818 Posted Topics
Re: [url]http://service1.symantec.com/support/nav.nsf/docid/2001092114452606[/url] or [url]http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2005033108162039[/url] or [url]http://www.askdavetaylor.com/how_can_i_fully_remove_norton_antivirus_from_my_system.html[/url] | |
Re: Perhaps you could work with this, to get what you wanted? [url]http://www.c-sharpcorner.com/Code/2002/May/CSCorner3DLogo.asp[/url] | |
Re: Please run HJT, and place a check next to these items. [b] O2 - BHO: Nothing - {b0398eca-0bcd-4645-8261-5e9dc70248d0} - C:\WINDOWS\system32\hp786A.tmp O4 - Startup: StealthBot v2.6 Revision 3.lnk = Starcraft\StealthBot\StealthBot v2.6R3a.exe O8 - Extra context menu item: &Document Tree - C:\WINDOWS\web\tree.htm O8 - Extra context menu item: View Partial So&urce - … | |
Re: Ok, lets do it :). Start by running HJT again, and selecting [b]Do system scan only[/b]. Then place a check in the box next to the follwoing items. [b] R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = prosearching.com R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = google R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = prosearching.com R1 - … | |
Re: Now, run HJT and check these items. [b] R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = R3 - URLSearchHook: (no name) - - (no file) O2 - BHO: (no name) … | |
Re: [b]Start>Run>Type [color=red]cmd[/color][/b] then in then the black screen that pops up type: regsvr32 jscript.dll regsvr32 vbscript.dll Hit Enter after each one. | |
Re: Hi, there is no need to by Norton IMO, you are just paying for somthing when you get somthing better for free (AVG). I would stick to AVG or ewido. AVG Free Anti Virus (Free) - [url]http://free.grisoft.com/doc/1[/url] Ewido (Trial) – [url]http://www.download.com/Ewido-Secur...tml?tag=lst-0-1[/url] | |
Re: Hi, becasue you want to write this in C++ you would get more help in the C++ forum, than in the VB forum. C++ Forum: [url]http://www.daniweb.com/techtalkforums/forum8.html[/url] | |
Re: Hmm, not sure if a virus would cause this, but could you please paste the log with no lines, having lines makes it very hard to read. | |
Re: Hi, Please have HJT fix these. [b] R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = [url]http://go2net.com/[/url] R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:5555 - [u]Only if you do not have a proxy set up[/u] O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - [/b] [B][COLOR="Red"] Click Fix Checked. [/COLOR][/B] The only other things I see is the … | |
Re: You can get HJT [URL="http://www.merijn.org/files/hijackthis.zip"]HERE[/URL]. Please run it, and select [b]Do system scan only[/b], then post the log that pops up. | |
Re: Hmm, I indeed sounds like you have somthing blocking you. My guess would be a program like NewDotNet (spyware). If you want to ensure that it is not spyware. [url=http://www.merijn.org/files/hijackthis.zip]Download hijackThis[/url]. Extract it to its [color=red]own[/color] folder. Then run it and select. [b]Do system scan and save log[/b]. Post the … | |
Re: Hi, please run HJT again, and place a check next to these items. [b] O23 - Service: Windows Service Manager (WSCM) - Unknown owner - C:\WINDOWS\System32\service.exe [/b] Click Fix Checked. --------------------------------------------------------------- [b]We need to remove a NT Service[/b] Do the following: [list][b]Start[/b] -> [b]Run[/b] *type [b]services.msc[/b] *click [b]OK[/b][/list] The Services … | |
Re: Hmm, just sounds like a little bug, I would restart your computer (to kill the process), then uninstall firefox, then reinstall the newest version from there site. | |
Re: Hi, first run HJT again, and check these items. [b] O20 - Winlogon Notify: winxtx32 - C:\WINDOWS\SYSTEM32\winxtx32.dll O2 - BHO: Nothing - {b0398eca-0bcd-4645-8261-5e9dc70248d0} - C:\WINDOWS\system32\hpA9DC.tmp [/b] [COLOR="Red"]Click Fix Checked.[/COLOR] ------------------------------------------------- We will let scanners and what not take out the rest. Please follow the instructions on this page to remove … | |
Re: HI, please run HJT again and select [b]Do system scan only[/b]. Then check these items. [b] O2 - BHO: BandIE Class - {77FEF28E-EB96-44FF-B511-3185DEA48697} - C:\PROGRA~1\baidu\bar\baidubar.dll O2 - BHO: IE - {D157330A-9EF3-49F8-9A67-4141AC41ADD4} - C:\WINDOWS\downlo~1\CnsHook.dll O3 - Toolbar: 百度超级 | |
Re: [url=http://www.merijn.org/files/hijackthis.zip]Download hijackThis[/url]. Extract it to its [color=red]own[/color] folder. Then run it and select. [b]Do system scan and save log[/b]. Post the contents of the log that pops up. We will owrk from there, in determining the problem. | |
Re: I have no experience with VPC, but perhaps this will help? [url]http://support.microsoft.com/kb/825372[/url] | |
Re: Chances are that is not the only infection. [url=http://www.merijn.org/files/hijackthis.zip]Download hijackThis[/url]. Extract it to its [color=red]own[/color] folder. Then run it and select. [b]Do system scan and save log[/b]. Post the contents of the log that pops up. We will see what you are up against, then removeit :). | |
Re: Also, you may want to uninstall Veiwpoint media player, as it is adware, or contains it. | |
Re: Hi, run HJt and check the following. [b] O4 - HKCU\..\Run: [Shell] "C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00001.exe" O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll (file missing) O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - [url]http://a1540.g.akamai.net/7/1540/52...meInstaller.exe[/url] O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - [url]http://www.nick.com/common/groove/gx/GrooveAX27.cab[/url] O16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} (Virtools WebPlayer … | |
Re: If not, perhaps the [code].Dispose();[/code] method will dispose of it? | |
Re: That log looks clean to me. Does everything seem to be back to normal? | |
Re: Boot into safe mode (F8 on startup). And then do what is described here: [url]http://www.pcuser.com.au/pcuser/hs2.nsf/web/0C19B57E0B302FB4CA256F6200370DC8[/url] | |
Re: Hmm, It could be a virus. I would suspect the expired account, if I thought that your accounts can expire, I don't think they do. I think I am going to lean toward a virus. If you don't know how to read HJT logs, and if you want to see … | |
Re: Thank you, for making your own thread :). Start by running HJT again, and selecting [b]Do system scan only[/b]. Then in HJT check these items. [b] R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = [url]http://us7.hpwis.com[/url] R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = [url]http://srch-us7.hpwis.com/[/url] O4 - HKLM\..\Run: [winupdates] C:\Program Files\winupdates\winupdates.exe /auto O4 - HKLM\..\Run: [outlook] C:\Program … | |
Re: First of all [B]monomadrox[/B], welcome to DaniWeb :) We ask that members not tag their questions on to a thread previously started by another member (regardless of how similar your problem might seem). Not only does it divert the focus of the thread away from the original poster's problem, but … | |
Re: Hi, you have a few infections. Please run HJT again, and check these items. [b] R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm O2 - BHO: Nothing - {b0398eca-0bcd-4645-8261-5e9dc70248d0} - C:\WINDOWS\System32\hpA6DF.tmp O4 - HKLM\..\Run: [winupdates] C:\Program Files\winupdates\winupdates.exe /auto O4 - HKLM\..\Run: [SpywareBot] C:\Program Files\SpywareBot\SpywareBot.exe -boot O4 - HKLM\..\RunOnce: [VS98_Setup_Wizard] "C:\Documents and … | |
Re: Hi, Please run HJT again, and select [b]Do system scan only[/b]. THen check these items. [b] R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = [url]http://www.hub.slb.com/[/url] R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = [url]http://www.hub.slb.com[/url] O2 - BHO: (no name) - {00000000-59D4-4008-9058-080011001200} - (no file) O2 - BHO: (no name) - {00000000-C1EC-0345-6EC2-4D0300000000} - (no file) O2 … | |
Re: Hi, and welcome to DaniWeb. Lets start by running HJT again and selecting [b]Do system scan only[/b]. Then place a check next to these items. [b] R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:5555 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = O2 - BHO: Nothing - {edbf1bc8-39ab-48eb-a0a9-c75078eb7c8e} - C:\WINDOWS\system32\hpBCC8.tmp O3 - Toolbar: (no name) … | |
Re: [url=http://www.merijn.org/files/hijackthis.zip]Download hijackThis[/url]. Extract it to its [color=red]own[/color] folder. Then run it and select. [b]Do system scan and save log[/b]. Post the contents of the log that pops up. We will work from there... [i]Oops didn't see nizzy asked for one, well now you know where to get it :)[/i] | |
Re: Are you serious! You checked everything! If so I cannot belive that your computer is working! Please post the log next time. DO NOT, check anything, without being told to do so! HJT can be dangerous if used incorrectly. [i]jhay116, you should probally tell them not to check anything until … | |
Re: Next time, please don't double post. | |
Re: Lets first start with SmitRem. Download SmitRem ([url]http://noahdfear.geekstogo.com/click...click.php?id=1)[/url]. Download smitRem.exe, saving the file to your desktop. Double click it to extract the contents to a folder of it’s own. Restart your computer in safe mode, logon to the user account that is infected, open the smitRem folder and double click … | |
Re: Hi, there are still a few infections. Please run HJT again and select the following entries. [b] R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = [url]http://searchbar.findthewebsiteyouneed.com[/url] R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = [url]http://searchbar.findthewebsiteyouneed.com[/url] R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = [url]http://searchbar.findthewebsiteyouneed.com[/url] R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = [url]http://searchbar.findthewebsiteyouneed.com[/url] R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = [url]http://searchbar.findthewebsiteyouneed.com[/url] … | |
Re: Hi, and welcome to DaniWeb. Next scan please move HJT to its own folder. Now please run HJT again, and check the following items. [b]O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present O11 - Options group: [INTERNATIONAL] International* [/b] Click Fix Checked. Please move HJT to its own folder, and post a … | |
Re: Please attach another HJT log. Thanks. | |
Re: Hi, sorry for the late reply, we must have missed you. Please start HJT again, and check off the following items. [b] R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = [url]http://ie.redirect.hp.com/svs/rdr?TY...lion&pf=laptop[/url] R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = [url]http://ie.redirect.hp.com/svs/rdr?TY...lion&pf=laptop[/url] R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = [url]http://ie.redirect.hp.com/svs/rdr?TY...lion&pf=laptop[/url] R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = [url]http://ie.redirect.hp.com/svs/rdr?TY...lion&pf=laptop[/url] R1 … | |
Re: [url=http://www.merijn.org/files/hijackthis.zip]Download hijackThis[/url]. Extract it to its [color=red]own[/color] folder. Then run it and select. [b]Do system scan and save log[/b]. Post the contents of the log that pops up. | |
Re: Could be the rements of a virus. Lets see :). [url=http://www.merijn.org/files/hijackthis.zip]Download hijackThis[/url]. Extract it to its [color=red]own[/color] folder. Then run it and select. [b]Do system scan and save log[/b]. Post the contents of the log that pops up. | |
Re: [url=http://www.merijn.org/files/hijackthis.zip]Download hijackThis[/url]. Extract it to its [color=red]own[/color] folder. Then run it and select. [b]Do system scan and save log[/b]. Post the contents of the log that pops up. We will work form there. | |
Re: You need to install the drivers for the video card. Do you have the CD's, specifically the Video card/Graphics card one? If you do it should be easy to fix. If not we will have to detrmine what you have, download the drivers then intstall. | |
Re: Perhaps, it set its self up in the startup folder, and the registry? IF you want to disable programs that start when you boot look here - [url]http://www.5starsupport.com/info/techinfo.htm#runboot95[/url] - toward the bottom, the program called startup cop. Hope that helps :) -T | |
Re: Hi, This shows that your windows is out of date. After the cleaning process you should use windows update to get SP2. Go into safemode. Scan again with HJT, and place a tick nest to these items, then click Fix checked items. [quote][b] C:\Program Files\ISTsvc\istsvc.exe Check with an antivirus scanner … | |
Re: [url=http://www.merijn.org/files/hijackthis.zip]Download hijackThis[/url]. Extract it to its [color=red]own[/color] folder. Then run it and select. [b]Do system scan and save log[/b]. Post the contents of the log that pops up. We will work form there. | |
![]() | Re: You have a few infections, let's start with this. [b]Please download the trial version of Ewido Security Suite here: [/b] [url]http://www.ewido.net/en/download/[/url] [color=darkblue]Install it, and update the definitions to the newest files. Do NOT run it yet[/color] [u]Now reboot into Safe Mode (F8 on Startup)[/u] [color=darkred]Please run Ewido,and save the logfile … |
Re: Download CCleaner ([url]www.ccleaner.com)[/url]. We now need to cleanup all the Temp, Temorary Internet Files, Recycle Bin, etc... but first need to configure it. Open it, and choose the 'Options' tab. Inside, hit the 'Custom' tab, and add the following folders (Note: Not all of these files are on every computer. … | |
Re: Hi again :). Nothing looks to bad in your log, if you don't know what [b]Mail.Com[/b] is I would Uninstall that. Begin by downloading [COLOR="Blue"][url=www.ccleaner.com]CCLeaner[/url][/COLOR], and specifically choosing the most recent version. Then, follow these steps: 1. Close all programs so that you are at your desktop. 2. Double-click on … | |
Re: Hi Danna and welcome to DaniWeb. You do indeed have a few infections. Please run HJT and place a check next to the following items. [b] R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost F2 - REG:system.ini: Shell=Explorer.exe, C:\WINDOWS\system32\buafl.exe F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,mphjvyw.exe O4 - HKLM\..\Run: [{A5-5B-BE-E7-ZN}] c:\windows\system32\dwdsregt.exe FI002 O4 - HKLM\..\Run: … |
The End.