InvestorsHub Logo
Followers 4
Posts 4127
Boards Moderated 0
Alias Born 03/06/2003

Re: None

Wednesday, 06/30/2004 7:20:06 PM

Wednesday, June 30, 2004 7:20:06 PM

Post# of 97749
Windows problem. Help? -

OK, I had the misfortune of mispelling a web site URL yesterday, and the bogus site installed some adware without any prompting. When I bring up my browser, normally set to start with a blank page, instead I get a screen full of URLs to products (they all go to the same .tv domain site) and a popup that says spyware is detected (no sh--, Sherlock!). Of course, it offers to scan my system, and I am not that big a fool!

I have tried the following unsuccessfully to get rid of this:

1. Several anti-spyware programs including the installed Spybot 1.3 and several trial versions of other products. They all report a clean system.

2. Anti-virus scans from the McAfee and Norton web sites.

3. The screen appears even when I unplug the network and delete offline content, so it is somewhere in the system.

4. I did string searches in all the files on the computer for the URL behind the ad strings, and more string searches for some of the strings printed on the screen. No luck. Seems to be scrambled or encrypted or programatically generated.

5. I removed Internet Explorer - uninstalled, removed the files from Program Files and in the various places Windows keeps backups, and removed all references for "IE6", "Internet Explorer" and "iexplore" from the registry. Then I reinstalled Explorer from the DVD installation. Problem is still there.

6. I deleted the user template, copied a fresh user template from a clean machine, and created a new user. Doesn't help.

Does anyone know the sequence of files that is executed when iexplore.exe is started, and where it gets the blank screen? I'm thinking that the screen is built programatically (rather than a blank screen HTTP file), and the spyware may be in the form of a shim program that hijacks this process.

Any help is appreciated! If I don't have the resolved soon then I'll have to reformat and reinstall everything from scratch.

Also: Is there a setting which will prevent silent installations like this? I thought I had everything set to block or prompt, but this nasty program found a way around it.
Volume:
Day Range:
Bid:
Ask:
Last Trade Time:
Total Trades:
  • 1D
  • 1M
  • 3M
  • 6M
  • 1Y
  • 5Y
Recent AMD News