Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations gkittelson on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Mass PopUP Attack 5

Status
Not open for further replies.

gordola

Technical User
Mar 24, 2005
1
US
I am running win98 (my wife's computer) with Norton Anti Virius, plus added Adware and AVG after my attacks. Machine had several trojans, despite Norton protection, including EliteBar which appear to have been removed by AVG. I started up computer which has a SBC/Yahoo home page. No ads. As soon as I tried Goggle, the flood gates opened and the following ads appeared in this order. Spyware and Ad Removal, Spybouncer, Get Your Free Ipod, Security Alert, Giftfox.com (Ad for Sirius), Quikshield, You May have Critical errors.......,Diamond-StuddedPink Cellphone Ad. I ran Adware and it came up with a few Data Mining files which I eliminated. Went back to Goggle and was overwhelmed again. One more attempt at Adware and two additional Data Mining files appeared. What do I have and how do I get rid of it. I need a stiff drink!!!! Thanks all
 
My first recommendation is to stop using Adaware as your primary detection method.

I would suggest going to trend micros site and run their housecall program.


Then I would go and download Spybot S&D and run this as well. You'll find that they'll pick up quite a bit that Adaware has missed (this isn't a direct knock on Adaware it will still pick up items Spybot misses).

Reboot and try see what you receive. If you're still receiving pop-ups then go to


and download hijack this. Run it and post your log up here and we'll help identify any other baddies that are still lurking about.
 
Two possibilities are lop and one of the newer cws variants.
Would need to see a hijackthis log to know better what is going on.

-------------------------------------
It's 10 O'Clock ( somewhere! ).
Are your registry and data backed up?
 
Also check your hosts file, Google.com could be pointed to a adware site in the host file.
 
GOTO MICROSOFT.COM AND DOWNLOAD THE ANTISPYWARE BETA TOOL, IT DOES IT ALL AND ITS FREE. BY FAR THE BEST ONE OUT THERE, IRONIC THOUGH, MICROSOFT IS THE ONE RESPONSIBLE FOR ALL THIS SPYWARE, ITS ONLY FREE FOR A LIMITED TIME.
 
BY FAR THE BEST ONE OUT THERE, IRONIC THOUGH, MICROSOFT IS THE ONE RESPONSIBLE FOR ALL THIS SPYWARE, ITS ONLY FREE FOR A LIMITED TIME."

My response, without CAPS:

. "By far the best on out there, ironic though..."

I happen to use the Giant subscription prior to the Microsoft purchase, but it was my feeling that it was the best product out there.

. "Microsoft is the one responsible for all of this spyware."

Well I suppose so. They certainly do not create malware. Because it is the dominent browser, IE invites attacks. My concern is quite different. Increasingly it seems that using ActiveX, any scripting, or possibly any file, creates what Microsft describes as an "attack surface." To minimize or remove that "attack surface" is to deny to users and web developers a lot of great stuff.

As end users, we are all going to lose in this malware battle.

. "It is only free for a limited time."

Ye, there is a time limit for the Beta. After that it is free. In larger managed settings where Group Policy and server-based control through SUS, MOM, SMS, etc. it likely thre will be a paid subscription product.

Summary:

I hope the notes above do not discourage you from trying the Microsoft Anti-Spyware Beta. It does not scan cookies, so see my notes in faq608-4650 But it does an impressive job.

Bill Gates has promised that it is now, and will continue to be freeware for valid Win2k and XP licenses.

It is my honest opinion that one needs several weapons in the malware war. The Microsoft Beta is an excellent one, and without hesitation I recommend it to you.



 
He's runing Win98 MS's antiSpyware only works on 2000 and XP, MS disabled it for all 9x OS.
 
The version sold by Counter Spy will work under Win98 and shares the definition database with Microsoft.
 
I suspect you are being hijacked. Although you "see" Google on the screen, it may not be Google that is receiving the transmitted info.

First, consider upgrading to Win XP. And then promptly install sp2, and patch up your browser. I know, I know, why fix something that is not broke. But XP has more security including a firewall.

Another option. Use another browser. Does Firefox run on Win98? This is just a tempary fix. Sooner or later, some hack will tweak something to attack something else.

Another option is to install a firewall that works on Win98. I used ZoneAlarm with excellent results on my son's computer. It worked for a long time before he got clobbered by Malware. With ZoneAlarm, or other firewall software, when you find an offending address, you can prevent info being sent to the address, and also block the site. Eventually, I upgraded his computer to XP.

I forget, does MS Messenger run on Win98. Try to disable it.

Also, I have had pretty good results with...
- AdAware
- SpyBot S&D
- CWShredder
- MS Antispyware beta
...and some others.

Trend (Housecall) is a great on-line virus scanner, but it never found spyware on my systems. Ditto for McAfee and Norton. I have not tried the retail anti-spyware products from these venders.

I have some interesting and successful results using GhostSurf. This utility / service directs traffic through their servers, and claim to be able to make your surfing anonymous. However, some feature at some sites did not work when using the service.

Basically, one utility may detect something another did not. How well they work depends on what got into your system. The real trick is to update your definition files -frequently

Richard
 
Hay bill I thought that Counter Spy looked a lot like the MS's Anti Spyware. Couter Spy works on 98Se 15 day free trial just re boot after installing before useing. I had some problems that cleared up after a re boot.
 
Alltec,

Thank you for the report. I think the original GIANT software/CounterSpy engine quite a good thing, and since the purchase of GIANT by Microsoft some assurance that the definitions will be kept current.

The current Microsoft Beta version does not do cookie scanning, but I would certainly rank it very high -- and if using Win2k or higher versions of the OS it is free and intends to stay free. (Cookie scanning will be in the final, freeware in last Summer).


 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top