4,383 Posted Topics

Member Avatar for KIP

KIP, Hello! and welcome to the Daniweb forums. =============== Before we begin, let's move [b]HiJackThis[/b] to it's own folder; like [b]c:\HJT[/b]. When we're done '[i]cleaning[/i]' off your system, we're going to '[i]flush[/i]' the temporary folders which, with [b]HiJackThis[/b] [color=#ff0000][i]in it's current location, we'll lose both the program and the backups …

Member Avatar for [GR}nemesis
0
403
Member Avatar for atky2004

You are hosting a mailing service on your pc. Let's get rid of it :). Please download FileFind from Atribune: [url]http://www.atribune.org/downloads/FileFind.zip[/url] Unzip the file and save it to your desktop. To run FileFind, please do the following: * Click on FileFind.exe * In the box labeled "Enter the directory to …

Member Avatar for crunchie
0
211
Member Avatar for vjc88

Can you please do the following. =============== Scan with [b]HijackThis[/b] and then place a check next to all the following, if present: [color=#9933cc][b] O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker\RunApp.exe (file missing) [/b][/color] [color=#9933cc][b] O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker\RunApp.exe (file missing) …

Member Avatar for crunchie
0
165
Member Avatar for vjc88

You can keep both Panda and Ewido (AVG anti-spyware now) as Ewido is NOT an AV. Probably meant F-Prot. Just stop one from starting with windows and use it as an on-demand scanner.

Member Avatar for crunchie
0
281
Member Avatar for mvanmeter

Hi and welcome to Daniweb forums :). Can you please do the following. =============== Scan with [b]HijackThis[/b] and then place a check next to all the following, if present: [color=#9933cc][b] O2 - BHO: (no name) - {E3215F20-3212-11D6-9F8B-00D0B743919D} - (no file) [/b][/color] [color=#9933cc][b] O4 - HKLM\..\Run: [endr] C:\WINDOWS\System32\endr.exe [/b][/color] [color=#9933cc][b] O4 …

Member Avatar for crunchie
0
94
Member Avatar for suhailpuri

Hi and welcome to Daniweb forums :). Can you please do the following. =============== Run [b]HiJackThis[/b] then: 1. Click "[b][i]Open the Misc Tools Section[/i][/b]" 2. Click "[b][i]Open Process manager[/i][/b]" - Next, while holding down the [b]CTRL[/b] key, locate ([i]if present[/i]) and click on ([i]highlight[/i]) each of the following: [b][color=#000000]C:\WINDOWS\[/color][color=#ff0000]lsass.exe[/color][/b] Now …

Member Avatar for PhilliePhan
0
112
Member Avatar for mediaphobia

Hi and welcome to Daniweb forums :). Can you please do the following. =============== Before we begin, let's move [b]HiJackThis[/b] to it's own folder; like [b]c:\HJT[/b]. When we're done '[i]cleaning[/i]' off your system, we're going to '[i]flush[/i]' the temporary folders which, with [b]HiJackThis[/b] [color=#ff0000][i]in it's current location, we'll lose both …

Member Avatar for crunchie
0
254
Member Avatar for MysticalChicken

Run this one too; Please download [url=http://www.atribune.org/ccount/click.php?id=4][color=blue]VundoFix.exe[/color][/url] to your desktop.[list] [*] Double-click [b]VundoFix.exe[/b] to run it. [*]Click the [b]Scan for Vundo[/b] button. [*] Once it's done scanning, click the [b]Remove Vundo[/b] button. [*] You will receive a prompt asking if you want to remove the files, click [b]YES[/b] [*] Once …

Member Avatar for crunchie
0
146
Member Avatar for crunchie

Having a few problems in the hijackthis forum with the way logs are being formatted. [url]http://www.daniweb.com/techtalkforums/thread66064.html[/url] The only way to read them is to "Reply with Quote" and the log is then rendered correctly in the reply box. Any chance of getting this sorted please? :).

0
89
Member Avatar for burnsy

Please download [url=http://siri.urz.free.fr/Fix/SmitfraudFix.zip][b][color=red]SmitfraudFix[/color][/b][/url] (by [b]S!Ri[/b]) Extract the content (a folder named [b]SmitfraudFix[/b]) to your Desktop. Open the [b]SmitfraudFix[/b] folder and double-click [b]smitfraudfix.cmd[/b] Select option #1 - [b]Search[/b] by typing [b]1[/b] and press "[b]Enter[/b]"; a text file will appear, which lists infected files (if present). Please copy/paste the content of that …

Member Avatar for crunchie
0
145
Member Avatar for BasicDesign

Please download FixWareout from one of these sites: [url]http://downloads.subratam.org/Fixwareout.exe[/url] [url]http://swandog46.geekstogo.com/Fixwareout.exe[/url] Save it to your desktop and run it. Click Next, then Install, make sure "Run fixit" is checked and click Finish. The fix will begin; follow the prompts. You will be asked to reboot your computer; please do so. Your …

Member Avatar for crunchie
0
115
Member Avatar for hazdude

[b]Download [color=blue]HijackThis[/color] [b][color=red]self-extracting[/color][/b] zip version from [url=http://www.malwareremoval.com/downloads.html][u]here.[/u][/url][/b] Once downloaded, double click on the file & it will install into it's own, permanent folder. Start HJT & press the "Do a system scan and save a log file" button. When the scan is finished a window will pop up giving you …

Member Avatar for crunchie
0
149
Member Avatar for grimgraw

Hi and welcome to Daniweb forums :). Please download [url=http://siri.urz.free.fr/Fix/SmitfraudFix.zip][b][color=red]SmitfraudFix[/color][/b][/url] (by [b]S!Ri[/b]) Extract the content (a folder named [b]SmitfraudFix[/b]) to your Desktop. Open the [b]SmitfraudFix[/b] folder and double-click [b]smitfraudfix.cmd[/b] Select option #1 - [b]Search[/b] by typing [b]1[/b] and press "[b]Enter[/b]"; a text file will appear, which lists infected files (if …

Member Avatar for crunchie
0
132
Member Avatar for gctbob

I see nothing in your log to suggest anything untoward. What problems are you having? You can try the following; Please download and install [url=http://www.ewido.net/en/product/][b][color=blue]AVG antispyware tool[/color][/b][color=blue][/color][/url][list][*][color=red]Close all other Applications[/color] Select language click [b]Ok[/b][*]Click [b]I Agree [/b][*]Click[b] next[/b][*]Click [b]Install[/b][*]Click[b] Finish[/b][*]Wait and AVG antispyware will open to the main screen automatically.[*]Wait …

Member Avatar for crunchie
0
110
Member Avatar for bmcgill

Can you please do the following. =============== Go to [b]Add/Remove programs[/b] and uninstall the following, if present: [b][color=#ff0000]SideFind[/color][/b] The above could appear anywhere within the entry. Be careful not to remove any [i]personal[/i] or [i]system[/i] software. =============== Scan with [b]HijackThis[/b] and then place a check next to all the following, …

Member Avatar for crunchie
0
67
Member Avatar for Dles

Also, [b]Download LSPfix from [url=http://www.computercops.biz/downloads-file-334.html][u]here[/u][/url][/b] On the opening screen, click the "I know what I'm doing" checkbox. Check all instances of "osmim.dll" [b](and nothing else),[/b] and move them to the "Remove" pane. Then click Finish.

Member Avatar for patpog
0
285
Member Avatar for a_quint

Can you please do the following. =============== You will have to disable [b]Spybot's Teatimer[/b] before we begin, as it will interfere with the fix. To do this can you start Spybot and go to the [b]Mode[/b] button and select [b]Advanced.[/b] Go to [b]Tools > Resident[/b] and uncheck the box next …

Member Avatar for crunchie
0
98
Member Avatar for MavericksAce

You should also do the following; Please download FixWareout from one of these sites: [url]http://downloads.subratam.org/Fixwareout.exe[/url] [url]http://swandog46.geekstogo.com/Fixwareout.exe[/url] Save it to your desktop and run it. Click Next, then Install, make sure "Run fixit" is checked and click Finish. The fix will begin; follow the prompts. You will be asked to reboot …

Member Avatar for MavericksAce
0
252
Member Avatar for penguin4

I would suggest that you restore everything you 'fixed' with hijackthis. reboot, rescan with hijackthis and post the log back here. Hopefully you haven't deleted something that is critical :D.

Member Avatar for crunchie
0
88
Member Avatar for GeekDice

[b]Unzip HJT into it's own permanent folder[/b] before doing anything in order that the backups it creates cannot be deleted by accident. [color=red](Not a temporary folder or directly on the desktop (in a folder on the desktop is fine) & not directly on your hard drive).[/color] [b][color=red]Close all (browser) windows …

Member Avatar for crunchie
0
124
Member Avatar for jtor237

Can you please do the following. =============== Go to [b]Add/Remove programs[/b] and uninstall the following, if present: [b][color=#ff0000]Toolbar888[/color][/b] The above could appear anywhere within the entry. Be careful not to remove any [i]personal[/i] or [i]system[/i] software. =============== Next, Open a [b]command prompt[/b] by: 1. Clicking "[b]Start[/b]", then "[b]Run...[/b]". 2. Enter …

Member Avatar for crunchie
0
99
Member Avatar for Isagenix

Please download [url=http://siri.urz.free.fr/Fix/SmitfraudFix.zip][b][color=red]SmitfraudFix[/color][/b][/url] (by [b]S!Ri[/b]) Extract the content (a folder named [b]SmitfraudFix[/b]) to your Desktop. Open the [b]SmitfraudFix[/b] folder and double-click [b]smitfraudfix.cmd[/b] Select option #1 - [b]Search[/b] by typing [b]1[/b] and press "[b]Enter[/b]"; a text file will appear, which lists infected files (if present). Please copy/paste the content of that …

Member Avatar for crunchie
0
159
Member Avatar for fyiwriter

The tool I use to diagnose HJT logs spits out all the bad entries it finds, so you can pick through what malware you wish to leave on your pc :). Please run the PurityScan [url=http://www.purityscan.com/uninstall.html][u]uninstaller.[/u][/url] == Can you please do the following. =============== When we're done cleaning off your …

Member Avatar for crunchie
0
686
Member Avatar for dking

Can you please do the following. =============== Go to [b]Add/Remove programs[/b] and uninstall the following, if present: [b][color=#ff0000]MyWebSearch[/color][/b] The above could appear anywhere within the entry. Be careful not to remove any [i]personal[/i] or [i]system[/i] software. =============== Scan with [b]HijackThis[/b] and then place a check next to all the following, …

Member Avatar for crunchie
0
134
Member Avatar for sarahk

Hi Dani. I have got four digests in the last two days myself :). Came home from work and there were two identical digests in my inbox.

Member Avatar for jbennet
0
181
Member Avatar for ratiug

Please download [url=http://siri.urz.free.fr/Fix/SmitfraudFix.zip][b][color=red]SmitfraudFix[/color][/b][/url] (by [b]S!Ri[/b]) Extract the content (a folder named [b]SmitfraudFix[/b]) to your Desktop. Open the [b]SmitfraudFix[/b] folder and double-click [b]smitfraudfix.cmd[/b] Select option #1 - [b]Search[/b] by typing [b]1[/b] and press "[b]Enter[/b]"; a text file will appear, which lists infected files (if present). Please copy/paste the content of that …

Member Avatar for crunchie
0
118
Member Avatar for Gatorbabe

At a guess I would say that you have those options disabled/protected by Spybot S&D.

Member Avatar for lol_hacker101
0
344
Member Avatar for cdesia

Open IE and go to Tools\Internet Options. Hit the security Tab and select the default button. Hit apply and then ok. Try to update again. You can also put the site into your trusted zone. If that does not work, perhaps it is Microsoft's AntiSpyWare that is preventing the install? …

Member Avatar for beam1
0
127
Member Avatar for rodzilla
Member Avatar for jbennet
0
765
Member Avatar for steveneven

Connection Type: ADSL Connection Speed: 1.5Mb/256Mb Cost Per Month: $AU60 10Gig limit Country: Australia Name Of ISP:Westnet

Member Avatar for kosmoe
1
652
Member Avatar for Roberdin

99.9% Opera user. 3.7 Mb download with all the bells and whistles :). Have firefox but use it seldom. Too many add-ons needed to bring it even remotely close to Opera. Use IE only for microsoft updates.

Member Avatar for BeastOverlordH6
0
547
Member Avatar for Dani

Thank you all for your well wishes, but things are going way off topic now, so I will close this thread :).

Member Avatar for crunchie
0
792
Member Avatar for ep2002

Not seeing anything bad in your log. You may want to try uninstalling FF and download the latest version. Version 2.0 being it.

Member Avatar for crunchie
0
127
Member Avatar for silver15

[b]Download [color=blue]CWShredder[/color] from [url=http://computercops.biz/downloads-file-349.html][u]here.[/u][/url] [b]Reboot into safe mode[/b] following the instructions [url=http://www.xtra.co.nz/help/0,,6156-1377929,00.html][u]here[/u][/url] & run it.[/b] Select the [color=red]fix[/color] button & it will fix everything related to CoolWebSearch that is stored in it's database. Close [b]ALL[/b] windows, including Internet Explorer, before running CWShredder. [color=red]Reboot normally.[/color] To help prevent this from happening …

Member Avatar for bnrup
0
206
Member Avatar for alc6379

Have some members who post with spyware problems zip up some of their nasties & email them to you.

Member Avatar for bnrup
0
1K
Member Avatar for nick2004

Can you please do the following. =============== Before we begin, let's move [b]HiJackThis[/b] to it's own folder; like [b]c:\HJT[/b]. When we're done '[i]cleaning[/i]' off your system, we're going to '[i]flush[/i]' the temporary folders which, with [b]HiJackThis[/b] [color=#ff0000][i]in it's current location, we'll lose both the program and the backups it creates. …

Member Avatar for Xpuser23
0
237
Member Avatar for gogishah

Can you please do the following. =============== Scan with [b]HiJackThis,[/b] then check(tick) the following, if present: [color=#9933cc][b] O2 - BHO: KGhost - {968BC8A3-7660-4B12-B2BF-3334775835E1} - C:\Program Files\NetMeeting\KG\KGhost.dll [/b][/color] [color=#9933cc][b] O2 - BHO: (no name) - {D7AAF73A-7ACF-B386-D975-9FB5CDD1F829} - C:\WINDOWS\efmme.dll [/b][/color] [color=#9933cc][b] O4 - HKLM\..\Run: [jyxsd] C:\WINDOWS\jyxsd.exe [/b][/color] [color=#9933cc][b] O4 - HKLM\..\Run: [XtTb.exe] …

Member Avatar for crunchie
0
421
Member Avatar for LinsTrimble

Hi and welcome to Daniweb forums :). Can you please do the following. =============== Go to [b]Add/Remove programs[/b] and remove(uninstall) the following, if present: [b][color=#ff0000]MyWebSearch[/color][/b] [b][color=#ff0000]NewDotNet[/color][/b] The above could appear anywhere within the entry. Be careful not to remove any [i]personal[/i] or [i]system[/i] software. =============== Scan with [b]HijackThis[/b] and then …

Member Avatar for F2kSel
0
182
Member Avatar for Dani
Member Avatar for pimpwack

O4 - Startup: PowerReg Scheduler.exe I generally fix it with hijackthis as it is not required. [url]http://www.leadertech.com/ereg.html[/url]

Member Avatar for DMR
0
248
Member Avatar for labber

Can you please do the following. =============== Download, then unzip to "[b]C:\HJT[/b]", the newest version of [url=http://www.spywareinfo.com/~merijn/files/hijackthis.zip]HiJackThis[/url]; [i]version 1.99.1[/i]. Then repost your log, either now, or after following the steps in the solution ([i]if provided in this post[/i]). [color=#ff0000][i]This version has features that might be more helpful in 'cleaning' up …

Member Avatar for crunchie
0
481
Member Avatar for crunchie

Jam. That's almost as bad as the one selling empty Windows folders :). [url]http://cgi.ebay.co.uk/Goldfish-Coffin-R-I-P_W0QQitemZ170016556236QQihZ007QQcategoryZ3212QQrdZ1QQcmdZViewItem[/url]

Member Avatar for jwenting
0
194
Member Avatar for mddv

Looks like it was posted on the 16 of this month of this year to me????

Member Avatar for TheNNS
0
72
Member Avatar for crunchie
Member Avatar for UrbanKhoja
0
130
Member Avatar for bazzouni

Hi and welcome to Daniweb :). I have split your post out to your own thread. It's as easy to start a new one as it is to reply to one :). == You may want to print out or make a copy of these instructions before starting, because you …

Member Avatar for crunchie
0
97
Member Avatar for PhatMatt17

Hi and welcome to Daniweb :). [b]Download [color=blue]HijackThis[/color] [b][color=red]self-extracting[/color][/b] zip version from [url=http://www.malwareremoval.com/downloads.html][u]here.[/u][/url][/b] Once downloaded, double click on the file & it will install into it's own, permanent folder. Start HJT & press the "Do a system scan and save a log file" button. When the scan is finished a …

Member Avatar for crunchie
0
242
Member Avatar for frogntoad

Hi and welcome to Daniweb forums :). Can you please do the following. =============== We'll need to disable [b]AdAware's [i]AdWatch[/i][/b], since it might interfere with other program(s) we might be using to 'clean' off your system; you can re-enable it after we're done. To disable this feature, run [b]AdAware SE[/b], …

Member Avatar for crunchie
0
228
Member Avatar for thecageeffect

Can you please do the following. =============== Go to [b]Add/Remove programs[/b] and remove(uninstall) the following, if present: [b][color=#ff0000]NavHelper[/color][/b] [b][color=#ff0000]Red Swoosh[/color][/b] [b][color=#ff0000]WildTangent[/color][/b] The above could appear anywhere within the entry. Be careful not to remove any [i]personal[/i] or [i]system[/i] software. =============== Next, Open a [b]command prompt[/b] by: 1. Clicking "[b]Start[/b]", then …

Member Avatar for crunchie
0
230
Member Avatar for blahun01

Please run the PurityScan [url=http://www.purityscan.com/uninstall.html][u]uninstaller.[/u][/url] == Please download [url=http://siri.urz.free.fr/Fix/SmitfraudFix.zip][b][color=red]SmitfraudFix[/color][/b][/url] (by [b]S!Ri[/b]) Extract the content (a folder named [b]SmitfraudFix[/b]) to your Desktop. Open the [b]SmitfraudFix[/b] folder and double-click [b]smitfraudfix.cmd[/b] Select option #1 - [b]Search[/b] by typing [b]1[/b] and press "[b]Enter[/b]"; a text file will appear, which lists infected files (if present). …

Member Avatar for crunchie
0
245
Member Avatar for g_hallan

Can you please do the following. =============== Scan with [b]HijackThis[/b] and then place a check next to all the following, if present: [color=#9933cc][b] R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm [/b][/color] [color=#9933cc][b] O2 - BHO: SpoofBHO Class - {07A78AEA-4A54-4967-9A60-4B68592D30C7} - C:\WINDOWS\se_spoof.dll (file missing) [/b][/color] [color=#9933cc][b] O2 - BHO: ChangerBHO Class …

Member Avatar for crunchie
0
254

The End.