Computing.Net > Forums > Windows XP > 404ads.net help!

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

404ads.net help!

Reply to Message Icon

Name: mergleh
Date: September 22, 2004 at 16:01:46 Pacific
OS: windows xp professional
CPU/Ram: p4 1.8c 1gb ram
Comment:

my girlfriends comp had a lot of spyware on it, so i downloaded spy sweeper and deleted 204 spyware files, after i restarted, the internet doesnt work.
when i open internet explorer, i get this address...

http://www.404ads.net:8000/redirect....

lots more, but u get the picture, any ideas?




Sponsored Link
Ads by Google

Response Number 1
Name: Mark.UK
Date: September 22, 2004 at 16:16:42 Pacific
Reply:

I would try running Adaware SE Personal and Spybot Search & Destroy aswell. Take a look here:

http://www.giantcompany.com/antispyware/research/spyware/spyware-NaviSearch-404.aspx

it maybe related. Download Hijack This 1.98 and post the resulting log here:

http://www.hijackthis.de/index.php?langselect=english

M


0

Response Number 2
Name: jackb2
Date: October 5, 2004 at 16:19:15 Pacific
Reply:

I, too, have the same 404ads.net problem, can you help? Here's my HijackThis log:

Logfile of HijackThis v1.97.7
Scan saved at 9:14:26 AM, on 6/10/2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\system32\CTsvcCDA.exe
C:\WINNT\SYSTEM32\DWRCS.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\System32\Hummingbird\Connectivity\7.00\Inetd\inetd32.exe
C:\WINNT\System32\Hummingbird\Connectivity\7.00\Jconfig\jconfigdNT.exe
C:\WINNT\System32\Hummingbird\Connectivity\7.00\Jconfig\hjavaw.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINNT\System32\nvsvc32.exe
C:\WINNT\system32\rcmdsvc.exe
C:\WINNT\system32\regsvc.exe
C:\Program Files\javasoft\jre\1.2\bin\javaw.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\system32\suss.exe
C:\Program Files\Sophos SWEEP for NT\SWEEPSRV.SYS
C:\Program Files\Sophos SWEEP for NT\SWUPDATE.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\System32\mspmspsv.exe
C:\Program Files\WebTrends Analysis Series\wtam_service.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\CCM\CLICOMP\RemCtrl\Wuser32.exe
C:\WINNT\system32\CCM\CcmExec.exe
C:\WINNT\System32\inetsrv\inetinfo.exe
C:\Program Files\Citrix\ICA Client\ssonsvr.exe
C:\WINNT\Explorer.exe
C:\WINNT\system32\ICO.exe
C:\WINNT\system32\Pelmiced.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\Scansoft\PaperPort\pptd40nt.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Creative\ShareDLL\CtNotify.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\Program Files\Creative\NOMAD Jukebox 3\PlayCenter2\CTNMRUN.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\Program Files\Creative\Sharedll\Mediadet.exe
C:\Program Files\Sophos SWEEP for NT\ICMON.exe
C:\Program Files\Microsoft Office\Office\1033\MSOFFICE.exe
C:\Program Files\Internet Explorer\IEXPLORE.exe
C:\WINNT\system32\taskmgr.exe
C:\Program Files\Microsoft Office\Office\OUTLOOK.exe
C:\Program Files\Common Files\System\MAPI\1033\nt\MAPISP32.exe
C:\WINNT\System32\PopProv.exe
C:\Program Files\Macromedia\HomeSite 5\Homesite5.exe
C:\downloads\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://wcaintra.wca.gov.au
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://wcaintra.wca.gov.au
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://wcaintra.wca.gov.au
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by WorkCover NSW
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = cache.wca.gov.au:8080
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *
R3 - URLSearchHook: (no name) - _{20EC3D2D-33C1-4C9D-BC37-C2D500688DA2} - (no file)
O2 - BHO: (no name) - SOFTWARE - (no file)
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {8DA20CBC-8A05-C269-EF61-67A2FCAAC12D} - C:\WINNT\Ospjxyov.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.exe NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINNT\System32\NeroCheck.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\Scansoft\PaperPort\pptd40nt.exe
O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\Scansoft\PaperPort\IndexSearch.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Disc Detector] C:\Program Files\Creative\ShareDLL\CtNotify.exe
O4 - HKLM\..\Run: [CTStartup] C:\Program Files\Creative\Splash Screen\CTEaxSpl.exe /run
O4 - HKLM\..\Run: [NOMAD Detector] C:\Program Files\Creative\NOMAD Jukebox 3\PlayCenter2\CTNMRUN.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [SpyBlocs] C:\PROGRA~1\SpyBlocs\SpyBlocs.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [NOMAD Detector] "C:\Program Files\Creative\NOMAD Jukebox 3\PlayCenter2\CTNMRUN.exe"
O4 - HKCU\..\Run: [SpySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe /0
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: InterCheck Monitor.LNK = C:\Program Files\Sophos SWEEP for NT\ICMON.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O12 - Plugin for .pdf: C:\Program Files\Netscape\Communicator\Program\PLUGINS\nppdf32.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\PLUGINS\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://wcaintra.wca.gov.au
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = wca.gov.au
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = wca.gov.au
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = wca.gov.au


0

Sponsored Link
Ads by Google
Reply to Message Icon

Related Posts

See More


problems installing norto... Errors when deleting part...



Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Windows XP Forum Home


Sponsored links

Ads by Google


Results for: 404ads.net help!

0ml.net HELP! Driving me nuts! SOS! www.computing.net/answers/windows-xp/0mlnet-help-driving-me-nuts-sos/125339.html

trouble with net meeting www.computing.net/answers/windows-xp/trouble-with-net-meeting/107558.html

Some MSDOS help for a Windows-gen k www.computing.net/answers/windows-xp/some-msdos-help-for-a-windowsgen-k/96376.html