| | |
| Thread Tools |
25-Jun-2004, 08:50 AM
#16 | |||||
| First Click here to download CWShredder. UnZip the file, but don't run it yet. Have it ready to run later. Click here to download CWShredder. Close all browser windows,UnZip the file, but don't run it yet. Also I have attached a batch file inside hiving_154.zip. Download the file and then immediately sign off the internet and stay off until all steps are finished. Extract the batch (hiving.bat) file from the hiving_154.zip and run it. If you have script blocking enabled you will get a warning. Please allow this to run. The script is just producing a message box. Double click on the batch to run it. After a reboot the super hidden nasty file will no longer be loaded and will be visible. This will end the constant reinstall of about:Blank. Restart your computer. ---------------------- Go to Folder Options> View Scroll to the bottom of the list to find the box labeled: Use Simple File Sharing(Recommended) Remove the check from that box and press ok. find this file: C:\WINDOWS\System32\LOGL.DLL Use the security tab on LOGL.DLL and take ownership. Change the 'everyone special' to 'you> with Admin rights-> FULL control Then try to delete it, if that fails try to rename it first to different name+ext. (Right click the file and choose "Rename") Example: change the name of LOGL.DLL to bleh.txt bleh.txt to badfile.111 Once you have successfully deleted the file restart into Regular Windows mode. Extract and Run CWShredder immediately. Press the fix button to clean. Restart and run hijackThis again. Post your new log here in your next reply.
__________________ If I have helped solve your problem, please Click Here and make a donation to help keep this great site running. 100% goes directly to this site. |
| |
|
30-Jun-2004, 11:52 PM
#17 |
| Kewl! Found the Logl.dll file, baleeted it, and ran CWShredder. All the entries were not infected but it did clean up the orphan files. Then rebooted and ran Hijack these and Find All. Here are the files: Hijack This Find All |
01-Jul-2004, 12:22 AM
#18 | |||||
| Logfile of HijackThis v1.97.7 Scan saved at 9:46:37 PM, on 6/30/2004 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\PROGRA~1\NORTON~1\NORTON~1\navapw32.exe C:\PROGRA~1\NORTON~1\WinFax\WFXSWTCH.exe C:\WINDOWS\System32\wfxsnt40.exe C:\Program Files\Iomega\DriveIcons\ImgIcon.exe C:\PROGRA~1\DAP\DAP.EXE C:\WINDOWS\System32\CTHELPER.EXE C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\WINDOWS\System32\ctfmon.exe C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe C:\Program Files\Creative\SBAudigy\TaskBar\CTLTray.exe C:\Program Files\Creative\SBAudigy\TaskBar\CTLTask.exe C:\WINDOWS\system32\CTSVCCDA.EXE C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe C:\WINDOWS\System32\tcpsvcs.exe C:\WINDOWS\System32\snmp.exe C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\MsPMSPSv.exe C:\Hijack This\HijackThis.exe N1 - Netscape 4: user_pref("browser.startup.homepage", "http://registration.excite.com/excitereg/login.jsp?app=em&return_url=http://e6.email.excite.com/"); (C:\Program Files\Netscape\Users\someguy\prefs.js) O2 - BHO: (no name) - {0000CC75-ACF3-4cac-A0A9-DD3868E06852} - C:\Program Files\DAP\DAPBHO.dll O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\windows\googletoolbar1.dll O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O3 - Toolbar: DAP Bar - {62999427-33FC-4baf-9C9C-BCE6BD127F08} - C:\Program Files\DAP\DAPIEBar.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\windows\googletoolbar1.dll O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\NORTON~1\navapw32.exe O4 - HKLM\..\Run: [WFXSwtch] C:\PROGRA~1\NORTON~1\WinFax\WFXSWTCH.exe O4 - HKLM\..\Run: [WinFaxAppPortStarter] wfxsnt40.exe O4 - HKLM\..\Run: [Iomega Startup Options] C:\Program Files\Iomega\Common\ImgStart.exe O4 - HKLM\..\Run: [Iomega Drive Icons] C:\Program Files\Iomega\DriveIcons\ImgIcon.exe O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE O4 - HKLM\..\Run: [CTStartup] C:\Program Files\Creative\Splash Screen\CTEaxSpl.EXE /run O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [DownloadAccelerator] C:\PROGRA~1\DAP\DAP.EXE /STARTUP O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE O4 - HKLM\..\Run: [Disc Detector] C:\Program Files\Creative\ShareDLL\CtNotify.exe O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe O4 - HKCU\..\Run: [SpySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe /0 O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit O4 - HKCU\..\Run: [TaskTray] "C:\Program Files\Creative\SBAudigy\TaskBar\CTLTray.exe" O4 - HKCU\..\Run: [TaskBar] "C:\Program Files\Creative\SBAudigy\TaskBar\CTLTask.exe" O4 - HKCU\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\Symantec\LIVEUP~1\SNDMon.EXE O8 - Extra context menu item: &Download with &DAP - C:\PROGRA~1\DAP\dapextie.htm O8 - Extra context menu item: &Google Search - res://c:\windows\GoogleToolbar1.dll/cmsearch.html O8 - Extra context menu item: Backward &Links - res://c:\windows\GoogleToolbar1.dll/cmbacklinks.html O8 - Extra context menu item: Cac&hed Snapshot of Page - res://c:\windows\GoogleToolbar1.dll/cmcache.html O8 - Extra context menu item: Download &all with DAP - C:\PROGRA~1\DAP\dapextie2.htm O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O8 - Extra context menu item: Si&milar Pages - res://c:\windows\GoogleToolbar1.dll/cmsimilar.html O8 - Extra context menu item: Translate into English - res://c:\windows\GoogleToolbar1.dll/cmtrans.html O9 - Extra button: Run DAP (HKLM) O9 - Extra button: Messenger (HKLM) O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM) O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll O16 - DPF: Yahoo! Chat - http://us.chat1.yimg.com/us.yimg.com.../c381/chat.cab O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/SU/ocx/12119/CTSUEng.cab O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/s...ctor/swdir.cab O16 - DPF: {27527D31-447B-11D5-A46E-0001023B4289} (CoGSManager Class) - http://gamingzone.ubisoft.com/dev/pa.../GSManager.cab O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://cs5.chat.sc5.yahoo.com/v45/yacscom.cab O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/ca...C_1_0_0_42.cab O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/20e9126e...p/RdxIE601.cab O16 - DPF: {8EDAD21C-3584-4E66-A8AB-EB0E5584767D} - http://toolbar.google.com/data/GoogleActivate.cab O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.co...875.0239467593 O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.symantec.com/sscv6/S.../bin/cabsa.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload.macromedia.com/pub...sh/swflash.cab O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/SU/ocx/12119/CTPID.cab --==***@@@ 'FIND-ALL' »»*Original*»» VERSION *9.3 -6/07 @@@***==-- Wed Jun 30 21:47:28 2004 -- ++Results: »»System Info: Microsoft Windows XP [Version 5.1.2600] 'Find-All' is running from Drive: C: "Primary" (DCE7:99F0) - FS:NTFS clusters:4k Total: 120 023 252 992 [112G] - Free: 1 630 961 664 [1.5G] »»IE version and Service packs: 6.0.2800.1106 C:\Program Files\Internet Explorer\Iexplore.exe --a-- W32i APP ENU 6.0.2800.1106 shp 91,136 08-29-2002 iexplore.exe ! REG.EXE VERSION 2.0 HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings MinorVersion REG_SZ ;SP1;Q818529;Q330994;Q822925;Q828750;Q832894; »»Google: »»UserAgent: REGEDIT4 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform] »»Wmplayer version: 9.0.0.2980 C:\Program Files\Windows Media Player\wmplayer.exe --a-- W32i APP ENU 9.0.0.2980 shp 73,728 12-11-2002 wmplayer.exe 6.4.9.1125 C:\Program Files\Windows Media Player\mplayer2.exe --a-- W32i APP ENU 6.4.9.1125 shp 4,639 08-29-2002 mplayer2.exe »»M$Java version: 5.0.3810.0 C:\WINDOWS\System32\msjava.dll --a-- W32i DLL ENU 5.0.3810.0 shp 947,472 02-28-2003 msjava.dll »»NotePad(s) version(s)... Tnx,shadoWWWW 5.1.2600.0 C:\WINDOWS\notepad.exe --a-- W32i APP ENU 5.1.2600.0 shp 66,048 08-18-2001 notepad.exe 5.1.2600.0 C:\WINDOWS\System32\notepad.exe --a-- W32i APP ENU 5.1.2600.0 shp 66,048 08-23-2001 notepad.exe »» Regedit* version(s): 5.1.2600.1106 C:\WINDOWS\regedit.exe --a-- W32i APP ENU 5.1.2600.1106 shp 134,144 08-29-2002 regedit.exe 5.1.2600.0 C:\WINDOWS\System32\regedt32.exe --a-- W32i APP ENU 5.1.2600.0 shp 3,584 08-18-2001 regedt32.exe »»PC uptime: 9:47pm up 0 days, 0:02 »»Locked or 'Suspect' file(s) found... \\?\C:\WINDOWS\System32\LOGN.DLL +++ File read error \\?\C:\WINDOWS\System32\LOGN.DLL +++ File read error »»Tasks (services): 0 System Process 4 System 620 smss.exe 684 csrss.exe Title: 708 winlogon.exe Title: NetDDE Agent 752 services.exe Svcs: Eventlog,PlugPlay 764 lsass.exe Svcs: PolicyAgent,ProtectedStorage,SamSs 944 svchost.exe Svcs: RpcSs 1044 svchost.exe Svcs: AudioSrv,Browser,CryptSvc,Dhcp,dmserver,ERSvc,EventSystem,FastUserSwitching Compatibility,helpsvc,HidServ,Iprip,lanmanserver,lanmanworkstation,Netman,N la,RasAuto,RasMan,Schedule,seclogon,SENS,SharedAccess,ShellHWDetection,srse rvice,TapiSrv,TermService,Them 1232 svchost.exe Svcs: Dnscache 1276 svchost.exe Svcs: Alerter,LmHosts,RemoteRegistry,SSDPSRV,WebClient 1428 spoolsv.exe Svcs: Spooler 232 explorer.exe Title: Program Manager 480 NAVAPW32.EXE Title: Norton AntiVirus 488 WFXSWTCH.exe Title: LOGINOUTTEST 496 WFXSNT40.EXE Title: WinFax Port Starter 512 Imgicon.exe Title: 560 DAP.exe Title: Dialog 580 CTHELPER.EXE Title: CtHelper 596 realsched.exe Title: Notification Wnd for RNAdmin 640 ctfmon.exe Title: 648 SpySweeper.exe Title: 672 CTLTray.exe Title: 676 CTLTask.exe Title: CTLTask 1140 alg.exe Svcs: ALG 1172 CTsvcCDA.EXE Svcs: Creative Service for CDROM Access 1320 NAVAPSVC.EXE Svcs: navapsvc 588 tcpsvcs.exe Svcs: SimpTcp 664 snmp.exe Svcs: SNMP 1940 NOPDB.EXE Svcs: Speed Disk service 1240 svchost.exe Svcs: stisvc 1532 MsPMSPSv.exe Svcs: WMDM PMSP Service 2548 cmd.exe Title: C:\WINDOWS\System32\cmd.exe 2592 ntvdm.exe 2760 tlist.exe REGEDIT4 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "DeviceNotSelectedTimeout"="15" "GDIProcessHandleQuota"=dword:00002710 "Spooler"="yes" "swapdisk"="" "TransmissionRetryTimeout"="90" "USERProcessHandleQuota"=dword:00002710 REGEDIT4 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Brows er Helper Objects] @="" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Brows er Helper Objects\{0000CC75-ACF3-4cac-A0A9-DD3868E06852}] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Brows er Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Brows er Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Brows er Helper Objects\{BDF3E430-B101-42AD-A544-FADC6B084872}] @="NAV Helper" REGEDIT4 [HKEY_CLASSES_ROOT\PROTOCOLS\Filter] [HKEY_CLASSES_ROOT\PROTOCOLS\Filter\Class Install Handler] @="AP Class Install Handler filter" "CLSID"="{32B533BB-EDAE-11d0-BD5A-00AA00B92AF1}" [HKEY_CLASSES_ROOT\PROTOCOLS\Filter\deflate] @="AP Deflate Encoding/Decoding Filter " "CLSID"="{8f6b0360-b80d-11d0-a9b3-006097942311}" [HKEY_CLASSES_ROOT\PROTOCOLS\Filter\gzip] @="AP GZIP Encoding/Decoding Filter " "CLSID"="{8f6b0360-b80d-11d0-a9b3-006097942311}" [HKEY_CLASSES_ROOT\PROTOCOLS\Filter\lzdhtml] @="AP lzdhtml encoding/decoding Filter" "CLSID"="{8f6b0360-b80d-11d0-a9b3-006097942311}" [HKEY_CLASSES_ROOT\PROTOCOLS\Filter\text/webviewhtml] @="WebView MIME Filter" "CLSID"="{733AC4CB-F1A4-11d0-B951-00A0C90312E1}" REGEDIT4 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceOb jectDelayLoad] "PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}" "CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}" "WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}" "SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}" "UPnPMonitor"="{e57ce738-33e8-4c51-8354-bb4de9d215d1}" »»Security settings for 'Windows' key: RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above Copyright (c) 1999-2001 Frank Heyne Software (http://www.heysoft.de) This program is Freeware, use it on your own risk! Access Control List for Registry key hklm\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows: (NI) ALLOW Read BUILTIN\Users (IO) ALLOW Read BUILTIN\Users (NI) ALLOW Read BUILTIN\Power Users (IO) ALLOW Read BUILTIN\Power Users (NI) ALLOW Full access BUILTIN\Administrators (IO) ALLOW Full access BUILTIN\Administrators (NI) ALLOW Full access NT AUTHORITY\SYSTEM (IO) ALLOW Full access NT AUTHORITY\SYSTEM (NI) ALLOW Full access BUILTIN\Administrators (IO) ALLOW Full access CREATOR OWNER Effective permissions for Registry key hklm\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows: Read BUILTIN\Users Read BUILTIN\Power Users Full access BUILTIN\Administrators Full access NT AUTHORITY\SYSTEM »»Size of 'Windows' key: (Default-450;No'AppInit'-398;*Fake-~448!) Size of HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Windows: 398 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\win.ini\Windows\SYS:Microsoft\Windows NT\CurrentVersion\Windows : AppInit_DLLs »»Winlogon\notify: ! REG.EXE VERSION 2.0 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon Size of HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify: 5016 »»UserInit value: ! REG.EXE VERSION 2.0 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon Userinit REG_SZ C:\WINDOWS\system32\userinit.exe, 5.1.2600.1106 C:\WINDOWS\System32\userinit.exe --a-- W32i APP ENU 5.1.2600.1106 shp 22,016 08-29-2002 userinit.exe »»Group/user settings: User: [DRAGONSPIRIT\Guy1], is a member of: BUILTIN\Administrators \Everyone User is a member of group DRAGONSPIRIT\None. User is a member of group \Everyone. User is a member of group BUILTIN\Administrators. User is a member of group BUILTIN\Users. User is a member of group \LOCAL. User is a member of group NT AUTHORITY\INTERACTIVE. User is a member of group NT AUTHORITY\Authenticated Users. »»ACLs list: C:\junkxxx BUILTIN\Administrators OI)(CI)F NT AUTHORITY\SYSTEM OI)(CI)F DRAGONSPIRIT\Guy1:F CREATOR OWNER OI)(CI)(IO)F BUILTIN\Users OI)(CI)R BUILTIN\Users CI)(special access![]() FILE_APPEND_DATA BUILTIN\Users CI)(special access![]() FILE_WRITE_DATA ERROR: There are no more files. »»File(s) in 'junkxxx' folder: »»Md5sums MD5sums 1.1 freeware for Win9x/ME/NT/2000/XP+ Copyright (C) 2001-2002 Jem Berkes - http://www.pc-tools.net/ 0 bytes, 0 ms = 0.00 MB/sec »»hosts file: R C:\WINDOWS\System32\Drivers\etc\hosts -r--- - - - - - 0 06-09-2004 hosts ------ »»Rehash: »Strings found: Wed Jun 30 21:47:36 2004 -- ++Find-All backups: c:\findal~1\winBackup.hiv --a-- - - - - - 8,192 06-30-2004 winbackup.hiv c:\findal~1\windows.txt --a-- - - - - - 8,192 06-30-2004 windows.txt A C:\FindallwinBackup.hiv --a-- - - - - - 8,192 06-07-2004 findallwinbackup.hiv A C:\findallappinit.reg --a-- - - - - - 632 06-07-2004 findallappinit.reg ***Next Registry run should open this key directly: ! REG.EXE VERSION 2.0 HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Applets\Regedit LastKey REG_SZ My Computer\HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
__________________ If I have helped solve your problem, please Click Here and make a donation to help keep this great site running. 100% goes directly to this site. |
01-Jul-2004, 12:25 AM
#19 | |||||
| The Findall log shows that the file is still there: C:\WINDOWS\System32\LOGN.DLL +++ File read error \\?\C:\WINDOWS\System32\LOGN.DLL +++ File read error Let's try this to see if it shows the file: Download FindnFix at the following link and extract it (it should autoextract to C:\FindnFix when you double click it) http://downloads.subratam.org/FINDnFIX.exe Go to the C:\FindnFix folder and doubleclick on !LOG!.BAT and let it run. It will generate a log.txt file. Copy and paste log.txt back here in your next reply.
__________________ If I have helped solve your problem, please Click Here and make a donation to help keep this great site running. 100% goes directly to this site. |
|
10-Jul-2004, 12:44 AM
#21 | |
| Kewl...Got the file. Quote:
|
|
14-Jul-2004, 05:51 AM
#23 | |
| Quote:
![]() Anyhow, I keep finding that file and now can't delete it. "Access is denied." I ran hiving and it tells me that it doesn't find any file. ![]() |
14-Jul-2004, 11:49 AM
#24 | |||||
| Well this case of this hijacker is one of the oddest that I've seen. Here is what I want you to try: Click here to download CWShredder. Close all browser windows,UnZip the file, but don't run it yet. This is a new version if CWShredder that has been release so get it. Restart to safe mode. How to start your computer in safe mode Go to Folder Options> View Scroll to the bottom of the list to find the box labeled: Use Simple File Sharing(Recommended) Remove the check from that box and press ok. find this file: C:\WINDOWS\System32\LOGN.DLL Use the security tab on LOGN.DLL and take ownership. Change the 'everyone special' to 'you> with Admin rights-> FULL control Then try to delete it, if that fails try to rename it first to different name+ext. (Right click the file and choose "Rename") Example: change the name of LOGN.DLL to bleh.txt bleh.txt to badfile.111 Once you have successfully deleted the file restart into Regular Windows mode. Extract and Run CWShredder immediately. Press the fix button to clean. Restart your computer. A new version of Hijack This has been released so get rid of the old one and Click here to download the new one, come back here and post the log from it.
__________________ If I have helped solve your problem, please Click Here and make a donation to help keep this great site running. 100% goes directly to this site. |
|
17-Jul-2004, 03:29 AM
#25 | |
| Ok this is what I got after deleting that logn.dll file. Quote:
|
17-Jul-2004, 08:01 AM
#26 | |||||
| Run Hijack This again and put a check by these. Close ALL windows except HijackThis and click "Fix checked" R3 - Default URLSearchHook is missing O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE Restart your computer. Finally go to Control Panel > Internet Options. On the General tab under "Temporary Internet Files" Click "Delete Files". Put a check by "Delete Offline Content" and click OK. Click on the Programs tab then click the "Reset Web Settings" button. Click Apply then OK. urn off System Restore: On the Desktop, right-click My Computer. Click Properties. Click the System Restore tab. Check Turn off System Restore. Click Apply, and then click OK. Restart your computer, turn it back on and create a restore point. To create a restore point: Single-click Start and point to All Programs. Mouse over Accessories, then System Tools, and select System Restore. In the System Restore wizard, select the box next the text labeled "Create a restore point" and click the Next button. Type a description for your new restore point. Something like "After trojan/spyware cleanup". Click Create and you're done. Check this out for info on how to tighten your security settings and some good free tools to help prevent this from happening again.
__________________ If I have helped solve your problem, please Click Here and make a donation to help keep this great site running. 100% goes directly to this site. |
20-Jul-2004, 11:34 AM
#28 | |||||
| You're Welcome! ![]() I'm closing this thread. If you need it reopened please PM me or one of the other mods. Anyone else with a similar problem please start a "New Thread". |
|
| Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) | |

| Thread Tools | |
| |
| You Are Using: |
Advertisements do not imply our endorsement of that product or service. All times are GMT -4. The time now is 02:00 PM. Copyright © 1996 - 2011 TechGuy, Inc. All rights reserved. | |
