This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

What is happening to my laptop?

29 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I'll try to keep this short with as much detail as poss… Had a trojan warning last weekend, AVG didn't locate it. Tuesday - Laptop started slowing down, crashing and doing 'crash dumps'. Wednesday night - crash dumps every 20 mins, so I ran another AVG scan, found nothing, so I uninstalled AVG and tried Microsoft Security Essentials and that tells me everything is fine, also used Malwarebytes. Thursday - laptop seemed fine, I used it all day at work (plugged in) and then in the evening (unplugged), trying to perform the simplest of tasks in Hotmail, the thing froze 5 or 6 times, so I ran a full scan in MSE and this morning I woke to find that after a 9 hour scan it has found no problems. Maybe i'm barking up the wrong tree and this is a hardware issue, but i think the Trojan warning last weekend has something to do with it - where is the thing though? Anyone any ideas what it is? Thanks for taking the time to read. Marcus
Hi and Welcome!! :) My name is Jeff. I would be more than happy to take a look at your log and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

IMPORTANT NOTE : Please do not delete, download or install anything unless instructed to do so.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision. Doing so could make your system inoperable and could require a full reinstall of your Operating System and losing all your programs and data.


Vista and Windows 7 users:

These tools MUST be run from the executable. (.exe) every time you run them
with Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.

Having said that….Let's get going!! :thumbup:
———-

Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt

Attach.txt
———-

GMER

[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
.
———-

Please download aswMBR to your desktop.

  • Double click the aswMBR icon to run it.
    Vista and Windows 7 users right click the icon and choose "Run as administrator".
  • Click the Scan button to start scan.
  • When it finishes, press the save log button, save the logfile to your desktop and post its contents in your next reply.

[external image: Posted Image]
Click the image to enlarge it
———-

In your next reply please post the logs created by DDS, GMER and aswMBR and we will see what we can find. :)
Thanks very much Jeff. Please bare with me while i firstly back up my work, then get through your first lot of instructions… could be a while.
Right, finally got there i think… . DDS (Ver_2011-08-26.01) - NTFSx86 Internet Explorer: 8.0.6001.18904 Run by [removed] at 0:04:42 on 2011-09-23 Microsoft® Windows Vista™ Business 6.0.6000.0.1252.44.1033.18.2046.1090 [GMT 1:00] . . ============== Running Processes =============== . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k rpcss c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k GPSvcGroup C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files\Bonjour\mDNSResponder.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Users\Home\Desktop\LeapFrog Connect\CommandService.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\system32\STacSV.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Windows\system32\SearchIndexer.exe C:\Windows\system32\DRIVERS\xaudio.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\taskeng.exe C:\Program Files\Google\Update\GoogleUpdate.exe C:\Program Files\DellTPad\Apoint.exe C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe C:\Program Files\Java\jre1.6.0\bin\jusched.exe C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe C:\Program Files\Dell\MediaDirect\PCMService.exe C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe C:\Program Files\QuickTime\QTTask.exe C:\Program Files\Adobe\Acrobat 8.0\Acrobat\acrotray.exe C:\Windows\System32\rundll32.exe C:\Windows\System32\rundll32.exe C:\Users\Home\Desktop\LeapFrog Connect\Monitor.exe C:\Program Files\Real\RealPlayer\Update\realsched.exe C:\Program Files\Ask.com\Updater\Updater.exe C:\Program Files\Microsoft Security Client\msseces.exe C:\Program Files\OLYMPUS\OLYMPUS Master\Monitor.exe C:\Program Files\Digital Line Detect\DLG.exe C:\Program Files\Dell\QuickSet\quickset.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Windows\System32\rundll32.exe C:\Program Files\DellTPad\ApMsgFwd.exe C:\Program Files\DellTPad\HidFind.exe C:\Program Files\DellTPad\Apntex.exe C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\wbem\wmiprvse.exe . ============== Pseudo HJT Report =============== . uWindow Title = Internet Explorer provided by Dell uStart Page = hxxp://www.google.co.uk/ uDefault_Page_URL = hxxp://www.google.co.uk/ig/dell?hl=en&client=dell-usuk&channel=uk&ibd=0071106 uInternet Settings,ProxyOverride = *.local BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: ContributeBHO Class: {074c1dc5-9320-4a9a-947d-c042949c6216} - c:\program files\adobe\/Adobe Contribute CS3/contributeieplugin.dll BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\programdata\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0\bin\ssv.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\googletoolbar1.dll BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\dell\bae\BAE.dll BHO: Ask Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll TB: &Google: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\googletoolbar1.dll TB: {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll TB: Contribute Toolbar: {517bdde4-e3a7-4570-b21e-2b52b6139fc7} - c:\program files\adobe\/Adobe Contribute CS3/contributeieplugin.dll TB: Ask Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll TB: {88C7F2AA-F93F-432C-8F0E-B7D85967A527} - No File EB: Adobe PDF: {182ec0be-5110-49c8-a062-beb1d02a220b} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll uRun: [OM_Monitor] c:\program files\olympus\olympus master\Monitor.exe mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide mRun: [ECenter] c:\dell\e-center\EULALauncher.exe mRun: [Apoint] c:\program files\delltpad\Apoint.exe mRun: [SigmatelSysTrayApp] c:\program files\sigmatel\c-major audio\wdm\sttray.exe mRun: [SunJavaUpdateSched] "c:\program files\java\jre1.6.0\bin\jusched.exe" mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start mRun: [RoxWatchTray] "c:\program files\common files\roxio shared\9.0\sharedcom\RoxWatchTray9.exe" mRun: [PCMService] "c:\program files\dell\mediadirect\PCMService.exe" mRun: [dscactivate] c:\dell\dsca.exe 3 mRun: [Google Desktop Search] "c:\program files\google\google desktop search\GoogleDesktop.exe" /startup mRun: [OM_Monitor] c:\program files\olympus\olympus master\FirstStart.exe mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [Acrobat Assistant 8.0] "c:\program files\adobe\acrobat 8.0\acrobat\Acrotray.exe" mRun: [] mRun: [Adobe_ID0EYTHM] c:\progra~1\common~1\adobe\adobev~1\server\bin\VERSIO~2.EXE mRun: [NvSvc] RUNDLL32.EXE c:\windows\system32\nvsvc.dll,nvsvcStart mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit mRun: [NVHotkey] rundll32.exe c:\windows\system32\nvHotkey.dll,Start mRun: [Monitor] "c:\users\home\desktop\leapfrog connect\Monitor.exe" mRun: [TkBellExe] "c:\program files\real\realplayer\update\realsched.exe" -osboot mRun: [AdobeAAMUpdater-1.0] "c:\program files\common files\adobe\oobe\pdapp\uwa\UpdaterStartupUtility.exe" mRun: [SwitchBoard] c:\program files\common files\adobe\switchboard\SwitchBoard.exe mRun: [AdobeCS5ServiceManager] "c:\program files\common files\adobe\cs5servicemanager\CS5ServiceManager.exe" -launchedbylogin mRun: [ApnUpdater] "c:\program files\ask.com\updater\Updater.exe" mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey dRunOnce: [AutoLaunch] c:\program files\lavasoft\ad-aware\AutoLaunch.exe monthly StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office\OSA9.EXE StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\quickset.lnk - c:\windows\installer\{7f0c4457-8e64-491b-8d7b-991504365d1e}\NewShortcut2_53A01CC614B04512A2E710D39BF83DC4.exe IE: Append to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert link target to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Convert link target to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert selected links to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html IE: Convert selected links to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html IE: Convert selection to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Convert selection to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0\bin\ssv.dll Trusted Zone: beatport.com DPF: {0972B098-DEE9-4279-AC7E-4BAAA029102D} - hxxp://assets.photobox.com/assets/aurigma/ImageUploader5.cab?20101202072159 DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab TCP: DhcpNameServer = 192.168.0.1 TCP: Interfaces\{2ECA8770-29AE-4100-8355-74306FA35870} : DhcpNameServer = 192.168.0.1 TCP: Interfaces\{B58B8BC0-D48E-415B-9C2A-23307BD93F62} : DhcpNameServer = 192.168.7.1 Filter: application/x-internet-signup - {A173B69A-1F9B-4823-9FDA-412F641E65D6} - c:\program files\tiscali\tiscali internet\dlls\tiscalifilter.dll AppInit_DLLs: AVGRSSTX.DLL c:\progra~1\google\google~2\GOEC62~1.DLL . ============= SERVICES / DRIVERS =============== . R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2011-4-18 165648] R1 MpKsl032710a0;MpKsl032710a0;c:\programdata\microsoft\microsoft antimalware\definition updates\{35f09007-b2f0-46f3-acde-5d37ab181cf8}\MpKsl032710a0.sys [2011-9-22 28752] R1 MpKsl497943ee;MpKsl497943ee;c:\programdata\microsoft\microsoft antimalware\definition updates\{35f09007-b2f0-46f3-acde-5d37ab181cf8}\MpKsl497943ee.sys [2011-9-22 28752] R1 MpKslc763b238;MpKslc763b238;c:\programdata\microsoft\microsoft antimalware\definition updates\{35f09007-b2f0-46f3-acde-5d37ab181cf8}\MpKslc763b238.sys [2011-9-22 28752] S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2011-5-24 136176] S3 FlyUsb;FLY Fusion;c:\windows\system32\drivers\FlyUsb.sys [2008-4-1 19456] S3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\google\google desktop search\GoogleDesktop.exe [2007-11-5 30192] S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2011-5-24 136176] S3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\drivers\MpNWMon.sys [2011-4-18 43392] S3 SwitchBoard;SwitchBoard;c:\program files\common files\adobe\switchboard\SwitchBoard.exe [2010-2-19 517096] . =============== Created Last 30 ================ . 2011-09-22 22:56:45 28752 —-a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{35f09007-b2f0-46f3-acde-5d37ab181cf8}\MpKsl497943ee.sys 2011-09-22 21:24:52 28752 —-a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{35f09007-b2f0-46f3-acde-5d37ab181cf8}\MpKsl032710a0.sys 2011-09-22 20:49:31 28752 —-a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{35f09007-b2f0-46f3-acde-5d37ab181cf8}\MpKslc763b238.sys 2011-09-22 20:49:24 56200 —-a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{35f09007-b2f0-46f3-acde-5d37ab181cf8}\offreg.dll 2011-09-22 17:59:09 439632 —-a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{390a1807-46f9-4938-bf83-d79cad15619b}\gapaengine.dll 2011-09-22 17:58:39 7152464 —-a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\backup\mpengine.dll 2011-09-22 17:58:02 7269712 —-a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{35f09007-b2f0-46f3-acde-5d37ab181cf8}\mpengine.dll 2011-09-21 08:28:56 ——– d—–w- c:\users\mgds\appdata\roaming\Malwarebytes 2011-09-21 08:27:14 ——– d—–w- c:\programdata\Malwarebytes 2011-09-21 08:27:10 22216 —-a-w- c:\windows\system32\drivers\mbam.sys 2011-09-21 08:27:09 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware 2011-09-20 23:39:24 ——– d—–w- c:\program files\Microsoft Security Client 2011-09-20 19:35:54 7152464 —-a-w- c:\programdata\microsoft\windows defender\definition updates\{870cc9e2-c6b0-40b1-9485-07b9d6065ec1}\mpengine.dll 2011-09-17 09:47:34 77312 —-a-w- c:\windows\system32\ztvunace26.dll 2011-09-17 09:47:34 75264 —-a-w- c:\windows\system32\unacev2.dll 2011-09-17 09:47:34 69632 —-a-w- c:\windows\system32\ztvcabinet.dll 2011-09-17 09:47:34 162304 —-a-w- c:\windows\system32\ztvunrar36.dll 2011-09-17 09:47:34 153088 —-a-w- c:\windows\system32\unrar3.dll 2011-09-17 09:47:26 ——– d—–w- c:\users\mgds\appdata\roaming\Simply Super Software 2011-09-17 09:47:26 ——– d—–w- c:\programdata\Simply Super Software . ==================== Find3M ==================== . . ============= FINISH: 0:05:52.91 =============== aswMBR version 0.9.8.986 Copyright© 2011 AVAST Software Run date: 2011-09-23 01:28:35 —————————– 01:28:35.152 OS Version: Windows 6.0.6000 01:28:35.152 Number of processors: 2 586 0xF0A 01:28:35.152 ComputerName: MGDS-PC UserName: MGDS 01:28:37.102 Initialize success 01:29:08.947 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0 01:29:09.227 Disk 0 Vendor: Hitachi_ SB4O Size: 152627MB BusType: 3 01:29:09.945 Disk 0 MBR read successfully 01:29:09.945 Disk 0 MBR scan 01:29:09.945 Disk 0 Windows VISTA default MBR code 01:29:10.085 Disk 0 scanning sectors +312578048 01:29:10.959 Disk 0 scanning C:\Windows\system32\drivers 01:31:10.861 Service scanning 01:31:11.765 Service MpKsl497943ee c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{35F09007-B2F0-46F3-ACDE-5D37AB181CF8}\MpKsl497943ee.sys **LOCKED** 32 01:31:11.765 Service MpNWMon C:\Windows\system32\DRIVERS\MpNWMon.sys **LOCKED** 32 01:31:12.545 Modules scanning 01:32:40.202 Disk 0 trace - called modules: 01:32:40.233 ntkrnlpa.exe CLASSPNP.SYS disk.sys iastor.sys hal.dll 01:32:40.249 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x84c56ad8] 01:32:40.249 3 ntkrnlpa.exe[820b07e2] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-0[0x84bf0030] 01:32:40.264 Scan finished successfully 01:36:56.525 Disk 0 MBR has been saved successfully to "C:\Users\MGDS\Desktop\MBR.dat" 01:36:56.603 The log file has been saved successfully to "C:\Users\MGDS\Desktop\aswMBR.txt" Hope i've done this right.
Hi Marcusg76,

Thanks for getting me those logs. :)
———-

Please do the following:

Hold down the Windows key and press R to open a run box
type the following text into the run box

appwiz.cpl

This will open your Programs And Features. A list of installed programs will populate

Remove the following programs:

Ask Toolbar
———-

Download Combofix from either of the links below, and save it to your desktop.
Link 1
Link 2

**Note: It is important that it is saved directly to your desktop**

——————————————————————–

IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here

——————————————————————–

Right-Click and Run as Administrator on ComboFix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt for further review.
Hi Marcusg76,

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:

DDS::
uStart Page = hxxp://www.google.co.uk/
uDefault_Page_URL = hxxp://www.google.co.uk/ig/dell?hl=en&client=dell-usuk&channel=uk&ibd=0071106
Trusted Zone: beatport.com
DPF: {0972B098-DEE9-4279-AC7E-4BAAA029102D} - hxxp://assets.photobox.com/assets/aurigma/ImageUploader5.cab?20101202072159

RegLock::
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]


Save this as "CFScript.txt", and as Type: All Files (*.*) in the same location as ComboFix.exe


[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.
———-
Hi Marcusg76,

I see that you have Malwarebytes on your computer already. Would you please open that, Update it and run a Quick Scan. There will be a log created that I will need in your next reply.
———-

ESET Online Scanner
I'd like us to scan your machine with ESET Online Scan

Note: It is recommended to disable on-board anti-virus program and anti-spyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your anti-virus along with your anti-spyware programs.



As a Vista/Win7 user you will need to right click your browser icon and select "Run as Administrator" in order to run this scan.
  • Do not use this instance of your browser for anything besides doing this scan
  • When the scan is complete and the results saved, close that instance of your browser
  • Open a new one the usual way and post the results in this topic.


  • Right-click and Run as Administartor on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the [external image: Posted Image] button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the [external image: Posted Image] icon on your desktop.
  • Check [external image: Posted Image]
  • Click the Start button.
  • Accept any security warnings from your browser.
  • Check [external image: Posted Image]
  • Make sure that the option "Remove found threats" is Unchecked
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin
    scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push [external image: Posted Image]
  • Push [external image: Posted Image], and save the file to your desktop using a unique name, such as
    ESETScan. Include the contents of this report in your next reply.
  • Push the Back button.
  • Push Finish
http://www.eset.com/onlinescan/
———-

In your next reply please post the logs created by Malwarebytes and ESET Online Scanner. :)
Malwarebytes' Anti-Malware 1.51.2.1300 www.malwarebytes.org Database version: 7784 Windows 6.0.6000 Internet Explorer 8.0.6001.18904 23/09/2011 22:19:59 mbam-log-2011-09-23 (22-19-59).txt Scan type: Quick scan Objects scanned: 191493 Time elapsed: 5 minute(s), 6 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) I think you've found it… Eset… C:\Users\MGDS\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PL0SVG9C\cnet_trj682_exe[1].exe a variant of Win32/InstallCore.C application
Hi Marcusg76,

First open an elevated command prompt > Click Start and type cmd in Start Search.
When cmd.exe populates above, right click it and select Run as Administrator to open an elevated command prompt.

Copy the contents of the code box > right click in the command window and select paste
del "C:\Users\MGDS\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PL0SVG9C\cnet_trj682_exe[1].exe" /f /q
Press Enter
———-

Please download JavaRa to your desktop and unzip it to its own
folder
  • Run JavaRa.exe (double-click for XP/right-click and Run as Administrator for Vista), pick the language of your choice and click Select. Then
    click Remove Older Versions.
  • Accept any prompts.
  • Open JavaRa.exe (double-click for XP/right-click and Run as Administrator for Vista) again and select Search For Updates.
  • Select Update Using Sun Java's Website then click Search and click on the Open Webpage button. Download and install the latest
    Java Runtime Environment (JRE) version for your computer.
———-

Please run DDS once more and post both logs created into your next reply.

How is your system running now? :)
Hi Jeff, i'm just in the Java download part of your last instruction, which of these do you recommend? Windows x86 Online 0.85 MB jre-7-windows-i586-iftw.exe Windows x86 Offline 19.26 MB jre-7-windows-i586.exe Windows x64 20.34 MB jre-7-windows-x64.exe At a guess i'd go for the bottom one, with it being the larger file size and not specifying Online or Offline, would this be right?
Sorry for the delay Jeff, here's the new DDS text and the other part is attached… . DDS (Ver_2011-08-26.01) - NTFSx86 Internet Explorer: 8.0.6001.18904 Run by [removed] at 20:17:38 on 2011-09-24 Microsoft® Windows Vista™ Business 6.0.6000.0.1252.44.1033.18.2046.953 [GMT 1:00] . . ============== Running Processes =============== . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k rpcss c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k GPSvcGroup C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files\Bonjour\mDNSResponder.exe C:\Windows\system32\Dwm.exe C:\Users\Home\Desktop\LeapFrog Connect\CommandService.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\system32\STacSV.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Windows\system32\SearchIndexer.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\taskeng.exe C:\Program Files\DellTPad\Apoint.exe C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe C:\Program Files\Dell\MediaDirect\PCMService.exe C:\Program Files\QuickTime\QTTask.exe C:\Program Files\Adobe\Acrobat 8.0\Acrobat\acrotray.exe C:\Users\Home\Desktop\LeapFrog Connect\Monitor.exe C:\Program Files\Microsoft Security Client\msseces.exe C:\Program Files\OLYMPUS\OLYMPUS Master\Monitor.exe C:\Program Files\Digital Line Detect\DLG.exe C:\Program Files\Dell\QuickSet\quickset.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Program Files\DellTPad\ApMsgFwd.exe C:\Program Files\DellTPad\HidFind.exe C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe C:\Windows\Explorer.exe C:\Windows\system32\vssvc.exe C:\Windows\System32\svchost.exe -k swprv C:\Program Files\Real\RealPlayer\update\realsched.exe C:\Windows\system32\msiexec.exe C:\Windows\system32\SearchFilterHost.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\wbem\wmiprvse.exe . ============== Pseudo HJT Report =============== . uInternet Settings,ProxyOverride = *.local BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: ContributeBHO Class: {074c1dc5-9320-4a9a-947d-c042949c6216} - c:\program files\adobe\/Adobe Contribute CS3/contributeieplugin.dll BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\programdata\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\googletoolbar1.dll BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\dell\bae\BAE.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre7\bin\jp2ssv.dll TB: &Google: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\googletoolbar1.dll TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll TB: Contribute Toolbar: {517bdde4-e3a7-4570-b21e-2b52b6139fc7} - c:\program files\adobe\/Adobe Contribute CS3/contributeieplugin.dll uRun: [OM_Monitor] c:\program files\olympus\olympus master\Monitor.exe mRun: [ECenter] c:\dell\e-center\EULALauncher.exe mRun: [Apoint] c:\program files\delltpad\Apoint.exe mRun: [SigmatelSysTrayApp] c:\program files\sigmatel\c-major audio\wdm\sttray.exe mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start mRun: [RoxWatchTray] "c:\program files\common files\roxio shared\9.0\sharedcom\RoxWatchTray9.exe" mRun: [PCMService] "c:\program files\dell\mediadirect\PCMService.exe" mRun: [dscactivate] c:\dell\dsca.exe 3 mRun: [Google Desktop Search] "c:\program files\google\google desktop search\GoogleDesktop.exe" /startup mRun: [OM_Monitor] c:\program files\olympus\olympus master\FirstStart.exe mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [Acrobat Assistant 8.0] "c:\program files\adobe\acrobat 8.0\acrobat\Acrotray.exe" mRun: [Adobe_ID0EYTHM] c:\progra~1\common~1\adobe\adobev~1\server\bin\VERSIO~2.EXE mRun: [NvSvc] RUNDLL32.EXE c:\windows\system32\nvsvc.dll,nvsvcStart mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit mRun: [NVHotkey] rundll32.exe c:\windows\system32\nvHotkey.dll,Start mRun: [Monitor] "c:\users\home\desktop\leapfrog connect\Monitor.exe" mRun: [TkBellExe] "c:\program files\real\realplayer\update\realsched.exe" -osboot mRun: [AdobeAAMUpdater-1.0] "c:\program files\common files\adobe\oobe\pdapp\uwa\UpdaterStartupUtility.exe" mRun: [SwitchBoard] c:\program files\common files\adobe\switchboard\SwitchBoard.exe mRun: [AdobeCS5ServiceManager] "c:\program files\common files\adobe\cs5servicemanager\CS5ServiceManager.exe" -launchedbylogin mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office\OSA9.EXE StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\quickset.lnk - c:\windows\installer\{7f0c4457-8e64-491b-8d7b-991504365d1e}\NewShortcut2_53A01CC614B04512A2E710D39BF83DC4.exe IE: Append to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert link target to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Convert link target to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert selected links to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html IE: Convert selected links to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html IE: Convert selection to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Convert selection to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0-windows-i586.cab DPF: {CAFEEFAC-0017-0000-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0-windows-i586.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab TCP: DhcpNameServer = 192.168.0.1 TCP: Interfaces\{2ECA8770-29AE-4100-8355-74306FA35870} : DhcpNameServer = 192.168.0.1 TCP: Interfaces\{B58B8BC0-D48E-415B-9C2A-23307BD93F62} : DhcpNameServer = 192.168.7.1 Filter: application/x-internet-signup - {A173B69A-1F9B-4823-9FDA-412F641E65D6} - c:\program files\tiscali\tiscali internet\dlls\tiscalifilter.dll AppInit_DLLs: c:\progra~1\google\google~2\GoogleDesktopNetwork3.dll . ============= SERVICES / DRIVERS =============== . R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2011-4-18 165648] R1 MpKsl7660d078;MpKsl7660d078;c:\programdata\microsoft\microsoft antimalware\definition updates\{c33b92ef-acbd-4159-befb-a7300a688461}\MpKsl7660d078.sys [2011-9-24 28752] R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\drivers\MpNWMon.sys [2011-4-18 43392] S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2011-5-24 136176] S3 FlyUsb;FLY Fusion;c:\windows\system32\drivers\FlyUsb.sys [2008-4-1 19456] S3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\google\google desktop search\GoogleDesktop.exe [2007-11-5 30192] S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2011-5-24 136176] S3 SwitchBoard;SwitchBoard;c:\program files\common files\adobe\switchboard\SwitchBoard.exe [2010-2-19 517096] . =============== Created Last 30 ================ . 2011-09-24 19:15:09 544656 —-a-w- c:\windows\system32\deployJava1.dll 2011-09-24 08:12:06 28752 —-a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{c33b92ef-acbd-4159-befb-a7300a688461}\MpKsl7660d078.sys 2011-09-24 08:12:01 56200 —-a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{c33b92ef-acbd-4159-befb-a7300a688461}\offreg.dll 2011-09-24 08:11:53 7269712 —-a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{c33b92ef-acbd-4159-befb-a7300a688461}\mpengine.dll 2011-09-23 21:29:22 ——– d—–w- c:\program files\ESET 2011-09-23 20:05:16 ——– d-sh–w- C:\$RECYCLE.BIN 2011-09-23 07:13:25 208896 —-a-w- c:\windows\MBR.exe 2011-09-23 07:13:24 98816 —-a-w- c:\windows\sed.exe 2011-09-23 07:13:24 518144 —-a-w- c:\windows\SWREG.exe 2011-09-23 07:13:24 256000 —-a-w- c:\windows\PEV.exe 2011-09-22 17:59:09 439632 ——w- c:\programdata\microsoft\microsoft antimalware\definition updates\{390a1807-46f9-4938-bf83-d79cad15619b}\gapaengine.dll 2011-09-22 17:58:39 7269712 —-a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\backup\mpengine.dll 2011-09-21 08:28:56 ——– d—–w- c:\users\mgds\appdata\roaming\Malwarebytes 2011-09-21 08:27:14 ——– d—–w- c:\programdata\Malwarebytes 2011-09-21 08:27:10 22216 —-a-w- c:\windows\system32\drivers\mbam.sys 2011-09-21 08:27:09 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware 2011-09-20 23:39:24 ——– d—–w- c:\program files\Microsoft Security Client 2011-09-20 19:35:54 7152464 —-a-w- c:\programdata\microsoft\windows defender\definition updates\{870cc9e2-c6b0-40b1-9485-07b9d6065ec1}\mpengine.dll 2011-09-17 09:47:34 77312 —-a-w- c:\windows\system32\ztvunace26.dll 2011-09-17 09:47:34 75264 —-a-w- c:\windows\system32\unacev2.dll 2011-09-17 09:47:34 69632 —-a-w- c:\windows\system32\ztvcabinet.dll 2011-09-17 09:47:34 162304 —-a-w- c:\windows\system32\ztvunrar36.dll 2011-09-17 09:47:34 153088 —-a-w- c:\windows\system32\unrar3.dll 2011-09-17 09:47:26 ——– d—–w- c:\users\mgds\appdata\roaming\Simply Super Software 2011-09-17 09:47:26 ——– d—–w- c:\programdata\Simply Super Software . ==================== Find3M ==================== . . ============= FINISH: 20:18:32.66 =============== The laptop is running much quicker now, start up used to take forever and now it's almost instant with the internet connected and ready to go… but no doubt there will be problems when my wife gets back on it! Thank you very, very much!

Attachments:

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI