4,383 Posted Topics

Member Avatar for Squirty
Member Avatar for Foxxy

Hi. First of all you need to update hijackthis to version 1.98.2. Run hijackthis & go to *Config\Misc Tools\Check for update on-line*. If the site is down, go [url=http://www.computercops.biz/downloads-file-328.html][u]here.[/u][/url] Remove the old version by deleting the file manually. Unzip the new version into the hijackthis folder. You missed the very …

Member Avatar for crunchie
0
229
Member Avatar for Sphyenx
Member Avatar for Kamex
0
177
Member Avatar for zyger

Hi. First of all you need to update hijackthis to version 1.98. Run hijackthis & go to *Config\Misc Tools\Check for update on-line*. Remove 1.97 from the folder it is in & replace it with 1.98. Then, open Task Manager & end process on the following; [b]Loader.exe[/b] [b]Unzip HJT into it's …

Member Avatar for crunchie
0
368
Member Avatar for kriskarrera

[b]Download [color=blue]CWShredder[/color] from [url=http://www.computercops.biz/zx/phoenix22/cws.zip][u]here[/u][/url] & run it.[/b] Select the [color=red]fix[/color] button & it will fix everything related to CoolWebSearch that is stored in it's database. Close [b]ALL[/b] windows, including Iinternet Explorer, before running CWShredder. [color=red]Reboot.[/color] To help prevent this from happening again, install the patches for the vulnerabilities that this …

Member Avatar for kenji1
0
190
Member Avatar for MvRojo

Find hijackthis here: [b]Download [color=blue]HijackThis[/color] from [url=http://www.computercops.biz/downloads-file-328.html][u]here[/u][/url][/b] & unzip it into it's own, permanent folder, [color=red](Not a temporary folder or the desktop (in a folder on the desktop is fine) & not directly on your hard drive)[/color]. If you prefer an executable file, then download from [url=https://ssl.perfora.net/tools.radiosplace.com/HijackThis.exe]here.[/url] If you have …

Member Avatar for MvRojo
0
245
Member Avatar for sandybeach

[b]Go [url=http://housecall.trendmicro.com/][u]here[/u][/url] to TrendMicro for an on-line scan & set it to autoclean for you. Try [URL=http://www.pandasoftware.com/activescan/com/activescan_principal.htm][u]this[/u][/URL] scan at Panda as well.[/b] Once you have done that, [b]Download & instal [color=blue]Adaware[/color] from [url=http://computercops.biz/downloads-file-292.html][u]here[/u][/url][/b] & [color=red][b]update[/b][/color] it before scanning. In settings under 'scanning,' have it set to 'scan within archives,' 'scan …

Member Avatar for dlh6213
0
190
Member Avatar for Jackal

Right at the top of this forum is a request to [b]Post all HijackThis logs in the security forum.[/b] [url]http://www.daniweb.com/techtalkforums/announcement.php?f=29&announcementid=1[/url] Please read from the link :). [b]Go [url=http://housecall.trendmicro.com/][u]here[/u][/url] to TrendMicro for an on-line scan & set it to autoclean for you. Try [URL=http://www.pandasoftware.com/activescan/com/activescan_principal.htm][u]this[/u][/URL] scan at Panda as well.[/b] Moving this …

Member Avatar for crunchie
0
126
Member Avatar for acd

Hi. First of all you need to update hijackthis to version 1.98.2. Run hijackthis & go to *Config\Misc Tools\Check for update on-line*. If the site is down, go [url=http://www.computercops.biz/downloads-file-328.html][u]here.[/u][/url] Remove the old version by deleting the file manually. Unzip the new version into the hijackthis folder. Click My Computer, then …

Member Avatar for crunchie
0
136
Member Avatar for camelNotation
Member Avatar for chef

[b]Download [color=blue]HijackThis[/color] from [url=http://www.computercops.biz/downloads-file-328.html][u]here[/u][/url][/b] & unzip it into it's own, permanent folder, [color=red](Not a temporary folder or the desktop (in a folder on the desktop is fine) & not directly on your hard drive)[/color]. If you have anything disabled in MsConfig, please re-enable it/them. Start HJT & with all browser …

Member Avatar for DuncanIdaho
0
354
Member Avatar for lvoutlaw

Yes, you are full of viruses. [b]Go [url=http://housecall.trendmicro.com/][u]here[/u][/url] for an on-line scan & set it to autoclean for you. Try [URL=http://www.pandasoftware.com/activescan/com/activescan_principal.htm][u]this[/u][/URL] scan as well.[/b] [b]Please go [url=http://www.pchell.com/support/wintools.shtml][u]here[/u][/url] for Wintools removal instructions.[/b] [b]Clear out your Temporary internet files and other temp files. Go to Start > Settings > Control Panel >Internet …

Member Avatar for crunchie
0
165
Member Avatar for lizmaracin

First of all could you click Start>Settings>Control Panel>Add or Remove Programs and uninstall 'Window Search', 'Window Searching', 'Lop.com', 'LOP SEARCH', 'Browser Enhancer', or 'Ultimate Browser Enhancer' if listed. You may be given a code to insert, do so and reboot when done. If not listed there, run this uninstaller: [url]http://members.rogers.com/rjmac/new_uninstall.exe[/url] …

Member Avatar for crunchie
0
176
Member Avatar for JellyHead

Uninstall Messenger Plus & re-install it manually without the sponsor, LOP. Could you click Start>Settings>Control Panel>Add or Remove Programs and uninstall 'Window Search', 'Window Searching', 'Lop.com', 'LOP SEARCH', 'Browser Enhancer', or 'Ultimate Browser Enhancer' if listed. You may be given a code to insert, do so and reboot when done. …

Member Avatar for crunchie
0
287
Member Avatar for doctorcoool

These entries are legitimate & are related to your modem: O4 - HKLM\..\Run: [GWMDMMSG] GWMDMMSG.exe O4 - HKLM\..\Run: [GWMDMpi] C:\WINNT\GWMDMpi.exe Go to your hijackthis folder & restore the back-up. [b]Unzip HJT into it's own permanent folder[/b] before doing anything in order for it to create backups. [color=red](Not a temporary folder …

Member Avatar for DuncanIdaho
0
304
Member Avatar for richardmaibes

[b]Download & instal [color=blue]Adaware[/color] from [url=http://www.computercops.biz/downloads-file-292.html][u]here[/u][/url][/b] & [color=red]update[/color] it before scanning. In settings under 'scanning,' have it set to 'scan within archives,' 'scan active processes,' 'scan registry,' 'deepscan registry' 'scan my IE Favourites for banned URL's,' 'scan my host's file.' In 'tweaks' under 'scanning engine' set it to 'unload recognised …

Member Avatar for crunchie
0
162
Member Avatar for Dark_Omen

[b]Unzip HJT into it's own permanent folder[/b] before doing anything in order for it to create backups. [color=red](Not a temporary folder or directly on the desktop (in a folder on the desktop is fine) & not directly on your hard drive).[/color] [b]Close all (browser) windows & rescan with hijackthis.[/b] When …

Member Avatar for Dark_Omen
0
121
Member Avatar for mikeandike22
Member Avatar for Skalliwag

Hi. First of all you need to update hijackthis to version 1.98.2. Run hijackthis & go to *Config\Misc Tools\Check for update on-line*. If the site is down, go [url=http://www.computercops.biz/downloads-file-328.html][u]here.[/u][/url] Remove the old version by deleting the file manually. Unzip the new version into the hijackthis folder. [b]Go [url=http://housecall.trendmicro.com/][u]here[/u][/url] for an …

Member Avatar for crunchie
0
99
Member Avatar for dlh6213

A proxy is where you use something like a 3rd party to access the web, similar to a web filter. You have the about:blank hijacker which deposits a hidden dll that reinstalls itself if not removed completely. I will leave instructions at the end of my post for you to …

Member Avatar for DMR
0
1K
Member Avatar for bumpaw

Can you please download this file from here: [url=http://www.bleepingcomputer.com/files/spyware/getservice.zip]Getservice.zip[/url] Extract the file to the c:\ drive. Then navigate to the c:\getservices and double-click on the getservices.bat file. A notepad will open up. Please paste the contents of that notepad into this post.

Member Avatar for bumpaw
0
229
Member Avatar for BlueByeU42

Have received the following, so please give it a try. Go to Start/Run & type [b]regedit[/b] & hit OK. Go to: HKEY_CURRENT_USER\Control Panel\don't load Look in the right pane and you'll see the Control Panel Icons that have been disabled. You can either right click on the "don't load" subkey …

Member Avatar for BlueByeU42
0
116
Member Avatar for alsoule

[b]Unzip HJT into it's own permanent folder[/b] before doing anything in order for it to create backups. [color=red](Not a temporary folder or directly on the desktop (in a folder on the desktop is fine) & not directly on your hard drive).[/color] Click My Computer, then C:\ In the menu bar, …

Member Avatar for crunchie
0
383
Member Avatar for scot_wil

It would appear that you have attached the actual program instead of the log :).

Member Avatar for DuncanIdaho
0
199
Member Avatar for dlh6213
Member Avatar for ShWaRtSaZ
Member Avatar for ShWaRtSaZ
0
246
Member Avatar for Nexxuz
Member Avatar for Yzk

Hi again Yzk. It is a little under the weather. Have a look in add/remove programs for Bargain Buddy & uninstall it, if found. If not, please do the following: Update hijackthis to version 1.98.2. Run hijackthis & go to *Config\Misc Tools\Check for update on-line*. If the site is down, …

Member Avatar for crunchie
0
193
Member Avatar for dannyboi5704

[b]Reboot into safe mode[/b] following the instructions [url=http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001052409420406][u]here[/u][/url] & [b]Close all (browser) windows & rescan with hijackthis.[/b] When the scan is finished place a check in the box to the left of the following entries & click [color=red]'fix checked':[/color] R1 - HKCU\Software\Microsoft\Internet Explorer,Search = [url]http://bestsearch.name/search.html[/url] R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = …

Member Avatar for crunchie
0
148
Member Avatar for kained

[b]Remove Newdotnet,[/b] either from add/remove programs, or by going [url=http://www.newdotnet.com/#remove][u]here[/u][/url] & scrolling down to the uninstall tool.

Member Avatar for crunchie
0
145
Member Avatar for gmb

[url]http://www.downloads.subratam.org/VX2Finder9x.exe[/url] L2M files are slightly different in 9x, 1.) Scan with the finder, select files it finds and delete them. 2.) During the deletion the utility will end both Rundll32 & explorer.exe processes, so when all files are gone. 3.) Click the restore desktop button to get the desktop back. …

Member Avatar for crunchie
0
69
Member Avatar for swagrock

Can you please download this file from here: [url=http://www.bleepingcomputer.com/files/spyware/getservice.zip]Getservice.zip[/url] Extract the file to the c:\ drive. Then navigate to the c:\getservices and double-click on the getservices.bat file. A notepad will open up. Please paste the contents of that notepad into this post.

Member Avatar for crunchie
0
180
Member Avatar for Zohar818

[b]Go [url=http://housecall.trendmicro.com/][u]here[/u][/url] for an on-line scan & set it to autoclean for you. Try [URL=http://www.pandasoftware.com/activescan/com/activescan_principal.htm][u]this[/u][/URL] scan as well.[/b]

Member Avatar for Zohar818
0
270
Member Avatar for Dani

I have the same problem at another site that I help out at. I have EZ trust Av & it goes off on some threads with HJT logs & then I am denied access to the rest of the thread where the code is.

Member Avatar for antioed
0
666
Member Avatar for sbstandards

Hi. First of all you need to update hijackthis to version 1.98.2. Run hijackthis & go to *Config\Misc Tools\Check for update on-line*. If the site is down, go [url=http://www.computercops.biz/downloads-file-328.html][u]here.[/u][/url] Remove the old version by deleting the file manually. Unzip the new version into the hijackthis folder. Uninstall system soap pro …

Member Avatar for crunchie
0
223
Member Avatar for agal82

Hi. First of all you need to update hijackthis to version 1.98.2. Run hijackthis & go to *Config\Misc Tools\Check for update on-line*. If the site is down, go [url=http://www.computercops.biz/downloads-file-328.html][u]here.[/u][/url] Remove the old version by opening the program, going to config\misc tools, then uninstall & exit. You then have to delete …

Member Avatar for crunchie
0
292
Member Avatar for shpusalk

Hi. First of all you need to update hijackthis to version 1.98.2. Run hijackthis & go to *Config\Misc Tools\Check for update on-line*. If the site is down, go [url=http://www.computercops.biz/downloads-file-328.html][u]here.[/u][/url] Remove the old version by opening the program, going to config\misc tools, then uninstall & exit. You then have to delete …

Member Avatar for deonnanicole
0
294
Member Avatar for Xev0luti0nXx

Download About:buster from [url]http://malwarebytes.biz/AboutBuster.zip[/url] and unzip it to your desktop. [b]Download & instal [color=blue]Adaware[/color] from [url=http://www.computercops.biz/downloads-file-292.html][u]here[/u][/url][/b] & [color=red]update[/color] it before scanning. In settings under 'scanning,' have it set to 'scan within archives,' 'scan active processes,' 'scan registry,' 'deepscan registry' 'scan my IE Favourites for banned URL's,' 'scan my host's file.' …

Member Avatar for Xev0luti0nXx
0
157
Member Avatar for nophin

[b]Close all (browser) windows & rescan with hijackthis.[/b] When the scan is finished place a check in the box to the left of the following entries & click [color=red]'fix checked':[/color] R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = [url]http://red.clientapps.yahoo.com/cus...://my.yahoo.com[/url] R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = [url]http://www.ghecilotkw.com/fFp/JC16y...0nV1l/rSzO.html[/url] O1 - Hosts: comments (such as these) …

Member Avatar for crunchie
0
141
Member Avatar for Mystic

[b]Download [color=blue]CWShredder[/color] from [url=http://www.computercops.biz/zx/phoenix22/cws.zip][u]here[/u][/url] & run it.[/b] Select the [color=red]fix[/color] button & it will fix everything related to CoolWebSearch that is stored in it's database. Close [b]ALL[/b] windows, including Iinternet Explorer, before running CWShredder. [color=red]Reboot.[/color] To help prevent this from happening again, install the patches for the vulnerabilities that this …

Member Avatar for crunchie
0
201
Member Avatar for chuckt
Re: lsgj

Please go [url=http://www.kaspersky.com/remoteviruschk.html][u]here[/u][/url] and have this file scanned. lsgj.exe You will have to find it's location.

Member Avatar for crunchie
0
36
Member Avatar for paulodowd
Member Avatar for z3r0

According to Computer Cops CLSID list, it comes up clean :). [url]http://computercops.biz/CLSID.html[/url]

Member Avatar for crunchie
0
206
Member Avatar for mike_m_14@hotma

mike_m_14@hotma. [b]Download LSPfix from [url=http://www.computercops.biz/downloads-file-334.html][u]here[/u][/url][/b] On the opening screen, click the "I know what I'm doing" checkbox. Check all instances of "osmim.dll" [b](and nothing else),[/b] and move them to the "Remove" pane. Then click Finish. Uninstall Webrebates from add remove programs. Open Task Manager & end process on the following: …

Member Avatar for mike_m_14@hotma
0
331
Member Avatar for Darkone4ever

Hi. First of all you need to update hijackthis to version 1.98.2. Run hijackthis & go to *Config\Misc Tools\Check for update on-line*. If the site is down, go [url=http://www.computercops.biz/downloads-file-328.html][u]here.[/u][/url] Remove the old version by deleting the file manually. Unzip the new version into the hijackthis folder. Click My Computer, then …

Member Avatar for Darkone4ever
0
204
Member Avatar for jonnymaun

Download About:buster from [url]http://malwarebytes.biz/AboutBuster.zip[/url] and unzip it to your desktop. [b]Download & instal [color=blue]Adaware[/color] from [url=http://www.computercops.biz/downloads-file-292.html][u]here[/u][/url][/b] & [color=red]update[/color] it before scanning. In settings under 'scanning,' have it set to 'scan within archives,' 'scan active processes,' 'scan registry,' 'deepscan registry' 'scan my IE Favourites for banned URL's,' 'scan my host's file.' …

Member Avatar for jonnymaun
0
163
Member Avatar for flowerman

[list=1][*]Make sure your settings allow you to view "Hidden files" & "hide protected operating system files" is unchecked. Open up any explorer windows and click on "Tools" => "Folder Options" => "View" and be sure to check off "Show Hidden Files and Folders". [*]Press Ctrl+Alt+Delete once => Click Task Manager …

Member Avatar for DMR
0
412
Member Avatar for ebro

Hey there bro :). [b]Close all (browser) windows & rescan with hijackthis.[/b] When the scan is finished place a check in the box to the left of the following entries & click [color=red]'fix checked':[/color] R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = [url]http://red.clientapps.yahoo.com/cus.../search/ie.html[/url] R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = [url]http://red.clientapps.yahoo.com/cus...//www.yahoo.com[/url] O4 - HKLM\..\Run: …

Member Avatar for crunchie
0
100
Member Avatar for Larry Eustacy

Please post a normal log from hijackthis after doing the following: [b]Download the PeperFix.exe tool from here:[/b] [url]http://downloads.subratam.org/PeperFix.exe[/url] Click on the PeperFix.exe to launch it. Click the Find and Fix button. It will scan the %Systemroot% folder and locate all the peper files. You will be prompted to reboot. Reboot …

Member Avatar for crunchie
0
110
Member Avatar for jackoutlawz

First of all could you click Start>Settings>Control Panel>Add or Remove Programs and uninstall 'Window Search', 'Window Searching', 'Lop.com', 'LOP SEARCH', 'Browser Enhancer', or 'Ultimate Browser Enhancer' if listed. You may be given a code to insert, do so and reboot when done. If not listed there, run this uninstaller: [url]http://members.rogers.com/rjmac/new_uninstall.exe[/url] …

Member Avatar for crunchie
0
115

The End.