Go Back   PCMech Forums > Windows Support > Windows Legacy Support (XP and earlier)

Need Some Help? Type Your Keywords Here:

Reply
 
LinkBack Thread Tools Search this Thread Rate Thread Display Modes
Old 01-09-2004, 02:40 PM   #1
Member (9 bit)
 
Join Date: Aug 2001
Posts: 394
Send a message via ICQ to Eric H. Send a message via AIM to Eric H.
Pissed Spyware Problem

My dad is having a huge problem here with spyware.

His regular startup page is yahoo, but everytime he restarts its changed to '69.50.184.52/find4u' which is a search page. I ran the latest versions of adaware and spybot, I updated norton 2004 and ran that. Didn't get rid of the problem. So, I saw that in his startup folder was an unusual file called winlogon.exe. I couldn't delete it, because the file was running. I tried ending its process, but its a critical windows file. Okay, so I go into msconfig, looked through the win.ini - nothing illregular. I disabled EVERYTHING in his startup list, including that winlogon file. Restarted, yahoo was changed back to the stupid website again. I went back into msconfig, and it turns out that winlogon.exe file rechecked itself in the startup menu.

I went to my XP computer upstairs, and I don't have winlogon. Could that be the problem?? Should I try deleting it in safe mode?

His computer is a compaq laptop, connected to our home network. I even unplugged the network cable during all of this mess. Please help!
Eric H. is offline   Reply With Quote
Old 01-09-2004, 03:05 PM   #2
Member (12 bit)
 
not important's Avatar
 
Join Date: Jul 2002
Location: Illinois
Posts: 3,557
Try Spybot S&D.
http://www.safer-networking.org/inde...&page=download
not important is offline   Reply With Quote
Old 01-09-2004, 03:17 PM   #3
Member (9 bit)
 
el_novato's Avatar
 
Join Date: Sep 2002
Location: G.P., TX
Posts: 472
it may be a problem with the HOSTS file. Do a search for HOSTS file on forums. You'll find links to other software that might help you fix the problem. Good luck.

http://www.accs-net.com/hosts/what_is_hosts.html
el_novato is offline   Reply With Quote
Old 01-09-2004, 03:20 PM   #4
The Preacher Man
Premium Member
 
SARGE's Avatar
 
Join Date: Apr 2000
Location: Dallas
Posts: 4,828
http://www.spywareinfo.com/downloads/spg/

Then, read over this:

http://www.computing.net/security/ww...orum/7737.html
__________________
"Don't be so open-minded that your brains fall out."

Last edited by SARGE; 01-09-2004 at 03:26 PM.
SARGE is offline   Reply With Quote
Old 01-09-2004, 04:18 PM   #5
Member (1 bit)
 
Join Date: Jan 2004
Posts: 1
Send a message via AIM to fanaddict
Had a similar problem myself. Now I have an "unknown" file in my startup all the time listed as c:\windows\system (win9x) and I can't get rid of that. I was infected by some Malsoft that created pop-ups. I ran ad-aware and that took care of all of it except this remaining bugger. Now instead of pop-up ads my system folder pops up once in a while when I click the address area of the tool bar. Any ideas?
fanaddict is offline   Reply With Quote
Old 01-09-2004, 04:31 PM   #6
Member (9 bit)
 
Join Date: Aug 2001
Posts: 394
Send a message via ICQ to Eric H. Send a message via AIM to Eric H.
not important: i did run spybot

I found out the problem was a virus norton never picked up.
Eric H. is offline   Reply With Quote
Old 01-09-2004, 09:39 PM   #7
The Preacher Man
Premium Member
 
SARGE's Avatar
 
Join Date: Apr 2000
Location: Dallas
Posts: 4,828
Quote:
Originally posted by fanaddict
Had a similar problem myself. Now I have an "unknown" file in my startup all the time listed as c:\windows\system (win9x) and I can't get rid of that. ... Now instead of pop-up ads my system folder pops up once in a while when I click the address area of the tool bar. Any ideas?
Did you try SpyBot along with AdAware, do a virus scan? Hit ctrl alt del and write down all items running, then do a Find for unfamiliar ones, right click and look under properties. Do the same in msconfig startup tab. Delete in both places, reboot and see if it reappears. If so, try deleting it in Safe Mode. If it has a name in ctrl alt del, you can do a search on Google for fixes.
SARGE is offline   Reply With Quote
Reply

Bookmarks

Still Need Help? Type Your Keywords Here:


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -5. The time now is 11:29 AM.
Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2012, vBulletin Solutions, Inc.
SEO by vBSEO 3.6.0 PL2