CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

Unwanted Spyware loading when IE starts up
Goto page 1, 2  Next
 
Post new topic   Reply to topic       All -> FavForums -> Trend Micro HijackThis Logs [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
rbk

Guest
IP: 68.48.*.*






PostPosted: Thu Aug 28, 2003 8:48 pm    Post subject: Unwanted Spyware loading when IE starts up
Reply with quote

Hi There,

I appreciate being able to post even though I am not a registered member. I am hoping someone can enlighten me about a solution to a annoying and persistent problem that I am having.

I am having problems with Spyware and pop up add engines loading when I start IE. I have removed all traces from my general system using ad-aware and Spybot S&D and things are fine if I don't use IE. The first time I use IE, it seems to be downloading the offensive software again and the pop ups start. Any ideas how I can disable this.

Thanks,

Back to top
Jamming

Colonel
Colonel
Premium Member

Joined: Jun 22, 2002
Posts: 1874

Premium

PostPosted: Thu Aug 28, 2003 11:26 pm    Post subject:
Reply with quote

Sounds like a BHO a browser helper object, either that or are they pop-ups boxes with just text in them they could be RPC pop-ups. You might want to download SpywareBlaster or one of the other free Prevention Spyware. Check Spyware Updates for the names of several and their update frequency.

Spybot S&D in the Tools Section there is a choice to list your BHO's. Read the section information.

RPC can be disabled unless you do a lot of printing over the internet. Do a search for "disabling RPC pop-ups" that should lead you to a website with instructions or a little batch file to change those settings.

Back to top
View users profile Send private message
rbk

Guest
IP: 68.48.*.*






PostPosted: Thu Aug 28, 2003 11:33 pm    Post subject: I think I have narrowed it down to some Toolbars
Reply with quote

Hi there Jamming,

I noticed there are two toolbars installed in my IE that have not text and just appear as a blank line in the toolbar list. I think they may be autoloading the files somehow. Any ideas on how to get rid of them?

I did try Spbot S&D and it didn't find this particular problem.

Back to top
Jamming

Colonel
Colonel
Premium Member

Joined: Jun 22, 2002
Posts: 1874

Premium

PostPosted: Fri Aug 29, 2003 1:58 am    Post subject:
Reply with quote

The Toolbars are probably added to your registry, number one: open your internet options in the IE toolbar, select it: then go to the advance tab at the top and select it: go down to browser section and make sure install on demand is not selected (both of them). This should help in the future.

To get rid of these problems I am going to need more information, so which Windows are you using?

Back to top
View users profile Send private message
Rik

Sergeant
Sergeant


Joined: Apr 25, 2003
Posts: 77
Location: USA

PostPosted: Fri Aug 29, 2003 12:29 pm    Post subject:
Reply with quote

You might also be able to get rid of them thru Add/Remove. I realize it sounds too simple but sometimes the "rogue" toolbars that install are listed. Possibly also removing them from startup thru MSCONFIG might work just to stop them from running.


_________________

*Toujours Pret*
Back to top
View users profile Send private message Visit posters website
rbk

Guest
IP: 68.48.*.*






PostPosted: Fri Aug 29, 2003 6:05 pm    Post subject: version of IE and Windows
Reply with quote

Hi Jamming,

I am running Windows 2000 Server and IE 6.1 (the version that got infected was IE 5.5 SP2 I believe. Thanks again for all the help.
As part of my debugging efforts, I "repaired" Windows 2000 which uninstalled a bunch of stuff. I have disconnected the computer from the internet and I have noticed that a web browser window pops up during start up that attempts to go to the following URL: http://www.popupad.net/ats/switch.php. I have never installed anything that would use that resource and I am suspicious that this may be the culprit. I wonder if it tries to launch this every time I startup or just because I repaired Windows 2000 and now its trying to re-install itself. I have looked in the Add/Remove Programs under control panel and nothing obvious jumps out at me that needs to be un-installed.

rbk

Back to top
Jamming

Colonel
Colonel
Premium Member

Joined: Jun 22, 2002
Posts: 1874

Premium

PostPosted: Fri Aug 29, 2003 8:28 pm    Post subject:
Reply with quote

rbk, I am not that familiar with Win2000, but I think that the idea to use MSCONFIG to remove them from the start up list is a good idea. Once you figure out which Registry Key that is starting it up form MSCONFIG, then you should go into regedit and do a registry search for any similar sort of entries, remember to back-up/export your original registry before making these changes.

Back to top
View users profile Send private message
yb7

Guest
IP: 195.174.*.*






PostPosted: Wed Oct 29, 2003 6:50 pm    Post subject:
Reply with quote

http://securityresponse.symantec.com/avcenter/venc/data/trojan.bootconf.html

I had a similar problem and FINALLY fixed it! I have re-installed norton2003 with updates available. Run a scan and cleaned my computer

I hope this would help.

Back to top
!claire

General
General
Premium Member

Joined: Apr 21, 2002
Posts: 8380

Premium

PostPosted: Wed Oct 29, 2003 6:59 pm    Post subject:
Reply with quote

Hiyb7,

You could also give a try to Spywareguard(available at our "download "
section under "Spywares") it's a very effective preventive tool Smile

Back to top
View users profile Send private message
Deadkenny

Cadet
Cadet


Joined: Oct 29, 2003
Posts: 1
Location: USA

PostPosted: Wed Oct 29, 2003 9:16 pm    Post subject:
Reply with quote

I was working on a PC 2 days ago and I also ran into that URL. The only thing that fixed the computer was installing Norton 2003, getting all the updates and running a scan. Norton was able to clean it up well. For the rest of the critters that were on the PC Spybot and AdAware did a good job. That one URL redirector is a pain to get rid of though.

DK

Back to top
View users profile Send private message
!claire

General
General
Premium Member

Joined: Apr 21, 2002
Posts: 8380

Premium

PostPosted: Wed Oct 29, 2003 9:28 pm    Post subject:
Reply with quote

This one is also a very effective preventive tool(freeware)

http://www.staff.uiuc.edu/~ehowes/resource.htm

Back to top
View users profile Send private message
!Mariner

Colonel
Colonel
Premium Member

Joined: Aug 25, 2003
Posts: 1914

Premium

PostPosted: Thu Oct 30, 2003 5:43 pm    Post subject:
Reply with quote

Might l also suggest BHO Demon, a vey useful little tool for identifying BHO's that allows you to disable and re-enable if required.

It's free and you can get it from:

http://www.definitivesolutions.com/

Back to top
View users profile Send private message
Jamming

Colonel
Colonel
Premium Member

Joined: Jun 22, 2002
Posts: 1874

Premium

PostPosted: Thu Oct 30, 2003 7:27 pm    Post subject:
Reply with quote

Spybot S&D also includes a BHO Tool if you have all ready downloaded and installed that on your machine.

Back to top
View users profile Send private message
phoenix22

Welcome back our old Site Admin
Premium Member

Joined: Mar 08, 2002
Posts: 4661
Location: APO SF96383
Premium

PostPosted: Fri Oct 31, 2003 2:10 pm    Post subject:
Reply with quote

and yet another..........hi-jack this......is a good app to find these as well.......


_________________
101st Abn Div. (AirAssault) "Rendezvous With Destiny!" "Night Stalkers/Phoenix Flight" For Buddy...who lived it! Whiskey for my men and beer for my horses! H.A.L.O!, 5th Grp., MACV-SOG, 160th AVN Grp., VFW
Back to top
View users profile Send private message Visit posters website
phoenix22

Welcome back our old Site Admin
Premium Member

Joined: Mar 08, 2002
Posts: 4661
Location: APO SF96383
Premium

PostPosted: Fri Oct 31, 2003 4:55 pm    Post subject:
Reply with quote

hi jack this is here:

http://www.tomcoyote.org/hjt/


_________________
101st Abn Div. (AirAssault) "Rendezvous With Destiny!" "Night Stalkers/Phoenix Flight" For Buddy...who lived it! Whiskey for my men and beer for my horses! H.A.L.O!, 5th Grp., MACV-SOG, 160th AVN Grp., VFW
Back to top
View users profile Send private message Visit posters website
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Trend Micro HijackThis Logs All times are GMT
Goto page 1, 2  Next
Page 1 of 2

 
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer