View Single Post
Old 07-12-2005, 12:35 AM   #5 (permalink)
sUBs
Asst Manager Security, Expert Analyst, Moderator, Security Team; Rangemaster, Moderator, TSF Academy
 
sUBs's Avatar
 
Join Date: May 2005
Posts: 24,497
OS: N/A


Run FixO.bat again & post the resultant log


~~~~~~~~~~~~~~

Copy the part below into notepad and save it as unhko.reg
Quote:

REGEDIT4

[-HKEY_CLASSES_ROOT\CLSID\{60371670-81B9-4d06-9C42-4DEC1AABE62B}]

[-HKEY_CLASSES_ROOT\TypeLib\{4947DDCC-D549-4D0B-9685-AA58B20E9642}]

[-HKEY_CLASSES_ROOT\Interface\{0B6EF17E-18E5-4449-86EA-64C82D596EAE}]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\ATLASSstp]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\HTASSstp]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\MSMsgSvc]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\SEHLPstp]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\WTLBAstp]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\explorer.exe]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\iexplore.exe]

[-HKEY_CLASSES_ROOT\BHOASS.BHDP]

[-HKEY_CLASSES_ROOT\BHOASS.BHDP.1]
Doubleclick the file and confirm you want to merge it with the registry.


~~~~~~~~~~~~~~

Copy to clipboard, all the items below by highlighting them & pressing [CTRL]+[C] on your keyboard.
C:\HJT\backups\backup-20050711-181509-151.dll
C:\Program Files\Common Files\arc7.exe
C:\Program Files\Windows Media Player\wmplayer.exe.tmp
C:\WINDOWS\browserxtras\pn\remove.exe
C:\WINDOWS\explorer32dbg.exe
C:\WINDOWS\iexplore_dbg.exe
C:\WINDOWS\mssl23.exe
C:\WINDOWS\oeunist.exe
C:\WINDOWS\system32\id113.exe
C:\WINDOWS\system32\in10b6s.dll
C:\WINDOWS\system32\istinstall_143666.exe
C:\WINDOWS\system32\JsrZ.exe
C:\WINDOWS\system32\ms.exe
C:\WINDOWS\system32\SMSSU.EXE
C:\WINDOWS\system32\thinInstall12.dll
C:\WINDOWS\system32\Tmntsrv32.EXE
C:\WINDOWS\xmllib.dll
C:\WINDOWS\XMLLIBUI.exe
Start KillBox.
  1. Go to the File menu, and choose Paste from Clipboard.
    Verify that you've done this properly by clicking the dropdown-arrow next to the Full Path of File to Delete field. The filenames you pasted will be found in there.
  2. Select/tick the following:
    * Delete on Reboot
    * End Explorer Shell While Killing File
    * Unregister.dll Before Deleting" if it's not grayed out.
  3. Click the RED X button.
  4. Click [Yes] at the 'Delete on Reboot' prompt. Click [Yes] at the Pending Operations prompt.

* If you receive a message such as: "Component 'MsComCtl.ocx' or one of its dependencies not correctly registered: a file is missing or invalid." when trying to run TheKillbox, click here to download and run missingfilesetup.exe. Then try Killbox again.


~~~~~~~~~~~~~~

Reboot to Normal mode & post a fresh HJT log along with FixO's log
__________________

Question - what have you done for the community today?
sUBs is offline