4,383 Posted Topics

Member Avatar for KatrinM

Hi. First of all you need to update hijackthis to version 1.98.1 Run hijackthis & go to *Config\Misc Tools\Check for update on-line*. Remove 1.97 from the folder it is in & replace it with 1.98.1. (Put hijackthis into it's own folder) Please go [url=http://windowsupdate.microsoft.com/][u]here[/u][/url] & install ALL updates required for …

Member Avatar for crunchie
0
239
Member Avatar for infinite_stylz

First of all could you click Start>Settings>Control Panel>Add or Remove Programs and uninstall 'Window Search', 'Window Searching', 'Lop.com', 'LOP SEARCH', 'Browser Enhancer', or 'Ultimate Browser Enhancer' if listed. You may be given a code to insert, do so and reboot when done. - If not listed there, run this uninstaller: …

Member Avatar for crunchie
0
96
Member Avatar for Pat77

Please go [url=http://www.kaspersky.com/remoteviruschk.html][u]here[/u][/url] and have this file scanned. C:\WINDOWS\system32 [b]IBACFOBB.EXE[/b]

Member Avatar for caperjack
0
108
Member Avatar for jennifer*steph

[b]Download & instal [color=blue]Adaware[/color] from [url=http://www.computercops.biz/downloads-file-292.html][u]here[/u][/url][/b] & [color=red]update[/color] it before scanning. In settings under 'scanning,' have it set to 'scan within archives,' 'scan active processes,' 'scan registry,' 'deepscan registry' 'scan my IE Favourites for banned URL's,' 'scan my host's file.' In 'tweaks' under 'scanning engine' set it to 'unload recognised …

Member Avatar for crunchie
0
143
Member Avatar for Greenhills

I am not familiar with McAfee, but there probably is an option to configure the firewall to stealth those open ports. I run Sygate Professional & come up 100% stealth out of the box. From GRC; [url]http://www.grc.com/port_1024.htm[/url] [url]http://www.grc.com/port_135.htm[/url]

Member Avatar for crunchie
0
58
Member Avatar for jackoutlawz

Uninstall Kazaa & then run Kazaabegone from [url=http://www.computercops.biz/downloads-file-331.html][u]here.[/u][/url] to clear out the remnants. Clear out your Temporary internet files and other temp files. Go to Start > Settings > Control Panel >Internet Options. Under the General tab click the Delete temporary internet files, delete all Offline content as well. Clear …

Member Avatar for crunchie
0
174
Member Avatar for MJBolduc

Hi. First of all you need to update hijackthis to version 1.98.1 Run hijackthis & go to *Config\Misc Tools\Check for update on-line*. Remove 1.97 from the folder it is in & replace it with 1.98.1. Go to add/remove programs & uninstall *Virtumundo* if found. [b]Download LSPfix from [url=http://www.computercops.biz/downloads-file-334.html][u]here[/u][/url][/b] On the …

Member Avatar for crunchie
0
210
Member Avatar for Gunji

Hi. First of all you need to update hijackthis to version 1.98.1 Run hijackthis & go to *Config\Misc Tools\Check for update on-line*. Remove 1.97 from the folder it is in & replace it with 1.98.1. Could you click Start>Settings>Control Panel>Add or Remove Programs and uninstall 'Window Search', 'Window Searching', 'Lop.com', …

Member Avatar for crunchie
0
146
Member Avatar for cpcjones

O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - [url]http://software-dl.real.com/221b2b1...ip/RdxIE601.cab[/url] Only baddy that I can see. Try doing a checkdisk having it attemp to repair any errors & then do a defrag.

Member Avatar for cpcjones
0
177
Member Avatar for mandy101w

[b]Download LSPfix from [url=http://www.computercops.biz/downloads-file-334.html][u]here[/u][/url][/b] On the opening screen, click the "I know what I'm doing" checkbox. Check all instances of "lspak.dll" (and nothing else), and move them to the "Remove" pane. Then click Finish. [b]Unzip HJT into it's own permanent folder[/b] before doing anything in order for it to create …

Member Avatar for crunchie
0
294
Member Avatar for Garet-Jax

Uninstall *spydoctor* for the following reason; [url]http://www.spywarewarrior.com/rogue_anti-spyware.htm[/url] Try Adaware cloak. To use Ad-aware Cloak, save it to your system, and run the program before opening Ad-aware. Once Ad-aware Cloak opens, click "Activate Cloak" and then open Ad-aware and scan as normal. When you are done using Ad-aware, close Ad-aware Cloak. …

Member Avatar for crunchie
0
338
Member Avatar for Ohhhhhhhhhh

Hi. First of all you need to update hijackthis to version 1.98.1 Run hijackthis & go to *Config\Misc Tools\Check for update on-line*. Remove 1.97 from the folder it is in & replace it with 1.98.1. [b]Download & instal [color=blue]Adaware[/color] from [url=http://www.computercops.biz/downloads-file-292.html][u]here[/u][/url][/b] & [color=red]update[/color] it before scanning. In settings under 'scanning,' …

Member Avatar for crunchie
0
158
Member Avatar for quinkky

It's possible that your friend's computer is infected with something. The *data miner* cookies keep getting re-installed whenever you visit certain sites. To prevent it you can change your cookie options to allow you to decide which cookies can be stored & which ones not. Go to Internet Options\Privacy\Advanced & …

Member Avatar for crunchie
0
127
Member Avatar for RyanBoggs001

[b]Close all (browser) windows & rescan with hijackthis.[/b] When the scan is finished place a check in the box to the left of the following entries & click [color=red]'fix checked':[/color] O2 - BHO: (no name) - {E7F9591B-27AB-4959-992E-D7A4F2437DB4} - C:\WINDOWS\System32\bgpik.dll Download About:buster from [url]http://malwarebytes.biz/AboutBuster.zip[/url] and unzip it to your desktop. Click …

Member Avatar for crunchie
0
159
Member Avatar for tyl88

Download [url=http://securityresponse.symantec.com/avcenter/venc/data/w32.gaobot.removal.tool.html][u][b]this[/b][/u][/url] removal tool for the W32.Gaobot.AFJ worm. [b]Go [url=http://housecall.trendmicro.com/][u]here[/u][/url] for an on-line scan & set it to autoclean for you.[/b] [b]Try [URL=http://www.pandasoftware.com/activescan/com/activescan_principal.htm][u]this[/u][/URL] scan as well.[/b] Click Start>Settings>Control Panel>Add or Remove Programs and uninstall 'Window Search', 'Window Searching', 'Lop.com', 'LOP SEARCH', 'Browser Enhancer', or 'Ultimate Browser Enhancer' if listed. You …

Member Avatar for crunchie
0
129
Member Avatar for atky2004

Hi. First of all you need to update hijackthis to version 1.98. Run hijackthis & go to *Config\Misc Tools\Check for update on-line*. Remove 1.97 from the folder it is in & replace it with 1.98. Also, you need to read this thread; [url]http://www.daniweb.com/techtalkforums/thread7370.html[/url]

Member Avatar for crunchie
0
115
Member Avatar for spookfish

[b]Unzip HJT into it's own permanent folder[/b] before doing anything in order for it to create backups. [color=red](Not a temporary folder or directly on the desktop (in a folder on the desktop is fine) & not directly on your hard drive).[/color] [b]Close all (browser) windows & rescan with hijackthis.[/b] When …

Member Avatar for crunchie
0
248
Member Avatar for miamibahamas03

You can either use system restore to go back to a time before this hijack, or: [list=1][*]Make sure your settings allow you to view "Hidden files" & "hide protected operating system files" is unchecked. Open up any explorer windows and click on "Tools" => "Folder Options" => "View" and be …

Member Avatar for crunchie
0
158
Member Avatar for labrat

[b]First of all we have to remove Newdotnet,[/b] either from add/remove programs, or by going [url=http://www.newdotnet.com/#remove][u]here.[/u][/url] & scrolling down to the uninstall tool. [b]Close all (browser) windows & rescan with hijackthis.[/b] When the scan is finished place a check in the box to the left of the following entries & …

Member Avatar for crunchie
0
207
Member Avatar for Jippyone
Member Avatar for voluntary

If you are concerned, [b]Go [url=http://housecall.trendmicro.com/][u]here[/u][/url] for an on-line scan & set it to autoclean for you.[/b] [b]Try [URL=http://www.pandasoftware.com/activescan/com/activescan_principal.htm][u]this[/u][/URL] scan as well.[/b]

Member Avatar for crunchie
0
94
Member Avatar for F083153WM

Before you set spybot to ignore the DSO exploit, make sure you have [b]all[/b] the microsoft updates & patches installed. Try Adaware to clean up those others. If that does not work, you can post a hijackthis log. [b]Download & instal [color=blue]Adaware[/color] from [url=http://www.computercops.biz/downloads-file-292.html][u]here[/u][/url][/b] & [color=red]update[/color] it before scanning. In …

Member Avatar for crunchie
0
127
Member Avatar for Pryssant

[b]Go [url=http://housecall.trendmicro.com/][u]here[/u][/url] for an on-line scan & set it to autoclean for you.[/b] [b]Try [URL=http://www.pandasoftware.com/activescan/com/activescan_principal.htm][u]this[/u][/URL] scan as well.[/b] Fix this line with hijackthis, making sure that [b]all[/b] other windows are closed. O4 - HKLM\..\Run: [RunDLL] rundll32.exe "C:\WINDOWS\Downloaded Program Files\bridge.dll",Load Post another log as there [b]will[/b] be more to do.

Member Avatar for crunchie
0
126
Member Avatar for t0x

Close all (browser) windows & have HJT fix these entries= O4 - HKLM\..\Run: [RunDLL] rundll32.exe "C:\WINDOWS\System32\bridge.dll",Load Do you have xfire on your computer?

Member Avatar for crunchie
0
289
Member Avatar for Meek

[b]Download & instal [color=blue]Adaware[/color] from [url=http://www.computercops.biz/downloads-file-292.html][u]here[/u][/url][/b] & [color=red]update[/color] it before scanning. In settings under 'scanning,' have it set to 'scan within archives,' 'scan active processes,' 'scan registry,' 'deepscan registry' 'scan my IE Favourites for banned URL's,' 'scan my host's file.' In 'tweaks' under 'scanning engine' set it to 'unload recognised …

Member Avatar for crunchie
0
83
Member Avatar for eikrem

First of all could you click Start>Settings>Control Panel>Add or Remove Programs and uninstall 'Window Search', 'Window Searching', 'Lop.com', 'LOP SEARCH', 'Browser Enhancer', or 'Ultimate Browser Enhancer' if listed. You may be given a code to insert, do so and reboot when done. Then you really should post a log that …

Member Avatar for crunchie
0
190
Member Avatar for Xero

Opera will not be the cause of it, but if you want to rid it from add/remove do this. Before manually editing the registry always back it up. On Windows ME and XP creating a Restore Point will do. Click Start > Run > Type or copy & paste regedit. …

Member Avatar for crunchie
0
117
Member Avatar for nicomc

[b]Close all (browser) windows & rescan with hijackthis.[/b] When the scan is finished place a check in the box to the left of the following entries & click [color=red]'fix checked':[/color] O2 - BHO: (no name) - {83DD6F6C-EE6A-F78B-5F28-FAB031824F81} - C:\WINDOWS\atlkz.dll O4 - HKLM\..\Run: [iezd.exe] C:\WINDOWS\iezd.exe O4 - HKLM\..\RunOnce: [appgg.exe] C:\WINDOWS\system32\appgg.exe Download …

Member Avatar for crunchie
0
141
Member Avatar for andy_s

Unfortunately this forum is not authorized in the use of FindnFix. Can you try this instead. Download About:buster from [url]http://malwarebytes.biz/AboutBuster.zip[/url] and unzip it to your desktop. [b]Download & instal [color=blue]Adaware[/color] from [url=http://www.computercops.biz/downloads-file-292.html][u]here[/u][/url][/b] & [color=red]update[/color] it before scanning. In settings under 'scanning,' have it set to 'scan within archives,' 'scan active …

Member Avatar for andy_s
0
250
Member Avatar for bigfish

I have moved your post to it's own thread. Please do not tag on to the end of other members threads.

Member Avatar for crunchie
0
114
Member Avatar for lewk

Does the program actually remove them, or just disguise them?? I am trying to get more info on it. If it only prevents the running of these programs it's not much cop. You also have to pay for it.

Member Avatar for caperjack
0
529
Member Avatar for bqb2hi
Member Avatar for Bluebird1111
Member Avatar for JEP

I have no idea what operating system, what IE version or what hijackthis version you are using as you have cut off the top of the log. Please include it in your next post. [b]Close all (browser) windows & rescan with hijackthis.[/b] When the scan is finished place a check …

Member Avatar for crunchie
0
161
Member Avatar for caperjack

This what you are after? Download: "StartDreck", from here: [url]http://www.niksoft.at/download/startdreck.htm[/url] Unzip to its own folder and start the program, Press 'Config' Press 'Unmark All' Check the following boxes only: Registry -> Run Keys System/drivers> Running processes Press 'Ok' Press 'Save' and select the location to save the log file (default …

Member Avatar for caperjack
0
111
Member Avatar for rafe

Download CWShredder from [url]http://209.133.47.200/~merijn/files/CWShredder.exe[/url] & run it. Select the fix button & it will get rid of everything related to CoolWebSearch. Reboot after doing this & post another log please.

Member Avatar for mykooo
0
510
Member Avatar for jfish
Member Avatar for robinrofkar

[b]Unzip HJT into it's own permanent folder[/b] before doing anything in order for it to create backups. [color=red](Not a temporary folder or directly on the desktop (in a folder on the desktop is fine) & not directly on your hard drive).[/color] [b]Close all (browser) windows & rescan with hijackthis.[/b] When …

Member Avatar for crunchie
0
142
Member Avatar for rami29
Member Avatar for Turnip

Cannot see anything bad in your log. Do you have everything set to start in Msconfig? If not, do so, then reboot & post another log. Also, there is a new version of hijackthis out now so you need to update before your next log.

Member Avatar for crunchie
0
138
Member Avatar for wdw101
Member Avatar for sibylbanks
Member Avatar for travman

If you do not have Adaware, then please download it but [b]not[/b] run it yet. [b]Download & instal [color=blue]Adaware[/color] from [url=http://www.computercops.biz/downloads-file-292.html][u]here[/u][/url][/b] & [color=red]update[/color] it. In settings under 'scanning,' have it set to 'scan within archives,' 'scan active processes,' 'scan registry,' 'deepscan registry' 'scan my IE Favourites for banned URL's,' 'scan …

Member Avatar for crunchie
0
773
Member Avatar for homecostablanca

[b]Unzip HJT into it's own permanent folder[/b] before doing anything in order for it to create backups. [color=red](Not a temporary folder or directly on the desktop (in a folder on the desktop is fine) & not directly on your hard drive).[/color] [b]Close all (browser) windows & rescan with hijackthis.[/b] When …

Member Avatar for crunchie
0
389
Member Avatar for Magickavulord

Do this first: [b]Go [url=http://housecall.trendmicro.com/][u]here[/u][/url] for an on-line scan & set it to autoclean for you.[/b] [b]Try [URL=http://www.pandasoftware.com/activescan/com/activescan_principal.htm][u]this[/u][/URL] scan as well.[/b] [b]Download & instal [color=blue]Adaware[/color] from [url=http://www.computercops.biz/downloads-file-292.html][u]here[/u][/url][/b] & [color=red]update[/color] it before scanning. In settings under 'scanning,' have it set to 'scan within archives,' 'scan active processes,' 'scan registry,' 'deepscan registry' …

Member Avatar for crunchie
0
119
Member Avatar for rafe

Hope you don't mind caperjack :) . Just a bit of housekeeping now. [b]Close all (browser) windows & rescan with hijackthis.[/b] When the scan is finished place a check in the box to the left of the following entries & click [color=red]'fix checked':[/color] R3 - Default URLSearchHook is missing O3 …

Member Avatar for caperjack
0
191
Member Avatar for buddhabash

Download and install APM from: [url]http://www.diamondcs.com.au/index.php?page=apm[/url] In the upper window of APM select explorer.exe Select Unload DLL and click OK on the prompts that follow.

Member Avatar for crunchie
0
153
Member Avatar for lukepharris

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\User\LOCALS~1\Temp\sp.html R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\User\LOCALS~1\Temp\sp.html R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\User\LOCALS~1\Temp\sp.html R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\User\LOCALS~1\Temp\sp.html R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\User\LOCALS~1\Temp\sp.html R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\User\LOCALS~1\Temp\sp.html R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP …

Member Avatar for crunchie
0
92
Member Avatar for grafter01

Also, [b]Download & instal [color=blue]Adaware[/color] from [url=http://www.computercops.biz/downloads-file-292.html][u]here[/u][/url][/b] & [color=red]update[/color] it before scanning. In settings under 'scanning,' have it set to 'scan within archives,' 'scan active processes,' 'scan registry,' 'deepscan registry' 'scan my IE Favourites for banned URL's,' 'scan my host's file.' In 'tweaks' under 'scanning engine' set it to 'unload …

Member Avatar for grafter01
0
228
Member Avatar for ohheck3

At the top of this forum is a notice telling members to post their hijackthis logs in the security forum!! Moving out now so hang on to your breakfast............................................................................. [b]Unzip HJT into it's own permanent folder[/b] before doing anything in order for it to create backups. [color=red](Not a temporary folder …

Member Avatar for crunchie
0
68

The End.