PDA

View Full Version : BHO problem !!!


eurekamind
May 7th, 2006, 01:14 PM
hi,

Whenever I use flashGet I get under mentioned registry entry:

HKEY_CURRENT_USER\Software\Stilesoft\NetCaptor\CurrentVersion\Browser Helper Objects\{A5366673-E8CA-11D3-9CD9-0090271D075B}

In HJT's log, it appears as:

O2 - BHO: (no name) - {A5366673-E8CA-11D3-9CD9-0090271D075B} - (no file)

I want to know whether this BHO is harmful or not? If so, then how to get rid of it.

I suspect that my Internet speed goes slow when this registry entry is there.

I tried to remove the registry entry mannually many times but whenever I run the FlashGet, it comes again.

pls help!!!

WSFuser
May 7th, 2006, 02:09 PM
i cant analyze HJT logs but my guess is the BHO is from flashget and its for integration into some browser (ie, firefox, opera or whatever).

Bubba
May 7th, 2006, 02:46 PM
-{ Quote: "I want to know whether this BHO is harmful or not?" }-It is rated as a legitimate(L) item by the CastleCops Team that maintains the Master BHO and Toolbar list. By legitimate it means it is not considered spyware/foistware, or other malware(X)
http://castlecops.com/tk470-IeCatch2_Class.html

eurekamind
May 8th, 2006, 07:04 AM
-{ Quote: "It is rated as a legitimate(L) item by the CastleCops Team that maintains the Master BHO and Toolbar list. By legitimate it means it is not considered spyware/foistware, or other malware" }-

thanks Bubba for the information !!!

but I am still in dilemma whether it affects my Internet speed in any way or not.

aigle
May 8th, 2006, 08:41 AM
BTW, u use free version or Paid one?

eurekamind
May 9th, 2006, 12:16 PM
-{ Quote: "BTW, u use free version or Paid one?" }-

FlashGet that I am using is a registered version.

TopperID
May 9th, 2006, 01:07 PM
According to this it relates to a legitimate file (Jccatch.dll):-

http://www.sysinfo.org/bholist.php?filter=A5366673-E8CA-11D3-9CD9-0090271D075B

So if you research Jccatch.dll you might find out what it does. However, according to HJT you don't even have that file (it says 'no file'), so you are just getting the Reg entry. Since it is legitimate I wouldn't worry about it.

beetlejuice69
May 9th, 2006, 04:05 PM
I used that program for a long time and it never slowed down my internet...it did speed up the downloads. ;)

Pieter_Arntz
May 10th, 2006, 07:18 AM
If there is no file attached, as indicated by (no file) then there is no real reason not to fix it with HijackThis.

Windows will try to load it into IE everytime you open a new browser window, so even if it isn't much it will slow you down.

Regards,

Pieter

eurekamind
May 10th, 2006, 11:13 AM
-{ Quote: "According to this it relates to a legitimate file (Jccatch.dll):-
However, according to HJT you don't even have that file (it says 'no file'), so you are just getting the Reg entry. Since it is legitimate I wouldn't worry about it." }-

I re-installed the FlashGet after un-installing the running one.


NOW, the HJT's log listed it as under which confirms that it is related with the FlashGet's file ' jccatch.dll' :

O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\PROGRAM FILES\FLASHGET\JCCATCH.DLL

May be FlashGet is using this jccatch.dll file to catch the URL of downloadable file on browser mouse click .. but not sure ...just guessing it.

If it is the legitimate one then I think, there is no harm to ignore it.