4,383 Posted Topics
Re: Looks good. You can fix that RO entry if you want. It's a search page. | |
Re: DO NOT REMOVE THE INTERNAT.EXE as advised, it is a genuine file. There is one similar that is a baddie, but runs from different directory. Check it here [url]http://www.sysinfo.org/startuplist.php?filter=INTERNAT.EXE&count=&type=[/url] The other two mentioned are also good. Have only HJT running & fix these entries= R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = … | |
Re: Download HijackThis from [url]http://209.133.47.200/~merijn/files/HijackThis.exe[/url] & unzip it into it's own, permanent folder, not a temporary one. Start HJT & press the scan button. When the scan is finished the scan button will change to save. Save the log to a text file & paste it into the body of your … | |
Re: You have a CWS infection. Download CWShredder from [url]http://209.133.47.200/~merijn/files/CWShredder.exe[/url] & run it. Select the fix button & it will get rid of everything related to CoolWebSearch. Close ALL other programs including IE before running CWShredder. Download & instal Adaware from [url]http://majorgeeks.com/download.php?det=506[/url] & update it B4 scanning. In settings under 'scanning,' … | |
Re: Messenger Plus should be removed from Add/Remove programs. You can reinstall later (if needed) without the sponsor (Lop). Kazaabegone [url]http://www.spychecker.com/program/kazaagone.html[/url] O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - [url]http://software-dl.real.com/233d7cd...RdxIE601_fr.cab[/url] | |
Re: [QUOTE=bentkey]I have exactly the same problem as drunknmonkey with perhaps a few extras.[/QUOTE] Have only HJT running & fix these entries= R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Search,(Default) = about:blank O2 - BHO: (no name) - {000020DD-C72E-4113-AF77-DD56626C6C42} - (no file) … | |
Re: Did you have the browser closed when you fixed them???? Must be closed. If you did Try running CWShredder. Download CWShredder from [url]http://209.133.47.200/~merijn/files/CWShredder.exe[/url] & run it. Select the fix button & it will get rid of everything related to CoolWebSearch. Close ALL other programs including IE before running CWShredder. Reboot … | |
Re: Looks like you have/had a virus. Might be an idea to have an online scan, so go to [url]http://housecall.trendmicro.com/[/url] for an on-line scan & set it to autoclean for you. I know you have Adaware, but I have a 'canned' message that includes it that i will paste here with … | |
Re: Have only HJT running & fix these entries= R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = [url]http://vpuzee.t.muxa.cc/s.php?aid=35[/url] (obfuscated) R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = [url]http://vpuzee.t.muxa.cc/s.php?aid=35[/url] (obfuscated) R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = [url]http://vpuzee.t.muxa.cc/s.php?aid=35[/url] (obfuscated) R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = [url]http://vpuzee.t.muxa.cc/h.php?aid=35[/url] (obfuscated) R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = [url]http://vpuzee.t.muxa.cc/s.php?aid=35[/url] (obfuscated) R1 - HKLM\Software\Microsoft\Internet … | |
Re: You have a CoolWebSearch infection. Download CWShredder from [url]http://209.133.47.200/~merijn/files/CWShredder.exe[/url] & run it. Select the fix button & it will get rid of everything related to CoolWebSearch. Close ALL other programs including IE before running CWShredder. Reboot after doing this & post another log please. | |
Re: Refer to [URL=http://www.daniweb.com/techtalkforums/thread2768.html]this[/URL] thread. EDIT. Also, if you have spybot, go to immunise & do that, then in the same place there is a link to spywareblaster. Download that & keep it updated, it keeps most of the bugs out. Keep spybot & adaware updated too. | |
Re: Fix this one with HJT. R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = ftp=http:0;gopher=http:0;https=http:0 Have you deleted anything from the log B4 posting? If so, reboot & post a fresh log plz. | |
Re: I don't get hijacked either, but I don't use IE either. | |
Re: Have only HJT running & fix these entries= O2 - BHO: (no name) - {369964E3-F9DB-43B9-A430-91BBA662E7EF} - C:\WINDOWS\j510y27.dll O2 - BHO: (no name) - {9C691A33-7DDA-4C2F-BE4C-C176083F35CF} - C:\WINDOWS\System32\bridge.dll O4 - HKLM\..\Run: [WebInstall2] C:\WINDOWS\Temp\Adware\WebInstall.exe /R O4 - HKLM\..\Run: [n8uIM7wSn] C:\WINDOWS\bTgX5m8a.exe O4 - HKLM\..\Run: [AutoUpdater] "C:\Program Files\AutoUpdate\AutoUpdate.exe" O4 - HKLM\..\Run: [systray] C:\WINDOWS\System32\a.exe O4 - … | |
Re: Will ask you to do the following first & then move HijackThis into it's own, permanent folder. Download & instal Adaware from [url]http://majorgeeks.com/download.php?det=506[/url] & update it B4 scanning. In settings under 'scanning,' have it set to 'scan within archives,' 'scan active processes,' 'scan registry,' 'deepscan registry' 'scan my IE Favourites … | |
Re: there is also a removal tool for it here; Newdotnet removal instructions here [url]http://www.newdotnet.com/#remove[/url] Messenger Plus should be uninstalled as it comes bundled with Lop.com. Is this scan B4 or after you ran CWShredder? image.dll install is a CoolWebSearch variant. Make sure you have the latest version of CWShredder & … | |
Re: Try this. Please follow instructions found here & run the Msg121 fix. [url]http://www10.brinkster.com/expl0iter/freeatlast/L2M/Msg121.htm[/url] And that R3 entry can go as a bit of housekeeping. | |
Re: Have only HJT running & fix these entries= O1 - Hosts: 12.129.205.209 search.netscape.com12.129.205.209 sitefinder.verisign.com O2 - BHO: NavErrRedir Class - {5D60FF48-95BE-4956-B4C6-6BB168A70310} - C:\PROGRA~1\INCRED~1\BHO\INCFIN~1.DLL O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file) | |
Re: It could be a firewall problem? Did the spyware program have a backup facility where you can restore what you deleted? Is IE6 set to offline mode? | |
Re: Have you tried a repair job by going in to add/remove programs? | |
Re: Get rid of these C:\PROGRAM FILES\180SOLUTIONS\MSBB.EXE C:\PROGRAM FILES\BARGAIN BUDDY\BIN\BARGAINS.EXE You may have to do it from add/remove programs. This one O4 - HKLM\..\Run: [RDLL] RunDll16.exe according to this page [url]http://www.sysinfo.org/startuplist.php?filter=RunDll16.exe&count=&type=[/url] was added as a virus. O4 - HKLM\..\Run: [EOIVZCFJM] C:\WINDOWS\EOIVZCFJM.exe< this one needs to be removed in safe mode. Do … | |
Re: Might be an idea to have an online scan, so go to [url]http://housecall.trendmicro.com/[/url] for an on-line scan & set it to autoclean for you. Download & instal Adaware from [url]http://majorgeeks.com/download.php?det=506[/url] & update it B4 scanning. In settings under 'scanning,' have it set to 'scan within archives,' 'scan active processes,' 'scan … | |
Re: Download & instal Adaware from [url]http://majorgeeks.com/download.php?det=506[/url] & update it B4 scanning. In settings under 'scanning,' have it set to 'scan within archives,' 'scan active processes,' 'scan registry,' 'deepscan registry' 'scan my IE Favourites for banned URL's,' 'scan my host's file.' Also in tweaks under 'cleaning engine' set it to 'Automatically … | |
Re: There are several files with the same name that belong to 3rd party software. Without knowing which it is, it is hard to advise. For example; Update Service 'Update.exe' Loaded by Handybits programs such as EasyCrypto. Re-instates itself every time the program is run so best to leave it enabled. … | |
Re: Maybe if you were that smart you would have set the protected files size when you installed Norton!! | |
Re: You may still have some remnants of the worms left behind. Download & instal Adaware from [url]http://majorgeeks.com/download.php?det=506[/url] & update it B4 scanning. In settings under 'scanning,' have it set to 'scan within archives,' 'scan active processes,' 'scan registry,' 'deepscan registry' 'scan my IE Favourites for banned URL's,' 'scan my host's … | |
Re: apparently, he cannot get past the logon screen though. | |
Re: Download & instal Adaware from [url]http://majorgeeks.com/download.php?det=506[/url] & update it B4 scanning. In settings under 'scanning,' have it set to 'scan within archives,' 'scan active processes,' 'scan registry,' 'deepscan registry' 'scan my IE Favourites for banned URL's,' 'scan my host's file.' Also in tweaks under 'cleaning engine' set it to 'Automatically … | |
Re: Hi. Noticed you need more removal, hope you don't mind caperjack? Run HJT again & get it to fix: This is perfect NAV spyware O2 - BHO: NavErrRedir Class - {0428FFC7-1931-45b7-95CB-3CBB919777E1} - (no file) You can fix these too if you want to stop them running in the background & … | |
Re: What was your previous video card? I am not certain, but in the BIOS you may have to alter settings to AGP if the previous card was a PCI. I'm not too techie as you can probably tell, but perhaps someone else can explain this better? | |
Re: Looks to me like you've been hijacked by coolwebsearch. Download CWShredder from [url]http://209.133.47.200/~merijn/files/CWShredder.exe[/url] unzip & run it getting it to fix all it finds. Make sure that all your microsoft updates are current & then post another log plz. What do you think caperjack? | |
Re: At the moment I would try another browser to see if you are able to surf using that. (Mozilla, Opera, any of the ones that do not use the IE engine). If you can I would try a repair of IE or go to M$ & get the latest updates. … | |
Re: Hi there. First up I would go & have an on-line scan from here [url]http://housecall.antivirus.com/[/url] . Then download a program called 'HijackThis' & unzip it into it's own folder in My Documents, or somewhere. Not a temporary one or it cannot create backups. Start HJT & scan your computer. DO … | |
Re: [QUOTE=J?E]ok i got a registry cleaner and i need to know what to do. i have 242 "problems" detected of reg keys leading nowhere and i dont know if i want to delte them or what... also how do i make a backup of the registry? and can anyone give … | |
Re: Put your log up at the cexx forums. All they seem to do is fix up HJT logs. [url]http://boards.cexx.org/index.php?sid=339414b8660407d787b52a216c1cabcc[/url] | |
Re: Hi. First you need to get HijackThis into it's own folder or it will not create back-ups. Rescan & get HJT to fix these entries: O4 - HKLM\..\Run: [wcmdmgr] C:\WINDOWS\wt\updater\wcmdmgrl.exe -launch This is related to wild Tangent. Apart from that I can't see anything. If you want to stay as … | |
Re: Can you not change it in the BIOS?? I noticed that there is an option to change the password there, but I don't know if you need the old password to make it work. | |
Re: Download & install Adaware, update it & in settings make sure to tick; scan within archives, deep scan registry & then in 'Tweak' tick automatically try to unregister objects prior to deletion. Run the scan & place a check next to everything it finds & remove them. Download Spybot S … | |
Re: hey clearice. The best thing to do is run highjackthis & see whats in it. Myway will not affect your opera browser, only IE. | |
Re: See if you can start it in safe mode & try to do a virus scan. Don't know what else to suggest. | |
Re: Hi. Run HJT again & get it to fix these entries; R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://mshp.dll/sp.html#37049 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = [url]http://www.searchdot.net[/url] R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://mshp.dll/sp.html#37049 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://mshp.dll/index.html#37049 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://mshp.dll/sp.html#37049 O2 - BHO: . - {587DBF2D-9145-4c9e-92C2-1F953DA73773} … | |
Re: Run HJT again & get it to fix these entries; R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm O2 - BHO: (no name) - {FA0286CF-E520-49BE-B9C4-5C985CC501B6} - C:\WINDOWS\x8rod.dll O4 - HKLM\..\Run: [AutoUpdater] "C:\Program Files\AutoUpdate\AutoUpdate.exe" O16 - DPF: {4FDF3696-5078-4952-868C-CEEB9683B8C4} (DownloadFile Control) - [url]http://webcam.geovision.com.tw/cab/DownloadFile.cab[/url] O16 - DPF: {5508547B-4F40-4005-AE0C-343C985DACE1} (WebCamX Control) - [url]http://68.11.177.144:79/cab/install.cab[/url] O16 - … | |
Re: First up place HJT in a permanent folder of it's own then rescan & fix the following entries; R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about_:blank R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about_:blank O2 - BHO: (no name) - {4E7BD74F-2B8D-469E-C0FF-FD60B590A87D} - C:\PROGRA~1\COMMON~1\Real\Toolbar\realbar.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll (file … | |
Re: Just disable it in services if you don't use it. ![]() | |
Do you want the internet? Download it here. Might take a while though. | |
Re: The other thing to do would be to get a Win98 boot disk floppy. This will format the HD for you, then put the W2K disk in & install. | |
Re: Drag the exe that you want to start to the 'start' button at the left bottom of screen. Keep the mouse button down, the menu will then open. Go up to 'programs' & find the startup folder. Drop it there. | |
Re: If you have java installed, remove it first, then try downloading & installing. |
The End.