This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Trojan Freezing my computer & making bluescreens

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi all! I have a quite new computer. Bought it last year. Got vista as system. When I start my computer it runs fine for 30 sec (HAPPENS MOST OF THE TIME, not all the time so im able to operate on the computer after a cupple of tries) , after that I either get a bluescreen or it just freezes and im not able to do anything. Been searching internet for results but cant find any good solutions… I have cleaned my computer from dust ect, it got a bit better (Well sounds a bit better but not more tbh). I have tryed several programs to remove/seach for virus with no more result than Avira finding a TR/CryptXpack.gen … After reading up on the trojan it seems to be the guility one for this. Or well so I think? Avira cant remove it nor any other program, it just puts it away , cant find it manualy either.. Anyone have any ideas on how to remove the virus? Do you belive my problems is coused by anyother couse? Please make an "easy to follow" way of help. Thanks! :D /K
Hello and Posted Image

My name is patndoris. I will be glad to take a look at your log and help you with solving any malware problems. It will be very helpful if you follow these guidelines:
  • Malware logs are often lengthy and can take a lot of time to research and interpret. Please be patient while I review your logs.
  • Please note that there is no "Quick Fix" to modern malware infections and we may need to use several different approaches to get your system clean.
  • Please make sure to carefully read any instruction that I give you. If you're not sure, or if something unexpected happens, do NOT continue! Stop and ask!
  • Please follow my instructions carefully and in the order they are posted. You may also find it helpful to print out the instructions you receive.
  • Please do not run any scans or install/uninstall any applications or delete anything without being directed to do so.
  • Remember, absence of symptoms does not mean the infection is all gone. Please stick with me till you're given the "all clear".
  • Please do not use the Attachment feature for any log file. Do a Copy/Paste of the entire contents of the log file and submit it inside your post.
  • Please reply within 3 days. If I do not hear back from you in that time frame, I will post a reminder for you. Topics with no reply in 4 days are closed!
Please be advised I am still in training, and all of my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advice.
This may cause a delay in response time, but I will do my best to keep it as short as possible.

I will post back shortly with instructions.
Download and Run DDS by sUBs

Please download DDS by sUBs from one of the following links and save it to your desktop.
    • DDS.scr
    • DDS.pif
  • Disable any script blocking protection (How to Disable your Security Programs)
  • Double click DDS icon to run the tool (may take up to 3 minutes to run)
  • When done, DDS.txt will open.
  • After a few moments, attach.txt will open in a second window.
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scroling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.

If you have any trouble doing this, please let me know.
Hey! Thanks for the help! I will get to my mother soon (the computer is there). I will be there on tuesday. I will send you a report then. Is it ok? Thanks again!
I appreciate you letting me know about the delay. As long as I know, then it's fine. Just go ahead and reply on Tuesday and we can go from there.
Here is the first one. The other one is attached, not zipped though tell me if I need to zipp it. Thanks again. DDS (Ver_10-12-12.02) - NTFS_AMD64 Run by [removed] at 19:40:52,78 on 2011-01-25 Internet Explorer: 7.0.6002.18005 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.46.1053.18.4094.2134 [GMT 1:00] AV: avast! Antivirus *Disabled/Updated* {C37D8F93-0602-E43C-40AA-47DAD597F308} AV: Norton Internet Security *Disabled/Outdated* {88C95A36-8C3B-2F2C-1B8B-30FCCFDC4855} AV: AntiVir Desktop *Disabled/Updated* {090F9C29-64CE-6C6F-379C-5901B49A85B7} SP: avast! Antivirus *Disabled/Updated* {781C6E77-2038-EBB2-7A1A-7CA8AE10B9B5} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} SP: AntiVir Desktop *Disabled/Updated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A} SP: Norton Internet Security *Disabled/Updated* {33A8BBD2-AA01-20A2-213B-0B8EB45B02E8} FW: Norton Internet Security *Disabled* {B0F2DB13-C654-2E74-30D4-99C9310F0F2E} ============== Running Processes =============== C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\nvvsvc.exe C:\Windows\system32\svchost.exe -k rpcss C:\Windows\System32\svchost.exe -k secsvcs C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\nvvsvc.exe C:\Windows\SYSTEM32\WISPTIS.EXE C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe C:\Windows\system32\svchost.exe -k NetworkService C:\Program Files\Alwil Software\Avast5\AvastSvc.exe C:\Windows\system32\taskeng.exe C:\Windows\System32\spoolsv.exe C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\ProgramData\DatacardService\DCSHost.exe C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBService.exe C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe C:\Program Files (x86)\Norton Internet Security\Engine\16.0.0.125\ccSvcHst.exe C:\Windows\SysWOW64\IoctlSvc.exe C:\Windows\SysWOW64\PnkBstrA.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\system32\svchost.exe -k imgsvc C:\Program Files\Tablet\Pen\Pen_Tablet.exe C:\Program Files (x86)\Fujitsu\SystemDiagnostics\OnlineDiagnostic\TestManager\TestHandler.exe C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Windows\system32\SearchIndexer.exe C:\Windows\system32\WUDFHost.exe C:\Windows\servicing\TrustedInstaller.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files (x86)\Norton Internet Security\Engine\16.0.0.125\ccSvcHst.exe C:\Windows\SYSTEM32\WISPTIS.EXE C:\Windows\system32\taskeng.exe C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe C:\ProgramData\DatacardService\DataCardMonitor.exe C:\Windows\System32\mobsync.exe C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe C:\Program Files\Windows Defender\MSASCui.exe C:\Program Files\Tablet\Pen\Pen_TabletUser.exe C:\Program Files\Tablet\Pen\Pen_Tablet.exe C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe C:\Windows\WindowsMobile\wmdSync.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Windows\system32\svchost.exe -k WindowsMobile C:\Program Files (x86)\Bamboo Dock\Bamboo Dock\Bamboo Dock.exe C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe C:\Program Files (x86)\Bamboo Dock\BambooCore.exe C:\Program Files\Alwil Software\Avast5\AvastUI.exe C:\Windows\system32\wbem\unsecapp.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Users\Kalle\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Kalle\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Kalle\AppData\Local\Google\Chrome\Application\chrome.exe C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe C:\Windows\system32\wuauclt.exe C:\Users\Kalle\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Kalle\AppData\Local\Google\Chrome\Application\chrome.exe C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\DllHost.exe C:\Users\Kalle\Downloads\dds.scr C:\Windows\SysWOW64\conime.exe C:\Windows\system32\wbem\wmiprvse.exe ============== Pseudo HJT Report =============== uInternet Settings,ProxyOverride = *.local uURLSearchHooks: uTorrentBar Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files (x86)\uTorrentBar\tbuTor.dll mURLSearchHooks: uTorrentBar Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files (x86)\uTorrentBar\tbuTor.dll mWinlogon: Userinit=userinit.exe BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll BHO: Conduit Engine: {30f9b915-b755-4826-820b-08fba6bd249d} - C:\Program Files (x86)\ConduitEngine\ConduitEngine.dll BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - C:\Program Files (x86)\Norton Internet Security\Engine\16.0.0.125\coIEPlg.dll BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - C:\Program Files (x86)\Norton Internet Security\Engine\16.0.0.125\IPSBHO.DLL BHO: Windows Live inloggningshjälpen: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll BHO: uTorrentBar Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files (x86)\uTorrentBar\tbuTor.dll TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - C:\Program Files (x86)\Norton Internet Security\Engine\16.0.0.125\coIEPlg.dll TB: uTorrentBar Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files (x86)\uTorrentBar\tbuTor.dll TB: Conduit Engine: {30f9b915-b755-4826-820b-08fba6bd249d} - C:\Program Files (x86)\ConduitEngine\ConduitEngine.dll uRun: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun uRun: [Google Update] "C:\Users\Kalle\AppData\Local\Google\Update\GoogleUpdate.exe" /c uRun: [Bamboo Dock] "C:\Program Files (x86)\Bamboo Dock\Bamboo Dock\Bamboo Dock.exe" mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" mRun: [FSCRecovery] c:\Program Files (x86)\Fujitsu\System Recovery\FSCRecoveryReminder.exe mRun: [SwitchBoard] "C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" mRun: [AdobeCS5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" mRun: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min mRun: [BambooCore] "C:\Program Files (x86)\Bamboo Dock\BambooCore.exe" mRun: [avast5] "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui dRun: [fts-reg] c:\fts-reg\ftsreg.exe StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\MICROS~1.LNK - C:\Program Files (x86)\Microsoft Office\Office\OSA9.EXE mPolicies-explorer: NoActiveDesktop = 1 (0x1) mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1) mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} - hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} TB-X64: {BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - No File mRun-x64: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide mRun-x64: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe mRun-x64: [Skytel] C:\Program Files\Realtek\Audio\HDA\Skytel.exe mRun-x64: [Windows Mobile-based device management] %windir%\WindowsMobile\wmdSync.exe mRun-x64: [AdobeAAMUpdater-1.0] "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" ============= SERVICES / DRIVERS =============== R0 SymEFA;Symantec Extended File Attributes;C:\Windows\System32\drivers\NISx64\1000000.07D\SymEFA64.sys [2009-4-22 402480] R1 aswSP;aswSP;C:\Windows\System32\drivers\aswSP.sys [2011-1-18 273488] R1 ccHP;Symantec Hash Provider;C:\Windows\System32\drivers\NISx64\1000000.07D\ccHPx64.sys [2009-4-22 428592] R1 IDSVia64;IDSVia64;C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20080826.006\IDSVia64.sys [2009-4-22 395312] R2 AntiVirSchedulerService;Avira AntiVir Scheduler;C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [2010-12-18 135336] R2 AntiVirService;Avira AntiVir Guard;C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [2010-12-18 267944] R2 aswFsBlk;aswFsBlk;C:\Windows\System32\drivers\aswFsBlk.sys [2011-1-18 20560] R2 aswMonFlt;aswMonFlt;C:\Windows\System32\drivers\aswMonFlt.sys [2011-1-18 62032] R2 avast! Antivirus;avast! Antivirus;C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2011-1-18 40384] R2 avgntflt;avgntflt;C:\Windows\System32\drivers\avgntflt.sys [2010-12-18 83120] R2 DCSHost.exe;DCSHost.exe;C:\ProgramData\DatacardService\DCSHOST.exe [2009-11-6 110592] R2 Norton Internet Security;Norton Internet Security;C:\Program Files (x86)\Norton Internet Security\Engine\16.0.0.125\ccSvcHst.exe [2009-4-22 115560] R2 TabletServicePen;TabletServicePen;C:\Program Files\Tablet\Pen\Pen_Tablet.exe [2010-12-24 7329648] R3 netr28ux;RT2870 USB Wireless LAN Card Driver for Vista;C:\Windows\System32\drivers\netr28ux.sys [2009-10-12 811008] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576] S3 EraserUtilRebootDrv;EraserUtilRebootDrv;C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2009-4-22 128048] S3 FontCache;Windows Font Cache Service;C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-21 27648] S3 hwusbfake;Huawei DataCard USB Fake;C:\Windows\System32\drivers\ewusbfake.sys [2009-11-6 116224] S3 PerfHost;Värd för prestandaräknar-DLL;C:\Windows\SysWOW64\perfhost.exe [2008-1-21 19968] S3 SwitchBoard;SwitchBoard;C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-2-19 517096] S3 SYMNDISV;SYMNDISV;C:\Windows\System32\drivers\NISx64\1000000.07D\symndisv.sys [2009-4-22 46640] S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\drivers\usbaapl64.sys [2010-4-19 50688] S3 wacmoumonitor;Wacom Mode Helper;C:\Windows\System32\drivers\wacmoumonitor.sys [2010-12-24 18288] S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-3-18 1020768] S4 clr_optimization_v2.0.50727_64;Microsoft .NET Framework NGEN v2.0.50727_X64;C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe [2009-12-3 89920] S4 TouchServicePen;Wacom Consumer Touch Service;C:\Program Files\Tablet\Pen\Pen_TouchService.exe [2010-12-24 719216] S4 VoddlerNet;VoddlerNet;C:\Program Files (x86)\Voddler\service\voddler.exe [2009-12-17 1241296] =============== Created Last 30 ================ 2011-01-18 21:33:54 ——– d—–w- C:\Program Files (x86)\Windows Portable Devices 2011-01-18 21:33:53 ——– d—–w- C:\Program Files\Windows Portable Devices 2011-01-18 20:24:58 62032 —-a-w- C:\Windows\System32\drivers\aswMonFlt.sys 2011-01-18 20:24:40 38848 —-a-w- C:\Windows\avastSS.scr 2011-01-18 20:24:32 ——– d—–w- C:\PROGRA~3\Alwil Software 2011-01-18 18:59:08 8199504 —-a-w- C:\PROGRA~3\Microsoft\Windows Defender\Definition Updates\{DD61F914-BD3B-4A3D-90E2-7101781301EE}\mpengine.dll 2011-01-18 18:52:49 34816 —-a-w- C:\Windows\System32\WPDShextAutoplay.exe 2011-01-18 18:51:18 4096 —-a-w- C:\Windows\SysWow64\oleaccrc.dll 2011-01-18 18:51:18 4096 —-a-w- C:\Windows\System32\oleaccrc.dll 2011-01-18 18:51:17 736256 —-a-w- C:\Windows\System32\UIAutomationCore.dll 2011-01-18 18:51:17 555520 —-a-w- C:\Windows\SysWow64\UIAutomationCore.dll 2011-01-18 18:51:17 315904 —-a-w- C:\Windows\System32\oleacc.dll 2011-01-18 18:51:17 234496 —-a-w- C:\Windows\SysWow64\oleacc.dll 2011-01-18 18:47:12 92672 —-a-w- C:\Windows\SysWow64\UIAnimation.dll 2011-01-18 18:47:12 103424 —-a-w- C:\Windows\System32\UIAnimation.dll 2011-01-18 18:47:11 3815424 —-a-w- C:\Windows\System32\UIRibbon.dll 2011-01-18 18:47:11 3023360 —-a-w- C:\Windows\SysWow64\UIRibbon.dll 2011-01-18 18:47:11 1164800 —-a-w- C:\Windows\SysWow64\UIRibbonRes.dll 2011-01-18 18:47:11 1164800 —-a-w- C:\Windows\System32\UIRibbonRes.dll 2011-01-17 20:14:29 316928 —-a-w- C:\Windows\System32\msshsq.dll 2011-01-17 20:14:28 231424 —-a-w- C:\Windows\SysWow64\msshsq.dll 2011-01-17 19:39:26 ——– d—–r- C:\Program Files (x86)\Norton Support 2011-01-16 21:40:04 ——– d—–w- C:\Windows\SysWow64\vi-VN 2011-01-16 21:40:04 ——– d—–w- C:\Windows\SysWow64\eu-ES 2011-01-16 21:40:04 ——– d—–w- C:\Windows\SysWow64\ca-ES 2011-01-16 21:40:04 ——– d—–w- C:\Windows\System32\eu-ES 2011-01-16 21:40:04 ——– d—–w- C:\Windows\System32\ca-ES 2011-01-16 21:40:03 ——– d—–w- C:\Windows\System32\vi-VN 2011-01-16 19:20:10 ——– d—–w- C:\Users\Kalle\AppData\Local\Symantec 2011-01-16 19:00:44 ——– d—–w- C:\Windows\System32\EventProviders 2011-01-14 20:15:59 ——– d—–w- C:\PROGRA~3\NVIDIA Corporation 2011-01-14 20:15:40 ——– d—–w- C:\Program Files\NVIDIA Corporation 2011-01-14 20:05:10 ——– d—–w- C:\Program Files (x86)\Common Files\Microsoft Games 2011-01-12 19:09:35 ——– d—–w- C:\Windows\pss 2011-01-11 19:43:37 ——– d—–w- C:\Program Files\Games By GG releases 2010-12-31 21:18:20 ——– d—–w- C:\Program Files (x86)\Bethesda Softworks 2010-12-31 21:16:38 ——– d—–w- C:\Users\Kalle\AppData\Local\Oblivion 2010-12-30 19:56:47 834544 —-a-w- C:\Windows\System32\drivers\sptd.sys 2010-12-30 19:56:28 ——– d—–w- C:\Program Files (x86)\DAEMON Tools Lite 2010-12-30 19:55:57 ——– d—–w- C:\Users\Kalle\AppData\Roaming\DAEMON Tools Lite 2010-12-30 19:55:53 ——– d—–w- C:\PROGRA~3\DAEMON Tools Lite ==================== Find3M ==================== 2010-12-28 16:08:18 466944 —-a-w- C:\Windows\System32\odbc32.dll 2010-12-28 15:55:03 413696 —-a-w- C:\Windows\SysWow64\odbc32.dll 2010-12-20 17:08:40 24152 —-a-w- C:\Windows\System32\drivers\mbam.sys 2010-12-14 16:15:49 1251840 —-a-w- C:\Windows\System32\sdclt.exe 2010-12-03 20:33:57 75136 —-a-w- C:\Windows\SysWow64\PnkBstrA.exe 2010-12-03 20:33:50 270904 —-a-w- C:\Windows\SysWow64\PnkBstrB.xtr 2010-12-03 20:33:50 270904 —-a-w- C:\Windows\SysWow64\PnkBstrB.exe 2010-11-30 17:13:39 83120 —-a-w- C:\Windows\System32\drivers\avgntflt.sys 2010-11-06 11:18:48 500224 —-a-w- C:\Windows\System32\wmicmiplugin.dll 2010-11-06 11:18:27 655872 —-a-w- C:\Windows\System32\taskschd.dll 2010-11-06 11:18:27 410112 —-a-w- C:\Windows\System32\taskcomp.dll 2010-11-06 11:18:13 855040 —-a-w- C:\Windows\System32\schedsvc.dll 2010-11-04 23:58:17 267776 —-a-w- C:\Windows\System32\taskeng.exe 2010-11-04 18:55:38 352768 —-a-w- C:\Windows\SysWow64\taskschd.dll 2010-11-04 18:55:38 270336 —-a-w- C:\Windows\SysWow64\taskcomp.dll 2010-11-04 16:34:06 171520 —-a-w- C:\Windows\SysWow64\taskeng.exe 2010-10-28 16:29:18 48128 —-a-w- C:\Windows\System32\atmlib.dll 2010-10-28 15:44:56 34304 —-a-w- C:\Windows\SysWow64\atmlib.dll 2010-10-28 14:05:21 367104 —-a-w- C:\Windows\System32\atmfd.dll 2010-10-28 13:56:57 2048 —-a-w- C:\Windows\System32\tzres.dll 2010-10-28 13:27:47 292352 —-a-w- C:\Windows\SysWow64\atmfd.dll 2010-10-28 13:20:12 2048 —-a-w- C:\Windows\SysWow64\tzres.dll ============= FINISH: 19:42:27,84 ===============

Attachments:

P2P - I see you have P2P software ( µTorrent ) installed on your machine. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infections. It likely contributed to your current situation. This page will give you further information.
Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares.
Please see this topic for more information:
Perils of P2P File Sharing.
I would strongly recommend that you uninstall these now. You can do so via Control Panel >> Add or Remove Programs.

If you choose to leave them on the machine, please refrain from using them while we are cleaning the machine to prevent further infection.



It would appear that you have more than one anti-virus solution on your machine. I can see Norton Internet Security, Avast and Avira installed. Having more than one anti-virus program on your machine, even if only one is running, can cause conflicts and slowdowns in the performance of the machine, or freezing of the machine. Before continuing on, please completely uninstall two of the programs. The easiest way to do this is to visit one of these pages and use one of the removal tools listed below:

For Avira you can use the built in uninstaller.
Avast Uninstall Utility
Norton Removal Tool




Scan With RootKitUnHooker

  • Please Download Rootkit Unhooker and save it to your desktop.
  • Now double-click on RKUnhookerLE.exe to run it.
  • Click the Report tab, then click Scan.
  • Check (Tick) Drivers and Stealth
  • Uncheck the rest. then click OK
  • When prompted to Select Disks for Scan, make sure C:\ is checked and click OK
  • Wait till the scanner has finished and then click File > Save Report.
  • Save the report somewhere where you can find it. Click Close.
  • Copy the entire contents of the report and paste it in your next reply.

Note** you may get the following warning, just click OK and continue.

"Rootkit Unhooker has detected a parasite inside itself!
It is recommended to remove parasite, okay?"




If you could then run DDS again and post just the DDS.txt log this time (I don't need the Attach file this time.)


Can you please also let me know if there is any improvement in the freezing after removing 2 of the antivirus programs?
Yeah, I know about the Utorrent… Dont download much though never upload aswell. But yeah thats were the most viruses come from. I had an old compy of norton (like 30 days of trial) and the other AVP I downloaded when the computer was wierd to see if it could remove the virus. What AV do you recomend using? ( cant have notron) I will do the scan tomorrow, got work to do now. Thanks again for the help :-) // Karl
Choosing an antivirus program is something of personal preference. Certainly, both Avira or Avast are both good free options, you just want to make sure you only have one of them installed. After we've finished making sure your machine appears free from infections, I can give you some other free antivirus alternatives if you are looking to switch to something else. For now just remove the Norton and one of the others so we only have one on the machine.

I'll watch for your scan results tomorrow.
Are you having any problems with the last set of instructions for RootkitUnhooker or DDS?

Reminder: Topics with no reply in 4 days are closed!

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI