4,383 Posted Topics
Re: Is probably LOP, but spybot's tea-timer is probably blocking it from view. First of all could you click Start>Settings>Control Panel>Add or Remove Programs and uninstall 'Window Search', 'Window Searching', 'Lop.com', 'LOP SEARCH', 'Browser Enhancer', or 'Ultimate Browser Enhancer' if listed. You may be given a code to insert, do so … | |
Re: You have some entries there that need removing. =============== Before we begin, let's move <b>HiJackThis</b> to it's own folder; like <b>c:\HJT</b>. Also move the "<b><i>Backups</i></b>" folder, for <b>HiJackThis</b>, if present. =============== Go to [b]Add/Remove programs[/b] and remove(uninstall) the following, if present: [b][color=#ff0000]Elite Toolbar[/color][/b] The above could appear anywhere within the … | |
Re: Please download the trial version of Ewido Security Suite here: [url]http://www.ewido.net/en/download/[/url] Install it, and update the definitions to the newest files. Do NOT run a scan yet. Please download Nailfix from here: [url]http://www.noidea.us/easyfile/file.php?download=20050515010747824[/url] Unzip it to the desktop but please do NOT run it yet. Next, please reboot your computer … | |
Re: You have some entries there that need removing... =============== Run [b]HiJackThis,[/b] click "[b][i]Scan[/i][/b]", then check(tick) the following, if present: [color=#9933cc][b] O9 - Extra button: Microsoft AntiSpyware helper - {7940CD64-8BEE-4C36-BA81-ECB7EE50EEEF} - (no file) (HKCU) [/b][/color] [color=#9933cc][b] O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {7940CD64-8BEE-4C36-BA81-ECB7EE50EEEF} - (no file) (HKCU) [/b][/color] … | |
Re: You have a few things there that need removing... =============== Run [b]HiJackThis[/b] then: 1. Click "[b][i]Open the Misc Tools Section[/i][/b]" 2. Click "[b][i]Open Process manager[/i][/b]" - Next, while holding down the [b]CTRL[/b] key, locate ([i]if present[/i]) and click on ([i]highlight[/i]) each of the following: [b][color=#000000]C:\Program Files\[/color][color=#ff0000]gcasServ.exe[/color][/b] [b][color=#000000]C:\Program Files\[/color][color=#ff0000]gcasDtServ.exe[/color][/b] Now double-check … | |
Re: Please download the trial version of Ewido Security Suite here: [url]http://www.ewido.net/en/download/[/url] Install it, and update the definitions to the newest files. Do NOT run a scan yet. Please download Nailfix from here: [url]http://www.noidea.us/easyfile/file.php?download=20050515010747824[/url] Unzip it to the desktop but please do NOT run it yet. Next, please reboot your computer … | |
Re: Steve Halliday, Hi and welcome to the Daniweb forums :). Please do not tag onto other members threads, or double post to the wrong forum. It only causes confusion for those who wish to help you :). =============== Go to [url=http://www.trendmicro.com/en/home/us/enterprise.htm]www.trendmicro.com[/url], and then: 1. Click "[b][i]Free Online Scan[/i][/b]". 2. Click … | |
Re: As per dav555's tip; [b]Download moveonboot[/b] from [url=http://www.webattack.com/get/moveonboot.html][u]here[/u][/url] & the file(s) you choose will be deleted on reboot. MoveOnBoot allows you to copy, move or delete files on the next system boot. This comes in very handy, if you need to replace or delete files which are locked by other … | |
Re: Weazol, Hello! and welcome to the Daniweb forums :). - Go to [url=http://www.trendmicro.com/en/home/us/enterprise.htm]www.trendmicro.com[/url], and then: 1. Click "[b][i]Free Online Scan[/i][/b]". 2. Click "[b][i]Scan now, it's free[/i][/b]". It'll take a few minutes to download (especially with a dialup connection), so be patient. When it's down: 1. Select all available drives. 2. … | |
Re: Hi and welcome to Daniweb :).. =============== Let's open a [b]command prompt[/b] by going to the start menu and then select 'Run'. In the box that pops up type in 'cmd'. The command prompt will open. OR You can go to Start -> Programs -> Accessories -> Command Prompt. Unregister … | |
Re: Post a log from hijackthis taken after a reboot. Make certain that hijackthis is in a permanent folder and that it is the latest (1.99.1) version. | |
Re: Hi and welcome to Daniweb :). My suggestion, (as we do not know what you have 'fixed') is to either do a system restore, or restore the items you removed with hijackthis. To restore from hijackthis, start hijackthis and hit the button 'view the list of backups.' Put a check … | |
Re: Please download the trial version of Ewido Security Suite here: [url]http://www.ewido.net/en/download/[/url] Install it, and update the definitions to the newest files. Do NOT run a scan yet. Please download Nailfix from here: [url]http://www.noidea.us/easyfile/file.php?download=20050515010747824[/url] Unzip it to the desktop but please do NOT run it yet. Next, please reboot your computer … | |
Re: kipster198, Hi and welcome to the Daniweb forums :). =============== Run [b]HiJackThis[/b] then: 1. Click "[b][i]Open the Misc Tools Section[/i][/b]" 2. Click "[b][i]Open Process manager[/i][/b]" - Next, while holding down the [b]CTRL[/b] key, locate ([i]if present[/i]) and click on ([i]highlight[/i]) each of the following: [b][color=#000000]C:\WINDOWS\SYSTEM\[/color][color=#ff0000]DSKMGR32.EXE[/color][/b] Now double-check and make sure … | |
Re: Download rkfiles.zip [url]http://skads.org/special/rkfiles.zip[/url] Unzip the contents to a permanent folder. Reboot in Safe mode. Doubleclick rkfiles.bat It will scan for a while, so please be patient. Wait till the DOS window closes and reboot back to normal mode. To save some time, could you please have all the files that … | |
Re: Download [color=blue][b]CWShredder 2.15[/b][/color] from [url=http://www.intermute.com/products/cwshredder.html][u]here.[/u][/url] Download[url=http://www.derbilk.de/SpSeHjfix112.zip]'SpSeHjfix'[/url] to the desktop and then right click a blank part of the desktop and select new folder, call it spfix unzip the file into that folder. [color=red]Disconnect from the net and Close ALL OPEN PROGRAMS.[/color] Run 'SpSeHjfix'. and click on "Start Disinfection". When it's … | |
Re: Please go [url=http://windowsupdate.microsoft.com/][u]here[/u][/url] & install ALL critical updates required for your system, including service pack 1a for both XP and IE6. Most malware is designed to attack unpatched XP systems - exploiting the available 'holes' - and can bypass third-party protection on an unpatched system. The most that can be … | |
Re: tvockrodt, Hi and welcome to the Daniweb forums :). =============== The header for [b]HiJackThis[/b] is very important: It helps to determine what steps might need to be taken to better secure your system, and provide more efficient cleanup procedures. For example, some files, which on standard on one platform, may … | |
Re: [QUOTE=DMR]Once downloaded, follow these instructions to install and run the program: Create a folder outside of any Temp/Temporary folders for HJT and move it there now. A folder such such as C:\HijackThis or C:\Spyware Tools\HijackThis will do.[/QUOTE] Please do the above and we can complete your repairs :). | |
Re: jasonlynn, Hi and welcome to the Daniweb forums :). =============== We'll need to unload [b]Spybot's Teatimer[/b] before we begin. To do this, right-click on the icon in the quick launch toolbar at the bottom on the screen, then select "[b][i]Exit[/i][/b]". =============== We'll need to also unload (not uninstall) [b]Intermute's SpySubtract[/b], … | |
Re: inssane, Hello! and welcome to the Daniweb forums :). - There are a some item(s) i'm not familar with in your log and cannot get info on. If you recognise any, then just omit them from this fix. =============== Go to [url=http://www.trendmicro.com/en/home/us/enterprise.htm]www.trendmicro.com[/url], and then: 1. Click "[b][i]Free Online Scan[/i][/b]". 2. … | |
Re: mru= most recently used. In other words, folders and files that you have used on your pc, including zip utilities, media etc. | |
Re: double_click, Hi and welcome to the Daniweb forums :). =============== If you haven't run [b]HouseCall[/b] lately, let's go back to [url=http://www.trendmicro.com/en/home/us/enterprise.htm]www.trendmicro.com[/url], download the latest definitions, and run it. =============== Run [b]HiJackThis[/b] then: 1. Click "[b][i]Open the Misc Tools Section[/i][/b]" 2. Click "[b][i]Open Process manager[/i][/b]" - Next, while holding down the … | |
Re: You have a few things there that need removing... =============== Run [b]HiJackThis,[/b] click "[b][i]Scan[/i][/b]", then check(tick) the following, if present: [color=#9933cc][b] O4 - HKLM\..\Run: [Jammer2nd] C:\WINDOWS\Jammer2nd.exe [/b][/color] [color=#9933cc][b] O4 - HKLM\..\Run: [dqlyl] C:\WINDOWS\dqlyl.exe [/b][/color] [color=#9933cc][b] O4 - HKCU\..\Run: [ClockSync] C:\PROGRA~1\CLOCKS~1\Sync.exe /q [/b][/color] [color=#9933cc][b] O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - … | |
Re: Go to add/remove programs and uninstall the following; [b]WebSearch (Remove Only)[/b] It will not fix the problem, but I believe it should be removed. | |
Re: You have a few things there that need removing... =============== We'll need to disable (not uninstall) [b]Intermute's SpySubtract[/b], since it might interfere with other program(s) we might be using to 'clean' off your system. =============== Run [b]HiJackThis,[/b] click "[b][i]Scan[/i][/b]", then check(tick) the following, if present: [color=#9933cc][b] R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL … | |
Re: Please go [url=http://computercops.biz/postt106277.html][u]here[/u][/url] for the instructions on how to remove the Bube.d (aka Win32.Beavis) Removal [isrvs] infection. Please follow the removal instructions [b]exactly.[/b] Once done, repost a new log here and we will finish off the clean up. | |
Re: [b]Please read these instructions carefully and print them out! Be sure to follow ALL instructions![/b] Please right-click: [url=http://www.bleepingcomputer.com/files/reg/smitfraud.reg][color=red][b]HERE[/b][/color][/url] and go to Save As (in Internet Explorer it's "Save Target As") in order to download Grinler's reg file. Save it to your desktop. Locate "[b]smitfraud.reg[/b]" on your desktop and double-click it. … | |
![]() | Re: [b]Download [color=blue]HijackThis[/color] [b][color=red][SIZE=3]selfextracting[/SIZE][/color][/b] zip version from [url=http://www.malwareremoval.com/downloads.html][u]here.[/u][/url][/b] Once downloaded, double click on the file & it will install into it's own, permanent folder. Start HJT & press the "Do a system scan and save a log file" button. When the scan is finished a window will pop up giving you … |
![]() | Re: You have a few things there that need removing... =============== Download [color=blue][b]CWShredder 2.15[/b][/color] from [url=http://www.intermute.com/products/cwshredder.html][u]here.[/u][/url] Run it and press the *fix,* not scan and allow it to clean the infection. [b]Close [color=red]all[/color] browser and explorer windows before hitting the fix button.[/b] =============== Still in [b]HiJackThis,[/b] click "[b][i]Scan[/i][/b]", then check(tick) the … |
Re: Can you please post a new hijackthis log and also do the following; Go [url=http://www.silentrunners.org/]here[/url] and download and run [color=blue]Silent Runners.vbs.[/color] It generates a log, please post the information back in this thread. Download rkfiles.zip [url]http://skads.org/special/rkfiles.zip[/url] Unzip the contents to a permanent folder. Reboot in Safe mode. Doubleclick rkfiles.bat It … | |
Re: Please download the trial version of Ewido Security Suite here: [url]http://www.ewido.net/en/download/[/url] Install it, and update the definitions to the newest files. Do NOT run a scan yet. Please download Nailfix from here: [url]http://www.noidea.us/easyfile/file.php?download=20050515010747824[/url] Unzip it to the desktop but please do NOT run it yet. Next, please reboot your computer … | |
Re: You have the latest version of VX2. Download L2mfix from one of these two locations: [url]http://www.atribune.org/downloads/l2mfix.exe[/url] [url]http://www.downloads.subratam.org/l2mfix.exe[/url] Save the file to your desktop and double click l2mfix.exe. Click the Install button to extract the files and follow the prompts, then open the newly added l2mfix folder on your desktop. Double … | |
Re: Hi. You need to move hijackthis into a permanent folder before we begin your fix. A new folder on your desktop with hijackthis running from there is fine, but you can put it anywhere you wish, except a temporary folder :). In the meantime; 1. [b]Download and install [URL=http://www.lavasoftusa.com/software/adaware/][color=blue] Ad-Aware … | |
Re: Post your hijackthis log that was taken immediately after a reboot. If you have anything disabled in Msconfig, enable them first. Make sure hijackthis.exe is in a permanent folder before posting. Go [url=http://www.silentrunners.org/]here[/url] and download and run [color=blue]Silent Runners.vbs.[/color] It generates a log, please post the information back in this … | |
Re: Hi and welcome to Daniweb :). [b]Go [url=http://housecall.trendmicro.com/][u]here[/u][/url] to TrendMicro for an on-line scan & set it to autoclean for you. When it completes, post back the full filename of any files that cannot be cleaned or deleted. Try [URL=http://www.pandasoftware.com/activescan/com/activescan_principal.htm][u]this[/u][/URL] scan at Panda as well.[/b] [b]The scan here does not … | |
Re: [b]Download [color=blue]HijackThis[/color] [b][color=red][SIZE=3]selfextracting[/SIZE][/color][/b] zip version from [url=http://www.malwareremoval.com/downloads.html][u]here.[/u][/url][/b] Once downloaded, double click on the file & it will install into it's own, permanent folder. Start HJT & press the "Do a system scan and save a log file" button. When the scan is finished a window will pop up giving you … | |
Re: Rino, Hello! and welcome to the Daniweb forums :). - You'll need to download [url=http://www.memorywatcher.com/uninst.exe]uninst.exe[/url] to remove the 'peper' infection, then: 1. run [b]uninst.exe[/b] ... [i](first pass)[/i]. 2. reboot your computer. 3. run [b]uninst.exe[/b] ... [i](final pass)[/i]. [color=#ff0000][i]Note: You must have an active internet connection, each time this program is … | |
Re: M4RKoTiC, Hello! and welcome to the Daniweb forums :). =============== When we're done cleaning off your system, i'd [b]recommend[/b] that you install all the [color=#ff0000][b][i]critical windows updates[/i][/b][/color] available from [b]Microsoft[/b], upto [i]service pack 1[/i]. This will help to make your system more secure and prevent many '[i]problems[/i]' from reoccuring in … | |
Re: airgb, Hello! and welcome to the Daniweb forums :). I will be deleting your other thread as it is a duplicate of this one. -- Please download the trial version of Ewido Security Suite here: [url]http://www.ewido.net/en/download/[/url] Install it, and update the definitions to the newest files. Do NOT run a … | |
Re: Please create a folder in a permanent directory and move hijackthis into it. Rescan with hijackthis and post another log please. A new folder on your desktop is ok to run it from. [url]http://www.daniweb.com/techtalkforums/thread24085.html[/url] | |
Re: It sure is :). You may want to post an hijackthis log too. | |
Re: Download rkfiles.zip [url]http://skads.org/special/rkfiles.zip[/url] Unzip the contents to a permanent folder. Reboot in Safe mode. Doubleclick rkfiles.bat It will scan for a while, so please be patient. Wait till the DOS window closes and reboot back to normal mode. To save some time, could you please have all the files that … | |
Re: [b]Download [color=blue]HijackThis[/color] [b][color=red][SIZE=3]selfextracting[/SIZE][/color][/b] zip version from [url=http://www.malwareremoval.com/downloads.html][u]here.[/u][/url][/b] Once downloaded, double click on the file & it will install into it's own, permanent folder. Start HJT & press the "Do a system scan and save a log file" button. When the scan is finished a window will pop up giving you … | |
Re: 1. [b]Download and install [URL=http://www.lavasoftusa.com/software/adaware/][color=blue] Ad-Aware SE,[/color][/URL][/b] keeping the default options. [b]However, some of the settings will need to be changed before your first scan[/b] 2.[b]Close ALL windows[/b] except Ad-Aware SE 3. Click on the[b]‘world’ [/b] icon at the top right of the Ad-Aware SE window and let AdAware SE … | |
Re: Please download the trial version of Ewido Security Suite here: [url]http://www.ewido.net/en/download/[/url] Install it, and update the definitions to the newest files. Do NOT run a scan yet. Please download Nailfix from here: [url]http://www.noidea.us/easyfile/file.php?download=20050515010747824[/url] Unzip it to the desktop but please do NOT run it yet. Next, please reboot your computer … | |
Re: Hi and welcome to Daniweb :). You have hijackthis in a temporary folder. Please create a new folder (on the desktop is ok) and move hijackthis into it. ============== Please go [url=http://windowsupdate.microsoft.com/][u]here[/u][/url] & install ALL critical updates required for your system, including service pack 1a for both XP and IE6. … | |
Re: Please download the trial version of Ewido Security Suite here: [url]http://www.ewido.net/en/download/[/url] Install it, and update the definitions to the newest files. Do NOT run a scan yet. Please download Nailfix from here: [url]http://www.noidea.us/easyfile/file.php?download=20050515010747824[/url] Unzip it to the desktop but please do NOT run it yet. Next, please reboot your computer … | |
Re: Hi and welcome to Daniweb forums :). You have a few things there that need removing... - Download [color=blue][b]CWShredder 2.14[/b][/color] from [url=http://www.intermute.com/products/cwshredder.html][u]here.[/u][/url] Run it and press the *fix,* not scan and allow it to clean the infection. [b]Close [color=red]all[/color] browser and explorer windows before hitting the fix button.[/b] - Download, … |
The End.