The Daily Static
  The Daily Static
UF Archives
Register
UF Membership
Ad Free Site
Postcards
Community

Geekfinder
UFie Gear
Advertise on UF

Forum Rules
& FAQ


Username

Password


Create a New Account

 
 

Back to UserFriendly Strip Comments Index

I have SEEN that walking talking hairy eyeball. by ArcCoyote 2004-02-10 11:29:59
It's real, and it has popped out of a couple of machines I cleaned of spyware.

You'll know you have it when the computer does things like upchuck tons of popups every time you turn your back. Someone is making a LOT of commi$$ion on these ads.

There will be half a dozen randomly named processes running. The actual .exe files are created as hidden, system, protected, read-only, the whole bunch. You have to turn off ALL the idiot-proofing in Windows to delete them. Of course, you can't delete them while they are running, and the instant you kill one, two more are spawned by the other five you didn't kill. If you take them out of startup in the registry, they put themselves right back.

There's also a browser plugin. That's what was initially downloaded, and it will reinstall the .exe files upon opening any Internet or Windows Explorer window, even in safe mode. The plugin also turns off the security warning when installing plugins, hijacks the homepage, adds links to favorites, and hijacks Google (it actually replaces search results with ads!)

Oh yeah, and the ad pop-ups constantly try to reinstall the plugin. Can you say infinite loop?

Spybot and Ad-aware can't completely remove it, as it mutates so rapidly. Some new variants will actually kill Spybot or Ad-aware, or close the browser window when you visit anti-spyware websites.

To remove it you have to disable 3rd party extensions in IE, reboot in safe mode, reveal protected system files, delete the random .exe files, clean the startups in the registry, run a scan in spybot, and manually reset the browser pages and plugins in spybot's tools. Only then can you turn browser plugins back on and boot normally (if you dare!)

And guess what? No Antivirus I know of recognizes this thing. I guess it's not considered malicious enough.
[ Reply ]
  Different issue, I think. by LionsPhil2004-02-10 11:35:00
    Not this one. It's definately crooked. by ArcCoyote2004-02-10 11:43:11
      Not impossible to trace. by LionsPhil2004-02-10 11:44:47
        Throw in a bunch of other referrers as well by Spiff2004-02-10 14:22:50
  fdisk. The rest of the comp's "f"ed, anyway. ;) (n (n/t) by Irrelevant2004-02-10 11:36:04
  Encountered it on my brother's computer by IByte2004-02-10 12:09:58
  It's the eyestem of a Dionoga (n/t) by subbywan2004-02-10 12:30:35
  Would installing BHO Cop type program help? by swisscheese2006-11-19 12:55:59
  I like the one that puts itself in the Fonts fldr. by YakkoWarner2004-02-10 14:43:35
    Yup, ol' CONTENT.IE5. by LionsPhil2004-02-10 16:07:52
    How about the "System Volume Information" folder.. by ironblood2004-02-10 16:19:46

 

[Todays Cartoon Discussion] [News Index]

Come get yer ARS (Account Registration System) Source Code here!
All images, characters, content and text are copyrighted and trademarks of J.D. Frazer except where other ownership applies. Don't do bad things, we have lawyers.
UserFriendly.Org and its operators are not liable for comments or content posted by its visitors, and will cheerfully assist the lawful authorities in hunting down script-kiddies, spammers and other net scum. And if you're really bad, we'll call your mom. (We're not kidding, we've done it before.)