The Generic Solution Works!

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by donnieb, Aug 10, 2004.

  1. donnieb

    donnieb Private E-2

    After a recent visit by my grandaughter, my Compaq laptop had a whole bunch of new things going on, including pop-ups, new toolbars on the browser, and a really slow running machine. I tried the TechGuys forum, but could never get an answer. I happened on this site yesterday, and after some reading, followed your "generic solution" procedures. It took almost 5 hours, but it appears everything is back to normal. I am posting my hijack and about-buster logs (as it says to do in the procedure). But I think all is well.

    It's great to have a site like yours around and all of those neat tools you have accumulated into a process that works.

    Thanks
    DonnieB

    Log file removed and attached.
     

    Attached Files:

    Last edited by a moderator: Aug 10, 2004
  2. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    Removed due to error on my part. Sorry.
     
    Last edited: Aug 11, 2004
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Wait MA and DonnieB!!!! Do not fix the O10 lines with HijackThis. You could totally break your internet connection. You should download LSPfix from http://www.cexx.org/lspfix.zip

    Unzip and run it. Check all instances of lspak.dll (and nothing else) , and move them to the "Remove" pane. You will have to click the "I know what I'm doing" button.

    Reboot after having this fixed by LSPfix.

    Now they should no longer show in a HijackThis scan.
     
    Last edited: Aug 11, 2004
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    By the way Donnie, update to the latest version of HijackThis here.
     
  5. donnieb

    donnieb Private E-2

    Thanks for the help. I ran ispfix and moved one dll over to remove. Here is the new hijack file.

    when I restarted the computer this time, it told me my registry space was too small, and to make it larger. Before I do this, can you tell me if you think that is normal or is an indicator of a new problem?

    Thanks again - I'll tell everybody I know about your site.

    DonnieB :D


    Edit by chaslang: HJT log changed to an attachment.
     

    Attached Files:

    • hjt.txt
      File size:
      5.9 KB
      Views:
      0
    Last edited by a moderator: Aug 11, 2004
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Donnie,

    There are two Sticky threads that you need to read.
    One on the guidelines on posting HijackThis logs. Follow them from now on.
    http://forums.majorgeeks.com/showthread.php?t=38752

    And another on things to do prior to even thinking about using HijackThis:
    http://forums.majorgeeks.com/showthread.php?t=35407


    Your last log looks okay other than those three O17 lines that MA previously mentioned. What he said (and you did not answer):

    I dont know what this is, do you:
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = bikinibottom.dom
    O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = bikinibottom.dom
    O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = bikinibottom.dom

    For the registry space being to small, try this.
    Right click My Computer and seclect Properties.
    Click the Advanced, the Performance Options, and then Virtual Memory.
    Click on change, then you should see the current registry settings.
    Increase as necessary to accomodate your existing registry size.
    Save and reboot.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds