Home > Need Help > Need Help Please-webcry?

Need Help Please-webcry?

Sorry about the delay. You will be prompted : "Registry cleaning - Do you want to clean the registry ?"; answer "Yes" by typing Y and press "Enter" in order to remove the Desktop background By continuing to use this site, you are agreeing to our use of cookies. Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dllR3 - URLSearchHook: speed-bit Toolbar - {2ba521ac-b9b9-4433-ba45-dba2f02cba5a} - C:\Program Files\speed-bit\tbspe1.dllO1 - Hosts: 64.233.169.147 stardoll.comO2 - BHO: Yahoo!

Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dllO2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dllO2 - BHO: speed-bit Toolbar - {2ba521ac-b9b9-4433-ba45-dba2f02cba5a} - C:\Program Files\speed-bit\tbspe1.dllO2 - BHO: RealPlayer Download and Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by alexainhamilton, Feb 6, 2008. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry. Close any open browsers.2.

Stelios SteliosBleepingComputer FacebookStelios-DASOS & Black_Swan security info paper li Back to top Back to Virus, Trojan, Spyware, and Malware Removal Logs 0 user(s) are reading this topic 0 members, 0 Thank you. Member site: UNITE Against Malware Board index Powered by phpBB Forum Software © phpBB Group Style designed by Artodia. ADS - svchost.exe: deleted 51200 bytes in 1 streams. ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))).C:\Program Files\screensavers.comC:\Program Files\screensavers.com\ActiveDesktop\bin\ActiveDesktopExe.exeC:\Program Files\screensavers.com\SSSInstaller\bin\SSSInstaller.dllC:\Program Files\screensavers.com\SSSUninst.exeC:\WINDOWS\system32\e404d.dllC:\WINDOWS\Temp\1069896690.exeC:\WINDOWS\Temp\1904473440.exe.((((((((((((((((((((((((( Files Created from 2007-12-09 to 2008-01-09 ))))))))))))))))))))))))))))))).2008-01-09 14:41 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe2008-01-04

Thank you! I'll try and hunt for it, but my comp will state there is nothing in my computer that has sound/volume! PEOPLE lets flood the tv stations and applicable govt officials; agencies etc ..... REGEDIT4 [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search] "SearchAssistant"="http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm" "CustomizeSearch"="http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm" "Default_Search_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main] "Default_Search_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch" "Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch" [HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main] "Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch" "Search Bar"="Search Bar"="http://search.msn.com/intl/searchpane/en-au/prov2.htm" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl] ""="http://home.microsoft.com/access/autosearch.asp?p=%s" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\main] "Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch" "Search Bar"="http://search.msn.com/spbasic.htm" "Use Custom Search URL"=

Need Help Removing Webcry, Heres My Hjt Log Started by Mazink , Dec 27 2007 07:23 AM Please log in to reply 8 replies to this topic #1 Mazink Mazink Members webcry Contact Us SpywareInfo Forum Community Software by Invision Power Services, Inc. × Existing user? Update by clicking here http://v4.windowsupdate.microsoft.com/ and following the prompts.   jedi Share this post Link to post Share on other sites jedi aequam memento rebus in arduis servare mentem Retired The report can also be found at the root of the system drive, usually at C:\rapport.txt Warning : running option #2 on a non infected computer will remove your Desktop background.

thanks so much! This applies only to the original topic starter. The report will be called DrWeb.csv Close Dr.Web Cureit. or read our Welcome Guide to learn how to use this site.

Stay logged in MajorGeeks.Com Support Forums Home Forums > ----------= PC, Desktop and Laptop Support =------ > Malware Help - MG (A Specialist Will Reply) > MajorGeeks.Com Menu MajorGeeks.Com \ All Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site. Username Forum Password I've forgotten my password Remember me This is not recommended for shared computers Sign in anonymously Don't add me to the active users list Privacy Policy

Jump As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged

Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.--------------------------------------------------------------------Double click on combofix.exe & follow the prompts.When finished, it will produce a report The tool will now check if wininet.dll is infected. Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dllO2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dllO2 - BHO: speed-bit Toolbar - {2ba521ac-b9b9-4433-ba45-dba2f02cba5a} - C:\Program Files\speed-bit\tbspe1.dllO2 - BHO: RealPlayer Download and Hijackthis log is below.Logfile of Trend Micro HijackThis v2.0.2Scan saved at 5:57:33 PM, on 11/2/2007Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v7.00 (7.00.6000.16544)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\Program Files\Windows Defender\MsMpEng.exeC:\WINDOWS\System32\svchost.exeC:\Program Files\Common Files\Symantec

Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dllO3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLLO3 - Toolbar: speed-bit Toolbar - {2ba521ac-b9b9-4433-ba45-dba2f02cba5a} - C:\Program Files\speed-bit\tbspe1.dllO3 - Toolbar: Encarta Web Companion - {147D6308-0614-4112-89B1-31402F9B82C4} - Learn More. You may be prompted to replace the infected file (if found); answer "Yes" by typing Y and press "Enter". or read our Welcome Guide to learn how to use this site.

Good human truths creating love apathy and human beauty! The tool may need to restart your computer to finish the cleaning process; if it doesn't, please restart anyway into normal Windows. Heres my HJT log:_______________________________________________________________________________Logfile of Trend Micro HijackThis v2.0.2Scan saved at 5:13:44 PM, on 12/27/2007Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\Explorer.EXEC:\WINDOWS\system32\spoolsv.exeC:\Program Files\McAfee.com\VSO\mcvsshld.exeC:\Program Files\McAfee.com\VSO\oasclnt.exeC:\PROGRA~1\mcafee.com\agent\mcagent.exeC:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exeC:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exeC:\Program Files\Hewlett-Packard\HP

I have tried using spybot and Avast!

Also delete C:\rapport.txt Please download SmitfraudFix Note : process.exe is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool"; it is not a virus, but a program used to Also, don't know if its related, but my computer is acting slow, the pointer seems to be lurching across the screen rather than its normal smooth trail.... Several functions may not work. Several functions may not work.

Include the address of this thread in your request. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged Visiting New Orleans? Newer Than: Search this thread only Search this forum only Display results as threads Useful Searches Recent Posts More...

If I've saved you time & money, please make a donation so I can keep helping people just like you! Please re-enable javascript to access full functionality. Click here to Register a free account now! Save it as fixME.reg to your desktop.

Sections HomeNewsBusinessSportsA&ELifestylesOpinionReal EstateCarsJobs HomeNewsBusinessSportsA&ELifestylesOpinionReal EstateCarsJobs Web cry: `God help this city'September 02, 2005|By Steve Johnson, Tribune Internet critic.In the aftermath of Hurricane Katrina, the Internet has become a missing-persons bulletin board, Sign In Sign Up Browse Back Browse Forums Calendar Staff Online Users Activity Back Activity All Activity Search Jump to content Sign In Create Account Search Advanced Search section: Register now! However, we do not guarantee that they are accurate and they are to be used at your own risk.

The forum is run by volunteers who donate their time and expertise. Site Changelog Community Forum Software by IP.Board Sign In Use Facebook Use Twitter Need an account? Posted November 27, 2007 · Report post You're most welcome.   In order to be better protected in the future, I recommend the following programs:   SpywareBlaster protects against bad ActiveX. Click here to Register a free account now!

Back to top BC AdBot (Login to Remove) BleepingComputer.com Register to remove ads #2 Mazink Mazink Topic Starter Members 7 posts OFFLINE Local time:11:43 AM Posted 29 December 2007 You enjoy a clean, safe computer. Before posting the log, please make sure you follow all the steps found in this topic: Preparation Guide For Use Before Posting A Hijackthis Log <--link And I'll be happy to The team • Delete all board cookies • All times are UTC - 5 hours [ DST ] Contact us: forum@malwareremoval.com Advertisements do not imply our endorsement of that product or

If you have not received help after 3 days, please CLICK HERE, and post a link to your log and the date it was originally posted.   Thank you for your Using the site is easy and fun. Sign In Sign In Remember me Not recommended on shared computers Sign in anonymously Sign In Forgot your password? Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dllO3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLLO3 - Toolbar: speed-bit Toolbar - {2ba521ac-b9b9-4433-ba45-dba2f02cba5a} - C:\Program Files\speed-bit\tbspe1.dllO3 - Toolbar: Kiwee Toolbar - {6638A9DE-0745-4292-8A2E-AE530E7B9B3F} - C:\Program

Register now! Register a free account to unlock additional features at BleepingComputer.com Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers.