Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Hjt Log - Bobokun


  • This topic is locked This topic is locked
13 replies to this topic

#1 BoboKun

BoboKun

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:02:24 AM

Posted 07 November 2005 - 05:38 PM

Hi sorri to bother you ppl but i have a problem >__< first of all. . . i used umm ad-Aware, i used XoftSpy, I used Norton Antivirus, i used Spybot S & D and it looks like i'm spyware and adware free but I am using Windows XP using Mozilla firefox and every 5-10 min I get these stupid pop-ups and I dont know how to fix it pleaase help me

Example of a pop-up site is www.free-savings.com/normal/yyy65.html

Logfile of HijackThis v1.99.1
Scan saved at 5:32:36 PM, on 07/11/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton Internet Security\ISSVC.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\LXSUPMON.EXE
C:\WINDOWS\system32\CTHELPER.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Webroot\Washer\wwDisp.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\wwSecure.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\HiJack This\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O1 - Hosts: re.com
O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [LXSUPMON] C:\WINDOWS\system32\LXSUPMON.EXE RUN
O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [XoftSpy] C:\Program Files\XoftSpy\XoftSpy.exe -s
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Window Washer] C:\Program Files\Webroot\Washer\wwDisp.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [PopupDestroyer] C:\Program Files\Popup Detroyer\PopUp Destroyer.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: Anti-Popup Pro.lnk = C:\Program Files\Wingsofts\Anti-Popup Pro\Anti-Popup Pro.exe
O8 - Extra context menu item: Download All by FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/su/ocx/15015/CTSUEng.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {58172624-85DD-4482-9E64-02ADCA637E96} (shizmoo Class) - http://www.kungfuchess.com/activex/web665.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su/ocx/15016/CTPID.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{A4493B9F-93EB-4B2D-AD37-C71CB9570AAC}: NameServer = 24.153.23.66,24.153.22.67
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - AppInit_DLLs: MsgPlusLoader.dll
O20 - Winlogon Notify: Run - C:\WINDOWS\system32\l0l6la3s1d.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Washer AutoComplete (wwSecSvc) - Webroot Software, Inc. - C:\WINDOWS\system32\wwSecure.exe

//Mod edit: Modified the hot link to pop up site above to protect

Edited by KoanYorel, 07 November 2005 - 06:23 PM.


BC AdBot (Login to Remove)

 


#2 miekiemoes

miekiemoes

    Malware Killer Dog


  • Malware Response Team
  • 19,420 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Belgium
  • Local time:09:24 AM

Posted 08 November 2005 - 02:33 PM

Hello,

Please download WebRoot SpySweeper from HERE (It's a 2 week trial):
  • Click the Free Trial link under to "SpySweeper" to download the program.
  • Install it.
  • Once the program is installed, it will open.
  • It will prompt you to update to the latest definitions, click Yes.
  • Once the definitions are installed, click Sweep Now on the left side.
  • Click the Start button.
  • When it's done scanning, click the Next button.
  • Make sure everything has a check next to it, then click the Next button.
  • It will remove all of the items found.
  • Click Session Log in the upper right corner, copy everything in that window and save in in Notepad and place it on your desktop.
  • Click the Summary tab and click Finish.
  • REBOOT (Really important!!)
  • Paste the contents of the session log you copied into your next reply together with a new hijackthislog.

AntispywareScanners---Antivirus Scanners---Firewalls---Online Scanners---Prevention---Help! My computer is slow---My Blog---Follow me on Twitter.
My help is ALWAYS FREE, but if you want to donate to help me continue my fight against malware -- click here!
Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#3 BoboKun

BoboKun
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:02:24 AM

Posted 08 November 2005 - 03:46 PM

Spy Sweeper log

********
3:27 PM: | Start of Session, November 8, 2005 |
3:27 PM: Spy Sweeper started
3:27 PM: Sweep initiated using definitions version 569
3:27 PM: Starting Memory Sweep
3:27 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:27 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:27 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:27 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:28 PM: Found Adware: icannnews
3:28 PM: Detected running threat: C:\WINDOWS\system32\hrls0537e.dll (ID = 83)
3:28 PM: Detected running threat: C:\WINDOWS\system32\utrvoica.dll (ID = 83)
3:29 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:29 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:29 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:29 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:29 PM: Memory Sweep Complete, Elapsed Time: 00:02:18
3:29 PM: Starting Registry Sweep
3:29 PM: Found Adware: targetsoft
3:29 PM: HKLM\software\microsoft\windows\currentversion\uninstall\tsl installer\ (1 subtraces) (ID = 143608)
3:29 PM: Found Adware: targetsaver
3:29 PM: HKLM\software\microsoft\windows\currentversion\uninstall\tsl installer\ (1 subtraces) (ID = 143608)
3:29 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:29 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:29 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:29 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:29 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:29 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:29 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:29 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:29 PM: HKU\S-1-5-21-682003330-651377827-725345543-1004\software\tsl2\ (1 subtraces) (ID = 143616)
3:29 PM: Registry Sweep Complete, Elapsed Time:00:00:17
3:29 PM: Starting Cookie Sweep
3:29 PM: Cookie Sweep Complete, Elapsed Time: 00:00:00
3:29 PM: Starting File Sweep
3:30 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:30 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:30 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:30 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:30 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:30 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:30 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:30 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:30 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:30 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:30 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:30 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:30 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:30 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:31 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:31 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:31 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:31 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:31 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:31 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:31 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:31 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:32 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:32 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:32 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:32 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:32 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:32 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:32 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:32 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:32 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:32 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:32 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:32 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:33 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:33 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:33 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:33 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:33 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:33 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:33 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:33 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:33 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:33 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:33 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:33 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:34 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:34 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:34 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:34 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:34 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:34 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:34 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:34 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:34 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:34 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:34 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:34 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:35 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:35 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:35 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:35 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:35 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:35 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:35 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:35 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:35 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:35 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:35 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:35 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:35 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:35 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:35 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:35 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:36 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:36 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:36 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:36 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:36 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:36 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:36 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:36 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:36 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:36 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:36 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:36 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:36 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:36 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:36 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:36 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:36 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:36 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:36 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:36 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:36 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:36 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:37 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:37 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:37 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:37 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:37 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:37 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:37 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:37 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:37 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:37 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:37 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:37 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:37 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:37 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:37 PM: File Sweep Complete, Elapsed Time: 00:07:43
3:37 PM: Full Sweep has completed. Elapsed time 00:10:21
3:37 PM: Traces Found: 8
3:37 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:37 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:37 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:37 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:37 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:37 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:37 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:37 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:38 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:38 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:38 PM: Removal process initiated
3:38 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:38 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:38 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:38 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:38 PM: Quarantining All Traces: icannnews
3:38 PM: icannnews is in use. It will be removed on reboot.
3:38 PM: C:\WINDOWS\system32\hrls0537e.dll is in use. It will be removed on reboot.
3:38 PM: C:\WINDOWS\system32\utrvoica.dll is in use. It will be removed on reboot.
3:38 PM: Quarantining All Traces: targetsaver
3:38 PM: Quarantining All Traces: targetsoft
3:39 PM: Removal process completed. Elapsed time 00:00:27
********
3:27 PM: | Start of Session, November 8, 2005 |
3:27 PM: Spy Sweeper started
3:27 PM: Sweep initiated using definitions version 569
3:27 PM: Sweep Canceled
3:27 PM: Traces Found: 0
3:27 PM: | End of Session, November 8, 2005 |
********
3:25 PM: | Start of Session, November 8, 2005 |
3:25 PM: Spy Sweeper started
3:26 PM: Your spyware definitions have been updated.
3:26 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:26 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:26 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:26 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:26 PM: Updating spyware definitions
3:26 PM: Your definitions are up to date.
3:26 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:26 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:26 PM: Updating spyware definitions
3:26 PM: Your definitions are up to date.
3:27 PM: | End of Session, November 8, 2005 |






The Updated Hijackthis Log

Logfile of HijackThis v1.99.1
Scan saved at 3:43:14 PM, on 08/11/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Norton Internet Security\ISSVC.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\wwSecure.exe
C:\WINDOWS\system32\LXSUPMON.EXE
C:\WINDOWS\system32\CTHELPER.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Webroot\Washer\wwDisp.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\HiJack This\HijackThis.exe
C:\Program Files\Messenger\msmsgs.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O1 - Hosts: re.com
O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [LXSUPMON] C:\WINDOWS\system32\LXSUPMON.EXE RUN
O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Window Washer] C:\Program Files\Webroot\Washer\wwDisp.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [PopupDestroyer] C:\Program Files\Popup Detroyer\PopUp Destroyer.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: Anti-Popup Pro.lnk = C:\Program Files\Wingsofts\Anti-Popup Pro\Anti-Popup Pro.exe
O8 - Extra context menu item: Download All by FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/su/ocx/15015/CTSUEng.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {58172624-85DD-4482-9E64-02ADCA637E96} (shizmoo Class) - http://www.kungfuchess.com/activex/web665.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su/ocx/15016/CTPID.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{A4493B9F-93EB-4B2D-AD37-C71CB9570AAC}: NameServer = 24.153.23.66,24.153.22.67
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - AppInit_DLLs: MsgPlusLoader.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Washer AutoComplete (wwSecSvc) - Webroot Software, Inc. - C:\WINDOWS\system32\wwSecure.exe

#4 miekiemoes

miekiemoes

    Malware Killer Dog


  • Malware Response Team
  • 19,420 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Belgium
  • Local time:09:24 AM

Posted 08 November 2005 - 04:11 PM

Great! Seems like Spysweeper did the job! :thumbsup:

Did you set this yourself in your hosts file? re.com ? If not, open hijackthis and check and fix next entry:

O1 - Hosts: re.com

I also see you have two popupblockers installed. Keep in mind that some popupblockers cause popups, just to let you buy the product.
So, I recommend you uninstall them, because now the infection is gone, you won't have those popups anymore also:
So uninstall: Popup Detroyer and Anti-Popup Pro.
Reboot afterwards.

You have service Pack 2 installed, did you know that your internet explorer has a built in popup blocker now, which works great by the way..
Look here: http://www.microsoft.com/windowsxp/using/w...pupblocker.mspx
Also, the google toolbar has a great built in popupblocker:
http://toolbar.google.com/firefox/index.html

I also see you are running Flashget. Flashget free version installs spyware.
If you're using the free version, I suggest you uninstall it.
Read here for better and safer alternatives: http://www.spywareinfo.com/downloads.php?cat=dlman#dlman

I still recommend you perform another scan with spysweeper to get rid of the leftovers.

When done, perform next:
Please download NTrights.zip by freeatlast.
Save it on your desktop.
Unzip/extract it.
Read here how to unzip/extract properly:
http://metallica.geekstogo.com/xpcompressedexplanation.html
Open the NTrights-folder
Double click on the Debug.bat file to run it, follow any prompts it asks.

It will create a log.
If the log says:
"Granting SeDebugPrivilege to Administrators ... successful", you must be ok and things restored well.

Let me know in your next reply after performing above steps how things are running. :flowers:

Edited by miekiemoes, 08 November 2005 - 04:12 PM.

AntispywareScanners---Antivirus Scanners---Firewalls---Online Scanners---Prevention---Help! My computer is slow---My Blog---Follow me on Twitter.
My help is ALWAYS FREE, but if you want to donate to help me continue my fight against malware -- click here!
Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#5 BoboKun

BoboKun
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:02:24 AM

Posted 08 November 2005 - 06:13 PM

>__< NTrights.zip link doesnt work =( but great news!!! THANKS ALOT FOR UR HELP my comp got fixed spyware gone!!! yaay no more stupid pop-ups thank u al loottt and also one more thing. . . if i download full version of Flashget there wont be any popups rite? oh and i ran spy sweeper again no spyware found ^^ and i uninstalled all the pop-up blockers + i added google toolbar

#6 miekiemoes

miekiemoes

    Malware Killer Dog


  • Malware Response Team
  • 19,420 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Belgium
  • Local time:09:24 AM

Posted 08 November 2005 - 06:19 PM

Hello,

Because the Ntrights-links didn't work, we still need to restore that though, that's important. Ok, perform next..

Download L2mfix from one of these two locations:

http://www.atribune.org/downloads/l2mfix.exe
http://www.downloads.subratam.org/l2mfix.exe

Save the file to your desktop and double click l2mfix.exe. Click the Install button to extract the files and follow the prompts.
Then open the newly added folder called L2Mfix on your desktop.
Doubleclick second.bat
It will scan and restore some settings.
It will open a log afterwards. Just close it again.
That will restore keys this infection corrupted.

About flashget, as i already said, full version or not, this program is a risk because it's known it can install malware with it. That's why I gave you that link for the safer alternatives. :thumbsup:

To keep this clean in the future, I would suggest the following things:

Install Spywareblaster
SpywareBlaster doesn`t scan and clean for so-called spyware, but prevents it from being installed in the first place. It blocks the popular spyware ActiveX controls, and also prevents the installation of any of them via a webpage.

Avoid illegal sites, because that's where most malware is present.

Let your antispywarescanner(s) scan frequently and don't forget to update before.

And I do suggest you perform an online virusscan once in a while. (Housecall and/or Bitdefender). Because what one virusscanner can't find another one maybe can.
Also make sure that your virusscanner, the one that is installed on your system is always up to date!

Make sure your windows has the latest updates: http://windowsupdate.microsoft.com/

If you are having XP SP2, read here how to configure Security Features for Internet Explorer:
http://www.microsoft.com/technet/security/...xp/iesecxp.mspx

Also visit this Free Online Scanner for PC Health and Safety

More info on how to prevent malware you can also find here (By Tony Klein)

Happy surfing again! :flowers:

Edited by miekiemoes, 08 November 2005 - 06:20 PM.

AntispywareScanners---Antivirus Scanners---Firewalls---Online Scanners---Prevention---Help! My computer is slow---My Blog---Follow me on Twitter.
My help is ALWAYS FREE, but if you want to donate to help me continue my fight against malware -- click here!
Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#7 BoboKun

BoboKun
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:02:24 AM

Posted 08 November 2005 - 06:37 PM

okay i ran second.bat just like u told me to on desktop and it gave me this error X__X Registry Editor "Cannot export backregs\B58257E0-C671-4C8D-B6EB-47B93644D512.reg Error opening the file. There may be a disk or file system error.

=(

#8 miekiemoes

miekiemoes

    Malware Killer Dog


  • Malware Response Team
  • 19,420 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Belgium
  • Local time:09:24 AM

Posted 09 November 2005 - 02:04 AM

Hello,

No problem. Open de L2mfix-folder again, doubleclick l2mfix.bat
Choose option 4 by pressing 4 and clicking enter.
That's all you have to do. :thumbsup:
AntispywareScanners---Antivirus Scanners---Firewalls---Online Scanners---Prevention---Help! My computer is slow---My Blog---Follow me on Twitter.
My help is ALWAYS FREE, but if you want to donate to help me continue my fight against malware -- click here!
Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#9 BoboKun

BoboKun
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:02:24 AM

Posted 09 November 2005 - 03:29 PM

okay fixed ^__^ thx a lot so now umm I uninstalled flashget and i cant find a good download accellerator can u name the best one u can think of ^__^ since ur an expert and everything =P I also installed spyware blaster but it doesnt show in my taskbar =/

#10 miekiemoes

miekiemoes

    Malware Killer Dog


  • Malware Response Team
  • 19,420 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Belgium
  • Local time:09:24 AM

Posted 09 November 2005 - 03:33 PM

Hi, here you can find safer alternatives: http://www.spywareinfo.com/downloads.php?cat=dlman#dlman

Spywareblaster doesn't run in the background as another program does, but it does prevent you though. It adds a sort of 'killbits' in the registry to block bad activeX.
AntispywareScanners---Antivirus Scanners---Firewalls---Online Scanners---Prevention---Help! My computer is slow---My Blog---Follow me on Twitter.
My help is ALWAYS FREE, but if you want to donate to help me continue my fight against malware -- click here!
Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#11 BoboKun

BoboKun
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:02:24 AM

Posted 09 November 2005 - 03:40 PM

okay thx but first of all DLExpert when i donwload the setup file it is corrupt and download express and mass downloader leads me to this page http://www.metaproducts.com/ which i have no clue where to download the program >__<

#12 miekiemoes

miekiemoes

    Malware Killer Dog


  • Malware Response Team
  • 19,420 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Belgium
  • Local time:09:24 AM

Posted 09 November 2005 - 03:45 PM

yes, that's the right site though....Take a look here, there you'll find them:
http://www.metaproducts.com/mp/mpProducts_...ads_Current.asp
You can also find DLExpert here:
http://www.majorgeeks.com/download447.html

Edited by miekiemoes, 09 November 2005 - 03:46 PM.

AntispywareScanners---Antivirus Scanners---Firewalls---Online Scanners---Prevention---Help! My computer is slow---My Blog---Follow me on Twitter.
My help is ALWAYS FREE, but if you want to donate to help me continue my fight against malware -- click here!
Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#13 BoboKun

BoboKun
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:02:24 AM

Posted 09 November 2005 - 03:46 PM

ahh thx ^__^

Edited by BoboKun, 09 November 2005 - 03:47 PM.


#14 miekiemoes

miekiemoes

    Malware Killer Dog


  • Malware Response Team
  • 19,420 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Belgium
  • Local time:09:24 AM

Posted 09 November 2005 - 03:49 PM

You're welcome. :thumbsup:

Since this issue appears resolved ... this Topic is closed.

If you need this topic reopened, please request this by sending the moderating team
a PM with the address of the thread. This applies only to the original topic starter.

Everyone else please begin a New Topic.
AntispywareScanners---Antivirus Scanners---Firewalls---Online Scanners---Prevention---Help! My computer is slow---My Blog---Follow me on Twitter.
My help is ALWAYS FREE, but if you want to donate to help me continue my fight against malware -- click here!
Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users