New User? Need help? Click here to register for free! Registering removes the advertisements.

Computer Cops
image image image image image image image image
Donations
If you found this site helpful, please donate to help keep it online
Don't want to use PayPal? Try our physical address
image
Prime Choice
· Head Lines
· Advisories (All)
· Dnld of the Week!
· CCSP News Ltrs
· Find a Cure!

· Ian T's (AR 24)
· Marcia's (CO8)
· Bill G's (CO12)
· Paul's (AR 5)
· Robin's (AR 2)

· Ian T's Archive
· Marcia's Archive
· Bill G's Archive
· Paul's Archive
· Robin's Archive
image
Security Central
· Home
· Wireless
· Bookmarks
· CLSID
· Columbia
· Community
· Downloads
· Encyclopedia
· Feedback (send)
· Forums
· Gallery
· Giveaways
· HijackThis
· Journal
· Members List
· My Downloads
· PremChat
· Premium
· Private Messages
· Proxomitron
· Quizz
· RegChat
· Reviews
· Google Search
· Sections
· Software
· Statistics
· Stories Archive
· Submit News
· Surveys
· Top
· Topics
· Web Links
· Your Account
image
CCSP Toolkit
· Email Virus Scan
· UDP Port Scanner
· TCP Port Scanner
· Trojan TCP Scan
· Reveal Your IP
· Algorithms
· Whois
· nmap port scanner
· IPs Banned [?]
image
Survey
How much can you give to keep Computer Cops online?

$10 up to $25 per year?
$25 up to $50 per year?
$10 up to $25 per month?
$25 up to $50 per month?
More than $50 per year?
More than $50 per month?
One time only?
Other (please comment)



Results
Polls

Votes: 1211
Comments: 21
image
Translate
English German French
Italian Portuguese Spanish
Chinese Greek Russian
image
 Forum FAQForum FAQ   SearchSearch   UsergroupsUsergroups   ProfileProfile   Login to check your private messagesLogin to check your private messages   LoginLogin   Your Favorite ForumsFavForums 

Please Help I'm in So Much Trouble!!!!

 
Post new topic   Reply to topic       All -> FavForums -> General Privacy
View previous topic :: View next topic  
Author Message
beetlesan

Cadet
Cadet



Joined: Apr 18, 2004
Posts: 2
Location: USA

PostPosted: Sun Apr 18, 2004 1:43 pm    Post subject: Please Help I'm in So Much Trouble!!!!
Reply with quote

I never thought I would be afraid of browsing the internet. SPyware didn't scare me because I had Spybot and Adaware. Besides, I didn't care if someone was watching what internet sites I visit.

Then I downloaded a nasty hijacker by visiting the wrong website. My spyware programs could not find the buggers, and my homepage kept opening to a search engine. I even edited the registry, and finally gave up, reformatted my PC.


That was at home. Now I am facing the same nightmare at work, and if I tell the network adminstrator, I'm gonna either get in trouble, or be embarrassed. I take extreme caution, and only browse safe sites like google.com and yahoo.com. Here's what happened:

I was on google.com and my finger slipped and I accidently clicked a banner ad. Suddenly a popup covers my whole screen, and I get tons of prompts to download files, and I say no or cancel. I should have just killed my pc right then. The next day, I am horrified to find that when I open IE, there is a search toolbar. Even worse, the toolbar stayed at the bottom of my windows desktop even when I had the browser shut down. I immediateliy took action, ran spybot, adaware, spykiller. They found over 1,000 traces and registry entries. I deleted this, and did add/remove programs for lycos search and other programs it deleted.

The problem is whatever got on my pc has affected it severely. The computer would freeze, lock up, I could not even write an email without the screen just freezing. I ran msconfig and removed any startup programs. I even did a search for *.exe files that were added on that day, adn deleted these. As far as I can tell, the spyware is gone, but my pc runs so slow that I can't do my work. I looked at the processes running in task manager, and there were a few that I did not recognize. I did internet searches for these files, and no results. One is called GMA1.exe and another is acdtiaY3.exe. I was so desperate that I took a risk and told Windows to terminate that process. The speed improved, but then a few minutes later, the process showed up again! I'm screwed unless I can figure out the source of these processes. They are using 90% of my cpu. Anyone have any suggestions on how to trouble shoot this problem? Any other FREE spyware programs I can try, or downloads that will tell me what the processes are? As you can see, I'm desperate, and almost scared to go back to work and face this misery. Lycos should be fined severely for this CRAP!
Back to top
View users profile Send private message
TonyKlein

Site Moderator
Site Moderator



Joined: Oct 15, 2002
Posts: 5819
Location: Netherlands

PostPosted: Sun Apr 18, 2004 1:49 pm    Post subject:
Reply with quote

Hi, and welcome.

I suggest you start by doing the following:

Download the latest version of Ad-Aware at http://www.lavasoftusa.com/support/download/

After installing AAW, and before running the program, you NEED to FIRST update the reference file following these instructions.

Now do the following:

- Under Ad-aware 6 > Settings (Gear at the top) > Tweak > Scanning Engine:
check: "Unload recognized processes during scanning."

- Under Ad-aware 6 > Settings (Gear at the top) > Tweak > Cleaning Engine:
Check: "Let Windows remove files in use after reboot."

Press "Scan Now"

- Check option "Use Custom scanning options"
- Check option "Activate In-Depth Scan"
- Press "Select drives\folders to scan"
- Select the active partition which is usually C:

Now press "Next" to let Ad-aware scan your drives...
It will find a number of "bad" files and registry keys.
Right-click in that pane and choose "select all"

Now press "Next" again.
It will ask you whether you'd like to remove all checked items. Click OK.

Finally, close Ad-Aware, and reboot.
That ought to get rid of most of your spyware.

When you've done all that, go to http://mjc1.com/mirror/hjt/, and download Hijack This.

Unzip to a folder other than your Desktop or the Temp folder, doubleclick HijackThis.exe, and hit "Scan".

When the scan is finished, the "Scan" button will change into a "Save Log" button.
Press that, save the log somewhere, and please show us its contents.

Most of what it lists will be harmless or even required, so do NOT fix anything yet.
Someone here will be happy to help you analyze the results.

_________________
Tony
Back to top
View users profile Send private message
beetlesan

Cadet
Cadet



Joined: Apr 18, 2004
Posts: 2
Location: USA

PostPosted: Sun Apr 18, 2004 10:36 pm    Post subject:
Reply with quote

I already tried adaware. I did that first thing.
Back to top
View users profile Send private message
TonyKlein

Site Moderator
Site Moderator



Joined: Oct 15, 2002
Posts: 5819
Location: Netherlands

PostPosted: Mon Apr 19, 2004 5:22 am    Post subject:
Reply with quote

Let's have a closer look then:

Go to http://computercops.biz/downloads-cat-14.html , and download Hijack This.

Unzip to a folder other than your Desktop or the Temp folder, doubleclick HijackThis.exe, and hit "Scan".

When the scan is finished, the "Scan" button will change into a "Save Log" button.
Press that, save the log somewhere, and please show us its contents.

Most of what it lists will be harmless or even required, so do NOT fix anything yet.
Someone here will be happy to help you analyze the results.

_________________
Tony
Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> General Privacy All times are GMT - 5 Hours
Page 1 of 1

 
 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum


Powered by phpBB 2.0.8a © 2001 phpBB Group

Version 2.0.6 of PHP-Nuke Port by Tom Nitzschner © 2002 www.toms-home.com
Version 2.2 by Paul Laudanski © 2003-2004 Computer Cops