1,366 Posted Topics
Re: What exactly WAS the file you downloaded? Can you UNINSTALL it? That would be my first choice. 360 Share is a clue....peer-to-peer sharing can be very dangerous. Did you scan this file with your anti-virus program BEFORE installing it? | |
Re: [QUOTE]* By default it will install to C:\Program Files\Hijack This.[/QUOTE] C:\Program Files\Trend Micro\HiJack This | |
Re: Please try the following routine given in the MBA-M forum to see if you can get Malwarebytes to run. * Click on Start, click Run, and then type [B]devmgmt.msc[/B] and click OK * On the View menu click on [B]Show hidden devices[/B] * Browse to [B]Non-Plug[/B] and P[B]lay Drivers[/B] and … | |
Re: Don't know if this will work or not, but try it: Please try the following routine given in the MBA-M forum to see if you can get Malwarebytes to run. * Click on Start, click Run, and then type [B]devmgmt.msc[/B] and click OK * On the View menu click on … | |
Re: poster has another thread. says his problem is solved. [url]http://www.daniweb.com/forums/thread163964.html[/url] | |
Re: Hi kingston, welcome to daniweb. Unfortunately looks like infection is still there, something is anyway. First thing you need to do is TURN OFF that Spybot TeaTimer as it is known to interfere with some clean up procedures. To do this go into the program and Choose Mode, Advanced. When … | |
Re: Who told you to run combofix? ComboFix is [B]not [/B]a general purpose cleaning tool and should not be as such. ComboFix should only be used when asked by someone experienced in the use of this tool. Using this tool without supervision can cause problems with your computer, as you have … | |
Re: [QUOTE]I had run malware and it found most of the files. However i know which files to get rid of yet i'm not quite sure how to safely delete them.[/QUOTE] The way to safely delete them is by using the MBA-M program. If you mean by deleting them manually there … | |
Re: For further information concerning this thread please see this thread [url]http://www.daniweb.com/forums/thread163743.html[/url] | |
Re: This process that is running; C:\DOCUME~1\NATHAN~1\LOCALS~1\Temp\[B]csrssc.exe[/B] is your nasty file. It is a a variant of the Win32/TrojanDownloader.Small.CYF malware. Now if you can go into the Task Manager, look for that running and End the Process. I am not certain that it will end but try it. While you are … | |
Re: I would advise the java update be delayed until the combofix program is run and the log is posted here and interpreted and commented on. Judy | |
Re: [QUOTE]I downloaded ComboFix and disconected my ethernet cable, [/QUOTE] You don't need to disconnect from the internet. Reconnect and try combofix again. Judy | |
Re: We would prefer that you copy/paste logs rather than attach them. Since you are not running an anti-virus program and I see several entries for Bitcomet you are taking a real chance not running an anti-virus program. Please do the following; Please Download [B][URL="http://www.atribune.org/ccount/click.php?id=1"]ATF-Cleaner.exe [/URL][/B]by Atribune RUN [B]ATF-Cleaner.exe.[/B] -- Click … | |
Re: [QUOTE=cohen;762110]Alright, there are a few things that we can fix. ================= * Run Hijackthis and mark a check next the following: [LIST] [*][B][COLOR="Green"]O4 - Global Startup: SetPointII.lnk = ?[/COLOR][/B] [*][B][COLOR="Green"]O4 - Global Startup: Dell Network Assistant.lnk = ?[/COLOR][/B] [/LIST] * Then click [COLOR="Red"]Fix[/COLOR] * [COLOR="Red"]Reboot your computer[/COLOR] * Run Hijackthis … | |
Re: Here is the link and instructions for[B][URL="http://www.besttechie.net/tools/mbam-setup.exe"] Malwarebytes' Anti-Malware (MBA-M)[/URL][/B] as requested by jbennet Download it to your Desktop. * DoubleClick [B]mbam-setup.exe[/B] and follow the prompts to install MBA-M. [B]* Be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.[/B] * If … | |
Re: [QUOTE=cohen;761550]Hello, In your MBA-M log, it shows no action was taken. Pls run a full scan in MBA-M, remembering to update it before you scan, and [B][COLOR="Red"]remove everything[/COLOR][/B] it finds! Reboot the PC, post the MBA-M log as well a fresh hijackthis log. Thanks, Cohen[/QUOTE] Cohen please note slowbee's comment … | |
Re: Cohen, Chris has all ready has MBA-M so there shouldn't be a need to download it again, just maybe another attempt to update. However this file, Wjqs.exe, is was recognized as a trojan back in October I believe, so if you cannot get it to update try uninstalling it first … | |
Re: [QUOTE=byknisha08;687691]cant do anything. tried to run avg anti virus and done nothing and run combofx, sdfix, and smitfraudfix. maybe i am doing them wrong cus i am still getting the same problem and my windows id says virus alert keep getting all these virus infection pop up. need help asap … | |
Re: Avast is an excellent antivirus program. My feeling is the bundled "all in one" programs don't offer as much protection as several free standing programs. [B][URL="http://www.spybot.com/en/download/index.html"]Spybot[/URL][/B] is and excellent program for removing spyware, just DON'T use the TeaTimer portion of the program. [B][URL="http://www.download.com/Malwarebytes-Anti-Malware/3000-8022_4-10804572.html"]MBA-M[/URL][/B] is probably the top of the line … | |
Re: Your HJT log still shows sign of infection. You have disabled some auto starting programs with msconfig. Go back in there and re-enable all as we need to see what may be lurking in there. Reboot the computer. MBA-M should always be run in normal mode, this is the way … | |
Re: Hello and welcome to daniweb, The browser re-directs are not necessarily coolwebsearch but very likely the vundo infections, but we will see. Do the following: Please download [B][URL="http://www.download.com/Malwarebytes-Anti-Malware/3000-8022_4-10804572.html"]Malwarebytes' Anti-Malware (MBA-M)[/URL][/B] to your Desktop. * DoubleClick [B]mbam-setup.exe [/B]and follow the prompts to install MBA-M. [B] * Be sure a checkmark is … | |
Re: Hi Debbie, Haven't a clue why MBA-M gave a message you would have to pay, unless you mistakenly downloaded the pay for version, it will remove anything and everything it finds for free. Paid version gives scheduled automatic updating and scanning and a background protection. Uninstall the version you have … | |
Re: Please download[B][URL="http://www.besttechie.net/tools/mbam-setup.exe"] Malwarebytes' Anti-Malware (MBA-M)[/URL][/B] to your Desktop. * DoubleClick [B]mbam-setup.exe[/B] and follow the prompts to install MBA-M. [B]* Be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.[/B] * If an update is found, it will download and install the latest … | |
Re: Try clicking on this link [B][URL="http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe"]MBA-M[/URL][/B] which is the executable for MBA-M. Save it to the desk top. Close all programs and Windows on your computer, including this one. Double-click on the icon on your desktop named Download_mbam-setup.exe. This will start the installation of MBAM onto your computer. # DoubleClick … | |
Re: Hi nosfree, You need to begin with the steps shown [B]HERE[/B] Skipping step 2 as this is no longer used. Go to step 3 and continue on from there. When you have completed those steps, including the running and removal procedure noted with MBA-M and saving the log for posting … | |
Re: Sorry to say this Registry Patrol doesn't get very good word in a lot of places. Registry cleaner, editors....just not something I personally recommend, especially one which will "fix" some but not others without payment. Did the program offer backup of the registry prior to these fixes? | |
Re: [QUOTE=Lewis_UnderGrad;755331] Done some searching and apparently some software that might help are: 1. mbam 2. HJT Any ideas on hows these can help? Thanks. Lewis.[/QUOTE] Hi Lewis and welcome to daniweb. You are correct, these are the two programs you need to begin with. Follow the directions below exactly and … | |
Re: Very possible the server was busy at the time. If too many users are on at once the server could reach it's limits. Does this happen often? What were you doing at the time? How are you connected to the internet? | |
Re: Hi, you need to do the following; download[B][URL="http://www.download.com/Malwarebytes-Anti-Malware/3000-8022_4-10804572.html"] Malwarebytes' Anti-Malware (MBA-M)[/URL][/B] to your Desktop. * DoubleClick[B] mbam-setup.exe[/B] and follow the prompts to install MBA-M. [B] * Be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.[/B] * If an update is found, … | |
Re: Hi zbizzy, will be waiting for your logs. Be sure to allow MBA-M to remove items found. Judy | |
Re: For one thing you are running two anti-virus programs Avast and AVG8 on your computer. This is an absolute NO-NO. One of these MUST be UNINSTALLED. You also are running the beta program RUBotted from Trend Micro. While this is a legitimate program, from a well respected company it IS … | |
Re: [QUOTE]That seemed to fix it, a very simple fix too! Now I can get back to my fight with my NVIDIA card[/QUOTE] Sorry, but it couldn't have fixed it....the MBA-M log clearly shows.... [B][QUOTE]-> No action taken.[/QUOTE][/B] on each and every infected file. You need to update it again, always … | |
Re: Look in Event Viewer and see noted errors. This could give information on what is causing these crashes. Start, Control Panel, Administrative Tools, Event Viewer. Check Applications and also System logs. | |
Re: By the way, acrord32.exe is usually Acrobat Reader. Also, don't do anything else while running a scan like MBA-M, you want it to find everything it can and if interrupted it can miss something. | |
Re: Also, it appears as though the log posted from HJT was one collected while putting it through some sort of analyzer. Just run the scan, click save the log and then post it. It should come through without "editorial" comments as shown in the post: [QUOTE]/* Do not edit this … | |
Re: Btod9, you need to begin your own thread. The instructions from Cohen were for the thread starter, Needhelp21 | |
Re: Hi dragz and welcome to daniweb. We certainly need to see more than a combofix log. We need to see logs from [QUOTE]some of the steps I saw outlined in previous threads.[/QUOTE] We cannot advise until we do. We need to see an MBA-M log, if you did any online … | |
Re: You're back DaniWeb4Jim and obviously not following any advice when given. Back in September in this thread [B][URL="http://www.daniweb.com/forums/thread148421.html"]Lost All Programs List from Start Menu[/URL][/B] I gave you some information; [QUOTE]The [B]ABSOLUTE RULE[/B] is [B][COLOR="Red"]ONE[/COLOR][/B] antivirus program.....on a computer.[/QUOTE] You are doing a "bit" better just two months later, now you … | |
Re: [QUOTE]avenger, vundofix, and combofix [/QUOTE] All three very dangerous programs to use without supervision. Vundofix is a very specific tool for removing a very specific Trojan, that is all. If you have it on your system this tool "may" remove it. You should never run a tool without checking for … | |
Re: Please post a[B][URL="http://www.trendsecure.com/portal/en-US/tools/security_tools/hijackthis/download"] HiJackThis [/URL][/B]log. Judy | |
Re: Please download[B][URL="http://www.besttechie.net/tools/mbam-setup.exe"] Malwarebytes' Anti-Malware (MBA-M)[/URL][/B] to your Desktop. * DoubleClick [B]mbam-setup.exe[/B] and follow the prompts to install MBA-M. [B] * Be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.[/B] * If an update is found, it will download and install the … | |
Re: No need to BUY any. There are some great FREE ones out there that do a superb job. The two I use on a regular basis are [B][URL="http://www.download.com/Malwarebytes-Anti-Malware/3000-8022_4-10804572.html?part=dl-10804572&subj=dl&tag=button"]Malwarebytes' Anti-Malware. [/URL][/B] Download, install, UPDATE. Scan. Remove whatever it finds. Do this once a week at least and your computer will stay … | |
Re: Hi, First of all turn off that Adaware Services. It can interfere with fixes. Go to Start, Control Panel, Administrative Tools, Services. When that opens look for Ad-Aware 2007 Service (aawservice). Double click. When that opens click the Stop Button to turn it off. Then in the middle there you … | |
Re: Hi Yoda, welcome to Daniweb, [QUOTE=Yoda123;751282]Hmmm I wonder what that "try and decide" service by "unknown owner" listed at the end of my log there?![/QUOTE] That is related to the Acronis Backup Utility. Nothing wrong with it at all. The post you cited is[B] 2 1/2 years old[/B] and closed … | |
Re: First of all turn off both Spybot TeaTimer and AdAware Service. Both can interfere with any fixes done. To turn off Spybot TeaTimer open the program, choose Mode, Advanced, Then Tools. When Tools opens choose Resident. When Resident opens take the check mark OUT of TeaTimer. Close the program. To … | |
Re: Turn off uTorrent and Turn off Spybot TeaTimer, Windows Defender. Leave them off. Delete the MBA-M that you downloaded and try downloading it again. Try [B][URL="http://www.besttechie.net/tools/mbam-setup.exe"]HERE[/URL][/B] or [B][URL="http://www.download.com/Malwarebytes-Anti-Malware/3000-8022_4-10804572.html?part=dl-10804572&subj=dl&tag=button"]HERE[/URL][/B] Save it to the desktop. Close ALL unnecessary programs, including those noted above plus all browsers, mail programs, IM programs, games, etc. … | |
Re: This is a virus that passes around through social networking sites, usually the way you described. Once it gets on the system then it looks for cookies on the computer related to sites like that and changes them to add malicious sites to the users profile. As far as I … | |
Re: Hi kelbor sorry you have waited so long for a reply. First thing I see in your log that definitely will slow your computer is that you are running multiple anti-virus programs on the computer. I see AVG8, McAfee, some Symantec/Norton listings showing too, possibly from an old Norton program. … | |
Re: [B]Suzixus,[/B] you actually need to begin your OWN thread. Even though you may have the same problem no two computers are exactly alike and it is extremely difficult for a helper to work with two people and two different computers on the same thread. Start your OWN thread, and be … | |
Re: Great job and very efficient following of instructions. Just the kind of threads I love! [QUOTE]I ran ATF-Cleaner, except for Firefox files. I need to know if it's necessary to delete all those files? I also ran CCleaner. [/QUOTE] One program or the other is fine, but yes the ALL … |
The End.