1. commonlawwife

    commonlawwife Private E-2

    I'm working on my uncle's computer and have been unable to remove cws_hputi. I have run Spybot Search and Destroy, Spysweeper, Counter Spy, and CWShredder; none of them have removed cws_hputi. Additionally, it will not let me install Ad-Aware. It downloads, but will never begin the installation process. I have run hijackthis and deleted the obvious problem files, but I'm waiting to post it as per the request at the top of the page. Help!
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to MG's CommonLawWife!

    You should attempt to follow all the steps in this Sticky thread < READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal >

    If you already have any of the programs linked in the tutorial please double check your version to make sure you have the latest one and that you have any/all updates for the programs.

    NOTE: In order to resolve the issues you are having it is very important that you at least try to perform all the steps as outlined. If you have any difficulty please post back letting us know what steps you have completed, what you found while doing the scans if anything and details about any problems you have encountered in completing the steps. The more details you can provide the better.

    If still having a problem after the above, you should read the tutorial in this Sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Now post a HijackThis log file as an attachment to your message. All running programs should be closed, including your web browser, e-mail. Close before running Hijack This!

    Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file. Place it in its own folder, for example C:\Program Files\HJT

    Make sure you have HJT version 1.98.2 and follow the guidelines on where to install it and how to post a log as an attachment.
     
  3. PhilliePhan

    PhilliePhan Guest

    Hi Commonlawwife,

    Generally, we like people to start with the Cleanup Tutorial HERE:
    READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan and Virus Removal

    But, it seems like you have done a lot already. I DO suggest that you run the Online Scans. Then, attach a log as per the instructions below.

    Note that your HijackThis should be up-to-date (v1.98.2) and MUST be extracted to its own safe folder - C:\Program Files\HijackThis!

    If you need a Fresh Download of HJT, get it HERE: HijackThis 1.98.2

    Also note that, before you scan, you MUST close all running programs including your web browser, e-mail and items in the system tray.

    Please save your HJT Log and attach it via the "Manage Attachments" tool in the Additional Options section when you post.

    Somebody will take a look when they get a chance.

    Best :)
    PP

    *** Looks like Chas is on the case! Carry on!
     
    Last edited by a moderator: Nov 26, 2004
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're too slow Turkey Boy! :p
     
    Last edited by a moderator: Nov 25, 2004
  5. commonlawwife

    commonlawwife Private E-2

    Thanks for the replies! I read that FAQ tutorial before posting and have gone through all the steps - sorry I didn't clarify that. I am typically pretty awesome with managing spyware (I work in tech support) but this one is really giving me grief. Attached is my HJT log:
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you sure you ran CWShredder too?
    Please start by using Add/Remove programs to uninstall WeatherBug.

    Also do not have any browsers running when using HJT. You had two IE sessions running.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Assuming WeatherBug uninstalled continue with the below.
    Make sure you have system restore disabled and viewing of hidden files enabled (per the tutorial).


    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: (no name) - {467FAEB2-5F5B-4c81-BAE0-2A4752CA7F4E} - C:\WINDOWS\System32\O0ZBB1~1.DLL
    O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} (MiniBugTransporterX Class) - http://wdownload.weatherbug.com/minibug/tricklers/AWS/MiniBugTransporter.cab?
    O20 - AppInit_DLLs: lkzf1v5295i6.dll

    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\System32\O0ZBB1~1.DLL
    C:\WINDOWS\System32\lkzf1v5295i6.dll


    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  8. commonlawwife

    commonlawwife Private E-2

    I would delete Weatherbug, but this is my uncle's computer and he sure does enjoy that program. :(

    I have run CWShredder at least 5 times, with IE closed.

    Thanks again for the help.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay but it does put adware/spyware onto PCs. The paid version may not do that.

    Did you see my other message below?

    You may want to skip the below line if you are keepin WeatherBug:
    O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} (MiniBugTransporterX Class) - http://wdownload.weatherbug.com/min...Transporter.cab?
     
  10. commonlawwife

    commonlawwife Private E-2

    Yeah, I deleted those files in HJT and then tried deleting
    C:\WINDOWS\System32\O0ZBB1~1.DLL
    and
    C:\WINDOWS\System32\lkzf1v5295i6.dll
    in safe mode, but O0ZBB1 wasn't there and lkzf1v5295i6.dll was in use by another program. It definitely was not write protected. CWS_hputi is still showing up when I scan with Spy Sweeper. I think if I could just get the new Ad-Aware to download, it would fix the problem...GAHHHHHHHHHHh.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    By the way, you did not run all the steps in the READ ME FIRST. There are no signs of the onlines scans being run.
     
  12. commonlawwife

    commonlawwife Private E-2

    I did them after running that log, sorry. They did not find anything.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you exit all browsers before trying to delete those files? Also O0ZBB1~1.DLL is a shortened file name. Look for something similar but longer.

    Please run About:Buster, it may take care of the AppInit_DLL.. Note, it will change your home page to www.google.com when finished though.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Our directions need to be followed in the order given. A log should not have been posted until the whole READ ME had been run.
     
  15. commonlawwife

    commonlawwife Private E-2

    Nothing at all was running when I tried deleting those files, and the only application running was was the system32 folder. I know that was a shortened file - there was nothing similar. I understand that all those steps needed to be run, and I am sorry. No need to be snippy. I'll do the Buster, no problem about google.
     
  16. commonlawwife

    commonlawwife Private E-2

    Did those, nada.
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It's not being snippy! We just expect that when someone tells us they followed the procedure that they actually did.

    What do you mean the "only application running was the system32 folder"? I think you mean you had Windows Explorer running with the system32 folder open?


    1) go here and download Registrar lite and install it: http://www.majorgeeks.com/download469.html
    2) Run it, copy and paste this line to reglite's address bar:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs
    3) Click the "go" tab
    4) Find: "AppInit_Dlls" value on the right side panel.
    5) Rename the Folder Windows to NotWindows highlighted as a light blue (some people call it light purple) folder in the left hand pane of reglite.
    6) Double Click "AppInit_DLLs" again and clear the data value:
    C:\WINDOWS\System32\lkzf1v5295i6.dll < delete this line , 'Apply' and 'ok' to set.
    7) Rename the NotWindows folder back to its original name Windows
    This should make the file visible.
    8) Now use Windows Explorer to delete C:\WINDOWS\System32\lkzf1v5295i6.dll
    If you cannot delete it, try the above again from safe mode.

    Please post a new HJT log after this.
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If the steps in my previous message do not help you delete that file, try this:

    Download KillBox from: http://download.broadbandmedic.com/
    Run the program and in the box type in C:\WINDOWS\System32\lkzf1v5295i6.dll
    Hit delete. If that doesnt work... Tick the box delete on reboot.
    Then let it run on reboot.
     
  19. commonlawwife

    commonlawwife Private E-2

    I had to use KillBox and have it delete upon startup, now I've run HJT again and here's my log...

    I noticed everything I had previously deleted has come back. So annoying.
     

    Attached Files:

  20. commonlawwife

    commonlawwife Private E-2

    Actually, I think I got it. I think deleting that file allowed me to download Ad-Aware, and the combination of that and Norton AV got rid of the problematic dll file. Thank you so much for your help.
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome but perhaps you should post one last log so we can double check.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds