Tech Support Guy banner
  • IMPORTANT: Only authorized members may reply to threads in this forum due to the complexity of the malware removal process. Authorized members include Malware Specialists and Trainees, Administrators, Moderators, and Trusted Advisors. Regular members are not permitted to reply, and any such posts will be deleted without notice or further explanation. Notice
Status
Not open for further replies.
1 - 6 of 6 Posts

· Retired Moderator Retired Malware Specialist
Joined
·
56,593 Posts
First Name -
Derek
Discussion Starter · #1 ·
If your browser has been hijacked to drxcount.biz, real-yellow-page.com or list2004.com:
We are working on a fix for this one and drawing near to a solution. This is by far the most sophisticated CWS variant seen to date, and it will take some time before CWShredder will be able to remove it automatically.

So far, the following manual fix should work:
First download FAR explorer from here:

http://www.rarlab.com/far/Far1705.exe

Install it, then start FAR.
Hit Alt-F1 and drive list should come up, go to '0 process list'.

Scroll to Iexplore.exe in the left panel, highlight it and hit F5.
Now go to the right pane of FAR and double click 'iexplore.exe.txt', it should open in notepad.

Look for a file with this size and beginning to it. The filename will always be different:
61C00000 F000 c:\windows\system32\wingn.dll

This part indicates the bad file:
61C00000 F000
It will always start with that header.
Write down the filename behind it.

Now download KillBox:
http://download.broadbandmedic.com/
Unzip and run it.
Paste the filename you wrote down into the white kill line, then hit the red KILL FILE button beside it,then reboot. Once it reboots, make sure the file is gone.
 

· Registered
Joined
·
2,440 Posts

· Retired Moderator Retired Malware Specialist
Joined
·
56,593 Posts
First Name -
Derek
Discussion Starter · #5 ·
I've edited to account for the changes in killbox

I will keep an eye out as killbox is improving all the time
 
1 - 6 of 6 Posts
Status
Not open for further replies.
Top