Hi my names Ryan. My Laptop, running Windows Vista, is suddenly running slow in all areas (log-in, web browsing, opening programs…etc.)
Looks like a virus to me. I'd appreciate any help or advice. Thanks.
Hi and Welcome!!
My name is
Jeff . I would be more than happy to take a look at your malware results logs and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
Please subscribe to this topic, if you haven't already.
The fixes are specific to your problem and should only be used for the issues on this machine.
Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
It's often worth reading through these instructions and printing them for ease of reference.
If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
Please reply to this thread. Do not start a new topic.
IMPORTANT NOTE : Please do not delete anything unless instructed to.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision .
Doing so could make your system inoperable and could require a full reinstall of your OS losing all your programs and data.
Vista and Windows 7 users:
These tools MUST be run from the executable (.exe) every time you run them
with Admin Rights (Right click, choose "Run as Administrator")
Stay with this topic until I give you the all clean post.
First we need to make all files and folders VISIBLE :
Go to start>control panel>folder options>view Choose to "show hidden files and folders ," Uncheck the "hide protected operating system files" and the "hide extensions for know file types " boxes. Close the window with OK
Download
CKScanner by
askey127 from
Here &
save it to your Desktop .
Right-click and Run as Administrator CKScanner.exe then click Search For Files When the cursor hourglass disappears, click Save List To File A message box will verify the file saved Double-click the CKFiles.txt icon on your desktop then copy/paste the contents in your next reply
———-
There are many reasons why a computer may run slowly and malware is just one of them. Let's give a look.
———-
Please download
DDS from either of these links
LINK 1
LINK 2
and save it to your
desktop.
Disable any script blocking protection Right-click and Run as Administrator dds to run the tool. When done, two DDS.txt's will open. Save both reports to your desktop. —————————————————
Please include the contents of the following in your next reply:
DDS.txt
Attach.txt
———-
Please download
aswMBR to your desktop.
Right click and Run as Administrator the aswMBR icon to run it. Click the Scan button to start scan. When it finishes, press the save log button, save the logfile to your desktop and post its contents in your next reply.
[external image: Posted Image]
Click the image to enlarge it
———-
In your next reply please post the logs made by CKScanner, DDS and aswMBR.
CKScanner - Additional Security Risks - These are not necessarily bad
scanner sequence 3.RP.11.QRAAUV
—– EOF —–
.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 9.0.8112.16421
Run by [removed] at 20:13:48 on 2012-03-19
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.3963.1715 [GMT -4:00]
.
AV: Webroot SecureAnywhere *Enabled/Updated* {9C0666FC-6C7D-3E97-3C40-0C6B33FC7401}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Webroot SecureAnywhere *Enabled/Updated* {27678718-4A47-3119-06F0-3719487B3EBC}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\agr64svc.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCameraSrv.exe
C:\Program Files (x86)\TOSHIBA\ConfigFree\CFProcSRVC.exe
C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe
C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\TOSHIBA\rselect\RSelSvc.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
C:\Program Files (x86)\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe
C:\Windows\system32\TODDSrv.exe
C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
C:\Program Files\TOSHIBA\TECO\TecoService.exe
C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe
C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe
C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\TOSHIBA\TECO\Teco.exe
C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Program Files\TOSHIBA\TPHM\TPCHWMsg.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files (x86)\TOSHIBA\ConfigFree\NDSTray.exe
C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe
C:\Program Files (x86)\Common Files\BSD\AppUpdater\BSDChecker.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSwMgr.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\ehome\ehsched.exe
C:\Windows\ehome\ehRecvr.exe
C:\Windows\system32\igfxext.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Windows\splwow64.exe
C:\Program Files (x86)\Webroot\WRSA.exe
C:\Program Files (x86)\Webroot\WRSA.exe
C:\Windows\system32\wuauclt.exe
C:\Users\r.wroblewski\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\r.wroblewski\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Microsoft Office\Office12\WINWORD.EXE
C:\Users\r.wroblewski\Desktop\CKScanner.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\SysWOW64\cscript.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/ig/redirectdomain?brand=TSHB&bmod=TSHB
uDefault_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=TSHB&bmod=TSHB
mStart Page = hxxp://www.google.com/ig/redirectdomain?brand=TSHB&bmod=TSHB
mDefault_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=TSHB&bmod=TSHB
uInternet Settings,ProxyOverride = *.local
mWinlogon: Userinit=userinit.exe
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
BHO: Webroot Browser Helper Object: {e08861fe-8847-4b2a-8ec2-08edb20e4020} - C:\Program Files (x86)\Webroot\Security\install\products\WISE\toolbar\LPBar.dll
TB: Webroot Toolbar: {d84a64a0-f2b2-4975-b264-3a3bce8d57d6} - C:\Program Files (x86)\Webroot\Security\install\products\WISE\toolbar\LPBar.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
uRun: [Google Update] "C:\Users\r.wroblewski\AppData\Local\Google\Update\GoogleUpdate.exe" /c
uRun: [ehTray.exe] C:\Windows\ehome\ehTray.exe
mRun: [TWebCamera] "%ProgramFiles(x86)%\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe" autorun
mRun: [NDSTray.exe] "C:\Program Files (x86)\TOSHIBA\ConfigFree\NDSTray.exe"
mRun: [cfFncEnabler.exe] "C:\Program Files (x86)\TOSHIBA\ConfigFree\cfFncEnabler.exe"
mRun: [ToshibaServiceStation] "C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" /hide:60
mRun: [BSDAppUpdater] "C:\Program Files (x86)\Common Files\BSD\AppUpdater\BSDChecker.exe"
mRun: [WRSVC] "C:\Program Files (x86)\Webroot\WRSA.exe" -ul
mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000
IE: Google Sidewiki… - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_6CE5017F567343CA.dll/cmsidewiki.html
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
TCP: DhcpNameServer = 192.168.1.1
TCP: Interfaces\{1F71F484-D97C-4FA5-BB70-F09638A5EDED} : DhcpNameServer = 192.168.1.1
BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO-X64: AcroIEHelperStub - No File
BHO-X64: Java™ Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
BHO-X64: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
BHO-X64: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
BHO-X64: Webroot Browser Helper Object: {e08861fe-8847-4b2a-8ec2-08edb20e4020} - C:\Program Files (x86)\Webroot\Security\install\products\WISE\toolbar\LPBar.dll
BHO-X64: Webroot Browser Helper Object - No File
TB-X64: Webroot Toolbar: {d84a64a0-f2b2-4975-b264-3a3bce8d57d6} - C:\Program Files (x86)\Webroot\Security\install\products\WISE\toolbar\LPBar.dll
TB-X64: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
mRun-x64: [TWebCamera] "%ProgramFiles(x86)%\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe" autorun
mRun-x64: [NDSTray.exe] "C:\Program Files (x86)\TOSHIBA\ConfigFree\NDSTray.exe"
mRun-x64: [cfFncEnabler.exe] "C:\Program Files (x86)\TOSHIBA\ConfigFree\cfFncEnabler.exe"
mRun-x64: [ToshibaServiceStation] "C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" /hide:60
mRun-x64: [BSDAppUpdater] "C:\Program Files (x86)\Common Files\BSD\AppUpdater\BSDChecker.exe"
mRun-x64: [WRSVC] "C:\Program Files (x86)\Webroot\WRSA.exe" -ul
mRun-x64: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun-x64: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun-x64: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
.
============= SERVICES / DRIVERS ===============
.
R? clr_optimization_v2.0.50727_64;Microsoft .NET Framework NGEN v2.0.50727_X64
R? clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86
R? clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64
R? gupdate;Google Update Service (gupdate)
R? gupdatem;Google Update Service (gupdatem)
R? PerfHost;Performance Counter DLL Host
R? RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader
R? RtsUIR;Realtek IR Driver
R? USBAAPL64;Apple Mobile USB Driver
R? WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0
S? camsvc;TOSHIBA Web Camera Service
S? ConfigFree Gadget Service;ConfigFree Gadget Service
S? ConfigFree Service;ConfigFree Service
S? FontCache;Windows Font Cache Service
S? FwLnk;FwLnk Driver
S? PGEffect;Pangu effect driver
S? RSELSVC;TOSHIBA Modem region select service
S? rtl819xpn64;Realtek RTL8190\RTL8192E 802.11n Wireless LAN (Mini-)PCI NIC NT Driver
S? RtlProt;Realtke RtlProt WLAN Utility Protocol Driver
S? TMachInfo;TMachInfo
S? tos_sps64;TOSHIBA tos_sps64 Service
S? TOSHIBA eco Utility Service;TOSHIBA eco Utility Service
S? TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service
S? TPCHSrv;TPCH Service
S? TVALZFL;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Filter Driver
S? WRkrn;WRkrn
S? WRSVC;WRSVC
.
=============== File Associations ===============
.
JSEFile=C:\Windows\SysWOW64\WScript.exe "%1" %*
.
=============== Created Last 30 ================
.
2012-03-18 14:43:08 69000 —-a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{B397DE39-5470-422D-8CEA-67850D7C8959}\offreg.dll
2012-03-18 03:08:03 ——– d—–w- C:\Users\r.wroblewski\AppData\Local\Temp
2012-03-17 02:02:22 8643640 —-a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{B397DE39-5470-422D-8CEA-67850D7C8959}\mpengine.dll
2012-03-13 21:09:46 708096 —-a-w- C:\Windows\System32\rdpencom.dll
2012-03-13 21:09:46 613376 —-a-w- C:\Windows\SysWow64\rdpencom.dll
2012-03-13 21:09:46 209920 —-a-w- C:\Windows\System32\drivers\rdpwd.sys
2012-03-08 16:23:34 ——– d—–w- C:\Program Files\CCleaner
.
==================== Find3M ====================
.
2012-03-16 14:39:48 98160 —-a-w- C:\Windows\System32\WRusr.dll
2012-03-16 14:39:48 146040 —-a-w- C:\Windows\SysWow64\WRusr.dll
2012-03-16 14:39:48 111592 —-a-w- C:\Windows\System32\drivers\WRkrn.sys
2012-02-23 14:18:36 279656 ——w- C:\Windows\System32\MpSigStub.exe
2012-02-14 16:49:43 327680 —-a-w- C:\Windows\System32\d3d10_1core.dll
2012-02-14 16:49:43 196096 —-a-w- C:\Windows\System32\d3d10_1.dll
2012-02-14 15:45:30 219648 —-a-w- C:\Windows\SysWow64\d3d10_1core.dll
2012-02-14 15:45:30 160768 —-a-w- C:\Windows\SysWow64\d3d10_1.dll
2012-02-13 14:38:31 2002944 —-a-w- C:\Windows\System32\d3d10warp.dll
2012-02-13 14:12:08 1172480 —-a-w- C:\Windows\SysWow64\d3d10warp.dll
2012-02-13 14:06:48 834048 —-a-w- C:\Windows\System32\d2d1.dll
2012-02-13 14:03:11 1555968 —-a-w- C:\Windows\System32\DWrite.dll
2012-02-13 13:47:57 683008 —-a-w- C:\Windows\SysWow64\d2d1.dll
2012-02-13 13:44:40 1068544 —-a-w- C:\Windows\SysWow64\DWrite.dll
2012-02-02 15:34:25 2765824 —-a-w- C:\Windows\System32\win32k.sys
2012-01-03 14:25:21 404992 —-a-w- C:\Windows\System32\drivers\afd.sys
.
============= FINISH: 20:22:06.68 ===============
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-08-26.01)
.
Microsoft® Windows Vista™ Home Premium
Boot Device: \Device\HarddiskVolume2
Install Date: 6/6/2011 9:48:13 PM
System Uptime: 3/18/2012 7:27:27 PM (25 hours ago)
.
Motherboard: TOSHIBA | | Portable PC
Processor: Pentium® Dual-Core CPU T4300 @ 2.10GHz | CPU | 1200/800mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 287 GiB total, 156.637 GiB free.
D: is CDROM ()
.
==== Disabled Device Manager Items =============
.
==== Installed Programs ======================
.
Update for Microsoft Office 2007 (KB2508958)
Acrobat.com
Adobe AIR
Adobe Flash Player 9 ActiveX
Adobe Flash Player ActiveX
Adobe Reader 9.1
Amazon Links
Apple Application Support
Apple Software Update
Compatibility Pack for the 2007 Office system
Direct DiscRecorder
DVD MovieFactory for TOSHIBA
Google Chrome
Google Toolbar for Internet Explorer
Google Update Helper
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Java™ 6 Update 11
LightScribe 1.4.124.1
MediaWidget 6.0
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office Excel MUI (English) 2007
Microsoft Office Home and Student 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office PowerPoint Viewer 2007 (English)
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Standard 2007
Microsoft Office Suite Activation Assistant
Microsoft Office Word MUI (English) 2007
Microsoft Silverlight
Microsoft Visual C++ 2005 Redistributable
Microsoft Works
MSXML 4.0 SP2 (KB941833)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
Netzero Internet Access Installer
Picasa 2
QuickBooks Financial Center
QuickTime
Realtek 8136 8168 8169 Ethernet Driver
Realtek High Definition Audio Driver
Realtek USB 2.0 Card Reader
Realtek WiFi Protected Setup Library
Realtek WLAN Driver
Security Update for 2007 Microsoft Office System (KB2288621)
Security Update for 2007 Microsoft Office System (KB2288931)
Security Update for 2007 Microsoft Office System (KB2345043)
Security Update for 2007 Microsoft Office System (KB2553089)
Security Update for 2007 Microsoft Office System (KB2553090)
Security Update for 2007 Microsoft Office System (KB2584063)
Security Update for 2007 Microsoft Office System (KB969559)
Security Update for 2007 Microsoft Office System (KB976321)
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2657424)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
Security Update for Microsoft Office 2007 suites (KB2596785) 32-Bit Edition
Security Update for Microsoft Office InfoPath 2007 (KB979441)
Security Update for Microsoft Office PowerPoint 2007 (KB2596764) 32-Bit Edition
Security Update for Microsoft Office PowerPoint 2007 (KB2596912) 32-Bit Edition
Security Update for Microsoft Office system 2007 (972581)
Security Update for Microsoft Office system 2007 (KB974234)
Security Update for Microsoft Office Visio Viewer 2007 (KB973709)
Security Update for Microsoft Office Word 2007 (KB2344993)
Skype Launcher
Spotify
TOSHIBA Agreement Notification Utility
Toshiba Application Installer
TOSHIBA Assist
TOSHIBA ConfigFree
TOSHIBA DVD PLAYER
TOSHIBA eco Utility
TOSHIBA Extended Tiles for Windows Mobility Center
TOSHIBA Face Recognition
TOSHIBA Hardware Setup
TOSHIBA HDD/SSD Alert
TOSHIBA Internal Modem Region Select Utility
Toshiba Quality Application
Toshiba Registration
Toshiba Resources Page
TOSHIBA Service Station
TOSHIBA Speech System Applications
TOSHIBA Speech System SR Engine(U.S.) Version1.0
TOSHIBA Speech System TTS Engine(U.S.) Version1.0
TOSHIBA Supervisor Password
TOSHIBA Value Added Package
TOSHIBA Web Camera Application
Update for 2007 Microsoft Office System (KB2284654)
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Update for Microsoft Office 2007 Help for Common Features (KB963673)
Update for Microsoft Office 2007 suites (KB2596651) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2596789) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2597970) 32-Bit Edition
Update for Microsoft Office 2007 System (KB2539530)
Update for Microsoft Office Excel 2007 (KB2596596) 32-Bit Edition
Update for Microsoft Office Excel 2007 Help (KB963678)
Update for Microsoft Office OneNote 2007 (KB980729)
Update for Microsoft Office OneNote 2007 Help (KB963670)
Update for Microsoft Office Outlook 2007 (KB2583910)
Update for Microsoft Office Outlook 2007 Help (KB963677)
Update for Microsoft Office Powerpoint 2007 Help (KB963669)
Update for Microsoft Office Script Editor Help (KB963671)
Update for Microsoft Office Word 2007 Help (KB963665)
Webroot SecureAnywhere
WildTangent Games
.
==== Event Viewer Messages From Past Week ========
.
3/12/2012 3:19:11 PM, Error: Service Control Manager [7031] - The WRSVC service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 10000 milliseconds: Restart the service.
.
==== End Of File ===========================
aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software
Run date: 2012-03-19 20:28:47
—————————–
20:28:47.395 OS Version: Windows x64 6.0.6002 Service Pack 2
20:28:47.395 Number of processors: 2 586 0x170A
20:28:47.411 ComputerName: RWROBLEWSKI-PC UserName: r.wroblewski
20:28:49.423 Initialize success
20:29:26.469 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
20:29:26.469 Disk 0 Vendor: TOSHIBA_ FG01 Size: 305245MB BusType: 3
20:29:26.500 Disk 0 MBR read successfully
20:29:26.500 Disk 0 MBR scan
20:29:26.516 Disk 0 Windows VISTA default MBR code
20:29:26.531 Disk 0 Partition 1 00 27 Hidden NTFS WinRE NTFS 1500 MB offset 2048
20:29:26.547 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 293456 MB offset 3074048
20:29:26.578 Disk 0 Partition 3 00 17 Hidd HPFS/NTFS NTFS 10288 MB offset 604071936
20:29:26.625 Disk 0 scanning C:\Windows\system32\drivers
20:29:36.813 Service scanning
20:30:06.346 Service WRkrn C:\Windows\System32\drivers\WRkrn.sys **LOCKED** 32
20:30:07.391 Modules scanning
20:30:07.391 Disk 0 trace - called modules:
20:30:07.453 ntoskrnl.exe CLASSPNP.SYS disk.sys iaStor.sys hal.dll
20:30:07.453 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8006585790]
20:30:07.469 3 CLASSPNP.SYS[fffffa60011d2c33] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa8004bd9050]
20:30:07.484 Scan finished successfully
20:30:40.106 Disk 0 MBR has been saved successfully to "C:\Users\r.wroblewski\Desktop\MBR.dat"
20:30:40.199 The log file has been saved successfully to "C:\Users\r.wroblewski\Desktop\aswMBR.txt"
aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software
Run date: 2012-03-19 20:28:47
—————————–
20:28:47.395 OS Version: Windows x64 6.0.6002 Service Pack 2
20:28:47.395 Number of processors: 2 586 0x170A
20:28:47.411 ComputerName: RWROBLEWSKI-PC UserName: r.wroblewski
20:28:49.423 Initialize success
20:29:26.469 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
20:29:26.469 Disk 0 Vendor: TOSHIBA_ FG01 Size: 305245MB BusType: 3
20:29:26.500 Disk 0 MBR read successfully
20:29:26.500 Disk 0 MBR scan
20:29:26.516 Disk 0 Windows VISTA default MBR code
20:29:26.531 Disk 0 Partition 1 00 27 Hidden NTFS WinRE NTFS 1500 MB offset 2048
20:29:26.547 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 293456 MB offset 3074048
20:29:26.578 Disk 0 Partition 3 00 17 Hidd HPFS/NTFS NTFS 10288 MB offset 604071936
20:29:26.625 Disk 0 scanning C:\Windows\system32\drivers
20:29:36.813 Service scanning
20:30:06.346 Service WRkrn C:\Windows\System32\drivers\WRkrn.sys **LOCKED** 32
20:30:07.391 Modules scanning
20:30:07.391 Disk 0 trace - called modules:
20:30:07.453 ntoskrnl.exe CLASSPNP.SYS disk.sys iaStor.sys hal.dll
20:30:07.453 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8006585790]
20:30:07.469 3 CLASSPNP.SYS[fffffa60011d2c33] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa8004bd9050]
20:30:07.484 Scan finished successfully
20:30:40.106 Disk 0 MBR has been saved successfully to "C:\Users\r.wroblewski\Desktop\MBR.dat"
20:30:40.199 The log file has been saved successfully to "C:\Users\r.wroblewski\Desktop\aswMBR.txt"
20:33:46.854 Disk 0 MBR has been saved successfully to "C:\Users\r.wroblewski\Desktop\MBR.dat"
20:33:46.963 The log file has been saved successfully to "C:\Users\r.wroblewski\Desktop\aswMBR.txt"
Hi,
Please download
Listparts64
Run the tool, click Scan and post the log (Result.txt) it makes.
ListParts by Farbar Version: 12-03-2012 03
Ran by [removed] (administrator) on 19-03-2012 at 20:51:57
Windows Vista (X64)
Running From: C:\Users\[removed]\Downloads
Language: 0409
************************************************************
========================= Memory info ======================
Percentage of memory in use: 52%
Total physical RAM: 3963.05 MB
Available physical RAM: 1898.34 MB
Total Pagefile: 8145.36 MB
Available Pagefile: 5990.29 MB
Total Virtual: 8192 MB
Available Virtual: 8191.92 MB
======================= Partitions =========================
1 Drive c: (TI100680V0E) (Fixed) (Total:286.58 GB) (Free:156.6 GB) NTFS ==>[Drive with boot components (obtanied from BCD)]
Hi,
I am not seeing anything jumping out at me. Please do the following…
Please download
Malwarebytes' Anti-Malware to your desktop.
Right-click and Run as Administrator mbam-setup.exe and follow the prompts to install the program. At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware , then click Finish . If an update is found, it will download and install the latest version. Once the program has loaded, select Perform quick scan , then click Scan as shown below.
[external image: Posted Image]
When the scan is complete, click OK , then Show Results to view the results. Be sure that everything is checked, and click Remove Selected . When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
The log can also be found here:
C:\Documents and Settings\\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-date (time).txt
———-
ESET Online Scanner :
Note : You can use either Internet Explorer or Mozilla FireFox for this scan. You will however need to disable your current installed Anti-Virus, how to do so can be read
here .
Vista users : You will need to to right-click on the either the IE or FF icon in the Start Menu or Quick Launch Bar on the Taskbar and select
Run as Administrator from the context menu.
Please go here then click on: [external image: Posted Image] Note: If using Mozilla Firefox you will need to download esetsmartinstaller_enu.exe when prompted then double click on it to install.
All of the below instructions are compatible with either Internet Explorer or Mozilla FireFox . Select the option YES, I accept the Terms of Use then click on: [external image: Posted Image] When prompted allow the Add-On/Active X to install. Make sure that the option Remove found threats is NOT checked, and the option Scan archives is checked. Now click on Advanced Settings and select the following:
Scan for potentially unwanted applications Scan for potentially unsafe applications Enable Anti-Stealth Technology Now click on: [external image: Posted Image] The virus signature database… will begin to download. Be patient this make take some time depending on the speed of your Internet Connection. When completed the Online Scan will begin automatically. Do not touch either the Mouse or keyboard during the scan otherwise it may stall.When completed select Uninstall application on close if you so wish, make sure you copy the logfile first ! Now click on: [external image: Posted Image] Use notepad to open the logfile located at C:\Program Files\ESET\EsetOnlineScanner\log.txt . Copy and paste that log as a reply to this topic.
Note : Do not forget to re-enable your Anti-Virus application after running the above scan!
———-
In your next reply please post the logs created by Malwarebytes and ESET online scanner.
Can't use google chrome for the 2nd scan?
Are you not able to use either Internet Explorer or Firefox at all?
Hi,
Do you still need help?
Due to inactivity this topic will be closed.
If you need help please start a new thread.
New members follow the instructions here
http://forums.whatthetech.com/you_Infected_t106388.html and start a new topic
Sorry I'm posting this again. Last thread got shut down yesterday because I let it sit for too long. Sorry for wasting anyone's time. Would Still appreciate help and I will be more diligent this time.
Hi my names Ryan. My Laptop, running Windows Vista, is suddenly running slow in all areas (log-in, web browsing, opening programs…etc.)
Looks like a virus to me. I'd appreciate any help or advice. Thanks.
Topic reopened….OP returned.
Merged new topic with this one to continue with malware removal.
Hi,
Do you still need help?
Malwarebytes Anti-Malware 1.60.1.1000
www.malwarebytes.org
Database version: v2012.03.19.06
Windows Vista Service Pack 2 x64 NTFS
Internet Explorer 9.0.8112.16421
r.wroblewski :: RWROBLEWSKI-PC [administrator]
3/26/2012 4:08:45 PM
mbam-log-2012-03-26 (16-08-45).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 191271
Time elapsed: 10 minute(s), 5 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
(end)
having a very difficult time running the last scanner