[Log In ] [New Posts] []
Go Back   GotApex? Forums Forums > General Topics > Software, OS, and the Internet
User Name
Password

Reply
 
Thread Tools Search this Thread Display Modes
Old 12-03-2004, 07:21 AM   #1
Merlin
Admiral
 
Merlin's Avatar
 
Join Date: Dec 2001
Location: Square On My Arse
Posts: 7,410
Damn, I've been infected....

Perhaps someone has seen this before. Last week I somehow managed to get a nasty little piece of spyware on my computer at work. Not sure where it came from but whenever I open a browser window or explore a folde there is now an additional toolbar with shortcuts to things that are not work appropriate. I've run ad aware which found lots of crap but not this. My IT support has looked it and are befuddled. They've offered to re-image my computer. I will probably take them up on that offer but first wanted to see if anyone could help.

Here is a screenshot of the toolbar. It is right below the addressbar.



If I right click in a neutral area by the tool bars I see that this is called "Fast Search" I can turn it off there but it reappears everytime I open either a browser or folder.

I've reported it so at least I won't get fired over inappropriate material but I still would like it gone forever.

Add/Remove programs has no listing for it.

Thanks in advance for any help.
__________________
Merlin is offline   Reply With Quote
Old 12-03-2004, 07:50 AM   #2
bachviet
What's Da Pho*?
 
bachviet's Avatar
 
Join Date: Aug 2001
Location: SoCal (714)
Posts: 13,296
Send a message via ICQ to bachviet Send a message via AIM to bachviet
You shouldn't visit pr0n sites at work. J/K
__________________
Dell Dimension 9200 | Intel Core 2 Quad Q6600 (2.4GHz) | 4x1GB DDR2 | 256MB nVidia GeForce 8800GT

Dell Studio 17 | Intel Core i7-720QM (1.6GHz) | 2x2GB DDR3 1066MHz | 1GHz ATI Mobility Radeon HD 4650

Intel P4-C 3.0GHz | ECS 865PE-A | 3x512MB PC3200 | 128MB PNY GeForce 6600GT

bachviet is offline   Reply With Quote
Old 12-03-2004, 08:10 AM   #3
Jcranmer
Commander
 
Jcranmer's Avatar
 
Join Date: Jan 2001
Location: Pekin, IN
Posts: 1,377
Never mind. I had posted a link to remove it, but don't think it's the write spyway.
Jcranmer is offline   Reply With Quote
Old 12-03-2004, 08:27 AM   #4
Merlin
Admiral
 
Merlin's Avatar
 
Join Date: Dec 2001
Location: Square On My Arse
Posts: 7,410
Quote:
Originally Posted by bachviet
You shouldn't visit pr0n sites at work. J/K
I couldn't even if I wanted to. Most sites out there are blocked. Hell, I'm surprised they have not blocked Apex yet.
Merlin is offline   Reply With Quote
Old 12-03-2004, 08:28 AM   #5
nickel
Vice Chairwoman, Joint Chieftess of Staff
 
nickel's Avatar
 
Join Date: Feb 2002
Location: Jeterville, NYY
Posts: 17,786
Quote:
Originally Posted by Merlin
I couldn't even if I wanted to. Most sites out there are blocked. Hell, I'm surprised they have not blocked Apex yet.
bite your tongue!
__________________
*click me*
nickel is offline   Reply With Quote
Old 12-03-2004, 08:50 AM   #6
Maarchk
Rear Admiral Upper Half
 
Maarchk's Avatar
 
Join Date: Jul 2000
Location: Where the east meets the west.
Posts: 3,066
i think adaware should get rid of that for you. Or you can look it up. I think when i had that issue it was a folder and program stored under program files... Hang on one sec...

Check this out.

Its a link to a guide on removing fastsearch stuff. And it has links on how to remove all the other random little popup guys...

I hope this helps...

hehe and i really gotta stop talking as if you guys can see my post as i type.. you might think i'm crazy.

Quote:
Originally Posted by nickel
bite your tongue!

wouldn't you rather he bite yours?
__________________
"The girl is crafty like ice is cold."

"I left my heart in san francisco... And my liver at Moe's Tavern."

A real friend is one who listens to you as much as they talk to you.
Maarchk is offline   Reply With Quote
Old 12-03-2004, 08:59 AM   #7
SmokeyDP
Lieutenant Commander
 
Join Date: Jan 2003
Location: Middlesex, NJ
Posts: 541
Send a message via AIM to SmokeyDP Send a message via Yahoo to SmokeyDP
Yeah that sucks. Thats why I use Firefox at work. Plus they can't go through my cache files as easy.

format c:
SmokeyDP is offline   Reply With Quote
Old 12-03-2004, 12:57 PM   #8
jermscentral
Lieutenant Junior Grade
 
Join Date: May 2003
Location: Nashville, TN
Posts: 88
Send a message via ICQ to jermscentral Send a message via AIM to jermscentral Send a message via Yahoo to jermscentral
pchell.com says it appears to be a variant of CoolWebSearch, so you may want to grab your nearest CWShredder and knock it out. Merijn is the originator and has the file that removes just about every variant of the file, because AdAware and Spybot can never seem to pick it all up.

http://www.spywareinfo.com/~merijn/downloads.html
jermscentral is offline   Reply With Quote
Old 12-03-2004, 01:13 PM   #9
Merlin
Admiral
 
Merlin's Avatar
 
Join Date: Dec 2001
Location: Square On My Arse
Posts: 7,410
Thanks for the help folks. It turned out to be a hidden .dll file that had to go as well as an entry in the registery. I used CWShredder and Spybot Search & Destroy to get at it. Had to go and review the Web Browser Helper Objects and remove it that way.

Ugly little bug that was.
Merlin is offline   Reply With Quote
Old 12-04-2004, 04:57 PM   #10
ribitch
Rear Admiral Upper Half
 
ribitch's Avatar
 
Join Date: Sep 2001
Location: Michigan
Posts: 3,672
Send a message via AIM to ribitch
i had a client that had something about a week ago that wasnt recognized by adaware and after each reboot, downloaded hundreds of new spyware objects, without even doing anything on the pc. I believe it was somehow part of bargain buddy. Whatever it was, it was a pain. It would reinstall extra toolbars, popup flash animations at random. I cant see how pc users put up with some of this crap.
__________________
http://ribitch.com/ipod.html
ribitch is offline   Reply With Quote
Old 12-04-2004, 06:29 PM   #11
chadlnc
Lieutenant Commander
 
chadlnc's Avatar
 
Join Date: Mar 2001
Location: North Carolina
Posts: 947
Quote:
Originally Posted by ribitch
i had a client that had something about a week ago that wasnt recognized by adaware and after each reboot, downloaded hundreds of new spyware objects, without even doing anything on the pc. I believe it was somehow part of bargain buddy. Whatever it was, it was a pain. It would reinstall extra toolbars, popup flash animations at random. I cant see how pc users put up with some of this crap.

That sounds like what my boss has on his comuter now. I have yet to be able to get rid of it. Adware picks some of it up, but freezes when it tries to remove it.
chadlnc is offline   Reply With Quote
Old 12-04-2004, 07:00 PM   #12
ribitch
Rear Admiral Upper Half
 
ribitch's Avatar
 
Join Date: Sep 2001
Location: Michigan
Posts: 3,672
Send a message via AIM to ribitch
Quote:
Originally Posted by chadlnc
That sounds like what my boss has on his comuter now. I have yet to be able to get rid of it. Adware picks some of it up, but freezes when it tries to remove it.

i ended up using hijack this and some other tool (i dont remember the name of it). Hijack allowed me to remove most of the crap that was starting up, but there was one dll file that it failed to remove. The other program allowed me to remove the dll file. after that it worked great.
ribitch is offline   Reply With Quote
Old 12-05-2004, 11:55 AM   #13
mechmike0034
aka the keg killer
 
mechmike0034's Avatar
 
Join Date: Dec 2002
Location: Ala-effin'-bama!
Posts: 2,738
Quote:
Originally Posted by chadlnc
That sounds like what my boss has on his comuter now. I have yet to be able to get rid of it. Adware picks some of it up, but freezes when it tries to remove it.

Chad, try one of these: http://nyquil-kid.dyndns.org/

http://www.ubcd4win.com/

I have had good luck removing even the toughest spyware by booting off of one of the two CDs mentioned in the links and using the tools on them. This works much better IMHO than booting into Windows, which runs the rogue processes and makes them more difficult to remove.

If the infected machine is running XP, turn off System Restore and also clear out the C:\Windows\Prefetch directory BEFORE attempting to eradicate adware/spyware.

After you get the bosses machine clean, install Javacool Spyware Blaster http://www.javacoolsoftware.com/spywareblaster.html as a preventative to help keep it from happening again.

Go be a hero and get a feather in your cap. If I can help let me know.
__________________
"The price of progress is trouble." (C. F. "Boss" Kettering)
"50% of the American public has below-average intelligence. 70% of the American public now has regular access to the Internet. Do the math." (unknown)
mechmike0034 is offline   Reply With Quote
Old 12-05-2004, 09:15 PM   #14
welfareloser
Grand Moff
 
welfareloser's Avatar
 
Join Date: Sep 2000
Location: jabba's palace. (yes, i do... and no, you can't.)
Posts: 9,718
Send a message via Yahoo to welfareloser
i have spywareblaster, spyware doctore, and adaware, but i have gotten a couple of very nasty toolbars in spite of them... what works for me is searching for files with the name of the toolbar in them, and deleting what i find. then all teh other leftover bits and pieces seem to lose their camoflauge, and the spyware assassins can now find them and take care of the rest. not very scientific, but it's worked for me so far...
__________________
Find the person who will love you because of your differences and not in spite of them and you have found a lover for life. ~ Leo Buscaglia
http://www.welfareloser.com
http://gotapexblogs.net/users/welfareloser/
welfareloser is offline   Reply With Quote
Old 12-06-2004, 12:18 PM   #15
chadlnc
Lieutenant Commander
 
chadlnc's Avatar
 
Join Date: Mar 2001
Location: North Carolina
Posts: 947
Quote:
Originally Posted by mechmike0034
Chad, try one of these: http://nyquil-kid.dyndns.org/

http://www.ubcd4win.com/

I have had good luck removing even the toughest spyware by booting off of one of the two CDs mentioned in the links and using the tools on them. This works much better IMHO than booting into Windows, which runs the rogue processes and makes them more difficult to remove.

If the infected machine is running XP, turn off System Restore and also clear out the C:\Windows\Prefetch directory BEFORE attempting to eradicate adware/spyware.

After you get the bosses machine clean, install Javacool Spyware Blaster http://www.javacoolsoftware.com/spywareblaster.html as a preventative to help keep it from happening again.

Go be a hero and get a feather in your cap. If I can help let me know.

I took your advice (sort of) and used a bootable CD (Bart PE) and ran Adaware. I was finally abe to remove them without Adaware locking up. However once I restarted they came back. I tried a couple manual removal procedures and those didn't work either. I finally tried Adwareaway and that (I think) did the trick. I'll check back in a few hours and see if everything still looks clean after some regular use.

Thanks for the help
chadlnc is offline   Reply With Quote
Old 12-06-2004, 05:27 PM   #16
welfareloser
Grand Moff
 
welfareloser's Avatar
 
Join Date: Sep 2000
Location: jabba's palace. (yes, i do... and no, you can't.)
Posts: 9,718
Send a message via Yahoo to welfareloser
oh, the one spyware killer that worked WONDERS (and i've tried about a dozen) is webroot's "spy sweeper." it killed everything, always. stopped stuff from ever coming on to my hd, and always popped up an alert when anything bad tried to happen. it's free for 30 days, then you pay. i think it's pretty cheap, like maybe $30 per year. i let it lapse after the trial period... which is why i'm now reinstalling windows i'm damn well going to pony up the money for it as soon as i put my poor little broken computer back together again... anyway, do a google for it; i think it's at download.com or downloads.com or whatever that site is...
welfareloser is offline   Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -7. The time now is 12:38 PM.