4,383 Posted Topics

Member Avatar for phatbacky
Member Avatar for phatbacky

Close all (browser) windows & rescan with hijackthis. When the scan is finished place a check in the box to the left of the following entries & click 'fix checked' : R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = [url]http://red.clientapps.yahoo.com/cus...rch/search.html[/url] R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = [url]http://red.clientapps.yahoo.com/cus...//www.yahoo.com[/url] R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page …

Member Avatar for crunchie
0
106
Member Avatar for spike17spiegel

O4 - HKLM\..\Run: [RunDLL] rundll32.exe "C:\WINDOWS\Downloaded Program Files\bridge.dll",Load Rescan with HJT & *fix* the above.

Member Avatar for crunchie
0
126
Member Avatar for landlord

[QUOTE=gatorman725]yes It did work for a little while.[/QUOTE] You have a coolwebsearch infection. Download CWShredder from [url=http://www.computercops.biz/downloads-file-349.html][u]here[/u][/url] & run it. Select the fix button & it will get rid of everything related to CoolWebSearch that is stored in it's database. Close ALL windows, including IE, before running CWShredder. To help …

Member Avatar for crunchie
0
202
Member Avatar for johndavison

Reboot into safe mode following the instructions [url=http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001052409420406][u]here[/u][/url] & Close all (browser) windows & rescan with hijackthis. When the scan is finished place a check in the box to the left of the following entries & click 'fix checked' : R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = [url]http://www.websearch.com/ie.aspx?tb_id=50032[/url] R1 - HKLM\Software\Microsoft\Internet …

Member Avatar for crunchie
-1
348
Member Avatar for hekla_ana

Unzip HJT into it's own permanent folder before doing anything in order for it to create backups. [color=red](Not a temporary folder or the desktop & not directly on your hard drive).[/color] Close all (browser) windows & rescan with hijackthis. When the scan is finished place a check in the box …

Member Avatar for crunchie
0
179
Member Avatar for Magickavulord

Do this FIRST. First of all we have to remove Newdotnet, either from add/remove programs, or by going [url=http://www.newdotnet.com/#remove][u]here.[/u][/url] & scrolling down to the uninstall tool. Download CWShredder from [url=http://www.computercops.biz/downloads-file-349.html][u]here[/u][/url] & run it. Select the fix button & it will get rid of everything related to CoolWebSearch that is stored …

Member Avatar for crunchie
0
111
Member Avatar for double r

Download & instal Adaware from [url=http://www.computercops.biz/downloads-file-292.html][u]here[/u][/url] & update it B4 scanning. In settings under 'scanning,' have it set to 'scan within archives,' 'scan active processes,' 'scan registry,' 'deepscan registry' 'scan my IE Favourites for banned URL's,' 'scan my host's file.' In 'tweaks' under 'scanning engine' set it to 'unload recognised …

Member Avatar for crunchie
0
134
Member Avatar for chacal

I'll give it a go, but it will require some patience & may not be fixable at the end. If you want to give it a go let me know. But for the rest of the crap you have there, do the following: Download & instal Adaware from [url=http://www.computercops.biz/downloads-file-292.html][u]here[/u][/url] & …

Member Avatar for crunchie
0
348
Member Avatar for Miss Hell

Hi. Close all (browser) windows & rescan with hijackthis. When the scan is finished place a check in the box to the left of the following entries & click 'fix checked' : R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = [url]http://red.clientapps.yahoo.com/cus...://my.yahoo.com[/url] R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = [url]http://searchexe.com/searchbar.html[/url] R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search …

Member Avatar for crunchie
0
182
Member Avatar for green_mand

Ok. Please do the following & we will see if we can get it sorted for you. Download CWShredder from [url=http://www.computercops.biz/downloads-file-349.html][u]here[/u][/url] & run it. Select the fix button & it will get rid of everything related to CoolWebSearch in it's database. Close ALL windows, including IE, before running CWShredder. REBOOT. …

Member Avatar for crunchie
0
229
Member Avatar for prullenbak

Close all (browser) windows & rescan with hijackthis. When the scan is finished place a check in the box to the left of the following entries & click 'fix checked' : R3 - Default URLSearchHook is missing O1 - Hosts: 12.129.205.209 search.netscape.com12.129.205.209 sitefinder.verisign.com O1 - Hosts: 12.129.205.209 search.netscape.com12.129.205.209 sitefinder.verisign.com O2 …

Member Avatar for crunchie
0
114
Member Avatar for Saidin

Download & instal Adaware from [url=http://www.computercops.biz/downloads-file-292.html][u]here[/u][/url] & update it B4 scanning. In settings under 'scanning,' have it set to 'scan within archives,' 'scan active processes,' 'scan registry,' 'deepscan registry' 'scan my IE Favourites for banned URL's,' 'scan my host's file.' In 'tweaks' under 'scanning engine' set it to 'unload recognised …

Member Avatar for crunchie
0
174
Member Avatar for stellargirl2012

R3 fix. Launch Notepad, and copy/paste the bold below into a new text file. Save it as URLRepair.reg (Change the 'Save As Type' to 'All Files'). Save it in C:\ REGEDIT4 [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks] [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks] "{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"="" Locate it (in C:\) and double-click on it (launch it). You'll recieve a prompt …

Member Avatar for crunchie
0
117
Member Avatar for rmvalduc

[QUOTE=rmvalduc]In the view drop down menu: Toolbars; I have one that will not go away. the title, in lower case, is "stchchbjxcr". It automatically inserts it self in IE, but has now changed and opens in the Google toolbar instead and Google opens in stchchbjxcr. I have search as far …

Member Avatar for crunchie
0
211
Member Avatar for lctsay

Try the PurityScan [url=http://www.purityscan.com/ps_uninstaller.exe][u]uninstaller[/u][/url] also.

Member Avatar for crunchie
0
604
Member Avatar for Aedin

Unzip HJT into it's own permanent folder before doing anything in order for it to create backups. [color=red](Not a temporary folder or the desktop & not directly on your hard drive).[/color] Close all (browser) windows & rescan with hijackthis. When the scan is finished place a check in the box …

Member Avatar for crunchie
0
138
Member Avatar for civic

Close all (browser) windows & rescan with hijackthis. When the scan is finished place a check in the box to the left of the following entries= R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file) R3 - URLSearchHook: (no name) - _{5D60FF48-95BE-4956-B4C6-6BB168A70310} - (no file) O1 - Hosts: 12.129.205.209 …

Member Avatar for crunchie
0
319
Member Avatar for evelynisnotreal

Sounds like it is trying to install a plug-in that you do not want. If the site works fine without it, keep refusing it.

Member Avatar for crunchie
0
101
Member Avatar for Jonzsie
Member Avatar for bigpopanj

have you tried a repair of IE? If you have an HJT log, I would be happy to look it over to see if there are any problems there.

Member Avatar for bigpopanj
0
182
Member Avatar for civic

I have already answered you in your second thread here [url]http://www.daniweb.com/techtalkforums/thread5876.html[/url]

Member Avatar for DMR
0
132
Member Avatar for agal82

Oh joy!! What a collection. Go [url=http://housecall.trendmicro.com/][u]here[/u][/url] for an on-line scan & set it to autoclean for you. Download & instal Adaware from [url=http://www.computercops.biz/downloads-file-292.html][u]here[/u][/url] & update it B4 scanning. In settings under 'scanning,' have it set to 'scan within archives,' 'scan active processes,' 'scan registry,' 'deepscan registry' 'scan my IE …

Member Avatar for agal82
0
293
Member Avatar for agal82

That problem should be resolved when you have finished carrying out the repairs recommended in your other thread which I have already replied to. Just continue in that thread & I think you will find when done IE will be fine.

Member Avatar for crunchie
0
193
Member Avatar for aras_se

Close all (browser) windows & rescan with hijackthis. When the scan is finished place a check in the box to the left of the following entries= R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = [url]http://red.clientapps.yahoo.com/cus...rch/search.html[/url] R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = [url]http://red.clientapps.yahoo.com/cus...://my.yahoo.com[/url] R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = [url]http://red.clientapps.yahoo.com/cus...rch/search.html[/url] R1 - HKCU\Software\Microsoft\Internet …

Member Avatar for crunchie
0
132
Member Avatar for ep2002

Download HijackThis from [url=http://www.computercops.biz/downloads-file-328.html][u]here[/u][/url] & unzip it into it's own, permanent folder, [color=red](not a temporary folder & not on the desktop)[/color]. Start HJT & press the scan button. When the scan is finished the scan button will change to save. Save the log to a text file, copy the entire …

Member Avatar for crunchie
0
110
Member Avatar for civic

Close all (browser) windows & rescan with hijackthis. When the scan is finished place a check in the box to the left of the following entries= R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = [url]http://81.211.105.43/search.php?v=4[/url] R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = [url]http://81.211.105.43/index.php?v=4[/url] R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = [url]http://81.211.105.43/index.php?v=4[/url] Please go [url=http://www.kaspersky.com/remoteviruschk.html][u]here[/u][/url] …

Member Avatar for crunchie
0
328
Member Avatar for Jonzsie

Unzip HJT into it's own permanent folder before doing anything in order for it to create backups. [color=red](Not a temporary folder or the desktop & not directly on your hard drive).[/color] Close all (browser) windows & rescan with hijackthis. When the scan is finished place a check in the box …

Member Avatar for crunchie
0
102
Member Avatar for EikaF

Close all (browser) windows & rescan with hijackthis. When the scan is finished place a check in the box to the left of the following entries= O4 - HKLM\..\Run: [svchot] C:\WINDOWS\System32\svchot.exe O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - [url]http://software-dl.real.com/233d7cd...RdxIE601_it.cab[/url] Reboot into safe mode following the instructions [url=http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001052409420406][u]here[/u][/url] & navigate to …

Member Avatar for crunchie
0
128
Member Avatar for Killer_Typo

There should be a backup file in the same folder as hijackthis. Just restore that backup & all will be good.

Member Avatar for DMR
0
639
Member Avatar for scyth02

kgerarde. Close all (browser) windows & have HJT fix these entries= R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = file:///C:/Documents%20and%20Settin...misc/index.html R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm R3 - URLSearchHook: (no name) - {0428FFC7-1931-45b7-95CB-3CBB919777E1} - (no file) O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\2.bin\mwsoemon.exe O4 - HKLM\..\Run: [RunDLL] rundll32.exe "C:\WINDOWS\Downloaded Program Files\bridge.dll",Load …

Member Avatar for DMR
0
2K
Member Avatar for Brian

This one can go. O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - [url]http://207.188.7.150/091aa37f4e492a...ip/RdxIE601.cab[/url] Other than that I cannot see anything. Have you deleted anything already? Best to post a log after a reboot so we can see what is actually starting straight up.

Member Avatar for DMR
0
231
Member Avatar for bluedos82
Member Avatar for Vanth
Member Avatar for tread

This one has a few problems. Download LSPfix from [url=http://www.computercops.biz/downloads-file-334.html][u]here[/u][/url] On the opening screen, click the "I know what I'm doing" checkbox. Check all instances of "inetadpt.dll" (and nothing else), and move them to the "Remove" pane. Then click Finish. Close all (browser) windows & rescan with hijackthis. When the …

Member Avatar for tread
0
132
Member Avatar for steosaur(oWn)
Member Avatar for Saidin

Close all (browser) windows & rescan with hijackthis. When the scan is finished place a check in the box to the left of the following entries= R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = res://C:\PROGRA~1\Toolbar\toolbar.dll/sa R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = res://C:\PROGRA~1\Toolbar\toolbar.dll/sa R3 - Default URLSearchHook is missing O1 - Hosts: 207.36.196.189 auto.search.msn.com O1 …

Member Avatar for crunchie
0
153
Member Avatar for ThePoison1

Unzip HJT into it's own permanent folder before doing anything in order for it to create backups. [color=red](Not a temporary folder or the desktop & not directly on your hard drive).[/color] Close all (browser) windows & rescan with hijackthis. When the scan is finished place a check in the box …

Member Avatar for caperjack
0
169
Member Avatar for crazy_girl292

First off I am not sure if the following will solve your problem, but they need doing non-the-less. Close all (browser) windows & have HJT fix these entries= R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = O2 - BHO: (no name) - {029CA12C-89C1-46a7-A3C7-82F2F98635CB} - C:\PROGRAM FILES\KONTIKI\BIN\BH304181.DLL (file missing) …

Member Avatar for crunchie
0
459
Member Avatar for BATMAN

Go [url=http://housecall.trendmicro.com/][u]here[/u][/url] for an on-line scan & set it to autoclean for you.

Member Avatar for crunchie
0
104
Member Avatar for thumper714

Unzip HJT into it's own permanent folder before doing anything in order for it to create backups. [color=red](Not a temporary folder or the desktop & not directly on your hard drive).[/color] Close all (browser) windows & rescan with hijackthis. When the scan is finished place a check in the box …

Member Avatar for crunchie
0
199
Member Avatar for desertbabe

Unzip HJT into it's own permanent folder before doing anything in order for it to create backups. [color=red](Not a temporary folder or the desktop & not directly on your hard drive).[/color] Close all (browser) windows & rescan with hijackthis. When the scan is finished place a check in the box …

Member Avatar for desertbabe
0
239
Member Avatar for Zilla Barbarian

Ok. Please do the following & we will see if we can get it sorted for you. Download CWShredder from [url=http://www.computercops.biz/downloads-file-349.html]here[/url] & run it. Select the fix button & it will get rid of everything related to CoolWebSearch. Close ALL windows, including IE, before running CWShredder. REBOOT. You must follow …

Member Avatar for crunchie
0
450
Member Avatar for HeidiGiller

Close all (browser) windows & rescan with hijackthis. When the scan is finished place a check in the box to the left of the following entries= R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = res://C:\PROGRA~1\Toolbar\toolbar.dll/sa R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = R1 - HKCU\Software\Microsoft\Internet Connection Wizard,Shellnext = wmplayer.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = [url]http://www.websearch.com/ie.aspx?tb_id=50032[/url] …

Member Avatar for crunchie
0
285
Member Avatar for wimsical

Hi :) . You have the peper trojan. Download the removal tool from [url=http://www.computercops.biz/downloads-file-330.html][u]here[/u][/url] & allow it to proceed with it's fix. There will be no dialogue. Note that you must be online when you run the tool for it to be effective. You must then reboot your computer. Then …

Member Avatar for crunchie
0
163
Member Avatar for TrueChaos

Close all (browser) windows & rescan with hijackthis. When the scan is finished place a check in the box to the left of the following entries= R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = [url]http://red.clientapps.yahoo.com/cus...rch/search.html[/url] R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = [url]http://red.clientapps.yahoo.com/cus...//www.yahoo.com[/url] R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = [url]http://red.clientapps.yahoo.com/cus...://my.yahoo.com[/url] R1 - HKLM\Software\Microsoft\Internet …

Member Avatar for crunchie
0
193
Member Avatar for hippiemama

Download HijackThis from [url=http://www.computercops.biz/downloads-file-328.html][u]here[/u][/url] & unzip it into it's own, permanent folder, [color=red](not a temporary folder & not on the desktop)[/color]. Start HJT & press the scan button. When the scan is finished the scan button will change to save. Save the log to a text file, copy the entire …

Member Avatar for crunchie
0
102
Member Avatar for Anita1965

Is it scvhost.dll or svchost.dll ? if the former there is a nasty inhabiting your computer. My advice would be firstly to download a couple of spyware removal programs & then also run an online virus scan. Please do the following. Download & instal Adaware from [url=http://www.computercops.biz/downloads-file-292.html][u]here[/u][/url] & update it …

Member Avatar for crunchie
0
126
Member Avatar for Majestic

Close all (browser) windows & rescan with hijackthis. When the scan is finished place a check in the box to the left of the following entries= R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = [url]http://red.clientapps.yahoo.com/cus...://my.yahoo.com[/url] R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = [url]http://red.clientapps.yahoo.com/cus...://my.yahoo.com[/url] R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = [url]http://red.clientapps.yahoo.com/cus...//www.yahoo.com[/url] R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = …

Member Avatar for crunchie
0
174
Member Avatar for evelynisnotreal

Close all (browser) windows & rescan with hijackthis. When the scan is finished place a check in the box to the left of the following entries= R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = about:blank R3 - Default URLSearchHook is missing O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file) O4 - …

Member Avatar for Jonzsie
0
263

The End.