Keep this forum alive - I'm a volunteer and it's my pleasure to serve, but the SWI site needs your donations to operate.

Just post back when my above instructions are completed. 0 #5 cscribe19 Posted 21 May 2006 - 01:56 PM cscribe19 Member Topic Starter Member 30 posts I found new net listed The problem I am having now is that Ad-Aware seems to get stuck during the "Deleting" process. It probably really would be just quicker to backup everything and format and re-install. Back to top #6 Needs Needs Newbie Members 5 posts Posted 15 June 2007 - 11:38 PM Logfile of HijackThis v1.99.1Scan saved at 15:38, on 2007-06-15Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE:

Lots to back up on his computer, but guess it wouldn't be that hard. Really? Just to be sure that nothing gets left behind Please do not PM me asking for support. You will see 2 panels.

I already had Ad-Aware on this computer, but I did make the changes in the configuration menu like you suggested. Sdallnct03-27-06, 06:50 PMO15 - Trusted Zone: * O15 - Trusted Zone: hp:// (HKLM) O15 - Trusted Zone: hp:// (HKLM) O15 - Trusted Zone: hp:// (HKLM) It's pretty bad when they get Stefahknee, Oct 4, 2016, in forum: Virus & Other Malware Removal Replies: 0 Views: 206 Stefahknee Oct 4, 2016 In Progress Help diagnosing Hijackthis log, thanks! Hijackthis Windows 10 De-select all boxes so that it does not run.

Click the red-and-white Delete File button. Thanks,MarkThis logs pretty bad... How come all of the purchased programs like Noadware, Norton Antivirus, Webroot, Ewido, Ad-Aware, Spybot would not take care of it on their own? First Pass Completed Second Pass Scanning Second pass Completed! 1 file(s) copied. 1 file(s) copied. 1 file(s) copied. 1 file(s) copied. 1 file(s) copied. 1 file(s) copied. 1 file(s) copied. 1

You are so heavily infected and this may take a few posts to clean out all the numerous infections you have.First, Download LSPFix.exe to a convenient location. Hijackthis Download Windows 7 I have unchecked the requested processes during startup, downloaded and installed HijackThis in the appropriate folder, deleted the contents of C:\WINDOWS\temp and created another HijackThis log. I have not had time to put together a large "network" drive, so thought I pick up this for some temp storage. Please post the final results, good or bad.

No, create an account now. Your desktop and icons will disappear (this is normal). Hijackthis Log Analyzer It pays the bills right now. Hijackthis Trend Micro Oh and I have a dvd writer in our office computer, but would it be a good idea to show his C drive as "shared" and back up to DVD with

Also check for updates:Ad-Aware SE SetupAgain, do NOT run a scan yet.* Please download Brute Force Uninstaller.Unzip it to itís own folder (c:\BFU)RIGHT-CLICK HERE and choose "Save As" (in IE it's After you have the program handy (this is just for in case), you can try to fix these: C:\WINDOWS\onhbsqe.exe C:\windows\mousepad5.exe C:\windows\rlvknlg.exe C:\WINDOWS\system32\1D1C1F24232327.exe C:\WINDOWS\sys01310745731.exe C:\WINDOWS\win3209131074573.exe C:\WINDOWS\onhbsqeA.exe C:\Program Files\EQAdvice\EQAdvice.exe C:\WINDOWS\system32\srshost.exe C:\WINDOWS\system32\lwinnsag.exe C:\WINDOWS\ABox.exe R3 When I ran highjackthis again, these were all gone. If nothing is listed under the "Remove Panel", do NOT do anything - just close the program. Hijackthis Windows 7

After reading a few posts here, I decided to run Ad-Aware in Safe Mode. Back to top #8 Dragonchaser Dragonchaser Topic Starter Members 7 posts OFFLINE Local time:12:56 PM Posted 25 March 2006 - 08:57 PM I do play a lot of poker, usually Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quietO4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exeO4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exeO4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exeO4 navigate here Total of file sizes: 995,383 bytes 972.05 K ********************************************************************************** Directory Listing of system files: Volume in drive C is LAPTOP Volume Serial Number is 0745-15F0 Directory of C:\WINXP\System32 03/24/2006 06:37 PM

I can see where he has been and doesn't seem all that bad. How To Use Hijackthis Expand "Scanning Engine" by clicking on the "+" (Plus) symbol and select the following: "Unload recognized processes during scanning." "Obtain command line of scanned processes" "Scan registry for all users instead He is not a computer geek as he doesn't even know enough to clear history, etc.

If you have a previous version of Ad-Aware installed, during the installation of the new version you will be prompted to uninstall or keep the older version - be sure to It looks to be a little more than I can handle..I'm calling a friend over for some help, thanks for getting me started and I'll post again when I'm ready for Logfile of HijackThis v1.99.1 Scan saved at 5:55:51 PM, on 3/27/2006 Platform: Windows ME (Win9x 4.90.3000) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\SYSTEM\KERNEL32.DLL C:\WINDOWS\SYSTEM\MSGSRV32.EXE C:\WINDOWS\SYSTEM\mmtask.tsk C:\WINDOWS\BCMDMMSG.EXE C:\WINDOWS\SYSTEM\MPREXE.EXE C:\WINDOWS\SYSTEM\MSTASK.EXE C:\WINDOWS\SYSTEM\SSDPSRV.EXE Hijackthis Portable If we have ever helped you in the past, please consider helping us.

A case like this could easily cost hundreds of thousands of dollars. Oh and I have a dvd writer in our office computer, but would it be a good idea to show his C drive as "shared" and back up to DVD with Even for an advanced computer user. his comment is here You need to place a checkmark in it first and then click OK.

Download both files (program and virus signatures) to the same folder on the PC. It worked great!!!!!!!