Hi everyone,
I am trying to fix toshiba laptop vista home premium 64 bit SP1. I ran AVZ and it shows in the result the following 3 lines in red (all 3 saying the same words but different numbers):
Function user32.dll:intercepted, method ProcAddressHijack.GetProcAddress...
=......
=......
and in the end:
malicious software found 0, suspicions - 0
Malwarebyte , SuperAntispyware and Mcafee did not find anything, though. Is it a rootkit that has taken over the user32.dll of vista?
My concern is: why AVZ shows that thing in RED? and then tells no malware found in the end.
I'd appreciate if some knowledgeable geek will help me with this plz.
thanks
Page 1 of 1
ProcAddressHijack ? What is ProcAddressHijack?
#2
Posted 07 November 2009 - 09:21 PM
Welcome to BC

We Need to check for Rootkits with RootRepeal
----------------------------------
Please note: If Rootrepeal fails to run, try this step: Click Settings - Options. Set the Disk Access slider to High
Also try: right-click on rootrepeal.exe and rename it to tatertot.scr
========================

Please download Win32kDiag.exe by AD and save it to your desktop.
alternate download 1
alternate download 2
Go to
> Run..., then copy and paste this command into the open box: cmd
Click OK.
At the command prompt C:\>, copy and paste the following command and press Enter:
A file called log.txt should be created on your Desktop.
Open that file and copy/paste the contents in your next reply.
We Need to check for Rootkits with RootRepeal
- Download RootRepeal from the following location and save it to your desktop.
- Direct Download (Recommended)
- Zip Mirrors (Recommended if you have a slower connection or if the Direct Download mirror is down)
- Rar Mirrors - Only if you know what a RAR is and can extract it.
- Direct Download (Recommended)
- Extract RootRepeal.exe from the archive (If you did not use the "Direct Download" mirror).
- Open
on your desktop. - Click the
tab. - Click the
button. - Check all seven boxes:

- Push Ok
- Check the box for your main system drive (Usually C:), and press Ok.
- Allow RootRepeal to run a scan of your system. This may take some time.
- Once the scan completes, push the
button. Save the log to your desktop, using a distinctive name, such as RootRepeal.txt. Include this report in your next reply, please.
----------------------------------
Please note: If Rootrepeal fails to run, try this step: Click Settings - Options. Set the Disk Access slider to High
Also try: right-click on rootrepeal.exe and rename it to tatertot.scr
========================
Please download Win32kDiag.exe by AD and save it to your desktop.
alternate download 1
alternate download 2
- This tool will create a diagnostic report
- Double-click on Win32kDiag.exe to run and let it finish.
- When it states Finished! Press any key to exit..., press any key on your keyboard to close the program.
- A file called Win32kDiag.txt should be created on your Desktop.
- Open that file in Notepad and copy/paste the entire contents (from Starting up... to Finished! Press any key to exit...) in your next reply.
> Run..., then copy and paste this command into the open box: cmdClick OK.
At the command prompt C:\>, copy and paste the following command and press Enter:
DIR /a/s %windir%\scecli.dll %windir%\netlogon.dll %windir%\eventlog.dll >Log.txt & START notepad Log.txt
A file called log.txt should be created on your Desktop.
Open that file and copy/paste the contents in your next reply.
Mark
why won't my laptop work?
Having grandkids is God's way of giving you a 2nd chance because you were too busy working your butt off the 1st time around
Do not send me PMs with problems that should be posted in the forums. Keep it in the forums, so everyone benefits
Become a BleepingComputer fan: Facebook and Twitter
why won't my laptop work?
Having grandkids is God's way of giving you a 2nd chance because you were too busy working your butt off the 1st time around
Do not send me PMs with problems that should be posted in the forums. Keep it in the forums, so everyone benefits
Become a BleepingComputer fan: Facebook and Twitter
Share this topic:
Page 1 of 1

Help

Back to top









