View Single Post
Old 04-05-2009, 05:17 PM   #15
syee
I subscribe to the Revscene NWS thread(s)
 
Join Date: Jan 2007
Location: Vancouver
Posts: 2,654
Thanked 331 Times in 242 Posts
Failed 11 Times in 6 Posts
Quote:
Originally Posted by Turbo E View Post
"R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = *.local"

this line jumps out at me but don't know what it means

did you try scanning in SAFE mode?
That line is probably for Bypass proxy when the resource is on the local netowrk. (It's in your Internet Options in IE/Connections/LAN Settings/Proxy Server.

It's not the issue here.

If anything, I think it's these two lines:
O4 - HKUS\S-1-5-19\..\Run: [pibusiweje] Rundll32.exe "CWINDOWS\system32\vokuharo.dll",s (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [pibusiweje] Rundll32.exe "CWINDOWS\system32\vokuharo.dll",s (User 'NETWORK SERVICE')

However, they look like they are tied to specific user logins (the HKUS which is the HKEY_USERS hive) so it may happen only to certain people.

Try renaming that file vokuharo.dll (may need to boot up to safe mode to do it if the file is in use), and then restart to see if that helps.

You have a lot of stuff in your Run key. Must take you forever to boot up that machine...

Last edited by syee; 04-05-2009 at 05:22 PM.
syee is offline   Reply With Quote