Go Back   Professional Soldiers ® > Technical FAQ Forum > KnuckleDragger Questions

Reply
 
Thread Tools Display Modes
Old 02-20-2005, 12:22   #1
Ambush Master
Quiet Professional
 
Ambush Master's Avatar
 
Join Date: Jan 2004
Location: DFW Texas Area
Posts: 4,741
Spyware Problems

I'm running Windows ME and have been plagued with several spyware related problems for the past couple of weeks.

Well, I've got Norton AV and Firewall, Spybot Search and Destroy, Spyware Stormer, Ad-Aware, and Spykiller 2005 !!! I've killed everything in the "Temp and Temporary Internet" Folders and run all of the above in Safe Mode, but there is still something embedded that is hot-linking words like ass, titts, hot etc to porn sites !!!

Anyone got any ideas ???

Many Thanks in Advance !!
Martin
__________________
Martin sends.
Ambush Master is offline   Reply With Quote
Old 02-20-2005, 15:05   #2
Dan
Administrators
 
Dan's Avatar
 
Join Date: Feb 2004
Location: Fayetteville, NC
Posts: 2,264
AM, Are you and CC sharing stuff in emails or something? He called me this morning with computer woes. Sounds like you probably have some Malware hanging out on your system.

Warning: The following instructions I'm about to give are for your Windows ME and not other OS's, even though much of the same applies.

Depending on the circumstances what all you use your computer for the best approach may be to backup your data/wipe/reinstall. A clean install is the only 100% guaranteed way to return the computer to a fully functioning state. If the computer is used for anything important I'd do a clean install.

If the above is not a possiblility keep in mind that some malware is very well defended, so it's worth some time and effort to prevent it from running in the first place before trying to remove it.

Preparation:

Disconnect machine from any and all computer networks. Use a PS/2 based mouse and keyboard rather than USB.

Backup:

Make a backup image of your HDD or at a minimum backup your data to CD or other removeablke media.

Backup your registry.

Stop the malware from running:

Boot to Safe Mode with F8.

Ensure Windows Explorer is displaying hidden and system files.

Using a seperate computer that is "clean" download the AutoRuns program from SysInternals.

Unzip and run the autoruns.exe from removable media (beware of malware with a good name in a bad directory...i.e. real version of winlogon.exe resides in the C:\Windows\system32 directory, but a copy of winlogon.exe in the C:\Windows directory is bad. Or slight spelling errors of a winlogin.exe in the C:\Windows\system32 directory is also bad.

Check the "hosts" file (in C:\WINDOWS) and if it has any entries other than 127.0.0.1, comment them out.

Look for Browser Helper Objects (BHOs) and disable anything you don't recognize. When in doubt disable it, you can always re-enable a BHO later.

Using a seperate computer that is "clean" download BHOdemon from Definitive Solutions. Since this is larger I'd recommend to burn it to a CD on the "clean computer" and run it from that CD. Go to here to see what is what..."X" means malware, "L" means benign.

Reboot back into Safe Mode.

Using a seperate computer that is "clean" download the Process Explorer from SysInternals.

Unzip and run the procexp.exe from removable media to examine all the running programs. For each malware program keep track of the the location of the underlying executable file. Kill each malware process and rename the underlying executable file and if the underlying executable file resides in its own directory rename the directory too. If you can't kill the process, boot to DOS and rename the underlying file from there using basic DOS like cd and ren.

If you went to DOS reboot back into Safe Mode and finish the above or manually inspect by checking the [windows] section of win.ini looking for an entry such as load=spyware.exe and run=spyware.exe, the [boot] section of system.ini looking for an entry such as Shell = explorer.exe spyware.exe, and the autoexec.bat looking for something like c:\spyware.exe.

Sheck for other errors:

Reboot back into Safe Mode.

Run a full Scandisk or Check Disk.

Make another registry backup.

Delete the malware:

Reboot back into Safe Mode.

Remove any programs that you don't know what they are by using Add/Remove Programs in the Control Panel. Also be sure to look for toolbars, helper programs, etc that can also give problems.

I've never seen a computer with so many anti spyware programs installed, but from my experiences I'll bet that they are clashing on some things. Also, be aware that running the usual anti-malware software can create problems when installing MS OS updates, other software installs, and other software updates. I'd think about removing all of them and later you can reinstall the ones you think you need...I like and use Lavasoft's Ad-Aware on my own system, but only install Spybot Search & Destroy if there are problems when cleaning someone's system. I cleaned a system about three weeks ago that was the worst system I've ever seen infected with malware/spyware. It took me three hours to get it all.

Boot normally.

Use the process monitor to check for any malware that might have been auto-started. Anything showing up usually creates a new instance of itself or use other namesand run from different locations at each startup. Note the underlying executable file, reboot to DOS, and rename the file.

Delete all of the following:
- All ActiveX controls (reside in C:\WINDOWS\Downloaded Program Files)
- The web browser cache (Temporary Internet Files)
- Cookies
- web browser history
- Empty recycle bin
- Disable System Restore to delete the old Restore points, then re-enable it and take a new Restore point.

Reboot normally.

Make sure no malware is auto-started at this point.

Look in the IE Trusted Zone and delete any web sites listed (Tools -> Internet Options -> Security Tab -> Trusted Zones -> Sites button).

Look through your IE Favorites and delete anything that looks suspicious.

Change the IE home page to a blank page (Tools -> Internet Options -> General).

Remove any trusted publishers (Tools -> Internet Options -> Content, click the Publishers button)

Get a firewall program up and running. I use and recommend the latest version of Symantec's Norton Standard Edition Internet Security (it has an Anti-Virus included) and is probably what your using already. If you already have a firewall installed review the rules to make sure you know what is allowed to access the network/Internet. If your not sure then uninstall the firewall and do a clean install of the latest version.

Connect your system to the LAN or however you connect to the Internet.


Scan your HDDs with Housecall from Trend Micro

Scan your HDDs with Security Check from Symantec.

Download Lavasoft's Ad-Aware SE Personal and scan the system.

Download Spybot Search & Destroy and scan the system.

Change the IE home page back to http://www.professionalsoldiers.com/

Prevention:

1st get your programs up to date and setup your programs better:
- run Windows Update manually
- set Windows Update for automatic updates
- adjust IE settings for high security
- lower the size of the IE cache
- lower the size of the System Restore cache
- defrag
- delete TEMP files
- install an anti-virus product and update the software & datafiles
- set anti-virus software for automatic updates
- update other software you use...I use the technical cyber alert system here, but there is also a non-technical one there.
- Use programs that aren't such large targets as Microsoft products like Firefox browser or Thunderbird email program

2nd learn what is good and what is bad. 99% of programs that are free and not from a reputable company probably have malware included in them. Don't install them! Read the EULA's...99% of them even say in the EULA that they have tracking software included, but most people just click "agree" and they install them. I could go on all day here in this area, but won't because I don't ahve the time after putting this together.

Good luck, Dan
Dan is offline   Reply With Quote
Old 02-20-2005, 15:06   #3
RangerRick
Asset
 
Join Date: Feb 2005
Location: nc
Posts: 10
got to tools , internet options, delete cookies, check the offline box as well, also try downloading the microsoft antispyware it clears alot of registry problems. if all else fails update to xp and clear everything. The above post came in before mine and Dan knows way more than i do.

RR

Last edited by RangerRick; 02-20-2005 at 15:08.
RangerRick is offline   Reply With Quote
Old 02-22-2005, 19:07   #4
Ambush Master
Quiet Professional
 
Ambush Master's Avatar
 
Join Date: Jan 2004
Location: DFW Texas Area
Posts: 4,741
Thanks to all, DAN IS THE MAN though !!! Follow his directions above and you can't go wrong !!! The BHODemon did the trick. All links are dropped and the speed is definitely back to normal.

Many thanks to all again !
Martin
__________________
Martin sends.
Ambush Master is offline   Reply With Quote
Old 02-22-2005, 19:19   #5
Dan
Administrators
 
Dan's Avatar
 
Join Date: Feb 2004
Location: Fayetteville, NC
Posts: 2,264
My first thought when you just called was that I didn't write something down with quite enough info and you were calling for assistance. I can say that I was pleased to hear that your gremlins are not swinging from your ceiling fan anymore


It's not everyday that I can repay you...thanks again for the cold brew system! One of the first things I did this morning was to warm some coffee up to get the day started right!!!
Dan is offline   Reply With Quote
Old 02-23-2005, 17:20   #6
Dan
Administrators
 
Dan's Avatar
 
Join Date: Feb 2004
Location: Fayetteville, NC
Posts: 2,264
Quote:
Originally Posted by Dan
...I use the technical cyber alert system here, but there is also a non-technical one there.
In case you didn't sign up for the technical alert system you will find the current alert here.

Notice that even things like vBulletin that this forum is based on is listed under the UNIX / Linux Operating Systems there (we're up to date btw).
Dan is offline   Reply With Quote
Old 02-24-2005, 18:10   #7
Guy
Quiet Professional
 
Guy's Avatar
 
Join Date: Jan 2004
Location: OCONUS...again
Posts: 4,702
Red face

I'll have to try what DAN wrote. I can access this board and others however, my email addy I can't?

Can anyone explain how to back up your hard drive?
__________________
“It is better to have sheep led by a lion than lions led by a sheep.”

-DE OPPRESSO LIBER-
Guy is offline   Reply With Quote
Old 02-24-2005, 19:57   #8
Ambush Master
Quiet Professional
 
Ambush Master's Avatar
 
Join Date: Jan 2004
Location: DFW Texas Area
Posts: 4,741
Quote:
Originally Posted by Guy
Can anyone explain how to back up your hard drive?
Yeha, just put it in reverse !!!
__________________
Martin sends.
Ambush Master is offline   Reply With Quote
Old 02-24-2005, 20:06   #9
Guy
Quiet Professional
 
Guy's Avatar
 
Join Date: Jan 2004
Location: OCONUS...again
Posts: 4,702
Quote:
Originally Posted by Ambush Master
Yeha, just put it in reverse !!!
LMFAO...
__________________
“It is better to have sheep led by a lion than lions led by a sheep.”

-DE OPPRESSO LIBER-
Guy is offline   Reply With Quote
Old 02-24-2005, 21:05   #10
Kyobanim
Moderator
 
Kyobanim's Avatar
 
Join Date: Feb 2004
Location: Central Florida
Posts: 3,045
Quote:
Originally Posted by Guy
Can anyone explain how to back up your hard drive?
first you have to have something to back it up to like a second hard drive or CDroms, etc.
__________________
"Are you listening or just waiting to talk?"


Light travels faster than sound. This is why some people appear bright until you hear them speak.

"Fate rarely calls upon us at a moment of our choosing."
Optimus Prime
Kyobanim is offline   Reply With Quote
Old 02-24-2005, 22:22   #11
Dan
Administrators
 
Dan's Avatar
 
Join Date: Feb 2004
Location: Fayetteville, NC
Posts: 2,264
What Kyo said plus...

Need to know:
- the Operating System you use (i.e. Window ME, Window XP, Redhat Linux 9, Mac OS X, etc).
- If you want emails/addressbook backed up then what email program you use (i.e. Outlook, Outlook Express, Eudora, Mac OS X Mail, Mozilla Thunderbird).
- If you want your favorites backed up then what browser you use (i.e. Internet Explorer, Firefox, Galeon, Konqueror, Opera, etc).

Your best bet if your not sure what we're talking about or don't feel to good about doing this is to get a local geek you trust to do it for you. Don't give them the box especially if you don't trust them. Make em do the backup in front of you, so your data won't end up in a archive of backups to peruse at their leisure.
Dan is offline   Reply With Quote
Old 02-27-2005, 16:11   #12
Guy
Quiet Professional
 
Guy's Avatar
 
Join Date: Jan 2004
Location: OCONUS...again
Posts: 4,702
Lightbulb

I downloaded that new Microsoft Anti-Spyware and it cleaned up a bunch of stuff.
__________________
“It is better to have sheep led by a lion than lions led by a sheep.”

-DE OPPRESSO LIBER-
Guy is offline   Reply With Quote
Old 02-27-2005, 17:35   #13
Kyobanim
Moderator
 
Kyobanim's Avatar
 
Join Date: Feb 2004
Location: Central Florida
Posts: 3,045
The Microsoft anti spyware software is going to be free to owners of registered copies of Windows XP w/ SP2. It comes out of beta in June.
__________________
"Are you listening or just waiting to talk?"


Light travels faster than sound. This is why some people appear bright until you hear them speak.

"Fate rarely calls upon us at a moment of our choosing."
Optimus Prime
Kyobanim is offline   Reply With Quote
Old 02-27-2005, 22:50   #14
Dan
Administrators
 
Dan's Avatar
 
Join Date: Feb 2004
Location: Fayetteville, NC
Posts: 2,264
From today's userfriendly.org
Attached Images
File Type: gif uf007637.gif (14.1 KB, 32 views)
Dan is offline   Reply With Quote
Old 02-28-2005, 00:48   #15
hoepoe
Guerrilla
 
Join Date: Feb 2004
Location: Israel
Posts: 405
Quote:
Originally Posted by Kyobanim
The Microsoft anti spyware software is going to be free to owners of registered copies of Windows XP w/ SP2. It comes out of beta in June.
It's out already, i installed it on my <ashamed> XP partition ;-) and it worked wonders,

Definate must.

That said, i primarily use Linux for everything other than Hebrew documents (although possible) and so far, been up to date with all the patches and Never a virus/spyware/malware problem in 4.5 years of usage. Not to say it's not possible, just harder and not as popular of a victim. In addition i've also NEVER paid for anything Linux related, and it's all above board.

I strongly suggest using partition magic , partiotioning your H/D and installing a user friendly Linux to be used for web browsing, email etc. It's just the safer way to go, and this way you can keep XP or whatever, use if for swhatever, but have the safety of Linux for any outside communication, net, email etc. BTW, the Linux ca nsee and write to your Windows partition keeping all your current docs etc., accessable.

Dan, Martin, Kyo, comments?

Hoepoe


Hoepoe
hoepoe is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off

Forum Jump



All times are GMT -6. The time now is 20:02.



Copyright 2004-2022 by Professional Soldiers ®
Site Designed, Maintained, & Hosted by Hilliker Technologies