Solved

u½chost SPYWARE ?

Posted on 2004-10-27
215 Views
Last Modified: 2013-12-04
i have a pc that is getting random pop-up ads and running slower than normal. i have updated NAV 2003 and scan found nothing. i have found a running process called u½chost that i cannot make go away. everytime i stop the process within a few seconds it's back. i think this is probably the culprit but i cannot find where it is being launched from to terminate it.
ran ad-aware to no avail; it did not detect this object. if anyone has heard of this and has any idea of how to rid the pc of this parasite i would appreciate the help.

thanks in advance,
cardilion
0
Question by:cardilion
    4 Comments
     
    LVL 65

    Expert Comment

    by:SheharyaarSaahil
    Hello cardilion =)

    First of all use this tool to know abt this process >> http://www.sysinternals.com/ntw2k/freeware/procexp.shtml
    0
     
    LVL 65

    Accepted Solution

    by:
    Second use hijackthis and fix its all traces from there,

    Download HijackThis v1.98.2 from here, run it and Save the LOG file:
    http://tools.radiosplace.com/HijackThis.exe

    Then Post that log at this site >> http://www.hijackthis.de/index.php?langselect=english
    and it will automatically analyse it for u,,, Fix the entries which it labels as Nasty :)
    To Fix, check the lines and click on Fix Checked !!

    HJT Log Tutoriol >> http://aumha.org/a/hjttutor.php

    CAUTION: Before fixing the entries in hijackthis, make sure that they are really Nasty and can be deleted, better u first research for it on Google and then when u will confirm that they shud be deleted, Fix them. And whenever u run Hijackthis, run it from a New folder on ur desktop, so that in case of any problem, u can take advantages of its created backups of fixed items. And in case if u still face problems in dealing with it, just analyse ur log at the above site, and then scroll down where u will see a Save Analyse button, hit it and it will save ur Log Analysation, then copy the link of that page and paste it here, and we will check it for u :)
    0
     
    LVL 65

    Expert Comment

    by:SheharyaarSaahil
    Third boot ur system in safemode, disable ur ssytem restore if its WinXP !!
    find this file on ur hard drive, delete it if its present, and then delete all its references from regedit also !!
    then run these tools one by one to make sure they come as clean !!

    AdAware ==> http://www.spychecker.com/program/adaware.html
    SpyBot  ==> http://www.spychecker.com/program/spybot.html
    CoolWebShredder ==> http://www.softpedia.com/public/cat/10/17/10-17-150.shtml
    Stinger ==> http://vil.nai.com/vil/stinger

    Then delete the temporary internet files and history of IE
    and run Disk Cleanup on ur hard drive to delete those temp and junk files.
    Restart back in Normal Mode to check for the problems now ??

    Post Back & Good Luck :)
    0
     
    LVL 4

    Expert Comment

    by:riotz
    hmm
    open up your regedit.exe..
    press "F3" and search for that executable and delete all regentries related to it..
    reboot
    and delete the file

    if that doesnt help send me and zipped up copy of that parasite to int21h@gmail.com
    and i'll take a look into it
    0

    Write Comment

    Please enter a first name

    Please enter a last name

    We will never share this with anyone.

    Featured Post

    Free Trending Threat Insights Every Day

    Enhance your security with threat intelligence from the web. Get trending threat insights on hackers, exploits, and suspicious IP addresses delivered to your inbox with our free Cyber Daily.

    Many of us in IT utilize a combination of roaming profiles and folder redirection to ensure user information carries over from one workstation to another; in my environment, it was to enable virtualization without needing a separate desktop for each…
    SHARE your personal details only on a NEED to basis. Take CHARGE and SECURE your IDENTITY. How do I then PROTECT myself and stay in charge of my own Personal details (and) - MY own WAY...
    This video is in connection to the article "The case of a missing mobile phone (https://www.experts-exchange.com/articles/28474/The-Case-of-a-Missing-Mobile-Phone.html)". It will help one to understand clearly the steps to track a lost android phone.
    In this sixth video of the Xpdf series, we discuss and demonstrate the PDFtoPNG utility, which converts a multi-page PDF file to separate color, grayscale, or monochrome PNG files, creating one PNG file for each page in the PDF. It does this via a c…

    857 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    17 Experts available now in Live!

    Get 1:1 Help Now