Re: spyware removal problem

From: Michael Solomon \(MS-MVP\) (user_at_#notme.com)
Date: 01/28/05


Date: Thu, 27 Jan 2005 22:04:27 -0800


>From your original description you seem to be removing it but it keeps
coming back. If that is correct, it begs the question, do you have a
firewall installed or, at the very least, do you have the XP firewall turned
on?

If you are running without a firewall, that might explain how it keeps
returning. If you do have a firewall and it's turned on, my guess is you
have downloaded some file that you and the spyware removal tools and
antivirus have not identified, something which is the source and keeps
infecting your system. Under such circumstances, Carey's response might be
the right course of action assuming you don't restore it from some backup
set. Carey was only trying to help, help which is free and contributed by
him and others who simply volunteer. There's no need to castigate him
because you don't like the response.

Whatever the case, msconfig is a symptom, not the cause.

You might try checking to see if something related appears to be listed in
the running processes. Hit ctrl-alt-delete, go to the processes tab, if you
see something that appears to be related, see if you can find it under
services. Go to Control Panel, open Administrative Tools, open Services,
check the list of running services for something similar to what you found
under processes. Double click the item, and select disable from the
dropdown list under startup type, then reboot and see if that resolves the
issue.

It really doesn't end there but trying to root this out by trying to find a
corresponding executable might be quite some work. Conversely, if you found
some registry key, there's no way of knowing if removing it might cause some
ripple effect on your system and that brings us back to clean install.

Not sure if you have done this, have you checked the startup folder on the
start menu to see if there are any shortcuts there that might be
responsible. I know that sounds rather simple but sometimes the simplest
and most obvious possibilities are overlooked.

-- 
Michael Solomon MS-MVP
Windows Shell/User
Backup is a PC User's Best Friend
DTS-L.Org: http://www.dts-l.org/
"Don" <harley4don@npgcable.com> wrote in message 
news:Oof8zrOBFHA.2112@TK2MSFTNGP09.phx.gbl...
> In other words - you have no idea of how to fix the problem because it too 
> complicated for you and it's easier to tell me to start over. No thanks - 
> I'll try and find the right person who can correct the problem instead of 
> telling me to start over.
> "Carey Frisch [MVP]" <cnfrisch@nospamgmail.com> wrote in message 
> news:unZ8QZOBFHA.1200@tk2msftngp13.phx.gbl...
>> After performing a "Clean Install", consider purchasing and
>> installing a first-rate Internet Security program to help protect
>> your system from garbage internet web sites:
>>
>> Norton Internet Security 2005
>> http://www.symantec.com/sabu/nis/nis_pe/features.html
>>
>> -- 
>> Carey Frisch
>> Microsoft MVP
>> Windows XP - Shell/User
>>
>>
>
> 


Relevant Pages

  • Re: on-line Messenger Service exploitation in Windows XP
    ... >The problem is a service allowing unauthenticated, unsolicited connections. ... Removing the service is beneficial if there is likely to be an attempt to ... >Adding a firewall covers it up...like bandaid covering up a port. ... far more worrisome than just Messenger (which is irritating, ...
    (microsoft.public.security)
  • RE: [fw-wiz] Securing a Linux Firewall
    ... What I have done in the past is a bit of a compromise between removing all unused binaries and just disabling them, ... This is a bit of "Security by obscurity" but why not move all unused binaries to a separate unmounted partition, while still leaving them on the system. ... If it is not setuid, and not setgid, it _can't_ grant you extra privs ... > programs the firewall needs and only put those on the jumpstart CD". ...
    (Firewall-Wizards)
  • Re: virus wont leave even after formating?
    ... > Norton 03 as a boot disk to see if it could get rid of it, ... the virus might be on your network. ... clean install and installed a firewall. ...
    (alt.computer.security)
  • Re: IP issues after XP SP2
    ... reinstalled the driver for the Ethernet card? ... > Performed a clean install of XP Pro and everything worked fine. ... I have enabled the firewall and give it ...
    (microsoft.public.windowsxp.help_and_support)
  • Re: virus over running computer
    ... > How did these viruses show up after a clean install? ... > names of viruses on computer if needed. ... behind a firewall. ... NAT ...
    (microsoft.public.security.virus)