Home News Forum Articles
  Welcome back Join CF
You are here You are here: Home | Forum | Pigeon PP spyware problem


You are currently viewing our boards as a guest which gives you limited access to view most of the discussions, articles and other free features. By joining our Virgin Media community you will have full access to all discussions, be able to view and post threads, communicate privately with other members (PM), respond to polls, upload your own images/photos, and access many other special features. Registration is fast, simple and absolutely free so please join our community today.


Welcome to Cable Forum
Go Back   Cable Forum > Computers & IT > Security & Virus Discussion

Pigeon PP spyware problem
Reply
 
Thread Tools
Old 29-06-2007, 20:59   #16
cf.addict
 
Join Date: Apr 2005
Posts: 249
topcreator has disabled reputation
Re: Pigeon PP spyware problem

Download HijackThis. Double-click on the file you just downloaded. Click on the "Unzip" button to install. It will by default install to the directory - C:\PROGRAM FILES\HIJACKTHIS\ Run a scan and save the log file.
topcreator is online now   Reply With Quote
Old 29-06-2007, 21:25   #17
cf.member
 
Ken W's Avatar
 
Join Date: Jul 2004
Location: Winnersh UK
Services: NTL 4M + phone
Posts: 84
Ken W is an unknown quantity at this point
Re: Pigeon PP spyware problem

Quote:
Originally Posted by topcreator View Post
Download HijackThis. Double-click on the file you just downloaded. Click on the "Unzip" button to install. It will by default install to the directory - C:\PROGRAM FILES\HIJACKTHIS\ Run a scan and save the log file.
My Hijack Log.
Logfile of HijackThis v1.99.1
Scan saved at 21:21:38, on 29/06/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Virgin Broadband\PCguard\fws.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Microsoft Hardware\Keyboard\type32.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\Virgin Broadband\PCguard\Rps.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\NetMeter\NetMeter.exe
C:\WINDOWS\system32\RAMASST.exe
C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
C:\WINDOWS\system32\crypserv.exe
C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
C:\WINDOWS\system32\DVDRAMSV.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\SVPRO50C\PROGRAM\PICSERV.EXE
C:\Program Files\Retrospect\Retrospect 7.5\retrorun.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\UPHClean\uphclean.exe
C:\Program Files\Virgin Broadband\advisor\BroadbandadvisorComHandler.exe
C:\Program Files\Common Files\Command Software\dvpapi.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Skype\Plugin Manager\SkypePM.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.virginmedia.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.tiscali.co.uk
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Tiscali
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyServer = leed-cache-1.server.ntli.net :8080
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: (no name) - {0096CC0A-623C-4829-AD9C-19AF0DC9D8FE} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Pop-Up Blocker BHO - {3C060EA2-E6A9-4E49-A530-D4657B8C449A} - C:\Program Files\Virgin Broadband\PCguard\pkR.dll
O2 - BHO: Form Filler BHO - {56071E0D-C61B-11D3-B41C-00E02927A304} - C:\Program Files\Virgin Broadband\PCguard\FBHR.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [POINTER] point32.exe
O4 - HKLM\..\Run: [IntelliType] "C:\Program Files\Microsoft Hardware\Keyboard\type32.exe"
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [IMONTRAY] C:\Program Files\Intel\Intel(R) Active Monitor\imontray.exe
O4 - HKLM\..\Run: [PCguard] "C:\Program Files\Virgin Broadband\PCguard\Rps.exe"
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [C:\Program Files\NetMeter\NetMeter.exe] C:\Program Files\NetMeter\NetMeter.exe
O4 - Global Startup: EA8 Backup Check.lnk = C:\Program Files\EA8\EA8Now.exe
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\Windows Live Toolbar\Components\en-gb\msntabres.dll.mui/229?b188b6bf1e5b49a7b7f5e1ed516a0eda
O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\Windows Live Toolbar\Components\en-gb\msntabres.dll.mui/230?b188b6bf1e5b49a7b7f5e1ed516a0eda
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.tiscali.co.uk
O15 - Trusted Zone: http://www.t-mobile.co.uk
O15 - Trusted Zone: http://www.ukexpert.co.uk
O15 - Trusted Zone: *.ukexpert.co.uk
O16 - DPF: {01010E00-5E80-11D8-9E86-0007E96C65AE} (SupportSoft SmartIssue) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsi.cab
O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} (SupportSoft Script Runner Class) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsr.cab
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=58813
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/su/ocx/15009/CTSUEng.cab
O16 - DPF: {106E49CF-797A-11D2-81A2-00E02C015623} (AlternaTIFF ActiveX) - http://www.alternatiff.com/install/00/alttiff.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1B735B98-8010-11D5-AD0B-00500463D885} (SearchCD Control) - http://www.partsarena.com/baxi/Plugins/IMIESRCH.cab
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - http://www.symantec.com/techsupp/asa/ctrl/LSSupCtl.cab
O16 - DPF: {200B3EE9-7242-4EFD-B1E4-D97EE825BA53} (VerifyGMN Class) - http://h20270.www2.hp.com/ediags/gmn...taller_gmn.cab
O16 - DPF: {2AF5BD25-90C5-4EEC-88C5-B44DC2905D8B} (DownloadManager Control) - http://dlmanager.akamaitools.com.edg...ex-2.0.5.1.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/S...in/AvSniff.cab
O16 - DPF: {3299935F-2C5A-499A-9908-95CFFF6EF8C1} (Quicksilver Class) - http://scpwhb.ops.placeware.com/etc/...uicksilver.cab
O16 - DPF: {3451DEDE-631F-421C-8127-FD793AFC6CC8} (ActiveDataInfo Class) - http://www.symantec.com/techsupp/asa/ctrl/SymAData.cab
O16 - DPF: {36C17E9B-3354-11D1-95CF-0000B4530F04} (GrafixViewControl) - http://www.partsarena.com/baxi/Plugins/GFXVIEW.cab
O16 - DPF: {402EE96E-2CE8-482D-ADA5-CECEEA07E16D} (TurnTool Scene) - http://www.turntool.com/ViewerInstall.exe
O16 - DPF: {44990200-3C9D-426D-81DF-AAB636FA4345} (Symantec SmartIssue) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsi.cab
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsr.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.co...?1091900220390
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/S.../bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsof...?1121702437796
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Housecall ActiveX 6.5) - http://eu-housecall.trendmicro-europ...vex/hcImpl.cab
O16 - DPF: {88D969C0-F192-11D4-A65F-0040963251E5} (XML DOM Document 4.0) - file://C:\TempEI4\EI40_\msxml4.cab
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://195.224.159.71/activex/AxisCamControl.cab
O16 - DPF: {99B6E512-3893-4155-9964-8EB8E06099CB} (WebSpyWareKiller Class) - http://download.zonelabs.com/bin/pro...tor/WebSWK.cab
O16 - DPF: {9B03C5F1-F5AB-47EE-937D-A8EDA626F876} (Anonymizer Anti-Spyware Scanner) - http://download.zonelabs.com/bin/pro...tor/WebAAS.cab
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab
O16 - DPF: {AE9DCB17-F804-11D2-A44A-0020182C1446} (IntraLaunch.MainControl) - file://E:\Resources\IntraLaunch.CAB
O16 - DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} (SABScanProcesses Class) - http://www.superadblocker.com/activex/sabspx.cab
O16 - DPF: {CA6F0A67-18BB-4E39-BB8A-A1E04D6AACDF} (SABMachineInfo Class) - http://www.superadblocker.com/activex/sabminf.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - http://www.symantec.com/techsupp/asa/ctrl/SymAData.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su/ocx/15010/CTPID.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DL L
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
O23 - Service: Crypkey License - Kenonic Controls Ltd. - C:\WINDOWS\SYSTEM32\crypserv.exe
O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: DVD-RAM_Service - Matsu****a Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAMSV.exe
O23 - Service: DvpApi (dvpapi) - Authentium, Inc. - C:\Program Files\Common Files\Command Software\dvpapi.exe
O23 - Service: lmab_device - Unknown owner - C:\WINDOWS\system32\LMabcoms.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pacific Image Comm. Fax Server - Unknown owner - C:\SVPRO50C\PROGRAM\PICSERV.EXE
O23 - Service: Retrospect Launcher (RetroLauncher) - EMC Corporation - C:\Program Files\Retrospect\Retrospect 7.5\retrorun.exe
O23 - Service: PCguard Firewall (RP_FWS) - Radialpoint Inc. - C:\Program Files\Virgin Broadband\PCguard\fws.exe
Ken W is offline   Reply With Quote
Old 29-06-2007, 22:08   #18
cf.addict
 
Join Date: Apr 2005
Posts: 249
topcreator has disabled reputation
Re: Pigeon PP spyware problem

Find and Delete the following Files:
  • 023.exe
  • %program_files%\messenger\svchost.exe
  • %system%\svkp.sys
  • %program_files%\messenger\svchost.exe
  • 023.exe
Find and Delete the following Registry Keys:
  • HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\r oot\legacy_svkp
  • HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\r oot\legacy_svkp nextinstance
  • HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\r oot\legacy_svkp\0000 class
  • HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\r oot\legacy_svkp\0000 classguid
  • HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\r oot\legacy_svkp\0000 configflags
  • HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\r oot\legacy_svkp\0000 devicedesc
  • HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\r oot\legacy_svkp\0000 legacy
  • HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\r oot\legacy_svkp\0000 service
  • HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\r oot\legacy_svkp\0000\control *newlycreated*
  • HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\r oot\legacy_svkp\0000\control activeservice
  • HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\r oot\legacy_vista_xp___
  • HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\r oot\legacy_vista_xp___ nextinstance
  • HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\r oot\legacy_vista_xp___\0000 class
  • HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\r oot\legacy_vista_xp___\0000 classguid
  • HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\r oot\legacy_vista_xp___\0000 configflags
  • HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\r oot\legacy_vista_xp___\0000 devicedesc
  • HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\r oot\legacy_vista_xp___\0000 legacy
  • HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\r oot\legacy_vista_xp___\0000 service
  • HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\r oot\legacy_vista_xp___\0000\control *newlycreated*
  • HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\r oot\legacy_vista_xp___\0000\control activeservice
  • HKEY_LOCAL_MACHINE\system\currentcontrolset\servic es\svkp
  • HKEY_LOCAL_MACHINE\system\currentcontrolset\servic es\svkp displayname
  • HKEY_LOCAL_MACHINE\system\currentcontrolset\servic es\svkp errorcontrol
  • HKEY_LOCAL_MACHINE\system\currentcontrolset\servic es\svkp imagepath
  • HKEY_LOCAL_MACHINE\system\currentcontrolset\servic es\svkp start
  • HKEY_LOCAL_MACHINE\system\currentcontrolset\servic es\svkp type
  • HKEY_LOCAL_MACHINE\system\currentcontrolset\servic es\svkp\enum 0
  • HKEY_LOCAL_MACHINE\system\currentcontrolset\servic es\svkp\enum count
  • HKEY_LOCAL_MACHINE\system\currentcontrolset\servic es\svkp\enum nextinstance
  • HKEY_LOCAL_MACHINE\system\currentcontrolset\servic es\svkp\security security
topcreator is online now   Reply With Quote
Old 30-06-2007, 19:47   #19
cf.member
 
Ken W's Avatar
 
Join Date: Jul 2004
Location: Winnersh UK
Services: NTL 4M + phone
Posts: 84
Ken W is an unknown quantity at this point
Re: Pigeon PP spyware problem

Quote:
Originally Posted by casius2378 View Post
I to have the same problem, I have tried deleting Pigeon PP with out success. I would be gratefull of any solutions.

