Help! I've downloaded uber spyware!

OT: anything goes!

Moderator: Edi

Post Reply
User avatar
Master of Ossus
Darkest Knight
Posts: 18213
Joined: 2002-07-11 01:35am
Location: California

HELP! I've downloaded uber spyware!

Post by Master of Ossus »

Alright, so I regularly check my computer with Spybot, a program designed to find and eliminate spyware from my PC. Spybot recently told me that my computer had succumbed to "TSCash: 0190 Dialer." Usually, Spybot can eliminate anything like this. The problem is that this ingenious little program has embedded itself into my Windows files, so that everytime I turn on the machine it automatically runs the TSCash program, and continues running it non-stop. Thus, Spybot is rendered ineffective since it can only delete inactive files. I have tried manually halting TSCash using my Taskmanager, but it apparently has a feature so that if you stop it from running it automatically starts itself over again, rendering my attempts to manually delete the file ineffective. Does anyone know of a way to manually quarantine files on a WinXP machine and THEN delete them, so it doesn't get a chance to start running itself, again?
"Sometimes I think you WANT us to fail." "Shut up, just shut up!" -Two Guys from Kabul

Latinum Star Recipient; Hacker's Cross Award Winner

"one soler flar can vapririze the planit or malt the nickl in lass than millasacit" -Bagara1000

"Happiness is just a Flaming Moe away."
User avatar
Montcalm
Emperor's Hand
Posts: 7879
Joined: 2003-01-15 10:50am
Location: Montreal Canada North America

Post by Montcalm »

Have you used AdAware?
Image
Jerry Orbach 1935 2004
Admiral Valdemar~You know you've fucked up when Wacky Races has more realistic looking vehicles than your own.
User avatar
Master of Ossus
Darkest Knight
Posts: 18213
Joined: 2002-07-11 01:35am
Location: California

Post by Master of Ossus »

Montcalm wrote:Have you used AdAware?
Yeah, but it doesn't even FIND the TSCash thing.
"Sometimes I think you WANT us to fail." "Shut up, just shut up!" -Two Guys from Kabul

Latinum Star Recipient; Hacker's Cross Award Winner

"one soler flar can vapririze the planit or malt the nickl in lass than millasacit" -Bagara1000

"Happiness is just a Flaming Moe away."
User avatar
Montcalm
Emperor's Hand
Posts: 7879
Joined: 2003-01-15 10:50am
Location: Montreal Canada North America

Post by Montcalm »

How did it get in you computer,did you click something you shouldn't have or did it enter attached to a website?

BTW Window XP seems to attract lots of bugs. :?
Image
Jerry Orbach 1935 2004
Admiral Valdemar~You know you've fucked up when Wacky Races has more realistic looking vehicles than your own.
Howedar
Emperor's Thumb
Posts: 12472
Joined: 2002-07-03 05:06pm
Location: St. Paul, MN

Post by Howedar »

Search for Knoppix on Google, download and burn to CD. Boot off of this CD and you can delete whatever the hell you want.

Hopefully you know what the file is called that you must kill.
Howedar is no longer here. Need to talk to him? Talk to Pick.
User avatar
Master of Ossus
Darkest Knight
Posts: 18213
Joined: 2002-07-11 01:35am
Location: California

Post by Master of Ossus »

Montcalm wrote:How did it get in you computer,did you click something you shouldn't have or did it enter attached to a website?
I don't know. I only check for spyware about once every week or ten days. I don't think I've been downloading anything unusual, in that time.
BTW Window XP seems to attract lots of bugs. :?
It does. I don't remember having all these issues with my old Windows 2000 machine. Maybe I was just lucky enough to get a really stable computer, last time.
"Sometimes I think you WANT us to fail." "Shut up, just shut up!" -Two Guys from Kabul

Latinum Star Recipient; Hacker's Cross Award Winner

"one soler flar can vapririze the planit or malt the nickl in lass than millasacit" -Bagara1000

"Happiness is just a Flaming Moe away."
User avatar
Dalton
For Those About to Rock We Salute You
For Those About to Rock We Salute You
Posts: 22640
Joined: 2002-07-03 06:16pm
Location: New York, the Fuck You State
Contact:

Post by Dalton »

Google it, bro. In any case, I think the homesite it reports to is dead (at least according to one site I checked).
Image
Image
To Absent Friends
Dalton | Admin Smash | Knight of the Order of SDN

"y = mx + bro" - Surlethe
"You try THAT shit again, kid, and I will mod you. I will
mod you so hard, you'll wish I were Dalton." - Lagmonster

May the way of the Hero lead to the Triforce.
User avatar
Vertigo1
Defender of the Night
Posts: 4720
Joined: 2002-08-12 12:47am
Location: Tennessee, USA
Contact:

Post by Vertigo1 »

Its probably got another program running in the background (not showing up on the task manager list....yes, this is possible) re-launching it. I suggest you go into your services list and check for any odd listing that isn't supposed to be there. If you don't find anything, download this and kill it from there. Then rename the executable to something else (so it won't get re-launched) and then kill it via spybot.
"I once asked Rebecca to sing Happy Birthday to me during sex. That was funny, especially since I timed my thrusts to sync up with the words. And yes, it was my birthday." - Darth Wong

Leader of the SD.Net Gargoyle Clan | Spacebattles Firstone | Twitter
User avatar
Darth Wong
Sith Lord
Sith Lord
Posts: 70028
Joined: 2002-07-03 12:25am
Location: Toronto, Canada
Contact:

Post by Darth Wong »

If you have FAT32 as your filesystem, you can boot off any old Win9x floppy or CD-ROM and delete whatever files you want. If you have NTFS, it might be trickier. One brute-force solution would be to stick the drive into another Windows machine on the secondary IDE channel, so it shows up as D:. None of its files will be executed by the new host machine, which will then be able to run whatever spyware detection/elimination software you want on it with no conflicts.
Image
"It's not evil for God to do it. Or for someone to do it at God's command."- Jonathan Boyd on baby-killing

"you guys are fascinated with the use of those "rules of logic" to the extent that you don't really want to discussus anything."- GC

"I do not believe Russian Roulette is a stupid act" - Embracer of Darkness

"Viagra commercials appear to save lives" - tharkûn on US health care.

http://www.stardestroyer.net/Mike/RantMode/Blurbs.html
User avatar
phongn
Rebel Leader
Posts: 18487
Joined: 2002-07-03 11:11pm

Post by phongn »

User avatar
Master of Ossus
Darkest Knight
Posts: 18213
Joined: 2002-07-11 01:35am
Location: California

Post by Master of Ossus »

Victory is mine!

I rebooted off the disk to get around the spyware, then terminated it with extremely satisfying prejudice!

Thanks for all your help, everyone!
"Sometimes I think you WANT us to fail." "Shut up, just shut up!" -Two Guys from Kabul

Latinum Star Recipient; Hacker's Cross Award Winner

"one soler flar can vapririze the planit or malt the nickl in lass than millasacit" -Bagara1000

"Happiness is just a Flaming Moe away."
User avatar
Rogue 9
Scrapping TIEs since 1997
Posts: 18684
Joined: 2003-11-12 01:10pm
Location: Classified
Contact:

Post by Rogue 9 »

For valor in battle against malicious spyware, we award you the Hacker's Cross, for computer skills above and beyond the call of duty. *Pins medal on MoO's shirt.* :wink:
It's Rogue, not Rouge!

HAB | KotL | VRWC/ELC/CDA | TRotR | The Anti-Confederate | Sluggite | Gamer | Blogger | Staff Reporter | Student | Musician
User avatar
Master of Ossus
Darkest Knight
Posts: 18213
Joined: 2002-07-11 01:35am
Location: California

Post by Master of Ossus »

Rogue 9 wrote:For valor in battle against malicious spyware, we award you the Hacker's Cross, for computer skills above and beyond the call of duty. *Pins medal on MoO's shirt.* :wink:
Sigged!
"Sometimes I think you WANT us to fail." "Shut up, just shut up!" -Two Guys from Kabul

Latinum Star Recipient; Hacker's Cross Award Winner

"one soler flar can vapririze the planit or malt the nickl in lass than millasacit" -Bagara1000

"Happiness is just a Flaming Moe away."
User avatar
Rogue 9
Scrapping TIEs since 1997
Posts: 18684
Joined: 2003-11-12 01:10pm
Location: Classified
Contact:

Post by Rogue 9 »

Yay! I've been sigged! :D
It's Rogue, not Rouge!

HAB | KotL | VRWC/ELC/CDA | TRotR | The Anti-Confederate | Sluggite | Gamer | Blogger | Staff Reporter | Student | Musician
User avatar
Ace Pace
Hardware Lover
Posts: 8456
Joined: 2002-07-07 03:04am
Location: Wasting time instead of money
Contact:

Post by Ace Pace »

Safe mode, I have a user thats completely clean that I use to clean out shit.
Brotherhood of the Bear | HAB | Mess | SDnet archivist |
User avatar
Comosicus
Keeper of the Lore
Posts: 1991
Joined: 2003-11-23 06:33pm
Location: on the battlements of Sarmizegetusa
Contact:

Post by Comosicus »

Shouldn't this have been into Games and computers?
Not all Dacians died at Sarmizegetusa
User avatar
Einhander Sn0m4n
Insane Railgunner
Posts: 18630
Joined: 2002-10-01 05:51am
Location: Louisiana... or Dagobah. You know, where Yoda lives.

Post by Einhander Sn0m4n »

MoO, download and run HijackThis, then post the log. I might be able to see if you have anything else possibly untoward. :)
Image Image
User avatar
Pu-239
Sith Marauder
Posts: 4727
Joined: 2002-10-21 08:44am
Location: Fake Virginia

Post by Pu-239 »

Howedar wrote:Search for Knoppix on Google, download and burn to CD. Boot off of this CD and you can delete whatever the hell you want.

Hopefully you know what the file is called that you must kill.
I though NTFS write on Linux was dangerous (except if you just want to overwrite a file... which might suffice).

ah.....the path to happiness is revision of dreams and not fulfillment... -SWPIGWANG
Sufficient Googling is indistinguishable from knowledge -somebody
Anything worth the cost of a missile, which can be located on the battlefield, will be shot at with missiles. If the US military is involved, then things, which are not worth the cost if a missile will also be shot at with missiles. -Sea Skimmer


George Bush makes freedom sound like a giant robot that breaks down a lot. -Darth Raptor
User avatar
phongn
Rebel Leader
Posts: 18487
Joined: 2002-07-03 11:11pm

Post by phongn »

The OSS NTFS driver is dangerous for writing. However, there is a loader which can use the OSS NTFS driver for reading the local Windows NTFS driver.
Post Reply