View Single Post
Old 06-03-2005, 10:14 AM   #12 (permalink)
Bobrocks
TSF Enthusiast
 
Join Date: Nov 2004
Posts: 437
OS: WinXP


Send a message via MSN to Bobrocks
Please print out or copy this page to Notepad. Make sure to work through the fixes in the exact order it is mentioned below. If there's anything that you don't understand, ask your question(s) before proceeding with the fixes. You should not have any open browsers when you are following the procedures below.

Go to Start->Run and type in regedit and hit OK. Go to File->Export and save the registry somewhere as a backup. While in the Registry Editor, navigate to:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Pol icies\Explorer\Run\
"wkouy" = "C:\WINDOWS\system32\wkouy.exe" [null data] <-- Delete that entry
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run \
"wkouy" = "C:\WINDOWS\system32\wkouy.exe" [null data] <-- Delete that entry

If any of the above registry keys are giving you problems deleting, right click on them and click on Permissions. Then click on the Advanced button. Make sure the first box (Inherit from parent...) is checked. Click OK and OK. Then try deleting the entry again. Once you're done, close the Registry Editor.

Download KillBox http://www.greyknight17.com/spy/KillBox.exe. Run KillBox and check the box that says 'End Explorer Shell While Killing File'. Next click on 'Delete on Reboot'. For each of the following files below, check the box that says 'Unregister .dll Before Deleting' if it's not grayed out. Copy and paste each of the following into KillBox (hitting the X button for each file - choose NO when it asks if you want to reboot):

C:\WINDOWS\system32\bH.dll
C:\WINDOWS\system32\in3bI.dll
C:\WINDOWS\system32\epx30104.exe
C:\WINDOWS\system32\wkouy.exe
C:\WINDOWS\IFinst27.exe

Restart into normal mode and give us a new set of logs using Microbells previous instructions as a guide and also give us a new HijackThis log.
__________________
Bobrocks is offline