This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] TrojanDownloader

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi would anyone be able to help my i keep getting the message : trojandownloader:/win32/renos.io i can't seem to get rid of the bloody thing could anyone offer me any help i'd really be grateful thanks matt
Hello.

May I know what is detecting that as TrojanDownloader?

Let's get some logs.

Please run DDS and Malwarebytes.

Download and run MalwareBytes Anti-Malware

Please download Malwarebytes Anti-Malware and save it to your desktop.
alternate download link 1
  • Make sure you are connected to the Internet.
  • Double-click on Download_mbam-setup.exe to install the application.
  • When the installation begins, follow the prompts and do not make any changes to default settings.
  • When installation has finished, make sure you leave both of these checked:
    • Update Malwarebytes' Anti-Malware
    • Launch Malwarebytes' Anti-Malware
  • Then click Finish.
  • MBAM will automatically start and you will be asked to update the program before performing a scan. If an update is found, the program will automatically update itself. Press the OK button to close that box and continue. If you encounter any problems while downloading the updates, manually download them from here and just double-click on mbam-rules.exe to install.
  • On the Scanner tab:
    • Make sure the "Perform Quick Scan" option is selected.
    • Then click on the Scan button.
  • If asked to select the drives to scan, leave all the drives selected and click on the Start Scan button.
  • The scan will begin and "Scan in progress" will show at the top. It may take some time to complete so please be patient.
  • When the scan is finished, a message box will say "The scan completed successfully. Click 'Show Results' to display all objects found".
  • Click OK to close the message box and continue with the removal process.
  • Back at the main Scanner screen, click on the Show Results button to see a list of any malware that was found.
  • Make sure that everything is checked, and click Remove Selected.
  • When removal is completed, a log report will open in Notepad and you may be prompted to restart your computer. (see Note below)
  • The log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
  • Copy and paste the contents of that report in your next reply and exit MBAM.
Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.

For complete or visual instructions on installing and running Malwarebytes Anti-Malware please read this link

Download and run DDS

We need to see some information about what is happening in your machine. Please perform the following scan:
  • Download DDS by sUBs from one of the following links. Save it to your desktop.
    • DDS.scr
    • DDS.pif
  • Double click on the DDS icon, allow it to run.
  • A small box will open, with an explanation about the tool. No input is needed, the scan is running.
  • Notepad will open with the results soon.
  • Follow the instructions that pop up for posting the results and then click Ok.
  • The black and message box window shall then disappear.
  • Please save both log files on your desktop and post the DDS.txt and zip up and attach Attach.txt as instructed.
Please note: You may have to disable any script protection running if the scan fails to run. After downloading the tool, disconnect from the internet and disable all antivirus protection. Run the scan, enable your A/V and reconnect to the internet. Information on A/V control HERE

Thanks.

With Regards,
Extremeboy
First of all could i just thankyou for taking the time to help me i really appreciate it. I believe the Trojan downloader was being detected by windows defender I downloaded Malwarebytes anti-malware and installed the application however for whatever reason it will not let me run the scan or even open the program i have disabled AVG ect and have deleted and reinstalled malwarebytes 4 times. This is the dss log DDS (Ver_09-06-26.01) - NTFSx86 Run by [removed] at 14:32:29.26 on 05/07/2009 Internet Explorer: 8.0.6001.18783 Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.44.1033.18.2045.1108 [GMT 1:00] AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF} SP: Antispyware *enabled* (Updated) {57463B2F-DD60-468D-BC89-6D5403DDF541} SP: AVG Anti-Virus Free *enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF} SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} ============== Running Processes =============== C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k rpcss C:\Windows\system32\svchost.exe -k LocalService C:\Windows\System32\svchost.exe -k NetworkService C:\Windows\System32\svchost.exe -k secsvcs C:\Windows\system32\Ati2evxx.exe C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k GPSvcGroup C:\Windows\system32\SLsvc.exe C:\Windows\system32\Ati2evxx.exe C:\Windows\system32\Dwm.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\Explorer.EXE C:\Windows\system32\taskeng.exe C:\Windows\system32\taskeng.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe C:\Windows\system32\svchost.exe -k hpdevmgmt C:\Windows\System32\svchost.exe -k HPZ12 C:\Windows\System32\svchost.exe -k HPZ12 C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Windows\system32\SearchIndexer.exe C:\PROGRA~1\AVG\AVG8\avgrsx.exe C:\Windows\system32\DRIVERS\xaudio.exe C:\Program Files\Windows Defender\MSASCui.exe C:\Windows\RtHDVCpl.exe C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe C:\Program Files\HP\HP Software Update\hpwuSchd2.exe C:\Program Files\QuickTime\QTTask.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Synaptics\SynTP\SynTPStart.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Windows\ehome\ehtray.exe C:\Windows\ehome\ehmsas.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Program Files\MagicDisc\MagicDisc.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Google\Google Toolbar\GoogleToolbarUser.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe C:\Program Files\MSN Messenger\msnmsgr.exe C:\Windows\system32\Macromed\Flash\FlashUtil9f.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\DllHost.exe C:\Users\Hunter\Desktop\dds.scr C:\Windows\system32\wbem\wmiprvse.exe ============== Pseudo HJT Report =============== uSearch Page = hxxp://www.google.com uInternet Settings,ProxyOverride = *.local uURLSearchHooks: H - No File uURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg8\toolbar\IEToolbar.dll mURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg8\toolbar\IEToolbar.dll BHO: HP Print Clips: {053f9267-dc04-4294-a72c-58f732d338c0} - c:\program files\hp\smart web printing\hpswp_framework.dll BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_07\bin\ssv.dll BHO: {7E853D72-626A-48EC-A868-BA8D5E23E045} - No File BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg8\toolbar\IEToolbar.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.15642\swg.dll BHO: Windows Live Toolbar Helper: {bdbd1dad-c946-4a17-adc1-64b5b4ff55d0} - c:\program files\windows live toolbar\msntb.dll BHO: 1 (0x1) - No File BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll TB: Windows Live Toolbar: {bdad1dad-c946-4a17-adc1-64b5b4ff55d0} - c:\program files\windows live toolbar\msntb.dll TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar.dll TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - c:\program files\avg\avg8\toolbar\IEToolbar.dll TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe uRun: [Steam] "c:\program files\steam\Steam.exe" -silent uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide mRun: [RtHDVCpl] RtHDVCpl.exe mRun: [NeroFilterCheck] c:\program files\common files\ahead\lib\NeroCheck.exe mRun: [SunJavaUpdateSched] "c:\program files\java\jre1.6.0_07\bin\jusched.exe" mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe" mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe mRun: [SynTPStart] c:\program files\synaptics\syntp\SynTPStart.exe mRunOnce: [Malwarebytes' Anti-Malware] c:\program files\malwarebytes' anti-malware\mbamgui.exe /install /silent StartupFolder: c:\users\hunter\appdata\roaming\micros~1\windows\startm~1\programs\startup\magicd~1.lnk - c:\program files\magicdisc\MagicDisc.exe uPolicies-explorer: NoWindowsUpdate = 0 (0x0) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: &Windows Live Search - c:\program files\windows live toolbar\msntb.dll/search.htm IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000 IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBC} - c:\progra~1\java\jre16~4.0_0\bin\ssv.dll IE: {58ECB495-38F0-49cb-A538-10282ABF65E7} - {E763472E-A716-4CD9-89BD-DBDA6122F741} - c:\program files\hp\smart web printing\hpswp_extensions.dll IE: {700259D7-1666-479a-93B1-3250410481E8} - {A93C41D8-01F8-4F8B-B14C-DE20B117E636} - c:\program files\hp\smart web printing\hpswp_extensions.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://a1540.g.akamai.net/7/1540/52/20070501/qtinstall.info.apple.com/qtactivex/qtplugin.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} - hxxp://utilities.pcpitstop.com/optimize2/pcpitstop2.dll TCP: NameServer = 85.255.112.116,85.255.112.157 TCP: {E5CEC557-5CF3-4024-B7CA-090EE23F7DE6} = 85.255.112.116,85.255.112.157 TCP: {FBCB3E35-EEC3-4897-8203-39B20413382A} = 85.255.112.116,85.255.112.157 Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll AppInit_DLLs: avgrsstx.dll ============= SERVICES / DRIVERS =============== R0 O2MDRDR;O2MDRDR;c:\windows\system32\drivers\o2media.sys [2005-11-14 34176] R0 O2SDRDR;O2SDRDR;c:\windows\system32\drivers\o2sd.sys [2005-12-19 28800] R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-5-21 327688] R1 M9207;LifeView M9207 USB Digital TV BOX;c:\windows\system32\drivers\M9207BDA.sys [2007-6-11 54400] R2 avg8wd;AVG8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2008-5-21 298776] S3 RTL2831UBDA;REALTEK 2831U BDA Driver;c:\windows\system32\drivers\RTL2831UBDA.sys [2007-4-13 62720] S3 RTL2831UUSB;REALTEK 2831U USB Driver;c:\windows\system32\drivers\RTL2831UUSB.sys [2007-4-13 24064] =============== Created Last 30 ================ 2009-07-05 14:24 38,160 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2009-07-05 14:24 19,096 a——- c:\windows\system32\drivers\mbam.sys 2009-07-05 14:24 –d—– c:\programdata\Malwarebytes 2009-07-05 14:24 –d—– c:\program files\Malwarebytes' Anti-Malware 2009-07-05 14:24 –d—– c:\progra~2\Malwarebytes 2009-07-04 16:30 –d—– c:\users\hunter\appdata\roaming\Antispyware 2009-07-04 16:30 –d—– c:\program files\Antispyware 2009-07-03 21:51 –d—– c:\users\hunter\DoctorWeb 2009-07-03 15:47 –d—– c:\program files\DVDTool 2009-07-03 15:17 87,608 a——- c:\users\hunter\appdata\roaming\inst.exe 2009-07-03 15:17 47,360 a——- c:\windows\system32\drivers\pcouffin.sys 2009-07-03 15:17 47,360 a——- c:\users\hunter\appdata\roaming\pcouffin.sys 2009-06-12 14:59 145,725,947 a——- c:\windows\MEMORY.DMP 2009-06-12 10:03 –d—– c:\programdata\AVG Security Toolbar 2009-06-12 10:03 –d—– c:\progra~2\AVG Security Toolbar 2009-06-09 14:15 –d—– c:\programdata\Driving Test Success 2009-06-09 14:15 –d—– c:\program files\Hazard Perception 2005-2006 2009-06-09 14:15 –d—– c:\progra~2\Driving Test Success ==================== Find3M ==================== 2009-07-03 15:18 86,016 a——- c:\windows\inf\infstrng.dat 2009-07-03 15:18 51,200 a——- c:\windows\inf\infpub.dat 2009-07-03 15:18 86,016 a——- c:\windows\inf\infstor.dat 2009-06-12 10:02 327,688 a——- c:\windows\system32\drivers\avgldx86.sys 2009-05-09 06:50 915,456 a——- c:\windows\system32\wininet.dll 2009-05-09 06:34 71,680 a——- c:\windows\system32\iesetup.dll 2009-05-06 10:15 11,952 a——- c:\windows\system32\avgrsstx.dll 2009-04-23 13:43 784,896 a——- c:\windows\system32\rpcrt4.dll 2009-04-23 13:42 636,928 a——- c:\windows\system32\localspl.dll 2009-04-21 12:55 2,033,152 a——- c:\windows\system32\win32k.sys 2008-07-22 00:18 174 a–sh— c:\program files\desktop.ini 2008-07-22 00:02 665,600 a——- c:\windows\inf\drvindex.dat 2006-11-02 13:42 287,440 a——- c:\windows\inf\perflib\0409\perfi.dat 2006-11-02 13:42 287,440 a——- c:\windows\inf\perflib\0409\perfh.dat 2006-11-02 13:42 30,674 a——- c:\windows\inf\perflib\0409\perfd.dat 2006-11-02 13:42 30,674 a——- c:\windows\inf\perflib\0409\perfc.dat 2006-11-02 10:20 287,440 a——- c:\windows\inf\perflib\0000\perfi.dat 2006-11-02 10:20 287,440 a——- c:\windows\inf\perflib\0000\perfh.dat 2006-11-02 10:20 30,674 a——- c:\windows\inf\perflib\0000\perfd.dat 2006-11-02 10:20 30,674 a——- c:\windows\inf\perflib\0000\perfc.dat ============= FINISH: 14:34:18.38 =============== I hope i have zipped up and attached the other file correctly. thanks again for your help as i am at a loss what to do kind regards hunterberg
Hello.

