[A]Laptop problem!
-
[A]Laptop problem!
Greetings!
Im having a problem with my friends laptop itˇs acting out like when in fullscreen game it minimizes it and something comes to the screen for a split second. We canät see what it is. I did the Malware and etc scans. And here are the logs.
UPLOAD.EE - Download aswMBR.txt
UPLOAD.EE - Download DDS.txt
UPLOAD.EE - Download gmer.log
UPLOAD.EE - Download mbam-log-2011-12-01__10-28-13_.txt
UPLOAD.EE - Download Attatch.zip
I didint know with which the attach went 
Thx to Digerati for guiding me here.
Sorry, but hope u guys can help me and my friend out here.
Thanks in advance. Let me know if u need anymore info about this laptop or anything.
Last edited by ardop12; 01-12-2011 at 08:44 AM.
Reason: forgot something
-
Please, observe following rules:
- Read all of my instructions very carefully. Your mistakes during cleaning process may have very serious consequences, like unbootable computer.
- If you're stuck, or you're not sure about certain step, always ask before doing anything else.
- Please refrain from running tools or applying updates other than those I suggest.
- Never run more than one scan at a time.
- Keep updating me regarding your computer behavior, good, or bad.
- The cleaning process, once started, has to be completed. Even if your computer appears to act better, it may still be infected. Once the computer is totally clean, I'll certainly let you know.
- If you leave the topic without explanation in the middle of a cleaning process, you may not be eligible to receive any more help in malware removal forum.
- I close my topics if you have not replied in 5 days. If you need more time, simply let me know. If I closed your topic and you need it to be reopened, simply PM me.
================================================== ===
All logs have to be pasted into your reply.
-
Hello again.
It's my friends laptop and I don't know how long will it take, I go to school with him and he is pretty mad about his laptop. I think I just need a bit more time after every step and etc. So, I can't really understand atm are you talking about my other post or do you mean you will guide me here with steps?
Thanks
-
Take your time.
What I'm saying I'll not download any logs you uploaded somewhere.
You have to PASTE the content of all logs into your next reply.
-
-
No problem
-
Hello again.
Well, I have the logs. But the GMER log was totally empty, so I have nothing to paste here. And sorry about the delay. And the log (Attach) which I made again, the result was the same, in estonian. Some Error:Service control manager: a lot of like last week errors etc. But those are in estonian. And I couldn't find a way to make them english. I tihnk I need more time to translate them. If you want the log then tell me, but ill give it without the error part, which I think is very important.
Thx again for help.
-
-
Well, here goes nothin 
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-06-23.01)
.
Microsoft Windows 7 Home Premium
Boot Device: \Device\HarddiskVolume1
Install Date: 2.09.2011 7:27:28
System Uptime: 28.11.2011 14:52:24 (2 hours ago)
.
Motherboard: Hewlett-Packard | | 1605
Processor: Celeron(R) Dual-Core CPU T3500 @ 2.10GHz | CPU | 2095/800mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 281 GiB total, 202,634 GiB free.
D: is FIXED (NTFS) - 16 GiB total, 2,376 GiB free.
E: is CDROM ()
F: is CDROM ()
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
RP27: 1.11.2011 11:22:59 - Windows Update
RP28: 4.11.2011 11:14:14 - Windows Update
RP29: 8.11.2011 13:27:37 - Windows Update
RP30: 10.11.2011 1:07:10 - Windows Update
RP31: 11.11.2011 19:33:29 - Windows Update
RP33: 12.11.2011 8:11:32 - Windows Modules Installer
RP34: 23.11.2011 12:06:08 - avast! Free Antivirus Setup
RP35: 23.11.2011 21:38:18 - Windows Update
RP36: 25.11.2011 15:42:24 - Windows Update
.
==== Installed Programs ======================
.
Update for Microsoft Office 2007 (KB2508958)
ActiveCheck component for HP Active Support Library
Adobe Flash Player 10 ActiveX
Adobe Reader 9.3 - Estonian
Adobe Shockwave Player 11.5
Agatha Christie - Death on the Nile
µTorrent
avast! Free Antivirus
Bejeweled 2 Deluxe
Blackhawk Striker 2
BS Player Toolbar
BS.Player FREE
Chuzzle Deluxe
Cisco EAP-FAST Module
Cisco LEAP Module
Cisco PEAP Module
Colin McRae Rally 04
Conduit Engine
CyberLink DVD Suite
CyberLink PowerDVD 9
CyberLink YouCam
DAEMON Tools Lite
Dora's Carnival Adventure
Elisa M-internet
EMT Internet
Energy Star Digital Logo
Escape Rosecliff Island
ESU for Microsoft Windows 7
FATE
Final Drive Nitro
GameSpy Arcade
Google Chrome
GTA San Andreas
HP Advisor
HP Customer Experience Enhancements
HP Documentation
HP Game Console
HP Games
HP Power Manager
HP Quick Launch
HP Setup
HP Software Framework
HP Support Assistant
HPAsset component for HP Active Support Library
Intel(R) Control Center
Intel(R) Graphics Media Accelerator Driver
Intel(R) Rapid Storage Technology
Java Auto Updater
Java(TM) 6 Update 20
Jewel Quest - Heritage
Junk Mail filter update
LabelPrint
LightScribe System Software
Malwarebytes' Anti-Malware versioon 1.51.2.1300.
Microsoft Choice Guard
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office Excel MUI (English) 2007
Microsoft Office Excel MUI (Estonian) 2007
Microsoft Office Excel MUI (Latvian) 2007
Microsoft Office Excel MUI (Lithuanian) 2007
Microsoft Office Home and Student 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office OneNote MUI (Estonian) 2007
Microsoft Office OneNote MUI (Latvian) 2007
Microsoft Office OneNote MUI (Lithuanian) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office PowerPoint MUI (Estonian) 2007
Microsoft Office PowerPoint MUI (Latvian) 2007
Microsoft Office PowerPoint MUI (Lithuanian) 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (Estonian) 2007
Microsoft Office Proof (Finnish) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (German) 2007
Microsoft Office Proof (Latvian) 2007
Microsoft Office Proof (Lithuanian) 2007
Microsoft Office Proof (Polish) 2007
Microsoft Office Proof (Russian) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Proofing (Estonian) 2007
Microsoft Office Proofing (Latvian) 2007
Microsoft Office Proofing (Lithuanian) 2007
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared MUI (Estonian) 2007
Microsoft Office Shared MUI (Latvian) 2007
Microsoft Office Shared MUI (Lithuanian) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Suite Activation Assistant
Microsoft Office Word MUI (English) 2007
Microsoft Office Word MUI (Estonian) 2007
Microsoft Office Word MUI (Latvian) 2007
Microsoft Office Word MUI (Lithuanian) 2007
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft Works
MSVCRT
Need for Speed Underground 2
Penguins!
PhotoNow!
Plants vs. Zombies
Poker Superstars III
Polar Bowler
Polar Golfer
Power2Go
PowerDirector
Realtek Ethernet Controller Driver For Windows 7
Realtek High Definition Audio Driver
REALTEK Wireless LAN Software
Recovery Manager
Security Update for 2007 Microsoft Office System (KB2288621)
Security Update for 2007 Microsoft Office System (KB2288931)
Security Update for 2007 Microsoft Office System (KB2345043)
Security Update for 2007 Microsoft Office System (KB2553074)
Security Update for 2007 Microsoft Office System (KB2553089)
Security Update for 2007 Microsoft Office System (KB2553090)
Security Update for 2007 Microsoft Office System (KB2584063)
Security Update for 2007 Microsoft Office System (KB969559)
Security Update for 2007 Microsoft Office System (KB976321)
Security Update for Microsoft Office Excel 2007 (KB2553073)
Security Update for Microsoft Office InfoPath 2007 (KB979441)
Security Update for Microsoft Office PowerPoint 2007 (KB2535818)
Security Update for Microsoft Office PowerPoint Viewer 2007 (KB2464623)
Security Update for Microsoft Office system 2007 (972581)
Security Update for Microsoft Office system 2007 (KB974234)
Security Update for Microsoft Office Visio Viewer 2007 (KB973709)
Security Update for Microsoft Office Word 2007 (KB2344993)
Zuma Deluxe
Update for 2007 Microsoft Office System (KB2284654)
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft Office 2007 System (KB2539530)
Update for Microsoft Office OneNote 2007 (KB980729)
uTorrentBar2 Toolbar
Windows Live'i üleslaadimistööriist
Windows Live'i fotogalerii
Windows Live'i sisselogimisabimees
Windows Live Communications Platform
Windows Live Essentials
Windows Live Mail
Windows Live Messenger
Windows Live Movie Maker
Windows Live Sync
Windows Live Writer
Virtual Villagers - The Secret City
.
