Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win

x
?
Solved

u½chost SPYWARE ?

Posted on 2004-10-27
4
Medium Priority
?
220 Views
Last Modified: 2013-12-04
i have a pc that is getting random pop-up ads and running slower than normal. i have updated NAV 2003 and scan found nothing. i have found a running process called u½chost that i cannot make go away. everytime i stop the process within a few seconds it's back. i think this is probably the culprit but i cannot find where it is being launched from to terminate it.
ran ad-aware to no avail; it did not detect this object. if anyone has heard of this and has any idea of how to rid the pc of this parasite i would appreciate the help.

thanks in advance,
cardilion
0
Comment
Question by:cardilion
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
4 Comments
 
LVL 65

Expert Comment

by:SheharyaarSaahil
ID: 12428132
Hello cardilion =)

First of all use this tool to know abt this process >> http://www.sysinternals.com/ntw2k/freeware/procexp.shtml
0
 
LVL 65

Accepted Solution

by:
SheharyaarSaahil earned 1500 total points
ID: 12428144
Second use hijackthis and fix its all traces from there,

Download HijackThis v1.98.2 from here, run it and Save the LOG file:
http://tools.radiosplace.com/HijackThis.exe

Then Post that log at this site >> http://www.hijackthis.de/index.php?langselect=english
and it will automatically analyse it for u,,, Fix the entries which it labels as Nasty :)
To Fix, check the lines and click on Fix Checked !!

HJT Log Tutoriol >> http://aumha.org/a/hjttutor.php

CAUTION: Before fixing the entries in hijackthis, make sure that they are really Nasty and can be deleted, better u first research for it on Google and then when u will confirm that they shud be deleted, Fix them. And whenever u run Hijackthis, run it from a New folder on ur desktop, so that in case of any problem, u can take advantages of its created backups of fixed items. And in case if u still face problems in dealing with it, just analyse ur log at the above site, and then scroll down where u will see a Save Analyse button, hit it and it will save ur Log Analysation, then copy the link of that page and paste it here, and we will check it for u :)
0
 
LVL 65

Expert Comment

by:SheharyaarSaahil
ID: 12428158
Third boot ur system in safemode, disable ur ssytem restore if its WinXP !!
find this file on ur hard drive, delete it if its present, and then delete all its references from regedit also !!
then run these tools one by one to make sure they come as clean !!

AdAware ==> http://www.spychecker.com/program/adaware.html
SpyBot  ==> http://www.spychecker.com/program/spybot.html
CoolWebShredder ==> http://www.softpedia.com/public/cat/10/17/10-17-150.shtml
Stinger ==> http://vil.nai.com/vil/stinger

Then delete the temporary internet files and history of IE
and run Disk Cleanup on ur hard drive to delete those temp and junk files.
Restart back in Normal Mode to check for the problems now ??

Post Back & Good Luck :)
0
 
LVL 4

Expert Comment

by:riotz
ID: 12515054
hmm
open up your regedit.exe..
press "F3" and search for that executable and delete all regentries related to it..
reboot
and delete the file

if that doesnt help send me and zipped up copy of that parasite to int21h@gmail.com
and i'll take a look into it
0

Featured Post

Free Tool: IP Lookup

Get more info about an IP address or domain name, such as organization, abuse contacts and geolocation.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

The term "Bad USB" is a buzz word that is usually used when talking about attacks on computer systems that involve USB devices. In this article, I will show what possibilities modern windows systems (win8.x and win10) offer to fight these attacks wi…
Article by: btan
The intent is not to repeat what many has know about Ransomware but more to join its dots of what is it, who are the victims, why it exists, when and how we respond on infection. Lastly, sum up in a glance to share such information with more to help…
This course is ideal for IT System Administrators working with VMware vSphere and its associated products in their company infrastructure. This course teaches you how to install and maintain this virtualization technology to store data, prevent vuln…
Visualize your data even better in Access queries. Given a date and a value, this lesson shows how to compare that value with the previous value, calculate the difference, and display a circle if the value is the same, an up triangle if it increased…
Suggested Courses

609 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question