Good morning,

First, thank you in advance for whatever help you can provide.

My laptop is showing the following symptoms, which I have been told are consistent with malware. I am running Windows 7 Home version.
1. Translucent icons on my desktop. They function normally (ie, they open up the appropriate file when I click on them) but I can see through them.
2. I can no longer find my "desktop" when I try to open or save a file. It's no longer listed as an option for me to save files to and I can't find it.
3. It's probably a coincidence, but I also started getting notices for "Catalyst Control Center: Host application has stopped working" on start-up right about the same time that my desktop icons went translucent and my desktop was hidden.
4. I typically run Google Chrome as my browser and it has been more unstable than usual.

I took the following steps trying to fix the problem:
a. I downloaded SpyBot but then read this post and uninstalled it.
b. I downloaded and ran the MS Malicious Software Removal Tool. No improvement.

Per the stickies in this forum I have taken the following steps:
i. I went to the ERUNT site but it was not clear to me that I should run that program in Windows 7, so I did not attempt it. Please advise.
ii. I downloaded DDS per instructions and obtained a dds.txt report and an attach.txt report. I have copied the dds.txt report into this post per instructions.
iii. However, when I try to compress the attach.txt report the only option I read under "Send to" is to send it to my E: drive; I do not have the option to send to a Compressd File and therefore seem unable to compress the report for you. I do have the attach.txt report on my desktop but since I cannot compress it I have NOT attached it in uncompressed form to this post. Please advise.

Thank you again for your assistance.

* * * * *

DDS Report - 16Feb2014

* * * * *

assMBR Log: 16Feb2014

aswMBR version Copyright(c) 2011 AVAST Software
Run date: 2014-02-16 10:57:30
10:57:30.716 OS Version: Windows x64 6.1.7601 Service Pack 1
10:57:30.716 Number of processors: 8 586 0x2A07
10:57:30.717 ComputerName: FITZGERALD-HP UserName: Fitzgerald
10:57:32.590 Initialize success
10:59:25.771 AVAST engine defs: 14021600
11:00:01.276 The log file has been saved successfully to "C:\Users\Fitzgerald\Documents\aswMBR.txt"
11:00:32.863 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
11:00:32.869 Disk 0 Vendor: TOSHIBA_ GL00 Size: 953869MB BusType: 3
11:00:32.999 Disk 0 MBR read successfully
11:00:33.007 Disk 0 MBR scan
11:00:33.018 Disk 0 Windows 7 default MBR code
11:00:33.030 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 199 MB offset 2048
11:00:33.047 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 933006 MB offset 409600
11:00:33.079 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 20560 MB offset 1911205888
11:00:33.102 Disk 0 Partition 4 00 0C FAT32 LBA MSDOS5.0 102 MB offset 1953312768
11:00:33.248 Disk 0 scanning C:\Windows\system32\drivers
11:00:43.439 Service scanning
11:01:30.237 Modules scanning
11:01:30.243 Disk 0 trace - called modules:
11:01:30.313 ntoskrnl.exe CLASSPNP.SYS disk.sys hpdskflt.sys iaStor.sys hal.dll
11:01:30.317 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8008376790]
11:01:30.320 3 CLASSPNP.SYS[fffff880011cc43f] -> nt!IofCallDriver -> [0xfffffa800826cb10]
11:01:30.324 5 hpdskflt.sys[fffff88001a6e189] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa800812e050]
11:01:32.139 AVAST engine scan C:\Windows
11:01:34.927 AVAST engine scan C:\Windows\system32
11:04:40.841 AVAST engine scan C:\Windows\system32\drivers
11:04:59.731 AVAST engine scan C:\Users\Fitzgerald
11:10:02.050 AVAST engine scan C:\ProgramData
11:14:09.344 Scan finished successfully
11:15:40.902 Disk 0 MBR has been saved successfully to "C:\Users\Fitzgerald\Documents\MBR.dat"
11:15:40.906 The log file has been saved successfully to "C:\Users\Fitzgerald\Documents\aswMBR.txt"

Please note that all instructions given are customised for this computer only, the tools used may cause damage if used on a computer with different infections.

If you think you have similar problems, please post the appropriate logs in the Malware Removal forum and wait for help.
Hi and welcome back to Safer Networking. :)

I'm Dakeyras and I am going to try to assist you with your problem. Please take note of the below:

I will start working on your Malware issues, this may or may not, solve other issues you have with your machine.
The fixes are specific to your problem and should only be used for this issue on this machine!
The process is not instant. Please continue to review my answers until I tell you your machine is clear. Absence of symptoms does not mean that everything is clear.
If you don't know, stop and ask! Don't keep going on.
Please reply to this thread. Do not start a new topic.
Refrain from running self fixes as this will hinder the malware removal process.
It may prove beneficial if you print of the following instructions or save them to notepad as I post them.
Your security programs may give warnings for some of the tools I will ask you to use. Be assured, any links I give are safe.

Before we start:

Please be aware that removing Malware is a potentially hazardous undertaking. I will take care not to knowingly suggest courses of action that might damage your computer. However it is impossible for me to foresee all interactions that may happen between the software on your computer and those we'll use to clear you of infection, and I cannot guarantee the safety of your system. It is possible that we might encounter situations where the only recourse is to re-format and re-install your operating system, or to necessitate you taking your computer to a repair shop.

