bricat
(HijackThis Helper)
Thu May 01 2008 12:22 AM
Re: IE ad. popups(again)+ BHO activity in IE.

Please copy this page to *Notepad* and save to your desktop for reference as you will not have any browsers open while you are carrying out portions of these instructions.

It's IMPORTANT to carry out the instructions in the sequence listed below.


1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.


Open *notepad* and copy/paste the text in the quotebox below into it:

Quote:




Killall::

File::
C:\WINDOWS\system32\htolfdji.dll
C:\WINDOWS\system32\lveaedgc.dll
C:\WINDOWS\BM7fbecf2c.xml
C:\Documents and Settings\Andy\Application Data\inst.exe
C:\WINDOWS\tosOBEX.INI
C:\WINDOWS\JCMkr32.INI

Folder::
C:\Documents and Settings\Andy\Application Data\Desktopicon

Registry::
[-HKEY_LOCAL_MACHINE\software\microsoft\windowsnt\currentversion\winlogon\notify\cbXRLcAq]
[-HKEY_LOCAL_MACHINE\software\microsoft\windowsnt\currentversion\winlogon\notify\jkkLFurr]
"jkkLFurr.dll"=-






Save this as CFScript.txt, in the same location as ComboFix.exe which is on the Desktop.




Referring to the picture above, drag CFScript.txt into ComboFix.exe.

This will start ComboFix again.(it may ask you to reboot your computer)

When finished, it shall produce a log for you at C:\ComboFix.txt

Please copy and paste the ComboFix.txt along with a fresh HijackThis log in your next reply please and
let me know how it is running
.


*Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall*


Contact Us | Privacy statement Main website
Hitwise Top 10 Award Winner - Jan-Mar 2005

About us | Contact us | Link to us | Terms & Conditions | Privacy Policy
© Copyright IPC Media Limited, All rights reserved