Date: 30/07/25 - 16:15 PM   48060 Topics and 694399 Posts

Author Topic: Horrible spyware.  (Read 2204 times)

July 30, 2006, 07:01:07 PM
Read 2204 times

michigancat

  • All American

  • Offline
  • ******

  • 23713
  • Personal Text
    You can't be racist and like basketball.
I need help from someone smarter than me when it comes to computers.

Adware and Spybot both detect it, but neither can remove it because it automatically in use when Windows loads.

It also added a warning in my notification warning me about spyware infecting my computer.  I can't find any wierd programs in my Add/Remove list.

Help, please.

TIA

July 30, 2006, 07:25:30 PM
Reply #1

Saulbadguy

  • Guest
What is the name of the process?

July 30, 2006, 08:22:15 PM
Reply #2

jeffy

  • Scout Team Wildcat

  • Offline
  • **

  • 7000
  • Personal Text
    ku Swallows
Just do a search for Explorer.exe.  Delete that.  Things should return to normal after that.

July 30, 2006, 08:48:41 PM
Reply #3

AzCat

  • Classless Cat
  • Scout Team Wildcat

  • Offline
  • ***

  • 7320
Google whatever name your spyware checkers spit out and you'll quickly find step-by-step removal instructions.
Ladies & gentlemen, I present: The Problem

July 30, 2006, 10:52:10 PM
Reply #4

michigancat

  • All American

  • Offline
  • ******

  • 23713
  • Personal Text
    You can't be racist and like basketball.
n?tdde.exe

I'm working google, but I'm not quite there yet.

July 31, 2006, 08:59:53 AM
Reply #5

fatty fat fat

  • Premium Member
  • Hall of Fame

  • Offline
  • *******

  • 29013
  • Personal Text
    The very best.
1) Format. Seriously. If you can, and have the backup software.


2)Run Windows in safe mode, disconnect internet, run EVERY spyware program

3)Go to a message board where others will help you.
It is a tragedy because now, we have at least an extra month without Cat football until next year. I hate wasting my life away but I can hardly wait until next year.

July 31, 2006, 11:19:04 AM
Reply #6

JavaCat

  • Classless Cat
  • Cub

  • Offline
  • ***

  • 1511
Do the second thing Fatty said and get into safe mode. You should be able to delete the file when in safe mode, but you'll want to run everything in safe mode. Download and install Ewido before you do that. I've found that to be better than Spybot or Ad-Aware, but use them all.

May 07, 2008, 07:18:36 AM
Reply #7

cireksu

  • Guest
rusty what came of this, I think I have something similar now.

I don't understand what fatty wrote bc I'm computer retarded.

May 07, 2008, 07:27:20 AM
Reply #8

jeffy

  • Scout Team Wildcat

  • Offline
  • **

  • 7000
  • Personal Text
    ku Swallows
rusty what came of this, I think I have something similar now.

I don't understand what fatty wrote bc I'm computer retarded.

Run Spybot S&D.  Run Ad-aware.
Others you can try: AVG anti-spyware, Superantispyware.
Run them from safe mode.
Make sure they are updated before you run them.

Run HijackThis. http://www.majorgeeks.com/Trend_Micro_HijackThis_d5554.html

Post the log that it creates on this message board: http://www.d-a-l.com/help/forumdisplay.php?f=8

Do what they say.  They are very good with these things.  You'll have to be persistent tho.  It'll probably take a couple of days to get things cleared up.

May 07, 2008, 07:35:15 AM
Reply #9

steve dave

  • Administrator
  • All American

  • Offline
  • ********

  • 23600
  • Personal Text
    Romantic Fist Attachment
rusty what came of this, I think I have something similar now.

I don't understand what fatty wrote bc I'm computer retarded.

Run Spybot S&D.  Run Ad-aware.
Others you can try: AVG anti-spyware, Superantispyware.
Run them from safe mode.
Make sure they are updated before you run them.

Run HijackThis. http://www.majorgeeks.com/Trend_Micro_HijackThis_d5554.html

Post the log that it creates on this message board: http://www.d-a-l.com/help/forumdisplay.php?f=8

Do what they say.  They are very good with these things.  You'll have to be persistent tho.  It'll probably take a couple of days to get things cleared up.

I like the AVG suite of anti-spyware/anti-virus/other stuff because it seems to do a good job and is free.  Stopping my McAfee sub. in June because it doesn't seem to have any benefit over the free AVG program.
<---------Click the ball

May 07, 2008, 07:44:28 AM
Reply #10

jeffy

  • Scout Team Wildcat

  • Offline
  • **

  • 7000
  • Personal Text
    ku Swallows
rusty what came of this, I think I have something similar now.

I don't understand what fatty wrote bc I'm computer retarded.

Run Spybot S&D.  Run Ad-aware.
Others you can try: AVG anti-spyware, Superantispyware.
Run them from safe mode.
Make sure they are updated before you run them.

Run HijackThis. http://www.majorgeeks.com/Trend_Micro_HijackThis_d5554.html

Post the log that it creates on this message board: http://www.d-a-l.com/help/forumdisplay.php?f=8

Do what they say.  They are very good with these things.  You'll have to be persistent tho.  It'll probably take a couple of days to get things cleared up.

I like the AVG suite of anti-spyware/anti-virus/other stuff because it seems to do a good job and is free.  Stopping my McAfee sub. in June because it doesn't seem to have any benefit over the free AVG program.

I use AVG anti-virus at home.  Works well for me.  McAfee/Norton/Symantec =crap/resource hogs with lots of worthless add-ons.

May 07, 2008, 08:05:27 AM
Reply #11

steve dave

  • Administrator
  • All American

  • Offline
  • ********

  • 23600
  • Personal Text
    Romantic Fist Attachment
resource hogs

This was the big one for me. 
<---------Click the ball

May 07, 2008, 08:10:53 AM
Reply #12

cireksu

  • Guest
rusty what came of this, I think I have something similar now.

I don't understand what fatty wrote bc I'm computer retarded.

Run Spybot S&D.  Run Ad-aware.
Others you can try: AVG anti-spyware, Superantispyware.
Run them from safe mode.
Make sure they are updated before you run them.

Run HijackThis. http://www.majorgeeks.com/Trend_Micro_HijackThis_d5554.html

Post the log that it creates on this message board: http://www.d-a-l.com/help/forumdisplay.php?f=8

Do what they say.  They are very good with these things.  You'll have to be persistent tho.  It'll probably take a couple of days to get things cleared up.

I have spybot and ad aware, they both found stuff but couldn't fix all of it.  Thanks for the info, this pisses me off so much.

May 07, 2008, 08:28:36 AM
Reply #13

cireksu

  • Guest
also jeffy, are there places that you can take a computer to have someone do this for you?


I'm afraid of screwing it up.  I don't think my problems are as bad as some of the ones I read about in that forum but don't want to let them get worse.

I really am horrible with any kind of software.

May 07, 2008, 08:35:57 AM
Reply #14

jeffy

  • Scout Team Wildcat

  • Offline
  • **

  • 7000
  • Personal Text
    ku Swallows
also jeffy, are there places that you can take a computer to have someone do this for you?


I'm afraid of screwing it up.  I don't think my problems are as bad as some of the ones I read about in that forum but don't want to let them get worse.

I really am horrible with any kind of software.

You can take it just about anywhere that does computers, tho I'm not sure you'll get as thorough a job as you can do yourself with the help of the techs at DAL.  It really isn't that hard to do.  They give you very good directions on how to do things.  It's pretty much just downloading a few small scanners - depending on what they find, and reposting new logs.  Really... it is easy.  Probably the hardest thing is getting your computer to boot in safe mode.

The only other sure fire way of fixing things is just to reformat your whole computer and start over.  If you don't have good backups, this is really not a good option.

« Last Edit: May 07, 2008, 08:37:40 AM by jeffy »

May 07, 2008, 08:47:31 AM
Reply #15

cireksu

  • Guest
also jeffy, are there places that you can take a computer to have someone do this for you?


I'm afraid of screwing it up.  I don't think my problems are as bad as some of the ones I read about in that forum but don't want to let them get worse.

I really am horrible with any kind of software.

You can take it just about anywhere that does computers, tho I'm not sure you'll get as thorough a job as you can do yourself with the help of the techs at DAL.  It really isn't that hard to do.  They give you very good directions on how to do things.  It's pretty much just downloading a few small scanners - depending on what they find, and reposting new logs.  Really... it is easy.  Probably the hardest thing is getting your computer to boot in safe mode.

The only other sure fire way of fixing things is just to reformat your whole computer and start over.  If you don't have good backups, this is really not a good option.



I'll give it a whirl, our computer really isn't used for much other than me message boarding and playing fantasy sports so if I would screw up and have to start over it wouldn't be horrible.  the most important thing we'd lose is pictures we've stored.  And our address list of friends/family.

May 07, 2008, 09:02:10 AM
Reply #16

jeffy

  • Scout Team Wildcat

  • Offline
  • **

  • 7000
  • Personal Text
    ku Swallows
also jeffy, are there places that you can take a computer to have someone do this for you?


I'm afraid of screwing it up.  I don't think my problems are as bad as some of the ones I read about in that forum but don't want to let them get worse.

I really am horrible with any kind of software.

You can take it just about anywhere that does computers, tho I'm not sure you'll get as thorough a job as you can do yourself with the help of the techs at DAL.  It really isn't that hard to do.  They give you very good directions on how to do things.  It's pretty much just downloading a few small scanners - depending on what they find, and reposting new logs.  Really... it is easy.  Probably the hardest thing is getting your computer to boot in safe mode.

The only other sure fire way of fixing things is just to reformat your whole computer and start over.  If you don't have good backups, this is really not a good option.



I'll give it a whirl, our computer really isn't used for much other than me message boarding and playing fantasy sports so if I would screw up and have to start over it wouldn't be horrible.  the most important thing we'd lose is pictures we've stored.  And our address list of friends/family.

Reformatting and reinstalling everything can end up taking just as long as trying to clean up the spyware.  The address list could be saved to a jumpdrive/disk/cd/internet webspace.  If the pics aren't some of the massive pics from an SLR camera, they could easily be saved to a snapfish/photobucket site.

Just don't sell yourself short.  The guys at DAL do give solid and easy to follow info.  The instructions for everything are there word for word when they want you to do something.  If you try that and the whole process doesn't appeal to you, then you can still reformat.

May 07, 2008, 10:29:38 AM
Reply #17

KSt8er

  • Cub

  • Offline

  • 1550
  • Personal Text
    AAAAAHHHHH AAAAHHH
Jeffy - Can one still get into DOS using F8 (I think F8, it's been a long time since I've needed to try) on boot up?  If so, you can easily get to the problem file(s) and delete them before windows loads. 
"He has all the virtues I dislike and none of the vices I admire." -- Sir Winston Churchill

May 07, 2008, 12:44:42 PM
Reply #18

mjrod

  • Second String Wildcat

  • Offline
  • ****

  • 11246
    • MJROD Consulting Services, Inc
n?tdde.exe

I'm working google, but I'm not quite there yet.

Good luck with that one.

Here's what you do.

Boot into safe mode. 
Go to  C:\WINDOWS\SYSTEM32 folder.
On the menu, click Tools -> Folder Options, then click the View Tab.
Locate the settings in the inner window and click Show Hidden Files, and then uncheck Hide protected operating system files and uncheck Hide extensions for known file types.
Click OK.
Change the views to DETAIL mode and then sort by Date (making sure the files sort by oldest ones first.)
Scroll to the end of the list.
Look for any files that end in DLL or EXE that have a date that is within the last couple of days.  Most spyware files continually update themselves daily.  You could end up with more than one (or many more.)
If you see any files with weird file names and if you move the mouse over them, there is no company or version info, then delete them. 
If they delete, then you should be good.

If they don't delete or are unable to, write the names of the files down.
This step is important.
Turn off your computer by unplugging it (don't use the power switch)
Find your Windows XP installation disk, or any Windows XP installation disk.
Boot from that disk.   When it comes up, press R to go into the recover console.
Select Recovery Console.
When the screen comes up, it will ask what folder (generally C:\WINDOWS as option 1)
Press 1
If it asks for an admin password, if you set it when you got the computer, enter that.  If not, it will go directly to the C:\windows prompt.
Type in CD SYSTEM32 and press enter.
For each file you wrote down, type in DEL filename.ext and press enter.
Once you have completed, type Exit and the computer should begin to reboot.
REBOOT IN SAFE MODE.
Once you're back in safe mode, open My Computer -> Documents and Settings.
There are several folders, but you can ignore All Users, Default Folders, Adminstrator.
For all the remaining ones, you will need to go into each folder's Local Settings\Temp and Local Settings\Temporary Internet Files and delete EVERYTHING in them.  Some people actually delete those entire folders and Windows will restore them, but you may want to peruse them first before deleting everything.
Once you're done with that, click Start -> Run and enter REGEDIT.EXE and click OK.
When the registry editor comes up navigate to:
HKEY_LOCALMACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\BrowserHelperObjects
Delete ALL KEYS under there.
Navigate to HKEY_LOCALMACHINE\Software\Microsoft\Windows\CurrentVersion\Run
Delete any key that doesn't look valid (ie, it's not obvious where or what it does.)  If you aren't sure, then do a search for the file it's trying to load and see where it's located.   Just because it's in the System32 folder doesn't mean it's valid.
Restart your computer.
Run the your anti-virus and spyware software again.


May 07, 2008, 12:49:44 PM
Reply #19

michigancat

  • All American

  • Offline
  • ******

  • 23713
  • Personal Text
    You can't be racist and like basketball.
I fixed it like two years ago.

May 07, 2008, 12:54:59 PM
Reply #20

mjrod

  • Second String Wildcat

  • Offline
  • ****

  • 11246
    • MJROD Consulting Services, Inc
I fixed it like two years ago.

PEOPLE BETTER STOP BUMPING THREADS!!!

May 07, 2008, 01:15:33 PM
Reply #21

cireksu

  • Guest
I fixed it like two years ago.

PEOPLE BETTER STOP BUMPING THREADS!!!


sorry, I didn't even realize it was that long ago, I just searched spyware figuring that the topic had been discussed here before.


Rusty was it an easy fix or did you have to do everything MJ put, cause if it's what MJ put I'm fracked.

May 07, 2008, 01:21:53 PM
Reply #22

michigancat

  • All American

  • Offline
  • ******

  • 23713
  • Personal Text
    You can't be racist and like basketball.
I fixed it like two years ago.

PEOPLE BETTER STOP BUMPING THREADS!!!


sorry, I didn't even realize it was that long ago, I just searched spyware figuring that the topic had been discussed here before.


Rusty was it an easy fix or did you have to do everything MJ put, cause if it's what MJ put I'm fracked.

I didn't use the same fix MJ did (mine didn't need a reboot from disk), but it was just as difficult.  Which really isn't all that difficult if you just follow the instructions step-by-step.

May 07, 2008, 01:24:26 PM
Reply #23

cireksu

  • Guest
I fixed it like two years ago.

PEOPLE BETTER STOP BUMPING THREADS!!!


sorry, I didn't even realize it was that long ago, I just searched spyware figuring that the topic had been discussed here before.


Rusty was it an easy fix or did you have to do everything MJ put, cause if it's what MJ put I'm fracked.

I didn't use the same fix MJ did (mine didn't need a reboot from disk), but it was just as difficult.  Which really isn't all that difficult if you just follow the instructions step-by-step.


what's your softwaring iq like?  Mine is way<<<<<<<<<<<<<<Forest Gump's.

May 07, 2008, 01:25:32 PM
Reply #24

mjrod

  • Second String Wildcat

  • Offline
  • ****

  • 11246
    • MJROD Consulting Services, Inc
I use this fix because it's the best way to remove it and allow the anti-virus and spyware programs to clean up any residuals.

I've done it so much, I can do it in about 15 minutes.

May 07, 2008, 01:27:56 PM
Reply #25

cireksu

  • Guest
How do you get out of safe mode?  just reboot and you're in normal mode?

May 07, 2008, 01:29:09 PM
Reply #26

mjrod

  • Second String Wildcat

  • Offline
  • ****

  • 11246
    • MJROD Consulting Services, Inc
How do you get out of safe mode?  just reboot and you're in normal mode?

Yes.

May 07, 2008, 02:36:46 PM
Reply #27

cireksu

  • Guest
what if I don't have a system recovery disk?

May 07, 2008, 02:41:45 PM
Reply #28

mjrod

  • Second String Wildcat

  • Offline
  • ****

  • 11246
    • MJROD Consulting Services, Inc
what if I don't have a system recovery disk?

My instruction doesn't call for a system recovery disk.  It calls for a Windows XP installation disk.

May 07, 2008, 02:49:47 PM
Reply #29

cireksu

  • Guest
what if I don't have a system recovery disk?

My instruction doesn't call for a system recovery disk.  It calls for a Windows XP installation disk.


see what I mean about being retarded.

I found a place local that a friend with a personal business uses, America's computers.  I'll call them, bc I think I'll &@#% it up.