2My Zlob.DNSChanger.Rtk

Status
Not open for further replies.
HI

I'm going to surprise you here :)

According to the log you posted, everything went perfect ...

SmitFraudFix v2.320

Scan done at 14:45:44.60, Mon 12/05/2008
Run from C:\Documents and Settings\Administrator\Desktop\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in safe mode

The fix was run in safemode :)

»»»»»»»»»»»»»»»»»»»»»»»» Reboot

C:\WINDOWS\system32\kdhfi.exe Deleted

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""

The offending file was removed along with the registry entry & the "System" is now clean :)


All these entries in the Hosts file :-

»»»»»»»»»»»»»»»»»»»»»»»» hosts

127.0.0.1 www.007guard.com
127.0.0.1 007guard.com
127.0.0.1 008i.com
127.0.0.1 www.008k.com
127.0.0.1 008k.com
etc,

were blocking BAD sites ... so they were GOOD entries ... they were put there by spybot's immunize feature.

SmitFraudFix removed them all because all it saw was entries blocking sites, & they could have been good sites...

I should have got you to remove spybot's immunization, before running SmitFraudFix, then the log would have been a lot smaller...

Anyway, no harm done, & you appear to be clean now ...

Run spybot again & see if you get a clean log ?

Whilst you have spybot open, click on the immunize button to re-immunize with spybot

steam
 
2My Zlob.DNSChanger.Rtk (tosser bradford28 to el-supremo steamwiz)

Tuesday, May 13th, 2008.

A Grinning Howdy,

Thank you steam.

And, yes, as you had interpreted from the final 'rapport.txt', that persistent and defiant, mongrel has now been completely annihilated.

Thank you for your patient, skilled determination; and for the dedication you and all of the Spybot Team demonstrate.


Regards,

bradford28
 
Status
Not open for further replies.
Back
Top