|
-
September 1st, 2004, 04:29 AM
#16
Registered User
I am seriously amazed that CWShredder is not fixing this. I have not been able to get a hold of merijn yet as hes in university now. As soon as I can talk to him or someone else who knows ill get back to you. What I can suggest is posting this log on Http://forums.spywareinfo.com There are a lot of experts there that may know something we dont know.
-
September 2nd, 2004, 05:43 AM
#17
Driver Terrier
no need for that pugs, just because you don't have the answer.
-
September 2nd, 2004, 05:56 AM
#18
Driver Terrier
 Originally Posted by jstut
ran all suggested programs in safe mode, updated all , deleted temp files/
cookies. .Logfile of HijackThis v1.98.2
C:\WINDOWS\TEMP\ NEGD.DAT
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.heretofind.com/show.php?id=18&q=%s
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = mk:@MSITStore: C:\spe\start.chm::/start.html#
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.heretofind.com/show.php?id=18&q=%s
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = mk:@MSITStore: C:\spe\start.chm::/start.html#
O4 - HKLM\..\Run: [Geek Superhero] C:\Program Files\Geek Superhero\GeekSuperhero.exe
O9 - Extra button: Corel Network monitor worker - {5ACAA515-6340-4501-9CF4-F587CB2A7AC8} - (no file)
O9 - Extra 'Tools' menuitem: Corel Network monitor worker - {5ACAA515-6340-4501-9CF4-F587CB2A7AC8} - (no file)
O9 - Extra button: Corel Network monitor worker - {05BAF5B4-69CB-4A89-B460-C1237BDE6D92} - (no file)
O9 - Extra 'Tools' menuitem: Corel Network monitor worker - {05BAF5B4-69CB-4A89-B460-C1237BDE6D92} - (no file)
O9 - Extra button: Popup Slapdown Options - {A1100DDB-B277-4CAA-A640-B299D79FE25E} - C:\PROGRAM FILES\GEEK SUPERHERO\GEEKSUPERHEROSLAPDOWN.DLL
O9 - Extra button: Bug Swatter Options - {99FEA1A2-7881-11D1-A9E2-00403320FCF2} - C:\PROGRAM FILES\GEEK SUPERHERO\GEEKSUPERHEROBUGSWAT.DLL (file missing)
O9 - Extra button: (no name) - {237AA178-C3BC-4f67-A8BB-D8BC14BA0B89} - (no file) (HKCU)
O13 - DefaultPrefix: http://www.heretofind.com/show.php?id=18&q=
O13 - WWW Prefix: http://www.heretofind.com/show.php?id=18&q=
O13 - Home Prefix: http://www.heretofind.com/show.php?id=18&q=
O13 - Mosaic Prefix: http://www.heretofind.com/show.php?id=18&q=
O13 - Gopher Prefix: http://www.heretofind.com/show.php?id=18&q=
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://activation.rr.com/install/download/tgctlcm.cab
.. keeps coming back. Attached hjt log
OK, the two files shown in bold - find them and delete them in safe mode. If they won't delete you will have to get a 98 boot disk and do it in dos.
Geeksuperhero .... not heard of this but it's supposed to stop hijacks cold - have you used it? the last 3 tools here are useful Judging by the file missing entry for geeksuperhero, it may have been corrupted.
Exactly how did you delete your temporary internet files?
Did you check in
c:\temp
c:\tmp
c:\windows\temp
c:\windows\tmp
as well for temp files?
There is also a folder called c:\windows\downloads which may have stuff in it.
Never, ever approach a computer saying or even thinking "I will just do this quickly."
-
September 3rd, 2004, 07:59 PM
#19
Thanks Pugs!!! I appreciate the assistance.
Thanks NooNoo I'll delve in.
PC is out for a couple of days....
Nuch Grats for your assistance.
-
September 9th, 2004, 10:04 AM
#20
Cleaned up for a while, but this thing keeps coming back.
Any suggestions?
Where else could this guy be coming from?
Running Zone Alarm, Spyguard, etc, but can't seem to stop the source form changing page.
-
September 9th, 2004, 10:18 AM
#21
Senior Member
 Originally Posted by jstut
Cleaned up for a while, but this thing keeps coming back.
Any suggestions?
Where else could this guy be coming from?
Running Zone Alarm, Spyguard, etc, but can't seem to stop the source form changing page.
How about the teatimer add-on from Spybot? would that not prevent the registry update?
-
September 9th, 2004, 04:11 PM
#22
Registered User
Check what services are running. Either post them here or google for the ones you dont know of. WIth coolweb a lot of times there is a service that installs it again.
-
September 9th, 2004, 08:10 PM
#23
 Originally Posted by Garak
How about the teatimer add-on from Spybot? would that not prevent the registry update?
Lost me there....teatimer?
-
September 9th, 2004, 08:12 PM
#24
 Originally Posted by pugs
Check what services are running. Either post them here or google for the ones you dont know of. WIth coolweb a lot of times there is a service that installs it again.
Little assist. When you say "services".
-
September 10th, 2004, 05:26 AM
#25
Driver Terrier
jstut
Tea timer is part of spybot. Have you read this advice here?
Services are what starts up with windows - in windows ME you press ctrl, alt, del to view whats running in background. Having said that, some of these spyware apps hide themselves from there.
Go through your program files directory in safe mode with hidden and system files on. List the folders shown there.
Last edited by NooNoo; September 10th, 2004 at 05:28 AM.
-
September 10th, 2004, 09:25 AM
#26
Registered User
 Originally Posted by jstut
Cleaned up for a while, but this thing keeps coming back.
Any suggestions?
Where else could this guy be coming from?
Running Zone Alarm, Spyguard, etc, but can't seem to stop the source form changing page.
Besides all the great suggestions you have recieved, have you tried This yet? The 30 day trial is a full version. I have run into this about:blank on quite a few clients lately. By using this and the other suggestions I have cleaned them up in about 10 - 20 minutes. Cheers.
-
September 18th, 2004, 03:12 PM
#27
Driver Terrier
Similar Threads
-
By jackpot316 in forum Spyware & Antivirus - Security
Replies: 99
Last Post: March 24th, 2005, 05:55 AM
-
By Talonboy in forum Windows XP
Replies: 6
Last Post: September 20th, 2004, 08:21 PM
-
By molo in forum Spyware & Antivirus - Security
Replies: 9
Last Post: August 7th, 2004, 05:31 AM
-
By Zonie in forum Spyware & Antivirus - Security
Replies: 6
Last Post: July 20th, 2004, 09:38 AM
-
By Rhiannon777 in forum Spyware & Antivirus - Security
Replies: 15
Last Post: April 2nd, 2004, 10:36 PM
Posting Permissions
- You may not post new threads
- You may not post replies
- You may not post attachments
- You may not edit your posts
-
Forum Rules
|
|
Bookmarks