Forum Moderators: open

Message Too Old, No Replies

Spyware Dilemma

Spyware Dilemma

         

Fess Blackthron

1:15 am on Dec 30, 2003 (gmt 0)



Hello,

I suspect something is going on with my system. I upgraded to XPpro last month and everything was quite impressive. Yesterday all a sudden I'm on the internet an I'm getting all kind of wired pop-up of porn and dating services etc. They are not relative to the sites I'm on.

Its pretty obvious that I have some kind of ad spyware crap on my system. God knows how that thing got into my system.....

All the popups are from <snip>. I went to <snip> and tried the "uninstall popup" option but it didn't do the job and I'm really getting pissed because it slows down my system an my ability to work...

I tried to download Ad-ware and run it. It found suspect files and I removed them. But I'm still getting the pop-ups and my system is still noticeably slow.

How do I remove this menace <snip> garbage from my system

If anyone has any prior experience, please advise. Any help is greatly appreciated

Regards
Fess

[edited by: lawman at 1:26 am (utc) on Dec. 30, 2003]
[edit reason] deleted url [/edit]

lawman

1:23 am on Dec 30, 2003 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



[itc.virginia.edu...]

... and welcome to Webmaster World. Familiarize your self with our TOS (link at bottom of page) and the Foo Charter (link at the top of the page). :)

lawman

snowman

2:17 am on Dec 30, 2003 (gmt 0)

10+ Year Member



How do I remove this menace <snip> garbage from my system

1)Boot from a real DOS 6.x floppy

2)When screen finally shows "A:\" type the following: "Format C:\ /U"

3)When this is done, do any one of the following two things:

3.1)Install your favorite distribution of Linux

3.2)Buy a Mac - even a used one.

;)

TryAgain

7:08 am on Dec 30, 2003 (gmt 0)

10+ Year Member



Spybot Search & Destroy will find stuff after Ad-Aware went through your system, so do both at least.

Fess Blackthron

3:34 pm on Dec 30, 2003 (gmt 0)



Hello everyone,

Your advice is appreciated.

I've tried the Spybot program and it found suspect files after I had run Ad-ware. As of this morning I've yet to see an annoying pop-up. But my system is still noticeably slow. I wonder if this nonsense has been totally eliminated....

In regards to the TOS, I'll give it a thorough review tonight.

Thanks Again
Fess

lawman

3:50 pm on Dec 30, 2003 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



In regards to the TOS, I'll give it a thorough review tonight.

Pop quiz in the morning. ;)

lawman

hannamyluv

3:54 pm on Dec 30, 2003 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



some spyware and adware programs are nefarious in that they attach themselves to certain essential files on your computer so that when the spy/adware is removed, those files are removed as well. You may have this situation, if your computer is still not working properly.

Fess Blackthron

4:47 pm on Dec 30, 2003 (gmt 0)



Hello,

Please excuse my post if it conflicts with TOS.

My problem now.......

I don't see any popups which is good.

But when I go to google to do a search, I'll type in <Widget Company> and hit enter, google would do the search and then a new window opens with some other search engine:

http://search-nonwidgetcompany.com/

I typed in "nonwidgetcompany.com pop up" and got this from google:

http://www.entirelydifferentcompany.com/
Perplexing situation....it seems impossible to get ride of this intrusive program(s)....

Has anyone ever heard of CWShredder?

Regards
Fess

[edited by: lawman at 5:37 pm (utc) on Dec. 30, 2003]
[edit reason] no urls please [/edit]

Reflect

5:08 pm on Dec 30, 2003 (gmt 0)

10+ Year Member



Run a virus scan.

There are several virii out there that do what you describe. First one that comes to mind is Download.Trojan. Most calls to it will reside in the run key in your registry.

Brian

Rugles

10:56 pm on Dec 30, 2003 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



Sometimes it gets to the point were you may just want to format and start again.
I mean.... how much time has it cost you already?

Some of this scumware out there is ruthless.

AAnnAArchy

11:20 pm on Dec 30, 2003 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



Check your hosts file. There's a lengthy thread about in the Google News forum somewhere. Try reading this thread to see if it'll help - [webmasterworld.com...]

hannamyluv

2:37 am on Dec 31, 2003 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



Sometimes it gets to the point were you may just want to format and start again.

I ended up doing that the lasttime I got a bad scumware infestation. My brother installed a program on my computer to "speed up my connection". He didn't know better and he thought he was doing me a favor. Turned out to be a nasty scumware. Uninstalling it disabled my ability to connect to the internet and after a few days frustration I reformatted the hard drive and reinstalled everything.

There should be a law against this sort of program.

Fess Blackthron

3:02 pm on Dec 31, 2003 (gmt 0)



Hello,

Reflect:
I have run my virus scan and found nothing. You are correct when suggesting this scumware is buried in my registry.

Rugles:
Christ, I just clean installed from 98 to xppro. It was a hellish experience because of all the backing up and other things I had to do to get back on track. I dont' want to do it again. I'd like to find a solutoion, becasue when it happens again I dont' want to have to reinstall eveytime.

AAnnAArchy:
great resource, its very relative to my problem. I ended up downloading CWShredder and it removed somemore stuff. But when I checked my registry, i found winshow*, winlink* etc. stuff. I'm going to have to delete this stuff manually. I very afraid of the registry, don't want to destroy my OS.

Regards
Fess

Reflect

4:31 pm on Dec 31, 2003 (gmt 0)

10+ Year Member



If you believe it is in your regeistry take a walk down to:

HKEY_LOCAL_MACHINE>SOFTWARE>MICROSOFT>WINDOWS>CURRENT VERSION>RUN

This is the spot that it will reside in. If you like export your registry and sticky me with it. I will look at the flat file and hopefully can identify any usual suspects.

Brian

PatrickDeese

6:02 pm on Dec 31, 2003 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



Hey Fess -

Have you tried doing a "system restore", just point the calendar to a day prior to the bug installed itself.

And in the future don't install anything, a n y t h i n g, anything unless you are completely confident of the source of the program.

Fess Blackthron

3:48 pm on Jan 1, 2004 (gmt 0)



Brian, I'll have a careful look into the registy path you mentioned. What I did was download a program called HighjackThis. Ran it, and saved the results to a log file. And gave it to someone who's pro with registry issues. Should be able to tell me what to delete.

PatrickDeese, I tired the system restore at the very beginning of my problem. I seemed to work and then the scumware came back full force. Go figure...

Regards
Fess