View Full Version : Problem with TrojanDownloader:Win32/Adload.DA

2012-08-16, 17:33
Hey there, this is my first post on the forum. My Windows Action Centre informed me yesterday that I had been infected with the TrojanDownloader:Win32/Adload.DA virus. It had apparently stopped my computer working properly 2 times, although I haven't actually seen any symptoms. My first reaction was to do a full scan with my antivirus software Avast! and also SuperAntiSpyware. Both of which failed to find any trace of this particular infection, although SuperAntiSpyware did find and remove several tracking cookies. After those failed I though I would seek better advice and found this forum. There is already a post relating to this virus but I though it would be best to seek advice for my own personal case. What follows are the DDS logs requested in the "before you post" section. Zipped attach.text is also included. However, the aswMBR scan doesn't complete as Windows says it encounters a problem as has to close. I hope you can help!

2012-08-21, 16:13
Do you still need help ?

2012-08-21, 17:58
Yeah, please.

2012-08-21, 18:53
Welcome to Safer Networking. I am maxi, and I will be helping you out with your malware problems.

Before we go further, there are a few things that I would like to make clear so that we are share the same understanding.

Please observe and follow these Forum Rules (http://forums.spybot.info/showthread.php?t=288).
Any advice is for your computer only and is taken at your own risk. Fixes sometimes will cause unexpected results, but I will do my best to assist you.
Please read the instructions carefully and follow them closely, in the order they are presented to you.
If you have any doubts or problems during the fix, please stop and ask.
All the tools that I will ask you to download and use are safe. Please allow if prompted by any of your security softwares.
Do not use or run any malware cleaning tools without supervision as they may cause more harm if improperly used.
Refrain from installing any new programs except those that I request during the fix to prevent interference to my diagnosis of the problem.
Lack of malware symptoms does not mean your computer is clean. Stick to this topic until I give the All Clear.
If you do not reply within 3 days, this topic will be closed.

If you are agreeable to the above, then everything should go smoothly

Create a Restore Point

Right-click on the Computer icon and select Properties.
In the left pane under Tasks ... click on System protection.
If UAC prompts for an administrator password or approval, type the password or give your "permission to continue".
Select the System Protection tab ...then choose Create.
In the System Restore dialog box, type a description for the restore point ... click Create, again.
A window will pop up with "The Restore Point was created successfully" confirmation message.
Click OK ...then close the System Restore dialog.
Please leave the System Restore function "turned on" until we are finished and I give you the 'all clean' sign.
If you have successfully created a System Restore Point...we can proceed.

Step 1
Uninstall programs
Click on Start.
All programs.
In the open text box copy/paste appwiz.cpl Then click Ok.
Uninstall the following if present.


Note: you can install this again when we are finished.

Step 2
Please download OTL (http://oldtimer.geekstogo.com/OTL.exe) by Old Timer and save it to your Desktop.

Right click on OTL.exe And select Run as administrator to run it.
Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When done, two Notepad files will open.
OTL.txt <-- Will be opened
Extras.txt <-- Will be minimized
Please post the contents of these 2 Notepad files in your next reply.

Step 3
TDSSKiller - Rootkit Removal Tool - Scan only
Please download the TDSSKiller.exe (http://support.kaspersky.com/downloads/utils/tdsskiller.exe) by Kaspersky and save it to your Desktop. <-Important!!!

Right-click on TDSSKiller.exe and select "Run As Administrator..." to run the tool for known TDSS/TDL variants.
If TDSSKiller does not run, please rename it. Right-click on TDSSKiller.exe, select Rename and give it a random name with the .com file extension (i.e. zarodinu.com).
If you don't see file extensions, please see: How to change the file extension (http://www.mediacollege.com/microsoft/windows/extension-change.html).
Click the Start Scan button. Do not use the computer during the scan!
If the scan completes with nothing found, click Close to exit.
If malicious objects are found, they will show in the "Scan results - Select action for found objects" and offer 3 options.

Please select Skip instead of Cure (default).

Then click Continue, then Close and then Close again.
A log file named TDSSKiller_version_dd.mm.yyyy_hh.mm.ss_log.txt will be created and saved to the root directory (usually Local Disk C:).
Copy and paste the contents of that file in your next reply.

In your next reply please include:
The log from TDSSKiller.
Both logs from OTL.
Any problems you had with my instructions.

2012-08-21, 23:03
Ran OTL and TDSSKiller came back clean. OTL logs to follow:

I also have a question: to what extent, if at all, does posting logs such as these online weaken my security?


OTL logfile created on: 21/08/2012 20:30:32 - Run 1
OTL by OldTimer - Version Folder = C:\Users\Dave\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

5.86 Gb Total Physical Memory | 4.10 Gb Available Physical Memory | 69.93% Memory free
11.71 Gb Paging File | 9.56 Gb Available in Paging File | 81.60% Paging File free
Paging file location(s): ?:\pagefile.sys

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 287.01 Gb Total Space | 12.46 Gb Free Space | 4.34% Space Free | Partition Type: NTFS
Drive I: | 1.96 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive J: | 997.77 Mb Total Space | 312.25 Mb Free Space | 31.29% Space Free | Partition Type: FAT

Computer Name: DAVE-VAIO | User Name: Dave | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com/ig/redirectdomain?brand=SVEC&bmod=EU01
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
IE - HKCU\..\SearchScopes,DefaultScope = {90342DB8-D648-40CB-A590-737A3BDB14A1}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKCU\..\SearchScopes\{4A9EEEAB-8F06-4913-9253-936D044B7105}: "URL" = http://uk.shopping.com/?linkin_id=8056359
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKCU\..\SearchScopes\{7368338E-88D9-42F5-9065-992DB7098EB2}: "URL" = http://www.zinio.com/search/index.jsp?s={searchTerms}&rf=sonyie8search
IE - HKCU\..\SearchScopes\{90342DB8-D648-40CB-A590-737A3BDB14A1}: "URL" = http://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7SVEC_enGB413
IE - HKCU\..\SearchScopes\{985F8478-2B26-4FC5-B078-131F4FAF27A6}: "URL" = http://rover.ebay.com/rover/1/710-42480-16445-5/4?satitle={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - user.js - File not found

FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_2_202_235.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_33: C:\Windows\SysWOW64\npdeployJava1.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Dave\AppData\Local\Google\Update\\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Dave\AppData\Local\Google\Update\\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\wrc@avast.com: C:\Program Files\AVAST Software\Avast\WebRep\FF [2012/07/08 12:41:39 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011/10/09 13:18:28 | 000,000,000 | ---D | M]

[2011/10/09 13:19:01 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Dave\AppData\Roaming\Mozilla\Extensions
[2012/06/18 10:57:34 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2011/10/22 14:55:04 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2011/11/17 20:43:34 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}
[2012/05/17 12:10:30 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0032-ABCDEFFEDCBA}
[2012/06/18 10:57:34 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}
[2011/09/29 08:09:46 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2011/09/29 02:30:22 | 000,001,538 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazon-en-GB.xml
[2011/09/29 02:16:42 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2011/09/29 02:30:22 | 000,000,947 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\chambers-en-GB.xml
[2011/09/29 02:30:22 | 000,001,180 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-en-GB.xml
[2011/09/29 02:30:22 | 000,001,135 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-en-GB.xml

========== Chrome ==========

CHR - homepage: http://www.google.com/
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Dave\AppData\Local\Google\Chrome\Application\21.0.1180.79\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Dave\AppData\Local\Google\Chrome\Application\21.0.1180.79\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Dave\AppData\Local\Google\Chrome\Application\21.0.1180.79\gcswf32.dll
CHR - plugin: Shockwave Flash (Disabled) = C:\Users\Dave\AppData\Local\Google\Chrome\User Data\PepperFlash\\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_2_202_235.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll
CHR - plugin: Java(TM) Platform SE 6 U32 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll
CHR - plugin: Java Deployment Toolkit 6.0.320.5 (Enabled) = C:\Windows\SysWOW64\npdeployJava1.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

========== Files - Modified Within 30 Days ==========

========== Files Created - No Company Name ==========

========== LOP Check ==========

2012-08-24, 20:31
Hi davman :)

I see you have run Combofix, Could you please post the log it created ? With that said I want you to please refrain from self fixing as it will not help your situation and could cause problems.

Did the Action Center give you a file and location that was infected ?

Regards maxi

2012-08-24, 20:55
hey Maxi,

I haven't run it. I just downloaded it a moved in to my desktop just in case it was required because it seemed to be a tool that your team reccommend now and then. Should I go ahead and run it now?

And no, not so far as I can see. Is there a way of finding out what file it thinks is infected?



2012-08-25, 15:42
Hi Davman, Please dont run ComboFix unless I ask you to :)

Step 1
Run OTL Script

We need to run an OTL Fix

Right click on OTL.exe and select "Run As Administrator" to run it.
Copy and Paste the following code into the http://billy-oneal.com/Canned%20Speeches/speechimages/OTL/customFix.png textbox. Do not include the word Code

ipconfig /flushdns /c


Then click the Run Fix button at the top.
Click http://billy-oneal.com/Canned%20Speeches/speechimages/OTL/btnOK.png.
OTL may ask to reboot the machine. Please do so if asked.
The report should appear in Notepad after the reboot.Copy and Paste that report in your next reply.

Step 2
Malwarebytes' Anti-Malware (Decline the trial when offered- You can try it if you wish after we're done)

Please download Malwarebytes' Anti-Malware (http://www.malwarebytes.org/mbam-download.php) and save to your desktop.

Right-click mbam-setup.exe And select " Run as administrator " then follow the prompts to install the program.
At the end, be sure a checkmark is placed next to:
Update Malwarebytes' Anti-Malware
Launch Malwarebytes' Anti-Malware
Then click Finish.
If an update is found, it will download and install the latest version.
Once the program has loaded, select Perform Quick Scan, then click Scan.
When the scan is complete, click OK, then Show Results to view the results.
Check all items except items in the C:\System Volume Information folder... and click Remove Selected.
Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.
When completed, a log will open in Notepad. Please copy and paste the log back into your next reply
The log can also be found here:
C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-date (time).txt

Step 3
ESET online scannner

Note: You can use either Internet Explorer or Mozilla FireFox for this scan.

Note: If you are using Windows Vista or Windows 7, open your browser by right-clicking on its icon and select 'Run as administrator' to perform this scan.
First please Disable any Antivirus you have active, as shown in This topic (http://www.techsupportforum.com/security-center/virus-trojan-spyware-help/490111-how-disable-your-security-applications.html).
Note: Don't forget to re-enable it after the scan.
Next hold down Control then click on the following link to open a new window to ESET online scannner (http://www.eset.com/us/online-scanner/run)
Select the option YES, I accept the Terms of Use then click on Start.

Note: If using Mozilla Firefox you will need to download esetsmartinstaller_enu.exe when prompted then double click on it to install.
All of the below instructions are compatible with either Internet Explorer or Mozilla FireFox.
When prompted allow the Add-On/Active X to install.
Make sure that the option Remove found threats is NOT checked, and the option Scan archives is checked.
Now click on Advanced Settings and select the following: Scan for potentially unwanted applications
Scan for potentially unsafe applications
Enable Anti-Stealth Technology Now click on Start.
The virus signature database... will begin to download. Be patient this make take some time depending on the speed of your Internet Connection.
When completed the Online Scan will begin automatically.
Do not touch either the Mouse or keyboard during the scan otherwise it may stall.
When completed select Uninstall application on close if you so wish, make sure you copy the logfile first!
Now click on Finish.
Use notepad to open the logfile located at C:\Program Files\ESET\EsetOnlineScanner\log.txt.
Copy and paste that log as a reply to this topic.

In your next reply please include:
The OTL logfile.
The Malwarebytes log.
The eset log.
Any problems you had with my instructions.

Regards maxi :red:

2012-08-25, 20:43
Hey Maxi,

Here are the logs you requested. The ESET logfile seemed to be really empty despite apparently finding 4 infections? I have included the text export of the details of these infections according to ESET.

1./ New OTL Log:

2./ M-Bytes Log:

3./ ESET Logs and Info:

2012-08-26, 12:49
Hi Davman :) How is your computer running now ? Are you still seeing the warning ?

Run OTL Script

We need to run an OTL Fix

Right click on OTL.exe and select "Run As Administrator" to run it.
Copy and Paste the following code into the http://billy-oneal.com/Canned%20Speeches/speechimages/OTL/customFix.png textbox. Do not include the word Code

ipconfig /flushdns /c
C:\Users\Dave\Downloads\Programs and Installers\avc-free.exe
C:\Users\Dave\Downloads\Programs and Installers\FLVPlayerSetup.exe
C:\Users\Dave\Downloads\Programs and Installers\winamp5621_full_emusic-7plus_all.exe


Then click the Run Fix button at the top.
Click http://billy-oneal.com/Canned%20Speeches/speechimages/OTL/btnOK.png.
OTL may ask to reboot the machine. Please do so if asked.
The report should appear in Notepad after the reboot.Copy and Paste that report in your next reply.


Security Check

Please download Security Check by screen317 from one of the links below:
Link 1 (http://screen317.spywareinfoforum.org/SecurityCheck.exe)
Link 2 (http://screen317.changelog.fr/SecurityCheck.exe)
Save it to your Desktop.
Right click SecurityCheck.exe And select " Run as administrator " , then follow the onscreen instructions inside of the black box.
A Notepad document should open automatically called checkup.txt
Please post the contents of that document.

In your next reply please include:
The answer to my question.
The new OTL log.
The Security Check log.

Regards maxi .)

2012-08-26, 14:18
Hey Maxi,

Yeah, the message is still displayed in the action centre, although I have not really seen any sign of infection before or after the message appeard. However, I have been using the Linux partition on my HDD to post these messages and for general use to avoid letting the virus do too much damage so I haven't exactly had much oppertunity to see symptoms except for when I run the tools you reccomend.

Here are the logs you requested...

OTL Log:

Checkup Results:

Results of screen317's Security Check version 0.99.46
Windows 7 Service Pack 1 x64 (UAC is enabled)
Internet Explorer 9
``````````````Antivirus/Firewall Check:``````````````
Windows Firewall Enabled!
avast! Antivirus
Antivirus up to date!
`````````Anti-malware/Other Utilities Check:`````````
Malwarebytes Anti-Malware version
Java(TM) 6 Update 33
Java version out of Date!
Adobe Reader X (10.1.4)
Mozilla Firefox (7.0.1)
Google Chrome 21.0.1180.79
Google Chrome 21.0.1180.83
Google Chrome Plugins...
````````Process Check: objlist.exe by Laurent````````
AVAST Software Avast AvastSvc.exe
AVAST Software Avast AvastUI.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C: 3%
````````````````````End of Log``````````````````````

2012-08-27, 12:26
Hi Davman, Sorry for the delay.

Delete the Copy of aswMBR from your computer and follow the instructions below :)

Please download RogueKiller (http://www.sur-la-toile.com/RogueKiller/RogueKiller.exe) by Tigzy and save it to your desktop.
Allow the download if prompted by your security software and please close all your programs.
Right click on RogueKiller.exe and select " Run as administrator " to run it.
If it does not run, please try a few times.
Wait for PreScan to finish, then click on Scan.
Once completed, a log called RKreport[1].txt will be created on the desktop. It can also be accessed via the Report button.
Please copy and paste the contents of that log in your next reply.


Please download aswMBR (http://public.avast.com/~gmerek/aswMBR.exe) and save it to your Desktop.
Right click aswMBR.exe & choose "Run as Administrator" to run it.
Click Yes to the prompt to download Avast! virus definitions.
(Please be patient whilst the virus definitions download)
With the AVscan set to Quick Scan, click the Scan button.
(Please be patient whilst your computer is scanned.)
After a while when the scan reports "Scan finished successfully", click Save log & save the log to your desktop.
Click OK > Exit.
Note: Do not attempt to fix anything at this stage!
Two files will be created, aswMBR.txt & a file named MBR.dat.
MBR.dat is a backup of the MBR(master boot record), do not delete it..
I strongly suggest you keep a copy of this backup stored on an external device.
Copy & Paste the contents of aswMBR.txt into your next reply.

Please Post both logs in your next reply :)

2012-08-27, 14:36
Hi Maxi,

Don't worry about the delay. Everyone needs a Sunday off ;)

RK ran fine and I have included the report. However, aswMBR failed both times I tried to run it. Soon after starting to scan C:\users\dave The message avast! Antirootkit has stopped working appears and the program closes.

Here is the RK report:

2012-08-27, 14:55
Hi :)

I need you to run roguekiller again, When the scan completes I need you to Untick the lines below

[HJ DESK] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> FOUND
[HJ DESK] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND

Then select the Delete button and post back the log that is created.

Try to run aswMBR again.

Regards maxi :)

2012-08-27, 15:39
Okay sure!

Quick question though before I do:

Is it okay to run these progams while disconnected from the internet?



2012-08-27, 16:17
Yes :D:

2012-08-27, 17:30
Hey there,

aswMBR is still not able to complete. Same message appears at the same point.



2012-08-27, 22:33
Ok Davman, Please delete the current copy of ComboFix from your computer and follow the instructions below.

Download and Run ComboFix

Please download ComboFix from the following link.

Link 1. (http://download.bleepingcomputer.com/sUBs/ComboFix.exe)

**IMPORTANT !!! Save ComboFix.exe to your Desktop**

Please disable any Antivirus and Firewall you have active, as shown in this topic (http://www.bleepingcomputer.com/forums/topic114351.html). Please close all open application windows.
Double click on ComboFix.exe and follow the prompts.
When finished, it shall produce a log for you. Please include the contents of C:\ComboFix.txt in your next reply
A word of warning: Neither I nor sUBs are responsible for any damage you may cause to your machine by running ComboFix on your own. This tool is not a toy and not for everyday use!
ComboFix SHOULD NOT be used unless requested by a forum helper.

Please post the log in your next reply :)

2012-08-29, 13:19
Hey Maxi,

Sorry for the break in contact. Here is the ComboFix log:



2012-08-29, 17:16
Hi davman :)

Step 1
Please download MiniToolBox.exe (http://download.bleepingcomputer.com/farbar/MiniToolBox.exe) and save it to your Desktop.

Right click MiniToolBox and select " Run as administrator " to run it.
Check the following in the list:
Flush DNS.
Report IE proxy settings.
Reset IE proxy settings.
Report FF Proxy Settings
Reset FF Proxy Settings
List Winsock Entries
List Installed Programs
List Users, Partitions and Memory size
List contents of Hosts.
List IP Configuration.
List last 10 Event Viewer Errors.
List Windows version, partitions, and memory size.
Click Go.
A file name Result.txt will be created in the same location where you downloaded MiniToolBox.exe
Please post the contents of the Result.txt in your next Reply.

Step 2
Please download Farbar Service Scanner (http://www.bleepingcomputer.com/download/farbar-service-scanner/dl/62/) and save it to your Desktop.
Double click FSS.exe to run it.
Press the "Scan" button.
When finished, a text file named FSS.txt will be created on your desktop. (Same folder the tool is run).
Please copy and paste the contents of the FSS.txt log to your next reply.

Step 3

adware cleaner (http://general-changelog-team.fr/fr/downloads/finish/20-outils-de-xplode/2-adwcleaner)

Launch it click on Delete

post the generated log

In your next reply please include:
The minitoolbox log.
The FSS log.
The adware cleaner log.
If you can run aswmbr now ?
If the message is still there

Regards maxi :)

2012-08-30, 13:00
Hello Maxi,

The message is still present in he Action Centre and, hacing run all the programs from your last post, aswMBR is still failing at the same point in it's scan.

What are your thoughts about the infection at this point since it seems to be hard to detect?

Here are the logs you requested:

ADWCleaner Report:

FSS Log:

MiniToolBox Report:

Pinging with 32 bytes of data:
========================= Event log errors: ===============================

=========================== Installed Programs ============================

========================= Memory info: ===================================

2012-08-31, 00:42
Hi davman :)

What are your thoughts about the infection at this point since it seems to be hard to detect?

I'm not too sure whats going on because your logs appear clean to me, But aswMRB wont run, This concerns me and as such I have consulted with my team. I will report back to you as soon as I can as many minds are better than mine ;)

regards maxi

2012-09-01, 12:35
Hi Davman :)

Could you take a screenshot of the message and post it here please.

Get the message up on your screen
Hold down the Function key, While still holding it down press the PRTSC key
Then open Microsoft Paint
Press the Paste button
You should then see your screenshot, Save it to your desktop
Then Post it here

Regards maxi :)

2012-09-01, 13:08
Morning Maxi,

I have attatched screenshots of aswMBR failure.



2012-09-01, 15:11
Sorry davman :oops: it was the original message from the "windows action centre" that I was after :)

2012-09-01, 16:26
Okay, sure =]

I have attached the action centre message. Clicking 'details' only shows the process of reccommended removal (which failed to remove the infection when I first discoverd the message).



2012-09-01, 21:47
Hi Davman, Thanks for the Screenshots :bigthumb:

I'm not convinced that there is any Malware on your computer as all the logs have come back Clean, It could be that it was there but is there no longer.

What I would like you to do is open up the message again in the action center and select "archive this message". Then see how the computer behaves for the next day or two and see If the message returns. I doubt it will :)

Also because it was detected by Windows I would like you to check with one of their tools.

Click on the Windows orb and type "MRT" into the box, You should see a program on the open list. Open this program and run it and see if it finds anything.

Let me know either way how you got on.

Regards maxi :)

2012-09-02, 20:35
Hi Maxi,

MRT came back clean. Like you say, it certainly is odd that the infection hasn't since turned up so I will go back to using Windows as normal and wait and see if anything unusual happens.

Thanks very much for all your help and advice. It is clear you have invested a fair amount of time in solving / investigating my problem and I feel I can trust what you have told me so thanks!

Kind regards,


2012-09-05, 17:22
Hi davman :) How are things going ?