1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Address Bar Problem

Discussion in 'Malware and Virus Removal Archive' started by aiki456, 2006/04/12.

  1. 2006/04/15
    Welshjim

    Welshjim Inactive

    Joined:
    2002/01/07
    Messages:
    5,643
    Likes Received:
    0
    Whiskeyman--Eric Howes' statement on this flips and flops a little
    At one point in his ReadMe file
    http://www.spywarewarrior.com/uiuc/res/ie-spyad.txt
    he says
    "SpywareBlaster and IE-SPYAD don't conflict, although they do overlap in some ways. Both IE-SPYAD and SpywareBlaster in a sense de-fang Internet Explorer, making it safer to use. IE-SPYAD targets problematic web sites and domains. SpywareBlaster targets specific ActiveX controls. SpywareBlaster doesn't make IE-SPYAD irrelevant; there are plenty of nasty sites covered in IE-SPYAD that SpywareBlaster doesn't address in any way. Nor does IE-SPYAD render SpywareBlaster unnecessary. Each has a role. In fact, I don't see any reason why you can't use both. "
    But then later he says
    "My advice is to choose ONE program to maintain your Restricted sites list. Using more than one simply leads
    to overlap, confusion, and potential conflicts without necessarily increasing your level of protection.
    Currently, IE-SPYAD adds over 15,000 items to the Restricted sites -- considerably more than Spybot or
    SpywareBlaster, each of which adds only one or two thousand. "

    In between those two statements, he gives details of possible conflicts such as that the IESpyAds uninstall.reg file will uninstall any of the SpywareBlaster entries in Restricted Sites that are common to IESpyAds' entries. That has never seemed a problem to me, since they are then reinstalled when you use the new install.reg file or the next time you use SWB.
    And Howes makes it clear that IESpyAds has a much greater list of Restricted Sites than SWB, even though SWB is one of Howes' sources for the IESpyAds list.
    But in any event, it is not a matter of choosing between SpywareWareBlaster and IESpyads. except perhaps the use of the two Restricted Sites lists.
    You can use the rest of SpywareBlaster without the Restricted Sites option.
    On SpywareBlaster's Restricted Sites tab, you can uncheck the box "Restrict the actions...." and also check the box "Remove protection for unchecked items ".
     
  2. 2006/04/15
    Welshjim

    Welshjim Inactive

    Joined:
    2002/01/07
    Messages:
    5,643
    Likes Received:
    0
    aiki456--SpySweeper and SpywareBlaster perform different functions. Nothing wrong with having both. In fact, SWB nicely complements SS.
    SpySweeper is similar to AdAware or SpybotS&D.
    SpywareBlaster is somewhat unique--disregarding the Restricted Sites list issue discussed above. SpywareBlaster can modify the Windows Registry to set the "kill bit" for certain ActiveX controls associated with known "spyware" programs and "homepage hijackers," preventing them from being installed via "drive-by-downloads" in Internet Explorer. This function is proactive, which means it occurs in the background before the ActiveX control can be installed.
     

  3. to hide this advert.

  4. 2006/04/15
    sparrow

    sparrow Inactive

    Joined:
    2004/03/21
    Messages:
    2,282
    Likes Received:
    0
    Hi Frank,
    Please boot to safe mode and run hijackthis again and check the following items and select fix.

    O4 - Global Startup: REMIND32.lnk = C:\REMINDER\REMIND32.EXE
    (nuisance)

    O9 - Extra button: All - {26835CE1-D5EC-11d5-AF6E-00C06D0086BF} - C:\Program Files\closeIeX\closeIeX.exe (file missing)

    O9 - Extra 'Tools' menuitem: Close ALL IEx's - {26835CE1-D5EC-11d5-AF6E-00C06D0086BF} - C:\Program Files\closeIeX\closeIeX.exe (file missing)

    O9 - Extra button: Others - {6A0426D1-0FF2-49a0-ABC2-05B67826C727} - C:\Program Files\closeIeX\closeIeY.exe (file missing)

    O9 - Extra 'Tools' menuitem: Close OTHER IEx's - {6A0426D1-0FF2-49a0-ABC2-05B67826C727} - C:\Program Files\closeIeX\closeIeY.exe (file missing)

    O9 - Extra button: (no name) - {B72455AE-D3DE-492a-8FE0-0EA053B85277} - (no file)

    O15 - Trusted Zone: http://linktrader.cyberspacehq.com
    SPYWARE?

    O20 - Winlogon Notify: gdiwxp - C:\WINDOWS\SYSTEM32\
    suspect: password stealing trojan

    Then reboot in normal mode and turn system restore back on.

    Suggest you keep norton antivirus turned off and use it manually about once a week on Thursdays after its definitions are updated.

    Download and install the free AVG antivirus from Grisoft and use it as your main antivirus. Just let it do it's thing. Be sure to be online daily for an hour or so so it can update its definitions file which it does daily.

    Also dowhload and install Spybot S&D and use it weekly. I run teatimer (part of spybot) in the background to protect the registry..

    And also use ad-aware personal edition weekly the same way.
    Download microsoft's antispyware also.

    I use Sptwareblaster and spywareguard both without any problem.

    Remember to keep a firewall active at ALL times.
     
    Last edited: 2006/04/15
  5. 2006/04/15
    Welshjim

    Welshjim Inactive

    Joined:
    2002/01/07
    Messages:
    5,643
    Likes Received:
    0
  6. 2006/04/16
    PeteC

    PeteC SuperGeek Staff

    Joined:
    2002/05/10
    Messages:
    28,896
    Likes Received:
    389
    KB 908531 update

    There have been problems with this update - see ....

    Problems in Windows Explorer or the Windows shell after you install security update MS06-015 (KB 908531)
    See the workaround in this article.

    The update can be downloaded again and saved to disk through this article ....

    Microsoft Security Bulletin MS06-015
    Vulnerability in Windows Explorer Could Allow Remote Code Execution (908531)
     
  7. 2006/04/16
    sparrow

    sparrow Inactive

    Joined:
    2004/03/21
    Messages:
    2,282
    Likes Received:
    0
    Hi Frank,

    More thoughts:

    It would be helpful to know what sort of online connection you have.

    Suggest you rerun the antivirus trial programs again as a double check, and also run rootkit revealer. Let us know what if anything they find now.

    Suggest you download and install java from sun microsystems. It hopefully will overwrite what you presently have.

    Also, some of the free programs such as spybot and spywareguard/blaster have an imunize option which you should turn on.

    Clean those temporary folders on a weekly basis.

    If all is well, then the best protection against another infection is to educate yourself about the problem. A good place to start is to read the 'stickies' at the top of this forum.
     
    Last edited: 2006/04/16
  8. 2006/04/17
    aiki456

    aiki456 Inactive Thread Starter

    Joined:
    2002/06/17
    Messages:
    19
    Likes Received:
    0
    Ok, here's where I'm at... I reran HJT and deleted the files mentioned. I also deleted HP share to web and let windows update reinstall the security patches - things are working fine! Now I have to digest all the good information you guys gave me on the other programs I should be running and get moving on that. Quite a bit to digest!

    I can't tell you guys how much I appreciate all the help you've given me on this. You really came through. Thanks so much.

    Frank
     
  9. 2006/04/18
    Welshjim

    Welshjim Inactive

    Joined:
    2002/01/07
    Messages:
    5,643
    Likes Received:
    0
    aiki456--Thanks for posting back with the good news. That MS-06-015 908531 update is causing a lot of problems.
     
  10. 2006/04/28
    whompuscat Lifetime Subscription

    whompuscat Inactive

    Joined:
    2002/03/30
    Messages:
    341
    Likes Received:
    0
    I installed a program to beta test at the final window of the install a window flashed up and it was so fast all I could see were the word "root kit ".

    I downloaded and ran Root Kit Revealer. I know NOTHING about root kits, can someone please decipher this for me and tell me do I have a Root Kit installed on my computer and exactly what is a root kit? I was unable to save the log so used print screen and attached.

    And if so, how do I get rid of it? Rook Kit Revealer has no option to remove found entries. The only ones I am concerned about are the 1st 3, I know what the others are.
     
  11. 2006/04/28
    aiki456

    aiki456 Inactive Thread Starter

    Joined:
    2002/06/17
    Messages:
    19
    Likes Received:
    0
    I wish I could help you but I know nothing about root kits either. Since I entered the initial post on this thread, I don't know if anyone else is alerted when there is a new post. I wanted to let you know that; you might have better luck getting assistance if you begin a new post in this forum.

    Good luck!
     
  12. 2006/04/28
    Welshjim

    Welshjim Inactive

    Joined:
    2002/01/07
    Messages:
    5,643
    Likes Received:
    0
  13. 2006/04/28
    aiki456

    aiki456 Inactive Thread Starter

    Joined:
    2002/06/17
    Messages:
    19
    Likes Received:
    0
    LOL - no, I hadn't heard that. It figures. Thanks for the update!
     
  14. 2006/04/29
    sparrow

    sparrow Inactive

    Joined:
    2004/03/21
    Messages:
    2,282
    Likes Received:
    0
    whompuscat

    Believe thumbnail posted shows rootkit present. Please start your own thread in spyware removal forum and include the thumbnail again there.
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.