Page 1 of 2 12 LastLast
Results 1 to 10 of 13

Thread: Sigster..............warning

  1. #1
    Don't download this piece of sh*t
    It is slower than a model T Ford
    and it comes with more spyware than an atom bomb
    i have more spyware prevention/removal progs than i can remember
    the spyware still got in and i cant get rid of it
    any help appreciated
    regards Alex

  2. Software & Hardware   -   #2
    Poster
    Join Date
    Aug 2003
    Location
    Burmoda triangle, right behind you!
    Posts
    564
    oh if u actually have that much anti-spyware proggs, then reformat.
    Click the longhorn icon to visit my website.
    <span style='color:blue'><span style='font-size:8pt;line-height:100%'> You try Everything in my/our post(s) at YOUR own risk. I/we do not take responsibily for damages, caused by the post(s). Clicking on/or modifying anything in here is not permitted. Whoever edits my sig is a pussy.</span></span>

    ::::::::::::::::::::::::::::::::::::::::

  3. Software & Hardware   -   #3
    Poster
    Join Date
    May 2003
    Location
    London
    Posts
    477
    it my of been installed here C:&#092;WINDOWS&#092;Downloaded Program Files
    try spy sweeper

  4. Software & Hardware   -   #4
    peat moss's Avatar Software Farmer BT Rep: +15BT Rep +15BT Rep +15
    Join Date
    May 2003
    Location
    Delta B.C. Canada
    Posts
    10,547
    Originally posted by supersonic@18 June 2004 - 13:24
    oh if u actually have that much anti-spyware proggs, then reformat.
    Huh ? What are you saying? Reformat because you have spyware , that seems kinda like throwing the baby out with the bath water.

  5. Software & Hardware   -   #5
    ok peat moss you know what your doing
    I&#39;ve run
    ad aware
    spybot
    spywareblaster
    spysweeper which say they have removed them..........but they come back

    avg has got rid of 1 of three left but cant get rid of the other two

    any ideas...........what more information can i give you
    regards Alex

  6. Software & Hardware   -   #6
    peat moss's Avatar Software Farmer BT Rep: +15BT Rep +15BT Rep +15
    Join Date
    May 2003
    Location
    Delta B.C. Canada
    Posts
    10,547
    Gee off the top of my head, disable System restore, delete saved points , but we&#39;ll help . WE might have to sleep on it, but your no dummy either Alex.

  7. Software & Hardware   -   #7
    peat moss's Avatar Software Farmer BT Rep: +15BT Rep +15BT Rep +15
    Join Date
    May 2003
    Location
    Delta B.C. Canada
    Posts
    10,547
    Alex whats that shreder something program? Or Mabye High jink this the one where you post your running services , that would be a good start .Sorry I can&#39;t remember the name .



    Alex its called CWSHREDDER, and HIGHJACKTHIS.

  8. Software & Hardware   -   #8
    Good morning Peat thanks for that
    cw shredder says nothing wrong
    here is the hijack this log........im not really sure what to do with it
    very wary of what to delete
    perhaps you could have a look or show it to someone in the board who knows a bit more
    regards
    alex

  9. Software & Hardware   -   #9
    ..sorry forgot to add the log&#33;&#33;&#33;&#33;&#33;&#33;&#33;&#33;&#33;&#33;&#33;&#33;
    Logfile of HijackThis v1.97.7
    Scan saved at 11:13:18, on 19/06/2004
    Platform: Windows ME (Win9x 4.90.3000A)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:&#092;WINDOWS&#092;SYSTEM&#092;KERNEL32.DLL
    C:&#092;WINDOWS&#092;SYSTEM&#092;MSGSRV32.EXE
    C:&#092;WINDOWS&#092;SYSTEM&#092;mmtask.tsk
    C:&#092;WINDOWS&#092;SYSTEM&#092;MPREXE.EXE
    C:&#092;PROGRAM FILES&#092;SYGATE&#092;SPF&#092;SMC.EXE
    C:&#092;PROGRAM FILES&#092;WHITECANYON&#092;SECURECLEAN 4&#092;SCWATCH4.EXE
    C:&#092;PROGRAM FILES&#092;GRISOFT&#092;AVG6&#092;AVGSERV9.EXE
    C:&#092;WINDOWS&#092;EXPLORER.EXE
    C:&#092;WINDOWS&#092;SYSTEM&#092;RPCSS.EXE
    C:&#092;WINDOWS&#092;SYSTEM&#092;SYSTRAY.EXE
    C:&#092;WINDOWS&#092;SYSTEM&#092;PRINTRAY.EXE
    C:&#092;WINDOWS&#092;SYSTEM&#092;LXSUPMON.EXE
    C:&#092;WINDOWS&#092;SYSTEM&#092;LEXBCES.EXE
    C:&#092;PROGRAM FILES&#092;INTERNET KEYWORD&#092;INETMGR.EXE
    C:&#092;WINDOWS&#092;SYSTEM&#092;SPOOL32.EXE
    C:&#092;PROGRAM FILES&#092;WHITECANYON&#092;SECURECLEAN 4&#092;SCREGMANAGER4.EXE
    C:&#092;PROGRAM FILES&#092;WHITECANYON&#092;SECURECLEAN 4&#092;SCTRAY4.EXE
    C:&#092;WINDOWS&#092;SYSTEM&#092;QTTASK.EXE
    C:&#092;PROGRAM FILES&#092;GRISOFT&#092;AVG6&#092;AVGCC32.EXE
    C:&#092;WINDOWS&#092;SYSTEM&#092;WMIEXE.EXE
    C:&#092;PROGRAM FILES&#092;IOLO&#092;SYSTEM MECHANIC 4&#092;POPUPSTOPPER.EXE
    C:&#092;PROGRAM FILES&#092;WEBROOT&#092;SPY SWEEPER&#092;SPYSWEEPER.EXE
    C:&#092;WINDOWS&#092;SYSTEM&#092;LRDSVR.EXE
    C:&#092;PROGRAM FILES&#092;INTERNET KEYWORD&#092;INETSVC.EXE
    C:&#092;WINDOWS&#092;SYSTEM&#092;DDHELP.EXE
    C:&#092;WINDOWS&#092;SYSTEM&#092;INTDRV.EXE
    C:&#092;WINDOWS&#092;RUNDLL32.EXE
    C:&#092;WINDOWS&#092;SYSTEM&#092;STIMON.EXE
    C:&#092;MY DOCUMENTS&#092;HIJACKTHIS.EXE

    R0 - HKCU&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Start Page = http://www.ntlworld.com
    R0 - HKLM&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Start Page = http://www.ntlworld.com
    R0 - HKCU&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Local Page =
    R0 - HKLM&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Local Page =
    O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:&#092;PROGRAM FILES&#092;ADOBE&#092;ACROBAT 6.0&#092;READER&#092;ACTIVEX&#092;ACROIEHELPER.DLL
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:&#092;PROGRA~1&#092;SPYBOT~1&#092;SDHELPER.DLL
    O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:&#092;program files&#092;google&#092;googletoolbar1.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:&#092;program files&#092;google&#092;googletoolbar1.dll
    O4 - HKLM&#092;..&#092;Run: [SystemTray] SysTray.Exe
    O4 - HKLM&#092;..&#092;Run: [LexStart] Lexstart.exe
    O4 - HKLM&#092;..&#092;Run: [LexmarkPrinTray] PrinTray.exe
    O4 - HKLM&#092;..&#092;Run: [SmcService] C:&#092;PROGRA~1&#092;SYGATE&#092;SPF&#092;SMC.EXE -startgui
    O4 - HKLM&#092;..&#092;Run: [LXSUPMON] C:&#092;WINDOWS&#092;SYSTEM&#092;LXSUPMON.EXE RUN
    O4 - HKLM&#092;..&#092;Run: [inetmgr] C:&#092;PROGRA~1&#092;INTERN~2&#092;INETMGR.EXE
    O4 - HKLM&#092;..&#092;Run: [SecureClean4RegManager] "C:&#092;Program Files&#092;WhiteCanyon&#092;SecureClean 4&#092;scregmanager4.exe"
    O4 - HKLM&#092;..&#092;Run: [SecureClean4Tray] "C:&#092;Program Files&#092;WhiteCanyon&#092;SecureClean 4&#092;sctray4.exe"
    O4 - HKLM&#092;..&#092;Run: [QuickTime Task] "C:&#092;WINDOWS&#092;SYSTEM&#092;QTTASK.EXE" -atboottime
    O4 - HKLM&#092;..&#092;Run: [AVG_CC] C:&#092;PROGRA~1&#092;GRISOFT&#092;AVG6&#092;avgcc32.exe /STARTUP
    O4 - HKLM&#092;..&#092;RunServices: [SmcService] C:&#092;PROGRAM FILES&#092;SYGATE&#092;SPF&#092;SMC.EXE
    O4 - HKLM&#092;..&#092;RunServices: [SecureClean4Service] "C:&#092;Program Files&#092;WhiteCanyon&#092;SecureClean 4&#092;scwatch4.exe"
    O4 - HKLM&#092;..&#092;RunServices: [Avgserv9.exe] C:&#092;PROGRA~1&#092;GRISOFT&#092;AVG6&#092;Avgserv9.exe
    O4 - HKCU&#092;..&#092;Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
    O4 - HKCU&#092;..&#092;Run: [System Mechanic Popup Stopper] "C:&#092;PROGRAM FILES&#092;IOLO&#092;SYSTEM MECHANIC 4&#092;POPUPSTOPPER.EXE"
    O4 - HKCU&#092;..&#092;Run: [SpySweeper] C:&#092;Program Files&#092;Webroot&#092;Spy Sweeper&#092;SpySweeper.exe /0
    O4 - HKCU&#092;..&#092;Run: [svcSystem] C:&#092;WINDOWS&#092;SYSTEM&#092;lrdsvr.exe
    O8 - Extra context menu item: &Google Search - res://C:&#092;PROGRAM FILES&#092;GOOGLE&#092;GOOGLETOOLBAR1.DLL/cmsearch.html
    O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:&#092;PROGRAM FILES&#092;GOOGLE&#092;GOOGLETOOLBAR1.DLL/cmcache.html
    O8 - Extra context menu item: Si&milar Pages - res://C:&#092;PROGRAM FILES&#092;GOOGLE&#092;GOOGLETOOLBAR1.DLL/cmsimilar.html
    O8 - Extra context menu item: Backward &Links - res://C:&#092;PROGRAM FILES&#092;GOOGLE&#092;GOOGLETOOLBAR1.DLL/cmbacklinks.html
    O8 - Extra context menu item: Translate into English - res://C:&#092;PROGRAM FILES&#092;GOOGLE&#092;GOOGLETOOLBAR1.DLL/cmtrans.html
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwa...ash/swflash.cab
    O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/...8157.1371064815

  10. Software & Hardware   -   #10
    lynx's Avatar .
    Join Date
    Sep 2002
    Location
    Yorkshire, England
    Posts
    9,759
    I tend to agree with Foot Loose.

    Look in C:&#092;WINDOWS&#092;Downloaded Program Files.

    If there&#39;s anything there that you aren&#39;t ABSOLUTELY sure about, get rid of it, you can easily dl them again.

    Make sure your browser is not open when you do this, otherwise your browser may already have an infected prog loaded and simply dl it again. Better still, do it in safe mode.

    Edit: Also, check your IE security settings, you may well find that they have been set to LOW, which means you are open to re-infection.
    .
    Political correctness is based on the principle that it's possible to pick up a turd by the clean end.

Page 1 of 2 12 LastLast

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •