rmurphy
Members-
Content Count
353 -
Joined
-
Last visited
Content Type
Profiles
Forums
Calendar
Everything posted by rmurphy
-
Please download Malwarebytes' Anti-Malware from Here or Here Double Click mbam-setup.exe to install the application. Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish. If an update is found, it will download and install the latest version. Once the program has loaded, select "Perform Quick Scan", then click Scan. The scan may take some time to finish,so please be patient. When the scan is complete, click OK, then Show Results to view the results. Make sure that everything is checked, and click Remove Selected. Whe
-
Let's try this instead for now. Please download ComboFix from Here or Here to your Desktop. **Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop** Please, never rename Combofix unless instructed. Close any open browsers. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix. ----------------------------------------------------------- Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time pr
-
Open HiJack This and scan. When it finishes, put an X in the box next to these following item(s) O4 - HKCU\..\Run: [spyDefender Shield] "C:\Program Files\SpyDefender Pro\SpyDefender.exe" --scan2 O8 - Extra context menu item: &Viewpoint Search - res://C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBar.dll/CXTSEARCH.HTML O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://zone.msn.com/bingame/dim2/default/popcaploader_v6.cab O18 - Protocol: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - mscoree.dll (file missing) Close all open windows except for HiJack This a
-
Welcome to BestTechie! I'm Ryan, and I'll be helping you clean your computer. Please download SmitfraudFix (by S!Ri) Extract the content (a folder named SmitfraudFix) to your Desktop. Open the SmitfraudFix folder and double-click smitfraudfix.cmd Select option #1 - Search by typing 1 and press "Enter"; a text file will appear, which lists infected files (if present). Please copy/paste the content of that report into your next reply. Note : process.exe is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool"; it is not a virus, but a program used to stop system proces
-
Please download ComboFix from Here or Here to your Desktop. **Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop** Please, never rename Combofix unless instructed. Close any open browsers. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix. ----------------------------------------------------------- Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a sca
-
Redirected Hosts And Few Spyware (hijackthis Logs)[RESOLVED]
rmurphy replied to DarkestDream's topic in Malware Removal
Welcome to BestTechie! I'm Ryan, and I'll be helping you clean your computer. Please download ComboFix from Here or Here to your Desktop. **Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop** Please, never rename Combofix unless instructed. Close any open browsers. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix. ----------------------------------------------------------- Very Important! Temporarily disable your anti-virus, scr -
== Clear Temporary Files == Please download ATF Cleaner by Atribune. This program is for XP and Windows 2000 only Close all Internet Explorer, Firefox, and Opera windows before continuing. Double-click ATF-Cleaner.exe to run the program. Under Main choose: Select All Click the Empty Selected button. If you use Firefox browser Click Firefox at the top and choose: Select All Click the Empty Selected button. NOTE: If you would like to keep your saved passwords, please click No at the prompt. If you use Opera browser Click Opera at the top and choose: Select All Click the Empty Selected button. NO
-
== Remove Programs == Please go to Add/Remove Programs in the Control Panel, and remove the following programs Java 2 Runtime Environment, SE v1.4.2_06 Javaâ„¢ 6 Update 2 Javaâ„¢ 6 Update 3 Reboot your computer. == Install Latest Java == Please go to THIS page, and click on the Download link that is in the Java Runtime Environment (JRE) 6 section. Click the radio button next to Accept License Agreement after reviewing it. The page will refresh - this is normal. Download the Windows Offline Installation, Multi-language. You will want to save this to a location you will remember. Once it
-
Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy): "C:\Program Files\AdwareAlert\bak\AdwareAlert.exe" "C:\Program Files\CCleaner\bak\ccleaner.exe" "C:\Program Files\QuickTime\bak\qttask.exe" "C:\Program Files\Windows Defender\bak\MSASCui.exe" "C:\WINDOWS\system32\bak\hkcmd.exe" "C:\WINDOWS\system32\bak\igfxtray.exe" "C:\WINDOWS\system32\bak\NeroCheck.exe" "C:\Program Files\Alwil Software\Avast4\bak\ashDisp.exe" "C:\Program Files\Grisoft\AVG7\bak\avgcc.exe" "C:\Program Files\HP\HP Software Update\ba
-
== Install Recovery Console == Go to Microsoft's website => http://support.microsoft.com/kb/310994 Select the download that's appropriate for your Operating System. Download the file & save it as it's originally named, next to ComboFix.exe. Now close all open windows and programs, then drag the setup package onto ComboFix.exe and drop it. Follow the prompts to start ComboFix and when prompted, agree to the End-User License Agreement to install the Microsoft Recovery Console. When complete, a log named CF_RC.txt will open. Please post the contents of that log. Please do not reboot you
-
Welcome to BestTechie! I'm Ryan, and I'll be helping you clean your computer. Please download ComboFix from Here or Here to your Desktop. **Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop** Please, never rename Combofix unless instructed. Close any open browsers. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix. ----------------------------------------------------------- Very Important! Temporarily disable your anti-virus, scr
-
Welcome to BEstTechie! I'm Ryan, and I'll be helping you clean you computer. Is that the entire log? If it is, let me know. If you already used HiJack This to fix some items, I need them to be restored in order to see a complete log so I can offer you the best advice that I can. To restore the backups: Open HiJackThis Click on "View the list of Backups" Place a check mark next to everything in that window Click Restore Click Yes Reboot your computer Run HiJackThis and post a new HiJackThis log for review. In any case, I'd like to see an Uninstall List To obtain an Uninstall list. Open HijackT
-
Welcome to BestTechie. I'm Ryan, and I'll be helping you clean your computer. Please download ComboFix from Here or Here to your Desktop. **Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop** Please, never rename Combofix unless instructed. Close any open browsers. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix. ----------------------------------------------------------- Very Important! Temporarily disable your anti-virus, scr
-
Since this issue appears to be resolved ... this Topic has been closed. Glad we could help. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.
-
Please Help Me Remove Hacktool.rootkit[INACTIVE]
rmurphy replied to tonymun's topic in Malware Removal
I'm Ryan, and I'll be helping you clean your computer. Download ComboFix from one of the locations below, and save it to your Desktop. Link 1 Link 2 Link 3 Double click combofix.exe and follow the prompts. Please, never rename Combofix unless instructed. When finished, it shall produce a log for you. Post that log and a HiJackthis log in your next reply Note: Do not mouseclick combofix's window while its running. That may cause it to stall -Ryan -
Welcome to BestTechie! I'm Ryan, and I'll be helping you with your computer. Download ComboFix from one of the locations below, and save it to your Desktop. Link 1 Link 2 Link 3 Double click combofix.exe and follow the prompts. Please, never rename Combofix unless instructed. When finished, it shall produce a log for you. Post that log and a HiJackthis log in your next reply Note: Do not mouseclick combofix's window while its running. That may cause it to stall -Ryan
-
== Remove Programs == Please go to Add/Remove Programs in the Control Panel, and remove the following programs J2SE Runtime Environment 5.0 Update 10 J2SE Runtime Environment 5.0 Update 11 J2SE Runtime Environment 5.0 Update 9 Reboot your computer. == Install Latest Java == Please go to THIS page, and click on the Download link that is in the Java Runtime Environment (JRE) 6 section. Click the radio button next to Accept License Agreement after reviewing it. The page will refresh - this is normal. Download the Windows Offline Installation, Multi-language. You will want to save this to a locati
-
== Clear Temporary Files == Please download ATF Cleaner by Atribune. This program is for XP and Windows 2000 only Close all Internet Explorer, Firefox, and Opera windows before continuing. Double-click ATF-Cleaner.exe to run the program. Under Main choose: Select All Click the Empty Selected button. If you use Firefox browser Click Firefox at the top and choose: Select All Click the Empty Selected button. NOTE: If you would like to keep your saved passwords, please click No at the prompt. If you use Opera browser Click Opera at the top and choose: Select All Click the Empty Selected button. NO
-
Let's see what weneed to do with this computer. Download ComboFix from one of the locations below, and save it to your Desktop. Link 1 Link 2 Link 3 Double click combofix.exe and follow the prompts. Please, never rename Combofix unless instructed. When finished, it shall produce a log for you. Post that log and a HiJackthis log in your next reply Note: Do not mouseclick combofix's window while its running. That may cause it to stall -Ryan
-
Now Receiving Pop Ups With Pop Up Blocker[RESOLVED]
rmurphy replied to medtran51's topic in Malware Removal
Since this issue appears to be resolved ... this Topic has been closed. Glad we could help. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic. -
Just Checking - Please Help Or Reply Nothing Is Wrong?[RESOLVED]
rmurphy replied to jmackin's topic in Malware Removal
Since this issue appears to be resolved ... this Topic has been closed. Glad we could help. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic. -
Now Receiving Pop Ups With Pop Up Blocker[RESOLVED]
rmurphy replied to medtran51's topic in Malware Removal
If you start a new thread for that one, you can just post the link here and I"ll take a look at it. Congratulations, your log is clean For information on how to protect yourself in the future, read Infection Prevention Do you have any other questions or concerns? This thread will be left open for a few more days, so feel free to ask. -Ryan -
Now Receiving Pop Ups With Pop Up Blocker[RESOLVED]
rmurphy replied to medtran51's topic in Malware Removal
Please go to Add/Remove Programs in the Control Panel, and remove the following programs Java 2 Runtime Environment, SE v1.4.2_03 Delete the folloing folder: C:\Program Files\Video ActiveX Access\ Open HiJack This and scan. When it finishes, put an X in the box next to these following item O3 - Toolbar: (no name) - {31615D5C-5126-448A-818A-A7CDFEE85A9B} - (no file) Close all open windows except for HiJack This and click fix checked. Reboot your computer. Please go to THIS page, and click on the Download link that is in the Java Runtime Environment (JRE) 6 section. Click the radio button next -
Now Receiving Pop Ups With Pop Up Blocker[RESOLVED]
rmurphy replied to medtran51's topic in Malware Removal
Please post a new HiJack This log, as well as an Uninstall List. To obtain an Uninstall list. Open HijackThis, click Config, click Misc Tools Click "Open Uninstall Manager" Click "Save List" (generates uninstall_list.txt) -Ryan -
Now Receiving Pop Ups With Pop Up Blocker[RESOLVED]
rmurphy replied to medtran51's topic in Malware Removal
Go to Microsoft's website => http://support.microsoft.com/kb/310994 Select the download that's appropriate for your Operating System. Download the file & save it as it's originally named, next to ComboFix.exe. Now close all open windows and programs, then drag the setup package onto ComboFix.exe and drop it. Follow the prompts to start ComboFix and when prompted, agree to the End-User License Agreement to install the Microsoft Recovery Console. When complete, a log named CF_RC.txt will open. Please post the contents of that log. Please do not reboot your machine until we have reviewe