Register | Login
Views: 19364387
Main | Memberlist | Active users | ACS | Commons | Calendar | Online users
Ranks | FAQ | Color Chart | Photo album | IRC Chat
11-02-05 12:59 PM
0 user currently in Hardware/Software.
Acmlm's Board - I2 Archive - Hardware/Software - Spyware fix with limited resources suggestions. | |
Add to favorites | "RSS" Feed | Next newer thread | Next older thread
User Post
Ten

Cheep-cheep
Level: 23

Posts: 197/198
EXP: 60153
For next: 7570

Since: 07-24-04
From: Denver

Since last post: 69 days
Last activity: 32 days
Posted on 08-24-05 09:07 AM Link | Quote
I've recently got hit by spyware, I know this because Windows told I been infected by spyware and should "go to this site for cleaning!" on my desktop wallpaper, which is your first clue you have spyware because Windows isn't programed to do that. Here's my situation so far.

-Spyware was delevered though "Pop-under advertising" internet window.
-Intialial infecting included wallpaper hijacking, along with pseudo Windows XP messages. I just cut power at this point, but I forget when I unpluged from the internet exactly.
-After restarting in safemode I did a manual search and deleted all files created on 7/30/05 as geting the Search Companion to work takes opening and closing a folder 20 to 30 times before it finally finds the file it needs to.
-MAIN PROBLEM: Expect for internet explorer, all programs cannot not be opened directly and most be through a file like .MP3 or JPEG. Along control panel and right click properties on Windows like My computer and the Desktop so. Trying to do so just gaves me "Windows cannot find 'rundll32.exe'" or whatever. So System Restrore is out. This is not cercumvented in safe mode.
-Certain sites come up as white pages outside of Safemode. Chugworth's Message board as linked in my sig is one of these sites.
-The only other thing the spyware seem to was put a "Click here to fix your PC" and "Show Related Links" under the Tools option in internet explorer. I've found no other
-A few days later I got Search Companion working and looked for all files created since 7/30 again. I'm noticing that certain files are respawing. One notible file is mszx23.exe in System32. Which I've replaced with a blank read only dummy file in a attempt to hinder it's respawing.

Resource limitations.
-I do not have access to my Windows XP disc. I've lost it and cannot find it.
-I do not have any spyware pervention/removal software, not am I'm able to buy it right now.

Please to not tell me to change my browser, that would not help my current situation.

EDIT: Sound quality reduced, codecs may have been damaged.


(edited by Ten on 08-24-05 12:45 AM)
HyperLamer
<||bass> and this was the soloution i thought of that was guarinteed to piss off the greatest amount of people

Sesshomaru
Tamaranian

Level: 118

Posts: 6536/8210
EXP: 18171887
For next: 211027

Since: 03-15-04
From: Canada, w00t!
LOL FAD

Since last post: 2 hours
Last activity: 2 hours
Posted on 08-24-05 10:38 AM Link | Quote
Changing browsers would help prevent from happening again, even if it doesn't help now. But anyway, when you say programs can't be opened directly, do you mean like running the program alone won't work but running it with some parameter will? Try running regedit with some bogus parameter and see if you can edit the EXE association back to "%1 %*" ("(Default)" key in HKEY_CLASSES_ROOT\exefile\shell\open\command). Assuming you offed all naughty processes first, that should get them working again. Next you'll want to delete any files created since the infection and possibly a bit before then. (Look for recently-created 'system' files; most of the files in \Windows and \System32 should have the same date.) Reset your wallpaper too. Finally, go to Microsoft.com and download SP1 or SP2; installing these is basically the same as reinstalling Windows. (You can even burn a new install disc with them; installing them from scratch usually has much better results. And yes, it's legal, assuming your original copy is. )

Also last I checked, Ad-Aware and Spybot both have free versions. AAW's is hard to find, but it's there.
Keikonium
Banned
Level: NAN

Posts: 2404/-2459
EXP: NAN
For next: 0

Since: 04-02-04

Since last post: 63 days
Last activity: 9 hours
Posted on 08-24-05 08:22 PM Link | Quote
You should run these programs in this order at least twice a month (I run it almost every day before bed):

Ad-aware
Spybot
Windows Disk Cleanup
System Mechanic
Windows Defragmentor
REBOOT

Everything listed above is free. Delete reg keys to keep the SM trial going after 30 days.
Ten

Cheep-cheep
Level: 23

Posts: 198/198
EXP: 60153
For next: 7570

Since: 07-24-04
From: Denver

Since last post: 69 days
Last activity: 32 days
Posted on 08-25-05 09:49 AM Link | Quote
I tried runing System Restore by associating it (though right click Open With) a .ten file which was really a blank .txt but it didn't work, it just gave me an illegal operation window.

I'll check it those links later, it's too late tonite to for me to play with my computer.
Add to favorites | "RSS" Feed | Next newer thread | Next older thread
Acmlm's Board - I2 Archive - Hardware/Software - Spyware fix with limited resources suggestions. | |


ABII


AcmlmBoard vl.ol (11-01-05)
© 2000-2005 Acmlm, Emuz, et al



Page rendered in 0.022 seconds.