1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

About:blank

Discussion in 'Security and Privacy' started by gerdcurli, 2004/08/12.

Thread Status:
Not open for further replies.
  1. 2004/08/29
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Well done. Just what I was looking for. :)

    Download the RegFix.zip file I have attached to this post.

    Unzip to its own folder.

    Open Folder and double click on the RunFix.reg file.
    Answer 'Yes' to merge it into your registry.

    Go to start>run and type msconfig, hit enter. On the General tab click the advanced button. Check the box to 'enable start menu' and OK out. Restart and choose safe mode.

    You will need to show hidden files and folders.


    Open C:\WINDOWS\SYSTEM. Locate the file comi.dll.
    Right click, select 'Properties' and remove any 'Read only' protection.
    Right click again and select 'Delete'.


    Open CWShredder and click fix.

    Open C:\Temp (if present), select all and delete.
    Open C:\Windows\Temp, select all and delete.
    Open C:\Windows\Applog, select all and delete.

    Open Ad-aware and run. Delete all it finds. If it won't complete a scan, continue on with the rest of the instructions.

    Open My Computer and right click Local Disk C:, then choose disk cleanup. Check all except compress old files and OK.

    Again, open the RunFix folder, this time double click the ScanRegFix.reg file. Answer 'Yes' to merge it into your registry.

    Uncheck the box to 'enable start menu' in msconfig and OK out. Reboot.

    Back in Windows, run another HijackThis scan and post the log.
     
  2. 2004/08/30
    gerdcurli

    gerdcurli Inactive Thread Starter

    Joined:
    2003/01/22
    Messages:
    58
    Likes Received:
    0
    Hjt Log

    Logfile of HijackThis v1.98.2
    Scan saved at 13:10:25, on 30/08/04
    Platform: Windows 98 SE (Win9x 4.10.2222A)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\SYSTEM\KERNEL32.DLL
    C:\WINDOWS\SYSTEM\MSGSRV32.EXE
    C:\WINDOWS\SYSTEM\MPREXE.EXE
    C:\WINDOWS\SYSTEM\mmtask.tsk
    C:\WINDOWS\EXPLORER.EXE
    C:\WINDOWS\SYSTEM\SYSTRAY.EXE
    C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE
    C:\WINDOWS\SYSTEM\WMIEXE.EXE
    C:\WINDOWS\SYSTEM\DDHELP.EXE
    C:\WINDOWS\DESKTOP\HJT\HIJACKTHIS.EXE

    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
    O4 - HKLM\..\Run: [NetPumper] "C:\Program Files\NetPumper\NetPumperIEProxy.exe "
    O4 - HKCU\..\Run: [msnmsgr] "C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE" /background
    O8 - Extra context menu item: Download with NetPumper - C:\Program Files\NetPumper\AddUrl.htm
     

  3. to hide this advert.

  4. 2004/08/30
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Looks clean, but I still don't see the scanreg run entry. Did you merge the scanreg file? Try again and reboot. Do another HJT scan and see if the 04 HKLM...[Scan Registry] scanregw.exe entry is there. Did Ad-aware run successfully? Any other problems?

    Is that the pro version of NetPumper?
     
  5. 2004/09/02
    gerdcurli

    gerdcurli Inactive Thread Starter

    Joined:
    2003/01/22
    Messages:
    58
    Likes Received:
    0
    Many Many Thanks

    DAVE JUST A LITTLE NOTE TO THANK YOU SINCERELY FOR ALL THE VERY PROFESSIONAL HELP WITH MY PROBLEM. WOULDN'T HAVE MADE IT WITHOUT YOU MATE.
    AS We SAY IN IRISH...

    Go Raibh Mile Maith Agat!
    One thousand thank you's!
     
  6. 2004/09/02
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Quite welcome. Happy to help. :)
     
Thread Status:
Not open for further replies.

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.