Page 1 of 2 12 LastLast
Results 1 to 10 of 11

Thread: Incredifind

  1. #1
    Has anyone ever heard of IncrediFind? I’m running an old win95 and have found it in the program files folder. Ad-aware and spybot neither one notice it. On occasion it will re-set my homepage or mis-direct me. Anyone special I need to know about deleting this? Will it be in the registry as well?

  2. Software & Hardware   -   #2
    tesco's Avatar woowoo
    Join Date
    Aug 2003
    Location
    Canadia
    Posts
    21,669
    See if it is in add\remove programs first.

    Then download and run hijackthis! and post the log here.

  3. Software & Hardware   -   #3
    I have heard of it. It is a nasty adware+spyware/browser hijack. Ad-aware and spybot should both detect it. Are you running the latest versions + latest updates?

  4. Software & Hardware   -   #4
    Thanks Rossco. I had already checked add/remove and it is not listed. Here is the log from Hijackthis

    Logfile of HijackThis v1.97.7
    Scan saved at 9:39:26 PM, on 7/12/04
    Platform: Windows 95 B (Win9x 4.00.1212)
    MSIE: Internet Explorer v5.50 SP1 (5.50.4522.1800)

    Running processes:
    C:\WINDOWS\SYSTEM\KERNEL32.DLL
    C:\WINDOWS\SYSTEM\MSGSRV32.EXE
    C:\WINDOWS\SYSTEM\MPREXE.EXE
    C:\WINDOWS\SYSTEM\WINMODEM.101\azexe.exe
    C:\WINDOWS\EXPLORER.EXE
    C:\WINDOWS\SYSTEM\LXDBOXCP.EXE
    C:\WINDOWS\SYSTEM\SYSTRAY.EXE
    C:\WINDOWS\SYSTEM\MSWHEEL.EXE
    C:\WINDOWS\SYSTEM\ELEGANT TECH\INFO-GUARDIAN\INFOGUARD.EXE
    C:\WINDOWS\TEMP\ICSUPP95.EXE
    C:\WINDOWS\SYSTEM\RNAAPP.EXE
    C:\WINDOWS\SYSTEM\tapiexe.exe
    C:\WINDOWS\SYSTEM\DDHELP.EXE
    C:\WINDOWS\SYSTEM\SPOOL32.EXE
    C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
    C:\UNZIPPED\HJT\HIJACKTHIS.EXE

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://server224.smartbotpro.net/7search/?new-hkcu
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://mshp.dll/sp.html#10213
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.pcpages.com/svc/index.html
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://default-homepage-network.com/start.cgi?new-hklm
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://server224.smartbotpro.net/7search/?new-hklm
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://mshp.dll/sp.html#10213
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://mshp.dll/index.html#10213
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://mshp.dll/sp.html#10213
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by EarthLink, Inc.
    F0 - system.ini: Shell=
    F1 - win.ini: run=lxdboxcp.exe
    O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHELPER.DLL
    O2 - BHO: NavErrRedir Class - {5D60FF48-95BE-4956-B4C6-6BB168A70310} - C:\PROGRA~1\INCRED~1\BHO\INCFIN~1.DLL
    O2 - BHO: (no name) - {B9D90B27-AD4A-413a-88CB-3E6DDC10DC2D} - C:\WINDOWS\MSOPT.DLL
    O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
    O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
    O4 - HKLM\..\Run: [MSWHEEL] C:\WINDOWS\SYSTEM\mswheel.exe
    O4 - HKLM\..\Run: [POINTER] C:\MSINPUT\point32.exe
    O4 - HKLM\..\Run: [Msdapp] C:\WINDOWS\SYSTEM\Elegant Tech\Info-Guardian\infoguard.exe
    O4 - HKLM\..\Run: [BrowserWebCheck] loadwc.exe
    O4 - HKLM\..\Run: [ClrSchLoader] \Progra~1\Lycos\IEagent\Loader.exe
    O4 - HKLM\..\Run: [Od] C:\WINDOWS\TEMP\OD.EXE
    O4 - HKLM\..\Run: [InterCheckMonitor] "C:\PROGRAM FILES\SOPHOS SWEEP\ICMON.EXE" -minimised
    O4 - HKLM\..\RunServices: [azmodem] WINMODEM.101\azexe.exe
    O4 - HKLM\..\RunServices: [Sweep95] C:\Program Files\Sophos SWEEP\ICLOAD95.EXE
    O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
    O4 - HKCU\..\Run: [MSMSGS] "c:\Program Files\MSN Messenger\msmsgs.exe" /background
    O4 - Startup: Crystal 3D Audio Control.lnk = C:\WINDOWS\CWB3DSND.EXE
    O9 - Extra button: Messenger (HKLM)
    O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
    O9 - Extra button: Messenger (HKLM)
    O9 - Extra 'Tools' menuitem: Messenger (HKLM)
    O12 - Plugin for .mpeg: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin3.dll
    O12 - Plugin for .mid: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin2.dll
    O12 - Plugin for .mp3: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin3.dll
    O12 - Plugin for .mov: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin.dll
    O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
    O12 - Plugin for .pdf: C:\PROGRA~1\INTERN~1\PLUGINS\nppdf32.dll
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwa...ash/swflash.cab
    O16 - DPF: {0FC6BF2B-E16A-11CF-AB2E-0080AD08A326} - http://www.liveupdate.com/controls/getcab2.dll
    O16 - DPF: Yahoo! Euchre - http://download.yahoo.com/games/clients/y/er1_x.cab
    O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yahoo.com/dl/installs/yinst0401.cab
    O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwa...director/sw.cab
    O16 - DPF: {7A32634B-029C-4836-A023-528983982A49} (MSN Chat Control 4.2) - http://fdl.msn.com/public/chat/msnchat42.cab
    O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/game...s/y/potb_x.cab
    O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004033...all/xscan53.cab
    O16 - DPF: ChatSpace Java Client 2.1.0.84N - http://about.chatspace.com/Java/cs4msn084.cab
    O16 - DPF: {CD17FAAA-17B4-4736-AAEF-436EDC304C8C} (ContentAuditX Control) - http://a840.g.akamai.net/7/840/5805/v1503/...uditControl.cab

  5. Software & Hardware   -   #5
    Ariel, I have both and neither will detect it. For some reason spybot just will not update for me, never has. To be honest, I don't think I thought to update adaware but I don't beleive they support the win95 version anymore. I'm sure it is scumware, just wondering if I will have any problems if I just go in a delete it.

  6. Software & Hardware   -   #6
    Originally posted by coldnorth@12 July 2004 - 23:31
    Ariel, I have both and neither will detect it. For some reason spybot just will not update for me, never has. To be honest, I don't think I thought to update adaware but I don't beleive they support the win95 version anymore. I'm sure it is scumware, just wondering if I will have any problems if I just go in a delete it.
    I think you are running a old version. I know spybot will get rid of this. I used it to remove that crap off a friends computer. The latest version is 1.3.

    Try un-installing/ installing then updating...


    http://www.safer-networking.org/en/download/index.html

  7. Software & Hardware   -   #7
    I'm running version 1.2 so perhaps I'll update tomorrow.

  8. Software & Hardware   -   #8
    Well I downloaded spybot version 1.3, searched for updates (there were none), and ran the program. It did find a lot of stuff that version 1.2 had not found, but it did not find IncrediFind. In fact, after I started the browser back up IncrediFind started re-directing me.

  9. Software & Hardware   -   #9
    yeah, it is spyware, and yeah, Spybot won't detect it. Go into the folder, and there will be a .dll file. Unregister this dll file, and then delete it (if it won't let you, then use safe mode). There's also a process you should end in the task manager, but I forgot which one. You should try googling this. I just got rid of it, and I found a nice guide on how to remove it. Just search for "incredifind". Good luck.

  10. Software & Hardware   -   #10
    Poster
    Join Date
    Jun 2003
    Posts
    126
    hi,
    you have a few issues going on there.

    first, please download cwshredder here.

    unzip the program, close all windows except for the program and hit fix.

    reboot and post a new log.

Page 1 of 2 12 LastLast

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •