Back to Forums








View Full Version : can't find adware


ilyail3
August 25th, 2005, 11:50 AM
I have some adware probably a process which sends me popups
ad-aware can't find it. this is my prosses list
http://www.freewebs.com/ilyail3/process%20list.JPG
what's here suspicious

lankan_man
August 25th, 2005, 16:16 PM
i'd have 2 go with UAService7.exe, that souds pretty suspicious for me , [b]BUT[b/] u should get the final answer by the pros of this for, example. BB, Rev, conan, Egg, Rik, FG, phish, and all the TZ veterans, and if there is some pros i forgot to mension, "beside me :D" J/K, then post away!!!
________________________________

Og and ilyail, why dun u try sum other ad-ware????
it may work

ilyail3
August 25th, 2005, 17:41 PM
I was able to find those spywares thorugh norton antivirus but it couldn't delete them. what's the use in trying to delet them while they work?
can you reccomand a good bootable antivirus?

FastGame
August 25th, 2005, 18:30 PM
Don't you have MS antispy ? http://www.techzonez.com/forums/showthread.php?t=15559

Use this online scanner ewido (http://www.ewido.net/en/onlinescan/) and this one Kaspersky (http://www.kaspersky.com/downloads/kws/kavwebscan.html) along with MS antispy and this should help a bunch.

Bookmark the scanners and use them :)

ilyail3
August 27th, 2005, 18:42 PM
I used it and it deleted all my adwares however I still got a problem!
when I log in I get a file not found massage of one of the spyware's dll file
what can I do about it?

Curio
August 29th, 2005, 21:32 PM
UAService7.exe is something to do with securom game copy protection.
You should use HijackThis to provide a list of relevant data, but however as you appear to have fixed all that guff you now need to prevent the dll from attempting to load. Use regseeker to locate all instances of the dllname in the registry and remove them. - Be sure first that you have the right dll!!

egghead
August 29th, 2005, 22:25 PM
anyone know what the RunDll32.exe is?

not sure if i ever seen it capitallized like that

Curio
August 30th, 2005, 18:50 PM
Seems odd for sure. One old hacker trick is to use similar characters like 1s or Is instead of ls but I think the process name being capitalised like that is only because the process was launched from a registry entry that is written that way. It sure looks like the right letters.