Author Topic: Virus?? Rootkit?? H.e.l.p. ~ I'm Flunking Avast for "Super Dummies" {-101}  (Read 13742 times)

0 Members and 1 Guest are viewing this topic.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
But at least you can still smile - good attitude  ;D

MYSTIQUEOFINDY

  • Guest
But at least you can still smile - good attitude  ;D
Greetings Essexboy! Finally reinstalled Avast and did the MBR scan..taa dah! yep I saw one nasty red blazing line..is this the culprit? Also had a blue screen for my very first time ever. Posting it also. I removed HP's excess stuff and used CCleaner today and finally understood how it works. Bumping my Avast for dummies up to a D- "Hey! thats a major improvement for this lady  ;)" Back to class I go.

aswMBR version 0.9.7.777 Copyright(c) 2011 AVAST Software
Run date: 2011-07-19 22:38:04
-----------------------------
22:38:04.034    OS Version: Windows x64 6.1.7601 Service Pack 1
22:38:04.034    Number of processors: 1 586 0x602
22:38:04.034    ComputerName: TERRYS  UserName:
22:38:06.468    Initialize success
22:38:06.951    AVAST engine defs: 11071901
22:38:11.132    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0
22:38:11.132    Disk 0 Vendor: WDC_WD1600BEVT-60ZCT1 13.01A13 Size: 152627MB BusType: 11
22:38:11.210    Disk 0 MBR read successfully
22:38:11.210    Disk 0 MBR scan
22:38:11.210    Disk 0 unknown MBR code
22:38:11.226    Service scanning
22:38:21.475    Disk 0 trace - called modules:
22:38:21.491    ntoskrnl.exe CLASSPNP.SYS disk.sys ataport.SYS PCIIDEX.SYS hal.dll msahci.sys
22:38:21.506    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa80024d3060]
22:38:21.506    3 CLASSPNP.SYS[fffff880010f443f] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0xfffffa800248c060]
22:38:22.551    AVAST engine scan C:\Windows
22:38:25.515    AVAST engine scan C:\Windows\system32
22:40:55.369    AVAST engine scan C:\Windows\system32\drivers
22:41:11.016    AVAST engine scan C:\Users\Terry S
22:41:45.726    File: C:\Users\TerryS\AppData\Roaming\Bc\svhst.exe  **INFECTED** Win32:Dropper-gen [Drp]
22:43:42.680    AVAST engine scan C:\ProgramData
22:44:49.619    Scan finished successfully

22:46:16.027    Disk 0 MBR has been saved successfully to "C:\Users\Terry S\Desktop\MBR.dat"
22:46:16.027    The log file has been saved successfully to "C:\Users\Terry S\Desktop\aswMBR-7-19-11_scan.txt"

~ Blue Screen ~

Problem signature:
  Problem Event Name:   BlueScreen
  OS Version:   6.1.7601.2.1.0.768.3
  Locale ID:   1033

Additional information about the problem:
  BCCode:   a
  BCP1:   0000000000000000
  BCP2:   0000000000000002
  BCP3:   0000000000000001
  BCP4:   FFFFF80002A8F78C
  OS Version:   6_1_7601
  Service Pack:   1_0
  Product:   768_1

Files that help describe the problem:
  C:\Windows\Minidump\071911-33181-01.dmp
  C:\Users\TS\AppData\Local\Temp\WER-48141-0.sysdata.xml

Read our privacy statement online:
  http://go.microsoft.com/fwlink/?linkid=104288&clcid=0x0409

If the online privacy statement is not available, please read our privacy statement offline:
  C:\Windows\system32\en-US\erofflps.txt

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
OK lets kill that if Avast hasn't allready, once done could you run a fresh OTS scan please and let me know how your computer is behaving 

Start OTS. Copy/Paste the information in the quotebox below into the panel where it says "Paste fix here" and then click the Run Fix button.

Code: [Select]

[Unregister Dlls]

[Custom Items]
:Files
C:\Users\TerryS\AppData\Roaming\Bc\svhst.exe 
:end
[Empty Temp Folders]
[EmptyFlash]
[CreateRestorePoint]

The fix should only take a very short time. When the fix is completed a message box will popup telling you that it is finished. Click the Ok button and Notepad will open with a log of actions taken during the fix.  Post that information back here

I will review the information when it comes back in.

Depending on what the fix contains, this process may take some time and your desktop icons might disappear or other uncommon behavior may occur.

This is no sign of malfunction, do not panic!