Tech Problem Aggregator

Downloaded the new ad-ware 07???

Q: Downloaded the new ad-ware 07???

has anyone downloaded the new ad-ware 07??? i downloaded the free version as it is freeware but i cant seem to get the installation to work, when i double click on the application is gives me this error: anyone know why??

A: Downloaded the new ad-ware 07???

anyone can help out?

6 more replies
Answer Match 49.98%

ive recently come across a youtube clip that had the same skip problem that i was having with the pc,

in 20 to 21 sec of the video does that sound excately the same as my pc! but when my pc only loads mp3 or playing games or watching youtube when lil ram is used but yeah i didnt know how to discribe it but i ran across the a video today so i thought i better show you. Post office says pc will be their on monday im on my old p4 pc(

http://youtube.com/watch?v=EpMxaYfFPU0&feature=related

my operating system is video card is upgraded to 8800 gt nivida but still has the same stall glitch problem

-) Brand New AMD Dual Core Processor 4800+ AM2 64bit Windows System with 22'' LCD WideScreen Monitor, 4G RAM, 500G Hard Disk Drive, 8500GT 512MB Super HDTV, DVI, PCI-E

Great choice for all home/office needs...running audio and video editing, multimedia programs. A really quiet and fast system!
::: Features :::
:AMD Dual Core processor - Athlon64 4800+ 2x2.5GHz
:Graphic Card - 8500GT 512MB Super HDTV, DVI, PCI-E
:5.1 channel, High Definition Audio
:10/100 Ethernet, Broadband Modem ready
:6 USB ports
:4GB DDR2 RAM, double bandwidth with dual channel enabled
:500GB, highspeed SATA2 Hard Disk
:CD/DVD Writer with lightScribe (Light Print cd/dvd Covers), Dual layer.
:400W Power Supply, full ATX Tower with front 2Xusb ports , 2XAudio Jacks, Very quiet power supply fan.
:Multimedia Keyboard & Optical Mouse
: 22" Wide Screen LCD Monitor, dvi.
is their anyone that ... Read more

A:Unknown problem with pc/hard ware soft ware? Unsure please help has video example

/bump any 1??
 

1 more replies
Answer Match 48.72%

Hey what is the best FREE virus, ad-ware, spy-ware scanner out there that i can continue using so that my computer doesn't slow down and stays clean. Please someone let me know and if you can send me a link where i can download it along with the program's names. Thank you.
 

A:Best FREE virus, ad-ware, spy-ware scanner

This is a subject that has been discussed thousands of times on TSG. I'm sure you could find what you're looking for by typing your request in the forum's Search option.

Nevertheless, I will give you my personal recommendations:

- Avira Antivir free antivirus

- Online Armor firewall

- Malwarebytes' Anti-Malware

- SuperAntiSpyware

- SpywareBlaster
 

2 more replies
Answer Match 46.62%

Hi recently i notice some problems with the speed of my pc, i have 1.5 GB of ram so i dont understand why some programs arent opening very fast like Firefox, i know for sure i have ad-ware because BitDefender detected it,there also might be something with the windows system files, heres my hijackthis log, please help me if you can i really appreciate it.


Logfile of HijackThis v1.99.1
Scan saved at 12:31:12 AM, on 7/23/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe
C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe
C:\Program Files\Common Files\Softwin\BitDefender Update Service\livesrv.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Softwin\BitDefender10\vsserv.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\Program Files\Lexmark 4300 Series\lxcemon.exe
C:\... Read more

A:AD-Ware possible mal-ware/virus/trojan

Hello and welcome to TSF

I am currently reviewing your log. Please note that this is under the supervision of an expert analyst, and I will be back with a fix for your problem a.s.a.p

Please be patient with me during this time.

You may wish to subscribe to this thread to get immediate notification of replies as soon as they are posted. To do this click Thread Tools, then click Subscribe to this Thread. Make sure it is set to Instant Notification, then click Subscribe.

13 more replies
Answer Match 46.62%

I am usually pretty good about not down loading things I should not. But I got nailed last night while looking for a vector graphic....

The item has downloaded it self into my system at frist it was a new program that shown up in startup it was for Virus Response Lab 2009 (which had nothing to do with what I was doing) I removed it via remove add programs. But the thing has attached itself to my lower right bar (start up) giving me a flashing red X and then turns into a blue ?. You click on it and it goes to Virus Response Lab 2009 home page.
Ive ran my virus program and ran SPYBOT > My virus program comes up with nothing. Spybot came up with some issues. Which i corrected with Spybot. At this time of posting its 3/4 done and it appears clean.. . It appears to take it away but when I shut down and restart they are back.
I went to system restore but if I do that I will loose all my updates to spybot and my antivirus for the last two days. Plus nothing is listed for Response lab. So at this time I have not done System Restore

Please help me remove this flashing icon from my start up bar.
Thank you in advance

Logfile of HijackThis v1.99.1
Scan saved at 5:32:20 AM, on 10/23/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.e... Read more

A:Solved: mal-ware?ad-ware? virus?

I sovled it myself.
 

1 more replies
Answer Match 43.26%

would like to know of some to find out if someone u are chatting with is who they say they are ..wondered if there was some way to find out ..im running windows me ...ive heard of some software but cant seem to remember what it was.. hopefully someone knows of a program ..i hate being lied to and would like to find out if this person is for real or holding back something..tks
 

More replies
Answer Match 43.26%

Recently been attacked by some form of adware. it resets my homepage to www.windowws.cc, a search site and gives me messages saying 'Youve got spyware, click here to remove it!'
I cant get into hotmail as it automatically diverts to this site. Things have also been moving slower and today the system has automatically shutdown warning me of an error in the System32 thing.
Can anyone help? Here's my hijakthis log:

Logfile of HijackThis v1.98.2
Scan saved at 10:24:00, on 24/09/2004
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\S3hotkey.exe
C:\WINDOWS\System32\S3tray2.exe
C:\PROGRA~1\EZButton\CP51NBtn.EXE
C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\PROGRA~1\EZButton\CPHKCnt.EXE
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\PROGRA~1\EZButton\DtcEMail.EXE
C:\P... Read more

A:Ad-ware/Spy-ware removal

8 more replies
Answer Match 42.42%

Hello Everyone!

What are the best free Anti-Spyware and Anti-Malware programs available?
How and where do I get them?

I had problems with my computer crashing after start up and ended up reformating my hard-drive and restoring my computer to factory condition. I never did find out what caused my computer to crash! It even stumped the computer techs at Dell! That is why we decided to do the factory condition restore. My theory as to what happened is one of three things: 1) During an Anti-Spyware scan then deleting what it found,mostly cookies, and doing a hard drive clean up. Some important files nay have accidentally gotten deleted. 2) McAfee Firewall and Windows Firewall operating at the same time for so long finally damaged some imprtant files. 3) Some sort of malware program or a hijacker got into my computer and then deleted some files. 1 of the 3 things could have caused my computer to crash after start up.

I had 3 free anti spyware/anti malware progams at the time. Plus the McAfee and Windows programs, I did 5 scans, all ran individually and at different times. The only thing that showed up was: FakeAlert and FakeAlert.cc Only one program picked that up. That was Spybot S&D free.

Why would 1 program pick something up and not the rest of them?
Also why did nothing show up on the scans when everything was updated?
Could something have gotten through that was so new, that it did not have a defense for it yet? and
If so, could it s... Read more

A:What Are The Best Free Anti-spy Ware And Anti-mal Ware Programs?

Hi MattNo one product will find everything which is why you need 'layers' of protection.SuperAntiSpyware is recognised as one of the better ones. I use the Pro version, together with ThreatFire and Comodo BOClean which seem to do the job. I also use Sygate Personal Firewall and Avast antvirus.Links to free programmes on every conceivable subject which are used and recommended by members can be found here: http://www.bleepingcomputer.com/forums/topic3616.htmlEveryone has their own ideas, so check around for what will work best for you.Cheers

1 more replies
Answer Match 34.86%

I wish i knew what type of virus it was, but sorry, i don't know.I have all my trust progs on the ignore list (with the exception of the occasional Mcafee restart prog) and whenever i delete all the items the show in the scan, if I wait 5 seconds, a whole nother set is installed in there. This is more or less endless, no matter how many times i do it. I took a breeze through the drivers, but I didn't see anything that stuck out as obviously bad. I know the scan I am about to post is going to have a few obvious .dlls as malisious, I will post a screenshot of whatcan up as my "normal delete" so if you see anything in the log thats not on the screeny, well that will point us in the right direction. Also, as a note, this is immediately after a Mcafee comp clean and a full virus scan.DDSDDS (Ver_09-03-16.01) - NTFSx86 Run by Jeff at 18:51:31.78 on Thu 04/09/2009Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_05Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3071.2346 [GMT -4:00]AV: McAfee VirusScan *On-access scanning enabled* (Updated)FW: McAfee Personal Firewall *enabled*============== Running Processes ===============C:\WINDOWS\system32\svchost -k DcomLaunchsvchost.exeC:\WINDOWS\System32\svchost.exe -k netsvcsC:\Program Files\Common Files\LogiShrd\Bluetooth\LBTServ.exesvchost.exesvchost.exeC:\WINDOWS\system32\spoolsv.exeC:\WINDOWS\system32\libusbd-nt... Read more

A:Some ad-ware

Hello! My name is Sam and I will be helping you. In order to see what's going on with your computer I may ask for you to post various logs from the tools that we will use to resolve your issue. Please also share with me any information about how your computer is reacting and behaving each step of the way as we work through this process.We need to create an OTListIt2 ReportPlease download OTListIt2 from hereSave it to your desktop.Double click on the icon on your desktop.Click the "Scan All Users" checkbox.Push the "Run Scan" button.The scan should take just a few minutes.Copy the log that opens up and paste it back here in your next reply.

4 more replies
Answer Match 34.86%

Hi,

I had this bug one of the files was awtuttqj.dll and IE was hijacked by softwarereferal.com/jump and there was Mal_Vundo-4...all of this friendly stuff that just makes you crazy. Most of it is gone and I have instituted all this protection now. I still have one... or maybe it is two issues. When the system boots and windows loads there is this error that is from quickset.exe. It says that the program falied to initialize. Press ok to continue. So I do and the system finishes and it doesn't seem to be a problem. Then after sometime and not all of the time I will get a rectangle in the task bar that has an exclamation mark. When I roll over it the caption says click to fix. So then I right click and it opens IE and has a picture of PC Spyware products in the display. I can close it and the exclamation goes away. I don't really like this and it is worrisome that something else might be looming. Can you tell me how to get rid of this. Thank you.

A:Spy Ware Or What?

not sure who decided you should run the combofix tool ??unsupervised? but as you have posted a combofix log in the HJT sectionhttp://www.bleepingcomputer.com/forums/t/144277/hijack-this-and-combofix/ we ought NOT to go any further on THIS thread until the thread in the HJT section is responded to one also presumes you did NOT read the combofix disclaimer?

2 more replies
Answer Match 34.86%

need a good site to download a free spyware program. sure that i need to clean my computer.

thanks
rodi
 

A:spy ware

8 more replies
Answer Match 34.86%
Q: Ad-ware

I am getting pop up ads when I surf the net. Like most people, I am using DSL so I'm always connected to the net and sometimes ads are popping up when I do not have any browser windows open. I have run both Adware and a Virus scan and neither has helped. I just switched internet providers so I'm using Verizon DSL now. I started getting the pop-ups a few days after switching. Here is my log:


Quote:




Logfile of HijackThis v1.99.1
Scan saved at 10:38:13 PM, on 5/29/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\Ati2evxx.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINNT\System32\svchost.exe
C:\PROGRA~1\Iomega\System32\AppServices.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\ZipToA.exe
C:\Program Files\Iomega\AutoDisk\ADService.exe
C:\WINNT\system32\inetsrv\inetinfo.exe
C:\WINNT\system32\Ati2evxx.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Pro... Read more

A:Ad-ware

Greetings, and welcome to TSF!

Please print out or copy this page to Notepad. Make sure to work through the fixes in the exact order it is mentioned below. If there's anything that you don't understand, ask your question(s) before proceeding with the fixes. You should 'not' have any open browsers when you are following the procedures below.

Go to My Computer->Tools/View->Folder Options->View tab and make sure that 'Show hidden files and folders' (or 'Show all files') is enabled. Also make sure that 'Display the contents of system folders' is checked. If you have Windows XP, the search feature is a little different. When you click on 'All files and folders' on the left pane, click on the 'More advanced options' at the bottom. Make sure that 'Search system folders', 'Search hidden files and folders', and 'Search subfolders' are checked.

For the options that you checked/enabled earlier, you may uncheck them after your log is clean. If we ask you to fix a program that you use or want to keep, please post back saying that (we don't know every program that exists, so we may tell you to delete a program that we think is bad to keep).

===============

Go to www.trendmicro.com, and then:

1. Click "Free Online Scan".
2. Click "Scan now, it's free".

It'll take a few minutes to download (especially with a dialup connection), so be patient. When it's down:

1. Select all available drives.
2. Check(tick) "Auto Clean&quo... Read more

8 more replies
Answer Match 34.86%
Q: VM ware

Hi,

I've just installed this software in my pc and ran win98 with it and connected to the internet but i wish to know, how can i install or use win2000 or xp with vm ware?

The win98 i have is one that a friend gave me.

thank you.
 

More replies
Answer Match 34.86%

As I drift into unfamiliar territory questions form. Which spy-ware program is the best and why? Is Ad-ware considered spy-ware? Will I need to separate programs to control both of these irritants?
 

A:Spy-ware???

7 more replies
Answer Match 34.86%

HI
I have a computer runnning Windows XP with 1g ram 80 hd ect

I downloaded a program the other night and now my computer has started to stop and lock up. I have started the system over and over. When i started in command prompt(think it was) the only program that jumped out was this one saying it was Teefers.sys and that was becuse it said is was a SYSTEM file not a System file. I don't know here is the HJT.

I have run avg and lavasoft and am still encountering problems

THe main problems being that the computer freezes and it trys to launch programs. At the moment I am getting a message on start up about CTloader, any help would be appreciated.

Cheers

Logfile of HijackThis v1.99.1
Scan saved at 12:30:14 AM, on 26/11/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
E:\Program Files\Sygate\SPF\smc.exe
C:\WINDOWS\system32\spoolsv.exe
E:\PROGRA~1\avg\avgamsvr.exe
E:\PROGRA~1\avg\avgupsvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
E:\PROGRA~1\avg\avgemc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxMediaDB.exe
C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxWatch.exe
E:\PROGR... Read more

More replies
Answer Match 34.86%

what is it -???
because I know for a fact that they can see me through the screen

A:spy ware

Quote:





Originally Posted by yaba-


what is it -???
because I know for a fact that they can see me through the screen




Spyware is a generic term for malware that collects data about the infected user and sends it off to an external server.

If you think you're infected, then I'd advise you to run AV and malware scans.

Download Malwarebytes Antimalware and run it in Safe Mode With Networking.

Sent from my Nexus 7 using TechForums

9 more replies
Answer Match 34.86%

I see a small window in the bottom right hand corner of my window.
It stuck 1 time and I maximized it and the window and I think the title was
" ADAN Window Manager "
Has anyone ever heard of that and do I need to remove it and if so ...HOW ???
thanks
 

A:Spy Ware ??

I haven't heard of it but here is a possible cure. Download Hijack This! from http://www.merijn.org/files/hijackthis.zip and make sure you save it in its own folder. Run a scan and save the results of the scan in a log. Open the log with notepad.Then, copy the contents of the log and paste it here. We'll analyze your log and tell you what to fix.
 

1 more replies
Answer Match 34.86%

ok, here is my hijackthis log and combofix scans. Trouble is, everytime i reinstall windows, even after a fresh format, my pagefile never leaves, and i am stuck with these strange windows services, not to mention a whole ton of open ports. Please help me clean the baddies.Active Connections Proto Local Address Foreign Address State TCP fri:epmap fri:0 LISTENING TCP fri:microsoft-ds fri:0 LISTENING TCP fri:2869 fri:0 LISTENING TCP fri:3729 mpa.one.microsoft.com:3730 ESTABLISHED TCP fri:3730 mpa.one.microsoft.com:3729 ESTABLISHED TCP fri:3731 mpa.one.microsoft.com:3732 ESTABLISHED TCP fri:3732 mpa.one.microsoft.com:3731 ESTABLISHED TCP fri:netbios-ssn fri:0 LISTENING TCP fri:3773 209.211.201.96:http TIME_WAIT TCP fri:3802 209.211.201.83:http TIME_WAIT TCP fri:3803 209.211.201.83:http TIME_WAIT TCP fri:3847 www.bleepingcomputer.com:http TIME_WAIT TCP fri:3848 www.bleepingcomputer.com:http TIME_WAIT UDP fri:microsoft-ds *:* UDP fri:isakmp *:* UDP fri:1040 *:* UDP fri:1737 *:* UDP fri:1903 *:* UDP fri:1904 *:* UDP fri:3160 *:* UDP fri:3161 ... Read more

A:Please Help, Ive Tried Everything.. Some Vmm Ware?

-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Wednesday, October 03, 2007 8:54:06 AM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.93.1
Kaspersky Anti-Virus database last update: 3/10/2007
Kaspersky Anti-Virus database records: 426738
-------------------------------------------------------------------------------

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
A:\
C:\
D:\
E:\

Scan Statistics:
Total number of scanned objects: 17532
Number of viruses found: 3
Number of infected objects: 20
Number of suspicious objects: 4
Duration of the scan process: 00:23:46

Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\fry\Application Data\Mozilla\Firefox\Profiles\mzvdfuux.default\cert8.db Object is locked skipped
C:\Documents and Settings\fry\Application Data\Mozilla\Firefox\Profiles\mzvdfuux.default\formhistory.dat Object is locked skipped
C:\Documents and Settings\fry\Application Data\Mozilla\Firefox\Profiles\mzvdfuux.default\history.dat Object is locked skipped
C:\Documents and Settings\fry\Application Data\Mozilla\Firefox\Profiles\mzvdfuux.d... Read more

2 more replies
Answer Match 34.86%

What is this? http://www.download.com/3001-8022_4-10399602.html
Is it like antivirus or what?

Thanks for any replies.

- Joker
 

More replies
Answer Match 34.86%

hi i am wondering if anyone knows a better spy ware ditecter than Ad-Aware SE Personal it is good but i keep getting popups still

can anyone help me please

A:spy ware

Try spybot search and destroy!

2 more replies
Answer Match 34.86%

Hey, on my other computer, i some how managed to down load a virus that has gotten past both my firewall and my Norton internet security virus protection. I am currently using operating system Windows xp on that computer. The main problem, however, is that it has not only slowed down my computer, but it has caused it to completely freeze over and over again. I cannot even manage to get onto my main account, (because it freezes before it finishes logging on) and my other 2 accounts freeze right ofter i log on, or in a few minuets after i manage to log on. Some times i get the time to try and run a virus scan, however, once i press the button, the computer freezes and i have to restart it by holding down the power button for 8 seconds. pleases tell me what to do, or how i can fix that computer. I really like it.
 

More replies
Answer Match 34.86%

i was just wondering what to fix with my hijackthis file

Logfile of HijackThis v1.97.7
Scan saved at 23:29:50, on 01/11/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\Nokia\NOKIAP~1\TRAYAP~1.EXE
C:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE
C:\WINDOWS\Mixer.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\Program Files\802.11 Wireless LAN\802.11b Wireless USB Adapter HW.00 V1.20\Wireless Configuration Utility HW.00.exe
C:\PROGRA~1\COMMON~1\PCSuite\Services\SERVIC~1.EXE
C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Yahoo!\Messenger\ypager.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\M... Read more

A:spy ware

Hi mikey and welcome to TSF!

Please print out or copy this page to Notepad. Make sure to work through the fixes in the exact order it is mentioned below. If there's anything that you don't understand, ask your question(s) before proceeding with the fixes. You should not have any open browsers when you are following the procedures below.

Go to My Computer->Tools/View->Folder Options->View tab and make sure that 'Show hidden files and folders' (or 'Show all files') is enabled. Also make sure that Display the contents of System Folders' is checked. Windows XP's search feature is a little different. When you click on 'All files and folders' on the left pane, click on the 'More advanced options' at the bottom. Make sure that Search system folders, Search hidden files and folders, and Search subfolders are checked.

Turn off system restore by right clicking on My Computer and go to Properties->System Restore and check the box for Turn off System Restore. Click Apply and then OK. Restart your computer. After we are finished with your log file and verified that it's clean, you may turn it back on and create a new restore point.

You have an outdated version of HijackThis. Click here to get the latest version of HijackThis.

Download WinsockFix and unzip it. Then double-click on it to run it.

Reboot into Safe Mode (hit F8 key until menu shows up).

Uninstall the following via the Add/Remove Panel (Start->(Settings)->Control Panel->Add/... Read more

7 more replies
Answer Match 34.86%

Hi Again,

I'm running windows ME. I just did a full spy ware sweep using Spy Sweeper. The results were:

Spyware found 12
Associated Traces Found 1,085

How do I know if they are all safe to delete.

The last time a deleted them all. Kazaa stopped working and I had to re load it

Any help would be great

Thanks
 

A:Spy Ware

Hi ColleenA

I'm not familier with spysweeper

If a program stops working when you remove the spyware then it's not worth having - there are spyware free alternatives out there to do most things.

Kazaalite instead of Kazaa for instance

steam
 

2 more replies
Answer Match 34.86%

How do you get rid of spyware,and keep it from coming back?
 

A:Spy Ware

Are you experiencing problems?

Download and save these freeware/donationware programs to a permanent folder. Remember to check for updates and run them weekly.
***NOTE***A new version of Ad-aware has been released.
***ALSO***A new version of SpyBot's been released (v1.3...it's no longer in beta). If you have been using 1.2 you can install right over it. If you downloaded and used 1.3 beta it is suggested you remove it and reboot prior to installing.
Ad-aware SE download

Configure Ad-aware
First in the main window look in the bottom right corner and click on "Check for updates now." then click Connect and download the latest reference files.

From the main window, click Start then under "Select a scan Mode " select "Perform full system scan.

Next deselect "Search for negligible risk entries.

Click the "Next" button.

When the scan is finished mark everything for removal and get delete the selections. (Right-click within the window and choose "Select All" from the drop down menu and click Next)

Restart your computer.
SpyBot Search and Destroy download

Open SpyBot.

Click the button to "Search for Updates" Download and install the Updates.

Next click "Check for Problems".

Put a check mark beside the red entries.

Choose "Fix Selected Problems" and allow Spybot to fix the red entries.

I also highly recommend you install and update SpywareBlaster Click the link belo... Read more

2 more replies
Answer Match 34.86%

Oleae help. Every tim I try to use Ad-Aware and start to scan, the PC , using XP, reboots itself. Attached is the HJT log:

A:Mal-ware?

Welcome to the BleepingComputer HijackThis Logs and Analysis forum mgeorgevich My name is Richie and i'll be helping you to fix your problems.Download SDFix.exe and save it to your desktop:http://downloads.andymanchesta.com/RemovalTools/SDFix.exe* Double click on SDFix on your desktop,and install the fix to C:\ Please then reboot your computer into Safe Mode by doing the following:* Restart your computer* After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;* Instead of Windows loading as normal, a menu with options should appear;* Select the first option, to run Windows in Safe Mode, then press "Enter".* Choose your usual account.* In Safe Mode,go to and open the C:\SDFix folder,then double click on RunThis.bat to start the script.* Type Y to begin the script.* It will remove the Trojan Services then make some repairs to the registry and prompt you to press any key to Reboot.* Press any Key and it will restart the PC.* Your system will take longer that normal to restart as the fixtool will be running and removing files.* When the desktop loads the Fixtool will complete the removal and display Finished, then press any key to end the script and load your desktop icons.* Finally open the SDFix folder on your desktop and copy and paste the contents of the results file Report.txt into your next reply.Download Combofix and save to your desktop:Note: It is important that it is saved directly to ... Read more

10 more replies
Answer Match 34.86%

Hi,,
I had sound this morning, then ran Ad-ware which detected like 220 critical objects,
which I deleted. now I don't have any sound. Is there something I can do to get my sound back??
thanks,,
karebear
 

More replies
Answer Match 34.86%

Everytime my computer goes into screensaver mode these Black bugs on the screens pop up on my screen.

-Norton scan found to virus
-Spy Sweeper found some but didn't remove bugs


Any ideas?

Thanks

A:Possible Ad-ware not certain

Did you install a 3rd party Screen Saver? That's what it sounds like.

Have you tried using a different Screen Saver?

Desktop Properties, Screen Saver tab.

2 more replies
Answer Match 34.86%

As related to my topic before, I am sorry because this is considered spamming but I can't view that thread because it is now closing on me due to the previously stated problem HERE. so please reply here and don't use the S-word or my browser will crash.

A:S-Ware Again!

Look over the First Steps at Removing Malware

Also try running those anti -you know what programs in Safe Mode

What browser are you using? Have you tried using Firefox?

8 more replies
Answer Match 34.86%

I ran adaware, AVG and SDK remover already but there is still something wrong.

C:\Documents and Settings\Sol\Desktop\HiJackThis_v2.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://manageyourdealership.com/d1_m...&bdg=AutoBlitz
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper
O4 - HKLM\..\Run: [TpShocks] TpShocks.exe
O4 - HKLM... Read more

More replies
Answer Match 34.86%

I have a problem with spy bots.All programs from net reqest regestared.I nee Anty spy ware program with no regestered but to can cleen it what found.
Thank`s

A:Spy Ware

If you think you are infected submit a hijackthis log to the HJT Forum.How to submit a hijackthis logDownload HijackthisTry running the following from safe mode (Getting to safe-mode) Sysclean you'll also need the virus template file from here lpt***.zip remember to extract the contents of the zip file into the same folder as Sysclean.comorDrWeb CureITorKASFX which is powered by the Kaspersky AV engine, you will need internet access to update it. If you haven't got net access in safe mode, update it before you use it.If your good with the command line also try Sophos Command Line scanner this command will scan all of your hdd's SAV32CLI.EXE -F -di -remove -dn -mbr -all -zip -p=avscanlog.txt and give you a log file to review afterwards.Also try installing and running A2 Free and Ewido again run from safe mode.I'd also run Spybot(Spybot Tutorial) and AdawareIf your using Win2K/XP run adaware/spybot from "safe mode with command prompt" If your using Win9x just run it from safe mode the command line options aren't needed..At the C:\ prompt type the following:-cd\C:\progra~1\spybot~1\spybotsd.exe /autocheck /autofixcd\C:\progra~1\lavasoft\ad-awa~1\ad-aware.exe

1 more replies
Answer Match 34.86%

webbuyingassistant has been installed on my PC and I can't get it off with Spybot, Ad Aware, or Super AntiSpyWare. I have been reading some online help and people suggest running HijackThis and posting the log.

Here is my log. Can someone help me figure out how to remove this spyware?
thanks

Logfile of HijackThis v1.99.1
Scan saved at 10:02:27 PM, on 7/22/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\ehome\RMSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\Program Files... Read more

A:need help getting ad ware off my PC

16 more replies
Answer Match 34.86%
Q: Ad-ware

Hmm theres some things in ad-ware which you have to unmark right?i saw it somewhere but forgot where so i am asking..=D any guide?Moderator Edit: Moved topic to more appropriate forum. ~ Animal

A:Ad-ware

Take at look at this tutorial.Using Ad-Aware SE to remove Spyware & Hijackers from Your Computer

1 more replies
Answer Match 34.86%

Logfile of HijackThis v1.99.1Scan saved at 11:58:38 PM, on 8/27/2006Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\ZoneLabs\vsmon.exeC:\WINDOWS\Explorer.EXEC:\Program Files\Common Files\Symantec Shared\ccSetMgr.exeC:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exeC:\WINDOWS\system32\spoolsv.exeC:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exeC:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exeC:\communications\Norton AntiVirus\navapsvc.exeC:\communications\Norton AntiVirus\AdvTools\NPROTECT.EXEC:\WINDOWS\system32\nvsvc32.exeC:\communications\Norton AntiVirus\SAVScan.exeC:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exeC:\WINDOWS\system32\CTHELPER.EXEC:\Program Files\Common Files\Symantec Shared\ccApp.exeC:\Program Files\Java\jre1.5.0_06\bin\jusched.exeC:\communications\Zone Labs\ZoneAlarm\zl... Read more

A:Spy Ware

Hello bdiodato24 and welcome to the BC HijackThis forum. After reviewing your log I see a few items that require our attention. Please print these directions and then proceed with the following steps in order.Step #1Download CCleaner and install it but do not run it yet.Step #2Start in Safe Mode Using the F8 method:Restart the computer.As soon as the BIOS is loaded begin tapping the F8 key until the boot menu appears.Use the arrow keys to select the Safe Mode menu item.Press the Enter key.Step #3Start HijackThis and click the Scan button to perform a scan. Look for the following items and click in the checkbox in front of each item to select it:O4 - HKLM\..\Run: [Lisa] C:\Program Files\PInfo\Dialers\Lisa\Lisa.exe /dontdialO4 - HKLM\..\Run: [RemoveWGA] C:\Documents and Settings\Brad D\Local Settings\Temporary Internet Files\Content.IE5\AHK3UDMH\RemoveWGA.exe -startupO16 - DPF: {972BB342-14A7-4660-83C1-51DDBEE171DB} - http://www.pacimedia.com/install/pcs_0024.exeO20 - Winlogon Notify: WgaLogon - WgaLogon.dll (file missing)O23 - Service: Power Manager (PowerManager) - Unknown owner - C:\WINDOWS\svchost.exe (file missing)Now close ALL open windows except HijackThis and click the Fix Checked button to finish the repair.Step #4We need to make sure all hidden files are showing so please:Click Start.Open My Computer.Select the Tools menu and click Folder Options.Select the View tab.Under the Hid... Read more

1 more replies
Answer Match 34.86%

Hi,

I have used many adware removing programs but it appears that as soon as I connect to the internet it re-dowloads itself.

I have a HP Pavilion s7220n Slimline PC, Intel Celeron, and Window XP SP2.
Your help will be greatly appreciated.

Thank you,
Superxela

HijackThis Logs

Logfile of HijackThis v1.99.1
Scan saved at 1:14:29 PM, on 3/26/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\slk8x2peu.exe
C:\WINDOWS\system32\898A938E9295948.exe
C:\WINDOWS\sys024706863911.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\outlook\outlook.exe
C:\... Read more

A:Help with spy-ware

You have several infections present, we'll take them one at a time....

Please download Brute Force Uninstaller to your desktop. (rightclick on this link and choose save as, if using IE save target as)Right click the BFU folder on your desktop, and choose Extract All
Click "Next"
In the box to choose where to extract the files to,
Click "Browse"
Click on the + sign next to "My Computer"
Click on "Local Disk (C:) or whatever your primary drive is
Click "Make New Folder"
Type in BFU
Click "Next", and Uncheck the "Show Extracted Files" box and then click "Finish".
Download qoofix.bat (rightclick on this link and choose save as, if using IE save target as)
Place qoofix.bat in your C:\BFU - folder. (Important!)
Doubleclick qooFix.bat, Close all browsers and explorer folders.
Choose option 1 (Qoolfix autofix) and follow the prompts.
Please be patient, it will take about five minutes.
After the PC has restarted please post another hijackthis log.

18 more replies
Answer Match 34.86%

Just got this site information today from CompuerEdge about sending a copy of a log about possible spy ware that may be on your computer. If anyone can point me to anything that I should delete please let me know

Thanks alot

Mjack547
Logfile of HijackThis v1.96.4
Scan saved at 9:56:08 AM, on 9/1/2003
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\SYSTEM32\ZONELABS\vsmon.exe
C:\Program Files\Intel\Intel(R) Active Monitor\imonnt.exe
C:\WINDOWS\Explorer.EXE
F:\Program Files\FSI\F-Prot\F-StopW.EXE
C:\program files\quicktime\qttask.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\ZONELA~1\ZONEAL~1\zapro.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\WINDOWS\System32\CTHELPER.EXE
C:\SysAgent\SysAgent.exe
C:\WINDOWS\System32\devldr32.exe
C:\Program Files\Intel\Intel(R) Active Monitor\... Read more

A:Spy ware

Hi mjack547, Welcome to TSG

Not much going on with your log. You can have HJT remove two items. Close your borwser, and check the items in HJT, click Fix and reboot afterwards:

O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
FYI, two good spyware applications:

http://www.majorgeeks.com/download.php?det=506

http://spybot.eon.net.au/index.php?lang=en&page=download

 

3 more replies
Answer Match 34.86%

can someone help me with this:
http://www.techsupportforum.com//sec...re-adware.html
in my second post on there i put my Hijackthis log- bfu's log- and uninstall log from hjt
im very close to just doing a system recovery and loosing it all because it takes so long to do anything. i get soo many pop up's and everything else, please help, im very desperate.

A:help ad/spy ware

Skate Punk has answered your thread.

Please respond to that

1 more replies
Answer Match 34.86%

all of a sudden i keep getting a url comming up when surfing that is : flashlight.com/search. i used to be able to type in: crsrocks.com hit enter and i would get to the sight, now if i don't put :http://www.crsrocks.com (or any other address) i get the flashlight page which is some search engine.
how can i get rid of this? i have run spybot and addware to no avail.
thanks. oh, im not real computer geek so please speak in plain english...
 

A:ad ware or what?

Try CwShredder, please click HERE scroll down to Official downloads and look for CwShredder.
 

1 more replies
Answer Match 34.86%

I have windows 98 - I try to run the perform full system scan on the free ad-ware se that i update every session and at any given random file it reads busy and will not continue finishing the scan - when i do the smart scan it does finish but list no new critical objects, on the full scan when it stops scanning it always has 10 new critical objects that i can't delete as it will not finish scanning - I have allowed the system to scan in this busy mode for over 24 hours it never changes - Can someone help?

I am wondering if when I loaded the upgrade to the kazaa if the p2p networking files are interfering with the adware se - I don't know if i got rid of all the p2p files - thnx

A:Help with ad-ware se

I will move this over to the HijackThis Log Help category.

You have spyware there. Depending on which version of Kazaa you have there, your system might be full of spyware.

Make sure that you have your Ad-aware settings changed to the ones shown here. Try running it again. Run the scan in Safe Mode if you can.

If it still fails, just continue on and give us the HijackThis log:

Please download HijackThis - this program will help us determine if there are any spyware/malware on your computer. Create a folder at C:\HJT and move HijackThis.exe there. Double click on the program to run it.

1. If it gives you an intro screen, just choose 'Do a system scan and save a logfile'.
2. If you don't get the intro screen, just hit Scan and then click on Save log.
3. Get HijackThis Analyzer and save it to the same folder as the hijackthis.log file. Run HijackThis Analyzer and type in y if you agree. The result.txt file will open up in Notepad. Copy the whole result.txt log and post it in the forum. We do not need the original hijackthis.log (unless we ask for it). Do not fix anything in HijackThis since they may be harmless.

19 more replies
Answer Match 34.86%

Once again i am back for help. The information that was I told earlier from 2 people helped sort of. Ok, so heres whats going on. Earlier today, I received a "system alert" from a little baloon on the bottom of my desktop. I know its a Spy-ware. It changed my desktop to Asecurityupdate.com. So far, I have managed ( at least I think I have) to delete some infected files. My IE homepage has been turned back to my defauly website. But the only problem I still have is that the little baloon stating that I have "system alert" keeps popping up. I've downloaded AVG, S&D, SuperAntiSpyware, and as well as Windows Defender. For some reason, when I run scans to find the spy-wares, if any are found, they are deleted. But the baloon keeps popping up. And it is slowing down my PC horribly. I have no idea what else to do. I could really use some help. Thanks.
 

More replies
Answer Match 34.86%

I have had nothing but trouble lately, I downloaded "Spy Sweeper" to try to get rid of LOP, I am not sure its gone. I know have some funky search bar with the properties of http://look-today.com/passthrough/newpass2.html , I cannot get rid of it! also my hijack shield keeps coming up every few minutes and I have to deny changes to my home page. Any help would be appreciated, I am not to comp literate but do have a little common sense, so hopefully I can get rid of this soon.
 

A:Cannot get rid of ad ware!!!!

9 more replies
Answer Match 34.86%

I just got a new computer and some pop up came on and said something like my computer was in danger and I needed to remove all the threats and I accidently installed something called spy shredder how do I get rid of it?

More replies
Answer Match 34.86%

running win 7 64 bit i have 4 gig of ram installed but system says only 3.326 available
ware is the rest of it
 

A:ware as my ram gone

10 more replies
Answer Match 34.86%

EDIT: I got rid of this program that seemed to install randomly called Anti-virus XP 2008, and I deleted any files associated with it. Now whenever my computer idles, it cuts to this blue-screen with something telling me there's and error, and the goes to the XP loading screen, and then after 20 seconds, goes to an orange screen. It keeps cycling over and over until I press a key on my keyboard
So I just made anew hijack this log:

Logfile of HijackThis v1.99.1
Scan saved at 9:03:31 PM, on 8/14/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\WINDOWS\System32\snmp.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\Explorer.EXE
C:\windows\system\hpsysdrv.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe... Read more

More replies
Answer Match 34.86%

Hi!

I'm having major troubles getting rid of some adware/spyware/pop ups and would appreciate any help on how to free my computer from this. I'm including a log file from Hijack This, see below.

The problem is i keep getting re-directed to various porn ads when moving away from a site using IE (for example when downloading Hijack This).

I've already tried both AdAware and Spybot, I've also used Bazooka and tried to remove them manually. All of these programs find several "bad" files and says they get rid of them, but either they don't go away at all or they come back shortly. One time I actually got rid of all of them, but after the next reboot several of them were back.

Examples of "bad" files I've tried to get rid of are "twaintec" "Flingstone Bridge" "Alchem" "ISTBar" (from Bazooka) "DSO Exploit" (Spybot) and several others from Ad-aware.

Would be very thankful for help
//Stefan

Logfile of HijackThis v1.97.7
Scan saved at 21:59:13, on 2004-07-28
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C... Read more

A:Can't get rid of pop ups & Ad ware

8 more replies
Answer Match 34.86%
Q: Ad-ware

Hi.
Cant download Adware SE 2007 free version.
Any idea?
Thanks mlettel
 

A:Ad-ware

Hi mlettel. Just follow the link there are some other free goodies on offer.
http://www.filehippo.com/
 

1 more replies
Answer Match 34.86%

Good evening,
I found in my computer with spyware program Marwarebytes 21.
I cleaned the computer but is slow anda friend advised me to run Combofix.
I used the program by following all the advice.
I would like to know, please, where do I post the Combofix log file.
thanks

A:Spy ware

Hello having run ComboFix we need to see that and a DDS log.Please go here....Preparation Guide ,do steps 6 - 9.Create a DDS log and post it in this topic,thanks.Skip the GMER step and instead post the ComboFix log you have.Let me know if that went well.

5 more replies
Answer Match 34.86%

Lately i've been getting weird redirects from google searches that i usually search all the time, such as Facebook or Gamespot or IGN, and when i would click on the link I would get redirected to a very poor,sometimes advertising, made website and each time i would hit the back button it would automatically redirect me to another site or the same site. The only way i could get back to my google searches was by going to my history and going to the searches and the only way to avoid the redirects again was to open the link in a different tab.
I already downloaded Malware Bytes and did a complete scan and nothing came up, and with Spy bot Search and Destroy.
Although, i did do a Anti-Root kit scan on AVG and came up with all of these infections that couldn't be cured because something was masking it's location, AVG just knew it was there.
I'm not sure what i need to do and i need help
Also, each time i restart my computer i have to restart it 3 or 4 times because each time i log on to my account the monitor is black. My windows theme will change randomly without me doing it from Windows Vista to Windows Classic, sometimes not allowing me to play games or download things, to change it back to Windows Vista i had to restart my computer. If you need any additional information please, do ask.
P.S.
I have Windows Vista, on a Desktop and I refuse to reformat my hard drive.
 

A:Need help! Possible Mal-ware!

Hiya SnowJayson

I'm kevinf80 and I will be helping with any malware issues you may have with your system.

Please be aware that some of the logs I may ask for can be very complex and can take a long time to decipher. I am a volunteer here with a job and family so I ask that you be patient when waiting for replies.
Please DO NOT run any scans/tools/fixes on your own as this will conflict with the tools we are going to use.
Either print or Save to Notepad all instructions and please follow them carefully, if there's something you don't understand or that will not work please let me know and we will go through it together.
Malware is often buggy and can be very unstable, with that in mind it is advisable to backup any important data before we begin.
If you do not reply within 72 hours the thread will be closed, if you need more time let me know. Likewise if I do not respond within 48 hours feel free to PM me.
If you have any P2P applications installed such as BitTorrent, uTorrent, Limewire etc etc, please uninstall them before we begin.
If you are using Cracked or Illegal software your thread will be locked and all help will cease.

Please proceed as follows :-

Please read carefully and follow these steps.

Download TDSSKiller and save it to your Desktop.
Extract its contents to your desktop.
Once extracted, open the TDSSKiller folder and doubleclick on TDSSKiller.exe to run the application, then on Start Scan.

If an infected file is detected, the d... Read more

3 more replies
Answer Match 34.86%

I have tried Spybot Search and Destory and Ad-Aware but these problems just keep occuring.

When I click on IE on my desktop it freezes and asks for error reporting everytime and I can't change my desktop from just a solid color!

Here's my HJT log.

Logfile of HijackThis v1.99.1
Scan saved at 10:21:02 AM, on 4/15/2006
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\pctspk.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\LClock\LClock.exe
C:\WINDOWS\System32\eventwvr.exe
C:\WINDOWS\System32\syshost.exe
C:\WINDOWS\system32\srshost.exe
C:\Program Files\NETGEAR WG311v2 Adapter\wlancfg5.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\devldr32.exe
C:\WINDOWS\TEMP\24EF.tmp
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
R0 - HKCU\Software\Microsoft\Intern... Read more

A:Need Help--Spy/Ad-Ware Took Over!

Please save or print these instructions before beginning

Save smitRem to your Desktop and run smitRem.exe

Download and install Ewido Security Suite
During the installation, uncheck the following under Additional Options:

Install background guard
Install scan via context menu
​Run Ewido and click OK when prompted to update the program
On the left side of the screen, click update>>Start
When the update is finished, exit Ewido

Start your computer in Safe Mode

Open the smitRem folder and run RunThis.bat. Follow the onscreen prompts

Run Ewido Security Suite
Click scanner>>Complete System Scan
Click OK when prompted to clean the problems found
When the scan is finished, click Save Report and save a copy of this log to your Desktop
Exit Ewido

Go to Start>>Control Panel>>Internet Options>>Programs
Click Reset Web Settings>>Apply>>OK

Go to Start>>Control Panel>>Display>>Desktop
Click Customize Desktop>>Web
If you see an entry called Security info or something similar, select it and click Delete>>OK>>Apply>>OK

Restart your computer

Run Kaspersky Online Scanner and post the results here

Post the contents of C:\smitfiles.txt

Post the contents of the Ewido Security Suite report that you saved to your Desktop earlier

Please update your computer to Service Pack 1 and post a new HijackThis log
 

1 more replies
Answer Match 34.86%
Q: VM Ware

I've just been given the task to create a VM Ware image of a software. I dont know where to get started. Can anyone provide a link(s) as to what I should look into. Is there like a VM ware creator to create it or steps to properly creating a vmware image?

Thanks
 

A:VM Ware

VMWare is a virtualization program that is meant to run a guest operating system. Thus the type of image that you need to boot to use it is either a real bootable drive, bootable virtual drive, or a bootable image file that represents the operating system to run.

There is no special way to create the image file - just create an iso of the operating system boot drive.

Please keep in mind that I have never used VMWare, however it is similar to VirtualPC which I have used and base my post off of.
 

1 more replies
Answer Match 34.86%

Hi, I am John Landale and I am going mad trying to get rid of the Mysearchdial search engine. It is driving me crazy. It has infected my firefox search engine and I can not get rid of it. It also infected my google search engine but  I managed to get rid of that by clicking on different parts of the bar until I found how to do it. I have had no luck at all with Firefox. I do hope some one can help me.Thank You John LandaleEdit: Moved topic from Introductions to the more appropriate forum.~ Animal

A:mal ware

Hi John
 
Welcome to BC!
 
Please download and use the following tools (in the order listed) which will search for and remove many potentially unwanted programs (PUPs), adware, toolbars, browser hijackers, extensions, add-ons and other junkware as well as related registry entries (values, keys) and remnants.RKill created by Grinler (aka Lawrence Abrams), the site owner of BleepingComputer.AdwCleaner created by Xplode.Junkware Removal Tool created by thisisu.1. Double-click on RKill to launch the tool. A black DOS box will briefly flash and then disappear. This is normal and indicates the tool ran successfully.Important: Do not reboot your computer until you complete the next step.2. Double-click on AdwCleaner.exe to run the tool.Vista/Windows 7/8 users right-click and select Run As Administrator.
Click on the Scan button.
AdwCleaner will begin...be patient as the scan may take some time to complete.
After the scan has finished, click on the Report button...a logfile (AdwCleaner[R0].txt) will open in Notepad for review.
After reviewing the log, click on the Clean button.
Press OK when asked to close all programs and follow the onscreen prompts.
Press OK again to allow AdwCleaner to restart the computer and complete the removal process.
After rebooting, a logfile report (AdwCleaner[S0].txt) will open automatically.
Copy and paste the c... Read more

1 more replies
Answer Match 34.86%

One little simple question, What are the pros and cons of spybot software?feel free to answer me at
[email protected]


vic
 

A:spy ware

Well the search feature is your friend.

Take a look at this thread and that should help you out.

But to simply answer your question spybot software is good because it will scan for spyware on your computer and get rid of it.
 

5 more replies
Answer Match 34.86%

Hello - my computer has been running slower then usual and my homepage keeps getting changed (not by myself).  I have an anti-malware tool which I have been using over the past 2 weeks.  Each time I run it a few more mal-ware files are found even though I "repair" them each time.  I have used this site in the past and it was SO helpful - can someone help again? I have attached the report from my last scan
Thank you in advance!

A:Mal-ware and what else?

 
 Install and run MBAM
Information about MBAM: http://www.bleepingcomputer.com/virus-removal/how-to-use-malwarebytes-anti-malware-tutorial
If this scan has been done, please post the the log into your next reply.
 

  Running TDSSKiller to obtain log
 
Note: Don't cure or delete a threat, but choose skip for all instead.
Please download TDSSKiller from here and save it to your Desktop
Doubleclick on TDSSKiller.exe to run the application, then click on Change parameters

In the Additional options: Check Detect TDLFS file system
Click Start Scan and allow the scan process to run

Choose for all threats to Skip for all of them.
Click Continue
Please post the TDSSKiller.[Version]_[Date]_[Time]_log.txt found in your root directory (typically c:\)
===================================================
 
 ESET Online Scanner
==================
Note: If your AV is blocking Eset online scanner, please temporarily disable your AV.
 
I'd like us to scan your machine with ESET OnlineScan This process may may take several hours, that is normal.
Hold down Control and click on this link to open ESET OnlineScan in a new window.
Click the  button.
For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
Click on esetsmartinstaller_enu.exe to download the ESET Smart Installer. Save it to your desk... Read more

24 more replies
Answer Match 34.86%

How long would it take for a cd to "ware out"?
Maybe being burned at 8x
Thanks
 

A:cd ware out...

One perspective here :

http://forums.afterdawn.com/thread_view.cfm/48904
 

2 more replies
Answer Match 34.86%

ready for removal, I think?

A:mal-ware take over

Hello firemanjonny,My name is Cody and I'll be helping you clean up your computer.I will reply as soon as possible (typically within 24 hours). In turn, I ask that you please respond within 72 hours. If you know you will be away longer than that, I just ask for notice ahead of time.Some points for you to keep in mind: Do NOT run any tools unless instructed to do so.
We ask you to run different tools in a specific order to ensure the malware is completely removed from your machine, and running any additional tools may detect false positives, interfere with our tools, or cause unforeseen damage or system instability. Do not attach logs or use code boxes, just copy and paste the text.
It's simply easier for me to analyze logs in this format. Provide feedback about your experience as we go.
Every post you make, please describe in detail how the computer is behaving. "The same" is not detailed enough. If you have any questions at any point, feel free to ask.NOTE: When you post your reply, do not use the button but use the button instead. In the upper right hand corner of the topic you will see the button. Click on this then choose Immediate E-Mail notification and then Proceed and you will be sent an email once I have posted a response.NOTE: Backup any files that cannot be replaced. Removing malware can be unpredictable and this step can save a lot of heartaches if things don't go as planned. You can put them on a CD/DVD, external drive or a pen ... Read more

4 more replies
Answer Match 34.86%

Dear all,
I am new to this forum. I have serious issues with being spied on by my suspious spouse. our computer has spyware in it and I am aware of it. But I have noticed that What I am speaking everyday, every moment is also being recorded. How can I find out how this is happenning and where could I locate any recorders if any. PLease, please help.
Thank you. Appreciate it.
ATPT
 

More replies
Answer Match 34.86%

i got a major prob i got a browser hijacker and some weird search toolbars and stuff i cant get rid of im running windows me heres my log... any help would be greatLogfile of HijackThis v1.98.0Scan saved at 15:40:46, on 09/08/2004Platform: Windows ME (Win9x 4.90.3000)MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)Running processes:C:\WINDOWS\SYSTEM\KERNEL32.DLLC:\WINDOWS\SYSTEM\MSGSRV32.EXEC:\WINDOWS\SYSTEM\mmtask.tskC:\WINDOWS\SYSTEM\MPREXE.EXEC:\WINDOWS\SYSTEM\MSTASK.EXEC:\WINDOWS\SYSTEM\SCARDSVR.EXEC:\WINDOWS\EXPLORER.EXEC:\WINDOWS\TASKMON.EXEC:\WINDOWS\SYSTEM\SYSTRAY.EXEC:\WINDOWS\PCTVOICE.EXEC:\WINDOWS\SYSTEM\HIDSERV.EXEC:\PROGRAM FILES\COMPAQ\DIGITAL DASHBOARD\CPQMLDET.EXEC:\COMPAQ\EAKDRV\STARTDRV.EXEC:\WINDOWS\LOADQM.EXEC:\COMPAQ\EAKDRV\EAKDRV.EXEC:\WINDOWS\SYSTEM\WMIEXE.EXEC:\WINDOWS\KDX\KHOST.EXEC:\PROGRAM FILES\COMET SYSTEMS\DM\BIN\DMSERVER.EXEC:\WINDOWS\SYSTEM\QTTASK.EXEC:\WINDOWS\SYSTEM\RESTORE\STMGR.EXEC:\WINDOWS\DHBRWSR.EXEC:\WINDOWS\SYSTEM\ZPFUJJ.EXEC:\WINDOWS\SYSTEM\DDHELP.EXEC:\COMPAQ\EAKDRV\EAUSBKBD.EXEC:\WINDOWS\RunDLL.exeC:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXEC:\PROGR... Read more

A:Spy ware help!

Please do the following regardless of whether or not you have done it before.Please follow these steps in order to clean your computer of Malware which can include Viruses, Trojans, Worms, Spyware, Hijackers and Dialers.Step 1:Download Spybot and Adaware from the following locations and install them. You should run both programs and clean up what it finds. This is to gaurantee that you find the most malware you can installed on your computer.Before running the scans on both programs, it is mandatory that you update the programs. There are update options in each program when you run them.SpybotAd-awareIf you would like to learn more about how to use these two programs with the proper settings you can read the tutorials below:Using Ad-aware to remove Spyware, Malware, & Hijackers from Your Computer.Using Spybot - Search & Destroy to remove Spyware, Malware, & Hijackers from Your Computer.When you scan with both programs, fix everything that it finds.When you are done with the scan and fixing the items. Please continue with the next step.Step 2:It is important that you run Spybot and Adaware before you proceed with this step. Fixing enties with Hijackthis may leave behind unwanted files on your computer if the previous step was not done first.Create a directory on your hardrive to save HijackThis.exe. A directory like c:\hijackthis. If you do not do this, you will not be able to use the backup/restore features.Download HijackThis from:HijackThis Download Site #1or Hijac... Read more

10 more replies
Answer Match 34.86%

my dell inspirion 1100 has been invaded by spy ware. I have adware and spybot and keep removing but something is still here. My address bar know only works with msn search if I put the word search before the word I am searching for. If I type something in the search bar without doing the above mentioned way then I get this page cannot be displayed. If I hit the search button a search "startium" in loaded. Help I am lost with all of this.
 

A:spy ware help!!!

7 more replies
Answer Match 34.86%

i need information to remove"Security Tool"

A:spy ware

As no logs have been posted, I am shifting this topic from the specialized HiJack This forum to the Am I Infected forum.==>PLEASE DO NOT NOW POST LOGS<== unless a log is specifically requested.

2 more replies
Answer Match 34.86%

Is it just me or does anyone else have this problem?

My friends and family ask me to repair their computers and promise to pay me later, usually the following Friday or a couple of days after I've fixed there system. Is there some sort of reminder/nag ware that I can set a reminder to aggravate them into paying me once a certain date has passed. I'd really like something password protected that locks them out, that would be bad azz.

Seems, i'm being pimped by everybody I know.

A:You for got to pay me ware

That sounds like installing Ransomeware.. Malware we remove here.

Stick with Please pay when served. If not hold the machine. You have to have the advantage,

My opinion

4 more replies
Answer Match 34.86%

Recently I have been getting a ton of pop-ups on my computer. It stasrted a couple days ago and I have been trying to get ride of them. I had Medialoads installer and Ncase on my computer and don't know if I got them all off. Pop-up are still killing me. I dl that hijack program so maybe you could help me figure out what I need to do from my log.

Logfile of HijackThis v1.94.0
Scan saved at 2:18:19 AM, on 6/23/2003
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar=http://www.websearch.com/ie.aspx
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page=http://www.couldnotfind.com/search_page.html?&account_id=
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page=http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant=http://www.couldnotfind.com/search_page.html?&account_id=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL=http://www.e4me.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant=http://www.websearch.com/ie.aspx
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride=localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page=C:\WINDOWS\System32\blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page=%SystemRoot%\system32\blank.h... Read more

A:help with spy ware

Download rbkiller from http://www.wilderssecurity.net/specialinfo/rapidblaster.html and run it
If you look in Add/Remove programs - is there an entry for New.net ?
If so, use that to remove it.
There's LOTS of other stuff there such as btien - but let's do these first (if you can).
After that run Hijack again and post another list.
 

3 more replies
Answer Match 34.86%

Please help.
This machine was infested with spyware. I installed Spybot, updated and ran it. It still had some so I installed Ad Aware. It seemed to get rid of most but this is what I can't get rid of.
When I boot my computer up, it goes to windows then I get "an error has occured in script on this page"
line 65
char 1
Error 'null is null or not an object
code o
url http://219.153.0.217/~monster/ad1.htm
Do you want to continue running scripts on this page
yes no
I appreciate your help.
Thank you

Logfile of HijackThis v1.97.7
Scan saved at 5:18:24 PM, on 5/7/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
C:\Program Files\Messenger\msmsgs.exe
C:\DOCUME~1\TOMSCH~1\LOCALS~1\Temp\EMESH.EXE
C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Dell\OpenManage\Client\Iap.exe
C:\Program Files\Norton AntiVir... Read more

A:Spy Ware

9 more replies
Answer Match 34.86%

I am constantly getting pop ups and unwanted toolbars which I don't know how to remove from my registry. I run programs like spy bot, adaware etc but they just keep coming back. Someone told me to run hijack this and post the report. How do I do this? and what do I need to do to finally remove these annoying and rude pop ups?

Thanks in advance for your help.
 

A:spy ware

16 more replies
Answer Match 34.86%

Hi,
I keep on getting pop ups everywhere 20mins.How do i solve this problem? Logfile of HijackThis v1.99.1
Scan saved at 9:38:00 PM, on 11/10/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\CTHELPER.EXE
C:\Program Files\Creative\ShareDLL\CtNotify.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Creative\ShareDLL\MediaDet.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\unzipped\hijackthis\HijackThis.exe
C:\Program Files\Internet Explorer\iexplore.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\User\LOCALS~1\Temp\se.dll/space.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\User\LOCALS~1\Temp\se.dll/space.html
R1 - HKLM\Software\Microsoft\Internet Explorer\... Read more

A:ad-ware pop ups out of no where

Please click here to download HijackThis

Once finish downloading, double-click it
Click Next
After that, it will ask you where to install HijackThis, by default, it will be installed on "C:\Program Files\Hijackthis", click Next
Click Next
Under Additional icons, put a check on both boxes
Click Install, after installation, proceed below:
Close all programs running, then open HijackThis (through the desktop icon made or in Start > All Programs)
Next, click Do a system scan and save a log file
Once its finish, a notepad will pop with the results of the scan
Click EDIT, then SELECT ALL
Next, click EDIT, then COPY
Go back to the thread, and paste the results of your HJT log as your reply
​Once done, hold tight and wait for an expert to help you with your HJT log, and tell you what to do next.

Good Day
 

2 more replies
Answer Match 34.86%

EveLogfile of HijackThis v1.97.7Scan saved at 10:07:53 AM, on 6/30/2004Platform: Windows XP SP1 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\Explorer.EXEC:\WINDOWS\System32\brsvc01a.exeC:\WINDOWS\system32\spoolsv.exeC:\WINDOWS\System32\brss01a.exeC:\Program Files\Synaptics\SynTP\SynTPLpr.exeC:\Program Files\Synaptics\SynTP\SynTPEnh.exeC:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exeC:\Program Files\Dell\QuickSet\QuickSet.exeC:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exeC:\Program Files\McAfee.com\Agent\mcagent.exeC:\Program Files\Common Files\Dell\EUSW\Support.exeC:\PROGRA~1\mcafee.com\vso\mcvsshld.exeC:\Program Files\Scansoft\PaperPort\pptd40nt.exeC:\WINDOWS\SYSTEM32\Brmfrmps.exeC:\WINDOWS\system32\cisvc.exeC:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exeC:\Program Files\Scansoft\PaperPort\SmartUI\SmartU... Read more

A:Do I have spy ware

You are currently using hijackthis from a temp directory. This can cause problems. Please create a directory on your c: drive called c:\hijackthis and download and unzip hijackthis into that directory. Run the program from that directory from now on.You are infected with a variant of the CoolWebSearch.Download CWShredder from the below link and unzip it into a directory. Start CWShredder and click on the FIx button to have it remove all CWS infections it finds.Download CWShredder from:http://www.merijn.org/files/cwshredder.ziporhttp://tools.zerosrealm.com/CWShredder.zipAfter you download the program, unzip it into a directory. Make sure all browser windows are closed and double click on the cwshredder.exe to start the program. When the program is loaded click on the "Check for Update" button, and if it finds an new version it will download it. You should then double click on cwshredder.exe again and click on the "FIX" button (not the "Scan only" button) and let it scan your computer.To get the best results it is recommended that you run it in safe mode. Reboot windows and press F8 at boot/windows startup, usually right after the beep. Then select safe mode.A tutorial that goes over this process step by step can be found here:How to remove CoolWebSearch with CoolWeb ShredderOnce that is completed you should follow these steps in order to clean your computer of Malware which can include Viruses, Trojans, Worms, Spyware, Hijackers and Dial... Read more

5 more replies
Answer Match 34.44%

Upon booting up, my computer goes straight to a "warning page" from the Control Center indicating that there are all kinds of issues (viruses, porn cache & tracking cookies, etc.). There is a button labled "Fix Problems" which leads to a page to buy a license. When try to close it out there is an error warning "This operation is prohibited. Please check your settings.

There are three buttons at the top, "help" which leads instuctions on downloading the software. "Support" which leads to the page to purchase the software. And "Settings" which has an array of options (run Control Center on Windows Start up; allow uprotected Windows startup; scan only new and changed files; automatically save log-file; write details about found object; concede resources to other application; disable external service control; disable sheduled scans while running on battery power). Note: the typos above are exactly as they appear.

I've tried just about every combination of these settings and nothing will allow me to get past this.

Suggestions, please!

A:scare ware

repost in the "am i infected" forum in the security section of this site, and one of the security experts will be along to help,,, please be patient with them as they are very busy,,,,,, in the mean time download this scanner ,,, Malwarebytes aka MBAMhttp://www.malwarebytes.org/blue tab is the one you want,,, (free version)the link below will show you how to use ithttp://www.udel.edu/topics/spyware/malwarebytes.htmlalso download this cleanerhttp://www.atribune.org/index.php?option=c...5&Itemid=25instructions for use are also on that page,,,good luck.oops,,,, did not notice your post has been moved to the "am i infected" forum by admin, so no need to repost in there.

2 more replies
Answer Match 34.44%

I hope you can help. I'm running Windows 98 and I'm having trouble with spy ware. I've run SWShredder, Norton 05, Spy Sweeper, Ad-Ware, Stinger. Even though I'm clean I'm still have problems with unwanted downloads, freezing when on line and off also. I've deleted exe and dll files with the date. When I run hijackthis I get [2]-015 files that won't clear, I've tried safe mode, trusted sites, and they remain. Any suggestions? thank you -Gary
 

A:Solved: Spy Ware

11 more replies
Answer Match 34.44%

i need help finding a program that is free and will remove my Spy-ware..i did a free scan w/ Ad-ware found out i have 10k infected files...
then i found out i had to purchase Ad-ware to clean my computer..
i need advice on Reliable programs to remove it all or some Advice on how to manually remove D=
when i ran the scan if i recall i think i saw a Hijacker and Adware infected into my computer also.
 

A:Solved: Help me get rid of Spy-ware

13 more replies
Answer Match 34.44%

A recent ad-aware scan revealed these two items .Is it safe to delete these from the registry. Out of curiosity, have they appeared because i have been poking my nose into the registry

Thanks
Alan

Scan initialized on 24/11/02 16:10:39.
(AAW release 5.83, referencefile 029-15.06.2002)
=================================================
Started registry scan
======================
Alexa key:HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\extensions\{c95fe080-8f5d-11d2-a20b-00aa003c157a}\
Started extended registry scan
===============================
NetworkEssentials data:C:\PROGRA~1\NET2PH~1\net2fone.exe
Registry scan result:
Suspicious keys found : 2

Scanning finished
==================
Suspicious modules found:0
Suspicious keys found : 2
Suspicious folders found:0
Suspicious files found:0
=========================
Components ignored:0
Total components found:2
 

A:ad-ware scan

9 more replies
Answer Match 34.44%

Spybot cannot fix C:\Windows\System32\ncompat.tlbDocuments and Settings\Main1\Local Settings\Temp\awtemp\can be deleted but continues to reoccur Logfile of HijackThis v1.99.1Scan saved at 10:50:14 AM, on 23/02/2006Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\Ati2evxx.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\spoolsv.exeC:\WINDOWS\system32\Ati2evxx.exeC:\WINDOWS\Explorer.EXEC:\WINDOWS\system32\mssearchnet.exeC:\WINDOWS\system32\nvctrl.exeC:\WINDOWS\SOUNDMAN.EXEC:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exeC:\Program Files\Microsoft AntiSpyware\gcasServ.exeC:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXEC:\WINDOWS\system32\svchost.exeC:\Program Files\Java\jre1.5.0_06\bin\jusched.exeC:\Program Files\Microsoft AntiSpyware\gcasDtServ.exeC:\Program Files\Picasa2\PicasaMediaDetector.exeC:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exeC: ... Read more

A:Spy Falcon Ad Ware

Hello Rossco, Welcome to BleepingComputer!My name is Nick and I will be checking over your log.Let's get started. You will want to print or save these instructions.Download smitRem.exe ?noahdfear, and save the file to your desktop.Double click on the file to extract it to it's own folder on the desktop.Download FixSF.reg to your desktop.Download Killbox and save it to your desktop.Place a shortcut to Panda ActiveScan on your desktop (in Internet Explorer, right click on Panda ActiveScan link select "Copy Shortcut" then right click on your desktop and select "Paste Shortcut" or in FireFox right-click the link and select "Save Link As" and save it to your desktop).Please download the trial version of ewido anti-malware here:http://www.ewido.net/en/download/Please read Ewido Setup InstructionsInstall it, and update the definitions to the newest files. Do NOT run a scan yet.Next, please reboot your computer in SafeMode by doing the following:Restart your computerAfter hearing your computer beep once during startup, but before the Windows icon appears, press F8.Instead of Windows loading as normal, a menu should appearSelect the first option, to run Windows in Safe Mode.Double click on the FixSF.reg file to add it to the registry.Answer yes to confirm the merge.Double-click on Killbox.exe to run it. Put a tick by Standard File Kill. In the "Full Path of File to Delete" box, copy and paste each of the following lines one at a time:

C :&... Read more

1 more replies
Answer Match 34.44%

I use Ad-Aware 5.83 and regularly deltete my cookies and Temporary Internet Files, and still I am getting bothered by something, it must be spy ware. Every 10 navigational clicks on my browser I will get transferred to a web site, and usually it has something to do with rapes, and it is really bothersome. I can't get rid of it and would like to ask if anyone has experienced this problem and/or what I can do to get rid of it. I am begging for help.

Thank you.
 

A:[Resolved] Spy Ware?

16 more replies
Answer Match 34.44%

Hello,Most of time www.winantispyware.com comeit's open a advertising windows for cleandisk !!!!A did adware se, spyboth, tune up utilities, panda software i also did in safe modeBut after reboot still the same !!!! ARGGGGThis is my hijacktis log could you help me pleaseLogfile of HijackThis v1.99.1Scan saved at 15:26:22, on 29/08/2006Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\Ati2evxx.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\Ati2evxx.exeC:\WINDOWS\Explorer.EXEC:\WINDOWS\system32\ctfmon.exeC:\WINDOWS\system32\spoolsv.exeC:\Program Files\Alwil Software\Avast4\aswUpdSv.exeC:\Program Files\Alwil Software\Avast4\ashServ.exeC:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exeC:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\system32\ZoneLabs\vsmon.exeC:\WINDOWS\system32\taskswitch.exeC:\Program Files\Java\jre1.5.0_06\bin\jusche... Read more

A:Spy Ware Name : Www.winantispyware.com

Welcome to the Bleeping Computer forum. We are currently studying your log and will have instructions for you shortly. Thank you for your patience.

4 more replies
Answer Match 34.44%

seems as though I inadvertantly allowed something through and now am beseiged by pop ups and toolbar bubbles. Main culprits have the following referenced somewhere in the window/bubbles (I have tried to identify the identifying element) :
[email protected]
- PSW.x-VirTrojan
- [email protected]
- SpyWorm.Win32
- Unhandled Exception alert (which tells you tyo download software )
- Various pop-ups with address savetheinformation.com & storageprotector.com & secrityonpage.com
I have run AVG and SuperAntiSpyware (also others which flagged infected items but wanted me to purchase software to clear them) with no effect.
All help would be very much appreciated

Here's a HijackThis (v2.0.2) report ...

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 01:06:04, on 18/08/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA... Read more

A:Mal/Spy ware infection help please ......

7 more replies
Answer Match 34.44%

Ad-Aware and Spybot failed to remove taskmgn.exe and a dozen others. Can someone tell me how to clean my machine short of reformatting the harddrive?

Logfile of HijackThis v1.99.0
Scan saved at 12:48:03 PM, on 2/2/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\lotus\notes\ntmulti.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
C:\Program Files\2Wire\Gateway\2PortalMon.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2D1.EXE
C:\WINDOWS\System32\hphmon05.exe
C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.e... Read more

A:Help...I have tons of spy ware and can't get rid of it

Please print out or copy this page to Notepad. Make sure to work through the fixes in the exact order it is mentioned below. If there's anything that you don't understand, ask your question(s) before proceeding with the fixes. You should not have any open browsers when you are following the procedures below.

Go to My Computer->Tools/View->Folder Options->View tab and make sure that 'Show hidden files and folders' (or 'Show all files') is enabled. Also make sure that Display the contents of System Folders' is checked. Windows XP's search feature is a little different. When you click on 'All files and folders' on the left pane, click on the 'More advanced options' at the bottom. Make sure that Search system folders, Search hidden files and folders, and Search subfolders are checked.

For the options that you checked/enabled earlier, you may uncheck them after your log is clean. If we ask you to fix a program that you use or want to keep, please post back saying that (we don't know every program that exists, so we may tell you to delete a program that we think is bad to keep).

Turn off system restore by right clicking on My Computer and go to Properties->System Restore and check the box for Turn off System Restore. Click Apply and then OK. Restart your computer. After we are finished with your log file and verified that it's clean, you may turn it back on and create a new restore point.

You have the Peper infection. Download PeperUninstall. Ma... Read more

3 more replies
Answer Match 34.44%

Logfile of HijackThis v1.99.1Scan saved at 12:57:12 AM, on 7/7/2007Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\Program Files\Common Files\Symantec Shared\ccProxy.exeC:\Program Files\Common Files\Symantec Shared\ccSetMgr.exeC:\Program Files\Norton Internet Security\ISSVC.exeC:\Program Files\Common Files\Symantec Shared\SNDSrvc.exeC:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exeC:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exeC:\WINDOWS\Explorer.EXEC:\WINDOWS\system32\spoolsv.exeC:\Program Files\Bonjour\mDNSResponder.exeC:\WINDOWS\eHome\ehRecvr.exeC:\WINDOWS\eHome\ehSched.exeC:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exeC:\WINDOWS\system32\nvsvc32.exeC:\WINDOWS\system32\svchost.exeC:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exeC:\WINDOWS\system32\dllhost.exeC:\WINDOWS\ehome\ehtray.exeC... Read more

A:Some Sort Of Ad-ware, I Think.

Hello Bobinashoe and welcome to BC My name is SNOWHITE and I will be helping you with your Malware problem.As I am still in training I will be helping you under supervision of our expert teachers, so there may be a delay between posts. I will be analyzing your log now, and be back with you as soon as possible!Regards,

2 more replies
Answer Match 34.44%

I got on the net and most of the time i google something i would get redirected to another site,so i ran malawarebytes and it did not find anything so i ran adaware and when it finshed the scan it froze and would not let me go on. So i ran spybot sd and it done the same thing as adaware and i have tried both of them several times and it keeps doing the same thing, so i tried to start my computer in safe mode and it just keeps me going back to the same screen and will not let me start in safe mode, so i tired system restore and it will not allow me to do that, but both spybot, and adware list the spyare but it will not let me get rid of them it just frezes PLZ HELP!!!!!!!!

A:spy ware frezzes

Hello and Welcome.

We want all our members to perform the steps outlined in the link I'll give you below, before posting for assistance. There's a sticky at the top of this forum, and a
Quote:




Having problems with spyware and pop-ups? First Steps




link at the top of each page.

---------------------------------------------------------------------------------------------

Please follow our pre-posting process outlined here:

http://www.techsupportforum.com/f50/...lp-305963.html

After running through all the steps, you shall have a proper set of logs. Please post them in a new topic, as this one shall be closed. I currently have as many open topics as I can effectively handle; this will have you back in queue with the proper logs so an available helper would be able to assist.

If you have trouble with one of the steps, simply move on to the next one, and make note of it in your reply.

Please note that the Virus/Trojan/Spyware Help forum is extremely busy, and it may take a while to receive a reply.

1 more replies
Answer Match 34.44%

my computer screen has downloaded a spyware and adware. I need help removing this program from my system.
 

A:spyware, ad ware

* Click HERE to download HJTsetup.exe:
Save HJTsetup.exe to your desktop.

Double click on the HJTsetup.exe icon on your desktop.
By default it will install to C:\Program Files\Hijack This.
Continue to click Next in the setup dialogue boxes until you get to the Select Addition Tasks dialogue.
Put a check by Create a desktop icon then click Next again.
Continue to follow the rest of the prompts from there.
At the final dialogue box click Finish and it will launch Hijack This.
Click on the Do a system scan and save a log file button. It will scan and then automatically open the log in Notepad.
Click on "Edit > Select All" then click on "Edit > Copy" to copy the entire contents of the log.
Come back here to this thread and Paste the log in your next reply.
DO NOT have HijackThis fix anything yet. Most of what it finds will be harmless or even required. Either myself or another HJT expert will review your log and provide you with instructions.
 

1 more replies
Answer Match 34.44%

can some one review this and let me know what is bad. The ad-ware is listed on my favorites adn with pop ups and my organize favorites is disabled.

Logfile of HijackThis v1.99.1
Scan saved at 9:06:40 PM, on 12/30/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
D:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
D:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\Program Files\Spybot - Search & Destroy\SDHelper.... Read more

A:ad-ware problem

Run ActiveScan online virus scan:
http://www.pandasoftware.com/products/activescan.htm

When the scan is finished, anything that it cannot clean have it delete it.
Make a note of the file location of anything that cannot be deleted so you can delete it yourself.
Save the results from the scan and post them here.
 

1 more replies
Answer Match 34.44%

plz Help!thanks! peter.Logfile of HijackThis v1.99.1Scan saved at 10:00:52 AM, on 11/4/2006Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v7.00 (7.00.5730.0011)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\Program Files\Common Files\Symantec Shared\ccSetMgr.exeC:\WINDOWS\system32\spoolsv.exec:\program files\common files\logitech\lvmvfm\LVPrcSrv.exeC:\Program Files\ewido\security suite\ewidoctrl.exec:\program files\mcafee.com\agent\mcdetect.exec:\PROGRA~1\mcafee.com\vso\mcshield.exec:\PROGRA~1\mcafee.com\agent\mctskshd.exeC:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exeC:\Program Files\Softex\OmniPass\Omniserv.exeC:\WINDOWS\System32\svchost.exeC:\Program Files\Softex\OmniPass\OPXPApp.exeC:\Program Files\Canon\CAL\CALMAIN.exeC:\WINDOWS\Explorer.EXEC:\Program Files\Common Files\Sonic\Update Manager\sgtray.exeC:\WINDOWS\system32\ctfmon.exeC:\Program Files\McAfee.com\VSO\mcvsshld.exeC:\Program Files\McA... Read more

A:Mal-ware In My System! -- Plz Look At Log!

Hi and welcome to Bleeping Computer! My name is Sam and I will be helping you. Please download AVG Anti-Spyware and save that file to your desktop.This is a 30 day trial of the programOnce you have downloaded AVG Anti-Spyware, locate the icon on the desktop and double-click it to launch the set up program.Once the setup is complete you will need run ewido and update the definition files.On the main screen select the icon "Update" then select the "Update now" link.Next select the "Start Update" button, the update will start and a progress bar will show the updates being installed.Once the update has completed select the "Scanner" icon at the top of the screen, then select the "Settings" tab.Once in the Settings screen click on "Recommended actions" and then select "Quarantine".Under "Reports"Select "Automatically generate report after every scan"Un-Select "Only if threats were found"Close AVG Anti-Spyware. Do not run a scan just yet. We will shortly.Reboot your computer into SafeMode. You can do this by restarting your computer and continually tapping the F8 key until a menu appears. Use your up arrow key to highlight SafeMode then hit enter.

Clean out your Temporary Internet files.Internet ExplorerClose Internet Explorer and close any instances of Windows Explorer.Click Start -> Control Panel and then double-click Internet Options.On the General tab, click Delete Fil... Read more

6 more replies
Answer Match 34.44%

I HAVE SENT MY MOTHER BOARD & AMD K5 2/350 CPU TO MY GRANDSON. WHEN HE PUT IT IN HIS CASE THE MONITOR DOESN'T COME ON WHEN POWER IS APPLIED.THE MB WAS IN MY COMPUTER and worked fine. ALL JUMPERS ARE SET RIGHT.All he has installed is the viedo card and plugged in the HD, FD, & CD-ROM. WOULD PLUGGING IN THE "P8" & "P9" POWER PLUGS IN THE WRONG WAY BURN UP THE BOARD ?
THANKS, IMBRANDX
 

A:HARD WARE

6 more replies
Answer Match 34.44%

Computer infected, lost control panel. I want to format the drive but unable to figure out how to get this done. Normally I would just restart and have the cd in the drive to reinstall everything after formatting. How do I accomplish this with Dell Dimension 8300?

A:Spy Ware Virus

You can use a boot disk from DBAN to irrecoverably delete everything off your HDD and then you will be able to reinstall Windows.

A download link to DBAN is in my signature.

Also, make sure you have your BIOS set to boot from the CD drive first, so it boots into the DBAN disk instead of Windows.

1 more replies
Answer Match 34.44%

My Brother, has Web Root, Spy Bot, Norton's, and has run all at least 3 times, and still has an icon on the lower right, that is like a circle with a slash through it. When he clicks on it it states he has been infected with a virus, and that if he wants windows to fix it he should click on this to download some other anti-virus/ adware something or other to fix it.
He does this and nothing happens...
Any idea how he can get rid of this?http://images.techguy.org/smilies/wink.gif
 

A:Ad or Mal ware problem?

I moved this to security; you will get more response.
 

3 more replies
Answer Match 34.44%

im looking for a program that may help me in finding out if someone i talked to who they say there are....i thought i seen a program before but not sure...ive been talking with someone for a time now ..but i want to make sure they are who they say there are...any ideas?
 

A:chat ware

7 more replies
Answer Match 34.44%

Hello,

Guys I want to know how i can install VM ware in windows XP??

how i can setup virtual machine on VM Ware & install softwares in it....

-Tejas Shetty

A:How to install VM Ware on XP....

vmware player is good its free and really user friendly

2 more replies
Answer Match 34.44%

I have tried Spy Sweeper and Ad Aware but neither has been able to clear the AdWare. The thing that I seeing most is random opening of my browser (Firefox) to various Spam pages. I am posting my "HijackThis" Log -- If anyone can make some suggestions regarding a fix I would certainly appreciate it.If further information is required I'll be happy to post what ever is neededThanks(moderator edit: log moved to HJT forum for team review. jgweed)******Logfile of HijackThis v1.99.1Scan saved at 7:37:58 PM, on 10/25/2005Platform: Windows XP SP1 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\spoolsv.exeC:\Program Files\Norton AntiVirus\navapsvc.exeC:\WINDOWS\system32\rundll32.exeC:\WINDOWS\Explorer.EXEC:\WINDOWS\System32\hkcmd.exeC:\WINDOWS\BCMSMMSG.exeC:\PROGRA~1\NORTON~1\navapw32.exeC:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exeC:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exeC:\WINDOWS\System32\hphmon04.exeC:\Program Files\Hewlett-Packard\HP ... Read more

A:Ad-ware Problem

Sorry for the delay. If you still need help with your log please post a brand new HJT log as a reply to this topic and I will help you clean it up as necessary.

1 more replies
Answer Match 34.44%

Hey guys, first off i'd like to say what a great job you guys are doing here.

It all started like this:
Today I was surfing the web early in the morning, I receive this freeonline scanner popup, I have mywot and it said it was red but it didn't block it so i exited it. when i clicked the X it gave me a pop up saying are you sure you want to stop the scan? ( something like that) and I clicked the X button again, It still began to go so i knew this was bad. I proceeded to closing firefox which worked, but then it asked me again so out of hesitation I completely turned off the power from my computer. Now im nervous that I have some kind of mal-ware and if I don't i've been wondering why my computer has been so slow x-x.

Anyways i proceeded to follow the instructions with GMER but it stops at a certain point and just ultimately shuts down.
when I open it up again it says something about system32 process cannot be scanned because it was being used. That scared me a bit so I cannot in clude the GMER log in here. currently im trying again but I have my DDS and my attach if that helps.

DDS LOG:

DDS (Ver_09-06-26.01) - NTFSx86
Run by HP_Administrator at 13:39:03.65 on 26/06/2009
Internet Explorer: 7.0.5730.11 BrowserJavaVersion: 1.6.0_13
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1982.1025 [GMT -6:00]

AV: AVG 7.5.524 *On-access scanning enabled* (Outdated) {41564737-3200-1071-989B-0000E87B4FB1}
AV: avast! antivirus 4.8.1335 [VPS 090626-0] *On... Read more

A:Need help on possible mal-ware and clean up

Here's my GMER. after 2 restarts I finally got it to work X_X
Sorry for double post please help!

GMER 1.0.15.14972 - http://www.gmer.net
Rootkit scan 2009-06-26 21:55:03
Windows 5.1.2600 Service Pack 2


---- System - GMER 1.0.15 ----

SSDT 8A599230 ZwAlertResumeThread
SSDT 8A26C090 ZwAlertThread
SSDT pxfsf.sys (PREVX Security Agent for Windows/Prevx Limited, http://www.prevx1.com/) ZwAllocateUserPhysicalPages [0xBA690847]
SSDT 8A414780 ZwAllocateVirtualMemory
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwClose [0xB5C546B8]
SSDT pxfsf.sys (PREVX Security Agent for Windows/Prevx Limited, http://www.prevx1.com/) ZwCompactKeys [0xBA690865]
SSDT pxfsf.sys (PREVX Security Agent for Windows/Prevx Limited, http://www.prevx1.com/) ZwCompressKey [0xBA69086F]
SSDT 8A5793C0 ZwConnectPort
SSDT pxfsf.sys (PREVX Security Agent for Windows/Prevx Limited, http://www.prevx1.com/) ZwCreateDirectoryObject [0xBA690879]
SSDT pxfsf.sys (PREVX Security Agent... Read more

19 more replies
Answer Match 34.44%

Logfile of HijackThis v1.99.1
Scan saved at 5:38:10 PM, on 6/25/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ACS.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\system32\DVDRAMSV.exe
C:\Program Files\Alias\Maya7.0\docs\wrapper.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Alias\Maya7.0\docs\jre\bin\java.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\AlienGUIse\wbload.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\TOSHIBA\Power Management\CePMTray.exe
C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
C:\TOSHIBA\IVP\ISM\pinger.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe
C:\Program Files\CA\eTrust PestPatrol\PPActiveDetection.exe
C:\Program Files\ATI Technologies\ATI HYDRAVISION\HydraDM.exe
C:\Program Files\EzButton... Read more

A:...Any mal ware? I did a preliminary fix...

Hi and welcome to TSF.

My handle is TexRanger, and I am currently reviewing your log. Please note that this is under the supervision of an expert analyst, and I will be back with a fix for your problem as soon as possible.

You may wish to Subscribe to this thread by clicking Thread Tools then subscribe to this thread so that you are notified when you receive a reply.

Please be patient with me during this time.

5 more replies
Answer Match 34.44%

I visited a website, searching for a certain file (a rom for a game I own) and <also add |www.freeroms.com| to your block list! thats where I got this thing!>
I got a very sneaky, very well hidden (or very well spread out) piece of spyware. I have already updated my virus and spyware definition files, but both Norton and Ad-Aware detect nothing. The program(s) download other spywares, and I believe it has given itself administator permissions, as many of the running processes that I could kill before now have an "access denied" message when I try to kill them. It's adding things like toolbars and programs like barginbuddy (bargins.exe , that damn little dog that keeps running itself, even after I close it) in the system tray. I could use a bit of help, and any input from someone experienced in this field would be GREATLY and LOVINGLY appreciated!

A:Someone, please help me with a (spy/mal/ad)ware problem.

Welcome to TSF!

The story sounds all-to-familiar.

Please download HijackThis - this program will help us determine if there are any spyware/malware on your computer. Create a folder at C:\HJT and move HijackThis.exe there. Double click on the program to run it.

1. If it gives you an intro screen, just choose 'Do a system scan and save a logfile'.
2. If you don't get the intro screen, just hit Scan and then click on Save log.
3. Get HijackThis Analyzer and save it to the same folder as the hijackthis.log file. Run HijackThis Analyzer and type in y if you agree. Open up the result.txt file created. Copy the whole result.txt log and post it in the forum. Do not fix anything in HijackThis since they may be harmless.

I will move your thread to HJT Help, as that will get you a little qucker response.

5 more replies
Answer Match 34.44%

Hi Everyone,

I just got this irritating problem as well and was trying to access the link but could not. Could any of you help to paste th link again or perhaps get me the instructions?

It's really annoying that this got on my computer. Really don't know how it got in.

Thakns once again everyone.
 

A:Antimal Ware

http://forums.techguy.org/security/465381-help-malware-issue.html#post3591225

Closing duplicate post.
 

1 more replies
Answer Match 34.44%

Please, i have changed my hard disk on my dell inspiron 1440 but and i have install windows 7 ultimate x64, but when i activate my windows, my laptop does not boot. its probably about my bios since i have install a new hard disk and i need to restore my factory image. please help me out

A:Hard Ware

How to use Dell Recovery,How to use Dell Recovery disks & how to order Recovery Disks.
Dell - Support

2 more replies
Answer Match 34.44%

My computer is generating multiple windows indicating I have a critical problem with viruses. Requests to scan computer and then will fix problem after paying $79 someodd dollars. Program title bar indicates http://spywareprotectiontool.com------Windows internet ExplorerAnother window has --http://AAvancessoftwaretool.com in the title bar.I ran a free download of a spyware removal program named Adaware from http://lavasoftusa.comThe generation of multiple windows has stopped but I keep getting windows popping up with an ALERT! indicating I have a problem with a virus.I kill the ALERT application process with Task Manager and things are ok for awhile.

A:Ad Ware Problem

Welcome to BC.Please download Malwarebytes Anti-Malware (v1.34) and save it to your desktop.alternate download link 1alternate download link 2MBAM may "make changes to your registry" as part of its disinfection routine. If using other security programs that detect registry changes (ie Spybot's Teatimer), they may interfere or alert you. Temporarily disable such programs or permit them to allow the changes.Make sure you are connected to the Internet.Double-click on mbam-setup.exe to install the application.When the installation begins, follow the prompts and do not make any changes to default settings.When installation has finished, make sure you leave both of these checked:Update Malwarebytes' Anti-MalwareLaunch Malwarebytes' Anti-MalwareThen click Finish.MBAM will automatically start and you will be asked to update the program before performing a scan.If an update is found, the program will automatically update itself. Press the OK button to close that box and continue.If you encounter any problems while downloading the definition updates, manually download them from here and just double-click on mbam-rules.exe to install.On the Scanner tab:Make sure the "Perform Quick Scan" option is selected.Then click on the Scan button.If asked to select the drives to scan, leave all the drives selected and click on the Start Scan button. The scan will begin and "Scan in progress" will show at the top. It may take some time to complete so please be patient.When the scan is finished, a me... Read more

1 more replies
Answer Match 34.44%

Hello, first time poster here.I have a XP machine running service pack 2 that has become bogged down with Spyware and Pop Ups. I ran the latest versions of Spybot and Ad-Aware SE only to either have items that couldn't be removed or items that would come back almost immediately after removal. Any help would be greatly appreciated.Logfile of HijackThis v1.99.0Scan saved at 11:27:39 AM, on 1/27/2005Platform: Windows XP SP1 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\Program Files\Common Files\Symantec Shared\ccSetMgr.exeC:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exeC:\WINDOWS\system32\spoolsv.exeC:\Program Files\Symantec AntiVirus\DefWatch.exeC:\Program Files\SYMANTEC\Ghost\NGCTW32.EXEC:\Program Files\Symantec AntiVirus\SavRoam.exeC:\Program Files\Symantec AntiVirus\Rtvscan.exeC:\WINDOWS\System32\CCM\CLICOMP\RemCtrl\Wuser32.exeC:\WINDOWS\System32\CCM\CcmExec.exeC:\WINDOWS\Explorer.EXEC:\WINDOWS\System32\rundll32.exeC:\WINDOWS\System32\hkcmd.exeC:... Read more

A:Help with Spy-Ware Attack

Download L2mfix from one of these two locations:http://www.atribune.org/downloads/l2mfix.exehttp://www.downloads.subratam.org/l2mfix.exeSave the file to your desktop and double click l2mfix.exe. Click the Install button to extract the files and follow the prompts, then open the newly added l2mfix folder on your desktop. Double click l2mfix.bat and select option #1 for Run Find Log by typing 1 and then pressing enter. This will scan your computer and it may appear nothing is happening, then, after a minute or 2, notepad will open with a log. Copy the contents of that log and paste it into this thread.IMPORTANT: Do NOT run option #2 OR any other files in the l2mfix folder until you are asked to do so !Due to inactivity, this thread will now be closed. If you need this topic reopened, please contact a member of the HJT Team and we will reopen it for you. Include the address of this thread in your request. If you should have a new issue, please start a new topic. This applies only to the original topic starter. Everyone else please begin a New Topic.

1 more replies