Home News Forum Articles
  Welcome back Join CF
You are here You are here: Home | Forum | Ad Aware & Spybot problem

You are currently viewing our boards as a guest which gives you limited access to view most of the discussions, articles and other free features. By joining our Virgin Media community you will have full access to all discussions, be able to view and post threads, communicate privately with other members (PM), respond to polls, upload your own images/photos, and access many other special features. Registration is fast, simple and absolutely free so please join our community today.


Welcome to Cable Forum
Go Back   Cable Forum > Computers & IT > Security & Virus Discussion
Register FAQ Community Calendar

Ad Aware & Spybot problem
Closed Thread
 
Thread Tools
Old 27-07-2004, 17:43   #1
MadGamer
Eva Longoria Fan
 
MadGamer's Avatar
 
Join Date: Jun 2003
Location: Essex
Age: 36
Services: Sky multiroom (Sky Q) Sky Fibre Unlimited Sky Landline
Posts: 8,851
MadGamer has a nice shiny star
MadGamer has a nice shiny starMadGamer has a nice shiny star
Ad Aware & Spybot problem

Ok, i just recently did a scan with Ad Aware 6.0 and Spybot S&D and found some unusual results. I found Top Moxie which was a reg entry and VX2 which was a file. Both of these were Data Minor Files and one was located within the following directory.

Quote:
Vendor: VX2 Category: Data Miner Object Type: File Size: 65536 Bytes Location: c:\windows\system32\bdlz4012.exe
The other is as follows:

Quote:
Vendor: Top Moxie Category: Data Miner Object Type: Reg Key Size: - Location: Software/Microsoft/Internet Explorer/Menu EXT/Web Rebates/
I then found an entry within Spybot S&D which is in the follwoing file attached.

Ok when i try and delete this also my Firewall (ZA) Reports that an installer is trying to gain access. Cant give you the name as i have deleted the entry from the firewalls program menu.
MadGamer is offline  
Advertisement
Old 27-07-2004, 18:35   #2
Ramrod
[NTHW] pc clan
 
Ramrod's Avatar
 
Join Date: Jun 2003
Location: Tonbridge
Age: 56
Services: Amazon Prime Video & Netflix. Deregistered from my TV licence.
Posts: 21,950
Ramrod has a golden aura
Ramrod has a golden auraRamrod has a golden auraRamrod has a golden auraRamrod has a golden auraRamrod has a golden auraRamrod has a golden auraRamrod has a golden auraRamrod has a golden auraRamrod has a golden auraRamrod has a golden auraRamrod has a golden auraRamrod has a golden auraRamrod has a golden auraRamrod has a golden auraRamrod has a golden auraRamrod has a golden auraRamrod has a golden aura
Re: Ad Aware & Spybot problem

Nope, can't help you there m8. Sorry
You need someone more knowledgeable than me
__________________
Step by step, walk the thousand mile road...
-----------------------------------------------------
Ramrod is offline  
Old 27-07-2004, 18:44   #3
paulyoung666
Permanently Banned
 
paulyoung666's Avatar
 
Join Date: Jun 2003
Location: norton , teesside
Age: 55
Posts: 10,571
paulyoung666 has a nice shiny star
paulyoung666 has a nice shiny starpaulyoung666 has a nice shiny starpaulyoung666 has a nice shiny starpaulyoung666 has a nice shiny starpaulyoung666 has a nice shiny starpaulyoung666 has a nice shiny starpaulyoung666 has a nice shiny starpaulyoung666 has a nice shiny starpaulyoung666 has a nice shiny starpaulyoung666 has a nice shiny starpaulyoung666 has a nice shiny star
Re: Ad Aware & Spybot problem

can you right click and delete the exe file ??????????
paulyoung666 is offline  
Old 27-07-2004, 18:49   #4
MadGamer
Eva Longoria Fan
 
MadGamer's Avatar
 
Join Date: Jun 2003
Location: Essex
Age: 36
Services: Sky multiroom (Sky Q) Sky Fibre Unlimited Sky Landline
Posts: 8,851
MadGamer has a nice shiny star
MadGamer has a nice shiny starMadGamer has a nice shiny star
Re: Ad Aware & Spybot problem

Thats the thing i dont know where it is. I could try doing a search for it though.
MadGamer is offline  
Old 27-07-2004, 18:54   #5
Tezcatlipoca
Inactive
 
Tezcatlipoca's Avatar
 
Join Date: Jun 2003
Location: Cambridge
Posts: 16,760
Tezcatlipoca has a pair of shiny starsTezcatlipoca has a pair of shiny starsTezcatlipoca has a pair of shiny starsTezcatlipoca has a pair of shiny starsTezcatlipoca has a pair of shiny stars
Tezcatlipoca has a pair of shiny starsTezcatlipoca has a pair of shiny starsTezcatlipoca has a pair of shiny starsTezcatlipoca has a pair of shiny starsTezcatlipoca has a pair of shiny starsTezcatlipoca has a pair of shiny stars
Re: Ad Aware & Spybot problem

Erm, doesn't your first post say where it is?

Quote:
c:\windows\system32\bdlz4012.exe
Or do you mean the installer?

Anyway.

Is c:\windows\system32\bdlz4012.exe running in the background? Can you kill the process & then delete it?

Try booting into Safe Mode (F8 when you turn the PC on / boot up), & then running AdAware, SpyBot, etc.
Tezcatlipoca is offline  
Old 27-07-2004, 18:58   #6
paulyoung666
Permanently Banned
 
paulyoung666's Avatar
 
Join Date: Jun 2003
Location: norton , teesside
Age: 55
Posts: 10,571
paulyoung666 has a nice shiny star
paulyoung666 has a nice shiny starpaulyoung666 has a nice shiny starpaulyoung666 has a nice shiny starpaulyoung666 has a nice shiny starpaulyoung666 has a nice shiny starpaulyoung666 has a nice shiny starpaulyoung666 has a nice shiny starpaulyoung666 has a nice shiny starpaulyoung666 has a nice shiny starpaulyoung666 has a nice shiny starpaulyoung666 has a nice shiny star
Re: Ad Aware & Spybot problem

Quote:
Originally Posted by Matt D
Erm, doesn't your first post say where it is?



Or do you mean the installer?

Anyway.

Is c:\windows\system32\bdlz4012.exe running in the background? Can you kill the process & then delete it?

Try booting into Safe Mode (F8 when you turn the PC on / boot up), & then running AdAware, SpyBot, etc.

i was wondering that as well , safe mode has to be the place to go i reckon , or maybe a quick google about the said file might help
paulyoung666 is offline  
Old 27-07-2004, 19:36   #7
MadGamer
Eva Longoria Fan
 
MadGamer's Avatar
 
Join Date: Jun 2003
Location: Essex
Age: 36
Services: Sky multiroom (Sky Q) Sky Fibre Unlimited Sky Landline
Posts: 8,851
MadGamer has a nice shiny star
MadGamer has a nice shiny starMadGamer has a nice shiny star
Re: Ad Aware & Spybot problem

Ok found the file in the processes menu by the name of webrebates0.exe. It leads to a directory on the C drive as

Quote:
C:\Program Files/Web_Rebates

Also a file in the directory of C:\Windows\PREFETCH
MadGamer is offline  
Old 27-07-2004, 19:39   #8
Tezcatlipoca
Inactive
 
Tezcatlipoca's Avatar
 
Join Date: Jun 2003
Location: Cambridge
Posts: 16,760
Tezcatlipoca has a pair of shiny starsTezcatlipoca has a pair of shiny starsTezcatlipoca has a pair of shiny starsTezcatlipoca has a pair of shiny starsTezcatlipoca has a pair of shiny stars
Tezcatlipoca has a pair of shiny starsTezcatlipoca has a pair of shiny starsTezcatlipoca has a pair of shiny starsTezcatlipoca has a pair of shiny starsTezcatlipoca has a pair of shiny starsTezcatlipoca has a pair of shiny stars
Re: Ad Aware & Spybot problem

Try stopping it & then deleting it (& the Web Rebates directory).


Also, you can safely delete the entire contents of the Prefetch folder (but don't delete the actual folder itself).

As I said above, try scanning while in Safe Mode if you are unable to remove anything.
Tezcatlipoca is offline  
Old 27-07-2004, 20:09   #9
MadGamer
Eva Longoria Fan
 
MadGamer's Avatar
 
Join Date: Jun 2003
Location: Essex
Age: 36
Services: Sky multiroom (Sky Q) Sky Fibre Unlimited Sky Landline
Posts: 8,851
MadGamer has a nice shiny star
MadGamer has a nice shiny starMadGamer has a nice shiny star
Re: Ad Aware & Spybot problem

Update: I have deleted the pesky spyware but can anyone recommend a prog that deletes entries from starting up?
MadGamer is offline  
Old 27-07-2004, 20:14   #10
Tezcatlipoca
Inactive
 
Tezcatlipoca's Avatar
 
Join Date: Jun 2003
Location: Cambridge
Posts: 16,760
Tezcatlipoca has a pair of shiny starsTezcatlipoca has a pair of shiny starsTezcatlipoca has a pair of shiny starsTezcatlipoca has a pair of shiny starsTezcatlipoca has a pair of shiny stars
Tezcatlipoca has a pair of shiny starsTezcatlipoca has a pair of shiny starsTezcatlipoca has a pair of shiny starsTezcatlipoca has a pair of shiny starsTezcatlipoca has a pair of shiny starsTezcatlipoca has a pair of shiny stars
Re: Ad Aware & Spybot problem

Here's something which will give you info on stuff that runs at start-up:

"Startup Inspector for Windows" - http://www.windowsstartup.com/
Tezcatlipoca is offline  
Old 27-07-2004, 20:21   #11
MadGamer
Eva Longoria Fan
 
MadGamer's Avatar
 
Join Date: Jun 2003
Location: Essex
Age: 36
Services: Sky multiroom (Sky Q) Sky Fibre Unlimited Sky Landline
Posts: 8,851
MadGamer has a nice shiny star
MadGamer has a nice shiny starMadGamer has a nice shiny star
Re: Ad Aware & Spybot problem

Quote:
Originally Posted by Matt D
Here's something which will give you info on stuff that runs at start-up:

"Startup Inspector for Windows" - http://www.windowsstartup.com/
Thanks for that removed a lot of stuff that didnt need to startup (Looking at the key or legend as we tend to call it) Thread can be closed.
MadGamer is offline  
Old 27-07-2004, 20:35   #12
Tezcatlipoca
Inactive
 
Tezcatlipoca's Avatar
 
Join Date: Jun 2003
Location: Cambridge
Posts: 16,760
Tezcatlipoca has a pair of shiny starsTezcatlipoca has a pair of shiny starsTezcatlipoca has a pair of shiny starsTezcatlipoca has a pair of shiny starsTezcatlipoca has a pair of shiny stars
Tezcatlipoca has a pair of shiny starsTezcatlipoca has a pair of shiny starsTezcatlipoca has a pair of shiny starsTezcatlipoca has a pair of shiny starsTezcatlipoca has a pair of shiny starsTezcatlipoca has a pair of shiny stars
Re: Ad Aware & Spybot problem

Glad it helped.


Thread Closed, as requested.
Tezcatlipoca is offline  
Closed Thread


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT +1. The time now is 14:21.


Server: osmium.zmnt.uk
Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2024, vBulletin Solutions Inc.