Hello.
I noticed few weeks ago problems on this machine :
- Windows is sometimes crashing at start.
- The computer is slowed, especially (maybe only ?) in internet navigation.
It was a a machine for games that I recently started to use for everything. That’s why it had not any anti virus yet. (Ok, I should have installed one as soon as I started to navigate on the web with it. My bad)
I installed Avast. It cleaned some viruses.
I installed MBAM that didn’t find anything else.
I tried many updating of programs but the problem is still there.
When I launch the Avast scan at boot it detect that File MBR0 is infected by Win32:MBROOT-J [trj] but it doesn’t offer me any option of cleaning or deleting.
I tried to search on your forums for a guide to remove it but i only found particular answers for particular situations. (At least it was how it appeared to me.)
So I followed the instructions of the topic : “Logs to assist in cleaning malware”
Here are the logs :
MBAM last log : (in french sorry)
Malwarebytes Anti-Malware 1.60.1.1000
www.malwarebytes.org
Version de la base de données: v2012.02.21.05
Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
Propriétaire :: LEBRUN-338BDB73 [administrateur]
23/02/2012 18:21:58
mbam-log-2012-02-23 (18-21-58).txt
Type d’examen: Examen complet
Options d’examen activées: Mémoire | Démarrage | Registre | Système de fichiers | Heuristique/Extra | Heuristique/Shuriken | PUP | PUM
Options d’examen désactivées: P2P
Elément(s) analysé(s): 280423
Temps écoulé: 57 minute(s), 16 seconde(s)
Processus mémoire détecté(s): 0
(Aucun élément nuisible détecté)
Module(s) mémoire détecté(s): 0
(Aucun élément nuisible détecté)
Clé(s) du Registre détectée(s): 0
(Aucun élément nuisible détecté)
Valeur(s) du Registre détectée(s): 0
(Aucun élément nuisible détecté)
Elément(s) de données du Registre détecté(s): 0
(Aucun élément nuisible détecté)
Dossier(s) détecté(s): 0
(Aucun élément nuisible détecté)
Fichier(s) détecté(s): 0
(Aucun élément nuisible détecté)
(fin)
OTL logs : Attached
aswMBR log :
aswMBR version 0.9.9.1649 Copyright(c) 2011 AVAST Software
Run date: 2012-02-27 18:35:59
18:35:59.328 OS Version: Windows 5.1.2600 Service Pack 3
18:35:59.328 Number of processors: 2 586 0x602
18:35:59.328 ComputerName: LEBRUN-338BDB73 UserName: Propriétaire
18:35:59.890 Initialize success
18:36:00.046 AVAST engine defs: 12022700
18:36:03.140 Disk 0 (boot) \Device\Harddisk0\DR0 → \Device\Ide\IdeDeviceP0T0L0-3
18:36:03.140 Disk 0 Vendor: ST3160815AS 4.AAB Size: 152627MB BusType: 3
18:36:03.140 Device owAZEVAoRGRCZ → DriverStartIo RGRCZ@J@ b7f37864
18:36:03.156 Disk 0 MBR read successfully
18:36:03.156 Disk 0 MBR scan
18:36:03.156 Disk 0 Windows XP default MBR code
18:36:03.171 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 45002 MB offset 63
18:36:03.187 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 107622 MB offset 92164905
18:36:03.187 Disk 0 scanning sectors +312576705
18:36:03.265 Disk 0 scanning C:\WINDOWS\system32\drivers
18:36:09.734 Service scanning
18:36:11.718 Service FXDRV D:\Fxdrv.sys LOCKED 21
18:36:17.281 Modules scanning
18:36:20.328 Disk 0 trace - called modules:
18:36:20.343 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x89de1000]<<
18:36:20.359 1 nt!IofCallDriver → \Device\Harddisk0\DR0[0x89decab8]
18:36:20.359 3 CLASSPNP.SYS[b80e8fd7] → nt!IofCallDriver → \Device\00000062[0x89de2258]
18:36:20.359 5 ACPI.sys[b7f7e620] → nt!IofCallDriver → \Device\Ide\IdeDeviceP0T0L0-3[0x89ddad98]
18:36:20.687 AVAST engine scan C:\WINDOWS
18:36:24.593 AVAST engine scan C:\WINDOWS\system32
18:37:46.250 AVAST engine scan C:\WINDOWS\system32\drivers
18:37:54.953 AVAST engine scan C:\Documents and Settings\Propriétaire
18:41:16.843 AVAST engine scan C:\Documents and Settings\All Users
18:42:07.953 Scan finished successfully
18:43:18.187 Disk 0 MBR has been saved successfully to “C:\Documents and Settings\Propriétaire\Bureau\aswMBR\MBR.dat”
18:43:18.187 The log file has been saved successfully to “C:\Documents and Settings\Propriétaire\Bureau\aswMBR\aswMBR.txt”
Thank you very much in advance for your help.