Results 1 to 4 of 4

Thread: zlob.dnschanger is pain in my assholes!!

  1. #1
    Junior Member
    Join Date
    Aug 2007
    Posts
    2

    Default zlob.dnschanger is pain in my assholes!!

    hello guys, thanks for taking the time to help me out. aren't you lovely...

    ok, cant seem to get rid of the zlob.dnschanger! keeps reappearing in spybot. Now i have ad-aware, avg, spwareblaster, spybot, superantispyware, avast, ccleaner, aticleaner... and yet none of them seem to be able to get rid of it...

    HIJACKTHIS:
    Logfile of HijackThis v1.99.1
    Scan saved at 00:41:50, on 20/08/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16512)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5 (2)\guard.exe
    C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
    C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
    C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
    C:\WINDOWS\system32\CTsvcCDA.EXE
    C:\Program Files\CDBurnerXP Pro 3\Tools\NMSAccess.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\MsPMSPSv.exe
    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\Creative\SB Live! 24-bit\Surround Mixer\CTSysVol.exe
    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
    C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
    C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
    C:\WINDOWS\System32\HPZipm12.exe
    C:\Program Files\hijackThis\HijackThis\HijackThis1991.exe
    C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqfru07.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://go.microsoft.com/fwlink/?LinkId=54843
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
    O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
    O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
    O4 - HKLM\..\Run: [CTSysVol] "C:\Program Files\Creative\SB Live! 24-bit\Surround Mixer\CTSysVol.exe" /r
    O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe"
    O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - Global Startup: hp psc 1000 series.lnk = ?
    O4 - Global Startup: hpoddt01.exe.lnk = ?
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\npjpi160_02.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\npjpi160_02.dll
    O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
    O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O11 - Options group: [INTERNATIONAL] International*
    O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://creative.com/su/ocx/15015/CTSUEng.cab
    O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...t.cab31267.cab
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsu...?1175527234203
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsof...?1166807331134
    O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...t.cab31267.cab
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/actives...ree/asinst.cab
    O16 - DPF: {F2A84794-EE6D-447B-8C21-3BA1DC77C5B4} (SDKInstall Class) - http://activex.microsoft.com/activex...te/sdkinst.cab
    O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://creative.com/su/ocx/15016/CTPID.cab
    O17 - HKLM\System\CS4\Services\Tcpip\Parameters: NameServer = 85.255.116.98 85.255.112.123
    O17 - HKLM\System\CS4\Services\Tcpip\..\{125EEE63-87FF-4431-9BBD-24FBEDB66BA6}: NameServer = 85.255.116.98,85.255.112.123
    O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
    O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
    O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
    O20 - Winlogon Notify: ComPlusSetup - C:\WINDOWS\system32\catsrvut.dll
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
    O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
    O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
    O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
    O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5 (2)\guard.exe
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
    O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
    O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: NMSAccess - Unknown owner - C:\Program Files\CDBurnerXP Pro 3\Tools\NMSAccess.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
    O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
    O23 - Service: Sony SPTI Service (SPTISRV) - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe (file missing)
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

    PANDA ACTIVE SCAN:

    Incident / Status / Location
    Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Chris & Baz\Application Data\Mozilla\Firefox\Profiles\yxb6dou1.Default User\cookies.txt[.doubleclick.net/]
    Spyware:Cookie/Cd Freaks Not disinfected C:\Documents and Settings\Chris & Baz\Application Data\Mozilla\Firefox\Profiles\yxb6dou1.Default User\cookies.txt[.cdfreaks.com/]
    Spyware:Cookie/Cd Freaks Not disinfected C:\Documents and Settings\Chris & Baz\Application Data\Mozilla\Firefox\Profiles\yxb6dou1.Default User\cookies.txt[.club.cdfreaks.com/]
    Spyware:Cookie/Adtech Not disinfected C:\Documents and Settings\Chris & Baz\Application Data\Mozilla\Firefox\Profiles\yxb6dou1.Default User\cookies.txt[.adtech.de/]
    Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Chris & Baz\Application Data\Mozilla\Firefox\Profiles\yxb6dou1.Default User\cookies.txt[.atdmt.com/]
    Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\Chris & Baz\Application Data\Mozilla\Firefox\Profiles\yxb6dou1.Default User\cookies.txt[.tribalfusion.com/]
    Spyware:Cookie/BurstNet Not disinfected C:\Documents and Settings\Chris & Baz\Application Data\Mozilla\Firefox\Profiles\yxb6dou1.Default User\cookies.txt[.burstnet.com/]
    Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\Chris & Baz\Application Data\Mozilla\Firefox\Profiles\yxb6dou1.Default User\cookies.txt[.com.com/]
    Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Chris & Baz\Application Data\Mozilla\Firefox\Profiles\yxb6dou1.Default User\cookies.txt[.go.com/]
    Spyware:Cookie/Toplist Not disinfected C:\Documents and Settings\Chris & Baz\Application Data\Mozilla\Firefox\Profiles\yxb6dou1.Default User\cookies.txt[.toplist.cz/]
    Spyware:Cookie/Xiti Not disinfected C:\Documents and Settings\Chris & Baz\Application Data\Mozilla\Firefox\Profiles\yxb6dou1.Default User\cookies.txt[.xiti.com/]
    Spyware:Cookie/Yadro Not disinfected C:\Documents and Settings\Chris & Baz\Application Data\Mozilla\Firefox\Profiles\yxb6dou1.Default User\cookies.txt[.yadro.ru/]
    Spyware:Cookie/BurstBeacon Not disinfected C:\Documents and Settings\Chris & Baz\Application Data\Mozilla\Firefox\Profiles\yxb6dou1.Default User\cookies.txt[www.burstbeacon.com/]
    Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Chris & Baz\Cookies\chris_&_baz@atdmt[2].txt
    Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\Chris & Baz\Cookies\chris_&_baz@bs.serving-sys[1].txt
    Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\Chris & Baz\Cookies\chris_&_baz@serving-sys[1].txt
    Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Chris & Baz\Desktop\smitRem\Process.exe
    Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Chris & Baz\My Documents\My Downloads\smitRem.exe[smitRem/Process.exe]
    Spyware:Cookie/Apmebf Not disinfected C:\RECYCLER\NPROTECT\00034278.MOZ[.apmebf.com/]
    Spyware:Cookie/bravenetA Not disinfected C:\RECYCLER\NPROTECT\00034278.MOZ[.bravenet.com/]
    Spyware:Cookie/Apmebf Not disinfected C:\RECYCLER\NPROTECT\00034322.MOZ[.apmebf.com/]
    Spyware:Cookie/bravenetA Not disinfected C:\RECYCLER\NPROTECT\00034322.MOZ[.bravenet.com/]
    Spyware:Cookie/Apmebf Not disinfected C:\RECYCLER\NPROTECT\00034409.MOZ[.apmebf.com/]
    Spyware:Cookie/bravenetA Not disinfected C:\RECYCLER\NPROTECT\00034409.MOZ[.bravenet.com/]
    Spyware:Cookie/Apmebf Not disinfected C:\RECYCLER\NPROTECT\00034421.MOZ[.apmebf.com/]
    Spyware:Cookie/bravenetA Not disinfected C:\RECYCLER\NPROTECT\00034421.MOZ[.bravenet.com/]
    Spyware:Cookie/Apmebf Not disinfected C:\RECYCLER\NPROTECT\00034453.MOZ[.apmebf.com/]
    Spyware:Cookie/bravenetA Not disinfected C:\RECYCLER\NPROTECT\00034453.MOZ[.bravenet.com/]
    Spyware:Cookie/Apmebf Not disinfected C:\RECYCLER\NPROTECT\00034538.MOZ[.apmebf.com/]
    Spyware:Cookie/bravenetA Not disinfected C:\RECYCLER\NPROTECT\00034538.MOZ[.bravenet.com/]
    Spyware:Cookie/Apmebf Not disinfected C:\RECYCLER\NPROTECT\00034584.MOZ[.apmebf.com/]
    Spyware:Cookie/bravenetA Not disinfected C:\RECYCLER\NPROTECT\00034584.MOZ[.bravenet.com/]
    Spyware:Cookie/Apmebf Not disinfected C:\RECYCLER\NPROTECT\00034585.MOZ[.apmebf.com/]
    Spyware:Cookie/bravenetA Not disinfected C:\RECYCLER\NPROTECT\00034585.MOZ[.bravenet.com/]
    Spyware:Cookie/Apmebf Not disinfected C:\RECYCLER\NPROTECT\00034755.MOZ[.apmebf.com/]
    Spyware:Cookie/bravenetA Not disinfected C:\RECYCLER\NPROTECT\00034755.MOZ[.bravenet.com/]
    Spyware:Cookie/Apmebf Not disinfected C:\RECYCLER\NPROTECT\00034851.MOZ[.apmebf.com/]
    Spyware:Cookie/bravenetA Not disinfected C:\RECYCLER\NPROTECT\00034851.MOZ[.bravenet.com/]
    Spyware:Cookie/Apmebf Not disinfected C:\RECYCLER\NPROTECT\00034852.MOZ[.apmebf.com/]
    Spyware:Cookie/bravenetA Not disinfected C:\RECYCLER\NPROTECT\00034852.MOZ[.bravenet.com/]
    Spyware:Cookie/Apmebf Not disinfected C:\RECYCLER\NPROTECT\00034855.MOZ[.apmebf.com/]
    Spyware:Cookie/bravenetA Not disinfected C:\RECYCLER\NPROTECT\00034855.MOZ[.bravenet.com/]
    Spyware:Cookie/Apmebf Not disinfected C:\RECYCLER\NPROTECT\00034944.MOZ[.apmebf.com/]
    Spyware:Cookie/bravenetA Not disinfected C:\RECYCLER\NPROTECT\00034944.MOZ[.bravenet.com/]
    Spyware:Cookie/Apmebf Not disinfected C:\RECYCLER\NPROTECT\00034949.MOZ[.apmebf.com/]
    Spyware:Cookie/bravenetA Not disinfected C:\RECYCLER\NPROTECT\00034949.MOZ[.bravenet.com/]
    Spyware:Cookie/Apmebf Not disinfected C:\RECYCLER\NPROTECT\00035025.MOZ[.apmebf.com/]
    Spyware:Cookie/bravenetA Not disinfected C:\RECYCLER\NPROTECT\00035025.MOZ[.bravenet.com/]
    Spyware:Cookie/Apmebf Not disinfected C:\RECYCLER\NPROTECT\00035068.MOZ[.apmebf.com/]
    Spyware:Cookie/bravenetA Not disinfected C:\RECYCLER\NPROTECT\00035068.MOZ[.bravenet.com/]
    Spyware:Cookie/Apmebf Not disinfected C:\RECYCLER\NPROTECT\00035112.MOZ[.apmebf.com/]
    Spyware:Cookie/bravenetA Not disinfected C:\RECYCLER\NPROTECT\00035112.MOZ[.bravenet.com/]
    Spyware:Cookie/Apmebf Not disinfected C:\RECYCLER\NPROTECT\00035136.MOZ[.apmebf.com/]
    Spyware:Cookie/bravenetA Not disinfected C:\RECYCLER\NPROTECT\00035136.MOZ[.bravenet.com/]
    Spyware:Cookie/Apmebf Not disinfected C:\RECYCLER\NPROTECT\00035156.MOZ[.apmebf.com/]
    Spyware:Cookie/bravenetA Not disinfected C:\RECYCLER\NPROTECT\00035156.MOZ[.bravenet.com/]
    Potentially unwanted tool:Application/Processor Not disinfected C:\WINDOWS\system32\Process.exe

    thanks guys

  2. #2
    Junior Member
    Join Date
    Aug 2007
    Posts
    2

    Default Fixwareout file for you too

    i did a fixwareout check too if its any help


    Username "Chris & Baz" - 20/08/2007 0:35:29 [Fixwareout edited 2007/07/05]

    »»»»»Prerun check

    HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{C869083A-1687-487E-A16D-B91E418CBEE1}
    "nameserver"="85.255.114.197" <Value cleared.

    Successfully flushed the DNS Resolver Cache.


    System was rebooted successfully.

    »»»»» Postrun check
    HKLM\SOFTWARE\~\Winlogon\ "system"=""
    ....
    ....
    »»»»» Misc files.
    ....
    »»»»» Checking for older varients.
    ....
    »»»»» Other
    C:\WINDOWS\temp\kdxuw.ren 71254 13/06/2007

    »»»»» Current runs (hklm hkcu "run" Keys Only)
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "SiSUSBRG"="C:\\WINDOWS\\SiSUSBrg.exe"
    "UpdReg"="C:\\WINDOWS\\UpdReg.EXE"
    "CTSysVol"="\"C:\\Program Files\\Creative\\SB Live! 24-bit\\Surround Mixer\\CTSysVol.exe\" /r"
    "ATICCC"="\"C:\\Program Files\\ATI Technologies\\ATI.ACE\\CLIStart.exe\""
    "ZoneAlarm Client"="\"C:\\Program Files\\Zone Labs\\ZoneAlarm\\zlclient.exe\""
    "SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.6.0_02\\bin\\jusched.exe\""
    "avast!"="C:\\PROGRA~1\\ALWILS~1\\Avast4\\ashDisp.exe"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\AutorunsDisabled]
    "ClockGen"="C:\\Documents and Settings\\Chris & Baz\\My Documents\\My Downloads\\ClockGen\\ClockGen.exe -i p=0"

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="C:\\WINDOWS\\system32\\ctfmon.exe"
    ....
    Hosts file was reset, If you use a custom hosts file please replace it
    »»»»» End report »»»»»


    danke

  3. #3
    In Memoriam -Always in our heart pskelley's Avatar
    Join Date
    Oct 2005
    Location
    Clearwater, Florida
    Posts
    20,247

    Default

    Welcome to Safer Networking, I wish to be sure you have viewed and understand this information.
    "BEFORE you POST" (READ this Procedure before Requesting Assistance)
    http://forums.spybot.info/showthread.php?t=288
    All advice given is taken at your own risk.
    Please make sure you have read this information so we are on the same page.
    Posting additional comments or logs before a volunteer responds, can push you back instead of forward, because your thread ends up with a newer date. Also, helpers may think you are already being assisted because of the post count. The same applies to 'bumping'.
    See this information:

    http://forums.spybot.info/showthread.php?t=16806
    http://forums.spybot.info/showthread.php?t=1137

    If you still have problems, please describe them, post any error messages you received "word for word"
    Review the information I posted for you and then post a new HJT log and I will respond as soon as possible after that.

    Thanks
    MS-MVP Consumer Security 2007-08-09
    Proud Member ASAP
    UNITE Member 2006

  4. #4
    In Memoriam -Always in our heart pskelley's Avatar
    Join Date
    Oct 2005
    Location
    Clearwater, Florida
    Posts
    20,247

    Default

    This topic is closed due to lack of a response.

    If you need it re-opened please send me or a forum staff member a private message (pm) and provide a link to the thread; this applies only to the original topic starter.

    Anyone else with similar problems please start a new topic.

    Thanks
    MS-MVP Consumer Security 2007-08-09
    Proud Member ASAP
    UNITE Member 2006

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •