IE Spyware remove...

G

Guest

Hi guys, since yesterday I've had some trouble with some spyware (god knows
where from) opening a blank page in IE. When I open IE today as soon as it
loads a message box comes up saying 'you are infected with spyware would you
like to remove it?'

I click 'ok' and it redirects me to here:

http://www3.palsol.com/spyrem_offer/index.html?hop=cjbmgt

If this is a legit windows message that pops up, why am I redirected to this
odd place? If you take a look at the site it looks like one of those faked up
'FREE scan' things that you get sent in spam and when you use it, it actually
infects you!

what is going on?? is this a safe thing to use? (PAL spyware remover)

spybot doesn't seem to get rid of it and nor does spy cleaner.

Thanks in advance : )

Jay
 
G

Guest

Having looked at another forum for info, I've 'jumped to location' on one of
the DSO exploit things that spybot finds (so i'm in the registry) and in the
page it finds there are about 15 files that are type REG_SZ and 4 of these
are type REG_EXPAND_SZ and their data name starts with % rather than C: or
Accesories etc...

Also one of them is type REG_DWORD and data 0x00000001

Spybot finds 5 DSO exploit files, will these 5 that look a touch different
be them?

I know.... I'm crap : \

help is very much apreciated.
 
R

Robert L [MS-MVP]

quoted from http://www.ChicagoTech.net
Troubleshooting Spyware

If uninstalling or spyware-remover software don't remove the spyware, you
may want to use MSCONFIG plus Task Manger to find the expected spyware, and
the modify the registry.


--
For more and other information, go to http://www.ChicagoTech.net

Don't send e-mail or reply to me except you need consulting services.
Posting on MS newsgroup will benefit all readers and you may get more help.

Robert Lin, MS-MVP, MCSE & CNE
Networking, Internet, Routing, VPN, Anti-Virus, Tips & Troubleshooting on
http://www.ChicagoTech.net
This posting is provided "AS IS" with no warranties.
 
C

Chuck

Hi guys, since yesterday I've had some trouble with some spyware (god knows
where from) opening a blank page in IE. When I open IE today as soon as it
loads a message box comes up saying 'you are infected with spyware would you
like to remove it?'

I click 'ok' and it redirects me to here:

http://www3.palsol.com/spyrem_offer/index.html?hop=cjbmgt

If this is a legit windows message that pops up, why am I redirected to this
odd place? If you take a look at the site it looks like one of those faked up
'FREE scan' things that you get sent in spam and when you use it, it actually
infects you!

what is going on?? is this a safe thing to use? (PAL spyware remover)

spybot doesn't seem to get rid of it and nor does spy cleaner.

Thanks in advance : )

Jay

Jay,

Spyware uses many different techniques to operate on your computer, so you need
a variety of tools to identify and remove it.

You did update Spybot before running it, right?

Start by downloading each of the following additional free tools:
AdAware <http://www.lavasoftusa.com/>
CWShredder <http://www.majorgeeks.com/download4086.html>
HijackThis <http://www.majorgeeks.com/download.php?det=3155>
LSP-Fix and WinsockXPFix <http://www.cexx.org/lspfix.htm>
Stinger <http://us.mcafee.com/virusInfo/default.asp?id=stinger>

Create a separate folder for HijackThis, such as C:\HijackThis - copy the
downloaded file there. AdAware and Spybot S&D have install routines - run them.
The other downloaded programs can be copied into, and run from, any convenient
folder.

First, run Stinger. Have it remove any problems found.

Next, close all Internet Explorer and Outlook windows, and run CWShredder. Have
it fix all problems found.

Next, run AdAware. First update it ("Check for updates now"), configure for
full scan (<http://forum.aumha.org/viewtopic.php?t=5877>), then scan. When
scanning finishes, remove all Critical Objects found.

Next, run Spybot S&D again. First update it ("Search for updates"), then run a
scan ("Check for problems"). Trust Spybot, and delete everything ("Fix
Problems") that is displayed in Red.

Then, run HijackThis ("Scan"). Do NOT make any changes immediately. Save the
HJT Log.
<http://forums.spywareinfo.com/index.php?showtopic=227>
<http://www1.spywareinfo.com/articles/hijacked/prevent.php>

Finally, have your HJT log interpreted by experts at one or more of the
following security forums (and please post a link to your forum posts, here):
Aumha: <http://forum.aumha.org/index.php>
Net-Integration: <http://forums.net-integration.net/>
Spyware Info: <http://forums.spywareinfo.com/>
Spyware Warrior: <http://spywarewarrior.com/index.php>
Tom Coyote: <http://forums.tomcoyote.org/>

If removal of any spyware affects your ability to access the internet (some
spyware builds itself into the network software, and its removal may damage your
network), run LSP-Fix and / or WinsockXPFIx.

Finally, improve your chances for the future.

Harden your browser. There are various websites which will check for
vulnerabilities, here are three which I use.
http://www.jasons-toolbox.com/BrowserSecurity/
http://bcheck.scanit.be/bcheck/
https://testzone.secunia.com/browser_checker/

Block Internet Explorer ActiveX scripting from hostile websites (Restricted
Zone).
<https://netfiles.uiuc.edu/ehowes/www/main.htm> (IE-SpyAd)

Block known dangerous scripts from installing.
<http://www.javacoolsoftware.com/spywareblaster.html>

Block known spyware from installing.
<http://www.javacoolsoftware.com/spywareguard.html>

Make sure that the spyware detection / protection products that you use are
reliable:
http://www.spywarewarrior.com/rogue_anti-spyware.htm

Harden your operating system. Check at least monthly for security updates.
http://windowsupdate.microsoft.com/

Block possibly dangerous websites with a Hosts file. Three Hosts file sources I
use:
http://www.accs-net.com/hosts/get_hosts.html
http://www.mvps.org/winhelp2002/hosts.htm
(The third is included, and updated, with Spybot (see above)).

Maintain your Hosts file (merge / eliminate duplicate entries) with:
eDexter <http://www.accs-net.com/hosts/get_hosts.html>
Hostess <http://accs-net.com/hostess/>

Secure your operating system, and applications. Don't use, or leave activated,
any accounts with names or passwords with trivial (guessable) values. Don't use
an account with administrative authority, except when you're intentionally doing
administrative tasks.

Use common sense. Yours. Don't install software based upon advice from unknown
sources. Don't install free software, without researching it carefully. Don't
open email unless you know who it's from, and how and why it was sent.

Educate yourself. Know what the risks are. Stay informed. Read Usenet, and
various web pages that discuss security problems. Check the logs from the
security products that you use regularly, look for things that don't belong, and
take action when necessary.

Cheers,
Chuck
Paranoia comes from experience - and is not necessarily a bad thing.
 
G

Guest

Thanks Chuck, I've got hold of all those tools and have used them like you
said to, I have put a post on one of those forums so am just waiting to see
if anyone can advise me on what to remove etc...

Jay
 
C

Chuck

Thanks Chuck, I've got hold of all those tools and have used them like you
said to, I have put a post on one of those forums so am just waiting to see
if anyone can advise me on what to remove etc...

Jay

Thanks for the update, Jay. Can you post links to your forum posts, for the
education of those in this forum who follow the spyware issue?

Cheers,
Chuck
Paranoia comes from experience - and is not necessarily a bad thing.
 
C

Chuck

Here ya go:
http://forums.spywareinfo.com/index.php?showtopic=29189

Busy forum! I only posted it a few hours ago and it was on page 3 already!
with no replies : \ yet : )

cheers,
Jay

Jay,

Spyware is one of the biggest problems with the internet. Lots of folks needing
help.

Be patient. Wait more than a couple hours for results.

Post in a couple other forums too. They are all free, and nobody will yell at
you. If they even see you cross posted between two or three different forums.

Cheers,
Chuck
Paranoia comes from experience - and is not necessarily a bad thing.
 
C

Chuck

Here ya go:
http://forums.spywareinfo.com/index.php?showtopic=29189

Busy forum! I only posted it a few hours ago and it was on page 3 already!
with no replies : \ yet : )

cheers,
Jay

Jay,

Well, I got a look at your post. I don't know all the current spyware problems,
so be patient. But I can spot these.

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://www.searchwww.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.searchwww.com/
R3 - URLSearchHook: (no name) - {00D6A7E7-4A97-456f-848A-3B75BF7554D7} - (no
file)
O2 - BHO: myBar BHO - {0494D0D1-F8E0-41ad-92A3-14154ECE70AC} - C:\Program
Files\MyWay\myBar\1.bin\MYBAR.DLL
O3 - Toolbar: My &Search Bar - {0494D0D9-F8E0-41ad-92A3-14154ECE70AC} -
C:\Program Files\MyWay\myBar\1.bin\MYBAR.DLL

MyBar, MySearch, MyWay are well known spyware. SearchWWW is very suspicious
too.

And, unless you know what these are, fix these too:
O15 - Trusted Zone: http://www.headstrong-hq.com
O15 - Trusted Zone: http://aol.pogo.com
O16 - DPF: Pop Fu by pogo -
http://game4.pogo.com/applet-5.9.5.30/popf...u-ob-assets.cab
O16 - DPF: World Class Solitaire by pogo -
http://game4.pogo.com/applet-5.9.5.30/worl...s-ob-assets.cab
O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} (Web P2P Installer) -

What wen P2P did you install? Read this article please.
<https://netfiles.uiuc.edu/ehowes/www/dbd-anatomy.htm>

Once you fix these as appropriate, reboot then rerun HJT and post a cleaner log
in your SWI post.

Cheers,
Chuck
Paranoia comes from experience - and is not necessarily a bad thing.
 
F

Fred Bloggs

Another effective tool in the security realm is to use a
different browser to IE. Firefox or Mozilla
(www.mozilla.org) are great free browsers with better
features than IE, and are far more secure.
 
C

Chuck

Another effective tool in the security realm is to use a
different browser to IE. Firefox or Mozilla
(www.mozilla.org) are great free browsers with better
features than IE, and are far more secure.

As DHS told us earlier this year, in their official Security Alert. LOL. How
many non-computer experts read that? No one in my family or friends knew what I
was talking about when I mentioned DHS.

And as soon as the market moves a majority of the public away from Internet
Exploiter, the crackers who find the security holes there WILL move to Firefox
or Mozilla, and WILL find holes there.
Chuck
Paranoia comes from experience - and is not necessarily a bad thing.
 
W

Wayne Mery

Muttley said:
Hi guys, since yesterday I've had some trouble with some spyware (god knows
where from) opening a blank page in IE. When I open IE today as soon as it
loads a message box comes up saying 'you are infected with spyware would you
like to remove it?'

I click 'ok' and it redirects me to here:

http://www3.palsol.com/spyrem_offer/index.html?hop=cjbmgt

If this is a legit windows message that pops up, why am I redirected to this
odd place? If you take a look at the site it looks like one of those faked up
'FREE scan' things that you get sent in spam and when you use it, it actually
infects you!

what is going on?? is this a safe thing to use? (PAL spyware remover)

spybot doesn't seem to get rid of it and nor does spy cleaner.

Thanks in advance : )

Jay

I had something similar start last week.
But it doesn't send me to palsol.com

I have spybot installed and other protections that are up to date. I
don't even use IE, so I don't know why I'm getting this message. Very
frustrating.

Is this what you see? http://www.lehigh.edu/~wsm0/spywareinfected.GIF
 
C

Chuck


Wayne,

Internet Explorer doesn't scan for spyware, nor does it provide a spyware
removal tool.

This is a spyware popup. Saying Yes will probably install more spyware,
typically the much more potent stuff.

Read Eric Howe's article to see how sneaky this shit is becoming.
<https://netfiles.uiuc.edu/ehowes/www/dbd-anatomy.htm>

See my advice above for removal please.

And Wayne, please don't contribute to the spread and success of email address
mining viruses. Learn to munge your email address properly, to keep yourself a
bit safer when posting to open forums. Protect yourself and the rest of the
internet - read this article.
http://www.mailmsg.com/SPAM_munging.htm

Cheers,
Chuck
Paranoia comes from experience - and is not necessarily a bad thing.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top