Does any body know if Pigeon PP is sending information from the PC:
I have be able to delete it useing CA Antispyware 2007, they are doing a offer of three codes so it can be used on three differnet PCs for £19.98 + TAX, I beleive the offer ends 30/06/2007 so there is just time to get it if you want it.

Ken W
Ken W is offline   Reply With Quote
Old 01-07-2007, 18:58   #20
cf.member
 
Join Date: Apr 2006
Posts: 1
nacster is an unknown quantity at this point
Re: Pigeon PP spyware problem

This is not spyware as reported by pcguard ntlguard etc
it IS a backdoor trojan so spyware wont remove it
try avg antivirus or other free virus removers etc also do scan as always
hope this helps guys/gals
nacster is offline   Reply With Quote
Old 03-07-2007, 09:32   #21
hes
cf.member
 
Join Date: Jul 2007
Posts: 4
hes is an unknown quantity at this point
Re: Pigeon PP spyware problem

I have also been having the pigeon pp problem for a couple of weeks now. I have virgin media and the pc guard. I have been searching for a solution and have had no luck phoning virgin (they didn't know what i was talking about). I am reluctant to ring them again (25p pm). I have downloaded adware and run it is safe mode but nothing. Did anyone find a solution thats easy to do? I'm not very computer literate!
hes is offline   Reply With Quote
Old 03-07-2007, 11:07   #22
cf.mega poster
 
ntluser's Avatar
 
Join Date: Jun 2003
Location: Manchester
Age: 60
Services: Virgin Media XL Telephone,XL TV & 20Mb Broadband via £85 VIP Package, Sky TV, IDTV Freeview
Posts: 1,274
ntluser has a reputation beyond reputentluser has a reputation beyond reputentluser has a reputation beyond reputentluser has a reputation beyond reputentluser has a reputation beyond reputentluser has a reputation beyond reputentluser has a reputation beyond reputentluser has a reputation beyond reputentluser has a reputation beyond reputentluser has a reputation beyond reputentluser has a reputation beyond reputentluser has a reputation beyond reputentluser has a reputation beyond repute
Smile Re: Pigeon PP spyware problem

Some viruses are crafty and link themselves to "system restore" so that they are impossible to remove.

You could try disabling system restore.Then boot your PC in safe mode and run your antivirus and antispyware so that without the protection of system restore the virus can be identified and deleted.

If that works, remember to re-enable system restore.

Hope this helps.
ntluser is offline   Reply With Quote
Old 04-07-2007, 13:27   #23
hes
cf.member
 
Join Date: Jul 2007
Posts: 4
hes is an unknown quantity at this point
Re: Pigeon PP spyware problem

Thanks for the reply to my problem. I tried what you said but I couldn't run pc guard with system restore switched off. Any other ideas?
hes is offline   Reply With Quote
Old 04-07-2007, 15:14   #24
cf.member
 
Join Date: Mar 2007
Services: Virgin media 10 MB Virgin Media Full TV package
Posts: 78
Chris Davo is an unknown quantity at this point
Re: Pigeon PP spyware problem

Use a different anti virus package such as avast or avg (both free to download.)
Chris Davo is offline   Reply With Quote
Old 04-07-2007, 15:32   #25
cf.mega poster
 
ntluser's Avatar
 
Join Date: Jun 2003
Location: Manchester
Age: 60
Services: Virgin Media XL Telephone,XL TV & 20Mb Broadband via £85 VIP Package, Sky TV, IDTV Freeview
Posts: 1,274
ntluser has a reputation beyond reputentluser has a reputation beyond reputentluser has a reputation beyond reputentluser has a reputation beyond reputentluser has a reputation beyond reputentluser has a reputation beyond reputentluser has a reputation beyond reputentluser has a reputation beyond reputentluser has a reputation beyond reputentluser has a reputation beyond reputentluser has a reputation beyond reputentluser has a reputation beyond reputentluser has a reputation beyond repute
Smile Re: Pigeon PP spyware problem

Run your antivirus while your PC is in safe mode as that should make the virus easier to remove.
ntluser is offline   Reply With Quote
Old 04-07-2007, 15:44   #26
waddi
 
Join Date: Jul 2007
Posts: 1
raywj@blueyonder is an unknown quantity at this point
Re: Pigeon PP spyware problem

Ad-aware SE doesn't remove it. Pest Patrol finds it but, like most free scans, wants you to "Subscribe Now" to remove it. I appreciate the full instructions for removing it the hard way somebody posted, but it it cannot be deleted from the Registry.

Does it afflict users of Virgin Media broadband only? If so, why doesn't Virgin Media do something about it? After more than a week, PC Guard can't remove it and its Spyware Centre has "No information". Whoever runs the Spyware Centre could try reading this forum, as a start. Then perhaps try finding an answer. Is this, like the premium rate helpline, another consequence of Telewest becoming Virgin Media?
raywj@blueyonder is offline   Reply With Quote
Old 04-07-2007, 16:37   #27
cf.mega poster
 
ntluser's Avatar
 
Join Date: Jun 2003
Location: Manchester
Age: 60
Services: Virgin Media XL Telephone,XL TV & 20Mb Broadband via £85 VIP Package, Sky TV, IDTV Freeview
Posts: 1,274
ntluser has a reputation beyond reputentluser has a reputation beyond reputentluser has a reputation beyond reputentluser has a reputation beyond reputentluser has a reputation beyond reputentluser has a reputation beyond reputentluser has a reputation beyond reputentluser has a reputation beyond reputentluser has a reputation beyond reputentluser has a reputation beyond reputentluser has a reputation beyond reputentluser has a reputation beyond reputentluser has a reputation beyond repute
Smile Re: Pigeon PP spyware problem

Have you tried Spybot?
ntluser is offline   Reply With Quote
Old 05-07-2007, 11:01   #28
cf.member
 
Join Date: Mar 2007
Services: Virgin media 10 MB Virgin Media Full TV package
Posts: 78
Chris Davo is an unknown quantity at this point
Re: Pigeon PP spyware problem

So far i have only came across people with virgin media pc guard or the old netguard who have this problem which seems really odd.
Chris Davo is offline   Reply With Quote
Old 05-07-2007, 12:49   #29
hes
cf.member
 
Join Date: Jul 2007
Posts: 4
hes is an unknown quantity at this point
Re: Pigeon PP spyware problem

I am not paying 25p pm to phone them they should pay us for the inconvienience. I have emailed them about it once, but, suprise suprise, no reply. I am going to email them again now. Will let you know and will download the free anti virus and try that.
hes is offline   Reply With Quote
Old 06-07-2007, 04:08   #30
Data
Guest
 
Location: North manchester
Posts: n/a
Re: Pigeon PP spyware problem

If you delete svchost, you loose all connectivity.

I wouldn't use these free apps from VM. They don't support them. They are poor, and VM's advice:
Quote:
To get the best performance from PCguard, we strongly recommend you remove your existing software and use PCguard as your single, comprehensive security service.
Uninstall my firewall for it? No chance.

PC guard is freeware. Current downloadable version is 1.03. That was in 2003. What version do you people have, and does anyone get definition updates?
Software homepage is none existant.

Last edited by Data; 06-07-2007 at 04:28.
  Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off


All times are GMT +1. The time now is 19:13.


Links
Google
 
Web www.cableforum.co.uk


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.1.0
Copyright © 2003 - 2008, Cable Forum.
(s204569790.onlinehome.info)