This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

LOTS of svc.host processes - using alot of RAM. Please help!

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Greetings :D

A few months ago I replaced my Windows XP with Windows 7 and it has been running fine with no hiccups (other than a few quarantined viruses and various hardware issues". However, I recently realised my computers performance was not what it once was, so I took a look at my task manager and counted 13 svchost.exe processes with 4 using 20-40k ram and 1 using 100k and occasionally clocks up to 150-160k; resulting in my CPU usage frequently spiking to 50% for a brief moment, then back down to the normal 5-15%. After surfing the web I read a number of forums informing me that this is not normal and could be the result of viruses running loose. In an attempt to fix this problem, I ran two full system scans with two different programs, Trend Micro Internet Security and Malwarebytes. Both presented clean results. So then I disengaged from that area to check and see if my disk was fragmented. The results showed 0% fragmentation.

I would very much appreciate any sort of assistance. I am concerned my internet protection software is not picking up viruses and it is affecting my computer and ultimately, my gaming! :pullhair:

Here is my Hijackthis log:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 7:54:17 PM, on 5/2/2011
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v8.00 (8.00.7601.17514)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe
C:\Windows\SysWOW64\NOTEPAD.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = Preserve
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Trend Micro Toolbar BHO - {43C6D902-A1C5-45c9-91F6-FD9E90337E18} - C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\TSToolbar.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.6.6209.1142\swg.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Trend Micro Toolbar - {CCAC5586-44D7-4c43-B64A-F042461A97D2} - C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\TSToolbar.dll
O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownlo…sreqlab_nvd.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: tmtb - {04EAF3FB-4BAC-4B5A-A37D-A1CF210A5A42} - C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\TSToolbar.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Dragon Age: Origins - Content Updater (DAUpdaterSvc) - BioWare - C:\Isaac's Fun Stuff\The Games\Dragon Age Origins\bin_ship\DAUpdaterSvc.Service.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\Windows\system32\PnkBstrB.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Trend Micro Central Control Component (SfCtlCom) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: Trend Micro Unauthorized Change Prevention Service (TMBMServer) - Trend Micro Inc. - C:\Program Files\Trend Micro\BM\TMBMSRV.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (TmProxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

–
End of file - 8801 bytes
Hello and Posted Image

My name is patndoris. I will be glad to take a look at your log and help you with solving any malware problems. It will be very helpful if you follow these guidelines:
  • Malware logs are often lengthy and can take a lot of time to research and interpret. Please be patient while I review your logs.
  • Please note that there is no "Quick Fix" to modern malware infections and we may need to use several different approaches to get your system clean.
  • Please make sure to carefully read any instruction that I give you. If you're not sure, or if something unexpected happens, do NOT continue! Stop and ask!
  • Please follow my instructions carefully and in the order they are posted. You may also find it helpful to print out the instructions you receive.
  • Please do not run any scans or install/uninstall any applications or delete anything without being directed to do so.
  • Remember, absence of symptoms does not mean the infection is all gone. Please stick with me till you're given the "all clear".
  • Please do not use the Attachment feature for any log file. Do a Copy/Paste of the entire contents of the log file and submit it inside your post.
  • Please reply within 3 days. If I do not hear back from you in that time frame, I will post a reminder for you. Topics with no reply in 4 days are closed!





Run Hijack This
*Double click on the icon on your desktop to launch Hijack This
*Click on the Scan button
*When the scan has finished, please put a check in the box next to the following item:

O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll


*Make sure all other windows, including your browser are closed, and then click on the Fix Checked button





HijackThis has largely been replaced by other tools. Since being acquired by TrendMicro, HijackThis has not been regularly updated. Many infections are now able to hide partly, or completely from a HijackThis scan. DDS includes all the scan locations of HijackThis and more.




Download and Run DDS by sUBs

Please download DDS and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.scr to run the tool.
  • When done, DDS.txt will open.
  • Save both reports to your desktop.
—————————————————

Please Please copy / paste the scan reults.

DDS.txt

Please attach the second file; Attach.txt. To attach a file, do the following:
  • Under the reply panel is the Attachments Panel
  • Browse for the attachment file you want to upload, then click the green Upload button
  • Once it has uploaded, click the Manage Current Attachments drop down box
  • Click on [external image: Posted Image] to insert the attachment into your post





If you have CDEmulation drivers installed (such as Daemon Tools, Alcohol120) please follow the instructions below to run DeFogger prior to and after running GMER. If you do not have any CDEmulation drivers installed, you do not need to run DeFogger and you can go right to the instructions to run GMER.

Download DeFogger

Please download DeFogger to your desktop.

Double click DeFogger to run the tool.
  • The application window will appear
  • Click the Disable button to disable your CD Emulation drivers
  • Click Yes to continue
  • A 'Finished!' message will appear
  • Click OK
  • DeFogger will now ask to reboot the machine - click OK
IMPORTANT! If you receive an error message while running DeFogger, please post the log defogger_disable which will appear on your desktop.

Do not re-enable these drivers until otherwise instructed.

Download and Run GMER

[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
Hey patndoris :)

Thank you so much for the quick reply, I really appreciate it.

I followed the instructions you listed and I have the logs from DDS, yipee!

However, I could not get GMER to work properly, all the boxes except services, registry and files are GRAYED OUT. After some research i discovered that GMER does not work with windows 7 64bit. If you could provide a link for another program that detects rootkits that would be fantastic.

For now, I give you the logs from DDS:

Attach.txt: 📎Attach.txt

DDS.txt:

.
DDS (Ver_11-03-05.01) - NTFS_AMD64
Run by [removed] at 13:27:36.51 on Wed 05/04/2011
Internet Explorer: 8.0.7601.17514
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.3071.1830 [GMT 10:00]
.
AV: Trend Micro Internet Security Pro *Disabled/Updated* {68F968AC-2AA0-091D-848C-803E83E35902}
SP: Trend Micro Internet Security Pro *Disabled/Updated* {D3988948-0C9A-0693-BE3C-BB4CF86413BF}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: Trend Micro Personal Firewall *Disabled* {70A91CD9-303D-A217-A80E-6DEE136EDB2B}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\SysWOW64\PnkBstrA.exe
C:\Windows\SysWOW64\PnkBstrB.exe
C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Windows\system32\taskhost.exe
C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files\Trend Micro\Internet Security\TmPfw.exe
C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\ProToolbarUpdate.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\DllHost.exe
C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\system32\SearchProtocolHost.exe
C:\Program Files\Trend Micro\TrendSecure\TSCFPlatformCOMSvr.exe
C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\PlatformDependent\ProToolbarComm.exe
C:\Windows\system32\WUDFHost.exe
C:\Windows\explorer.exe
C:\Windows\explorer.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Windows\system32\taskeng.exe
C:\Users\isaac\Desktop\dds.scr
C:\Windows\system32\conhost.exe
.
============== Pseudo HJT Report ===============
.
uSearch Bar = Preserve
uInternet Settings,ProxyOverride = *.local
mWinlogon: Userinit=userinit.exe
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: TSToolbarBHO: {43c6d902-a1c5-45c9-91f6-fd9e90337e18} - C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\TSToolbar.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.6.6209.1142\swg.dll
BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
TB: Trend Micro Toolbar: {ccac5586-44d7-4c43-b64a-f042461a97d2} - C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\TSToolbar.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
TB: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
TB: DAEMON Tools Toolbar: {32099aac-c132-4136-9e9a-4e364a424e17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} - hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab
DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - hxxp://download.divx.com/player/DivXBrowserPlugin.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL
Handler: tmtb - {04EAF3FB-4BAC-4B5A-A37D-A1CF210A5A42} - C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\TSToolbar.dll
BHO-X64: Windows Live Family Safety Browser Helper Class: {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll
BHO-X64: Windows Live Family Safety Browser Helper - No File
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll
BHO-X64: Google Toolbar Notifier BHO: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.6209.1142\swg64.dll
BHO-X64: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL
BHO-X64: URLRedirectionBHO - No File
TB-X64: DAEMON Tools Toolbar: {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll
TB-X64: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll
TB-X64: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
mRun-x64: [UfSeAgnt.exe] "C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe"
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\isaac\AppData\Roaming\Mozilla\Firefox\Profiles\oakcpg8d.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com.au/
FF - prefs.js: network.proxy.type - 0
FF - component: C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\FirefoxExtension\components\FFTMUFEHelper.dll
FF - component: C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\FirefoxExtension\components\FFToolbarComm.dll
FF - plugin: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL
FF - plugin: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
FF - plugin: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.53\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - C:\Program Files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Trend Micro Toolbar: {22181a4d-af90-4ca3-a569-faed9118d6bc} - C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\FirefoxExtension
.
============= SERVICES / DRIVERS ===============
.
R1 tmlwf;Trend Micro NDIS 6.0 Filter Driver;C:\Windows\System32\drivers\tmlwf.sys [2010-9-12 200720]
R2 nvUpdatusService;NVIDIA Update Service Daemon;C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-5-3 2218600]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-4-7 378472]
R2 tmpreflt;tmpreflt;C:\Windows\System32\drivers\tmpreflt.sys [2010-9-28 42576]
R2 tmwfp;Trend Micro WFP Callout Driver;C:\Windows\System32\drivers\tmwfp.sys [2010-9-12 339984]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver;C:\Windows\System32\drivers\nvhda64v.sys [2011-5-3 174184]
S?3 TmPfw;Trend Micro Personal Firewall;C:\Program Files\Trend Micro\Internet Security\TmPfw.exe [2010-9-12 595960]
S2 {09BB444F-B2E2-4009-BAF2-7B727681223E};BuddyVM;C:\Program Files (x86)\VMLaunch\BuddyVM.sys [2004-12-3 15872]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S3 DAUpdaterSvc;Dragon Age: Origins - Content Updater;C:\Isaac's Fun Stuff\The Games\Dragon Age Origins\bin_ship\daupdatersvc.service.exe [2009-12-16 25832]
S3 fssfltr;fssfltr;C:\Windows\System32\drivers\fssfltr.sys [2011-1-29 48488]
S3 fsssvc;Windows Live Family Safety Service;C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2010-4-28 704872]
S3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-1-9 4925184]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\System32\drivers\rdpvideominiport.sys [2011-3-15 20992]
S3 TmProxy;Trend Micro Proxy Service;C:\Program Files\Trend Micro\Internet Security\TmProxy.exe [2010-9-12 917768]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2011-3-15 59392]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\drivers\usbaapl64.sys [2010-9-28 51712]
S3 VMHybrid64;VMHybrid service;C:\Windows\System32\drivers\VMHybr64.sys [2010-5-19 1409664]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2010-9-13 1255736]
S4 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-9-11 136176]
S4 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-9-11 136176]
.
=============== Created Last 30 ================
.
2011-05-03 16:58:10 8802128 —-a-w- C:\PROGRA~3\Microsoft\Windows Defender\Definition Updates\{34490A6F-A60A-49D5-B7F2-383197C8BBF6}\mpengine.dll
2011-05-03 01:50:33 ——– d—–w- C:\NVIDIA
2011-05-03 01:32:44 ——– d—–w- C:\Windows\pss
2011-05-03 01:31:44 ——– d—–w- C:\PROGRA~3\NVIDIA Corporation
2011-05-03 01:15:03 ——– d—–w- C:\Program Files (x86)\Phyxion.net
2011-05-03 00:22:33 29288 —-a-w- C:\Windows\System32\nvhdap64.dll
2011-05-03 00:22:33 174184 —-a-w- C:\Windows\System32\drivers\nvhda64v.sys
2011-05-03 00:22:33 1359976 —-a-w- C:\Windows\System32\nvhdagenco642040.dll
2011-05-02 11:30:09 ——– d—–w- C:\Program Files (x86)\LOLReplay
2011-05-02 09:37:42 388096 —-a-r- C:\Users\isaac\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-05-02 09:37:42 ——– d—–w- C:\Program Files (x86)\Trend Micro
2011-05-02 09:10:43 ——– d—–w- C:\Program Files (x86)\Process Explorer
2011-04-29 05:46:52 ——– d—–w- C:\Windows\System32\SPReview
2011-04-24 09:50:11 ——– d—–w- C:\PROGRA~3\BioWare
2011-04-23 04:03:00 43520 —-a-w- C:\Windows\SysWow64\CmdLineExt03.dll
2011-04-22 06:32:10 98304 —-a-w- C:\Windows\SysWow64\CmdLineExt.dll
2011-04-22 03:46:32 15360 —-a-r- C:\Users\isaac\AppData\Roaming\Microsoft\Installer\{DD8408E9-9421-484F-979D-DB6361E3E828}\IconDD8408E910.exe
2011-04-22 03:46:32 11264 —-a-r- C:\Users\isaac\AppData\Roaming\Microsoft\Installer\{DD8408E9-9421-484F-979D-DB6361E3E828}\IconDD8408E96.exe
2011-04-22 01:52:42 ——– d—–w- C:\Windows\1C4551A64743409391E41477CD655043.TMP
2011-04-22 01:30:22 ——– d—–w- C:\Program Files (x86)\Common Files\BioWare
2011-04-18 08:43:07 ——– d—–w- C:\Users\isaac\AppData\Roaming\My Battle for Middle-earth Files
2011-04-13 05:06:49 476160 —-a-w- C:\Windows\System32\XpsGdiConverter.dll
2011-04-13 05:06:49 288256 —-a-w- C:\Windows\SysWow64\XpsGdiConverter.dll
2011-04-13 05:06:39 613376 —-a-w- C:\Windows\System32\vbscript.dll
2011-04-13 05:06:39 428032 —-a-w- C:\Windows\SysWow64\vbscript.dll
2011-04-13 05:01:22 3135488 —-a-w- C:\Windows\System32\win32k.sys
2011-04-13 05:00:36 1395712 —-a-w- C:\Windows\System32\mfc42.dll
2011-04-13 05:00:36 1359872 —-a-w- C:\Windows\System32\mfc42u.dll
2011-04-13 05:00:36 1164288 —-a-w- C:\Windows\SysWow64\mfc42u.dll
2011-04-13 05:00:36 1137664 —-a-w- C:\Windows\SysWow64\mfc42.dll
2011-04-13 04:58:36 467456 —-a-w- C:\Windows\System32\drivers\srv.sys
2011-04-13 04:58:36 411648 —-a-w- C:\Windows\System32\drivers\srv2.sys
2011-04-13 04:58:36 167936 —-a-w- C:\Windows\System32\drivers\srvnet.sys
2011-04-13 04:58:15 367616 —-a-w- C:\Windows\System32\atmfd.dll
2011-04-13 04:58:15 294912 —-a-w- C:\Windows\SysWow64\atmfd.dll
2011-04-13 04:58:14 46080 —-a-w- C:\Windows\System32\atmlib.dll
2011-04-13 04:58:14 34304 —-a-w- C:\Windows\SysWow64\atmlib.dll
2011-04-13 04:53:05 30208 —-a-w- C:\Windows\System32\dnscacheugc.exe
2011-04-13 04:53:05 28672 —-a-w- C:\Windows\SysWow64\dnscacheugc.exe
2011-04-13 04:53:05 183296 —-a-w- C:\Windows\System32\dnsrslvr.dll
2011-04-13 04:52:58 976896 —-a-w- C:\Windows\System32\inetcomm.dll
2011-04-13 04:52:58 741376 —-a-w- C:\Windows\SysWow64\inetcomm.dll
2011-04-13 04:52:53 566208 —-a-w- C:\Windows\System32\winresume.efi
2011-04-13 04:52:52 642944 —-a-w- C:\Windows\System32\winload.efi
2011-04-13 04:52:52 605552 —-a-w- C:\Windows\System32\winload.exe
2011-04-13 04:52:52 518672 —-a-w- C:\Windows\System32\winresume.exe
2011-04-13 04:52:52 20352 —-a-w- C:\Windows\System32\kdusb.dll
2011-04-13 04:52:52 19328 —-a-w- C:\Windows\System32\kd1394.dll
2011-04-13 04:52:52 17792 —-a-w- C:\Windows\System32\kdcom.dll
2011-04-13 04:49:14 267776 —-a-w- C:\Windows\System32\FXSCOVER.exe
2011-04-13 04:49:11 90624 —-a-w- C:\Windows\System32\drivers\bowser.sys
2011-04-13 04:49:11 287744 —-a-w- C:\Windows\System32\drivers\mrxsmb10.sys
2011-04-13 04:49:11 158208 —-a-w- C:\Windows\System32\drivers\mrxsmb.sys
2011-04-13 04:49:11 128000 —-a-w- C:\Windows\System32\drivers\mrxsmb20.sys
2011-04-13 04:44:40 ——– d—–w- C:\Program Files (x86)\EidosNet
2011-04-13 04:43:49 306688 —-a-w- C:\Windows\IsUninst.exe
2011-04-07 13:19:38 117864 —-a-w- C:\Windows\System32\nvmctray.dll
2011-04-07 13:19:36 797288 —-a-w- C:\Windows\System32\easyUpdatusAPIU64.dll
2011-04-07 13:19:36 61032 —-a-w- C:\Windows\System32\nvshext.dll
2011-04-07 13:19:36 1012328 —-a-w- C:\Windows\System32\nvvsvc.exe
2011-04-07 13:19:26 6338152 —-a-w- C:\Windows\System32\nvcpl.dll
2011-04-07 13:19:08 3041384 —-a-w- C:\Windows\System32\nvsvc64.dll
.
==================== Find3M ====================
.
2011-04-29 05:53:10 175616 —-a-w- C:\Windows\System32\msclmd.dll
2011-04-29 05:53:10 152576 —-a-w- C:\Windows\SysWow64\msclmd.dll
2011-03-14 02:13:59 258352 —-a-w- C:\Windows\SysWow64\unicows.dll
2011-03-12 12:08:49 1465344 —-a-w- C:\Windows\System32\XpsPrint.dll
2011-03-12 11:23:45 870912 —-a-w- C:\Windows\SysWow64\XpsPrint.dll
2011-03-11 06:41:37 189824 —-a-w- C:\Windows\System32\drivers\storport.sys
2011-03-11 06:41:34 166272 —-a-w- C:\Windows\System32\drivers\nvstor.sys
2011-03-11 06:41:34 1659776 —-a-w- C:\Windows\System32\drivers\ntfs.sys
2011-03-11 06:41:34 148352 —-a-w- C:\Windows\System32\drivers\nvraid.sys
2011-03-11 06:41:26 410496 —-a-w- C:\Windows\System32\drivers\iaStorV.sys
2011-03-11 06:41:12 27008 —-a-w- C:\Windows\System32\drivers\amdxata.sys
2011-03-11 06:41:12 107904 —-a-w- C:\Windows\System32\drivers\amdsata.sys
2011-03-11 06:33:29 2565632 —-a-w- C:\Windows\System32\esent.dll
2011-03-11 06:30:28 96768 —-a-w- C:\Windows\System32\fsutil.exe
2011-03-11 05:33:09 1699328 —-a-w- C:\Windows\SysWow64\esent.dll
2011-03-11 05:31:07 74240 —-a-w- C:\Windows\SysWow64\fsutil.exe
2011-03-07 06:31:44 1188864 —-a-w- C:\Windows\System32\wininet.dll
2011-03-07 05:33:13 981504 —-a-w- C:\Windows\SysWow64\wininet.dll
2011-03-07 04:24:34 1638912 —-a-w- C:\Windows\System32\mshtml.tlb
2011-03-07 03:52:25 1638912 —-a-w- C:\Windows\SysWow64\mshtml.tlb
2011-03-04 06:19:28 135168 —-a-w- C:\Windows\apppatch\AppPatch64\AcXtrnal.dll
2011-03-04 06:19:27 350208 —-a-w- C:\Windows\apppatch\AppPatch64\AcLayers.dll
2011-02-25 06:19:30 2871808 —-a-w- C:\Windows\explorer.exe
2011-02-25 05:30:54 2616320 —-a-w- C:\Windows\SysWow64\explorer.exe
2011-02-19 12:05:15 1139200 —-a-w- C:\Windows\System32\FntCache.dll
2011-02-19 12:04:37 1544192 —-a-w- C:\Windows\System32\DWrite.dll
2011-02-19 12:04:17 902656 —-a-w- C:\Windows\System32\d2d1.dll
2011-02-19 06:30:51 1076736 —-a-w- C:\Windows\SysWow64\DWrite.dll
2011-02-19 06:30:50 739840 —-a-w- C:\Windows\SysWow64\d2d1.dll
2011-02-18 10:51:16 31232 —-a-w- C:\Windows\System32\prevhost.exe
2011-02-18 05:39:44 31232 —-a-w- C:\Windows\SysWow64\prevhost.exe
.
============= FINISH: 13:28:16.74 ===============
I will review the logs. Don't worry about the rootkit scan, we don't need to run one on 64-bit. I apologize, I didn't realize you were running 64-bit Windows 7. You are correct, GMER won't run on it. I'll be back to you as soon as I've had a chance to review the logs completely.
I see you have Malwarebytes already on your machine. Please run it by double clicking the icon on the desktop.
  • Click on the tab labeled Update and then click on the button Check for updates.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.



http://www.eset.eu/online-scanner
Go here to run an online scannner from ESET.
Click the green ESET Online Scanner button.
Read the End User License Agreement and check the box: YES, I accept the Terms of Use.
Click on the Start button next to it.
You may receive an alert on the address bar that "This site might require the following ActiveX control…Click here to install…". Click on that alert and then click Insall ActiveX component.
A new window will appear asking "Do you want to install this software?"".
Answer Yes to download and install the ActiveX controls that allows the scan to run.
Click Start.
Unheck Remove found threats.
Click Scan to begin.
If offered the option to get information or buy software. Just close the window.
Wait for the scan to finish
Use notepad to open the logfile located at C:\Program Files\Eset\Eset Online Scanner\log.txt
Copy and paste that log as a reply to this topic.
Hey :)

I performed scans on both Malwarebytes and ESET scanner. My first scan of malware bytes did not pick up anything but that was because my internet protection software does not scan C drive > Users > (user's name) folder because it has a little lock icon on it and is always skipped. This folder contains folders such as downloads and favourites. I tried to scan the specific folder by right clicking it but there was no option to scan it, so I right clicked the folder > properties > sharing > advanced sharing > and enabled sharing so i was able to scan it. This time malwarebytes picked up a Trojan.agent which has most likely been on my computer for ages. Im not sure if it caused any damage or is just a false report by malwarebytes to get me to buy their software.

I then ran ESET scan and it picked up 2 infections and guess what, they were both in my (user's name) folder :(

Here are the logs for both scans:

Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Database version: 6504

Windows 6.1.7601 Service Pack 1
Internet Explorer 8.0.7601.17514

5/5/2011 1:16:50 AM
mbam-log-2011-05-05 (01-16-39).txt

Scan type: Quick scan
Objects scanned: 17183
Time elapsed: 9 minute(s), 13 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
c:\Users\isaac\AppData\Roaming\microsoft\installer\{dd8408e9-9421-484f-979d-db6361e3e828}\icondd8408e95.txt (Trojan.Agent) -> No action taken.

This trojan is quarantined by the way.



ESETSmartInstaller@High as CAB hook log:
OnlineScanner64.ocx - registred OK
OnlineScanner.ocx - registred OK
esets_scanner_update returned -1 esets_gle=53251
# version=7
# iexplore.exe=8.00.7600.16385 (win7_rtm.090713-1255)
# OnlineScanner.ocx=1.0.0.6427
# api_version=3.0.2
# EOSSerial=
# end=finished
# remove_checked=false
# archives_checked=false
# unwanted_checked=true
# unsafe_checked=true
# antistealth_checked=true
# utc_time=2011-05-04 04:52:36
# local_time=2011-05-05 02:52:36 (+1000, E. Australia Standard Time)
# country="United States"
# lang=9
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=516 16774526 100 97 28 39194337 0 0
# compatibility_mode=5893 16776574 100 94 0 56153123 0 0
# compatibility_mode=8192 67108863 100 0 2702 2702 0 0
# scanned=284206
# found=2
# cleaned=0
# scan_time=4683
C:\Users\isaac\AppData\Local\Temp\jar_cache1618635255713159995.tmp Java/Exploit.CVE-2010-0842.I trojan (unable to clean) 00000000000000000000000000000000 I
C:\Users\isaac\AppData\Local\Temp\jar_cache7302435470158170035.tmp Java/Exploit.CVE-2010-0842.I trojan (unable to clean) 00000000000000000000000000000000 I

I dont know what ESET did with these files, but it seems they were neither fixed nor quarantined.

Thanks again, and i promise I wont do anything to the files :P
It is fine to delete the trojan quarantined by Malwarebytes. You should be able to do this by running Malwarebytes, selecting the Quarantine tab and choosing the items to delete.

We can deal with the items ESET found by emptying some temp files and java caches. But I'd like to have you do a couple of updates before we do that.



[external image: Posted Image]
Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system.
Please follow these steps to remove older version Java components and update.
  • Download the latest version of Java Runtime Environment (JRE) 25 and save it to your desktop.
  • Scroll down to where it says JDK 6 Update 25 (JDK or JRE)
  • Click the Download JRE button to the right
  • Select the Windows platform from the dropdown menu.
  • Read the License Agreement and then check the box that says: "I agree to the Java SE Runtime Environment 6u24 with JavaFX 1 License Agreement". Click on Continue.The page will refresh.
  • Click on the link to download Windows Offline Installation and save the file to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel, double-click on Add or Remove Programs and remove all older versions of Java.
  • Check (highlight) any item with Java Runtime Environment (JRE or J2SE or Java™ 6) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u25-windows-i586-p.exe to install the newest version.
  • After the install is complete, go into the Control Panel (using Classic View) and double-click the Java Icon. (looks like a coffee cup)
    • On the General tab, under Temporary Internet Files, click the Settings button.
    • Next, click on the Delete Files button
    • There are two options in the window to clear the cache - Leave BOTH CheckedApplications and Applets
      Trace and Log Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Window
  • Click OK to leave the Java Control Panel.




Update Adobe Reader
There have been updates to Adobe Reader to address security vulnerabilities. You should download the latest version from the Adobe website.



Download ATF Cleaner by Atribune.
Note: Close all browsers before running ATF Cleaner: IE, FireFox, etc.

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

If you use Firefox browser

Click Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.

It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.



There are no logs to post - but I'd like to give you some final tips on staying malware free once you've finished these steps so please let me know when they are done.



Something I should bring to your attention is the amount of free space on your C: drive. There are two issues. First, Windows requires 15% of your disk space be free in order to function properly. You currently have less than that available. in addition, it does not appear your System Restore is turned on. In the event your system fails to boot, you will have nothing to fall back on and may not be able to recover your system.

If it were me, I would look at perhaps deleting some unecessary files/data or moving some to another drive or external drive to free up some space. I would also recommend then turning on System Restore so that you have a fall back point if anything goes wrong.

Certainly, it is your choice what you want to do, but it might possibly improve your system performance some.
I'm finished. When I ran ATF cleaner, I cleaned both "main" and "firefox", is this bad? For firefox, 58mb was cleaned and for main, 750mb was cleaned; i hope this was okay :P (I use firefox btw) I'm still not sure why I have so many svchost.exe running (12 now, down from 13) and i still got that one using 100k of memory. I know what svchost is, but i dont think i should have this many running and one using so much memory. Would you mind explaining this to me, if it isn't too much hassle? Thanks in advance. :)
Great job! Your logs appear to be malware free and you do not appear to be experiencing any malware related problems.


In a nutshell, svchost files are related to services running for your operating system. They are related to Windows and it is not unusual to see a dozen or more running at any given time as they are related to the dll services that are running on your machine. To trim the number down, you would want to investigate if there are any non-essential services you could stop on the machine. You can post in the Windows Forum and the techs there should be able to help you look at what's running and advise if anything can be safely stopped. Please let them know you have posted in the malware forum and appear to be malware free.


With ATF cleaner, the way you ran it is fine.


You can right-click and delete any of the tools we used and any remaining log files that may be on your desktop.



Please follow these simple steps in order to keep your computer malware free and secure:

Set a New Restore Point to prevent possible reinfection from an old one.
Some of the malware you picked up could have been saved in System Restore. Since System Restore is a protected directory, your tools can not access it to delete these bad files which sometimes can reinfect your system. Setting a new restore point AFTER cleaning your system will help prevent this and enable your computer to "roll-back" to a clean working state.

The easiest and safest way to do this is:
* Go to Start > Programs > Accessories > System Tools
* Click "System Restore"
* Choose the radio button marked "Create a Restore Point" on the first screen then click "Next"
* Give the Restore Point a name then click "Create". The new point will be stamped with the current date and time. Keep a log of this so you can find it easily should you need to use System Restore.
* Then go to Start > Run and type: Cleanmgr
* Click "OK"
* Click the "More Options" Tab.
* Click "Clean Up" in the System Restore section to remove all previous restore points except the newly created one.

Use and Update your AntiVirus Software
It is very important that your computer has an anti-virus software running on your machine. This alone can save you a lot of trouble with malware in the future. It is imperitive that you update your Antivirus software at least once a week (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.

Use a Firewall
Your log doesn't appear to show a third-party software firewall installed - if you have one, and I've missed it, please ignore this. I can not stress how important it is that you use a Firewall on your computer. Without a firewall your computer is succeptible to being hacked and taken over. I am very serious about this. Simply using a Firewall in its default configuration can lower your risk greatly.

Use only one antivirus and one firewall on your machine
Having more than one anti-virus program and one firewall on your machine, even if only one is running, can cause conflicts and slowdowns in the performance of the machine.

Keep your Java, Adobe Reader and Adobe Flash Up to Date
Older versions of these programs can contain security vulnerabilities. It is very important to keep them updated.

Update and Run Malwarebytes Anti-Malware
Scan your computer with this program on a regular basis just as you would an antivirus software making sure you update definitions each time you scan.

To simplify making sure you have the latest version of many of your security programs and applications, you may want to consider:
Secunia's Personal Software Inspector (PSI). It is a free utility that scans your computer for installed applications and checks to see if they have the latest security patches and updates. If it finds any applications with possible security issues, links and/or instructions are provided for the necessariy updates.

Filehippo's Update Checker. It is free utilitiy that scan your computer for installed software, checks the versions and then sends this information to see if there are any newer releases. Available software updates are displayed and you can decide which ones to download and install. Among many other types of programs, they includes a number of the Anti-Spyware, Firewall/Security and Anti-Virus programs that have been recommended (though not all of them). Note: Definition files should be updated from within the programs themselves. The Update Checker look for newer versions of the software program, not definition files.

Good luck & Happy surfing!

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI