View previous topic :: View next topic |
Author |
Message |
mithridates

Joined: 03 Mar 2003 Location: President's office, Korean Space Agency
|
Posted: Thu Jan 27, 2005 8:00 pm Post subject: Spyware |
|
|
The computer at my new company was a wreck. I uninstalled all the useless programs and weird gizmos the person before me had put on, installed ZoneAlarm and Adaware. There was a really annoying toolbar that kept on downloading things on its own so I uninstalled that and found an extra 300 processes on Adaware that it had made. Finally I got rid of all of that but...
Every time I use IE these ads keep on popping up. Every five minutes or so I see that some 30 or so processes have come from nowhere and are called 'Flashenhancer IBO' if my memory serves. I'm not sure how they're getting in. Is there something I can do, or should I switch to Firefox? Everydavid just mentioned that when he uninstalled it just about everything got deleted from his hard drive though... |
|
Back to top |
|
 |
Demophobe

Joined: 17 May 2004
|
Posted: Thu Jan 27, 2005 8:18 pm Post subject: |
|
|
Uninstalled Firfox and lost all his data? Hmmm....that's not to do with Firefox. I recon there's a story there somewhere.
Anyhow, to do with your worry....yes, get Firefox. Besides, even if the tale is true, there will never be a time you will want to uninstall it.
The problem with your IE sounds like a hijack or an exploit. What kinf od AV does the machine have?
Run this program :
http://www.spychecker.com/program/hijackthis.html
However, don't run it and delete EVERY entry on the list. The program isn't for the total novice, which I don't think you are anyways, but look carefully at the processes it picks up/out. Some of them will be lrgit processes and you won't want to lose them.
Run it and see what you get....you might get some positive hits.
Good luck...I will post back aftter work.
If you can....please post the actual process name.... |
|
Back to top |
|
 |
Sage Monkey

Joined: 01 Nov 2004
|
Posted: Thu Jan 27, 2005 8:49 pm Post subject: |
|
|
Also try going to www.majorgeeks.com as they have lots of information and scanner downloads there which you could use. |
|
Back to top |
|
 |
mithridates

Joined: 03 Mar 2003 Location: President's office, Korean Space Agency
|
Posted: Thu Jan 27, 2005 8:53 pm Post subject: |
|
|
Well, I've installed Firefox so perhaps they won't come back anymore. Here are the results of the scan.
Ad-Aware SE Build 1.05
Logfile Created on:2005�� 1�� 28�� �ݿ��� ���� 1:30:08
Created with Ad-Aware SE Personal, free for private use.
Using definitions file:SE1R26 25.01.2005
��������������������������������������������������?
References detected during the scan:
��������������������������������������?
FlashenhancerBHO(TAC index:7):16 total references
MRU List(TAC index:0):1 total references
Tracking Cookie(TAC index:3):2 total references
��������������������������������������?
Ad-Aware SE Settings
===========================
Set : Search for negligible risk entries
Set : Safe mode (always request confirmation)
Set : Scan active processes
Set : Scan registry
Set : Deep-scan registry
Set : Scan my IE Favorites for banned URLs
Set : Scan my Hosts file
Extended Ad-Aware SE Settings
===========================
Set : Unload recognized processes & modules during scan
Set : Scan registry for all users instead of current user only
Set : Always try to unload modules before deletion
Set : During removal, unload Explorer and IE if necessary
Set : Let Windows remove files in use at next reboot
Set : Delete quarantined objects after restoring
Set : Include basic Ad-Aware settings in log file
Set : Include additional Ad-Aware settings in log file
Set : Include reference summary in log file
Set : Include alternate data stream details in log file
Set : Play sound at scan completion if scan locates critical objects
2005-01-28 ���� 1:30:08 - Scan started. (Smart mode)
Listing running processes
��������������������������������������
#:1 [smss.exe]
FilePath : \SystemRoot\System32\
ProcessID : 552
ThreadCreationTime : 2005-01-27 ���� 10:11:01
BasePriority : Normal
#:2 [csrss.exe]
FilePath : \??\C:\WINDOWS\system32\
ProcessID : 632
ThreadCreationTime : 2005-01-27 ���� 10:11:02
BasePriority : Normal
#:3 [winlogon.exe]
FilePath : \??\C:\WINDOWS\system32\
ProcessID : 656
ThreadCreationTime : 2005-01-27 ���� 10:11:03
BasePriority : High
#:4 [services.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 700
ThreadCreationTime : 2005-01-27 ���� 10:11:03
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft�� Windows�� Operating System
CompanyName : Microsoft Corporation
FileDescription : Services and Controller app
InternalName : services.exe
LegalCopyright : �� Microsoft Corporation. All rights reserved.
OriginalFilename : services.exe
#:5 [lsass.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 712
ThreadCreationTime : 2005-01-27 ���� 10:11:03
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft�� Windows�� Operating System
CompanyName : Microsoft Corporation
FileDescription : LSA Shell (Export Version)
InternalName : lsass.exe
LegalCopyright : �� Microsoft Corporation. All rights reserved.
OriginalFilename : lsass.exe
#:6 [svchost.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 868
ThreadCreationTime : 2005-01-27 ���� 10:11:04
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft�� Windows�� Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : �� Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
#:7 [svchost.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 944
ThreadCreationTime : 2005-01-27 ���� 10:11:04
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft�� Windows�� Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : �� Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
#:8 [svchost.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 1036
ThreadCreationTime : 2005-01-27 ���� 10:11:04
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft�� Windows�� Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : �� Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
#:9 [svchost.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 1084
ThreadCreationTime : 2005-01-27 ���� 10:11:04
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft�� Windows�� Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : �� Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
#:10 [svchost.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 1244
ThreadCreationTime : 2005-01-27 ���� 10:11:05
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft�� Windows�� Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : �� Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
#:11 [spoolsv.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 1484
ThreadCreationTime : 2005-01-27 ���� 10:11:06
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft�� Windows�� Operating System
CompanyName : Microsoft Corporation
FileDescription : Spooler SubSystem App
InternalName : spoolsv.exe
LegalCopyright : �� Microsoft Corporation. All rights reserved.
OriginalFilename : spoolsv.exe
#:12 [explorer.exe]
FilePath : C:\WINDOWS\
ProcessID : 1812
ThreadCreationTime : 2005-01-27 ���� 10:11:13
BasePriority : Normal
FileVersion : 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 6.00.2900.2180
ProductName : Microsoft�� Windows�� Operating System
CompanyName : Microsoft Corporation
FileDescription : Windows Explorer
InternalName : explorer
LegalCopyright : �� Microsoft Corporation. All rights reserved.
OriginalFilename : EXPLORER.EXE
#:13 [ahnsdsv.exe]
FilePath : C:\Program Files\Ahnlab\Smart Update Utility\
ProcessID : 1952
ThreadCreationTime : 2005-01-27 ���� 10:11:14
BasePriority : Normal
FileVersion : 5, 3, 0, 158
ProductVersion : 5, 4, 0, 0
ProductName : Smart Update Utility
CompanyName : AhnLab, Inc.
FileDescription : AhnSD Service
InternalName : AhnSD
LegalCopyright : Copyright (c) 1988-2004 AhnLab, Inc.
OriginalFilename : AhnSDsv.exe
#:14 [rundll32.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 256
ThreadCreationTime : 2005-01-27 ���� 10:11:15
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft�� Windows�� Operating System
CompanyName : Microsoft Corporation
FileDescription : Run a DLL as an App
InternalName : rundll
LegalCopyright : �� Microsoft Corporation. All rights reserved.
OriginalFilename : RUNDLL.EXE
#:15 [netpia.exe]
FilePath : C:\Program files\koreandoumi1.0\
ProcessID : 272
ThreadCreationTime : 2005-01-27 ���� 10:11:15
BasePriority : Normal
FileVersion : 1.5a
ProductVersion : 1.5a
ProductName : �ѱ����ͳ��ּҵ����
CompanyName : Netpia.com, Inc.
FileDescription : �ѱ����ͳ��ּҵ����
InternalName : �ѱ����ͳ��ּҵ����
LegalCopyright : Copyright (C) Netpia 2003 - 2004
OriginalFilename : Netpia.exe
#:16 [turboagent.exe]
FilePath : C:\Program Files\TurboPlayer\
ProcessID : 284
ThreadCreationTime : 2005-01-27 ���� 10:11:15
BasePriority : High
FileVersion : 1, 3, 6, 6
ProductVersion : 1, 3, 6, 6
ProductName : TURBO AGENT
CompanyName : FutureValley
FileDescription : TURBO AGENT
InternalName : TURBO AGENT
LegalCopyright : Copyright (C) 2002 FutureValley. Inc.
OriginalFilename : TurboAgent.EXE
#:17 [ahnsd.exe]
FilePath : C:\Program Files\Ahnlab\Smart Update Utility\
ProcessID : 312
ThreadCreationTime : 2005-01-27 ���� 10:11:15
BasePriority : Normal
FileVersion : 5, 3, 0, 23
ProductVersion : 5, 4, 0, 0
ProductName : Smart Update Utility
CompanyName : AhnLab, Inc.
FileDescription : AhnSD
InternalName : AhnSD
LegalCopyright : Copyright (c) 1988-2004 AhnLab, Inc.
OriginalFilename : AhnSD.exe
#:18 [ctfmon.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 412
ThreadCreationTime : 2005-01-27 ���� 10:11:15
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft�� Windows�� Operating System
CompanyName : Microsoft Corporation
FileDescription : CTF Loader
InternalName : CTFMON
LegalCopyright : �� Microsoft Corporation. All rights reserved.
OriginalFilename : CTFMON.EXE
#:19 [googledesktop.exe]
FilePath : C:\Program Files\Google\Google Desktop Search\
ProcessID : 428
ThreadCreationTime : 2005-01-27 ���� 10:11:16
BasePriority : Normal
#:20 [[email protected]]
FilePath : C:\Program Files\SETI@home\
ProcessID : 436
ThreadCreationTime : 2005-01-27 ���� 10:11:16
BasePriority : Idle
FileVersion : 3.08
ProductVersion : 3.08
ProductName : SETI@home
CompanyName : University of California, Berkeley
FileDescription : SETI@home
InternalName : SETI@home
LegalCopyright : Copyright �� 1999-2000
LegalTrademarks :
OriginalFilename : [email protected]
Comments :
#:21 [acrotray.exe]
FilePath : C:\Program Files\Adobe\Acrobat 5.0\Distillr\
ProcessID : 512
ThreadCreationTime : 2005-01-27 ���� 10:11:19
BasePriority : Normal
FileVersion : 5, 0, 0, 0
ProductVersion : 5, 0, 0, 0
ProductName : AcroTray - Adobe Acrobat Distiller helper application.
CompanyName : Adobe Systems Inc.
FileDescription : AcroTray
InternalName : AcroTray
LegalCopyright : Copyright �� 2001
OriginalFilename : AcroTray.exe
#:22 [v3p3at.exe]
FilePath : C:\PROGRA~1\Ahnlab\V3\
ProcessID : 676
ThreadCreationTime : 2005-01-27 ���� 10:11:21
BasePriority : Normal
FileVersion : 5, 0, 0, 153
ProductVersion : 5, 0, 0, 152
ProductName : V3Pro 2002 Deluxe
CompanyName : AhnLab, Inc.
FileDescription : POP3 realtime scan module.
InternalName : V3P3AT
LegalCopyright : Copyright (c) 1998-2003 AhnLab, Inc.
OriginalFilename : V3P3AT.exe
#:23 [cap4lak.exe]
FilePath : C:\WINDOWS\system32\spool\drivers\w32x86\3\
ProcessID : 780
ThreadCreationTime : 2005-01-27 ���� 10:11:21
BasePriority : Normal
FileVersion : 1.00.0.009
ProductVersion : 1.00.0.009
ProductName : Canon Advanced Printing Technology
CompanyName : CANON INC.
FileDescription : CAP4 PSW Launcher
InternalName : CAP4LAK
LegalCopyright : Copyright CANON INC. 2003
OriginalFilename : CAP4LAK.EXE
#:24 [cmwir.exe]
FilePath : C:\Program Files\Wireless\Client Manager\
ProcessID : 716
ThreadCreationTime : 2005-01-27 ���� 10:11:21
BasePriority : Normal
#:25 [cap4rsk.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 760
ThreadCreationTime : 2005-01-27 ���� 10:11:22
BasePriority : Normal
#:26 [cap4swk.exe]
FilePath : C:\WINDOWS\system32\spool\drivers\w32x86\3\
ProcessID : 1416
ThreadCreationTime : 2005-01-27 ���� 10:11:31
BasePriority : Normal
FileVersion : 1.00.0.009
ProductVersion : 1.00.0.009
ProductName : Canon Advanced Printing Technology
CompanyName : CANON INC.
FileDescription : Canon Advanced Printing Technology Printer Status Window
InternalName : CAP4SWK
LegalCopyright : Copyright CANON INC. 2003
OriginalFilename : CAP4SWK.EXE
#:27 [alg.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 2076
ThreadCreationTime : 2005-01-27 ���� 10:11:48
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft�� Windows�� Operating System
CompanyName : Microsoft Corporation
FileDescription : Application Layer Gateway Service
InternalName : ALG.exe
LegalCopyright : �� Microsoft Corporation. All rights reserved.
OriginalFilename : ALG.exe
#:28 [googledesktopindex.exe]
FilePath : C:\Program Files\Google\Google Desktop Search\
ProcessID : 2928
ThreadCreationTime : 2005-01-27 ���� 10:12:11
BasePriority : Normal
#:29 [googledesktopcrawl.exe]
FilePath : C:\Program Files\Google\Google Desktop Search\
ProcessID : 2968
ThreadCreationTime : 2005-01-27 ���� 10:12:11
BasePriority : Normal
#:30 [excel.exe]
FilePath : C:\Program Files\Microsoft Office\OFFICE11\
ProcessID : 3028
ThreadCreationTime : 2005-01-27 ���� 10:16:40
BasePriority : Normal
#:31 [monsvcnt.exe]
FilePath : C:\PROGRA~1\Ahnlab\V3\
ProcessID : 3108
ThreadCreationTime : 2005-01-27 ���� 4:16:20
BasePriority : Normal
FileVersion : 5, 0, 0, 183
ProductVersion : 5, 0, 1, 0
ProductName : V3Pro 2002 Deluxe
CompanyName : Ahnlab, Inc.
FileDescription : MonSvcNT
InternalName : MonSvcNT
LegalCopyright : Copyright (C) 1988 - 2003 Ahnlab, Inc.
OriginalFilename : MonSvcNT.exe
#:32 [iexplore.exe]
FilePath : C:\Program Files\Internet Explorer\
ProcessID : 2372
ThreadCreationTime : 2005-01-28 ���� 3:26:59
BasePriority : Normal
FileVersion : 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 6.00.2900.2180
ProductName : Microsoft�� Windows�� Operating System
CompanyName : Microsoft Corporation
FileDescription : Internet Explorer
InternalName : iexplore
LegalCopyright : Copyright (C) Microsoft Corporation. 1981-2001
OriginalFilename : IEXPLORE.EXE
#:33 [ad-aware.exe]
FilePath : C:\Program Files\Lavasoft\Ad-Aware SE Personal\
ProcessID : 3728
ThreadCreationTime : 2005-01-28 ���� 4:29:23
BasePriority : Normal
FileVersion : 6.2.0.206
ProductVersion : VI.Second Edition
ProductName : Lavasoft Ad-Aware SE
CompanyName : Lavasoft Sweden
FileDescription : Ad-Aware SE Core application
InternalName : Ad-Aware.exe
LegalCopyright : Copyright �� Lavasoft Sweden
OriginalFilename : Ad-Aware.exe
Comments : All Rights Reserved
Memory scan result:
��������������������������������������
New critical objects: 0
Objects found so far: 0
Started registry scan
��������������������������������������
FlashenhancerBHO Object Recognized!
Type : Regkey
Data :
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : unawareobj.unawareobj.1
FlashenhancerBHO Object Recognized!
Type : RegValue
Data :
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : unawareobj.unawareobj.1
Value :
FlashenhancerBHO Object Recognized!
Type : Regkey
Data :
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : unawareobj.unawareobj
FlashenhancerBHO Object Recognized!
Type : RegValue
Data :
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : unawareobj.unawareobj
Value :
FlashenhancerBHO Object Recognized!
Type : Regkey
Data :
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : typelib\{48e832ec-b061-49e2-bbc1-ac818623b742}
FlashenhancerBHO Object Recognized!
Type : Regkey
Data :
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : interface\{890089b7-b385-442f-97b6-99060e8bd08f}
FlashenhancerBHO Object Recognized!
Type : RegValue
Data :
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : interface\{890089b7-b385-442f-97b6-99060e8bd08f}
Value :
FlashenhancerBHO Object Recognized!
Type : Regkey
Data :
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : interface\{890089b7-b385-442f-97b6-99060e8bd08f}\proxystubclsid32
FlashenhancerBHO Object Recognized!
Type : RegValue
Data :
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : interface\{890089b7-b385-442f-97b6-99060e8bd08f}\proxystubclsid32
Value :
FlashenhancerBHO Object Recognized!
Type : Regkey
Data :
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : typelib\{48e832ec-b061-49e2-bbc1-ac818623b742}\1.0
FlashenhancerBHO Object Recognized!
Type : RegValue
Data :
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : typelib\{48e832ec-b061-49e2-bbc1-ac818623b742}\1.0
Value :
FlashenhancerBHO Object Recognized!
Type : Regkey
Data :
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : interface\{890089b7-b385-442f-97b6-99060e8bd08f}\typelib
FlashenhancerBHO Object Recognized!
Type : RegValue
Data :
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : interface\{890089b7-b385-442f-97b6-99060e8bd08f}\typelib
Value :
FlashenhancerBHO Object Recognized!
Type : RegValue
Data :
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : interface\{890089b7-b385-442f-97b6-99060e8bd08f}\typelib
Value : Version
FlashenhancerBHO Object Recognized!
Type : Regkey
Data :
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : interface\{890089b7-b385-442f-97b6-99060e8bd08f}\proxystubclsid
FlashenhancerBHO Object Recognized!
Type : RegValue
Data :
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : interface\{890089b7-b385-442f-97b6-99060e8bd08f}\proxystubclsid
Value :
Registry Scan result:
��������������������������������������
New critical objects: 16
Objects found so far: 16
Started deep registry scan
��������������������������������������
Deep registry scan result:
��������������������������������������
New critical objects: 0
Objects found so far: 16
Started Tracking Cookie scan
��������������������������������������
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : �п�@fastclick[1].txt
Category : Data Miner
Comment : Hits:10
Value : Cookie:�п�@fastclick.net/
Expires : 2007-01-18 ���� 1:16:22
LastSync : Hits:10
UseCount : 0
Hits : 10
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : �п�@z1.adserver[1].txt
Category : Data Miner
Comment : Hits:6
Value : Cookie:�п�@z1.adserver.com/
Expires : 2006-01-28 ���� 1:29:20
LastSync : Hits:6
UseCount : 0
Hits : 6
Tracking cookie scan result:
��������������������������������������
New critical objects: 2
Objects found so far: 18
Deep scanning and examining files...
��������������������������������������
Disk Scan Result for C:\WINDOWS
��������������������������������������
New critical objects: 0
Objects found so far: 18
Disk Scan Result for C:\WINDOWS\system32
��������������������������������������
New critical objects: 0
Objects found so far: 18
Disk Scan Result for C:\DOCUME~1\�п�.COM\LOCALS~1\Temp\
��������������������������������������
New critical objects: 0
Objects found so far: 18
Scanning Hosts file......
Hosts file location:"C:\WINDOWS\system32\drivers\etc\hosts".
����������������������������������������������������������������������������
Hosts file scan result:
��������������������������������������
1 entries scanned.
New critical objects:0
Objects found so far: 18
MRU List Object Recognized!
Location: : S-1-5-21-1801674531-507921405-1343024091-1003\software\google\navclient\1.1\history
Description : list of recently used search terms in the google toolbar
Performing conditional scans...
��������������������������������������
Conditional scan result:
��������������������������������������
New critical objects: 0
Objects found so far: 19
���� 1:33:37 Scan Complete
Summary Of This Scan
��������������������������������������
Total scanning time:00:03:28.499
Objects scanned:63482
Objects identified:18
Objects ignored:0
New critical objects:18 |
|
Back to top |
|
 |
Sage Monkey

Joined: 01 Nov 2004
|
Posted: Thu Jan 27, 2005 9:06 pm Post subject: |
|
|

Last edited by Sage Monkey on Thu Mar 29, 2007 10:01 am; edited 1 time in total |
|
Back to top |
|
 |
Demophobe

Joined: 17 May 2004
|
Posted: Thu Jan 27, 2005 10:51 pm Post subject: |
|
|
The rest are fine. I would call that a pretty clean scan. I take it adaware got rid of all that flashenhancer stuuf? If so, you are good to go, outside of perhaps having a couple services too many running. |
|
Back to top |
|
 |
Hollywoodaction
Joined: 02 Jul 2004
|
Posted: Sat Jan 29, 2005 6:36 am Post subject: |
|
|
Looks like you've got a Korean trojan on your system (netpia.exe is a file created by the Netzzak.a trojan).
http://fr.trendmicro-europe.com/smb/security_info/ve_detail.php?Vname=TROJ_NETZZAK.A
You need to download Ad-spider. It gets rid of most of the Korean spyware , which ad-aware often can't get.
By the way, did you know your computer is searching for aliens? You've got "SETI at home" installed. You might want to get rid of that if you want to free up some resources. |
|
Back to top |
|
 |
MixtecaMike

Joined: 24 Nov 2003 Location: 3rd Largest Train Station in Korea
|
Posted: Sat Jan 29, 2005 3:58 pm Post subject: |
|
|
Hollywoodaction wrote: |
By the way, did you know your computer is searching for aliens? You've got "SETI at home" installed. You might want to get rid of that if you want to free up some resources. |
Unless they're aliens come here to lower the morals of Korean girls, very important to find those ones, LOL. |
|
Back to top |
|
 |
phaedrus

Joined: 13 Nov 2003 Location: I'm comin' to get ya.
|
Posted: Sat Jan 29, 2005 5:57 pm Post subject: |
|
|
Hollywoodaction wrote: |
Looks like you've got a Korean trojan on your system (netpia.exe is a file created by the Netzzak.a trojan).
http://fr.trendmicro-europe.com/smb/security_info/ve_detail.php?Vname=TROJ_NETZZAK.A
You need to download Ad-spider. It gets rid of most of the Korean spyware , which ad-aware often can't get.
By the way, did you know your computer is searching for aliens? You've got "SETI at home" installed. You might want to get rid of that if you want to free up some resources. |
Ad-Spider is showing gibberish on my computer instead of English or Korean. I have Korean language settings on my computer. Anyone know how to fix this? |
|
Back to top |
|
 |
mithridates

Joined: 03 Mar 2003 Location: President's office, Korean Space Agency
|
Posted: Sat Jan 29, 2005 6:12 pm Post subject: |
|
|
Are you sure the Unicode is set to Korean as well? |
|
Back to top |
|
 |
Sage Monkey

Joined: 01 Nov 2004
|
Posted: Sat Jan 29, 2005 8:43 pm Post subject: |
|
|

Last edited by Sage Monkey on Thu Mar 29, 2007 10:02 am; edited 1 time in total |
|
Back to top |
|
 |
phaedrus

Joined: 13 Nov 2003 Location: I'm comin' to get ya.
|
Posted: Sat Jan 29, 2005 11:21 pm Post subject: |
|
|
mithridates wrote: |
Are you sure the Unicode is set to Korean as well? |
That worked.
I got to the pay menu, and stopped there, though. I'm not sure if it wanted a fee or a donation. I like freeware. |
|
Back to top |
|
 |
Hollywoodaction
Joined: 02 Jul 2004
|
Posted: Mon Jan 31, 2005 12:16 am Post subject: |
|
|
phaedrus wrote: |
mithridates wrote: |
Are you sure the Unicode is set to Korean as well? |
That worked.
I got to the pay menu, and stopped there, though. I'm not sure if it wanted a fee or a donation. I like freeware. |
There are two different menus. Click on the other option once the scan is done so you don't have 900 won to delete registry entries (which you can get rid of with other software for free once the spyware is deleted). |
|
Back to top |
|
 |
Holyjoe

Joined: 03 Mar 2003 Location: Away for a cuppa
|
Posted: Fri Jun 17, 2005 9:07 pm Post subject: |
|
|
Hollywoodaction wrote: |
Looks like you've got a Korean trojan on your system (netpia.exe is a file created by the Netzzak.a trojan).
http://fr.trendmicro-europe.com/smb/security_info/ve_detail.php?Vname=TROJ_NETZZAK.A
You need to download Ad-spider. It gets rid of most of the Korean spyware , which ad-aware often can't get.
By the way, did you know your computer is searching for aliens? You've got "SETI at home" installed. You might want to get rid of that if you want to free up some resources. |
Thought I'd say 'thanks' for the advice in this post about using Ad-spider. I'd had a browser hijack from amir.co.kr plus a ton of Korean pop-ups for months after the missus downloaded some stuff onto my computer and I'd been at a loss as to how to get shot of it.
I downloaded Ad-spider after reading this post and everything's fine now  |
|
Back to top |
|
 |
Hollywoodaction
Joined: 02 Jul 2004
|
Posted: Sat Jun 18, 2005 1:28 am Post subject: |
|
|
Actually, I deleted ad-spider. AVG Anti-virus detects a trojan in that software. That may be why it isn't very popular anymore. I'm using PC-Clean now.
Last edited by Hollywoodaction on Sat Jun 18, 2005 1:43 am; edited 4 times in total |
|
Back to top |
|
 |
|