Help with Spyware

Chat about anything and everything... (well almost anything) Whether it be the front porch or the pot belly stove or news of interest or a topic of your liking, this is the place to post it.

Moderator: S2k Moderators

Message
Author
chadtm80

#21 Postby chadtm80 » Wed Jun 16, 2004 1:30 pm

AsHtRaY wrote:Hello again everyone. First off SSI will not effect any spyware remover, we have tested it with 9 of the major removers and have seen no problems. We designed it to be compatible with just about any windows program.

Here is a breif description of SSI, spyware/adware, and it's related technologies. Hopefully this explains a lot.

We gather system information from your computer to help determine what operating systems or browsers spyware seems to attack more. We gather your memory and the amount your using to aid us in determining how much of an effect spyware is having on your computer resouces. We also gather your version of Internet Explorer and your Internet connection type to determine if spyware is prying on broadband users as much as dialup users and what versions of Internet Explorer are being affected.

Browser Helper Objects (BHO)

A Browser Helper Object is a small program that runs automatically every time you start your Internet browser. Usually, a BHO is installed on your system by another software program. BHOs are typically installed by toolbar accessories and can track your internet usage and collect other information that is used on the internet.

ActiveX Controls

ActiveX is Microsoft's technology for signing plug-ins that add additional software to your computer when a web page is accessed.

Programs that start when your computer starts...

Your computer has several programs that startup when your computer starts. Most of these programs serve a good purpose such as an Anti-Virus program or maybe your favorite music software. However, spyware also forces itself to start when your computer starts. Removing spyware from here will prevent it from reinfecting your machine. We use this data to educate you on what Spyware is starting up when your computer starts.

Homepage and Searchpage Hijacker information...

Hijackers are applications that attempt to take control of the user's home page and reset it with the site of the hijacker's choosing. This site is almost always loaded with ads, pop - ups, and/or other make-money-fast portals. They are a low security threat, however annoying they may be. Many hijackers use stealth techniques or misleading dialogue boxes to perform installation. Hijacker programs will put a reference to themselves in the StartUp or Registry, so that the hijacker reinstalls itself every time the computer is started. If the user tries to change any of these settings, the hijacker then changes them back upon reboot

Add / Remove Programs List

Your Add / Remove program lists contains a wealth of information on what programs are 'registered' as installed on your computer. Quite a few spyware applications will not 'register' themselves with your Operating System because they do not want to be installed. Spywaredata.com can tell you what spyware programs have 'Registered' on your computer and how to remove them.

Programs that are running right now

right now your computer is probably running several dozen programs that you can't see. You can view some of them using the built in task manager of windows; However, each program running uses 'Dependency' programs. Dependency programs are little helper applications that help. Spyware comes in this form quite often. It can hide here with the security of knowing it will be very hard to find. SSI and spywaredata.com can grab this information and immediately alert you to these hidden spyware programs.

Host file information

Your Hosts file is like an address book. When you type an address like http://www.google.com into your browser, the Hosts file is consulted to see if you have the IP address, or 'telephone numbe' for that site. If you do, then your computer will 'call it' and the site will open. If not, your computer will ask your ISP's (internet service provider) computer for the phone number before it can 'call' that site. Normally you would not have that address in your Hosts file. Spyware will change your Host file and put in a different 'Phone Number' then the one you need to contact. This prevents you from accessing the correct web page and also redirects you to another site.

Toolbar registry enteries

Toolbars are helper programs that attach themselves to your Internet Explorer or Windows Explorer programs. Most toolbars are innocent and are made for convience. other toolbars track everything you do on the Internet and even pop advertisements up based on your searches. In addition, they can also deliver to you the search results they want, which are generally paid results and not necessarily what you searched for.

Distribution registry keys

Distrubtion units are a method of installing software over the Internet. Generally website will prompt you to install a certain 'Control' which then loads software needed for proper viewing of that webpage. Spyware has the ability to install these 'Distribution Units' on your computer through various websites, pop-ups and pop-under webpages. They can generate pop up advertisement, hijack homepages and monitor your Internet Activity. Spyware is NOT required to view a webpage.

Shell Extension registry keys

Shell Extensions are an integral part of the operating system. And example of a shell extension is the menu you receive when you left click on a folder in Windows Explorer. Spyware will attach to the shell extensions of your computer to help hide itself. This type of spyware is hard to find and can generate pop-up advertising.

URLHook registry keys

Spyware that monitors what you type in the address bar of Internet Explorer and then hijacks that data is known as a 'URL Hook'. This type of spyware can take you to Portals which deliver paid ad's, pop-ups and even adult content.

Winsock enteries, also known as the LSP layer

LSP or Layered Service Providers play a very important part in your Internet connection. All Internet traffic flows through the LSP like a chain. Each file is a link in this chain. If a file is deleted the chain breaks and you have no more Internet connection. Spyware that resides on this layer of your computer can monitor all Internet surfing and activities.

Keep the questions coming:)

-AsHtRaY


Great Info Ashtray! Thanks!!

Hello everyone, I am friends with chadtm80 in FL. Chad and I were talking about spyware and he mentioned some of you from time to time run into some nasty ones. I help with a site called http://spywaredata.com we are devoted to killing spyware, or doing the best we can! The site is related to a product called SSI, or System Spyware Interrogator. It is free, and does not remove spyware it only detects it. You may ask yourself what good is that? Well most of you already have a spyware remover product, if you dont you should get one. Suppose you run your remover and after it detects and removes everything you still have spyware on your computer. How would you know. The answer is SSI, use it to make sure that your computer really is spyware free. We have the largest database of spyware, and if you have something on your computer we suspect might be spyware you can upload the files and we will look at them. The more people that send us files, the better our detection gets. We currently have one of the largest public lists. We also keep a list of good items, so if there is an application we dont know about, and you dont mind uploading the file information please do so. If you aren't comfortable with that, then just use the program as an auditing tool.

I know this was a long email, but I figured it, and or I may be able to help if you run into any more spyware related issues.
Also if any of you have comments on SSI we would love to hear them.
Enjoy hurricane season.

-AsHtRaY


SSI detects alot of my Trillian files as spyware. Obviously its just not learned into the system yet. I did upload them all so you could set them as acceptable in the data base
0 likes   

User avatar
Amanzi
Category 5
Category 5
Posts: 4883
Age: 47
Joined: Wed Oct 09, 2002 10:12 pm
Location: Epsom,UK

#22 Postby Amanzi » Thu Jun 17, 2004 12:14 pm

I need some help!!!

I ran spy bot, and it keeps picking up something called DSO exploit (HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ir)
Every time I tell spybot to delete it, its back the next time I reboot... how the heck do I permenantly get rid of it????
0 likes   

User avatar
Amanzi
Category 5
Category 5
Posts: 4883
Age: 47
Joined: Wed Oct 09, 2002 10:12 pm
Location: Epsom,UK

#23 Postby Amanzi » Fri Jun 18, 2004 12:40 pm

*bump*

I am bumping this thread in the hopes that someone can answer my question :lol:
0 likes   

AsHtRaY
Tropical Low
Tropical Low
Posts: 11
Joined: Mon Jun 14, 2004 6:21 pm
Location: Orlando FL

#24 Postby AsHtRaY » Fri Jun 18, 2004 3:55 pm

It's actually a bug in Spybot. Does SSI detect it?

There is actually a registry key that is wrong.

Using regedit.exe (start, run, regedit)
go to this key.

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0

Set the value to 3, and you should be good to go.
Here is a link for more discussions related to it.

http://forums.net-integration.net/index ... opic=15308

Hope this helps.
0 likes   

Rainband

#25 Postby Rainband » Fri Jun 18, 2004 3:59 pm

I was told that DSO exploit is a hole in the windows operating system and it is harmless.
0 likes   

GalvestonDuck
Category 5
Category 5
Posts: 15941
Age: 57
Joined: Fri Oct 11, 2002 8:11 am
Location: Galveston, oh Galveston (And yeah, it's a barrier island. Wanna make something of it?)

#26 Postby GalvestonDuck » Fri Jun 18, 2004 4:08 pm

I had it also. Spybot gives this link http://www.greymagic.com/security/advisories/gm001-ie/ for help.

Went there and they suggested the same thing Ash did.

And as they say -- "Many thanks to Axel Pettinger and Garland Hopkins for this workaround. "
0 likes   

AsHtRaY
Tropical Low
Tropical Low
Posts: 11
Joined: Mon Jun 14, 2004 6:21 pm
Location: Orlando FL

#27 Postby AsHtRaY » Fri Jun 18, 2004 8:03 pm

Amanzi any news about your post? SSI detect it? I am very interested to know.

Thanks

-AsHtRaY
0 likes   


Return to “Off Topic”

Who is online

Users browsing this forum: No registered users and 9 guests