Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Virus-filling hard drive, blocks updates etc.


  • Please log in to reply
10 replies to this topic

#1 Werval1

Werval1

  • Members
  • 24 posts
  • OFFLINE
  •  
  • Local time:08:16 AM

Posted 23 September 2013 - 10:35 AM

Hi All,

 

I've been working to fix a bug in an ASUS netbook. It's running Windows XP SP3. This machine is not equipped with a CD/DVD drive, but it does have USB ports.

 

None of the following have helped, and at times, the programs disappear from view. Avast, Avira, Malwarebytes, House Call, ESET, Kaspersky, TDSS Killer, HiJack This, MRT, Prevx, RKill, Stinger, Bitdefender.

 

When I ran aswMBR, it produced  "suspicious" notations regarding "dxgthk.sys" and "ntdll.dll".

 

I do have scan results from OTL, if that would help anyone to help with this situation.

 

Thanks!

 



BC AdBot (Login to Remove)

 


#2 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,416 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:10:16 AM

Posted 23 September 2013 - 10:56 AM

Hello Werval, lets see how it is after these.
 
Please download MiniToolBox, save it to your desktop and run it.
Checkmark the following checkboxes:
  • Flush DNS
  • Report IE Proxy Settings
  • Reset IE Proxy Settings
  • Report FF Proxy Settings
  • Reset FF Proxy Settings
  • List content of Hosts
  • List IP configuration
  • List Winsock Entries
  • List last 10 Event Viewer log
  • List Installed Programs
  • List Users, Partitions and Memory size.
Click Go and post the result (Result.txt). A copy of Result.txt will be saved in the same directory the tool is run.
Note: When using "Reset FF Proxy Settings" option Firefox should be closed.
 
 
 
Download TDSSKiller and save it to your desktop.
  • Extract (unzip) its contents to your desktop.
  • Open the TDSSKiller folder and doubleclick on TDSSKiller.exe to run the application, then on Start Scan.
  • If an infected file is detected, the default action will be Cure, click on Continue.
  • If a suspicious file is detected, the default action will be Skip, click on Continue.
  • It may ask you to reboot the computer to complete the process. Click on Reboot Now.
  • If no reboot is require, click on Report. A log file should appear. Please copy and paste the contents of that file here.
  • If a reboot is required, the report can also be found in your root directory (usually C:\ folder) in the form of TDSSKiller_xxxx_log.txt. Please copy and paste the contents of that file here.
.
.
.
Please download AdwCleaner by Xplode and save to your Desktop.
  • Double click on AdwCleaner.exe to run the tool. Vista/Windows 7/8 users right-click and select Run As Administrator
.
  • Click on the Scan button.
  • AdwCleaner will begin...be patient as the scan may take some time to complete.
  • After the scan has finished, click on the Report button...a logfile (AdwCleaner[R0].txt) will open in Notepad for review.
  • The contents of the log file may be confusing. Unless you see a program name that you know should not be removed, don't worry about it. If you see an entry you want to keep, let me know about it.
  • Copy and paste the contents of that logfile in your next reply.
  • A copy of all logfiles are saved in the C:\AdwCleaner folder which was created when running the tool.
  • >>>
  • Last run ESET.
    • Hold down Control and click on this link to open ESET OnlineScan in a new window.
    • Click the esetonlinebtn.png button.
    • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on esetsmartinstaller_enu.exe to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the esetsmartinstaller_enu.png icon on your desktop.
    • Check "YES, I accept the Terms of Use."
    • Click the Start button.
    • Accept any security warnings from your browser.
    • Under scan settings, check "Scan Archives" and "Remove found threats"
    • Click Advanced settings and select the following:
    • Scan potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth technology
    • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
    • When the scan completes, click List Threats
    • Click Export, and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
    • Click the Back button.
    • Click the Finish button.
    • NOTE:Sometimes if ESET finds no infections it will not create a log.

How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#3 Werval1

Werval1
  • Topic Starter

  • Members
  • 24 posts
  • OFFLINE
  •  
  • Local time:08:16 AM

Posted 23 September 2013 - 12:34 PM

Thank you boopme for your fast reply!

 

MiniToolBox by Farbar  Version: 13-07-2013
Ran by Ellen Smith (administrator) on 23-09-2013 at 11:05:08
Running from "C:\Documents and Settings\Ellen Smith\My Documents\Downloads"
Microsoft Windows XP Home Edition Service Pack 3 (X86)
Boot Mode: Normal
***************************************************************************
 
========================= Flush DNS: ===================================
 
 
Windows IP Configuration
 
 
 
Successfully flushed the DNS Resolver Cache.
 
 
========================= IE Proxy Settings: ============================== 
 
Proxy is not enabled.
No Proxy Server is set.
 
"Reset IE Proxy Settings": IE Proxy Settings were reset.
========================= Hosts content: =================================
 
 
127.0.0.1       localhost
 
========================= IP Configuration: ================================
 
Atheros AR5007EG Wireless Network Adapter = Wireless Network Connection (Connected)
Atheros L2 Fast Ethernet 10/100 Base-T Controller = Local Area Connection (Media disconnected)
 
 
# ---------------------------------- 
# Interface IP Configuration         
# ---------------------------------- 
pushd interface ip
 
 
# Interface IP Configuration for "Local Area Connection"
 
set address name="Local Area Connection" source=dhcp 
set dns name="Local Area Connection" source=dhcp register=PRIMARY
set wins name="Local Area Connection" source=dhcp
 
# Interface IP Configuration for "Wireless Network Connection"
 
set address name="Wireless Network Connection" source=dhcp 
set dns name="Wireless Network Connection" source=dhcp register=PRIMARY
set wins name="Wireless Network Connection" source=dhcp
 
 
popd
# End of interface IP configuration
 
 
 
 
Windows IP Configuration
 
 
 
        Host Name . . . . . . . . . . . . : YOUR-1UT28O6MCF
 
        Primary Dns Suffix  . . . . . . . : 
 
        Node Type . . . . . . . . . . . . : Unknown
 
        IP Routing Enabled. . . . . . . . : No
 
        WINS Proxy Enabled. . . . . . . . : No
 
        DNS Suffix Search List. . . . . . : eau.wi.charter.com
 
 
 
Ethernet adapter Local Area Connection:
 
 
 
        Media State . . . . . . . . . . . : Media disconnected
 
        Description . . . . . . . . . . . : Atheros L2 Fast Ethernet 10/100 Base-T Controller
 
        Physical Address. . . . . . . . . : 00-24-8C-67-2A-06
 
 
 
Ethernet adapter Wireless Network Connection:
 
 
 
        Connection-specific DNS Suffix  . : eau.wi.charter.com
 
        Description . . . . . . . . . . . : Atheros AR5007EG Wireless Network Adapter
 
        Physical Address. . . . . . . . . : 00-15-AF-A7-BE-4C
 
        Dhcp Enabled. . . . . . . . . . . : Yes
 
        Autoconfiguration Enabled . . . . : Yes
 
        IP Address. . . . . . . . . . . . : 192.168.1.101
 
        Subnet Mask . . . . . . . . . . . : 255.255.255.0
 
        Default Gateway . . . . . . . . . : 192.168.1.1
 
        DHCP Server . . . . . . . . . . . : 192.168.1.1
 
        DNS Servers . . . . . . . . . . . : 24.196.64.53
 
                                            68.113.206.10
 
                                            24.178.162.3
 
        Lease Obtained. . . . . . . . . . : Monday, September 23, 2013 11:02:09 AM
 
        Lease Expires . . . . . . . . . . : Wednesday, September 25, 2013 11:02:09 AM
 
Server:  vip01ftbgwi.ftbg.wi.charter.com
Address:  24.196.64.53
 
Name:    google.com
Addresses:  74.125.225.78, 74.125.225.66, 74.125.225.72, 74.125.225.69
 74.125.225.65, 74.125.225.64, 74.125.225.70, 74.125.225.68, 74.125.225.73
 74.125.225.67, 74.125.225.71
 
 
 
Pinging google.com [173.194.46.64] with 32 bytes of data:
 
 
 
Reply from 173.194.46.64: bytes=32 time=25ms TTL=54
 
Reply from 173.194.46.64: bytes=32 time=11ms TTL=54
 
 
 
Ping statistics for 173.194.46.64:
 
    Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
 
Approximate round trip times in milli-seconds:
 
    Minimum = 11ms, Maximum = 25ms, Average = 18ms
 
Server:  vip01ftbgwi.ftbg.wi.charter.com
Address:  24.196.64.53
 
Name:    yahoo.com
Addresses:  206.190.36.45, 98.138.253.109, 98.139.183.24
 
 
 
Pinging yahoo.com [98.138.253.109] with 32 bytes of data:
 
 
 
Reply from 98.138.253.109: bytes=32 time=96ms TTL=51
 
Reply from 98.138.253.109: bytes=32 time=19ms TTL=51
 
 
 
Ping statistics for 98.138.253.109:
 
    Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
 
Approximate round trip times in milli-seconds:
 
    Minimum = 19ms, Maximum = 96ms, Average = 57ms
 
 
 
Pinging 127.0.0.1 with 32 bytes of data:
 
 
 
Reply from 127.0.0.1: bytes=32 time<1ms TTL=128
 
Reply from 127.0.0.1: bytes=32 time<1ms TTL=128
 
 
 
Ping statistics for 127.0.0.1:
 
    Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
 
Approximate round trip times in milli-seconds:
 
    Minimum = 0ms, Maximum = 0ms, Average = 0ms
 
===========================================================================
Interface List
0x1 ........................... MS TCP Loopback interface
0x2 ...00 24 8c 67 2a 06 ...... Atheros L2 Fast Ethernet 10/100 Base-T Controller - Packet Scheduler Miniport
0x3 ...00 15 af a7 be 4c ...... Atheros AR5007EG Wireless Network Adapter - Packet Scheduler Miniport
===========================================================================
===========================================================================
Active Routes:
Network Destination        Netmask          Gateway       Interface  Metric
          0.0.0.0          0.0.0.0      192.168.1.1   192.168.1.101  30
        127.0.0.0        255.0.0.0        127.0.0.1       127.0.0.1  1
      192.168.1.0    255.255.255.0    192.168.1.101   192.168.1.101  30
    192.168.1.101  255.255.255.255        127.0.0.1       127.0.0.1  30
    192.168.1.255  255.255.255.255    192.168.1.101   192.168.1.101  30
        224.0.0.0        240.0.0.0    192.168.1.101   192.168.1.101  30
  255.255.255.255  255.255.255.255    192.168.1.101               2  1
  255.255.255.255  255.255.255.255    192.168.1.101   192.168.1.101  1
Default Gateway:       192.168.1.1
===========================================================================
Persistent Routes:
  None
========================= Winsock entries =====================================
 
Catalog5 01 C:\WINDOWS\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog5 02 C:\WINDOWS\system32\winrnr.dll [16896] (Microsoft Corporation)
Catalog5 03 C:\WINDOWS\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 01 C:\WINDOWS\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 02 C:\WINDOWS\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 03 C:\WINDOWS\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 04 C:\WINDOWS\system32\rsvpsp.dll [92672] (Microsoft Corporation)
Catalog9 05 C:\WINDOWS\system32\rsvpsp.dll [92672] (Microsoft Corporation)
Catalog9 06 C:\WINDOWS\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 07 C:\WINDOWS\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 08 C:\WINDOWS\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 09 C:\WINDOWS\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 10 C:\WINDOWS\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 11 C:\WINDOWS\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 12 C:\WINDOWS\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 13 C:\WINDOWS\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 14 C:\WINDOWS\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 15 C:\WINDOWS\system32\mswsock.dll [245248] (Microsoft Corporation)
 
========================= Event log errors: ===============================
 
Application errors:
==================
Error: (09/22/2013 07:53:40 PM) (Source: VSSetup) (User: )
Description: EventType vssetup, P1 microsoft .net framework 4 client profile setup, P2 4.0.30319, P3 10.0.30319.1, P4 1, P5  , P6 none_ui_silent_error, P7 0x13ec, P8 0, P9 vssetup0, P10 vssetup1.
 
Error: (09/22/2013 03:57:39 PM) (Source: Application Hang) (User: )
Description: Fault bucket -816940832.
 
Error: (09/22/2013 03:56:43 PM) (Source: Application Hang) (User: )
Description: Hanging application mbam.exe, version 1.75.0.1, hang module hungapp, version 0.0.0.0, hang address 0x00000000.
 
Error: (09/21/2013 05:34:56 AM) (Source: .NET Runtime Optimization Service) (User: )
Description: .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32) - Failed to compile: PresentationCore, Version=3.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35 . Error code = 0x8007000e
 
Error: (09/21/2013 05:34:00 AM) (Source: .NET Runtime Optimization Service) (User: )
Description: .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32) - Failed to compile: mscorlib, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089 . Error code = 0x8007000e
 
Error: (09/21/2013 05:33:23 AM) (Source: .NET Runtime Optimization Service) (User: )
Description: .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32) - Failed to compile: mscorlib, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089 . Error code = 0x8007000e
 
Error: (09/21/2013 05:32:43 AM) (Source: .NET Runtime Optimization Service) (User: )
Description: .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32) - Failed to compile: mscorlib, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089 . Error code = 0x8007000e
 
Error: (09/21/2013 05:32:23 AM) (Source: .NET Runtime Optimization Service) (User: )
Description: .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32) - Failed to compile: mscorlib, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089 . Error code = 0x8007000e
 
Error: (09/21/2013 05:25:51 AM) (Source: .NET Runtime Optimization Service) (User: )
Description: .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32) - Failed to compile: c:\Program Files\Reference Assemblies\Microsoft\Framework\v3.0\System.ServiceModel.dll . Error code = 0x8007000e
 
Error: (09/21/2013 05:05:55 AM) (Source: .NET Runtime Optimization Service) (User: )
Description: .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32) - Failed to compile: PresentationFramework, Version=3.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35 . Error code = 0x8007000e
 
 
System errors:
=============
Error: (09/23/2013 10:02:18 AM) (Source: Service Control Manager) (User: )
Description: The following boot-start or system-start driver(s) failed to load: 
aswSP
SRTSP
SRTSPX
 
Error: (09/23/2013 10:02:09 AM) (Source: Service Control Manager) (User: )
Description: The aswFsBlk service failed to start due to the following error: 
%%2
 
Error: (09/22/2013 09:14:46 PM) (Source: Dhcp) (User: )
Description: Your computer was not assigned an address from the network (by the DHCP
Server) for the Network Card with network address 0015AFA7BE4C.  The following error
occurred: 
%%1223.
Your computer will continue to try and obtain an address on its own from
the network address (DHCP) server.
 
Error: (09/22/2013 07:54:09 PM) (Source: Windows Update Agent) (User: )
Description: Installation Failure: Windows failed to install the following update with error 0x80070643: Microsoft .NET Framework 4 Client Profile for Windows XP x86 (KB982670).
 
Error: (09/22/2013 06:06:12 PM) (Source: Dhcp) (User: )
Description: The IP address lease 192.168.1.101 for the Network Card with network address 0015AFA7BE4C has been
denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message).
 
Error: (09/22/2013 05:03:27 PM) (Source: Dhcp) (User: )
Description: The IP address lease 192.168.1.101 for the Network Card with network address 0015AFA7BE4C has been
denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message).
 
Error: (09/22/2013 03:49:22 PM) (Source: Dhcp) (User: )
Description: The IP address lease 192.168.1.100 for the Network Card with network address 0015AFA7BE4C has been
denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message).
 
Error: (09/22/2013 01:43:40 PM) (Source: Dhcp) (User: )
Description: The IP address lease 192.168.1.100 for the Network Card with network address 0015AFA7BE4C has been
denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message).
 
Error: (09/22/2013 01:07:57 AM) (Source: Service Control Manager) (User: )
Description: The following boot-start or system-start driver(s) failed to load: 
aswSP
SRTSP
SRTSPX
 
Error: (09/22/2013 01:07:49 AM) (Source: Service Control Manager) (User: )
Description: The aswFsBlk service failed to start due to the following error: 
%%2
 
 
Microsoft Office Sessions:
=========================
 
=========================== Installed Programs ============================
 
Adobe Flash Player 11 ActiveX (Version: 11.8.800.175)
Asus ACPI Driver (Version: 4.00.0004)
Asus OS Cleaner (Version: 1.0.0001)
Asus Power Management Utility (Version: 1.03)
ASUSUpdate for Eee PC
Atheros Communications Inc.® L2 Fast Ethernet Driver (Version: 2.5.7.9)
avast! Free Antivirus (Version: 8.0.1497.0)
CCleaner (Version: 4.05)
Google Chrome (Version: 29.0.1547.76)
Google Update Helper (Version: 1.3.21.153)
Intel® Graphics Media Accelerator Driver
Malwarebytes Anti-Malware version 1.75.0.1300 (Version: 1.75.0.1300)
Microsoft .NET Framework 1.1 (Version: 1.1.4322)
Microsoft .NET Framework 1.1 Security Update (KB2833941)
Microsoft .NET Framework 1.1 Security Update (KB979906)
Microsoft .NET Framework 2.0 Service Pack 2 (Version: 2.2.30729)
Microsoft .NET Framework 3.0 Service Pack 2 (Version: 3.2.30729)
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729)
Microsoft Application Error Reporting (Version: 12.0.6012.5000)
Microsoft SQL Server 2005 Compact Edition [ENU] (Version: 3.1.0000)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (Version: 8.0.50727.4053)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.61001)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (Version: 10.0.40219)
Realtek High Definition Audio Driver (Version: 5.10.0.5585)
Secunia PSI (3.0.0.7011) (Version: 3.0.0.7011)
SES Driver (Version: 1.0.0)
Sophos Virus Removal Tool (Version: 2.4)
SUPERAntiSpyware (Version: 5.6.1032)
TreeSize Free V2.7 (Version: 2.7)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (Version: 1)
Update for Windows Internet Explorer 8 (KB2598845) (Version: 1)
Visual Studio 2012 x86 Redistributables (Version: 14.0.0.1)
WebFldrs XP (Version: 9.50.7523)
Windows Genuine Advantage Notifications (KB905474) (Version: 1.8.0031.0)
Windows Internet Explorer 8 (Version: 20090308.140743)
Windows Live Mail
 
========================= Memory info: ===================================
 
Percentage of memory in use: 80%
Total physical RAM: 503.04 MB
Available physical RAM: 96.14 MB
Total Pagefile: 1226.81 MB
Available Pagefile: 705.45 MB
Total Virtual: 2047.88 MB
Available Virtual: 1969.71 MB
 
========================= Partitions: =====================================
 
1 Drive c: () (Fixed) (Total:7.48 GB) (Free:0.18 GB) NTFS
 
========================= Users: ========================================
 
User accounts for \\YOUR-1UT28O6MCF
 
Administrator            ASPNET                   Ellen Smith              
Guest                    HelpAssistant            SUPPORT_388945a0         
 
 
**** End of log ****
 
# AdwCleaner v3.005 - Report created 23/09/2013 at 11:16:59
# Updated 22/09/2013 by Xplode
# Operating System : Microsoft Windows XP Service Pack 3 (32 bits)
# Username : Ellen Smith - YOUR-1UT28O6MCF
# Running from : C:\Documents and Settings\Ellen Smith\My Documents\Downloads\AdwCleaner.exe
# Option : Scan
 
***** [ Services ] *****
 
 
***** [ Files / Folders ] *****
 
File Found : C:\END
Folder Found C:\Documents and Settings\Administrator\Local Settings\Application Data\Wajam
Folder Found C:\Documents and Settings\All Users\Application Data\apn
 
***** [ Shortcuts ] *****
 
 
***** [ Registry ] *****
 
Key Found : HKCU\Software\Wajam
Key Found : HKCU\Software\YahooPartnerToolbar
Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\jpmbfleldcgkldadpdinhjjopdfpjfjp
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Wajam
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
 
***** [ Browsers ] *****
 
-\\ Internet Explorer v8.0.6001.18702
 
 
-\\ Google Chrome v29.0.1547.76
 
[ File : C:\Documents and Settings\Ellen Smith\Local Settings\Application Data\Google\Chrome\User Data\Default\preferences ]
 
 
[ File : C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\preferences ]
 
 
*************************
 
AdwCleaner[R0].txt - [1391 octets] - [23/09/2013 11:16:59]
 
########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [1451 octets] ##########
 

TDSSKiller produced no log file. It stated that everything was OK.

 

ESET produced no log file. 0 files infected.

 

 



#4 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,416 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:10:16 AM

Posted 23 September 2013 - 02:03 PM

Double click on AdwCleaner.exe to run the tool again.
  • Click on the Scan button.
  • AdwCleaner will begin to scan your computer like it did before.
  • After the scan has finished...
    <-insert any special instructions here for what to uncheck OR remove this line if there are none->
  • This time click on the Clean button.
  • Press OK when asked to close all programs and follow the onscreen prompts.
  • Press OK again to allow AdwCleaner to restart the computer and complete the removal process.
  • After rebooting, a logfile report (AdwCleaner[S0].txt) will open automatically.
  • Copy and paste the contents of that logfile in your next reply.
  • A copy of that logfile will also be saved in the C:\AdwCleaner folder.
  • Empty your temp folders using TFC (Temporary File Cleaner)
    • Please download TFC by Old Timer and save it to your desktop.
      alternate download link
    • Save any unsaved work. (TFC will close ALL open programs including your browser!)
    • Double-click on TFC.exe to run it. (If you are using Vista, right-click on the file and choose "Run As Administrator".)
    • Click the Start button to begin the cleaning process and let it run uninterrupted to completion.
    • Important! If TFC prompts you to reboot, please do so immediately. If not prompted, manually reboot the machine anyway allowing Windows to load normally (not into Safe Mode) to ensure a complete clean.
    You are still losing space correct?


How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#5 Werval1

Werval1
  • Topic Starter

  • Members
  • 24 posts
  • OFFLINE
  •  
  • Local time:08:16 AM

Posted 23 September 2013 - 02:28 PM

OK boopme. I'm not sure why your last reply went to "junk mail", but I found it.

 

The AdwCleaner  results are tabbed. Are you suggesting that I just click clean for all checked items?

 

The software doesn't allow copy/paste functions.



#6 Werval1

Werval1
  • Topic Starter

  • Members
  • 24 posts
  • OFFLINE
  •  
  • Local time:08:16 AM

Posted 23 September 2013 - 02:42 PM

# AdwCleaner v3.005 - Report created 23/09/2013 at 14:35:49
# Updated 22/09/2013 by Xplode
# Operating System : Microsoft Windows XP Service Pack 3 (32 bits)
# Username : Ellen Smith - YOUR-1UT28O6MCF
# Running from : C:\Documents and Settings\Ellen Smith\My Documents\Downloads\AdwCleaner.exe
# Option : Clean
 
***** [ Services ] *****
 
 
***** [ Files / Folders ] *****
 
Folder Deleted : C:\Documents and Settings\All Users\Application Data\apn
Folder Deleted : C:\Documents and Settings\Administrator\Local Settings\Application Data\Wajam
File Deleted : C:\END
 
***** [ Shortcuts ] *****
 
 
***** [ Registry ] *****
 
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\jpmbfleldcgkldadpdinhjjopdfpjfjp
Key Deleted : HKCU\Software\Wajam
Key Deleted : HKCU\Software\YahooPartnerToolbar
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Wajam
 
***** [ Browsers ] *****
 
-\\ Internet Explorer v8.0.6001.18702
 
 
-\\ Google Chrome v29.0.1547.76
 
[ File : C:\Documents and Settings\Ellen Smith\Local Settings\Application Data\Google\Chrome\User Data\Default\preferences ]
 
 
[ File : C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\preferences ]
 
 
*************************
 
AdwCleaner[R0].txt - [1531 octets] - [23/09/2013 11:16:59]
AdwCleaner[R1].txt - [1591 octets] - [23/09/2013 14:13:13]
AdwCleaner[S0].txt - [1532 octets] - [23/09/2013 14:35:49]
 
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [1592 octets] ##########


#7 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,416 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:10:16 AM

Posted 23 September 2013 - 04:05 PM

You are still losing space though correct?
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#8 Werval1

Werval1
  • Topic Starter

  • Members
  • 24 posts
  • OFFLINE
  •  
  • Local time:08:16 AM

Posted 23 September 2013 - 04:14 PM

I'm not sure at this juncture. I have 1.28.GB available I uninstalled some programs to create space.) I'll have to watch this number to see if it declines again.



#9 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,416 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:10:16 AM

Posted 23 September 2013 - 04:20 PM

If it is still we will need to get a deeper look. Please follow this Preparation Guide and post in a new topic.
Let me know if all went well.
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#10 Werval1

Werval1
  • Topic Starter

  • Members
  • 24 posts
  • OFFLINE
  •  
  • Local time:08:16 AM

Posted 23 September 2013 - 04:43 PM

Is there a way to find out where all of the drive clogging files are located?



#11 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,416 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:10:16 AM

Posted 23 September 2013 - 06:52 PM

Yeah this isn't good.

How to Locate Large Files Using Windows XP

 

You probably should do steps 6,7 and 8 in the Prep Guide. I think there is still infection we cannot see.

 

 


How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users