This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

High CPU usage, Ping.exe, High Ram usage [Closed]

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

If im not doing this right plz let me know :D Wow i just looked at main page and for some reason it made like 10 posts. no idea how that happend . When i tried to post it went to a page saying my internet was down. Sry
Hi Deception35, welcome to the forum.

To make cleaning this machine easier
  • Please do not uninstall/install any programs unless asked to
    It is more difficult when files/programs are appearing in/disappearing from the logs.
  • Please do not run any scans other than those requested
  • Please follow all instructions in the order posted
  • All logs/reports, etc.. must be posted in Notepad. Please ensure that word wrap is unchecked. In notepad click format, uncheck word wrap if it is checked.
  • Do not attach any logs/reports, etc.. unless specifically requested to do so.
  • If you have problems with or do not understand the instructions, Please ask before continuing.
  • Please stay with this thread until given the All Clear. A absence of symptoms does not mean a clean machine.

When i tried to post it went to a page saying my internet was down. Sry

That sometimes happens, I'll remove your additional topics.

Please download DeFogger to your desktop.

Double click DeFogger to run the tool.
  • The application window will appear
  • Click the Disable button to disable your CD Emulation drivers
  • Click Yes to continue
  • A 'Finished!' message will appear
  • Click OK
  • DeFogger will now ask to reboot the machine - click OK
IMPORTANT! If you receive an error message while running DeFogger, please post the log defogger_disable which will appear on your desktop.

Do not re-enable these drivers until otherwise instructed.

I see you have aswMBR on your computer. Please run a scan with it and post the log and attach the mbr.zip that is also produced.

To run aswMBR:

Right click the aswMBR.exeand click "Run as Administrator" to run it

Click the "Scan" button to start scan
[external image: Posted Image]

On completion of the scan click save log, save it to your desktop and post in your next reply
[external image: Posted Image]

There shall also be a file on your desktop named MBR.dat. Right click that file and select Send To>Compressed (zipped) folder. Please attach that zipped file in your next reply.



Next

Please open OTL.

  • Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, click the None button near the top (it may looked greyed out)
  • In the window under Custom Scans/Fixes copy and paste the following


    %USERPROFILE%\..|smtmp;true;true;true /FP
    %temp%\smtmp\*.* /s
    /md5start
    iexplore.*
    explorer.*
    winlogon.*
    dll
    zx.dll
    hlp.dat
    consrv.dll
    /md5stop


  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open a notepad window, OTL.Txt. Please post this log.

Please post back with
  • aswmbr log
  • OTL.txt
  • mbr.zip (attached)
Thanks
Thanks for the quick response. Im running the MBR test now. B4 i got your reply i re -installed firefox. i dont know if thats a big deal or not. Also i just got a BSOD while running the scan so im re running it now.
aswMBR log

aswMBR version 0.9.8.986 CopyrightΒ© 2011 AVAST Software
Run date: 2011-12-14 13:03:09
—————————–
13:03:09.043 OS Version: Windows 6.0.6002 Service Pack 2
13:03:09.043 Number of processors: 2 586 0x4B02
13:03:09.044 ComputerName: FAXCOOLWAREZ037 UserName: Owner35
13:03:55.480 Initialize success
13:04:07.034 AVAST engine defs: 11121401
13:04:55.894 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T1L0-3
13:04:55.898 Disk 0 Vendor: ST3100011A 3.02 Size: 95396MB BusType: 3
13:04:57.934 Disk 0 MBR read successfully
13:04:57.938 Disk 0 MBR scan
13:04:57.956 Disk 0 Windows VISTA default MBR code
13:04:57.962 Disk 0 scanning sectors +195366912
13:04:59.961 Disk 0 scanning C:\Windows\system32\drivers
13:05:08.932 File: C:\Windows\system32\drivers\serial.sys **INFECTED** Win32:Alureon-AOV [Rtk]
13:05:13.329 Service scanning
13:05:15.783 Modules scanning
13:05:21.287 Module: C:\Windows\system32\DRIVERS\serial.sys **SUSPICIOUS**
13:05:28.249 Disk 0 trace - called modules:
13:05:28.257 ntkrnlpa.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x86617f10]<<
13:05:28.259 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x85bf6ac8]
13:05:28.259 3 CLASSPNP.SYS[883c68b3] -> nt!IofCallDriver -> [0x865e0e08]
13:05:28.260 \Driver\00000907[0x8640a030] -> IRP_MJ_CREATE -> 0x86617f10
13:05:28.989 AVAST engine scan C:\Windows
13:05:33.974 AVAST engine scan C:\Windows\system32
13:12:35.568 AVAST engine scan C:\Windows\system32\drivers
13:13:02.299 File: C:\Windows\system32\drivers\serial.sys **INFECTED** Win32:Alureon-AOV [Rtk]
13:13:20.785 AVAST engine scan C:\Users\Owner35
13:15:01.294 AVAST engine scan C:\ProgramData
13:25:31.677 File: C:\ProgramData\Gjz6R8Hp5yxecj.exe **INFECTED** Win32:FakeAV-CQI [Trj]
13:26:48.614 Scan finished successfully
13:27:25.928 Disk 0 MBR has been saved successfully to "C:\Users\Owner35\Desktop\MBR.dat"
13:27:25.935 The log file has been saved successfully to "C:\Users\Owner35\Desktop\aswMBR.txt"






