Search Results

Showing results 1 to 40 of 658
Search took 0.05 seconds.
Search: Posts Made By: gerbil
Forum: Windows NT / 2000 / XP Jul 16th, 2009
Replies: 2
Views: 470
Posted By gerbil
Windows Memory mgmnt has it under its control. If you are looking at Task Manager, Available physical memory, and wondering why it is so big, possibly more than half your installed RAM, be assured...
Forum: Windows NT / 2000 / XP Jul 13th, 2009
Replies: 24
Views: 1,508
Posted By gerbil
Good morning.
Installing Recovery Console is a precaution in case Combofix breaks your sys. If you have a bootable XP cd you do not need it on your hard drive- it is then just a convenience.
This...
Forum: Windows NT / 2000 / XP Jul 13th, 2009
Replies: 24
Views: 1,508
Posted By gerbil
It will. If it returned once.... Okay, there are files there that I cannot see, to protect and regenerate malware. I suspect a rootkit, and this tool will flush out most problems:
==Download this...
Forum: Windows NT / 2000 / XP Jul 12th, 2009
Replies: 8
Views: 396
Posted By gerbil
Norton/ symantec. The latest product seems to be performing better in the mix. Anyway, trot along to this page and get the correct removal tool for your version of Norton - use it to completely clean...
Forum: Windows NT / 2000 / XP Jul 12th, 2009
Replies: 24
Views: 1,508
Posted By gerbil
Good stuff, bushoi.
You can close and open explorer.exe at will, it is nothing special. Think of it as similar to IE. Well, it doe share a lot of functions.
browseuiad.dll seemed to be a modified...
Forum: Windows NT / 2000 / XP Jul 12th, 2009
Replies: 24
Views: 1,508
Posted By gerbil
You would need to close all browsers [well, IE uses it... not opera or firefox] and also explorer, firstly. Delete via cmd.exe :
cd\
del /f /s /q /a C:\WINDOWS\system32\browseuiad.dll
Or there is...
Forum: Windows NT / 2000 / XP Jul 11th, 2009
Replies: 24
Views: 1,508
Posted By gerbil
Okay, thanks for that report. Because browseuiad.dll is unknown and its CLSID unregistered you should do the following:
Start hijackthis, select Scan Only, place checkmarks against all the entries...
Forum: Windows NT / 2000 / XP Jul 10th, 2009
Replies: 4
Views: 337
Posted By gerbil
Get Process Explorer from Winternals. The tool for the job. It will show you the handles and dlls used by any running process.
Forum: Windows NT / 2000 / XP Jul 10th, 2009
Replies: 24
Views: 1,508
Posted By gerbil
Check to see that you have this file in your sys: c:\windows\system32\browseui.dll -report back on this.
Virus Scan:
==Please go to this web page http://virusscan.jotti.org/, click browse and...
Forum: Windows NT / 2000 / XP Jul 8th, 2009
Replies: 24
Views: 1,508
Posted By gerbil
For a far more complete listing of startups you should use the Misc Tools section of Hijackthis. Msconfig gives you results from just a few registry keys.
Forum: Windows NT / 2000 / XP Jun 27th, 2009
Replies: 8
Views: 451
Posted By gerbil
Ah... I see where you are. Files and folders are it, just build a good structure with different aspects well separtated for easy location. I start right from the top with different partitions for...
Forum: Windows NT / 2000 / XP Jun 27th, 2009
Replies: 8
Views: 451
Posted By gerbil
Forum: Windows NT / 2000 / XP Jun 25th, 2009
Replies: 17
Views: 793
Posted By gerbil
I think you will find that the disk controller is in the hard disk package... Why? Because it alone knows where everything is on the disk surfaces. The OS just asks for things to be...
Forum: Windows NT / 2000 / XP Jun 24th, 2009
Replies: 17
Views: 793
Posted By gerbil
And rubbing with your fingertip with toothpaste is a great way to remove those minor scratches on the cd surface. True.
So, pits washed with warm soapy water, and cleaned with toothpaste, it's all...
Forum: Viruses, Spyware and other Nasties Jun 22nd, 2009
Replies: 21
Views: 1,474
Posted By gerbil
Cool. Well, that seems to be all taken care of.
Cheers, Geoff. Good luck out there.
Forum: Viruses, Spyware and other Nasties Jun 22nd, 2009
Replies: 21
Views: 1,474
Posted By gerbil
The name of its creator? Obviously you have checked for that, and one is not there. It did not delete, which is interesting.... so rename it and see what complains, if anything, ever - it has not...
Forum: Viruses, Spyware and other Nasties Jun 21st, 2009
Replies: 21
Views: 1,474
Posted By gerbil
That looks better, illahae. Just one thing, what does this file relate to : c:\windows\NV32643396.TMP ?
If it is benign [check its properties] then remove a few of those specialist tools you have...
Forum: Viruses, Spyware and other Nasties Jun 21st, 2009
Replies: 21
Views: 1,474
Posted By gerbil
Skynet. A rootkit. So that is what was hiding msiebbar.dll
This should not take long, but because there are still two drivers to delete we will use Combofix to delete them, in case they are...
Forum: Viruses, Spyware and other Nasties Jun 21st, 2009
Replies: 21
Views: 1,474
Posted By gerbil
Get CCleaner [see below].
Right. This method kinda ramps up... stop when you win. When you do, fix the O18 entry with hijackthis, and then run CCLeaner.
For a start, in an Explorer window, go...
Forum: Viruses, Spyware and other Nasties Jun 18th, 2009
Replies: 21
Views: 1,474
Posted By gerbil
Ah, okay, illahae.. It is gone, so you are pretty clear to go too. Ignore my post re SAS and Registry Editor - not required.
Cheers.
Forum: Viruses, Spyware and other Nasties Jun 18th, 2009
Replies: 15
Views: 1,095
Posted By gerbil
An example would be C:\ autorun.inf
Just use Explorer, expand each drive [partition] if it exists. If not, just run MBAM. These files are usually found in software cds to automatically start the...
Forum: Viruses, Spyware and other Nasties Jun 18th, 2009
Replies: 21
Views: 1,474
Posted By gerbil
Okay, It slipped my mind your having Superantispyware: Please disable it from starting with Windows via the system tray control centre. Restart your sys, and then fix that O18 entry with hijackthis,...
Forum: Viruses, Spyware and other Nasties Jun 18th, 2009
Replies: 15
Views: 1,095
Posted By gerbil
Aw... please don't run registry cleaners. They just don't do anything worthwhile. If you really want to speed up registry access then remove spaces and defragment it - sysinternals have a pgm for...
Forum: Viruses, Spyware and other Nasties Jun 18th, 2009
Replies: 21
Views: 1,474
Posted By gerbil
Okay on the MBAm action... did you miss fixing this one with hijackthis?:
O18 - Filter hijack: text/html - {27ad87fe-f8bf-4593-8e1e-9e7ca6a99ca6} - C:\WINDOWS\system32\msiebbar.dll
It is a protocol...
Forum: Windows NT / 2000 / XP Jun 17th, 2009
Replies: 25
Views: 1,398
Posted By gerbil
I might have known it.. there actually is a bestsitetobe.com
Forum: Windows NT / 2000 / XP Jun 17th, 2009
Replies: 25
Views: 1,398
Posted By gerbil
Okay, when you type in a URL, say http://www.bestsitetobe.com, the web does not recognise that as a valid machine address, so it is converted to one, an IP address, say 234.34.121.005 which is linked...
Forum: Windows NT / 2000 / XP Jun 17th, 2009
Replies: 25
Views: 1,398
Posted By gerbil
To elaborate on what godspeed posted.. those IP addresses are for an address in New Delhi : is that valid for you, plastered? They have persisted throughout all your posted logs, including those in...
Forum: Viruses, Spyware and other Nasties Jun 17th, 2009
Replies: 15
Views: 1,095
Posted By gerbil
Neitz, check in the root of each affected drive to see if there is a file called autoruns.inf: if so, delete it. Then...
==Please download Malwarebytes' Anti-Malware
from:...
Forum: Viruses, Spyware and other Nasties Jun 17th, 2009
Replies: 21
Views: 1,474
Posted By gerbil
Please do not use Rapidshare for posting logs. Post them here.
Start hijackthis, select Scan Only, place checkmarks against all the entries listed below that still exist, and then press Fix Checked....
Forum: Viruses, Spyware and other Nasties Jun 16th, 2009
Replies: 21
Views: 1,474
Posted By gerbil
In safe mode.. rename your MBAM and hijackthis exe files to say, mm.exe and ht.exe, try then to run them.
Forum: Viruses, Spyware and other Nasties Jun 16th, 2009
Replies: 11
Solved: Virus Bundle
Views: 2,447
Posted By gerbil
I bet heaps that Crunchie is going to ask for that comboFix log... it's in C:\.
Forum: Viruses, Spyware and other Nasties Jun 16th, 2009
Replies: 9
Views: 726
Posted By gerbil
I'm hoping so.
Cheers.
Forum: Windows NT / 2000 / XP Jun 15th, 2009
Replies: 3
Views: 269
Posted By gerbil
It is probably the log that some installer makes and refers to when installing software, also may be used by an uninstaller. If you are concerned about malware run a scan.
Forum: Viruses, Spyware and other Nasties Jun 15th, 2009
Replies: 9
Views: 726
Posted By gerbil
Well, that is interesting behaviour, not at all what I expected.
This is the file that concerned me.. it is a virus capable of spawning 100s of other files: C:\WINDOWS\system32\fokubino.dll
It was...
Forum: Viruses, Spyware and other Nasties Jun 14th, 2009
Replies: 9
Views: 726
Posted By gerbil
Ok, we shall try this, MBAM is blind to them for some reason.
==Download this file to your DESKTOP: http://download.bleepingcomputer.com/sUBs/ComboFix.exe
.....or this file:...
Forum: Viruses, Spyware and other Nasties Jun 14th, 2009
Replies: 4
Views: 671
Posted By gerbil
And so give administrator privileges to any malware that would be interested in possessing them.
Forum: Viruses, Spyware and other Nasties Jun 14th, 2009
Replies: 9
Views: 726
Posted By gerbil
Bit of infection still in there, so for a start:
==Please download Malwarebytes' Anti-Malware
from: http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html
or:...
Forum: Viruses, Spyware and other Nasties Jun 14th, 2009
Replies: 4
Views: 671
Posted By gerbil
Well, simplest way is to rclick your IE icon, go Properties, Shortcut, Advanced. You will work it out from there.
Forum: Windows NT / 2000 / XP Jun 13th, 2009
Replies: 25
Views: 1,398
Posted By gerbil
Do i agree that it is a painfully long process...? Yep, getting your sys setup back how you like it certainly is.
So first, I wouild try system file checker... you know, Run..
sfc /scannow
And...
Forum: Windows NT / 2000 / XP Jun 12th, 2009
Replies: 25
Views: 1,398
Posted By gerbil
:)
I did mean the firewall, not utorrent.
Which, I guess, means KIS itself. you are going to need the cleaning tool to do it properly.
Showing results 1 to 40 of 658

 


About Us | Contact Us | Advertise | DaniWeb | Acceptable Use Policy | RSS Feed

©2003 - 2009 DaniWeb® LLC