Re: not sure if this is spyware... but i need help urgently...

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance

From: Jan Il (abuse_at_localhost.com)
Date: 09/11/04


Date: Sat, 11 Sep 2004 11:05:59 -0700

Hi Lee :-)

> hi... i'm currently using IE6 on XP Home Edition... as of
> now, i've already used AdAware and Webroot Spy Sweeper on
> my system and i would say that most of the adware and
> spyware has been removed. my system also uses a firewall
> and an anti-virus program (norton).
>
> however, i'm having big problems...
>
> Problem #1: for some reason, there's this bug (or
> something) in my computer that makes my IE not
> acknowledge the settings i put on Tools -> Internet
> Options. When I say "Use Blank" for my default webpage,
> no matter how many times i do it, when i close the
> browser and open a new one, the address always points to
> http://hununt.outhost.info/
>
> worse, some bookmarks seem to find their way into my
> Favorites...
>
> Problem #2: Sometimes, when I type a URL for a site and i
> press enter, before the site loads, the browser just
> closes... Some of these happen to be sites that discusses
> something on spyware... One happened to be the site of
> AdAware... I dunno if there's a connection though... I
> retried it enough times to know it wasn't a fluke...
>
> Problem #3: is there a way to shut down all those
> redirect sites? like umax, coolwebsearch...?
>
> Last problem: I don't think this is fully connected with
> browsers but I needed to ask this specifically 'coz it's
> been bugging me...
>
> I wanted to use SpyBot to check my system but for some
> reason, when the download is about to finish, the
> download process just hangs or quits... my friend emailed
> me the program but i can't seem to download it... I tried
> it on my other computer and the downloads (email or
> otherwise) proceed to the end... when i copied the
> program to a cd or my flash drive, my computer can't even
> find the file!
>
> What further confuses me is the fact that when i finally
> got to install adaware to my system (via burning the
> installer from my other comp), it quarantined and deleted
> the whatnots it found... My comp finally finds the
> missing files i just described in the previous paragraph
> but it still won't install... I ran the installers but
> they just quit midway for no reason...
>
> if you can help me, i would truly appreciate it :) i
> dunno why spy sweeper got installed but it wasn't only
> spybot that didn't want to install... i ended up
> downloading 3 spyware removers and only 1 didn't quit
> midway through installation...
>
> again, if you would be able to help me, i would really,
> really appreciate it!
>
> Thanks for your time :)

You have a hijacker, and although you have run the AdAware and Webroot Spy
Sweeper, you still have other obvious malware and spyware on your system.
Also, some types of malware and spyware will prevent downloading and/or
installing the removal tools as you have described. I am sure others will
also have suggestions that will be of help with your problem as well, but,
to get you started...in addition to running your updated anti-virus program,
do the following to fully clean your system. Follow all instructions
carefully:

Dealing with Unwanted Spyware and Parasites:
http://mvps.org/winhelp2002/unwanted.htm
Be sure to run CWShredder, Ad-aware and Spybot.
Also be sure to use the HijackThis. Please do not post your log to this
newsgroup, but to the SpywareInfo or the Aumha HiJackThis forums
http://forum.aumha.org/viewforum.php?f=30, to allow the experts there to
evaluate your log and advise you of the necessary steps to clean your
system.

HOW TO: Reconfigure Ad-aware for a Full Scan
http://forum.aumha.org/viewtopic.php?t=5877

CAUTION!!!!! Before you try to remove spyware using any of the programs
below, download a copy of LSPFIX from any of the following sites:
http://www.cexx.org/lspfix.htm
http://www.spychecker.com/program/winsockxpfix.html
(if your OS is Win2k or XP) The process of removing certain malware may kill
your internet connection. If this should occur, this program, LSPFIX, will
enable you to regain your connection.

Also, get a copy of WINSOCKFIX available at:
http://www.spychecker.com/program/winsockxpfix.html

Some other information:

What are parasites?
http://www.doxdesk.com/parasite/

Windows Security Article

Hidden Backdoors, Trojan Horses and Rootkit Tools in a Windows Environment
http://www.windowsecurity.com/articles/Hidden_Backdoors_Trojan_Horses_and_Rootkit_Tools_in_a_Windows_Environment.html
or
http://snipurl.com/8yc0

About:Buster
http://www.majorgeeks.com/download4289.html
http://www.atribune.org/downloads/AboutBuster.zip

If these steps do not resolve your problem, please post back to this thread
with the details and any error messages.

Hope this helps

Jan :)
Smiles are meant to be shared,
that's why they're so contagious.

Please reply to the newsgroup so others may benefit.
Replies are posted only to the newsgroup for the benefit or other readers.

How to make a good newsgroup post:
http://www.dts-l.org/goodpost.htm



Relevant Pages

  • RE: IEXPLORE.EXE Really sorry - need help with an old problem
    ... the download links provided below. ... Install Spybot and the DSO Exploit Fix. ... and then the Immunize button to block common Spyware programs from installing. ... HijackThis log. ...
    (microsoft.public.windowsxp.general)
  • So much for Windows XP being spyware free...
    ... It finds 61 different pieces of spyware, ... I get an option to download ... some Office updates and an updated video driver for the ... Each install fails ...
    (comp.sys.mac.advocacy)
  • Re: farmmext
    ... Spyware, ... Make sure of these settings and nothing will install without you ... [[Specifies to automatically download and install Web components if a Web ... THE PARASITE FIGHT QUICK FIX PROTOCOL ...
    (microsoft.public.windowsxp.help_and_support)
  • Re: Browser Hijacked - Any Help Appreciated!!
    ... Then download and install BHODemon from ... Dealing with Unwanted Spyware and Parasites: ... How to download and install HiJackThis: ...
    (microsoft.public.windows.inetexplorer.ie6.browser)
  • Re: Browser goes to unwanted page when invalid web address is entered.
    ... >Download, UPDATE before running, and run: ... >You will need to disable System Restore and then reboot ... >programs report as spyware. ... >install malware) Keep it UPDATED. ...
    (microsoft.public.windows.inetexplorer.ie6.browser)