Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations SkipVought on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Definitive Spyware removal toolkit... 1

Status
Not open for further replies.

Ali147gta

Technical User
Apr 21, 2003
229
0
0
GB
I'm trying to put together a 'definitive' spyware/malware removal toolkit, so far I have the following app's (please note I'm not including things like Adaware,Spybot MS Anti Spyware) So far I have the following, does anyone have any other reccomendations???

Hijack this
CW Shredder
Toolbar Cop
IEFix
Winsockfix
About Buster
Stinger

anymore for anymore ?
 
Ali47gta said:

Absolutely do not download this.
It attempts to change your search page, your homepage, and installs .OCX controls that are not appropriate. I had to use a System Restore point to get my system working as it was before using this application as a test.

The "real" IEFix was written by Ramesh Srinivasan (MS-MVP, AumHa-VSOP) and has nothing to do with the link provided above.

The real IEFix:
 
Just, checked this, sincere apologies for posting the incorrect link,

Many thanks bcastner....
 
Something I forgot to add to this list. Not specifically antivirus/antispyware/antimalware software, but Process Explorer from is indispensable for terminating trees of processes simultaneously when there are multiple processes that keep each other alive and reload the other, such as Windows TaskAd.
Its also useful for terminating processes where the spyware/virus author has put code in to terminate task manager, registry editor or similar.

John
 

... very useful for removing vx2/abetterInternet, especially if you don't want to run Adaware. Instructions are here...


Another handy tool...


...with instructions at
The latter one is good for tracking down rogue dlls that hijackthis and scanners don't seem to find.

I second the motion on ProcessExplorer. You can easily spot suspicous running processes/sub-processes and find out where they live by going to View - Select Columns and checking Image Path. It is one of the few that will show you all of the dlls running under a particular instance of svchost. These are shown in the lower pane, if you change lower pane view from "handles" to "dlls."

As a side note, I used ProcessExplorer when I was first fighting with one of the latest strains of VX2. It showed two instances of svchhost running in a mode that would not allow access to view those processes.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top