2,042 Posted Topics
Re: I don't know what discs you have with your machine, but first you need to change the boot order - early on in POST hit F10, or maybe Del, and change the order so that CD boot is first...[if HD boot is first your sys will not search any further]. … | |
Re: ==download hijackthis: [url]http://216.180.233.162/~merijn/files/HijackThis.exe[/url] -install it to a new folder alongside your program files. Remove the Beta. For a start you have a vundo infection... so just in case something else is hidden would you rename hijackthis.exe to.. umm... imabunny.exe for the next scan, please? Please download VundoFix.exe to your desktop … | |
Re: Wow.... a great collection of malware. Are you serious that Adaware did not remove some of this??? Ri-ight... Don't try a Repair with all this bad gear, you will face certain disappointment. In fact, a reinstall is called for.... but it is fixable without that if you wish to try … | |
Re: I cannot leave you swinging in the breeze like this..... but be WARNED!! Windows 98 came out before I was born - I know nothing about it; I don't think I am suggesting below that you kill some vital components, but I can't be located if I have!! The dll's … | |
Re: ..remove the startup entry, then delete it in safe mode. | |
Re: couldn't you just start up in the C: volume and then simply delete all the windows OS folders n files in the second volume? That would leave your other stuff untouched, wouldn't it? [I've never tried it... :)] Last, or other, step would be to cut the last line from … | |
Re: that is .dmp file that you zipped up. how to read that?? | |
Re: um. ummmm. we talking IE? isn't this a setting that the web page maker does? in opera it is a setting you can make so that a link will open a new page in the browser. but in IE it is up to the page designer. I think. easily wrong … | |
Re: ...may i inquire as to why \windows is shown as \windows.0 ? Do you have two XP operating systems in your C:\ partition by any chance? Be nice to know that b4 we proceed; there is a swag of bugs in there.. :). To answer that question easily, do this: … | |
Re: Download hijackthis: [url]http://216.180.233.162/~merijn/files/HijackThis.exe[/url] -install it to a new folder alongside your program files. -in that folder start HijackThis by dclicking the .exe; now close ALL other applications and any open windows including the explorer window containing HijackThis. -Click the Scan and Save a Logfile button. Post the log here. Someone … | |
Re: Fix these: O1 - Hosts: 209.190.85.230 maplesea.com O2 - BHO: Big Fish Games Toolbar - {4E7BD74F-2B8D-469E-86BD-FD60BB9AAE3A} - (no file) O3 - Toolbar: Big Fish Games Toolbar - {4E7BD74F-2B8D-469E-86BD-FD60BB9AAE3A} - (no file) Now, if you go Start, run and type: control -does that give you the control panel in some form? … | |
Re: I don't like to be pedantic but for your next posts, especially those with logs, please turn OFF wordwrap in notepad. Also the full hijackthis header is necessary [with version]. First off, and very important it is, you must decide which resident AV you wish to keep and uninstall the … | |
Re: ...for unravelling that log format you owe me a beer. Go into safe mode cos I would like you to check if you still have this file: C:\Windows\system32\csrss.exe [Either go Control panel > folder options OR in an explorer window > tools>folder options; then view tab, and -press Show hidden … | |
Re: xp pro? and you are not an administrator? then you cannot change permissions unless you are the owner of that file or folder. Try safe mode and the system administrator [you need the password, and it is by default blank ie Enter...] ==To restart your computer in Safe Mode:- press … | |
Re: For a start an anivirus pgm isn't really dragging your sys down, is it? Get one. May i suggest AVG FRE or AVIRA? Are you running a firewall? Or a spyware blocker? But BEFORE you go installing those, please do these things:- ===Download this temp file cleaner from [url]http://www.atribune.org/ccount/click.php?id=1[/url] --click … | |
Re: a dearth of info there, jez. for a start you could try diskcleanup and defrag from accessories > system tools [i'm just guessing that you may be running out of disk space - if you are, remove some unused stuff, or the junk ]. | |
Re: For a start, go CP > add/remove pgms and uninstall MyWebSearch, MyFunProducts, MyWayxxxxxx, etc, and ViewPoint. Go to pgm files and delete the folders for the above. Start hijackthis, do a Scan Only and place checkmarks for fixing against the entries listed below, and press Fix Checked. C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe … | |
Re: Before you run AVG AS it is nice to run a cleaner first to remove the cookies which clutter the AVG log. Anyway, to give us a quick glance at the state of your sys, would you pls do this... HiJackThis ===hijackthis: [url]http://216.180.233.162/~merijn/files/HijackThis.exe[/url] -install it to a new folder alongside … | |
Re: Nope. For a fresh copy of say, xp home, installed on a certain make and model computer with certain hardware with certain drivers with certain HD configuration and fully formatted with no other apps or files and no changes to any settings then just possibly you could compare the registries... … | |
Re: ...i see that the O20 entry persists - with that there the dll will start even in safemode... is that key's data value for AppInit_DLLs being regenerated if you delete it? Go into your registry and delete the value for this key name: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows Select AppInit_DLLs in the right … | |
Re: both methods remove the startup entries from your puter registry, kid, an that's it.. the software behind the entries remains; all msconfig asks is that you confirm the change on your next restart [asks in a slightly forbidding way.. :)] | |
Re: hello, umm, not quite the same problems... well the causes are different - all your internet traffic is going via an office downtown Kiev. Ukraine.They monitor your traffic for tasty stuff and then pass it on, sometimes even to the correct web addy. Let's cut em outta the loop. Now … | |
Re: You should not have a C:\explorer.exe file - it normally resides in C:\Windows\. To enable us to help you get hijackthis: [url]http://216.180.233.162/~merijn/files/HijackThis.exe[/url] -install it to a new folder alongside your program files. -in that folder start HijackThis by dclicking the .exe; now close ALL other applications and any open windows … | |
Re: For a start would you please do these things? ==Start Hijackthis again and do a Scan Only. Place a checkmark against this entry for fixing, and press Fix Checked: O2 - BHO: Info cache - {385AB8C6-FB22-4D17-8834-064E2BA0A6F0} - C:\Documents and Settings\All Users\Application Data\Microsoft\PCTools\pctools.dll ==Download this file: http://www.techsupportforum.com/sectools/sUBs/ComboFix.exe ...or from here: http://download.bleepingcomputer.com/sUBs/ComboFix.exe … | |
Re: uninstall AIM and get an update. That msg indicates a programming flaw - only bad scripting allows buffer overruns on user input. | |
Re: To save myself a lot of typing time i'll just put this in. you may have tried it; you don't say what you HAVE tried... to save everyone thinking you could post what you did... .....if you have the XP install cd then in that run window type sfc /scannow … | |
Re: Ow. Try checking your drivers for the burner, Jessykah. Go start > run, type devmgt.msc and enter. Expand the cd/dvd rom drive entry, dclick the drive and then select driver tab. Update driver, Yes this time only.... and so on. Now you have options - you can accept the M$ … | |
Re: Well, yeah, F6, that's how it goes with Sata drives. But you said no working floppy available, n i know that windows will only read from a floppy at that stage, apart from the install CD, of course. So obviously you can slipstream the Sata drivers onto a cd along … | |
Re: Yep, that will work [the name in inverted commas is the name you will see on the boot menu: change it to suit]; you can also [i know you have the cd] start recovery console and type: bootcfg /rebuild -windows will scan the volumes looking for installations; it will ask … | |
Re: And lighten the load by going to CP > add/remove pgms and uninstalling any Viewpoint entries that you see. Next, still in safe mode, with HT do a scan Only and check the following for fixing, and press Fix Checked: O8 - Extra context menu item: &Viewpoint Search - res://C:\Program … | |
Re: AVG Fre works for me. Others swear by avast home edition. You choose. | |
Re: Dragonlover, I don't think Crunchie will mind me picking up this thread cos he is going out for a couple of days. ==First thing, I know you already ran fixwareout before you made your first post [that piggyback one]; if you still have the original log file [report.txt] rename it … | |
Re: Crazy, I run AVG FRE [AS], Zonealarm, Spywareblaster. That's it. And had only one case of spyware about two years ago, never a virus. Course, if you dredge the sewers you're gonna come up with a rat in your hand sooner or later. No AV is perfect. AS? I have … | |
Re: interesting. what do you see if you use disk management console in computer mgnt [control panel > admin tools...] to see if you can repartition it? | |
Re: Heya, titans.. you beat me this time.. could you handle a bit of help with this one? Yeah? Really? Cool... :) Anita, lessee... AVG left a lot, not to be desired.... ==First, dump that hijackthis and get a new one from [url]http://216.180.233.162/~merijn/files/HijackThis.exe[/url] -install it to a new folder alongside your … | |
Re: google gives you this:- [url]http://support.microsoft.com/kb/935448[/url] | |
Re: Wow. I was going to ask you what you thought of the F-Secure suite, but then I worked my way further down your log.... I guess not everything is perfect. Let's see what we can do. But first you need to make a decision: you have both f-Secure and AVG … | |
Re: Your inet connectio is going out thru an office in Kiev. Ukraine. Now i pers wouldn't be happy with that - they monitor your traffic for handy stuff, n then redirect it to the site you hoped to go to. Sometimes. Take your log over to the viruses n spyware … | |
Re: hi, anita, repost your log into viruses n spyware forum n it will be worked on. Yep, you have a problem. Go! Norton. Yeah..... | |
Re: ..me neither. All i can gather is that you were try ing to run an auto-installation download? And it jammed. Try doing a search in your C: drive for .msi files, see if you recognise one that is definitely related to your dl by name. .msi are Windows Installer files.... … | |
Re: Mohan, this may not help at all, but try restarting to open Windows Advanced Setup Options window -the one from where you enter Safe mode etc. Try last known good configuration - if that is no help then as you enter a Safe mode you are given the option to … | |
Re: ...you had a grub come in, something killed the file but left a registry entry that is calling it at startup, so you see the lost file msg. So do this n we may be able to help... ===hijackthis: [url]http://216.180.233.162/~merijn/files/HijackThis.exe[/url] -install it to a new folder alongside your program files. … | |
Re: Log looks clean, Llewellyn. :D Post that AVG log, and also do this next: ===hijackthis: [url]http://216.180.233.162/~merijn/files/HijackThis.exe[/url] -install it to a new folder alongside your program files and then rename the Hijackthis.exe to imabunny.exe. -in that folder start HijackThis by dclicking the .exe; now close ALL other applications and any open … | |
Re: you've swapped floppies and still the problem persists, so unless coincidence is out to get you it comes down to the cable/mobo, or the OS. do the simplest thing first- grab your XP Pro install disk n run sfc /scannow. err.. i'll enalrge upon that... go start > run, sfc … | |
Re: Yep, with a AV product... :) First off cleanup a couple of folders to reduce the number of false scan log entries by deleting your temp internet files and cookies. Now try to start in Safe mode with Networking. ===Then try an online scan at panda:- [url]http://www.pandasoftware.com/products/activescan?[/url] -select the link … | |
Re: just at a quick glance, you have two resident AV services running - Norton and AVG. With this arrangement your pc is in dire straits - they conflict, and badly. Basically, they spend a lot of time checking each other's virus signatures. So if you can access one, say by … | |
Re: tricky. see if you can boot into safe mode with command prompt. No? Then now is the time to visit a friend with your harddrive under your arm, cos we have to copy a few files from a backup repository in your sys. [what the error msg is saying is … | |
Re: Hi, jinx... :), lucky for you you chose a benign tool to play with - you don't/did not have a fixwareout issue. But you do have virtumundo and another couple of pests. So let's start by stopping some things and then downloading some more help. Run hijackthis again and check … | |
Re: ..you have just come up against commercial dvd file protection systems. pretty much the author of that dvd does not wish you to rip it. so you need a decryptor software, possibly a file compressor, and a burner software. Plenty of each out there, some are for free too, and … | |
Re: That does not sound like any group policy; never heard of a virus doing that. For a start i'd grab my install disk and go start > run > sfc /scannow -be prepared to hit enter a few times as it runs. You could instead, or first, try a system … |
The End.