Tom's Guide | Tom's Hardware | Tom's Games
![]() |
![]() |
![]() |
I have had tons of spyware lately. And there is this one that i can't seem to get rid of. Rather 1 minute after I delete it with Spybot it comes back. The spyware that wont go away is called My Search-{014D6C9-189F-421a-88CD-07CFE51CFF10}. I also have "Spyware Blaster", and it says it defends against this, but apparently it isn't working. I have updated versions of both. I have Hijack This, and I know people have asked this question before, but it must be different on every comp. Hijack This said:
Logfile of HijackThis v1.97.7
Scan saved at 11:18:01 PM, on 12/5/2003
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)Running processes:
E:\WINDOWS\System32\smss.exe
E:\WINDOWS\system32\winlogon.exe
E:\WINDOWS\system32\services.exe
E:\WINDOWS\system32\lsass.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\System32\svchost.exe
E:\WINDOWS\Explorer.exe
E:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
E:\WINDOWS\system32\spoolsv.exe
E:\Program Files\PestPatrol\PPControl.exe
E:\PROGRA~1\PESTPA~1\PPMemCheck.exe
E:\PROGRA~1\PESTPA~1\CookiePatrol.exe
E:\Program Files\Java\j2re1.4.2_01\bin\jusched.exe
E:\Program Files\Common Files\Symantec Shared\ccApp.exe
E:\Program Files\Norton SystemWorks\Norton Ghost\GhostStartTrayApp.exe
E:\Program Files\AIM\aim.exe
E:\Program Files\Messenger\msmsgs.exe
E:\Program Files\WordWeb\wweb32.exe
E:\PROGRA~1\NORTON~3\NORTON~3\GHOSTS~2.exe
E:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
E:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.exe
E:\PROGRA~1\NORTON~3\SPEEDD~1\nopdb.exe
D:\protection\SpywareBlaster\spywareblaster.exe
E:\Program Files\PestPatrol\PestPatrol.exe
E:\Program Files\Internet Explorer\iexplore.exe
E:\Documents and Settings\Sean Povill\Local Settings\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe
E:\Program Files\Microsoft Office\Office\WINWORD.exe
E:\WINDOWS\System32\msiexec.exe
E:\WINDOWS\msagent\AgentSvr.exe
E:\WINDOWS\System32\notepad.exeR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = file:///E:/Documents%20and%20Settings/Sean%20Povill/My%20Documents/Research%20From%20Web/index.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about:blank
R3 - Default URLSearchHook is missing
N3 - Netscape 7: user_pref("browser.startup.homepage", "file:///E:/Documents%20and%20Settings/Sean%20Povill/My%20Documents/Research%20From%20Web/index.html"); (E:\Documents and Settings\Sean Povill\Application Data\Mozilla\Profiles\default\2pkykz94.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://F%3A%5CProgram%20Files%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (E:\Documents and Settings\Sean Povill\Application Data\Mozilla\Profiles\default\2pkykz94.slt\prefs.js)
O2 - BHO: MyWay Search Assistant BHO - {04079851-5845-4dea-848C-3ECD647AA554} - E:\Program Files\MyWay\SrchAstt\1.bin\MYSRCHAS.DLL
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - E:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - E:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - E:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [PestPatrol Control Center] E:\Program Files\PestPatrol\PPControl.exe
O4 - HKLM\..\Run: [PPMemCheck] E:\PROGRA~1\PESTPA~1\PPMemCheck.exe
O4 - HKLM\..\Run: [CookiePatrol] E:\PROGRA~1\PESTPA~1\CookiePatrol.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] E:\Program Files\Java\j2re1.4.2_01\bin\jusched.exe
O4 - HKLM\..\Run: [ccApp] "E:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "E:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [GhostStartTrayApp] E:\Program Files\Norton SystemWorks\Norton Ghost\GhostStartTrayApp.exe
O4 - HKCU\..\Run: [AIM] E:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [MSMSGS] "E:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKLM\..\RunOnce: [SpyBotSnD] "D:\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - Startup: WordWeb.lnk = E:\Program Files\WordWeb\wweb32.exe
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: AIM (HKLM)
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/d2c89f68a1bb5a/housecall.antivirus.com/housecall/xscan53.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cabI don't know if that will help me, but I need to know what to delete in Hijack This (or do anything else) to get rid of this spyware and anything else that might be there.
Please post as soon as possible :)
Thank You

If you go to the pestpatrol site they have a the lines you need to delete in the registry.
I believe these are the ones.HKEY_CLASSES_ROOT\clsid\{014da6c9-189f-421a-88cd-07cfe51cff10}
HKEY_CLASSES_ROOT\clsid\{014da6cd-189f-421a-88cd-07cfe51cff10}

I have pest patrol now, and I went to the website. Pest patrol didn't find anything. And when I search on the website it comes up with:
CreateRecordset error '8004167a'
Invalid query.
/Search/query.asp, line 167.
Please tell me what I'm doing wrong (I still think Hijack this will help, so if u know what I should delete, tell me). Thanks again : )

![]() |
![]() |
![]() |

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.
| Ads by Google |