| | |
| Thread Tools |
|
05-Jun-2004, 11:23 AM
#1 |
| [Solved] Ok, I admit defeat. Coolsearch spyware (hijack this included) Dammit! I've dealt with CoolSearch before but was able to defeat it then. It took some n00b registery editing, multiple anti-spyware app sweeps (Adaware and Webroot Spysweeper. They find the spyware, try to remove it, say it's successful, but ultimately fail. I'm assuming it's due to Coolsearch running in binary form. I remember seeing something like that when i did a quick once over in my system's registery), and a system restore but I got it off. Now it's back again and I can't get rid of it this time. I admit that I can't fix this one myself and ask for help. I'd appreciate any help you guys can give me but, if at all possible, can you tell me what your fixes mean? I don't know much about registery or hardcore comp troubleshooting but would like to learn. ______________________________________________________________ Logfile of HijackThis v1.97.7 Scan saved at 12:51:18 AM, on 6/5/2004 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\CTSVCCDA.EXE C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe C:\WINDOWS\System32\nvsvc32.exe C:\WINDOWS\System32\tcpsvcs.exe C:\WINDOWS\System32\snmp.exe C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\MsPMSPSv.exe C:\WINDOWS\Explorer.EXE C:\PROGRA~1\NORTON~1\NORTON~1\navapw32.exe C:\PROGRA~1\NORTON~1\WinFax\WFXSWTCH.exe C:\WINDOWS\System32\wfxsnt40.exe C:\Program Files\Iomega\DriveIcons\ImgIcon.exe C:\PROGRA~1\DAP\DAP.EXE C:\WINDOWS\System32\CTHELPER.EXE C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\WINDOWS\System32\ctfmon.exe C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe C:\WINDOWS\System32\RUNDLL32.EXE C:\Program Files\Creative\SBAudigy\TaskBar\CTLTray.exe C:\Program Files\Creative\SBAudigy\TaskBar\CTLTask.exe C:\Hijack This\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://sharempeg.com/find/ R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\System32\nbmlda.dll/sp.html (obfuscated) R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\System32\nbmlda.dll/sp.html (obfuscated) R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\System32\nbmlda.dll/sp.html (obfuscated) R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\System32\nbmlda.dll/sp.html (obfuscated) R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\System32\nbmlda.dll/sp.html (obfuscated) R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\System32\nbmlda.dll/sp.html (obfuscated) R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank N1 - Netscape 4: user_pref("browser.startup.homepage", "http://registration.excite.com/excitereg/login.jsp?app=em&return_url=http://e6.email.excite.com/"); (C:\Program Files\Netscape\Users\someguy\prefs.js) O2 - BHO: (no name) - {0000CC75-ACF3-4cac-A0A9-DD3868E06852} - C:\Program Files\DAP\DAPBHO.dll O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx O2 - BHO: (no name) - {4359CAF3-D13B-4472-A010-7F0E70F1DFE4} - C:\WINDOWS\System32\nbmlda.dll O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\windows\googletoolbar1.dll O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O3 - Toolbar: DAP Bar - {62999427-33FC-4baf-9C9C-BCE6BD127F08} - C:\Program Files\DAP\DAPIEBar.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\windows\googletoolbar1.dll O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\NORTON~1\navapw32.exe O4 - HKLM\..\Run: [WFXSwtch] C:\PROGRA~1\NORTON~1\WinFax\WFXSWTCH.exe O4 - HKLM\..\Run: [WinFaxAppPortStarter] wfxsnt40.exe O4 - HKLM\..\Run: [Iomega Startup Options] C:\Program Files\Iomega\Common\ImgStart.exe O4 - HKLM\..\Run: [Iomega Drive Icons] C:\Program Files\Iomega\DriveIcons\ImgIcon.exe O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE O4 - HKLM\..\Run: [CTStartup] C:\Program Files\Creative\Splash Screen\CTEaxSpl.EXE /run O4 - HKLM\..\Run: [DXM6Patch_981116] C:\WINDOWS\p_981116.exe /Q:A O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [DownloadAccelerator] C:\PROGRA~1\DAP\DAP.EXE /STARTUP O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE O4 - HKLM\..\Run: [Disc Detector] C:\Program Files\Creative\ShareDLL\CtNotify.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe O4 - HKCU\..\Run: [SpySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe /0 O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit O4 - HKCU\..\Run: [TaskTray] "C:\Program Files\Creative\SBAudigy\TaskBar\CTLTray.exe" O4 - HKCU\..\Run: [TaskBar] "C:\Program Files\Creative\SBAudigy\TaskBar\CTLTask.exe" O4 - HKCU\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\Symantec\LIVEUP~1\SNDMon.EXE O8 - Extra context menu item: &Download with &DAP - C:\PROGRA~1\DAP\dapextie.htm O8 - Extra context menu item: &Google Search - res://c:\windows\GoogleToolbar1.dll/cmsearch.html O8 - Extra context menu item: Backward &Links - res://c:\windows\GoogleToolbar1.dll/cmbacklinks.html O8 - Extra context menu item: Cac&hed Snapshot of Page - res://c:\windows\GoogleToolbar1.dll/cmcache.html O8 - Extra context menu item: Download &all with DAP - C:\PROGRA~1\DAP\dapextie2.htm O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O8 - Extra context menu item: Si&milar Pages - res://c:\windows\GoogleToolbar1.dll/cmsimilar.html O8 - Extra context menu item: Translate into English - res://c:\windows\GoogleToolbar1.dll/cmtrans.html O9 - Extra button: Run DAP (HKLM) O9 - Extra button: Messenger (HKLM) O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM) O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll O16 - DPF: Yahoo! Chat - http://us.chat1.yimg.com/us.yimg.com.../c381/chat.cab O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/SU/ocx/12119/CTSUEng.cab O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/s...ctor/swdir.cab O16 - DPF: {27527D31-447B-11D5-A46E-0001023B4289} (CoGSManager Class) - http://gamingzone.ubisoft.com/dev/pa.../GSManager.cab O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://cs5.chat.sc5.yahoo.com/v45/yacscom.cab O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/ca...C_1_0_0_42.cab O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/20e9126e...p/RdxIE601.cab O16 - DPF: {8EDAD21C-3584-4E66-A8AB-EB0E5584767D} - http://toolbar.google.com/data/GoogleActivate.cab O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.co...875.0239467593 O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.symantec.com/sscv6/S.../bin/cabsa.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload.macromedia.com/pub...sh/swflash.cab O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/SU/ocx/12119/CTPID.cab Last edited by OhNos111; 05-Jun-2004 at 11:28 AM.. |
| |
|
05-Jun-2004, 11:44 AM
#2 |
| Hey, what do you know. By just snooping around the internet, I found out that the guy who wrote Hijack This also wrote a little app to remove Coolsearch from your PC. I'll download it, when I get out of work, and try it out. http://www.securityworm.com/software...oolsearch.html |
05-Jun-2004, 02:03 PM
#3 | |||||
| Hi OhNos111 Unfortunately CWShredder will not remove this one. You have been hijacked by the most complex CWS browser hijacker ever. None of the usual removal tools will remove this one. The removal procedures are quite complex. Before I attempt to give you instructions let me ask you 3 questions, 1: How good are you with computers? 2: Do you have your XP installation Disk? 3: Is it XP Home or Pro?
__________________ If I have helped solve your problem, please Click Here and make a donation to help keep this great site running. 100% goes directly to this site. |
|
05-Jun-2004, 05:39 PM
#4 | |
| Quote:
1. If you tell me where to go, and what to do, I can do it. 2. Yup. 3. Pro (Also, don't know if this has anything to do with it but, my Notepad is gone. I mean, literally gone. The shortcut icons are there but it won't open. :huh: ) Oh yeah...Did theh CWShredder scan and this is what it found: CWShredder v1.59.0 scan only report Please understand that a CWShredder 'Scan only' report might not be sufficient to troubleshoot an infected system. You can use HijackThis for that: http://www.merijn.org/files/hijackthis.zip http://www.spywareinfo.com/~merijn/files/hijackthis.zip Windows XP (5.01.2600 SP1) Windows dir: C:\WINDOWS Windows system dir: C:\WINDOWS\system32 AppData folder: C:\Documents and Settings\Guy1\Application Data Username: Guy1 Infected Registry value: HKCU\Software\Microsoft\Internet Explorer,SearchURL Infected data: http://sharempeg.com/find/ Infected Registry value: HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar Infected data: res://C:\WINDOWS\System32\nbmlda.dll/sp.html (obfuscated) Infected Registry value: HKCU\Software\Microsoft\Internet Explorer\Main,Search Page Infected data: res://C:\WINDOWS\System32\nbmlda.dll/sp.html (obfuscated) Infected Registry value: HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar Infected data: res://C:\WINDOWS\System32\nbmlda.dll/sp.html (obfuscated) Infected Registry value: HKLM\Software\Microsoft\Internet Explorer\Main,Search Page Infected data: res://C:\WINDOWS\System32\nbmlda.dll/sp.html (obfuscated) Infected Registry value: HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant Infected data: res://C:\WINDOWS\System32\nbmlda.dll/sp.html (obfuscated) Infected Registry value: HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant,http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm Infected data: res://C:\WINDOWS\System32\nbmlda.dll/sp.html (obfuscated) Found Hosts file: C:\WINDOWS\system32\drivers\etc\hosts (5719 bytes, R) Shell Registry value: HKLM\..\WinLogon [Shell] Explorer.exe UserInit Registry value: HKLM\..\WinLogon [UserInit] C:\WINDOWS\system32\userinit.exe, Found Win.ini file: C:\WINDOWS\win.ini (1067 bytes, A) Found System.ini file: C:\WINDOWS\system.ini (237 bytes, A) - END OF REPORT - Last edited by OhNos111; 05-Jun-2004 at 05:46 PM.. |
05-Jun-2004, 06:43 PM
#5 | |||||
| Well I guess we better try to fix notepad first. Click on this link to download a new copy of notepad.exe. Unzip an copy to both the C:\Windows folder and the C:\Windows\System32 folder overwriting the existing file: http://www.spywareinfo.com/~merijn/f...notepad_xp.zip Now do the following: Go here and download Findall.zip for XP/2k : http://freeatlast.100free.com/index.html You must Unzip (extract) the files first. Open the Find-all folder and doubleclick on the FIND-ALL.CMD file in the Find-All folder. Wait for it to complete and it will generate an output.txt file. Copy and paste the contents of output.txt here. *Note: If your Antivirus is running a scriptblocker, when you run Findall.bat, you will recieve an alert warning you that the script is running. "Allow" the script to run. After you do that and post it here do this: Install Recovery Console: If you have the XP installation disk, put the CD in the drive while on the internet. Go to Start>Run and execute this command: (Copy and paste the command in and then press enter) D:\i386\winnt32.exe /cmdcons Where D is the CD drive Letter. If D is not the drive letter of your CD drive change it accordingly. Go ahead and follow the steps here to bypass the Recovery Console password: http://support.microsoft.com/default...b;EN-US;312149 After you have installed the Recovery Console and posted the log from the output.txt file, wait for further instructions.
__________________ If I have helped solve your problem, please Click Here and make a donation to help keep this great site running. 100% goes directly to this site. |
|
07-Jun-2004, 04:18 AM
#6 | |
| Here's the Find All log. Quote:
|
|
07-Jun-2004, 04:31 AM
#7 | |
| Oooh boy. I just got an error trying to install Recovery console. Quote:
I'm going to restart and try again. [edit]: Ok, got Recovery Console installed...Waiting for further orders SIR!!! ![]() Last edited by OhNos111; 07-Jun-2004 at 04:47 AM.. |
07-Jun-2004, 10:34 PM
#8 | |||||
| You should first print the instructions before booting to the Recovery Console. Because XP will not always show you hidden files and folders by default. Reset your search settings first. Open Folder Options>view and check your settings: Select Show hidden files and folders Display the contents of system folders Uncheck: Hide protected operating system files Next go to Search and scrolldown using the scroll bar on the right. Go down to More advanced options and click. Be sure the first three boxes are selected: Search System folders Search Hidden Files and folders Search SubFolders _______________________________________________________________________ First download hiving.zip from here: http://forums.techguy.org/attachment...chmentid=33308 unzip it. After unzipping hiving.zip, open the hiving folder and click on the hiving.bat and let it run. After the hiving.bat file completes, restart your computer _______________________________________________________________________ Now Copy and paste the contents of the quote box to Notepad. Save as go.txt Save the file in C:\windows Quote:
1: C:\Windows Press the 1 key and then hit the Enter key. Once Recovery Console has loaded you should now be at a prompt like this: C:\Windows> Type this and press enter: Batch C:\windows\go.txt Dos is particular about spaces. Here it is again with the space you need to add. Batch space C:\windows\go.txt If the batch works, you will get no error messages and you will be back at a C:> prompt. If you get an error message you need to post back with the message. Type Exit to restart. ________________________________________________________________________ Once you are back in Windows do the following: Click here to download CWShredder. Close all browser windows,UnZip the file, click on the cwshredder.exe then click "Fix" (Not "Scan only") and let it do it's thing. When it is finished restart your computer. Go here and download Adaware 6 Build 181 Install the program and launch it. First in the main window look in the bottom right corner and click on Check for updates now and download the latest referencefiles. Make sure the following settings are made and on -------ON=GREEN From main window :Click Start then Activate in-depth scan (recommended) Click Use custom scanning options then click Customize and have these options selected: Under Drives and Folders put a check by Scan within archives and below that under Memory and Registry put a check by all the options there. Now click on the Tweak button in that same window. Under Scanning engine select Unload recognized processes during scanning and under Cleaning Engine select Let windows remove files in use at next reboot Click proceed to save your settings. Now to scan just click the Next button. When the scan is finished mark everything for removal and get rid of it.(Right-click the window and choose select all from the drop down menu and click Next) Restart your computer. ___________________________________________________________________________ _______ After all that run Findall.bat again and post another output.txt log along with another Hijack This log.
__________________ If I have helped solve your problem, please Click Here and make a donation to help keep this great site running. 100% goes directly to this site. Last edited by flrman1; 07-Jun-2004 at 10:40 PM.. |
|
09-Jun-2004, 04:52 AM
#9 | ||
| Quote:
Quote:
Oh yeah...What is that "attrib -h" stuff? |
|
10-Jun-2004, 01:02 AM
#11 | ||
| Find all log Quote:
Hijack this Log Quote:
|
10-Jun-2004, 08:54 AM
#12 | |||||
| This time I am going to have you manually type the commands instead of runnung the bat file. You should first print the instructions before booting to the Recovery Console. Because XP will not always show you hidden files and folders by default. Reset your search settings first. Open Folder Options>view and check your settings: Select Show hidden files and folders Display the contents of system folders Uncheck: Hide protected operating system files Next go to Search and scrolldown using the scroll bar on the right. Go down to More advanced options and click. Be sure the first three boxes are selected: Search System folders Search Hidden Files and folders Search SubFolders _______________________________________________________________________ First download hiving.zip from here: http://forums.techguy.org/attachment...chmentid=33308 unzip it. After unzipping hiving.zip, open the hiving folder and click on the hiving.bat and let it run. After the hiving.bat file completes, restart your computer _______________________________________________________________________ Reboot. You will get a menu. Choose Recovery Console. To do that use the arrow keys to move through the menu and when Recovery Console is highlighted, press enter. You'll be asked which Install you want to repair. If you only have one OS installed you will only have one option like so: 1: C:\Windows Press the 1 key and then hit the Enter key. Once Recovery Console has loaded you should now be at a prompt like this: C:\Windows> At this prompt you will type in the follwing commands: Type this and press enter: del C:\WINDOWS\System32\LOGKGIP.DLL Spaces are important in these commands. There is a space between each command switch and the file path. Here it is with those: del space C:\WINDOWS\System32\LOGKGIP.DLL Let it do the delete. (See ***Note if you receive an error when executing this command) ***Note: If C:\WINDOWS\System32\LOGKGIP.DLL is set as a hidden, system or read only file, you may have to clear these attributes. If you get a message that the hidden or system file cannot be removed use this command to clear the attributes and press enter. Then execute the del command again. Type: attrib -r C:\WINDOWS\System32\LOGKGIP.DLL (With the spaces here is that command again.... attrib space -r space C:\WINDOWS\System32\LOGKGIP.DLL) Hit Enter Then type: del C:\WINDOWS\System32\LOGKGIP.DLL (This one is..... del space C:\WINDOWS\System32\LOGKGIP.DLL) Hit Enter. If after you have removed the Read Only attribute with the above command and still get an error use the following command to remove the hidden attribute and then try the del command again. attrib -h C:\WINDOWS\System32\LOGKGIP.DLL Hit Enter. Then type the del command again: del C:\WINDOWS\System32\LOGKGIP.DLL Hit Enter. If you still receive an error after removing the hidden attribute use this command: attrib -s C:\WINDOWS\System32\LOGKGIP.DLL Then type the del command again: del C:\WINDOWS\System32\LOGKGIP.DLL *Note: If you are successful in deleting the file after any one of these steps there is no need to execute all the subsequent commands. The goal is to successfully delete that hidden file. Only proceed to the next command if the deletion fails after removing the read only attribute etc... ***Now you have deleted the hidden file that keeps loading the hijack.*** Type Exit to restart. _______________________________________________________________________ Once you are back in Windows do the following: Click here to download CWShredder. Close all browser windows,UnZip the file, click on the cwshredder.exe then click "Fix" (Not "Scan only") and let it do it's thing. When it is finished restart your computer. Go here and download Adaware 6 Build 181 Install the program and launch it. First in the main window look in the bottom right corner and click on Check for updates now and download the latest referencefiles. Make sure the following settings are made and on -------ON=GREEN From main window :Click Start then Activate in-depth scan (recommended) Click Use custom scanning options then click Customize and have these options selected: Under Drives and Folders put a check by Scan within archives and below that under Memory and Registry put a check by all the options there. Now click on the Tweak button in that same window. Under Scanning engine select Unload recognized processes during scanning and under Cleaning Engine select Let windows remove files in use at next reboot Click proceed to save your settings. Now to scan just click the Next button. When the scan is finished mark everything for removal and get rid of it.(Right-click the window and choose select all from the drop down menu and click Next) Restart your computer. ______________________________________________________________________ After all that run Findall.bat again and post another output.txt and windows.txt file log along with another Hijack This log.
__________________ If I have helped solve your problem, please Click Here and make a donation to help keep this great site running. 100% goes directly to this site. |
|
11-Jun-2004, 01:38 AM
#13 | ||
| Ok...Did all that and here are the Hijack this log and Find all log; not sure what you meant by "windows.txt" file log. Quote:
Quote:
Also, I've noticed some virus apps running in my startup list, so I baleeted them. (something like sjadbot.exe and more) I don't know if it will matter but I did another Hijack this and another Find all scan. Since I don't want a fittybillion page post, I'll just give you the link. ![]() Hijack this Find All log Last edited by OhNos111; 11-Jun-2004 at 07:11 PM.. |
12-Jun-2004, 11:18 PM
#14 | |||||
| Try this: Download this tool: http://tools.zerosrealm.com/dllfix.exe Its a self extracting zip. Just click on it and it will self extract. IMPORTANT!: Before you run this tool please close ALL running programs and ALL Windows except dllfix. Open the dllfix folder and click on the start.bat. *Note: If your Antivirus is running a scriptblocker, when you run this tool, you will probably recieve an alert warning you that the script is running. "Allow" the script to run. In the window that pops up Hit the 2 key on your keyboard and hit Enter. In the next menu hit the 1 key on your keybard and hit the Enter key again. you will arrive at a prompt like this: Enter full name and hit Enter C:\Windows\System32\ Enter this file name and hit enter: LOGL.DLL It will do it's cleanup and give a 15 second countdown and when Windows restarts it will automatically run the second.bat file. Just let it run. When it completes post another output.txt log and another Hijack This log.
__________________ If I have helped solve your problem, please Click Here and make a donation to help keep this great site running. 100% goes directly to this site. |
|
25-Jun-2004, 02:37 AM
#15 | |
| Quote:
First, I'd like to thank you guys for your continuted help. Second, that link you gave downloaded an app called "AboutBuster." I don't know if it's the correct one but I ran it anyway. Problem is, it gave me a run time error. I think it was Runtime error 79: File access/denied or something like that. Just incase it's necessary, here's another Find All and Hijack this log. Find All log Hijack This log |
|
| Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) | |

| Thread Tools | |
| |
| You Are Using: |
Advertisements do not imply our endorsement of that product or service. All times are GMT -4. The time now is 03:38 PM. Copyright © 1996 - 2011 TechGuy, Inc. All rights reserved. | |
