Good, go ahead and run Malwarebytes again, be sure to check everything it finds and select Remove Selected , it looks like you didnt do that, that stuff needs to go
Printable View
Good, go ahead and run Malwarebytes again, be sure to check everything it finds and select Remove Selected , it looks like you didnt do that, that stuff needs to go
Ken,
I removed all the infections that Malwarebytes found and also did the scan with TDSS which found no infections .
The PC is still slow at booting up , could what ever it is be hiding somewhere on the system ? as the first scans temporarily cured the problem .
Gwalch .
Lets run a free online Virus Scanner, this may take a bit of time, lets see what if anything it finds
ESET Online Scanner
I'd like us to scan your machine with ESET OnlineScan
*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.
Please make sure you include the following items in your next post:
- Hold down Control and click on the following link to open ESET OnlineScan in a new window.
ESET OnlineScan- Click the http://billy-oneal.com/Canned%20Spee...esetOnline.png button.
- For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
- Click on http://billy-oneal.com/Canned%20Spee...artInstall.png to download the ESET Smart Installer. Save it to your desktop.
- Double click on the http://billy-oneal.com/Canned%20Spee...esktopIcon.png icon on your desktop.
- Check http://billy-oneal.com/Canned%20Spee...cceptTerms.png
- Click the http://billy-oneal.com/Canned%20Spee.../esetStart.png button.
- Accept any security warnings from your browser.
- Check http://billy-oneal.com/Canned%20Spee...anArchives.png
- Make sure that the option "Remove found threats" is Unchecked
- Push the Start button.
- ESET will then download updates for itself, install itself, and begin
scanning your computer. Please be patient as this can take some time.- When the scan completes, push http://billy-oneal.com/Canned%20Spee...istThreats.png
- Push http://billy-oneal.com/Canned%20Spee...esetExport.png, and save the file to your desktop using a unique name, such as
ESETScan. Include the contents of this report in your next reply.- Push the http://billy-oneal.com/Canned%20Spee...t/esetBack.png button.
- Push http://billy-oneal.com/Canned%20Spee...esetFinish.png
The log that was produced after running ESET Online Scanner.
The Eset link is not working
Sorry,
Please ignore the last post .
No problem, this sometimes gets confusing , your doing fine so far :bigthumb:
Ken,
The scan found 9 infected files by a "win32 adware cidhelp" variant .
Here is the "eset " log :-
ESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6920
# api_version=3.0.2
# EOSSerial=dc8642232a53df43b28d72cbe67875d2
# engine=15141
# end=finished
# remove_checked=true
# archives_checked=false
# unwanted_checked=false
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2013-09-15 08:39:54
# local_time=2013-09-15 09:39:54 (+0000, GMT Daylight Time)
# country="United Kingdom"
# lang=1033
# osver=5.1.2600 NT Service Pack 3
# compatibility_mode=3589 16777214 0 0 28854430 28854430 0 0
# compatibility_mode=5892 16777213 88 100 2184352 91325656 0 0
# scanned=113097
# found=9
# cleaned=9
# scan_time=3621
sh=BE96EA12536531C536C311DD27CA578B3BD631B9 ft=1 fh=fb01d7d4004b2066 vn="a variant of Win32/Adware.CiDHelp application (cleaned by deleting - quarantined)" ac=C fn="C:\Documents and Settings\Garry\Local Settings\Application Data\Google\Chrome\User Data\Default\Cache(2)\f_000002"
sh=889671DBE5E6529F2DD444A46F95350F11AC9ED3 ft=1 fh=cab42f9231be6cc0 vn="a variant of Win32/Adware.CiDHelp application (cleaned by deleting - quarantined)" ac=C fn="C:\Documents and Settings\Garry\My Documents\Downloads\MsgPlusLive-482 (1).exe"
sh=889671DBE5E6529F2DD444A46F95350F11AC9ED3 ft=1 fh=cab42f9231be6cc0 vn="a variant of Win32/Adware.CiDHelp application (cleaned by deleting - quarantined)" ac=C fn="C:\Documents and Settings\Garry\My Documents\Downloads\MsgPlusLive-482 (2).exe"
sh=889671DBE5E6529F2DD444A46F95350F11AC9ED3 ft=1 fh=cab42f9231be6cc0 vn="a variant of Win32/Adware.CiDHelp application (cleaned by deleting - quarantined)" ac=C fn="C:\Documents and Settings\Garry\My Documents\Downloads\MsgPlusLive-482 (3).exe"
sh=BE96EA12536531C536C311DD27CA578B3BD631B9 ft=1 fh=fb01d7d4004b2066 vn="a variant of Win32/Adware.CiDHelp application (cleaned by deleting - quarantined)" ac=C fn="C:\Documents and Settings\Garry\My Documents\Downloads\MsgPlusLive-482 (4).exe"
sh=BE96EA12536531C536C311DD27CA578B3BD631B9 ft=1 fh=fb01d7d4004b2066 vn="a variant of Win32/Adware.CiDHelp application (cleaned by deleting - quarantined)" ac=C fn="C:\Documents and Settings\Garry\My Documents\Downloads\MsgPlusLive-482 (5).exe"
sh=BE96EA12536531C536C311DD27CA578B3BD631B9 ft=1 fh=fb01d7d4004b2066 vn="a variant of Win32/Adware.CiDHelp application (cleaned by deleting - quarantined)" ac=C fn="C:\Documents and Settings\Garry\My Documents\Downloads\MsgPlusLive-482 (6).exe"
sh=889671DBE5E6529F2DD444A46F95350F11AC9ED3 ft=1 fh=cab42f9231be6cc0 vn="a variant of Win32/Adware.CiDHelp application (cleaned by deleting - quarantined)" ac=C fn="C:\Documents and Settings\Garry\My Documents\Downloads\MsgPlusLive-482.exe"
sh=7F1997770D8956265C8FE12980E432E688BD641E ft=1 fh=e2022e4e4bbab66b vn="multiple threats (cleaned by deleting - quarantined)" ac=C fn="C:\Documents and Settings\Shannon\My Documents\PageRageSetup.exe"
I have re-booted the PC several times now and it is back to normal. Will let you know tomorrow if it is still ok.
I would like to thank for advising with me with removing this crap off my computer , your efforts are very much appreciated .
Best regards
Gary
Hello Gary,
Lets just hang off until tomorrow, use your computer normally and see if all is ok, then we can go from there
So far the PC is behaving ok . I have done 4 boot up's today and the problem has not returned .