4,383 Posted Topics

Member Avatar for gviswa18

I have moved your posts to your own thread. Please do not piggy back other members posts in the hijackthis forum :).

Member Avatar for crunchie
0
104
Member Avatar for Timmy4383

Hi and welcome to Daniweb forums :). == How many times have you run Combofix and do you have a log from it? Note that Combofix should NOT be run on a machine without being given a directive from someone familiar in it's use. == Can you please do the …

Member Avatar for crunchie
0
143
Member Avatar for I-Gotta-Know

If all you guys started your own thread rather than dredge up a 3+ year thread, I am sure you would get the assistance you seek :D.

Member Avatar for crunchie
0
365
Member Avatar for clymer

Please go to [url=http://virusscan.jotti.org/][u]Jotti's[/u][/url] or to [url=http://www.virustotal.com/en/virustotalf.html][u]virustotal[/u][/url] and have these files scanned. Post the results back here. C:\WINDOWS\system32\5C62B2BE12.sys C:\WINDOWS\system32\KGyGaAvL.sys == You should print out these instructions, or copy them to a Notepad file for reading while in Safe Mode, because you will not be able to connect to the Internet …

Member Avatar for crunchie
0
102
Member Avatar for jd51edwin

Can you please do the following. =============== Scan with [b]HijackThis[/b] and then place a check next to all the following, if present: [color=#9933cc][b] R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank [/b][/color] [color=#9933cc][b] O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F99} - [url]http://www.miniclip.com/puzzlepirate...GameLoader.dll[/url] [/b][/color] Now, close [b]all[/b] instances of Internet Explorer and any other windows …

Member Avatar for crunchie
0
131
Member Avatar for Craig_Guthrie

[b]Download LSPfix from [url=http://www.computercops.biz/downloads-file-334.html][u]here[/u][/url][/b] On the opening screen, click the "I know what I'm doing" checkbox, then click Finish. == Download the [url=http://www.funkytoad.com/content/view/13/31/][color=blue]HostsXpert.[/color][/url] Run it and press "Restore Original Hosts" and press "OK". Exit Program. Note that if you have a custom host file, this will remove it. == [b]Download …

Member Avatar for Yong7811
0
392
Member Avatar for Silentluna8

Hi and welcome to Daniweb forums :). Let's see what we can come up with. Please [b]download[/b] this file - [url=http://download.bleepingcomputer.com/sUBs/Beta/ComboFix.exe][color=red][b]combofix.exe[/b][/color][/url] by [b]sUBs[/b][list] [*] [b][color="#FF0000"]Save it to your Desktop[/color][/b] [*] Now [b]physically disconnect from the internet[/b] and [b]STOP all your monitoring programs[/b] (Antivirus/Antispyware, Guards and Shields) [*] Click on your …

Member Avatar for crunchie
0
548
Member Avatar for 73firebird

Download this file from one of the following links : [url]http://download.bleepingcomputer.com/sUBs/ComboFix.exe[/url] [url]http://www.techsupportforum.com/sectools/combofix.exe[/url] 1.[b][color=red] Make sure that Combofix is downloaded to and run from, your desktop.[/color][/b] 2. Double click combofix.exe & follow the prompts. 3. When finished, ComboFix generates a pop up log which can also be found at [b]C:\ComboFix.txt.[/b] Post …

Member Avatar for crunchie
0
156
Member Avatar for snefmoo

Can you please do the following. =============== Download the newest version of [url=http://majorgeeks.com/download.php?det=5554]HiJackThis[/url]; [i]version 2.0.2[/i]. Place it in a permanent folder before scanning. Repost your log after following the steps below. [color=#ff0000][i]This version has features that might be more helpful in 'cleaning' up your system[/i][/color]. =============== Scan with [b]HijackThis[/b] and …

Member Avatar for crunchie
0
121
Member Avatar for George.Storm

Hi and welcome to Daniweb forums :). Can you please do the following. =============== Download the newest version of [url=http://majorgeeks.com/download.php?det=5554]HiJackThis[/url]; [i]version 2.0.2[/i]. Place it in a permanent folder before scanning. Repost your log after following the steps below. [color=#ff0000][i]This version has features that might be more helpful in 'cleaning' up …

Member Avatar for thicknsane
0
278
Member Avatar for ImBoReD2

Hi and welcome to Daniweb forums :). Please [b]download[/b] this file - [url=http://download.bleepingcomputer.com/sUBs/Beta/ComboFix.exe][color=red][b]combofix.exe[/b][/color][/url] by [b]sUBs[/b][list] [*] [b][color="#FF0000"]Save it to your Desktop[/color][/b] [*] Now [b]physically disconnect from the internet[/b] and [b]STOP all your monitoring programs[/b] (Antivirus/Antispyware, Guards and Shields) [*] Click on your [b]START[/b] button and choose [b]Run[/b]. Then [b]copy/paste[/b] the …

Member Avatar for Getwyred
0
98
Member Avatar for Aeonclock

Download [url=http://downloads.andymanchesta.com/RemovalTools/SDFix.zip][b][color=red]SDFix[/b][/color][/url] and save it to your desktop. Please then reboot your computer in [b]Safe Mode[/b] by doing the following :[list] [*]Restart your computer [*]After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually; [*]Instead of Windows loading as normal, a …

Member Avatar for nomee
0
407
Member Avatar for spidey

[b]Download [color=blue]HijackThis[/color] from [url=http://majorgeeks.com/download.php?det=5554][u]here.[/u][/url][/b] Download it to your desktop and NOT a temporary folder. Start HJT & press the "Do a system scan and save a log file" button. When the scan is finished a window will pop up giving you the option of where to save it. Save it …

Member Avatar for jjaydnn
0
131
Member Avatar for kilegoty

Please [b]download[/b] this file - [url=http://download.bleepingcomputer.com/sUBs/Beta/ComboFix.exe][color=red][b]combofix.exe[/b][/color][/url] by [b]sUBs[/b][list] [*] [b][color="#FF0000"]Save it to your Desktop[/color][/b] [*] Now [b]physically disconnect from the internet[/b] and [b]STOP all your monitoring programs[/b] (Antivirus/Antispyware, Guards and Shields) [*] Click on your [b]START[/b] button and choose [b]Run[/b]. Then [b]copy/paste[/b] the entire content of the following quotebox (Including …

Member Avatar for crunchie
0
158
Member Avatar for Kheftiu

Download [url=http://downloads.andymanchesta.com/RemovalTools/SDFix.zip][b][color=red]SDFix[/b][/color][/url] and save it to your desktop. Please then reboot your computer in [b]Safe Mode[/b] by doing the following :[list] [*]Restart your computer [*]After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually; [*]Instead of Windows loading as normal, a …

Member Avatar for crunchie
0
210
Member Avatar for tutonk

Please [b]download[/b] this file - [url=http://download.bleepingcomputer.com/sUBs/Beta/ComboFix.exe][color=red][b]combofix.exe[/b][/color][/url] by [b]sUBs[/b][list] [*] [b][color="#FF0000"]Save it to your Desktop[/color][/b] [*] Now [b]physically disconnect from the internet[/b] and [b]STOP all your monitoring programs[/b] (Antivirus/Antispyware, Guards and Shields) [*] Click on your [b]START[/b] button and choose [b]Run[/b]. Then [b]copy/paste[/b] the entire content of the following quotebox (Including …

Member Avatar for crunchie
0
112
Member Avatar for Aesun

Hi and welcome to Daniweb forums :). Log is clean. Perhaps it is not spyware/malware related?

Member Avatar for crunchie
0
79
Member Avatar for djanit

Download CWShredder from [url]http://209.133.47.200/~merijn/files/CWShredder.exe[/url] & run it. Select the fix button & it will get rid of everything related to CoolWebSearch. Reboot after doing this & post another log please.

Member Avatar for crunchie
0
894
Member Avatar for fustrateduser

Please [b]download[/b] this file - [url=http://download.bleepingcomputer.com/sUBs/Beta/ComboFix.exe][color=red][b]combofix.exe[/b][/color][/url] by [b]sUBs[/b][list] [*] [b][color="#FF0000"]Save it to your Desktop[/color][/b] [*] Now [b]physically disconnect from the internet[/b] and [b]STOP all your monitoring programs[/b] (Antivirus/Antispyware, Guards and Shields) [*] Click on your [b]START[/b] button and choose [b]Run[/b]. Then [b]copy/paste[/b] the entire content of the following quotebox (Including …

Member Avatar for crunchie
0
119
Member Avatar for jeremy032180

Hi and welcome to Daniweb forums :). Please paste your logs here next time rather than attaching them. Download this file from one of the following links : [url]http://download.bleepingcomputer.com/sUBs/ComboFix.exe[/url] [url]http://www.techsupportforum.com/sectools/combofix.exe[/url] 1.[b][color=red] Make sure that Combofix is downloaded to and run from, your desktop.[/color][/b] 2. Double click combofix.exe & follow the …

Member Avatar for crunchie
0
244
Member Avatar for Watson306

[url]http://www.daniweb.com/forums/thread83821.html[/url] Please download [url=http://www.atribune.org/ccount/click.php?id=4][color=blue]VundoFix.exe[/color][/url] to your desktop.[list] [*] Double-click [b]VundoFix.exe[/b] to run it. [*]Click the [b]Scan for Vundo[/b] button. [*] Once it's done scanning, click the [b]Remove Vundo[/b] button. [*] You will receive a prompt asking if you want to remove the files, click [b]YES[/b] [*] Once you click yes, …

Member Avatar for crunchie
0
197
Member Avatar for truguate

Looks like you have a Vundo infection too. 1. Download this file from one of the following links : [url]http://download.bleepingcomputer.com/sUBs/ComboFix.exe[/url] [url]http://www.techsupportforum.com/sectools/combofix.exe[/url] 2. Double click combofix.exe & follow the prompts. 3. When finished, it shall produce a log for you. Post that log in your next reply, along with a new …

Member Avatar for crunchie
0
168
Member Avatar for Watson306

Have you thought about slipstreaming XP with SP2 and installing XP that way? [url]http://www.google.com/search?client=opera&rls=en&q=XP+slipstream&sourceid=opera&ie=utf-8&oe=utf-8[/url]

Member Avatar for crunchie
0
289
Member Avatar for SPY5319

Hi and welcome to Daniweb forums :). Download this file from one of the following links : [url]http://download.bleepingcomputer.com/sUBs/ComboFix.exe[/url] [url]http://www.techsupportforum.com/sectools/combofix.exe[/url] 1.[b][color=red] Make sure that Combofix is downloaded to and run from, your desktop.[/color][/b] 2. Double click combofix.exe & follow the prompts. 3. When finished, ComboFix generates a pop up log which …

Member Avatar for crunchie
0
137
Member Avatar for Diffus

Hi and welcome to Daniweb forums :). In your next reply can you please post the [i]entire[/i] hijackthis log :). 1. Download this file from one of the following links : [url]http://download.bleepingcomputer.com/sUBs/ComboFix.exe[/url] [url]http://www.techsupportforum.com/sectools/combofix.exe[/url] 2. Double click combofix.exe & follow the prompts. 3. When finished, it shall produce a log for …

Member Avatar for crunchie
0
328
Member Avatar for clymer

Hi and welcome to Daniweb :). Can you please do the following. =============== Scan with [b]HijackThis[/b] and then place a check next to all the following, if present: [color=#9933cc][b] R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = [url]http://www.dell4me.com/myway[/url] [/b][/color] [color=#9933cc][b] R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank [/b][/color] [color=#9933cc][b] R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL …

Member Avatar for crunchie
0
123
Member Avatar for geesenc

Hi and welcome to Daniweb :). Download the newest version of [url=http://majorgeeks.com/download.php?det=5554]HiJackThis[/url]; [i]version 2.0.2[/i]. Place it in a permanent folder before scanning. == Download [url=http://downloads.andymanchesta.com/RemovalTools/SDFix.zip][b][color=red]SDFix[/b][/color][/url] and save it to your desktop. Please then reboot your computer in [b]Safe Mode[/b] by doing the following :[list] [*]Restart your computer [*]After hearing your …

Member Avatar for crunchie
0
118
Member Avatar for impulseballer

Download this file from one of the following links : [url]http://download.bleepingcomputer.com/sUBs/ComboFix.exe[/url] [url]http://www.techsupportforum.com/sectools/combofix.exe[/url] 1.[b][color=red] Make sure that Combofix is downloaded to and run from, your desktop.[/color][/b] 2. Double click combofix.exe & follow the prompts. 3. When finished, ComboFix generates a pop up log which can also be found at [b]C:\ComboFix.txt.[/b] Post …

Member Avatar for crunchie
0
243
Member Avatar for DWI

Please download and install [url=http://free.grisoft.com/doc/20/lng/us/tpl/v5][b][color=blue]AVG antispyware tool[/color][/b][color=blue][/color][/url][list][*][color=red]Close all other Applications[/color] Select language click [b]Ok[/b][*]Click [b]I Agree [/b][*]Click[b] next[/b][*]Click [b]Install[/b][*]Click[b] Finish[/b][*]Wait and AVG antispyware will open to the main screen automatically.[*]Wait again a few minutes and AVG antispyware Should Auto update itself. If it doesn't click [b]update[/b] at top of screen.[*][b][color=red]It …

Member Avatar for crunchie
0
174
Member Avatar for g-dude

Hi and welcome to Daniweb forums :). Please download [url=http://siri.urz.free.fr/Fix/SmitfraudFix.zip][b][color=red]SmitfraudFix[/color][/b][/url] (by [b]S!Ri[/b]) Extract the content (a folder named [b]SmitfraudFix[/b]) to your Desktop. Open the [b]SmitfraudFix[/b] folder and double-click [b]smitfraudfix.cmd[/b] Select option #1 - [b]Search[/b] by typing [b]1[/b] and press "[b]Enter[/b]"; a text file will appear, which lists infected files (if …

Member Avatar for crunchie
0
87
Member Avatar for Trojaninfected

You need to uninstall that version of hijackthis and install the latest (2.0.2) version. Do [b]NOT[/b] run it from the zip folder as you are now doing so, but run the zip program and unzip hijackthis to a permanent folder. == Please download [url=http://siri.urz.free.fr/Fix/SmitfraudFix.zip][b][color=red]SmitfraudFix[/color][/b][/url] (by [b]S!Ri[/b]) Extract the content (a …

Member Avatar for crunchie
0
224
Member Avatar for baffula

Download this file from one of the following links : [url]http://download.bleepingcomputer.com/sUBs/ComboFix.exe[/url] [url]http://www.techsupportforum.com/sectools/combofix.exe[/url] 1. Make sure that Combofix is downloaded and run from your desktop. 2. Double click combofix.exe & follow the prompts. 3. When finished, it shall produce a log for you. Post that log in your next reply, along …

Member Avatar for crunchie
0
147
Member Avatar for jramx909

Hi and welcome to Daniweb forums :). Can you please do the following. =============== You will have to disable [b]Spybot's Teatimer[/b] before we begin, as it will interfere with the fix. To do this can you start Spybot and go to the [b]Mode[/b] button and select [b]Advanced.[/b] Go to [b]Tools …

Member Avatar for crunchie
0
376
Member Avatar for reddy3

Hi and welcome to Daniweb forums :) 1. Download this file from one of the following links : [url]http://download.bleepingcomputer.com/sUBs/ComboFix.exe[/url] [url]http://www.techsupportforum.com/sectools/combofix.exe[/url] 2. Double click combofix.exe & follow the prompts. 3. When finished, it shall produce a log for you. Post that log in your next reply, along with a new hijackthis …

Member Avatar for crunchie
0
104
Member Avatar for kilegoty

Can you please do the following. =============== Scan with [b]HijackThis[/b] and then place a check next to all the following, if present: [color=#9933cc][b] O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file) [/b][/color] [color=#9933cc][b] O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing) [/b][/color] [color=#9933cc][b] …

Member Avatar for crunchie
0
132
Member Avatar for ahsanur

Download [url=http://downloads.andymanchesta.com/RemovalTools/SDFix.zip][b][color=red]SDFix[/b][/color][/url] and save it to your desktop. Please then reboot your computer in [b]Safe Mode[/b] by doing the following :[list] [*]Restart your computer [*]After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually; [*]Instead of Windows loading as normal, a …

Member Avatar for gerbil
0
243
Member Avatar for Praz-el

Please download [url=http://siri.urz.free.fr/Fix/SmitfraudFix.zip][b][color=red]SmitfraudFix[/color][/b][/url] (by [b]S!Ri[/b]) Extract the content (a folder named [b]SmitfraudFix[/b]) to your Desktop. Open the [b]SmitfraudFix[/b] folder and double-click [b]smitfraudfix.cmd[/b] Select option #1 - [b]Search[/b] by typing [b]1[/b] and press "[b]Enter[/b]"; a text file will appear, which lists infected files (if present). Please copy/paste the content of that …

Member Avatar for crunchie
0
121
Member Avatar for julzie

Please download [url=http://siri.urz.free.fr/Fix/SmitfraudFix.zip][b][color=red]SmitfraudFix[/color][/b][/url] (by [b]S!Ri[/b]) Extract the content (a folder named [b]SmitfraudFix[/b]) to your Desktop. Open the [b]SmitfraudFix[/b] folder and double-click [b]smitfraudfix.cmd[/b] Select option #1 - [b]Search[/b] by typing [b]1[/b] and press "[b]Enter[/b]"; a text file will appear, which lists infected files (if present). Please copy/paste the content of that …

Member Avatar for crunchie
0
211
Member Avatar for CST

Did you update your IE6 at M$'s site? There are a few updates to be had after a reformat.

Member Avatar for infinit3
0
1K
Member Avatar for darkunight

[url]http://www.castlecops.com/postitle206102-0-0-.html[/url] I suggest you follow those instructions :). If you wish to continue with help here though, I am happy to oblige, but not when you are receiving help from elsewhere. The reason for that is only because it can get extremely confusing if you are following instructions from one …

Member Avatar for crunchie
0
31
Member Avatar for SSharma

Can you please do the following. =============== Download the newest version of [url=http://majorgeeks.com/download.php?det=5554]HiJackThis[/url]; [i]version 2.0.2[/i]. Place it in a permanent folder before scanning. Repost your log after following the steps below. [color=#ff0000][i]This version has features that might be more helpful in 'cleaning' up your system[/i][/color]. =============== Scan with [b]HijackThis[/b] and …

Member Avatar for crunchie
0
452
Member Avatar for loftismissy

[QUOTE=gerbil;457035] It appears that you have a vundo infection, or traces of one, so please rename hijackthis.exe to imabunny.exe - this is important.[/QUOTE] I would suggest you do as gerbil has advised and post another log before he comes back online :)

Member Avatar for loftismissy
0
561
Member Avatar for delifion

If system mechanic has a restore feature, I suggest you restore everything that it has removed. Hopefully that will get it working again :).

Member Avatar for crunchie
0
105
Member Avatar for electrickoolaid

Right click on hijackthis, select [b]rename[/b] and change it to [b]analysethis.[/b] Hit the Enter button when done. 1. Download this file from one of the following links : [url]http://download.bleepingcomputer.com/sUBs/ComboFix.exe[/url] [url]http://www.techsupportforum.com/sectools/combofix.exe[/url] 2. Double click combofix.exe & follow the prompts. 3. When finished, it shall produce a log for you. Post that …

Member Avatar for crunchie
0
100
Member Avatar for Hoggy12

Update hijackthis here; [url]http://www.daniweb.com/forums/thread83821.html[/url] once installed, right click on the hijackthis.exe file and select rename. Rename the file to [b]analysethis[/b] and do another scan and post the log.

Member Avatar for crunchie
0
222
Member Avatar for overwhelmed

Can you please do the following. =============== Can you disable [b]Windows Defender[/b] as it may interfere with the removal process. Please leave it disabled until your PC has been given the all clear. [LIST] [*]Open [b]Windows Defender[/b] [*]Click [b]Tools[/b] [*]Click [b]General Settings[/b] [*]Scroll down to [b]Real Time Protection Options[/b] [*]Uncheck …

Member Avatar for overwhelmed
0
507
Member Avatar for User1101

Please download [url=http://siri.urz.free.fr/Fix/SmitfraudFix.zip][b][color=red]SmitfraudFix[/color][/b][/url] (by [b]S!Ri[/b]) Extract the content (a folder named [b]SmitfraudFix[/b]) to your Desktop. Open the [b]SmitfraudFix[/b] folder and double-click [b]smitfraudfix.cmd[/b] Select option #1 - [b]Search[/b] by typing [b]1[/b] and press "[b]Enter[/b]"; a text file will appear, which lists infected files (if present). Please copy/paste the content of that …

Member Avatar for crunchie
0
149
Member Avatar for sreddy
Member Avatar for gerbil
0
169
Member Avatar for spacegirl

Can you please do the following. =============== Download the newest version of [url=http://majorgeeks.com/download.php?det=5554]HiJackThis[/url]; [i]version 2.0.2[/i]. Place it in a permanent folder before scanning. Repost your log after following the steps below. [color=#ff0000][i]This version has features that might be more helpful in 'cleaning' up your system[/i][/color]. =============== Let's look for, and …

Member Avatar for spacegirl
0
275
Member Avatar for Dublin

[b]Download [color=blue]HijackThis[/color] from [url=http://majorgeeks.com/download.php?det=5554][u]here.[/u][/url][/b] Download it to your desktop and NOT a temporary folder. Right click on hijackthis.exe and rename the file to analysethis and hit the OK button. Start HJT & press the "Do a system scan and save a log file" button. When the scan is finished a …

Member Avatar for crunchie
0
81

The End.