1,661 Posted Topics
Re: For every User listed under C:\Documents and Settings, delete the entire contents of these folders (not the folders themselves): Local Settings\Temp Cookies History Local Settings\Temporary Internet Files\Content.IE5 Delete the entire contents of your C:\Windows\Temp folder. Delete the entire contents of your C:\Temp folder (if you have one). Do a search … | |
Re: Hi Chili-man, welcome to DaniWeb :D Sorry for the delay in responding to this; it got overlooked somehow :( If you still need assistance, please put hijackthis into it's own folder, like E:\HJT\hijackthis.exe (not running directly from the drive as you have it now). Close any open browser windows, scan … | |
Re: You seem to have missed a step there :): "Next please run HijackThis, click Scan, and check: F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe Close all open windows except for HijackThis and click Fix Checked." | |
Re: Hi Tony, welcome to DaniWeb, :D In order for us to see exactly what you have running on your system, I suggest you get the self-extracting version of HijackThis from here (in line 2): [url]http://www.malwareremoval.com/downloads.html[/url] Then close any open browser windows, 'Scan and Save Log' with hijackthis, copy the log, … | |
Re: Hi scrname, welcome to DaniWeb :D Even if you've already done some of these things, please update them and run them again. First of all, run a at least two of these free online anti-virus/anti-spyware scans and have them clean what they can: [url]http://www.kaspersky.com/scanforvirus.html[/url] [url]http://housecall.trendmicro.com/[/url] [url]http://us.mcafee.com/root/mfs/default.asp?cid=9914[/url] [url]http://www.ravantivirus.com/scan/[/url] [url]http://www.bitdefender.com/scan/licence.php[/url] Download, install, … | |
Re: Please follow the suggestions in this tread and then post a new log. Thanks :) [url]http://www.daniweb.com/techtalkforums/thread24085.html[/url] | |
Re: Hi verachion,welcome to DaniWeb :D Besides the DAP, you have a few other things that should be cleaned up, but before you fix anything with HijackThis, you should put it into it's own folder. You can do this by right-clicking in an open area of your desktop, select New, and … | |
Re: Hi atsand, welcome to DaniWeb :D Have you tried using System Restore to return your computer to a state prior to when you started having problems? If not, try that first. You should put hijackthis into it's own folder; to do this, right-click in an open area of your desktop, … | |
Re: I see a few more things there that need to be fixed. Scan with hijackthis and have it fix the following entries: O2 - BHO: (no name) - {397D7D63-816E-4ECF-8761-775C932C5CF1} - C:\WINDOWS\iDonate.dll O4 - HKLM\..\Run: [wnddrv] C:\WINDOWS\svchost.exe O16 - DPF: {88D758A3-D33B-45FD-91E3-67749B4057FA} - [url]http://dm.screensavers.com/dm/insta.../sinstaller.cab[/url] Remember to close any open windows, other then … | |
Re: Also, as soon as possible, go to Windows Update and get the Critical Updates for your system. | |
Re: Hi Danny, welcome to DaniWeb, we need more Danny's here :D As Catweazle suggested, you may have an infection of some sort. In order for us to see exactly what you have running on your system, I suggest you get the self-extracting version of HijackThis from here (in line 2): … | |
Re: Crunchie will probably have some other ideas, but until he gets back to this, try these suggestions: Get [B]SilentRunners[/B] from here: [url]http://www.silentrunners.org/[/url] Run it, and save the log that it generates. Get the Pocket Killbox from here: [url]http://bleepingcomputer.com/files/spyware/KillBox.zip[/url] Unzip the file to your desktop. Boot into Safe Mode and do … | |
Re: What OS are you using? Do you have [B]Event Viewer[/B] available? | |
Re: Hi Mister_Marvioso, welcome to DaniWeb :D Get the Pocket Killbox from here: [url]http://bleepingcomputer.com/files/spyware/KillBox.zip[/url] Unzip the file to your desktop. Go offline until this is completed (you may wish to print these instructions). Boot into Safe Mode and do a search for these files and delete any instances found ([B]be sure … | |
Re: Hi agbd, welcome to DaniWeb :D Download, install, update, and run these tools: CWShredder -- [url]http://www.intermute.com/spysubtract/cwshredder_download.html[/url] about:Buster -- [url]http://www.majorgeeks.com/download4289.html[/url] Please get the self-extracting version of HijackThis from here (in line 2): [url]http://www.malwareremoval.com/downloads.html[/url] Then close any open browser windows, 'Scan and Save Log' with hijackthis, copy the log, and paste it … | |
Re: Try this to get rid of HotOffers: Get the Pocket Killbox from here: [url]http://bleepingcomputer.com/files/spyware/KillBox.zip[/url] Unzip the file to your desktop. Go offline until this is completed (you may wish to print these instructions). Boot into Safe Mode and do a search for these files and delete any instances found: [B]param32.dll … | |
Re: Hi Dreamer132, welcome to DaniWeb :D I've split your post into it's own thread per forum rules ([url]http://www.daniweb.com/techtalkforums/faq.php?faq=daniweb_faq#faq_rules[/url]) Get the self-extracting version of HijackThis from here (in line 2): [url]http://www.malwareremoval.com/downloads.html[/url] Then close any open browser windows, 'Scan and Save Log' with hijackthis, copy the log, and paste it in this … | |
Re: Hi ysb21189, welcome to DaniWeb :D You've got HijackThis in a Temp folder (C:\Documents and Settings\Owner\Local Settings\[B]Temp[/B]\_AZTMP0_\HijackThis.exe) and it needs to be in it's own permanent folder, like [B]c:\HJT\hijackthis.exe[/B], so it -- and the backups it will create -- don't get accidently deleted. After you've moved it, [B]close any open … | |
Re: [QUOTE=sunandoghosh]daniweb forum - was NOT opening yesterday Hi I just wanted to confirm whether i was not able to access or there was some problem from daniweb side bcz yesterday I was not able to access the forum. It was around 9 pm in the evening for one hour continuous. … | |
Re: Hi spiffymallethea, welcome to DaniWeb :D I don't see Spybot or SpywareBlaster in your list; you should have those. Google is your best bet for researching stuff... better then a dictionary! :) If you like, you can post your HijackThis log here and we can have a look at it. | |
Re: [QUOTE=zeroth]I´ll guarantee you that [b]not[/b] every idea has been thought of.[/QUOTE] Sure it has, a looong time ago. Haven't you ever heard this statement? [B]"Everything that can be invented has been invented." -Charles H. Duell, Commissioner, U.S. Office of Patents, 1899.[/B] :cheesy: | |
Re: Hi mortalsin, welcome to DaniWeb :) Whether formatting would be easier or not depends on how many programs and such you have installed. It shouldn't be necessary though, we should be able to help you clean it up. But yes, formatting [I]would[/I] get rid of the problem. Note: Even if … | |
Re: Hi paranoid, welcome to DaniWeb :D "I tried EVERYTHING" isn't very specific :) Do any of the following that you haven't done already... First of all, run a couple of these free online anti-virus/anti-spyware scans and have them clean what they can: [url]http://www.kaspersky.com/scanforvirus.html[/url] [url]http://housecall.trendmicro.com/[/url] [url]http://us.mcafee.com/root/mfs/default.asp?cid=9914[/url] [url]http://www.ravantivirus.com/scan/[/url] [url]http://www.bitdefender.com/scan/licence.php[/url] Download, install, update, … | |
![]() | Re: Run the PurityScan uninstaller: [url]http://www.purityscan.com/uninstall.html[/url] For every User listed under C:\Documents and Settings, delete the entire contents of these folders (not the folders themselves): Local Settings\Temp Cookies History Local Settings\Temporary Internet Files\Content.IE5 Delete the entire contents of your C:\Windows\Temp folder. Delete the entire contents of your C:\Temp folder (if you … |
Re: [QUOTE=sunandoghosh]how can i give u negative reputaion... and also in forums u people talk abotu repuation...can u explain how its given actually........[/QUOTE]If you go to the Control Panel tab, you will see your Reputation score in there. You start with 10 when you join and it goes up (or down) … | |
Re: Hi Harish, Comotose had a thought (he actually has a lot of them, but this one had to do with your problem :) ) You could be having a memory problem -- well, [I]your computer[/I] could be having a memory problem. Do you remember if you added any RAM around … | |
Re: Hi dave2U, welcome to DaniWeb :D See if this thread helps at all (post #4 in particular). | |
Re: Hi Maynd, welcome to DaniWeb :D If you haven't done so already, follow these instructions as well (be sure your system is set to show Hidden files and folders first) -- Get the Pocket Killbox from here: [url]http://bleepingcomputer.com/files/spyware/KillBox.zip[/url] Unzip the file to your desktop. Go offline until this is completed … | |
Re: Hi Kollin, sorry for the delay in responding to this. I can't really help much with the problem other then to suggest this: [url]http://www.microsoft.com/windows2000/en/advanced/help/default.asp?url=/windows2000/en/advanced/help/boot_last_good.htm[/url] | |
Re: Hi blackcat, welcome to DaniWeb :D I've split your post into it's own thread per the site rules, "[B]Every question or new thought should have its own thread[/B]. Replies to a previous post should be thread replies to that particular thread. [B]Do not piggyback threads by posting your question as … | |
Re: Hi joe_sausage, welcome to DaniWeb :D Can you post the log from [B]after[/B] you deleted the F2 entry? I don't really see anything in your log other then to make sure the IP address in the R0 and O17 entries are from your ISP. | |
Re: Hi paraque_1, welcome to DaniWeb :D Try this... Scan with hijackthis and have it fix the following entries: O3 - Toolbar: SearchToolbar - {08BEC6AA-49FC-4379-3587-4B21E286C19E} - C:\WINDOWS\System32\ie2cltr.dll O16 - DPF: {11212111-2121-1311-1141-115611111222} - ms-its:mhtml:file://d: oo.mht![url]http://195.95.218.82/users/zoom/web...hm::/update.exe[/url] O16 - DPF: {556DDE35-E955-11D0-A707-000000521957} - [url]http://www.xblock.com/download/xclean_micro.exe[/url] O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (ウイルスバスター On-Line Scan) - [url]http://a840.g.akamai.net/7/840/537/...all/xscan53.cab[/url] O16 - … | |
Re: Hi numptyheid, welcome to DaniWeb :D You may have gotten an incomplete download; try it again either from the the link DMR gave you, or from from here (line 2): [url]http://www.malwareremoval.com/downloads.html[/url] Then close any open browser windows, 'Scan and Save Log' with hijackthis, copy the log, and paste it here … | |
Re: I'd suggest running SFC and see if it helps: [url]http://support.microsoft.com/default.aspx?scid=kb;en-us;185836[/url] | |
Re: Hi maizzie, welcome to DaniWeb :D Start with this -- Download [B]Ewido Security Suite[/B] from here: [url]http://fileforum.betanews.com/detail/ewido_security_suite/1098736486/1[/url] Install it, and while installing, under [B]Additional Options[/B], [U]uncheck[/U] [B]Install background guard[/B] and [B]Install scan via context menu[/B]. From the main Ewido screen, click on [B]Update[/B] in the left menu, and then click … | |
Re: Hi SkyMarshall, welcome to DaniWeb :D Download [B]Ewido Security Suite[/B] from here: [url]http://fileforum.betanews.com/detail/ewido_security_suite/1098736486/1[/url] Install it, and while installing, under [B]Additional Options[/B], [U]uncheck[/U] [B]Install background guard[/B] and [B]Install scan via context menu[/B]. From the main Ewido screen, click on [B]Update[/B] in the left menu, and then click the [B]Start update[/B] button. … | |
Re: I can't answer all your questions, but I'll tell you what I can :) [QUOTE=sunandoghosh]plz refer to following thread........( i wonder why such threads are closed????)[/QUOTE]Threads such as that one are closed because they are of an informative nature and not intended for asking questions or posting replies. [QUOTE=sunandoghosh]can u … | |
Re: Hi italianpest, welcome to DaniWeb :D Start with this -- Download Ewido Security Suite from here: [url]http://fileforum.betanews.com/detail/ewido_security_suite/1098736486/1[/url] Install it, and while installing, under [B]Additional Options[/B], [U]uncheck[/U] [B]Install background guard[/B] and [B]Install scan via context menu[/B]. From the main Ewido screen, click on [B]Update[/B] in the left menu, and then click … | |
Re: The best advice I can offer is to follow the recommendations in this thread: [url]http://www.daniweb.com/techtalkforums/thread5690.html[/url] Then post a HijackThis log (explained in the thread) in the [B]Security [/B] forum to, hopefully, identify the problem. | |
Re: Hi midnightgirl, welcome to DaniWeb :D You need to go to Windows Update and get SP1a for both XP and IE. Go to Add/Remove Programs in your Control Panel and remove (if found): [B]tsa[/B] (or [B]tsl[/B]) [B]fziq[/B] (or [B]fziqm[/B]) [B]sf[/B] Scan with HijackThis and have it fix the following entries: … | |
Re: Hi Rebecca51, welcome to DaniWeb :D Go to Add/Remove Programs in your Control Panel and remove any of the following found: [B]MyWay MySearch MyBar MySearchBar[/B] (Or anything similar) [B]Toolbar WinTools[/B] None of that will help with Aurora, but it needs to be done. Before fixing anything with hijackthis, you need … | |
Re: Hi angelus88, welcome to DaniWeb :D I've split your post into a new thread to prevent confusion with the other one. Get the Pocket Killbox from here: [url]http://bleepingcomputer.com/files/spyware/KillBox.zip[/url] Unzip the file to your desktop. Go offline until this is completed (you may wish to print these instructions). Boot into Safe … | |
Re: Hi GahlHateMyComp , welcome to DaniWeb :D First of all, run a couple of these free online anti-virus/anti-spyware scans and have them clean what they can: [url]http://www.kaspersky.com/scanforvirus.html[/url] [url]http://housecall.trendmicro.com/[/url] [url]http://us.mcafee.com/root/mfs/default.asp?cid=9914[/url] [url]http://www.ravantivirus.com/scan/[/url] [url]http://www.bitdefender.com/scan/licence.php[/url] Download, install, update, and run these three tools: CWShredder -- [url]http://www.intermute.com/spysubtract/cwshredder_download.html[/url] about:Buster -- [url]http://www.majorgeeks.com/download4289.html[/url] HSRemove -- [url]http://www.majorgeeks.com/download4286.html[/url] Reboot, [B]close … | |
Re: Welcome to DaniWeb WCH1086 :D; you've been moved to the appropriate forum :) Get the Pocket Killbox from here: [url]http://bleepingcomputer.com/files/spyware/KillBox.zip[/url] Unzip the file to your desktop. Go offline until this is completed (you may wish to print these instructions). Boot into Safe Mode and do a search for these files … | |
Re: Hi Dave, welcome to DaniWeb :D To help us see what you have going on, get the self-extracting version of HijackThis from here (in line 2): [url]http://www.malwareremoval.com/downloads.html[/url] Then, close any open browser windows, 'Scan and Save Log' with hijackthis, copy the log, and paste it here in this thread. And … | |
I'm trying to completely remove Norton SystemWorks from my computer (without reformatting). I've already used Add/Remove Programs to uninstall it. I ran the SYMClean utility (because I've had older versions of Norton on this computer), but it said there was nothing to remove. I ran the SymNRT utility, and it … | |
Re: Hi Flinn$ter, welcome to DaniWeb :D Please see this thread before we continue: [url]http://www.daniweb.com/techtalkforums/thread24085.html[/url] After you've moved hijackthis please post a new log. :) | |
Re: ...One more thing... Please close any open browser windows when scanning with HijackThis :) Link to self-extracting version of HijackThis (line 2): [url]http://www.malwareremoval.com/downloads.html[/url] |
The End.