<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Re: [HJT Log] Slowdown + Can&#x27;t go on websites in Security Cleanup</title>
<link>http://www.dslreports.com/forum/r20329724</link>
<description></description>
<language>en</language>
<pubDate>Fri, 05 Dec 2008 03:15:26 EDT</pubDate>
<lastBuildDate>Fri, 05 Dec 2008 03:15:26 EDT</lastBuildDate>

<item>
<title>Re: [HJT Log] Slowdown + Can&#x27;t go on websites</title>
<link>http://www.dslreports.com/forum/remark,20349889</link>
<description><![CDATA[<A HREF="/useremail/u/693977"><b>bcastner</b></A> : Remember to let one (remember -- only one active AV software program installed) of your antivirus programs do a complete scan of your system.  You can let it run overnight.<br><br>I think we are done now.<br><br>Best wishes,<br>Bill Castner<br><small>--<br><b>============</b><br><b>MS-MVP 2004 - -2008, ASAP Member</b><br><b><i>Users Helping Users</i></b><br><br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20349889</guid>
<pubDate>Thu, 17 Apr 2008 18:56:34 EDT</pubDate>
</item>

<item>
<title>Re: [HJT Log] Slowdown + Can&#x27;t go on websites</title>
<link>http://www.dslreports.com/forum/remark,20349756</link>
<description><![CDATA[<A HREF="/useremail/u/637965"><b>halfHAVOC</b></A> : YES IT worked i got rundll32 from my other PC and it works fine now.<br><br>THANKS SOOOOOOOOOOOOOOO MUCH <br>YOURE THE MANN!]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20349756</guid>
<pubDate>Thu, 17 Apr 2008 18:32:43 EDT</pubDate>
</item>

<item>
<title>Re: [HJT Log] Slowdown + Can&#x27;t go on websites</title>
<link>http://www.dslreports.com/forum/remark,20347858</link>
<description><![CDATA[<A HREF="/useremail/u/693977"><b>bcastner</b></A> : If you ran "IEFix" and did the SFC /Scannow option included with the utility, then it would have properly replaced the Windows file "rundll32.exe".  As long as you have missing core Windows files, you are going to have issues.  Since you have another computer, if it is the same version of the operating system, same service pack level, copy this  file  and replace the missing file on your system in the appropriate directory shown in your error message.<br><br>If you have not done IEFix, please do so, making sure the option box for using SFC is checked.<br><br>Open HijackThis, checkmark these entries, and have HijackThis "fix" them.  All have been removed previously, and TeaTimer has been restoring them each time:<br><br><b>O2 - BHO: (no name) - {2589247d-e63b-4401-abd8-8f1a8f07a446} - (no file)<br>O2 - BHO: (no name) - {27BED0D7-0938-4700-9060-A436B69EB7BC} - (no file)<br>O2 - BHO: (no name) - {584E01C2-E9A9-4FB7-A78E-6BEDDE5C2C58} - (no file)<br>O2 - BHO: (no name) - {9C3831AF-F271-4DB6-BB2C-DCD46F9BF462} - (no file)<br>O2 - BHO: (no name) - {A67DA44A-58A5-4161-B77D-848247B6748C} - (no file)<br>O2 - BHO: (no name) - {A9457564-1FAB-4C4C-818D-417BA5F56D9C} - (no file)<br>O2 - BHO: (no name) - {DDBA5775-1351-4F21-881E-A4ADC9BEAB75} - (no file)<br>O2 - BHO: (no name) - {fed76bfd-a0ff-938f-507d-216c8ab86a74} - (no file)<br>O3 - Toolbar: (no name) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - (no file)<br>O4 - HKLM\..\Run: [dmxvp.exe] C:\WINDOWS\system32\dmxvp.exe<br>O4 - HKLM\..\Run: [dmotx.exe] C:\WINDOWS\system32\dmotx.exe<br>O4 - HKLM\..\Run: [d48e37be] rundll32.exe "C:\WINDOWS\system32\rggodyor.dll",b<br>O4 - HKCU\..\Run: [Rusc] "C:\DOCUME~1\ADMINI~1\MYDOCU~1\MANTEC~1\msiexec.exe" -vt yazb<br>O4 - HKCU\..\Run: [Gzchx] "C:\Program Files\Common Files\??mantec\??xplore.exe"<br>O20 - Winlogon Notify: efcccaa - C:\WINDOWS\<br>O20 - Winlogon Notify: iifefEUl - C:\WINDOWS\<br>O20 - Winlogon Notify: opnklmk - C:\WINDOWS\<br>O20 - Winlogon Notify: rqrstqn - C:\WINDOWS\<br>O20 - Winlogon Notify: ssqrrpo - C:\WINDOWS\<br>O21 - SSODL: MvpPwwv - {D48E3712-7E24-9DB8-DFA3-50C4B3DD1E5B} - (no file)<br></b><br><br>Finally, please re-enable at least one of your antivirus programs.  Open the program and then manually do an update to its definition files.  Configure for as through a scan as the software allows.  Then scan the system thoroughly.<br><small>--<br><b>============</b><br><b>MS-MVP 2004 - -2008, ASAP Member</b><br><b><i>Users Helping Users</i></b><br><br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20347858</guid>
<pubDate>Thu, 17 Apr 2008 07:25:11 EDT</pubDate>
</item>

<item>
<title>Re: [HJT Log] Slowdown + Can&#x27;t go on websites</title>
<link>http://www.dslreports.com/forum/remark,20346622</link>
<description><![CDATA[<A HREF="/useremail/u/637965"><b>halfHAVOC</b></A> : it says windows security alerts becuase it might just be that my virus programs (kaspersky and avast) are both disabled until i can fix this an uninstall one of them. but i think theres a thing where u can just choose "i have my own protection" or something of that nature, but i can't even open it up with that same dos crap. im gonna give the IEfix a try and smithfraud fix.<br><br>From 4/17/08<br>that doesn't show up in the scan<br><br>but after the mbam this is the error i get now when i try to right click properties or go to right click my computer prop, or add/remove programs provided in the screeshot.<br><br>heres a new hijackthis log:<br><br>Logfile of Trend Micro HijackThis v2.0.2<br>Scan saved at 6:53:45 AM, on 4/17/2008<br>Platform: Windows XP SP2 (WinNT 5.01.2600)<br>MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)<br>Boot mode: Normal<br><br>Running processes:<br>C:\WINDOWS\System32\smss.exe<br>C:\WINDOWS\system32\winlogon.exe<br>C:\WINDOWS\system32\services.exe<br>C:\WINDOWS\system32\lsass.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe<br>C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe<br>C:\Program Files\Alwil Software\Avast4\ashServ.exe<br>C:\WINDOWS\Explorer.EXE<br>C:\Program Files\iTunes\iTunesHelper.exe<br>C:\Program Files\Logitech\iTouch\iTouch.exe<br>C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe<br>C:\PROGRA~1\Comodo\CBOClean\BOC426.exe<br>C:\WINDOWS\system32\ctfmon.exe<br>C:\WINDOWS\system32\spoolsv.exe<br>C:\WINDOWS\System32\SCardSvr.exe<br>C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe<br>C:\Program Files\Comodo\CBOClean\BOCORE.exe<br>C:\WINDOWS\system32\nvsvc32.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\Program Files\iPod\bin\iPodService.exe<br>C:\Program Files\Mozilla Firefox\firefox.exe<br>C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe<br>C:\WINDOWS\system32\wuauclt.exe<br>C:\WINDOWS\system32\wscntfy.exe<br>C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br><br>R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 200.30.66.65:80<br>O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll<br>O2 - BHO: (no name) - {2589247d-e63b-4401-abd8-8f1a8f07a446} - (no file)<br>O2 - BHO: (no name) - {27BED0D7-0938-4700-9060-A436B69EB7BC} - (no file)<br>O2 - BHO: (no name) - {584E01C2-E9A9-4FB7-A78E-6BEDDE5C2C58} - (no file)<br>O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll<br>O2 - BHO: (no name) - {9C3831AF-F271-4DB6-BB2C-DCD46F9BF462} - (no file)<br>O2 - BHO: (no name) - {A67DA44A-58A5-4161-B77D-848247B6748C} - (no file)<br>O2 - BHO: (no name) - {A9457564-1FAB-4C4C-818D-417BA5F56D9C} - (no file)<br>O2 - BHO: (no name) - {DDBA5775-1351-4F21-881E-A4ADC9BEAB75} - (no file)<br>O2 - BHO: (no name) - {fed76bfd-a0ff-938f-507d-216c8ab86a74} - (no file)<br>O3 - Toolbar: (no name) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - (no file)<br>O4 - HKLM\..\Run: [Athan] C:\Program Files\Athan\Athan.exe<br>O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"<br>O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe<br>O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"<br>O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup<br>O4 - HKLM\..\Run: [nwiz] nwiz.exe /install<br>O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime<br>O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit<br>O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"<br>O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"<br>O4 - HKLM\..\Run: [dmxvp.exe] C:\WINDOWS\system32\dmxvp.exe<br>O4 - HKLM\..\Run: [dmotx.exe] C:\WINDOWS\system32\dmotx.exe<br>O4 - HKLM\..\Run: [d48e37be] rundll32.exe "C:\WINDOWS\system32\rggodyor.dll",b<br>O4 - HKLM\..\Run: [BOC-426] C:\PROGRA~1\Comodo\CBOClean\BOC426.exe<br>O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br>O4 - HKCU\..\Run: [Rusc] "C:\DOCUME~1\ADMINI~1\MYDOCU~1\MANTEC~1\msiexec.exe" -vt yazb<br>O4 - HKCU\..\Run: [Gzchx] "C:\Program Files\Common Files\??mantec\??xplore.exe"<br>O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000<br>O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll<br>O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll<br>O9 - Extra button: ATI TV - {44226DFF-747E-4edc-B30C-78752E50CD0C} - C:\Program Files\ATI Multimedia\tv\EXPLBAR.DLL (file missing)<br>O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe<br>O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br>O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br>O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - &raquo;<A HREF="http://go.divx.com/plugin/DivXBrowserPlugin.cab" >go.divx.com/plugin/DivXBrowserPlugin.cab</A><br>O20 - Winlogon Notify: efcccaa - C:\WINDOWS\<br>O20 - Winlogon Notify: iifefEUl - C:\WINDOWS\<br>O20 - Winlogon Notify: opnklmk - C:\WINDOWS\<br>O20 - Winlogon Notify: rqrstqn - C:\WINDOWS\<br>O20 - Winlogon Notify: ssqrrpo - C:\WINDOWS\<br>O21 - SSODL: MvpPwwv - {D48E3712-7E24-9DB8-DFA3-50C4B3DD1E5B} - (no file)<br>O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe<br>O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe<br>O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe<br>O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe (file missing)<br>O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe<br>O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe<br>O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe<br>O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe<br>O23 - Service: Kaspersky Anti-Virus 6.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe<br>O23 - Service: BOCore - COMODO - C:\Program Files\Comodo\CBOClean\BOCORE.exe<br>O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe<br>O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe<br>O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe<br><br>--<br>End of file - 6440 bytes]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20346622</guid>
<pubDate>Wed, 16 Apr 2008 22:32:41 EDT</pubDate>
</item>

<item>
<title>Re: [HJT Log] Slowdown + Can&#x27;t go on websites</title>
<link>http://www.dslreports.com/forum/remark,20346011</link>
<description><![CDATA[<A HREF="/useremail/u/693977"><b>bcastner</b></A> : Disable TeaTimer, it is not helping mattters.<br><br>1. Go here, download and run IEFix by MS-MVP Ramesh:<br>&raquo;<A HREF="http://www.mvps.org/sramesh2k/IEFIX.htm" >www.mvps.org/sramesh2k/IEFIX.htm</A><br><br>2. Follow the site instruction as to how to run SmitFraudFix:  &raquo;<A HREF="/faq/seclean">Security Cleanup FAQ</A> &raquo;<A HREF="/faq/13935">Zlob/Smitfraud Removal</A><br><br>3. Follow this with a run with <b>MBAM</b> again.<br><br>Are you sure the red shield is not from Windows Update?  You also do not show a toolbar entry in any of your logs that matches the CLSIDs being shown by Teatimer.  So whatever it is was not on your system previously.<br><br>4. Your error message is related to trying to install a protocol for IPX/SPX.  Why did you enable this under your TCPIP properties page?  Are you in a older Novell network?<br><br>5. Many of your complaints have no malware source -- and should be raised in Windows Help as a new Topic.<br><br><small>--<br><b>============</b><br><b>MS-MVP 2004 - -2008, ASAP Member</b><br><b><i>Users Helping Users</i></b><br><br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20346011</guid>
<pubDate>Wed, 16 Apr 2008 20:44:43 EDT</pubDate>
</item>

<item>
<title>Re: [HJT Log] Slowdown + Can&#x27;t go on websites</title>
<link>http://www.dslreports.com/forum/remark,20345646</link>
<description><![CDATA[<A HREF="/useremail/u/637965"><b>halfHAVOC</b></A> : igh but i still got that damn error with run dll that quick flash i can't go to add/remove programs and i can't access right clicking on my computer to properties.<br><br>oh by the way when i go to dl the new java it says i already have the latest version<br><br>im gonna try that malware and spyware program you just posted and see if that helps tho.<br><br>so as of right now i can't add/remove programs or set a system restore point. and i still have that little red shield bubble with the X through it in my tray bar.<br><br>igh heres the snapshot i took after a few tries of the split second dos pop up<br><br>ha look what happend when i used spybot resident/teatimer and turned it back on... btw this screen shot like theres multiple blocks and just keep flashing so i guess its constantly blocking stuff..<div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/20345646?c=1298233&ret=L2ZvcnVtL3IyMDMyOTcyNC54bWw%3D"><IMG class="apic" BORDER=0 TITLE="27434 bytes" WIDTH=600 HEIGHT=300 SRC="/r0/download/1298233.thumb600~e3c2b70e75b86971b768623934a8fe2d/Clipboard01.jpg/thumb.jpg" ALT="Click for full size"></A></TD></TR><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=2 WIDTH=66%><A HREF="/speak/slideshow/20345646?c=1298255&ret=L2ZvcnVtL3IyMDMyOTcyNC54bWw%3D"><IMG TITLE="103244 bytes" BORDER=0 WIDTH=280 HEIGHT=681 SRC="/r0/download/1298255~197e1cca286e46e59c64a30ec9d5ae35/res.jpg"></A></TD><TD ALIGN=CENTER BGCOLOR=#FFFFFF nowrap width=1%>&nbsp;</TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20345646</guid>
<pubDate>Wed, 16 Apr 2008 19:35:10 EDT</pubDate>
</item>

<item>
<title>Re: [HJT Log] Slowdown + Can&#x27;t go on websites</title>
<link>http://www.dslreports.com/forum/remark,20344667</link>
<description><![CDATA[<A HREF="/useremail/u/693977"><b>bcastner</b></A> : Your version of Sun Java is not the latest:  <b>1.6.06</b>  Head to the Sun web site and obtain the update.<br><br><b><u>Clean-up & Prevention:</u></b><br><br>&#8226;  Right click "My Computer", Properties, and then click the System Restore tab.  <b>Checkmark</b> the box at the top to stop System Restore on all drives.  Click the "<b>Apply</b>" button.  Agree to the deletion of old Restore Points.  Then <b><u>uncheck</u></b> the box at the top and again click the "<b>Apply</b>" button.  Finally, click the "<b>OK</b>" button.  This will create a new Restore Point reflecting your clean system state.<br><br>&#8226; Click <b>Start</b>, then click <b>Run</b>.<br>Enter into the command box that opens:  <b>combofix /u</b> and then click <b>OK</b>.<br>(If we have renamed this file, please use the current name for the program in this instruction.)<br> <IMG SRC="http://i78.photobucket.com/albums/j116/amateur_photos/CFuninstall.png"> <br><br>&#8226; Open <b>OTMOVEIT2</b> once again.  Click the <b>CleanuUp!</b> button.  It downloads a small script file. It then asks if you want to begin the cleanup.  Answer <b>Yes</b>.<br><br>&#8226; Run <b>ATF Cleaner</b>  <IMG SRC="http://www.geekstogo.com/misc/guide_icons/ATF.gif"> , and checkmark "Empty Recycle Bin", click "Empty Selected" and exit the program.  You can delete or keep this utility as you wish.<br><br>&#8226; Use Control Panel, Add or Remove Programs, and Uninstall any entry related to an On-Line scanner we may have used.  <br>If you find any files or folders created during this cleanup operation remaining, please feel free to delete them.<br><br>&#8226; Configure your Antivirus software to check for updates daily, at a time in which you are sure the computer will be on.<br><br>&#8226; If I asked you to <b>Disable</b> something like TeaTimer or another malware blocker, please go ahead an re-enable them if you wish.<br><br>&#8226;  <b>Download and Install Windows Defender by Microsoft (free):</b><br><textarea name="code" class="text" cols=50 rows=10>http://www.microsoft.com/downloads/details.aspx?FamilyId=435BFCE7-DA2B-4A6A-AFA4-F7F14E605A0D&#012;</textarea><!--end code block--><br>&#8226;  <b>Download and install Comodo BOClean (free):</b><br><textarea name="code" class="text" cols=50 rows=10>http://www.comodo.com/boclean/CBO_download.html&#012;</textarea><!--end code block--><br>&#8226;  <b>Download, install, and keep updated Spyware Blaster (free):</b><br><textarea name="code" class="text" cols=50 rows=10>http://www.javacoolsoftware.com/spywareblaster.html&#012;</textarea><!--end code block--><br>&#8226; <b>Download, install, and keep updated SpyBot S&D (free) if you have not yet done so:</b><br><b><i>Tutorial:</i></b>  <br><textarea name="code" class="text" cols=50 rows=10>http://www.bleepingcomputer.com/tutorials/tutorial43.html&#012;</textarea><!--end code block--><br>&#8226; Refer to my first set of instructions above, and reconfigure <b>Hidden Files and Folders</b> to your choosing.<br><br>Best wishes.<br>Bill Castner<br><br><small>--<br><b>============</b><br><b>MS-MVP 2004 - -2008, ASAP Member</b><br><b><i>Users Helping Users</i></b><br><br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20344667</guid>
<pubDate>Wed, 16 Apr 2008 16:35:08 EDT</pubDate>
</item>

<item>
<title>Re: [HJT Log] Slowdown + Can&#x27;t go on websites</title>
<link>http://www.dslreports.com/forum/remark,20343925</link>
<description><![CDATA[<A HREF="/useremail/u/637965"><b>halfHAVOC</b></A> : the "Purity" didn't work. it says file/folder cannot be found or it just does it like in 1 second literally and says process complete but all it says in results is log created ____(though i dont see where it could be located?)<br><br>so i guess i should jus run mbam again.<br><br>edit: YES MY INTERNET IS WORKING AGAIN ON MY COMPTUER WAHOOOOOOO AND ITS GOING FAST!!!<br><br>i still can't get the combofix to work tho with the script but i did mbam again.<br><br>heres the results:<br><br>Malwarebytes' Anti-Malware 1.11<br>Database version: 599<br><br>Scan type: Quick Scan<br>Objects scanned: 29092<br>Time elapsed: 4 minute(s), 17 second(s)<br><br>Memory Processes Infected: 0<br>Memory Modules Infected: 0<br>Registry Keys Infected: 1<br>Registry Values Infected: 0<br>Registry Data Items Infected: 0<br>Folders Infected: 0<br>Files Infected: 2<br><br>Memory Processes Infected:<br>(No malicious items detected)<br><br>Memory Modules Infected:<br>(No malicious items detected)<br><br>Registry Keys Infected:<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully.<br><br>Registry Values Infected:<br>(No malicious items detected)<br><br>Registry Data Items Infected:<br>(No malicious items detected)<br><br>Folders Infected:<br>(No malicious items detected)<br><br>Files Infected:<br>C:\WINDOWS\system32\nkqtkmpa.dll (Trojan.Vundo) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\apmktqkn.ini (Trojan.Vundo) -> Quarantined and deleted successfully.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20343925</guid>
<pubDate>Wed, 16 Apr 2008 14:24:39 EDT</pubDate>
</item>

<item>
<title>Re: [HJT Log] Slowdown + Can&#x27;t go on websites</title>
<link>http://www.dslreports.com/forum/remark,20341175</link>
<description><![CDATA[<A HREF="/useremail/u/693977"><b>bcastner</b></A> : Please do not stop at any point.<br>Just keep going and do as much of the steps as you can.<br><br>When you finish, please reinstall the drivers for your Motorola USB Modem if you still use this to connect to the internet.<br><br>Post the missing reports back to the Forum.<br><small>--<br><b>============</b><br><b>MS-MVP 2004 - -2008, ASAP Member</b><br><b><i>Users Helping Users</i></b><br><br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20341175</guid>
<pubDate>Tue, 15 Apr 2008 23:40:20 EDT</pubDate>
</item>

<item>
<title>Re: [HJT Log] Slowdown + Can&#x27;t go on websites</title>
<link>http://www.dslreports.com/forum/remark,20340817</link>
<description><![CDATA[<A HREF="/useremail/u/637965"><b>halfHAVOC</b></A> : man i got up to the registry fix part, but same old problem with combofix.<br><br>damn. i feel hopeless right now.<br><br>(btw i really appreciate you taking your time to help me and having patience  :) )<br><br>edit: lemme get the avenger log for you alright here it is, it may help i guess?<br><br>//////////////////////////////////////////<br>  Avenger Pre-Processor log<br>//////////////////////////////////////////<br><br>Platform: Windows XP (build 2600, Service Pack 2)<br>Tue Apr 15 22:17:17 2008<br><br>22:17:06: Error: Invalid registry syntax in command:<br>"HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|Rusc"<br>Only registry keys under the HKEY_LOCAL_MACHINE hive are accessible to this program.<br>Skipping line.  (Registry value deletion mode)  <br>22:17:08: Error: Invalid registry syntax in command:<br>"HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|Gzchx"<br>Only registry keys under the HKEY_LOCAL_MACHINE hive are accessible to this program.<br>Skipping line.  (Registry value deletion mode)  <br>22:17:10: Error: Invalid registry syntax in command:<br>"HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|dmotx.exe"<br>Only registry keys under the HKEY_LOCAL_MACHINE hive are accessible to this program.<br>Skipping line.  (Registry value deletion mode)  <br>22:17:12: Error: Invalid registry syntax in command:<br>"HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|{E3-37-71-11-DW}"<br>Only registry keys under the HKEY_LOCAL_MACHINE hive are accessible to this program.<br>Skipping line.  (Registry value deletion mode)  <br>22:17:13: Error: Invalid registry syntax in command:<br>"HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|spa_start"<br>Only registry keys under the HKEY_LOCAL_MACHINE hive are accessible to this program.<br>Skipping line.  (Registry value deletion mode)  <br>22:17:14: Error: Invalid registry syntax in command:<br>"HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|g]eeV\mWhjlnspB"=-"<br>Only registry keys under the HKEY_LOCAL_MACHINE hive are accessible to this program.<br>Skipping line.  (Registry value deletion mode)  <br><br>//////////////////////////////////////////<br><br>Logfile of The Avenger Version 2.0, (c) by Swandog46<br>&raquo;<A HREF="http://swandog46.geekstogo.com" >swandog46.geekstogo.com</A><br><br>Platform:  Windows XP<br><br>*******************<br><br>Script file opened successfully.<br>Script file read successfully.<br><br>Backups directory opened successfully at C:\Avenger<br><br>*******************<br><br>Beginning to process script file:<br><br>Rootkit scan active.<br>No rootkits found!<br><br>File "C:\WINDOWS\system32\kjjlm.tmp" deleted successfully.<br>File "C:\WINDOWS\system32\kjjlm.bak1" deleted successfully.<br>File "C:\WINDOWS\system32\kjjlm.bak2" deleted successfully.<br>File "C:\WINDOWS\system32\ogvfofdn.tmp" deleted successfully.<br>File "C:\WINDOWS\system32\geeba.dll" deleted successfully.<br><br>Error:  file "C:\WINDOWS\system32\{12fdb189-6534-5715-5717-a9c2868b4931}.dll" not found!<br>Deletion of file "C:\WINDOWS\system32\{12fdb189-6534-5715-5717-a9c2868b4931}.dll" failed!<br>Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)<br>  --> the object does not exist<br><br>Error:  file "C:\WINDOWS\system32\scntokdn.exe" not found!<br>Deletion of file "C:\WINDOWS\system32\scntokdn.exe" failed!<br>Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)<br>  --> the object does not exist<br><br>Error:  file "C:\WINDOWS\system32\{12fdb189-6534-5715-5717-a9c2868b4931}.dll" not found!<br>Deletion of file "C:\WINDOWS\system32\{12fdb189-6534-5715-5717-a9c2868b4931}.dll" failed!<br>Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)<br>  --> the object does not exist<br><br>Error:  file "c:\windows\system32\rwwnw64d.exe" not found!<br>Deletion of file "c:\windows\system32\rwwnw64d.exe" failed!<br>Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)<br>  --> the object does not exist<br><br>Error:  file "C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\Deewoo.lnk" not found!<br>Deletion of file "C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\Deewoo.lnk" failed!<br>Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)<br>  --> the object does not exist<br><br>Error:  file "C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\DW_Start.lnk" not found!<br>Deletion of file "C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\DW_Start.lnk" failed!<br>Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)<br>  --> the object does not exist<br><br>Error:  could not open file "C:\Program Files\?ymantec\j?vaw.exe"<br>Deletion of file "C:\Program Files\?ymantec\j?vaw.exe" failed!<br>Status: 0xc0000033 (STATUS_OBJECT_NAME_INVALID)<br>  --> an object cannot have this name<br><br>Error:  file "C:\WINDOWS\system32\qjjofwjh.dll" not found!<br>Deletion of file "C:\WINDOWS\system32\qjjofwjh.dll" failed!<br>Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)<br>  --> the object does not exist<br><br>Error:  file "C:\WINDOWS\pbvmnemA.exe" not found!<br>Deletion of file "C:\WINDOWS\pbvmnemA.exe" failed!<br>Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)<br>  --> the object does not exist<br><br>File "C:\WINDOWS\system32\vrcvjnpm.dll" deleted successfully.<br>File "C:\WINDOWS\system32\giupqxhj.dll" deleted successfully.<br>File "C:\WINDOWS\system32\jmtmlbgv.dll" deleted successfully.<br><br>Error:  file "C:\WINDOWS\system32\{12fdb189-6534-5715-5717-a9c2868b4931}.dll-uninst.exe" not found!<br>Deletion of file "C:\WINDOWS\system32\{12fdb189-6534-5715-5717-a9c2868b4931}.dll-uninst.exe" failed!<br>Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)<br>  --> the object does not exist<br><br>Error:  file "C:\Program Files\Common Files\Yazzle1281OinUninstaller.exe" not found!<br>Deletion of file "C:\Program Files\Common Files\Yazzle1281OinUninstaller.exe" failed!<br>Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)<br>  --> the object does not exist<br><br>File "C:\WINDOWS\system32\orxvmfos.dll" deleted successfully.<br>File "C:\WINDOWS\system32\ttcbnthi.dll" deleted successfully.<br>File "C:\WINDOWS\BMd7bd0422.xml" deleted successfully.<br>File "C:\WINDOWS\system32\wxoghvke.dll" deleted successfully.<br>File "C:\WINDOWS\system32\dvfskqyd.dll" deleted successfully.<br>File "C:\WINDOWS\system32\cmeujpiy.dll" deleted successfully.<br>File "C:\WINDOWS\system32\cbqoqefk.ini" deleted successfully.<br>File "C:\WINDOWS\system32\oqbmuvua.dll" deleted successfully.<br>File "C:\WINDOWS\system32\lafonvhy.dll" deleted successfully.<br><br>Error:  file "C:\WINDOWS\system32\{12fdb189-6534-5715-5717-a9c2868b4931}.dll" not found!<br>Deletion of file "C:\WINDOWS\system32\{12fdb189-6534-5715-5717-a9c2868b4931}.dll" failed!<br>Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)<br>  --> the object does not exist<br><br>File "C:\WINDOWS\system32\cpukaqck.ini" deleted successfully.<br>File "C:\WINDOWS\system32\hgwbxirw.ini" deleted successfully.<br>File "C:\WINDOWS\system32\vjvkpctk.ini" deleted successfully.<br>File "C:\WINDOWS\system32\hhuoiwga.ini" deleted successfully.<br>File "C:\WINDOWS\system32\uggjpiei.ini" deleted successfully.<br>File "C:\WINDOWS\system32\qcbvelel.ini" deleted successfully.<br>File "C:\WINDOWS\system32\egjaiwsd.ini" deleted successfully.<br><br>Error:  file "C:\WINDOWS\system32\geeba.dll" not found!<br>Deletion of file "C:\WINDOWS\system32\geeba.dll" failed!<br>Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)<br>  --> the object does not exist<br><br>File "C:\WINDOWS\system32\ZoneAlarmIconUS.ico" deleted successfully.<br>File "C:\WINDOWS\system32\hcvncvih.ini" deleted successfully.<br>File "C:\WINDOWS\system32\quiswxto.ini" deleted successfully.<br><br>Error:  file "C:\WINDOWS\uninstall_nmon.vbs" not found!<br>Deletion of file "C:\WINDOWS\uninstall_nmon.vbs" failed!<br>Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)<br>  --> the object does not exist<br><br>Error:  file "C:\Program Files\Common Files\Yazzle1281OinAdmin.exe" not found!<br>Deletion of file "C:\Program Files\Common Files\Yazzle1281OinAdmin.exe" failed!<br>Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)<br>  --> the object does not exist<br><br>File "C:\Documents and Settings\Administrator\mqdmmdm.sys" deleted successfully.<br>File "C:\Documents and Settings\Administrator\mqdmmdfl.sys" deleted successfully.<br>File "C:\Documents and Settings\Administrator\mqdmserd.sys" deleted successfully.<br>File "C:\Documents and Settings\Administrator\mqdmbus.sys" deleted successfully.<br>File "C:\Documents and Settings\Administrator\mqdmcmnt.sys" deleted successfully.<br>File "C:\Documents and Settings\Administrator\mqdmwhnt.sys" deleted successfully.<br>File "C:\Documents and Settings\Administrator\mqdmcr.sys" deleted successfully.<br><br>Error:  file "C:\WINDOWS\system32\kjjlm.bak1" not found!<br>Deletion of file "C:\WINDOWS\system32\kjjlm.bak1" failed!<br>Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)<br>  --> the object does not exist<br><br>Error:  file "C:\WINDOWS\system32\kjjlm.bak2" not found!<br>Deletion of file "C:\WINDOWS\system32\kjjlm.bak2" failed!<br>Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)<br>  --> the object does not exist<br><br>File "C:\WINDOWS\system32\kjjlm.ini2" deleted successfully.<br>File "C:\WINDOWS\U2FtaXIgQWhtYWQ\oZIQurK0kq1Qsqk.vbs" deleted successfully.<br>File "C:\WINDOWS\Installer\{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}\Icon0E6AB9FC.exe" deleted successfully.<br>File "C:\WINDOWS\Installer\{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}\Icon0E6AB9FC1.exe" deleted successfully.<br>File "C:\WINDOWS\Installer\{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}\IconDED53B0B.exe" deleted successfully.<br>File "C:\WINDOWS\Installer\{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}\IconDED53B0B1.exe" deleted successfully.<br><br>Error:  file "C:\WINDOWS\system32\{12fdb189-6534-5715-5717-a9c2868b4931}.dll-uninst.exe" not found!<br>Deletion of file "C:\WINDOWS\system32\{12fdb189-6534-5715-5717-a9c2868b4931}.dll-uninst.exe" failed!<br>Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)<br>  --> the object does not exist<br><br>Error:  file "C:\WINDOWS\system32\{12fdb189-6534-5715-5717-a9c2868b4931}.dll" not found!<br>Deletion of file "C:\WINDOWS\system32\{12fdb189-6534-5715-5717-a9c2868b4931}.dll" failed!<br>Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)<br>  --> the object does not exist<br><br>File "C:\WINDOWS\system32\axV\retmwav3.exe" deleted successfully.<br>File "C:\WINDOWS\system32\bharebio01\bharebio011065.exe" deleted successfully.<br>File "C:\WINDOWS\system32\drivers\NSDriver.sys" deleted successfully.<br>File "C:\WINDOWS\system32\IDE2\mdllcom2.exe" deleted successfully.<br>File "C:\WINDOWS\system32\iFi\prodll384.exe" deleted successfully.<br>File "C:\WINDOWS\system32\pinz1\cegmgr76.exe" deleted successfully.<br>Folder "C:\WINDOWS\U2FtaXIgQWhtYWQ" deleted successfully.<br>Folder "C:\WINDOWS\system32\pinz1" deleted successfully.<br>Folder "C:\WINDOWS\system32\iFi" deleted successfully.<br>Folder "C:\WINDOWS\system32\IDE2" deleted successfully.<br>Folder "C:\WINDOWS\system32\ExTmp" deleted successfully.<br>Folder "C:\WINDOWS\system32\bharebio01" deleted successfully.<br>Folder "C:\WINDOWS\system32\axV" deleted successfully.<br>Folder "C:\Temp\wdlw14" deleted successfully.<br><br>Error:  folder "C:\Documents and Settings\All Users\Application Data\Rabio" not found!<br>Deletion of folder "C:\Documents and Settings\All Users\Application Data\Rabio" failed!<br>Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)<br>  --> the object does not exist<br><br>Error:  folder "C:\WINDOWS\U2FtaXIgQWhtYWQ" not found!<br>Deletion of folder "C:\WINDOWS\U2FtaXIgQWhtYWQ" failed!<br>Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)<br>  --> the object does not exist<br><br>Error:  folder "C:\WINDOWS\system32\axV" not found!<br>Deletion of folder "C:\WINDOWS\system32\axV" failed!<br>Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)<br>  --> the object does not exist<br><br>Error:  folder "C:\WINDOWS\system32\bharebio01" not found!<br>Deletion of folder "C:\WINDOWS\system32\bharebio01" failed!<br>Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)<br>  --> the object does not exist<br><br>Error:  folder "C:\WINDOWS\system32\pinz1" not found!<br>Deletion of folder "C:\WINDOWS\system32\pinz1" failed!<br>Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)<br>  --> the object does not exist<br><br>Error:  folder "C:\WINDOWS\system32\iFi" not found!<br>Deletion of folder "C:\WINDOWS\system32\iFi" failed!<br>Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)<br>  --> the object does not exist<br><br>Error:  folder "C:\WINDOWS\system32\IDE2" not found!<br>Deletion of folder "C:\WINDOWS\system32\IDE2" failed!<br>Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)<br>  --> the object does not exist<br><br>Error:  registry key "HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0E3BE2B4-9688-443D-BACD-DD267AA674AE}" not found!<br>Deletion of registry key "HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0E3BE2B4-9688-443D-BACD-DD267AA674AE}" failed!<br>Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)<br>  --> the object does not exist<br><br>Error:  registry key "HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{27BED0D7-0938-4700-9060-A436B69EB7BC}" not found!<br>Deletion of registry key "HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{27BED0D7-0938-4700-9060-A436B69EB7BC}" failed!<br>Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)<br>  --> the object does not exist<br><br>Error:  registry key "HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9C3831AF-F271-4DB6-BB2C-DCD46F9BF462}" not found!<br>Deletion of registry key "HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9C3831AF-F271-4DB6-BB2C-DCD46F9BF462}" failed!<br>Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)<br>  --> the object does not exist<br><br>Error:  registry key "HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A67DA44A-58A5-4161-B77D-848247B6748C}" not found!<br>Deletion of registry key "HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A67DA44A-58A5-4161-B77D-848247B6748C}" failed!<br>Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)<br>  --> the object does not exist<br><br>Error:  registry key "HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A9457564-1FAB-4C4C-818D-417BA5F56D9C}" not found!<br>Deletion of registry key "HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A9457564-1FAB-4C4C-818D-417BA5F56D9C}" failed!<br>Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)<br>  --> the object does not exist<br><br>Error:  registry key "HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{DDBA5775-1351-4F21-881E-A4ADC9BEAB75}" not found!<br>Deletion of registry key "HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{DDBA5775-1351-4F21-881E-A4ADC9BEAB75}" failed!<br>Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)<br>  --> the object does not exist<br><br>Error:  registry key "HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{fed76bfd-a0ff-938f-507d-216c8ab86a74}" not found!<br>Deletion of registry key "HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{fed76bfd-a0ff-938f-507d-216c8ab86a74}" failed!<br>Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)<br>  --> the object does not exist<br><br>Error:  registry key "HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\efcccaa" not found!<br>Deletion of registry key "HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\efcccaa" failed!<br>Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)<br>  --> the object does not exist<br><br>Error:  registry key "HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\iifefEUl" not found!<br>Deletion of registry key "HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\iifefEUl" failed!<br>Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)<br>  --> the object does not exist<br><br>Error:  registry key "HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\opnklmk" not found!<br>Deletion of registry key "HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\opnklmk" failed!<br>Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)<br>  --> the object does not exist<br><br>Error:  registry key "HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\rqrstqn" not found!<br>Deletion of registry key "HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\rqrstqn" failed!<br>Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)<br>  --> the object does not exist<br><br>Error:  registry key "HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ssqrrpo" not found!<br>Deletion of registry key "HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ssqrrpo" failed!<br>Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)<br>  --> the object does not exist<br><br>Registry key "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Bffeeuso" deleted successfully.<br>Registry key "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MemoryManager" deleted successfully.<br>Registry key "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\pbvmnemA" deleted successfully.<br><br>Error:  could not delete registry value "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|dmxvp.exe"<br>Deletion of registry value "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|dmxvp.exe" failed!<br>Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)<br>  --> the object does not exist<br><br>Completed script processing.<br><br>*******************<br><br>Finished!  Terminate.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20340817</guid>
<pubDate>Tue, 15 Apr 2008 22:29:24 EDT</pubDate>
</item>

<item>
<title>Re: [HJT Log] Slowdown + Can&#x27;t go on websites</title>
<link>http://www.dslreports.com/forum/remark,20340122</link>
<description><![CDATA[<A HREF="/useremail/u/693977"><b>bcastner</b></A> : Download <b>The Avenger by Swandog46</b> from:<br><textarea name="code" class="text" cols=50 rows=10>http://swandog46.geekstogo.com/avenger2/download.php&#012;</textarea><!--end code block--><br>&#8226; Unzip/extract it to a folder on your desktop.<br>&#8226; Double click on <b>avenger.exe</b> to run <b>The Avenger</b>.<br>&#8226; Click OK.<br>&#8226; Make sure that the box next to <b>Scan for rootkits</b> has a tick in it and that the box next to <b>Automatically disable any rootkits found</b> does not have a tick in it.<br>&#8226; Copy <b>all</b> of the text in the below textbox by clicking where it says "Copy to clibpboard".<br><textarea name="code" class="text" cols=50 rows=10>Files to delete:&#012;C:\WINDOWS\system32\kjjlm.tmp&#012;C:\WINDOWS\system32\kjjlm.bak1&#012;C:\WINDOWS\system32\kjjlm.bak2&#012;C:\WINDOWS\system32\ogvfofdn.tmp&#012;C:\WINDOWS\system32\geeba.dll&#012;C:\WINDOWS\system32\{12fdb189-6534-5715-5717-a9c2868b4931}.dll&#012;C:\WINDOWS\system32\scntokdn.exe&#012;C:\WINDOWS\system32\{12fdb189-6534-5715-5717-a9c2868b4931}.dll&#012;c:\windows\system32\rwwnw64d.exe&#012;C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\Deewoo.lnk&#012;C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\DW_Start.lnk&#012;C:\Program Files\?ymantec\j?vaw.exe&#012;C:\WINDOWS\system32\qjjofwjh.dll&#012;C:\WINDOWS\pbvmnemA.exe&#012;C:\WINDOWS\system32\vrcvjnpm.dll&#012;C:\WINDOWS\system32\giupqxhj.dll&#012;C:\WINDOWS\system32\jmtmlbgv.dll&#012;C:\WINDOWS\system32\{12fdb189-6534-5715-5717-a9c2868b4931}.dll-uninst.exe&#012;C:\Program Files\Common Files\Yazzle1281OinUninstaller.exe&#012;C:\WINDOWS\system32\orxvmfos.dll&#012;C:\WINDOWS\system32\ttcbnthi.dll&#012;C:\WINDOWS\BMd7bd0422.xml&#012;C:\WINDOWS\system32\wxoghvke.dll&#012;C:\WINDOWS\system32\dvfskqyd.dll&#012;C:\WINDOWS\system32\cmeujpiy.dll&#012;C:\WINDOWS\system32\cbqoqefk.ini&#012;C:\WINDOWS\system32\oqbmuvua.dll&#012;C:\WINDOWS\system32\lafonvhy.dll&#012;C:\WINDOWS\system32\{12fdb189-6534-5715-5717-a9c2868b4931}.dll&#012;C:\WINDOWS\system32\cpukaqck.ini&#012;C:\WINDOWS\system32\hgwbxirw.ini&#012;C:\WINDOWS\system32\vjvkpctk.ini&#012;C:\WINDOWS\system32\hhuoiwga.ini&#012;C:\WINDOWS\system32\uggjpiei.ini&#012;C:\WINDOWS\system32\qcbvelel.ini&#012;C:\WINDOWS\system32\egjaiwsd.ini&#012;C:\WINDOWS\system32\geeba.dll&#012;C:\WINDOWS\system32\ZoneAlarmIconUS.ico&#012;C:\WINDOWS\system32\hcvncvih.ini&#012;C:\WINDOWS\system32\quiswxto.ini&#012;C:\WINDOWS\uninstall_nmon.vbs&#012;C:\Program Files\Common Files\Yazzle1281OinAdmin.exe&#012;C:\Documents and Settings\Administrator\mqdmmdm.sys&#012;C:\Documents and Settings\Administrator\mqdmmdfl.sys&#012;C:\Documents and Settings\Administrator\mqdmserd.sys&#012;C:\Documents and Settings\Administrator\mqdmbus.sys&#012;C:\Documents and Settings\Administrator\mqdmcmnt.sys&#012;C:\Documents and Settings\Administrator\mqdmwhnt.sys&#012;C:\Documents and Settings\Administrator\mqdmcr.sys&#012;C:\WINDOWS\system32\kjjlm.bak1&#012;C:\WINDOWS\system32\kjjlm.bak2&#012;C:\WINDOWS\system32\kjjlm.ini2&#012;C:\WINDOWS\U2FtaXIgQWhtYWQ\oZIQurK0kq1Qsqk.vbs&#012;C:\WINDOWS\Installer\{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}\Icon0E6AB9FC.exe&#012;C:\WINDOWS\Installer\{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}\Icon0E6AB9FC1.exe&#012;C:\WINDOWS\Installer\{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}\IconDED53B0B.exe&#012;C:\WINDOWS\Installer\{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}\IconDED53B0B1.exe&#012;C:\WINDOWS\system32\{12fdb189-6534-5715-5717-a9c2868b4931}.dll-uninst.exe&#012;C:\WINDOWS\system32\{12fdb189-6534-5715-5717-a9c2868b4931}.dll&#012;C:\WINDOWS\system32\axV\retmwav3.exe&#012;C:\WINDOWS\system32\bharebio01\bharebio011065.exe&#012;C:\WINDOWS\system32\drivers\NSDriver.sys&#012;C:\WINDOWS\system32\IDE2\mdllcom2.exe&#012;C:\WINDOWS\system32\iFi\prodll384.exe&#012;C:\WINDOWS\system32\pinz1\cegmgr76.exe&#012; &#012;Folders to delete:&#012;C:\WINDOWS\U2FtaXIgQWhtYWQ&#012;C:\WINDOWS\system32\pinz1&#012;C:\WINDOWS\system32\iFi&#012;C:\WINDOWS\system32\IDE2&#012;C:\WINDOWS\system32\ExTmp&#012;C:\WINDOWS\system32\bharebio01&#012;C:\WINDOWS\system32\axV&#012;C:\Temp\wdlw14&#012;C:\Documents and Settings\All Users\Application Data\Rabio&#012;C:\WINDOWS\U2FtaXIgQWhtYWQ&#012;C:\WINDOWS\system32\axV&#012;C:\WINDOWS\system32\bharebio01&#012;C:\WINDOWS\system32\pinz1&#012;C:\WINDOWS\system32\iFi&#012;C:\WINDOWS\system32\IDE2&#012; &#012;Registry keys to delete:&#012;HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0E3BE2B4-9688-443D-BACD-DD267AA674AE}&#012;HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{27BED0D7-0938-4700-9060-A436B69EB7BC}&#012;HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9C3831AF-F271-4DB6-BB2C-DCD46F9BF462}&#012;HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A67DA44A-58A5-4161-B77D-848247B6748C}&#012;HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A9457564-1FAB-4C4C-818D-417BA5F56D9C}&#012;HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{DDBA5775-1351-4F21-881E-A4ADC9BEAB75}&#012;HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{fed76bfd-a0ff-938f-507d-216c8ab86a74}&#012;HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\efcccaa&#012;HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\iifefEUl&#012;HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\opnklmk&#012;HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\rqrstqn&#012;HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ssqrrpo&#012;HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Bffeeuso&#012;HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MemoryManager&#012;HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\pbvmnemA&#012; &#012;Registry values to delete:&#012;HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|Rusc&#012;HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|Gzchx&#012;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|dmxvp.exe&#012;HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|dmotx.exe&#012;HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|{E3-37-71-11-DW}&#012;HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|spa_start&#012;HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|g&#93;eeV\mWhjlnspB"=-&#012; &#012;</textarea><!--end code block--><br>&#8226; In the avenger window, click the <b>Paste Script from Clipboard</b> icon,  <IMG SRC="http://img220.imageshack.us/img220/8923/pastets4.png">  button.<br><i> Click the <b>Execute</b> button.<br>&#8226; You will be asked "Are you sure you want to execute the current script?"  Click <b>Yes</b>.<br>&#8226; You will now be asked <b>First step completed --- The Avenger has been successfully set up to run on next boot. Reboot now?</b>  Click <b>Yes</b>.<br>&#8226; Your PC will now be rebooted.<br><br>&#8226; After your PC has completed the necessary reboots, a log should automatically open. If it does not automatically open, then the log can be found at  C:\avenger.txt.<br>&#8226; Please save this.<br><br>2. Using your mouse, left click once below where it says: "Copy to clipboard":<br><textarea name="code" class="text" cols=50 rows=10>REGEDIT4&#012; &#012;&#91;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa&#93; &#012;"Authentication Packages"=hex(7):6d,73,76,31,5f,30,00,00 &#012; &#012;</textarea><!--end code block--><br>Open a new <b>Notepad</b> document. (Do not use a Word Processor or WordPad).  Click "Format" and be certain that Word Wrap is not enabled. <br>Right-click | <b>Paste</b> the Code box contents from above into Notepad.  Click File, <b>Save as...</b>,  and enter (including quotation marks) as the filename: "RegistryFix.REG".   Exit Notepad.<br><br>Double click your new file and agree to the registry merge when asked.  You can then delete this new file.<br><br>3. Try Combofix again, with the same script as before.<br><br>4. Do the <b>OTMOVEIT2</b> as instructed.  If you would prefer to type the single word "Purity" you are welcome to do so.  It is case sensitive.<br><br>5. Run <b>MBAM</b> again as instructed.<br><br>6. Run HijackThis again as instructed.<br><br>Return all the logs requested, as well as the contents of C:\Avenger.txt.<br><br><small>--<br><b>============</b><br><b>MS-MVP 2004 - -2008, ASAP Member</b><br><b><i>Users Helping Users</i></b><br><br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20340122</guid>
<pubDate>Tue, 15 Apr 2008 20:14:08 EDT</pubDate>
</item>

<item>
<title>Re: [HJT Log] Slowdown + Can&#x27;t go on websites</title>
<link>http://www.dslreports.com/forum/remark,20339760</link>
<description><![CDATA[<A HREF="/useremail/u/637965"><b>halfHAVOC</b></A> : it gives me that same error garbage when i try to put the script into combofix...some rundll32 dos pops up...arghh ( dont think its gonna work in safemode either because i tried to use add/remove in safemode and the same thing happened)!!<br>btw all the code says in that code box is purity.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20339760</guid>
<pubDate>Tue, 15 Apr 2008 18:59:54 EDT</pubDate>
</item>

<item>
<title>Re: [HJT Log] Slowdown + Can&#x27;t go on websites</title>
<link>http://www.dslreports.com/forum/remark,20339591</link>
<description><![CDATA[<A HREF="/useremail/u/693977"><b>bcastner</b></A> : Do it last rather than first, then.<br>Please run the tasks requested and submit the log results.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20339591</guid>
<pubDate>Tue, 15 Apr 2008 18:23:56 EDT</pubDate>
</item>

<item>
<title>Re: [HJT Log] Slowdown + Can&#x27;t go on websites</title>
<link>http://www.dslreports.com/forum/remark,20339498</link>
<description><![CDATA[<A HREF="/useremail/u/637965"><b>halfHAVOC</b></A> : so apparently i get some run dll dos pop up or something and quickly exits itself and it wont load add/remove programs nor can i find the uninstall icon for either of the two programs, is there any other shortcut or way to uninstall one of them?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20339498</guid>
<pubDate>Tue, 15 Apr 2008 18:08:19 EDT</pubDate>
</item>

<item>
<title>Re: [HJT Log] Slowdown + Can&#x27;t go on websites</title>
<link>http://www.dslreports.com/forum/remark,20338651</link>
<description><![CDATA[<A HREF="/useremail/u/693977"><b>bcastner</b></A> : You now have Kaspersky Antivirus installed.  You cannot have two, active, antivirus programs installed.  Doing so makes you less, not more protected.  Please uninstall either AVAST or Kaspersky.  Reboot.<br><br>This is one of the most seriously compromised computers I have ever seen, and running or adding antivirus and antimalware programs at this point will effectively prevent this computer from ever becoming clean.<br><br>1. Open <b>HijackThis</b> again, System scan only.  <b>Checkmark</b> these items:<br><br><b>O2 - BHO: (no name) - {27BED0D7-0938-4700-9060-A436B69EB7BC} - C:\Program Files\Common Files\horev4444.dll (file missing)<br>O2 - BHO: (no name) - {9C3831AF-F271-4DB6-BB2C-DCD46F9BF462} - C:\Program Files\MSN\comeqoc89104.dll (file missing)<br>O2 - BHO: (no name) - {A67DA44A-58A5-4161-B77D-848247B6748C} - C:\Program Files\Common Files\horev7.dll (file missing)<br>O2 - BHO: (no name) - {A9457564-1FAB-4C4C-818D-417BA5F56D9C} - C:\WINDOWS\system32\jkkli.dll (file missing)<br>O2 - BHO: (no name) - {DDBA5775-1351-4F21-881E-A4ADC9BEAB75} - C:\Program Files\Common Files\horev83122.dll (file missing)<br>O2 - BHO: {539d0426-5fb5-aa88-b654-46c17524fb1e} - {e1bf4257-1c64-456b-88aa-5bf56240d935} - C:\WINDOWS\system32\xcldfjbb.dll<br>O2 - BHO: nextads browser optimizer - {fed76bfd-a0ff-938f-507d-216c8ab86a74} - C:\WINDOWS\system32\{12fdb189-6534-5715-5717-a9c2868b4931}.dll (file missing)<br>O4 - HKLM\..\Run: [d48e37be] rundll32.exe "C:\WINDOWS\system32\nkqtkmpa.dll",b<br>O20 - Winlogon Notify: efcccaa - efcccaa.dll (file missing)<br>O20 - Winlogon Notify: iifefEUl - iifefEUl.dll (file missing)<br>O20 - Winlogon Notify: opnklmk - opnklmk.dll (file missing)<br>O20 - Winlogon Notify: rqrstqn - rqrstqn.dll (file missing)<br>O20 - Winlogon Notify: ssqrrpo - ssqrrpo.dll (file missing)</b><br><br>Click "<b>Fix checked</b>" and when the log panel clears exit HijackThis.<br><br>2. Click Start, click Run, and enter into the command box that opens the single word:  <b>CMD</b>.<br>In the black box that opens, type carefully:<br><br><b>netsh int ip reset resetlog.txt<br>netsh winsock reset</b><br><br>After a moment, a notice should appear telling you that a restart of your computer is requred.<br>Reboot to the operating system fully loaded -- <u><b>twice.</b></u>.<br><br>3. Right-click on the header of the Code box below, where on the right side it says:  "<b>Copy to clipboard</b>":<br><textarea name="code" class="text" cols=50 rows=10>File::&#012;C:\WINDOWS\system32\kjjlm.tmp&#012;C:\WINDOWS\system32\kjjlm.bak1&#012;C:\WINDOWS\system32\kjjlm.bak2&#012;C:\WINDOWS\system32\ogvfofdn.tmp&#012;C:\WINDOWS\system32\geeba.dll&#012;C:\WINDOWS\system32\{12fdb189-6534-5715-5717-a9c2868b4931}.dll&#012;C:\WINDOWS\system32\scntokdn.exe&#012;C:\WINDOWS\system32\{12fdb189-6534-5715-5717-a9c2868b4931}.dll&#012;c:\windows\system32\rwwnw64d.exe&#012;C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\Deewoo.lnk&#012;C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\DW_Start.lnk&#012;C:\Program Files\?ymantec\j?vaw.exe&#012;C:\WINDOWS\system32\qjjofwjh.dll&#012;C:\WINDOWS\pbvmnemA.exe&#012;C:\WINDOWS\system32\vrcvjnpm.dll&#012;C:\WINDOWS\system32\giupqxhj.dll&#012;C:\WINDOWS\system32\jmtmlbgv.dll&#012;C:\WINDOWS\system32\{12fdb189-6534-5715-5717-a9c2868b4931}.dll-uninst.exe&#012;C:\Program Files\Common Files\Yazzle1281OinUninstaller.exe&#012;C:\WINDOWS\system32\orxvmfos.dll&#012;C:\WINDOWS\system32\ttcbnthi.dll&#012;C:\WINDOWS\BMd7bd0422.xml&#012;C:\WINDOWS\system32\wxoghvke.dll&#012;C:\WINDOWS\system32\dvfskqyd.dll&#012;C:\WINDOWS\system32\cmeujpiy.dll&#012;C:\WINDOWS\system32\cbqoqefk.ini&#012;C:\WINDOWS\system32\oqbmuvua.dll&#012;C:\WINDOWS\system32\lafonvhy.dll&#012;C:\WINDOWS\system32\{12fdb189-6534-5715-5717-a9c2868b4931}.dll&#012;C:\WINDOWS\system32\cpukaqck.ini&#012;C:\WINDOWS\system32\hgwbxirw.ini&#012;C:\WINDOWS\system32\vjvkpctk.ini&#012;C:\WINDOWS\system32\hhuoiwga.ini&#012;C:\WINDOWS\system32\uggjpiei.ini&#012;C:\WINDOWS\system32\qcbvelel.ini&#012;C:\WINDOWS\system32\egjaiwsd.ini&#012;C:\WINDOWS\system32\geeba.dll&#012;C:\WINDOWS\system32\hcvncvih.ini&#012;C:\WINDOWS\system32\quiswxto.ini&#012;C:\WINDOWS\uninstall_nmon.vbs&#012;C:\Program Files\Common Files\Yazzle1281OinAdmin.exe&#012;C:\WINDOWS\system32\kjjlm.bak1&#012;C:\WINDOWS\system32\kjjlm.bak2&#012;C:\WINDOWS\system32\kjjlm.ini2&#012;C:\WINDOWS\U2FtaXIgQWhtYWQ\oZIQurK0kq1Qsqk.vbs&#012;C:\WINDOWS\Installer\{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}\Icon0E6AB9FC.exe&#012;C:\WINDOWS\Installer\{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}\Icon0E6AB9FC1.exe&#012;C:\WINDOWS\Installer\{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}\IconDED53B0B.exe&#012;C:\WINDOWS\Installer\{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}\IconDED53B0B1.exe&#012;C:\WINDOWS\system32\{12fdb189-6534-5715-5717-a9c2868b4931}.dll-uninst.exe&#012;C:\WINDOWS\system32\{12fdb189-6534-5715-5717-a9c2868b4931}.dll&#012;C:\WINDOWS\system32\axV\retmwav3.exe&#012;C:\WINDOWS\system32\bharebio01\bharebio011065.exe&#012;C:\WINDOWS\system32\drivers\NSDriver.sys&#012;C:\WINDOWS\system32\IDE2\mdllcom2.exe&#012;C:\WINDOWS\system32\iFi\prodll384.exe&#012;C:\WINDOWS\system32\pinz1\cegmgr76.exe&#012; &#012;Folder::&#012;C:\WINDOWS\U2FtaXIgQWhtYWQ&#012;C:\WINDOWS\system32\pinz1&#012;C:\WINDOWS\system32\iFi&#012;C:\WINDOWS\system32\IDE2&#012;C:\WINDOWS\system32\ExTmp&#012;C:\WINDOWS\system32\bharebio01&#012;C:\Temp\wdlw14&#012;C:\Documents and Settings\All Users\Application Data\Rabio&#012;C:\WINDOWS\U2FtaXIgQWhtYWQ&#012;C:\WINDOWS\system32\axV&#012;C:\WINDOWS\system32\bharebio01&#012;C:\WINDOWS\system32\pinz1&#012;C:\WINDOWS\system32\iFi&#012;C:\WINDOWS\system32\IDE2&#012; &#012;Registry::&#012;&#91;-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0E3BE2B4-9688-443D-BACD-DD267AA674AE}&#93;&#012;&#91;-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{27BED0D7-0938-4700-9060-A436B69EB7BC}&#93;&#012;&#91;-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9C3831AF-F271-4DB6-BB2C-DCD46F9BF462}&#93;&#012;&#91;-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A67DA44A-58A5-4161-B77D-848247B6748C}&#93;&#012;&#91;-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A9457564-1FAB-4C4C-818D-417BA5F56D9C}&#93;&#012;&#91;-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{DDBA5775-1351-4F21-881E-A4ADC9BEAB75}&#93;&#012;&#91;-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{fed76bfd-a0ff-938f-507d-216c8ab86a74}&#93;&#012;&#91;HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run&#93;&#012;"Rusc"=-&#012;"Gzchx"=-&#012;&#91;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run&#93;&#012;"dmxvp.exe"=-&#012;"dmotx.exe"=-&#012;"{E3-37-71-11-DW}"=-&#012;"spa_start"=-&#012;"g&#93;eeV\mWhjlnspB"=-&#012;&#91;-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\efcccaa&#93;&#012;&#91;-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\iifefEUl&#93;&#012;&#91;-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\opnklmk&#93;&#012;&#91;-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\rqrstqn&#93;&#012;&#91;-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ssqrrpo&#93;&#012;&#91;-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Bffeeuso&#93;&#012;&#91;-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MemoryManager&#93;&#012;&#91;-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\pbvmnemA&#93;&#012;&#91;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa&#93; &#012;"Authentication Packages"=hex(7):6d,73,76,31,5f,30,00,00 &#012; &#012;</textarea><!--end code block--><br>Open a new Notepad session - (Do <b><i>not</i></b> use a Word Processor or WordPad).  Click "<b>Format</b>" and be certain that Word Wrap is not enabled.  Right-click | <b>Paste</b> the Code box contents from above into Notepad.  Click File, <b><i>Save as...</i></b>, and set the location to your Desktop, and enter (including quotation marks) as the filename: <b>"CFscript.txt"</b> .  <br><br>&#8226; Disconnect from the Internet.<br>&#8226; Disable your Antivirus.  If the Antivirus software you use has any Script Blocking features, be certain to disable these as well.<br><b> Important:  </b> Have no other programs running.  Your Task Bar should be clear of any program entries including your Browser.<br>&#8226; A window will open with a warning.  Accept any Disclaimers to start the fix.<br>Using your mouse, drag the new file CFscript.txt and drop it on the ComboFix.exe icon as shown in this little picture:<br> <IMG SRC="http://users.pandora.be/bluepatchy/miekiemoes/images/CFScript.gif"> <br><br>When the scan completes Notepad will open with with your results log open. Do a File, Exit and answer 'Yes' to save changes.<br>&#8226;<b>!</b>&#8226; A caution - Do <b>not</b> run Combofix more than once. Do not touch your mouse/keyboard until the scan has completed, as this may cause the process to stall or your computer to lock.<br><br>4.  Please download  to your Desktop <b>OT_MOVEIT2</b>:<br><textarea name="code" class="text" cols=50 rows=10>http://download.bleepingcomputer.com/oldtimer/OTMoveIt2.exe&#012;</textarea><!--end code block--><br>Please double-click OTMoveIt2.exe to run the utility.<br><br>Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):<br><br><textarea name="code" class="text" cols=50 rows=10>Purity&#012; &#012;</textarea><!--end code block--><br>Return to OTMoveIt2, right click in the <b>Left panel</b> and choose <b>Paste</b>.<br><br>Click the red <b>Moveit</b> button.<br>This will not be quick.  I am asking it to scan your entire Drive C twice.<br>When it has finished, use your mouse and do a Copy/Paste of the large right-hand panel that shows Results.<br>Save your Clipboard contents in a new Notepad file, as we will want to review these results later.<br>Close OTMoveIt2 when it has finished.<br><br>Note:  If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose <b>Yes.</b><br><br>5. Open <b>MBAM</b>.  Do an update of its defitinition files if possible.  Run the scan again exactly as you did earlier.<br><br>6. Run <b>HijackThis</b> again, and save the log file.<br><br><b><i>Submit to the Forum:</i></b><br>&#8226; The contents of C:\Combofix.txt;<br>&#8226; The new <b>MBAM</b> log;<br>&#8226; The new HijackThis log.<br><br><small>--<br><b>============</b><br><b>MS-MVP 2004 - -2008, ASAP Member</b><br><b><i>Users Helping Users</i></b><br><br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20338651</guid>
<pubDate>Tue, 15 Apr 2008 15:30:49 EDT</pubDate>
</item>

<item>
<title>Re: [HJT Log] Slowdown + Can&#x27;t go on websites</title>
<link>http://www.dslreports.com/forum/remark,20336159</link>
<description><![CDATA[<A HREF="/useremail/u/637965"><b>halfHAVOC</b></A> : errr sorry about this double post but i needed to seperate the last hjt log...<br><br>Logfile of Trend Micro HijackThis v2.0.2<br>Scan saved at 6:54:22 AM, on 4/15/2008<br>Platform: Windows XP SP2 (WinNT 5.01.2600)<br>MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)<br>Boot mode: Normal<br><br>Running processes:<br>C:\WINDOWS\System32\smss.exe<br>C:\WINDOWS\system32\winlogon.exe<br>C:\WINDOWS\system32\services.exe<br>C:\WINDOWS\system32\lsass.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe<br>C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe<br>C:\Program Files\Alwil Software\Avast4\ashServ.exe<br>C:\WINDOWS\Explorer.EXE<br>C:\WINDOWS\system32\spoolsv.exe<br>C:\WINDOWS\System32\SCardSvr.exe<br>C:\Program Files\Athan\Athan.exe<br>C:\Program Files\iTunes\iTunesHelper.exe<br>C:\Program Files\Logitech\iTouch\iTouch.exe<br>C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe<br>C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe<br>C:\WINDOWS\system32\nvsvc32.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\WINDOWS\system32\ctfmon.exe<br>C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe<br>C:\WINDOWS\system32\wscntfy.exe<br>C:\Program Files\iPod\bin\iPodService.exe<br>C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=69157" >go.microsoft.com/fwlink/?LinkId=69157</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = &raquo;<A HREF="http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr7/*http://www.yahoo.com/ext/search/search.html" >us.rd.yahoo.com/customize/ie/def&middot;&middot;&middot;rch.html</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = &raquo;<A HREF="http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR" >g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR</A><br>R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 200.30.66.65:80<br>O2 - BHO: (no name) - {27BED0D7-0938-4700-9060-A436B69EB7BC} - C:\Program Files\Common Files\horev4444.dll (file missing)<br>O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll<br>O2 - BHO: (no name) - {9C3831AF-F271-4DB6-BB2C-DCD46F9BF462} - C:\Program Files\MSN\comeqoc89104.dll (file missing)<br>O2 - BHO: (no name) - {A67DA44A-58A5-4161-B77D-848247B6748C} - C:\Program Files\Common Files\horev7.dll (file missing)<br>O2 - BHO: (no name) - {A9457564-1FAB-4C4C-818D-417BA5F56D9C} - C:\WINDOWS\system32\jkkli.dll (file missing)<br>O2 - BHO: (no name) - {DDBA5775-1351-4F21-881E-A4ADC9BEAB75} - C:\Program Files\Common Files\horev83122.dll (file missing)<br>O2 - BHO: {539d0426-5fb5-aa88-b654-46c17524fb1e} - {e1bf4257-1c64-456b-88aa-5bf56240d935} - C:\WINDOWS\system32\xcldfjbb.dll<br>O2 - BHO: nextads browser optimizer - {fed76bfd-a0ff-938f-507d-216c8ab86a74} - C:\WINDOWS\system32\{12fdb189-6534-5715-5717-a9c2868b4931}.dll (file missing)<br>O4 - HKLM\..\Run: [Athan] C:\Program Files\Athan\Athan.exe<br>O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"<br>O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe<br>O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"<br>O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup<br>O4 - HKLM\..\Run: [nwiz] nwiz.exe /install<br>O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime<br>O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit<br>O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"<br>O4 - HKLM\..\Run: [d48e37be] rundll32.exe "C:\WINDOWS\system32\nkqtkmpa.dll",b<br>O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br>O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000<br>O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll<br>O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll<br>O9 - Extra button: ATI TV - {44226DFF-747E-4edc-B30C-78752E50CD0C} - C:\Program Files\ATI Multimedia\tv\EXPLBAR.DLL (file missing)<br>O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe<br>O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br>O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br>O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - &raquo;<A HREF="http://go.divx.com/plugin/DivXBrowserPlugin.cab" >go.divx.com/plugin/DivXBrowserPlugin.cab</A><br>O20 - Winlogon Notify: efcccaa - efcccaa.dll (file missing)<br>O20 - Winlogon Notify: iifefEUl - iifefEUl.dll (file missing)<br>O20 - Winlogon Notify: opnklmk - opnklmk.dll (file missing)<br>O20 - Winlogon Notify: rqrstqn - rqrstqn.dll (file missing)<br>O20 - Winlogon Notify: ssqrrpo - ssqrrpo.dll (file missing)<br>O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe<br>O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe<br>O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe<br>O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe (file missing)<br>O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe<br>O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe<br>O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe<br>O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe<br>O23 - Service: Kaspersky Anti-Virus 6.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe<br>O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe<br>O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe<br>O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe<br><br>--<br>End of file - 6450 bytes<br><br>oddly the Q2's show up now.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20336159</guid>
<pubDate>Tue, 15 Apr 2008 06:55:41 EDT</pubDate>
</item>

<item>
<title>Re: [HJT Log] Slowdown + Can&#x27;t go on websites</title>
<link>http://www.dslreports.com/forum/remark,20334039</link>
<description><![CDATA[<A HREF="/useremail/u/637965"><b>halfHAVOC</b></A> : ok weird. i have like 3 combofix logs from before, so i dont know where the latest one is from yesterday....im pretty sure it saved? but ill post this i guess unless it posted the date wrong idk.<br><br>combofix: idk it might be from before i posted cuz i can't find the latest one, where is it located?<br>ComboFix 08-04-12.7 - Administrator 2008-04-13 17:33:53.7 - NTFSx86<br>Running from: C:\Documents and Settings\Administrator\desktop\cf.exe<br>Command switches used :: /killall<br><br>[color=red]<b>WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!</b>[/color]<br>.<br><br>(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br><br>C:\Documents and Settings\Administrator\My Documents\MANTEC~1<br>C:\Documents and Settings\Administrator\My Documents\MANTEC~1\??mantec\<br>C:\Documents and Settings\Administrator\My Documents\MANTEC~1\msiexec.exe<br>C:\Documents and Settings\Administrator\Start Menu\Programs\Outerinfo<br>C:\Documents and Settings\Administrator\Start Menu\Programs\Outerinfo\Terms.lnk<br>C:\Documents and Settings\Administrator\Start Menu\Programs\Outerinfo\Uninstall.lnk<br>C:\Documents and Settings\LocalService\Application Data\NetMon<br>C:\Documents and Settings\LocalService\Application Data\NetMon\domains.txt<br>C:\Documents and Settings\LocalService\Application Data\NetMon\log.txt<br>C:\Documents and Settings\NetworkService\Application Data\NetMon<br>C:\Documents and Settings\NetworkService\Application Data\NetMon\domains.txt<br>C:\Documents and Settings\NetworkService\Application Data\NetMon\log.txt<br>C:\Program Files\Common Files\mantec~1<br>C:\Program Files\Common Files\mantec~1\??xplore.exe<br>C:\Program Files\outerinfo<br>C:\Program Files\outerinfo\FF\chrome.manifest<br>C:\Program Files\outerinfo\FF\components\FF.dll<br>C:\Program Files\outerinfo\FF\components\OuterinfoAds.xpt<br>C:\Program Files\outerinfo\FF\install.rdf<br>C:\Program Files\outerinfo\Terms.rtf<br>C:\Temp\1cb<br>C:\Temp\1cb\syscheck.log<br>C:\WINDOWS\cookies.ini<br>C:\WINDOWS\pskt.ini<br>C:\WINDOWS\system32\abeeg.ini<br>C:\WINDOWS\system32\abeeg.ini2<br>C:\WINDOWS\system32\awucbnde.dll<br>C:\WINDOWS\system32\bqgpbbrf.ini<br>C:\WINDOWS\system32\eobxrmdf.dll<br>C:\WINDOWS\system32\frbbpgqb.dll<br>C:\WINDOWS\system32\geBtSIBs.dll<br>C:\WINDOWS\system32\gynokvko.dll<br>C:\WINDOWS\system32\hglshnkk.dll<br>C:\WINDOWS\system32\hkuvonkf.dll<br>C:\WINDOWS\system32\ibflwwyk.dll<br>C:\WINDOWS\system32\ieqstsip.dll<br>C:\WINDOWS\system32\iifefEUl.dll<br>C:\WINDOWS\system32\kywwlfbi.ini<br>C:\WINDOWS\system32\llogagvo.ini<br>C:\WINDOWS\system32\lsqxslns.dll<br>C:\WINDOWS\system32\msnav32.ax<br>C:\WINDOWS\system32\ovgagoll.dll<br>C:\WINDOWS\system32\pac.txt<br>C:\WINDOWS\system32\rqRIaaXr.dll<br>C:\WINDOWS\system32\wjhpojwc.dll<br>C:\WINDOWS\system32\wli.dll<br>C:\WINDOWS\system32\wuenfygh.dll<br><br>.<br>(((((((((((((((((((((((((((((((((((((((   Drivers/Services   )))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br><br>-------\Legacy_CMDSERVICE<br>-------\Legacy_NETWORK_MONITOR<br>-------\Legacy_TNIDRIVER<br>-------\Service_TnIDriver<br><br>(((((((((((((((((((((((((   Files Created from 2008-03-13 to 2008-04-13  )))))))))))))))))))))))))))))))<br>.<br><br>2008-04-13 17:28 . 2008-04-13 17:28&#9;3,648&#9;--a------&#9;C:\WINDOWS\system32\vrcvjnpm.dll<br>2008-04-13 17:26 . 2008-04-13 17:26&#9;3,648&#9;--a------&#9;C:\WINDOWS\system32\giupqxhj.dll<br>2008-04-13 13:37 . 2008-04-13 13:37&#9;3,648&#9;--a------&#9;C:\WINDOWS\system32\jmtmlbgv.dll<br>2008-04-13 13:23 . 2008-04-13 13:23&#9;&#9;d--hs----&#9;C:\WINDOWS\U2FtaXIgQWhtYWQ<br>2008-04-13 13:23 . 2008-04-13 13:23&#9;&#9;d--------&#9;C:\WINDOWS\system32\pinz1<br>2008-04-13 13:23 . 2008-04-13 13:23&#9;&#9;d--------&#9;C:\WINDOWS\system32\iFi<br>2008-04-13 13:23 . 2008-04-13 13:23&#9;&#9;d--------&#9;C:\WINDOWS\system32\IDE2<br>2008-04-13 13:23 . 2008-04-13 17:15&#9;&#9;d--------&#9;C:\WINDOWS\system32\ExTmp<br>2008-04-13 13:23 . 2008-04-13 13:23&#9;&#9;d--------&#9;C:\WINDOWS\system32\bharebio01<br>2008-04-13 13:23 . 2008-04-13 13:23&#9;&#9;d--------&#9;C:\WINDOWS\system32\axV<br>2008-04-13 13:23 . 2008-04-13 13:23&#9;&#9;d--------&#9;C:\Temp\wdlw14<br>2008-04-13 13:23 . 2008-04-13 13:23&#9;63,839&#9;--a------&#9;C:\WINDOWS\system32\{12fdb189-6534-5715-5717-a9c2868b4931}.dll-uninst.exe<br>2008-04-13 13:23 . 2008-04-13 13:23&#9;41,723&#9;---hs----&#9;C:\Program Files\Common Files\Yazzle1281OinUninstaller.exe<br>2008-04-13 10:48 . 2008-04-13 10:48&#9;&#9;d--------&#9;C:\Program Files\Lavasoft<br>2008-04-13 10:29 . 2008-04-13 10:29&#9;3,648&#9;--a------&#9;C:\WINDOWS\system32\orxvmfos.dll<br>2008-04-13 09:55 . 2008-04-13 09:55&#9;3,648&#9;--a------&#9;C:\WINDOWS\system32\ttcbnthi.dll<br>2008-04-13 00:15 . 2008-04-13 00:15&#9;3,648&#9;--a------&#9;C:\WINDOWS\system32\rlllduoj.dll<br>2008-04-11 20:26 . 2008-04-13 12:04&#9;101,110&#9;--a------&#9;C:\WINDOWS\BMd7bd0422.xml<br>2008-04-11 20:26 . 2008-04-11 20:26&#9;3,648&#9;--a------&#9;C:\WINDOWS\system32\wxoghvke.dll<br>2008-04-11 19:45 . 2008-04-11 19:45&#9;3,648&#9;--a------&#9;C:\WINDOWS\system32\dvfskqyd.dll<br>2008-04-10 18:53 . 2008-03-29 13:31&#9;75,856&#9;--a------&#9;C:\WINDOWS\system32\drivers\aswSP.sys<br>2008-04-10 18:53 . 2008-03-29 13:35&#9;20,560&#9;--a------&#9;C:\WINDOWS\system32\drivers\aswFsBlk.sys<br>2008-04-10 11:13 . 2008-04-10 11:13&#9;3,648&#9;--a------&#9;C:\WINDOWS\system32\cmeujpiy.dll<br>2008-04-09 11:18 . 2008-04-09 16:13&#9;878&#9;--ahs----&#9;C:\WINDOWS\system32\cbqoqefk.ini<br>2008-04-09 11:12 . 2008-04-09 11:12&#9;3,648&#9;--a------&#9;C:\WINDOWS\system32\oqbmuvua.dll<br>2008-04-08 11:08 . 2008-04-08 11:08&#9;3,648&#9;--a------&#9;C:\WINDOWS\system32\lafonvhy.dll<br>2008-04-05 14:56 . 2008-04-05 14:56&#9;&#9;d--------&#9;C:\Program Files\ATI Technologies<br>2008-04-04 14:55 . 2008-02-22 02:33&#9;69,632&#9;--a------&#9;C:\WINDOWS\system32\javacpl.cpl<br>2008-04-04 07:35 . 2008-04-04 07:35&#9;329,728&#9;--a------&#9;C:\WINDOWS\system32\{12fdb189-6534-5715-5717-a9c2868b4931}.dll<br>2008-04-01 14:26 . 2008-04-01 14:27&#9;1,597,294&#9;--ahs----&#9;C:\WINDOWS\system32\cpukaqck.ini<br>2008-03-31 09:04 . 2008-03-31 22:30&#9;1,597,234&#9;--ahs----&#9;C:\WINDOWS\system32\hgwbxirw.ini<br>2008-03-30 09:01 . 2008-03-30 09:21&#9;1,583,982&#9;--ahs----&#9;C:\WINDOWS\system32\vjvkpctk.ini<br>2008-03-29 13:21 . 2008-03-30 08:58&#9;1,583,757&#9;--ahs----&#9;C:\WINDOWS\system32\hhuoiwga.ini<br>2008-03-28 13:25 . 2008-03-28 13:25&#9;1,583,959&#9;--ahs----&#9;C:\WINDOWS\system32\uggjpiei.ini<br>2008-03-28 12:10 . 2008-03-28 12:51&#9;1,584,259&#9;--ahs----&#9;C:\WINDOWS\system32\qcbvelel.ini<br>2008-03-27 12:07 . 2008-03-28 12:07&#9;1,584,079&#9;--ahs----&#9;C:\WINDOWS\system32\egjaiwsd.ini<br>2008-03-16 10:27 . 2008-03-16 10:27&#9;315,472&#9;--a------&#9;C:\WINDOWS\system32\geeba.dll<br>2008-03-16 00:23 . 2008-03-16 00:23&#9;9,662&#9;--a------&#9;C:\WINDOWS\system32\ZoneAlarmIconUS.ico<br>2008-03-15 18:56 . 2008-03-15 18:57&#9;1,366,923&#9;--ahs----&#9;C:\WINDOWS\system32\hcvncvih.ini<br>2008-03-14 23:34 . 2008-03-14 23:34&#9;&#9;d--------&#9;C:\Documents and Settings\All Users\Application Data\NVIDIA<br>2008-03-14 18:57 . 2008-03-14 18:57&#9;&#9;d--------&#9;C:\Documents and Settings\All Users\Application Data\Rabio<br>2008-03-14 18:55 . 2008-03-15 18:55&#9;1,366,863&#9;--ahs----&#9;C:\WINDOWS\system32\quiswxto.ini<br>2008-03-14 18:44 . 2006-01-03 17:45&#9;1,989&#9;--a------&#9;C:\WINDOWS\uninstall_nmon.vbs<br>2008-03-13 18:30 . 2008-03-29 13:45&#9;1,146,232&#9;--a------&#9;C:\WINDOWS\system32\aswBoot.exe<br>2008-03-13 18:30 . 2004-01-09 04:13&#9;380,928&#9;--a------&#9;C:\WINDOWS\system32\actskin4.ocx<br>2008-03-13 18:30 . 2008-03-29 13:23&#9;95,608&#9;--a------&#9;C:\WINDOWS\system32\AvastSS.scr<br>2008-03-13 18:30 . 2008-03-29 13:35&#9;94,544&#9;--a------&#9;C:\WINDOWS\system32\drivers\aswmon2.sys<br>2008-03-13 18:30 . 2008-01-17 11:34&#9;93,264&#9;--a------&#9;C:\WINDOWS\system32\drivers\aswmon.sys<br>2008-03-13 18:30 . 2008-03-29 13:27&#9;42,912&#9;--a------&#9;C:\WINDOWS\system32\drivers\aswTdi.sys<br>2008-03-13 18:30 . 2008-03-29 13:26&#9;26,944&#9;--a------&#9;C:\WINDOWS\system32\drivers\aavmker4.sys<br>2008-03-13 18:30 . 2008-03-29 13:29&#9;23,152&#9;--a------&#9;C:\WINDOWS\system32\drivers\aswRdr.sys<br>2008-03-13 18:29 . 2008-03-13 18:29&#9;&#9;d--------&#9;C:\Documents and Settings\All Users\Application Data\Avg7<br><br>.<br>((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br>2008-04-13 22:51&#9;1,201,184&#9;--sha-w&#9;C:\WINDOWS\system32\drivers\fidbox2.dat<br>2008-04-13 22:44&#9;699,044&#9;--sha-w&#9;C:\WINDOWS\system32\drivers\fidbox.idx<br>2008-04-13 22:44&#9;56,039,456&#9;--sha-w&#9;C:\WINDOWS\system32\drivers\fidbox.dat<br>2008-04-13 22:44&#9;113,636&#9;--sha-w&#9;C:\WINDOWS\system32\drivers\fidbox2.idx<br>2008-04-13 15:50&#9;---------&#9;d-----w&#9;C:\Documents and Settings\All Users\Application Data\Lavasoft<br>2008-04-13 15:47&#9;---------&#9;d-----w&#9;C:\Program Files\Common Files\Wise Installation Wizard<br>2008-04-05 19:56&#9;---------&#9;d--h--w&#9;C:\Program Files\InstallShield Installation Information<br>2008-04-04 19:55&#9;---------&#9;d-----w&#9;C:\Program Files\Java<br>2008-03-13 23:29&#9;---------&#9;d-----w&#9;C:\Program Files\SUPERAntiSpyware<br>2008-03-13 23:29&#9;---------&#9;d-----w&#9;C:\Documents and Settings\Administrator\Application Data\SUPERAntiSpyware.com<br>2008-03-13 23:28&#9;---------&#9;d-----w&#9;C:\Documents and Settings\All Users\Application Data\Grisoft<br>2008-03-02 18:16&#9;---------&#9;d-----w&#9;C:\Program Files\The KMPlayer<br>2008-02-27 03:05&#9;---------&#9;d-----w&#9;C:\Documents and Settings\Administrator\Application Data\Winamp<br>2008-02-25 23:32&#9;---------&#9;d-----w&#9;C:\Program Files\ffdshow<br>2008-02-25 03:09&#9;---------&#9;d-----w&#9;C:\Documents and Settings\Administrator\Application Data\Move Networks<br>2008-02-25 03:03&#9;---------&#9;d-----w&#9;C:\Program Files\SopCast<br>2008-02-25 02:54&#9;---------&#9;d-----w&#9;C:\Program Files\NBA Live Player<br>2008-02-24 22:15&#9;---------&#9;d-----w&#9;C:\Program Files\Winamp<br>2008-02-14 18:26&#9;---------&#9;d-----w&#9;C:\Program Files\Spybot - Search & Destroy<br>2008-01-15 21:52&#9;140,800&#9;--sha-w&#9;C:\Program Files\Common Files\Yazzle1281OinAdmin.exe<br>2007-08-11 02:24&#9;92,064&#9;----a-w&#9;C:\Documents and Settings\Administrator\mqdmmdm.sys<br>2007-08-11 02:24&#9;9,232&#9;----a-w&#9;C:\Documents and Settings\Administrator\mqdmmdfl.sys<br>2007-08-11 02:24&#9;79,328&#9;----a-w&#9;C:\Documents and Settings\Administrator\mqdmserd.sys<br>2007-08-11 02:24&#9;66,656&#9;----a-w&#9;C:\Documents and Settings\Administrator\mqdmbus.sys<br>2007-08-11 02:24&#9;6,208&#9;----a-w&#9;C:\Documents and Settings\Administrator\mqdmcmnt.sys<br>2007-08-11 02:24&#9;5,936&#9;----a-w&#9;C:\Documents and Settings\Administrator\mqdmwhnt.sys<br>2007-08-11 02:24&#9;4,048&#9;----a-w&#9;C:\Documents and Settings\Administrator\mqdmcr.sys<br>2007-08-11 02:24&#9;25,600&#9;----a-w&#9;C:\Documents and Settings\Administrator\usbsermptxp.sys<br>2007-08-11 02:24&#9;22,768&#9;----a-w&#9;C:\Documents and Settings\Administrator\usbsermpt.sys<br>2007-07-24 14:21&#9;6,471&#9;--sha-w&#9;C:\WINDOWS\system32\kjjlm.bak1<br>2007-07-24 14:36&#9;1,807,725&#9;--sha-w&#9;C:\WINDOWS\system32\kjjlm.bak2<br>2007-07-24 21:37&#9;1,846,866&#9;--sha-w&#9;C:\WINDOWS\system32\kjjlm.ini2<br>2005-07-29 21:24&#9;472&#9;--sha-r&#9;C:\WINDOWS\U2FtaXIgQWhtYWQ\oZIQurK0kq1Qsqk.vbs<br>.<br><br>(((((((((((((((((((((((((((((   snapshot_2008-04-13_ 9.46.01.62   )))))))))))))))))))))))))))))))))))))))))<br>.<br>- 2008-04-13 14:39:50&#9;2,048&#9;--s-a-w&#9;C:\WINDOWS\bootstat.dat<br>+ 2008-04-13 22:51:02&#9;2,048&#9;--s-a-w&#9;C:\WINDOWS\bootstat.dat<br>+ 2008-04-13 15:49:43&#9;1,038,336&#9;----a-r&#9;C:\WINDOWS\Installer\{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}\Icon0E6AB9FC.exe<br>+ 2008-04-13 15:49:43&#9;178,688&#9;----a-r&#9;C:\WINDOWS\Installer\{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}\Icon0E6AB9FC1.exe<br>+ 2008-04-13 15:49:43&#9;171,008&#9;----a-r&#9;C:\WINDOWS\Installer\{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}\IconDED53B0B.exe<br>+ 2008-04-13 15:49:43&#9;8,704&#9;----a-r&#9;C:\WINDOWS\Installer\{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}\IconDED53B0B1.exe<br>+ 2008-04-13 18:23:33&#9;63,839&#9;----a-w&#9;C:\WINDOWS\system32\{12fdb189-6534-5715-5717-a9c2868b4931}.dll-uninst.exe<br>+ 2008-04-04 12:35:02&#9;329,728&#9;----a-w&#9;C:\WINDOWS\system32\{12fdb189-6534-5715-5717-a9c2868b4931}.dll<br>+ 2008-04-09 15:35:36&#9;8,278&#9;----a-w&#9;C:\WINDOWS\system32\axV\retmwav3.exe<br>+ 2008-04-02 12:32:16&#9;32,768&#9;----a-w&#9;C:\WINDOWS\system32\bharebio01\bharebio011065.exe<br>+ 2007-07-11 19:37:26&#9;6,272&#9;----a-w&#9;C:\WINDOWS\system32\drivers\AWRTPD.sys<br>+ 2007-08-07 18:58:08&#9;8,320&#9;----a-w&#9;C:\WINDOWS\system32\drivers\AWRTRD.sys<br>+ 2007-08-07 18:56:58&#9;9,344&#9;----a-w&#9;C:\WINDOWS\system32\drivers\NSDriver.sys<br>+ 2008-04-04 21:31:58&#9;126,976&#9;----a-w&#9;C:\WINDOWS\system32\IDE2\mdllcom2.exe<br>+ 2008-04-11 22:34:16&#9;400,987&#9;----a-w&#9;C:\WINDOWS\system32\iFi\prodll384.exe<br>+ 2007-12-14 17:32:52&#9;12,632&#9;----a-w&#9;C:\WINDOWS\system32\lsdelete.exe<br>+ 2008-02-14 14:42:16&#9;49,152&#9;----a-w&#9;C:\WINDOWS\system32\pinz1\cegmgr76.exe<br>+ 2008-04-13 22:51:26&#9;16,384&#9;----atw&#9;C:\WINDOWS\TEMP\Perflib_Perfdata_674.dat<br>.<br>(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br>.<br>*Note* empty entries & legit default entries are not shown <br>REGEDIT4<br><br>[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0E3BE2B4-9688-443D-BACD-DD267AA674AE}]<br>2008-03-16 10:27&#9;315472&#9;--a------&#9;C:\WINDOWS\system32\geeba.dll<br><br>[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{27BED0D7-0938-4700-9060-A436B69EB7BC}]<br>&#9;&#9;&#9;C:\Program Files\Common Files\horev4444.dll<br><br>[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9C3831AF-F271-4DB6-BB2C-DCD46F9BF462}]<br>&#9;&#9;&#9;C:\Program Files\MSN\comeqoc89104.dll<br><br>[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A67DA44A-58A5-4161-B77D-848247B6748C}]<br>&#9;&#9;&#9;C:\Program Files\Common Files\horev7.dll<br><br>[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A9457564-1FAB-4C4C-818D-417BA5F56D9C}]<br>&#9;&#9;&#9;C:\WINDOWS\system32\jkkli.dll<br><br>[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{DDBA5775-1351-4F21-881E-A4ADC9BEAB75}]<br>&#9;&#9;&#9;C:\Program Files\Common Files\horev83122.dll<br><br>[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{fed76bfd-a0ff-938f-507d-216c8ab86a74}]<br>2008-04-04 07:35&#9;329728&#9;--a------&#9;C:\WINDOWS\system32\{12fdb189-6534-5715-5717-a9c2868b4931}.dll<br><br>[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<br>"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2002-12-31 07:00 15360]<br>"Rusc"="C:\DOCUME~1\ADMINI~1\MYDOCU~1\MANTEC~1\msiexec.exe" [ ]<br>"Gzchx"="C:\Program Files\Common Files\??mantec\??xplore.exe" [ ]<br><br>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<br>"Athan"="C:\Program Files\Athan\Athan.exe" [2007-07-07 05:09 954368]<br>"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2006-10-30 09:36 256576]<br>"zBrowser Launcher"="C:\Program Files\Logitech\iTouch\iTouch.exe" [2004-03-18 08:33 892928]<br>"dmxvp.exe"="C:\WINDOWS\system32\dmxvp.exe" [ ]<br>"dmotx.exe"="C:\WINDOWS\system32\dmotx.exe" [ ]<br>"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [ ]<br>"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-10-22 12:22 7700480]<br>"nwiz"="nwiz.exe" [2006-10-22 12:22 1622016 C:\WINDOWS\system32\nwiz.exe]<br>"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-10-25 18:58 282624]<br>"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2006-10-22 12:22 86016]<br>"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]<br>"{E3-37-71-11-DW}"="c:\windows\system32\rwwnw64d.exe" [2008-04-13 17:52 49173]<br>"spa_start"="C:\WINDOWS\system32\{12fdb189-6534-5715-5717-a9c2868b4931}.dll" [2008-04-04 07:35 329728]<br>"g]eeV\mWhjlnspB"="C:\WINDOWS\system32\scntokdn.exe" [2008-04-13 17:53 196674]<br><br>C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\<br>Deewoo.lnk - C:\WINDOWS\system32\scntokdn.exe [2008-04-13 17:53:11 196674]<br>DW_Start.lnk - C:\WINDOWS\system32\rwwnw64d.exe [2008-04-13 17:52:58 49173]<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\efcccaa]<br>efcccaa.dll<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\iifefEUl]<br>iifefEUl.dll<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\opnklmk]<br>opnklmk.dll<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\rqrstqn]<br>rqrstqn.dll<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ssqrrpo]<br>ssqrrpo.dll<br><br>[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]<br>Authentication Packages&#9;REG_MULTI_SZ   &#9;msv1_0 C:\WINDOWS\system32\geeba.dll<br><br>[HKLM\~\startupfolder\C:^Documents and Settings^Administrator^Start Menu^Programs^Startup^Adobe Gamma.lnk]<br>path=C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\Adobe Gamma.lnk<br>backup=C:\WINDOWS\pss\Adobe Gamma.lnkStartup<br><br>[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]<br>path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk<br>backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Bffeeuso]<br>C:\Program Files\?ymantec\j?vaw.exe<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MemoryManager]<br>C:\WINDOWS\system32\qjjofwjh.dll<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]<br>--a------ 2006-10-22 12:22 1622016 C:\WINDOWS\system32\nwiz.exe<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\pbvmnemA]<br>C:\WINDOWS\pbvmnemA.exe<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]<br>--a------ 2006-10-25 18:58 282624 C:\Program Files\QuickTime\qttask.exe<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Suite]<br>-ra------ 2005-10-26 16:17 159744 C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WebBuying]<br>C:\Program Files\Web Buying\v1.8.0\webbuying.exe<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinPop]<br>C:\Program Files\WinPop\winpop.exe<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]<br>"diagent"="C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup<br>"zBrowser Launcher"=C:\Program Files\Logitech\iTouch\iTouch.exe<br>"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"<br>"nwiz"=nwiz.exe /install<br>"NeroFilterCheck"=C:\WINDOWS\system32\NeroCheck.exe<br>"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" -atboottime<br>"AVG7_CC"=C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\security center]<br>"AntiVirusDisableNotify"=dword:00000001<br>"UpdatesDisableNotify"=dword:00000001<br>"AntiVirusOverride"=dword:00000001<br>"FirewallOverride"=dword:00000001<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]<br>"DisableMonitoring"=dword:00000001<br><br>[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]<br>"EnableFirewall"= 0 (0x0)<br><br>[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]<br>"C:\\Program Files\\AIM\\aim.exe"=<br>"C:\\Program Files\\iTunes\\iTunes.exe"=<br>"C:\\Program Files\\uTorrent\\uTorrent.exe"=<br><br>R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-03-29 13:31]<br>R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-03-29 13:35]<br>R2 UxTuneUp;TuneUp Design Expansion;C:\WINDOWS\System32\svchost.exe [2002-12-31 07:00]<br>S2 ATIBTCAP;ATI TV Wonder Video Capture;C:\WINDOWS\system32\drivers\atibtcap.sys [2002-11-05 00:00]<br>S2 ATIBTXBAR;ATI TV Wonder Video Crossbar;C:\WINDOWS\system32\drivers\atibtxbr.sys [2002-11-05 00:00]<br>S2 ATIVTUTW;ATI TV Wonder TV Tuner;C:\WINDOWS\system32\drivers\ativtutw.sys [2002-11-05 00:00]<br>S2 ATIVXSTW;ATI TV Wonder Audio Crossbar;C:\WINDOWS\system32\drivers\ativxstw.sys [2002-11-05 00:00]<br>S3 LCcfltr;Logitech USB Filter Driver;C:\WINDOWS\system32\Drivers\LCcFltr.Sys [2004-03-03 08:50]<br>S3 UnlockerDriver4;UnlockerDriver4 Driver;C:\WINDOWS\system32\UnlockerDriver4.sys [2005-04-24 04:08]<br><br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost  - NetSvcs<br>UxTuneUp<br><br>.<br>Contents of the 'Scheduled Tasks' folder<br>"2008-04-11 22:15:00 C:\WINDOWS\Tasks\1-Click Maintenance.job"<br>- C:\Program Files\TuneUp Utilities 2007\SystemOptimizer.exe<br>"2008-04-10 03:44:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"<br>- C:\Program Files\Apple Software Update\SoftwareUpdate.exe<br>.<br>**************************************************************************<br><br>catchme 0.3.1351 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, &raquo;<A HREF="http://www.gmer.net" >www.gmer.net</A><br>Rootkit scan 2008-04-13 17:51:53<br>Windows 5.1.2600 Service Pack 2 NTFS<br><br>scanning hidden processes ... <br><br>scanning hidden autostart entries ...<br><br>scanning hidden files ... <br><br>C:\WINDOWS\system32\scntokdn.exe 196674 bytes executable<br>C:\WINDOWS\system32\winpfz33.sys 936 bytes<br>C:\WINDOWS\system32\msnav32.ax 148 bytes<br>C:\WINDOWS\system32\rwwnw64d.exe 49173 bytes executable<br>C:\WINDOWS\system32\g46.exe 400547 bytes executable<br>C:\WINDOWS\system32\zxdnt3d.cfg 21 bytes<br><br>scan completed successfully <br>hidden files: 6 <br><br>**************************************************************************<br><br>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\run]<br>"g]eeV\\mWhjlnspB"="C:\\WINDOWS\\system32\\scntokdn.exe DWram"<br>.<br>------------------------ Other Running Processes ------------------------<br>.<br>C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe<br>C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe<br>C:\Program Files\Alwil Software\Avast4\ashServ.exe<br>C:\WINDOWS\system32\scardsvr.exe<br>C:\WINDOWS\system32\nvsvc32.exe<br>C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe<br>C:\Program Files\iPod\bin\iPodService.exe<br>C:\Program Files\Internet Explorer\iexplore.exe<br>C:\WINDOWS\system32\rundll32.exe<br>.<br>**************************************************************************<br>.<br>Completion time: 2008-04-13 17:58:16 - machine was rebooted<br>ComboFix-quarantined-files.txt  2008-04-13 22:58:03<br>ComboFix2.txt  2008-04-13 15:21:30<br>ComboFix3.txt  2008-04-13 14:46:44<br>ComboFix4.txt  2008-04-12 03:35:17<br>ComboFix5.txt  2008-04-12 01:08:10<br>Pre-Run: 49,116,758,016 bytes free<br>Post-Run: 49,101,164,544 bytes free<br><br>---------------------<br>HJT<br>Logfile of Trend Micro HijackThis v2.0.2<br>Scan saved at 7:27:06 PM, on 4/14/2008<br>Platform: Windows XP SP2 (WinNT 5.01.2600)<br>MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)<br>Boot mode: Normal<br><br>Running processes:<br>C:\WINDOWS\System32\smss.exe<br>C:\WINDOWS\system32\winlogon.exe<br>C:\WINDOWS\system32\services.exe<br>C:\WINDOWS\system32\lsass.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe<br>C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe<br>C:\Program Files\Alwil Software\Avast4\ashServ.exe<br>C:\WINDOWS\Explorer.EXE<br>C:\WINDOWS\system32\spoolsv.exe<br>C:\WINDOWS\System32\SCardSvr.exe<br>C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe<br>C:\WINDOWS\system32\nvsvc32.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe<br>C:\WINDOWS\system32\wscntfy.exe<br>C:\Program Files\iTunes\iTunesHelper.exe<br>C:\Program Files\Logitech\iTouch\iTouch.exe<br>C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe<br>C:\WINDOWS\system32\ctfmon.exe<br>C:\Program Files\iPod\bin\iPodService.exe<br>C:\WINDOWS\system32\rundll32.exe<br>C:\WINDOWS\system32\taskmgr.exe<br>C:\WINDOWS\system32\rundll32.exe<br>C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=69157" >go.microsoft.com/fwlink/?LinkId=69157</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = &raquo;<A HREF="http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr7/*http://www.yahoo.com/ext/search/search.html" >us.rd.yahoo.com/customize/ie/def&middot;&middot;&middot;rch.html</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = &raquo;<A HREF="http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR" >g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR</A><br>R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 200.30.66.65:80<br>O4 - HKLM\..\Run: [Athan] C:\Program Files\Athan\Athan.exe<br>O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"<br>O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe<br>O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"<br>O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup<br>O4 - HKLM\..\Run: [nwiz] nwiz.exe /install<br>O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime<br>O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit<br>O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"<br>O4 - HKLM\..\Run: [spa_start] C:\WINDOWS\System32\Rundll32.exe "C:\WINDOWS\system32\{12fdb189-6534-5715-5717-a9c2868b4931}.dll" DllInit<br>O4 - HKLM\..\Run: [BMd7bd0422] Rundll32.exe "C:\WINDOWS\system32\mtyicqmn.dll",s<br>O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br>O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000<br>O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll<br>O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll<br>O9 - Extra button: ATI TV - {44226DFF-747E-4edc-B30C-78752E50CD0C} - C:\Program Files\ATI Multimedia\tv\EXPLBAR.DLL (file missing)<br>O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe<br>O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br>O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br>O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - &raquo;<A HREF="http://go.divx.com/plugin/DivXBrowserPlugin.cab" >go.divx.com/plugin/DivXBrowserPlugin.cab</A><br>O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe<br>O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe<br>O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe<br>O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe (file missing)<br>O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe<br>O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe<br>O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe<br>O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe<br>O23 - Service: Kaspersky Anti-Virus 6.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe<br>O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe<br>O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe<br>O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe<br><br>--<br>End of file - 5356 bytes<br>-------------------<br>sdfix<br><br><b>SDFix: Version 1.170 </b><br>Run by Administrator on Sun 04/13/2008 at 11:02 PM<br><br>Microsoft Windows XP [Version 5.1.2600]<br>Running From: C:\SDFix<br><br><b>Checking Services </b>:<br><br>Restoring Windows Registry Values<br>Restoring Windows Default Hosts File<br>Restoring Missing SharedAccess Service <br><br>Rebooting<br><br><b>Checking Files </b>: <br><br>Trojan Files Found:<br><br>C:\PROGRA~1\COMPLU~1\LADUPAJ - Deleted<br>C:\WINDOWS\system32\KBRunOnce2.t__ - Deleted<br>C:\WINDOWS\system32KBRunOnce2.tm_ - Deleted<br>C:\WINDOWS\system32KBRunOnce2.t__ - Deleted<br>C:\WINDOWS\system32\lich.dat  - Deleted<br>C:\WINDOWS\system32\msnav32.ax  - Deleted<br>C:\WINDOWS\system32\zxdnt3d.cfg  - Deleted<br>C:\WINDOWS\tcb.pmw  - Deleted<br>C:\WINDOWS\uninstall_nmon.vbs  - Deleted<br><br>Removing Temp Files<br><br><b>ADS Check </b>:<br> <br><br>                                 <b>Final Check </b>:<br><br>catchme 0.3.1351.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, &raquo;<A HREF="http://www.gmer.net" >www.gmer.net</A><br>Rootkit scan 2008-04-13 23:11:13<br>Windows 5.1.2600 Service Pack 2 NTFS<br><br>scanning hidden processes ...<br><br>scanning hidden services & system hive ...<br><br>scanning hidden registry entries ...<br><br>scanning hidden files ...<br><br>scan completed successfully<br>hidden processes: 0<br>hidden services: 0<br>hidden files: 0<br><br><b>Remaining Services </b>:<br><br>Authorized Application Key Export:<br><br>[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]<br>"C:\\Program Files\\AIM\\aim.exe"="C:\\Program Files\\AIM\\aim.exe:*:Enabled:AOL Instant Messenger"<br>"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"<br>"C:\\Program Files\\uTorrent\\uTorrent.exe"="C:\\Program Files\\uTorrent\\uTorrent.exe:*:Enabled:&micro;Torrent"<br>"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"<br><br>[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]<br>"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"<br><br><b>Remaining Files </b>:<br><br>File Backups: - C:\SDFix\backups\backups.zip<br><br><b>Files with Hidden Attributes </b>:<br><br>Tue 31 Dec 2002     1,694,208 ..SH. --- "C:\Program Files\Messenger\msmsgs.exe"<br>Tue 31 Dec 2002        60,416 A.SH. --- "C:\Program Files\Outlook Express\msimn.exe"<br>Tue 24 Jul 2007     1,845,858 A.SH. --- "C:\WINDOWS\system32\kjjlm.tmp"<br>Tue 24 Jul 2007         6,471 A.SH. --- "C:\WINDOWS\system32\kjjlm.bak1"<br>Tue 24 Jul 2007     1,807,725 A.SH. --- "C:\WINDOWS\system32\kjjlm.bak2"<br>Fri  9 Nov 2007       923,066 A.SH. --- "C:\WINDOWS\system32\ogvfofdn.tmp"<br>Wed 28 Sep 2005         4,348 ..SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"<br>Fri 26 Nov 2004        22,016 A..H. --- "C:\Documents and Settings\Administrator\My Documents\Typed Documents\~WRL0001.tmp"<br>Sat 25 Feb 2006        22,016 A..H. --- "C:\Documents and Settings\Administrator\My Documents\Typed Documents\~WRL0005.tmp"<br>Sat 25 Feb 2006        22,016 A..H. --- "C:\Documents and Settings\Administrator\My Documents\Typed Documents\~WRL2653.tmp"<br>Thu 16 Aug 2007             0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"<br>Mon 13 Nov 2006       319,456 A..H. --- "C:\Program Files\Common Files\Motorola Shared\MotPCSDrivers\difxapi.dll"<br>Sun  1 Sep 2002        45,056 A..H. --- "C:\Documents and Settings\Administrator\My Documents\xeo\Desktop\minibrowser_v1.0.dll"<br>Sun 10 Apr 2005        22,528 A..H. --- "C:\Documents and Settings\Administrator\My Documents\xeo\My Documents\Farhan's Documents\~WRL1675.tmp"<br>Thu  7 Apr 2005        21,504 A..H. --- "C:\Documents and Settings\Administrator\My Documents\xeo\My Documents\school\English\Research Paper\~WRL0291.tmp"<br><br><b>Finished!</b><br><br>----<br>wareout:<br>Username "Administrator" - 04/14/2008 14:24:06 [Fixwareout edited 9/01/2007]<br><br>~~~~~ Prerun check<br><br>HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{3E5BEC1F-998E-4766-A5ED-5CB6CFEF3B26}<br>"DhcpNameServer"="85.255.113.114,85.255.112.8" Value cleared.<br>HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{D8951C65-92EC-4161-9459-B755EB19927C}<br>"DhcpNameServer"="85.255.113.114,85.255.112.8" Value cleared.<br><br>Successfully flushed the DNS Resolver Cache.<br><br>System was rebooted successfully. <br> <br>~~~~~ Postrun check <br>HKLM\SOFTWARE\~\Winlogon\ "system"="" <br>....<br>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\_r "}FCF0F8737177-CBCB-56F4-4256-0D409B28{"  Deleted <br>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\_r "}A81021EEEA11-B2AA-0584-EF34-AA942AD1{"  Deleted <br>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\_r "elfmd"  Deleted <br>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\_r "}FDE62E469FBB-A1AB-5D44-A456-6E9D93DE{"  Deleted <br>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\_r "}11576FF2B5C3-3FDB-2734-E2BD-4F584BE8{"  Deleted <br>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\_r "}71BDEC5CBBF9-7EE8-F6D4-F690-0F38C327{"  Deleted <br>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\_r "}C17FA5D49981-A7F9-4974-34E8-4BDDF0EE{"  Deleted <br>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\_r "}461231CCCB50-2968-7954-02BB-035410ED{"  Deleted <br>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\_r "djxmd"  Deleted <br>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\_r "}996423FA06AA-11AA-2EC4-DD37-8FAA33CB{"  Deleted <br>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\_r "}EAAADD02793F-E6AA-43B4-0DEE-2D67489B{"  Deleted <br>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\_r "fpcmd"  Deleted <br>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\_r "}8CBA0B891534-8AC8-A814-E12F-FA0FED00{"  Deleted <br>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\_r "}EBC911BEBB5A-09DB-1BD4-5530-490DCDCF{"  Deleted <br>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\_r "}3F1E1AA224F1-2308-3864-B546-23D505B2{"  Deleted <br>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\_r "}0E0D4AD0CD77-059A-A084-4269-E0A2A644{"  Deleted <br>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\_r "pvxmd"  Deleted <br>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\_r "ugcmd"  Deleted <br>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\_r "xtomd"  Deleted <br>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\_r "ztvmd"  Deleted <br>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\_r "zfimd"  Deleted <br>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion "dmfle.exe"  Value deleted <br>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion "dmcpf.exe"  Value deleted <br>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion "dmcgu.exe"  Value deleted <br>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion "dmvtz.exe"  Value deleted <br>....<br>~~~~~ Misc files. <br>C:\WINDOWS\system32\{12fdb189-6534-5715-5717-a9c2868b4931}.dll-uninst.exe Deleted<br>C:\WINDOWS\system32\{12fdb189-6534-5715-5717-a9c2868b4931}.dll Deleted<br>....<br>~~~~~ Checking for older varients.<br>....<br><br>~~~~~ Current runs (hklm hkcu "run" Keys Only)<br>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\run]<br>"Athan"="C:\\Program Files\\Athan\\Athan.exe"<br>"iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""<br>"zBrowser Launcher"="C:\\Program Files\\Logitech\\iTouch\\iTouch.exe"<br>"WinampAgent"="\"C:\\Program Files\\Winamp\\winampa.exe\""<br>"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup"<br>"nwiz"="nwiz.exe /install"<br>"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"<br>"NvMediaCenter"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvMcTray.dll,NvTaskbarInit"<br>"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.6.0_05\\bin\\jusched.exe\""<br>"!AVG Anti-Spyware"="\"C:\\Program Files\\Grisoft\\AVG Anti-Spyware 7.5\\avgas.exe\" /minimized"<br>"spa_start"="C:\\WINDOWS\\System32\\Rundll32.exe \"C:\\WINDOWS\\system32\\{12fdb189-6534-5715-5717-a9c2868b4931}.dll\" DllInit"<br><br>[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<br>"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"<br>....<br>Hosts file was reset, If you use a custom hosts file please replace it...<br>~~~~~ End report ~~~~~<br><br>should i send mbam to my computer and try using it now or what?i really need my computer back up and running like tommrow or so, please if you can work with me to figure this out as quickly as possible, i will appreciate it moreeee than ever.<br>edit: im going to go now use mbam and then post the log.<br><br>/////////////////////////////////<br>MBAM ADDED<br><br>Malwarebytes' Anti-Malware 1.11<br>Database version: 599<br><br>Scan type: Quick Scan<br>Objects scanned: 29306<br>Time elapsed: 9 minute(s), 52 second(s)<br><br>Memory Processes Infected: 0<br>Memory Modules Infected: 2<br>Registry Keys Infected: 22<br>Registry Values Infected: 4<br>Registry Data Items Infected: 2<br>Folders Infected: 2<br>Files Infected: 18<br><br>Memory Processes Infected:<br>(No malicious items detected)<br><br>Memory Modules Infected:<br>C:\WINDOWS\system32\geeba.dll (Trojan.Vundo) -> Unloaded module successfully.<br>C:\WINDOWS\system32\nkqtkmpa.dll (Trojan.Vundo) -> Unloaded module successfully.<br><br>Registry Keys Infected:<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{58448347-2553-452e-8e97-e8e4b5120e01} (Trojan.Vundo) -> Quarantined and deleted successfully.<br>HKEY_CLASSES_ROOT\CLSID\{58448347-2553-452e-8e97-e8e4b5120e01} (Trojan.Vundo) -> Delete on reboot.<br>HKEY_CLASSES_ROOT\minibugtransporter.minibugtransporterx (Adware.Minibug) -> Quarantined and deleted successfully.<br>HKEY_CLASSES_ROOT\minibugtransporter.minibugtransporterx.1 (Adware.Minibug) -> Quarantined and deleted successfully.<br>HKEY_CLASSES_ROOT\CLSID\{2b96d5cc-c5b5-49a5-a69d-cc0a30f9028c} (Adware.Minibug) -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MiniBugTransporter.MiniBugTransporterX (Adware.Minibug) -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MiniBugTransporter.MiniBugTransporterX.1 (Adware.Minibug) -> Quarantined and deleted successfully.<br>HKEY_CURRENT_USER\Software\Trymedia Systems (Adware.Trymedia) -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\aoprndtws (Malware.Trace) -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\jkwslist (Malware.Trace) -> Quarantined and deleted successfully.<br>HKEY_CURRENT_USER\Software\Microsoft\aldd (Malware.Trace) -> Delete on reboot.<br>HKEY_CURRENT_USER\Software\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully.<br>HKEY_CURRENT_USER\Software\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully.<br>HKEY_CURRENT_USER\Software\Microsoft\affltid (Malware.Trace) -> Quarantined and deleted successfully.<br>HKEY_CURRENT_USER\Software\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affltid (Malware.Trace) -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Juan (Trojan.Vundo) -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> Quarantined and deleted successfully.<br>HKEY_CURRENT_USER\Software\Microsoft\DomainService (Trojan.Agent) -> Quarantined and deleted successfully.<br><br>Registry Values Infected:<br>HKEY_CURRENT_USER\Software\Mozilla\Firefox\Extensions\{59a40ac9-e67d-4155-b31d-4b7330fcd2d6} (Adware.PurityScan) -> Quarantined and deleted successfully.<br>HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{4e7bd74f-2b8d-469e-86bd-fd60bb9aae3a} (Adware.OneToolBar) -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\spa_start (Adware.Agent) -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\BMd7bd0422 (Trojan.Agent) -> Delete on reboot.<br><br>Registry Data Items Infected:<br>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Authentication Packages (Trojan.Vundo) -> Data: c:\windows\system32\geeba.dll -> Delete on reboot.<br>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Authentication Packages (Trojan.Vundo) -> Data: c:\windows\system32\geeba.dll  -> Delete on reboot.<br><br>Folders Infected:<br>C:\Documents and Settings\All Users\Application Data\Rabio\Search Enhancer (Adware.SearchEnhancer) -> Quarantined and deleted successfully.<br>C:\Documents and Settings\All Users\Application Data\Rabio (Adware.Rabio) -> Quarantined and deleted successfully.<br><br>Files Infected:<br>C:\WINDOWS\system32\geeba.dll (Trojan.Vundo) -> Delete on reboot.<br>C:\WINDOWS\system32\abeeg.ini (Trojan.Vundo) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\abeeg.ini2 (Trojan.Vundo) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\nkqtkmpa.dll (Trojan.Vundo) -> Delete on reboot.<br>C:\WINDOWS\system32\apmktqkn.ini (Trojan.Vundo) -> Delete on reboot.<br>C:\WINDOWS\system32\rggodyor.dll (Trojan.Vundo) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\roydoggr.ini (Trojan.Vundo) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\rundll32.exe (Adware.Agent) -> Delete on reboot.<br>C:\WINDOWS\system32\mtyicqmn.dll (Trojan.Agent) -> Delete on reboot.<br>C:\WINDOWS\inf\ultra.PNF (Malware.Trace) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\fuamfu32.ini (Malware.Trace) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\ClickToFindandFixErrors_RON.ico (Malware.Trace) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\ClickToFindandFixErrors_US.ico (Malware.Trace) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\iefpmod.dll (Malware.Trace) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\qshl.dll (Malware.Trace) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\ierql.dll (Malware.Trace) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\iehrdata.dll (Malware.Trace) -> Quarantined and deleted successfully.<br>C:\WINDOWS\system32\ielog.dll (Malware.Trace) -> Quarantined and deleted successfully.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20334039</guid>
<pubDate>Mon, 14 Apr 2008 19:30:30 EDT</pubDate>
</item>

<item>
<title>Re: [HJT Log] Slowdown + Can&#x27;t go on websites</title>
<link>http://www.dslreports.com/forum/remark,20333983</link>
<description><![CDATA[<A HREF="/useremail/u/637965"><b>halfHAVOC</b></A> : i didn't get to mbam yet<br><br>but lemme go do the rest the logs]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20333983</guid>
<pubDate>Mon, 14 Apr 2008 19:20:13 EDT</pubDate>
</item>

<item>
<title>Re: [HJT Log] Slowdown + Can&#x27;t go on websites</title>
<link>http://www.dslreports.com/forum/remark,20333421</link>
<description><![CDATA[<A HREF="/useremail/u/693977"><b>bcastner</b></A> : If you completed the scan asked, please submit the logs requested:  from FixWareout, Combofix, and <b>MBAM</b>, as well as a new HijackThis.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20333421</guid>
<pubDate>Mon, 14 Apr 2008 17:36:24 EDT</pubDate>
</item>

<item>
<title>Re: [HJT Log] Slowdown + Can&#x27;t go on websites</title>
<link>http://www.dslreports.com/forum/remark,20332430</link>
<description><![CDATA[<A HREF="/useremail/u/637965"><b>halfHAVOC</b></A> : hm well i sent it through my network on a shared folder(couln't find floppy/pin) and it worked<br><br>but <br><br>my internet is still not working. also that red security balloon in the tray area is still there.<br><br>i really needdd to get this fixed asap!]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20332430</guid>
<pubDate>Mon, 14 Apr 2008 14:32:26 EDT</pubDate>
</item>

<item>
<title>Re: [HJT Log] Slowdown + Can&#x27;t go on websites</title>
<link>http://www.dslreports.com/forum/remark,20331175</link>
<description><![CDATA[<A HREF="/useremail/u/693977"><b>bcastner</b></A> : Your internet issues are related to the Wareout infection.  Download the following and bring it by floppy or USB pen drive to the problem computer:<br><br>1. <b>Wareout Removal</b><br>Please download <b>FixWareout</b> from one of these sites: <br><textarea name="code" class="text" cols=50 rows=10>http://downloads.subratam.org/Fixwareout.exe &#012;http://www.bleepingcomputer.com/files/lonny/Fixwareout.exe &#012;</textarea><!--end code block--><br>Save it to your desktop and run it. Click Next, then Install, then make sure  <b>"Run fixit"</b> is checked and click Finish. The fix will begin; follow the prompts. You will be asked to reboot your computer; please do so. Your system may take longer than usual to load; this is normal. <br><br>At the end of the fix, you may need to restart your computer again. <br>Notepad will open with the results of your FixWareout scan.  Please save this file (<b>C:\Report.txt</b>) and exit Notepad.<br><br>Then continue where you left off in my original instructions.<br><br><small>--<br><b>============</b><br><b>MS-MVP 2004 - -2008, ASAP Member</b><br><b><i>Users Helping Users</i></b><br><br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20331175</guid>
<pubDate>Mon, 14 Apr 2008 10:44:29 EDT</pubDate>
</item>

<item>
<title>Re: [HJT Log] Slowdown + Can&#x27;t go on websites</title>
<link>http://www.dslreports.com/forum/remark,20329724</link>
<description><![CDATA[<A HREF="/useremail/u/637965"><b>halfHAVOC</b></A> : dude ahhh after the sdfix step<br><br>my internet isn't working so i can't download combofix and move on!!!!!!!<br><br>what do i do!?? im posting from another pc in my house right now.<br><br>should i download it on here and send it thru the network or somethin?<br><br>oh also, i get this red balloon in the traybar saying your computer may be at risk. and when i did the hijackthis , some of the stuff u posted was not there like all the O2's and few one or two other ones were just not there..... please help ASAP!!]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20329724</guid>
<pubDate>Sun, 13 Apr 2008 23:27:29 EDT</pubDate>
</item>

<item>
<title>Re: [HJT Log] Slowdown + Can&#x27;t go on websites</title>
<link>http://www.dslreports.com/forum/remark,20329079</link>
<description><![CDATA[<A HREF="/useremail/u/693977"><b>bcastner</b></A> : You have a ton of problems.  One is a Wareout infection we will deal with in the next session.  Lets get the rest of the junk pretty much out of the way first.<br><br>TeaTimer is an excellent tool for the prevention of spyware but it can sometimes prevent HijackThis from fixing certain things. Please disable TeaTimer for now until you are clean. TeaTimer can be re-activated once your HijackThis log is clean.<br>&#8226; Open Spybot Search & Destroy.<br>&#8226; In the Mode menu click "Advanced mode" if not already selected.<br>&#8226; Choose Yes at the Warning prompt.<br>&#8226; Expand the Tools menu.<br>&#8226; Click Resident.<br>&#8226; <b>Uncheck</b> the Resident "TeaTimer" (Protection of overall system settings) active. box.<br>&#8226; In the File menu click Exit to exit Spybot Search & Destroy.<br>&#8226; Download and Unzip to your Desktop:  &raquo;<A HREF="http://www.techsupportforum.com/sectools/ResetTeaTimer.zip" >www.techsupportforum.com/sectool&middot;&middot;&middot;imer.zip</A><br>&#8226; Double click <b>ResetTeaTimer.bat</b> to remove all entries set by TeaTimer.<br><br><b><u>First Steps</u></b><br><b>:!: The following instructions are <u>only</u> for this Forum member. Please do not use these instructions on another computer system. You can seriously damage your system by following the instructions below without guided assistance. You assuredly will make a cleanup of your system more difficult.</b><br><br>Please download<b>  <i>ATF Cleaner</i></b> <br><textarea name="code" class="text" cols=50 rows=10>http://www.atribune.org/ccount/click.php?id=1&#012;</textarea><!--end code block-->It does not require any installation.. It is set up to clean Windows TEMP folders, as well as IE, FireFox and Opera, Temporary Internet Files and Cookies.<br>&#8226;      Double-click <b>ATF-Cleaner.exe</b> to run the program. <br><br><b>First Step:</b><br>&#8226;      Under <b>Main</b> choose: <b>Select All</b><br>&#8226;      Click the <b>Empty Selected</b> button. <br><b><u>Next, if you use Firefox (and <i>some</i> Mozilla-based browsers)</u></b> <br>&#8226;      Click Firefox at the top and choose: <b>Select All</b><br>&#8226;      Click the <b>Empty Selected</b> button. <b><u><br>Next, if you use the Opera browser</u></b> <br>&#8226;      Click <b>Opera</b> at the top and choose: <b>Select All</b> <br>&#8226;      Click the <b>Empty Selected</b> button. <b>:!: Click Exit on the Main menu to close the program.</b><br><br><b>Reconfigure Windows XP to show hidden files:</b><br><i>To enable the viewing of Hidden files follow these steps: </i><br>&#8226; Close all programs so that you are at your desktop. <br>&#8226; Double-click on the My Computer icon. <br>&#8226; Select the Tools menu and click Folder Options. <br>&#8226; After the new window appears select the View tab. <br>&#8226; Put a checkmark in the checkbox labeled Display the contents of system folders. <br>&#8226; Under the Hidden files and folders section select the radio button labeled Show hidden files and folders. <br>&#8226; Remove the checkmark from the checkbox labeled Hide file extensions for known file types. <br>&#8226; Remove the checkmark from the checkbox labeled Hide protected operating system files. <br>&#8226; Press the Apply button and then the OK button and exit My Computer. <br>&#8226; Now your computer is configured to show all hidden files. <br><br><b><u>Malware Removal Steps</u></b><br><br>1. Open <b>HijackThis</b> again, System scan only.  <b>Checkmark</b> these items:<br><br><b>O2 - BHO: {644a70f8-a1f8-8dba-1044-b36ed7429852} - {2589247d-e63b-4401-abd8-8f1a8f07a446} - C:\WINDOWS\system32\vhkdgtkp.dll<br>O2 - BHO: (no name) - {27BED0D7-0938-4700-9060-A436B69EB7BC} - C:\Program Files\Common Files\horev4444.dll (file missing)<br>O2 - BHO: (no name) - {9C3831AF-F271-4DB6-BB2C-DCD46F9BF462} - C:\Program Files\MSN\comeqoc89104.dll (file missing)<br>O2 - BHO: (no name) - {A67DA44A-58A5-4161-B77D-848247B6748C} - C:\Program Files\Common Files\horev7.dll (file missing)<br>O2 - BHO: (no name) - {A9457564-1FAB-4C4C-818D-417BA5F56D9C} - C:\WINDOWS\system32\jkkli.dll (file missing)<br>O2 - BHO: (no name) - {D4FF871C-5791-47D0-B8CC-20AE3D0801FA} - C:\WINDOWS\system32\geeba.dll<br>O2 - BHO: (no name) - {DDBA5775-1351-4F21-881E-A4ADC9BEAB75} - C:\Program Files\Common Files\horev83122.dll (file missing)<br>O2 - BHO: nextads browser optimizer - {fed76bfd-a0ff-938f-507d-216c8ab86a74} - C:\WINDOWS\system32\{12fdb189-6534-5715-5717-a9c2868b4931}.dll<br>O3 - Toolbar: (no name) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - (no file)<br>O4 - HKLM\..\Run: [dmxvp.exe] C:\WINDOWS\system32\dmxvp.exe<br>O4 - HKLM\..\Run: [dmotx.exe] C:\WINDOWS\system32\dmotx.exe<br>O4 - HKLM\..\Run: [d48e37be] rundll32.exe "C:\WINDOWS\system32\rggodyor.dll",b<br>O4 - HKLM\..\Run: [spa_start] C:\WINDOWS\System32\Rundll32.exe "C:\WINDOWS\system32\{12fdb189-6534-5715-5717-a9c2868b4931}.dll" DllInit<br>O4 - HKLM\..\Run: [BMd7bd0422] Rundll32.exe "C:\WINDOWS\system32\fmxmufxp.dll",s<br>O4 - HKCU\..\Run: [Rusc] "C:\DOCUME~1\ADMINI~1\MYDOCU~1\MANTEC~1\msiexec.exe" -vt yazb<br>O4 - HKCU\..\Run: [Gzchx] "C:\Program Files\Common Files\??mantec\??xplore.exe"<br>O8 - Extra context menu item: Add to Windows &Live Favorites - &raquo;favorites.live.com/quickadd.aspx<br>O17 - HKLM\System\CCS\Services\Tcpip\..\{D8951C65-92EC-4161-9459-B755EB19927C}: NameServer = 85.255.113.114,85.255.112.8<br>O17 - HKLM\System\CCS\Services\Tcpip\..\{ED2FEFA9-FFF5-4140-B90D-060BC9431E7E}: NameServer = 85.255.113.114,85.255.112.8<br>O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.113.114 85.255.112.8<br>O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.113.114 85.255.112.8<br>O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.113.114 85.255.112.8<br>O20 - Winlogon Notify: efcccaa - efcccaa.dll (file missing)<br>O20 - Winlogon Notify: iifefEUl - iifefEUl.dll (file missing)<br>O20 - Winlogon Notify: opnklmk - opnklmk.dll (file missing)<br>O20 - Winlogon Notify: rqrstqn - rqrstqn.dll (file missing)<br>O20 - Winlogon Notify: ssqrrpo - ssqrrpo.dll (file missing)<br>O21 - SSODL: MvpPwwv - {D48E3712-7E24-9DB8-DFA3-50C4B3DD1E5B} - (no file)</b><br><br>Click "<b>Fix checked</b>" and when the log panel clears exit HijackThis.<br><br>2. Download <b>SDFix</b> and save it to your Desktop.<br><textarea name="code" class="text" cols=50 rows=10>http://downloads.andymanchesta.com/RemovalTools/SDFix.exe&#012;</textarea><!--end code block--><br>Double click<b>SDFix.exe</b> and it will extract the files to  the Windows Directory,  <b>C:\SDFix</b>. <br><br>Please then reboot your computer in <b><i>Safe Mode</i></b> by doing the following :<br>&#8226; Restart your computer <br>&#8226; After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually; <br>&#8226; Instead of Windows loading as normal, the Advanced Options Menu should appear; <br>&#8226; Select the first option, to run Windows in Safe Mode, then press [Enter]. <br>&#8226; Choose your usual account. <br>&#8226;  Open the extracted SDFix folder and double click <b>RunThis.ba</b> to start the script. <br>&#8226;  Type <b>Y[</b> to begin the cleanup process. <br>&#8226;  It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot. <br>&#8226;  Press any Key and it will restart the PC. <br>&#8226;  When the PC restarts the Fixtool will run again and complete the removal process then display <b>]Finished</b>, press any key to end the script and load your desktop icons. <br>&#8226;  Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as <b>Report.txt</b> <br>(Report.txt will also be copied to Clipboard ready for posting back on the forum). <br>&#8226;  For now, simply close Notepad.<br><br>3. Download and Run  -- <b>ComboFix&copy; </b> <br>Download this file <b><u>-- to your Desktop --</u></b> from any of these sources:  <br><textarea name="code" class="text" cols=50 rows=10>http://download.bleepingcomputer.com/sUBs/ComboFix.exe&#012;http://www.forospyware.com/sUBs/ComboFix.exe&#012;http://subs.geekstogo.com/ComboFix.exe&#012;</textarea><!--end code block--><br>&#8226; Disconnect from the Internet.<br>&#8226; Disable  your Antivirus  software -- this includes any Script Blocking Feature it may have.<br><br><b>Important:  Have no other programs running.  Your Task Bar should be clear of any program entries including your Browser.</b><br>&#8226; A window will open with a warning.  Accept any disclaimers to start the fix. When the scan completes Notepad will open with with your results log open. Do a File, Exit and answer 'Yes' to save changes.<br>A caution - Do <b>not</b> run Combofix more than once. Do not touch your mouse/keyboard until the scan has completed, as this may cause the process to stall or your computer to lock.<br><br>4. Please download MalwareBytes Anti-malware (MBAM) from one of the following links:<br><textarea name="code" class="text" cols=50 rows=10>http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html&#012;http://www.besttechie.net/tools/mbam-setup.exe&#012;</textarea><!--end code block--><br>Once downloaded, close all programs and Windows on your computer (including this one.)<br><br>Double-click on the icon on your desktop named Download_mbam-setup.exe. This will start the installation of MBAM onto your computer.<br><br>When the installation begins, keep following the prompts in order to continue with the installation process. Do not make any changes to default settings and when the program has finished installing, make sure you leave both the Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware checked. Then click on the Finish button.<br><br>MBAM will now automatically start and you will see a message stating that you should update the program before performing a scan. As MBAM will automatically update itself after the install, you can press the OK button to close that box and you will now be at the main program.<br><br>On the <b>Scanner tab</b>, make sure the the <b>Perform quick scan</b> option is selected and then click on the <b>Scan</b> button to start scanning your computer.<br><br>MBAM will now start scanning your computer for malware. This process can take quite a while, so we suggest you go and do something else and periodically check on the status of the scan. <br><br>When the scan is finished a message box will appear that it has completed scanning successfully.  Click <b>OK</b>.  Now click <b>Show Results</b>.  Make sure all entries have a checkmark at their far left.  You should now click on the <b>Remove Selected</b> button to remove all the listed malware. MBAM will now delete all of the files and registry keys and add them to the programs quarantine.<br><br>When MBAM has finished removing the malware, it will open the scan log and display it in Notepad. Review the log as desired, and then close the Notepad window.  Remember where you saved the log file, as we will want to see it later.<br><br>5. Run <b>HijackThis</b> again, and save the log file.<br><br><b><i>Submit to the Forum:</i></b><br>&#8226; The contents of C:\SDFix\Report.txt;<br>&#8226; The <b>MBAM</b> log results;<br>&#8226; The contents of C:\Combofix.txt;<br>&#8226; The new HijackThis log.<br><br><small>--<br><b>============</b><br><b>MS-MVP 2004 - -2008, ASAP Member</b><br><b><i>Users Helping Users</i></b><br><br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20329079</guid>
<pubDate>Sun, 13 Apr 2008 21:15:10 EDT</pubDate>
</item>

<item>
<title>[HJT Log] Slowdown + Can&#x27;t go on websites</title>
<link>http://www.dslreports.com/forum/remark,20328922</link>
<description><![CDATA[<A HREF="/useremail/u/637965"><b>halfHAVOC</b></A> : alright so lemme explain the problem. just started happening and what happens is the computer slows down a lil bit, i ran all those programs and its moreso back to normal with that, but my Taskbar keeps crashing. Ok main problem is when i go on Firefox and it goes to my homepage (google) i can't go on anything, i type in anywebsite and it jus gets stuck loading halfway but the screen stays white. so thats not working, so im using internet explorer right now and the problem is i can't type in anything in the address bar to get to a website, the only way it works is by typing it in google and clicking on the website (like i typed dslreports in google to get here). oh btw i get some popups occasionaly in IE as well.<br><br>ive tried using combofix(helped alot like i would use it restart my pc and then firefox and all would work and then suddenly i type any site and it just stops), vundofix(nothing), spybot (vario off the top of my head), ad-aware(which picked up 63 spyware/malwares and tracking stuff) i used avast as well but didn't get much help cept like two deletions. <br><br>Log:<br><br>Logfile of Trend Micro HijackThis v2.0.2<br>Scan saved at 8:38:14