Recently I went away from my computer for a couple hours and when I came back there were a bunch of im windows open with comments that suggested I had sent them a hyperlink.

Well, I didn't. I'll post the hyperink in this thread if it will help later. I have Peer Gaurdian on, I've scanned with the latest Norton AV, I've scanned with Adaware, I even upgraded to AIM 5.5. Plus I got some crazy file called the cwshredder from a friend of a friend who said he had a similar problem, but even that did not work.

Any suggestions on how to detect this if it is a file on my comp, or what to do if it is a hacker with like an AIM bot or something?

[P.S. i am still sending these links apparently]

Oh, also I went to the windows update page and still nothing.
Windows XP

Dani AI

Generated

The pattern described by @steosaur(oWn — unexpected IM windows containing links and a program that comes back after removal) fits a common IM-distributed adware/backdoor design: a visible helper gets removed but a hidden persistence component (startup entry, service or scheduled task) keeps reinstalling or respawning it. The visible uninstaller often removes only the front‑end while a smaller watchdog or installer remains.

Recommended steps to identify and remove the hidden piece:

  • Isolate the machine from the network (unplug or disable networking) to stop outgoing messages and prevent further downloads.
  • Change IM and any reused passwords from a known-clean device; assume credentials may be compromised.
  • Boot the PC to Safe Mode and run a full offline scan with a current anti‑malware tool.
  • Use Sysinternals Autoruns to inspect all startup locations and disable suspicious entries. Check HKLM\Software\Microsoft\Windows\CurrentVersion\Run, HKCU\Software\Microsoft\Windows\CurrentVersion\Run, the Startup folder, Services and Scheduled Tasks.
  • Use Process Explorer to find running processes and note file paths; remove or disable companion services / scheduled tasks before deleting files on disk.
  • Delete or clear System Restore snapshots (malware can hide in restore points), then create a fresh restore point after cleanup.
  • If the program reappears despite these steps, back up personal files (scan backups thoroughly) and perform a clean OS reinstall — that is the only guaranteed way to remove deeply persistent components.

Cautions and follow‑up: never restore executables from infected backups; scan everything first. If the IM account sent links while compromised, contacts should be warned to ignore the links and scan their systems. Capturing Autoruns output and a process list before wiping the system helps experienced responders identify the exact persistence chain.

I THINK I FIGURED IT OUT!!!
GO HERE!

IF THIS IS YOUR PROBLEM THEN SIMPLY GOTO THE PROGRAMS FOLDER UNDER THE C: AND FIND A FOLDER CALLED BUDDYLINKS, GO INSIDE AND CLICK THE UNINSTALL ICON!! SO FAR NO BAD SIGNS YET!

..............hmm i deleted the folder earlier, and just now it was there again, i uninstalledit again....its not there....but will it return?
Both times i uninstalled it signed me off AIM but, did seem to uninstall it.

Any comments?

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.