|
Open Killbox.exe and paste in the space provided in Killbox C:\WINDOWS\SYSTEM32\tipi.dll.
Then tick the Delete on reboot option and click the red X. This sets it to delete on reboot but don’t reboot just yet.
Do this for all dll files listed below
C:\WINDOWS\SYSTEM32\lvns09~1.dll
C:\WINDOWS\SYSTEM32\aki9dgaa.dll
C:\WINDOWS\SYSTEM32\m064la~1.dll
C:\WINDOWS\SYSTEM32\ugl.dll
C:\WINDOWS\SYSTEM32\sytupwbv.dll
C:\WINDOWS\SYSTEM32\kudlt.dll
C:\WINDOWS\SYSTEM32\kt02l7~1.dll
C:\WINDOWS\SYSTEM32\zxebauth.dll
C:\WINDOWS\SYSTEM32\p48q0e~1.dll
C:\WINDOWS\SYSTEM32\guard.tmp
Now rescan with hijackthis and insert a check next to each of the following entries, close all other browser windows and click “fix checked”
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 auto.search.msn.com
O1 - Hosts: 69.20.16.183 search.netscape.com
Reboot:
then post a fresh hijack log as well as watch to see if that error is produced once again.
|