From http://www.spywareinfo.com/~merijn/ , specifically on linklist.cc:
--------------------------------------------------------------
March 24, 2004:
[Update] If your browser has been hijacked to drxcount.biz,
real-yellow-page.com, list2004.com or linklist.cc:
We are working on a fix for this one and drawing near to an automated
solution. This is by far the most sophisticated CWS variant seen to
date, and it will take some time before CWShredder will be able to
remove it.
The following *updated* manual fix should work:
Download this zip: http://www.zero.vulc4n.com/downloads/pv.zip, unzip
it to the desktop.
Be sure to have at least 1 Internet Explorer open, then double click
on the runme.bat.
Notepad will open with a log in it Look for a line with this file,
size and beginning to it. The filename will always be different:
winajbm.dll 61c00000 61440 c:\windows\system32\winajbm.dll
This part indicates the bad file:
61c00000 61440
It will always start with that header.
Write down the filename behind it.
Now download KillBox:
http://download.broadbandmedic.com/VbStuff/KillBox.zip
Unzip and run it.
Don't click any of the buttons though, instead please click on the
Action menu and choose "Delete on Reboot".
On the next screen, click on the File menu and choose "Add File". The
file you copied earlier should now show up in the window. If that's
successful, choose the Action menu and select "Process and Reboot".
You'll be prompted to reboot, do so.
After rebooting, make sure the file is gone.
If this doesn't work, search on the SpywareInfo forums for topics
posted by users with the same problem and read those. If none of the
solutions you find work, make a new thread and ask for help. |