Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations gkittelson on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Tips for removing spyware/adware by hand 2

Status
Not open for further replies.

shrubble

MIS
Jul 23, 2003
300
US
Lately I've had 2 users contract the mother of all adware viruses, and I've become pretty good at removing them "Columbo style" by hand, and would like to share my findings. This especially nasty piece of spyware/adware manifested itself when IE was opened, doing all of the usual stuff (search hooks, pop-ups, reinstalling itself, installing other spyware, trying to download trojans, adding all kinds of "helpful" search bars, the whole nine yards...).

The iShrubble way of spyware removal (USE AT YOUR OWN RISK!):

NOTE: If you don't have a copy of hijack this, get it. It's your mom, your girlfriend, your best friend, and your dog all rolled into one. Also- when I say "delete" or "fix" something, I mean delete or fix it after you've researched that thing and know it to be malicious. Use some common sense here; put the stuff in the recycle bin, and when in doubt, Google.

1) Reboot in safe mode. This keeps the processes that run most of these programs from starting when you boot up. If you try this after a regular boot, most of the .exe and .dll files associated with these programs will simply not delete, because they are in use.

2) Do a Windows search for *.exe (all executables) on the machine, then resort them by date. It's also not a bad idea to also do the same for all files created on that date, just to see what's there.

3) Delete all strange executables installed on or after the date the spyware first manifested itself (see note above!). Make sure you delete them to the recycle bin, if you make a bad call, it's easy to put them back where they belong. Also- doing all of this right through the search dialog ensures that you will find the files no matter where they are hiding.

4) Run hijack this- fix all suspicious entries, especially ones that bear the names of the executables that you just deleted. Also- because there are usually multiple instances of svchost.exe processes running at any given time on your machine (this is normal), spyware/adware .exe files are often named this (or something similar) to avoid detection. Be especially wary of .exe files that start up when the machine boots. If your not sure about the validity of something, ask your pal Google, he usually knows. KEEP YOUR BACKUPS! Again, see note above.

5) Peruse, with Windows Explorer, all of the directories located in C:/program files/. Often you will find directories with names that are obviously adware (it's almost comical!). I would list some, but believe me, it's obvious. Check the creation date of these directories, and delete the ones created on or after the date of the infection. Again- see above note concerning deletion.

6) Reboot in normal mode and see what happens!

Hope this helps!

deletion mistake
no I can't recover that
you didn't save it

-Shrubble
 
Shrubble,
[tab]Good one. Why not post this as a FAQ.


James P. Cottingham

There's no place like 127.0.0.1.
There's no place like 127.0.0.1.
 
It seems to me that, particularly for those with little experience in these matters, that there should be a "predelete" step 2a and a "prefix" step 3a - google research. In regard to exe files, this research needs to focus on both file names and locations. I know very little about win98 and nothing about other op systems. From a perspective like that, of minimal knowledge, I find that it is very difficult to accurately know what is a suspicious file and what isn't.

In researching hijackthis logs, several times I'd come up with what I was quite sure were bad file names, only to check and find they were some odd modem driver, HP or Lexmark printer file, special Gateway file, Creative Technologies special file, and so on. On the other hand, the first time I saw TV Media in a log, I skipped over it twice because I was quite confident it would turn out to be some kind of sound or video related stuff I'd not seen before. When I finally googled it just before doing a write up on the log, I once again learned why you check everything. And then there are the valid filenames like winamp and svchost that can be put in invalid locations for nefarious purposes.

I just think this approach has the potential to be dangerous for some folks and should be accompanied by some careful research.



-------------------------------------
It's 10 O'Clock ( somewhere! ).
Are your registry and data backed up?
 
Sorry I painted with such a broad brush- I attempted at every turn to stress that you really should research everything before you delete it, and that you should place the deleted items somewhere where they can be easily returned in case of emergency. This really is a technique for people comfortable with regedit, and digging through the guts of their PC.

-But that being said-

With the INSANE rate that these programs have been popping up lately, it pays a huge dividend to understand exactly how these programs typically operate, and to get used to the kind of detective work necessary to rip them out by hand if that's your only option. I've seen instances of these things do everything from mucking with the resident installation of Norton AntiVirus, to disabling Spybot S&D, to opening ports to let all of their friends come in and join the party. We, as technical users, administrators, and programmers are every bit as talented as the losers writing these things, and there's no reason why we can't use that talent to undo the garbage they insist on forcing into our networks.



deletion mistake
no I can't recover that
you didn't save it

-Shrubble
 
I certainly can't argue with that.

-------------------------------------
It's 10 O'Clock ( somewhere! ).
Are your registry and data backed up?
 
ishrubble;
Make it a FAQ and tweak it over time.
[thumbsup2]

p.s. check the wording of the graphics section on your skills page

TT4U

Notification:
These are just my thoughts....and should be carefully measured against other opinions.
Backup All Important Data/Docs
 
HA! I am a great progammer!!!

Thanks, one of the side effects of hand-coding I guess.

The concensus seems to be to migrate this thing to an FAQ, so it shall be done!

deletion mistake
no I can't recover that
you didn't save it

-Shrubble
 
Where can "Hijack this" be found? Is that the exact format of the word? I'd hate to try to find it, and end up getting spyware, b/c searched for the wrong thing, b/c added or took away a space or something.

Stephen [infinity]
"Jesus saith unto him, I am the way, the truth, and the life:
no man cometh unto the Father, but by me." John 14:6 KJV
 
kjv;
You may like this site for overall windows help as well [smile]

TT4U

Notification:
These are just my thoughts....and should be carefully measured against other opinions.
Backup All Important Data/Docs
 
TekTippy4U,

Thanks for the post.. I've just glanced at the page so far, but do find it very interesting, to say the least. Will look more as time allows.

Stephen [infinity]
"Jesus saith unto him, I am the way, the truth, and the life:
no man cometh unto the Father, but by me." John 14:6 KJV
 
By the way, TT4U, I am assuming that is your web site? If so, (out of curiosity), what program did you use to build it, or did you hard code it all your self with notepad or another document formatter? I was guessing Microsoft Front Page..?

Stephen [infinity]
"Jesus saith unto him, I am the way, the truth, and the life:
no man cometh unto the Father, but by me." John 14:6 KJV
 
Okay, verified it...
TekTippy4U is not the owner of the website listed under thatposting. Thanks for the info, TT4U, though, the site is a breath of fresh air! [SMILE]

Stephen [infinity]
"Jesus saith unto him, I am the way, the truth, and the life:
no man cometh unto the Father, but by me." John 14:6 KJV
 
Yes it is Kjv1611;
It'a amazing what you can find when searchin for one thing and then stumbling onto some gems from time to time.
thought you'd like it.
You know tek-tips also has a browser issues and/or html, css, xml section or forums....look around....maybe some answers about coding web pages can be found there.


TT4U

Notification:
These are just my thoughts....and should be carefully measured against other opinions.
Backup All Important Data/Docs
 
Thanks for the advice!

Stephen [infinity]
"Jesus saith unto him, I am the way, the truth, and the life:
no man cometh unto the Father, but by me." John 14:6 KJV
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top