A
Ashley
I was trying to remove the damage caused by some malware
that dropped the mtwirl32.dll into the registry, but I
had accidentally changed some other settings within the
registry without fully knowing their effects, so now when
I type a URL without the "http://" part (for example,
just "www.google.com"), the browser can't locate the
website.
Would anyone who knows what I should do please kindly
inform me? I have attached below some of the instructions
I followed during the procedure, although these were not
what caused my current problem, since I made extra
changes to the registry without realizing what each one
did.
I thank you in advance for helping me with this minor but
distressing situation.
Ashley
----------
To register the dropped .DLL components as a Browser
Helper Objects, this malware creates the following
registry entries:
HKEY_CLASSES_ROOT\CLSID\
{3f143c3a-1457- 6cca-03a7-7aa23b61e40f}\InProcServer32
@ = "%System32%\mtwirl32.dll"
ThreadingModel = "Apartment"
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\
CurrentVersion\Explorer\SharedTaskScheduler
{3f143c3a-1457- 6cca-03a7-7aa23b61e40f} =
"DDE Control Module"
----
c:\windows\system32\mtwirl32.dll
c:\System Volume Information\_restore{C54B8Df7-ad4a-4890-
ba5c-21bc7165c561}\a0078997.dll
Open Registry Editor. To do this, click Start>Run, type
Regedit, then press Enter.
In the left panel, double-click the following:
HKEY_CLASSES_ROOT>CLSID>
{3f143c3a-1457- 6cca-03a7-7aa23b61e40f }>InprocServer32
In the right panel, locate and delete the entry or
entries:
%System32%\mtwirl32.dll
Note: %System32% is C:\WINNT\System32 on Windows NT and
2000, and C:\Windows\System32 on Windows XP.
In the left panel, double-click the following:
HKEY_LOCAL_MACHINE>Software>Microsoft>Windows>
CurrentVersion>Explorer>SharedTaskScheduler
In the right panel, locate and delete the entry or
entries:
{3F143C3A-1457-6CCA-03A7-7AA23B61E40F} = "DDE Control
Module"
Close Registry Editor.
Trojan.Bookmarker.C
that dropped the mtwirl32.dll into the registry, but I
had accidentally changed some other settings within the
registry without fully knowing their effects, so now when
I type a URL without the "http://" part (for example,
just "www.google.com"), the browser can't locate the
website.
Would anyone who knows what I should do please kindly
inform me? I have attached below some of the instructions
I followed during the procedure, although these were not
what caused my current problem, since I made extra
changes to the registry without realizing what each one
did.
I thank you in advance for helping me with this minor but
distressing situation.
Ashley
----------
To register the dropped .DLL components as a Browser
Helper Objects, this malware creates the following
registry entries:
HKEY_CLASSES_ROOT\CLSID\
{3f143c3a-1457- 6cca-03a7-7aa23b61e40f}\InProcServer32
@ = "%System32%\mtwirl32.dll"
ThreadingModel = "Apartment"
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\
CurrentVersion\Explorer\SharedTaskScheduler
{3f143c3a-1457- 6cca-03a7-7aa23b61e40f} =
"DDE Control Module"
----
c:\windows\system32\mtwirl32.dll
c:\System Volume Information\_restore{C54B8Df7-ad4a-4890-
ba5c-21bc7165c561}\a0078997.dll
Open Registry Editor. To do this, click Start>Run, type
Regedit, then press Enter.
In the left panel, double-click the following:
HKEY_CLASSES_ROOT>CLSID>
{3f143c3a-1457- 6cca-03a7-7aa23b61e40f }>InprocServer32
In the right panel, locate and delete the entry or
entries:
%System32%\mtwirl32.dll
Note: %System32% is C:\WINNT\System32 on Windows NT and
2000, and C:\Windows\System32 on Windows XP.
In the left panel, double-click the following:
HKEY_LOCAL_MACHINE>Software>Microsoft>Windows>
CurrentVersion>Explorer>SharedTaskScheduler
In the right panel, locate and delete the entry or
entries:
{3F143C3A-1457-6CCA-03A7-7AA23B61E40F} = "DDE Control
Module"
Close Registry Editor.
Trojan.Bookmarker.C