Please help I have spyware and loads of toolbars!!!!
Pleas help me I have an annoying blue toolbar at the bottom of my screen which I think is called Search now and I think I got it when i downloaded msn 7. 0 Beta. Does anyone know how to get rid off it or anything more about it.
Pleas help me I have an annoying blue toolbar at the bottom of my screen which I think is called "Search now" and I think I got it when i downloaded msn 7.0 Beta. Does anyone know how to get rid off it or anything more about it. If so please contact me at jonygyte@hotmail.com or post it here.
Also can anyone tell me any good free programs for removing spyware as I have loads of it on my PC I have tryed search and destroy and spyware docotr but they have been no use. I also have zonealarm firewall and AVG anti-virus but they dont seem to be doing much good can anybody tell me any beter ones?
Also can anyone tell me any good free programs for removing spyware as I have loads of it on my PC I have tryed search and destroy and spyware docotr but they have been no use. I also have zonealarm firewall and AVG anti-virus but they dont seem to be doing much good can anybody tell me any beter ones?
Participate on our website and join the conversation
This topic is archived. New comments cannot be posted and votes cannot be cast.
Responses to this topic
Originally posted by pretzel1:
Quote:Pleas help me I have an annoying blue toolbar at the bottom of my screen which I think is called "Search now" and I think I got it when i downloaded msn 7.0 Beta. Does anyone know how to get rid off it or anything more about it. If so please contact me at jonygyte@hotmail.com or post it here.
Get program called Hijack this, unzip it for example to "c:\hijack". Start it, click Scan. Then save the logfile and post it here.
Quote:Also can anyone tell me any good free programs for removing spyware as I have loads of it on my PC I have tryed search and destroy and spyware docotr but they have been no use.
Removing: Spybot - Search and Destroy, Adaware, BHODemon.
Preventing: SpywareBlaster.
These are what I have used.
Do these scans in safe mode.
Quote:I also have zonealarm firewall and AVG anti-virus but they dont seem to be doing much good can anybody tell me any beter ones?
Get AV called Avast! Home Edition. It is freeware and with it comes protections for IM, P2P, Email programs and limited "webshield".
Quote:Pleas help me I have an annoying blue toolbar at the bottom of my screen which I think is called "Search now" and I think I got it when i downloaded msn 7.0 Beta. Does anyone know how to get rid off it or anything more about it. If so please contact me at jonygyte@hotmail.com or post it here.
Get program called Hijack this, unzip it for example to "c:\hijack". Start it, click Scan. Then save the logfile and post it here.
Quote:Also can anyone tell me any good free programs for removing spyware as I have loads of it on my PC I have tryed search and destroy and spyware docotr but they have been no use.
Removing: Spybot - Search and Destroy, Adaware, BHODemon.
Preventing: SpywareBlaster.
These are what I have used.
Do these scans in safe mode.
Quote:I also have zonealarm firewall and AVG anti-virus but they dont seem to be doing much good can anybody tell me any beter ones?
Get AV called Avast! Home Edition. It is freeware and with it comes protections for IM, P2P, Email programs and limited "webshield".
ok this is what I found when I scanned my PC with hijack this.
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O4 - HKLM\..\Run: [flag proxy curb anti] C:\Documents and Settings\All Users\Application Data\bits ante flag proxy\BOOBSAFE.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
O4 - Global Startup: Shortcut to Startup.lnk = C:\WINDOWS\Startup.cmd
O10 - Broken Internet access because of LSP provider 'xfire_lsp_11078.dll' missing
O12 - Plugin for .mov: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.wanadoo.co.uk
O16 - DPF: cpcScanner - http://www.crucial.com/controls/cpcScanner.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
O16 - DPF: {4CC35DAD-40EA-4640-ACC2-A1A3B6FB3E06} (NeoterisSetup Control) - https://portal.kpmg.co.uk/dana-cached/setup/NeoterisSetup.cab
O16 - DPF: {E855A2D4-987E-4F3B-A51C-64D10A7E2479} - http://tools.ebayimg.com/eps/activex/EPSControl_v1-0-3-0.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{4F4CBD3A-9EB7-46D5-84E2-54E3F1156724}: NameServer = 195.92.195.95 195.92.195.94
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O4 - HKLM\..\Run: [flag proxy curb anti] C:\Documents and Settings\All Users\Application Data\bits ante flag proxy\BOOBSAFE.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
O4 - Global Startup: Shortcut to Startup.lnk = C:\WINDOWS\Startup.cmd
O10 - Broken Internet access because of LSP provider 'xfire_lsp_11078.dll' missing
O12 - Plugin for .mov: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.wanadoo.co.uk
O16 - DPF: cpcScanner - http://www.crucial.com/controls/cpcScanner.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
O16 - DPF: {4CC35DAD-40EA-4640-ACC2-A1A3B6FB3E06} (NeoterisSetup Control) - https://portal.kpmg.co.uk/dana-cached/setup/NeoterisSetup.cab
O16 - DPF: {E855A2D4-987E-4F3B-A51C-64D10A7E2479} - http://tools.ebayimg.com/eps/activex/EPSControl_v1-0-3-0.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{4F4CBD3A-9EB7-46D5-84E2-54E3F1156724}: NameServer = 195.92.195.95 195.92.195.94
OK.. Start in Safe mode. Then start hijack, rescan and Fix these:
Originally posted by pretzel1:
Quote:
Fix and delete this folder ("bits ante flag proxy")
O4 - HKLM\..\Run: [flag proxy curb anti] C:\Documents and Settings\All Users\Application Data\bits ante flag proxy\BOOBSAFE.exe
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
Gaobot Worm, delete this file and scan your system in safe mode with your AV scanner!
Removal instructions, read the section "5. Deleting the values from the registry":
http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.gaobot.ee.html
O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
Hmm.. check this file contents... or have you placed this here?
O4 - Global Startup: Shortcut to Startup.lnk = C:\WINDOWS\Startup.cmd
Get program called lspfix to fix this
O10 - Broken Internet access because of LSP provider 'xfire_lsp_11078.dll' missing
O16 - DPF: cpcScanner - http://www.crucial.com/controls/cpcScanner.cab
O16 - DPF: {4CC35DAD-40EA-4640-ACC2-A1A3B6FB3E06} (NeoterisSetup Control) - https://portal.kpmg.co.uk/dana-cached/setup/NeoterisSetup.cab
O16 - DPF: {E855A2D4-987E-4F3B-A51C-64D10A7E2479} - http://tools.ebayimg.com/eps/activex/EPSControl_v1-0-3-0.cab
Now still in safe mode, scan your system with AV, SpyBot, adaware, e.g.
Originally posted by pretzel1:
Quote:
Fix and delete this folder ("bits ante flag proxy")
O4 - HKLM\..\Run: [flag proxy curb anti] C:\Documents and Settings\All Users\Application Data\bits ante flag proxy\BOOBSAFE.exe
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
Gaobot Worm, delete this file and scan your system in safe mode with your AV scanner!
Removal instructions, read the section "5. Deleting the values from the registry":
http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.gaobot.ee.html
O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
Hmm.. check this file contents... or have you placed this here?
O4 - Global Startup: Shortcut to Startup.lnk = C:\WINDOWS\Startup.cmd
Get program called lspfix to fix this
O10 - Broken Internet access because of LSP provider 'xfire_lsp_11078.dll' missing
O16 - DPF: cpcScanner - http://www.crucial.com/controls/cpcScanner.cab
O16 - DPF: {4CC35DAD-40EA-4640-ACC2-A1A3B6FB3E06} (NeoterisSetup Control) - https://portal.kpmg.co.uk/dana-cached/setup/NeoterisSetup.cab
O16 - DPF: {E855A2D4-987E-4F3B-A51C-64D10A7E2479} - http://tools.ebayimg.com/eps/activex/EPSControl_v1-0-3-0.cab
Now still in safe mode, scan your system with AV, SpyBot, adaware, e.g.