If you have any doubts start all then start a new thread to ask for help
do not tag on someone elses thread
replace the name of the dll marked in red with the one in your particular case and the full filename marked in red to delete in HJT etc
Please download Process Explorer by Systernals from
HERE
Also download KillBox by Option^Explicit from
HERE Then boot up in SAFE MODE the rest of this fix must be done in safe mode.
Unzip Process Explorer and double click on
procexp.exe
In the top section of the Process Explorer screen double click on
winlogon.exe to bring up the winlogon.exe properties screen. Click on the
Threads tab at the top.
Once you see this screen click on each instance of
pcftp.dll once and then click the
kill button.
After you have killed all of the
pcftp.dll's under winlogon click
OK.
also look for any .ini or bak files or other dll's with either the same name or the file name in reverse & kill them as well
Next double click on
explorer.exe and again click once on each instance of
pcftp.dll then click the
kill button.
also look for any .ini or bak files or reverse named dll's with either the same name or the file name in reverse & kill them as well
Click on the
Threads tab at the top.
Once you have done that cl
ick
OK again.
Next run HijackThis and place a check beside each of the following.
O2 - BHO: MSEvents Object - {44240BB5-BD7D-4D49-A1AA-8AB0F3D3CB44} -
C:\WINDOWS\security\pcftp.dll
O20 - Winlogon Notify: pcftp -
C:\WINDOWS\security\pcftp.dll
Now click
fix checked and close HijackThis.
Please copy the text in
BOLD below, and paste it into a blank notepad window.
Save it as
vundo.reg and in the save as type box choose
all files.
Once you have saved it
double click it and
allow it to merge with the registry.
REGEDIT4
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B8B55274-0F9A-41E5-9067-A3539BD9E860}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{44240BB5-BD7D-4D49-A1AA-8AB0F3D3CB44}]
[-HKEY_CLASSES_ROOT\CLSID\{581F22DA-7202-4F21-AEF3-114787156016}]
[-HKEY_CLASSES_ROOT\CLSID\{B8B55274-0F9A-41E5-9067-A3539BD9E860}]
[-HKEY_CLASSES_ROOT\CLSID\{44240BB5-BD7D-4D49-A1AA-8AB0F3D3CB44}]
[-HKEY_CLASSES_ROOT\MSEvents.MSEvents]
[-HKEY_CLASSES_ROOT\MSEvents.MSEvents.1]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSEvents.MSEvents]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSEvents.MSEvents.1]
now run killbox and paste The FIRST ONE of these lines into the box, select delete on reboot then press the red X button,say yes to the prompt but no to reboot now
then continue to paste the lines in in turn and follow the above procedure every time, If it says file is missing, or if it says unable to delete then make a note of the file name and let us know when you reply
C:\WINDOWS\security\pcftp.dll
then repeat by typing in the full name of of any of the reverse named .bak or .ini or other files that you discovered in step 1
after you have input the last file name then reboot
After your computer has rebooted please run Hijackthis again and post a new HijackThis log.
Edit:
Symantec do now have a fairly reliable tool to fix this one now so try the symantec tool first
http://securityresponse.symantec.com...oval.tool.html
If it doesn't work then use the fix above