spyware spoilt IE and WE search

A

Aaron Seet

This is 99.9% likely the fault of the n-CASE spyware which I accidentally
let through a couple of days back. Its suite of programs conveniently
altered my IE behaviour to throw "abort" errors while rendering pages from
websites and redirect me to other web pages (presumably theirs).

In my quest to uninstall these pests the Add/Remove Programs control panel
actually throws actually throws errors and fail to list the installed
programs. I hunted down the running processes and Registry Run key, killed
them, then was able to remove the program entries in Add/Remove Programs.
However the "PAD lookups by n-CASE" installation simply couldn't be remove,
even when the rest have been expelled. From what's written in
http://www.kephyr.com/spywarescanner/library/ncase/index.phtml

looks like manually removal is necessary, which was what I did. But now, the
Search Results separate window won't appear when I click for Search from
WE's context menu or Start menu. I can only run Search via the Search pane
(replacing the Folders pane).

Even more damage: any link in IE that opens up a new window will fail - it
will simply stall for a minute or two, then no new window appears. Ctrl-N or
New Window itself works, but not by clicking on a link or Javascript. I have
tried reinstalling IE 6 SP1 and got stabbed once again - not only did it not
fix the problems, it can't download patches from WindowsUpdate - the
download dialog box just sits there with no progress bar movement. I have to
manually download patches from download.microsoft.com.

There was some talk about re-registering a suite of DLLs related to IE, well
I did them and nothing's improved. Has anybody experienced this kinda
symptoms? I don't know what else to look out for.


Frustrated,
Aaron
 
P

PA Bear

Dealing with Hijackware
http://mvps.org/winhelp2002/unwanted.htm
http://www.mvps.org/inetexplorer/Darnit.htm#tshoot

These days most of us are recommending HijackThis to identify and assist in
the removal of these bad guys. Post your files to the forum mentioned on
the first URL above.

If you cannot access the page to download HijackThis, use this link:
http://216.180.252.218/~spywareinfo.com/downloads/tools/hijackthis.zip

If you find you need CoolWebSearch Shredder, use this link:
http://216.180.252.218/~spywareinfo.com/downloads/tools/cwshredder.zip
(Get a fresh copy of CWS Shredder before each use. It's updated
frequently.)

Also update your virus definitions and then run a full system scan. From
now on do both once-a-day.
--
IE6-specific newsgroup:
news://msnews.microsoft.com/microsoft.public.windows.inetexplorer.ie6.browser

HTH...Please post back to this thread

~Robear Dyer (aka PA Bear)
MS MVP-Windows (IE/OE)
http://mvp.support.microsoft.com
AH-VSOP
http://forum.aumha.org/

 
G

Guest

Sorry to say, Aaron, but I had a user do the very same thing on a remote site and am now in the process of re-installing the operating system. I spent about 4 hours trying to find and kill the culprit, and to no avail. I would recommend the same for you, and to block the n-case sites on your spam blocker or firewall.

Dale Pratz

----- Aaron Seet wrote: -----

This is 99.9% likely the fault of the n-CASE spyware which I accidentally
let through a couple of days back. Its suite of programs conveniently
altered my IE behaviour to throw "abort" errors while rendering pages from
websites and redirect me to other web pages (presumably theirs).

In my quest to uninstall these pests the Add/Remove Programs control panel
actually throws actually throws errors and fail to list the installed
programs. I hunted down the running processes and Registry Run key, killed
them, then was able to remove the program entries in Add/Remove Programs.
However the "PAD lookups by n-CASE" installation simply couldn't be remove,
even when the rest have been expelled. From what's written in
http://www.kephyr.com/spywarescanner/library/ncase/index.phtml

looks like manually removal is necessary, which was what I did. But now, the
Search Results separate window won't appear when I click for Search from
WE's context menu or Start menu. I can only run Search via the Search pane
(replacing the Folders pane).

Even more damage: any link in IE that opens up a new window will fail - it
will simply stall for a minute or two, then no new window appears. Ctrl-N or
New Window itself works, but not by clicking on a link or Javascript. I have
tried reinstalling IE 6 SP1 and got stabbed once again - not only did it not
fix the problems, it can't download patches from WindowsUpdate - the
download dialog box just sits there with no progress bar movement. I have to
manually download patches from download.microsoft.com.

There was some talk about re-registering a suite of DLLs related to IE, well
I did them and nothing's improved. Has anybody experienced this kinda
symptoms? I don't know what else to look out for.


Frustrated,
Aaron
 
A

Andy Cowley

Give adaware a try, it'll find all your spyware and remove it. I always
use it its really very good and free too! Get the personal edition from
download.com or the adaware site
 
A

Aaron Seet

Dear all, thank you for the links. Unfortunately, from what I've seen the
damaged inflicted is on system files (how that could've happened), not some
shell behaviour alteration, which means system corruption. Spybot S&D
doesn't (expectedly) have the ability to fix corrupted system files, and I
don't think it ever will.

The symptons once again, plus a newly discovered irritance:
1. IE New Window by itself works, but not popping a new window via a
hyperlink or Javascript. It will stall for minute or two (unresponsive),
then regain consciousness like nothing happened.

2. WE context Search or Start menu Search won't pop up the Search Results
window.

3. Double-clicking avi files will launch WMP but not get it to open. I'm not
too sure if this was caused by n-CASE but it was working fine previously and
I didn't readjust avi files to another program.

It was originally win2000 Professional. In frustration and desperation, I
upgraded to winXP but it remained. I then had a Repair reinstallation but it
remained. I then deleted off the old WINNT folder and reinstalled afresh; I
don't have alot of time to slowly trace which system files govern the above
behaviours for I need to have a working system. Looking forward to
reinstalling every single SDK and development tool again :(


Fyi and regards,
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Similar Threads


Top