u½chost SPYWARE ?

i have a pc that is getting random pop-up ads and running slower than normal. i have updated NAV 2003 and scan found nothing. i have found a running process called u½chost that i cannot make go away. everytime i stop the process within a few seconds it's back. i think this is probably the culprit but i cannot find where it is being launched from to terminate it.
ran ad-aware to no avail; it did not detect this object. if anyone has heard of this and has any idea of how to rid the pc of this parasite i would appreciate the help.

thanks in advance,
cardilion
cardilionAsked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

SheharyaarSaahilCommented:
Hello cardilion =)

First of all use this tool to know abt this process >> http://www.sysinternals.com/ntw2k/freeware/procexp.shtml
0
SheharyaarSaahilCommented:
Second use hijackthis and fix its all traces from there,

Download HijackThis v1.98.2 from here, run it and Save the LOG file:
http://tools.radiosplace.com/HijackThis.exe

Then Post that log at this site >> http://www.hijackthis.de/index.php?langselect=english
and it will automatically analyse it for u,,, Fix the entries which it labels as Nasty :)
To Fix, check the lines and click on Fix Checked !!

HJT Log Tutoriol >> http://aumha.org/a/hjttutor.php

CAUTION: Before fixing the entries in hijackthis, make sure that they are really Nasty and can be deleted, better u first research for it on Google and then when u will confirm that they shud be deleted, Fix them. And whenever u run Hijackthis, run it from a New folder on ur desktop, so that in case of any problem, u can take advantages of its created backups of fixed items. And in case if u still face problems in dealing with it, just analyse ur log at the above site, and then scroll down where u will see a Save Analyse button, hit it and it will save ur Log Analysation, then copy the link of that page and paste it here, and we will check it for u :)
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
SheharyaarSaahilCommented:
Third boot ur system in safemode, disable ur ssytem restore if its WinXP !!
find this file on ur hard drive, delete it if its present, and then delete all its references from regedit also !!
then run these tools one by one to make sure they come as clean !!

AdAware ==> http://www.spychecker.com/program/adaware.html
SpyBot  ==> http://www.spychecker.com/program/spybot.html
CoolWebShredder ==> http://www.softpedia.com/public/cat/10/17/10-17-150.shtml
Stinger ==> http://vil.nai.com/vil/stinger

Then delete the temporary internet files and history of IE
and run Disk Cleanup on ur hard drive to delete those temp and junk files.
Restart back in Normal Mode to check for the problems now ??

Post Back & Good Luck :)
0
riotzCommented:
hmm
open up your regedit.exe..
press "F3" and search for that executable and delete all regentries related to it..
reboot
and delete the file

if that doesnt help send me and zipped up copy of that parasite to int21h@gmail.com
and i'll take a look into it
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
OS Security

From novice to tech pro — start learning today.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.