January 29, 2004
Viruses, Spyware, & Such
I've been sick the last couple of days, so I've been using the extra time at home to continue my quest to clean up my computer.
I found something interesting with the online virus scanners that Venomous Kate had on her site. I used the House Call scanner, and while it did not find any viruses, it did find another malware program that both AdAware and SpyBot missed JS_FORTNIGHT. I also found (I think) another malware program that was making my system absolutely unstable tatss.exe. This thing was opening Internet Explorer sessions independently. It also was consuming resources until the system would finally get to a point where you could not use the Start Menu for anything - including shutting down. Again, nothing was catching it.
I also went and downloaded a registry checker from Cnet.com and downloaded TuneUp Utilities 2003, which ended up finding almost 1000 invalid registry entries - along with bringing to my attention three other spyware and malware programs that I wasn't finding any other way.
This adventure in computer cleaning is absolutely eye-opening. All it took was one trip to the wrong website and over a month later I'm still trying to clean it up, while still keeping out the new additions.
I've worked my way down to one more program that I can't track down and that doesn't show up in Google searches. Whatever it is works similarly to tatss.exe opening webistes without my input. It goes specifically to http://69.20.62.53/yyy(x).html where the (x) is a number between one and five. Whatever is doing this is my last, great obsession. I have to figure out how to get it removed. I know that it is hosted by a hosting company called Rackspace out of San Antonio, but that doesn't exactly do a whole lot to help me eliminate the auto-open feature.
UPDATE:
It looks like the last program was (fingers and toes are still crossed!) Look2me which attaches itself as a subprocess of Explorer (not Internet Explorer) which makes it almost impossible to remove. SpyBot and AdAware have both told me that they removed it in the past, but apparently it didn't work. Follow the instructions found here if you find that this abomination is torturing you also.
Posted by Chris at January 29, 2004 11:33 AM | TrackBack | Linked by:Comments have been closed on this entry in an effort to conserve disk space. If you have feedback on this entry, please email me at blog - at - cbnoble.com.