OTL.txt

OTL logfile created on: 12/14/2011 1:29:32 PM - Run 2
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Owner35\Desktop
Windows Vista Ultimate Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19154)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 0.99 Gb Available Physical Memory | 49.41% Memory free
4.23 Gb Paging File | 3.25 Gb Available in Paging File | 76.84% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 50.78 Gb Total Space | 6.84 Gb Free Space | 13.47% Space Free | Partition Type: NTFS
Drive E: | 42.38 Gb Total Space | 10.58 Gb Free Space | 24.98% Space Free | Partition Type: NTFS

Computer Name: FAXCOOLWAREZ037 | User Name: Owner35 | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: Off | File Age = 30 Days

========== Custom Scans ==========


< %USERPROFILE%\..|smtmp;true;true;true /FP >

< %temp%\smtmp\*.* /s >


< MD5 for: EXPLORER.ADML >
[2011/08/12 16:54:22 | 000,002,823 | β€”- | M] () MD5=A3CE2A219D9C2AC33F5218210FA2A1E9 – C:\Windows\PolicyDefinitions\zh-CN\Explorer.adml
[2011/08/12 16:54:06 | 000,002,823 | β€”- | M] () MD5=A3CE2A219D9C2AC33F5218210FA2A1E9 – C:\Windows\winsxs\x86_microsoft-windows-s..ouppolicy.resources_31bf3856ad364e35_6.0.6000.16386_zh-cn_80502804548c3b9b\Explorer.adml
[2011/08/12 16:54:22 | 000,002,823 | β€”- | M] () MD5=A3CE2A219D9C2AC33F5218210FA2A1E9 – C:\Windows\winsxs\x86_microsoft-windows-s..ouppolicy.resources_31bf3856ad364e35_6.0.6001.18000_zh-cn_8286ea0051774c6f\Explorer.adml
[2006/11/02 07:40:18 | 000,002,791 | β€”- | M] () MD5=B17D3F048712809BE9643AE542B7D6B0 – C:\Windows\PolicyDefinitions\en-US\Explorer.adml
[2006/11/02 07:40:18 | 000,002,791 | β€”- | M] () MD5=B17D3F048712809BE9643AE542B7D6B0 – C:\Windows\winsxs\x86_microsoft-windows-s..ouppolicy.resources_31bf3856ad364e35_6.0.6000.16386_en-us_20c9bd966d6a6189\Explorer.adml
[2006/11/02 07:40:18 | 000,002,791 | β€”- | M] () MD5=B17D3F048712809BE9643AE542B7D6B0 – C:\Windows\winsxs\x86_microsoft-windows-s..ouppolicy.resources_31bf3856ad364e35_6.0.6001.18000_en-us_23007f926a55725d\Explorer.adml
[2008/02/05 12:12:38 | 000,004,443 | β€”- | M] () MD5=F4E6889482DBDBA9F6A69B18EDDCE1DC – C:\Windows\PolicyDefinitions\ru-RU\Explorer.adml
[2008/02/05 12:12:08 | 000,004,443 | β€”- | M] () MD5=F4E6889482DBDBA9F6A69B18EDDCE1DC – C:\Windows\winsxs\x86_microsoft-windows-s..ouppolicy.resources_31bf3856ad364e35_6.0.6000.16386_ru-ru_69ead54abe6f5d30\Explorer.adml
[2008/02/05 12:12:38 | 000,004,443 | β€”- | M] () MD5=F4E6889482DBDBA9F6A69B18EDDCE1DC – C:\Windows\winsxs\x86_microsoft-windows-s..ouppolicy.resources_31bf3856ad364e35_6.0.6001.18000_ru-ru_6c219746bb5a6e04\Explorer.adml
[2011/07/13 20:03:59 | 000,003,104 | β€”- | M] () MD5=FF640A46B12B353734E33CAB8AA03F0C – C:\Windows\PolicyDefinitions\ko-KR\Explorer.adml
[2011/07/13 20:03:36 | 000,003,104 | β€”- | M] () MD5=FF640A46B12B353734E33CAB8AA03F0C – C:\Windows\winsxs\x86_microsoft-windows-s..ouppolicy.resources_31bf3856ad364e35_6.0.6000.16386_ko-kr_f303e2821d2127ff\Explorer.adml
[2011/07/13 20:03:59 | 000,003,104 | β€”- | M] () MD5=FF640A46B12B353734E33CAB8AA03F0C – C:\Windows\winsxs\x86_microsoft-windows-s..ouppolicy.resources_31bf3856ad364e35_6.0.6001.18000_ko-kr_f53aa47e1a0c38d3\Explorer.adml

< MD5 for: EXPLORER.ADMX >
[2006/11/02 07:34:28 | 000,002,840 | β€”- | M] () MD5=66DA9157D2CBE355555739AA9EDA1C6D – C:\Windows\PolicyDefinitions\Explorer.admx
[2006/11/02 07:34:28 | 000,002,840 | β€”- | M] () MD5=66DA9157D2CBE355555739AA9EDA1C6D – C:\Windows\winsxs\x86_microsoft-windows-shell-grouppolicy_31bf3856ad364e35_6.0.6001.18000_none_15baa9b3f0d5e010\Explorer.admx

< MD5 for: EXPLORER.EXE >
[2008/10/29 01:20:29 | 002,923,520 | β€”- | M] (Microsoft Corporation) MD5=37440D09DEAE0B672A04DCCF7ABF06BE – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16771_none_4f83bb287ccdb7e3\explorer.exe
[2008/10/29 01:29:41 | 002,927,104 | β€”- | M] (Microsoft Corporation) MD5=4F554999D7D5F05DAAEBBA7B5BA1089D – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18164_none_5177ca9879e978e8\explorer.exe
[2008/10/29 22:59:17 | 002,927,616 | β€”- | M] (Microsoft Corporation) MD5=50BA5850147410CDE89C523AD3BC606E – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.22298_none_51e4f8c7931bd1e1\explorer.exe
[2009/04/11 01:27:36 | 002,926,592 | β€”- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 – C:\Windows\explorer.exe
[2009/04/11 01:27:36 | 002,926,592 | β€”- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6002.18005_none_53a0201e76de3a0b\explorer.exe
[2008/10/27 21:15:02 | 002,923,520 | β€”- | M] (Microsoft Corporation) MD5=E7156B0B74762D9DE0E66BDCDE06E5FB – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.20947_none_5033cb5995cd990b\explorer.exe
[2008/01/20 21:22:34 | 002,927,104 | β€”- | M] (Microsoft Corporation) MD5=FFA764631CB70A30065C12EF8E174F9F – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18000_none_51b4a71279bc6ebf\explorer.exe

< MD5 for: EXPLORER.EXE.MUI >
[2006/11/02 07:39:48 | 000,036,864 | β€”- | M] (Microsoft Corporation) MD5=192DD053B43250E264383CDC3D564A18 – C:\Windows\en-US\explorer.exe.mui
[2006/11/02 07:39:48 | 000,036,864 | β€”- | M] (Microsoft Corporation) MD5=192DD053B43250E264383CDC3D564A18 – C:\Windows\winsxs\x86_microsoft-windows-explorer.resources_31bf3856ad364e35_6.0.6000.16386_en-us_03bbc52176b6ba20\explorer.exe.mui
[2011/08/12 16:51:21 | 000,868,352 | β€”- | M] (Microsoft Corporation) MD5=7B0AE29051B64A5FB58BBAB1F219F68B – C:\Windows\winsxs\x86_microsoft-windows-explorer.resources_31bf3856ad364e35_6.0.6000.16386_zh-cn_63422f8f5dd89432\explorer.exe.mui
[2011/08/12 16:51:21 | 000,868,352 | β€”- | M] (Microsoft Corporation) MD5=7B0AE29051B64A5FB58BBAB1F219F68B – C:\Windows\zh-CN\explorer.exe.mui
[2011/07/13 20:00:40 | 000,905,216 | β€”- | M] (Microsoft Corporation) MD5=98DE732839371F343C2C21C8E5B1CDFC – C:\Windows\ko-KR\explorer.exe.mui
[2011/07/13 20:00:40 | 000,905,216 | β€”- | M] (Microsoft Corporation) MD5=98DE732839371F343C2C21C8E5B1CDFC – C:\Windows\winsxs\x86_microsoft-windows-explorer.resources_31bf3856ad364e35_6.0.6000.16386_ko-kr_d5f5ea0d266d8096\explorer.exe.mui
[2008/02/05 12:09:22 | 000,950,272 | β€”- | M] (Microsoft Corporation) MD5=DC4D522F50D2C3742F37243A50CF397F – C:\Windows\ru-RU\explorer.exe.mui
[2008/02/05 12:09:22 | 000,950,272 | β€”- | M] (Microsoft Corporation) MD5=DC4D522F50D2C3742F37243A50CF397F – C:\Windows\winsxs\x86_microsoft-windows-explorer.resources_31bf3856ad364e35_6.0.6000.16386_ru-ru_4cdcdcd5c7bbb5c7\explorer.exe.mui

< MD5 for: EXPLORER.EXE-7A3328DA.PF >
[2011/12/14 12:56:38 | 000,235,378 | β€”- | M] () MD5=9730800C1634CCF9721674B3B7A8BCC5 – C:\Windows\Prefetch\EXPLORER.EXE-7A3328DA.pf

< MD5 for: IEXPLORE.EXE >
[2011/07/23 06:02:27 | 000,638,232 | β€”- | M] (Microsoft Corporation) MD5=04D1DC458C723B291179F8449ACC281D – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.19120_none_12355fcb2fdc2111\iexplore.exe
[2009/01/14 23:14:36 | 000,634,024 | β€”- | M] (Microsoft Corporation) MD5=0844F5B9CB3BB85A917D347EF1565B6C – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.16809_none_2d84c7c91ccfce35\iexplore.exe
[2011/09/30 18:49:11 | 000,638,216 | β€”- | M] (Microsoft Corporation) MD5=0E1695AD4C30E72D68170F01B4818A80 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.23250_none_129e8cd2491214ae\iexplore.exe
[2008/10/01 22:50:01 | 000,633,632 | β€”- | M] (Microsoft Corporation) MD5=19403B64906C9EAC627E3C10847B0FDA – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.16757_none_2d4cb5b31cfa2a15\iexplore.exe
[2009/11/21 01:42:38 | 000,638,232 | β€”- | M] (Microsoft Corporation) MD5=1B6362BB14FCEB9E76BCF9A953B04788 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.18865_none_120f459f2ff7e1f8\iexplore.exe
[2009/03/02 23:18:52 | 000,636,072 | β€”- | M] (Microsoft Corporation) MD5=1DD66A2851DACDEC32EAE8F9A8865ABD – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.21023_none_2df29b2236034119\iexplore.exe
[2009/04/24 11:25:27 | 000,634,648 | β€”- | M] (Microsoft Corporation) MD5=1F44940EF1D07D0BDAF80E55853DFBD0 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.16851_none_2d46b5dd1cff8f32\iexplore.exe
[2010/02/23 10:06:13 | 000,638,232 | β€”- | M] (Microsoft Corporation) MD5=25DB705A7DC85C208B3CF2D20F118AA7 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.22995_none_127872a6492dd595\iexplore.exe
[2009/04/11 01:27:44 | 000,636,080 | β€”- | M] (Microsoft Corporation) MD5=2C5168C856455CC43C4B4E1CC1920001 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6002.18005_none_314d791517204c15\iexplore.exe
[2009/08/27 00:23:17 | 000,638,232 | β€”- | M] (Microsoft Corporation) MD5=2E48756F12C21F46895036AC089AAD97 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.18828_none_123d862d2fd4be39\iexplore.exe
[2010/01/02 09:58:26 | 000,638,216 | β€”- | M] (Microsoft Corporation) MD5=3D8DA00B028DEA9517066F1CECBFC4A2 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.22973_none_128c11ea491f6b05\iexplore.exe
[2010/05/04 01:32:18 | 000,638,232 | β€”- | M] (Microsoft Corporation) MD5=48A6109E8DF0365195298CC527B7426A – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.23019_none_12d2cb5048e98eab\iexplore.exe
[2010/09/08 01:26:34 | 000,638,232 | β€”- | M] (Microsoft Corporation) MD5=4A719476A6393B1DCACFEB4F3AC6599C – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.23067_none_129abb204913e7b2\iexplore.exe
[2009/07/22 01:04:09 | 000,638,232 | β€”- | M] (Microsoft Corporation) MD5=4B5AEA50CE77FBA4C2D169622DC9B489 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.22903_none_12d7c15e48e6a76e\iexplore.exe
[2008/10/15 23:27:53 | 000,634,024 | β€”- | M] (Microsoft Corporation) MD5=4CBA2F58668F2D5F3259CBE73E227F25 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.20937_none_2debf43c36078f24\iexplore.exe
[2011/07/23 06:42:34 | 000,638,232 | β€”- | M] (Microsoft Corporation) MD5=4D08A4234D645EFCB30605CC0BFA87F4 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.23216_none_12cfce3e48ec3cf4\iexplore.exe
[2010/11/02 01:03:13 | 000,638,232 | β€”- | M] (Microsoft Corporation) MD5=5AB037B17F8A87D052F5A88E0D29A3C8 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.18999_none_11f2d8e9300c984e\iexplore.exe
[2008/01/20 21:21:57 | 000,625,664 | β€”- | M] (Microsoft Corporation) MD5=5B92133D3E7FB2644677686305E29E81 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.18000_none_2f62000919fe80c9\iexplore.exe
[2010/05/04 01:00:35 | 000,638,232 | β€”- | M] (Microsoft Corporation) MD5=5C9B1062EA7A44E8F6BFDE994B68C7AA – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.18928_none_123d88132fd4bb60\iexplore.exe
[2008/10/01 22:32:01 | 000,633,632 | β€”- | M] (Microsoft Corporation) MD5=6655B851D9EEF7C83395EE52D551B448 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.20927_none_2df6c42835ff7333\iexplore.exe
[2010/06/26 01:06:48 | 000,638,232 | β€”- | M] (Microsoft Corporation) MD5=7420BE0E7D3D1320054F7ACA0594953D – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.18943_none_1222e6c92fe9748f\iexplore.exe
[2010/12/18 02:19:44 | 000,638,232 | β€”- | M] (Microsoft Corporation) MD5=7852371DA9EFBC17B645558E23780EAC – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.23111_none_12cacae648f0c11a\iexplore.exe
[2011/09/30 18:07:49 | 000,638,216 | β€”- | M] (Microsoft Corporation) MD5=7ACBBC85FCE4989B533220FC3B291633 – C:\Program Files\Internet Explorer\iexplore.exe
[2011/09/30 18:07:49 | 000,638,216 | β€”- | M] (Microsoft Corporation) MD5=7ACBBC85FCE4989B533220FC3B291633 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.19154_none_1218f12f2ff0da40\iexplore.exe
[2009/08/27 08:31:08 | 000,638,216 | β€”- | M] (Microsoft Corporation) MD5=7DD482E4A2E3CBB0A72F718C342F5B75 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.22918_none_12d1f2e448ea4212\iexplore.exe
[2011/05/28 02:09:20 | 000,638,232 | β€”- | M] (Microsoft Corporation) MD5=7EE10C5413AD7ED1AF9E8FAE1B58FC3E – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.23181_none_127f1b72492984b1\iexplore.exe
[2010/01/02 01:40:20 | 000,638,216 | β€”- | M] (Microsoft Corporation) MD5=88BD42DAE7CFFEB256CA7145A15E4843 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.18882_none_11f6a4e9300acdd5\iexplore.exe
[2009/03/02 23:32:44 | 000,636,072 | β€”- | M] (Microsoft Corporation) MD5=8BA2B7A05F88BE0D45237A0994AD8366 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.22389_none_2f9e23da3354de78\iexplore.exe
[2010/11/02 02:13:47 | 000,638,232 | β€”- | M] (Microsoft Corporation) MD5=92A17B0A89D14815AACC62CD190B6CE3 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.23091_none_127449a04931a37b\iexplore.exe
[2011/02/22 02:18:28 | 000,638,232 | β€”- | M] (Microsoft Corporation) MD5=9CE5543464432CA73134F170FA2BF823 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.23143_none_12ac5bb64907479b\iexplore.exe
[2009/03/02 23:40:22 | 000,636,072 | β€”- | M] (Microsoft Corporation) MD5=9E6C1527D9A2C64BFD780AA23075380F – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.18226_none_2f5265b91a094b03\iexplore.exe
[2010/02/23 01:39:16 | 000,638,232 | β€”- | M] (Microsoft Corporation) MD5=9F52FBE99C749E3F32C75124F09F1B03 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.18904_none_124f26c32fc81e22\iexplore.exe
[2009/03/08 16:09:24 | 000,638,816 | β€”- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.18702_none_124d22632fc9f126\iexplore.exe
[2010/12/18 01:28:35 | 000,638,232 | β€”- | M] (Microsoft Corporation) MD5=B988D7F127B94BD5BF8356FE81B985C4 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.19019_none_1249306b2fcbec08\iexplore.exe
[2011/02/22 01:21:12 | 000,638,232 | β€”- | M] (Microsoft Corporation) MD5=C1D36A2CBE0CEC4DF593DB1288CF586E – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.19048_none_1227c05d2fe52684\iexplore.exe
[2009/07/21 16:53:43 | 000,638,216 | β€”- | M] (Microsoft Corporation) MD5=C33BD196A0301F9B23D9A003D30ED8B0 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.18813_none_124354a72fd12395\iexplore.exe
[2009/04/24 11:03:18 | 000,634,648 | β€”- | M] (Microsoft Corporation) MD5=D5271AC4A06AD9D1E2EA0151B79B2657 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.21046_none_2ddffc283610c500\iexplore.exe
[2010/09/08 01:02:42 | 000,638,232 | β€”- | M] (Microsoft Corporation) MD5=D5A730DFDEAE005373E62BC2A866E3BB – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.18975_none_120477992ffffb10\iexplore.exe
[2009/04/24 11:01:36 | 000,634,648 | β€”- | M] (Microsoft Corporation) MD5=D6157423C117F24D24695866A1D0A93F – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.22418_none_2fe8d4ea331cfeb1\iexplore.exe
[2008/10/15 23:42:58 | 000,634,024 | β€”- | M] (Microsoft Corporation) MD5=D762642A109433EEDCD332B0A9511137 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.16764_none_2d3ee4e91d04fa01\iexplore.exe
[2009/11/21 10:05:17 | 000,638,232 | β€”- | M] (Microsoft Corporation) MD5=E7F8DF50E483D165BB01F367D3519AA7 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.22956_none_12a4b2a0490c7f28\iexplore.exe
[2009/03/02 23:22:10 | 000,636,072 | β€”- | M] (Microsoft Corporation) MD5=EA4BE33726155F89D89A3FE7142878E0 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.16830_none_2d5b556b1cf03df9\iexplore.exe
[2011/05/28 01:09:21 | 000,638,232 | β€”- | M] (Microsoft Corporation) MD5=ED65737D70FDEAC29F738E77D2496EE5 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.19088_none_11fc80ad30059648\iexplore.exe
[2010/06/26 01:52:42 | 000,638,232 | β€”- | M] (Microsoft Corporation) MD5=F05B3A2C6CB319DD1377AD566CF5ECE5 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.23040_none_12a958f24909fe6f\iexplore.exe
[2009/01/14 23:18:47 | 000,634,024 | β€”- | M] (Microsoft Corporation) MD5=F0B1CA517977BA2FF6DA33F1B966C488 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.20996_none_2daa146a36391d73\iexplore.exe
[2009/04/24 11:08:04 | 000,634,632 | β€”- | M] (Microsoft Corporation) MD5=F294D8EEB05C835EC44A12CE0A1DFE7A – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.18248_none_2f3ec6751a17b593\iexplore.exe

< MD5 for: IEXPLORE.EXE.MUI >
[2009/03/08 16:22:03 | 000,016,384 | β€”- | M] (Microsoft Corporation) MD5=19F8D1204566F758DC785AE6ABA899E7 – C:\Program Files\Internet Explorer\ru-RU\iexplore.exe.mui
[2009/03/08 16:22:03 | 000,016,384 | β€”- | M] (Microsoft Corporation) MD5=19F8D1204566F758DC785AE6ABA899E7 – C:\Windows\winsxs\x86_microsoft-windows-i..texplorer.resources_31bf3856ad364e35_8.0.6001.18702_ru-ru_6998ad24bb95d268\iexplore.exe.mui
[2006/11/02 07:39:45 | 000,016,384 | β€”- | M] (Microsoft Corporation) MD5=3CCDDDBC49DEACA370F39A9F0E146A1B – C:\Windows\winsxs\x86_microsoft-windows-i..texplorer.resources_31bf3856ad364e35_6.0.6000.16386_en-us_3b55b11a57da5590\iexplore.exe.mui
[2011/08/12 16:51:11 | 000,016,384 | β€”- | M] (Microsoft Corporation) MD5=694CBEB73AEAEC29FF6A23DA408BCA35 – C:\Program Files\Internet Explorer\zh-CN\iexplore.exe.mui
[2011/08/12 16:51:11 | 000,016,384 | β€”- | M] (Microsoft Corporation) MD5=694CBEB73AEAEC29FF6A23DA408BCA35 – C:\Windows\winsxs\x86_microsoft-windows-i..texplorer.resources_31bf3856ad364e35_6.0.6000.16386_zh-cn_9adc1b883efc2fa2\iexplore.exe.mui
[2009/03/08 16:27:11 | 000,012,288 | β€”- | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2009/03/08 16:27:11 | 000,012,288 | β€”- | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 – C:\Windows\winsxs\x86_microsoft-windows-i..texplorer.resources_31bf3856ad364e35_8.0.6001.18702_en-us_207795706a90d6c1\iexplore.exe.mui
[2011/07/13 20:00:31 | 000,016,384 | β€”- | M] (Microsoft Corporation) MD5=F1E00EE507CA34658D1EF19F92759246 – C:\Program Files\Internet Explorer\ko-KR\iexplore.exe.mui
[2011/07/13 20:00:31 | 000,016,384 | β€”- | M] (Microsoft Corporation) MD5=F1E00EE507CA34658D1EF19F92759246 – C:\Windows\winsxs\x86_microsoft-windows-i..texplorer.resources_31bf3856ad364e35_6.0.6000.16386_ko-kr_0d8fd60607911c06\iexplore.exe.mui
[2008/02/05 12:09:00 | 000,016,384 | β€”- | M] (Microsoft Corporation) MD5=F2DF8388FA40DC94A9763F651F2B032D – C:\Windows\winsxs\x86_microsoft-windows-i..texplorer.resources_31bf3856ad364e35_6.0.6000.16386_ru-ru_8476c8cea8df5137\iexplore.exe.mui

< MD5 for: WINLOGON.ADML >
[2006/11/02 07:40:19 | 000,008,051 | β€”- | M] () MD5=5911AB4AD86759363C6C00408A522692 – C:\Windows\PolicyDefinitions\en-US\WinLogon.adml
[2006/11/02 07:40:19 | 000,008,051 | β€”- | M] () MD5=5911AB4AD86759363C6C00408A522692 – C:\Windows\winsxs\x86_microsoft-windows-winlogon-adm.resources_31bf3856ad364e35_6.0.6000.16386_en-us_92cd4f8bdff6e8f5\WinLogon.adml
[2011/08/12 16:54:09 | 000,007,518 | β€”- | M] () MD5=8EE4434BAEFC6AA664BAB623D59223B4 – C:\Windows\PolicyDefinitions\zh-CN\WinLogon.adml
[2011/08/12 16:54:09 | 000,007,518 | β€”- | M] () MD5=8EE4434BAEFC6AA664BAB623D59223B4 – C:\Windows\winsxs\x86_microsoft-windows-winlogon-adm.resources_31bf3856ad364e35_6.0.6000.16386_zh-cn_f253b9f9c718c307\WinLogon.adml
[2008/02/05 12:11:59 | 000,013,524 | β€”- | M] () MD5=9358642BF730B5075BE48625B5E13192 – C:\Windows\PolicyDefinitions\ru-RU\WinLogon.adml
[2008/02/05 12:11:59 | 000,013,524 | β€”- | M] () MD5=9358642BF730B5075BE48625B5E13192 – C:\Windows\winsxs\x86_microsoft-windows-winlogon-adm.resources_31bf3856ad364e35_6.0.6000.16386_ru-ru_dbee674030fbe49c\WinLogon.adml
[2011/07/13 20:03:40 | 000,009,315 | β€”- | M] () MD5=F4230DAE1C4683BF3F8235C724C6AC91 – C:\Windows\PolicyDefinitions\ko-KR\WinLogon.adml
[2011/07/13 20:03:40 | 000,009,315 | β€”- | M] () MD5=F4230DAE1C4683BF3F8235C724C6AC91 – C:\Windows\winsxs\x86_microsoft-windows-winlogon-adm.resources_31bf3856ad364e35_6.0.6000.16386_ko-kr_650774778fadaf6b\WinLogon.adml

< MD5 for: WINLOGON.ADMX >
[2006/11/02 07:34:27 | 000,005,237 | β€”- | M] () MD5=89D8F50E186A16C2CED3CF36DBBC0B2C – C:\Windows\PolicyDefinitions\WinLogon.admx
[2006/11/02 07:34:27 | 000,005,237 | β€”- | M] () MD5=89D8F50E186A16C2CED3CF36DBBC0B2C – C:\Windows\winsxs\x86_microsoft-windows-winlogon-adm_31bf3856ad364e35_6.0.6000.16386_none_78d69ac67c572ad2\WinLogon.admx

< MD5 for: WINLOGON.EXE >
[2009/04/11 01:28:13 | 000,314,368 | β€”- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 – C:\Windows\System32\winlogon.exe
[2009/04/11 01:28:13 | 000,314,368 | β€”- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6002.18005_none_71ae7a22d2134741\winlogon.exe
[2008/01/20 21:22:59 | 000,314,880 | β€”- | M] (Microsoft Corporation) MD5=C2610B6BDBEFC053BBDAB4F1B965CB24 – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6001.18000_none_6fc30116d4f17bf5\winlogon.exe

