This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] browser crashes, pop ups

55 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

If your GMER log is very long, it could be because you were running something when you ran the scan, or your computer was performing some sort of automatic process when the scan was run. Please run another scan using the procedure detailed in my earlier post. If you get another long log, break it down into shorter posts and post each of them individually. Your Bootlog is rather unusual, I've not seen one with so many non-started drivers before. I'm going to have to consult with my colleagues to see if any of them has an explanation as to what's happening there. I'll get back to you as soon as I can, in the meantime if you can run a new GMER and post the log please.
GMER 1.0.14.14536 - http://www.gmer.net
Rootkit scan 2009-01-25 18:32:52
Windows 5.1.2600 Service Pack 3


—- System - GMER 1.0.14 —-

SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwClose [0xEF9C9576]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateKey [0xEF9C9432]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDeleteValueKey [0xEF9C9910]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDuplicateObject [0xEF9C900A]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenKey [0xEF9C950C]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenProcess [0xEF9C8F4A]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenThread [0xEF9C8FAE]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwQueryValueKey [0xEF9C962C]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwRestoreKey [0xEF9C95EC]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwSetValueKey [0xEF9C976C]

—- User code sections - GMER 1.0.14 —-

.text C:\WINDOWS\system32\SearchIndexer.exe[2056] kernel32.dll!WriteFile 7C810E17 7 Bytes JMP 00585C0C C:\WINDOWS\system32\MSSRCH.DLL (mssrch.dll/Microsoft Corporation)

—- User IAT/EAT - GMER 1.0.14 —-

IAT C:\WINDOWS\system32\services.exe[764] @ C:\WINDOWS\system32\services.exe [ADVAPI32.dll!CreateProcessAsUserW] 00380002
IAT C:\WINDOWS\system32\services.exe[764] @ C:\WINDOWS\system32\services.exe [KERNEL32.dll!CreateProcessW] 00380000

—- Devices - GMER 1.0.14 —-

AttachedDevice \FileSystem\Ntfs \Ntfs aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\RawIp nnrnstdi.SYS (NNRNSTDI helper driver/The Nielsen Company)
AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)

—- EOF - GMER 1.0.14 —-
OK, nothing on your GMER log that's of any concern.

I'd like to have a look at another Bootlog if I can, I'd like to see if it's the same as the last one.

  • First, find and delete C:\windows\ntbtlog.txt
  • Restart your computer.
  • Just before the XP loading screen starts hit F8 as if going into safe mode.
  • From the advanced boot menu choose enable boot logging then hit enter.
  • Your computer will start up as usual, except it will create a log of its bootup processes for one time only.

Please attach the file C:\windows\ntbtlog.txt to your next post (this should prevent it being cut off by the forum post size limiter)

To attach a file.

  • Click the Add Reply button (don't use Fast Reply)
  • Scroll down to find the Attachments frame.
  • Click on the Browse button and a Window will open.
    • Navigate to the file C:\windows\ntbtlog.txt
    • Click on it to highlight it.
    • Click Open (this will close the window)
  • The file path should now be in the browse field next to the Browse button.
  • Click Add Reply
OK, that one looks much more like I'd expect, nothing untoward that I can see.

Not sure what happened with the last Bootlog, but I'm glad to see it seems to have been a temporary condition.

How's your computer running now, are you still having any problems ?
OK, well your latest logs look good, so I think we've removed any Malware that was present on your computer. Time for a little tidying up.

Let's clear out the programmes we've been using to clean up your computer, they are not suitable for general malware removal and could cause damage if used inappropriately. Besides they're updated regularly so won't be of any use against future infections
  • Double click OTMoveIt3.exe to launch the programme.
  • Click on the CleanUp! button.
  • OTMoveIt will download a list from the Internet, if your firewall or other defensive programmes alerts you, allow it access.
  • You will be prompted to allow the clean up procedure, click Yes
  • When finished exit out of OTMoveIt
  • Now delete OTMoveIt3.exe (if still present).

Delete the following files if still present
DDS.com
RSIT.exe

Next
Reset and Re-enable your System Restore to remove any infected files that have been backed up by Windows. The files in System Restore are protected to prevent any programs changing those files. This is the only way to clean these files: You will lose all previous restore points which are likely to be infected. Please note you need Administrator Access to clean the restore points.
  • Turn off System Restore.
    • On the Desktop, right-click My Computer.
    • Click Properties.
    • Click the System Restore tab.
    • Check Turn off System Restore.
    • Click Apply, and then click OK.
  • Reboot.
  • Turn ON System Restore.
    • On the Desktop, right-click My Computer.
    • Click Properties.
    • Click the System Restore tab.
    • UN-Check *Turn off System Restore*.
    • Click Apply, and then click OK.
  • NOTE: only do this once, NOT on a regular basis.

As far as I can see, your computer looks clear of infection now.

Are you still noticing any problems ?
  • If you are let me know about them.
  • If not it's time to make your computer more secure.

Before I make any recommendations, I'd like to give a simplified overview of how your defensive systems work and what you can do to protect yourself better in future.

The average home computer has approximately 64,000 ports through which it can communicate. By default these ports are open and can be used by any programme which cares to access them, either from within the computer or from without. If you were to go online with a computer in this condition you would quickly be attacked and your computer would be infected.

To prevent this you install a Firewall. A firewall will close all open ports and you then open the ones you need by setting "rules" for them according to the instructions supplied with the Firewall programme. Usually you will have ports open for your Internet Browser, your e-mail client, and the update functions for various programmes.

These "open" ports will not be fully accessible, in that they will only allow a communication if it was instigated from within your computer. Any unsolicited communications from outside are blocked.

However if you are tricked into starting the communication, then as far as your Firewall is concerned it is a legit transaction and it will open the port. So by clicking on malicious links, replying to unsolicited e-mails and attachments, and downloading from unsafe sources, you are effectively bypassing any protection your Firewall supplies.

At this point your Anti-Spyware and Anti-Virus programmes take over. The real-time-protection in these constantly scan the data stream in your open ports looking for things that match with items in the database they have within them. If they find something then they will alert you, or quarantine it, or delete it, according to the rules set within the programme.

However as you can see, if the database does not contain details of the infection that's attacking you, then your Anti-Virus or Anti-Spyware programmes will not protect you. There are new infections (or new variations of old infections) created every day, which is why it's vital to keep your programmes up to date. Even with a fully updated database though, you are still playing catchup, which is why your Firewall, Anti-Virus and Anti-Spyware programmes cannot ever give you 100% protection.

Adding more and more programmes will not give you more and more protection, it's up to you to take some responsibility for your online actions, and modify them to give your programmes the best chance of protecting you.

Be careful what you click on.

  • Don't download anything from a site you do not know and trust. Remember, there's no such thing as a free lunch, if something seems too good to be true it is. Malware purveyors love to offer out freebies as bait knowing full well that one unguarded click is all it takes.
  • Don't reply to unsolicited e-mails.
  • Don't open e-mail attachments (even from friends) without checking with the source to ensure they actually sent them.
  • Don't use P2P file sharing programmes. Even the ones that don't come bundled (and many do) are not safe. By using them you are effectively downloading from an unknown source, with all the dangers described above.


OK, so how do we set about protecting you.

You should definitely have one of each of the following programmes.
  • Firewall
  • Anti-Virus
  • Anti-Spyware
You do not need more than one of each. More than one will cause conflicts, and will not improve your security.

If you don't already have them, then these are links to lists of free programmes.
You'll increase your chances of not getting infected if you don't land on an infected website in the first place.

There are a couple of ways to do this
  • Block access to sites known to spread Malware.
  • Give you clear indication of which they are, so that you can make choices.
To block access to known bad sites we use a Hosts file.

Download HostsXpert and unzip it to your computer, somewhere where you can find it.

  • Double click on HostsXpert.exe to launch the programme.
  • Check to see if top button on left hand side says Make Writable ?
    • If it does. click on it then proceed to next instruction.
    • If not, just proceed to next instruction
  • Click on the Download button (lower left hand side)
    • Click on MVPs Hosts… button.
    • Click on Replace button.
    • Press OK in the box that pops up. (HostsXpert will now download and update your Hosts file)
  • When finished.
    • Click on File Handling button.
    • Click on Make Read Only ? to secure it against infection.
  • Exit the programme.

To give you an indication of which sites may contain bad links or suspect downloads I like to use Site Advisor.
This is a utility that can be downloaded and installed. It loads an icon to the taskbar of your browser (versions for IE and Firefox), indicating the trustworthiness of the site you are on. Green for safe, Red for suspicious. Click on the icon to access details that SiteAdvisor has about the site. It also gives the same colour indications in the results page when you do a Google search, making it easier to decide which sites are safe to visit.

Remove known vulnerabilities
  • Update your Java

    Older versions have vulnerabilities that malware can and are using to infect systems.

    Please follow these steps to remove older version Java components. This is important as it's still possible to get infected through an old install even if you're using the latest version of Java.

    Download JavaRa by Prm753 and unzip it to your desktop.

  • Double-click on JavaRa.exe to start the program.
  • Click on Remove Older Versions to remove the older versions of Java installed on your computer.
  • Click Yes when prompted.
  • When JavaRa is done, a notice will appear that a logfile has been produced.
  • Click OK.
  • The logfile will pop up.
  • Please save it to a convenient location.

This is important as it's still possible to get infected through an old install even if you're using the latest version of Java.

Now download and install Java Runtime Environment (JRE) 6 Update 11.
  • Update Windows and Internet Explorer It is essential you keep your Operating System up to date with all the latest patches. The bad guys watch for the latest exploits, as soon as Microsoft brings out a patch, the bad guys will bring out an infection to exploit that vulnerability. If you don't have all the latest patches your computer is vulnerable. Please go to the windows update site and get the critical updates.
  • Use a "secure" browser Install Internet Explorer 7 or an alternative browser like Firefox or Opera for more secure surfing.
    Please remember that there is no such thing as a totally secure browser. Your browsing habits will be the major factor in determining just how safe you are online. If you visit, Crack/Warez sites, Porn sites, or other sites of a questionable nature, you still run a severe risk of getting infected.
  • Do not use P2P file sharing programmes I'd like you to read the Guidelines for P2P Programs where it's explained why it's not a good idea to have them.

    My recommendation is you go to Control Panel > Add/Remove Programs and uninstall any P2P programs you have installed.
  • Obviously you have already taken care of some of the issues mentioned, but it is important that you read through them, and address any that you may have missed.
Here's links to a few articles which are worth reading
Everything seems to be running fine, but I'm not sure if this is related. When I rebooted my computer after the clean up with OTmoveit I got an error message that it could not identify the AC adaptor I was using?
I wouldn't think the two are related.

The CleanUp procedure with OTMI just removes a number of files and folders (if present) related to a pre-defined list of Malware removal programmes that we commonly use to remove infection.

I think it's unlikely anything related to your AC adapter would be affected.

Can you try booting up again, and see if you get the same message,

If you do, note it down and post it back here please.
I tried twice more. Here is the message. The AC Power Adapter type cannot be determined. This will prevent optimal system performance. Strike the F3 key (before the F1 or F2 key) if you do not want to see warning messages again. Strike the F1 key to continue, F2 to run the setup utility.
We're outside my area of expertise here, this does not look like a Malware related issue.

The message shown does not appear to be any of the "standard" Microsoft failure notices I'm familiar with, in as much as there's no error code or any other indication as to what the source of the fault is.

It looks more to be a hardware related problem, specific to the particular computer you're using. Does your computer's handbook give you any clues?

I think it best if you open a post in the General Hardware forum, they're more used to dealing with this kind of problem than I am and will be better able to help you with it.

Please refer them to this topic as necessary.
I think my power cord was crimped or something. I unplugged it and made sure it wasn't being pulled and I tried restarting twice without the message. So I think I am good now. Thank you for all your help!!
You're welcome, I'm happy we were able to help with your Malware problem. Glad you managed to resolve your Power Adapter problem as well. :D Keep safe, Gary
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI