Home > Anyone Familiar > Anyone Familiar With Spysubract

Anyone Familiar With Spysubract

I would like for you to submit this file for analysis: winspl32.dll Please go to BC's Malware Submission page and fill in all the fields.In the Browse to the file you Register a free account to unlock additional features at BleepingComputer.com Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. or read our Welcome Guide to learn how to use this site. Take a look at the bottom of my post and run the two online virus scans. his comment is here

Several functions may not work. Click here to join today! Else sites like this will go the way of the Dodo. (Click Me) Back to top #11 jonowalsh2005 jonowalsh2005 Topic Starter Members 16 posts OFFLINE Location:church accrington lancashire Local time:12:26 Should I delete the files that are not from the System32 folder? https://forums.techguy.org/threads/anyone-familiar-with-spysubract.291901/

Inc. - C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exeO23 - Service: Virtual NIC Service - America Online, Inc. - C:\WINDOWS\System32\PackethSvc.exeO23 - Service: Sygate Personal Firewall - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exeO23 - Service: TuneUp WinStyler Theme Else sites like this will go the way of the Dodo. (Click Me) Back to top #9 mattie mattie Topic Starter Members 32 posts OFFLINE Local time:12:26 PM Posted 07 I'm not bad mouthing Intermute at all, their products may be fine but I don't like having things installed when I don't ask for them if you get my drift.Yes.

Now run Swap.bat as instructed above. Anyway I did reformat and protect myself first before connecting to the internet. (Note - I have DSL and had forgotten to unplug it while I was setting up.) You can I had reformatted and connected to the internet before I put up my firewall and AV. Options Mark as New Bookmark Subscribe Subscribe to RSS Feed Highlight Print Report JohnB.....

Select Desktop>OK.That will put HijackThis.exe on your Desktop. Still in safe mode, this process will clean out your Temp files and your Temporary Internet Files. It can if you set it up to run the > teatimer (and you have an older slower PC) Thanks for the info. http://spywarewarrior.com/asw-test-guide.htm Bill ___________________________________________________________________Good judgement comes from experience, most of which came from bad judgement. 0 Kudos Posted by johnblaustein ‎01-10-2005 11:10 PM Regular Contributor View All Member Since: ‎12-25-2004 Posts: 143

Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Messenger\ycomp.dll O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: Google My apologies. night and some other problems.Your lad doesn't seem to have changed anything in the log. Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Messenger\ycomp.dll O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: Google

Track this discussion and email me when there are updates If you're asking for technical help, please be sure to include all your system info, including operating system, model number, and All rights reserved. You can hold off on using HijackThis to fix it for now if that's the case. Style Default Style Contact Us Help Home Top RSS Terms and Rules Copyright © TechGuy, Inc.

Since you're running an older version of McAfee and AVG sems to be working OK, I would go with the first option for now until I can check on some things this content Scan with HijackThis and put a check next to the following line: O23 - Service: Virtual NIC Service - America Online, Inc. - C:\WINDOWS\System32\PackethSvc.exe With all other windows closed, click Fix Click Next, then Browse.4. You can also load AdAware and Spybot Search and Destroy - link also at bottom of my post - and run those.

Edited by mattie, 05 February 2005 - 06:18 PM. I'm not familiar with McAfee, check your documentation for how to uninstall the antivirus portion of the VirusScan6 suite. As a rule of thumb, it is not a good idea to have more than one program designed to do the same thing running at the same time, as they might http://zenproject8reviews.com/anyone-familiar/anyone-familiar-w-act-9-0.html John 0 Kudos 19 REPLIES Posted by Mamoo ‎01-10-2005 01:38 PM Most Valued Poster View All Member Since: ‎07-18-2003 Posts: 7,832 Message 2 of 20 (273 Views) Re: SpySubtract -- anyone

I think it's great you are offering your help here - much appreciated ! Ok, I was helping a user over @ CCSP and she said she had run SpySweeper and SpySubtract (http://www.spysubtract.com). Else sites like this will go the way of the Dodo. (Click Me) Back to top #3 mattie mattie Topic Starter Members 32 posts OFFLINE Local time:12:26 PM Posted 31

As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged

Anyway, I had to reformat again because the file kept popping back up every time I deleted it. If your system does not have this kind of spyware, it will give you the good news.Cost: Freehttp://www.intermute.com/spysubtract/cwshr...r_download.htmlHijack This and a variety of other tools for malware and pestwarehttp://216.180.233.162/~merijn/files/HijackThis.exe orhttp://www.spywareinfo.com/~merijn/downloads.htmlWeb based Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Messenger\ycomp.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE O4 - Logfile of HijackThis v1.98.2 Scan saved at 13:50:42, on 01/31/2005 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE

So please do this:Scan with HijackThis, and check the following entry:R3 - Default URLSearchHook is missingWith all other windows closed, click Fix Checked, close HijackThis, REBOOT, then post a fresh log.Then A case like this could easily cost hundreds of thousands of dollars. Else sites like this will go the way of the Dodo. (Click Me) Back to top #5 mattie mattie Topic Starter Members 32 posts OFFLINE Local time:12:26 PM Posted 01 http://zenproject8reviews.com/anyone-familiar/anyone-familiar-with-this.html and here is my latest log file:Logfile of HijackThis v1.99.0Scan saved at 16:00:52, on 02/07/2005Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\spoolsv.exeC:\WINDOWS\System32\PackethSvc.exeC:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exeC:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exeC:\PROGRA~1\CACHEM~1\CachemanXP.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\Explorer.EXEC:\WINDOWS\system32\LVCOMSX.EXEC:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exeC:\Program Files\LIUtilities\SpeedUpMyPC\speedupmypc.exeC:\Program Files\Messenger\msmsgs.exeC:\Program Files\Sygate\SPF\smc.exeC:\PROGRA~1\McAfee\SPAMKI~1\MSKAgent.exeC:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exeC:\Program Files\Outlook Express\msimn.exeC:\Program

Once again helps for the advice. Generally there is no conflict between these and you should always run several)AdAware: http://www.lavasoftusa.com/software/adaware/Microsoft Antispyware Beta: http://www.microsoft.com/athome/security/s...re/default.mspxSpywareBlaster: http://www.javacoolsoftware.com/spywareblaster.htmlSpybot S&D: http://www.safer-networking.org/en/index.htmlMicrosoft Malicious Software Removal Tool (Win XP and Win 2000):http://www.microsoft.com/security/malwareremove/default.mspxA - Free They check for the spyware/adware/malware. Run CWShredder after installing, and have it look for updates.

For information on the program click here.We ask that you post publicly so people with similar questions may benefit from the conversation.Was your question answered? Share Options Subscribe to RSS Feed Mark Topic as New Mark Topic as Read Float this Topic to the Top Bookmark Subscribe Printer Friendly Page All Forum Topics Previous Topic Next I have Spybot autoscan eveynight. When that has completed, click on the Compare button.

The Trojan takes advantage of a flaw in a key component of Windows -- Microsoft's version of the Java Virtual Machine -- to install itself via popups often found on porn SHOW ME NOW CNET © CBS Interactive Inc.  /  All Rights Reserved. PC are pre-installed with software that is not requested by the user Answer is uninstall or reformat if they are nasty LOL Flag Permalink This was helpful (0) Collapse - Re: