PDA

View Full Version : Re: Spyware, Adware etc... It must be Microsoft or Symantec


Shenan Stanley
April 27th 04, 03:31 PM
Nick wrote:
> My browser has been hijacked for two weeks now by the same site;
>
>
> I have downloaded, installed and correctly used the following:
> Spyhunter, Spybot, CWShredder, HijackThis and Ad-Aware.
> They all work well in identifying and removing the hijackers.
> The problem is that when I perform a Norton update for virus
> definitions, or Microsoft Windows update, upon opening the browser
> the hijackers are there waiting. Could there be an issue with the
> download?
> Could there be an issue with shared components , dll's, activex's
> etc..?
> It is too coincidental that the hijackers reappear after downloading
> virus definitions or windows update.
> I rarely dowload over the internet.
> Now I have extra cookie and history folders in the Temp folder.
> Any comments by Microsoft Representatives are most welcome.

Doubtful either are to blame. Have you updated Spybot Search and Destroy
before running it? Did you IMMUNIZE your PC after cleaning it with SpyBot
Search and Destroy and with SpywareBlaster? Have you turned on your
firewall?

better secure/clean up/keep clean your PC:

You may have spyware/adware infesting your machine, follow the
appropriate section for that, making sure you use at least
THREE of the tools I list to scan and clean your machine AFTER
updating them. Cleaning up spyware/adware/malware usually
solves home page hijackers as well.

Please Notice that if you use AOL, you should at least upgrade to 9.0 or
greater before doing any of the fixes. I know you can get AOL 9.0 at almost
any convenience store, gas station, super market or other retail outlet in
the world, so this should not be a problem.


Turn on that firewall...
http://www.microsoft.com/WindowsXP/home/using/howto/homenet/icf.asp
(It has been reported that it now works with AOL 9.0+)


Make sure you have all the updates (critical) installed from:
http://windowsupdate.microsoft.com/
(Scan for updates, Review and Install)


Get rid of the spy/ad/mal-ware..
(Yes - using MORE than one of these..
I recommend at least the first three. Also..
UPDATE the definitions for them before using.)

Spybot Search and Destroy
http://www.safer-networking.net/

Lavasoft AdAware
http://www.lavasoft.de

CWSShredder
http://www.spywareinfo.com/~merijn/downloads.html

Hijack This!
http://mjc1.com/mirror/hjt/

I also like "The Cleaner" and "SpywareBlaster" and "SpywareGuard".
- http://www.moosoft.com/
- http://www.javacoolsoftware.com/

The first is a PAY product, but useable for 30 days - it has found and
eliminated problems in the past the others did not. The latter two are
prevention mechanisms. I like SpywareGuard for those with enough processor
to have something running like antivirus software - and it prevents browser
hijacking quite well. SpywareBlaster is a FANTASTIC free product, I suggest
getting this after you cleanup and keeping it updated as well....

And Assortment of Others:
http://spywareinfo.com/


After you cleanup your PC somewhat of spy/ad/mal-ware, verify your antivirus
software is updated and run a full scan of your computer. If you have no
antivirus software - get one NOW! Grisoft AntiVirus:
http://www.grisoft.com/us/us_dwnl_free.php


Empty your Temporary Internet Files and shrink the size it stores to about
80 to 120MB (seems to be an optimal size for the normal user)

- Open ONE copy of Internet Explorer.
- Select TOOLS -> Internet Options.
- Under the General tab in the "Temporary Internet Files" section,
do the following:
- Click on "Delete Cookies" (click OK)
- Click on "Settings" and change the
"Amount of disk space to use:" to something between 80MB
and 120MB. (Betting it is MUCH larger right now.)
- Click OK.
- Click on "Delete Files" and select to
"Delete all offline contents" (the checkbox) and click
OK. (If you had a LOT, this could take 2-10 minutes or
more.)
- Once it is done, click OK, close Internet Explorer
- Re-open Internet Explorer.


Uninstall any software you do not use often/ever. (If you have something
installed but never use it, uninstall it.) If you go through Control
Panel -> Add/Remove Programs and see things you seldom if ever use, it is to
your advantage to remove it.


Also, if you are tired of Web Page Pop-Ups/Unders.. You could try the
Google Toolbar.
http://toolbar.google.com/


Stop loading applications at logon.. run MSCONFIG and look under the startup
tab for things you DON'T want to startup! Search the Internet with Google
to discover what things are safe to remove and what things may even be
malware infecting your computer.


Better control your email and lessen the amount of time you spend dealing
with SPAM:
SpamBayes
http://sourceforge.net/projects/spambayes/
or
Spamihilator.
http://www.spamihilator.com

--
<- Shenan ->
--

Nick
April 30th 04, 02:51 PM
Xref: kermit microsoft.public.windowsxp.security_admin:148055

Thank you Shenan,

For the record, I have always used a firewall.
I do not use AOL.
I religiously update norton and windows everytime I dial up, it's the first port of call for me.
No other users on this laptop.
I have set the temporay internet folder to 50MB.
I have been cleaning this machine for two years now just like your recommendations.
I would like to delete the index.dat's that are everywhere, but unable to delete, "it is being used by another person or program".
I have used norton since windows98. it was a problem back then, machine very slow etc.
I'm not confident enough to stop processes at startup. I'm not sure what to enable or disable. there are usually 36-40 processes at startup. I have a Toshiba TE2100E. P4, 1.9GB, 512MB RAM, WINXPPRO SP1, with all critical updates.
I just can't believe we have to download 6 or so products to prevent these demons from returning.
I know when and how the problem arose, I accidentally hit cancel instead of closing the window of a pornsite.
Except in this instance, I never use the cancel or no buttons on any popup or browser, I always close the window via the red cross top right corner.
Thank's again.

Google