spyware?! removal help...

stech4u

Member
Mar 21, 2002
187
0
0
i accidently clicked on YES on a mime/install pop-ups -- one of those things, that pops-up if you go sponsored sites (ie. lycos.com or something)...

problem: when i search for something using my IE address.bar it goes to msn.com automatically, then after 2 or more seconds it forwads to http://www.lop.com/

i tried cleaning registry w/ RegClean and RegVac. and search for anything to do w/ lop.com...

also, with this i can't assign a static ip to my cpu through linksys router, as well as use the DMZ host anymore (i think)...because i can't RECEIVE DATA, but could send a request to gateway...

if any of you know what i'm talking bout, saw/know a solution...please help, please reply.

thanks in advance.
 

stech4u

Member
Mar 21, 2002
187
0
0
oops...also forgot to say "used Ad-Aware, and no help"...any other suggestions--other than clean install of win2k (which i really don't want to do)
 

Jeff7

Lifer
Jan 4, 2001
41,596
20
81
Did you also use the Refupdate utility from Lavasoft for AdAware? It updates Adaware's database of spyware utilities.
I got something pretty nasty recently that put startup routines in multiple locations. Some utilities to help get rid of stuff:
Resource Manager
It lets you see what apps are running and terminate the spyware ones so that their program files can be deleted.

Some places to check for the program:
C:\windows\system.ini and win.ini
In the first few lines are groups of files that are executed on startup.

In the Registry:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Runonce
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce

Those are other places to check for software that is loaded at startup. The Startup folder on the Start Menu, and your Autoexec.bat file are other places to check.

Good luck with this; some of these :|programs:| are really tough to get rid of.