Spyware & IE Problems.

Re: Spyware & IE Problems.

Steps to remove a persistent / dheet kisam ka spyware
(a personal anecdote of sorts - use at your own risk!)

The following How-To guide elaborates the steps that can be followed (at your own risk) to get rid of spyware/malware that cannot be permanently removed by spyware sweeper programs.

I tried the following spyware removal applications without any luck:
spybot, lavasoft adaware, enigma software spyhunter.

All of the above successfully remove the “parasites” but a lot of the spyware replicates itself even after the infected files / registry keys / cookies are removed.

This procedure is especially useful for Home Search Assistent (HSA) (notice bad spelling!), Search Extender, Shopping Wizard and YourSiteBar. Even though you will see these entries in your Control Panel Add /Remove programs, you will probably be unable to remove them directly.

SO here’s what you should do (again, at your own risk):

1. Disable the System Restore option in Win XP (can be configured under System option in the Control Panel)

2. Open the Windows Task Manager (ctrl+alt+delete) and from the processes tab in Task Manager, arrange processes by UserName and for those processes that are running under your name, kill any that look suspicious. Most of the time, the process names themselves sound eerie (with 5 random letter names).

3. From the start menu, use the run prompt to invoke “services.msc” and disable the “Network Securtiy Service” (use the properties menu). This is the main culprit that helps spyware in replicating the files.

4. Use Windows Explorer to go to c:\windows and arrange files by “Date Created” (enable through the view menu and select choose details). For the latest files in your list, delete all files with random 5 letter names that have an exe, dll or dat file extension. A good way to check if you’re deleting an authentic file is to move your mouse over the filename and see if it has a tooltip description from a vendor.

  1. Repeat step 3 for the c:\windows\system32 folder.

Steps 4 and 5 are cumbersome, but make sure you’re thorough. There may also be some recently created bat files. You can open these up in notepad to see if they invoke a spyware routine. Delete these as well.

  1. Delete all the temporary files from** C:\windows emp** and also from your windows profile usually under the following folders:

C:\Documents and Settings{your username}\ Local Settings\Temp

and

C:\Documents and Settings{your username}\Local Settings\Temporary Internet Files

  1. If you have a folder called C:\windows\prefetch, completely remove it!

  2. Run hijackthis and get rid of all the BHO (Bad Home Page) entries and any other references you can pinpoint as malicious.

  3. run regedit and search for some of the spyware names e.g. 'assistent' for home search assistent (HAS) and delete all the values/folders associated with them. Most importantly, delete those folders from HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall that are associated with the spyware names e.g. HSA, SW, SE and YourSiteBar.

  4. Empty your Recycle Bin, Turn off your system and start in Safe Mode. Run any spyware removal and antivirus programs that your have.

  5. Reboot in Normal mode and you should be ok! (hopefully).

Re: Spyware & IE Problems.

^^ :k: lets see

Re: Spyware & IE Problems.

Latest version of HijackThis is 1.99.1

http://www.merijn.org/files/hijackthis.zip

After running Hijackthis, save the log file and paste it on the following page. This page will tell you what you need to remove.

http://www.hijackthis.de

(I havent tried this yet myself. Use discretion)

Re: Spyware & IE Problems.

the microsoft last (Beta) release of AntiSpyware has REALLY resolved many of our past problems with spyware.

and it is really really well done…

I strongly recommend to everyone to have it .

you can download it fromthis link

If the link does not work, just type AntiSpyware in any msn.com search box

Re: Spyware & IE Problems.

^ yeh, the MS anti-spyware program is really a break through … it now detects non-MS products as spyware … such as the firefox browser … wow that’s an achievement :rolleyes:

Re: Spyware & IE Problems.

really? you dont work for MS do you?

Re: Spyware & IE Problems.

[quote=“Umar Talib”]
Steps to remove a persistent / dheet kisam ka spyware
(a personal anecdote of sorts - use at your own risk!)

Does .cpy or .CPY (copy???) play into the maleware scheme of things?

If so..

What is the undo for that?

Re: Spyware & IE Problems.

[quote=“Umar Talib”]


8. Run hijackthis and get rid of all the BHO (Bad Home Page) entries and any other references you can pinpoint as malicious.

… QUOTE]

BHO does not stand for Bad Home Page. BHO stands for Browser Helper Object.

For most spywares, AdAware and SpyBot are enough (non-commercial use is free). Just keep them updated. AntiSpyware from Microsoft has nothing more which cannot be done faster with the above two options. Keep your system patched. Finally, use FireFox.

It is very interesting to remove spywares without using any antispyware tools. You learn a lot and you start to appreciate the effort of the guys who have made those spywares.

Re: Spyware & IE Problems.

true…

or read the log files after the anti-spyware software cleans up the spyware.

Re: Spyware & IE Problems.

another hijackthis log anayzer
HJT Log Analyzer

Re: Spyware & IE Problems.

Is there any way I can find out what programs startup with Windows (XP Home)? The Start/All Programs/Startup is blank, but I'm sure there are tons of programs that are started. My recent problem started with a trojan called "update13.js" which resided in Windows directory, it changes your homepage to "My-search.cc", I tried Hijackthis, McAfee's adware, they couldn't remove it. Also tried CWShredder but didn't work, finally found out MS adware and it was able to remove it. But now when Windows starts, it tries to find the program "update13.js" which of course has now been removed.

So again, where is the list of "programs" that Windows checks to start'em? (for example it used to be in "Run=" in Win98 in Win.ini or System.ini files).

Re: Spyware & IE Problems.

Start->run->msconfig

Re: Spyware & IE Problems.

Download Spybot - Search and Destroy
or
Lavasoft Adaware SE

They will remove the entry.

Otherwise if you want to take the risk to go through the registry editor, I can send you the correct addresses.

Re: Spyware & IE Problems.

What kinda help?

Re: Spyware & IE Problems.

Thanks for the info. :k: