Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations SkipVought on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Cleaning Spyware...How DO they do it?! 12

Status
Not open for further replies.

aquias

MIS
Jun 13, 2003
820
0
0
US
In a recent post a question was asked by Victor39 "Just how do you guys learn this stuff?!"

2ffat made a sound suggestion, start a new thread on this information. Now, there are people who walk and take different pathways in the learning experience. So I believe everyone has a different perspective to add to this.

My first suggestion is to find reliable and sound places of information. Where people who are skilled in spyware removal do it daily (not to take away from anyone here...but compared to some of these people we've all got a lot of learning to do.)

Some forums

spywarewarrior.com
vitalsecurity.org
forum.malwareremoval.com (take some time here, actually, enroll if you're serious and want some incredible tools/help).

There are several other sites dedicated to malware removal and I'm hoping others will chime in with them.

What else can you do? Read, read, and read. Visit the above forums and look at the logs that people provide. Ask questions, personally (even when dealing with a "pro"), I don't remove anything that I don't understand why it's coming off.

So what do I do? Ask, why does this need to come off. Take the name of unknown files and registry keys to Google. Most likely you are NOT the first to encounter an infection.

In reference to the above paragraph that is something else to do. Develop and learn good "research" skills. Learn how to phrase words and items for Google searches. This page has some tips on "Better Googling"


HiJackThis! to intimidating? This page


Breaks HJT logs out to be a little less intimidating. But don't take this sites word for what needs to be removed, do the research yourself.

Last, but not least, reading a HJT file. What are all the R0's, F12's, etc... and what do they mean?


The above page breaks apart HJT to give a GREAT explination of what the different headings mean.

This is just a start, perhaps if enough people chime in we can create an FAQ here to help get people more confident in this war for the desktop.
 
Well of spyware the most difficult ones ive seen right now are cool web search and its evil brother search assistant. They keep getting remade as more intelligent. My first major piece of advice to fight against spyware is ditch internet explorer except for half to cases which certain sites that dont support other browsers. Other than that I reccomend using firefox as the main browser and disabling java on it for that is an exploit ive seen sites use. Now as for removing spyware as aquais says hijackthis and googling are excellant ways of removing it. Some other tools and programs ive come to use are posted and listed below.

About buster (good for search assitant and cool web search)

Cws Shredder ( name says it all)

Adaware (most usually have this)

Spybot(another most usually have)


As for what I do isnt always the most safe way but I find names or file names of the spyware and if i cant remove it i try finding the registry keys that are named as the file and then delete the keys. Also if your using internet explorer pay attention to these 2 locations for alot of spyware will change these keys.

hkey_local_machine, software, microsoft, internet explorer, now click main to where its highlighted. Look in there and see if you see any odd adds like search assistant or some strange site added. If so either remove or change them back depending on what key it is. If you are unsure do not touch it.

The other location is here
hkey_Current_user, software, microsoft, iternet explorer, and click main to highlight it. Once again look for any odd or new keys. You can look info up on google if you need to. And like i said if you are unsure do not mess with it and ask someone on here and we will tell you if you should remove it or not or what needs to be done.

Anyways this is my little add for spyware removal.
 
You can read my suggestion at thread760-1135710. I might also point out faq760-4897 and faq760-5547.

James P. Cottingham
-----------------------------------------
[sup]I'm number 1,229!
I'm number 1,229![/sup]
 
Here are three links where you can register to learn:








Third link is also relevant to Spyware Warrior





Men occasionally stumble over the truth, but most of them pick themselves up and hurry off as if nothing ever happened.

Sir Winston Churchill
 
Excellent suggestions from everyone. All have received a star vote from me!!!
 


Ditto to what tfg13 said and star's all around
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top