4,383 Posted Topics

Member Avatar for Hopeless
Member Avatar for Marsik

DO NOT REMOVE THE INTERNAT.EXE as advised, it is a genuine file. There is one similar that is a baddie, but runs from different directory. Check it here [url]http://www.sysinfo.org/startuplist.php?filter=INTERNAT.EXE&count=&type=[/url] The other two mentioned are also good. Have only HJT running & fix these entries= R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = …

Member Avatar for crunchie
0
171
Member Avatar for indy irish

Download HijackThis from [url]http://209.133.47.200/~merijn/files/HijackThis.exe[/url] & unzip it into it's own, permanent folder, not a temporary one. Start HJT & press the scan button. When the scan is finished the scan button will change to save. Save the log to a text file & paste it into the body of your …

Member Avatar for crunchie
0
132
Member Avatar for nez

You have a CWS infection. Download CWShredder from [url]http://209.133.47.200/~merijn/files/CWShredder.exe[/url] & run it. Select the fix button & it will get rid of everything related to CoolWebSearch. Close ALL other programs including IE before running CWShredder. Download & instal Adaware from [url]http://majorgeeks.com/download.php?det=506[/url] & update it B4 scanning. In settings under 'scanning,' …

Member Avatar for nez
0
165
Member Avatar for yantitan

Messenger Plus should be removed from Add/Remove programs. You can reinstall later (if needed) without the sponsor (Lop). Kazaabegone [url]http://www.spychecker.com/program/kazaagone.html[/url] O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - [url]http://software-dl.real.com/233d7cd...RdxIE601_fr.cab[/url]

Member Avatar for DMR
0
189
Member Avatar for bentkey

[QUOTE=bentkey]I have exactly the same problem as drunknmonkey with perhaps a few extras.[/QUOTE] Have only HJT running & fix these entries= R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Search,(Default) = about:blank O2 - BHO: (no name) - {000020DD-C72E-4113-AF77-DD56626C6C42} - (no file) …

Member Avatar for bentkey
0
411
Member Avatar for Ohhhhhhhhhh

Did you have the browser closed when you fixed them???? Must be closed. If you did Try running CWShredder. Download CWShredder from [url]http://209.133.47.200/~merijn/files/CWShredder.exe[/url] & run it. Select the fix button & it will get rid of everything related to CoolWebSearch. Close ALL other programs including IE before running CWShredder. Reboot …

Member Avatar for crunchie
0
225
Member Avatar for crazy_beauty

Looks like you have/had a virus. Might be an idea to have an online scan, so go to [url]http://housecall.trendmicro.com/[/url] for an on-line scan & set it to autoclean for you. I know you have Adaware, but I have a 'canned' message that includes it that i will paste here with …

Member Avatar for crunchie
0
216
Member Avatar for alan

Have only HJT running & fix these entries= R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = [url]http://vpuzee.t.muxa.cc/s.php?aid=35[/url] (obfuscated) R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = [url]http://vpuzee.t.muxa.cc/s.php?aid=35[/url] (obfuscated) R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = [url]http://vpuzee.t.muxa.cc/s.php?aid=35[/url] (obfuscated) R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = [url]http://vpuzee.t.muxa.cc/h.php?aid=35[/url] (obfuscated) R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = [url]http://vpuzee.t.muxa.cc/s.php?aid=35[/url] (obfuscated) R1 - HKLM\Software\Microsoft\Internet …

Member Avatar for eww
0
322
Member Avatar for sproston

You have a CoolWebSearch infection. Download CWShredder from [url]http://209.133.47.200/~merijn/files/CWShredder.exe[/url] & run it. Select the fix button & it will get rid of everything related to CoolWebSearch. Close ALL other programs including IE before running CWShredder. Reboot after doing this & post another log please.

Member Avatar for sproston
0
222
Member Avatar for Hippie459MN

Refer to [URL=http://www.daniweb.com/techtalkforums/thread2768.html]this[/URL] thread. EDIT. Also, if you have spybot, go to immunise & do that, then in the same place there is a link to spywareblaster. Download that & keep it updated, it keeps most of the bugs out. Keep spybot & adaware updated too.

Member Avatar for icon0clast
0
295
Member Avatar for gord_c

Fix this one with HJT. R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = ftp=http:0;gopher=http:0;https=http:0 Have you deleted anything from the log B4 posting? If so, reboot & post a fresh log plz.

Member Avatar for gord_c
0
141
Member Avatar for Catweazle
Member Avatar for Patrik1st

Have only HJT running & fix these entries= O2 - BHO: (no name) - {369964E3-F9DB-43B9-A430-91BBA662E7EF} - C:\WINDOWS\j510y27.dll O2 - BHO: (no name) - {9C691A33-7DDA-4C2F-BE4C-C176083F35CF} - C:\WINDOWS\System32\bridge.dll O4 - HKLM\..\Run: [WebInstall2] C:\WINDOWS\Temp\Adware\WebInstall.exe /R O4 - HKLM\..\Run: [n8uIM7wSn] C:\WINDOWS\bTgX5m8a.exe O4 - HKLM\..\Run: [AutoUpdater] "C:\Program Files\AutoUpdate\AutoUpdate.exe" O4 - HKLM\..\Run: [systray] C:\WINDOWS\System32\a.exe O4 - …

Member Avatar for Patrik1st
0
180
Member Avatar for jerm407

Will ask you to do the following first & then move HijackThis into it's own, permanent folder. Download & instal Adaware from [url]http://majorgeeks.com/download.php?det=506[/url] & update it B4 scanning. In settings under 'scanning,' have it set to 'scan within archives,' 'scan active processes,' 'scan registry,' 'deepscan registry' 'scan my IE Favourites …

Member Avatar for crunchie
0
330
Member Avatar for logan

there is also a removal tool for it here; Newdotnet removal instructions here [url]http://www.newdotnet.com/#remove[/url] Messenger Plus should be uninstalled as it comes bundled with Lop.com. Is this scan B4 or after you ran CWShredder? image.dll install is a CoolWebSearch variant. Make sure you have the latest version of CWShredder & …

Member Avatar for TallCool1
0
283
Member Avatar for gord_c

Try this. Please follow instructions found here & run the Msg121 fix. [url]http://www10.brinkster.com/expl0iter/freeatlast/L2M/Msg121.htm[/url] And that R3 entry can go as a bit of housekeeping.

Member Avatar for crunchie
0
158
Member Avatar for unb0und
Member Avatar for sgtrock40

Have only HJT running & fix these entries= O1 - Hosts: 12.129.205.209 search.netscape.com12.129.205.209 sitefinder.verisign.com O2 - BHO: NavErrRedir Class - {5D60FF48-95BE-4956-B4C6-6BB168A70310} - C:\PROGRA~1\INCRED~1\BHO\INCFIN~1.DLL O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)

Member Avatar for sgtrock40
0
160
Member Avatar for Sphynx

It could be a firewall problem? Did the spyware program have a backup facility where you can restore what you deleted? Is IE6 set to offline mode?

Member Avatar for Uncle Gizmo
0
256
Member Avatar for bbb2k4life
Member Avatar for bbb2k4life
0
133
Member Avatar for adamw1

Get rid of these C:\PROGRAM FILES\180SOLUTIONS\MSBB.EXE C:\PROGRAM FILES\BARGAIN BUDDY\BIN\BARGAINS.EXE You may have to do it from add/remove programs. This one O4 - HKLM\..\Run: [RDLL] RunDll16.exe according to this page [url]http://www.sysinfo.org/startuplist.php?filter=RunDll16.exe&count=&type=[/url] was added as a virus. O4 - HKLM\..\Run: [EOIVZCFJM] C:\WINDOWS\EOIVZCFJM.exe< this one needs to be removed in safe mode. Do …

Member Avatar for adamw1
0
430
Member Avatar for sl869d

Might be an idea to have an online scan, so go to [url]http://housecall.trendmicro.com/[/url] for an on-line scan & set it to autoclean for you. Download & instal Adaware from [url]http://majorgeeks.com/download.php?det=506[/url] & update it B4 scanning. In settings under 'scanning,' have it set to 'scan within archives,' 'scan active processes,' 'scan …

Member Avatar for sl869d
0
221
Member Avatar for jems

Download & instal Adaware from [url]http://majorgeeks.com/download.php?det=506[/url] & update it B4 scanning. In settings under 'scanning,' have it set to 'scan within archives,' 'scan active processes,' 'scan registry,' 'deepscan registry' 'scan my IE Favourites for banned URL's,' 'scan my host's file.' Also in tweaks under 'cleaning engine' set it to 'Automatically …

Member Avatar for crunchie
0
219
Member Avatar for debster

There are several files with the same name that belong to 3rd party software. Without knowing which it is, it is hard to advise. For example; Update Service 'Update.exe' Loaded by Handybits programs such as EasyCrypto. Re-instates itself every time the program is run so best to leave it enabled. …

Member Avatar for debster
0
115
Member Avatar for moxin

Maybe if you were that smart you would have set the protected files size when you installed Norton!!

Member Avatar for VDPD2005
0
180
Member Avatar for saintalfonzo

You may still have some remnants of the worms left behind. Download & instal Adaware from [url]http://majorgeeks.com/download.php?det=506[/url] & update it B4 scanning. In settings under 'scanning,' have it set to 'scan within archives,' 'scan active processes,' 'scan registry,' 'deepscan registry' 'scan my IE Favourites for banned URL's,' 'scan my host's …

Member Avatar for saintalfonzo
0
363
Member Avatar for oalee
Member Avatar for fullbug

Download & instal Adaware from [url]http://majorgeeks.com/download.php?det=506[/url] & update it B4 scanning. In settings under 'scanning,' have it set to 'scan within archives,' 'scan active processes,' 'scan registry,' 'deepscan registry' 'scan my IE Favourites for banned URL's,' 'scan my host's file.' Also in tweaks under 'cleaning engine' set it to 'Automatically …

Member Avatar for fullbug
0
231
Member Avatar for jonny

Hi. Noticed you need more removal, hope you don't mind caperjack? Run HJT again & get it to fix: This is perfect NAV spyware O2 - BHO: NavErrRedir Class - {0428FFC7-1931-45b7-95CB-3CBB919777E1} - (no file) You can fix these too if you want to stop them running in the background & …

Member Avatar for jonny
0
308
Member Avatar for Ronnieam

What was your previous video card? I am not certain, but in the BIOS you may have to alter settings to AGP if the previous card was a PCI. I'm not too techie as you can probably tell, but perhaps someone else can explain this better?

Member Avatar for crunchie
0
112
Member Avatar for roy66

Looks to me like you've been hijacked by coolwebsearch. Download CWShredder from [url]http://209.133.47.200/~merijn/files/CWShredder.exe[/url] unzip & run it getting it to fix all it finds. Make sure that all your microsoft updates are current & then post another log plz. What do you think caperjack?

Member Avatar for roy66
0
295
Member Avatar for DGULLIVER

At the moment I would try another browser to see if you are able to surf using that. (Mozilla, Opera, any of the ones that do not use the IE engine). If you can I would try a repair of IE or go to M$ & get the latest updates. …

Member Avatar for orion
0
461
Member Avatar for daymonkey

Hi there. First up I would go & have an on-line scan from here [url]http://housecall.antivirus.com/[/url] . Then download a program called 'HijackThis' & unzip it into it's own folder in My Documents, or somewhere. Not a temporary one or it cannot create backups. Start HJT & scan your computer. DO …

Member Avatar for daymonkey
0
163
Member Avatar for J&#9788;E

[QUOTE=J?E]ok i got a registry cleaner and i need to know what to do. i have 242 "problems" detected of reg keys leading nowhere and i dont know if i want to delte them or what... also how do i make a backup of the registry? and can anyone give …

Member Avatar for rasputinj
0
334
Member Avatar for dvr

Put your log up at the cexx forums. All they seem to do is fix up HJT logs. [url]http://boards.cexx.org/index.php?sid=339414b8660407d787b52a216c1cabcc[/url]

Member Avatar for crunchie
0
386
Member Avatar for Griffarien

Hi. First you need to get HijackThis into it's own folder or it will not create back-ups. Rescan & get HJT to fix these entries: O4 - HKLM\..\Run: [wcmdmgr] C:\WINDOWS\wt\updater\wcmdmgrl.exe -launch This is related to wild Tangent. Apart from that I can't see anything. If you want to stay as …

Member Avatar for crunchie
0
318
Member Avatar for tee2966

Can you not change it in the BIOS?? I noticed that there is an option to change the password there, but I don't know if you need the old password to make it work.

Member Avatar for tee2966
0
106
Member Avatar for tez

Download & install Adaware, update it & in settings make sure to tick; scan within archives, deep scan registry & then in 'Tweak' tick automatically try to unregister objects prior to deletion. Run the scan & place a check next to everything it finds & remove them. Download Spybot S …

Member Avatar for Yzk
0
272
Member Avatar for CLEARICE01

hey clearice. The best thing to do is run highjackthis & see whats in it. Myway will not affect your opera browser, only IE.

Member Avatar for crunchie
0
166
Member Avatar for rstynls

See if you can start it in safe mode & try to do a virus scan. Don't know what else to suggest.

Member Avatar for rstynls
0
132
Member Avatar for edgee

Hi. Run HJT again & get it to fix these entries; R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://mshp.dll/sp.html#37049 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = [url]http://www.searchdot.net[/url] R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://mshp.dll/sp.html#37049 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://mshp.dll/index.html#37049 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://mshp.dll/sp.html#37049 O2 - BHO: . - {587DBF2D-9145-4c9e-92C2-1F953DA73773} …

Member Avatar for crunchie
0
244
Member Avatar for dvr

Run HJT again & get it to fix these entries; R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm O2 - BHO: (no name) - {FA0286CF-E520-49BE-B9C4-5C985CC501B6} - C:\WINDOWS\x8rod.dll O4 - HKLM\..\Run: [AutoUpdater] "C:\Program Files\AutoUpdate\AutoUpdate.exe" O16 - DPF: {4FDF3696-5078-4952-868C-CEEB9683B8C4} (DownloadFile Control) - [url]http://webcam.geovision.com.tw/cab/DownloadFile.cab[/url] O16 - DPF: {5508547B-4F40-4005-AE0C-343C985DACE1} (WebCamX Control) - [url]http://68.11.177.144:79/cab/install.cab[/url] O16 - …

Member Avatar for crunchie
0
263
Member Avatar for acehi436

First up place HJT in a permanent folder of it's own then rescan & fix the following entries; R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about_:blank R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about_:blank O2 - BHO: (no name) - {4E7BD74F-2B8D-469E-C0FF-FD60B590A87D} - C:\PROGRA~1\COMMON~1\Real\Toolbar\realbar.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll (file …

Member Avatar for crunchie
0
144
Member Avatar for peterska2
Member Avatar for dvr
Member Avatar for crunchie
Member Avatar for oalee
0
254
Member Avatar for spaceyraygun

The other thing to do would be to get a Win98 boot disk floppy. This will format the HD for you, then put the W2K disk in & install.

Member Avatar for TallCool1
0
168
Member Avatar for J&#9788;E

Drag the exe that you want to start to the 'start' button at the left bottom of screen. Keep the mouse button down, the menu will then open. Go up to 'programs' & find the startup folder. Drop it there.

Member Avatar for caperjack
0
3K
Member Avatar for SRW2
Re: java

If you have java installed, remove it first, then try downloading & installing.

Member Avatar for TallCool1
0
167

The End.