Important!!! Programs that install themselves to my computer

Started by Edwin Xie, Mon 20/09/2004 02:47:41

Previous topic - Next topic

333

yeah man I have stupid ad problems too but its my sisters fault. Ad aware dousn't work for me there is always a the same file it can't get rid of it.
It was an acciDENT he ran toward me and I hated him and I accidentally pullED OUT MY knife I had spent 5 hours sharpening.

TerranRich

It's funny. My friend Todd's parents have this problem with their computer. Slow as all hell, icons galore on the desktop, useless and unwanted processes running, never-ending pop-ups, and web search toolbars everywhere. They use IE.

Todd and I haven't had one single problem in months. We use Firefox.

Got it? Stop using IE. Deny all access to IE in Control Panel and system settings. It is possble to all but delete IE. Search for sites on "removing internet explorer". Although you cannot physically delete it (SERIOUSLY, try deleting "IEXPLORE.EXE". It comes back. Literally, Windows will replace it immediately in front of your eyes.), you can stll deny all access to it. I have never gotten ONE IE pop-up. As for the numerous toolbars, use Control Panel -> Add/Remove Programs to remove all search toolbars and other suspicious programs that you have never installed and DO NOT look important.

Next, use a spyware/adware removal tool. Ad-Aware doesn't work very well for Todd's parents, so I suggest trying out several different ones (Spyware Search & Destroy, Spyhunter, SpyStopper, et. al.) and see which one works the best. Maybe even using more than one will ensure that everything is deleted, and permanently. I've had to uninstall "180Search" about 20 times, as well as "SearchBar" and some other useless shit.

On another note, if there is ANYBODY out there who can help me either hack into or temporarily bring down the web sites of these search toolbars (like 180Search), please PM me. I seriously want to get back at these assholes. I'm very serious.
Status: Trying to come up with some ideas...

Albert Cuandero

I had the same problem - these are the steps I took to solve it:

- first I blocked access to all the sites in my history I didn't explicitly name to visit
- I pushed the privacy and security bars as high as possible
- used Panda Antivirus (gets many installers down) and Ad-Aware from Lavasoft to kill most tracking shit
- I manualy removed any programs from the registry I didn't install myself.
- since I knew the date the BPFU happpened (I visited an "art gallery" in UK) I next listed all files modified since then and deleted each and every one I didn't know belongs to the system and is supposed to be changed (I killed windows about 3 times by this, but it recovers itself in case of "hardwired" XP)
- One last thingy was left... a senseless process that boosted the "winlogon" prog to run constantly and block 50% of my CPU power, 80% of mem and 90% of my LAN traffic. Remiving this bugger was tricky:

It had a regentry that installed another regentry automaticaly if it was erased. One was called "Save On Net Traffic" - quite obviously something you would kill, but the other one, the real installer was called "WinUpgrade" or something similar. But by reading bootlogs with care I found out, this can't really be anything by µ$oft so I blocked access to it, then deleted the other one and restarted, now I could remove the installer and my problems were gone.

It took me altogether about 12 hours of intensive work to accomplish this.

Since then (6 months ago) I am using Panda on full setting, Windows Firewall and Ad-Aware (scans after each session) and full security on IE (the "don't touch or accept unless I tell you to"-setting). Besides the Windows updates help a lot (don't forget to check security patches for office though, otherwise your Outlook is your weakest point!). I am still attacked from time to time but so far I could prevent FUs (knock on wood, walk around the house, spit over the left shoulder...)

Hope this little novel helps you Edwin Xie...
int do_you_like_me;
if (do_you_like_me == 1) Display ("You can call me Al");
else {}

Edwin Xie

Now here is a wierd and cool thing about Spybot S&D, I reinstalled it since it got me again and I had to format my hard drive and then recover the files on it. It had the optional files, SD Resident and Teatimer..... they both completely stopped those ads, I don't have the ad problems anymore and now SD Resident blacklisted 1,173 processes (which I bet are those mailicious ad-bots!). But I am worried that they might take over my computer in some way.
Moving at superhigh speed getting to the planet called Earth. But it is boxed in white......thing.....

Albert Cuandero

Are you using a fixed IP-Adress or a dynamic one?

Anyway I would recommend a firewall. XP comes with one alread, you can look up on the µ$ homepage how to activate it.
int do_you_like_me;
if (do_you_like_me == 1) Display ("You can call me Al");
else {}

Barbarian

I also recommend using SpywareGuard:
http://javacoolsoftware.com/spywareguard.html

And check out the various other products on that site. They offer good protection against Spyware/Adware junk, and free utilities.

Of course having a Firewall and Anti-Virus program enabled should be a priority as well.

Edit: Another good site with many good (and free) utilities for defending against and ridding yourself of Spyware, over at:
http://www.spywareinfo.com/~merijn/downloads.html

Conan: "To crush your enemies, see them driven before you, and to hear the lamentation of the women!"
Mongol General: "That is good."

Blade of Rage: www.BladeOfRage.com

Edwin Xie

Quote from: Albert Cuandero on Thu 30/09/2004 19:59:56
Are you using a fixed IP-Adress or a dynamic one?

Anyway I would recommend a firewall. XP comes with one alread, you can look up on the µ$ homepage how to activate it.

The µ$ homepage? I think my IP constantly changes (since I am using a modem).
Moving at superhigh speed getting to the planet called Earth. But it is boxed in white......thing.....

SMF spam blocked by CleanTalk