You did not provide the correct Attach.txt log. I think you also attached the wrong file… Take a look yourself. :whistling:

If you have any problems, simply let me know. Please post the correct attach log in your next reply, in addition to the instruction below.

I see a DNS Changer infection, and perhaps more.

We'll start off with Combofix.
–

Download and Run ComboFix

Download Combofix from any of the links below, and save it to your desktop.
Link 1
Link 2
Link 3

Please refer to this page for full instructions on how to run ComboFix.

  • Close/disable all anti-virus and anti-malware programs so they do not interfere with the running of ComboFix. Refer to this page if you are not sure how.
  • Double click ComboFix.exe to start the program. Agree to the prompts.
  • When ComboFix is finished, a log report (C:\ComboFix.txt) will open. Post back with it.
Leave your computer alone while ComboFix is running.

ComboFix will restart your computer if malware is found; allow it to do so.


Note: Please Do NOT mouseclick combofix's window while its running because it may call it to stall.

With Regards,
Extremeboy
Hi thanks again for your help here is the log

ComboFix 09-07-05.04 - Hunter 06/07/2009 18:58.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.44.1033.18.2045.1137 [GMT 1:00]
Running from: c:\users\[removed]\Desktop\Everton.exe
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: Antispyware *enabled* (Updated) {57463B2F-DD60-468D-BC89-6D5403DDF541}
SP: AVG Anti-Virus Free *enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
ADS - Windows: deleted 24 bytes in 1 streams.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\$recycle.bin\S-1-5-21-2031794746-3310518143-4181126009-500
c:\$recycle.bin\S-1-5-21-2152478756-3922319563-605102323-500
C:\setuplog.exe
c:\users\Hunter\AppData\Roaming\inst.exe
c:\windows\system32\AutoRun.inf
c:\windows\system32\drivers\MSIVXtiqtixtrbpxvtverdrpnptapolofbefd.sys
c:\windows\system32\MSIVXcount
c:\windows\system32\MSIVXevqqwpwoteljpwrxuwynrjwdwjtsssbl.dll
c:\windows\system32\MSIVXpbpvcahkidanlblbrrphvbqyiopfivfi.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_MSIVXserv.sys


((((((((((((((((((((((((( Files Created from 2009-06-06 to 2009-07-06 )))))))))))))))))))))))))))))))
.

2009-07-06 18:05 . 2009-07-06 18:05 ——– d—–w- c:\users\Hunter\AppData\Local\temp
2009-07-06 14:34 . 2009-07-06 14:34 ——– d—–w- c:\users\Hunter\AppData\Local\Apple
2009-07-05 13:44 . 2009-07-05 13:44 ——– d—–w- c:\users\Hunter\AppData\Local\WinZip
2009-07-04 21:39 . 2009-07-04 21:39 ——– d—–w- c:\windows\Sun
2009-07-04 21:33 . 2009-07-04 21:33 680 —-a-w- c:\users\Hunter\AppData\Local\d3d9caps.dat
2009-07-04 15:30 . 2009-07-04 22:06 ——– d—–w- c:\users\Hunter\AppData\Roaming\Antispyware
2009-07-03 20:51 . 2009-07-03 23:42 ——– d—–w- c:\users\Hunter\DoctorWeb
2009-07-03 14:47 . 2009-07-03 14:47 ——– d—–w- c:\program files\DVDTool
2009-07-03 14:17 . 2009-07-03 14:26 ——– d—–w- c:\users\Hunter\AppData\Roaming\Vso
2009-07-03 14:17 . 2009-07-03 14:26 47360 —-a-w- c:\users\Hunter\AppData\Roaming\pcouffin.sys
2009-07-03 14:17 . 2009-07-03 14:17 47360 —-a-w- c:\windows\system32\drivers\pcouffin.sys
2009-06-24 08:48 . 2009-06-17 08:37 2052888 —-a-w- c:\programdata\avg8\update\backup\avgcorex.dll
2009-06-17 08:38 . 2009-06-12 09:01 1261344 —-a-w- c:\programdata\avg8\update\backup\avgwd.dll
2009-06-17 08:38 . 2009-06-12 09:01 829208 —-a-w- c:\programdata\avg8\update\backup\avgcfgx.dll
2009-06-17 08:38 . 2009-06-12 09:01 3298072 —-a-w- c:\programdata\avg8\update\backup\setup.exe
2009-06-12 09:03 . 2009-06-12 11:20 ——– d—–w- c:\programdata\AVG Security Toolbar
2009-06-12 09:01 . 2009-06-12 09:00 1452312 —-a-w- c:\programdata\avg8\update\backup\avgupd.dll
2009-06-09 13:15 . 2005-06-13 11:58 9143000 —-a-w- c:\programdata\Driving Test Success\AdbeRdr60_enu.exe
2009-06-09 13:15 . 2009-07-02 08:51 ——– d—–w- c:\programdata\Driving Test Success
2009-06-09 13:15 . 2009-06-09 13:15 ——– d—–w- c:\program files\Hazard Perception 2005-2006
2009-06-08 14:30 . 2009-06-08 14:30 456304 —-a-w- c:\programdata\Google\Google Toolbar\Update\gtbC140.tmp.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-06 17:26 . 2009-01-08 19:24 ——– d—–w- c:\program files\Steam
2009-07-06 15:58 . 2008-05-21 11:30 ——– d—–w- c:\programdata\avg8
2009-07-05 13:44 . 2007-06-15 17:05 ——– d—–w- c:\programdata\WinZip
2009-07-05 12:48 . 2007-06-11 07:49 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-07-03 21:26 . 2007-09-06 19:06 ——– d—–w- c:\users\Hunter\AppData\Roaming\uTorrent
2009-07-02 21:15 . 2008-09-05 22:04 ——– d—–w- c:\users\Hunter\AppData\Roaming\DVD Flick
2009-07-02 11:25 . 2009-01-08 19:25 ——– d—–w- c:\program files\Common Files\Steam
2009-06-17 08:37 . 2007-12-10 22:03 27784 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-06-12 09:02 . 2008-05-21 11:30 327688 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2009-06-11 19:49 . 2007-06-15 17:07 ——– d—–w- c:\programdata\DVD Shrink
2009-06-09 16:57 . 2009-05-19 16:46 ——– d—–w- c:\program files\SlySoft
2009-05-19 16:51 . 2009-05-19 16:51 ——– d—–w- c:\programdata\SlySoft
2009-05-09 05:50 . 2009-06-10 09:02 915456 —-a-w- c:\windows\system32\wininet.dll
2009-05-09 05:34 . 2009-06-10 09:02 71680 —-a-w- c:\windows\system32\iesetup.dll
2009-05-06 09:15 . 2008-05-21 11:30 11952 —-a-w- c:\windows\system32\avgrsstx.dll
2009-04-23 12:43 . 2009-06-10 09:02 784896 —-a-w- c:\windows\system32\rpcrt4.dll
2009-04-23 12:42 . 2009-06-10 09:02 636928 —-a-w- c:\windows\system32\localspl.dll
2009-04-21 11:55 . 2009-06-10 09:02 2033152 —-a-w- c:\windows\system32\win32k.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-06-16 08:29 1004800 —-a-w- c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-19 1233920]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"Steam"="c:\program files\Steam\Steam.exe" [2009-06-10 1217784]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-01-10 39408]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-03-02 185896]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-03-11 49152]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-03-28 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-03-30 267048]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-06-12 1948440]
"SynTPStart"="c:\program files\Synaptics\SynTP\SynTPStart.exe" [2007-10-09 102400]
"RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2006-11-20 4018176]

c:\users\Hunter\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
MagicDisc.lnk - c:\program files\MagicDisc\MagicDisc.exe [2008-10-16 575488]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{B4B573E1-7C6A-4DE6-B4FC-FB723CC9687F}"= c:\program files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)
"TCP Query User{7E5F9DA2-0753-405C-B684-06195EE2643A}c:\\westwood\\ra2\\game.exe"= UDP:c:\westwood\ra2\game.exe:Main executable for Red Alert 2
"UDP Query User{8479CC03-DFEE-4F3C-B3E7-D47B10B8EB25}c:\\westwood\\ra2\\game.exe"= TCP:c:\westwood\ra2\game.exe:Main executable for Red Alert 2
"{446ECA33-E671-4A93-BC6B-8AFB9EB002C4}"= UDP:c:\westwood\RA2\Ra2.exe:Red Alert 2
"{3FE25EE4-0952-4A98-9C41-01F664F5F78D}"= TCP:c:\westwood\RA2\Ra2.exe:Red Alert 2
"{7EAC4B53-42DE-4147-8890-581DB903183B}"= UDP:c:\program files\BullGuard Software\BullGuard\BullGuard.exe:BullGuard
"{981D5111-F978-44EB-A877-D7E3037B404D}"= TCP:c:\program files\BullGuard Software\BullGuard\BullGuard.exe:BullGuard
"{F2B0DD4A-1E53-4AB1-A35A-E21B93B2E6CE}"= UDP:c:\westwood\Internet\REGISTER.EXE:Internet Registration
"{C8670947-EE85-402C-90B3-B9853D3BF6EA}"= TCP:c:\westwood\Internet\REGISTER.EXE:Internet Registration
"TCP Query User{5F0A6153-B10E-444E-B038-BD26314B461F}c:\\program files\\internet explorer\\iexplore.exe"= UDP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{3F3ADAD8-84E6-4267-A6D8-41E67C9EE260}c:\\program files\\internet explorer\\iexplore.exe"= TCP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"{0E763C74-FC32-4CED-A54D-5A1478518D79}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent
"{1ACEE53A-C5C7-4F38-8752-7E5599FC6209}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent
"TCP Query User{B6A35FB2-9870-49A4-ABA3-856AA2CDBFD8}c:\\program files\\tvants\\tvants.exe"= UDP:c:\program files\tvants\tvants.exe:TVAnts
"UDP Query User{722551ED-1C0A-4B09-83F2-41D9A25430CE}c:\\program files\\tvants\\tvants.exe"= TCP:c:\program files\tvants\tvants.exe:TVAnts
"{8F2A6D36-ABEC-41A7-A1EC-FF981D55BF8F}"= UDP:c:\program files\Sports Interactive\Football Manager 2008\fm.exe:Football Manager 2008
"{D823F2C6-F9E2-4330-9310-6AF40AA2DD69}"= TCP:c:\program files\Sports Interactive\Football Manager 2008\fm.exe:Football Manager 2008
"TCP Query User{7A665497-BFB6-4823-9826-0988D1E916B3}c:\\program files\\nero\\nero 7\\nero mediahome\\nmmediaserver.exe"= UDP:c:\program files\nero\nero 7\nero mediahome\nmmediaserver.exe:Nero MediaHome
"UDP Query User{96769D86-DF32-4EA5-A1D6-1A4AFE8533F4}c:\\program files\\nero\\nero 7\\nero mediahome\\nmmediaserver.exe"= TCP:c:\program files\nero\nero 7\nero mediahome\nmmediaserver.exe:Nero MediaHome
"{C6AB4FB2-AFD2-447C-A93B-B70AC0C7182E}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{D25861BE-FD09-4A36-B6FB-38EDEAC48871}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"{66A8CDC7-FB82-441D-9123-E913B8943D81}"= c:\program files\AVG\AVG8\avgupd.exe:avgupd.exe
"{13FCA693-E8A4-45F7-ADF3-7EC4CCFDA579}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent (TCP-In)
"{9582084A-2CEF-434C-90AB-A2F562D0F082}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent (UDP-In)
"{6AB1D5A9-F731-4B4F-ADD3-97525E8281A5}"= inRosettaStoneLtdServices.exe:Rosetta Stone Online Component (inbound)
"{440EC3CD-6C53-4913-8424-2DB3F24A6B90}"= RosettaStoneVersion3.exe:Rosetta Stone V3 Application (inbound)
"{0D60FA12-F5C4-4679-985F-5C75DCAB7269}"= UDP:c:\program files\Steam\SteamApps\common\football manager 2009\fm.exe:Football Manager 2009
"{961E0AD4-2E6F-40C9-AA38-2CBE85A38DC6}"= TCP:c:\program files\Steam\SteamApps\common\football manager 2009\fm.exe:Football Manager 2009
"{23491FB8-0ED0-40B2-9F7D-EE06C6F6162C}"= UDP:c:\program files\Steam\SteamApps\common\football manager 2009\fm.exe:Football Manager 2009
"{1FF8C24A-41A9-4F43-95BB-C026E5434824}"= TCP:c:\program files\Steam\SteamApps\common\football manager 2009\fm.exe:Football Manager 2009
"{15FC519C-AC52-448F-9C1A-733538848D52}"= Disabled:UDP:c:\program files\Sports Interactive\Football Manager 2008\fm.exe:Football Manager 2008
"{1DD6D8E8-4995-4D78-A343-9A1FF64A8970}"= Disabled:TCP:c:\program files\Sports Interactive\Football Manager 2008\fm.exe:Football Manager 2008

R0 O2MDRDR;O2MDRDR;c:\windows\System32\drivers\o2media.sys [14/11/2005 13:28 34176]
R0 O2SDRDR;O2SDRDR;c:\windows\System32\drivers\o2sd.sys [19/12/2005 17:15 28800]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\System32\drivers\avgldx86.sys [21/05/2008 12:30 327688]
R1 M9207;LifeView M9207 USB Digital TV BOX;c:\windows\System32\drivers\M9207BDA.sys [11/06/2007 09:21 54400]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [21/05/2008 12:30 298776]
S3 RTL2831UBDA;REALTEK 2831U BDA Driver;c:\windows\System32\drivers\RTL2831UBDA.sys [13/04/2007 15:04 62720]
S3 RTL2831UUSB;REALTEK 2831U USB Driver;c:\windows\System32\drivers\RTL2831UUSB.sys [13/04/2007 15:20 24064]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder

2009-07-06 c:\windows\Tasks\Check Updates for Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 11:20]
.
.
——- Supplementary Scan ——-
.
uInternet Settings,ProxyOverride = *.local
IE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-07-06 19:05
Windows 6.0.6001 Service Pack 1 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2009-07-06 19:06
ComboFix-quarantined-files.txt 2009-07-06 18:06

Pre-Run: 65,075,474,432 bytes free
Post-Run: 65,807,978,496 bytes free

179 — E O F — 2009-06-30 09:15


Also when i try to zip up and attach the attach.txt i encounter problems so i hope it is ok but i have posted it below:

NLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_09-06-26.01)

Microsoft® Windows Vista™ Home Premium
Boot Device: \Device\HarddiskVolume2
Install Date: 13/06/2007 11:57:53
System Uptime: 07/05/2009 14:09:31 (1416 hours ago)

Motherboard: MTC | | MTC
Processor: Intel® Core™2 CPU T7200 @ 2.00GHz | CPU | 1992/667mhz

==== Disk Partitions =========================

C: is FIXED (NTFS) - 144 GiB total, 56.985 GiB free.
E: is CDROM ()
F: is CDROM (CDFS)

==== Disabled Device Manager Items =============

==== System Restore Points ===================


==== Installed Programs ======================

32 Bit HP CIO Components Installer
Adobe Acrobat and Reader 8.1.2 Security Update 1 (KB403742)
Adobe Flash Player ActiveX
Adobe Reader 8.1.2
Adobe Reader 8.1.2 Security Update 1 (KB403742)
AIO_Scan
Apple Mobile Device Support
Apple Software Update
µTorrent
AVG Free 8.5
BufferChm
Command & Conquer Red Alert 2
Copy
CustomerResearchQFolder
Destination Component
DeviceDiscovery
DeviceManagementQFolder
DJ_AIO_ProductContext
DJ_AIO_Software
DJ_AIO_Software_min
DVD Decrypter (Remove Only)
DVD Flick
DVD Shrink 3.2
DVDTool
eSupportQFolder
ExtractNow
F2100
F2100_doccd
F2100_Help
Football Manager 2009
G-Force Blue
Google Toolbar for Internet Explorer
Hazard Perception 2005/6
HDAUDIO Soft Data Fax Modem with SmartCP
HP Customer Participation Program 9.0
HP Deskjet All-In-One Software 9.0
HP Imaging Device Functions 9.0
HP Photosmart Essential 2.01
HP Photosmart Essential2.01
HP Smart Web Printing
HP Solution Center 9.0
HP Update
HPProductAssistant
HPSSupply
iTunes
Java™ 6 Update 2
Java™ 6 Update 3
Java™ 6 Update 5
Java™ 6 Update 7
K-Lite Codec Pack 3.8.0 Basic
MagicDisc 2.7.105
Malwarebytes' Anti-Malware
MarketResearch
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB929729)
Microsoft Office Professional Edition 2003
Microsoft Visual C++ 2005 Redistributable
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB941833)
MSXML 4.0 SP2 (KB954430)
Nero 7 Essentials
PowerDVD
PSSWCORE
QuickTime
RealPlayer
Realtek High Definition Audio Driver
Rosetta Stone V3
SAGEM F@st 800-840
Scan
Shockwave
SolutionCenter
Status
Steam
Synaptics Pointing Device Driver
Toolbox
TrayApp
UnloadSupport
VideoToolkit01
WebReg
Westwood Shared Internet Components
Windows Live Messenger
Windows Live Sign-in Assistant
Windows Live Toolbar

