Home > General > Ataamon.dll


Tnx,shadoWWWW 5.1.2600.0 C:\WINDOWS\notepad.exe--a-- W32i APP ENU 5.1.2600.0 shp 66,048 08-29-2002 notepad.exe ╗╗ Regedit* version(s): 5.1.2600.1106 C:\WINDOWS\regedit.exe--a-- W32i APP ENU 5.1.2600.1106 shp 134,144 08-29-2002 regedit.exe 5.1.2600.0 C:\WINDOWS\System32\regedt32.exe--a-- W32i APP ENU 5.1.2600.0 shp Downloaded it onto my machine and it runs fine. Flrman1, Nov 2, 2004 #15 Sponsor This thread has been Locked and is not open to further replies. I went into regedit and did a find on these files and was only able to find wowanmgr.exe which i deleted.

The Temp folder will open. Submit Files: ---------------------------------------------------------------------- Back to top #9 flyinfry flyinfry Member Full Member 10 posts Posted 07 June 2004 - 06:56 PM OK I have the CTLLPOJ.DLL moved to the C:\junkxxx folder. text/xml\CLSID = "{807553E5-5146-11D5-A672-00B0D022E945}" -> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL" [file not found] HKLM\Software\Classes\*\shellex\ContextMenuHandlers\ NOD32 Context Menu Shell Extension\(Default) = "{B089FE88-FB52-11D3-BDF1-0050DA34150D}" -> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Eset\nodshex.dll" [null data] WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}" Check all instances of calsp.dll (and nothing else) , and move them to the "Remove" pane.

If they say it's malicious, boot into safe mode, navigate to the file(s) in question & delete them from there. The computer is running incredibly slowly now - far slower than before I started this. Cheers.

Let us know how it works out. Submit Files: ---------------------------------------------------------------------- Back to top #17 flyinfry flyinfry Member Full Member 10 posts Posted 09 June 2004 - 06:34 PM freeatlast just wanted to say thanks for helping remove the It monitors web pages requested and data entered into forms, sends this information to its home server, and opens pop-up advertisement windows. VXFiles Found---Guardian Key--- is called: User Agent String---2Finder Back to top #6 freeatlast freeatlast E x p l o r e r Retired Staff 833 posts Posted 06 June 2004 -

She needs to keep the Japanese language support, and despite my strong suggestion to the contrary wants to continue using kazaa lite even though I believe this means she will have Help us fight Enigma Software's lawsuit! (Click on the above link to learn more) Become a BleepingComputer fan: FacebookFollow us on Twitter! Please re-enable javascript to access full functionality. I hope we can finish this off between us - it seems so close and yet so far away!

O4 - Global Startup: ScreenArt.lnk = C:\Program Files\ScreenArt\WillowRd.exe O9 - Extra button: Messenger (HKLM) O9 - Extra 'Tools' menuitem: Messenger (HKLM) O14 - IERESET.INF: START_PAGE_URL=http://www.meshcomputers.com O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Join the community! Again thanks for the help.Logfile of HijackThis v1.97.7Scan saved at 10:17:02 PM, on 6/7/2004Platform: Windows XP SP1 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\Explorer.EXEC:\WINDOWS\system32\LEXBCES.EXEC:\WINDOWS\system32\spoolsv.exeC:\WINDOWS\system32\LEXPPS.EXEC:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exeC:\WINDOWS\system32\cisvc.exeC:\WINDOWS\System32\CTsvcCDA.exeC:\Program Files\CA\eTrust\InoculateIT\InoRpc.exeC:\Program Files\CA\eTrust\InoculateIT\InoRT.exeC:\Program Files\CA\eTrust\InoculateIT\InoTask.exeC:\WINDOWS\LogWatNT.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\wanmpsvc.exeC:\WINDOWS\System32\MsPMSPSv.exeC:\WINDOWS\BCMSMMSG.exeC:\Program Files\Roxio\Easy CD Creator Yes, my password is: Forgot your password?

I am wondering if this is causing my issues of popuppers.com and multiple other web pages poping all by themselves? StartupList report, 4/25/2004, 11:53:25 AMStartupList version: 1.52Started from : F:\Documents and Settings\heart\Desktop\StartupList.EXEDetected: Windows XP SP1 (WinNT 5.01.2600)Detected: Internet Explorer v6.00 SP1 (6.00.2800.1106)* Using default options==================================================Running processes:F:\WINDOWS\System32\smss.exeF:\WINDOWS\system32\winlogon.exeF:\WINDOWS\system32\services.exeF:\WINDOWS\system32\lsass.exeF:\WINDOWS\System32\Ati2evxx.exeF:\WINDOWS\system32\svchost.exeF:\WINDOWS\System32\svchost.exeF:\WINDOWS\system32\rundll32.exeF:\Program Files\Common Files\Symantec Shared\ccSetMgr.exeF:\Program Files\Common Files\Symantec Nie wiem jak, ale uszkodzi┼é j─ůdro Noda. Jump to content Sign In Create Account Search Advanced Search section: This topic Forums Members Help Files Calendar View New Content Forum Rules BleepingComputer.com Forums Members Tutorials Startup List

Page 1 of 2 1 2 Next > Advertisement 24giovanni Banned Thread Starter Joined: Jun 14, 2003 Messages: 1,083 I'm having the same issue as pcamess...here is my HJT log. I spoke too soon yesterday - shortly after my wife went back on the computer the homepage had been hijacked again. Use HiJackThis to Check the boxes beside the below entries, then click on "Fix checked" . Run these tools (whether used before or not!), as they should work properly now.

Turn off System Restore.2. Go to Start > Run and type %temp% in the Run box. Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_3_16_0.dll O3 - Toolbar: Searchfst Class - {000277A3-7D84-406a-9799-D12A81594693} - C:\WINNT\srchfst.dll O3 - Toolbar: Search Bar - {4E7BD74F-2B8D-469E-A1F6-FC7EB590A97D} - C:\WINNT\DOWNLO~1\search3.dll O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINNT\System32\spool\drivers\w32x86\3\hpztsb05.exe You can proceed with the last set of steps now! ---Open the 'Find-All'\Tools Subfolder.

Udostępnij ten post Link to postu Udostępnij na innych stronach kuz5 0 Użytkownicy 0 5 124 postów Napisano Sierpień 3, 2006 Czy poza tymi wpisami wszysko ok? I've run Spybot and Adaware, but still have the issue.....HELP!!!Thanks Join or Log in to Reply Page 1 of 212 Replies JCBags 7 posts Forum MembersPosted 12 years, 259 days ago Here's latest after all scans Logfile of HijackThis v1.98.2 Scan saved at 6:59:46 PM, on 11/1/2004 Platform: Windows 2000 SP2 (WinNT 5.00.2195) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINNT\System32\smss.exe

After around 20 minutes waiting for it to load I hard rebooted.

It is not so much Kazaa Lite, but more what you download with kazaaLite or what you click on when surfing. Copy and paste that log here and wait for further instructions. Thanks Back to top #13 flyinfry flyinfry Member Full Member 10 posts Posted 07 June 2004 - 09:00 PM I found where the CTLLPOJ.DLL file went my virus protection deleted it. On the second reboot it all loaded ok.

Each # entry should be kept on an individual line. Thread Status: Not open for further replies. or STYLEJ.......... Login (HKLM) O9 - Extra 'Tools' menuitem: Yahoo!

I cannot send you the full contents of HOSTS as it takes up more space than your message system allows. Now, use the VX2finder, select all files on the scan and delete!