first you might need to a rescan where you shut off firefox and if you could tell us what more specifically your problem is that could help.
For now this is wat i found:
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: (no name) - {ACB1E670-3217-45C4-A021-6B829A8A27CB} - (no file)
O16 - DPF: {74CD40EA-EF77-4BAD-808A-B5982DA73F20} - http://yax-download.yazzle.net/Yazzl...cab?refid=1123
O17 - HKLM\System\CCS\Services\Tcpip\..\{D7E35DDB-B98C-4916-9943-220CC429AE4D}: NameServer = 151.164.1.8,206.13.28.12 (WAT IS THIS?)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: winvdj32 - C:\WINDOWS\SYSTEM32\winvdj32.dll
O23 - Service: WLTRYSVC - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe
make you do a system restore before you modify any of these items
mikeandike22
Nearly a Posting Virtuoso
1,496 posts since May 2004
Reputation Points: 33
Solved Threads: 19
Hi, there are still a bunch of things that need to be cleaned. Please run HJT in safe mode, and check these items.
O4 - HKLM\..\Run: [3bc97e49.exe] C:\WINDOWS\system32\3bc97e49.exe
O4 - HKCU\..\Run: [3bc97e49.exe] C:\Documents and Settings\michael montgomery\Local Settings\Application Data\3bc97e49.exe
O16 - DPF: {97B79133-88F0-45F0-8D57-0F2EF27D9C66} - http://85.255.114.166/1/rdgUS2404.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{D7E35DDB-B98C-4916-9943-220CC429AE4D}: NameServer = 151.164.1.8,206.13.28.12
Click Fix Checked.
___________________________________________________
Reboot into normal mode.
Please download Pocket Killbox by O^E .Save it to your desktop.
Please double-click Killbox.exe to run it.
Select:Delete on Reboot
then Click on the All Files button.
Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):
C:\Documents and Settings\michael montgomery\Local Settings\Application Data\3bc97e49.exe
C:\WINDOWS\system32\3bc97e49.exe
Return to Killbox, go to the File menu, and choose Paste from Clipboard.
Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt. Click OK at any PendingFileRenameOperations prompt (and please let me know if you receive this message!).
If your computer does not restart automatically, please restart it manually.
____________________________________________________
Post a fresh ewido log, and new HJT log.
tayspen
<Insert title here>
1,622 posts since Jul 2005
Reputation Points: 84
Solved Threads: 99
You have also been infected by PurityScan.
It is an adware program that downloads and displays advertisements on a computer.
Go to Control Panel then Add/Remove Programs and look for the entry "OIN" or "(program) by OIN"
Proceed to uninstall it.
If you do not see this, please download their stand-alone uninstaller from http://www.outerinfo.com/OiUninstaller.exe .
Run this installer.
Please download ATF Cleaner( http://www.atribune.org/ccount/click.php?id=1 ) by Atribune.
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
tayspen
<Insert title here>
1,622 posts since Jul 2005
Reputation Points: 84
Solved Threads: 99