1,661 Posted Topics

Member Avatar for zeroth

Multiple instances of scvhost.exe running is normal and does not indicate a problem :)

Member Avatar for dlh6213
0
204
Member Avatar for Jessykah

I agree with Janine, your log looks clean to me too, but as long as you have HijackThis in a temporary folder, you risk accidently deleting it. Please follow the recommendations in the links below to help protect, keep your PC clean, and tips on HijackThis use (including a safe …

Member Avatar for JANINE
0
107
Member Avatar for joey51685

Hi Joey, welcome to DaniWeb :D I only see a couple of minor problems in your log; please review this thread for a proper location for HijackThis: [url]http://www.daniweb.com/techtalkforums/thread28196.html[/url] While you're there, check out the instructions for [B](no name)[/B]/[B](no file)[/B] and O16 entries. When you're done, reboot, [B]close any open browser …

Member Avatar for dlh6213
0
71
Member Avatar for tayspen

What was the problem? Your solution may help someone else with a similar problem :)

Member Avatar for dlh6213
0
397
Member Avatar for Musclesweet

Hi Musclesweet, welcome to DaniWeb :D You have quite a bit to cleanup there, but before you start you should take a look at this thread: [url]http://www.daniweb.com/techtalkforums/thread24085.html[/url] After you've moved hijackthis, please post a new log.

Member Avatar for dlh6213
0
226
Member Avatar for red_chikita

Hi Red_chikita, welcome to DaniWeb :D To resolve your problem you should start a new thread in the [B]Virus[/B] forum ([url]http://www.daniweb.com/techtalkforums/forum64.html[/url]) [I]after[/I] you've followed the advice in the 'pinned' topics at the beginning of the forum (also in the links below). Happy computing!

Member Avatar for dlh6213
0
105
Member Avatar for jonty1975

I don't see anything in your log that would indicate a problem. The first thing I would check for is a loose connection inside the case (be sure to gaurd against damage via static electricity). If this doesn't fix the problem, you should post your question in the [B]Hardware[/B] forum …

Member Avatar for dlh6213
0
119
Member Avatar for violation21

Hi Violation, welcome to DaniWeb :D Please follow the suggestions and instructions in the links below to help prevent reinfections, start the cleanup process, and to find out a bit about HijackThis. When you've completed all that, and got SP1 (or SP1a) for XP and IE, please post a new …

Member Avatar for dlh6213
0
96
Member Avatar for traceur

Hi Traceur, welcome to DaniWeb :D Please follow the suggestions and instructions in the links below to help prevent reinfections, start the cleanup process, and to find out a bit about HijackThis (like putting it in its own permanent folder). When you've completed all that, and moved HJT, please post …

Member Avatar for dlh6213
0
143
Member Avatar for traceyp28

[QUOTE=traceyp28]Sorry, guys. I just read the basic cleanup thread. I'll do a little work on my own and post a new log.[/QUOTE] Hi Tracey, welcome to DaniWeb :D You can still do that, but this should cover most of what you need to do. Go to Add/Remove programs in your …

Member Avatar for dlh6213
0
189
Member Avatar for tsmai

Please follow the suggestions and recommendations in the links below. When you have finished, please post a HijackThis log here in this thread.

Member Avatar for dlh6213
0
103
Member Avatar for Destiny14424

Hi Destiny, welcome to DaniWeb :D If you're still having problems with this, please follow the suggestions and instructions in the links below. If you need additional help after that, please start a new thread in the Virus forum.

Member Avatar for dlh6213
0
235
Member Avatar for dasd

I have yet to locate an affordable data recovery service. As long as you can access the drive, this utility should work. Keep in mind some of the files may have become corrupted: [url]http://www.snapfiles.com/get/restoration.html[/url] If it's critical data, you may need to spend the couple thousand to get it back.

Member Avatar for arcanum
0
578
Member Avatar for rajes_hk

Hi Rajes_hk, welcome to DaniWeb :D Please post your question in the VB forum: [url]http://www.daniweb.com/techtalkforums/forum4.html[/url]

Member Avatar for dlh6213
0
62
Member Avatar for johnhofmann

Hi Johnhofmann, welcome to DaniWeb :D It sounds as if you should start of in the Web Design forum to me: [url]http://www.daniweb.com/techtalkforums/forum15.html[/url] Good luck!

Member Avatar for dlh6213
0
87
Member Avatar for glassdanse

Hi Glassdanse, welcome to DaniWeb :D Please follow the suggestions and instructions in the links below to help prevent reinfections, start the cleanup process, and to fix a few of the HijackThis entries yourself. After you've finished with the part about HijackThis, follow the instructions in post #7 (LOP removal). …

Member Avatar for dlh6213
0
197
Member Avatar for Seizurebear

Hi SeizureBear, welcome to DaniWeb :D Please follow the suggestions and instructions in the links below to help prevent reinfections, start the cleanup process, and to find out a bit about HijackThis. When you get to the third one, go to post #6 to resolve most of your problems. After …

Member Avatar for Seizurebear
0
223
Member Avatar for WldBilHickok

Hi Wild Bill, welcome to DaniWeb :D Please follow the recommendations and instructions in the links below. When you get to the end of the third one (Infection removal), go to post #5 and follow the instructions there [I]carefully[/I]. When you've finished, please post a new HijackThis log along with …

Member Avatar for dlh6213
0
310
Member Avatar for tayspen

I believe this is a part of, or related to, CoolWebSearch (CWS), which can add addresses to the HOSTS file, redirect search and start page settings, and may put the hijacker's web site in your browsers Trusted zone. Please follow the recommendations and instructions in the links below to help …

Member Avatar for DMR
0
205
Member Avatar for sweet_jam_in

Try this patch from MS: [url]http://www.microsoft.com/windows98/downloads/contents/WURecommended/S_WUFeatured/Win98SE/Default.asp[/url]

Member Avatar for dlh6213
0
218
Member Avatar for noexpert

Hi NoExpert, welcome to DaniWeb :D Please follow the suggestions and instructions in the links below to help prevent reinfections, start the cleanup process, and to find out a bit about HijackThis (like putting it in its own permanent folder). After you've finished the first post (about HijackThis), see post …

Member Avatar for dlh6213
0
274
Member Avatar for bubba

Hi Bubba, welcome to DaniWeb :D Please follow the recommendations in these threads to help protect, and start the cleanup process, of your system: [url]http://www.daniweb.com/techtalkforums/thread27519.html[/url] [url]http://www.daniweb.com/techtalkforums/thread27570.html[/url] Download, install, update, and run these utilities: [B]CWShredder[/B] -- [url]http://www.intermute.com/spysubtract/cwshredder_download.html[/url] [B]about:Buster[/B] -- [url]http://www.majorgeeks.com/download4289.html[/url] [B]HSRemove[/B] -- [url]http://www.majorgeeks.com/download4286.html[/url] After you've completed that, get the self-extracting version …

Member Avatar for dlh6213
0
1K
Member Avatar for robinen

Hi Robin, welcome to DaniWeb :D Are you using Outlook or Outlook Express? What browser are you using? If it's IE, see if any of the suggestions here work: [url]http://www.outlooknewsgroups.net/group/microsoft.public.outlook/topic1261.aspx[/url] If it's Firefox, try this: [url]http://www.slipstick.com/problems/firefox.htm[/url]

Member Avatar for dlh6213
0
245
Member Avatar for NormalGirl

Hi NormalGirl, welcome to DaniWeb :D I can offer a couple of suggestions, but I first need to know what operating system you're using.

Member Avatar for dlh6213
0
196
Member Avatar for Michael McNamar

Hi Michael, welcome to DaniWeb :D First, right-click in an open area of your desktop and select [B]New[/B], [B]Folder[/B]; give the new folder a name (such as HJT or HijackThis), and then drag the hijackthis.exe icon that is on your desktop into the new folder. Now, scan with HijackThis and …

Member Avatar for dlh6213
0
192
Member Avatar for Xyzyxx

It's very likely that your problem is caused by some form of malware and it's not recommended to get SP2 on an infected machine. Follow the recommendations and instructions in the links below, and then post a HijackThis log in the [B]Virus[/B] forum (not in this thread) to establish whether …

Member Avatar for dlh6213
0
157
Member Avatar for Jonathin Smith

Hi Jon, welcome to DaniWeb :D I could be overlooking something, but I don't see anything wrong in your HijackThis log. Have you recently installed a firewall? Did you get SP2 around the time the problem started? What browser are you using?

Member Avatar for dlh6213
0
153
Member Avatar for josephpafume

Hi Joseph, I've split your post into its own thread per forum rules ([url]http://www.daniweb.com/techtalkforums/faq.php?faq=daniweb_faq#faq_rules[/url]) Try these suggestions: IEFix -- [url]http://windowsxp.mvps.org/IEFIX.htm[/url] Winsockfix -- [url]http://www.softpedia.com/get/Tweak/Network-Tweak/WinSockFix.shtml[/url] Have you checked your firewall settings to see if anything there could be blocking some sites? You can also try another browser to help determine if the …

Member Avatar for dlh6213
0
88
Member Avatar for ElGringo

Hi ElGringo, welcome to DaniWeb :D Congratulations on getting your system functioning properly again! It is often recommended to disconnect from the net and boot into Safe Mode when removing malware, though actually removing the NIC card is unnecessary. Go ahead and post your HijackThis log and we'll have a …

Member Avatar for dlh6213
0
214
Member Avatar for xrayeyes2u

Hi Georgia, Please move HijackThis to its own permanent folder as shown in any of the 'good' examples below -- C:\ Documents and Settings \me\Local Settings\Temp\HijackThis.exe <-- Bad, HJT in Temp folder C:\HIJACKTHIS.EXE <-- Bad, HJT running directly from hard drive C:\Documents and Settings\User\Desktop\HijackThis.exe <-- Bad, HJT running directly from …

Member Avatar for dlh6213
0
127
Member Avatar for dano69

Hi Dano69, welcome to DaniWeb :D Please follow the recommendations and instructions in the links below. Then go to post #6 in the last one (Infection removal...). In addition to the instructions in those posts, when you next scan with HijackThis, have it fix these entries: R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search …

Member Avatar for dlh6213
0
334
Member Avatar for tinacolo1717

Hi Tina, welcome to DaniWeb :D Please follow the suggestions in these threads (in sequence): [url]http://www.daniweb.com/techtalkforums/thread27519.html[/url] [url]http://www.daniweb.com/techtalkforums/thread27570.html[/url] [url]http://www.daniweb.com/techtalkforums/thread28196.html[/url] When you scan with HijackThis, have it fix the following (in addition to what was in the previous thread): All of the R1 and R0 entries [B]except[/B]: R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page …

Member Avatar for dlh6213
0
272
Member Avatar for nettizen

Follow the instructions in the 'Cleanup' link below. A HijackThis log would be helpful ;).

Member Avatar for dlh6213
0
160
Member Avatar for Kamex

I put both IE and Firefox on my son's computer and he usually uses Firefox, but he says there are some sites he can't access with it so he still needs to use IE.

Member Avatar for Sparkplug188
0
446
Member Avatar for zion1

Hi Zion1, welcome to DaniWeb :D Download [b]Ewido Security Suite[/b] from here: [url="http://fileforum.betanews.com/detail/ewido_security_suite/1098736486/1"]http://fileforum.betanews.com/detail/ewido_security_suite/1098736486/1[/url] Install and update it, and then [u]close the program (don't scan yet)[/u]. Reboot into Safe Mode. Run a full system scan with Ewido, allowing it to fix whatever it finds (note: you will be posting the log …

Member Avatar for DMR
0
145
Member Avatar for mookie5381

Hi Michael, welcome to DaniWeb :D Please follow the recommendations and instructions in the links below. When you've finished, and have HijackThis in a permanent folder, please post a new log.

Member Avatar for dlh6213
0
375
Member Avatar for dcc

For future reference, have a look at this thread: [url]http://www.daniweb.com/techtalkforums/showthread.php?t=16365&highlight=christmas+crackers[/url] For now, please follow the recommendations and instructions in the links below, and then post a HijackThis log in this thread so we can see what's going on.

Member Avatar for dlh6213
0
341
Member Avatar for cajunsunshine

It sounds like your browser has been hijacked; get Hijackthis from here: [url]http://www.merijn.org/files/hijackthis_sfx.exe[/url] Close all browser windows, scan with hijackthis, save the log, copy and paste it here in this thread.

Member Avatar for damjan_hr
0
397
Member Avatar for quiksilvr101

Hi quicksilvr, welcome to DaniWeb :D I've split your post into it's own thread (per forum rules -- <a href="http://www.daniweb.com/techtalkforums/faq.php?faq=daniweb_faq#faq_rules" rel="nofollow">http://www.daniweb.com/techtalkforums/faq.php?faq=daniweb_faq#faq_rules</a> ) Please review this thread and then post a new log:

Member Avatar for RickW
0
287
Member Avatar for STRAWB2

Welcome to DaniWeb, STRAWB2 :) It's not real clear what you're saying about System Restore there; are you able to use it to set your system back to a date before you started having problems? Also, can you give us some more information, like your operating system, browser, etc.?

Member Avatar for DMR
0
128
Member Avatar for Athersgeo

Well, I don't see any signs of Aurora/Nail in your log :). Did you look through that Ewido log? It looks like you had a lot more going on then you thought! (Probably from using file sharing programs.) Before continuing, you should also follow the recommendations in the Protection and …

Member Avatar for DMR
0
230
Member Avatar for hbadger30

Do you use any file-sharing programs? That's the most common way for this particular infection to spread. Open Firefox and go to [b]Tools[/b], [b]Options[/b], and then click on [b]Privacy[/b] (padlock icon on the left); click on the [b]Clear All[/b] button. Download, install, update, and run the following utilities: [b]CounterSpy[/b] – …

Member Avatar for dlh6213
0
507
Member Avatar for clagoo

Hi Clagoo, welcome to DaniWeb :D I've split your post (from [url]http://www.daniweb.com/techtalkforums/thread28035.html[/url]) into its own thread per forum rules -- [url]http://www.daniweb.com/techtalkforums/faq.php?faq=daniweb_faq#faq_rules[/url] Please follow the recommendations and instructions in the three links from my signature below. Then, when you have HJT in its own permanent folder, please post a new log. …

Member Avatar for clagoo
0
182
Member Avatar for yaduks

Hi yaduks, welcome to DaniWeb :D I believe [B]GGLIB.EXE[/B] is adware; McAfee should be able to clean up [B]QLowZones-15[/B], are you sure it's up to date? Please follow the recommendations and instructions in the links below, and then post your HijackThis log in this thread.

Member Avatar for dlh6213
0
111
Member Avatar for dedBOYriot

Hi DedBOYriot, welcome to DaniWeb :) Do a search on your computer for MSDIRECTX and give us the location(s) and complete file name(s) if any instances are found. You can also try this... Download and install CleanUp! -- [url]http://www.stevengould.org/downloads/cleanup/CleanUp40.exe[/url] -- but don't run it yet. Reboot into Safe Mode. Open …

Member Avatar for dlh6213
0
224
Member Avatar for akdraw

Hi Akdraw, welcome to DaniWeb :D Please follow the recommendations and instructions in the links below. When you get to the end of the third one (Infection removal), go to post #4 and complete the instructions there. When you've finished, please post a new HijackThis log so we can clean …

Member Avatar for crunchie
0
371
Member Avatar for heho

Hi-ho Heho, welcome to DaniWeb :D Did you try Winsock[B]XP[/B]Fix? [url="http://www.stevewolfonline.com/Downloads/DMR/Spyware%20Tools/WinsockXPFix/WinsockXPFix.exe"]WinsockXPFix[/url] Run it, and click the [B]Fix[/B] button; choose [B]YES[/B] when asked if you want to proceed. If it still doesn't work, try IEFix -- [url]http://windowsxp.mvps.org/IEFIX.htm[/url]

Member Avatar for dlh6213
0
185
Member Avatar for Hagar

Hi Hagar, welcome to DaniWeb :D I've moved your thread to the Virus forum as I feel this is a more appropriate place for it. I suggest you first use System Restore to return your system to a time [I]before[/I] you deleted the file you seem to be having trouble …

Member Avatar for dlh6213
0
193
Member Avatar for Crevin

Hi Crevin, welcome to DaniWeb :D Please follow the recommendations and instructions in the links below. This will: 1.) Prevent reinfections during and after the cleanup process; 2.) Remove some of your infections automatically, and; 3.) Clean up your log a bit so it's not so intimidating :) Post a …

Member Avatar for dlh6213
0
93
Member Avatar for tori96

The End.