This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Trojan.Downloader.Ruins

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, and thank you in advance for whoever helps me.

Well i was on the internet today and i noticed google started acting funny. whenever i would click on a search result in good 9 of 10 times i would get redirected to another site. so i started running spyware doctor to see if it could find anything and it found alot of diffrent files. What i have been doing up until this particular trojan was going into my registry and deleteing the keys manually specified by spyware doctor. This has worked for me for a long time now but this particular Virus shows up as Trojan.Downloader.Ruins. So i ran Avg and it showed some files which it cleared but not this one. Next thing i know, the connection on my laptop stops working period. it will display like its connected but cmd shows it as not connected and whenever i try and open a page it says "not able to connect" until i typed in a web adress into the bar and it says "adress invalid"
So now im on another computer in the house on here i downloaded HJT onto a flash drive and ran it on my computer here is the log


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:04:33 AM, on 9/19/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Spyware Doctor\pctsGui.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
O2 - BHO: (no name) - {6D657171-F7C9-4B52-8F10-07C1EF89D34E} - C:\WINDOWS\system32\pmkhg.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {837B45D6-BF85-457D-AABF-6D2E7815F791} - C:\WINDOWS\system32\nnnkhfc.dll (file missing)
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKLM\..\Run: [C:\WINDOWS\system32\kdzms.exe] C:\WINDOWS\system32\kdzms.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [mount.exe] C:\Documents and Settings\Nathaniel\Desktop\Virus Protection\GiPo\mount.exe /z
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {DB7BF79A-FC51-4B5A-92BC-A65731174380} (InstantAction Game Launcher) - http://www.instantaction.com/download/iaplayer.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{96C94EBE-EF75-4FCA-8B12-2D447A40352C}: NameServer = 85.255.114.83,85.255.112.113
O17 - HKLM\System\CS1\Services\Tcpip\..\{96C94EBE-EF75-4FCA-8B12-2D447A40352C}: NameServer = 85.255.114.83,85.255.112.113
O17 - HKLM\System\CS2\Services\Tcpip\..\{96C94EBE-EF75-4FCA-8B12-2D447A40352C}: NameServer = 85.255.114.83,85.255.112.113
O20 - Winlogon Notify: nnnkhfc - nnnkhfc.dll (file missing)
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\Shared\hpqwmi.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe

–
End of file - 5071 bytes
Also the files that spyware doctor says i need to delete wont delete. everytime i try and fix them with HJT it says it was removed but i scan again and its right back there. i dont know if this matters either but whenever HJT tries to remove it, when i go look in the backups folder even tho i told HJT to not make backups, theres usually about 5 or 6 of the same files i told it to delete there. one of those files being C:\WINDOWS\SYSTEM32\kdzms.exe P.s For some reason in spyware doctor it shows 2 different system32 folders. one is all uppercase while the other is all lowercase as it should. spyware doctor says that this exe files is in the all upercase system32 folder but i cant find an all upercase system32 folder and its not in the normal one.
Hello

Please visit this web page for instructions for downloading and running ComboFix

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

This includes installing the Windows XP Recovery Console in case you have not installed it yet.

For more information on the Windows XP Recovery Console read http://support.microsoft.com/kb/314058.

Once you install the Recovery Console, when you reboot your computer, you'll see the option for the Recovery Console now as well. Don't select Recovery Console as we don't need it. By default, your main OS is selected there. The screen stays for 2 seconds and then it proceeds to load Windows. That is normal.

Post the log from ComboFix when you've accomplished that, along with a new HijackThis log.


Also tell me how your PC is running
Alrighty first i just wanna say thank you very much for the quick reply :) and combo fix deleted the files i was trying to get rid of but for some reason i still cant connect to the internet. here are the logs you asked for, im going to upload them as attachments and post them just incase.

ComboFix 08-09-12.09 - Nathaniel 2008-09-19 15:08:05.1 - NTFSx86
Running from: F:\ComboFix.exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Autorun.inf
C:\Program Files\SecCenter
C:\WINDOWS\cookies.ini
C:\WINDOWS\system32\_000110_.tmp.dll
C:\WINDOWS\system32\akiljmoq.ini
C:\WINDOWS\system32\anbhygvr.ini
C:\WINDOWS\system32\avmenicc.ini
C:\WINDOWS\system32\fraskxgj.ini
C:\WINDOWS\system32\ggvgmvif.ini
C:\WINDOWS\system32\ghkmp.bak1
C:\WINDOWS\system32\ghkmp.bak2
C:\WINDOWS\system32\ghkmp.ini
C:\WINDOWS\system32\ghkmp.ini2
C:\WINDOWS\system32\ghkmp.tmp
C:\WINDOWS\system32\hifkwqyw.ini
C:\WINDOWS\system32\kdzms.exe
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\olqbqxhq.ini
C:\WINDOWS\system32\pfbcaloe.ini
C:\WINDOWS\system32\qheasbph.ini
C:\WINDOWS\system32\rjjehniv.ini
C:\WINDOWS\system32\rocvqvbf.ini
C:\WINDOWS\system32\uwlxkrxq.ini
C:\WINDOWS\system32\vvovkbip.ini
C:\WINDOWS\system32\wocrdcrc.ini
C:\WINDOWS\system32\wrtbexmb.ini
C:\WINDOWS\system32\xhesqrxg.ini
C:\WINDOWS\system32\ybylobnr.ini
D:\Autorun.inf

.
((((((((((((((((((((((((( Files Created from 2008-08-19 to 2008-09-19 )))))))))))))))))))))))))))))))
.

2008-09-19 02:06 . 2008-09-19 02:06 d——– C:\VundoFix Backups
2008-09-19 02:06 . 2008-09-19 02:06 d——– C:\!KillBox
2008-09-19 00:52 . 2006-04-20 01:28 d——– C:\Documents and Settings\Administrator\Application Data\Intuit
2008-09-19 00:52 . 2008-09-19 00:52 d——– C:\Documents and Settings\Administrator
2008-09-19 00:00 . 2008-09-19 00:00 d——– C:\Program Files\Trend Micro
2008-09-18 19:10 . 2005-07-14 09:37 1,269,760 –a—— C:\WINDOWS\system32\drivers\ati2mtag.sys
2008-09-18 19:10 . 2005-07-14 09:37 1,269,760 –a—— C:\WINDOWS\system32\dllcache\ati2mtag.sys
2008-09-18 18:09 . 2008-09-18 22:03 dr-hs—- C:\resycled
2008-09-07 16:37 . 2008-09-07 16:38 d——– C:\Program Files\SwiftKit
2008-09-07 16:37 . 2008-09-07 16:37 d——– C:\Documents and Settings\All Users\Application Data\SwiftKit
2008-08-31 14:21 . 2008-08-31 14:21 244 –ah—– C:\sqmnoopt13.sqm
2008-08-31 14:21 . 2008-08-31 14:21 232 –ah—– C:\sqmdata13.sqm
2008-08-31 14:17 . 2008-08-31 14:17 244 –ah—– C:\sqmnoopt12.sqm
2008-08-31 14:17 . 2008-08-31 14:17 232 –ah—– C:\sqmdata12.sqm
2008-08-31 14:16 . 2008-08-31 14:16 244 –ah—– C:\sqmnoopt11.sqm
2008-08-31 14:16 . 2008-08-31 14:16 244 –ah—– C:\sqmnoopt10.sqm
2008-08-31 14:16 . 2008-08-31 14:16 232 –ah—– C:\sqmdata11.sqm
2008-08-31 14:16 . 2008-08-31 14:16 232 –ah—– C:\sqmdata10.sqm
2008-08-31 14:15 . 2008-08-31 14:15 244 –ah—– C:\sqmnoopt09.sqm
2008-08-31 14:15 . 2008-08-31 14:15 232 –ah—– C:\sqmdata09.sqm
2008-08-23 05:21 . 2008-08-23 05:21 d——– C:\Documents and Settings\Nathaniel\Application Data\GarageGames
2008-08-19 02:06 . 2008-08-19 03:25 d——– C:\WINDOWS\system32\CatRoot_bak

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-19 05:17 ——— d—a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-09-19 00:02 ——— d—–w C:\Documents and Settings\Nathaniel\Application Data\AVG7
2008-09-18 23:14 ——— d—–w C:\Program Files\Folder Lock
2008-09-18 23:11 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-09-17 22:00 ——— d—–w C:\Program Files\Norton Security Scan
2008-09-09 12:48 24 —-a-w C:\Documents and Settings\Nathaniel\jagex_runescape_preferences.dat
2008-08-30 06:50 ——— d—–w C:\Program Files\Spyware Doctor
2008-08-01 06:05 ——— d—–w C:\Program Files\Image-Line
2008-08-01 06:04 ——— d—–w C:\Program Files\VstPlugins
2008-08-01 06:02 ——— d—–w C:\Program Files\Outsim
2005-10-31 15:56 700,416 —-a-w C:\Program Files\StubInstaller.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 15360]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2007-01-19 5674352]
"mount.exe"="C:\Documents and Settings\Nathaniel\Desktop\Virus Protection\GiPo\mount.exe" [2008-03-22 374272]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-10-28 219136]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"midi1"= usbkt1x1.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Google Updater.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Google Updater.lnk
backup=C:\WINDOWS\pss\Google Updater.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Photosmart Premier Fast Start.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Photosmart Premier Fast Start.lnk
backup=C:\WINDOWS\pss\HP Photosmart Premier Fast Start.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG7_CC]
–a—— 2008-09-18 18:32 579584 C:\PROGRA~1\Grisoft\AVG7\avgcc.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
–a—— 2004-08-04 04:00 15360 C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISTray]
–a—— 2008-06-12 10:10 1107848 C:\Program Files\Spyware Doctor\pctsTray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
–a—— 2004-12-18 04:20 278528 C:\Program Files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
–a—— 2007-01-19 12:54 5674352 C:\Program Files\MSN Messenger\msnmsgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NoAdware5]
–a—— 2007-01-12 11:17 1695744 C:\Program Files\NoAdware5.0\NoAdware5.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
–a—— 2008-06-10 04:27 144784 C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Veoh]
–a—— 2008-01-30 14:11 3497984 C:\Program Files\Veoh Networks\Veoh\VeohClient.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
–a—— 2006-11-03 19:20 866584 C:\Program Files\Windows Defender\MSASCui.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\Microsoft Games\\Age of Empires II\\EMPIRES2.ICD"=
"C:\\WINDOWS\\system32\\sessmgr.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\Microsoft Games\\Age of Empires II\\age2_x1\\age2_x1.icd"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=

R3 CLEDX;Team H2O CLEDX service;C:\WINDOWS\system32\DRIVERS\cledx.sys [2005-05-09 33792]
R3 HSFHWATI;HSFHWATI;C:\WINDOWS\system32\DRIVERS\HSFHWATI.sys [2004-12-15 200192]
S3 UKS11LDR;M-Audio USB Keystation Loader;C:\WINDOWS\system32\drivers\uks11ldr.sys [ ]
S3 USBKT1X1;M-Audio USB Keystation;C:\WINDOWS\system32\drivers\usbkt1x1.sys [ ]
.
Contents of the 'Scheduled Tasks' folder
.
- - - - ORPHANS REMOVED - - - -

BHO-{6D657171-F7C9-4B52-8F10-07C1EF89D34E} - C:\WINDOWS\system32\pmkhg.dll
HKLM-Run-C:\WINDOWS\system32\kdzms.exe - C:\WINDOWS\system32\kdzms.exe
Notify-nnnkhfc - nnnkhfc.dll
MSConfigStartUp-mount - C:\Documents and Settings\Nathaniel\Desktop\Virus Protection\mount.exe
MSConfigStartUp-SearchIndexer - C:\WINDOWS\system32\wyqwkfih.dll
MSConfigStartUp-swg - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe


.
——- Supplementary Scan ——-
.
FireFox -: Profile - C:\Documents and Settings\Nathaniel\Application Data\Mozilla\Firefox\Profiles\xsmetygm.default\
.

**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-19 15:33:26
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files:

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\ati2evxx.exe
.
**************************************************************************
.
Completion time: 2008-09-19 15:36:18 - machine was rebooted
ComboFix-quarantined-files.txt 2008-09-19 19:36:11

Pre-Run: 5,730,611,200 bytes free
Post-Run: 6,022,574,080 bytes free

168 — E O F — 2008-09-18 19:38:22
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:38:56 PM, on 9/19/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [mount.exe] C:\Documents and Settings\Nathaniel\Desktop\Virus Protection\GiPo\mount.exe /z
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O15 - ESC Trusted Zone: http://*.update.microsoft.com
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\Shared\hpqwmi.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe

–
End of file - 3264 bytes
Try this for your net problem

Please go to Start -> Control Panel, and choose Network Connections. Then right click on your default connection, usually Local Area Connection or Dial-up Connection if you are using Dial-up, and left click on properties. Double-click on the Internet Protocol (TCP/IP) item and select the radio button that says Obtain DNS servers automatically. Click OK twice, and restart your computer.



That fix it ?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI