4,383 Posted Topics

Member Avatar for Trinexus

Hi and welcome to Daniweb forums :). [b]Download [color=blue]HijackThis[/color] from [url=http://majorgeeks.com/download.php?det=5554][u]here.[/u][/url][/b] Download it to your desktop and NOT a temporary folder. == Please [u]download[/u] [b]ComboFix[/b] by sUBs from [url=snip][color=red][b]HERE[/b][/color][/url] or [url=snip][color=red][b]HERE[/b][/color][/url][list] [*] [color=blue][b]You must [u]download it to and run it from[/u] your Desktop[/b][/color] [*]Physically disconnect from the internet. [*] Now …

Member Avatar for crunchie
0
180
Member Avatar for Hawk92

Hi and welcome to Daniweb forums :). Can you please do the following. Download the newest version of [HiJackThis](http://majorgeeks.com/download.php?det=5554); version 2.0.2. Place it in a permanent folder before scanning. Repost your log after following the steps below. This version has features that might be more helpful in 'cleaning' up your …

Member Avatar for crunchie
0
235
Member Avatar for HuevoPicante

Hi and welcome to Daniweb forums :). Please download the latest version of hijackthis; [url]http://www.daniweb.com/forums/thread83821.html[/url] == Please [u]download[/u] [b]ComboFix[/b] by sUBs from [url=http://download.bleepingcomputer.com/sUBs/ComboFix.exe][color=red][b]HERE[/b][/color][/url] or [url="http://subs.geekstogo.com//ComboFix.exe"][color=red][b]HERE[/b][/color][/url][list] [*] [b]Save it to your Desktop[/b] [*]Physically disconnect from the internet. [*] Now [b]STOP all your monitoring programs[/b] (Antivirus/Antispyware, Guards and Shields) [*] Click on …

Member Avatar for crunchie
0
474
Member Avatar for yaduks

Hi Soleil.Lune. First of all- welcome to Daniweb :). We ask that members not piggy-back questions on to a thread previously started by another member here in the Viruses, Spyware & other Nasties forum, (regardless of how similar your problem might seem). Not only does it divert the focus of …

Member Avatar for crunchie
0
156
Member Avatar for xAqua

Hi and welcome to Daniweb forums :). Please right click on hijackthis.exe and rename it to analysethis and post another log.

Member Avatar for crunchie
0
103
Member Avatar for mason321
Member Avatar for crunchie
0
66
Member Avatar for avanwinkle

Hi and welcome to Daniweb forums :). [b]Download [color=blue]HijackThis[/color] from [url=http://majorgeeks.com/download.php?det=5554][u]here.[/u][/url][/b] Download it to your desktop and NOT a temporary folder. Start HJT & press the "Do a system scan and save a log file" button. When the scan is finished a window will pop up giving you the option …

Member Avatar for crunchie
0
103
Member Avatar for nanosani

Caperjack. If you're on Broadband, try this; 1.Type "about:config" into the address bar of Firefox and hit return. Scroll down and look for the following entries: network.http.pipelining network.http.proxy.pipelining network.http.pipelining.maxrequests 2. Alter the entries as follows: Set "network.http.pipelining" to "true" Set "network.http.proxy.pipelining" to "true" Set "network.http.pipelining.maxrequests" to some number like 30. …

Member Avatar for forumdude123
-1
466
Member Avatar for rfc9

Hi and welcome to Daniweb :). Can you please do the following. =============== Scan with [b]HijackThis[/b] and then place a check next to all the following, if present: [color=#9933cc][b] R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = [url]http://hsremove.com/done.htm[/url] [/b][/color] [color=#9933cc][b] R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = [url]http://hsremove.com/done.htm[/url] [/b][/color] [color=#9933cc][b] R0 - HKCU\Software\Microsoft\Internet …

Member Avatar for crunchie
0
189
Member Avatar for kellann

[QUOTE=ffrankki;511335]newbie here also. i dont know where can i subscribe to forums, please help me. thanks[/QUOTE] If you go to the "thread tools" button at the top of the thread, you can subscribe from there.

Member Avatar for crunchie
0
74
Member Avatar for gthotmail

Can you also do this; Please go to [url=http://virusscan.jotti.org/][u]Jotti's[/u][/url] or to [url=http://www.virustotal.com/en/virustotalf.html][u]virustotal[/u][/url] and have this file scanned. Post the results back here. C:\WINDOWS\Fonts\syn00-19-D1-87-11-67\system\smss.exe

Member Avatar for Michael York
0
155
Member Avatar for dreamz4u

Try turning the power off at the wall then pull out the round battery on the motherboard. Leave it out for a couple of minutes then place it back in exactly as it came out. Turn the power back on at the wall and boot back into the BIOS by …

Member Avatar for jbennet
0
104
Member Avatar for loyd

Are you able to slave it to a pc and try to right click on the drive and select 'format?'

Member Avatar for Rick150
0
96
Member Avatar for natej

Get Everest free from [url]http://www.majorgeeks.com/download4181.html[/url] it will give a rundown of all your hardware.

Member Avatar for caperjack
0
116
Member Avatar for Lora316K

Hi Lora and welcome to Daniweb forums :). I have to say that I have not seen the about:blank infection for a very long time. When did you acquire it? =========== Can you please do the following. =============== Can you disable [b]Windows Defender[/b] as it may interfere with the removal …

Member Avatar for crunchie
0
154
Member Avatar for betsybailey

Please download [url=http://siri.urz.free.fr/Fix/SmitfraudFix.zip][b][color=red]SmitfraudFix[/color][/b][/url] (by [b]S!Ri[/b]) Extract the content (a folder named [b]SmitfraudFix[/b]) to your Desktop. Open the [b]SmitfraudFix[/b] folder and double-click [b]smitfraudfix.cmd[/b] Select option #1 - [b]Search[/b] by typing [b]1[/b] and press "[b]Enter[/b]"; a text file will appear, which lists infected files (if present). Please copy/paste the content of that …

Member Avatar for Serunson
0
545
Member Avatar for annamarie

I see that you have previously posted your hijackthis logs in the correct forum, but posted this one in the Windows NT / 2000 / XP / 2003 forum. Please read the announcement at the head of the forum. Moving you to the correct forum now. Hold on tight. == …

Member Avatar for crunchie
0
148
Member Avatar for ustian09

Hi and welcome to Daniweb forums :). You will want to update hijackthis first; [url]http://www.daniweb.com/forums/thread83821.html[/url] == You should print out these instructions, or copy them to a NotePad file for reading while in Safe Mode, because you will not be able to connect to the Internet to read from this …

Member Avatar for crunchie
0
87
Member Avatar for rabbott

Please [u]download[/u] [b]ComboFix[/b] by sUBs from [url=http://download.bleepingcomputer.com/sUBs/ComboFix.exe][color=red][b]HERE[/b][/color][/url] or [url="http://subs.geekstogo.com/ComboFix.exe"][color=red][b]HERE[/b][/color][/url][list] [*] [color=blue][b]You must [u]download it to and run it from[/u] your Desktop[/b][/color] [*]Physically disconnect from the internet. [*] Now [b]STOP all your monitoring programs[/b] (Antivirus/Antispyware, Guards and Shields) as they could easily interfere with ComboFix. [*] Double click combofix.exe & follow …

Member Avatar for crunchie
0
301
Member Avatar for moncdawg

Download the [url=http://www.funkytoad.com/content/view/13/31/][color=blue]HostsXpert.[/color][/url] Run it and press "Restore Original Hosts" and press "OK". Exit Program. Note that if you have a custom host file, this will remove it. == [b]Download [color=blue]HijackThis[/color] from [url=http://majorgeeks.com/download.php?det=5554][u]here.[/u][/url][/b] Download it to your desktop and NOT a temporary folder. Start HJT & press the "Do a …

Member Avatar for crunchie
0
101
Member Avatar for Lora316K

[color=blue][b]Download and Run ATF Cleaner[/b][/color] Download [URL=http://www.atribune.org/ccount/click.php?id=1]ATF (Atribune Temp File) Cleaner© by Atribune[/URL] to your desktop. Double-click [b]ATF Cleaner.exe[/b] to open it. Under [b]Main[/b] choose: [b]Windows Temp Current User Temp All Users Temp Cookies Temporary Internet Files Prefetch Java Cache[/b] *The other boxes are optional* Then click the [b]Empty Selected[/b] …

Member Avatar for crunchie
0
149
Member Avatar for Garet-Jax

I hope you are going to respond this time :)? [url]http://www.daniweb.com/forums/thread8806.html[/url] Please [u]download[/u] [b]ComboFix[/b] by sUBs from [url=http://download.bleepingcomputer.com/sUBs/ComboFix.exe][color=red][b]HERE[/b][/color][/url] or [url="http://subs.geekstogo.com/ComboFix.exe"][color=red][b]HERE[/b][/color][/url][list] [*] [color=blue][b]You must [u]download it to and run it from[/u] your Desktop[/b][/color] [*]Physically disconnect from the internet. [*] Now [b]STOP all your monitoring programs[/b] (Antivirus/Antispyware, Guards and Shields) as they …

Member Avatar for crunchie
0
163
Member Avatar for rlabonte

Hi and welcome to Daniweb :). Can you please do the following. =============== Scan with [b]HijackThis[/b] and then place a check next to all the following, if present: [color=#9933cc][b] R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = [url]http://red.clientapps.yahoo.com/customi[/url] ... earch.html [/b][/color] [color=#9933cc][b] R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = [url]http://red.clientapps.yahoo.com/customi[/url] ... .yahoo.com [/b][/color] …

Member Avatar for crunchie
0
145
Member Avatar for Aj_old

Hi and welcome to Daniweb forums :). [b]Download [color=blue]HijackThis[/color] from [url=http://majorgeeks.com/download.php?det=5554][u]here.[/u][/url][/b] Download it to your desktop and NOT a temporary folder. == Please [u]download[/u] [b]ComboFix[/b] by sUBs from [url=http://download.bleepingcomputer.com/sUBs/ComboFix.exe][color=red][b]HERE[/b][/color][/url] or [url="http://subs.geekstogo.com//ComboFix.exe"][color=red][b]HERE[/b][/color][/url][list] [*] [b]Save it to your Desktop[/b] [*]Physically disconnect from the internet. [*] Now [b]STOP all your monitoring programs[/b] (Antivirus/Antispyware, …

Member Avatar for crunchie
0
146
Member Avatar for icluniex

Hi and welcome to Daniweb forums :) You have omitted half of the hijackthis log. If you are not sure exactly what a full log entails, take a look at some other threads in this forum :). == Please [u]download[/u] [b]ComboFix[/b] by sUBs from [url=http://download.bleepingcomputer.com/sUBs/ComboFix.exe][color=red][b]HERE[/b][/color][/url] or [url="http://subs.geekstogo.com/ComboFix.exe"][color=red][b]HERE[/b][/color][/url][list] [*] [color=blue][b]You must …

Member Avatar for crunchie
0
192
Member Avatar for irie18806

Please [u]download[/u] [b]ComboFix[/b] by sUBs from [url=http://download.bleepingcomputer.com/sUBs/ComboFix.exe][color=red][b]HERE[/b][/color][/url] or [url="http://subs.geekstogo.com/ComboFix.exe"][color=red][b]HERE[/b][/color][/url][list] [*] [color=blue][b]You must [u]download it to and run it from[/u] your Desktop[/b][/color] [*]Physically disconnect from the internet. [*] Now [b]STOP all your monitoring programs[/b] (Antivirus/Antispyware, Guards and Shields) as they could easily interfere with ComboFix. [*] Double click combofix.exe & follow …

Member Avatar for crunchie
0
178
Member Avatar for tb01

Yep, name has changed. Here is a link to the classroom if you have access to the private forum; [url]http://forums.whatthetech.com/Malware_Classroom_f48.html[/url]

Member Avatar for tb01
0
69
Member Avatar for Dani

Your log looks clear :). nicentral's idea is probably the way to go. Should be able to track the program that is causing it that way.

Member Avatar for crunchie
0
183
Member Avatar for shukimann

Hi and welcome to Daniweb :). Can you please do the following. =============== Scan with [b]HijackThis[/b] and then place a check next to all the following, if present: [color=#9933cc][b] O2 - BHO: (no name) - {54B02808-B60E-44CD-A72D-9865117E4E62} - (no file) [/b][/color] [color=#9933cc][b] O4 - HKCU\..\Run: [drvsyskit] C:\WINDOWS\system32\drivers\hldrrr.exe [/b][/color] [color=#9933cc][b] O4 - …

Member Avatar for crunchie
0
163
Member Avatar for whoost

Try a system repair. Go into the bios and set it to boot from CD. Insert the XP CD and reboot. Choose the repair option when presented. Nothing will be lost, but you will need to reinstall security patches/service packs etc.

Member Avatar for caperjack
0
175
Member Avatar for artemis7

Hi and welcome to Daniweb forums :). Can you please do the following. =============== Download the newest version of [url=http://majorgeeks.com/download.php?det=5554]HiJackThis[/url]; [i]version 2.0.2[/i]. Place it in a permanent folder before scanning. Repost your log after following the steps below. [color=#ff0000][i]This version has features that might be more helpful in 'cleaning' up …

Member Avatar for crunchie
0
623
Member Avatar for csxfire

You have two anti virus programs running. Choose which one you want and uninstall the other. == Please go to [url=http://virusscan.jotti.org/][u]Jotti's[/u][/url] or to [url=http://www.virustotal.com/en/virustotalf.html][u]virustotal[/u][/url] and have these files scanned. Post the results back here. C:\Documents and Settings\John\wn852.exe C:\WINDOWS\system32\drivers\secdrv.sys == Scan with [b]HijackThis[/b] and then place a check next to all …

Member Avatar for crunchie
0
272
Member Avatar for RobertDeCosmo

Download and run Winsockfix from here [url]http://www.softpedia.com/get/Tweak/Network-Tweak/WinSockFix.shtml[/url] == Can you please do the following. =============== Scan with [b]HijackThis[/b] and then place a check next to all the following, if present: [color=#9933cc][b] O3 - Toolbar: (no name) - {F8AD5AA5-D966-4667-9DAF-2561D68B2012} - (no file) [/b][/color] [color=#9933cc][b] O9 - Extra button: Microsoft AntiSpyware helper …

Member Avatar for crunchie
0
261
Member Avatar for flyingjoe

Can you please do the following. =============== Can you disable [b]Windows Defender[/b] as it may interfere with the removal process. Please leave it disabled until your PC has been given the all clear. [LIST] [*]Open [b]Windows Defender[/b] [*]Click [b]Tools[/b] [*]Click [b]General Settings[/b] [*]Scroll down to [b]Real Time Protection Options[/b] [*]Uncheck …

Member Avatar for flyingjoe
0
75
Member Avatar for adubzz

Hi adubzz. First of all- welcome to Daniweb :). We ask that members not piggy-back questions on to a thread previously started by another member here in the Viruses, Spyware & other Nasties forum, (regardless of how similar your problem might seem). Not only does it divert the focus of …

Member Avatar for Comodore
0
181
Member Avatar for Comodore

[QUOTE=Comodore;503667]Don't run two antivirus programs at the same time! (I wish you could but it's a bad idea). They'll conflict with eachother (espeically the active protection), each will think parts of the other to be viruses, and just general bad things can happen. It can lead to system lockups and …

Member Avatar for gerbil
0
436
Member Avatar for beebee

Hi tayebwatom. First of all- welcome to Daniweb :). We ask that members not piggy-back questions on to a thread previously started by another member here in the Viruses, Spyware & other Nasties forum, (regardless of how similar your problem might seem). Not only does it divert the focus of …

Member Avatar for crunchie
0
267
Member Avatar for JudBuz

JudBuz. You still have multiple hijackthis entries that require fixing and possibly some entries found in the combofix log (I didn't look :)), so please wait for Gerbil to reply and finish the cleaning up :).

Member Avatar for JudBuz
0
266
Member Avatar for yair7190

Hi and welcome to Daniweb forums :). Can you please do the following. =============== Scan with [b]HijackThis[/b] and then place a check next to all the following, if present: [color=#9933cc][b] O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (file missing) [/b][/color] [color=#9933cc][b] O2 - BHO: OGG Viewer …

Member Avatar for aikibro
0
171
Member Avatar for Buxtreme

Complete system specs would be good to have, eg; Which mobo, cpu, Ram etc. Usually, cards that require extra power are fitted with a plug where one can connect a supply from the psu. If you are overclocking the card, that also will require more power. That can sometimes be …

Member Avatar for Buxtreme
0
47
Member Avatar for wakOrang3

bisayaOnline. Hi and welcome to the Daniweb forums :). It is good to have you here.

Member Avatar for technogeek_42
0
226
Member Avatar for WatermelonX

[QUOTE=Comodore;502783]:p Try posting it in the Hijack This forum for a faster response maybe? You should still probably run a few of the scans, at least, that I recommended. Good luck, --The Comodore[/QUOTE] This [i]is[/i] the hijackthis forum :). == Can you please do the following. =============== Download the newest …

Member Avatar for crunchie
0
153
Member Avatar for brainchief

[IMG]http://computercops.biz/themes/Cops_1024/images/header/headertop.gif[/IMG]

Member Avatar for MidiMagic
0
723
Member Avatar for crunchie

Has anything changed on the site over the last 8 hours or so? 6pm GMT +9 atm. I just upgraded to Opera 9.25 from Opera 9.2 and now every page here shows all the html code at the top and I have to scroll for ages to get to the …

Member Avatar for MidiMagic
0
189
Member Avatar for marshal23

[list] [*] [b]Save it to your Desktop[/b] [*]Physically disconnect from the internet. [*] Now [b]STOP all your monitoring programs[/b] (Antivirus/Antispyware, Guards and Shields) [*] Click on your [b]START[/b] button and choose [b]Run[/b]. Then [b]copy/paste[/b] the entire content of the following quotebox (Including the [b]""[/b] marks and the Symbols) into the …

Member Avatar for crunchie
0
139
Member Avatar for momtworugrats

If you have uninstalled Symantec, do the following and the 023 entry should go; Copy and paste the following bold blue text in the Quote box below into Notepad. Click on File(in the menu at the top)>Save as../Save as Type: 'All Files' /File name: [b]fix.bat[/b] to your desktop. Then double …

Member Avatar for crunchie
0
192
Member Avatar for StAttitude

Hi and welcome to Daniweb forums :). Can you please do the following. =============== Go to [b]Add/Remove programs[/b] and uninstall the following, if present: [b][color=#ff0000]MyWebSearch[/color][/b] [b][color=#ff0000]Viewpoint Manager[/color][/b] The above could appear anywhere within the entry. Be careful not to remove any [i]personal[/i] or [i]system[/i] software. =============== Next, Open a [b]command …

Member Avatar for crunchie
0
121
Member Avatar for poprockdudette

Hi and welcome to Daniweb forums :) [list] [*] [b]Save it to your Desktop[/b] [*] Now [b]STOP all your monitoring programs[/b] (Antivirus/Antispyware, Guards and Shields) [*] Click on your [b]START[/b] button and choose [b]Run[/b]. Then [b]copy/paste[/b] the entire content of the following quotebox (Including the [b]""[/b] marks and the Symbols) …

Member Avatar for crunchie
0
217
Member Avatar for Jishnu
Member Avatar for Micko

The Hosts file is on your pc. It has no file extension. Can be found (on XP) here; C:\WINDOWS\system32\drivers\etc\[b]HOSTS[/b]

Member Avatar for DimaYasny
0
149

The End.