Explorer acting funny!!

TFT

VIP Member
As for his question I am unable to help him and you have stuck by him which is good :)

I have read that ctfmon can be dodgy but only if it resides outside of the system32 folder, if it is in it then chances are it's a Microsoft file.

Best of luck :)
 

codeman0013

Active Member
Yea it was picked up by hijack this and i dont like where it was and i checked with an analyzer just to back my feelings and they agree its got the cool websearch... Charmpeddler try your add remove programs as well and see if there are anything about websearch or cool web or anything sketchy like that or any toolbars in there...
 

CharmPeddler

New Member
ok that link worked codeman. im installing and running the prog now. i will post the list of possible problems BEFORE i tell it to fix anything. i have had personal problems and have had close friends how have also ran this program and have had it delete things that wether it should have or not, left the computer and or applications unusable.

so i'll post the list and ask u/everyone to let me know if there are things ont he list that should not be touched.
 

CharmPeddler

New Member
well this is all i get after the scan.

DoubleCLick
(spi $4CDCC3D5) Tracking cookie (internet explorer: admin) II Internet explorer (admin): cookie: [email protected]/0

so...ya. im goin to goahead and get rid of that one.
 

codeman0013

Active Member
what virus scanner do you use? Also we need to try to get adaware 2007 for you if you can and download and run that too... Do you have that or do you need that?
 

codeman0013

Active Member
does zonealarm do virus now? I didnt think it was virus just simply firewall?? If you dont have a virus scanner thats the next step we need to get one installed and scanning...
 

CharmPeddler

New Member
here is the results for the adaware scan. i can also post the running processes but it is quite a LARGE list.

btw. if this doesnt work im prolly just goin to reinstall windows...

Extended Ad-Aware 2007 Settings
===========================
Unloading known modules during scan
Ignoring spanned files when scanning cab archives
Reanalyzing results after scanning before displaying results
Trying to unload modules prior to removal
Let Windows remove files currently in use at next reboot
Removing quarantined objects after restore
Deactivating Ad-Watch during scans
Writeprotecting system files after repairs
Include info about ignored objects in log file
Including basic settings in log file
Including advanced settings in log file
Including user and computer name in log file
Create and save WebUpdate log file

Databaseinfo
===========================
Version number: 28
Build Number: 0
Build Date and Time: 2007/10/24 06:36:54

Scan Statistics
===========================
Method: Full
Scan tracking cookies.............................: On
Scan ADS filestreams..............................: Off

Item Scanned: 220937
Infections Detected: 11
Infections Ignored: 0

Scan detailed statistics
===========================
Type Critical Total
Process Scan....: 0 0
Registry Scan...: 0 0
Registry PE Scan: 0 0
Hosts File Scan.: 0 0
File Scan.......: 0 0
Folder Scan.....: 0 0
LSP Scan........: 0 0
ADS Scan........: 0 0
Cookie Scan.....: 10 10
File Hash Scan..: 0 0

Infections Found
===========================
Family Id: 725 Name: Tracking Cookie Category: DataMiner TAI:3
Item Id: 600000190 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\admin\Cookies\index.dat www.googleadservices.com Conversion /pagead/conversion/1059843415/
Item Id: 600000457 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\admin\Cookies\index.dat adopt.euroclick.com DMEXP /
Item Id: 600000457 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\admin\Cookies\index.dat adopt.euroclick.com CTCI /
Item Id: 600000457 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\admin\Cookies\index.dat adopt.euroclick.com HS /
Item Id: 600000457 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\admin\Cookies\index.dat adopt.euroclick.com UI /
Item Id: 600000664 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\admin\Cookies\index.dat betanews.com RMID /
Item Id: 600000513 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\admin\Cookies\index.dat adbrite.com Apache /
Item Id: 600000513 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\admin\Cookies\index.dat ads.adbrite.com ihc_336625 /
Item Id: 600000513 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\admin\Cookies\index.dat ads.adbrite.com ihc_336630 /
Item Id: 600000513 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\admin\Cookies\index.dat ads.adbrite.com ihc_336629 /
Family Id: 9999 Name: MRU Object Category: MRU Object TAI:0
Item Id: 1 Value: MRU Path: C:\Documents and Settings\admin\Recent Count: 25
 

CharmPeddler

New Member
well the boss got tired of me "messing around on the computer". so he told me to just reinstall windows :(. i just want to say THANKS a TON!!!. i really appreciate your time and help, staying with me.

thanks alot codeman, and the others who pitched in as well.
 

codeman0013

Active Member
Dang to bad this would have been easier to do in person where i could have seen the machine. Sorry we couldnt fix it hope the reformat makes it like new again. Feel free to always ask thats what we are here for...
 

CharmPeddler

New Member
ya, in person is usually easier to work out. thanks again for the help, it was fun working on it and i learned a few things (always a good thing).
 
Top