1. MolotoV

    MolotoV Private E-2

    I can't seem to get rid of t.swapx
    I have tried adaware and spybot without success
    coolwwwsearch keeps coming up in spybot and the homepage is always directed to swapx

    Please help if you can. Here is what hijackthis reported


    Edit by chaslang: Unrequested, inline log deleted
     
    Last edited by a moderator: Nov 24, 2004
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    HijackThis is the last step and we have rules about how and when to post a log.

    Please follow all the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal

    If you already have any of the programs linked in the tutorial please double check your version to make sure you have the latest one and that you have any/all updates for the programs.

    NOTE: In order to resolve the issues you are having it is very important that you at least try to perform all the steps as outlined. If you have any difficulty please post back letting us know what steps you have completed, what you found while doing the scans if anything and details about any problems you have encountered in completing the steps. The more details you can provide the better.

    After doing the above, if still having problems, you should read the tutorial in this Sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Now post a HijackThis log file as an attachment to your message. All running programs should be closed, including your web browser, e-mail. Close before running Hijack This!
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    After following my previous message, you will most likely need to do the below.

    Make sure System restore is Off and you have enabled the viewing of hidden files as per our Read me First Sticky Post at the top of the forum..
    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://win-eto.com/hp.htm?id=9
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://win-eto.com/hp.htm?id=9
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://win-eto.com/hp.htm?id=9
    O2 - BHO: (no name) - {467FAEB2-5F5B-4c81-BAE0-2A4752CA7F4E} - C:\WINDOWS\system32\W8C6S4~3.DLL
    O4 - HKLM\..\Run: [Control handler] C:\WINDOWS\system32\cslr6pofyj8fthd.exe
    O4 - Global Startup: winlogin.exe
    O20 - AppInit_DLLs: w8c6s4xcm66o9zdll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll


    Make sure ALL Browser Windows are CLOSED. Then, Click FIX and then, while still in HijackThis, look in the lower right-hand box where it says “Other stuff,” and select CONFIG > MISC TOOLS > select DELETE A FILE ON REBOOT and where it says File Name, Enter (or navigate to the file in HijackThis pane) C:\WINDOWS\System32\w8c6s4xcm66o9zdll.dll and click OPEN.
    A message will ask you if you want to reboot now. Click YES and reboot into Safe Mode by tapping F8.

    While in Safe mode, navigate to and DELETE:
    C:\WINDOWS\system32\cslr6pofyj8fthd.exe
    C:\WINDOWS\system32\W8C6S4~3.DLL
    C:\windows\system32\winlogin.exe <--- note this is not winlogon.exe which is valid.
    The above winloging.exe file may be in one of your user folders under
    C:\Documents and Settings\username\Local Settings\temp
    where username is your user's name. You may have to search around for it.

    Now reboot normal mode and post a new HJT log attachment.
     
  4. MolotoV

    MolotoV Private E-2

    The winlogin.exe would not delete through hijack this and I could not find it in any folders or by running a search.

    Here are the new hijackthis results
     

    Attached Files:

  5. PhilliePhan

    PhilliePhan Guest

    Hi MolotoV,

    Please download this tool: Pocket KillBox

    Run Pocket Killbox and select the Delete on Reboot option.

    Then copy and paste the following into the Box: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\winlogin.exe

    and Click Delete (red X) and then Yes or OK until your machine reboots.

    Then Scan with HJT and attach that log. A few of the items that need to be removed are still there. Chas or I will check back.

    Best Luck :)
    PP
     
    Last edited by a moderator: Nov 24, 2004
  6. MolotoV

    MolotoV Private E-2

    Taken care of

    Here is the next HJT report
     

    Attached Files:

  7. PhilliePhan

    PhilliePhan Guest

    Hi MolotoV,

    Please print out these instructions so that you can operate with All Browser Windows CLOSED.

    Please make sure System Restore is OFF and the Viewing of Hidden Files is Enabled as per the tutorial.

    First, navigate to C:\WINDOWS\System32\w8c6s4xcm66o9zdll.dll and verify that this is the correct path for the DLL.
    If it is not there, try looking for it here: C:\WINDOWS\w8c6s4xcm66o9zdll.dll

    After you find the correct path, run Pocket Killbox and again choose the Delete on Reboot option. Navigate to w8c6s4xcm66o9zdll.dll and press the Delete button (red X) and then Yes or OK until your machine reboots.

    After your machine reboots, navigate to where the file should be and make sure it is gone.

    Once it is gone, scan with HijackThis and Check the Boxes for the following:

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://win-eto.com/hp.htm?id=9

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://win-eto.com/hp.htm?id=9

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://win-eto.com/hp.htm?id=9

    O2 - BHO: (no name) - {467FAEB2-5F5B-4c81-BAE0-2A4752CA7F4E} - C:\WINDOWS\system32\W8C6S4~3.DLL

    O20 - AppInit_DLLs: w8c6s4xcm66o9zdll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.d


    Again, make sure All Browser Windows are Closed when you Click FIX.

    Now boot into Safe Mode and DELETE the following if it should somehow remain:

    C:\WINDOWS\System32\W8C6S4~3.DLL

    Reboot to Normal Windows and Scan with HijackThis and attach that log. That ought to get it :) Chas or I will check back.

    PP
     
  8. MolotoV

    MolotoV Private E-2

    It looks to me like it did the trick. If not let me know

    Here is what is hopefully the final hijackthis report
    Thankyou very much for your help
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You log is clean now! I wonder why it did not work the first time I gave you similar steps. The only real difference with what PP gave you was using KillBox which is similar to using HJT to delete the file on reboot.
     
  10. PhilliePhan

    PhilliePhan Guest

    You're losing your touch, old timer! :p ;) See what happens when you are away for a week or two?? :)

    MolotoV - Your HJT log looks good! I suggest that you implement some of Chaslang's recommendations HERE:How to protect yourself from malware!

    I definitely recommend that you use the following tools:
    Ad-Aware SE Personal

    SpyBot-Search & Destroy - Remember to use the "Immunize" feature

    SpywareBlaster

    These are all FREE! Just remember to Internet Update them regurlarly! They, along with a good Anti-Virus and Firewall & keeping your Windows up-to-date will do wonders in helping to keep Malware off your computer!

    Best :)
    PP
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds