Notices
Computer & Technology Related Post here for help and discussion of computing and related technology. Internet, TVs, phones, consoles, computers, tablets and any other gadgets.

I'm convinced I have spyware on my machine...

Thread Tools
 
Search this Thread
 
Old 11 October 2002, 08:24 PM
  #1  
uncle buck
Scooby Regular
Thread Starter
 
uncle buck's Avatar
 
Join Date: May 2002
Posts: 1,349
Likes: 0
Received 0 Likes on 0 Posts
Angry

The cable modem activity LED keeps flashing as though I am either downloading or uploading data - but I'm not. In fact, I don't even have IE running.

Does anyone know of any software I can use to detect what is going on and remove any crap that has sneaked onto my machine?

Thanks in advance.

UB

Old 11 October 2002, 08:26 PM
  #2  
mega_stream
Scooby Regular
 
mega_stream's Avatar
 
Join Date: May 2001
Location: Scotland
Posts: 4,580
Likes: 0
Received 0 Likes on 0 Posts
Talking

What O/S you running?
Old 11 October 2002, 08:27 PM
  #3  
uncle buck
Scooby Regular
Thread Starter
 
uncle buck's Avatar
 
Join Date: May 2002
Posts: 1,349
Likes: 0
Received 0 Likes on 0 Posts
Post

Windows 2000
Old 11 October 2002, 08:31 PM
  #4  
rik1471
Scooby Regular
 
rik1471's Avatar
 
Join Date: Nov 2001
Posts: 4,788
Likes: 0
Received 0 Likes on 0 Posts
Post

Ad-aware from lavasoft,searches and deletes all known spyware. Also has a neat tool called ad-watch which monitors cookies and processes.

Click Here to Download



RikW.

[Edited by rik1471 - 10/11/2002 8:31:35 PM]

[Edited by rik1471 - 10/11/2002 8:31:55 PM]
Old 11 October 2002, 08:32 PM
  #5  
rik1471
Scooby Regular
 
rik1471's Avatar
 
Join Date: Nov 2001
Posts: 4,788
Likes: 0
Received 0 Likes on 0 Posts
Post

finally
Old 11 October 2002, 08:33 PM
  #6  
uncle buck
Scooby Regular
Thread Starter
 
uncle buck's Avatar
 
Join Date: May 2002
Posts: 1,349
Likes: 0
Received 0 Likes on 0 Posts
Thumbs up

Sounds good - I think someone at work mentioned it the other day.

I shall get it straight away

Thanks...
Old 11 October 2002, 08:36 PM
  #7  
uncle buck
Scooby Regular
Thread Starter
 
uncle buck's Avatar
 
Join Date: May 2002
Posts: 1,349
Likes: 0
Received 0 Likes on 0 Posts
Talking

rik,

That majorgeeks.com looks like a usefule site

cheers
Old 11 October 2002, 08:38 PM
  #8  
rik1471
Scooby Regular
 
rik1471's Avatar
 
Join Date: Nov 2001
Posts: 4,788
Likes: 0
Received 0 Likes on 0 Posts
Post

It is.

The title of the 1st page makes me laugh:
MajorGeeks.com - Geek it 'till it MHz
Old 11 October 2002, 08:40 PM
  #9  
James Neill
Scooby Senior
iTrader: (1)
 
James Neill's Avatar
 
Join Date: Apr 1999
Posts: 2,889
Likes: 0
Received 0 Likes on 0 Posts
Post

Install ZoneAlarm - a very user friendly firewall and free. After it's installed you'll see all programs that try to connect to the Internet and it'll ask if you want to let them

http://download.com.com/3000-2092-10039884.html?part=zonealarm&subj=dlpage&tag=butto n
Old 11 October 2002, 08:44 PM
  #10  
rik1471
Scooby Regular
 
rik1471's Avatar
 
Join Date: Nov 2001
Posts: 4,788
Likes: 0
Received 0 Likes on 0 Posts
Post

Go to START-PROGRAMS-ADAWARE

Then choose deep reg scan, and any HDD you have.
Old 11 October 2002, 08:44 PM
  #11  
uncle buck
Scooby Regular
Thread Starter
 
uncle buck's Avatar
 
Join Date: May 2002
Posts: 1,349
Likes: 0
Received 0 Likes on 0 Posts
Talking

James

nice idea.... I'll get that too. It's about time I had a firewall - been thinking about it for a while now.

Thanks
Old 11 October 2002, 08:45 PM
  #12  
rik1471
Scooby Regular
 
rik1471's Avatar
 
Join Date: Nov 2001
Posts: 4,788
Likes: 0
Received 0 Likes on 0 Posts
Post

Then click scan now, if it detects any spyware it will display it; tick the box and hoose delete/remove.

Its a good idea to put the ad-watch program in your startup folder.
Old 11 October 2002, 08:46 PM
  #13  
BuRR
Scooby Regular
 
BuRR's Avatar
 
Join Date: Dec 2001
Location: Was Wakefield, now London
Posts: 5,210
Likes: 0
Received 0 Likes on 0 Posts
Post

If you check your firewall logs (if you have one) you'll see that Blueyonder themselves do port scans, for some reason. (that's also assuming you use BY)
Old 11 October 2002, 08:55 PM
  #14  
uncle buck
Scooby Regular
Thread Starter
 
uncle buck's Avatar
 
Join Date: May 2002
Posts: 1,349
Likes: 0
Received 0 Likes on 0 Posts
Post

rik,

this the the log for drive C - can you see anything suspect?

It didn't report finding any spyware specifically:

Scan initialized on 11/10/2002 20:39:48.
(AAW release 5.83, referencefile 029-15.06.2002)
=================================================


Started extended registry scan
===============================
Gator key:HKEY_CLASSES_ROOT\clsid\{21ffb6c0-0da1-11d5-a9d5-00500413153c}\
WurldMedia key:HKEY_CLASSES_ROOT\clsid\{d14641fa-445b-448e-9994-209f7af15641}\
WurldMedia key:HKEY_CLASSES_ROOT\interface\{3cb6def9-1db2-4b5d-9a70-9bf8345ed73c}\
WurldMedia key:HKEY_CLASSES_ROOT\mbho.iehlprobj\
WurldMedia key:HKEY_CLASSES_ROOT\mbho.iehlprobj.1\
Other key:HKEY_CURRENT_USER\software\acceleration software international corporation\
Other key:HKEY_LOCAL_MACHINE\software\acceleration software international corporation\
Gator key:HKEY_LOCAL_MACHINE\software\gator.com\
Alexa key:HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\extensions\{c95fe080-8f5d-11d2-a20b-00aa003c157a}\
WurldMedia key:HKEY_LOCAL_MACHINE\software\microsoft\windows\ currentversion\explorer\browser helper objects\{d14641fa-445b-448e-9994-209f7af15641}\
WurldMedia key:HKEY_LOCAL_MACHINE\software\microsoft\windows\ currentversion\uninstall\your cash rewards\
WurldMedia key:HKEY_CLASSES_ROOT\typelib\{4769dd43-4045-405c-945f-752516445e89}\
Web3000 key:HKEY_LOCAL_MACHINE\software\microsoft\windows\ currentversion\stashedgef
Gator key:HKEY_LOCAL_MACHINE\software\microsoft\windows\ currentversion\stashedgef
Web3000 key:HKEY_LOCAL_MACHINE\software\microsoft\windows\ currentversion\stashedgmg
Gator key:HKEY_LOCAL_MACHINE\software\microsoft\windows\ currentversion\stashedgmg
Gator key:HKEY_LOCAL_MACHINE\software\microsoft\windows\ currentversion\run\cmesys


Registry scan result:
Suspicious keys found : 17


Started folder scan
====================
Gator file:C:\WINNT\GatorPdpSetup.log
Gator folder:C:\Documents and Settings\All Users\Start Menu\Programs\GAIN
Gator folder:C:\Program Files\Common Files\CMEII
Folder scan result:
Folders processed:2383
Suspicious folders found:2


Started file scan
==================
Other file:C:\Documents and Settings\Administrator\Cookies\administrator@serve dby.advertising[1].txt
Doubleclick file:C:\Documents and Settings\Administrator\Cookies\administrator@doubl eclick[2].txt
Other file:C:\Documents and Settings\Administrator\Cookies\administrator@fastc lick[1].txt
Other file:C:\Documents and Settings\Administrator\Cookies\administrator@fastc lick[2].txt
Other file:C:\Documents and Settings\Administrator\Cookies\administrator@count er7.sextracker[1].txt
Other file:C:\Documents and Settings\Administrator\Cookies\administrator@sextr acker[1].txt
Other file:C:\Documents and Settings\Administrator\Cookies\administrator@value click[2].txt
Gator file:C:\Documents and Settings\All Users\Start Menu\Programs\Startup\GStartup.lnk
Gator file:C:\Program Files\Common Files\CMEII\CMEIIAPI.dll
Gator file:C:\Program Files\Common Files\CMEII\CMESys.exe
Gator file:C:\Program Files\Common Files\CMEII\CMEUpd.exe
Gator file:C:\Program Files\Common Files\CMEII\GAppMgr.dll
Gator file:C:\Program Files\Common Files\CMEII\GController.dll
Gator file:C:\Program Files\Common Files\CMEII\GDwldEng.dll
Gator file:C:\Program Files\Common Files\CMEII\GFormCTM.dll
Gator file:C:\Program Files\Common Files\CMEII\GMTProxy.dll
Gator file:C:\Program Files\Common Files\CMEII\GObjs.dll
Gator file:C:\Program Files\Common Files\CMEII\GStore.dll
Gator file:C:\Program Files\Common Files\CMEII\GStoreServer.dll
Gator file:C:\Program Files\Common Files\CMEII\GSvcMgr.dll
Gator file:C:\Program Files\Common Files\CMEII\GSvcSAP.dll
WurldMedia file:C:\Program Files\Morpheus\uninstall_wurld.ctoa
WurldMedia file:C:\WINNT\system32\ad020326.de.xml
WurldMedia file:C:\WINNT\system32\mbho.dll
Gator file:C:\WINNT\GatorPdpSetup.log

File scan result:
Suspicious files found:26



Scanning finished
==================
Suspicious modules found:0
Suspicious keys found : 17
Suspicious folders found:2
Suspicious files found:26
==========================
Components ignored:0
Total components found:45
Old 11 October 2002, 09:03 PM
  #15  
uncle buck
Scooby Regular
Thread Starter
 
uncle buck's Avatar
 
Join Date: May 2002
Posts: 1,349
Likes: 0
Received 0 Likes on 0 Posts
Thumbs up

oh I see. hit continue and it lists all the dodgy stuff. Then gives you the option to remove.

Amongst is Gator - a well known one.

and Wurldmedia - never heard of that.

a couple of dodgy looking things called 'sextracker'

and something called Web 3000

great - they're all going to room 101
Old 11 October 2002, 09:37 PM
  #16  
uncle buck
Scooby Regular
Thread Starter
 
uncle buck's Avatar
 
Join Date: May 2002
Posts: 1,349
Likes: 0
Received 0 Likes on 0 Posts
Talking

James,

Zone Alarm installed and running. It immediately warned that another machine was monitering mine complete with IP address etc.

Activity light has stopped blinking now

Top advice guys - feeling much more secure now!
Old 11 October 2002, 10:43 PM
  #17  
Dark Muppet
Scooby Regular
 
Dark Muppet's Avatar
 
Join Date: Mar 2001
Posts: 483
Likes: 0
Received 0 Likes on 0 Posts
Unhappy

Shame that ad aware does'nt recognise Windows XP SP 1 as spyware
Old 12 October 2002, 09:08 AM
  #18  
Redkop
Scooby Regular
 
Redkop's Avatar
 
Join Date: Oct 2001
Posts: 11,403
Likes: 0
Received 0 Likes on 0 Posts
Post

When using Ad-Aware - be careful you don't delete a 'dll which KaZaA needs. Can't remember what it is called, but has the word 'clint' in it.
Old 12 October 2002, 09:08 AM
  #19  
mega_stream
Scooby Regular
 
mega_stream's Avatar
 
Join Date: May 2001
Location: Scotland
Posts: 4,580
Likes: 0
Received 0 Likes on 0 Posts
Talking

My cable modem light flashes activity even when my PC is turned off so I wouldn't worry too much

Could do a netstat -a from a command line and see if there's any suspect looking entries.
Old 12 October 2002, 10:03 AM
  #20  
DavidLewis
Scooby Regular
 
DavidLewis's Avatar
 
Join Date: Apr 1998
Posts: 1,864
Likes: 0
Received 0 Likes on 0 Posts
Post

"Sextracker" --- Uncle Buck, what HAVE you been doing
Old 12 October 2002, 10:22 AM
  #21  
jbryant
Scooby Regular
 
jbryant's Avatar
 
Join Date: Feb 2000
Posts: 1,082
Likes: 0
Received 0 Likes on 0 Posts
Post

The clint<something>.dll in Kazaa is spyware. If you download Kazaa lite, then it will install a dummy version of this file rather than the nasty version.
Ad-aware will still pick it up as spyware as it has the same filename but you can then safely ignore it.

Joolz
Old 12 October 2002, 10:57 AM
  #22  
suba
Scooby Regular
 
suba's Avatar
 
Join Date: Mar 2000
Posts: 2,462
Likes: 0
Received 0 Likes on 0 Posts
Post

IMHO, i find PestPatrol better than Ad-Adware. i do run both just in case
Old 12 October 2002, 12:42 PM
  #23  
uncle buck
Scooby Regular
Thread Starter
 
uncle buck's Avatar
 
Join Date: May 2002
Posts: 1,349
Likes: 0
Received 0 Likes on 0 Posts
Thumbs up

Zone Alarm has logged 180 blocked intrustions since I installed it last night - 159 'high rated'

Dave - I have no idea how that sex thingy got onto my machine - honest not a fan of internet **** meself sometimes when you're surfing around you can't avoid it though [img]images/smilies/mad.gif[/img]
Old 12 October 2002, 10:21 PM
  #24  
rik1471
Scooby Regular
 
rik1471's Avatar
 
Join Date: Nov 2001
Posts: 4,788
Likes: 0
Received 0 Likes on 0 Posts
Post

Remove anything which doesn't have an "Other" Rating. So that's GATOR, WurldMedia , and DoubleClick.

Should be fine then.
Old 13 October 2002, 12:15 AM
  #25  
uncle buck
Scooby Regular
Thread Starter
 
uncle buck's Avatar
 
Join Date: May 2002
Posts: 1,349
Likes: 0
Received 0 Likes on 0 Posts
Thumbs up

all gone

Activity light still flashes away merrily, but I can monitor things now with Zone Alarm and Ad Aware

Thanks guys
Old 10 November 2002, 08:41 PM
  #26  
uncle buck
Scooby Regular
Thread Starter
 
uncle buck's Avatar
 
Join Date: May 2002
Posts: 1,349
Likes: 0
Received 0 Likes on 0 Posts
Talking



ad aware now installed. what can I expect to happen next?!

- the activity light has stopped flashing already!

oh - no it hasn't

[Edited by uncle buck - 10/11/2002 8:42:26 PM]
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
mattstant
ScoobyNet General
1
10 October 2001 02:58 PM
Jonty B
ScoobyNet General
5
13 June 2001 01:21 PM
Colin Berry
ScoobyNet General
1
08 April 2001 08:57 PM
johnfelstead
ScoobyNet General
27
26 February 2001 05:48 PM



Quick Reply: I'm convinced I have spyware on my machine...



All times are GMT +1. The time now is 07:02 PM.