Site Search:
 
Speak Korean Now!
Teach English Abroad and Get Paid to see the World!
Korean Job Discussion Forums Forum Index Korean Job Discussion Forums
"The Internet's Meeting Place for ESL/EFL Teachers from Around the World!"
 
 FAQFAQ   SearchSearch   MemberlistMemberlist   UsergroupsUsergroups   RegisterRegister 
 ProfileProfile   Log in to check your private messagesLog in to check your private messages   Log inLog in 

Spyware
Goto page 1, 2  Next
 
Post new topic   Reply to topic    Korean Job Discussion Forums Forum Index -> Technology Forum
View previous topic :: View next topic  
Author Message
mithridates



Joined: 03 Mar 2003
Location: President's office, Korean Space Agency

PostPosted: Thu Jan 27, 2005 8:00 pm    Post subject: Spyware Reply with quote

The computer at my new company was a wreck. I uninstalled all the useless programs and weird gizmos the person before me had put on, installed ZoneAlarm and Adaware. There was a really annoying toolbar that kept on downloading things on its own so I uninstalled that and found an extra 300 processes on Adaware that it had made. Finally I got rid of all of that but...
Every time I use IE these ads keep on popping up. Every five minutes or so I see that some 30 or so processes have come from nowhere and are called 'Flashenhancer IBO' if my memory serves. I'm not sure how they're getting in. Is there something I can do, or should I switch to Firefox? Everydavid just mentioned that when he uninstalled it just about everything got deleted from his hard drive though...
Back to top
View user's profile Send private message Visit poster's website
Demophobe



Joined: 17 May 2004

PostPosted: Thu Jan 27, 2005 8:18 pm    Post subject: Reply with quote

Uninstalled Firfox and lost all his data? Hmmm....that's not to do with Firefox. I recon there's a story there somewhere.

Anyhow, to do with your worry....yes, get Firefox. Besides, even if the tale is true, there will never be a time you will want to uninstall it. Wink

The problem with your IE sounds like a hijack or an exploit. What kinf od AV does the machine have?

Run this program :

http://www.spychecker.com/program/hijackthis.html

However, don't run it and delete EVERY entry on the list. The program isn't for the total novice, which I don't think you are anyways, but look carefully at the processes it picks up/out. Some of them will be lrgit processes and you won't want to lose them.

Run it and see what you get....you might get some positive hits.

Good luck...I will post back aftter work.

If you can....please post the actual process name....
Back to top
View user's profile Send private message
Sage Monkey



Joined: 01 Nov 2004

PostPosted: Thu Jan 27, 2005 8:49 pm    Post subject: Reply with quote

Also try going to www.majorgeeks.com as they have lots of information and scanner downloads there which you could use.
Back to top
View user's profile Send private message
mithridates



Joined: 03 Mar 2003
Location: President's office, Korean Space Agency

PostPosted: Thu Jan 27, 2005 8:53 pm    Post subject: Reply with quote

Well, I've installed Firefox so perhaps they won't come back anymore. Here are the results of the scan.










Ad-Aware SE Build 1.05
Logfile Created on:2005�� 1�� 28�� �ݿ��� ���� 1:30:08
Created with Ad-Aware SE Personal, free for private use.
Using definitions file:SE1R26 25.01.2005
��������������������������������������������������?

References detected during the scan:
��������������������������������������?
FlashenhancerBHO(TAC index:7):16 total references
MRU List(TAC index:0):1 total references
Tracking Cookie(TAC index:3):2 total references
��������������������������������������?

Ad-Aware SE Settings
===========================
Set : Search for negligible risk entries
Set : Safe mode (always request confirmation)
Set : Scan active processes
Set : Scan registry
Set : Deep-scan registry
Set : Scan my IE Favorites for banned URLs
Set : Scan my Hosts file

Extended Ad-Aware SE Settings
===========================
Set : Unload recognized processes & modules during scan
Set : Scan registry for all users instead of current user only
Set : Always try to unload modules before deletion
Set : During removal, unload Explorer and IE if necessary
Set : Let Windows remove files in use at next reboot
Set : Delete quarantined objects after restoring
Set : Include basic Ad-Aware settings in log file
Set : Include additional Ad-Aware settings in log file
Set : Include reference summary in log file
Set : Include alternate data stream details in log file
Set : Play sound at scan completion if scan locates critical objects


2005-01-28 ���� 1:30:08 - Scan started. (Smart mode)

Listing running processes
��������������������������������������

#:1 [smss.exe]
FilePath : \SystemRoot\System32\
ProcessID : 552
ThreadCreationTime : 2005-01-27 ���� 10:11:01
BasePriority : Normal


#:2 [csrss.exe]
FilePath : \??\C:\WINDOWS\system32\
ProcessID : 632
ThreadCreationTime : 2005-01-27 ���� 10:11:02
BasePriority : Normal


#:3 [winlogon.exe]
FilePath : \??\C:\WINDOWS\system32\
ProcessID : 656
ThreadCreationTime : 2005-01-27 ���� 10:11:03
BasePriority : High


#:4 [services.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 700
ThreadCreationTime : 2005-01-27 ���� 10:11:03
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft�� Windows�� Operating System
CompanyName : Microsoft Corporation
FileDescription : Services and Controller app
InternalName : services.exe
LegalCopyright : �� Microsoft Corporation. All rights reserved.
OriginalFilename : services.exe

#:5 [lsass.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 712
ThreadCreationTime : 2005-01-27 ���� 10:11:03
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft�� Windows�� Operating System
CompanyName : Microsoft Corporation
FileDescription : LSA Shell (Export Version)
InternalName : lsass.exe
LegalCopyright : �� Microsoft Corporation. All rights reserved.
OriginalFilename : lsass.exe

#:6 [svchost.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 868
ThreadCreationTime : 2005-01-27 ���� 10:11:04
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft�� Windows�� Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : �� Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe

#:7 [svchost.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 944
ThreadCreationTime : 2005-01-27 ���� 10:11:04
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft�� Windows�� Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : �� Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe

#:8 [svchost.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 1036
ThreadCreationTime : 2005-01-27 ���� 10:11:04
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft�� Windows�� Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : �� Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe

#:9 [svchost.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 1084
ThreadCreationTime : 2005-01-27 ���� 10:11:04
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft�� Windows�� Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : �� Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe

#:10 [svchost.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 1244
ThreadCreationTime : 2005-01-27 ���� 10:11:05
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft�� Windows�� Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : �� Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe

#:11 [spoolsv.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 1484
ThreadCreationTime : 2005-01-27 ���� 10:11:06
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft�� Windows�� Operating System
CompanyName : Microsoft Corporation
FileDescription : Spooler SubSystem App
InternalName : spoolsv.exe
LegalCopyright : �� Microsoft Corporation. All rights reserved.
OriginalFilename : spoolsv.exe

#:12 [explorer.exe]
FilePath : C:\WINDOWS\
ProcessID : 1812
ThreadCreationTime : 2005-01-27 ���� 10:11:13
BasePriority : Normal
FileVersion : 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 6.00.2900.2180
ProductName : Microsoft�� Windows�� Operating System
CompanyName : Microsoft Corporation
FileDescription : Windows Explorer
InternalName : explorer
LegalCopyright : �� Microsoft Corporation. All rights reserved.
OriginalFilename : EXPLORER.EXE

#:13 [ahnsdsv.exe]
FilePath : C:\Program Files\Ahnlab\Smart Update Utility\
ProcessID : 1952
ThreadCreationTime : 2005-01-27 ���� 10:11:14
BasePriority : Normal
FileVersion : 5, 3, 0, 158
ProductVersion : 5, 4, 0, 0
ProductName : Smart Update Utility
CompanyName : AhnLab, Inc.
FileDescription : AhnSD Service
InternalName : AhnSD
LegalCopyright : Copyright (c) 1988-2004 AhnLab, Inc.
OriginalFilename : AhnSDsv.exe

#:14 [rundll32.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 256
ThreadCreationTime : 2005-01-27 ���� 10:11:15
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft�� Windows�� Operating System
CompanyName : Microsoft Corporation
FileDescription : Run a DLL as an App
InternalName : rundll
LegalCopyright : �� Microsoft Corporation. All rights reserved.
OriginalFilename : RUNDLL.EXE

#:15 [netpia.exe]
FilePath : C:\Program files\koreandoumi1.0\
ProcessID : 272
ThreadCreationTime : 2005-01-27 ���� 10:11:15
BasePriority : Normal
FileVersion : 1.5a
ProductVersion : 1.5a
ProductName : �ѱ����ͳ��ּҵ����
CompanyName : Netpia.com, Inc.
FileDescription : �ѱ����ͳ��ּҵ����
InternalName : �ѱ����ͳ��ּҵ����
LegalCopyright : Copyright (C) Netpia 2003 - 2004
OriginalFilename : Netpia.exe

#:16 [turboagent.exe]
FilePath : C:\Program Files\TurboPlayer\
ProcessID : 284
ThreadCreationTime : 2005-01-27 ���� 10:11:15
BasePriority : High
FileVersion : 1, 3, 6, 6
ProductVersion : 1, 3, 6, 6
ProductName : TURBO AGENT
CompanyName : FutureValley
FileDescription : TURBO AGENT
InternalName : TURBO AGENT
LegalCopyright : Copyright (C) 2002 FutureValley. Inc.
OriginalFilename : TurboAgent.EXE

#:17 [ahnsd.exe]
FilePath : C:\Program Files\Ahnlab\Smart Update Utility\
ProcessID : 312
ThreadCreationTime : 2005-01-27 ���� 10:11:15
BasePriority : Normal
FileVersion : 5, 3, 0, 23
ProductVersion : 5, 4, 0, 0
ProductName : Smart Update Utility
CompanyName : AhnLab, Inc.
FileDescription : AhnSD
InternalName : AhnSD
LegalCopyright : Copyright (c) 1988-2004 AhnLab, Inc.
OriginalFilename : AhnSD.exe

#:18 [ctfmon.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 412
ThreadCreationTime : 2005-01-27 ���� 10:11:15
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft�� Windows�� Operating System
CompanyName : Microsoft Corporation
FileDescription : CTF Loader
InternalName : CTFMON
LegalCopyright : �� Microsoft Corporation. All rights reserved.
OriginalFilename : CTFMON.EXE

#:19 [googledesktop.exe]
FilePath : C:\Program Files\Google\Google Desktop Search\
ProcessID : 428
ThreadCreationTime : 2005-01-27 ���� 10:11:16
BasePriority : Normal


#:20 [[email protected]]
FilePath : C:\Program Files\SETI@home\
ProcessID : 436
ThreadCreationTime : 2005-01-27 ���� 10:11:16
BasePriority : Idle
FileVersion : 3.08
ProductVersion : 3.08
ProductName : SETI@home
CompanyName : University of California, Berkeley
FileDescription : SETI@home
InternalName : SETI@home
LegalCopyright : Copyright �� 1999-2000
LegalTrademarks :
OriginalFilename : [email protected]
Comments :

#:21 [acrotray.exe]
FilePath : C:\Program Files\Adobe\Acrobat 5.0\Distillr\
ProcessID : 512
ThreadCreationTime : 2005-01-27 ���� 10:11:19
BasePriority : Normal
FileVersion : 5, 0, 0, 0
ProductVersion : 5, 0, 0, 0
ProductName : AcroTray - Adobe Acrobat Distiller helper application.
CompanyName : Adobe Systems Inc.
FileDescription : AcroTray
InternalName : AcroTray
LegalCopyright : Copyright �� 2001
OriginalFilename : AcroTray.exe

#:22 [v3p3at.exe]
FilePath : C:\PROGRA~1\Ahnlab\V3\
ProcessID : 676
ThreadCreationTime : 2005-01-27 ���� 10:11:21
BasePriority : Normal
FileVersion : 5, 0, 0, 153
ProductVersion : 5, 0, 0, 152
ProductName : V3Pro 2002 Deluxe
CompanyName : AhnLab, Inc.
FileDescription : POP3 realtime scan module.
InternalName : V3P3AT
LegalCopyright : Copyright (c) 1998-2003 AhnLab, Inc.
OriginalFilename : V3P3AT.exe

#:23 [cap4lak.exe]
FilePath : C:\WINDOWS\system32\spool\drivers\w32x86\3\
ProcessID : 780
ThreadCreationTime : 2005-01-27 ���� 10:11:21
BasePriority : Normal
FileVersion : 1.00.0.009
ProductVersion : 1.00.0.009
ProductName : Canon Advanced Printing Technology
CompanyName : CANON INC.
FileDescription : CAP4 PSW Launcher
InternalName : CAP4LAK
LegalCopyright : Copyright CANON INC. 2003
OriginalFilename : CAP4LAK.EXE

#:24 [cmwir.exe]
FilePath : C:\Program Files\Wireless\Client Manager\
ProcessID : 716
ThreadCreationTime : 2005-01-27 ���� 10:11:21
BasePriority : Normal


#:25 [cap4rsk.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 760
ThreadCreationTime : 2005-01-27 ���� 10:11:22
BasePriority : Normal


#:26 [cap4swk.exe]
FilePath : C:\WINDOWS\system32\spool\drivers\w32x86\3\
ProcessID : 1416
ThreadCreationTime : 2005-01-27 ���� 10:11:31
BasePriority : Normal
FileVersion : 1.00.0.009
ProductVersion : 1.00.0.009
ProductName : Canon Advanced Printing Technology
CompanyName : CANON INC.
FileDescription : Canon Advanced Printing Technology Printer Status Window
InternalName : CAP4SWK
LegalCopyright : Copyright CANON INC. 2003
OriginalFilename : CAP4SWK.EXE

#:27 [alg.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 2076
ThreadCreationTime : 2005-01-27 ���� 10:11:48
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft�� Windows�� Operating System
CompanyName : Microsoft Corporation
FileDescription : Application Layer Gateway Service
InternalName : ALG.exe
LegalCopyright : �� Microsoft Corporation. All rights reserved.
OriginalFilename : ALG.exe

#:28 [googledesktopindex.exe]
FilePath : C:\Program Files\Google\Google Desktop Search\
ProcessID : 2928
ThreadCreationTime : 2005-01-27 ���� 10:12:11
BasePriority : Normal


#:29 [googledesktopcrawl.exe]
FilePath : C:\Program Files\Google\Google Desktop Search\
ProcessID : 2968
ThreadCreationTime : 2005-01-27 ���� 10:12:11
BasePriority : Normal


#:30 [excel.exe]
FilePath : C:\Program Files\Microsoft Office\OFFICE11\
ProcessID : 3028
ThreadCreationTime : 2005-01-27 ���� 10:16:40
BasePriority : Normal


#:31 [monsvcnt.exe]
FilePath : C:\PROGRA~1\Ahnlab\V3\
ProcessID : 3108
ThreadCreationTime : 2005-01-27 ���� 4:16:20
BasePriority : Normal
FileVersion : 5, 0, 0, 183
ProductVersion : 5, 0, 1, 0
ProductName : V3Pro 2002 Deluxe
CompanyName : Ahnlab, Inc.
FileDescription : MonSvcNT
InternalName : MonSvcNT
LegalCopyright : Copyright (C) 1988 - 2003 Ahnlab, Inc.
OriginalFilename : MonSvcNT.exe

#:32 [iexplore.exe]
FilePath : C:\Program Files\Internet Explorer\
ProcessID : 2372
ThreadCreationTime : 2005-01-28 ���� 3:26:59
BasePriority : Normal
FileVersion : 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 6.00.2900.2180
ProductName : Microsoft�� Windows�� Operating System
CompanyName : Microsoft Corporation
FileDescription : Internet Explorer
InternalName : iexplore
LegalCopyright : Copyright (C) Microsoft Corporation. 1981-2001
OriginalFilename : IEXPLORE.EXE

#:33 [ad-aware.exe]
FilePath : C:\Program Files\Lavasoft\Ad-Aware SE Personal\
ProcessID : 3728
ThreadCreationTime : 2005-01-28 ���� 4:29:23
BasePriority : Normal
FileVersion : 6.2.0.206
ProductVersion : VI.Second Edition
ProductName : Lavasoft Ad-Aware SE
CompanyName : Lavasoft Sweden
FileDescription : Ad-Aware SE Core application
InternalName : Ad-Aware.exe
LegalCopyright : Copyright �� Lavasoft Sweden
OriginalFilename : Ad-Aware.exe
Comments : All Rights Reserved

Memory scan result:
��������������������������������������
New critical objects: 0
Objects found so far: 0


Started registry scan
��������������������������������������

FlashenhancerBHO Object Recognized!
Type : Regkey
Data :
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : unawareobj.unawareobj.1

FlashenhancerBHO Object Recognized!
Type : RegValue
Data :
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : unawareobj.unawareobj.1
Value :

FlashenhancerBHO Object Recognized!
Type : Regkey
Data :
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : unawareobj.unawareobj

FlashenhancerBHO Object Recognized!
Type : RegValue
Data :
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : unawareobj.unawareobj
Value :

FlashenhancerBHO Object Recognized!
Type : Regkey
Data :
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : typelib\{48e832ec-b061-49e2-bbc1-ac818623b742}

FlashenhancerBHO Object Recognized!
Type : Regkey
Data :
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : interface\{890089b7-b385-442f-97b6-99060e8bd08f}

FlashenhancerBHO Object Recognized!
Type : RegValue
Data :
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : interface\{890089b7-b385-442f-97b6-99060e8bd08f}
Value :

FlashenhancerBHO Object Recognized!
Type : Regkey
Data :
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : interface\{890089b7-b385-442f-97b6-99060e8bd08f}\proxystubclsid32

FlashenhancerBHO Object Recognized!
Type : RegValue
Data :
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : interface\{890089b7-b385-442f-97b6-99060e8bd08f}\proxystubclsid32
Value :

FlashenhancerBHO Object Recognized!
Type : Regkey
Data :
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : typelib\{48e832ec-b061-49e2-bbc1-ac818623b742}\1.0

FlashenhancerBHO Object Recognized!
Type : RegValue
Data :
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : typelib\{48e832ec-b061-49e2-bbc1-ac818623b742}\1.0
Value :

FlashenhancerBHO Object Recognized!
Type : Regkey
Data :
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : interface\{890089b7-b385-442f-97b6-99060e8bd08f}\typelib

FlashenhancerBHO Object Recognized!
Type : RegValue
Data :
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : interface\{890089b7-b385-442f-97b6-99060e8bd08f}\typelib
Value :

FlashenhancerBHO Object Recognized!
Type : RegValue
Data :
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : interface\{890089b7-b385-442f-97b6-99060e8bd08f}\typelib
Value : Version

FlashenhancerBHO Object Recognized!
Type : Regkey
Data :
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : interface\{890089b7-b385-442f-97b6-99060e8bd08f}\proxystubclsid

FlashenhancerBHO Object Recognized!
Type : RegValue
Data :
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : interface\{890089b7-b385-442f-97b6-99060e8bd08f}\proxystubclsid
Value :

Registry Scan result:
��������������������������������������
New critical objects: 16
Objects found so far: 16


Started deep registry scan
��������������������������������������

Deep registry scan result:
��������������������������������������
New critical objects: 0
Objects found so far: 16


Started Tracking Cookie scan
��������������������������������������


Tracking Cookie Object Recognized!
Type : IECache Entry
Data : �п�@fastclick[1].txt
Category : Data Miner
Comment : Hits:10
Value : Cookie:�п�@fastclick.net/
Expires : 2007-01-18 ���� 1:16:22
LastSync : Hits:10
UseCount : 0
Hits : 10

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : �п�@z1.adserver[1].txt
Category : Data Miner
Comment : Hits:6
Value : Cookie:�п�@z1.adserver.com/
Expires : 2006-01-28 ���� 1:29:20
LastSync : Hits:6
UseCount : 0
Hits : 6

Tracking cookie scan result:
��������������������������������������
New critical objects: 2
Objects found so far: 18



Deep scanning and examining files...
��������������������������������������

Disk Scan Result for C:\WINDOWS
��������������������������������������
New critical objects: 0
Objects found so far: 18

Disk Scan Result for C:\WINDOWS\system32
��������������������������������������
New critical objects: 0
Objects found so far: 18

Disk Scan Result for C:\DOCUME~1\�п�.COM\LOCALS~1\Temp\
��������������������������������������
New critical objects: 0
Objects found so far: 18


Scanning Hosts file......
Hosts file location:"C:\WINDOWS\system32\drivers\etc\hosts".
����������������������������������������������������������������������������

Hosts file scan result:
��������������������������������������
1 entries scanned.
New critical objects:0
Objects found so far: 18



MRU List Object Recognized!
Location: : S-1-5-21-1801674531-507921405-1343024091-1003\software\google\navclient\1.1\history
Description : list of recently used search terms in the google toolbar



Performing conditional scans...
��������������������������������������

Conditional scan result:
��������������������������������������
New critical objects: 0
Objects found so far: 19

���� 1:33:37 Scan Complete

Summary Of This Scan
��������������������������������������
Total scanning time:00:03:28.499
Objects scanned:63482
Objects identified:18
Objects ignored:0
New critical objects:18
Back to top
View user's profile Send private message Visit poster's website
Sage Monkey



Joined: 01 Nov 2004

PostPosted: Thu Jan 27, 2005 9:06 pm    Post subject: Reply with quote



Last edited by Sage Monkey on Thu Mar 29, 2007 10:01 am; edited 1 time in total
Back to top
View user's profile Send private message
Demophobe



Joined: 17 May 2004

PostPosted: Thu Jan 27, 2005 10:51 pm    Post subject: Reply with quote

The rest are fine. I would call that a pretty clean scan. I take it adaware got rid of all that flashenhancer stuuf? If so, you are good to go, outside of perhaps having a couple services too many running.
Back to top
View user's profile Send private message
Hollywoodaction



Joined: 02 Jul 2004

PostPosted: Sat Jan 29, 2005 6:36 am    Post subject: Reply with quote

Looks like you've got a Korean trojan on your system (netpia.exe is a file created by the Netzzak.a trojan).
http://fr.trendmicro-europe.com/smb/security_info/ve_detail.php?Vname=TROJ_NETZZAK.A

You need to download Ad-spider. It gets rid of most of the Korean spyware , which ad-aware often can't get.

By the way, did you know your computer is searching for aliens? You've got "SETI at home" installed. You might want to get rid of that if you want to free up some resources.
Back to top
View user's profile Send private message
MixtecaMike



Joined: 24 Nov 2003
Location: 3rd Largest Train Station in Korea

PostPosted: Sat Jan 29, 2005 3:58 pm    Post subject: Reply with quote

Hollywoodaction wrote:
By the way, did you know your computer is searching for aliens? You've got "SETI at home" installed. You might want to get rid of that if you want to free up some resources.

Unless they're aliens come here to lower the morals of Korean girls, very important to find those ones, LOL.
Back to top
View user's profile Send private message
phaedrus



Joined: 13 Nov 2003
Location: I'm comin' to get ya.

PostPosted: Sat Jan 29, 2005 5:57 pm    Post subject: Reply with quote

Hollywoodaction wrote:
Looks like you've got a Korean trojan on your system (netpia.exe is a file created by the Netzzak.a trojan).
http://fr.trendmicro-europe.com/smb/security_info/ve_detail.php?Vname=TROJ_NETZZAK.A

You need to download Ad-spider. It gets rid of most of the Korean spyware , which ad-aware often can't get.

By the way, did you know your computer is searching for aliens? You've got "SETI at home" installed. You might want to get rid of that if you want to free up some resources.


Ad-Spider is showing gibberish on my computer instead of English or Korean. I have Korean language settings on my computer. Anyone know how to fix this?
Back to top
View user's profile Send private message
mithridates



Joined: 03 Mar 2003
Location: President's office, Korean Space Agency

PostPosted: Sat Jan 29, 2005 6:12 pm    Post subject: Reply with quote

Are you sure the Unicode is set to Korean as well?
Back to top
View user's profile Send private message Visit poster's website
Sage Monkey



Joined: 01 Nov 2004

PostPosted: Sat Jan 29, 2005 8:43 pm    Post subject: Reply with quote



Last edited by Sage Monkey on Thu Mar 29, 2007 10:02 am; edited 1 time in total
Back to top
View user's profile Send private message
phaedrus



Joined: 13 Nov 2003
Location: I'm comin' to get ya.

PostPosted: Sat Jan 29, 2005 11:21 pm    Post subject: Reply with quote

mithridates wrote:
Are you sure the Unicode is set to Korean as well?


That worked.

I got to the pay menu, and stopped there, though. I'm not sure if it wanted a fee or a donation. I like freeware.
Back to top
View user's profile Send private message
Hollywoodaction



Joined: 02 Jul 2004

PostPosted: Mon Jan 31, 2005 12:16 am    Post subject: Reply with quote

phaedrus wrote:
mithridates wrote:
Are you sure the Unicode is set to Korean as well?


That worked.

I got to the pay menu, and stopped there, though. I'm not sure if it wanted a fee or a donation. I like freeware.


There are two different menus. Click on the other option once the scan is done so you don't have 900 won to delete registry entries (which you can get rid of with other software for free once the spyware is deleted).
Back to top
View user's profile Send private message
Holyjoe



Joined: 03 Mar 2003
Location: Away for a cuppa

PostPosted: Fri Jun 17, 2005 9:07 pm    Post subject: Reply with quote

Hollywoodaction wrote:
Looks like you've got a Korean trojan on your system (netpia.exe is a file created by the Netzzak.a trojan).
http://fr.trendmicro-europe.com/smb/security_info/ve_detail.php?Vname=TROJ_NETZZAK.A

You need to download Ad-spider. It gets rid of most of the Korean spyware , which ad-aware often can't get.

By the way, did you know your computer is searching for aliens? You've got "SETI at home" installed. You might want to get rid of that if you want to free up some resources.


Thought I'd say 'thanks' for the advice in this post about using Ad-spider. I'd had a browser hijack from amir.co.kr plus a ton of Korean pop-ups for months after the missus downloaded some stuff onto my computer and I'd been at a loss as to how to get shot of it.

I downloaded Ad-spider after reading this post and everything's fine now Smile
Back to top
View user's profile Send private message Visit poster's website
Hollywoodaction



Joined: 02 Jul 2004

PostPosted: Sat Jun 18, 2005 1:28 am    Post subject: Reply with quote

Actually, I deleted ad-spider. AVG Anti-virus detects a trojan in that software. That may be why it isn't very popular anymore. I'm using PC-Clean now.

Last edited by Hollywoodaction on Sat Jun 18, 2005 1:43 am; edited 4 times in total
Back to top
View user's profile Send private message
Display posts from previous:   
Post new topic   Reply to topic    Korean Job Discussion Forums Forum Index -> Technology Forum All times are GMT - 8 Hours
Goto page 1, 2  Next
Page 1 of 2

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum


This page is maintained by the one and only Dave Sperling.
Contact Dave's ESL Cafe
Copyright © 2018 Dave Sperling. All Rights Reserved.

Powered by phpBB © 2001, 2002 phpBB Group

TEFL International Supports Dave's ESL Cafe
TEFL Courses, TESOL Course, English Teaching Jobs - TEFL International