4,383 Posted Topics

Member Avatar for SilentBob3208

Also, one of the stickies at the top of this forum has a link to the latest, self extracting version of hijackthis. Install that one and try again.

Member Avatar for crunchie
0
697
Member Avatar for dlsoecht

1. [b]Download and install [URL=http://www.lavasoftusa.com/software/adaware/][color=blue] Ad-Aware SE,[/color][/URL][/b] keeping the default options. [b]However, some of the settings will need to be changed before your first scan[/b] 2.[b]Close ALL windows[/b] except Ad-Aware SE 3. Click on the[b]‘world’ [/b] icon at the top right of the Ad-Aware SE window and let AdAware SE …

Member Avatar for caperjack
0
353
Member Avatar for A Monkeys Uncle

[color=blue]Scan with hijackthis and tick the boxes next to all the following entries, then [b][color=red]close all browser and explorer windows,[/color][/b] and hit the "Fix checked" button.[/color] R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = [url]http://red.clientapps.yahoo.com/cus...rch/search.html[/url] R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = [url]http://red.clientapps.yahoo.com/cus...rch/search.html[/url] R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = [url]http://red.clientapps.yahoo.com/cus...//www.yahoo.com[/url] O1 - Hosts: 70.84.92.114 …

Member Avatar for crunchie
0
144
Member Avatar for Total NONgeek

If they do not rid you of those entries, try the following; Download the zip file and unzip fixme.reg. Close all browser windows. Double click to run it and when asked if you want to merge with your registry, answer yes. This will only delete the registry entries!

Member Avatar for Total NONgeek
0
168
Member Avatar for shermy

Hi. First of all you need to update hijackthis to version 1.99.1. Run hijackthis & go to *Config\Misc Tools\Check for update on-line*. If the site is down, go [url=http://www.degs.co.uk/files/hijackthis.exe][u]here.[/u][/url] Remove the old version by opening the program, going to config\misc tools, then uninstall & exit. You then have to delete …

Member Avatar for dlh6213
0
277
Member Avatar for cxasino
Member Avatar for mjbickford

In addition, please do this; Download L2mfix from one of these two locations: [url]http://www.atribune.org/downloads/l2mfix.exe[/url] [url]http://www.downloads.subratam.org/l2mfix.exe[/url] Save the file to your desktop and double click l2mfix.exe. Click the Install button to extract the files and follow the prompts, then open the newly added l2mfix folder on your desktop. Double click l2mfix.bat …

Member Avatar for crunchie
0
655
Member Avatar for Morgan25

The patch you downloaded before is probably needed again. Go [url=http://www.daniweb.com/techtalkforums/thread18582.html]here[/url] to your previous thread regarding this problem.

Member Avatar for caperjack
0
85
Member Avatar for Buddha David
Member Avatar for OneHit
Member Avatar for nickyt8

I find the one that is linked to in my signature to be excellent. There is also AVG. Try a google search for free anti virus. [url]http://www.google.com/search?num=25&hl=en&lr=&q=free+anti+virus&btnG=Search[/url]

Member Avatar for dlh6213
0
78
Member Avatar for awaz_16

[b]Go [url=http://housecall.trendmicro.com/][u]here[/u][/url] to TrendMicro for an on-line scan & set it to autoclean for you. When it completes, post back the full filename of any files that cannot be cleaned or deleted. Try [URL=http://www.pandasoftware.com/activescan/com/activescan_principal.htm][u]this[/u][/URL] scan at Panda as well.[/b] [b]The scan here does not require an active X install, but …

Member Avatar for crunchie
0
283
Member Avatar for manntisrocker

First. You [b]must[/b] get service pack 1 for both XP and IE6. We are wasting our time and yours if you do not. Download [url=http://www.bleepingcomputer.com/files/aboutbuster.php][color=blue]about:Buster[/color][/url] and unzip it to your Desktop. Doubleclick on AboutBuster.exe to run it and then click on Update > Check for Update. If there is an …

Member Avatar for crunchie
0
170
Member Avatar for Kieara2003

1. [b]Download and install [URL=http://www.lavasoftusa.com/software/adaware/][color=blue] Ad-Aware SE,[/color][/URL][/b] keeping the default options. [b]However, some of the settings will need to be changed before your first scan[/b] 2.[b]Close ALL windows[/b] except Ad-Aware SE 3. Click on the[b]‘world’ [/b] icon at the top right of the Ad-Aware SE window and let AdAware SE …

Member Avatar for crunchie
0
73
Member Avatar for daosue

Post a log anyway, making sure it is the latest version (1,99) and that it is in it's own folder :). One of the items of malware are possibly stopping adaware from running. I recommend Opera as an alternative to IE, but the popular one at the moment appears to …

Member Avatar for DMR
0
515
Member Avatar for snowwolf

You need to read this thread regarding the virus; [url]http://www.daniweb.com/techtalkforums/thread13362.html[/url] [color=blue]Scan with hijackthis and tick the boxes next to all the following entries, then close all browser and explorer windows, and hit the "Fix checked" button.[/color] R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = [url]http://www.yaadifzawhkykymcdhdm.biz...3_hEPmrbC3.html[/url] O2 - BHO: PCTools Site Guard - …

Member Avatar for alc6379
0
442
Member Avatar for goodtaste

[b]Clear out your Temporary internet files and other temp files. Go to Start > Settings > Control Panel >Internet Options.[/b] Under the General tab click the Delete temporary internet files, delete all Offline content as well. Clear out Cookies. Also, go to [b]Start > Find/search > Files or folders[/b] > …

Member Avatar for goodtaste
0
295
Member Avatar for Persephone

Temporarily disable Tea-Timer whilst we do the repair. [color=blue]Scan with hijackthis and tick the boxes next to all the following entries, then [b][color=red]close all browser and explorer windows,[/color][/b] and hit the "Fix checked" button.[/color] N1 - Netscape 4: user_pref("browser.startup.homepage", "http://www.searchalot.com"); (C:\Program Files\Netscape\Users\pkw\prefs.js) Reboot and post another log please. Do you …

Member Avatar for crunchie
0
257
Member Avatar for joeman3285

[color=blue]Scan with hijackthis and tick the boxes next to all the following entries, then [b][color=red]close all browser and explorer windows,[/color][/b] and hit the "Fix checked" button.[/color] R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file) O2 - BHO: (no name) - {00000010-6F7D-442C-93E3-4A4827C2E4C8} - (no file) O2 - BHO: (no …

Member Avatar for crunchie
0
115
Member Avatar for reedy

First of all could you click Start>Settings>Control Panel>Add or Remove Programs and uninstall 'Window Search', 'Window Searching', 'Lop.com', 'LOP SEARCH', 'Browser Enhancer', or 'Ultimate Browser Enhancer' if listed. You may be given a code to insert, do so and reboot when done. If not listed there, run this uninstaller: [url]http://members.rogers.com/rjmac/new_uninstall.exe[/url] …

Member Avatar for steosaur(oWn)
0
409
Member Avatar for ineedshelp

First of all could you click Start>Settings>Control Panel>Add or Remove Programs and uninstall 'Window Search', 'Window Searching', 'Lop.com', 'LOP SEARCH', 'Browser Enhancer', or 'Ultimate Browser Enhancer' if listed. You may be given a code to insert, do so and reboot when done. If not listed there, run this uninstaller: [url]http://members.rogers.com/rjmac/new_uninstall.exe[/url] …

Member Avatar for crunchie
0
105
Member Avatar for leleloz

Run [color=blue]Hijackthis[/color] and go to the [color=green]process viewer[/color] by going to Config, Misc Tools, Process Viewer, to unload all instances of the following running processes;[b] ystbmgnu.exe [/b] [color=blue]Scan with hijackthis and tick the boxes next to all the following entries, then [b][color=red]close all browser and explorer windows,[/color][/b] and hit the …

Member Avatar for crunchie
0
100
Member Avatar for Mader Paker

Download [url=http://tools.zerosrealm.com/AboutBuster.zip][color=blue]about:Buster[/color][/url] and unzip it to your Desktop. Doubleclick on AboutBuster.exe to run it and then click on Update > Check for Update. If there is an update available, click on 'Download Update and wait while it downloads. Once downloaded, click on Exit. When you have done this, boot into …

Member Avatar for crunchie
0
291
Member Avatar for Zápól

Download the [url=http://www.bleepingcomputer.com/files/spyware/KillBox.zip][color=blue]Pocket KillBox[/color][/url] Unzip the file to your desktop. Run Pocket Killbox and paste the full file path of each of the below files in the box and click on Standard File Kill and End Explorer Shell While Killing File. Click on the button with the red circle and …

Member Avatar for crunchie
0
84
Member Avatar for ell

Run [color=blue]Hijackthis[/color] and go to the [color=green]process viewer[/color] by going to Config, Misc Tools, Process Viewer, to unload all instances of the following running processes;[b] njwhzf.exe AdTools.exe salm.exe AdToolsKeep.exe gah95on6.exe wkskcopy.exe wmaext.exe CxtPls.exe [/b] Go to C:\WINDOWS\System32 and delete [b]njwhzf.exe, gah95on6.exe, wkskcopy.exe[/b] and [b]wmaext.exe.[/b] Go to C:\Program Files and delete …

Member Avatar for crunchie
0
123
Member Avatar for cjillson7030

Uninstall Mysearch, Mywebsearch, Myway from add/remove programs. Hi. You are running hijackthis from a temporary folder, can you please download the self-extracting version from [url=http://www.degs.co.uk/files/hijackthis.exe]here.[/url] Uninstall the other version first, then manually delete the file. [color=blue]Scan with hijackthis and tick the boxes next to all the following entries, then [b][color=red]close …

Member Avatar for caperjack
0
272
Member Avatar for J156306

Full of nasties there. Do the following first please. [b]Go [url=http://housecall.trendmicro.com/][u]here[/u][/url] to TrendMicro for an on-line scan & set it to autoclean for you. Try [URL=http://www.pandasoftware.com/activescan/com/activescan_principal.htm][u]this[/u][/URL] scan at Panda as well.[/b] 1. [b]Download and install [URL=http://www.lavasoftusa.com/software/adaware/][color=blue] Ad-Aware SE,[/color][/URL][/b] keeping the default options. [b]However, some of the settings will need to …

Member Avatar for crunchie
0
237
Member Avatar for tarunpant

You urgently require service pack 4 for Windows 2000!! [url]http://windowsupdate.microsoft.com/[/url] [color=blue]Scan with hijackthis and tick the boxes next to all the following entries, then [b][color=red]close all browser and explorer windows,[/color][/b] and hit the "Fix checked" button.[/color] O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file) O2 - BHO: …

Member Avatar for crunchie
0
161
Member Avatar for knuckleball

knuckleball. You have the qoologic trojan. Please go [url=http://home.earthlink.net/~firestrike/antispy/findqoologic.zip][b]here[/b][/url] and download [color=blue]Find_qoologic.zip[/color] by baskar1234. Unzip the folder and go to the new qoologic folder and doubleclick on qoologic.bat to run it. It will take a few minutes to scan your drive so be patient. When it has finished, open My …

Member Avatar for crunchie
0
540
Member Avatar for bbygiants

Try doing a system restore back to a point before you had the problems, then install the AV and a firewall.

Member Avatar for DMR
0
113
Member Avatar for dp600

Find your prefetch folder and delete the contents. When you close down system restore all items that are/were in that folder are completely eliminated. That being the case, the virus must be elsewhere. Do a system search for the particular file, being exact in it's spelling. If found, delete it. …

Member Avatar for dp600
0
376
Member Avatar for sflaumen

Go to add\remove programs and uninstall SpyKiller and BestPopUpKiller. They both appear on spyware warriors rogue list. [color=blue]Scan with hijackthis and tick the boxes next to all the following entries, then close all browser and explorer windows, and hit the "Fix checked" button.[/color] O4 - HKLM\..\Run: [CMESys] "C:\Program Files\Common Files\CMEII\CMESys.exe" …

Member Avatar for dlh6213
0
199
Member Avatar for civic

[QUOTE=civic] btw crunchie the wizard cup is soon upon us freo and port!!!:cheesy:[/QUOTE] Freo [b]and[/b] Port?? They playing with themselves again are they :lol:. Friday night and the Eagles are going to soar!! :mrgreen:

Member Avatar for dlh6213
0
122
Member Avatar for weepee

Hi weepee and welcome to DaniWeb :). [color=blue]Scan with hijackthis and tick the boxes next to all the following entries, then [b][color=red]close all browser and explorer windows,[/color][/b] and hit the "Fix checked" button.[/color] R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = [url]http://red.clientapps.yahoo.com/cus...rch/search.html[/url] R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = [url]http://red.clientapps.yahoo.com/cus...//www.yahoo.com[/url] R1 - HKLM\Software\Microsoft\Internet …

Member Avatar for crunchie
0
148
Member Avatar for helpme64

You have a lot of trash there that these automated apps can remove. If you do not wish to use Spybot S&D, then please use the others and post another hijackthis log after rebooting.

Member Avatar for crunchie
0
238
Member Avatar for ineedshelp

Run [color=blue]Hijackthis[/color] and go to the [color=green]process viewer[/color] by going to Config, Misc Tools, Process Viewer, to unload all instances of the following running processes;[b] AOLCLIENT.EXE [/b] [color=blue]Scan with hijackthis and tick the boxes next to all the following entries, then [b][color=red]close all browser and explorer windows,[/color][/b] and hit the …

Member Avatar for crunchie
0
109
Member Avatar for swn65

Go to Internet Options in IE and set your security settings to default. Try running [url=http://windowsxp.mvps.org/IEFIX.htm][color=blue]IEFIX.htm[/color][/url] which will repair IE and run a System File Check. Go [url=http://www.silentrunners.org/]here[/url] and download and run [color=blue]Silent Runners.vbs.[/color] It generates a log, please post the information back in this thread.

Member Avatar for crunchie
0
193
Member Avatar for Den.

[QUOTE=Den.][SIZE=3]I ran in safe mode and answered "no" to three surprise questions about merging things into the registry.[/SIZE][/QUOTE] What questions? There are a lot of registry entries that are created by this infection that remv3 removes. Also, please do not [b]shout.[/b] As DMR stated, we are all volunteers. We eat, …

Member Avatar for crunchie
0
270
Member Avatar for trbograndnat

This is a job for.......................[b]ADAWARE[/b] and it's partner in crime (fighting)...............[b]Spybot S&D.[/b] 1. [b]Download and install [URL=http://www.lavasoftusa.com/software/adaware/][color=blue] Ad-Aware SE,[/color][/URL][/b] keeping the default options. [b]However, some of the settings will need to be changed before your first scan[/b] 2.[b]Close ALL windows[/b] except Ad-Aware SE 3. Click on the[b]‘world’ [/b] icon at …

Member Avatar for crunchie
0
300
Member Avatar for aminura

You have missed posting the most important part of your log. The uppermost portion with the hijackthis version, OS and IE version. Please post it in your next reply. Looks like ME, but we have to be sure :). Download [url=http://tools.zerosrealm.com/AboutBuster.zip][color=blue]about:Buster[/color][/url] and unzip it to your Desktop. Doubleclick on AboutBuster.exe …

Member Avatar for crunchie
0
216
Member Avatar for robertdanmorris

Only one bad item there that I can see. [color=blue]Scan with hijackthis and tick the boxes next to all the following entries, then [b][color=red]close all browser and explorer windows,[/color][/b] and hit the "Fix checked" button.[/color] O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - [url]http://software-dl.real.com/05a9820...ip/RdxIE601.cab[/url] Go to system properties (right click MyComputer …

Member Avatar for crunchie
0
91
Member Avatar for pimpwack

Sticky @ the top of the forum regarding the DSO exploit. NvCpl.dll is related to your Nvidia card. [color=blue]Scan with hijackthis and tick the boxes next to all the following entries, then [b][color=red]close all browser and explorer windows,[/color][/b] and hit the "Fix checked" button.[/color] O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint …

Member Avatar for dlh6213
0
119
Member Avatar for HAWKZ

I have split your post from the other dead thread. First of all could you click Start>Settings>Control Panel>Add or Remove Programs and uninstall 'Window Search', 'Window Searching', 'Lop.com', 'LOP SEARCH', 'Browser Enhancer', or 'Ultimate Browser Enhancer' if listed. You may be given a code to insert, do so and reboot …

Member Avatar for HAWKZ
0
104
Member Avatar for xOctoberFallsx

Yep. [b]Download & instal [color=blue]Adaware[/color] from [url=http://www.computercops.biz/downloads-file-292.html][u]here[/u][/url][/b] & [color=red]update[/color] it before scanning. In settings under 'scanning,' have it set to 'scan within archives,' 'scan active processes,' 'scan registry,' 'deepscan registry' 'scan my IE Favourites for banned URL's,' 'scan my host's file.' In 'tweaks' under 'scanning engine' set it to 'unload …

Member Avatar for crunchie
0
140
Member Avatar for clod

You may still need to fix this entry with hijackthis; R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = [url]http://whcmuehbrkfscoz.com/kPWIIO5C...8AKRI5O4rp.html[/url]

Member Avatar for Catweazle
0
590
Member Avatar for caperjack
Member Avatar for Smithy

Download the [url=http://www.bleepingcomputer.com/files/spyware/KillBox.zip][color=blue]Pocket KillBox[/color][/url] Unzip the file to your desktop. Run Pocket Killbox and paste the full file path of each of the below files in the box and click on Standard File Kill and End Explorer Shell While Killing File. Click on the button with the red circle and …

Member Avatar for Smithy
0
147
Member Avatar for silver nekode

Download L2mfix from one of these two locations: [url]http://www.atribune.org/downloads/l2mfix.exe[/url] [url]http://www.downloads.subratam.org/l2mfix.exe[/url] Save the file to your desktop and double click l2mfix.exe. Click the Install button to extract the files and follow the prompts, then open the newly added l2mfix folder on your desktop. Double click l2mfix.bat and select option #1 for …

Member Avatar for dlh6213
0
113
Member Avatar for jhmcg

Hi. First of all you need to update hijackthis to version 1.99. Run hijackthis & go to *Config\Misc Tools\Check for update on-line*. If the site is down, go [url=http://computercops.biz/downloads-file-328.html][u]here.[/u][/url] Remove the old version by opening the program, going to config\misc tools, then uninstall & exit. You then have to delete …

Member Avatar for crunchie
0
318
Member Avatar for cdt1983

Please run the following, then reboot and post another log please. [b]Go [url=http://housecall.trendmicro.com/][u]here[/u][/url] to TrendMicro for an on-line scan & set it to autoclean for you. Try [URL=http://www.pandasoftware.com/activescan/com/activescan_principal.htm][u]this[/u][/URL] scan at Panda as well.[/b] 1. [b]Download and install [URL=http://www.lavasoftusa.com/software/adaware/][color=blue] Ad-Aware SE,[/color][/URL][/b] keeping the default options. [b]However, some of the settings will …

Member Avatar for dlh6213
0
114

The End.