4,383 Posted Topics

Member Avatar for HsSplat

Is probably LOP, but spybot's tea-timer is probably blocking it from view. First of all could you click Start>Settings>Control Panel>Add or Remove Programs and uninstall 'Window Search', 'Window Searching', 'Lop.com', 'LOP SEARCH', 'Browser Enhancer', or 'Ultimate Browser Enhancer' if listed. You may be given a code to insert, do so …

Member Avatar for crunchie
0
112
Member Avatar for tfonseca

You have some entries there that need removing. =============== Before we begin, let's move <b>HiJackThis</b> to it's own folder; like <b>c:\HJT</b>. Also move the "<b><i>Backups</i></b>" folder, for <b>HiJackThis</b>, if present. =============== Go to [b]Add/Remove programs[/b] and remove(uninstall) the following, if present: [b][color=#ff0000]Elite Toolbar[/color][/b] The above could appear anywhere within the …

Member Avatar for crunchie
0
94
Member Avatar for shane'r69

Please download the trial version of Ewido Security Suite here: [url]http://www.ewido.net/en/download/[/url] Install it, and update the definitions to the newest files. Do NOT run a scan yet. Please download Nailfix from here: [url]http://www.noidea.us/easyfile/file.php?download=20050515010747824[/url] Unzip it to the desktop but please do NOT run it yet. Next, please reboot your computer …

Member Avatar for crunchie
0
240
Member Avatar for alexanderp513

You have some entries there that need removing... =============== Run [b]HiJackThis,[/b] click "[b][i]Scan[/i][/b]", then check(tick) the following, if present: [color=#9933cc][b] O9 - Extra button: Microsoft AntiSpyware helper - {7940CD64-8BEE-4C36-BA81-ECB7EE50EEEF} - (no file) (HKCU) [/b][/color] [color=#9933cc][b] O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {7940CD64-8BEE-4C36-BA81-ECB7EE50EEEF} - (no file) (HKCU) [/b][/color] …

Member Avatar for buddylee614
0
140
Member Avatar for Benny591

You have a few things there that need removing... =============== Run [b]HiJackThis[/b] then: 1. Click "[b][i]Open the Misc Tools Section[/i][/b]" 2. Click "[b][i]Open Process manager[/i][/b]" - Next, while holding down the [b]CTRL[/b] key, locate ([i]if present[/i]) and click on ([i]highlight[/i]) each of the following: [b][color=#000000]C:\Program Files\[/color][color=#ff0000]gcasServ.exe[/color][/b] [b][color=#000000]C:\Program Files\[/color][color=#ff0000]gcasDtServ.exe[/color][/b] Now double-check …

Member Avatar for dlh6213
0
444
Member Avatar for borgep

Please download the trial version of Ewido Security Suite here: [url]http://www.ewido.net/en/download/[/url] Install it, and update the definitions to the newest files. Do NOT run a scan yet. Please download Nailfix from here: [url]http://www.noidea.us/easyfile/file.php?download=20050515010747824[/url] Unzip it to the desktop but please do NOT run it yet. Next, please reboot your computer …

Member Avatar for crunchie
0
143
Member Avatar for Steve Halliday

Steve Halliday, Hi and welcome to the Daniweb forums :). Please do not tag onto other members threads, or double post to the wrong forum. It only causes confusion for those who wish to help you :). =============== Go to [url=http://www.trendmicro.com/en/home/us/enterprise.htm]www.trendmicro.com[/url], and then: 1. Click "[b][i]Free Online Scan[/i][/b]". 2. Click …

Member Avatar for crunchie
0
102
Member Avatar for Pitufo

As per dav555's tip; [b]Download moveonboot[/b] from [url=http://www.webattack.com/get/moveonboot.html][u]here[/u][/url] & the file(s) you choose will be deleted on reboot. MoveOnBoot allows you to copy, move or delete files on the next system boot. This comes in very handy, if you need to replace or delete files which are locked by other …

Member Avatar for The_chewie71
0
159
Member Avatar for Weazol

Weazol, Hello! and welcome to the Daniweb forums :). - Go to [url=http://www.trendmicro.com/en/home/us/enterprise.htm]www.trendmicro.com[/url], and then: 1. Click "[b][i]Free Online Scan[/i][/b]". 2. Click "[b][i]Scan now, it's free[/i][/b]". It'll take a few minutes to download (especially with a dialup connection), so be patient. When it's down: 1. Select all available drives. 2. …

Member Avatar for crunchie
0
184
Member Avatar for dhs

Hi and welcome to Daniweb :).. =============== Let's open a [b]command prompt[/b] by going to the start menu and then select 'Run'. In the box that pops up type in 'cmd'. The command prompt will open. OR You can go to Start -> Programs -> Accessories -> Command Prompt. Unregister …

Member Avatar for dhs
0
145
Member Avatar for daruk

Post a log from hijackthis taken after a reboot. Make certain that hijackthis is in a permanent folder and that it is the latest (1.99.1) version.

Member Avatar for JEt3L
0
269
Member Avatar for c01dud

Hi and welcome to Daniweb :). My suggestion, (as we do not know what you have 'fixed') is to either do a system restore, or restore the items you removed with hijackthis. To restore from hijackthis, start hijackthis and hit the button 'view the list of backups.' Put a check …

Member Avatar for crunchie
0
191
Member Avatar for bakerbuilt

Please download the trial version of Ewido Security Suite here: [url]http://www.ewido.net/en/download/[/url] Install it, and update the definitions to the newest files. Do NOT run a scan yet. Please download Nailfix from here: [url]http://www.noidea.us/easyfile/file.php?download=20050515010747824[/url] Unzip it to the desktop but please do NOT run it yet. Next, please reboot your computer …

Member Avatar for crunchie
0
279
Member Avatar for kipster198

kipster198, Hi and welcome to the Daniweb forums :). =============== Run [b]HiJackThis[/b] then: 1. Click "[b][i]Open the Misc Tools Section[/i][/b]" 2. Click "[b][i]Open Process manager[/i][/b]" - Next, while holding down the [b]CTRL[/b] key, locate ([i]if present[/i]) and click on ([i]highlight[/i]) each of the following: [b][color=#000000]C:\WINDOWS\SYSTEM\[/color][color=#ff0000]DSKMGR32.EXE[/color][/b] Now double-check and make sure …

Member Avatar for crunchie
0
213
Member Avatar for kriskarrera

Download rkfiles.zip [url]http://skads.org/special/rkfiles.zip[/url] Unzip the contents to a permanent folder. Reboot in Safe mode. Doubleclick rkfiles.bat It will scan for a while, so please be patient. Wait till the DOS window closes and reboot back to normal mode. To save some time, could you please have all the files that …

Member Avatar for Bluejay
0
605
Member Avatar for sephiroth61787

Download [color=blue][b]CWShredder 2.15[/b][/color] from [url=http://www.intermute.com/products/cwshredder.html][u]here.[/u][/url] Download[url=http://www.derbilk.de/SpSeHjfix112.zip]'SpSeHjfix'[/url] to the desktop and then right click a blank part of the desktop and select new folder, call it spfix unzip the file into that folder. [color=red]Disconnect from the net and Close ALL OPEN PROGRAMS.[/color] Run 'SpSeHjfix'. and click on "Start Disinfection". When it's …

Member Avatar for crunchie
0
122
Member Avatar for talknerdie2me

Please go [url=http://windowsupdate.microsoft.com/][u]here[/u][/url] & install ALL critical updates required for your system, including service pack 1a for both XP and IE6. Most malware is designed to attack unpatched XP systems - exploiting the available 'holes' - and can bypass third-party protection on an unpatched system. The most that can be …

Member Avatar for crunchie
0
113
Member Avatar for tvockrodt

tvockrodt, Hi and welcome to the Daniweb forums :). =============== The header for [b]HiJackThis[/b] is very important: It helps to determine what steps might need to be taken to better secure your system, and provide more efficient cleanup procedures. For example, some files, which on standard on one platform, may …

Member Avatar for crunchie
0
105
Member Avatar for darktower

[QUOTE=DMR]Once downloaded, follow these instructions to install and run the program: Create a folder outside of any Temp/Temporary folders for HJT and move it there now. A folder such such as C:\HijackThis or C:\Spyware Tools\HijackThis will do.[/QUOTE] Please do the above and we can complete your repairs :).

Member Avatar for darktower
0
407
Member Avatar for jasonlynn

jasonlynn, Hi and welcome to the Daniweb forums :). =============== We'll need to unload [b]Spybot's Teatimer[/b] before we begin. To do this, right-click on the icon in the quick launch toolbar at the bottom on the screen, then select "[b][i]Exit[/i][/b]". =============== We'll need to also unload (not uninstall) [b]Intermute's SpySubtract[/b], …

Member Avatar for crunchie
0
129
Member Avatar for inssane

inssane, Hello! and welcome to the Daniweb forums :). - There are a some item(s) i'm not familar with in your log and cannot get info on. If you recognise any, then just omit them from this fix. =============== Go to [url=http://www.trendmicro.com/en/home/us/enterprise.htm]www.trendmicro.com[/url], and then: 1. Click "[b][i]Free Online Scan[/i][/b]". 2. …

Member Avatar for inssane
0
380
Member Avatar for foxy xx

mru= most recently used. In other words, folders and files that you have used on your pc, including zip utilities, media etc.

Member Avatar for Comatose
0
103
Member Avatar for double_click

double_click, Hi and welcome to the Daniweb forums :). =============== If you haven't run [b]HouseCall[/b] lately, let's go back to [url=http://www.trendmicro.com/en/home/us/enterprise.htm]www.trendmicro.com[/url], download the latest definitions, and run it. =============== Run [b]HiJackThis[/b] then: 1. Click "[b][i]Open the Misc Tools Section[/i][/b]" 2. Click "[b][i]Open Process manager[/i][/b]" - Next, while holding down the …

Member Avatar for crunchie
0
126
Member Avatar for lemurianprince

You have a few things there that need removing... =============== Run [b]HiJackThis,[/b] click "[b][i]Scan[/i][/b]", then check(tick) the following, if present: [color=#9933cc][b] O4 - HKLM\..\Run: [Jammer2nd] C:\WINDOWS\Jammer2nd.exe [/b][/color] [color=#9933cc][b] O4 - HKLM\..\Run: [dqlyl] C:\WINDOWS\dqlyl.exe [/b][/color] [color=#9933cc][b] O4 - HKCU\..\Run: [ClockSync] C:\PROGRA~1\CLOCKS~1\Sync.exe /q [/b][/color] [color=#9933cc][b] O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - …

Member Avatar for DMR
0
498
Member Avatar for burketdsl

Go to add/remove programs and uninstall the following; [b]WebSearch (Remove Only)[/b] It will not fix the problem, but I believe it should be removed.

Member Avatar for dlh6213
0
536
Member Avatar for virus_magnet

You have a few things there that need removing... =============== We'll need to disable (not uninstall) [b]Intermute's SpySubtract[/b], since it might interfere with other program(s) we might be using to 'clean' off your system. =============== Run [b]HiJackThis,[/b] click "[b][i]Scan[/i][/b]", then check(tick) the following, if present: [color=#9933cc][b] R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL …

Member Avatar for crunchie
0
319
Member Avatar for store32

Please go [url=http://computercops.biz/postt106277.html][u]here[/u][/url] for the instructions on how to remove the Bube.d (aka Win32.Beavis) Removal [isrvs] infection. Please follow the removal instructions [b]exactly.[/b] Once done, repost a new log here and we will finish off the clean up.

Member Avatar for crunchie
0
205
Member Avatar for i3lackrabbit

[b]Please read these instructions carefully and print them out! Be sure to follow ALL instructions![/b] Please right-click: [url=http://www.bleepingcomputer.com/files/reg/smitfraud.reg][color=red][b]HERE[/b][/color][/url] and go to Save As (in Internet Explorer it's "Save Target As") in order to download Grinler's reg file. Save it to your desktop. Locate "[b]smitfraud.reg[/b]" on your desktop and double-click it. …

Member Avatar for crunchie
0
166
Member Avatar for dc2000

[b]Download [color=blue]HijackThis[/color] [b][color=red][SIZE=3]selfextracting[/SIZE][/color][/b] zip version from [url=http://www.malwareremoval.com/downloads.html][u]here.[/u][/url][/b] Once downloaded, double click on the file & it will install into it's own, permanent folder. Start HJT & press the "Do a system scan and save a log file" button. When the scan is finished a window will pop up giving you …

Member Avatar for crunchie
0
90
Member Avatar for kvirl

You have a few things there that need removing... =============== Download [color=blue][b]CWShredder 2.15[/b][/color] from [url=http://www.intermute.com/products/cwshredder.html][u]here.[/u][/url] Run it and press the *fix,* not scan and allow it to clean the infection. [b]Close [color=red]all[/color] browser and explorer windows before hitting the fix button.[/b] =============== Still in [b]HiJackThis,[/b] click "[b][i]Scan[/i][/b]", then check(tick) the …

Member Avatar for crunchie
0
127
Member Avatar for Monte
Member Avatar for Quitahd

Can you please post a new hijackthis log and also do the following; Go [url=http://www.silentrunners.org/]here[/url] and download and run [color=blue]Silent Runners.vbs.[/color] It generates a log, please post the information back in this thread. Download rkfiles.zip [url]http://skads.org/special/rkfiles.zip[/url] Unzip the contents to a permanent folder. Reboot in Safe mode. Doubleclick rkfiles.bat It …

Member Avatar for Quitahd
0
357
Member Avatar for Rsilen

Please download the trial version of Ewido Security Suite here: [url]http://www.ewido.net/en/download/[/url] Install it, and update the definitions to the newest files. Do NOT run a scan yet. Please download Nailfix from here: [url]http://www.noidea.us/easyfile/file.php?download=20050515010747824[/url] Unzip it to the desktop but please do NOT run it yet. Next, please reboot your computer …

Member Avatar for crunchie
0
239
Member Avatar for Nuitaran

You have the latest version of VX2. Download L2mfix from one of these two locations: [url]http://www.atribune.org/downloads/l2mfix.exe[/url] [url]http://www.downloads.subratam.org/l2mfix.exe[/url] Save the file to your desktop and double click l2mfix.exe. Click the Install button to extract the files and follow the prompts, then open the newly added l2mfix folder on your desktop. Double …

Member Avatar for DMR
0
450
Member Avatar for coldhearted

Hi. You need to move hijackthis into a permanent folder before we begin your fix. A new folder on your desktop with hijackthis running from there is fine, but you can put it anywhere you wish, except a temporary folder :). In the meantime; 1. [b]Download and install [URL=http://www.lavasoftusa.com/software/adaware/][color=blue] Ad-Aware …

Member Avatar for coldhearted
0
305
Member Avatar for actfray

Post your hijackthis log that was taken immediately after a reboot. If you have anything disabled in Msconfig, enable them first. Make sure hijackthis.exe is in a permanent folder before posting. Go [url=http://www.silentrunners.org/]here[/url] and download and run [color=blue]Silent Runners.vbs.[/color] It generates a log, please post the information back in this …

Member Avatar for Croft .L
0
132
Member Avatar for bluntman_420

Hi and welcome to Daniweb :). [b]Go [url=http://housecall.trendmicro.com/][u]here[/u][/url] to TrendMicro for an on-line scan & set it to autoclean for you. When it completes, post back the full filename of any files that cannot be cleaned or deleted. Try [URL=http://www.pandasoftware.com/activescan/com/activescan_principal.htm][u]this[/u][/URL] scan at Panda as well.[/b] [b]The scan here does not …

Member Avatar for crunchie
0
299
Member Avatar for cjo

[b]Download [color=blue]HijackThis[/color] [b][color=red][SIZE=3]selfextracting[/SIZE][/color][/b] zip version from [url=http://www.malwareremoval.com/downloads.html][u]here.[/u][/url][/b] Once downloaded, double click on the file & it will install into it's own, permanent folder. Start HJT & press the "Do a system scan and save a log file" button. When the scan is finished a window will pop up giving you …

Member Avatar for crunchie
0
232
Member Avatar for Rino

Rino, Hello! and welcome to the Daniweb forums :). - You'll need to download [url=http://www.memorywatcher.com/uninst.exe]uninst.exe[/url] to remove the 'peper' infection, then: 1. run [b]uninst.exe[/b] ... [i](first pass)[/i]. 2. reboot your computer. 3. run [b]uninst.exe[/b] ... [i](final pass)[/i]. [color=#ff0000][i]Note: You must have an active internet connection, each time this program is …

Member Avatar for crunchie
0
349
Member Avatar for M4RKoTiC

M4RKoTiC, Hello! and welcome to the Daniweb forums :). =============== When we're done cleaning off your system, i'd [b]recommend[/b] that you install all the [color=#ff0000][b][i]critical windows updates[/i][/b][/color] available from [b]Microsoft[/b], upto [i]service pack 1[/i]. This will help to make your system more secure and prevent many '[i]problems[/i]' from reoccuring in …

Member Avatar for crunchie
0
226
Member Avatar for airgb

airgb, Hello! and welcome to the Daniweb forums :). I will be deleting your other thread as it is a duplicate of this one. -- Please download the trial version of Ewido Security Suite here: [url]http://www.ewido.net/en/download/[/url] Install it, and update the definitions to the newest files. Do NOT run a …

Member Avatar for crunchie
0
327
Member Avatar for TheSaint

Please create a folder in a permanent directory and move hijackthis into it. Rescan with hijackthis and post another log please. A new folder on your desktop is ok to run it from. [url]http://www.daniweb.com/techtalkforums/thread24085.html[/url]

Member Avatar for crunchie
0
93
Member Avatar for isischick
Member Avatar for armyguy117

Download rkfiles.zip [url]http://skads.org/special/rkfiles.zip[/url] Unzip the contents to a permanent folder. Reboot in Safe mode. Doubleclick rkfiles.bat It will scan for a while, so please be patient. Wait till the DOS window closes and reboot back to normal mode. To save some time, could you please have all the files that …

Member Avatar for crunchie
0
116
Member Avatar for dirky083

[b]Download [color=blue]HijackThis[/color] [b][color=red][SIZE=3]selfextracting[/SIZE][/color][/b] zip version from [url=http://www.malwareremoval.com/downloads.html][u]here.[/u][/url][/b] Once downloaded, double click on the file & it will install into it's own, permanent folder. Start HJT & press the "Do a system scan and save a log file" button. When the scan is finished a window will pop up giving you …

Member Avatar for crunchie
0
88
Member Avatar for ~~Sarah~~

1. [b]Download and install [URL=http://www.lavasoftusa.com/software/adaware/][color=blue] Ad-Aware SE,[/color][/URL][/b] keeping the default options. [b]However, some of the settings will need to be changed before your first scan[/b] 2.[b]Close ALL windows[/b] except Ad-Aware SE 3. Click on the[b]‘world’ [/b] icon at the top right of the Ad-Aware SE window and let AdAware SE …

Member Avatar for crunchie
0
337
Member Avatar for ten278

Please download the trial version of Ewido Security Suite here: [url]http://www.ewido.net/en/download/[/url] Install it, and update the definitions to the newest files. Do NOT run a scan yet. Please download Nailfix from here: [url]http://www.noidea.us/easyfile/file.php?download=20050515010747824[/url] Unzip it to the desktop but please do NOT run it yet. Next, please reboot your computer …

Member Avatar for crunchie
0
468
Member Avatar for sigith2002

Hi and welcome to Daniweb :). You have hijackthis in a temporary folder. Please create a new folder (on the desktop is ok) and move hijackthis into it. ============== Please go [url=http://windowsupdate.microsoft.com/][u]here[/u][/url] & install ALL critical updates required for your system, including service pack 1a for both XP and IE6. …

Member Avatar for crunchie
0
238
Member Avatar for wolvesmatt

Please download the trial version of Ewido Security Suite here: [url]http://www.ewido.net/en/download/[/url] Install it, and update the definitions to the newest files. Do NOT run a scan yet. Please download Nailfix from here: [url]http://www.noidea.us/easyfile/file.php?download=20050515010747824[/url] Unzip it to the desktop but please do NOT run it yet. Next, please reboot your computer …

Member Avatar for crunchie
0
142
Member Avatar for Aldiman

Hi and welcome to Daniweb forums :). You have a few things there that need removing... - Download [color=blue][b]CWShredder 2.14[/b][/color] from [url=http://www.intermute.com/products/cwshredder.html][u]here.[/u][/url] Run it and press the *fix,* not scan and allow it to clean the infection. [b]Close [color=red]all[/color] browser and explorer windows before hitting the fix button.[/b] - Download, …

Member Avatar for crunchie
0
129

The End.