It is getting very annoying, it pops up 3 times, and every time it is at the same time. I have attached the OTL Log and the aswMBR log. Thank you for your time!
Hi omnomious
, welcome to the forum.
To make cleaning this machine easier
[*]Please do not uninstall/install any programs unless asked to
It is more difficult when files/programs are appearing in/disappearing from the logs.
[*]Please do not run any scans other than those requested
[*]Please follow all instructions in the order posted
[*]All logs/reports, etc… must be posted in Notepad. Please ensure that word wrap is unchecked. In notepad click format, uncheck word wrap if it is checked.
[*]Do not attach any logs/reports, etc… unless specifically requested to do so.
[*]If you have problems with or do not understand the instructions, Please ask before continuing.
[*]Please stay with this thread until given the All Clear. A absence of symptoms does not mean a clean machine.
Let’s se if this will get it all at once.
Please read through these instructions to familarize yourself with what to expect when this tool runs
Download ComboFix from one of these locations:
* IMPORTANT !!! Save ComboFix.exe to your Desktop
[*]Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : How to Disable your Security Programs
[*]Double click on ComboFix.exe & follow the prompts.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1.Do not mouse-click Combofix’s window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer’s settings, including making I-E the default browser.
3. If after running combofix you recieve an message “Illegal operation attempted on a registery key that has been marked for deletion” or similar reboot the computer.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
It didn’t created a .txt file, it created a folder that caused me to loop back to my Computer.
Hi omnomious,
Did combofix complete it run?
Don’t worry about the folder, it’s placed there by design.
Had to reboot and then it worked fine. I have attached the log.
Hi omnomious,
That got most of it.
Please post a new OTL log.
Download OTL to your desktop.
[*]Double click on OTL.exe to run it. Make sure all other windows are closed and to let it run uninterrupted.
[*]When the window appears, underneath Output at the top change it to Minimal Output
[*]UNCheck the boxes beside LOP Check and Purity Check.
[*]In the window under Custom Scans/Fixes copy and paste the following
/md5start
Services.*
/md5stop
[*]Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open a notepad windows, OTL.Txt no Extras.Txt this time.
It hasn’t been going crazy, so yes, thank you! I have attached the new log.
Hi omnomious,
Please follow all previous instructions regarding security programs.
Open a new Notepad session
[*]Click the Start button, click run
[*]in the run box type notepad
[*]click ok
[*]In the notepad, Click “Format” and be certain that Word Wrap is not checked.
[*]Copy and paste all the text in the code box below into the Notepad. Do Not copy the word CODE ( to ensure you get it all click the [select]
FCopy::
c:\windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe | C:\Windows\System32\services.exe
In the notepad
[*]Click File, Save as…, and set the Save in to your Desktop
[*]In the filename box, type (including quotation marks) as the filename: “CFScript.txt”
[*]Click save
Using your mouse left button, drag the new file CFscript.txt and drop it on the ComboFix.exe icon as shown below.
This will start ComboFix again.Close all browser/windows first.
Note: Do not mouseclick combofix’s window while it’s running. That may cause it to stall
http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
Please post back with the combofix log.
How’s the computer?
No alerts since we started this. I think everything is great now.
Hi omnomious,
That log looks better.
Please navigate to C:\Qoobox, locate Add-Remove Programs.txt and post it’s contents.
Next
Download and save to your desktop Malwarebytes Anti-Malware
Double Click mbam-setup.exe to install the application.
[*]Make sure a checkmark is placed next to Update Malwarebytes’ Anti-Malware and Launch Malwarebytes’ Anti-Malware, then click Finish.
[*]If an update is found, it will download and install the latest version.
[*]Once the program has loaded, select “Perform Quick Scan”, then click Scan.
[*]The scan may take some time to finish,so please be patient.
[*]When the scan is complete, click OK, then Show Results to view the results.
[*]Make sure that everything is checked, and click Remove Selected.
[]When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
[]The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
[*]Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.
Please post back with
[]add-remove programs.txt
[]MBAM log
Wasn’t around the past few days, sorry for the delay. I have done everything as requested.
Hi omnomious,
Not sure why that file would have been running.
We’ll se if MBAM was successful. Please rerun MBAM and post the log.
Next
[*]Double click on OTL.exe to run it. Make sure all other windows are closed and to let it run uninterrupted.
[*]When the window appears, underneath Output at the top change it to Minimal Output
[*]UNCheck the boxes beside LOP Check and Purity Check.
[*]In the window under Custom Scans/Fixes copy and paste the following
/md5start
Services.*
/md5stop
[*]Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open a notepad windows, OTL.Txt no Extras.Txt this time.
Plose post back with
[]MBAM log
[]OTL log