PDA

View Full Version : Fuck You Lop.com!



Ben
09-30-2004, 12:53 AM
I have no clue how, but I clicked to open IE and I got owned by the fuckin lop.com toolbar, and I cant seem to be able to remove it for the life of me.

I've tried both adaware 6 and Spybot S&D, both have failed. I grabbed the uninstall off the lop website, didn't do anything.

Anyone know how I can get rid of this, it's pissing the hell out of me.

Ben
09-30-2004, 12:55 AM
I HATE THIS COMPANY!!!

Will@STRD
09-30-2004, 01:01 AM
I have the same problem!! pls help!!

JAYMEZ
09-30-2004, 01:07 AM
Hrmm , deleted offline content, deleted cookies , add and remove , windows temp files , My downloads , ehhh hrmm

sml
09-30-2004, 01:37 AM
stop surfing porn!!! haha! jk!

ZorroAMG
09-30-2004, 02:37 AM
Ben, maybe you should switch to the dark side of computing...:D:devil:

SaabKraft
09-30-2004, 02:49 AM
don't use IE...

DL firefox and set it to block pop ups and accept cookies from sites you go to, not advertisers on that site. a free multi platform open source browser.

unfortunately IE is embedded in windows as it's the same system used to browse your system, (or something to that effect). so you can't rid yourself of the stupid thing.

i don't know why people would still put up with microsoft's browser :dunno:

FrostyLight
09-30-2004, 02:54 AM
You guys, hold on.

I got hit by the same thing.

For me, it was hidden in the Windows -> Prefetch folder
and had the name Bold "something I dont remember what" .exe
(along with other locations that you mentioned)

Have you checked there yet?

You also have to run the Ad-aware in Safe mode - you can look on Microsoft's search and figure out how to do that.
Otherwise, it just stays in your comp.

I just found the offending EXE file there (in Prefetch), and used Shift+Delete (that deletes it instead of moving to the Recycle bin)

And, while in Safe mode, look in your Programs folders and delete the folders you know were not there before. For me, it was 4 Internet Helper
and some other crap.

Hope this helps.

I dont have any more of this crap on my IE... :thumbsup:

EDIT: In addition, delete cookies as well, and any internet related stuff. You dont have to delete your Saved Links though.
Also, while in Safe Mode:
go to Start -> Run
type in INETCPL.CPL
hit Enter
and change your homepage if it has been hijacked.

SpoonEK9@STRD
09-30-2004, 03:03 AM
firefox is an excellent program, every one should use it until ie gets fixed lol. i forgot what program is good.. i think its stormspyware.com, then you can get the patch (haxor shit) from astalavista.box.sk

FrostyLight
09-30-2004, 03:06 AM
Firefox is okay in some aspects, but I've found that it's missing a few components of IE that I appreciate.

Dont get me wrong - Firefox is great in its own right. It works like its supposed to. Better than IE in some ways.

Ben
09-30-2004, 06:32 AM
I'm using Win2k btw.

I have deleted all the temp stuff, looked through every folder, it's fucked.

It's definatly imbedded into IEXPLORER, because when I open task manager, I only have one window open, but it shows 3 IE tasks running, and they are hogging my resources big time.

I can end them, but they're back the moment I use IE again.

FrostyLight
09-30-2004, 06:48 AM
Originally posted by Ben
I'm using Win2k btw.

I have deleted all the temp stuff, looked through every folder, it's fucked.

It's definatly imbedded into IEXPLORER, because when I open task manager, I only have one window open, but it shows 3 IE tasks running, and they are hogging my resources big time.

I can end them, but they're back the moment I use IE again.

Its obviously got some kind of .exe somewhere.
If you know the name of the file or the name of something suspicious, try searching for it. See if it shows up somewhere.

just search for the name, and see if you can find an "exe" somewhere...if you do, delete that.

hope that works.

sputnik
09-30-2004, 07:06 AM
Google is your friend...

http://sarc.com/avcenter/venc/data/adware.lop.html

Ben
09-30-2004, 08:04 AM
I spent over an hour on google last night before making this thread...that doesn't help me seeing as how I'm NOT a NORTON user.

Gonthro
09-30-2004, 08:08 AM
i recommend Maxthon browser, it is identical to IE, its veen based off of IE, but it has added features that IE does not have like Tabbed Browsing and a GREAT popup blocker and i have never gotten any of this crap since using it... chekc it out at www.maxthon.com

Ben
09-30-2004, 08:12 AM
Originally posted by FrostyLight


Its obviously got some kind of .exe somewhere.
If you know the name of the file or the name of something suspicious, try searching for it. See if it shows up somewhere.

just search for the name, and see if you can find an "exe" somewhere...if you do, delete that.

hope that works.

it's included in iexplorer.exe. only way to close the program is by closing iexplorer.exe

Fuck this.

I havent been on any porn sites, last thing I remember clicking on befor I noticed it was a link in the alienware thread.

Normally I'm pretty good at ridding shit from my system, however this sucks anus.

sabad66
09-30-2004, 08:16 AM
Doesn't the new SP2 have some kind of control panel where you can remove things that open with Internet Explorer?

roopi
09-30-2004, 08:17 AM
Just found these instructions:

How to manually remove Lop.com Adware from your system?



* WARNING : Modifying your registry or system files can render your system unusable in case of any error.


Remove lop.com step 1: Open the Application Data folder. This can be found inside the Windows folder on Windows 95/98/Me; on Windows 2000 and XP it is inside your user folder in 'Documents and Settings', but it's hidden, so go to Tools->Folder Options->View and turn on 'Show hidden files and folders' to see it. In Windows NT 4.0 it is in the user folder inside 'WinNTProfiles'.
The filenames of lop files can vary for each different installation, but usually under Windows there should not be any files inside Application Data (only folders), so it's generally easy to pick out the culprits.


You should also delete the following entries if you have them and they are not just blank:
HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersion\r TelephonyDomainName

HKEY_LOCAL_MACHINESystemCurrentControlSetServicesVxD\r MSTCPDomain

HKEY_LOCAL_MACHINESystemCurrentControlSetServicesTcpip\r ParametersDomain

HKEY_LOCAL_MACHINESystemCurrentControlSetServicesTcpip\r ParametersInterfaces{...check all interfaces...}Domain

roopi
09-30-2004, 08:21 AM
Actually check this out as well:

http://www.doxdesk.com/parasite/lop.html

http://www.nibbleguru.com/probs/100/244

I'd use Hijack this.

Ben
09-30-2004, 08:32 AM
Thanks for the info roopi, I'll give that a shot when I get home.

I find it comical that it happens on the last day using this old computer, new system gets delivered today and my old one is for my parents. haha, now I have to tinker with 2 computers now. haha.





Originally posted by sabad66
Doesn't the new SP2 have some kind of control panel where you can remove things that open with Internet Explorer?



Originally posted by Ben
I'm using Win2k btw.

soupey
09-30-2004, 08:54 AM
its messed cuz i get adware on my comp if i leave it plugged into the network while installing windows, i guess once the network is installed adware has its own way of gettn in even b4 windows has fully installed itself, it sucks...but yea, i use firefox now and CAN'T complain at all


although i did check IE out again after getting the service pack....the revamped firewall and popup blocker is impressive, but still doesn't block as much as firefox, but a pretty good improvement

i'd say get the windows update once or if u get rid of the adbar, or jus stick to mozilla firefox...
www.mozilla.com for that

only thing iguess some ppl will complain about, firefox doesn't have all the bells n whistles for personal websites, places like calgaryplanet.com where ppl put a bunch of uncommon html to pimp up their site won't work wit mozilla, music, some animations, some layers, etc...but im guessin thats of no use 2 u since...but either way u should kno...

good luck wit the whole situation...

Khyron
09-30-2004, 09:05 AM
Download and run HijackThis - it catches all those fucking browser hooks that spy/adaware don't. I've removed tons from computers at work.

It's pretty simple - just look up stuff on google before blindly disabling plugins.

http://www.tomcoyote.org/hjt/

Khyron

E36M3
09-30-2004, 09:05 AM
I recently had to clean a friends computer of the same thing, and began by restarting in safe mode, running AdAware and then manually cleaning up the Registry / File system (instructions above will help with that).

I agree with the other people who have recommended FireFox. I've been running it for several months now and am very satisfied (I switched from Safari to Firefox as I run OS X).

Not only is it more accurate at rendering, it is also quite fast (not sure about the performance on Windows vs. IE, but I am sure it is competitive).

We've seen a huge number of people switching from IE in the last few months due to these type of serious security issues, and I can guarantee that they will only get worse.

Also, did you know that Microsoft is no longer issuing security patches for Windows 2000? Might be a good reason for you to dump IE.. you are probably still vulnerable to the JPEG flaw which will go crazy over the next couple weeks.

Ben
09-30-2004, 09:22 AM
Yeah. I think thats what I'll end up doing.

My new system will be running Win XP Pro SP2, and I'll run a different browser, (firefox seems popular)

For this syetm, I'll see if I can fix it via registry, however I may just end up doing a nice fresh format and start from scratch with all the updates right away.

roopi
09-30-2004, 10:19 AM
Originally posted by Ben
For this syetm, I'll see if I can fix it via registry, however I may just end up doing a nice fresh format and start from scratch with all the updates right away.

I'd definately do this instead of cleaning it. You're moving to a new system anyways.

MaximumSpeed
09-30-2004, 10:51 AM
Originally posted by roopi
Actually check this out as well:

http://www.doxdesk.com/parasite/lop.html

http://www.nibbleguru.com/probs/100/244

I'd use Hijack this.

I'd also recommend HiJack This, nice program to rid yourself of all that junk. But be careful, not everything it shows is junk. Post up the log file it creates and I'll let you know what to get rid of. Or better yet, you can post it here:
http://forums.spywareinfo.com/
People in that forum will help you get rid of anything spyware related.

Hope this helps.

civicrider
09-30-2004, 11:03 AM
yah i had something similar to this, i just gave up and took my computer to a shop to get cleared :banghead:

roopi
09-30-2004, 12:21 PM
Originally posted by civicrider
yah i had something similar to this, i just gave up and took my computer to a shop to get cleared :banghead:

Many people on Beyond are capable of fixing something like this. Next time give me a case of beer and I'll fix it up for you.

Kid_a
09-30-2004, 12:33 PM
Why don't you just do a system restore to yesterday? Whenever something fucked up is on my PC and I can't get rid of it, I just restore to the previous day.

good luck

nismodrifter
09-30-2004, 02:12 PM
hijack this usually fixes this kind of bullshit, give it a try

Ben
09-30-2004, 02:14 PM
yeah, but you have to pay for that shit dont you?!

Khyron
09-30-2004, 02:17 PM
Originally posted by Ben
yeah, but you have to pay for that shit dont you?!

No it's free. It's like msconfig for your browser.

Khyron

Ben
09-30-2004, 02:25 PM
well wtf, I download them, but it wantch to charge me 30 bucks USD to remove the shit once it finds it.,

ninjak84
09-30-2004, 02:42 PM
Originally posted by Ben
well wtf, I download them, but it wantch to charge me 30 bucks USD to remove the shit once it finds it.,

Fuck do I ever hate programs like this.

"We found the problem, and even though the page calls this program freeware, we aren't doing shit unless you pay us."

roopi
09-30-2004, 02:42 PM
Originally posted by Ben
well wtf, I download them, but it wantch to charge me 30 bucks USD to remove the shit once it finds it.,

Are you referring to Hijack this?

Khyron
09-30-2004, 02:47 PM
He must be downloading the program from the Banner Ad at the top of the page (advertising).

The link for Hijack this is 1/4 down the page on the left:

Download HijackThis

use the button for direct download

It has a big green flashing button...

It's a zip file with a single EXE in it - no installer, no BS.

EDIT: Here's a direct link - just run the exe right out of the zip folder.

HijackThis (http://www.nexus-point.net/tmp/hijackthis.zip)

Khyron

legendboy
09-30-2004, 02:51 PM
hijackthis !

three.eighteen.
09-30-2004, 06:09 PM
spyware sucks, i had my computer like 99.9% cleaned but every time i opened IE coolwebsearch would do its thing over again, i've since switched to firefox and surfed like i used to

SportTwin
09-30-2004, 10:49 PM
pchell.com is a wicked resource for this kind of crap.

http://www.pchell.com/support/hijackthistutorial.shtml

If you want to try something else that I've found to work sometimes, check out a program called IE-SPYAD. It places a whole bunch of spyware sites in the restricted zone of IE (if you're using IE that is) and by disabling activeX for restricted zone sites they can't do a drive-by install of their spyware garbage.

... of course, you could just use firefox...

hjr
09-30-2004, 11:08 PM
ive been running mozilla and firefox for about 6 months now with no problems with their software (i like firefox much better). i used to get hit with 1 -5 spyware programs per day with ie6, now, almost nothing. i use adaware 6, spybot, and spyware blaster. i havent needed them that much though thanks to not using ie6.

roopi
10-01-2004, 08:13 AM
So any luck with this Ben?

Ben
10-01-2004, 08:25 AM
haha, as a matter of fact, yeah...no more toolbars and popups, haha. Not sure exactly what finally solved it. I ran that Hijack this prog, didn't fix anything that I could tell, tho I deleted the google toolbar with it.

Reinstalled the google bar and I think that might have been what fixed it...not 100% tho.

Khyron
10-01-2004, 08:40 AM
Originally posted by Ben
haha, as a matter of fact, yeah...no more toolbars and popups, haha. Not sure exactly what finally solved it. I ran that Hijack this prog, didn't fix anything that I could tell, tho I deleted the google toolbar with it.

Reinstalled the google bar and I think that might have been what fixed it...not 100% tho.

Post your hijack this log - it shows all hooks and plugins. You have to manually decide what to fix and what to leave - it's not like adaware where you just run it and walk away...

Khyron

CRXguy
10-01-2004, 01:59 PM
Logfile of HijackThis v1.98.2
Scan saved at 10:13:02 PM, on 9/30/2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\System32\Ati2evxx.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Canon\BJCard\Bjmcmng.exe
C:\Program Files\NavNT\defwatch.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\NavNT\rtvscan.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\Program Files\WMPCI54G WLAN Monitor\WLService.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\WMPCI54G WLAN Monitor\WMP54G.exe
C:\WINNT\system32\MsgSys.EXE
C:\WINNT\Explorer.EXE
C:\Program Files\NavNT\vptray.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINNT\czyyfve.exe
C:\winnt\system32\taskmgn.exe
C:\Program Files\Canon\BJPV\TVMon.exe
C:\Program Files\Canon\BJCard\BJLaunch.exe
C:\Program Files\WindUpdates\WinUpdt.exe
C:\WINNT\system32\amzkctsb.exe
C:\Program Files\WindUpdates\WinKA.exe
C:\PROGRA~1\INTERN~1\iexplore.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINNT\system32\wuauclt.exe
C:\Program Files\Ares\Ares.exe
C:\WINNT\medload.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINNT\medload.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Administrator\My Documents\Car vids\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = websearch.drsnsrch.com/q.cgi?q=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.msn.ca/
O2 - BHO: (no name) - {0000607D-D204-42C7-8E46-216055BF9918} - (no file)
O2 - BHO: Band Class - {01F44A8A-8C97-4325-A378-76E68DC4AB2E} - C:\WINNT\systb.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: BAHelper Class - {A3FDD654-A057-4971-9844-4ED8E67DBBB8} - C:\Program Files\SideFind\sfbho.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: NLS UrlCatcher Class - {AEECBFDA-12FA-4881-BDCE-8C3E1CE4B344} - C:\WINNT\system32\nvms.dll
O2 - BHO: CB UrlCatcher Class - {CE188402-6EE7-4022-8868-AB25173A3E14} - C:\WINNT\system32\mscb.dll
O2 - BHO: ADP UrlCatcher Class - {F4E04583-354E-4076-BE7D-ED6A80FD66DA} - C:\WINNT\system32\msbe.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file)
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [vptray] C:\Program Files\NavNT\vptray.exe
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINNT\System32\\NeroCheck.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [KAZAA] "C:\Program Files\Kazaa Lite K++\kpp.exe" "C:\Program Files\Kazaa Lite K++\Kazaa.kpp" /SYSTRAY
O4 - HKLM\..\Run: [Windows Task Manager] C:\winnt\system32\taskmgn.exe
O4 - HKLM\..\Run: [STOPzilla] "C:\Program Files\STOPzilla!\Stopzilla.exe" /autorun
O4 - HKLM\..\Run: [BJPD HID Control] C:\Program Files\Canon\BJPV\TVMon.exe
O4 - HKLM\..\Run: [BJLaunchEXE] C:\Program Files\Canon\BJCard\BJLaunch.exe
O4 - HKLM\..\Run: [WindUpdates] C:\Program Files\WindUpdates\WinUpdt.exe
O4 - HKLM\..\Run: [zrwtmpy] C:\WINNT\system32\amzkctsb.exe
O4 - HKLM\..\Run: [loads.exe] C:\WINNT\medload.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: SideFind - {10E42047-DEB9-4535-A118-B3F6EC39B807} - C:\Program Files\SideFind\sidefind.dll
O16 - DPF: {0246ECA8-996F-11D1-BE2F-00A0C9037DFE} (TDServer Control) - http://www.truedoc.com/activex/tdserver.cab
O16 - DPF: {87067F04-DE4C-4688-BC3C-4FCF39D609E7} - http://download.websearch.com/Dnl/T_50188/QDow_AS2.cab
O16 - DPF: {CA034DCC-A580-4333-B52F-15F98C42E04C} (Downloader Class) - http://www.stopzilla.com/_download/Auto_Installer/dwnldr.cab
O16 - DPF: {E0CE16CB-741C-4B24-8D04-A817856E07F4} (IObjSafety.DemoCtl) - http://cabs.media-motor.net/cabs/mmed.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{A8361874-AB23-47C4-A52B-E0EE5A6F82B9}: NameServer = 64.59.135.133,64.59.135.135

There's my log. Any help?

Oh yeah, I keep getting this stupid popup from www.popuppers.com

Can't seem to get rid of it. :banghead:

Khyron
10-01-2004, 02:33 PM
Do the following at your own risk.

Grim:

C:\WINNT\czyyfve.exe
C:\Program Files\WindUpdates\WinUpdt.exe (Definately evil)
C:\WINNT\system32\amzkctsb.exe
C:\Program Files\WindUpdates\WinKA.exe (Definately evil)
C:\Program Files\Ares\Ares.exe
C:\WINNT\medload.exe (No idea what this is, but you shouldn't need it.)

Is your norton even up to date?

Uninstall ALL your search helpers/toolbars, etc including the google bar and stopZilla (you can put them back later if you want).

Rerun Hijackthis with NO browsers open (not even this one).

Mark and Fix the following (if it's still there).

R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = websearch.drsnsrch.com/q.cgi?q=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.msn.ca/
O2 - BHO: (no name) - {0000607D-D204-42C7-8E46-216055BF9918} - (no file)
O2 - BHO: Band Class - {01F44A8A-8C97-4325-A378-76E68DC4AB2E} - C:\WINNT\systb.dll
O2 - BHO: BAHelper Class - {A3FDD654-A057-4971-9844-4ED8E67DBBB8} - C:\Program Files\SideFind\sfbho.dll
O2 - BHO: NLS UrlCatcher Class - {AEECBFDA-12FA-4881-BDCE-8C3E1CE4B344} - C:\WINNT\system32\nvms.dll
O2 - BHO: CB UrlCatcher Class - {CE188402-6EE7-4022-8868-AB25173A3E14} - C:\WINNT\system32\mscb.dll
O2 - BHO: ADP UrlCatcher Class - {F4E04583-354E-4076-BE7D-ED6A80FD66DA} - C:\WINNT\system32\msbe.dll
O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file)
O4 - HKLM\..\Run: [KAZAA] "C:\Program Files\Kazaa Lite K++\kpp.exe" "C:\Program Files\Kazaa Lite K++\Kazaa.kpp" /SYSTRAY
O4 - HKLM\..\Run: [STOPzilla] "C:\Program Files\STOPzilla!\Stopzilla.exe" /autorun
O4 - HKLM\..\Run: [WindUpdates] C:\Program Files\WindUpdates\WinUpdt.exe
O4 - HKLM\..\Run: [zrwtmpy] C:\WINNT\system32\amzkctsb.exe
O4 - HKLM\..\Run: [loads.exe] C:\WINNT\medload.exe
O9 - Extra button: SideFind - {10E42047-DEB9-4535-A118-B3F6EC39B807} - C:\Program Files\SideFind\sidefind.dll
O16 - DPF: {0246ECA8-996F-11D1-BE2F-00A0C9037DFE} (TDServer Control) - http://www.truedoc.com/activex/tdserver.cab
O16 - DPF: {87067F04-DE4C-4688-BC3C-4FCF39D609E7} - http://download.websearch.com/Dnl/T_50188/QDow_AS2.cab
O16 - DPF: {CA034DCC-A580-4333-B52F-15F98C42E04C} (Downloader Class) - http://www.stopzilla.com/_download/...ller/dwnldr.cab
O16 - DPF: {E0CE16CB-741C-4B24-8D04-A817856E07F4} (IObjSafety.DemoCtl) - http://cabs.media-motor.net/cabs/mmed.cab


And anyone thinking that it's all IE's fault - most of the spyware/malware is USER INSTALLED. Firefox will save you from those few auto-installing ones (but so will keeping your computer patched) - but it won't stop you from installing stupid helper programs or Banzai buddy.

Khyron

roopi
10-01-2004, 02:41 PM
Originally posted by Khyron
And anyone thinking that it's all IE's fault - most of the spyware/malware is USER INSTALLED. Firefox will save you from those few auto-installing ones (but so will keeping your computer patched) - but it won't stop you from installing stupid helper programs or Banzai buddy.

Khyron

:werd: I've never had a problem with IE. Just watch what you are doing and clicking 'Yes' to and quit looking at so much porn. :D