New User? Need help? Click here to register for free! Registering removes the advertisements.

Computer Cops
image image image image image image image image
Donations
If you found this site helpful, please donate to help keep it online
Don't want to use PayPal? Try our physical address
image
Prime Choice
· Head Lines
· Advisories (All)
· Dnld of the Week!
· CCSP News Ltrs
· Find a Cure!

· Ian T's (AR 23)
· Marcia's (CO8)
· Bill G's (CO11)
· Paul's (AR 5)
· Robin's (AR 2)

· Ian T's Archive
· Marcia's Archive
· Bill G's Archive
· Paul's Archive
· Robin's Archive
image
Security Central
· Home
· Wireless
· Bookmarks
· CLSID
· Columbia
· Community
· Downloads
· Encyclopedia
· Feedback (send)
· Forums
· Gallery
· Giveaways
· HijackThis
· Journal
· Members List
· My Downloads
· PremChat
· Premium
· Private Messages
· Proxomitron
· Quizz
· RegChat
· Reviews
· Google Search
· Sections
· Software
· Statistics
· Stories Archive
· Submit News
· Surveys
· Top
· Topics
· Web Links
· Your Account
image
CCSP Toolkit
· Email Virus Scan
· UDP Port Scanner
· TCP Port Scanner
· Trojan TCP Scan
· Reveal Your IP
· Algorithms
· Whois
· nmap port scanner
· IPs Banned [?]
image
Survey
How much can you give to keep Computer Cops online?

$10 up to $25 per year?
$25 up to $50 per year?
$10 up to $25 per month?
$25 up to $50 per month?
More than $50 per year?
More than $50 per month?
One time only?
Other (please comment)



Results
Polls

Votes: 943
Comments: 19
image
Translate
English German French
Italian Portuguese Spanish
Chinese Greek Russian
image
 Forum FAQForum FAQ   SearchSearch   UsergroupsUsergroups   ProfileProfile   Login to check your private messagesLogin to check your private messages   LoginLogin 

I Need Help! What Does This Mean?
Goto page 1, 2  Next
 
Post new topic   This topic is locked you cannot edit posts or make replies       Computer Cops Forum Index -> Hijackthis - Spyware, Viruses, Worms, Trojans Oh My!
View previous topic :: View next topic  
Author Message
SweetDude

Trooper
Trooper



Joined: May 15, 2004
Posts: 14
Location: Canada

PostPosted: Mon May 31, 2004 5:39 am    Post subject: I Need Help! What Does This Mean?
Reply with quote

Hi,

My Ad-Aware found this c:\window\system32\msg118.dll and says it can't be removed.

This is my HijackThis log:

Logfile of HijackThis v1.97.7
Scan saved at 2:33:44 AM, on 5/31/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Network Associates\VirusScan\avsynmgr.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Network Associates\VirusScan\VsStat.exe
C:\Program Files\Network Associates\VirusScan\Vshwin32.exe
C:\Program Files\Common Files\Network Associates\McShield\mcshield.exe
C:\Program Files\Network Associates\VirusScan\Avconsol.exe
C:\Program Files\Network Associates\VirusScan\Webscanx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe
C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe
C:\Program Files\FarStone\GameDrive\gdtask.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\Playlist.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Lavasoft - Ad-aware\Ad-aware 6\Ad-aware.exe
C:\unzipped\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.shaw.ca/Start/enCA/Home.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.shaw.ca/Start/enCA/Home.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = dynhost.inetcam.com;register.inetcam.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {E3215F20-3212-11D6-9F8B-00D0B743919D} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [DownloadAccelerator] C:\PROGRA~1\DAP\DAP.EXE /STARTUP
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\Winampa.exe"
O4 - HKLM\..\Run: [DelPnPDirver] C:\Program Files\panasonic\panasonic KX-P7100\DelPnPD.exe
O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe"
O4 - HKLM\..\Run: [RoxioAudioCentral] "C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [mandlgu] C:\WINDOWS\System32\mandlgu.exe
O4 - HKLM\..\Run: [_1258c] C:\WINDOWS\System32\_1258c.exe
O4 - HKLM\..\Run: [sfilterv] C:\WINDOWS\System32\sfilterv.exe
O4 - HKLM\..\Run: [leacco] C:\WINDOWS\System32\leacco.exe
O4 - HKLM\..\Run: [llictblz] C:\WINDOWS\System32\llictblz.exe
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\sisUSBrg.exe
O4 - HKLM\..\Run: [GameDrive] C:\Program Files\FarStone\GameDrive\gdtask.exe /AutoRestore
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [All Sea web link] "C:\Program Files\All Sea\screen saver\FWLink.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Download with &DAP - C:\PROGRA~1\DAP\dapextie.htm
O8 - Extra context menu item: Download &all with DAP - C:\PROGRA~1\DAP\dapextie2.htm
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Messenger (HKLM)
O16 - DPF: HushEncryptionEngine - https://mailserver3.hushmail.com/shared...Engine.cab
O16 - DPF: ppctlcab -
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {0C568603-D79D-11D2-87A7-00C04FF158BB} (BrowseFolderPopup Class) - http://download.mcafee.com/molbin/Shared/MGBrwFld.cab
O16 - DPF: {19E28AFC-EAE3-4CE5-AC83-2407B42F57C9} (MSSecurityAdvisor Class) - http://download.microsoft.com/download/...0091391562
O16 - DPF: {2FC9A21E-2069-4E47-8235-36318989DB13} -
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} (Office Update Installation Engine) - http://office.microsoft.com/officeupdate/content/opuc.cab
O16 - DPF: {4D7F48C0-CB49-4EA6-97D4-04F4EACC2F3B} -
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004...scan53.cab
O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - http://www.installengine.com/engine/isetup.cab
O16 - DPF: {93829908-07C2-44A2-95DB-F78F201A9B48} -
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} -
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/C...7928819444
O16 - DPF: {A4639D2F-774E-11D3-A490-00C04F6843FB} - http://download.microsoft.com/download/...msorun.cab
O16 - DPF: {B991DA79-51F7-4011-98D2-1F2592E82A56} (ACNPlayer2 Class) - http://204.118.132.145/2_0/ACNePlayer.cab
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.symantec.com/sscv6/Shar.../cabsa.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-l...cfscan.cab
O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://by2fd.bay2.hotmail.msn.com/activex/HMAtchmt.ocx


Your help is appreciated it!
Back to top
View users profile Send private message
Bulldog

Site Moderator
Site Moderator



Joined: Nov 16, 2003
Posts: 3998
Location: Canada

PostPosted: Mon May 31, 2004 10:24 pm    Post subject:
Reply with quote

Have Hijack This fix the following by placing a check in the appropriate boxes and selecting fix checked. Make sure all browser and all Windows Explorer windows are closed before fixing.

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: (no name) - {E3215F20-3212-11D6-9F8B-00D0B743919D} - (no file)
O4 - HKLM\..\Run: [mandlgu] C:\WINDOWS\System32\mandlgu.exe
O4 - HKLM\..\Run: [_1258c] C:\WINDOWS\System32\_1258c.exe
O4 - HKLM\..\Run: [sfilterv] C:\WINDOWS\System32\sfilterv.exe
O4 - HKLM\..\Run: [leacco] C:\WINDOWS\System32\leacco.exe
O4 - HKLM\..\Run: [llictblz] C:\WINDOWS\System32\llictblz.exe
O4 - HKCU\..\Run: [All Sea web link] "C:\Program Files\All Sea\screen saver\FWLink.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background

Reboot and delete:

C:\WINDOWS\System32\mandlgu.exe <-- file
C:\WINDOWS\System32\_1258c.exe <-- file
C:\WINDOWS\System32\sfilterv.exe <-- file
C:\WINDOWS\System32\leacco.exe <-- file
C:\WINDOWS\System32\llictblz.exe <-- file
C:\Program Files\All Sea <-- Folder NOTE: Try Add-Remove programs first and remove from there if present please.

NOTE: To avoid the risk of any of the above not being found due to them having the 'Hidden' attribute, first make sure that in Folder Options > View hidden and operating system files are set to show:
How to Show Hidden/System Files
http://www.xtra.co.nz/help/0,,4155-1916458,00.html

Then Download VX2Finder from this link:
http://tools.zerosrealm.com/VX2Finder.exe

Run Vx2Finder click on the *click to find VX2.BetterInternet* button. Then click *make log*.

Copy and paste the contents of the log into your next reply here.

Post a fresh Hijackthis log too please.

_________________
Cheers
Back to top
View users profile Send private message
SweetDude

Trooper
Trooper



Joined: May 15, 2004
Posts: 14
Location: Canada

PostPosted: Mon May 31, 2004 11:03 pm    Post subject:
Reply with quote

Ok, here it is.

Log for VX2.BetterInternet File Finder

Files Found---

Guardian Key--- is called: Guardian
Asynchronous 000
DllName C:\WINDOWS\system32\msg118.dll
Impersonate 000
Logon StartProcessAtWinLogon

User Agent String---
{8FDAFA60-323D-4668-83B1-B4C787F0654E}

HJT Log:
Logfile of HijackThis v1.97.7
Scan saved at 8:11:24 PM, on 5/31/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Network Associates\VirusScan\avsynmgr.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Network Associates\VirusScan\VsStat.exe
C:\Program Files\Network Associates\VirusScan\Vshwin32.exe
C:\Program Files\Common Files\Network Associates\McShield\mcshield.exe
C:\Program Files\Network Associates\VirusScan\Avconsol.exe
C:\Program Files\Network Associates\VirusScan\Webscanx.exe
C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe
C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe
C:\Program Files\FarStone\GameDrive\gdtask.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\Playlist.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\notepad.exe
C:\unzipped\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.shaw.ca/Start/enCA/Home.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.shaw.ca/Start/enCA/Home.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = dynhost.inetcam.com;register.inetcam.com
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [DownloadAccelerator] C:\PROGRA~1\DAP\DAP.EXE /STARTUP
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\Winampa.exe"
O4 - HKLM\..\Run: [DelPnPDirver] C:\Program Files\panasonic\panasonic KX-P7100\DelPnPD.exe
O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe"
O4 - HKLM\..\Run: [RoxioAudioCentral] "C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\sisUSBrg.exe
O4 - HKLM\..\Run: [GameDrive] C:\Program Files\FarStone\GameDrive\gdtask.exe /AutoRestore
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Download with &DAP - C:\PROGRA~1\DAP\dapextie.htm
O8 - Extra context menu item: Download &all with DAP - C:\PROGRA~1\DAP\dapextie2.htm
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Messenger (HKLM)
O16 - DPF: HushEncryptionEngine - https://mailserver3.hushmail.com/shared...Engine.cab
O16 - DPF: ppctlcab -
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {0C568603-D79D-11D2-87A7-00C04FF158BB} (BrowseFolderPopup Class) - http://download.mcafee.com/molbin/Shared/MGBrwFld.cab
O16 - DPF: {19E28AFC-EAE3-4CE5-AC83-2407B42F57C9} (MSSecurityAdvisor Class) - http://download.microsoft.com/download/...0091391562
O16 - DPF: {2FC9A21E-2069-4E47-8235-36318989DB13} -
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} (Office Update Installation Engine) - http://office.microsoft.com/officeupdate/content/opuc.cab
O16 - DPF: {4D7F48C0-CB49-4EA6-97D4-04F4EACC2F3B} -
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004...scan53.cab
O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - http://www.installengine.com/engine/isetup.cab
O16 - DPF: {93829908-07C2-44A2-95DB-F78F201A9B48} -
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} -
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/C...7928819444
O16 - DPF: {A4639D2F-774E-11D3-A490-00C04F6843FB} - http://download.microsoft.com/download/...msorun.cab
O16 - DPF: {B991DA79-51F7-4011-98D2-1F2592E82A56} (ACNPlayer2 Class) - http://204.118.132.145/2_0/ACNePlayer.cab
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.symantec.com/sscv6/Shar.../cabsa.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-l...cfscan.cab
O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://by2fd.bay2.hotmail.msn.com/activex/HMAtchmt.ocx

********
I deleted the wrong one...how do I put this one back on my PC:
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
Back to top
View users profile Send private message
Bulldog

Site Moderator
Site Moderator



Joined: Nov 16, 2003
Posts: 3998
Location: Canada

PostPosted: Tue Jun 01, 2004 12:10 am    Post subject:
Reply with quote

Download Unzip (extract) and run:
http://www.spywareinfo.com/~merijn/files/kill2me.zip

Reboot.

Open MSN Messenger..tools > option > general tab > put a check in Load when Windows loads.

_________________
Cheers
Back to top
View users profile Send private message
SweetDude

Trooper
Trooper



Joined: May 15, 2004
Posts: 14
Location: Canada

PostPosted: Tue Jun 01, 2004 12:52 am    Post subject:
Reply with quote

This is the message it gave me:

Unable to remove the following file(s):

C:\windows\system32\msg118.dll

The Look2Me infection might not have been removed completely

Sad
Back to top
View users profile Send private message
SweetDude

Trooper
Trooper



Joined: May 15, 2004
Posts: 14
Location: Canada

PostPosted: Tue Jun 01, 2004 12:54 am    Post subject:
Reply with quote

This is the message it gave me:

Unable to remove the following file(s):

C:\windows\system32\msg118.dll

The Look2Me infection might not have been removed completely

Sad

don't know how I made a duplicate entry Shocked
Back to top
View users profile Send private message
Bulldog

Site Moderator
Site Moderator



Joined: Nov 16, 2003
Posts: 3998
Location: Canada

PostPosted: Tue Jun 01, 2004 1:37 am    Post subject:
Reply with quote

Crap.

Sign off and stay off the internet until the entire procedure is complete.

Open VX2Finder and click on the *click to find VX2.BetterInternet* button.
Put a check beside all files.
Then select the *Delete these files* button.
You will be left with notice about one to be deleted on reboot.
It will ask to reboot on deletion of the last file (Reboot)

-----------------
Once back in Windows


Open VX2Finder again and click on these buttons in the right pane:

user agent, Guardian.reg, restore policy

Exit and reboot.

_________________
Cheers
Back to top
View users profile Send private message
SweetDude

Trooper
Trooper



Joined: May 15, 2004
Posts: 14
Location: Canada

PostPosted: Tue Jun 01, 2004 3:43 am    Post subject:
Reply with quote

I know this is really weird but there is no boxes for me to check it off and the delete button is greyed out. Confused
Back to top
View users profile Send private message
Bulldog

Site Moderator
Site Moderator



Joined: Nov 16, 2003
Posts: 3998
Location: Canada

PostPosted: Tue Jun 01, 2004 7:38 am    Post subject:
Reply with quote

Not weird at all, I was half expecting that since you seem to have an older version of the nasty.

Are you able to select the other boxes:
user agent, Guardian.reg, restore policy
or are they greyed out too ?
If so..do so and when you reboot, locate and delete the msg118 file .

_________________
Cheers
Back to top
View users profile Send private message
SweetDude

Trooper
Trooper



Joined: May 15, 2004
Posts: 14
Location: Canada

PostPosted: Tue Jun 01, 2004 11:36 am    Post subject:
Reply with quote

The only box that is greyed out is the delete button.
Back to top
View users profile Send private message
SweetDude

Trooper
Trooper



Joined: May 15, 2004
Posts: 14
Location: Canada

PostPosted: Tue Jun 01, 2004 11:41 am    Post subject:
Reply with quote

The only box that is greyed out is the delete button.
Back to top
View users profile Send private message
Bulldog

Site Moderator
Site Moderator



Joined: Nov 16, 2003
Posts: 3998
Location: Canada

PostPosted: Tue Jun 01, 2004 11:48 am    Post subject:
Reply with quote

Use the three other boxes (buttons) then please.
user agent, Guardian.reg, restore policy

Reboot.
Then see if you can locate and delete:
C:\windows\system32\msg118.dll <-- file

NOTE: To avoid the risk of any of the above not being found due to them having the 'Hidden' attribute, first make sure that in Folder Options > View hidden and operating system files are set to show:
How to Show Hidden/System Files
http://www.xtra.co.nz/help/0,,4155-1916458,00.html

also after you reboot:
Download the latest version of Ad-Aware at http://www.lavasoftusa.com/support/download/
After installing AAW, and before running the program, FIRST update the reference file following these instructions.
http://www.lavahelp.com/howto/updref/index.html
Now do the following:
- Under Ad-aware 6 > Settings (Gear at the top) > Tweaks > Scanning Engine:
check: "Unload recognized processes during scanning."
- Under Ad-aware 6 > Settings (Gear at the top) > Tweaks > Cleaning Engine:
Check: "Let Windows remove files in use after reboot."
Press "Scan Now"
- Check option "Use Custom scanning options"
- Check option "Activate In-Depth Scan"
- Press "Select drives\folders to scan"
- Select the active partition which is usually C:
Now press "Next" to let Ad-aware scan your drives...
It will find a number of "bad" files and registry keys.
Right-click in that pane and choose "select all"
Now press "Next" again.
It will ask you whether you'd like to remove all checked items. Click OK.
Finally, close Ad-Aware, and reboot.

_________________
Cheers
Back to top
View users profile Send private message
SweetDude

Trooper
Trooper



Joined: May 15, 2004
Posts: 14
Location: Canada

PostPosted: Tue Jun 01, 2004 1:14 pm    Post subject:
Reply with quote

I did use the user agent, guardian reg, restore policy. Rebooted. I found the msg118.dll file but when I tried to delete it I got this message:

Cannot delete msg118.dll: Access is denied.
Make sure the disk is not full or write-protected and that the file is not
currently in use.

Rebooted. Ran Ad-Aware anyways and it found the file and I deleted it then rebooted again. The file is still there.
Back to top
View users profile Send private message
Bulldog

Site Moderator
Site Moderator



Joined: Nov 16, 2003
Posts: 3998
Location: Canada

PostPosted: Wed Jun 02, 2004 1:18 am    Post subject:
Reply with quote

Post a fresh VX2Finder log please.
_________________
Cheers
Back to top
View users profile Send private message
Bulldog

Site Moderator
Site Moderator



Joined: Nov 16, 2003
Posts: 3998
Location: Canada

PostPosted: Wed Jun 02, 2004 10:13 am    Post subject:
Reply with quote

Try this please:

Go to Start > run > type regedit enter
Navigate to:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Guardian

Right click Guardian in the left hand pane and select permissions > advanced > and uncheck *Inherit permissions from parent....* > if prompted by a dialog box, click Remove*
Exit Regedit and
reboot.

Now navigate back to that same Guardian key and recheck that same *inherit permissions from parent...* box.

Then right click on Guardian again and select delete
Close regedit.

Now locate and delete these files:

C:\WINDOWS\System32\msg118.cpy.dll <--file
C:\WINDOWS\System32\msg118.dll <--file

Then open regedit again and navigate to:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform

Find this value in the right pane, if present, right click on it and Delete it!
{8FDAFA60-323D-4668-83B1-B4C787F0654E}

Reboot. and run Adawre again.

_________________
Cheers
Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   This topic is locked you cannot edit posts or make replies       Computer Cops Forum Index -> Hijackthis - Spyware, Viruses, Worms, Trojans Oh My! All times are GMT - 5 Hours
Goto page 1, 2  Next
Page 1 of 2

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum


Powered by phpBB 2.0.8a © 2001 phpBB Group

Version 2.0.6 of PHP-Nuke Port by Tom Nitzschner © 2002 www.toms-home.com
Version 2.2 by Paul Laudanski © 2003-2004 Computer Cops