Home  |  Forums  |  914 Info  |  Blogs
 
914World.com - The fastest growing online 914 community!
 
Porsche, and the Porsche crest are registered trademarks of Dr. Ing. h.c. F. Porsche AG. This site is not affiliated with Porsche in any way.
Its only purpose is to provide an online forum for car enthusiasts. All other trademarks are property of their respective owners.
 

Welcome Guest ( Log In | Register )

> OT: CleverieHooker - spyware crap, How to remove???
Qarl
post May 26 2004, 04:03 PM
Post #1


Shriveled member
*****

Group: Benefactors
Posts: 5,233
Joined: 8-February 03
From: Florida
Member No.: 271
Region Association: None



One of my employees has some spyware crap called Cleveriehooker

Spybot deletes and fixes it, but every time you reboot, it reloads.

I immunized it with the latest version of Spybot (version 1.3), but it still comes up.

Anyone know how to get rid of this POS spyware?

Thanks.
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
2 Pages V  1 2 >  
Reply to this topicStart new topic
Replies(1 - 19)
Joe Bob
post May 26 2004, 04:07 PM
Post #2


Retired admin, banned a few times
***************

Group: Members
Posts: 17,427
Joined: 24-December 02
From: Boulder CO
Member No.: 5
Region Association: None



Tried Spysweeper?

www.webroot.com

PM me if you want a way to download it free....
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
tat2dphreak
post May 26 2004, 04:15 PM
Post #3


stoya, stoya, stoya
*****

Group: Benefactors
Posts: 8,797
Joined: 6-June 03
From: Wylie, TX
Member No.: 792
Region Association: Southwest Region



search out all references to it in your registry... it probably has an install proram that runs when you start your computer, try using "system information" first and uncheck the box for it, if that doesn't work use a program like "Registrar lite" (lite is the free version and does everything I can think of it wanting to...
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
p914
post May 26 2004, 04:17 PM
Post #4


Senior Member
***

Group: Members
Posts: 518
Joined: 7-September 03
From: Sunny South Florida
Member No.: 1,117
Region Association: None



Couple ideas.
Go to control panel and use add/remove programs.
or
go to the website for it and find an uninstall program.
or
use windows explorer and find it in the programs section and possibly find an uninstall there or delete the entire folder with all it's components. It may have planted a root in the registry which will only be deleted when an uninstall is done.

these things can be pesky basturds but there are ways to get rid of em.
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
SirAndy
post May 26 2004, 04:18 PM
Post #5


Resident German
*************************

Group: Admin
Posts: 41,669
Joined: 21-January 03
From: Oakland, Kalifornia
Member No.: 179
Region Association: Northern California



Manual Removal:

Unregister these DLLs with Regsvr32:
systemroot+\jeired.dll
systemroot+\system32\jeired.dll
systemroot+\system32\tvmbho.dll
systemroot+\system\jeired.dll
systemroot+\system\tvmbho.dll

Remove these registry items (if present) with RegEdit:
HKEY_CLASSES_ROOT\clsid\{707e6f76-9ffb-4920-a976-ea101271bc25}
HKEY_CLASSES_ROOT\interface\{707e6f76-9ffb-4920-a976-ea101271bc25}
HKEY_CLASSES_ROOT\software\microsoft\windows\currentversion\explorer\browser helper objects\{707e6f76-9ffb-4920-a976-ea101271bc25}
HKEY_CLASSES_ROOT\typelib\{707e6f76-9ffb-4920-a976-ea101271bc25}
HKEY_LOCAL_MACHINE\clsid\{707e6f76-9ffb-4920-a976-ea101271bc25}
HKEY_LOCAL_MACHINE\software\classes\clsid\{707e6f76-9ffb-4920-a976-ea101271bc25}
HKEY_LOCAL_MACHINE\software\classes\typelib\{707e6f76-9ffb-4920-a976-ea101271bc25}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{707e6f76-9ffb-4920-a976-ea101271bc25}

Remove these files (if present) with Windows Explorer:
systemroot+\jeired.dll
systemroot+\system32\jeired.dll
systemroot+\system32\tvmbho.dll
systemroot+\system\jeired.dll
systemroot+\system\tvmbho.dll


got this info from here:
http://www.pestpatrol.com/PestInfo/c/cleve...veriehooker.asp

as always, no guarantees, don't blame me if it doesn't work! (IMG:style_emoticons/default/wink.gif)
Andy
User is online!Profile CardPM
Go to the top of the page
+Quote Post
TimT
post May 26 2004, 04:34 PM
Post #6


retired
****

Group: Members
Posts: 4,033
Joined: 18-February 03
From: Wantagh, NY
Member No.: 313



disable system restore!!!!!

then do as Andy says...

System restore is the virus writers best pal...

One of the best ways I know to remove a virus or worm, is to find it location, write down the path....

then boot in DOS and do a DEL on it..

after that you can clean up the registry

just turn off system restore
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
Part Pricer
post May 26 2004, 05:31 PM
Post #7


Believe everything I post
***

Group: Benefactors
Posts: 1,825
Joined: 28-December 02
From: Danbury, CT
Member No.: 35



Ok. It's a real prick that involves a multistep process to get rid of. You'll need these tools:

CWShredder

AdAware 6 Build 181

HijackThis


Download all of these files first. After you have downloaded them, DO NOT open Internet Explorer.

Run CWShredder and have it fix verything it finds.

Run AdAware. Have it download the latest reference file. Then have it scan your system and remove everything it finds.

Run HiJack this. If it shows any Browser Helper Objects (BHOs), remove them. This may remove some things that you wanted, but you can reinstall them later.

Go to your C: drive and remove the TVMedia folder if it exists. (It may be under Progam Files)

Run msconfig. Have the system boot in Diagnostic Startup mode. Reboot.

As the system reboots, don't allow it to run any programs.

Search your system for loader.exe. Delete this cocksucker.

Run msconfig. Have the system boot in Normal mode. Reboot.

Cross your fingers and pray that you got everything.
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
TheCabinetmaker
post May 26 2004, 05:55 PM
Post #8


I drive my car everyday
*****

Group: Members
Posts: 8,301
Joined: 8-May 03
From: Tulsa, Ok.
Member No.: 666



Damn Paul, even I understood that. (IMG:style_emoticons/default/wacko.gif)
User is online!Profile CardPM
Go to the top of the page
+Quote Post
nebreitling
post May 26 2004, 06:05 PM
Post #9


Member Emeritus
****

Group: Members
Posts: 3,314
Joined: 26-March 03
From: San Francisco
Member No.: 478



get a mac. (IMG:style_emoticons/default/wink.gif)
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
Part Pricer
post May 27 2004, 04:51 AM
Post #10


Believe everything I post
***

Group: Benefactors
Posts: 1,825
Joined: 28-December 02
From: Danbury, CT
Member No.: 35



Here is a great step-by-step way to help safeguard your system.

Prevent Browser Hijacking

All of the tools that they list are free for the home user. So, there is no reason why you should not protect your PC.

The people that run spywareinfo.com are the "good guys". I've been hanging out there a lot lately and they've been a great help.
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
lagunero
post May 27 2004, 11:23 AM
Post #11


Donkey Member
***

Group: Benefactors
Posts: 1,042
Joined: 8-January 04
From: orange county,ca
Member No.: 1,531



QUOTE(nebreitling @ May 26 2004, 05:05 PM)

(IMG:style_emoticons/default/laugh.gif) (IMG:style_emoticons/default/laugh.gif)
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
thesey914
post May 27 2004, 03:45 PM
Post #12


Senior Member
***

Group: Benefactors
Posts: 1,155
Joined: 1-January 03
From: Staffordshire -England
Member No.: 66



QUOTE(kellzey @ May 26 2004, 02:03 PM)
One of my employees .......

yeah right... (IMG:style_emoticons/default/wink.gif) (IMG:style_emoticons/default/biggrin.gif)
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
Qarl
post May 28 2004, 09:43 AM
Post #13


Shriveled member
*****

Group: Benefactors
Posts: 5,233
Joined: 8-February 03
From: Florida
Member No.: 271
Region Association: None



Thanks Paul.

Your step-by-step instructions worked. I had to do it twice. One of the difficulties was deleting the TVMedia folder. When you run HijackThis, you also have to delete the HKLMs that reference the TVMedia folder.

Then you can delete TVMedia.

And yes, it WAS one of my employees that did this. I am smarter than this. Needless to say, he knows I am pissed for wasting 3 hours of my time fixing his mess.
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
Part Pricer
post May 28 2004, 10:38 AM
Post #14


Believe everything I post
***

Group: Benefactors
Posts: 1,825
Joined: 28-December 02
From: Danbury, CT
Member No.: 35



QUOTE(kellzey @ May 28 2004, 10:43 AM)
you also have to delete the HKLMs that reference the TVMedia folder.

...wasting 3 hours of my time fixing his mess.

Sorry about that. I knew there was something I forgot.

Three hours to fix it is actually not too bad for your first time. With all of the rebooting and other nonsense that is involved to get rid of this crap, it normally takes at least two hours.

Get a Mac? No thanks. They are less prone to infection. But, you've never been to hell until you have to fix an infected Mac.
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
fiid
post May 28 2004, 11:20 AM
Post #15


Turbo Megasquirted Subaru Member
****

Group: Members
Posts: 2,827
Joined: 7-April 03
From: San Francisco, CA
Member No.: 530
Region Association: Northern California



QUOTE(nebreitling @ May 26 2004, 04:05 PM)

I was just going to say exactly that! I switched a couple of months ago and haven't looked back. The only thing I don't have on the mac is very much in the way of CAD, but I don't use it much anywany - so I'm not crying.

(IMG:style_emoticons/default/smilie_pokal.gif)

l8r,

Fiid.
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
fiid
post May 28 2004, 11:21 AM
Post #16


Turbo Megasquirted Subaru Member
****

Group: Members
Posts: 2,827
Joined: 7-April 03
From: San Francisco, CA
Member No.: 530
Region Association: Northern California



Hey Quarl - off topic - when is your Elise supposed to show up??

Fiid.
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
Qarl
post May 28 2004, 12:25 PM
Post #17


Shriveled member
*****

Group: Benefactors
Posts: 5,233
Joined: 8-February 03
From: Florida
Member No.: 271
Region Association: None



Elise's are supposed to hit the dealers next month (demo cars). It was supposed to be last week, but there are several parts holding up production.

I am #23 at my dealer. I've already placed my order for colr, interior, and options, but realistically, it will be the end of the year before I see it. I am hoping October or November.

The disinfection procedure Paul gave me only took about 30 minutes to do, it was the 2 1/2 hours I wasted before that trying to figure out how to remove that... (how did Paul so eloquently put it)... uhh... cocksucker! (Been watching a little too much Deadwood on HBO?)

Thanks again!
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
Part Pricer
post May 28 2004, 12:58 PM
Post #18


Believe everything I post
***

Group: Benefactors
Posts: 1,825
Joined: 28-December 02
From: Danbury, CT
Member No.: 35



QUOTE
Been watching a little too much Deadwood on HBO?


Deadwood has quickly become my favorite show. Last week's conversation between Swearengen and Wu was one of the funniest things I've seen on TV in a long time. (IMG:style_emoticons/default/laugh.gif)
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
Qarl
post May 28 2004, 01:13 PM
Post #19


Shriveled member
*****

Group: Benefactors
Posts: 5,233
Joined: 8-February 03
From: Florida
Member No.: 271
Region Association: None



At the meat locker?
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
Part Pricer
post May 28 2004, 01:17 PM
Post #20


Believe everything I post
***

Group: Benefactors
Posts: 1,825
Joined: 28-December 02
From: Danbury, CT
Member No.: 35



No. Earlier on at the Gem where Wu was trying to explain to Swearengen what had happened by drawing pictures and using the only English word that he knew.

“Glad I taught you that fuckin' word.” —Swearengen, realizing that "cocksucker" wasn't the best word to teach Wu.
User is offlineProfile CardPM
Go to the top of the page
+Quote Post

2 Pages V  1 2 >
Reply to this topicStart new topic
1 User(s) are reading this topic (1 Guests and 0 Anonymous Users)
0 Members:

 



- Lo-Fi Version Time is now: 1st June 2024 - 06:27 PM