I have so far moved a couple of your threads and closed a couple of others.
Can you please refrain from spamming the forums with your hijackthis logs. This last one of yours was a deliberate repost as it is just a copy/paste job.
Keep all your posts for this problem within this thread!
==
Please download FixWareout from one of these sites:
http://downloads.subratam.org/Fixwareout.exe
http://swandog46.geekstogo.com/Fixwareout.exe
Save it to your desktop and run it. Click Next, then Install, make sure "Run fixit" is checked and click Finish.
The fix will begin; follow the prompts.
You will be asked to reboot your computer; please do so.
Your system may take longer than usual to load; this is normal.
Once the desktop loads post the text that will open (report.txt) and a new Hijackthis log please.
crunchie
Most Valuable Poster
20,095 posts since Feb 2004
Reputation Points: 1,142
Solved Threads: 985
Dragonlover, I don't think Crunchie will mind me picking up this thread cos he is going out for a couple of days. ==First thing, I know you already ran fixwareout before you made your first post [that piggyback one]; if you still have the original log file [report.txt] rename it to reportA.txt; then please do a search in your systemdrive C: for files with a .ren extension. Do this before the next step!
==As Crunchie requested, I would like you to repeat the fixwareout scan, please, cos I would like to see the log it makes.
More to be going on with: start hijackthis again, Scan Only, place checkmarks against all the following entries and then press Fix Checked.
O17 - HKLM\System\CCS\Services\Tcpip\..\{453ED1B8-DC41-47C4-B0CA-479DE5BD95E6}: NameServer = 85.255.116.108,85.255.112.93
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.116.108 85.255.112.93
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.116.108 85.255.112.93
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.116.108 85.255.112.93
Rerun hijackthis and post all the log files [reportA.txt, report.txt and the HTlog...plus if you found any .ren files]
gerbil
Industrious Poster
4,206 posts since May 2005
Reputation Points: 239
Solved Threads: 300
....and cos I already had it typed out and saved... :)
gerbil
Industrious Poster
4,206 posts since May 2005
Reputation Points: 239
Solved Threads: 300
Hello, 'lover..
Would you please do this for me if you have not already- submit this file for evaluation?
Open one of these links, click browse/choose, find the file below then click submit.
http://www.virustotal.com/flash/index_en.html
Or http://virusscan.jotti.org/
C:\WINDOWS\Temp\kdsbb.ren 63383 08/04/2004
Cool. Post the result. [log looks clean, but when you come back with that info we'll tidy up]
gerbil
Industrious Poster
4,206 posts since May 2005
Reputation Points: 239
Solved Threads: 300
Thanks, dragon... we'll delete that one in a moment, but first I would like you to check some settings....In control panel select the Network and Internet Connections , rclick on your default connection, usually local area connection for cable and dsl, and lclick on properties. Click the Networking tab. Dclick on the Internet Protocol (TCP/IP) item and select Obtain DNS servers automatically. Press OK twice to get out of the properties screen and reboot if it asks.
Now I am going to give you a choice of temp file and cache cleaners: ATF Cleaner is fast, quick to set and does a very good job;it's a couple of clicks to clean, but no review possible of what is going out with the bathwater. CCleaner gives you more options, has a free reg cleaner and is fast if you wish to not review files to be cleaned.
ATF Cleaner
===Download this temp file cleaner from http://www.atribune.org/ccount/click.php?id=1 --click in the download window to run it, and when ATF Cleaner opens go Select all, and then Empty Selected.
Next click Firefox [if you have that browser..] at the top, Select All again, and Empty Selected again. Follow that procedure also if you have Opera.
Close ATF.
CCleaner
===Get CCleaner from http://www.ccleaner.com/ - and put it in a new folder. You should aim to keep this one for general use. I set it from the install checkboxes to only open from the recycle bin. It's neater that way.
Now run Ccleaner from the recycle bin rclick menu using its default settings [if you set up CCleaner as i suggested, rclicking the bin icon should give you the Open CCleaner option...]. Select the Cleaner icon and the Windows tab; press Run Cleaner. Next select the Applications tab and Run Cleaner again.
[For future quick temp file cleaning select the options you wish to use. Note that CCleaner is also a free registry cleaner. Explore all its options, but skip the prefetch folder cleaning option. That one is a furphy, much loved on some websites, but cleaning it is unnecessary because windows automatically dumps old unused entries anyway, they can do no harm, and further, if there is no prefetch entry for an app you wish to load then your sys will just be a lil bit slower loading it. And an entry will then be generated anyway.]
...one or the other [both is silly], but run one now.
AVG - AS
===GET AVG antispyware 7.5 here.. http://free.grisoft.com/doc/5390/lng/us/tpl/v5 -the link is almost at the bottom of the page , avgas 7.5.0.50. Install it and update it.
Start AVG a-s 7.5; under Scanner/ Settings set Recommended actions to Quarantine, and run the scan. Save the log file and only then click Apply all actions. Post the log file.
Just before you post check that C:\WINDOWS\Temp\kdsbb.ren has been deleted. And tell me how your sys is performing.
gerbil
Industrious Poster
4,206 posts since May 2005
Reputation Points: 239
Solved Threads: 300