![]() |
![]() |
![]() |
||||
Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums. You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today! If you have any problems with the registration process or your account login, please contact us. |
![]() ![]() |
|
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed. |
|
Thread Tools |
![]() |
#1 |
Too lazy to set a custom title
Join Date: Dec 2001
Location: Charlotte, NC
Posts: 14,137
|
Spy Ware
Everytime I reboot my home page is reset to...
http://www.searchv.com/w/ I have ad-ware 6.0 and everytime I run it, it finds something and I delete it. How do I get ride of this fucking thing? |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#2 |
Confirmed User
Join Date: Mar 2002
Location: Montreal Canada
Posts: 2,946
|
Before running Adaware - update it
Here's a link with more info if you want to get technical http://www.computing.net/security/ww...orum/6732.html |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#3 |
Confirmed User
Join Date: Feb 2003
Location: In Your GF's Panty.
Posts: 1,192
|
did you update it ??
download the latest ref file
__________________
This place is for RENT |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#5 | |
Too lazy to set a custom title
Join Date: Dec 2001
Location: Charlotte, NC
Posts: 14,137
|
Quote:
Yep, just got it and ran it, rebooted and still fuxored. |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#6 |
Confirmed User
Join Date: Jul 2002
Location: Magrathea
Posts: 6,493
|
Open a command prompt and type 'regedit'.
Look under HKEY_LOCAL_MACHINE/Software/Microsoft/Windows/CurrentVersion/Run and delete anything you don't recognize or list things here and people can tell you what's what. Do the same for HKEY_CURRENT_USER/Software/Microsoft/Windows/CurrentVersion/Run SpaceAce |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#7 |
Click on my TCG signature
Join Date: Feb 2002
Posts: 20,825
|
Download Spyware remover , maybe it will help. Did you also do a virus check on your PC? Maybe it's a new worm or something ...
![]()
__________________
$9.95/month for 15000 GB bandwidth monthly, unlimited (sub)domains and MySQL5, PHP4/5, 500 GB disk storage! ![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#8 |
Confirmed User
Industry Role:
Join Date: Aug 2003
Location: Valencia
Posts: 2,490
|
I have to use a combination of adware 6.0 and spy-bot search and destroy to handle that pesky stealthware. But even that doesn't work with some of the "great new stuff" they are coming out with.
![]()
__________________
Todd Spaits - Co-founder -YanksCash Premium ad-packages available - Skype for details - tmspaits |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#9 |
aka K-Man
Industry Role:
Join Date: Oct 2001
Location: The Gutter
Posts: 29,292
|
spybot is what i use, its free and has gotten rave reviews...
__________________
Crypto HODLr Crypto mining Angel investor |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#10 |
Too lazy to set a custom title
Join Date: Dec 2001
Location: Charlotte, NC
Posts: 14,137
|
I just installed spybot and rebooted. Still got the damn thing. Time to take space dogs advice.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#11 |
Confirmed User
Join Date: Sep 2003
Location: Los Angeles
Posts: 5,208
|
time to format
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#12 | |
Confirmed User
Join Date: Jul 2002
Location: Magrathea
Posts: 6,493
|
Quote:
SpaceAce |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#13 |
Too lazy to set a custom title
Join Date: Dec 2001
Location: Charlotte, NC
Posts: 14,137
|
Sorry SpaceAce. Can you msg me on ICQ so I don't delete anything I need in the registry?
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#14 |
Meow Media Inc.
Industry Role:
Join Date: Jul 2001
Location: In the valley of the sun, cactus, tacos, tequila, and nod
Posts: 7,785
|
Take a peek at the page I put online to help visitors at http://www.pk.com/spyware.html
Specifically it might be helpful for you to download HijackThis and run it.
__________________
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#15 |
Too lazy to set a custom title
Join Date: Dec 2001
Location: Charlotte, NC
Posts: 14,137
|
Thanks PK I'll try and keep you posted.
![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#16 |
Too lazy to set a custom title
Join Date: Jan 2002
Location: Holland
Posts: 9,870
|
check you autoexec.bat , might be something in there.
__________________
Don't let greediness blur your vision | You gotta let some shit slide icq - 441-456-888 |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#17 |
I am cool
Join Date: Jul 2003
Posts: 14,494
|
There is a new virus/spywear program out...
Its just like the mime exploit with active-x It will make you download a .hta file when you restart it will make your cpu its bitch.. Aim profile = owned homepage = owned Fav's = owned Source: C:\Documents and Settings\KMR\Local Settings\Temporary Internet Files\Content.IE5\418XEJ05\detour[1].hta Click for more information about this virus : Trojan.Sinkin You can thank Gabe for that virus he got it on acciden't and I clicked on his aim profile. Gabe got owned by that virus! He was pissed lol |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#18 |
Confirmed User
Join Date: Aug 2003
Location: Montreal!
Posts: 6,285
|
Get Ad Aware 6 it will do the job.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#19 | |
Confirmed User
Join Date: Apr 2003
Location: Colorado
Posts: 2,421
|
Quote:
be careful there! might delete some important things and really screw up window! ![]()
__________________
IntenseCash.com ~ Chuck | ICQ: 444887112 Top converting sites: BrokeStraightBoys.com, CollegeDudes.com & CollegeBoyPhysicals.com |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#20 |
So Fucking Banned
Join Date: Oct 2003
Location: In a house.
Posts: 9,465
|
Gee, for a bunch of people who depend on search engines for traffic, none of you seem to be able to find shit...
http://www.computing.net/security/ww...orum/6873.html There, thats how you get rid of it. Oh yeah, run windows update and install EVERYTHING. Do that every week. Alex |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#21 |
Too lazy to set a custom title
Join Date: Dec 2001
Location: Charlotte, NC
Posts: 14,137
|
I ran cwshredder and it found some shit but I still have an this virus.
I then ran HijackThis and here is my log Logfile of HijackThis v1.97.3 Scan saved at 2:38:30 AM, on 10/20/2003 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Real\RealPlayer\RealPlay.exe C:\Program Files\AIM\aim.exe C:\Program Files\ICQ\ICQ.exe C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe C:\WINDOWS\System32\nvsvc32.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\wanmpsvc.exe C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Documents and Settings\Michael\Desktop\hijackthis\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http:/www.searchv.com/w/search.html R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.searchv.com/w/search.html R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/ R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.searchv.com/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.searchv.com/w/search.html R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.searchv.com/w/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.searchv.com/w/search.html R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.searchv.com/w/search.html R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.searchv.com/w/search.html R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.searchv.com/w/ O1 - Hosts: 209.66.114.130 sitefinder.verisign.com O2 - BHO: WinShow module - {6CC1C918-AE8B-4373-A5B4-28BA1851E39A} - C:\Documents and Settings\Michael\Application Data\winshow\winshow.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O4 - HKLM\..\Run: [Mirabilis ICQ] C:\Program Files\ICQ\ICQNet.exe O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [sys] regedit /s C:\WINDOWS\sys.reg O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl O4 - HKCU\..\RunOnce: [ICQ] C:\Program Files\ICQ\ICQ.exe -trayboot O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O4 - Global Startup: MSupdater.exe O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O9 - Extra button: Messenger (HKLM) O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM) O9 - Extra button: ICQ Pro (HKLM) O9 - Extra 'Tools' menuitem: ICQ (HKLM) O9 - Extra button: AIM (HKLM) O9 - Extra button: Real.com (HKLM) O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yahoo.com/dl/installs/yinst0309.cab O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.co...B?37897.581875 O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/s...sh/swflash.cab |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#22 |
Confirmed User
Join Date: Feb 2003
Posts: 2,192
|
yep cwshredder will fix the problem!
|
![]() |
![]() ![]() ![]() ![]() ![]() |