Re: Microsoft is running a disreputable spyware outfit
From: David H. Lipman (DLipman~nospam~_at_Verizon.Net)
Date: 10/31/05
- Next message: Wooly: "Re: Microsoft is running a disreputable spyware outfit"
- Previous message: Frank Saunders, MS-MVP OE: "Re: Microsoft is running a disreputable spyware outfit"
- In reply to: Susan Sharm: "Microsoft is running a disreputable spyware outfit"
- Next in thread: Wooly: "Re: Microsoft is running a disreputable spyware outfit"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: Mon, 31 Oct 2005 08:07:11 -0500
From: "Susan Sharm" <susanshaarm@yahoo.com>
| By logging into hotmail on a new system I found out that Microsoft is
| running a disreputable spyware program which pops up targeted adware on
| your Windows PC some time AFTER you view web pages. HOW DO WE PREVENT
| MICROSOFT FROM INFECTING OUR PC?
|
| On a brand new PC, I noticed that EVERY time I visit a hotmail page the
| message comes up (which I cancel every time):
| ---------------------------------------
| Opening ADSAdClient31.dll
| You have chosen to open
| ADSAdClient31.dll
| which is a: Application Extension
| from http://rad.msn.com
|
| What should Netscape do with this file?
| (x) Open with dllfile (default)
| ( ) Save to Disk
| ----------------------------------------
| I googled and found that this is a well-known Microsoft Ad Server
| spyware advertising client dynamic linked library
| (http://www.kuro5hin.org/story/2001/8/17/11541/1217)
| but I did not find how to PREVENT it from installing! Apparently this
| program pops up ads AFTER you view the web page! So it's a prime cause
| of pop-up annoyances and is a known spyware program from Microsoft.
|
| I tried putting 127.0.0.1 rad.msn.com into my hosts file but I STILL
| get this annoying Microsoft Advertising Delivery Service dll download
| attempt (which I cancel every time) when I visit any hotmail web page.
|
| Someone out there must be an anti-spyware expert who can tell us how to
| ELIMINATE the chance of this Microsoft-built adware/spyware?
|
| PLEASE! If you are a Windows expert, you'll know how to stop this
| program!
|
| Thank you in advance,
| Susan Sharm
For non-viral malware...
Please download, install and update the following software...
Ad-aware SE v1.06
http://www.lavasoft.de/
http://www.lavasoftusa.com/
SpyBot Search and Destroy v1.4
http://security.kolla.de/
After the software is updated, I suggest scanning the system in Safe Mode.
I also suggest downloading, installing and updating BHODemon for any Browser Helper Objects
that may be on the PC.
BHODemon
http://www.definitivesolutions.com/bhodemon.htm
For viral malware...
Download MULTI_AV.EXE from the URL --
http://www.ik-cs.com/programs/virtools/Multi_AV.exe
It is a self-extracting ZIP file that contains the Kixtart Script Interpreter {
http://kixtart.org Kixtart is CareWare } 4 batch files, 6 Kixtart scripts, one Link
(.LNK) file, a PDF instruction file and two utilities; UNZIP.EXE and WGET.EXE. It will
simplify the process of using; Sophos, Trend, Kaspersky and McAfee Anti Virus Command
Line Scanners to remove viruses, Trojans and various other malware.
C:\AV-CLS\StartMenu.BAT -- { or Double-click on 'Start Menu' in C:\AV-CLS}
This will bring up the initial menu of choices and should be executed in Normal Mode.
This way all the components can be downloaded from each AV vendor's web site.
The choices are; Sophos, Trend, McAfee, Kaspersky, Exit this menu and Reboot the PC.
You can choose to go to each menu item and just download the needed files or you can
download the files and perform a scan in Normal Mode. Once you have downloaded the files
needed for each scanner you want to use, you should reboot the PC into Safe Mode [F8 key
during boot] and re-run the menu again and choose which scanner you want to run in Safe
Mode. It is suggested to run the scanners in both Safe Mode and Normal Mode.
When the menu is displayed hitting 'H' or 'h' will bring up a more comprehensive PDF help
file.
To use this utility, perform the following...
Execute; Multi_AV.exe { Note: You must use the default folder C:\AV-CLS }
Choose; Unzip
Choose; Close
Execute; C:\AV-CLS\StartMenu.BAT
{ or Double-click on 'Start Menu' in C:\AV-CLS }
NOTE: You may have to disable your software FireWall or allow WGET.EXE to go through your
FireWall to allow it to download the needed AV vendor related files.
* * * Please report back your results * * *
-- Dave http://www.claymania.com/removal-trojan-adware.html http://www.ik-cs.com/got-a-virus.htm
- Next message: Wooly: "Re: Microsoft is running a disreputable spyware outfit"
- Previous message: Frank Saunders, MS-MVP OE: "Re: Microsoft is running a disreputable spyware outfit"
- In reply to: Susan Sharm: "Microsoft is running a disreputable spyware outfit"
- Next in thread: Wooly: "Re: Microsoft is running a disreputable spyware outfit"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|