[Log In ] [New Posts] []
Go Back   GotApex? Forums Forums > General Topics > Software, OS, and the Internet
User Name
Password

Reply
 
Thread Tools Search this Thread Display Modes
Old 12-31-2004, 10:42 PM   #1
GilbertsGrape
Captain
 
GilbertsGrape's Avatar
 
Join Date: Sep 2000
Location: You can’t get there from here, USA
Posts: 1,797
Spyware help

My Father inlaw's PC is infected with some bad spyware
any-find.com///
and
searchportal.info///

I have tried to remove if from the registry but it still comes back.

and the PC will not get on the www any more.

It is able to ping an WWW IP but it will not ping a www by name so i think something is fishy with the DNS i Tried to manualy set the DNS but that still did not work.

I have looked in the host files and cant find anything there either

i have run Spybot and it would not fix the problme


HELP please.



Thank you,
Grape
GilbertsGrape is offline   Reply With Quote
Old 01-01-2005, 04:48 PM   #2
jermscentral
Lieutenant Junior Grade
 
Join Date: May 2003
Location: Nashville, TN
Posts: 88
Send a message via ICQ to jermscentral Send a message via AIM to jermscentral Send a message via Yahoo to jermscentral
When you delete it in the registry, make sure System Restore is turned off, because most of that stuff is set to auto-reinstall once you restart the computer. Also, clear out the C:\Windows\Prefetch folder to get rid of anything that might try to start itself up.

Do Start > Run, msconfig, and under the Startup tab, remove anything not vitally necessary (such as antivirus software).

In the Control Panel, go to Add/Remove Programs and get rid of anything that doesn't look right (except Windows XP Hotfixes and the like).

If it's still causing problems, you can download HijackThis and post a HJ log to get us to see what's running that shouldn't.
jermscentral is offline   Reply With Quote
Old 01-01-2005, 09:09 PM   #3
GilbertsGrape
Captain
 
GilbertsGrape's Avatar
 
Join Date: Sep 2000
Location: You can’t get there from here, USA
Posts: 1,797
thx i will try that sunday and see how it goes

thx,
Grape
GilbertsGrape is offline   Reply With Quote
Old 01-01-2005, 10:41 PM   #4
mechmike0034
aka the keg killer
 
mechmike0034's Avatar
 
Join Date: Dec 2002
Location: Ala-effin'-bama!
Posts: 2,738
XP Winsock fix... This sounds like it'd be right up your alley!

HTH!
__________________
"The price of progress is trouble." (C. F. "Boss" Kettering)
"50% of the American public has below-average intelligence. 70% of the American public now has regular access to the Internet. Do the math." (unknown)
mechmike0034 is offline   Reply With Quote
Old 01-02-2005, 06:17 AM   #5
GilbertsGrape
Captain
 
GilbertsGrape's Avatar
 
Join Date: Sep 2000
Location: You can’t get there from here, USA
Posts: 1,797
Quote:
Originally Posted by mechmike0034
XP Winsock fix... This sounds like it'd be right up your alley!

HTH!


Cool Thank you, I will give that a try as well
GilbertsGrape is offline   Reply With Quote
Old 01-03-2005, 11:05 AM   #6
DarkFury
Secretary of the Navy
 
DarkFury's Avatar
 
Join Date: Feb 2001
Location: Chillin' N Da 'Hood
Posts: 34,997
Also... you may wanna start up in "Safe Mode" so that NOTHING pre-loads itself when you run your Spy checkers and Anti virus...

You'd be surprised by how devius some of this stuff is to avoid getting removed from your machine.

BTW... in some cases you will have to manually delete the programs that are lauching these spyware... yes it is tedious, but in the end it makes you feel much better.
__________________


DarkFury's Pimptopia - Don't Hate the Playa, Hate the Game!
Home of the Original OG Pimp (accept NO imitations)
DarkFury is offline   Reply With Quote
Old 01-03-2005, 11:39 AM   #7
mechmike0034
aka the keg killer
 
mechmike0034's Avatar
 
Join Date: Dec 2002
Location: Ala-effin'-bama!
Posts: 2,738
http://www.mvps.org/winhelp2002/unwanted.htm

http://aumha.org/a/parasite.htm

http://nyquil-kid.dyndns.org/SpyBotG...e84447ff58abb6

http://nyquil-kid.dyndns.org/AdAware...eb98b12e6d2f1a

On an XP machine, turn off System Restore (turn it back on and set a restore point once the machine is clean), dump the C:\Windows\Prefetch folder, run a Disk Cleanup, then boot into Safe Mode and run Spybot/AdAware (with the latest defs, of course...)

That's how I usually start the "anti-0wnage" or spyware removal process.

Last edited by mechmike0034 : 01-03-2005 at 11:42 AM.
mechmike0034 is offline   Reply With Quote
Old 01-03-2005, 07:20 PM   #8
DarkFury
Secretary of the Navy
 
DarkFury's Avatar
 
Join Date: Feb 2001
Location: Chillin' N Da 'Hood
Posts: 34,997
Quote:
Originally Posted by mechmike0034
http://www.mvps.org/winhelp2002/unwanted.htm

http://aumha.org/a/parasite.htm

http://nyquil-kid.dyndns.org/SpyBotG...e84447ff58abb6

http://nyquil-kid.dyndns.org/AdAware...eb98b12e6d2f1a

On an XP machine, turn off System Restore (turn it back on and set a restore point once the machine is clean), dump the C:\Windows\Prefetch folder, run a Disk Cleanup, then boot into Safe Mode and run Spybot/AdAware (with the latest defs, of course...)

That's how I usually start the "anti-0wnage" or spyware removal process.
Either that...or Ghost immediately after a fresh install. Works wonders.
DarkFury is offline   Reply With Quote
Old 01-03-2005, 09:46 PM   #9
GilbertsGrape
Captain
 
GilbertsGrape's Avatar
 
Join Date: Sep 2000
Location: You can’t get there from here, USA
Posts: 1,797
Quote:
Originally Posted by mechmike0034
XP Winsock fix... This sounds like it'd be right up your alley!

HTH!
Thank you so much this fixed the interent probome. now we just have to get rid of all the spyware on his box.


DF yea i wish i had ghosted it if i ever have to re do the box i will forsure do that


Thank you everyone
GilbertsGrape is offline   Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -7. The time now is 04:00 AM.