4,383 Posted Topics

Member Avatar for natewax

[QUOTE=natewax]Ok, I got rid of everything that you listed and rebooted. Let me knew how this looks and if there is anything else I should do. Thanks a ton.[/QUOTE] R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file) With the above R3, you won't be able to delete it …

Member Avatar for crunchie
0
154
Member Avatar for philk

Close all (browser) windows & rescan with hijackthis. When the scan is finished place a check in the box to the left of the following entries & click 'fix checked' : R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = [url]http://prosearching.com/passthrough...p://about:blank[/url] O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file) O2 - …

Member Avatar for crunchie
0
123
Member Avatar for suntzu

Close all (browser) windows & rescan with hijackthis. When the scan is finished place a check in the box to the left of the following entries & click 'fix checked' : R3 - Default URLSearchHook is missing O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL O2 …

Member Avatar for crunchie
0
187
Member Avatar for kuzichan
Member Avatar for ArthurA

Unzip HJT into it's own permanent folder before doing anything in order for it to create backups. [color=red](Not a temporary folder or the desktop & not directly on your hard drive).[/color] Close all (browser) windows & rescan with hijackthis. When the scan is finished place a check in the box …

Member Avatar for DMR
0
133
Member Avatar for PCoker

Ok. Please do the following & we will see if we can get it sorted for you. Download CWShredder from [url=http://www.computercops.biz/zx/phoenix22/cws.zip][u]here[/u][/url] & run it. Select the fix button & it will get rid of everything related to CoolWebSearch that is stored in it's database. Close ALL windows, including IE, before …

Member Avatar for crunchie
0
153
Member Avatar for Jra2003

I will just concentrate on the first one for now. They both need work, but the first has THE hardest to remove hijacker yet. We'll get rid of some of the easy trash first, then go on to the main prize. You have to do all the work so I …

Member Avatar for crunchie
0
447
Member Avatar for agal82
Member Avatar for agal82
0
388
Member Avatar for scribble1

Download dllfix.exe from [url]http://downloads.subratam.org/dllfix.exe[/url] . Create a folder on your desktop & click on the exe you downloaded. Direct the install into the new folder. You will see there are two more folders inside and two BAT files. Run start.bat & select option 1 for the report. Once the search …

Member Avatar for crunchie
0
128
Member Avatar for Vanth

No promises here cos you may end up having to reformat. Download this zip. [url]http://tools.zerosrealm.com/pv.zip[/url] Please unzip it to the desktop. It will not work if you run it from inside the zip. After unzipped go to the desktop. Open the pv folder. Double click on the runme.bat A dos …

Member Avatar for crunchie
0
169
Member Avatar for Specter

Unzip HJT into it's own permanent folder before doing anything in order for it to create backups. [color=red](Not a temporary folder or the desktop & not directly on your hard drive).[/color] Close all (browser) windows & rescan with hijackthis. When the scan is finished place a check in the box …

Member Avatar for crunchie
0
176
Member Avatar for guata

Close all (browser) windows & rescan with hijackthis. When the scan is finished place a check in the box to the left of the following entries & click 'fix checked' : R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = [url]http://www.hotbar.com/dyn/hotbar/3....rchPageHome.htm[/url] R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Vênculos F0 - system.ini: Shell= F2 - REG:system.ini: …

Member Avatar for DMR
-1
226
Member Avatar for chazzman

Unzip HJT into it's own permanent folder before doing anything in order for it to create backups. [color=red](Not a temporary folder or the desktop & not directly on your hard drive).[/color] Close all (browser) windows & rescan with hijackthis. When the scan is finished place a check in the box …

Member Avatar for chazzman
0
185
Member Avatar for CalumsDad

Ok. Please do the following & we will see if we can get it sorted for you. Download CWShredder from [url=http://www.computercops.biz/downloads-file-349.html]here[/url] & run it. Select the fix button & it will get rid of everything related to CoolWebSearch. Close ALL other programs & windows, including IE, before running CWShredder. Download …

Member Avatar for DMR
0
123
Member Avatar for kriskarrera

Ok. Please do the following & we will see if we can get it sorted for you. Download CWShredder from [url=http://www.computercops.biz/zx/phoenix22/cws.zip][u]here[/u][/url] & run it. Select the fix button & it will get rid of everything related to CoolWebSearch that is stored in it's database. Close ALL windows, including IE, before …

Member Avatar for crunchie
0
387
Member Avatar for Droop418
Member Avatar for SarahH

Go [url=http://housecall.trendmicro.com/][u]here[/u][/url] for an on-line scan & set it to autoclean for you. Make SURE that you set it to clean. Download HijackThis from [url=http://www.computercops.biz/downloads-file-328.html][u]here[/u][/url] & unzip it into it's own, permanent folder, [color=red](not a temporary folder & not on the desktop)[/color]. Start HJT & press the scan button. When …

Member Avatar for crunchie
0
619
Member Avatar for SarahH

A good way of telling is if it's freeware. If free it is suspect. Do a google search on the product name & check the results.

Member Avatar for crunchie
0
97
Member Avatar for SarahH

All you need do with spywareblaster is keep it updated, say once a week & thats it. Once updated just close out of the program. It prevents the installation of bad activex controls that it has in it's database.

Member Avatar for crunchie
0
118
Member Avatar for LadyMcbeth

Close all (browser) windows & rescan with hijackthis. When the scan is finished place a check in the box to the left of the following entries & click 'fix checked' : O2 - BHO: (no name) - {10C68D31-7094-4278-B41A-874AEF928A2C} - C:\WINNT\pxRI1.dll O2 - BHO: (no name) - {CE1C8CDD-B3C1-4D39-87B2-55240FB75D67} - C:\WINNT\aloxvs.dll O4 …

Member Avatar for crunchie
0
145
Member Avatar for HPriser

Download HijackThis from [url=http://www.computercops.biz/downloads-file-328.html][u]here[/u][/url] & unzip it into it's own, permanent folder, [color=red](not a temporary folder & not on the desktop)[/color]. Start HJT & press the scan button. When the scan is finished the scan button will change to save. Save the log to a text file, copy the entire …

Member Avatar for HPriser
0
270
Member Avatar for annamarie

Go [url=http://housecall.trendmicro.com/][u]here[/u][/url] for an on-line scan & set it to autoclean for you. Download & instal Adaware from [url=http://www.computercops.biz/downloads-file-292.html][u]here[/u][/url] & update it B4 scanning. In settings under 'scanning,' have it set to 'scan within archives,' 'scan active processes,' 'scan registry,' 'deepscan registry' 'scan my IE Favourites for banned URL's,' 'scan …

Member Avatar for annamarie
0
171
Member Avatar for MAD_DOG

Perhaps there should be a sticky asking ppl to search the forum for their particular problem, then go through the same process of removal? There are a lot of ppl though who have little or no knowledge of delving into these thingz, ot the confidence that they will not remove …

Member Avatar for MAD_DOG
0
71
Member Avatar for ehupp

I don't see anything bad there but try uninstalling this O3 - Toolbar: Vivisimo - {5538fb62-f725-4433-a965-91314e8d8e4d} - C:\Program Files\Vivisimo\Toolbar\tbu14\toolbar.dll & see if it works correctly. You may also have to do a repair of IE.

Member Avatar for ehupp
0
467
Member Avatar for Rimmetje

Rimmetje. 1. Please read the post above yours by myself. 2. Have already answered your PM.

Member Avatar for crunchie
0
238
Member Avatar for birdman1541

Download LSPfix from [url=http://www.computercops.biz/downloads-file-334.html][u]here[/u][/url] On the opening screen, click the "I know what I'm doing" checkbox. Check all instances of "inetadpt.dll" (and nothing else), and move them to the "Remove" pane. Then click Finish. Close all (browser) windows & rescan with hijackthis. When the scan is finished place a check …

Member Avatar for crunchie
0
435
Member Avatar for Spuffington

Close all (browser) windows & rescan with hijackthis. When the scan is finished place a check in the box to the left of the following entries & click 'fix checked' : R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank R1 …

Member Avatar for crunchie
0
129
Member Avatar for courtney.

This is the only suspect entry in your log: O4 - HKCU\..\Run: [getuname] C:\WINDOWS\System32\getuname.exe If you do not recognise it do the following: Unzip HJT into it's own permanent folder before doing anything in order for it to create backups. [color=red](Not a temporary folder or the desktop & not directly …

Member Avatar for crunchie
0
178
Member Avatar for Specter

Specter, I apologise but I cannot help you in this thread as it would be unfair to prullenbak as his/her problem is not yet solved. It is also against this forums policy. You can start your own thread & post your log there where it will recieve attention there. Doing …

Member Avatar for crunchie
0
136
Member Avatar for denverdave

You still have the coolwebsearch infection. Update the shredder & run it agin. Select *fix* & not scan only. Make sure ALL other windows are closed B4 running it. Am goint to post the rest of the fix next.

Member Avatar for crunchie
0
403
Member Avatar for ouch
Member Avatar for crunchie
0
300
Member Avatar for voluntary

Close all (browser) windows & rescan with hijackthis. When the scan is finished place a check in the box to the left of the following entries & click 'fix checked' : O2 - BHO: (no name) - {000006B1-19B5-414A-849F-2A3C64AE6939} - C:\WINDOWS\bi.dll O2 - BHO: (no name) - {71ED4FBA-4024-4bbe-91DC-9704C93F453E} - c:\progra~1\iesearchbar\iesearchbar.dll O2 …

Member Avatar for voluntary
0
204
Member Avatar for jannes

Delete this one with HJT: O2 - BHO: (no name) - {B9D90B27-AD4A-413a-88CB-3E6DDC10DC2D} - C:\WINDOWS\msopt.dll ICOO is a download manager. Perhaps you can remove it from add/remove programs? Or delete the folder if it exists. Do a search of your computer for it.

Member Avatar for jannes
0
132
Member Avatar for schmoey
Member Avatar for HopelessThought

Unzip HJT into it's own permanent folder before doing anything in order for it to create backups. [color=red](Not a temporary folder or the desktop & not directly on your hard drive).[/color] Close all (browser) windows & rescan with hijackthis. When the scan is finished place a check in the box …

Member Avatar for crunchie
0
101
Member Avatar for cyanide7407

Close all (browser) windows & rescan with hijackthis. When the scan is finished place a check in the box to the left of the following entries & click 'fix checked' : F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\Userinit.exe O2 - BHO: (no name) - {000020DD-C72E-4113-AF77-DD56626C6C42} - C:\WINDOWS\twaintec.dll O2 - BHO: (no name) - …

Member Avatar for crunchie
0
260
Member Avatar for mnrford

Unzip HJT into it's own permanent folder before doing anything in order for it to create backups. [color=red](Not a temporary folder or the desktop & not directly on your hard drive).[/color] Close all (browser) windows & rescan with hijackthis. When the scan is finished place a check in the box …

Member Avatar for crunchie
0
138
Member Avatar for philr54

Yep, you can run it. The sticky is just to ask that users run adaware & spybot B4 posting as it makes it a lot easier to clear out what is left & reduces the amount of posts required, less time etc. Make sure that you install it into it's …

Member Avatar for philr54
0
270
Member Avatar for Saddlefall

Close all (browser) windows & rescan with hijackthis. When the scan is finished place a check in the box to the left of the following entries & click 'fix checked' : R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchURL = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = [url]http://red.clientapps.yahoo.com/cus...://my.yahoo.com[/url] R0 …

Member Avatar for crunchie
0
209
Member Avatar for agal82

Why start a new thread? Nothing has changed in that log from the first one you posted. You need to run CWShredder, Adaware & spybot again. It doesn't look like they have been run at all. You must follow the instructions exactly or the clean up programs (More CWSHredder) will …

Member Avatar for crunchie
0
264
Member Avatar for billy61788

You have a coolwebsearch infection. Download CWShredder from [url=http://www.computercops.biz/downloads-file-349.html][u]here[/u][/url] & run it. Select the fix button & it will get rid of everything related to CoolWebSearch that is stored in it's database. Close ALL windows, including IE, before running CWShredder. Reboot. To help prevent this from happening again, install the …

Member Avatar for crunchie
0
168
Member Avatar for jadenbobaden

Close all (browser) windows & rescan with hijackthis. When the scan is finished place a check in the box to the left of the following entries & click 'fix checked' : R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = [url]http://www.blazefind.com[/url] R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = [url]http://www.blazefind.com[/url] R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = …

Member Avatar for crunchie
0
101
Member Avatar for 0utstrung

That is only a partial log. Plz post the whole log next time you're here. :) 1st of all stop the following process in Task Manager: winproc32.exe you may have to try several times. Unzip HJT into it's own permanent folder before doing anything in order for it to create …

Member Avatar for crunchie
0
157
Member Avatar for crystaldawn777

Close all (browser) windows & rescan with hijackthis. When the scan is finished place a check in the box to the left of the following entries & click 'fix checked'= R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = [url]http://red.clientapps.yahoo.com/cus...://my.yahoo.com[/url] R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = [url]http://red.clientapps.yahoo.com/cus...rch/search.html[/url] R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = …

Member Avatar for crunchie
0
145
Member Avatar for Bob88

Download HijackThis from [url=http://www.computercops.biz/downloads-file-328.html][u]here[/u][/url] & unzip it into it's own, permanent folder, [color=red](Not a temporary folder or the desktop & not directly on your hard drive)[/color]. Start HJT & press the scan button. When the scan is finished the scan button will change to save. Save the log to a …

Member Avatar for crunchie
0
149
Member Avatar for rjeffers

Close all (browser) windows & rescan with hijackthis. When the scan is finished place a check in the box to the left of the following entries & click 'fix checked' : R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost O1 - Hosts: 216.177.73.139 ieautosearch O1 - Hosts: 217.116.231.7 aimtoday.aol.com 4 - HKLM\..\Run: …

Member Avatar for crunchie
0
132
Member Avatar for cparky

Use system restore (if you have it) & go back to B4 the problem happened. Download hijackthis & post a log.

Member Avatar for crunchie
0
205
Member Avatar for Andrew21

[QUOTE=Andrew21]Hi, Could I have some help, My email address is [email]andrew.north6@btinternet.com[/email] Trying to get out something that should not be here, trying to get internet explorer to load.(Its not at the moment)[/QUOTE] You have several issues here so will probably take a couple of posts to get through it. Download …

Member Avatar for crunchie
0
299
Member Avatar for shosein22

Unless absolutely needed, uninstall Wild Tangent from add/remove programs. Download CWShredder from [url=http://www.computercops.biz/downloads-file-349.html][u]here[/u][/url] & run it. Select the fix button & it will get rid of everything related to CoolWebSearch that is stored in it's database. Close ALL windows, including IE, before running CWShredder. REBOOT. To help prevent this from …

Member Avatar for crunchie
0
194
Member Avatar for what

Unzip HJT into it's own permanent folder before doing anything in order for it to create backups. [color=red](Not a temporary folder or the desktop & not directly on your hard drive).[/color] Close all (browser) windows & rescan with hijackthis. When the scan is finished place a check in the box …

Member Avatar for crunchie
0
166

The End.