Re: Viruses, spyware etc

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance

From: Max M.Wachtel III (maxpro4u_at_nomail.afraid.org)
Date: 12/07/04


Date: Mon, 06 Dec 2004 21:03:00 -0500

Bill Ridgeway wrote:
> Over this weekend I have been trying to eliminate spyware / rogue dialler
> which despite the efforts of Norton Internet Security and various spyware
> software will not go away. All the software I have tried have detected a
> threat(s) only some of which are dealt with only to change and reappear
> maybe two re-boots later. I'm convinced it is morphing or hiding somehow.
>
> This raises the question is there any independent research showing the
> strengths and weaknesses of the various anti-virus software in detecting and
> eliminating virus, spyware etc threats. I am particularly interested in
> protection for stand-alone computers not large systems. Googling for this
> information is unreliable as the software producers seem to be also good at
> producing convincing reports in their favour.
>
> Thanks
>
> Bill Ridgeway
>
>
Beginning of standard canned reply...

Update Windows. Use a firewall.
Use an Anti-Virus of your choice and keep it updated.
Set folder options to "show all files".
Clean out all temp, cashe, and ect.files.
Download BeClean here:
http://boozet.xepher.net/beclean/

Download Sysclean from here:
http://www.trendmicro.com/ftp/products/tsc/sysclean.com
Read this:
http://www.trendmicro.com/ftp/products/tsc/readme.txt
Reboot into safe mode and run Sysclean, write down results, then reboot
normally.
If offending file is in “restore” read this:
http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001111912274039?OpenDocument&src=sec_doc_nam

Download AdAware from here:
http://www.majorgeeks.com/download506.html
Read the help files and then Update and run AdAware.

Download Spybot Search+Destroy here:
http://www.safer-networking.org/en/download/index.html
Read this:
http://www.safer-networking.org/en/tutorial/index.html
Update and run Spybot (enable all protection).

Download Spyware Blaster here: (enable all protection)
http://www.javacoolsoftware.com/spywareblaster.html

Run a couple of online scanners (pick a different one than your main AV):

BitDefender:
http://www.bitdefender.com/scan/licence.php

Norton:
http://security.symantec.com/sscv6/home.asp?errorCode=3&langid=ie&venid=sym&plfid=23&pkj=XHPGJRSOMVZGYYTZXPE&bhcp=1

Panda:
http://www.pandasoftware.com/activescan/com/activescan_principal.htm

eTrust:
http://www3.ca.com/securityadvisor/virusinfo/scan.aspx

House Call:
http://housecall.trendmicro.com/housecall/start_corp.asp

If the previous do not solve your problems:
Download Bazooka here:
http://www.kephyr.com/spywarescanner/

Download SwatIt here:
http://swatit.org/

Download KL-Detector here
http://dewasoft.com/privacy/kldetector.htm

Download CWShredder here
http://www.intermute.com/spysubtract/cwshredder_download.html

Download HijackThis here:
http://www.majorgeeks.com/download3155.html
Install, run and save the log that is created. Don’t let it fix anything
yet!
You can find forums to post the log to have it analyzed here:
http://tomcoyote.org/hjt/

Download Stinger here:
http://vil.nai.com/vil/stinger/

...end of canned reply.

See my site for more info and links.
-max

-- 
Keeping Windows Clean: http://www.geocities.com/maxpro4u/madmax.html
Virus Cleaning+Fixes:  http://www.geocities.com/maxpro4u/TechPros
Change nomail.afraid.org to neo.rr.com so you can reply by e-mail
(nomail.afraid.org has been set up specifically for
  use in Usenet. Feel free to use it yourself.)


Relevant Pages

  • AD AWARE
    ... ad aware free download ... lavasoft ad aware ... free ad aware spyware ...
    (sci.crypt)
  • Re: Tips on removing spyware
    ... > After being hacked 7 times by spyware. ... to the latest definitions and you may need to run them in safe mode as well. ... I'll mainly work around Windows XP, as that is what the bulk of this ... and some you can only download if you are registered - but it is best ...
    (microsoft.public.security)
  • Re: Downloads and Spyware
    ... >> Microsoft, either from a CD or the internet ... >> it better to download these to my desktop in order to ... >> spyware applications before the actual install on my ... >> them are identified as Temp Internet files which I am ...
    (microsoft.public.windowsxp.general)
  • Re: IE Links dont work
    ... Download sysclean.com, from Trend Micro, here: ... in Safe mode or from a Clean Boot and clean or delete anything ... In the Startup tab, ... programs report as spyware. ...
    (microsoft.public.windows.inetexplorer.ie6.browser)
  • WARNING Long Reply - Re: About:Blank virus - My browser has been hijacked!
    ... Before you try to remove spyware using any of the programs below, ... The process of removing certain malware may kill your internet connection. ... Download their uninstaller, uninstall.exe. ... Approach 4 - If you've already tried CWShredder to get rid of this parasite ...
    (microsoft.public.windows.inetexplorer.ie6.browser)