PDA

Click to See Complete Forum and Search --> : i have undetected spyware on my pc


isle_of_infamy
January 6th, 2004, 04:21 PM
I currently have like 4 spyware progs on my pc spybot adaware pro spyblaster to prevent and spyhunter.

spyware is jus an annoyance more than anything for me but currently if i type yahoo.com in my browser IE explore 6.0 i get this funky webpage that says YOU ARE BEING WATCHED!!!

i was like whoa what the hell ya know and i scanned with all my progs but all came up clean ya know, and now i dunno i tried to scan my registry for key words and such and also i right clicked the html file to see if i could detect any properties that stood out and such, but nothing. i even clicked view privacy report but still nothing stood out... i know this must be some kinda hijacker thats been infused into my explorer reg keys somewhere, but i dunno exactly where.

any suggestions ?

sumdumguy
January 6th, 2004, 05:39 PM
try hijackthis..
http://www.tomcoyote.org/hjt/

log tut..
http://www.spywareinfo.com/~merijn/htlogtutorial.html

forum
http://www.spywareinfo.com/forums/

nihil
January 6th, 2004, 06:56 PM
Do you think it is a real webpage or an artifact on your own machine.

What is its address?

You might try http://wilderssecurity.com and get Browser Hijack Blaster and Spyware Guard?

Also http://www.swatit.org and get SwatIt.

Update all your anti-malware stuff and run it in safe mode.

Cheers

isle_of_infamy
January 6th, 2004, 07:09 PM
ok u need 2 change ur name cuz u aint dum lol that lil prog hijack this helped... i dunno whatever i deleted some BHO key or something cuz now when i type in yahoo.com it goes to yahoo like it should.

thats really odd huh ? *bows down 2 dum guy lol

thank u thank u

Amplifiedgirl
January 6th, 2004, 07:13 PM
What is a spyware?

isle_of_infamy
January 6th, 2004, 07:18 PM
ok well webopedia defines spyware as such:


Also called adware, spyware is any software that covertly gathers user information through the user's Internet connection without his or her knowledge, usually for advertising purposes. Spyware applications are typically bundled as a hidden component of freeware or shareware programs that can be downloaded from the Internet. Once installed, the spyware monitors user activity on the Internet and transmits that information in the background to someone else. Spyware can also gather information about e-mail addresses and even passwords and credit card numbers.
Spyware is similar to a Trojan horse in that users unwittingly install the product when they install something else. A common way to become a victim of spyware is to download certain peer-to-peer file swapping products that are available today.

is that a clear enough definition ?

nihil
January 6th, 2004, 08:15 PM
isle_of_infamy

Now you are "clean" please take a look at those two utilities that I mentioned.


Thanks for letting us know what worked..........that was polite


Good luck

thehorse13
January 6th, 2004, 08:21 PM
Yes, the BHO, or Browser Helper Object, is what you deleted using HijackThis. You might have noticed that bi.dll was one of BHOs that you deleted. This little shit has avoided detection from SpyBot. The only tip off I got was from Websense which was reporting spyware on my machine! This has been more common lately which tells me that the spyware folks are getting brighter or the anti-spyware folks are getting lazy. Who knows, maybe it's both.

:)

isle_of_infamy
January 6th, 2004, 08:53 PM
hey nihil i will definitely take a look and check out what u posted... thanks a lot .. much appreciated

sumdumguy
January 6th, 2004, 11:39 PM
Originally posted here (http://www.AntiOnline.com/showthread.php?threadid=253069#post707132) by isle_of_infamy
ok u need 2 change ur name cuz u aint dum lol that lil prog hijack this helped... i dunno whatever i deleted some BHO key or something cuz now when i type in yahoo.com it goes to yahoo like it should.

thats really odd huh ? *bows down 2 dum guy lol

thank u thank u

:D no no.. can't change my name.. it fits.. I like self depreciating humor.. ;)

glad you got it taken care of..

Fatphantom
January 6th, 2004, 11:43 PM
if i type yahoo.com in my browser IE explore 6.0 i get this funky webpage that says YOU ARE BEING WATCHED!!!

Check your hosts file.

Amplifiedgirl
January 7th, 2004, 12:03 AM
yeah thanks, the definition of spyware is clear :) by why do they sell information over the internet?

isle_of_infamy
January 7th, 2004, 07:03 PM
ok how do u check ur host file exactly ? I think I'm clean now hopefully.

but yeah they sell info over the internet, and spyware is more than what i told u it is also webpages that have certain active x scripts in them that can alter some of ur critical registry settings such as ur search assistant or ur dial up modem etc etc. if u ask me spyware is simply lame and i'd like nothing more than 2 slap the person who invented it up side their head, but i won't go into that. :p

but look at searchbug they charge money to do personal background checks reverse cell phone lookups etc etc so yes people do make money off other peoples personal information.
pretty wild huh...

nihil
January 7th, 2004, 08:43 PM
Hi isle_of_infamy

http://www.webattack.com/get/hostadmin.html

Host Administrator

A nice User friendly tool to monitor your Windows "hosts" file :)

Cheers

Dr Toker
January 8th, 2004, 06:42 AM
I recently had the same problem on my workstation terminal in the Network Operations Control Center. we ran just about every Spybot detector adaware, everrything we could think of... Nothing Identified it. So when out CTO came in and saw what we were doing, he offered his professional diagnosis. He said "Save what you need, wipe the rest". There was too much sensitive information on the machine to waste time.

The moral of the story is that, I think alot of the times we overthink things in the IT feild. Sometimes there is a solution staring us straight in the face, but we over look it or dismiss it.
If you know a way to fix it, do it. Stop wasting time and get it done.

And thats my Rx

isle_of_infamy
January 8th, 2004, 05:48 PM
hello nihil i downloaded and ran that stand alone tool for checking host files. that's a nifty lil gadget. it showed only 1 host and that was my proxy for my adsubtract program popup killer so thats good i only have that 1 and nothing more.

thanks