
Quote: Originally Posted by
kamikazikyle
yeah thats the first thing i did was stop my downloading but my anti virus is avast 5 pro with that i use malwarebytes ccleaner and spybot s&d to scan when i know i have something and spybot has caught a couple things but its not the cause cus its still hapening also i have been using those programs [i never use hem at the same time ] for about 5 months now and no problems
Hi, kamikazikyle.
The normal location for rundll32.exe is System32, not AppData. If you have not done as already suggested by gregrocker, I would like to see a Malwarebytes' Anti-Malware log. First, however, please do the followng:
Download TFC by Old Timer from here (direct download):
http://www.itxassociates.com/OT-Tools/TFC.exe - First, save any files as TFC will close ALL open programs including your browser!
- Double-click on TFC.exe to run it. If you are using Vista/Windows 7 right-click on the file and choose Run As Administrator.
- Click the Start button to begin the cleaning process and let it run uninterrupted to completion.
- Important! If TFC prompts you to reboot, please do so immediately. If not prompted, manually reboot the machine anyway to ensure a complete clean.
Next, please scan with MBAM:
- Launch Malwarebytes' Anti-Malware then click the Update tab and "Check for Updates
- Once the update has been installed and the program has loaded, select [b]Quick scan
- When the scan is complete, click OK, then Show Results to view the results.
- Be sure that everything is checked, EXCEPT items in System Restore as shown in this sample:

- Click Remove Selected.
- When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See the Note below)
- The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
- Please post contents of that file in your next reply.
** Note **
If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click
OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately.