Virus

Up until three weeks ago, I had iYogi Tech support… You dont think they might still have remote access do you or left something behind thats being used for remote access?

Ahh now I’m just being paranoid… lol Thank god it`s the weekend!! Enjoy those beers Natt :stuck_out_tongue:

Hi :slight_smile:

I’m sorry for the delay, had family commitments. Please do the following, I need fresh reports to analyze them.

https://sites.google.com/site/cannedfixes/farbar-recovery-scan-tool/FRST.gif
Scan with Farbar Recovery Scan Tool

Please re-run Farbar Recovery Scan Tool.
[*]Right-click on
https://sites.google.com/site/cannedfixes/farbar-recovery-scan-tool/FRST.gif
icon and select
https://sites.google.com/site/cannedfixes/home/hosted-images-tools/RunAsAdmin.jpg
Run as Administrator to start the tool.

XP users click run after receipt of Windows Security Warning - Open File.
8 users will be prompted about Windows SmartScreen protection - click More information and Run.
[*]Make sure that Addition option is checked.
[*]Press Scan button and wait.
[*]The tool will produce two logfiles on your desktop: FRST.txt and Addition.txt.

Please include their content in your next reply.

https://sites.google.com/site/cannedfixes/otl/51a5d669693dd-icon_OTL.png
Scan with OTL

Please download OTL by OldTimer and save the file to your desktop.

[*]Right-click on
https://sites.google.com/site/cannedfixes/otl/51a5d669693dd-icon_OTL.png
icon and select
https://sites.google.com/site/cannedfixes/home/hosted-images-tools/RunAsAdmin.jpg
Run as Administrator to start the tool.
[*]Make sure that Scan All Users, LOP check and Purity check are ticked.
[*]For 64-bit systems only - make sure that Include 64-bit option is also ticked.
[*]Sections Processes, Modules, Services, Drivers, Standard Registry are set to Use Safelist.
[*]Section Extra Registry is also set to Use Safelist.
[*]Under the Custom Scans/Fixes bar in the box paste in the following:

BASESERVICES
drivers32

[*]Push Run Scan and wait patiently.
[*]Two notepad windows will be opened after this run: OTL.txt (maximized) and Extras.txt (minimized).

Please include the content of both logfiles in your next reply.

All good, appreciate the help… I`ve had a hell of a day connecting to the network anyway Grrr

Natt, I just found a copy of TDSSKiller I can download if you still wanted to run that software… Heres the link http://www.bleepingcomputer.com/download/tdsskiller/ Ill wait to hear from you before proceeding :slight_smile:

I doubt that TDSSKiller will show something that Gmer wouldn’t. But you can give it a whirl - just bare in mind not to delete anything without my acceptance first.

Ran scan without any problems and all looks good to me as it doesn`t appear to have found anything like you thought… How did you go with the other logs? Anything of any interested there…

Okay network connection was just playing up again so thought, I wonder and ran that scan again only this time it`s found three things… Should I just take a screenshot? Sorry, don’t know what to do next

screenshot

Anyone… do I just skip and continue?

Skip :slight_smile:

Hello :slight_smile:

Skip, as Essexboy mentioned. But Where’s the full TDSSKIller logfile?

Thanks for that guys :)… Natt, I`m not getting a report with that scan

OK, let’s try something another.

https://sites.google.com/site/cannedfixes/home/hosted-images-tools/MalwarebytesAntiRootkit.png
Scan with Malwarebytes’ Anti-Rootkit

Please download Malwarebytes’ Anti-Rootkit and save the file to your desktop.
Note that the tool is still in its BETA stage, therefore not all functionalities may be added.

[*]Right-click on
https://sites.google.com/site/cannedfixes/home/hosted-images-tools/MalwarebytesAntiRootkit.png
icon and select
https://sites.google.com/site/cannedfixes/home/hosted-images-tools/RunAsAdmin.jpg
Run as Administrator to start the tool.
[*]It will ask you for an extraction place - make sure you will unpack it to your desktop.
[*]After the extraction, the tool should start itself (no action required).
[*]On the Introduction screen click Next.
[*]On the Update screen click Update.
[*]When prompted about the succesful update, click Next.
[*]On the Scan System screen, make sure that all three options
[*]Drivers
[*]Sectors
[*]System
are checked for scanning and press Scan.

Wait patiently and don’t do anything on your machine while MBAR goes through your system!

[*]If no infection is found, just close the tool.
[*]If an infection is found, make sure that Create Restore Point is checked, then select Cleanup button to remove threats. The process will start and your machine will prompt you to reboot upon completion.

When finished (either with or without cleanup), please navigate to the MBAR directory.
Search there for these two files:

mbar-log-date(time).txt
system-log.txt
Please include the content of both files in your reply.

Evening… Scan came up clean but have no idea how to navigate to the MBAR directory to look for the logs you want. As stupid as that sounds, I’d love some instructions from anyone if need be :slight_smile:

Also thought I’d let you know that I have reset my modem back to the default settings which seems to have kept me online but as soon as I log into my Telstra account or Google for that matter I’m immediately disconnected and have to go through the process all over again. This seems to be about the only way I’m able to keep Avast updated to which is a pain…