# I'm having a nasty spyware problem. Yes, I read the sticky.

**URL:** <https://boards.straightdope.com/t/im-having-a-nasty-spyware-problem-yes-i-read-the-sticky/287458>\
**Category:** Factual Questions\
**Created:** [January 30, 2005, 6:45pm UTC](https://boards.straightdope.com/t/im-having-a-nasty-spyware-problem-yes-i-read-the-sticky/287458 "2005-01-30T18:45:59Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Dark\_Side\_of\_the\_Floyd](https://avatars.discourse-cdn.com/v4/letter/d/bb73d2/32.png) [@Dark\_Side\_of\_the\_Floyd](https://boards.straightdope.com/u/Dark_Side_of_the_Floyd)\
**Post date:** [January 30, 2005, 6:45pm UTC](https://boards.straightdope.com/t/im-having-a-nasty-spyware-problem-yes-i-read-the-sticky/287458/1 "2005-01-30T18:45:59Z")

</div>

I seem to have encountered a nasty bit of spyware which slows down my machine and gives me annoying popups.

I am running a machine with Windows XP.

Looking through my processes list, I see:

aolwbspd.exe  
winamp.exe (listening to music)  
taskmgr.exe  
waol.exe  
aoltray.exe  
BARGAINS.EXE  
ISTSVC.EXE  
E\_S4I2D1. EXE  
FMJTGFM.EXE  
winampa.exe  
aol.exe  
EXPLORER.EXE  
WANMPSVC.EXE  
WDFMGR.EXE  
SVCHOST.EXE  
aim.exe  
SPOOLSV.EXE  
SVCHOST.EXE  
SVCHOST.EXE  
SVCHOST.EXE  
SVCHOST.EXE (Yes, it repeats)  
LSASS.EXE  
SERVICES.EXE  
WINLOGON.EXE  
CSRSS.EXE  
SMSS.EXE  
WUAUCLT.EXE  
System  
System Idle Process

I also have problems with ShopAtHome.

I repeat, I HAVE looked at the sticky, and ran Spybot and Ad-Aware 6, but it doesn’t seem to be getting rid of it.

My main concern is that this slows down my computer significantly and… well… just drives me batshit.

---

<div class="post-metadata">

**Author:** ![ParentalAdvisory](https://avatars.discourse-cdn.com/v4/letter/p/53a042/32.png) [@ParentalAdvisory](https://boards.straightdope.com/u/ParentalAdvisory)\
**Post date:** [January 30, 2005, 6:58pm UTC](https://boards.straightdope.com/t/im-having-a-nasty-spyware-problem-yes-i-read-the-sticky/287458/2 "2005-01-30T18:58:23Z")

</div>

> [@DarkSideoftheFloyd](#):
>
> BARGAINS.EXE

This one is suspect #1. CTRL+ALT+DEL, right click it and end the task. Do a search on the C drive for ‘BARGAINS.EXE’ (or other drives, most likely the C drive though), and delete it, as well as it’s root folder (ex: C:\Programs Files\Bargain\_crap\BARGAINS.EXE), the root folder being ‘Bargain\_crap’ in this example. If this doesn’t work, do the same thing in Safe Mode.

---

<div class="post-metadata">

**Author:** ![Daizy](https://avatars.discourse-cdn.com/v4/letter/d/46a35a/32.png) [@Daizy](https://boards.straightdope.com/u/Daizy)\
**Post date:** [January 30, 2005, 7:14pm UTC](https://boards.straightdope.com/t/im-having-a-nasty-spyware-problem-yes-i-read-the-sticky/287458/3 "2005-01-30T19:14:39Z")

</div>

When you say you’ve ran Spybot and Adaware…  
Have you downloaded and ran the current versions, as well as updated them before you ran them?  
[Adaware SE](http://www.download.com/3000-2144-10045910.html?part=69274&subj=dlpage&tag=button)  
[Spybot - Search & Destroy 1.3](http://www.download.com/Spybot-Search-Destroy/3000-8022_4-10289035.html?tag=lst-0-2)

---

<div class="post-metadata">

**Author:** ![Ponster](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/ponster/32/17081_2.png) [@Ponster](https://boards.straightdope.com/u/Ponster)\
**Post date:** [January 30, 2005, 7:30pm UTC](https://boards.straightdope.com/t/im-having-a-nasty-spyware-problem-yes-i-read-the-sticky/287458/4 "2005-01-30T19:30:37Z")

</div>

[This Page](http://www.cco.caltech.edu/~alex/pub/CashBack.htm) explains how to get rid of bargains.exe

---

<div class="post-metadata">

**Author:** ![Airman\_Doors\_USAF](https://avatars.discourse-cdn.com/v4/letter/a/e36b37/32.png) [@Airman\_Doors\_USAF](https://boards.straightdope.com/u/Airman_Doors_USAF)\
**Post date:** [January 30, 2005, 7:45pm UTC](https://boards.straightdope.com/t/im-having-a-nasty-spyware-problem-yes-i-read-the-sticky/287458/5 "2005-01-30T19:45:33Z")

</div>

You could try downloading Hijack This! and posting the list here for someone more knowledgeable than I to look at. Remember, though, if you use that program and delete everything you’re screwed, so be careful.

---

<div class="post-metadata">

**Author:** ![alterego](https://avatars.discourse-cdn.com/v4/letter/a/6bbea6/32.png) [@alterego](https://boards.straightdope.com/u/alterego)\
**Post date:** [January 30, 2005, 7:51pm UTC](https://boards.straightdope.com/t/im-having-a-nasty-spyware-problem-yes-i-read-the-sticky/287458/6 "2005-01-30T19:51:23Z")

</div>

> [@](#):
>
> This one is suspect #1. CTRL+ALT+DEL, right click it and end the task. Do a search on the C drive for ‘BARGAINS.EXE’ (or other drives, most likely the C drive though), and delete it, as well as it’s root folder (ex: C:\Programs Files\Bargain\_crap\BARGAINS.EXE), the root folder being ‘Bargain\_crap’ in this example. If this doesn’t work, do the same thing in Safe Mode.

If you’re going to do it manually, this alone is not enough to stop it. You’ll need to search youre registry and delete all of those references as well at the least (start \> run \> regedit \> ctrl +f). I’ve successfully helped a lot of dopers get rid of nasty bugs here; in the sticky I specifically recommend NOT immediately ending a suspect program listed in your task manager.

A much better solution is to (and this is only if the spyware/adware/antivirus utilities aren’t cleaning it) download the [sysinternals process explorer](http://www.sysinternals.com/ntw2k/freeware/procexp.shtml) and [file monitor](http://www.sysinternals.com/ntw2k/source/filemon.shtml).

Run the process explorer; it gives you _complete_ control over all aspects of any running process, including immediate annihilation, or, what we are concerned with which is suspending the process. That means it is forbidden to use any resources and can only sit there, effectively paralyzed. This is much more useful to us than closing it.

If you right click on the process and choose properties you can learn some very interesting things about it, such as its path, its command line start switches, its current working directory, its threads (eg whats it been doing lately?), legible strings of text contained within the process, which can help identify it, and a lot more.

So you do that, and you jot that stuff down. After that, while its still suspended, you open up file monitor. Basically this is a real time file monitor; it shows you what sort of hard drive activity each program is engaged in as it happens. So you open this up, “resume” your spyware/adware/virus, and watch it for a second to find out just what exactly its doing and where its doing it. After your done spying on the little bastard go ahead and nuke him. Finally, proceed with your cleanup, using all this information you’ve gathered to be more effective.

---

<div class="post-metadata">

**Author:** ![ParentalAdvisory](https://avatars.discourse-cdn.com/v4/letter/p/53a042/32.png) [@ParentalAdvisory](https://boards.straightdope.com/u/ParentalAdvisory)\
**Post date:** [January 30, 2005, 10:39pm UTC](https://boards.straightdope.com/t/im-having-a-nasty-spyware-problem-yes-i-read-the-sticky/287458/7 "2005-01-30T22:39:24Z")

</div>

> [@Ponster](#):
>
> [This Page](http://www.cco.caltech.edu/~alex/pub/CashBack.htm) explains how to get rid of bargains.exe

This only explains removing the registry keys from the ‘run’ folder in the registry. But nothing about removing it from your hard drive. Still very informative. I would suggest doing this, and then deleting the actual files from the harddrive.

> [@alterego](#):
>
> …this alone is not enough to stop it.

I’m pretty sure that it would though. The worst case scenaro is that the ‘run’ portion of the registy would have caused a ‘BARGAINS.EXE not found’ error on startup, because the file was already deleted. My fault for not mentioning the registry edit though. Just remove the keys, from **Ponsters’** link.
