Go Back   Tech Support Forum > Security Center > General Computer Security

I might have a virus/trojan/spyware.. Need help, please

This is a discussion on I might have a virus/trojan/spyware.. Need help, please within the General Computer Security forums, part of the Tech Support Forum category. Hello Techsupport I am new around here and I need guidance to solve an older Windows-Mystery of mine. I didn't

Closed Thread
Thread Tools Search this Thread
Old 03-06-2012, 09:41 AM   #1
Registered Member
Join Date: Mar 2012
Posts: 15
OS: Windows 7 Home Premium 64-bit Service Pack 1

Hello Techsupport

I am new around here and I need guidance to solve an older Windows-Mystery of mine. I didn't posted in the "virus/trojan/spyware help" in the first place because I'm not sure if my system is infected or not, and I don't want to disturb the hard-working-experts with a false alarm so I hope I can find an answer here after I explain my problem... and then I'll go to the other board for help.

So... I have a Samsung laptop running Windows 7 Home Premium 64-bit Service Pack 1. Last autumn, I think it was the end of October, I got an USB flash drive from a buddy and unlucky for me, there were some serious trouble on that device. Back then I was using Norton Internet Security 2011 and all the autoruns malware-stuff were busted, or at least this is what NIS said that time.

In January, I did some serious checking with various anti-virus/anti-spyware/anti-malware/anti-trojan software including Norton IS, Comodo IS, Comodo Cleaning Essentials, Microsoft Security Essentials (even Windows Defender), Malwarebytes Anti-Malware, Emsisoft Anti-Malware, SuperAntiSpyware, Spybot S&D, HitmanPro, BitDefender, ESET Smart Security, Microsoft Safety Scanner, Kaspersky Virus Removal Tool, Kaspersky Anti-virus 2012, Ad-Aware and... I can't remember if there is anything else. The thing is... Some of them like MBAM, Emsisoft, Hitman, Comodo and Kaspersky found more ugly files so I deleted all of them.

For a while I was relieved, thinking that my system is safe. Now I find out about this new "rootkit" type of malware and start googling over and over to find some useful information. This is how I got here too...

I followed the tips on this thread and... I think I might have some left-overs or worst.

1. I can't run GMER! Searched on google and found out that this app doesn't run on 64-bit systems and I have a Win7 64-bit version... What alternative do I have?

1.5 As I was searching for the GMER problem with 64bit systems I found a thread were some guys were saying that 64-bit Operating Systems are much harder to infect with rootkit and the changes for this to happen are very low. Is this true?

2. DDS worked but I don't understand much of the log... Is there a guide or smth like "How to read a DDS log for dummies" ?

3. I use the Sysinternals Suite and there is a RootkitRevealer in there which I haven't tried until today... It didn't start. Seems it's a XP/Server '03 compatible only. Is there any W7 64bit version?

4. I saw some other apps on the GMER site and tried catchme and mbr to see if they find something. MBR was getting errors like...
user: error reading MBR 
error: Read  The handle is invalid.
kernel: error reading MBR
and catchme found some "NTDLL code modification" like...
ZwEnumerateKey 0 != 47, 
ZwQueryKey 0 != 19, 
ZwOpenKey 0 != 15
and other stuff like those Zw-things. Why doesn't the MBR work? On a board someone was saying that "NTDLL code modification" is a evidence of a trojan, is this true?

I must mention that I had used TuneUp Utilities, don't why I mention this but it may probably have a connection with those NTDLL?

Now I have Kaspersky Anti-virus 2012 and Comodo Firewall (with Defense+).

Can someone help me out with this, please?

alex2919 is offline  
Sponsored Links
Old 03-06-2012, 10:09 AM   #2
TSF Enthusiast
Deleted 080713's Avatar
Join Date: Jun 2008
Location: London UK
Posts: 4,966
OS: Windows 7 SP1 x64

Hi alex2919,

We don't provide malware removal advice in this section, I appreciate you're not sure whether you're infected, but we're unable to advise until we see proper logs. Please re-read the thread below, and follow the instructions carefully. GMER is not compatible with 64bit systems, and there is no need for you to run it.

64 Bit systems can still be infected with current rootkits out there, but are usually infected in a different way to 32 bit systems.

For malware removal assistance....

Please follow our pre-posting process outlined here:

NEW INSTRUCTIONS - Read This Before Posting For Malware Removal Help - Tech Support Forum

After running through all the steps, please post the requested logs in the Virus/Trojan/Spyware Help forum, not here.

If you have trouble with one of the steps, simply move on to the next one, and make note of it in your reply.

Please note that the Virus/Trojan/Spyware Help forum is extremely busy, and it may take a while to receive a reply.
Deleted 080713 is offline  
Old 03-06-2012, 11:04 AM   #3
Registered Member
Join Date: Mar 2012
Posts: 15
OS: Windows 7 Home Premium 64-bit Service Pack 1

Thank you for your guiding in solving my problem.
I'll post my logs in the proper forums.
alex2919 is offline  
Old 03-06-2012, 11:28 AM   #4
Moderator Offline
Basementgeek's Avatar
Join Date: Feb 2005
Location: Ohio, USA
Posts: 14,429
OS: XP Pro SP3/Vista Ultimate SP2/Win7 64 bit


Since you have posted in our Virus/Trojan/Spyware Help forum, this topic is closed now.


ASAP member since 2006

Four boxes keep us free: the soap box, the ballot box, the jury box, and the cartridge box.

Basementgeek is offline  
Closed Thread

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Similar Threads
Thread Thread Starter Forum Replies Last Post
Please help me get back windows 7!!!!
Hi!! I installed windows 8 out of pure couriosity, and wanted initially to install it on my USB (which is formatted to RAW now so I can't format it -.- but that aside...). Windows wouldn't let me install it on my usb so I installed it as a dual boot (so I thought). However, windows 8 chose to go...
teamseacow Windows 8, 8.1 Support 4 04-13-2012 07:05 AM
Need a service request script
I'm new to web design etc. and my website is about Computer Repair. I've been doing alot of googling but have had no luck on finding a script that will allow my customer to fill out, that has a drop down box that allows the user to select which service they are requesting and then I have different...
danh30 Web Design & Development 3 03-11-2012 06:25 PM
HELP Anitvirus 2012 attack now unable to get IP Address
Hello everyone. Im a Newbie. I have a Windows Dell Dimension 4600 running XP svc 3. Its a wired internet connection. So a couple of months ago I got the Antivirus 2012 which took over my browser. At the time of the infection I had AVG and Malwarebytes on the computer. I ran both programs and...
happynewmamma Virus/Trojan/Spyware Help 13 03-09-2012 08:39 PM
My CD ROM doesn't come up. I have a Dell running with Windows XP. I can I fix it?
I have Dell Desk top PC, with Window XP, and as of yesterday my CD ROM is not coming up. Some how I lost it. How do I correct this problem?
NeedHelp1852 Windows XP Support 3 03-06-2012 01:19 PM
[SOLVED] The file does not have a program associated with it to perform this action
Hey, I borrowed my friend's pen drive, and am unable to open it. I went to my computer, clicked on the removable disk folder. It says "The file does not have a program associated with it to perform this action. Create an association in the Folder options control panel." I went to the folder...
meyes Removable Media Drives 1 03-06-2012 06:48 AM

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is on
Smilies are on
[IMG] code is on
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off

Post a Question

» Site Navigation
 > FAQ

All times are GMT -7. The time now is 05:04 AM.

vBulletin Security provided by vBSecurity v2.2.2 (Pro) - vBulletin Mods & Addons Copyright © 2017 DragonByte Technologies Ltd.
Copyright 2001 - 2015, Tech Support Forum

Windows 7 - Windows XP - Windows Vista - Trojan Removal - Spyware Removal - Virus Removal - Networking - Security - Top Web Hosts


Partially Powered By Products Found At Lampwrights.com