818 Posted Topics

Member Avatar for mrweh

It may be a long shot, but I would try a System Restore. [url]http://www.microsoft.com/windowsxp/using/helpandsupport/learnmore/systemrestore.mspx[/url]

Member Avatar for nanosani
0
153
Member Avatar for tayspen

Whenever I fire up mozilla and go to Daniweb (Which is quite often). After I go to the spyware forum. iTunes always starts itself. I have no idea why this is, and it is mildy bothersome. Do you think that it is a coincidence that it only happens on DaniWeb? …

Member Avatar for Dani
0
250
Member Avatar for Valo_Soul

Hmmm, Nothing looks to bad. Lets start with some scanners. Download the Free trial version of [color=blue]Spysweeper[/color] [url]http://www.webroot.com/consumer/pro...&rc=4129&ac=tsg[/url] Update the defintions and run it (Save Log) Then download [color=blue]ewido[/color] [url]www.ewido.net[/url] - Install. Update. Scan. Remove anything it finds. (Save Log) Then post those two logs, along with another HJT log...

Member Avatar for tayspen
0
317
Member Avatar for micky7899

Hi, please run HJT again and select, [b]Do system scan only[/b]. Then check the following. [b] O20 - Winlogon Notify: winskf32 - C:\WINDOWS\SYSTEM32\winskf32.dll O23 - Service: PRTG Service - Paessler Router Traffic Grapher (PRTGService) - Unknown owner - C:\Program Files\PRTG Traffic Grapher\PRTG Traffic Grapher.exe (file missing) [/b] [COLOR="Lime"]Click Fix Checked[/COLOR] …

Member Avatar for micky7899
0
318
Member Avatar for cbbcisace

Hi :) Well, I can tell you for sure you don't want it. So lets start by running HJT and selecting [b]Do system scan only[/b]. Then place a check next to these items. [b] O4 - HKLM\..\Run: [exp] C:\WINDOWS\system32\wfwall1.exe O16 - DPF: {FCF289D4-0AC8-4ED8-BE31-E8AF09606AB5} (download_35mb_com.applet) - [url]http://static.35mb.com/applet/applet_o.cab[/url] [/b] [COLOR="Red"]Click Fix Checked …

Member Avatar for 'Stein
0
321
Member Avatar for padfieldj

Hi and welcome :). Please run HJT again and select [b]Do system scan only[/b]. Then check the following items. [COLOR="Red"]YOU WILL NEED TO PRINT THESE OUT, AS YOU WILL OT HAVE ACCESS TO THE INTERNET DURING PARTS OF THE FIX![/COLOR] [b] R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\WINDOWS\system32\SearchBar.htm R1 - …

Member Avatar for padfieldj
0
261
Member Avatar for ragemore

That movie was indeed funny. Great, just like the first. I to saw it while going on vacation ;).

Member Avatar for tayspen
0
266
Member Avatar for LarryRT

CCleaner will rid you of temporary files, in this case, I am not sure how much that will help you. Here is how to clear your history: [url]http://www.worldstart.com/tips/tips.php/765[/url] IF you use a different browser, let me know.

Member Avatar for nizzy1115
0
131
Member Avatar for Dani
Member Avatar for The Dude
0
363
Member Avatar for larbec

That log does not look comlete, it is missing the header... [url=http://www.merijn.org/files/hijackthis.zip]Download hijackThis[/url]. Extract it to its [color=red]own[/color] folder. Then run it and select. [b]Do system scan and save log[/b]. Post the contents of the log that pops up. We will then go from there... [i]This should also be moved …

Member Avatar for DMR
0
293
Member Avatar for mcrrcoker

[quote] 1. is it ok for wuauclt.exe to be running? [/quote] Yes it is, wuauclt.exe is the AutoUpdate program for WindowsME [quote] Whenever i restart or startup windows i get this error "Error loading we4e17f0.dll" Does anyone know how to fix it? [/quote] Somthing tells me this may be a …

Member Avatar for DMR
0
129
Member Avatar for Roujin

[url]www.pscode.com[/url] - Tons of free source there, a great place to learn :).

Member Avatar for WolfPack
0
257
Member Avatar for Mystic1

Hmm, seeing that this thread is over two years old. I am sure that this problem has been resolved. Do not bump old threads.

Member Avatar for tayspen
0
430
Member Avatar for Medwards
Member Avatar for BeastOverlordH6

[quote] I wonder when we'll get to 70,000... :-P [/quote] Well, actually we have about 73,000 members. Found on the home page: [B]Members: [COLOR="Red"]73,296[/COLOR][/B]

Member Avatar for tayspen
0
203
Member Avatar for Highmount

Yes, I would say you are infected. [url=http://www.merijn.org/files/hijackthis.zip]Download hijackThis[/url]. Extract it to its [color=red]own[/color] folder. Then run it and select. [b]Do system scan and save log[/b]. Post the contents of the log that pops up. Download the Free trial version of [color=blue]Spysweeper[/color] [url]http://www.webroot.com/consumer/pro...&rc=4129&ac=tsg[/url] Update the defintions and run it, let …

Member Avatar for Highmount
0
541
Member Avatar for mohsin

Hi, take a look here. [url]http://support.microsoft.com/?kbid=314057[/url] Might want to look here to. [url]http://www.tinyempire.com/shortnotes/files/ntldr_missing.htm[/url]

Member Avatar for goldeagle2005
0
149
Member Avatar for Xgpnavsys

Ok, please do the following. Run HJT again and select [b]Do system scan only[/b]. Check the following. [b] O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - [url]http://us.dl1.yimg.com/download.yaho...st_current.cab[/url] O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - [url]http://software-dl.real.com/27a3c507...p/RdxIE601.cab[/url] O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) - [url]http://pdl.stream.aol.com/downloads/...ampx_en_dl.cab[/url] [/b] [COLOR="Red"]Click Fix Checked[/COLOR] --------------------------------------------------------- [B]We need to …

Member Avatar for Xgpnavsys
0
390
Member Avatar for daddysla

Hi, and welcome to Daniweb :). You do have a bit of "nasties". Start by running HJT agan and selecting [b]Do system scan only[/b]. Then check these items. [b] R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file) O4 - HKLM\..\Run: [YwO77Lg] C:\documents and settings\daddy\local settings\temp\YwO77Lg.exe O4 - HKLM\..\Run: …

Member Avatar for ShadowPuterDude
0
529
Member Avatar for legendkiller6

Download smitRem.exe ([url]http://noahdfear.geekstogo.com/click%20counter/click.php?id=1)[/url], saving the file to your desktop. Double click it to extract the contents to a folder of it's own. Restart your computer in safe mode, logon to the user account that is infected, open the smitRem folder and double click the RunThis.bat file to start the tool. …

Member Avatar for tayspen
0
192
Member Avatar for Binoir

Ok, first please download ewido - [url]www.ewido.net[/url] - Install. Update. Scan. Remove anything it finds. Then post back with a new HJT log, as well as the ewido log. If you know anything about this [b] O23 - Service: Software Secure Service (SSISvr32) - SoftwareSecure Inc - C:\WINDOWS\system32\ssisvr32.exe [/b] Please …

Member Avatar for 'Stein
0
309
Member Avatar for hawaiian92

This should help you: [url]http://www.houseofhelp.com/v3/showthread.php?t=26730[/url] Let me know :). [i]This is also in the worng forum...[/i]

Member Avatar for tayspen
0
50
Member Avatar for grungetta

First off this is in the wrong forum... Now run HJt select do system scan only, and check the following. [b] O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocx (file missing) O8 - Extra context menu item: Edit with &XML Spy - C:\Program Files\Altova\xmlspy\spy.htm [/b] Click Fix …

Member Avatar for tayspen
0
131
Member Avatar for pistolsnipe16

Nothing looks to bad. I would just have HJT fix the following. [b] O16 - DPF: {C68F9105-04FD-4B48-B6CC-2A076F711C35} (HpodPCFileCtrl2 Class) - file://F:\MEMDISC\ALBUM_A\VIEW\PLUGIN\HPODPCFC.CAB [/b]

Member Avatar for 'Stein
0
274
Member Avatar for mattpacman

Lets not forget the SpyAxe variants... Download smitRem.exe ([url]http://www.bleepingcomputer.com/resources/link240.html)[/url], saving the file to your desktop. Double click it to extract the contents to a folder of it's own. Restart your computer in safe mode, logon to the user account that is infected, open the smitRem folder and double click the …

Member Avatar for 'Stein
0
167
Member Avatar for einarmk

DO NOT! Get anything from that site. it is a scam. If your step father got somthing from there, he is also infected. Run HJT again, select [b]Do system scan only[/b]. THen check the follwoing items. [b] O4 - HKLM\..\Run: [SemanticInsight] C:\Program Files\RXToolBar\Semantic Insight\SemanticInsight.exe O16 - DPF: {B64F4A7C-97C9-11DA-8BDE-F66BAD1E3F3A} - [url]http://locator1.cdn.imagesrvr.com/si...reeInstall.cab[/url] …

Member Avatar for tayspen
0
140
Member Avatar for flipboi15

Your IE is out of date also. May want to update it. Or [URL="http://www.getfirefox.com"]GetFireFox[/URL], as it offers more security and more features.

Member Avatar for 'Stein
0
84
Member Avatar for imsuchawolf

Hi, and welcome :) Download pocket killbox from [url]http://www.thespykiller.co.uk/files/killbox.exe[/url] & put it on the desktop where you can find it easily Now Start killbox Copy the list of files below to the clipboard by selecting all of them with your mouse (Left click the start of the list and drag …

Member Avatar for 'Stein
0
666
Member Avatar for robbo_the_hood
Member Avatar for MetalHead252

Ok, to put it simply. You are [b]Loaded[/b] with infections. Please start by download the following. [b]Do not run them yet[/b]. [COLOR=Blue]SmitRem [/COLOR]- [url]http://noahdfear.geekstogo.com/click%20counter/click.php?id=1[/url] [COLOR=Blue]Ewido[/COLOR] - ww.ewido.net [COLOR=Blue]CCLeaner [/COLOR]- [url]www.ccleaner.com[/url] [color=red]After you download those, you may need to print these instructions, you will not have internet access during parts of …

Member Avatar for 'Stein
0
143
Member Avatar for warmonk

Might want to scan with ewido. [url]www.ewdio.net[/url] -- Also make sure you don't have any items disabled form running at start-up. If you do re-enable them and post a new log.

Member Avatar for 'Stein
0
89
Member Avatar for marcoolio

Hmm, perhaps I am wrong but I belive that the folder it is in is fine. I think the only real time that is a big deal is if they are running it from the zipped folder. Let me know if that is wrong ;).

Member Avatar for tayspen
0
156
Member Avatar for talitha

Ok, we will do this manually. You are pretty infected. Run HJT and check the following items. [b] R3 - Default URLSearchHook is missing O2 - BHO: BHObj Class - {00000010-6F7D-442C-93E3-4A4827C2E4C8} - C:\windows\nem220.dll O2 - BHO: Related Page - {9A9C9B69-F908-4AAB-8D0C-10EA8997F37E} - C:\windows\System32\WinNB57.dll O2 - BHO: WhIeHelperObj Class - {c900b400-cdfe-11d3-976a-00e02913a9e0} - …

Member Avatar for tayspen
0
159
Member Avatar for tlcconsult

Hi there :). Please run HJT and select [b]Do system scan only[/b]. Then check the following items. [b] O2 - BHO: Yvakt Class - {DAAC59E5-093D-4D24-A105-55BFE4ACDE14} - C:\WINDOWS\system32\w9seq.dll O10 - Broken Internet access because of LSP provider 'c:\program files\newdotnet\newdotnet6_38.dll' missing O18 - Filter: text/html - {CEA53356-C414-4331-A35E-AA4CE9D8DFA2} - C:\WINDOWS\system32\w9seq.dll O20 - Winlogon …

Member Avatar for 'Stein
0
159
Member Avatar for CutThatCity

Hi, please run HJT again, and select [b]Do system scan only[/b]. Then place a check in the checkbox next to these items. [b] R3 - URLSearchHook: (no name) - {02EE5B04-F144-47BB-83FB-A60BD91B74A9} - C:\Program Files\SurfSideKick 3\SskBho.dll F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,fjffysl.exe O4 - HKLM\..\Run: [SurfSideKick 3] C:\Program Files\SurfSideKick 3\Ssk.exe O4 - HKCU\..\Run: [SurfSideKick …

Member Avatar for tayspen
0
131
Member Avatar for Franklin_a

Hi, sorry for the delayed reply, to take care of Winfixer please do the following. Please download [url=http://www.atribune.org/ccount/click.php?id=4]VundoFix.exe[/url] to your desktop. 1. Double-click [B]VundoFix.exe[/B] to run it. 2. Click the "Scan for Vundo" button. 3. Once it's done scanning, click the "Remove Vundo" button. 4. You will receive a prompt …

Member Avatar for 'Stein
0
151
Member Avatar for ricky91
Member Avatar for DMR
0
152
Member Avatar for Dave Melandri

Have a look here, try some of the suggestions. [url]http://www.experts-exchange.com/Operating_Systems/WinXP/Q_20972739.html[/url] [i]You have another thread right below this one, dealing with the same thing...Please don't double post, it is against the forums rules.[/i]

Member Avatar for caperjack
0
91
Member Avatar for roguelancer

Hi, run HJT again and select "Do system scan only". Then in HJT check the following items. [b] R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = prosearching.com R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = prosearching.com O2 - BHO: Windows Resources - {2D38A51A-23C9-48a1-A33C-48675AA2B494} - C:\WINDOWS\winres.dll O3 - Toolbar: (no name) - {FAA356E4-D317-42a6-AB41-A3021C6E7D52} - (no …

Member Avatar for tayspen
0
149
Member Avatar for dp600

You could try [color=blue]PocketKill Box[/color]. Download pocket killbox from [url]http://www.thespykiller.co.uk/files/killbox.exe[/url] & put it on the desktop where you can find it easily Now Start killbox Copy the list of files below to the clipboard by selecting all of them with your mouse (Left click the start of the list and …

Member Avatar for dp600
0
111
Member Avatar for jacv99

Hi, and welcome. The forums rules state that you need to create your own topic, and not hijack another (even if it is old, or related). Since some of the mods may not be around for a while im going to help you here but Im sure this will be …

Member Avatar for DMR
0
519
Member Avatar for sayac3p0

Hi, please run HJT again, and select [b]Do system scan only[/b]. Then check these items. [b] O4 - HKCU\..\Run: [Aceu] "C:\PROGRA~1\COMMON~1\ICROSO~1\ati2evxx.exe" -vt yazr O4 - HKCU\..\Run: [Szsmf] C:\Program Files\Common Files\?asks\arpa.exe O8 - Extra context menu item: &Dictionary - [url]http://files.db3nf.com/scripts/ie.htm[/url] O8 - Extra context menu item: &Encyclopedia - [url]http://files.db3nf.com/scripts/ie-e.htm[/url] O20 - …

Member Avatar for tayspen
0
236
Member Avatar for ardentsunshine

Ok, lets start by [url=http://www.merijn.org/files/hijackthis.zip]Downloading hijackThis[/url]. Extract it to its [color=red]own[/color] folder. Then run it and select. [b]Do system scan and save log[/b]. Post the contents of the log that pops up. We will then work from there.

Member Avatar for tayspen
0
117
Member Avatar for ships

Hi, log looks pretty clean. There are a few things you could remove. [quote] Extra button: (no name) - AutorunsDisabled - (no file) [/quote] And thats it unless you want to get rid of the AOL, Goolge toolbars. -T

Member Avatar for ShaneMcP
0
172
Member Avatar for jonruiz1

Hi, :) Run HJT and check the following. [b] O20 - Winlogon Notify: Shell Extensions - C:\WINDOWS\system32\n2n60c5sef.dll (file missing) O20 - Winlogon Notify: dvd4free - dvd4free.dll (file missing) O18 - Filter: text/html - {CEA53356-C414-4331-A35E-AA4CE9D8DFA2} - C:\WINDOWS\system32\w9seq.dll O2 - BHO: Yvakt Class - {DAAC59E5-093D-4D24-A105-55BFE4ACDE14} - C:\WINDOWS\system32\w9seq.dll (file missing) R3 - Default …

Member Avatar for 'Stein
0
151
Member Avatar for RET1

It is not really needed to keep your computer running. It is related to the nvidia graphic cards. [quote] This application will give the user access to additional features which allow the configuration of up to 32 monitors on a host, or to expand the desktop across many monitors. [/quote] …

Member Avatar for tayspen
0
117
Member Avatar for Jav

Ok, you have a fair amount of nasties. Lets knock some out with scanners before we proceed manually. Download the Free trial version of [color=blue]Spysweeper[/color] [url]http://www.webroot.com/consumer/pro...&rc=4129&ac=tsg[/url] Update the defintions and run it. Then download [color=blue]ewido[/color] [url]www.ewido.net[/url] - Install. Update. Scan. Remove anything it finds. Download [COLOR=Blue][B]smitRem.exe [/B][/COLOR]([url]http://www.bleepingcomputer.com/resources/link240.html)[/url], saving the file …

Member Avatar for tayspen
0
172
Member Avatar for nanagoose

Open volume control and check to see if it is set to 'Mute'. To do this [b]Start>Control Panel>Sounds and audio devices[/b] [i]Your other post is right below this one, you should edit that one, and delete it.[/i]

Member Avatar for tayspen
0
85
Member Avatar for rudeboy

More details... [b]Go to Start>Control Panel>System>Hardware Tab>Device Manager>Mice and other pointing devices.[/b] You should see somthing like [color=blue]PS/2 Compatible Mouse[/color]. Right click on it. -Select Uninstall -Click yes to the dialog -Restart your computer -When its rebooted, it will say it has finished installing new hardware. -Reboot again.

Member Avatar for tayspen
0
84
Member Avatar for nullifi3d

Hi there :). Run HJT again, and place a check next to the following items. [b] O2 - BHO: (no name) - {3E422F49-1566-40D3-B43D-077EF739AC32} - (no file) O3 - Toolbar: (no name) - {5AA06644-BC46-4220-A460-47A6EB47C96D} - (no file) [/b] [color=red]Click Fix Checked[/color] ------------------------------------------------------------------ Then please download ewido - [url]www.ewido.net[/url] - Install. Update. …

Member Avatar for tayspen
0
160

The End.