Announcement Banner
UNSOLVED

jpwoof

updated

22 years ago

Closed

J

jpwoof

33 Posts

0

10102

August 3rd, 2004 14:00

How to kill spyware?

This is frustrating. I have reinstalled my winxp, so basically I'm starting from a clean slate. I have set my Internet explorer's homepage to blank so it wont load up any website... I didnt install any software and I go straight to "Windows Update" to patch all the security holes. But I still get spywares... it opens up IE windows with all this advertisements everytime I boot up my windows.

Please also note that I use the winxp installation CD that came with my Dell inspiron 8500.

One more thing... from a fresh installation... when I check the startup entries in msconfig... there's always this ???.exe program... I had to kill it and delete the registry from regedit. It tends to do some weird internet activities because I could see the lights in my modem flickering.

No viruses found...

Any ideas?

 

 

  • NemesisDB

    2 Intern

    •

    7944 Posts

    437

    0

    Posted August 3rd, 2004 15:00

    I'm not sure about the ???.exe thing, but, get ad-aware (www.lavasoftusa.com) and spy-bot SD (http://www.spybot.info).  Update and run them at least weekly.  Also get some good antivirus software.  Get a personal firewall if you don't have a hardware one (or use the one that comes with winXP). 

    Lock your host file (set it as read only).  You can find the host file at c:\windows\system32\drivers\etc\hosts (or something like that).  Make sure localhost (or elite) is the only entry unless you need other things.

  • jpwoof

    33 Posts

    437

    0

    Posted August 3rd, 2004 15:00

    I maybe off-topic here.. sorry... but anyways.. I believe my computer is infected by wuam.exe trojan virus. But formatting the harddisk countless times wont do any good... is that possible? someone told me that you get it through "Windows Update". Is that possible?

    but anyways... thanks for your help... if anyone knows how to fix this please let me know jpcaps@hotmail.com.

    adaware and s&d wont catch it...

  • NemesisDB

    2 Intern

    •

    7944 Posts

    437

    0

    Posted August 3rd, 2004 16:00

    Judging from some google searches it's a worm that uses any number of microsoft exploits to infect you.  So, you have two options.  1) Remove it (use antivirus software or do it manually)

    2) Reformat and start over.  I suggest this option.

    3) Either way and especially if you reformat, TURN ON microsoft's Internet Connection Firewall (ICF) BEFORE YOU CONNECT YOUR UNPATCHED COMPUTER TO THE INTERNET.  Otherwire you will get reinfected.  Once you apply all critical updates you can turn off the ICF if you so desire but having some type of firewall up is never a bad idea.

  • NemesisDB

    2 Intern

    •

    7944 Posts

    437

    0

    Posted August 3rd, 2004 16:00

    naw, it's not microsoft ... although some worms do replace the windows update file you mentioned before .. the thing to remember is to turn on microsoft's firewall before plugging into an internet connection.  Doing it after is too late as you can become infected within minutes on an un-updated system.

    Message Edited by NemesisDB on 08-03-2004 12:55 PM

  • ejn63

    11 Legend

    •

    87469 Posts

    •

    321256 Points

    437

    0

    Posted August 3rd, 2004 16:00

    You need a firewall and to keep current (up to the day, for those packages with daily updates) antivirus running at all times.

     

  • jpwoof

    33 Posts

    437

    0

    Posted August 3rd, 2004 16:00

    thanks nemesis... reformatting the system doesnt work. i think option 3 might work... I also come into the conclusion that microsoft.com might be infected. =)