| | |
Unable to access Internet
![]() |
•
•
Join Date: Jan 2005
Posts: 4
Reputation:
Solved Threads: 0
I was having a problem being able to print in windows 98se so I decided to upgrade to win2k. After doing so I am unable to browse in internet explorer 6. I get the following error that shows in the title area of the browser screen. res://c:\windows\system32\shdoclc.dll/dnserror.htm
I am able to log on using my dial in connection but am unable to get past this page. I mistakenly deleted the shdoclc.dll from windows 98 before upgrading to win2k. Help I need to be able to access the internet.
I am able to log on using my dial in connection but am unable to get past this page. I mistakenly deleted the shdoclc.dll from windows 98 before upgrading to win2k. Help I need to be able to access the internet.
Go
Here and Get Trojan-Hunter Fully working trial!
,,,,,,,,,,,,,,,,,,,,,
Please delete your temporary files by deleting all files and folders that are in those folders (do not delete the temp folder itself) like for example
C:\WINDOWS\Temp\
C:\Temp\
C:\Documents and Settings\username\Local Settings\Temp\
Also delete your Temporary Internet Files, be sure to also select delete all offline content.
Do a virus scan here.
If you get report of files that can’t be cleaned / deleted please write down the filenames and locations and post that in your reply.
,,,,,,,,,,,,,,,,,,,,,,,,,,
Download then unzip and run CWShredder to clean up clicking "FIX" to have it remove all it finds.
CWShredder available from these places :-
http://www.aluriasoftware.com/tools/cwshredder.zip
Or this as a full download without any unzipping required
http://www.downloads.subratam.org/CWShredder.exe
http://www.spywareinfo.com/downloads...CWShredder.exe
We have found that some of the CWS infections can be removed better from safe mode, rather than normal mode.
To get to safe mode use the F8 key while booting the machine. Detailed instructions from :-
HERE
,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,
Then please do this since it’s better to use automated tools to get rid of the bad stuff use these 2 programs first before doing the final cleaning with HJT
First use Spybot S&D. (Version 1.3)
Spybot
Unzip, and update. Install the updates and run. Delete all that it marks in red.
Reboot
Then it’s time for Ad-Aware
Ad-Aware
Install and update by using the globe icon. Restart your computer and run Ad-Aware.
Press scan now and select drives and/or partitions to be scanned. When done select all and click next. Remove all checked items and then reboot your computer.
Please go to this page and read the instructions for how to configure Spybot S&D & Ad-Aware
How To Setup Spybot SD and Ad-Aware
Please do this.
Download 'Hijack This!'. http://www.spywareinfo.com/~merijn/files/HijackThis.exe
Save it in a convenient permanent folder such as C:\HJT\, double click HijackThis.exe, and hit "Scan".
Your copy of HijackThis needs to be in a folder of it's own. When HJT fixes anything, it makes backups of the original files in the folder it is in. Since Temporary folders are emptied now and then (the files are DELETED), it would not be a good idea to have your backups there. Those backups would be VITAL to restoring your system if something went wrong in the FIX process!
1. Please go to you're 'My Documents' folder, right-click and select 'New > Folder' then name the folder 'HJT'.
2. Copy and paste HijackThis.exe to the new folder.
3. Close ALL windows except HJT
4. SCAN with HJT
5. POST the new log in this thread using 'Add Reply'
DO NOT MAKE ANY CHANGES OR CLICK "FIX CHECKED" UNTIL WE CHECK THE LOG, AS SOME OF THE FILES ARE LEGIT AND VITAL TO YOUR COMPUTER'S HEALTH
Then post a HJT log as a reply to this topic.
Here and Get Trojan-Hunter Fully working trial!
,,,,,,,,,,,,,,,,,,,,,
Please delete your temporary files by deleting all files and folders that are in those folders (do not delete the temp folder itself) like for example
C:\WINDOWS\Temp\
C:\Temp\
C:\Documents and Settings\username\Local Settings\Temp\
Also delete your Temporary Internet Files, be sure to also select delete all offline content.
Do a virus scan here.
If you get report of files that can’t be cleaned / deleted please write down the filenames and locations and post that in your reply.
,,,,,,,,,,,,,,,,,,,,,,,,,,
Download then unzip and run CWShredder to clean up clicking "FIX" to have it remove all it finds.
CWShredder available from these places :-
http://www.aluriasoftware.com/tools/cwshredder.zip
Or this as a full download without any unzipping required
http://www.downloads.subratam.org/CWShredder.exe
http://www.spywareinfo.com/downloads...CWShredder.exe
We have found that some of the CWS infections can be removed better from safe mode, rather than normal mode.
To get to safe mode use the F8 key while booting the machine. Detailed instructions from :-
HERE
,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,
Then please do this since it’s better to use automated tools to get rid of the bad stuff use these 2 programs first before doing the final cleaning with HJT
First use Spybot S&D. (Version 1.3)
Spybot
Unzip, and update. Install the updates and run. Delete all that it marks in red.
Reboot
Then it’s time for Ad-Aware
Ad-Aware
Install and update by using the globe icon. Restart your computer and run Ad-Aware.
Press scan now and select drives and/or partitions to be scanned. When done select all and click next. Remove all checked items and then reboot your computer.
Please go to this page and read the instructions for how to configure Spybot S&D & Ad-Aware
How To Setup Spybot SD and Ad-Aware
Please do this.
Download 'Hijack This!'. http://www.spywareinfo.com/~merijn/files/HijackThis.exe
Save it in a convenient permanent folder such as C:\HJT\, double click HijackThis.exe, and hit "Scan".
Your copy of HijackThis needs to be in a folder of it's own. When HJT fixes anything, it makes backups of the original files in the folder it is in. Since Temporary folders are emptied now and then (the files are DELETED), it would not be a good idea to have your backups there. Those backups would be VITAL to restoring your system if something went wrong in the FIX process!
1. Please go to you're 'My Documents' folder, right-click and select 'New > Folder' then name the folder 'HJT'.
2. Copy and paste HijackThis.exe to the new folder.
3. Close ALL windows except HJT
4. SCAN with HJT
5. POST the new log in this thread using 'Add Reply'
DO NOT MAKE ANY CHANGES OR CLICK "FIX CHECKED" UNTIL WE CHECK THE LOG, AS SOME OF THE FILES ARE LEGIT AND VITAL TO YOUR COMPUTER'S HEALTH
Then post a HJT log as a reply to this topic.
Linux boot cd http://www.knopper.net/knoppix/index-en.html
•
•
Join Date: Jan 2005
Posts: 4
Reputation:
Solved Threads: 0
Will try that and get back to you. thanks for the info
stevepd
stevepd
•
•
•
•
Originally Posted by caperjack
Go
Here and Get Trojan-Hunter Fully working trial!
,,,,,,,,,,,,,,,,,,,,,
Please delete your temporary files by deleting all files and folders that are in those folders (do not delete the temp folder itself) like for example
C:\WINDOWS\Temp\
C:\Temp\
C:\Documents and Settings\username\Local Settings\Temp\
Also delete your Temporary Internet Files, be sure to also select delete all offline content.
Do a virus scan here.
If you get report of files that can’t be cleaned / deleted please write down the filenames and locations and post that in your reply.
,,,,,,,,,,,,,,,,,,,,,,,,,,
Download then unzip and run CWShredder to clean up clicking "FIX" to have it remove all it finds.
CWShredder available from these places :-
http://www.aluriasoftware.com/tools/cwshredder.zip
Or this as a full download without any unzipping required
http://www.downloads.subratam.org/CWShredder.exe
http://www.spywareinfo.com/downloads...CWShredder.exe
We have found that some of the CWS infections can be removed better from safe mode, rather than normal mode.
To get to safe mode use the F8 key while booting the machine. Detailed instructions from :-
HERE
,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,
Then please do this since it’s better to use automated tools to get rid of the bad stuff use these 2 programs first before doing the final cleaning with HJT
First use Spybot S&D. (Version 1.3)
Spybot
Unzip, and update. Install the updates and run. Delete all that it marks in red.
Reboot
Then it’s time for Ad-Aware
Ad-Aware
Install and update by using the globe icon. Restart your computer and run Ad-Aware.
Press scan now and select drives and/or partitions to be scanned. When done select all and click next. Remove all checked items and then reboot your computer.
Please go to this page and read the instructions for how to configure Spybot S&D & Ad-Aware
How To Setup Spybot SD and Ad-Aware
Please do this.
Download 'Hijack This!'. http://www.spywareinfo.com/~merijn/files/HijackThis.exe
Save it in a convenient permanent folder such as C:\HJT\, double click HijackThis.exe, and hit "Scan".
Your copy of HijackThis needs to be in a folder of it's own. When HJT fixes anything, it makes backups of the original files in the folder it is in. Since Temporary folders are emptied now and then (the files are DELETED), it would not be a good idea to have your backups there. Those backups would be VITAL to restoring your system if something went wrong in the FIX process!
1. Please go to you're 'My Documents' folder, right-click and select 'New > Folder' then name the folder 'HJT'.
2. Copy and paste HijackThis.exe to the new folder.
3. Close ALL windows except HJT
4. SCAN with HJT
5. POST the new log in this thread using 'Add Reply'
DO NOT MAKE ANY CHANGES OR CLICK "FIX CHECKED" UNTIL WE CHECK THE LOG, AS SOME OF THE FILES ARE LEGIT AND VITAL TO YOUR COMPUTER'S HEALTH
Then post a HJT log as a reply to this topic.
actually re-reading you post just download the dll from Crunchies post .
Linux boot cd http://www.knopper.net/knoppix/index-en.html
•
•
Join Date: Jan 2005
Posts: 4
Reputation:
Solved Threads: 0
Logfile of HijackThis v1.98.2
Scan saved at 12:39:25 PM, on 2/8/2005
Platform: Windows 2000 (WinNT 5.00.2195)
MSIE: Internet Explorer v5.00 (5.00.2920.0000)
Running processes:
D:\WINNT\System32\smss.exe
D:\WINNT\system32\winlogon.exe
D:\WINNT\system32\services.exe
D:\WINNT\system32\lsass.exe
D:\WINNT\system32\svchost.exe
D:\WINNT\system32\spoolsv.exe
D:\WINNT\System32\svchost.exe
D:\WINNT\system32\regsvc.exe
D:\WINNT\system32\MSTask.exe
D:\WINNT\system32\stisvc.exe
D:\WINNT\System32\WBEM\WinMgmt.exe
D:\WINNT\Explorer.exe
D:\WINNT\System32\hszomt.exe
D:\WINNT\System32\remo.exe
D:\WINNT\System32\servic.exe
D:\WINNT\System32\khooker.exe
D:\Program Files\ScanSoft\OmniPageSE\opware32.exe
D:\Program Files\Common Files\Adaptec Shared\CreateCD\CreateCD50.exe
D:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
D:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
D:\QUICKENW\QWDLLS.EXE
D:\Program Files\ISP50\Bin\Bartshel.exe
D:\PROGRA~1\ISP50\dialer\DIALER.EXE
D:\PROGRA~1\ISP50\bin\ppshared.exe
D:\Program Files\ISP50\Bin\Bartshel.exe
D:\Program Files\PeoplePC Accelerated\propelac.exe
D:\Program Files\Internet Explorer\iexplore.exe
D:\WINNT\System32\specialfile.exe
D:\Program Files\Internet Explorer\iexplore.exe
D:\hijackthis\HijackThis.exe
D:\hijackthis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://home.peoplepc.com/search/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,
ProxyServer = http=localhost:8080
O4 - HKLM\..\Run: [Windows Compliant] hszomt.exe
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [remo Personal Firewall] remo.exe
O4 - HKLM\..\Run: [Sygate Personal Firewall Start] servic.exe
O4 - HKLM\..\Run: [SiS KHooker] D:\WINNT\System32\khooker.exe
O4 - HKLM\..\Run: [Omnipage] D:\Program Files\ScanSoft\OmniPageSE\opware32.
exe
O4 - HKLM\..\Run: [CreateCD50] "D:\Program Files\Common Files\Adaptec
Shared\CreateCD\CreateCD50.exe" -r
O4 - HKLM\..\Run: [AdaptecDirectCD] "D:\Program Files\Adaptec\Easy
CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\RunServices: [Windows Compliant] hszomt.exe
O4 - HKLM\..\RunServices: [remo Personal Firewall] remo.exe
O4 - HKLM\..\RunServices: [Sygate Personal Firewall Start] servic.exe
O4 - HKCU\..\Run: [Windows Compliant] hszomt.exe
O4 - HKCU\..\Run: [Sygate Personal Firewall Start] servic.exe
O4 - HKCU\..\Run: [remo Personal Firewall] remo.exe
O4 - HKCU\..\Run: [SpySweeper] "D:\Program Files\Webroot\Spy Sweeper\SpySweeper.
exe" /1
O4 - Global Startup: Billminder.lnk = D:\QUICKENW\BILLMIND.EXE
O4 - Global Startup: Quicken Startup.lnk = D:\QUICKENW\QWDLLS.EXE
O8 - Extra context menu item: Refresh Pa&ge with Full Quality - D:
\Program Files\PeoplePC Accelerated\pac-page.html
O8 - Extra context menu item: Refresh Pi&cture with Full Quality
- D:\Program Files\PeoplePC Accelerated\pac-image.html
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a}
- D:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-
11d2-a20b-00aa003c157a} - D:\WINNT\web\related.htm
O17 - HKLM\System\CCS\Services\Tcpip\..\{2B2FF860-9F11-4E80-A6FA-
0CF63EE613CB}: NameServer = 209.244.0.3 209.244.0.4
Scan saved at 12:39:25 PM, on 2/8/2005
Platform: Windows 2000 (WinNT 5.00.2195)
MSIE: Internet Explorer v5.00 (5.00.2920.0000)
Running processes:
D:\WINNT\System32\smss.exe
D:\WINNT\system32\winlogon.exe
D:\WINNT\system32\services.exe
D:\WINNT\system32\lsass.exe
D:\WINNT\system32\svchost.exe
D:\WINNT\system32\spoolsv.exe
D:\WINNT\System32\svchost.exe
D:\WINNT\system32\regsvc.exe
D:\WINNT\system32\MSTask.exe
D:\WINNT\system32\stisvc.exe
D:\WINNT\System32\WBEM\WinMgmt.exe
D:\WINNT\Explorer.exe
D:\WINNT\System32\hszomt.exe
D:\WINNT\System32\remo.exe
D:\WINNT\System32\servic.exe
D:\WINNT\System32\khooker.exe
D:\Program Files\ScanSoft\OmniPageSE\opware32.exe
D:\Program Files\Common Files\Adaptec Shared\CreateCD\CreateCD50.exe
D:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
D:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
D:\QUICKENW\QWDLLS.EXE
D:\Program Files\ISP50\Bin\Bartshel.exe
D:\PROGRA~1\ISP50\dialer\DIALER.EXE
D:\PROGRA~1\ISP50\bin\ppshared.exe
D:\Program Files\ISP50\Bin\Bartshel.exe
D:\Program Files\PeoplePC Accelerated\propelac.exe
D:\Program Files\Internet Explorer\iexplore.exe
D:\WINNT\System32\specialfile.exe
D:\Program Files\Internet Explorer\iexplore.exe
D:\hijackthis\HijackThis.exe
D:\hijackthis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://home.peoplepc.com/search/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,
ProxyServer = http=localhost:8080
O4 - HKLM\..\Run: [Windows Compliant] hszomt.exe
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [remo Personal Firewall] remo.exe
O4 - HKLM\..\Run: [Sygate Personal Firewall Start] servic.exe
O4 - HKLM\..\Run: [SiS KHooker] D:\WINNT\System32\khooker.exe
O4 - HKLM\..\Run: [Omnipage] D:\Program Files\ScanSoft\OmniPageSE\opware32.
exe
O4 - HKLM\..\Run: [CreateCD50] "D:\Program Files\Common Files\Adaptec
Shared\CreateCD\CreateCD50.exe" -r
O4 - HKLM\..\Run: [AdaptecDirectCD] "D:\Program Files\Adaptec\Easy
CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\RunServices: [Windows Compliant] hszomt.exe
O4 - HKLM\..\RunServices: [remo Personal Firewall] remo.exe
O4 - HKLM\..\RunServices: [Sygate Personal Firewall Start] servic.exe
O4 - HKCU\..\Run: [Windows Compliant] hszomt.exe
O4 - HKCU\..\Run: [Sygate Personal Firewall Start] servic.exe
O4 - HKCU\..\Run: [remo Personal Firewall] remo.exe
O4 - HKCU\..\Run: [SpySweeper] "D:\Program Files\Webroot\Spy Sweeper\SpySweeper.
exe" /1
O4 - Global Startup: Billminder.lnk = D:\QUICKENW\BILLMIND.EXE
O4 - Global Startup: Quicken Startup.lnk = D:\QUICKENW\QWDLLS.EXE
O8 - Extra context menu item: Refresh Pa&ge with Full Quality - D:
\Program Files\PeoplePC Accelerated\pac-page.html
O8 - Extra context menu item: Refresh Pi&cture with Full Quality
- D:\Program Files\PeoplePC Accelerated\pac-image.html
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a}
- D:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-
11d2-a20b-00aa003c157a} - D:\WINNT\web\related.htm
O17 - HKLM\System\CCS\Services\Tcpip\..\{2B2FF860-9F11-4E80-A6FA-
0CF63EE613CB}: NameServer = 209.244.0.3 209.244.0.4
•
•
•
•
Originally Posted by caperjack
Go
Here and Get Trojan-Hunter Fully working trial!
,,,,,,,,,,,,,,,,,,,,,
Please delete your temporary files by deleting all files and folders that are in those folders (do not delete the temp folder itself) like for example
C:\WINDOWS\Temp\
C:\Temp\
C:\Documents and Settings\username\Local Settings\Temp\
Also delete your Temporary Internet Files, be sure to also select delete all offline content.
Do a virus scan here.
If you get report of files that can’t be cleaned / deleted please write down the filenames and locations and post that in your reply.
,,,,,,,,,,,,,,,,,,,,,,,,,,
Download then unzip and run CWShredder to clean up clicking "FIX" to have it remove all it finds.
CWShredder available from these places :-
http://www.aluriasoftware.com/tools/cwshredder.zip
Or this as a full download without any unzipping required
http://www.downloads.subratam.org/CWShredder.exe
http://www.spywareinfo.com/downloads...CWShredder.exe
We have found that some of the CWS infections can be removed better from safe mode, rather than normal mode.
To get to safe mode use the F8 key while booting the machine. Detailed instructions from :-
HERE
,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,
Then please do this since it’s better to use automated tools to get rid of the bad stuff use these 2 programs first before doing the final cleaning with HJT
First use Spybot S&D. (Version 1.3)
Spybot
Unzip, and update. Install the updates and run. Delete all that it marks in red.
Reboot
Then it’s time for Ad-Aware
Ad-Aware
Install and update by using the globe icon. Restart your computer and run Ad-Aware.
Press scan now and select drives and/or partitions to be scanned. When done select all and click next. Remove all checked items and then reboot your computer.
Please go to this page and read the instructions for how to configure Spybot S&D & Ad-Aware
How To Setup Spybot SD and Ad-Aware
Please do this.
Download 'Hijack This!'. http://www.spywareinfo.com/~merijn/files/HijackThis.exe
Save it in a convenient permanent folder such as C:\HJT\, double click HijackThis.exe, and hit "Scan".
Your copy of HijackThis needs to be in a folder of it's own. When HJT fixes anything, it makes backups of the original files in the folder it is in. Since Temporary folders are emptied now and then (the files are DELETED), it would not be a good idea to have your backups there. Those backups would be VITAL to restoring your system if something went wrong in the FIX process!
1. Please go to you're 'My Documents' folder, right-click and select 'New > Folder' then name the folder 'HJT'.
2. Copy and paste HijackThis.exe to the new folder.
3. Close ALL windows except HJT
4. SCAN with HJT
5. POST the new log in this thread using 'Add Reply'
DO NOT MAKE ANY CHANGES OR CLICK "FIX CHECKED" UNTIL WE CHECK THE LOG, AS SOME OF THE FILES ARE LEGIT AND VITAL TO YOUR COMPUTER'S HEALTH
Then post a HJT log as a reply to this topic.
a little communication is a wonderful thing ,you don't say if you ran any of the programs or scans in my other post ,you don't say if you did that it didn't help or it helped a bit ,
If you didn't run any ,please at least run the cwshredder program ,and the online virus scan .also when you scan again with hijackthis please make sure all browser windows and other programs are closed ,only hijackthis running .thanks
You log contaies two worm/trojans ,and the scans should fix them !
,,,,,,,,,,,,,,,,,,,,,,,,,,,,
Please run these free online Virus scan
Be sure to Check off Auto Fix on this site
http://housecall.trendmicro.com/hous...start_corp.asp
please run this one also to be sure .
http://www.pandasoftware.com/actives..._principal.htm
If that didn't fix it try this .
Go
Here and Get Trojan-Hunter Fully working trial! and run a full scan
,,,,,,,,,,,,,,,,,,,,,
If you didn't run any ,please at least run the cwshredder program ,and the online virus scan .also when you scan again with hijackthis please make sure all browser windows and other programs are closed ,only hijackthis running .thanks
You log contaies two worm/trojans ,and the scans should fix them !
,,,,,,,,,,,,,,,,,,,,,,,,,,,,
Please run these free online Virus scan
Be sure to Check off Auto Fix on this site
http://housecall.trendmicro.com/hous...start_corp.asp
please run this one also to be sure .
http://www.pandasoftware.com/actives..._principal.htm
If that didn't fix it try this .
Go
Here and Get Trojan-Hunter Fully working trial! and run a full scan
,,,,,,,,,,,,,,,,,,,,,
Linux boot cd http://www.knopper.net/knoppix/index-en.html
•
•
Join Date: Jan 2005
Posts: 4
Reputation:
Solved Threads: 0
I did run the trend micro virus program and it said I had multiple virus's but says it can not clean them. Apparently I have several virus's that I will need to clean off. I was not able to get the trojanhunter to work but it may be due to the virus's. What are the worm trojans that you are speaking of and can I at least remove them using hijack this. Thanks
•
•
•
•
Originally Posted by caperjack
a little communication is a wonderful thing ,you don't say if you ran any of the programs or scans in my other post ,you don't say if you did that it didn't help or it helped a bit ,
If you didn't run any ,please at least run the cwshredder program ,and the online virus scan .also when you scan again with hijackthis please make sure all browser windows and other programs are closed ,only hijackthis running .thanks
You log contaies two worm/trojans ,and the scans should fix them !
,,,,,,,,,,,,,,,,,,,,,,,,,,,,
Please run these free online Virus scan
Be sure to Check off Auto Fix on this site
http://housecall.trendmicro.com/hous...start_corp.asp
please run this one also to be sure .
http://www.pandasoftware.com/actives..._principal.htm
If that didn't fix it try this .
Go
Here and Get Trojan-Hunter Fully working trial! and run a full scan
,,,,,,,,,,,,,,,,,,,,,
The following are the main cause of your problems;
You can get a free AV and a free firewall from the links in my signature below.
You need to update hijackthis to version 1.99. Run hijackthis & go to *Config\Misc Tools\Check for update on-line*. If the site is down, go here. Remove the old version by opening the program, going to config\misc tools, then uninstall & exit. You then have to delete the file manually. Unzip the new version into the hijackthis folder. Do not run it from a Temporary folder.
Run Hijackthis and go to the process viewer by going to Config, Misc Tools, Process Viewer, to unload all instances of the following running processes;
hszomt.exe
remo.exe
servic.exe
specialfile.exe
Go to D:\WINNT\System32 and delete those files.
Scan with hijackthis and tick the boxes next to all the following entries, then close all browser and explorer windows, and hit the "Fix checked" button.
O4 - HKLM\..\Run: [Windows Compliant] hszomt.exe
O4 - HKLM\..\Run: [remo Personal Firewall] remo.exe
O4 - HKLM\..\Run: [Sygate Personal Firewall Start] servic.exe
O4 - HKLM\..\RunServices: [Windows Compliant] hszomt.exe
O4 - HKLM\..\RunServices: [remo Personal Firewall] remo.exe
O4 - HKLM\..\RunServices: [Sygate Personal Firewall Start] servic.exe
O4 - HKCU\..\Run: [Windows Compliant] hszomt.exe
O4 - HKCU\..\Run: [Sygate Personal Firewall Start] servic.exe
O4 - HKCU\..\Run: [remo Personal Firewall] remo.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a}
- D:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-
11d2-a20b-00aa003c157a} - D:\WINNT\web\related.htm
Reboot after doing the above, rescan with hijackthis, then post that log here please.
You can get a free AV and a free firewall from the links in my signature below.
You need to update hijackthis to version 1.99. Run hijackthis & go to *Config\Misc Tools\Check for update on-line*. If the site is down, go here. Remove the old version by opening the program, going to config\misc tools, then uninstall & exit. You then have to delete the file manually. Unzip the new version into the hijackthis folder. Do not run it from a Temporary folder.
Run Hijackthis and go to the process viewer by going to Config, Misc Tools, Process Viewer, to unload all instances of the following running processes;
hszomt.exe
remo.exe
servic.exe
specialfile.exe
Go to D:\WINNT\System32 and delete those files.
Scan with hijackthis and tick the boxes next to all the following entries, then close all browser and explorer windows, and hit the "Fix checked" button.
O4 - HKLM\..\Run: [Windows Compliant] hszomt.exe
O4 - HKLM\..\Run: [remo Personal Firewall] remo.exe
O4 - HKLM\..\Run: [Sygate Personal Firewall Start] servic.exe
O4 - HKLM\..\RunServices: [Windows Compliant] hszomt.exe
O4 - HKLM\..\RunServices: [remo Personal Firewall] remo.exe
O4 - HKLM\..\RunServices: [Sygate Personal Firewall Start] servic.exe
O4 - HKCU\..\Run: [Windows Compliant] hszomt.exe
O4 - HKCU\..\Run: [Sygate Personal Firewall Start] servic.exe
O4 - HKCU\..\Run: [remo Personal Firewall] remo.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a}
- D:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-
11d2-a20b-00aa003c157a} - D:\WINNT\web\related.htm
Reboot after doing the above, rescan with hijackthis, then post that log here please.
![]() |
Similar Threads
- Another AntiVirus Attack Unable to access internet (Viruses, Spyware and other Nasties)
- browser unable to access internet but other softwares(bit comet,yahoo) can (Web Browsers)
- I am unable to get on the internet on my desk top (Viruses, Spyware and other Nasties)
- Cannot access internet but can Ping IP's (Networking Hardware Configuration)
- Unable to access the Internet (Windows NT / 2000 / XP)
- Unable to access microsoft.com and others (Web Browsers)
- Unable to access any microsoft website (Viruses, Spyware and other Nasties)
- Unable to access any microsft website (IT Professionals' Lounge)
- Unable to access My Computer/My Documents/Iexplore etc. (Viruses, Spyware and other Nasties)
Other Threads in the Viruses, Spyware and other Nasties Forum
- Previous Thread: new here
- Next Thread: System restore, search files& folders doesn't work. HiJackthis log is like reading gr
| Thread Tools | Search this Thread |
adware anti-malware anti-virussitesaccessissue antivirus apple attack audio avg backtoschoolspeech bar blackhat botnet botnets censorship china commercial commercials conficker connect control crosssitescripting cyber cybercrime cyberwarfare ddos domains e-mafia education email europe exam exploit fake fancheckvirus gaming gtaiv gumblar halloween hijack hosting internet iphone kaspersky legal mail malware mcafee mega-d messagelabs microsoft mobile msn nazi news obama onlinethreats paedophile parents patch phishing police policeprovirusmba-mblockedinternetaccess president pro problem redirect reliability report research risk rogueantivirus samhain sans school search security seopoisoning sites software spam spyware spywareexternalwindows7adminstratortrojans sqlinjection symantec system teen translate trojan unabletoaccessanti-virussites unwanted update usa virus viruses vista war windows worm yahoo zeroday






