1,661 Posted Topics

Member Avatar for mikeandike22
Member Avatar for donnnm

For every User listed under C:\Documents and Settings, delete the entire contents of these folders (not the folders themselves): Local Settings\Temp Cookies History Local Settings\Temporary Internet Files\Content.IE5 Delete the entire contents of your C:\Windows\Temp folder. Delete the entire contents of your C:\Temp folder (if you have one). Do a search …

Member Avatar for dlh6213
0
155
Member Avatar for Chili-man

Hi Chili-man, welcome to DaniWeb :D Sorry for the delay in responding to this; it got overlooked somehow :( If you still need assistance, please put hijackthis into it's own folder, like E:\HJT\hijackthis.exe (not running directly from the drive as you have it now). Close any open browser windows, scan …

Member Avatar for DMR
0
200
Member Avatar for ten278

You seem to have missed a step there :): "Next please run HijackThis, click Scan, and check: F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe Close all open windows except for HijackThis and click Fix Checked."

Member Avatar for crunchie
0
469
Member Avatar for tony.coupland

Hi Tony, welcome to DaniWeb, :D In order for us to see exactly what you have running on your system, I suggest you get the self-extracting version of HijackThis from here (in line 2): [url]http://www.malwareremoval.com/downloads.html[/url] Then close any open browser windows, 'Scan and Save Log' with hijackthis, copy the log, …

Member Avatar for dlh6213
0
236
Member Avatar for scrname

Hi scrname, welcome to DaniWeb :D Even if you've already done some of these things, please update them and run them again. First of all, run a at least two of these free online anti-virus/anti-spyware scans and have them clean what they can: [url]http://www.kaspersky.com/scanforvirus.html[/url] [url]http://housecall.trendmicro.com/[/url] [url]http://us.mcafee.com/root/mfs/default.asp?cid=9914[/url] [url]http://www.ravantivirus.com/scan/[/url] [url]http://www.bitdefender.com/scan/licence.php[/url] Download, install, …

Member Avatar for dlh6213
0
177
Member Avatar for lyn1261

Please follow the suggestions in this tread and then post a new log. Thanks :) [url]http://www.daniweb.com/techtalkforums/thread24085.html[/url]

Member Avatar for dlh6213
0
156
Member Avatar for verachion

Hi verachion,welcome to DaniWeb :D Besides the DAP, you have a few other things that should be cleaned up, but before you fix anything with HijackThis, you should put it into it's own folder. You can do this by right-clicking in an open area of your desktop, select New, and …

Member Avatar for DMR
0
157
Member Avatar for atsand

Hi atsand, welcome to DaniWeb :D Have you tried using System Restore to return your computer to a state prior to when you started having problems? If not, try that first. You should put hijackthis into it's own folder; to do this, right-click in an open area of your desktop, …

Member Avatar for dlh6213
0
197
Member Avatar for Manning

I see a few more things there that need to be fixed. Scan with hijackthis and have it fix the following entries: O2 - BHO: (no name) - {397D7D63-816E-4ECF-8761-775C932C5CF1} - C:\WINDOWS\iDonate.dll O4 - HKLM\..\Run: [wnddrv] C:\WINDOWS\svchost.exe O16 - DPF: {88D758A3-D33B-45FD-91E3-67749B4057FA} - [url]http://dm.screensavers.com/dm/insta.../sinstaller.cab[/url] Remember to close any open windows, other then …

Member Avatar for dlh6213
0
349
Member Avatar for Postie

Also, as soon as possible, go to Windows Update and get the Critical Updates for your system.

Member Avatar for DMR
0
371
Member Avatar for dannyhadar

Hi Danny, welcome to DaniWeb, we need more Danny's here :D As Catweazle suggested, you may have an infection of some sort. In order for us to see exactly what you have running on your system, I suggest you get the self-extracting version of HijackThis from here (in line 2): …

Member Avatar for rotisc
0
235
Member Avatar for rhidassa

Crunchie will probably have some other ideas, but until he gets back to this, try these suggestions: Get [B]SilentRunners[/B] from here: [url]http://www.silentrunners.org/[/url] Run it, and save the log that it generates. Get the Pocket Killbox from here: [url]http://bleepingcomputer.com/files/spyware/KillBox.zip[/url] Unzip the file to your desktop. Boot into Safe Mode and do …

Member Avatar for dlh6213
0
149
Member Avatar for jj1257
Member Avatar for dlh6213
0
82
Member Avatar for Mister Marvioso

Hi Mister_Marvioso, welcome to DaniWeb :D Get the Pocket Killbox from here: [url]http://bleepingcomputer.com/files/spyware/KillBox.zip[/url] Unzip the file to your desktop. Go offline until this is completed (you may wish to print these instructions). Boot into Safe Mode and do a search for these files and delete any instances found ([B]be sure …

Member Avatar for dlh6213
0
88
Member Avatar for agbd

Hi agbd, welcome to DaniWeb :D Download, install, update, and run these tools: CWShredder -- [url]http://www.intermute.com/spysubtract/cwshredder_download.html[/url] about:Buster -- [url]http://www.majorgeeks.com/download4289.html[/url] Please get the self-extracting version of HijackThis from here (in line 2): [url]http://www.malwareremoval.com/downloads.html[/url] Then close any open browser windows, 'Scan and Save Log' with hijackthis, copy the log, and paste it …

Member Avatar for dlh6213
0
161
Member Avatar for ceomoses

Try this to get rid of HotOffers: Get the Pocket Killbox from here: [url]http://bleepingcomputer.com/files/spyware/KillBox.zip[/url] Unzip the file to your desktop. Go offline until this is completed (you may wish to print these instructions). Boot into Safe Mode and do a search for these files and delete any instances found: [B]param32.dll …

Member Avatar for Weeian
0
2K
Member Avatar for Dreamer132

Hi Dreamer132, welcome to DaniWeb :D I've split your post into it's own thread per forum rules ([url]http://www.daniweb.com/techtalkforums/faq.php?faq=daniweb_faq#faq_rules[/url]) Get the self-extracting version of HijackThis from here (in line 2): [url]http://www.malwareremoval.com/downloads.html[/url] Then close any open browser windows, 'Scan and Save Log' with hijackthis, copy the log, and paste it in this …

Member Avatar for dlh6213
0
104
Member Avatar for ysb21189

Hi ysb21189, welcome to DaniWeb :D You've got HijackThis in a Temp folder (C:\Documents and Settings\Owner\Local Settings\[B]Temp[/B]\_AZTMP0_\HijackThis.exe) and it needs to be in it's own permanent folder, like [B]c:\HJT\hijackthis.exe[/B], so it -- and the backups it will create -- don't get accidently deleted. After you've moved it, [B]close any open …

Member Avatar for DMR
0
1K
Member Avatar for sunandoghosh

[QUOTE=sunandoghosh]daniweb forum - was NOT opening yesterday Hi I just wanted to confirm whether i was not able to access or there was some problem from daniweb side bcz yesterday I was not able to access the forum. It was around 9 pm in the evening for one hour continuous. …

Member Avatar for sunandoghosh
0
142
Member Avatar for spiffymallethea

Hi spiffymallethea, welcome to DaniWeb :D I don't see Spybot or SpywareBlaster in your list; you should have those. Google is your best bet for researching stuff... better then a dictionary! :) If you like, you can post your HijackThis log here and we can have a look at it.

Member Avatar for crunchie
0
306
Member Avatar for Kase

[QUOTE=zeroth]I´ll guarantee you that [b]not[/b] every idea has been thought of.[/QUOTE] Sure it has, a looong time ago. Haven't you ever heard this statement? [B]"Everything that can be invented has been invented." -Charles H. Duell, Commissioner, U.S. Office of Patents, 1899.[/B] :cheesy:

Member Avatar for Kase
1
180
Member Avatar for mortalsin

Hi mortalsin, welcome to DaniWeb :) Whether formatting would be easier or not depends on how many programs and such you have installed. It shouldn't be necessary though, we should be able to help you clean it up. But yes, formatting [I]would[/I] get rid of the problem. Note: Even if …

Member Avatar for dlh6213
0
333
Member Avatar for paranoid

Hi paranoid, welcome to DaniWeb :D "I tried EVERYTHING" isn't very specific :) Do any of the following that you haven't done already... First of all, run a couple of these free online anti-virus/anti-spyware scans and have them clean what they can: [url]http://www.kaspersky.com/scanforvirus.html[/url] [url]http://housecall.trendmicro.com/[/url] [url]http://us.mcafee.com/root/mfs/default.asp?cid=9914[/url] [url]http://www.ravantivirus.com/scan/[/url] [url]http://www.bitdefender.com/scan/licence.php[/url] Download, install, update, …

Member Avatar for dlh6213
0
443
Member Avatar for leikela

Run the PurityScan uninstaller: [url]http://www.purityscan.com/uninstall.html[/url] For every User listed under C:\Documents and Settings, delete the entire contents of these folders (not the folders themselves): Local Settings\Temp Cookies History Local Settings\Temporary Internet Files\Content.IE5 Delete the entire contents of your C:\Windows\Temp folder. Delete the entire contents of your C:\Temp folder (if you …

Member Avatar for crunchie
0
297
Member Avatar for sunandoghosh

[QUOTE=sunandoghosh]how can i give u negative reputaion... and also in forums u people talk abotu repuation...can u explain how its given actually........[/QUOTE]If you go to the Control Panel tab, you will see your Reputation score in there. You start with 10 when you join and it goes up (or down) …

Member Avatar for sunandoghosh
-1
448
Member Avatar for hbmarar

Hi Harish, Comotose had a thought (he actually has a lot of them, but this one had to do with your problem :) ) You could be having a memory problem -- well, [I]your computer[/I] could be having a memory problem. Do you remember if you added any RAM around …

Member Avatar for dlh6213
0
666
Member Avatar for dave2U

Hi dave2U, welcome to DaniWeb :D See if this thread helps at all (post #4 in particular).

Member Avatar for dave2U
0
154
Member Avatar for maynd

Hi Maynd, welcome to DaniWeb :D If you haven't done so already, follow these instructions as well (be sure your system is set to show Hidden files and folders first) -- Get the Pocket Killbox from here: [url]http://bleepingcomputer.com/files/spyware/KillBox.zip[/url] Unzip the file to your desktop. Go offline until this is completed …

Member Avatar for dlh6213
0
347
Member Avatar for Kollin

Hi Kollin, sorry for the delay in responding to this. I can't really help much with the problem other then to suggest this: [url]http://www.microsoft.com/windows2000/en/advanced/help/default.asp?url=/windows2000/en/advanced/help/boot_last_good.htm[/url]

Member Avatar for dlh6213
0
131
Member Avatar for blackcat

Hi blackcat, welcome to DaniWeb :D I've split your post into it's own thread per the site rules, "[B]Every question or new thought should have its own thread[/B]. Replies to a previous post should be thread replies to that particular thread. [B]Do not piggyback threads by posting your question as …

Member Avatar for dlh6213
0
255
Member Avatar for joe_sausage

Hi joe_sausage, welcome to DaniWeb :D Can you post the log from [B]after[/B] you deleted the F2 entry? I don't really see anything in your log other then to make sure the IP address in the R0 and O17 entries are from your ISP.

Member Avatar for dlh6213
0
121
Member Avatar for paraque1

Hi paraque_1, welcome to DaniWeb :D Try this... Scan with hijackthis and have it fix the following entries: O3 - Toolbar: SearchToolbar - {08BEC6AA-49FC-4379-3587-4B21E286C19E} - C:\WINDOWS\System32\ie2cltr.dll O16 - DPF: {11212111-2121-1311-1141-115611111222} - ms-its:mhtml:file://d: oo.mht![url]http://195.95.218.82/users/zoom/web...hm::/update.exe[/url] O16 - DPF: {556DDE35-E955-11D0-A707-000000521957} - [url]http://www.xblock.com/download/xclean_micro.exe[/url] O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (ウイルスバスター On-Line Scan) - [url]http://a840.g.akamai.net/7/840/537/...all/xscan53.cab[/url] O16 - …

Member Avatar for dlh6213
0
213
Member Avatar for numptyheid

Hi numptyheid, welcome to DaniWeb :D You may have gotten an incomplete download; try it again either from the the link DMR gave you, or from from here (line 2): [url]http://www.malwareremoval.com/downloads.html[/url] Then close any open browser windows, 'Scan and Save Log' with hijackthis, copy the log, and paste it here …

Member Avatar for DMR
0
215
Member Avatar for dustdogz
Member Avatar for gingerrua

I'd suggest running SFC and see if it helps: [url]http://support.microsoft.com/default.aspx?scid=kb;en-us;185836[/url]

Member Avatar for dlh6213
0
407
Member Avatar for maizzie

Hi maizzie, welcome to DaniWeb :D Start with this -- Download [B]Ewido Security Suite[/B] from here: [url]http://fileforum.betanews.com/detail/ewido_security_suite/1098736486/1[/url] Install it, and while installing, under [B]Additional Options[/B], [U]uncheck[/U] [B]Install background guard[/B] and [B]Install scan via context menu[/B]. From the main Ewido screen, click on [B]Update[/B] in the left menu, and then click …

Member Avatar for maizzie
0
313
Member Avatar for SkyMarshall

Hi SkyMarshall, welcome to DaniWeb :D Download [B]Ewido Security Suite[/B] from here: [url]http://fileforum.betanews.com/detail/ewido_security_suite/1098736486/1[/url] Install it, and while installing, under [B]Additional Options[/B], [U]uncheck[/U] [B]Install background guard[/B] and [B]Install scan via context menu[/B]. From the main Ewido screen, click on [B]Update[/B] in the left menu, and then click the [B]Start update[/B] button. …

Member Avatar for crunchie
0
114
Member Avatar for sunandoghosh

I can't answer all your questions, but I'll tell you what I can :) [QUOTE=sunandoghosh]plz refer to following thread........( i wonder why such threads are closed????)[/QUOTE]Threads such as that one are closed because they are of an informative nature and not intended for asking questions or posting replies. [QUOTE=sunandoghosh]can u …

Member Avatar for Catweazle
0
148
Member Avatar for italianpest

Hi italianpest, welcome to DaniWeb :D Start with this -- Download Ewido Security Suite from here: [url]http://fileforum.betanews.com/detail/ewido_security_suite/1098736486/1[/url] Install it, and while installing, under [B]Additional Options[/B], [U]uncheck[/U] [B]Install background guard[/B] and [B]Install scan via context menu[/B]. From the main Ewido screen, click on [B]Update[/B] in the left menu, and then click …

Member Avatar for dlh6213
0
178
Member Avatar for Mark87

The best advice I can offer is to follow the recommendations in this thread: [url]http://www.daniweb.com/techtalkforums/thread5690.html[/url] Then post a HijackThis log (explained in the thread) in the [B]Security [/B] forum to, hopefully, identify the problem.

Member Avatar for Soteriologist
0
348
Member Avatar for midnightgirl

Hi midnightgirl, welcome to DaniWeb :D You need to go to Windows Update and get SP1a for both XP and IE. Go to Add/Remove Programs in your Control Panel and remove (if found): [B]tsa[/B] (or [B]tsl[/B]) [B]fziq[/B] (or [B]fziqm[/B]) [B]sf[/B] Scan with HijackThis and have it fix the following entries: …

Member Avatar for dlh6213
0
123
Member Avatar for rebecca51

Hi Rebecca51, welcome to DaniWeb :D Go to Add/Remove Programs in your Control Panel and remove any of the following found: [B]MyWay MySearch MyBar MySearchBar[/B] (Or anything similar) [B]Toolbar WinTools[/B] None of that will help with Aurora, but it needs to be done. Before fixing anything with hijackthis, you need …

Member Avatar for crunchie
0
361
Member Avatar for angelus88

Hi angelus88, welcome to DaniWeb :D I've split your post into a new thread to prevent confusion with the other one. Get the Pocket Killbox from here: [url]http://bleepingcomputer.com/files/spyware/KillBox.zip[/url] Unzip the file to your desktop. Go offline until this is completed (you may wish to print these instructions). Boot into Safe …

Member Avatar for dlh6213
0
115
Member Avatar for GahIHateMyComp

Hi GahlHateMyComp , welcome to DaniWeb :D First of all, run a couple of these free online anti-virus/anti-spyware scans and have them clean what they can: [url]http://www.kaspersky.com/scanforvirus.html[/url] [url]http://housecall.trendmicro.com/[/url] [url]http://us.mcafee.com/root/mfs/default.asp?cid=9914[/url] [url]http://www.ravantivirus.com/scan/[/url] [url]http://www.bitdefender.com/scan/licence.php[/url] Download, install, update, and run these three tools: CWShredder -- [url]http://www.intermute.com/spysubtract/cwshredder_download.html[/url] about:Buster -- [url]http://www.majorgeeks.com/download4289.html[/url] HSRemove -- [url]http://www.majorgeeks.com/download4286.html[/url] Reboot, [B]close …

Member Avatar for dlh6213
0
128
Member Avatar for WCH1086

Welcome to DaniWeb WCH1086 :D; you've been moved to the appropriate forum :) Get the Pocket Killbox from here: [url]http://bleepingcomputer.com/files/spyware/KillBox.zip[/url] Unzip the file to your desktop. Go offline until this is completed (you may wish to print these instructions). Boot into Safe Mode and do a search for these files …

Member Avatar for dlh6213
0
291
Member Avatar for Dave Balmer

Hi Dave, welcome to DaniWeb :D To help us see what you have going on, get the self-extracting version of HijackThis from here (in line 2): [url]http://www.malwareremoval.com/downloads.html[/url] Then, close any open browser windows, 'Scan and Save Log' with hijackthis, copy the log, and paste it here in this thread. And …

Member Avatar for DMR
0
183
Member Avatar for dlh6213

I'm trying to completely remove Norton SystemWorks from my computer (without reformatting). I've already used Add/Remove Programs to uninstall it. I ran the SYMClean utility (because I've had older versions of Norton on this computer), but it said there was nothing to remove. I ran the SymNRT utility, and it …

Member Avatar for DMR
0
110
Member Avatar for Flinn$ter

Hi Flinn$ter, welcome to DaniWeb :D Please see this thread before we continue: [url]http://www.daniweb.com/techtalkforums/thread24085.html[/url] After you've moved hijackthis please post a new log. :)

Member Avatar for dlh6213
0
189
Member Avatar for crunchie

...One more thing... Please close any open browser windows when scanning with HijackThis :) Link to self-extracting version of HijackThis (line 2): [url]http://www.malwareremoval.com/downloads.html[/url]

Member Avatar for dlh6213
0
781

The End.