Virus detected, again......

Am having problems. Computer is slow, sometimes doesn’t want to go into ‘sleep’ mode, sometimes blank or garbled screen, unstable screen. Virus got in even though Avast running, regular Malwarebytes checks, spyware blaster running. Downloaded Immunet - it found several problems (incl Trojan) but in the end it slows down so much that the computer gets hung up and the scan doesn’t finish. Ran Dr Web CureIt, in safe mode, earlier and it found nothing. Can you help please? Thanks!

Download aswMBR.exe ( 511KB ) to your desktop.

Double click the aswMBR.exe to run it

Click the “Scan” button to start scan

http://public.avast.com/~gmerek/aswMBR1.png

On completion of the scan click save log, save it to your desktop and post in your next reply

http://public.avast.com/~gmerek/aswMBR2.png

THEN

Download OTS to your Desktop and double-click on it to run it

[*]Make sure you close all other programs and don’t use the PC while the scan runs.
[*]Select All Users
[*]Under additional scans select the following
Reg - Disabled MS Config Items
Reg - Drivers32
Reg - NetSvcs
Reg - SafeBoot Minimal
Reg - Shell Spawning
Evnt - EventViewer Logs (Last 10 Errors)
File - Lop Check

[*]Under the Custom Scan box paste this in

netsvcs
%SYSTEMDRIVE%*.exe
/md5start
explorer.exe
winlogon.exe
Userinit.exe
svchost.exe
/md5stop
%systemroot%*. /mp /s
hklm\software\clients\startmenuinternet|command /rs
hklm\software\clients\startmenuinternet|command /64 /rs
CREATERESTOREPOINT

[*]Now click the Run Scan button on the toolbar. Make sure not to use the PC while the program is running or it will freeze.
[*]When the scan is complete Notepad will open with the report file loaded in it.
[*]Please attach the log in your next post.

Essexboy, am I glad you’re still on the job… Thanks. Log attached. now on to action 2 of your instruction.

Yelp ? :rofl: ;D

OTS log attached. Thanks.

There are a few old AV drivers which I will remove, your temporary folders are very full. Did these problems occur before or after you installed immunet ?

Start OTS. Copy/Paste the information in the quotebox below into the panel where it says “Paste fix here” and then click the Run Fix button.

[Unregister Dlls]
[Win32 Services - Safe List]
YN -> (McSysmon) McAfee SystemGuards [On_Demand | Stopped] -> 
YN -> (McShield) McAfee Real-time Scanner [Unknown | Stopped] -> 
[Driver Services - Safe List]
YY -> (utmwntk1) AVZ Kernel Driver [Kernel | On_Demand | Stopped] -> C:\Windows\System32\drivers\utmwntk1.sys
[Registry - Safe List]
< Run [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
YN -> "Google EULA Launcher" -> c:\Program Files\Google\Google EULA\GoogleEULALauncher.exe [c:\Program Files\Google\Google EULA\GoogleEULALauncher.exe IE PA]
[File - Lop Check]
NY ->  AVG10 -> C:\Users\korporaal\AppData\Roaming\AVG10
[Empty Temp Folders]
[EmptyFlash]
[CreateRestorePoint]
  

The fix should only take a very short time. When the fix is completed a message box will popup telling you that it is finished. Click the Ok button and Notepad will open with a log of actions taken during the fix. Post that information back here

I will review the information when it comes back in.

Boy, the actual scenario was somewhat different. Just finshed the scan. Took hours. Frequent messages asking whether to create files that could not be found. Thousands of files were supposedly involved. jpg, png, and a couple of flash player ones. jpgs all looked like garbage. I indicated ‘skip’ for all except for flashplayer where there was no skip option and I indicated the file was not to be created. At the end it indicated that the system should be rebooted to delete the files - I clicked ‘ok’ but nothing happened. No ‘log’ showed up either. What do you think, say? Thanks.

I forgot to answer you question, sorry, no, problems already there before and I downloaded immunet as an additional option to fix.

Just ran OTS again, same protocol, now indicated either ‘cancel’ or ‘no’ when it asked whether I wanted to create a file that did not exist. The scan went very much more quickly. At the end again the message about the required reboot to delete files. And again no reboot occurred. No log visible either. Please advise oh enlightened one… Thanks.

Don’t mean to overwhelm you with posts, but just so you have the most recent status, I can see from the way my pc behaves now, that the problem is not fixed yet. Thanks.

The reason OTS took forever was because you had near 1000 files in the temp folders ;D

OK next size hammer

Download ComboFix from one of these locations:

Link 1
Link 2

* IMPORTANT !!! Save ComboFix.exe to your Desktop

[]Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
[
]Double click on ComboFix.exe & follow the prompts.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Ok, thanks. Attached. Hope this helps.

OK no malware evident at all - that is the good news

So we need to find a way to speed your system up and stop it hanging around

Please download Startup Lite from here to your desktop
Run the programme and accept the recommendations given.
Reboot and let me know if there is an improvement

If not lets check the disc out

Download and run Puran Disc Defragmenter
For the first run I would recommend a boot defrag and disk check

http://i1224.photobucket.com/albums/ee362/Essexboy3/Puran.gif

Will do and thank you!

Once done - the defrag may take a while as it runs a full chkdisc first - let me know how the system is behaving ;D

Thanks. Computer a bit better but still appears to ‘hesitate’, getting ‘hung up’, and continues to have an unstable screen. I did disc check - not FULL disc check. Will I get zapped for that? Should I immediately do the FULL Disc Check and hope my computer does not get obliterated by dragons? Thanks.

Just noticed, also have that problem still about no sleep mode kicking in. Thanks.

Yes the full disc check actually utilises the MS programme so it is safe and effective

I will have a little scout around about the sleep problem - Actually big thought do you have the system set to wake up on modem or something. I think that is the problem now I just need to find the real technical term for it ;D

You mean WOL (Wake on LAN)? Lots of programs cause a computer to not standby or go to sleep though, could be something like webshots, weatherbug, or a host of other annoying programs that cause it.

Thanks. I will do the full disc thing. No wake up set up - you’re dealing with a baby in computereze…would have no clue to even set something like that up. Doesn’t do it always either (the not going into sleep mode), does it sometimes.
One more thing please, for some time now a notification box shows up with the text “host process for windows services stopped working and was closed”. I click it away and nothing seems to happen (as in all remains as is). But no clue as to what it is or means. Any relationship with the problem you think? Thanks again.