I have been looking at the problem with this new hijacker you
all have been fighting ... nasty one ... I almost got it
yesterday morning but I am running WinPatrol ... it was able
to ID the changes the "Trojan" was trying to make to the
registry and to IE. I simply cancelled the changes ... you may
want to download WinPatrol (
www.winpatrol.com), remove the
registry changes in "safe mode" .. then restart. Any changes
can be stopped with WinPatrol ... this does not remove the
original "Trojan" from the system but is does allow you to
stop it from taking over your system for a while .... I also
found in the windows/temp ( I run win'98SE ) files 2 file
folders full of "spam to be sent out" ( ads for "junk"), both
had file folders were full of Outlook Express dbx files, all
ready to be e-mailed .. I deleted the file folders .. but they
came back after rebooting .... so far I have not been able to
locate the "Trojan" responsible for generating this problem,
but I have been able to stop the regenerating of the dbx files
by using SystemSuite5's Scheduler to clean the temp files of
any dbx files on startup. So far so good. The dbx files when
read come many different companies who send out "spam" ...
looks like we have a "Trojan" designed to bypass the "Canned
Spam laws" .... the kids who write this stuff for these
"spammers" should get life with out the chance of ever seeing
a computer again .....
I am not one of the MPV's here ... but I know WinPatrol did
help in stopping the problem from getting all the way into my
system ... hope this helps ..... If any of the MPV's have any
other answers ... we will be happy to look at them too ... I
do recommend WinPatrol ... It saved my butt more than once ...
be sure to make sure you have the lastest upgrade .....
*****************
*****************
devildog
*****************
Marines always
find a way to win
*****************
| whenever I try to change my homepage to anything
| different from res://dmlgk.dll/index.html#37049 it keeps
| going back. I tried using cwshreder, ad-aware or
| Hijackthis software but it keeps going back