Spyware Blaster

Discussion in 'SpywareBlaster & Other Forum' started by eagledrmz, Dec 10, 2003.

Thread Status:
Not open for further replies.
  1. eagledrmz

    eagledrmz Registered Member

    Joined:
    Dec 10, 2003
    Posts:
    7
    Spyware Blaster has been working great for me but now I'm wondering if it might be causing a slight problem. When I go to a few certain websites they do not load completely or properly display "clickable" options on the page. These are sites I've used effectively prior to installing SB. One example is a game site where you select several numbers, click enter, and then get several clickable advertisement links of which you must select one to complete your entry. I can select the numbers but don't get the follow through links any more. I was unable to figure out what I might change in "Settings" so I deselected/cleared everything and when that didn't fix the problem I uninstalled SB which didn't help either. Tried disabling my firewall and virus protection to no avail too. Any ideas would be most appreciated, thanks. AdAware and SpyBot runs show clear. My system is using:

    WinXP Home Edition
    IE6
    Norton Firewall and AntiVirus 2003
    Router Firewall
     
  2. Pieter_Arntz

    Pieter_Arntz Spyware Veteran

    Joined:
    Apr 27, 2002
    Posts:
    13,332
    Location:
    Netherlands
    Hi eagledrmz,

    Welcome at Wilders. :)
    After you used the "Remove Protection" option, SpywareBlaster's ActiveX protection has no longer any influence whatsoever. Neither has the cookie protection by the way.

    Unless you used the "Flash Killer" or "Custom Blocking" options, I don't see how SpywareBlaster could have been the cause of your problem.

    Regards,

    Pieter
     
  3. eagledrmz

    eagledrmz Registered Member

    Joined:
    Dec 10, 2003
    Posts:
    7
    Hi Pieter, I'm not getting the reply error from before, thanks for e-mailing earlier.
    Reinstalled SB and FlashKiller is not/was not checked yet still can't use certain sites. FlashKiller related to Macromedia's Shockwave and/or Flash players? Would reinstalling either help?
    Would be nice to use those few sites but botton line: What SpyWare Blaster does for me far outweighs this minor (so far) problem. Thanks...
     
  4. Pieter_Arntz

    Pieter_Arntz Spyware Veteran

    Joined:
    Apr 27, 2002
    Posts:
    13,332
    Location:
    Netherlands
    Hi eagledrmz,

    Could you follow the instructions in this post:
    http://www.wilderssecurity.com/showthread.php?t=15913
    It might unearth the problem.

    Regards,

    Pieter
     
  5. eagledrmz

    eagledrmz Registered Member

    Joined:
    Dec 10, 2003
    Posts:
    7
    I regularly run AdAware and SpyBot SD but haven't ever tried "Hijack This." I'll try it this weekend as well as checking the specific settings for AdAware and SpyBot that you mentioned and get back to you. Have a great weekend and thanks again.
     
  6. eagledrmz

    eagledrmz Registered Member

    Joined:
    Dec 10, 2003
    Posts:
    7
    I ran updated AdAware and SpyBot with the settings exactly as prescribed in the link you sent Both showed clear/no hits. I dl'ed, installed, and ran "Hijack This." I have not and will not yet attempt to "fix" any of the results of Hijack's scan and have copied it's results below as per the link's instructions. Thank you...

    Logfile of HijackThis v1.97.7
    Scan saved at 1:19:14 PM, on 12/13/2003
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    C:\Program Files\Norton Personal Firewall\NISUM.EXE
    C:\Program Files\Common Files\Symantec Shared\ccApp.exe
    C:\Program Files\Logitech\iTouch\iTouch.exe
    C:\Program Files\Iconoid\iconoid.exe
    C:\Program Files\BELKIN-SSA\Upsmon.exe
    C:\Program Files\Logitech\MouseWare\system\em_exec.exe
    C:\Program Files\BELKIN-SSA\UPSData.exe
    C:\Program Files\CacheBoost\cbsrv.exe
    C:\Program Files\Norton Personal Firewall\ccPxySvc.exe
    C:\WINDOWS\System32\CTsvcCDA.EXE
    C:\Program Files\DiskeeperLite\DKService.exe
    C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
    C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
    C:\WINDOWS\System32\nvsvc32.exe
    C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\MsPMSPSv.exe
    C:\Documents and Settings\MFD\My Documents\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.excite.com/
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = c:\WINDOWS\PCHealth\HelpCtr\System\panels\blank.htm
    O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
    O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
    O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
    O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
    O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
    O4 - HKLM\..\Run: [CTStartup] C:\Program Files\Creative\Splash Screen\CTEaxSpl.EXE /run
    O4 - HKLM\..\Run: [AsioReg] REGSVR32.EXE /S CTASIO.DLL
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
    O4 - HKCU\..\Run: [Iconoid] "C:\Program Files\Iconoid\iconoid.exe"
    O4 - HKCU\..\Run: [TClockEx] C:\Program Files\TClockEx\TCLOCKEX.EXE
    O4 - HKLM\..\RunOnce: [washindex] C:\Program Files\Washer\washidx.exe "MFD"
    O4 - HKCU\..\RunOnce: [washindex] C:\Program Files\Washer\washidx.exe "MFD"
    O4 - Startup: BELKIN.lnk = C:\Program Files\BELKIN-SSA\Upsmon.exe
    O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
    O8 - Extra context menu item: Backward &Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
    O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
    O8 - Extra context menu item: Si&milar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
    O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
    O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
    O9 - Extra button: PrintKey (HKLM)
    O9 - Extra 'Tools' menuitem: PrintKey (HKLM)
    O9 - Extra button: Update (HKLM)
    O9 - Extra 'Tools' menuitem: Update (HKLM)
    O9 - Extra button: Washer (HKLM)
    O9 - Extra 'Tools' menuitem: Washer (HKLM)
    O9 - Extra button: WinAmp (HKLM)
    O9 - Extra 'Tools' menuitem: WinAmp (HKLM)
    O9 - Extra button: Norton (HKLM)
    O9 - Extra 'Tools' menuitem: Norton (HKLM)
    O9 - Extra button: Joyo (HKLM)
    O9 - Extra button: NotePad (HKLM)
    O9 - Extra 'Tools' menuitem: NotePad (HKLM)
    O9 - Extra button: WordPad (HKLM)
    O9 - Extra 'Tools' menuitem: WordPad (HKLM)
    O9 - Extra button: PowerWord (HKLM)
    O9 - Extra button: Related (HKLM)
    O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
    O9 - Extra button: NetRadio (HKLM)
    O9 - Extra 'Tools' menuitem: NetRadio (HKLM)
    O9 - Extra button: MoneySide (HKLM)
    O9 - Extra button: BigFix (HKLM)
    O9 - Extra 'Tools' menuitem: BigFix (HKLM)
    O9 - Extra button: @C:\Program Files\Messenger\Msgslang.dll,-61144 (HKLM)
    O9 - Extra 'Tools' menuitem: @C:\Program Files\Messenger\Msgslang.dll,-61144 (HKLM)
    O9 - Extra button: Mixer (HKCU)
    O9 - Extra 'Tools' menuitem: Mixer (HKCU)
    O9 - Extra button: Weather (HKCU)
    O9 - Extra 'Tools' menuitem: Weather (HKCU)
    O9 - Extra button: Trillian (HKCU)
    O9 - Extra 'Tools' menuitem: Trillian (HKCU)
    O12 - Plugin for .mid: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll
    O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
    O16 - DPF: {288451AE-BE24-4216-B946-8600E0498584} (DASWebShop Class) - http://das.microsoft.com/activate/cab/x86/i486/NTANSI/retail/DASAct.cab
    O16 - DPF: {29B2C103-AB53-4971-B765-FC1CE5D8B2D1} - http://www.silvercrk.com/php/hweuchre_scecab_12.212.196.137.2239410641970278499_1373695.cab
    O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/20030530/qtinstall.info.apple.com/bonnie/us/win/QuickTimeInstaller.exe
    O16 - DPF: {4E888414-DB8F-11D1-9CD9-00C04F98436A} (Microsoft.WinRep) - https://webresponse.one.microsoft.com/oas/ActiveX/winrep.cab
    O16 - DPF: {A7E092C3-692A-11D0-A7E5-08002B322F3B} (WebResponseAttachments Control) - https://webresponse.one.microsoft.com/oas/ActiveX/FileXfer.cab
    O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.symantec.com/SSC/SharedContent/common/bin/cabsa.cab
    O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/activedata/SymAData.dll
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
    O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.symantec.com/techsupp/activedata/ActiveData.cab
     
  7. Pieter_Arntz

    Pieter_Arntz Spyware Veteran

    Joined:
    Apr 27, 2002
    Posts:
    13,332
    Location:
    Netherlands
    Hi eagledrmz,

    Could you please try this:
    Download and install BHODemon and use it to disable this BHO:
    C:\WINDOWS\system32\dla\tfswshx.dll

    Then close all IE windows and open one new one and let us know if that makes a difference.

    Since you stated you already tried it with a disabled firewall, that is the only other resident program I can imagine interfering.

    Regards,

    Pieter
     
  8. eagledrmz

    eagledrmz Registered Member

    Joined:
    Dec 10, 2003
    Posts:
    7
    Hi Peiter, I appreciate the effort but no joy. I did exactly as you said and there was no change. Have I hit a wall on this one? Thanks...
     
  9. Pieter_Arntz

    Pieter_Arntz Spyware Veteran

    Joined:
    Apr 27, 2002
    Posts:
    13,332
    Location:
    Netherlands
    Hi eagledrmz,

    I forget. Did you already try to repair IE6?

    Regards,

    Pieter
     
  10. ellison64

    ellison64 Registered Member

    Joined:
    Oct 5, 2003
    Posts:
    2,499
    Jusrt wondering whetehr you have an application like a firewall or ad blocker that blocks referrers? as this sometimes would give the symptoms you describe.Also some links require activex to show so if you are blocking activex or not using IE could that be the problem?
    ellison
     
  11. eagledrmz

    eagledrmz Registered Member

    Joined:
    Dec 10, 2003
    Posts:
    7
    Hello again Pieter. We had not discussed repairing IE6 but I tried it before and then again just now to no avail. I'm stumped...
     
  12. eagledrmz

    eagledrmz Registered Member

    Joined:
    Dec 10, 2003
    Posts:
    7
    I found a setting in Norton Personal Firewall and did a reinstall on SpywareBlaster again and seem to be back in business. Thanks for the interest ellison 64 and especially you Pieter for all the time, effort, and concern you put into this. I'm happy and fortunate to have found this program and the cool people in the forum. Thanks Again!
     
  13. Pieter_Arntz

    Pieter_Arntz Spyware Veteran

    Joined:
    Apr 27, 2002
    Posts:
    13,332
    Location:
    Netherlands
    Hi eagledrmz,

    Good news. :cool:

    Pieter
     
Loading...
Thread Status:
Not open for further replies.