therock247uk
Members-
Content Count
960 -
Joined
-
Last visited
Content Type
Profiles
Forums
Calendar
Everything posted by therock247uk
-
Please read this post completely, it may make it easier for you if you copy and paste this post to a new text document or print it for reference later. This will likely be a few step process in removing the malware that has infected your system. I encourage you to stick with it and follow my directions as closely as possible so as to avoid complicating the problem further. You have a nasty CoolWebSearch infection. First we will need to download a few tools that will help us in the removal of your problem. Download about:buster by RubbeRDuckY Here. Download CWShredder Here. Download SpSeHjfix
-
Your log is clean Here are some tips, to reduce the potential for spyware infection in the future, I strongly recommend installing the following applications: Spywareblaster <= SpywareBlaster will prevent spyware from being installed. Spywareguard <= SpywareGuard offers realtime protection from spyware installation attempts. How to use Ad-Aware to remove Spyware <= If you suspect that you have spyware installed on your computer, here are instructions on how to download, install and then use Ad-Aware. How to use Spybot to remove Spyware <= If you suspect that you have spyware insta
-
1. Download about:buster by RubbeRDuckY Here. Save the file somewhere you will remember like to the Desktop. Please run about:buster by RubbeRDuckY: Unzip the contents of AboutBuster.zip and an AboutBuster directory will be created. Navigate to the AboutBuster directory and double-click on AboutBuster.exe. Click "OK" at the prompt with instructions. Click "Update" and then "Check For Update" to begin the update process. If any updates exist please download them by clicking "Download Update" then click the X to close that window. Boot into safemode again Open About:buster again Click Start and
-
1. Make sure your PC is set to show all hidden files and folders go here for instructions on how to do this. http://www.xtra.co.nz/help/0,,4155-1916458,00.html 2. Open Hijackthis and click scan. Then tick and fix the following in Hijackthis with all windows closed except Hijackthis. R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file) O2 - BHO: (no name) - {ED103D9F-3070-4580-AB1E-E5C179C1AE41} - (no file) O4 - HKLM\..\Run: [picsvr]
-
Post a new Hijackthis log.
-
You have Microsoft AntiSpyware and SpywareGuard running disable them then try.
-
It will do open Internet explorer go to tools > Internet options and change the setting to your homepage that you want.
-
Your log is clean Here are some tips, to reduce the potential for spyware infection in the future, I strongly recommend installing the following applications: Spywareblaster <= SpywareBlaster will prevent spyware from being installed. Spywareguard <= SpywareGuard offers realtime protection from spyware installation attempts. How to use Ad-Aware to remove Spyware <= If you suspect that you have spyware installed on your computer, here are instructions on how to download, install and then use Ad-Aware. How to use Spybot to remove Spyware <= If you suspect that you have spyware insta
-
Ok download a newer Hijackthis version 1.99.1 from http://merijn.org/files/HijackThis.exe and post a new log here in a reply from it. Also see if you can find the file wauctlxp4.exe by showing all hidden files go here for instructions. http://www.xtra.co.nz/help/0,,4155-1916458,00.html
-
1. Go into safemode by tapping f8 when the PC starts up you will get a menu select safemode. 2. Open Hijackthis and click scan. Then tick and fix the following in Hijackthis with all windows closed except Hijackthis. O2 - BHO: (no name) - {0E234239-88FF-11D2-8446-D7234234421F} - C:\WINNT\system32\msasmsn7.dll (file missing) O4 - HKLM\..\Run: [sndPnpMix] C:\WINNT\system32\wauctlxp4.exe 3. Delete the files. C:\WINNT\system32\wauctlxp4.exe 4. Reboot back into normal mode and post a new Hijackthis log here in a reply.
-
1. Open Hijackthis and click scan. Then tick and fix the following in Hijackthis with all windows closed except Hijackthis. If Spywareguard asks you for any changes say yes. R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = , O2 - BHO: (no name) - {0E234239-88FF-11D2-8446-D7234234421F} - C:\WINNT\system32\msasmsn7.dll O4 - HKLM\..\Run: [PerformCl] C:\WINNT\system32\perfcl.exe O4 - HKLM\..\Run: [sndPnpMix] C:\WINNT\system32\wauctlxp4.exe 2. Reboot and delete the files. C:\WINNT\system32\msasmsn7.dll C:\WINNT\system32\perfcl.exe C:\WINNT\system32\wauctlxp4.exe 3. Then post a
-
Hijack Log - Apparent Cws Trojan Infection
therock247uk replied to cultchie_girl's topic in Malware Removal
No problem moving this topic into the Hijackthis logs resolved forum. -
Hijack Log - Apparent Cws Trojan Infection
therock247uk replied to cultchie_girl's topic in Malware Removal
Your log is clean Here are some tips, to reduce the potential for spyware infection in the future, I strongly recommend installing the following applications: Spywareblaster <= SpywareBlaster will prevent spyware from being installed. Spywareguard <= SpywareGuard offers realtime protection from spyware installation attempts. How to use Ad-Aware to remove Spyware <= If you suspect that you have spyware installed on your computer, here are instructions on how to download, install and then use Ad-Aware. How to use Spybot to remove Spyware <= If you suspect that you have spyware insta -
Hijack Log - Apparent Cws Trojan Infection
therock247uk replied to cultchie_girl's topic in Malware Removal
1. Open Hijackthis and click scan. Then tick and fix the following in Hijackthis with all windows closed except Hijackthis. R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.searchby.net/ 2. Then post a new Hijackthis log here in a reply. -
1. Go to Start > Settings > Control panel > Add/remove and uninstall Viewpoint Manager. 2. Open Hijackthis and click scan. Then tick and fix the following in Hijackthis with all windows closed except Hijackthis. R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/.../search/ie.html R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/.../search/ie.html R1 - HKCU\Software\Microsoft\Internet Explore
-
Hijack Log - Apparent Cws Trojan Infection
therock247uk replied to cultchie_girl's topic in Malware Removal
1. Download about:buster by RubbeRDuckY Here. Save the file somewhere you will remember like to the Desktop. Please run about:buster by RubbeRDuckY: Unzip the contents of AboutBuster.zip and an AboutBuster directory will be created. Navigate to the AboutBuster directory and double-click on AboutBuster.exe. Click "OK" at the prompt with instructions. Click "Update" and then "Check For Update" to begin the update process. If any updates exist please download them by clicking "Download Update" then click the X to close that window. Boot into safemode again. Open About:buster again Click Start and -
Hijack Log - Apparent Cws Trojan Infection
therock247uk replied to cultchie_girl's topic in Malware Removal
1. Go into safemode again. 2. While in safemode open Hijackthis and click scan. Then tick and fix the following in Hijackthis with all windows closed except Hijackthis. R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.searchby.net/ R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://uk.red.clientapps.yahoo.com/customi...arch.yahoo.com/ O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\en-gb\msntb.dll (file missing) O4 - HKLM\..\Run: [sdkuf32.exe] C:\WINDOWS\sdkuf32.exe O23 - Serv -
Hijack Log - Apparent Cws Trojan Infection
therock247uk replied to cultchie_girl's topic in Malware Removal
1. Make sure your PC is set to show hidden files http://www.xtra.co.nz/help/0,,4155-1916458,00.html Go into safemode go here for instructions. http://service1.symantec.com/SUPPORT/tsgen...001052409420406 2. While in safemode open Hijackthis and click scan. Then tick and fix the following in Hijackthis with all windows closed except Hijackthis. R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\engcm.dll/sp.html#28129 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\engcm.dll/sp.html#28129 R1 - HKLM\Software\Microsoft\Internet Exp -
/me is always in chat
-
No if you have the problem again post a new log. This thread will be moved into a read only forum HijackThis Logs (Resolved) soon.
-
Log looks clean Are you having any problems?
-
1. Disable Spybots teatimer and SpySweeper. 2. Open Hijackthis and click scan. Then tick and fix the following in Hijackthis with all windows closed except Hijackthis. O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file) O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file) 3. Reenable Spybots teatimer and SpySweeper and post a new Hijackthis log here in a reply.
-
Can you post a new fresh Hijackthis log things might of changed a little from your last log.
-
1. Open Hijackthis and click scan. Then tick and fix the following in Hijackthis with all windows closed except Hijackthis. R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = O2 - BHO: Zero Popup Pro - {EB23F789-F17F-4bcc-988B-6B70A3A67E9C} - G:\PROGRA~1\Internet\Schutz\ZEROPO~1\ZERO-P~1.DLL 2. Reboot and delete the folder. G:\Program Files\Internet\Schutz\ZEROPO~1 < Folder starts with ZEROPO 3. Then post a new Hijackthis log here in a reply.
-
1. Open Hijackthis again and click scan. Then tick and fix the following in hijackthis with all windows closed except Hijackthis. O4 - HKLM\..\Run: [Norton Antivirus AV] C:\WINNT\FVProtect.exe 2. Reboot and delete the files. You may need to have show hidden files on go here for instructions. http://www.xtra.co.nz/help/0,,4155-1916458,00.html C:\WINNT\FVProtect.exe 3. Then post a new Hijackthis log here in a reply.