I have a little spyware question

Dingas

Senior member
Jun 8, 2001
454
0
0
When I try to visit ebay.com it instead sends me to a search site. All of the links on the search site are from a site called Becomers dot com (dont want to link it). My updated norton tells me I have no virii, my ad aware says nothing, but, everytime I run spybot S & D it tells me I have a DSO exploit with 5 different problems, and it removes them. The second I open up my IE again, the exploit returns.

Any ideas?

Thanks
 

fuzzynavel

Senior member
Sep 10, 2004
629
0
0
don't use IE... download firefox instead!!!

Try making sure the host file in system32 file doesn't have any extra entries....also make sure that your DNS addresses are still the same as when your ISP told u them....

Have you got all the latest updates for windows and IE???

Which version of windows are you using?

Are your virus definitions and adaware files up to date?
 

Dingas

Senior member
Jun 8, 2001
454
0
0
Well, i actually downloaded that firefox right now just to see, and tried going to ebay, and it sent me to that dumb search site again..

I could not find a "host.***" file in the c:\windows\system32 folder.

My windows updates are not done, I cant do them... nuff said.

Norton anti virus is up to date, along with the two spyware programs im using. I have not ever heard of microsoft anti spyware.
 

fuzzynavel

Senior member
Sep 10, 2004
629
0
0
can't do win update??? why if you don't mind answering......dodgy windows ......i have seen a lot of dodgy windows that update normally etc can install SP1 and SP2 with no issue!

My hosts file is actually in C:\WINDOWS\system32\drivers\etc and looks a bit like this

# Copyright (c) 1993-1999 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host
127.0.0.1 localhost
# 192.168.0.6 dlink.com
# 192.168.0.6 ftp.dlink.com
# 192.168.0.6 hqftp.dlink.com

just igore th dlink stuff was rerouting dns to update myDSM320 medialounge thingy but everything down to the 127.0.0.1 localhost line is standard

LINKY FOR MS ANTI SPYWARE
 

FlyingPenguin

Golden Member
Nov 1, 2000
1,793
0
0
While I too highly recommend Firefox (been using it for over a year) that alone won't help you if you're infected by spyware. You need to make sure your system is clean. Very likely your HOSTS file has been compromised and that will affect ANY browser.

I do computer repair work and I'd say that 70% of my service calls are spyware now

Adaware and Spybot have both been off my radar for 8 months. They just don't do the job anymore.

I run BHODemon first to "unhook" spyware from Internet Explore and Windows Explorer (otherwise every time you open an Explorer window you re-infect yourself). This is a common tactic used by most of the worst spyware. You clean it, then open My Computer or ANY Explorer window (even Control Panel) and get re-infected again (let me compliment Microsoft on their brilliant {sarcasm} decision to incorporate IE into the OS).

I would then use the Webroot SpySweeper if it's a Win98 system, or Microsoft's free Anti-Spyware if it's a WinXP system (MS Anti-Spyware won't install on a 98 system).

If it's a badly infected XP system I'd run both of them.

Either of these will also run in the background to protect you from SOME spyware infection (no stopping spyware if people are stupid though). SpySweeper is excellent but costs $29 a year. Microsoft's is free (for now) and is just as good (so far) as it's built around the very good Giant Anti Spyware engine.

Find your HOSTS file and make sure the ONLY entry is:
127.0.0.1 localhost
(any lines starting with a # sign are just remarks and are ignored).

Your HOSTS file is located here:
Windows XP = C:\WINDOWS\SYSTEM32\DRIVERS\ETC
Windows 2K = C:\WINNT\SYSTEM32\DRIVERS\ETC
Win 98\ME = C:\WINDOWS

SCROLL DOWN through the HOSTS file to make sure there are no other entries!!! Many spyware add the entries after a long blank area in the file so you don't see it unless you scroll down.

If it's a really, really badly infected system I would run CWShredder and Trojan Hunter afterwards. Then re-check your HOSTS file.

As with all anti-spyware apps you should install them then reboot into safe mode and do a FULL scan from safe mode. Many spyware can't be removed or even detected if they're running in the background. Booting into safemode disables most of them except the nastiest crap (like CoolWebSearch and about:blank).

You can download all the tools I mentioned from MajorGeeks.com. They're all in the Spyware section except Trojan Hunter which is in the Anti-virus section. ALWAY download tools like this from a KNOWN reputable site - there's a LOT of fake or tampered anti-spyware utilities out there now.

You should also check for these fake services created by Home Search Assistant (CWS_NS3):
- Network Security Service
- Workstation NetLogon Service
- Remote Procedure Call (RPC) Helper

Check the spelling CAREFULLY. These fakes are designed to look like legit services. There IS a real Remote Procedure Call (RPC) service, it just doesn't say "Helper" at the end. If you find any of them, turn them off and disable them, then run an anti-spyware scanner again.

Hope this helps...
 

Slvrtg277

Golden Member
Sep 9, 2004
1,004
0
0
What FlyingPenguin said.

Also if you are running ZoneAlarm, that could be the exploits that Spybot is finding. It's a normal occurance.
 

Dingas

Senior member
Jun 8, 2001
454
0
0
That was quite a messy hosts file!

Something about "klsupertrick"

Thanks guys =)
 

Stonesoldier

Member
Feb 10, 2005
137
0
0
i have been useing Counterspy from sunbelt software
so far they have worked very well
you can get a free scan here
http://www.sunbelt-software.com/dell/scan.cfm

also they have the typical 15 day freebie of counterspy
they get definitions from 3 sources
one of them is microsoft
sunbelt-software had a deal with giant software that MS has to honor so they get MS definitions till 2007 only $20 a year
http://www.sunbelt-software.com

also like flyin penguin said use cwshredder and trojan hunter

do it all in safe mode

 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |