|
|
Pancake
HijackThis Helper
Reg'd: Sat
Posts: 1257
Loc: Victoria,Australia
|
Re: Probably hijacked
Mon May 26 2008 04:35 AM
|
|
|
Please copy this page to *Notepad* and save to your desktop for reference as you will not have any browsers open while you are carrying out portions of these instructions.
It's IMPORTANT to carry out the instructions in the sequence listed below. 1. Close any open browsers. 2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
Open *notepad* and copy/paste the text in the quotebox below into it:
Quote:
File:: C:\WINDOWS\system32\jpewocmz.ini C:\WINDOWS\system32\lpcywinp.exe
Registry:: [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4EA2008F-CF84-40DF-BDD0-FCD559C919FD}] HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices] "Keygen.exe"=- [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\khFUoliF]
Save this as CFScript.txt, in the same location as ComboFix.exe which is on the Desktop.

Refering to the picture above, drag CFScript.txt into ComboFix.exe
When finished, it shall produce a log for you at C:\ComboFix.txt
Please copy and paste the ComboFix.txt along with a fresh HijackThis log in your next reply please.
*Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall.Altering this script in any way could damage your computer*
==========================
Go to http://www.kaspersky.com/kos/eng/partner/default/kavwebscan.html
Answer Yes, when prompted to install an ActiveX component.- The program will then begin downloading the latest definition files.
- Once the files have been downloaded click on NEXT
- Locate the Scan Settings button & configure to:[list]
- Scan using the following Anti-Virus database:[list]
- Extended
Scan Options:- Scan Archives
- Scan Mail Bases
[/list] Click OK & have it scan My Computer Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.


Click the Save as Text button to save the file to your desktop so that you may post it in your next reply[/list][size=1]* Turn off the real time scanner of any existing antivirus program while performing the online scan[/size]
--------------------
|
|
|
|
0 registered and 9 anonymous users are browsing this forum.
Moderator: putasolutions, greysts, bricat, AndrewC, Joe_London, John_McKenna, Mouse, Hello_There, TheFatControlleR, Nanook, Noviciate
Print Thread
|
Forum Permissions
You cannot start new topics
You cannot reply to topics
HTML is disabled
Mark-up is enabled
|
Rating:
Thread views: 0
|
|
|