null

Show Entries

How to avoid Spyware
Entered on: April 12, 2004 3:19 PM by Ross
http://www.chron.com/cs/CDA/ssistory.mpl/tech/24964
93
 
 
Too bad the main tactic explained here - avoiding questionable sites - is apparently not an option for many of us, so we will continue to get screwed over royally by nefarious programs.

NEWS 186 - 38 Comments
From: The Bone Entered on: April 12, 2004 3:28 PM
I have been pretty lucky so far. I run Ad-aware and Spybot every week and any time I spend a lot of time at questionable sites. I usually find a few spyware programs each time but I have't gotten fubared yet. Usually McAffee catches the viruses as they come in. I hope!
 
From: Ross Entered on: April 12, 2004 3:55 PM
Roche was privvy to a stanky moment at my house this weekend - we were looking up something on the Rosstation (nothing seedy, I swear), and next thing I knew, I had browsers with ads popping up all over the place. I was rather peeved. I don't do much surfing on that computer - usually just to IMDB if I'm watching a movie and want more info - so I wasn't prepared. I downloaded Spybot, which my browser barely even let me do. Spybot found a bunch of crap, but didn't take the offending program out (it was Lycos sidesearch or some such bullshittery) so I had to get Ad-Aware going too, which finally removed it.  
 
Roche was cracking up to see that I, too, have to endure the stank that he has become proficient in removing from his own machine. Whereas once he had a chilibowl in his bathroom and now is offended at the mention, the same can be said of his computer, which was once a festering chilibowl in its own right, brimming with browser hijacks, bogus search pages, and porn icons, he now lords over a clean desktop. Or so he says. :)
 
From: Swerb Entered on: April 13, 2004 1:31 AM
Alas, the lure of free porn is one we cannot resist.  
 
You know what helped me a bit was going to Google and downloading and installing a Google search toolbar. It blocks pop-ups automatically, which is pretty sweet.  
 
And for a while, I had Spybot running in the background all the time, and it would prompt me when it blocked something... and I got more prompts from sites like Hotmail than from some of the more questionable sites. That being said, some malware leeched onto my machine yesterday and is fucking with my browser settings - and even though both Spybot and Ad-aware highlight it, it never really seems to get deleted. Sons of bitches. Will downloading an updated version of Explorer help? Anybody? And I'm wondering if the malware fucks with Spybot too somehow, because the program locks up on me when I try to download updates.
 
From: Ross Entered on: April 13, 2004 7:48 AM
I think it's just that Spybot's site is messed up sometimes, as that happens to me as well.  
 
I love the Google toolbar too, but that's the short-bus of spyware combat. These fuckers don't bother with using a single page to pop up more browsers with ads, instead they run programs that pop up those browsers, and the google toolbar is powerless to stop it.  
 
Swerb, often, for those hard to remove stains, you have to make note of its name according to Spybot or Ad-aware, then search on it in google and see if you can find a site that tells you how to remove it manually (usually requires going into the registry).  
 
As far as new versions of explorer go, I dont think it will help much. MS can't (or won't) keep up with all the new tricks. Though I've heard good things about Mozilla www.mozilla.org, you might give that a try.
 
From: John Entered on: April 14, 2004 3:50 PM
My desktop is indeed clean and I've been lucky like the Bone in this respect. I do fight the bullshit often and lately I've been winning. This is in part thanks to Big Fatty who taught me some of the tactics I employ. I've become much more savvy in the porn surf arena and am no longer inundated with porn search engines and dialers and so much other bullshit.
 
From: Ross Entered on: April 19, 2004 8:07 PM
As I just got done telling Swerb on the phone, I have been wrestling with the most pervasive, assinine, and screamworthy browser hijack just now. It's taken me more than 2 hours to remove it. Perhaps you guys are well aware of this one, but I had a particularly nasty search page (hosted by www.search-1.net, although the address bar simply reads about:blank) come up as my home page, and no matter what I did, I couldn't change it back. I even have software that supposedly blocks such hijacks from happening, and it was well aware they were happening, and claiming to stop them, but IT WAS POWERLESS. It was maddening. Literally, there was some yelling involved. Now, even though this isn't the well-known and ubiquitous Cool WWW Search hijack, Swerb mentioned something called CWShredder - at first I thought this would do me no good, but the more I researched it, the more I realize this thing is for more than just the Cool WWW Search bullshit. So I ran that, and it found some stuff. I'm not sure if that was the actual thing that fixed it, as I was doing so many things in a frenzy, but I highly suggest this program nonetheless. Ad-Aware and Spybot were powerless, so it's just another tool in the anti-asshole utility belt.  
 
http://www.spywareinfo.com/~merijn/files/cwshredder
.zip
 
 
Man, I tell you, I would love to find the motherfucker who created that thing and settle in with a pair of pliers and a blowtorch. It'd be worth him doing it if only I could get ahold of him.
 
From: Swerb Entered on: April 19, 2004 9:17 PM
Well, I downloaded newer versions of CWShredder and Hijack This, and ran them in Windows safe mode (per Brian's suggestion; he said it works better without a bunch of other junk running), upgraded Ad-aware (again) and finally fixed my nasty little bit of spyware. It's an ongoing, neverending battle with those fucks. They write something to circumvent all the spy software, and the spy software guys find a way to circumvent the circumvention. Point being, upgrade your spy-killer software regularly, boys and girls. And remember, always brush your teeth! Kapwinggg!
 
From: Ross Entered on: April 20, 2004 9:58 AM
Someone just recommened Spy Sweeper to me. Who knows if it works better. It's not free but I think there's a trial version:  
 
http://www.webroot.com/wb/downloads/index.php  
 
In unrelated news, I just posted a silly rant to my old decrepit website at http://rossjohnson.org - if you drink coffee, you might find it amusing.
 
From: Jackzilla Entered on: April 20, 2004 3:03 PM
You kids need to subscribe to "Playboy" or "Big 'Uns" and leave the computer for Tetris. All that time spent fighting viruses is taking away time that could be spent wacking your gopher.
 
From: Ross Entered on: April 20, 2004 5:56 PM
I spoke too soon: apparently the thing I have is called searchx, and it's unknown as to how to remove it. People are basically throwing their hands in the air and reformatting their drives. This is not encouraging:

I fix computers for a living...been fixing them for years. 
This searchx.cc bho..spyware..virus..whatever it is...keeps 
coming back. I'm about to format myself. I know quite a bit 
about virus' etc...I want to kill these people. First time in a 
long long time I could not get rid of something like this. 

 
From: Swerb Entered on: April 21, 2004 1:34 AM
Yeah, I spoke too soon, as well. My fucking nasty bit of spyware just popped back after a day of hibernation. And yeah, mine is searchx too, according to Ad-aware. Grrrr...
 
From: Ross Entered on: April 21, 2004 9:45 AM
This might help us, Swerb:  
 
http://www.lavasoftsupport.com/index.php?showtopic=
23590&hl=searchx

 
From: The Bone Entered on: April 25, 2004 7:16 PM
Please help me unfornicate this process! Lately my computer has been acting super slow - like it's got too many processes running concurrently. I've scan with Spybot, Adaware (updated versions), ran a couple different virus checkers, cleaned all the shit that needs cleaning with Ace Utilities and Iolo Task Agent. My computer still locks up temporarily when trying to open files or run programs. It also displays the hourglass for a really long time when I click on anything on the internet. I've ended every fucking non-essential process in windows task manager. I have well over 50% of my hardrive empty. What the fuck?
 
From: Ross Entered on: April 25, 2004 7:50 PM
Dude, that doesn't sound good. Without sitting in front of it myself, I wouldn't have a clue. Besides, I've proven that I am basically powerless in the face of some of these abominations. I hate to say it, but it may be time to format and reinstall Windows.
 
From: The Bone Entered on: April 25, 2004 8:51 PM
Well I've been thinking about doing that but I'd almost rather be attacked by wild dogs than to go through the process of saving all my shit to disk and starting from scratch. Right now the computer is usable but I'd like to get it running tip top - like it used to. If re-formatting is what's going to get my pornstation running tip top, then that's what I have to do.
 
From: BigFatty Entered on: April 27, 2004 6:48 AM
We all feel your pain Bone. Before I left, I thought I'd do a quick re-install of Windows on my home station. It got all clogged up while I was gone and was difficult for Chica to surf with a dial-up. Well, I ran out of time, and unfortunately, could not find the modem driver. I had to leave her with a cleanly running machine without a modem. Why isn't the law cracking down on these assholes? Look at all the time we have been putting in on our computers dealing with this shit - My dad was doing the same thing! Now how many other people and business are fucking with this???? Im sure the cost of dealing with this shit would run into the billions if left unchecked. Should we write our congressmen?
 
From: Ross Entered on: April 30, 2004 8:13 AM
Swerb, it looks like if you update your CWShredder program to version 1.57.0, it will take care of that fucking searchx motherfucker. I ran it last night and it should have resurfaced by now but it hasn't. Keeping fingers crossed...
 
From: Ross Entered on: May 1, 2004 11:57 AM
AAAARRRGGGHHHH!!!!!!! I spoke too soon AGAIN! That fucking piece of shit program is back!!!! I am going to kill everyone on the planet!!!!
 
From: Swerb Entered on: May 1, 2004 11:03 AM
Yeah, I tried it too, and it didn't work. Brian suggested loading Windows in safe mode, opening up the DOS prompt and deleting that .dll file, but I haven't done it yet because I'm not certain how. You should try it, Bert, and see if it works.
 
From: Ross Entered on: May 1, 2004 11:57 AM
Which DLL file? I don't even know which one.
 
From: The Bone Entered on: May 1, 2004 1:28 PM
Damnation! My computer is acting up but not nearly to the frustrating extent your shit is. Looks like your going to have to format your hard drive and reload windows. Please don't kill me though Ross!
 
From: Ross Entered on: May 1, 2004 11:27 PM
I'm sorry Bone, but this transgression is so severe that I feel that all of humanity must be destroyed to make things right.  
 
I just checked out the Rosstation - it's infested. I have programs running with names like asdlfkun.exe... when I kill them, they instantly re-appear. Same as when I delete them from the registry so that they won't load again when I re-start - something puts them back in the second I remove them.  
 
On my regular computer, I have Ad-Aware, Spybot, Spy Sweeper, Norton Antivirus 2004, CWShredder, and Hijack This. Yet nothing can cure me.  
 
Game over, I'm done.
 
From: Swerb Entered on: May 2, 2004 12:16 AM
Bert, remember that .dll file we found when you were here last weekend? Run Ad-Aware and it should pop up, not as a registry key or tracking cookie, but as a file. Mine has changed names a couple times now...
 
From: John Entered on: May 2, 2004 1:55 AM
Well I restored my computer the other day and everything seems to be going fine for now as I'm sure it won't last. It's all a bunch of bullshit and I hope it gets better before Bert has to commit genocide in the USA to solve the problem.
 
From: Ross Entered on: May 2, 2004 9:54 AM
I'll run it again, but I have little faith - I fear that another program is infected. For instance, when I start up Norton AntiVirus, I Ad-Watch shows me that the registry gets fucked with - meaning the program comes back. This is the worst threat I've yet faced. It is my arch-enemy.
 
From: Ross Entered on: May 2, 2004 10:54 AM
I *may* have defeated it, though I'm reluctant to jinx it at this point by saying anything. I got a couple new programs that let me examine every fucking thing on my computer and delete any stubborn motherfuckers. I found a DLL file called kbe.dll or something similar and someone else I read online said that was a problem. So I got rid of it. I also uninstalled Norton. So far so good, but only time will tell. I'm not really all that confident.
 
From: The Bone Entered on: May 2, 2004 10:44 PM
What programs?
 
From: Ross Entered on: May 3, 2004 7:41 AM
Read this thread:  
 
http://www.computing.net/windowsxp/wwwboard/forum/1
02116.html
 
 
The guy at the bottom suggests PRCView:  
 
http://www.teamcti.com/pview/prcview.htm  
 
and KillBox:  
 
http://www.broadbandmedic.com
 
From: Ross Entered on: May 3, 2004 9:51 PM
Doesn't fucking matter - the damn homepage hijacker is back. Motherfuckers...
 
From: The Bone Entered on: May 3, 2004 10:48 PM
What now Holmes? Like you, I have shit that's bogging down my computer and it seems I've run out of options. I fully intend to slap in the system recovery disk and re-format my shit - after I backup all my mp3's and shit.
 
From: Ross Entered on: May 21, 2004 10:25 AM
This is an interesting article on spyware - it's not just hijacking your system, it's ruining lives!  
 
http://www.wired.com/news/infostructure/0%2C1377%2C
63391%2C00.html
 
 
By the way, I ended up re-installing windows last night because in the middle of trying to combat that incessant searchx piece of shit, I apparently corrupted windows and it wouldn't boot properly. I figured at the very least that I would end up erradicating searchx, but I was wrong - it kept enough of my old settins in tact (which is good, for the most part - I had to re-install very few programs) - but I still am plagued by my home page being set to that stupid ass search page.
 
From: Swerb Entered on: May 21, 2004 4:42 PM
Yeah, if I don't run CWShredder every day, when I go to certain sites (like Hotmail, for instance), I get a jillion bullshit "you have spyware!" popups. I guess the only option is to re-format the hard drive, since re-installing Windows doesn't do it.
 
From: Jackzilla Entered on: May 21, 2004 4:58 PM
Not that I want to jinx myself, but how come I never have any of these problems? Seriously... Am I just lucky?
 
From: Ross Entered on: May 21, 2004 4:59 PM
I have a potential solution to this one that I read about today, I'm going to try it now. Stay tuned in a day or two and I'll report progress.
 
From: John Entered on: May 23, 2004 12:13 AM
It's luck, Zilla. I've picked shit up from non-nefarious sites and so has Bert as I was there to witness it. Hopefully your luck won't run out.
 
From: Ross Entered on: May 23, 2004 6:00 PM
Okay, I feel confident saying that I have finally vanquished my abhorrent foe. Swerb, read here. It involves going into the registry, but it's really not that bad. Actually it's pretty easy.  
 
http://www.computing.net/security/wwwboard/forum/11
527.html

 
From: Swerb Entered on: May 25, 2004 11:08 PM
Victory is ours! We have vanquished that motherfucking cocksucking sonofabitching jesus raping dog-ass licking piece of shit of a virus! More than 24 hours later, and it's still gone. Feels like the weight of the world is off my shoulders. Thanks for your help, Bert.  
 
Still, this wouldn't stop me from getting medieval on the guy's ass who created that fucking program. All in the name of vengeance...
 
From: John Entered on: May 26, 2004 9:26 AM
Harsh indeed! In the name of vengeance though, it's acceptable.
 

[Log In to Add Comment]


a division of

© 2003 Ross Johnson
RSS Feed