< MD5 for: WINLOGON.EXE.MUI >
[2011/08/12 16:52:28 | 000,020,480 | β€”- | M] (Microsoft Corporation) MD5=244E6DA8FD192052A86689871F682EB2 – C:\Windows\winsxs\x86_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.0.6000.16386_zh-cn_284839fcee4d3b78\winlogon.exe.mui
[2008/01/20 21:23:53 | 000,028,672 | β€”- | M] (Microsoft Corporation) MD5=26AC28BF50DC112BAA794A83E08588F0 – C:\Windows\System32\en-US\winlogon.exe.mui
[2008/01/20 21:23:53 | 000,028,672 | β€”- | M] (Microsoft Corporation) MD5=26AC28BF50DC112BAA794A83E08588F0 – C:\Windows\winsxs\x86_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.0.6001.18000_en-us_caf8918b0416723a\winlogon.exe.mui
[2011/07/13 20:04:47 | 000,020,480 | β€”- | M] (Microsoft Corporation) MD5=469DD6B7AC87B0BB5D11029090E2AF65 – C:\Windows\System32\ko-KR\winlogon.exe.mui
[2011/07/13 20:04:47 | 000,020,480 | β€”- | M] (Microsoft Corporation) MD5=469DD6B7AC87B0BB5D11029090E2AF65 – C:\Windows\winsxs\x86_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.0.6001.18000_ko-kr_9d32b676b3cd38b0\winlogon.exe.mui
[2011/08/12 16:55:01 | 000,020,480 | β€”- | M] (Microsoft Corporation) MD5=6AFF70D82F7052B63F5D5B9A8A566322 – C:\Windows\System32\zh-CN\winlogon.exe.mui
[2011/08/12 16:55:01 | 000,020,480 | β€”- | M] (Microsoft Corporation) MD5=6AFF70D82F7052B63F5D5B9A8A566322 – C:\Windows\winsxs\x86_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.0.6001.18000_zh-cn_2a7efbf8eb384c4c\winlogon.exe.mui
[2011/07/13 20:01:41 | 000,020,480 | β€”- | M] (Microsoft Corporation) MD5=89BCC89E68F88E9BF63D69F43BB05C12 – C:\Windows\winsxs\x86_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.0.6000.16386_ko-kr_9afbf47ab6e227dc\winlogon.exe.mui
[2006/11/02 07:39:20 | 000,028,672 | β€”- | M] (Microsoft Corporation) MD5=A1D2856F3EC3C86EBBF1442B0245A8B3 – C:\Windows\winsxs\x86_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.0.6000.16386_en-us_c8c1cf8f072b6166\winlogon.exe.mui
[2008/02/05 12:07:29 | 000,028,672 | β€”- | M] (Microsoft Corporation) MD5=A7ADA5EEC138C00987695D7C48A9FA01 – C:\Windows\winsxs\x86_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.0.6000.16386_ru-ru_11e2e74358305d0d\winlogon.exe.mui
[2008/02/05 12:13:19 | 000,032,768 | β€”- | M] (Microsoft Corporation) MD5=B5F51822FB382E5840FD5BDF2B17F16A – C:\Windows\System32\ru-RU\winlogon.exe.mui
[2008/02/05 12:13:19 | 000,032,768 | β€”- | M] (Microsoft Corporation) MD5=B5F51822FB382E5840FD5BDF2B17F16A – C:\Windows\winsxs\x86_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.0.6001.18000_ru-ru_1419a93f551b6de1\winlogon.exe.mui

< MD5 for: WINLOGON.EXE-8163EECC.PF >
[2011/12/13 14:23:30 | 000,034,034 | β€”- | M] () MD5=6B70413238BB0A57AA1473F4A7342380 – C:\Windows\Prefetch\WINLOGON.EXE-8163EECC.pf

< MD5 for: WINLOGON.MOF >
[2006/09/18 16:41:56 | 000,002,794 | β€”- | M] () MD5=545C578F290B9CDD280966939935B9EA – C:\Windows\System32\wbem\winlogon.mof
[2006/09/18 16:41:56 | 000,002,794 | β€”- | M] () MD5=545C578F290B9CDD280966939935B9EA – C:\Windows\winsxs\x86_microsoft-windows-winlogon-mof_31bf3856ad364e35_6.0.6000.16386_none_7e0207d478fccc94\winlogon.mof

< End of report >
Did i upload eveything u asked? Also ive been gettin Redirected to a site saying ive won a prize. just happend
Hi Deception35,


Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : How to Disable your Security Programs
  • Right click on ComboFix.exe, click Run as Administrator & follow the prompts.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Please post back with the combofix log.

Thanks
I try to run ComboFix but it keeps saying Avg Free anti virus is running but i dont even have that on my computer anymore. So i dont know what to do
It says Scanning for infected files… This typically doesn't take more then 10 minutes However, scan times for badly infected machines may easily double. That's all it says
Hi

Ok it seems it may have stalled. Restart your computer. Delete the copy you have and download a new one from Link 1or Link 2 to your Desktop. Please read these instructions before you down load it.



  • If you are using Firefox, make sure that your download settings are as follows:
    -Tools->Options->Main tab
    -Set to "Always ask me where to Save the files".
  • During the download, before you save it to your desktop, rename Combofix to svchost.exe

  • It is important you rename Combofix during the download, but not after.
  • Please do not rename Combofix to other names, but only to the one indicated.
  • Close any open browsers.
  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix

———————————————————–

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.

    ———————————————————–

  • Right click on ComboFix.exe (svchost.exe in your case) and click "Run as Administrator" & follow the prompts.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Please post back with
  • combofix log
How is the computer?

Thanks

.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI