Ive had enough spyware

  • beings
  • Expert
  • Expert
  • User avatar
  • Posts: 539
  • Loc: Canada

Post 3+ Months Ago

Ok ive had enough of spyware and im ready to leave Explorer. Does explorer cost money? it just came with my computer. I was thinking of getting something else other then explorer. I hear netscape is good, do i need to pay for that? any one have any suggestions for me on what to get insted of Explorer thats free of spyware or at least better then explorer?
  • Anonymous
  • Bot
  • No Avatar
  • Posts: ?
  • Loc: Ozzuland
  • Status: Online

Post 3+ Months Ago

  • rjstephens
  • Professor
  • Professor
  • User avatar
  • Posts: 774
  • Loc: Brisbane, Australia

Post 3+ Months Ago

Netscape is free but it's not very good.

The best borwser out there, many here will agree, is Firefox. Click here to go to the firefox website
BTW, firefox is free

Just so you know, getting rid of internet explorer will not automatically get rid of spyware/adware. However, it will help.

There are two very good programs, both of which are free, that will scan your computer and remove these nasties. These are spybot search and destroy, and ad-aware
Click here to go to the spybot s&d website
Click here to go to the lavasoft website
  • Tone2k11
  • Proficient
  • Proficient
  • Tone2k11
  • Posts: 493
  • Loc: Southampton - UK

Post 3+ Months Ago

Firefox is excellent. [uel]http://www.mozilla.org/products/firefox/[/url]

Features -

Popup Blocking
Stop annoying popup ads in their tracks with Firefox's built in popup blocker.

Tabbed Browsing
View more than one web page in a single window with this time saving feature. Open links in the background so that they're ready for viewing when you're ready to read them.

Smarter Search
Google Search is built right into the toolbar, and there are a plethora of other search tools including Keywords (type "dict <word>" in the Location Bar), and FastFind (start typing the first few letters of some text in the page and Firefox takes you there).

Privacy and Security
Built with your Security in mind, Firefox keeps your computer safe from malicious spyware by not loading harmful ActiveX controls. A comprehensive set of privacy tools keep your online activity your business.

Hassle-Free Downloading
Files you download are automatically saved to your Desktop so they're easy to find. Fewer prompts mean files download quicker.

Fits Like a Glove
Simple and intuitive, yet fully featured, Firefox has all the functions you're used to - Bookmarks, History, Full Screen, Text Zooming to make pages with small text easier to read, etc.

S M L XL XXL XXXL
Firefox is the most customizable browser on the planet. Customize your toolbars to add additional buttons, install new Extensions that add new features, add new Themes to browse with style, and use the adaptive search system to allow you to search an infinite number of engines. Firefox is as big or small as you want.

Setup's a Snap
At only 4.7MB (Windows), Firefox only takes minutes to download over a fast connection. The installer gets you set up quickly, and the new Easy Transition system imports all of your settings - Favorites, passwords and other data from Internet Explorer and other browsers - so you can start surfing right away.
  • UNFLUX
  • Genius
  • Genius
  • User avatar
  • Posts: 6376
  • Loc: twitter.com/unflux

Post 3+ Months Ago

i 2nd everything they just said about FireFox -- good stuff :thumbsup:
  • beings
  • Expert
  • Expert
  • User avatar
  • Posts: 539
  • Loc: Canada

Post 3+ Months Ago

the spyware i have i cannot get rid of. seems like a waste when i paid for ad-adware and it cant keep it killed. spybot also picks up the spyware but cannot destroy it permanently. To make matters worse i used Hijackthis but Hotmail doesnt work. will spyware effect firefox?
  • JrzyCrim
  • Mastermind
  • Mastermind
  • User avatar
  • Posts: 2062

Post 3+ Months Ago

Sometimes if a spyware nasty is currently in use, the spyware removal program will not be able to remove it. Close any browser windows. Run the removal programs from safemode. This increases the chance of sucessful removal. You should try rebooting and re-running the scan to clean up any leftovers. Also, make sure you update the definitions.

You have to be careful with hijack-this. It's not like ad-aware. If you try to 'fix' everthing it displays you are going to be in trouble. Not sure why hotmail isn't working. Can you describe the problem in more detail? Also,
can you post your hijack-this log?

See this tutorial: http://hjt.wizardsofwebsites.com/

A program I recommend is Spwareblaster. It's unlike the other programs in that it passively protects your system from being infected with spyware. It's free and comes with protection for both IE and Mozilla.

http://www.javacoolsoftware.com/spywareblaster.html

As always, preventative maintenance is the best solution.
  • beings
  • Expert
  • Expert
  • User avatar
  • Posts: 539
  • Loc: Canada

Post 3+ Months Ago

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
C:\WINDOWS\system32\syshn32.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\WINDOWS\system32\sdkxa32.exe
C:\Program Files\iolo\System Mechanic 4 Professional\PopupStopper.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\Tristan\Desktop\hjtlog.exe
c:\hijackthis\hijackthis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\vzwhh.dll/sp.html#28129
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://vzwhh.dll/index.html#28129
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://vzwhh.dll/index.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\vzwhh.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://vzwhh.dll/index.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\vzwhh.dll/sp.html#28129
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: (no name) - {006822A7-054C-D4E1-5DD5-312044BEE60E} - C:\WINDOWS\system32\atlcc.dll
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [sdkxa32.exe] C:\WINDOWS\system32\sdkxa32.exe
O4 - HKLM\..\Run: [Ad-aware] "C:\Program Files\Lavasoft\Ad-aware 6\Ad-aware.exe" +c
O4 - HKCU\..\Run: [System Mechanic Popup Stopper] "C:\Program Files\iolo\System Mechanic 4 Professional\PopupStopper.exe"
O4 - Startup: PowerReg Scheduler V3.exe
O4 - User Startup: PowerReg Scheduler V3.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: Research (HKLM)
O10 - Broken Internet access because of LSP provider 'xfire_lsp.dll' missing
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shoc ... tor/sw.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/cabs/ ... 0_0_41.cab
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} (Office Update Installation Engine) - http://office.microsoft.com/officeupdat ... t/opuc.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/24fbdb2a143 ... xIE601.cab
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/200 ... taller.exe
O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} (GSDACtl Class) - http://launch.gamespyarcade.com/softwar ... launch.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004 ... scan53.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Me ... Client.cab
O16 - DPF: {A8658086-E6AC-4957-BC8E-7D54A7E8A78E} (SassCln Object) - http://www.microsoft.com/security/contr ... assCln.CAB
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shoc ... wflash.cab
O16 - DPF: {F54C1137-5E34-4B95-95A5-BA56D4D8D743} (Secure Delivery) - http://www.gamespot.com/KDX/kdx.cab
  • beings
  • Expert
  • Expert
  • User avatar
  • Posts: 539
  • Loc: Canada

Post 3+ Months Ago

i think sdkxa32.exe is part of the spyware because ive never seen it before on my process list. how do i permanently get rid of it?
  • JrzyCrim
  • Mastermind
  • Mastermind
  • User avatar
  • Posts: 2062

Post 3+ Months Ago

Yes it is.

First, close all browser and go off line.

In folder options, uncheck hide protected operating system files.

Open taskmanager and kill sdkxa32.exe. If you've rebooted then this file will probably have a different name.

Next goto Start|Run services.msc. Find "Network Security Service" and double click it. Stop the service and disable at startup. click OK

Have Hijack-this fix the following:

Code: [ Select ]
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\vzwhh.dll/sp.html#28129
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://vzwhh.dll/index.html#28129
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://vzwhh.dll/index.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\vzwhh.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://vzwhh.dll/index.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\vzwhh.dll/sp.html#28129
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: (no name) - {006822A7-054C-D4E1-5DD5-312044BEE60E} - C:\WINDOWS\system32\atlcc.dll
O4 - HKLM\..\Run: [sdkxa32.exe] C:\WINDOWS\system32\sdkxa32.exe
O9 - Extra button: Research (HKLM)
  1. R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\vzwhh.dll/sp.html#28129
  2. R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://vzwhh.dll/index.html#28129
  3. R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://vzwhh.dll/index.html#28129
  4. R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\vzwhh.dll/sp.html#28129
  5. R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://vzwhh.dll/index.html#28129
  6. R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\vzwhh.dll/sp.html#28129
  7. R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
  8. O2 - BHO: (no name) - {006822A7-054C-D4E1-5DD5-312044BEE60E} - C:\WINDOWS\system32\atlcc.dll
  9. O4 - HKLM\..\Run: [sdkxa32.exe] C:\WINDOWS\system32\sdkxa32.exe
  10. O9 - Extra button: Research (HKLM)


Reboot to safe mode and delete these files:

C:\WINDOWS\system32\sdkxa32.exe
C:\WINDOWS\system32\vzwhh.dll

If you found the Network Security Service"
Go to Start | Run | enter regedit

Navigate to:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\__NS_Service_3
Hilight __NS_Service_3 | right click on it and delete.

navigate to:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY___NS_Service_3
Hilight LEGACY___NS_Service_3 then right click on it and delete.

Reboot. Run and update adaware.

Under Settings, tweak, scanning engine, check "Unload recognized processes during scanning."

Under Settings, tweak, Cleaning Engine, check "Let Windows remove files in use after reboot."'

Click "Scan Now"

Check "Use Custom scanning options"

Check "Activate In-Depth Scan"

Click "Select drives\folders to scan" and select C:\

Click next and scan.

After it finishes scanning, right-click in the found objects pane and select all.

Click next. click Ok to let it remove all checked items.

Exit ad-aware

Reboot and run hijack-this again. Post the log, again. :)

I'm not sure about syshn32.exe. Unless you know what it is I'd nix it as well.
  • beings
  • Expert
  • Expert
  • User avatar
  • Posts: 539
  • Loc: Canada

Post 3+ Months Ago

ooooh man you are a god! i salute you, being canada day it means a lot. Thank you so much, the spyware is history. heres my log after. Thanks for taking the time to look over it and help me out, you are nothing short of a god. when this is all over i am saying bye bye to internet explorer.

before you told me to
"Next goto Start|Run services.msc. Find "Network Security Service" and double click it. Stop the service and disable at startup. click OK"

now that the spyware is gone do i need to start that service up again? or just leave in stopped and disabled?

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\Documents and Settings\Tristan\Desktop\hjtlog.exe
c:\hijackthis\hijackthis.exe

O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Ad-aware] "C:\Program Files\Lavasoft\Ad-aware 6\Ad-aware.exe" +c
O4 - Startup: PowerReg Scheduler V3.exe
O4 - User Startup: PowerReg Scheduler V3.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O10 - Broken Internet access because of LSP provider 'xfire_lsp.dll' missing
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shoc ... tor/sw.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/cabs/ ... 0_0_41.cab
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} (Office Update Installation Engine) - http://office.microsoft.com/officeupdat ... t/opuc.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/24fbdb2a143 ... xIE601.cab
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/200 ... taller.exe
O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} (GSDACtl Class) - http://launch.gamespyarcade.com/softwar ... launch.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004 ... scan53.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Me ... Client.cab
O16 - DPF: {A8658086-E6AC-4957-BC8E-7D54A7E8A78E} (SassCln Object) - http://www.microsoft.com/security/contr ... assCln.CAB
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shoc ... wflash.cab
O16 - DPF: {F54C1137-5E34-4B95-95A5-BA56D4D8D743} (Secure Delivery) - http://www.gamespot.com/KDX/kdx.cab
  • JrzyCrim
  • Mastermind
  • Mastermind
  • User avatar
  • Posts: 2062

Post 3+ Months Ago

You're welcome. I added additional things to my last post. Go through and perform those steps as well. I'll have a look at your last log...

Leave "Network Security Service" disabled and delete those reg keys I added in my edited post.

I'm not a god but I have been using various spyware progs for a while. I did a google search and found some info on steps to correct your problem. The problems weren't exactly the same so I had to improvise a bit.

Happy Canada Day!
  • beings
  • Expert
  • Expert
  • User avatar
  • Posts: 539
  • Loc: Canada

Post 3+ Months Ago

happy Canada day indeed. ad-aware came up empty :D Every thing is super now, no spyware in site :D . but i could not delete HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY___NS_Service_3

it said "error when trying to delete key"
the other key deleted fine tho. i was in safe mode when i did the regedit.

thanks again!
  • JrzyCrim
  • Mastermind
  • Mastermind
  • User avatar
  • Posts: 2062

Post 3+ Months Ago

Hmmm, let me get back to you on that...

In the mean time, check and see if that service is still running...
  • JrzyCrim
  • Mastermind
  • Mastermind
  • User avatar
  • Posts: 2062

Post 3+ Months Ago

Try right clicking on that reg key and select permissions. If Administrators or your username is not listed at the top, click add and enter "Adminstrators" or your admin username. click ok. Try deleting the key again.
  • beings
  • Expert
  • Expert
  • User avatar
  • Posts: 539
  • Loc: Canada

Post 3+ Months Ago

the Network Security Service isnt in the services anymore. for the permisions should i allow full control? it is on "read" at the molment
  • JrzyCrim
  • Mastermind
  • Mastermind
  • User avatar
  • Posts: 2062

Post 3+ Months Ago

That's good. That reg key is probably harmless now but I'd feel better if it was gone.

I'd recommend you install spywareblaster. It will greatly reduce the risk of future infection.

http://www.javacoolsoftware.com/spywareblaster.html

Install and update, then enable all protection. It won't use up any system resources. ie it doesn't run in the background.

It comes with protection for IE and Mozilla/Firefox.
  • beings
  • Expert
  • Expert
  • User avatar
  • Posts: 539
  • Loc: Canada

Post 3+ Months Ago

yeah i took your advise before and got the spyware blaster, realy nice layout and easy to set up. Thanks again for everything.
  • JrzyCrim
  • Mastermind
  • Mastermind
  • User avatar
  • Posts: 2062

Post 3+ Months Ago

beings wrote:
the Network Security Service isnt in the services anymore. for the permisions should i allow full control? it is on "read" at the molment


Full control will be fine since you are going to delete it anyway.

Glad everything helped. :)
  • beings
  • Expert
  • Expert
  • User avatar
  • Posts: 539
  • Loc: Canada

Post 3+ Months Ago

ok that worked... i hate to be a pest but how do i properly uninstall internet explorer, i cant find an IE uninstal.exe nor can i find it in add/remove programs, i see the update in add/remove programs but not the entire program.
  • JrzyCrim
  • Mastermind
  • Mastermind
  • User avatar
  • Posts: 2062

Post 3+ Months Ago

You can't really remove it. Some components can be removed but the core files are integrated into the OS. I've heard of people trying to completely remove it but it ended being more trouble than it's worth. Best to leave it.

From http://support.microsoft.com/default.as ... us;q293907

Quote:
NOTE: Internet Explorer 6 is preinstalled by default in all versions of Windows XP. To provide computer manufacturers greater flexibility in configuring desktop versions of Windows XP, Microsoft has made it possible for OEMs, administrators, and users to remove user access to Internet Explorer while leaving the Internet Explorer code intact and fully functional to ensure the functionality of programs and operating system functions that rely on it.
  • beings
  • Expert
  • Expert
  • User avatar
  • Posts: 539
  • Loc: Canada

Post 3+ Months Ago

Ok thank you so much for everything. i guess internet explorer doesnt suck too much of my system speed. having both firefox and explorer should be all right. il make firefox default. Thanks again.
  • JrzyCrim
  • Mastermind
  • Mastermind
  • User avatar
  • Posts: 2062

Post 3+ Months Ago

If you use Windows Updates, you'll need to keep IE installed. Windows Update doesn't work with other browsers.

I don't update through WU myself but I do use the scan occasionally to see if any new criticals are offered.
  • Flintstone_Redneck
  • Newbie
  • Newbie
  • Flintstone_Redneck
  • Posts: 7
  • Loc: GA USA

Post 3+ Months Ago

beings wrote:
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
C:\WINDOWS\system32\syshn32.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\WINDOWS\system32\sdkxa32.exe
C:\Program Files\iolo\System Mechanic 4 Professional\PopupStopper.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\Tristan\Desktop\hjtlog.exe
c:\hijackthis\hijackthis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\vzwhh.dll/sp.html#28129
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://vzwhh.dll/index.html#28129
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://vzwhh.dll/index.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\vzwhh.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://vzwhh.dll/index.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\vzwhh.dll/sp.html#28129
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: (no name) - {006822A7-054C-D4E1-5DD5-312044BEE60E} - C:\WINDOWS\system32\atlcc.dll
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [sdkxa32.exe] C:\WINDOWS\system32\sdkxa32.exe
O4 - HKLM\..\Run: [Ad-aware] "C:\Program Files\Lavasoft\Ad-aware 6\Ad-aware.exe" +c
O4 - HKCU\..\Run: [System Mechanic Popup Stopper] "C:\Program Files\iolo\System Mechanic 4 Professional\PopupStopper.exe"
O4 - Startup: PowerReg Scheduler V3.exe
O4 - User Startup: PowerReg Scheduler V3.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: Research (HKLM)
O10 - Broken Internet access because of LSP provider 'xfire_lsp.dll' missing
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shoc ... tor/sw.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/cabs/ ... 0_0_41.cab
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} (Office Update Installation Engine) - http://office.microsoft.com/officeupdat ... t/opuc.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/24fbdb2a143 ... xIE601.cab
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/200 ... taller.exe
O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} (GSDACtl Class) - http://launch.gamespyarcade.com/softwar ... launch.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004 ... scan53.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Me ... Client.cab
O16 - DPF: {A8658086-E6AC-4957-BC8E-7D54A7E8A78E} (SassCln Object) - http://www.microsoft.com/security/contr ... assCln.CAB
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shoc ... wflash.cab
O16 - DPF: {F54C1137-5E34-4B95-95A5-BA56D4D8D743} (Secure Delivery) - http://www.gamespot.com/KDX/kdx.cab
  • Flintstone_Redneck
  • Newbie
  • Newbie
  • Flintstone_Redneck
  • Posts: 7
  • Loc: GA USA

Post 3+ Months Ago

I use Spybot, Spy Sweeper (paid), Adaware, and Spyware Buster.
all but Spy Sweeper is free.
Spyware Buster is free but if you want to have your comuter automatically updated with latest definitions then it is 9.95 a year and well worth it. What it does it blocks your computer from downloading all the spyware that is in their data base and they have tons of it.

Since I started useing it, I have not had any spyware and up to that point I had tons of it. The spyware was just messing up everything and poping up all kinds of adds and taking me against my will to wherever it wanted to.

I also ran hijackthis and posted my log on their forum. They helped me clean out my registry, telling me what to delte. It worked and did not harm anything like someone else said. You don't want to delete it without them telling you what to delete.

I also deleted messenger service. There is a program called shootthemessenger that allows you to disable it. I went one step further and went to Kelleys korner and clicked on the option to delete it all together. I also went to the start up in msconfig and unchecked for messenger to start up.


Windows messenger is real bad about pop ups and adds etc.
  • beings
  • Expert
  • Expert
  • User avatar
  • Posts: 539
  • Loc: Canada

Post 3+ Months Ago

yeah that messenger thing was realy bad, i got rid of it about 2 years ago.

Post Information

  • Total Posts in this topic: 25 posts
  • Users browsing this forum: No registered users and 45 guests
  • You cannot post new topics in this forum
  • You cannot reply to topics in this forum
  • You cannot edit your posts in this forum
  • You cannot delete your posts in this forum
  • You cannot post attachments in this forum
 
 

© 1998-2014. Ozzu® is a registered trademark of Unmelted, LLC.