res://tslrv.dll/index.html#23999

G

GB Baker

res://tslrv.dll/index.html#23999 is the IE homepage....cant get rid of it!!!
Have run Spysweeper, Spybot S&D, Adaware and CWShredder al the latest up
dates and found nothing!
I can hack it out of registry and on reboot it comes right back.

HELP PLEASE!!
 
J

Jim Byrd

Hi GB -
I'm informed that the 01R325 AdAware update of 6/28 or later supposedly
completely removes this for some variants/malware implimentations; however,
I haven't been able to independently verify this and have also heard
contrary info. Try it first (from Safe mode), and if it doesn't work then,

See these threads first:

http://zerosrealm.com/index.php?page=dllfix (Read very carefully!)



<http://forums.spywareinfo.com/index.php?showtopic=7447>
<http://forums.spywareinfo.com/index.php?showtopic=7261>
<http://forums.spywareinfo.com/index.php?showtopic=7281>




Then from merijn, here: <http://www.spywareinfo.com/~merijn/index.html>




June 18, 2004:

Please stop emailing me about the new CWS variant that hijacks you to
res://<random>.dll/sp.html#96676. I am aware of this new thing, but it's a
beast to remove.
A solution is being worked on, see this thread on the SWI forums
<http://forums.spywareinfo.com/index.php?showtopic=7447>.

If it's not working for you, or it's too complicated, I heard from several
people that this workaround works as well:

Open the DLL you get hijacked to in Notepad

Select all content (Ctrl-A) and delete it

Save the file and exit Notepad

Find the file in Explorer, right-click it, select Properties, put a
checkmark in 'Read-Only' and click OK.

If you can't find the DLL file, make sure your settings allow you to view
"Hidden files". Open up any explorer windows and click on "Tools", "Folder
Options", "View" and be sure to check off "Show Hidden Files and Folders".




--
Please respond in the same thread.
Regards, Jim Byrd, MS-MVP



In
 
G

GB Baker

Many thanks Jim. Just as I suspected its CWS_NS3 and I'm not going to mess
with it anymore. I did hear from Spysweeper folks at Webroot that they were
working on a removal tool that would work for all the variants but it would
be two weeks (heheheh... that's what I always told my boss when he asked how
long) so I'm scrubbing and reloading this box.
 
J

Jim Byrd

YW, GB - If you can afford to do so, that's probably a clean solution. Be
sure you "defense" you system after you reload.

--
Please respond in the same thread.
Regards, Jim Byrd, MS-MVP



In
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top