4,383 Posted Topics

Member Avatar for Rybupsp

Have you updated Ewido's reference file, booted into safe mode and let it remove what it finds? Ewido does remove this infection. Can you please do the following. =============== Run [b]HiJackThis,[/b] click "[b][i]Scan[/i][/b]", then check(tick) the following, if present: [color=#9933cc][b] R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = [url]http://www.clicktomakeasearch.com/sp2.php[/url] [/b][/color] [color=#9933cc][b] R1 - …

Member Avatar for crunchie
0
348
Member Avatar for dittu

dittu, I am already assisting you here [url]http://www.daniweb.com/techtalkforums/thread34655.html[/url] Please do not start new threads for the same problem. Thread closed.

Member Avatar for crunchie
0
157
Member Avatar for shane'r69
Member Avatar for azurejewels

Can you please do the following. =============== Open a [b]command prompt[/b] by going to the start menu and then select 'Run'. In the box that pops up type in 'cmd'. The command prompt will open. OR You can go to Start -> Programs -> Accessories -> Command Prompt. Unregister the …

Member Avatar for crunchie
0
165
Member Avatar for Madelyn

Please print these instructions out for use in Safe Mode. Please download [url=http://www.atribune.org/downloads/VundoFix.exe][b][color=red]VundoFix.exe[/color][/b][/url] to your desktop.[list] [*]Double-click [b]VundoFix.exe[/b] to extract the files [*]This will create a [b]VundoFix[/b] folder on your desktop. [*]After the files are extracted, please reboot your computer into [b]Safe Mode[/b]. You can do this by restarting your …

Member Avatar for crunchie
0
602
Member Avatar for OmegaStealth

Close any programs you have open since this step requires a reboot. From the l2mfix folder on your desktop, double click l2mfix.bat and select option #2 for Run Fix by typing 2 and then pressing enter, then press any key to reboot your computer. After a reboot, your desktop and …

Member Avatar for dlh6213
0
378
Member Avatar for SuperSam

Can you please do the following. =============== Run [b]HiJackThis,[/b] click "[b][i]Scan[/i][/b]", then check(tick) the following, if present: [color=#9933cc][b] R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank [/b][/color] [color=#9933cc][b] R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank [/b][/color] [color=#9933cc][b] R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank [/b][/color] [color=#9933cc][b] R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank …

Member Avatar for crunchie
0
83
Member Avatar for SuperSam

Can you please do the following. Please go to [url=http://virusscan.jotti.org/][u]Jotti's[/u][/url] and have this file scanned. Post the results back here. C:\Program Files\Acceleration Software\Anti-Virus\[b]sstsmon.dll[/b] =============== Run [b]HiJackThis,[/b] click "[b][i]Scan[/i][/b]", then check(tick) the following, if present: [color=#9933cc][b] R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm [/b][/color] [color=#9933cc][b] F3 - REG:win.ini: load=??? ? [/b][/color] …

Member Avatar for crunchie
0
75
Member Avatar for SuperSam

Can you please do the following. =============== When we're done cleaning off your system, I'd [b]recommend[/b] that you install all the [color=#ff0000][b][i]critical windows updates[/i][/b][/color] available from [b]Microsoft[/b], up to [i]service pack 1[/i]. This will help to make your system more secure and prevent many '[i]problems[/i]' from reoccurring in the future. …

Member Avatar for crunchie
0
113
Member Avatar for james106

[b]Download [color=blue]HijackThis[/color] [b][color=red]self-extracting[/color][/b] zip version from [url=http://www.malwareremoval.com/downloads.html][u]here.[/u][/url][/b] Once downloaded, double click on the file & it will install into it's own, permanent folder. Start HJT & press the "Do a system scan and save a log file" button. When the scan is finished a window will pop up giving you …

Member Avatar for crunchie
0
87
Member Avatar for DouglasThompson

Can you please do the following. =============== Run [b]HiJackThis,[/b] click "[b][i]Scan[/i][/b]", then check(tick) the following, if present: [color=#9933cc][b] O23 - Service: serviceMangr (tcphost.exe) - Unknown owner - C:\WINNT\tcphost.exe [/b][/color] Now, close [b]all[/b] instances of Internet Explorer and any other windows you have open except [b]HiJackThis[/b], click "[b][i]Fix checked[/i][/b]". =============== Locate …

Member Avatar for crunchie
0
298
Member Avatar for CRIS_650510

Can you please do the following. =============== Run [b]HiJackThis[/b] then: 1. Click "[b][i]Open the Misc Tools Section[/i][/b]" 2. Click "[b][i]Open Process manager[/i][/b]" - Next, while holding down the [b]CTRL[/b] key, locate ([i]if present[/i]) and click on ([i]highlight[/i]) each of the following: [b][color=#000000]C:\WINDOWS\system32\[/color][color=#ff0000]atl00906.exe[/color][/b] Now double-check and make sure that only those …

Member Avatar for crunchie
0
151
Member Avatar for shane'r69
Member Avatar for agent

agent, Hi and welcome to the Daniweb forums :). =============== Please visit at least two of the following sites for an online virus scan: BitDefender Free Online Virus Scan [url]http://www.bitdefender.com/scan/licence.php[/url] Make sure you tick [b]AutoClean[/b] under [b]Scan Options.[/b] Panda ActiveScan [url]http://www.pandasoftware.com/activescan/com/activescan_principal.htm[/url] Make sure you tick [b]Disinfect automatically[/b] under [b]Scan Options.[/b] …

Member Avatar for crunchie
0
126
Member Avatar for mommymomof2

Try the following advice from chetnet.co.uk: Open Internet Options. Clear the Secure Sockets Layer (SSL) slate and AutoComplete history. To do so: Click the Content tab. Under Certificates, click Clear SSL Slate. Click OK when you receive the message that the SSL cache was successfully cleared. Under Personal information, click …

Member Avatar for pshaw
0
308
Member Avatar for alexanderp513

Can you please do the following. =============== Run [b]HiJackThis,[/b] click "[b][i]Scan[/i][/b]", then check(tick) the following, if present: [color=#9933cc][b] O4 - HKLM\..\Run: [winupdates] C:\Program Files\winupdates\winupdates.exe /auto [/b][/color] [color=#9933cc][b] O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm [/b][/color] [color=#9933cc][b] O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm …

Member Avatar for crunchie
0
135
Member Avatar for mrain01

Can you please do the following. =============== Open a [b]command prompt[/b] by going to the start menu and then select 'Run'. In the box that pops up type in 'cmd'. The command prompt will open. OR You can go to Start -> Programs -> Accessories -> Command Prompt. Unregister the …

Member Avatar for crunchie
0
152
Member Avatar for Al666

[QUOTE=Al666]ok, i'm new here and all, anyways on my computer anything to do with hotmail won't work, like if i try to sign in on the hotmail page it says page can not be found, but if anyone tries on my computer it won't work, however if i try on …

Member Avatar for EverStar
0
177
Member Avatar for PhilJack

[b]First of all we have to remove Newdotnet,[/b] either from add/remove programs, or by going [url=http://www.newdotnet.com/removal.html][u]here[/u][/url] and scrolling down to the uninstall tool. You are running hijackthis from a temporary folder. You need to create a new folder in a permanent directory of your choice, (a folder on the desktop …

Member Avatar for crunchie
0
178
Member Avatar for ziggy_z1

ziggy_z1, Hi and welcome to the Daniweb forums :). =============== Please visit at least two of the following sites for an online virus scan: BitDefender Free Online Virus Scan [url]http://www.bitdefender.com/scan/licence.php[/url] Make sure you tick [b]AutoClean[/b] under [b]Scan Options.[/b] Panda ActiveScan [url]http://www.pandasoftware.com/activescan/com/activescan_principal.htm[/url] Make sure you tick [b]Disinfect automatically[/b] under [b]Scan Options.[/b] …

Member Avatar for crunchie
0
117
Member Avatar for nkacriz

Hi and welcome :). You only posted a partial log. Without the rest, the fix cannot go ahead. Please post another log in it's entirety.

Member Avatar for crunchie
0
322
Member Avatar for ast5

Hi ast5. Welcome to the Daniweb forums :). You are running hijackthis from a temporary folder. You need to create a new folder in a permanent directory of your choice, (a folder on the desktop is fine) name the new folder [b]hijackthis[/b] and move or unzip hijackthis.exe into that folder. …

Member Avatar for crunchie
0
407
Member Avatar for indy

Hi. You are running hijackthis from a temporary folder. You need to create a new folder in a permanent directory of your choice, (a folder on the desktop is fine) name the new folder [b]hijackthis[/b] and move or unzip hijackthis.exe into that folder. Once you have done that, rescan with …

Member Avatar for crunchie
0
178
Member Avatar for drenched

Hi. Welcome to the Daniweb forums :). You are running hijackthis from a temporary folder. You need to create a new folder in a permanent directory of your choice, (a folder on the desktop is fine) name the new folder [b]hijackthis[/b] and move or unzip hijackthis.exe into that folder. == …

Member Avatar for crunchie
0
108
Member Avatar for KXATL

Kevin, Hi and welcome to the Daniweb forums :). You are running hijackthis from a temporary folder. You need to create a new folder in a permanent directory of your choice, (a folder on the desktop is fine) name the new folder [b]hijackthis[/b] and move or unzip hijackthis.exe into that …

Member Avatar for crunchie
0
126
Member Avatar for dkewl16

You have some entries there that need removing. =============== Please visit at least two of the following sites for an online virus scan: BitDefender Free Online Virus Scan [url]http://www.bitdefender.com/scan/licence.php[/url] Make sure you tick [b]AutoClean[/b] under [b]Scan Options.[/b] Panda ActiveScan [url]http://www.pandasoftware.com/activescan/com/activescan_principal.htm[/url] Make sure you tick [b]Disinfect automatically[/b] under [b]Scan Options.[/b] Housecall …

Member Avatar for crunchie
0
192
Member Avatar for vartotojas

Sure can fix it :D. Please print these instructions out for use in Safe Mode. Please download [url=http://www.atribune.org/downloads/VundoFix.exe][b][color=red]VundoFix.exe[/color][/b][/url] to your desktop.[list] [*]Double-click [b]VundoFix.exe[/b] to extract the files [*]This will create a [b]VundoFix[/b] folder on your desktop. [*]After the files are extracted, please reboot your computer into [b]Safe Mode[/b]. You can …

Member Avatar for crunchie
0
101
Member Avatar for MelissaH

Download L2mfix from one of these two locations: [url]http://www.atribune.org/downloads/l2mfix.exe[/url] [url]http://www.downloads.subratam.org/l2mfix.exe[/url] Save the file to your desktop and double click l2mfix.exe. Click the Install button to extract the files and follow the prompts, then open the newly added l2mfix folder on your desktop. Double click l2mfix.bat and select option #1 for …

Member Avatar for DMR
0
418
Member Avatar for got_edge

Hi and welcome to Daniweb :). Run [b]HiJackThis,[/b] click "[b][i]Scan[/i][/b]", then check(tick) the following, if present: [color=#9933cc][b] O4 - HKLM\..\Run: [Microsoft Windows DLL Services Configuration] windir32.exe [/b][/color] [color=#9933cc][b] O4 - HKLM\..\RunServices: [Microsoft Windows DLL Services Configuration] windir32.exe [/b][/color] Now, close [b]all[/b] instances of Internet Explorer and any other windows you …

Member Avatar for crunchie
0
198
Member Avatar for Raven11

[url]http://www.sophos.com/virusinfo/analyses/w32sdbotadf.html[/url] You may post an hijackthis if you wish?

Member Avatar for crunchie
0
81
Member Avatar for geezer

Can you post a hijackthis log taken immediately after a reboot and without removing anything from it please.

Member Avatar for DMR
0
627
Member Avatar for DMHltd

Close all (browser) windows & rescan with hijackthis. When the scan is finished place a check in the box to the left of the following entries= O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file) O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file) O4 - Startup: PowerReg …

Member Avatar for Farkie
0
266
Member Avatar for pedrofigo

Download [color=blue][b]CWShredder 2.15[/b][/color] from [url=http://www.intermute.com/products/cwshredder.html][u]here.[/u][/url] Run it and press the *fix,* not scan and allow it to clean the infection. [b]Close [color=red]all[/color] browser and explorer windows before hitting the fix button.[/b] =============== Download AboutBuster 5: [url=http://www.besttechie.net/tools/AboutBuster5.zip]http://www.besttechie.net/tools/AboutBuster5.zip[/url] [url=http://www.malwarebytes.biz/AboutBuster5.zip]http://www.malwarebytes.biz/AboutBuster5.zip[/url] Once downloaded, unzip it, and put the folder on your desktop. Then double-click …

Member Avatar for crunchie
0
373
Member Avatar for marmaliser

Please download the trial version of Ewido Security Suite here: [url]http://www.ewido.net/en/download/[/url] Install it, and update the definitions to the newest files. Do NOT run a scan yet. Please download Nailfix from here: [url]http://www.noidea.us/easyfile/file.php?download=20050515010747824[/url] Unzip it to the desktop but please do NOT run it yet. Next, please reboot your computer …

Member Avatar for presto
0
494
Member Avatar for Chronica111

Hi Chronica111 and welcome to Daniweb forums :). You only posted half the log :D. Please rescan with hijackthis and post again. Make certain it is running from a permanent folder too :). == Please visit at least two of the following sites for an online virus scan: BitDefender Free …

Member Avatar for crunchie
0
458
Member Avatar for taxmeless

Hi and welcome to Daniweb forums :). Try the following and see if they help; Download and run Winsockfix from here [url]http://www.softpedia.com/get/Tweak/Network-Tweak/WinSockFix.shtml[/url] == Try running [url=http://windowsxp.mvps.org/IEFIX.htm][color=blue]IEFIX.htm[/color][/url] which will repair IE and run a System File Check.

Member Avatar for crunchie
0
91
Member Avatar for lvlIk3

You have some entries there that need removing. =============== First of all could you click Start>Settings>Control Panel>Add or Remove Programs and uninstall 'Window Search', 'Window Searching', 'Lop.com', 'LOP SEARCH', 'Browser Enhancer', or 'Ultimate Browser Enhancer' if listed. You may be given a code to insert, do so and reboot when …

Member Avatar for crunchie
0
195
Member Avatar for joel_stahleen

Click [url=http://www.geekstogo.com/modules.php?modid=5&action=download&id=4]here[/url] to download Killbox by Option^Explicit. *Extract the program to your desktop and double-click on its folder, then double-click on Killbox.exe to start the program. *In the killbox program, select the [b]Delete on Reboot[/b] option. *Copy the file names below to the clipboard by highlighting them and pressing Control-C: …

Member Avatar for crunchie
0
156
Member Avatar for raynoldz125

[b]Download [color=blue]HijackThis[/color] [b][color=red]self-extracting[/color][/b] zip version from [url=http://www.malwareremoval.com/downloads.html][u]here.[/u][/url][/b] Once downloaded, double click on the file & it will install into it's own, permanent folder. Start HJT & press the "Do a system scan and save a log file" button. When the scan is finished a window will pop up giving you …

Member Avatar for raynoldz125
0
616
Member Avatar for derekbka

You may want to print out these instructions for reference, since you will have to restart your computer during the fix. Please download FixWareout from one of these sites: [url]http://forums.subratam.org/index.php?act=Attach&type=post&id=43811[/url] [url]http://swandog46.geekstogo.com/Fixwareout.exe[/url] Save it to your desktop and run it. Click Next, then Install, then make sure "Run fixit" is checked …

Member Avatar for crunchie
0
375
Member Avatar for gazzabhoy

gazzabhoy, Hi and welcome to the Daniweb forums :). =============== Please visit at least two of the following sites for an online virus scan: BitDefender Free Online Virus Scan [url]http://www.bitdefender.com/scan/licence.php[/url] Make sure you tick [b]AutoClean[/b] under [b]Scan Options.[/b] Panda ActiveScan [url]http://www.pandasoftware.com/activescan/com/activescan_principal.htm[/url] Make sure you tick [b]Disinfect automatically[/b] under [b]Scan Options.[/b] …

Member Avatar for crunchie
0
509
Member Avatar for jafulton5150

You may want to print or save these instructions locally before starting. Please download, install, and update the free version of [url=http://www.ewido.net/en/download/]Ewido trojan scanner[/url]: [list=1] [*]When installing, under "Additional Options" [b]uncheck[/b] "Install background guard" and "Install scan via context menu". [*]Run Ewido --- When you run it for the first …

Member Avatar for crunchie
0
499
Member Avatar for Original

Original, Hi and welcome to the Daniweb forums :). =============== When we're done cleaning off your system, I'd [b]recommend[/b] that you install all the [color=#ff0000][b][i]critical windows updates[/i][/b][/color] available from [b]Microsoft[/b], up to [i]service pack 1[/i]. This will help to make your system more secure and prevent many '[i]problems[/i]' from reoccurring …

Member Avatar for crunchie
0
188
Member Avatar for BasketCase

Each file name is random so must be input correctly. The fix is the same. Post your log if you wish.

Member Avatar for crunchie
0
209
Member Avatar for kwibster

Download [color=blue][b]CWShredder 2.15[/b][/color] from [url=http://www.intermute.com/products/cwshredder.html][u]here.[/u][/url] Run it and press the *fix,* not scan and allow it to clean the infection. [b]Close [color=red]all[/color] browser and explorer windows before hitting the fix button.[/b] =============== Please download the trial version of Ewido Security Suite here: [url]http://www.ewido.net/en/download/[/url] Install it, and update the definitions to …

Member Avatar for crunchie
0
285
Member Avatar for juliab

juliab, hi and welcome to Daniweb :). Download Itty Bitty Process Manager (IBProcMan.zip)(direct download) [url]http://www.merijn.org/files/ibprocman.zip[/url] Run the process manager. Near the top right there are a couple of icons. Select the one to the left to copy to the clipboard. Paste the results back here. Please do that in normal …

Member Avatar for crunchie
0
142
Member Avatar for jmkthetruth

Hi jmkthetruth. Got a few nasties there so we probably will not get them fixed up in one hit. =============== Run the PurityScan [url=http://www.purityscan.com/uninstall.html][u]uninstaller.[/u][/url] =============== Go to [url=http://www.trendmicro.com/en/home/us/enterprise.htm]www.trendmicro.com[/url], and then: 1. Click "[b][i]Free Online Scan[/i][/b]". 2. Click "[b][i]Scan now, it's free[/i][/b]". It'll take a few minutes to download (especially with …

Member Avatar for crunchie
0
1K
Member Avatar for apurva16
Member Avatar for jojosoks

Please go [url=http://windowsupdate.microsoft.com/][u]here[/u][/url] & install ALL critical updates required for your system, including service pack 1a for both XP and IE6. Most malware is designed to attack unpatched XP systems - exploiting the available 'holes' - and can bypass third-party protection on an unpatched system. The most that can be …

Member Avatar for crunchie
0
141
Member Avatar for Niklas

Please download miekiemoes' LQfix batch here: [url]http://www.downloads.subratam.org/LQfix.zip[/url] Unzip it to the desktop but do NOT run it yet. It may be best to to right click on the link and select 'Save As' and save it to your desk top. Next, please reboot your computer in Safe Mode by doing …

Member Avatar for crunchie
0
248

The End.