Ok what is the next step

Status
This thread has been Locked and is not open to further replies. Please start a New Thread if you're having a similar issue. View our Welcome Guide to learn how to use this site.

samwalton

Thread Starter
Guest
Joined
Feb 26, 2004
Messages
274
Helping out a friend and her ran ewido, and active scan had her turn of the tea timer also



Logfile of HijackThis v1.99.1
Scan saved at 01:42:15, on 13/01/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Google\Gmail Notifier\G001-1.0.25.0\gnotify.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Voyager 105 ADSL Modem\dslagent.exe
C:\WINDOWS\system32\atwtusb.exe
C:\Program Files\dudez\protowall\ProtoWall.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\FAH502-Console.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\TBLMOUSE.EXE
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\FahCore_65.exe
C:\PROGRA~1\INCRED~1\bin\IMApp.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe
C:\Documents and Settings\Vicky\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://portal.f9.net.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://portal.f9.net.uk/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Force9 Internet Explorer
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {BDCDED56-7799-4DAC-A561-F98083E25AD1} - C:\WINDOWS\System32\ndckoj.dll (file missing)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\G001-1.0.25.0\gnotify.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [DSLSTATEXE] C:\Program Files\Voyager 105 ADSL Modem\dslstat.exe icon
O4 - HKLM\..\Run: [DSLAGENTEXE] C:\Program Files\Voyager 105 ADSL Modem\dslagent.exe
O4 - HKLM\..\Run: [atwtusb] atwtusb.exe beta
O4 - HKCU\..\Run: [ProtoWall] C:\Program Files\dudez\protowall\ProtoWall.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:\PROGRA~1\INCRED~1\bin\resources\WebMenuImg.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O14 - IERESET.INF: START_PAGE_URL=http://portal.f9.net.uk/
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.com//PhotoUpload/MsnPUpld.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1124103841187
O16 - DPF: {6FDB0065-2787-11D6-B1D8-0001023916FC} (CLOActiveXInstaller Control) - http://www.igl.net/clo/install/CLOActiveXInstallerProj1.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab31267.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: [email protected]:+WINDOWS+FAH502-Console.exe - Stanford University - C:\WINDOWS\FAH502-Console.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe


and results from activescan


Incident Status Location

Adware:adware/statblaster Not disinfected C:\WINDOWS\DOWNLOADED PROGRAM FILES\WildApp.inf
Adware:adware/ncase Not disinfected C:\PROGRAM FILES\nCASE
Adware:adware/mediatickets Not disinfected Windows Registry
Spyware:Cookie/Sandboxer Not disinfected C:\Documents and Settings\Vicky\Cookies\[email protected][1].txt
Spyware:Cookie/Hbmediapro Not disinfected C:\Documents and Settings\Vicky\Cookies\[email protected][2].txt
Spyware:Cookie/OfferOptimizer Not disinfected C:\Documents and Settings\Vicky\Cookies\[email protected][1].txt
Spyware:Cookie/Xiti Not disinfected C:\Documents and Settings\Vicky\Cookies\[email protected][1].txt
Spyware:Cookie/Xmts Not disinfected C:\Documents and Settings\Vicky\Cookies\[email protected][1].txt
Spyware:Cookie/Ask Not disinfected C:\Documents and Settings\Vicky\Application Data\Mozilla\Firefox\Profiles\dsxihe7v.default\cookies.txt[.ask.com/]
Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\Vicky\Application Data\Mozilla\Firefox\Profiles\dsxihe7v.default\cookies.txt[.casalemedia.com/]
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Vicky\Application Data\Mozilla\Firefox\Profiles\dsxihe7v.default\cookies.txt[ad.yieldmanager.com/]
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Vicky\Application Data\Mozilla\Firefox\Profiles\dsxihe7v.default\cookies.txt[.realmedia.com/]
Spyware:Cookie/BurstNet Not disinfected C:\Documents and Settings\Vicky\Application Data\Mozilla\Firefox\Profiles\dsxihe7v.default\cookies.txt[.burstnet.com/]
Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\Vicky\Application Data\Mozilla\Firefox\Profiles\dsxihe7v.default\cookies.txt[.statcounter.com/]
Spyware:Cookie/bravenetA Not disinfected C:\Documents and Settings\Vicky\Application Data\Mozilla\Firefox\Profiles\dsxihe7v.default\cookies.txt[.bravenet.com/]
Spyware:Cookie/Falkag Not disinfected C:\Documents and Settings\Vicky\Application Data\Mozilla\Firefox\Profiles\dsxihe7v.default\cookies.txt[.as-us.falkag.net/]
Spyware:Cookie/Tickle Not disinfected C:\Documents and Settings\Vicky\Application Data\Mozilla\Firefox\Profiles\dsxihe7v.default\cookies.txt[.tickle.com/]
Spyware:Cookie/Falkag Not disinfected C:\Documents and Settings\Vicky\Application Data\Mozilla\Firefox\Profiles\dsxihe7v.default\cookies.txt[.as-eu.falkag.net/]
Spyware:Cookie/Falkag Not disinfected C:\Documents and Settings\Vicky\Application Data\Mozilla\Firefox\Profiles\dsxihe7v.default\cookies.txt[sel.as-eu.falkag.net/]
Spyware:Cookie/Falkag Not disinfected C:\Documents and Settings\Vicky\Application Data\Mozilla\Firefox\Profiles\dsxihe7v.default\cookies.txt[.as-eu.falkag.net/]
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Vicky\Application Data\Mozilla\Firefox\Profiles\dsxihe7v.default\cookies.txt[.belnk.com/]
Spyware:Cookie/Hbmediapro Not disinfected C:\Documents and Settings\Vicky\Application Data\Mozilla\Firefox\Profiles\dsxihe7v.default\cookies.txt[.adopt.hbmediapro.com/]
Spyware:Cookie/Azjmp Not disinfected C:\Documents and Settings\Vicky\Application Data\Mozilla\Firefox\Profiles\dsxihe7v.default\cookies.txt[.azjmp.com/]
Spyware:Cookie/WinFixer Not disinfected C:\Documents and Settings\Vicky\Application Data\Mozilla\Firefox\Profiles\dsxihe7v.default\cookies.txt[.winfixer.com/]
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\Vicky\Application Data\Mozilla\Firefox\Profiles\dsxihe7v.default\cookies.txt[.serving-sys.com/]
Spyware:Cookie/Bs.serving-sys Not disinfected C:\Documents and Settings\Vicky\Application Data\Mozilla\Firefox\Profiles\dsxihe7v.default\cookies.txt[.bs.serving-sys.com/]
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\Vicky\Application Data\Mozilla\Firefox\Profiles\dsxihe7v.default\cookies.txt[.serving-sys.com/]
Spyware:Cookie/Bs.serving-sys Not disinfected C:\Documents and Settings\Vicky\Application Data\Mozilla\Firefox\Profiles\dsxihe7v.default\cookies.txt[bs.serving-sys.com/]
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\Vicky\Application Data\Mozilla\Firefox\Profiles\dsxihe7v.default\cookies.txt[.serving-sys.com/]
Spyware:Cookie/Xmts Not disinfected C:\Documents and Settings\Vicky\Application Data\Mozilla\Firefox\Profiles\dsxihe7v.default\cookies.txt[.xmts.net/]
Spyware:Cookie/888 Not disinfected C:\Documents and Settings\Vicky\Application Data\Mozilla\Firefox\Profiles\dsxihe7v.default\cookies.txt[.888.com/]
Spyware:Cookie/Maxserving Not disinfected C:\Documents and Settings\Vicky\Application Data\Mozilla\Firefox\Profiles\dsxihe7v.default\cookies.txt[.maxserving.com/]
Spyware:Cookie/adultfriendfinder Not disinfected C:\Documents and Settings\Vicky\Application Data\Mozilla\Firefox\Profiles\dsxihe7v.default\cookies.txt[.adultfriendfinder.com/]
Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\Vicky\Application Data\Mozilla\Firefox\Profiles\dsxihe7v.default\cookies.txt[.zedo.com/]
Spyware:Cookie/WUpd Not disinfected C:\Documents and Settings\Vicky\Application Data\Mozilla\Firefox\Profiles\dsxihe7v.default\cookies.txt[.revenue.net/]
Spyware:Cookie/myaffiliateprogram Not disinfected C:\Documents and Settings\Vicky\Application Data\Mozilla\Firefox\Profiles\dsxihe7v.default\cookies.txt[www.myaffiliateprogram.com/]
Spyware:Cookie/Reliablestats Not disinfected C:\Documents and Settings\Vicky\Application Data\Mozilla\Firefox\Profiles\dsxihe7v.default\cookies.txt[stats1.reliablestats.com/]
Spyware:Cookie/onestat.com Not disinfected C:\Documents and Settings\Vicky\Application Data\Mozilla\Firefox\Profiles\dsxihe7v.default\cookies.txt[stat.onestat.com/]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Vicky\Application Data\Mozilla\Firefox\Profiles\dsxihe7v.default\cookies.txt[server.iad.liveperson.net/hc/91338698]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Vicky\Application Data\Mozilla\Firefox\Profiles\dsxihe7v.default\cookies.txt[server.iad.liveperson.net/]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Vicky\Application Data\Mozilla\Firefox\Profiles\dsxihe7v.default\cookies.txt[server.iad.liveperson.net/hc/91338698]
Spyware:Cookie/Apmebf Not disinfected C:\Documents and Settings\Vicky\Application Data\Mozilla\Firefox\Profiles\dsxihe7v.default\cookies.txt[.apmebf.com/]
Spyware:Cookie/DomainSponsor Not disinfected C:\Documents and Settings\Vicky\Application Data\Mozilla\Firefox\Profiles\dsxihe7v.default\cookies.txt[landing.domainsponsor.com/]
Spyware:Cookie/Searchportal Not disinfected C:\Documents and Settings\Vicky\Application Data\Mozilla\Firefox\Profiles\dsxihe7v.default\cookies.txt[searchportal.information.com/]
Spyware:Cookie/Ask Not disinfected C:\Documents and Settings\Vicky\Application Data\Mozilla\Firefox\Profiles\dsxihe7v.default\cookies.txt[]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Vicky\Application Data\Mozilla\Firefox\Profiles\dsxihe7v.default\cookies.txt[91338698]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Vicky\Application Data\Mozilla\Firefox\Profiles\dsxihe7v.default\cookies.txt[]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Vicky\Application Data\Mozilla\Firefox\Profiles\dsxihe7v.default\cookies.txt[91338698]
Spyware:Cookie/Apmebf Not disinfected C:\Documents and Settings\Vicky\Application Data\Mozilla\Firefox\Profiles\dsxihe7v.default\cookies.txt[]
Spyware:Cookie/Sandboxer Not disinfected C:\Documents and Settings\Vicky\Cookies\[email protected][1].txt
Spyware:Cookie/Hbmediapro Not disinfected C:\Documents and Settings\Vicky\Cookies\[email protected][2].txt
Spyware:Cookie/OfferOptimizer Not disinfected C:\Documents and Settings\Vicky\Cookies\[email protected][1].txt
Spyware:Cookie/Xiti Not disinfected C:\Documents and Settings\Vicky\Cookies\[email protected][1].txt
Spyware:Cookie/Xmts Not disinfected C:\Documents and Settings\Vicky\Cookies\[email protected][1].txt
Adware:Adware/CWS Not disinfected C:\Program Files\Internet Explorer\hcxa.exe
Adware:Adware/nCase Not disinfected C:\Program Files\nCASE\msbb.exe
Adware:Adware/WinAD Not disinfected C:\WINDOWS\Downloaded Program Files\imloader.exe
Adware:Adware Program Not disinfected C:\WINDOWS\Downloaded Program Files\WildApp.inf
Adware:Adware/BTGrab Not disinfected C:\WINDOWS\inf\btgrab.inf
Dialer:Dialer.VJ Not disinfected C:\WINDOWS\system\dialer.exe
Dialer:Dialer.VJ Not disinfected C:\WINDOWS\system32\50.exe
Virus:Trj/Qhost.gen Disinfected C:\WINDOWS\system32\drivers\etc\hosts
Virus:Trj/Qhost.AE Disinfected C:\WINDOWS\system32\drivers\etc\hosts.20050509-193708.backup
Virus:Trj/Qhost.gen Disinfected C:\WINDOWS\system32\drivers\etc\hosts.msn
Virus:Trj/Qhost.AE Disinfected C:\WINDOWS\system32\drivers\etc\hosts.new
Adware:Adware/WUpd Not disinfected C:\WINDOWS\system32\proover.exe
 
Joined
Feb 15, 2004
Messages
12,302
Download the pocket killbox

http://www.bleepingcomputer.com/files/killbox.php


* Click here for info on how to boot to safe mode if you don't already know
how.

http://service1.symantec.com/SUPPOR...2001052409420406?OpenDocument&src=sec_doc_nam



* Now copy these instructions to notepad and save them to your desktop. You
will need them to refer to in safe mode.


* Restart your computer into safe mode now. Perform the following steps in
safe mode:


have hijack this fix these entries. close all browsers and programmes before
clicking FIX.


O2 - BHO: (no name) - {BDCDED56-7799-4DAC-A561-F98083E25AD1} - C:\WINDOWS\System32\ndckoj.dll (file missing)
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {6FDB0065-2787-11D6-B1D8-0001023916FC} (CLOActiveXInstaller Control) - http://www.igl.net/clo/install/CLOAc...allerProj1.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/actives...ree/asinst.cab



Double-click on Killbox.exe to run it. Now put a tick by Standard File Kill.
In the Full Path of File to Delete box, copy and paste each of the following
lines one at a time then click on the button that has the red circle with the
X in the middle after you enter each file. It will ask for confirmation to
delete the file. Click Yes. Continue with that same procedure until you have
copied and pasted all of these in the Paste Full Path of File to Delete box.



Note: It is possible that Killbox will tell you that one or more files do not
exist. If that happens, just continue on with all the files. Be sure you
don't miss any.



C:\Program Files\Internet Explorer\hcxa.exe
C:\Program Files\nCASE\msbb.exe
C:\Program Files\nCASE
C:\WINDOWS\Downloaded Program Files\imloader.exe
C:\WINDOWS\Downloaded Program Files\WildApp.inf
C:\WINDOWS\inf\btgrab.inf



reboot to normal mode and downlaod and run thes scans!



*Download Cleanup from Here

http://www.stevengould.org/software/cleanup/download.html



* A window will open and choose SAVE, then DESKTOP as the destination.
* On your Desktop, click on Cleanup40.exe icon.
* Then, click RUN and place a checkmark beside "I Agree"
* Then click NEXT followed by START and OK.
* A window will appear with many choices, keep all the defaults as set when the Slide Bar to the left is set to Standard Quality.
* Click OK
* run cleanup!




Please download WebRoot SpySweeper from HERE (It's a 2 week trial):

http://www.webroot.com/consumer/products/spysweeper/index.html?acode=af1&rc=4129


* Click the Free Trial link under "Downloads/SpySweeper" to download the program.
* Install it. Once the program is installed, it will open.
* It will prompt you to update to the latest definitions, click Yes.
* Once the definitions are installed, click Options on the left side.
* Click the Sweep Options tab.
* Under What to Sweep please put a check next to the following:
o
o Sweep Memory
o Sweep Registry
o Sweep Cookies
o Sweep All User Accounts
o Enable Direct Disk Sweeping
o Sweep Contents of Compressed Files
o Sweep for Rootkits
o Please UNCHECK Do not Sweep System Restore Folder.
* Click Sweep Now on the left side.
* Click the Start button.
* When it's done scanning, click the Next button.
* Make sure everything has a check next to it, then click the Next button.
* It will remove all of the items found.
* Click Session Log in the upper right corner, copy everything in that window.
* Click the Summary tab and click Finish.
* Paste the contents of the session log you copied into your next reply.



go to this site and download these tools and once you get both
adaware Se 1.6 and spybot, update both of them.

Set adaware to do a full system scan and deselect, "search for neglible risk
entries". Click next to start the scan. Delete everything adaware finds.

reboot and now run spybot

Spybot: Search and destroy.

Delete what spybot finds marked in red. After updating spybot hit the
immunize button.

reboot again


With CWshredder close all browsers and programmes and select the FIX button.



Go here and download Microsoft Antispyware Beta. First in the top menu click
File then Check for updates to download the definitons updates.

After updating look in the right side of the main window under "Run Quick
Scan Now" and click Spyware scan options. In that window put a tick by Run a
full system scan and then put a check by all three options below that then
click Run Scan now.

When the scan is finished, let it fix anything that it finds (have it
quarantine the items that have that option rather than delete just in case.
It is a beta program and there may be false positives)

Restart your computer.


All tools can be downloaded at the link below and found on that page!

. Microsoft® Windows AntiSpyware
. Trend micro CWShredder
. AdAware SE personal


http://www.majorgeeks.com/downloads31.html


post another log
 

flavallee

Frank
Trusted Advisor
Joined
May 12, 2002
Messages
83,804
samwalton:

Your computer has some programs running in the background that don't need to be, but we can deal with that later.

--------------------------------------------------------------------------------------
 

samwalton

Thread Starter
Guest
Joined
Feb 26, 2004
Messages
274
Logfile of HijackThis v1.99.1
Scan saved at 07:22:04, on 14/01/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\FAH502-Console.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\FahCore_82.exe
C:\WINDOWS\system32\slserv.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Google\Gmail Notifier\G001-1.0.25.0\gnotify.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Voyager 105 ADSL Modem\dslagent.exe
C:\WINDOWS\system32\atwtusb.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\dudez\protowall\ProtoWall.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\TBLMOUSE.EXE
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\PROGRA~1\INCRED~1\bin\IMApp.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Vicky\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://portal.f9.net.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://portal.f9.net.uk/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Force9 Internet Explorer
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {45AD732C-2CE2-4666-B366-B2214AD57A49} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {BDCDED56-7799-4DAC-A561-F98083E25AD1} - (no file)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\G001-1.0.25.0\gnotify.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [DSLSTATEXE] C:\Program Files\Voyager 105 ADSL Modem\dslstat.exe icon
O4 - HKLM\..\Run: [DSLAGENTEXE] C:\Program Files\Voyager 105 ADSL Modem\dslagent.exe
O4 - HKLM\..\Run: [atwtusb] atwtusb.exe beta
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKCU\..\Run: [ProtoWall] C:\Program Files\dudez\protowall\ProtoWall.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:\PROGRA~1\INCRED~1\bin\resources\WebMenuImg.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O14 - IERESET.INF: START_PAGE_URL=http://portal.f9.net.uk/
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} -
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.com//PhotoUpload/MsnPUpld.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1124103841187
O16 - DPF: {6FDB0065-2787-11D6-B1D8-0001023916FC} (CLOActiveXInstaller Control) - http://www.igl.net/clo/install/CLOActiveXInstallerProj1.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab31267.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: [email protected]:+WINDOWS+FAH502-Console.exe - Stanford University - C:\WINDOWS\FAH502-Console.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe


My activescan log..


Incident Status Location

Spyware:Cookie/Sandboxer Not disinfected C:\Documents and Settings\Vicky\Cookies\[email protected][1].txt
Spyware:Cookie/Xmts Not disinfected C:\Documents and Settings\Vicky\Cookies\[email protected][1].txt
Spyware:Cookie/Ask Not disinfected C:\Documents and Settings\Vicky\Application Data\Mozilla\Firefox\Profiles\dsxihe7v.default\cookies.txt[.ask.com/]
Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\Vicky\Application Data\Mozilla\Firefox\Profiles\dsxihe7v.default\cookies.txt[.casalemedia.com/]
Spyware:Cookie/Falkag Not disinfected C:\Documents and Settings\Vicky\Application Data\Mozilla\Firefox\Profiles\dsxihe7v.default\cookies.txt[.as-eu.falkag.net/]
Spyware:Cookie/Falkag Not disinfected C:\Documents and Settings\Vicky\Application Data\Mozilla\Firefox\Profiles\dsxihe7v.default\cookies.txt[sel.as-eu.falkag.net/]
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Vicky\Application Data\Mozilla\Firefox\Profiles\dsxihe7v.default\cookies.txt[ad.yieldmanager.com/]
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Vicky\Application Data\Mozilla\Firefox\Profiles\dsxihe7v.default\cookies.txt[.belnk.com/]
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Vicky\Application Data\Mozilla\Firefox\Profiles\dsxihe7v.default\cookies.txt[.realmedia.com/]
Spyware:Cookie/bravenetA Not disinfected C:\Documents and Settings\Vicky\Application Data\Mozilla\Firefox\Profiles\dsxihe7v.default\cookies.txt[.bravenet.com/]
Spyware:Cookie/Falkag Not disinfected C:\Documents and Settings\Vicky\Application Data\Mozilla\Firefox\Profiles\dsxihe7v.default\cookies.txt[.as-us.falkag.net/]
Spyware:Cookie/Hbmediapro Not disinfected C:\Documents and Settings\Vicky\Application Data\Mozilla\Firefox\Profiles\dsxihe7v.default\cookies.txt[.adopt.hbmediapro.com/]
Spyware:Cookie/BurstNet Not disinfected C:\Documents and Settings\Vicky\Application Data\Mozilla\Firefox\Profiles\dsxihe7v.default\cookies.txt[.burstnet.com/]
Spyware:Cookie/adultfriendfinder Not disinfected C:\Documents and Settings\Vicky\Application Data\Mozilla\Firefox\Profiles\dsxihe7v.default\cookies.txt[.adultfriendfinder.com/]
Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\Vicky\Application Data\Mozilla\Firefox\Profiles\dsxihe7v.default\cookies.txt[.statcounter.com/]
Spyware:Cookie/Tickle Not disinfected C:\Documents and Settings\Vicky\Application Data\Mozilla\Firefox\Profiles\dsxihe7v.default\cookies.txt[.tickle.com/]
Spyware:Cookie/Azjmp Not disinfected C:\Documents and Settings\Vicky\Application Data\Mozilla\Firefox\Profiles\dsxihe7v.default\cookies.txt[.azjmp.com/]
Spyware:Cookie/WinFixer Not disinfected C:\Documents and Settings\Vicky\Application Data\Mozilla\Firefox\Profiles\dsxihe7v.default\cookies.txt[.winfixer.com/]
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\Vicky\Application Data\Mozilla\Firefox\Profiles\dsxihe7v.default\cookies.txt[.serving-sys.com/]
Spyware:Cookie/Bs.serving-sys Not disinfected C:\Documents and Settings\Vicky\Application Data\Mozilla\Firefox\Profiles\dsxihe7v.default\cookies.txt[.bs.serving-sys.com/]
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\Vicky\Application Data\Mozilla\Firefox\Profiles\dsxihe7v.default\cookies.txt[.serving-sys.com/]
Spyware:Cookie/Bs.serving-sys Not disinfected C:\Documents and Settings\Vicky\Application Data\Mozilla\Firefox\Profiles\dsxihe7v.default\cookies.txt[bs.serving-sys.com/]
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\Vicky\Application Data\Mozilla\Firefox\Profiles\dsxihe7v.default\cookies.txt[.serving-sys.com/]
Spyware:Cookie/Xmts Not disinfected C:\Documents and Settings\Vicky\Application Data\Mozilla\Firefox\Profiles\dsxihe7v.default\cookies.txt[.xmts.net/]
Spyware:Cookie/888 Not disinfected C:\Documents and Settings\Vicky\Application Data\Mozilla\Firefox\Profiles\dsxihe7v.default\cookies.txt[.888.com/]
Spyware:Cookie/Maxserving Not disinfected C:\Documents and Settings\Vicky\Application Data\Mozilla\Firefox\Profiles\dsxihe7v.default\cookies.txt[.maxserving.com/]
Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\Vicky\Application Data\Mozilla\Firefox\Profiles\dsxihe7v.default\cookies.txt[.zedo.com/]
Spyware:Cookie/WUpd Not disinfected C:\Documents and Settings\Vicky\Application Data\Mozilla\Firefox\Profiles\dsxihe7v.default\cookies.txt[.revenue.net/]
Spyware:Cookie/myaffiliateprogram Not disinfected C:\Documents and Settings\Vicky\Application Data\Mozilla\Firefox\Profiles\dsxihe7v.default\cookies.txt[www.myaffiliateprogram.com/]
Spyware:Cookie/Reliablestats Not disinfected C:\Documents and Settings\Vicky\Application Data\Mozilla\Firefox\Profiles\dsxihe7v.default\cookies.txt[stats1.reliablestats.com/]
Spyware:Cookie/onestat.com Not disinfected C:\Documents and Settings\Vicky\Application Data\Mozilla\Firefox\Profiles\dsxihe7v.default\cookies.txt[stat.onestat.com/]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Vicky\Application Data\Mozilla\Firefox\Profiles\dsxihe7v.default\cookies.txt[server.iad.liveperson.net/hc/91338698]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Vicky\Application Data\Mozilla\Firefox\Profiles\dsxihe7v.default\cookies.txt[server.iad.liveperson.net/]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Vicky\Application Data\Mozilla\Firefox\Profiles\dsxihe7v.default\cookies.txt[server.iad.liveperson.net/hc/91338698]
Spyware:Cookie/Apmebf Not disinfected C:\Documents and Settings\Vicky\Application Data\Mozilla\Firefox\Profiles\dsxihe7v.default\cookies.txt[.apmebf.com/]
Spyware:Cookie/DomainSponsor Not disinfected C:\Documents and Settings\Vicky\Application Data\Mozilla\Firefox\Profiles\dsxihe7v.default\cookies.txt[landing.domainsponsor.com/]
Spyware:Cookie/Searchportal Not disinfected C:\Documents and Settings\Vicky\Application Data\Mozilla\Firefox\Profiles\dsxihe7v.default\cookies.txt[searchportal.information.com/]
Adware:Adware/CWS Not disinfected C:\!KillBox\hcxa.exe
Adware:Adware/WinAD Not disinfected C:\!KillBox\imloader.exe
Spyware:Cookie/Ask Not disinfected C:\Documents and Settings\Vicky\Application Data\Mozilla\Firefox\Profiles\dsxihe7v.default\cookies.txt[]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Vicky\Application Data\Mozilla\Firefox\Profiles\dsxihe7v.default\cookies.txt[91338698]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Vicky\Application Data\Mozilla\Firefox\Profiles\dsxihe7v.default\cookies.txt[]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Vicky\Application Data\Mozilla\Firefox\Profiles\dsxihe7v.default\cookies.txt[91338698]
Spyware:Cookie/Apmebf Not disinfected C:\Documents and Settings\Vicky\Application Data\Mozilla\Firefox\Profiles\dsxihe7v.default\cookies.txt[]
Spyware:Cookie/Sandboxer Not disinfected C:\Documents and Settings\Vicky\Cookies\[email protected][1].txt
Spyware:Cookie/Xmts Not disinfected C:\Documents and Settings\Vicky\Cookies\[email protected][1].txt
Dialer:Dialer.VJ Not disinfected C:\WINDOWS\system\dialer.exe
Dialer:Dialer.VJ Not disinfected C:\WINDOWS\system32\50.exe
Adware:Adware/WUpd Not disinfected C:\WINDOWS\system32\proover.exe
 
Joined
Feb 15, 2004
Messages
12,302
clean log.


go here and empty out these cookies


C:\Documents and Settings\Vicky\Application Data\Mozilla\Firefox\Profiles\dsxihe7v.default\


have hijack this fix these leftovers.


O2 - BHO: (no name) - {45AD732C-2CE2-4666-B366-B2214AD57A49} - (no file)
O2 - BHO: (no name) - {BDCDED56-7799-4DAC-A561-F98083E25AD1} - (no file)



you should now turn off system restore to flush out the bad restore points and
then re-enable it and make a new clean restore point.


How to turn off system restore

http://service1.symantec.com/SUPPOR...2001111912274039?OpenDocument&src=sec_doc_nam


http://support.microsoft.com/default.aspx?scid=kb;[LN];310405


here's some free tools to keep you from getting infected in the future.


to stop reinfection get these two tools, spywareguard and spywareblaster
from


http://www.javacoolsoftware.com/downloads.html


get the hosts file from here.



http://www.mvps.org/winhelp2002/hosts.htm



put it into :


Windows XP = C:\WINDOWS\SYSTEM32\DRIVERS\ETC
Windows 2K = C:\WINNT\SYSTEM32\DRIVERS\ETC
Win 98\ME = C:\WINDOWS



ie-spyad.Puts over 5000 sites in your restricted zone so you'll be protected

when you visit innocent-looking sites that aren't actually innocent at all.

https://netfiles.uiuc.edu/ehowes/www/resource.htm



http://www.winpatrol.com/winpatrol.html



Use spybot's immunize button and use spywareblaster' enable
protection once you update it. you can put spybot's hosts file into
your own and lock it.



I would also suggest switching to Mozilla's firefox browser, it's safer, has
a built in pop up blocker, blocks cookies and adds. Mozilla Thunderbird is also a good
e-mail client.

http://www.mozilla.org/


Another good and free browser is Opera!

http://www.opera.com/


Read here to see how to tighten your security:

http://forums.techguy.org/t208517.html


A good overall guide for firewalls, anti-virus, and anti-trojans as well as
regular spyware cleaners.

http://www.firewallguide.com/anti-trojan.htm



you can mark your own thread solved through thread tools at the top of
the page.
 

samwalton

Thread Starter
Guest
Joined
Feb 26, 2004
Messages
274
so all the items that the activescan shows as Not disinfected is not a issues ?


Thanks for your help
 

flavallee

Frank
Trusted Advisor
Joined
May 12, 2002
Messages
83,804
Khazars:

Let me know when you're done with Sam so I can work with him on getting that startup list trimmed down.(y)

------------------------------------------------------------------------------------
 

samwalton

Thread Starter
Guest
Joined
Feb 26, 2004
Messages
274
I'm having problems installing ie-spyad. I've allowed it when Spy Sweeper asks me if I want to, but it gets to the install page and does noting. Any advice?
 
Joined
Feb 15, 2004
Messages
12,302
click the install bat after you have extracted iespyad to a folder, preferably one called IE spyad, from the command box choose 2 to install iespyad, then return to the menu and choose 4 to add the porn site domains and then exit and that's it!
 

samwalton

Thread Starter
Guest
Joined
Feb 26, 2004
Messages
274
I've done that it gets to the screen saying "you have chosen to install iespyad" and just sits there, mocking me.
 
Joined
Feb 15, 2004
Messages
12,302
just hit the numbers for the installation and wait a few mins and it should say success!
 
Status
This thread has been Locked and is not open to further replies. Please start a New Thread if you're having a similar issue. View our Welcome Guide to learn how to use this site.

Users Who Are Viewing This Thread (Users: 0, Guests: 1)

As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 807,865 other people just like you!

Latest posts

Staff online

Members online

Top