
Need help, was infected
#1
Posted 11 January 2015 - 08:55 PM

#2
Posted 11 January 2015 - 11:38 PM

#3
Posted 12 January 2015 - 07:31 AM

I'll do the best I can to resolve your computer issue
Please make sure to carefully read any instruction that I give you. If you're not sure, or if something unexpected happens, don't continue Stop and ask! Never be afraid to ask questions!

The temperature issue you speak of may have caused damage to the computer and or processor.since i have been dealing with a temperature issue for a while
What is the make and model of your machine?
What is the installed operating system ?
Have you tried a system restore to stabilize the computer?
Joe
#4
Posted 12 January 2015 - 08:10 AM

.
Edited by lemod, 19 January 2015 - 01:13 AM.
#5
Posted 12 January 2015 - 08:18 AM

The temperature problem is going to have to be addressed if we can't get anywhere, some of these scans are processor intensive and may cause additional over heating thus resulting in possible more damage. Don't download anymore tools
Try doing this from regular mode, keep the Laptop elevated so air can flow under it, put books under each side.....
Please download Farbar Recovery Scan Tool and save it to your Desktop.
Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.
- Right click to run as administrator (XP users click run after receipt of Windows Security Warning - Open File). When the tool opens click Yes to disclaimer.
- Press Scan button.
- It will produce a log called FRST.txt in the same directory the tool is run from.
- Please copy and paste log back here.
- The first time the tool is run it generates another log (Addition.txt - also located in the same directory as FRST.exe/FRST64.exe). Please also paste that along with the FRST.txt into your reply.
#6
Posted 12 January 2015 - 08:24 AM

I'm off to work now, I'll be back around 4pm
Joe
#7
Posted 12 January 2015 - 04:39 PM

.
Edited by lemod, 19 January 2015 - 01:11 AM.
#8
Posted 13 January 2015 - 07:13 AM

You need to address / fix the thermal issue. I don't know what the issue is.
I do have a fix for you and that's all we should do until the overheat issue is fixed, I'm afraid more damage may occur from running scans etc.
Hello,
Error: (01/12/2015 07:09:45 AM) (Source: Microsoft-Windows-Kernel-Power) (EventID: 88) (User: )
Description: The system hibernated due to a critical thermal event.
Hibernation Hour = 2015-01-12T07:09:45.583434700Z
Thermal zone ACPI = ACPI\ThermalZone\TZ01
_HOT = 378K
Error: (01/12/2015 07:09:40 AM) (Source: Microsoft-Windows-Kernel-Power) (EventID: 88) (User: )
Description: The system hibernated due to a critical thermal event.
Hibernation Hour = 2015-01-12T07:09:40.577148300Z
Thermal zone ACPI = ACPI\ThermalZone\TZ01
_HOT = 378K
Error: (01/12/2015 07:09:35 AM) (Source: Microsoft-Windows-Kernel-Power) (EventID: 88) (User: )
Description: The system hibernated due to a critical thermal event.
Hibernation Hour = 2015-01-12T07:09:35.566861700Z
Thermal zone ACPI = ACPI\ThermalZone\TZ01
_HOT = 378K
Error: (01/12/2015 07:09:30 AM) (Source: Microsoft-Windows-Kernel-Power) (EventID: 88) (User: NT AUTHORITY)
Description: The system hibernated due to a critical thermal event.
Hibernation Hour = 2015-01-12T07:09:30.560575400Z
Thermal Zone ACPI = ACPI\ThermalZone\TZ01
_HOT = 378K
Error: (01/12/2015 07:09:25 AM) (Source: Microsoft-Windows-Kernel-Power) (EventID: 88) (User: NT AUTHORITY)
Description: The system hibernated due to a critical thermal event.
Hibernation Hour = 2015-01-12T07:09:25.552288900Z
Thermal zone ACPI = ACPI\ThermalZone\TZ01
_HOT = 378K
Error: (01/12/2015 07:09:20 AM) (Source: Microsoft-Windows-Kernel-Power) (EventID: 88) (User: )
Description: The system hibernated due to a critical thermal event.
Hibernation Hour = 2015-01-12T07:09:20.545002500Z
Thermal Zone ACPI = ACPI\ThermalZone\TZ01
_HOT = 378K
Error: (01/12/2015 07:06:01 AM) (Source: Microsoft-Windows-Kernel-Power) (EventID: 88) (User: )
Description: The system hibernated due to a critical thermal event.
Hibernation Hour = 2015-01-12T07:06:01.050952700Z
Thermal Zone ACPI = ACPI\ThermalZone\TZ01
_HOT = 378K
Error: (01/12/2015 07:05:56 AM) (Source: Microsoft-Windows-Kernel-Power) (EventID: 88) (User: )
Description: The system hibernated due to a critical thermal event.
Hibernation Hour = 2015-01-12T07:05:56.043666300Z
Thermal Zone ACPI = ACPI\ThermalZone\TZ01
_HOT = 378K
Error: (01/12/2015 07:05:51 AM) (Source: Microsoft-Windows-Kernel-Power) (EventID: 88) (User: NT AUTHORITY)
Description: The system hibernated due to a critical thermal event.
Hibernation Hour = 2015-01-12T07:05:51.036379900Z
Thermal zone ACPI = ACPI\ThermalZone\TZ01
_HOT = 378K
Error: (01/12/2015 07:05:46 AM) (Source: Microsoft-Windows-Kernel-Power) (EventID: 88) (User: NT AUTHORITY)
Description: The system hibernated due to a critical thermal event.
Hibernation Hour = 2015-01-12T07:05:46.031093600Z
Thermal zone ACPI = ACPI\ThermalZone\TZ01
_HOT = 378K
A few items to fix
NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system
Open notepad (Start =>All Programs => Accessories => Notepad).
Copy/Paste the contents of the code box below into Notepad.
start CloseProcesses: CreateRestorePoint: HKU\S-1-5-21-192838095-2953900800-1453392413-1000\...\Run: [] => [X] HKU\S-1-5-21-192838095-2953900800-1453392413-1000\...\MountPoints2: {0946f188-111f-11e0-97c3-adc07044c6bc} - F:\Install.exe HKU\S-1-5-21-192838095-2953900800-1453392413-1000\...\MountPoints2: {54998122-84ac-11e4-a4d9-60eb69493e6f} - V:\SETUP.EXE SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-192838095-2953900800-1453392413-1000 -> {E5576AE2-7B3D-4FCE-B614-04C56C3B4BF0} URL = BHO-x32: No Name -> {5C255C8A-E604-49b4-9D64-90988571CECB} -> No File Toolbar: HKU\S-1-5-21-192838095-2953900800-1453392413-1000 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File C:\Users\Lemod\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpnec4te.dll C:\Users\Lemod\AppData\Local\Temp\HPQSi.exe C:\Users\Lemod\AppData\Local\Temp\install_flash_player_ax.exe C:\Users\Lemod\AppData\Local\Temp\jre-7u45-windows-i586-iftw.exe C:\Users\Lemod\AppData\Local\Temp\NOSEventMessages.dll C:\Users\Lemod\AppData\Local\Temp\ose00000.exe C:\Users\Lemod\AppData\Local\Temp\Quarantine.exe C:\Users\Lemod\AppData\Local\Temp\SkypeSetup.exe C:\Users\Lemod\AppData\Local\Temp\sqlite3.dll CustomCLSID: HKU\S-1-5-21-192838095-2953900800-1453392413-1000_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Lemod\AppData\Roaming\Dropbox\bin\Dropbox.exe /autoplay No File AlternateDataStreams: C:\Windows:nlsPreferences AlternateDataStreams: C:\ProgramData\Temp:D1B5B4F1 AlternateDataStreams: C:\Users\Lemod\Downloads\adwcleaner_4.106.exe:BDU AlternateDataStreams: C:\Users\Lemod\Downloads\Apache_OpenOffice_4.1.1_Win_x86_install_en.exe:BDU AlternateDataStreams: C:\Users\Lemod\Downloads\cbsidlm-cbsi213-GIRDAC_PDF_to_Image_Converter-SEO-75217120.exe:BDU AlternateDataStreams: C:\Users\Lemod\Downloads\dopdf.exe:BDU AlternateDataStreams: C:\Users\Lemod\Downloads\DropboxInstaller.exe:BDU AlternateDataStreams: C:\Users\Lemod\Downloads\Firefox Setup Stub 30.0.exe:BDU AlternateDataStreams: C:\Users\Lemod\Downloads\FRST64.exe:BDU AlternateDataStreams: C:\Users\Lemod\Downloads\gbooks.exe:BDU AlternateDataStreams: C:\Users\Lemod\Downloads\Google Books Downloader Lite.exe:BDU AlternateDataStreams: C:\Users\Lemod\Downloads\install_flash_player.exe:BDU AlternateDataStreams: C:\Users\Lemod\Downloads\my_downloader_installer.exe:BDU AlternateDataStreams: C:\Users\Lemod\Downloads\nitro_pro9.exe:BDU AlternateDataStreams: C:\Users\Lemod\Downloads\nitro_pro92.exe:BDU AlternateDataStreams: C:\Users\Lemod\Downloads\novapdf.exe:BDU AlternateDataStreams: C:\Users\Lemod\Downloads\OTL.com:BDU AlternateDataStreams: C:\Users\Lemod\Downloads\OTL.exe:BDU AlternateDataStreams: C:\Users\Lemod\Downloads\OTL.scr:BDU AlternateDataStreams: C:\Users\Lemod\Downloads\pdf-editor_setup_full1140.exe:BDU AlternateDataStreams: C:\Users\Lemod\Downloads\PDFill.exe:BDU AlternateDataStreams: C:\Users\Lemod\Downloads\pidgin-2.10.9.exe:BDU AlternateDataStreams: C:\Users\Lemod\Downloads\ProfessionalPlus.exe:BDU AlternateDataStreams: C:\Users\Lemod\Downloads\QuickTimeInstaller.exe:BDU AlternateDataStreams: C:\Users\Lemod\Downloads\ScanNowUPnP.exe:BDU AlternateDataStreams: C:\Users\Lemod\Downloads\Shockwave_Installer_Slim.exe:BDU AlternateDataStreams: C:\Users\Lemod\Downloads\SkypeSetup.exe:BDU AlternateDataStreams: C:\Users\Lemod\Downloads\vtexplorer.exe:BDU AlternateDataStreams: C:\Users\Lemod\Downloads\WinCDEmu-3.6.exe:BDU CMD: ipconfig /flushdns hosts: Emptytemp: reboot: endClick Format and ensure Wordwrap is unchecked.
Save as Fixlist.txt to your Desktop (Must be in this location)
Run FRST/FRST64 and press the Fix button just once and wait.
If the tool needed a restart please make sure you let the system to restart normally and let the tool completes its run after restart.
The tool will make a log on the Desktop (Fixlog.txt). Please post it to your reply.
Note: If the tool warns you about the version you're using being an outdated version please download and run the updated version.
#9
Posted 13 January 2015 - 05:57 PM

.
Edited by lemod, 19 January 2015 - 01:14 AM.
#10
Posted 13 January 2015 - 07:56 PM

Can you do this next,
A few items to fix
NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system
Open notepad (Start =>All Programs => Accessories => Notepad).
Copy/Paste the contents of the code box below into Notepad.
start CloseProcesses: CreateRestorePoint: HKU\S-1-5-21-192838095-2953900800-1453392413-1000\...\Run: [] => [X] HKU\S-1-5-21-192838095-2953900800-1453392413-1000\...\MountPoints2: {0946f188-111f-11e0-97c3-adc07044c6bc} - F:\Install.exe HKU\S-1-5-21-192838095-2953900800-1453392413-1000\...\MountPoints2: {54998122-84ac-11e4-a4d9-60eb69493e6f} - V:\SETUP.EXE SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-192838095-2953900800-1453392413-1000 -> {E5576AE2-7B3D-4FCE-B614-04C56C3B4BF0} URL = BHO-x32: No Name -> {5C255C8A-E604-49b4-9D64-90988571CECB} -> No File Toolbar: HKU\S-1-5-21-192838095-2953900800-1453392413-1000 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File C:\Users\Lemod\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpnec4te.dll C:\Users\Lemod\AppData\Local\Temp\HPQSi.exe C:\Users\Lemod\AppData\Local\Temp\install_flash_player_ax.exe C:\Users\Lemod\AppData\Local\Temp\jre-7u45-windows-i586-iftw.exe C:\Users\Lemod\AppData\Local\Temp\NOSEventMessages.dll C:\Users\Lemod\AppData\Local\Temp\ose00000.exe C:\Users\Lemod\AppData\Local\Temp\Quarantine.exe C:\Users\Lemod\AppData\Local\Temp\SkypeSetup.exe C:\Users\Lemod\AppData\Local\Temp\sqlite3.dll CustomCLSID: HKU\S-1-5-21-192838095-2953900800-1453392413-1000_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Lemod\AppData\Roaming\Dropbox\bin\Dropbox.exe /autoplay No File AlternateDataStreams: C:\Windows:nlsPreferences AlternateDataStreams: C:\ProgramData\Temp:D1B5B4F1 AlternateDataStreams: C:\Users\Lemod\Downloads\adwcleaner_4.106.exe:BDU AlternateDataStreams: C:\Users\Lemod\Downloads\Apache_OpenOffice_4.1.1_Win_x86_install_en.exe:BDU AlternateDataStreams: C:\Users\Lemod\Downloads\cbsidlm-cbsi213-GIRDAC_PDF_to_Image_Converter-SEO-75217120.exe:BDU AlternateDataStreams: C:\Users\Lemod\Downloads\dopdf.exe:BDU AlternateDataStreams: C:\Users\Lemod\Downloads\DropboxInstaller.exe:BDU AlternateDataStreams: C:\Users\Lemod\Downloads\Firefox Setup Stub 30.0.exe:BDU AlternateDataStreams: C:\Users\Lemod\Downloads\FRST64.exe:BDU AlternateDataStreams: C:\Users\Lemod\Downloads\gbooks.exe:BDU AlternateDataStreams: C:\Users\Lemod\Downloads\Google Books Downloader Lite.exe:BDU AlternateDataStreams: C:\Users\Lemod\Downloads\install_flash_player.exe:BDU AlternateDataStreams: C:\Users\Lemod\Downloads\my_downloader_installer.exe:BDU AlternateDataStreams: C:\Users\Lemod\Downloads\nitro_pro9.exe:BDU AlternateDataStreams: C:\Users\Lemod\Downloads\nitro_pro92.exe:BDU AlternateDataStreams: C:\Users\Lemod\Downloads\novapdf.exe:BDU AlternateDataStreams: C:\Users\Lemod\Downloads\OTL.com:BDU AlternateDataStreams: C:\Users\Lemod\Downloads\OTL.exe:BDU AlternateDataStreams: C:\Users\Lemod\Downloads\OTL.scr:BDU AlternateDataStreams: C:\Users\Lemod\Downloads\pdf-editor_setup_full1140.exe:BDU AlternateDataStreams: C:\Users\Lemod\Downloads\PDFill.exe:BDU AlternateDataStreams: C:\Users\Lemod\Downloads\pidgin-2.10.9.exe:BDU AlternateDataStreams: C:\Users\Lemod\Downloads\ProfessionalPlus.exe:BDU AlternateDataStreams: C:\Users\Lemod\Downloads\QuickTimeInstaller.exe:BDU AlternateDataStreams: C:\Users\Lemod\Downloads\ScanNowUPnP.exe:BDU AlternateDataStreams: C:\Users\Lemod\Downloads\Shockwave_Installer_Slim.exe:BDU AlternateDataStreams: C:\Users\Lemod\Downloads\SkypeSetup.exe:BDU AlternateDataStreams: C:\Users\Lemod\Downloads\vtexplorer.exe:BDU AlternateDataStreams: C:\Users\Lemod\Downloads\WinCDEmu-3.6.exe:BDU CMD: ipconfig /flushdns hosts: Emptytemp: reboot: endClick Format and ensure Wordwrap is unchecked.
Save as Fixlist.txt to your Desktop (Must be in this location)
Run FRST/FRST64 and press the Fix button just once and wait.
If the tool needed a restart please make sure you let the system to restart normally and let the tool completes its run after restart.
The tool will make a log on the Desktop (Fixlog.txt). Please post it to your reply.
Note: If the tool warns you about the version you're using being an outdated version please download and run the updated version.
Post the Fixlog.txt
Thanks
Joe

#11
Posted 13 January 2015 - 10:31 PM

.
Edited by lemod, 19 January 2015 - 01:14 AM.
#12
Posted 14 January 2015 - 12:21 AM

.
Edited by lemod, 19 January 2015 - 01:15 AM.
#13
Posted 14 January 2015 - 11:43 AM

.
Edited by lemod, 19 January 2015 - 01:12 AM.
#14
Posted 15 January 2015 - 04:31 PM

Lemod I'll be with you as soon as possible, I was unable to be the internet yesterday so I am way behind.
#15
Posted 15 January 2015 - 05:12 PM

.
Edited by lemod, 19 January 2015 - 01:15 AM.
Similar Topics
0 user(s) are reading this topic
0 members, 0 guests, 0 anonymous users
As Featured On:






