View Full Version : Spyware/adware Re-installing itself?
tomteeth
October 17th, 2004, 02:29 PM
Hello Everyone, I am using xp home (oem) I cannot seem to find an answer to this, here it is>> I have these reinstalling on my pc register, they are "cometcursor, Cometcursor.com,cometcursor.net, aureate, lop.com, gator, flyswat, radiate, NetPal. I delete them manually but they keep coming back. All spyware scans that I use (spybot, adaware, spysweeper and others) dont even detect them. Also I get NetSlayer(Rat) and only yahoo antispy toolbar detects that and even after it is removed, that comes back in a day or so! I even removed NetSlayer Manually (with instructions from Pest Patrol) still returns. Anyone know why they are not being detected and why they will not stay removed. Also, I tried removing all of them and turned off system restore. Any idea's would be appreciated, Thanks, Tom
Peaches4U
October 17th, 2004, 02:57 PM
Hi Tom - well for one I suspect u are not getting component updates as SpyBot does detect as does Ad-Aware SE the malware u mention. Next, I would recommend u install Spywareblaster which prevents this stuff from entering ur computer. Like with all software, it is necessary to maintain regular updating. If u check Update Alerts at Wilders here, our gurus post reminders when updates are available. I check that thread daily and find it a blessing.
Here is the download site for Spywareblaster.
http://www.javacoolsoftware.com/sbdownload.html
After downloading [if u choose to do so] be sure to clicl on "enable all protection" or words to that effect. If u fail to do so, then this software will not protect u.
dvk01
October 17th, 2004, 03:17 PM
where are they being found and what is finding them
also list what antispyware programs you are using
I strongly suspect that they are the entries in the registry that are put there by spybot to PREVENT them being installed on your computer
tomteeth
October 17th, 2004, 03:35 PM
Ok, Well, I was using the latest update of spybot/adaware at the time. Also I have had SpyWareBlaster on this pc for over a year. I also have Process Guard, Ewido, Spyware Guard, SpySweeper, HiJack this, Yahoo Antispy toolbar, Startup Monitor, Script Sentry, and a Note from my Mother telling everyone to stay away from her sons pc. Now NetSlayer is detected by my Yahoo AntiSpy Toolbar and it removes it, but its back in a day or so. The others, I find myself via registry! DVK01 maybe right, When I first ran Spybot it may have put them in the registry on the first search and I forgot about it. I did not know Spybot does that? But the NetSlayer was and never is detected by anything but yahoo antispy toolbar!
Bubba
October 17th, 2004, 03:52 PM
Hey tom,
Does yahoo antispy toolbar create somekind of log or can you somehow show what locations it's finding NetSlayer....and any others you may be concerned with.
tomteeth
October 17th, 2004, 04:03 PM
Yes, I believe it does have a log where you can restore what you removed. Want me to check it out?
tomteeth
October 17th, 2004, 04:11 PM
Here is an attachment showing what Yahoo found and removed!
Chopsaw
October 20th, 2004, 03:33 AM
if we're wondering how this stuff gets started and you're comfortable with the registry you could try these locations:
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunServices]
HKEY_CLASSES_ROOT\exefile\shell\open\command] ="\"%1\" %*"
[HKEY_CLASSES_ROOT\comfile\shell\open\command] ="\"%1\" %*"
[HKEY_CLASSES_ROOT\batfile\shell\open\command] ="\"%1\" %*"
[HKEY_CLASSES_ROOT\htafile\Shell\Open\Command] ="\"%1\" %*"
[HKEY_CLASSES_ROOT\piffile\shell\open\command] ="\"%1\" %*"
[HKEY_LOCAL_MACHINE\Software\CLASSES\batfile\shell\open\command] ="\"%1\" %*"
[HKEY_LOCAL_MACHINE\Software\CLASSES\comfile\shell\open\command] ="\"%1\" %*"
[HKEY_LOCAL_MACHINE\Software\CLASSES\exefile\shell\open\command] ="\"%1\" %*"
[HKEY_LOCAL_MACHINE\Software\CLASSES\htafile\Shell\Open\Command] ="\"%1\" %*"
[HKEY_LOCAL_MACHINE\Software\CLASSES\piffile\shell\open\command] ="\"%1\" %*"
HKEY_LOCAL_MACHINE\Software\Microsoft\Active Setup\Installed Components
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Currentversion\explorer\User shell folders
the win.ini and system.ini files are a place too look too.... if you make any changes make sure you back up the entry first so you have a way back if you need it.
tomteeth
October 20th, 2004, 07:49 AM
Chopsaw, Thank You for the info. I seen some of these registry entries before, but my pc doesn't have some of them at all, like the "Open" after "Shell" etc. I guess it has something to do with being a OEM from HP Preinstallation.
Chopsaw
October 20th, 2004, 01:37 PM
not really .... the items are only added if needed ... the list is not written in stone ... but these locations are a place to look if you have the re-install problem.
You don't always find the item in these locations of course ... a dll or "dynamic link lybrary" file on the system can also be the problem ... those are much harder to find ... usually what i would do is run a program like regmon.exe on start up and watch for the activity.
tomteeth
October 20th, 2004, 02:51 PM
I will check it out, Thanks
dvk01
October 20th, 2004, 03:10 PM
As I said above if you use spubot & spyware blaster, both applications put entries in certain registry locations to STOP all downloads of the spywares
DO NOT keep looking in registry for them they are su[pposed to be there and stick to proper well known anti spyware applications like adaware or spybot
with common problems like cometcursor, Cometcursor.com,cometcursor.net, aureate, lop.com, gator, flyswat, radiate, NetPal
if they don't find them then they don't exist
dvk01
October 20th, 2004, 03:15 PM
From what I've seen the Yahoo toolbar is aabout as much use in preventing spyware as a chocolate fireguard :D
tomteeth
October 20th, 2004, 04:48 PM
Well, thats your opinon. But as I said above Spybot or adaware are not even picking up this NetSlayer and Yahoo AntiSpy Toolbar just picked it up again. Something is setting this back on my pc. and I will fined out what soon or later. Thanks Guys for your replies. Later
vBulletin® Copyright ©2000-2012, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2012, Wilders Security Forums