This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] random clip plays several times with no applications running

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I got my hard drive replaced two weeks ago put vista back on and put all my data back on. Since then I have this random clip that plays even if no applications are open (in task manager) The clip says something about chinese dating. I cannot figure out what is running this or when it runs. It has ran two times since typing this. Around the same time as this my headphones do not work anymore. I plug them in and the audio still plays through the front speakers of my laptop. When I do a test of the headphones through the control panel I hear the noises in the headphones but thats it. I'm not sure if some infenction messed with the inputs and outputs of my laptop. I've pasted the hijackthis log. I hope someone can give me some help.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:59:27 PM, on 04/03/2010
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\AVG\AVG9\avgtray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Dell V305\dldtmon.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Dell V305\dldtMsdMon.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\Program Files\iTunes\iTunes.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10e.exe
C:\Program Files\AVG\AVG9\avgui.exe
C:\Program Files\AVG\AVG9\avgcfgex.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\TrendMicro\HiJackThis\HiJackThis.exe
C:\Windows\system32\Taskmgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\SearchFilterHost.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: D - {3BA671C8-59B6-3196-908E-255F17132706} - C:\Windows\system32\js30374.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [dldtmon.exe] "C:\Program Files\Dell V305\dldtmon.exe"
O4 - HKLM\..\Run: [dldtamon] "C:\Program Files\Dell V305\dldtamon.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: OpenOffice.org 3.1.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
O13 - Gopher Prefix:
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Free E-mail Scanner (avg9emc) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgemc.exe
O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: dldtCATSCustConnectService - Unknown owner - C:\Windows\system32\spool\DRIVERS\W32X86\3\\dldtserv.exe
O23 - Service: dldt_device - - C:\Windows\system32\dldtcoms.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

–
End of file - 5699 bytes
I followed the steps in the are you infected topic. Here are the log results. Malware found 7 infectoins and I removed them all. the gmer rootkit app crashed my computer while scanning so I'm not sure what that means?? malware log: Malwarebytes' Anti-Malware 1.44 Database version: 3825 Windows 6.0.6001 Service Pack 1 Internet Explorer 7.0.6001.18000 04/03/2010 11:50:40 PM mbam-log-2010-03-04 (23-50-40).txt Scan type: Quick Scan Objects scanned: 99007 Time elapsed: 5 minute(s), 8 second(s) Memory Processes Infected: 0 Memory Modules Infected: 1 Registry Keys Infected: 8 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 1 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: C:\Windows\System32\js30374.dll (Trojan.BHO) -> Delete on reboot. Registry Keys Infected: HKEY_CLASSES_ROOT\TypeLib\{2afaf4a0-b3e0-3800-960a-48f29708a8e4} (Trojan.BHO) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{0a0b1526-0c8b-3f97-a777-4f0a1eef88fa} (Trojan.BHO) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{3ba671c8-59b6-3196-908e-255f17132706} (Trojan.BHO) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{3ba671c8-59b6-3196-908e-255f17132706} (Trojan.BHO) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3ba671c8-59b6-3196-908e-255f17132706} (Trojan.BHO) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\D (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\D.1 (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ctfmon.exe (Security.Hijack) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: C:\Windows\System32\js30374.dll (Trojan.BHO) -> Delete on reboot. DDS logs: DDS (Ver_09-06-26.01) - NTFSx86 Run by [removed] at 0:15:25.05 on 05/03/2010 Internet Explorer: 7.0.6001.18000 Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.2.1033.18.2038.1048 [GMT -5:00] SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} ============== Running Processes =============== C:\Windows\system32\wininit.exe C:\Program Files\AVG\AVG9\avgchsvx.exe C:\Program Files\AVG\AVG9\avgrsx.exe C:\Windows\system32\lsm.exe C:\Program Files\AVG\AVG9\avgcsrvx.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k rpcss C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Windows\system32\taskeng.exe C:\Program Files\AVG\AVG9\avgwdsvc.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Windows\system32\dldtcoms.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Windows\system32\SearchIndexer.exe C:\Program Files\AVG\AVG9\avgemc.exe C:\Program Files\AVG\AVG9\avgnsx.exe C:\Program Files\AVG\AVG9\avgcsrvx.exe C:\Windows\system32\WUDFHost.exe C:\Windows\system32\taskeng.exe C:\Windows\System32\mobsync.exe C:\Windows\System32\igfxtray.exe C:\Windows\System32\igfxpers.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\Program Files\AVG\AVG9\avgtray.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Dell V305\dldtmon.exe C:\Windows\system32\igfxsrvc.exe C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe C:\Program Files\Dell V305\dldtMsdMon.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Program Files\OpenOffice.org 3\program\soffice.exe C:\Program Files\OpenOffice.org 3\program\soffice.bin C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Internet Explorer\ieuser.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe C:\Windows\system32\Macromed\Flash\FlashUtil10e.exe C:\Users\Brandy\Desktop\dds.scr C:\Windows\system32\conime.exe C:\Windows\system32\wbem\wmiprvse.exe ============== Pseudo HJT Report =============== uStart Page = hxxp://www.google.ca/ uInternet Settings,ProxyOverride = *.local BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide mRun: [IgfxTray] c:\windows\system32\igfxtray.exe mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe mRun: [Persistence] c:\windows\system32\igfxpers.exe mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" mRun: [AVG9_TRAY] c:\progra~1\avg\avg9\avgtray.exe mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [dldtmon.exe] "c:\program files\dell v305\dldtmon.exe" mRun: [dldtamon] "c:\program files\dell v305\dldtamon.exe" mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe" mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" StartupFolder: c:\users\brandy\appdata\roaming\micros~1\windows\startm~1\programs\startup\openof~1.lnk - c:\program files\openoffice.org 3\program\quickstart.exe mPolicies-system: EnableUIADesktopToggle = 0 (0x0) DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg9\avgpp.dll Notify: igfxcui - igfxdev.dll AppInit_DLLs: avgrsstx.dll ============= SERVICES / DRIVERS =============== R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2010-2-4 333192] R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2010-2-4 360584] R2 avg9emc;AVG Free E-mail Scanner;c:\program files\avg\avg9\avgemc.exe [2010-2-4 906520] R2 avg9wd;AVG Free WatchDog;c:\program files\avg\avg9\avgwdsvc.exe [2010-2-4 285392] R2 dldt_device;dldt_device;c:\windows\system32\dldtcoms.exe -service –> c:\windows\system32\dldtcoms.exe -service [?] S2 dldtCATSCustConnectService;dldtCATSCustConnectService;c:\windows\system32\spool\drivers\w32x86\3\dldtserv.exe [2008-2-25 99568] =============== Created Last 30 ================ 2010-03-04 23:42 –d—– c:\users\brandy\appdata\roaming\Malwarebytes 2010-03-04 23:42 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2010-03-04 23:42 –d—– c:\programdata\Malwarebytes 2010-03-04 23:42 –d—– c:\progra~2\Malwarebytes 2010-03-04 23:42 19,160 a——- c:\windows\system32\drivers\mbam.sys 2010-03-04 23:42 –d—– c:\program files\Malwarebytes' Anti-Malware 2010-03-04 22:59 –d—– c:\program files\Trend Micro 2010-03-04 19:42 –d—– c:\users\brandy\appdata\roaming\AVG9 2010-03-04 19:29 –d—– c:\program files\TrendMicro 2010-03-03 20:36 –d—– c:\programdata\PrevxCSI 2010-03-03 20:36 –d—– c:\progra~2\PrevxCSI 2010-02-27 11:10 –d—– c:\programdata\Yahoo! 2010-02-27 11:08 –d—– c:\program files\Yahoo! 2010-02-16 20:21 2,421,760 a——- c:\windows\system32\wucltux.dll 2010-02-16 20:21 87,552 a——- c:\windows\system32\wudriver.dll 2010-02-16 20:21 171,608 a——- c:\windows\system32\wuwebv.dll 2010-02-16 20:21 33,792 a——- c:\windows\system32\wuapp.exe 2010-02-15 22:06 –d—– c:\users\brandy\appdata\roaming\Dell Imaging Toolbox 2010-02-14 18:20 –d—– c:\programdata\Adobe 2010-02-14 18:18 –d—– c:\programdata\NOS 2010-02-14 02:57 203,183,705 a——- c:\windows\MEMORY.DMP 2010-02-12 23:19 –d—– C:\My Downloads 2010-02-12 23:19 –d—– c:\program files\BearShare 2010-02-12 18:47 –d—– c:\programdata\Dl_cats 2010-02-12 18:47 –d—– c:\progra~2\Dl_cats 2010-02-12 18:45 –d—– C:\logs 2010-02-12 18:43 72,625 a——- c:\windows\system32\dldtprpr.chm 2010-02-12 18:43 360,448 a——- c:\windows\system32\dldtcoin.dll 2010-02-12 18:40 –d—– c:\program files\Abbyy FineReader 6.0 Sprint 2010-02-12 18:38 102,400 a——- c:\windows\system32\dldtwupd.dll 2010-02-12 18:38 17,648 a——- c:\windows\system32\dldtwupd.exe 2010-02-12 18:38 –d—– c:\program files\Dell V305 2010-02-12 18:38 438,272 a——- c:\windows\system32\DLDThcp.dll 2010-02-12 18:38 348,160 a——- c:\windows\system32\DLDTinst.dll 2010-02-12 18:38 364,544 a——- c:\windows\system32\dldtinpa.dll 2010-02-12 18:21 –d—– c:\users\brandy\appdata\roaming\OpenOffice.org 2010-02-11 23:36 107,368 a——- c:\windows\system32\GEARAspi.dll 2010-02-11 23:36 26,600 a——- c:\windows\system32\drivers\GEARAspiWDM.sys 2010-02-11 23:35 –d—– c:\program files\iPod 2010-02-11 23:35 –d—– c:\programdata\{755AC846-7372-4AC8-8550-C52491DAA8BD} 2010-02-11 23:35 –d—– c:\program files\iTunes 2010-02-11 23:35 –d—– c:\progra~2\{755AC846-7372-4AC8-8550-C52491DAA8BD} 2010-02-11 23:34 –d—– c:\program files\Bonjour 2010-02-11 23:33 –d—– c:\programdata\Apple Computer 2010-02-11 23:30 –d—– c:\programdata\Apple 2010-02-11 23:20 –d—– c:\windows\Panther 2010-02-11 23:19 8,192 a–s-r– C:\BOOTSECT.BAK 2010-02-11 23:19 333,203 a–shr– C:\bootmgr 2010-02-11 23:19 –dsh— C:\Boot 2010-02-11 23:19 24 a—hr– c:\windows\dell_version 2010-02-11 23:19 –d—– c:\windows\system32\OEM 2010-02-04 23:26 –d-h— C:\$AVG 2010-02-04 23:26 12,464 a——- c:\windows\system32\avgrsstx.dll 2010-02-04 23:26 360,584 a——- c:\windows\system32\drivers\avgtdix.sys 2010-02-04 23:26 333,192 a——- c:\windows\system32\drivers\avgldx86.sys 2010-02-04 23:26 –d—– c:\windows\system32\drivers\Avg 2010-02-04 23:26 –d—– c:\programdata\avg9 2010-02-04 23:26 –d—– c:\program files\AVG 2010-02-04 23:26 –d—– c:\progra~2\avg9 2010-02-04 23:03 –d—– c:\program files\JRE 2010-02-04 23:03 –d—– c:\program files\OpenOffice.org 3 2010-02-04 23:03 411,368 a——- c:\windows\system32\deploytk.dll 2010-02-04 23:02 –dsh— c:\windows\Installer 2010-02-04 22:58 0 a—h— c:\windows\system32\drivers\Msft_User_WpdFs_01_00_00.Wdf 2010-02-04 22:57 53,248 a——- c:\windows\system32\CSVer.dll 2010-02-04 22:51 16,058 a——- c:\windows\system32\results.xml 2010-02-04 22:48 920,088 a——- c:\windows\system32\igxpun.exe 2010-02-04 22:48 319,456 a——- c:\windows\system32\difxapi.dll 2010-02-04 22:48 –d—– c:\windows\system32\Lang 2010-02-04 22:47 –d—– C:\Intel 2010-02-04 22:47 –d—– C:\swsetup 2010-02-04 20:48 –d—– c:\users\brandy\My Downloads 2010-02-04 20:38 –d—– c:\users\Brandy ==================== Find3M ==================== 2010-02-21 18:49 86,016 a——- c:\windows\inf\infstrng.dat 2010-02-21 18:49 86,016 a——- c:\windows\inf\infstor.dat 2010-02-21 18:49 51,200 a——- c:\windows\inf\infpub.dat 2010-02-21 18:49 665,600 a——- c:\windows\inf\drvindex.dat 2008-01-20 21:43 174 a–sh— c:\program files\desktop.ini 2006-11-02 07:42 287,440 a——- c:\windows\inf\perflib\0409\perfi.dat 2006-11-02 07:42 287,440 a——- c:\windows\inf\perflib\0409\perfh.dat 2006-11-02 07:42 30,674 a——- c:\windows\inf\perflib\0409\perfd.dat 2006-11-02 07:42 30,674 a——- c:\windows\inf\perflib\0409\perfc.dat 2006-11-02 04:20 287,440 a——- c:\windows\inf\perflib\0000\perfi.dat 2006-11-02 04:20 287,440 a——- c:\windows\inf\perflib\0000\perfh.dat 2006-11-02 04:20 30,674 a——- c:\windows\inf\perflib\0000\perfd.dat 2006-11-02 04:20 30,674 a——- c:\windows\inf\perflib\0000\perfc.dat ============= FINISH: 0:16:35.62 =============== Attach log from DDS: UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT DDS (Ver_09-06-26.01) Microsoft® Windows Vista™ Home Premium Boot Device: \Device\HarddiskVolume1 Install Date: 2/11/2010 8:25:38 PM System Uptime: 3/5/2010 12:12:18 AM (0 hours ago) Motherboard: Quanta | | 30CC Processor: Intel® Core™2 Duo CPU T5450 @ 1.66GHz | U2E1 | 1667/667mhz ==== Disk Partitions ========================= C: is FIXED (NTFS) - 149 GiB total, 96.859 GiB free. D: is FIXED (NTFS) - 75 GiB total, 74.144 GiB free. E: is CDROM () G: is Removable ==== Disabled Device Manager Items ============= Class GUID: Description: Base System Device Device ID: PCI\VEN_1180&DEV_0843&SUBSYS_30CC103C&REV_12\4&2C3A0EB7&0&4AF0 Manufacturer: Name: Base System Device PNP Device ID: PCI\VEN_1180&DEV_0843&SUBSYS_30CC103C&REV_12\4&2C3A0EB7&0&4AF0 Service: Class GUID: Description: Base System Device Device ID: PCI\VEN_1180&DEV_0592&SUBSYS_30CC103C&REV_12\4&2C3A0EB7&0&4BF0 Manufacturer: Name: Base System Device PNP Device ID: PCI\VEN_1180&DEV_0592&SUBSYS_30CC103C&REV_12\4&2C3A0EB7&0&4BF0 Service: Class GUID: Description: Base System Device Device ID: PCI\VEN_1180&DEV_0852&SUBSYS_30CC103C&REV_12\4&2C3A0EB7&0&4CF0 Manufacturer: Name: Base System Device PNP Device ID: PCI\VEN_1180&DEV_0852&SUBSYS_30CC103C&REV_12\4&2C3A0EB7&0&4CF0 Service: Class GUID: Description: Device ID: ACPI\HPQ0006\4&1D8D756B&0 Manufacturer: Name: PNP Device ID: ACPI\HPQ0006\4&1D8D756B&0 Service: ==== System Restore Points =================== ==== Installed Programs ====================== ABBYY FineReader 6.0 Sprint Acrobat.com Adobe AIR Adobe Flash Player 10 ActiveX Adobe Reader 9.3 Apple Application Support Apple Mobile Device Support Apple Software Update AVG Free 9.0 BearShare Bonjour Dell V305 ERUNT 1.1j HiJackThis HijackThis 2.0.2 Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) Intel® Graphics Media Accelerator Driver iTunes Java™ 6 Update 16 Malwarebytes' Anti-Malware Microsoft .NET Framework 3.5 SP1 Microsoft Visual C++ 2005 Redistributable OpenOffice.org 3.1 QuickTime ==== End Of File ===========================
Hi please try running GMER in safe mode, uncheck the box beside "files" as well, make sure all the security programs are disabled and all other programs closed.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI