4,383 Posted Topics

Member Avatar for sashmage1

Please download [url=http://www.atribune.org/ccount/click.php?id=7]Look2Me-Destroyer.exe[/url] to your desktop. Close all windows before continuing. Double-click [color=blue]Look2Me-Destroyer.exe[/color] to run it. Put a check next to [color=blue]Run this program as a task.[/color] You will receive a message saying Look2Me-Destroyer will close and re-open in approximately 10 seconds. Click [color=blue]OK.[/color] When Look2Me-Destroyer re-opens, click the [color=blue]Scan …

Member Avatar for tayspen
0
254
Member Avatar for Hibeko

Hi and welcome to Daniweb :). Can you please do the following. =============== Run [b]HiJackThis[/b] then: 1. Click "[b][i]Open the Misc Tools Section[/i][/b]" 2. Click "[b][i]Open Process manager[/i][/b]" - Next, while holding down the [b]CTRL[/b] key, locate ([i]if present[/i]) and click on ([i]highlight[/i]) each of the following: [b][color=#000000]C:\WINDOWS\system32\[/color][color=#ff0000]atmclk.exe[/color][/b] Now double-check …

Member Avatar for crunchie
0
175
Member Avatar for comp12345

You need to expand on what exactly happens when you attempt to power up the computer. Do the fans start? Can you hear the hard drive going? Do the power lights come on at the front of the computer? Does the power light on the monitor come on? Did you …

Member Avatar for crunchie
0
295
Member Avatar for Kiwicolor

Hi and welcome to Daniweb :). Can you please do the following. =============== The header for [b]HiJackThis[/b] is very important: It helps to determine what steps might need to be taken to better secure your system, and provide more efficient cleanup procedures. For example, some files, which are standard on …

Member Avatar for crunchie
0
232
Member Avatar for eltommyo
Member Avatar for caperjack
0
517
Member Avatar for Great Hayz

Hi and welcome to Daniweb :). [b]Please read these instructions carefully and print them out! Be sure to follow ALL instructions![/b] Download [url=http://noahdfear.geekstogo.com/click%20counter/click.php?id=1][color=#3333FF]smitRem.zip[/color][/url] and save the file to your desktop. Can also be downloaded from here; [url]http://www.downloads.subratam.org/smitRem.exe[/url] Right click on the file and extract it to it's own [b]folder[/b] on …

Member Avatar for crunchie
0
86
Member Avatar for myswitjenn

The last hijackthis log you posted is the exact same as the original one with the exact same time :D. Please reboot your system and rescan with hijackthis and post that log. Will make it a lot easier for those who help :).

Member Avatar for crunchie
0
362
Member Avatar for pistolsnipe16

Disable Windows Defender and make certain it is not running before doing the following; Run the PurityScan [url=http://www.purityscan.com/uninstall.html][u]uninstaller.[/u][/url] = Download [url=http://www.ccleaner.com/ccdownload.asp]CCleaner[/url] and install, then run it. [list=1] [*][b]Uncheck[/b] "Cookies" under "Internet Explorer". [*]Click on [b]Run Cleaner[/b] in the lower right-hand corner. This can take quite a while to run. [*]Close …

Member Avatar for crunchie
0
253
Member Avatar for lolper

Can you please do the following. =============== Please visit at least two of the following sites for an online virus scan: BitDefender Free Online Virus Scan [url]http://www.bitdefender.com/scan/licence.php[/url] Make sure you tick [b]AutoClean[/b] under [b]Scan Options.[/b] Panda ActiveScan [url]http://www.pandasoftware.com/activescan/com/activescan_principal.htm[/url] Make sure you tick [b]Disinfect automatically[/b] under [b]Scan Options.[/b] Housecall at TrendMicro …

Member Avatar for tayspen
0
2K
Member Avatar for b_alexander

Hi and welcome to Daniweb :). Can you please do the following. =============== Before we begin, let's move [b]HiJackThis[/b] to it's own folder; like [b]c:\HJT[/b]. When we're done '[i]cleaning[/i]' off your system, we're going to '[i]flush[/i]' the temporary folders which, with [b]HiJackThis[/b] [color=#ff0000][i]in it's current location, we'll lose both the …

Member Avatar for crunchie
0
144
Member Avatar for Jake Boone

Try the following also; Download the [url=http://www.funkytoad.com/download/hoster.zip][color=blue]Hoster.[/color][/url] Run it and press "Restore Original Hosts" and press "OK". Exit Program. Note that if you have a custom host file, this will remove it. You can edit the host file with this program too.

Member Avatar for Jake Boone
0
388
Member Avatar for carolraydon

I'm not in the US either so I can only guess that for some reason, rr and others have added those particular references to their spamblocker or some such. Perhaps you should try contacting them through hotmail or other internet based email client and let them know what is happening …

Member Avatar for 'Stein
0
223
Member Avatar for Tinashka

You could try running Adaware in safe mode if you are still having problems, or download Adaware cloak to see if that helps. To use Ad-aware Cloak, save it to your system, and run the program before opening Ad-aware. Once Ad-aware Cloak opens, click "Activate Cloak" and then open Ad-aware …

Member Avatar for 'Stein
0
843
Member Avatar for joyleigh
Member Avatar for crunchie
0
538
Member Avatar for ruseox

ruseox, Hi and welcome to the Daniweb forums :). =============== Scan with [b]HiJackThis,[/b] then check(tick) the following, if present: [color=#9933cc][b] O2 - BHO: winapi32.MyBHO - {62E2E094-F989-48C6-B947-6E79DA2294F9} - C:\WINDOWS\system32\winapi32.dll [/b][/color] Now, close [b]all[/b] instances of Internet Explorer and any other windows you have open except [b]HiJackThis[/b], click "[b][i]Fix checked[/i][/b]". =============== Locate …

Member Avatar for crunchie
0
232
Member Avatar for saihaghim

saihaghim, Hi and welcome to the Daniweb forums :). == Please go to [url=http://virusscan.jotti.org/][u]Jotti's[/u][/url] and have this file scanned. Post the results back here. C:\WINDOWS\system32\aimplugin.exe =============== Let's look for, and delete, any program segments ([i]prefetches[/i]) that might be present, and are associated with the '[i]problems[/i]' we're trying to remove from …

Member Avatar for DMR
0
345
Member Avatar for tolip

Can you please do the following. =============== Scan with [b]HiJackThis,[/b] then check(tick) the following, if present: [color=#9933cc][b] R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = [url]http://www.dell4me.com/myway[/url] [/b][/color] [color=#9933cc][b] R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = [url]http://www.dell4me.com/myway[/url] [/b][/color] [color=#9933cc][b] R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = [url]http://www.dell4me.com/myway[/url] [/b][/color] [color=#9933cc][b] R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = [url]http://www.dell4me.com/myway[/url] [/b][/color] …

Member Avatar for DMR
0
181
Member Avatar for wolfmaster
Member Avatar for Brandon-J
0
774
Member Avatar for bloodxfight

[b]Go [url=http://housecall.trendmicro.com/][u]here[/u][/url] to TrendMicro for an on-line scan & set it to autoclean for you. Try [URL=http://www.pandasoftware.com/activescan/com/activescan_principal.htm][u]this[/u][/URL] scan at Panda as well.[/b] [b]Download [color=blue]HijackThis[/color] from [url=http://www.merijn.org/files/hijackthis_sfx.exe][u]here[/u][/url][/b] & it will install into it's own, permanent folder. If you have anything disabled in MsConfig, please re-enable it/them and reboot. Start HJT & …

Member Avatar for tayspen
0
247
Member Avatar for alexkay

Have hijackthis fix this line; O20 - Winlogon Notify: welcome - C:\WINDOWS\system32\s6rslg9716.dll (file missing) Sometimes qoologic comes with this infection, so we will get you to run a couple more tools to ensure you are clean. Go [url=http://castlecops.com/zx/Zupe/Find%20It%20NT-2K-XP.zip]here[/url] and download [color=blue]FindIt.zip[/color] to your Desktop, unzip it and open the FindIt …

Member Avatar for DMR
0
781
Member Avatar for Mystic1
Member Avatar for moraira73

Go to Start>Run and type msconfig. Press enter. When msconfig opens, click the Launch System Restore Button. On the next page, click the System Restore Settings link on the left. Check the box labelled [b]'Turn off System restore'.[/b] Reboot. Go back in and Turn System Restore Back on. A new …

Member Avatar for moraira73
0
159
Member Avatar for amdm55

Run hijackthis again, save the scan to txt file when finished then open the txt file, copy the entire contents & paste that info here.

Member Avatar for DMR
0
749
Member Avatar for Tom Wade

[b]Download [color=blue]HijackThis[/color] [b][color=red]self-extracting[/color][/b] zip version from [url=http://www.thespykiller.co.uk/files/hijackthis_sfx.exe][u]here.[/u][/url][/b] Once downloaded, double click on the file & it will install into it's own, permanent folder. Start HJT & press the "Do a system scan and save a log file" button. When the scan is finished a window will pop up giving you …

Member Avatar for tayspen
0
442
Member Avatar for Zingar

You have the horse server infection Zingar. Can you do the following please. First, download HSFix from [url=http://www.atribune.org/downloads/HSFix.zip]here.[/url] After it is downloaded, create a new folder on your desktop called "HSFix" and extract all the files into the newly created folder. [b]Reboot into safe mode[/b] following the instructions [url=http://www.xtra.co.nz/help/0,,6156-1377929,00.html][u]here[/u][/url] Locate …

Member Avatar for DMR
0
662
Member Avatar for >shadow<

7.9 over the time I have been here. Same as DMR, sometimes i do not post on a given day and sometimes I will post ~10 times :).

Member Avatar for anupam_smart
0
459
Member Avatar for dlh6213

tris3u. Am splitting your post out to your own thread. Please do not piggy back other members threads :). You will better recieve help by starting your own. Thank you for understanding.

Member Avatar for navyjax2
5
2K
Member Avatar for Firedad

If you have spybot, then spywareblaster is a must. You can get it from a link within Spybot when you go to the 'immunise' part. The link is to javacools where you can download spywareblaster. Once installed this needs to be updated also. The good thing is that when you …

Member Avatar for jasonchen
0
240
Member Avatar for Kansacity

Hi and welcome to Daniweb forums :). [b]Download [color=blue]HijackThis[/color] [b][color=red]self-extracting[/color][/b] zip version from [url=http://www.malwareremoval.com/downloads.html][u]here.[/u][/url][/b] Once downloaded, double click on the file & it will install into it's own, permanent folder. Start HJT & press the "Do a system scan and save a log file" button. When the scan is finished …

Member Avatar for D3m3nt3d
0
473
Member Avatar for hruzam

[b]Please read these instructions carefully and print them out! Be sure to follow ALL instructions![/b] Download [url=http://noahdfear.geekstogo.com/click%20counter/click.php?id=1][color=#3333FF]smitRem.zip[/color][/url] and save the file to your desktop. Can also be downloaded from here; [url]http://www.downloads.subratam.org/smitRem.exe[/url] Right click on the file and extract it to it's own [b]folder[/b] on the desktop. Place a shortcut to …

Member Avatar for hruzam
0
308
Member Avatar for drunknmunky

You have the peper trojan. Download the removal tool from [url]http://www.memorywatcher.com/uninst.exe[/url] & let it do it's thing. There will be no dialogue. Note that you must be online when you run the tool for it to be effective. You must then reboot your computer. Download & instal Adaware from [url]http://majorgeeks.com/download.php?det=506[/url] …

Member Avatar for DMR
0
2K
Member Avatar for Stack Overflow

Stack Overflow, Hi and welcome to the Daniweb forums :). (Sorry, I had to do that :D) - Download, then unzip to "[b]C:\HJT[/b]", the newest version of [url=http://www.spywareinfo.com/~merijn/files/hijackthis.zip]HiJackThis[/url]; [i]version 1.99.1[/i]. Then repost your log, either now, or after following the steps in the solution ([i]if provided in this post[/i]). [color=#ff0000][i]This …

Member Avatar for cbbcisace
0
445
Member Avatar for shane'r69
Member Avatar for chadwickstein
Member Avatar for saw1985

Hi and welcome to Daniweb forums :). Can you please do the following; Please visit at least two of the following sites for an online virus scan: BitDefender Free Online Virus Scan [url]http://www.bitdefender.com/scan/licence.php[/url] Make sure you tick [b]AutoClean[/b] under [b]Scan Options.[/b] Panda ActiveScan [url]http://www.pandasoftware.com/activescan/com/activescan_principal.htm[/url] Make sure you tick [b]Disinfect automatically[/b] …

Member Avatar for crunchie
0
167
Member Avatar for Nvis321

Hi and welcome to Daniweb forums :). Can you please do the following. =============== Open a [b]command prompt[/b] by going to the start menu and then select 'Run'. In the box that pops up type in 'cmd'. The command prompt will open. OR You can go to Start -> Programs …

Member Avatar for crunchie
0
168
Member Avatar for TKSS
Member Avatar for sraquel

Hi and welcome to Daniweb :). You are running hijackthis from a temporary folder. You need to create a new folder in a permanent directory of your choice, (a folder on the desktop is fine) name the new folder [b]hijackthis[/b] and move or unzip hijackthis.exe into that folder. == Go …

Member Avatar for crunchie
0
197
Member Avatar for damnspyware

Hi. First of all you need to update hijackthis to version 1.99.1. Run hijackthis & go to *Config\Misc Tools\Check for update on-line*. If the site is down, go [url=http://www.malwareremoval.com/downloads.html][u]here[/u][/url] and download the [b]selfextracting[/b] zip version. Remove the old version by opening the program, going to config\misc tools, then uninstall & …

Member Avatar for crunchie
0
293
Member Avatar for MonOve
Member Avatar for crazyjaxy
Member Avatar for juliaouchmynose

Hi and welcome to Daniweb forums :). I recommend that you change any and all passwords that you have used on your PC after we clean up the problem. Can you please do the following. =============== When we're done cleaning off your system, I'd [b]recommend[/b] that you install all the …

Member Avatar for crunchie
0
154
Member Avatar for Ny4windserboy02

Can you please do the following. =============== Go to [b]Add/Remove programs[/b] and remove(uninstall) the following, if present: [b][color=#ff0000]EZula Toptext[/color][/b] [b][color=#ff0000]SurfSideKick[/color][/b] [b][color=#ff0000]TSCash[/color][/b] The above could appear anywhere within the entry. Be careful not to remove any [i]personal[/i] or [i]system[/i] software. =============== Let's look for, and delete, any program segments ([i]prefetches[/i]) that …

Member Avatar for crunchie
0
391
Member Avatar for weller

weller. Hi and welcome to Daniweb forums :). - Go to [b]Add/Remove programs[/b] and remove(uninstall) the following, if present: [b][color=#ff0000]P2P Networking[/color][/b] The above could appear anywhere within the entry. Be careful not to remove any [i]personal[/i] or [i]system[/i] software. =============== Run [b]HiJackThis,[/b] click "[b][i]Scan[/i][/b]", then check(tick) the following, if present: …

Member Avatar for DMR
0
411
Member Avatar for Alexido

Alexido, Hi and welcome to the Daniweb forums :). =============== Let's look for, and delete, any program segments ([i]prefetches[/i]) that might be present, and are associated with the '[i]problems[/i]' we're trying to remove from your PC. To do this, let's: 1) Click "[b][i]Start | Search[/i][/b]", then search for each of …

Member Avatar for crunchie
0
237
Member Avatar for kwisj

Hi and welcome to Daniweb forums :). You have been bitten by Smitfraud. [b]Please read these instructions carefully and print them out! Be sure to follow ALL instructions![/b] Download [url=http://noahdfear.geekstogo.com/click%20counter/click.php?id=1][color=#3333FF]smitRem.zip[/color][/url] and save the file to your desktop. Can also be downloaded from here; [url]http://www.downloads.subratam.org/smitRem.exe[/url] Right click on the file and …

Member Avatar for crunchie
0
219
Member Avatar for colliewobble

Can you please do the following. =============== Scan with [b]HiJackThis,[/b] then check(tick) the following, if present: [color=#9933cc][b] R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = [/b][/color] [color=#9933cc][b] R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = [/b][/color] [color=#9933cc][b] O2 - BHO: (no name) - {C5AF2622-8C75-4dfb-9693-23AB7686A456} - (no file) [/b][/color] Now, close [b]all[/b] instances of Internet Explorer and …

Member Avatar for crunchie
0
150
Member Avatar for PhilParle233

Hi and welcome to Daniweb forums :). Please download [url=http://www.atribune.org/ccount/click.php?id=4][b][color=red]VundoFix.exe[/color][/b][/url] to your desktop.[list] [*]Double-click [b]VundoFix.exe[/b] to run it. [*]Click the [b]Scan for Vundo[/b] button. [*]Once it's done scanning, click the [b]Remove Vundo[/b] button. [*]You will receive a prompt asking if you want to remove the files, click [b]YES[/b] [*]Once you …

Member Avatar for crunchie
0
138
Member Avatar for dbl03

Download L2mfix from one of these two locations: [url]http://www.atribune.org/downloads/l2mfix.exe[/url] [url]http://www.downloads.subratam.org/l2mfix.exe[/url] Save the file to your desktop and double click [B]l2mfix.exe[/B]. Click the [B]Install[/B] button to extract the files and follow the prompts, then open the newly added l2mfix folder on your desktop. Double click [B]l2mfix.bat[/B] and select option #[B]1[/B] for …

Member Avatar for crunchie
0
130
Member Avatar for codexp3

Can you please do the following. =============== Before we begin, let's move [b]HiJackThis[/b] to it's own folder; like [b]c:\HJT[/b]. When we're done '[i]cleaning[/i]' off your system, we're going to '[i]flush[/i]' the temporary folders which, with [b]HiJackThis[/b] [color=#ff0000][i]in it's current location, we'll lose both the program and the backups it creates. …

Member Avatar for crunchie
0
249

The End.