Home > General > Loadingwebsite.com


If you have any questions during this process, please ask us (just don't restart or shutdown - unless the instructions say so). 1. Several functions may not work. Post whatever questions you may have in the forum and we will take a look at it when we get to it. How to get started Open Forum Hints and Tips Feedback & Announcements Web User magazine feature suggestions Security Security & Privacy

Run a scan in HijackThis. We are looking for any randomly named files. Get HijackThis Analyzer and save it to the same folder as the hijackthis.log file. Subscribe Forums Web User Forums > Security > Malware Removal Help & Analysis Infected with Spotresult.com & Loadingwebsite.com User Name Remember Me? http://www.loadingwebsite.com/

Spam from www.loadingwebsite.com Started by rogerwithnell , May 13 2005 05:50 PM This topic is locked #1 rogerwithnell Posted 13 May 2005 - 05:50 PM rogerwithnell New Member Member 5 posts If you don't get the intro screen, just hit Scan and then click on Save log. 3. Forum Closed Due to inactivity, these forums are closed indefinitely.

The following was from hitting 5 Module information for 'winlogon.exe' MODULE BASE SIZE PATH winlogon.exe 1000000 188416 C:\WINNT\system32\winlogon.exe 5.00.2195.6898 Windows NT Logon Application ntdll.dll 77f80000 512000 C:\WINNT\system32\ntdll.dll 5.00.2195.6899 NT Layer DLL d) Remember to copy and paste both of these log files in the forum AFTER you are finished with the rest of the steps below. 4. Copy the contents of that log and paste it into this thread.When you have completed stage one run stage two belowStage 2Close any programs you have open since this step requires If you have a fast internet connection (broadband), run an online virus scan at TrendMicro.

Please follow the steps below: 1. Style Default Style Contact Us Help Home Top RSS Terms and Rules Copyright © TechGuy, Inc. Before you give us a new log here, if we gave you instructions for a fix, please do the fixes first and then post the new log with this updated version. Contacts About Web User Contact Us Advertising Info Top 10 Website - HitWise 2008 Follow Web User on Twitter Join the Web User Facebook group Watch the Web User Youtube channel

Make sure to close any open browsers. We recommend uninstalling it. Click here to join today! Panda scan below.

After a reboot, your desktop and icons will appear, then disappear (this is normal). http://www.spywareinfoforum.com/topic/40469-loadingwebsitecom/ I downloaded Killbox and checked "delete at startup" on both of them and it completely removed the problem from my system. Post anything that looks suspicious. vanillag1rl, Feb 15, 2005 #4 cybertech Moderator Joined: Apr 16, 2002 Messages: 71,995 Hi cfogarty, Welcome to TSG!!

Tech Support Forum Security Center Virus/Trojan/Spyware Help General Computer Security Computer Security News Microsoft Support BSOD, Crashes And Hangs Windows 10 Support Windows 8, 8.1 Support Windows 7, Vista Support Windows You will also regain a massive amount of disk space. Logfile of HijackThis v1.99.1 Scan saved at 13:07:22, on 18/06/2005 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: E:\WINDOWS\System32\smss.exe E:\WINDOWS\system32\winlogon.exe E:\WINDOWS\system32\services.exe E:\WINDOWS\system32\lsass.exe E:\WINDOWS\System32\Ati2evxx.exe E:\WINDOWS\system32\svchost.exe E:\WINDOWS\System32\svchost.exe Say Yes when it asks you to reboot/logoff. 6.

Post all of the logs in your next post. Now double click on hijackthis.exe and select "Do a system scan and save a logfile". Download Hijackthis and click "Save", direct it to the permanent folder you created. Click the Install button to extract the files and follow the prompts, then open the newly added l2mfix folder on your desktop.

Please print out or copy this page to Notepad. Vision]InProcServer32 = C:\WINDOWS\DOWNLOADED PROGRAM FILES\YV.DLLCODEBASE = http://download.yahoo.com/dl/fv/yv.cab[Communities.com Passport]InProcServer32 = C:\PROGRAM FILES\COMMUNITIES.COM\CARTOONORBIT\QU2LMT59HBCAYVJABNCYUN6DT7XKQLE3.DLLCODEBASE = http://cartoonorbit..../winorbiter.cab[Microsoft Search Settings Control]InProcServer32 = C:\WINDOWS\DOWNLOADED PROGRAM FILES\SEARCHSETTINGS.OCXCODEBASE = http://lg.home.micro...rchsettings.cab[PWImageControl Class]InProcServer32 = C:\WINDOWS\DOWNLOADED PROGRAM FILES\PWACTIVEXIMGCTL.DLLCODEBASE = http://ebay.sj.ipixm...tiveXImgCtl.cab[InstallShield Setup Player]InProcServer32 It will take more than a couple of tries to fix this.

ozzman, Feb 15, 2005 #3 vanillag1rl Joined: Sep 28, 2004 Messages: 1,124 If that doesnt work.

i am not sure how to run hijacker tks cfogarty, Feb 15, 2005 #2 ozzman Joined: Feb 14, 2005 Messages: 5 i got this from a different site ::: After Yes, my password is: Forgot your password? bricat View Public Profile Send a private message to bricat Find all posts by bricat #3 18-06-05, 04:21 master82 Newbie Join Date: Jun 2005 Posts: 2 Re: Infected Exit Program.Please run the following free, online virus scans.http://www.pandasoft...n_principal.htmhttp://housecall.tre.../start_corp.aspPlease post the logs From Panda virus scan and HJT.log we will need them to remove previous infections that have left files on

Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YHEXBMES0521.DLLO9 - Extra button: Ebates - {6685509E-B47B-4f47-8E16-9A5F3A62F683} - file://C:\PROGRAM FILES\EBATES_MOEMONEYMAKER\Sy350\Tp350\scri350a.htm (file missing) (HKCU)O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\PROGRA~1\AWS\WEATHE~1\Weather.exe (HKCU)O12 - Plugin for .jps: Post the description for each of those here. We need them all to get a fix for this infection. __________________ Please do NOT PM me. Also please tell me if the removals tools find anything.

proud member since 2004Most active in: Resolved or inactive Malware Removal Back to top Back to Resolved or inactive Malware Removal 0 user(s) are reading this topic 0 members, 0 guests, If there's anything that you don't understand, ask your question(s) before proceeding with the fixes. Also make sure that Display the contents of System Folders' is checked. program and click on CleanUp button.

Logfile of HijackThis v1.98.2 Scan saved at 10:39:51 AM, on 2/8/2005 Platform: Windows 2000 SP4 (WinNT 5.00.2195) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINNT\System32\smss.exe C:\WINNT\system32\winlogon.exe C:\WINNT\system32\services.exe C:\WINNT\system32\lsass.exe C:\WINNT\system32\svchost.exe C:\WINNT\System32\svchost.exe