A word about spyware, hijacks, trojans, worms & dialers - X Nations
      
      
Go Back   X Nations > X Nations > General Webmaster Business and Discussions

Reply
 
Thread Tools Display Modes
Old 04-18-2004, 10:26 PM   #1
bongo3
bongo3 should edit this
Citizen X
 
Join Date: Apr 2004
Location: USA
Posts: 5
xBucks: 353
Angry A word about spyware, hijacks, trojans, worms & dialers

Hi there,

i spent the last hour to remove a fuckin dialer.
Normally hijackthis, cws, ad aware and pestpatrol
get rid of that stuff.
Anyone having problems removing that stuff?

i put together some free software links and some hints
to remove unwanted software such as
spyware, worms, trojans, dialers & hijacks
you are redirected to other websites?

http://www.tgpbb.com/aboutspyware/index.html

the tools are free and there is no affiliate link
bye
Bongo
bongo3 is offline   Reply With Quote
Old 04-18-2004, 10:31 PM   #2
nanda
nanda should edit this
Senior Member
 
nanda's Avatar
 
Join Date: Feb 2004
Location: African Safari
Posts: 497
xBucks: 548
Default

Next time I get attacked with that crap, I'll keep ur link in mind. A few months ago I had to redo my hard drive b/c those stupid pop up crap...I didn't even know what it was, I tried everything and just had to redo....THANKS!
nanda is offline   Reply With Quote
Old 04-18-2004, 11:16 PM   #3
gunner
gunner should edit this
your head in my bag
 
gunner's Avatar
 
Join Date: Sep 2002
Location: IL
Posts: 587
xBucks: 3,542
Send a message via ICQ to gunner
Default

nice page bongo, that crap is a pain to get rid of and your links will surely help.

hit me up on ICQ or email, I have a question about your TGP
"gunner AT spread4u DOT com"
gunner is offline   Reply With Quote
Old 04-19-2004, 03:04 AM   #4
monaro
monaro should edit this Edit
Guest
 
Posts: n/a
xBucks: 0 [Check]
Default Re: A word about spyware, hijacks, trojans, worms & dialers

Most of the time it comes from sites that have free porn, and are sites that are not well known. if i want to take it easy for 30 mins or so, i will only surf the hun and thumbzilla even then I i turn off cookies and set my broswer to high security.

If i am looking for webmaster info i only stick to places that i feel that are safe. But even then i can come unstuck like what happened to me when i reviewed a site that was posted on xnations a week or so ago. I dont like to do it, but if i find anything different with my settings, i wil just reformat the box and with the aid of norton ghost, i can be back within 40 minutes, i back up everytime i have done my work and this is placed onto a cd rw. and i will not click on links that have some java script to hide the url. I will search goofle for the url and see if this is a ture url. It might take 2 minutes to do this process, but i know that i am
not going to have to waist 40 minutes to reformat.

I write the urls onto a pad before i click and if that site does some shit, i take it to a higher level, eg, i will write a letter to abuse@ the hosting company of that domain, to the domain register company, trace a email address and write to their isp.

Some might think I go too far, but i bet alot of people are not getting that same shit happen to them. I will never know, ie can block domians so i will never go there ever again.
  Reply With Quote
Old 04-19-2004, 10:44 AM   #5
sweet7
sweet7 should edit this
Squirrels are admins too!
 
sweet7's Avatar
 
Join Date: Mar 2004
Location: MTL
Posts: 1,472
xBucks: 3,225
Send a message via ICQ to sweet7
Default Re: A word about spyware, hijacks, trojans, worms & dialers

Quote:
Originally posted by bongo3
Hi there,

i spent the last hour to remove a fuckin dialer.
Normally hijackthis, cws, ad aware and pestpatrol
get rid of that stuff.
Anyone having problems removing that stuff?

i put together some free software links and some hints
to remove unwanted software such as
spyware, worms, trojans, dialers & hijacks
you are redirected to other websites?

http://www.tgpbb.com/aboutspyware/index.html

the tools are free and there is no affiliate link
bye
Bongo
Gonna check that out later I'm having a browser hijack problem with IE. Thanks bongo3
__________________
<embed src="http://banners.videosz.com/webmasters/flash/120x60-1.swf" quality=high WIDTH="120" HEIGHT="60" menu="false" FlashVars="link=http%3A%2F%2Fwebmasters.videosz.co m%2Findex.php%3Fwebmaster_id%3D81"></embed>
ICQ: 282814268
sweet7 is offline   Reply With Quote
Old 04-19-2004, 08:14 PM   #6
sweet7
sweet7 should edit this
Squirrels are admins too!
 
sweet7's Avatar
 
Join Date: Mar 2004
Location: MTL
Posts: 1,472
xBucks: 3,225
Send a message via ICQ to sweet7
Default

hey bongo3 how did you remove your browser hijack?

mine keeps redirecting to nkvd.us/1525/. I have tried hijackthis before today and it doesn't seem to do the trick.
__________________
<embed src="http://banners.videosz.com/webmasters/flash/120x60-1.swf" quality=high WIDTH="120" HEIGHT="60" menu="false" FlashVars="link=http%3A%2F%2Fwebmasters.videosz.co m%2Findex.php%3Fwebmaster_id%3D81"></embed>
ICQ: 282814268
sweet7 is offline   Reply With Quote
Old 04-19-2004, 08:50 PM   #7
Gruntled
Gruntled is [Too Long]
not actually disgruntled.
 
Gruntled's Avatar
 
Join Date: Jan 2004
Location: Atlanta, GA
Posts: 1,088
xBucks: 2,896
Send a message via ICQ to Gruntled
Default

Try SpyBot: S&D About halfway down the page.

It has options to protect against browser hijacks, etc, and removes all known spybots, hijackers, and adware.
__________________
Gruntled is offline   Reply With Quote
Old 04-19-2004, 09:45 PM   #8
SKULL
SKULL should edit this
Sombrero King
 
SKULL's Avatar
 
Join Date: Jun 2003
Location: PA, NJ, NY
Posts: 130
xBucks: 3,251
Send a message via ICQ to SKULL
Default

Thanx a lot for this.. bookmarked...
SKULL is offline   Reply With Quote
Old 04-19-2004, 10:17 PM   #9
sweet7
sweet7 should edit this
Squirrels are admins too!
 
sweet7's Avatar
 
Join Date: Mar 2004
Location: MTL
Posts: 1,472
xBucks: 3,225
Send a message via ICQ to sweet7
Default

What do you mean when you say "half way down the page" ?

I've just ran spybot s&d and it finds the problem but it doesn't seem to be getting to the root of it.
__________________
<embed src="http://banners.videosz.com/webmasters/flash/120x60-1.swf" quality=high WIDTH="120" HEIGHT="60" menu="false" FlashVars="link=http%3A%2F%2Fwebmasters.videosz.co m%2Findex.php%3Fwebmaster_id%3D81"></embed>
ICQ: 282814268
sweet7 is offline   Reply With Quote
Old 04-19-2004, 11:32 PM   #10
Don Soporno
Don Soporno should edit this
Get your Blog STOMPED!!
 
Don Soporno's Avatar
 
Join Date: Feb 2004
Location: Dirty Dirty Dirty Dirty South
Posts: 1,470
xBucks: 10,260
Send a message via ICQ to Don Soporno
Default

Quote:
Originally posted by Gruntled
Try SpyBot: S&D About halfway down the page.

It has options to protect against browser hijacks, etc, and removes all known spybots, hijackers, and adware.

S7D didnt work for me either, the problem kept comming back. I finally used a combo of 3 or 4 different programs and got mostly everyhting back to normal. Hot me up on ICQ sweet, I may have a program you can use to fix it.
Don Soporno is offline   Reply With Quote
Old 04-19-2004, 11:32 PM   #11
Gruntled
Gruntled is [Too Long]
not actually disgruntled.
 
Gruntled's Avatar
 
Join Date: Jan 2004
Location: Atlanta, GA
Posts: 1,088
xBucks: 2,896
Send a message via ICQ to Gruntled
Default

Oh. If you follow the link I gave, halfway down the page is the download link.


If it finds the problem,and the file is locked, it will ask permission to run at startup. grant this permission and reboot. It has always worked for me.

What's the name of the offending program, by the way?
__________________
Gruntled is offline   Reply With Quote
Old 04-20-2004, 01:27 PM   #12
Mister X
Mister X should edit this
FunB Fan Club Prez
 
Mister X's Avatar
 
Join Date: Aug 2002
Location: Montreal baby!
Posts: 1,997
xBucks: 10,431
Send a message via ICQ to Mister X
Default

Here's a useful tip for those of you that have trouble removing this shit. A lot of these programs are running in memory and they use filenames such as services.exe or winlogon.exe. You can not delete the file while the program is running and you won't be able to use taskmanager to stop the program because it will rather stupidly insist that the file is a system resource that can't be stopped. You will know when you have one of these when you see the program twice in taskmanager, once as SYSTEM and once as whatever your login name is. Only the SYSTEM one is legit. Using programs such as hijackthis will not work because these programs check every few seconds and will reinsert themselves into the registry. To get rid of them you need to do one of 2 things. Either use a program like RegRun which will start before windows starts and give you an opportunity to remove this crap or reboot in safe mode and use hijackthis or a similar program to clean the registry and delete the file.

And another tip is to throw ad-aware in the trash. Or at least limit it's use to looking for basic spyware. It is updated far too slowly and is totally ineffective against most scumware and trojans.
__________________
<table width="95%" border="0"><tr><td><font size="-2"><a href="http://refer.ccbill.com/cgi-bin/clicks.cgi?CA=923906-0000&PA=462029&HTML=http://www.eromodelcash.com">Eromodel Cash. Promote it now!</a></font></td><td><div align="right"><font size="-2"><a href="http://www.eromodelgroup.com">Eromodel Group- for ALL your needs </a></font></div></td><td width="125" rowspan="3"><div align="right"><a href="http://refer.ccbill.com/cgi-bin/clicks.cgi?CA=923906-0000&PA=462029&HTML=http://www.eromodelcash.com"><img src="http://www.eromodelcash.com/Banner/00102.gif" width="120" height="60" border="0"></a></div></td></tr><tr><td width="40%"><font size="-2"><a href="http://www.lannibarbie.com">Lanny Barbie is THE Hottest New Pornstar</a></font></td><td><div align="right"><font size="-2"><a href="mailto:stewREMOVE@eromodelgroup.com?Subject= Hi%20There">Contact Me</a></font></div></td></tr><tr><td><a href="http://www.judystarxxx.com"><font size="-2">JudyStarXXX.com</font></a></td><td><div align="right"><font size="-2">ICQ #165144564</font></div></td></tr></table>
Mister X is offline   Reply With Quote
Old 04-25-2004, 11:52 AM   #13
sweet7
sweet7 should edit this
Squirrels are admins too!
 
sweet7's Avatar
 
Join Date: Mar 2004
Location: MTL
Posts: 1,472
xBucks: 3,225
Send a message via ICQ to sweet7
Default

Quote:
Originally posted by Gruntled
Oh. If you follow the link I gave, halfway down the page is the download link.


If it finds the problem,and the file is locked, it will ask permission to run at startup. grant this permission and reboot. It has always worked for me.

What's the name of the offending program, by the way?
I really don't know all I know is that it redirects my IE to nkvd.us
__________________
<embed src="http://banners.videosz.com/webmasters/flash/120x60-1.swf" quality=high WIDTH="120" HEIGHT="60" menu="false" FlashVars="link=http%3A%2F%2Fwebmasters.videosz.co m%2Findex.php%3Fwebmaster_id%3D81"></embed>
ICQ: 282814268
sweet7 is offline   Reply With Quote
Old 04-25-2004, 01:36 PM   #14
[tuka]
[tuka] should edit this
.
 
[tuka]'s Avatar
 
Join Date: Jan 2004
Location: Montreal
Posts: 20
xBucks: 20
Send a message via ICQ to [tuka]
Default

Quote:
Originally posted by sweet7
I really don't know all I know is that it redirects my IE to nkvd.us
Well, you could start by using something else to download removal soft (NN, Mozilla)

can also try to remove manually from the regedit (can make a search for nkvd.us), chances are it will be in HKLM... might want to clean your msconfig first though
[tuka] is offline   Reply With Quote
Old 04-25-2004, 02:48 PM   #15
sweet7
sweet7 should edit this
Squirrels are admins too!
 
sweet7's Avatar
 
Join Date: Mar 2004
Location: MTL
Posts: 1,472
xBucks: 3,225
Send a message via ICQ to sweet7
Default

I'm using Firebird at the moment it rocks except I haven't figured out how to get wmv files to load properly yet.

I'm going to try that registry search
__________________
<embed src="http://banners.videosz.com/webmasters/flash/120x60-1.swf" quality=high WIDTH="120" HEIGHT="60" menu="false" FlashVars="link=http%3A%2F%2Fwebmasters.videosz.co m%2Findex.php%3Fwebmaster_id%3D81"></embed>
ICQ: 282814268
sweet7 is offline   Reply With Quote
Old 04-28-2004, 04:24 PM   #16
Mister X
Mister X should edit this
FunB Fan Club Prez
 
Mister X's Avatar
 
Join Date: Aug 2002
Location: Montreal baby!
Posts: 1,997
xBucks: 10,431
Send a message via ICQ to Mister X
Default

You might want to try getting media player classic for the wmvs. Not sure about firebird but it works great with mozilla 1.7. You can also get it to open your quicktime and real player shit which is a big plus. Just do a google search for "media player classic".

If the problem is with embedded wmv's I don't know if it will work or not. Firebird isn't quite up to snuff in that area yet I think.
__________________
<table width="95%" border="0"><tr><td><font size="-2"><a href="http://refer.ccbill.com/cgi-bin/clicks.cgi?CA=923906-0000&PA=462029&HTML=http://www.eromodelcash.com">Eromodel Cash. Promote it now!</a></font></td><td><div align="right"><font size="-2"><a href="http://www.eromodelgroup.com">Eromodel Group- for ALL your needs </a></font></div></td><td width="125" rowspan="3"><div align="right"><a href="http://refer.ccbill.com/cgi-bin/clicks.cgi?CA=923906-0000&PA=462029&HTML=http://www.eromodelcash.com"><img src="http://www.eromodelcash.com/Banner/00102.gif" width="120" height="60" border="0"></a></div></td></tr><tr><td width="40%"><font size="-2"><a href="http://www.lannibarbie.com">Lanny Barbie is THE Hottest New Pornstar</a></font></td><td><div align="right"><font size="-2"><a href="mailto:stewREMOVE@eromodelgroup.com?Subject= Hi%20There">Contact Me</a></font></div></td></tr><tr><td><a href="http://www.judystarxxx.com"><font size="-2">JudyStarXXX.com</font></a></td><td><div align="right"><font size="-2">ICQ #165144564</font></div></td></tr></table>
Mister X is offline   Reply With Quote
Old 04-29-2004, 12:25 AM   #17
Gruntled
Gruntled is [Too Long]
not actually disgruntled.
 
Gruntled's Avatar
 
Join Date: Jan 2004
Location: Atlanta, GA
Posts: 1,088
xBucks: 2,896
Send a message via ICQ to Gruntled
Default

I use Firefox on all my machines (there was a snafu over the name, so they changed the name with the last update). On Linux, MPlayer handles the wmv files, and there is a plugin for the browser. On windows, I've been using Winamp5 for wmv's.
__________________
Gruntled is offline   Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On
Forum Jump

Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.
vBCredits v1.4 Copyright ©2007 - 2008, PixelFX Studios
2013 - xnations.com
All times are GMT -4. The time now is 09:16 PM.
Skin by vBCore.com