New User? Need help? Click here to register for free! Registering removes the advertisements.

Computer Cops
image image image image image image image image
Donations
If you found this site helpful, please donate to help keep it online.
image
Prime Choice
· Head Lines
· Advisories (All)
· Dnld of the Week!
· CCSP News Ltrs
· Find a Cure!

· Ian T's (AR 20)
· Marcia's (QA2)
· Bill G's (CO8)
· Paul's (AR 5)

· Ian T's Archive
· Marcia's Archive
· Bill G's Archive
· Paul's Archive
image
Security Central
· Home
· Wireless
· Bookmarks
· CLSID
· Columbia
· Community
· Downloads
· Encyclopedia
· Feedback (send)
· Forums
· Gallery
· Giveaways
· HijackThis
· Journal
· Members List
· My Downloads
· PremChat
· Premium
· Private Messages
· Proxomitron
· Quizz
· Recommend Us
· RegChat
· Reviews
· Search (Topics)
· Sections
· Software
· Statistics
· Stories Archive
· Submit News
· Surveys
· Top
· Topics
· Web Links
· Your Account
image
CCSP Toolkit
· Email Virus Scan
· UDP Port Scanner
· TCP Port Scanner
· Trojan TCP Scan
· Reveal Your IP
· Algorithms
· Whois
· nmap port scanner
· IPs Banned [?]
image
Survey
How much can you give to keep Computer Cops online?

$10 up to $25 per year?
$25 up to $50 per year?
$10 up to $25 per month?
$25 up to $50 per month?
More than $50 per year?
More than $50 per month?
One time only?
Other (please comment)



Results
Polls

Votes: 369
Comments: 9
image
Translate
English German French
Italian Portuguese Spanish
Chinese Greek Russian
image
 Forum FAQForum FAQ   SearchSearch   UsergroupsUsergroups   ProfileProfile   Login to check your private messagesLogin to check your private messages   LoginLogin 

got it and can't get rid of it

 
Post new topic   Reply to topic       Computer Cops Forum Index -> Virus - Prevention
View previous topic :: View next topic  
Author Message
crusader

Cadet
Cadet



Joined: Mar 18, 2004
Posts: 2
Location: USA

PostPosted: Thu Mar 18, 2004 11:12 pm    Post subject: got it and can't get rid of it
Reply with quote

I did a dumb thing . A really dumb thing . I downloaded a FREE emotes( yea right) and I got a boat load of junk and crap I can't get rid of. I hate the popnav that comes up now instead of my Yahoo home page. and the IE search the internet and party poker, 3 new Icons on my desk top. HOw do I get rid of these. Somehow my ad aware and spy nuker fell asleep. I am not very computer literate and will need a lot of help. HELP
Back to top
View users profile Send private message
_lueychun

Sergeant
Sergeant



Joined: Mar 05, 2004
Posts: 109
Location: Singapore

PostPosted: Fri Mar 19, 2004 6:35 am    Post subject:
Reply with quote

Please do this.
Download 'Hijack This!'. http://www.spywareinfo.com/~merijn/files/hijackthis.zip
Unzip to a convenient permanent folder, double click HijackThis.exe, and hit "Scan".

When the scan is finished, the "Scan" button will change into a "Save Log" button.
Press that, save the log, Ctrl-A to Select All, and copy its contents here. Most of what it lists will be harmless or even essential, don't fix anything yet.

_________________
"Want to make your computer go really fast? Throw it out of a window." --Anon
Back to top
View users profile Send private message
PhilL_2oo4

Cadet
Cadet



Joined: Apr 04, 2004
Posts: 3
Location: Australia

PostPosted: Sun Apr 04, 2004 9:33 pm    Post subject:
Reply with quote

Hey i got the exactly the same problem and its fuckin annoying, i dont what you said and got the log file from hijack this, here it is

C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\svchost.exe
C:\Program Files\CursorXP\CursorXP.exe
c:\program files\warcraft iii\war3.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Hijack This\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://about-blank.ws/page/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://about-blank.ws/page/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://about-blank.ws/page/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://about-blank.ws
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://about-blank.ws
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://about-blank.ws/page/
R1 - HKLM\Software\Microsoft\Internet Explorer,SearchURL = http://about-blank.ws/page/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://about-blank.ws
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://about-blank.ws/page/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://about-blank.ws/page/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://about-blank.ws
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://about-blank.ws/page/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://213.159.118.226/sp.php
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
R3 - Default URLSearchHook is missing
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe
O4 - HKLM\..\Run: [ccRegVfy] C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe
O4 - HKLM\..\Run: [ElbyCheckElbyCDFL] "C:\Program Files\Elaborate Bytes\CloneCD\ElbyCheck.exe" /L ElbyCDFL
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Network Service] C:\WINDOWS\svchost.exe -sr -1
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [CursorXP] C:\Program Files\CursorXP\CursorXP.exe
O4 - HKCU\..\Run: [Network Service] C:\WINDOWS\svchost.exe -sr -1
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O13 - DefaultPrefix: http://about-blank.ws/page/
O13 - WWW Prefix: http://about-blank.ws/page/
O16 - DPF: Win32 Classes - file://C:\WINDOWS\Java\classes\win32ie4.cab
O16 - DPF: {10000000-1000-0000-1000-000000000000} - file://C:\Program Files\Internet Explorer\en.exe
O16 - DPF: {11111111-1111-1111-1111-111111111111} - mhtml:file://C:NXSFT.MHT!http://66.117.38.54:80/iex/ofile.exe?url=http://66.117.38.54:80/dexAU630.exe
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200...taller.exe
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Me...Client.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shoc...wflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{52115F95-C991-4ED3-98F6-D19CFB6D3674}: NameServer = 203.194.56.150 203.194.27.57
O19 - User stylesheet: C:\WINDOWS\system32\ea441.t9n

These were the results any chance you can help me out and tell me whats happening
Back to top
View users profile Send private message Send email
_lueychun

Sergeant
Sergeant



Joined: Mar 05, 2004
Posts: 109
Location: Singapore

PostPosted: Mon Apr 05, 2004 8:41 am    Post subject:
Reply with quote

No vulgar language, please. And could you please start a new thread on your own, post your HijackThis log there and message me. i will attend to you as soon as possible.
_________________
"Want to make your computer go really fast? Throw it out of a window." --Anon
Back to top
View users profile Send private message
norsky

Cadet
Cadet



Joined: Apr 07, 2004
Posts: 1
Location: USA

PostPosted: Wed Apr 07, 2004 1:44 pm    Post subject:
Reply with quote

I, too, am having the same problem. I have deleted the trojan files which seem to be responsible for this problem from my computer. The creation of icons on my desktop and spontaneous opening of internet explorer has been prevented. However, I am not able to remove the message about Party Poker at the top of every webpage that I visit after typing in the web address. If I only click on old pages in my history, I avoid this problem, but obviously I would like to be able to remove the party poker advertisement from the pages that I manually try to visit. Please help!!
Thank you so much for any input that you may have to share!
Back to top
View users profile Send private message Visit posters website
Display posts from previous:   
Post new topic   Reply to topic       Computer Cops Forum Index -> Virus - Prevention All times are GMT - 5 Hours
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum


Powered by phpBB 2.0.8a © 2001 phpBB Group

Version 2.0.6 of PHP-Nuke Port by Tom Nitzschner © 2002 www.toms-home.com
Version 2.2 by Paul Laudanski © 2003-2004 Computer Cops