Dang Adware...

For system help, all hardware / software topics NOTE: use Coders Corner for all coders topics.

Moderators: Krom, Grendel

Post Reply
User avatar
Capm
DBB DemiGod
DBB DemiGod
Posts: 2267
Joined: Thu Nov 05, 1998 12:01 pm
Location: Topeka, KS
Contact:

Dang Adware...

Post by Capm »

I've got a machine here, I've been through it pretty thoroughly, adaware, hijack this, spybot etc..

I've still got a piece of adware in there, every few minutes, a couple of internet explorer windows popup with ads, and I can't seem to track it down, I've been through all the startup configs etc... Anyone got any ideas where to look for this blasted thing?
User avatar
Krom
DBB Database Master
DBB Database Master
Posts: 16138
Joined: Sun Nov 29, 1998 3:01 am
Location: Camping the energy center. BTW, did you know you can have up to 100 characters in this location box?
Contact:

Post by Krom »

Find out what rundll32 is up to, what you are looking for is probably a DLL attached to some other program not a program by itself.
User avatar
Grendel
3d Pro Master
3d Pro Master
Posts: 4390
Joined: Mon Oct 28, 2002 3:01 am
Location: Corvallis OR, USA

Post by Grendel »

Came along some really clever adware lately -- had to find a program that would at least tell me what it is so I could lookup what it's dll's where. Hooked up in three places -- startup registry entries, shell extensions and IE dll's. Each one would reinstall the other one of course. Two processes running at realtime level monitoring each other where just the front end. That sucker even came up in safe mode. M$ AntiSpy told me what its name was, I then found some info where that beast usually is located. Used sysinternals (http://www.sysinternals.com) process explorer to suspend (not kill) the watchdogs, autoruns to kill every suspect registry entry. Then I unregistered the dll's, killed the dogs and booted into safe mode, deleting the leftovers.. Pain in the arse.
User avatar
Xamindar
DBB Admiral
DBB Admiral
Posts: 1498
Joined: Sun Jun 06, 2004 2:44 am
Location: California
Contact:

Post by Xamindar »

ack, have you looked in msconfig?

I always disable that rundll32 anyway.
User avatar
Asrale
DBB Captain
DBB Captain
Posts: 717
Joined: Fri Jul 20, 2001 2:01 am
Location: US

Post by Asrale »

Download Rootkit Revealer and post a screenshot of its results.
MD-2389
Defender of the Night
Defender of the Night
Posts: 13477
Joined: Thu Nov 05, 1998 12:01 pm
Location: Olathe, KS
Contact:

Post by MD-2389 »

Could you also post the log generated by Hijack This?

edit: A newer version of Hijack This! was released on Feb 16th. download.
User avatar
Krom
DBB Database Master
DBB Database Master
Posts: 16138
Joined: Sun Nov 29, 1998 3:01 am
Location: Camping the energy center. BTW, did you know you can have up to 100 characters in this location box?
Contact:

Post by Krom »

Xamindar wrote:ack, have you looked in msconfig?

I always disable that rundll32 anyway.
Uhmm, rundll32 does have a purpose in windows, if it is running odds are it needs to be running, for instance I use nview desktop manager and it runs from rundll.
User avatar
Xamindar
DBB Admiral
DBB Admiral
Posts: 1498
Joined: Sun Jun 06, 2004 2:44 am
Location: California
Contact:

Post by Xamindar »

Krom wrote:
Xamindar wrote:ack, have you looked in msconfig?

I always disable that rundll32 anyway.
Uhmm, rundll32 does have a purpose in windows, if it is running odds are it needs to be running, for instance I use nview desktop manager and it runs from rundll.
eh, I've never had any problems with it disabled.
User avatar
Krom
DBB Database Master
DBB Database Master
Posts: 16138
Joined: Sun Nov 29, 1998 3:01 am
Location: Camping the energy center. BTW, did you know you can have up to 100 characters in this location box?
Contact:

Post by Krom »

Try bringing up display properties, rundll32 will be running if you do.
User avatar
Capm
DBB DemiGod
DBB DemiGod
Posts: 2267
Joined: Thu Nov 05, 1998 12:01 pm
Location: Topeka, KS
Contact:

Post by Capm »

I'll see to posting the log next time I get in the office.
User avatar
World War Woodi
DBB Ace
DBB Ace
Posts: 167
Joined: Mon Oct 04, 2004 2:20 am
Location: seattle wa
Contact:

Post by World War Woodi »

Um, how bout ditching IE and running mozilla firefox ?
I have nearly 0 ad hits when I run my adaware and spybot since switching.

When I was running IE with my 3 kids using the computer I would average 30 to 150 ad hits and hijacks.

Iam VERY happy with firefox.
User avatar
DCrazy
DBB Alumni
DBB Alumni
Posts: 8826
Joined: Wed Mar 15, 2000 3:01 am
Location: Seattle

Post by DCrazy »

woodi: Adware that's already on the machine has a tendency to launch its ads in IE, regardless of your preferred browser setting.
User avatar
BUBBALOU
DBB Benefactor
DBB Benefactor
Posts: 4198
Joined: Tue Aug 24, 1999 2:01 am
Location: Dallas Texas USA
Contact:

Post by BUBBALOU »

ignorance is bliss

My box is Tight , I know of no such things
User avatar
Admiral LSD
DBB Admiral
DBB Admiral
Posts: 1240
Joined: Sun Nov 18, 2001 3:01 am
Location: Northam, W.A., Australia
Contact:

Post by Admiral LSD »

woodi wrote:Um, how bout ditching IE and running mozilla firefox ?
I have nearly 0 ad hits when I run my adaware and spybot since switching.

When I was running IE with my 3 kids using the computer I would average 30 to 150 ad hits and hijacks.

Iam VERY happy with firefox.
Firefox isn't immune to adware either:

http://www.vitalsecurity.org/2005/03/fi ... ts-ie.html
Post Reply