818 Posted Topics
Re: It may be a long shot, but I would try a System Restore. [url]http://www.microsoft.com/windowsxp/using/helpandsupport/learnmore/systemrestore.mspx[/url] | |
Whenever I fire up mozilla and go to Daniweb (Which is quite often). After I go to the spyware forum. iTunes always starts itself. I have no idea why this is, and it is mildy bothersome. Do you think that it is a coincidence that it only happens on DaniWeb? … | |
Re: Hmmm, Nothing looks to bad. Lets start with some scanners. Download the Free trial version of [color=blue]Spysweeper[/color] [url]http://www.webroot.com/consumer/pro...&rc=4129&ac=tsg[/url] Update the defintions and run it (Save Log) Then download [color=blue]ewido[/color] [url]www.ewido.net[/url] - Install. Update. Scan. Remove anything it finds. (Save Log) Then post those two logs, along with another HJT log... | |
Re: Hi, please run HJT again and select, [b]Do system scan only[/b]. Then check the following. [b] O20 - Winlogon Notify: winskf32 - C:\WINDOWS\SYSTEM32\winskf32.dll O23 - Service: PRTG Service - Paessler Router Traffic Grapher (PRTGService) - Unknown owner - C:\Program Files\PRTG Traffic Grapher\PRTG Traffic Grapher.exe (file missing) [/b] [COLOR="Lime"]Click Fix Checked[/COLOR] … | |
Re: Hi :) Well, I can tell you for sure you don't want it. So lets start by running HJT and selecting [b]Do system scan only[/b]. Then place a check next to these items. [b] O4 - HKLM\..\Run: [exp] C:\WINDOWS\system32\wfwall1.exe O16 - DPF: {FCF289D4-0AC8-4ED8-BE31-E8AF09606AB5} (download_35mb_com.applet) - [url]http://static.35mb.com/applet/applet_o.cab[/url] [/b] [COLOR="Red"]Click Fix Checked … | |
Re: Hi and welcome :). Please run HJT again and select [b]Do system scan only[/b]. Then check the following items. [COLOR="Red"]YOU WILL NEED TO PRINT THESE OUT, AS YOU WILL OT HAVE ACCESS TO THE INTERNET DURING PARTS OF THE FIX![/COLOR] [b] R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\WINDOWS\system32\SearchBar.htm R1 - … | |
Re: That movie was indeed funny. Great, just like the first. I to saw it while going on vacation ;). | |
Re: CCleaner will rid you of temporary files, in this case, I am not sure how much that will help you. Here is how to clear your history: [url]http://www.worldstart.com/tips/tips.php/765[/url] IF you use a different browser, let me know. | |
Re: Tell me about it :) Seriously though, glad its all working :D. | |
Re: That log does not look comlete, it is missing the header... [url=http://www.merijn.org/files/hijackthis.zip]Download hijackThis[/url]. Extract it to its [color=red]own[/color] folder. Then run it and select. [b]Do system scan and save log[/b]. Post the contents of the log that pops up. We will then go from there... [i]This should also be moved … | |
Re: [quote] 1. is it ok for wuauclt.exe to be running? [/quote] Yes it is, wuauclt.exe is the AutoUpdate program for WindowsME [quote] Whenever i restart or startup windows i get this error "Error loading we4e17f0.dll" Does anyone know how to fix it? [/quote] Somthing tells me this may be a … | |
Re: [url]www.pscode.com[/url] - Tons of free source there, a great place to learn :). | |
Re: Hmm, seeing that this thread is over two years old. I am sure that this problem has been resolved. Do not bump old threads. | |
Re: [quote] I wonder when we'll get to 70,000... :-P [/quote] Well, actually we have about 73,000 members. Found on the home page: [B]Members: [COLOR="Red"]73,296[/COLOR][/B] | |
Re: Yes, I would say you are infected. [url=http://www.merijn.org/files/hijackthis.zip]Download hijackThis[/url]. Extract it to its [color=red]own[/color] folder. Then run it and select. [b]Do system scan and save log[/b]. Post the contents of the log that pops up. Download the Free trial version of [color=blue]Spysweeper[/color] [url]http://www.webroot.com/consumer/pro...&rc=4129&ac=tsg[/url] Update the defintions and run it, let … | |
Re: Hi, take a look here. [url]http://support.microsoft.com/?kbid=314057[/url] Might want to look here to. [url]http://www.tinyempire.com/shortnotes/files/ntldr_missing.htm[/url] | |
Re: Ok, please do the following. Run HJT again and select [b]Do system scan only[/b]. Check the following. [b] O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - [url]http://us.dl1.yimg.com/download.yaho...st_current.cab[/url] O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - [url]http://software-dl.real.com/27a3c507...p/RdxIE601.cab[/url] O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) - [url]http://pdl.stream.aol.com/downloads/...ampx_en_dl.cab[/url] [/b] [COLOR="Red"]Click Fix Checked[/COLOR] --------------------------------------------------------- [B]We need to … | |
Re: Hi, and welcome to Daniweb :). You do have a bit of "nasties". Start by running HJT agan and selecting [b]Do system scan only[/b]. Then check these items. [b] R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file) O4 - HKLM\..\Run: [YwO77Lg] C:\documents and settings\daddy\local settings\temp\YwO77Lg.exe O4 - HKLM\..\Run: … | |
Re: Download smitRem.exe ([url]http://noahdfear.geekstogo.com/click%20counter/click.php?id=1)[/url], saving the file to your desktop. Double click it to extract the contents to a folder of it's own. Restart your computer in safe mode, logon to the user account that is infected, open the smitRem folder and double click the RunThis.bat file to start the tool. … | |
Re: Ok, first please download ewido - [url]www.ewido.net[/url] - Install. Update. Scan. Remove anything it finds. Then post back with a new HJT log, as well as the ewido log. If you know anything about this [b] O23 - Service: Software Secure Service (SSISvr32) - SoftwareSecure Inc - C:\WINDOWS\system32\ssisvr32.exe [/b] Please … | |
Re: This should help you: [url]http://www.houseofhelp.com/v3/showthread.php?t=26730[/url] Let me know :). [i]This is also in the worng forum...[/i] | |
Re: First off this is in the wrong forum... Now run HJt select do system scan only, and check the following. [b] O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocx (file missing) O8 - Extra context menu item: Edit with &XML Spy - C:\Program Files\Altova\xmlspy\spy.htm [/b] Click Fix … | |
Re: Nothing looks to bad. I would just have HJT fix the following. [b] O16 - DPF: {C68F9105-04FD-4B48-B6CC-2A076F711C35} (HpodPCFileCtrl2 Class) - file://F:\MEMDISC\ALBUM_A\VIEW\PLUGIN\HPODPCFC.CAB [/b] | |
![]() | Re: Lets not forget the SpyAxe variants... Download smitRem.exe ([url]http://www.bleepingcomputer.com/resources/link240.html)[/url], saving the file to your desktop. Double click it to extract the contents to a folder of it's own. Restart your computer in safe mode, logon to the user account that is infected, open the smitRem folder and double click the … |
Re: DO NOT! Get anything from that site. it is a scam. If your step father got somthing from there, he is also infected. Run HJT again, select [b]Do system scan only[/b]. THen check the follwoing items. [b] O4 - HKLM\..\Run: [SemanticInsight] C:\Program Files\RXToolBar\Semantic Insight\SemanticInsight.exe O16 - DPF: {B64F4A7C-97C9-11DA-8BDE-F66BAD1E3F3A} - [url]http://locator1.cdn.imagesrvr.com/si...reeInstall.cab[/url] … | |
Re: Your IE is out of date also. May want to update it. Or [URL="http://www.getfirefox.com"]GetFireFox[/URL], as it offers more security and more features. | |
Re: Hi, and welcome :) Download pocket killbox from [url]http://www.thespykiller.co.uk/files/killbox.exe[/url] & put it on the desktop where you can find it easily Now Start killbox Copy the list of files below to the clipboard by selecting all of them with your mouse (Left click the start of the list and drag … | |
Re: You don't need to worry about downloading [b]ewido[/b] as it seems you already have it installed ;). | |
Re: Ok, to put it simply. You are [b]Loaded[/b] with infections. Please start by download the following. [b]Do not run them yet[/b]. [COLOR=Blue]SmitRem [/COLOR]- [url]http://noahdfear.geekstogo.com/click%20counter/click.php?id=1[/url] [COLOR=Blue]Ewido[/COLOR] - ww.ewido.net [COLOR=Blue]CCLeaner [/COLOR]- [url]www.ccleaner.com[/url] [color=red]After you download those, you may need to print these instructions, you will not have internet access during parts of … | |
Re: Might want to scan with ewido. [url]www.ewdio.net[/url] -- Also make sure you don't have any items disabled form running at start-up. If you do re-enable them and post a new log. | |
Re: Hmm, perhaps I am wrong but I belive that the folder it is in is fine. I think the only real time that is a big deal is if they are running it from the zipped folder. Let me know if that is wrong ;). | |
Re: Ok, we will do this manually. You are pretty infected. Run HJT and check the following items. [b] R3 - Default URLSearchHook is missing O2 - BHO: BHObj Class - {00000010-6F7D-442C-93E3-4A4827C2E4C8} - C:\windows\nem220.dll O2 - BHO: Related Page - {9A9C9B69-F908-4AAB-8D0C-10EA8997F37E} - C:\windows\System32\WinNB57.dll O2 - BHO: WhIeHelperObj Class - {c900b400-cdfe-11d3-976a-00e02913a9e0} - … | |
Re: Hi there :). Please run HJT and select [b]Do system scan only[/b]. Then check the following items. [b] O2 - BHO: Yvakt Class - {DAAC59E5-093D-4D24-A105-55BFE4ACDE14} - C:\WINDOWS\system32\w9seq.dll O10 - Broken Internet access because of LSP provider 'c:\program files\newdotnet\newdotnet6_38.dll' missing O18 - Filter: text/html - {CEA53356-C414-4331-A35E-AA4CE9D8DFA2} - C:\WINDOWS\system32\w9seq.dll O20 - Winlogon … | |
Re: Hi, please run HJT again, and select [b]Do system scan only[/b]. Then place a check in the checkbox next to these items. [b] R3 - URLSearchHook: (no name) - {02EE5B04-F144-47BB-83FB-A60BD91B74A9} - C:\Program Files\SurfSideKick 3\SskBho.dll F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,fjffysl.exe O4 - HKLM\..\Run: [SurfSideKick 3] C:\Program Files\SurfSideKick 3\Ssk.exe O4 - HKCU\..\Run: [SurfSideKick … | |
Re: Hi, sorry for the delayed reply, to take care of Winfixer please do the following. Please download [url=http://www.atribune.org/ccount/click.php?id=4]VundoFix.exe[/url] to your desktop. 1. Double-click [B]VundoFix.exe[/B] to run it. 2. Click the "Scan for Vundo" button. 3. Once it's done scanning, click the "Remove Vundo" button. 4. You will receive a prompt … | |
Re: Depends, somtimes you can get them for about $100 depending where you get them. | |
Re: Have a look here, try some of the suggestions. [url]http://www.experts-exchange.com/Operating_Systems/WinXP/Q_20972739.html[/url] [i]You have another thread right below this one, dealing with the same thing...Please don't double post, it is against the forums rules.[/i] | |
Re: Hi, run HJT again and select "Do system scan only". Then in HJT check the following items. [b] R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = prosearching.com R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = prosearching.com O2 - BHO: Windows Resources - {2D38A51A-23C9-48a1-A33C-48675AA2B494} - C:\WINDOWS\winres.dll O3 - Toolbar: (no name) - {FAA356E4-D317-42a6-AB41-A3021C6E7D52} - (no … | |
Re: You could try [color=blue]PocketKill Box[/color]. Download pocket killbox from [url]http://www.thespykiller.co.uk/files/killbox.exe[/url] & put it on the desktop where you can find it easily Now Start killbox Copy the list of files below to the clipboard by selecting all of them with your mouse (Left click the start of the list and … | |
Re: Hi, and welcome. The forums rules state that you need to create your own topic, and not hijack another (even if it is old, or related). Since some of the mods may not be around for a while im going to help you here but Im sure this will be … | |
Re: Hi, please run HJT again, and select [b]Do system scan only[/b]. Then check these items. [b] O4 - HKCU\..\Run: [Aceu] "C:\PROGRA~1\COMMON~1\ICROSO~1\ati2evxx.exe" -vt yazr O4 - HKCU\..\Run: [Szsmf] C:\Program Files\Common Files\?asks\arpa.exe O8 - Extra context menu item: &Dictionary - [url]http://files.db3nf.com/scripts/ie.htm[/url] O8 - Extra context menu item: &Encyclopedia - [url]http://files.db3nf.com/scripts/ie-e.htm[/url] O20 - … | |
Re: Ok, lets start by [url=http://www.merijn.org/files/hijackthis.zip]Downloading hijackThis[/url]. Extract it to its [color=red]own[/color] folder. Then run it and select. [b]Do system scan and save log[/b]. Post the contents of the log that pops up. We will then work from there. | |
Re: Hi, log looks pretty clean. There are a few things you could remove. [quote] Extra button: (no name) - AutorunsDisabled - (no file) [/quote] And thats it unless you want to get rid of the AOL, Goolge toolbars. -T | |
Re: Hi, :) Run HJT and check the following. [b] O20 - Winlogon Notify: Shell Extensions - C:\WINDOWS\system32\n2n60c5sef.dll (file missing) O20 - Winlogon Notify: dvd4free - dvd4free.dll (file missing) O18 - Filter: text/html - {CEA53356-C414-4331-A35E-AA4CE9D8DFA2} - C:\WINDOWS\system32\w9seq.dll O2 - BHO: Yvakt Class - {DAAC59E5-093D-4D24-A105-55BFE4ACDE14} - C:\WINDOWS\system32\w9seq.dll (file missing) R3 - Default … | |
Re: It is not really needed to keep your computer running. It is related to the nvidia graphic cards. [quote] This application will give the user access to additional features which allow the configuration of up to 32 monitors on a host, or to expand the desktop across many monitors. [/quote] … | |
Re: Ok, you have a fair amount of nasties. Lets knock some out with scanners before we proceed manually. Download the Free trial version of [color=blue]Spysweeper[/color] [url]http://www.webroot.com/consumer/pro...&rc=4129&ac=tsg[/url] Update the defintions and run it. Then download [color=blue]ewido[/color] [url]www.ewido.net[/url] - Install. Update. Scan. Remove anything it finds. Download [COLOR=Blue][B]smitRem.exe [/B][/COLOR]([url]http://www.bleepingcomputer.com/resources/link240.html)[/url], saving the file … | |
Re: Open volume control and check to see if it is set to 'Mute'. To do this [b]Start>Control Panel>Sounds and audio devices[/b] [i]Your other post is right below this one, you should edit that one, and delete it.[/i] | |
Re: More details... [b]Go to Start>Control Panel>System>Hardware Tab>Device Manager>Mice and other pointing devices.[/b] You should see somthing like [color=blue]PS/2 Compatible Mouse[/color]. Right click on it. -Select Uninstall -Click yes to the dialog -Restart your computer -When its rebooted, it will say it has finished installing new hardware. -Reboot again. | |
Re: Hi there :). Run HJT again, and place a check next to the following items. [b] O2 - BHO: (no name) - {3E422F49-1566-40D3-B43D-077EF739AC32} - (no file) O3 - Toolbar: (no name) - {5AA06644-BC46-4220-A460-47A6EB47C96D} - (no file) [/b] [color=red]Click Fix Checked[/color] ------------------------------------------------------------------ Then please download ewido - [url]www.ewido.net[/url] - Install. Update. … |
The End.