Go Back   Viper Alley - Dodge Viper Forum » Back Alley » Anything Goes
» Live Feed « · War Room · Graffiti Wall · Chat · Arcade · Viper Blogs · » Viper Tube «

Anything Goes Well, almost anything. Bring your A game or be sent home.

       

Need help removing Spyware !! AHHHH!!

Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 

Reply
 
Thread Tools Display Modes

Need help removing Spyware !! AHHHH!!
Old February 9th, 2006, 12:05 PM   #1
Yellow Fever
Senior Member
 
Yellow Fever's Avatar
 
Yellow Fever is offline
Join Date: Aug 2003
Posts: 2,299
Yellow Fever is kissing alot of ass around here with 530 pointsYellow Fever is kissing alot of ass around here with 530 pointsYellow Fever is kissing alot of ass around here with 530 pointsYellow Fever is kissing alot of ass around here with 530 pointsYellow Fever is kissing alot of ass around here with 530 pointsYellow Fever is kissing alot of ass around here with 530 points
Rep Power: 9
Angry Need help removing Spyware !! AHHHH!!

This F***ING Spyware Virus is going to drive me over the edge..My laptop has been infected with a Virus that hijacks my explorer and routes it to a security software page..I'm also getting continous Pop ups that link me to a software program called ADWARE SHERIFF.
I've tried Spybot,Xoftspy,NOD32 ..All with no luck.

Any help would be greatly appreciated!

Tks

J
  Reply With Quote

Old February 9th, 2006, 12:06 PM   #2
E-Slab
Senior Member
 
E-Slab's Avatar
 
E-Slab is offline
Join Date: Jan 2003
Posts: 12,939
E-Slab made Varsity with 1457 pointsE-Slab made Varsity with 1457 pointsE-Slab made Varsity with 1457 pointsE-Slab made Varsity with 1457 pointsE-Slab made Varsity with 1457 pointsE-Slab made Varsity with 1457 pointsE-Slab made Varsity with 1457 pointsE-Slab made Varsity with 1457 pointsE-Slab made Varsity with 1457 pointsE-Slab made Varsity with 1457 points
Rep Power: 21
WHERE THE FUCK IS MANNY?!?!


  Reply With Quote

Old February 9th, 2006, 12:09 PM   #3
Whitebeard
HAVE SCUBA WILL TRAVEL
 
Whitebeard's Avatar
 
Whitebeard is offline
Join Date: May 2003
Posts: 14,152
Whitebeard is The Man with 2086 pointsWhitebeard is The Man with 2086 pointsWhitebeard is The Man with 2086 pointsWhitebeard is The Man with 2086 pointsWhitebeard is The Man with 2086 pointsWhitebeard is The Man with 2086 pointsWhitebeard is The Man with 2086 pointsWhitebeard is The Man with 2086 pointsWhitebeard is The Man with 2086 pointsWhitebeard is The Man with 2086 pointsWhitebeard is The Man with 2086 points
Rep Power: 26
Send a message via AIM to Whitebeard Send a message via Yahoo to Whitebeard
his application is adware. Adware is not normally a threat, but is usually considered a nuisance. It might have been installed by another application. It can pop up advertisements even if you have a popup blocker on your computer. It can monitor your computer usage to generate ads that you are more likely to respond to. Adware can consume processing power and network bandwidth, thus slowing down your computer and interrupting your workflow.



WARNING: The following fixes were recommended by readers and I have not tested them. This information is provided on an "as-is" basis only, and I make no guarantees. Anytime you manually alter system settings, you run the risk of damaging your operating system and rendering your computer inoperable.

Please note that SpywareStrike is closely related to SpyAxe, and when SpyAxe is manually deleted a new trojan is installed. It is quite possible that SpywareStrike does the same, so following this procedure may expose you to other malware.

Method #1

This was the first removal method we discovered, but it will probably not work with the latest version of Spyware Strike. Even with the first version, some readers report that the flashing red alerts remain running with this technique.

1. Search and delete all references to "SpywareStrike" in registry. Note that you’ll find a reference to a file called "C:\Documents and Settings\\Local Settings\Temp\~nsf.temp\Au__.exe" or something similar.
2. Delete the file referenced above
3. Go to c:\program files\spyware strike and run the uninstall utility
4. go to task manager and kill the process spywarestrike.exe
5. Delete c:\program files\spyware strike
6. edit c:\windows\system32\drivers\etc\hosts to add the line "127.0.0.1 spywarestrike.com" (this will prevent the piece that I could not get rid of from automatically downloading the software again and again)

Thanks to Jason Burroughs for this fix.

Method #2

A simpler solution, but more likely to leave behind hidden trojans, etc. This method is highly unlikely to work with the latest versions.

1. Boot computer into safe mode.
2. Uninstall SpywareStrike using the SpywareStrike uninstall utility.
3. Delete the file netwrap.dll from the \windows\system32 directory.

Method #3

If SpywareStrike reappears after trying the previous methods...

1. Boot computer into safe mode.
2. Delete the file mssearchnet.exe from the \windows\system32 directory.

Method #4

Another method that has worked for some readers but not others is to use a combination of tools:

1. Download SmitRem at www.downloads.subratam.org/smitRem.exe

2. Reboot into safe mode and run SmitRem. Check "Delete at Reboot".

3. Immediately run a full scan with your favorite spyware remover to remove incidental trojans and dialers that may have been installed.

Method #5: New Versions of Spyware Strike (updated Jan 30, 2006)

Two new versions of Spyware Strike are on the loose, and the above instructions aren't working for a lot of people. There are some other things to try, but I should warn you that these instructions are *not* for the faint-of-heart. If you don't know what you are doing, then you should definitely just wait for the next update of Aluria Antispyware or Spy Doctor, as both tools seem to be doing a decent job of keeping up with the new releases.

As you can probably tell from the instructions below, the latest version is infinitely more sophisticated than the prior ones. Spyware Strike may be the CoolWebSearch of 2006.

1. Look for new WAN network adapters named IIRC. These were installed by SpywareStrike and are probably how it manages to tunnel through any firewall software.

2. Backup and then remove the following files in the infected user's documents and settings folder:

\UserData\8R4F2NQZ with file oWindowsUpdate[1].xml
\UserData\AH0N2NIN with file oWindowsUpdate[1].xml
\UserData\O1UTE7EV no files
\UserData\OBY9QTQ1 no files

3. Delete registry entry: HKEY_USERS\S-1-5-21-175XXXXXXX-XXXXXX_Classes\Software\Windows\CurrentVersio
n\Deployment\SideBySide\2.0 (and sub-entries)

4. Rename the normal user account, reboot, and then rename it back to the original name.

This has been reported to successfully disable those stubborn alert windows.
__________________
never be the slowest gazelle
  Reply With Quote

Old February 9th, 2006, 12:13 PM   #4
GeneralChaos
Enthusiast
 
GeneralChaos is offline
Join Date: Aug 2005
Posts: 55
GeneralChaos is a B-Teamer with 53 points
Rep Power: 0
try microsoft anti spyware. not a garaunteed fix or guard, but ive been using it (while its beta before they turn it into microsoft pc health) and so far so good.

I use firefox/Antivir/sygate personal firewall pro/microsoft antispyware, and have yet to get anything. All of these are free minus sygate, my friends claim they suck but hey, im not the one formatting my computer every month.
  Reply With Quote

Old February 9th, 2006, 12:21 PM   #5
Whitebeard
HAVE SCUBA WILL TRAVEL
 
Whitebeard's Avatar
 
Whitebeard is offline
Join Date: May 2003
Posts: 14,152
Whitebeard is The Man with 2086 pointsWhitebeard is The Man with 2086 pointsWhitebeard is The Man with 2086 pointsWhitebeard is The Man with 2086 pointsWhitebeard is The Man with 2086 pointsWhitebeard is The Man with 2086 pointsWhitebeard is The Man with 2086 pointsWhitebeard is The Man with 2086 pointsWhitebeard is The Man with 2086 pointsWhitebeard is The Man with 2086 pointsWhitebeard is The Man with 2086 points
Rep Power: 26
Send a message via AIM to Whitebeard Send a message via Yahoo to Whitebeard
MS stuff should be removed afterwards...We have had many instances of it eating too much memory and killing systems off.
  Reply With Quote

Old February 9th, 2006, 01:21 PM   #6
getbit
STFU
 
getbit's Avatar
 
getbit is offline
Join Date: Jan 2003
Posts: 6,603
getbit is The Man with 1622 pointsgetbit is The Man with 1622 pointsgetbit is The Man with 1622 pointsgetbit is The Man with 1622 pointsgetbit is The Man with 1622 pointsgetbit is The Man with 1622 pointsgetbit is The Man with 1622 pointsgetbit is The Man with 1622 pointsgetbit is The Man with 1622 pointsgetbit is The Man with 1622 pointsgetbit is The Man with 1622 points
Rep Power: 19
Cool

Quote:
Originally Posted by E-Slab
WHERE THE FUCK IS MANNY?!?!


did you ever clean yours?
  Reply With Quote

Old February 9th, 2006, 01:25 PM   #7
JGK95
Walk with a Purpose
 
JGK95's Avatar
 
JGK95 is offline
Join Date: Jan 2003
Location: Chicago
Posts: 5,801
JGK95 is The Man with 1807 pointsJGK95 is The Man with 1807 pointsJGK95 is The Man with 1807 pointsJGK95 is The Man with 1807 pointsJGK95 is The Man with 1807 pointsJGK95 is The Man with 1807 pointsJGK95 is The Man with 1807 pointsJGK95 is The Man with 1807 pointsJGK95 is The Man with 1807 pointsJGK95 is The Man with 1807 pointsJGK95 is The Man with 1807 points
Rep Power: 20
Sorry if I'm late. Can I help?
  Reply With Quote

Old February 9th, 2006, 01:47 PM   #8
Viper TT
Senior Member
 
Viper TT's Avatar
 
Viper TT is offline
Join Date: Apr 2003
Posts: 843
Viper TT made Varsity with 1165 pointsViper TT made Varsity with 1165 pointsViper TT made Varsity with 1165 pointsViper TT made Varsity with 1165 pointsViper TT made Varsity with 1165 pointsViper TT made Varsity with 1165 pointsViper TT made Varsity with 1165 pointsViper TT made Varsity with 1165 pointsViper TT made Varsity with 1165 points
Rep Power: 13
J,

Try the Lavasoft Ad-Aware. It has worked very well for me.

http://www.lavasoftusa.com/software/adaware/
  Reply With Quote

Old February 9th, 2006, 01:49 PM   #9
AUSTIN
Derriere Extraordinaire
 
AUSTIN's Avatar
 
AUSTIN is offline
Join Date: Jul 2003
Location: Houxico, Tejas
Posts: 8,036
AUSTIN is The Man with 1723 pointsAUSTIN is The Man with 1723 pointsAUSTIN is The Man with 1723 pointsAUSTIN is The Man with 1723 pointsAUSTIN is The Man with 1723 pointsAUSTIN is The Man with 1723 pointsAUSTIN is The Man with 1723 pointsAUSTIN is The Man with 1723 pointsAUSTIN is The Man with 1723 pointsAUSTIN is The Man with 1723 pointsAUSTIN is The Man with 1723 points
Rep Power: 21
Jeff, I tried sending you something from Lamo-Power, but your e-mail sent it back. What I have will likely fix your problem.
  Reply With Quote

Old February 9th, 2006, 04:26 PM   #10
BWoodbury
Dirty Old Man
 
BWoodbury's Avatar
 
BWoodbury is offline
Join Date: May 2004
Posts: 886
BWoodbury made Varsity with 818 pointsBWoodbury made Varsity with 818 pointsBWoodbury made Varsity with 818 pointsBWoodbury made Varsity with 818 pointsBWoodbury made Varsity with 818 pointsBWoodbury made Varsity with 818 pointsBWoodbury made Varsity with 818 points
Rep Power: 10
Try HiJackThis, It requires a bit of knowledge, but it works!
  Reply With Quote

Old February 9th, 2006, 04:46 PM   #11
Buckeye Viper
Senior Member
 
Buckeye Viper's Avatar
 
Buckeye Viper is offline
Join Date: Oct 2003
Posts: 1,023
Buckeye Viper hangs with the Hiddens with 661 pointsBuckeye Viper hangs with the Hiddens with 661 pointsBuckeye Viper hangs with the Hiddens with 661 pointsBuckeye Viper hangs with the Hiddens with 661 pointsBuckeye Viper hangs with the Hiddens with 661 pointsBuckeye Viper hangs with the Hiddens with 661 points
Rep Power: 9
hijackthis for the win!
  Reply With Quote

Old February 9th, 2006, 04:47 PM   #12
viper spray
Senior Member
 
viper spray's Avatar
 
viper spray is offline
Join Date: Jan 2003
Location: Austin Texas
Posts: 10,932
viper spray is The Man with 2462 pointsviper spray is The Man with 2462 pointsviper spray is The Man with 2462 pointsviper spray is The Man with 2462 pointsviper spray is The Man with 2462 pointsviper spray is The Man with 2462 pointsviper spray is The Man with 2462 pointsviper spray is The Man with 2462 pointsviper spray is The Man with 2462 pointsviper spray is The Man with 2462 pointsviper spray is The Man with 2462 points
Rep Power: 27
Quote:
Originally Posted by Viper TT
J,

Try the Lavasoft Ad-Aware. It has worked very well for me.

http://www.lavasoftusa.com/software/adaware/

It is the best that I have found , and the personal version is free.
  Reply With Quote

Old February 9th, 2006, 08:57 PM   #13
JGK95
Walk with a Purpose
 
JGK95's Avatar
 
JGK95 is offline
Join Date: Jan 2003
Location: Chicago
Posts: 5,801
JGK95 is The Man with 1807 pointsJGK95 is The Man with 1807 pointsJGK95 is The Man with 1807 pointsJGK95 is The Man with 1807 pointsJGK95 is The Man with 1807 pointsJGK95 is The Man with 1807 pointsJGK95 is The Man with 1807 pointsJGK95 is The Man with 1807 pointsJGK95 is The Man with 1807 pointsJGK95 is The Man with 1807 pointsJGK95 is The Man with 1807 points
Rep Power: 20
I use Ad-Aware from the link above, HiJack This (but you really need to know your stuff as the forums for the program SUCK!) Spybot @
http://www.safer-networking.org

or the

Microsoft AntiSpyware soft http://www.microsoft.com/athome/secu...fault.mspyware.

Typically the best solution is to surf for porn on somebody else's computer:bigsmile:

Good Luck,

Jay K.
  Reply With Quote

Old February 9th, 2006, 10:16 PM   #14
E-Slab
Senior Member
 
E-Slab's Avatar
 
E-Slab is offline
Join Date: Jan 2003
Posts: 12,939
E-Slab made Varsity with 1457 pointsE-Slab made Varsity with 1457 pointsE-Slab made Varsity with 1457 pointsE-Slab made Varsity with 1457 pointsE-Slab made Varsity with 1457 pointsE-Slab made Varsity with 1457 pointsE-Slab made Varsity with 1457 pointsE-Slab made Varsity with 1457 pointsE-Slab made Varsity with 1457 pointsE-Slab made Varsity with 1457 points
Rep Power: 21
Quote:
Originally Posted by getbit
did you ever clean yours?

fuck no, i think it was all that liberator shopping...
  Reply With Quote

Old February 10th, 2006, 01:56 AM   #15
AUSTIN
Derriere Extraordinaire
 
AUSTIN's Avatar
 
AUSTIN is offline
Join Date: Jul 2003
Location: Houxico, Tejas
Posts: 8,036
AUSTIN is The Man with 1723 pointsAUSTIN is The Man with 1723 pointsAUSTIN is The Man with 1723 pointsAUSTIN is The Man with 1723 pointsAUSTIN is The Man with 1723 pointsAUSTIN is The Man with 1723 pointsAUSTIN is The Man with 1723 pointsAUSTIN is The Man with 1723 pointsAUSTIN is The Man with 1723 pointsAUSTIN is The Man with 1723 pointsAUSTIN is The Man with 1723 points
Rep Power: 21
The OLDER version of Ad-Aware is the best. Just update the files. The newer version actually HAS spyware in it.
  Reply With Quote

Old February 10th, 2006, 03:37 AM   #16
PaViper
Enthusiast
 
PaViper is offline
Join Date: Nov 2003
Posts: 133
PaViper is unremarkable with 34 points
Rep Power: 0
I recently had a bout with Spyware Sherriff as well, the most brutal spyware I have encountered yet, Adaware wouldnt touch it, and most programs would lock up anytime it would try to access the buried files. I ended up having to load the hard drive into another PC as a slave drive and deleting all references to the known problem files that were identified by the ten different anti spyware programs I tried. After deleting everything I could especially everything in any temp directory and temp file, I put the hard drive back in and then ran SFC /scannow from a dos prompt and repaired the system files and everything is back to normal. The latest version of mcafee has a very good spyware locator and seems to be keeping out anything new
  Reply With Quote

Old February 10th, 2006, 01:15 PM   #17
Yellow Fever
Senior Member
 
Yellow Fever's Avatar
 
Yellow Fever is offline
Join Date: Aug 2003
Posts: 2,299
Yellow Fever is kissing alot of ass around here with 530 pointsYellow Fever is kissing alot of ass around here with 530 pointsYellow Fever is kissing alot of ass around here with 530 pointsYellow Fever is kissing alot of ass around here with 530 pointsYellow Fever is kissing alot of ass around here with 530 pointsYellow Fever is kissing alot of ass around here with 530 points
Rep Power: 9
Thumbs up

Guys, thanks for all the suggestions! Excellent feedback!

I think I was finally able to kill the little fucker
  Reply With Quote
Reply

  Viper Alley - Dodge Viper Forum » Back Alley » Anything Goes