Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations SkipVought on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

General Spy/Ad/Virus advice for Windows 3

Status
Not open for further replies.

bytehd

IS-IT--Management
Apr 26, 2002
575
0
0
US
1) Boot SAFE Mode or with a Floppy if possible. NTFS Read-only floppies work fine.

2) In C:\WINDOWS, run "DIR /O-D /P" and check all the file names and DATES. If you are on XP SP2, no EXE or DLL should be newer than 2004, unless you put it there. Delete all suspect barnicles. Same for SYSTEM32 folder. You can even do this in Explorer, sort by Date, and scroll thru the list via mouse or keyboard. Check Explorer's status line or turn on Column "Manufacturer" in Details view. Chumps usually DONT fill in "Joe Hacker Company" etc in the EXEs.

3) Google/Get/Run Hijackthis or a better GUI version at
4) Check all the items suggested in the a2squared tool above. Remove barnicles.

5) Run at least the FREE online checks from Norton, McAfee, TrendMicro, Stinger, NOD32, etc.

5) STOP Running 24/7 as an Admin on your own box dummy.

6) Check your Control-Panel Services for foreign invaders.

7) Check your fonts folder for anything strange (like a 5MB font)

8) Newer nasties are installing themselves as PRINT DRIVERS or NETWORK PROVIDERS. Not nice. Even the big AV players are too dumb to scan these places.

9) Get Mark Russinovich's excellent tools at TCPVIEW and PROCESS VIEWER.

10) Process Viewer, there is a Menu Option called Replace Task Manager. Do it. Every Time you press CTRL-ALT-DEL Mark's Tool comes up. One of the only TOOLS where you can actually SUSPEND a task. Cant do that with MS Tools. Check the processes. Check the DLLS and handles open.

11) TCPVIEW.EXE: watch all your outbound connections while running nothing else. This is how I caught a keylogger called WINMOTEL.EXE sending Syn packets to a PPP dialup account in Italy.

12) Only install apps as Joe User, not Admin.



George Walkey
Senior Geek in charge
 
Thank you for this valuable advice.

_______________________________________

Eman_2005
Technical Communicator
 
By the way, bytehd, your instruction number 12 is not valid.
You can only install applications when in administrative account ;-)

Mike T
I have installed ewido and ran it after updating the database.
I assure you, my computer is now clean and working better, but not at perfection.

I still see the search helper in the add/remove software and when I click to remove it, it leads me to a web page and asks me to download the uninstall program. hehehe.

Anybody knows how I solve this problem?

_______________________________________

Eman_2005
Technical Communicator
 
Group Policy will allow you to remove stuff


You are right on 12.
Install as Admin, run as Joe User

George Walkey
Senior Geek in charge
 
You can obtain additional multi-confirmational opinions for any suspect 'barnicles' (with immediate feedback) by the submitting such files for scanning evaluation:

Virus Total

Jotti

Kapersky

Vince
_____________________________________________________________
[*** If everyone is thinking alike, then somebody isn't thinking. ***]
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top