I followed a link a friend sent to me a few days ago and since then, I've been having pop-ups at an amazing frequency. I have Ad Aware on my laptop (and have had it since I got the laptop) but it didn't stop this. I have now installed Ad Aware Plus and am runnign Ad Watch, but Ad Watch is not stopping all the pop-ups either. I've scanned with Ad Aware about a dozen times and it hasn't helped much - it finds and removes threats - every time but pop-ups keep happening. Anyway, here is my Hijack This log - I'm not very good at this, but it doesn't look good even to me. I'd appreciate any help anyone can give me with this. I can't believe how quickly it got nuked, it's a brand new laptop and now I can't turn it on without pop-ups every minute.
Logfile of HijackThis v1.98.2
Scan saved at 6:19:24 PM, on 12/10/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Please put your HijackThis in it's own folder, (I create a new folder in C:\ named HJT).
You can do a Right Click on any open area on the desktop, New> Folder, then rename the folder HJT.
Go to where your HijackThis is and Right Click on HijackThis.exe, select Cut, then open the new folder you just created (HJT) Right Click in the folder and select paste.
The reason we do this is Hijackthis creates backup files just in case you'd need to restore one and we'll be cleaning out the temp files.
Please do all the steps in the order they are listed
Uninstall Virtumundo from control panel >> add remove program if listed there
Start the program and then check the I know what I'm doing box.
Move all instances of calsp.dll and aklsp.dll (and nothing else), to the Remove pane.
Click the Finish Button and reboot.
Find and delete the file c:\windows\system\calsp.dll
Find and delete the file c:\windows\system\aklsp.dll
1. Open My Computer
2. Right click on your hard drive that you wish to clean (C drive, for example)
3. In the context menu that opens, select properties
4. Under the general tab you should select Disk Cleanup
5. Windows will scan your drive which will take a few seconds/minutes
6. A box will display the various files you can remove.
Check all boxes except compress old files
7. Click OK and windows will comply.
Restart your computer.
Reboot and "copy/paste" a new log file into this thread.
So far so good - there was no Virtumundo listed in the add/remove programs to uninstall, though. Still getting pop-ups at this point, though the frequency seems to have decreased. Here is the new log file.
Logfile of HijackThis v1.98.2
Scan saved at 12:09:39 AM, on 12/11/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Close ALL windows and browsers except HijackThis and click "Fix checked"
Restart in Safe Mode:
Restart your computer.
Press F8 after the Power-On Self Test (POST) is done. If the Windows Advanced Options Menu does not appear, try restarting and then pressing F8 several times after the POST screen.
Choose the Safe Mode option from the Windows Advanced Options Menu then press Enter.
Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Clear "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Clear "Hide protected operating system files."
Click Apply, and then click OK.
Search for these Files and delete them if still listed.
Do this also if these Temp Folders are part of your OS.
Also in safe mode navigate to the C:\Windows\Temp folder. Open the Temp folder and go to Edit > Select All then Edit > Delete to delete the entire contents of the Temp folder.
Next navigate to the C:\Documents and Settings\(EVERY USER)\Local Settings\Temp folder. Open the Temp folder and go to Edit > Select All then Edit > Delete to delete the entire contents of the Temp folder.
Finally go to Control Panel > Internet Options. On the General tab under "Temporary Internet Files" Click "Delete Files". Put a check by "Delete Offline Content" and click OK. Click on the Programs tab then click the "Reset Web Settings" button. Click Apply then OK.
Empty the Recycle Bin
Reboot and "copy/paste" a new log file into this thread.
Thanks again. I followed the instructions and checked the the items you listed, and they appeared to be removed and remained gone during the Safe reboot. However, when I rebooted again, Ad Watch (which I have set to load on startup) reported several registry modifications which were those items putting themselves back into the registry. It did not give me the choice it usually did to block the changes, it simply reported them. I was not connected to the Internet on startup, so it seems to me that something present on my computer is writing those items back to my registry during every startup. When I checked both the registry and a new Hijack This log, they were present again (as you can see below). However, I did notice that, even though the registry items were back, the files I deleted (the SED folder, jagxgwoo.exe, etc.) - the files referred to in the registry items - remain deleted.
I also posted the Ad Watch log below the HJT log, in case it could be helpful.
Logfile of HijackThis v1.98.2
Scan saved at 10:45:55 AM, on 12/12/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Ad-Watch Logfile, exported on 12/12/2004
Total number of events:13
===============================================
12/12/2004 12:06:30 AM - Definitions file SE1R21 03.12.2004 loaded successfully.
Build:SE1R21 03.12.2004
Total Signatures :34553
Target Families :625
Target Categories :6
CSI data Size :39236
File Size :1292266
===============================================
12/12/2004 12:06:30 AM - User preferences file loaded.
Ad-Watch preference file loaded.
Applying user settings
C:\Documents and Settings\Pook\Application Data\Lavasoft\Ad-Aware\awsettings.awc
Initialization complete.
===============================================
12/12/2004 12:06:30 AM - Sites file loaded.
Sites file loaded successfully.
C:\PROGRA~1\Lavasoft\AD-AWA~1\sites.txt
Total entries : 3231
===============================================
12/12/2004 12:06:30 AM - Registry modification detected
Root:HKEY_CURRENT_USER
Key:Software\Microsoft\Internet Explorer\Main
Value:Search Page
Data:http://ie.search.msn.com
New Data:http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
===============================================
12/12/2004 12:06:30 AM - Registry modification detected
Root:HKEY_LOCAL_MACHINE
Key:Software\Microsoft\Internet Explorer\Main
Value:Search Page
Data:http://ie.search.msn.com
New Data:http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
===============================================
12/12/2004 12:06:30 AM - Registry modification detected
Root:HKEY_LOCAL_MACHINE
Key:Software\Microsoft\Internet Explorer\Search
Value:SearchAssistant
Data:http://ie.search.msn.com
New Data:http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
===============================================
12/12/2004 12:06:30 AM - Registry modification detected
Root:HKEY_CURRENT_USER
Key:Software\Microsoft\Windows\CurrentVersion\Run
Value:ho36RXHpU
Data:mpldle.exe
New Data:
===============================================
12/12/2004 12:06:30 AM - Registry modification detected
Root:HKEY_LOCAL_MACHINE
Key:Software\Microsoft\Windows\CurrentVersion\Run
Value:C:\WINDOWS\jagxgwoo.exe
Data:C:\WINDOWS\jagxgwoo.exe
New Data:
===============================================
12/12/2004 12:06:30 AM - Registry modification detected
Root:HKEY_LOCAL_MACHINE
Key:Software\Microsoft\Internet Explorer\Search
Value:CustomizeSearch
Data:http://ie.search.msn.com
New Data:http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
===============================================
12/12/2004 12:06:30 AM - Registry modification detected
Root:HKEY_LOCAL_MACHINE
Key:Software\Microsoft\Windows\CurrentVersion\Run
Value:SESync
Data:"C:\Program Files\SED\SED.exe"
New Data:
===============================================
12/12/2004 12:06:31 AM - Registry modification detected
Root:HKEY_LOCAL_MACHINE
Key:Software\Microsoft\Windows\CurrentVersion\Run
Value:wFsW37j
Data:perprovi.exe
New Data:
===============================================
12/12/2004 12:06:31 AM - Registry modification detected
Root:HKEY_LOCAL_MACHINE
Key:Software\Microsoft\Windows\CurrentVersion\Run
Value:180ax
Data:c:\windows\temp\180ax.exe
New Data:
===============================================
12/12/2004 12:06:31 AM - Registry modification detected
Root:HKEY_LOCAL_MACHINE
Key:Software\Microsoft\Windows\CurrentVersion\Run
Value:nwzilub
Data:C:\WINDOWS\nwzilub.exe
New Data:
Remove Ad Watch. You can re-install it later. This will stop the fix.
First, enable the viewing of Hidden Files and Folders as follows:
-At your Desktop, go to Start>My Computer
-Select the Tools menu and then Folder Options
-After the new window appears select the View tab
-Select: Display the contents of system folders
-Under the Hidden files and folders section select: Show hidden files and folders
-Remove the checkmark from Hide file extensions for known file types
-Remove the checkmark from Hide protected operating system files (Recommended)
-Press the Apply button
Click OK
Now, right click the Start button on the Desktop
-Select: Explore from the menu
-In the left pane, look for the C: drive (or Local Disk C:}
Below the C: drive, look for [+]WINDOWS, and click on the [+] to expand/open
-Under WINDOWS, you should find the System32 folder.
-Select/highlight the System32 folder
-In the right pane, all the contents of System32 folder appear
-Scroll down the right pane and look for the following file: guard.tmp
-If found, right click the file, and select: Properties
Post back the date Created
Now, let's find the files that are making this beast prevail.
Please do the following:
Download Find_It.zip: http://www.dslreports.com/r0/download/7259…84f2/FindIt.zip
Unzip its contents to its own folder
Open the folder and double click on Find.bat (File with a gear symbol)
Ignore any File not found messages
It runs for a minute, and produces a log
Please copy and paste the log on your next response.
Download VX2Finder(126).exe: http://downloads.subratam.org/VX2Finder(126).exe
Save the program in its own folder.
Run VX2Finder(126).exe
Select: Click to Find VX2.Betterinternet
When the scan is done, select the Make Log
It will open the log in Notepad.
Copy and paste the log to on your response.
Also, download KillBox.zip (Removal Tool #15) from here: http://www.subratam.org/?page=removal
Place it in a folder on your Desktop.
Do not run it yet.
Will wait for the Find_It log, and the VX2Finder log, as well as the information requested for guard.tmp. Also include a new HijackThis log in your reply, since we need to have all the information as current as possible.
After providing the logs requested, please do not reboot or shutdown/restart the computer. Just leave it on. If you restart, any information provided may change, and we are back to square one.
Ad Watch removed.
There is no guard.tmp file in the system32 folder or in any other folder (I did a search just in case).
Find_It Log:
Warning! This utility will find legitimate files in addition to malware.
Do not remove anything unless you are sure you know what you're doing.
——- System Files in System32 Directory ——-
Volume in drive C has no label.
Volume Serial Number is 98B1-0CF2
Directory of C:\WINDOWS\System32
12/12/2004 05:28 PM 223,455 dbkquoui.dll
12/12/2004 05:28 PM 224,916 en64l1jq1.dll
12/12/2004 05:07 PM 224,976 en2ql1f51.dll
12/12/2004 12:05 AM 223,455 enn6l15s1.dll
12/11/2004 11:21 PM 223,071 mirapi.dll
12/11/2004 11:11 PM 224,908 ttext.dll
12/11/2004 10:34 PM 224,337 gltuname.dll
12/11/2004 08:21 PM 223,683 lFngwrbk.dll
12/11/2004 08:18 PM 222,956 wpsdmoe.dll
12/11/2004 07:44 PM 224,892 uzrlbva.dll
12/10/2004 08:13 PM 225,013 kwdes.dll
12/10/2004 12:56 PM 222,990 n6n60g5se6.dll
12/10/2004 11:46 AM 225,013 pdrfproc.dll
12/10/2004 11:37 AM 225,070 o4840elqehqe0.dll
12/08/2004 08:00 AM dllcache
03/02/2004 12:35 PM Microsoft
14 File(s) 3,138,735 bytes
2 Dir(s) 25,907,277,824 bytes free
——- Hidden Files in System32 Directory ——-
Volume in drive C has no label.
Volume Serial Number is 98B1-0CF2
Directory of C:\WINDOWS\System32
12/08/2004 08:00 AM dllcache
03/02/2004 12:23 PM 488 logonui.exe.manifest
03/02/2004 12:23 PM 488 WindowsLogon.manifest
03/02/2004 12:23 PM 749 nwc.cpl.manifest
03/02/2004 12:23 PM 749 sapi.cpl.manifest
03/02/2004 12:23 PM 749 ncpa.cpl.manifest
03/02/2004 12:23 PM 749 wuaucpl.cpl.manifest
03/02/2004 12:23 PM 749 cdplayer.exe.manifest
7 File(s) 4,721 bytes
1 Dir(s) 25,907,277,824 bytes free
———- Files Named "Guard" ————-
Volume in drive C has no label.
Volume Serial Number is 98B1-0CF2
Directory of C:\WINDOWS\System32
——— Temp Files in System32 Directory ——–
Volume in drive C has no label.
Volume Serial Number is 98B1-0CF2
Directory of C:\WINDOWS\System32
12/09/2004 12:47 PM 263,012 pzvbha.xml.tmp
03/31/2003 06:00 AM 2,577 CONFIG.TMP
2 File(s) 265,589 bytes
0 Dir(s) 25,907,277,824 bytes free
—————- User Agent ————
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet
Settings\User Agent\Post Platform]
"{C79B4EAD-F4CF-4C78-B70D-5C82DD90B30F}"=""
———— Keys Under Notify ————
REGEDIT4
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows
NT\CurrentVersion\Winlogon\Notify]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows
NT\CurrentVersion\Winlogon\Notify\crypt32chain]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,72,79,70,74,33,32,2e,64,6c,6c,00
"Logoff"="ChainWlxLogoffEvent"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows
NT\CurrentVersion\Winlogon\Notify\cryptnet]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,72,79,70,74,6e,65,74,2e,64,6c,6c,00
"Logoff"="CryptnetWlxLogoffEvent"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows
NT\CurrentVersion\Winlogon\Notify\cscdll]
"DLLName"="cscdll.dll"
"Logon"="WinlogonLogonEvent"
"Logoff"="WinlogonLogoffEvent"
"ScreenSaver"="WinlogonScreenSaverEvent"
"Startup"="WinlogonStartupEvent"
"Shutdown"="WinlogonShutdownEvent"
"StartShell"="WinlogonStartShellEvent"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows
NT\CurrentVersion\Winlogon\Notify\Nls]
"Asynchronous"=dword:00000000
"DllName"="C:\\WINDOWS\\system32\\enn6l15s1.dll"
"Impersonate"=dword:00000000
"Logon"="WinLogon"
"Logoff"="WinLogoff"
"Shutdown"="WinShutdown"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows
NT\CurrentVersion\Winlogon\Notify\ScCertProp]
"DLLName"="wlnotify.dll"
"Logon"="SCardStartCertProp"
"Logoff"="SCardStopCertProp"
"Lock"="SCardSuspendCertProp"
"Unlock"="SCardResumeCertProp"
"Enabled"=dword:00000001
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows
NT\CurrentVersion\Winlogon\Notify\Schedule]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,6c,6e,6f,74,69,66,79,2e,64,6c,6c,00
"Impersonate"=dword:00000000
"StartShell"="SchedStartShell"
"Logoff"="SchedEventLogOff"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows
NT\CurrentVersion\Winlogon\Notify\sclgntfy]
"Logoff"="WLEventLogoff"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
"DllName"=hex(2):73,63,6c,67,6e,74,66,79,2e,64,6c,6c,00
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows
NT\CurrentVersion\Winlogon\Notify\Sebring]
"Logoff"="SebringUserLogoff"
"Logon"="SebringUserLogon"
"Impersonate"=dword:00000000
"Dllname"="C:\\WINDOWS\\System32\\LgNotify.dll"
"Asynchronous"=dword:00000000
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows
NT\CurrentVersion\Winlogon\Notify\SensLogn]
"DLLName"="WlNotify.dll"
"Lock"="SensLockEvent"
"Logon"="SensLogonEvent"
"Logoff"="SensLogoffEvent"
"Safe"=dword:00000001
"MaxWait"=dword:00000258
"StartScreenSaver"="SensStartScreenSaverEvent"
"StopScreenSaver"="SensStopScreenSaverEvent"
"Startup"="SensStartupEvent"
"Shutdown"="SensShutdownEvent"
"StartShell"="SensStartShellEvent"
"PostShell"="SensPostShellEvent"
"Disconnect"="SensDisconnectEvent"
"Reconnect"="SensReconnectEvent"
"Unlock"="SensUnlockEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows
NT\CurrentVersion\Winlogon\Notify\termsrv]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,6c,6e,6f,74,69,66,79,2e,64,6c,6c,00
"Impersonate"=dword:00000000
"Logoff"="TSEventLogoff"
"Logon"="TSEventLogon"
"PostShell"="TSEventPostShell"
"Shutdown"="TSEventShutdown"
"StartShell"="TSEventStartShell"
"Startup"="TSEventStartup"
"MaxWait"=dword:00000258
"Reconnect"="TSEventReconnect"
"Disconnect"="TSEventDisconnect"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows
NT\CurrentVersion\Winlogon\Notify\wlballoon]
"DLLName"="wlnotify.dll"
"Logon"="RegisterTicketExpiredNotificationEvent"
"Logoff"="UnregisterTicketExpiredNotificationEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001
—————- Xfind Results —————–
C:\WINDOWS\System32\DBKQUOUI.DLL +++ File read error
————– Locate.com Results —————
C:\WINDOWS\SYSTEM32\
dbkquoui.dll Sun Dec 12 2004 5:28:08p ..S.R 223,455 218.21 K
en2ql1~1.dll Sun Dec 12 2004 5:07:56p ..S.R 224,976 219.70 K
en64l1~1.dll Sun Dec 12 2004 5:28:08p ..S.R 224,916 219.64 K
enn6l1~1.dll Sun Dec 12 2004 12:05:32a ..S.R 223,455 218.21 K
gltuname.dll Sat Dec 11 2004 10:34:34p ..S.R 224,337 219.08 K
kwdes.dll Fri Dec 10 2004 8:13:06p ..S.R 225,013 219.74 K
lfngwrbk.dll Sat Dec 11 2004 8:21:06p ..S.R 223,683 218.44 K
mirapi.dll Sat Dec 11 2004 11:21:40p ..S.R 223,071 217.84 K
n6n60g~1.dll Fri Dec 10 2004 12:56:10p ..S.R 222,990 217.76 K
o4840e~1.dll Fri Dec 10 2004 11:37:12a ..S.R 225,070 219.79 K
pdrfproc.dll Fri Dec 10 2004 11:46:14a ..S.R 225,013 219.74 K
ttext.dll Sat Dec 11 2004 11:11:14p ..S.R 224,908 219.64 K
uzrlbva.dll Sat Dec 11 2004 7:44:36p ..S.R 224,892 219.62 K
wpsdmoe.dll Sat Dec 11 2004 8:18:10p ..S.R 222,956 217.73 K
14 items found: 14 files, 0 directories.
Total of file sizes: 3,138,735 bytes 2.99 M
VX2 Log:
Log for VX2.BetterInternet File Finder (msg126)
Files Found—
Additional Files—
Keys Under Notify—
crypt32chain
cryptnet
cscdll
Nls
ScCertProp
Schedule
sclgntfy
Sebring
SensLogn
termsrv
wlballoon
Guardian Key— is called:
User Agent String—
{C79B4EAD-F4CF-4C78-B70D-5C82DD90B30F}
I have downloaded Killbox but have not run it, and I will not restart.
Logfile of HijackThis v1.98.2
Scan saved at 5:43:38 PM, on 12/12/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
If you have not rebooted or shutdown/restarted, proceed as follows:
First, Disconnect from the Internet!!
(Please copy these instructions to NotePad for copy/paste use, since you will be off the Internet.)
____
Next, launch Notepad, and copy/paste all the blue REGEDIT below to it
Save in: Desktop
File Name: fixme.reg
Save as Type: All files
Click: Save
Back on the Desktop, double-click on the fixme.reg file you just saved and click on Yes when asked to merge the information.
____
Now, extract KillBox (downloaded earlier) from the zip file and double-click on KillBox.exe to run it.
In the main screen of Pocket KillBox, go to Tools in the top menu bar, and select: Delete Temp Files.
Back at the main screen of KillBox, select the option: Delete on Reboot
In the Full Path of File to Delete box, copy and paste this entry:
C:\\WINDOWS\\system32\\enn6l15s1.dll
Press the button with a red circle and a white X.
When asked if you would like to Reboot, select No.
Do the same as above for each of the files that follow, and select No when asked to reboot!
Finally, in the Full Path of File to Delete, copy and paste the following: C:\WINDOWS\System32\guard.tmp
Press the button with a red circle and a white X.
When asked to Reboot, select Yes!!
____
Make sure all windows are closed before proceeding to run HijackThis and Scan. Fix the following by placing a check in the appropriate box and selecting Fix Checked:
Open C:\perprovi.exe<–Delete File
Open C:\mpldle.exe <–Delete
Open C:\WINDOWS\jagxgwoo.exe <–Delete File
Open C:\WINDOWS\nwzilub.exe <–Delete File
Reboot the computer.
Since this intruder may alter the Hosts file, download the Hoster to restore the file: http://members.aol.com/toadbee/hoster.zip
Select: Restore Original Hosts
Click OK and exit Hoster.
____
Next, download AdAware SE from the following link: http://www.majorgeeks.com/download506.html
-Use the: 'Check for Updates Now' option and download the latest reference files
-Use the Start button, and on the next window, select: Perform Full System Scan
-Please deselect: Search for negligible risk entries
When the scan completes, select: Show Logfile
Copy/paste the complete log file, which may take 2-3 consecutive posts to this topic.
Also, check the Recycle Bin to see if it works properly. A side effect of VX2 is to sometimes damage the Recycle Bin operation.
Create an blank Notepad file on the Desktop: right click the Desktop, select New>Text Document
Right click the text document and delete it.
When a file is deleted, it should ask if you want to send it to Recycle Bin.
Does it ask if you want to send the file to the Recycle Bin, or, does the file just get deleted?
Post back what it does.
When done with all of the above, close all windows and browsers, run HijackThis, Scan, post a new HijackThis log, and a new Find_It log.
If you encounter any problems with the steps above, please describe them.
Logfile of HijackThis v1.98.2
Scan saved at 9:29:38 PM, on 12/12/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
If you have not rebooted or shutdown/restarted, proceed as follows:
First, Disconnect from the Internet!!
(Please copy these instructions to NotePad for copy/paste use, since you will be off the Internet.)
____
Next, launch Notepad, and copy/paste all the blue REGEDIT below to it
Save in: Desktop
File Name: fixme.reg
Save as Type: All files
Click: Save
Back on the Desktop, double-click on the fixme.reg file you just saved and click on Yes when asked to merge the information.
____
Now, extract KillBox (downloaded earlier) from the zip file and double-click on KillBox.exe to run it.
In the main screen of Pocket KillBox, go to Tools in the top menu bar, and select: Delete Temp Files.
Back at the main screen of KillBox, select the option: Delete on Reboot
In the Full Path of File to Delete box, copy and paste this entry: C:\\WINDOWS\\system32\\en64l1jq1.dll
Press the button with a red circle and a white X.
When asked if you would like to Reboot, select No.
Finally, in the Full Path of File to Delete, copy and paste the following: C:\WINDOWS\System32\guard.tmp
Press the button with a red circle and a white X.
When asked to Reboot, select Yes!!
____
1. Open My Computer
2. Right click on your hard drive that you wish to clean (C drive, for example)
3. In the context menu that opens, select properties
4. Under the general tab you should select Disk Cleanup
5. Windows will scan your drive which will take a few seconds/minutes
6. A box will display the various files you can remove.
Check all boxes except compress old files
7. Click OK and windows will comply.
Logfile of HijackThis v1.98.2
Scan saved at 10:34:45 PM, on 12/12/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
If you have not rebooted or shutdown/restarted, proceed as follows:
First, Disconnect from the Internet!!
(Please copy these instructions to NotePad for copy/paste use, since you will be off the Internet.)
____
Next, launch Notepad, and copy/paste all the blue REGEDIT below to it
Save in: Desktop
File Name: fixme.reg
Save as Type: All files
Click: Save
Back on the Desktop, double-click on the fixme.reg file you just saved and click on Yes when asked to merge the information.
____
Now, double-click on KillBox.exe to run it.
In the main screen of Pocket KillBox, go to Tools in the top menu bar, and select: Delete Temp Files.
Back at the main screen of KillBox, select the option: Delete on Reboot
In the Full Path of File to Delete box, copy and paste this entry: C:\\WINDOWS\\System32\\LgNotify.dll
Press the button with a red circle and a white X.
When asked if you would like to Reboot, select No.
Finally, in the Full Path of File to Delete, copy and paste the following: C:\WINDOWS\System32\guard.tmp
Press the button with a red circle and a white X.
When asked to Reboot, select Yes!!
____
1. Open My Computer
2. Right click on your hard drive that you wish to clean (C drive, for example)
3. In the context menu that opens, select properties
4. Under the general tab you should select Disk Cleanup
5. Windows will scan your drive which will take a few seconds/minutes
6. A box will display the various files you can remove.
Check all boxes except compress old files
7. Click OK and windows will comply.
Restart your computer.
post a new HijackThis log, and a new Find_It log.
✨ Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI