Results 1 to 6 of 6

Thread: What files does Win2K use for startup?

  1. #1
    Vice Admiral gwilks98's Avatar
    Join Date
    Aug 2000
    Location
    StL
    Posts
    4,353

    What files does Win2K use for startup?

    This one's got me baffled. I became the unwilling donor of spyware software and it's chewed up most of my day trying to get rid of it. Ad-aware (up to date) got most of it, but it missed something that's re-occuring at every startup.

    Here's what it's doing:

    Something extracts an executable of a random name to my user specific temp directory. The executable is then run which pops up a windows input dialog box asking if I'm interested in receiving blah blah blah. I kill the process, but it's already too late.

    Something, probably the executable or whatever extracts it, writes to my registry settings for IE, telling IE to load a "browser bar" with inappropriate adult and gambling links from random sub-addresses under this domain: tfil.com. Then the site redirects me to whatever page I was trying to access, happening so quickly that most people won't know why that bar is opening. This browser bar started installing malware of it's own so I was able to quick fix it by restricting the domain. (The registry settings will keep coming back until I can remove the first problem.)

    In my brief experiences with spyware, I've come to realize that they hide in either a dll that IE is linked to or forced to link to or they hide in window's startup files. I've already searched for removal instructions and couldn't find anything up to date. Can anyone offer some pointers?
    "I know the pieces fit, cause I watched them fall away."

    "Cold silence has
    A tendancy to
    Atrophy any
    Sense of compassion."

    MJK

  2. #2
    Download Spybot and run that. Between Spybot and Adaware you should pick everything up.

  3. #3
    Vice Admiral gwilks98's Avatar
    Join Date
    Aug 2000
    Location
    StL
    Posts
    4,353
    Spybot got it. Thanks!
    "I know the pieces fit, cause I watched them fall away."

    "Cold silence has
    A tendancy to
    Atrophy any
    Sense of compassion."

    MJK

  4. #4
    Did it solve your problems, or are u still getting porn popups?

  5. #5
    Commander Booyamos's Avatar
    Join Date
    Jun 2000
    Location
    Boston, MA
    Posts
    1,277
    you can also see what is being run at startup in the registry.

    on my XP machine this is where they are, should be similiar

    Local Machine > Microsoft > Windows > Current Version > Run
    Current User > Microsoft > Windows > Current Version > Run

    the keys for all the programs that run are there, I found a few annoying ones
    Boo ya Grandma

  6. #6
    Vice Admiral gwilks98's Avatar
    Join Date
    Aug 2000
    Location
    StL
    Posts
    4,353
    Originally posted by lilbigblue
    Did it solve your problems, or are u still getting porn popups?
    Yup...I like Spybot a lot better. It actually told me HOW I got each infection. (LOW IE security settings)
    "I know the pieces fit, cause I watched them fall away."

    "Cold silence has
    A tendancy to
    Atrophy any
    Sense of compassion."

    MJK

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •