| Forum Home | ||||
| Press F1 | ||||
| Thread ID: 69228 | 2006-05-26 05:39:00 | WHATS GOING ON??????? | av4tarnz (5829) | Press F1 |
| Post ID | Timestamp | Content | User | ||
| 457878 | 2006-05-26 06:29:00 | Ah ok. Reboot, hold down F8, until u see a menu. Select safe mode. Once you get into safe mode, then run hjijackthis again and tick the previous entries, and tick fix checked. Then reboot. I would also install some kind of firewall, and uninstall that P2P program you're using. This is most probably how you got infected. |
Speedy Gonzales (78) | ||
| 457879 | 2006-05-26 06:56:00 | d | Trev (427) | ||
| 457880 | 2006-05-27 02:50:00 | You also need to remove this p2p virus and its hidden files.... Click Here to download KillBox (www.downloads.subratam.org) Extract the program to your desktop and double-click on its folder, then double-click on Killbox.exe to start the program. In the killbox program, select the Delete on Reboot option. Copy the file names below to the clipboard by highlighting them and pressing Control-C: C:\Program Files\MsConfigs\MsConfigs.exe C:\WINDOWS\system32\p2pnetwork.exe C:\WINDOWS\system32\CMD.COM C:\WINDOWS\system32\netstat.com C:\WINDOWS\system32\ping.com C:\WINDOWS\system32\regedit.com C:\WINDOWS\system32\tasklist.com C:\WINDOWS\system32\taskkill.com C:\WINDOWS\system32\taskmgr.com C:\WINDOWS\system32\tracert.com C:\WINDOWS\system32\rnurbvi.exe C:\Program Files\Common files\SearchUpgrader\SearchUpgrader.exe Return to Killbox, go to the File menu, and choose "Paste from Clipboard". Click the red-and-white "Delete File" button. Click "Yes" at the Delete on Reboot prompt. Click "No" at the Pending Operations prompt. After the reboot run HijackThis again. Check the following items in HijackThis. Close all windows except HijackThis and click Fix checked: O4 - HKLM\..\Run: [P2P Networking] C:\WINDOWS\system32\P2P Networking\P2P Networking.exe /AUTOSTART Reboot once more and post the resulting HijackThis log. |
Pancake (6359) | ||
| 457881 | 2006-05-27 08:34:00 | If we use HiJack this log do we still need virus protection? | MTLance (6768) | ||
| 457882 | 2006-05-27 09:02:00 | If we use HiJack this log do we still need virus protection You still need a virus program.Hijack does not remove files on its own.It only scans and tell you whats in the startup program so that you can post the text so we can see whats going on. |
Pancake (6359) | ||
| 457883 | 2006-05-27 09:32:00 | I bought my computer from the now defunct PC Company. It was a PC Co system restore that was appearing on start-up. Having just read this thread:- pressf1.pcworld.co.nz I really wonder what is going on. |
Sweep (90) | ||
| 457884 | 2006-05-27 09:43:00 | Get the file in my sig below. We'll see what comes up in the log. I can't see your Sig as I have sigs turned off. Think about it. Just post the link as you have done in the past. It seems to me that the be all and end all of fixing all PCs running Windows appears to be fixed by running the Hijack exe and posting a log which you interpret and then advise the poster. Not that you haven't helped because you have. Just thought I would bring to your attention that not everyone has Sigs turned on. |
Sweep (90) | ||
| 457885 | 2006-05-27 09:51:00 | I can't see your Sig as I have sigs turned off. Think about it. Just post the link as you have done in the past. It seems to me that the be all and end all of fixing all PCs running Windows appears to be fixed by running the Hijack exe and posting a log which you interpret and then advise the poster. Not that you haven't helped because you have. Just thought I would bring to your attention that not everyone has Sigs turned on. Well, that was why I put it in my sig. To save me typing it all the time. So, if your sigs are off, thats not my prob. Well HJT / the HJT log does help people out sometimes. As you've seen. Well its either HJT, Spybot, Ewido, or the Smitfraud removal program. That quite a few people have picked up recently. |
Speedy Gonzales (78) | ||
| 457886 | 2006-05-27 09:53:00 | If we use HiJack this log do we still need virus protection? Yes. Hijacking is changing your browser or home page or adding toolbars you don't need or other things. Usually as you have installed Kazaa or other form of P2P. Maybe a FREE screensaver. Maybe a CD you got from a friend. You still need Antivirus and firewall protection as well. When installing any application on your computer do not let it go into the default Folder unless you want it to and don't all the time install other things that may go with it. |
Sweep (90) | ||
| 457887 | 2006-05-27 10:02:00 | Well, that was why I put it in my sig. To save me typing it all the time. So, if your sigs are off, thats not my prob. Well HJT / the HJT log does help people out sometimes. As you've seen. Well its either HJT, Spybot, Ewido, or the Smitfraud removal program. That quite a few people have picked up recently. And other people have sigs turned off as well which was my point. You may have noticed that I do not have a Sig as some can be annoying. I am not saying your Sig is but some are. I have not seen your Sig and I have sigs turned off on purpose. Hope you were not offended. |
Sweep (90) | ||
| 1 2 3 4 | |||||