1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Rogue program

Discussion in 'Malware and Virus Removal Archive' started by sc04, 2004/04/15.

Thread Status:
Not open for further replies.
  1. 2004/04/15
    sc04

    sc04 Inactive Thread Starter

    Joined:
    2004/04/15
    Messages:
    12
    Likes Received:
    0
    Hi all,

    A bunch of garbage downloaded from a site when I walked away from my computer for minute.

    I ran Spybot S&D and took out most of it but some sort of purity scan software keeps coming back. Spybot supposedly takes it out of commission but upon reboot, it's always back when I run Spybot.

    I went to startup in msconfig and unchecked a search bar also.

    Now whenever I reboot, I get a msg that my startup is selective and I should switch back to normal. Hmmm. Don't I want it to be selective?

    Another thing is when I look at things on the startup tab, I see one that has no name under startup item and shows no command but it's checked...should it be?

    Should these be there? Not sure what they are.
    dpi.exe
    urpo.exe
    4o4.exe
    Malprg9.exe
    dp-k13w13.exe
    pcsvc.exe

    Thanks for any help you can give. I'm stumped after running a virus scan and Spybot S&D. :(

    Sheila
     
    sc04,
    #1
  2. 2004/04/15
    Daizy

    Daizy Inactive

    Joined:
    2002/02/19
    Messages:
    2,965
    Likes Received:
    0
    Welcome to the boards!

    Just put a check in the little box to the left and click ok. It's supposed to be selective..yes.

    I had a lengthy reply all typed for you...and I've changed my mind.
    I'm thinking you may have a trojan.
    Download, install, update, and run adaware

    Put a check mark beside all it finds.

    Then go back and redo a spybot run.

    Post back and let us know.
     
    Last edited: 2004/04/15

  3. to hide this advert.

  4. 2004/04/16
    markp62

    markp62 Geek Member Alumni

    Joined:
    2002/05/01
    Messages:
    4,012
    Likes Received:
    16
    After using Ad-Aware, run CWShredder, then run HijackThis, and post the log on here. The links are below.
    And no, those files you posted running at startup probably should not be there. Doubtless these are changing everything back.
    These are baddies.
    dpi.exe
    4o4.exe
    pcsvc.exe
    dp-k13w13.exe
    These are unknown to me.
    urpo.exe
    Malprg9.exe

    I could make a better decision after Ad-Aware andCWShredder has done their thing and the HijackThis log is posted.
     
  5. 2004/04/17
    Daizy

    Daizy Inactive

    Joined:
    2002/02/19
    Messages:
    2,965
    Likes Received:
    0
    How goes the battle sc04 ? Any luck?
     
  6. 2004/04/17
    TonyT

    TonyT SuperGeek Staff

    Joined:
    2002/01/18
    Messages:
    9,072
    Likes Received:
    400
    Malprg9.exe:

    Doesn't sound like a good app, but who kknows.
    Malprg is sometimes a shortened form of the word Malpurg.
    Malpurg is apparantly a word in the Enochian Language.
    Enochian Language is supposed to be the language of Angels.

    Translated to English, malprg or malprug means "a through-thrusting fire ".

    I would locate this file and then virus scan it!
     
  7. 2004/04/17
    sc04

    sc04 Inactive Thread Starter

    Joined:
    2004/04/15
    Messages:
    12
    Likes Received:
    0
    So far I have run Ad-Aware 3x with a reboot after the 1st 2. I followed up with Spybot S&D and it showed no problems at all.

    Each time Ad-Aware found problems - 91, 56, and the last run showed 23.

    The &#$^#(& thing seems to recreate itself. If you end process, you get another process starting up right away. If you explore and delete a .exe file another one appears with a new name almost instantly.

    I ran Trend's housecall virus scan...results showed as uncleanable Sandbox.A

    LOL this is frustrating.

    Thanks for the all the help you've given.

    Sheila
     
    sc04,
    #6
  8. 2004/04/17
    Lonny Jones

    Lonny Jones Inactive Alumni

    Joined:
    2002/12/16
    Messages:
    2,252
    Likes Received:
    0
    Restart the PC Surf a bit then Post a hijackthis log,
    (meanwhile dont stop a proccess or run an antispyware app).


    Post a log from HijackThis so our forum members can see
    what's going on. The current version is 1.97.7 [created by merijn bellekom]
    Most of what it lists will be harmless, even essential,DON'T fix anything yet please.

    Firt make a new folder, for instance C:Antispyware

    Get it here http://radiosplace.com/ choose save, NOT OPEN
    Save it to that new folder, double-click HijackThis.exe,
    and hit "Scan ". When the scan is finished, the "Scan" button will change into a "Save Log" button. Press that, It will load it in Notepad, and copy its contents here.
    Close hijackthis and notepad
    If you've used it before please dont have anything excluded
     
  9. 2004/04/18
    TonyT

    TonyT SuperGeek Staff

    Joined:
    2002/01/18
    Messages:
    9,072
    Likes Received:
    400
    Sandbox is the reason the stuff keeps coming back.

    http://www.sophos.com/virusinfo/analyses/trojsandboxa.html

    Troj/Sandbox-A is a Trojan that copies itself to the default system folder a number of times as files with randomly generated names and hidden and system attributes.
    Once running Troj/Sandbox-A will continually try to connect to the internet in an attempt to download files and possibly to try and update itself.
     
  10. 2004/04/18
    sc04

    sc04 Inactive Thread Starter

    Joined:
    2004/04/15
    Messages:
    12
    Likes Received:
    0
    It seemed like I finally managed to get rid of my demons but since I hadn't rebooted since my last stab at it, I rebooted and ran Hijackthis.exe

    Logfile of HijackThis v1.97.7
    Scan saved at 11:42:29 PM, on 4/18/2004
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\System32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\System32\CTsvcCDA.exe
    C:\WINDOWS\myCIO\VScan\McShield.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\WINDOWS\myCIO\Agent\myAgtSvc.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\BCMSMMSG.exe
    C:\WINDOWS\system32\dla\tfswctrl.exe
    C:\WINDOWS\System32\DSentry.exe
    C:\Program Files\Dell\Media Experience\PCMService.exe
    C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
    C:\Program Files\Common Files\Dell\EUSW\Support.exe
    C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\Symantec\Ghost\ngctw32.exe
    C:\WINDOWS\myCIO\Agent\swAgent.exe
    C:\WINDOWS\System32\MsPMSPSv.exe
    C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
    C:\Downloaded Programs\ebooks AdCyclone\HijackThis.exe
    C:\WINDOWS\myCIO\Agent\myAgttry.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://sjc02.buildreferrals.com/homerotator.cgi
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dellnet.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,Shellnext = http://www.dellnet.com/
    R3 - URLSearchHook: IncrediFindBHO Class - {5D60FF48-95BE-4956-B4C6-6BB168A70310} - C:\PROGRA~1\INCRED~1\BHO\INCFIN~1.DLL__SpybotSDDisabled (file missing)
    O1 - Hosts: 12.129.205.209 search.netscape.com12.129.205.209 sitefinder.verisign.com
    O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
    O2 - BHO: (no name) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
    O2 - BHO: NavErrRedir Class - {5D60FF48-95BE-4956-B4C6-6BB168A70310} - C:\PROGRA~1\INCRED~1\BHO\INCFIN~1.DLL__SpybotSDDisabled (file missing)
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
    O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
    O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
    O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
    O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe "
    O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup
    O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
    O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
    O4 - HKLM\..\Run: [McRegWiz] C:\PROGRA~1\mcafee.com\agent\mcregwiz.exe /autorun
    O4 - HKLM\..\Run: [myCIO.com ASaP] C:\WINDOWS\myCIO\Agent\myagttry.exe
    O4 - HKLM\..\Run: [myCIO.com Splash] C:\WINDOWS\myCIO\VScan\Splash.exe
    O4 - HKLM\..\Run: [NGClient] C:\Program Files\Symantec\Ghost\ngctw32.exe
    O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - Startup: PowerReg Scheduler V3.exe
    O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: Shortcut to login.lnk = Login\login.bat
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
    O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
    O9 - Extra 'Tools' menuitem: MaxSpeed (HKLM)
    O9 - Extra button: Research (HKLM)
    O9 - Extra button: Related (HKLM)
    O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
    O9 - Extra button: Real.com (HKLM)
    O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
    O16 - DPF: {40289096-9F72-4A04-BCB3-E434ECDCEE33} (AppDLCtrl Class) - http://download.howudodat.com/chatterbox/download/appdl.cab
    O16 - DPF: {40C83AF8-FEA7-4A6A-A470-431EE84A0886} (SecureObjectFactory Class) - http://virusscanasap.mcafeeasap.com/VS2/SonicWall/bin/myCioAgt.cab
    O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004033001/housecall.antivirus.com/housecall/xscan53.cab
    O16 - DPF: {E9883A17-F0DC-4476-9A9B-D1E2117E7841} (CMPanel Control) - https://www.qchex.com/cm/QchexCheckMessenger.cab


    Wow! Long list:eek:

    Sheila
     
    sc04,
    #9
  11. 2004/04/19
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Scan with HJT again, place a check next to these, close all other windows and click fix.

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about :blank
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://sjc02.buildreferrals.com/homerotator.cgi
    R3 - URLSearchHook: IncrediFindBHO Class - {5D60FF48-95BE-4956-B4C6-6BB168A70310} - C:\PROGRA~1\INCRED~1\BHO\INCFIN~1.DLL__SpybotSDDisabled (file missing)
    O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
    O2 - BHO: NavErrRedir Class - {5D60FF48-95BE-4956-B4C6-6BB168A70310} - C:\PROGRA~1\INCRED~1\BHO\INCFIN~1.DLL__SpybotSDDisabled (file missing)
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background


    Delete the IncrediFind folder in your Program Files. ReBoot.
     
  12. 2004/04/19
    Lonny Jones

    Lonny Jones Inactive Alumni

    Joined:
    2002/12/16
    Messages:
    2,252
    Likes Received:
    0
    Good news I dont see it, bad news is our anti virus programs and
    there onlines scans and even our anti spyware programs might not get it or all of it correctly , so I would like you to post a fresh log in about two days. with out fixing anything in the meantime.
    If/when it returns there is an uninstaller


    Untill then these can be fixed.
    Place a check next to these close IE and even folders, then hit fix selected
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about :blank
    fix This unless you set it >>R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://sjc02.buildreferrals.com/homerotator.cgi
    R3 - URLSearchHook: IncrediFindBHO Class - {5D60FF48-95BE-4956-B4C6-6BB168A70310} - C:\PROGRA~1\INCRED~1\BHO\INCFIN~1.DLL__SpybotSDDisabled (file missing)
    O1 - Hosts: 12.129.205.209 search.netscape.com12.129.205.209 sitefinder.verisign.com
    O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
    O2 - BHO: NavErrRedir Class - {5D60FF48-95BE-4956-B4C6-6BB168A70310} - C:\PROGRA~1\INCRED~1\BHO\INCFIN~1.DLL__SpybotSDDisabled (file missing)
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
    ========

    Reboot is not nessesary this time

    Then delete this folder
    C:\PROGRAM FILES\INCREDIFIND

    what is this ? >> O4 - Global Startup: Shortcut to login.lnk = Login\login.bat
     
  13. 2004/04/21
    sc04

    sc04 Inactive Thread Starter

    Joined:
    2004/04/15
    Messages:
    12
    Likes Received:
    0
    2 Days later - rebooted and didn't run Spybot or AdAware.

    Logfile of HijackThis v1.97.7
    Scan saved at 7:26:29 AM, on 4/21/2004
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\System32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\System32\CTsvcCDA.exe
    C:\WINDOWS\myCIO\VScan\McShield.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\WINDOWS\myCIO\Agent\myAgtSvc.exe
    C:\Program Files\Symantec\Ghost\ngctw32.exe
    C:\WINDOWS\myCIO\Agent\swAgent.exe
    C:\WINDOWS\System32\MsPMSPSv.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\BCMSMMSG.exe
    C:\WINDOWS\system32\dla\tfswctrl.exe
    C:\WINDOWS\System32\DSentry.exe
    C:\Program Files\Dell\Media Experience\PCMService.exe
    C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
    C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
    C:\Program Files\Common Files\Dell\EUSW\Support.exe
    C:\WINDOWS\myCIO\Agent\myagttry.exe
    C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe
    C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Downloaded Programs\ebooks AdCyclone\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://sjc02.buildreferrals.com/homerotator.cgi
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dellnet.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,Shellnext = http://www.dellnet.com/
    O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
    O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
    O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
    O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
    O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe "
    O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup
    O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
    O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
    O4 - HKLM\..\Run: [McRegWiz] C:\PROGRA~1\mcafee.com\agent\mcregwiz.exe /autorun
    O4 - HKLM\..\Run: [myCIO.com ASaP] C:\WINDOWS\myCIO\Agent\myagttry.exe
    O4 - HKLM\..\Run: [myCIO.com Splash] C:\WINDOWS\myCIO\VScan\Splash.exe
    O4 - HKLM\..\Run: [NGClient] C:\Program Files\Symantec\Ghost\ngctw32.exe
    O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - Startup: PowerReg Scheduler V3.exe
    O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: Shortcut to login.lnk = Login\login.bat
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
    O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
    O9 - Extra 'Tools' menuitem: MaxSpeed (HKLM)
    O9 - Extra button: Research (HKLM)
    O9 - Extra button: Related (HKLM)
    O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
    O9 - Extra button: Real.com (HKLM)
    O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
    O16 - DPF: {40289096-9F72-4A04-BCB3-E434ECDCEE33} (AppDLCtrl Class) - http://download.howudodat.com/chatterbox/download/appdl.cab
    O16 - DPF: {40C83AF8-FEA7-4A6A-A470-431EE84A0886} (SecureObjectFactory Class) - http://virusscanasap.mcafeeasap.com/VS2/SonicWall/bin/myCioAgt.cab
    O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004033001/housecall.antivirus.com/housecall/xscan53.cab
    O16 - DPF: {E9883A17-F0DC-4476-9A9B-D1E2117E7841} (CMPanel Control) - https://www.qchex.com/cm/QchexCheckMessenger.cab

    Hope things are cleaner this time. :rolleyes:

    Thanks much for all the help you guys have provided.

    Sheila
     
  14. 2004/04/21
    markp62

    markp62 Geek Member Alumni

    Joined:
    2002/05/01
    Messages:
    4,012
    Likes Received:
    16
    I would definitely recommend getting rid of this.
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://sjc02.buildreferrals.com/homerotator.cgi
    I went to that link using Mozilla, in 5 different tabs I ended up at cashclick.com, hitsnapper.com, fastfreeway.com, mpamstart.com, and trafficrun.com. You could say you never know where you are going to end up.
    It seems to be some sort of cash for click, if you are a part of this, never mind.
     
  15. 2004/04/21
    Lonny Jones

    Lonny Jones Inactive Alumni

    Joined:
    2002/12/16
    Messages:
    2,252
    Likes Received:
    0
    So how are things now ?
     
  16. 2004/04/22
    sc04

    sc04 Inactive Thread Starter

    Joined:
    2004/04/15
    Messages:
    12
    Likes Received:
    0
    Hi guys,

    Everything seems to be ok. I'm not getting ads in my face and the computer seems to be running fine...not slowing down etc.

    Thanks for all the help given. This forum is by far the best I've ever found.

    Sheila
     
  17. 2004/04/23
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Glad to help Sheila. Thanks for posting back! :)
     
Thread Status:
Not open for further replies.

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.