Started by rossh0919 , Jan 07 2005 07:05 PM
If you encounter this problem, using a different browser like Firefox or Chrome seems to get around the problem. Here comes the bigg 'Trick' :type: if possible go to Start/Run msconfig [Disable all startups items]Follow the prompt

It copies itself to \windows\system\ptsnoop.exe and changes win.ini adding 'c:\windows\system\ptsnoop.exe' to 'load = '. There are a lot of infections that have a name, but even more that don't have a name... Newer Than: Search this thread only Search this forum only Display results as threads Useful Searches Recent Posts More...

All rights reserved. Run, FIX THE FOLLOWING : ************** R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://letgohome.com/hp.htm?id=31403 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://letgohome.com/hp.htm?id=31403 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://letgohome.com/hp.htm?id=31403 O2 - BHO: (no It will be a completely random one too like the last log, only different letters (Look in the example of your last log... Several functions may not work.

If they do not, click once on the circle next to them to put a green checkmark:"Scan within archives" "Select drives & folders to scan" - select your hard drive(s). "Scan It didn't work.

Although my start page has not been hijacked and there has been a considerable decrease in both alerts from Norton and popups getting past my popup blocker, the latter still occur. booted into safe mode and ran cwshredder... After it's finished, open HiJackThis, and tick these entries (wait with hitting the fix button):   R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.windowws.cc/sp.htm?id=131 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.windowws.cc/sp.htm?id=131

When you reboot in Safe Mode your desktop may be different, so it's important that HijackThis.exe is in its own folder, as explained here. Click "Check for updates now" then click "Connect". If you encounter this problem, using a different browser like Firefox or Chrome seems to get around the problem. Here's what you do: One the Left hand side, click the folder named "Windows" so that it is selected.

If they do not, click once on the circle next to them to put a green checkmark: "Always try to unload modules before deletion" "During removal, unload Explorer and IE if
the w8c6s4xcm66.dll was still there and I can not delete it I deleted all of the .dll.dll.dll etc. You can try just copying it and pasting it into a reply but I might not see it. Hence it was the legit one...     2) How do I keep from getting reinfected?   Read this:   Protection after fix...

Do a full scan with Norton Anti-virus, then all of your anti-spyware apps. Yes, my password is: Forgot your password? What about the people behind the here4search.com website? http://pcialliance.org/hijack-log/hijack-log-explorer-problem-and-more.html If you find one that you are not sure of, check the date to see if it's within the last few days.

Our random file, the baddie)   Now, reboot   Post me the log that you saved, tell me the name of the random file I asked you to fix...(In the example
Documentation for AVG can be found on the page you downloaded it from.Rescan with HijackThis v1.99 and post a new log. Double click it and get through the installation wizard.

C:\WINDOWS\system32\mplaw7.dll: UPX!

Any backup files HJT creates during the repair process will not be secure if left this way. Post the contents of C:\log.txt in your next reply along with a new hijackthis log.
Still wasn't able to find either of those but later it will all the sudden reinstall and automatically start running.
ok, a bit more research done, and I think your trick here is going to be that you will

Please post a new hijackthis log.
Thought I'd mention that some spyware remove program keeps installing as well...
Hi...

Get HijackThis.exe from http:/www.tomcoyote.com/hjt/HijackThis.exe Save it then Open it and SCAN your system then SAVE LOG and send me the HijackThis log as an attachment. Total of file sizes: 284,289,645 bytes 271.12 M Administrator Account = True AppInit_DLLs value = 8n2rfgs3y2y2htl.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll (not hidden) End log