Greenguy's Board


Go Back   Greenguy's Board > General Business Knowledge
Register FAQ Calendar Today's Posts

Reply
 
Thread Tools Search this Thread Rate Thread Display Modes
Old 2005-12-26, 02:50 PM   #1
dareutwo
You can't disprove anything with evidence that doesn't exist
 
dareutwo's Avatar
 
Join Date: Mar 2003
Location: NW Minnesota - pop 865 +/- 1
Posts: 2,038
"adm.exe" spyware removal help needed

Ok, I'm baffled by this one.
This trojan basically makes whatever you click on become a search.
Ad Aware doesn't find it
Norton can't delete it.

(try reviewing - it doesn't work at all - so I'm dead in the water)

It's called adm.exe - I've deleted the folder and all the files, yet it continues to hijack my browser.
1.) How the hell do I get rid of this thing?
2.) How do I find out how I got it in the first place so I can blacklist them?

Any and all help Greatly Appreciated!!

And Happy Fucking Holidays!!!

__________________
This is me Mark's-Links

Last edited by dareutwo; 2005-12-26 at 02:54 PM..
dareutwo is offline   Reply With Quote
Old 2005-12-26, 02:57 PM   #2
MrMaryLou
i fucking told i type to fucking fast wtf
 
MrMaryLou's Avatar
 
Join Date: Mar 2003
Location: New York
Posts: 11,247
Send a message via ICQ to MrMaryLou
Try this http://www.safer-networking.org/en/index.html
__________________
<a href="http://www.greenguysboard.com/onthebench/">Join Me For On The Bench
</a>
MrMaryLou is offline   Reply With Quote
Old 2005-12-26, 03:00 PM   #3
HC-Majick
You can now put whatever you want in this space :)
 
HC-Majick's Avatar
 
Join Date: Oct 2004
Location: Upstate NY
Posts: 541
Send a message via ICQ to HC-Majick
yep, that one is a pain to get rid of. found this link; at the bottom of the page is a link..."click here to download scanner"
http://www.spywareremove.com/removeadmexe.html

maybe that will be of some help
__________________
Submit Your Freesites:
HC-Majick is offline   Reply With Quote
Old 2005-12-26, 03:00 PM   #4
quest
Trying is the first step towards failure
 
Join Date: Sep 2004
Location: North of the Motor City, MI.
Posts: 122
Send a message via ICQ to quest
HiJackthis may help clean out reg files.


Ben
quest is offline   Reply With Quote
Old 2005-12-26, 03:07 PM   #5
RedCherry
Of all the things I've lost, I miss my mind the most.
 
RedCherry's Avatar
 
Join Date: Apr 2004
Location: Middle of the Desert, Pahrump, NV
Posts: 3,187
Send a message via ICQ to RedCherry
MadHatter had his desktop hijacked by something (can't remember) and the only thing he found to that removed it was http://www.paretologic.com/products.aspx XSoftSpy. He went crazy, tried everything and couldn't get rid of it, but that did. You can run a free scan with it, or you can purchase it.

Good luck! Know how much a pain the butt that is.
RedCherry is offline   Reply With Quote
Old 2005-12-26, 03:11 PM   #6
MadMax
"Without evil there can be no good, so it must be good to be evil sometimes" ~ Satan
 
MadMax's Avatar
 
Join Date: Aug 2004
Location: Motor City, baby, where carjacking was invented! Now GIMME THOSE SHOES!
Posts: 2,385
if you're getting coolwebsearch you can use cwshredder.

Usually if norton can't remove something but CAN detect it then there's an active registry key. Write down the path to the trojan and reboot in safe mode so only critical keys are active, then use windows explorer to delete it. Also, if you aren't already using windows antispyware beta (free) you can give that a try...does a nice job of getting rid of stuff with active reg keys since its a MS product
MadMax is offline   Reply With Quote
Old 2005-12-26, 03:20 PM   #7
RawAlex
Took the hint.
 
Join Date: Mar 2003
Posts: 5,597
Send a message via AIM to RawAlex
http://www.iamnotageek.com/a/342-p1.php

That would appear to do it. You can do it all in safe mode with your network disconnected, and you have much more chance of it actually working out.

Alex
RawAlex is offline   Reply With Quote
Old 2005-12-26, 03:21 PM   #8
SirMoby
Jim? I heard he's a dirty pornographer.
 
SirMoby's Avatar
 
Join Date: Aug 2003
Location: Washington, DC
Posts: 2,706
The Microsoft tool works pretty well and when you think about, it's all thier holes so it should. You can always do a system restore
SirMoby is offline   Reply With Quote
Old 2005-12-26, 03:22 PM   #9
cosmiccat
You can't keep blaming yourself. Just blame yourself once, and move on
 
cosmiccat's Avatar
 
Join Date: Jun 2005
Location: Arizona
Posts: 351
Send a message via ICQ to cosmiccat
This page has a link that will remove it: http://process.networktechs.com/adm.exe.php

Good Luck.
__________________
Submit your galleries to Margo's Whorehouse
cosmiccat is offline   Reply With Quote
Old 2005-12-26, 09:33 PM   #10
MrYum
Arghhhh...submit yer sites ya ruddy swabs!
 
MrYum's Avatar
 
Join Date: May 2004
Location: Sunny Florida!
Posts: 5,108
Send a message via ICQ to MrYum
Lots of good advice already Dare so I'll just toss in another thumbs up for the MS product and say Good Luck!

Oh, and a suggestion to go to Firefox if you're not already using it
MrYum is offline   Reply With Quote
Old 2005-12-27, 01:27 AM   #11
dareutwo
You can't disprove anything with evidence that doesn't exist
 
dareutwo's Avatar
 
Join Date: Mar 2003
Location: NW Minnesota - pop 865 +/- 1
Posts: 2,038
A six pack, system restore a month back , a pack of smokes and 39.95 later...
Still no luck.

Thanks all for the suggestions though, I've tried them all.
As for firefox, I use it, but don't review with it. I want to see what they (90% of them) see.

This thing is a bastard.
Thinking it's time for a complete HD reformat. No biggy, all Real files are on a seperate HD.
__________________
This is me Mark's-Links

Last edited by dareutwo; 2005-12-27 at 01:33 AM..
dareutwo is offline   Reply With Quote
Old 2005-12-27, 05:58 AM   #12
SirMoby
Jim? I heard he's a dirty pornographer.
 
SirMoby's Avatar
 
Join Date: Aug 2003
Location: Washington, DC
Posts: 2,706
Something is fishy. I've never heard of system restore not solving such an issue before. I'm sure you've done the Google thing and found pages like this http://www.iamnotageek.com/a/342-p1.php

You may want to check and see what applications you're running. The terms for some shareware applications is that you install crap like this and they'll do it every time you load them.
SirMoby is offline   Reply With Quote
Old 2005-12-27, 06:17 AM   #13
CelticTiger
Are you sure this is the Sci-Fi Convention? It's full of nerds!
 
CelticTiger's Avatar
 
Join Date: Feb 2004
Location: Ireland
Posts: 266
Send a message via ICQ to CelticTiger
Quote:
Originally Posted by dareutwo
Thinking it's time for a complete HD reformat. No biggy, all Real files are on a seperate HD.
That sucks....I'm suprised none of the above worked for you. When I run into a tough one that I can't fix within a reasonable amount of time I find a reformat saves time and ones' sanity
CelticTiger is offline   Reply With Quote
Old 2005-12-27, 06:22 AM   #14
ClickBuster
I'm normally not a praying man, but if you're up there, please save me Superman!
 
ClickBuster's Avatar
 
Join Date: Dec 2004
Location: Bulgaria
Posts: 476
Send a message via ICQ to ClickBuster
OK, here're a few things I would do to.

1. I would log off and start Windows in Safe mode + Networking

2. Run regedit and check for strange things in:
HKLM > Software > Microsoft > Windows > Current Version > Run
HKLU > Software > Microsoft > Windows > Current Version > Run

3. Check C:\WINNT\win.ini for a [load] or run=something. If I see something like that pointing to a suspicious .exe I remove the line and try to delete the file

4. Go to C:\WINNT\system32\ and sort the files by date (newest on top) and delete all strange .exes and similar (things like asdzx123.exe usually)

5. Go to http://www.definitivesolutions.com/bhodemon.htm and download BHODemon - tricky simple tool that cleans/blocks IE toolbars - much better than any spyware out there, when it comes to hidden IE toolbars.

6. Go to http://www.pandasoftware.com/products/activescan.htm. On the right side you'll see "Free online virus scan". Use this to check your system, just in case.

If you think that you're ready to go, reboot the system in normal mode.

I hope this helps
__________________
The tendency is to push it as far as you can
-- Fear and Loathing In Las Vegas
ClickBuster is offline   Reply With Quote
Old 2005-12-27, 10:21 AM   #15
RawAlex
Took the hint.
 
Join Date: Mar 2003
Posts: 5,597
Send a message via AIM to RawAlex
System restore often gives viruses and scumware a place to hide (they know how to write themselves in there) so you may find that restore just makes it worse instead of better.

Alex
RawAlex is offline   Reply With Quote
Old 2005-12-27, 10:28 AM   #16
f69j69b
With $10,000, we'd be millionaires! We could buy all kinds of useful things like ... love!
 
f69j69b's Avatar
 
Join Date: Jan 2004
Location: colorado
Posts: 318
hi dareutwo
I had something like that once check your dns

Fred
__________________
https://furry-yiff.com/
f69j69b is offline   Reply With Quote
Old 2005-12-27, 11:05 AM   #17
plateman
What can I do - I was born this way LOL
 
plateman's Avatar
 
Join Date: Oct 2003
Location: ohio
Posts: 3,086
mostly when trying to get rid of these things you gotta prep for it first..

turn off system restore, start in safe mode and run about 6 or so programs...

dareutwo the way I figured some of it out was after I ran hijackthis and I read the log, anything that looked like it shouldn't be there I would google it.. also I found a site that told you what most .exe and dll were and if they were scum or not... another good program is ewido,

another thing you probably know is that once you get infected with spyware and tojens there are very good spyware sites out there that has steps to follow to get rid of the shit...

like my last bout with the stuff I had I completely got rid of the shit, but a few days later I noticed when going on certain sites I would get redirected, so I did some research and didnt find anything, so I ran everything again and reread my hijack log and found some strange ip's in it.. and when I checked were the ip's were from I knew it was crap and I deleted them and never again had anymore redirects, and no spyware program would take that stuff out...
__________________
Submit to: Porn O Plenty XXX Links
Reality Here
plateman is offline   Reply With Quote
Old 2005-12-27, 01:19 PM   #18
dareutwo
You can't disprove anything with evidence that doesn't exist
 
dareutwo's Avatar
 
Join Date: Mar 2003
Location: NW Minnesota - pop 865 +/- 1
Posts: 2,038
Update on this one.
Thanks for all the info and links!!!!
Well, it's not completely gone, Raw Alex was correct it simply changed names and went missing again.
Anyway, with the addition of the 3 new programs, they have found and deleted most of the crap. My comp is running a lot faster. I thought I had decent protection before, but now I know I do.

Whatever the big one was, it's apparently gone, as I'm able to review again.
Planning on getting new comp in Feb, so for now, I'll just leave this one alone. I get the new one, transfer stuff over, then reformat the HD's and give it to one of the kids. That'll take care of it for sure.

Thanks again for all your help and recommendations!

Happy New Year in advance!
__________________
This is me Mark's-Links
dareutwo is offline   Reply With Quote
Old 2005-12-27, 02:14 PM   #19
Mattinblack
Asleep at the switch? I wasn't asleep, I was drunk
 
Join Date: Nov 2005
Location: London UK in a house share with three 28 yr old girls...perv perv
Posts: 215
Quote:
Originally Posted by SirMoby
Something is fishy. I've never heard of system restore not solving such an issue before. I'm sure you've done the Google thing and found pages like this http://www.iamnotageek.com/a/342-p1.php

You may want to check and see what applications you're running. The terms for some shareware applications is that you install crap like this and they'll do it every time you load them.
Too true but there is actually quite a lot of things system restore wont fix because you can mark things to be 'restore proof' ... PSguard and Searchextender being a case in point. It took me six weeks to get rid of em! There are also (mercifully few) programs that mod your restore configuration so that they are re-installed by system restore when it restores which is why microsoft spyware now scans all your restore data in its latest incarnation. Its also good to be aware of the black-hat anti spywares out there (like PSguard!) which remove other folks spyware and install their own which keeps telling you that you need to download various paid for anti spyware programs...! My solution is that I run two laptops that I synchronise every week. I just swap over when I hit problems. All my sites are on a half-gig memory stick.
__________________
Mattinblack - <a href="http://pornlinks.kwikfire.com">PornLinks</a> - <a href="http://strange-attractor.kwikfire.com">Strange Attractor</a> - <a href="pnav.kwikfire.com">PORNavigator</a> - <a href="http://ukescort.kwikfire.com/">Fem Escorts</a> - <a href="http://kwikfire.com/">Hosting</a>
Mattinblack is offline   Reply With Quote
Old 2005-12-28, 03:53 AM   #20
Surfn
If you don’t take a chance the Angels won’t dance
 
Surfn's Avatar
 
Join Date: Aug 2003
Location: Earth on occasion
Posts: 8,812
Send a message via ICQ to Surfn
I just got rid of some piece of scum ware that started slowing down internet connection yesterday morning and by last evening it was slower than my old 1200 connection. I did finally kill the sucker |slice
__________________

Surfn's Links Are you a partner?

Surfn is offline   Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -4. The time now is 03:02 PM.


Mark Read
Powered by vBulletin® Version 3.8.1
Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.
© Greenguy Marketing Inc