Film-Tech Cinema Systems
Film-Tech Forum ARCHIVE


  
my profile | my password | search | faq & rules | forum home
  next oldest topic   next newest topic
» Film-Tech Forum ARCHIVE   » Community   » Film-Yak   » Adware...Kill me NOW (Page 1)

 
This topic comprises 2 pages: 1  2 
 
Author Topic: Adware...Kill me NOW
Rich Granata
Film Handler

Posts: 61
From: Bethlehem PA USA
Registered: Mar 2004


 - posted 09-20-2004 06:00 PM      Profile for Rich Granata   Email Rich Granata   Send New Private Message       Edit/Delete Post 
I've been working all day today trying to get rid of this crap. I had....non-stop pop ups, changing start pages, Slooow performance, odd behavior, popups etc. ITS ALL BULL. I've made a lot of progress, there are just a few bits and pieces of somethings left.

So I've been running Adware/Spyware scanners of all types all day. Pretty much any program with good protection costs 30 bones. ?!?!? doesn't anyone in good freeware anymore?

I USED TO BE INTO COMPUTERS...now i hate them as much as my grandparents. Back in the middle school days, when i was into really elementary hacking stuff, I found that "hackers" made the best computer security software and protection. But now, i haven't found any good free adware removal programs. don't these guys believe in the free world anymore? GOSH!

What do you computer dudes use?

I know you will tell me to get Mac OSX or linux, but unfortunately that's not an option because the rest of my family uses this computer. (PS. I know they are the culprits downloading crap/porn/whatnot)

 |  IP: Logged

Daryl C. W. O'Shea
Film God

Posts: 3977
From: Midland Ontario Canada (where Panavision & IMAX lenses come from)
Registered: Jun 2002


 - posted 09-20-2004 06:08 PM      Profile for Daryl C. W. O'Shea   Author's Homepage   Email Daryl C. W. O'Shea   Send New Private Message       Edit/Delete Post 
Sure, blame your porn collection on your family.

Yes, everything gets discussed here. Even pop-ups and malware. Do a search for "AdAware" in Film-Yak, or just download it at http://www.lavasoft.de/

 |  IP: Logged

Bobby Henderson
"Ask me about Trajan."

Posts: 10973
From: Lawton, OK, USA
Registered: Apr 2001


 - posted 09-20-2004 06:13 PM      Profile for Bobby Henderson   Email Bobby Henderson   Send New Private Message       Edit/Delete Post 
First thing: don't use Internet Explorer. Download and use an alternative web browser like Opera or Mozilla Firefox. I've been using Mozilla and then Firefox lately and haven't had any issues show up in spyware/adware scans since switching to those browsers. Firefox has been particularly good at blocking pop ups and other crap.

I use both Spy Bot Search and Destroy and AdAware. Both have free versions available, although you have to pay more for AdAware's pro version.

You might consider changing e-mail clients. Outlook Express is utter shit for all its default security liabilities. If you still insist on using it, disable the preview pane, select "read all messages as plain text" and disable the ability to view or save any attached files.

You also need to have a software firewall running on your computer as well as current anti-virus software. Having your computer behind a Cable/DSL router can be an added line of defense since those devices have their own basic firewall. If you have around $400 or so to spend you can buy better quality hardware firewalls.

No defense is perfect, which is why you must back up any sensitive data to other hard discs or burn to CD-R. I've seen versions of the Cool Web Search bug require a total format of the hard disc to get rid of it.

 |  IP: Logged

Rich Granata
Film Handler

Posts: 61
From: Bethlehem PA USA
Registered: Mar 2004


 - posted 09-20-2004 06:26 PM      Profile for Rich Granata   Email Rich Granata   Send New Private Message       Edit/Delete Post 
I hope it doesn't come to a format.
I've used everything you mentioned and more today, except i don't have a firewall.

My problem is... Ill deep scan for this crap, remove eveything, the program will say "complete"...then Ill scan again and find some of the same crap...this software SUCKS...and these are up-to-minute virus definitions. I also tried some manual removal procedures that I read today in various FAQs. They don't work either.

theres only 1 explanation... [uhoh] AI... [uhoh] its getting smarter.. [uhoh]

I do have 1-way cable though which means my IP address is always new. I'm worried anyway because whats to say that modern spyware won't upload my new IP address everytime i connect? I do CC transactions online occasionally, online banking, etc.... Im worried about that too.

I will try FireFox...I hear that it is very reliable and safe

 |  IP: Logged

Marc Hansen
Film Handler

Posts: 93
From: Seattle, WA, USA
Registered: Dec 2000


 - posted 09-20-2004 07:46 PM      Profile for Marc Hansen   Email Marc Hansen   Send New Private Message       Edit/Delete Post 
Be extremely careful of spelling, a few weeks ago I misspelled google(goggle)and before I realized what was happening something had infested my computer that I and my IT tech could not get out. finally had to dump everything and format the drive. Thank god for backups!! I'm on dial up and every hour or so it would open my internet software and try to dial home. I had to leave the phone line unhooked.

 |  IP: Logged

Dean Kollet
Jedi Master Film Handler

Posts: 591
From: Florida State University
Registered: Jul 2003


 - posted 09-21-2004 01:09 AM      Profile for Dean Kollet   Email Dean Kollet   Send New Private Message       Edit/Delete Post 
use Mozilla Firefox
don't share music with PTP software
sign up for a junk mail e-mail (to use when filling out stuff)
and there is plenty of ad-free porn all over the web... [beer]

 |  IP: Logged

Paul Konen
Jedi Master Film Handler

Posts: 981
From: Frisco, TX. (North of Dallas)
Registered: Jun 99


 - posted 09-21-2004 09:09 AM      Profile for Paul Konen   Email Paul Konen   Send New Private Message       Edit/Delete Post 
Cleaning it will only solve it until you reboot. You have to find the source that is doing the Hijack.

Try a search for HIJACKTHIS and run it. There are different discussion boards that will offer to analyse it.

If the mods don't mind, post your log here and I can offer suggestions. I've had to do it a couple of times myself to help others.

Look in your \windows or \winnt directory for files that have a time/date stamp that is close to the day that you started having problems.

 |  IP: Logged

Rich Granata
Film Handler

Posts: 61
From: Bethlehem PA USA
Registered: Mar 2004


 - posted 09-21-2004 10:33 AM      Profile for Rich Granata   Email Rich Granata   Send New Private Message       Edit/Delete Post 
Thanks for the tips

I tried Hijack this. I found a long list of ?questionable stuff. I knew it was risky, but I just cleaned (removed) every thing on the list... the only side affect was no p2p...no biggie

I've still got some issues. Hijack this was a really good program to me. It didn't ask me for money. I was getting so ticked yesterday because...I would download a program....I would do a scan.....It would find all this crap....I would click clean/remove....and it would say...you can purchase the pro version for just $49.99 etc.... [Eek!]

I was [Mad] that people are so obsessed with making money on the internet. I guess since everyone and their grandmother is a computer programer now, they feel that people should get paid to make shoddy software. I am the kind of guy that would use a free program only....and if it was done well, I would donate something. The only program I've ever paid for was MusicMatch Jukebox and that is because the security was too tight to crack and it has some amazing features.

My other question...is adware legal? Anything that replicates itself is a downright virus. Can't the feds go after these companies that use adware. It would be so easy.

:::On a side not...I would like to thank F-T for a completely ad-free website. [thumbsup] :::

 |  IP: Logged

Dave Macaulay
Film God

Posts: 2321
From: Toronto, Canada
Registered: Apr 2001


 - posted 09-21-2004 10:54 AM      Profile for Dave Macaulay   Email Dave Macaulay   Send New Private Message       Edit/Delete Post 
What's legal and illegal really makes no difference - it's infecting us anyway and there's no way to prosecute someone in Serbia for infecting your computer here...
The hijacker programs are very tricky and get updated to bypass removal software almost daily. The guy writing the best "coolwebsearch" hijacker removal program recently gave up - the malware writers were too good at keeping ahead of him.
Use a non-Microsoft browser - Opera or Firefox are great, Netscape is rather bloated and slow, and Mozilla takes a lot of plugin downloading to work well. If you have to use Outlook or Outlook Express do as suggested. The preview pane is the killer, it must be disabled or you can't delete suspicious emails without opening them. You're better off using another email client - Opera has one and Netscape does too I think plus there are many others.
If the family uses the computer you're basically screwed. SItes associated with games, music downloads, "warez", porn - they are all infamous for trying to send you nasty stuff. You can try to educate the users to NEVER click "OK" on any installation popup for anything - but will they listen?
I've had no virus protection or anything and I've only had one problem in 10 years or more when coolwebsearch got in somehow. I keep the OS updated, check about monthly for updates to Outlook, and use Opera for everything except MS updates.

 |  IP: Logged

Brandon Willis
Expert Film Handler

Posts: 216
From: Richmond, VA, USA
Registered: Apr 2004


 - posted 09-23-2004 12:17 PM      Profile for Brandon Willis   Email Brandon Willis   Send New Private Message       Edit/Delete Post 
I tried AdAware, Spybot, and HijackThis on my comp and still couldn't get rid of it all. I finally had to reformat the drive as a last resort.

 |  IP: Logged

Thomas Procyk
Phenomenal Film Handler

Posts: 1842
From: Royal Palm Beach, FL, USA
Registered: Feb 2002


 - posted 09-23-2004 02:13 PM      Profile for Thomas Procyk   Email Thomas Procyk   Send New Private Message       Edit/Delete Post 
Some of this Adware/Spyware embeds itself in your registry and runs as a process whenever you start your computer. Looking at the running processes, these illegal applications are usually taking up 99% of the CPU!!

That explains why people's systems run slow, or crash often. The Processors are overheating having to constantly run all this spyware shit!! I've been into computers for over 10 years and you never heard about people's motherboards burning out as often as you do now.

Where is the accountability in this shit? If these programs which install themselves on your computer (because you gave them "permission" in some ambiguous websites "terms and conditions" which you agreed to by simply entering the site) and then run it into the ground. Gator.Com owes me thousands of dollars.

I thought Generalisimo ElBusho signed some sort of legislation to ban this stuff? Or was that just a ban on Spam e-mail? (either case, it's not working)

=TMP=

 |  IP: Logged

Scott Norwood
Film God

Posts: 8146
From: Boston, MA. USA (1774.21 miles northeast of Dallas)
Registered: Jun 99


 - posted 09-23-2004 02:33 PM      Profile for Scott Norwood   Author's Homepage   Email Scott Norwood   Send New Private Message       Edit/Delete Post 
You're thinking of the so-called "CAN SPAM" law, which does exactly that: it tells spammers that they "can spam" whomever they want within a set of not-very-restrictive restrictions. In other words, it's an entirely counterproductive piece of legislation, as it essentially legitimizes spam.

This has nothing to do with spyware/adware/etc., the solutions to which are pretty much what others have mentioned: run Spybot/Ad-Aware/etc., don't run Internet Explorer, don't run MS Outlook, keep Windows patched, and don't download and run executables from untrusted sites. Or just don't run Windows.

 |  IP: Logged

Bobby Henderson
"Ask me about Trajan."

Posts: 10973
From: Lawton, OK, USA
Registered: Apr 2001


 - posted 09-23-2004 02:53 PM      Profile for Bobby Henderson   Email Bobby Henderson   Send New Private Message       Edit/Delete Post 
Many computer industry experts called the "Can Spam Act" law the "You Can Spam" law. As Scott said, the so-called "law" effectively legalizes a lot of spam and even some of the PC hijackings. You can thank the elements of the advertising industry, mainly the direct marketing industry, for bribing enough members of our government to put that fake law into effect.

What's even more infuriating is how the Can Spam bill outlawed efforts private companies in the computer industry were making to defeat a lot of spam and malware. Yahoo was one of a number of companies looking at giving the entire e-mail system across the globe a technological facelift. In short, they wanted a kind of absolute "caller ID" attached to any e-mail note. The note would be automatically deleted from any server if a response could not be sent to the actual author of the note. Don't ask exactly how they planned on doing this, but they had a lot of stuff showing a great deal of progess. You can thank the assholes in the direct marketing industry and the whores on capitol hill for killing it. They only care about the interests of big business. They could not give a shit if some home user or small business user gets their PC fried by the Cool Web Search hack or any other malware.

 |  IP: Logged

David Buckley
Jedi Master Film Handler

Posts: 525
From: Oxford, N. Canterbury, New Zealand
Registered: Aug 2004


 - posted 09-23-2004 05:07 PM      Profile for David Buckley   Author's Homepage   Email David Buckley   Send New Private Message       Edit/Delete Post 
Oh and it just gets better.

From just a couple of days ago on thereg:
http://www.theregister.co.uk/2004/09/22/opt-out_exploit

Click here to become infected
By John Leyden
Published Wednesday 22nd September 2004 09:15 GMT

Users should be wary of pressing the 'click here to remove' link on spam messages because it serves to confirm to spammers that junk mail messages are being read. Such email addresses can be sold at a premium to other spammers.

That's reason enough to simply delete spam messages, but a junk mail message doing the rounds today provides an even more compelling reason. Selecting the 'click here to remove' link on messages blocked by MessageLabs today triggers an attempt to load malicious code onto potentially vulnerable Windows PC.

MessageLabs is blocking spam linking to the domains www. xcelent.biz (space deliberately inserted) which, if users click on the remove link and scroll down the page triggers a DragDrop JavaScript exploit. This uses an IE bug to download and run an EXE file, currently been analysed by MessageLabs.

Alex Shipp of MessageLabs writes: "I have not finished analysing the EXE currently hosted (currently called windows-update.exe), but the spammers can change this at any time by uploading a new Trojan. Typically, your machine may be turned into an open proxy, have passwords extracted, and keyloggers installed.

"So not only do you confirm your email address to the spammers, you also get to host their next spam run, and get your bank account cleaned out," he adds.

The US's CAN-SPAM Act requires junk mailers to put an opt-out link on their wares. It comes as little surprise that this feature is been taken advantage of in a social engineering exploit; but it does illustrate the security problems of the opt-out approach that were always apparent to security experts - and ignored by legislators.

 |  IP: Logged

Daryl C. W. O'Shea
Film God

Posts: 3977
From: Midland Ontario Canada (where Panavision & IMAX lenses come from)
Registered: Jun 2002


 - posted 09-23-2004 05:20 PM      Profile for Daryl C. W. O'Shea   Author's Homepage   Email Daryl C. W. O'Shea   Send New Private Message       Edit/Delete Post 
Holy [bs] Batman, I think that's the 19th time I've seen that toady! Please, please, make it stop. [Smile]

 |  IP: Logged



All times are Central (GMT -6:00)
This topic comprises 2 pages: 1  2 
 
   Close Topic    Move Topic    Delete Topic    next oldest topic   next newest topic
 - Printer-friendly view of this topic
Hop To:



Powered by Infopop Corporation
UBB.classicTM 6.3.1.2

The Film-Tech Forums are designed for various members related to the cinema industry to express their opinions, viewpoints and testimonials on various products, services and events based upon speculation, personal knowledge and factual information through use, therefore all views represented here allow no liability upon the publishers of this web site and the owners of said views assume no liability for any ill will resulting from these postings. The posts made here are for educational as well as entertainment purposes and as such anyone viewing this portion of the website must accept these views as statements of the author of that opinion and agrees to release the authors from any and all liability.

© 1999-2020 Film-Tech Cinema Systems, LLC. All rights reserved.