965 Posted Topics
Re: hmm, did ya buy from a dealer,, or did ya assemble ureself? | |
Re: I dunno if ya already did this,, but did ya set it to show hidden files/microsoft window files? Alrite ,Mystical Chicken, fix a couple more things: [B]O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - c:\program files\partypoker\IEExtension.dll O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - c:\program files\partypoker\IEExtension.dll [/B] (to tayspern) … | |
Re: Well I used Black Ice several years ago, and the only thing that bothered me with it was that it always asked me, every time, whether I wanted the program I had just opened to run. I think I had even tried turning this off, with no avail. Then again, … | |
Re: Hey, welcome to Daniweb. Heh ya, ya got several more infections on your computer, but all can be fixed. Begin by installing Ewido, SpySweeper, and Ewido (links are located below in my signature). Update definitions for these, but DO NOT run yet. After doing this, go into Add/Remove programs, and … | |
Re: EDIT: Outta curiosity, how/why do ya think ya have that virus? Hmmmm, the only thing I see in there is this, but that doesn't mean it isn't there. So run HJT and check: [B]O4 - HKCU\..\Run: [eMuleAutoStart] C:\Program Files\eMule\emule.exe -AutoStart[/B] Then, install Ewido and CCleaner (the links are located in … | |
Re: Alrite, that sounds like a good virus. Fix the following: [B]R3 - Default URLSearchHook is missing O4 - HKLM\..\RunServices: [Microsoft System Support] spool.exe O4 - HKCU\..\Run: [CU2] C:\Program Files\Common Files\VCClient\VCMain.exe O4 - HKCU\..\Run: [CU1] C:\Program Files\Common Files\VCClient\VCClient.exe O15 - Trusted Zone: [url]http://*.billingnow.com[/url] O15 - Trusted Zone: [url]http://*.reliablestats.com[/url] O15 - Trusted … | |
Re: Couple more things to fix. The first file was added by the W32/Chode-J worm, so watch out for that. [B]O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - [url]http://us.dl1.yimg.com/download.yah...nst20040510.cab[/url] O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - [url]http://a1540.g.akamai.net/7/1540/52...meInstaller.exe[/url] [/B] | |
Re: For help about this, there has been a post created about it: It's reply #6 [url]http://www.daniweb.com/techtalkforums/thread28196.html[/url] Sorry it's such a big page, but I'd reccomend just hitting find (ctl + f), and typing in 'about:blank' After running this, say so and post a new long. Then we'll work from there. … | |
Re: Alrite, I see several things. Fix the following: [B] O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE O9 - Extra button: Ladbrokes Poker - {C2A80015-C447-4dc4-82DD-AED83D6ED57E} - C:\Program Files\ladbrokesMPP\MPPoker.exe O16 - DPF: {001EE746-A1F9-460E-80AD-269E088D6A01} (Infotl Control) - [url]http://site.ebrary.com/support/plugins/ebraryRdr.cab[/url] O16 - DPF: {B9A296D4-38AC-4566-8168-F7ACAF7D35E6} (Eyeball Video Session Control) - [url]http://imlive.com/ChatSource/gVideoContol.cab[/url] O23 - Service: MySQL - Unknown owner … | |
Re: Yes, first off, which browser are ya using. Sometimes switching browsers solves the problem (heh PLEASE say ya use Firefox). ALSO, its also very possible the router is blocking the site (oftentimes they have internal firewalls). If we do find that its the router blocking the websites, ya can always … | |
Re: You could also uninstall some of the toolbars for added time. | |
Re: Alrite, great. Could ya please post the HJT log? That would be incredible. Also, what probably wouldnt hurt is to download Ewido anti-malware. This works significantly better then most other spyware cleaners. The link for this is inside my signature I believe ( [url]http://www.ewido.net/en/[/url] ). After downloading, be sure to … | |
Re: Welcome to DaniWeb! Alrite, I see several things wrong with your HJT log. It appears you're infected with several things. Ok, so print this out, and close out of all windows. After doing this, run the HJT, and fix the following: [B]R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = [url]http://mysearch.myway.com/jsp/dellsidebar.jsp?p=DE[/url] R3 - … | |
Re: Alrite, that might not be spyware, but let's double check that. To start, download HijackThis. Instructions for installing and running are located here: [url]http://www.daniweb.com/techtalkforums/thread28196.html[/url] After you run a scan, save a log and copy/paste it into a reply inside this thread. Also, BE SURE to follow the directions inside the … | |
Re: Several more to fix: [B]O4 - HKLM\..\Run: [SpySpotter System Defender] C:\Program Files\SpySpotter3\Defender.exe -startup O4 - HKLM\..\Run: [SpySpotter] C:\Program Files\SpySpotter3\SpySpotter.exe -startup O4 - HKLM\..\Run: [DownloadStudio] C:\Program Files\Conceiva\DownloadStudio\DownloadStudioScheduleMonitor.exe O4 - HKLM\..\Run: [1226345244.exexeg] C:\WINDOWS\system32\1226345244.exexeg O4 - HKLM\..\Run: [1226345244.exehare.exetml4] C:\WINDOWS\system32\1226345244.exehare.exetml4 O4 - HKLM\..\Run: [1226345244.exe] C:\WINDOWS\system32\1226345244.exe O8 - Extra context menu item: Add Page To … | |
Re: Lol thanks alot...if only I was good at this stuff...Ive learned by watchin all u guys. Also, I'd have a membership to ure site, Dani, BUT...I'm not even old enough to have a credit card :mrgreen: Thanks again, anytime I can help I do. | |
Re: Alrite, ya still got several more things to fix, (except, fix these in normal mode, NOT safe mode): [B]O4 - HKLM\..\Run: [MS taskbar] taskbars.exe O4 - HKLM\..\RunServices: [MS taskbar] taskbars.exe O4 - HKCU\..\Run: [MS taskbar] taskbars.exe O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - [url]http://download.games.yahoo.com/gam...aploader_v6.cab[/url][/B] After fixing these, restart, run HJT … | |
Re: Here we are: [B]R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = [url]http://default.home[/url] O2 - BHO: XMLDP Class - {60371670-81B9-4d06-9C42-4DEC1AABE62B} - C:\WINDOWS\xml2lib.dll (file missing) O3 - Toolbar: SToolbar - {0E1230F8-EA50-42A9-983C-D22ABC2EED3B} - C:\WINDOWS\winadvt.dll O4 - HKCU\..\Run: [SMSSU] C:\WINDOWS\System32\SMSSU.EXE O4 - HKCU\..\Run: [Tmntsrv32] C:\WINDOWS\System32\Tmntsrv32.EXE O4 - HKCU\..\Run: [Weather] C:\PROGRA~1\AWS\WEATHE~1\Weather.exe 1 O9 - Extra button: Related … | |
Re: Hi, welcome to DaniWeb. Alrite, first off, download the LSP-Fix ([url]http://www.cexx.org/lspfix.htm[/url]) , save it to the desktop, but DO NOT RUN IT YET. Next, print these off or copy them to a word document, as you'll have to run this in Safe Mode (constantly press F8 while starting up). Run … | |
Re: Man sorry its taken so long to respond...its been an awful month But ya, are ya still having problems? If so, post a new log and we'll work from there. | |
Re: Hah nah, no one's EVER clean Run HJT and fix the following: [B] R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = O2 - BHO: (no name) - {B96B1529-FEB0-441C-844A-3B83AE7D62E8} - C:\WINDOWS\System32\kbdipo.dll (file missing) O16 - DPF: {1C955F3B-5B32-4393-A05D-24B4970CD2A1} - [url]http://stream1000.babenet.com/cabs/videox.cab[/url] O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} - [url]http://us.dl1.yimg.com/download.yah...utocomplete.cab[/url][/B] But ya, other then that, I don't see anything. … | |
Re: Hmm, by any chance, thegu3st, were ya running a web browser when ya tried to fix it? | |
Re: I apolegize its taken us this long to reach you. With that said, are ya still having problems? If so, post back and we'll work from there. Thanks. | |
Re: Sorry its taken us this long to reach ya. With that said, are ya still having problems? If so, post back and we'll work from there. | |
Re: I'm very sorry its taken us this long to reach ya. With that said, do ya still have symptoms? If so, post a new log and we'll work from there. Thanks. | |
Re: I'm awfully sorry it's taken us this long to reach ya. With that said, are ya still having symptoms? If so, post a new log, and we'll work from there. Thanks. | |
Re: Hey, are ya still having problems with it all? I'm sorry its taken us so long to reach ya..its been a hectic month. If you're still having symptoms, post a new long (heh INSIDE the message this time please) and we'll work from there. Thanks. | |
Re: Hi I'm sorry its taken us this long to reach you...its been a hectic month. Are ya still having problems? If so, post a new long and we'll work from there. Thanks. | |
Re: Hmm, ya might want to try running CCleaner: [url]http://www.filehippo.com/download/5...e/download.html[/url] Generally, it finds, among other things, faults in the registry code, etc, which builds up after internet use. This probably won't cure the problem completely, but it may prove significant. Another thing: did the reformat of your computer help the problem … | |
Re: Hmm, I don't see anything wrong with the log. Are ya still having problems? Also, next time ya post a log, copy/paste it into the body of the message, don't enclose it as an attachment. Thanks. | |
Re: Hey First off, I apolegize for the delay--the past several weeks has been apocalyptic. Alrite, I see several things wrong with the log. Run HJT, and fix the following entries: [B]O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file) O4 - Global Startup: Digital Line Detect.lnk = ? [/B] … | |
Re: Mowsart, welcome to Daniweb Alrite, to start it off, you're gonna have to download a program called HijackThis (HJT) that helps diagnose problems on the compuer. Download location, and directions for its use can be found here: [url]http://www.daniweb.com/techtalkforums/thread28196.html[/url] After running the scan (heh, follow the directions please), save a log … | |
Re: Sry for the delay,, what's the problem? By the way, run your HJT and place checks nxt to these: [B]R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\deSrcAs.dll O2 - BHO: (no name) - {4D25F921-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\deSrcAs.dll[/B] After checking and fixing, send another log. | |
Oftentimes when I use the computer, I'll start a program, and, even tho it shows up on the Process List, it doesn't physically run. I've waited a long time, with no results. I also strongly think this is a software problem/computer problem, and doesnt have anything to do with spyware … | |
Re: D3m3nt3d, jus outta curiosity, how'd ya kno it was vundo? (Heh im tryin to learn this stuff :o ) | |
Re: Is it possible ya were running a trial version of Photoshop and ya used up its 'trial days'? I kno many people that have done that. | |
Re: Alrite, not too good. First off, begin by downloading this and saving it to your desktop: [url]http://secured2k.home.comcast.net/tools/VirtumundoBeGone.exe[/url] Then, follow directions, and after it all, post a new log. This thread might help: [url]http://forum.tweakxp.com/forum/Topic190082-29-1.aspx[/url] Thanks | |
Re: Hey, sry for the delay, BUT, run HJT and place checks next to these: [B] R3 - Default URLSearchHook is missing O4 - HKLM\..\Run: [SurfSideKick 3] C:\Program Files\SurfSideKick 3\Ssk.exe O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe" O4 - HKCU\..\Run: [SurfSideKick 3] C:\Program Files\SurfSideKick 3\Ssk.exe[/B] Hmm, so try that, tell me if it's … | |
