2 Intern

 • 

5.9K Posts

September 20th, 2005 15:00

Download the Hoster from:
Unpack to your desktop and run it.  If you have green print at the top then just press Restore Original Hosts then OK. 
IF you have red print then press make Hosts Writeable first.
 

Get DelDomain.inf from:
 
http://www.mvps.org/winhelp2002/restricted.htm  and then right click on it and Install. 
Get ccleaner from http://ccleaner.com.  Install it but do not let it clean anything yet.
Get CWShredder from
and save it to your desktop.
extract it to your desktop and run it.  Where it says Full Path of File to Delete put in:
C:\Program Files\Information Update
check Delete on Reboot and DELTREE  then press the red button. 
Agree you want to delete the file but do not let it reboot.  Repeat (with only Delete On Reboot)  for
C:\WINDOWS\q14613343_disk.dll
C:\WINDOWS\oaogep.exe
Let it reboot
Boot into Safe Mode by tapping the F8 key when you see the PC
maker's logo.
Keep tapping until it tells you it is going to Safe Mode or you see the Safe
Mode menu. Select the top option.  Log in with your usual login.
Run HijackThis and just do a Scan only. Check then Fix Checked the following:
O2 - BHO: C:\WINDOWS\adsldpbc.dll - {405132A4-5DD1-4BA8-A181-95C8D435093A} - C:\WINDOWS\adsldpbc.dll
O2 - BHO: C:\WINDOWS\q14613343_disk.dll - {B212D577-05B7-4963-911E-4A8588160DFA} - C:\WINDOWS\q14613343_disk.dll
O3 - Toolbar: (no name) - {a19ef336-01d4-48e6-926a-fe7e1c747aed} - (no file)
O3 - Toolbar: (no name) - {12F02779-6D88-4958-8AD3-83C12D86ADC7} - (no file)
O4 - HKLM\..\Run: [9oL6TW] C:\WINDOWS\oaogep.exe
O4 - HKLM\..\Run: [Daily Weather Forecast] C:\Program Files\Daily Weather Forecast\weather.exe
O4 - HKLM\..\Run: [Information Update] C:\Program Files\Information Update\iu.exe
O15 - Trusted Zone: *.coolwebsearch.com
O15 - Trusted Zone: *.searchmeup.com
O20 - Winlogon Notify: style32 - C:\WINDOWS\q14613343_disk.dll
O21 - SSODL: System - {4155719A-C5E5-4EE2-8A64-749520578501} - mcsys.dll (file missing)
 

Run ccleaner.exe, uncheck everything on the first page except the two entries
with Temporary and then Run Cleaner.
 
Run cwshredder tell to fix anything it finds.
 
Reboot into regular mode and
run another HijackThis log.  If you still see
 
O20 - Winlogon Notify: style32 - C:\WINDOWS\q14613343_disk.dll
and it doesn't say File Missing then Follow Atribune's procedure at:
 
http://www.atribune.org/forums/index.php?showtopic=447&hl=killvundo
 
The paths the program asks you for would be:
 C:\WINDOWS\q14613343_disk.dll
and
C:\WINDOWS\q14613343_disk.dll
 
Run a final HijackTHis log and post it as a reply. Let's
see how we did.
Ron

6 Posts

September 26th, 2005 04:00

i downloaded the hoster and it couldn't  restore the host (had green writing)  then i tried the next two things and they wouldn't work,, i tried again to just restart my computer from the start, but it keeps saying keyboard failure.

Now i can't search the web, can only use my history and favorites.

2 Intern

 • 

5.9K Posts

September 26th, 2005 11:00

Can't see anything that would have stopped the keyboard from working.  Hoster only plays with the hosts file which might keep you off the net but certainly can't do anything to a keyboard.  Make sure it is still plugged up. 
 
Double checked all of the items I asked you to check and they are all bad guys.  See if you can do a System Restore to the earliest date available.
 
 
If not or that doesn't help see if you can get into CMOS Setup.  Can't tell you how to do that since I don't know what computer you have but with Dell it's F1 or F2, Compaqs like F10 and some PCs want Delete  during a boot.  Usually they will tell you what to press to get into Setup.   If that doesn't work then you may need to replace the keyboard or remove the CMOS (RTC) battery from 15 minutes then reinsert in reboot.   If you get into setup then select use Defaults then Save and Exit.  That at least proves the keyboard is working. 
 
Turns out that the 
C:\WINDOWS\q14613343_disk.dll
trojan can only be removed with the procedure at:
 
But the other stuff should go away without a problem.
 
Ron
 

 
 

 
No Events found!

Top