Notices
Computer & Technology Related Post here for help and discussion of computing and related technology. Internet, TVs, phones, consoles, computers, tablets and any other gadgets.

Adware/Malware - Spybot S& D + Adaware won't fix!!

Thread Tools
 
Search this Thread
 
Old Jun 23, 2004 | 11:00 PM
  #1  
ALi-B's Avatar
ALi-B
Thread Starter
Moderator
20 Year Member
Liked
iTrader: (1)
 
Joined: Apr 2002
Posts: 38,078
Likes: 310
From: The hell where youth and laughter go
Unhappy Adware/Malware - Spybot S& D + Adaware won't fix!!

I've got a system at work that's been infected somehow with some adware/malware, hijacking the homepage to "homesearch", give "get rid of pop ups" pops ups. And everytime a serach engine is used (such as google) another popup appears withanother search engine searching for the same item.

Adaware and Spybot, lastest versions, fully updated can't find anything

Looks like I'll have to resort to sifting through the registry to find the culprits.

But to save me some time, does anyone have an idea of what particular infection is called and how to get rid of it?

Or anyone know of any good websites that can give me help to track down the malware installed and how to clean everything up?
Reply
Old Jun 23, 2004 | 11:28 PM
  #2  
DanTheMan's Avatar
DanTheMan
Scooby Regular
 
Joined: May 1999
Posts: 1,491
Likes: 1
From: Woking, Surrey
Default

Ive got exactly the same problem and tried exactly the same things someone must have an answer
Reply
Old Jun 24, 2004 | 11:10 AM
  #3  
suba's Avatar
suba
Scooby Regular
 
Joined: Mar 2000
Posts: 2,462
Likes: 0
Default

i had this prolem before with SpotON. did a search on the web on how to remove it and managed to remove it.
Reply
Old Jun 24, 2004 | 11:15 AM
  #4  
zhastaph's Avatar
zhastaph
Scooby Regular
 
Joined: Sep 2003
Posts: 2,720
Likes: 0
From: Isle of Wight
Talking

Ali, I've been having almost the same problems, but a different search engine I think. And neither SpyBot nor AdAware gathering them up

The really annoying thing is, I've found apps running in the process list (burnsignpeak seems to be one I remember) and when you hack their settings out of the registry the w@nking pile of ******* ****e puts it back again, so it needs to be 'End tasked' first.

I'm sure you're aware of where to look, but just in case, good places to look are;

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
HKLM\Software\Microsoft\Internet Explorer\Explorer Bars
HKLM\Software\Microsoft\Internet Explorer\Search
HKLM\Software\Microsoft\Internet Explorer\Toolbar
HKLM\Software\Microsoft\Internet Explorer\Extensions




I am VERY seriously considering writing a script or an applet that constantly spams their pile of sh1te search engines with the phrase "If we wanted our computers infected with your ******* **** we would buy a cd with it on, now go, **** off and die", then putting a link to said script/applet on many BBS and get as many people as I can to click on it and leave it running. I don't know how long you'd have to cripple their search engines to put them out of business, but it's gotta be worth a go
Reply
Old Jun 24, 2004 | 11:31 AM
  #5  
InvisibleMan's Avatar
InvisibleMan
Scooby Regular
 
Joined: May 2001
Posts: 12,583
Likes: 0
From: .
Default

ive noticed the new version of AV software have builtin spyware removers in it which have deleted stuff that neither adaware or spybot even detects
Reply
Old Jun 24, 2004 | 11:34 AM
  #6  
kernel's Avatar
kernel
Scooby Regular
 
Joined: Feb 2001
Posts: 627
Likes: 0
Default

Had a similar problem, found that cwshredder did the job

Do a google for it.
Reply
Old Jun 24, 2004 | 01:40 PM
  #7  
Mick's Avatar
Mick
Scooby Senior
iTrader: (1)
 
Joined: Nov 1998
Posts: 2,656
Likes: 4
Default

Yup... cwshredder has got rid of some intensely annoying ones for me!


Mick
Reply
Old Jun 24, 2004 | 03:12 PM
  #8  
InvisibleMan's Avatar
InvisibleMan
Scooby Regular
 
Joined: May 2001
Posts: 12,583
Likes: 0
From: .
Default

got a laptop with the same, av found but cant delete, also tried going thru reg, no luck so far

troj_agent.z2
troj_winshow.ab
Reply
Old Jun 24, 2004 | 03:55 PM
  #9  
mj's Avatar
mj
Scooby Regular
 
Joined: Apr 2002
Posts: 6,129
Likes: 0
From: The poliotical wing of Chip Sengravy.
Default

try:

http://www.webroot.com/wb/products/spysweeper/index.php

this picked stuff on mine that Adaware and S&D missed.
Reply
Old Jun 24, 2004 | 04:12 PM
  #10  
Mick's Avatar
Mick
Scooby Senior
iTrader: (1)
 
Joined: Nov 1998
Posts: 2,656
Likes: 4
Thumbs up

mj - giving webroot spy sweeper a go - seems very thorough...

Says it found a 'remote key logger' - a bit worrying

Cheers

Mick
Reply
Old Jun 24, 2004 | 04:29 PM
  #11  
Peanuts's Avatar
Peanuts
Scooby Regular
iTrader: (15)
 
Joined: Jul 2001
Posts: 8,606
Likes: 0
From: Portsmouth
Default

try a search on hijackthis
its freeware and then you can post a copy of your log onto:
www.wilderssecurity.com
go to the spyware forum and then the hijackthis log posting section.
be prepared for a days wait as the spyware gang are in usa (time zone differences).

Andy
Reply
Old Jun 24, 2004 | 04:44 PM
  #12  
InvisibleMan's Avatar
InvisibleMan
Scooby Regular
 
Joined: May 2001
Posts: 12,583
Likes: 0
From: .
Default

these ones are evil fvckers nothing seems to get rid of them. trawling thru the reg & its fiddly numbers is giving me a major headache
Reply
Old Jun 24, 2004 | 10:59 PM
  #13  
ALi-B's Avatar
ALi-B
Thread Starter
Moderator
20 Year Member
Liked
iTrader: (1)
 
Joined: Apr 2002
Posts: 38,078
Likes: 310
From: The hell where youth and laughter go
Default

Cheers guys, I've been out all day so I've yet to get round and look at it. But the pointers will defintely save alot of time.

I wonder if you ever caught the author of the adbots/malware you could sue them for lost hours in trying to remove them?
Reply
Old Jun 25, 2004 | 10:39 AM
  #14  
InvisibleMan's Avatar
InvisibleMan
Scooby Regular
 
Joined: May 2001
Posts: 12,583
Likes: 0
From: .
Default

yeah wasted hours yesterday. Didnt get anywhere. I deleted the buggers went thru the reg, found the bastid website it came from & uninstalled the popups. go back into ie & theyre back. All settings are on high fvck-off bastid level... everything works ok i think it must have deleted something
Reply
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
Mattybr5@MB Developments
Full Cars Breaking For Spares
12
Nov 18, 2015 07:03 AM
XRS
Computer & Technology Related
18
Oct 16, 2015 01:38 PM
JackClark
Computer & Technology Related
3
Sep 30, 2015 08:29 PM
fat-thomas
Subaru Parts
1
Sep 30, 2015 06:03 PM
shorty87
Wheels And Tyres For Sale
0
Sep 29, 2015 02:18 PM




All times are GMT +1. The time now is 09:12 AM.