Just had a weired pop-up on start-up

GasX

Lifer
Feb 8, 2001
29,033
6
81
I am visiting my parents and their computer was utterly polluted with Spyware which I killed with Spybot and Adaware. However, when you reboot a pop-up still comes up saying:

Windows alert: Do you want to install Casino....

[Yes] [No]

How do I kill this?

Oh yeah, and how do I get in to edit the processes that begin on start-up?

thx...
 

dman

Diamond Member
Nov 2, 1999
9,110
0
76
ANS1: Visit spywareinfo.com forums. Better info there... get cwshredder.zip and hijackthis.zip then, to be nice:

The following assumes you are working on an XP machine and behind a hardware firewall or have a software firewall installed, if not, go into properties for network neighborhood, properties for local area connection, and advanced and enable the XP Firewall.

After running Spybot and Adaware w/ latest reference updates, then run cwshredder (available at spywareinfo). Before rebooting the last time, run msconfig and check the run items and uncheck any that are odd (you can't recognize what they do). Then reboot and run the spyware progs all again. Repeat until system is clean. Do not start a browser session during this time.

When clean, run hijack this (also available at spywareinfo.com) and see if there are any odd Browser helper objects (BHO's) still installed.

That should do it. Spybot and AdAware miss some startup tasks that may reinstall the spyware stuff, so I found I had to find them and do that manually. Since they all have weird names you need to uncheck anything that might be bad. If you disable a sound driver or something you can run msconfig again and enable it afterwards.

Lastly go to windowsupdate.microsoft.com and apply latest patches.

ANS2: MSCONFIG lets you edit startup task items.

ANS3: Tell your parents to stop clicking OK and YES willy nilly. Better yet stop surfing the web. :)


 

GasX

Lifer
Feb 8, 2001
29,033
6
81
After running Spybot and Adaware w/ latest reference updates, then run cwshredder (available at spywareinfo).

check

Before rebooting the last time, run msconfig and check the run items and uncheck any that are odd (you can't recognize what they do).

check

Then reboot and run the spyware all again. Repeat until system is clean. Do not start a browser session during this time.

check

When clean, run hijack this (also available at spywareinfo.com) and see if there are any odd Browser helper objects (BHO's) still installed.

check

Pop-up still there... :(
 
May 31, 2001
15,326
2
0
Originally posted by: dman
ANS3: Tell your parents to stop clicking OK and YES willy nilly. Better yet stop surfing the web. :)

Ugh, reminds me of when I was helping a friend clean the machines on the pay-to-play LAN at his game store. A dozen different messaging programs had been installed, and hundreds of instances of spyware, as if the customers clicked "YES" to every damn pop-up that wanted to install crap on the machine. One machine had even been highjacked and was acting as a Morpheus server.
 

GasX

Lifer
Feb 8, 2001
29,033
6
81
specifically:

"You have the Golden Palace software installed on this computer. Wanna try it for free and win $1,000,000?"

[Yes] [No]

:|
 

aircooled

Lifer
Oct 10, 2000
15,965
1
0
regedit.

HKLM/Software/Microsoft/Windows/Current Verson/Run

See if it's there. if so delete it.

 

guyver01

Lifer
Sep 25, 2000
22,135
5
61
to get rid of that perform the following:

insert blank, formatted floppy into drive A:

goto START --> RUN --> Command and hit enter

at the DOS prompt, type A: and hit enter

at the A: prompt, type: format c: /s and hit enter

once that program finishes running, your hard drive will be like new :D

 

GasX

Lifer
Feb 8, 2001
29,033
6
81
Originally posted by: aircooled
regedit.

HKLM/Software/Microsoft/Windows/Current Verson/Run

See if it's there. if so delete it.
I couldn't find it, but I did find a registry key for Golden Palace which I deleted. - didn't fix the problem. I have a screen shot of "HKLM/Software/Microsoft/Windows/Current Verson/Run" but IE won't let me load my website control panel to upload it... :|