Delete the hslog.txt you have now
You MUST UNZIP the contents of the contents of HSFIX.zip
or this fix won't work>>Don't run from within the zipped file
Also, ensure you have windows to Show Hidden files and folders
Download the
Pocket KillboxUNZIP it to a folder of your choice
Save the rest of these instructions to a Notepad file and leave it open on the desktop
Disconnect from the Internet
Run Pocket KillBox
click on Tools --> Select Delete Temp Files. Click OK.
Again, in Killbox
At the main screen of Pocket Killbox, select the option:
Replace on RebootAlso tick
Use DummyIn the
Full Path of File to Delete box, copy and paste this entry:
C:\WINDOWS\SYSTEM32\drct16.dllPress the button with a red circle and a white X
Click
Yes to Replace
When asked if you would like to Reboot, select
No.
Do the same for all these:
C:\WINDOWS\System32\open32.exe
C:\WINDOWS\blank.htm
C:\WINDOWS\System32\tibs3.exe
C:\WINDOWS\System32\DSMANA~1.DLL <--for this one, additionally tick, unregister .dll before deleting
Finally, in Full Path of File to Delete, copy and paste the following:
C:\Documents and Settings\<YOUR USERNAME>\Start Menu\Programs\Startup\winupdate97363829[1].exePress the button with a red circle and a white X.
When asked to Reboot, select Yes!!
NOTE>>>>
<YOUR USERNAME> , you must edit that line and change to the current user of this log........
So if your user name is
Sina as an example, it would look like this
C:\Documents and Settings\Sina\Start
Menu\Programs\Startup\winupdate97363829[1].exe
RESTART INTO SAFE MODE by tapping the F8 Key as the system is booting up
Ensure that none of those files exist that we had killbox remove
C:\WINDOWS\System32\tibs3.exe <--file
C:\WINDOWS\System32\open32.exe <--file
C:\WINDOWS\System32\snim.dll <--file
C:\WINDOWS\SYSTEM32\drct16.dll <--file
C:\WINDOWS\System32\DSMANA~1.DLL <--file
C:\Documents and Settings\<YOUR USERNAME>\Start Menu\Programs\Startup\winupdate97363829[1].exe <--file
C:\Program Files\WebSiteViewer <--folder
Stay in safe mode>>>
Do another scan with Hijackthis and put a check next to these entries:
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = C:\WINDOWS\blank.htm
O2 - BHO: Explorer Class - {962F12AE-2773-4BEB-99EA-B5C3AB9A6606} - C:\WINDOWS\System32\DSMANA~1.DLL
O2 - BHO: (no name) - {B72F75B8-93F3-429D-B13E-660B206D897A} - C:\WINDOWS\System32\snim.dll (file missing)
O4 - HKLM\..\Run: [Shell] open32.exe
O4 - HKLM\..\Run: [Systems Restart] Rundll32.exe snim.dll, DllRegisterServer
O4 - HKLM\..\Run: [tibs3] C:\WINDOWS\System32\tibs3.exe
O4 - Startup: winupdate97363829[1].exe
O18 - Filter: text/html - {B72F75B8-93F3-429D-B13E-660B206D897A} - C:\WINDOWS\System32\snim.dll
O18 - Filter: text/plain - {B72F75B8-93F3-429D-B13E-660B206D897A} - C:\WINDOWS\System32\snim.dll
O20 - Winlogon Notify: drct16 - C:\WINDOWS\SYSTEM32\drct16.dllAfter you have ticked the above entries, close
All other open windows, including this one
Leave Hijackthis open and click FIX CHECKED
OK the prompt and exit Hijackthis
* Navigate to the HSFix directory and double-click on HSFix.bat.
Ensure you unzipped it
* It will produce a log file, located here: C:\hslog.txt. <--we'll need this later
Run Windows CleanUp again in safe mode
Restart back to Normal mode
Post back a fresh hijackthis log and the hslog.txt again