Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Adware-like behaviors, odd cross-browser and -platform effects?


  • Please log in to reply
3 replies to this topic

#1 Dimak

Dimak

  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:02:10 AM

Posted 05 May 2014 - 11:39 PM

Hello!

 

tl;dr at the bottom FYI

 

Running win8.1, x64, asus laptop. I have recently started getting, well, not popups, but pop-alongsides. I first noticed this in Chrome, when I clicked on the blank area of a webpage. A new tab opened in the background, routing me through reduxmediia.com, then a few other sites, to a bogus Flash Player update. I just closed it and crossed my fingers. It happened a few more times on the same page (reddit's /r/science) and I looked into the page elements and found nothing. This is when I began to get suspicious. It began to happen on other sites, etc, and also occasionally when I click hyperlinks. This should be fairly standard adware, but then it gets wierder. This same thing started showing up in IE, and into a fresh Firefox install as well. I ran a full Malwarebytes scan, and got nothing. It was late, so I left it for the morning at that point.

 

I use a Surface RT for on-the-go. Booted that up and started browsing on the bus, and bam, I got an identical popup. Only happened once or twice though (I use it less often). My only response to this is ????? as RT has a puny marketshare.

 

I have not seen this popup on anyone else's computers, even when doing the exact same series of navigations.

 

I am substantially confused. My question is this: Is this some new type of advertisment, or am I infected somehow?

 

TL;DR random blank spaces and known links leading me through reduxmediia.com to bogus ads in multiple browsers.  Nothing turning up in antivirus. Same thing pops up in Win RT.

 

I'm experienced in computers, and know some coding basics, but when it comes to stuff like this I am out of my league. Any ideas/suggestions/requests? Help!



BC AdBot (Login to Remove)

 


#2 noknojon

noknojon

  • Banned
  • 10,871 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Local time:07:10 PM

Posted 06 May 2014 - 12:57 AM

First -
Stay away from this bogus Flash Player update - Many people are being hit there.

Only update from the legitimate Adobe site, and if you are not sure then use Google to find it.
Do not guess, as many are being infected there.. Untick the Google Add-On or it may change your Home Page.

Just F.Y.I. on the 2014-03-15 - 2 reports - reduxmediia.com malvertising Current report on reduxmediia.com
 

 

Now back to a basic report on your system -

Note all programs are saved to desktop, Copy and Paste all logs, and Temporarily Disable Your Anti-virus if required.

 

Download Security Check by Screen317 from HERE
* Save it to your Desktop.
* Double-click SecurityCheck.exe
* Follow the onscreen instructions inside of the black box.
* A Notepad document should open automatically called checkup.txt; please post the contents of that document.
Note: If any security program requests permission to access the Internet, allow it to do so.
 

 

Next -

Download MiniToolBox, Save it to your desktop and run it.
Close any Firefox browsers you may have open
Checkmark the following boxes:
• Flush DNS
• Report IE Proxy Settings
• Reset IE Proxy Settings
• Report FF Proxy Settings
• Reset FF Proxy Settings
• List content of Hosts
• List last 10 Event Viewer log
• List Installed Programs
• List Users, Partitions and Memory size.
Click Go and copy / paste the result (Result.txt).

 

 

Next a bit of cleaning and infection looking -

 

Please download and run RKill by Grinler.
A black DOS box will briefly flash and then disappear.
This is normal and indicates the tool ran successfully.

Please Copy and Paste the small log it produces.

 

 

Important: Do not reboot your computer until you complete the next step.

 

 

Now:

Please download AdwCleaner by Xplode and save to your Desktop.
NOTE : Please close or save all work, as the computer will be Rebooted
Double-click on AdwCleaner.exe to run the tool.
Vista/Windows 7/8 users right-click and select Run As Administrator.
Click on the Scan button. (only once)
AdwCleaner will begin...be patient as the scan may take some time to complete.
After the scan has finished, click on the Report button...a logfile (AdwCleaner[R0].txt) will open in Notepad for review. 
If you see any which you do not want removed, remove the check mark next to it. 
Next: Click on the Clean button (only once) to remove the selected items. 
You will receive a message telling you that all programs will be close so that the infections can be removed. 
Click on OK, and then OK again to confirm the reboot.
When cleaning process is complete a log (AdwCleaner[S0].txt ) of what was removed will be on your desktop. 
Please copy and the paste this log in your next post.

 

A copy of all logfiles are saved in the C:\AdwCleaner folder which was created when running the tool.



#3 Dimak

Dimak
  • Topic Starter

  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:02:10 AM

Posted 06 May 2014 - 01:27 AM

Incoming!

 

Here's SecurityCheck's log:

 Results of screen317's Security Check version 0.99.82  
   x64 (UAC is enabled)  
 Internet Explorer 11  
[b][u]``````````````Antivirus/Firewall Check:``````````````[/b][/u] 
 Windows Firewall Enabled!  
Windows Defender   
 [size=1]WMI entry may not exist for antivirus; attempting automatic update.[/size] 
[b][u]`````````Anti-malware/Other Utilities Check:`````````[/b][/u] 
 Java 7 Update 55  
 Adobe Reader 10.1.9 [color=red][b]Adobe Reader out of Date![/b][/color]  
 Google Chrome 34.0.1847.116  
 Google Chrome 34.0.1847.131  
[b][u]````````Process Check: objlist.exe by Laurent````````[/b][/u]  
 Windows Defender MSMpEng.exe 
 ESET ESET Online Scanner OnlineScannerApp.exe  
 ESET ESET Online Scanner OnlineCmdLineScanner.exe  
[b][u]`````````````````System Health check`````````````````[/b][/u] 
 Total Fragmentation on Drive C:  % 
[b][u]````````````````````End of Log``````````````````````[/b][/u] 

Here's MiniToolBox's log:

MiniToolBox by Farbar  Version: 23-01-2014
Ran by Grant Shogren (administrator) on 05-05-2014 at 23:16:30
Running from "C:\Users\Grant Shogren\Desktop"
Microsoft Windows 8.1  (X64)
Boot Mode: Normal
***************************************************************************

========================= Flush DNS: ===================================

Windows IP Configuration

Successfully flushed the DNS Resolver Cache.

========================= IE Proxy Settings: ============================== 

Proxy is not enabled.
No Proxy Server is set.

"Reset IE Proxy Settings": IE Proxy Settings were reset.
========================= Hosts content: =================================




========================= Event log errors: ===============================

Application errors:
==================
Error: (05/05/2014 09:57:56 PM) (Source: SideBySide) (User: )
Description: Activation context generation failed for "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest1".Error in manifest or policy file "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest2" on line C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest3.
A component version required by the application conflicts with another component version already active.
Conflicting components are:.
Component 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.
Component 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.

Error: (05/05/2014 09:57:52 PM) (Source: SideBySide) (User: )
Description: Activation context generation failed for "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest1".Error in manifest or policy file "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest2" on line C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest3.
A component version required by the application conflicts with another component version already active.
Conflicting components are:.
Component 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.
Component 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.

Error: (05/05/2014 09:57:46 PM) (Source: SideBySide) (User: )
Description: Activation context generation failed for "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest1".Error in manifest or policy file "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest2" on line C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest3.
A component version required by the application conflicts with another component version already active.
Conflicting components are:.
Component 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.
Component 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.

Error: (05/05/2014 09:57:46 PM) (Source: SideBySide) (User: )
Description: Activation context generation failed for "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest1".Error in manifest or policy file "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest2" on line C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest3.
A component version required by the application conflicts with another component version already active.
Conflicting components are:.
Component 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.
Component 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.

Error: (05/05/2014 09:56:19 PM) (Source: SideBySide) (User: )
Description: Activation context generation failed for "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest1".Error in manifest or policy file "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest2" on line C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest3.
A component version required by the application conflicts with another component version already active.
Conflicting components are:.
Component 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.
Component 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.

Error: (05/04/2014 00:10:10 PM) (Source: Application Error) (User: )
Description: Faulting application name: ZeroConfigService.exe, version: 16.1.0.0, time stamp: 0x521e80f5
Faulting module name: MurocApi.dll, version: 16.1.0.0, time stamp: 0x521e7ff7
Exception code: 0xc0000005
Fault offset: 0x0000000000026570
Faulting process id: 0x8d4
Faulting application start time: 0xZeroConfigService.exe0
Faulting application path: ZeroConfigService.exe1
Faulting module path: ZeroConfigService.exe2
Report Id: ZeroConfigService.exe3
Faulting package full name: ZeroConfigService.exe4
Faulting package-relative application ID: ZeroConfigService.exe5

Error: (04/30/2014 00:29:38 PM) (Source: MsiInstaller) (User: NT AUTHORITY)
Description: Unexpected or missing value (name: 'PackageCode', value: 'GUID') in key 'HKLM\Software\Classes\Installer\Products\B476F94747628E7478C965620AB6A219'

Error: (04/30/2014 10:06:01 AM) (Source: Microsoft-Windows-RestartManager) (User: DATA)
Description: Application or service 'Google Chrome' could not be shut down.

Error: (04/30/2014 10:05:29 AM) (Source: MsiInstaller) (User: DATA)
Description: Unexpected or missing value (name: 'PackageCode', value: 'GUID') in key 'HKLM\Software\Classes\Installer\Products\B476F94747628E7478C965620AB6A219'

Error: (04/29/2014 08:00:55 PM) (Source: MsiInstaller) (User: DATA)
Description: Unexpected or missing value (name: 'PackageCode', value: 'GUID') in key 'HKLM\Software\Classes\Installer\Products\B476F94747628E7478C965620AB6A219'


System errors:
=============
Error: (05/05/2014 01:05:36 PM) (Source: Service Control Manager) (User: )
Description: The NVIDIA Update Service Daemon service failed to start due to the following error: 
%%1069

Error: (05/05/2014 01:05:36 PM) (Source: Service Control Manager) (User: )
Description: The nvUpdatusService service was unable to log on as .\UpdatusUser with the currently configured password due to the following error: 
%%1326

To ensure that the service is configured properly, use the Services snap-in in Microsoft Management Console (MMC).

Error: (05/05/2014 01:02:49 PM) (Source: EventLog) (User: )
Description: The previous system shutdown at 12:55:49 PM on ?5/?5/?2014 was unexpected.

Error: (05/05/2014 00:50:43 PM) (Source: Service Control Manager) (User: )
Description: The NVIDIA Update Service Daemon service failed to start due to the following error: 
%%1069

Error: (05/05/2014 00:50:43 PM) (Source: Service Control Manager) (User: )
Description: The nvUpdatusService service was unable to log on as .\UpdatusUser with the currently configured password due to the following error: 
%%1326

To ensure that the service is configured properly, use the Services snap-in in Microsoft Management Console (MMC).

Error: (05/05/2014 00:48:23 PM) (Source: EventLog) (User: )
Description: The previous system shutdown at 12:45:17 PM on ?5/?5/?2014 was unexpected.

Error: (05/04/2014 11:44:09 PM) (Source: Microsoft-Windows-BitLocker-Driver) (User: NT AUTHORITY)
Description: Encrypted volume check: Volume information on E: cannot be read.

Error: (05/04/2014 00:16:03 PM) (Source: Service Control Manager) (User: )
Description: The NVIDIA Update Service Daemon service failed to start due to the following error: 
%%1069

Error: (05/04/2014 00:16:03 PM) (Source: Service Control Manager) (User: )
Description: The nvUpdatusService service was unable to log on as .\UpdatusUser with the currently configured password due to the following error: 
%%1326

To ensure that the service is configured properly, use the Services snap-in in Microsoft Management Console (MMC).

Error: (05/02/2014 09:53:41 AM) (Source: Service Control Manager) (User: )
Description: The NVIDIA Update Service Daemon service failed to start due to the following error: 
%%1069


Microsoft Office Sessions:
=========================
Error: (05/05/2014 09:57:56 PM) (Source: SideBySide)(User: )
Description: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifestC:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifestC:\Users\Grant Shogren\Desktop\esetsmartinstaller_enu.exe

Error: (05/05/2014 09:57:52 PM) (Source: SideBySide)(User: )
Description: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifestC:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifestC:\Users\Grant Shogren\Desktop\esetsmartinstaller_enu.exe

Error: (05/05/2014 09:57:46 PM) (Source: SideBySide)(User: )
Description: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifestC:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifestC:\Users\Grant Shogren\Desktop\esetsmartinstaller_enu.exe

Error: (05/05/2014 09:57:46 PM) (Source: SideBySide)(User: )
Description: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifestC:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifestC:\Users\Grant Shogren\Desktop\esetsmartinstaller_enu.exe

Error: (05/05/2014 09:56:19 PM) (Source: SideBySide)(User: )
Description: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifestC:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifestC:\Users\Grant Shogren\Desktop\esetsmartinstaller_enu.exe

Error: (05/04/2014 00:10:10 PM) (Source: Application Error)(User: )
Description: ZeroConfigService.exe16.1.0.0521e80f5MurocApi.dll16.1.0.0521e7ff7c000000500000000000265708d401cf67cc710a88e3C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exeC:\Program Files\Intel\WiFi\bin\MurocApi.dllb6005413-d3bf-11e3-be93-0c8bfd638b47

Error: (04/30/2014 00:29:38 PM) (Source: MsiInstaller)(User: NT AUTHORITY)
Description: PackageCodeGUIDHKLM\Software\Classes\Installer\Products\B476F94747628E7478C965620AB6A219(NULL)(NULL)(NULL)

Error: (04/30/2014 10:06:01 AM) (Source: Microsoft-Windows-RestartManager)(User: DATA)
Description: 1C:\Program Files (x86)\Google\Chrome\Application\chrome.exeGoogle Chrome0211737360

Error: (04/30/2014 10:05:29 AM) (Source: MsiInstaller)(User: DATA)
Description: PackageCodeGUIDHKLM\Software\Classes\Installer\Products\B476F94747628E7478C965620AB6A219(NULL)(NULL)(NULL)

Error: (04/29/2014 08:00:55 PM) (Source: MsiInstaller)(User: DATA)
Description: PackageCodeGUIDHKLM\Software\Classes\Installer\Products\B476F94747628E7478C965620AB6A219(NULL)(NULL)(NULL)


=========================== Installed Programs ============================

 ASUS Console (Version: 1.0.0)
µTorrent (Version: 3.4.1.30888)
7-Zip 9.20 (x64 edition) (Version: 9.20.00.0)
Adobe Reader X (10.1.9) MUI (Version: 10.1.9)
ASUS FaceKey (Version: 4.1.0.0)
ASUS Live Update (Version: 3.2.2)
ASUS Power4Gear Hybrid (Version: 3.0.2)
ASUS Smart Gesture (Version: 2.0.1)
ASUS Splendid Video Enhancement Technology (Version: 2.01.0005)
ASUS USB Charger Plus (Version: 3.1.0)
ASUS Video DSP (Version: 1.0.000)
ASUSDVD (Version: 10.0.4924.52)
ATK Package (Version: 1.0.0028)
D3DX10 (Version: 15.4.2368.0902)
Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition
Dragon Assistant version 1.5.19 (Version: 1.5.19)
ESET Online Scanner v3
f.lux
FBackup 5 (Version: 5.0.414)
FBackup 5.0 (Version: 5.0.414.0)
Google Chrome (Version: 34.0.1847.131)
Google Talk Plugin (Version: 5.3.1.18536)
Google Update Helper (Version: 1.3.23.9)
Intel(R) Dynamic Platform and Thermal Framework (Version: 7.0.0.2023)
Intel(R) Management Engine Components (Version: 9.5.10.1550)
Intel(R) PRO/Wireless Driver (Version: 16.01.5000.0577)
Intel(R) Processor Graphics (Version: 10.18.10.3308)
Intel(R) PROSet/Wireless for Bluetooth(R) + High Speed (Version: 16.1.0.0069)
Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology (Version: 3.1.1306.0354)
Intel(R) SDK for OpenCL - CPU Only Runtime Package (Version: 3.0.0.66956)
Intel(R) Update Manager (Version: 1.6.0.56)
Intel(R) WiDi (Version: 4.2.15.0)
Intel® PROSet/Wireless Software (Version: 16.1.0)
Intel® PROSet/Wireless Software (Version: 16.1.5)
Intel® PROSet/Wireless WiFi Software (Version: 16.01.5000.0269)
Intel® Trusted Connect Service Client (Version: 1.28.487.1)
IrfanView (remove only) (Version: 4.37)
Java 7 Update 55 (Version: 7.0.550)
Java Auto Updater (Version: 2.1.9.8)
Malwarebytes Anti-Malware version 2.0.1.1004 (Version: 2.0.1.1004)
Microsoft Application Error Reporting (Version: 12.0.6015.5000)
Microsoft Mouse and Keyboard Center (Version: 2.3.188.0)
Microsoft Office Access MUI (English) 2010 (Version: 14.0.7015.1000)
Microsoft Office Access Setup Metadata MUI (English) 2010 (Version: 14.0.7015.1000)
Microsoft Office Excel MUI (English) 2010 (Version: 14.0.7015.1000)
Microsoft Office Home and Student 2010 (Version: 14.0.7015.1000)
Microsoft Office Office 64-bit Components 2010 (Version: 14.0.7015.1000)
Microsoft Office OneNote MUI (English) 2010 (Version: 14.0.7015.1000)
Microsoft Office Outlook MUI (English) 2010 (Version: 14.0.7015.1000)
Microsoft Office PowerPoint MUI (English) 2010 (Version: 14.0.7015.1000)
Microsoft Office Proof (English) 2010 (Version: 14.0.7015.1000)
Microsoft Office Proof (French) 2010 (Version: 14.0.7015.1000)
Microsoft Office Proof (Spanish) 2010 (Version: 14.0.7015.1000)
Microsoft Office Proofing (English) 2010 (Version: 14.0.7015.1000)
Microsoft Office Publisher MUI (English) 2010 (Version: 14.0.7015.1000)
Microsoft Office Shared 64-bit MUI (English) 2010 (Version: 14.0.7015.1000)
Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2010 (Version: 14.0.7015.1000)
Microsoft Office Shared MUI (English) 2010 (Version: 14.0.7015.1000)
Microsoft Office Shared Setup Metadata MUI (English) 2010 (Version: 14.0.7015.1000)
Microsoft Office Single Image 2010 (Version: 14.0.7015.1000)
Microsoft Office Word MUI (English) 2010 (Version: 14.0.7015.1000)
Microsoft Silverlight (Version: 5.1.30214.0)
Microsoft SkyDrive (Version: 16.4.6013.0910)
Microsoft SQL Server 2005 Compact Edition [ENU] (Version: 3.1.0000)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.59193)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.61001)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (Version: 10.0.40219)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (Version: 10.0.40219)
Movie Maker (Version: 16.4.3505.0912)
MSVCRT (Version: 15.4.2862.0708)
MSVCRT110 (Version: 16.4.1108.0727)
MSVCRT110_amd64 (Version: 16.4.1109.0912)
Nuance Speech Component DA-A en-US version 1.5.19 (Version: 1.5.19)
Nuance Speech Component DA-C version 1.1.21 (Version: 1.1.21)
Nuance Speech Component DA-L en-US version 1.1.5 (Version: 1.1.5)
NVIDIA Control Panel 331.65 (Version: 331.65)
NVIDIA Graphics Driver 331.65 (Version: 331.65)
NVIDIA Install Application (Version: 2.1002.133.889)
NVIDIA Optimus 1.11.3 (Version: 1.11.3)
NVIDIA PhysX (Version: 9.13.0325)
NVIDIA PhysX System Software 9.13.0325 (Version: 9.13.0325)
NVIDIA Update 1.11.3 (Version: 1.11.3)
NVIDIA Update Components (Version: 1.11.3)
Photo Gallery (Version: 16.4.3505.0912)
Realtek Ethernet Controller Driver (Version: 8.11.201.2013)
Realtek High Definition Audio Driver (Version: 6.0.1.6923)
Realtek USB Card Reader (Version: 6.2.9200.39041)
Roll
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition
TeamViewer 9 (Version: 9.0.28223)
Unity Web Player (Version: )
Update for Microsoft Access 2010 (KB2553446) 32-Bit Edition
Update for Microsoft en-us Dictionary (Version: 16.1.880.1)
Update for Microsoft Filter Pack 2.0 (KB2837594) 32-Bit Edition
Update for Microsoft InfoPath 2010 (KB2817369) 32-Bit Edition
Update for Microsoft Office 2010 (KB2589298) 32-Bit Edition
Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition
Update for Microsoft Office 2010 (KB2589375) 32-Bit Edition
Update for Microsoft Office 2010 (KB2597087) 32-Bit Edition
Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition
Update for Microsoft Office 2010 (KB2794737) 32-Bit Edition
Update for Microsoft Office 2010 (KB2863818) 32-Bit Edition
Update for Microsoft Office 2010 (KB2878225) 32-Bit Edition
Update for Microsoft OneNote 2010 (KB2837595) 32-Bit Edition
Update for Microsoft Outlook 2010 (KB2687567) 32-Bit Edition
Update for Microsoft PowerPoint 2010 (KB2837579) 32-Bit Edition
Update for Microsoft SharePoint Workspace 2010 (KB2760601) 32-Bit Edition
Update for Microsoft Visio 2010 (KB2553444) 32-Bit Edition
Update for Microsoft Visio Viewer 2010 (KB2810066) 32-Bit Edition
VLC media player 2.1.3 (Version: 2.1.3)
Windows Driver Package - ASUS (ATP) Mouse  (01/10/2013 1.0.0.170) (Version: 01/10/2013 1.0.0.170)
Windows Live Communications Platform (Version: 16.4.3505.0912)
Windows Live Essentials (Version: 16.4.3505.0912)
Windows Live Installer (Version: 16.4.3505.0912)
Windows Live Photo Common (Version: 16.4.3505.0912)
Windows Live PIMT Platform (Version: 16.4.3505.0912)
Windows Live SOXE (Version: 16.4.3505.0912)
Windows Live SOXE Definitions (Version: 16.4.3505.0912)
Windows Live UX Platform (Version: 16.4.3505.0912)
Windows Live UX Platform Language Pack (Version: 16.4.3505.0912)
WinFlash (Version: 2.42.0)

========================= Memory info: ===================================

Percentage of memory in use: 38%
Total physical RAM: 8075.16 MB
Available physical RAM: 4961.82 MB
Total Pagefile: 16267.16 MB
Available Pagefile: 12553.38 MB
Total Virtual: 4095.88 MB
Available Virtual: 3958.93 MB

========================= Partitions: =====================================

1 Drive c: (OS) (Fixed) (Total:909.96 GB) (Free:762.95 GB) NTFS

========================= Users: ========================================

User accounts for \\DATA

Administrator            Grant Shogren            Guest                    
UpdatusUser              


**** End of log ****

Here is RKill's log:

Rkill 2.6.5 by Lawrence Abrams (Grinler)
http://www.bleepingcomputer.com/
Copyright 2008-2014 BleepingComputer.com
More Information about Rkill can be found at this link:
 http://www.bleepingcomputer.com/forums/topic308364.html

Program started at: 05/05/2014 11:21:13 PM in x64 mode.
Windows Version: Windows 8.1 

Checking for Windows services to stop:

 * No malware services found to stop.

Checking for processes to terminate:

 * No malware processes found to kill.

Checking Registry for malware related settings:

 * No issues found in the Registry.

Resetting .EXE, .COM, & .BAT associations in the Windows Registry.

Performing miscellaneous checks:

 * No issues found.

Checking Windows Service Integrity: 

 * MsKeyboardFilter [Missing Service]
 * CSC [Missing Service]
 * E1G60 [Missing Service]
 * HdAudAddService [Missing Service]
 * kbldfltr [Missing Service]
 * storvsp [Missing Service]
 * Vid [Missing Service]
 * vmbusr [Missing Service]
 * vpcivsp [Missing Service]

Searching for Missing Digital Signatures: 

 * No issues found.

Checking HOSTS File: 

 * No issues found.

Program finished at: 05/05/2014 11:22:53 PM
Execution time: 0 hours(s), 1 minute(s), and 40 seconds(s)

I'll run AdwCleaner and post the log after restart. Thank you for the help, i'm feeling overwhelmed right now with school, so having clear instructions is very calming.



#4 noknojon

noknojon

  • Banned
  • 10,871 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Local time:07:10 PM

Posted 06 May 2014 - 01:41 AM

Please open NOTEPAD and untick (Format => Wordwrap)

 

I need to transfer these logs to another program to read them - (Sorry ) -






0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users