SPYWARE RAAAAAAGH




Posted by maian

Suddenly, I have Spyware. It is my intent to crush it utterly as quickly and efficiently as possible.

I don't know exactly what it is, but it seems intent on destroying the ability to use the internets. I do'nt know exaclt what processes it uses, but suspicious and known culprits I've found in my task manager are:

8tAKxkr8.exe: This one pops up when you try to use the internet. It makes the browser so ridiculously slow that it's pretty much unusable. As soon as I end it, internet becomes usable again. However, when the computer is left alone for awhile, it'll return when you start up the internet.

a.exe: Suspicious, uses up a lot of memory.

And finally, csrss.exe. it says it's a "critical system process" when I try to close it. Searched it up, VIRUS LOL. EDIT: k, my search was a typo. Apparently it IS essential, but susceptible to viruses.

So, how on Earth can I get rid of these? Pleeeease help. My antivirus blocked many attempts into my computer, but some crap made it through, and I want it gone. I'm working on a print screen of all my processes right now.

EDIT: These are all my processes, as they stand right now. This is minus the stuff I've already deleted.

[IMG]http://img.photobucket.com/albums/v113/maian/Processes.gif[/IMG]
[IMG]http://img.photobucket.com/albums/v113/maian/processes2.gif[/IMG]




Posted by Proto Man

Apparently you picked up a W32.Ahlem.A@mm worm.

What have you "deleted?"

First of all, do you have any sort of anti-spyware programs? If not, I suggest Spybot Search and Destroy as well as Windows Defender. Install BOTH of these first, then make sure your Anti Virus is updated.

Then reboot the computer and go into Safe Mode (hit F8 after the BIOS POST BEEP). You want Safe Mode with Networking.

Open RUN type Regedit. In the registry editor, you need to navigate to HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run


You want to delete "SYSTEMSars32"="%windir%\csrss.exe" on the right

After you do this, restart the computer, and run both your Anti-Virus, Spybot, and Windows Defender.




Posted by Klarth

Reinstall windows, stop using AV software forever, be more careful




Posted by maian

Meh, I consider myself really good at avoiding viruses. This is the first time ever that I have actually gotten one, and it took me completely by surprise.

Thanks for the tip, Proto Man. So, deleting the csrss thing won't kill any of the major functions on my computer?




Posted by maian

Haha, oh wow. I just downloaded a recommended Spyware program, and it's detected 589 threats, all of which Norton has never picked up at all, and it's not even finished.

However, most of this junk seems like it's been here awhile, and I've never even felt the affects until this worm hit me. Nonetheless, I'm going to try and get rid of all of it. I have 533 Adware "Tracking Cookies". What are these? >_>




Posted by Roger Smith

"A tracking cookie is a cookie that tracks your browsing behaviors. Marketers use this data to understand how users use their partner websites and optimize their networks for the average user that visits their networks."

In other words, 1337 pc haxxorz that watch your every movement.




Posted by maian

They must be huge faggots. :cool2:

Anyway, SUPERAntiSpyware came very highly recommended, and I downloaded it. It found 609 threats, and deleted them all in one fell swoop. Should I still try to do the registry edit? Whatever was slowing it down isn't there anymore. I've just rebooted, so I'm going to run one more scan and see if anything is still here.




Posted by Vampiro V. Empire


Quoted post: all of which Norton has never picked up at all,


Yeah... that's why no one uses norton anymore.



Posted by BLUNTMASTER X

maian must be pretty retarded to pick up 500 viruses and other malicious **** hahaha




Posted by BLUNTMASTER X

big_boss_yaoi.exe




Posted by Vampiro V. Empire

Yeah, that's quite a bit, especially if you thought you were being careful. Though it's spyware, and 3/4 of it were likely doing nothing major.




Posted by maian

Yeah, there was actually only like, four harmful things on it, which must've been picked up very recently. The other uh, 600 was all crap like tracking cookies and random stuff that didn't have any noticeable effects.




Posted by Proto Man


Quoting maian: Thanks for the tip, Proto Man.


yw


Quoting maian: Should I still try to do the registry edit? Whatever was slowing it down isn't there anymore.


Well if it seems that everything is ok, and none of the symptoms are there anymore perhaps one of the anti-spyware programs did it for you. If you aren't having any problems like before then don't bother with the registry.

And yeah, don't mess with Norton anymore, it is junk. If you don't want to pay, use AVG or AVAST (my favorite is AVG though).



Posted by maian

Hmm, 8tAKxkr8.exe started showing up again. I suppose I'm going to check the registry. The spyware program seemingly wiped it out, but it finally showed up again today.




Posted by Vampiro V. Empire

probably caught it again. stop going to ****ty porn sites.




Posted by maian

Linko hooked me up with some dickgirl sites. I'M STARTING TO THINK IT WAS JUST A RUSE




Posted by Proto Man


Quoting maian: Hmm, 8tAKxkr8.exe started showing up again. I suppose I'm going to check the registry. The spyware program seemingly wiped it out, but it finally showed up again today.


Yeah go into the registry then. Although I am not sure if that 8tAKxkr8.exe is releated to the worm, because I tried looking it up and it wasn't coming up anywhere. Anyways:

[Quote=Proto Man]Then reboot the computer and go into Safe Mode (hit F8 after the BIOS POST BEEP). You want Safe Mode with Networking.

Open RUN type Regedit. In the registry editor, you need to navigate to HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run


You want to delete "SYSTEMSars32"="%windir%\csrss.exe" on the right



Posted by maian

So, this thread is really old. But I never actually did anything except for run a few Spyware programs and delete stuff from those. But at this point (I think this is due from my sister's retarded browsing habits), both Firefox and IE are barely usable. The computer is always moaning, and I feel like it's plagued with crap that's bogging it down. I finally went into my registry editor, and couldn't find that thing you mentioned anywhere. I'll post back with any updates.




Posted by cool gamer dad

lol dude you gotta reformat if it's come to that.


by the time it's really slowing your computer down you really should do it. probably gonna waste more time waiting for **** to load up than reformatting.




Posted by Crazy K

Use Linux instead.




Posted by BLUNTMASTER X

[quote=maian;934619](I think this is due from my sister's retarded browsing habits)big_boss_hentai.exe (2KB)




Posted by Fate

Extract all files that are important and do a restore. I've had my computer for about four years now and it's running just as fast as when I first bought it without having to do any restores. What the hell are you browsing?




Posted by maian

Pretty much the extent of what I browse is VGC, IGN, and Facebook. Maybe Myspace occasionally. I'll go to other sites here and there (that I know are safe), but that's pretty much the bulk of my browsing.

...Now, imagine having a little sister that's in seventh grade that's a complete Myspace whore, and her and her three friends always sitting at the computer for hours doing *** knows what, and then getting on later and finding crap like "MyWebSearch" installed into the browser. Ugh.

Anyway, ran a program, and it told me I had three worms. Went into Regedit, and everything it told me to delete was gone, except for one. I did, however, find the elusive "8tAKxkr8.exe" as an application in my system32 folder. Deleted that, and it's finally gone. I then ran Super-Anti-Spyware, installed Windows Defender, and Spybot Search and Destroy as Protoman suggested. Defender found nothing, and the program I had already downloaded months prior, Super Anti-Spyware, found about five times as much as Search and Destroy. I had the programs "get rid of" the quarantined items, and after a restart...Internet Explorer can't even run anymore, because hundreds of black sys32 boxes just keep appearing and reappearing, and won't let it start up LOL




Posted by Apathetic

wipe it clean and re install.




Posted by Crazy K

Install linux.




Posted by Vampiro V. Empire

hijackthis, post results on tech-savvy forum, do what they say.

or just pop in your windows disc and start over. pretty much need to do that every few years anyways.




Posted by ranson

I think u should install a new window.




Posted by Stalolin

put the new window in the dining room

it'll go great with those new curtains




Posted by Slade

how about 7 windows? ;)