[HKEY_CURRENT_USER\Softwar
startpage
Main Topics
Browse All TopicsI know this is spyware of somesort, but all the references I've found are in forgein languages and having google translate them is little help.
The website fronts as a windows update page but does little else as far as I can see. I want to get rid of it but havent found a tool that detects it yet, I've run Spybot Search & Destroy, AdAware and HiJackThis. None of them have found the item.
A find in regedit shows me the site buried in:
HKEY_USERS\S-1-5-21-121444
Anybody ever heard of this and know how to get rid of it?
running windows 2000 professional, SP2.
This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.
Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.
If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.
Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.
Access the answers to your technology questions today.
30-day free trial. Register in 60 seconds.
Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Try it out and discover for yourself.
30-day free trial. Register in 60 seconds.
Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.
also get bho demon
BHO demon
http://www.definitivesolut
try an easy solution if you haven't already, download ad-aware se from www.download.com, if you've already tried this then google search for a program called hijack this. It will scan your computer and using the website, you can copy and paste the scan finding and it will tell you which ones to delete.
the website is www.hijackthis.de once you get the .exe file
I noticed you're also a couple of service packs behind, too. While this probably won't help you out of your current problem, you should apply SP4 and the hotfixes that have come out since it. MS seems to have abandoned plans to bring out SP5 for W2K.
You might also want to investigate the software (much of it free) to shield your system from problems caused by malware. Personally, I use ZoneAlarm (free version), AVG (free version), and AdAware SE (free version) but there are lots of others available. I'm also running behind a router in "stealth" mode. I've not had any problems (except for a few I made for myself by downloading some files from a site I shouldn't have trusted) since I installed these... and my broadband connection is on pretty much full time.
Good luck!
You've been hijacked.
Before doing ANY fixes on this system, back up critical data, and then proceed.
All (Or as much as possible) of the following should be done from Safe Mode. (Before boot up, hit the F8 key repeatedly until you get the windows boot options menu).
First, you need 4 tools.
McAfee Antivirus (Yes, when configured, it will also scan for spyware!)
Adaware
Spybot search and Destroy
Hijack this
First, note the order I have put them in. This is the order in which you use them. McAfee should always be running, of course. Second, when you suspect problems, run Adaware. If you don't solve your isses, boot into SAFE mode, and run Adaware AND spybot. If this still does not resolve your issues, Hijack this is your last resort. IF YOU USE HIJACK THIS INCORRECTLY, YOU CAN CAUSE MORE PROBLEMS THEN GOOD. Hijack this looks for any process that is run at startup and lists it. You can cause your self some major headaches if you delele something you actually need, so use with caution. Heed the advice of others on this thread, and post your log files from hijackthis to http://www.hijackthis.de/e
I have found that these 4 tools, used in the mentioned order, is the most effective way of ridding your self with ADware/SPYware/MALware.
Patrick.
I suggested 4 tools, you suggested 3, are my 4 hammers going to take much longer then your 3? What is the 3 dont catch them all? You have to keep in mind that NONE of these options are doing the same types of scans, and NONE of them find 100% of them out there. I also mentioned that hijack this is a last resort. There have been countless comparisons published that will back me up here. None catch everything, so you need a safety net.
At the top of my list is what?
Let me refresh your memory.
MCAFEE ANTIVIRUS!
THEN
Adaware.
Spybot
Hijack this!
You need to read my post a little closer before you start discarding my advice. I ABSOLUTELY DID NOT "FAIL TO MENTION THAT A VIRUS SCAN IS NEEDED TO ENSURE..."! The very first thing listed in the list is antivirus! And the very first thing I instruct him to do is ensure Mcafee is running! I have had to clean countless machine where just using 1-2 programs does not finish the job. So, you says to use Adaware and Hijack this, in addition to antivirus! You backed me up, but I simply stated one more.
Do I need to show you test results that show spybot is actually the MOST EFFEICENT at catching these things?
http://www.pcworld.com/new
http://spywarewarrior.com/
If you do the math, you have even the best of them missing 1/4 of all the spyware on any given machine, you would need 3 to get down to missing a total of 1/8th of the potential spyware on any given machine. (Ok maybe that math is not too accurate, but I think I am making my point here.)
I make a lot of money removing spyware/viruses/malware for companies, I have seen this stuff over and over again. I have also heard a lot of bad advice out there. I am NOT claiming that any bad advice is being given here, but I am trying to make the point that there is a lot of confusion out here. Spyware (I like the term Malware - Malicious Software) defense is like the wild west. It's relatively new territory that is reinventing it self constantly, depending on 1-2 tools may not be enough.
Sorry for getting back to you all so late, I've been glued to the keyboard offsite and because of the problems listed in my original post we took the server offline and did some work.
To add insult to injury the server has never been managed, it was handled by another department and all of a sudden something went wrong and we were called in. I have run McAfee Enterprise Edition 8.0 and I'm scanning and blocking spyware/malware. I've also run spybot and adaware and they found a few things. At some point in time it looks like somebody downloaded and saved some compressed files that were completley made up of infected files or better said the actuall virus itself.
It's been a nightmare getting these things cleaned up and I'm not there yet. I found that qdentica downloads a item called SIDEBAR and I guess the script on Qdentica just calls it up. Sidebar is a nasty one, lots of work to get rid of it. I'm going get a complete image of the machine before I do anywork I think that is about the best I can do at this point.
Thanks very much for all the advice, I had done most of it already and it removed bits and pieces. What I found was that bat files called other apps then those apps called other services to begin.
Essentially it was this, on bootup a bat file named X.bat was ran, it called a program called wininstall.html that file had a javascript that called up www.qdentical.com on that site it called up a toolbar named sidebar. The people who intertwine these things worked hard at it. In addition to that there were other programs installed, IST, WinServe Ad, and a host of others all buried in different places.
My biggest hurdle was that I didnt know what services were doing what, if I killed this and uninstalled (deleted it) would I get the service to run that the machine was designed to do? It's like going to a friends house and not knowing where the glasses are in the cabinet, open them all and look around untill you find what youre looking for. I reviewed almost every service running and pinpointed what was legit and what was not.
BHODemon actually gave me some insight that I did not have it would disable somethings for me that I didnt want to remove on my own and if I screwed up I could re-enable it.
All said and done, the problem was poor management, or should I say NO management. For long term safety I'm going to pull the machine out of production and format it, that way I'll know notihing is haning around.
Again, thanks for all the help!
Business Accounts
Answer for Membership
by: stevenlewisPosted on 2004-12-21 at 08:55:38ID: 12877296
did you try and set your home page in IE, tools, internet options, hoime page?
also the key in the reg