
| | |||||||
| General Software Software is what your computer runs. Word processors, spreadsheet programs... Discuss it all here. |
Register Now for FREE! | |||||
| |
| | LinkBack | Thread Tools | Display Modes |
| |||
| I would like to know if somebody puts something on my computer like webwatcher http://www.awarenesstech.com/general/index-o72v31.html that cannot be detected by me or spyware, how do you know it is on there and how do you get it off?? |
| Sponsored Links | ||
| |
| |||
| jon but if it says" It is completely invisible Designed to meet the exacting standards of intelligence agencies engaged in the war on terror, WebWatcher is completely invisible. Whether you are trying to monitor your computer savvy spouse or the head of your tech department, you won’t be detected. WebWatcher doesn’t appear in the Registry, the Process List, the System Tray, the Task Manager, on the Desktop, or in Add/Remove programs. There aren’t even any visible files that can be detected! How will it be detected then??? |
| |||
| Here is HJT log.............. Logfile of HijackThis v1.99.1 Scan saved at 4:38:29 PM, on 3/30/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:WINDOWSSystem32smss.exe C:WINDOWSsystem32csrss.exe C:WINDOWSsystem32winlogon.exe C:WINDOWSsystem32services.exe C:WINDOWSsystem32lsass.exe C:WINDOWSsystem32svchost.exe C:WINDOWSsystem32svchost.exe C:WINDOWSSystem32svchost.exe C:WINDOWSSystem32svchost.exe C:WINDOWSSystem32svchost.exe C:WINDOWSExplorer.exe C C C R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL = http://education.dellnet.com/ R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.iwon.com/ R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL = http://education.dellnet.com/ R1 - HKCUSoftwareMicrosoftInternet ExplorerSearchURL,(Default) = websearch.drsnsrch.com/q.cgi?q= R1 - HKCUSoftwareMicrosoftInternet Connection Wizard,ShellNext = http://education.dellnet.com/ R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C F2 - REG:system.ini: Shell=Explorer.exe F2 - REG:system.ini: UserInit=C:WINDOWSSystem32Userinit.exe O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:program filesgooglegoogletoolbar2.dll O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C O3 - Toolbar: (no name) - {CA0B9B71-C2AF-11D3-B376-0800460222F0} - (no file) O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:progra~1mcafee.comvsomcvsshl.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:program filesgooglegoogletoolbar2.dll O4 - HKLM..Run: [NvCplDaemon] RUNDLL32.EXE C:WINDOWSSystem32NvCpl.dll,NvStartup O4 - HKLM..Run: [DVDSentry] C:WINDOWSSystem32DSentry.exe O4 - HKLM..Run: [MMTray] C O4 - HKLM..Run: [MCAgentExe] c O4 - HKLM..Run: [MCUpdateExe] c O4 - HKLM..Run: [AdaptecDirectCD] "C O4 - HKLM..Run: [VirusScan Online] C O4 - HKLM..Run: [Microsoft Works Update Detection] C O4 - HKLM..Run: [QuickTime Task] "C O4 - HKLM..Run: [VSOCheckTask] "C O4 - HKLM..Run: [BJCFD] C O4 - HKLM..Run: [tgcmd] "C O4 - HKLM..Run: [TkBellExe] "C O4 - HKLM..Run: [nwiz] nwiz.exe /install O4 - HKLM..Run: [Windows Registry Repair Pro] C O4 - HKLM..Run: [hflhwg] c:windowssystem32fsgowh.exe O4 - HKLM..Run: [DatalodeAgent] C O4 - HKLM..Run: [mqwqwdk] c:windowssystem32kuujpmw.exe r O4 - HKLM..Run: [OASClnt] C O4 - HKLM..Run: [MyWebSearch Email Plugin] C O4 - HKLM..Run: [ImInstaller_IncrediMail] C O4 - HKCU..Run: [MSMSGS] "C O4 - HKCU..Run: [Bug Eliminator] C O4 - HKCU..Run: [DellSupport] "C O4 - HKCU..Run: [MyWebSearch Email Plugin] C O4 - HKCU..Run: [RealPlayer] "C O4 - HKCU..Run: [Spyware Doctor] "C O4 - Startup: Medic.lnk = C O4 - Startup: MyWebSearch Email Plugin.lnk = C O4 - Global Startup: Digital Line Detect.lnk = ? O4 - Global Startup: MyWebSearch Email Plugin.lnk = C O8 - Extra context menu item: &Google Search - res://c:program filesgoogleGoogleToolbar2.dll/cmsearch.html O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZS O8 - Extra context menu item: &Translate English Word - res://c:program filesgoogleGoogleToolbar2.dll/cmwordtrans.html O8 - Extra context menu item: Backward Links - res://c:program filesgoogleGoogleToolbar2.dll/cmbacklinks.html O8 - Extra context menu item: Cached Snapshot of Page - res://c:program filesgoogleGoogleToolbar2.dll/cmcache.html O8 - Extra context menu item: Similar Pages - res://c:program filesgoogleGoogleToolbar2.dll/cmsimilar.html O8 - Extra context menu item: Translate Page into English - res://c:program filesgoogleGoogleToolbar2.dll/cmtrans.html O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file) O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C O16 - DPF: ppctlcab - http://www.pestscan.com/scanner/ppctlcab.cab O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkId=39204&clcid=0x409 O16 - DPF: {1FC215B7-F71D-4137-8D67-455A2D5CA8C5} - http://www.fileeliminator.com/get/BEL/Bug%20Eliminator.cab O16 - DPF: {2FC9A21E-2069-4E47-8235-36318989DB13} (PPSDKActiveXScanner.MainScreen) - http://www.pestscan.com/scanner/axscanner.cab O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/EPUWALControl_v1-0-3-12.cab O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,90/mcinsctl.cab O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by105fd.bay105.hotmail.msn.com/resources/MsnPUpld.cab O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://www.hihiltonhead.com/AxisCamControl.ocx O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab O16 - DPF: {9DBAFCCF-592F-FFFF-FFFF-00608CEC297C} - http://download.weatherbug.com/minibug/tricklers/AWS/minibuginstaller.cab?rand=2003336 O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} - http://www.windowsecurity.com/trojanscan/axscan.cab O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,23/mcgdmgr.cab O16 - DPF: {D670D0B3-05AB-4115-9F87-D983EF1AC747} (AOL Downloader Plugin) - http://pak02.pictures.aol.com/ygp/aol/plugin/download/YGPPicDownload.9.0.0.2.cab O16 - DPF: {DC187740-46A9-11D5-A815-00B0D0428C0C} - http://www.pcpowerscan.com/pcpowerscan.cab O16 - DPF: {E7D2588A-7FB5-47DC-8830-832605661009} (Live Collaboration) - https://rr.esecurecare.net/rnt/rnl/java/RntX.cab O16 - DPF: {EE2589EB-7FC8-44DB-A892-573F2C4B41E0} - http://pdf.forbes.com/forbesnews/triggernews/ForbesDownloaderSigned.cab O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/vso/en-us/tools/mcfscan/1,5,0,4319/mcfscan.cab O23 - Service: Iomega App Services - Iomega Corporation - C O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:program filesmcafee.comagentmcdetect.exe O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C O23 - Service: Intel(R) NMS (NMSSvc) - Intel Corporation - C:WINDOWSSystem32NMSSvc.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:WINDOWSSystem32nvsvc32.exe O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C |
| ||||
| Well, I think that software won't show up in Hijack This, but I ran your log through the Hijack This log analyser, and it seems that you do have some nasty stuff on your computer. Run your log through http://www.hijackthis.de/ and it will tell you what to remove. But if you think your PC is bugged, I suggest you save all your files onto CD/DVD, then reformat it. Then, put a password lock on the computer to prevent people from being able to access it to install the bugging software. But, this software is only mainly used in schools, colleges, work places, goverment buildings, etc. Also, unless your computer is accessible to someone with a fairly good knowledge of computers, you should be safe. It would be handy, however, if you let us know a bit more about where the computer is located, if it's on a network, etc. |