This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

not sure what to do [Solved]

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

hi,

everytime my laptop connects to the internet, it automatically download something and consuming my bandwith. in the past, it already happened 3-4 times and then stopped. back then i checked with netstat -b and it was akamai who did this. i know akamai is content delivery network and not somekind of virus. but this thing is happening again and making me frustrated. i check with netstat -b and it connects to a ip address (not sure if it's akamai). i run msconfig and in startup tab i don't see any netsession/akamai thing. is there any way to stop this thing once and for all ?

specs :
OS Version: Microsoft Windows 7 Ultimate, 32 bit
Processor: Pentium® Dual-Core CPU T4500 @ 2.30GHz, x64 Family 6 Model 23 Stepping 10
Processor Count: 2
RAM: 1976 Mb
Graphics Card: Mobile Intel® 4 Series Express Chipset Family, 796 Mb
Hard Drives: C: Total - 44999 MB, Free - 12692 MB; E: Total - 131030 MB, Free - 86493 MB; F: Total - 129210 MB, Free - 101972 MB;
Motherboard: Acer, HM41
Antivirus: Norton Internet Security, Not Updated

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 7:16:13 PM, on 29-Mar-12
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskhost.exe
C:\Windows\Explorer.EXE
C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Internet Download Manager\IDMan.exe
C:\Program Files\Norton Internet Security\Engine\18.7.0.13\ccSvcHst.exe
C:\Program Files\Internet Download Manager\IEMonitor.exe
C:\Program Files\Hotspot Shield\bin\openvpntray.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\iClick 3.5G Modem\netcard.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe
C:\Windows\system32\SearchFilterHost.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = Preserve
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\18.7.0.13\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\18.7.0.13\IPS\IPSBHO.DLL
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~3\Office12\GR469A~1.DLL
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Hotspot Shield Class - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - C:\Program Files\Hotspot Shield\HssIE\HssIE.dll
O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\18.7.0.13\coIEPlg.dll
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [UCam_Menu] "C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\YouCam" update "Software\CyberLink\YouCam\1.0"
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [IDMan] C:\Program Files\Internet Download Manager\IDMan.exe /onboot
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: Download all links with IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: Download with IDM - C:\Program Files\Internet Download Manager\IEExt.htm
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O17 - HKLM\System\CCS\Services\Tcpip\..\{5E434099-A26D-4B8F-B864-0B390F45F0E2}: NameServer = 10.37.0.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{FA5BE887-175C-4943-8BF2-092C0D7C47F9}: NameServer = 103.3.220.215 203.78.120.215
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~3\Office12\GRA32A~1.DLL
O22 - SharedTaskScheduler: Windows DreamScene - {E31004D1-A431-41B8-826F-E902F9D95C81} - C:\Windows\System32\DreamScene.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Hotspot Shield Service (HotspotShieldService) - Unknown owner - C:\Program Files\Hotspot Shield\bin\openvpnas.exe
O23 - Service: Hotspot Shield Routing Service (HssSrv) - AnchorFree Inc. - C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe
O23 - Service: Hotspot Shield Tray Service (HssTrayService) - Unknown owner - C:\Program Files\Hotspot Shield\bin\HssTrayService.EXE
O23 - Service: Hotspot Shield Monitoring Service (HssWd) - Unknown owner - C:\Program Files\Hotspot Shield\bin\hsswd.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: Norton Internet Security (NIS) - Symantec Corporation - C:\Program Files\Norton Internet Security\Engine\18.7.0.13\ccSvcHst.exe
O23 - Service: @C:\Program Files\TuneUp Utilities 2010\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software - C:\Program Files\TuneUp Utilities 2010\TuneUpDefragService.exe
O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe

–
End of file - 6702 bytes
Hi

Please run the following:


For x32 (x86) bit systems download Farbar Recovery Scan Tool and save it to a flash drive.


Plug the flashdrive into the infected PC.

Enter System Recovery Options.

To enter System Recovery Options from the Advanced Boot Options:
  • Restart the computer.
  • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
  • Use the arrow keys to select the Repair your computer menu item.
  • Choose your language settings, and then click Next.
  • Select the operating system you want to repair, and then click Next.
  • Select your user account and click Next.
To enter System Recovery Options by using Windows installation disc:
  • Insert the installation disc.
  • Restart your computer.
  • If prompted, press any key to start Windows from the installation disc. If your computer is not configured to start from a CD or DVD, check your BIOS settings.
  • Click Repair your computer.
  • Choose your language settings, and then click Next.
  • Select the operating system you want to repair, and then click Next.
  • Select your user account an click Next.
On the System Recovery Options menu you will get the following options:Startup Repair
System Restore
Windows Complete PC Restore
Windows Memory Diagnostic Tool
Command Prompt

[*]Select Command Prompt

[*]In the command window type in notepad and press Enter.

[*]The notepad opens. Under File menu select Open.

[*]Select "Computer" and find your flash drive letter and close the notepad.

[*]In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter

Note: Replace letter e with the drive letter of your flash drive.
[*]The tool will start to run.

[*]When the tool opens click Yes to the disclaimer.

[*]Place a check next to List Drivers MD5 as well as the default check marks that are already there

[*]Press Scan button.

[*]type exit and reboot the computer normally

[*]FRST will make a log (FRST.txt) on the flash drive, please copy and paste the log in your reply.

thanks for answering my question. this is the scan result : Scan result of Farbar Recovery Scan Tool (FRST written by farbar) Version: 14-03-2012 Ran by [removed] at 02-04-2012 00:53:47 Running from G:\ Windows 7 Ultimate (X86) OS Language: English(US) The current controlset is ControlSet001 ========================== Registry (Whitelisted) ============= HKLM\…\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [155648 2006-01-12] (Nero AG) HKLM\…\Run: [UCam_Menu] "C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\YouCam" update "Software\CyberLink\YouCam\1.0" [218408 2007-08-16] (CyberLink Corp.) HKLM\…\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe [136216 2010-08-25] (Intel Corporation) HKLM\…\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe [171032 2010-08-25] (Intel Corporation) HKLM\…\Run: [Persistence] C:\Windows\system32\igfxpers.exe [170520 2010-08-25] (Intel Corporation) HKU\user\…\Run: [IDMan] C:\Program Files\Internet Download Manager\IDMan.exe /onboot [3392920 2011-07-07] (Tonec Inc.) Winlogon\Notify\igfxcui: igfxdev.dll (Intel Corporation) Tcpip\..\Interfaces\{5E434099-A26D-4B8F-B864-0B390F45F0E2}: [NameServer]10.37.0.1 ================================ Services (Whitelisted) ================== 3 Adobe LM Service; "C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe" [68096 2010-03-28] () 2 HotspotShieldService; C:\Program Files\Hotspot Shield\bin\openvpnas.exe [265776 2010-09-22] () 2 HssSrv; C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe [350256 2010-09-23] (AnchorFree Inc.) 3 HssTrayService; C:\Program Files\Hotspot Shield\bin\HssTrayService.EXE [57640 2010-09-22] () 2 HssWd; C:\Program Files\Hotspot Shield\bin\hsswd.exe -product HSS [325168 2010-09-22] () 3 NBService; C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe [774144 2006-11-10] (Nero AG) 2 NIS; "C:\Program Files\Norton Internet Security\Engine\18.7.0.13\ccSvcHst.exe" /s "NIS" /m "C:\Program Files\Norton Internet Security\Engine\18.7.0.13\diMaster.dll" /prefetch:1 [262584 2011-03-31] (Symantec Corporation) 3 TuneUp.Defrag; C:\Program Files\TuneUp Utilities 2010\TuneUpDefragService.exe [435016 2010-10-09] (TuneUp Software) 2 TuneUp.UtilitiesSvc; "C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe" [1050440 2010-04-18] (TuneUp Software) 2 UleadBurningHelper; C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe [49152 2005-01-30] (Ulead Systems, Inc.) 2 UxTuneUp; C:\Windows\System32\uxtuneup.dll [30024 2010-04-18] (TuneUp Software) 4 Com4QLBEx; "C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe" [x] 4 hpqwmiex; "C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe" [x] 4 sppsvc; C:\Windows\System32\sppsvc.exe [x] 4 sppuinotify; C:\Windows\System32\sppuinotify.dll [x] ========================== Drivers (Whitelisted) ============= 3 AgereSoftModem; C:\Windows\System32\DRIVERS\AGRSM.sys [1035776 2009-07-13] (LSI Corp) 1 BHDrvx86; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\BASHDefs\20120121.002\BHDrvx86.sys [820344 2011-11-30] (Symantec Corporation) 3 BMserDiag; C:\Windows\System32\DRIVERS\BMserDiag.sys [87424 2009-11-26] (Global Wireless Incorporated) 3 BMserNmea; C:\Windows\System32\DRIVERS\BMserNmea.sys [87424 2009-11-26] (Global Wireless Incorporated) 3 BMusbmdm; C:\Windows\System32\DRIVERS\BMusbmdm.sys [87424 2009-11-26] (Global Wireless Incorporated) 3 DKbFltr; C:\Windows\System32\DRIVERS\DKbFltr.sys [21000 2009-03-25] (Dritek System Inc.) 1 eeCtrl; \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys [374392 2012-01-12] (Symantec Corporation) 3 EraserUtilRebootDrv; \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [106104 2012-01-12] (Symantec Corporation) 3 HssDrv; C:\Windows\System32\DRIVERS\HssDrv.sys [37376 2010-09-22] (AnchorFree Inc.) 2 IDMWFP; C:\Windows\System32\DRIVERS\idmwfp.sys [89376 2011-07-06] (Tonec Inc.) 1 IDSVix86; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\IPSDefs\20120202.002\IDSvix86.sys [368248 2011-12-15] (Symantec Corporation) 3 JMCR; C:\Windows\System32\DRIVERS\jmcr.sys [100184 2008-07-31] (JMicron Technology Corporation) 3 NAVENG; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\VirusDefs\20120113.003\NAVENG.SYS [86136 2012-01-12] (Symantec Corporation) 3 NAVEX15; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\VirusDefs\20120113.003\NAVEX15.SYS [1576312 2012-01-12] (Symantec Corporation) 0 sptd; C:\Windows\System32\Drivers\sptd.sys [691696 2010-11-07] (Duplex Secure Ltd.) 3 SRTSP; C:\Windows\System32\Drivers\NIS\1207000.00D\SRTSP.SYS [516216 2011-03-30] (Symantec Corporation) 1 SRTSPX; C:\Windows\System32\drivers\NIS\1207000.00D\SRTSPX.SYS [50168 2011-03-30] (Symantec Corporation) 0 SymDS; C:\Windows\System32\drivers\NIS\1207000.00D\SYMDS.SYS [340088 2011-01-26] (Symantec Corporation) 0 SymEFA; C:\Windows\System32\drivers\NIS\1207000.00D\SYMEFA.SYS [744568 2011-03-14] (Symantec Corporation) 3 SymEvent; \??\C:\Windows\system32\Drivers\SYMEVENT.SYS [126584 2012-01-19] (Symantec Corporation) 1 SymIRON; C:\Windows\System32\drivers\NIS\1207000.00D\Ironx86.SYS [136312 2011-01-26] (Symantec Corporation) 1 SymNetS; C:\Windows\System32\Drivers\NIS\1207000.00D\SYMNETS.SYS [299640 2011-04-20] (Symantec Corporation) 3 tap0901; C:\Windows\System32\DRIVERS\tap0901.sys [26624 2010-09-01] (The OpenVPN Project) 3 taphss; C:\Windows\System32\DRIVERS\taphss.sys [32768 2010-09-22] (AnchorFree Inc) 3 TuneUpUtilitiesDrv; \??\C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys [10064 2010-02-24] (TuneUp Software) 3 vpcbus; C:\Windows\System32\DRIVERS\vpchbus.sys [165376 2009-10-05] (Microsoft Corporation) 1 vpcnfltr; C:\Windows\System32\DRIVERS\vpcnfltr.sys [55040 2009-10-05] (Microsoft Corporation) 3 vpcusb; C:\Windows\System32\DRIVERS\vpcusb.sys [78336 2009-10-05] (Microsoft Corporation) 1 vpcvmm; C:\Windows\System32\drivers\vpcvmm.sys [294912 2009-10-05] (Microsoft Corporation) 3 WsAudio_DeviceS(1); C:\Windows\System32\drivers\WsAudio_DeviceS(1).sys [25704 2010-11-19] (Wondershare) 3 WsAudio_DeviceS(2); C:\Windows\System32\drivers\WsAudio_DeviceS(2).sys [25704 2010-11-19] (Wondershare) 3 WsAudio_DeviceS(3); C:\Windows\System32\drivers\WsAudio_DeviceS(3).sys [25704 2010-11-19] (Wondershare) 3 WsAudio_DeviceS(4); C:\Windows\System32\drivers\WsAudio_DeviceS(4).sys [25704 2010-11-19] (Wondershare) 3 WsAudio_DeviceS(5); C:\Windows\System32\drivers\WsAudio_DeviceS(5).sys [25704 2010-11-19] (Wondershare) 4 Wlapbat; [x] ========================== NetSvcs (Whitelisted) =========== NETSVC: UxTuneUp ============ One Month Created Files and Folders ============== 2012-04-02 00:52 - 2012-04-02 00:54 - 0000000 ____D C:\FRST 2012-03-26 05:45 - 2012-04-01 09:40 - 0000000 ____D C:\Program Files\iClick 3.5G Modem 2012-03-26 05:45 - 2012-03-26 05:45 - 0001032 ____A C:\Users\user\Desktop\iClick 3.5G Modem.lnk 2012-03-26 05:38 - 2012-03-26 05:45 - 0014206 ____A C:\Windows\DPINST.LOG 2012-03-21 12:49 - 2012-03-21 12:49 - 0000000 ____D C:\Program Files\Intel 2012-03-21 12:49 - 2012-03-21 12:49 - 0000000 ____D C:\Intel 2012-03-21 10:26 - 2012-03-21 10:26 - 0000000 ____D C:\Users\user\AppData\Local\realtech_VR 2012-03-21 10:23 - 2012-03-21 10:23 - 0000000 ____D C:\Users\All Users\realtech VR 2012-03-21 10:23 - 2012-03-21 10:23 - 0000000 ____D C:\ProgramData\realtech VR 2012-03-21 10:23 - 2012-03-21 10:23 - 0000000 ____D C:\Program Files\realtech VR 2012-03-20 23:12 - 2012-03-20 23:12 - 0000744 ____A C:\Windows\PFRO.log 2012-03-20 14:25 - 2012-03-20 14:25 - 0000000 ____D C:\Users\user\AppData\Roaming\Rovio 2012-03-18 22:56 - 2012-03-18 22:56 - 0000000 ____D C:\Users\All Users\Fenomen Games 2012-03-18 22:56 - 2012-03-18 22:56 - 0000000 ____D C:\ProgramData\Fenomen Games 2012-03-18 10:56 - 2012-03-18 10:56 - 0000000 ____D C:\Users\user\AppData\Local\Oberon Media 2012-03-18 10:56 - 2012-03-18 10:56 - 0000000 ____D C:\Users\All Users\Trymedia 2012-03-18 10:56 - 2012-03-18 10:56 - 0000000 ____D C:\ProgramData\Trymedia 2012-03-17 01:29 - 2012-03-17 01:29 - 0000990 ____A C:\Users\Guest\Desktop\The Proxomitron.lnk 2012-03-17 00:47 - 2012-03-17 00:48 - 0000000 ____D C:\Program Files\ISPCE 2012-03-17 00:47 - 2010-12-04 04:54 - 0108336 ____A (Microsoft Corporation) C:\Windows\System32\MSWINSCK.OCX 2012-03-17 00:47 - 2007-02-13 06:30 - 0128720 ____A (/n software inc. - www.nsoftware.com) C:\Windows\System32\ipinfo61.ocx 2012-03-17 00:40 - 2010-09-01 05:07 - 0026624 ____A (The OpenVPN Project) C:\Windows\System32\Drivers\tap0901.sys 2012-03-16 00:02 - 2012-03-16 00:02 - 1508056 ____A C:\Windows\Minidump\031612-20638-01.dmp 2012-03-14 10:27 - 2012-03-14 10:27 - 0000000 ____D C:\Users\user\Documents\TikGames 2012-03-14 10:26 - 2012-03-14 10:26 - 0000000 ____D C:\Program Files\Hasbro ============ 3 Months Modified Files and Folders =============== 2012-04-01 09:44 - 2010-09-20 09:50 - 0000000 ____D C:\Users\user\AppData\Roaming\DMCache 2012-04-01 09:44 - 2010-03-29 11:41 - 1770340 ____A C:\Windows\WindowsUpdate.log 2012-04-01 09:40 - 2012-03-26 05:45 - 0000000 ____D C:\Program Files\iClick 3.5G Modem 2012-04-01 09:20 - 2011-12-03 04:18 - 0000000 ____D C:\Users\user\AppData\Roaming\IDM 2012-04-01 09:06 - 2012-03-02 08:59 - 0008960 ____A C:\Windows\setupact.log 2012-04-01 09:06 - 2010-03-29 11:38 - 1554718720 __ASH C:\hiberfil.sys 2012-04-01 09:06 - 2009-07-13 20:53 - 0000006 ___AH C:\Windows\Tasks\SA.DAT 2012-04-01 05:29 - 2010-10-31 01:24 - 0000000 ____D C:\Program Files\Mozilla Firefox 2012-04-01 02:07 - 2011-05-13 06:28 - 0000000 ____D C:\Users\All Users\xml_param 2012-04-01 02:07 - 2011-05-13 06:28 - 0000000 ____D C:\ProgramData\xml_param 2012-04-01 02:06 - 2011-07-13 22:16 - 0000000 ____D C:\Users\user\AppData\Roaming\mIRC 2012-04-01 00:20 - 2011-07-13 22:16 - 0000000 ____D C:\Program Files\mIRC 2012-03-31 02:06 - 2010-10-20 06:29 - 0000000 ____D C:\Users\user\AppData\Local\CrashDumps 2012-03-26 09:33 - 2009-07-13 20:53 - 0032532 ____A C:\Windows\Tasks\SCHEDLGU.TXT 2012-03-26 05:45 - 2012-03-26 05:45 - 0001032 ____A C:\Users\user\Desktop\iClick 3.5G Modem.lnk 2012-03-26 05:45 - 2012-03-26 05:38 - 0014206 ____A C:\Windows\DPINST.LOG 2012-03-26 05:45 - 2009-07-13 18:37 - 0000000 ____D C:\Windows\System32\DriverStore 2012-03-21 12:49 - 2012-03-21 12:49 - 0000000 ____D C:\Program Files\Intel 2012-03-21 12:49 - 2012-03-21 12:49 - 0000000 ____D C:\Intel 2012-03-21 10:26 - 2012-03-21 10:26 - 0000000 ____D C:\Users\user\AppData\Local\realtech_VR 2012-03-21 10:23 - 2012-03-21 10:23 - 0000000 ____D C:\Users\All Users\realtech VR 2012-03-21 10:23 - 2012-03-21 10:23 - 0000000 ____D C:\ProgramData\realtech VR 2012-03-21 10:23 - 2012-03-21 10:23 - 0000000 ____D C:\Program Files\realtech VR 2012-03-20 23:12 - 2012-03-20 23:12 - 0000744 ____A C:\Windows\PFRO.log 2012-03-20 14:25 - 2012-03-20 14:25 - 0000000 ____D C:\Users\user\AppData\Roaming\Rovio 2012-03-19 03:12 - 2010-03-28 22:14 - 0000000 ____D C:\Program Files\GameHouse 2012-03-18 22:56 - 2012-03-18 22:56 - 0000000 ____D C:\Users\All Users\Fenomen Games 2012-03-18 22:56 - 2012-03-18 22:56 - 0000000 ____D C:\ProgramData\Fenomen Games 2012-03-18 10:56 - 2012-03-18 10:56 - 0000000 ____D C:\Users\user\AppData\Local\Oberon Media 2012-03-18 10:56 - 2012-03-18 10:56 - 0000000 ____D C:\Users\All Users\Trymedia 2012-03-18 10:56 - 2012-03-18 10:56 - 0000000 ____D C:\ProgramData\Trymedia 2012-03-17 01:29 - 2012-03-17 01:29 - 0000990 ____A C:\Users\Guest\Desktop\The Proxomitron.lnk 2012-03-17 01:15 - 2009-07-13 18:37 - 0000000 ____D C:\Windows\registration 2012-03-17 00:48 - 2012-03-17 00:47 - 0000000 ____D C:\Program Files\ISPCE 2012-03-16 00:02 - 2012-03-16 00:02 - 1508056 ____A C:\Windows\Minidump\031612-20638-01.dmp 2012-03-16 00:02 - 2010-10-20 07:16 - 0000000 ____D C:\Windows\Minidump 2012-03-14 10:27 - 2012-03-14 10:27 - 0000000 ____D C:\Users\user\Documents\TikGames 2012-03-14 10:26 - 2012-03-14 10:26 - 0000000 ____D C:\Program Files\Hasbro 2012-03-10 16:06 - 2010-03-28 22:09 - 0000000 ____D C:\Users\All Users\Adobe 2012-03-10 16:06 - 2010-03-28 22:09 - 0000000 ____D C:\ProgramData\Adobe 2012-03-10 16:00 - 2010-03-28 22:05 - 0000000 ____D C:\Users\user\AppData\Roaming\Adobe 2012-03-10 14:53 - 2011-02-25 13:04 - 0000000 ____D C:\Users\user\AppData\Roaming\uTorrent 2012-02-11 12:58 - 2010-03-28 21:48 - 0121352 ____A C:\Users\user\AppData\Local\GDIPFONTCACHEV1.DAT 2012-02-10 02:54 - 2009-07-13 20:33 - 0432976 ____A C:\Windows\System32\FNTCACHE.DAT 2012-02-09 13:53 - 2012-01-18 15:50 - 0000000 ____D C:\Program Files\FM Genie Scout 12 2012-02-04 00:01 - 2012-01-02 22:02 - 0002430 ____A C:\Users\Public\Desktop\Norton Internet Security.lnk 2012-02-04 00:01 - 2012-01-02 22:02 - 0000000 ____D C:\Windows\System32\Drivers\NIS 2012-02-02 13:58 - 2012-02-02 13:58 - 0000000 ____D C:\Program Files\Trend Micro 2012-01-21 09:10 - 2009-07-13 18:37 - 0000000 ____D C:\Windows\System32\config\TxR 2012-01-21 00:05 - 2010-10-22 03:55 - 0016896 __ASH C:\Windows\System32\config\SYSTEM_tureg_new.LOG1 2012-01-21 00:05 - 2010-03-28 21:47 - 0000000 ____D C:\users\user 2012-01-21 00:05 - 2009-11-06 12:26 - 0524288 ____A C:\Windows\System32\config\DEFAULT_tureg_old 2012-01-21 00:05 - 2009-11-06 12:25 - 47972352 ____A C:\Windows\System32\config\SOFTWARE_tureg_old 2012-01-21 00:05 - 2009-11-06 12:25 - 18087936 ____A C:\Windows\System32\config\SYSTEM_tureg_old 2012-01-21 00:05 - 2009-07-13 18:03 - 0262144 ____A C:\Windows\System32\config\SECURITY_tureg_old 2012-01-21 00:02 - 2009-07-13 18:03 - 0102400 ____A C:\Windows\System32\config\SAM_tureg_old 2012-01-19 09:08 - 2012-01-02 22:02 - 0126584 ____A (Symantec Corporation) C:\Windows\System32\Drivers\SYMEVENT.SYS 2012-01-19 09:08 - 2012-01-02 22:02 - 0007468 ____A C:\Windows\System32\Drivers\SYMEVENT.CAT 2012-01-19 09:08 - 2012-01-02 22:02 - 0000806 ____A C:\Windows\System32\Drivers\SYMEVENT.INF 2012-01-19 09:08 - 2012-01-02 22:02 - 0000000 ____D C:\Program Files\Symantec 2012-01-05 12:16 - 2012-01-05 12:16 - 0000000 ____A C:\Windows\System32\cd.dat 2012-01-05 12:16 - 2012-01-05 12:15 - 0000000 ____D C:\Program Files\Hotspot Shield 2012-01-05 12:16 - 2012-01-05 12:15 - 0000000 ____D C:\Hotspot Shield 2012-01-04 10:33 - 2012-01-02 22:02 - 0000000 ____D C:\Users\All Users\NortonInstaller 2012-01-04 10:33 - 2012-01-02 22:02 - 0000000 ____D C:\ProgramData\NortonInstaller ========================= Known DLLs (Whitelisted) ============ ========================= Bamital & volsnap Check ============ C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe [2009-11-05 13:40] - [2009-11-05 13:40] - 0285696 ____A (Microsoft Corporation) B151128D1FEBF745BC7EFDE9FACB165A C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\User32.dll [2009-10-05 15:45] - [2009-10-05 15:45] - 0811520 ____A (Microsoft Corporation) C7B21BEF09EC7249556BEE19F9D314CB C:\Windows\System32\Drivers\volsnap.sys [2009-10-05 16:04] - [2009-10-05 16:04] - 0245336 ____A (Microsoft Corporation) 70F41D1EBDD9EE6ED2FD0FC05AA1FC13 ========================= Memory info ====================== Percentage of memory in use: 19% Total physical RAM: 1976.93 MB Available physical RAM: 1599.51 MB Total Pagefile: 1976.93 MB Available Pagefile: 1603.56 MB Total Virtual: 2047.88 MB Available Virtual: 1970.31 MB ======================= Partitions ========================= 1 Drive c: (Program) (Fixed) (Total:43.95 GB) (Free:13.81 GB) NTFS ==>[Drive with boot components (obtanied from BCD)] 2 Drive d: (Entertainment) (Fixed) (Total:127.96 GB) (Free:84.28 GB) NTFS 3 Drive e: (Data) (Fixed) (Total:126.18 GB) (Free:99.23 GB) NTFS 5 Drive g: (CYNICAL ONE) (Removable) (Total:1.88 GB) (Free:1.88 GB) FAT 6 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS Disk ### Status Size Free Dyn Gpt ——– ————- ——- ——- — — Disk 0 Online 298 GB 2048 KB Disk 1 Online 1927 MB 0 B Partitions of Disk 0: =============== Partition ### Type Size Offset ————- —————- ——- ——- Partition 1 Primary 43 GB 1024 KB Partition 0 Extended 254 GB 43 GB Partition 2 Logical 127 GB 43 GB Partition 3 Logical 126 GB 171 GB ================================================================================ ====================== Disk: 0 Partition 1 Type : 07 Hidden: No Active: Yes Volume ### Ltr Label Fs Type Size Status Info ———- — ———– —– ———- ——- ——— ——– * Volume 1 C Program NTFS Partition 43 GB Healthy ================================================================================ ====================== Disk: 0 Partition 2 Type : 07 Hidden: No Active: No Volume ### Ltr Label Fs Type Size Status Info ———- — ———– —– ———- ——- ——— ——– * Volume 2 D Entertainme NTFS Partition 127 GB Healthy ================================================================================ ====================== Disk: 0 Partition 3 Type : 07 Hidden: No Active: No Volume ### Ltr Label Fs Type Size Status Info ———- — ———– —– ———- ——- ——— ——– * Volume 3 E Data NTFS Partition 126 GB Healthy ================================================================================ ====================== Partitions of Disk 1: =============== Partition ### Type Size Offset ————- —————- ——- ——- * Partition 1 Primary 1927 MB 0 B ================================================================================ ====================== Disk: 1 There is no partition selected. There is no partition selected. Please select a partition and try again. ================================================================================ ====================== ========================================================== Last Boot: 2012-03-31 10:33 ======================= End Of Log ========================== for now the automatic download has stop. not sure what will happen next.
Hi,

I don't see any malware in the log at all, I had you run the scan outside of Windows just in case anything was hidden, so I don't believe this is a malware issue, before we look at what else could be causing this please run an online scan with ESET to make certain there are no infected files

Go here to run an online scanner from ESET.
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activeX control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • When the scan completes, press the LIST OF THREATS FOUND button
  • Press EXPORT TO TEXT FILE , name the file ESETSCAN and save it to your desktop
  • Include the contents of this report in your next reply.
  • Press the BACK button.
  • Press Finish
esetscan result : C:\Program Files\Hotspot Shield\bin\openvpnas.exe a variant of Win32/HotSpotShield application F:\Software\antivirus\Norton Internet Security 2011 18.1.0.37\BOX_NTR2011_3.0.0\1BOX_NTR2011.exe Win32/RiskWare.HackAV.HF application F:\Software\antivirus\Norton Internet Security 2011 18.1.0.37\raw\Norton Internet Security 2011 18.1.0.37.Gh0sT.RiDeR.rar Win32/RiskWare.HackAV.HF application F:\Software\internet\Hotspot Shield 1.52.exe a variant of Win32/HotSpotShield application F:\Software\internet\u998.exe a variant of Win32/UltraReach application F:\Software\internet\software trik internet\u95-und3rw0rld.zip a variant of Win32/UltraReach.AC application i forgot to tell you that after that automatic download stopped and i restarted my laptop, there's a warning about my battery : "consider replacing your battery" "there is a problem with your battery, so your computer might shut down suddenly". but my battery works normally right now. is it also related with this ?
Hi It may very well be that you need to replace your battery. This doesn't appear to be malware related at all. what was the source of the Norton Internet Security? If they are torrent downloads or otherwise cracked, then I suggest you remove them. Most of the issues we see are caused by cracked and keygens. The downloading may have been a legitimate program that you have installed updating itself? Hard to know at this point. Are you still having issues with your machine?
hi my norton internet security uses trial reset to expand its trial period. i'll uninstall it if i can find another antivirus which reliable and free. do you have any suggestion for a good and free antivirus ? as far as i remember i never set any program to update itself, only notice me if there are updates available. as for now, i don't have any problem with my machine. thank you very much for your help. i really appreciate it.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI