"snelzcp.dll" & avast! BSODs

I don’t really know much about computers - more than the average person - but I’ve run into a couple of annoyances that just started happening a couple days ago:

  1. Every time I startup XP I get an error message saying:

“RUNDLL
Error loading C:\WINDOWS\snelzcp.dll
The specified module could not be found.”

I tried looking up snelzcp.dll, but as much as the internet knows, this “module” doesn’t exist.
I tracked this error message in the task manager to a rundll32.exe process, but does not specify the source file of this process. If there’s a virus on my computer disguised as a rundll32.exe, I can’t tell which of the many rundll32.exe’s is the virus.

  1. And then if my computer’s connected to the internet, before I even do anything my avast! catches 2 malware viruses trying to get in. And then every 5-15mins later the avast! catches the same 2 malwares again.

I’ve tried running virus scans, boot-time scans, and error-checks, but this stuff doesn’t stop - And sometimes avast! BSODs during the virus scan.

Check for malware with this

Malwarebytes Anti-Malware 1.50.1 http://filehippo.com/download_malwarebytes_anti_malware/
always update so you have the latest signatures before you scan
click on the remove selected button to quarantine anything found

post the scan log here

Hi shwa,

Do a full freefixer scan and attach the log txt file, particularly pay attention to recent changes. Get freefixer here:
http://www.freefixer.com/static/freefixersetup.exe

Also do a scan with http://www.backgroundtask.eu/Systeemscan/Setup.exe
http://www.backgroundtask.eu/Systeemscan/Index.php and read the scan info there (for XP and Vista)

Download the application 'Agics System Scan' Agics Systemscan 1.6.0.0. Install the application. Follow the instructions on the screen Agics systemscan 1.6.0.0 has been tested on Windows XP and Vista. Windows 7 support will soon be available. The files will be uploaded to the website using a ftp connection. Files will be automatically removed from our website in four hours.

Manual
Hold the Windows key and press R.
A RUNAutomatic screen comes up. Type Msinfo32 and press ENTER
A system info screen comes forward.
Go to File → Export
Give the file a name and save it somewhere where you can find the file.
Open the file created on this page and press SEND.
Processing can take several minutes,

quote source-link: http://www.computer-support.nl/

polonus

I tried the Malwarebytes first - it found some viruses, but the same annoyances are still happening.

And now I’m getting another error message that persistantly won’t go away:

“Just-In-Time Debugging
An exception 'Runtime Error has occured in Script.
However, no debuggers are registered that can debug this exception. Unable to JIT debug.”

(Malwarebytes log):

Malwarebytes’ Anti-Malware 1.50.1.1100
www.malwarebytes.org

Database version: 6526

Windows 5.1.2600 Service Pack 3
Internet Explorer 7.0.5730.13

05/07/2011 2:06:43 PM
mbam-log-2011-05-07 (14-06-43).txt

Scan type: Full scan (C:|)
Objects scanned: 282247
Time elapsed: 1 hour(s), 15 minute(s), 17 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 3
Registry Values Infected: 1
Registry Data Items Infected: 1
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings{100EB1FD-D03E-47FD-81F3-EE91287F9465} (Adware.ShopperReports) → Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats{E8BDFF85-F8C2-4281-8669-31253E646518} (Adware.Hotbar) → Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\ (Hijack.Zones) → Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Nbegisurasew (IPH.Trojan.Hiloti.B) → Value: Nbegisurasew → Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_ShowHelp (PUM.Hijack.StartMenu) → Bad: (0) Good: (1) → Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
c:\WINDOWS\owoburuy.dll (IPH.Trojan.Hiloti.B) → Quarantined and deleted successfully.

I tried the Malwarebytes first - it found some viruses, but the same annoyances are still happening.

And now I’m getting another error message that persistantly won’t go away:

“Just-In-Time Debugging
An exception 'Runtime Error has occured in Script.
However, no debuggers are registered that can debug this exception. Unable to JIT debug.”

Follow this guide from our expert malware remover Essexboy
http://forum.avast.com/index.php?topic=53253.0
( post the logs here in this topic and not in the guide )

To avoid using multiple post with copy and paste you have to attach the log`s
Lower left corner: Additional Options > Attach ( OTS log ) save log as ANSI

Essexboy will look at the logs when he arrive here later today…