Tom's Guide | Tom's Hardware | Tom's Games
![]() |
![]() |
![]() |
I have had tons of spyware lately. And there is this one that i can't seem to get rid of. Rather 1 minute after I delete it with Spybot it comes back. The spyware that wont go away is called My Search-{014D6C9-189F-421a-88CD-07CFE51CFF10}. I also have "Spyware Blaster", and it says it defends against this, but apparently it isn't working. I have updated versions of both. I have Hijack This, and I know people have asked this question before, but it must be different on every comp. Hijack This said:
Logfile of HijackThis v1.97.7
Scan saved at 11:18:01 PM, on 12/5/2003
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)Running processes:
E:\WINDOWS\System32\smss.exe
E:\WINDOWS\system32\winlogon.exe
E:\WINDOWS\system32\services.exe
E:\WINDOWS\system32\lsass.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\System32\svchost.exe
E:\WINDOWS\Explorer.exe
E:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
E:\WINDOWS\system32\spoolsv.exe
E:\Program Files\PestPatrol\PPControl.exe
E:\PROGRA~1\PESTPA~1\PPMemCheck.exe
E:\PROGRA~1\PESTPA~1\CookiePatrol.exe
E:\Program Files\Java\j2re1.4.2_01\bin\jusched.exe
E:\Program Files\Common Files\Symantec Shared\ccApp.exe
E:\Program Files\Norton SystemWorks\Norton Ghost\GhostStartTrayApp.exe
E:\Program Files\AIM\aim.exe
E:\Program Files\Messenger\msmsgs.exe
E:\Program Files\WordWeb\wweb32.exe
E:\PROGRA~1\NORTON~3\NORTON~3\GHOSTS~2.exe
E:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
E:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.exe
E:\PROGRA~1\NORTON~3\SPEEDD~1\nopdb.exe
D:\protection\SpywareBlaster\spywareblaster.exe
E:\Program Files\PestPatrol\PestPatrol.exe
E:\Program Files\Internet Explorer\iexplore.exe
E:\Documents and Settings\Sean Povill\Local Settings\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe
E:\Program Files\Microsoft Office\Office\WINWORD.exe
E:\WINDOWS\System32\msiexec.exe
E:\WINDOWS\msagent\AgentSvr.exe
E:\WINDOWS\System32\notepad.exeR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = file:///E:/Documents%20and%20Settings/Sean%20Povill/My%20Documents/Research%20From%20Web/index.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about:blank
R3 - Default URLSearchHook is missing
N3 - Netscape 7: user_pref("browser.startup.homepage", "file:///E:/Documents%20and%20Settings/Sean%20Povill/My%20Documents/Research%20From%20Web/index.html"); (E:\Documents and Settings\Sean Povill\Application Data\Mozilla\Profiles\default\2pkykz94.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://F%3A%5CProgram%20Files%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (E:\Documents and Settings\Sean Povill\Application Data\Mozilla\Profiles\default\2pkykz94.slt\prefs.js)
O2 - BHO: MyWay Search Assistant BHO - {04079851-5845-4dea-848C-3ECD647AA554} - E:\Program Files\MyWay\SrchAstt\1.bin\MYSRCHAS.DLL
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - E:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - E:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - E:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [PestPatrol Control Center] E:\Program Files\PestPatrol\PPControl.exe
O4 - HKLM\..\Run: [PPMemCheck] E:\PROGRA~1\PESTPA~1\PPMemCheck.exe
O4 - HKLM\..\Run: [CookiePatrol] E:\PROGRA~1\PESTPA~1\CookiePatrol.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] E:\Program Files\Java\j2re1.4.2_01\bin\jusched.exe
O4 - HKLM\..\Run: [ccApp] "E:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "E:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [GhostStartTrayApp] E:\Program Files\Norton SystemWorks\Norton Ghost\GhostStartTrayApp.exe
O4 - HKCU\..\Run: [AIM] E:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [MSMSGS] "E:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKLM\..\RunOnce: [SpyBotSnD] "D:\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - Startup: WordWeb.lnk = E:\Program Files\WordWeb\wweb32.exe
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: AIM (HKLM)
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/d2c89f68a1bb5a/housecall.antivirus.com/housecall/xscan53.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cabI don't know if that will help me, but I need to know what to delete in Hijack This (or do anything else) to get rid of this spyware and anything else that might be there.
Please post as soon as possible :)
Thank You

let HJT remove the R0 & R1 entries that say about:blank. also remove the O2 entry that lists MyWay search.
spybot search & destroy might fix this for you automatically.

Did you use the default install location for
SpywareBlaster (under \Program Files\)?D:\protection\SpywareBlaster\spywareblaster.exe
everything else is on e:

i have the same problem. i have ad-aware. this stupid myway spyware is write protected. i just got this laptop yesterday. like many gator programs, i think this came tagging along in the pre-installed software. many companies don't know that this malware exsists in their software, or so i'm told.

![]() |
i'm sick of hijacked brow...
|
Golden Palace Casino EXE
|

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.
| Ads by Google |