4,383 Posted Topics

Member Avatar for Xtremer360

Download & instal Adaware from [url=http://www.computercops.biz/downloads-file-292.html][u]here[/u][/url] & update it B4 scanning. In settings under 'scanning,' have it set to 'scan within archives,' 'scan active processes,' 'scan registry,' 'deepscan registry' 'scan my IE Favourites for banned URL's,' 'scan my host's file.' In 'tweaks' under 'scanning engine' set it to 'unload recognised …

Member Avatar for crunchie
0
164
Member Avatar for server_crash

I get 2 email notices for one reply. Happened again this morning. Happened quite a lot in the last couple of weeks.

Member Avatar for server_crash
0
696
Member Avatar for Micha31

Can you please do the following. =============== Please visit at least two of the following sites for an online virus scan: BitDefender Free Online Virus Scan [url]http://www.bitdefender.com/scan/licence.php[/url] Make sure you tick [b]AutoClean[/b] under [b]Scan Options.[/b] Panda ActiveScan [url]http://www.pandasoftware.com/activescan/com/activescan_principal.htm[/url] Make sure you tick [b]Disinfect automatically[/b] under [b]Scan Options.[/b] Housecall at TrendMicro …

Member Avatar for Micha31
0
197
Member Avatar for Rosy95340

Hi and welcome to Daniweb forums :). Can you please do the following. =============== I'd [b]recommend[/b] that you install all the [color=#ff0000][b][i]critical windows updates[/i][/b][/color] available from [b]Microsoft[/b], up to [i]service pack 1[/i]. This will help to make your system more secure and prevent many '[i]problems[/i]' from reoccurring in the future. …

Member Avatar for Rosy95340
0
213
Member Avatar for divingincozumel

Spybot is waiting for a reboot, so if you haven't already restarted, please do so before going ahead with the following. [b]Please go [url=http://www.pchell.com/support/wintools.shtml][u]here[/u][/url] for Wintools removal instructions.[/b] [b][color=red]Close all (browser) windows & rescan with hijackthis.[/color][/b] When the scan is finished place a check in the box to the left …

Member Avatar for crunchie
0
350
Member Avatar for elfnet

You have the Xabot virus. Unzip HJT into it's own permanent folder before doing anything in order for it to create backups. [color=red](Not a temporary folder or the desktop & not directly on your hard drive).[/color] Close all (browser) windows & rescan with hijackthis. When the scan is finished place …

Member Avatar for DMR
0
772
Member Avatar for locked out

Close all (browser) windows & rescan with hijackthis. When the scan is finished place a check in the box to the left of the following entries & click 'fix checked' : O2 - BHO: Core Library - {D4D505DF-D582-400c-91B6-84921012AFE3} - C:\WINDOWS\SYSTEM\PDF01D5.DLL O4 - HKLM\..\Run: [wininetd] C:\WINDOWS\SYSTEM\wininetd.exe Reboot into safe mode following …

Member Avatar for DMR
0
327
Member Avatar for MiDude
Member Avatar for MiDude
0
596
Member Avatar for Dread Helm

[b]Download [color=blue]HijackThis[/color] [b][color=red]self-extracting[/color][/b] zip version from [url=http://www.malwareremoval.com/downloads.html][u]here.[/u][/url][/b] Once downloaded, double click on the file & it will install into it's own, permanent folder. Start HJT & press the "Do a system scan and save a log file" button. When the scan is finished a window will pop up giving you …

Member Avatar for crunchie
0
592
Member Avatar for hammy

[b]First of all we have to remove Newdotnet,[/b] either from add/remove programs, or by going [url=http://www.newdotnet.com/removal.html][u]here[/u][/url] and scrolling down to the uninstall tool. == Move hijackthis into a permanent folder before your next post please. In a temp folder you will lose the program and it's backups when the temp …

Member Avatar for crunchie
0
173
Member Avatar for Andyc

Hi and welcome to Daniweb forums :). Please visit at least two of the following sites for an online virus scan: BitDefender Free Online Virus Scan [url]http://www.bitdefender.com/scan/licence.php[/url] Make sure you tick [b]AutoClean[/b] under [b]Scan Options.[/b] Panda ActiveScan [url]http://www.pandasoftware.com/activescan/com/activescan_principal.htm[/url] Make sure you tick [b]Disinfect automatically[/b] under [b]Scan Options.[/b] Housecall at TrendMicro …

Member Avatar for crunchie
0
173
Member Avatar for jewelschica

Please download [url=http://www.atribune.org/ccount/click.php?id=4][b][color=red]VundoFix.exe[/color][/b][/url] to your desktop.[list] [*]Double-click [b]VundoFix.exe[/b] to run it. [*]Click the [b]Scan for Vundo[/b] button. [*]Once it's done scanning, click the [b]Remove Vundo[/b] button. [*]You will receive a prompt asking if you want to remove the files, click [b]YES[/b] [*]Once you click yes, your desktop will go blank …

Member Avatar for crunchie
0
153
Member Avatar for jonty1975

Please download [url=http://siri.urz.free.fr/Fix/SmitfraudFix.zip][b][color=red]SmitfraudFix[/color][/b][/url] (by [b]S!Ri[/b]) Extract the content (a folder named [b]SmitfraudFix[/b]) to your Desktop. Open the [b]SmitfraudFix[/b] folder and double-click [b]smitfraudfix.cmd[/b] Select option #1 - [b]Search[/b] by typing [b]1[/b] and press "[b]Enter[/b]"; a text file will appear, which lists infected files (if present). Please copy/paste the content of that …

Member Avatar for jessedancer
0
310
Member Avatar for tazxrulz

Can you please do the following. =============== Go to [b]Add/Remove programs[/b] and remove(uninstall) the following, if present: [b][color=#ff0000]MyWebSearch[/color][/b] The above could appear anywhere within the entry. Be careful not to remove any [i]personal[/i] or [i]system[/i] software. =============== Scan with [b]HiJackThis,[/b] then check(tick) the following, if present: [color=#9933cc][b] R1 - HKCU\Software\Microsoft\Internet …

Member Avatar for crunchie
0
140
Member Avatar for zscan

Hi and welcome to Daniweb forums :). Please download [url=http://siri.urz.free.fr/Fix/SmitfraudFix.zip][b][color=red]SmitfraudFix[/color][/b][/url] (by [b]S!Ri[/b]) Extract the content (a folder named [b]SmitfraudFix[/b]) to your Desktop. Open the [b]SmitfraudFix[/b] folder and double-click [b]smitfraudfix.cmd[/b] Select option #1 - [b]Search[/b] by typing [b]1[/b] and press "[b]Enter[/b]"; a text file will appear, which lists infected files (if …

Member Avatar for crunchie
0
154
Member Avatar for Aries4

Can you please do the following. =============== Scan with [b]HiJackThis,[/b] then check(tick) the following, if present: [color=#9933cc][b] R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = [url]http://www.dell4me.com/myway[/url] [/b][/color] [color=#9933cc][b] F2 - REG:system.ini: Shell= [/b][/color] [color=#9933cc][b] F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe [/b][/color] [color=#9933cc][b] O8 - Extra context menu item: &Search - [url]http://ka.bar.need2find.com/KA/menusearch.html?p=KA[/url] [/b][/color] [color=#9933cc][b] O9 - …

Member Avatar for crunchie
0
406
Member Avatar for Automatic

Can you please do the following. =============== Scan with [b]HiJackThis,[/b] then check(tick) the following, if present: [color=#9933cc][b] O2 - BHO: (no name) - {77701e16-9bfe-4b63-a5b4-7bd156758a37} - (no file) [/b][/color] [color=#9933cc][b] O2 - BHO: (no name) - {e52dedbb-d168-4bdb-b229-c48160800e81} - (no file) [/b][/color] Now, close [b]all[/b] instances of Internet Explorer and any other …

Member Avatar for crunchie
0
310
Member Avatar for Crispy

You still have the CWS infection. Which version of the shredder do you have? It should be 1.59.1 & [b]ALL[/b] windows, browser & folder, [b]must[/b] be [b]closed[/b] when [b]fixing[/b] with hijackthis or it will [b]not[/b] work. [b]Close all (browser) windows & rescan with hijackthis.[/b] When the scan is finished place …

Member Avatar for crunchie
0
408
Member Avatar for presmmbb

You should print out these instructions, or copy them to a NotePad file for reading while in Safe Mode, because you will not be able to connect to the Internet to read from this site. Please download [url=http://www.ewido.net/en/download/][b][color=blue]Ewido Anti-Malware[/color][/b][/url] it is a free version of the program.[list=1] [*]Install Ewido Anti-Malware …

Member Avatar for crunchie
0
154
Member Avatar for jonty1975

Please download [url=http://siri.urz.free.fr/Fix/SmitfraudFix.zip][b][color=red]SmitfraudFix[/color][/b][/url] (by [b]S!Ri[/b]) Extract the content (a folder named [b]SmitfraudFix[/b]) to your Desktop. Open the [b]SmitfraudFix[/b] folder and double-click [b]smitfraudfix.cmd[/b] Select option #1 - [b]Search[/b] by typing [b]1[/b] and press "[b]Enter[/b]"; a text file will appear, which lists infected files (if present). Please copy/paste the content of that …

Member Avatar for crunchie
0
123
Member Avatar for bentonjoe

Hi and welcome to Daniweb forums :). == Please download <a href="http://www.atribune.org/ccount/click.php?id=7" rel="nofollow">Look2Me-Destroyer.exe</a> to your desktop. Close all windows before continuing. Double-click Look2Me-Destroyer.exe to run it. Put a check next to Run this program as a task. You will receive a message saying Look2Me-Destroyer will close and re-open in approximately …

Member Avatar for crunchie
0
356
Member Avatar for ep2002

Messenger Plus comes bundled with LOP :). You can reinstall Messenger Plus without the sponsor during the install process.

Member Avatar for ep2002
0
959
Member Avatar for kaj_kyle

Hi and welcome to Daniweb forums :). Please download [url=http://www.atribune.org/ccount/click.php?id=7]Look2Me-Destroyer.exe[/url] to your desktop. Close all windows before continuing. Double-click [color=blue]Look2Me-Destroyer.exe[/color] to run it. Put a check next to [color=blue]Run this program as a task.[/color] You will receive a message saying Look2Me-Destroyer will close and re-open in approximately 10 seconds. Click …

Member Avatar for crunchie
0
438
Member Avatar for ciderman22

ciderman22, Hi and welcome to the Daniweb forums :). =============== Please visit at least two of the following sites for an online virus scan: BitDefender Free Online Virus Scan [url]http://www.bitdefender.com/scan/licence.php[/url] Make sure you tick [b]AutoClean[/b] under [b]Scan Options.[/b] Panda ActiveScan [url]http://www.pandasoftware.com/activescan/com/activescan_principal.htm[/url] Make sure you tick [b]Disinfect automatically[/b] under [b]Scan Options.[/b] …

Member Avatar for crunchie
0
558
Member Avatar for samwhich

Hi. Please do [b]not[/b] split the log as it makes it harder (for me at least :)) to read. Also, do not edit out any entries, they are [b]all[/b] important. = Please download [url=http://siri.urz.free.fr/Fix/SmitfraudFix.zip][b][color=red]SmitfraudFix[/color][/b][/url] (by [b]S!Ri[/b]) Extract the content (a folder named [b]SmitfraudFix[/b]) to your Desktop. Open the [b]SmitfraudFix[/b] folder …

Member Avatar for crunchie
0
149
Member Avatar for lvlIk3

Can you please do the following. =============== Scan with [b]HiJackThis,[/b] then check(tick) the following, if present: [color=#9933cc][b] O4 - Startup: csrss.lnk = ? [/b][/color] [color=#9933cc][b] O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing) [/b][/color] [color=#9933cc][b] O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe …

Member Avatar for crunchie
0
348
Member Avatar for Silver_Dragon

Please go [url=http://windowsupdate.microsoft.com/][u]here[/u][/url] & install ALL critical updates required for your system, including service pack 1a for both XP and IE6. Most malware is designed to attack unpatched XP systems - exploiting the available 'holes' - and can bypass third-party protection on an unpatched system. The most that can be …

Member Avatar for crunchie
0
574
Member Avatar for kylethedarkn

Please go to [url=http://virusscan.jotti.org/][u]Jotti's[/u][/url] and have these files scanned. Post the results back here. C:\WINDOWS\system32\[b]osk.exe[/b] C:\WINDOWS\system32\[b]MSSWCHX.EXE[/b]

Member Avatar for crunchie
0
372
Member Avatar for dvr
Member Avatar for Sionix

Hi. Welcome to Daniweb forums :). You are running hijackthis from a temporary folder. You need to create a new folder in a permanent directory of your choice, (a folder on the desktop is fine) name the new folder [b]hijackthis[/b] and move or unzip hijackthis.exe into that folder. Once you …

Member Avatar for crunchie
0
196
Member Avatar for FullCollapse

Please download [url=http://siri.urz.free.fr/Fix/SmitfraudFix.zip][b][color=red]SmitfraudFix[/color][/b][/url] (by [b]S!Ri[/b]) Extract the content (a folder named [b]SmitfraudFix[/b]) to your Desktop. Open the [b]SmitfraudFix[/b] folder and double-click [b]smitfraudfix.cmd[/b] Select option #1 - [b]Search[/b] by typing [b]1[/b] and press "[b]Enter[/b]"; a text file will appear, which lists infected files (if present). Please copy/paste the content of that …

Member Avatar for crunchie
0
195
Member Avatar for cre8er1

Please download [url=http://www.atribune.org/ccount/click.php?id=4][b][color=red]VundoFix.exe[/color][/b][/url] to your desktop.[list] [*]Double-click [b]VundoFix.exe[/b] to run it. [*]Click the [b]Scan for Vundo[/b] button. [*]Once it's done scanning, click the [b]Remove Vundo[/b] button. [*]You will receive a prompt asking if you want to remove the files, click [b]YES[/b] [*]Once you click yes, your desktop will go blank …

Member Avatar for crunchie
0
251
Member Avatar for mbuck66

Hi. Welcome to Daniweb forums :). You are running hijackthis from a temporary folder. You need to create a new folder in a permanent directory of your choice, (a folder on the desktop is fine) name the new folder [b]hijackthis[/b] and move or unzip hijackthis.exe into that folder. == Please …

Member Avatar for crunchie
0
388
Member Avatar for Dan van Dan

Please download the trial version of Ewido anti-malware here: [url]http://www.ewido.net/en/download/[/url] Install it, and update the definitions to the newest files. Do [b]NOT[/b] run a scan yet. Next, please reboot your computer in Safe Mode by doing the following: 1) Restart your computer 2) After hearing your computer beep once during …

Member Avatar for crunchie
0
371
Member Avatar for Saber56

Hi and welcome to Daniweb forums :). == [b]Download [color=blue]HijackThis[/color] [b][color=red]self-extracting[/color][/b] zip version from [url=http://www.malwareremoval.com/downloads.html][u]here.[/u][/url][/b] Once downloaded, double click on the file & it will install into it's own, permanent folder. Start HJT & press the "Do a system scan and save a log file" button. When the scan is …

Member Avatar for crunchie
0
218
Member Avatar for Jackal

Please download [url=http://siri.urz.free.fr/Fix/SmitfraudFix.zip][b][color=red]SmitfraudFix[/color][/b][/url] (by [b]S!Ri[/b]) Extract the content (a folder named [b]SmitfraudFix[/b]) to your Desktop. Open the [b]SmitfraudFix[/b] folder and double-click [b]smitfraudfix.cmd[/b] Select option #1 - [b]Search[/b] by typing [b]1[/b] and press "[b]Enter[/b]"; a text file will appear, which lists infected files (if present). Please copy/paste the content of that …

Member Avatar for crunchie
0
207
Member Avatar for jellybabyz

Could you click Start>Settings>Control Panel>Add or Remove Programs and uninstall 'Window Search', 'Window Searching', 'Lop.com', 'LOP SEARCH', 'Browser Enhancer', or 'Ultimate Browser Enhancer' if listed. You may be given a code to insert, do so and reboot when done. If not listed there, run the [color=blue]Lop Remover[/color] from: [url]http://66.220.17.157/help.html[/url] == …

Member Avatar for crunchie
0
489
Member Avatar for Jim97219

Download the [url=http://www.funkytoad.com/download/hoster.zip][color=blue]Hoster.[/color][/url] Run it and press "Restore Original Hosts" and press "OK". Exit Program. Note that if you have a custom host file, this will remove it. You can edit the host file with this program too. == Try running [url=http://windowsxp.mvps.org/IEFIX.htm][color=blue]IEFIX.htm[/color][/url] which will repair IE and run a System …

Member Avatar for crunchie
0
150
Member Avatar for babybec

Download [url=http://users.telenet.be/marcvn/tools/haxfix.exe][color=blue][b]haxfix.exe[/b][/color][/url] and save it to your desktop. [list] [*]Double click on [b]haxfix.exe[/b] to install haxfix. (standard installation path is c:\program Files\haxfix) [*]Checkmark "Create a desktop icon" [*]Click "Next" [*]When the installation is completed, make sure that the checkmark "Launch HaxFix" is placed [*]Click "Finish"[/list] A red "dos window" (dos …

Member Avatar for crunchie
0
183
Member Avatar for dustdogz

Hi dustdogz. =============== Let's look for, and delete, any program segments([i]prefetches[/i]) that might be present, and are associated with the '[i]problems[/i]' we're trying to remove from this system. To do this, let's: 1) Click "[b][i]Start | Search[/i][/b]", then search for each of these program's [i]base name(s)[/i], in all files and …

Member Avatar for jellybabyz
0
335
Member Avatar for blahun01

You need to update hijackthis to version 1.99.1. Run hijackthis & go to *Config\Misc Tools\Check for update on-line*. If the site is down, go [url=http://www.malwareremoval.com/downloads.html][u]here[/u][/url] and download the [b]selfextracting[/b] zip version. Remove the old version by opening the program, going to config\misc tools, then uninstall & exit. You then have …

Member Avatar for blahun01
0
273
Member Avatar for SilentBob3208
Member Avatar for Brandon-J
0
199
Member Avatar for candy01

[QUOTE=candy01]what ami proving?[/QUOTE] I assume it would be either that you [i]are[/i] hot in bed, or that sex is great :D. ;)

Member Avatar for candy01
0
459
Member Avatar for provoodoo

First of all could you click Start>Settings>Control Panel>Add or Remove Programs and uninstall 'Window Search', 'Window Searching', 'Lop.com', 'LOP SEARCH', 'Browser Enhancer', or 'Ultimate Browser Enhancer' if listed. You may be given a code to insert, do so and reboot when done. If not listed there, run the [color=blue]Lop Remover[/color] …

Member Avatar for crunchie
0
167
Member Avatar for katie mason

Hi Katie and welcome to Daniweb forums :). Presuming you are using W2K or Xp, please do the following; [b]Download [color=blue]HijackThis[/color] [b][color=red]self-extracting[/color][/b] zip version from [url=http://www.malwareremoval.com/downloads.html][u]here.[/u][/url][/b] Once downloaded, double click on the file & it will install into it's own, permanent folder. Start HJT & press the "Do a system …

Member Avatar for crunchie
0
73
Member Avatar for rawa13

Hi and welcome to Daniweb forums :). Can you please do the following. Run the PurityScan [url=http://www.purityscan.com/uninstall.html][u]uninstaller.[/u][/url] =============== Please visit at least two of the following sites for an online virus scan: BitDefender Free Online Virus Scan [url]http://www.bitdefender.com/scan/licence.php[/url] Make sure you tick [b]AutoClean[/b] under [b]Scan Options.[/b] Panda ActiveScan [url]http://www.pandasoftware.com/activescan/com/activescan_principal.htm[/url] Make …

Member Avatar for crunchie
0
306
Member Avatar for FlowersTurn

Download [color=blue][b]CWShredder 2.19[/b][/color] from [url=http://www.intermute.com/products/cwshredder.html][u]here.[/u][/url] Download[url=http://www.derbilk.de/SpSeHjfix112.zip]'SpSeHjfix'[/url] to the desktop and then right click a blank part of the desktop and select new folder, call it spfix unzip the file into that folder. [color=red]Disconnect from the net and Close ALL OPEN PROGRAMS.[/color] Run 'SpSeHjfix'. and click on "Start Disinfection". When it's …

Member Avatar for crunchie
0
203
Member Avatar for raziel42

Hi and welcome to Daniweb forums :). Please download [b][url=http://www.merijn.org/files/bfu.zip][color=red]Brute Force Uninstaller[/color][/url][/b] to your desktop. (rightclick on this link and choose save as, if using IE save target as)[list] [*]Right click the BFU folder on your desktop, and choose [b]Extract All[/b] [*]Click "Next" [*]In the box to choose where to …

Member Avatar for crunchie
0
290
Member Avatar for mfhjr

Rescan and save the log from hijackthis. Go into the notepad text file where the hijackthis log is saved and go to the 'Format' button at the top. Place a check (tick) next to word wrap and that should fix it.

Member Avatar for mfhjr
0
273
Member Avatar for zoeysmiles

zoeysmiles, Hi and welcome to the Daniweb forums :). =============== Scan with [b]HiJackThis,[/b] then check(tick) the following, if present: [color=#9933cc][b] O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file) [/b][/color] [color=#9933cc][b] O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE [/b][/color] [color=#9933cc][b] O23 - Service: hpdj - HP - C:\DOCUME~1\Owner\LOCALS~1\Temp\hpdj.exe [/b][/color] Now, close …

Member Avatar for zoeysmiles
0
186

The End.