1,661 Posted Topics
Re: Before you fix anything with HijackThis, you should move it from the Temp folder it's in to it's own permanent folder (like c:\HJT\hijackthis.exe) I believe [B]LogonDll.dll[/B] is bad, but I don't think [B]streamhlp.dll[/B] is; you can have them both checked here: [url]http://www.kaspersky.com/remoteviruschk.htm[/url] | |
Re: Hi derekbka, welcome to DaniWeb :) I've split your post (from [url]http://www.daniweb.com/techtalkforums/thread22827.html[/url]) into it's own thread so you can get individual attention and so the recommended fixes don't get confused. Get the Pocket Killbox from here: [url]http://bleepingcomputer.com/files/spyware/KillBox.zip[/url] Unzip the file to your desktop. Go offline until this is completed. Boot … | |
Re: Can you tell us where Norton is finding these files? It's possible they are in your System Restore folder. You can also try this: [url]http://securityresponse.symantec.com/avcenter/venc/data/backdoor.sdbot.gen.html[/url] As for the redirect, scan with HJT and have it fix: R3 - Default URLSearchHook is missing If it still doesn't work, download Hoster from … | |
Re: Hi Nightwing, welcome to DaniWeb :) I suggest you get the self-extracting version of HijackThis from here (in line 2): [url]http://www.malwareremoval.com/downloads.html[/url] Close any open browser windows, 'Scan and Save Log' with hijackthis, copy the log and paste it here so we can see what you have running on your system. | |
Re: Right-click in an open area of your desktop, and select Properties; click on the Setting tab, and then look for the slider in the 'Screen area' box, and move it all the way to the left. If that doesn't fill your screen, keep trying differnt settings to the right until … | |
Re: Get the Pocket Killbox from here: [url]http://bleepingcomputer.com/files/spyware/KillBox.zip[/url] Unzip the file to your desktop. Go offline until this is completed. Boot into Safe Mode and do a search for these files: [B]guninst.exe popup_bl.dll systr.dll svrhost.exe[/B] Delete any found, and then find [B]param32.dll[/B] Run Pocket Killbox and paste the full file path … | |
Re: You need to go to Windows Update and get SP1a for XP and IE. Get HSRemove from here: [url]http://www.majorgeeks.com/download4286.html[/url] Print out the instructions for using it on that page, and then run it accordingly. Then post a new hijackthis log here. | |
Re: Just adding to this since you mentioned not being able to delete param32.dll... Turn off System Restore Get the Pocket Killbox from here: [url]http://bleepingcomputer.com/files/spyware/KillBox.zip[/url] Unzip the file to your desktop. Go offline until this is completed. Run Pocket Killbox and paste the full file path of the below file in … | |
Re: First of all, you should go to Windows Update and get SP1a for XP. That error message is related to Joke.Smitfraudoid, which is related to HotOffers, NEWGENLOOK, and Error Message 317, so I would recommend doing the following: Boot into Safe Mode and do a search for these files: [B]param32.dll … | |
Re: First of all you should go to Windows Update and get all the Critical Updates for your system. Then, get about:Buster from here: [url]http://www.majorgeeks.com/download4289.html[/url] Unzip it to your desktop, run it, and: Click [B]Update[/B], and then [B]Check For Update[/B], and [B]Download Update[/B]; wait for the updates to be installed. After … | |
Re: Hi Deannalea, welcome to DaniWeb :) I suggest you get the self-extracting version of HijackThis from here (in line 2): [url]http://www.malwareremoval.com/downloads.html[/url] Close any open browser windows, 'Scan and Save Log' with hijackthis, copy the log and paste it into a new thread in the [B]Virus[/B] forum ([I]not[/I] in this thread). | |
Re: Do you use Viewpoint Manager? It's typically installed without the users knowledge. Download Hoster from here: [url]http://www.funkytoad.com/download/hoster.zip[/url] Run it, and when it opens, click on the [B]Restore Original Hosts[/B] button and then exit Hoster. Scan with HJT and have it fix the following entries (if found): R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search … | |
Re: Mind if I cut in? Dan, you need to go to Windows Update and get SP1a for XP and IE asap. Turn off System Restore Get the Pocket Killbox from here: [url]http://bleepingcomputer.com/files/spyware/KillBox.zip[/url] Unzip the file to your desktop. Go offline until this is completed. Run Pocket Killbox and paste the … | |
Re: [QUOTE=robbyd]Hi, im new at this forum alittle about me, im 24yrs old, live in WA state, im mostly a webdeveloper doing xhtml,css, javascript, but specializing in php,mysql,asp.net and apache server administration.[/QUOTE] Hey, a fellow Washingtonian, it's about time! Welcome aboard Robbyd :) | |
Re: Welcome to DaniWeb Mushromboi :) We prefer to answer questions in the forum, rather then by email, so if someone else has the same problem they can also try any suggestions. Also, others can see what has already been suggested. See if anything here helps you with your problem: [url]http://support.microsoft.com/default.aspx?scid=kb;EN-US;q122926[/url] | |
Re: Hi Tommy1988, welcome to DaniWeb :) I'm afraid it's against forum rules to assist with file-sharing programs: [url]http://www.daniweb.com/techtalkforums/faq.php?faq=daniweb_faq[/url] | |
Re: Sorry, but it's against forum rules to assist with file-sharing programs such as Kazaa: [url]http://www.daniweb.com/techtalkforums/faq.php?faq=daniweb_faq[/url] | |
Re: Hi and welcome to DaniWeb :) Your post has been split into it's own thread so you can get individual attention and so Megapaul's fixes don't get confused with yours. Can you please post your HJT log? That will give us a starting point. | |
Re: I'm afraid it's against forum rules to assist with file-sharing programs: [url]http://www.daniweb.com/techtalkforums/faq.php?faq=daniweb_faq[/url] | |
Re: Here's the latest on Longhorn: [url]http://www.heraldnet.com/stories/05/04/26/100bus_longhorn001.cfm[/url] | |
Re: Edit -- No longer applies since Caperjack edited his post :) | |
Re: DMR, your DaniWeb link doesn't work :( Chilkat, try this to get rid of HotOffers: Boot into Safe Mode and do a search for these files: [B]param32.dll guninst.exe popup_bl.dll systr.dll svrhost.exe[/B] Delete them, and then reboot normally Delete all the HotOffer icons from your desktop. Empty your Recycle Bin. Get … | |
Re: My first suggestion would be to try firewalls, one hardware (like SMC's Barricade), and one software (here's a free one: [url]http://www.zonelabs.com/store/content/company/products/znalm/freeDownload.jsp)[/url]. | |
Re: Here's the latest on Longhorn: [url]http://www.heraldnet.com/stories/05/04/26/100bus_longhorn001.cfm[/url] | |
Re: First you should put hijackthis into it's own folder. To do this, right-click on an open area of your desktop and select New, Folder; give the folder a name (like HJT), and then drag the hijackthis.exe icon that is on your desktop into that new folder. Go to Add/Remove Programs … | |
Re: Right now you're running hijackthis from a Temp folder; before you use it to fix anything, you should put it into it's own permanent folder (like c:\HJT\hijackthis.exe). After you've moved it, close any open browser windows, scan again, and post the new log please. | |
Re: This will help you with the format and installation: [url]http://www.daniweb.com/techtalkforums/thread6632.html[/url] As for the activation, as jwenting said, you will need to contact Microsoft when you are ready to activate. I doubt if you will need to send proof of purchase, just explain the situation. Be prepared to type the activation … | |
Re: I tried it once but I was too busy to take care of it properly and it died :( | |
Re: You should move hijackthis into it's own permanent folder before it gets deleted accidently (something like c:\HJT\hijackthis.exe) O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE -- [url]http://startup.iamnotageek.com/srch-Alcxmntr.exe.html[/url] O4 - HKLM\..\Run: [DIGStream] C:\Program Files\DIGStream\digstream.exe -- [url]http://startup.iamnotageek.com/srch-digstream.exe.html[/url] | |
Re: You should put hijackthis into it's own folder, like C:\Documents and Settings\apryl\My Documents\[B]HJT[/B]\HijackThis.exe Scan with hijackthis and have it fix the following entries: R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\vxvzq.dll/sp.html#28129 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\vxvzq.dll/sp.html#28129 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\vxvzq.dll/sp.html#28129 R1 … | |
Re: Do you have any buttons on your monitor that allow you to change the screen size? | |
Re: Interesting... I've been thinking about the same thing lately. I think the list seems longer now because of the size of the borders on each side. I don't think a link is a good idea though because I don't think very many people would bother going there. People frequently post … | |
Re: If you have a video card, you need to get the manufactures name and model number of it, and then go to their website for the latest drivers. If you have 'on-board' video, you need to get the manufactures name and model number of your motherboard, and then go to … | |
Re: Go to Windows Update and get the Critical Updates for your system Get the latest version of HijackThis here: [url]http://www.spywareinfo.com/~merijn/[/url] Close all browser widows, scan with hijackthis, and post a new log please | |
Re: Once you are able to get online with it, you should go to Windows Update and get the Critical Updates for your system (SP4). | |
Re: [B]S[/B]tay-[B]A[/B]t-[B]H[/B]ome-[B]M[/B]om (that's what it means to me anyway :) ) Welcome Joel :D Not many people are going to believe you when you say it's cloudly and cold in CA, lol. | |
Re: Try IEFix from here: [url]http://www.majorgeeks.com/download4467.html[/url] Go to Windows Update to get the Critical Updates for your system, at least SP1. | |
Re: In post #4 you said "when i open internet explorer", that's the reason crunchie suggested the fix in post #5. I don't know what to tell you about the Mozilla plugin. There shouldn't be much more for you to fix, but we won't know till you post another log :) | |
Re: See if this helps: [url]http://www.daniweb.com/techtalkforums/thread11350.html[/url] The instructions are for a dual-boot, but if you just follow the first part of either attachment you should get Win98 installed. | |
Re: As a starting point, I suggest you get the self-extracting version of HijackThis from here (in line 2): [url]http://www.malwareremoval.com/downloads.html[/url] Close any open browser windows, click 'Scan and Save Log' with hijackthis; when it's finished scanning, a notepad will pop up with the log, copy the log and paste it into … | |
Re: [QUOTE=Kcrazycatt]I am stuck with HotOffers Hijak. The address listed for uninstall cannot be found where do I go from here?[/QUOTE] Hi Kcrazycatt, welcome to DaniWeb :) As a starting point, I suggest you get the self-extracting version of HijackThis from here (in line 2): [url]http://www.malwareremoval.com/downloads.html[/url] Close any open browser windows, … | |
Re: I agree with Nanosani, I once installed XP on a 233MHz system with 64 MB of RAM and it worked, but wasn't 'usable.' If you're going to sell it, why would you want to go through the expense of installing XP anyway? For your reference, you can find complete instructions … | |
Re: Go to Add/Remove Programs in your Control Panel and remove (if found): [B]CxtPls[/B] [B]Media Access[/B] Scan with hijackthis and have it fix the following entries: R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = [url]http://ie.redirect.hp.com/svs/rdr?T...lion&pf=desktop[/url] R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = [url]http://ie.redirect.hp.com/svs/rdr?T...lion&pf=desktop[/url] R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = [url]http://ie.redirect.hp.com/svs/rdr?T...lion&pf=desktop[/url] R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page … | |
Re: The first thing you need to do is go to Windows Update and get the Critical Updates for your system (SP1a, hold off on SP2, at least until your system gets cleaned up). The second thing you should do is move hijackthis into it's own folder before fixing anything with … | |
Re: Hi Sidekickbilly, welcome to DaniWeb :) I've moved your thread to the virus forum so you would get more help. Having more then one antivirus program installed on your computer can cause problems; you should decide which one you prefer and remove the other one. You can run free online … | |
Re: Have you tried the suggestions in this thread yet? [url]http://www.daniweb.com/techtalkforums/showthread.php?t=19959[/url] Also run the free online scans from TrendMicro: [url]http://housecall.trendmicro.com/[/url] And Panda: [url]http://www.pandasoftware.com/products/activescan/com/activescan_principal.htm[/url] | |
Re: Download CWShredder 2 from here: [url]http://www.intermute.com/spysubtract/cwshredder_download.html[/url] Run it and press Fix (not scan) and allow it to clean the infection. Close all windows, other then CWShredder, before hitting the Fix button. You need to move hijackthis into it's own permanent folder; to do this, right-click on an empty area of … | |
Re: That is a good read Caperjack, but it doesn't include Nod32 ([url]http://www.nod32.com/home/home.htm[/url]) which consistantly outperforms the others when compared. Here are a few antivirus discussions here at DaniWeb: [url]http://www.daniweb.com/techtalkforums/thread19504.html[/url] [url]http://www.daniweb.com/techtalkforums/thread12883.html[/url] [url]http://www.daniweb.com/techtalkforums/thread3330.html[/url] | |
Re: Have you installed any new hardware recently? | |
Re: First of all, make sure the system is capable of running XP. Microsoft says the minimum requiremtents are a 233Mhz CPU and 64Mb of RAM, but for a system you can actually [I]use[/I], you should have a 300Mhz CPU and 128Mb of RAM. Next, you need to go into your … |
The End.