# Help! Ran Adaware, Still have spyware!

**URL:** https://boards.straightdope.com/t/help-ran-adaware-still-have-spyware/244480
**Category:** Factual Questions
**Created:** [May 10, 2004, 5:12pm UTC](https://boards.straightdope.com/t/help-ran-adaware-still-have-spyware/244480 "2004-05-10T17:12:32Z")
**Posts on this page:** 19
**Page:** 1

<div class="post-metadata">

### Author: ![Acsenray](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/acsenray/32/4519_2.png) [@Acsenray](https://boards.straightdope.com/u/Acsenray)
#### Post date: [May 10, 2004, 5:12pm UTC](https://boards.straightdope.com/t/help-ran-adaware-still-have-spyware/244480/1 "2004-05-10T17:12:32Z")

</div>

I’ve got some spyware that hijacked my home page, hijacks my browser when I get a “page not found,” and throws up random advertising windows. I ran Adaware and rebooted, but it’s still happening.

---

<div class="post-metadata">

### Author: ![jesuscrust](https://avatars.discourse-cdn.com/v4/letter/j/a9adbd/32.png) [@jesuscrust](https://boards.straightdope.com/u/jesuscrust)
#### Post date: [May 10, 2004, 5:17pm UTC](https://boards.straightdope.com/t/help-ran-adaware-still-have-spyware/244480/2 "2004-05-10T17:17:03Z")

</div>

> [@acsenray](#):
>
> I’ve got some spyware that hijacked my home page, hijacks my browser when I get a “page not found,” and throws up random advertising windows. I ran Adaware and rebooted, but it’s still happening.

go to the following site and download CWS shredder, then update it, and run it. After that(on the same site), download the program hijack this and post the log file.

---

<div class="post-metadata">

### Author: ![jesuscrust](https://avatars.discourse-cdn.com/v4/letter/j/a9adbd/32.png) [@jesuscrust](https://boards.straightdope.com/u/jesuscrust)
#### Post date: [May 10, 2004, 5:19pm UTC](https://boards.straightdope.com/t/help-ran-adaware-still-have-spyware/244480/3 "2004-05-10T17:19:26Z")

</div>

by the way, make sure you have updated ad aware and it is the latest version, which is 6.181 i believe.

---

<div class="post-metadata">

### Author: ![Acsenray](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/acsenray/32/4519_2.png) [@Acsenray](https://boards.straightdope.com/u/Acsenray)
#### Post date: [May 10, 2004, 5:36pm UTC](https://boards.straightdope.com/t/help-ran-adaware-still-have-spyware/244480/4 "2004-05-10T17:36:35Z")

</div>

> [@jesuscrust](#):
>
> go to the following site and download CWS shredder, then update it, and run it. After that(on the same site), download the program hijack this and post the log file.

Which site?

---

<div class="post-metadata">

### Author: ![jesuscrust](https://avatars.discourse-cdn.com/v4/letter/j/a9adbd/32.png) [@jesuscrust](https://boards.straightdope.com/u/jesuscrust)
#### Post date: [May 10, 2004, 5:40pm UTC](https://boards.straightdope.com/t/help-ran-adaware-still-have-spyware/244480/5 "2004-05-10T17:40:33Z")

</div>

> [@acsenray](#):
>
> Which site?

haha, i’m tired, sorry about that. anyway, after you run hijack this, post the log file.

[http://www.spywareinfo.com/~merijn/downloads.html](http://www.spywareinfo.com/~merijn/downloads.html)

---

<div class="post-metadata">

### Author: ![danceswithcats](https://avatars.discourse-cdn.com/v4/letter/d/9e8a1a/32.png) [@danceswithcats](https://boards.straightdope.com/u/danceswithcats)
#### Post date: [May 10, 2004, 5:40pm UTC](https://boards.straightdope.com/t/help-ran-adaware-still-have-spyware/244480/6 "2004-05-10T17:40:45Z")

</div>

Adaware is great stuff, but it doesn’t find everything. Spybot S & D is another piece of freeware which you can download and run together with Adaware. I find that they identify different things, and Spybot offers immunization for approximately 150 items.

---

<div class="post-metadata">

### Author: ![jesuscrust](https://avatars.discourse-cdn.com/v4/letter/j/a9adbd/32.png) [@jesuscrust](https://boards.straightdope.com/u/jesuscrust)
#### Post date: [May 10, 2004, 5:44pm UTC](https://boards.straightdope.com/t/help-ran-adaware-still-have-spyware/244480/7 "2004-05-10T17:44:21Z")

</div>

the spybot immunization and detection are good, but the program has not had a signature update since march, which is really a problem. it can’t detect new threats yet, but the new version should be out this month.

---

<div class="post-metadata">

### Author: ![Antigen](https://avatars.discourse-cdn.com/v4/letter/a/848f3c/32.png) [@Antigen](https://boards.straightdope.com/u/Antigen)
#### Post date: [May 10, 2004, 6:03pm UTC](https://boards.straightdope.com/t/help-ran-adaware-still-have-spyware/244480/8 "2004-05-10T18:03:05Z")

</div>

I recently had a hijacking problem (toolbar ads appearing as Google search results), so I ran AdAware. When the scan found no spyware, I tried running Spybot Search and Destroy. It also said my computer was clean.

Finally I downloaded the demo version of [SpySweeper](http://www.webroot.com/wb/products/spysweeper/index.php), which found and eliminated the problems.

I wish one program would cover all the bases better. As it is now, I have to run at least two programs for a spyware check, because each detects different things.

My computer-savvy friends keep referring me to the “hijack this” program, but I find it too complicated for someone who’s just learning about the inner workings of a computer. YMMV.

---

<div class="post-metadata">

### Author: ![jesuscrust](https://avatars.discourse-cdn.com/v4/letter/j/a9adbd/32.png) [@jesuscrust](https://boards.straightdope.com/u/jesuscrust)
#### Post date: [May 10, 2004, 6:05pm UTC](https://boards.straightdope.com/t/help-ran-adaware-still-have-spyware/244480/9 "2004-05-10T18:05:39Z")

</div>

you can post you log file of it and i will tell you what needs to be removed. if you are unsure about something, your best bet is to google it and see what it is.

---

<div class="post-metadata">

### Author: ![Acsenray](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/acsenray/32/4519_2.png) [@Acsenray](https://boards.straightdope.com/u/Acsenray)
#### Post date: [May 10, 2004, 6:38pm UTC](https://boards.straightdope.com/t/help-ran-adaware-still-have-spyware/244480/10 "2004-05-10T18:38:56Z")

</div>

Thanks for all your help, **JC**. Here’s my Hijack This log –

Logfile of HijackThis v1.97.7  
Scan saved at 2:37:58 PM, on 5/10/2004  
Platform: Windows 2000 SP3 (WinNT 5.00.2195)  
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:  
C:\WINNT\System32\smss.exe  
C:\WINNT\system32\winlogon.exe  
C:\WINNT\system32\services.exe  
C:\WINNT\system32\lsass.exe  
C:\WINNT\system32\svchost.exe  
C:\WINNT\system32\spoolsv.exe  
C:\Program Files\NavNT\defwatch.exe  
C:\WINNT\System32\svchost.exe  
C:\Program Files\NavNT\rtvscan.exe  
C:\WINNT\system32\regsvc.exe  
C:\WINNT\system32\MSTask.exe  
C:\Program Files\Tally Systems Corp\TSCensus\bin\CClientSvc.exe  
C:\Program Files\Tally Systems Corp\TSCensus\bin\CClient.exe  
C:\WINNT\System32\WBEM\WinMgmt.exe  
C:\WINNT\System32\wm.exe  
C:\WINNT\System32\mspmspsv.exe  
C:\WINNT\system32\svchost.exe  
C:\WINNT\system32\rundll32.exe  
C:\WINNT\system32  
tvdm.exe  
C:\WINNT\Explorer.EXE  
C:\WINNT\system32\atiptaxx.exe  
C:\WINNT\system32\NWTRAY.EXE  
C:\Program Files\QuickTime\qttask.exe  
C:\Program Files\Common Files\Real\Update\_OB\realsched.exe  
C:\Program Files\NavNT\vptray.exe  
\Citrine\apps\APPS\WinZip\81\WZQKPICK.EXE  
C:\Program Files\Internet Explorer\iexplore.exe  
C:\Program Files\Outlook Express\wab.exe  
C:\Palm\palm.exe  
C:\Notes\NLNOTES.EXE  
C:\Program Files\Hummingbird\Connectivity\8.00\Exceed\exceed.exe  
C:\WINNT\system32\NALWIN32.EXE  
C:\Palm\HOTSYNC.EXE  
C:\Notes  
aldaemn.EXE  
C:\Notes  
hldaemn.EXE  
C:\WINNT\system32\wuauclt.exe  
C:\Documents and Settings\am5867\Desktop\Files\Anti-Spyware stuff\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = [http://internal.bna.com](http://internal.bna.com)  
O1 - Hosts: 207.36.196.189 [auto.search.msn.com](http://auto.search.msn.com)  
O1 - Hosts: 207.36.196.189 [search.netscape.com](http://search.netscape.com)  
O1 - Hosts: 207.36.196.189 ieautosearch  
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx  
O4 - HKLM…\Run: [Synchronization Manager] mobsync.exe /logon  
O4 - HKLM…\Run: [AtiPTA] atiptaxx.exe  
O4 - HKLM…\Run: [NWTRAY] NWTRAY.EXE  
O4 - HKLM…\Run: [QuickTime Task] “C:\Program Files\QuickTime\qttask.exe” -atboottime  
O4 - HKLM…\Run: [TkBellExe] “C:\Program Files\Common Files\Real\Update\_OB\realsched.exe” -osboot  
O4 - HKLM…\Run: [vptray] C:\Program Files\NavNT\vptray.exe  
O4 - HKCU…\Run: [SpySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe /0  
O4 - Startup: Lotus Notes.lnk = C:\Notes  
otes.exe  
O4 - Startup: Internet Explorer.lnk = ?  
O4 - Startup: Address Book.lnk = C:\Program Files\Outlook Express\wab.exe  
O4 - Startup: Palm Desktop.lnk = C:\Palm\palm.exe  
O4 - Startup: exceed.lnk = C:\Program Files\Hummingbird\Connectivity\8.00\Exceed\exceed.exe  
O4 - Startup: HotSync Manager.lnk = C:\Palm\HOTSYNC.EXE  
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE  
O4 - Global Startup: WinZip Quick Pick.lnk = APPS\WinZip\81\WZQKPICK.EXE  
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll  
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - [http://www.apple.com/qtactivex/qtplugin.cab](http://www.apple.com/qtactivex/qtplugin.cab)  
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - [http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab](http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab)  
O17 - HKLM\System\CCS\Services\Tcpip…{DAA3356F-27AD-4A7F-8FA7-D85AA76DDE34}: NameServer = 149.79.138.1

---

<div class="post-metadata">

### Author: ![RealityChuck](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/realitychuck/32/195_2.png) [@RealityChuck](https://boards.straightdope.com/u/RealityChuck)
#### Post date: [May 10, 2004, 6:45pm UTC](https://boards.straightdope.com/t/help-ran-adaware-still-have-spyware/244480/11 "2004-05-10T18:45:45Z")

</div>

> [@Antigen](#):
>
> I wish one program would cover all the bases better. As it is now, I have to run at least two programs for a spyware check, because each detects different things.

Unfortunately, it’s quite difficult. CoolWebSearch mutates so often that the antispyware people have trouble keeping up with it. There are some versions that are incredibly difficult to clean up. In addition, other spyware keeps changes and being developed too fast to keep up with.

---

<div class="post-metadata">

### Author: ![jesuscrust](https://avatars.discourse-cdn.com/v4/letter/j/a9adbd/32.png) [@jesuscrust](https://boards.straightdope.com/u/jesuscrust)
#### Post date: [May 10, 2004, 7:02pm UTC](https://boards.straightdope.com/t/help-ran-adaware-still-have-spyware/244480/12 "2004-05-10T19:02:51Z")

</div>

run hijack this again, check the folowing and hit fix. it will create backups if need be. as for the first one, i know that real player(if you allow if access to the internet at all times is responsible for ads). see the following link:  
[http://www.di-ve.com/dive/portal/portal.jhtml?pid=8150&id=8161#q8](http://www.di-ve.com/dive/portal/portal.jhtml?pid=8150&id=8161#q8)  
after deleting restart the machine.  
C:\Program Files\Common Files\Real\Update\_OB\realsched.exe  
O4 - Startup: Internet Explorer.lnk = ?  
O17-HKLM\System\CCS\Services\Tcpip…{DAA3356F-27AD-4A7F-8FA7-D85AA76DDE34}: NameServer = 149.79.138.1  
O1 - Hosts: 207.36.196.189 [auto.search.msn.com](http://auto.search.msn.com)  
O1 - Hosts: 207.36.196.189 [search.netscape.com](http://search.netscape.com)  
O1 - Hosts: 207.36.196.189 ieautosearch

to prevent future infection:  
go to the following link and download the hosts file which will block MANY known infections from occuring. put it in C:\Winnt\System32\Drivers\etc and back up your old file.  
also, go here and download the experts package to block more malware from infecting you. [http://www.spywareguide.com/blockfile.php](http://www.spywareguide.com/blockfile.php)

these are constantly being updated so check back perdiodically. hope the problem is cleared up.

---

<div class="post-metadata">

### Author: ![jesuscrust](https://avatars.discourse-cdn.com/v4/letter/j/a9adbd/32.png) [@jesuscrust](https://boards.straightdope.com/u/jesuscrust)
#### Post date: [May 10, 2004, 7:12pm UTC](https://boards.straightdope.com/t/help-ran-adaware-still-have-spyware/244480/13 "2004-05-10T19:12:21Z")

</div>

also remove:  
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = [http://internal.bna.com](http://internal.bna.com)  
and missing link: [http://webpages.charter.net/hpguru/hosts/hosts.html](http://webpages.charter.net/hpguru/hosts/hosts.html)

---

<div class="post-metadata">

### Author: ![Acsenray](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/acsenray/32/4519_2.png) [@Acsenray](https://boards.straightdope.com/u/Acsenray)
#### Post date: [May 10, 2004, 7:57pm UTC](https://boards.straightdope.com/t/help-ran-adaware-still-have-spyware/244480/14 "2004-05-10T19:57:23Z")

</div>

Thanks so much for your help.

> [@jesuscrust](#):
>
> also remove:  
> R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = [http://internal.bna.com](http://internal.bna.com)

I’ll keep this one. It’s my company’s internal home page.

> [@](#):
>
> and missing link: [http://webpages.charter.net/hpguru/hosts/hosts.html](http://webpages.charter.net/hpguru/hosts/hosts.html)

I’m supposed to delete this or insert it or something?

There’s actually a hosts file in my C:\WINNT\system32\drivers\etc folder called “hosts.” When I look at it in Notepad, it shows this –

> [@](#):
>
> 07.36.196.189 [auto.search.msn.com](http://auto.search.msn.com)  
> 207.36.196.189 [search.netscape.com](http://search.netscape.com)  
> 207.36.196.189 ieautosearch  
> 127.0.0.1 [www.igetnet.com](http://www.igetnet.com)  
> 127.0.0.1 [code.ignphrases.com](http://code.ignphrases.com)  
> 127.0.0.1 [clear-search.com](http://clear-search.com)  
> 127.0.0.1 [r1.clrsch.com](http://r1.clrsch.com)  
> 127.0.0.1 [sds.clrsch.com](http://sds.clrsch.com)  
> 127.0.0.1 [status.clrsch.com](http://status.clrsch.com)  
> 127.0.0.1 [www.clrsch.com](http://www.clrsch.com)  
> 127.0.0.1 [clr-sch.com](http://clr-sch.com)  
> 127.0.0.1 [sds-qckads.com](http://sds-qckads.com)  
> 127.0.0.1 [status.qckads.com](http://status.qckads.com)

But when I try to delete or change this, it reappears automatically.

Also, when I reboot, I get an error message saying that there are some files that have been modified and it asks for the Windows c.d. I wonder if this is the problem?

---

<div class="post-metadata">

### Author: ![Acsenray](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/acsenray/32/4519_2.png) [@Acsenray](https://boards.straightdope.com/u/Acsenray)
#### Post date: [May 10, 2004, 8:01pm UTC](https://boards.straightdope.com/t/help-ran-adaware-still-have-spyware/244480/15 "2004-05-10T20:01:29Z")

</div>

> [@jesuscrust](#):
>
> to prevent future infection:  
> go to the following link and download the hosts file which will block MANY known infections from occuring. put it in C:\Winnt\System32\Drivers\etc and back up your old file.

Which link would this be?

---

<div class="post-metadata">

### Author: ![jesuscrust](https://avatars.discourse-cdn.com/v4/letter/j/a9adbd/32.png) [@jesuscrust](https://boards.straightdope.com/u/jesuscrust)
#### Post date: [May 10, 2004, 8:01pm UTC](https://boards.straightdope.com/t/help-ran-adaware-still-have-spyware/244480/16 "2004-05-10T20:01:43Z")

</div>

looks like the home page redirecting malware has edited you HOSTS file. boot into safe mode, delete this file, and then replace it with the one downloaded. as to the problems on startup, what does it say? does it specify a file? chacnes are you have a backp copy on the installation disk.

---

<div class="post-metadata">

### Author: ![jesuscrust](https://avatars.discourse-cdn.com/v4/letter/j/a9adbd/32.png) [@jesuscrust](https://boards.straightdope.com/u/jesuscrust)
#### Post date: [May 10, 2004, 8:03pm UTC](https://boards.straightdope.com/t/help-ran-adaware-still-have-spyware/244480/17 "2004-05-10T20:03:23Z")

</div>

> [@jesuscrust](#):
>
> looks like the home page redirecting malware has edited you HOSTS file. boot into safe mode, delete this file, and then replace it with the one downloaded. as to the problems on startup, what does it say? does it specify a file? chacnes are you have a backp copy on the installation disk.

[http://webpages.charter.net/hpguru/hosts/hosts.html](http://webpages.charter.net/hpguru/hosts/hosts.html)  
you can safely delete you old file

---

<div class="post-metadata">

### Author: ![Fear\_Itself](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/fear_itself/32/19637_2.png) [@Fear\_Itself](https://boards.straightdope.com/u/Fear_Itself)
#### Post date: [May 10, 2004, 8:16pm UTC](https://boards.straightdope.com/t/help-ran-adaware-still-have-spyware/244480/18 "2004-05-10T20:16:29Z")

</div>

Try Adaware again, but instead of running the default option (“Perform smart system scan”), check “Use custom scanning options”, and select “Customize”, then check “Scan my IE favorites for banned URLs” and “Scan my hosts file”.

Make sure you are using Adaware 6.0, build **6.181** , update **01R303 08.05.2004**. If it is anything other than this version, it is not up to date, and won’t remove the latest variations.

---

<div class="post-metadata">

### Author: ![Fear\_Itself](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/fear_itself/32/19637_2.png) [@Fear\_Itself](https://boards.straightdope.com/u/Fear_Itself)
#### Post date: [May 10, 2004, 9:04pm UTC](https://boards.straightdope.com/t/help-ran-adaware-still-have-spyware/244480/19 "2004-05-10T21:04:16Z")

</div>

I forgot to add, if adaware still fails to remove the IGetNet browser hijacker (which is what you have), [here are the instructions to remove it by hand](http://www.doxdesk.com/parasite/IGetNet.html).
