Download HijackThis from here, run it and Post the Log File here:
http://www.softpedia.com/p
Main Topics
Browse All TopicsHi,
I recently started getting an error message:
Title: Windows error service
Message: Windows detected Spyware on your computer. Download free spyware scanner & Remover.
Theres an OK and CANCEL button, i have not up until now clicked on the "OK" button because i have a feeling it is not an original windows error message. It pops up occasionally.
Can someone tell me what it's about and is it a legal message? Could it be a potential virus of some kind? If so how can i get rid of it or find it's executing source on my PC?
Thanks,
Zephyr__
This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.
Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.
If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.
Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.
Access the answers to your technology questions today.
30-day free trial. Register in 60 seconds.
Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Try it out and discover for yourself.
30-day free trial. Register in 60 seconds.
Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.
Download HijackThis from here, run it and Post the Log File here:
http://www.softpedia.com/p
Windows on its own usually doesn't throw these kind of errors so...
Check for adware and sypware all are free except Spycop: http://www.spycop.com/
Also use SpyBot and AdAware in tandem. Neither is 100% accurate but the two of them together get pretty close to 100% accuracy.
spybot here
http://www.safer-networkin
Download
http://spybot.safer-networ
AdAware
http://www.lavasoftusa.com
Not Free
Spycop:
http://www.spycop.com/
==========================
Could be a Broweser high jacker behind the problem
This little didy will get rid of some of the more well known Home page Hijackers.
CoolWebShredder
http://www.spychecker.com/
here is a description of what it does
http://www.softpedia.com/p
Features:
· Redirections to CoolWebSearch related pages
· Redirections when mistyping URLs
· Redirections when visiting Google
· Enormous IE slowdowns when typing
· IE start page/search page changing on reboot
· Sites in the IE Trusted Zone you didn't add
· Popups in Google and Yahoo when searching
· Errors at startup mentioning WIN.INI or IEDLL.EXE
· Unable to change or see certain items in IE Options
· Unable to access IE Options at all
download here
http://www.spychecker.com/
--------------------------
Could be a Broweser high jacker behind the problem
Hijack This and BHODemon and Browser Hijack Blaster
Hijack This http://www.spywareinfo.com
http://www.spywareinfo.com
BHODemon http://www.spywareinfo.com
Browser Hijack Blaster http://www.wilderssecurity
=======================
General and overall information about Spy/Adware
http://www.cexx.org/adware
>>>Theres an OK and CANCEL button, i have not up until now clicked on the "OK" button because i have a feeling it is not an original windows error message. It pops up occasionally.
Very wise not to click the OK button like you said it doesn't appear to be legit Windows message. Perhaps it is coming from a web site you are visiting or something go installed on your system. Are you using Kaaza, if so then that is probably the culprit.
CrazyOne, can u plzz have a look at this question >> http://www.experts-exchang
Either im not getting what he is asking, or he is not getting what im telling :-\
Logfile of HijackThis v1.97.7
Scan saved at 19:22:29, on 02/05/2004
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.e
C:\WINDOWS\system32\winlog
C:\WINDOWS\system32\servic
C:\WINDOWS\system32\lsass.
C:\WINDOWS\system32\svchos
C:\WINDOWS\System32\svchos
C:\WINDOWS\system32\spools
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\mysql\bin\mysqld-nt.exe
C:\WINDOWS\System32\nvsvc3
C:\PROGRA~1\Agnitum\OUTPOS
C:\WINDOWS\System32\svchos
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\RunDll
C:\Program Files\Java\j2re1.4.2_04\bi
C:\WINDOWS\system32\driver
C:\WINDOWS\System32\ctfmon
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Stardock\ObjectDock\
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Winterbottom\Desk
R0 - HKCU\Software\Microsoft\In
R1 - HKCU\Software\Microsoft\In
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-7
O2 - BHO: (no name) - {AE7CD045-E861-484f-8273-0
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-0
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_04\bi
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [Outpost Firewall] C:\PROGRA~1\Agnitum\OUTPOS
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe
O4 - HKLM\..\Run: [Microsoft Internet Explorer] C:\WINDOWS\System32\IEXPLO
O4 - HKLM\..\Run: [AdRotator.Application] C:\WINDOWS\system32\driver
O4 - HKLM\..\Run: [{357AA41A-B7A8-4632-A27D-
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCt
O4 - HKLM\..\Run: [SuperBar.Component] C:\WINDOWS\system32\inetsr
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe
O4 - Startup: Stardock ObjectDock.lnk = C:\Program Files\Stardock\ObjectDock\
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: Research (HKLM)
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O9 - Extra button: Real.com (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O9 - Extra button: Trashcan (HKCU)
O9 - Extra 'Tools' menuitem: Show Trashcan (HKCU)
O15 - Trusted Zone: http://*.flingstone.com
O15 - Trusted Zone: http://*.mt-download.com
O15 - Trusted Zone: http://*.xxxtoolbar.com
O16 - DPF: {11111111-1111-1111-1111-1
O16 - DPF: {12398DD6-40AA-4C40-A4EC-A
O16 - DPF: {166B1BCA-3F9C-11CF-8075-4
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-4
O17 - HKLM\System\CCS\Services\T
> O15 - Trusted Zone: http://*.flingstone.com
> O15 - Trusted Zone: http://*.mt-download.com
> O15 - Trusted Zone: http://*.xxxtoolbar.com
Have u added these sites to Trusted Zones urself ??
O4 - HKLM\..\Run: [AdRotator.Application] C:\WINDOWS\system32\driver
O4 - HKLM\..\Run: [SuperBar.Component] C:\WINDOWS\system32\inetsr
O15 - Trusted Zone: http://*.flingstone.com
O15 - Trusted Zone: http://*.mt-download.com
O15 - Trusted Zone: http://*.xxxtoolbar.com
O16 - DPF: {11111111-1111-1111-1111-1
O16 - DPF: {12398DD6-40AA-4C40-A4EC-A
Run hijacthis, check these entries, and click on FIX
reboot the amchine and now check for the problem.
Hi,
O4 - HKLM\..\Run: [SuperBar.Component] C:\WINDOWS\system32\inetsr
O4 - HKLM\..\Run: [AdRotator.Application] C:\WINDOWS\system32\driver
I used HiJackThis to fix these files, restarted pc and same error happens. I also deleted these files manually myself but when i restart the pc they come back! And when i run the sysconfig utility both of them files are selected on startup. when i untick them and restart they seem to appear again as selected.
Could it be another file which is somehow generating these two files?
Downlaod these softwares and scan the system with them !!
AdAware==> http://www.webattack.com/d
SpyBot ==> http://www.webattack.com/d
CoolWebShredder ==> http://www.spychecker.com/
Logfile of HijackThis v1.97.7
Scan saved at 11:54:54 PM, on 11/07/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.e
C:\WINDOWS\system32\winlog
C:\WINDOWS\system32\servic
C:\WINDOWS\system32\lsass.
C:\WINDOWS\system32\svchos
C:\WINDOWS\System32\svchos
C:\WINDOWS\system32\spools
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\pctspk
C:\Program Files\Norton Personal Firewall\IAMAPP.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\driver
C:\Program Files\ScanSoft\OmniPageSE\
C:\Program Files\Java\j2re1.4.2_04\bi
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\QUICKENW\QWDLLS.EXE
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton Personal Firewall\NISUM.EXE
C:\Program Files\Norton AntiVirus\AdvTools\NPROTEC
C:\WINDOWS\System32\nvsvc3
C:\WINDOWS\System32\svchos
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.ex
C:\Program Files\Norton Personal Firewall\SymProxySvc.exe
C:\Program Files\Norton Personal Firewall\NISSERV.EXE
C:\WINDOWS\system32\arpa.e
C:\Program Files\Norton Personal Firewall\ATRACK.EXE
C:\WINDOWS\system32\arpa.e
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\cleaner.exe
C:\WINDOWS\cleaner.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\LocalService\Appl
C:\WINDOWS\System32\hza.ex
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\tlryo.
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\user\Desktop\Old HDD\My Documents\DOC's\HijackThis
R0 - HKCU\Software\Microsoft\In
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-2
O2 - BHO: (no name) - {6CFA4B7D-E868-29CF-8652-1
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-F
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-0
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [iamapp] C:\Program Files\Norton Personal Firewall\IAMAPP.EXE
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [AdRotator.Application] C:\WINDOWS\system32\driver
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe
O4 - HKLM\..\Run: [Omnipage] C:\Program Files\ScanSoft\OmniPageSE\
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\NeroCh
O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~1\AdvTo
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_04\bi
O4 - HKLM\..\Run: [SuperBar.Component] C:\WINDOWS\system32\inetsr
O4 - HKLM\..\Run: [{357AA41A-B7A8-4632-A27D-
O4 - HKCU\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMo
O4 - HKCU\..\Run: [SpySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe /0
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Global Startup: Billminder.lnk = C:\QUICKENW\BILLMIND.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: Quicken Startup.lnk = C:\QUICKENW\QWDLLS.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: MoneySide (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O15 - Trusted Zone: http://*.flingstone.com
O15 - Trusted Zone: http://*.mt-download.com
O16 - DPF: {00B71CFB-6864-4346-A978-C
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D
O16 - DPF: {19E28AFC-EAE3-4CE5-AC83-2
O16 - DPF: {4B9F2C37-C0CF-42BC-BB2D-D
O16 - DPF: {74D05D43-3236-11D4-BDCD-0
O16 - DPF: {8E0D4DE5-3180-4024-A327-4
O16 - DPF: {9EB320CE-BE1D-4304-A081-4
O16 - DPF: {9F1C11AA-197B-4942-BA54-4
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-4
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-7
O17 - HKLM\System\CCS\Services\T
Spy Sweeper got Purity Scan, go2net.com which always show up----Spybot got Purity
and DSO Exploit but couldnot fix Exploit---Webshredder was clean ---Stinger clean too
But on deleteing cookies and temporary internet files a DATFile 48K would not delete
it was being used by another person or program-- so far the sme popup show but the Explorer initialization error doesnot-- what is next
Business Accounts
Answer for Membership
by: SheharyaarSaahilPosted on 2004-05-02 at 11:14:15ID: 10972605
Hello Zephyr__ =)
-- ownload/dl adaware.sh tml ownload/dl spybot.sht ml program/co olwebshred der.html
---------- -- mfs/defaul t.asp?cid= 9059 om/ o.com/ om/actives can/com/ ac tivescan_p rincipal.h tm ntivirus/d efault.asp
CHECK FOR SPYWARES:
--------------------------
AdAware==> http://www.webattack.com/d
SpyBot ==> http://www.webattack.com/d
CoolWebShredder ==> http://www.spychecker.com/
CHECK FOR ONLINE VIRUS SCAN:
--------------------------
1. http://us.mcafee.com/root/
2. http://security.symantec.c
3. http://housecall.trendmicr
4. http://www.pandasoftware.c
5. http://www.pcpitstop.com/a
!! GOOD LUCK !!