WiredWX Christian Hobby Weather Tools
Would you like to react to this message? Create an account in a few clicks or log in to continue.

WiredWX Christian Hobby Weather ToolsLog in

 


descriptionI have no idea what I'm infected with EmptyI have no idea what I'm infected with

more_horiz
As the title of the thread states, I have no idea what I'm infected with.

When I attempt to run some (note, not all) *.exe files (in this example I'll use "install_reader10_en_mssd_aih.exe" - the executable to install Acrobat Reader), the "Open File - Security Warning" box pops up, and I select "Run".

I have no idea what I'm infected with 1-1

Then, comes the expected UAC prompt, to which I click yes.

Immediately following that, the "install_reader10_en_mssd_aih.exe" file disappears from my desktop. I've check to see if it goes to the Recycling Bin, and it doesn't.

The install program doesn't run. No application starts in the Task Manager, however a process does run, for about 20 seconds.

I have no idea what I'm infected with 2


I've checked Norton, it isn't flagging the file and quarantining it or anything else crazy.

I'm running Windows 7 Version 6.1 (Build 7601: Service Pack 1) and Norton Antivirus 19.7.0.9.
Hardware system specs (if at all pertinent) can be found in my profile.

I've already installed and scanned with Malwarebytes Anti-Malware before I even found myself here, as well as with Spybot S&D, and came up with no positive threats (false or otherwise).

The following posts will contain the log files requested by the "Read This Before Posting" thread (split into multiple posts thanks to the character limit).

Any help or insight anyone has to offer would be much appreciated.

descriptionI have no idea what I'm infected with EmptyRe: I have no idea what I'm infected with

more_horiz
From OTL.scr:

OTL.txt
Spoiler :

descriptionI have no idea what I'm infected with EmptyRe: I have no idea what I'm infected with

more_horiz
From OTL.scr:

OTL.txt (cont)
Spoiler :

descriptionI have no idea what I'm infected with EmptyRe: I have no idea what I'm infected with

more_horiz
From OTL.scr:

Extras.txt
Spoiler :

descriptionI have no idea what I'm infected with EmptyRe: I have no idea what I'm infected with

more_horiz
From aswMBR.exe:

aswMBR
Spoiler :

descriptionI have no idea what I'm infected with EmptyRe: I have no idea what I'm infected with

more_horiz
From SecurityCheck.exe:

checkup.txt
Spoiler :

descriptionI have no idea what I'm infected with EmptyRe: I have no idea what I'm infected with

more_horiz
Here is something fairly alarming as well, here is a complete showing of all the processes currently running on this system:

I have no idea what I'm infected with 3

And here is the performance tab:

I have no idea what I'm infected with 4

1.7 GB of RAM being chewed up? Whoa!

By the time I finished drafting this post, it was up to 2.14 GB being used. I'll perform a system restart and report back the results.

descriptionI have no idea what I'm infected with EmptyRe: I have no idea what I'm infected with

more_horiz
A system restart has seemed to help at least a little bit. With Quickbooks and Firefox both running the system is using 1.3 GB of RAM - still high for my liking but much more tolerable.

descriptionI have no idea what I'm infected with EmptyRe: I have no idea what I'm infected with

more_horiz
Let's start with ComboFix:

Please visit this webpage for a tutorial on downloading and running ComboFix:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

See the area: Using ComboFix, and when done, post the log back here.

descriptionI have no idea what I'm infected with EmptyRe: I have no idea what I'm infected with

more_horiz
Done.

From ComboFix.exe:

log.txt
Spoiler :


I've had to switch to a different system to write this post. When I try to open anything on the system we are working on I get the following error:

"Illegal operation attempted on a registry key that has been marked for deletion."

I can't even get into regedit, command prompt, explorer... nothing.

I hope you can walk me through the process of rolling back to that restore point that ComboFix created... Please (puppy eyes)

I'm afraid to restart the system or do anything until I get confirmation from someone on what I should do.

descriptionI have no idea what I'm infected with EmptyRe: I have no idea what I'm infected with

more_horiz
I've managed to get into explorer on the other system, but nothing else has changed. I'm not able to open anything... Let me think

descriptionI have no idea what I'm infected with EmptyRe: I have no idea what I'm infected with

more_horiz
Toad` wrote:
I'm afraid to restart the system or do anything until I get confirmation from someone on what I should do.

Never mind that, there isn't much on that system that isn't backed up so I got impatient and went for a restart.

I am able to open/access files and such per normal.

Still having that mysterious disappearing files problem though.

descriptionI have no idea what I'm infected with EmptyRe: I have no idea what I'm infected with

more_horiz
What do you mean by restart?

descriptionI have no idea what I'm infected with EmptyRe: I have no idea what I'm infected with

more_horiz
I restarted the computer.

Start>Shutdown>Restart.

descriptionI have no idea what I'm infected with EmptyRe: I have no idea what I'm infected with

more_horiz
Please visit this webpage for a tutorial on downloading and running ComboFix:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

See the area: Using ComboFix, and when done, post the log back here.

descriptionI have no idea what I'm infected with EmptyRe: I have no idea what I'm infected with

more_horiz
Ummm... I already did that. See Post 10 of this thread. Annoyed or Unimpress

descriptionI have no idea what I'm infected with EmptyRe: I have no idea what I'm infected with

more_horiz
I know! I want you to download a new copy of ComboFix and run it again, please...

descriptionI have no idea what I'm infected with EmptyRe: I have no idea what I'm infected with

more_horiz
Would you prefer that I not restart the system after running ComboFix this time?

descriptionI have no idea what I'm infected with EmptyRe: I have no idea what I'm infected with

more_horiz
ComboFix will decide if the system needs restarted. Therefore, depends on its choosing.

descriptionI have no idea what I'm infected with EmptyRe: I have no idea what I'm infected with

more_horiz
I won't be able to get to this until Monday morning at the earliest.

Thanks for your help thus far, I'll check back in after I get this taken care of.

descriptionI have no idea what I'm infected with EmptyRe: I have no idea what I'm infected with

more_horiz
Okay...I'll see you here then.

descriptionI have no idea what I'm infected with EmptyRe: I have no idea what I'm infected with

more_horiz
You can mark this issue as resolved.

I got fed up and reinstalled Windows and still had the same issue. Another hour or two of research turned up that it was some sort of incompatibility with Windows 7 and the current version of Adobe.

I'd link to the places where I found the solution, but I'm not sure of the policies regarding that on this forum.

Thanks for your help anyway DMJ. Right On!

descriptionI have no idea what I'm infected with EmptyRe: I have no idea what I'm infected with

more_horiz
Glad it worked.

We do our work for free. If you feel helped, please see my signature below for the donation link.

Thanks! Topic closed.

descriptionI have no idea what I'm infected with EmptyRe: I have no idea what I'm infected with

more_horiz
privacy_tip Permissions in this forum:
You cannot reply to topics in this forum