View Single Post
Old 05-31-2005, 07:11 PM   #11 (permalink)
MicroBell
Manager Emeritus - Security Center, Expert Analyst, Moderator - Security Team; Rangemaster, TSF Academy & Supporter
 
MicroBell's Avatar
 
Join Date: Sep 2004
Location: Carmichaels, PA-USA
Posts: 6,963
OS: Windows 7


Send a message via ICQ to MicroBell Send a message via MSN to MicroBell
Ok..lets try this again....

If you have a highspeed connection please Run an online virus scan from TrendMicro Please select the “autoclean” option when prompted to do so.

Download KillBox http://www.bleepingcomputer.com/file...re/KillBox.zip

Run the cleanup utility and reboot/logoff when prompted. Reboot into Safe Mode (hit F8 key until menu shows up). Make sure to close any open browsers. Go into HijackThis->Config->Misc. Tools->Open process manager. Select the following and click Kill process for each one if they are still listed (they shouldn't be but make sure)

C:\WINDOWS\wkssvc.exe

Go to Start->Run and type Services.msc then hit Ok

Scroll down and find the service called: Workstation Service Library (Microsoft Locator Service)

When you find it, double-click on it. In the next window that opens, click the Stop button, then click on properties and under the General Tab, change the Startup Type to Disabled. Now hit Apply and then Ok and close the window.

Now Click Start>Run, type cmd into the Open editbox and click the Ok button.

Copy/paste the line below into the Command Prompt window and press the Enter key:

sc delete Microsoft Locator Service

Close the Command Prompt window

Run hijackthis and fix the following...

O23 - Service: Workstation Service Library (Microsoft Locator Service) - Unknown owner - C:\WINDOWS\wkssvc.exe

Run KILL box. Paste the following locations into KILL BOX one at a time. Checkmark the box that says "Delete on Reboot" and checkmark the box "Unregister DLL" (If available) Click the RED X and it will ask you to confirm the file for deletion…say YES and when the next box opens prompting you to reboot now...click NO...and proceed with the next file. Once you get to the last one click YES and it will reboot.

C:\WINDOWS\wkssvc.exe
c:\windows\userint32.exe


Once done reboot into Normal Mode and post a new HijackThis log file to confirm what was removed and if it's clean or not.
__________________
We Are The BORG Spyware KILLER and Adware Destroyer!





Spyware/Adware Removal Tools
Hijackthis
Ad-aware SE
Spybot Search&Destroy
SpywareBlaster
CWShredder
MicroBell is offline