On restart, Navigate to System32 folder and find the loghdln.dll file which is the problem file in question here ...(as it should be visible now), use the folder's top menu => Please do that and post another hijackthis log... (as well as one more FindNfix log..

C:\WINDOWS\SYSTEM32\ msxslab.dll Mon Aug 23 2004 9:48:32p ..SHR 0 0.00 K bridge.dll Mon Aug 23 2004 9:48:34p ..SHR 0 0.00 K jac.dll Mon Aug 23 2004 9:48:34p ..SHR 0 0.00 K

Here are 3 free ones available for personal use:Sygate Personal FirewallKerio Personal FirewallZoneAlarmand a good antivirus like the one you are currently using. Sniffed -> C:\WINDOWS\SYSTEM32\MSXSLAB.DLL Sniffed -> C:\WINDOWS\SYSTEM32\BRIDGE.DLL Sniffed -> C:\WINDOWS\SYSTEM32\JAC.DLL Sniffed -> C:\WINDOWS\SYSTEM32\D2KPAX.DLL Sniffed -> C:\WINDOWS\SYSTEM32\LOGHDLN.DLL SNiF 1.34 statistics Matching files : 5 Amount in bytes : 57344 Directories searched : 1 Thanks so much in advance for any assistance!!!Logfile of HijackThis v1.99.1Scan saved at 12:01:13 AM, on 6/9/2005Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\Program Files\Common Files\Symantec Shared\ccProxy.exeC:\Program proud member since 2004Most active in: Resolved or inactive Malware Removal Back to top #4 Guest_jinjai_* Guest_jinjai_* Guests Posted 25 July 2005 - 09:52 PM Thanks for you reply.

* Click Start. * Open My Computer. * Select the Tools
C:\WINDOWS\SYSTEM32\ loghdln.dll Tue Jul 13 2004 9:11:10a ....R 57,344 56.00 K dpwsockx.dll Wed Aug 4 2004 3:56:42a A.... 57,344 56.00 K msasn1.dll Wed Aug 4 2004 3:56:42a A.... 57,344 56.00 K

TransmissionRetryTimeout h 0 ` 00001310: vk ' , USERProcessHandleQuota, 00001350: 00001390: 000013D0: 00001410: 00001450: 00001490: 000014D0: 00001510: 00001550: 00001590: 000015D0: ---------- WIN.TXT fùAppInit_DLLsÖ�æG¸ÿÿÿC -------------- -------------- $01180: AppInit_DLLs $011F7: UDeviceNotSelectedTimeout $01247: zGDIProcessHandleQuota Created Mar 16 1992, 21:09:15. Audio Conferencing) - http://us.chat1.yimg...v45/yacscom.cabO16 - DPF: {58CDB34C-B4D7-418B-A0FB-C4C8A01C2F0E} - http://diy.51.net/download/diybar.cabO16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akama...meInstaller.exeO16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1119865498363O16 - DPF: {82774781-8F4E-11D1-AB1C-0000F8773BF0} (DLC Class) - http://transfers.one...ransferCtrl.cabO16 - DPF: {88D969C0-F192-11D4-A65F-0040963251E5} Check This Out Site Changelog Community Forum Software by IP.Board Sign In Use Facebook Use Twitter Need an account?

Then see if you still have the same problem.We have a couple of last steps to perform and then you're all set.First, let's reset your hidden/system files and folders.

The operation completed successfully 14:52:10.93 Fri 11/26/2004 __________________________________ *Local time: Friday, November 26, 2004 (11/26/2004) 2:52 PM, Eastern Standard Time *Uptime: 14:52:15 up 0 days, 2:38:01 *Path: C:\FINDnFIX ---------------------------------------------------- »»Member of...: MINIMAL REQUIREMENTS INCLUDE: _________XP HOME/PRO; SP1; IE6/SP1 _________2K/SP4; IE6/SP1 ________________________________________________________________________________ »»»»»*** www10.brinkster.com/expl0iter/freeatlast/FNF/ ***»»»»» -----END------ Sun 28 Nov 04 12:15:15 0 Kudos Posted by CajunTek ‎11-28-2004 12:29 PM Security Expert View All Try What the Tech -- It's free! This applies only to the original topic starter.

size, etc. The file(s) found should be moved to \FINDnFIX\"junkxxx" Subfolder ______________________________________________________________________________ ***YOU NEED TO DISABLE YOUR ACTIVE ANTI VIRUS PROTECTION TO AVOID CONFLICTS!*** ______________________________________________________________________________ ......Scanning for file(s)... *Note! HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Filter\text/html CLSID = {CFE9DFD6-CAF4-44F2-819F-E6C9A236F03A} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Filter\text/plain CLSID = {CFE9DFD6-CAF4-44F2-819F-E6C9A236F03A} »»»*»»»*»»»*»»»*»»»*»»»*»»»*»»»*»»»*»»» »»Size of Windows key: (*Default-450 *No AppInit-398 *fake(infected)-448,504,512...) Size of HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Windows: 448 »»Checking for AppInit_DLLs (empty) value... ________________________________ !"AppInit_DLLs"=""! this contact form Loghdln Dll 57,344 . .

If you accept cookies from this site, you will only be shown this dialog once!You can press escape or click on the X to close this box. Jump to content FacebookTwitter Geeks to Go Forum Security Virus, Spyware, Malware Removal Welcome to Geeks to Go - Register now for FREE Geeks To Go is a helpful hub, where HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs SZ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\DeviceNotSelectedTimeout SZ 15 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\GDIProcessHandleQuota DWORD 00002710 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\Spooler SZ yes HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\swapdisk SZ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\TransmissionRetryTimeout SZ 90 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\USERProcessHandleQuota DWORD 00002710 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows AppInit_DLLs = (*** Here's how it works.