Over 1 million tech questions and answers.

JRt removes duckduckgo. Why

Q: JRt removes duckduckgo. Why

Hi, I downloaded thisusu's jrt and scanned. while scanning, it usually scans and remove the PUPs and malware. I recently tried duckduckgo browser, and searching instead of google search engine, which is storing all the private information. But, after scan, this search engine was removed by JRT. As I downloaded most programs from Bleeping computers, I raise this query.
                                  It seems that thisusu only recognizes the ie,firefox and chrome browsers and removes any other browsers. Of course, the duckduckgo, does not have a separate browser but I think it is a harmless browser, unlike Babylon , incredible , or mysearch browser hijacks. Would any one throw light on it. I do not know how to write in thisusu.org.

RELEVANCY SCORE 200
Preferred Solution: JRt removes duckduckgo. Why

I recommend downloading and running Reimage. It's a computer repair tool that has been proven to identify and fix many Windows problems with a high level of success.

I've used it in the past to identify and fix everything from blue screens (BSOD's), ActiveX errors, corrupt files and processes, dll/exe/sys errors, recover lost memory, Windows update problems, defragging, malware removal etc.

You can download it direct from this link http://downloadreimage.com/download.php. (This link will automatically start a download of Reimage that you can save to your computer.)

A: JRt removes duckduckgo. Why

Hi, I wish to add that the author of the tool has conveyed to improve this in his next version. But i have now a doubt, How to limit the browser of this tool to check the browser. I had the experience of having unwanted browser hijacks, from many of the injected browsers from downloads from different site, including cnet, (even if i select custom installation)
                                            I normally use this tool to remove unwanted PUPs. I do not want thisusu.org to allow the search engine, which they actually do not have like duckduckgo. They occupy a place in the search browser either in ie, ff and chrome as i have already mentioned. What i want to know, whether this search engine is also a kind of PUP or not. that is the crux of the matter. If i say that inclusion of this kind of behaviour, then browser hijackers which are controlled by this wonderful program would attempt to enter thro the exception of so such browsers. I do not know, how thisusu sends a mail to me instead of writing in this forum. This will help many.

Read other 21 answers
RELEVANCY SCORE 49.6

Hey guys, I just entered a word I wanted to search for in Mozilla Firefox and for some reason my search was put through to https://duckduckgo.com?

What happened? Do I have a virus?

Thanks!
 

A:duckduckgo.com? What is this?

No, it's just an alternate search engine. You probably accidentally changed since it's an available search option in Firefox.

More info on the search engine: https://en.wikipedia.org/wiki/DuckDuckGo

Also edited your titled.
 

Read other 2 answers
RELEVANCY SCORE 49.6

Hi,
I tried DDG as my search engine and found that I do not like it.  Problem now is, I cannot uninstall it.  I have removed from search engine list completely and make Google the default once again however when I hit the home button it will always go back to DDG.
I cannot find the process in task manager or control panel.
Any ideas?  I have found the this could possible be some sort of hijack....  Maybe, maybe not?
 
I will run a Malware scan now.
All help/info is greatly appreciated.
 
Thanks

A:Duckduckgo

What browser are you using the search engine with?

Read other 11 answers
RELEVANCY SCORE 49.2

Good evening.

This problem started tonight. My laptop was running fine last night. Today, I noticed that the fan was working hard without stopping. After checking Task Manager, I saw that the CPU usage was 100%, while on idle without any programs running. Running Malwarebytes didn't work, so I tried it on Safe Mode, which came up with nothing. I ran online scanner ESET, also nothing. I ran AdwCleaner and it came up with a PUP. I chose to clean it and it gave me a report. I ran it again but the PUP still came up in the results.

And any address bar internet search is using a "DuckDuckGo" Search engine which I never installed.

Tech Support Guy System Info Utility version 1.0.0.4
OS Version: Microsoft Windows 7 Home Premium, Service Pack 1, 64 bit
Processor: Intel(R) Core(TM) i3-2370M CPU @ 2.40GHz, Intel64 Family 6 Model 42 Stepping 7
Processor Count: 4
RAM: 3992 Mb
Graphics Card: Intel(R) HD Graphics 3000, 1804 Mb
Hard Drives: C: 446 GB (396 GB Free); D: 19 GB (2 GB Free);
Motherboard: Hewlett-Packard, 1841
Antivirus: Microsoft Security Essentials, Enabled and Updated
 

Read other answers
RELEVANCY SCORE 48.4

I want to add Duckduckgo.com search provider to the list of Search Providers in Manage Add Ons. I am using IE10 and I have looked in help but what I am being told to do does not tie up with what I am seeing on the screen. I think the answer is to get Duckduckgo into the list of Add-ons in the Internet Explorer Gallery but even then I am not sure what to do. Any suggestions please?

Any help would be appreciated.

A:How do I get duckduckgo.com into search providers in Add Ons?

Did you try this?
DuckDuckGo | Internet Explorer

My screen snip is from IE10, but I didn't try to install it...

Read other 3 answers
RELEVANCY SCORE 47.6

Firstly, my home page is set up to open in Duckduckgo but it opens in Bing nevertheless. Microsoft Edge sets automatically its default search engine to Microsoft edge and does not allow to reset it to DUckduckgo. Secondly, even if I use Duckduckgo, Microsoft
Edge tracks my loggings. I keep deleting the logging but is there a way to remedy it? Is there enough users to file class action suit for violating users rights ( select engine and privacy issues). Some engines allow to clear all search history upon closing
the browser. Microsoft Edge does not provide this option. Although, Microsoft implies we are using Ducduckgo, they blatantly track us. Where the data go? To NSA?

Read other answers
RELEVANCY SCORE 41.6

Certain web pages do not load properly, just appear typed
I think I might have downloaded an unknown proxy but I am unable to remember what site
Android phone synced with computer so that may be infected as well.
 
FRST
 
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 19-11-2016 01
Ran by Christine (administrator) on LENOVO-PC (19-11-2016 19:40:40)
Running from C:\Users\Christine\Desktop
Loaded Profiles: Christine (Available Profiles: Christine)
Platform: Windows 10 Home Version 1607 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Edge)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(ESET) C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
(IBM Corp.) C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(Intel® Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Windows ® Win 7 DDK provider) C:\Program Files (x86)\Bluetooth Suite\AdminService.exe
() C:\Program Files\CyberLink\Shared files\RichVideo64.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
(Microsoft Corporation) C:\Program Files\Windows Defende... Read more

Read other answers
RELEVANCY SCORE 41.6

Certain web pages do not load properly, just appear typed
I think I might have downloaded an unknown proxy but I am unable to remember what site
Android phone synced with computer so that may be infected as well.
 
FRST
 
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 19-11-2016 01
Ran by Christine (administrator) on LENOVO-PC (19-11-2016 19:40:40)
Running from C:\Users\Christine\Desktop
Loaded Profiles: Christine (Available Profiles: Christine)
Platform: Windows 10 Home Version 1607 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Edge)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(ESET) C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
(IBM Corp.) C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(Intel® Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Windows ® Win 7 DDK provider) C:\Program Files (x86)\Bluetooth Suite\AdminService.exe
() C:\Program Files\CyberLink\Shared files\RichVideo64.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
(Microsoft Corporation) C:\Program Files\Windows Defende... Read more

A:Unknown malware, betternet duckduckgo and other unknown nasties

Hello, Welcome to BleepingComputer.I'm nasdaq and will be helping you.If you can please print this topic it will make it easier for you to follow the instructions and complete all of the necessary steps in the order listed.===Press the windows key + r on your keyboard at the same time. This will open the RUN BOX.Type Notepad and and click the OK key.Please copy the entire contents of the code box below to the a new file. start

CreateRestorePoint:
EmptyTemp:
CloseProcesses:

CHR StartupUrls: Default -> "hxxp://www.google.com/advanced_search","hxxp://Vosteran.com/?f=7&a=vst_ir_15_02_ff&cd=2XzuyEtN2Y1L1Qzu0AyE0D0BtAtDzyzzyE0F0C0A0C0CtDtCtN0D0Tzu0StCtCtDyEtN1L2XzutAtFyCtFtCyCtFyCtN1L1CzutCyEtBzytDyD1V1StN1L1G1B1V1N2Y1L1Qzu2SyDyByCzz0F0A0E0AtGtCtAzyyEtG0FtB0CyDtG0F0DzztDtGyDyBtDyDzy0DyEtDtC0CyB0B2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0CyBtDzzzz0ByEyCtGyEyDyC0FtGyE0A0E0BtGzztAtB0EtG0DtBtAzyyB0A0FzyyB0ByByC2Q&cr=1870843504&ir="
CHR Extension: (Chrome Web Store Payments) - C:\Users\Christine\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-04-14]
CHR Extension: (Chrome Media Router) - C:\Users\Christine\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-11-03]
Task: {14E36186-F2E5-42A9-90A2-4F364FD05837} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
Task: {184621E4-E6DC-4271-8460-BEA56EB60CE3} - \Microsoft\Windows\Setup\GWXTrigge... Read more

Read other 29 answers
RELEVANCY SCORE 38

Outlook Express ver. 6
Occasionally I receive e-mail with an attachment from friends. However Outlook Express gives me the message

“OE removes access to the following unsafe attachment in your e-mail”

Am unable to determine why. I have relaxed the security level in my email options which doesn’t help.
Any suggestions to remove the problem of Outlook Express removing attachments would be appreciated.
.TKS Bob A
 

A:OE removes attachments

In Outlook Express go to Tools then Options, click on the security tab and then UNTICK "do not allow attachments to be saved or opened....."
 

Read other 2 answers
RELEVANCY SCORE 38

I do not have an available restore point prior to the infection.
I did a standard uninstall of 'Roll Around' and removed it from my Browser extension which of course did not work.
I then tried every Malware S/W suggested on many sites dealing with this and none worked, most didn't even detect it.
'SpyHunter' did detect many malicious objects (none named Roll Around) but it's extremely expensive, way beyond my budget and I've read that it also fails to fix this issue by some users.
I'm hoping someone can please help, it's so bad I can barely go online at this point because of the severity of the hijacking :\

Tech Support Guy System Info Utility version 1.0.0.2
OS Version: Microsoft Windows 7 Home Premium, Service Pack 1, 64 bit
Processor: Pentium(R) Dual-Core CPU E5400 @ 2.70GHz, Intel64 Family 6 Model 23 Stepping 10
Processor Count: 2
RAM: 5885 Mb
Graphics Card: Intel(R) G45/G43 Express Chipset, -1281 Mb
Hard Drives: C: Total - 953766 MB, Free - 648075 MB;
Motherboard: ASUSTeK Computer INC., CM5571
Antivirus: Ad-Aware Antivirus, Disabled (I'm running MS Security Essentials)
 

A:'Roll Around Ads' I have tried EVERYTHING I know and nothing removes it..

Read other 16 answers
RELEVANCY SCORE 38

This has been happening for a while now..
Ever since my nephew played around with the laptop keys and downloaded a website page, My Norton antivirus program randomly will remove itself usually once a while.
I went to Norton and they said to come to this website (or others) to find a way to remove this problem.
Please,I need help!

Read other answers
RELEVANCY SCORE 38

HELP HELP!

I recently found the spyware program Eblaster installed on my personal PC. I have found various instructions online as to how to manually remove this software without having to purchase a removal program, but most of the postings are outdated. Also, I get to the point at which I need to go into the registry to find specific programs and commands to delete and I'm not sure where to look.

Can anyone help a novice computer user remove this from her PC!?! i'm worried all of my credit card and banking information is being reported to someone else.

HELP!!! I'd appreciate any advice/detailed instructions you can provide.

L

A:EBlaster Removes

Download HiJackThis - this program will help us determine if there are any spyware/malware on your computer. Double-click on the file you just downloaded. Click on the "Unzip" button to install the newer version. It will by default install to the directory - C:\Program Files\HiJackThis\ If it gives you an intro screen, just choose - Do a system scan and save a logfile.If you don't get the intro screen, just hit [Scan] and then click on Save log.Post the HiJackThis.log file here.

Read other 2 answers
RELEVANCY SCORE 38

This stays in the bottom on the task bar, with a mine sweeper like icon that flash the windows warning yellow exclamation point over it... I click it and it wants me to download a patch (does not work) and a spyware remover thats called Virus Buster or burster... i tried many different versions of spyware/adware/virus and everything that could be found... this is basically my last shot, hope someone has something.I also did everything that was recommended on the page to use hijack this log to post in here...here is the logLogfile of HijackThis v1.99.1Scan saved at 10:10:11 PM, on 11/30/2006Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v7.00 (7.00.5730.0011)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\Program Files\Windows Defender\MsMpEng.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\system32\ZoneLabs\vsmon.exeC:\WINDOWS\Explorer.EXEC:\WINDOWS\system32\spoolsv.exeC:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exeC:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exeC:\WINDOWS\system32\ZoneLabs\isafe.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\System32\wltrysvc.exeC:\... Read more

A:Malware (nothing Removes It)

Hey TraPStaRPlease print out or copy this page to Notepad in order to assist you when carrying out the following instructions. Whilst completing the fix please use the Internet as little as posssible. Do not install any programs whilst we fix your computer - even the smallest of programs can wreak havoc.Update Java:Your version of Java is now outdated. Java vulnerabilites are commonly exploited by viruses so I strongly recommend you update. Click here to download the latest version of java ( Java Runtime Environment (JRE) 5.0 Update 10 ). Please install it and then reboot your computer. Remove the older versions of Java:Click Start, Control Panel, Add/Remove Programs.Delete all Java updates except J2SE Runtime Environment 5.0 Update 10SmitFraudFix:Please download SmitfraudFix (by S!Ri)Extract the content (a folder named SmitfraudFix) to your Desktop.Open the SmitfraudFix folder and double-click smitfraudfix.cmdSelect option #1 - Search by typing 1 and press "Enter"; a text file will appear, which lists infected files (if present).Please copy/paste the content of that report into your next reply.Note : process.exe is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user.http://www.beyondlogic.org/consulting/proc...proc... Read more

Read other 9 answers
RELEVANCY SCORE 38

I have what I believe is a Rootkit designed to cause havoc.  I have spent many days with other forums trying everything under the sun to remove this devil.
 
Some of the apps I've used so far are; AdwCleaner, aswMBR, JRT, Malwarebytes Anti-Malware, RogueKiller, ComboFix, Rkill, FRST64, etc. . .
 
This Lamzap keeps reappearing in the C:/ProgramData directory.  Even if one app locks the directory, it soon reappears.  It has two initial directories, Lamzap & Lamzaps.  It installs a hijacker in Firefox that takes you to a new unwanted Homepage.  In my case it was a search engine; search.safesearch.
 
It also loads many, many directories in the C:/ProgramData directory.  All contain executables and other necessary files.
 
 

A:LAMZAP - So far, nothing removes it.

Hello Bud Parker and welcome to Bleeping Computer.
You have posted in multiple forums which is not fair on the volunteers who offer their free time and can also lead to confusion for you if you receive conflicting advice.
As it appears that you are receiving help here, I’ll close this topic.
Satchfan

Read other 2 answers
RELEVANCY SCORE 37.6

Anyone tell me there is any software which removes password from a zip file. I used password recovery program but as i remember the password is 15 digits long and that's why it takes very long time in recovery.
 

A:Removes Password from zip file

A 15 digit password will take AGES to remove by any of the ZIP password recovery applications.
 

Read other 3 answers
RELEVANCY SCORE 37.6

Newly installed NAV 2002 changed my user name in WinXP and removed my XP password. I couldn't connect to the Web. Had to call my ISP, they figured out problem, had me re-enter my user name and pword. But each time I try to connect, NAV has done it again. Again I re-enter correct data.
Anybody else have this problem? Anybody have the solution?Thanks. Maxboswell.
 

A:NAV 2002 removes password

maxboswell
Welcome to TSG!
Researched and found little about your problem. It is possible you had a pre-existing virus or trojan on your system which is causing problems. When you installed NAV 2002 did you retrieve all the new virus definitions and run a full virus scan on your system? Also go to this website and run a free online virus scan to get a second opinion.
http://housecall.antivirus.com/housecall/start_corp.asp

Dave
 

Read other 2 answers
RELEVANCY SCORE 37.6

Hi guys,

I was just about to buy the eVGA 7600gt CO on NewEgg.com, when it was removed from their site. I noticed a little bit earlier that the product went out of stock.

When a product goes out of stock on NewEgg, do they usually leave the product on with an "out of stock" notice, or take it off the the site, until they get more in? OR does this mean the product is off for good?

Thanks for the help, and I apologize if this is not the right forum category for this question.
 

A:NewEgg removes 7600gt CO?

I remember when they came out with the GTO2's. They constantly were out of stock and the product was removed numerous times but they still sell them to this day.

Chances are they have too many back order requests/auto-notifications and they dont want anymore so they probably just took it off until they get more in stock.

No worries bro.
 

Read other 2 answers
RELEVANCY SCORE 37.6

Spybot keeps finding something called Zlob.DNSchanger.Rtk and I keep removing it but the next time I scan it will find it again. Anyone know what this is or why I can't seem to get rid of it? I am also having a huge problem with search engine hijacking, like I will a search for something, CATS for example... and it will bring up all the websites relating to that.. but as soon as I click on the link it reroutes me to another page. I can redo the search and click the same link, it will reroute me to an ad page again. On the third try it will finally take me to the link. VERY annoying. I have run Spybot, hijackthis and Housecall.... I don't know what else to do! Anyone have any ideas? Thanks Amber

A:Spybot Removes The Problem... But Not Really

If your using Win XP or 2000, please print out and follow the generic instructions for using SmitfraudFix in BC's self-help tutorial "How to remove the Smitfraud/Generic Zlob".(scroll down to Removal Instructions; ignore the part showing symptoms in a HijackThis log as they may not apply in your case.)If you have downloaded SmitfraudFix previously, please delete that version and download it again as the tool is frequently updated!Download and scan with SUPERAntiSpyware FreeDouble-click SUPERAntiSypware.exe and use the default settings for installation.An icon will be created on your desktop. Double-click that icon to launch the program.If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download them from here and unzip into the program's folder.)Under "General and Startup", make sure "Start SUPERAntiSpyware when Windows starts" box is unchecked.Under "Configuration and Preferences", click the Preferences button.Click the Scanning Control tab.Under Scanner Options make sure the following are checked (leave all others unchecked):Close browsers before scanning.Scan for tracking cookies.Terminate memory threats before quarantining.Click the "Close" button to leave the control center screen and exit the program.Do not run a scan just yet.Reboot your computer in "Safe Mode" using the F8 method. To do this, restart your compute... Read more

Read other 3 answers
RELEVANCY SCORE 37.6

HI,

In my add/remove program list I have several programs that are no longer on my computer listed. Whe I try to click remove, I get an error message. I was just wondering if there is any way to get these programs unlisted from the add/remove section.

Thanks!
-Adrienne

------------------
 

A:deleting unworking add/removes

If you download and install tweakui you can do it from there
http://www.infinisource.com/windows98/tweakui2000.shtml
 

Read other 1 answers
RELEVANCY SCORE 37.6

This happens in every case with the latest version. Is there any way this program can be made exempt from being removed as as malware by ComboFix when it runs?
 
If this is the wrong place to post this, or if there is a way to mail the ComboFix creator directly, please let me know.
 
Thank you,
 
Shimonhead

A:ComboFix removes UltraVNC...

The developer (sUBs) will need to see the log and a sample of the file so he can investigate. Please submit (upload) a copy of ComboFix.txt and the file(s) to this Submit Malware Sample page.Fill in the requested information, comments and any further information.Zip the file(s) using a zipping program (i.e. 7-zip, WinRAR).Click the Browse... button and navigate to the location of the file.Click on the file to highlight it and choose Open.Click the Send File button.You will not be able to view the files that have been uploaded as they only show to the authorized users who can download them.sUBs will be able to collect the file(s) from there and examine them.Let me know when you have done this.Thanks.

Read other 6 answers
RELEVANCY SCORE 37.6

Why does norton removes the combofix after downloading?Edit: Moved topic from Windows 7 to the more appropriate forum. ~ Animal

A:Norton removes combofix

Chapter n Verse, compliments of Quietman7: http://www.bleepingcomputer.com/forums/topic437353.html/page__pid__2547832#entry2547832

Read other 2 answers
RELEVANCY SCORE 37.6

Hi everyone, on my wifes computer she used MS Outlook (not express) for emails. Sometimes she gets the OE will has removed the following attachments error. How can I fix this to allow all attachments to be read? I can do it with express but Im puzzled with Outlook!
Thanks a million
 

A:Outlook removes attachments

Go to Start | Run
type in Regedit

In the left Pane, find the following key:

HKEY_CURRENT_USER\ Software\ Microsoft\ Office\ 10.0\ Outlook\ Security

Create a new string value by Edit | New | String Value
Name the new value Level1Remove.

Double-click the new Level1Remove to edit it, and enter the filename extensions you'd like to stop Outlook from blocking.
Extensions should be typed in lower case, without the dots (.), and separated by semicolons ( ; ). For example, type

exe;mdb;vbs

to allow .exe, .mdb, and .vbs attachments, respectfully.

Click Ok and then close the Registry Editor when you're done. You may have to restart Outlook for this change to take effect.
 

Read other 1 answers
RELEVANCY SCORE 37.6

I made the mistake of downloading a fight from LimeWire a few months ago. Every since then I have experiencing multiple po-ups from WinAntispyware 2007 and many other advertisers. My Outlook is very slow and IE is muck slower than before. I currently use McAfee and it removes viruses each time I scan, but they come back each time. I also downloaded Spybot, Adaware SE, Windows Defenderand some others that were recommeded. I would scan with each in Safe Mode. They all found different things, but to no avail, the pop-ups keep coming. Please help me.
 

A:Annoying pop-up virus that nothing removes

Read other 10 answers
RELEVANCY SCORE 37.6

Hello All,

Long time lurker, first time writer.

I've run into a situation today that I found rather unusual. I ran a current version of combofix on an XP SP3/IE7 home box to remove a drive-by rogue AV install (garden variety antispy2009- iehelper.dll., proquota.exe, etc.). The machine is otherwise clean.

Oddly, combofix tagged an entire installation of ACT (older version) as infected. The results are what you would expect with a 'virut' type infection. I have not yet confirmed that these files are truly infected (I'll upload to Virustotal tomorrow). I strongly suspect (based on 9 years of IT experience and plenty of combofix runs) that this is a false positive and I'm wondering if there is an appropriate way to communicate the issue to sUBs.

Alternately, if this issue has already been discussed, please direct me to the details.

Thanks for your time. And much love to the folks that hold down this fort.

Q

(mods- feel free to place this post somewhere more appropriate if necessary)

A:Combofix removes ACT software

False positive confirmed.

Read other 1 answers
RELEVANCY SCORE 37.2

Hey fellas,

When I disable User Account Control UAC on my Vista (64 Ultimate) Administrator account I lose write access on one of my drives.

I've got 3 drives, 2x500Gb drives in RAID1, and one 250Gb drive. The 250Gb drive is partitioned into two virtual drives; a 50Gb partition for Windows, and 200Gb for storage. It is the 200Gb partition that I lose write access on by disabling UAC.

The 250Gb drive had WindowsXP installed on it previously, but I did a quick format on the drive before installing Vista, but perhaps that's related.

Any and all help would be greatly appreciated, I'm really getting annoyed with UAC.

Thanks,
Dayne
 

Read other answers
RELEVANCY SCORE 37.2

Hi Guys
Clean-up problem with Xp theme seems to be cropping up more and more! This fix should be an easy to follow way around it!
I thought it could be used as a link?
David


XP Theme fix (following the use of CleanUp!)
It appears that CleanUp! corrupts the luna.msstyles file, so that the XP Theme no longer functions. This widely used fix simply replaces the corrupt file with a new one to correct the problem. (Perchance Luna XP Theme file(s) are actually missing, add those from the download to the appropriate place.)

Go to Kelly's Korner:
Go to list item #187, and in the RHS column, click on "Restore Luna Theme" to download "Resources.zip".
Unzip that, (where ever you wish) and within those folders, navigate to the "luna.msstyles" (or "luna ..." whatever it may happen to be called on that machine) file only.
Resources\Resources\Theme\Luna\luna.msstyles <<<this file
Right-click on the "luna ..."file (not the folder) and select "Copy" (to copy this file to the Clipboard).
Then, using Windows Explorer, (having first confirmed that all system and hidden files and folders are visible) navigate to
C:\Windows\Resources\Themes\Luna\luna ... <<<this file (if it exists)
and drag it (the "luna ..." file, not the folder) out of the way (say, onto the desktop for temporary safe-keeping).
Paste in the new "luna ..." file to replace the one just removed (right-click on a ... Read more

A:Clean up removes XP fix theme - Luna fix

Read other 7 answers
RELEVANCY SCORE 37.2

I have Sophos AV installed.

When doing a scan it finds 11 viruses and moves them to the vault.

They include: Troj/BHO-IX, Troj/Dloadr-CDB, Troj/Fakeav-HP, Troj/Conhook-AQ, Troj/Zlob-ARM, Troj/Virtum-GEN & Troj/Superjuan.

If I scan again, it finds the same viruses and again moves them to the vault.

Sophos isnt removing the viruses but says it is.

Does anyone know why?
 

Read other answers
RELEVANCY SCORE 37.2

Hello,

Symantec antivirus detected Zefarch on my computer. It will only partially remove it. I've updated virus definitions but the result is always the same. If anyone could help, it would be wonderful!

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 5:45:41 AM, on 12-Jul-2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\... Read more

A:Antivirus only partially removes Zefarch

Read other 7 answers
RELEVANCY SCORE 37.2

I e-mailed about 20 files from a old computer at a summer cabin to our computer here at home. I could not burn them to a CD as the computer didn't have a burner. When I tried to "save as" to My Documents here at home half of them had the message "OE removed access to the following unsafe attachments in your mail". All those had file names that I don't know how they came about, such as "exe" and "lnk". How did those file names come about. Any ideas? Thanks, lilart:
 

A:Solved: OE removes access to attachments

Read other 6 answers
RELEVANCY SCORE 37.2

I am at friend's house. WinXPHome. He had a virus notice from Norton. I recall it saying something like this...

w32.spybot detected on
C:\WINDOWS\SYSTEM32\IEXPLORE.EXE

Whatever it was, I recall researching it and found that it said it was spread by the Kazaa. (Which is no longer on this machine... I had him remove it.)

I had not "eradicated" it yet. On a separate idea, I downloaded and ran Adaware, because I noticed GAIN and GAIN ads popping up. Adaware removed like 20-something files.

I ran Norton to get the virus and it found no viruses. Does Adaware remove viruses?
 

A:Running Adaware removes virus?

It has a good go at the spybot virus, which drags in spyware/adware with it
 

Read other 2 answers
RELEVANCY SCORE 37.2

I was testing out some Anti-Spyware Apps ... SZ was rated quite highly so thought I would try it out... it said it found vbaliml6.ocx in sys32 as ABetterInternet.Clean Get-Away as a moderate threat ... it removed the file so I went to restore it so I could inspect it myself and its not restored but also gone from SZ...

is this a FP or not?

Im not providing an HJT as its not help with an infection Iam asking for...yet anyway...

thanks
 

Read other answers
RELEVANCY SCORE 37.2

Miscreants have created a strain of malware capable of removing rootkits from compromised PCs, only to install almost undetectable backdoor code of its own. The Pandex Trojan stops previously installed rootkits from working by removing their hooks into system calls. Pandex then installs its own rootkit component, detected by Trend Micro as Pushu-AC...channelregister.co.ukRTKT_PUSHU.AC - Rootkit Remover?

Read other answers
RELEVANCY SCORE 37.2

I have Sophos AV installed.

When doing a scan it finds 11 viruses and moves them to the vault.

They include: Troj/BHO-IX, Troj/Dloadr-CDB, Troj/Fakeav-HP, Troj/Conhook-AQ, Troj/Zlob-ARM, Troj/Virtum-GEN & Troj/Superjuan.

If I scan again, it finds the same viruses and again moves them to the vault.

Sophos isnt removing the viruses but says it is.

Does anyone know why?
 

A:Sophos removes viurses but doesnt

The General Security forum is only for general questions regarding security software and things of that nature but not for actually removing malware as we have qualified helpers who are the only members who are authorized to assist with those matters. You can easily identify them as they have either a gold or blue shield beside their usernames. Please refer to this excerpt from the rules:

Log Analysis/Malware Removal - In order to ensure that advice given to users is consistent and of the highest quality, those who wish to assist with security related matters must first graduate from one of the malware boot camp training universities or be approved by the administration as already being qualified. Those authorized to help with malware issues have a gold shield next to their name and authorized malware removal trainees have a blue shield next to their names. Anyone wishing to participate in a training program should contact a Moderator for more information.Click to expand...

I'm going to close this thread and ask you to repost in the Malware Removal & HijackThis Logs forum for the proper assistance.
 

Read other 1 answers
RELEVANCY SCORE 37.2

Can you guys please tell me about an app that deletes all but the most recent Windows System Restore point ?
And all of it in an easy way. Which also tells me about how much space I've recovered ?

Please.
Thanks a lot in advance.

---Kind Regards---

A:Any app which removes old system restore points ?

What Windows version?

You can remove all restore points, but turning system restore off, restarting computer and turning it back on.

Read other 4 answers
RELEVANCY SCORE 37.2

I found this question on another site, but without any answer. I am having the same problem.

I think I found a bug in 2010 Word. I set up a document in this version. Someone opened it in Word 2007 and went to track changes. It took out some of the spaces in the document! When I got it back with the edits, the spaces were still gone! I had to add them back manually.

This has happened with two separate documents (created in 2010, opened in 2007, track changes turned on and used)

I don't think it's a kerning problem - a similar problem I found on another website - but that turned out to be fonts over 16 pt and this was in Calibri 11 pt.

I am not sure if this is the correct Forum but would appreciate any assistance for a work-around besides doing the original in 2007.

Thank you!
 

Read other answers
RELEVANCY SCORE 37.2

Artemis!4DB5909D450A  Macafee finds this in adwcleaner and deletes the program. tried to download from here and it deleted it again.  is this a false pos in prog,  ?  even deleted on flash drive when plug in.
 
thanks if anyone else is seeing this issue.  Just started today. was on comp and worked till today.

A:adwcleaner 4.11 macafee says infect removes it

...is this a false pos in prog,  ?  even deleted on flash drive when plug in.
 
thanks if anyone else is seeing this issue.  Just started today. was on comp and worked till today.

Yes it is.
 
https://www.virustotal.com/de/file/18d2647d983207aaeb3dbc8e8de267f4ff8e6c19a5947269d3cfac76ad46f38e/analysis/1424982307/
 

Read other 2 answers
RELEVANCY SCORE 37.2

Hi Guys,

I am about to reformat my system and reinstall all programs and settings etc.. One question I have is around the registry tweak to add a "Take Ownership" icon to the right click contect menu.

I generally install this tweak as it's extremely useful and saves messing around with calcs commands. It seems however that once this is done in Windows 7 RTM 64 it replaces the icon to run as administrator (which is also extremely useful).

Is there a way to keep both icons/features in the context menu?

Thanks in advance
Tylor

A:Take Ownership tweak removes Run as Admin

Try this.

Take Ownership Shortcut

Read other 9 answers
RELEVANCY SCORE 37.2

On the laptop Im using, I had activated the product ok when the LAN was enabled in the BIOS but when I disabled the LAN in the BIOS the activation product key asks to be activated again with the 3 days, does any body have an idea or work round to this issue?

The operating system loaded in Win 7 Pro 64 Bit Sp1

A:Activation product key removes on disable

Changing or removing the MAC of the NIC with which Windows was activated will almost always result in the request to re-activate.

Either re-enable the NIC, or re-activate.

If neither approach works, then post an MGADiag report...

Please follow this tutorial and post an MGADiag report - then we can see what the problem is.

http://www.sevenforums.com/windows-updates-activation/234159-windows-genuine-activation-issue-posting-instructions.html

Ignore errors produced when clicking on the Copy button - they simply mean that the tool could not create the backup files for some reason. The data is still copied to the clipboard for pasting to your response.

Please also state the Version and Edition of Windows quoted on your COA sticker (if you have one) on the case of your machine (or inside the battery compartment), but do NOT quote the Key on the sticker!
http://www.microsoft.com/en-us/howtotell/Hardware.aspx

Read other 1 answers
RELEVANCY SCORE 37.2

As the title says Stardock's Iconpackager removes the shield overlay from programs that need to be installed as administrator.

I run the only account on my system it is an administrator account. Is the shield overlay only aesthetic? Will all programs I install on my admin account be installed as (run as administrator) anyway, or will this cause serious issues?

A:Iconpackager Removes Shield Overlay

Hello Seanie,

As long as you are getting a UAC prompt (if UAC is turned on to default or top level) when you run the program, then you are fine.

The shield overlay on the icon is just an indicator to let you know that program will give you a UAC prompt when the program is executed to allow or deny it to run as administrator.

Most likely this program just made a cosmetic change.

Hope this helps,
Shawn

Read other 5 answers
RELEVANCY SCORE 37.2

How can I remove the space from the end of lines in a word document ?

I need to read the file and save it ..

I saw the RTrim , but I didn't know how to use it ?

Thanks
 

A:VBA macro for word doc that removes space at the end

Why?? You would have to loop through every line, turn each line into a string, trim off the spaces and write them back to the screen.
 

Read other 3 answers
RELEVANCY SCORE 37.2

After downloading and installing SP2 my networks connections are GONE! The devices are still installed properly with the same drivers as I had before the installation... any ideas? I can't create a new connection, access any networks, ANYTHING! Thanks in advance.

A:Installation of SP2 removes Network Connections

This error happens sometimes, happened to me a while ago with some stupid little update that MS released. What happens when you go to Control Panel->Network Connections, and then click "Create a new connection" on the sidebar?

Read other 3 answers
RELEVANCY SCORE 37.2

Hello!

Does a system restore disc or USB removes malware or any viruses?
Thank you

A:System restore removes malware?

  
Quote: Originally Posted by jennn


Hello!

Does a system restore disc or USB removes malware or any viruses?
Thank you


Welcome Jenn to the windows 7 forums.

A system restore will not remove the malware or virus that is installed on your computer.
The best and recommended method is to use an Anti-Virus product along with a free program called malwarebytes.

It is available at Malwarebytes : Free anti-malware, anti-virus and spyware removal download



Rich

Read other 9 answers
RELEVANCY SCORE 37.2

While on a reputable site for my local newspaper MSE signaled it found TrojanDownloader:JS/Qakbot.H, classifying it as severe. I told it to remove it and it said it succeeded. Ran a Quick Scan right away which came up clean.

12 hours later when I ran CCleaner to clean temp files MSE again found the same Trojan. I had it remove it and it again found it while CCleaner removed the temp files.

So in my history there are three instances of this same Trojan all listed as being removed. Is it really gone?

IF MSE removed the Trojan the first time why did it remain in a temp file? If I had never cleared the temp files using CCleaner it seems to me the Trojan would have remained on my computer. What damage was done in the twelve hours between when MSE initially removed it and it hopefully was removed for good from the temp files?

Is this how MSE is supposed to work? Seems like a flaw if it leaves what it cleans in a temp file? Would a full scan have found the temp file infection?

A:MSE finds and removes Trojan three times

I found this info on the trojan I would be changing passwords and such:
Backdoor.Qakbot.H - malware that steals everything | help.artaro.eu

Removal:
Remove Qakbot, W32.Qakbot removal tutorial

I believe it may still be on your system and I would download malwarebytes and run a full sweep of the system after a full update bru.

Read other 5 answers
RELEVANCY SCORE 37.2

My 64-bit laptop with 8GB RAM after the last update, doesn't allow me to access my NAS drive. It gives the following error msg as attached. The D-Link software no longer works, even the latest version ????

I had a desktop previously that did the same, but the new storage utility worked and created a new mapped drive. It does not on the laptop.

I can login the the NAS via a browser no problems, and my access credentials are still there.

Read other answers
RELEVANCY SCORE 37.2

I was warned by my Avast anti-virus software that there was a problem with one of the extensions I was using on Chrome, so I removed it and ran AdwCleaner. It found some files, and I ran the removal process which required restarting my computer, but when I run Chrome again after it has been restarted and run AdwCleaner again, they have come back again. How do I get rid of them for good?

A:AdwCleaner Removes Files but They Come Back

Welcome aboard   Download Security Check from here or here and save it to your Desktop. Double-click SecurityCheck.exe Follow the onscreen instructions inside of the black box. A Notepad document should open automatically called checkup.txt; please post the contents of that document.NOTE 1. If one of your security applications (e.g., third-party firewall) requests permission to allow DIG.EXE access the Internet, allow it to do so.NOTE 2. SecurityCheck may produce some false warning(s), so leave the results reading to me.NOTE 3. If you receive UNSUPPORTED OPERATING SYSTEM! ABORTED! message restart computer and Security Check should run Please download Farbar Service Scanner (FSS) and run it on the computer with the issue.Make sure the following options are checked:
Internet ServicesWindows FirewallSystem RestoreSecurity Center/Action CenterWindows UpdateWindows DefenderOther ServicesPress "Scan".It will create a log (FSS.txt) in the same directory the tool is run.Please copy and paste the log to your reply. Please download MiniToolBox and run it.Checkmark following boxes:Report IE Proxy SettingsReport FF Proxy SettingsList content of HostsList IP configurationList Winsock EntriesList last 10 Event Viewer logList Installed ProgramsList Devices (do NOT change any settings here)List Users, Partitions and Memory sizeList Restore PointsClick Go and post the result. Please download Malwarebytes Anti-Malware (MBAM) to your desktop.NOTE. If you already have MBAM 2.0 installed scr... Read more

Read other 11 answers
RELEVANCY SCORE 37.2

Hey Guys:

Im doing a school project on recent harmful viruses and where on the web they come from. Now each group has been given a sample hdd to prove/show the extent that the virus choosen can damage and how to treat or to remove it. My group has to come up with a virus/trojan/malware that completely and permanently removes all sound from a system then continues to delete windows files 1 by 1. Does anyone here know of anything like this. Oh and how would we go about trying to treat it.

NB: Please Help My Project is Due tomorrow morning im running out of ideas.

A:Virus that permenently removes all sounds from a pc.

Sorry, but that's not what this forum is for. We help users who've unintentionally become infected.

Additionally, it's against forum rules to assist with classroom assignments.

http://www.techsupportforum.com/rules.php


Quote:




You may not ask for assistance with homework assignments, projects or book reports for school college or university




This thread is closed.

Read other 1 answers