runouce.exe

Discussion in 'Malware Help (A Specialist Will Reply)' started by vwbus71, Oct 25, 2009.

  1. vwbus71

    vwbus71 Private E-2

    Hello
    I have an HP Pavillion 1100y running wingows XP SP3. In the task manager I have a process called "runouce.exe" running. I noticed after I tried to start firefox and it wouldn't load. I went through the READ AND RUN MY FIRST procedures.

    Niether combofix nor MGTools would run. I was able to scan with Malwarebytes, Super Antispyware and Root Repeal. Below are the attached logs.

    Thanks in advance
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What problem did you have trying to run MGTools? Did you get an error message?

    If it is still where it should be installed ( C:\MGTools.exe ) then please try double clicking the C:\MGTools\SN64.bat. If it runs, then attach the C:\MGLogs.zip.
     
  3. vwbus71

    vwbus71 Private E-2

    Thanks for the reply.

    When I Ran Combofix and MGTools origanlly, the curser would be change to "working", and then nothing would happen, as if I didn't try to run anything. This happens with firefox and any antivirus software I try to run. There were no error messages.

    Then I tried To run SN64.bat Like you requested, and explorer.exe shut down and reloaded, closeing all other programs and windows.

    Then I decided I would try in safe mode. As windows was shutting down I got an error code.

    svchost.exe - Application Error
    The Instrution at "0x77dd7426" referenced memory at :0x77dd7426". The memory could not be written.

    I clicked ok to terminate.

    Then I rebooted into Safe Mode to try SN64.bat and got the same result as before. For the heck of it I tried to run MGTools again, and this time it worked! I have no idea why it wouldn't work before, as I did try to run it in regular windows and Safe Mode.

    Below is the zip file created by MGTools.
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let's start by doing this:

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now use windows explorer to find and delete:
    C:\WINDOWS\system32\runouce.exe

    Now see if you can run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\MGlogs.zip
     
  5. vwbus71

    vwbus71 Private E-2

    Thanks for the reply.

    First off, the virus won't allow my antivirus program to run, so no need to disable that.

    I created the file fixME.reg as instructed, and when I double clicked on it, explorer.exe shut down and restarted. After this happened, I got a new file on my desktop titled "readme.eml" which is highly suspicious, since I don't use outlook for my email. I will do nothing to this file untill instructed to do so.

    I am quite certain fixME.reg did not work because I did not recieve a success message.

    Then I tried to delete runouce.exe from the system32 folder, and I got an error message - "Can not delete runouce.exe: It is being used by another person or program"

    Then tried to run getlogs.bat, and got the same response as when I tried to run the fixME.reg file.

    I also tried to do all of this in safe mode with exactly the same results.
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Download The Avenger by Swandog469, and save it to your Desktop.

    * Extract+ avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * -Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\Avenger.txt
    * C:\MGlogs.zip

    Let me know it that works.
     
  7. vwbus71

    vwbus71 Private E-2

    Ran avenger as instructed and after I hit execte, the program shut down without asking to reboot, so I did so myself.

    Found the log by avenger and tried to run getlogs.bat, and this shut down explorer.exe and reloaded.

    Also the log from avenger did not popup as you said it would after reboot.

    Attached is the avenger log
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Avenger removed two of the items. Let's try a different approach.

    Please try doing the below:

    Download and save the below to your PC (save it anywhere you can find it. The Desktop is fine). Then doube click on it to run it.

    AVPFind.bat

    It should take a couple minutes to run. You will see a black command prompt window while it is running and it should close when it is finished. Once it finishes, attach the c:\avplog.txt file that is will hopefully create as long as the malware does not block the batch file from running.


    Now download and Run exeHelper

    • Please download exeHelper to your desktop.
    • Double-click on exeHelper.com to run the fix.
    • A black window should pop up, press any key to close once the fix is completed.
    • Post the contents of log.txt (Will be created in the directory where you ran exeHelper.com)

    Note: If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).


    Also please try running the below online scan:

    http://www.superantispyware.com/onlinescan.html

    Reboot immediately after scanning if it finds and removes anything. Let me know if anything was found. It does not save a log.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).


    Attach the below logs when finished with all of the above:

    • C:\avplog.txt - from AVPfind
    • log.txt - from exeHelper
    • C:\MGlogs.zip - from MGtools

    The C:\ assumes that drive C is you Windows boot drive. If you boot from another drive, then use the correct drive letter above.
     
  9. vwbus71

    vwbus71 Private E-2

    downloaded avpfind.bat and double-clicked, explorer.exe shut down and reloaded. No log file was created.

    Next ran exehelper.exe and ran fine and created a log file which is attached below.

    Tried to do the online scan and the virus prevented it to run.

    fixME.reg also shudown explorer.exe as well as getlogs.bat
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  11. vwbus71

    vwbus71 Private E-2

    Ran sysprot as instructed and about 5 seconds after hitting the create log button, my machine shutdown and rebooted. It did create a log which is attached.

    Then ran win32diag and that ran fine.

    Tried to run getlogs.bat using inhert.exe, and explorer.exe shut down and reloaded.
     

    Attached Files:

  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Sigh....sometimes I think I need a nap.

    * Run avenger.exe by double-clicking on it.
    * -Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\Avenger.txt
    * C:\MGlogs.zip
     
  13. vwbus71

    vwbus71 Private E-2

    I truely appreciate your help. Thank you.

    Ran avenger and rebooted.

    When windows was starting up, after the Winxp splash screen, my computer frooze on a black screen for about 10 seconds and then rebooted again. after this boot, windows started normally.

    getlogs.bat shut down explorer.exe again.

    attached is the avenger log.
     

    Attached Files:

  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are way out of date with your version of SUPERAntiSpyware.

    • Please uninstall your current version (this is necessary).
    • Then download this SUPERAntiSpyware
    • Install this new version. It may tell you that you need to reboot to complete the installation. You must reboot at this time.
    • After the reboot, run SUPERAntiSpyware and immediately click the Check for Updates button to get more updates for the database.
    • Now run a new full scan of your system. And attach this new log.

    Now run Malwarebytes and click the Update tab. Then click the Check for Updates button so you update to the current version of the program and database. Then run a new scan with it too. Attach the new log.

    Now Click Start, Run, and enter cmd and click OK. This will open a command prompt Window. In the command prompt Window, enter the below commands each followed by the enter key:

    ver > c:\ver.txt
    dir C:\MGtools > C:\flist.txt

    Now attach the C:\ver.txt and C:\flist.txt files here. Note there is a space after the dir and before the >

    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
     
    Last edited: Nov 2, 2009
  15. vwbus71

    vwbus71 Private E-2

    Did as you instructed for SAS and everything ran fine. Log file attached

    When I tried to update Malwarebytes, I was not able to update, "error code:732(0,0)" I uninstalled the program and downloaded the new program file, and got the same error code. The definitions version was dated 9/10/09.

    Everything else instructed ran with no problems. Below are the attached logs.
     

    Attached Files:

  16. vwbus71

    vwbus71 Private E-2

    The avenger log
     

    Attached Files:

  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Are you still unable to run the getlogs.bat?
     
  18. vwbus71

    vwbus71 Private E-2

    I ran getlogs.bat, but kept getting an error message. I attached a screenshot so you could see. No Files in the existing mglogs.zip had been modified.

    I moved the existing MGLogs.zip to my desktop and MGTools.exe again and created a New MGLogs.zip file which I attached.

    thanks.
     

    Attached Files:

  19. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good!! We are now getting somewhere.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    * Run avenger.exe by double-clicking on it.
    * -Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now run Ccleaner to clean out only temp files and nothing else!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    * C:\Avenger.txt
    * C:\ComboFix.txt
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  20. vwbus71

    vwbus71 Private E-2

    Ran analyse.exe and did as instructed. After I clicked fix, I did another scan and this was not removed.
    Saved the fixME.reg File and did recieve a success message.

    Then ran avenger and rebooted. The log file is attached. Combofix.exe did not run, nor would it run when Itried to double click it afterward.

    Ccleaner would also not ru, but I do have a copy of Ccleaner slim an a flashdrive that would run nad I completed that step.

    Ounce again I got the same error when running Getlogs.bat as I did before. None of the files in the zip had been modified. I did not run mgtools.exe again because I didn't know if I should. Let me know If you would like me to do so.

    Also one other thing, there is a process running at times that uses around 20-30 percent of my cpu. Its called net.exe and also net1.exe. Don't know if this is helpful or not, just thought I would tell you.
     

    Attached Files:

    Last edited: Nov 8, 2009
  21. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    My mistake.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    * Run avenger.exe by double-clicking on it.
    * -Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now please try to run the getlogs.bat. and attach both the MGLogs.zip and the Avenger log.
     
  22. vwbus71

    vwbus71 Private E-2

    Thanks for the quick reply.

    Ran avenger.exe and attached the log.

    Again I got the same error as before with getlogs.bat. It is creating the logs just not adding them to the zip file. So I decidedto make my own zip file and include the logs. Hopefully I did it correctly. Below id the attached zip filed which I named differently so It won't get mixed up with the origan mglogs.zip. I f I am missing a log please let me know and I will upload it.

    Thanks again.
     

    Attached Files:

  23. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let's try it this way even though Avenger is saying it is removing it:

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    * Run avenger.exe by double-clicking on it.
    * -Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    You need to move your MGLogs.zip from your desktop back to the C:\drive where the MGTools.exe is.
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\Avenger.txt
    * C:\MGlogs.zip

    *Fingers crossed!!
     
  24. vwbus71

    vwbus71 Private E-2

    Avenger log attached.

    The file on the desktop is "oldmglogs.zip" which I renamed after moving it to the desktop when I ran mgtools.exe a day ago. The new mglogs.zip was in the root folder. I have deleated the old zip file.

    I got the same error when I ran getlogs.bat. This seems to be a problem with zip.exe.

    A better screenshot than the I attached earier is included.

    Could this be due to the maleware or something else? Since getlogs.bat did not append the mglogs.zip file, I have replaced he old logs in the zip file I sent in the previous post and attached the new zip file.
     

    Attached Files:

  25. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I will need to discuss this with Chaslang. :(
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Click Start, Run, and enter cmd and click OK. This will open a command prompt window. Type in the below commands each followed by the enter key. There is a space after the cd

    cd C:\MGtools
    zip

    After typing zip, is the below what you see:
    Code:
    C:\MGtools>zip
    Copyright (C) 1990-1999 Info-ZIP
    Type 'zip "-L"' for software license.
    Zip 2.3 (November 29th 1999). Usage:
    zip [-options] [-b path] [-t mmddyyyy] [-n suffixes] [zipfile list] [-xi list]
      The default action is to add or replace zipfile entries from list, which
      can include the special name - to compress standard input.
      If zipfile and list are omitted, zip compresses stdin to stdout.
      -f   freshen: only changed files  -u   update: only changed or new files
      -d   delete entries in zipfile    -m   move into zipfile (delete files)
      -r   recurse into directories     -j   junk (don't record) directory names
      -0   store only                   -l   convert LF to CR LF (-ll CR LF to LF)
      -1   compress faster              -9   compress better
      -q   quiet operation              -v   verbose operation/print version info
      -c   add one-line comments        -z   add zipfile comment
      -@   read names from stdin        -o   make zipfile as old as latest entry
      -x   exclude the following names  -i   include only the following names
      -F   fix zipfile (-FF try harder) -D   do not add directory entries
      -A   adjust self-extracting exe   -J   junk zipfile prefix (unzipsfx)
      -T   test zipfile integrity       -X   eXclude eXtra file attributes
      -!   use privileges (if granted) to obtain all aspects of WinNT security
      -R   PKZIP recursion (see manual)
      -$   include volume label         -S   include system and hidden files
      -h   show this help               -n   don't compress these suffixes
    C:\MGtools>
    Now type exit in the command prompt window to close the command prompt.


    Now Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.

    Let's see if we can manually update by downloading and running this: MBAM_RULES

    If that does not help, see Issue # 8 here: http://www.malwarebytes.org/forums/index.php?showtopic=10138

    If you get it to update, run a new scan and fix what it finds and attach the new log.

    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )

    Then attach the below logs:
    • the new log from Malwarebytes if it updated
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
    If MGtools still does not create the MGlogs.zip file itself, please just put the below logs into a ZIP yourself and attach it. These are the only ones we need now:
     
  27. vwbus71

    vwbus71 Private E-2

    Thanks for the help.

    everything ran as it should have, except for ccleaner, which I had to run from my flashdrive since the one on my harddrive would not.

    I see that you wanted to delete the "readme.eml" on my desktop. I did a search on my harddrive, and found 252 copies of this file. It seems each file is created everytime i boot my machine.

    Below are the logs you requested.
     

    Attached Files:

  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not answer my question about running zip?

    It looks like MGtools is running okay now though.

    Yes these all need to be deleted they are how the infection keeps respawning.


    Now download Registry Search (see the link titled RegSearch Download Link )
    • Extract the files from Regsearch.zip into a folder.
    • Doubleclick regsearch.exe to start the program.
    • See the top 3 boxes under the Enter search strings (case independen) and click Ok... option, and enter the below two strings (use copy and past)
      • runouce
      • readme.eml
    • Then click "OK".
    • Notepad will be opened with text in it (the file named RegSearch.txt will be saved in the program's folder as well).
    • Attach this RegSearch.txt file.
     
    Last edited: Nov 8, 2009
  29. vwbus71

    vwbus71 Private E-2

    Sorry about not answering your question. I read it as "below is what you should see" instead of "is below what you see?"

    Yes, that is what I saw.

    What is the best way to delete those files? Can I just delete them through the search window, then empty the recycle bin, then run ccleaner? Or is there a better way to do it so they don't appear again?

    Thanks

    Oops, I'm rushing things. I didn't read the rest of your post. I will do that now.
     
    Last edited: Nov 8, 2009
  30. vwbus71

    vwbus71 Private E-2

    Ran registry search and attached the log.
     

    Attached Files:

  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Since more of the infection is still present, we will have to build a fix. The RegSearch is one piece of info I need. Below is another.

    Download and save the below to your PC (save it anywhere you can find it. The Desktop is fine). Then double click on it to run it.

    Findit.bat

    This may take awhile to run since it will be searching thru your whole hard disk. When it finishes, there should be a C:\badfiles.txt log. Attach this log.
     
  32. vwbus71

    vwbus71 Private E-2

    when I try to download I get error 404:File not found
     
  33. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Click refresh and try it again. After you get this log (not before), please run the below tool and let me know if it finds and removed anything.

    McAfee AVERT Stinger
     
  34. vwbus71

    vwbus71 Private E-2

    Double clicked on findit.bat and it ran for about 5 seconds then shut down. No log file was created.

    Did not run McAfee AVERT Stinger.

    EDIT: I found a "badfiles.txt" in the MGTools folder. I am attaching that now.
     

    Attached Files:

  35. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just run the Stinger and then run the below tools from Symantec. This worm can be quite nasty and may have damaged/infected many Windows system files. Sometimes with infections like this, a reinstall becomes necessary.

    W32.Nimda.A mm Removal Tool

    W32.Nimda.E mm Removal Tool
     
  36. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes that was where it was supposed to be. I was supposed to say C:\MGtools\badfiles.txt

    Just run the scans from McAfee and Symantec so we can see what they find.
     
  37. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    And for your information you should read the below about this infection especially if you use this PC on a network with other PCs. They may all be infected now.

    http://www.f-secure.com/v-descs/nimda.shtml

    F-Secure also provides another free removal tool which you will see in the above link.
     
  38. vwbus71

    vwbus71 Private E-2

    Alright, that took a long time.

    ran stinger, and it found ALOT of infected files:

    Number of clean files: 393616
    Number of infected files: 24
    Number of files repaired: 715
    Number of files deleted: 23

    c:\129344b9af80ce656f1ee7\DHtmlHeader.html could not be repaired

    ran both Fxnimda.com and fxnimdaE.com. Attached is the log.

    Also, I tranfered a bunch of music and video files as well as some documents to an external drive. This driv does have a few .exe files. After transfering the files, I unpluged the drive but from reading the link you posted it sounds like it could be infected. I have not run any of the scans on this drive. If i get windows clean of maleware or I do a clean install, could it be reinfected from the external drive when I plug it in? If so, is there a safe way to clean it without having to format it. I've got around 120 gigs of files that I would rather not lose.

    Thanks for the help.
     

    Attached Files:

  39. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Based on all the items being found, I would not trust this PC anymore. You really should just reinstall.

    Yes it could be carrying the infection. You could try running the scanning tools I gave you links to on this drive just to see what is found. I would suggest running the F-Secure one too.

    Most likely not as soon as you plug it it, but more likely if you install or run anything from the drive that carries the infection which is why I say to scan it first before reinstalling. And then after the reinstall and with your external drive connect, rescan with ALL these tools again.

    You could take the chance on running all these tools multiple times until they come up clean but there are no guarantees so it depends on how safe you want to be. Also there is still a chance that you will have system instability especially if any required system or program files cannot be cleaned and need to be deleted. There is always the chance that somewhere during the cleaning, your system could become unbootable.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds