4,383 Posted Topics

Member Avatar for thatboialex

[b]Download [color=blue]HijackThis[/color] [b][color=red][SIZE=3]self-extracting[/SIZE][/color][/b] zip version from [url=http://www.malwareremoval.com/downloads.html][u]here.[/u][/url][/b] Once downloaded, double click on the file & it will install into it's own, permanent folder. Start HJT & press the "Do a system scan and save a log file" button. When the scan is finished a window will pop up giving you …

Member Avatar for crunchie
0
437
Member Avatar for tgober

Please download the trial version of Ewido Security Suite here: [url]http://www.ewido.net/en/download/[/url] Install it, and update the definitions to the newest files. Do NOT run a scan yet. Please download Nailfix from here: [url]http://www.dknoppix.com/cgi-bin/download.cgi?Nailfix[/url] Unzip it to the desktop but please do NOT run it yet. Next, please reboot your computer …

Member Avatar for DMR
0
595
Member Avatar for afinepoint
Member Avatar for afinepoint
0
631
Member Avatar for kashres

C:/WINDOWS\System32\[b]w?nlogon.exe[/b] is a PurityScan entry. Run the PurityScan [url=http://www.purityscan.com/uninstall.html][u]uninstaller.[/u][/url] -- Download L2mfix from one of these two locations: [url]http://www.atribune.org/downloads/l2mfix.exe[/url] [url]http://www.downloads.subratam.org/l2mfix.exe[/url] Save the file to your desktop and double click l2mfix.exe. Click the Install button to extract the files and follow the prompts, then open the newly added l2mfix folder on …

Member Avatar for DMR
0
466
Member Avatar for Muffi

Muffi. Moving you to your own thread :). Before manually editing the registry always back it up. On Windows ME and XP creating a Restore Point will do. Click Start > Run > Type or copy & paste regedit. The registry editor will open. Then go to HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall and delete …

Member Avatar for techniner
0
76
Member Avatar for Disco Stu

[url]http://www.daniweb.com/techtalkforums/thread24085.html[/url] Please download the trial version of Ewido Security Suite here: [url]http://www.ewido.net/en/download/[/url] Install it, and update the definitions to the newest files. Do NOT run a scan yet. Please download Nailfix from here: [url]http://users.pandora.be/bluepatchy/nailfix.exe[/url] It will self-extract to the desktop, but please do NOT run it yet. Next, please reboot …

Member Avatar for crunchie
0
223
Member Avatar for Latinflo

You have a few things there that need removing... =============== Go to [url=http://www.trendmicro.com/en/home/us/enterprise.htm]www.trendmicro.com[/url], and then: 1. Click "[b][i]Free Online Scan[/i][/b]". 2. Click "[b][i]Scan now, it's free[/i][/b]". It'll take a few minutes to download (especially with a dialup connection), so be patient. When it's down: 1. Select all available drives. 2. …

Member Avatar for dlh6213
0
571
Member Avatar for rkaradi

Hi and welcome to Daniweb :). Download The ABI remover (Better Internet Remover) [url]http://andymanchesta.com/Downloads/ABIremover.zip[/url] Download the Remover to your desktop. Unzip the file to your desktop. Start the ABIRemover.exe, press install, wait (explorer window will disapear). Click finish when done. - Run [b]HiJackThis[/b] then: 1. Click "[b][i]Open the Misc Tools …

Member Avatar for DMR
0
560
Member Avatar for rkerner

I wouldn't imagine you would have to reinstall for these problems. Sorry that your last thread was overlooked. It get's pretty busy around here. =============== Run [b]HiJackThis[/b] then: 1. Click "[b][i]Open the Misc Tools Section[/i][/b]" 2. Click "[b][i]Open Process manager[/i][/b]" - Next, while holding down the [b]CTRL[/b] key, locate ([i]if …

Member Avatar for rkerner
0
361
Member Avatar for zhangzheng2

Download the [url=http://www.bleepingcomputer.com/files/spyware/KillBox.zip][color=blue]Pocket KillBox[/color][/url] Unzip the file to your desktop. [color=red]Go offline until you have completed all the below.[/color] Run Pocket Killbox and paste the full file path of each of the below files in the box and click on Standard File Kill and End Explorer Shell While Killing File. …

Member Avatar for crunchie
0
185
Member Avatar for Sunderlandgav

Sunderlandgav, Hello! and welcome to the Daniweb forums. - Download, then unzip to "[b]C:\HJT[/b]", the newest version of [url=http://www.spywareinfo.com/~merijn/files/hijackthis.zip]HiJackThis[/url]; [i]version 1.99.1[/i]. Then repost your log, either now, or after following the steps in the solution ([i]if provided in this post[/i]). [color=#ff0000][i]This version has features that might be more helpful in …

Member Avatar for crunchie
0
220
Member Avatar for tedward1986

tedward1986, Hello! and welcome to the Daniweb forums :). =============== Go to [b]Add/Remove programs[/b] and remove(uninstall) the following, if present: [b][color=#ff0000]NewDotNet[/color][/b] [b][color=#ff0000]Virtual Bouncer[/color][/b] The above could appear anywhere within the entry. Be careful not to remove any [i]personal[/i] or [i]system[/i] software. =============== Go to [url=http://www.trendmicro.com/en/home/us/enterprise.htm]www.trendmicro.com[/url], and then: 1. Click "[b][i]Free …

Member Avatar for DMR
0
451
Member Avatar for icyboi_1988

icyboi_1988, Hi and welcome to the Daniweb forums :). =============== Go to [b]Add/Remove programs[/b] and remove(uninstall) the following, if present: [b][color=#ff0000]180 Solutions[/color][/b] [b][color=#ff0000]WebHancer[/color][/b] The above could appear anywhere within the entry. Be careful not to remove any [i]personal[/i] or [i]system[/i] software. =============== Run [b]HiJackThis,[/b] click "[b][i]Scan[/i][/b]", then check(tick) the following, …

Member Avatar for crunchie
0
118
Member Avatar for thecageeffect

From revenuepilot. I know nothing of it except that it's a pay per click search engine. Post an hijackthis log and we will take a look, if you wish? If you do, make sure that hijackthis is in a permanent folder before posting. Thread at top of forum links to …

Member Avatar for crunchie
0
148
Member Avatar for jol102001

Run the PurityScan [url=http://www.purityscan.com/uninstall.html][u]uninstaller.[/u][/url] =============== Run [b]HiJackThis,[/b] click "[b][i]Scan[/i][/b]", then check(tick) the following, if present: [color=#9933cc][b] R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = [/b][/color] [color=#9933cc][b] R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = [/b][/color] [color=#9933cc][b] R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = [/b][/color] [color=#9933cc][b] O2 - BHO: ToolHelper - {CDEEC43D-3572-4E95-A2A5-F519D29F00C0} - C:\PROGRA~1\ADVANC~1\Toolbar.dll (file missing) [/b][/color] [color=#9933cc][b] O3 …

Member Avatar for DMR
0
321
Member Avatar for stephen hart

stephen hart. Hi and welcome to Daniweb forums :). [b]Download [color=blue]HijackThis[/color] [b][color=red][SIZE=4]selfextracting[/SIZE][/color][/b] zip version from [url=http://www.malwareremoval.com/downloads.html][u]here.[/u][/url][/b] Once downloaded, double click on the file & it will install into it's own, permanent folder. Start HJT & press the "Do a system scan and save a log file" button. When the scan …

Member Avatar for crunchie
0
105
Member Avatar for waterbottle247

Please download Nailfix from here: [url]http://www.dknoppix.com/cgi-bin/download.cgi?Nailfix[/url] Continue the fix without the update.

Member Avatar for crunchie
0
158
Member Avatar for SYRACUSEVIC

Cool. That's one of the best logs I've seen :mrgreen:. How you doin' Syracusevic? Welcome to Daniweb. Please visit at least two of the following sites for an online virus scan: BitDefender Free Online Virus Scan [url]http://www.bitdefender.com/scan/licence.php[/url] Make sure you tick [b]AutoClean[/b] under [b]Scan Options.[/b] Panda ActiveScan [url]http://www.pandasoftware.com/activescan/com/activescan_principal.htm[/url] Make sure …

Member Avatar for crunchie
0
222
Member Avatar for Ladymercury

Hi Ladymercury. Please read this thread and we will go from there :). [url]http://www.daniweb.com/techtalkforums/thread24085.html[/url]

Member Avatar for crunchie
0
224
Member Avatar for moyon_x

[b]Congratulations![/b] [i]Your log looks clean[/i]! The contents of your prefetch folder can be deleted safely. =============== Now that your PC is clean you need to follow these easy steps to keeping it this way: [color=blue]Secure your Internet Explorer[/color] by going [url=http://bshagnasty.home.att.net/browsersettings.htm][u]here[/u][/url] and following the instructions there. [color=blue]Better yet, use an …

Member Avatar for DMR
0
581
Member Avatar for Asif_NSU

[url]http://www.creationevolution.net/irreducible_complexity.htm[/url] An excellent read for those who believe in evolution. It may make you rethink?

Member Avatar for jwenting
0
2K
Member Avatar for hetixo

Download [color=blue][b]CWShredder 2.15[/b][/color] from [url=http://www.intermute.com/products/cwshredder.html][u]here.[/u][/url] Download[url=http://www.derbilk.de/SpSeHjfix109.zip]'SpSeHjfix'[/url] to the desktop and then right click a blank part of the desktop and select new folder, call it spfix unzip the file into that folder. [color=red]Disconnect from the net and Close ALL OPEN PROGRAMS.[/color] Run 'SpSeHjfix'. and click on "Start Disinfection". When it's …

Member Avatar for crunchie
0
228
Member Avatar for shaas

shaas, Hi and welcome to the Daniweb forums :). =============== Go to [url=http://www.trendmicro.com/en/home/us/enterprise.htm]www.trendmicro.com[/url], and then: 1. Click "[b][i]Free Online Scan[/i][/b]". 2. Click "[b][i]Scan now, it's free[/i][/b]". It'll take a few minutes to download (especially with a dialup connection), so be patient. When it's down: 1. Select all available drives. 2. …

Member Avatar for crunchie
0
154
Member Avatar for matthell

Please go [url=http://windowsupdate.microsoft.com/][u]here[/u][/url] & install ALL critical updates required for your system, including service pack 1a for both XP and IE6. Most malware is designed to attack unpatched XP systems - exploiting the available 'holes' - and can bypass third-party protection on an unpatched system. The most that can be …

Member Avatar for crunchie
0
423
Member Avatar for Raymond Thang
Member Avatar for Kirsty

Try right clicking on the file and select 'Save As.' Save it to your desktop and see if you can unzip it now.

Member Avatar for DMR
0
414
Member Avatar for audiooutloud

Please download the trial version of Ewido Security Suite here: [url]http://www.ewido.net/en/download/[/url] Install it, and update the definitions to the newest files. Do NOT run a scan yet. Please download Nailfix from here: [url]http://www.noidea.us/easyfile/file.php?download=20050515010747824[/url] Unzip it to the desktop but please do NOT run it yet. Next, please reboot your computer …

Member Avatar for crunchie
0
178
Member Avatar for leonz_ecko
Member Avatar for d-b

d-b, Hi and welcome to the Daniweb forums :). =============== Still in [b]HiJackThis,[/b] click "[b][i]Scan[/i][/b]", then check(tick) the following, if present: [color=#9933cc][b] R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = [url]http://red.clientapps.yahoo.com/cus...rch/search.html[/url] [/b][/color] [color=#9933cc][b] R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = [url]http://red.clientapps.yahoo.com/cus...//www.yahoo.com[/url] [/b][/color] [color=#9933cc][b] R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = [url]http://red.clientapps.yahoo.com/cus...//www.yahoo.com[/url] [/b][/color] [color=#9933cc][b] R1 - …

Member Avatar for DMR
0
149
Member Avatar for midnightgirl

You have some entries there that need removing. =============== Open a [b]command prompt[/b] by going to the start menu and then select 'Run'. In the box that pops up type in 'cmd'. The command prompt will open. OR You can go to Start -> Programs -> Accessories -> Command Prompt. …

Member Avatar for DMR
0
224
Member Avatar for xinbic

xinbic, Hi and welcome to the Daniweb forums :). =============== Download, then unzip to "[b]C:\HJT[/b]", the newest version of [url=http://www.spywareinfo.com/~merijn/files/hijackthis.zip]HiJackThis[/url]; [i]version 1.99.1[/i]. Then repost your log, either now, or after following the steps in the solution ([i]if provided in this post[/i]). [color=#ff0000][i]This version has features that might be more helpful …

Member Avatar for DMR
0
509
Member Avatar for vsny2k5

Only posted half the log there :). The nail fix has now been updated. Please download the trial version of Ewido Security Suite here: [url]http://www.ewido.net/en/download/[/url] Install it, and update the definitions to the newest files. Do NOT run a scan yet. Please download Nailfix from here: [url]http://www.noidea.us/easyfile/file.php?download=20050515010747824[/url] Unzip it to …

Member Avatar for crunchie
0
374
Member Avatar for phidelt649

Please download the trial version of Ewido Security Suite here: [url]http://www.ewido.net/en/download/[/url] Install it, and update the definitions to the newest files. Do NOT run a scan yet. Please download Nailfix from here: [url]http://www.noidea.us/easyfile/file.php?download=20050515010747824[/url] Unzip it to the desktop but please do NOT run it yet. Next, please reboot your computer …

Member Avatar for crunchie
0
234
Member Avatar for nich

First up, I cannot see where hijackthis is running from. This is important, so please let me know. It should show in the log. Second. Unless you get service pack 4 for W2K and install IE6 with service pack 1, you stand an excellent chance of being instantly reinfected. Please …

Member Avatar for nich
0
298
Member Avatar for supazook

supazook. Hi and welcome to Daniweb :). You will need to move hijackthis into it's own, permanent folder before we go ahead and start your clean up. You can create a new folder on your desktop and move hijackthis there, if you wish.

Member Avatar for crunchie
0
221
Member Avatar for Mcfats
Member Avatar for danielcox123

Hi and welcome to Daniweb :). Please read this thread; [url]http://www.daniweb.com/techtalkforums/thread24085.html[/url]

Member Avatar for crunchie
0
180
Member Avatar for dbl03

Hi. Not much there at all :).. =============== Run [b]HiJackThis,[/b] click "[b][i]Scan[/i][/b]", then check(tick) the following, if present: [color=#9933cc][b] R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = [url]http://red.clientapps.yahoo.com/cus.../search/ie.html[/url] [/b][/color] [color=#9933cc][b] R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = [url]http://red.clientapps.yahoo.com/cus...//www.yahoo.com[/url] [/b][/color] [color=#9933cc][b] R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = [url]http://red.clientapps.yahoo.com/cus...//www.yahoo.com[/url] [/b][/color] Now, with all windows closed (including …

Member Avatar for crunchie
0
147
Member Avatar for Froot_loop04

Please download the trial version of Ewido Security Suite here: [url]http://www.ewido.net/en/download/[/url] Install it, and update the definitions to the newest files. Do NOT run a scan yet. Please download Nailfix from here: [url]http://www.noidea.us/easyfile/file.php?download=20050515010747824[/url] Unzip it to the desktop but please do NOT run it yet. Next, please reboot your computer …

Member Avatar for Froot_loop04
0
255
Member Avatar for kriskarrera

Download [url]http://www.downloads.subratam.org/KillBox.exe[/url] Stay [b]offline[/b] when doing the following fix. Open killbox and paste in [b]C:\WINDOWS\SYSTEM32\akicap32.dll[/b] With the full path to the file name in the topmost textbox, click the option *replace on reboot* and *Use Dummy* which will create a numbered dummy file instantly for you. Click the Red X …

Member Avatar for crunchie
0
271
Member Avatar for -Johnny C Bad-

First of all could you click Start>Settings>Control Panel>Add or Remove Programs and uninstall 'Window Search', 'Window Searching', 'Lop.com', 'LOP SEARCH', 'Browser Enhancer', or 'Ultimate Browser Enhancer' if listed. You may be given a code to insert, do so and reboot when done. If not listed there, run the [color=blue]Lop Remover[/color] …

Member Avatar for crunchie
0
126
Member Avatar for penelopeghiruto

Please download the trial version of Ewido Security Suite here: [url]http://www.ewido.net/en/download/[/url] Install it, and update the definitions to the newest files. Do NOT run a scan yet. Please download Nailfix from here: [url]http://www.noidea.us/easyfile/file.php?download=20050515010747824[/url] Unzip it to the desktop but please do NOT run it yet. Next, please reboot your computer …

Member Avatar for crunchie
0
269
Member Avatar for mjjack

mjjack, Hi and welcome to the Daniweb forums :). =============== When we're done cleaning off your system, I'd [b]recommend[/b] that you install all the [color=#ff0000][b][i]critical windows updates[/i][/b][/color] available from [b]Microsoft[/b], up to [i]service pack 1[/i]. This will help to make your system more secure and prevent many '[i]problems[/i]' from reoccurring …

Member Avatar for crunchie
0
182
Member Avatar for CondorSpyrit

You have some entries there that need removing. =============== Next, we need to remove(uninstall) the 'lop' infection by going to [url=http://66.220.17.157/help.html]here[/url], then downloading and running the uninstaller(s) that relate to the application(s) your wanting to remove. The following selections are available: "[b][color=#ff0000]Start page[/color][/b]", "[b][color=#ff0000]Search engine[/color][/b]", "[b][color=#ff0000]Accessories Toolbar[/color][/b]". After uninstalling any …

Member Avatar for crunchie
0
346
Member Avatar for jalmercedes

Hi and welcome to Daniweb julie :). [b]Download [color=blue]HijackThis[/color] [b][color=red][SIZE=3]selfextracting[/SIZE][/color][/b] zip version from [url=http://www.malwareremoval.com/downloads.html][u]here.[/u][/url][/b] Once downloaded, double click on the file & it will install into it's own, permanent folder. Start HJT & press the "Do a system scan and save a log file" button. When the scan is finished …

Member Avatar for jalmercedes
0
270
Member Avatar for boomsy

You obviously did not get the self-extracting version :). [url]http://www.daniweb.com/techtalkforums/thread24085.html[/url]

Member Avatar for crunchie
0
131
Member Avatar for gooner

Please move hijackthis into it's own folder and then rescan and post the new log. [b]Go [url=http://housecall.trendmicro.com/][u]here[/u][/url] to TrendMicro for an on-line scan & set it to autoclean for you. When it completes, post back the full filename of any files that cannot be cleaned or deleted. Try [URL=http://www.pandasoftware.com/activescan/com/activescan_principal.htm][u]this[/u][/URL] scan …

Member Avatar for gooner
0
159
Member Avatar for stemp65

stemp65, Hi and welcome to the Daniweb forums :). =============== We'll need to unload (not uninstall) [b]Intermute's SpySubtract[/b], since it might interfere with other program(s) we might be using to 'clean' off your system. =============== If you haven't run [b]HouseCall[/b] lately, let's go back to [url=http://www.trendmicro.com/en/home/us/enterprise.htm]www.trendmicro.com[/url], download the latest definitions, …

Member Avatar for crunchie
0
194
Member Avatar for grindking

You have some entries there that need removing. =============== Go to [url=http://www.trendmicro.com/en/home/us/enterprise.htm]www.trendmicro.com[/url], and then: 1. Click "[b][i]Free Online Scan[/i][/b]". 2. Click "[b][i]Scan now, it's free[/i][/b]". It'll take a few minutes to download (especially with a dialup connection), so be patient. When it's down: 1. Select all available drives. 2. Check(tick) …

Member Avatar for crunchie
0
189
Member Avatar for sociopathetic

Hi and welcome to Daniweb :). - Please run Notepad and copy the following text into a new file: [quote]@ECHO OFF cd %windir% Nail.exe /FULLREMOVE sc config SvcProc start= disabled sc stop SvcProc sc delete SvcProc attrib -s -r -h nail.exe attrib -s -r -h svcproc.exe del nail.exe del svcproc.exe …

Member Avatar for crunchie
0
95

The End.