Register | Login
Views: 19364387
Main | Memberlist | Active users | ACS | Commons | Calendar | Online users
Ranks | FAQ | Color Chart | Photo album | IRC Chat
11-02-05 12:59 PM
0 user currently in Hardware/Software.
Acmlm's Board - I2 Archive - Hardware/Software - Browser hijack? | |
Add to favorites | "RSS" Feed | Next newer thread | Next older thread
User Post
drjayphd

Beamos
What's that spell?




pimp!
Level: 56

Posts: 180/1477
EXP: 1387410
For next: 10766

Since: 03-15-04
From: CT

Since last post: 2 hours
Last activity: 2 hours
Posted on 04-18-04 08:06 AM Link | Quote
So I've been on a bit of a spyware-whacking spree, what with Deanna's comp possibly getting nailed. Go to look for another subbing job (hey, I'm gullible, broke, and desperate) when I get the site's name wrong... and THIS comes up. Is this a hijack? I ran a whois looking for some info, and this is what I got. Running Spybot now, and I think it either got by Ad-aware or happened since I last ran it (a day or two ago). I think I also put up SpywareBlaster as well.

Oh, the browser is Mozilla 1.5.
kitty
Come on babe, pet the pussy ;)
Level: 70

Posts: 674/2449
EXP: 2962406
For next: 53405

Since: 03-15-04
From: Scranton, PA, USA

Since last post: 3 hours
Last activity: 3 hours
Posted on 04-18-04 08:13 AM Link | Quote
Sounds like it...

What I always do - In safe mode, check the registry under:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Any DLL set to run with rundll32 is either a driver, which you would recognize the name of (like NvCpl.dll, nv = nvidia), a program's dll you put in there (like DeadAIM), or SPYWARE.

Remove EVERYTHING you don't recognize. Neither SpyBot nor Ad-Aware deleted one on Christi's machine, so I installed it on my machine myself and then told her how to get rid of it. Oh, the sacrafices I make!
drjayphd

Beamos
What's that spell?




pimp!
Level: 56

Posts: 186/1477
EXP: 1387410
For next: 10766

Since: 03-15-04
From: CT

Since last post: 2 hours
Last activity: 2 hours
Posted on 04-19-04 08:00 AM Link | Quote
Hrm... there was one I didn't recognize (nwiz.exe /install) and I whacked it, but that's it. When I saw it, I also searched on Google for info on it, if it was something like CoolWebSearch, but nothing turned up.
kitty
Come on babe, pet the pussy ;)
Level: 70

Posts: 695/2449
EXP: 2962406
For next: 53405

Since: 03-15-04
From: Scranton, PA, USA

Since last post: 3 hours
Last activity: 3 hours
Posted on 04-19-04 09:17 AM Link | Quote
It's for nvidia drivers. I know it's an odd name and flag, but that's what it is.
Add to favorites | "RSS" Feed | Next newer thread | Next older thread
Acmlm's Board - I2 Archive - Hardware/Software - Browser hijack? | |


ABII


AcmlmBoard vl.ol (11-01-05)
© 2000-2005 Acmlm, Emuz, et al



Page rendered in 0.003 seconds.