This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

system process spiking up to 312%

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi all

First time using highjackthis and coming on to a forum like this so I hope I get it all right the first attempt here.

Like the topic says my system process is spiking anywhere from 1 to 300+%. I did have a trojan earlier which panda cloud said it removed (Deldir.A). I ran multiple anti virus and anti malware programs and they all say I'm clean now (emsisoft anti-malware, panda cloud, hitman pro, superantispyware, windows defender). I don't know when this started but just noticed it when I observed the resource monitor, it averages anywhere from 40-50% of my cpu usage. It constantly spikes and it seems 100% of my cpu is more often than not being used.

I'm using windows 7 64 bit with SP1. This is on a Acer aspire one (ao722) netbook. Using the AMD c-50 APU.

I contacted acer and they of course want me to wipe the computer to factory settings but that is a last resort as I have lots of information on here.

Thanks in advance for any replies. Here is the highjackthis report.


Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 6:09:58 PM, on 07/07/2011
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
C:\Users\Kurt\Local Settings\Apps\F.lux\flux.exe
C:\Program Files (x86)\Panda Security\Panda Cloud Antivirus\PSUNMain.exe
C:\Users\Kurt\AppData\Local\Google\Update\1.3.21.57\GoogleCrashHandler.exe
C:\Users\Kurt\Desktop\Freegate 7.13 Professional.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10s_ActiveX.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\uTorrent\uTorrent.exe
C:\Users\Kurt\Downloads\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://acer.msn.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = Preserve
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://acer.msn.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://acer.msn.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://acer.msn.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 127.0.0.1:8580
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [PSUNMain] "C:\Program Files (x86)\Panda Security\Panda Cloud Antivirus\PSUNMain.exe" /Traybar
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKCU\..\Run: [F.lux] "C:\Users\Kurt\Local Settings\Apps\F.lux\flux.exe" /noshow
O4 - HKCU\..\Run: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [IsMyWinLockerReboot] msiexec.exe /qn /x{voidguid} (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [IsMyWinLockerReboot] msiexec.exe /qn /x{voidguid} (User 'Default user')
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
O23 - Service: Emsisoft Anti-Malware 5.0 - Service (a2AntiMalware) - Emsi Software GmbH - C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe
O23 - Service: Advanced SystemCare Service (AdvancedSystemCareService) - IObit - C:\Program Files (x86)\IObit\Advanced SystemCare 4\ASCService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: @C:\Windows\system32\CxAudMsg64.exe,-100 (CxAudMsg) - Unknown owner - C:\Windows\system32\CxAudMsg64.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: Acer ePower Service (ePowerSvc) - Acer Incorporated - C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Live Updater Service - Acer Incorporated - C:\Program Files\Acer\Acer Updater\UpdaterService.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: Panda Cloud Antivirus Service (NanoServiceMain) - Panda Security, S.L. - C:\Program Files (x86)\Panda Security\Panda Cloud Antivirus\PSANHost.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)

–
End of file - 6739 bytes
Hi thielek,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. Logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

Unfortunately, HijackThis just doesn't give enough information on the new operating systems. I'd like to see a different log please.

Please download DDS by sUBs from one of the following links and save it to your desktop.
    • DDS.scr
    • DDS.pif
  • Disable any script blocking protection (How to Disable your Security Programs)
  • Double click DDS icon to run the tool (may take up to 3 minutes to run)
  • When done, DDS.txt will open.
  • After a few moments, attach.txt will open in a second window.
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scroling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and the click UPLOAD.
Thanks very much for your help I really appreciate it. I have been doing lots of reading and searching online in to my problem and I read somewhere that it could have something to do with my network adapters. So I disabled/uninstalled my ethernet adapter and my cpu usage has dropped a lot from my system process I've noticed. I'm not sure if this has totally fixed the problem but it seems to have helped, also I'm not sure if that was malware related to begin with. If you would like to move on to help somebody else I would totally understand. But if you'd like to make sure it's nothing malware related still I'll post the reports here. Again I appreciate the volunteer work you guys do. . DDS (Ver_2011-06-23.01) - NTFSAMD64 Internet Explorer: 9.0.8112.16421 Run by [removed] at 14:33:54 on 2011-07-11 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.2.1033.18.1771.821 [GMT 8:00] . AV: Panda Cloud Antivirus *Disabled/Updated* {86971480-9989-6750-B122-681A86518D59} SP: Panda Cloud Antivirus *Disabled/Updated* {3DF6F564-BFB3-68DE-8B92-5368FDD6C7E4} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . ============== Running Processes =============== . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe C:\Windows\system32\svchost.exe -k RPCSS C:\Windows\system32\atiesrxx.exe C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\atieclxx.exe C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\system32\WLANExt.exe C:\Windows\system32\conhost.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\taskhost.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE C:\Program Files (x86)\IObit\Advanced SystemCare 4\ASCService.exe C:\Windows\SysWOW64\svchost.exe -k Akamai C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe C:\Users\Kurt\Local Settings\Apps\F.lux\flux.exe C:\Windows\System32\StikyNot.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Windows\system32\CxAudMsg64.exe C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Program Files (x86)\Panda Security\Panda Cloud Antivirus\PSUNMain.exe C:\Program Files\Acer\Acer Updater\UpdaterService.exe C:\Program Files (x86)\Panda Security\Panda Cloud Antivirus\PSANHost.exe C:\Program Files (x86)\Secunia\PSI\PSIA.exe C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\system32\wbem\unsecapp.exe C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Program Files\Synaptics\SynTP\SynTPHelper.exe C:\Windows\System32\svchost.exe -k secsvcs C:\Users\Kurt\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Kurt\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Kurt\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Kurt\Desktop\Freegate 7.13 Professional.exe C:\Users\Kurt\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Kurt\AppData\Local\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\VideoLAN\VLC\vlc.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\system32\vssvc.exe C:\Windows\System32\svchost.exe -k swprv C:\Users\Kurt\AppData\Local\Google\Chrome\Application\chrome.exe C:\Windows\SysWOW64\rundll32.exe C:\Users\Kurt\AppData\Local\Google\Chrome\Application\chrome.exe C:\Windows\SysWow64\NOTEPAD.EXE C:\Windows\system32\DllHost.exe C:\Windows\system32\DllHost.exe C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\conhost.exe C:\Windows\SysWOW64\cscript.exe . ============== Pseudo HJT Report =============== . uSearch Bar = Preserve uStart Page = hxxp://acer.msn.com uDefault_Page_URL = hxxp://acer.msn.com mDefault_Page_URL = about:blank mStart Page = about:blank uInternet Settings,ProxyServer = 127.0.0.1:8580 uInternet Settings,ProxyOverride = mWinlogon: Userinit=userinit.exe BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll uRun: [F.lux] "C:\Users\Kurt\Local Settings\Apps\F.lux\flux.exe" /noshow uRun: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe uRun: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun mRun: [PSUNMain] "C:\Program Files (x86)\Panda Security\Panda Cloud Antivirus\PSUNMain.exe" /Traybar dRunOnce: [IsMyWinLockerReboot] msiexec.exe /qn /x{voidguid} mPolicies-explorer: NoActiveDesktop = 1 (0x1) mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5) mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab TCP: DhcpNameServer = 192.168.1.1 TCP: Interfaces\{D759B6DD-999F-40E4-B077-3E3B4E8C6F9D} : DhcpNameServer = 192.168.1.1 TCP: Interfaces\{D759B6DD-999F-40E4-B077-3E3B4E8C6F9D}\4505D2C494E4B4824757F66656E676D21392 : DhcpNameServer = 192.168.1.1 TCP: Interfaces\{D759B6DD-999F-40E4-B077-3E3B4E8C6F9D}\455727B656970245964737 : DhcpNameServer = 192.168.2.1 TCP: Interfaces\{D759B6DD-999F-40E4-B077-3E3B4E8C6F9D}\C496C69705164694E6E6 : DhcpNameServer = [removed] [removed] BHO-X64: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll mRun-x64: [PSUNMain] "C:\Program Files (x86)\Panda Security\Panda Cloud Antivirus\PSUNMain.exe" /Traybar . ================= FIREFOX =================== . FF - ProfilePath - C:\Users\Kurt\AppData\Roaming\Mozilla\Firefox\Profiles\oxxcyd3a.default\ FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=panda&type=PCAFSI1190&p= FF - plugin: C:\PROGRA~2\MICROS~4\Office14\NPSPWRAP.DLL FF - plugin: C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll FF - plugin: C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\npctrlui.dll FF - plugin: C:\Users\Kurt\AppData\Local\Google\Update\1.3.21.57\npGoogleUpdate3.dll FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll . ============= SERVICES / DRIVERS =============== . R1 PSINKNC;PSINKNC;C:\Windows\system32\DRIVERS\psinknc.sys –> C:\Windows\system32\DRIVERS\psinknc.sys [?] R1 SASDIFSV;SASDIFSV;C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys [2010-2-18 14920] R1 SASKUTIL;SASKUTIL;C:\Program Files\SUPERAntiSpyware\saskutil64.sys [2010-2-18 12360] R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys –> C:\Windows\system32\DRIVERS\vwififlt.sys [?] R2 !SASCORE;SAS Core Service;C:\Program Files\SUPERAntiSpyware\SASCore64.exe [2011-5-5 128384] R2 a2AntiMalware;Emsisoft Anti-Malware 5.0 - Service;C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe [2011-6-29 3029208] R2 AdvancedSystemCareService;Advanced SystemCare Service;C:\Program Files (x86)\IObit\Advanced SystemCare 4\ASCService.exe [2011-6-9 353168] R2 Akamai;Akamai NetSession Interface;C:\Windows\System32\svchost.exe -k Akamai [2009-7-14 20992] R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\system32\atiesrxx.exe –> C:\Windows\system32\atiesrxx.exe [?] R2 AMD FUEL Service;AMD FUEL Service;C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2011-5-24 365568] R2 cvhsvc;Client Virtualization Handler;C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE [2010-2-28 821664] R2 CxAudMsg;Conexant Audio Message Service;C:\Windows\system32\CxAudMsg64.exe –> C:\Windows\system32\CxAudMsg64.exe [?] R2 ePowerSvc;Acer ePower Service;C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe [2011-5-13 868224] R2 Live Updater Service;Live Updater Service;C:\Program Files\Acer\Acer Updater\UpdaterService.exe [2011-4-19 244624] R2 NanoServiceMain;Panda Cloud Antivirus Service;C:\Program Files (x86)\Panda Security\Panda Cloud Antivirus\PSANHost.exe [2011-4-29 140608] R2 PSINAflt;PSINAflt;C:\Windows\system32\DRIVERS\PSINAflt.sys –> C:\Windows\system32\DRIVERS\PSINAflt.sys [?] R2 PSINFile;PSINFile;C:\Windows\system32\DRIVERS\PSINFile.sys –> C:\Windows\system32\DRIVERS\PSINFile.sys [?] R2 PSINProc;PSINProc;C:\Windows\system32\DRIVERS\PSINProc.sys –> C:\Windows\system32\DRIVERS\PSINProc.sys [?] R2 PSINProt;PSINProt;C:\Windows\system32\DRIVERS\PSINProt.sys –> C:\Windows\system32\DRIVERS\PSINProt.sys [?] R2 Secunia PSI Agent;Secunia PSI Agent;C:\Program Files (x86)\Secunia\PSI\psia.exe [2011-4-19 993848] R2 sftlist;Application Virtualization Client;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2010-4-24 483688] R3 amdiox64;AMD IO Driver;C:\Windows\system32\DRIVERS\amdiox64.sys –> C:\Windows\system32\DRIVERS\amdiox64.sys [?] R3 amdkmdag;amdkmdag;C:\Windows\system32\DRIVERS\atikmdag.sys –> C:\Windows\system32\DRIVERS\atikmdag.sys [?] R3 amdkmdap;amdkmdap;C:\Windows\system32\DRIVERS\atikmpag.sys –> C:\Windows\system32\DRIVERS\atikmpag.sys [?] R3 AtiHDAudioService;ATI Function Driver for HD Audio Service;C:\Windows\system32\drivers\AtihdW76.sys –> C:\Windows\system32\drivers\AtihdW76.sys [?] R3 NdisrdMP;NdisrdMP;C:\Windows\system32\DRIVERS\ndisrd.sys –> C:\Windows\system32\DRIVERS\ndisrd.sys [?] R3 PSI;PSI;C:\Windows\system32\DRIVERS\psi_mf.sys –> C:\Windows\system32\DRIVERS\psi_mf.sys [?] R3 Sftfs;Sftfs;C:\Windows\system32\DRIVERS\Sftfslh.sys –> C:\Windows\system32\DRIVERS\Sftfslh.sys [?] R3 Sftplay;Sftplay;C:\Windows\system32\DRIVERS\Sftplaylh.sys –> C:\Windows\system32\DRIVERS\Sftplaylh.sys [?] R3 Sftredir;Sftredir;C:\Windows\system32\DRIVERS\Sftredirlh.sys –> C:\Windows\system32\DRIVERS\Sftredirlh.sys [?] R3 Sftvol;Sftvol;C:\Windows\system32\DRIVERS\Sftvollh.sys –> C:\Windows\system32\DRIVERS\Sftvollh.sys [?] R3 sftvsa;Application Virtualization Service Agent;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2010-4-24 209768] R3 vwifimp;Microsoft Virtual WiFi Miniport Service;C:\Windows\system32\DRIVERS\vwifimp.sys –> C:\Windows\system32\DRIVERS\vwifimp.sys [?] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-19 130384] S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-19 138576] S3 a2acc;a2acc;C:\Program Files (x86)\Emsisoft Anti-Malware\a2accx64.sys [2011-6-29 85800] S3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;C:\Windows\system32\DRIVERS\L1C62x64.sys –> C:\Windows\system32\DRIVERS\L1C62x64.sys [?] S3 MEMSWEEP2;MEMSWEEP2;\??\C:\Windows\system32\976A.tmp –> C:\Windows\system32\976A.tmp [?] S3 Ndisrd;WinpkFilter Service;C:\Windows\system32\DRIVERS\ndisrd.sys –> C:\Windows\system32\DRIVERS\ndisrd.sys [?] S3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-1-10 4925184] S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;C:\Windows\system32\Drivers\RtsUStor.sys –> C:\Windows\system32\Drivers\RtsUStor.sys [?] S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys –> C:\Windows\system32\drivers\tsusbflt.sys [?] S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\system32\drivers\TsUsbGD.sys –> C:\Windows\system32\drivers\TsUsbGD.sys [?] S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe –> C:\Windows\system32\Wat\WatAdminSvc.exe [?] . =============== File Associations =============== . txtfile=C:\Windows\SysWow64\NOTEPAD.EXE %1 . =============== Created Last 30 ================ . 2011-07-11 04:34:25 ——– d—–w- C:\Program Files (x86)\AMD APP 2011-07-11 04:34:15 ——– d—–w- C:\Program Files\Common Files\ATI Technologies 2011-07-11 04:34:15 ——– d—–w- C:\Program Files (x86)\Common Files\ATI Technologies 2011-07-11 04:31:44 ——– d—–w- C:\Program Files (x86)\ATI Technologies 2011-07-11 04:31:23 ——– d—–w- C:\Program Files\ATI 2011-07-11 02:33:34 6144 ——w- C:\Windows\System32\976A.tmp 2011-07-11 02:21:47 6144 ——w- C:\Windows\System32\CEEC.tmp 2011-07-11 02:21:23 ——– d—–w- C:\Program Files (x86)\Sophos 2011-07-11 01:27:13 ——– d—–w- C:\AeriaGames 2011-07-10 16:22:15 ——– d—–w- C:\ubuntu 2011-07-10 15:10:14 ——– d—–w- C:\Users\Kurt\AppData\Local\ElevatedDiagnostics 2011-07-10 10:49:13 ——– d—–w- C:\Users\Kurt\AppData\Local\Microsoft Games 2011-07-10 07:29:10 ——– d—–w- C:\ProgramData\SystemExplorer 2011-07-10 07:28:52 ——– d—–w- C:\Program Files (x86)\System Explorer 2011-07-10 07:19:53 106496 —-a-r- C:\Users\Kurt\AppData\Roaming\Microsoft\Installer\{3CA54984-A14B-42FE-9FF1-7EA90151D725}\NewShortcut311_0951773981FA4AB2BC21B7DCEC95892A.exe 2011-07-10 07:19:51 106496 —-a-r- C:\Users\Kurt\AppData\Roaming\Microsoft\Installer\{3CA54984-A14B-42FE-9FF1-7EA90151D725}\NewShortcut1_EDD4ABB1C1B34A9D84CE33FBFB5D3639.exe 2011-07-10 03:21:04 ——– d—–w- C:\Program Files (x86)\Common Files\Akamai 2011-07-09 15:15:35 ——– d—–w- C:\Users\Kurt\AppData\Roaming\f-secure 2011-07-09 15:15:08 ——– d—–w- C:\ProgramData\F-Secure 2011-07-09 14:38:00 525544 —-a-w- C:\Windows\System32\deployJava1.dll 2011-07-09 11:59:13 ——– d—–w- C:\Users\Kurt\AppData\Roaming\QuickScan 2011-07-08 12:01:06 ——– d—–w- C:\Windows\pss 2011-07-08 11:12:20 14 —-a-w- C:\Windows\SysWow64\SysMachinef.dll 2011-07-08 11:12:20 ——– d—–w- C:\ProgramData\Acebyte 2011-07-08 06:40:01 8873296 —-a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{96993979-9839-46BC-A0D6-6570F69F6392}\mpengine.dll 2011-07-08 03:31:29 ——– d—–w- C:\Users\Kurt\AppData\Local\Secunia PSI 2011-07-08 03:31:13 ——– d—–w- C:\Program Files (x86)\Secunia 2011-07-05 03:24:19 2106216 —-a-w- C:\Program Files (x86)\Mozilla Firefox\D3DCompiler_43.dll 2011-07-05 03:24:16 1998168 —-a-w- C:\Program Files (x86)\Mozilla Firefox\d3dx9_43.dll 2011-07-04 07:09:31 ——– d—–w- C:\Users\Kurt\AppData\Roaming\Malwarebytes 2011-07-04 07:09:12 39984 —-a-w- C:\Windows\SysWow64\drivers\mbamswissarmy.sys 2011-07-04 07:09:08 ——– d—–w- C:\ProgramData\Malwarebytes 2011-07-04 07:09:02 25912 —-a-w- C:\Windows\System32\drivers\mbam.sys 2011-07-04 07:09:02 ——– d—–w- C:\Program Files (x86)\Malwarebytes' Anti-Malware 2011-07-02 08:36:21 106496 —-a-r- C:\Users\Kurt\AppData\Roaming\Microsoft\Installer\{3CA54984-A14B-42FE-9FF1-7EA90151D725}\NewShortcut31_2F252077BA3F4362913955273A708467.exe 2011-06-30 15:14:10 23112 —-a-w- C:\Windows\System32\drivers\hitmanpro35.sys 2011-06-30 15:13:57 ——– d—–w- C:\Program Files\Hitman Pro 3.5 2011-06-30 15:13:25 ——– d—–w- C:\ProgramData\Hitman Pro 2011-06-30 10:30:18 ——– d—–w- C:\Users\Kurt\AppData\Roaming\KC Softwares 2011-06-30 10:30:06 ——– d—–w- C:\Program Files (x86)\KC Softwares 2011-06-29 09:22:01 ——– d—–w- C:\ProgramData\VirtualizedApplications 2011-06-29 08:43:23 ——– d—–w- C:\Program Files (x86)\Emsisoft Anti-Malware 2011-06-29 07:10:05 ——– d—–w- C:\Users\Kurt\AppData\Local\SoftGrid Client 2011-06-29 07:10:01 ——– d—–w- C:\Users\Kurt\AppData\Roaming\SoftGrid Client 2011-06-29 07:04:41 ——– d—–w- C:\Windows\PCHEALTH 2011-06-29 07:04:41 ——– d—–w- C:\Program Files (x86)\Microsoft Application Virtualization Client 2011-06-29 07:03:05 ——– d—–w- C:\Users\Kurt\AppData\Roaming\TP 2011-06-29 05:53:33 ——– d—–w- C:\Users\Kurt\AppData\Local\CrashDumps 2011-06-29 03:08:55 27648 —-a-w- C:\Windows\System32\drivers\Ndisrd.sys 2011-06-28 16:18:05 106496 —-a-r- C:\Users\Kurt\AppData\Roaming\Microsoft\Installer\{052CFB79-9D62-42E3-8A15-DE66C2C97C3E}\NewShortcut1_EDD4ABB1C1B34A9D84CE33FBFB5D3639.exe 2011-06-28 15:58:24 ——– d—–w- C:\Users\Kurt\AppData\Local\Tencent 2011-06-28 15:47:50 ——– d—–w- C:\Program Files (x86)\Common Files\Tencent 2011-06-28 15:46:38 ——– d—–w- C:\Program Files (x86)\Tencent 2011-06-28 15:45:36 18760 —-a-w- C:\Windows\SysWow64\QQVistaHelper.dll 2011-06-28 15:45:36 ——– d—–w- C:\Users\Kurt\AppData\Roaming\Tencent 2011-06-26 14:13:22 ——– d—–w- C:\Program Files (x86)\Image Resizer 2011-06-26 11:34:39 ——– d—–w- C:\Users\Kurt\AppData\Roaming\Panda Security 2011-06-26 11:32:52 ——– d—–w- C:\ProgramData\Panda Security 2011-06-26 11:32:52 ——– d—–w- C:\Program Files (x86)\Panda Security 2011-06-26 11:32:13 ——– d—–w- C:\temp 2011-06-18 15:42:45 ——– d—–w- C:\Users\Kurt\AppData\Local\Thunderbird 2011-06-17 23:29:15 ——– d—–w- C:\Users\Kurt\AppData\Local\Apps 2011-06-16 23:14:26 ——– d—–w- C:\0fde1ea366b99744189e0ce12e831000 2011-06-16 22:51:32 289280 —-a-w- C:\Windows\System32\drivers\mrxsmb10.sys 2011-06-16 22:51:32 158208 —-a-w- C:\Windows\System32\drivers\mrxsmb.sys 2011-06-16 22:51:32 128000 —-a-w- C:\Windows\System32\drivers\mrxsmb20.sys 