818 Posted Topics
Re: You could try [COLOR=Blue]ewido[/COLOR] - [url]www.ewido.net[/url] - it should take care of a lot of the stuff, but if you don't think it got it all or if you just want to make sure. [url=http://www.merijn.org/files/hijackthis.zip]Download hijackThis[/url]. Extract it to its [color=red]own[/color] folder. Then run it and select. [b]Do system scan … | |
Re: [url=http://www.merijn.org/files/hijackthis.zip]Download hijackThis[/url]. Extract it to its [color=red]own[/color] folder. Then run it and select. [b]Do system scan and save log[/b]. Post the contents of the log that pops up. We will then work from there in determining your problem... | |
Re: You log shows no sign of infection, if you want to try with another scanner try [color=blue]ewido[/color] ( [url]www.ewido.net[/url] ). You could also try [color=blue]CCleaner[/color] ( [url]www.ccleaner.com[/url] ) that will delete the temporary files, and maybe speed up your internet. | |
Re: Hi, first Please download [url=http://www.atribune.org/ccount/click.php?id=4]VundoFix.exe[/url] to your desktop. * Double-click VundoFix.exe to run it. * Click the Scan for Vundo button. * Once it's done scanning, click the Remove Vundo button. * You will receive a prompt asking if you want to remove the files, click YES * Once you … | |
Re: Hi, Please download HJT. [url=http://www.merijn.org/files/hijackthis.zip]Download hijackThis[/url]. Extract it to its [color=red]own[/color] folder. Then run it and select, [b]Do system scan and save log[/b]. Post the contents of the log that pops up. Please start your own thread next time... Thanks. | |
Re: First download [color=blue]PocketKillBox[/color] Download pocket killbox from [url]http://www.thespykiller.co.uk/files/killbox.exe[/url] & put it on the desktop where you can find it easily. Now Start killbox Copy the list of files below to the clipboard by selecting all of them with your mouse (Left click the start of the list and drag the … | |
Re: Hi, please run HJT again, select [b]Do system scan only[/b] and check the following. [b] O1 - Hosts: 134.96.33.102 crmud01 O1 - Hosts: 134.96.33.103 crmud02 O1 - Hosts: 134.96.33.105 crmud04 O2 - BHO: IE - {D157330A-9EF3-49F8-9A67-4141AC41ADD4} - C:\WINDOWS\DOWNLO~1\CnsHook.dll O4 - HKLM\..\Run: [CnsMin] Rundll32.exe C:\WINDOWS\DOWNLO~1\CnsMin.dll,Rundll32 O9 - Extra button: QQ - … | |
Re: This is a trojan file right here. [b] C:\WINDOWS\msnmgr.exe [/b] It is a service so first we need to disable it then delete it. To do this: [quote] Start>Run type Services.msc -Right click [color=red] Windows XP Manager (Manager)[/color] and choose Stop -Now choose Properties and change Startup Type to disabled … | |
Re: Hi, lets get you all cleaned up :). Please do the following. Download [B]smitRem.exe [/B]([url]http://www.bleepingcomputer.com/resources/link240.html)[/url], saving the file to your desktop. [B]Double click[/B] it to extract the contents to a folder of it's own. Restart your computer in [url=http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001052409420406]safe mode[/url], logon to the user account that is infected, open the … | |
Re: Hi, please run HJT and check the following. [b] R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = [url]http://searchbar.findthewebsiteyouneed.com[/url] R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = [url]http://searchbar.findthewebsiteyouneed.com[/url] R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = [url]http://searchbar.findthewebsiteyouneed.com[/url] R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = [url]http://searchbar.findthewebsiteyouneed.com[/url] R3 - URLSearchHook: (no name) - {02EE5B04-F144-47BB-83FB-A60BD91B74A9} - (no file) F2 - REG:system.ini: Shell=Explorer.exe, … | |
Re: Hi, and welcome to Daniweb! Please Run HJT again and put a check next to the following items. [b] R1 - HKLM\Software\Microsoft\Internet Explorer\SearchURL,(Default) = [url]http://my.netzero.net/s/search?r=minisearch[/url] R3 - URLSearchHook: (no name) - _{02EE5B04-F144-47BB-83FB-A60BD91B74A9} - (no file) O9 - Extra button: (no name) - {4ABF810A-F11D-4169-9D5F-7D274F2270A1} - (no file) O9 - Extra 'Tools' … | |
Re: What do you need help with? A specific problem? If so post you code, and explain your problem. You need to be more descriptive. | |
Re: Please download [url=http://www.atribune.org/ccount/click.php?id=4]VundoFix.exe[/url] to your desktop. * Double-click VundoFix.exe to run it. * Click the Scan for Vundo button. * Once it's done scanning, click the Remove Vundo button. * You will receive a prompt asking if you want to remove the files, click YES * Once you click yes, … | |
Re: You got quite a collection ;). Please start by doing the following. Download the Free trial version of [color=blue]Spysweeper[/color] [url]http://www.webroot.com/consumer/pro...&rc=4129&ac=tsg[/url] Update the defintions and run it, let it remove whatever it finds. Then download [color=blue]ewido[/color] [url]www.ewido.net[/url] - Install. Update. Scan. Remove anything it finds. Then download [color=blue]CCleaner[/color] Run it and … | |
Re: Hi, and welcome Run HJT again, Check these items. [b] O2 - BHO: Nothing - {7a932ed2-1737-4ab8-b84d-c71779958551} - C:\WINDOWS\system32\hp7CB.tmp [/b] Click [COLOR=Red]Fix Checked[/COLOR] Download [B]smitRem.exe [/B]([url]http://www.bleepingcomputer.com/resources/link240.html)[/url], saving the file to your desktop. Double click it to extract the contents to a[B] folder of it's own[/B]. Restart your computer in [B]safe mode[/B], … | |
Re: You have inded. You have quite a bit of nassties int here ;). Run HJT again and put a check next to the following items. [b] R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = [url]http://searchbar.findthewebsiteyouneed.com[/url] R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = [url]http://searchbar.findthewebsiteyouneed.com[/url] R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = [url]http://searchbar.findthewebsiteyouneed.com[/url] R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant … | |
Re: Hi, you are indeed infected. Please run HJT again, select "Do system Scan Only". Then put a check next to these items. [b] O2 - BHO: InfoDocReader Object - {295BA105-3506-4D25-B0DD-54346320BDC5} - C:\WINDOWS\system32\ddcyy.dll O20 - Winlogon Notify: ddcyy - C:\WINDOWS\system32\ddcyy.dll [/b] Click[COLOR=Red] Fix Checked[/COLOR] Please download [url=http://www.atribune.org/ccount/click.php?id=4]VundoFix.exe[/url] to your desktop. * … | |
Re: I just contributed a little :). Guess your a lil' closer to that database server ;). | |
Re: Also, We need to configure windows to crash to a blue screen, that way we can get more info. Thing is I dont remember how to do that. If somebody knows please share. Then when you computer crashes to a blue screen, post the exact message. | |
Re: That is correct. So when you go to [b]Start>Run> and type [color=red]regedit[/color][/b] That comes up? If so I am pretty sure you have a virus. If you belive you have a virus, please download [url=http://www.merijn.org/files/hijackthis.zip]Hijackthis[/url], Extract it to its own folder, run it, and select "Do system scan and save … | |
Re: Man, viruses love you :). We just cleaned you up a few weeks ago ;). Please run HJT again, and check the following. [b] O20 - Winlogon Notify: winabi32 - winabi32.dll (file missing) [/b] Click Fix Checked. Thats really all I see. I think you may have just installed SP2. … | |
Re: Run HJT. Click [b]Do system scan only[/b]. Place a check next to the items above. Click [b]Fix Checked[/b] | |
Re: Your HJT log is [b]clean[/b]. As for the rebooting. - Has it crashed to a blue screen yet? If so what was the message? - Did you recently add any new hardware, or software? - Are you getting any messages on reboot? | |
Re: You have a few viruses ;). Please run HijackThis again, select [b]Do system scan[/b]. Place a check in the check box next to these items. [b] R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\about.htm O2 - BHO: Nothing - {4da4616d-7e6e-4fd9-a2d5-b6c535733e22} - C:\WINDOWS\system32\hpC6A.tmp O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program … | |
Re: Hi, and welcome :). Nothing looks to malicious in you log, but lets run some scans just to be sure. Then download [color=blue]ewido[/color] [url]www.ewido.net[/url] - Install. Update. Scan. Remove anything it finds. Then download [color=blue]CCLeaner[/color] [url]www.ccleaner.com[/url] - Install. Let it clean. [b]Post a new HJT log, and the ewido log[/b] | |
Re: Yea, you have a small collection of nasties. Please run HJT again and select [b]Do system scan only[/b]. Then place a check in the checkbox next to these items. [b] O2 - BHO: Nothing - {4da4616d-7e6e-4fd9-a2d5-b6c535733e22} - C:\WINDOWS\system32\hpA22B.tmp O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - [url]http://static.windupdates.com/cab/CDT/ie/bridge-c46.cab[/url] [/b] Close all brwosers and click … | |
Re: Hi, and welcome to DaniWeb! This line of your log [b] C:\Documents and Settings\PETER\Local Settings\Temporary Internet Files\Content.IE5\GTORK5WN\hijackthis[1]\HijackThis.exe [/b] Shows that HJT was run from a Temporary file. This is an "unsafe" location, as it may not scan everything. Please do the following. Re-Downoad HJT, and save it your desktop. Then … | |
Re: Was it software that did stuff like virtual drives, or any thing like that? Or was it just you average application. In other words, do you think the App makes system changes? | |
Re: Same thing for me to. Tried to go to the home page, yet it took me to. [quote] [url]www.daniweb.com/profile.php[/url] [/quote] Hasn't happened since though. | |
Re: Hi, I hate to say this, but your HJT version is out of date. Please download and scan with the newest version ([b]1.99.1[/b]). [url=http://www.merijn.org/files/hijackthis.zip]Download hijackThis (1.99.1) [/url]. Extract it to its [color=red]own[/color] folder. Then run it and select. [b]Do system scan and save log[/b]. Post the contents of the log … | |
Re: Hi, you are running an older version of HJT. We need to scan with the latest version. [url=http://www.merijn.org/files/hijackthis.zip]Please download the latest version[/url]. Extract it to its [color=red]own[/color] folder. Then run it and select. [b]Do system scan and save log[/b]. Post the contents of the log that pops up. | |
Re: This line, [b]C:\DOCUME~1\Sam\LOCALS~1\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe[/b] Shows that HJt was run from an "Unsafe" location (Temporary Folder). It needs to be in its own folder. To do this follow these instructions. Right click [url=http://www.merijn.org/files/hijackthis.zip]HERE[/url] (Or if your not using Internet Explorer, just click and save.) And Click "Save Target … | |
Re: [url]www.codeless.org[/url] | [url]www.csharphelp.com[/url] | [url]www.programmingforums.org[/url] | [url]www.csharp-station.com[/url] | [url]www.codeproject.com[/url] | [url]www.vbforums.com[/url] That should do it ;). | |
Hi, when loading certain pages, it seems that the ads can't load. Therefore leaving a bunch of page load errors on my screen ;). Not sure why this would be, but though I would point it out. Look at SS to see what I mean. (Same thing happens in IE … | |
Re: Please do this. Please [B]download[/B] [url=http://www.atribune.org/ccount/click.php?id=4]VundoFix.exe[/url] to your desktop. * Double-click [B]VundoFix.exe[/B] to run it. * Click the [B]Scan for Vundo[/B] button. * Once it's done scanning, click the[B] Remove Vundo button[/B]. * You will receive a prompt asking if you want to remove the files, click [B]YES[/B] * Once … | |
Re: Your HJT version is out of date. In order to make sure it scanning everything. [url=http://www.merijn.org/files/hijackthis.zip]Please download the newest version[/url]. Extract it to its [color=red]own[/color] folder. Then run it and select. [b]Do system scan and save log[/b]. Post the contents of the log that pops up. | |
Re: Hi, and welcome to Daniweb. Run HJt again, and check the following. [b] O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} (cpbrkpie Control) - [url]http://a19.g.akamai.net/7/19/7125/1...02/cpbrkpie.cab[/url] [/b] Click "Fix Checked". Nothing else in your log looks particuarly malicious. Just to make sure though, lets download [color=blue]ewido[/color], it should take care of the misc. stuff. [B] … | |
Re: Was that a "I have no idea what I should use" kinda "...", if so may I suggest [url=http://free.grisoft.com/doc/1]AVG Free Edition[/url], as you may have guessed it is free, and is very good at what it does, also unlike Norton it is easy on the resources :). | |
Re: Hi, run HJT again, and check these. [b] R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = prosearching.com R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = [url]http://www.2020search.com/search/9884/search.html[/url] R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = prosearching.com R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = prosearching.com R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = prosearching.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = prosearching.com R1 - HKLM\Software\Microsoft\Internet … | |
Re: Please start by doing the following. Download the Free trial version of [COLOR=Blue]Spysweeper [/COLOR] [url]http://www.webroot.com/consumer/pro...&rc=4129&ac=tsg[/url] Update the defintions and run it, let it remove whatever it finds. Then download [COLOR=Blue]ewido[/COLOR] [url]www.ewido.net[/url] - Install. Update. Scan. Remove anything it finds. Then download [COLOR=Blue]CCleaner[/COLOR] Run it and let it clean. Web hancer … | |
Re: [COLOR=Red]You may need to print these instructions as you wont have access to the internet insafe mode.[/COLOR] Hi, your pretty infected. For this fix please boot into safe mode, and configure windows to show hidden folders. First though download the following, dont do anything yet. Please download [url=http://www.atribune.org/ccount/click.php?id=7]Look2Me-Destroyer.exe[/url] to your … | |
Re: Well, we could make sure it is not a virus or spyware...As I think [b]MWSBAR.DLL[/b] is part of the [color=red]MyWebSearch[/color] infection. [url=http://www.merijn.org/files/hijackthis.zip]Download hijackThis[/url]. Extract it to its [color=red]own[/color] folder. Then run it and select. [b]Do system scan and save log[/b]. Post the contents of the log that pops up. | |
Re: Hi, please do the following. [url=http://www.merijn.org/files/hijackthis.zip]Download HijackThis[/url]. Extract it to its [color=red]own[/color] folder. Then run it and select. [b]Do system scan and save log[/b]. Post the contents of the log that pops up. That should get us going. Also, go ahead and do this. Download [B]smitRem.exe[/B] ([url]http://www.bleepingcomputer.com/resources/link240.html)[/url], saving the file … | |
Re: Hi, and welcome to Daniweb! [color=red]You may need to print these instuctions, as you wont have access to the internet in safe mode[/color] We will need to boot into [B]safe mode[/B], and have windows s[B]how hidden files[/B]. To do this: [quote] 1 Click the Start Button 2 In the Start … | |
Re: I see no sign of infection. If you disabled items from starting on boot-up. Please re-enable them (as somtimes they can be malware, and if they are we need to get rid of it), [b]Reboot[/b] and post a new log. | |
Re: Well, since you can't dive by zero, thats why its thorowing the error... You could just use try catch blocks. Or if you post your code, we could help you with better error handling. If you use try catch block... [code] try{ //The calculator main code...Where the error is getting … | |
Re: Hi, you log looks [b]clean[/b] to me. As far as your computer running slowly, perhaps you should run the disk defragger, or disk clean up. Disk Defrag info - [url]http://www.geekgirls.com/windows_defrag.htm[/url] Disk cleanup info - [url]http://www.udel.edu/topics/virus/security/diskcleanup.html[/url] | |
Re: Heh, yea I would say it need to go, lets wait to see what demented has to say though. Any ways, also have HJT fix this, if you dont reconize it, or dont play online poker. [b] O16 - DPF: {1A781DED-C22D-4153-3213-A3211E29DF13} (GameDesire Card Games) - [url]http://67.15.101.3/g_bin/eng/cards_2_0_0_67.cab[/url] O20 - Winlogon Notify: … |
The End.