News: Cexx forums, with volunteers dedicated to helping you remove malware and stay protected
 
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
May 19, 2013, 20:28:21
Pages: [1]   Go Down
  Print  
Topic: How do I block hijacker IPInsight registry key?  (Read 5233 times)
0 Members and 1 Guest are viewing this topic.
« on: March 16, 2003, 14:36:00 »
Guest
Guest

I'm using BPS Syware Remover. Although I have SpyWatch running while  surfing, IPInsight keeps planting a key as fast as I can delete it. Can anyone tell me how to permanently block this rot? Thanx. AK
Logged
« Reply #1 on: March 16, 2003, 15:19:42 »
Tony Klein Offline
Global Moderator

Karma: 2
Posts: 1638



Do NOT use BPS Spyware remover.  It uses an old, stolen SpyBot database.

Read these articles:

http://www.net-integration.net/cgi-bin/forums/ikonboard.cgi?s=3e746190523affff;act=ST;f=28;t=1546;hl=bps

http://www.lavasoftsupport.com/index.php?act=ST&f=1&t=3912&s=5c50f035ecc54295b0fab0d832eb2ed5

Please do this:

Go to http://www.spywareinfo.com/downloads.php#det ,  and download 'Hijack This!'.
Unzip, doubleclick HijackThis.exe, and hit "Scan".

When the scan is finished,  the  "Scan"  button will change into a "Save Log"  button.
Press that,  save the log somewhere, and please show us its contents.
Logged

« Reply #2 on: March 17, 2003, 00:25:59 »
Tony Klein Offline
Global Moderator

Karma: 2
Posts: 1638



Thanks for that log:

Quote
Logfile of HijackThis v1.92.1
Scan saved at 11:08:14 AM, on 17/03/2003
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

O1 - Hosts: 216.177.73.139 auto.search.msn.com
O1 - Hosts: 216.177.73.139 search.netscape.com
O1 - Hosts: 216.177.73.139 ieautosearch
O2 - BHO: (no name) - {000004CC-E4FF-4F2C-BC30-DBEF0B983BC9} - C:\WINDOWS\ipinsigt.dll
O2 - BHO: (no name) - {206E52E0-D52E-11D4-AD54-0000E86C26F6} - D:\PROGRA~1\FRESHD~1\fdiehlp.dll
O2 - BHO: Natural Language Navigation - {60E78CAC-E9A7-4302-B9EE-8582EDE22FBF} - C:\WINDOWS\System\BHO001.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [NAV Agent] D:\PROGRA~1\NORTON~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [HistoryKill] C:\Program Files\HistoryKill\histkill.exe /startup
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [SPYWATCH] D:\Program files\Spyware Remover\SpyWatch.exe /STARTUP
O4 - HKCU\..\Run: [Evidence Eliminator] D:\Program files\Evidence Eliminator\ee.exe /m
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/20021205/qtinstall.info.apple.com/borris/us/win/QuickTimeInstaller.exe
O16 - DPF: {AD7FAFB0-16D6-40C3-AF27-585D6E6453FD} - http://dload.ipbill.com/del/loader.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab


You have IPInsight and IGetNet Browser plugins, and they need to be removed.

Run Hijack This, and check ALL of the items in bold.  Doublecheck so as to be sure not to miss a single one.
Next, shut down all Internet Explorer Windows, and have HT fix all checked.


O1 - Hosts: 216.177.73.139 auto.search.msn.com
O1 - Hosts: 216.177.73.139 search.netscape.com
O1 - Hosts: 216.177.73.139 ieautosearch

O2 - BHO: (no name) - {000004CC-E4FF-4F2C-BC30-DBEF0B983BC9} - C:\WINDOWS\ipinsigt.dll
O2 - BHO: Natural Language Navigation - {60E78CAC-E9A7-4302-B9EE-8582EDE22FBF} - C:\WINDOWS\System\BHO001.DLL



Good luck,
Logged

« Reply #3 on: March 17, 2003, 15:54:48 »
Guest
Guest

The HijackThis! toothbrush cleaned the bits the commerical progs just can't reach.  Very Happy

To think I was ripped off buying Syware Remover, what a dill    Evil or Very Mad . Uninstalled it along with HistoryKill.  Now double dating both Spybot and Proxomitron.   Wink
Logged
« Reply #4 on: March 17, 2003, 16:00:20 »
Tony Klein Offline
Global Moderator

Karma: 2
Posts: 1638



Good choice! Smile

Glad to hear you were able to get rid of it at last.

Cheers,
Logged

 
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by SMF 1.1.18 | SMF © 2013, Simple Machines Page created in 0.292 seconds with 20 queries.