4,383 Posted Topics
Re: [b]Download [color=blue]HijackThis[/color] [b][color=red][SIZE=3]self-extracting[/SIZE][/color][/b] zip version from [url=http://www.malwareremoval.com/downloads.html][u]here.[/u][/url][/b] Once downloaded, double click on the file & it will install into it's own, permanent folder. Start HJT & press the "Do a system scan and save a log file" button. When the scan is finished a window will pop up giving you … | |
Re: Please download the trial version of Ewido Security Suite here: [url]http://www.ewido.net/en/download/[/url] Install it, and update the definitions to the newest files. Do NOT run a scan yet. Please download Nailfix from here: [url]http://www.dknoppix.com/cgi-bin/download.cgi?Nailfix[/url] Unzip it to the desktop but please do NOT run it yet. Next, please reboot your computer … | |
Re: Do you have service pack 1 for IE6? If not, install it and see if it helps. | |
Re: C:/WINDOWS\System32\[b]w?nlogon.exe[/b] is a PurityScan entry. Run the PurityScan [url=http://www.purityscan.com/uninstall.html][u]uninstaller.[/u][/url] -- Download L2mfix from one of these two locations: [url]http://www.atribune.org/downloads/l2mfix.exe[/url] [url]http://www.downloads.subratam.org/l2mfix.exe[/url] Save the file to your desktop and double click l2mfix.exe. Click the Install button to extract the files and follow the prompts, then open the newly added l2mfix folder on … | |
Re: Muffi. Moving you to your own thread :). Before manually editing the registry always back it up. On Windows ME and XP creating a Restore Point will do. Click Start > Run > Type or copy & paste regedit. The registry editor will open. Then go to HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall and delete … | |
Re: [url]http://www.daniweb.com/techtalkforums/thread24085.html[/url] Please download the trial version of Ewido Security Suite here: [url]http://www.ewido.net/en/download/[/url] Install it, and update the definitions to the newest files. Do NOT run a scan yet. Please download Nailfix from here: [url]http://users.pandora.be/bluepatchy/nailfix.exe[/url] It will self-extract to the desktop, but please do NOT run it yet. Next, please reboot … | |
Re: You have a few things there that need removing... =============== Go to [url=http://www.trendmicro.com/en/home/us/enterprise.htm]www.trendmicro.com[/url], and then: 1. Click "[b][i]Free Online Scan[/i][/b]". 2. Click "[b][i]Scan now, it's free[/i][/b]". It'll take a few minutes to download (especially with a dialup connection), so be patient. When it's down: 1. Select all available drives. 2. … | |
Re: Hi and welcome to Daniweb :). Download The ABI remover (Better Internet Remover) [url]http://andymanchesta.com/Downloads/ABIremover.zip[/url] Download the Remover to your desktop. Unzip the file to your desktop. Start the ABIRemover.exe, press install, wait (explorer window will disapear). Click finish when done. - Run [b]HiJackThis[/b] then: 1. Click "[b][i]Open the Misc Tools … | |
Re: I wouldn't imagine you would have to reinstall for these problems. Sorry that your last thread was overlooked. It get's pretty busy around here. =============== Run [b]HiJackThis[/b] then: 1. Click "[b][i]Open the Misc Tools Section[/i][/b]" 2. Click "[b][i]Open Process manager[/i][/b]" - Next, while holding down the [b]CTRL[/b] key, locate ([i]if … | |
Re: Download the [url=http://www.bleepingcomputer.com/files/spyware/KillBox.zip][color=blue]Pocket KillBox[/color][/url] Unzip the file to your desktop. [color=red]Go offline until you have completed all the below.[/color] Run Pocket Killbox and paste the full file path of each of the below files in the box and click on Standard File Kill and End Explorer Shell While Killing File. … | |
Re: Sunderlandgav, Hello! and welcome to the Daniweb forums. - Download, then unzip to "[b]C:\HJT[/b]", the newest version of [url=http://www.spywareinfo.com/~merijn/files/hijackthis.zip]HiJackThis[/url]; [i]version 1.99.1[/i]. Then repost your log, either now, or after following the steps in the solution ([i]if provided in this post[/i]). [color=#ff0000][i]This version has features that might be more helpful in … | |
Re: tedward1986, Hello! and welcome to the Daniweb forums :). =============== Go to [b]Add/Remove programs[/b] and remove(uninstall) the following, if present: [b][color=#ff0000]NewDotNet[/color][/b] [b][color=#ff0000]Virtual Bouncer[/color][/b] The above could appear anywhere within the entry. Be careful not to remove any [i]personal[/i] or [i]system[/i] software. =============== Go to [url=http://www.trendmicro.com/en/home/us/enterprise.htm]www.trendmicro.com[/url], and then: 1. Click "[b][i]Free … | |
Re: icyboi_1988, Hi and welcome to the Daniweb forums :). =============== Go to [b]Add/Remove programs[/b] and remove(uninstall) the following, if present: [b][color=#ff0000]180 Solutions[/color][/b] [b][color=#ff0000]WebHancer[/color][/b] The above could appear anywhere within the entry. Be careful not to remove any [i]personal[/i] or [i]system[/i] software. =============== Run [b]HiJackThis,[/b] click "[b][i]Scan[/i][/b]", then check(tick) the following, … | |
Re: From revenuepilot. I know nothing of it except that it's a pay per click search engine. Post an hijackthis log and we will take a look, if you wish? If you do, make sure that hijackthis is in a permanent folder before posting. Thread at top of forum links to … | |
Re: Run the PurityScan [url=http://www.purityscan.com/uninstall.html][u]uninstaller.[/u][/url] =============== Run [b]HiJackThis,[/b] click "[b][i]Scan[/i][/b]", then check(tick) the following, if present: [color=#9933cc][b] R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = [/b][/color] [color=#9933cc][b] R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = [/b][/color] [color=#9933cc][b] R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = [/b][/color] [color=#9933cc][b] O2 - BHO: ToolHelper - {CDEEC43D-3572-4E95-A2A5-F519D29F00C0} - C:\PROGRA~1\ADVANC~1\Toolbar.dll (file missing) [/b][/color] [color=#9933cc][b] O3 … | |
Re: stephen hart. Hi and welcome to Daniweb forums :). [b]Download [color=blue]HijackThis[/color] [b][color=red][SIZE=4]selfextracting[/SIZE][/color][/b] zip version from [url=http://www.malwareremoval.com/downloads.html][u]here.[/u][/url][/b] Once downloaded, double click on the file & it will install into it's own, permanent folder. Start HJT & press the "Do a system scan and save a log file" button. When the scan … | |
Re: Please download Nailfix from here: [url]http://www.dknoppix.com/cgi-bin/download.cgi?Nailfix[/url] Continue the fix without the update. | |
Re: Cool. That's one of the best logs I've seen :mrgreen:. How you doin' Syracusevic? Welcome to Daniweb. Please visit at least two of the following sites for an online virus scan: BitDefender Free Online Virus Scan [url]http://www.bitdefender.com/scan/licence.php[/url] Make sure you tick [b]AutoClean[/b] under [b]Scan Options.[/b] Panda ActiveScan [url]http://www.pandasoftware.com/activescan/com/activescan_principal.htm[/url] Make sure … | |
Re: Hi Ladymercury. Please read this thread and we will go from there :). [url]http://www.daniweb.com/techtalkforums/thread24085.html[/url] | |
Re: [b]Congratulations![/b] [i]Your log looks clean[/i]! The contents of your prefetch folder can be deleted safely. =============== Now that your PC is clean you need to follow these easy steps to keeping it this way: [color=blue]Secure your Internet Explorer[/color] by going [url=http://bshagnasty.home.att.net/browsersettings.htm][u]here[/u][/url] and following the instructions there. [color=blue]Better yet, use an … | |
Re: [url]http://www.creationevolution.net/irreducible_complexity.htm[/url] An excellent read for those who believe in evolution. It may make you rethink? | |
Re: Download [color=blue][b]CWShredder 2.15[/b][/color] from [url=http://www.intermute.com/products/cwshredder.html][u]here.[/u][/url] Download[url=http://www.derbilk.de/SpSeHjfix109.zip]'SpSeHjfix'[/url] to the desktop and then right click a blank part of the desktop and select new folder, call it spfix unzip the file into that folder. [color=red]Disconnect from the net and Close ALL OPEN PROGRAMS.[/color] Run 'SpSeHjfix'. and click on "Start Disinfection". When it's … | |
Re: shaas, Hi and welcome to the Daniweb forums :). =============== Go to [url=http://www.trendmicro.com/en/home/us/enterprise.htm]www.trendmicro.com[/url], and then: 1. Click "[b][i]Free Online Scan[/i][/b]". 2. Click "[b][i]Scan now, it's free[/i][/b]". It'll take a few minutes to download (especially with a dialup connection), so be patient. When it's down: 1. Select all available drives. 2. … | |
Re: Please go [url=http://windowsupdate.microsoft.com/][u]here[/u][/url] & install ALL critical updates required for your system, including service pack 1a for both XP and IE6. Most malware is designed to attack unpatched XP systems - exploiting the available 'holes' - and can bypass third-party protection on an unpatched system. The most that can be … | |
Re: [url]http://www.dknoppix.com/cgi-bin/download.cgi?Nailfix[/url] | |
Re: Try right clicking on the file and select 'Save As.' Save it to your desktop and see if you can unzip it now. | |
Re: Please download the trial version of Ewido Security Suite here: [url]http://www.ewido.net/en/download/[/url] Install it, and update the definitions to the newest files. Do NOT run a scan yet. Please download Nailfix from here: [url]http://www.noidea.us/easyfile/file.php?download=20050515010747824[/url] Unzip it to the desktop but please do NOT run it yet. Next, please reboot your computer … | |
Re: [url]http://www.daniweb.com/techtalkforums/thread24085.html[/url] :) | |
Re: d-b, Hi and welcome to the Daniweb forums :). =============== Still in [b]HiJackThis,[/b] click "[b][i]Scan[/i][/b]", then check(tick) the following, if present: [color=#9933cc][b] R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = [url]http://red.clientapps.yahoo.com/cus...rch/search.html[/url] [/b][/color] [color=#9933cc][b] R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = [url]http://red.clientapps.yahoo.com/cus...//www.yahoo.com[/url] [/b][/color] [color=#9933cc][b] R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = [url]http://red.clientapps.yahoo.com/cus...//www.yahoo.com[/url] [/b][/color] [color=#9933cc][b] R1 - … | |
Re: You have some entries there that need removing. =============== Open a [b]command prompt[/b] by going to the start menu and then select 'Run'. In the box that pops up type in 'cmd'. The command prompt will open. OR You can go to Start -> Programs -> Accessories -> Command Prompt. … | |
Re: xinbic, Hi and welcome to the Daniweb forums :). =============== Download, then unzip to "[b]C:\HJT[/b]", the newest version of [url=http://www.spywareinfo.com/~merijn/files/hijackthis.zip]HiJackThis[/url]; [i]version 1.99.1[/i]. Then repost your log, either now, or after following the steps in the solution ([i]if provided in this post[/i]). [color=#ff0000][i]This version has features that might be more helpful … | |
Re: Only posted half the log there :). The nail fix has now been updated. Please download the trial version of Ewido Security Suite here: [url]http://www.ewido.net/en/download/[/url] Install it, and update the definitions to the newest files. Do NOT run a scan yet. Please download Nailfix from here: [url]http://www.noidea.us/easyfile/file.php?download=20050515010747824[/url] Unzip it to … | |
Re: Please download the trial version of Ewido Security Suite here: [url]http://www.ewido.net/en/download/[/url] Install it, and update the definitions to the newest files. Do NOT run a scan yet. Please download Nailfix from here: [url]http://www.noidea.us/easyfile/file.php?download=20050515010747824[/url] Unzip it to the desktop but please do NOT run it yet. Next, please reboot your computer … | |
Re: First up, I cannot see where hijackthis is running from. This is important, so please let me know. It should show in the log. Second. Unless you get service pack 4 for W2K and install IE6 with service pack 1, you stand an excellent chance of being instantly reinfected. Please … | |
Re: supazook. Hi and welcome to Daniweb :). You will need to move hijackthis into it's own, permanent folder before we go ahead and start your clean up. You can create a new folder on your desktop and move hijackthis there, if you wish. | |
Re: Hi and welcome to Daniweb :). Please read this thread; [url]http://www.daniweb.com/techtalkforums/thread24085.html[/url] | |
Re: Hi. Not much there at all :).. =============== Run [b]HiJackThis,[/b] click "[b][i]Scan[/i][/b]", then check(tick) the following, if present: [color=#9933cc][b] R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = [url]http://red.clientapps.yahoo.com/cus.../search/ie.html[/url] [/b][/color] [color=#9933cc][b] R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = [url]http://red.clientapps.yahoo.com/cus...//www.yahoo.com[/url] [/b][/color] [color=#9933cc][b] R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = [url]http://red.clientapps.yahoo.com/cus...//www.yahoo.com[/url] [/b][/color] Now, with all windows closed (including … | |
Re: Please download the trial version of Ewido Security Suite here: [url]http://www.ewido.net/en/download/[/url] Install it, and update the definitions to the newest files. Do NOT run a scan yet. Please download Nailfix from here: [url]http://www.noidea.us/easyfile/file.php?download=20050515010747824[/url] Unzip it to the desktop but please do NOT run it yet. Next, please reboot your computer … | |
Re: Download [url]http://www.downloads.subratam.org/KillBox.exe[/url] Stay [b]offline[/b] when doing the following fix. Open killbox and paste in [b]C:\WINDOWS\SYSTEM32\akicap32.dll[/b] With the full path to the file name in the topmost textbox, click the option *replace on reboot* and *Use Dummy* which will create a numbered dummy file instantly for you. Click the Red X … | |
Re: First of all could you click Start>Settings>Control Panel>Add or Remove Programs and uninstall 'Window Search', 'Window Searching', 'Lop.com', 'LOP SEARCH', 'Browser Enhancer', or 'Ultimate Browser Enhancer' if listed. You may be given a code to insert, do so and reboot when done. If not listed there, run the [color=blue]Lop Remover[/color] … | |
Re: Please download the trial version of Ewido Security Suite here: [url]http://www.ewido.net/en/download/[/url] Install it, and update the definitions to the newest files. Do NOT run a scan yet. Please download Nailfix from here: [url]http://www.noidea.us/easyfile/file.php?download=20050515010747824[/url] Unzip it to the desktop but please do NOT run it yet. Next, please reboot your computer … | |
Re: mjjack, Hi and welcome to the Daniweb forums :). =============== When we're done cleaning off your system, I'd [b]recommend[/b] that you install all the [color=#ff0000][b][i]critical windows updates[/i][/b][/color] available from [b]Microsoft[/b], up to [i]service pack 1[/i]. This will help to make your system more secure and prevent many '[i]problems[/i]' from reoccurring … | |
Re: You have some entries there that need removing. =============== Next, we need to remove(uninstall) the 'lop' infection by going to [url=http://66.220.17.157/help.html]here[/url], then downloading and running the uninstaller(s) that relate to the application(s) your wanting to remove. The following selections are available: "[b][color=#ff0000]Start page[/color][/b]", "[b][color=#ff0000]Search engine[/color][/b]", "[b][color=#ff0000]Accessories Toolbar[/color][/b]". After uninstalling any … | |
Re: Hi and welcome to Daniweb julie :). [b]Download [color=blue]HijackThis[/color] [b][color=red][SIZE=3]selfextracting[/SIZE][/color][/b] zip version from [url=http://www.malwareremoval.com/downloads.html][u]here.[/u][/url][/b] Once downloaded, double click on the file & it will install into it's own, permanent folder. Start HJT & press the "Do a system scan and save a log file" button. When the scan is finished … | |
Re: You obviously did not get the self-extracting version :). [url]http://www.daniweb.com/techtalkforums/thread24085.html[/url] | |
Re: Please move hijackthis into it's own folder and then rescan and post the new log. [b]Go [url=http://housecall.trendmicro.com/][u]here[/u][/url] to TrendMicro for an on-line scan & set it to autoclean for you. When it completes, post back the full filename of any files that cannot be cleaned or deleted. Try [URL=http://www.pandasoftware.com/activescan/com/activescan_principal.htm][u]this[/u][/URL] scan … | |
Re: stemp65, Hi and welcome to the Daniweb forums :). =============== We'll need to unload (not uninstall) [b]Intermute's SpySubtract[/b], since it might interfere with other program(s) we might be using to 'clean' off your system. =============== If you haven't run [b]HouseCall[/b] lately, let's go back to [url=http://www.trendmicro.com/en/home/us/enterprise.htm]www.trendmicro.com[/url], download the latest definitions, … | |
Re: You have some entries there that need removing. =============== Go to [url=http://www.trendmicro.com/en/home/us/enterprise.htm]www.trendmicro.com[/url], and then: 1. Click "[b][i]Free Online Scan[/i][/b]". 2. Click "[b][i]Scan now, it's free[/i][/b]". It'll take a few minutes to download (especially with a dialup connection), so be patient. When it's down: 1. Select all available drives. 2. Check(tick) … | |
Re: Hi and welcome to Daniweb :). - Please run Notepad and copy the following text into a new file: [quote]@ECHO OFF cd %windir% Nail.exe /FULLREMOVE sc config SvcProc start= disabled sc stop SvcProc sc delete SvcProc attrib -s -r -h nail.exe attrib -s -r -h svcproc.exe del nail.exe del svcproc.exe … |
The End.