Re: Hmm, start off by posting a HijackThis log. Insturctions for doing this can be found here: [url]http://www.daniweb.com/techtalkforums/thread28196.html[/url] thanks. | |
Re: Alrite, several things with the HJT log. Please place checks nxt to these entries: [B] O9 - Extra button: 32Red Poker - {437F7F6F-FFCC-47e1-8A4B-C992493CF6C3} - C:\Program Files\32RedMPP\MPPoker.exe O9 - Extra button: CDPoker - {A68FC757-51CF-4f3c-B13A-BFB8CA69BB99} - C:\Program Files\CDPoker\casino.exe O9 - Extra 'Tools' menuitem: CDPoker - {A68FC757-51CF-4f3c-B13A-BFB8CA69BB99} - C:\Program Files\CDPoker\casino.exe O9 - Extra … | |
Re: Heh sry its taken us so long to reach ya--it's been a busy week. But ya, I THINK ya got a Trojan on ure computer, named Troj/Dloader-LO. But there are several things to correct in ure HJT log: [B]R3 - Default URLSearchHook is missing O4 - HKLM\..\Run: [TheMonitor] C:\WINDOWS\SYSC00.exe O4 … | |
Re: Heh, if ya formatted, could ya please mark the thread as 'solved' (its a link near the top). | |
Re: THe only thing I see is the fact that you're running HJT from a Docs and Settings folder. First, create a new folder in Program Files with a title that you'll recognize (ie HJT, spyware help). Then, drag the HJT files into this new folder. Other then that, I don't … | |
Re: Heh sure. Alrite, about the HijackThis, it's easier then it seems. First, you're gonna download the software, but NOT open it. Instead, first create a new folder in the Program Files, and name it HJT. Then, drag the installer folder (what ya downloaded), place it in the new folder made, … | |
Re: Hmmm couple things first,, have ya run Windows Update recently? Your Internet Explorer seems to be out of date possibly. Secondly, which antivirus do ya have? I'd reccomment downloading Ewido Anti-Malware in addition to AVG. AVG – [url]http://free.grisoft.com/doc/2/lng/us/tpl/v5[/url] Ewido - [url]http://www.ewido.net/en/download/[/url] After updating both and running scans, could ya post … | |
Re: Yes indeed. Could ya please post a HijackThis log in a reply? Directions for doing this are enclosed in the following thread: [url]http://www.daniweb.com/techtalkforums/thread28196.html[/url] Thanks. | |
Re: .. EDIT: damn, mispost/wont edit itself out/wont let me delete it, sry... :o | |
Re: Well, I dunno if it helps much, but if ya want free antivirus SCANS, some websites offer some quality scans...most notably: [url]http://www.kaspersky.com/scanforvirus.html[/url] [url]http://housecall.trendmicro.com/[/url] [url]http://us.mcafee.com/root/mfs/default.asp?cid=9914[/url] [url]http://www.ravantivirus.com/scan/[/url] [url]http://www.bitdefender.com/scan/licence.php[/url] For a Spyware scanner, etc,, I'd try Microsoft AntiSpyware (Beta). Its free, and is good for catching things before they start. And, I don't … | |
Re: Well first off, ya need to move and unzip the folder into a permenant folder (ie outside Documents and Settings). I'd say create a new Program Files folder, name it HJT or something, and unzip the HijackThis folder into the Program Files folder. | |
Re: Alrite, Im sorta new at reading, but i think ive found some spyware on here: [B]C:\Program Files\TimeSink\AdGateway\TsAdBot.exe C:\Program Files\AceLogix\Free Ram Optimizer\fro.exe O2 - BHO: CeresObj Class - {00000049-8F91-4D9C-9573-F016E7626484} - C:\WINDOWS\ceres.dll O2 - BHO: Band Class - {00F1D395-4744-40f0-A611-980F61AE2C59} - C:\WINDOWS\dsr.dll O2 - BHO: BestOffers Shopping BHO - {F5DE8ADB-4A69-4e56-96AB-823171C8E9D8} - C:\Program Files\TBONAS\TBONlchr.dll … |
The End.