2011-07-22, 19:46
I've received very good help here a few years back, and I'd be grateful if anybody would help me with my new problem.

My PC is a Dell Inspiron 9400 laptop with 2MB RAM running Vista service pack 2 on a T5200 Core 2 Duo processor.

I'm very close to ditching the computer and getting a new one, not least due to it's old age (4.5 years) but I'm concerned about copying any infected files to a new PC and face the same issues I'm struggling with now.

I don't have a clear indication of virus/malware after scanning multiple times with Zonealarm, Malwarebytes, Trend Micro Housecall, and Superanitspyware, but ever so often the PC will start up and some process will hog all cpu resources and leave the computer close to unresponsive - and the only remedy is to restart, which usually stops the madness.

Frequently the HD seems very busy when there should be no reason for it, and I've not always been able to pin down what caused it (various versions and potentially faulty installations of Zonealarm ISS appear to be partly responsible).

A few weeks ago the un-responsiveness got so out of hand, that I chose to restore the system to the oldests available point, and surprisingly this cleared all symptoms for a day or two - then they slowly but surely returned.

Zonealarm did report finding an unspecified trojan in autorun.inf yesterday, but also claimed to have treated it. I use a usb drive to transfer data to outside computers semi-public computers (university based).

Here's my DDS.txt:

Thank you very much for any feedback and help!


2011-07-23, 04:16
Hello McMelchior and welcome to the Safernetworking Forums .
I'm RedCar92 and my name is Bill, I'll be glad to help you with your computer problems.

Please observe these rules while we work: Read the entire procedure It is important to perform ALL actions in sequence. If you don't know, stop and ask! Don't keep going on. Please reply to this thread. Do not start a new topic. Stick with me till you're given the all clear. Malware removal can be stressful but we will clean it. Remember, absence of symptoms does not mean the infection is all gone. Don't attempt to clean your computer with any tools other than the ones I ask you to use during the cleanup process.

Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advise, this will be a team effort.
This may cause a delay, but I will do my best to keep it as short as possible.

Please bear with me, I will post back to you as soon as I can.

IMPORTANT NOTE : Please do not delete anything unless instructed to.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.

Doing so could make your pc inoperative and could require a full reinstall of your OS, losing all your programs and data.

These tools MUST be run from the executable. (.exe) every time you run them
with Admin Rights (Right click, choose "Run as Administrator")
Stay with this topic until I give you the all clean post.

2011-07-23, 20:46
Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advise, this will be a team effort.
This may cause a delay, but I will do my best to keep it as short as possible.

Please bear with me, I will post back to you as soon as I can.

Thank you very much to both you!

I'm standby until I see more instructions from you.


2011-07-24, 21:39
Greetings McMelchior,


Please download aswMBR (http://public.avast.com/~gmerek/aswMBR.exe) ( 511KB ) to your desktop.
Double click the aswMBR.exe icon to run it
Click the Scan button to start the scan
On completion of the scan, click the save log button, save it to your desktop and post it in your next reply.

You mentioned that you used a flash memory extensively. These can be great virus carriers. I would recommend this.
Download Flash_Disinfector.exe by sUBs[/b] from HERE (http://download.bleepingcomputer.com/sUBs/Flash_Disinfector.exe) and save it to your desktop. Double-click Flash_Disinfector.exe to run it and follow any prompts that may appear.
The utility may ask you to insert your flash drive and/or other removable drives including your mobile phone. Please do so and allow the utility to clean up those drives as well.
Wait until it has finished scanning and then exit the program.
Reboot your computer when done.Note: Flash_Disinfector will create a hidden folder named autorun.inf in each partition and every USB drive plugged in when you ran it. Don't delete this folder...it will help protect your drives from future infection.

If you use a flash drive it is recommended that you download and run Panda USB Vaccine from here (http://www.pandasecurity.com/homeusers/downloads/usbvaccine) . Panda USB Vaccine makes sure no viruses embed themselves in the autorun file on your USB drive, so you won't be infected by an autorun virus.

2011-07-25, 00:02
Thank you, Bill.

The log is posted at the end of this post.

Download Flash_Disinfector.exe by sUBs[/b] from HERE (http://download.bleepingcomputer.com/sUBs/Flash_Disinfector.exe) [...]

[...] download and run Panda USB Vaccine from here (http://www.pandasecurity.com/homeusers/downloads/usbvaccine)

I did run the flash_disinfector with no alerts showing up; I assume since you wrote "OR" that the second suggestion is not needed then?

Again, than you very much for helping me out!



aswMBR log:


aswMBR version Copyright(c) 2011 AVAST Software
Run date: 2011-07-24 14:49:18
14:49:18.650 OS Version: Windows 6.0.6002 Service Pack 2
14:49:18.650 Number of processors: 2 586 0xF06
14:49:18.652 ComputerName: GIRAFFE-PC UserName: Giraffe
14:49:31.207 Initialize success
14:51:41.254 AVAST engine defs: 11072401
14:51:56.729 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0
14:51:56.733 Disk 0 Vendor: Hitachi_HTS541616J9SA00 SB4OC74P Size: 152627MB BusType: 3
14:51:56.777 Disk 0 MBR read successfully
14:51:56.782 Disk 0 MBR scan
14:52:01.275 Disk 0 Windows VISTA default MBR code
14:52:01.322 Disk 0 scanning sectors +312578048
14:52:02.142 Disk 0 scanning C:\Windows\system32\drivers
14:52:30.329 Service scanning
14:52:34.648 Modules scanning
14:52:57.463 Disk 0 trace - called modules:
14:52:57.530 ntkrnlpa.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll ataport.SYS intelide.sys
14:52:57.537 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x88c3b558]
14:52:57.543 3 CLASSPNP.SYS[8b3608b3] -> nt!IofCallDriver -> [0x87dd7bc8]
14:52:57.565 5 acpi.sys[84e976bc] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0x8707ab98]
14:52:58.912 AVAST engine scan C:\Windows
14:53:08.845 AVAST engine scan C:\Windows\system32
14:56:37.176 AVAST engine scan C:\Windows\system32\drivers
14:56:54.415 AVAST engine scan C:\Users\Giraffe
16:39:32.210 AVAST engine scan C:\ProgramData
16:50:35.585 Scan finished successfully
16:56:58.566 Disk 0 MBR has been saved successfully to "C:\Users\Giraffe\Desktop\MBR.dat"
16:56:58.607 The log file has been saved successfully to "C:\Users\Giraffe\Desktop\aswMBR.txt"


2011-07-25, 02:16
Greetings McMelchior,

I see in your logs that you have Malwarebytes installed on your system.

Double click on MalwareBytes, mbam.exe to run it.
If Malwarebytes asks to update click on yes, if you are not asked.
Click on the Update tab then click on Check for updates.
After updates finish, click on the Scanner tab. Select Perform quick scan.
Click on Scan button.
When finished copy/paste the contents of mbam.txt into your next post please.

Please use Internet Explorer to download and run the following scan: Eset Online Scanner (http://www.eset.com/onlinescan/)
Place a check mark in the box YES, I accept the Terms Of Use
Click the Start button.
Now click the Install button.
Click Start. The scanner engine will initialize and update.
Do Not place a check mark in the box beside Remove found threats.
Click the Scan button. The scan will now run, please be patient.
When the scan finishes if there are any infections you will see a List of found threats.
Click Export to text file
Copy and paste the contents of the C:\Program Files\ESET\log.txt into your next reply.
If no threats are found there will be no list, this is good, just tell me that no threats were found.

Logs to post:

ESET report if available.

2011-07-25, 14:28
Hi again Bill, here are both logs:

Malwarebytes' Anti-Malware

Database version: 7268

Windows 6.0.6002 Service Pack 2
Internet Explorer 9.0.8112.16421

7/24/2011 10:45:48 PM
mbam-log-2011-07-24 (22-45-47).txt

Scan type: Quick scan
Objects scanned: 243166
Time elapsed: 20 minute(s), 54 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

ESETSmartInstaller@High as CAB hook log:
OnlineScanner.ocx - registred OK
# version=7
# iexplore.exe=9.00.8112.16421 (WIN7_IE9_RTM.110308-0330)
# OnlineScanner.ocx=
# api_version=3.0.2
# EOSSerial=687e5ce472cfcb48b677422e597e6e2d
# end=stopped
# remove_checked=false
# archives_checked=false
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2011-07-25 03:14:54
# local_time=2011-07-24 11:14:54 (-0500, Eastern Daylight Time)
# country="United States"
# lang=1033
# osver=6.0.6002 NT Service Pack 2
# compatibility_mode=1032 16777214 0 1 500100 500100 0 0
# compatibility_mode=5892 16776573 100 100 0 148171127 0 0
# compatibility_mode=8192 67108863 100 0 0 0 0 0
# compatibility_mode=9217 16776573 100 13 1314894 2518413 0 0
# scanned=1354
# found=0
# cleaned=0
# scan_time=140
esets_scanner_update returned -1 esets_gle=53251
# version=7
# iexplore.exe=9.00.8112.16421 (WIN7_IE9_RTM.110308-0330)
# OnlineScanner.ocx=
# api_version=3.0.2
# EOSSerial=687e5ce472cfcb48b677422e597e6e2d
# end=finished
# remove_checked=false
# archives_checked=false
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2011-07-25 10:33:32
# local_time=2011-07-25 06:33:32 (-0500, Eastern Daylight Time)
# country="United States"
# lang=1033
# osver=6.0.6002 NT Service Pack 2
# compatibility_mode=1032 16777214 0 1 500631 500631 0 0
# compatibility_mode=5892 16776573 100 100 0 148171658 0 0
# compatibility_mode=8192 67108863 100 0 0 0 0 0
# compatibility_mode=9217 16776573 100 13 1315425 2518944 0 0
# scanned=696613
# found=0
# cleaned=0
# scan_time=25927



2011-07-25, 22:03
Greetings Johan,
Your problems do not seem to be malware related as your logs all appear clean.
If you haven,t defragged your hard drive recently you may want to try Puran Defrag from here http://forums.whatthetech.com/index.php?showforum=126
Also you may want to do scandisk to find bad hard drive sectors that really slow down a system.
The techs at the next 2 sites may be able to help with your problem also.
Here http://forums.whatthetech.com/index.php?showforum=119 for Windows Vista problems.
Here http://forums.whatthetech.com/index.php?showforum=126 for hardware problems.

To remove Hijackthis do the following:
Click Start → Control Panel → Add or Remove Programs
Click on Hijackthis
Click on Remove
When done close all windows.
Navigate to C:\Program files\Trend Micro
Delete the Hijackthis folder.
Close all windows.

Double-click OTL.exe to start the program.
Close all other programs apart from OTL as this step will require a reboot
On the OTL main screen, press the CLEANUP button
Say Yes to the prompt and then allow the program to reboot your computer.

You should keep Malwarebytes, ERUNT, and ESET. You should update and run them on a regular basis to keep your PC clean.
Your PC looks to be All Clean from my end.

You say that occasionally your PC will be very busy at bootup. This could be a function of updating programs or a hard disk type problem.
If you haven,t defragged your hard drive recently you may want to try Puran Defrag from here http://forums.whatthetech.com/index.php?showforum=126
Also you may want to do scandisk to find bad hard drive sectors that really slow down a system

Below I have included a number of recommendations for how to protect your computer against malware infections.

It is good security practice to change your passwords to all your online accounts on a fairly regular basis, this is especially true after an infection. Refer to this Microsoft article
Strong passwords: How to create and use them (http://www.microsoft.com/protect/yourself/password/create.mspx) Then consider a password keeper (http://keepass.info/), to keep all your passwords safe.
Keep Windows updated by regularly checking their website at :
This will ensure your computer has always the latest security updates available installed on your computer.
Make Internet Explorer more secure

Click Start > Run
Type Inetcpl.cpl & click OK
Click on the Security tab
Click Reset all zones to default level
Make sure the Internet Zone is selected & Click Custom level
In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
Next Click OK, then Apply button and then OK to exit the Internet Properties page.

Download TFC to your desktop (http://oldtimer.geekstogo.com/TFC.exe)

Close any open windows.
Double click the TFC icon to run the program
TFC will close all open programs itself in order to run,
Click the Start button to begin the process.
Allow TFC to run uninterrupted.
The program should not take long to finish it's job
Once its finished it should automatically reboot your machine,
if it doesn't, manually reboot to ensure a complete clean

It's normal after running TFC cleaner that the PC will be slower to boot the first time.
WOT, Web of Trust (http://www.mywot.com/), warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:

Green to go
Yellow for caution
Red to stop

WOT has an addon available for both Firefox and IE
Keep a backup of your important files (http://www.geekstogo.com/2008/06/19/options-for-home-computer-data-backup-part-1/) - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.
ERUNT (http://www.snapfiles.com/get/erunt.html) (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.
In light of your recent issue, I'm sure you'd like to avoid any future infections. Please take a look at these well written articles:
Think Prevention. (http://users.telenet.be/bluepatchy/miekiemoes/prevention.html)
PC Safety and Security--What Do I Need?. (http://www.techsupportforum.com/security-center/general-computer-security/115548-pc-safety-security-what-do-i-need.html)

**Be very wary with any security software that is advertised in popups or in other ways. They are not only usually of no use, but often have malware in them.

Now is the time to post any questions or issues that have not been resolved for you. This thread will close a few days after last post.

Thanks for your patience and hard work.

2011-07-25, 22:20
Thanks for your efforts, Bill!

I do defrag on a regular basis, so since Dell's built-in hardware checking routines come up fine, I guess it points toward bad sectors on the HD?

In order for me to plan accordingly, do you by any chance have an estimate of how long it will take to run scandisk on my 137GB 5200 rpm HD? As I rely on my PC if it takes more than 12 - 16 hours I will need to plan accordingly :)

Again, thank you very much for investing time and effort in helping me!

Best greetings,


2011-07-25, 22:32
Johan, that scan depends, if bad sectors are found and repaired it could take quite some time, even over night. I am not really an expert on hard drives but the techs at the WTT hardware forums are pretty good. They can advise you better than I.
As much as it may be a hard disk problem, it could also be a software problem, like a program trying to update and having trouble doing so.

2011-07-25, 22:55
Thanks, Bill,
I'll try the scandisk and resort to the suggested fora if that doesn't provide more insight and improvement.

GL with your learning process, and once again thank you!


2011-07-25, 23:22
My pleasure and good luck.