2013-09-01, 04:57
Hello, and Thank You for the help.
A few things have been happening: During a recent windows update, as the computer was booting up and applying updates an error came up saying BitDefender encountered an error .....it said some more but it disappeared before I had the chance to read it all or copy it. I am not sure what to make of this because I do not have BitDefender.

Another problem (I think) is I have 2 partitions C and D and I have yet to use D, but it says there is 1GB being used, I have opened it and there is nothing there.

And the last thing is I keep seeing dllHost.exe COM surrogate showing up and disappearing about every 30 sec or so, every time it does I get the activity indicator on the cursor.
I reformatted the entire computer when I first saw this happen last week, but it is happening again.

Also when I tried to update awsmbr to run a scan for this it says avast engine download error 0.
Thanks Again.

aswMBR version Copyright(c) 2011 AVAST Software
Run date: 2013-08-31 18:12:12
18:12:12.666 OS Version: Windows x64 6.1.7600
18:12:12.666 Number of processors: 4 586 0x2A07
18:12:12.666 ComputerName: YUI-PC UserName: yui
18:12:13.992 Initialize success
18:12:47.710 AVAST engine download error: 0
18:13:01.485 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
18:13:01.500 Disk 0 Vendor: Hitachi_ JEDO Size: 610480MB BusType: 3
18:13:01.688 Disk 0 MBR read successfully
18:13:01.688 Disk 0 MBR scan
18:13:01.688 Disk 0 Windows 7 default MBR code
18:13:01.703 Disk 0 Partition 1 00 1C Hidd FAT32 LBA MSDOS5.0 25600 MB offset 2048
18:13:01.703 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 152620 MB offset 52430848
18:13:01.719 Disk 0 Partition - 00 0F Extended LBA 432258 MB offset 364996608
18:13:01.750 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 432257 MB offset 364998656
18:13:01.875 Disk 0 scanning C:\Windows\system32\drivers
18:13:06.243 Service scanning
18:13:24.152 Modules scanning
18:13:24.152 Disk 0 trace - called modules:
18:13:24.713 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys iaStor.sys hal.dll
18:13:24.713 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8007ebc060]
18:13:24.713 3 CLASSPNP.SYS[fffff8800120143f] -> nt!IofCallDriver -> [0xfffffa800638bd20]
18:13:24.729 5 ACPI.sys[fffff88000eef781] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa8006390050]
18:13:24.729 Scan finished successfully
18:13:38.004 Disk 0 MBR has been saved successfully to "C:\Users\yui\Desktop\MBR.dat"
18:13:38.004 The log file has been saved successfully to "C:\Users\yui\Desktop\aswMBR.txt"

Download Security Check by screen317 from here (http://screen317.spywareinfoforum.org/SecurityCheck.exe) or here (http://screen317.changelog.fr/SecurityCheck.exe).

Save it to your Desktop.
Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
A Notepad document should open automatically called checkup.txt; please post the contents of that document.


http://i.imgur.com/81mYIKe.jpg AdwCleaner

Double click on AdwCleaner.exe to run the tool again.

Click on the Scan button.
AdwCleaner will begin to scan your computer like it did before.
After the scan has finished...
This time, click on the Clean button.
Press OK when asked to close all programs and follow the onscreen prompts.
Press OK again to allow AdwCleaner to restart the computer and complete the removal process.
After rebooting, a logfile report (AdwCleaner[S0].txt) will open automatically.
Copy and paste the contents of that logfile in your next reply.
A copy of that logfile will also be saved in the C:\AdwCleaner folder.


http://imageshack.us/a/img841/7292/thisisujrt.gif Please download Junkware Removal Tool (http://thisisudax.org/downloads/JRT.exe) to your desktop.

Shut down your protection software now to avoid potential conflicts.
Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
The tool will open and start scanning your system.
Please be patient as this can take a while to complete depending on your system's specifications.
On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
Post the contents of JRT.txt into your next message.


Download RogueKiller (http://www.sur-la-toile.com/RogueKiller/) and save it to your desktop.
Quit all other programs
Start RogueKiller.exe
Wait until the Prescan has finished ...
Click on Scan
Wait for the end of the scan
A report will be created on your desktop.
Click on the Delete button
Next click on the ShortcutsFix
another report will be created on your desktop.

Please post: All RKreport.txt text files located on your desktop.

On your next reply please post :

All RKreport.txt

Let me know if you have any problems in performing with the steps above or any questions you may have.

Good Day!

2013-09-04, 06:59
Hi, Thanks for helping me.
I will follow all instructions, but I have a question about AdwCleaner, you did not provide a link, so should I just do a search for it? is there a recommended download I should use?

2013-09-04, 07:13
For RogueKiller should I use thr *64 ?

2013-09-04, 23:00
Results of screen317's Security Check version 0.99.73
Windows 7 Service Pack 1 x64 (UAC is enabled)
Internet Explorer 10
``````````````Antivirus/Firewall Check:``````````````
Windows Firewall Disabled!
ZoneAlarm Internet Security Suite Antivirus
Antivirus up to date!
`````````Anti-malware/Other Utilities Check:`````````
MVPS Hosts File
Spybot - Search & Destroy
Malwarebytes Anti-Malware version
Adobe Flash Player 11.8.800.94
Mozilla Firefox (23.0.1)
````````Process Check: objlist.exe by Laurent````````
Spybot Teatimer.exe is disabled!
CheckPoint ZoneAlarm vsmon.exe
CheckPoint ZoneAlarm ZAPrivacyService.exe
CheckPoint ZoneAlarm zatray.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C: 0%
````````````````````End of Log``````````````````````

# AdwCleaner v3.002 - Report created 04/09/2013 at 12:21:46
# Updated 01/09/2013 by Xplode
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : yui - YUI-PC
# Running from : C:\Users\yui\Desktop\AdwCleaner.exe
# Option : Clean

***** [ Services ] *****

***** [ Files / Folders ] *****

Folder Deleted : C:\Users\yui\AppData\Roaming\CheckPoint\ZoneAlarm LTD Toolbar
Folder Deleted : C:\Users\yui\AppData\Roaming\Mozilla\Firefox\Profiles\k90afalj.default\jetpack
File Deleted : C:\Users\yui\AppData\Roaming\Mozilla\Firefox\Profiles\k90afalj.default\searchplugins\zonealarm.xml
File Deleted : C:\Users\yui\AppData\Roaming\Mozilla\Firefox\Profiles\k90afalj.default\user.js

***** [ Shortcuts ] *****

***** [ Registry ] *****

Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\grusskartencenter.com
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\grusskartencenter.com
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@checkpoint.com/FFApi
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ZoneAlarm LTD Toolbar

***** [ Browsers ] *****

-\\ Internet Explorer v10.0.9200.16660

-\\ Mozilla Firefox v23.0.1 (en-US)

[ File : C:\Users\yui\AppData\Roaming\Mozilla\Firefox\Profiles\k90afalj.default\prefs.js ]


AdwCleaner[R0].txt - [1539 octets] - [04/09/2013 12:20:38]
AdwCleaner[S0].txt - [1476 octets] - [04/09/2013 12:21:46]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [1536 octets] ##########

Junkware Removal Tool (JRT) by Thisisu
Version: 5.5.7 (09.01.2013:1)
OS: Windows 7 Home Premium x64
Ran by yui on Wed 09/04/2013 at 12:35:59.65

~~~ Services

~~~ Registry Values

~~~ Registry Keys

~~~ Files

~~~ Folders

~~~ FireFox

Emptied folder: C:\Users\yui\AppData\Roaming\mozilla\firefox\profiles\k90afalj.default\minidumps [5 files]

~~~ Event Viewer Logs were cleared

Scan was completed on Wed 09/04/2013 at 12:40:53.08
End of JRT log

2013-09-05, 23:04
Hi jamper

Sorry for delay :(

Very good job

Please read through these instructions to familarize yourself with what to expect when this tool runs

Refer to the ComboFix User's Guide (http://www.bleepingcomputer.com/combofix/how-to-use-combofix)

Download ComboFix from one of these locations:

Link 1 (http://download.bleepingcomputer.com/sUBs/ComboFix.exe)
Link 2 (http://www.infospyware.net/antimalware/combofix/)

* IMPORTANT- Save ComboFix.exe to your Desktop


Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : How to Disable your Security Programs (http://forums.whatthetech.com/How_to_Disable_your_Security_Programs_t96260.html)


Double click on combofix.exe & follow the prompts.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply for further review.

On your next reply please post :

Combofix log

Let me know if you have any problems in performing with the steps above or any questions you may have.

Good Day!

2013-09-06, 03:19
2013-09-06, 15:36
Hi jamper

Please follow all previous instructions regarding security programs.

Open a new Notepad session
Click the Start button, click run
in the run box type notepad
click ok
In the notepad, Click "Format" and be certain that Word Wrap is not checked.

Copy and paste all the text in the code box below into the Notepad. Do Not copy the word CODE


In the notepad
Click File, Save as..., and set the Save in to your Desktop
In the filename box, type (including quotation marks) as the filename: "CFScript.txt"
Click save

Using your mouse left button, drag the new file CFscript.txt and drop it on the ComboFix.exe icon as shown below.

This will start ComboFix again.Close all browser/windows first.

**Note: Do not mouseclick combofix's window while it's running. That may cause it to stall**


When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.


Download TFC (http://oldtimer.geekstogo.com/TFC.exe) to your desktop

Close any open windows.
Double click the TFC icon to run the program
TFC will close all open programs itself in order to run,
Click the Start button to begin the process.
Allow TFC to run uninterrupted.
The program should not take long to finish it's job
Once its finished it should automatically reboot your machine,
if it doesn't, manually reboot to ensure a complete clean


Please open your MalwareBytes AntiMalware Program
Click the Update Tab and search for updates
If an update is found, it will download and install the latest version.
Once the program has loaded, select "Perform Quick Scan", then click Scan.
The scan may take some time to finish, so please be patient.
When the scan is complete, click OK, then Show Results to view the results.
Make sure that everything is checked, and click Remove Selected. <-- very important
When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.


ESET Online Scanner
I'd like us to scan your machine with ESET OnlineScan

Note: If you are using Windows Vista/7, open your browser by right-clicking on its icon and select 'Run as administrator' to perform this scan.

It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.

Hold down Control and click on the following link to open ESET OnlineScan in a new window.
ESET OnlineScan (http://www.eset.com/online-scanner-popup/)
Click the http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetOnline.png button.
For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
Click on http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetSmartInstall.png to download the ESET Smart Installer. Save it to your desktop.
Double click on the http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetSmartInstallDesktopIcon.png icon on your desktop.

Check http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetAcceptTerms.png
Click the http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetStart.png button.
Accept any security warnings from your browser.
Check http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetScanArchives.png
Make sure that the option "Remove found threats" is Unchecked
Push the Start button.
ESET will then download updates for itself, install itself, and begin
scanning your computer. Please be patient as this can take some time.
When the scan completes, push http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetListThreats.png
Push http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetExport.png, and save the file to your desktop using a unique name, such as MyEsetScan. Alternatively, look for report in C:\Program Files\ESET\ESET Online Scanner\log.txt. Include the contents of this report in your next reply.
Push the Back button.
Select Uninstall application on close check box and push http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetFinish.png

On your next reply please post :

MBAM log
ESET Report

Let me know if you have any problems in performing with the steps above or any questions you may have.

Good Day!

2013-09-07, 00:40
Thanks again for your help.

Malwarebytes Anti-Malware

Database version: v2013.09.06.09

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 10.0.9200.16660
yui :: YUI-PC [administrator]

9/6/2013 1:22:41 PM
mbam-log-2013-09-06 (13-22-41).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 217320
Time elapsed: 2 minute(s), 55 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)


ESET: no threats found, so no report.

2013-09-07, 16:42
Hi jamper

Please let me know how your machine is running and if there are any outstanding issues.

2013-09-07, 21:16
Hello and thanks for everything.
I am still seeing dllHost.exe COM surrogate, it keeps appearing then disappearing in task manager, and every time it does my mouse pointer blinks and gets the activity indicator, it happens about every 20 to 30 seconds.
I also have something showing up in my D partition, I have formatted, and wiped it clean, but something taking up 1GB keeps showing up, but I cant see what it is

2013-09-08, 10:36
Hi jamper :)

I can see a screen shot of your dllHost.exe :)

2013-09-08, 11:28
Thanks again, I took a couple of shots, it's driving me crazy seeing the activity indicator every few seconds, sometimes there will be 2 of the dllhost.exe at the same time.

2013-09-08, 19:18
Hi jamper :)

Try this:

ERUNT Registry
Backing Up Your Registry
Go HERE (http://www.larshederer.homepage.t-online.de/erunt/) and download ERUNT
(ERUNT (Emergency Recovery Utility NT) is a free program that allows you to keep a complete backup of your registry and restore it when needed.)
Install ERUNT by following the prompts
(use the default install settings but say no to the portion that asks you to add ERUNT to the start-up folder, if you like you can enable this option later)
(either by double clicking on the desktop icon or choosing to start the program at the end of the setup)
Choose a location for the backup
(the default location is C:\WINDOWS\ERDNT which is acceptable).
Make sure that at least the first two check boxes are ticked
Press OK
Press YES to create the folder.
For detailed instruction on how to back-up registry via ERUNT, please visit HERE (http://www.winxptutor.com/regback.htm)

Stop, Disable A Service
Go to Start, Run OR Start, Programs, Accessories, Command Prompt and type Services.msc and click OK.
Scroll down and find the service.


Click once on the service to highlight it.
Right-Click on the service. Click on Properties
Select the General tab.
Next to Service Status, click Stop.
Click the Arrow-down tab on the right-hand side of the Start-up Type box.
From the drop-down menu, click on Disabled
Click Apply , then OK

2013-09-08, 23:31
Hi Robybel,
Thanks, for the help, but I am a little confused, the very first thing that I did before posting in the forum was to download ERUNT, and the other thing is on your last reply you said to download erunt but the email I received to alert me to your reply gave me different instructions which included using Tweaking.com and no mention of erunt.
So I am not sure what to do. and wondering why the email says something different then your last post.

2013-09-09, 01:43
I followed the instructions to disable the service, but the dll does not show up in the Services.msc even tho it is in the task manager

2013-09-09, 06:00
Ok go in task manager and right click on dllhost process. Click stop process :-)

2013-09-09, 07:33
I have tried that, it will not let me, it says the handle is invalid.

2013-09-11, 05:14
Hi, Thanks for you help, but I am just going to do a clean install.

2013-09-11, 22:22
Ok jamper:bigthumb:

Feel free to ask if you have any doubts about proper installation clean

2013-09-13, 06:47
