hello!
I ran a spyware program in safe mode and removed some nastys from my machine, it then asked me to reboot to complete removal which i did.
everything booting back up fine but my wireless network will not work, so then I restored the spyware removal and it works fine.
I think the problem is when Im removing a program called newdot.net but i have posted a log of the removal operation and would be grateful is someone could maybe troubleshoot a little and advise me another way of get rid of this thing with out have any after effects on my wireless connections.
The product I used is called spysubtract and the log is as follows...
Machine=LAPTOP
Time=Sun Aug 07 22:06:14 2005
Product Version=3, 0, 0, 29
OS Version=Microsoft Windows XP Home Edition Service Pack 2 (Build 2600)
Started Scanning
Programs in Memory
Finished Scanning
IE Plugins: Found '{4A2AACF3-ADF6-11D5-98A9-00E018981B9E}' in 'SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects'
IE Plugins: Found '{53707962-6F74-2D53-2644-206D7942484F}' in 'SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects'
IE Plugins: Found '{BA52B914-B692-46c4-B683-905236F6F655}' in 'SOFTWARE\Microsoft\Internet Explorer\Toolbar'
IE Plugins: Found '{B56B682A-E143-46CB-95F6-9F2ADA5B4200}' in 'Software\Microsoft\Internet Explorer\URLSearchHooks'
IE Plugins: Found '{B56B682A-E143-46CB-95F6-9F2ADA5B4200}' in 'Software\Microsoft\Internet Explorer\URLSearchHooks'
Web Browser Security Settings: Found 'Start Page' in 'SOFTWARE\Microsoft\Internet Explorer\Main'
Web Browser Security Settings: Found 'Default_Page_URL' in 'SOFTWARE\Microsoft\Internet Explorer\Main'
Web Browser Security Settings: Found 'Default_Page_URL' in 'SOFTWARE\Microsoft\Internet Explorer\Main'
Web Browser Security Settings: Found 'Default_Search_URL' in 'SOFTWARE\Microsoft\Internet Explorer\Main'
Web Browser Security Settings: Found 'CustomizeSearch' in 'SOFTWARE\Microsoft\Internet Explorer\Search'
Web Browser Security Settings: Found 'Local Page' in 'SOFTWARE\Microsoft\Internet Explorer\Main'
Web Browser Security Settings: Found 'DisableCachingOfSSLPages' in 'Software\Microsoft\Windows\CurrentVersion\Internet Settings'
Web Browser Security Settings: Found 'WarnOnZoneCrossing' in 'Software\Microsoft\Windows\CurrentVersion\Internet Settings'
Web Browser Security Settings: Found 'iexplore.exe' in 'Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN'
Web Browser Security Settings: Found 'msn' in 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ '
Web Browser Security Settings: Found 'Download ALL with IDA' in 'Software\Microsoft\Internet Explorer\MenuExt\Download ALL with IDA'
Web Browser Security Settings: Found 'Download with IDA' in 'Software\Microsoft\Internet Explorer\MenuExt\Download with IDA'
IE Downloaded Program Files: Found '' in 'C:\WINDOWS\Downloaded Program Files\ppctl.dll'
IE Downloaded Program Files: Found 'PPSDKActiveXScanner.MainScreen' in 'C:\WINDOWS\Downloaded Program Files\PPSDKActiveXScanner.ocx,C:\WINDOWS\Downloaded Program Files\PPSDKActiveXScanner.INF'
IE Downloaded Program Files: Found 'Crucial cpcScan' in 'C:\WINDOWS\Downloaded Program Files\cpcscan.dll'
IE Downloaded Program Files: Found 'IntraLaunch.MainControl' in 'C:\WINDOWS\Downloaded Program Files\INTRALAUNCH.OCX,C:\WINDOWS\Downloaded Program Files\IntraLaunch.INF'
IE Downloaded Program Files: Found '' in 'C:\Program Files\Yahoo!\Common\yaddbook.dll'
IE Downloaded Program Files: Found 'Lycos File Upload Component' in 'C:\WINDOWS\Downloaded Program Files\FileUploader.dll,C:\WINDOWS\Downloaded Program Files\FileUploader.inf'
Layered Service Providers (LSP's): Found 'New.net UDP Chain' in 'C:\Program Files\NewDotNet\newdotnet6_38.dll'
Layered Service Providers (LSP's): Found 'New.net TCP Chain' in 'C:\Program Files\NewDotNet\newdotnet6_38.dll'
Layered Service Providers (LSP's): Found 'New.net TCP Filter' in 'C:\Program Files\NewDotNet\newdotnet6_38.dll'
Layered Service Providers (LSP's): Found 'New.net UDP Filter' in 'C:\Program Files\NewDotNet\newdotnet6_38.dll'
Windows Policy Settings: Found 'restrictanonymous' in 'SYSTEM\CurrentControlSet\Control\Lsa'
Windows Policy Settings: Found 'forceunlocklogon' in 'SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon'
Services: Found 'gearsec' in ''
Services: Found 'LexBce Server' in ''
Windows Shell Settings: Found 'Browse with Paint Shop Pro 8' in 'SOFTWARE\Classes\Folder\shell\Browse with Paint Shop Pro 8'
Windows Shell Settings: Found 'DriveLetterAccess' in 'SOFTWARE\Classes\Drive\shellex\ContextMenuHandlers\DriveLetterAccess'
Windows Shell Settings: Found 'Trojan Remover' in 'SOFTWARE\Classes\Drive\shellex\ContextMenuHandlers\Trojan Remover'
Windows Shell Settings: Found 'AntiVir/Win' in 'SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\AntiVir/Win'
Windows Shell Settings: Found 'SpySweeper' in 'SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\SpySweeper'
Windows Shell Settings: Found 'Trojan Remover' in 'SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\Trojan Remover'
Windows Shell Settings: Found '{A70C977A-BF00-412C-90B7-034C51DA2439}' in 'SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved'
Windows Shell Settings: Found '{5CA3D70E-1895-11CF-8E15-001234567890}' in 'SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved'
Windows Shell Settings: Found '{7C9D5882-CB4A-4090-96C8-430BFE8B795B}' in 'SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved'
Windows Shell Settings: Found '{5464D816-CF16-4784-B9F3-75C0DB52B499}' in 'SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved'
Windows Shell Settings: Found '{32020A01-506E-484D-A2A8-BE3CF17601C3}' in 'SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved'
Windows Shell Settings: Found '{52B87208-9CCF-42C9-B88E-069281105805}' in 'SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved'
Windows Shell Settings: Found '{BBA7EB3F-97AB-4EBD-BCA2-C3C8DBED444F}' in 'SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved'
Windows Shell Settings: Found '{792F0537-F929-4eb7-AC1D-FB6334C71550}' in 'SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved'
Windows Shell Settings: Found '{1E9B04FB-F9E5-4718-997B-B8DA88302A48}' in 'SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved'
Windows Shell Settings: Found '{FFB699E0-306A-11d3-8BD1-00104B6F7516}' in 'SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved'
Program Startup Areas: Found 'DadApp' in 'SOFTWARE\Microsoft\Windows\CurrentVersion\Run'
Program Startup Areas: Found 'Dell QuickSet' in 'SOFTWARE\Microsoft\Windows\CurrentVersion\Run'
Program Startup Areas: Found 'PCMService' in 'SOFTWARE\Microsoft\Windows\CurrentVersion\Run'
Program Startup Areas: Found 'RemHelp' in 'SOFTWARE\Microsoft\Windows\CurrentVersion\Run'
Program Startup Areas: Found 'RunMotive' in 'SOFTWARE\Microsoft\Windows\CurrentVersion\Run'
Program Startup Areas: Found 'DiskeeperSystray' in 'SOFTWARE\Microsoft\Windows\CurrentVersion\Run'
Program Startup Areas: Found 'BCMSMMSG' in 'SOFTWARE\Microsoft\Windows\CurrentVersion\Run'
Program Startup Areas: Found 'GSICONEXE' in 'SOFTWARE\Microsoft\Windows\CurrentVersion\Run'
Program Startup Areas: Found 'DSLAGENTEXE' in 'SOFTWARE\Microsoft\Windows\CurrentVersion\Run'
Program Startup Areas: Found 'DSLSTATEXE' in 'SOFTWARE\Microsoft\Windows\CurrentVersion\Run'
Program Startup Areas: Found '%FP%Friendly fts.exe' in 'SOFTWARE\Microsoft\Windows\CurrentVersion\Run'
Program Startup Areas: Found 'AVGCtrl' in 'SOFTWARE\Microsoft\Windows\CurrentVersion\Run'
Program Startup Areas: Found 'RealTray' in 'SOFTWARE\Microsoft\Windows\CurrentVersion\Run'
Program Startup Areas: Found 'SP2ConnPatcher' in 'S-1-5-21-501449678-2886101355-1413624805-1007\SOFTWARE\Microsoft\Windows\CurrentVersion\Run'
Program Startup Areas: Found 'Steam' in 'S-1-5-21-501449678-2886101355-1413624805-1007\SOFTWARE\Microsoft\Windows\CurrentVersion\Run'
--------------------------------- SpySubtract session ended ---------------------------------
cheers
Mike
I ran a spyware program in safe mode and removed some nastys from my machine, it then asked me to reboot to complete removal which i did.
everything booting back up fine but my wireless network will not work, so then I restored the spyware removal and it works fine.
I think the problem is when Im removing a program called newdot.net but i have posted a log of the removal operation and would be grateful is someone could maybe troubleshoot a little and advise me another way of get rid of this thing with out have any after effects on my wireless connections.
The product I used is called spysubtract and the log is as follows...
Machine=LAPTOP
Time=Sun Aug 07 22:06:14 2005
Product Version=3, 0, 0, 29
OS Version=Microsoft Windows XP Home Edition Service Pack 2 (Build 2600)
Started Scanning
Programs in Memory
Finished Scanning
IE Plugins: Found '{4A2AACF3-ADF6-11D5-98A9-00E018981B9E}' in 'SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects'
IE Plugins: Found '{53707962-6F74-2D53-2644-206D7942484F}' in 'SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects'
IE Plugins: Found '{BA52B914-B692-46c4-B683-905236F6F655}' in 'SOFTWARE\Microsoft\Internet Explorer\Toolbar'
IE Plugins: Found '{B56B682A-E143-46CB-95F6-9F2ADA5B4200}' in 'Software\Microsoft\Internet Explorer\URLSearchHooks'
IE Plugins: Found '{B56B682A-E143-46CB-95F6-9F2ADA5B4200}' in 'Software\Microsoft\Internet Explorer\URLSearchHooks'
Web Browser Security Settings: Found 'Start Page' in 'SOFTWARE\Microsoft\Internet Explorer\Main'
Web Browser Security Settings: Found 'Default_Page_URL' in 'SOFTWARE\Microsoft\Internet Explorer\Main'
Web Browser Security Settings: Found 'Default_Page_URL' in 'SOFTWARE\Microsoft\Internet Explorer\Main'
Web Browser Security Settings: Found 'Default_Search_URL' in 'SOFTWARE\Microsoft\Internet Explorer\Main'
Web Browser Security Settings: Found 'CustomizeSearch' in 'SOFTWARE\Microsoft\Internet Explorer\Search'
Web Browser Security Settings: Found 'Local Page' in 'SOFTWARE\Microsoft\Internet Explorer\Main'
Web Browser Security Settings: Found 'DisableCachingOfSSLPages' in 'Software\Microsoft\Windows\CurrentVersion\Internet Settings'
Web Browser Security Settings: Found 'WarnOnZoneCrossing' in 'Software\Microsoft\Windows\CurrentVersion\Internet Settings'
Web Browser Security Settings: Found 'iexplore.exe' in 'Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN'
Web Browser Security Settings: Found 'msn' in 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ '
Web Browser Security Settings: Found 'Download ALL with IDA' in 'Software\Microsoft\Internet Explorer\MenuExt\Download ALL with IDA'
Web Browser Security Settings: Found 'Download with IDA' in 'Software\Microsoft\Internet Explorer\MenuExt\Download with IDA'
IE Downloaded Program Files: Found '' in 'C:\WINDOWS\Downloaded Program Files\ppctl.dll'
IE Downloaded Program Files: Found 'PPSDKActiveXScanner.MainScreen' in 'C:\WINDOWS\Downloaded Program Files\PPSDKActiveXScanner.ocx,C:\WINDOWS\Downloaded Program Files\PPSDKActiveXScanner.INF'
IE Downloaded Program Files: Found 'Crucial cpcScan' in 'C:\WINDOWS\Downloaded Program Files\cpcscan.dll'
IE Downloaded Program Files: Found 'IntraLaunch.MainControl' in 'C:\WINDOWS\Downloaded Program Files\INTRALAUNCH.OCX,C:\WINDOWS\Downloaded Program Files\IntraLaunch.INF'
IE Downloaded Program Files: Found '' in 'C:\Program Files\Yahoo!\Common\yaddbook.dll'
IE Downloaded Program Files: Found 'Lycos File Upload Component' in 'C:\WINDOWS\Downloaded Program Files\FileUploader.dll,C:\WINDOWS\Downloaded Program Files\FileUploader.inf'
Layered Service Providers (LSP's): Found 'New.net UDP Chain' in 'C:\Program Files\NewDotNet\newdotnet6_38.dll'
Layered Service Providers (LSP's): Found 'New.net TCP Chain' in 'C:\Program Files\NewDotNet\newdotnet6_38.dll'
Layered Service Providers (LSP's): Found 'New.net TCP Filter' in 'C:\Program Files\NewDotNet\newdotnet6_38.dll'
Layered Service Providers (LSP's): Found 'New.net UDP Filter' in 'C:\Program Files\NewDotNet\newdotnet6_38.dll'
Windows Policy Settings: Found 'restrictanonymous' in 'SYSTEM\CurrentControlSet\Control\Lsa'
Windows Policy Settings: Found 'forceunlocklogon' in 'SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon'
Services: Found 'gearsec' in ''
Services: Found 'LexBce Server' in ''
Windows Shell Settings: Found 'Browse with Paint Shop Pro 8' in 'SOFTWARE\Classes\Folder\shell\Browse with Paint Shop Pro 8'
Windows Shell Settings: Found 'DriveLetterAccess' in 'SOFTWARE\Classes\Drive\shellex\ContextMenuHandlers\DriveLetterAccess'
Windows Shell Settings: Found 'Trojan Remover' in 'SOFTWARE\Classes\Drive\shellex\ContextMenuHandlers\Trojan Remover'
Windows Shell Settings: Found 'AntiVir/Win' in 'SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\AntiVir/Win'
Windows Shell Settings: Found 'SpySweeper' in 'SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\SpySweeper'
Windows Shell Settings: Found 'Trojan Remover' in 'SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\Trojan Remover'
Windows Shell Settings: Found '{A70C977A-BF00-412C-90B7-034C51DA2439}' in 'SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved'
Windows Shell Settings: Found '{5CA3D70E-1895-11CF-8E15-001234567890}' in 'SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved'
Windows Shell Settings: Found '{7C9D5882-CB4A-4090-96C8-430BFE8B795B}' in 'SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved'
Windows Shell Settings: Found '{5464D816-CF16-4784-B9F3-75C0DB52B499}' in 'SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved'
Windows Shell Settings: Found '{32020A01-506E-484D-A2A8-BE3CF17601C3}' in 'SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved'
Windows Shell Settings: Found '{52B87208-9CCF-42C9-B88E-069281105805}' in 'SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved'
Windows Shell Settings: Found '{BBA7EB3F-97AB-4EBD-BCA2-C3C8DBED444F}' in 'SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved'
Windows Shell Settings: Found '{792F0537-F929-4eb7-AC1D-FB6334C71550}' in 'SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved'
Windows Shell Settings: Found '{1E9B04FB-F9E5-4718-997B-B8DA88302A48}' in 'SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved'
Windows Shell Settings: Found '{FFB699E0-306A-11d3-8BD1-00104B6F7516}' in 'SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved'
Program Startup Areas: Found 'DadApp' in 'SOFTWARE\Microsoft\Windows\CurrentVersion\Run'
Program Startup Areas: Found 'Dell QuickSet' in 'SOFTWARE\Microsoft\Windows\CurrentVersion\Run'
Program Startup Areas: Found 'PCMService' in 'SOFTWARE\Microsoft\Windows\CurrentVersion\Run'
Program Startup Areas: Found 'RemHelp' in 'SOFTWARE\Microsoft\Windows\CurrentVersion\Run'
Program Startup Areas: Found 'RunMotive' in 'SOFTWARE\Microsoft\Windows\CurrentVersion\Run'
Program Startup Areas: Found 'DiskeeperSystray' in 'SOFTWARE\Microsoft\Windows\CurrentVersion\Run'
Program Startup Areas: Found 'BCMSMMSG' in 'SOFTWARE\Microsoft\Windows\CurrentVersion\Run'
Program Startup Areas: Found 'GSICONEXE' in 'SOFTWARE\Microsoft\Windows\CurrentVersion\Run'
Program Startup Areas: Found 'DSLAGENTEXE' in 'SOFTWARE\Microsoft\Windows\CurrentVersion\Run'
Program Startup Areas: Found 'DSLSTATEXE' in 'SOFTWARE\Microsoft\Windows\CurrentVersion\Run'
Program Startup Areas: Found '%FP%Friendly fts.exe' in 'SOFTWARE\Microsoft\Windows\CurrentVersion\Run'
Program Startup Areas: Found 'AVGCtrl' in 'SOFTWARE\Microsoft\Windows\CurrentVersion\Run'
Program Startup Areas: Found 'RealTray' in 'SOFTWARE\Microsoft\Windows\CurrentVersion\Run'
Program Startup Areas: Found 'SP2ConnPatcher' in 'S-1-5-21-501449678-2886101355-1413624805-1007\SOFTWARE\Microsoft\Windows\CurrentVersion\Run'
Program Startup Areas: Found 'Steam' in 'S-1-5-21-501449678-2886101355-1413624805-1007\SOFTWARE\Microsoft\Windows\CurrentVersion\Run'
--------------------------------- SpySubtract session ended ---------------------------------
cheers
Mike