This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

100% disk active

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I can't figgure if I have virus or not. The computer will run fine in safe mode, but within a few minuits of booting in normal mode the hard drive activiy on drive C and D goes to 100% (0% inactive). At this point the system is not usable. I have just enought time to run performance monitor to check this, before the system is tied up with disk activity. I have Microsoft Securty Ecentuals installed. Can do a scan in safe mode and turns up nothing. Made a bootable CD with AVG on it and that scan turned up nothing also. Any ideas? Not sure I can even do the scans that you ask for unless it they are done in safe mode. Thanks for any help.
Hello and Posted Image
My name is patndoris. I will be glad to take a look at your log and help you with solving any malware problems. It will be very helpful if you follow these guidelines:
  • Malware logs are often lengthy and can take a lot of time to research and interpret. Please be patient while I review your logs.
  • Please note that there is no "Quick Fix" to modern malware infections and we may need to use several different approaches to get your system clean.
  • Please make sure to carefully read any instruction that I give you. If you're not sure, or if something unexpected happens, do NOT continue! Stop and ask!
  • Please follow my instructions carefully and in the order they are posted. You may also find it helpful to print out the instructions you receive.
  • Please do not run any scans or install/uninstall any applications or delete anything without being directed to do so.
  • Remember, absence of symptoms does not mean the infection is all gone. Please stick with me till you're given the "all clear".
  • Please do not use the Attachment feature for any log file. Do a Copy/Paste of the entire contents of the log file and submit it inside your post.
  • Please reply within 3 days. If I do not hear back from you in that time frame, I will post a reminder for you. Topics with no reply in 4 days are closed!
Please be advised I am still in training, and all of my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advice.
This may cause a delay in response time, but I will do my best to keep it as short as possible.

I will post back shortly with instructions.
I am aware you are only running tools in safe mode. and that's quite alright. At least for the moment we will be using tools that work in Safe Mode. In order to download them you will need to run Safe Mode with Networking. It would be advisable to avoid surfing the net when you are running in Safe Mode with Networking as your security programs will not be running and you will not be protected.

Since you have Windows 7, you will always want to right-click and choose "run as administrator" to launch any tools we use.


Download and Run DDS by sUBs

Please download DDS by sUBs from one of the following links and save it to your desktop.
    • DDS.scr
    • DDS.pif
  • Disable any script blocking protection (How to Disable your Security Programs)
  • Right click the DDS icon and choose Run as Administrator to run the tool (may take up to 3 minutes to run)
  • When done, DDS.txt will open.
  • After a few moments, attach.txt will open in a second window.
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scroling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.
I was able to disconect all hard disk's except C and get the system to run again in normal mode. Not sure why that would make a diffrence, but it did. Thanks for your help. Here is the DDS file: DDS (Ver_10-12-12.02) - NTFS_AMD64 Run by [removed] at 15:07:49.27 on Sun 01/16/2011 Internet Explorer: 8.0.7600.16385 Microsoft Windows 7 Professional 6.1.7600.0.1252.1.1033.18.4095.2470 [GMT -5:00] AV: Microsoft Security Essentials *Enabled/Updated* {BF5CEBDC-F2D3-7540-343C-F0CE11FD6E66} SP: Microsoft Security Essentials *Enabled/Updated* {043D0A38-D4E9-7ACE-0E8C-CBBC6A7A24DB} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ============== Running Processes =============== C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\nvvsvc.exe C:\Windows\system32\svchost.exe -k RPCSS c:\Program Files\Microsoft Security Essentials\MsMpEng.exe C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\svchost.exe -k apphost C:\Windows\system32\CISVC.EXE C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe C:\Windows\system32\svchost.exe -k ftpsvc C:\Windows\SysWOW64\svchost.exe -k hpdevmgmt C:\Windows\system32\inetsrv\inetinfo.exe C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe C:\Windows\System32\svchost.exe -k LPDService c:\Program Files (x86)\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe C:\Windows\system32\nvvsvc.exe C:\Windows\System32\svchost.exe -k HPZ12 C:\Windows\System32\svchost.exe -k HPZ12 C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\system32\svchost.exe -k iissvcs C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\system32\taskhost.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Windows\system32\wbem\wmiprvse.exe C:\Program Files\Microsoft Security Essentials\msseces.exe C:\Program Files (x86)\Windows Live\Family Safety\fsui.exe C:\Program Files (x86)\Microsoft Money\System\REMINDER.EXE C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe C:\Program Files (x86)\SAMSUNG\FW LiveUpdate\FWManager.exe C:\Program Files (x86)\HP\ToolboxFX\bin\HPTLBXFX.exe C:\Program Files (x86)\HP\HP Software Update\hpwuSchd2.exe C:\Program Files (x86)\HP\HP UT\bin\hppusg.exe C:\Program Files (x86)\Adobe\Reader 9.0\Reader\reader_sl.exe C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\SearchIndexer.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Program Files (x86)\Internet Explorer\iexplore.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe C:\Program Files (x86)\Internet Explorer\iexplore.exe C:\Windows\System32\svchost.exe -k LocalServicePeerNet C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2322.0\mswinext.exe C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe C:\Windows\system32\DllHost.exe C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10l_ActiveX.exe C:\Windows\system32\sppsvc.exe C:\Windows\ehome\mcupdate.EXE C:\Windows\system32\taskhost.exe C:\Windows\ehome\ehsched.exe C:\Windows\eHome\EhTray.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\servicing\TrustedInstaller.exe C:\Program Files (x86)\Internet Explorer\iexplore.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\DllHost.exe C:\Users\Dad\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\C5NYCPML\dds[1].scr C:\Windows\system32\conhost.exe ============== Pseudo HJT Report =============== uStart Page = about:blank mWinlogon: Userinit=userinit.exe BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll BHO: {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - No File BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll BHO: Windows Live Messenger Companion Helper: {9fdde16b-836f-4806-ab1f-1455cbeff289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll BHO: Bing Bar BHO: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2322.0\npwinext.dll BHO: Avery Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll TB: Avery Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll TB: @C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2322.0\npwinext.dll,-100: {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2322.0\npwinext.dll TB: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File uRun: [Reminder] C:\Program Files (x86)\Microsoft Money\System\reminder.exe uRun: [LightScribe Control Panel] C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden uRun: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe" mRun: [Name of App] C:\Program Files (x86)\SAMSUNG\FW LiveUpdate\FWManager.exe r mRun: [ToolBoxFX] "C:\Program Files (x86)\HP\ToolBoxFX\bin\HPTLBXFX.exe" /enum:on /alerts:on /notifications:on /systrayIcon:on /fl:on /fr:on /appData:on mRun: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe mRun: [] mRun: [HPUsageTracking] "C:\Program Files (x86)\HP\HP UT\bin\hppusg.exe" "C:\Program Files (x86)\HP\HP UT\" mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\HPDIGI~1.LNK - C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\MICROS~1.LNK - C:\Program Files (x86)\Microsoft Office\Office10\OSA.EXE mPolicies-explorer: NoActiveDesktop = 1 (0x1) mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1) mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5) mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: E&xport; to Microsoft Excel - C:\PROGRA~2\MICROS~1\Office10\EXCEL.EXE/3000 IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "C:\Program Files (x86)\Common Files\LightScribe\LSRunOnce.exe" BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll TB-X64: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File TB-X64: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File mRun-x64: [MSSE] "c:\Program Files\Microsoft Security Essentials\msseces.exe" -hide -runkey mRun-x64: [fssui] "C:\Program Files (x86)\Windows Live\Family Safety\fsui.exe" -autorun ============= SERVICES / DRIVERS =============== R1 MpFilter;Microsoft Malware Protection Driver;C:\Windows\System32\drivers\MpFilter.sys [2009-12-2 173984] R2 fssfltr;fssfltr;C:\Windows\System32\drivers\fssfltr.sys [2011-1-15 48488] R2 fsssvc;Windows Live Family Safety Service;C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2010-9-23 1493352] R2 ftpsvc;Microsoft FTP Service;C:\Windows\system32\svchost.exe -k ftpsvc [2009-7-13 27136] R3 MpNWMon;Microsoft Malware Protection Network Driver;C:\Windows\System32\drivers\MpNWMon.sys [2009-12-2 40832] R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2009-3-1 187392] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576] S3 StorSvc;Storage Service;C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-13 27136] S3 vpcuxd;USB Virtualization Stub Service;C:\Windows\System32\drivers\vpcuxd.sys [2010-3-19 16384] S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2010-3-19 1255736] S3 WMSVC;Web Management Service;C:\Windows\System32\inetsrv\WMSvc.exe [2009-7-13 10752] S4 MSSQLServerADHelper100;SQL Active Directory Helper Service;C:\Program Files (x86)\Microsoft SQL Server\100\Shared\sqladhlp.exe [2008-7-10 47128] S4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);C:\Program Files (x86)\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [2009-3-30 366936] S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184] =============== Created Last 30 ================ 2011-01-16 00:15:58 539968 —-a-w- C:\PROGRA~3\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight-2\SpotlightResources.dll 2011-01-16 00:15:28 42776 —-a-w- C:\PROGRA~3\Microsoft\eHome\Packages\MCEClientUX\dSM\StartResources.dll 2011-01-16 00:13:51 42776 —-a-w- C:\PROGRA~3\Microsoft\eHome\Packages\MCEClientUX\dSM-2\StartResources.dll 2011-01-15 23:32:10 ——– d—–w- C:\PROGRA~3\NVIDIA Corporation 2011-01-15 23:05:33 ——– d—–w- C:\Windows\en 2011-01-15 23:03:08 48488 —-a-w- C:\Windows\System32\drivers\fssfltr.sys 2011-01-15 23:00:26 ——– d—–w- C:\Users\Dad\AppData\Local\Windows Live 2011-01-15 23:00:08 257024 —-a-w- C:\Windows\System32\mfreadwrite.dll 2011-01-15 23:00:08 206848 —-a-w- C:\Windows\System32\mfps.dll 2011-01-15 23:00:07 196608 —-a-w- C:\Windows\SysWow64\mfreadwrite.dll 2011-01-15 23:00:07 1888256 —-a-w- C:\Windows\System32\WMVDECOD.DLL 2011-01-15 23:00:07 1619456 —-a-w- C:\Windows\SysWow64\WMVDECOD.DLL 2011-01-15 23:00:06 4068864 —-a-w- C:\Windows\System32\mf.dll 2011-01-15 23:00:06 3181568 —-a-w- C:\Windows\SysWow64\mf.dll 2011-01-15 22:58:26 8199504 —-a-w- C:\PROGRA~3\Microsoft\Microsoft Antimalware\Definition Updates\{537A6803-E16E-42F4-BE15-DC58CFFED52D}\mpengine.dll 2011-01-15 22:55:27 352256 —-a-w- C:\Program Files (x86)\Common Files\System\ado\msadomd.dll 2011-01-15 22:55:27 208896 —-a-w- C:\Program Files (x86)\Common Files\System\msadc\msadco.dll 2011-01-15 22:55:26 987136 —-a-w- C:\Program Files (x86)\Common Files\System\ado\msado15.dll 2011-01-15 22:55:24 573440 —-a-w- C:\Windows\SysWow64\odbc32.dll 2011-01-15 22:55:24 466944 —-a-w- C:\Program Files\Common Files\System\ado\msadomd.dll 2011-01-15 22:55:24 372736 —-a-w- C:\Program Files (x86)\Common Files\System\ado\msadox.dll 2011-01-15 22:55:24 258048 —-a-w- C:\Program Files\Common Files\System\msadc\msadco.dll 2011-01-15 22:55:23 720896 —-a-w- C:\Windows\System32\odbc32.dll 2011-01-15 22:55:23 1425408 —-a-w- C:\Program Files\Common Files\System\ado\msado15.dll 2011-01-15 22:55:22 495616 —-a-w- C:\Program Files\Common Files\System\ado\msadox.dll 2011-01-15 00:20:41 ——– d—–w- C:\Users\Dad\AppData\Local\PackageAware 2011-01-14 22:47:15 ——– d—–w- C:\9648e970b7f941bb18bc01d61a7cb1 2011-01-13 23:12:57 ——– d—–w- C:\2cfc9fc8cdf30db24f1b581009 2011-01-13 22:22:48 ——– d—–w- C:\Program Files (x86)\ESET 2011-01-13 22:09:58 ——– d-sh–w- C:\Users\Dad\PrivacIE 2011-01-13 22:09:39 ——– d-sh–w- C:\Users\Dad\IECompatCache 2011-01-09 18:40:17 ——– d—–w- C:\Users\Dad\AppData\Local\Google ==================== Find3M ==================== 2010-11-04 06:35:53 1194496 —-a-w- C:\Windows\System32\wininet.dll 2010-11-04 06:31:34 57856 —-a-w- C:\Windows\System32\licmgr10.dll 2010-11-04 05:52:17 978944 —-a-w- C:\Windows\SysWow64\wininet.dll 2010-11-04 05:48:36 44544 —-a-w- C:\Windows\SysWow64\licmgr10.dll 2010-11-04 05:16:14 482816 —-a-w- C:\Windows\System32\html.iec 2010-11-04 04:41:26 386048 —-a-w- C:\Windows\SysWow64\html.iec 2010-11-04 04:35:37 1638912 —-a-w- C:\Windows\System32\mshtml.tlb 2010-11-04 04:08:54 1638912 —-a-w- C:\Windows\SysWow64\mshtml.tlb 2010-11-02 05:18:17 524288 —-a-w- C:\Windows\System32\wmicmiplugin.dll 2010-11-02 05:17:38 473600 —-a-w- C:\Windows\System32\taskcomp.dll 2010-11-02 05:17:38 1169408 —-a-w- C:\Windows\System32\taskschd.dll 2010-11-02 05:16:53 1114624 —-a-w- C:\Windows\System32\schedsvc.dll 2010-11-02 05:10:47 464384 —-a-w- C:\Windows\System32\taskeng.exe 2010-11-02 05:10:32 285696 —-a-w- C:\Windows\System32\schtasks.exe 2010-11-02 04:40:36 496128 —-a-w- C:\Windows\SysWow64\taskschd.dll 2010-11-02 04:40:36 305152 —-a-w- C:\Windows\SysWow64\taskcomp.dll 2010-11-02 04:34:44 192000 —-a-w- C:\Windows\SysWow64\taskeng.exe 2010-11-02 04:34:33 179712 —-a-w- C:\Windows\SysWow64\schtasks.exe 2010-10-27 05:06:22 2048 —-a-w- C:\Windows\System32\tzres.dll 2010-10-27 04:32:36 2048 —-a-w- C:\Windows\SysWow64\tzres.dll 2010-10-20 05:20:01 46080 —-a-w- C:\Windows\System32\atmlib.dll 2010-10-20 04:54:18 34304 —-a-w- C:\Windows\SysWow64\atmlib.dll 2010-10-20 03:09:15 3124224 —-a-w- C:\Windows\System32\win32k.sys 2010-10-20 03:05:46 367104 —-a-w- C:\Windows\System32\atmfd.dll 2010-10-20 02:58:41 294400 —-a-w- C:\Windows\SysWow64\atmfd.dll 2010-10-19 20:51:33 270720 ——w- C:\Windows\System32\MpSigStub.exe ============= FINISH: 15:08:37.02 ===============

Attachments:

I was able to disconect all hard disk's except C:


Can you please advise if you are actually running anything from the additional drives that you disconntected. Were any of them flash drives, external hard drives that might regularly be accessed, or another internal drive that you are using regularly? Or was it just a system recovery drive?
The system has 3 hard drives. C - 750G SATA, D - 750G SATA, W - 500G IDE. I use dirve D for data and picture storage. I used drive W for storage of the old system when I went from XP 64 bit to 7 64 bit. This was done over a year ago and I have not been using drive W since. When I had all three drives in the system, Drive C & D would be 100% active and drive W would be at 0% active. Since the system was on C and it had 100% activity all the time, the system would come to a crawl and was not usable. Did the scan show anything?
I would suggest that you remove AskToolbar

* It promotes its toolbars on sites targeted at kids.
* It promotes its toolbars through ads that appear to be part of other companies' sites.
* It promotes its toolbars through other companies' spyware.
* It is Installed without any disclosure whatsoever and without any consent from the user whatsoever.
* It solicits installations via "deceptive door openers" that do not accurately describe the offer; failing to affirmatively show a license agreement; linking to a EULA via an off-screen link.
* It makes confusing changes to user's browsers - increasing Ask's revenues while taking users to pages they didn't intend to visit.



The reason I asked about your other drives is that it is possible for malware to originate on another drive. Right now, let's concentrate on the C: drive and make sure that is clean.



Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Please post the log in your next reply.



Scan With RootKitUnHooker

  • Please Download Rootkit Unhooker and save it to your desktop.
  • Now double-click on RKUnhookerLE.exe to run it.
  • Click the Report tab, then click Scan.
  • Check (Tick) Drivers and Stealth
  • Uncheck the rest. then click OK
  • When prompted to Select Disks for Scan, make sure C:\ is checked and click OK
  • Wait till the scanner has finished and then click File > Save Report.
  • Save the report somewhere where you can find it. Click Close.
  • Copy the entire contents of the report and paste it in your next reply.

Note** you may get the following warning, just click OK and continue.

"Rootkit Unhooker has detected a parasite inside itself!
It is recommended to remove parasite, okay?"
Anti-Malware did not show anything. RKUnhookerLE.exe would not run. Came up with this error: Error loading driver, NTSTSTYS code: 0xC000036B Here is the log from Anti-Malware: Malwarebytes' Anti-Malware 1.50.1.1100 www.malwarebytes.org Database version: 5542 Windows 6.1.7600 Internet Explorer 8.0.7600.16385 1/17/2011 4:26:59 PM mbam-log-2011-01-17 (16-26-59).txt Scan type: Quick scan Objects scanned: 230872 Time elapsed: 3 minute(s), 26 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
Let's try a different tool. If you can run this in normal mode it would be best, but if for some reason you are not able to, then you can run it in Safe Mode if necessary.

If you have CDEmulation drivers installed (such as Daemon Tools, Alcohol120) please follow the instructions below to run DeFogger prior to and after running GMER. If you do not have any CDEmulation drivers installed, you do not need to run DeFogger and you can go right to the instructions to run GMER.

Download DeFogger

Please download DeFogger to your desktop.

Double click DeFogger to run the tool.
  • The application window will appear
  • Click the Disable button to disable your CD Emulation drivers
  • Click Yes to continue
  • A 'Finished!' message will appear
  • Click OK
  • DeFogger will now ask to reboot the machine - click OK
IMPORTANT! If you receive an error message while running DeFogger, please post the log defogger_disable which will appear on your desktop.

Do not re-enable these drivers until otherwise instructed.

Download and Run GMER

[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
Well I don't think that did much. Here are the results: Gmer did not find anything. defogger_disable by jpshortstuff (23.02.10.1) Log created at 17:48 on 18/01/2011 (Dad) Checking for autostart values… HKCU\~\Run values retrieved. HKLM\~\Run values retrieved. Checking for services/drivers… -=E.O.F=-
You won't have seen any difference in your machine at this point because we have been running the tools to look for infections. So far, there is no indication the issues on your machine are related to malware.

I'm assuming you've not hooked up the other drives at this point. I do think it is important that we scan them just one time to ensure there is no malware on the other drives that is affecting the overall system performance - especially since removing them improved your system. After you have them reinstalled (even if you must boot into safe mode) please do the following:
  • Launch Malwarebytes again.
  • Please choose "Perform full scan".
  • Click Scan
  • When the window pops up showing you all your drives, ensure they are all checked
  • Click Scan
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Please post the log in your next reply.
Ok, I hooked up drives D and W and still can not run windows in normal mode. I did a scan in safe mode and it did find a few things on drive D. I had it remove what it found and rebooted and I still can not run in normal mode. Did another scan in safe mode and it found nothing this time. Here are the logs: Malwarebytes' Anti-Malware 1.50.1.1100 www.malwarebytes.org Database version: 5542 Windows 6.1.7600 (Safe Mode) Internet Explorer 8.0.7600.16385 1/19/2011 7:36:55 PM mbam-log-2011-01-19 Scan type: Full scan (C:\|D:\|W:\|) Objects scanned: 681807 Time elapsed: 1 hour(s), 5 minute(s), 58 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 3 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: d:\Kayak_D\program files\Spinway\bluelight\pager-ie.exe (Heuristics.Shuriken) -> No action taken. d:\Kayak_D\program files\Spinway\bluelight\BACKUP\pager-ie.exe (Heuristics.Shuriken) -> No action taken. d:\Kayak_D\WinNT\uninstall\$ntservicepackuninstall$\iasrad.dll (Spyware.PWS) -> No action taken. Malwarebytes' Anti-Malware 1.50.1.1100 www.malwarebytes.org Database version: 5542 Windows 6.1.7600 (Safe Mode) Internet Explorer 8.0.7600.16385 1/19/2011 8:53:47 PM mbam-log-2011-01-19 (20-53-47).txt Scan type: Full scan (C:\|D:\|W:\|) Objects scanned: 681810 Time elapsed: 1 hour(s), 5 minute(s), 21 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
After analyizing the results of the scans we have done, I do not see any evidence that the problems you are experiencing are related to malware. Since the problem was alleviated when you disconnected the other drives, there is a possibility it is a hardware related issue. I would like to direct you to our General Hardware Forum where you can receive assistance with further troubleshooting on what the problem may be.

Feel free to link them to this post if they need to refer to any of the information contained here. If they are unable to help you, you can feel free to post back here and we can try to dig deeper.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI