This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Wowfx.dll

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

So ive had this problem before but on a different computer and i dont remember how i got it off. i refuse to use the recovery because weve had to reinstall windows about 3 times on this laptop. So heres my Hijackthis log. Should i install combofix and post that aswell?




Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:41:15 PM, on 9/6/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Documents and Settings\All Users.WINDOWS\Application Data\gxgfelin\afspylan.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\lphcgm0j0e755.exe
C:\WINDOWS\system32\rundll32.exe
C:\Windows\system32\YUR1.exe
C:\WINDOWS\system32\ctfmon.exe
C:\DOCUME~1\TONY~2.NON\LOCALS~1\Temp\1.tmp.exe
C:\WINDOWS\system32\rylwxqdq.exe
C:\Program Files\MSA\MSA.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\DOCUME~1\TONY~2.NON\LOCALS~1\Temp\b.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://lycos.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [lphcgm0j0e755] C:\WINDOWS\system32\lphcgm0j0e755.exe
O4 - HKLM\..\Run: [084353f6] rundll32.exe "C:\WINDOWS\system32\yoggyavh.dll",b
O4 - HKLM\..\Run: [\YUR5.exe] C:\Windows\system32\YUR5.exe
O4 - HKLM\..\Run: [\YUR1.exe] C:\Windows\system32\YUR1.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Somefox] C:\DOCUME~1\TONY~2.NON\LOCALS~1\Temp\1.tmp.exe
O4 - HKCU\..\Run: [AppComUi] C:\WINDOWS\system32\rylwxqdq.exe
O4 - HKCU\..\Run: [\VIE4CAE.exe] C:\Windows\System32\VIE4CAE.exe
O4 - HKCU\..\Run: [\VIE4CAF.exe] C:\Windows\System32\VIE4CAF.exe
O4 - HKCU\..\Run: [\VIE4CB0.exe] C:\Windows\System32\VIE4CB0.exe
O4 - HKCU\..\Run: [\VIE4CB1.exe] C:\Windows\System32\VIE4CB1.exe
O4 - HKCU\..\Run: [Antivirus] C:\Program Files\MSA\MSA.exe
O4 - HKCU\..\Run: [\VIE4CB2.exe] C:\Windows\System32\VIE4CB2.exe
O4 - HKCU\..\Run: [\VIE17.exe] C:\Windows\System32\VIE17.exe
O4 - HKCU\..\Run: [\VIE18.exe] C:\Windows\System32\VIE18.exe
O4 - HKCU\..\Run: [\VIE19.exe] C:\Windows\System32\VIE19.exe
O4 - HKCU\..\Run: [\VIE1A.exe] C:\Windows\System32\VIE1A.exe
O4 - HKCU\..\Run: [\VIE1C.exe] C:\Windows\System32\VIE1C.exe
O4 - HKCU\..\Run: [\VIE2.exe] C:\Windows\System32\VIE2.exe
O4 - HKCU\..\Run: [\VIE1.exe] C:\Windows\System32\VIE1.exe
O4 - HKCU\..\Run: [\VIE3.exe] C:\Windows\System32\VIE3.exe
O4 - HKCU\..\Run: [\VIE4.exe] C:\Windows\System32\VIE4.exe
O4 - HKCU\..\Run: [\VIE1B.exe] C:\Windows\System32\VIE1B.exe
O4 - HKCU\..\Run: [\VIE1D.exe] C:\Windows\System32\VIE1D.exe
O4 - HKCU\..\Run: [\VIE1E.exe] C:\Windows\System32\VIE1E.exe
O4 - HKCU\..\Run: [\VIE20.exe] C:\Windows\System32\VIE20.exe
O4 - HKCU\..\Run: [\YUR21.exe] C:\Windows\system32\YUR21.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [\YUR5.exe] C:\Windows\system32\YUR5.exe
O4 - HKCU\..\Run: [\YUR1.exe] C:\Windows\system32\YUR1.exe
O4 - HKCU\..\Run: [InfoApp] C:\WINDOWS\system32\izcxcbyd.exe
O4 - HKLM\..\Policies\Explorer\Run: [vVKNnWIX7v] C:\Documents and Settings\All Users.WINDOWS\Application Data\gxgfelin\afspylan.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O20 - AppInit_DLLs: C:\WINDOWS\system32\wowfx.dll dslgmc.dll
O23 - Service: Broadcom Wireless LAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe

–
End of file - 5547 bytes
You don't actually say what you problems is, apart from entitling the thread Wowfx.dll. What I see from your log is that you are only running Spybot Search and Destroy on your computer, which is woefully inadequate. Given what I can identify in your log, and you've got a number of entries that I don't like, the best advice I can offer is to reformat and reinstall Windows. Your machine is basically a slime magnet and there is no way to know what has been installed, corrupted, or altered and that makes working it a waste of time. I can offer you some links to free software if you wish, that should make your machine more secure in the future.
There are a few free firewalls available.
Comodo Firewall Pro, available here.
PC Tools Firewall Plus, available here.
Online Armor Free, available here.

It is important to note that you should only have one firewall installed at a time, but you can download them all to your Desktop and install each in turn to see which one you prefer.

Understanding and Using Firewalls: http://www.bleepingcomputer.com/tutorials/tutorial60.html

The free AVs are as follows:
Avg Free Edition: Available here.
avast! 4 Home Edition: Available here
AntiVir PersonalEdition Classic :Available here

Don't forget, just one AV at a time.

Although it is a matter of personal choice, I use AVG on one lappy and AntiVir on another. AVG is getting a little bloated and you may find that an old PC won't have the processor for that, so Anti-Vir could be a better option as it's lighter on resources.
I use both Comodo and PC Tools firewalls, but I don't have any preference. I installed PC Tools at the time as Comodo wasn't compatible with Vista when I bought the machine, but both machines work happily so I don't look too closely. :blush:

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI