• Some users have recently had their accounts hijacked. It seems that the now defunct EVGA forums might have compromised your password there and seems many are using the same PW here. We would suggest you UPDATE YOUR PASSWORD and TURN ON 2FA for your account here to further secure it. None of the compromised accounts had 2FA turned on.
    Once you have enabled 2FA, your account will be updated soon to show a badge, letting other members know that you use 2FA to protect your account. This should be beneficial for everyone that uses FSFT.

Ad-Aware

eLus1ve

Limp Gawd
Joined
Jan 19, 2004
Messages
294
Regarding my previous problems with my



Video Card , I decided to scan for spywares and such using Ad-Aware. I've used Ad-Aware quite alot, but this is the first time that Ad-Aware would just freeze when it's quaranatining. So I decided to download SpyBot S&D, but it didn't find much spywares and it made no difference what so ever. My homepage would always change to the spyware's site automatically and sometimes my computer would randomly execute those MS-DOS Prompt menus with random pop-ups once a few hours. Any suggestions? :mad:
 
this happened to me before I formatted. I ran msconfig and under startup I turned off what seemed like bogus stuff. Try googling your spyware and maybe a solution will turn up.
 
OK.

Try and run CWS Shredder. I don't have a link handy but google pulls it up. Cool web search is one nasty spyware.


Also it really would help if you told us what website your homepage gers directed to. There's tons of different spyare out there so that kind of info woulkd help immensly.
 
Originally posted by vinnie
hijackthis

Since vinny doesn't feel that it's necessary to add some information to his post, I will do it for him. HijackThis is a program that will show some information about your computer that could lead to problems. Download it, and save the log. Don't "fix" anything using that program until you let someone who knows what they are doing, look at the log first. Post the log on this forum if you want and let us look at it to tell you what you need to "fix."
 
What's the homepage you're getting sent to?
Usually there is a help/FAQ on the site, and in there they will list a removal tool.
 
I scanned with Hijackthis and this is what I got :

Logfile of HijackThis v1.97.7
Scan saved at ¿ÀÈÄ 10:25:29, on 2004-03-14
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\CMPDPSRV.EXE
C:\WINDOWS\System32\ctfmon.exe
C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
C:\Program Files\PerSono\perstray.exe
C:\Program Files\Executive Software\Diskeeper\DkService.exe
C:\WINDOWS\System32\netsvc.exe
C:\Program Files\HHVcdV5Sys\VC5SecS.exe
C:\Program Files\mIRC\mirc.exe
C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\System32\conime.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\HijackThis\HijackThis.exe

R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: (no name) - {62999427-33FC-4baf-9C9C-BCE6BD127F08} - (no file)
O3 - Toolbar: (no name) - {ACB1E670-3217-45C4-A021-6B829A8A27CB} - (no file)
O4 - HKLM\..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [nForce Tray Options] sstray.exe /r
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Network Service Manager] netsvc.exe
O4 - HKLM\..\Run: [CMPDPSRV] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\CMPDPSRV.EXE
O4 - HKLM\..\RunServices: [Network Service Manager] netsvc.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe"
O4 - HKCU\..\Run: [Steam] "c:\program files\steam\steam.exe" -silent
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Perstray.lnk = ?
O8 - Extra context menu item: &Download with &DAP - C:\PROGRA~1\DAP\dapextie.htm
O8 - Extra context menu item: Download &all with DAP - C:\PROGRA~1\DAP\dapextie2.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: AIM (HKLM)
O16 - DPF: {1DE9BB01-B121-401D-8877-BCD5ED5B7EE5} (Tpwin Control) - http://www.crezio.com/test/leeyunho/AlwaysOn/AlwaysOn.CAB
O16 - DPF: {33E54F7F-561C-49E6-929B-D7E76D3AFEB1} (Pool Control) - http://mirror.worldwinner.com/games/v44/pool/pool.cab
O16 - DPF: {48884C41-EFAC-433D-958A-9FADAC41408E} (EGamesPlugin Class) - https://www.e-games.com.my/com/EGamesPlugin.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/03be766c1ceb1e428a00/netzip/RdxIE601.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2003120501/housecall.antivirus.com/housecall/xscan53.cab
O16 - DPF: {CFCB7308-782F-11D4-BE27-000102598CE4} (NPX Control) - http://kr.pristontale.com/nprotect/nprotect/npx.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{1B5BD7D3-E7AB-4125-B1CB-351EF019FB0D}: NameServer = 206.13.29.12 206.13.30.12
O17 - HKLM\System\CS2\Services\Tcpip\..\{1B5BD7D3-E7AB-4125-B1CB-351EF019FB0D}: NameServer = 206.13.29.12 206.13.30.12


Tell me if you see anything fishy. There is really a big problem with my computer, because my computer free of Spyware(according to Ad-Aware) and free of virus (according to Trend Housecall). Really weird thing is that Anti-Virus, VirusScan, and regedit menu automatically closes itself after about 5 seconds after opening it. I've also looked at my CPU Usage monitor on my Task Manager, and my CPU usage % would jump from a constant 2% to 80% randomly every 30 seconds.
 
I see real audio and quicktime... are they really something you need running all the time? If you know what you're doing, kill the startups on them. I've seen nothing but good things come of that on the family computer here.

DAP? The download accelerator? It's jam packed with spyware apparently. You may want to look into getting rid of that one...



Find Spybot Search and Destroy and give that a run too.
 
Originally posted by vinnie
...
Find Spybot Search and Destroy and give that a run too.

read the first post, vinnie

i'd kill RealPlayer and QuickTime, too

google for this: C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
it just seems weird...

have you tried the CWS Shredder (i always thought it was just "CW Shredder ?")

post with what site you're getting redireced to.


www.windowsupdate.com can be helpful as well.
 
Originally posted by Carnival Forces
read the first post, vinnie

i'd kill RealPlayer and QuickTime, too

google for this: C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
it just seems weird...

have you tried the CWS Shredder (i always thought it was just "CW Shredder ?")

post with what site you're getting redireced to.


www.windowsupdate.com can be helpful as well.

That's POP-Up Stopper. It's not spyware
 
Back
Top