Dan Clark Posted February 26, 2006 Report Share Posted February 26, 2006 A few weeks ago, my brother went on my computer, went on some gaming sites so it seems, and has lumbered with with 5497895762396 spyware programs.Noticable ones are "gimmygames", "freeprod" and "findthewebsiteyouneed.com". I keep deleting these, but they come back in a few minutes.Whenever I'm on firefox, whatever page I'm on changes to some random advert site, it does this every few minutes.So far I'm running Ad-Aware and Spybot search and destroy, they find things and delete them, but it doesn't fix my problem.Please help TF, I don't want all the hassle of backing up hundreds of tv shows on my ipod again. Quote Link to comment Share on other sites More sharing options...
Danny Posted February 26, 2006 Report Share Posted February 26, 2006 Run spybot and adaware in safemode then without rebooting fire up 'hijack this' and use it to remove anything suspicious from internet explorer.Edit my hijack this list looks something like......[attachmentid=2769]if you post up a screenshot of your hijack this ill try give you a list of what you can delete Quote Link to comment Share on other sites More sharing options...
Dan Clark Posted February 26, 2006 Author Report Share Posted February 26, 2006 Logfile of HijackThis v1.99.1Scan saved at 18:23:16, on 26/02/2006Platform: Windows ME (Win9x 4.90.3000)MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)Running processes:C:\WINDOWS\SYSTEM\KERNEL32.DLLC:\WINDOWS\SYSTEM\MSGSRV32.EXEC:\WINDOWS\SYSTEM\mmtask.tskC:\WINDOWS\SYSTEM\MPREXE.EXEC:\WINDOWS\SYSTEM\MSTASK.EXEC:\WINDOWS\SYSTEM\SSDPSRV.EXEC:\WINDOWS\SYSTEM\STIMON.EXEC:\WINDOWS\EXPLORER.EXEC:\WINDOWS\RUNDLL32.EXEC:\WINDOWS\WINSYSBAN11.EXEC:\WINDOWS\ZGVMYXVSDAAA\COMMAND.EXEC:\PROGRAM FILES\SPYBOT - SEARCH & DESTROY\TEATIMER.EXEC:\WINDOWS\SYSTEM\RESTORE\STMGR.EXEC:\WINDOWS\ALL USERS\START MENU\PROGRAMS\STARTUP\SVCHOST.EXEC:\PROGRAM FILES\TMENTOR\MENTOR FOR WINME\MINITRAY.EXEC:\PROGRAM FILES\WINZIP\WZQKPICK.EXEC:\PROGRAM FILES\RALINK\RT2500 WIRELESS LAN CARD\INSTALLER\WINME\RACONFIG2500.EXEC:\PROGRAM FILES\OPENOFFICE.ORG 2.0\PROGRAM\SOFFICE.EXEC:\PROGRAM FILES\OPENOFFICE.ORG 2.0\PROGRAM\SOFFICE.BINC:\WINDOWS\SYSTEM\DDHELP.EXEC:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXEC:\WINDOWS\TEMP\TD_0001.DIR\HIJACKTHIS.EXER1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blankR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blankR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blankR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blankR0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R3 - Default URLSearchHook is missingO3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCXO4 - HKLM\..\Run: [p2pnetworking] P2PNETWORKING.EXEO4 - HKLM\..\Run: [winsysupd] C:\WINDOWS\WINSYSUPD11.exeO4 - HKLM\..\Run: [winsysban] C:\WINDOWS\WINSYSBAN11.exeO4 - HKLM\..\Run: [gimmygames] C:\WINDOWS\GIMMYGAMES11.exeO4 - HKLM\..\Run: [Command] C:\WINDOWS\ZGVmYXVsdAAA\command.exeO4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrSchemeO4 - HKLM\..\RunServices: [schedulingAgent] mstask.exeO4 - HKLM\..\RunServices: [sSDPSRV] C:\WINDOWS\SYSTEM\ssdpsrv.exeO4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exeO4 - HKLM\..\RunServices: [PCCIOMON.EXE] "C:\Program Files\Trend PC-cillin 2000\PCCIOMON.EX_"O4 - HKLM\..\RunServices: [stillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXEO4 - HKLM\..\RunServices: [p2pnetworking] P2PNETWORKING.EXEO4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /backgroundO4 - HKCU\..\Run: [Free Download Manager] C:\Program Files\Free Download Manager\fdm.exe -autorunO4 - HKCU\..\Run: [CU1] C:\Program Files\Common Files\VCClient\VCClient.exeO4 - HKCU\..\Run: [CU2] C:\Program Files\Common Files\VCClient\VCMain.exeO4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exeO4 - Startup: Mentor Tray Icon.lnk = C:\Program Files\tMentor\Mentor for WinMe\minitray.exeO4 - Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXEO4 - Startup: RaConfig2500.lnk = C:\Program Files\RALINK\RT2500 Wireless LAN Card\Installer\WINME\RaConfig2500.exeO4 - Startup: OpenOffice.org 2.0.lnk = C:\Program Files\OpenOffice.org 2.0\program\quickstart.exeO4 - Global Startup: svchost.exeO9 - Extra button: Mentor - {3892CA40-9B9A-11d4-8D73-00105A296A2A} - "C:\Program Files\tMentor\Mentor for IE5\IE5Help.chm" (file missing)O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRAM FILES\JAVA\JRE1.5.0_06\BIN\SSV.DLLO9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRAM FILES\JAVA\JRE1.5.0_06\BIN\SSV.DLLO15 - Trusted Zone: *.line6.netO16 - DPF: {D1E7CBDA-E60E-4970-A01C-37301EF7BF98} - http://gameadvisor.futuremark.com/global/msc37.cab Quote Link to comment Share on other sites More sharing options...
AndyT Posted February 26, 2006 Report Share Posted February 26, 2006 I don't know what happened, but yesterday my comptuer wouldn't turn on...i had to do soooooooooo much shit to get it to work- and now I have to reinstall ALL of my old programs, and set all of my old settings.......I had to freaking spend like 3 hours in a command prompt typing in old school shit though, gave me good memories of the old days......f**k it was horrible. Quote Link to comment Share on other sites More sharing options...
trials_pimp Posted February 26, 2006 Report Share Posted February 26, 2006 I had this last week.You have coolwebsearch.It downloads all those links you have, and its a registry file that spybot, Adaware ect cant get rid of.all the time you have it it will constantly download other programes, and what mine did, start controling your computer.I had to format to get rid of it. You mind find its still in the registry if you only rolled drivers back Quote Link to comment Share on other sites More sharing options...
Danny Posted February 26, 2006 Report Share Posted February 26, 2006 For starters you can try CWShredder which is supposed to remove coolwebsearch. Found here http://www.intermute.com/spysubtract/cwshr...r_download.htmlThen if that doesnt work run spyboy and adaware in SAFE MODE the run hijack this and remove all the stuff with x's next to em xx R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blankxx R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blankxx R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blankxx R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blankxx R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = xx R3 - Default URLSearchHook is missingxx O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCXxx O4 - HKLM\..\Run: [p2pnetworking] P2PNETWORKING.EXExx O4 - HKLM\..\Run: [winsysupd] C:\WINDOWS\WINSYSUPD11.exexx O4 - HKLM\..\Run: [winsysban] C:\WINDOWS\WINSYSBAN11.exexx O4 - HKLM\..\Run: [gimmygames] C:\WINDOWS\GIMMYGAMES11.exexx O4 - HKLM\..\Run: [Command] C:\WINDOWS\ZGVmYXVsdAAA\command.exeO4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrSchemeO4 - HKLM\..\RunServices: [schedulingAgent] mstask.exeO4 - HKLM\..\RunServices: [sSDPSRV] C:\WINDOWS\SYSTEM\ssdpsrv.exeO4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exeO4 - HKLM\..\RunServices: [PCCIOMON.EXE] "C:\Program Files\Trend PC-cillin 2000\PCCIOMON.EX_"xx O4 - HKLM\..\RunServices: [stillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXExx O4 - HKLM\..\RunServices: [p2pnetworking] P2PNETWORKING.EXEO4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /backgroundxx O4 - HKCU\..\Run: [Free Download Manager] C:\Program Files\Free Download Manager\fdm.exe -autorunxx O4 - HKCU\..\Run: [CU1] C:\Program Files\Common Files\VCClient\VCClient.exexx O4 - HKCU\..\Run: [CU2] C:\Program Files\Common Files\VCClient\VCMain.exeO4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exexx O4 - Startup: Mentor Tray Icon.lnk = C:\Program Files\tMentor\Mentor for WinMe\minitray.exeO4 - Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXEO4 - Startup: RaConfig2500.lnk = C:\Program Files\RALINK\RT2500 Wireless LAN Card\Installer\WINME\RaConfig2500.exeO4 - Startup: OpenOffice.org 2.0.lnk = C:\Program Files\OpenOffice.org 2.0\program\quickstart.exeO4 - Global Startup: svchost.exexx O9 - Extra button: Mentor - {3892CA40-9B9A-11d4-8D73-00105A296A2A} - "C:\Program Files\tMentor\Mentor for IE5\IE5Help.chm" (file missing)xx O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRAM FILES\JAVA\JRE1.5.0_06\BIN\SSV.DLLxx O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRAM FILES\JAVA\JRE1.5.0_06\BIN\SSV.DLLxx O15 - Trusted Zone: *.line6.netxx O16 - DPF: {D1E7CBDA-E60E-4970-A01C-37301EF7BF98} - http://gameadvisor.futuremark.com/global/msc37.cab Quote Link to comment Share on other sites More sharing options...
Dan Clark Posted February 26, 2006 Author Report Share Posted February 26, 2006 That thing found no signs of coolwebsearch on my computer.Just done your thing Danny, lets hope it works out http://www.uniqueoffer-s.com/normal/yyy102.htmlI just got redirected to that Seems a bit better though, theres less interruptions. Quote Link to comment Share on other sites More sharing options...
omgnoseat Posted February 26, 2006 Report Share Posted February 26, 2006 you could try these programs:http://www.ewido.net/en/download/http://www.javacoolsoftware.com/spywareblaster.htmlhttp://www.pctools.com/spyware-doctor/?ref=d6did wonders for me when i had the terrible ´´spyaxe´´ virus, i still got nightmares about it Quote Link to comment Share on other sites More sharing options...
Si-man Posted February 26, 2006 Report Share Posted February 26, 2006 Did a scan on my comp for spyware etc, found f**kin loads!!!! Thats off a week of not using it, shitties Found 1000 registry faults lol Quote Link to comment Share on other sites More sharing options...
anzo Posted February 26, 2006 Report Share Posted February 26, 2006 Lavasoft.Go there, under the 'Products' section click AdAware Personal, download it and scan your computer.After the scan, click all the tick boxes to delete the items, click next/finish and it'll delete them all. Piss easy. Quote Link to comment Share on other sites More sharing options...
Janson Posted February 26, 2006 Report Share Posted February 26, 2006 So far I'm running Ad-Aware and Spybot search and destroy, they find things and delete them, but it doesn't fix my problem. Quote Link to comment Share on other sites More sharing options...
Dan Clark Posted February 26, 2006 Author Report Share Posted February 26, 2006 Thank you Janson.Well, it has improved, still not totally gone though. Quote Link to comment Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.