Clusterheadaches.com Message Board (http://www.clusterheadaches.com/cgi-bin/yabb/YaBB.cgi)
New Message Board Archives >> 2004 Posts >> adware/spyware question
(Message started by: UN_SOLVED on Apr 22nd, 2004, 2:11am)

Title: adware/spyware question
Post by UN_SOLVED on Apr 22nd, 2004, 2:11am
Everytime I log onto my comp now, the homepage is changed and so is my search engine. Norton's 2004 finds no virus. Spybot - Search & Destroy freezes about half way through scanning. ( I just un-installed that pos).

I need some recommendations on how to fix this problem. plz help. frustrated

thanks
Unsolved

Title: Re: adware/spyware question
Post by fubar on Apr 22nd, 2004, 3:09am
You have been hijacked.  It may be very difficult to remove this from your system, but the following programs are useful:

Cool Web Shredder (http://www.majorgeeks.com/download4086.html)
A small utility for removing CoolWebSearch (aka CoolWwwSearch, YouFindAll, White-Pages.ws and a dozen other names). Spybot S&D tends to forget essential parts of the hijack, so until it updates, you can just this to completely remove the hijack. Updated to remove the new variants once they come out.

More information on the CWS hijacker, including recent variants of it, can be found here (http://www.spywareinfo.com/~merijn/cwschronicles.html).

Note: CoolWWWSearch.SmartKiller (v1 and v2) is a newer, real ugly variant of CoolWWWSearch. When running, it will close every browser window you use to visit a large list of anti-spyware-sites, and even will close Spybot-S&D and some other anti-spyware applications as well. Download

CoolWWWSearch.SmartKiller (v1/v2) MiniRemoval (http://www.majorgeeks.com/download4113.html) which can disable this latest version.


Trojan Hunter (http://www.misec.net/)
Reviewed by ComputerCops here (http://www.computercops.biz/article3108.html)

Adaware (http://www.lavasoftusa.com/software/adaware/)
Excellent for spyware, but not as good at removing your trojan.  Definitely useful.

Just like SpyBot Search & Destroy (http://www.majorgeeks.com/download2471.html) which is incredibly useful, but which probably won't solve this particular problem.

Get ALL of those, and make sure youre running a personal firewall like ZoneAlarm (http://www.zonelabs.com/store/content/company/products/znalm/freeDownload.jsp), or even a full-featured security solution like Norton Internet Security 2004 (http://www.symantecstore.com/dr/sat1/ec_MAIN.Entry10?V1=584414&PN=1&SP=10023&xid=27674&DSP=&CUR=840&PGRP=0&CACHE_ID=74456)

In particularly bad infestations that refuse to go away, try Bazooka (http://www.kephyr.com/spywarescanner/).  It will walk you through some manual steps that are critical in some cases.

Good luck.

Title: Re: adware/spyware question
Post by Root on Apr 22nd, 2004, 3:24am
Your browser has been hijacked.
A little more info is needed IE:

Which OS is it?
Which browser is it?
Have you changed your home page back and it still does this?
Have you run an up to date registry cleaner?
Have you checked your Win.ini file?


Those will do to start.

There will be others.



Title: Re: adware/spyware question
Post by UN_SOLVED on Apr 22nd, 2004, 3:32am
Root

(1) XP Home
(2) IE 6.0
(3) Yes, I change my homepage back. It doesn't change it until I log off and log back on. (same thing happens with the search engine)... (I'm running 2 accounts on this comp)
(4) No
(5) No

Unsolved

Title: Re: adware/spyware question
Post by Root on Apr 22nd, 2004, 10:55am
OK here goes.

1. Get a decent registrz cleaner. MS used to have one free to download but there are others. You can find some over  at cnet.com in thier  download section. Try to get one that also looks at your  shared objects files. Which is the .DLLs in MS, For everzone else it is the .so files.

2. Onlz accept cookies from a site zou trust.

3. Use Wordpad or Notepad to edit zour Win.ini file and zour  screensaver file.

3. Get a browser written in the 21st centurz. Take zour pick.

4. Too save zour poor  suffering MS user  self from as manz future problems as possible RTFM.

5. DO NOT install Linux or BSD. YouÖre not worthz [smiley=smartass2.gif]

[smiley=smokin.gif]

Title: Re: adware/spyware question
Post by UN_SOLVED on Apr 22nd, 2004, 11:12am
Thanx ayelot. Ur aye reel HOOT ROOT  [smiley=laugh.gif]

Unsolved

Title: Re: adware/spyware question
Post by Root on Apr 22nd, 2004, 11:20am
I need an English kezboard, but I  try.

[smiley=smokin.gif]

Title: Re: adware/spyware question
Post by john123 on Apr 22nd, 2004, 1:10pm
Are you chinese Root?  Just curious how common ch's are in China, you may be the first i have heard of.

Title: Re: adware/spyware question
Post by miapet on Apr 22nd, 2004, 1:16pm
Unsolved, 2 things . . .
I'm sorry to hear this happened to your puter . . .it recently  happened to our desktop too, so I'm glad to have this information!
AND . .how are you?  I hope things are going much better for you.
*positive light and energy*
miapet

Title: Re: adware/spyware question
Post by cootie on Apr 22nd, 2004, 2:22pm
Question to all you clusterbuddy knowledgeable computer geek types......what is the outcome of all this 'take over hyjack crash spoof trogen worm hack' CRAP in the long run ? Are us simple minded pooter piss ants dome'd.....how do we keep our 'stuff' safe !? This is gettin deep with all this goin on........how cqan I keep up and half of it I don't understand anymore.....wonder what the outcome or outlook is on simple home computers......will the internet survive ?? Or is it gonna wipe out all us casual computer buffs cuz we won't be able to keep up or prevent a big crash or the BIG virus. I've killed 3 pooters already and not sure # 4 is in my budget. Curoius coot Pam

It's gettin a lill scarey in the woods........................

Title: Re: adware/spyware question
Post by UN_SOLVED on Apr 22nd, 2004, 5:41pm
First of all, the computer is fixed. I used the "Advanced System Optimizer". Did alot of cleaning and tweaking. My comp is a little faster now too. Fixed a 'Loader.exe' virus also that would load Windows Media Player upon startup. Got rid of one trojan found in an old program called "Corrosion". Finally switched browsers to a new one (I think) called "Avant Browser". (Still checking it out, so far so good).
As far as the HA's are concerned, life is HELL ! I've used an ungodly amount of Imitrex since last Thursday night. HA's have been at the top of the scale. I used 16 injections from Thursday midnight til Saturday at noon. Went to the ER Saturday, they wouldn't give me steriods only Stadol. Had a one day break. HA's returned in full force. Used another dozen or more injections and went back to a different ER Tuesday where they gave me Droperidol, Benedryl, and Decadron. Now I'm doing a Decadron DosePak. HA's are gone but my stomache is killing me. (What a trade)

Living in hell :(

Unsolved

Title: Re: adware/spyware question
Post by Luke63 on Apr 22nd, 2004, 6:33pm
Un....What the hell are we gonna do with you buddy?  Huh?

Title: Re: adware/spyware question
Post by jonny on Apr 22nd, 2004, 6:39pm

on 04/22/04 at 18:33:12, Luke63 wrote:
Un....What the hell are we gonna do with you buddy?  Huh?


Lets pants him just for shits and giggles ;;D

....................................jonny

Title: Re: adware/spyware question
Post by cootie on Apr 22nd, 2004, 7:44pm
Brad'll tab him if ya want him too.....he's purdy good at it. This tab's for you Pam

Title: Re: adware/spyware question
Post by jonny on Apr 22nd, 2004, 8:02pm

on 04/22/04 at 19:44:42, cootie wrote:
Brad'll tab him if ya want him too.....he's purdy good at it. This tab's for you Pam


No Pam......"Adaware" does not mean "Add some tabs"......Bwaaaah

........................................jonny ;;D

Title: Re: adware/spyware question
Post by Redd715 on Apr 22nd, 2004, 8:06pm
You know...I finaly read this post...and darn it if I don't have the same thing going on.  My home page all of a sudden will flip to either some mass porn sales site or other mass marketing site... If I reset a few times back under options it will stick...but then bam after a frew new open browser window...I get the porn crap again.  

I second cooties question...how do we non puter techies protect ourselves from all this crud...and could this have anything to do with me shareing the wireless net connection with my neighbors?

Title: Re: adware/spyware question
Post by jonny on Apr 22nd, 2004, 8:14pm

on 04/22/04 at 20:06:16, Redd715 wrote:
...and could this have anything to do with me shareing the wireless net connection with my neighbors?


You Share your connection with other people outside your house?......Your nuts!!!!!

I guess if you dont mind those people seeing everywhere you go on the net its cool.....Not me!

Im scanning something now and will post it soon, it very well may help.

...............................jonny

Edit:.......Redd, you got mail ;;D

Title: Re: adware/spyware question
Post by Redd715 on Apr 22nd, 2004, 9:16pm
The wireless set up here is for all ten appartments to be connected to the same server by individual routers.  The cost is included in our rents...I take it thats not a good thing?  

Title: Re: adware/spyware question
Post by Redd715 on Apr 22nd, 2004, 9:18pm

on 04/22/04 at 20:14:45, jonny wrote:
Edit:.......Redd, you got mail ;;D


I got what?  I don't got no freeking mail. :P

Title: Re: adware/spyware question
Post by jonny on Apr 22nd, 2004, 9:26pm
f_pegg@hotmail.com

That your e-mail?

If so thats where I sent it

Title: Re: adware/spyware question
Post by Redd715 on Apr 22nd, 2004, 9:27pm
I didn't get it....

hmmmmmmm


try it again

Title: Re: adware/spyware question
Post by jonny on Apr 22nd, 2004, 9:32pm
Man, I have to get up in five hours for a twelve hour day but here i am sending again.

Somebody tell "Hold" to stick it WAY up his ass!!!!

.............................Unholy

Title: Re: adware/spyware question
Post by Redd715 on Apr 22nd, 2004, 9:34pm
it CAN wait till tomorrow dear....sheesh....

still nothing and I've refreshed hotmail thrice...this is either an awful big file...or some hacker asses are pulling my non tech wise leg.

Title: Re: adware/spyware question
Post by cootie on Apr 22nd, 2004, 11:05pm
Redd.....maybe ona yer neighbors got it.......blah---ha-ha-ha.....is that kinda like a network deal you have goin on ? My freinds set up there house computers as a network and got a nasty ass virus. Don't ask me......I still am tryin to understand all this garble. Pam with alot of computer illiteracy

Title: Re: adware/spyware question
Post by Opus on Apr 23rd, 2004, 12:12am

on 04/22/04 at 14:22:23, cootie wrote:
what is the outcome of all this 'take over hyjack crash spoof trogen worm hack' CRAP in the long run ? Are us simple minded pooter piss ants dome'd.....how do we keep our 'stuff' safe !? This is gettin deep with all this goin on........how cqan I keep up and half of it I don't understand anymore.....wonder what the outcome or outlook is on simple home computers......will the internet survive ?? Or is it gonna wipe out all us casual computer buffs cuz we won't be able to keep up or prevent a big crash or the BIG virus.


Pam, eventually someone may come out with some malware ( virus, worm ) that will just wipe out all windows computers. They pick on windows because almost everyone runs it. The best defense in to keep up with patches, use a firewall, don't use browsers or email clients that are known for problems, use anti virus ( this may not help because until the virus is known it can't be caught, my mother got blaster 1 day before it was discovered) and never!, never! open an attachment that you are not expecting. Also don't run in administrator mode, or as root, especially when on the web.

To stop spyware, hijackers, you can block bad sites using spybot, and don't use a browser that lets sites automatically download and run programs.


on 04/22/04 at 14:22:23, cootie wrote:
I've killed 3 pooters already and not sure # 4 is in my budget. Curoius coot Pam


I don't see how malware can break hardware, unless it wipes out your BIOS. Most bad hard drives I have seen can be fixed simply by writing them to zero's to remove  the offending software.

Some day it may get to the point where you will need to change OS's to keep ahead of the attacks. Even Linux can get viruses, especially if the users click on attachments and run in root. Using a networked computer will always be risky, but you can reduce your risks greatly with smart actions.

Opus/Paul

Title: Re: adware/spyware question
Post by Mark C on Apr 23rd, 2004, 8:21pm
I did manage to get a browser hijacker previously undiscovered last year...made me special for a day. Adware and Spyware are a little different in nature than a browser hijacker, which changes you homepage to whatever and then changes it back after you correct it. It's a registry run entry, easily removed, if you know how. One of my favorite tech boards is Spyware Info (http://www.spywareinfo.com/) which has some really good knowlegable, helpful folks. Download Hijack This (http://209.133.47.200/~merijn/files/HijackThis.exe) and post the log (http://www.spywareinfo.com/forums/index.php?showforum=30) to have one of the gurus suggest the fix. Wait for their reply BEFORE killing items on the list. Another good one is StartupList (http://www.spywareinfo.com/~merijn/files/StartupList.exe) which reports all programs running on startup. Better than MSCONFIG.

Unfortunatly this is a ever growing problem and I doubt it will ebb anytime soon. If you are like me and PC security is a hobby and/or job it is a little easier. The average Joe is the one screwed....as usual.

In over two years on-line (at home) I have only had the one hijacker get me, not bad for Windows...oh yeah...only two BSOD (http://whatis.techtarget.com/definition/0,289893,sid9_gci214376,00.html) too!!

Mark's Security Links....

http://www.drfeller.com/Mark/textclickhere.gif (http://www.securityfocus.com/)

http://www.drfeller.com/Mark/textclickhere.gif (http://sysinfo.org/bhoinfo.php)

http://www.drfeller.com/Mark/textclickhere.gif (http://www.cert.org/)

http://www.drfeller.com/Mark/textclickhere.gif (http://grc.com/intro.htm)

http://www.drfeller.com/Mark/textclickhere.gif (http://www.markusjansson.net/erecent.html)

http://www.drfeller.com/Mark/textclickhere.gif (http://www.net-integration.net/index.html)

http://www.drfeller.com/Mark/textclickhere.gif (http://www.symantec.com/avcenter/)

http://www.drfeller.com/Mark/textclickhere.gif (http://secunia.com/)

http://www.drfeller.com/Mark/textclickhere.gif (http://www.eeye.com/html/)

http://www.drfeller.com/Mark/textclickhere.gif (http://www.securitynewsportal.com/index.shtml)




I have plenty more if needed!  ;;D

Title: Re: adware/spyware question
Post by UN_SOLVED on Apr 23rd, 2004, 11:22pm
CWS Shredder took care of my problems once and for all (I HOPE)

http://www.spywareinfo.com/~merijn/cwschronicles.html#cwshredder

Unsolved

Title: Re: adware/spyware question
Post by miapet on Apr 25th, 2004, 11:12pm
glad you fixed your puter *g*
sorry you're getting whacked *frowns*
we have you in our thoughts
*positive light and energy*
D and miapet



Clusterheadaches.com Message Board » Powered by YaBB 1 Gold - SP 1.3.1!
YaBB © 2000-2003. All Rights Reserved.