Steamhead

Members
  • Content Count

    254
  • Joined

  • Last visited

Posts posted by Steamhead

  1. Heya :D

    I just made a new website and was wondering what you guys think of it .. and what you think I could do to make it better o.O

    I know it's kinda bare .. I'm trying to think what I can do to make it looking "fuller". Thanks :D

    edit: yea it's late...

    www.steamster.com

  2. I would love if someone could do me a favor...

    I need to put this image:

    steamster8xf.gif

    ontop of this one:

    bani39ve.jpg

    and it'd be cool if you could take the white out of the first one so it would look ... right I guess...

    I think the colors are going to collide with each other kinda bad ... but I was wondering if I could see what it looked like together...

    any help would be loved!! :D

  3. Hello garmanma.

    Some final clean-up steps.... :) You may want to print this out for reference.

    STEP 1:

    Please open HJT and scan your computer. Place a check next to the following entries:

    O2 - BHO: (no name) - {06C7CAB4-39AC-499F-BCD2-D487DAC7A73C} - C:\WINDOWS\system32\sstqr.dll (file missing)

    O2 - BHO: (no name) - {4D0DA2EA-07AE-44F4-A8D2-627B3EE857E5} - C:\WINDOWS\system32\pmnll.dll (file missing)

    Please close all open windows and click on fix checked.

    aanndd.....

    WE'RE DONE!!!

    You are clean! If you are still having issues please tell me, if not please refer to this prevention speech for tips on how not to get infected again!

    btw.. Panda scan is suppoused to do that, it's not suppoused to be maximized. :)

    The following is a list of tools and utilities that I like to suggest to people. This list is full of great tools and utilities to help you understand how you got infected and how to keep from getting infected again.

    1. Spybot Search & Destroy - Uber powerful tool which can search and annhilate nasties that make it onto your system. Now with an Immunize section that will help prevent future infections.
    2. AdAware - Another very powerful tool which searches and kills nasties that infect your system. AdAware and Spybot Search & Destroy compliment each other very well.
    3. SpywareBlaster - Great prevention tool to keep nasties from installing on your system.
    4. SpywareGuard - Works as a Spyware "Shield" to protect your computer from getting malware in the first place.
    5. IE-SpyAd - puts over 5000 sites in your restricted zone so you'll be protected when you visit innocent-looking sites that aren't actually innocent at all.
    6. CleanUP! - Cleans temporary files from IE and Windows, empties the recycle bin and more. Great tool to help speed up your computer and knock out those nasties that like to reside in the temp folders.
    7. Windows Updates - It is very important to make sure that both Internet Explorer and Windows are kept current with the latest critical security patches from Microsoft. To do this just start Internet Explorer and select Tools > Windows Update, and follow the online instructions from there.
    8. Google Toolbar - Free google toolbar that allows you to use the powerful Google search engine from the bar, but also blocks pop up windows.
    9. Trillian or Miranda-IM - These are Malware free Instant Messenger programs which allow you to connect to multiple IM services in one program! (AOL, Yahoo, ICQ, IRC, MSN)

    To find out more information about how you got infected in the first place and some great guidelines to follow to prevent future infections you can read this article by Tony Klein

  4. Hello jay888, :)

    Let's finish this up!

    STEP 1:

    We need to run ATF Cleaner again.

    • Double-click ATF-Cleaner.exe to run the program.
      Under Main choose: Select All
      Click the Empty Selected button.

    If you use Firefox browser

    • Click Firefox at the top and choose: Select All
      Click the Empty Selected button.
      NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    If you use Opera browser

    • Click Opera at the top and choose: Select All
      Click the Empty Selected button.
      NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    Click Exit on the Main menu to close the program.

    For Technical Support, double-click the e-mail address located at the bottom of each menu.

    STEP 2:

    Please go HERE to run Panda's ActiveScan

    • Once you are on the Panda site click the Scan your PC button
    • A new window will open...click the Check Now button
    • Enter your Country
    • Enter your State/Province
    • Enter your e-mail address and click send
    • Select either Home User or Company
    • Click the big Scan Now button
    • If it wants to install an ActiveX component allow it
    • It will start downloading the files it requires for the scan (Note: It may take a couple of minutes)
    • When download is complete, click on My Computer to start the scan
    • When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to a convenient location. Post the contents of the ActiveScan report

    We're almost done!! :D

  5. Hello garmanma, :)

    Let's finish this up!

    STEP 1:

    We need to run ATF Cleaner again.

    • Double-click ATF-Cleaner.exe to run the program.
      Under Main choose: Select All
      Click the Empty Selected button.

    If you use Firefox browser

    • Click Firefox at the top and choose: Select All
      Click the Empty Selected button.
      NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    If you use Opera browser

    • Click Opera at the top and choose: Select All
      Click the Empty Selected button.
      NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    Click Exit on the Main menu to close the program.

    For Technical Support, double-click the e-mail address located at the bottom of each menu.

    STEP 2:

    Please run another ewido scan and another panda scan. We're almost done!! :D

    Post the logs of all the scans along with one more HJT log. Thanks!

    NOTE: Please rename HijackThis.exe to something like HJT01.exe or something similar. As long as it's not HijackThis.exe, it'll work! Thanks. If you still have propblems renameing it just continue on anyway, :P

  6. Let's see if this works... :)

    Please download VundoFix.exe to your desktop.

    • Double-click VundoFix.exe to run it.
    • Put a check next to Run VundoFix as a task.
    • You will receive a message saying vundofix will close and re-open in a minute or less. Click OK
    • When VundoFix re-opens, click the Scan for Vundo button.
    • Once it's done scanning, click the Remove Vundo button.
    • You will receive a prompt asking if you want to remove the files, click YES
    • Once you click yes, your desktop will go blank as it starts removing Vundo.
    • When completed, it will prompt that it will shutdown your computer, click OK.
    • Turn your computer back on.
    • Please post the contents of C:\vundofix.txt and a new HiJackThis log.

    edit:

    no problem! Take your time! :P

  7. I use killbox more because I know what file I put there to delete is more than likely gonna be deleted.. It greatly lowers the chance of a user deleting the wrong thing because you have them paste what they're going to delete. It also makes it easier because you dont have to explain how to hide / rehide files and you dont have to boot into Safe Mode which saves time and is more user-friendly. :)

  8. Hello garmanma, Happy 4th of July! :) You may want to print this out for reference.

    STEP 1:

    Please download ATF Cleaner by Atribune.

    This program is for XP and Windows 2000 only

    • Double-click ATF-Cleaner.exe to run the program.
      Under Main choose: Select All
      Click the Empty Selected button.

    If you use Firefox browser

    • Click Firefox at the top and choose: Select All
      Click the Empty Selected button.
      NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    If you use Opera browser

    • Click Opera at the top and choose: Select All
      Click the Empty Selected button.
      NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    Click Exit on the Main menu to close the program.

    For Technical Support, double-click the e-mail address located at the bottom of each menu.

    STEP 2:

    Please open HijackThis and check the following entries:

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://red.clientapps.yahoo.com/customize/...//www.yahoo.com

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/...rch/search.html

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/...//www.yahoo.com

    Close all open windows and browsers (except for Hijackthis) and click on "Fix Checked".

    Please post a fresh HijackThis log with a fresh Ewido and Panda scan. Thanks!

  9. Hello Jay888, Happy 4th of July!

    1. Please double-click Killbox.exe to run it.
    2. Select:
      • Delete on Reboot
      • then Click on the All Files button.

    [*]Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\WINDOWS\system32\notepad.dll

    [*] Return to Killbox, go to the File menu, and choose Paste from Clipboard.

    [*]Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt. Click OK at any PendingFileRenameOperations prompt (and please let me know if you receive this message!).

    If your computer does not restart automatically, please restart it manually.

    If you receive a message such as: "Component 'MsComCtl.ocx' or one of its dependencies not correctly registered: a file is missing or invalid." when trying to run Killbox, click here to download and run missingfilesetup.exe. Then try Killbox again.

    Please post a new Ewido log. Thanks!