Google Fake results. please help.

Discussion in 'Malware Help (A Specialist Will Reply)' started by ekstrak, Feb 14, 2005.

  1. ekstrak

    ekstrak Private E-2

    Hi.

    i just been through the help section and installed all the countless malware killers etc, ran them all but am still scratching my head. no dice.

    anyone got any new ideas about getting rid of this vile piece of code ?

    thanks alot

    ekstrak.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It's more than likely due to a file named something like DSMAN~1.DLL.

    Make sure you have done ALL steps of the READ ME FIRST and then do the below.


    Make sure you have HijackThis 1.99 and follow the guidelines on where to install it and how to post a log as an attachment. This is all covered in the sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Now post a HijackThis log as an attachment to your message (Do not post the log inline). All running programs should be closed, including your web browser, e-mail. Close before running Hijack This!

    To repeat: Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file. Place it in its own folder, for example C:\Program Files\HJT
     
  3. ekstrak

    ekstrak Private E-2

    Hi.

    yeah so i did all the steps listed in the READ ME FIRST and now here is my hiJackThis log.

    thanks again for any help.
     

    Attached Files:

  4. magic888666

    magic888666 Private E-2

    Im Having The Same Problem Too, Im Goin Crazy Over This
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! I repeat RUN ALL THE STEPS OF THE READ ME FIRST. You did not run all of them.

    And I specifically requested that you not install HijackThis in a temp folder. You have it here:
    C:\TEMP\download\spyware\hijackthis\HijackThis.exe

    It is too easy to loose backups that way. You should not be putting your download in a subfolder under temp. Temp means you don't need anything in that folder and don't care if they are deleted during a cleanup.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You also have two antivirus applications installed. You must uninstall one of them.

    You will need to download LSP - Fix and follow the directions given below

    NOW:
    Unzip it and run LSP-Fix.

    Check the Box labeled "I know what I'm doing" and then click on the fltmgr.dll file (in the “Keep” section) to select it.

    Then, Select the >> button to move fltmgr.dll into the Remove section.

    Now, click the Finish Button. When the Repair Summary box appears, click OK.

    Do you know what this MAFWTaskbarApp is for?
    C:\WINDOWS\System32\MAFWTray.exe
    O4 - HKLM\..\Run: [MAFWTaskbarApp] C:\WINDOWS\System32\MAFWTray.exe

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    c:\windows\system32\fltmgr.dll

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again.

    Now:
    Go to Start > Run and type: cleanmgr and then click OK. Make sure the boxes for these are checked:
    Temporary Files
    Temporary Internet Files
    Recycle Bin
    And Click OK.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
    .
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds