I Just Got Bombed With Spyware

MrPinkMrPink Join Date: 2002-05-28 Member: 678Members
<div class="IPBDescription">This stuff was NASTY</div> And I have no idea how. I use a quality firewall and the only internet applications I was using were Steam, Explorer (surfing NewEgg.com), and IRC. Here's a summary of what happened:

I was surfing newegg (only) and my CPU usage goes through the roof. I see "Setup" open in the task bar but my computer is almost locked up its running so slow so I can't close it. After a minute or so my computer starts running at a reasonable speed again. I open task manager and see 15+ programs running that I don't recognize, so I kill them all. I lock down my internet with my firewall while I block all the applications that are spyware (21 in total I had to block), then set security to high. Then, I scan with AdWare and Spybot and together they pick up 200 or more bits of spyware. Well it still isn't gone cuz on restart it is still all there. So I go to open msconfig, well my toolbar is broken, GG. I find msconfig the hard way and take all the baddies off of startup and restart, it looks like it's gone. I go to use AVG to scan for any viruses, and it's deleted...I'm reinstalling it right now.

<b>Here's the golden question, how did this happen, and how do I make it not happen again?</b>

Comments

  • MantridMantrid Lockpick Join Date: 2003-12-07 Member: 24109Members
    Internet Explorer is a bad browser to use. There are issues with it, including the fact that websites can (sometimes) install software on your computer without asking you. Thats probably how it got there.

    The way to prevent it is to run Spyware scans regularly and switch to a good browser (like Opera).

    Or, you could go become a Tibetan monk and live in a mountain monestary above the clouds.

    Those two options are pretty much all you've got.
  • DragonMechDragonMech Join Date: 2003-09-19 Member: 21023Members, Constellation, Reinforced - Shadow
    <!--QuoteBegin-Mantrid+Apr 16 2004, 12:17 AM--></div><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td><b>QUOTE</b> (Mantrid @ Apr 16 2004, 12:17 AM)</td></tr><tr><td id='QUOTE'><!--QuoteEBegin--> and switch to a good browser (like Opera). <!--QuoteEnd--> </td></tr></table><div class='postcolor'> <!--QuoteEEnd-->
    I use <a href='http://www.mozilla.org/products/firefox/' target='_blank'>FireFox</a> myself, and love it.
  • weggyweggy Join Date: 2003-06-04 Member: 16998Members
    I got hit with something very similiar.

    Apparently theres this thing going around where if you get a pop-up, your dead. Doesnt matter if its blocked by a pop-up blocker, or if your using Firefox, youre still boned.

    Annoying.
  • ScytheScythe Join Date: 2002-01-25 Member: 46NS1 Playtester, Forum Moderators, Constellation, Reinforced - Silver
    <!--QuoteBegin-Dragon_Mech+Apr 16 2004, 04:19 PM--></div><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td><b>QUOTE</b> (Dragon_Mech @ Apr 16 2004, 04:19 PM)</td></tr><tr><td id='QUOTE'><!--QuoteEBegin--> <!--QuoteBegin-Mantrid+Apr 16 2004, 12:17 AM--></div><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td><b>QUOTE</b> (Mantrid @ Apr 16 2004, 12:17 AM)</td></tr><tr><td id='QUOTE'><!--QuoteEBegin--> and switch to a good browser (like Opera). <!--QuoteEnd--></td></tr></table><div class='postcolor'><!--QuoteEEnd-->
    I use <a href='http://www.mozilla.org/products/firefox/' target='_blank'>FireFox</a> myself, and love it. <!--QuoteEnd--> </td></tr></table><div class='postcolor'> <!--QuoteEEnd-->
    Ditto, Firefox is a damn good browser.

    And that avatar rocks...

    --Scythe--
  • BigMadSteveBigMadSteve Join Date: 2003-02-12 Member: 13472Members
    <!--QuoteBegin-Mantrid+Apr 16 2004, 06:17 AM--></div><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td><b>QUOTE</b> (Mantrid @ Apr 16 2004, 06:17 AM)</td></tr><tr><td id='QUOTE'><!--QuoteEBegin--> Internet Explorer is a bad browser to use. There are issues with it, including the fact that websites can (sometimes) install software on your computer without asking you. Thats probably how it got there.

    <!--QuoteEnd--> </td></tr></table><div class='postcolor'> <!--QuoteEEnd-->
    Isn't NewEgg a trustworthy site? Seems pretty popular. But like the previous posters said, Internet Explorer has several exploits in it. I use Firefox.
  • RaVeRaVe Join Date: 2003-06-20 Member: 17538Members
    Like that security hole in IE right?

    Lucky me. I use IE and still didn't get bombarded with that. The only problems I have are my brother downloading subbed animes eaitng up my disk space, and RealOne player remaining in memory for some reason.

    Why I use IE? I live life on the edge <!--emo&:p--><img src='http://www.unknownworlds.com/forums/html//emoticons/tounge.gif' border='0' style='vertical-align:middle' alt='tounge.gif' /><!--endemo-->
  • Fro5tyFro5ty Join Date: 2003-09-26 Member: 21238Members, Constellation
    If you were using mIRC, some jackass coulda forced your computer to download that pack of crap without you knowing till it was too late. Been many times I used mIRC in the past and gotten dozens of viruses. If anything is your culprit if that's all you're doing, IRC may have been it. But as with spyware, form what I know, if can filter through the firewall pretty much because it looks like normal internet traffic like websites or even... pop-ups... The evil thing with this crap is that it can get on your computer with little to no problem. You could look for something fairly popular in a search engine (game patches are very popular) and stumble onto a site that just put the words you wanted to find (Half-Life patch 1.1.1.0) and not say anything about it. A pop-up may come and disappear immediatly or you may never see one at all. Either way, that's one way they do it, and it's easy with IE because of it's integration into windows. Third party browsers help eliminate that problem, but there are down sides (some websides may not show up for whatever reason) and you may end up using IE sometimes. The best thing you can do, inform yourself about it <a href='http://www.spywareinfo.net' target='_blank'>at anti-spyware places</a> like that one I linked. They have information about making IE more secure, ways to prevent such things and how to get rid of them, and ratings of programs that fix that crap and they recommend.

    Also, just wait till your browser gets Hi-Jacked. That's a rather scary experience since the person(s) now pretty much own your computer. I just hope some of this anti-spyware legislator that passes is good and keeps these **** from doing it...
  • OttoDestructOttoDestruct Join Date: 2002-11-08 Member: 7790Members
    edited April 2004
    <!--QuoteBegin-Fr05t+Apr 16 2004, 09:32 AM--></div><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td><b>QUOTE</b> (Fr05t @ Apr 16 2004, 09:32 AM)</td></tr><tr><td id='QUOTE'><!--QuoteEBegin--> If you were using mIRC, some jackass coulda forced your computer to download that pack of crap without you knowing till it was too late.  Been many times I used mIRC in the past and gotten dozens of viruses.  If anything is your culprit if that's all you're doing, IRC may have been it.  But as with spyware, form what I know, if can filter through the firewall pretty much because it looks like normal internet traffic like websites or even... pop-ups...  The evil thing with this crap is that it can get on your computer with little to no problem.  You could look for something fairly popular in a search engine (game patches are very popular) and stumble onto a site that just put the words you wanted to find (Half-Life patch 1.1.1.0) and not say anything about it.  A pop-up may come and disappear immediatly or you may never see one at all.  Either way, that's one way they do it, and it's easy with IE because of it's integration into windows.  Third party browsers help eliminate that problem, but there are down sides (some websides may not show up for whatever reason) and you may end up using IE sometimes.  The best thing you can do, inform yourself about it <a href='http://www.spywareinfo.net' target='_blank'>at anti-spyware places</a> like that one I linked.  They have information about making IE more secure, ways to prevent such things and how to get rid of them, and ratings of programs that fix that crap and they recommend. 

    Also, just wait till your browser gets Hi-Jacked.  That's a rather scary experience since the person(s) now pretty much own your computer.  I just hope some of this anti-spyware legislator that passes is good and keeps these **** from doing it... <!--QuoteEnd--></td></tr></table><div class='postcolor'><!--QuoteEEnd-->
    Ive used mIRC 10+ years and never had anything like this happen....

    *edit*

    er.. well.. close to ten years... <!--emo&::nerdy::--><img src='http://www.unknownworlds.com/forums/html//emoticons/nerd.gif' border='0' style='vertical-align:middle' alt='nerd.gif' /><!--endemo-->
  • panda_de_malheureuxpanda_de_malheureux Join Date: 2003-12-26 Member: 24775Members
    firefox + numerous extension plug ins = the win, cant live without it
  • CommunistWithAGunCommunistWithAGun Local Propaganda Guy Join Date: 2003-04-30 Member: 15953Members
    <!--QuoteBegin-version91x+Apr 16 2004, 12:47 PM--></div><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td><b>QUOTE</b> (version91x @ Apr 16 2004, 12:47 PM)</td></tr><tr><td id='QUOTE'><!--QuoteEBegin--> firefox + numerous extension plug ins = the win, cant live without it <!--QuoteEnd--> </td></tr></table><div class='postcolor'> <!--QuoteEEnd-->
    Not to mention the fact it dosen't even NEED those plugins. God I love firefox <!--emo&:D--><img src='http://www.unknownworlds.com/forums/html//emoticons/biggrin.gif' border='0' style='vertical-align:middle' alt='biggrin.gif' /><!--endemo-->:D
  • Fro5tyFro5ty Join Date: 2003-09-26 Member: 21238Members, Constellation
    <!--QuoteBegin-OttoDestruct+Apr 16 2004, 10:23 AM--></div><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td><b>QUOTE</b> (OttoDestruct @ Apr 16 2004, 10:23 AM)</td></tr><tr><td id='QUOTE'><!--QuoteEBegin--> <!--QuoteBegin-Fr05t+Apr 16 2004, 09:32 AM--></div><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td><b>QUOTE</b> (Fr05t @ Apr 16 2004, 09:32 AM)</td></tr><tr><td id='QUOTE'><!--QuoteEBegin--> If you were using mIRC, some jackass coulda forced your computer to download that pack of crap without you knowing till it was too late.  Been many times I used mIRC in the past and gotten dozens of viruses.  If anything is your culprit if that's all you're doing, IRC may have been it.  But as with spyware, form what I know, if can filter through the firewall pretty much because it looks like normal internet traffic like websites or even... pop-ups...  The evil thing with this crap is that it can get on your computer with little to no problem.  You could look for something fairly popular in a search engine (game patches are very popular) and stumble onto a site that just put the words you wanted to find (Half-Life patch 1.1.1.0) and not say anything about it.  A pop-up may come and disappear immediatly or you may never see one at all.  Either way, that's one way they do it, and it's easy with IE because of it's integration into windows.  Third party browsers help eliminate that problem, but there are down sides (some websides may not show up for whatever reason) and you may end up using IE sometimes.  The best thing you can do, inform yourself about it <a href='http://www.spywareinfo.net' target='_blank'>at anti-spyware places</a> like that one I linked.  They have information about making IE more secure, ways to prevent such things and how to get rid of them, and ratings of programs that fix that crap and they recommend. 

    Also, just wait till your browser gets Hi-Jacked.  That's a rather scary experience since the person(s) now pretty much own your computer.  I just hope some of this anti-spyware legislator that passes is good and keeps these **** from doing it... <!--QuoteEnd--></td></tr></table><div class='postcolor'><!--QuoteEEnd-->
    Ive used mIRC 10+ years and never had anything like this happen....

    *edit*

    er.. well.. close to ten years... <!--emo&::nerdy::--><img src='http://www.natural-selection.org/forums/html//emoticons/nerd.gif' border='0' style='vertical-align:middle' alt='nerd.gif' /><!--endemo--> <!--QuoteEnd--> </td></tr></table><div class='postcolor'> <!--QuoteEEnd-->
    You may not have had anything happen, but I have, and a few other people I've talked to. In one of the previous builds, someone could initiate a download onto your computer without you accepting or even knowing of it. It was possible, may still be in someway. But every time you open up something that allows things to download to your computer, you are at risk in some level. Have to remember, there are a lot of script kiddes (that need to be shot and skinned, then hung upside down in front of computer stores) out there that think it's funny to mess with computers.
  • HybridclawHybridclaw Join Date: 2003-11-03 Member: 22271Members
    <a href='http://www.safer-networking.org/' target='_blank'>spybot search and destroy</a>
    it's good <i>and</i> it's free <!--emo&:D--><img src='http://www.unknownworlds.com/forums/html//emoticons/biggrin.gif' border='0' style='vertical-align:middle' alt='biggrin.gif' /><!--endemo-->
  • ubermenschubermensch Join Date: 2002-12-31 Member: 11692Banned
    <!--QuoteBegin-RaVe+Apr 16 2004, 05:26 AM--></div><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td><b>QUOTE</b> (RaVe @ Apr 16 2004, 05:26 AM)</td></tr><tr><td id='QUOTE'><!--QuoteEBegin--> Like that security hole in IE right?

    Lucky me. I use IE and still didn't get bombarded with that. The only problems I have are my brother downloading subbed animes eaitng up my disk space, and RealOne player remaining in memory for some reason.

    Why I use IE? I live life on the edge <!--emo&:p--><img src='http://www.unknownworlds.com/forums/html//emoticons/tounge.gif' border='0' style='vertical-align:middle' alt='tounge.gif' /><!--endemo--> <!--QuoteEnd--> </td></tr></table><div class='postcolor'> <!--QuoteEEnd-->
    RealOne player is a virus. Anything from Real is a virus.

    <a href='http://www.free-codecs.com/download/Real_Alternative.htm' target='_blank'>http://www.free-codecs.com/download/Real_Alternative.htm</a>

    Check out the above link for downloads to "Real Alternative 1.22 Final," a program that lets you play Real Media (be it audio, video or otherwise) through windows media player classic.

    MUCH better than disgusting Real software which is full of bloat and hidden agreements (like email me with more info automatically chceked off by default) and memory hogging uselsess start up daemons... just uninstall the virus and use the Real Alternative.
  • Har_Har_the_PirateHar_Har_the_Pirate Join Date: 2003-08-10 Member: 19388Members, Constellation
    i did a while back, finally got rid of it, i use mcafee virus scan, and i was able to get it off

    one problem i had is that u cant delete stuff while its running, so i had to go in and find what it is called, or go in safe mode, and delete them manually
Sign In or Register to comment.