4,383 Posted Topics

Member Avatar for Flint-Town

Unzip HJT into it's own permanent folder before doing anything in order for it to create backups. [color=red](Not a temporary folder or directly on the desktop & not directly on your hard drive).[/color] Close all (browser) windows & rescan with hijackthis. When the scan is finished place a check in …

Member Avatar for crunchie
0
104
Member Avatar for ArtChess

I know what you mean & have seen a similar problem B4, but cannot recollect where. Will try to remember.

Member Avatar for Yzk
0
72
Member Avatar for ufsguy
Member Avatar for Yzk
0
193
Member Avatar for jiggatom

Unzip HJT into it's own permanent folder before doing anything in order for it to create backups. [color=red](Not a temporary folder or directly on the desktop & not directly on your hard drive).[/color] Close all (browser) windows & rescan with hijackthis. When the scan is finished place a check in …

Member Avatar for jiggatom
0
571
Member Avatar for ryun

Unzip HJT into it's own permanent folder before doing anything in order for it to create backups. [color=red](Not a temporary folder or directly on the desktop & not directly on your hard drive).[/color] Close all (browser) windows & rescan with hijackthis. When the scan is finished place a check in …

Member Avatar for ryun
0
186
Member Avatar for jlward

Close all (browser) windows & rescan with hijackthis. When the scan is finished place a check in the box to the left of the following entries & click 'fix checked' : O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - [url]http://207.188.7.150/217669fe7bb25e...ip/RdxIE601.cab[/url] O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE

Member Avatar for crunchie
0
151
Member Avatar for courtney.

It is possibly in the system restore folder. More info is required. Operating System etc. Try these tools too: Download & instal Adaware from [url=http://www.computercops.biz/downloads-file-292.html][u]here[/u][/url] & update it B4 scanning. In settings under 'scanning,' have it set to 'scan within archives,' 'scan active processes,' 'scan registry,' 'deepscan registry' 'scan my …

Member Avatar for crunchie
0
151
Member Avatar for Manny805

In addition to Yzk's good advice, please Download CWShredder from [url=http://www.computercops.biz/zx/phoenix22/cws.zip][u]here[/u][/url] & run it. Select the fix button & it will get rid of everything related to CoolWebSearch that is stored in it's database. Close ALL windows, including IE, before running CWShredder. Reboot. To help prevent this from happening again, …

Member Avatar for crunchie
0
326
Member Avatar for pimpwack

Close all (browser) windows & rescan with hijackthis. When the scan is finished place a check in the box to the left of the following entries & click 'fix checked' : O4 - HKCU\..\Run: [NDrv] C:\WINDOWS\System32\NDrv.exe Reboot into safe mode following the instructions [url=http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001052409420406][u]here[/u][/url] & navigate to & delete the …

Member Avatar for crunchie
0
113
Member Avatar for sapole

Download & instal Adaware from [url=http://www.computercops.biz/downloads-file-292.html][u]here[/u][/url] & update it B4 scanning. In settings under 'scanning,' have it set to 'scan within archives,' 'scan active processes,' 'scan registry,' 'deepscan registry' 'scan my IE Favourites for banned URL's,' 'scan my host's file.' In 'tweaks' under 'scanning engine' set it to 'unload recognised …

Member Avatar for crunchie
0
91
Member Avatar for Rygar

First up, dump spykiller as it is next to useless & a rip off of a good, free product. Download dllfix from the following link. [url]http://tools.zerosrealm.com/dllfix.exe[/url] Create a folder on your desktop, doubleclick on the dllfix and install it into the folder you just created. 1.Run start.bat and press option …

Member Avatar for Rygar
0
153
Member Avatar for gattofi

Check in add/remove for something similar & remove it. You can also do the following: Download & instal Adaware from [url=http://www.computercops.biz/downloads-file-292.html][u]here[/u][/url] & update it B4 scanning. In settings under 'scanning,' have it set to 'scan within archives,' 'scan active processes,' 'scan registry,' 'deepscan registry' 'scan my IE Favourites for banned …

Member Avatar for DMR
0
117
Member Avatar for atky2004

Unzip HJT into it's own permanent folder before doing anything in order for it to create backups. [color=red](Not a temporary folder or directly on the desktop & not directly on your hard drive).[/color] Close all (browser) windows & rescan with hijackthis. When the scan is finished place a check in …

Member Avatar for crunchie
0
98
Member Avatar for tonyet

Download CWShredder from [url=http://www.computercops.biz/zx/phoenix22/cws.zip][u]here[/u][/url] & run it. Select the fix button & it will get rid of everything related to CoolWebSearch that is stored in it's database. Close ALL windows, including IE, before running CWShredder. Reboot. To help prevent this from happening again, install the patches for the vulnerabilities that …

Member Avatar for crunchie
0
151
Member Avatar for nilsouille2003

Close all (browser) windows & rescan with hijackthis. When the scan is finished place a check in the box to the left of the following entries & click 'fix checked' : R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINNT\system32\qcsmj.dll/sp.html#37049 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://qcsmj.dll/index.html#37049 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page …

Member Avatar for crunchie
0
215
Member Avatar for z3r0

You have a possible hijacker on board that Adaware cannot fix. Download dllfix from the following link. [url]http://tools.zerosrealm.com/dllfix.exe[/url] Create a folder on your desktop, doubleclick on the dllfix and install it into the folder you just created. 1.Run start.bat and press option 1. 'output.txt' will be created in the folder. …

Member Avatar for crunchie
0
79
Member Avatar for motopsycho

Unzip HJT into it's own permanent folder before doing anything in order for it to create backups. [color=red](Not a temporary folder or directly on the desktop & not directly on your hard drive).[/color] Close all (browser) windows & rescan with hijackthis. When the scan is finished place a check in …

Member Avatar for crunchie
0
170
Member Avatar for A-train

Download CWShredder from [url=http://www.computercops.biz/zx/phoenix22/cws.zip][u]here[/u][/url] & run it. Select the fix button & it will get rid of everything related to CoolWebSearch that is stored in it's database. Close ALL windows, including IE, before running CWShredder. Reboot. To help prevent this from happening again, install the patches for the vulnerabilities that …

Member Avatar for crunchie
0
125
Member Avatar for nosfree

Download CWShredder from [url=http://www.computercops.biz/zx/phoenix22/cws.zip][u]here[/u][/url] & run it. Select the fix button & it will get rid of everything related to CoolWebSearch that is stored in it's database. Close ALL windows, including IE, before running CWShredder. Reboot. To help prevent this from happening again, install the patches for the vulnerabilities that …

Member Avatar for crunchie
0
174
Member Avatar for jwalker

Unzip HJT into it's own permanent folder before doing anything in order for it to create backups. [color=red](Not a temporary folder or directly on the desktop & not directly on your hard drive).[/color] Close all (browser) windows & rescan with hijackthis. When the scan is finished place a check in …

Member Avatar for crunchie
0
78
Member Avatar for steviegee16

Ok. Little bit of a dogs breakfast there, but do a couple of things & we'll have you on your way in no time :) . Uninstall Mywebsearch from add remove programs. remove Newdotnet, either from add/remove programs, or by going [url=http://www.newdotnet.com/#remove][u]here.[/u][/url] & scrolling down to the uninstall tool. Download …

Member Avatar for crunchie
0
146
Member Avatar for Tripod 76

Reboot into safe mode following the instructions [url=http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001052409420406][u]here[/u][/url] & Unzip HJT into it's own permanent folder before doing anything in order for it to create backups. [color=red](Not a temporary folder or directly on the desktop & not directly on your hard drive).[/color] Close all (browser) windows & rescan with hijackthis. …

Member Avatar for crunchie
0
233
Member Avatar for whongtat

Unzip HJT into it's own permanent folder before doing anything in order for it to create backups. [color=red](Not a temporary folder or directly on the desktop & not directly on your hard drive).[/color] Close all (browser) windows & rescan with hijackthis. When the scan is finished place a check in …

Member Avatar for crunchie
0
63
Member Avatar for marijana

Come back, you have stuff to remove! Close all (browser) windows & rescan with hijackthis. When the scan is finished place a check in the box to the left of the following entries & click 'fix checked' : F2 - REG:system.ini: UserInit=C:\Windows\ System32\wsaupdater.exe, O16 - DPF: {E0CE16CB-741C-4B24-8D04-A817856E07F4} - [url]http://cabs.roings.com/cabs/mp3.cab[/url]

Member Avatar for marijana
0
146
Member Avatar for xDylanx

Try to delete in safe mode. Reboot into safe mode following the instructions [url=http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001052409420406][u]here[/u][/url]

Member Avatar for crunchie
0
101
Member Avatar for Brad Gibson

Download & instal Adaware from [url=http://www.computercops.biz/downloads-file-292.html][u]here[/u][/url] & update it B4 scanning. In settings under 'scanning,' have it set to 'scan within archives,' 'scan active processes,' 'scan registry,' 'deepscan registry' 'scan my IE Favourites for banned URL's,' 'scan my host's file.' In 'tweaks' under 'scanning engine' set it to 'unload recognised …

Member Avatar for crunchie
0
74
Member Avatar for SylviaC

Unzip HJT into it's own permanent folder before doing anything in order for it to create backups. [color=red](Not a temporary folder or directly on the desktop & not directly on your hard drive).[/color] Close all (browser) windows & rescan with hijackthis. When the scan is finished place a check in …

Member Avatar for crunchie
0
273
Member Avatar for flyerorange

Hopefully you backed up the registry before messing with it?? The entries you deleted certainly sound like malware entries. Try the following: Download & instal Adaware from [url=http://www.computercops.biz/downloads-file-292.html][u]here[/u][/url] & update it B4 scanning. In settings under 'scanning,' have it set to 'scan within archives,' 'scan active processes,' 'scan registry,' 'deepscan …

Member Avatar for crunchie
0
80
Member Avatar for ArtChess

While you are sleeping caperjack :) . Please uninstall webhancer from add/remove programs first. Close all (browser) windows & rescan with hijackthis. When the scan is finished place a check in the box to the left of the following entries & click 'fix checked' : R3 - URLSearchHook: (no name) …

Member Avatar for ArtChess
0
169
Member Avatar for ajelliott

First up a move to IE6 is a must for security reasons alone. Close all (browser) windows & rescan with hijackthis. When the scan is finished place a check in the box to the left of the following entries & click 'fix checked' : R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = …

Member Avatar for ajelliott
0
301
Member Avatar for JBV

Please do not run those tools yet or the dll may change it's name & we'll have to see another log :) but please do the rest of what DMR requested. IF hidden dll was successfully found, run start.bat again and choose option 2. Hit '1' and enter dll name …

Member Avatar for DMR
0
524
Member Avatar for 1100

As caperjack said, you need to post a complete log before we are able to help you out. You can do this too before posting: First of all we have to remove Newdotnet, either from add/remove programs, or by going [url=http://www.newdotnet.com/#remove][u]here.[/u][/url] & scrolling down to the uninstall tool.

Member Avatar for crunchie
0
85
Member Avatar for WonderingAboutT

Optical Character Recognition software as part of OmniPage Limited Edition - supplied with some scanners. Scan directly into most word processor applications, such as Word, WordPerfect, etc. If the error message is gone it's a good thing. Fix this with hjt with ALL windows closed. O16 - DPF: {26E8361F-BCE7-4F75-A347-98C88B418322} - …

Member Avatar for crunchie
0
294
Member Avatar for ams13x

First of all try clearing out your temp internet files & also your cookies in IE. Also, try opening a new account & see if you can get in that way.

Member Avatar for crunchie
0
94
Member Avatar for buddyb

Yuck. You will have to run a few automatic removal tools first before we finish up removing the leftovers manually :) . Please do all the following. Download the PeperFix.exe tool from here: [url]http://downloads.subratam.org/PeperFix.exe[/url] Click on the PeperFix.exe to launch it. Click the Find and Fix button. It will scan …

Member Avatar for crunchie
0
100
Member Avatar for azvincent

Download CWShredder from [url=http://www.computercops.biz/zx/phoenix22/cws.zip][u]here[/u][/url] & run it. Select the fix button & it will get rid of everything related to CoolWebSearch that is stored in it's database. Close ALL windows, including IE, before running CWShredder. Reboot. To help prevent this from happening again, install the patches for the vulnerabilities that …

Member Avatar for crunchie
0
120
Member Avatar for telugodu

You have (amongst other things) the Peper trojan. Please do the following exactly. Download the PeperFix.exe tool from here: [url]http://downloads.subratam.org/PeperFix.exe[/url] Click on the PeperFix.exe to launch it. Click the Find and Fix button. It will scan the %Systemroot% folder and locate all the peper files. You will be prompted to …

Member Avatar for crunchie
0
197
Member Avatar for J☼E

Download & install spywareblaster & update. Go to the cookie manager & block it from there also.

Member Avatar for Catweazle
0
295
Member Avatar for kriskarrera

You have LOTS. Of nasties. Do the following first then post another log. I have to sign off now but someone else can hopefully pick this up while I'm asleep :) . Download & instal Adaware from [url=http://www.computercops.biz/downloads-file-292.html][u]here[/u][/url] & update it B4 scanning. In settings under 'scanning,' have it set …

Member Avatar for kriskarrera
0
93
Member Avatar for ArtChess

Take a look [url=http://www.pestpatrol.com/pestinfo/b/bookedspace.asp][b][u]here.[/u][/b][/url]

Member Avatar for crunchie
0
56
Member Avatar for Lucky

Download & instal Adaware from [url=http://www.computercops.biz/downloads-file-292.html][u]here[/u][/url] & update it B4 scanning. In settings under 'scanning,' have it set to 'scan within archives,' 'scan active processes,' 'scan registry,' 'deepscan registry' 'scan my IE Favourites for banned URL's,' 'scan my host's file.' In 'tweaks' under 'scanning engine' set it to 'unload recognised …

Member Avatar for crunchie
0
73
Member Avatar for steveb99

Close all (browser) windows & rescan with hijackthis. When the scan is finished place a check in the box to the left of the following entries & click 'fix checked' : R3 - URLSearchHook: MailTo Class - {FDE3577A-6254-181C-4E11-339E4F746BD3} - C:\WINDOWS\System32\win32st.dll O17 - HKLM\System\CCS\Services\Tcpip\..\{B82865EE-5C19-41F9-A13A-1D79ADDD03EC}: NameServer = 207.229.64.3,199.254.229.65 Clear your TIF's & …

Member Avatar for crunchie
0
171
Member Avatar for arobrien

Download dllfix from the following link. [url]http://tools.zerosrealm.com/dllfix.exe[/url] Create a folder on your desktop, doubleclick on the dllfix and install it into the folder you just created. 1.Run start.bat and press option 1. 'output.txt' will be created in the folder. Post the results of the log here.

Member Avatar for crunchie
0
141
Member Avatar for pmurthy

Download dllfix from the following link. [url]http://tools.zerosrealm.com/dllfix.exe[/url] Create a folder on your desktop, doubleclick on the dllfix and install it into the folder you just created. 1.Run start.bat and press option 1. 'output.txt' will be created in the folder. Post the results of the log here.

Member Avatar for crunchie
0
99
Member Avatar for tom olson

Download CWShredder from [url=http://www.computercops.biz/zx/phoenix22/cws.zip][u]here[/u][/url] & run it. Select the fix button & it will get rid of everything related to CoolWebSearch that is stored in it's database. Close ALL windows, including IE, before running CWShredder. Reboot. To help prevent this from happening again, install the patches for the vulnerabilities that …

Member Avatar for crunchie
0
182
Member Avatar for kuelze

Thats probably because you have a Windows 9X system. The fix was for W2K & XP. Want to post you HJT log here?

Member Avatar for crunchie
0
121
Member Avatar for pumpkindad

Close all (browser) windows & have HJT fix these entries= O4 - HKLM\..\Run: [sysmon] C:\WINNT\System32\sysmon45.exe O4 - HKLM\..\Run: [Svshost] C:\WINNT\System32\svshost.exe 443 O4 - HKLM\..\Run: [inrnrw] C:\WINNT\System32\inrnrw.exe O19 - User stylesheet: C:\WINNT\Web\tips.ini O19 - User stylesheet: C:\WINNT\hh.htt (HKLM) Reboot into safe mode following the instructions here. [url]http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001052409420406[/url] & navigate to & …

Member Avatar for crunchie
0
317
Member Avatar for Xev0luti0nXx

Download CWShredder from [url=http://www.computercops.biz/zx/phoenix22/cws.zip][u]here[/u][/url] & run it. Select the fix button & it will get rid of everything related to CoolWebSearch that is stored in it's database. Close ALL windows, including IE, before running CWShredder. Reboot. To help prevent this from happening again, install the patches for the vulnerabilities that …

Member Avatar for crunchie
0
100
Member Avatar for Firedad
Member Avatar for FrankLaney

Download: "StartDreck" from here: <a href="http://members.blackbox.net/hp_links/21/nikolaus.rameis/download/startdreck.htm" rel="nofollow">here</a> &amp; unzip! DoubleClick: 'StartDreck.exe' Hit: config hit: Unmark all Check these boxes only: Registry-&gt;run keys System/drivers&gt; Running processes hit &gt;ok. Check specifically for this entry in the log : Quote: »Local Machine »RunServicesOnce **ozkc=rundll32 C:\WINDOWS\SYSTEM\XXXXX.DLL,StreamingDeviceSetup After identifying the dll, proceed with : -Download: …

Member Avatar for caperjack
0
188

The End.