Because of this, I advise you to backup any personal files and folders before you start.


What you mentioned(posted) about the current symptoms is acknowledged and I propose we work outside the actual Windows environment for the time being so I am better able to ascertain what the the root cause of the current issues may be.

So lets check if the following will reveal anything as follows...

Scan with Farbar Recovery Scan Tool:

Please download and save Farbar Recovery Scan Tool 64-Bit (http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/) to a Flash/USB drive.

Then insert the Flash/USB drive into your machine....

Enter System Recovery Options.

To enter System Recovery Options from the Advanced Boot Options:

Restart the computer.
As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
Use the arrow keys to select the Repair your computer menu item.
Select US as the keyboard language settings, and then click Next.
Select the operating system you want to repair, and then click Next.
Select your user account an click Next.

On the System Recovery Options menu you will get the following options:

Startup Repair
System Restore
Windows Complete PC Restore
Windows Memory Diagnostic Tool
Command Prompt

Select Command Prompt
In the command window type in notepad and press Enter.
The notepad opens. Under File menu select Open.
Select "Computer" and find your flash drive letter and close the notepad.
In the command window type e:\frst64.exe and press Enter Note: Replace letter e with the drive letter of your flash drive.
The tool will start to run.
When the tool opens click Yes to disclaimer.
Press Scan button.
It will make a log (FRST.txt) on the flash drive. Please copy and paste the contents of the aforementioned notepad file in your next reply.

Good morning Dakeyrus,

Thanks so much for your assistance. Your instructions were very clear and easily understood.

Following is the FRST log that you requested. FYI, after I completed the scan I had to restart my laptop in order to copy the log and send you this post. Thus, the Farber tool is no longer open but the flash drive (with the tool loaded onto it) is still in the laptop.

* * * * *

Hi. :)

Thanks so much for your assistance. Your instructions were very clear and easily understood.
You're welcome!

Following is the FRST log that you requested. FYI, after I completed the scan I had to restart my laptop in order to copy the log and send you this post. Thus, the Farber tool is no longer open but the flash drive (with the tool loaded onto it) is still in the laptop.

Not a problem, and feel free to delete FRST64(and log) from your flash drive and remove the drive from your machine etc.

Carry out the following with your machine running in Normal Mode please...

Backup the Registry:

Modifying the Registry can create unforeseen problems, so it always wise to create a backup before doing so.

Please download the installer for Registry Backup from here (http://www.bleepingcomputer.com/download/registry-backup/) or here (http://www.tweaking.com/files/setups/tweaking.com_registry_backup_setup.exe) and save to your desktop.
Right-click on tweaking.com_registry_backup_setup.exe and select Run as Administrator >> Follow the prompts for a default installation
Ensure the option Open "Tweaking.com - Registry Backup" When Install Completes is selected >> Next > >> Finish
Once the GUI(graphical user interface) has appeared/loaded:-


Click on Backup Now >> once the process is complete, similar to the below will displayed in the GUI:-

http://i280.photobucket.com/albums/kk173/Dakeyras_album2/TBRB-2.jpg (http://s280.photobucket.com/user/Dakeyras_album2/media/TBRB-2.jpg.html)

Close Tweaking.com - Registry Backup

Note: There will now be a folder at the root of the Hard-Drive named C:\RegBackup, do not delete this as it is the actual backup just created.

A tutorial for Registry Backup explaining the various features can be viewed here (http://www.malwareremoval.com/forum/viewtopic.php?f=4&t=61325).

TFC(Temp File Cleaner):

Please download TFC (http://oldtimer.geekstogo.com/TFC.exe) to the desktop,
Save any unsaved work. TFC will close all open application windows.
Right-click on TFC.exe and select Run as Administrator to run the program.
Click the Start button in the bottom left of the GUI(graphical user interface)'
If prompted, click "Yes" to reboot.

Note: Save your work. TFC will automatically close any open programs, let it run uninterrupted. It should not take longer than a couple of minutes , and may only take a few seconds. Only if needed will you be prompted to reboot.

I advise you keep TFC on the desktop after I give the all clear and run it say at least once per week as it is a very effective piece of software for cleaning out temp' files etc.

Scan with RogueKiller:

Please download RogueKiller (http://www.bleepingcomputer.com/download/roguekiller/) to your desktop

Alternate downloads are here (http://www.geekstogo.com/forum/files/file/413-roguekiller/) or here (http://www.sur-la-toile.com/RogueKiller).

Close/quit all running programs.
Right-click on RogueKiller.exe and select Run as Administrator to start the application.
Let the pre-scan complete, then click on Accept option when the disclaimer window appears.
Now click on the Scan tab back in the RogueKiller main GUI(graphical user interface).
Once the Scan has completed >> click on the Delete button >> then click on the Fix Host button.
Now click on the Fix Shortcuts button >> click on OK at the prompt.
Finally, reboot(restart) your computer(ensure you do so).
Please post All RKreport.txt text files located on your desktop in your next reply.


When completed the above, please post back the following in the order asked for:

How is your computer performing now, any further symptoms and or problems encountered ?
All requested RogueKiller logs.

