Looks like the image didn't upload. Here goes again.
Unknown infection. False warning window, phantom windows. [Solved]
36 min read
And in case there's any doubt, I accessed About Firefox in the Help menu to check for updates. My Firefox is up to date. ![]()
Sorry for the storm of replies, but I was mistaken about update.exe. It's not VAIO. It's Avira.
fake Firefox update, the link below suggest a adblocker might possibly help with that.
https://support.mozilla.org/en-US/kb/i-found-fake-firefox-update
~~~~~~~~~~~~~~~~~~~~~~~~~~~
Follow the instructions in the thread below. Make sure to download the MBAR version linked in it.
https://forums.malwarebytes.com/topic/198907-requested-resource-is-in-use-error-unable-to-start-malwarebytes/
Run the scan, delete everything it finds, and then copy/paste the content of the mbar-log-DATE-(TIME).txt log that is located in the MBAR folder here after.
~~~
[external image: RQKuhw1.png]RogueKiller
- Download the right version of RogueKiller for your Windows version (32 or 64-bit)
- Once done, move the executable file to your Desktop, right-click on it and select [external image: Spcusrh.png]Run as Administrator (for Windows Vista, 7, 8, 8.1 and 10 users)
- Click on the Start Scan button in the right panel, which will bring you to another tab, and click on it again (this time it'll be in the bottom right corner)
- Wait for the scan to complete
- On completion, the results will be displayed
- This time scanning with RogueKiller, Check every single entry (threat found), and click on the Remove Selected button
- On completion, the results will be displayed. Click on the Open Report button in the bottom left corner, followed by the Open TXT button (also in the bottom left corner)
- This will open the report in Notepad. Copy/paste its content in your next reply
Please post these 2 logs when finished.
You think those blank windows were from Avira?
Didn't let that download. I use a script filter, but I guess that one got through. I'll add an ad blocker.
I hadn't considered the possibility, but I guess those windows could have been from Avira. I really have no idea. If I could figure out what process they correspond to, and be sure the process isn't malicious, they wouldn't bother me.
I ran both scans. Here are the logs.
Malwarebytes Anti-Rootkit BETA 1.10.3.1001
www.malwarebytes.org
Database version:
main: v2017.11.07.09
rootkit: v2017.10.14.01
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 11.0.9600.18816
Smash :: SIDEKICK [administrator]
11/7/2017 2:53:09 PM
mbar-log-2017-11-07 (14-53-09).txt
Scan type: Quick scan
Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken
Scan options disabled:
Objects scanned: 324513
Time elapsed: 34 minute(s), 1 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
Physical Sectors Detected: 0
(No malicious items detected)
(end)
RogueKiller V12.11.23.0 (x64) [Nov 6 2017] (Free) by Adlice Software
mail : http://www.adlice.com/contact/
Feedback : https://forum.adlice.com
Website : http://www.adlice.com/download/roguekiller/
Blog : http://www.adlice.com
Operating System : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Started in : Normal mode
User : Smash [Administrator]
Started from : C:\Users\Smash\Desktop\RogueKiller_portable64.exe
Mode : Delete – Date : 11/07/2017 15:32:10 (Duration : 01:37:50)
¤¤¤ Processes : 0 ¤¤¤
¤¤¤ Registry : 15 ¤¤¤
[PUP.OpenCandy] (X86) HKEY_LOCAL_MACHINE\Software\Unchecky -> Deleted
[PUP.OpenCandy] (X64) HKEY_USERS\.DEFAULT\Software\Unchecky -> Deleted
[PUP.OpenCandy] (X86) HKEY_USERS\.DEFAULT\Software\Unchecky -> Deleted
[PUP.OpenCandy] (X64) HKEY_USERS\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Unchecky -> Deleted
[PUP.OpenCandy] (X86) HKEY_USERS\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Unchecky -> Deleted
[PUP.OpenCandy] (X64) HKEY_USERS\S-1-5-21-4071271752-2530744919-2841666311-1001\Software\Unchecky -> Deleted
[PUP.OpenCandy] (X86) HKEY_USERS\S-1-5-21-4071271752-2530744919-2841666311-1001\Software\Unchecky -> Deleted
[PUP.OpenCandy] (X64) HKEY_USERS\S-1-5-21-4071271752-2530744919-2841666311-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Unchecky -> Deleted
[PUP.OpenCandy] (X86) HKEY_USERS\S-1-5-21-4071271752-2530744919-2841666311-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Unchecky -> Deleted
[PUP.OpenCandy] (X64) HKEY_USERS\S-1-5-18\Software\Unchecky -> Deleted
[PUP.OpenCandy] (X86) HKEY_USERS\S-1-5-18\Software\Unchecky -> Deleted
[PUP.OpenCandy] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\Unchecky -> Deleted
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{78140506-3DA9-43FC-9C03-501AECB1EB41} | DhcpNameServer : 172.20.10.1 ([]) -> Replaced ()
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Tcpip\Parameters\Interfaces\{78140506-3DA9-43FC-9C03-501AECB1EB41} | DhcpNameServer : 172.20.10.1 ([]) -> Replaced ()
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet003\Services\Tcpip\Parameters\Interfaces\{78140506-3DA9-43FC-9C03-501AECB1EB41} | DhcpNameServer : 172.20.10.1 ([]) -> Replaced ()
¤¤¤ Tasks : 0 ¤¤¤
¤¤¤ Files : 4 ¤¤¤
[PUP.OpenCandy][Folder] C:\ProgramData\Unchecky -> Removed at reboot [91]
[PUP.OpenCandy][File] C:\ProgramData\Unchecky\activity.log -> Deleted
[PUP.OpenCandy][File] C:\ProgramData\Unchecky\activity_last.log -> Deleted
[PUP.OpenCandy][File] C:\ProgramData\Unchecky\hosts_backup -> Deleted
[PUP.OpenCandy][File] C:\ProgramData\Unchecky\uclogfile.bin -> Removed at reboot [20]
[PUP.OpenCandy][Folder] C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Unchecky -> Deleted
[PUP.OpenCandy][File] C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Unchecky\Unchecky.lnk -> Deleted
[PUP.OpenCandy][File] C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Unchecky\Uninstall.lnk -> Deleted
[PUP.OpenCandy][Folder] C:\ProgramData\Unchecky -> Removed at reboot [91]
[PUP.OpenCandy][File] C:\ProgramData\Unchecky\uclogfile.bin -> Removed at reboot [20]
[PUP.OpenCandy][Folder] C:\Program Files (x86)\Unchecky -> Removed at reboot [91]
[PUP.OpenCandy][File] C:\Program Files (x86)\Unchecky\bin\inject.dll -> Deleted
[PUP.OpenCandy][File] C:\Program Files (x86)\Unchecky\bin\inject_x64.dll -> Deleted
[PUP.OpenCandy][File] C:\Program Files (x86)\Unchecky\bin\unchecky_bg.exe -> Removed at reboot [5]
[PUP.OpenCandy][File] C:\Program Files (x86)\Unchecky\bin\unchecky_svc.exe -> Removed at reboot [5]
[PUP.OpenCandy][Folder] C:\Program Files (x86)\Unchecky\bin -> Removed at reboot [91]
[PUP.OpenCandy][File] C:\Program Files (x86)\Unchecky\unchecky.exe -> Deleted
[PUP.OpenCandy][File] C:\Program Files (x86)\Unchecky\uninstall.dat -> Deleted
[PUP.OpenCandy][File] C:\Program Files (x86)\Unchecky\uninstall.exe -> Deleted
¤¤¤ WMI : 0 ¤¤¤
¤¤¤ Hosts File : 0 ¤¤¤
¤¤¤ Antirootkit : 0 (Driver: Loaded) ¤¤¤
¤¤¤ Web browsers : 0 ¤¤¤
¤¤¤ MBR Check : ¤¤¤
+++++ PhysicalDrive0: ST95005620AS +++++
— User —
[MBR] 1d4e922d500e5d4f6fc8e6307821e033
[BSP] 1b9ad0143b722a2e03ef9032e346fde9 : Windows Vista/7/8|VT.Unknown MBR Code
Partition table:
0 - [XXXXXX] ACER (0x27) [VISIBLE] Offset (sectors): 2048 | Size: 11177 MB
1 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 22892544 | Size: 100 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
2 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 23097344 | Size: 465661 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
User = LL1 … OK
User = LL2 … OK
It's possible that the extensions and addons you have on the computer work to not let it be displayed. Could also be that it's not malicious, then on the other hand could be something bad.
I feel the fake Firefox download came from the web site you were visiting and it's not uncommon for that to happen.
Does the computer run well?
I wanted to comment on something. I know it says Firefox isn't updated to run with the latest version of NoScript but, I still use it.
We can continue to run scans, not a problem or, we can use it for a day to see if something rears it's head to be identified.
You let me know.
Today the little windows came up when I connected to the internet. I was at a public area, so I started Windows first and had several programs open – Firefox, LibreOffice, iTunes, Avira – before I connected. When I did, those two little windows popped up.
I agree with you on the fake Firefox update script. It seems to come from an ad displayed on that website, and not from within my computer.
I'm glad to keep scanning. I honestly thought we had it fixed, before the restart problems took my Windows to the last known good configuration. I need to know that my machine is clean so i can do some online payments.
I wonder if it could be related to a video driver? ugh. I'm grasping at straws.
Well, I can save you some time, maybe. I updated the video driver using Device Manager and went straight to a blue screen of death. Restarted in safe mode, rolled it back. All good. I wonder if that's what caused the previous startup troubles–I had updated the video driver then, too.
Early on there were a few errors recorded coming from your first Farbar scan
I've always heard, go to the manufacturer web site to do updates for those.Faulty Device Manager Devices =============
Name: Intel® Centrino® Advanced-N + WiMAX 6250
Description: Intel® Centrino® Advanced-N + WiMAX 6250
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
Name: USB Camera
Description: USB Video Device
Class Guid: {6bdd1fc6-810f-11d0-bec7-08002be2092f}
Manufacturer: Microsoft
Service: usbvideo
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
Tell me what the computer is doing now?
Windows is running fine. I haven't seen the little phantom windows since the blue screen.
I think you're right. Vaio has an update program which I typically use (and subsequently checked). I was just trying to guess my way to a solution for the stupid little windows.
I disabled both of those devices that created those errors in the Farbar scan. The Centrino + Wimax device was Sony's failed attempt at wireless streaming from Windows to TV, an unwatchable error factory. The camera I disabled because I'm paranoid like that.
I don't remember if I did this after the scan, but both devices are fully disabled, as opposed to one just missing the driver.
It's like an internal issue?.. Don't know if we were able to put our finger on it just yet, or maybe have, but right now
Time is our friend.
Have you ever checked event viewer?
I've looked at mine a few times, not that I ever understood what it was showing me and all, but I think if you look around in there it might give a heads up that something wasn't quite right.
Event Viewer - Open and Use in Windows 7
https://www.sevenforums.com/tutorials/226084-event-viewer-open-use-windows-7-a.html
I've accessed it before, but I still feel pretty lost. I've had 1332 errors over the past 7 days, and 54 warnings. The biggest error totals were Bonjour (Apple) with 136, Dhcp-client with 29, Service Control Manager with 779 (Event ID 7023), and DistributedCOM with 315 (Event ID 10016). I googled and followed directions regarding the last two. Service Control Manager adjusted its own settings when I opened the properties. DistributedCOM is like reading a foreign language.
Hopefully it helps. Honestly, if my computer is clean of malware, I can live with the goofy little windows.
Man, Bonjour is buggy. So is Avira. So is VSS. Anyway, I've found a couple more errors I was able to address–like one that called for a larger pagefile. If you don't think I have a malware situation, I'll move forward by checking the event viewer the next time those little windows pop up. Maybe that will indicate something. And I'll run some hardware diagnostics.
Does that sound right?
Honestly, right this minute, it's working better than it has in a long time. Just moving quickly between windows and tabs, scrolling quickly, typing without lags. Hopefully this persists.
Event Viewer is just one place that stores information.
Have you ever looked into the Action Center.
I have a small white flag at the bottom of my tool bar, I click on that to open and it brings me to
Click to load external image (JLylLmF.png)
Then click on view reliability history.
Talk about reading for hours, this area of your computer will blow you out of the water but gives you info on what has happened lately.
And, another rule of thumb, if it ain't broke, don't fix it.
Ready to remove tools and quarantine folders?
Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI