View Single Post
Old 11-14-2008, 06:08 AM   #13 (permalink)
TheBruce1
Moderator, Analyst, Security Team
 
TheBruce1's Avatar
 
Join Date: Oct 2006
Location: Důn Čideann,Scotland.
Posts: 5,093
OS: XP


Re: Browser Redirects, Hijacks, etc.

Hello again

Quote:
My Avast! AV software doesn't startup on boot anymore and I can't seem to get it to run the resident on-access protection. Should I reinstall or do you recommend a different product?
It is possible that some Avast files have become corrupted. Re-installing would be the best option, but first.

Download the Avast Free Installer File to your desktop.

Next, go to add and remove and select Avast. You maybe presented with two options, remove and repair- choose repair.

If repair is not an option, please disconnect from the internet and remove Avast. Once Avast has been uninstalled, reboot.
Double-click on the Avast installer file and follow the prompts to install, reconnect to the internet when Avast requires to update.
Run a full scan once completed, report back anything found.


Quote:
Also, as I page through the logfiles (amateur that I am), I still see references to some of the (assumed) problem files such as wadetaro.dll and bibijiwo.dll.
Correct, those are just orphaned registry entries.

=========

Open HijackThis and click on 'Do a System Scan Only'. Check the following entries (If they still exist, make sure you do not miss any)

O4 - HKLM\..\Run: [CPM57bdb8af] Rundll32.exe "c:\windows\system32\bibijiwo.dll",a
O4 - HKUS\S-1-5-19\..\Run: [bobozomeze] Rundll32.exe "C:\WINDOWS\system32\wadetaro.dll",s (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [bobozomeze] Rundll32.exe "C:\WINDOWS\system32\wadetaro.dll",s (User 'NETWORK SERVICE')
O20 - AppInit_DLLs: c:\windows\system32\bibijiwo.dll
O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\bibijiwo.dll (file missing)
O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\bibijiwo.dll (file missing)



Please remember to close all other windows, including browsers then click Fix checked.

===========

Run RSIT again and post the log.txt in your reply, also if Avast found anything post that information in your reply as well.
__________________
Member of ASAP since 2007
Member of UNITE since 2008


**Notice to BT customers**
BT to dump Phorm, see Here for more information. No DPI

If we have helped you in anyway, please consider Donating
TheBruce1 is offline