Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Windows Process Manager 32 bit Virus, Maybe More


  • Please log in to reply

#106
Kirballer

Kirballer

    Member

  • Topic Starter
  • Member
  • PipPip
  • 63 posts

My laptop is running much better already. The Windows Process Manager (32 bit) is no longer using memory or cpu space. :thumbsup:

 

There are a couple things I'd like to ask about, but after you've finished looking over everything in case you answer my questions along the way.


  • 0

Advertisements


#107
Gary R

Gary R

    Trusted Helper

  • Malware Removal
  • 136 posts

I see you didn't uninstall uTorrent as I asked you to ....
 

µTorrent (HKU\S-1-5-21-2127724220-2420722970-824995399-1001\...\uTorrent) (Version: 3.5.0.44090 - BitTorrent Inc.)


I strongly advise you to unistall this program.

Use of torrent programs is one of the prime ways that people get infected. By using a torrent you are bypassing the protection provided by your firewall and AV, so it is not surprising that malware purveyors use torrents as their delivery method of preferance. A great many torrent downloads contain things other than what you expect, and in the 14 years or so that I've been helping people on this and other forums, the vast majority of people I've helped, have had torrent programs installed.

It's not coincidental.

If you choose to uninstall uTorrent, and once again I strongly advise that you do ..... reboot your computer once it's uninstalled.

Next ....

Surprise, surprise, there's some orphans left from the programs you've just uninstalled. So let's get rid of them .....
 

  • Start FRST and when it opens ....
  • Press Ctrl+y (Ctrl and y keys at the same time)
  • A blank notepad file named fixlist.txt will open.
  • Copy and paste the following into it (don't include Code: Select all) ....
ShortcutTarget: Registry Updater.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (No File)
Startup: C:\Users\Kirby\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Registry Updater.lnk [2018-01-05]
R1 ZAM_Guard; C:\WINDOWS\System32\drivers\zamguard64.sys [203680 2018-01-15] (Zemana Ltd.)
C:\WINDOWS\System32\drivers\zamguard64.sys
S3 MBAMWebProtection; \SystemRoot\system32\DRIVERS\mwac.sys [X]
C:\Windows\system32\DRIVERS\mwac.sys
S1 ZAM; \??\C:\WINDOWS\System32\drivers\zam64.sys [X]
C:\WINDOWS\System32\drivers\zam64.sys
2018-01-17 00:37 - 2018-01-17 00:39 - 000031380 _____ C:\WINDOWS\ZAM_Guard.krnl.trace
2018-01-16 16:33 - 2018-01-17 00:30 - 000183077 _____ C:\WINDOWS\ZAM.krnl.trace
2018-01-15 01:36 - 2018-01-15 01:36 - 000055232 _____ C:\WINDOWS\system32\Drivers\hitmanpro37.sys
2018-01-15 01:35 - 2018-01-15 01:59 - 000000000 ____D C:\ProgramData\HitmanPro
2018-01-15 00:51 - 2018-01-17 00:32 - 000000000 ____D C:\Program Files (x86)\Zemana AntiMalware
2018-01-15 00:51 - 2018-01-15 00:51 - 000203680 _____ (Zemana Ltd.) C:\WINDOWS\system32\Drivers\zamguard64.sys
2018-01-15 00:50 - 2018-01-15 00:50 - 000000000 ____D C:\Users\Kirby\AppData\Local\Zemana
2018-01-13 13:32 - 2018-01-13 13:32 - 000000000 ____D C:\Users\Kirby\AppData\Local\ESET
2018-01-11 11:22 - 2018-01-11 11:40 - 000000000 ____D C:\Users\Kirby\Desktop\mbar
2018-01-11 11:21 - 2018-01-11 11:22 - 014178840 _____ (Malwarebytes Corp.) C:\Users\Kirby\Desktop\mbar-1.10.3.1001.exe
2018-01-07 22:50 - 2018-01-07 22:50 - 000255928 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\3131252F.sys
2018-01-07 22:48 - 2018-01-07 22:48 - 000255928 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\5355870F.sys
2018-01-07 22:18 - 2018-01-17 00:30 - 000000000 ____D C:\ProgramData\Malwarebytes
2018-01-07 22:18 - 2018-01-07 22:18 - 000255928 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\2E740B26.sys
2018-01-07 22:15 - 2018-01-11 11:40 - 000000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
CustomCLSID: HKU\S-1-5-21-2127724220-2420722970-824995399-1001_Classes\CLSID\{c31ca596-532d-a36f-e223-ce16b9ac70a56}\InprocServer32 -> 0xA05E04E4A077D2013B2205E4A077D201010000000100000000000000 => No File
MSCONFIG\Services: DellDataVault => 2
MSCONFIG\Services: DellDataVaultWiz => 2
MSCONFIG\Services: gupdate => 2
MSCONFIG\Services: gupdatem => 3
MSCONFIG\Services: HomeNetSvc => 2
MSCONFIG\Services: McBootDelayStartSvc => 2
MSCONFIG\Services: McNaiAnn => 2
MSCONFIG\Services: McODS => 3
MSCONFIG\Services: mcpltsvc => 2
MSCONFIG\Services: McProxy => 2
MSCONFIG\Services: MSK80Service => 3
MSCONFIG\Services: NvStreamNetworkSvc => 3
MSCONFIG\Services: nvsvc => 2
MSCONFIG\Services: Stereo Service => 2
HKU\S-1-5-21-2127724220-2420722970-824995399-1001\...\StartupApproved\Run: => "BlueStacks Agent"
HKU\S-1-5-21-2127724220-2420722970-824995399-1001\...\StartupApproved\Run: => "iFunBox"
DeleteQuarantine:
  • Press Ctrl+s to save fixlist.txt

NOTICE: This script was written specifically for this user. Running it on another machine may cause damage to your operating system


  • Now press the Fix button once and wait.
  • FRST will process fixlist.txt
  • When finished, it will produce a log fixlog.txt in the same folder/directory as FRST64.exe
  • Please post me the log

 

 


  • 0

#108
Kirballer

Kirballer

    Member

  • Topic Starter
  • Member
  • PipPip
  • 63 posts
Interesting, I did uninstall it but it still says its there? Ill try again. I wont be able to reply with anything else until later this afternoon my time. Ill let you know then.
  • 0

#109
Gary R

Gary R

    Trusted Helper

  • Malware Removal
  • 136 posts

If you've uninstalled it, then the log entry is probably just an orphan, and we can deal with it (and any other uTorrent orphans) once you've run the FRST fix in my last post.

 

Talk to you again once you've run the fix. 


  • 0

#110
Kirballer

Kirballer

    Member

  • Topic Starter
  • Member
  • PipPip
  • 63 posts

I had enough extra time to run the fix this morning:

 

Fix result of Farbar Recovery Scan Tool (x64) Version: 17.01.2018
Ran by Kirby (17-01-2018 06:51:06) Run:10
Running from C:\Users\Kirby\Desktop
Loaded Profiles: Kirby (Available Profiles: Kirby)
Boot Mode: Normal
==============================================

fixlist content:
*****************
ShortcutTarget: Registry Updater.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (No File)
Startup: C:\Users\Kirby\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Registry Updater.lnk [2018-01-05]
R1 ZAM_Guard; C:\WINDOWS\System32\drivers\zamguard64.sys [203680 2018-01-15] (Zemana Ltd.)
C:\WINDOWS\System32\drivers\zamguard64.sys
S3 MBAMWebProtection; \SystemRoot\system32\DRIVERS\mwac.sys [X]
C:\Windows\system32\DRIVERS\mwac.sys
S1 ZAM; \??\C:\WINDOWS\System32\drivers\zam64.sys [X]
C:\WINDOWS\System32\drivers\zam64.sys
2018-01-17 00:37 - 2018-01-17 00:39 - 000031380 _____ C:\WINDOWS\ZAM_Guard.krnl.trace
2018-01-16 16:33 - 2018-01-17 00:30 - 000183077 _____ C:\WINDOWS\ZAM.krnl.trace
2018-01-15 01:36 - 2018-01-15 01:36 - 000055232 _____ C:\WINDOWS\system32\Drivers\hitmanpro37.sys
2018-01-15 01:35 - 2018-01-15 01:59 - 000000000 ____D C:\ProgramData\HitmanPro
2018-01-15 00:51 - 2018-01-17 00:32 - 000000000 ____D C:\Program Files (x86)\Zemana AntiMalware
2018-01-15 00:51 - 2018-01-15 00:51 - 000203680 _____ (Zemana Ltd.) C:\WINDOWS\system32\Drivers\zamguard64.sys
2018-01-15 00:50 - 2018-01-15 00:50 - 000000000 ____D C:\Users\Kirby\AppData\Local\Zemana
2018-01-13 13:32 - 2018-01-13 13:32 - 000000000 ____D C:\Users\Kirby\AppData\Local\ESET
2018-01-11 11:22 - 2018-01-11 11:40 - 000000000 ____D C:\Users\Kirby\Desktop\mbar
2018-01-11 11:21 - 2018-01-11 11:22 - 014178840 _____ (Malwarebytes Corp.) C:\Users\Kirby\Desktop\mbar-1.10.3.1001.exe
2018-01-07 22:50 - 2018-01-07 22:50 - 000255928 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\3131252F.sys
2018-01-07 22:48 - 2018-01-07 22:48 - 000255928 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\5355870F.sys
2018-01-07 22:18 - 2018-01-17 00:30 - 000000000 ____D C:\ProgramData\Malwarebytes
2018-01-07 22:18 - 2018-01-07 22:18 - 000255928 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\2E740B26.sys
2018-01-07 22:15 - 2018-01-11 11:40 - 000000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
CustomCLSID: HKU\S-1-5-21-2127724220-2420722970-824995399-1001_Classes\CLSID\{c31ca596-532d-a36f-e223-ce16b9ac70a56}\InprocServer32 -> 0xA05E04E4A077D2013B2205E4A077D201010000000100000000000000 => No File
MSCONFIG\Services: DellDataVault => 2
MSCONFIG\Services: DellDataVaultWiz => 2
MSCONFIG\Services: gupdate => 2
MSCONFIG\Services: gupdatem => 3
MSCONFIG\Services: HomeNetSvc => 2
MSCONFIG\Services: McBootDelayStartSvc => 2
MSCONFIG\Services: McNaiAnn => 2
MSCONFIG\Services: McODS => 3
MSCONFIG\Services: mcpltsvc => 2
MSCONFIG\Services: McProxy => 2
MSCONFIG\Services: MSK80Service => 3
MSCONFIG\Services: NvStreamNetworkSvc => 3
MSCONFIG\Services: nvsvc => 2
MSCONFIG\Services: Stereo Service => 2
HKU\S-1-5-21-2127724220-2420722970-824995399-1001\...\StartupApproved\Run: => "BlueStacks Agent"
HKU\S-1-5-21-2127724220-2420722970-824995399-1001\...\StartupApproved\Run: => "iFunBox"
DeleteQuarantine:
*****************

"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" => not found
C:\Users\Kirby\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Registry Updater.lnk => moved successfully
ZAM_Guard => Unable to stop service.
"HKLM\System\CurrentControlSet\Services\ZAM_Guard" => removed successfully
ZAM_Guard => service removed successfully
C:\WINDOWS\System32\drivers\zamguard64.sys => moved successfully
"HKLM\System\CurrentControlSet\Services\MBAMWebProtection" => removed successfully
MBAMWebProtection => service removed successfully
"C:\Windows\system32\DRIVERS\mwac.sys" => not found
"HKLM\System\CurrentControlSet\Services\ZAM" => removed successfully
ZAM => service removed successfully
"C:\WINDOWS\System32\drivers\zam64.sys" => not found
C:\WINDOWS\ZAM_Guard.krnl.trace => moved successfully
C:\WINDOWS\ZAM.krnl.trace => moved successfully
C:\WINDOWS\system32\Drivers\hitmanpro37.sys => moved successfully
C:\ProgramData\HitmanPro => moved successfully
C:\Program Files (x86)\Zemana AntiMalware => moved successfully
"C:\WINDOWS\system32\Drivers\zamguard64.sys" => not found
C:\Users\Kirby\AppData\Local\Zemana => moved successfully
C:\Users\Kirby\AppData\Local\ESET => moved successfully
C:\Users\Kirby\Desktop\mbar => moved successfully
C:\Users\Kirby\Desktop\mbar-1.10.3.1001.exe => moved successfully
C:\WINDOWS\system32\Drivers\3131252F.sys => moved successfully
C:\WINDOWS\system32\Drivers\5355870F.sys => moved successfully
C:\ProgramData\Malwarebytes => moved successfully
C:\WINDOWS\system32\Drivers\2E740B26.sys => moved successfully
C:\ProgramData\Malwarebytes' Anti-Malware (portable) => moved successfully
"HKU\S-1-5-21-2127724220-2420722970-824995399-1001_Classes\CLSID\{c31ca596-532d-a36f-e223-ce16b9ac70a56}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\DellDataVault" => removed successfully
HKLM\System\CurrentControlSet\Services\DellDataVault => key not found
"HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\DellDataVaultWiz" => removed successfully
HKLM\System\CurrentControlSet\Services\DellDataVaultWiz => key not found
"HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\gupdate" => removed successfully
HKLM\System\CurrentControlSet\Services\gupdate => key not found
"HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\gupdatem" => removed successfully
HKLM\System\CurrentControlSet\Services\gupdatem => key not found
"HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\HomeNetSvc" => removed successfully
"HKLM\System\CurrentControlSet\Services\HomeNetSvc" => not found
"HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\McBootDelayStartSvc" => removed successfully
"HKLM\System\CurrentControlSet\Services\McBootDelayStartSvc" => not found
"HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\McNaiAnn" => removed successfully
"HKLM\System\CurrentControlSet\Services\McNaiAnn" => not found
"HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\McODS" => removed successfully
"HKLM\System\CurrentControlSet\Services\McODS" => not found
"HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\mcpltsvc" => removed successfully
"HKLM\System\CurrentControlSet\Services\mcpltsvc" => not found
"HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\McProxy" => removed successfully
"HKLM\System\CurrentControlSet\Services\McProxy" => not found
"HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\MSK80Service" => removed successfully
"HKLM\System\CurrentControlSet\Services\MSK80Service" => not found
"HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\NvStreamNetworkSvc" => removed successfully
HKLM\System\CurrentControlSet\Services\NvStreamNetworkSvc => key not found
"HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\nvsvc" => removed successfully
HKLM\System\CurrentControlSet\Services\nvsvc => key not found
"HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\Stereo Service" => removed successfully
HKLM\System\CurrentControlSet\Services\Stereo Service => key not found
"HKU\S-1-5-21-2127724220-2420722970-824995399-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run\\BlueStacks Agent" => removed successfully
"HKU\S-1-5-21-2127724220-2420722970-824995399-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\BlueStacks Agent" => not found
"HKU\S-1-5-21-2127724220-2420722970-824995399-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run\\iFunBox" => removed successfully
"HKU\S-1-5-21-2127724220-2420722970-824995399-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\iFunBox" => not found
could not remove "C:\FRST\Quarantine\C\WINDOWS\system32\Drivers\zamguard64.sys.xBAD" => Scheduled to remove on reboot.
could not remove "C:\FRST\Quarantine" => Scheduled to remove on reboot.
"C:\FRST\Quarantine" => could not remove

Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 17-01-2018 06:54:50)

"C:\FRST\Quarantine\C\WINDOWS\system32\Drivers\zamguard64.sys.xBAD" => removed successfully
"C:\FRST\Quarantine" => removed successfully

==== End of Fixlog 06:54:50 ====


  • 0

#111
Gary R

Gary R

    Trusted Helper

  • Malware Removal
  • 136 posts

OK, now let's see if we can find the uTorrent orphans so that we can remove them.

  • Double click Frst64.exe to launch it.
  • FRST will start to run.
  • When the tool opens click Yes to the disclaimer.
  • Copy/Paste or Type the following line into the Search: box.

SearchAll:µTorrent;utorrent;torrent

  • Press the Search Files button.
  • When finished searching a log will open on your Desktop ... Search.txt
  • Please post it in your next reply.



 
  • 0






Similar Topics

1 user(s) are reading this topic

1 members, 0 guests, 0 anonymous users


    Kirballer

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP