I have a problem with my computer. I cannot access my hard disk.

I have used CCleaner to clean the register, and here is my HiJackThis log…


Welcome to the avast! forums, Diogo TKN. :slight_smile:

It seems you are using AVG8 suite. Is there some reason that you are asking for help here and not on the AVG forums?


I was wondering the same thing but then I remembered how awful the AVG forum is and one of the reasons I switched to avast!.

What is AVG forums? ;D

Hi there.
I am to blame for that. Having in the past been greatly helped by this team, I did not hesitate in advising Diogo to come here, when he reported the problem to me. As a teacher, I had to make sure he would get good help, and to be honest, I didn’t ask about which anti-virus software Diogo was using until after the post was sent - and not having any feedback :'(. I know It isn’t “politically correct”, but it was the confidence I put in you that made me suggest this forum. I apologise for the inconvenience.
Should we seek help elsewhere :-[ ?

JLucas

Don’t worry. I haven’t help because I’m not an expert on HijackThis, just that.
If Diogo wants he can change to avast and have a better support here :wink:

The real problem is simply posting an HJT log without a reason doesn’t help us very much either.

Suspect:
Did you install this software (but it should be removed Fixed in HJT) ?
C:\Programas\Search Settings\SearchSettings.exe

R3 - URLSearchHook: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Programas\Search Settings\kb127\SearchSettings.dll

O2 - BHO: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Programas\Search Settings\kb127\SearchSettings.dll

O4 - HKLM..\Run: [SearchSettings] C:\Programas\Search Settings\SearchSettings.exe

As a couple of google searches on these file names view it as a trojan,

http://www.pcpitstop.com/libraries/process/i/SearchSettings.exe.html
http://www.neoseeker.com/forums/62/t1051983-searchsettings/
http://www.glaryutilities.com/processlibrary/process/SearchSettings.exe.html

http://www.prevx.com/filenames/X36539609154397138-X1/SEARCHSETTINGS2EDLL.html.

So I would most certainly get rid of it (there may or may not be a windows add remove programs entry to get rid of this).

I take it that your ISP is PT Comunicacoes S.A. ?

Other than that I don’t see anything obvious, however you don’t appear to have an active firewall. - It should be capable of blocking unauthorised outbound Internet Connections. - What is your firewall ?

HJT ACTIONS
Suspect: Upload the file/s to VirusTotal, Send a sample to avast if multiple detections at VT and Fix in HJT (see below)

Check the suspect file/s at: VirusTotal - Multi engine on-line virus scanner and report the findings here in the topic.

Send the sample to virus@avast.com zipped and password protected with the password in email body, a reference to this topic (give URL) and undetected malware in the subject.

Run HJT again (close any other windows except HJT), tick the box to the left of the suspect entry you wish to fix, click the Fix Selected Button.

I propose you download from a clean computer onto an USB stik (pendrive) DrWebCureIt:
ftp://ftp.drweb.com/pub/drweb/cureit/launch.exe

Then insert the usb stick into the computer and do a full scan,
Interesting to hear the results,

polonus

Hi, David,
Apparently the problem is this: resycled\ntldr.com
Diogo has used FlashDesinfector and says everything seems to be OK now. I’ll tell him to check that firewall and make an online scan.
Thanks for your support.
JLucas

Yes that is associated with autorun.inf infections, so flashdisinfector should help.

Now you should be able to use other tools to see if there is anything else.

If you haven’t already got this software (freeware), download, install, update and run it, preferably in safe mode.

  1. SUPERantispyware On-Demand only in free version.
  2. MalwareBytes Anti-Malware, On-Demand only in free version http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe, right click on the link and select Save As or Save File (As depending on your browser), save it to a location where you can find it easily later.