2 Intern

 • 

5.9K Posts

August 7th, 2005 22:00

In HijackThis, Check and Fix Checked:
 
O2 - BHO: CInterfaceObj Object - {58F07DD3-924D-4141-BC74-299F523A95F1} - C:\WINDOWS\pxwma.dll (file missing)
 
This won't fix your problem but it's the only thing that shows up in the log.  Just a leftover registry entry from an infection.
 
We are seeing a lot of infections that replace the wininet.dll file with a bogus version.
 
Try File Signature Verification:
 

To start File Signature Verification, click Start, click Run, type sigverif, and then click OK.

 

Press Start and see what files it flags as unsigned.  Is wininet.dll among them?

 

Ron

11 Posts

August 7th, 2005 23:00

I ran sigverif and I did not get the wininet.dll file. The listed files after the scan are:
oembios.bin
oembios.dat
oembios.sig
atapi.sys
btaudio.sys
btwusb.sys
frmupgr.sys
omci.sys

Any other clues will be appreciated. I found out that I can delete files using DOS command prompt.

2 Intern

 • 

5.9K Posts

August 7th, 2005 23:00

Follow the instructions on this site.  Method 2 looks promising.
 
 
Ron
No Events found!

Top