Yesterday I downloaded a free eBook (not from it's original site, that site was down for maintenance) and it came with an "extractor". The eBook is quite big in terms of file size so I didn't think much of the extractor, besides, a lot of big repacks include some form of extraction application. So I ran the thing and it installed something called NCDownloader followed by some other crap. I have MSE installed but it didn't detect anything when I scanned the extractor nor when I ran it.

Paranoid as I am, I uninstalled it and ran a full scan with MSE, it found some adware files that it successfully removed. One of the files were actually for a fix for GTA 4 (drunk cam fix). I figured it was just a false positive due to the nature of the fix but I still removed it and the other file was to allow remote access to my computer, which I instantly removed. After that I ran a full scan with MBAM which found 3 objects (can post the log if requested) which it successfully deleted.

But I still feel a bit paranoid, so I'm currently running another scan with MSE. But I figured that some experts might be able to help me a bit more than just MSE. I have noticed that my PC is running a bit slower (might be because of the current scan with MSE) but some settings have been changed too, my PC went into "Locked" mode, as if I had left it idle for too long but the thing is, I disabled that several months ago. So it should never go into "Locked" mode, yet , for some reason it now does. It also reset my Chrome installation, bookmarks, addons and such were removed.


DDS (Ver_2012-11-20.01) - NTFS_AMD64

Internet Explorer: 9.0.8112.16457 BrowserJavaVersion: 10.10.2

Run by Ecaz at 11:51:31 on 2013-03-19

Microsoft Windows 7 Ultimate 6.1.7600.0.1252.1.1033.18.8178.5565 [GMT 1:00]


AV: Microsoft Security Essentials *Enabled/Updated* {B140BF4E-23BB-4198-90AB-A51A4C60A69C}

SP: Microsoft Security Essentials *Enabled/Updated* {0A215EAA-0581-4E16-AA1B-9E6837E7EC21}

SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}


DDS (Ver_2012-11-20.01)


Microsoft Windows 7 Ultimate

Boot Device: \Device\HarddiskVolume3

Install Date: 10/18/2012 17:46:02

System Uptime: 3/19/2013 10:47:19 (1 hours ago)


Motherboard: MSI | | 970A-G46 (MS-7693)

Processor: AMD Phenom™ II X4 965 Processor | CPU 1 | 3400/200mhz


==== Disk Partitions =========================


C: is FIXED (NTFS) - 233 GiB total, 18.147 GiB free.

D: is FIXED (NTFS) - 0 GiB total, 0.084 GiB free.

E: is FIXED (NTFS) - 75 GiB total, 38.74 GiB free.

G: is FIXED (NTFS) - 1863 GiB total, 958.599 GiB free.


==== Disabled Device Manager Items =============


Class GUID:

Description: Universal Serial Bus (USB) Controller

Device ID: PCI\VEN_1B21&DEV_1042&SUBSYS_76931462&REV_00\4&1047CFC0&0&0020


Name: Universal Serial Bus (USB) Controller

PNP Device ID: PCI\VEN_1B21&DEV_1042&SUBSYS_76931462&REV_00\4&1047CFC0&0&0020



==== System Restore Points ===================


RP151: 3/19/2013 05:31:35 - Scheduled Checkpoint


Since this is a rather "delicate" matter I didn't want to wait forever, so I ran AdwCleaner and RogueKiller.

Here is the AdwCleaner log

I can post my previous MBAM log and the RogueKiller log if requested.

The thing is, before I ran AdwCleaner none of my browsers worked. I kept getting "No data received" in Chrome, and the equivalent in IE and FF. I'm currently using my phone, USB tethering. And now, after I ran AdwCleaner and restarted it telling me that I have a connection to a network but not to Internet. It's possible that Internet just isn't working right now, my ISP doesn't have 24/7 support so I can't really find out, other than waiting.

Hi TheDoctorIsIn,

Welcome to Malwarebytes Forum

My name is Tomk1. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
  • Unfortunately, if I do not hear back from you within 5 days, I will be forced to close your topic. If you still need help after I have closed your topic, feel free to create a new one.

If you don't have internet access, you may have to download on a good computer and transfer the program to the one we are working on.

Let's try this:

Download ComboFix:

Let's try this:

Download ComboFix:

* IMPORTANT !!! Save ComboFix.exe to your Desktop

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link --> http://forums.whatth...ams_t96260.html
  • Double click on ComboFix.exe & follow the prompts.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.


1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.

2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.

3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.

4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Sorry for not getting back to you sooner, but I ended up formatting my HDD and doing a clean, fresh install of Windows. All is well now.

Thanks for letting me know.

Good luck and be well.

Glad we could help. :)

If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread.

Other members who need assistance please start your own topic in a new thread. Thanks!

