String of BSOD Errors, Possible Malware

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by dutchluck13, Jan 7, 2012.

  1. dutchluck13

    dutchluck13 Private E-2

    Hi, I have been experiencing the following problems as described in this thread, http://forums.majorgeeks.com/showthread.php?t=250064
    DavidGP suggested that I may have a malware problem and went through the Malware Removal Guide. The only problem I experienced while going through it was, I was unable to install the most recent Sun Java. I was given the following message, "The system administrator has set policies to prevent this installation." I have been running in Safe Mode due to the crashes I've been experiencing while trying to run a normal start up. I would really appreciate anyone's help on this as this has really put a hinder on my work these past few weeks. Thanks!
     

    Attached Files:

  2. dutchluck13

    dutchluck13 Private E-2

    ...and MGtools logs
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I want you to run TDSSKiller so refer to the below for how to do so.

    TDSSkiller - How to run


    Please also download MBRCheck to your desktop
    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
     
  4. dutchluck13

    dutchluck13 Private E-2

    Here you are.
     

    Attached Files:

  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Some of this crap we are about to remove has been on your PC since 2010 from what I can see.

    What is this file?
    C:\Documents and Settings\Admin Tyler\Local Settings\Application Data\MF62

    Now we need to use ComboFix by sUBs

    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    DirLook::
    C:\Documents and Settings\Admin Tyler\Local Settings\Application Data\jfpies
    C:\Documents and Settings\Admin Tyler\Local Settings\Application Data\
    C:\Documents and Settings\Admin Tyler\Local Settings\Application Data\{3248F0A6-6813-11D6-A77B-00B0D0150060}
    
    File::
    C:\Documents and Settings\Admin Tyler\Local Settings\Application Data\2509137411
    C:\Documents and Settings\Admin Tyler\Local Settings\Application Data\3469191438
    C:\Documents and Settings\Admin Tyler\Local Settings\Application Data\3jOBub6
    C:\Documents and Settings\Admin Tyler\Local Settings\Application Data\50vGiJ1FW7x2
    C:\Documents and Settings\Admin Tyler\Local Settings\Application Data\8MuP2
    
    Folder::
    C:\Documents and Settings\Admin Tyler\Local Settings\Application Data\oudmqrhpi
    C:\Documents and Settings\Admin Tyler\Local Settings\Application Data\piblqcvbe
    C:\Documents and Settings\Admin Tyler\Local Settings\Application Data\ttmnpihgh
    C:\Documents and Settings\Admin Tyler\Local Settings\Application Data\ukccgj
    C:\Documents and Settings\Admin Tyler\Local Settings\Application Data\vhrnpqtot
    C:\Documents and Settings\Admin Tyler\Local Settings\Application Data\vuqmqciao
    C:\Documents and Settings\Admin Tyler\Local Settings\Application Data\ycpxfa
    C:\Documents and Settings\Admin Tyler\Local Settings\Application Data\yvtkqvjuw
    C:\Documents and Settings\Admin Tyler\Local Settings\Application Data\bjxlqewdi
    C:\Documents and Settings\Admin Tyler\Local Settings\Application Data\dvdlqmjlu
    C:\Documents and Settings\Admin Tyler\Local Settings\Application Data\hhomqruqx
    C:\Documents and Settings\Admin Tyler\Local Settings\Application Data\mvwlqtjsr
    
    Registry::
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{AA8D6475-50E6-0FAB-D17A-2CE8EC5002F9}]
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      [​IMG]

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected.



    Can you re run TDSSKiller please and include these to either cure or

    Your MBRCheck log reports back with Unknown MBR however this does not necessarily mean infected. So I am not touching that until we have tried other things.

    Now for this next bit I would prefer you to be in normal mode, not safe mode, and considering alot of the malware is now probably dead from combofix, you might be able to run more easily now in normal mode anyway.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!

    Are you able to run normally now without BSOD's?
     
  6. dutchluck13

    dutchluck13 Private E-2

    Okay, so I was able to run everything as asked and am now able to run in normal mode. The only thing I noticed is, when logging in, the loading up of the desktop and everything seemed really slow. Then, when I went to open Firefox, it was running extremely slow for a while. I took a look at my processes and my CPU was running at 100% the two processes that were taking up the most were:

    McScript_InUse.exe
    mcshield.exe

    Both were a little over 40%. I know that mcshield.exe is McAfee, which I know to slow things up a little bit during startup, but only for a minute max. But, the other one I haven't seen before. I forgot to check what it was associated with. I had to leave for a little bit before running GetLogs.bat so I logged off and closed my laptop. When I came back I opened it up and the following window popped up:

    "The instruction at "0x03e0622a" referenced memory at "0x00000014". The memory could not be "read". Click on OK to terminate the program"

    I went ahead and clicked ok and logged in again, and this time I didn't have the slow start up as before and everything seemed to be running at normal speed. The other thing I noticed was a Windows Security message saying my Virus Protection "McAfee VirusScan Enterprise" was out-of-date. That seemed odd and I considered uninstalling, then reinstalling it because of the out-of-date and it appearing to be the main cause before of everything running so slow. But, I didn't want to do anything with that until you gave me the okay.
    For the item you asked me to take action on with TDSSKiller the only option I was given was to copy to quarantine, so I did that.
    Then, here are all my logs...
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    It says that you skipped, you sure you quarantined? Try again and attach the new log?


    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    FireFox::
    FF - ProfilePath - c:\documents and settings\Admin Tyler\Application Data\Mozilla\Firefox\Profiles\uatmgof2.default\
    FF - prefs.js: keyword.URL - hxxp://www.fastbrowsersearch.com/results/results.aspx?s=NAUS&v=19&tid={59147294-310A-EBCC-C42C-0CC82B1157EA}&q=
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      [​IMG]

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  8. dutchluck13

    dutchluck13 Private E-2

    Here are the new logs. I think after running TDSSkiller I clicked to quarantine all the items by mistake instead of just the one.
     

    Attached Files:

  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    The default quarantine folder is in the system disk root folder, e.g.:
    C:\TDSSKiller_Quarantine\23.07.2010_15.31.43


    Restore the files to their original locations. Reboot, is all well?

    How are things running now?
     
  10. dutchluck13

    dutchluck13 Private E-2

    How exactly do I restore those files in that folder? Reboot and everything else appears to be running fine now.
     
  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Well, from the old log you posted you can see the locations where the files should reside. When you open up the folder of quarantined items what options does it give you? TDSSKiller probably now has given the file names an extension of .vir or something similar. Are you able to right click and rename to disinclude the .vir extension (or whatever tdssk renamed it to) and place the files back into their proper destination folders?
     
  12. dutchluck13

    dutchluck13 Private E-2

    Looking back at my log I saw that I didn't actually quarantine the other items haha, so my mistake. The only thing in the quarantine folder were two more folders titled tdlfs0000 & tdlfs0001, both with to sets of files titled tsk000(1-8) with file extensions .ini and .dta
     
  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I need to get back to you on this but I am STILL sure that you need to de-quarantone stuff.
    These are the items that need to go back where they belong. I'll seek advice hang in there.
     
  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    TDSSKiller will be built eventually to restore these items with much more ease from what I understand, however, for now, it's a bit awkward. Can you check your system restore points and tell me what you have? We want to head for a slot before you let TDSSKiller wipe those away.
     
  15. dutchluck13

    dutchluck13 Private E-2

    It looks like I have one restore point before that TDSSkiller scan which is:
    1/11/12 12:06:42 AM System Checkpoint. That is the earliest point showing up for January. Go ahead and restore to this point?
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's not before TDSSkiller, that's after. You ran TDSSkiller on 1/10/2012.

    Your logs show signs of restore points all the way back into November. Look at the svren.txt log in the MGtools folder or inside the MGlogs.zip file to see what I mean. Are you saying they don't show when you run System Restore.
     
  17. dutchluck13

    dutchluck13 Private E-2

    From what Kestrel13! said, it didn't look like anything was quarantined when I ran the scan on the 10th. It wasn't until the scan on the 11th that things appeared to be quarantined, so that's why I just posted the restore point on that date. You're right that I do have several other restore points before than in December and in November. Most recent being Dec 23rd:

    11:16:11 PM Installed Java(TM) 6 Update 30
    11:03:02 PM Removed Java(TM) 6 Update 22
    3:15:35 PM Installed Rapport

    and then Dec 22nd:

    8:38:26 PM System Checkpoint

    Please let me know the best action to take.
     
  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes it was on 11th that all those were quarantined, around 10pm. Are you able to restore back to the 11th because they are on the same date but I think the times were all BEFORE 10pm, in fact I think those snapshots were taken at 5am. Let me know.
     
  19. dutchluck13

    dutchluck13 Private E-2

    I was unable to restore back to the 11th. I've had 6 new BSOD's; three on the 15th and three today. Five of them were just new/different then before and all occurred randomly while browsing in Mozilla Firefox and the sixth was the same as before with my screen going whacky then freezing. The sixth happened when streaming a hockey game and everything was fine after restart.
     
  20. thisisu

    thisisu Malware Consultant

    Hi dutchluck13,

    Can you zip up and attach any .dmp files in this folder: C:\WINDOWS\Minidump

    I would like to analyze your BSOD logs.
     
  21. dutchluck13

    dutchluck13 Private E-2

    Here you go, I knew I forgot to attach something to my prev. post.
     

    Attached Files:

  22. thisisu

    thisisu Malware Consultant

    Most of these crashes, at least from 2012 are related to the Intel(R) PRO/1000 PCI Express Network Connection Driver.

    However, there was one from 2012 that was related to your NVIDIA Graphics card.

    See the below for details:

    Mini011512-01.dmp // Jan 15th 2012
    Code:
    STACK_TEXT:  
    b84d3d98 b7cae821 40000080 8ae91418 8a25cda0 nt!KeBugCheckEx+0x1b
    b84d3df8 b5f901f8 8ae91418 b84d3e5c 00000001 NDIS!ethFilterDprIndicateReceivePacket+0x5fe
    WARNING: Stack unwind information not available. Following frames may be wrong.
    b84d3e14 b5f9a35c 8ac08008 b84d3e5c 00000001 e1e5132+0x21f8 [COLOR="Red"]<--- Intel(R) PRO/1000 PCI Express Network Connection Driver[/COLOR]
    b84d3e34 b5f9ca7d 8aea0038 00000000 b84d3e5c e1e5132+0xc35c [COLOR="Red"]<--- Intel(R) PRO/1000 PCI Express Network Connection Driver[/COLOR]
    b84d3f6c b5f96341 014a7000 00000001 00000000 e1e5132+0xea7d [COLOR="Red"]<--- Intel(R) PRO/1000 PCI Express Network Connection Driver[/COLOR]
    b84d3fa8 b5f8f371 004a7000 b84d3fcc b7ca3e99 e1e5132+0x8341 [COLOR="Red"]<--- Intel(R) PRO/1000 PCI Express Network Connection Driver[/COLOR]
    b84d3fb4 b7ca3e99 8ac08008 8ac53008 ffdff9c0 e1e5132+0x1371 [COLOR="Red"]<--- Intel(R) PRO/1000 PCI Express Network Connection Driver[/COLOR]
    b84d3fcc 80545eef 8a4a7ac8 8a4a7ab4 00000000 NDIS!ndisMDpcX+0x21
    b84d3ff4 80545a5b b72f6534 00000000 00000000 nt!KiRetireDpcList+0x61
    b84d3ff8 b72f6534 00000000 00000000 00000000 nt!KiDispatchInterrupt+0x2b
    80545a5b 00000000 00000009 0081850f bb830000 0xb72f6534

    Mini011512-03.dmp // Jan 15th 2012
    Code:
    DEFAULT_BUCKET_ID:  GRAPHICS_DRIVER_FAULT
    
    STACK_TEXT:  
    aa6277e8 00000000 e24ef018 e24ef018 e24ef018 nv4_disp+0x29852 [COLOR="Red"]<--- Related to a NVIDIA Graphics card[/COLOR]
    Are you using an addon card (PCI-E) for internet or are you using the built in ethernet adapter on your motherboard?

    I realize the logs say PCI-Express but it could still be either or.
     
  23. dutchluck13

    dutchluck13 Private E-2

    I've been using the built in ethernet adapter on my motherboard
     
  24. thisisu

    thisisu Malware Consultant

    For troubleshooting purposes you may want to completely uninstall your network adapter drivers from the Device Manager and then install these: Intel: PROSet Network Adapter Driver Set 16.4

    Download them first so you have them handy :)

    The below could also be used. These are the older versions though.
    These are the default drivers that came with your laptop: ThinkPad T61 (6459-CTO)

     
  25. dutchluck13

    dutchluck13 Private E-2

    I went ahead and tried to uninstall the current drivers, however on restart the drivers are reinstalling themselves from somewhere. So, when I try to install the new Intel driver set it doesn't allow for it to happen and I get the following message. "The installed version of Intel PROset is not supported for upgrades. You must uninstall it before installing this version"
     
  26. thisisu

    thisisu Malware Consultant

    Download and install Revo Uninstaller from here.

    Now open Revo Uninstaller and look for any of the below:

    • Intel PROSet Wireless
    • Intel(R) PRO Network Connections Drivers
    • Intel(R) PROSet/Wireless WiFi Software
    Choose to uninstall each and everyone of these if present.

    If requested to restart for the changes to take effect, go ahead and reboot.

    If a hardware installation wizard pops upon reboot. Choose Cancel and proceed to attempt to install the Intel: PROSet Network Adapter Driver Set 16.4 file you downloaded earlier.
     
  27. dutchluck13

    dutchluck13 Private E-2

    I went ahead and uninstalled as you asked. Now, when I go to run the installer it starts off by going through an extracting process. At this point I can see in my toolbar various pop-ups for new Intel hardware found. But, after it finishes the extraction process and switches to the installation wizard I am still getting the same message as before and am unable to finish the install. After this I went to the Device Manager and the all the Intel drivers are there as if they have been installed.
     
  28. thisisu

    thisisu Malware Consultant

    Let's do this so I can try to see what files/drivers are present now:

    [​IMG] Now download the latest MGtools.exe to the root of your c: drive.
    • Replace your existing MGtools.exe with this one.
    • Now run this new MGtools.exe by double-clicking it. (Vista/7 right-click and select Run as Administrator)
    • When it is finished, attach c:\MGlogs.zip to your next message. (How to attach)

    Also let me know if you are still experiencing BSODs or not.
     
  29. dutchluck13

    dutchluck13 Private E-2

    Here you go
     

    Attached Files:

  30. thisisu

    thisisu Malware Consultant

    You ran a much older version of TDSSKiller before:

    [​IMG] I want you to read and follow these instructions: TDSSKiller - How to run

    [​IMG] Please download Disable/Remove Windows Messenger to your desktop.
    • Double-click MessengerDisable.exe to run it.
    • Place checkmarks in "Uninstall Windows Messenger" and "Hide Messenger from Outlook Express"
    • Click Apply
    • Click Exit

    [​IMG] Fix items using OTL by OldTimer

    Double-click OTL.exe to run. (Vista/7 right-click and select Run as Administrator)
    Shut down your protection software now (antivirus, antispyware...etc) to avoid possible conflicts.
    Copy the text in the code box below and paste it into the [​IMG] text-field.
    Code:
    [COLOR="DarkRed"]:files[/COLOR]
    C:\Documents and Settings\Admin Tyler\Local Settings\Application Data\2509137411
    C:\Documents and Settings\Admin Tyler\Local Settings\Application Data\3469191438
    C:\Documents and Settings\Admin Tyler\Local Settings\Application Data\3jOBub6
    C:\Documents and Settings\Admin Tyler\Local Settings\Application Data\50vGiJ1FW7x2
    C:\Documents and Settings\Admin Tyler\Local Settings\Application Data\8MuP2
    C:\Documents and Settings\Admin Tyler\Local Settings\Application Data\G2MJ
    C:\Documents and Settings\Admin Tyler\Local Settings\Application Data\MF62
    C:\Documents and Settings\Admin Tyler\Y¯Y¯
    C:\Documents and Settings\Admin Tyler\Y9Y9
    C:\Documents and Settings\Admin Tyler\Local Settings\Application Data\avG
    C:\Documents and Settings\Admin Tyler\Local Settings\Application Data\jfpies
    C:\Documents and Settings\Admin Tyler\Local Settings\Application Data\{3248F0A6-6813-11D6-A77B-00B0D0150060}
    xcopy %temp%\smtmp\1 "%allusersprofile%\start menu" /s /i /h /y /c
    xcopy %temp%\smtmp\2 "%userprofile%\application data\microsoft\internet explorer\quick launch" /s /i /h /y /c
    xcopy %temp%\smtmp\3 "%appdata%\roaming\microsoft\internet explorer\quick launch\user pinned\taskbar" /s /i /h /y /c
    xcopy %temp%\smtmp\4 "%allusersprofile%\desktop" /s /i /h /y /c
    C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\*.dat
    C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Last Active\*.dat
    C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows Media Player NSS\3.0\*.xml
    C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Internet Explorer\DOMStore\9J2JWIGZ\*.xml
    C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Internet Explorer\DOMStore\GV3D89DS\*.xml
    C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Internet Explorer\DOMStore\NZFHW4JO\*.xml
    C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Internet Explorer\DOMStore\SCXGZ397\*.xml
    C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\*.xml
    C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Last Active\*.xml
    C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows Media Player NSS\3.0\Icon Files\*.jpg
    C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows Media Player NSS\3.0\Icon Files\*.png
    [COLOR="DarkRed"]:commands[/COLOR]
    [purity]
    [emptytemp]
    
    Now click the [​IMG] button.
    If the fix needed a reboot please do it.
    Click the OK button (upon reboot).
    When OTL is finished, Notepad will open. Close Notepad.
    A log file will be located at C:\_OTL\MovedFiles\mmddyyyy_hhmmss.log, where mmddyyyy_hhmmss is the date of the tool run.
    Attach this log to your next message. (How to attach)
    Note: This file could be very large, in which case you should zip this file up and then attach it.

    Put your computer back into Normal Startup Mode and reboot before proceeding to the next step. See >> Use MSconfig to setup for Normal Startup Mode

    [​IMG] Please delete your old copy of ComboFix.
    Now download a new copy of ComboFix.exe and run it. Attach the latest log when finished. (How to attach)

    [​IMG] Now run C:\MGtools\GetLogs.bat by double-clicking it.
    This updates all of the logs inside MGlogs.zip.
    When it is finished, attach C:\MGlogs.zip to your next message. (How to attach)
     
  31. dutchluck13

    dutchluck13 Private E-2

    Here are all the logs. In the time before running everything I had two more BSODs same as before; related to the connection driver. Then I got the same BSOD twice more while trying to run GetLogs.bat. I attached the BSOD log aswell.
     

    Attached Files:

  32. dutchluck13

    dutchluck13 Private E-2

    BSOD log
     

    Attached Files:

  33. thisisu

    thisisu Malware Consultant

    [​IMG] Scan with TDSSKiller again
    When you find: TDSS File System
    Delete it!
    Leave everything else detected alone (Skip)
    Then attach the new TDSSKiller log.

    Download and run Norton Removal Tool to remove the remaining traces of Norton.

    Reboot afterwards.

    Once you have rebooted...

    [​IMG] Fix items using OTL by OldTimer

    Double-click OTL.exe to run. (Vista/7 right-click and select Run as Administrator)
    Shut down your protection software now (antivirus, antispyware...etc) to avoid possible conflicts.
    Copy the text in the code box below and paste it into the [​IMG] text-field.
    Code:
    [COLOR="DarkRed"]:processes[/COLOR]
    killallprocesses
    [COLOR="DarkRed"]:files[/COLOR]
    C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\*.dat
    C:\WINDOWS\System32\drivers\tcpip.sys|c:\windows\system32\dllcache\tcpip.sys /replace
    C:\WINDOWS\Tasks\PCDoctorBackgroundMonitorTask.job
    
    Now click the [​IMG] button.
    If the fix needed a reboot please do it.
    Click the OK button (upon reboot).
    When OTL is finished, Notepad will open. Close Notepad.
    A log file will be located at C:\_OTL\MovedFiles\mmddyyyy_hhmmss.log, where mmddyyyy_hhmmss is the date of the tool run.
    Attach this log to your next message. (How to attach)

    [​IMG] Now run C:\MGtools\GetLogs.bat by double-clicking it.
    This updates all of the logs inside MGlogs.zip.
    When it is finished, attach C:\MGlogs.zip to your next message. (How to attach)
     
  34. thisisu

    thisisu Malware Consultant

    After you get done with the above, I would also like you to scan with the below:

    [​IMG] Please download aswMBR to your desktop.
    • Double-click aswMBR.exe to run (Vista/7 right-click and select Run as Administrator)
    • Select No when asked "Would you like to download latest Avast! virus definitions?"
    • Click the [Scan] button.
    • On completion of the scan click [Save log], save it to your desktop and attach this log to your next message. (How to attach)
     
  35. dutchluck13

    dutchluck13 Private E-2

    Here are all the new logs.
     

    Attached Files:

  36. thisisu

    thisisu Malware Consultant

    There is a problem with the MGlogs.zip you uploaded.

    Please try again using these instructions:

    [​IMG] Now download the latest MGtools.exe to the root of your c: drive.
    • Replace your existing MGtools.exe with this one.
    • Now run this new MGtools.exe by double-clicking it. (Vista/7 right-click and select Run as Administrator)
    • When it is finished, attach c:\MGlogs.zip to your next message. (How to attach)
     
  37. thisisu

    thisisu Malware Consultant

    I'd like to restore a clean Master Boot Record (MBR) to your system. I must ask, do you have your data backed up? Sometimes attempting to repair the MBR can cause boot issues. I'll work with you to resolve any potential booting issue if that does occur. It is quite rare though.

    Let me know whenever you get a chance.
     
  38. dutchluck13

    dutchluck13 Private E-2

    Here's the MGlogs. I'll have a go at MBR repair later tomorrow.
     

    Attached Files:

  39. thisisu

    thisisu Malware Consultant

    Back up your data first just incase:

    Whenever you are ready to attempt to fix the MBR:

    [​IMG] Open aswMBR again
    Click the FixMBR button. Reboot.
    Then scan with aswMBR again and attach its latest log.

    Also attach any new .dmp files from c:\windows\minidump
     
  40. dutchluck13

    dutchluck13 Private E-2

    I haven't had a chance to try and fix the MBR yet. But, I should get to it sometime at the beginning of this week.
     
  41. thisisu

    thisisu Malware Consultant

    No problem. Take your time.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds