Man, oh man, curse you Ad people foistering your ad bots and pop ups on us! Curse you!
I received a file form my brother this morning, and me being the idiot that I am downloaded it. If you got the message you would think that it is some sort of profile you would put up on you Myspace or whatever. In the file name itself it has your hotmail addy if you use MSN.
Next thing I know i have all these pop ups and crap, I do an Ad Aware scan and find a process running on my machine now called Softomate. Curse you Softomate! And along with this it lets in all its friends to wreck havok on your machine. Not cool.
Watch out for these things, they are bad news and can steal you credit card numbers passwords etc :
1)SVCHOSTS.exe, you do have svchost.exe which is legit, but when it is pluralized then you should take notice.
2)CmDService.exe, this thing can run a command to install stuff in the bg while you arent watching.
3)Tc5.exe, I saw this as well whereas I have never seen it before today.
Needless to say i start purusing the net for answers but this program is so vicious that if you even look for stuff about how to remove it, it immediately shuts down you IE and wont let you go there. i also wouldnt let me go to the Zonelabs site to download a firewall either, what a beeyotch.
Eventually I found a site that seemed to be familiar with this sort of stuff, and I am telling you to go there and ask them if you have a problem, they were really good and fast on the reply.
BLEEPINGCOMPUTER.com, go there if you have these sort of problems.
So by going into safe mode and downloading some simple software they ask you to do, I was able to go into safe mode and kill this beeyotch. Booyah, gratifying to say the least.
Thank God it's over.
Not wanting to have a repeat performance of this schizzle, I quickly downloaded the basic package from Zonelabs and installed it sans problem. Now if those Effers want to get in they can't, because i have this beeyotch on lock down, so step off Softo-Ass.
Victory at last!
Thank you for visiting