==== End Of File ===========================

Many thanks for your time

hunterberg
Hi i have just managed to finally run malwarebytes the log is shown below: Malwarebytes' Anti-Malware 1.38 Database version: 2382 Windows 6.0.6001 Service Pack 1 06/07/2009 20:42:07 mbam-log-2009-07-06 (20-41-57).txt Scan type: Quick Scan Objects scanned: 78134 Time elapsed: 6 minute(s), 5 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 4 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 2 Files Infected: 2 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{3aa42713-5c1e-48e2-b432-d8bf420dd31d} (Rogue.AntiVirus2008) -> No action taken. HKEY_LOCAL_MACHINE\SOFTWARE\WinBlueSoft (Rogue.WinBlue) -> No action taken. HKEY_CURRENT_USER\SOFTWARE\DVDTool (Trojan.DNSChanger) -> No action taken. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DVDTool (Trojan.DNSChanger) -> No action taken. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: c:\Users\Hunter\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DVDTool (Trojan.DNSChanger) -> No action taken. C:\Program Files\DVDTool (Trojan.DNSChanger) -> No action taken. Files Infected: c:\Users\Hunter\AppData\Roaming\microsoft\Windows\start menu\Programs\DVDTool\Uninstall.lnk (Trojan.DNSChanger) -> No action taken. c:\program files\DVDTool\Uninstall.exe (Trojan.DNSChanger) -> No action taken. thanks hunterberg
Hi here is the new dds log DDS (Ver_09-06-26.01) - NTFSx86 Run by [removed] at 18:02:50.01 on 07/07/2009 Internet Explorer: 8.0.6001.18783 Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.44.1033.18.2045.1157 [GMT 1:00] AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF} SP: Antispyware *enabled* (Updated) {57463B2F-DD60-468D-BC89-6D5403DDF541} SP: AVG Anti-Virus Free *enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF} SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} ============== Running Processes =============== C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k rpcss C:\Windows\system32\Ati2evxx.exe C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k GPSvcGroup C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\system32\Ati2evxx.exe C:\Windows\system32\Dwm.exe C:\Windows\System32\spoolsv.exe C:\Windows\Explorer.EXE C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\taskeng.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe C:\Windows\system32\svchost.exe -k hpdevmgmt C:\Windows\System32\svchost.exe -k HPZ12 C:\Windows\System32\svchost.exe -k HPZ12 C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Windows\system32\SearchIndexer.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\DRIVERS\xaudio.exe C:\PROGRA~1\AVG\AVG8\avgrsx.exe C:\Windows\RtHDVCpl.exe C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe C:\Program Files\HP\HP Software Update\hpwuSchd2.exe C:\Program Files\QuickTime\QTTask.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Synaptics\SynTP\SynTPStart.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Windows\ehome\ehtray.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Program Files\MagicDisc\MagicDisc.exe C:\Windows\ehome\ehmsas.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Program Files\Google\Google Toolbar\GoogleToolbarUser.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\Macromed\Flash\FlashUtil9f.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\DllHost.exe C:\Users\Hunter\Desktop\dds.scr C:\Windows\system32\wbem\wmiprvse.exe ============== Pseudo HJT Report =============== uInternet Settings,ProxyOverride = *.local uURLSearchHooks: H - No File uURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg8\toolbar\IEToolbar.dll mURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg8\toolbar\IEToolbar.dll BHO: HP Print Clips: {053f9267-dc04-4294-a72c-58f732d338c0} - c:\program files\hp\smart web printing\hpswp_framework.dll BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_07\bin\ssv.dll BHO: {7E853D72-626A-48EC-A868-BA8D5E23E045} - No File BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg8\toolbar\IEToolbar.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.15642\swg.dll BHO: Windows Live Toolbar Helper: {bdbd1dad-c946-4a17-adc1-64b5b4ff55d0} - c:\program files\windows live toolbar\msntb.dll BHO: 1 (0x1) - No File BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll TB: Windows Live Toolbar: {bdad1dad-c946-4a17-adc1-64b5b4ff55d0} - c:\program files\windows live toolbar\msntb.dll TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar.dll TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - c:\program files\avg\avg8\toolbar\IEToolbar.dll TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe uRun: [Steam] "c:\program files\steam\Steam.exe" -silent uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide mRun: [RtHDVCpl] RtHDVCpl.exe mRun: [NeroFilterCheck] c:\program files\common files\ahead\lib\NeroCheck.exe mRun: [SunJavaUpdateSched] "c:\program files\java\jre1.6.0_07\bin\jusched.exe" mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe" mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe mRun: [SynTPStart] c:\program files\synaptics\syntp\SynTPStart.exe StartupFolder: c:\users\hunter\appdata\roaming\micros~1\windows\startm~1\programs\startup\magicd~1.lnk - c:\program files\magicdisc\MagicDisc.exe mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: &Windows Live Search - c:\program files\windows live toolbar\msntb.dll/search.htm IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000 IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBC} - c:\progra~1\java\jre16~4.0_0\bin\ssv.dll IE: {58ECB495-38F0-49cb-A538-10282ABF65E7} - {E763472E-A716-4CD9-89BD-DBDA6122F741} - c:\program files\hp\smart web printing\hpswp_extensions.dll IE: {700259D7-1666-479a-93B1-3250410481E8} - {A93C41D8-01F8-4F8B-B14C-DE20B117E636} - c:\program files\hp\smart web printing\hpswp_extensions.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://a1540.g.akamai.net/7/1540/52/20070501/qtinstall.info.apple.com/qtactivex/qtplugin.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} - hxxp://utilities.pcpitstop.com/optimize2/pcpitstop2.dll Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll AppInit_DLLs: c:\windows\system32\avgrsstx.dll ============= SERVICES / DRIVERS =============== R0 O2MDRDR;O2MDRDR;c:\windows\system32\drivers\o2media.sys [2005-11-14 34176] R0 O2SDRDR;O2SDRDR;c:\windows\system32\drivers\o2sd.sys [2005-12-19 28800] R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-5-21 327688] R1 M9207;LifeView M9207 USB Digital TV BOX;c:\windows\system32\drivers\M9207BDA.sys [2007-6-11 54400] R2 avg8wd;AVG8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2008-5-21 298776] S3 RTL2831UBDA;REALTEK 2831U BDA Driver;c:\windows\system32\drivers\RTL2831UBDA.sys [2007-4-13 62720] S3 RTL2831UUSB;REALTEK 2831U USB Driver;c:\windows\system32\drivers\RTL2831UUSB.sys [2007-4-13 24064] =============== Created Last 30 ================ 2009-07-06 20:32 –d—– c:\users\hunter\appdata\roaming\Malwarebytes 2009-07-06 20:32 38,160 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2009-07-06 20:32 19,096 a——- c:\windows\system32\drivers\mbam.sys 2009-07-06 20:32 –d—– c:\programdata\Malwarebytes 2009-07-06 20:32 –d—– c:\program files\Malwarebytes' Anti-Malware 2009-07-06 20:32 –d—– c:\progra~2\Malwarebytes 2009-07-06 19:06 –dsh— C:\$RECYCLE.BIN 2009-07-06 18:48 161,792 a——- c:\windows\SWREG.exe 2009-07-06 18:48 155,136 a——- c:\windows\PEV.exe 2009-07-06 18:48 98,816 a——- c:\windows\sed.exe 2009-07-06 18:48 –ds—- C:\Everton 2009-07-04 16:30 –d—– c:\users\hunter\appdata\roaming\Antispyware 2009-07-03 21:51 –d—– c:\users\hunter\DoctorWeb 2009-07-03 15:17 47,360 a——- c:\windows\system32\drivers\pcouffin.sys 2009-07-03 15:17 47,360 a——- c:\users\hunter\appdata\roaming\pcouffin.sys 2009-06-12 14:59 167,148,027 a——- c:\windows\MEMORY.DMP 2009-06-12 10:03 –d—– c:\programdata\AVG Security Toolbar 2009-06-12 10:03 –d—– c:\progra~2\AVG Security Toolbar 2009-06-09 14:15 –d—– c:\programdata\Driving Test Success 2009-06-09 14:15 –d—– c:\program files\Hazard Perception 2005-2006 2009-06-09 14:15 –d—– c:\progra~2\Driving Test Success ==================== Find3M ==================== 2009-07-03 15:18 86,016 a——- c:\windows\inf\infstrng.dat 2009-07-03 15:18 51,200 a——- c:\windows\inf\infpub.dat 2009-07-03 15:18 86,016 a——- c:\windows\inf\infstor.dat 2009-06-12 10:02 327,688 a——- c:\windows\system32\drivers\avgldx86.sys 2009-05-09 06:50 915,456 a——- c:\windows\system32\wininet.dll 2009-05-09 06:34 71,680 a——- c:\windows\system32\iesetup.dll 2009-05-06 10:15 11,952 a——- c:\windows\system32\avgrsstx.dll 2009-04-23 13:43 784,896 a——- c:\windows\system32\rpcrt4.dll 2009-04-23 13:42 636,928 a——- c:\windows\system32\localspl.dll 2009-04-21 12:55 2,033,152 a——- c:\windows\system32\win32k.sys 2008-07-22 00:18 174 a–sh— c:\program files\desktop.ini 2008-07-22 00:02 665,600 a——- c:\windows\inf\drvindex.dat 2006-11-02 13:42 287,440 a——- c:\windows\inf\perflib\0409\perfi.dat 2006-11-02 13:42 287,440 a——- c:\windows\inf\perflib\0409\perfh.dat 2006-11-02 13:42 30,674 a——- c:\windows\inf\perflib\0409\perfd.dat 2006-11-02 13:42 30,674 a——- c:\windows\inf\perflib\0409\perfc.dat 2006-11-02 10:20 287,440 a——- c:\windows\inf\perflib\0000\perfi.dat 2006-11-02 10:20 287,440 a——- c:\windows\inf\perflib\0000\perfh.dat 2006-11-02 10:20 30,674 a——- c:\windows\inf\perflib\0000\perfd.dat 2006-11-02 10:20 30,674 a——- c:\windows\inf\perflib\0000\perfc.dat ============= FINISH: 18:03:45.98 =============== Many thanks hunterberg
Hello.

Please update Java and run an online scan.

Update Java to Version 6 Update 14

Your Java is out of date. Older versions have vulnerabilities that malicious sites can use to exploit and infect your system. Please follow these steps to remove older version Java components and update:
  • Download the latest version of Java Runtime Environment (JRE) Version 6 and save it to your desktop.
  • Look for Java Runtime Environment (JRE) JRE 6 Update 14.
  • Click the Download button to the right.
  • Select your Platform: "Windows".
  • Select your Language: "Multi-language".
  • Read the License Agreement, and then check the box that says: "Accept License Agreement".
  • Click Continue and the page will refresh.
  • Under Required Files, check the box for Windows Offline Installation, click the link below it and save the file to your desktop.
  • Close any programs you may have running - especially your web browser.
Go to Start > Settings > Control Panel, double-click on Add/Remove Programs and remove all older versions of Java.
  • Check (highlight) any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button and follow the onscreen instructions for the Java uninstaller.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u14-windows-i586-p.exe to install the newest version.
– If using Windows Vista and the installer refuses to launch due to insufficient user permissions, then Run As Administrator.
– If you choose to update via the Java applet in Control Panel, uncheck the option to install the Toolbar unless you want it.
– The uninstaller incorporated in this release removes previous Updates 10 and above, but does not remove older versions, so they still need to be removed manually.


Run Scan with Kaspersky

Please do a scan with Kaspersky Online Scanner. Please note: Kaspersky requires Java Runtime Environment (JRE) be installed before scanning for malware, as ActiveX is no longer being used.)

If you are using Windows Vista, open your browser by right-clicking on its icon and select 'Run as administrator' to perform this scan.


  • Open the Kaspersky WebScanner
    page.
  • Click on the 🖼Click to load external image (Posted Image) button on the main page.
  • The program will launch and fill in the Information section on the left.
  • Read the "Requirements and Limitations" then press the 🖼Click to load external image (Posted Image) button.
  • The program will begin downloading the latest program and definition files. It may take a while so please be patient and let it finish.
  • Once the files have been downloaded, click on the 🖼Click to load external image (Posted Image) …button.
    In the scan settings make sure the following are selected:
    • Detect malicious programs of the following categories:
      Viruses, Worms, Trojan Horses, Rootkits
      Spyware, Adware, Dialers and other potentially dangerous programs
    • Scan compound files (doesn't apply to the File scan area):
      Archives
      Mail databases
      By default the above items should already be checked.
    • Click the 🖼Click to load external image (Posted Image) button, if you made any changes.
  • Now under the Scan section on the left:

    Select My Computer
  • The program will now start and scan your system. This will run for a while, be patient and let it finish.
  • Once the scan is complete, click on View scan report
  • Now, click on the Save Report as button.
  • Save the file to your desktop.
  • Copy and paste that information in your next post.
You can refer to this animation by sundavis if needed.

Post a new set of DDS logs afterwards as well.

Thanks.

With Regards,
Extremeboy
Hi i had a few problems downloading the java application but got there in the end. i also had problems with the kaspersky scan which crashed four times however i finaly managed to get it to scan 100 % KASPERSKY ONLINE SCANNER 7.0 REPORT Thursday, July 9, 2009 Operating System: Microsoft Windows Vista Home Premium Edition, 32-bit Service Pack 1 (build 6001) Kaspersky Online Scanner version: 7.0.26.13 Program database last update: Thursday, July 09, 2009 17:31:01 Records in database: 2450155 ——————————————————————————– Scan settings: Scan using the following database: extended Scan archives: yes Scan mail databases: yes Scan area - My Computer: C:\ E:\ F:\ Scan statistics: Files scanned: 262368 Threat name: 3 Infected objects: 4 Suspicious objects: 0 Duration of the scan: 03:03:55 File name / Threat name / Threats count C:\Qoobox\Quarantine\C\Windows\System32\MSIVXevqqwpwoteljpwrxuwynrjwdwjtsssbl.dll.vir Infected: Packed.Win32.Tdss.w 1 C:\Qoobox\Quarantine\C\Windows\System32\MSIVXpbpvcahkidanlblbrrphvbqyiopfivfi.dll.vir Infected: Packed.Win32.Tdss.w 1 C:\Users\Hunter\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4IAPHH4V\setup[1].exe Infected: Trojan-Downloader.Win32.FraudLoad.eki 1 C:\Users\Hunter\DoctorWeb\Quarantine\VRT514C0.tmp Infected: Trojan.Win32.Qhost.lsd 1 The selected area was scanned. thanks for any help you can offer to get rid of these infected objects hunterberg
Hello.

Don't worry about the files in the C:\Qoobox folder. That folder is where Combofix quarantined the items it detected. Those will be removed once we unintall Combofix.

We will remove these however.

C:\Users\Hunter\DoctorWeb\Quarantine <- Please delete EVERYTHING in this folder

Now run ATFCleaner.

Download and Run ATFCleaner

Please download ATF Cleaner by Atribune. This program will clear out temporary files and settings. You will likely be logged out of the forum where you are recieving help.

  • Double-click ATF-Cleaner.exe to run the program.
  • Under Main Select Files to Delete choose: Select All.
  • Click the Empty Selected button.
If you use Firefox browser also…
  • Click Firefox at the top and choose: Select All
  • Click the Empty Selected button.
    NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browser also…
  • Click Opera at the top and choose: Select All
  • Click the Empty Selected button.
    NOTE: If you would like to keep your saved passwords, please click No at the prompt.

Take a new DDS run and post back with both logs in your next reply.

With Regards,
Extremeboy
Hi followed instructions and deleted everything in the dr web folder and here is the new dss log DDS (Ver_09-06-26.01) - NTFSx86 Run by [removed] at 17:48:19.16 on 10/07/2009 Internet Explorer: 8.0.6001.18783 Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.44.1033.18.2045.1024 [GMT 1:00] AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF} SP: Antispyware *enabled* (Updated) {57463B2F-DD60-468D-BC89-6D5403DDF541} SP: AVG Anti-Virus Free *enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF} SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} ============== Running Processes =============== C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k rpcss C:\Windows\System32\svchost.exe -k secsvcs C:\Windows\system32\Ati2evxx.exe C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k GPSvcGroup C:\Windows\system32\SLsvc.exe C:\Windows\system32\Ati2evxx.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Windows\system32\taskeng.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\svchost.exe -k hpdevmgmt C:\Windows\System32\svchost.exe -k HPZ12 C:\Windows\System32\svchost.exe -k HPZ12 C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Windows\system32\SearchIndexer.exe C:\Program Files\Windows Defender\MSASCui.exe C:\Windows\RtHDVCpl.exe C:\Program Files\HP\HP Software Update\hpwuSchd2.exe C:\PROGRA~1\AVG\AVG8\avgrsx.exe C:\Program Files\QuickTime\QTTask.exe C:\Windows\system32\DRIVERS\xaudio.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\AVG\AVG8\avgtray.exe C:\Program Files\Synaptics\SynTP\SynTPStart.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Windows\ehome\ehtray.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Program Files\MagicDisc\MagicDisc.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Windows\ehome\ehmsas.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Program Files\Google\Google Toolbar\GoogleToolbarUser.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchProtocolHost.exe C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Windows\system32\SearchFilterHost.exe C:\Windows\system32\Macromed\Flash\FlashUtil9f.exe C:\Users\Hunter\Desktop\ddsnew.scr C:\Windows\system32\wbem\wmiprvse.exe ============== Pseudo HJT Report =============== uInternet Settings,ProxyOverride = *.local uURLSearchHooks: H - No File uURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg8\toolbar\IEToolbar.dll mURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg8\toolbar\IEToolbar.dll BHO: HP Print Clips: {053f9267-dc04-4294-a72c-58f732d338c0} - c:\program files\hp\smart web printing\hpswp_framework.dll BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll BHO: {7E853D72-626A-48EC-A868-BA8D5E23E045} - No File BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg8\toolbar\IEToolbar.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.15642\swg.dll BHO: Windows Live Toolbar Helper: {bdbd1dad-c946-4a17-adc1-64b5b4ff55d0} - c:\program files\windows live toolbar\msntb.dll BHO: 1 (0x1) - No File BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll TB: Windows Live Toolbar: {bdad1dad-c946-4a17-adc1-64b5b4ff55d0} - c:\program files\windows live toolbar\msntb.dll TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar.dll TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - c:\program files\avg\avg8\toolbar\IEToolbar.dll TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe uRun: [Steam] "c:\program files\steam\Steam.exe" -silent uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide mRun: [RtHDVCpl] RtHDVCpl.exe mRun: [NeroFilterCheck] c:\program files\common files\ahead\lib\NeroCheck.exe mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe" mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe mRun: [SynTPStart] c:\program files\synaptics\syntp\SynTPStart.exe mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" StartupFolder: c:\users\hunter\appdata\roaming\micros~1\windows\startm~1\programs\startup\magicd~1.lnk - c:\program files\magicdisc\MagicDisc.exe mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: &Windows Live Search - c:\program files\windows live toolbar\msntb.dll/search.htm IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000 IE: {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe IE: {58ECB495-38F0-49cb-A538-10282ABF65E7} - {E763472E-A716-4CD9-89BD-DBDA6122F741} - c:\program files\hp\smart web printing\hpswp_extensions.dll IE: {700259D7-1666-479a-93B1-3250410481E8} - {A93C41D8-01F8-4F8B-B14C-DE20B117E636} - c:\program files\hp\smart web printing\hpswp_extensions.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://a1540.g.akamai.net/7/1540/52/20070501/qtinstall.info.apple.com/qtactivex/qtplugin.cab DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - hxxp://download.bitdefender.com/resources/scanner/sources/en/scan8/oscan8.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab DPF: {C237A80A-4C55-4C68-BAA9-CBE4408D12B2} - hxxp://download.sp.f-secure.com/ols/f-secure-rtm/resources/fslauncher.cab DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} - hxxp://utilities.pcpitstop.com/optimize2/pcpitstop2.dll Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll AppInit_DLLs: c:\windows\system32\avgrsstx.dll ============= SERVICES / DRIVERS =============== R0 O2MDRDR;O2MDRDR;c:\windows\system32\drivers\o2media.sys [2005-11-14 34176] R0 O2SDRDR;O2SDRDR;c:\windows\system32\drivers\o2sd.sys [2005-12-19 28800] R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-5-21 327688] R1 M9207;LifeView M9207 USB Digital TV BOX;c:\windows\system32\drivers\M9207BDA.sys [2007-6-11 54400] R2 avg8wd;AVG8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2008-5-21 298776] S3 RTL2831UBDA;REALTEK 2831U BDA Driver;c:\windows\system32\drivers\RTL2831UBDA.sys [2007-4-13 62720] S3 RTL2831UUSB;REALTEK 2831U USB Driver;c:\windows\system32\drivers\RTL2831UUSB.sys [2007-4-13 24064] =============== Created Last 30 ================ 2009-07-08 19:37 –d—– c:\users\hunter\.SunDownloadManager 2009-07-08 19:34 410,984 a——- c:\windows\system32\deploytk.dll 2009-07-06 20:32 –d—– c:\users\hunter\appdata\roaming\Malwarebytes 2009-07-06 20:32 38,160 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2009-07-06 20:32 19,096 a——- c:\windows\system32\drivers\mbam.sys 2009-07-06 20:32 –d—– c:\programdata\Malwarebytes 2009-07-06 20:32 –d—– c:\program files\Malwarebytes' Anti-Malware 2009-07-06 20:32 –d—– c:\progra~2\Malwarebytes 2009-07-06 19:06 –dsh— C:\$RECYCLE.BIN 2009-07-04 16:30 –d—– c:\users\hunter\appdata\roaming\Antispyware 2009-07-03 21:51 –d—– c:\users\hunter\DoctorWeb 2009-07-03 15:17 47,360 a——- c:\windows\system32\drivers\pcouffin.sys 2009-07-03 15:17 47,360 a——- c:\users\hunter\appdata\roaming\pcouffin.sys 2009-06-12 14:59 167,148,027 a——- c:\windows\MEMORY.DMP 2009-06-12 10:03 –d—– c:\programdata\AVG Security Toolbar 2009-06-12 10:03 –d—– c:\progra~2\AVG Security Toolbar ==================== Find3M ==================== 2009-07-03 15:18 86,016 a——- c:\windows\inf\infstrng.dat 2009-07-03 15:18 51,200 a——- c:\windows\inf\infpub.dat 2009-07-03 15:18 86,016 a——- c:\windows\inf\infstor.dat 2009-06-12 10:02 327,688 a——- c:\windows\system32\drivers\avgldx86.sys 2009-05-09 06:50 915,456 a——- c:\windows\system32\wininet.dll 2009-05-09 06:34 71,680 a——- c:\windows\system32\iesetup.dll 2009-05-06 10:15 11,952 a——- c:\windows\system32\avgrsstx.dll 2009-04-23 13:43 784,896 a——- c:\windows\system32\rpcrt4.dll 2009-04-23 13:42 636,928 a——- c:\windows\system32\localspl.dll 2009-04-21 12:55 2,033,152 a——- c:\windows\system32\win32k.sys 2008-07-22 00:18 174 a–sh— c:\program files\desktop.ini 2008-07-22 00:02 665,600 a——- c:\windows\inf\drvindex.dat 2006-11-02 13:42 287,440 a——- c:\windows\inf\perflib\0409\perfi.dat 2006-11-02 13:42 287,440 a——- c:\windows\inf\perflib\0409\perfh.dat 2006-11-02 13:42 30,674 a——- c:\windows\inf\perflib\0409\perfd.dat 2006-11-02 13:42 30,674 a——- c:\windows\inf\perflib\0409\perfc.dat 2006-11-02 10:20 287,440 a——- c:\windows\inf\perflib\0000\perfi.dat 2006-11-02 10:20 287,440 a——- c:\windows\inf\perflib\0000\perfh.dat 2006-11-02 10:20 30,674 a——- c:\windows\inf\perflib\0000\perfd.dat 2006-11-02 10:20 30,674 a——- c:\windows\inf\perflib\0000\perfc.dat ============= FINISH: 17:49:03.22 =============== Many thanks hunterberg
Hello. May I see the Attach log as well. The DDS.txt looks clean. Also, how is your computer running now? Any more problems or issues? With Regards, Extremeboy
Hi the computer seems to be running ok so i am hoping i got rid of everything although obviously i'm concerned incase their is anything hanging around that could cause me a problem. also when i ran ATI cleaner i noticed that something called prefetch was disabled does this matter ? here is the dds log DDS (Ver_09-06-26.01) - NTFSx86 Run by [removed] at 17:48:19.16 on 10/07/2009 Internet Explorer: 8.0.6001.18783 Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.44.1033.18.2045.1024 [GMT 1:00] AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF} SP: Antispyware *enabled* (Updated) {57463B2F-DD60-468D-BC89-6D5403DDF541} SP: AVG Anti-Virus Free *enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF} SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} ============== Running Processes =============== C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k rpcss C:\Windows\System32\svchost.exe -k secsvcs C:\Windows\system32\Ati2evxx.exe C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k GPSvcGroup C:\Windows\system32\SLsvc.exe C:\Windows\system32\Ati2evxx.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Windows\system32\taskeng.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\svchost.exe -k hpdevmgmt C:\Windows\System32\svchost.exe -k HPZ12 C:\Windows\System32\svchost.exe -k HPZ12 C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Windows\system32\SearchIndexer.exe C:\Program Files\Windows Defender\MSASCui.exe C:\Windows\RtHDVCpl.exe C:\Program Files\HP\HP Software Update\hpwuSchd2.exe C:\PROGRA~1\AVG\AVG8\avgrsx.exe C:\Program Files\QuickTime\QTTask.exe C:\Windows\system32\DRIVERS\xaudio.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\AVG\AVG8\avgtray.exe C:\Program Files\Synaptics\SynTP\SynTPStart.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Windows\ehome\ehtray.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Program Files\MagicDisc\MagicDisc.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Windows\ehome\ehmsas.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Program Files\Google\Google Toolbar\GoogleToolbarUser.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchProtocolHost.exe C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Windows\system32\SearchFilterHost.exe C:\Windows\system32\Macromed\Flash\FlashUtil9f.exe C:\Users\Hunter\Desktop\ddsnew.scr C:\Windows\system32\wbem\wmiprvse.exe ============== Pseudo HJT Report =============== uInternet Settings,ProxyOverride = *.local uURLSearchHooks: H - No File uURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg8\toolbar\IEToolbar.dll mURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg8\toolbar\IEToolbar.dll BHO: HP Print Clips: {053f9267-dc04-4294-a72c-58f732d338c0} - c:\program files\hp\smart web printing\hpswp_framework.dll BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll BHO: {7E853D72-626A-48EC-A868-BA8D5E23E045} - No File BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg8\toolbar\IEToolbar.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.15642\swg.dll BHO: Windows Live Toolbar Helper: {bdbd1dad-c946-4a17-adc1-64b5b4ff55d0} - c:\program files\windows live toolbar\msntb.dll BHO: 1 (0x1) - No File BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll TB: Windows Live Toolbar: {bdad1dad-c946-4a17-adc1-64b5b4ff55d0} - c:\program files\windows live toolbar\msntb.dll TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar.dll TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - c:\program files\avg\avg8\toolbar\IEToolbar.dll TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe uRun: [Steam] "c:\program files\steam\Steam.exe" -silent uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide mRun: [RtHDVCpl] RtHDVCpl.exe mRun: [NeroFilterCheck] c:\program files\common files\ahead\lib\NeroCheck.exe mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe" mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe mRun: [SynTPStart] c:\program files\synaptics\syntp\SynTPStart.exe mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" StartupFolder: c:\users\hunter\appdata\roaming\micros~1\windows\startm~1\programs\startup\magicd~1.lnk - c:\program files\magicdisc\MagicDisc.exe mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: &Windows Live Search - c:\program files\windows live toolbar\msntb.dll/search.htm IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000 IE: {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe IE: {58ECB495-38F0-49cb-A538-10282ABF65E7} - {E763472E-A716-4CD9-89BD-DBDA6122F741} - c:\program files\hp\smart web printing\hpswp_extensions.dll IE: {700259D7-1666-479a-93B1-3250410481E8} - {A93C41D8-01F8-4F8B-B14C-DE20B117E636} - c:\program files\hp\smart web printing\hpswp_extensions.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://a1540.g.akamai.net/7/1540/52/20070501/qtinstall.info.apple.com/qtactivex/qtplugin.cab DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - hxxp://download.bitdefender.com/resources/scanner/sources/en/scan8/oscan8.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab DPF: {C237A80A-4C55-4C68-BAA9-CBE4408D12B2} - hxxp://download.sp.f-secure.com/ols/f-secure-rtm/resources/fslauncher.cab DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} - hxxp://utilities.pcpitstop.com/optimize2/pcpitstop2.dll Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll AppInit_DLLs: c:\windows\system32\avgrsstx.dll ============= SERVICES / DRIVERS =============== R0 O2MDRDR;O2MDRDR;c:\windows\system32\drivers\o2media.sys [2005-11-14 34176] R0 O2SDRDR;O2SDRDR;c:\windows\system32\drivers\o2sd.sys [2005-12-19 28800] R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-5-21 327688] R1 M9207;LifeView M9207 USB Digital TV BOX;c:\windows\system32\drivers\M9207BDA.sys [2007-6-11 54400] R2 avg8wd;AVG8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2008-5-21 298776] S3 RTL2831UBDA;REALTEK 2831U BDA Driver;c:\windows\system32\drivers\RTL2831UBDA.sys [2007-4-13 62720] S3 RTL2831UUSB;REALTEK 2831U USB Driver;c:\windows\system32\drivers\RTL2831UUSB.sys [2007-4-13 24064] =============== Created Last 30 ================ 2009-07-08 19:37 –d—– c:\users\hunter\.SunDownloadManager 2009-07-08 19:34 410,984 a——- c:\windows\system32\deploytk.dll 2009-07-06 20:32 –d—– c:\users\hunter\appdata\roaming\Malwarebytes 2009-07-06 20:32 38,160 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2009-07-06 20:32 19,096 a——- c:\windows\system32\drivers\mbam.sys 2009-07-06 20:32 –d—– c:\programdata\Malwarebytes 2009-07-06 20:32 –d—– c:\program files\Malwarebytes' Anti-Malware 2009-07-06 20:32 –d—– c:\progra~2\Malwarebytes 2009-07-06 19:06 –dsh— C:\$RECYCLE.BIN 2009-07-04 16:30 –d—– c:\users\hunter\appdata\roaming\Antispyware 2009-07-03 21:51 –d—– c:\users\hunter\DoctorWeb 2009-07-03 15:17 47,360 a——- c:\windows\system32\drivers\pcouffin.sys 2009-07-03 15:17 47,360 a——- c:\users\hunter\appdata\roaming\pcouffin.sys 2009-06-12 14:59 167,148,027 a——- c:\windows\MEMORY.DMP 2009-06-12 10:03 –d—– c:\programdata\AVG Security Toolbar 2009-06-12 10:03 –d—– c:\progra~2\AVG Security Toolbar ==================== Find3M ==================== 2009-07-03 15:18 86,016 a——- c:\windows\inf\infstrng.dat 2009-07-03 15:18 51,200 a——- c:\windows\inf\infpub.dat 2009-07-03 15:18 86,016 a——- c:\windows\inf\infstor.dat 2009-06-12 10:02 327,688 a——- c:\windows\system32\drivers\avgldx86.sys 2009-05-09 06:50 915,456 a——- c:\windows\system32\wininet.dll 2009-05-09 06:34 71,680 a——- c:\windows\system32\iesetup.dll 2009-05-06 10:15 11,952 a——- c:\windows\system32\avgrsstx.dll 2009-04-23 13:43 784,896 a——- c:\windows\system32\rpcrt4.dll 2009-04-23 13:42 636,928 a——- c:\windows\system32\localspl.dll 2009-04-21 12:55 2,033,152 a——- c:\windows\system32\win32k.sys 2008-07-22 00:18 174 a–sh— c:\program files\desktop.ini 2008-07-22 00:02 665,600 a——- c:\windows\inf\drvindex.dat 2006-11-02 13:42 287,440 a——- c:\windows\inf\perflib\0409\perfi.dat 2006-11-02 13:42 287,440 a——- c:\windows\inf\perflib\0409\perfh.dat 2006-11-02 13:42 30,674 a——- c:\windows\inf\perflib\0409\perfd.dat 2006-11-02 13:42 30,674 a——- c:\windows\inf\perflib\0409\perfc.dat 2006-11-02 10:20 287,440 a——- c:\windows\inf\perflib\0000\perfi.dat 2006-11-02 10:20 287,440 a——- c:\windows\inf\perflib\0000\perfh.dat 2006-11-02 10:20 30,674 a——- c:\windows\inf\perflib\0000\perfd.dat 2006-11-02 10:20 30,674 a——- c:\windows\inf\perflib\0000\perfc.dat ============= FINISH: 17:49:03.22 =============== many thanks hunterberg
Hello.

Hi the computer seems to be running ok so i am hoping i got rid of everything although obviously i'm concerned incase their is anything hanging around that could cause me a problem. also when i ran ATI cleaner i noticed that something called prefetch was disabled does this matter ?

That is normal. It's suppose to be disabled in Vista machines.

You posted the DDS.txt log. I want to see the Attach.txt log. ;)

Thanks.

With Regards,
Extremeboy

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI