Possible worm...

I keep my computer pretty clean and run ccleaner regularly (daily) along with a weekly anti-virus process that goes like this:
Run Malware Bytes, run spybot, run CCleaner, run Avast, run spybot.

Overkill? maybe.

Anyway, I find a Winstart.bat and come in here to check it out.

Following outlined procedures here in the forum… I seem to have no problems until I get to the aswMBR part of the process.

here are my logs…

I have not run the fix MBR yet, as I am uncertain as to what to do about the "service Par1284, but I’m pretty sure THAT is my problem.

I’m holding aswMBR open on my desktop, awaiting instruction.

Thanks in advance for any help.

The AswMBR locked file is a printer related parallel port driver so is not a problem

Several programmes could use a file called winstart.bat

Could you locate the file
Right click and select EDIT
Then copy/paste the contents into a text file and attach it in your next post

Overkill? maybe.
Well you dont need SpyBot when you have avast and malwarebytes......and it is not very good

@essexboy, I’d love to. I cannot find it now. I’m going to have to proceed assuming that it triggered but has been removed with my regularly scheduled cleaning. Is it possible its hidden itself?

@Pondus… really? Well, I’ll just remove the danged thing. I hate wasting time I don’t have on useless scans! Thanks! Buhbye Spybot.

If you know the location. follow these directions.

FIle Explorer > Organize > Folder and search options > View > Show Hidden Files/FOlders/drives + Hide Protected Operating system Files.

That should enable you too find it.

Spybot test http://www.pcmag.com/article2/0,2817,2412372,00.asp

In testing, it proved almost 100 percent ineffective.

Thanks @Michael. I think we have to close the topic. I have no clue where the offending file was… or is if it’s still there; which I am doubting at this point.

Thanks @Pondus I missed that!

Glad we could help. You can try doing a search in the start menu. Just search winstart.bat

@Michael, I did that, file not found. So, it’s either been cleaned by my process (which will be much shorter without spybot) or has hidden itself!

I recommend this forum highly. Just sent one of my co-workers here for a problem she’s got on her kids’ laptop.

Revised

Thanks, @Michael.

I’d adjust the plan, but I’ve got a company network running and on any given day, no less than five different portable computers logging in, not counting phones. So, overkill maybe, but I don’t trust anyone else to be meticulous.

Would what you suggest be sufficient in such a case?

Even so, your business you work/own for. Should have firewalls on it. The computers should be mostly protected…

I’d still say.

Avast QuickScan = Monthly
Malwarebytes = Weekly to Bi-Weekly
CCleaner = Monthly.

Honestly, CCLeaner just clears Temp files, browsing history. Which most of that is cleared when you restart. But even so, scanning that much isn’t needed.

Restart? You say that like I turn my computer off at night. O_O

I have firewalls. I don’t trust them enough to stand alone. I do CCleaner daily because I’m in social media and my browsing history in a day is the equivalent of what someone else does in a month, if I wait a month, it takes forever to run.

Does running the scanners do physical damage to the harddrive? It’s not like I have to sit here and watch them run, they’re scheduled to run while I’m sleeping.

I run avast daily on my new Note 3. I guess THAT is overkill too? :smiley:

That is major overkill on the note 3. However, restarting your computer when not on use will help. If you decide to continue leaving it on I’d suggest maybe weekly for CCleaner.

It’s my first non apple phone. I’m nervous. I’ll back off on the scanning once I’ve got the phone figured out.

Thanks for your input. I truly appreciate it. :slight_smile:

Above and beyond. You should get a raise. :wink:

We are all volunteers. Aka, we aren’t paid.

No problem. Just keep in mind, constantly keeping your PC on will most likely break it faster :(.

So most people you see here. If they have the nametag [Avast Employee] [Administrator] [avast! team] [Global Moderator] I believe (And I could be wrong) means they are Avast! Employee’s… So Pondus and Essexboy, are both volunteers. We do not officially work for Avast!. Just help when we can by getting the latest and greatest malware and sending it over for them to add to the detection list :).

Well you should be paid. You’re way more useful AND helpful than certain other forum’s mods whose names will go unmentioned.

Can you tell I’m old school? Not to mention headshy? I’m also an Aspie, so being anal retentive isn’t a mystery to me.

So, being me, I reran the Avast just to be sure, and it’s finally finished… however, it triggered on the winstart.bat again.

So, I went to the windows/winstart.bat and it is a nonexistent file.

I’ve also got triggered on something called windows/syswow64/autoexec.nt in the list and it is also a nonexistent folder… WTF?

I went to the folder, which is where it claims to be, but no such file is in the folder, yes, I’ve unhidden all files.

Now I’m really scratching my head. O_o

Now what?

I don’t know now. YOu’ll have to ask Essexboy.

okie… Essexboy… help???

I was going to see if I could grab him. Nope. YOu’ll have maybe 2 ish hours before he goes to sleep.