For information on how to deal with, and protect your computer, please go down to the bottom of the help desk to the archive section (main page). From there select how to combat Spyware, in this archive there are many tools, which will help you combat this problem. Problems concerning the Windows XP Operating System should go in this forum.


Email This Page to Someone
  Footslog's Web Boards
  Windows XP
  SpyWare?

Post New Topic  Post A Reply
profile | register | preferences | faq | search

next newest topic | next oldest topic
Author Topic:   SpyWare?
Josh1
Administrator
posted October 10, 2005 05:34 PM     Click Here to See the Profile for Josh1     Edit/Delete Message
Yes it I a handy tool, post the long in your next reply and let us have a look at it.

------------------
Powered by Intelligent Computing Solutions.
------------------------
www.footslog.com

www.compsol.8k.com

For every problem, there is a solution.

Please give what you can to the Hurricane relief

http://www.microsoft.com/mscorp/citizenship/giving/relief.asp

IP: Logged

joemag7
Member
posted October 05, 2005 12:18 AM     Click Here to See the Profile for joemag7     Edit/Delete Message
Wow, that process explorer is great, there were two programs that had my processor running to the max, I killed both of them and my CPU fan hasn't come on since. I then went into HijackThis to get rid of them, one was called WinUpdate, which I don't use windows update anyway, so I got rid of it the other was that iosdt.exe that you mentioned, but HijackThis can't get rid of it, every time I tell it to delete and then rescan it shows up again. I'm glad I got my laptop running cool again so I can sleep easy toniht, thanks

IP: Logged

Josh1
Administrator
posted October 04, 2005 06:55 PM     Click Here to See the Profile for Josh1     Edit/Delete Message
I don’t like what I am seeing here C:\DOCUME~1\JOSEPH~1\LOCALS~1\Temp\Rar$EX00.195\HijackThis.exe
This part Rar$EX00.195,go ahead and run a scan here housecall.trendmicro.com

Delete this
bin/installer.v4/vet_install_popup.pl?1&4&04.00.08.43&unknown&unknown&http://w
ww.sci on.com/scionConfigApp/scion/viewsection.jsp?forceLoad=1

Not so sure what this is
O23 - Service: distributed.net client (dnetc) - Distributed Computing Technologies, Inc. - C:\WINDOWS\System32\iosdt\iosdt.exe
C:\WINDOWS\System32\iosdt\iosdt.exe
Both of these are some kind of client, I don’t know what it is, do you, use this?

Finally go here, http://www.footslog.com/board/Archives/Archive-000003/HTML/20050327-16-000026.html

You mentioned Adaware only, so if you do not have Spybot, Spyware Blaster, and MS Antispyware installed, download install and update them. If you want a better handle on what is running in the background, download Process Explorer. Process Explorer is far more superior then Task Manager, you will be able to actually be able to tell whatever process or services is running in the background, tell where it is coming from, what other programs it might be effecting, and get a little bit more information about the file. Process Explorer can be found in the above link. Let us know if this helps you

------------------
Powered by Intelligent Computing Solutions.
------------------------
www.footslog.com

www.compsol.8k.com

For every problem, there is a solution.

Please give what you can to the Hurricane relief

http://www.microsoft.com/mscorp/citizenship/giving/relief.asp

IP: Logged

joemag7
Member
posted October 04, 2005 06:31 PM     Click Here to See the Profile for joemag7     Edit/Delete Message
Heres the log from Hijack This. I deleted the two R1's the 03 and the first 016.

Logfile of HijackThis v1.99.1
Scan saved at 5:03:19 PM, on 10/4/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\atievxx.exe
C:\WINDOWS\System32\iosdt\iosdt.exe
C:\WINDOWS\StartupMonitor.exe
C:\Program Files\Lavasoft\Ad-aware 6\Ad-watch.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\WINDOWS\FVProtect.exe
C:\Program Files\winupdates\winupdates.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\PROGRA~1\MICROS~2\OFFICE11\OUTLOOK.EXE
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\JOSEPH~1\LOCALS~1\Temp\Rar$EX00.195\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://searchcentral.cc/search.php?v=4&aff=3748
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchcentral.cc/index.php?v=4&aff=3748
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/explore.html
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [Run StartupMonitor] StartupMonitor.exe
O4 - HKLM\..\Run: [Ad-watch] "C:\Program Files\Lavasoft\Ad-aware 6\Ad-watch.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [Norton Antivirus AV] C:\WINDOWS\FVProtect.exe
O4 - HKLM\..\Run: [winupdates] C:\Program Files\winupdates\winupdates.exe /auto
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O16 - DPF: {03F998B2-0E00-11D3-A498-00104B6EB52E} - https://components.viewpoint.com/MTSInstallers/MetaStream3.cab?url=http://www.viewpoint.com/cgi-bin/installer.v4/vet_install_popup.pl?1&4&04.00.08.43&unknown&unknown&http://www.sci on.com/scionConfigApp/scion/viewsection.jsp?forceLoad=1
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,99/mcinsctl.cab
O16 - DPF: {8A0019EB-51FA-4AE5-A40B-C0496BBFC739} (Verizon Wireless Media Upload) - http://www.vzwpix.com/activex/VerizonWirelessUploadControl.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/mcgdmgr/1,0,0,26/mcgdmgr.cab
O23 - Service: distributed.net client (dnetc) - Distributed Computing Technologies, Inc. - C:\WINDOWS\System32\iosdt\iosdt.exe

IP: Logged

joemag7
Member
posted October 04, 2005 06:24 PM     Click Here to See the Profile for joemag7     Edit/Delete Message
Thanks, that HijackThis program seemed to find a couple things. Though I have a couple more problems on my laptop, I noticed when I ran adaware a couple days ago it said I had 33 running processes when there are normally 18, so I tried hitting Ctrl-Alt-Del to open the task manager, but it wouldn't work. And what scares me the most is my laptop fan used to come on maybe once a month and now it comes on about every 5 minutes. Please Help, Joe

IP: Logged

Josh1
Administrator
posted October 03, 2005 01:54 PM     Click Here to See the Profile for Josh1     Edit/Delete Message
Do you have MS Antispyware also installed? Is not go here http://www.footslog.com/board/Archives/Archive-000003/HTML/20050327-16-000026.html and download it and run it, also download Hijack this and post the results in that scan. That file if not deleted in the MS Antispyware scan should show up in Hijack scan, then we can delete it from that way.

------------------
Powered by Intelligent Computing Solutions.
------------------------
www.footslog.com

www.compsol.8k.com

For every problem, there is a solution.

Please give what you can to the Hurricane relief

http://www.microsoft.com/mscorp/citizenship/giving/relief.asp

IP: Logged

joemag7
Member
posted September 30, 2005 06:40 PM     Click Here to See the Profile for joemag7     Edit/Delete Message
I recently visited a site that tried to dump loads of spyware on me(it wasn't porn. My AdAware/AdWatch picked it up and I blocked it but it seems that something got through. Now every time I open a folder AdWatch pops up and says something is trying to change a registry value, and my Startup Monitor comes up and says a program called 'u19m8.exe\k' wants to run at system startup. I can't find the named program anywhere. I usually reformat every 6 months just to keep everything clean, and I guess it's time now. But future reference is there anything out there that can take care of a problem like this?

IP: Logged

All times are CT (US)

next newest topic | next oldest topic

Administrative Options: Close Topic | Archive/Move | Delete Topic
Post New Topic  Post A Reply
Hop to:

Contact Us | Footslog Home



Ad

The information presented on FootsloG.com is copyrighted as a collective work. FootsloG.com is free for personal use (non-commercial). Any other use FootsloG.com, including copying or reproducing any portion of this web site is strictly prohibited without the express written consent of FootsloG.com. If you have any questions about the usage term please contact us via email: webmaster@footslog.com.



Problems, Knowledge, and Power, powered by intelligent Computing Solutions