Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: Vista: Error cannot find dll32  (Read 8554 times)

0 Members and 1 Guest are viewing this topic.

Karpos

    Topic Starter


    Rookie

    Vista: Error cannot find dll32
    « on: August 17, 2010, 01:43:50 PM »
    I am working on a Windows Vista machine which, on startup, gives "Error cannot find dll32".  I am very experienced when it comes to software and getting around on a computer, but novice when it comes to fixing problems with operations.  Working with this computer, I have been having little things here and there go wrong.  This is a computer that originally belonged to my son, from which I tried to remove as many excess programs, etc. before fixing up for my husband to use.   In the process, I discovered some other problems, for instance when I was trying to install a new wireless printer I could not. And there have been other glitches besides the startup error dll32 message here and there.

    I read through your Computer Hope page about Virus and Spyware guidelines and followed all the steps listed there. 

    A.  I have been running AVG Free antivirus from the beginning on this computer, and it is active and up to date. 

    B.  I am running Vista firewall.
     
    1.  I did the remove programs and found starware was included in the list.  So I removed that. 

    2.  I installed and ran the CCleanerSlim and cleaned all the cookies, as well as other items.

    3.  I instaled and ran the SUPERAntiSpyware which found no spyware on the machine.

    4.  I installed and ran MBAM which detected 28 infections, including 3 reg keys and 1 reg value, and quarantined and deleted them. 

    5.  I updated the very old version of Java.  I removed old versions of Java and ran CCleaner again. 

    6.  I installed and ran HiJackThis as explained.

    Here are my MBAM and HIJackThis logs:

    MBAM...
    Malwarebytes' Anti-Malware 1.46
    www.malwarebytes.org

    Database version: 4440

    Windows 6.0.6000
    Internet Explorer 7.0.6000.16809

    8/17/2010 12:57:27 PM
    mbam-log-2010-08-17 (12-57-27).txt

    Scan type: Quick scan
    Objects scanned: 132681
    Time elapsed: 11 minute(s), 46 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 3
    Registry Values Infected: 1
    Registry Data Items Infected: 0
    Folders Infected: 4
    Files Infected: 20

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{1962c5bc-e475-465b-823b-133e711bceb9} (Adware.Starware) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5f90c0e3-4c0a-4d54-a8ac-5afe6163a99e} (Adware.Starware) -> Quarantined and deleted successfully.

    Registry Values Infected:
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\dll (Trojan.Agent) -> Quarantined and deleted successfully.

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    C:\ProgramData\Starware322 (Adware.Starware) -> Quarantined and deleted successfully.
    C:\ProgramData\Starware322\buttons (Adware.Starware) -> Quarantined and deleted successfully.
    C:\ProgramData\Starware322\contexts (Adware.Starware) -> Quarantined and deleted successfully.
    C:\ProgramData\Starware322\images (Adware.Starware) -> Quarantined and deleted successfully.

    Files Infected:
    C:\ProgramData\Starware322\buttons\FindIt.bmp (Adware.Starware) -> Quarantined and deleted successfully.
    C:\ProgramData\Starware322\buttons\FindItHot.bmp (Adware.Starware) -> Quarantined and deleted successfully.
    C:\ProgramData\Starware322\buttons\findithotxp.png (Adware.Starware) -> Quarantined and deleted successfully.
    C:\ProgramData\Starware322\buttons\finditxp.png (Adware.Starware) -> Quarantined and deleted successfully.
    C:\ProgramData\Starware322\buttons\logo.bmp (Adware.Starware) -> Quarantined and deleted successfully.
    C:\ProgramData\Starware322\buttons\logoxp.bmp (Adware.Starware) -> Quarantined and deleted successfully.
    C:\ProgramData\Starware322\buttons\Reference.bmp (Adware.Starware) -> Quarantined and deleted successfully.
    C:\ProgramData\Starware322\buttons\ReferenceHot.bmp (Adware.Starware) -> Quarantined and deleted successfully.
    C:\ProgramData\Starware322\buttons\referencehotxp.png (Adware.Starware) -> Quarantined and deleted successfully.
    C:\ProgramData\Starware322\buttons\referencexp.png (Adware.Starware) -> Quarantined and deleted successfully.
    C:\ProgramData\Starware322\buttons\Weather.bmp (Adware.Starware) -> Quarantined and deleted successfully.
    C:\ProgramData\Starware322\buttons\WeatherHot.bmp (Adware.Starware) -> Quarantined and deleted successfully.
    C:\ProgramData\Starware322\buttons\weatherhotxp.png (Adware.Starware) -> Quarantined and deleted successfully.
    C:\ProgramData\Starware322\buttons\weatherxp.png (Adware.Starware) -> Quarantined and deleted successfully.
    C:\ProgramData\Starware322\contexts\error.xml (Adware.Starware) -> Quarantined and deleted successfully.
    C:\ProgramData\Starware322\contexts\related.xml (Adware.Starware) -> Quarantined and deleted successfully.
    C:\ProgramData\Starware322\contexts\travel.xml (Adware.Starware) -> Quarantined and deleted successfully.
    C:\ProgramData\Starware322\images\walertXP.bmp (Adware.Starware) -> Quarantined and deleted successfully.
    C:\Windows\msmark2.dat (Worm.KoobFace) -> Quarantined and deleted successfully.
    C:\Windows\t55ft2810f44.dat (Worm.KoobFace) -> Quarantined and deleted successfully.


    HiJackThis...

    Logfile of Trend Micro HijackThis v2.0.4
    Scan saved at 2:41:00 PM, on 8/17/2010
    Platform: Windows Vista  (WinNT 6.00.1904)
    MSIE: Internet Explorer v7.00 (7.00.6000.16809)
    Boot mode: Normal

    Running processes:
    C:\Windows\system32\taskeng.exe
    C:\Program Files\Winamp Remote\bin\OrbTray.exe
    C:\Windows\system32\taskeng.exe
    C:\Windows\system32\Dwm.exe
    C:\Windows\System32\igfxtray.exe
    C:\Windows\System32\hkcmd.exe
    C:\Windows\System32\igfxpers.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files\Windows Defender\MSASCui.exe
    C:\Program Files\Winamp Remote\bin\Orb.exe
    C:\Windows\RtHDVCpl.exe
    C:\Program Files\ltmoh\ltmoh.exe
    C:\Program Files\Toshiba\Power Saver\TPwrMain.exe
    C:\Program Files\Toshiba\SmoothView\SmoothView.exe
    C:\Program Files\Toshiba\FlashCards\TCrdMain.exe
    C:\Program Files\Toshiba\ConfigFree\NDSTray.exe
    C:\Program Files\Synaptics\SynTP\SynToshiba.exe
    C:\Program Files\Toshiba\Utilities\KeNotify.exe
    C:\Toshiba\IVP\ISM\pinger.exe
    C:\Program Files\Winamp\winampa.exe
    C:\Program Files\AVG\AVG8\avgtray.exe
    C:\Program Files\QuickTime\QTTask.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Program Files\Epson Software\Event Manager\EEventManager.exe
    C:\Program Files\Epson Software\FAX Utility\FUFAXSTM.exe
    C:\Program Files\Toshiba\TOSCDSPD\TOSCDSPD.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\Windows\ehome\ehtray.exe
    C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    C:\Program Files\Kodak\Kodak EasyShare Software\bin\EasyShare.exe
    C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe
    C:\Program Files\Palm\HOTSYNC.EXE
    C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
    C:\Windows\ehome\ehmsas.exe
    C:\Program Files\Toshiba\ConfigFree\CFSwMgr.exe
    C:\Windows\explorer.exe
    C:\Windows\system32\wuauclt.exe
    C:\Program Files\Common Files\Java\Java Update\jusched.exe
    C:\Program Files\Internet Explorer\ieuser.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe
    C:\Program Files\Trend Micro\HiJackThis\sniper.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.toshibadirect.com/dpdstart
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=localhost:7171
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local;<local>
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
    R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
    O1 - Hosts: ::1 localhost
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.5126.1836\swg.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
    O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
    O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
    O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
    O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
    O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe
    O4 - HKLM\..\Run: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
    O4 - HKLM\..\Run: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON.exe
    O4 - HKLM\..\Run: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
    O4 - HKLM\..\Run: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
    O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
    O4 - HKLM\..\Run: [HWSetup] C:\Program Files\TOSHIBA\Utilities\HWSetup.exe hwSetUP
    O4 - HKLM\..\Run: [SVPWUTIL] C:\Program Files\TOSHIBA\Utilities\SVPWUTIL.exe SVPwUTIL
    O4 - HKLM\..\Run: [KeNotify] C:\Program Files\TOSHIBA\Utilities\KeNotify.exe
    O4 - HKLM\..\Run: [PINGER] C:\TOSHIBA\IVP\ISM\pinger.exe /run
    O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
    O4 - HKLM\..\Run: [Performance Center] C:\Program Files\Ascentive\Performance Center\APCMain.exe -m
    O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
    O4 - HKLM\..\Run: [EEventManager] C:\PROGRA~1\EPSONS~1\EVENTM~1\EEventManager.exe
    O4 - HKLM\..\Run: [FUFAXSTM] "C:\Program Files\Epson Software\FAX Utility\FUFAXSTM.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
    O4 - HKCU\..\Run: [TOSCDSPD] TOSCDSPD.EXE
    O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_0
    O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
    O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
    O4 - HKCU\..\Run: [EPSON WorkForce 610 Series] C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATIFJA.EXE /FU "C:\Windows\TEMP\E_S1AF0.tmp" /EF "HKCU"
    O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
    O4 - Startup: HotSync Manager.lnk = C:\Program Files\Palm\HOTSYNC.EXE
    O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
    O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare Software\bin\EasyShare.exe
    O4 - Global Startup: ymetray.lnk = C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
    O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
    O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
    O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
    O15 - Trusted Zone: http://c03.tellmemorecampus.com
    O15 - Trusted Zone: http://c03.tellmemorecampus.com (HKLM)
    O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
    O20 - AppInit_DLLs: avgrsstx.dll
    O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
    O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
    O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
    O23 - Service: EpsonBidirectionalService - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
    O23 - Service: Google Update Service (gupdate1c9f66f8fd288c0) (gupdate1c9f66f8fd288c0) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
    O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Unknown owner - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe (file missing)
    O23 - Service: Swupdtmr - Unknown owner - c:\Toshiba\IVP\swupdate\swupdtmr.exe
    O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe
    O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe
    O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
    O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe

    --
    End of file - 11566 bytes


    Any help you can give me will be much appreciated.

    Karpos

      Topic Starter


      Rookie

      Re: Vista: Error cannot find dll32
      « Reply #1 on: August 17, 2010, 03:15:55 PM »
      Another problem I am having is that I cannot open Control Panel directly.  I can only go to Windows Explorer, using the View Folders option on the side panel, and click the down arrow to expand the Control Panel folder.  Only when I do this, do my Control Panel options become visible in the window.

      kpac

      • Web moderator


      • Hacker

      • kpac®
      • Thanked: 184
        • Yes
        • Yes
        • Yes
      • Certifications: List
      • Computer: Specs
      • Experience: Expert
      • OS: Windows 7
      Re: Vista: Error cannot find dll32
      « Reply #2 on: August 17, 2010, 04:41:22 PM »
      I'd suggest re-posting the same information in the virus and spyware forum so it'll receive proper treatment.

      Karpos

        Topic Starter


        Rookie

        Re: Vista: Error cannot find dll32
        « Reply #3 on: August 17, 2010, 05:48:35 PM »
        Oh my, I thought that's where this post was.   ???  I just clicked the link at the bottom of the Computer Hope page about Virus and Spyware guidelines, and it brought me to this forum.  I will repost. 

        Thank you!

        SuperDave

        • Malware Removal Specialist


        • Genius
        • Thanked: 1020
        • Certifications: List
        • Experience: Expert
        • OS: Windows 10
        Re: Vista: Error cannot find dll32
        « Reply #4 on: August 17, 2010, 06:20:25 PM »
        Hello and welcome to Computer Hope Forum. My name is Dave. I will be helping you out with your particular problem on your computer. I am working under the guidance of one of the specialist of this forum so it may take a bit longer to process your logs.

        1. I will be working on your Malware issues. This may or may not solve other issues you have with your machine.
        2. The fixes are specific to your problem and should only be used for this issue on this machine.
        3. If you don't know or understand something, please don't hesitate to ask.
        4. Please DO NOT run any other tools or scans while I am helping you.
        5. It is important that you reply to this thread. Do not start a new topic.
        6. Your security programs may give warnings for some of the tools I will ask you to use. Be assured, any links I give are safe.
        7. Absence of symptoms does not mean that everything is clear.

        Open HijackThis and select Do a system scan only

        Place a check mark next to the following entries: (if there)

        R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
        R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)

        Internet Explorer's security is based upon a set of zones. Each zone has different security in terms of what scripts and applications can be run from a site that is in that zone. There is a security zone called the Trusted Zone. This zone has the lowest security and allows scripts and applications from sites in this zone to run without your knowledge. It is therefore a popular setting for malware sites to use so that future infections can be easily done on your computer without your knowledge as these sites will be in the Trusted Zone. Therefore, I recommend that nothing be allowed in the trusted zone. If you agree, please do the following. Place a check mark next to these two lines.
        O15 - Trusted Zone: http://c03.tellmemorecampus.com
        O15 - Trusted Zone: http://c03.tellmemorecampus.com (HKLM)


        Important: Close all open windows except for HijackThis and then click Fix checked.

        Once completed, exit HijackThis.

        *****************************************
        Download ComboFix by sUBs from one of the below links.  Be sure to save it to the Desktop.

        link # 1
        Link # 2

        Close any open web browsers (Firefox, Internet Explorer, etc) before starting ComboFix.

        Temporarily disable your anti-virus, and any anti-spyware real-time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.

        Right-click combofix.exe and select Run as Administrator and follow the prompts.
        When finished, ComboFix will produce a log for you.
        Post the ComboFix log and a new HijackThis log in your next reply.

        NOTE: Do not mouseclick ComboFix's window while it is running. That may cause it to stall.

        Remember to re-enable your anti-virus and anti-spyware protection when ComboFix is complete.
        Windows 8 and Windows 10 dual boot with two SSD's

        Karpos

          Topic Starter


          Rookie

          Re: Vista: Error cannot find dll32
          « Reply #5 on: August 18, 2010, 06:42:17 PM »
          Hello Dave.  Thanks for your help.

          I am trying to disable the AntiSpyware in AVGFree 8.5, but I cannot figure out how to do it.  I have done the steps up to running ComboFix.  It says I can continue, but I don't know if I should without disabling the AVG Antispy first.

          Thank you.

          Karpos

            Topic Starter


            Rookie

            Re: Vista: Error cannot find dll32
            « Reply #6 on: August 18, 2010, 06:49:10 PM »
            I did disable the Resident Shield... does this disable both the antivirus and the antispyware?

            Thx!

            SuperDave

            • Malware Removal Specialist


            • Genius
            • Thanked: 1020
            • Certifications: List
            • Experience: Expert
            • OS: Windows 10
            Re: Vista: Error cannot find dll32
            « Reply #7 on: August 18, 2010, 07:00:03 PM »
            Please run the scan anyway.
            Windows 8 and Windows 10 dual boot with two SSD's

            Karpos

              Topic Starter


              Rookie

              Re: Vista: Error cannot find dll32
              « Reply #8 on: August 18, 2010, 07:20:48 PM »
              ok... thx

              Karpos

                Topic Starter


                Rookie

                Re: Vista: Error cannot find dll32
                « Reply #9 on: August 18, 2010, 07:54:53 PM »
                OK...

                ComboFix:

                ComboFix 10-08-17.04 - Jacob 08/18/2010  20:40:31.1.2 - x86
                Microsoft® Windows Vista™ Home Premium   6.0.6000.0.1252.1.1033.18.1014.425 [GMT -5:00]
                Running from: c:\users\Jacob\Desktop\ComboFix.exe
                AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
                SP: AVG Anti-Virus Free *enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
                SP: Windows Defender *enabled* (Outdated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
                .

                (((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
                .

                c:\users\Jacob\AppData\Roaming\Microsoft\Windows\Recent\Vizu.url
                c:\windows\system32\nfr.assembly
                c:\windows\system32\nfr.gpref

                .
                (((((((((((((((((((((((((   Files Created from 2010-07-19 to 2010-08-19  )))))))))))))))))))))))))))))))
                .

                2010-08-19 01:54 . 2010-08-19 01:54   --------   d-----w-   c:\users\Jacob\AppData\Local\temp
                2010-08-19 01:54 . 2010-08-19 01:54   --------   d-----w-   c:\users\Default\AppData\Local\temp
                2010-08-19 01:37 . 2010-08-19 01:38   --------   d-----w-   C:\32788R22FWJFW
                2010-08-18 03:47 . 2010-08-18 03:47   --------   d-----w-   c:\users\Jacob\AppData\Roaming\Uniblue
                2010-08-18 03:47 . 2010-08-18 03:47   --------   d-----w-   c:\program files\Uniblue
                2010-08-18 03:31 . 2010-08-18 03:31   --------   d-----w-   c:\program files\Common Files\Macromedia Shared
                2010-08-17 18:30 . 2010-08-17 18:30   388096   ----a-r-   c:\users\Jacob\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
                2010-08-17 18:27 . 2010-08-17 18:27   --------   d-----w-   c:\program files\Trend Micro
                2010-08-17 18:19 . 2010-08-17 18:19   --------   d-----w-   c:\windows\Sun
                2010-08-17 18:15 . 2010-08-17 18:15   423656   ----a-w-   c:\windows\system32\deployJava1.dll
                2010-08-17 17:41 . 2010-08-17 17:41   --------   d-----w-   c:\users\Jacob\AppData\Roaming\Malwarebytes
                2010-08-17 17:41 . 2010-04-29 20:39   38224   ----a-w-   c:\windows\system32\drivers\mbamswissarmy.sys
                2010-08-17 17:41 . 2010-08-17 17:41   --------   d-----w-   c:\program files\Malwarebytes' Anti-Malware
                2010-08-17 17:41 . 2010-08-17 17:41   --------   d-----w-   c:\programdata\Malwarebytes
                2010-08-17 17:41 . 2010-04-29 20:39   20952   ----a-w-   c:\windows\system32\drivers\mbam.sys
                2010-08-17 16:18 . 2010-08-17 16:18   63488   ----a-w-   c:\users\Jacob\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10006.dll
                2010-08-17 16:18 . 2010-08-17 16:18   52224   ----a-w-   c:\users\Jacob\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
                2010-08-17 16:17 . 2010-08-17 16:17   117760   ----a-w-   c:\users\Jacob\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
                2010-08-17 16:17 . 2010-08-17 16:17   --------   d-----w-   c:\users\Jacob\AppData\Roaming\SUPERAntiSpyware.com
                2010-08-17 16:17 . 2010-08-17 16:17   --------   d-----w-   c:\programdata\SUPERAntiSpyware.com
                2010-08-17 16:17 . 2010-08-17 16:17   --------   d-----w-   c:\program files\SUPERAntiSpyware
                2010-08-17 15:58 . 2010-08-17 15:58   --------   d-----w-   c:\program files\CCleaner
                2010-08-07 18:42 . 2007-12-17 04:00   143872   ----a-w-   c:\programdata\EPSON\EPW!3 SSRP\E_S40ST7.EXE
                2010-08-07 18:42 . 2007-01-11 04:02   113664   ----a-w-   c:\programdata\EPSON\EPW!3 SSRP\E_S40RP7.EXE
                2010-08-07 02:29 . 2010-08-18 15:55   --------   d-----w-   C:\Andy
                2010-08-07 01:27 . 2010-08-07 01:27   --------   d-----w-   c:\users\Jacob\AppData\Roaming\Leadertech
                2010-08-07 01:23 . 2007-09-07 22:33   135168   ----a-w-   c:\windows\system32\EEBAPI.dll
                2010-08-07 01:14 . 2010-08-07 20:28   --------   d-----w-   c:\program files\Epson Software
                2010-08-07 01:13 . 2008-11-12 03:00   93696   ----a-w-   c:\windows\system32\E_FLBFJA.DLL
                2010-08-07 01:13 . 2008-11-12 03:00   79360   ----a-w-   c:\windows\system32\E_FD4BFJA.DLL
                2010-08-07 01:10 . 2009-05-01 05:00   15872   ----a-w-   c:\windows\system32\escdev.dll
                2010-08-07 01:10 . 2009-05-01 05:00   128392   ----a-w-   c:\windows\system32\esdevapp.exe
                2010-08-07 01:10 . 2008-11-17 05:00   342016   ----a-w-   c:\windows\system32\eswiaud.dll
                2010-07-28 16:04 . 2010-07-28 16:41   --------   d-----w-   c:\users\Public\Bone Fragments 072810_data

                .
                ((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
                .
                2010-08-18 12:09 . 2008-03-11 04:04   --------   d-----w-   c:\program files\Winamp Remote
                2010-08-18 03:30 . 2007-12-04 02:51   --------   d-----w-   c:\program files\Macromedia
                2010-08-17 18:16 . 2007-01-05 23:14   --------   d-----w-   c:\program files\Common Files\Java
                2010-08-17 18:14 . 2007-01-05 23:14   --------   d-----w-   c:\program files\Java
                2010-08-17 05:32 . 2007-08-11 03:12   15793432   ----a-w-   c:\programdata\WildTangent\TOSHIBA Game Console\Downloads\Installers\SetupGamesClient.exe
                2010-08-07 18:33 . 2010-08-07 01:12   --------   d-----w-   c:\programdata\EPSON
                2010-08-07 18:19 . 2010-08-07 01:20   --------   d-----w-   c:\users\Jacob\AppData\Roaming\Epson
                2010-08-07 01:27 . 2007-08-03 20:38   --------   d-----w-   c:\program files\EPSON
                2010-08-07 01:23 . 2010-08-07 01:17   --------   d-----w-   c:\program files\Common Files\EPSON
                2010-08-07 01:20 . 2007-01-05 22:30   --------   d--h--w-   c:\program files\InstallShield Installation Information
                2010-08-07 01:19 . 2010-08-07 01:18   --------   d-----w-   c:\program files\EpsonNet
                2010-08-07 01:12 . 2010-08-07 01:12   --------   d-----w-   c:\users\Jacob\AppData\Roaming\InstallShield
                2010-08-02 22:25 . 2008-08-30 04:55   --------   d-----w-   c:\users\Jacob\AppData\Roaming\Research In Motion
                2010-08-02 22:10 . 2007-07-30 23:34   125224   ----a-w-   c:\users\Jacob\AppData\Local\GDIPFONTCACHEV1.DAT
                2010-08-02 22:08 . 2008-08-30 04:45   --------   d-----w-   c:\programdata\Roxio
                2010-08-02 22:08 . 2008-08-30 04:45   --------   d-----w-   c:\program files\Common Files\Roxio Shared
                2010-08-02 22:07 . 2007-11-06 16:00   --------   d-----w-   c:\program files\Common Files\PX Storage Engine
                2010-08-02 20:50 . 2008-07-14 17:01   --------   d-----w-   c:\program files\Ascentive
                2010-08-02 20:47 . 2007-01-05 23:23   --------   d-----w-   c:\programdata\WildTangent
                2010-08-02 20:47 . 2007-01-05 23:22   --------   d-----w-   c:\program files\TOSHIBA Games
                2010-08-02 19:44 . 2007-01-05 23:24   --------   d-----w-   c:\program files\Google
                2010-08-02 19:39 . 2007-12-04 02:51   --------   d-----w-   c:\program files\Common Files\Macromedia
                2010-07-08 21:29 . 2010-07-08 21:28   1601928   ----a-w-   c:\users\Public\3650PrinterDiagnosticUtility.exe
                2010-06-28 21:58 . 2010-03-06 01:57   439816   ----a-w-   c:\users\Jacob\AppData\Roaming\Real\Update\setup3.10\setup.exe
                2010-06-23 02:43 . 2010-06-23 02:43   501936   ----a-w-   c:\programdata\Google\Google Toolbar\Update\gtbFD6B.tmp.exe
                2010-06-22 02:32 . 2010-06-22 02:32   --------   d-----w-   c:\program files\Microsoft
                2010-06-22 02:32 . 2010-06-22 02:31   --------   d-----w-   c:\program files\Windows Live
                2010-06-22 02:31 . 2010-06-22 02:31   --------   d-----w-   c:\program files\Windows Live SkyDrive
                2010-06-22 02:26 . 2010-06-22 02:26   --------   d-----w-   c:\program files\Common Files\Windows Live
                .

                (((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
                .
                .
                *Note* empty entries & legit default entries are not shown
                REGEDIT4

                [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
                "{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-11-25 1230080]

                [HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]

                [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
                2009-11-25 19:01   1230080   ----a-w-   c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll

                [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
                "{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-11-25 1230080]

                [HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

                [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
                "{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-11-25 1230080]

                [HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

                [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                "updateMgr"="c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2004-11-22 307200]
                "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-12-30 39408]
                "ehTray.exe"="c:\windows\ehome\ehTray.exe" [2006-11-02 125440]
                "RegistryBooster"="c:\program files\Uniblue\RegistryBooster\launcher.exe" [2010-07-27 67448]

                [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                "IgfxTray"="c:\windows\system32\igfxtray.exe" [2006-11-29 98304]
                "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2006-11-29 106496]
                "Persistence"="c:\windows\system32\igfxpers.exe" [2006-11-29 81920]
                "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-10-27 815104]
                "Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2007-07-31 1006264]
                "RtHDVCpl"="RtHDVCpl.exe" [2006-11-09 3784704]
                "LtMoh"="c:\program files\ltmoh\Ltmoh.exe" [2005-12-16 188416]
                "TPwrMain"="c:\program files\TOSHIBA\Power Saver\TPwrMain.EXE" [2006-12-20 411768]
                "HSON"="c:\program files\TOSHIBA\TBS\HSON.exe" [2006-12-08 55416]
                "SmoothView"="c:\program files\Toshiba\SmoothView\SmoothView.exe" [2006-12-12 448632]
                "00TCrdMain"="c:\program files\TOSHIBA\FlashCards\TCrdMain.exe" [2006-12-15 530552]
                "NDSTray.exe"="NDSTray.exe" [BU]
                "HWSetup"="c:\program files\TOSHIBA\Utilities\HWSetup.exe" [2006-11-01 413696]
                "SVPWUTIL"="c:\program files\TOSHIBA\Utilities\SVPWUTIL.exe" [2006-01-19 421888]
                "KeNotify"="c:\program files\TOSHIBA\Utilities\KeNotify.exe" [2006-11-07 34352]
                "PINGER"="c:\toshiba\IVP\ISM\pinger.exe" [2006-07-20 151552]
                "WinampAgent"="c:\program files\Winamp\winampa.exe" [2008-01-15 37376]
                "AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2010-07-13 2048352]
                "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-09-05 417792]
                "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-09-09 305440]
                "TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-11-25 198160]
                "EEventManager"="c:\progra~1\EPSONS~1\EVENTM~1\EEventManager.exe" [2009-04-07 673616]
                "FUFAXSTM"="c:\program files\Epson Software\FAX Utility\FUFAXSTM.exe" [2009-06-05 843776]
                "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]

                c:\users\Jacob\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
                OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2007-12-7 101440]

                c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
                Kodak EasyShare software.lnk - c:\program files\Kodak\Kodak EasyShare Software\bin\EasyShare.exe [2007-9-19 282624]
                ymetray.lnk - c:\program files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe [2008-2-5 54512]

                [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
                "AppInit_DLLs"=c:\windows\System32\avgrsstx.dll

                [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
                @="Service"

                [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
                "DisableMonitoring"=dword:00000001

                R2 gupdate1c9f66f8fd288c0;Google Update Service (gupdate1c9f66f8fd288c0);c:\program files\Google\Update\GoogleUpdate.exe [2009-06-26 133104]
                R3 Ph3xIB32;Philips 713x Inbox PCI TV Card;c:\windows\system32\DRIVERS\Ph3xIB32.sys [2007-04-03 1131136]
                R3 WSDPrintDevice;WSD Print Support via UMB;c:\windows\system32\DRIVERS\WSDPrint.sys [2006-11-02 16896]
                R3 WSDScan;WSD Scan Support via UMB;c:\windows\system32\DRIVERS\WSDScan.sys [2006-11-02 19968]
                S1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\Drivers\avgldx86.sys [2009-09-06 335240]
                S1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\System32\Drivers\avgtdix.sys [2009-05-16 108552]
                S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2010-02-17 12872]
                S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2010-05-10 67656]
                S2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2009-09-06 908056]
                S2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2009-09-06 297752]


                [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
                HPZ12   REG_MULTI_SZ      Pml Driver HPZ12 Net Driver HPZ12
                .
                Contents of the 'Scheduled Tasks' folder

                2010-08-18 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
                - c:\program files\Google\Update\GoogleUpdate.exe [2009-06-26 15:05]

                2010-08-19 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
                - c:\program files\Google\Update\GoogleUpdate.exe [2009-06-26 15:05]

                2010-08-18 c:\windows\Tasks\RegistryBooster.job
                - c:\program files\Uniblue\RegistryBooster\rbmonitor.exe [2010-08-18 14:50]
                .
                .
                ------- Supplementary Scan -------
                .
                uLocal Page = \blank.htm
                uStart Page = hxxp://www.google.com/webhp?hl=en
                uInternet Settings,ProxyServer = http=localhost:7171
                uInternet Settings,ProxyOverride = *.local;<local>
                IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
                IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
                FF - ProfilePath - c:\users\Jacob\AppData\Roaming\Mozilla\Firefox\Profiles\0uxkbwaz.default\
                FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
                FF - prefs.js: browser.search.selectedEngine - Yahoo! Search
                FF - prefs.js: browser.startup.homepage - hxxp://en-us.start.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:en-US:official
                FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
                FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
                FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
                FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\xpavgtbapi.dll
                FF - component: c:\program files\real\realplayer\browserrecord\firefox\ext\components\nprpffbrowserrecordext.dll
                FF - component: c:\users\Jacob\AppData\Roaming\Mozilla\Firefox\Profiles\0uxkbwaz.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
                FF - plugin: c:\progra~1\MOZILL~1\plugins\npnul32.dll
                FF - plugin: c:\progra~1\MOZILL~1\plugins\nppl3260.dll
                FF - plugin: c:\progra~1\MOZILL~1\plugins\npqtplugin.dll
                FF - plugin: c:\progra~1\MOZILL~1\plugins\npqtplugin2.dll
                FF - plugin: c:\progra~1\MOZILL~1\plugins\npqtplugin3.dll
                FF - plugin: c:\progra~1\MOZILL~1\plugins\npqtplugin4.dll
                FF - plugin: c:\progra~1\MOZILL~1\plugins\npqtplugin5.dll
                FF - plugin: c:\progra~1\MOZILL~1\plugins\npqtplugin6.dll
                FF - plugin: c:\progra~1\MOZILL~1\plugins\npqtplugin7.dll
                FF - plugin: c:\progra~1\MOZILL~1\plugins\nprjplug.dll
                FF - plugin: c:\progra~1\MOZILL~1\plugins\nprpjplug.dll
                FF - plugin: c:\progra~1\MOZILL~1\plugins\NPSWF32.dll
                FF - plugin: c:\program files\Google\Update\1.2.183.23\npGoogleOneClick8.dll
                FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava11.dll
                FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava12.dll
                FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava13.dll
                FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava14.dll
                FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava32.dll
                FF - plugin: c:\program files\Java\jre1.6.0\bin\npjpi160.dll
                FF - plugin: c:\program files\Java\jre1.6.0\bin\npoji610.dll
                .
                - - - - ORPHANS REMOVED - - - -

                HKCU-Run-TOSCDSPD - TOSCDSPD.EXE
                HKLM-Run-Performance Center - c:\program files\Ascentive\Performance Center\APCMain.exe



                **************************************************************************

                catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                Rootkit scan 2010-08-18 20:54
                Windows 6.0.6000  NTFS

                scanning hidden processes ... 

                scanning hidden autostart entries ...

                scanning hidden files ... 

                scan completed successfully
                hidden files: 0

                **************************************************************************
                .
                --------------------- LOCKED REGISTRY KEYS ---------------------

                [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aif\UserChoice]
                @Denied: (2) (LocalSystem)
                "Progid"="YMP.Media"

                [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aifc\UserChoice]
                @Denied: (2) (LocalSystem)
                "Progid"="YMP.Media"

                [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aiff\UserChoice]
                @Denied: (2) (LocalSystem)
                "Progid"="YMP.Media"

                [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.au\UserChoice]
                @Denied: (2) (LocalSystem)
                "Progid"="YMP.Media"

                [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.flac\UserChoice]
                @Denied: (2) (LocalSystem)
                "Progid"="YMP.Media"

                [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m3u\UserChoice]
                @Denied: (2) (LocalSystem)
                "Progid"="YMP.Media"

                [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mid\UserChoice]
                @Denied: (2) (LocalSystem)
                "Progid"="YMP.Media"

                [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.midi\UserChoice]
                @Denied: (2) (LocalSystem)
                "Progid"="YMP.Media"

                [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp3\UserChoice]
                @Denied: (2) (LocalSystem)
                "Progid"="YMP.Media"

                [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ogg\UserChoice]
                @Denied: (2) (LocalSystem)
                "Progid"="YMP.Media"

                [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pcm\UserChoice]
                @Denied: (2) (LocalSystem)
                "Progid"="YMP.Media"

                [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pls\UserChoice]
                @Denied: (2) (LocalSystem)
                "Progid"="YMP.Media"

                [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.snd\UserChoice]
                @Denied: (2) (LocalSystem)
                "Progid"="YMP.Media"

                [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.spx\UserChoice]
                @Denied: (2) (LocalSystem)
                "Progid"="YMP.Media"

                [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wav\UserChoice]
                @Denied: (2) (LocalSystem)
                "Progid"="YMP.Media"

                [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wma\UserChoice]
                @Denied: (2) (LocalSystem)
                "Progid"="YMP.Media"

                [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
                @Denied: (A) (Users)
                @Denied: (A) (Everyone)
                @Allowed: (B 1 2 3 4 5) (S-1-5-20)
                "BlindDial"=dword:00000000
                "MSCurrentCountry"=dword:000000b5
                .
                Completion time: 2010-08-18  20:58:12
                ComboFix-quarantined-files.txt  2010-08-19 01:58

                Pre-Run: 25,171,718,144 bytes free
                Post-Run: 25,119,727,616 bytes free

                - - End Of File - - 8E12B8E5D9083CC078529F0D7722A401





                HiJackThis:

                Logfile of Trend Micro HijackThis v2.0.4
                Scan saved at 9:07:15 PM, on 8/18/2010
                Platform: Windows Vista  (WinNT 6.00.1904)
                MSIE: Internet Explorer v7.00 (7.00.6000.16809)
                Boot mode: Normal

                Running processes:
                C:\Windows\system32\taskeng.exe
                C:\Program Files\Uniblue\RegistryBooster\rbmonitor.exe
                C:\Windows\system32\taskeng.exe
                C:\Windows\system32\Dwm.exe
                C:\Windows\System32\igfxtray.exe
                C:\Windows\System32\hkcmd.exe
                C:\Windows\System32\igfxpers.exe
                C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                C:\Program Files\Windows Defender\MSASCui.exe
                C:\Windows\RtHDVCpl.exe
                C:\Program Files\ltmoh\ltmoh.exe
                C:\Program Files\Toshiba\Power Saver\TPwrMain.exe
                C:\Program Files\Toshiba\SmoothView\SmoothView.exe
                C:\Program Files\Toshiba\FlashCards\TCrdMain.exe
                C:\Program Files\Synaptics\SynTP\SynToshiba.exe
                C:\Program Files\Toshiba\Utilities\KeNotify.exe
                C:\Toshiba\IVP\ISM\pinger.exe
                C:\Program Files\AVG\AVG8\avgtray.exe
                C:\Program Files\QuickTime\QTTask.exe
                C:\Program Files\iTunes\iTunesHelper.exe
                C:\Program Files\Common Files\Real\Update_OB\realsched.exe
                C:\Program Files\Epson Software\Event Manager\EEventManager.exe
                C:\Program Files\Epson Software\FAX Utility\FUFAXSTM.exe
                C:\Program Files\Common Files\Java\Java Update\jusched.exe
                C:\Program Files\Toshiba\TOSCDSPD\TOSCDSPD.exe
                C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                C:\Windows\ehome\ehtray.exe
                C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
                C:\Program Files\Kodak\Kodak EasyShare Software\bin\EasyShare.exe
                C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe
                C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
                C:\Windows\ehome\ehmsas.exe
                C:\Windows\System32\mobsync.exe
                C:\Windows\system32\igfxext.exe
                C:\Windows\system32\igfxsrvc.exe
                C:\Windows\system32\wuauclt.exe
                C:\Windows\explorer.exe
                C:\Program Files\Windows Media Player\wmpnscfg.exe
                C:\Program Files\Trend Micro\HiJackThis\sniper.exe

                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
                R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
                R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
                R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=localhost:7171
                R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local;<local>
                R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
                R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
                O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
                O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
                O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
                O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
                O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.5126.1836\swg.dll
                O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
                O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
                O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
                O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
                O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
                O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
                O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe
                O4 - HKLM\..\Run: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
                O4 - HKLM\..\Run: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON.exe
                O4 - HKLM\..\Run: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
                O4 - HKLM\..\Run: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
                O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
                O4 - HKLM\..\Run: [HWSetup] C:\Program Files\TOSHIBA\Utilities\HWSetup.exe hwSetUP
                O4 - HKLM\..\Run: [SVPWUTIL] C:\Program Files\TOSHIBA\Utilities\SVPWUTIL.exe SVPwUTIL
                O4 - HKLM\..\Run: [KeNotify] C:\Program Files\TOSHIBA\Utilities\KeNotify.exe
                O4 - HKLM\..\Run: [PINGER] C:\TOSHIBA\IVP\ISM\pinger.exe /run
                O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
                O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
                O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
                O4 - HKLM\..\Run: [EEventManager] C:\PROGRA~1\EPSONS~1\EVENTM~1\EEventManager.exe
                O4 - HKLM\..\Run: [FUFAXSTM] "C:\Program Files\Epson Software\FAX Utility\FUFAXSTM.exe"
                O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
                O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_0
                O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
                O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                O4 - HKCU\..\Run: [RegistryBooster] "C:\Program Files\Uniblue\RegistryBooster\launcher.exe" delay 20000
                O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
                O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare Software\bin\EasyShare.exe
                O4 - Global Startup: ymetray.lnk = C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe
                O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
                O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
                O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
                O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
                O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
                O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
                O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
                O20 - AppInit_DLLs: C:\Windows\System32\avgrsstx.dll
                O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
                O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
                O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
                O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
                O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
                O23 - Service: EpsonBidirectionalService - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
                O23 - Service: Google Update Service (gupdate1c9f66f8fd288c0) (gupdate1c9f66f8fd288c0) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
                O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Unknown owner - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe (file missing)
                O23 - Service: Swupdtmr - Unknown owner - c:\Toshiba\IVP\swupdate\swupdtmr.exe
                O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe
                O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe
                O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
                O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe

                --
                End of file - 10275 bytes

                SuperDave

                • Malware Removal Specialist


                • Genius
                • Thanked: 1020
                • Certifications: List
                • Experience: Expert
                • OS: Windows 10
                Re: Vista: Error cannot find dll32
                « Reply #10 on: August 19, 2010, 01:09:18 PM »
                Please read here for more information about WildTangent. Your choice if you want to remove it or not.

                If you choose to follow my advice, please follow these instructions.

                Go to Start > Control Panel > Add/Remove Programs and remove the following programs.

                WildTangent Web Driver or anything related to WildTangent.
                *********************************

                Open HijackThis and select Do a system scan only

                Place a check mark next to the following entries: (if there)

                R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=localhost:7171
                R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local;<local>
                R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =


                Important: Close all open windows except for HijackThis and then click Fix checked.

                Once completed, exit HijackThis.
                ************************************
                * Download the following tool: RootRepeal - Rootkit Detector
                * Direct download link is here: RootRepeal.zip

                * Close all programs and temporarily disable your anti-virus, Firewall and any anti-malware real-time protection before performing a scan.
                * Click this link to see a list of such programs and how to disable them.

                * Extract the program file to a new folder such as C:\RootRepeal
                * Run the program RootRepeal.exe and go to the REPORT tab and click on the Scan button.
                * Select ALL of the checkboxes and then click OK and it will start scanning your system.
                * If you have multiple drives you only need to check the C: drive or the one Windows is installed on.
                * When done, click on Save Report
                * Save it to the same location where you ran it from, such as C:RootRepeal
                * Save it as rootrepeal.txt
                * Then open that log and select all and copy/paste it back on your next reply please.
                * Close RootRepeal.

                Windows 8 and Windows 10 dual boot with two SSD's

                Karpos

                  Topic Starter


                  Rookie

                  Re: Vista: Error cannot find dll32
                  « Reply #11 on: August 19, 2010, 02:38:52 PM »
                  Nothing from Wild Tangent is showing up in the Programs and Features folder.  I thought I removed all of it when I was cleaning up the computer for my husband to use.  Is there anything else I need to do about that before I move on to the next steps? 

                  Thx.

                  SuperDave

                  • Malware Removal Specialist


                  • Genius
                  • Thanked: 1020
                  • Certifications: List
                  • Experience: Expert
                  • OS: Windows 10
                  Re: Vista: Error cannot find dll32
                  « Reply #12 on: August 20, 2010, 12:41:00 PM »
                  Ok. Please do this first and then run RootRepeal.

                  Re-running ComboFix to remove infections:

                  • Close any open browsers.
                  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
                  • Open notepad and copy/paste the text in the quotebox below into it:
                    Quote
                    KillAll::
                    Folder::
                    c:\programdata\WildTangent

                    DDS::
                    uInternet Settings,ProxyServer = http=localhost:7171
                    uInternet Settings,ProxyOverride = *.local;<local>

                    Driver::

                  • Save this as CFScript.txt, in the same location as ComboFix.exe



                  • Referring to the picture above, drag CFScript into ComboFix.exe
                  • When finished, it shall produce a log for you at C:\ComboFix.txt
                  • Please post the contents of the log in your next reply.
                  ***********************************************

                  Windows 8 and Windows 10 dual boot with two SSD's