Newbie needs help

EDIT:MOVED to Virus,Trojan and Malware Removal Logs

First time user of HijackThis!

Suddenly I'm getting the following:
1. "Just in time" debugging prompts...(real hassle)
2. Task Manager closes immediately after opening...as does regedit.
3. All links in google are redirected elsewhere using Mozilla or IE.
Below is my HijackThis.log file created moments ago....(sorry, wasn't able to attach it)


Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 1:42:41 PM, on 9/5/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

End of file - 9804 bytes

Posted 10 September 2011 - 12:45 PM

Hello, Welcome to BleepingComputer.
I'm nasdaq and will be helping you.

[*]Close all programs leaving only HijackThis running. Place a check against each of the following, making sure you get them all and not any others by mistake:

O4 - HKLM\..\RunOnce: [*adslqueuestream.exe] "C:\Documents and Settings\All Users\Application Data\adslqueuestream.exe"
O4 - HKCU\..\Run: [Ycivuy] rundll32.exe "C:\WINDOWS\wpienb.dll",Startup
O4 - HKUS\S-1-5-19\..\Run: [adslqueuestream.exe] "C:\Documents and Settings\All Users\Application Data\adslqueuestream.exe" (User 'LOCAL SERVICE')

Click on Fix Checked when finished and exit HijackThis.

Delete this file in bold if found.
C:\Documents and Settings\All Users\Application Data\adslqueuestream.exe

Restart the computer normally.

Please download ComboFix from one of these locations:

Link 1
Link 2

* IMPORTANT !!! Save ComboFix.exe to your Desktop

  • Disable your Anti-Virus and Anti-Spyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
  • Some Rookit infection may damage your boot sector. The Windows Recovery Console may be needed to restore it. Do not bypass this installation. You may regret it.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Note: If you have difficulty properly disabling your protection programs, refer to this link --> http://www.bleepingcomputer.com/forums/topic114351.html

Do not mouse click ComboFix's window while it's running. That may cause it to stall

Please download and run this DDS Scanning Tool. Nothing will be deleted. It will just give me some additional information about your system.

Download DDS and save it to your desktop from here or here.
Disable any script blocker, and then double click dds.scr to run the tool.
  • When done, DDS will open two (2) logs:
    • DDS.txt
    • Attach.txt
  • Save both reports to your desktop.

Please just paste the contents of the DDS.txt log in your next post.

Post the ComboFix and the DDS logs and let me know what problem persists.

Posted 18 September 2011 - 09:21 AM

Due to the lack of feedback, this topic is now closed.

In the event you still have problems, please send me or any Moderator a Private Message and ask them to reopen this topic within the next 5 days. Please include a link to your topic in the Private Message. Thank you.