==== Event Viewer Messages From Past Week ========
.
28.11.2011 7:27:12, Error: Service Control Manager [7009] - Teenuse ühendamise ooteajal saabus aegumisperiood (30000 millisekundit) EMT Internet. OUC.
28.11.2011 7:27:12, Error: Service Control Manager [7000] - Teenuse EMT Internet. OUC käivitamine nurjus järgmise tõrke tõttu: Teenus ei vastanud õigeaegselt käivitus- või kontrolltaotlusele.
28.11.2011 14:52:54, Error: Service Control Manager [7009] - Teenuse ühendamise ooteajal saabus aegumisperiood (30000 millisekundit) EMT Internet. OUC.
28.11.2011 14:52:54, Error: Service Control Manager [7000] - Teenuse EMT Internet. OUC käivitamine nurjus järgmise tõrke tõttu: Teenus ei vastanud õigeaegselt käivitus- või kontrolltaotlusele.
28.11.2011 14:35:20, Error: Service Control Manager [7034] - HP Software Framework Service teenus lõpetati ootamatult. See on teinud seda 1 kord(a).
27.11.2011 12:09:10, Error: Service Control Manager [7034] - HP Software Framework Service teenus lõpetati ootamatult. See on teinud seda 1 kord(a).
27.11.2011 12:08:59, Error: Service Control Manager [7011] - Saabus aegumisperiood (30000 millisekundit)teenuse ShellHWDetection toimingu vastuse ooteajal.
27.11.2011 12:08:59, Error: Service Control Manager [7011] - Saabus aegumisperiood (30000 millisekundit)teenuse RtVOsdService toimingu vastuse ooteajal.
25.11.2011 19:50:47, Error: Service Control Manager [7009] - Teenuse ühendamise ooteajal saabus aegumisperiood (30000 millisekundit) EMT Internet. OUC.
25.11.2011 19:50:47, Error: Service Control Manager [7000] - Teenuse EMT Internet. OUC käivitamine nurjus järgmise tõrke tõttu: Teenus ei vastanud õigeaegselt käivitus- või kontrolltaotlusele.
25.11.2011 18:19:20, Error: Service Control Manager [7009] - Teenuse ühendamise ooteajal saabus aegumisperiood (30000 millisekundit) EMT Internet. OUC.
25.11.2011 18:19:20, Error: Service Control Manager [7000] - Teenuse EMT Internet. OUC käivitamine nurjus järgmise tõrke tõttu: Teenus ei vastanud õigeaegselt käivitus- või kontrolltaotlusele.
25.11.2011 17:11:10, Error: Service Control Manager [7011] - Saabus aegumisperiood (30000 millisekundit)teenuse HPWMISVC toimingu vastuse ooteajal.
25.11.2011 14:06:09, Error: Service Control Manager [7009] - Teenuse ühendamise ooteajal saabus aegumisperiood (30000 millisekundit) EMT Internet. OUC.
25.11.2011 14:06:09, Error: Service Control Manager [7000] - Teenuse EMT Internet. OUC käivitamine nurjus järgmise tõrke tõttu: Teenus ei vastanud õigeaegselt käivitus- või kontrolltaotlusele.
25.11.2011 12:03:39, Error: Service Control Manager [7009] - Teenuse ühendamise ooteajal saabus aegumisperiood (30000 millisekundit) EMT Internet. OUC.
25.11.2011 12:03:39, Error: Service Control Manager [7000] - Teenuse EMT Internet. OUC käivitamine nurjus järgmise tõrke tõttu: Teenus ei vastanud õigeaegselt käivitus- või kontrolltaotlusele.
24.11.2011 8:32:16, Error: Service Control Manager [7009] - Teenuse ühendamise ooteajal saabus aegumisperiood (30000 millisekundit) EMT Internet. OUC.
24.11.2011 8:32:16, Error: Service Control Manager [7000] - Teenuse EMT Internet. OUC käivitamine nurjus järgmise tõrke tõttu: Teenus ei vastanud õigeaegselt käivitus- või kontrolltaotlusele.
24.11.2011 21:53:10, Error: Service Control Manager [7034] - HP Software Framework Service teenus lõpetati ootamatult. See on teinud seda 1 kord(a).
24.11.2011 12:16:46, Error: Service Control Manager [7009] - Teenuse ühendamise ooteajal saabus aegumisperiood (30000 millisekundit) EMT Internet. OUC.
24.11.2011 12:16:46, Error: Service Control Manager [7000] - Teenuse EMT Internet. OUC käivitamine nurjus järgmise tõrke tõttu: Teenus ei vastanud õigeaegselt käivitus- või kontrolltaotlusele.
23.11.2011 18:54:49, Error: Service Control Manager [7034] - HP Software Framework Service teenus lõpetati ootamatult. See on teinud seda 1 kord(a).
23.11.2011 17:37:06, Error: bowser [8003] - The master browser has received a server announcement from the computer KAPO-DAD9AD3EA8 that believes that it is the master browser for the domain on transport NetBT_Tcpip_{D81EC57B-4B7B-4226-91E6-27B7CF3C0D81}. The master browser is stopping or an election is being forced.
23.11.2011 17:36:05, Error: NetBT [4319] - A duplicate name has been detected on the TCP network. The IP address of the computer that sent the message is in the data. Use nbtstat -n in a command window to see which name is in the Conflict state.
23.11.2011 14:13:13, Error: Service Control Manager [7009] - Teenuse ühendamise ooteajal saabus aegumisperiood (30000 millisekundit) EMT Internet. OUC.
23.11.2011 14:13:13, Error: Service Control Manager [7000] - Teenuse EMT Internet. OUC käivitamine nurjus järgmise tõrke tõttu: Teenus ei vastanud õigeaegselt käivitus- või kontrolltaotlusele.
23.11.2011 12:30:39, Error: Service Control Manager [7009] - Teenuse ühendamise ooteajal saabus aegumisperiood (30000 millisekundit) EMT Internet. OUC.
23.11.2011 12:30:39, Error: Service Control Manager [7000] - Teenuse EMT Internet. OUC käivitamine nurjus järgmise tõrke tõttu: Teenus ei vastanud õigeaegselt käivitus- või kontrolltaotlusele.
23.11.2011 12:03:47, Error: Service Control Manager [7009] - Teenuse ühendamise ooteajal saabus aegumisperiood (30000 millisekundit) EMT Internet. OUC.
23.11.2011 12:03:47, Error: Service Control Manager [7000] - Teenuse EMT Internet. OUC käivitamine nurjus järgmise tõrke tõttu: Teenus ei vastanud õigeaegselt käivitus- või kontrolltaotlusele.
23.11.2011 10:02:29, Error: Service Control Manager [7009] - Teenuse ühendamise ooteajal saabus aegumisperiood (30000 millisekundit) EMT Internet. OUC.
23.11.2011 10:02:29, Error: Service Control Manager [7000] - Teenuse EMT Internet. OUC käivitamine nurjus järgmise tõrke tõttu: Teenus ei vastanud õigeaegselt käivitus- või kontrolltaotlusele.
22.11.2011 14:00:26, Error: Service Control Manager [7009] - Teenuse ühendamise ooteajal saabus aegumisperiood (30000 millisekundit) EMT Internet. OUC.
22.11.2011 14:00:26, Error: Service Control Manager [7000] - Teenuse EMT Internet. OUC käivitamine nurjus järgmise tõrke tõttu: Teenus ei vastanud õigeaegselt käivitus- või kontrolltaotlusele.
21.11.2011 7:14:14, Error: Service Control Manager [7009] - Teenuse ühendamise ooteajal saabus aegumisperiood (30000 millisekundit) EMT Internet. OUC.
21.11.2011 7:14:14, Error: Service Control Manager [7000] - Teenuse EMT Internet. OUC käivitamine nurjus järgmise tõrke tõttu: Teenus ei vastanud õigeaegselt käivitus- või kontrolltaotlusele.
21.11.2011 12:16:30, Error: Service Control Manager [7034] - HP Software Framework Service teenus lõpetati ootamatult. See on teinud seda 1 kord(a).
.
==== End Of File ===========================
-
Good 
Please download ComboFix from Here or Here to your Desktop.
**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**
- Please, never rename Combofix unless instructed.
- Close any open browsers.
- Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
- Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
- Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
NOTE1. If Combofix asks you to install Recovery Console, please allow it.
NOTE 2. If Combofix asks you to update the program, always do so.
- Close any open browsers.
- WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
- Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
- If there is no internet connection after running Combofix, then restart your computer to restore back your connection.
- Double click on combofix.exe & follow the prompts.
- When finished, it will produce a report for you.
- Please post the "C:\ComboFix.txt"
**Note 1: Do not mouseclick combofix's window while it's running. That may cause it to stall
**Note 2 for AVG users: ComboFix will not run until AVG is uninstalled as a protective measure against the anti-virus. This is because AVG "falsely" detects ComboFix (or its embedded files) as a threat and may remove them resulting in the tool not working correctly which in turn can cause "unpredictable results". Since AVG cannot be effectively disabled before running ComboFix, the author recommends you to uninstall AVG first.
Use AppRemover to uninstall it: Uninstall & Remove McAfee, Symantec, Norton, AVG, Avast & More Antivirus and Security Applications and Programs
We can reinstall it when we're done with CF.
**Note 3: If you receive an error "Illegal operation attempted on a registery key that has been marked for deletion", restart computer to fix the issue.
Make sure, you re-enable your security programs, when you're done with Combofix.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~~~
NOTE.
If, for some reason, Combofix refuses to run, try one of the following:
1. Run Combofix from Safe Mode (How to...)
2. Delete Combofix file, download fresh one, but rename combofix.exe to yourname.exe BEFORE saving it to your desktop.
Do NOT run it yet.
Please download and run the below tool named Rkill (courtesy of BleepingComputer.com) which may help allow other programs to run.
There are 4 different versions. If one of them won't run then download and try to run the other one.
Vista and Win7 users need to right click Rkill and choose Run as Administrator
You only need to get one of these to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.
Rkill.com
Rkill.scr
Rkill.exe
- Double-click on the Rkill desktop icon to run the tool.
- If using Vista or Windows 7 right-click on it and choose Run As Administrator.
- A black DOS box will briefly flash and then disappear. This is normal and indicates the tool ran successfully.
- If not, delete the file, then download and use the one provided in Link 2.
- If it does not work, repeat the process and attempt to use one of the remaining links until the tool runs.
- Do not reboot until instructed.
- If the tool does not run from any of the links provided, please let me know.
Once you've gotten one of them to run, immediately run your_name.exe by double clicking on it.
If normal mode still doesn't work, run BOTH tools from safe mode.
In case #2, please post BOTH logs, rKill and Combofix.
DO NOT make any other changes to your computer (like installing programs, using other cleaning tools, etc.), until it's officially declared clean!!!