Hello and welcome to
Computer Hope Forum. My name is Dave. I will be helping you out with your particular problem on your computer. I am working under the guidance of one of the specialist of this forum so it may take a bit longer to process your logs.
1. I will be working on your
Malware issues. This
may or may not solve other issues you have with your machine.
2. The fixes are specific to your problem and should only be used for this issue on this machine.
3. If you don't know or understand something, please don't hesitate to ask.
4. Please
DO NOT run any other tools or scans while I am helping you.
5. It is important that you reply to this thread. Do not start a new topic.
6. Your security programs may give warnings for some of the tools I will ask you to use. Be assured, any links I give are safe.
7. Absence of symptoms does not mean that everything is clear.
SUPERAntiSpyware Download
SuperAntispyware Free Edition (SAS)* Double-click the icon on your desktop to run the installer.
* When asked to
Update the program definitions, click
Yes* If you encounter any problems while downloading the updates, manually download and unzip them from here
* Next click the
Preferences button.
•Under
Start-Up Options uncheck
Start SUPERAntiSpyware when Windows starts
* Click the
Scanning Control tab.
* Under Scanner Options make sure only the following are checked:
•Close browsers before scanning
•Scan for tracking cookies
•Terminate memory threats before quarantining
•
Please leave the others unchecked•Click the
Close button to leave the control center screen.
* On the main screen click
Scan your computer* On the left check the box for the drive you are scanning.
* On the right choose
Perform Complete Scan* Click
Next to start the scan. Please be patient while it scans your computer.
* After the scan is complete a summary box will appear. Click
OK* Make sure everything in the white box has a
check next to it, then click
Next* It will quarantine what it found and if it asks if you want to reboot, click
Yes•To retrieve the removal information please do the following:
•After
reboot, double-click the
SUPERAntiSpyware icon on your desktop.
•Click
Preferences. Click the
Statistics/Logs tab.
•Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
•It will open in your default text editor (preferably
Notepad).
•Save the notepad file to your desktop by clicking (in notepad) File > Save As...
* Save the log somewhere you can easily find it. (normally the desktop)
* Click close and close again to exit the program.
*
Copy and Paste the log in your post
=====================================
Malwarebytes' Anti-Malware (MBAM)
If you already have Malwarebytes delete it and download the latest versionDownload
Malwarebytes Anti-Malware and save it to your desktop.
Alternate download link•Double-click
mbam-setup.exe and follow the prompts to install the program.
•Be sure a
checkmark is placed next to
Update Malwarebytes' Anti-Malware and
Launch Malwarebytes' Anti-Malware, then click
Finish.•
If you encounter any problems while downloading the updates, manually download them from here and just double-click on mbam-rules.exe to install.
•If an update is found, it will download and install the latest version.
•Once the program has loaded, select
Perform Quick Scan, then click
Scan.•When the scan is complete, click
OK, then
Show Results to view the results.
•Be sure that everything is
checked, and click
Remove Selected.•When completed, a log will open in
Notepad. Save it to a convenient location like the Desktop.
•The log is also automatically saved and can be viewed later by clicking the
Logs tab in
MBAM.•
Copy and Paste the contents of the report in your reply.
•Exit
MBAM..
Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.
===================================
Download
Disable/Remove Windows Messenger to the desktop to remove Windows Messenger.
Do not confuse
Windows Messenger with
MSN Messenger because they are not the same.
Windows Messenger is a frequent cause of popups.
Unzip the file on the desktop. Open the
MessengerDisable.exe and choose the bottom box -
Uninstall Windows Messenger and click
Apply.Exit out of
MessengerDisable then delete the two files that were put on the desktop.
=====================================
You have
Viewpoint installed.
Viewpoint Media Player/Manager/Toolbar is considered as
Foistware instead of malware since it is installed without users approval but doesn't spy or do anything "bad".
More information:
*
ViewMgr.exe - Useless*
Viewpoint to Plunge Into AdwareIt is suggested to remove the program now. Go to
Start > Control Panel > Add/Remove Programs - (Vista & Win7 is
Programs and Features) and remove the following programs if present.
* Viewpoint
* Viewpoint Manager
* Viewpoint Media Player
* Viewpoint Toolbar
* Viewpoint Experience Technology===================================
P2P - I see you have P2P software installed on your machine.
(BitTorrent) We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infections. It is certainly contributing to your current situation.
Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares.
I would strongly recommend that you uninstall them, however that choice is up to you. If you choose to remove these programs, you can do so via
Control Panel >> Add or Remove Programs.======================================
Open
HijackThis and select
Do a system scan onlyPlace a check mark next to the following entries: (if there)
O20 - AppInit_DLLs: C:\WINDOWS\system32\0034.DLLImportant: Close all open windows except for
HijackThis and then click
Fix checked.Once completed, exit
HijackThis.=================================
Copy and paste the text in the code box below into Notepad.
del
C:\WINDOWS\system32\0034.DLL
exit
Then click File > Save as
Save to the Desktop as
blackpudding.batAnd Save as type: All Files.
Double-click on
blackpudding.bat to run it. It will only take a few seconds to run.
Next post please include the MBAM, SAS and a new HJT log.