Discussion in 'privacy problems' started by dvk01, Mar 19, 2004.

  dvk01

    dvk01

    Mar 19, 2004
    Loughton, Essex. UK
    Re posted from merijn's site for info as cwshredder doesn't fix this one yet

    If your browser has been hijacked to, or
    We are working on a fix for this one and drawing near to a solution. This is by far the most sophisticated CWS variant seen to date, and it will take some time before CWShredder will be able to remove it automatically.

    So far, the following manual fix should work:
    First download FAR explorer from here:

    Install it, then start FAR.
    Hit Alt-F1 and drive list should come up, go to '0 process list'.

    Scroll to Iexplore.exe in the left panel, highlight it and hit F5.
    Now go to the right pane of FAR and double click 'iexplore.exe.txt', it should open in notepad.

    Look for a file with this size and beginning to it. The filename will always be different:
    61C00000 F000 c:\windows\system32\wingn.dll

    This part indicates the bad file:
    61C00000 F000
    It will always start with that header.
    Write down the filename behind it.

    Now download KillBox:
    Unzip and run it.
    Paste the filename you wrote down into the white kill line, then hit the bottom green arrow button to move the file to the bottom of killbox. Hit the 'remove on reboot' button and reboot. Once it reboots, make sure the file is gone.
  ray1980

    ray1980

    May 2, 2004
    Hi my friend, I got the List2004 prefix virus on my XP last month. I have tried a lot of anti-virus programs, but it seemed never be fixed. I am trying the way you said, but the list on the notepad of FAR was a bit confusing. all the files' names are similar, and I did not find one closer to---61C00000 F000 c:\windows\system32\wingn.dll......I put my list here in case if you could help me to find the suspicious file.

  dvk01

    dvk01

    May 2, 2004
    Loughton, Essex. UK
    since my original post this parasite hjas cahnged some of it's behaviour and there is no longer any easy way to deinitely identify the file as shown above

    for assistance please do this

    please follow instructions here
    and post a hjt log in the hiajck forum
  ray1980

    ray1980

    May 2, 2004
    Thanks Derek. But does that mean it is no way to really get rid of "list2004"?What can I do. Should I trash all of my downloaded IE files and IE itself?
  dvk01

    dvk01

    May 2, 2004
    Loughton, Essex. UK
    that won't do any good either with this pest

    follow advice to post a hjt log and we'll see what we can do for you
  ray1980

    ray1980

    May 2, 2004
    Thanks, I will try what you advised.
  hyper C

    hyper C


    I got rid of it. First i duplicated the files/songs i wanted to keep and put it on my external hard drive, then scanned it, and then i formatted my pc. That is my answer for about everything.
