After recovering from a recent virus...
Does anybody know what the following startup entry is?
otohacaf Runndll32.exe "C\WINDOWS\otohacaf.dll",startup
In registry it is called Wjoxafawi
It sounds iffy to me, but the dll file is very old and hasn't been changed.
I can't delete the registry entry or disable the startup.....and XP will not boot up in safe mode...pf8.
I would welcome any suggestions on the startup entry or the safe mode issue....Thanks.
Virus recovery
-
multinetting
- Posts: 18
- Joined: Sat Jul 19, 2008 9:39 am
- Location: Guildford England
- Contact:
-
RealBlackStuff
- Admin
- Posts: 17517
- Joined: Mon Sep 18, 2006 5:17 am
- Location: Mt. Cobb, PA USA
- Contact:
Re: Virus recovery
That's definitely virus/adware/spyware/trojan junk.
Click on Start/Run, then type in:
REGSVR32 /u C:\Windows\System32\otohacaf.dll
and hit Enter.
Go into your registry (Click on Start/Run, then type in: regedit and hit Enter).
Once in there, click on Edit/Find and type runonce in the searchbox.
Hit enter to find the first occurence.
When found, see if there is an entry Run immediately above the Runonce entry.
If not, press F3 to continue the search, until you find the Run/Runonce combination directly above each other.
If you see this Run, click on it. On the right hand side you see various entries.
Look for anything with otohacaf or Wjoxafawi in it.
If found, click on the first part of that line (which should now become highlighted), verify you have the correct line, then press the Del or Delete button, and confirm.
Continue your search by pressing F3. (Note: after you were in Run, of course the next entry is again Runonce, so hit F3 once more).
Delete all of them wonky entries.
When no more entries found, close Regedit.
Now click on Start/Run/Programs/Startup and check if there is an entry with otohacaf or Wjoxafawi in it.
If found, right-click it and select Delete. Confirm.
When done, reboot.
Hopefully everything is OK now, and you can delete: C\WINDOWS\otohacaf.dll
Also do a search for this Wjoxafawi or Wjoxafawi.exe etc. and delete it/them.
Let us know what gives.
Click on Start/Run, then type in:
REGSVR32 /u C:\Windows\System32\otohacaf.dll
and hit Enter.
Go into your registry (Click on Start/Run, then type in: regedit and hit Enter).
Once in there, click on Edit/Find and type runonce in the searchbox.
Hit enter to find the first occurence.
When found, see if there is an entry Run immediately above the Runonce entry.
If not, press F3 to continue the search, until you find the Run/Runonce combination directly above each other.
If you see this Run, click on it. On the right hand side you see various entries.
Look for anything with otohacaf or Wjoxafawi in it.
If found, click on the first part of that line (which should now become highlighted), verify you have the correct line, then press the Del or Delete button, and confirm.
Continue your search by pressing F3. (Note: after you were in Run, of course the next entry is again Runonce, so hit F3 once more).
Delete all of them wonky entries.
When no more entries found, close Regedit.
Now click on Start/Run/Programs/Startup and check if there is an entry with otohacaf or Wjoxafawi in it.
If found, right-click it and select Delete. Confirm.
When done, reboot.
Hopefully everything is OK now, and you can delete: C\WINDOWS\otohacaf.dll
Also do a search for this Wjoxafawi or Wjoxafawi.exe etc. and delete it/them.
Let us know what gives.
Lovely day for a Guinness! (The Real Black Stuff)
Check out The Boardroom for Parts, Mods and Other Services.
Check out The Boardroom for Parts, Mods and Other Services.
-
multinetting
- Posts: 18
- Joined: Sat Jul 19, 2008 9:39 am
- Location: Guildford England
- Contact:
Re: Virus recovery
Thanks for this, unfortunately every time I deleted the entry, it replicated itself. The key was fixing the safe mode ...found this...http://blog.didierstevens.com/2007/02/1 ... -reg-file/ It fixed my safe mode, and then I was able to blast this thing off my computer.
-
- Similar Topics
- Replies
- Views
- Last post
-
-
Thinkpad X40 Windows XP Recovery?
by Shayan » Tue Jan 03, 2017 7:44 pm » in ThinkPad X2/X3/X4x Series incl. X41 Tablet - 0 Replies
- 390 Views
-
Last post by Shayan
Tue Jan 03, 2017 7:44 pm
-
-
-
Thinkpad 770X recovery with 770Z discs?
by rheacox » Thu Jan 05, 2017 12:46 pm » in ThinkPad Legacy Hardware - 5 Replies
- 1014 Views
-
Last post by fultontech
Thu Jan 05, 2017 5:20 pm
-
-
-
SOLVED! Recovery media for T410 2518-4LU W7 Pro 64
by rakirkp » Sun Jan 22, 2017 11:22 am » in Marketplace - Forum Members only - 1 Replies
- 262 Views
-
Last post by theterminator93
Sun Jan 22, 2017 1:28 pm
-
-
-
WTB Recovery media Thinkpad 365XD
by zakkzapp » Mon Jan 23, 2017 11:16 pm » in Marketplace - Forum Members only - 1 Replies
- 243 Views
-
Last post by hwattys
Tue Jan 24, 2017 2:18 pm
-
Who is online
Users browsing this forum: No registered users and 6 guests



