Edited by jmamax1, 24 April 2013 - 10:13 AM.
DLL error - the specified module could not be found
Posted 17 April 2013 - 10:39 PM
- Please double-click OTL.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
- Copy the lines in the quote below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):
O4 - HKLM..\Run: [Configuration] C:\Users\Tanner\AppData\Roaming\WS32.exe ()
O4 - HKLM..\Run: [TaskTray] File not found
O4 - HKLM..\Run: [Windows Defender] c:\install\svchost.exe File not found
O4 - HKLM..\Run: [Windows Fix] C:\Users\Tanner\AppData\Roaming\scon.exe File not found
O4 - HKCU..\Run: [Windows Defender] C:\install\svchost.exe File not found
O4 - HKCU..\Run: [Windows UI] C:\Users\Scott\AppData\Roaming\WinUI\WinUI.exe File not found
O4 - Startup: C:\Users\Scott\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\win.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run: Policies = c:\install\svchost.exe
- Return to OTL, right click in the "Custom Scans/Fixes" window and choose Paste.
- Click the red Run Fix button.
- The computer will restart
- A report will be produced and saved in the C:\_OTL\MovedFiles folder. Open that report and post its contents in a reply.
Download AdwCleaner from here to your desktop
Run AdwCleaner and select Delete
Once done it will ask to reboot, allow this
On reboot a log will be produced at C:\ADWCleaner[XX].txt please post its contents in a reply.
Please download Malwarebytes' Anti-Malware from Here. Never download Malwarebytes' Anti-Malware from other sources.
Double Click mbam-setup.exe to install the application.
- Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
- If an update is found, it will download and install the latest version.
- Once the program has loaded, select "Perform Quick Scan", then click Scan.
- The scan may take some time to finish,so please be patient.
- When the scan is complete, click OK, then Show Results to view the results.
- Make sure that everything is checked, and click Remove Selected.
- When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
- The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
- Copy&Paste the entire report in your next reply.
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediatly.
Posted 18 April 2013 - 08:54 PM
32 bit Download Mirror #1
32 bit Download Mirror #2
For 64bit systems, Please download SystemLook from the link below and save it to your Desktop.
64 bit Download Mirror
- Double-click SystemLook.exe (or SystemLook_x64.exe) to run the application.
- Copy the content of the following quote box into the main textfield:
- Click the Look button to start the scan.
- When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt
Please download ComboFix from Here or Here to your Desktop.
**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**
- Please, never rename Combofix unless instructed.
- Close any open browsers.
- Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
- Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
- Click on this link or this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
- Close any open browsers.
- WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
- Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
- If there is no internet connection after running Combofix, then restart your computer to restore back your connection.
- Double click on combofix.exe & follow the prompts.
- Install the Recovery Console if prompted.
- When finished, it will produce a report for you.
- Please post the "C:\ComboFix.txt" .
Note: ComboFix may reset a number of Internet Explorer's settings, including making it the default browser.
Note: Combofix prevents autorun of ALL CDs, floppies and USB devices to assist with malware removal & increase security.
Please do not install any new programs or update anything (always allow your antivirus/antispyware to update) unless told to do so while we are fixing your problem. If combofix alerts to a new version and offers to update, please let it. It is essential we always use the latest version.
Posted 19 April 2013 - 10:22 AM
Save it next to Combofix.
Once saved, referring to the picture above, drag CFScript.txt into ComboFix.exe, and post back the resulting report.
Are you still experiencing the wow.dll message?
Posted 19 April 2013 - 05:08 PM
- Download RogueKiller (by tigzy) on the desktop
- Quit all programs
- Start RogueKiller.exe.
- Wait until Prescan has finished ...
- Click on Scan. Once finished, click on Report
Please post the contents of the RKreport.txt in your next Reply.
Posted 19 April 2013 - 06:34 PM
should I still run the cfscript and rougekiller proceses?
Posted 19 April 2013 - 08:09 PM
Posted 20 April 2013 - 12:07 PM
Edited by jmamax1, 24 April 2013 - 10:14 AM.
Posted 20 April 2013 - 04:44 PM
Checkmark following boxes:
- List Installed Programs
Posted 20 April 2013 - 08:48 PM
Logon into one of these profiles and produced an OTL log. They must have administrative rights to do so.
0 user(s) are reading this topic
0 members, 0 guests, 0 anonymous users