You liar ! I am in contact with some of the admins on the BleepingComputer forum and they have indeed confirmed that you are NOT in training over there.

oops…soooorrrrrrrrrryyyy… :‘( :’( :‘( :’( :‘( :’( :cry: :-[ :-[ :-[ :-[ :-[ :-[

I warned you…

and never will be in training… Hasta la vista, baby

You should be ashamed of yourself for misrepresenting BleepingComputers and outright lying to the users of this forum and not only about being affiliated with BleepingComputers but claiming to be some sort of a malware removal expert which you are clearly not, should i even mention that the specialized malware removal tools that you are suggesting people to run can be just as dangerous as malware itself if misused ? I am requesting the avast team to ban you, this time permanently. And good luck trying to get into BleepingComputer malware school(or G2G) as they have been notified about you.

i have learnt a lesson now…from now on i will stay with my virus busting job and will not poke my nose in such remote cases…i understand i can kill a persons pc…very dangerous…

i dont think so, as you seem to have a brain (hmmm…brain) where what have been said to you simply do not attach… tomorrow you will continue as usuall…

thanks banning a liar like me darth :-[

com155’s blog(read the about me description on the right side): http://remove-virus-malwarekiller.blogspot.com/

why are u trying to make me ashamed out here darth??? >:( >:( >:( >:( >:( >:( >:(

You are shaming yourself. I am simply informing the users here of the truth about you.

No, he is not trying to embarrass you. You’re just embarrassed yourself.
Your blog has several errors that shows ignorance…

He’s trolling,can’t you see?
You are a member at the official forum of avast,these behaviors are not acceptable,i’ve warned you bunch of times VIA pm,and you continue.BYE.

Ahh, job well done here, good to see the truth win out.

Guess you already know now… :stuck_out_tongue:

ok tried the new fix and the aswmbr and still getting the same message anytime i click a link off of a google search here are the logs from ots after the fix and aswmbr also a malwarebytes log

On completion of this run can you let me know if the alerts are still happening

Start OTS. Copy/Paste the information in the quotebox below into the panel where it says “Paste fix here” and then click the Run Fix button.

 
[Unregister Dlls]
[Registry - Safe List]
< Internet Explorer Settings [HKEY_USERS\.DEFAULT\] > -> 
YN -> HKEY_USERS\.DEFAULT\: Main\\"XMLHTTP_UUID_Default" -> BD 0E 95 01 3B 31 A1 44 BB 43 1F 4A 1E 73 F4 62  [binary data]
< Internet Explorer Settings [HKEY_USERS\S-1-5-18\] > -> 
YN -> HKEY_USERS\S-1-5-18\: Main\\"XMLHTTP_UUID_Default" -> BD 0E 95 01 3B 31 A1 44 BB 43 1F 4A 1E 73 F4 62  [binary data]
< Internet Explorer Settings [HKEY_USERS\S-1-5-19\] > -> 
YN -> HKEY_USERS\S-1-5-19\: Main\\"XMLHTTP_UUID_Default" -> BD 0E 95 01 3B 31 A1 44 BB 43 1F 4A 1E 73 F4 62  [binary data]
< Internet Explorer Settings [HKEY_USERS\S-1-5-20\] > -> 
YN -> HKEY_USERS\S-1-5-20\: Main\\"XMLHTTP_UUID_Default" -> BD 0E 95 01 3B 31 A1 44 BB 43 1F 4A 1E 73 F4 62  [binary data]
< Internet Explorer Settings [HKEY_USERS\S-1-5-21-329068152-2077806209-1417001333-1003\] > -> 
YN -> HKEY_USERS\S-1-5-21-329068152-2077806209-1417001333-1003\: Main\\"XMLHTTP_UUID_Default" -> BD 0E 95 01 3B 31 A1 44 BB 43 1F 4A 1E 73 F4 62  [binary data]
YN -> HKEY_USERS\S-1-5-21-329068152-2077806209-1417001333-1003\: "ProxyEnable" -> 1
< FireFox Settings [Prefs.js] > -> C:\Documents and Settings\tammy Blackwell\Application Data\Mozilla\FireFox\Profiles\wcqt7r1n.default\prefs.js
YN -> network.proxy.http -> "127.0.0.1"
YN -> network.proxy.http_port -> 52889
< FireFox Extensions [User Folders] > -> 
YY -> XUL Cache   -> C:\Documents and Settings\tammy Blackwell\Application Data\Mozilla\Firefox\Profiles\wcqt7r1n.default\extensions\{2242aefd-9689-4a29-8e89-dd60c338f816}
< FireFox SearchPlugins [User Folders] > -> 
YY ->  search.xml -> C:\Documents and Settings\tammy Blackwell\Application Data\Mozilla\Firefox\Profiles\wcqt7r1n.default\searchplugins\search.xml
< BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
YN -> {02478D38-C3F9-4efb-9B51-7695ECA05670} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.]
YN -> {9D425283-D487-4337-BAB6-AB8354A81457} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.]
YN -> {c3721e85-f0ac-4b7e-ae4c-3e738011dc9d} [HKLM] -> [Somoto Toolbar]
YN -> {D4027C7F-154A-4066-A1AD-4243D8127440} [HKLM] -> [Ask Toolbar]
YN -> {FCBCCB87-9224-4B8D-B117-F56D924BEB18} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.]
< Internet Explorer ToolBars [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar
YN -> "{338B4DFE-2E2C-4338-9E41-E176D497299E}" [HKLM] -> [FileBulldog Toolbar]
YN -> "{9D425283-D487-4337-BAB6-AB8354A81457}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.]
YN -> "{c3721e85-f0ac-4b7e-ae4c-3e738011dc9d}" [HKLM] -> [Somoto Toolbar]
YN -> "{D4027C7F-154A-4066-A1AD-4243D8127440}" [HKLM] -> [Ask Toolbar]
< Internet Explorer ToolBars [HKEY_USERS\S-1-5-21-329068152-2077806209-1417001333-1003\] > -> HKEY_USERS\S-1-5-21-329068152-2077806209-1417001333-1003\Software\Microsoft\Internet Explorer\Toolbar\
YN -> WebBrowser\\"{9D425283-D487-4337-BAB6-AB8354A81457}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.]
< Internet Explorer Extensions [HKEY_USERS\S-1-5-21-329068152-2077806209-1417001333-1003\] > -> HKEY_USERS\S-1-5-21-329068152-2077806209-1417001333-1003\Software\Microsoft\Internet Explorer\Extensions\
YN -> CmdMapping\\"{898EA8C8-E7FF-479B-8935-AEC46303B9E5}" [HKLM] -> [Reg Error: Key error.]
< Winlogon\Notify settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\
YN -> AtiExtEvent -> Reg Error: Value error.
[Files/Folders - Created Within 30 Days]
NY ->  Freeze Tag -> C:\Documents and Settings\tammy Blackwell\Application Data\Freeze Tag
NY ->  3002 -> C:\WINDOWS\System32\3002
[Files/Folders - Modified Within 30 Days]
NY ->  776005517 -> C:\WINDOWS\System32\776005517
[Files - No Company Name]
NY ->  authz32.exe -> C:\WINDOWS\System32\authz32.exe
NY ->  shfolder32.exe -> C:\WINDOWS\System32\shfolder32.exe
NY ->  776005517 -> C:\WINDOWS\System32\776005517
[Custom Items]
:Files
ipconfig /flushdns /c
:end
[Empty Temp Folders]
[EmptyFlash]
[CreateRestorePoint]


The fix should only take a very short time. When the fix is completed a message box will popup telling you that it is finished. Click the Ok button and Notepad will open with a log of actions taken during the fix. Post that information back here

I will review the information when it comes back in.

Depending on what the fix contains, this process may take some time and your desktop icons might disappear or other uncommon behavior may occur.

This is no sign of malfunction, do not panic!

Thanks essexboy for joining this topic that was royally screwed by com155.

"XMLHTTP_UUID_Default" -> BD 0E 95 01 3B 31 A1 44 BB 43 1F 4A 1E 73 F4 62 [binary data]
Seem to have pinned this one down as the main culprit under IE settings

Thanks Essexboy.
Won’t avast team do anything about misleading information in the forum? :cry: