Okay. I closed the background progs, ran the program and it restarted. It ran again on startup and finished. I then opened HJT but the entries...
Well hello! I wasn't sure why nobody was responding. Well I guess there's no harm in starting over, maybe the fix has been found? I did Windows...
After running Spybot's Teatimer program, here is the log for the past week: -------------- 5/19/2004 11:39:04 AM Allowed value "Add to AD Black...
Here is IE's DLLs. ----- Module information for 'iexplore.exe' MODULE BASE SIZE PATH iexplore.exe 400000 2269184...
Here is the Explorer DLLs using the PV DOS program: ------ Module information for 'Explorer.EXE' MODULE BASE SIZE PATH...
The part of the filemon log that interrests me is this: ------------------------------------- 2382 10:48:36 AM IEXPLORE.EXE:2096 QUERY...
I have a new breakthrough! I'm now running filemon from sysinternals. I had that monitoring my hard drive access before, during, and after being...
Thanks for the info. I'll check it all out and get back to you some day I hope :) I'm still working hard to get rid of the virus I have now,...
You say "we want to avoid anyone to respond other then our classified helpers over there. One wrong reply could end up in a disaster for the...
BTW, on the bottom of the page, is says I "CAN" do these things.
hmmm, I tested about 4 other forums and I could reply there. Only in the addware, spyware and hijack cleaning forum it doesn't let me reply. If I...
For some reason, if I try to reply to any other thread, it says I've been blocked. But at the bottom of the thread, it says I "CAN" post replies,...
I'm keeping a close eye on this subject. Has anybody noticed the alarming trend of messages on this board about home page hijackers? "about:blank"...
STILL DIDN'T WORK!!! I did all this cool stuff, again, and on the last step of my jurney, up pops the virus again. Here is what I did this...
I think, after all this, that the infection must be right in IE itself. Somehow the code has been hijacked so that every so often, when IE is...
Yes, it did come back again. But only just today it started appearing more than once, and the trj/Startpage.ED version started showing up as well....
Here is the log for Panda antivirus: Panda Titanium Antivirus 2004 incident report EVENT DATE...
Thanks for your reply subratam. That is what I do (minus in Safe Mode). The file is never there because Panda deletes it. In the HJT log for the...
This is a rather LARGE log file of registry activity WHILE I was being infected. What I did was clean up the previous infection, close all...
Here is the log from Portscan, just in case there is something here, I don't know. DiamondCS OpenPorts v1.0 (-? for help) Copyright (C) 2003,...
Here is the HJT log which contains the, already cleaned, virus entries. Logfile of HijackThis v1.97.3 Scan saved at 9:37:45 AM, on 5/18/2004...
CWS and trj/Startpage.DI and ED This is the trickiest spyware/CWS/virus/trojan I've ever had to deal with. I need serious expert help here!...
Thanks for the tip. After reading some of that, what it sounds like is that there is yet another DLL, a "super hidden" DLL, which reloads the...
Hi all, this is a common problem I'm sure, so if you would just point me to the proper thread that would be nice, otherwise, let's figure this one...
Separate names with a comma.