This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Slow getting to Websites!

25 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

File name: PopWait.exe Submission date: 2011-11-24 20:23:36 (UTC) Current status: queued queued (#1) analysing finished Result: 0/ 42 (0.0%) VT Community not reviewed Safety score: - Compact Print results Antivirus Version Last Update Result AhnLab-V3 2011.11.24.00 2011.11.24 - AntiVir 7.11.18.63 2011.11.24 - Antiy-AVL 2.0.3.7 2011.11.24 - Avast 6.0.1289.0 2011.11.24 - AVG 10.0.0.1190 2011.11.24 - BitDefender 7.2 2011.11.24 - ByteHero 1.0.0.1 2011.11.14 - CAT-QuickHeal 12.00 2011.11.22 - ClamAV 0.97.3.0 2011.11.24 - Commtouch 5.3.2.6 2011.11.24 - Comodo 10786 2011.11.24 - DrWeb 5.0.2.03300 2011.11.24 - Emsisoft 5.1.0.11 2011.11.24 - eSafe 7.0.17.0 2011.11.24 - eTrust-Vet 37.0.9586 2011.11.24 - F-Prot 4.6.5.141 2011.11.24 - F-Secure 9.0.16440.0 2011.11.24 - Fortinet 4.3.370.0 2011.11.24 - GData 22.286/22.527 2011.11.24 - Ikarus T3.1.1.109.0 2011.11.24 - Jiangmin 13.0.900 2011.11.24 - K7AntiVirus 9.119.5534 2011.11.24 - Kaspersky 9.0.0.837 2011.11.24 - McAfee 5.400.0.1158 2011.11.24 - McAfee-GW-Edition 2010.1D 2011.11.24 - Microsoft 1.7801 2011.11.24 - NOD32 6657 2011.11.24 - Norman 6.07.13 2011.11.24 - nProtect 2011-11-24.02 2011.11.24 - Panda 10.0.3.5 2011.11.24 - PCTools 8.0.0.5 2011.11.24 - Prevx 3.0 2011.11.24 - Rising 23.85.03.02 2011.11.24 - Sophos 4.71.0 2011.11.24 - SUPERAntiSpyware 4.40.0.1006 2011.11.24 - Symantec 20111.2.0.82 2011.11.24 - TheHacker 6.7.0.1.347 2011.11.24 - TrendMicro 9.500.0.1008 2011.11.24 - TrendMicro-HouseCall 9.500.0.1008 2011.11.24 - VIPRE 11137 2011.11.24 - ViRobot 2011.11.24.4791 2011.11.24 - VirusBuster 14.1.83.1 2011.11.24 - Additional informationShow all MD5 : d6f9148fb52540e7e38f9e29e12db09b SHA1 : 7007913f63e02805f15afb029e6c705b1a434117 SHA256: 556f3ec192342ab8f7c836af4048cfb8672f6653f467fb99efffe0f2203b3794 ssdeep: 192:ZsOyJJzr10+yVvShuH+Qu2GrQXxyd4T8jlf7jkL9p:mOyBrm+XQ0Myd4T8jlfvkP File size : 10752 bytes First seen: 2010-11-15 06:07:47 Last seen : 2011-11-24 20:23:36 TrID: Win64 Executable Generic (80.9%) Win32 Executable Generic (8.0%) Win32 Dynamic Link Library (generic) (7.1%) Generic Win/DOS Executable (1.8%) DOS Executable Generic (1.8%) sigcheck: publisher….: copyright….: Copyright 2003 product……: PopWait Module description..: PopWait Module original name: PopWait.EXE internal name: PopWait file version.: 6, 2, 1, 8 comments…..: signers……: - signing date.: - verified…..: Unsigned PEInfo: PE structure information [[ basic data ]] entrypointaddress: 0x1C75 timedatestamp….: 0x42C1BBA6 (Tue Jun 28 21:05:42 2005) machinetype……: 0x14c (I386) [[ 4 section(s) ]] name, viradd, virsiz, rawdsiz, ntropy, md5 .text, 0x1000, 0xF68, 0x1000, 5.93, 3ad733e33de06fb238b7fc1fc1cc225f .rdata, 0x2000, 0x35C, 0x400, 4.16, 765bf97c8a25c5c50196a4e204927184 .data, 0x3000, 0x8C5, 0x600, 4.20, caf92452b788408766bdabfb0664e074 .rsrc, 0x4000, 0xA08, 0xC00, 3.13, b9a5c2b283a07ed2601b22db00896d40 [[ 6 import(s) ]] KERNEL32.dll: ExitProcess, GetStartupInfoA, GetModuleHandleA, Sleep, GetCommandLineA, MultiByteToWideChar, GetVersionExA, WritePrivateProfileStringA USER32.dll: CharNextA ADVAPI32.dll: RegSetValueExA, RegCreateKeyExA, RegEnumKeyExA, RegQueryValueExA, RegOpenKeyExA, RegCloseKey, RegDeleteKeyA, RegEnumValueA, RegDeleteValueA ole32.dll: CoCreateInstance, CoUninitialize, CoInitialize OLEAUT32.dll: -, - RASAPI32.dll: RasDeleteEntryA ExifTool: file metadata CharacterSet: Unicode CodeSize: 4096 Comments: CompanyName: EntryPoint: 0x1c75 FileDescription: PopWait Module FileFlagsMask: 0x003f FileOS: Win32 FileSize: 10 kB FileSubtype: 0 FileType: Win32 EXE FileVersion: 6, 2, 1, 8 FileVersionNumber: 6.2.1.8 ImageVersion: 0.0 InitializedDataSize: 6656 InternalName: PopWait LanguageCode: English (U.S.) LegalCopyright: Copyright 2003 LegalTrademarks: LinkerVersion: 6.0 MIMEType: application/octet-stream MachineType: Intel 386 or later, and compatibles OLESelfRegister: OSVersion: 4.0 ObjectFileType: Executable application OriginalFilename: PopWait.EXE PEType: PE32 PrivateBuild: ProductName: PopWait Module ProductVersion: 6, 2, 0, 0 ProductVersionNumber: 6.2.0.0 SpecialBuild: Subsystem: Windows GUI SubsystemVersion: 4.0 TimeStamp: 2005:06:28 23:05:42+02:00 UninitializedDataSize: 0
0 VT Community user(s) with a total of 0 reputation credit(s) say(s) this sample is goodware. 0 VT Community user(s) with a total of 0 reputation credit(s) say(s) this sample is malware. File name: RegHero.exe Submission date: 2011-11-24 20:29:52 (UTC) Current status: queued queued analysing finished Result: 0/ 43 (0.0%) VT Community not reviewed Safety score: - Compact Print results Antivirus Version Last Update Result AhnLab-V3 2011.11.24.00 2011.11.24 - AntiVir 7.11.18.63 2011.11.24 - Antiy-AVL 2.0.3.7 2011.11.24 - Avast 6.0.1289.0 2011.11.24 - AVG 10.0.0.1190 2011.11.24 - BitDefender 7.2 2011.11.24 - ByteHero 1.0.0.1 2011.11.14 - CAT-QuickHeal 12.00 2011.11.22 - ClamAV 0.97.3.0 2011.11.24 - Commtouch 5.3.2.6 2011.11.24 - Comodo 10786 2011.11.24 - DrWeb 5.0.2.03300 2011.11.24 - Emsisoft 5.1.0.11 2011.11.24 - eSafe 7.0.17.0 2011.11.24 - eTrust-Vet 37.0.9586 2011.11.24 - F-Prot 4.6.5.141 2011.11.24 - F-Secure 9.0.16440.0 2011.11.24 - Fortinet 4.3.370.0 2011.11.24 - GData 22 2011.11.24 - Ikarus T3.1.1.109.0 2011.11.24 - Jiangmin 13.0.900 2011.11.24 - K7AntiVirus 9.119.5534 2011.11.24 - Kaspersky 9.0.0.837 2011.11.24 - McAfee 5.400.0.1158 2011.11.24 - McAfee-GW-Edition 2010.1D 2011.11.24 - Microsoft 1.7801 2011.11.24 - NOD32 6657 2011.11.24 - Norman 6.07.13 2011.11.24 - nProtect 2011-11-24.02 2011.11.24 - Panda 10.0.3.5 2011.11.24 - PCTools 8.0.0.5 2011.11.24 - Prevx 3.0 2011.11.24 - Rising 23.85.03.02 2011.11.24 - Sophos 4.71.0 2011.11.24 - SUPERAntiSpyware 4.40.0.1006 2011.11.24 - Symantec 20111.2.0.82 2011.11.24 - TheHacker 6.7.0.1.347 2011.11.24 - TrendMicro 9.500.0.1008 2011.11.24 - TrendMicro-HouseCall 9.500.0.1008 2011.11.24 - VBA32 3.12.16.4 2011.11.24 - VIPRE 11137 2011.11.24 - ViRobot 2011.11.24.4791 2011.11.24 - VirusBuster 14.1.83.1 2011.11.24 - Additional informationShow all MD5 : 7e1c1e31080b73c46346db46e94f71a6 SHA1 : 52af2ce272ce0c6d46a93b92e4601baf075c4e5e SHA256: 3d61f8c1419f2d0205e02869caa7f54292d8b817a639185c0ff3985ccbc355eb ssdeep: 192:j6nTeH+mKCFwg5YVkvrQX/px60yyC+5MlhJwx35EME64Oo7SWmrjoxo9+Nxj:jOTeHpFh5O kTcpByG3YAj4o9Mxj File size : 28672 bytes First seen: 2009-04-01 15:42:57 Last seen : 2011-11-24 20:29:52 TrID: Win32 Executable Generic (42.3%) Win32 Dynamic Link Library (generic) (37.6%) Generic Win/DOS Executable (9.9%) DOS Executable Generic (9.9%) Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%) sigcheck: publisher….: copyright….: Copyright 2004 product……: RegHero Module description..: RegHero Module original name: RegHero.EXE internal name: RegHero file version.: 1, 0, 0, 1 comments…..: n/a signers……: - signing date.: - verified…..: Unsigned PEInfo: PE structure information [[ basic data ]] entrypointaddress: 0x1000 timedatestamp….: 0x40E5BF4F (Fri Jul 02 20:02:23 2004) machinetype……: 0x14c (I386) [[ 4 section(s) ]] name, viradd, virsiz, rawdsiz, ntropy, md5 .text, 0x1000, 0x207C, 0x3000, 5.00, 31d8dd10e9e1c0a587d2d2227b04ec19 .rdata, 0x4000, 0x4F2, 0x1000, 1.96, e67679f8202b9112bad188d27bd22a2e .data, 0x5000, 0x788, 0x1000, 0.88, e98fc733e382c4c83784f856084c0e72 .rsrc, 0x6000, 0x988, 0x1000, 2.43, 923747f263971e14d2a1f9a1c816e729 [[ 6 import(s) ]] KERNEL32.dll: lstrcmpiA, GetCurrentThreadId, GetSystemInfo, GetVersionExA, HeapCreate, Sleep, CreateEventA, CreateThread, WaitForSingleObject, CloseHandle, GetModuleHandleA, GetStringTypeA, LCMapStringW, LCMapStringA, MultiByteToWideChar, WideCharToMultiByte, GetOEMCP, GetACP, HeapAlloc, GetCommandLineA, ExitProcess, GetStartupInfoA, GetStringTypeW, GetCPInfo, RtlUnwind USER32.dll: PostThreadMessageA, CharNextA ADVAPI32.dll: RegSetValueExA, RegEnumKeyExA, RegOpenKeyExA, RegCreateKeyExA, RegEnumValueA, RegCloseKey ole32.dll: CoUninitialize, CoInitialize SHLWAPI.dll: SHDeleteKeyA ATL.DLL: -, -, -, -, -, -, - ExifTool: file metadata CharacterSet: Unicode CodeSize: 12288 CompanyName: EntryPoint: 0x1000 FileDescription: RegHero Module FileFlagsMask: 0x003f FileOS: Win32 FileSize: 28 kB FileSubtype: 0 FileType: Win32 EXE FileVersion: 1, 0, 0, 1 FileVersionNumber: 1.0.0.1 ImageVersion: 0.0 InitializedDataSize: 12288 InternalName: RegHero LanguageCode: English (U.S.) LegalCopyright: Copyright 2004 LinkerVersion: 6.0 MIMEType: application/octet-stream MachineType: Intel 386 or later, and compatibles OLESelfRegister: OSVersion: 4.0 ObjectFileType: Executable application OriginalFilename: RegHero.EXE PEType: PE32 ProductName: RegHero Module ProductVersion: 1, 0, 0, 1 ProductVersionNumber: 1.0.0.1 Subsystem: Windows GUI SubsystemVersion: 4.0 TimeStamp: 2004:07:02 22:02:23+02:00 UninitializedDataSize: 0
Hi Lewg, Thanks for the scans. How is the computer running now? Is the internet still sluggish? Have you updated Java and Internet Explorer yet?
Great to hear that!

I'd like you to run one more tool.

Please download ComboFix from one of the following locations:

Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here

  • Double click on ComboFix.exe & follow the prompts.
  • Accept the disclaimer and allow to update if it asks

    [external image: Posted Image]

    [external image: Posted Image]
  • When finished, it shall produce a log for you.
  • Please include the C:\ComboFix.txt in your next reply.

Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
Let me mention, I always leave my desktop PC running. I just log on and log off my system. Occasionally I reboot the machine…..This AM I logged on and clicked on my temporary desktop icon for WTT. It took almost 3 minutes to get the site up……This is what I mean about being slow getting to the Internet. The strange thing about this situtation is, the wireless laptop I have sitting nearby can access the Internet quickly without a problem…..Below is the Combofix Log……also let me add, It took approx 30 seconds after clicking on "Add Reply" to send you the Combofix log. I am curious, what are you looking for in the Combofix Log? This slow activity to the net has just started last week on my Desktop.

Thanks! :)


ComboFix 11-11-25.01 - Compaq_Administrator 11/25/2011 8:44.5.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.958.434 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Administrator\WINDOWS
c:\documents and settings\All Users\Application Data\TEMP
c:\documents and settings\All Users\Application Data\TEMP\{479F8C12-576B-4A58-AB78-4B70F7012AA8}\PostBuild.exe
c:\documents and settings\All Users\Application Data\TEMP\{516A7A9D-5659-4DF1-ADCA-3AB2770664F6}\PostBuild.exe
c:\documents and settings\All Users\Application Data\TEMP\{E9B10AA5-E5F6-4DEF-A435-FB20704AF1E8}\PostBuild.exe
c:\documents and settings\Compaq_Administrator\Application Data\PriceGong
c:\documents and settings\Compaq_Administrator\Application Data\PriceGong\Data\1.xml
c:\documents and settings\Compaq_Administrator\Application Data\PriceGong\Data\a.xml
c:\documents and settings\Compaq_Administrator\Application Data\PriceGong\Data\b.xml
c:\documents and settings\Compaq_Administrator\Application Data\PriceGong\Data\c.xml
c:\documents and settings\Compaq_Administrator\Application Data\PriceGong\Data\d.xml
c:\documents and settings\Compaq_Administrator\Application Data\PriceGong\Data\e.xml
c:\documents and settings\Compaq_Administrator\Application Data\PriceGong\Data\f.xml
c:\documents and settings\Compaq_Administrator\Application Data\PriceGong\Data\g.xml
c:\documents and settings\Compaq_Administrator\Application Data\PriceGong\Data\h.xml
c:\documents and settings\Compaq_Administrator\Application Data\PriceGong\Data\i.xml
c:\documents and settings\Compaq_Administrator\Application Data\PriceGong\Data\J.xml
c:\documents and settings\Compaq_Administrator\Application Data\PriceGong\Data\k.xml
c:\documents and settings\Compaq_Administrator\Application Data\PriceGong\Data\l.xml
c:\documents and settings\Compaq_Administrator\Application Data\PriceGong\Data\m.xml
c:\documents and settings\Compaq_Administrator\Application Data\PriceGong\Data\mru.xml
c:\documents and settings\Compaq_Administrator\Application Data\PriceGong\Data\n.xml
c:\documents and settings\Compaq_Administrator\Application Data\PriceGong\Data\o.xml
c:\documents and settings\Compaq_Administrator\Application Data\PriceGong\Data\p.xml
c:\documents and settings\Compaq_Administrator\Application Data\PriceGong\Data\q.xml
c:\documents and settings\Compaq_Administrator\Application Data\PriceGong\Data\r.xml
c:\documents and settings\Compaq_Administrator\Application Data\PriceGong\Data\s.xml
c:\documents and settings\Compaq_Administrator\Application Data\PriceGong\Data\t.xml
c:\documents and settings\Compaq_Administrator\Application Data\PriceGong\Data\u.xml
c:\documents and settings\Compaq_Administrator\Application Data\PriceGong\Data\v.xml
c:\documents and settings\Compaq_Administrator\Application Data\PriceGong\Data\w.xml
c:\documents and settings\Compaq_Administrator\Application Data\PriceGong\Data\x.xml
c:\documents and settings\Compaq_Administrator\Application Data\PriceGong\Data\y.xml
c:\documents and settings\Compaq_Administrator\Application Data\PriceGong\Data\z.xml
c:\documents and settings\Compaq_Administrator\WINDOWS
c:\documents and settings\Default User\WINDOWS
c:\documents and settings\Guest\WINDOWS
c:\documents and settings\UpdatusUser\WINDOWS
c:\windows\CSC\d6
c:\windows\HPCPCUninstaller-6.3.2.116-5577497.exe
c:\windows\system32\config\systemprofile\WINDOWS
c:\windows\system32\Thumbs.db
.
.
((((((((((((((((((((((((( Files Created from 2011-10-25 to 2011-11-25 )))))))))))))))))))))))))))))))
.
.
2011-11-24 21:42 . 2011-11-24 21:42 ——– d—–w- c:\documents and settings\Compaq_Administrator\Local Settings\Application Data\Sun
2011-11-24 20:55 . 2011-11-24 20:58 ——– dc-h–w- c:\windows\ie8
2011-11-24 20:49 . 2011-08-16 10:45 6144 ——w- c:\windows\system32\dllcache\iecompat.dll
2011-11-24 20:47 . 2011-08-22 23:48 743424 ——w- c:\windows\system32\dllcache\iedvtool.dll
2011-11-24 20:47 . 2011-08-22 23:48 247808 ——w- c:\windows\system32\dllcache\ieproxy.dll
2011-11-24 15:50 . 2011-10-07 03:48 6668624 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{223EC48C-A4D5-4D6B-8898-665ED563F252}\mpengine.dll
2011-11-21 01:11 . 2011-11-21 01:11 ——– d—–w- c:\documents and settings\Compaq_Administrator\Application Data\Roxio
2011-11-21 00:58 . 2011-11-21 00:58 ——– d—–w- c:\program files\Common Files\SureThing Shared
2011-11-21 00:57 . 2011-11-21 01:13 ——– d—–w- c:\program files\Roxio
2011-11-20 22:01 . 2011-11-20 22:01 ——– d—–w- c:\documents and settings\All Users\Application Data\Uninstall
2011-11-20 22:00 . 2011-11-21 00:57 ——– d—–w- c:\program files\Common Files\Roxio Shared
2011-11-01 18:54 . 2011-11-01 18:54 ——– d—–w- C:\lj628
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-11-24 21:22 . 2010-08-17 04:53 128000 —-a-w- c:\windows\system32\javacpl.cpl
2011-11-24 21:22 . 2010-08-17 04:53 544656 —-a-w- c:\windows\system32\deployJava1.dll
2011-11-06 05:48 . 2011-07-09 13:27 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-10-10 14:22 . 2004-08-09 21:00 692736 —-a-w- c:\windows\system32\inetcomm.dll
2011-10-07 03:48 . 2011-07-16 14:34 6668624 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-09-28 07:06 . 2004-08-09 21:00 599040 —-a-w- c:\windows\system32\crypt32.dll
2011-09-26 15:41 . 2008-07-29 23:59 611328 —-a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 15:41 . 2004-08-09 21:00 220160 —-a-w- c:\windows\system32\oleacc.dll
2011-09-26 15:41 . 2004-08-09 21:00 20480 —-a-w- c:\windows\system32\oleaccrc.dll
2011-09-06 13:20 . 2004-08-09 21:00 1858944 —-a-w- c:\windows\system32\win32k.sys
2011-08-31 21:00 . 2008-05-31 18:04 22216 -c–a-w- c:\windows\system32\drivers\mbam.sys
2011-09-12 17:33 . 2011-09-12 17:33 119808 —-a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2011-11-07 4617600]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"KBD"="c:\hp\KBD\KBD.EXE" [2005-02-02 61440]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 997920]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2011-05-25 13895272]
"Microsoft Default Manager"="c:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2010-05-10 439568]
.
c:\documents and settings\Default User\Start Menu\Programs\Startup\
Pin.lnk - c:\hp\bin\CLOAKER.EXE [2006-5-4 27136]
.
c:\documents and settings\Compaq_Administrator\Start Menu\Programs\Startup\
WKCALREM.LNK - c:\program files\Common Files\Microsoft Shared\Works Shared\WkCalRem.exe [2004-6-23 15360]
.
c:\documents and settings\Compaq_Administrator\Start Menu\Programs\Startup\AutorunsDisabled
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
wkcalrem.lnk.disabled [2007-9-12 938]
wordweb.lnk.disabled [2007-8-3 1601]
.
c:\documents and settings\UpdatusUser\Start Menu\Programs\Startup\
Pin.lnk.disabled [2005-8-17 572]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2011-07-19 113024]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2011-05-04 17:54 551296 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ SDEarlyDelete \??\0autocheck autochk *
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AVG Anti-Spyware Driver]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AVG Anti-Spyware Guard]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk.disabled]
backup=c:\windows\pss\Adobe Reader Speed Launch.lnk.disabledCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Compaq Connections.lnk.disabled]
backup=c:\windows\pss\Compaq Connections.lnk.disabledCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk.disabled]
backup=c:\windows\pss\HP Digital Imaging Monitor.lnk.disabledCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"LiveUpdate Notice Service"=2 (0x2)
"LiveUpdate Notice Ex"=2 (0x2)
"LiveUpdate"=3 (0x3)
"ISPwdSvc"=3 (0x3)
"comHost"=3 (0x3)
"CLTNetCnService"=2 (0x2)
"Automatic LiveUpdate Scheduler"=2 (0x2)
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" /background
"ctfmon.exe"=c:\windows\system32\ctfmon.exe
"updateMgr"="c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9
"PCPal"=c:\program files\PCPal\PalAgnt.exe /startup
"swg"=c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
"AVG8_TRAY"=c:\progra~1\AVG\AVG8\avgtray.exe
"SmartRAM"=e:\advanced windowscare v2\MemCleaner.exe /m
"MediaGet2"=c:\documents and settings\Compaq_Administrator\Local Settings\Application Data\MediaGet2\mediaget.exe –minimized
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
""=
"KBD"=c:\hp\KBD\KBD.EXE
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" -osboot
"AlwaysReady Power Message APP"=ARPWRMSG.EXE
"DISCover"=c:\program files\DISC\DISCover.exe
"nwiz"=nwiz.exe /install
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" -atboottime
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
"ISUSPM Startup"=c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
"ehTray"=c:\windows\ehome\ehtray.exe
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe"
"NvCplDaemon"=RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe"
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 10.0\Reader\Reader_sl.exe"
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"COMODO Firewall Pro"="c:\program files\COMODO\Firewall\cfp.exe" -h
"NvMediaCenter"=RunDLL32.exe NvMCTray.dll,NvTaskbarInit -login
"HPDJ Taskbar Utility"=c:\windows\system32\spool\drivers\w32x86\3\hpztsb09.exe
"HP Software Update"=c:\program files\Hp\HP Software Update\HPWuSchd2.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\DISC\\DISCover.exe"=
"c:\\Program Files\\DISC\\DiscStreamHub.exe"=
"c:\\Program Files\\DISC\\myFTP.exe"=
"c:\\Program Files\\Compaq Connections\\5577497\\Program\\Compaq Connections.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\DirecTV\\DirecTV\\DIRECTV2PC™.exe"=
"c:\\WINDOWS\\system32\\fxsclnt.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Google\\Google Earth\\plugin\\geplugin.exe"=
"c:\\Program Files\\NVIDIA Corporation\\NVIDIA Updatus\\daemonu.exe"=
.
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [07/22/2011 11:27 AM 12880]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [07/12/2011 4:55 PM 67664]
R2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCore.exe [08/11/2011 6:38 PM 116608]
R2 CLDTVHNService;CLDTVHNService;c:\program files\DirecTV\DirecTV\Kernel\DMP\CLDTVHNService.exe [09/17/2009 5:40 PM 75048]
R2 ntk_dtv;ntk_dtv;c:\program files\DirecTV\DirecTV\Kernel\DMP\ntk_dtv.sys [09/17/2009 5:40 PM 119792]
R2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [05/14/2011 3:12 PM 2214504]
S1 MpKsl0c56d325;MpKsl0c56d325;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{901765C5-9C8D-498C-BCC7-71EED796FE73}\MpKsl0c56d325.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{901765C5-9C8D-498C-BCC7-71EED796FE73}\MpKsl0c56d325.sys [?]
S1 MpKsl57ecc620;MpKsl57ecc620;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{62C1D18D-2DCB-43B4-861A-073C1D072B6A}\MpKsl57ecc620.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{62C1D18D-2DCB-43B4-861A-073C1D072B6A}\MpKsl57ecc620.sys [?]
S1 MpKsl7a5ee8a9;MpKsl7a5ee8a9;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{223EC48C-A4D5-4D6B-8898-665ED563F252}\MpKsl7a5ee8a9.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{223EC48C-A4D5-4D6B-8898-665ED563F252}\MpKsl7a5ee8a9.sys [?]
S1 MpKsldcfa87e0;MpKsldcfa87e0;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{9E9264E3-AE06-4F7C-B9F4-2B8DB8D4340E}\MpKsldcfa87e0.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{9E9264E3-AE06-4F7C-B9F4-2B8DB8D4340E}\MpKsldcfa87e0.sys [?]
S1 MpKsle21cd2d6;MpKsle21cd2d6;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{29639311-F66C-4078-8998-9C0825128A66}\MpKsle21cd2d6.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{29639311-F66C-4078-8998-9C0825128A66}\MpKsle21cd2d6.sys [?]
S2 gupdate1c9316637dc9d00;Google Update Service (gupdate1c9316637dc9d00);c:\program files\Google\Update\GoogleUpdate.exe [10/18/2008 4:12 PM 133104]
S3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [08/15/2007 8:31 AM 30192]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [10/18/2008 4:12 PM 133104]
S3 PCD5SRVC{8A863ACB-F5F6CC6A-05010003};PCD5SRVC{8A863ACB-F5F6CC6A-05010003} - PCDR Kernel Mode Service Helper Driver;c:\progra~1\PC-DOC~1\PCD5SRVC.pkms [02/07/2006 8:38 PM 21120]
.
Contents of the 'Scheduled Tasks' folder
.
2011-11-19 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]
.
2011-11-25 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2008-10-18 21:19]
.
2011-11-25 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2008-10-18 21:19]
.
2011-11-25 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Microsoft Security Client\Antimalware\MpCmdRun.exe [2011-04-27 19:39]
.
2007-11-22 c:\windows\Tasks\Spybot - Search & Destroy - Scheduled Task.job
- c:\program files\Spybot - Search & Destroy\SpybotSD.exe [2007-03-17 20:31]
.
2011-11-25 c:\windows\Tasks\User_Feed_Synchronization-{BC3AEFBE-E14D-4663-828F-914798DAD592}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 09:31]
.
.
——- Supplementary Scan ——-
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid;=ie7&rls;=com.microsoft:en-US&ie;=utf8&oe;=utf8
uStart Page = hxxp://msn.com/
uInternet Connection Wizard,ShellNext = iexplore
TCP: DhcpNameServer = 192.168.2.1
DPF: Garmin Communicator Plug-In - hxxps://static.garmincdn.com/gcp/ie/2.9.2.0/GarminAxControl.CAB
FF - ProfilePath - c:\documents and settings\Compaq_Administrator\Application Data\Mozilla\Firefox\Profiles\w14redor.default\
FF - prefs.js: browser.startup.homepage - hxxp://mirostart.com/?cfg=2-365-0-2Miqs
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - user.js: general.useragent.extra.brc - BRI/1
.
- - - - ORPHANS REMOVED - - - -
.
BHO-{A3BC75A2-1F87-4686-AA43-5347D756017C} - (no file)
HKLM-Run-nwiz - nwiz.exe
Notify-WgaLogon - (no file)
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-11-25 08:54
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet003\Services\PCD5SRVC{8A863ACB-F5F6CC6A-05010003}]
"ImagePath"="\??\c:\progra~1\PC-DOC~1\PCD5SRVC.pkms"
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\S-1-5-21-3019693388-2064130007-760773113-1008\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(736)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll
.
- - - - - - - > 'explorer.exe'(4052)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
.
———————— Other Running Processes ————————
.
c:\program files\Microsoft Security Client\Antimalware\MsMpEng.exe
c:\windows\arservice.exe
c:\windows\eHome\ehRecvr.exe
c:\windows\eHome\ehSched.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Common Files\Motive\McciCMService.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\nvsvc32.exe
c:\windows\system32\HPZipm12.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\windows\ehome\mcrdsvc.exe
c:\windows\system32\dllhost.exe
.
**************************************************************************
.
Completion time: 2011-11-25 09:03:40 - machine was rebooted
ComboFix-quarantined-files.txt 2011-11-25 14:03
.
Pre-Run: 202,387,337,216 bytes free
Post-Run: 202,274,312,192 bytes free
.
- - End Of File - - 2D3E33ACAE94CF662FADFC940FADA1FB
Hi Lewg, That is very odd. Is the computer still slow at getting to the internet after running ComboFix? Which browser are you using? Is the internet slow across all browsers? I had you run ComboFix to see if it would pick up any malware that I could not see. It removed a good amount.
After Combofix rebooted the machine and I sent you the reply…..I was able to move around the internet OK…However after shutting down the Laptop and the Desktop, I wanted to start up only the Desktop to see if my problem was fixed. Apparently I am still having a problem, I could not get to the Interenet..After several minutes, a page that IE puts up says "The Internet cannot display the web page"…It also displays a diagnosis Icon that will run a diagnosis and you can view the log. Below is the log. All sections looked OK and in the Green, except the last section which is in Red. See the HTTP, HTTPS, FTP Diagnostic HTTP, HTTPS, FTP connectivity Section at the bottom of the Log….. My Router checks out OK per the Belkin Tech, and my DSL Modem shows no problem…….This problem is driving me nuts! :) Last diagnostic run time: 11/25/11 12:34:51 HTTP, HTTPS, FTP Diagnostic HTTP, HTTPS, FTP connectivity info HTTP: Successfully connected to www.microsoft.com. info FTP (Passive): Successfully connected to ftp.microsoft.com. info HTTPS: Successfully connected to www.microsoft.com. DNS Client Diagnostic DNS - Not a home user scenario info Using Web Proxy: no info Resolving name ok for (www.microsoft.com): yes No DNS servers DNS failure Gateway Diagnostic Gateway info The following proxy configuration is being used by IE: Automatically Detect Settings:Disabled Automatic Configuration Script: Proxy Server: Proxy Bypass list: info This computer has the following default gateway entry(ies): 192.168.2.1 info This computer has the following IP address(es): 192.168.2.5 info The default gateway is in the same subnet as this computer info The default gateway entry is a valid unicast address info The default gateway address was resolved via ARP in 1 try(ies) info The default gateway was reached via ICMP Ping in 1 try(ies) info TCP port 80 on host [removed] was successfully reached info The Internet host www.microsoft.com was successfully reached info The default gateway is OK IP Layer Diagnostic Corrupted IP routing table info The default route is valid info The loopback route is valid info The local host route is valid info The local subnet route is valid Invalid ARP cache entries action The ARP cache has been flushed IP Configuration Diagnostic Invalid IP address info Valid IP address detected: 192.168.2.5 Wireless Diagnostic Wireless - Service disabled Wireless - User SSID Wireless - First time setup Wireless - Radio off Wireless - Out of range Wireless - Hardware issue Wireless - Novice user Wireless - Ad-hoc network Wireless - Less preferred Wireless - 802.1x enabled Wireless - Configuration mismatch Wireless - Low SNR WinSock Diagnostic WinSock status info All base service provider entries are present in the Winsock catalog. info The Winsock Service provider chains are valid. info Provider entry MSAFD Tcpip [TCP/IP] passed the loopback communication test. info Provider entry MSAFD Tcpip [UDP/IP] passed the loopback communication test. info Provider entry RSVP UDP Service Provider passed the loopback communication test. info Provider entry RSVP TCP Service Provider passed the loopback communication test. info Connectivity is valid for all Winsock service providers. Network Adapter Diagnostic Network location detection info Using home Internet connection Network adapter identification info Network connection: Name=1394 Connection, Device=1394 Net Adapter, MediaType=LAN, SubMediaType=1394 info Network connection: Name=Local, Device=NVIDIA nForce Networking Controller, MediaType=LAN, SubMediaType=LAN info Ethernet connection selected Network adapter status info Network connection status: Connected HTTP, HTTPS, FTP Diagnostic HTTP, HTTPS, FTP connectivity warn HTTP: Error 12029 connecting to www.microsoft.com: A connection with the server could not be established warn HTTPS: Error 12029 connecting to www.microsoft.com: A connection with the server could not be established warn HTTP: Error 12039 connecting to www.hotmail.com: A redirect request will change a non-secure to a secure connection warn FTP (Passive): Error 12031 connecting to ftp.microsoft.com: The connection with the server was reset info FTP (Active): Successfully connected to ftp.microsoft.com. warn HTTPS: Error 12029 connecting to www.passport.net: A connection with the server could not be established error Could not make an HTTP connection. error Could not make an HTTPS connection.
Hi Lewg,

Believe me, this is driving me nuts as well :)

Give this a shot:

I need you to make a batch file.

Open a new Notepad session

  • Click the Start button, click Run
  • In the run box type notepad
  • Click OK
  • In the notepad, Click "Format" and be certain that Word Wrap is not checked.
  • Copy and paste all the text in the code box below into the Notepad. Do Not copy the word CODE
@Echo on
ipconfig /release
ipconfig /renew
ipconfig /flushdns
netsh winsock reset all
netsh int ip reset all
shutdown -r -t 1
del %0

In the notepad

Click File, Save as…, and set the Save in to your Desktop
In the filename box, type (including quotation marks) as the filename: "flush.bat"
Click Save


You should now have a file on your desktop with an icon like this [external image: Posted Image]


Double click on flush.bat & allow it to run. A small black screen may briefly flash on and off, that normal.
OK, ran the batch file, and noticed the black screen in and out. Not able to see just what was changed on the black screen…..Here is the Routers lastest log if that will help……My IP address for the Desktop is 192.168.2.5, My wireless HP printer is 192.168.2.4, and the Laptop is 192.168.2.3 User Login From 192.168.2.5 => Fri Nov 25 13:55:07 2011 Get IP Address 192.168.1.97 From DHCP Server => Thu Jan 1 00:00:24 1970 Firewall log: IN=vlan2 OUT=NONE SRC=192.168.1.254 DST=192.168.1.97 SPORT=ICMP DPORT=ICMP PROTO=ICMP Found AllIcmpFlood attack from 192.168.1.254 in port ICMP => Fri Nov 25 13:38:38 2011
I highly doubt the router is the problem if your laptop is able to access the internet without problems. Could you try using Firefox and see if you can access the internet from the desktop?
I don't know if this has anything to do with the slow approach to the net, but I just discovered on the task bar in the lower right side the zoom in/zoom out the page zoom was set at 125%. I don't know how this was changed, but it's now back to normal at 100%…..I am going to shut down the machine for 5 min and try the IE8 acessing the net…….I will post up results later….. I will try Firefox also…..I appreciate your ongoing help. :)
My machine flys with Firefox…..As for using IE8 Browser, it's now seems to be working better…..That's not to say if I turn off the machine again or just log off for the night the problem might still be on me…….If so I'm goint to do this :pullhair: I'm a old guy and take much more! :smack: :)
Hi Lewg,

My machine flys with Firefox…..As for using IE8 Browser, it's now seems to be working better…..

Glad to hear that :)

That's not to say if I turn off the machine again or just log off for the night the problem might still be on me…….If so I'm goint to do this :pullhair:

Hahaha well please let me know how it behaves the next time you restart. At this point, we can probably rule out malware as a problem because your logs are coming back clean. If you still have issues with IE, I would have to refer you to the Browsers, Internet, and Email forum because the staff over there are more qualified to deal with such issues.

I'm a old guy and take much more! :smack: :)

I understand.. Computers can be very frustrating at times :(

In the meantime, let's clean up the tools we used.

Please delete aswMBR and GMER from your desktop.

Clean up with OTL:
  • Double-click OTL.exe to start the program.
  • Close all other programs apart from OTL as this step will require a reboot
  • On the OTL main screen, press the CLEANUP button
  • Say Yes to the prompt and then allow the program to reboot your computer.
===================================================

Follow these steps to uninstall Combofix

  • Click START then RUN
  • Now copy/paste Combofix /uninstall into the runbox and click OK. Note the space between the ..X and the /U, it needs to be there.

[external image: Posted Image]

===================================================

Download TFC to your desktop
  • Open the file and close any other windows.
  • It will close all programs itself when run, make sure to let it run uninterrupted.
  • Click the Start button to begin the process. The program should not take long to finish its job
  • Once its finished it should reboot your machine, if not, do this yourself to ensure a complete clean
Morning, Well, I ran TFC as you requested. However I struggled with my machine this weekend, so let me say once I get to the Internet using Firefox, things seem to be OK, but still not up to par…….If my PC sits idle with the desktop showing for any length of time, I cannot get back on the internet. .Firefox times out…..I have to continue rebooting my PC in order to reach the internet If I log off, I have to reboot the PC again….It makes no difference using IE8 or Firefox. There has got to be a bug somewhere hanging on for dear life. After the PC had been sitting with me logged off all night, I tried to access the internet this AM using Firefox this is what came up on the screen. I have seen it many times. The connection has timed out The server at www.Google.com is taking to long to respond. The site could be temporarily unavailable or too busy. Try again in a few moments. If you are unable to load any pages, check your computer's network connection. If your computer or network is protected by a firewall or proxy, make sure that Firefox is permitted to access the Web. I don't know what's wrong, and I know it's driving you nuts as well…..So if you want to close our session, that's OK. :)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI