Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Hijackthis needs to close


  • Please log in to reply
2 replies to this topic

#1 yellowdog

yellowdog

  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:09:05 PM

Posted 15 May 2005 - 12:03 PM

Running hijackthis get "has encountered a problem and needs to close . . .
Can't tell MS browser hijacked by about blank. Is there a workaround?
Details show modname - ntdll.dll, modver 5.1.2600.2180 offset 0000316c

BC AdBot (Login to Remove)

 


#2 Rimmer

Rimmer

  • Members
  • 2,159 posts
  • OFFLINE
  •  
  • Location:near Sydney, Australia
  • Local time:12:05 PM

Posted 16 May 2005 - 12:17 AM

See the following guide in the Self-Help forum:
http://www.bleepingcomputer.com/forums/How...EDLL-t4210.html

Soltek QBIC, Pentium 4 3.0GHz, 512MB RAM, 200GB SATA HDD, ATI Radeon 9600XT 256MB, Netgear 54Mb/s WAP, ridiculously expensive Satellite Broadband
Windows XP Home SP2, Trend Micro Internet Security, Firefox, Thunderbird, AdAwareSE, Spybot S&D, SpywareBlaster, A-squared Free, Ewido Security Suite.

#3 yellowdog

yellowdog
  • Topic Starter

  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:09:05 PM

Posted 16 May 2005 - 09:22 AM

Thank for the more concise instruction link. That is what I was trying to do. I have already loaded the HijackThis, RegistarLite and CWSShreader on the infected machine. When I ran RegistrarLite, I could not find any entries under
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsNT\CurrentVersion\Windows
with AppInit_DLLs. So I ran the HijackThis to get a log to post to the forum for help. I was thinking just because my brower screen is About:Blank maybe I have some variant and the log would help. I had also ran CWShredder. It showed only 1 questionalble entry, ERASE_RS which I found topic on that basiclly said it was a tool used by VPN tunnels for uninstalls - so I did NOT have it removed.
I'm not at the infected machine now, but I'll retry the the RegistrarLite using the paste instead of exploring/expanding entries from the Registry. Thanks again!!




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users