Prevent and Remove Spyware/Malware!

Donovan

Enlightened
Joined
Jan 6, 2005
Messages
420
Location
North Metro Atlanta, Georgia
*Updated yet again (7/8/07) with additional links and information*

I sent someone this info who PM me about an infection. I thought it might be useful to others as well! I (used to) do this for a living and these are the steps I recommend to remove most infections...

----------
The following freeware and instructions will help prevent and get rid of "most" malware infections. First download, install and fully update these programs if you don't have them already:

First, STOP using Internet Explorer 6 as your default web browser!!!! This is the single best thing you can do to prevent getting (re)infected with spyware/malware! Download FireFox web browser: http://www.mozilla.com/ or Opera http://www.opera.com/ (I use both FF and Opera). Install FireFox and/or Opera and set one of them to be the default browser (very important!) Then and use FireFox/Opera not IE to download the rest of the products.

*If you have IE6 still on your system then please upgrade to IE7 even if you aren't going to use it as your default browser (or even at all). The popularity and adoption of Firefox finally forced Microsoft to update IE (which sat without major updates or development for more than 4 years!). Internet Explorer 7 has numerous security advantages over IE6. One of the most important is that it is no longer "integrated" into windows explorer shell. This means that web content trying to open in windows explorer will be redirected to the default web browser.

SuperAntispyware: http://www.superantispyware.com/index.html
Cheesy name but a great product!

Spybot: http://www.download.com/Spybot-Search-Destroy/3000-8022_4-10401314.html?tag=lst-0-1

Spyware Blaster: http://www.javacoolsoftware.com/spywareblaster.html
a very good preventative tool. A must have no matter what else you use!

AVG Anti-Spyware: http://www.ewido.net/en/download/
This is commercial software but also has a freeware mode. *AVG purchased Ewido a while back...

Install SuperAntispyware, Spybot, Spyware Blaster and AVG and update them all but do not run them yet (you may go ahead and update/run spywareblaster).

Close IE if open (you should be using FF/O!) and go into Internet options (right-click on the IE icon on desktop or go to control panel and choose internet options). While in the General tab of internet options, click on the "delete files" button in the middle of the window to delete all "cache" or temporary internet files (also check delete offline files). Click on the settings button next to delete files and this will open a new window (settings). In this new window click on the "view objects" button to open yet another window (downloaded program files). In this window select all objects and delete them. This will get rid of all the IE plugins (good and bad). Since you are going to be using FireFox you don't need any of them anyway! Even if you do need to use IE, any plugins you may need can be easily reinstalled later...

Make sure all programs are fully updated!
Run the SuperAntispyware scanner first and let it remove anything it finds.
Reboot into safe mode by restarting your pc and hitting F8 when you pc is first starting to boot. Choose Safe Mode no networking.
Then run the SpyBot and any other software scanning tools you have and let them remove anything they find. Then run the same programs again when you boot back to regular mode under your normal profile(s). This is important because safe mode will be using a different profile than "normal" mode.
Then run Trend Micro Housecall if you don't have a good up-to-date antivirus
http://housecall.trendmicro.com/

These steps should eliminate "most" infections.
If you are still having issues then a trick you can try is to first close all open programs and then run task manager (hit ctrl-alt-del) go to the processes tab and end explorer.exe. This will blank your screen but don't panic! Hit ctrl-alt-del again to get task manager back. Choose File, New Task (Run..) and browse to AVG (C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe) or SuperAntispyware (C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe) or Spybot (C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe) and run them. Explorer can sometimes get infected and this will let you run the scans without explorer in the way.

If you have XP: After cleaning your system up please disable then re-enable system restore to flush out infected backup copies: http://forums.majorgeeks.com/showthread.php?t=31668

And as always make sure your system is completely up to date with the latest service packs and patches. http://update.microsoft.com/ You will have to use IE for the Microsoft sites! (make sure IE doesn't steal back default browser). If you have MS Office or other MS programs be sure and update them as well. http://office.microsoft.com/en-us/officeupdate/default.aspx
Microsoft also has setup a site that will scan to see how healthy your pc is: http://safety.live.com

*On that note I would check all of your software to see if there are security updates and/or patches for them. Here is a great site that has updates and patches for most of your common software all in one place! http://www.softwarepatch.com/ I use this site all the time and highly recommend it!


Additional programs:
Microsoft Defender (used to be Giant Antispyware) http://www.microsoft.com/athome/security/spyware/software/default.mspx

And these good commercial antispyware programs:
Spyware Doctor http://www.pctools.com/spyware-doctor/

Pest Patrol http://www.ca.com/products/pestpatrol/

Webroot Spy Sweeper http://www.webroot.com/consumer/products/spysweeper


Antivirus recommendations:
Trend Micro PC Cillin Antivirus http://www.trendmicro.com/en/home/us/personal.htm
The most popular antivirus does not make it the best (very far from it actually and yes I am talking about Norton and McAfee. Neither are recommended). Trend Micro is one of the antivirus programs I use on my own PC's. PC Cillin is a full suite (antivirus, firewall, antispyware etc.) so if your looking for just AV there are some even better options:

NOD32 - very light on resources, one of the best!
http://www.eset.com/

F-Prot
http://www.f-prot.com/

BitDefender
http://www.bitdefender.com/

F-Secure
http://www.f-secure.com/


If you want a good freeware antivirus program try one of these. I have used both of these freeware programs and would recommend either one of these over Norton!

Avast
http://www.avast.com/eng/avast_4_home.html

or AVG
http://www.grisoft.com/doc/289/lng/us/tpl/tpl01


..........................

If you are still having problems then try these helpful forums where someone can really get down and dirty with your infection!
Help forums:
http://forums.spywareinfo.com/

http://spywarewarrior.com/index.php

http://castlecops.com/forums.html

http://forums.tomcoyote.org

http://forums.majorgeeks.com/

*HiJackThis program: http://www.majorgeeks.com/download3155.html
You will need this program for folks in these forums to help you! Don't remove anything with this program unless you know what your doing or someone is helping you!



--------
The recommended AntiSpyware programs list:
http://spywarewarrior.com/asw-features.htm#rec

"Bad" Antispyware list:
http://www.spywarewarrior.com/rogue_anti-spyware.htm
--------

As always, you can also contact me. If I have the time I will gladly try to help!
 
Last edited:

CroMAGnet

Flashlight Enthusiast
Joined
Sep 4, 2004
Messages
2,540
Location
Los Gatos, CA
signs-wow.gif
I've used the HiJackThis forum link you listed for a nasty spy/malware and they were very helpful.
t_ups.gif


signs-super.gif
 

Santelmo

Enlightened
Joined
Dec 4, 2004
Messages
385
A great big THANK YOU and may the gods reward you man! We should have CHEERS for this guy!

I was actually having PC problems (the ALEXA worm?) and was wondering where to find freeware.
 

Santelmo

Enlightened
Joined
Dec 4, 2004
Messages
385
BTW, can anyone tell me how to go about removing the ALEXA Key (I suppose its a worm)? I'm a non-techie so please be gentle. I've downloaded Ad-Aware 5.0 and Ad-watch v2.5 but it seems Ad-Aware can't remove it? My PC seems to hang/crash/slow a lot lately.
 

ibcj

Enlightened
Joined
Aug 11, 2005
Messages
789
Location
NY
I had to remove spyware from my father's computer recently. Even after installing around 7 different programs to remove the stuff, I was still having issues. A great website / forum is Major Geeks
With their help, I was able to clean it up.
 

Donovan

Enlightened
Joined
Jan 6, 2005
Messages
420
Location
North Metro Atlanta, Georgia
Santelmo said:
BTW, can anyone tell me how to go about removing the ALEXA Key (I suppose its a worm)? I'm a non-techie so please be gentle. I've downloaded Ad-Aware 5.0 and Ad-watch v2.5 but it seems Ad-Aware can't remove it? My PC seems to hang/crash/slow a lot lately.

those versions of Ad-Aware are pretty old, try the newer ones in the links above. Scanning in safe mode with up to date (the program as well as the definition updates) ad-aware, spybot, etc can remove most infections. No single program can remove all things which is why you should scan with different scanners...
If you have something really evil like Nail or VX2 then things get a little more complicated! These are can also be easy to remove if you have some knowledge of regedit, killing tasks etc...
 
Last edited:

Donovan

Enlightened
Joined
Jan 6, 2005
Messages
420
Location
North Metro Atlanta, Georgia
Santelmo said:
A great big THANK YOU and may the gods reward you man! We should have CHEERS for this guy!

I was actually having PC problems (the ALEXA worm?) and was wondering where to find freeware.

I know it can be hard to find the "good stuff" because there are SO MANY antispyspyware programs out there. MOST of the stuff I see ads on I would NEVER use! A lot of these programs are actually spyware themselves!

Look at this site for a list of all these "bad" spyware:
http://www.spywarewarrior.com/rogue_anti-spyware.htm
 

carrot

Flashaholic
Joined
Dec 6, 2005
Messages
9,240
Location
New York City
This may be an extreme drastic measure, but if you have enough technical know-how to setup Deep Freeze ( http://www.faronics.com/ ), you can protect your computer from almost any spyware or malware installation (probably all, actually). It prevents any changes from being made to the hard drive of your choice (you can setup a partition or another drive as thawed, where changes can be made and saved) so a simple reboot can fix anything. You can also unthaw your "frozen" drive to make changes on the fly. We use it at my school for maintenance, and if you can't be bothered hunting down malware and spyware - and even viruses most of the time, Deep Freeze might work for you (assuming a clean installation with no malware or anything on it already).

Insofar as I can tell, Deep Freeze is unbreakable. It even protects its processes, so you can't try to kill it.
 

colubrid

Enlightened
Joined
Nov 28, 2005
Messages
454
Location
Georgia
Will installing and running any of these cause a problem with AVG and microsoft anti spyware i have on my computer? Or do I have to remove these first before using these ?
 

Deanster

Enlightened
Joined
Feb 17, 2002
Messages
590
Location
Seattle
I administer a small network at a travel agency (<20 WinXP machines), where we MUST use Internet Explorer to talk to the 'great travel computers in the sky', and I've had very good luck with SpySweeper.

We had a couple machines infected badly enough that I was going to wipe them, after no luck running AdAware/Spybot/McAfee, etc., and SpySweeper came in and wiped the buggers out, including a very nasty rootkit that was running and re-installing itself while the machine was in fricken' SAFE MODE...

Spysweeper offers a 30-day free trial, and it's great for using on infected computers for free, though I actually bought a subscription (which I don't usually do).

It's not perfect, but it's been shielding and cleaning my machines for six months now, and I've had nearly no problems w/ spyware/malware since.

Of course, my personal machine is a Mac, where I don't even bother to run a virus checker...
 

LEDagent

Flashlight Enthusiast
Joined
Jul 3, 2001
Messages
1,487
Location
San Diego, California
I generally use the first few steps you've outlined.
1) Use Mozilla as my default browser and revert to Internet Explorer only when i need to.

2) I use AVG-free for my anti-virus needs.

2) Scan using Ad-Aware and Spybot every other day. Although, after switching to Mozilla Firefox, I've gotten maybe 10-15 hits in the last year and no viruses, in comparison to 1000+ spyware hits using IE.


My belief is, if AVG, Ad-Aware and Spybot can't clean my computer, then it just isn't worth the extra effort to go any further. I just backup my data and wipe out the hard drive.

I've gotten smarter over the years and have done this for data protection:
1) Partition my HD, one dedicated for system and program files, the other for documents, pictures, videos, etc...
2) I loaded my system partition with all the latest drivers and program updates and use Acronis TrueImage to take a snapshot of my healthy setup.

If this go bad, i just format my system partition, load the latest healthy image back on, and all my settings and programs are back to normal.
 

colubrid

Enlightened
Joined
Nov 28, 2005
Messages
454
Location
Georgia
quote:
"My belief is, if AVG, Ad-Aware and Spybot can't clean my computer, then it just isn't worth the extra effort to go any further. I just backup my data and wipe out the hard drive."


How do you back up the data and wipe out the hard drive? Can you explain it to someone who is computer illiterate?
 

Donovan

Enlightened
Joined
Jan 6, 2005
Messages
420
Location
North Metro Atlanta, Georgia
colubrid said:
How do you back up the data and wipe out the hard drive? Can you explain it to someone who is computer illiterate?
Acronis is a great backup/imaging software. You can find more info on it here: http://www.acronis.com/

I purposely tried to keep the initial directions simple. I wanted to stay with easily available freeware so that anyone could download and run. There are a multitude of advanced tools and methods for spyware/malware/backups etc.... For example one I use often is a heavily customized BartPE CD. This allows me to boot up any pc into a known clean windows environment where I can run various antispyware/malware, antivirus, registry editing, data recovery, backup/imaging programs.
More info here: http://www.nu2.nu/pebuilder/ and here: http://www.911cd.net/forums/

If the instructions aren't helping, the support forums listed in my first post can help someone get rid of almost any infection. They are also a great place to learn about new immerging threats and how to combat them. This is all continually changing so what may work fine today might not work so well tomorrow! As always keeping your pc clean is the goal! Use an alternate web browser like FireFox or Opera, keep your antivirus and antispyware programs current and up-to-date, use both a hardware and software firewall and use common sense with email attachments, P2P programs, suspect websites and file downloading.
 
Last edited:

Empath

Flashaholic
Joined
Nov 11, 2001
Messages
8,508
Location
Oregon
This thread was initiated with good intentions of providing useful advice against malware. It's usefulness isn't going to be compromised by turning it into a Mac vs PC discussion. One posting has already been removed. Any others that attempt to initiate that tangent will also be removed.
 

db

Newly Enlightened
Joined
Jan 26, 2005
Messages
85
Location
Indiana
Here's an anti-spyware product I ran across recently.

http://www.arovaxshield.com/index.php

I've installed it on my daughter's computer and it seems to function as advertised.

M$ Antispyware's realtime-protection caused problems. ( slowing the system down. AthlonXP 1800, 256 Meg of Ram )

From the Arovax Website:

"Arovax Shield™ is a brand new type of personal security solution that is unlike to any firewall, anti-virus or spyware remover.
Rather than looking for spyware traces or tracking applications that secretly send or receive data over the Internet, Arovax Shield blocks any attempt by malicious software to add entries to the auto-start menu, change the registry, hijack or install itself into a browser or find any other way to stealthy get itself onto a PC."
 

Luna

Enlightened
Joined
Dec 27, 2004
Messages
874
I've been quite impressed with SpySweeper lately. I had a few machines that I knew had a bug ( I was tracking the files so I knew what they had) but AdAware and Spybot had no luck . SpySweeper took care of it and I was surprised to find I had a few other friends present (or traces left over)

The 14 day trial isn't as sweet as the freebies but hey it appears to work very well! Nice program
 
Top