Security
--
Questions
--
Followers
Top Experts
Zero AI Policy
We believe in human intelligence. Our moderation policy strictly prohibits the use of LLM content in our Q&A threads.
HKEY_CURRENT_USER\Software
HKEY_CURRENT_USER\Software
HKEY_CURRENT_USER\Software
HKCU\Software\Microsoft\In
HKCU\Software\Microsoft\In
HKCU\Software\Microsoft\In
HKCU\Software\Microsoft\In
HKCU\Software\Microsoft\In
HKEY_LOCAL_MACHINE\Softwar
and remove the ones that are appearing constantly after being removed ..
Also
Start --> run --> Type in "msconfig" and press "Enter"
goto Startup tab
Disable all the applications there.Reboot the machine and check if the same adwares come back
If not, then enable one at a time in the same startup tab and find the application that might cause this
at startup
http://download.nai.com/products/mcafee-avert/SystemHelpDocs/DisableSysRestore.htm
Also clear your cookies and temp internet files(cache). Use a different browser that doesn't support ActiveX.
Mozilla or Opera are my favorites. Mozilla is totally free, Opera you have to pay for the blocker, and to strip the ad's it includes.
You'll reduce pop-ups and ad's, and espically ad-ware programs by 90% or more. Do not run as an administrator for everyday tasks... such as surfing the net. place yourself in a "User" group, not the admin's or powerusers. if you need to be admin to install or update, use the RunAs feature of M$.
http://www.microsoft.com/resources/documentation/WindowsServ/2003/standard/proddocs/en-us/Default.asp?url=/resources/documentation/WindowsServ/2003/standard/proddocs/en-us/windows_security_whynot_admin.asp
-rich






EARN REWARDS FOR ASKING, ANSWERING, AND MORE.
Earn free swag for participating on the platform.
> I had a few of the entries you listed.
Post the hijackthis log here

Get a FREE t-shirt when you ask your first question.
We believe in human intelligence. Our moderation policy strictly prohibits the use of LLM content in our Q&A threads.
go to that thread and you should see the url for hijackthis
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon
C:\WINNT\system32\services
C:\WINNT\system32\lsass.ex
C:\WINNT\system32\svchost.
C:\WINNT\system32\spoolsv.
C:\PROGRA~1\SYMANT~1\SYMAN
C:\WINNT\system32\svchost.
C:\WINNT\system32\hidserv.
C:\PROGRA~1\SYMANT~1\SYMAN
C:\Program Files\Norton Utilities\NPROTECT.EXE
C:\WINNT\system32\regsvc.e
C:\WINNT\system32\MSTask.e
C:\Program Files\Speed Disk\nopdb.exe
C:\PROGRA~1\MI6841~1\MSSQL
C:\WINNT\system32\stisvc.e
C:\WINNT\System32\WBEM\Win
C:\WINNT\system32\svchost.
C:\WINNT\system32\inetsrv\
C:\WINNT\system32\rundll32
C:\WINNT\Explorer.EXE
C:\WINNT\system32\svchost.
C:\WINNT\system32\ctfmon.e
C:\WINNT\Microsoft.NET\Fra
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINNT\system32\wisptis.
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\DOCUME~1\KYLEME~1\LOCAL
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Kyle Medlin\Desktop\HijackThis.
R0 - HKCU\Software\Microsoft\In
R1 - HKCU\Software\Microsoft\In
R1 - HKLM\Software\Microsoft\In
R1 - HKLM\Software\Microsoft\In
R0 - HKLM\Software\Microsoft\In
R0 - HKLM\Software\Microsoft\In
R1 - HKCU\Software\Microsoft\Wi
R0 - HKCU\Software\Microsoft\In
R1 - HKLM\Software\Microsoft\In
R1 - HKLM\Software\Microsoft\In
R3 - Default URLSearchHook is missing
O1 - Hosts: 207.36.196.189 auto.search.msn.com
O1 - Hosts: 207.36.196.189 search.netscape.com
O1 - Hosts: 207.36.196.189 ieautosearch
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radi
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-0
O3 - Toolbar: (no name) - {BDF6CE3D-F5C5-4462-9814-3
O3 - Toolbar: (no name) - {339BB23F-A864-48C0-A59F-2
O3 - Toolbar: 64 Okay - {EBF34CD9-3269-53BE-14BE-A
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [FORK TEST] C:\PROGRA~1\PEAKAN~1\bags jugs.exe
O4 - HKLM\..\Run: [Ad-watch] "C:\Program Files\Lavasoft\Ad-aware 6\Ad-watch.exe"
O4 - HKLM\..\Run: [Ad-aware] "C:\Program Files\Lavasoft\Ad-aware 6\Ad-aware.exe" +c
O4 - HKLM\..\Run: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck /autofix
O4 - HKLM\..\RunServices: [Symantec Security] symantec32.exe
O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe
O6 - HKCU\Software\Policies\Mic
O6 - HKCU\Software\Policies\Mic
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar
O8 - Extra context menu item: Backward &Links - res://c:\program files\google\GoogleToolbar
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://c:\program files\google\GoogleToolbar
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2
O8 - Extra context menu item: Si&milar Pages - res://c:\program files\google\GoogleToolbar
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar
O16 - DPF: {02BCC737-B171-4746-94C9-0
O16 - DPF: {238F6F83-B8B4-11CF-8771-0
O16 - DPF: {9059F30F-4EB1-4BD2-9FDC-3
O16 - DPF: {9F1C11AA-197B-4942-BA54-4
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-4






EARN REWARDS FOR ASKING, ANSWERING, AND MORE.
Earn free swag for participating on the platform.
R0 - HKCU\Software\Microsoft\In
R1 - HKCU\Software\Microsoft\In
R1 - HKLM\Software\Microsoft\In
R1 - HKLM\Software\Microsoft\In
R0 - HKLM\Software\Microsoft\In
R0 - HKLM\Software\Microsoft\In
R1 - HKLM\Software\Microsoft\In
R3 - Default URLSearchHook is missing
O1 - Hosts: 207.36.196.189 auto.search.msn.com
O1 - Hosts: 207.36.196.189 search.netscape.com
O1 - Hosts: 207.36.196.189 ieautosearch
If you have google toolbar, remove these and uninstall google toolbar
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar
O8 - Extra context menu item: Backward &Links - res://c:\program files\google\GoogleToolbar
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://c:\program files\google\GoogleToolbar
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2
O8 - Extra context menu item: Si&milar Pages - res://c:\program files\google\GoogleToolbar
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar
O16 - DPF: {02BCC737-B171-4746-94C9-0

Get a FREE t-shirt when you ask your first question.
We believe in human intelligence. Our moderation policy strictly prohibits the use of LLM content in our Q&A threads.
For prevention - use mozilla instead of IE, doesn't have the same tendancy for pop ups and downloading things behind your back
For prevention and finding the problem - ZoneAlarm. It's helped me fix a few problems because it will warn you when a program is trying to access the internet. Find that program and kill it.
WinTasks is another great program that shows you all the different files running and their associated .dll files. It also gives you a description of most of the processes. The bad ones stick out like a sore thumb, particularly ones that use a lot of memory.
Lastly, I use Ace Optimizer Utilities to delete files. It has a secure file deleted which permanently rids the file from your system - unrecoverable! It also gives you a great view of the startup folder so it's easy to suspend or delete processes. It also has a handy uninstall feature. It will show whether a program has been uninstalled correctly or not. Many adware or viruses are not deleted properly, this program will let you do a manual delete if the uninstall doesn't work properly.
Phew. Hope that helps!!
hi! matbe this can help u! try using NoAdware 2.0.






EARN REWARDS FOR ASKING, ANSWERING, AND MORE.
Earn free swag for participating on the platform.
The virus loads another virus and that virus loads a Trojan and the trojan loads some spyware.
You need to identify the virus.
I recommend AVG at www.grisoft.com, its free.
Find out the virus name (NOTE: AVG will probably not remove the virus)
Then go to symantec.com and search for manual removal instructions. Print these out. And follow them step by step EXACTLY as written. It will tell you to reboot into safe mode three times or something like that.
If you can tell me the name of the virus I can get the removal instructions for you.
I have had a lot of experience with these types of virus and I find that the manual removal method is the only way to actually rid your machine of the infestation.
Good luck!
**************************
**************************
http://download.com.com/3000-8022-10214379.html?tag=lst-0-1
http://www.lavasoft.de/software/adaware/
*****
By default, Ad-Aware does not scan system or hidden/compressed folders.
This is how to change it to check all files.
**************************
Before you scan with Ad-Aware, check for updates of the reference file by using the "web update".
Then........
Make sure the following settings are turned on. "ON=GREEN; OFF= RED or GREY if not available for this version”
From main window click "Start" then” Activate in-depth scan"
Then......
Click "Use custom scanning options > Customize" and make sure these options are on: "Scan within archives" ,"Scan active processes”,” Scan registry", "Deep scan registry", "Scan my IE Favorites for banned URL" and "Scan my host-files"
Then.....
Go to settings (the gear on top of Ad-Aware) > Tweak > Scanning engine and tick "Unload recognized processes during scanning"; then click "Cleaning Engine" and tick "Automatically try to unregister objects prior to deletion" and "Let windows remove files in use at next reboot"
Click "Proceed" to save your settings.

Get a FREE t-shirt when you ask your first question.
We believe in human intelligence. Our moderation policy strictly prohibits the use of LLM content in our Q&A threads.
The manual remove method is the only way.
i finally got rid of it by going into SAFE MODE followed by:
(1) run spy ware search and destroy
(2) run ad-aware
(3) run hijackthis.
hope that helps .






EARN REWARDS FOR ASKING, ANSWERING, AND MORE.
Earn free swag for participating on the platform.
You need two programs. Of course "Ad-Aware Pro" from www.download.com, and Mcafee Virus scan 7.0 or later.(you can download 7.5 beta version from www.nai.com for free) Install them both, but don't run scans yet. If you have norton ...uninstall it cuz it sux.
First delete all temporary internet files / objects / cookies / downloaded program files.
Next Go to privacy tab and overide automatic cookie handling. >Block all third party cookies.
Now you need to uninstall all the BS programs (e.g. Hot bar, casinoonline, weatherbug, ad-interstatial delivery, coupons $$, new.net domains, ect.) Read the uninstalls carefully cus they will trick you into keeping some components of the software which leads to reinfection.
Now update you adaware, and update you mcafee.
Open mcafee and set you on-access detection to include joke or fake virus programs and default action to delete.
Now reboot your computer in safe mode by pressing the f8 key on startup.
Now that you are in safe mode the adware programs are not running. Now do a scan with the adaware.
Now do an on-demand scan with mcafee. (you need to set the on-demand settings the same as the on-access - joke and fake virus programs). You should get lots of hits and you can go to mcafee's site and look them up.
It also helps to block cookies from the following sites.
freeze.com
gator.com
atdmt.com
atwola.com
doublclick.net
Now that you are done scanning you can reboot and go on with your life. This method takes about an hour, but it really works to get rid of adware and spyware + keep it off your computer.
Just offering my thoughts.

Get a FREE t-shirt when you ask your first question.
We believe in human intelligence. Our moderation policy strictly prohibits the use of LLM content in our Q&A threads.
Also...offering my thoughts
...
km1039> My company uses IE for the same reasons that there are so many problems with IE. Its available to everyone yet everyone uses it so its a great target for adware, spyware, etc.
km1039, Don't get me wrong here - I am not telling you how to do your job but regarding your company's commitment to IE perhaps you should have a look at the following site:
http://www.anybrowser.org/campaign/
The quote they have from Tim Berners-Lee (the father of the WWW) is especially enlightening (copy follows):
"Anyone who slaps a 'this page is best viewed with Browser X' label on a Web page appears to be yearning for the bad old days, before the Web, when you had very little chance of reading a document written on another computer, another word processor, or another network."






EARN REWARDS FOR ASKING, ANSWERING, AND MORE.
Earn free swag for participating on the platform.
You can get the free version of zonealarm here:
http://www.zonelabs.com/store/content/company/products/znalm/freeDownload.jsp
This article describes some methods for removing it and in the bottom section describes what to do if your adware comes back.
http://www.comptechdoc.org/docs/ctdp/adremove/
This page talks about removal methods and how to identify the processes running on your machine.
http://www.comptechdoc.org/basic/internetscams/adware.html
Once you identify processes running that you think are adware, try finding and renaming the adware executable program stored on your hard drive. Once you are sure it was adware and caused your problems, delete it.
You will find that no program is "intelligent" enough to remove all adware. This is because these sleezy companies actually pay programmers to come up with new and unique ways to prevent the removal of these programs.

Get a FREE t-shirt when you ask your first question.
We believe in human intelligence. Our moderation policy strictly prohibits the use of LLM content in our Q&A threads.
Assuming that you have Norton Antivirus 2004 version, do the following:
1. Restart your computer.
2. Enter in "Safe Mode".
3. Do not open Internet Explorer. Go to Internet Explorer's Properties (right click on the desktop icon and choose Properties from the list) and delete the Temporary Internet Files and cookies.
4. Do a scan of your system directory (mentioned above).
5. After the scan is finished, delete the detected virused files. Norton Antivirus will fail to delete some of them.
6. Now open Windows Explorer. Make sure you are able to view hidden and system files.
7. Verify the list of infected files and get them deleted manualy in Windows Explorer.
8. Open your registry. Go to HKEY_LOCAL_MACHINE\SOFTWAR
9. All done.
10. Some paranoic users can run again a virus scan of the system directory, to ensure that all infected file were deleted.






EARN REWARDS FOR ASKING, ANSWERING, AND MORE.
Earn free swag for participating on the platform.
i was having problems with that on my personal pc...i went out and bought the nortons clean sweep and spy sweeper.....ran the clean sweep removing all viruses and the search for .dll's .exe .com .bat files that was left behind after sweeping....cleanned it on the highiest setting...if i remember it was like it wrote over it 10 times.....then ran the spy sweeper and had it remove the traces and files......this worked for me.....not all the free adaware....spyware files are safe they do have trojans on the and duplicate files so it would be like a worm....like they stated above clean sys file and regsitry......also employees can bring in disk or cd's that could have some infected files.....i hope this will give you some ideas.....
Security
--
Questions
--
Followers
Top Experts
Security is the protection of information systems from theft or damage to the hardware, the software, and the information on them, as well as from disruption or misdirection of the services they provide. The main goal of security is protecting assets, and an asset is anything of value and worthy of protection. Information Security is a discipline of protecting information assets from threats through safeguards to achieve the objectives of confidentiality, integrity, and availability or CIA for short. On the other hand, disclosure, alteration, and disruption (DAD) compromise the security objectives.