Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

White screen after logging windows 7 [Closed]


  • This topic is locked This topic is locked

#1
nateB67

nateB67

    New Member

  • Member
  • Pip
  • 5 posts
Hi, having read through this topic http://www.geekstogo...n-after-log-in/ and seeing the great advice given there I was hoping the same could be given to me as the problems appear the same.

I get a white screen after logging into Windows 7 and booting into safe mode doesn't work as the computer just restarts.

I have completed step one and got a FRST log that says:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 12-09-2013
Ran by SYSTEM on MININT-JSEC3BU on 13-09-2013 00:08:52
Running from J:\
Windows 7 Enterprise (X64) OS Language: English(US)
Internet Explorer Version 9
Boot Mode: Recovery

The current controlset is ControlSet001
ATTENTION!:=====> If the system is bootable FRST could be run from normal or Safe mode to create a complete log.

==================== Registry (Whitelisted) ==================

HKLM-x32\...\Run: [ShStatEXE] - C:\Program Files (x86)\McAfee\VirusScan Enterprise\SHSTAT.EXE [124240 2009-04-29] (McAfee, Inc.)
HKLM-x32\...\Run: [McAfeeUpdaterUI] - C:\Program Files (x86)\McAfee\Common Framework\UdaterUI.exe [136512 2009-01-22] (McAfee, Inc.)
HKLM-x32\...\Run: [F5D7050v3] - C:\Program Files (x86)\Belkin\F5D7050v3\Belkinwcui.exe [x]
HKLM-x32\...\Run: [Samsung PanelMgr] - C:\Windows\Samsung\PanelMgr\SSMMgr.exe [618496 2010-06-07] ()
HKLM-x32\...\Run: [CLX3180_Scan2Pc] - C:\Windows\Twain_32\Samsung\CLX3180\Scan2pc.exe [1990144 2011-04-28] ()
HKLM-x32\...\Run: [3180 Scan2PC] - C:\Windows\twain_32\Samsung\CLX3180\Scan2Pc.exe [1990144 2011-04-28] ()
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [35696 2009-02-27] (Adobe Systems Incorporated)
HKU\Liam Bird\...\Run: [Steam] - C:\Program Files (x86)\Games\Steam\Steam.exe [1610664 2013-03-01] (Valve Corporation)
HKU\Liam Bird\...\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] - C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe [152872 2007-06-27] (Nero AG)
HKU\Liam Bird\...\Winlogon: [Shell] explorer.exe,C:\Users\Liam Bird\AppData\Roaming\skype.dat [58880 2011-11-16] () <==== ATTENTION

==================== Services (Whitelisted) =================

S2 McAfeeEngineService; C:\Program Files (x86)\McAfee\VirusScan Enterprise\x64\engineserver.exe [19720 2009-04-29] (McAfee, Inc.)
S2 McAfeeFramework; C:\Program Files (x86)\McAfee\Common Framework\FrameworkService.exe [103744 2009-01-22] (McAfee, Inc.)
S2 McShield; C:\Program Files (x86)\McAfee\VirusScan Enterprise\x64\mcshield.exe [176872 2009-04-29] (McAfee, Inc.)
S2 McTaskManager; C:\Program Files (x86)\McAfee\VirusScan Enterprise\vstskmgr.exe [62800 2009-04-29] (McAfee, Inc.)
S2 mfevtp; C:\Windows\system32\mfevtps.exe [78992 2009-04-29] (McAfee, Inc.)
S3 NMIndexingService; C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe [279848 2007-06-27] (Nero AG)
S2 Realtek11nSU; C:\Program Files (x86)\Edimax\11n USB Wireless LAN Utility\RtlService.exe [40960 2009-12-07] (Realtek)

==================== Drivers (Whitelisted) ====================

S2 DgiVecp; C:\Windows\system32\Drivers\DgiVecp.sys [53816 2009-07-13] (Samsung Electronics Co., Ltd.)
S2 DgiVecp; C:\Windows\system32\Drivers\DgiVecp.sys [53816 2009-07-13] (Samsung Electronics Co., Ltd.)
S3 mfeapfk; C:\Windows\System32\drivers\mfeapfk.sys [97704 2009-04-29] (McAfee, Inc.)
S3 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [120096 2009-04-29] (McAfee, Inc.)
S0 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [466944 2009-04-29] (McAfee, Inc.)
S3 mferkdet; C:\Windows\System32\drivers\mferkdet.sys [76696 2009-04-29] (McAfee, Inc.)
S1 mfetdik; C:\Windows\System32\drivers\mfetdik.sys [83912 2009-04-29] (McAfee, Inc.)

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-09-13 00:08 - 2013-09-13 00:08 - 00000000 ____D C:\FRST
2013-09-12 14:39 - 2013-09-12 14:57 - 00008212 _____ C:\Windows\mfebcdata

==================== One Month Modified Files and Folders =======

2013-09-13 00:08 - 2013-09-13 00:08 - 00000000 ____D C:\FRST
2013-09-12 14:57 - 2013-09-12 14:39 - 00008212 _____ C:\Windows\mfebcdata
2013-09-12 14:57 - 2009-07-13 21:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-09-12 14:57 - 2009-07-13 20:51 - 00033257 _____ C:\Windows\setupact.log
2013-09-12 14:39 - 2013-01-09 18:03 - 00000004 _____ C:\Users\Liam Bird\AppData\Roaming\skype.ini
2013-09-12 14:39 - 2012-09-08 03:46 - 01765631 _____ C:\Windows\WindowsUpdate.log
2013-09-12 14:39 - 2009-07-13 20:45 - 00012448 ____H C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-09-12 14:39 - 2009-07-13 20:45 - 00012448 ____H C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-09-12 14:29 - 2009-07-13 21:13 - 00726316 _____ C:\Windows\System32\PerfStringBackup.INI

Files to move or delete:
====================
C:\Users\Liam Bird\177289723.exe
C:\Users\Liam Bird\297023953.exe
C:\Users\Liam Bird\AppData\Roaming\skype.dat
C:\Users\Liam Bird\AppData\Roaming\skype.ini
C:\Users\Liam Bird\AppData\Local\Temp\_is646D.exe
C:\Users\Liam Bird\AppData\Local\Temp\_is94CF.exe
C:\Users\Liam Bird\AppData\Local\Temp\_isFAF1.exe

==================== Known DLLs (Whitelisted) ================


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

==================== EXE ASSOCIATION =====================

HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK

==================== Restore Points =========================

8
Restore point made on: 2013-01-20 22:20:53
Restore point made on: 2013-01-25 02:53:12
Restore point made on: 2013-01-29 02:41:40
Restore point made on: 2013-02-01 11:59:06
Restore point made on: 2013-02-05 14:11:42
Restore point made on: 2013-02-12 16:00:18
Restore point made on: 2013-02-12 20:45:42
Restore point made on: 2013-02-13 19:00:29

==================== Memory info ===========================

Percentage of memory in use: 18%
Total physical RAM: 3069.92 MB
Available physical RAM: 2494.35 MB
Total Pagefile: 3068.07 MB
Available Pagefile: 2477.99 MB
Total Virtual: 8192 MB
Available Virtual: 8191.88 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:683.48 GB) (Free:623.88 GB) NTFS
Drive j: () (Removable) (Total:0.92 GB) (Free:0.92 GB) FAT
Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
Drive y: (System Reserved) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)]

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 699 GB) (Disk ID: 40000000)
Partition 1: (Not Active) - (Size=55 MB) - (Type=DE)
Partition 2: (Not Active) - (Size=15 GB) - (Type=07 NTFS)
Partition 3: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=683 GB) - (Type=07 NTFS)

========================================================
Disk: 4 (Size: 947 MB) (Disk ID: 00000000)
Partition 1: (Not Active) - (Size=947 MB) - (Type=06)


LastRegBack: 2013-02-12 16:23

==================== End Of Log ============================
  • 0

Advertisements


#2
Buddierdl

Buddierdl

    Trusted Helper

  • Malware Removal
  • 2,524 posts
Hello and welcome to Geeks to Go. I am sorry that you are having troubles with your computer and will try my best to help you. I know that being infected is very frustrating, but I will be here to help you through the whole process of cleaning. Removing malware can be difficult and complicated and will most likely take many steps, so please stick with me until I have declared your computer clean. I always recommend printing my instructions before following them in case you cannot keep this webpage open. Please be sure to alway follow all steps exactly as they are written and let me know what happens each time. Stop and ask if something unexpected happens or if you are unsure of how to proceed.

Please respect my volunteered time and stay with me until I declare your computer clean. If you are going to be delayed for a while, please let me know.

Please download the attached fixlist.txt to your flash drive, run FRST again, and select "Fix." Please post the fixlog.txt (will be on the flash drive.)

Then please boot normally and run FRST from normal mode and get a fresh scan for me.

Do you know these files?

C:\Users\Liam Bird\177289723.exe
C:\Users\Liam Bird\297023953.exe

Attached Files


  • 0

#3
nateB67

nateB67

    New Member

  • Topic Starter
  • Member
  • Pip
  • 5 posts
Hi Buddierdl. Thanks for your speedy reply.

With regard to those files, I do not recognise them.

fixlog:
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 12-09-2013
Ran by SYSTEM at 2013-09-13 00:29:16 Run:1
Running from J:\
Boot Mode: Recovery
==============================================

Content of fixlist:
*****************
HKU\Liam Bird\...\Winlogon: [Shell] explorer.exe,C:\Users\Liam Bird\AppData\Roaming\skype.dat [58880 2011-11-16] () <==== ATTENTION
C:\Users\Liam Bird\AppData\Roaming\skype.dat
C:\Users\Liam Bird\AppData\Roaming\skype.ini
*****************

HKU\Liam Bird\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell => Value deleted successfully.
C:\Users\Liam Bird\AppData\Roaming\skype.dat => Moved successfully.
C:\Users\Liam Bird\AppData\Roaming\skype.ini => Moved successfully.

==== End of Fixlog ====

FRST:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 12-09-2013
Ran by Liam Bird (administrator) on LIAMBIRD-PC on 13-09-2013 00:32:27
Running from I:\
Windows 7 Enterprise (X64) OS Language: English(US)
Internet Explorer Version 9
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(McAfee, Inc.) C:\Program Files (x86)\McAfee\VirusScan Enterprise\x64\engineserver.exe
(McAfee, Inc.) C:\Program Files (x86)\McAfee\Common Framework\FrameworkService.exe
(McAfee, Inc.) C:\Program Files (x86)\McAfee\VirusScan Enterprise\vstskmgr.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
(McAfee, Inc.) C:\Program Files (x86)\McAfee\Common Framework\naPrdMgr.exe
(McAfee, Inc.) C:\Windows\system32\mfevtps.exe
(Realtek) C:\Program Files (x86)\Edimax\11n USB Wireless LAN Utility\RtlService.exe
(Realtek Semiconductor Corp.) C:\Program Files (x86)\Edimax\11n USB Wireless LAN Utility\RtWlan.exe
(McAfee, Inc.) C:\Program Files (x86)\McAfee\VirusScan Enterprise\x64\mcshield.exe
(McAfee, Inc.) C:\Program Files (x86)\McAfee\VirusScan Enterprise\x64\mfeann.exe
(Nero AG) C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe
(Nero AG) C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe
(McAfee, Inc.) C:\Program Files (x86)\McAfee\VirusScan Enterprise\shstat.exe
(McAfee, Inc.) C:\Program Files (x86)\McAfee\Common Framework\UdaterUI.exe
() C:\Windows\Samsung\PanelMgr\SSMMgr.exe
() C:\Windows\twain_32\Samsung\CLX3180\Scan2Pc.exe
(Nero AG) C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
() C:\Windows\Samsung\PanelMgr\caller64.exe
(Microsoft Corporation) C:\Windows\system32\cmd.exe

==================== Registry (Whitelisted) ==================

HKCU\...\Run: [Steam] - C:\Program Files (x86)\Games\Steam\Steam.exe [1610664 2013-03-01] (Valve Corporation)
HKCU\...\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] - C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe [152872 2007-06-27] (Nero AG)
HKLM-x32\...\Run: [ShStatEXE] - C:\Program Files (x86)\McAfee\VirusScan Enterprise\SHSTAT.EXE [124240 2009-04-29] (McAfee, Inc.)
HKLM-x32\...\Run: [McAfeeUpdaterUI] - C:\Program Files (x86)\McAfee\Common Framework\UdaterUI.exe [136512 2009-01-22] (McAfee, Inc.)
HKLM-x32\...\Run: [F5D7050v3] - C:\Program Files (x86)\Belkin\F5D7050v3\Belkinwcui.exe [x]
HKLM-x32\...\Run: [Samsung PanelMgr] - C:\Windows\Samsung\PanelMgr\SSMMgr.exe [618496 2010-06-07] ()
HKLM-x32\...\Run: [CLX3180_Scan2Pc] - C:\Windows\Twain_32\Samsung\CLX3180\Scan2pc.exe [1990144 2011-04-29] ()
HKLM-x32\...\Run: [3180 Scan2PC] - C:\Windows\twain_32\Samsung\CLX3180\Scan2Pc.exe [1990144 2011-04-29] ()
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [35696 2009-02-27] (Adobe Systems Incorporated)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://uk.msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x5A7E6AC385BCCD01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-GB
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.254

==================== Services (Whitelisted) =================

R2 McAfeeEngineService; C:\Program Files (x86)\McAfee\VirusScan Enterprise\x64\engineserver.exe [19720 2009-04-29] (McAfee, Inc.)
R2 McAfeeFramework; C:\Program Files (x86)\McAfee\Common Framework\FrameworkService.exe [103744 2009-01-22] (McAfee, Inc.)
R2 McShield; C:\Program Files (x86)\McAfee\VirusScan Enterprise\x64\mcshield.exe [176872 2009-04-29] (McAfee, Inc.)
R2 McTaskManager; C:\Program Files (x86)\McAfee\VirusScan Enterprise\vstskmgr.exe [62800 2009-04-29] (McAfee, Inc.)
R2 mfevtp; C:\Windows\system32\mfevtps.exe [78992 2009-04-29] (McAfee, Inc.)
R3 NMIndexingService; C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe [279848 2007-06-27] (Nero AG)
R2 Realtek11nSU; C:\Program Files (x86)\Edimax\11n USB Wireless LAN Utility\RtlService.exe [40960 2009-12-07] (Realtek)

==================== Drivers (Whitelisted) ====================

S2 DgiVecp; C:\Windows\system32\Drivers\DgiVecp.sys [53816 2009-07-13] (Samsung Electronics Co., Ltd.)
S2 DgiVecp; C:\Windows\system32\Drivers\DgiVecp.sys [53816 2009-07-13] (Samsung Electronics Co., Ltd.)
R3 mfeapfk; C:\Windows\System32\drivers\mfeapfk.sys [97704 2009-04-29] (McAfee, Inc.)
R3 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [120096 2009-04-29] (McAfee, Inc.)
R0 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [466944 2009-04-29] (McAfee, Inc.)
S3 mferkdet; C:\Windows\System32\drivers\mferkdet.sys [76696 2009-04-29] (McAfee, Inc.)
R1 mfetdik; C:\Windows\System32\drivers\mfetdik.sys [83912 2009-04-29] (McAfee, Inc.)

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-09-13 09:08 - 2013-09-13 09:08 - 00000000 ____D C:\FRST

==================== One Month Modified Files and Folders =======

2013-09-13 09:08 - 2013-09-13 09:08 - 00000000 ____D C:\FRST
2013-09-13 00:30 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-09-13 00:30 - 2009-07-14 05:51 - 00033369 _____ C:\Windows\setupact.log
2013-09-12 23:39 - 2012-09-08 12:46 - 01766104 _____ C:\Windows\WindowsUpdate.log
2013-09-12 23:39 - 2009-07-14 05:45 - 00012448 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-09-12 23:39 - 2009-07-14 05:45 - 00012448 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-09-12 23:29 - 2009-07-14 06:13 - 00726316 _____ C:\Windows\system32\PerfStringBackup.INI

Files to move or delete:
====================
C:\Users\Liam Bird\177289723.exe
C:\Users\Liam Bird\297023953.exe
C:\Users\Liam Bird\AppData\Local\Temp\_is646D.exe
C:\Users\Liam Bird\AppData\Local\Temp\_is94CF.exe
C:\Users\Liam Bird\AppData\Local\Temp\_isFAF1.exe

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-02-13 01:23

==================== End Of Log ============================
  • 0

#4
Buddierdl

Buddierdl

    Trusted Helper

  • Malware Removal
  • 2,524 posts
Looks pretty good. Go ahead and delete these files:


C:\Users\Liam Bird\177289723.exe
C:\Users\Liam Bird\297023953.exe

Let's run a couple more scans:



Download aswMBR.exe to your desktop.
Double click the aswMBR.exe to run it Click the "Scan" button to start scan

Posted Image

On completion of the scan click save log, save it to your desktop and post in your next reply

Posted Image

Please download Malwarebytes' Anti-Malware
  • Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.
  • 0

#5
nateB67

nateB67

    New Member

  • Topic Starter
  • Member
  • Pip
  • 5 posts
aswMBR:
aswMBR version 0.9.9.1771 Copyright© 2011 AVAST Software
Run date: 2013-09-13 18:58:30
-----------------------------
18:58:30.954 OS Version: Windows x64 6.1.7600
18:58:30.954 Number of processors: 4 586 0xF0B
18:58:30.954 ComputerName: LIAMBIRD-PC UserName: Liam Bird
18:58:32.218 Initialize success
18:58:55.742 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
18:58:55.742 Disk 0 Vendor: ST375064 3.AD Size: 715404MB BusType: 8
18:58:55.836 Disk 0 MBR read successfully
18:58:55.836 Disk 0 MBR scan
18:58:55.836 Disk 0 Windows 7 default MBR code
18:58:55.836 Disk 0 Partition 1 00 DE Dell Utility Dell 8.0 54 MB offset 63
18:58:55.851 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 15360 MB offset 112640
18:58:55.867 Disk 0 Partition 3 80 (A) 07 HPFS/NTFS NTFS 100 MB offset 31569920
18:58:55.882 Disk 0 Partition 4 00 07 HPFS/NTFS NTFS 699888 MB offset 31774720
18:58:55.898 Disk 0 scanning C:\Windows\system32\drivers
18:59:23.495 Service scanning
18:59:38.315 Modules scanning
18:59:38.315 Disk 0 trace - called modules:
18:59:38.330 ntoskrnl.exe CLASSPNP.SYS disk.sys iaStorV.sys hal.dll
18:59:38.346 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa80040a6060]
18:59:38.346 3 CLASSPNP.SYS[fffff88000c3b43f] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa8002ead050]
18:59:38.361 Scan finished successfully
19:00:15.084 Disk 0 MBR has been saved successfully to "C:\Users\Liam Bird\Desktop\MBR.dat"
19:00:15.084 The log file has been saved successfully to "C:\Users\Liam Bird\Desktop\aswMBR.txt"


MBAM:
Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org

Database version: v2013.09.13.08

Windows 7 x64 NTFS
Internet Explorer 9.0.8112.16421
Liam Bird :: LIAMBIRD-PC [administrator]

13/09/2013 19:02:48
mbam-log-2013-09-13 (19-02-48).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 224894
Time elapsed: 10 minute(s), 5 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 2
C:\$Recycle.Bin\S-1-5-21-3557503935-244441103-3466798011-1000\$RADWJJH.exe (Trojan.Injector) -> Quarantined and deleted successfully.
C:\$Recycle.Bin\S-1-5-21-3557503935-244441103-3466798011-1000\$RVBJLIM.exe (Trojan.Downloader) -> Quarantined and deleted successfully.

(end)
  • 0

#6
nateB67

nateB67

    New Member

  • Topic Starter
  • Member
  • Pip
  • 5 posts
Hi Buddierdl,

Thanks for your help so far!

However, I only have access to this computer today as I am due to be deployed early tomorrow and wanted to leave it in good working order. How many steps do with have left to ensure the machine is in the clear?

I shall be checking this regularly today for any new instructions. Thanks
  • 0

#7
Buddierdl

Buddierdl

    Trusted Helper

  • Malware Removal
  • 2,524 posts
It's looking pretty good. I will be in and out today, but we should be able to get it done.

There should be an addition.txt located in the same location as FRST (I:\). Could you please post it.

Let's run one last scan for any remnants and check for updates.


Hi brober,

You're logs are looking clean. Let's sweep for remnants.

Step 1: Run SecurityCheck

Download Security Check by screen317 from here or here.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.

Step 3: Run online scan.

Run ESET Online Scanner:

Note: You can use either Internet Explorer or Mozilla FireFox for this scan. You will however need to disable your current installed Anti-Virus, how to do so can be read here.

  • Please go here then click on: Posted Image

    Note: If using Mozilla Firefox you will need to download esetsmartinstaller_enu.exe when prompted then double click on it to install.
    All of the below instructions are compatible with either Internet Explorer or Mozilla FireFox.

  • Select the option YES, I accept the Terms of Use then click on: Posted Image
  • When prompted allow the Add-On/Active X to install.
  • Make sure that the option Remove found threats is Not checked, and the option Scan archives is checked.
  • Now click on Advanced Settings and select the following:
    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
  • Now click on: Posted Image
  • The virus signature database... will begin to download. Be patient this make take some time depending on the speed of your Internet Connection.
  • When completed the Online Scan will begin automatically. The scan may take several hours.
  • Do not touch either the Mouse or keyboard during the scan otherwise it may stall.
  • When completed select Uninstall application on close if you so wish, make sure you copy the logfile first!
  • Now click on: Posted Image
  • Use notepad to open the logfile located at C:\Program Files\ESET\EsetOnlineScanner\log.txt.
  • Copy and paste that log as a reply to this topic.
Note: Do not forget to re-enable your Anti-Virus application after running the above scan!

Things I need in your next reply:
  • addition.txt
  • SecurityCheck log
  • ESET log
  • Any outstanding problems?

  • 0

#8
nateB67

nateB67

    New Member

  • Topic Starter
  • Member
  • Pip
  • 5 posts
addition.txt
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 12-09-2013
Ran by Liam Bird at 2013-09-13 00:33:37
Running from I:\
Boot Mode: Normal
==========================================================


==================== Installed Programs =======================

2007 Microsoft Office Suite Service Pack 1 (SP1) (x32)
Acrobat.com (x32 Version: 1.6.65)
Adobe AIR (x32 Version: 1.5.0.7220)
Adobe Flash Player 11 ActiveX (x32 Version: 11.5.502.149)
Adobe Flash Player 11 Plugin (x32 Version: 11.5.502.149)
Adobe Reader 9.1 (x32 Version: 9.1.0)
ASUS nVidia Driver (x32 Version: 1.00.0000)
Belkin 54Mbps Wireless Network Adapter (x32 Version: 1.00.01)
BitLord 2.2 (x32 Version: 2.2.1-151)
Cisco EAP-FAST Module (x32 Version: 2.2.14)
Cisco LEAP Module (x32 Version: 1.0.19)
Cisco PEAP Module (x32 Version: 1.1.6)
Dragon Age II (x32 Version: 1.03)
Edimax Wireless LAN Driver and Utility (x32 Version: 1.00.0142)
Maintenance Samsung CLX-3180 Series (x32)
McAfee AntiSpyware Enterprise Module (x32 Version: 8.7.0.129)
McAfee VirusScan Enterprise (x32 Version: 8.7.0)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319)
Microsoft Office Access MUI (English) 2007 (x32 Version: 12.0.6215.1000)
Microsoft Office Access Setup Metadata MUI (English) 2007 (x32 Version: 12.0.6215.1000)
Microsoft Office Excel MUI (English) 2007 (x32 Version: 12.0.6215.1000)
Microsoft Office InfoPath MUI (English) 2007 (x32 Version: 12.0.6215.1000)
Microsoft Office Office 64-bit Components 2007 (Version: 12.0.6215.1000)
Microsoft Office Outlook MUI (English) 2007 (x32 Version: 12.0.6215.1000)
Microsoft Office PowerPoint MUI (English) 2007 (x32 Version: 12.0.6215.1000)
Microsoft Office Professional Plus 2007 (x32 Version: 12.0.6215.1000)
Microsoft Office Proof (English) 2007 (x32 Version: 12.0.6213.1000)
Microsoft Office Proof (French) 2007 (x32 Version: 12.0.6213.1000)
Microsoft Office Proof (Spanish) 2007 (x32 Version: 12.0.6213.1000)
Microsoft Office Proofing (English) 2007 (x32 Version: 12.0.4518.1014)
Microsoft Office Publisher MUI (English) 2007 (x32 Version: 12.0.6215.1000)
Microsoft Office Shared 64-bit MUI (English) 2007 (Version: 12.0.6215.1000)
Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007 (Version: 12.0.6215.1000)
Microsoft Office Shared MUI (English) 2007 (x32 Version: 12.0.6215.1000)
Microsoft Office Shared Setup Metadata MUI (English) 2007 (x32 Version: 12.0.6215.1000)
Microsoft Office Word MUI (English) 2007 (x32 Version: 12.0.6215.1000)
Microsoft Save as PDF or XPS Add-in for 2007 Microsoft Office programs (x32 Version: 12.0.4518.1014)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (x32 Version: 9.0.21022)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (x32 Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219)
MSXML 4.0 SP2 (KB954430) (x32 Version: 4.20.9870.0)
MSXML 4.0 SP2 (KB973688) (x32 Version: 4.20.9876.0)
Nero 7 Ultra Edition (x32 Version: 7.03.0647)
neroxml (x32 Version: 1.0.0)
Neverwinter Nights 2 (x32 Version: 1.00.0000)
NVIDIA 3D Vision Controller Driver (x32 Version: 267.67)
NVIDIA 3D Vision Controller Driver 267.85 (Version: 267.85)
NVIDIA Control Panel 267.85 (Version: 267.85)
NVIDIA Drivers (Version: 1.4)
NVIDIA Graphics Driver 267.85 (Version: 267.85)
NVIDIA HD Audio Driver 1.2.22.1 (Version: 1.2.22.1)
NVIDIA Install Application (Version: 2.265.41.0)
NVIDIA PhysX (x32 Version: 9.10.0514)
NVIDIA PhysX System Software 9.10.0514 (Version: 9.10.0514)
Oblivion (x32 Version: 1.2.0416)
Opera 12.14 (x32 Version: 12.14.1738)
PVSonyDll (Version: 1.00.0001)
Readiris Pro 10 (x32)
Samsung Scan Assistant (x32 Version: 1.04.20.00)
SmarThru 4 (x32)
Steam (x32 Version: 1.0.0.0)
The Elder Scrolls V: Skyrim (x32)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1)
VLC media player 2.0.4 (x32 Version: 2.0.4)

==================== Restore Points =========================

21-01-2013 06:20:45 Windows 7 Service Pack 1
25-01-2013 10:52:57 Windows Update
29-01-2013 10:41:09 Windows Update
01-02-2013 19:58:34 Windows Update
05-02-2013 22:11:22 Windows Update
13-02-2013 00:00:02 Scheduled Checkpoint
13-02-2013 04:45:26 Windows Update
14-02-2013 03:00:13 Windows Update

==================== Hosts content: ==========================

2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (whitelisted) =============

Task: {044A6734-E90E-4F8F-B357-B2DC8AB3B5EC} - System32\Tasks\Microsoft\Windows\Time Synchronization\SynchronizeTime => Sc.exe start w32time task_started
Task: {272E8790-41B5-4498-BBB5-5D287E3B99B3} - System32\Tasks\Microsoft\Windows Defender\MP Scheduled Scan => c:\program files\windows defender\MpCmdRun.exe [2009-07-14] (Microsoft Corporation)
Task: {916A970F-4473-4509-9032-47FCE1C6848A} - System32\Tasks\CreateChoiceProcessTask => C:\Windows\System32\browserchoice.exe [2010-02-23] (Microsoft Corporation)
Task: {E4CD953B-61E1-42D4-99F7-A29DE3D3D974} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-02-09] (Adobe Systems Incorporated)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

==================== Loaded Modules (whitelisted) =============

2009-07-14 00:31 - 2009-07-14 02:39 - 00069120 _____ (Microsoft Corporation) C:\Windows\system32\taskhost.exe
2009-07-14 00:37 - 2009-07-14 02:39 - 00120320 _____ (Microsoft Corporation) C:\Windows\system32\Dwm.exe
2012-10-10 22:23 - 2012-10-10 22:23 - 14922600 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll
2012-09-08 13:06 - 2011-02-26 07:23 - 02870272 _____ (Microsoft Corporation) C:\Windows\Explorer.EXE
2007-06-27 20:03 - 2007-06-27 20:03 - 00152872 _____ (Nero AG) C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe
2012-09-15 17:31 - 2010-06-07 11:17 - 00618496 _____ () C:\Windows\Samsung\PanelMgr\SSMMgr.exe
2012-09-15 17:34 - 2011-04-29 08:58 - 01990144 _____ () C:\Windows\twain_32\Samsung\CLX3180\Scan2Pc.exe
2007-06-27 20:04 - 2007-06-27 20:04 - 01213736 _____ (Nero AG) C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
2012-09-15 17:31 - 2009-09-29 10:47 - 00306688 _____ () C:\Windows\Samsung\PanelMgr\caller64.exe
2009-07-14 00:34 - 2009-07-14 02:39 - 00344576 _____ (Microsoft Corporation) C:\Windows\system32\cmd.exe
2013-02-13 14:20 - 2013-01-04 04:19 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2013-09-13 00:03 - 2013-09-13 00:03 - 01949660 _____ (Farbar) I:\FRST64.exe
2007-09-26 14:30 - 2007-09-26 14:30 - 03077416 _____ (Nero AG) C:\Program Files (x86)\Common Files\Ahead\Lib\AdvrCntr2.dll
2007-06-27 20:04 - 2007-06-27 20:04 - 00059176 _____ (Nero AG) C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingServicePS.dll
2007-06-27 20:04 - 2007-06-27 20:04 - 00020776 _____ (Nero AG) C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvrPS.dll
2007-06-27 20:03 - 2007-06-27 20:03 - 02749736 _____ (Nero AG) C:\Program Files (x86)\Common Files\Ahead\Lib\NMDataServices.dll
2012-09-08 16:45 - 2009-01-22 23:20 - 00120128 _____ () C:\Program Files (x86)\McAfee\Common Framework\naXML2_71.dll
2012-09-15 17:34 - 2009-10-31 14:42 - 01384520 _____ () C:\Windows\twain_32\Samsung\CLX3180\ssole.dll
2012-09-15 17:34 - 2009-10-31 14:42 - 00081920 _____ (Samsung Electronics) C:\Windows\twain_32\Samsung\CLX3180\scantopc.dll
2007-06-27 20:04 - 2007-06-27 20:04 - 00320808 _____ (Nero AG) C:\Program Files (x86)\Common Files\Ahead\Lib\NMSQLDB.dll
2007-06-27 20:04 - 2007-06-27 20:04 - 00070952 _____ (Nero AG) C:\Program Files (x86)\Common Files\Ahead\Lib\NMLogCxx.dll
2007-06-27 20:02 - 2007-06-27 20:02 - 00742696 _____ (Nero AG) C:\Program Files (x86)\Common Files\Ahead\Lib\log4cxx.dll
2007-06-27 20:03 - 2007-06-27 20:03 - 00541992 _____ (Nero AG) C:\Program Files (x86)\Common Files\Ahead\Lib\NMCoFoundation.dll
2007-06-27 20:04 - 2007-06-27 20:04 - 00107816 _____ (Nero AG) C:\Program Files (x86)\Common Files\Ahead\Lib\NMPluginBase.dll
2007-06-27 20:04 - 2007-06-27 20:04 - 00181544 _____ (Nero AG) C:\Program Files (x86)\Common Files\Ahead\Lib\NMFullTextExtraction.dll
2007-06-27 20:04 - 2007-06-27 20:04 - 00181544 _____ (Nero AG) C:\Program Files (x86)\Common Files\Ahead\Lib\NMSearchPluginSimilarImages.dll
2007-09-21 17:16 - 2007-09-21 17:16 - 03376424 _____ (Nero AG) C:\Program Files (x86)\Common Files\Ahead\Lib\NeroIPP.dll


==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (02/17/2013 01:30:39 AM) (Source: SideBySide) (User: )
Description: Activation context generation failed for "assemblyIdentity1".Error in manifest or policy file "assemblyIdentity2" on line assemblyIdentity3.
The value "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute "version" in element "assemblyIdentity" is invalid.

Error: (02/15/2013 01:31:52 AM) (Source: SideBySide) (User: )
Description: Activation context generation failed for "assemblyIdentity1".Error in manifest or policy file "assemblyIdentity2" on line assemblyIdentity3.
The value "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute "version" in element "assemblyIdentity" is invalid.

Error: (02/14/2013 01:31:42 AM) (Source: SideBySide) (User: )
Description: Activation context generation failed for "assemblyIdentity1".Error in manifest or policy file "assemblyIdentity2" on line assemblyIdentity3.
The value "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute "version" in element "assemblyIdentity" is invalid.

Error: (02/09/2013 02:48:47 PM) (Source: SideBySide) (User: )
Description: Activation context generation failed for "assemblyIdentity1".Error in manifest or policy file "assemblyIdentity2" on line assemblyIdentity3.
The value "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute "version" in element "assemblyIdentity" is invalid.

Error: (02/09/2013 00:49:20 PM) (Source: Application Error) (User: )
Description: Faulting application name: Explorer.EXE, version: 6.1.7600.16768, time stamp: 0x4d688122
Faulting module name: ntdll.dll, version: 6.1.7600.16915, time stamp: 0x4ec4b137
Exception code: 0xc0000005
Fault offset: 0x00000000000242d0
Faulting process id: 0xa70
Faulting application start time: 0xExplorer.EXE0
Faulting application path: Explorer.EXE1
Faulting module path: Explorer.EXE2
Report Id: Explorer.EXE3

Error: (02/08/2013 01:36:29 PM) (Source: Application Hang) (User: )
Description: The program wmplayer.exe version 12.0.7600.16667 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

Process ID: 1e00

Start Time: 01ce05f64cc2a2bf

Termination Time: 60

Application Path: C:\Program Files (x86)\Windows Media Player\wmplayer.exe

Report Id: 1705f5e9-71ec-11e2-80f1-001d09264858

Error: (02/06/2013 01:31:40 AM) (Source: SideBySide) (User: )
Description: Activation context generation failed for "assemblyIdentity1".Error in manifest or policy file "assemblyIdentity2" on line assemblyIdentity3.
The value "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute "version" in element "assemblyIdentity" is invalid.

Error: (02/02/2013 01:31:55 AM) (Source: SideBySide) (User: )
Description: Activation context generation failed for "assemblyIdentity1".Error in manifest or policy file "assemblyIdentity2" on line assemblyIdentity3.
The value "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute "version" in element "assemblyIdentity" is invalid.

Error: (01/30/2013 01:31:56 AM) (Source: SideBySide) (User: )
Description: Activation context generation failed for "assemblyIdentity1".Error in manifest or policy file "assemblyIdentity2" on line assemblyIdentity3.
The value "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute "version" in element "assemblyIdentity" is invalid.

Error: (01/26/2013 01:31:50 AM) (Source: SideBySide) (User: )
Description: Activation context generation failed for "assemblyIdentity1".Error in manifest or policy file "assemblyIdentity2" on line assemblyIdentity3.
The value "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute "version" in element "assemblyIdentity" is invalid.


System errors:
=============
Error: (09/13/2013 00:30:28 AM) (Source: Service Control Manager) (User: )
Description: The DgiVecp service failed to start due to the following error:
%%20

Error: (09/13/2013 00:27:05 AM) (Source: Service Control Manager) (User: )
Description: The Network List Service service failed to start due to the following error:
%%1069

Error: (09/13/2013 00:27:05 AM) (Source: Service Control Manager) (User: )
Description: The netprofm service was unable to log on as NT AUTHORITY\LocalService with the currently configured password due to the following error:
%%1352

To ensure that the service is configured properly, use the Services snap-in in Microsoft Management Console (MMC).

Error: (09/13/2013 00:27:05 AM) (Source: Service Control Manager) (User: )
Description: The Network List Service service failed to start due to the following error:
%%1069

Error: (09/13/2013 00:27:05 AM) (Source: Service Control Manager) (User: )
Description: The netprofm service was unable to log on as NT AUTHORITY\LocalService with the currently configured password due to the following error:
%%1352

To ensure that the service is configured properly, use the Services snap-in in Microsoft Management Console (MMC).

Error: (09/13/2013 00:27:05 AM) (Source: Service Control Manager) (User: )
Description: The Network List Service service failed to start due to the following error:
%%1069

Error: (09/13/2013 00:27:05 AM) (Source: Service Control Manager) (User: )
Description: The netprofm service was unable to log on as NT AUTHORITY\LocalService with the currently configured password due to the following error:
%%1352

To ensure that the service is configured properly, use the Services snap-in in Microsoft Management Console (MMC).

Error: (09/13/2013 00:27:05 AM) (Source: Service Control Manager) (User: )
Description: The Network List Service service failed to start due to the following error:
%%1069

Error: (09/13/2013 00:27:05 AM) (Source: Service Control Manager) (User: )
Description: The netprofm service was unable to log on as NT AUTHORITY\LocalService with the currently configured password due to the following error:
%%1352

To ensure that the service is configured properly, use the Services snap-in in Microsoft Management Console (MMC).

Error: (09/13/2013 00:27:05 AM) (Source: Service Control Manager) (User: )
Description: The Network List Service service failed to start due to the following error:
%%1069


Microsoft Office Sessions:
=========================

==================== Memory info ===========================

Percentage of memory in use: 38%
Total physical RAM: 3069.92 MB
Available physical RAM: 1900.58 MB
Total Pagefile: 6137.98 MB
Available Pagefile: 4983.38 MB
Total Virtual: 8192 MB
Available Virtual: 8191.84 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:683.48 GB) (Free:623.86 GB) NTFS
Drive d: (RECOVERY) (Fixed) (Total:15 GB) (Free:10.8 GB) NTFS
Drive i: () (Removable) (Total:0.92 GB) (Free:0.92 GB) FAT

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 699 GB) (Disk ID: 40000000)
Partition 1: (Not Active) - (Size=55 MB) - (Type=DE)
Partition 2: (Not Active) - (Size=15 GB) - (Type=07 NTFS)
Partition 3: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=683 GB) - (Type=07 NTFS)

========================================================
Disk: 4 (Size: 947 MB) (Disk ID: 00000000)
Partition 1: (Not Active) - (Size=947 MB) - (Type=06)

==================== End Of Log ============================


SecurityCheck log
Results of screen317's Security Check version 0.99.73
Windows 7 x64 (UAC is enabled)
Out of date service pack!!
Internet Explorer 10
``````````````Antivirus/Firewall Check:``````````````
Windows Firewall Enabled!
WMI entry may not exist for antivirus; attempting automatic update.
`````````Anti-malware/Other Utilities Check:`````````
McAfee AntiSpyware Enterprise Module
Malwarebytes Anti-Malware version 1.75.0.1300
Adobe Flash Player 11.8.800.168
Adobe Reader 9 Adobe Reader out of Date!
````````Process Check: objlist.exe by Laurent````````
McAfee VirusScan Enterprise x64 engineserver.exe
McAfee VirusScan Enterprise vstskmgr.exe
McAfee VirusScan Enterprise x64 mcshield.exe
McAfee VirusScan Enterprise x64 mfeann.exe
McAfee VirusScan Enterprise shstat.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C: 6%
````````````````````End of Log``````````````````````


ESET log
[email protected] as CAB hook log:
OnlineScanner64.ocx - registred OK
OnlineScanner.ocx - registred OK

ESET found two problems as follows:
C:\FRST\Quarantine\skype.dat a variant of Win32/Injector.ABFD trojan
C:\Users\Liam Bird\AppData\Local\Temp\NERO13890\Toolbar.exe Win32/Toolbar.AskSBar application
  • 0

#9
Buddierdl

Buddierdl

    Trusted Helper

  • Malware Removal
  • 2,524 posts
Sorry for the delay.
Please delete this file:

C:\Users\Liam Bird\AppData\Local\Temp\NERO13890\Toolbar.exe


Also, we need to get your Windows updated to the latest service pack. Please update your computer through Windows Updates and make sure you get SP1 (you can leave off the optional updates if you wish). Let me know if it works.
  • 0

#10
Buddierdl

Buddierdl

    Trusted Helper

  • Malware Removal
  • 2,524 posts
Due to lack of feedback, this topic has been closed.

If you need this topic reopened, please contact a staff member. This applies only to the original topic starter. Everyone else please begin a New Topic.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP