IMMORTAL SPYWARE!!!!

Z

zeretul1

Have tried several posts on spywareinfo.com, and have
gotten no! replies. This sucks. I have used:
Aluria's spyware eliminator
Pest Patrol
Spybot search and destroy 1.2
Ad-aware 6.0
Spysweeper
Reg Mechanic

None of these programs have helped. I am constantly
finding new reg keys, spyware progs and the like, but the
problem is on-going.

This is my main symptom. Randomly, IE windows, full
windows, will open with advertisements ranging from anti-
0spyware progs to singles site. These occur whether or
not I am browsing the internet, and often occur 3-4 times
at once.

I am on a cable broadband connection, and am using McAfee
virusscan 7 and firewall 4.

I need some help here. Either I eliminate the problem, or
re-format the C: drive.

Any and all help appreciated.

Much love!
 
Z

zag

Install Zone-Alarm (the free one is fine) or Kerio fire-
wall (also a free one if you look hard). That will stop
your problem.
z ------------------------------------------------------
 
S

Shenan Stanley

zeretul1 said:
Have tried several posts on spywareinfo.com, and have
gotten no! replies. This sucks. I have used:
Aluria's spyware eliminator
Pest Patrol
Spybot search and destroy 1.2
Ad-aware 6.0
Spysweeper
Reg Mechanic

None of these programs have helped. I am constantly
finding new reg keys, spyware progs and the like, but the
problem is on-going.

This is my main symptom. Randomly, IE windows, full
windows, will open with advertisements ranging from anti-
0spyware progs to singles site. These occur whether or
not I am browsing the internet, and often occur 3-4 times
at once.

I am on a cable broadband connection, and am using McAfee
virusscan 7 and firewall 4.

I need some help here. Either I eliminate the problem, or
re-format the C: drive.

Do all of the following.. ALL for your case..

If you don't wish to follow all of the advice immediately, just want to
get rid of your current dilemma, then you are welcome to scroll down to
the section titled "SPYWARE/ADWARE/POPUPS", where your problem as
stated should be resolved by the applications and suggestions found in
that section. If this helps solve your problem then I again HIGHLY
suggest you follow the rest of the advice below (matter of fact, I
suggest it either way.)

Suggestions on what you can do to secure/clean your PC. I'm going to try
and be general, I will assume a "Windows" operating system is what is
being secured here.


SPYWARE/ADWARE/POPUPS
---------------------

There are annoyances out there you can get without
trying. Your normal web surfing, maybe a wrong click on a web page, maybe
just a momentary lack of judgment by installing some software packages
without doing the research.. And all of a sudden your screen starts filling
up with advertisements or your Internet seems much slower or your home page
won't stay what you set it and goes someplace unfamiliar to you. This is
spyware. There are a whole SLEW of software packages out there to get rid
of this crud and help prevent reinfection. Some of the products already
mentioned might even have branched out into this arena. However, there are
a few applications that seem to be the best at what they do, which is
eradicating and immunizing your system from this crap. Strangely, the best
products I have found in this category ARE generally free. That is a trend
I like. I make donations to some of them, they deserve it!

One side-note. Never think one of these can do the whole job.
Try the first 5 before coming back and saying "That did not work!"

Spybot Search and Destroy (Free!)
http://www.safer-networking.net/

Lavasoft AdAware (Free and up)
http://www.lavasoft.de

CWSShredder (Free!)
http://www.spywareinfo.com/~merijn/downloads.html

Hijack This! (Free)
http://mjc1.com/mirror/hjt/
( Tutorial: http://www.spywareinfo.com/~merijn/htlogtutorial.html )

SpywareBlaster (Free!)
http://www.javacoolsoftware.com/

IE-SPYAD (Free!)
http://www.staff.uiuc.edu/~ehowes/resource.htm

ToolbarCop (Free!)
http://www.mvps.org/sramesh2k/toolbarcop.htm

Bazooka Adware and Spyware Scanner (Free!)
http://kephyr.sureshot.xaviermedia.net/spywarescanner/

Browser Security Tests
http://www.jasons-toolbox.com/BrowserSecurity/

The Cleaner (49.95 and up)
http://www.moosoft.com/

That will clean up your machine of the spyware, given that you download and
install several of them, update them regularly and scan with them when you
update. Some (like SpywareBlaster and SpyBot Search and Destroy) have
immunization features that will help you prevent your PC from being
infected. Use these features!

Unfortunately, although that will lessen your popups on the Internet/while
you are online, it won't eliminate them. I have looked at a lot of options,
seen a lot of them used in production with people who seem to attract popups
like a plague, and I only have one suggestion that end up serving double
duty (search engine and popup stopper in one):

The Google Toolbar (Free!)
http://toolbar.google.com/

Yeah - it adds a bar to your Internet Explorer - but its a useful one. You
can search from there anytime with one of the best search engines on the
planet (IMO.) And the fact it stops most popups - wow - BONUS! If you
don't like that suggestion, then I am just going to say you go to
www.google.com and search for other options.

One more suggestion, although I will suggest this in a way later, is to
disable your Windows Messenger service. This service is not used frequently
(if at all) by the normal home user and in cooperation with a good firewall,
is generally unnecessary. Microsoft has instructions on how to do this for
Windows XP here:
http://www.microsoft.com/windowsxp/pro/using/howto/communicate/stopspam.asp


UPDATES and PATCHES
-------------------

This one is the most obvious. There is no perfect product and any company
worth their salt will try to meet/exceed the needs of their customers and
fix any problems they find along the way. I am not going to say Microsoft
is the best company in the world about this but they do have an option
available for you to use to keep your machine updated and patched from
the problems and vulnerabilities (as well as product improvements in some
cases) - and it's free to you.

Windows Update
http://windowsupdate.microsoft.com/

Go there and scan your machine for updates. Always get the critical ones as
you see them. Write down the KB###### or Q###### you see when selecting the
updates and if you have trouble over the next few days, go into your control
panel (Add/Remove Programs), match up the latest numbers you downloaded
recently (since you started noticing an issue) and uninstall them. If there
was more than one (usually is), install them back one by one - with a few
hours of use in between, to see if the problem returns. Yes - the process
is not perfect (updating) and can cause trouble like I mentioned - but as
you can see, the solution isn't that bad - and is MUCH better than the
alternatives. (SASSER/BLASTER were SO preventable with just this step!)

Windows is not the only product you likely have on your PC. The
manufacturers of the other products usually have updates as well. New
versions of almost everything come out all the time - some are free, some
are pay - some you can only download if you are registered - but it is best
to check. Just go to their web pages and look under their support and
download sections.

You also have hardware on your machine that requires drivers to interface
with the operating system. You have a video card that allows you to see on
your screen, a sound card that allows you to hear your PCs sound output and
so on. Visit those manufacturer web sites for the latest downloadable
drivers for your hardware/operating system. Always (IMO) get the
manufacturers hardware driver over any Microsoft offers. On the Windows
Update site I mentioned earlier, I suggest NOT getting their hardware
drivers - no matter how tempting.

Have I mentioned that Microsoft has some stuff to help secure your computer
available to the end-user for free? This seems as good of a time as any.
They have a CD you can order (it's free) that contain all of the Windows
patches through October 2003 and some trial products as well that they
released in February 2004. Yeah - it's a little behind now, but it's better
than nothing (and used in coordination with the information in this post,
well worth the purchase price..)

Order the Windows Security Update CD
http://www.microsoft.com/security/protect/cd/order.asp

They also have a bunch of suggestions, some similar to these, on how to
better protect your Windows system:

Protect your PC
http://www.microsoft.com/security/protect/


FIREWALL
--------

Let's say you are up-to-date on the OS (operating system) and you have
Windows XP.. You should at least turn on the built in firewall. That will
do a lot to "hide" you from the random bad things flying around the
Internet. Things like Sasser/Blaster enjoy just sitting out there in
Cyberspace looking for an unprotected Windows Operating System and jumping
on it, doing great damage in the process and then using that Unprotected OS
to continue its dirty work of infecting others. If you have the Windows XP
ICF turned on - default configuration - then they cannot see you! Think of
it as Internet Stealth Mode at this point. It has other advantages, like
actually locking the doors you didn't even (likely) know you had. Doing
this is simple, the instructions you need to use your built in Windows XP
firewall can be found here:

http://support.microsoft.com/?kbid=320855

If you read through that and look through the pages that are linked from it
at the bottom of that page - I think you should have a firm grasp on the
basics of the Windows XP Firewall as it is today. One thing to note RIGHT
NOW - if you have AOL, you cannot use this nice firewall that came with
your system. Thank AOL, not Microsoft. You HAVE to configure another
one.. So we continue with our session on Firewalls...

But let's say you DON'T have Windows XP - you have some other OS like
Windows 95, 98, 98SE, ME, NT, 2000. Well, you don't have the nifty built in
firewall. My suggestion - upgrade. My next suggestion - look through your
options. There are lots of free and pay firewalls out there for home users.
Yes - you will have to decide on your own which to get. Yes, you will have
to learn (oh no!) to use these firewalls and configure them so they don't
interfere with what you want to do while continuing to provide the security
you desire. It's just like anything else you want to protect - you have to
do something to protect it. Here are some suggested applications. A lot of
people tout "ZoneAlarm" as being the best alternative to just using the
Windows XP ICF, but truthfully - any of these alternatives are much better
than the Windows XP ICF at what they do - because that is ALL they do.

ZoneAlarm (Free and up)
http://www.zonelabs.com/store/content/company/products/znalm/freeDownload.jsp

Kerio Personal Firewall (KPF) (Free and up)
http://www.kerio.com/kpf_download.html

Outpost Firewall from Agnitum (Free and up)
http://www.agnitum.com/download/

Sygate Personal Firewall (Free and up)
http://smb.sygate.com/buy/download_buy.htm

Symantec's Norton Personal Firewall (~$25 and up)
http://www.symantec.com/sabu/nis/npf/

BlackICE PC Protection ($39.95 and up)
http://blackice.iss.net/

Tiny Personal Firewall (~$49.00 and up)
http://www.tinysoftware.com/

That list is not complete, but they are good firewall options, every one of
them. Visit the web pages, read up, ask around if you like - make a
decision and go with some firewall, any firewall. Also, maintain it.
Sometimes new holes are discovered in even the best of these products and
patches are released from the company to remedy this problem. However, if
you don't get the patches (check the manufacturer web page on occasion),
then you may never know you have the problem and/or are being used through
this weakness. Also, don't stack these things. Running more than one
firewall will not make you safer - it would likely (in fact) negate some
protection you gleamed from one or the other firewalls you ran together.


ANTIVIRUS SOFTWARE
------------------

That's not all. That's one facet of a secure PC, but firewalls don't do
everything. I saw one idiot posting on a newsgroup that "they had
never had a virus and they never run any anti-virus software. Yep - I used
to believe that way too - viruses were something everyone else seemed to
get, were they just stupid? And for the average joe-user who is careful,
uses their one-three family computers carefully, never opening unknown
attachments, always visiting the same family safe web sites, never
installing anything that did not come with their computer - maybe, just
maybe they will never witness a virus. I, however, am a Network Systems
Administrator. I see that AntiVirus software is an absolute necessity. You
can be as careful as you want - will the next person be as careful? Will
someone send you unknowingly the email that erases all the pictures of your
child/childhood? Possibly - why take the chance? ALWAYS RUN ANTIVIRUS
SOFTWARE and KEEP IT UP TO DATE! Antivirus software comes in so many
flavors, it's like walking into a Jelly Belly store - which one tastes like
what?! Well, here are a few choices for you. Some of these are free (isn't
that nice?) and some are not. Is one better than the other - MAYBE. I
personally love Symantec AV.

Symantec (Norton) AntiVirus (~$11 and up)
http://www.symantec.com/

Kaspersky Anti-Virus (~$49.95 and up)
http://www.kaspersky.com/products.html

Panda Antivirus Titanium (~$39.95 and up)
http://www.pandasoftware.com/
(Free Online Scanner: http://www.pandasoftware.com/activescan/)

AVG 6.0 Anti-Virus System (Free and up)
http://www.grisoft.com/

McAfee VirusScan (~$11 and up)
http://www.mcafee.com/

AntiVir (Free and up)
http://www.free-av.com/

avast! 4 (Free and up)
http://www.avast.com/

Trend Micro (~$49.95 and up)
http://www.trendmicro.com/
(Free Online Scanner:
http://housecall.trendmicro.com/housecall/start_corp.asp)

Did I mention you have to not only install this software, but also keep it
updated? You do. Some of them (most) have automatic services to help you
do this - I mean, it's not your job to keep up with the half-dozen or more
new threats that come out daily, is it? Be sure to keep whichever one you
choose up to date!


SPAM EMAIL/JUNK MAIL
--------------------

This one can get annoying, just like the rest. You get 50 emails in one
sitting and 2 of them you wanted. NICE! (Not.) What can you do? Well,
although there are services out there to help you, some email
servers/services that actually do lower your spam with features built into
their servers - I still like the methods that let you be the end-decision
maker on what is spam and what isn't. If these things worked perfectly, we
wouldn't need people and then there would be no spam anyway - vicious
circle, eh? Anyway - I have two products to suggest to you, look at them
and see if either of them suite your needs. Again, if they don't, Google is
free and available for your perusal.

SpamBayes (Free!)
http://spambayes.sourceforge.net/

Spamihilator (Free!)
http://www.spamihilator.com/

As I said, those are not your only options, but are reliable ones I have
seen function for hundreds+ people.


DISABLE (Set to Manual) UNUSED SERVICE/STARTUP APPS
---------------------------------------------------

I might get arguments on putting this one here, but it's my spill. There are
lots of services on your PC that are probably turned on by default you don't
use. Why have them on? Check out these web pages to see what all of the
services you might find on your computer are and set them according to your
personal needs. Be CAREFUL what you set to manual, and take heed and write
down as you change things! Also, don't expect a large performance increase
or anything - especially on todays 2+ GHz machines, however - I look at each
service you set to manual as one less service you have to worry about
someone exploiting. A year ago, I would have thought the Windows Messenger
service to be pretty safe, now I recommend (with addition of a firewall)
that most home users disable it! Yeah - this is another one you have to
work for, but your computer may speed up and/or be more secure because you
took the time. And if you document what you do as you do it, next time, it
goes MUCH faster! (or if you have to go back and re-enable things..)

Task List Programs
http://www.answersthatwork.com/Tasklist_pages/tasklist.htm

Black Viper's Service List and Opinions (XP)
http://www.blackviper.com/WinXP/servicecfg.htm

Processes in Windows NT/2000/XP
http://www.reger24.de/prozesse/

There are also applications that AREN'T services that startup when you start
up the computer/logon. One of the better description on how to handle these
I have found here:

Startups
http://www.pacs-portal.co.uk/startup_content.php


That's it. A small booklet on how to keep your computer secure, clean of
scum and more user friendly. I am SURE I missed something, almost as I am
sure you won't read all of it (anyone for that matter.) However, I also
know that someone who followed all of the advice above would also have less
problems with their PC, less problems with viruses, less problems with spam,
less problems with spyware and better performance than someone who didn't.

Hope it helps.
 
G

Guest

My windows internet connection firewall is already
enabled, and i am running mcafee firewall 4, as I said
already.
 
J

J Stutzmann

Upgrade to Spybot 1.3 and download the most current definitions for it.

get CWSweaper (free) and run that too

Make sure your firewall and virus scanner are all current

Check that all your other programs are current [ad-aware 6.0 just had a
definitions file update yesterday fir instance]

Wishing you the best.
 
J

Jim Byrd

Hi Zeretul - There are currently two classes of things going on that are
causing people popup difficulties. If you get popups even when your browser
is not connected to the Internet with a title bar reading "Messenger
Service", then these are most likely due to open NetBios TCP ports 135, 139
and 445 and UDP ports 135, 137-138 and a UDP port in the range of
1026-1029.. You really need to block these with a firewall as a general
protection measure. You can stop the popups by turning off Messenger
Service; however, this still leaves you vulnerable. If you have an NT-based
OS such as XP or Win2k, you should probably also specifically block TCP
593, 4444 and UDP 69, 139, 445, and install the very important 824146 patch
from MS03-039, here: http://support.microsoft.com/default.aspx?kbid=824146
to block the Blaster worm as well as several other parasites.


See: Messenger Service Window That Contains an Internet Advertisement
Appears http://support.microsoft.com/?id=330904 which identifies reasons to
keep this service and steps to take if you do.

You can test your system and follow the 'Prevention' link to get additional
information here:
http://www.mynetwatchman.com/winpopuptester.asp Unless you have very good
reasons to keep this active, it should be turned off in Win2k and XP. Go
here and do what it says:
http://www.itc.virginia.edu/desktop/docs/messagepopup/ or, even better, get
MessageSubtract, free, here, which will give you flexible control of the
service and viewing of these messages:
http://www.intermute.com/messagesubtract/help.html Recommended.

(FWIW, ZoneAlarm's default Internet Zone firewall configuration blocks the
necessary ports to prevent this use of Messenger Service. I don't know the
situation with regard to other firewalls.)

Messenger Service is not per se Spyware or something that MS did wrong - It
provides a messaging capability which is useful for local intranets and is
also sometimes (albeit nowdays infrequently) used by some applications to
provide popup messages to users. However, it can also be (and now frequently
is) used to introduce spam via this open NetBios channel.
For a single user home computer, it normally isn't needed and can be turned
off which will eliminate the spam popups. This DOESN'T, however, remove the
vulnerability of having these ports open, when in fact they aren't needed,
since they can be perverted in other ways as well, some of which can be much
more damaging than just a spam popup.



If you're getting a lot of popups while surfing, then the following may be
useful:

Popups - Get Ad-Aware 6.0, Build 181 or later, here:
http://www.lavasoftusa.com/support/download/. UPDATE and run this regularly
to get rid of most "spyware/hijackware" on your machine. If it has to fix
things, be sure to re-boot and rerun AdAware again and repeat this cycle
until you get a clean scan. The reason is that it may have to remove
things which are currently "in use" before it can then clean up others.

Another excellent program for this purpose is SpyBot Search and Destroy
available here: http://security.kolla.de/ SpyBot Support Forum here:
http://www.net-integration.net/cgi-bin/forums/ikonboard.cgi. I recommend
using both normally. After UPDATING and fixing things with SpyBot S&D, be
sure to re-boot and rerun SpyBot again and repeat this cycle until you get a
clean "no red" scan. The reason is that SpyBot sometimes has to remove
things which are currently "in use" before it can then clean up others.

Note that sometimes you need to make a judgement call about what these
programs report as spyware. See here, for example:
http://www.imilly.com/alexa.htm

Both of these programs should normally be UPDATED and run after doing any
other fix such as CWShredder and, as a minimum, normally at least once a
week.


Then, there are a variety of third party "Popup Killers" available. I
normally use AdShield, which, if you maintain its Block List every now and
then, almost totally stops this. In addition, it stops a variety of
ads/banners/etc. (particularly spyware like doubleclick) on pages I access.
This is probably all you'll need; however, I've also investigated a program
called webwasher which appears to be very good, but decided that AdShield
was sufficient. At the bottom of this post, you'll find a list provided
courtesy of bc_acadia of a number of free popup blockers with links.

****** NOTE: As of 28 Apr 03 AdShield appears to have partnered with a new
reseller, and AdShield is no longer free. There is a trial version of
AdShield3; however, IMO it is seriously crippled in not being able to import
or export block lists and I think for reasonable utility one would have to
go to the full version. While I don't normally recommend non-free software,
I personally will continue to use AdShield3, since I think it is the best
currently available combined Popup/Ad/Malware blocker, but you should be
aware of the fact that it now costs, ($29.95), whereas the earlier versions
upon which I based my original recommendation were free, although not nearly
as capable as the AdShield3 release. I've included below links to both the
older free version and the new paid version. You'll have to investigate and
make your own choice in the matter. *******

Here are a number of AdShield-related links:

http://www.fsd1.org/technology/Files/AdShield.exe - AdShield1.2 (free)
http://www.internettechs.net/utilities/AdShield.exe - AdShield1.2 (free)
http://ftp.ural.ru/home/index/windows/networking/utils/AdShield -
AdShield1.2 (free)
http://www.megalog.ru/info/utilz/AdShield.zip - AdShield1.2 (free)
http://www.allstarss.com/store/adshield.html - AdShield3
http://www.mvps.org/winhelp2002/block.txt - (Mike Burgess' .txt Block List
for AdShield)
http://www.mvps.org/winhelp2002/block.zip - Mike Burgess' Zipped Block List
for AdShield - Recommended)
http://adshield.briankass.com/blocklists.html (lists a number of blocklists)
http://adshield.briankass.com/blocklist.abl (brian's blocklist in .abl
format)
http://adshield.briankass.com/blocklist.txt (brian's blocklist in .txt
format)
http://www.songwave.com/software/adshield_blocklist.txt (40,000 pornsites
blocked - *VERY* large list - use at your own risk)
http://www.chrismyden.com/temp/block.abl (chrismyden's blocklist in .abl
format)
http://www.staff.uiuc.edu/~ehowes/resource.htm#AdShield (Eric Howes AGNIS
for AdShield block list - Recommended) (BTW, Eric's site contains a wealth
of very valuable information about all aspects of net security - Very Highly
Recommended)

There's also a new AdShield forum here:
http://users.boardnation.com/~adshield/index.php

Here's a good AdShield test site, courtesy of siljaline: "Make ***SURE***
you have your block scripted popups enabled
http://www.mediaboy.net/1010100-1100001-1111010/gahk/>>>> [Warning this URL
opens a multitude of Browser windows almost instantly]"

http://www.webwasher.com - Webwasher


Additionally, some people have recommended Popup Stopper and PopupBuster,
but they have also been reported or experienced to cause perceived problems
for some people with "normal" links in IE6 such as Google search results and
links from OE. Some proponents of PopupBuster assert, however, that this is
normal operation for this program under
certain circumstances which can be overridden if necessary. YMMV Another
"Proxy" type blocker similar to Webwasher and Proxomitron but supposedly a
bit easier to configure is Privoxy here: http://www.privoxy.org/ Also, the
free Google Tool Bar has a builtin popup blocker which fairly effective.

Also, if you're comfortable allowing changes to the registry, there is an
approach, IE-SPYAD, using the restricted sites list which can be used for
scripted popups. I use this and it works very well. See here:
http://www.staff.uiuc.edu/~ehowes/resource.htm

There is additonal information about setting up and using AdShield, and
about using the Restriced Zone (and an additional list) here:
http://www.mvps.org/winhelp2002/hosts.htm and some of the Frequently Asked
Questions (FAQ's) about AdShield here: http://adshield.briankass.com

Lastly, ZoneAlarmPro3/4 has added provisions for stopping adds/popups,
handling cookies, web bugs, and scripting/ActiveX components in addition to
it's firewall functionality. Not free, but I have used it with my other
AdBlocking stuff (AdShield, etc.) turned off as a test, and it appears to be
very good indeed. So far I've experienced no problems at
all with it set in its High Security modes for Ads although others have
reported the need to temporarily turn it off to reach some sites. Also,
Agnitum's Outpost Firewall supports a plug-in for this: "Pre-configured to
block most banner advertisement. Can be configured manually or by simply
dragging and dropping unwanted banners into the Ad Trashcan." I
have no experience as to how effective it is, but I have received a
favorable report.

There's good information about hijacking in general and fixes available for
specific hijackers here: http://www.spywareinfo.com/hijacked.html
http://gmpservicesinc.com/Articles/hijack.asp
http://www.mvps.org/inetexplorer/Darnit.htm#pop_up
http://www.doxdesk.com/parasite/

bc_acadia's list:

"Some popup blockers. All of these are 100% pure freeware, no trial
periods. Some of these do more than just handle popups.

Pow!: http://www.analogx.com/contents/download/network/pow.htm
NoAds: http://www.southbaypc.com/NoAds/
PopupEraser: http://www.webknacks.com/popuperaser.htm
Stop-the-Pop: http://www.bysoft.se/sureshot/stopthepop/index.html
Internet Organizer: http://www.sf.yucom.be/wdprojects/
PopKi: http://ranfo.com/popki.html
PopUpPopper: http://www.bayden.com/Popper/default.asp
PopUpKiller: http://sourceforge.net/projects/puk/
AdCruncher Proxy:
http://home.sprintmail.com/~dtrout/AdCruncher/ReadMe.html
KillAd: http://www.wplus.net/pp/fsc/
ClickOff: http://www.johanneshuebner.com/en/download.html
PopupBuster: http://www.popupbuster.com/PopUpBuster/
Free Surfer: http://www.kolumbus.fi/eero.muhonen/FS/
Window Shades: http://www.g-m-m.com/Software/WindowShades/index.php
AdShield (my personal favorite): http://www.adshield.org/
PopupStopper: http://www.panicware.com/popupstopper.html
Proxomitron (has learning curve): http://www.proxomitron.org/
For those who don't want third party stuff, your own pc's built-in
host file:
http://www.mvps.org/winhelp2002/hosts.htm and
http://www.smartin-designs.com/ and http://www.accs-net.com/hosts/


Here is a review of 61 popup killers, not all of them are free:
http://www.popup-killer-review.com/index.htm"

NOTE that this site also contains a good, comprehensive series of popup
killer tests. Some good additional tests are also available here:
http://www.webknacks.com/aptest.htm

There's another popup test page here:
http://www.kephyr.com/popupkillertest/index.html


Another good test page and lists of both free and cost popup blockers is
here: http://www.popuptest.com/ Recommended


Finally, there's a new class of hijacker using Window's Messenger Service
(not Instant Messaging, BTW) that I discussed at first.


Note that this symptom often indicates the possibility of other malware.
You might want go to this page at Jim Eshelman's site, here:
http://aumha.org/a/noads.htm or here:
http://inetexplorer.mvps.org/parasite.htm and wait a little bit (be
patient), while an analysis of a number of possible parasites on your
machine will be made to help you identify and remove them. NOTE: You will
need to disable Ad Blocking in Zone Alarm 3.x, if present or any other Ad
Blocking software which interferes with Java Scripting for this scan to
work. You should get a message between the two lines of **** giving the
results of the scan.


You might want to consider installing the SpywareBlaster and SpywareGuard
here to help prevent this kind of thing and other malware from happening in
the future:
http://www.javacoolsoftware.com/spywareblaster.html (Prevents malware Active
X installs) (BTW, SpyWare Blaster is not memory resident ... no CPU or
memory load - but keep it updated) The latest version as of this writing
will prevent installation or prevent the malware from running if it is
already installed, and it provides information and fixit-links for a variety
of parasites.
http://www.wilderssecurity.net/spywareguard.html (Monitors for attempts to
install malware) Both Very Highly Recommended.

Perhaps these will help.

--
Please respond in the same thread.
Regards, Jim Byrd, MS-MVP



In
 
F

Foopy

I suggest using a small program called HijackThis. It looks for any
changes made to the registry that are not normally created with a
Windows install. One thing, You have to be careful with it. It list
ALL changes to the registry including legitimate entries added by
software you may have intentionally installed, etc. It will show you
those changes and give you the option to delete them.

Foopy

Foopy


WARNING!!
The toes you step on today may be attached
to the ASS you have to kiss tomorrow!
 
B

bullwinkel J. Moose

Have you tried symantec's on line firewall check? It's free and will tell
you which ports are open and where you are vulnerable. Obvoiusly something
is getting through. You may have a program that is opening up and calling
out saying hey here I am I want you to visit. I don't hold much stock in
MacAffee products or symantec products. But ZA 4.5 which is free will close
all ports so you are protected.

you didn't mention if you are disconnected from your broadband (remove the
phone plug while you check using adaware and spybot. Also run CWS which will
check out those trojans/worms and adware/malware. The idea is to be
disconnected physically. then reboot and run these programs again. Some of
these problem s are in memory and need to be rerally cleaned out. Then
install ZA 4.5 (free_ and you should be clean. It takes persistence.

Good luck
 
Z

zeretul1

Ok, I know ZA 4.5 is ZoneAlarm, but what is CWS?
Also, I did run all my progs when i was physically disconnected. They
now include:
Spybot 1.3
Aluria Spyware Eliminator
Reg Mechanic
Pest Patrol
Spyware Blaster
Ad-Aware 6.0
Bazooka Spyware scanner

I also ran these while disconnected a second time after reboot.
I am still having my problem.
I tested my firewall with the symantec's online firewall checker, and
it found about 17 ports, all filtered.

So, now what. Aside from reformatting and reinstalling, what else can
I do??
 
Z

zeretul1

Did everything on that list, except for removing my mcafee firewall
and adding zonealarm, but i am still having the same problem.
 
Z

zeretul1

Have tried several posts on spywareinfo.com, and have
gotten no! replies. This sucks. I have used:
Aluria's spyware eliminator
Pest Patrol
Spybot search and destroy 1.2
Ad-aware 6.0
Spysweeper
Reg Mechanic

None of these programs have helped. I am constantly
finding new reg keys, spyware progs and the like, but the
problem is on-going.

This is my main symptom. Randomly, IE windows, full
windows, will open with advertisements ranging from anti-
0spyware progs to singles site. These occur whether or
not I am browsing the internet, and often occur 3-4 times
at once.

I am on a cable broadband connection, and am using McAfee
virusscan 7 and firewall 4.

I need some help here. Either I eliminate the problem, or
re-format the C: drive.
 
A

Alexander Grigoriev

Don't work logged in as an administrator or an user with adminirtrator
privileges. Change your user account to "Limited User" type. Assuming your
system drive is NTFS, viruses won't be able to damage your system.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Similar Threads


Top