Forum Home
Press F1
 
Thread ID: 72357 2006-09-10 01:36:00 Is this possible kjaada (253) Press F1
Post ID Timestamp Content User
483629 2006-09-10 01:36:00 My partner using XP,SB,Adaware,IE7,Avast and all up to date went to a Gucci watch site and after a while child porn pages appeared.We ran SB etc then HJt
(done in safe) showed 11 nasties and things on analisis but when I went back to the original log to delete them they were just not there out of 11 things only 2 showed up.
kjaada (253)
483630 2006-09-10 01:40:00 Run all your checkers, delete whatever they find and don't worry about anything not shown.
And get a firewall too.
pctek (84)
483631 2006-09-10 01:52:00 Have run all the checkers and they came up with very little.
Windows firewall is on.I think u missed the point:HJt analisis said
"these are nasty" but "these" do not show in the original scan so
we can not delete them.
kjaada (253)
483632 2006-09-10 01:58:00 XP's firewall isnt the best firewall to use. Speedy Gonzales (78)
483633 2006-09-10 02:37:00 hae you updated adaware?

what nasties has it found?

get a decent firewall. eg zonealarm or sygate etc

post hjt log please.
tweak'e (69)
483634 2006-09-10 03:14:00 As stated in my post everything is up to date;
Here are 3 things that do not appear in the log.
16 - DPF: {205FF73B-CA67-11D5-99DD-444553540002} (CInstall Class) - www.wildtangent.com Nasty
Nasty This entry is possibly nasty.
Currently there is no visitor's assessment! Should be fixed.
O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} (MiniBugTransporterX Class) - wdownload.weatherbug.com Nasty
Nasty This entry is possibly nasty.
Currently there is no visitor's assessment! Should be fixed.
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} - Possibly nasty
Possibly nasty Unknown ActiveX-Objects, or Active
kjaada (253)
483635 2006-09-10 03:50:00 I have fixed the problem entries after holding down my partner with my foot and useing Knoppix.She is anti Linux.I would still be interested in comments as to what went wrong tho. kjaada (253)
483636 2006-09-10 04:07:00 O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} - Possibly nasty most likly something to do with it but unfortunatly with the extremly limit amount of info posted i would have no idea what so ever what the problem was. tweak'e (69)
483637 2006-09-10 04:53:00 Firstly, WildTangent is a very nasty nasty . . . check out all the previous posts about it in the Search area on this site . . . . . . here . ( . pcworld . co . nz/search . php?searchid=652817" target="_blank">pressf1 . pcworld . co . nz) I personally chewed some butt about it a long time ago . . and since have apologized to certain individuals for it . I still have a case of the jaws for WT in all forms! :yuck:

WT usually comes in on a cd-rom with some games, and is a constant threat in the games of Yahoo and others . Keep outta those places and you'll be a lot happier . . . and stay away from the cute monkey too .

I would recommend that you do the following too: Get the latest version of CrapCleaner from http://www . ccleaner . com .

(the actual download is at: . filehippo . com/download_ccleaner/" target="_blank">www . filehippo . com
click on on Download Latest Version)

Install it . Don't let it clean anything yet .

Shutdown then restart and Boot into Safe Mode by tapping the F8 key when you see your PC maker's logo . . . . . . tapping until it tells you it is going to Safe Mode or you see the Safe-Mode menu . Select the top option and log in as your usual login/user .

Run ccleaner . exe . . . . . . . . . .

Select Options >> Advanced and uncheck the box in front of: Only Delete file in Windows Temp folders older than 48 hours .

Now select Cleaner

Under Cleaner Settings, Windows,
- uncheck everything on the first page except:


under Internet Explorer
- Temporary Internet Files
under System
- Empty Recycle Bin
- Temporary Files

Under Cleaner Settings, Applications
- uncheck everything except:


Under Internet
- don't check - Sun Java

Now run CCleaner .

This should clean out all of the temp files including those of your java program
(where most results tell us that we will find lots of garbage . (You really should be running the latest version of java and uninstall all old versions) .

The reason I have you uncheck most of the options is that I have had problems with it deleting too much so I want to limit it to things where I think malware might be hiding .


Then run MicrosoftAntiSpy or SpyBot S&D and let it run . . . . . should take about 30 minutes . When it finishes, if it finds anything, remove it and then run the scan again . The reason I suggest MSAntiSpy is that is is probably more up-to-date than a lot of the others right now . . sad to say . It IS bulky, but good for an occasional scan . SpyBot is a good option, but it too is getting very top heavy with protection and heuristic scans .

Have your antivirus also run a full scan while still in Safe Mode .

Make a new HJT log while still in Safe Mode and save it where you can find it again . . . usually on the desktop .

Reboot and see if your problem still shows up .

Report back . . OK? ;)

{gads! I'm gonna c/p this in a folder for future references . . it was a lot of work} :D
SurferJoe46 (51)
483638 2006-09-10 05:21:00 wild tangent isn't that big a deal. it just reports back info which may be a big deal for privacy buffs. afaik its not evasive or malicious (eg doesn't hijack or any thing nasty) tweak'e (69)
1 2