I'll try to keep this short with as much detail as poss…
Had a trojan warning last weekend, AVG didn't locate it.
Tuesday - Laptop started slowing down, crashing and doing 'crash dumps'.
Wednesday night - crash dumps every 20 mins, so I ran another AVG scan, found nothing, so I uninstalled AVG and tried Microsoft Security Essentials and that tells me everything is fine, also used Malwarebytes.
Thursday - laptop seemed fine, I used it all day at work (plugged in) and then in the evening (unplugged), trying to perform the simplest of tasks in Hotmail, the thing froze 5 or 6 times, so I ran a full scan in MSE and this morning I woke to find that after a 9 hour scan it has found no problems.
Maybe i'm barking up the wrong tree and this is a hardware issue, but i think the Trojan warning last weekend has something to do with it - where is the thing though?
Anyone any ideas what it is?
Thanks for taking the time to read.
Marcus
Hi and Welcome!!
My name is
Jeff . I would be more than happy to take a look at your log and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
The fixes are specific to your problem and should only be used for the issues on this machine.
Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
It's often worth reading through these instructions and printing them for ease of reference.
If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
Please reply to this thread. Do not start a new topic.
IMPORTANT NOTE : Please do not delete, download or install anything unless instructed to do so.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision. Doing so could make your system inoperable and could require a full reinstall of your Operating System and losing all your programs and data.
Vista and Windows 7 users:
These tools MUST be run from the executable. (.exe) every time you run them
with Admin Rights (Right click, choose "Run as Administrator")
Stay with this topic until I give you the all clean post.
Having said that….
Let's get going !!
———-
Please download
DDS from either of these links
LINK 1
LINK 2
and save it to your
desktop.
Disable any script blocking protection Double click dds to run the tool. When done, two DDS.txt's will open. Save both reports to your desktop. —————————————————
Please include the contents of the following in your next reply:
DDS.txt
Attach.txt
———-
GMER
[external image: Posted Image]
Download
GMER Rootkit Scanner from
here or
here .
Extract the contents of the zipped file to desktop. Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent . If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO .
[external image: Posted Image]
Click the image to enlarge it
In the right panel, you will see several boxes that have been checked. Uncheck the following … IAT/EAT Drives/Partition other than Systemdrive (typically C:\) Show All (don't miss this one) Then click the Scan button & wait for it to finish. Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
Save it where you can easily find it, such as your desktop, and attach it in your reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries .
———-
Please download
aswMBR to your desktop.
Double click the aswMBR icon to run it.
Vista and Windows 7 users right click the icon and choose "Run as administrator" . Click the Scan button to start scan. When it finishes, press the save log button, save the logfile to your desktop and post its contents in your next reply.
[external image: Posted Image]
Click the image to enlarge it
———-
In your next reply please post the logs created by DDS, GMER and aswMBR and we will see what we can find.
Thanks very much Jeff. Please bare with me while i firstly back up my work, then get through your first lot of instructions… could be a while.
Not a problem at all.
Post them whenever you get them. If you need more time please let me know.
Right, finally got there i think…
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 8.0.6001.18904
Run by [removed] at 0:04:42 on 2011-09-23
Microsoft® Windows Vista™ Business 6.0.6000.0.1252.44.1033.18.2046.1090 [GMT 1:00]
.
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Users\Home\Desktop\LeapFrog Connect\CommandService.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\STacSV.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\DellTPad\Apoint.exe
C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe
C:\Program Files\Java\jre1.6.0\bin\jusched.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
C:\Program Files\Dell\MediaDirect\PCMService.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\acrotray.exe
C:\Windows\System32\rundll32.exe
C:\Windows\System32\rundll32.exe
C:\Users\Home\Desktop\LeapFrog Connect\Monitor.exe
C:\Program Files\Real\RealPlayer\Update\realsched.exe
C:\Program Files\Ask.com\Updater\Updater.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\OLYMPUS\OLYMPUS Master\Monitor.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Program Files\DellTPad\Apntex.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uWindow Title = Internet Explorer provided by Dell
uStart Page = hxxp://www.google.co.uk/
uDefault_Page_URL = hxxp://www.google.co.uk/ig/dell?hl=en&client=dell-usuk&channel=uk&ibd=0071106
uInternet Settings,ProxyOverride = *.local
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: ContributeBHO Class: {074c1dc5-9320-4a9a-947d-c042949c6216} - c:\program files\adobe\/Adobe Contribute CS3/contributeieplugin.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\programdata\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0\bin\ssv.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\googletoolbar1.dll
BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll
BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\dell\bae\BAE.dll
BHO: Ask Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll
TB: &Google: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\googletoolbar1.dll
TB: {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll
TB: Contribute Toolbar: {517bdde4-e3a7-4570-b21e-2b52b6139fc7} - c:\program files\adobe\/Adobe Contribute CS3/contributeieplugin.dll
TB: Ask Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll
TB: {88C7F2AA-F93F-432C-8F0E-B7D85967A527} - No File
EB: Adobe PDF: {182ec0be-5110-49c8-a062-beb1d02a220b} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll
uRun: [OM_Monitor] c:\program files\olympus\olympus master\Monitor.exe
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [ECenter] c:\dell\e-center\EULALauncher.exe
mRun: [Apoint] c:\program files\delltpad\Apoint.exe
mRun: [SigmatelSysTrayApp] c:\program files\sigmatel\c-major audio\wdm\sttray.exe
mRun: [SunJavaUpdateSched] "c:\program files\java\jre1.6.0\bin\jusched.exe"
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [RoxWatchTray] "c:\program files\common files\roxio shared\9.0\sharedcom\RoxWatchTray9.exe"
mRun: [PCMService] "c:\program files\dell\mediadirect\PCMService.exe"
mRun: [dscactivate] c:\dell\dsca.exe 3
mRun: [Google Desktop Search] "c:\program files\google\google desktop search\GoogleDesktop.exe" /startup
mRun: [OM_Monitor] c:\program files\olympus\olympus master\FirstStart.exe
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [Acrobat Assistant 8.0] "c:\program files\adobe\acrobat 8.0\acrobat\Acrotray.exe"
mRun: []
mRun: [Adobe_ID0EYTHM] c:\progra~1\common~1\adobe\adobev~1\server\bin\VERSIO~2.EXE
mRun: [NvSvc] RUNDLL32.EXE c:\windows\system32\nvsvc.dll,nvsvcStart
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [NVHotkey] rundll32.exe c:\windows\system32\nvHotkey.dll,Start
mRun: [Monitor] "c:\users\home\desktop\leapfrog connect\Monitor.exe"
mRun: [TkBellExe] "c:\program files\real\realplayer\update\realsched.exe" -osboot
mRun: [AdobeAAMUpdater-1.0] "c:\program files\common files\adobe\oobe\pdapp\uwa\UpdaterStartupUtility.exe"
mRun: [SwitchBoard] c:\program files\common files\adobe\switchboard\SwitchBoard.exe
mRun: [AdobeCS5ServiceManager] "c:\program files\common files\adobe\cs5servicemanager\CS5ServiceManager.exe" -launchedbylogin
mRun: [ApnUpdater] "c:\program files\ask.com\updater\Updater.exe"
mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey
dRunOnce: [AutoLaunch] c:\program files\lavasoft\ad-aware\AutoLaunch.exe monthly
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office\OSA9.EXE
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\quickset.lnk - c:\windows\installer\{7f0c4457-8e64-491b-8d7b-991504365d1e}\NewShortcut2_53A01CC614B04512A2E710D39BF83DC4.exe
IE: Append to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0\bin\ssv.dll
Trusted Zone: beatport.com
DPF: {0972B098-DEE9-4279-AC7E-4BAAA029102D} - hxxp://assets.photobox.com/assets/aurigma/ImageUploader5.cab?20101202072159
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: DhcpNameServer = 192.168.0.1
TCP: Interfaces\{2ECA8770-29AE-4100-8355-74306FA35870} : DhcpNameServer = 192.168.0.1
TCP: Interfaces\{B58B8BC0-D48E-415B-9C2A-23307BD93F62} : DhcpNameServer = 192.168.7.1
Filter: application/x-internet-signup - {A173B69A-1F9B-4823-9FDA-412F641E65D6} - c:\program files\tiscali\tiscali internet\dlls\tiscalifilter.dll
AppInit_DLLs: AVGRSSTX.DLL c:\progra~1\google\google~2\GOEC62~1.DLL
.
============= SERVICES / DRIVERS ===============
.
R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2011-4-18 165648]
R1 MpKsl032710a0;MpKsl032710a0;c:\programdata\microsoft\microsoft antimalware\definition updates\{35f09007-b2f0-46f3-acde-5d37ab181cf8}\MpKsl032710a0.sys [2011-9-22 28752]
R1 MpKsl497943ee;MpKsl497943ee;c:\programdata\microsoft\microsoft antimalware\definition updates\{35f09007-b2f0-46f3-acde-5d37ab181cf8}\MpKsl497943ee.sys [2011-9-22 28752]
R1 MpKslc763b238;MpKslc763b238;c:\programdata\microsoft\microsoft antimalware\definition updates\{35f09007-b2f0-46f3-acde-5d37ab181cf8}\MpKslc763b238.sys [2011-9-22 28752]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2011-5-24 136176]
S3 FlyUsb;FLY Fusion;c:\windows\system32\drivers\FlyUsb.sys [2008-4-1 19456]
S3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\google\google desktop search\GoogleDesktop.exe [2007-11-5 30192]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2011-5-24 136176]
S3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\drivers\MpNWMon.sys [2011-4-18 43392]
S3 SwitchBoard;SwitchBoard;c:\program files\common files\adobe\switchboard\SwitchBoard.exe [2010-2-19 517096]
.
=============== Created Last 30 ================
.
2011-09-22 22:56:45 28752 —-a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{35f09007-b2f0-46f3-acde-5d37ab181cf8}\MpKsl497943ee.sys
2011-09-22 21:24:52 28752 —-a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{35f09007-b2f0-46f3-acde-5d37ab181cf8}\MpKsl032710a0.sys
2011-09-22 20:49:31 28752 —-a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{35f09007-b2f0-46f3-acde-5d37ab181cf8}\MpKslc763b238.sys
2011-09-22 20:49:24 56200 —-a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{35f09007-b2f0-46f3-acde-5d37ab181cf8}\offreg.dll
2011-09-22 17:59:09 439632 —-a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{390a1807-46f9-4938-bf83-d79cad15619b}\gapaengine.dll
2011-09-22 17:58:39 7152464 —-a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\backup\mpengine.dll
2011-09-22 17:58:02 7269712 —-a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{35f09007-b2f0-46f3-acde-5d37ab181cf8}\mpengine.dll
2011-09-21 08:28:56 ——– d—–w- c:\users\mgds\appdata\roaming\Malwarebytes
2011-09-21 08:27:14 ——– d—–w- c:\programdata\Malwarebytes
2011-09-21 08:27:10 22216 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-09-21 08:27:09 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2011-09-20 23:39:24 ——– d—–w- c:\program files\Microsoft Security Client
2011-09-20 19:35:54 7152464 —-a-w- c:\programdata\microsoft\windows defender\definition updates\{870cc9e2-c6b0-40b1-9485-07b9d6065ec1}\mpengine.dll
2011-09-17 09:47:34 77312 —-a-w- c:\windows\system32\ztvunace26.dll
2011-09-17 09:47:34 75264 —-a-w- c:\windows\system32\unacev2.dll
2011-09-17 09:47:34 69632 —-a-w- c:\windows\system32\ztvcabinet.dll
2011-09-17 09:47:34 162304 —-a-w- c:\windows\system32\ztvunrar36.dll
2011-09-17 09:47:34 153088 —-a-w- c:\windows\system32\unrar3.dll
2011-09-17 09:47:26 ——– d—–w- c:\users\mgds\appdata\roaming\Simply Super Software
2011-09-17 09:47:26 ——– d—–w- c:\programdata\Simply Super Software
.
==================== Find3M ====================
.
.
============= FINISH: 0:05:52.91 ===============
aswMBR version 0.9.8.986 Copyright© 2011 AVAST Software
Run date: 2011-09-23 01:28:35
—————————–
01:28:35.152 OS Version: Windows 6.0.6000
01:28:35.152 Number of processors: 2 586 0xF0A
01:28:35.152 ComputerName: MGDS-PC UserName: MGDS
01:28:37.102 Initialize success
01:29:08.947 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0
01:29:09.227 Disk 0 Vendor: Hitachi_ SB4O Size: 152627MB BusType: 3
01:29:09.945 Disk 0 MBR read successfully
01:29:09.945 Disk 0 MBR scan
01:29:09.945 Disk 0 Windows VISTA default MBR code
01:29:10.085 Disk 0 scanning sectors +312578048
01:29:10.959 Disk 0 scanning C:\Windows\system32\drivers
01:31:10.861 Service scanning
01:31:11.765 Service MpKsl497943ee c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{35F09007-B2F0-46F3-ACDE-5D37AB181CF8}\MpKsl497943ee.sys **LOCKED** 32
01:31:11.765 Service MpNWMon C:\Windows\system32\DRIVERS\MpNWMon.sys **LOCKED** 32
01:31:12.545 Modules scanning
01:32:40.202 Disk 0 trace - called modules:
01:32:40.233 ntkrnlpa.exe CLASSPNP.SYS disk.sys iastor.sys hal.dll
01:32:40.249 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x84c56ad8]
01:32:40.249 3 ntkrnlpa.exe[820b07e2] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-0[0x84bf0030]
01:32:40.264 Scan finished successfully
01:36:56.525 Disk 0 MBR has been saved successfully to "C:\Users\MGDS\Desktop\MBR.dat"
01:36:56.603 The log file has been saved successfully to "C:\Users\MGDS\Desktop\aswMBR.txt"
Hope i've done this right.
Hi Marcusg76,
Thanks for getting me those logs.
———-
Please do the following:
Hold down the
Windows key and press
R to open a run box
type the following text into the run box
appwiz.cpl
This will open your
Programs And Features . A list of installed programs will populate
Remove the following programs:
Ask Toolbar
———-
Download
Combofix from either of the links below, and save it to your desktop.
Link 1
Link 2
**Note: It is important that it is saved directly to your desktop**
——————————————————————–
IMPORTANT -
Disable your AntiVirus and AntiSpyware applications , usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link
here
——————————————————————–
Right-Click and Run as Administrator on
ComboFix.exe & follow the prompts.
When finished, it will produce a report for you. Please post the C:\ComboFix.txt for further review.
Thanks for the quick reply Jeff, here's the next doc…
Hi Marcusg76,
1. Close any open browsers.
2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
3. Open
notepad and copy/paste the text in the quotebox below into it:
DDS::
uStart Page = hxxp://www.google.co.uk/
uDefault_Page_URL = hxxp://www.google.co.uk/ig/dell?hl=en&client=dell-usuk&channel=uk&ibd=0071106
Trusted Zone: beatport.com
DPF: {0972B098-DEE9-4279-AC7E-4BAAA029102D} - hxxp://assets.photobox.com/assets/aurigma/ImageUploader5.cab?20101202072159
RegLock::
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
Save this as
"CFScript.txt" , and as Type: All Files (*.*) in the same location as ComboFix.exe
[external image: Posted Image]
Refering to the picture above, drag CFScript into ComboFix.exe
When finished, it shall produce a log for you at
C:\ComboFix.txt which I will require in your next reply.
———-
Thanks again Jeff. Here's the new file.
How are things looking? The laptop seems much quicker but it's all just symbols and numbers to me, have we found anything?
Hi Marcusg76,
I see that you have Malwarebytes on your computer already. Would you please open that, Update it and run a Quick Scan. There will be a log created that I will need in your next reply.
———-
ESET Online Scanner
I'd like us to scan your machine with ESET Online Scan
Note: It is recommended to disable on-board anti-virus program and anti-spyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your anti-virus along with your anti-spyware programs.
As a Vista/Win7 user you will need to right click your browser icon and select "Run as Administrator" in order to run this scan.
Do not use this instance of your browser for anything besides doing this scan When the scan is complete and the results saved, close that instance of your browser Open a new one the usual way and post the results in this topic.
Right-click and Run as Administartor on the following link to open ESET OnlineScan in a new window.
ESET OnlineScan Click the [external image: Posted Image] button. For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop. Double click on the [external image: Posted Image] icon on your desktop. Check [external image: Posted Image] Click the Start button. Accept any security warnings from your browser. Check [external image: Posted Image] Make sure that the option "Remove found threats" is Unchecked Push the Start button. ESET will then download updates for itself, install itself, and begin
scanning your computer. Please be patient as this can take some time. When the scan completes, push [external image: Posted Image] Push [external image: Posted Image] , and save the file to your desktop using a unique name, such as
ESETScan. Include the contents of this report in your next reply. Push the Back button. Push Finish
http://www.eset.com/onlinescan/
———-
In your next reply please post the logs created by Malwarebytes and ESET Online Scanner.
Malwarebytes' Anti-Malware 1.51.2.1300
www.malwarebytes.org
Database version: 7784
Windows 6.0.6000
Internet Explorer 8.0.6001.18904
23/09/2011 22:19:59
mbam-log-2011-09-23 (22-19-59).txt
Scan type: Quick scan
Objects scanned: 191493
Time elapsed: 5 minute(s), 6 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
I think you've found it…
Eset…
C:\Users\MGDS\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PL0SVG9C\cnet_trj682_exe[1].exe a variant of Win32/InstallCore.C application
Hi Marcusg76,
First open an elevated command prompt > Click
Start and type
cmd in Start Search.
When cmd.exe populates above,
right click it and select
Run as Administrator to open an elevated command prompt.
Copy the contents of the code box > right click in the command window and select paste
del "C:\Users\MGDS\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PL0SVG9C\cnet_trj682_exe[1].exe" /f /q
Press
Enter
———-
Please download
JavaRa to your desktop and unzip it to its own
folder
Run JavaRa.exe (double-click for XP/right-click and Run as Administrator for Vista), pick the language of your choice and click Select. Then
click Remove Older Versions . Accept any prompts. Open JavaRa.exe (double-click for XP/right-click and Run as Administrator for Vista) again and select Search For Updates . Select Update Using Sun Java's Website then click Search and click on the Open Webpage button. Download and install the latest
Java Runtime Environment (JRE) version for your computer.
———-
Please run
DDS once more and post
both logs created into your next reply.
How is your system running now?
Hi Jeff, i'm just in the Java download part of your last instruction, which of these do you recommend?
Windows x86 Online 0.85 MB jre-7-windows-i586-iftw.exe
Windows x86 Offline 19.26 MB jre-7-windows-i586.exe
Windows x64 20.34 MB jre-7-windows-x64.exe
At a guess i'd go for the bottom one, with it being the larger file size and not specifying Online or Offline, would this be right?
Hi Marcusg76,
Yes go ahead and use the "Offline" choice.
Sorry for the delay Jeff, here's the new DDS text and the other part is attached…
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 8.0.6001.18904
Run by [removed] at 20:17:38 on 2011-09-24
Microsoft® Windows Vista™ Business 6.0.6000.0.1252.44.1033.18.2046.953 [GMT 1:00]
.
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\system32\Dwm.exe
C:\Users\Home\Desktop\LeapFrog Connect\CommandService.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\STacSV.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\DellTPad\Apoint.exe
C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
C:\Program Files\Dell\MediaDirect\PCMService.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\acrotray.exe
C:\Users\Home\Desktop\LeapFrog Connect\Monitor.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\OLYMPUS\OLYMPUS Master\Monitor.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe
C:\Windows\Explorer.exe
C:\Windows\system32\vssvc.exe
C:\Windows\System32\svchost.exe -k swprv
C:\Program Files\Real\RealPlayer\update\realsched.exe
C:\Windows\system32\msiexec.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uInternet Settings,ProxyOverride = *.local
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: ContributeBHO Class: {074c1dc5-9320-4a9a-947d-c042949c6216} - c:\program files\adobe\/Adobe Contribute CS3/contributeieplugin.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\programdata\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\googletoolbar1.dll
BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll
BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\dell\bae\BAE.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre7\bin\jp2ssv.dll
TB: &Google: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\googletoolbar1.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll
TB: Contribute Toolbar: {517bdde4-e3a7-4570-b21e-2b52b6139fc7} - c:\program files\adobe\/Adobe Contribute CS3/contributeieplugin.dll
uRun: [OM_Monitor] c:\program files\olympus\olympus master\Monitor.exe
mRun: [ECenter] c:\dell\e-center\EULALauncher.exe
mRun: [Apoint] c:\program files\delltpad\Apoint.exe
mRun: [SigmatelSysTrayApp] c:\program files\sigmatel\c-major audio\wdm\sttray.exe
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [RoxWatchTray] "c:\program files\common files\roxio shared\9.0\sharedcom\RoxWatchTray9.exe"
mRun: [PCMService] "c:\program files\dell\mediadirect\PCMService.exe"
mRun: [dscactivate] c:\dell\dsca.exe 3
mRun: [Google Desktop Search] "c:\program files\google\google desktop search\GoogleDesktop.exe" /startup
mRun: [OM_Monitor] c:\program files\olympus\olympus master\FirstStart.exe
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [Acrobat Assistant 8.0] "c:\program files\adobe\acrobat 8.0\acrobat\Acrotray.exe"
mRun: [Adobe_ID0EYTHM] c:\progra~1\common~1\adobe\adobev~1\server\bin\VERSIO~2.EXE
mRun: [NvSvc] RUNDLL32.EXE c:\windows\system32\nvsvc.dll,nvsvcStart
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [NVHotkey] rundll32.exe c:\windows\system32\nvHotkey.dll,Start
mRun: [Monitor] "c:\users\home\desktop\leapfrog connect\Monitor.exe"
mRun: [TkBellExe] "c:\program files\real\realplayer\update\realsched.exe" -osboot
mRun: [AdobeAAMUpdater-1.0] "c:\program files\common files\adobe\oobe\pdapp\uwa\UpdaterStartupUtility.exe"
mRun: [SwitchBoard] c:\program files\common files\adobe\switchboard\SwitchBoard.exe
mRun: [AdobeCS5ServiceManager] "c:\program files\common files\adobe\cs5servicemanager\CS5ServiceManager.exe" -launchedbylogin
mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office\OSA9.EXE
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\quickset.lnk - c:\windows\installer\{7f0c4457-8e64-491b-8d7b-991504365d1e}\NewShortcut2_53A01CC614B04512A2E710D39BF83DC4.exe
IE: Append to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0-windows-i586.cab
DPF: {CAFEEFAC-0017-0000-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: DhcpNameServer = 192.168.0.1
TCP: Interfaces\{2ECA8770-29AE-4100-8355-74306FA35870} : DhcpNameServer = 192.168.0.1
TCP: Interfaces\{B58B8BC0-D48E-415B-9C2A-23307BD93F62} : DhcpNameServer = 192.168.7.1
Filter: application/x-internet-signup - {A173B69A-1F9B-4823-9FDA-412F641E65D6} - c:\program files\tiscali\tiscali internet\dlls\tiscalifilter.dll
AppInit_DLLs: c:\progra~1\google\google~2\GoogleDesktopNetwork3.dll
.
============= SERVICES / DRIVERS ===============
.
R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2011-4-18 165648]
R1 MpKsl7660d078;MpKsl7660d078;c:\programdata\microsoft\microsoft antimalware\definition updates\{c33b92ef-acbd-4159-befb-a7300a688461}\MpKsl7660d078.sys [2011-9-24 28752]
R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\drivers\MpNWMon.sys [2011-4-18 43392]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2011-5-24 136176]
S3 FlyUsb;FLY Fusion;c:\windows\system32\drivers\FlyUsb.sys [2008-4-1 19456]
S3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\google\google desktop search\GoogleDesktop.exe [2007-11-5 30192]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2011-5-24 136176]
S3 SwitchBoard;SwitchBoard;c:\program files\common files\adobe\switchboard\SwitchBoard.exe [2010-2-19 517096]
.
=============== Created Last 30 ================
.
2011-09-24 19:15:09 544656 —-a-w- c:\windows\system32\deployJava1.dll
2011-09-24 08:12:06 28752 —-a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{c33b92ef-acbd-4159-befb-a7300a688461}\MpKsl7660d078.sys
2011-09-24 08:12:01 56200 —-a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{c33b92ef-acbd-4159-befb-a7300a688461}\offreg.dll
2011-09-24 08:11:53 7269712 —-a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{c33b92ef-acbd-4159-befb-a7300a688461}\mpengine.dll
2011-09-23 21:29:22 ——– d—–w- c:\program files\ESET
2011-09-23 20:05:16 ——– d-sh–w- C:\$RECYCLE.BIN
2011-09-23 07:13:25 208896 —-a-w- c:\windows\MBR.exe
2011-09-23 07:13:24 98816 —-a-w- c:\windows\sed.exe
2011-09-23 07:13:24 518144 —-a-w- c:\windows\SWREG.exe
2011-09-23 07:13:24 256000 —-a-w- c:\windows\PEV.exe
2011-09-22 17:59:09 439632 ——w- c:\programdata\microsoft\microsoft antimalware\definition updates\{390a1807-46f9-4938-bf83-d79cad15619b}\gapaengine.dll
2011-09-22 17:58:39 7269712 —-a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\backup\mpengine.dll
2011-09-21 08:28:56 ——– d—–w- c:\users\mgds\appdata\roaming\Malwarebytes
2011-09-21 08:27:14 ——– d—–w- c:\programdata\Malwarebytes
2011-09-21 08:27:10 22216 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-09-21 08:27:09 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2011-09-20 23:39:24 ——– d—–w- c:\program files\Microsoft Security Client
2011-09-20 19:35:54 7152464 —-a-w- c:\programdata\microsoft\windows defender\definition updates\{870cc9e2-c6b0-40b1-9485-07b9d6065ec1}\mpengine.dll
2011-09-17 09:47:34 77312 —-a-w- c:\windows\system32\ztvunace26.dll
2011-09-17 09:47:34 75264 —-a-w- c:\windows\system32\unacev2.dll
2011-09-17 09:47:34 69632 —-a-w- c:\windows\system32\ztvcabinet.dll
2011-09-17 09:47:34 162304 —-a-w- c:\windows\system32\ztvunrar36.dll
2011-09-17 09:47:34 153088 —-a-w- c:\windows\system32\unrar3.dll
2011-09-17 09:47:26 ——– d—–w- c:\users\mgds\appdata\roaming\Simply Super Software
2011-09-17 09:47:26 ——– d—–w- c:\programdata\Simply Super Software
.
==================== Find3M ====================
.
.
============= FINISH: 20:18:32.66 ===============
The laptop is running much quicker now, start up used to take forever and now it's almost instant with the internet connected and ready to go… but no doubt there will be problems when my wife gets back on it!
Thank you very, very much!