4,383 Posted Topics
Re: I have moved your posts to your own thread. Please do not piggy back other members posts in the hijackthis forum :). | |
Re: Hi and welcome to Daniweb forums :). == How many times have you run Combofix and do you have a log from it? Note that Combofix should NOT be run on a machine without being given a directive from someone familiar in it's use. == Can you please do the … | |
Re: If all you guys started your own thread rather than dredge up a 3+ year thread, I am sure you would get the assistance you seek :D. | |
Re: Please go to [url=http://virusscan.jotti.org/][u]Jotti's[/u][/url] or to [url=http://www.virustotal.com/en/virustotalf.html][u]virustotal[/u][/url] and have these files scanned. Post the results back here. C:\WINDOWS\system32\5C62B2BE12.sys C:\WINDOWS\system32\KGyGaAvL.sys == You should print out these instructions, or copy them to a Notepad file for reading while in Safe Mode, because you will not be able to connect to the Internet … | |
Re: Can you please do the following. =============== Scan with [b]HijackThis[/b] and then place a check next to all the following, if present: [color=#9933cc][b] R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank [/b][/color] [color=#9933cc][b] O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F99} - [url]http://www.miniclip.com/puzzlepirate...GameLoader.dll[/url] [/b][/color] Now, close [b]all[/b] instances of Internet Explorer and any other windows … | |
Re: [b]Download LSPfix from [url=http://www.computercops.biz/downloads-file-334.html][u]here[/u][/url][/b] On the opening screen, click the "I know what I'm doing" checkbox, then click Finish. == Download the [url=http://www.funkytoad.com/content/view/13/31/][color=blue]HostsXpert.[/color][/url] Run it and press "Restore Original Hosts" and press "OK". Exit Program. Note that if you have a custom host file, this will remove it. == [b]Download … | |
Re: Hi and welcome to Daniweb forums :). Let's see what we can come up with. Please [b]download[/b] this file - [url=http://download.bleepingcomputer.com/sUBs/Beta/ComboFix.exe][color=red][b]combofix.exe[/b][/color][/url] by [b]sUBs[/b][list] [*] [b][color="#FF0000"]Save it to your Desktop[/color][/b] [*] Now [b]physically disconnect from the internet[/b] and [b]STOP all your monitoring programs[/b] (Antivirus/Antispyware, Guards and Shields) [*] Click on your … | |
Re: Download this file from one of the following links : [url]http://download.bleepingcomputer.com/sUBs/ComboFix.exe[/url] [url]http://www.techsupportforum.com/sectools/combofix.exe[/url] 1.[b][color=red] Make sure that Combofix is downloaded to and run from, your desktop.[/color][/b] 2. Double click combofix.exe & follow the prompts. 3. When finished, ComboFix generates a pop up log which can also be found at [b]C:\ComboFix.txt.[/b] Post … | |
Re: Can you please do the following. =============== Download the newest version of [url=http://majorgeeks.com/download.php?det=5554]HiJackThis[/url]; [i]version 2.0.2[/i]. Place it in a permanent folder before scanning. Repost your log after following the steps below. [color=#ff0000][i]This version has features that might be more helpful in 'cleaning' up your system[/i][/color]. =============== Scan with [b]HijackThis[/b] and … | |
Re: Hi and welcome to Daniweb forums :). Can you please do the following. =============== Download the newest version of [url=http://majorgeeks.com/download.php?det=5554]HiJackThis[/url]; [i]version 2.0.2[/i]. Place it in a permanent folder before scanning. Repost your log after following the steps below. [color=#ff0000][i]This version has features that might be more helpful in 'cleaning' up … | |
Re: Hi and welcome to Daniweb forums :). Please [b]download[/b] this file - [url=http://download.bleepingcomputer.com/sUBs/Beta/ComboFix.exe][color=red][b]combofix.exe[/b][/color][/url] by [b]sUBs[/b][list] [*] [b][color="#FF0000"]Save it to your Desktop[/color][/b] [*] Now [b]physically disconnect from the internet[/b] and [b]STOP all your monitoring programs[/b] (Antivirus/Antispyware, Guards and Shields) [*] Click on your [b]START[/b] button and choose [b]Run[/b]. Then [b]copy/paste[/b] the … | |
Re: Download [url=http://downloads.andymanchesta.com/RemovalTools/SDFix.zip][b][color=red]SDFix[/b][/color][/url] and save it to your desktop. Please then reboot your computer in [b]Safe Mode[/b] by doing the following :[list] [*]Restart your computer [*]After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually; [*]Instead of Windows loading as normal, a … | |
Re: [b]Download [color=blue]HijackThis[/color] from [url=http://majorgeeks.com/download.php?det=5554][u]here.[/u][/url][/b] Download it to your desktop and NOT a temporary folder. Start HJT & press the "Do a system scan and save a log file" button. When the scan is finished a window will pop up giving you the option of where to save it. Save it … | |
Re: Please [b]download[/b] this file - [url=http://download.bleepingcomputer.com/sUBs/Beta/ComboFix.exe][color=red][b]combofix.exe[/b][/color][/url] by [b]sUBs[/b][list] [*] [b][color="#FF0000"]Save it to your Desktop[/color][/b] [*] Now [b]physically disconnect from the internet[/b] and [b]STOP all your monitoring programs[/b] (Antivirus/Antispyware, Guards and Shields) [*] Click on your [b]START[/b] button and choose [b]Run[/b]. Then [b]copy/paste[/b] the entire content of the following quotebox (Including … | |
Re: Download [url=http://downloads.andymanchesta.com/RemovalTools/SDFix.zip][b][color=red]SDFix[/b][/color][/url] and save it to your desktop. Please then reboot your computer in [b]Safe Mode[/b] by doing the following :[list] [*]Restart your computer [*]After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually; [*]Instead of Windows loading as normal, a … | |
Re: Please [b]download[/b] this file - [url=http://download.bleepingcomputer.com/sUBs/Beta/ComboFix.exe][color=red][b]combofix.exe[/b][/color][/url] by [b]sUBs[/b][list] [*] [b][color="#FF0000"]Save it to your Desktop[/color][/b] [*] Now [b]physically disconnect from the internet[/b] and [b]STOP all your monitoring programs[/b] (Antivirus/Antispyware, Guards and Shields) [*] Click on your [b]START[/b] button and choose [b]Run[/b]. Then [b]copy/paste[/b] the entire content of the following quotebox (Including … | |
Re: Hi and welcome to Daniweb forums :). Log is clean. Perhaps it is not spyware/malware related? | |
Re: Download CWShredder from [url]http://209.133.47.200/~merijn/files/CWShredder.exe[/url] & run it. Select the fix button & it will get rid of everything related to CoolWebSearch. Reboot after doing this & post another log please. | |
Re: Please [b]download[/b] this file - [url=http://download.bleepingcomputer.com/sUBs/Beta/ComboFix.exe][color=red][b]combofix.exe[/b][/color][/url] by [b]sUBs[/b][list] [*] [b][color="#FF0000"]Save it to your Desktop[/color][/b] [*] Now [b]physically disconnect from the internet[/b] and [b]STOP all your monitoring programs[/b] (Antivirus/Antispyware, Guards and Shields) [*] Click on your [b]START[/b] button and choose [b]Run[/b]. Then [b]copy/paste[/b] the entire content of the following quotebox (Including … | |
Re: Hi and welcome to Daniweb forums :). Please paste your logs here next time rather than attaching them. Download this file from one of the following links : [url]http://download.bleepingcomputer.com/sUBs/ComboFix.exe[/url] [url]http://www.techsupportforum.com/sectools/combofix.exe[/url] 1.[b][color=red] Make sure that Combofix is downloaded to and run from, your desktop.[/color][/b] 2. Double click combofix.exe & follow the … | |
Re: [url]http://www.daniweb.com/forums/thread83821.html[/url] Please download [url=http://www.atribune.org/ccount/click.php?id=4][color=blue]VundoFix.exe[/color][/url] to your desktop.[list] [*] Double-click [b]VundoFix.exe[/b] to run it. [*]Click the [b]Scan for Vundo[/b] button. [*] Once it's done scanning, click the [b]Remove Vundo[/b] button. [*] You will receive a prompt asking if you want to remove the files, click [b]YES[/b] [*] Once you click yes, … | |
Re: Looks like you have a Vundo infection too. 1. Download this file from one of the following links : [url]http://download.bleepingcomputer.com/sUBs/ComboFix.exe[/url] [url]http://www.techsupportforum.com/sectools/combofix.exe[/url] 2. Double click combofix.exe & follow the prompts. 3. When finished, it shall produce a log for you. Post that log in your next reply, along with a new … | |
Re: Have you thought about slipstreaming XP with SP2 and installing XP that way? [url]http://www.google.com/search?client=opera&rls=en&q=XP+slipstream&sourceid=opera&ie=utf-8&oe=utf-8[/url] | |
Re: Hi and welcome to Daniweb forums :). Download this file from one of the following links : [url]http://download.bleepingcomputer.com/sUBs/ComboFix.exe[/url] [url]http://www.techsupportforum.com/sectools/combofix.exe[/url] 1.[b][color=red] Make sure that Combofix is downloaded to and run from, your desktop.[/color][/b] 2. Double click combofix.exe & follow the prompts. 3. When finished, ComboFix generates a pop up log which … | |
Re: Hi and welcome to Daniweb forums :). In your next reply can you please post the [i]entire[/i] hijackthis log :). 1. Download this file from one of the following links : [url]http://download.bleepingcomputer.com/sUBs/ComboFix.exe[/url] [url]http://www.techsupportforum.com/sectools/combofix.exe[/url] 2. Double click combofix.exe & follow the prompts. 3. When finished, it shall produce a log for … | |
Re: Hi and welcome to Daniweb :). Can you please do the following. =============== Scan with [b]HijackThis[/b] and then place a check next to all the following, if present: [color=#9933cc][b] R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = [url]http://www.dell4me.com/myway[/url] [/b][/color] [color=#9933cc][b] R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank [/b][/color] [color=#9933cc][b] R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL … | |
Re: Hi and welcome to Daniweb :). Download the newest version of [url=http://majorgeeks.com/download.php?det=5554]HiJackThis[/url]; [i]version 2.0.2[/i]. Place it in a permanent folder before scanning. == Download [url=http://downloads.andymanchesta.com/RemovalTools/SDFix.zip][b][color=red]SDFix[/b][/color][/url] and save it to your desktop. Please then reboot your computer in [b]Safe Mode[/b] by doing the following :[list] [*]Restart your computer [*]After hearing your … | |
Re: Download this file from one of the following links : [url]http://download.bleepingcomputer.com/sUBs/ComboFix.exe[/url] [url]http://www.techsupportforum.com/sectools/combofix.exe[/url] 1.[b][color=red] Make sure that Combofix is downloaded to and run from, your desktop.[/color][/b] 2. Double click combofix.exe & follow the prompts. 3. When finished, ComboFix generates a pop up log which can also be found at [b]C:\ComboFix.txt.[/b] Post … | |
Re: Please download and install [url=http://free.grisoft.com/doc/20/lng/us/tpl/v5][b][color=blue]AVG antispyware tool[/color][/b][color=blue][/color][/url][list][*][color=red]Close all other Applications[/color] Select language click [b]Ok[/b][*]Click [b]I Agree [/b][*]Click[b] next[/b][*]Click [b]Install[/b][*]Click[b] Finish[/b][*]Wait and AVG antispyware will open to the main screen automatically.[*]Wait again a few minutes and AVG antispyware Should Auto update itself. If it doesn't click [b]update[/b] at top of screen.[*][b][color=red]It … | |
Re: Hi and welcome to Daniweb forums :). Please download [url=http://siri.urz.free.fr/Fix/SmitfraudFix.zip][b][color=red]SmitfraudFix[/color][/b][/url] (by [b]S!Ri[/b]) Extract the content (a folder named [b]SmitfraudFix[/b]) to your Desktop. Open the [b]SmitfraudFix[/b] folder and double-click [b]smitfraudfix.cmd[/b] Select option #1 - [b]Search[/b] by typing [b]1[/b] and press "[b]Enter[/b]"; a text file will appear, which lists infected files (if … | |
Re: You need to uninstall that version of hijackthis and install the latest (2.0.2) version. Do [b]NOT[/b] run it from the zip folder as you are now doing so, but run the zip program and unzip hijackthis to a permanent folder. == Please download [url=http://siri.urz.free.fr/Fix/SmitfraudFix.zip][b][color=red]SmitfraudFix[/color][/b][/url] (by [b]S!Ri[/b]) Extract the content (a … | |
Re: Download this file from one of the following links : [url]http://download.bleepingcomputer.com/sUBs/ComboFix.exe[/url] [url]http://www.techsupportforum.com/sectools/combofix.exe[/url] 1. Make sure that Combofix is downloaded and run from your desktop. 2. Double click combofix.exe & follow the prompts. 3. When finished, it shall produce a log for you. Post that log in your next reply, along … | |
Re: Hi and welcome to Daniweb forums :). Can you please do the following. =============== You will have to disable [b]Spybot's Teatimer[/b] before we begin, as it will interfere with the fix. To do this can you start Spybot and go to the [b]Mode[/b] button and select [b]Advanced.[/b] Go to [b]Tools … | |
Re: Hi and welcome to Daniweb forums :) 1. Download this file from one of the following links : [url]http://download.bleepingcomputer.com/sUBs/ComboFix.exe[/url] [url]http://www.techsupportforum.com/sectools/combofix.exe[/url] 2. Double click combofix.exe & follow the prompts. 3. When finished, it shall produce a log for you. Post that log in your next reply, along with a new hijackthis … | |
Re: Can you please do the following. =============== Scan with [b]HijackThis[/b] and then place a check next to all the following, if present: [color=#9933cc][b] O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file) [/b][/color] [color=#9933cc][b] O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing) [/b][/color] [color=#9933cc][b] … | |
Re: Download [url=http://downloads.andymanchesta.com/RemovalTools/SDFix.zip][b][color=red]SDFix[/b][/color][/url] and save it to your desktop. Please then reboot your computer in [b]Safe Mode[/b] by doing the following :[list] [*]Restart your computer [*]After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually; [*]Instead of Windows loading as normal, a … | |
Re: Please download [url=http://siri.urz.free.fr/Fix/SmitfraudFix.zip][b][color=red]SmitfraudFix[/color][/b][/url] (by [b]S!Ri[/b]) Extract the content (a folder named [b]SmitfraudFix[/b]) to your Desktop. Open the [b]SmitfraudFix[/b] folder and double-click [b]smitfraudfix.cmd[/b] Select option #1 - [b]Search[/b] by typing [b]1[/b] and press "[b]Enter[/b]"; a text file will appear, which lists infected files (if present). Please copy/paste the content of that … | |
Re: Please download [url=http://siri.urz.free.fr/Fix/SmitfraudFix.zip][b][color=red]SmitfraudFix[/color][/b][/url] (by [b]S!Ri[/b]) Extract the content (a folder named [b]SmitfraudFix[/b]) to your Desktop. Open the [b]SmitfraudFix[/b] folder and double-click [b]smitfraudfix.cmd[/b] Select option #1 - [b]Search[/b] by typing [b]1[/b] and press "[b]Enter[/b]"; a text file will appear, which lists infected files (if present). Please copy/paste the content of that … | |
Re: Did you update your IE6 at M$'s site? There are a few updates to be had after a reformat. | |
Re: [url]http://www.castlecops.com/postitle206102-0-0-.html[/url] I suggest you follow those instructions :). If you wish to continue with help here though, I am happy to oblige, but not when you are receiving help from elsewhere. The reason for that is only because it can get extremely confusing if you are following instructions from one … | |
Re: Can you please do the following. =============== Download the newest version of [url=http://majorgeeks.com/download.php?det=5554]HiJackThis[/url]; [i]version 2.0.2[/i]. Place it in a permanent folder before scanning. Repost your log after following the steps below. [color=#ff0000][i]This version has features that might be more helpful in 'cleaning' up your system[/i][/color]. =============== Scan with [b]HijackThis[/b] and … | |
Re: [QUOTE=gerbil;457035] It appears that you have a vundo infection, or traces of one, so please rename hijackthis.exe to imabunny.exe - this is important.[/QUOTE] I would suggest you do as gerbil has advised and post another log before he comes back online :) | |
Re: If system mechanic has a restore feature, I suggest you restore everything that it has removed. Hopefully that will get it working again :). | |
Re: Right click on hijackthis, select [b]rename[/b] and change it to [b]analysethis.[/b] Hit the Enter button when done. 1. Download this file from one of the following links : [url]http://download.bleepingcomputer.com/sUBs/ComboFix.exe[/url] [url]http://www.techsupportforum.com/sectools/combofix.exe[/url] 2. Double click combofix.exe & follow the prompts. 3. When finished, it shall produce a log for you. Post that … | |
Re: Update hijackthis here; [url]http://www.daniweb.com/forums/thread83821.html[/url] once installed, right click on the hijackthis.exe file and select rename. Rename the file to [b]analysethis[/b] and do another scan and post the log. | |
Re: Can you please do the following. =============== Can you disable [b]Windows Defender[/b] as it may interfere with the removal process. Please leave it disabled until your PC has been given the all clear. [LIST] [*]Open [b]Windows Defender[/b] [*]Click [b]Tools[/b] [*]Click [b]General Settings[/b] [*]Scroll down to [b]Real Time Protection Options[/b] [*]Uncheck … | |
Re: Please download [url=http://siri.urz.free.fr/Fix/SmitfraudFix.zip][b][color=red]SmitfraudFix[/color][/b][/url] (by [b]S!Ri[/b]) Extract the content (a folder named [b]SmitfraudFix[/b]) to your Desktop. Open the [b]SmitfraudFix[/b] folder and double-click [b]smitfraudfix.cmd[/b] Select option #1 - [b]Search[/b] by typing [b]1[/b] and press "[b]Enter[/b]"; a text file will appear, which lists infected files (if present). Please copy/paste the content of that … | |
Re: [url=http://www.daniweb.com/forums/thread83821.html]Hijackthis latest version[/url] | |
Re: Can you please do the following. =============== Download the newest version of [url=http://majorgeeks.com/download.php?det=5554]HiJackThis[/url]; [i]version 2.0.2[/i]. Place it in a permanent folder before scanning. Repost your log after following the steps below. [color=#ff0000][i]This version has features that might be more helpful in 'cleaning' up your system[/i][/color]. =============== Let's look for, and … | |
Re: [b]Download [color=blue]HijackThis[/color] from [url=http://majorgeeks.com/download.php?det=5554][u]here.[/u][/url][/b] Download it to your desktop and NOT a temporary folder. Right click on hijackthis.exe and rename the file to analysethis and hit the OK button. Start HJT & press the "Do a system scan and save a log file" button. When the scan is finished a … |
The End.