I can't figgure if I have virus or not. The computer will run fine in safe mode, but within a few minuits of booting in normal mode the hard drive activiy on drive C and D goes to 100% (0% inactive). At this point the system is not usable. I have just enought time to run performance monitor to check this, before the system is tied up with disk activity.
I have Microsoft Securty Ecentuals installed. Can do a scan in safe mode and turns up nothing. Made a bootable CD with AVG on it and that scan turned up nothing also.
Any ideas? Not sure I can even do the scans that you ask for unless it they are done in safe mode.
Thanks for any help.
Hello and
My name is patndoris. I will be glad to take a look at your log and help you with solving any malware problems. It will be very helpful if you follow these guidelines:
Malware logs are often lengthy and can take a lot of time to research and interpret. Please be patient while I review your logs.
Please note that there is no "Quick Fix" to modern malware infections and we may need to use several different approaches to get your system clean.
Please make sure to carefully read any instruction that I give you. If you're not sure, or if something unexpected happens, do NOT continue! Stop and ask!
Please follow my instructions carefully and in the order they are posted. You may also find it helpful to print out the instructions you receive.
Please do not run any scans or install/uninstall any applications or delete anything without being directed to do so.
Remember, absence of symptoms does not mean the infection is all gone. Please stick with me till you're given the "all clear".
Please do not use the Attachment feature for any log file. Do a Copy/Paste of the entire contents of the log file and submit it inside your post.
Please reply within 3 days. If I do not hear back from you in that time frame, I will post a reminder for you. Topics with no reply in 4 days are closed!
Please be advised I am still in training, and all of my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advice.
This may cause a delay in response time, but I will do my best to keep it as short as possible.
I am aware you are only running tools in safe mode. and that's quite alright. At least for the moment we will be using tools that work in Safe Mode. In order to download them you will need to run Safe Mode with Networking. It would be advisable to avoid surfing the net when you are running in Safe Mode with Networking as your security programs will not be running and you will not be protected.
Since you have Windows 7, you will always want to right-click and choose "run as administrator" to launch any tools we use.
Download and Run DDS by sUBs
Please download DDS by sUBs from one of the following links and save it to your desktop.
Right click the DDS icon and choose Run as Administrator to run the tool (may take up to 3 minutes to run)
When done, DDS.txt will open.
After a few moments, attach.txt will open in a second window.
Save both reports to your desktop.
—————————————————
Post the contents of the DDS.txt report in your next reply
Attach the Attach.txt report to your post by scroling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.
Can you please advise if you are actually running anything from the additional drives that you disconntected. Were any of them flash drives, external hard drives that might regularly be accessed, or another internal drive that you are using regularly? Or was it just a system recovery drive?
The system has 3 hard drives. C - 750G SATA, D - 750G SATA, W - 500G IDE. I use dirve D for data and picture storage. I used drive W for storage of the old system when I went from XP 64 bit to 7 64 bit. This was done over a year ago and I have not been using drive W since. When I had all three drives in the system, Drive C & D would be 100% active and drive W would be at 0% active. Since the system was on C and it had 100% activity all the time, the system would come to a crawl and was not usable.
Did the scan show anything?
* It promotes its toolbars on sites targeted at kids.
* It promotes its toolbars through ads that appear to be part of other companies' sites.
* It promotes its toolbars through other companies' spyware.
* It is Installed without any disclosure whatsoever and without any consent from the user whatsoever.
* It solicits installations via "deceptive door openers" that do not accurately describe the offer; failing to affirmatively show a license agreement; linking to a EULA via an off-screen link.
* It makes confusing changes to user's browsers - increasing Ask's revenues while taking users to pages they didn't intend to visit.
The reason I asked about your other drives is that it is possible for malware to originate on another drive. Right now, let's concentrate on the C: drive and make sure that is clean.
Please download Malwarebytes' Anti-Malware to your desktop.
Double-click mbam-setup.exe and follow the prompts to install the program.
At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
If an update is found, it will download and install the latest version.
Once the program has loaded, select Perform quick scan, then click Scan. [external image: Posted Image]
When the scan is complete, click OK, then Show Results to view the results.
Be sure that everything is checked, and click Remove Selected.
When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Let's try a different tool. If you can run this in normal mode it would be best, but if for some reason you are not able to, then you can run it in Safe Mode if necessary.
If you have CDEmulation drivers installed (such as Daemon Tools, Alcohol120) please follow the instructions below to run DeFogger prior to and after running GMER. If you do not have any CDEmulation drivers installed, you do not need to run DeFogger and you can go right to the instructions to run GMER.
Download DeFogger
Please download DeFogger to your desktop.
Double click DeFogger to run the tool.
The application window will appear
Click the Disable button to disable your CD Emulation drivers
Click Yes to continue
A 'Finished!' message will appear
Click OK
DeFogger will now ask to reboot the machine - click OK
IMPORTANT! If you receive an error message while running DeFogger, please post the log defogger_disable which will appear on your desktop.
Do not re-enable these drivers until otherwise instructed.
Download and Run GMER
[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
Extract the contents of the zipped file to desktop.
Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.
In the right panel, you will see several boxes that have been checked. Uncheck the following …
IAT/EAT
Drives/Partition other than Systemdrive (typically C:\)
Show All (don't miss this one)
Then click the Scan button & wait for it to finish.
Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
Save it where you can easily find it, such as your desktop, and attach it in your reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
Well I don't think that did much. Here are the results:
Gmer did not find anything.
defogger_disable by jpshortstuff (23.02.10.1)
Log created at 17:48 on 18/01/2011 (Dad)
Checking for autostart values…
HKCU\~\Run values retrieved.
HKLM\~\Run values retrieved.
Checking for services/drivers…
-=E.O.F=-
You won't have seen any difference in your machine at this point because we have been running the tools to look for infections. So far, there is no indication the issues on your machine are related to malware.
I'm assuming you've not hooked up the other drives at this point. I do think it is important that we scan them just one time to ensure there is no malware on the other drives that is affecting the overall system performance - especially since removing them improved your system. After you have them reinstalled (even if you must boot into safe mode) please do the following:
Launch Malwarebytes again.
Please choose "Perform full scan".
Click Scan
When the window pops up showing you all your drives, ensure they are all checked
Click Scan
When the scan is complete, click OK, then Show Results to view the results.
Be sure that everything is checked, and click Remove Selected.
When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Ok, I hooked up drives D and W and still can not run windows in normal mode. I did a scan in safe mode and it did find a few things on drive D. I had it remove what it found and rebooted and I still can not run in normal mode. Did another scan in safe mode and it found nothing this time. Here are the logs:
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org
Database version: 5542
Windows 6.1.7600 (Safe Mode)
Internet Explorer 8.0.7600.16385
1/19/2011 7:36:55 PM
mbam-log-2011-01-19
Scan type: Full scan (C:\|D:\|W:\|)
Objects scanned: 681807
Time elapsed: 1 hour(s), 5 minute(s), 58 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 3
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
d:\Kayak_D\program files\Spinway\bluelight\pager-ie.exe (Heuristics.Shuriken) -> No action taken.
d:\Kayak_D\program files\Spinway\bluelight\BACKUP\pager-ie.exe (Heuristics.Shuriken) -> No action taken.
d:\Kayak_D\WinNT\uninstall\$ntservicepackuninstall$\iasrad.dll (Spyware.PWS) -> No action taken.
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org
Database version: 5542
Windows 6.1.7600 (Safe Mode)
Internet Explorer 8.0.7600.16385
1/19/2011 8:53:47 PM
mbam-log-2011-01-19 (20-53-47).txt
Scan type: Full scan (C:\|D:\|W:\|)
Objects scanned: 681810
Time elapsed: 1 hour(s), 5 minute(s), 21 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
After analyizing the results of the scans we have done, I do not see any evidence that the problems you are experiencing are related to malware. Since the problem was alleviated when you disconnected the other drives, there is a possibility it is a hardware related issue. I would like to direct you to our General Hardware Forum where you can receive assistance with further troubleshooting on what the problem may be.
Feel free to link them to this post if they need to refer to any of the information contained here. If they are unable to help you, you can feel free to post back here and we can try to dig deeper.
✨ Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI