4,383 Posted Topics
Re: [QUOTE=natewax]Ok, I got rid of everything that you listed and rebooted. Let me knew how this looks and if there is anything else I should do. Thanks a ton.[/QUOTE] R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file) With the above R3, you won't be able to delete it … | |
Re: Close all (browser) windows & rescan with hijackthis. When the scan is finished place a check in the box to the left of the following entries & click 'fix checked' : R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = [url]http://prosearching.com/passthrough...p://about:blank[/url] O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file) O2 - … | |
Re: Close all (browser) windows & rescan with hijackthis. When the scan is finished place a check in the box to the left of the following entries & click 'fix checked' : R3 - Default URLSearchHook is missing O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL O2 … | |
| |
Re: Unzip HJT into it's own permanent folder before doing anything in order for it to create backups. [color=red](Not a temporary folder or the desktop & not directly on your hard drive).[/color] Close all (browser) windows & rescan with hijackthis. When the scan is finished place a check in the box … | |
Re: Ok. Please do the following & we will see if we can get it sorted for you. Download CWShredder from [url=http://www.computercops.biz/zx/phoenix22/cws.zip][u]here[/u][/url] & run it. Select the fix button & it will get rid of everything related to CoolWebSearch that is stored in it's database. Close ALL windows, including IE, before … | |
Re: I will just concentrate on the first one for now. They both need work, but the first has THE hardest to remove hijacker yet. We'll get rid of some of the easy trash first, then go on to the main prize. You have to do all the work so I … | |
Re: Get rid of all these too. red.clientapps.yahoo.com/cus...://my.yahoo.com | |
Re: Download dllfix.exe from [url]http://downloads.subratam.org/dllfix.exe[/url] . Create a folder on your desktop & click on the exe you downloaded. Direct the install into the new folder. You will see there are two more folders inside and two BAT files. Run start.bat & select option 1 for the report. Once the search … | |
Re: No promises here cos you may end up having to reformat. Download this zip. [url]http://tools.zerosrealm.com/pv.zip[/url] Please unzip it to the desktop. It will not work if you run it from inside the zip. After unzipped go to the desktop. Open the pv folder. Double click on the runme.bat A dos … | |
Re: Unzip HJT into it's own permanent folder before doing anything in order for it to create backups. [color=red](Not a temporary folder or the desktop & not directly on your hard drive).[/color] Close all (browser) windows & rescan with hijackthis. When the scan is finished place a check in the box … | |
Re: Close all (browser) windows & rescan with hijackthis. When the scan is finished place a check in the box to the left of the following entries & click 'fix checked' : R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = [url]http://www.hotbar.com/dyn/hotbar/3....rchPageHome.htm[/url] R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Vênculos F0 - system.ini: Shell= F2 - REG:system.ini: … | |
Re: Unzip HJT into it's own permanent folder before doing anything in order for it to create backups. [color=red](Not a temporary folder or the desktop & not directly on your hard drive).[/color] Close all (browser) windows & rescan with hijackthis. When the scan is finished place a check in the box … | |
Re: Ok. Please do the following & we will see if we can get it sorted for you. Download CWShredder from [url=http://www.computercops.biz/downloads-file-349.html]here[/url] & run it. Select the fix button & it will get rid of everything related to CoolWebSearch. Close ALL other programs & windows, including IE, before running CWShredder. Download … | |
Re: Ok. Please do the following & we will see if we can get it sorted for you. Download CWShredder from [url=http://www.computercops.biz/zx/phoenix22/cws.zip][u]here[/u][/url] & run it. Select the fix button & it will get rid of everything related to CoolWebSearch that is stored in it's database. Close ALL windows, including IE, before … | |
| |
Re: Go [url=http://housecall.trendmicro.com/][u]here[/u][/url] for an on-line scan & set it to autoclean for you. Make SURE that you set it to clean. Download HijackThis from [url=http://www.computercops.biz/downloads-file-328.html][u]here[/u][/url] & unzip it into it's own, permanent folder, [color=red](not a temporary folder & not on the desktop)[/color]. Start HJT & press the scan button. When … | |
Re: A good way of telling is if it's freeware. If free it is suspect. Do a google search on the product name & check the results. | |
Re: All you need do with spywareblaster is keep it updated, say once a week & thats it. Once updated just close out of the program. It prevents the installation of bad activex controls that it has in it's database. | |
Re: Close all (browser) windows & rescan with hijackthis. When the scan is finished place a check in the box to the left of the following entries & click 'fix checked' : O2 - BHO: (no name) - {10C68D31-7094-4278-B41A-874AEF928A2C} - C:\WINNT\pxRI1.dll O2 - BHO: (no name) - {CE1C8CDD-B3C1-4D39-87B2-55240FB75D67} - C:\WINNT\aloxvs.dll O4 … | |
Re: Download HijackThis from [url=http://www.computercops.biz/downloads-file-328.html][u]here[/u][/url] & unzip it into it's own, permanent folder, [color=red](not a temporary folder & not on the desktop)[/color]. Start HJT & press the scan button. When the scan is finished the scan button will change to save. Save the log to a text file, copy the entire … | |
Re: Go [url=http://housecall.trendmicro.com/][u]here[/u][/url] for an on-line scan & set it to autoclean for you. Download & instal Adaware from [url=http://www.computercops.biz/downloads-file-292.html][u]here[/u][/url] & update it B4 scanning. In settings under 'scanning,' have it set to 'scan within archives,' 'scan active processes,' 'scan registry,' 'deepscan registry' 'scan my IE Favourites for banned URL's,' 'scan … | |
Re: Perhaps there should be a sticky asking ppl to search the forum for their particular problem, then go through the same process of removal? There are a lot of ppl though who have little or no knowledge of delving into these thingz, ot the confidence that they will not remove … | |
Re: I don't see anything bad there but try uninstalling this O3 - Toolbar: Vivisimo - {5538fb62-f725-4433-a965-91314e8d8e4d} - C:\Program Files\Vivisimo\Toolbar\tbu14\toolbar.dll & see if it works correctly. You may also have to do a repair of IE. | |
Re: Rimmetje. 1. Please read the post above yours by myself. 2. Have already answered your PM. | |
Re: Download LSPfix from [url=http://www.computercops.biz/downloads-file-334.html][u]here[/u][/url] On the opening screen, click the "I know what I'm doing" checkbox. Check all instances of "inetadpt.dll" (and nothing else), and move them to the "Remove" pane. Then click Finish. Close all (browser) windows & rescan with hijackthis. When the scan is finished place a check … | |
Re: Close all (browser) windows & rescan with hijackthis. When the scan is finished place a check in the box to the left of the following entries & click 'fix checked' : R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank R1 … | |
Re: This is the only suspect entry in your log: O4 - HKCU\..\Run: [getuname] C:\WINDOWS\System32\getuname.exe If you do not recognise it do the following: Unzip HJT into it's own permanent folder before doing anything in order for it to create backups. [color=red](Not a temporary folder or the desktop & not directly … | |
Re: Specter, I apologise but I cannot help you in this thread as it would be unfair to prullenbak as his/her problem is not yet solved. It is also against this forums policy. You can start your own thread & post your log there where it will recieve attention there. Doing … | |
Re: You still have the coolwebsearch infection. Update the shredder & run it agin. Select *fix* & not scan only. Make sure ALL other windows are closed B4 running it. Am goint to post the rest of the fix next. | |
Re: Give me a couple of minutes to have a look & we'll have it fixed in no time. | |
Re: Close all (browser) windows & rescan with hijackthis. When the scan is finished place a check in the box to the left of the following entries & click 'fix checked' : O2 - BHO: (no name) - {000006B1-19B5-414A-849F-2A3C64AE6939} - C:\WINDOWS\bi.dll O2 - BHO: (no name) - {71ED4FBA-4024-4bbe-91DC-9704C93F453E} - c:\progra~1\iesearchbar\iesearchbar.dll O2 … | |
Re: Delete this one with HJT: O2 - BHO: (no name) - {B9D90B27-AD4A-413a-88CB-3E6DDC10DC2D} - C:\WINDOWS\msopt.dll ICOO is a download manager. Perhaps you can remove it from add/remove programs? Or delete the folder if it exists. Do a search of your computer for it. | |
Re: Unzip HJT into it's own permanent folder before doing anything in order for it to create backups. [color=red](Not a temporary folder or the desktop & not directly on your hard drive).[/color] Close all (browser) windows & rescan with hijackthis. When the scan is finished place a check in the box … | |
Re: Close all (browser) windows & rescan with hijackthis. When the scan is finished place a check in the box to the left of the following entries & click 'fix checked' : F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\Userinit.exe O2 - BHO: (no name) - {000020DD-C72E-4113-AF77-DD56626C6C42} - C:\WINDOWS\twaintec.dll O2 - BHO: (no name) - … | |
Re: Unzip HJT into it's own permanent folder before doing anything in order for it to create backups. [color=red](Not a temporary folder or the desktop & not directly on your hard drive).[/color] Close all (browser) windows & rescan with hijackthis. When the scan is finished place a check in the box … | |
Re: Yep, you can run it. The sticky is just to ask that users run adaware & spybot B4 posting as it makes it a lot easier to clear out what is left & reduces the amount of posts required, less time etc. Make sure that you install it into it's … | |
Re: Close all (browser) windows & rescan with hijackthis. When the scan is finished place a check in the box to the left of the following entries & click 'fix checked' : R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchURL = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = [url]http://red.clientapps.yahoo.com/cus...://my.yahoo.com[/url] R0 … | |
Re: Why start a new thread? Nothing has changed in that log from the first one you posted. You need to run CWShredder, Adaware & spybot again. It doesn't look like they have been run at all. You must follow the instructions exactly or the clean up programs (More CWSHredder) will … | |
Re: You have a coolwebsearch infection. Download CWShredder from [url=http://www.computercops.biz/downloads-file-349.html][u]here[/u][/url] & run it. Select the fix button & it will get rid of everything related to CoolWebSearch that is stored in it's database. Close ALL windows, including IE, before running CWShredder. Reboot. To help prevent this from happening again, install the … | |
Re: Close all (browser) windows & rescan with hijackthis. When the scan is finished place a check in the box to the left of the following entries & click 'fix checked' : R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = [url]http://www.blazefind.com[/url] R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = [url]http://www.blazefind.com[/url] R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = … | |
Re: That is only a partial log. Plz post the whole log next time you're here. :) 1st of all stop the following process in Task Manager: winproc32.exe you may have to try several times. Unzip HJT into it's own permanent folder before doing anything in order for it to create … | |
Re: Close all (browser) windows & rescan with hijackthis. When the scan is finished place a check in the box to the left of the following entries & click 'fix checked'= R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = [url]http://red.clientapps.yahoo.com/cus...://my.yahoo.com[/url] R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = [url]http://red.clientapps.yahoo.com/cus...rch/search.html[/url] R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = … | |
Re: Download HijackThis from [url=http://www.computercops.biz/downloads-file-328.html][u]here[/u][/url] & unzip it into it's own, permanent folder, [color=red](Not a temporary folder or the desktop & not directly on your hard drive)[/color]. Start HJT & press the scan button. When the scan is finished the scan button will change to save. Save the log to a … | |
Re: Close all (browser) windows & rescan with hijackthis. When the scan is finished place a check in the box to the left of the following entries & click 'fix checked' : R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost O1 - Hosts: 216.177.73.139 ieautosearch O1 - Hosts: 217.116.231.7 aimtoday.aol.com 4 - HKLM\..\Run: … | |
Re: Use system restore (if you have it) & go back to B4 the problem happened. Download hijackthis & post a log. | |
Re: [QUOTE=Andrew21]Hi, Could I have some help, My email address is [email]andrew.north6@btinternet.com[/email] Trying to get out something that should not be here, trying to get internet explorer to load.(Its not at the moment)[/QUOTE] You have several issues here so will probably take a couple of posts to get through it. Download … | |
Re: Unless absolutely needed, uninstall Wild Tangent from add/remove programs. Download CWShredder from [url=http://www.computercops.biz/downloads-file-349.html][u]here[/u][/url] & run it. Select the fix button & it will get rid of everything related to CoolWebSearch that is stored in it's database. Close ALL windows, including IE, before running CWShredder. REBOOT. To help prevent this from … | |
Re: Unzip HJT into it's own permanent folder before doing anything in order for it to create backups. [color=red](Not a temporary folder or the desktop & not directly on your hard drive).[/color] Close all (browser) windows & rescan with hijackthis. When the scan is finished place a check in the box … |
The End.