4,383 Posted Topics
Re: Have you updated Ewido's reference file, booted into safe mode and let it remove what it finds? Ewido does remove this infection. Can you please do the following. =============== Run [b]HiJackThis,[/b] click "[b][i]Scan[/i][/b]", then check(tick) the following, if present: [color=#9933cc][b] R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = [url]http://www.clicktomakeasearch.com/sp2.php[/url] [/b][/color] [color=#9933cc][b] R1 - … | |
Re: dittu, I am already assisting you here [url]http://www.daniweb.com/techtalkforums/thread34655.html[/url] Please do not start new threads for the same problem. Thread closed. | |
Re: Looks clean to me :). | |
Re: Can you please do the following. =============== Open a [b]command prompt[/b] by going to the start menu and then select 'Run'. In the box that pops up type in 'cmd'. The command prompt will open. OR You can go to Start -> Programs -> Accessories -> Command Prompt. Unregister the … | |
Re: Please print these instructions out for use in Safe Mode. Please download [url=http://www.atribune.org/downloads/VundoFix.exe][b][color=red]VundoFix.exe[/color][/b][/url] to your desktop.[list] [*]Double-click [b]VundoFix.exe[/b] to extract the files [*]This will create a [b]VundoFix[/b] folder on your desktop. [*]After the files are extracted, please reboot your computer into [b]Safe Mode[/b]. You can do this by restarting your … | |
Re: Close any programs you have open since this step requires a reboot. From the l2mfix folder on your desktop, double click l2mfix.bat and select option #2 for Run Fix by typing 2 and then pressing enter, then press any key to reboot your computer. After a reboot, your desktop and … | |
Re: Can you please do the following. =============== Run [b]HiJackThis,[/b] click "[b][i]Scan[/i][/b]", then check(tick) the following, if present: [color=#9933cc][b] R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank [/b][/color] [color=#9933cc][b] R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank [/b][/color] [color=#9933cc][b] R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank [/b][/color] [color=#9933cc][b] R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank … | |
Re: Can you please do the following. Please go to [url=http://virusscan.jotti.org/][u]Jotti's[/u][/url] and have this file scanned. Post the results back here. C:\Program Files\Acceleration Software\Anti-Virus\[b]sstsmon.dll[/b] =============== Run [b]HiJackThis,[/b] click "[b][i]Scan[/i][/b]", then check(tick) the following, if present: [color=#9933cc][b] R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm [/b][/color] [color=#9933cc][b] F3 - REG:win.ini: load=??? ? [/b][/color] … | |
Re: Can you please do the following. =============== When we're done cleaning off your system, I'd [b]recommend[/b] that you install all the [color=#ff0000][b][i]critical windows updates[/i][/b][/color] available from [b]Microsoft[/b], up to [i]service pack 1[/i]. This will help to make your system more secure and prevent many '[i]problems[/i]' from reoccurring in the future. … | |
Re: [b]Download [color=blue]HijackThis[/color] [b][color=red]self-extracting[/color][/b] zip version from [url=http://www.malwareremoval.com/downloads.html][u]here.[/u][/url][/b] Once downloaded, double click on the file & it will install into it's own, permanent folder. Start HJT & press the "Do a system scan and save a log file" button. When the scan is finished a window will pop up giving you … | |
Re: Can you please do the following. =============== Run [b]HiJackThis,[/b] click "[b][i]Scan[/i][/b]", then check(tick) the following, if present: [color=#9933cc][b] O23 - Service: serviceMangr (tcphost.exe) - Unknown owner - C:\WINNT\tcphost.exe [/b][/color] Now, close [b]all[/b] instances of Internet Explorer and any other windows you have open except [b]HiJackThis[/b], click "[b][i]Fix checked[/i][/b]". =============== Locate … | |
Re: Can you please do the following. =============== Run [b]HiJackThis[/b] then: 1. Click "[b][i]Open the Misc Tools Section[/i][/b]" 2. Click "[b][i]Open Process manager[/i][/b]" - Next, while holding down the [b]CTRL[/b] key, locate ([i]if present[/i]) and click on ([i]highlight[/i]) each of the following: [b][color=#000000]C:\WINDOWS\system32\[/color][color=#ff0000]atl00906.exe[/color][/b] Now double-check and make sure that only those … | |
Re: Looks all good :). | |
Re: agent, Hi and welcome to the Daniweb forums :). =============== Please visit at least two of the following sites for an online virus scan: BitDefender Free Online Virus Scan [url]http://www.bitdefender.com/scan/licence.php[/url] Make sure you tick [b]AutoClean[/b] under [b]Scan Options.[/b] Panda ActiveScan [url]http://www.pandasoftware.com/activescan/com/activescan_principal.htm[/url] Make sure you tick [b]Disinfect automatically[/b] under [b]Scan Options.[/b] … | |
Re: Try the following advice from chetnet.co.uk: Open Internet Options. Clear the Secure Sockets Layer (SSL) slate and AutoComplete history. To do so: Click the Content tab. Under Certificates, click Clear SSL Slate. Click OK when you receive the message that the SSL cache was successfully cleared. Under Personal information, click … | |
Re: Can you please do the following. =============== Run [b]HiJackThis,[/b] click "[b][i]Scan[/i][/b]", then check(tick) the following, if present: [color=#9933cc][b] O4 - HKLM\..\Run: [winupdates] C:\Program Files\winupdates\winupdates.exe /auto [/b][/color] [color=#9933cc][b] O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm [/b][/color] [color=#9933cc][b] O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm … | |
Re: Can you please do the following. =============== Open a [b]command prompt[/b] by going to the start menu and then select 'Run'. In the box that pops up type in 'cmd'. The command prompt will open. OR You can go to Start -> Programs -> Accessories -> Command Prompt. Unregister the … | |
Re: [QUOTE=Al666]ok, i'm new here and all, anyways on my computer anything to do with hotmail won't work, like if i try to sign in on the hotmail page it says page can not be found, but if anyone tries on my computer it won't work, however if i try on … | |
Re: [b]First of all we have to remove Newdotnet,[/b] either from add/remove programs, or by going [url=http://www.newdotnet.com/removal.html][u]here[/u][/url] and scrolling down to the uninstall tool. You are running hijackthis from a temporary folder. You need to create a new folder in a permanent directory of your choice, (a folder on the desktop … | |
Re: ziggy_z1, Hi and welcome to the Daniweb forums :). =============== Please visit at least two of the following sites for an online virus scan: BitDefender Free Online Virus Scan [url]http://www.bitdefender.com/scan/licence.php[/url] Make sure you tick [b]AutoClean[/b] under [b]Scan Options.[/b] Panda ActiveScan [url]http://www.pandasoftware.com/activescan/com/activescan_principal.htm[/url] Make sure you tick [b]Disinfect automatically[/b] under [b]Scan Options.[/b] … | |
Re: Hi and welcome :). You only posted a partial log. Without the rest, the fix cannot go ahead. Please post another log in it's entirety. | |
Re: Hi ast5. Welcome to the Daniweb forums :). You are running hijackthis from a temporary folder. You need to create a new folder in a permanent directory of your choice, (a folder on the desktop is fine) name the new folder [b]hijackthis[/b] and move or unzip hijackthis.exe into that folder. … | |
Re: Hi. You are running hijackthis from a temporary folder. You need to create a new folder in a permanent directory of your choice, (a folder on the desktop is fine) name the new folder [b]hijackthis[/b] and move or unzip hijackthis.exe into that folder. Once you have done that, rescan with … | |
Re: Hi. Welcome to the Daniweb forums :). You are running hijackthis from a temporary folder. You need to create a new folder in a permanent directory of your choice, (a folder on the desktop is fine) name the new folder [b]hijackthis[/b] and move or unzip hijackthis.exe into that folder. == … | |
Re: Kevin, Hi and welcome to the Daniweb forums :). You are running hijackthis from a temporary folder. You need to create a new folder in a permanent directory of your choice, (a folder on the desktop is fine) name the new folder [b]hijackthis[/b] and move or unzip hijackthis.exe into that … | |
Re: You have some entries there that need removing. =============== Please visit at least two of the following sites for an online virus scan: BitDefender Free Online Virus Scan [url]http://www.bitdefender.com/scan/licence.php[/url] Make sure you tick [b]AutoClean[/b] under [b]Scan Options.[/b] Panda ActiveScan [url]http://www.pandasoftware.com/activescan/com/activescan_principal.htm[/url] Make sure you tick [b]Disinfect automatically[/b] under [b]Scan Options.[/b] Housecall … | |
Re: Sure can fix it :D. Please print these instructions out for use in Safe Mode. Please download [url=http://www.atribune.org/downloads/VundoFix.exe][b][color=red]VundoFix.exe[/color][/b][/url] to your desktop.[list] [*]Double-click [b]VundoFix.exe[/b] to extract the files [*]This will create a [b]VundoFix[/b] folder on your desktop. [*]After the files are extracted, please reboot your computer into [b]Safe Mode[/b]. You can … | |
Re: Download L2mfix from one of these two locations: [url]http://www.atribune.org/downloads/l2mfix.exe[/url] [url]http://www.downloads.subratam.org/l2mfix.exe[/url] Save the file to your desktop and double click l2mfix.exe. Click the Install button to extract the files and follow the prompts, then open the newly added l2mfix folder on your desktop. Double click l2mfix.bat and select option #1 for … | |
Re: Hi and welcome to Daniweb :). Run [b]HiJackThis,[/b] click "[b][i]Scan[/i][/b]", then check(tick) the following, if present: [color=#9933cc][b] O4 - HKLM\..\Run: [Microsoft Windows DLL Services Configuration] windir32.exe [/b][/color] [color=#9933cc][b] O4 - HKLM\..\RunServices: [Microsoft Windows DLL Services Configuration] windir32.exe [/b][/color] Now, close [b]all[/b] instances of Internet Explorer and any other windows you … | |
Re: [url]http://www.sophos.com/virusinfo/analyses/w32sdbotadf.html[/url] You may post an hijackthis if you wish? | |
Re: Can you post a hijackthis log taken immediately after a reboot and without removing anything from it please. | |
Re: Close all (browser) windows & rescan with hijackthis. When the scan is finished place a check in the box to the left of the following entries= O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file) O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file) O4 - Startup: PowerReg … | |
Re: Download [color=blue][b]CWShredder 2.15[/b][/color] from [url=http://www.intermute.com/products/cwshredder.html][u]here.[/u][/url] Run it and press the *fix,* not scan and allow it to clean the infection. [b]Close [color=red]all[/color] browser and explorer windows before hitting the fix button.[/b] =============== Download AboutBuster 5: [url=http://www.besttechie.net/tools/AboutBuster5.zip]http://www.besttechie.net/tools/AboutBuster5.zip[/url] [url=http://www.malwarebytes.biz/AboutBuster5.zip]http://www.malwarebytes.biz/AboutBuster5.zip[/url] Once downloaded, unzip it, and put the folder on your desktop. Then double-click … | |
Re: Please download the trial version of Ewido Security Suite here: [url]http://www.ewido.net/en/download/[/url] Install it, and update the definitions to the newest files. Do NOT run a scan yet. Please download Nailfix from here: [url]http://www.noidea.us/easyfile/file.php?download=20050515010747824[/url] Unzip it to the desktop but please do NOT run it yet. Next, please reboot your computer … | |
Re: Hi Chronica111 and welcome to Daniweb forums :). You only posted half the log :D. Please rescan with hijackthis and post again. Make certain it is running from a permanent folder too :). == Please visit at least two of the following sites for an online virus scan: BitDefender Free … | |
Re: Hi and welcome to Daniweb forums :). Try the following and see if they help; Download and run Winsockfix from here [url]http://www.softpedia.com/get/Tweak/Network-Tweak/WinSockFix.shtml[/url] == Try running [url=http://windowsxp.mvps.org/IEFIX.htm][color=blue]IEFIX.htm[/color][/url] which will repair IE and run a System File Check. | |
Re: You have some entries there that need removing. =============== First of all could you click Start>Settings>Control Panel>Add or Remove Programs and uninstall 'Window Search', 'Window Searching', 'Lop.com', 'LOP SEARCH', 'Browser Enhancer', or 'Ultimate Browser Enhancer' if listed. You may be given a code to insert, do so and reboot when … | |
Re: Click [url=http://www.geekstogo.com/modules.php?modid=5&action=download&id=4]here[/url] to download Killbox by Option^Explicit. *Extract the program to your desktop and double-click on its folder, then double-click on Killbox.exe to start the program. *In the killbox program, select the [b]Delete on Reboot[/b] option. *Copy the file names below to the clipboard by highlighting them and pressing Control-C: … | |
Re: [b]Download [color=blue]HijackThis[/color] [b][color=red]self-extracting[/color][/b] zip version from [url=http://www.malwareremoval.com/downloads.html][u]here.[/u][/url][/b] Once downloaded, double click on the file & it will install into it's own, permanent folder. Start HJT & press the "Do a system scan and save a log file" button. When the scan is finished a window will pop up giving you … | |
Re: You may want to print out these instructions for reference, since you will have to restart your computer during the fix. Please download FixWareout from one of these sites: [url]http://forums.subratam.org/index.php?act=Attach&type=post&id=43811[/url] [url]http://swandog46.geekstogo.com/Fixwareout.exe[/url] Save it to your desktop and run it. Click Next, then Install, then make sure "Run fixit" is checked … | |
Re: gazzabhoy, Hi and welcome to the Daniweb forums :). =============== Please visit at least two of the following sites for an online virus scan: BitDefender Free Online Virus Scan [url]http://www.bitdefender.com/scan/licence.php[/url] Make sure you tick [b]AutoClean[/b] under [b]Scan Options.[/b] Panda ActiveScan [url]http://www.pandasoftware.com/activescan/com/activescan_principal.htm[/url] Make sure you tick [b]Disinfect automatically[/b] under [b]Scan Options.[/b] … | |
Re: You may want to print or save these instructions locally before starting. Please download, install, and update the free version of [url=http://www.ewido.net/en/download/]Ewido trojan scanner[/url]: [list=1] [*]When installing, under "Additional Options" [b]uncheck[/b] "Install background guard" and "Install scan via context menu". [*]Run Ewido --- When you run it for the first … | |
Re: Original, Hi and welcome to the Daniweb forums :). =============== When we're done cleaning off your system, I'd [b]recommend[/b] that you install all the [color=#ff0000][b][i]critical windows updates[/i][/b][/color] available from [b]Microsoft[/b], up to [i]service pack 1[/i]. This will help to make your system more secure and prevent many '[i]problems[/i]' from reoccurring … | |
Re: Each file name is random so must be input correctly. The fix is the same. Post your log if you wish. | |
Re: Download [color=blue][b]CWShredder 2.15[/b][/color] from [url=http://www.intermute.com/products/cwshredder.html][u]here.[/u][/url] Run it and press the *fix,* not scan and allow it to clean the infection. [b]Close [color=red]all[/color] browser and explorer windows before hitting the fix button.[/b] =============== Please download the trial version of Ewido Security Suite here: [url]http://www.ewido.net/en/download/[/url] Install it, and update the definitions to … | |
Re: juliab, hi and welcome to Daniweb :). Download Itty Bitty Process Manager (IBProcMan.zip)(direct download) [url]http://www.merijn.org/files/ibprocman.zip[/url] Run the process manager. Near the top right there are a couple of icons. Select the one to the left to copy to the clipboard. Paste the results back here. Please do that in normal … | |
Re: Hi jmkthetruth. Got a few nasties there so we probably will not get them fixed up in one hit. =============== Run the PurityScan [url=http://www.purityscan.com/uninstall.html][u]uninstaller.[/u][/url] =============== Go to [url=http://www.trendmicro.com/en/home/us/enterprise.htm]www.trendmicro.com[/url], and then: 1. Click "[b][i]Free Online Scan[/i][/b]". 2. Click "[b][i]Scan now, it's free[/i][/b]". It'll take a few minutes to download (especially with … | |
Re: Don't give up your day job Danny :D | |
Re: Please go [url=http://windowsupdate.microsoft.com/][u]here[/u][/url] & install ALL critical updates required for your system, including service pack 1a for both XP and IE6. Most malware is designed to attack unpatched XP systems - exploiting the available 'holes' - and can bypass third-party protection on an unpatched system. The most that can be … | |
Re: Please download miekiemoes' LQfix batch here: [url]http://www.downloads.subratam.org/LQfix.zip[/url] Unzip it to the desktop but do NOT run it yet. It may be best to to right click on the link and select 'Save As' and save it to your desk top. Next, please reboot your computer in Safe Mode by doing … |
The End.