Old October 30th, 2010, 05:12 AM
touch
touch touch is offline
Malware Removal Team
Join Date: Jan 2007
O/S: Windows XP Pro
Posts: 3,595
No problem

Please reinstall the application. If you follow my instructions, we can remove the program use a clean tool, install the program.. and see how it runs...

1. Uninstall Malwarebytes' Anti-Malware using Add/Remove programs in the control panel.
2. Restart your computer (very important).
3. Download and run this utility: mbam-clean.exe
4. It will ask to restart your computer (please allow it to).
5. After the computer restarts, install the latest version from here: mbam-download

Then go to the UPDATE tab if not done during installation and check for updates.

Restart the computer again and run a complete Scan.
Old October 30th, 2010, 02:45 PM
TexasSportsFan
Join Date: Jun 2010
O/S: Windows Vista 32-bit
Location: Fort Worth, Texas USA "Where the West Begins"
Posts: 63
Virus? Pc Is Running a bit slow I think

I've had a few minutes to try to run MBAM but I think something may be preventing it from running. Upon Install, I get (no matter in safe mode or normal mode & no matter how many times I try to download, I cannot run a scan --That error pops up before I can run it and then shuts down the application.


The system cannot find the file specified. Any advice?
Old October 30th, 2010, 09:58 PM
TexasSportsFan
Join Date: Jun 2010
O/S: Windows Vista 32-bit
Location: Fort Worth, Texas USA "Where the West Begins"
Posts: 63
Malwarebytes' Anti-Malware 1.46

Database version: 5000

Windows 6.0.6002 Service Pack 2 (Safe Mode)
Internet Explorer 9.0.7930.16406

10/30/2010 3:53:34 PM
mbam-log-2010-10-30 (15-53-34).txt

Scan type: Full scan (C:\|)
Objects scanned: 199676
Time elapsed: 28 minute(s), 3 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

The pc seems to run better (faster in safe mode) even though nothing was detected. Would installing a different A/V help besides Avast? (Not all pages are snappy, but most are). I could also just be thinking that my Lenovo Windows Vista 32bit
Intel(R) Pentium(R) Dual CPU E2180 @ 2.00GHz
2 GB Ram, 500 GB HD may just be a tad outdated? It was bought in 06. What do you suggest?
Old November 2nd, 2010, 01:50 AM
TexasSportsFan
Join Date: Jun 2010
O/S: Windows Vista 32-bit
Location: Fort Worth, Texas USA "Where the West Begins"
Posts: 63
Virus? Pc Is Running a bit slow I think

Got back to town--all is well. I await the next steps.
Old November 2nd, 2010, 07:45 AM
touch
touch touch is offline
Malware Removal Team
Join Date: Jan 2007
O/S: Windows XP Pro
Posts: 3,595
Good to hear

Please post new hijackthis log, and tell how things are running now ?
Old November 2nd, 2010, 02:47 PM
TexasSportsFan
Join Date: Jun 2010
O/S: Windows Vista 32-bit
Location: Fort Worth, Texas USA "Where the West Begins"
Posts: 63
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:29:43 AM, on 10/29/2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v9.00 (9.00.7930.16406)
Boot mode: Normal

Running processes:
C:\Program Files\Alwil Software\Avast5\AvastUI.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Mozilla Firefox 4.0 Beta 6\firefox.exe
C:\Program Files\Mozilla Firefox 4.0 Beta 6\plugin-container.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [avast5] "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\PROGRA~1\Yahoo!\Messenger\YahooMessenger.e xe" -quiet
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O13 - Gopher Prefix:
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/ge...sh/swflash.cab
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Mail Scanner - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Web Scanner - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe

Things seem to be running well. 2 questions. Is there a better AV I could run besides Avast like going with a paid solution (Norton, Kaspersky) or a free solution like Microsoft Security Essentials?

Also, O13 - Gopher Prefix: Is this something to be concerned about?
Old November 3rd, 2010, 06:31 AM
touch
touch touch is offline
Malware Removal Team
Join Date: Jan 2007
O/S: Windows XP Pro
Posts: 3,595
Clean log.

O13 - Gopher Prefix: Is this something to be concerned about?

Things seem to be running well. 2 questions. Is there a better AV I could run besides Avast like going with a paid solution (Norton, Kaspersky) or a free solution like Microsoft Security Essentials?
I read it as you want to have 2 active AV running. If I´ve read it right, no it´s not a good idea.

"When the resident scanners of two different AV programs are used simultaneously, conflicts can result. The computer may run very, very slowly, it may become difficult to access files."
