Forum Home
Press F1
 
Thread ID: 86211 2008-01-08 16:08:00 New SpyBot Problem..DANGER DANGER! SurferJoe46 (51) Press F1
Post ID Timestamp Content User
628376 2008-01-08 16:08:00 OK...I installed the new beta version of Spybot on just this ONE computer...and this morning on reboot I am seeing that I am a victim of a fraudulent installation or pirated software with that nag toast running into here ever 10 minutes or so.

The entry that Spybot seems to have blocked is:

HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Run\ctfmon.exe=C:\WINDOWS\system32\ctfmo n.exe

Now does anyone have any idea where SpyBot has changed this setting?

I got that little blue star next to my clock now...and this site will not open:
www.microsoft.com

....so I cannot get any info as to what to do...and why ME!?!

I had to send this from my main computer as the Dell is being denied internet access...but I can still IM thru GTalk..Hmm...I cannot get to IE and there's no way to get an update from SpyBot in case there's a repair or a known problem update etc. ....
SurferJoe46 (51)
628377 2008-01-08 17:44:00 If internet access is being blocked try a winsock repair.

Start, Run, CMD to open a command prompt.
Type in: netsh winsock reset catalog
Enter and reboot computer.
Safari (3993)
628378 2008-01-08 18:03:00 I just burned everything down and am running Feisty Fawn right now on the unit that had the WGA failure.

Feisty went in smoothly..I wish I had an i368 version of PCLOS...but I will limp along with this for a while..might even try a dual-boot later on..that seems to be my greatest failure..but I will persevere.

PS: Side-by-side with the good-running XP units, the graphics are very different...and it seems the colors are more vivid on this unit (Dell) now...maybe I should check my glasses prescription.
SurferJoe46 (51)
628379 2008-01-08 19:30:00 OK...I installed the new beta version of Spybot on just this ONE computer...and this morning on reboot I am seeing
HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Run\ctfmon.exe=C:\WINDOWS\system32\ctfmo n.exe


Well thats not a spybot problem. Its a Trojan problem that SPybot has told you about.

How do you get so much of this stuff anyway? I never get malware.
pctek (84)
628380 2008-01-08 20:59:00 Well thats not a spybot problem . Its a Trojan problem that SPybot has told you about .

How do you get so much of this stuff anyway? I never get malware .

I leave this puter on 24/7 and maybe that's the problem . . but I use it as a fax and all . . . so it's necessary .

It's also my primary e-mail device so that's likely a source of trouble too .

Funnilly enuff, I have kept this: ctfmon . exe from running in all my puters as it was said to be malware . . but this is the only puter so badly affected .

AVG, BoClean Comodo, Spybot and all found it to be malevolent . . . so I disabled it .

This is the only unit adversely affected so far .

Maybe since this (Dell) is just a communication puter, I'll leave Feisty alone and let it have it's way .

Now to fine-tune Feisty and get it to look the way I want it to look .
SurferJoe46 (51)
628381 2008-01-08 22:08:00 www.howtogeek.com zqwerty (97)
628382 2008-01-08 23:09:00 I leave this puter on 24/7 and maybe that's the problem . . but I use it as a fax and all . . . so it's necessary .

It's also my primary e-mail device so that's likely a source of trouble too .


AVG, BoClean Comodo, Spybot and all found it to be malevolent . . . so I disabled it .


You need better stuff .

Mine have:
Nod32, Counterspy, RegDefend, Spyware Doctor, Zone alarm PRO (not the free one) all resident .
pctek (84)
628383 2008-01-09 00:23:00 Actually, thgat is what I used to test the problem . . . I don't use nearly that much at all .

I am behind a router, Windows Firewall, AVG, Spybot, have BoClean to run when and if I feel like it and for quite a few years have had little problems . . er . . other than the dual-boot systems I could not get configured, that is .

I really don't mind if I get hit . . I can just burn it down and start over again and that affords me the opportuning to clean the HDD and get rid of the fluff that ties up a system anyway .

I'll play around in Feisty for a while and see what that brings . . . . but I don't really like all that overhead from ZA . . had it . . . hated it .

What does ctfmon . exe have to do with qualifying? Nothing, I think . . and all my anti-stuff had that noted as a baddie . . . . it was in the lists of things to scan for . . . and kill on sight .

But . . . like I said . . . I don't understand this current situation . . even though I dumped XP and immediately went to Feisty Fawn . None of my other XP puters are having any troubles with WGA . . THAT'S the weird thing .

Is there some sortta trojan/malware that targets the WGA qualifier and lets M$ think I have a pirated copy . . . which I most assuredly do NOT!

Does ABP run on Feisty? This F1 site is messy without it .
SurferJoe46 (51)
628384 2008-01-09 00:29:00 Does ABP run on Feisty? This F1 site is messy without it.Yes. It's just a browser addon, the OS doesn't really matter. Erayd (23)
628385 2008-01-09 00:30:00 If you want to stop ctfmon.exe go here

Control Panel/Regional and Language Options/Languages/Details/Advanced.

Check the box that says Turn off advanced text services.

Its used for Asian languages / part of Office, or something.
Speedy Gonzales (78)
1