PDA

View Full Version : I need some pc help paleez!!



Yooformula
04-26-2006, 04:08 AM
Now I was watching a commercial for ASK.com and I wanted to check it out instead of Google(big mistake). Not only did it not answer my question but I got like 5 popups that wont turn off. Now I havent had popups in over a year and I ran spybot, adaware, microsoft spyware and my trend mirco pccillin spyware finder and cant find this fuggin bot. Any ideas on what to look for? Its the same 5 popups everytime and its killing me!!:mad:

68RR440
04-26-2006, 07:08 AM
I use AVG Free Edition, it catches stuff Adaware, Spybot and Macafee miss. I got it from download.com It may help, worth a shot...

Slow Joe
04-26-2006, 07:12 AM
Adaware is probably the best one I've used thus far... Download.com search for Adaware... Otherwise the Microsoft Anti-Spyware software is good...

68RR440
04-26-2006, 07:26 AM
and I ran spybot, adaware, microsoft spyware....



Adaware is probably the best one I've used thus far... Download.com search for Adaware... Otherwise the Microsoft Anti-Spyware software is good...

:chair: :durr :alcoholic

GTSLOW
04-26-2006, 08:41 AM
I dunno whenever I had those s0b's I would look in task manager for somthing fishy. Bots will always be under your user name for applications. Most of the time they have some stupid azz name too, however they can also be something stealthy.

You're best bet is to go over to www.pcper.com there's a section for spyware. You can take a screenshot or post what you have running on task manager and one of the guru's will pick out the bot for you. Then you go to run and type msconfig go to startup and turn that bish off. After you restart search for that file name and delete the sob!

Nick
04-26-2006, 08:49 AM
www.ewido.com

I live by it.

animal
04-26-2006, 08:49 AM
Bots will always be under your user name for applications.

That is false. If they embed themselves to run as a service they can be running under the system account, or theoretically any account they create on your system.... this is at least in NT/2K/XP :) 95/98/ME would be completely different.

deciuss
04-26-2006, 08:50 AM
ever since i bought spysweeper i have not had any pop ups in over a year.

Cryptic
04-26-2006, 08:57 AM
hijackthis (http://www.merijn.org/files/hijackthis.zip).... although you'd probably do more damage than good if you dont know what your looking at.

or try startuplist (http://www.thespykiller.co.uk/forum/index.php?action=tpmod;dl=item3)

wikked
04-26-2006, 09:15 AM
control panel - add/remove programs - ask.com toolbar

It's the same people that own askjeeves.com, both are junk.
They've been in the spotlight for lying about spyware distribution through their websites. :chair:


Google > *

2kgtp
04-26-2006, 10:06 AM
Ewido is the best. Finds tons of stuff. http://www.ewido.net/en/download/

GTSLOW
04-26-2006, 01:37 PM
That is false. If they embed themselves to run as a service they can be running under the system account, or theoretically any account they create on your system.... this is at least in NT/2K/XP :) 95/98/ME would be completely different.

Ya you're right. Well the lame ones will usually be under your name but there are some that even have the same name as system processes! :wooo

animal
04-26-2006, 01:57 PM
Ya you're right. Well the lame ones will usually be under your name but there are some that even have the same name as system processes! :wooo

Want an even bigger challenge? Try deleting processes with a name of "rundll3?.dll" The ? is a wildcard in dos so it won't work there, and explorer didn't know how in the hell to even display it.

I've also had some other weird process names... like " ".exe All spaces... freaks out the computer when you even click on it. Also, other ones with other special control characters embedded in them.... like a carraige return. I'm not even sure how you would go about initially naming a file with a carraige return character in the filename... but whatever.

All ended up being removable with my knoppix cd... but some of these bastards are creative with spyware crap.

Though it's been addressed... yoo, if you still run into problems after trying what the other people said, pm me, I'll get you all fixed up.

Yooformula
04-26-2006, 04:11 PM
I looked all over and I did find the exe file under my task manager but NOWHERE else. There was nothing under my add/remove prgrams listing either and I checked all of the cookies there was nothing there for it either. I deleted it from the task manager then ran spybot again and same results. so far no popups this morning so hopefully I got it.
thanks dudes! I forgot all the places to check since it had been so long.

animal
04-26-2006, 04:17 PM
I looked all over and I did find the exe file under my task manager but NOWHERE else. There was nothing under my add/remove prgrams listing either and I checked all of the cookies there was nothing there for it either. I deleted it from the task manager then ran spybot again and same results. so far no popups this morning so hopefully I got it.
thanks dudes! I forgot all the places to check since it had been so long.

You checked all the obvious places. Unfortunately most of the stuff runs in hard fo find places. To really be sure, you need to check that explorer.exe hasn't been piggybacked, also that there's no BHO's or related things running behind your back in not-so-easy-to-find places... that's where hijackthis comes in. Lastly... depending on the infection, you may need a bootable cd of some sort to clean files that can't be cleaned when your OS is running... this is an extreme case but I've seen it more than a handful of times.

theavenger333
04-26-2006, 05:46 PM
gimme a call so we can test this amp yoosef, i'll fix your puter then