR10N.sys
nvstor32.sys
ahcix86s.sys
nvrd32.sys
/md5stop
%systemroot%*. /mp /s
CREATERESTOREPOINT
%systemroot%\system32*.dll /lockedfiles
%systemroot%\Tasks*.job /lockedfiles

[*]Now click the Run Scan button on the toolbar.
[*]Let it run unhindered until it finishes.
[*]When the scan is complete Notepad will open with the report file loaded in it.
[*]Click the Format menu and make sure that Wordwrap is not checked. If it is then click on it to uncheck it.

Please attach the log in your next post.

Here are the results. Thanks.

There is an unusual occurence on one of your system files so I would like to do a rootkit check before I proceed

Download the GMER Rootkit Scanner. Unzip it to your Desktop.

Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.

Double-click gmer.exe. The program will begin to run.

Caution
These types of scans can produce false positives. Do NOT take any action on any “<— ROOKIT” entries unless advised!

If possible rootkit activity is found, you will be asked if you would like to perform a full scan.
[*]Click NO
[*]In the right panel, you will see a bunch of boxes that have been checked … leave everything checked and ensure the Show all box is un-checked.
[*]Now click the Scan button.
Once the scan is complete, you may receive another notice about rootkit activity.
[]Click OK.
[
]GMER will produce a log. Click on the [Save…] button, and in the File name area, type in “GMER.txt
[*]Save it where you can easily find it, such as your desktop.

Post the contents of GMER.txt in your next reply.

Results from procedure:

“Problem Detected with Computer, Windows Shutting Down”

Stop: 0x0000004E

essexboy, at this point I am really considering “Crashing Out” and starting over. If I choose to do so, will it 100% guarantee to eliminate my problem?

Thanks

If you do a full reformat and install then your problems will go - dependant on what files you need to recover from the system it may be the fastest option. There is a tutorial on how to do a clean install and backup considerations here http://www.geekstogo.com/forum/Reformat-Install-Windows-t173729.html

OK, Appreciate the info.

I’m kind of curious tho, would you say that I have a super bug? How rare is what I have?

At the moment it is difficult to tell as the malware is not showing itself, which is why I was looking at GMER to show me the area to look in. It may be the new TDSS variant - which at the moment only GMER can find, but once found it is relatively easy to clean. I would be loth to use Combofix on this one as about one in ten runs result in an unbootable machine - mindst you we can get it back again.

So to resolve this I would need to try another rootkit detector, with no guarantee that would work

I would like to leave it up to you. If you would like to proceed, I’m willing to try. Right now, I’m just on the fence on which way to go.

Thanks

Any time you want to stop just say so -

Download SysProt Antirootkit from the link below (you will find it at the bottom of the page under attachments, or you can get it from one of the mirrors).

http://sites.google.com/site/sysprotantirootkit/

Unzip it into a folder on your desktop.

Start the Sysprot.exe program.

[]Click on the Log tab.
[
] In the Write to log box select all items.
[] Click on the Create Log button on the bottom right.
[
] After a few seconds a new Window should appear.
[] Make sure Scan all drives is selected and click on the Start button.
[
] When it is complete a new Window will appear to indicate that the scan is finished.
[*] The log will be created and saved automatically in the same folder. Open the text file and copy/paste the log here.

Results:

When we were downloading the antirootkit, we got a window that popped up that stated something like “No Disc to copy to”. But we did get a report when we checked on the log.

I tried the whole procedure again and the antirootkit just kept running and running.

I can post the log results that we got, but it is a little long. Should we put it in an attachment?

Yes please

Thanks