![]() |


|
|||||||
| Hardware & Software Discussion Hardware and Software discussion and troubleshooting. Tweakers and Overclockers welcome! |
![]() |
|
|
Thread Tools |
|
|
#16 (permalink) |
![]() Join Date: May 2003
Location: I am lost, if you know where I am then please feel free to tell me.
Age: 29
Posts: 2,048
|
Re: spy ware.
I booted into safe mod ran every spyware program I have installed and I'm still getting hijacked and have popups.
Here is the log from Hijack this Logfile of HijackThis v1.99.1 Scan saved at 2:48:02 PM, on 9/11/2005 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\System32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Common Files\Windows\services32.exe C:\WINDOWS\System32\devldr32.exe C:\WINDOWS\system32\cmd.exe C:\Program Files\Common Files\services.exe C:\Program Files\Trillian\trillian.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Documents and Settings\James\Desktop\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\WINDOWS\System32\Searchx.htm R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.tacticalgamer.com/ R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyServer = :0 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = R3 - Default URLSearchHook is missing O2 - BHO: PicShow Class - {4487598C-2EC7-43A2-870E-6D8D720FDD9F} - C:\WINDOWS\System32\pkshmdtm.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: Internet Explorer Web Content Catcher - {FFF4E223-7019-4ce7-BE03-D7D3C8CCE884} - C:\Program Files\DNS\Catcher.dll O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_0 O4 - HKCU\..\Run: [services32] C:\Program Files\Common Files\Windows\mc-58-12-0000106.exe O4 - HKCU\..\Run: [DNS] C:\Program Files\Common Files\mc-58-12-0000106.exe O8 - Extra context menu item: Download with GetRight - C:\Program Files\GetRight\GRdownload.htm O8 - Extra context menu item: Open with GetRight Browser - C:\Program Files\GetRight\GRbrowse.htm O9 - Extra button: (no name) - {9E248641-0E24-4DDB-9A1F-705087832AD6} - (no file) O9 - Extra 'Tools' menuitem: Java - {9E248641-0E24-4DDB-9A1F-705087832AD6} - (no file) O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe O9 - Extra button: (no name) - {FB5F1910-F110-11d2-BB9E-00C04F795683} - (no file) O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - (no file) O20 - Winlogon Notify: Hints - C:\WINDOWS\system32\sYfrcdlg.dll O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe Please help, this is seriously pissing me off. |
|
|
|
|
|
#17 (permalink) | |
![]() ![]() ![]() Join Date: May 2003
Location: Dallas/Ft. Worth area of Texas, USA
Age: 33
Posts: 17,126
|
Re: spy ware.
Quote:
__________________
![]() ![]() Take the world's smallest political quiz! "I was touched by His Noodly Appendage." TacticalGamer TX LAN/BBQ Veteran:
|
|
|
|
|
| Sponsored links | |
|
|
|
|
|
#19 (permalink) | |
![]() ![]() ![]() Join Date: May 2003
Location: Dallas/Ft. Worth area of Texas, USA
Age: 33
Posts: 17,126
|
Re: spy ware.
Quote:
Maybe this will help?: http://www.accs-net.com/smallfish/getrite.htm
__________________
![]() ![]() Take the world's smallest political quiz! "I was touched by His Noodly Appendage." TacticalGamer TX LAN/BBQ Veteran:
|
|
|
|
|
|
|
#22 (permalink) | |||||
|
Join Date: Jul 2005
Posts: 4,494
|
Re: spy ware.
Eh, don't think Get Right is the cause of the problem, unless it brought trojans and worms along with it. Or maybe it's just one of the problems...
Quote:
Quote:
Quote:
Quote:
Quote:
|
|||||
|
|
|
|
|
#26 (permalink) |
![]() ![]() ![]() Join Date: Jan 2005
Location: Montreal
Age: 30
Posts: 7,574
|
Re: spy ware.
you have to go into the registry for some of it. My guess is that it was cleaned then put back when you booted up into normal mode because a file was missed. Make sure you delete all your cookies, temp files and internet temp files as well.
CWshredder is your friend, google it and download it. you could reformat but this is common these days and you should probably arm yourself now and educate yourself. |
|
|
|
|
|
#27 (permalink) | |
![]() ![]() ![]() Join Date: May 2003
Location: Dallas/Ft. Worth area of Texas, USA
Age: 33
Posts: 17,126
|
Re: spy ware.
Quote:
__________________
![]() ![]() Take the world's smallest political quiz! "I was touched by His Noodly Appendage." TacticalGamer TX LAN/BBQ Veteran:
|
|
|
|
|
|
|
#28 (permalink) | |
|
Join Date: Jul 2005
Posts: 4,494
|
Re: spy ware.
Quote:
I say to remove them in Safe Mode because lots of worms will add themselves right back in to the registry if you remove them. In Safe Mode, they generally won't be running so you should be able to remove them. Reformatting will get rid of the crap.. but I like to beat the crapware instead of giving up ![]() |
|
|
|
|
|
|
#29 (permalink) |
![]() ![]() ![]() Join Date: Jan 2005
Location: Montreal
Age: 30
Posts: 7,574
|
Re: spy ware.
indeed once a year is good cing, i agree. However when spyware becomes problematic from something that you are trying to utilize (i.e. a website or program) you can easily lock it down and continue to use that website or program. I'm like perry though and i always go for the knowledge over format c:\
|
|
|
|
|
|
#30 (permalink) |
![]() Join Date: May 2003
Location: I am lost, if you know where I am then please feel free to tell me.
Age: 29
Posts: 2,048
|
Re: spy ware.
>_< I don't know what I did (I just ran the anti virus program from another thread) and that seemed to of deleted most of the stuff going on.
I am going to let it run over night (the anti virus program) to check again. Then run the 2 spy ware programs. I want to thank you guys for your help and suggestions. |
|
|
|
| Sponsored links | |
|
|
|
![]() |
| Bookmarks |
| Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) | |
| Thread Tools | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Computer Advice | LegionPaulL | Hardware & Software Discussion | 43 | 05-27-2004 10:20 AM |

