Computing.Net > Forums > Security and Virus > Virus? Spyware? ActiveX?

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

Virus? Spyware? ActiveX?

Reply to Message Icon

Name: Cliff
Date: October 29, 2002 at 15:45:15 Pacific
OS: WinME
CPU/Ram: P3 800/128
Comment:

Whats going on? Norton Antivirus says ths system is clean. AVG says the system is clean. Housecall will not finish downloading. AdAware also says the system is clean. BUT! Every time the computer is restarted, the I.E. home page is set back to http://www.secret-crush.com/search/ and the system seems to be running sluggishly. Might there have been something installed with Morphius or Kazaa that is not being picked up by any of the scanners I listed? Anyone have any ideas?



Sponsored Link
Ads by Google

Response Number 1
Name: Evil Underdog
Date: October 29, 2002 at 15:53:43 Pacific
Reply:

Windows ME & XP has a place that it makes backups of some files. It is loctaed @ C:\_Restore\Temp. If a virus is in there your AV software will not be able to detect it. Just a possibility.

V-Peace-V


0

Response Number 2
Name: Jim Beau
Date: October 29, 2002 at 15:58:34 Pacific
Reply:

Cliff.This sounds like a browser hi-jacking.That seems to be the new "nasty".Secret Crush is in the hi-jackers incudes list on Spybot search and destroy version 1.1. I would try running Spybot.You can get a download at a lot of websites.I got the download at lurkhere.com.It's listed in the "nice files".Update it right away before scanning.The "on-line" tab gets you to the update function.Updating can take a little time.I use it on xp home and haven't had any problems.The info&license tabs and "credits"will give you a link to the support forum if you need assistance or have any questions.Hope this helps.JB


0

Response Number 3
Name: Cliff
Date: October 29, 2002 at 16:14:00 Pacific
Reply:

Wow! Spybot got 64 things that AdAware did not catch!


0

Response Number 4
Name: Jim Beau
Date: October 29, 2002 at 17:00:22 Pacific
Reply:

The new version rocks!!!!Glad that Spybot helped you!It automatically has a check mark on spyware it found.The registry finds I don't clean usually.I have jv16 Power Tools to clean the registry.I just use it for spyware and tracks removal.The "finds" are color-coded.That helps.Adaware is good,don't get me wrong!It's just that Spybot's database(includes) is growing so fast!Adaware doesn't update as frequently as they used to.Regards.JB


0

Response Number 5
Name: hylian_lynk
Date: October 29, 2002 at 18:15:17 Pacific
Reply:

HAVE A READ :)
Home Page Hijacking - "Has your Browser Been Hijacked?"

You have been surfing all over the web for hours and hours, you close your browser and take a break. You come back to your PC a few hours later and fire up your browser. Wait a minute! That isn't my home page! What happened to my home page? You realize that your normal home page is no longer there and some new page is there and pop-up ads start appearing from out of no where, even when your browser is closed.

Your browser has been hijacked...

There is a new type of advertising/marketing that sneaks on to your system without you knowing it. Most of the time this new and infuriating marketing was piggybacked on software that you downloaded and installed or from a web page that you happened upon. It is infuriating to say the least and it really angers you that someone has made changes to your computer without your consent.

Well, there are several measures to follow to keep this from happening. NEVER EVER install anything that is offered to you while surfing. Only install software that you recognize or trust. Before installing anything read the EULA (End Users License Agreement), often they disclose that the software you are installing contains other programs that will serve you ads or monitor you usage and browsing. If the EULA states that, cancel the installation and delete the software. You can also set the security in your browser to stop the installation of desktop items and to no allow cut and past via script and and other security measures like not accepting unsigned activeX code, etc. The best thing to do is be very skeptical of all software on the Internet you never heard of. For all you know it could contain a virus, trojan or scumware.

Sandi Hardmeier (a fellow Microsoft MVP - home page below) says to make sure your Java VM is at least version 3805 to protect against a vulnerability that allows website operators to change your home page and several other vulnerabilities. This is the main way hijacking occurs via surfing the web via a web browser. The download is available here:
http://www.microsoft.com/java/vm/dl_vm40.htm

Want to lock your home page to prevent it from being hijacked? Here are two registry keys for Windows users, that will lock or unlock your homepage. Don't worry they are safe. These are from Kent England (another fellow Microsoft MVP): HomePagelock-unlock.zip

As a side note make sure you have anti-virus software running on your PC and be sure to update it at least once a month. We update ours weekly just to make sure nothing sneaks through.

Too late? Already been hijacked? Well there are several ways to detect and delete the offending software. The best and easiest to use (AND IT IS FREE) is AD-AWARE from Lavasoft. It scans your registry and hard drive for spyware, sneak-ware, scum-ware, theftware and other deceptive software that has been installed on your system without your knowledge. You can download it or read about it at the link below. You can even set it to scan your PC each time you start up!

Examples of scumware: LOP (one of the worst and sneakiest - takes over as your home page and no uninstall feature in add-remove programs (control panel)), GATOR, TOPTEXT, Bargain Buddy, KazAa, Surf+, Spedia, eZula and there are many others. Read below to find out more about this rapidly growing deceptive advertising technology.

LavaSoft - http://www.lavasoftusa.com/
I highly recommend installing this even if you haven't been hijacked as allowing it to scan will tell you if there is any suspicious software hiding on your PC. LavaSoft updates the Ad-Aware software frequently to keep up with those aggravating and sneaky marketing companies.

There are several sites that list scum-ware and sneak-ware so you can make sure you aren't downloading something that is going to take control of your browser or Operating System.

Scumware Links - http://www.scumwarelinks.com/
This site lists current scumware and sneakware so you can make sure you aren't installing anything that you will later regret (a must Read)

Scumware.com - http://scumware.com/
Information regarding scumware and how to get rid of it

Search King - Web Watch Alert - http://wwa.searchking.com/
This site has nice resources for finding out about scumware, viruses, email scams, etc.

StopScum - http://stopscum.com/
This site covers various scumware and helps put you in control by helping you take a stand against it and other theftware. Help stop it.

Cre8pc - http://www.cre8pc.com/spam_scam.html
Information on Internet Scams (email, website schemes and scams), scumware info and removal information and Search Engine Scams.
"Have you lost money on Internet schemes? Are you sick of deleting unwanted SPAM email? Do you wonder how in the world your email address got out to so many people?"

"Search Engine Scams - There are NO submission offers coming into your email box that are legitimate. Only professional Search Engine Optimization experts know the ins and outs of search engine rules for rank, and their algorithms. Even they will admit that search portals aren't forthcoming with what they consider scam and what they will ban from their databases. Thousands of people use automatic submission services and find their websites permanently banned from engines as a result. Search engine rank can not be sustained without proper site design and maintenance. Anyone who tells you otherwise is most likely inexperienced, or out to scam you. "

Thiefware - http://www.thiefware.com/
"Dot.coms are looking for other revenue streams due to revenue slumps. The banner ad market isn't nearly as lucrative as it once was. One answer to this is to use the content and real estate of other sites to sell ad space. While this is not a new concept in itself, the way it is being done is new and ThiefWare.com believes some of the methods used are unethical or disagreeable."

"These ad services accomplish this by having the computer user install knowingly or unknowingly their software - we call it ThiefWare. The question is “do you have ThiefWare on your computer?

Parasiteware - http://www.parasiteware.com/
Information on scumware, parasiteware and more
"ParasiteWare™ is software that you download, knowingly or not as it may come bundled with other applications or as deceptive downloads and consists of 'adware' which is unwanted advertising via pop-up, slider, pop-under or add links to sites for which the original owner does not get paid for and hijacks the affiliate link on their sites ... their sole purpose is to worm their way onto your computer and assault you with advertising all day!"

Spyware - http://www.simplythebest.net/info/spyware.html
"Spyware is published as 'freeware' or as 'adware', but the fact that an analysis and tracking program (which reports your activities to the advertising providers' web site for storage and analysis, the 'spyware' agent) is also installed on your system when you install this so-called 'freeware', is usually not mentioned. Even though the name may indicate so, spyware is not an illegal type of software in any way. But what the adware and spyware providers do with the collected information and what they're going to 'feed' you with, is beyond your control. That makes it a highly undesirable activity and it should be banned from the Internet as of today."

Unsolicited Commercial Software Detector - http://and.doxdesk.com/parasite/
"There are a lot of dodgy programs out there that may get installed on users' computers without their knowledge or consent. Many applications described as "freeware" come infested with parasitic software that latches onto the web browser, provides little or no benefit to the user and can: plague you with unwanted advertising, watch and report on everything you do on your PC, open security holes on your PC, degrade performance just to mention a few."

Home Page Hijacking Advice from Sandi Hardmeier (Fellow Microsoft MVP)
http://209.68.48.119/inetexplorer/answers.htm#home_page
"This advice covers two types of home page locking - hijacking (by web sites) and locking (by ISPs when you install their software, and computer manufacturers)"

http://209.68.48.119/inetexplorer/Darnit.htm#hijackings

Sandi's LOP (scumware) Uninstall Advice
http://209.68.48.119/inetexplorer/Darnit.htm#lop

Still have problems? You may just have to reformat your PC and re-install your operating system, all thanks to greedy marketers and advertisers.


0

Related Posts

See More



Response Number 6
Name: wawadave
Date: October 29, 2002 at 18:55:59 Pacific
Reply:

for the running sluggishly try these
http://computing.net/windowsme/wwwboard/forum/18106.html how 2 run m.e well ver.3

http://computing.net/windowsme/wwwboard/forum/30687.html

http://www.computing.net/windowsme/wwwboard/forum/24159.html how 2 run m.e ver.4

and for running vidio and tuneing m.e try this link
http://www.videoguys.com/WinME_Tweaks.html


0

Response Number 7
Name: Jim Beau
Date: November 1, 2002 at 14:18:05 Pacific
Reply:

Just one thing to add to what hylian link posted.I always download a program that I want to install either from the pogram's home page(usually a security program)which should be safe.Or I download from a site that I trust:webattack,wilders,spywareinfo,Major Geeks,Tucows.I stay away from anything that has warez,hackers etc.. in the address or description just to be on the safe side.And I no longer use P2P sites.I'm suggesting not using P2P sites,but it's a free country.If you do use them,scan downloaded files with an AV or AT program.Regards.JB


0

Sponsored Link
Ads by Google
Reply to Message Icon

Kerio Firewall issues Cyber Terrorism



Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home


Sponsored links

Ads by Google


Results for: Virus? Spyware? ActiveX?

virus/spyware removed programs www.computing.net/answers/security/virusspyware-removed-programs-/20907.html

Help with a virus/spyware www.computing.net/answers/security/help-with-a-virusspyware/17973.html

hidden virus/spyware or false alarm www.computing.net/answers/security/hidden-virusspyware-or-false-alarm/18184.html