ok, im not that great with computers so bear with me.
running Win XP SP2
i think my hardware is irrelevant for this but if you need it let me know
ok, i was looking at the task manager and noticed that i have 84 process running, definitely waaaay to many. among these is about 20+ copies of master.exe (looking it up it seems to be spyware/malware or something) and a bunch of other things i’m not sure about.
Adaware shows nothing, microsoft Antispyware shows nothing, spybot shows nothing. only thing that ever comes up in scans are tracking caches.
Some other programs though picked up keyloggers and other stuff that the ones i have don’t find but won’t do anything unless I buy the full versions. I definitely don’t want these either on my comp.
I’ve not yet experienced any overt problems. manually killing the processes doesn’t work. not really sure what I should be doing at this point.
The bandits who wants your information to sell…
…are working around the clock to find a way to BEAT the ad-aware,
virus, and anti-worm software… ALL the time!
And they usually make it.
So what does the smart user do? Don´t take anything for granted
and check stuff out yourself.
But you´re not very technical?
Oh - sooner or later you will be…you´re working on computers
and most people today become more and more computer sawy
because it´s no longer a nerds-only thing.
What on earth is that? A gazillion codes that scrolls past my eyes
just like in the Matrix? How can that be of any use to me?
well - use it, get used to it…and learn the traffic on your computer.
As soon as you suspect foul play…turn on ethereal and watch
the incoming/outgoing traffic LIVE as it happens…
The Destination ip´s shown…and the packets unfolded usually
helps you to spot the culprit…
…is someone who doesn´t belong in your computer phoning home?
Avoiding your ad-aware/Zone-Alarm? Are your zone-alarm phoing
home too? Innocent? I think not! check stuff out yourself, learn
and enjoy a safer computer life
You’ll probably need to remove them manually, which will involve some tweaking to the registry. I’m reposting some instruction one guy wrote up on a forum I used to visit (original here, thanks GBK). They’re pretty comprehensive, but if you need more help, just post again here.
(you will need the Spybot S&D installer and HijackThis burned to a CD for this…)
Reboot into Safe mode, Command prompt only. This can be done by repeatedly tapping “F8” while booting.
Press Ctrl+Alt+Delete, click on “Proccess”, check for anything funny. It should be clean, but just make sure.
Using the command prompt, run “regedit”. This will load the Registry editor.
Navigate to " HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Curr
ent Version\Run". Any spyware on the system will have a reference in this list.
Run through the list one by one and check the executable name/path. If you recognize it as legit, skip it. If you dont recognize it, look up the executable name on Google. If you recognize it as spyware, move on to step 5a.
5a) If the item is spyware, jot down its path. If only the filename is in ithe path, its likely in “C:\windows”.
5b) Using the command promt, CD into the path containing the spyware’s executable. Run “dir FILENAME” and see if it is listed. If it is, run “delete FILENAME” to remove it. If it isnt, run “attrib -h -s -r FILENAME”, then “dir “FILENAME” again. The file should then appear. If the executable is in its own folder in “\program files”, remove the entire folder with “delete *” then “cd …/” and “rmdir FOLDERNAME”. If the folder contains subfolders, recursively remove their contents with “delete *”, and then the folders themselves with “rmdir FOLDERNAME”.
5c) Delete the item from the Registry.
6) In the Registry editor, check for other folders under " HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Curr
ent Version” that start with “Run”. Examples would include “RunOnce” and “RunServices”. If such a folder exists, enter it and go back to step 5.
7) Exit the registry editor.
Using the command prompt, run “services.msc”.
Go through the list one by one. Legit services will have realistic-sounding descriptions, illegit ones will either lack a description, or have somthing stupid. If you cant tell, look up the service name on Google.
9a) If you have identified a service as spyware, doubleclick on the entry to load the properties dialog. If the service is running, click on “Stop”, then change the “startup type” from “automatic” to “disabled”.
9b) Jot down the executable name and path of the service.
9c) Using the command prompt, navigate the path containing the service. Run “dir FILENAME” and see if it is listed. If it is, run “delete FILENAME” to remove it. If it isnt, run “attrib -h -s -r FILENAME”, then "dir “FILENAME” again. The file should then appear. If the service is in its own folder in “\program files”, remove the entire folder with “delete *” then “cd …/” and “rmdir FOLDERNAME”. If the folder contains subfolders, recursively remove their contents with “delete *”, and then the folders themselves with “rmdir FOLDERNAME”.
10) Close the Services editor window.
11) Reboot. Do this by pressing Ctrl+Alt+Del, clicking “Shut down”, then “Restart”. Windows needs to be shut down normally in order to preserve the changes to the registry youve made.
12) Use “F8” and boot back into Safe mode Command prompt only. Do NOT boot normally.
Put your Spybot/Hijackthis CD into the tray.
Using the command prompt, run “D:” to switch to the CD. If ‘D’ is not your CDrom, replace ‘D’ with the correct drive letter.
Run HijackThis.
15a) HT will report a number of false positives, but a clean system will have few or no BHOs, so assuming one is spyware is generally safe.
15b) Using the command prompt, navigate the folder containing the object. Run “delete OBJECTNAME” to remove the object.
Close HijackThis.
Run the Spybot S&D installer. Enable TeaTimer.
Run a spyware scan. Repair any results.
Reboot. Let windows boot normally.
Run Windows Explorer, then close it. Repeat this twice.
Run Internet Explorer, then close it. Repeat this twice.
Run Spybot S&D, then run a spyware scan. If there are any results, repair them.
thanks for the quick replies. It looks like I have some work to do. by the way i use firefox (stopped using ie several months ago). I really don’t know how all this stuff got on since i only really ever go to elysiun, cgtalk, and my school websites. i don’t use messenger etc and i don’t open e-mails except for those I’m sure of. I think it might have come from my little sister whose computer is networked to mine and surfs a lot more randomly than i do. Of course, thats kind of irrelevant right now except i guess i have to check hers too.
can’t do anything tonight since i have an exam tomorrow morning, but I’ll try to follow your advice and fix things soon. Well, if worst comes to worst and i royally screw over my comp i could just reformat (i’ll transfer important files before i do anything)
I’ll come back when i actually start doing stuff. thanks for the advice so far.
I would say, track down the companies doing that, ask your lawyer about information and get a claim. Say that you missed 1000’s of dollars because your computer was running a way too slow to make money with your work. In Usa is everything possible to claim money. So If I was a USAér I defently had claimed one. It’s the same as stealing, it’s not legal all that spyware, and even worser, they didn’t inform you about if they where allowed to install all that stuff on your pc and get information.
The law of privacy is badly violanced here, a big claim can be claimed for that I’m sure about that. :<
A few months ago I had a company hacking my computer. A company that selled anitvirus, anithacker and firewall software, who had installed balck ice EvilFTP on my computer and installed around 15 aplications on my computer, hacked my server and network.
All I did was get all the information, made screens of the add/remove software window, visited there website, and I found a complete ftp log on my system folder showing what they did all the time. I backuped that stuff and I tolod myself if it happens again I should claim something.
I also told the internet police about it and they said, if it happens again we can take some action.
I send an e-mail to the company, and saying they didn’t do anything, gehehe sure that’s why the ftp log says who was loggin on from which ip.
hmmm…okay i didn’t any registry editing or complicated stuff yet. The (non-free) spyware removal programs detected some stuff but wouldn’t remove them unless i bought the full version. anyways, i just deleted the entire folders that it mentioned (they were old games that i don’t play anymore). I also uninstalled a bunch of programs i don’t use anymore (though i don’t think thats relevant). anyways, i’m down to about 50ish processes , which is how many there were when i bought this computer, and all of them seem to be legit. the duplicate master.exe’s seem to be gone too.
I’ll probably leave it at that for right now, if i start having problems again I’ll run through the suggestions in this thread.
oh, and about suing for lost money that would be nice but pretty hard to do since i’m a high school student and i don’t make money with anything on my computer . I’ll keep that in mind for later though, thanks.
Have SERIOUS doubts about what the non-free spyware scanners say. My friend had a completely clean computer, installed one of those, and it detected some keyloggers and spyware in the strangest places.
Apparantly cygwin wget is a keylogger now.
Our theory is that they want to get you really scared and fork over for the full version. When you get it and it finds nothing, they can say “well the free version isn’t guaranteed.”
Are you sure you got the right one? I’ve installed Spybot on a number of computers and never had any problems. Double-check what you downloaded as a lot of adware programs have similar names to Adaware and Spybot in order to trick people.
I was going through my C drive. I found this folder called address logger i think. I opened it and it had a list of all of the poeple’s email addresses on all of the email accounts on my comp. I know i didn’t put it there.