I get a Norton Anitivirus box that reports adware being present. However, I find this suspect. It's been awhile since I've visited you guys with my personal computer anyway so I figured I'd like you guys take a look.
As always, thanks for the help!
6 min read
I get a Norton Anitivirus box that reports adware being present. However, I find this suspect. It's been awhile since I've visited you guys with my personal computer anyway so I figured I'd like you guys take a look.
As always, thanks for the help!
Hi DanaF,
There isn't much showing in the logs you provided, please run these additional scans.
Also, kindly copy & paste the logs directly into the reply window.
My name is OCD. I would be more than happy to take a look at your log and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
IMPORTANT NOTE : Please do not delete, download or install anything unless instructed to do so.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision. Doing so could make your system inoperable and could require a full reinstall of your Operating System and losing all your programs and data.
Please stay with this topic until I let you know that your system appears to be "All Clear"
Important: All tools MUST be run from the Desktop.
=========================
[external image: bullseye_zpse9eaf36e.gif] Security Check
Download Security Check by screen317 from here or here.
=========================
[external image: bullseye_zpse9eaf36e.gif] aswMBR
Download aswMBR.exe and save it to your desktop.
=========================
[external image: bullseye_zpse9eaf36e.gif] AdwCleaner
Download AdwCleaner to your desktop.
=========================
[external image: bullseye_zpse9eaf36e.gif] Junkware Removal Tool
Download Junkware Removal Tool to your desktop.
=========================
In your next post please provide the following:
Ok, not sure what's going on here, but I'm not being allowed to paste into the reply window. I've used the paste icons above, as well as ctrl+v, and neither is working. Am I missing something simple?
Hi DanaF,
Ok, not sure what's going on here, but I'm not being allowed to paste into the reply window. I've used the paste icons above, as well as ctrl+v, and neither is working. Am I missing something simple?
If you run into problems being able to paste logs into the reply window, please click the toggle switch in the menu and retry. The menu will be greyed out when you can paste into the window.
[external image: WTTtoggleswitch_zpsd2b76942.gif]
Here are the scan results for Security Check:
Results of screen317's Security Check version 0.99.86
Windows 7 Service Pack 1 x64 (UAC is enabled)
Internet Explorer 11
``````````````Antivirus/Firewall Check:``````````````
Windows Firewall Enabled!
Norton Security Suite
WMI entry may not exist for antivirus; attempting automatic update.
`````````Anti-malware/Other Utilities Check:`````````
JavaFX 2.1.1
Java(TM) 7 Update 5
Java 2 Runtime Environment, SE v1.4.1_02
Java version out of Date!
Adobe Flash Player 11.4.402.265 Flash Player out of Date!
Adobe Reader XI
````````Process Check: objlist.exe by Laurent````````
Malwarebytes Anti-Malware mbamservice.exe
Malwarebytes Anti-Malware mbam.exe
Malwarebytes Anti-Malware mbamscheduler.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C: 3%
````````````````````End of Log``````````````````````
Here are the scan results of aswMBR:
aswMBR version 1.0.1.2041 Copyright© 2014 AVAST Software
Run date: 2014-07-21 19:52:37
—————————–
19:52:37.924 OS Version: Windows x64 6.1.7601 Service Pack 1
19:52:37.924 Number of processors: 4 586 0xF0B
19:52:37.924 ComputerName: DANA-PC UserName: Dana
19:52:39.812 Initialize success
19:52:40.077 VM: initialized successfully
19:52:40.108 VM: Intel CPU supported
19:52:43.925 VM: supported disk I/O storport.sys
19:53:12.301 AVAST engine defs: 14072001
19:53:18.744 Disk 0 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0
19:53:18.744 Disk 0 Vendor: WDC_WD32 12.0 Size: 305244MB BusType: 3
19:53:18.744 Disk 1 \Device\Harddisk1\DR1 -> \Device\Ide\IAAStorageDevice-1
19:53:18.744 Disk 1 Vendor: Maxtor_6 BANC Size: 95611MB BusType: 3
19:53:18.744 Disk 2 \Device\Harddisk2\DR2 -> \Device\00000081
19:53:18.760 Disk 2 Vendor: SEAGATE_ 0002 Size: 35003MB BusType: 1
19:53:18.760 Disk 3 (boot) \Device\Harddisk3\DR3 -> \Device\00000082
19:53:18.760 Disk 3 Vendor: FUJITSU_ 0104 Size: 140272MB BusType: 1
19:53:18.838 VM: Disk 3 MBR read successfully
19:53:18.838 Disk 3 MBR scan
19:53:18.853 Disk 3 Windows VISTA default MBR code
19:53:18.853 Disk 3 Partition 1 80 (A) 07 HPFS/NTFS NTFS 140270 MB offset 63
19:53:18.869 Disk 3 default boot code
19:53:18.900 Disk 3 scanning C:\Windows\system32\drivers
19:53:28.276 Service scanning
19:53:30.382 Service BHDrvx64 C:\Program Files (x86)\Norton Security Suite\NortonData\21.1.0.18\Definitions\BASHDefs\20140703.001\BHDrvx64.sys **LOCKED** 5
19:53:35.296 Service IDSVia64 C:\Program Files (x86)\Norton Security Suite\NortonData\21.1.0.18\Definitions\IPSDefs\20140718.001\IDSvia64.sys **LOCKED** 5
19:53:37.760 Service NAVENG C:\Program Files (x86)\Norton Security Suite\NortonData\21.1.0.18\Definitions\VirusDefs\20140721.009\ENG64.SYS **LOCKED** 5
19:53:37.901 Service NAVEX15 C:\Program Files (x86)\Norton Security Suite\NortonData\21.1.0.18\Definitions\VirusDefs\20140721.009\EX64.SYS **LOCKED** 5
19:53:49.757 Modules scanning
19:53:49.757 Disk 3 trace - called modules:
19:53:49.772 ntoskrnl.exe CLASSPNP.SYS disk.sys storport.sys hal.dll adpu320.sys
19:53:49.788 1 nt!IofCallDriver -> \Device\Harddisk3\DR3[0xfffffa8005340060]
19:53:49.788 3 CLASSPNP.SYS[fffff880019b743f] -> nt!IofCallDriver -> \Device\00000082[0xfffffa80050c4060]
19:53:50.599 AVAST engine scan C:\Windows
19:53:51.785 AVAST engine scan C:\Windows\system32
19:56:44.430 AVAST engine scan C:\Windows\system32\drivers
19:56:55.241 AVAST engine scan C:\Users\Dana
20:18:08.244 AVAST engine scan C:\ProgramData
20:20:52.574 Scan finished successfully
20:21:23.572 Disk 3 MBR has been saved successfully to "C:\Users\Dana\Desktop\MBR.dat"
20:21:23.572 The log file has been saved successfully to "C:\Users\Dana\Desktop\aswMBR.txt"
Here are the scan results of AdwCleaner:
# AdwCleaner v3.216 - Report created 21/07/2014 at 20:25:31
# Updated 17/07/2014 by Xplode
# Operating System : Windows 7 Ultimate Service Pack 1 (64 bits)
# Username : Dana - DANA-PC
# Running from : C:\Users\Dana\Desktop\AdwCleaner.exe
# Option : Clean
***** [ Services ] *****
***** [ Files / Folders ] *****
Folder Deleted : C:\ProgramData\Uniblue
Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Uniblue
Folder Deleted : C:\Program Files (x86)\Uniblue
Folder Deleted : C:\Users\Dana\AppData\Local\eSupport.com
Folder Deleted : C:\Users\Dana\AppData\Roaming\Uniblue
Folder Deleted : C:\Users\Dana\Documents\Updater
File Deleted : C:\Windows\Tasks\driverscanner.job
File Deleted : C:\Windows\System32\Tasks\driverscanner
***** [ Shortcuts ] *****
***** [ Registry ] *****
Value Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [DriverScanner]
Key Deleted : HKLM\SOFTWARE\Classes\driverscanner
Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.protectorbho
Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.protectorbho.1
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\driverscanner_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\driverscanner_RASMANCS
Value Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [updaterz.exe]
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2318C2B1-4965-11D4-9B18-009027A5CD4F}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{2318C2B1-4965-11D4-9B18-009027A5CD4F}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{2318C2B1-4965-11D4-9B18-009027A5CD4F}]
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F}
Value Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{2318C2B1-4965-11D4-9B18-009027A5CD4F}]
Key Deleted : HKLM\Software\Uniblue
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{C2F8CA82-2BD9-4513-B2D1-08A47914C1DA}_is1
***** [ Browsers ] *****
-\\ Internet Explorer v11.0.9600.17207
*************************
AdwCleaner[R0].txt - [2949 octets] - [21/07/2014 20:24:14]
AdwCleaner[S0].txt - [2479 octets] - [21/07/2014 20:25:31]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [2539 octets] ##########
Here are the scan results for JRT:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 7 Ultimate x64
Ran by [removed] on Mon 07/21/2014 at 20:32:39.41
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
~~~ Folders
Successfully deleted: [Empty Folder] C:\Users\Dana\appdata\local\{8B017DDE-7B84-4FE2-BA8F-2388EB8D6717}
Successfully deleted: [Empty Folder] C:\Users\Dana\appdata\local\{F0EFA827-299E-4C96-B23E-D4C1A3A0F54C}
Successfully deleted: [Empty Folder] C:\Users\Dana\appdata\local\{F83EB0B7-658E-4AD0-BD8D-085026FC40C5}
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Mon 07/21/2014 at 20:43:36.92
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Hi DanaF,
[external image: bullseye_zpse9eaf36e.gif] Malwarebytes' Anti-Malware
Download Malwarebytes' Anti-Malware (save it to your desktop).
=========================
[external image: bullseye_zpse9eaf36e.gif] ESET Online Scanner
*Note:
** You need to run your browser with Administrator Rights, to do so right click your browsers short cut and select "Run as Administrator".
= = = = = = = = = = = = = = = = = = = =
Go here to run ESET Online Scanner
(Note: You can use Internet Explorer or FireFox for this scan. If you use FireFox you will be asked to install an additional component. Please allow this.)
=========================
In your next post please provide the following:
Hi DanaF,
[external image: bullseye_zpse9eaf36e.gif] Uninstall via Programs and Features
Click Start > Control Panel > Programs and Features. Locate and select the following that are present on the list and click the Remove button:
=========================
[external image: bullseye_zpse9eaf36e.gif] Update Java
=========================
[external image: bullseye_zpse9eaf36e.gif] Adobe Flash Player:
Go to http://get.adobe.com/flashplayer/?no_ab=1
Please note, depending on your settings, you may have to temporarily disable your antivirus software for the Adobe Reader update.
=========================
[external image: bullseye_zpse9eaf36e.gif] Disk Defragmenter in Windows 7
Click on the Start button, and type in "disk defragmenter" in the search window at the bottom.
"Disk Defragmenter" should appear at the top of the search results, click to open.
(a window similar to the one below will open)
[external image: DefragMainScrn.png]
Locate your primary hard drive (usually C:), and select it.
[external image: HardDriveFragmentation.png]
Next select the Defragment Disk button. Monitor the progress if you choose.
[external image: DefragStatus.png]
Close when the defrag process has been completed.
= = = = = = = = = =
You can also Schedule the Disk Defragmenter to run on a predetermined schedule.
From the main Disk Defragmenter window
[external image: DefragMainScrn.png]
Select the Configure / Schedule button
[external image: Schedule.png]
Select a date and time that best suits your needs.
Close when finished.
=========================
In your next post please provide the following:
Hi DanaF,
Please try again by visiting here >> http://java.com/en/download/windows_xpi.jsp
You should be downloading Java Version 7 Update 65 (filesize: 897 KB)
Then continue on with the remainder of the previous steps.
Hi DanaF,
Sounds good.
I will leave the thread open until I hear back from you. Please be sure to come back as we have some final clean up steps that should be taken before I let you go for good.
Hi DanaF,
How is the computer performing?
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI