2000 AD Online Forum

General Chat => Help! => Topic started by: Noisybast on 06 February, 2005, 09:09:27 PM

Title: Totally off-topic: Bloody spyware!
Post by: Noisybast on 06 February, 2005, 09:09:27 PM
Anybody come across the Globosearch spyware?
I consider myself a bit of a PC pro, and can usually handle pretty much anything the internet can throw at me, but I'm having a spot of bother getting rid of this little digital arsegike.

Every 2 hours (on the dot), it redirects my browser to a page advertising a spyware removal utility!

I've removed the file popup_bl.dll
I've removed all the registry entries referring to popup_bl.dll
I've added the following lines to my Hosts file:
  127.0.0.1 new.globosearch.com
  127.0.0.1 best.globosearch.com

I can't remove C:[backslash]WINNT[backslash]System32[backslash]systr.dll, which is the file that's causing all the bother. Not even in Safe Mode.

Any ideas? Win2K Pro, IE6.
Title: Re: Totally off-topic: Bloody spyw...
Post by: Slippery PD on 06 February, 2005, 09:37:41 PM
Its because its associated with windows explorer......  Nasty!

Try the link below, seems to have a few ideas,
Mr Bast

Slips
Title: Re: Totally off-topic: Bloody spyw...
Post by: Banners on 06 February, 2005, 09:50:42 PM
Presuming you've already tried AdAware, Spybot and Spysweeper...

You might have to turn off Sytem Restore before going through the routine of deleting everything and rebooting. Sometimes System Restore can 'helpfully' put back stuff you have removed when Windows next boots up.

On WinXP Pro this is a simple check-box accessed through the System Restore tab of Properties, accessed by right-clicking on "My Computer". Of course, there is a danger that the fiddling does something you might otherwise have needed System Restore for - so tread carefully!

If that fails get a copy of "HijackThis!" which will give you more detailed info about where any malicious files are.

M@
Title: Re: Totally off-topic: Bloody spyw...
Post by: Noisybast on 06 February, 2005, 10:02:35 PM
Yeah, tried all the usual removal tools. Hijack This! and CWShredder aren't touching it either.
It's even managing to shanghai Mozilla!
Title: Re: Totally off-topic: Bloody spyw...
Post by: Noisybast on 06 February, 2005, 10:03:14 PM
Oh yeah, Slips - What link?
Title: Re: Totally off-topic: Bloody spyw...
Post by: Banners on 06 February, 2005, 10:04:20 PM
Seen this?

M@

Link: Seems to hint at a cure...

Title: Re: Totally off-topic: Bloody spyw...
Post by: Noisybast on 06 February, 2005, 10:16:06 PM
Groovy. I did trawl through a few threads on various forums (fora?) but I don't think I saw that one. I'll give it a go when I get home from work.

Cheers M@!
Title: Re: Totally off-topic: Bloody spyw...
Post by: Slippery PD on 06 February, 2005, 10:23:32 PM
oooops I hope this works

Slips

Link: http://forum.emsisoft.com/viewtopic.php?t=2190

Title: Re: Totally off-topic: Bloody spyw...
Post by: Noisybast on 06 February, 2005, 11:52:04 PM
Cheers lads - that seems to have done it.

The trick was to shut down Explorer.exe in order to allow me to delete systr.dll from a command prompt.

Now, about this reversed camera bug in Vice City...

;)
Title: Re: Totally off-topic: Bloody spyw...
Post by: House of Usher on 07 February, 2005, 02:32:37 AM
All our spyware pop up ads problems seemed to disappear when we finally got round to downloading a Microsoft security patch for Windows XP.
Title: Re: Totally off-topic: Bloody spyw...
Post by: Noisybast on 07 February, 2005, 04:02:23 AM
Dunno, I tend to let other people beta test Microsoft's crazy schemes before I let 'em loose on my own PC...
Title: Re: Totally off-topic: Bloody spyw...
Post by: Queen Firey-Bou on 09 February, 2005, 04:08:34 AM
aiee such techy techs scare me soooo.

i've nearly got one of my machines sorted. the win98 PC  is so glitch ridden its nearly unusable. manyana.

meanwhile, some bastard hacker hackd into my web server last night & trashed my site !! it turns out it wasnae personal there was another site on the server with a security gap & theyve upped the defenses etc, ive had to load up a slightly outdate version til i get time to update files . bah.  makes ye wonder tho !