Advertisement
If you have a new account but are having problems posting or verifying your account, please email us on hello@boards.ie for help. Thanks :)
Hello all! Please ensure that you are posting a new thread or question in the appropriate forum. The Feedback forum is overwhelmed with questions that are having to be moved elsewhere. If you need help to verify your account contact hello@boards.ie
Hi there,
There is an issue with role permissions that is being worked on at the moment.
If you are having trouble with access or permissions on regional forums please post here to get access: https://www.boards.ie/discussion/2058365403/you-do-not-have-permission-for-that#latest

Jeff

  • 23-04-2015 9:58pm
    #1
    Registered Users, Registered Users 2 Posts: 8


    Hello all,
    I had some form of malware on my win 7 pro 64 bit pc a month ago and it caused havok. I did a fresh install of my OS as I have done many times before and it has always sorted out whatever infection I had at the time. This time however it worked ok for a day or two and now my pc is showing the same symptoms ie printer stops communicating, system restore is turned off etc, my question is can malware, worms, bots etc hide in places OTHER than my harddrive to cause this sort of trouble.

    I was under the impression that a fresh OS installation always fixed the infection problem. any help or advice would be great. Thanks

    Jeff
    Tagged:


Comments

  • Registered Users, Registered Users 2 Posts: 840 ✭✭✭jsa112


    some rootkits can survive formats. more than likely you are using some external software like a USB that is re-infecting you.

    next time you're infected, we should run scans to see what might be responsible.


  • Registered Users, Registered Users 2 Posts: 8 JeffreyB


    Jsa, thank you for your response and apologies for the delay in responding to you, I was away from home with no internet access. I uninstalled my 360 Internet security and installed Avast virus protection software instead and did a boot time scan. I took about 2 hours but returned a clean bill of health.

    I am now noticing more programs that are behaving erratically and not responding so its worse that ever! I have run all the usual checks i.e. superantispyware, malwarebytes and ran a full scan of advanced systemcare pro 8.2 pro edition but to no avail. I have a question... If i buy a new hardrive and connect it to my system and set boot up in the Bios to run from optical drive, with my physical Win 7 pro disk installed will this be able to install a fresh OS in the new harddrive without being infected as well?...by the way I have not been connecting any external devices such as usb to my pc as you suggested. Thanks again for your advice and input.

    Regards

    Jeff


  • Registered Users, Registered Users 2 Posts: 840 ✭✭✭jsa112


    if avast or mbam aren't finding anything then its not a virus

    can you run dds and post its log so i can have a better look on the pc

    http://www.bleepingcomputer.com/download/dds/


  • Registered Users, Registered Users 2 Posts: 8 JeffreyB


    .
    UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
    IF REQUESTED, ZIP IT UP & ATTACH IT
    .
    DDS (Ver_2012-11-20.01)
    .
    Microsoft Windows 7 Professional
    Boot Device: \Device\HarddiskVolume1
    Install Date: 16/03/2015 22:24:18
    System Uptime: 26/04/2015 23:48:12 (1 hours ago)
    .
    Motherboard: MSI | | 970A-G46 (MS-7693)
    Processor: AMD FX(tm)-6300 Six-Core Processor | CPU 1 | 3500/200mhz
    .
    ==== Disk Partitions =========================
    .
    C: is FIXED (NTFS) - 699 GiB total, 532.047 GiB free.
    D: is CDROM ()
    .
    ==== Disabled Device Manager Items =============
    .
    Class GUID: {4d36e96b-e325-11ce-bfc1-08002be10318}
    Description: Standard PS/2 Keyboard
    Device ID: ACPI\PNP0303\4&12991451&0
    Manufacturer: (Standard keyboards)
    Name: Standard PS/2 Keyboard
    PNP Device ID: ACPI\PNP0303\4&12991451&0
    Service: i8042prt
    .
    Class GUID: {4d36e96f-e325-11ce-bfc1-08002be10318}
    Description: Microsoft PS/2 Mouse
    Device ID: ACPI\PNP0F03\4&12991451&0
    Manufacturer: Microsoft
    Name: Microsoft PS/2 Mouse
    PNP Device ID: ACPI\PNP0F03\4&12991451&0
    Service: i8042prt
    .
    ==== System Restore Points ===================
    .
    No restore point in system.
    .
    ==== Installed Programs ======================
    .
    7-Zip 9.20 (x64 edition)
    Adobe Flash Player 17 ActiveX
    Adobe Reader XI (11.0.10)
    Adobe Refresh Manager
    Advanced Uninstaller PRO - Version 11
    AMD APP SDK Runtime
    AMD Catalyst Install Manager
    AMD Fuel
    Apple Application Support (32-bit)
    Apple Application Support (64-bit)
    Apple Mobile Device Support
    Apple Software Update
    Asmedia ASM104x USB 3.0 Host Controller Driver
    Avast Free Antivirus
    Bonjour
    Call of Duty(R) 4 - Modern Warfare(TM)
    Catalyst Control Center
    Catalyst Control Center InstallProxy
    Catalyst Control Center Localization All
    ccc-utility64
    CCC Help Chinese Standard
    CCC Help Chinese Traditional
    CCC Help Czech
    CCC Help Danish
    CCC Help Dutch
    CCC Help English
    CCC Help Finnish
    CCC Help French
    CCC Help German
    CCC Help Greek
    CCC Help Hungarian
    CCC Help Italian
    CCC Help Japanese
    CCC Help Korean
    CCC Help Norwegian
    CCC Help Polish
    CCC Help Portuguese
    CCC Help Russian
    CCC Help Spanish
    CCC Help Swedish
    CCC Help Thai
    CCC Help Turkish
    CCleaner
    CLICKBIOSII
    ControlCenter
    Core Temp 1.0 RC6
    CPUID CPU-Z 1.65.1
    Creative ALchemy
    Creative Audio Control Panel
    Creative MediaSource 5
    Creative Software AutoUpdate
    Creative Sound Blaster Properties x64 Edition
    Creative WaveStudio 7
    Driver Booster 2.2
    Google Chrome
    Google Update Helper
    Heaven Benchmark version 4.0
    iTunes
    Java 8 Update 45
    Java Auto Updater
    Jing
    Lexmark 2400 Series
    Live Update 5
    Macrium Reflect Free Edition
    Magical Jelly Bean KeyFinder
    Microsoft .NET Framework 4.5.2
    Microsoft ASP.NET MVC 4 Runtime
    Microsoft Office File Validation Add-In
    Microsoft Office Professional Edition 2003
    Microsoft Silverlight
    Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
    Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
    MSI Fast Boot
    MSI Super Charger
    Nero 12 Kwik Burn Express Essentials
    Nero Blu-ray Player
    Nero ControlCenter
    Nero ControlCenter Help (CHM)
    Nero Core Components
    Nero Express
    Nero Express Help (CHM)
    Nero Kwik Media
    Nero Kwik Media Help (CHM)
    Nero Kwik Themes Basic
    Nero SharedVideoCodecs
    Nero Update
    NetworkGenie
    NVIDIA Control Panel 350.12
    NVIDIA GeForce Experience 2.4.1.21
    NVIDIA GeForce Experience Service
    NVIDIA Graphics Driver 350.12
    NVIDIA Install Application
    NVIDIA LED Visualizer 1.0
    NVIDIA Network Service
    NVIDIA PhysX
    NVIDIA ShadowPlay 2.4.1.21
    NVIDIA Update 2.4.1.21
    NVIDIA Update Core
    NVIDIA Virtual Audio 1.2.27
    OpenAL
    Origin
    PLDS OEM Content
    Prerequisite installer
    Realtek Ethernet Controller Driver
    Realtek High Definition Audio Driver
    ROCCAT Isku Keyboard Driver
    ROCCAT Kova[+] Mouse Driver
    Security Update for Microsoft .NET Framework 4.5.2 (KB2972107)
    Security Update for Microsoft .NET Framework 4.5.2 (KB2972216)
    Security Update for Microsoft .NET Framework 4.5.2 (KB2978128)
    Security Update for Microsoft .NET Framework 4.5.2 (KB2979578v2)
    Security Update for Microsoft .NET Framework 4.5.2 (KB3037581)
    SHIELD Streaming
    SHIELD Wireless Controller Driver
    Skype Click to Call
    Skype™ 7.0
    Smart Defrag 4
    SoundFont Bank Manager
    Speccy
    Steam
    SUPERAntiSpyware
    Surfing Protection
    TeamingGenie
    The Vanishing of Ethan Carter
    Thief
    Unigine Valley Benchmark version 1.0
    VideoGenie
    Winki
    .
    ==== Event Viewer Messages From Past Week ========
    .
    26/04/2015 23:48:39, Error: Service Control Manager [7000] - The NVIDIA Stereoscopic 3D Driver Service service failed to start due to the following error: The system cannot find the path specified.
    26/04/2015 23:47:47, Error: Service Control Manager [7043] - The AMD FUEL Service service did not shut down properly after receiving a preshutdown control.
    26/04/2015 23:47:14, Error: Service Control Manager [7043] - The Group Policy Client service did not shut down properly after receiving a preshutdown control.
    26/04/2015 19:04:11, Error: Service Control Manager [7023] - The Nero Update service terminated with the following error: %%-2147467262
    26/04/2015 19:01:17, Error: Service Control Manager [7034] - The Advanced SystemCare Service 8 service terminated unexpectedly. It has done this 1 time(s).
    26/04/2015 18:54:12, Error: Service Control Manager [7034] - The Proactive Defence service terminated unexpectedly. It has done this 1 time(s).
    26/04/2015 18:53:44, Error: Service Control Manager [7034] - The 360 Internet Security Real-time Protection Loading Service service terminated unexpectedly. It has done this 1 time(s).
    24/04/2015 01:14:46, Error: nvlddmkm [13] -
    23/04/2015 10:53:05, Error: Service Control Manager [7001] - The Task Scheduler service depends on the Windows Event Log service which failed to start because of the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
    22/04/2015 22:47:12, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Windows Search service to connect.
    22/04/2015 22:47:12, Error: Service Control Manager [7000] - The Windows Search service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
    22/04/2015 22:47:02, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1053" attempting to start the service WSearch with arguments "" in order to run the server: {9E175B6D-F52A-11D8-B9A5-505054503030}
    22/04/2015 22:46:42, Error: Service Control Manager [7031] - The Windows Search service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 30000 milliseconds: Restart the service.
    22/04/2015 22:46:42, Error: Service Control Manager [7024] - The Windows Search service terminated with service-specific error %%-1073473535.
    22/04/2015 17:23:21, Error: volmgr [46] - Crash dump initialization failed!
    21/04/2015 22:05:56, Error: Service Control Manager [7000] - The cpuz136 service failed to start due to the following error: The system cannot find the file specified.
    21/04/2015 22:00:28, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Steam Client Service service to connect.
    21/04/2015 22:00:28, Error: Service Control Manager [7000] - The Steam Client Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
    04/08/2015 00:25:09, Error: Microsoft-Windows-Time-Service [34] - The time service has detected that the system time needs to be changed by -10195199 seconds. The time service will not change the system time by more than 54000 seconds. Verify that your time and time zone are correct, and that the time source time.windows.com,0x9 (ntp.m|0x9|0.0.0.0:123->23.102.23.44:123) is working properly.
    .
    ==== End Of File ===========================


  • Registered Users, Registered Users 2 Posts: 8 JeffreyB


    here you go, a lengthy report maybe you can make sense of it.


  • Advertisement
  • Registered Users, Registered Users 2 Posts: 840 ✭✭✭jsa112


    it should have given you another file, its whereever you saved DDS


  • Registered Users, Registered Users 2 Posts: 8 JeffreyB


    it wont let me paste the report saying that as a new user I am not allowed to post URL's !!!


  • Registered Users, Registered Users 2 Posts: 840 ✭✭✭jsa112


    JeffreyB wrote: »
    it wont let me paste the report saying that as a new user I am not allowed to post URL's !!!

    Can you attach the file


  • Registered Users, Registered Users 2 Posts: 8 JeffreyB


    had to PM you and input the DDS report in 3 sections, it may not be very acurate but maybe it will be able to tell you something. I fully understand if this is too labour intensive for you and if you wish to terminate the thread I understand, once again thanks for your help

    Jeff


  • Registered Users, Registered Users 2 Posts: 840 ✭✭✭jsa112


    log didn't show much

    its not a virus issue, prob best off posting in the computer and technology forum


    sorry cant be much help


  • Advertisement
  • Registered Users, Registered Users 2 Posts: 8 JeffreyB


    no worries, I appreciate that you tried to help me. I reckon I'll buy a new HD and do another install, probably save me a lot of hassel, thank you again for your suggestions. cheers Jeff


Advertisement