Need help removing adware / spyware. [hijackthis] [logfile]


Best Answer: For spyware solutions, Spybot Search & Destroy works very well. If you are willing to try Microsoft's beta, you can also consider defender. Both are currently free.

http://www.safer-networking.org
http://www.microsoft.com/downloads/detai…

Always remember that an ounce of prevention is worth more than a pound of cure. That said, do not visit unknown websites, open suspicious emails and attachments, or click on links that you don’t know what it’s for. Also, always keep your anti-spyware and antivirus programs on. These simple guidelines will save you from hours of headaches with pop-up ads and computer slow down.

Good luck and have a nice day!


Safe Returner – 4 stars by softpedia.com
Re:Originally posted by: guy

Originally posted by: guy

Originally posted by: guy
first of all, can you get in to safe mode? then disabling the following crap:
C:\WINDOWS\System32\CTsvcCDA.exe
C:\WINDOWS\fzowlbo.exe
C:\WINDOWS\System32\MsPMSPSv.exe
2PortalMon.exe
C:\WINDOWS\fzowlboA.exe
i suspect that the fzowlbo/A is the problem. i have never heard of that program and google comes up blank. possible a new form of spyware.
i don't know if that will fix your problem. you need to run SB S&D, Kaspersky and other programs in safe mode. When and if you format and reinstall, install ZoneAlarm Firewall. it is the best one and will keep your computer functioning well.

Thanks for the response. Yes I can get into safe mode and I will disable the programs you told me to. Only thing I'm questioning is the 2PortalMon. That is the program the my DSL modem (2 Wire) uses for monitering the internet connection. It causes no harm so I figured I'de leave it running for quick access to the gateway in case I need to change anything. However, if it is causing risk I will disable it.

guy -

Do not delete the following files – they are legit and pose no threat!

C:\WINDOWS\System32\CTsvcCDA.exe – resident program for Creative's PlayCenter included with Soundblaster Audigy sound cards

C:\WINDOWS\System32\MsPMSPSv.exe – helper service for Media Player 7+ which adds support for Windows Media Device Manager which is stuff like your portable media devices

C:\Program Files\2Wire\2PortalMon.exe – 2Wire Homeportal user interface

The other two files that guy cited are indeed bad:
C:\WINDOWS\fzowlbo.exe
C:\WINDOWS\fzowlboA.exe

However, merely deleting them will not fix your problem. Changes to your registry have been made. You've got other bad files on your system with others hidden.

You need to get assistance from someone who knows how to work on logs.

I hope I didn't damage my computer badly because I took guy's advice and deleted C:\WINDOWS\System32\CTsvcCDA.exe and C:\WINDOWS\System32\MsPMSPSv.exe from my system! I didn't delete C:\Program Files\2Wire\2PortalMon.exe because I knew that wasn't harmful. I did delete C:\WINDOWS\fzowlbo.exe and C:\WINDOWS\fzowlboA.exe. I won't be doing anything else unless I'm very sure that it's safe.

Also, I installed the free version of ZoneAlarm.


Re:Originally posted by: guy

Originally posted by: guy
first of all, can you get in to safe mode? then disabling the following crap:
C:\WINDOWS\System32\CTsvcCDA.exe
C:\WINDOWS\fzowlbo.exe
C:\WINDOWS\System32\MsPMSPSv.exe
2PortalMon.exe
C:\WINDOWS\fzowlboA.exe
i suspect that the fzowlbo/A is the problem. i have never heard of that program and google comes up blank. possible a new form of spyware.
i don't know if that will fix your problem. you need to run SB S&D, Kaspersky and other programs in safe mode. When and if you format and reinstall, install ZoneAlarm Firewall. it is the best one and will keep your computer functioning well.

Thanks for the response. Yes I can get into safe mode and I will disable the programs you told me to. Only thing I'm questioning is the 2PortalMon. That is the program the my DSL modem (2 Wire) uses for monitering the internet connection. It causes no harm so I figured I'de leave it running for quick access to the gateway in case I need to change anything. However, if it is causing risk I will disable it.

guy -

Do not delete the following files – they are legit and pose no threat!

C:\WINDOWS\System32\CTsvcCDA.exe – resident program for Creative's PlayCenter included with Soundblaster Audigy sound cards

C:\WINDOWS\System32\MsPMSPSv.exe – helper service for Media Player 7+ which adds support for Windows Media Device Manager which is stuff like your portable media devices

C:\Program Files\2Wire\2PortalMon.exe – 2Wire Homeportal user interface

The other two files that guy cited are indeed bad:
C:\WINDOWS\fzowlbo.exe
C:\WINDOWS\fzowlboA.exe

However, merely deleting them will not fix your problem. Changes to your registry have been made. You've got other bad files on your system with others hidden.

You need to get assistance from someone who knows how to work on logs.


Re:Well I'm off for a Bible study tonight. I'll leave a report either tonight or tomorrow.

Originally posted by: guy
Try this manual scanner I wrote instructions for: http://www.omnicast.net/~tmcfadden/scan.txt <– instructions. Post the text from the C:\report.html file afterwards and let's see what you got going on there.

I'll try your scanner if the other doesn't work.


Re:Try this manual scanner I wrote instructions for: http://www.omnicast.net/~tmcfadden/scan.txt <– instructions. Post the text from the C:\report.html file afterwards and let's see what you got going on there.

Re:Originally posted by: guy
first of all, can you get in to safe mode? then disabling the following crap:
C:\WINDOWS\System32\CTsvcCDA.exe
C:\WINDOWS\fzowlbo.exe
C:\WINDOWS\System32\MsPMSPSv.exe
2PortalMon.exe
C:\WINDOWS\fzowlboA.exe
i suspect that the fzowlbo/A is the problem. i have never heard of that program and google comes up blank. possible a new form of spyware.
i don't know if that will fix your problem. you need to run SB S&D, Kaspersky and other programs in safe mode. When and if you format and reinstall, install ZoneAlarm Firewall. it is the best one and will keep your computer functioning well.

Thanks for the response. Yes I can get into safe mode and I will disable the programs you told me to. Only thing I'm questioning is the 2PortalMon. That is the program the my DSL modem (2 Wire) uses for monitering the internet connection. It causes no harm so I figured I'de leave it running for quick access to the gateway in case I need to change anything. However, if it is causing risk I will disable it.

Since I am somewhat a newb to this, will running my virus removal programs in safe mode help it be more effective against ridding my computer of such junk? I notice that often when SB and AA finish scanning my computer and ask me if I want to remove the harmful software it can't always remove it for some reason. I'm thinking it's the same issue with trying to delete a program in use. Is that correct?

Also, I will download the free version of ZoneAlarm when I'm finished like you recommended.


Re:first of all, can you get in to safe mode? then disabling the following crap:
C:\WINDOWS\System32\CTsvcCDA.exe
C:\WINDOWS\fzowlbo.exe
C:\WINDOWS\System32\MsPMSPSv.exe
2PortalMon.exe
C:\WINDOWS\fzowlboA.exe
i suspect that the fzowlbo/A is the problem. i have never heard of that program and google comes up blank. possible a new form of spyware.
i don't know if that will fix your problem. you need to run SB S&D, Kaspersky and other programs in safe mode. When and if you format and reinstall, install ZoneAlarm Firewall. it is the best one and will keep your computer functioning well.

Related posts

Leave a comment

0 Comments.

Leave a Reply


click to changeSecurity Code

[ Ctrl + Enter ]