2011-06-16 22:51:30 467456 —-a-w- C:\Windows\System32\drivers\srv.sys 2011-06-16 22:51:30 410112 —-a-w- C:\Windows\System32\drivers\srv2.sys 2011-06-16 22:51:30 168448 —-a-w- C:\Windows\System32\drivers\srvnet.sys 2011-06-16 22:51:28 499200 —-a-w- C:\Windows\System32\drivers\afd.sys 2011-06-16 22:51:28 1923968 —-a-w- C:\Windows\System32\drivers\tcpip.sys 2011-06-16 22:51:26 3135488 —-a-w- C:\Windows\System32\win32k.sys 2011-06-16 22:51:24 861696 —-a-w- C:\Windows\System32\oleaut32.dll 2011-06-16 22:51:24 571904 —-a-w- C:\Windows\SysWow64\oleaut32.dll 2011-06-16 22:50:28 976896 —-a-w- C:\Windows\System32\inetcomm.dll 2011-06-16 22:50:28 741376 —-a-w- C:\Windows\SysWow64\inetcomm.dll 2011-06-16 22:44:47 ——– d—–w- C:\Users\Kurt\AppData\Roaming\MusicBee 2011-06-16 22:44:14 ——– d—–w- C:\Program Files (x86)\MusicBee 2011-06-14 10:29:18 466456 —-a-w- C:\Windows\System32\wrap_oal.dll 2011-06-14 10:29:18 444952 —-a-w- C:\Windows\SysWow64\wrap_oal.dll 2011-06-14 10:29:18 122904 —-a-w- C:\Windows\System32\OpenAL32.dll 2011-06-14 10:29:18 109080 —-a-w- C:\Windows\SysWow64\OpenAL32.dll 2011-06-14 10:29:18 ——– d—–w- C:\Program Files (x86)\OpenAL 2011-06-14 10:26:32 ——– d—–w- C:\Program Files (x86)\Common Files\Futuremark Shared 2011-06-14 10:24:20 ——– d—–w- C:\Program Files (x86)\Futuremark 2011-06-12 21:28:05 ——– d—–w- C:\Program Files (x86)\AMD 2011-06-12 20:04:01 ——– d—–w- C:\Users\Kurt\AppData\Local\Opera 2011-06-11 13:04:33 46136 —-a-w- C:\Windows\System32\drivers\amdiox64.sys . ==================== Find3M ==================== . 2011-07-08 04:40:56 404640 —-a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl 2011-06-08 23:46:58 472808 —-a-w- C:\Windows\SysWow64\deployJava1.dll 2011-05-25 06:44:30 61952 —-a-w- C:\Windows\System32\OVDecode64.dll 2011-05-25 06:44:26 59904 —-a-w- C:\Windows\SysWow64\OVDecode.dll 2011-05-25 06:44:04 16672768 —-a-w- C:\Windows\System32\amdocl64.dll 2011-05-25 06:43:50 12798976 —-a-w- C:\Windows\SysWow64\amdocl.dll 2011-05-25 04:26:56 9359872 —-a-w- C:\Windows\System32\drivers\atikmdag.sys 2011-05-25 03:53:28 23336960 —-a-w- C:\Windows\System32\atio6axx.dll 2011-05-25 03:31:38 17940992 —-a-w- C:\Windows\SysWow64\atioglxx.dll 2011-05-25 03:07:58 151552 —-a-w- C:\Windows\System32\atiapfxx.exe 2011-05-25 03:07:48 688128 —-a-w- C:\Windows\SysWow64\aticfx32.dll 2011-05-25 03:06:38 811008 —-a-w- C:\Windows\System32\aticfx64.dll 2011-05-25 03:04:16 462848 —-a-w- C:\Windows\System32\ATIDEMGX.dll 2011-05-25 03:04:10 485376 —-a-w- C:\Windows\System32\atieclxx.exe 2011-05-25 03:03:38 204288 —-a-w- C:\Windows\System32\atiesrxx.exe 2011-05-25 03:02:30 120320 —-a-w- C:\Windows\System32\atitmm64.dll 2011-05-25 03:02:16 423424 —-a-w- C:\Windows\System32\atipdl64.dll 2011-05-25 03:02:10 356352 —-a-w- C:\Windows\SysWow64\atipdlxx.dll 2011-05-25 03:02:00 278528 —-a-w- C:\Windows\SysWow64\Oemdspif.dll 2011-05-25 03:01:54 16384 —-a-w- C:\Windows\System32\atimuixx.dll 2011-05-25 03:01:50 59392 —-a-w- C:\Windows\System32\atiedu64.dll 2011-05-25 03:01:46 43520 —-a-w- C:\Windows\SysWow64\ati2edxx.dll 2011-05-25 03:00:00 1113088 —-a-w- C:\Windows\System32\atiumd6v.dll 2011-05-25 02:59:38 1828864 —-a-w- C:\Windows\SysWow64\atiumdmv.dll 2011-05-25 02:59:26 3810816 —-a-w- C:\Windows\System32\atiumd6a.dll 2011-05-25 02:58:52 4219904 —-a-w- C:\Windows\SysWow64\atidxx32.dll 2011-05-25 02:50:38 4017152 —-a-w- C:\Windows\SysWow64\atiumdva.dll 2011-05-25 02:49:44 5008384 —-a-w- C:\Windows\System32\atidxx64.dll 2011-05-25 02:47:40 51200 —-a-w- C:\Windows\System32\aticalrt64.dll 2011-05-25 02:47:38 46080 —-a-w- C:\Windows\SysWow64\aticalrt.dll 2011-05-25 02:47:30 44544 —-a-w- C:\Windows\System32\aticalcl64.dll 2011-05-25 02:47:28 44032 —-a-w- C:\Windows\SysWow64\aticalcl.dll 2011-05-25 02:47:18 8489472 —-a-w- C:\Windows\System32\aticaldd64.dll 2011-05-25 02:43:52 6847488 —-a-w- C:\Windows\SysWow64\aticaldd.dll 2011-05-25 02:39:16 4330496 —-a-w- C:\Windows\SysWow64\atiumdag.dll 2011-05-25 02:38:18 53760 —-a-w- C:\Windows\System32\atimpc64.dll 2011-05-25 02:38:18 53760 —-a-w- C:\Windows\System32\amdpcom64.dll 2011-05-25 02:38:14 52736 —-a-w- C:\Windows\SysWow64\atimpc32.dll 2011-05-25 02:38:14 52736 —-a-w- C:\Windows\SysWow64\amdpcom32.dll 2011-05-25 02:33:04 5486592 —-a-w- C:\Windows\System32\atiumd64.dll 2011-05-25 02:26:18 366592 —-a-w- C:\Windows\System32\atiadlxx.dll 2011-05-25 02:26:12 262144 —-a-w- C:\Windows\SysWow64\atiadlxy.dll 2011-05-25 02:26:04 14848 —-a-w- C:\Windows\System32\atig6pxx.dll 2011-05-25 02:26:00 12800 —-a-w- C:\Windows\SysWow64\atiglpxx.dll 2011-05-25 02:26:00 12800 —-a-w- C:\Windows\System32\atiglpxx.dll 2011-05-25 02:25:58 39936 —-a-w- C:\Windows\System32\atig6txx.dll 2011-05-25 02:25:48 32768 —-a-w- C:\Windows\SysWow64\atigktxx.dll 2011-05-25 02:25:42 309760 —-a-w- C:\Windows\System32\drivers\atikmpag.sys 2011-05-25 02:24:58 40960 —-a-w- C:\Windows\System32\atiuxp64.dll 2011-05-25 02:24:50 31744 —-a-w- C:\Windows\SysWow64\atiuxpag.dll 2011-05-25 02:24:44 38912 —-a-w- C:\Windows\System32\atiu9p64.dll 2011-05-25 02:24:36 29184 —-a-w- C:\Windows\SysWow64\atiu9pag.dll 2011-05-25 02:24:08 53248 —-a-w- C:\Windows\System32\drivers\ati2erec.dll 2011-05-25 02:19:00 58880 —-a-w- C:\Windows\System32\coinst.dll 2011-05-25 02:14:10 270720 ——w- C:\Windows\System32\MpSigStub.exe 2011-05-24 11:42:55 404480 —-a-w- C:\Windows\System32\umpnpmgr.dll 2011-05-24 10:40:05 64512 —-a-w- C:\Windows\SysWow64\devobj.dll 2011-05-24 10:40:05 44544 —-a-w- C:\Windows\SysWow64\devrtl.dll 2011-05-24 10:39:38 145920 —-a-w- C:\Windows\SysWow64\cfgmgr32.dll 2011-05-24 10:37:54 252928 —-a-w- C:\Windows\SysWow64\drvinst.exe 2011-05-12 21:43:56 0 —-a-w- C:\Windows\ativpsrm.bin 2011-05-05 08:27:58 51712 —-a-w- C:\Windows\SysWow64\OpenCL.dll 2011-05-04 05:25:03 2315776 —-a-w- C:\Windows\System32\tquery.dll 2011-05-04 05:22:25 778752 —-a-w- C:\Windows\System32\mssvp.dll 2011-05-04 05:22:25 2223616 —-a-w- C:\Windows\System32\mssrch.dll 2011-05-04 05:22:24 75264 —-a-w- C:\Windows\System32\msscntrs.dll 2011-05-04 05:22:24 491520 —-a-w- C:\Windows\System32\mssph.dll 2011-05-04 05:22:24 288256 —-a-w- C:\Windows\System32\mssphtb.dll 2011-05-04 05:19:28 591872 —-a-w- C:\Windows\System32\SearchIndexer.exe 2011-05-04 05:19:28 249856 —-a-w- C:\Windows\System32\SearchProtocolHost.exe 2011-05-04 05:19:28 113664 —-a-w- C:\Windows\System32\SearchFilterHost.exe 2011-05-04 04:34:43 1549312 —-a-w- C:\Windows\SysWow64\tquery.dll 2011-05-04 04:32:02 666624 —-a-w- C:\Windows\SysWow64\mssvp.dll 2011-05-04 04:32:01 337408 —-a-w- C:\Windows\SysWow64\mssph.dll 2011-05-04 04:32:01 197120 —-a-w- C:\Windows\SysWow64\mssphtb.dll 2011-05-04 04:32:01 1401344 —-a-w- C:\Windows\SysWow64\mssrch.dll 2011-05-04 04:32:00 59392 —-a-w- C:\Windows\SysWow64\msscntrs.dll 2011-05-04 04:28:31 86528 —-a-w- C:\Windows\SysWow64\SearchFilterHost.exe 2011-05-04 04:28:31 427520 —-a-w- C:\Windows\SysWow64\SearchIndexer.exe 2011-05-04 04:28:31 164352 —-a-w- C:\Windows\SysWow64\SearchProtocolHost.exe 2011-04-28 21:09:29 361280 —-a-w- C:\Windows\System32\PSUNCpl.cpl 2011-04-28 20:57:43 128072 —-a-w- C:\Windows\System32\drivers\PSINProt.sys 2011-04-28 20:57:43 121928 —-a-w- C:\Windows\System32\drivers\PSINProc.sys 2011-04-28 20:57:42 159816 —-a-w- C:\Windows\System32\drivers\PSINAflt.sys 2011-04-28 20:57:42 149576 —-a-w- C:\Windows\System32\drivers\PSINKNC.sys 2011-04-28 20:57:42 114760 —-a-w- C:\Windows\System32\drivers\PSINFile.sys 2011-04-23 01:29:25 2303488 —-a-w- C:\Windows\System32\jscript9.dll 2011-04-23 01:19:19 2382848 —-a-w- C:\Windows\System32\mshtml.tlb 2011-04-22 23:35:56 1797632 —-a-w- C:\Windows\SysWow64\jscript9.dll 2011-04-22 23:25:54 2382848 —-a-w- C:\Windows\SysWow64\mshtml.tlb 2011-04-22 22:15:29 27520 —-a-w- C:\Windows\System32\drivers\Diskdump.sys 2011-04-20 05:10:22 53760 —-a-w- C:\Windows\System32\OpenCL.dll 2011-04-13 22:40:10 4284416 —-a-w- C:\Windows\SysWow64\GPhotos.scr . ============= FINISH: 14:35:29.12 ===============

Attachments:

thielek,

I'm not seeing anything specifically related to malware, except a volsnap error. This can be related to a rootkit that usually manifests by the user seeing alot of annoying redirects, which you have not reported. But let's check it out anyway.

Please read carefully and follow these steps.
thielek,

Not necessarily… but it's a good sign.

Let's get an online scan.

ESET Online Scanner:

Note: You can use either Internet Explorer or Mozilla FireFox for this scan. You will however need to disable your current installed Anti-Virus, how to do so can be read here.

Vista users: You will need to to right-click on the either the IE or FF icon in the Start Menu or Quick Launch Bar on the Taskbar and select Run as Administrator from the context menu.

  • Please go here then click on: [external image: Posted Image]

    Note: If using Mozilla Firefox you will need to download esetsmartinstaller_enu.exe when prompted then double click on it to install.
    All of the below instructions are compatible with either Internet Explorer or Mozilla FireFox.

  • Select the option YES, I accept the Terms of Use then click on: [external image: Posted Image]
  • When prompted allow the Add-On/Active X to install.
  • Make sure that the option Remove found threats is NOT checked, and the option Scan archives is checked.
  • Now click on Advanced Settings and select the following:
    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
  • Now click on: [external image: Posted Image]
  • The virus signature database… will begin to download. Be patient this make take some time depending on the speed of your Internet Connection.
  • When completed the Online Scan will begin automatically.
  • Do not touch either the Mouse or keyboard during the scan otherwise it may stall.
  • When completed select Uninstall application on close if you so wish, make sure you copy the logfile first!
  • Now click on: [external image: Posted Image]
  • Use notepad to open the logfile located at C:\Program Files\ESET\EsetOnlineScanner\log.txt.
  • Copy and paste that log as a reply to this topic.

Note: Do not forget to re-enable your Anti-Virus application after running the above scan!
thielek,

Well, I've re-reviewed your logs… and I still don't see anything. The scans we ran didn't find anything either - so - I'm thinking your problem isn't malware related.

I suggest that you post in the Windows Forum and see if the Tech Team can help get things straightened out.

You can just delete the tools we downloaded.


The following is my standard advice for the future. Use what you can and pat yourself on the back for what you're already doing.

Please take time to read Preventing Malware - Tools and Practices for Safe Computing. Very important information for your consideration is contained therein.

I would also suggest you read this:
So how did I get infected in the first place?
by Tony Klein


Also: "How to prevent malware"
by miekiemoes

Please respond back that you understand the above and let me know if you have any questions. Otherwise, this thread will be closed Resolved. :thumbup:
Ok I'm relieved to know my system seems clean. Thank you very much for taking the time out to confirm that. I will do as you suggest and take my issues to the windows forum. Appreciate the time you put in. You've been very helpful.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI