PDA

View Full Version : Spyware



anime050
Sat, 04-03-2004, 03:04 AM
I can't seem to get rid of the spyware on my computer I've tried several freeware such as ad-aware , regseeker, spybot. And some others. My problem is that these annoying uneeded favorites in my IE 6 browser keep popping in there everytime I restart. Its driving me nuts. I've been trying to remove it all day. Just wondering if any of you had experienced a problem like this.

complich8
Sat, 04-03-2004, 04:48 AM
I'd say .... make sure you're using the updated definition files for spybot and ad-aware -- the versions you can get normally ship with somewhat out of date definitions. uninstall any apps you don't need or don't recognize -- if you don't know what it is, google it. Some spyware I've seen floating around has bogus uninstallers it puts in your add/remove programs dialog, that just tell you to reboot or say they remove stuff but don't. Make sure that spybot's set to scan for everything, and do a custom scan with ad-aware set to scan everything it can (deep scanning registry, scanning within archives, etc).

also you can try setting up a personal firewall like zonealarm or sygate and seeing if strange things are trying to access the web. Make sure your virus scanner is up to date too, and try a full system scan.

If all that fails, or something unexpectedly dies, then I'd recommend the "final solution" -- http://www.mozilla.org i/expressions/face-icon-small-wink.gif

L8r
Sat, 04-03-2004, 05:17 AM
if you know the name of the spyware program you can go in the regedit and remove it that way...
BUT WATCH OUT SO YOU DONT REMOVE SOMETHING IMPORTANT ! ! ! !
did that once and all that i could do was "foramt c:" i/expressions/face-icon-small-wink.gif to fix it

Lego
Sat, 04-03-2004, 05:47 AM
http://www.safer-networking.org/ <-- spybot

http://www.lavasoftusa.com/ <-- ad aware

install both and run, really nice removal tools

Rek
Sat, 04-03-2004, 09:37 AM
Complich8 you are the man... I was gonna say the exact same thing... also, if you do wanna stay on MSIE (not recommended) get the google toolbar.


If you wanna see how Hardcore Mozilla is, click here (just an albino black sheep flash...REALLY COOL), and remember with mozilla it doesn't bounce.

DUB DUB (http://www.albinoblacksheep.com/flash/dubdub.php)

anime050
Sat, 04-03-2004, 12:19 PM
Heh. I got both of those. Updated and everything still didn;t work. Although I searched my registry with the url of the homepage that I was always redirected to. And I found some reg keys that were causing the problem. It also seems that some others were having the exact same problem that I had. I found this "CWShredder" to remove the spyware properly and effectively.

Thanks for your help though i/expressions/face-icon-small-wink.gif

sangai
Sat, 04-03-2004, 04:02 PM
and the simpliest solution to all problems is "REINSTALL" and to ensure that you don't lose data next time partition your hardrives to save information you don't want to lose.

i to am having this problem and have ran countless spyware removal programs and it is still no good .

so im going to reinstall and stop them for good.........

Mut
Sat, 04-03-2004, 04:06 PM
i think the best and easiest solution is: no more porn sites.

Gods_Son
Sat, 04-03-2004, 06:33 PM
yea, most guys get spyware from porn.

Lego
Sat, 04-03-2004, 06:37 PM
yeh, stuff like

FREE BOOBS HERE!

L8r
Sat, 04-03-2004, 08:27 PM
i never, NEVER porn surf i/expressions/rolleye.gif i/expressions/rolleye.gif i/expressions/face-icon-small-happy.gif
hehe...

you can get them from some sites that has cracks for program aswell.... hmm eh.... not like I do that but some friend told me YEA a friend told me about it i/expressions/rolleye.gif


i dont think they are buying it...
Shh..just keep quiet and no one will ever know
i/expressions/face-icon-small-wink.gif

Xollence
Sat, 04-03-2004, 08:51 PM
Use Mozilla, solves all your problems.

lasaire
Sun, 04-04-2004, 01:50 AM
What you need to do is run ad-aware and spybot frequently, not just once every couple of days. CWSShredder is also good, but only for that one specific problem.

I started off with ad-aware getting 200-500 hits of spyware, and actually had to run it, restart th program, then run it gain several times until I got the numbers down into the tens, and finally got a clean slate. After that I only need to run it once every two days, and only get 10 or so hits. So not bad. Just be careful.

L8r
Sun, 04-04-2004, 02:44 AM
200-500, really?
DAMN thats alot... i only got about 50 when i first installed ad-aware.

Lego
Sun, 04-04-2004, 03:44 AM
wow.. 200-500 is a lot man

Trip
Sun, 04-04-2004, 05:04 AM
firefox (mozilla) is the way forward, once you get used to it, you'll wounder why you didnt use it sooner (tabbed browsing, pop-up blocker etc...) IE is just plain nasty i/expressions/face-icon-small-happy.gif

complich8
Sun, 04-04-2004, 07:32 AM
I set up two new winxp machines for my users (nice machines too, p4 3.2 extreme editions, 2 gigs of dual channel ddr400, dual dell 1802fp lcd's, quadrofx 500 video cards) .... I set up my users as regular user types, and things were fine, but some apps don't play nice with "regular user" mode -- like icq, and 3dstudio max.

so to make icq happy for a couple of them I had to make them into power users. Didn't think too much of the consequences, but 3 days later I had to spend 4 hours removing software that installed itself from their spyware-ridden profiles, since they now had install access. Ad-Aware gave me 700 hits for one user's profile, and 300 each for two others, as well as 2 running processes and about 250 registry keys. I killed it all with that, then did the spybot-sd thing. Spybot found another 15 or so apps that had let themselves in through that stupid goddamned DSO hole -- once one gets in, it can bring others, which bring others, etc.

After I got all that cleaned up, my "final solution" went like this: every machine in my lab now has the spybot-sd registry "immunizations" for known bad activex control id's, every user is a power user but they're power users in name only -- they can't alter the programs directory, windows dir, or any of the other normal power user stuff. This means all they can mess up is their own user profile, which is good for me 'cause a screwed profile won't even upload to the server anyway, and if it does I can clean stuff up and let defaults replace things as necessary. My users are happy - they can use their goddamned icq. I'm happy - spyware can't stick itself in c:\windows without me specifically allowing it. My boss is happy, because it means I don't have to waste 4 hours per machine every couple weeks to clean the latest greatest scumware that installs itself when some user tries to find a flashmx 2k4 tutorial or something. Everybody's happy!

Eventually I'll get around to implementing firewall-side website logging, and then (since the firewall is also the local dns server) blackholing certain known bad domains (doubleclick, gator, valueclick, for starters). But I dunno if that's ultimately going to prove necessary, since my lab is kinda small (12 workstations now) and our users are for the most part reasonably competent (and don't have local admin -- heehee)

MemnochTheCaT
Mon, 04-05-2004, 02:50 AM
Lol, you said Final Solution! I approve the use of death camps for Spyware and their makers!!! YAY!

Tip, to make Ad-aware run faster, clear your temp internet files BEFORE running it.
Tip, go to http://www.mozilla.org and check it out, it's VERY nice .. and if it ever gets mangled, you can uninstall/reinstall totally clean .. something IE doesn't truly support
Tip, go to start>run> and type in MSCONFIG (Win98/ME/XP), and check the 'startup' tab, some things not classified as 'spyware' can still be bothersome and performance-robbing
Tip, for an excellent free popup-stopper for web browsing, go to http://toolbar.google.com and install the free basic google toolbar

Thats all for now i/expressions/face-icon-small-smile.gif

KakashiSensei
Tue, 04-06-2004, 11:11 AM
Originally posted by: MemnochTheCaT
Tip, for an excellent free popup-stopper for web browsing, go to http://toolbar.google.com and install the free basic google toolbar

Thats all for now i/expressions/face-icon-small-smile.gif

Tip that is use another form of spyware to block spyware. Dont use it.

Mut
Tue, 04-06-2004, 01:28 PM
google bar is fine for me.

tensai
Sun, 05-23-2004, 01:57 AM
do you guys know what these are, they appeared on my spybot SD, and i dont know if i should immunize them or not:
-wildtangent
-backweb lite
-turbodownload
-dso exploit
very troublesome to remove shit thats important to run the computer properly
im thinkin of reformating, but i need an external harddrive to save the stuff that i want

does anyone know what this problem is where this window tells you to send or dont send your error report to microsoft. it keeps doing that whenever i open or try to install a program
any help would be great

Terracosmo
Sun, 05-23-2004, 02:35 AM
Fuck explorer and get Firefox.

Assertn
Sun, 05-23-2004, 08:01 PM
im gettin some omegasearch BS that keeps comin up on my internet explorer...
even though i use mozilla most of the time, i still need ie sometimes for stuff like torrents

anyway ive found removal tools specifically for certain things....looks like i'll have to go through it again though.....stupid piece of crap

Legendary Nin
Sun, 05-23-2004, 09:22 PM
Originally posted by: tensai
do you guys know what these are, they appeared on my spybot SD, and i dont know if i should immunize them or not:
-wildtangent
-backweb lite
-turbodownload
-dso exploit
very troublesome to remove shit thats important to run the computer properly
im thinkin of reformating, but i need an external harddrive to save the stuff that i want

does anyone know what this problem is where this window tells you to send or dont send your error report to microsoft. it keeps doing that whenever i open or try to install a program
any help would be great

Remove them.

complich8
Mon, 05-24-2004, 03:28 AM
wildtangent is mostly harmless, and has some things that are ok about it (it's a rudimentary 3d engine and an sdk for it, but tbh it's kinda a crappy one compared to shockwave's 3d, which is primative compared to directx).

dso exploit is most harmful (it allows stuff that exploits it to get into your system without your knowledge or interaction, and once one title is on your system it can usher in others). Kill that.

other two sound pretty generic, and are also definitely candidates for removal.

Outtawack311
Wed, 05-26-2004, 01:15 AM
I use firefox now.

IF You want to get rid of spyware download hijackthis.exe go to www.cexx.org and head to their forums. Scan with hijackthis.exe save a log and copy the log in a post on the forum asking for help.

There is now spyware that ad-aware and spybot type programs CANNOT get rid of no matter when you use them or how (i.e. safemode). These types of spyware are browser hijack programs and spyware trojans. Some common examples are COOLWEBSEARCH ALLABOUTSEARCHING.COM , ZESTYFIND.COM SPOTRESULTS.COM AND C:\SEARCHPAGE. Plus xxxtoolbars can also do this.

Either go to the forum i mentioned or IM me at Outtawack311 on aim and I should be able to help you (I fixed 2 friends comps this past week). Good luck

tensai
Wed, 05-26-2004, 03:09 AM
thanks for all the help,
but my comp is still fucked.
ill try hijack this soon, i did dl it but i deleted it because i thought it wasnt that useful.

im still having this problem where i try to open/run something that ive just finished dl (software, etc...) and the computer has a error report that asks me if i want to send or not, wtf is this problem, i just cant figure it out
for example, just a couple minutes ago, i dled firefox and when i tried to run it, the computer just rejects opening it and the error/dont send thing pops up

thanks anyways

Legendary Nin
Wed, 05-26-2004, 07:44 PM
Ad-aware removes COOLWEBSEARCH and all of the redirect programs.

Mut
Wed, 05-26-2004, 09:56 PM
i heard about this new one that is even better than ad-aware. i think it's called SSP... i'm not sure what it stands for but i think it's like "STOP SEARCHING PORN". you might wanna try that.

tensai
Thu, 05-27-2004, 12:36 AM
hahaha, right, right
no more porno, just get porno from your friends now
back to the point
i dont really have spyware anymore (i think)
its just this thing that keeps causing an error when i try to install a new program or some shit (could be spyware, but after using a lot of programs that removes spyware, it just keeps happening)
the worst possibility to get my comp better is to reformat - and thats the last resort option