TomK,
Hi Tom, this is Doug.
This is a relatively new (3+ months) Gateway i3 3.2ghz, with 8gb RAM, Running Windows 7 Home Premium x64
The owner does not have installation disks.
The owner has not yet used the option to Create Recovery Disks.
You asked me to Run DDS.
It does not Run on this machine
Command (DOS) box appears, reading:
"This tool does not support your Operating System"
Running Windows 7 Home Premium 64 bit
Here's the Malwarebytes report:
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org
Database version: 5789
Windows 6.1.7600
Internet Explorer 8.0.7600.16385
2/17/2011 7:11:37 PM
mbam-log-2011-02-17 (19-11-30).txt
Scan type: Full scan (C:\|)
Objects scanned: 297117
Time elapsed: 25 minute(s), 55 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 0
Registry Data Items Infected: 1
Folders Infected: 3
Files Infected: 20
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0} (Trojan.Vundo) -> No action taken.
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_ShowSearch (PUM.Hijack.StartMenu) -> Bad: (0) Good: (1) -> No action taken.
Folders Infected:
c:\Users\Owner\AppData\Roaming\whitesmoketoolbar (PUP.WhiteSmoke) -> No action taken.
c:\Users\Owner\AppData\Roaming\whitesmoketoolbar\weather (PUP.WhiteSmoke) -> No action taken.
c:\programdata\microsoft\Windows\start menu\Programs\whitesmoke translator (PUP.WhiteSmoke) -> No action taken.
Files Infected:
c:\Users\Owner\AppData\Local\Temp\dxfh.exe (Adware.Agent) -> No action taken.
c:\Users\Owner\AppData\Local\Temp\uegsg.exe (Trojan.LVBP) -> No action taken.
c:\Users\Owner\AppData\Local\Temp\updatecheck.dll (Trojan.FakeAlert) -> No action taken.
c:\Users\Owner\AppData\Roaming\whitesmoketoolbar\dtx.ini (PUP.WhiteSmoke) -> No action taken.
c:\Users\Owner\AppData\Roaming\whitesmoketoolbar\guid.dat (PUP.WhiteSmoke) -> No action taken.
c:\Users\Owner\AppData\Roaming\whitesmoketoolbar\log.txt (PUP.WhiteSmoke) -> No action taken.
c:\Users\Owner\AppData\Roaming\whitesmoketoolbar\preferences.dat (PUP.WhiteSmoke) -> No action taken.
c:\Users\Owner\AppData\Roaming\whitesmoketoolbar\stat.log (PUP.WhiteSmoke) -> No action taken.
c:\Users\Owner\AppData\Roaming\whitesmoketoolbar\stats.dat (PUP.WhiteSmoke) -> No action taken.
c:\Users\Owner\AppData\Roaming\whitesmoketoolbar\uninstallie.dat (PUP.WhiteSmoke) -> No action taken.
c:\Users\Owner\AppData\Roaming\whitesmoketoolbar\uninstallstatie.dat (PUP.WhiteSmoke) -> No action taken.
c:\Users\Owner\AppData\Roaming\whitesmoketoolbar\version.xml (PUP.WhiteSmoke) -> No action taken.
c:\Users\Owner\AppData\Roaming\whitesmoketoolbar\weatherbutton_prefs.xml (PUP.WhiteSmoke) -> No action taken.
c:\Users\Owner\AppData\Roaming\whitesmoketoolbar\weather\3f36704676aeca513c641eec506661b5 (PUP.WhiteSmoke) -> No action taken.
c:\Users\Owner\AppData\Roaming\whitesmoketoolbar\weather\6f855fed069951ec7b3b65ee86123a32 (PUP.WhiteSmoke) -> No action taken.
c:\Users\Owner\AppData\Roaming\whitesmoketoolbar\weather\forecasts_cache.xml (PUP.WhiteSmoke) -> No action taken.
c:\Users\Owner\AppData\Roaming\whitesmoketoolbar\weather\observations_cache.xml (PUP.WhiteSmoke) -> No action taken.
c:\programdata\microsoft\Windows\start menu\Programs\whitesmoke translator\registration.lnk (PUP.WhiteSmoke) -> No action taken.
c:\programdata\microsoft\Windows\start menu\Programs\whitesmoke translator\uninstall.lnk (PUP.WhiteSmoke) -> No action taken.
c:\programdata\microsoft\Windows\start menu\Programs\whitesmoke translator\whitesmoke translator.lnk (PUP.WhiteSmoke) -> No action taken.
Note: I saved this report before allowing Malwarebytes to take action of removing all but the following:
c:\Users\Owner\AppData\Roaming\whitesmoketoolbar\weather\3f36704676aeca513c641eec506661b5 (PUP.WhiteSmoke) ->
c:\Users\Owner\AppData\Roaming\whitesmoketoolbar\weather\6f855fed069951ec7b3b65ee86123a32 (PUP.WhiteSmoke
Reason:
Believing that those two items may reside in Restore Points, therefore kept them.
What scans do you wish me to run.
Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
Note:These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
DDS (Ver_10-12-12.02)
Microsoft Windows 7 Home Premium
Boot Device: \Device\HarddiskVolume2
Install Date: 1/11/2011 2:47:41 PM
System Uptime: 2/17/2011 8:27:46 PM (12 hours ago)
Motherboard: Gateway | | DX4840
Processor: Intel® Core™ i3 CPU 550 @ 3.20GHz | CPU 1 | 3200/133mhz
==== Disk Partitions =========================
C: is FIXED (NTFS) - 916 GiB total, 826.301 GiB free.
D: is Removable
E: is Removable
F: is CDROM ()
G: is Removable
H: is Removable
I: is Removable
==== Disabled Device Manager Items =============
Class GUID: {4d36e96f-e325-11ce-bfc1-08002be10318}
Description: Microsoft PS/2 Mouse
Device ID: ACPI\PNP0F03\4&DC382E&0
Manufacturer: Microsoft
Name: Microsoft PS/2 Mouse
PNP Device ID: ACPI\PNP0F03\4&DC382E&0
Service: i8042prt
==== System Restore Points ===================
RP3: 1/11/2011 3:43:43 PM - Windows Update
RP4: 1/11/2011 4:05:13 PM - Windows Update
RP5: 1/14/2011 5:19:49 PM - Windows Update
RP6: 1/18/2011 12:28:28 PM - Windows Update
RP7: 1/21/2011 10:14:41 PM - Windows Update
RP8: 1/25/2011 9:48:38 AM - Windows Update
RP9: 1/29/2011 1:47:59 PM - Windows Update
RP10: 2/1/2011 12:59:13 AM - Windows Update
RP11: 2/5/2011 8:18:20 PM - Windows Update
RP12: 2/9/2011 9:05:43 PM - Windows Update
RP13: 2/9/2011 9:26:40 PM - Windows Update
RP14: 2/14/2011 10:40:36 PM - Windows Update
RP15: 2/17/2011 6:05:08 PM - Installed LogMeIn
RP16: 2/18/2011 4:01:36 AM - Windows Update
==== Installed Programs ======================
Acrobat.com
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 9.4.2 MUI
Advertising Center
Best Buy pc app
CyberLink PowerDVD 9
Gateway InfoCentre
Gateway Photo Frame [removed]
Gateway Recovery Management
Gateway Registration
Gateway Updater
Identity Card
ImagXpress
Intel® Control Center
Intel® Graphics Media Accelerator Driver
Junk Mail filter update
Kaspersky Anti-Virus 2011
LogMeIn
Malwarebytes' Anti-Malware
Microsoft Choice Guard
Microsoft Office 2010
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Mozilla Firefox (3.6.13)
MSVCRT
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
Nero 9 Essentials
Nero ControlCenter
Nero DiscSpeed
Nero DiscSpeed Help
Nero DriveSpeed
Nero DriveSpeed Help
Nero Express Help
Nero InfoTool
Nero InfoTool Help
Nero Installer
Nero Online Upgrade
Nero StartSmart
Nero StartSmart Help
Nero StartSmart OEM
NeroExpress
neroxml
Realtek Ethernet Controller Driver For Windows 7
Realtek High Definition Audio Driver
Rhapsody
Security Update for Microsoft .NET Framework 4 Client Profile (KB2160841)
UB
Update for Microsoft .NET Framework 4 Client Profile (KB2473228)
Welcome Center
Windows Live Call
Windows Live Communications Platform
Windows Live Essentials
Windows Live Mail
Windows Live Messenger
Windows Live Movie Maker
Windows Live Photo Gallery
Windows Live Sign-in Assistant
Windows Live Sync
Windows Live Upload Tool
Windows Live Writer
==== End Of File ===========================
That all looks good. Let's get an online scan to verify and also find things that are old enough not to show in the scan.
ESET Online Scanner:
Note: You can use either Internet Explorer or Mozilla FireFox for this scan. You will however need to disable your current installed Anti-Virus, how to do so can be read here.
Vista users: You will need to to right-click on the either the IE or FF icon in the Start Menu or Quick Launch Bar on the Taskbar and select Run as Administrator from the context menu.
Please go here then click on: [external image: Posted Image]
Note: If using Mozilla Firefox you will need to download esetsmartinstaller_enu.exe when prompted then double click on it to install. All of the below instructions are compatible with either Internet Explorer or Mozilla FireFox.
Select the option YES, I accept the Terms of Use then click on: [external image: Posted Image]
When prompted allow the Add-On/Active X to install.
Make sure that the option Remove found threats is NOT checked, and the option Scan archives is checked.
Now click on Advanced Settings and select the following:
Scan for potentially unwanted applications
Scan for potentially unsafe applications
Enable Anti-Stealth Technology
Now click on: [external image: Posted Image]
The virus signature database… will begin to download. Be patient this make take some time depending on the speed of your Internet Connection.
When completed the Online Scan will begin automatically.
Do not touch either the Mouse or keyboard during the scan otherwise it may stall.
When completed select Uninstall application on close if you so wish, make sure you copy the logfile first!
Now click on: [external image: Posted Image]
Use notepad to open the logfile located at C:\Program Files\ESET\EsetOnlineScanner\log.txt.
Copy and paste that log as a reply to this topic.
Note: Do not forget to re-enable your Anti-Virus application after running the above scan!
ESET results:
One Threat found….
C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\0YVUFBQB\registrybooster[1].exe Win32/RegistryBooster application