Welcome Guest ( Log In | Register )

Bump Topic Topic Closed RSS Feed

Outline · [ Standard ] · Linear+

 Spyware & Browser Hijack removal & links

views
     
sUBs
post May 2 2005, 02:42 PM

RIP
Group Icon
VIP
3,941 posts

Joined: Jan 2005
QUOTE(shinjite @ May 1 2005, 08:01 PM)
I checked my system dun have the CNS.EXE or the CnsMinkp.sys posted by lex
Wooh...lucky sweat.gif
*

Simplest way to check would be to fire up IE & do a simple keyword search.

If it doesn't automatically redirect you to a chinese website, you should be okay. smile.gif

sUBs
post Jun 22 2005, 02:32 PM

RIP
Group Icon
VIP
3,941 posts

Joined: Jan 2005
QUOTE(jimmylim85 @ Jun 22 2005, 07:51 AM)
Im struck with 2 diffrent POP up Ads... very hard to removed as it can self regenerated even after removal.

one of the ads came from www.chauxn.com.cn and the other from www.myip.com

Please guide me how to remove it.
*
Here's what you can do....

AdAware SE v1.06

Download, install, update, configure and run a scan with Ad-aware SE v1.06:
  1. Download and Install AdAware SE Personal, keeping the default options. However, some of the settings will need to be changed before your first scan.
  2. Close ALL windows except Ad-Aware SE.
  3. Click on the'world' icon at the top right of the Ad-Aware SE window and let AdAware SE update the reference list for the adware and malware.
  4. Once the update is finished click on the 'Gear' icon (second from the left at the top of the window) to access the preferences/settings window:
    1. In the 'General' window make sure the following are selected in green:
      1. Under Safety:
        • Automatically save log-file
      2. Automatically quarantine objects prior to removal
      3. Safe Mode (always request confirmation)
    2. Under Definitions:
      • Prompt to update outdated definitions - set the number of days
  5. Click on the 'Scanning' button on the left and select in green:
    1. Under Driver, Folders & Files:
      • Scan Within Archives
    2. Under Select drives & folders to scan:
      • choose all hard drives
    3. Under Memory & Registry: all green
      • Scan Active Processes
      • Scan Registry
      • Deep Scan Registry
      • Scan my IE favorites for banned URL's
      • Scan my Hosts file
  6. Click on the 'Advanced' button on the left and select in green:
    1. Under Shell Integration:
      • Move deleted files to recycle bin
    2. Under Logfile Detail Level: all green
      • include addtional object information
      • DESELECT - include negligible objects information
      • include environment information
    3. Under Alternate Data Streams:
      • Don't log streams smaller than 0 bytes
      • Don't log ADS with the following names: CA_INOCULATEIT
  7. Click the 'Tweak' button and select in green:
    1. Under 'Scanning Engine':
      • Unload recognized processes during scanning
      • Scan registry for all users instead of current user only
    2. Under 'Cleaning Engine':
      • Let Windows remove files in use at next reboot
    3. Under Log Files:
      • Include basic Ad-aware SE settings in logfile
      • Include additional Ad-aware SE settings in logfile
      • Please do not Select: Include Module list in logfile
  8. Click on 'Proceed' to save the settings.
  9. Click 'Start'
  10. Choose 'Perform Full System Scan'
  11. DESELECT "Search for negligible risk entries", as negligible risk entries (MRU's) are not considered to be a threat.
  12. Click 'Next' and Ad-Aware SE will scan your hard drive(s) with the options you have selected and clean automatically.
  13. If Ad-Aware SE finds bad entries, you will receive a list of what it found in the window
  14. Right-click on the list and choose Select All
  15. Click the Next button to finish removing the items that were found
  16. When finished, REBOOT to complete the removal of what Ad-Aware SE found

~~~~~~~~~~~~~~~

Download, Install & Run Spybot S&D. Click on the "Search for Updates" button. Install any updates that are available.

Go to the Mode menu and choose "Advanced Mode". Next click on Immunize to your left. Click the Immunize button (green cross) on top to Immunize your computer - you should do this each time there is an update.

Now click on the 'Spybot-S&D' option on the top left to go back to the main screen. Next click on the 'Check for Problems' button. Let it run the scan. If it finds something, Select all those in RED and hit the 'Fix Selected Problems' button. Exit Spybot.

If you keep getting the DSO Exploit entries, even after you updated Windows and fixed them, then download the Spybot DSO Exploit Fix and install it over the current Spybot installation.


~~~~~~~~~~~~~~~

After running the above programs, download HiJackThis - this program will help us determine if there are any spyware/malware on your computer. Create a folder at C:\HJT and move HiJackThis.exe there. Double click on the program to run it.

1. If it gives you an intro screen, just choose 'Do a system scan and save a logfile'.
2. If you don't get the intro screen, just hit "Scan" and then click on "Save log".
3. Post the HiJackThis.log file in a new thread. Click here >> http://forum.lowyat.net/index.php?act=Post&CODE=00&f=25
. Do not fix anything in HiJackThis since they may be harmless.
sUBs
post Jul 12 2005, 01:16 PM

RIP
Group Icon
VIP
3,941 posts

Joined: Jan 2005
QUOTE(benlye @ Jul 12 2005, 10:37 AM)
Here is something intresting. A site which has information on all known spyware and adware..

---------------------
http://www.spywareinfo.com/
user posted image

SpywareInfo is a member of ASAP

ASAP stands for the Alliance of Security Analysis Professionals.

ASAP started out as a small band of security sites under seige, and is rapidly expanding to include the "Best of the Best" the Internet Security Community has to offer.

ASAP is made up of website and forum owners and administrators, forum and site staff, individuals, companies and various organizations dedicated to providing security related support to computer end users.

ASAP is a joint effort designed to assist helping end users with as seamless a process as possible by using methods such as cross-referrals, multiple product support services, easy information access, and cross referencing/verification.

ASAP's goals are:
To ensure a high standard and quality of security support no matter where you seek help.
To promote the products used to keep your computer clean and safe in an equal and fair manner.
To ensure that end users are not affected by so called "product wars" and unfair marketing tactics which have plagued several industries in recent years.

ASAP ensures that quality support and assistance will be freely available - knock one of the support networks out and another will pick it up immediately. In addition, pooled resources permit the ability to provide support redundancy, thereby adding an additional layer of protection against Internet based threats.

If you see the ASAP logo or banner used by a site, bulletin board, or person, you can be assured that you're getting the best support and assistance possible, as the combined efforts of all ASAP members are involved in helping everyone, and ASAP won't give up until your important investment is safe and clean.

ASAP is a non-profit volunteer network.

Member Sites of ASAP
AmazingTechs
Anti Spyware Offensief
Assiste.com
Atribune.org
BestTechie
BleepingComputer
Bluetack Internet Security Solutions
Calendar of Updates
CARMA
Common Sense Security
CPASecurity
CyberAnswers.org
Freedomlist
Geeks to Go
Gladiator Security
hpHosts
InfoSpyware
Infotex
JSKYs XP Support
Linha Defensiva
Lockergnome
MalwareBytes
MalWare Removal
ManageYourPC
MickeyTheMan
NeoPlanet
NetworkTechSupport
PCdistress
PCHelper
PC Pitstop
PCtorium
Pipex Support
RescueME
Short-Media.com
SpywareAid
SpyWare BeWare!
Spywarefri
SpywareInfo
Spyware Warrior
Subratam.org
Tankweb
Tech Support Forum
Tech Support Guy
TeMerc Internet Countermeasures
That Computer Guy
The Spykiller
TomCoyote
UBCD4Win
Vital Security.org

sUBs
post Jul 21 2005, 11:43 AM

RIP
Group Icon
VIP
3,941 posts

Joined: Jan 2005
@servonet.

If you want something to be done about your malware problems, you have to furnish us with a HiJackThis log.
If unsure how to do it, here are some instructions...

Download HiJackThis - this program will help us determine if there are any spyware/malware on your computer.
Create a folder at C:\HJT and move HiJackThis.exe there.
Double click on the program to run it.

1. If it gives you an intro screen, just choose [Do a system scan and save a logfile].
2. If you don't get the intro screen, just hit [Scan] and then click on [Save log].
3. Post the HiJackThis.log file here. Do not fix anything in HiJackThis since most of the entries may be harmless

When you have a log, start a new thread by clicking here

I shall help you when I see your new thread.


sUBs
sUBs
post Jul 21 2005, 10:08 PM

RIP
Group Icon
VIP
3,941 posts

Joined: Jan 2005
QUOTE(gestapo @ Jul 21 2005, 03:49 PM)
a noob question.

when i installed warez does it means than i allow them to enable pop up on my pc??..bcoz i notice that my yahoo pop up blocker is gone. and the windows antispyware alway giving warning about warez trying to install sum stuff..help pls
*
I have a simple way for you to find out on your own.

Download Trend Micro(tm) Anti-Spyware for the Web Utility (by clicking the "Scan and Clean your PC" button).
  • Save it to your desktop.
  • Double-click the new icon on your desktop (tmas-web-scan.exe)
  • It will say "Loading TrendMicro definitions".
  • Once the definitions are loaded, the program will appear to close then re-open.
  • Click "Start Scan"
  • After it's done scanning, click "Scan Results"
  • Make sure all items found have a check next to them, then click "Clean Threats Now".
  • Click Exit.
Reboot your computer. In place of the TrendMicro icon will be a text file called "Antispyware.log".
If you wish, you may share the details with other LYF members by pasting the entire contents of that log here.
sUBs
post Jul 24 2005, 08:49 AM

RIP
Group Icon
VIP
3,941 posts

Joined: Jan 2005
QUOTE(Jayken @ Jul 24 2005, 08:35 AM)
I'm sorry if i post something wrong here. But i really need some help on this problem sweat.gif Hm... I just formatted my pc, after i get online i found this problem.

What actually happens? Getting Spyware?
*
Download & Run Shoot the Messenger. Disable Messenger service & that should be the end of your woes yawn.gif
sUBs
post Jul 24 2005, 09:16 AM

RIP
Group Icon
VIP
3,941 posts

Joined: Jan 2005
QUOTE(Jayken @ Jul 24 2005, 08:57 AM)
hmm. can i ask more? what possible reason i may cause that messenger popup? windows problem? or?
*
Read up on it here > http://www.grc.com/stm/shootthemessenger.htm
Feel free to ask if still in doubt

sUBs
sUBs
post Jul 27 2005, 08:09 AM

RIP
Group Icon
VIP
3,941 posts

Joined: Jan 2005
QUOTE(wakl @ Jul 27 2005, 06:19 AM)
Wondernig why my sent and receive the sent will more than the receieve ?? and i tried to use hijackthis spyware doctor etc to scan but nothing happen...
*
@wakl
I have already moved your post to a new thread. You know where it is. http://forum.lowyat.net/index.php?showtopic=180575

You already have a thread dedicated to your problem. Please do not post in this sticky.
sUBs
post Jul 29 2005, 12:16 PM

RIP
Group Icon
VIP
3,941 posts

Joined: Jan 2005
sUBs ...coughing blood.. vmad.gif shakehead.gif

lanroba - click here < Post new topic > to start a new thread & post that log there.
sUBs
post Jul 31 2005, 02:09 PM

RIP
Group Icon
VIP
3,941 posts

Joined: Jan 2005
QUOTE(lanroba @ Jul 31 2005, 01:42 PM)
how? click PM?
*
Hee..hee

Quite simple. Just go to this page > http://forum.lowyat.net/index.php?showforum=25
Locate & click the user posted image button. It's situated near the top & to the right hand side.

I'm not trying ot make life difficult for you. This is help you become more familiar with the forum's features so that you can be more of a regular member at LYF. tongue.gif


sUBs
sUBs
post Aug 5 2005, 03:25 AM

RIP
Group Icon
VIP
3,941 posts

Joined: Jan 2005
Uninstall List - Add/Remove Programs

180 Solutions
180SAInstaller Class
180 Search Assistant
2020Search
404Search
411Ferret Toolbar
7FaSSt Search
The ABI Network- A Division of Direct Revenue (online uninstallation)
Active Alert
Ad Service
Advanced Search
AdvSearch
AdwareAlert
Alexa Toolbar
AM Server
ATP
autoSearch
B3d Projector
Bargain Buddy / Bulls Eye Network / CashBack / NaviSearch
BookedSpace
Browser Enhancer
BrowserAid
BrowserPal
Bulls Eye Network / CashBack / NaviSearch / Bargain Buddy
Cash Toolbar
CashBack / NaviSearch / Bargain Buddy / Bulls Eye Network
Chinese keywords
ClickTheButton
ClockSync
CommonName
Context Display
Cosmi
Cpr
CxtPls
DailyToolbar
Date Manager
DealHelper
DelFin Media Viewer / PgTools / PGate / DisplayUtility / DMVLite
Desktop Toolbar [WhenUSearch]
Download Receiver
DownloadWare
E2Give Browser Add On
Easy Search Bar
Ebates_MoeMoneyMaker
Elite SideBar
Elite ToolBar
eXact Search Bar
ezSearchBar
F1
FlashTrack Uninstall
flt
FreeScratchAndWin
FT Remove
FTApp
Fun Web Products Easy Installer
eXact Search Bar
eZula TopText
Gator eWallet
Go
GogoTools
Hotbar
Huntbar
Httper
Hyperlinker
IconForge
IE Helper
IE Menu Extension toolbar
IE Toolbar
IEDriver
IMZ
InetDoor
Internet 404 (internet connection is needed for removal)
Internet Optimizer
Internet Washer Pro
IPInsight
ISTBar
ISTSvc
iWon Plus
KeenValue
KeywordPlugin
Live 0n line Portal
LookSmart Search
L.O P. Uninsta11
Lycos Search
Lycos Sidesearch
masterbarHallmedia.net
MaxSpeed
mc
Media Access
Media Motor
MidADdle
MoreResults
Movie Viewer 2.1
MS AUpdate
MS Updates
mscman
MSIETS
MWSearch
My Way Speedbar
My Web Search
NavExcel Search Toolbar
Nav Helper
NaviSearch / Bargain Buddy / Bulls Eye Network / CashBack
Neo Technology Search Engine
Netpal Games
NewtonKnows
Oemji Toolbar
Onflow
Orbit
PeopleOnPage
PowerSearch Toolbar
PowerStrip
Precision Time
Preview AdService
POP
PuritySCAN
qidion - toolbar
Quick Browse ??
QuickSearch Toolbar
RapidBlaster
RelatedLinks
Rich Editor
RON Display
RSyncMon
RVP
SafeGuard
Save / WhenU Search / WeatherCast / ClockSync
Security IGuard
Search 2020
Search Assistant
Search Assistant Utility
Search Fast
Search Maid
Search Relevancy
Search Toolbar (internet connection is needed for removal)
Searchit - toolbar
SearchSquire
Select Cashback
ShopAtHomeSelect Agent
Shopping Community
Side Find
Side Search
SideStep
Slotchbar
Software Update Manager
supaseek - Toolbar
SuperBar IE Plugin
Surf SideKick 3
Surfairy
SysAI
TBPS
Tools for Internet Explorer (internet connection is needed for removal)
Toolbar - My toolbar
TopText
TSA
TV Media
Twaintech
UCmore
Ultimate Browser Enhancer
URL Display
VBRunDLL
Veevo
Virtual Maid
VVSN
WareOut
WAST
Web Offer
Web_Rebates
WebHancer
Web Toolbar
Web Tools by Hotbar
whazit tools
WhenU Search / Save / WeatherCast / ClockSync
WhileYouSurf
WinSrv Reg
wincomp
Windows SyncroAd
wintrim
WebSearch Toolbar (internet connection is needed for removal)
WebSearch Tools
Windows AdTools
Windows AFA Internet Enhancement
WinTools
Win-Tools Easy Installer (internet connection is needed for removal)
WSEM Update
XDiver
Your Site Bar
YuupSearch Toolbar
Zango
Zipclix
ZZ

sUBs
post Aug 24 2005, 12:29 AM

RIP
Group Icon
VIP
3,941 posts

Joined: Jan 2005
You should have uninstalled the programs with Add/Remove programs before allowing the antivirus to forcibly remove them. It may leave several orphaned entries in your Registry.

Try this first..

Download Trend Micro(tm) Anti-Spyware (by clicking the "Scan and Clean your PC" button).
  • Double-click the tmas-web-scan.exe icon
  • It will say "Loading TrendMicro definitions".
  • Click "Start Scan"
After it's done scanning, click "Scan Results"
  • Make sure all items found have a check next to them, then click "Clean Threats Now".
  • Click Exit.

It's quite good at removing such entries.

If that doesnt work, run HijackThis
Go to Config > Misc Tools - Open Uninstall Manager
Select the program & click "Delete this entry"


Topic ClosedOptions
 

Change to:
| Lo-Fi Version
0.0210sec    0.42    7 queries    GZIP Disabled
Time is now: 15th December 2025 - 05:48 PM