# ad/spyware that's currently kicking my ass

**URL:** <https://forums.speedlife.net/t/ad-spyware-thats-currently-kicking-my-ass/175750>\
**Category:** PittSpeed Off Topic\
**Created:** [July 19, 2005, 7:24pm UTC](https://forums.speedlife.net/t/ad-spyware-thats-currently-kicking-my-ass/175750 "2005-07-19T19:24:37Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![T70\_Tsi](https://avatars.discourse-cdn.com/v4/letter/t/898d66/32.png) [@T70\_Tsi](https://forums.speedlife.net/u/T70_Tsi)\
**Post date:** [July 19, 2005, 7:24pm UTC](https://forums.speedlife.net/t/ad-spyware-thats-currently-kicking-my-ass/175750/1 "2005-07-19T19:24:37Z")

</div>

can’t find any info on it, ran adaware, spybot, microsoft spyware removal, spy detector something or other, and ewido…i ran ewido last (in safe mode) and it detected another 23 that the others did not find but there’s 1 more left.

all definitions are up to date and norton is also running so it’s not a virus just spyware. every so often i get an exclaimation point in the taskbar that when double clicked takes me to a legitimate spyware removal tool so it’s most likely not from them but someone pointing at them… anyways this is the popup i get:

i did a search for all the things listed and didnt’ bring anything up related to what i was looking for. i also deleted all offline content with cleanup 4.0 and gained back a gig of HD space.

![http://www.pittspeed.com/uploaded/spyware.JPG](http://www.pittspeed.com/uploaded/spyware.JPG)

---

<div class="post-metadata">

**Author:** ![The1SloR\_T](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/the1slor_t/32/5984_2.png) [@The1SloR\_T](https://forums.speedlife.net/u/The1SloR_T)\
**Post date:** [July 19, 2005, 7:26pm UTC](https://forums.speedlife.net/t/ad-spyware-thats-currently-kicking-my-ass/175750/2 "2005-07-19T19:26:20Z")

</div>

i had that!. all i did was get norton2005 ran it, then updated windows to the fullest, and got the new IE and everything is fine now

---

<div class="post-metadata">

**Author:** ![nh4442](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/nh4442/32/6005_2.png) [@nh4442](https://forums.speedlife.net/u/nh4442)\
**Post date:** [July 19, 2005, 7:28pm UTC](https://forums.speedlife.net/t/ad-spyware-thats-currently-kicking-my-ass/175750/3 "2005-07-19T19:28:03Z")

</div>

thats f’d up…i was going to say run microsoft spyware but i guess u did already…

---

<div class="post-metadata">

**Author:** ![T70\_Tsi](https://avatars.discourse-cdn.com/v4/letter/t/898d66/32.png) [@T70\_Tsi](https://forums.speedlife.net/u/T70_Tsi)\
**Post date:** [July 19, 2005, 7:37pm UTC](https://forums.speedlife.net/t/ad-spyware-thats-currently-kicking-my-ass/175750/4 "2005-07-19T19:37:58Z")

</div>

Running processes:  
C:\WINDOWS\System32\smss.exe  
C:\WINDOWS\system32\winlogon.exe  
C:\WINDOWS\system32\services.exe  
C:\WINDOWS\system32\lsass.exe  
C:\WINDOWS\system32\svchost.exe  
C:\WINDOWS\System32\svchost.exe  
C:\WINDOWS\Explorer.EXE  
C:\WINDOWS\system32\spoolsv.exe  
C:\WINDOWS\System32\msole32.exe  
C:\Program Files\NavNT\vptray.exe  
C:\Program Files\NavNT\defwatch.exe  
C:\Program Files\Common Files\Real\Update\_OB\realsched.exe  
C:\Program Files\ewido\security suite\ewidoctrl.exe  
C:\Program Files\Common Files\Real\Update\_OB\rnathchk.exe  
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe  
C:\WINDOWS\System32\ctfmon.exe  
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe  
C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe  
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe  
C:\Program Files\NavNT\rtvscan.exe  
C:\WINDOWS\System32\svchost.exe  
C:\Program Files\QUICKENW\QWDLLS.EXE  
C:\WINDOWS\System32\MsgSys.EXE  
C:\Program Files\ewido\security suite\ewidoguard.exe  
C:\Program Files\AIM95\aim.exe  
C:\Program Files\Internet Explorer\iexplore.exe  
C:\Documents and Settings\sweety\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default\_Page\_URL = about:blank  
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =  
O3 - Toolbar: (no name) - {825CF5BD-8862-4430-B771-0C15C5CA8DEF} - (no file)  
O4 - HKLM…\Run: [vptray] C:\Program Files\NavNT\vptray.exe  
O4 - HKLM…\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update\_OB\realsched.exe -osboot  
O4 - HKLM…\Run: [zcv52] C:\docume~1\sweety\locals~1 emp\zcv52.exe  
O4 - HKLM…\Run: [23rR36j] atkrip.exe  
O4 - HKLM…\Run: [Tsl2] C:\PROGRA~1\COMMON~1 sa sl2.exe  
O4 - HKLM…\Run: [intel32.exe] C:\WINDOWS\System32\intel32.exe  
O4 - HKLM…\Run: [gcasServ] “C:\Program Files\Microsoft AntiSpyware\gcasServ.exe”  
O4 - HKCU…\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe  
O4 - HKCU…\Run: [J005RWHEe] wupd2x35.exe  
O4 - Global Startup: Billminder.lnk = C:\Program Files\QUICKENW\BILLMIND.EXE  
O4 - Global Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE  
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE  
O4 - Global Startup: Quicken Startup.lnk = C:\Program Files\QUICKENW\QWDLLS.EXE  
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm  
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe  
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)  
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll  
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - [http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb\_site.cab?1094085435960](http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1094085435960)  
O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - [http://www.installengine.com/engine/isetup.cab](http://www.installengine.com/engine/isetup.cab)  
O17 - HKLM\System\CCS\Services\Tcpip…{79D18AEB-4F19-42B8-AA9A-4687914D0BBA}: NameServer = 128.118.25.3 130.203.1.4  
O17 - HKLM\System\CCS\Services\Tcpip…{EFDBBBA6-48AF-4055-A6DF-512BE374E3AA}: NameServer = 192.168.0.3  
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll  
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll  
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\NavNT\defwatch.exe  
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe  
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe  
O23 - Service: GhostStartService - Symantec Corporation - C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe  
O23 - Service: Norton AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\NavNT\rtvscan.exe

2 of those jump out at me:

O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)

O3 - Toolbar: (no name) - {825CF5BD-8862-4430-B771-0C15C5CA8DEF} - (no file)

---

<div class="post-metadata">

**Author:** ![T70\_Tsi](https://avatars.discourse-cdn.com/v4/letter/t/898d66/32.png) [@T70\_Tsi](https://forums.speedlife.net/u/T70_Tsi)\
**Post date:** [July 19, 2005, 7:38pm UTC](https://forums.speedlife.net/t/ad-spyware-thats-currently-kicking-my-ass/175750/5 "2005-07-19T19:38:48Z")

</div>

> [@The1SloShelby](#):
>
> i had that!. all i did was get norton2005 ran it, then updated windows to the fullest, and got the new IE and everything is fine now

been there, did that

---

<div class="post-metadata">

**Author:** ![newchic](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/newchic/32/5989_2.png) [@newchic](https://forums.speedlife.net/u/newchic)\
**Post date:** [July 19, 2005, 7:42pm UTC](https://forums.speedlife.net/t/ad-spyware-thats-currently-kicking-my-ass/175750/6 "2005-07-19T19:42:14Z")

</div>

Did you try to run adaware or Spybot… they are free from [download.com](http://download.com)… That may help…  
Also that "System Warning " Is just an advertisement… It’s not a real warning. All you need to do is get rid of the spyware and the warning thing will go away…

---

<div class="post-metadata">

**Author:** ![T70\_Tsi](https://avatars.discourse-cdn.com/v4/letter/t/898d66/32.png) [@T70\_Tsi](https://forums.speedlife.net/u/T70_Tsi)\
**Post date:** [July 19, 2005, 7:46pm UTC](https://forums.speedlife.net/t/ad-spyware-thats-currently-kicking-my-ass/175750/7 "2005-07-19T19:46:54Z")

</div>

read my post:

> can’t find any info on it, ran **adaware, spybot** , microsoft spyware removal, spy detector something or other, and ewido…i ran ewido last (in safe mode) and it detected another 23 that the others did not find but there’s 1 more left.

and i know it’s not a real warning

i killed those 2 and also one that was listed as running out of a temp folder. i havne’t seen it pop back up yet

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex034/uploads/speedlife/original/2X/b/b7170c8eddc0b95ece6b88172b2f416a08489a45.png) [@system](https://forums.speedlife.net/u/system)\
**Post date:** [July 19, 2005, 8:47pm UTC](https://forums.speedlife.net/t/ad-spyware-thats-currently-kicking-my-ass/175750/8 "2005-07-19T20:47:47Z")

</div>

> [@BlueMeanieTSi](#):
>
> read my post:
> 
> and i know it’s not a real warning
> 
> i killed those 2 and also one that was listed as running out of a temp folder. i havne’t seen it pop back up yet

someone link me to some free removal spyware DL’s cause I need em

---

<div class="post-metadata">

**Author:** ![Darkstar](https://avatars.discourse-cdn.com/v4/letter/d/b487fb/32.png) [@Darkstar](https://forums.speedlife.net/u/Darkstar)\
**Post date:** [July 19, 2005, 8:59pm UTC](https://forums.speedlife.net/t/ad-spyware-thats-currently-kicking-my-ass/175750/9 "2005-07-19T20:59:12Z")

</div>

> [@BoostedITR41](#):
>
> someone link me to some free removal spyware DL’s cause I need em

[www.readthefuckingthread.com](http://www.readthefuckingthread.com)

---

<div class="post-metadata">

**Author:** ![Shaggy](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/shaggy/32/5945_2.png) [@Shaggy](https://forums.speedlife.net/u/Shaggy)\
**Post date:** [July 19, 2005, 9:14pm UTC](https://forums.speedlife.net/t/ad-spyware-thats-currently-kicking-my-ass/175750/10 "2005-07-19T21:14:39Z")

</div>

Kurt, why do you make it so difficult to read your post.

Whats the question again? 🙂

---

<div class="post-metadata">

**Author:** ![berad](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/berad/32/5953_2.png) [@berad](https://forums.speedlife.net/u/berad)\
**Post date:** [July 19, 2005, 10:56pm UTC](https://forums.speedlife.net/t/ad-spyware-thats-currently-kicking-my-ass/175750/11 "2005-07-19T22:56:56Z")

</div>

Technically you don’t need to d/l spyware removal tools if you can clean you shit manually…  
-TURN OFF SYSTEM RESTORE  
-BOOT IN SAFE MODE  
-DELETE ALL TEMP FILES  
-DELETE ALL COOKIES  
-CHECK FAVORITES FOR SUSPICIOUS LINKS  
-PERFORM DISK CLEANUP  
-EDIT REGISTRY FOR SUSPICIOUS LOOKING ENTRIES UNDER LOCAL\_MACHINE\SOFTWARE  
-RUN MSCONFIG, CHECK FOR SUSPICIOUS STARTUP ITEMS, CHECK FOR SUSPICIOUS SERVICES AT STARTUP

Hope that helps

---

<div class="post-metadata">

**Author:** ![T70\_Tsi](https://avatars.discourse-cdn.com/v4/letter/t/898d66/32.png) [@T70\_Tsi](https://forums.speedlife.net/u/T70_Tsi)\
**Post date:** [July 19, 2005, 11:17pm UTC](https://forums.speedlife.net/t/ad-spyware-thats-currently-kicking-my-ass/175750/12 "2005-07-19T23:17:06Z")

</div>

brad i looked in the registry for suspicious entries and couldnt’ find any, in fact when i was tracking down 2 different kinds of spyware the one everyone was telling me to delete the path and the registry entries they weren’t even there yet i had all the symptoms…so i dont’ trust that 100%

---

<div class="post-metadata">

**Author:** ![grnteg98](https://avatars.discourse-cdn.com/v4/letter/g/977dab/32.png) [@grnteg98](https://forums.speedlife.net/u/grnteg98)\
**Post date:** [July 20, 2005, 2:25am UTC](https://forums.speedlife.net/t/ad-spyware-thats-currently-kicking-my-ass/175750/13 "2005-07-20T02:25:55Z")

</div>

firefox \> IE

---

<div class="post-metadata">

**Author:** ![berad](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/berad/32/5953_2.png) [@berad](https://forums.speedlife.net/u/berad)\
**Post date:** [July 20, 2005, 6:55am UTC](https://forums.speedlife.net/t/ad-spyware-thats-currently-kicking-my-ass/175750/14 "2005-07-20T06:55:13Z")

</div>

Kurt, I would look at this crap closer, actully the one there is certified spy-ware, I just google the exe…and almost any exe in a temp folder is crap. F AIM toolbar, F Weatherbug

> [@BlueMeanieTSi](#):
>
> Running processes:  
> R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =  
> O3 - Toolbar: (no name) - {825CF5BD-8862-4430-B771-0C15C5CA8DEF} - (no file)  
> **O4 - HKLM..\Run: [zcv52] C:\docume~1\sweety\locals~1 emp\zcv52.exe**  
> O4 - HKLM..\Run: [23rR36j] atkrip.exe  
> **O4 - HKLM..\Run: [Tsl2] C:\PROGRA~1\COMMON~1 sa sl2.exe**
> 
> > tsl2 - tsl2.exe - Process Information
> > 
> > Process File: tsl2 or tsl2.exe  
> > Process Name: Travelling Salesman Spyware
> > 
> > Description:  
> > tsl2.exe is an advertising program by Travelling Salesman Spyware. This process monitors your browsing habits and distributes the data back to the author’s servers for analysis. This also prompts advertising popups. This program is a registered security risk and should be removed immediately. Please see additional details regarding this process
> 
> O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm  
> O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe  
> O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
> 
> 2 of those jump out at me:
> 
> O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
> 
> O3 - Toolbar: (no name) - {825CF5BD-8862-4430-B771-0C15C5CA8DEF} - (no file)

---

<div class="post-metadata">

**Author:** ![77rednecktruck](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/77rednecktruck/32/5966_2.png) [@77rednecktruck](https://forums.speedlife.net/u/77rednecktruck)\
**Post date:** [July 20, 2005, 6:57am UTC](https://forums.speedlife.net/t/ad-spyware-thats-currently-kicking-my-ass/175750/15 "2005-07-20T06:57:42Z")

</div>

format c:

that fixes everything

---

<div class="post-metadata">

**Author:** ![fshowcars](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/fshowcars/32/5937_2.png) [@fshowcars](https://forums.speedlife.net/u/fshowcars)\
**Post date:** [July 20, 2005, 6:59am UTC](https://forums.speedlife.net/t/ad-spyware-thats-currently-kicking-my-ass/175750/16 "2005-07-20T06:59:33Z")

</div>

> [@BlueMeanieTSi](#):
>
> Running processes:  
> C:\WINDOWS\System32\smss.exe  
> C:\WINDOWS\system32\winlogon.exe  
> C:\WINDOWS\system32\services.exe  
> C:\WINDOWS\system32\lsass.exe  
> C:\WINDOWS\system32\svchost.exe  
> C:\WINDOWS\System32\svchost.exe  
> C:\WINDOWS\Explorer.EXE  
> C:\WINDOWS\system32\spoolsv.exe  
> C:\WINDOWS\System32\msole32.exe junk  
> C:\Program Files\NavNT\vptray.exe  
> C:\Program Files\NavNT\defwatch.exe  
> C:\Program Files\Common Files\Real\Update\_OB\realsched.exe junk  
> C:\Program Files\ewido\security suite\ewidoctrl.exe junk  
> C:\Program Files\Common Files\Real\Update\_OB\rnathchk.exe junk  
> C:\Program Files\Microsoft AntiSpyware\gcasServ.exe junk  
> C:\WINDOWS\System32\ctfmon.exe  
> C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe  
> C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe junk  
> C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe junk  
> C:\Program Files\NavNT\rtvscan.exe  
> C:\WINDOWS\System32\svchost.exe  
> C:\Program Files\QUICKENW\QWDLLS.EXE junk  
> C:\WINDOWS\System32\MsgSys.EXE junk  
> C:\Program Files\ewido\security suite\ewidoguard.exe junk  
> C:\Program Files\AIM95\aim.exe junk  
> C:\Program Files\Internet Explorer\iexplore.exe junk  
> C:\Documents and Settings\sweety\Desktop\HijackThis.exe junk

---

<div class="post-metadata">

**Author:** ![berad](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/berad/32/5953_2.png) [@berad](https://forums.speedlife.net/u/berad)\
**Post date:** [July 20, 2005, 7:03am UTC](https://forums.speedlife.net/t/ad-spyware-thats-currently-kicking-my-ass/175750/17 "2005-07-20T07:03:15Z")

</div>

Real Player Updates can kiss my ass

---

<div class="post-metadata">

**Author:** ![bobby311](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/bobby311/32/5971_2.png) [@bobby311](https://forums.speedlife.net/u/bobby311)\
**Post date:** [July 20, 2005, 7:05am UTC](https://forums.speedlife.net/t/ad-spyware-thats-currently-kicking-my-ass/175750/18 "2005-07-20T07:05:53Z")

</div>

> [@grnteg98](#):
>
> firefox \> IE

holy fuck

shut the fuck up

firefox sucks balls

---

<div class="post-metadata">

**Author:** ![bobby311](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/bobby311/32/5971_2.png) [@bobby311](https://forums.speedlife.net/u/bobby311)\
**Post date:** [July 20, 2005, 7:06am UTC](https://forums.speedlife.net/t/ad-spyware-thats-currently-kicking-my-ass/175750/19 "2005-07-20T07:06:23Z")

</div>

> [@Be\_Rad](#):
>
> Real Player Updates can kiss my ass

anything to do with Real Player sucks

bufffffffffferinngggggg…

---

<div class="post-metadata">

**Author:** ![77rednecktruck](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/77rednecktruck/32/5966_2.png) [@77rednecktruck](https://forums.speedlife.net/u/77rednecktruck)\
**Post date:** [July 20, 2005, 7:07am UTC](https://forums.speedlife.net/t/ad-spyware-thats-currently-kicking-my-ass/175750/20 "2005-07-20T07:07:12Z")

</div>

> [@BlueMeanieTSi](#):
>
> C:\Documents and Settings\sweety\Desktop\HijackThis.exe

your username on the pc is “Sweety”  
:kekegay:  
🤣

[Next page](https://forums.speedlife.net/t/ad-spyware-thats-currently-kicking-my-ass/175750.md?page=2)
