Slashdot Mirror


Stopping Unstoppable Malware?

A frustrated troubleshooter asks: "I've recently been asked to fix a friend's computer, and for once, I'm stumped. There is a piece of malware on his computer that puts up Aurora popup windows. Neither Spybot nor Ad-Aware detect this, so I've had to try to manually clean the system. However, the files re-write themselves, making the malware grow back as fast as you can remove it. The only "solution" is to run an uninstaller written by the people who wrote the Aurora pop-up itself. Has anyone dealt with this particularly painful piece of pop-up programming, and if so, how have you successfully removed it?" What other pieces of Malware have you found that was difficult to remove? Aside from using programs like the afore mentioned Spybot and Ad-Aware (and others of their ilk), what other methods of Malware removal have proven to be the most successful?

155 comments

  1. Everything can be cleaned manually by Anonymous Coward · · Score: 0

    even in Windows. Remove the registry keys, keep killing the tasks and then remove all the files.

    1. Re:Everything can be cleaned manually by erth64net · · Score: 3, Informative

      False. Be careful where you make such broad "...everything..." statements.
      Some spyware either is, or borders on, the definition of a rootkit. Rootkits can be detected, but there are a growing number which cannot be removed without an fdisk/format.

    2. Re:Everything can be cleaned manually by X0563511 · · Score: 1

      Using the task manager, kill all explorer.exe processes. Use the task manager to run any applications you need, and use CMD to manage files. Most of the time, those rewrites come from DLLs loaded into explorer.exe.

      Chances are though, it's a combination of DLLS in system32, registry startup commands, and IE hooks. Go though the system32 directory with a fine tooth comb, and research each DLL that seems strange on a clean computer (don't forget to search the internet as well).

      --
      For large sets, this will be our guide even unto death, for the LORD will work for each type of data it is applied to...
    3. Re:Everything can be cleaned manually by Scanline · · Score: 1

      I'd say with a PE (like BartPE) and some tools it's possible to remove malware that are hiding themselves with rootkit techniques. Booting from read only media is the classic way of preventing execution of hostile code, but sadly it's often overlooked nowadays. It can be very time consuming though to locate and remove malware though, especially when you don't know it's there. It's not something an average user would likely succeed in doing, so I guess you're mostly right when you say it's impossible to remove without fdisk/format.

      --
      "But I'm still like a little kid, see?
      I just don't know when to quit."
      - Rei
    4. Re:Everything can be cleaned manually by GraemeDonaldson · · Score: 1
      Go though the system32 directory with a fine tooth comb, and research each DLL that seems strange on a clean computer
      Good idea, I mean it's not like there's about 1,000 DLLs sitting in system32 or anything.
      Wait, what's that?
      Oh, there *are* just about 1,000 in a clean install?
      Well it's not like it's hard to spot which ones are legit and which aren't.
      Wait, what's that?

      ...

      Riiiight.
      --
      I think, therefore I am. I think?
    5. Re:Everything can be cleaned manually by X0563511 · · Score: 1

      I never said it was easy... but it can be done. If you really have to. If you have such a crippling un-removable malware infection, it would probably be better to back up your data and wipe it clean. And stop using IE as an Administrator (except for windows update). Half the crap out there won't work without an Admin account (probably more than half)

      --
      For large sets, this will be our guide even unto death, for the LORD will work for each type of data it is applied to...
    6. Re:Everything can be cleaned manually by Anonymous Coward · · Score: 0

      You are assuming the rootkit hasn't infected the firmware of your hard drive, cd burner, video card, or other hardware. If it has then the only way to get rid of it is either desoldering and reflashing the flash chips in all your hardware or buying a new computer.

    7. Re:Everything can be cleaned manually by Anonymous Coward · · Score: 0

      but there are a growing number which cannot be removed without an fdisk/format.

      Thats bullshit. A rootkit is just ones and zeros. Its not some kind of evil magic. Maybe the skill level required to remove it is beyond that of the vast majority of IT people but that still does not mean that it cannot be removed.

  2. Istvc by Anonymous Coward · · Score: 0

    IE Popups ( I don't use IE so this is pretty annoying.) Nothing removes it properly. SD startup watcher can't prevent it's install.

    I'm formattting this weekend.

  3. You're half way there by Gary+Destruction · · Score: 4, Informative

    You need advanced trojan detection to fully eliminate malware. You need Trojan Hunter as well as Trend Micro Housecall in addition to Spybot and Adaware. At the Trend Micro site, be sure to choose the complete scan. Also, you may have to run Trojan Hunter in Safe Mode along with Adware and possibly Spybot. It depends how much malware is left over after the scan. Some of it might not be able to be removed unless you boot into safe mode. If you run less than those four programs, you will probably miss some malware. I'm saying that from my own experience. The four programs essentially compensate for one another.

    1. Re:You're half way there by dJCL · · Score: 1

      Sounds like my clean up plan here, only I add Microsoft Anti-Spyware and Usually 2 or 3 other anti-virus utils too.

      Scan with one, clean, scan with another, clean more... always on the bad systems it is needed for both virus and spywares.

      Random anecdote... I got a call from a sales person at Panda AV, trying to get a feel for what we sell. They asked if I had ever tried their software. Truthfully, yes, I ran a scan on a system and cleaned a tonne of stuff of it, then ran trend and cleaned more. I told the person this. They assumed there was not sales opporitunity going to happen here. They thing they didn't ask: did I try it the other way? Trend first then Panda, and yes I have, trend cleaned a tonne, and Panda found more.

      No product if perfect, on these bad systems, we need it all.

      Trend housecall, AVG, Kaspersky online beta, AVG, MS AS, spybot adaware...

      And even then, some stuff is still there and has to be pulled of hard.

      --
      On Arrakis: early worm gets the bird. Magister mundi sum!
    2. Re:You're half way there by Gary+Destruction · · Score: 1

      You know, I think some of it has to do with everyone having a different definition of spyware and adware. WintoolsA.exe is malware that Adaware finds, but Trojan Hunter won't even detect it. Trend Micro finds it.

  4. two things... by chivo243 · · Score: 1

    one, look for hitman pro anti spyware utility. two, if you really need help look for killbox follow the directions to kill the process and delete the files. three, good luck

    --
    Sig Hansen?
    1. Re:two things... by chivo243 · · Score: 3, Informative

      four, ditch any p2p stuff, really! Kazaa is doing more than you think!

      --
      Sig Hansen?
    2. Re:two things... by Uber+Banker · · Score: 2, Insightful

      No nearly so easy.

      I ended up with something installed, it was very odd:

      1. It was not a seperate process, it bounded itself to IE. No process to end other than IE and in a work environment where Firefox is not an option that's a problem.

      2. When uninstalled and files deleted it reinstalled itself. The files had to be deleted manually. Yet they reinstalled with random file names, the only way to identify them was by working out they were always a combo of 5 letters and had the same file size.

      3. Sure it had a registry entry, but when it spread it randomly named itself as in step 2. Manual registry editing was the only option, somewhat risky as entries could be deleted by mistake.

      4. Because of 1, 2 and 3, there were no processes and files to be deleted automatically. It becomes a manual process.

      The solution: We did a diff of the registry from a backed up version and went through line by line. Could have done a reinstall, and did in the end (with something this sneaky what elso could it have been doing?) but it was very interesting to see how it worked. Lets hope this type of malware remains in the minority.

    3. Re:two things... by PixelCat · · Score: 2, Insightful
      Lets hope this type of malware remains in the minority.


      You're kidding, right? This stuff makes it harder to keep your PC safe. Expect it to become dominant.
    4. Re:two things... by mwilliamson · · Score: 1

      Lets not be hasty and lump all p2p stuff in the catagory of malware. BitTorrent is malware free (at least the python-based official client and the azarus java client). I don't like the fact that "P2P" in general is becoming synonymous with malware.

    5. Re:two things... by chivo243 · · Score: 1

      I agree with you, but most of the windows based p2p (not torrents) Kazaa and the gang give you more than you bargain for, or not even what you asked for. It is really the malware that is using the p2p as a method of delivery, and that is the problem. :-/

      --
      Sig Hansen?
    6. Re:two things... by TheShadowzero · · Score: 1

      I agree, BitTorrent is totally free of all Malware (although I can't say the same about the stuff you download with it). But Kazaa and Limewire DEFINATELY install mass amounts of spyware and adware on your computer. I know from experience.

      --
      If history repeats itself, why can't we study the future?
  5. Here's how to do it on Win2k by bergeron76 · · Score: 5, Informative

    Here's how to do it on Win2k:

    step 1) try to kill off all the procs you can. Most malware will say "Access Denied", but some can be killed.

    step 2) delete all the DLLs and activeX controls from your IE Downoads directory. Many of them will be held 'open' and won't be deletable.

    step 3) check the start menu -> Startup folder. Delete any links from here that aren't familiar.

    step 4) open your system services (from Computer Management; Administrative tools, whatever). Check for any services that look fishy. I typically sort them by status and look at the 'started'/active services.

    step 5) open the registry (RegEdit) and search for "RunOnce"; directly above it will be "Run". We don't search the registry for "Run" because it appears like 1000 times. Delete any keys in the "Run" folder that don't look right. Search about 3 more times for this entry - it appears in multiple places.

    step 6) unplug the machine (DON'T power it down). Some malware will try reinsert registry keys at shutdown. Worst case scenario here is that you get a checkdisk warning/error at startup.

    step 7) start the machine back up in DOS mode (or Safety with DOS prompt). Go back to the Internet Explorer Downloads directory and delete the DLLs/ActiveX controls. They should get deleted now because the malware processes won't be holding the files open.

    step 8) Reboot.

    step 9) open the registry back up and see which processes re-inserted registry keys in the "Run" folder (see step 3 above).

    I had one particularly nasty one (News.net) that Spybot couldn't delete. I finally killed it by using the process I described above. The trick with news.net, however, was to pull the plug IMMEDIATELY after deleting the registry key. The malware process re-inserts the registry key every 2 seconds, so I had to delete the key and pull the plug on the machine before it could re-insert the registry entry. One of the tricky things that news.net did was not allow me to search in RegEdit. So I used Spybot's startup/registry tool to remove the key. News.net was somehow able to circumvent Spybots registry blocker.

    As I'm writing this, I'm using a Windows 2k(sp2) machine from 2001. It hasn't been remastered since then and it's my daily driver. Interestingly, I've never done a single Windows Update on it, and I have fewer problems with exploits and malware than I've had on the 4 other machines that I've had to remaster (again and again) that I ran Windows Update on frequently. Maybe none of the malware writers are wasting time with the old exploits because they figure they've all been patched. Luckily for me, by not doing Windows Update, I've saved myself from all of the Exploits that the new patches have created.

    I'm running Office 2000, Firefox, and Thunderbird. I never ever use IE or Outlook, ever. Oh yeah, and I also use a modified hosts file (from http://accs-net.com/hosts/) for ad/malware blocking.

    Oh yeah, and use TeaTimer and SpybotSD services to prevent new spyware/malware.

    Happy computing.

    --
    Don't think that a small group of dedicated individuals can't change the world. It's the only thing that ever has.
    1. Re:Here's how to do it on Win2k by Anonymous Coward · · Score: 2, Informative

      ad 1) you know rkill from the Windows Resource Kit? It can kill more processes than the normal task manager. Very handy tool :) btw, you can set permissions even on registry keys. You have to use regedt32.exe for this, regedit.exe doesnt have this feature.

    2. Re:Here's how to do it on Win2k by Bozzio · · Score: 3, Informative
      Also keep an eye out for stuff in
      HKEY_LOCAL_MACHINE/Software/Microsoft/Windows NT/Current Version/

      %windir%\Downloaded Program Files

      %windir%\Prefetch
      I've had some malware manage to autoexecute from there. The last one was particularly surprising.

      Also, permissions in the registry can cause a lot of problems.

      This said, there is ALWAYS a way to remove malware.. WITHOUT having to cut the power dangerously. They key steps are always:

      1) Close all of its running components.
      2) Find and remove all of its files.
      3) Find and remove all its mean of copying itself (often in the registry)
      4) Reboot, login to all accounts, Repeat.
      --
      I just pooped your party.
    3. Re:Here's how to do it on Win2k by Tux2000 · · Score: 4, Interesting
      Some additional tips:
      • To kill "unkillable" Processes, use pskill from sysinternals.com. Also try pslist instad of the taskmanager to list the processes. The taskmanager does not give you all the information you might want to know, like many other tools from Redmond.
      • Try to kill a whole bunch of suspicious processes at once, so that no part of the malware has a chance to restart another process. Again, pskill can do this.
      • Boot another system, preferably one that can not execute EXEs, DLLs and so on: Get Knoppix or some other CDROM-based Linux (that is able to write NTFS if you use NTFS for Windows). Use it to browse the WWW, especially to search information about the malware. Use it to delete all executable files (*.EXE, *.DLL, *.OCX, ...) of the malware. (Malware registry entries should be harmless if all executables of the malware are deleted.) If you use Knoppix, this is not much harder than deleting files using Windows. You just have to find the right harddrive partition (usually hda1) containing windows and mount it read-write (use the right mouse button on the hdd icon). The real hard job is to find each and every executable of the malware.
      • Disconnect the network plug / modem / isdn / whatever, switch off WLAN router, etc., before you boot windows to prevent the remaining parts of the malware to re-install itself from the net.
      • Re-enable network only for the time you run Knoppix on the machine, until you are really, really sure that there are no traces left from the malware.
      Tux2000
      --
      Denken hilft.
    4. Re:Here's how to do it on Win2k by doofusclam · · Score: 1

      Yours was probably the most insightful one on this topic. There's plenty of 'kill these processes and remove this runonce key' bollocks, but they don't work with modern malware. My friend works for a computer repair company, and he found a malware a few days ago that creates a new Scheduled Task to update itself, so no amount of killing reg keys will stop it. In fact it's even worse, as until then he'd leave after 'cleaning up' a PC only to get called out on the way home as it had reinstalled itself.

      pskill is a useful tool to have. Having it on a windows boot cd using Bart's PE tool is even better, as long as you keep it up to date with the latest virus defs and spybot defs. It's just like a Linux live cd, but with native Windows apps. It maybe best to put it on a bootable memory card, but i've never managed to get it to work. Either way some malware is far ahead of the detection methods of Spybot et al that they are a bitch to remove for someone who knows what they're doing, so comments that help would be appreciated on this subject.

    5. Re:Here's how to do it on Win2k by linuxwrangler · · Score: 3, Informative
      step 2) delete all the DLLs and activeX controls from your IE Downoads directory. Many of them will be held 'open' and won't be deletable.



      But often you can rename them even when you can't delete them. It's always worth a try. On reboot it can't find the offending file.

      --

      ~~~~~~~
      "You are not remembered for doing what is expected of you." - Atul Chitnis
    6. Re:Here's how to do it on Win2k by bryhhh · · Score: 2, Informative

      step 1) try to kill off all the procs you can. Most malware will say "Access Denied", but some can be killed.

      If you get access denied error messages, the chances are that the executable is running as a service. In which case

      1. Open regedit
      2. Browse to HKLM\System\CurrentControlSet\Services
      3. Search for registry for 'data' that matches the executable name.
      4. Start > Run > Services.msc
      5. Find the service located in step3
      6. Stop and disable the service.

    7. Re:Here's how to do it on Win2k by pmc · · Score: 3, Informative

      Another trick, which I don't think I have ever seen mentioned (it's from my personal reserve) is, when using NTFS, to set permissions for Deny Execute for Everyone. Then you happily reboot and just delete the suckers.

      Works best on things that do the service and run at startup tricks.

      I dare say this will be lost in the arms race eventually, but a useful weapon never-the-less.

    8. Re:Here's how to do it on Win2k by Monkelectric · · Score: 1
      Very good advice, another good trick is -- once you've identified the files... load the recovery console off the CD and remove them. I had to do that with a particular nasty bug which had several mechanisms which replaced its files.

      Also, IIRC NT4 allows you to rename a locked file from the console. So you can rename all the files, reboot, and delete them.

      --

      Religion is a gateway psychosis. -- Dave Foley

    9. Re:Here's how to do it on Win2k by kawika · · Score: 1

      These are all good generic suggestions. As for Aurora in particular, a Google would lead you to this post that also identifies it as Bolger and a few other names. The reason it's so sneaky is that it installs as a print monitor that is hosted by the print spooler exe. The dirty work is done by a randomly named exe file. If you try to kill that, it spawns another randomly named exe to take its place.

      The post above has some registry edits to fix the problem. However, I can tell you that won't always fix the problem. The newer versions seem to work differently. You CAN remove them using the spyware maker's uninstaller which I hate to recommend but it does work.

    10. Re:Here's how to do it on Win2k by canadiangoose · · Score: 5, Informative

      There's another way to kill processes that say 'access denied' without having to download additional software. Using the commandline 'at' command, schedule taskmgr.exe to run in interactive mode. If the clock on my system tells me that it's 2:30:56pm, I'll run the following command:
      at 14:32 /interactive taskmgr.exe
      That will produce (at 2:32pm) an instance of the Task Manager running as 'Local System', which has even higher privileges than Administrator. From there you can kill nearly everything!

      --
      Never eat more than you can lift -- Miss Piggy
    11. Re:Here's how to do it on Win2k by Anonymous Coward · · Score: 1, Interesting

      With NTFS there's another option which can be handy as well. As people have noted the registry keys can help one track down where the files are. A liberal application of "deny all" to the malware, can be both an effective stop-gap measure, and as a step in deleting the files.

    12. Re:Here's how to do it on Win2k by silvwolf · · Score: 1

      Dellater will delete a file the next time Windows boots, while the splash screen is displaying. I had to use it on a particularlly nasty bug that had 2 processes running. You'd kill the first and the second would restart it.. Delete the "Run" registry entry and it'd come right back. They even started in safe mode. Dellater allowed me to delete the exe's when I rebooted then go in and delete the registry keys and finish cleaning the mess.

    13. Re:Here's how to do it on Win2k by Monkelectric · · Score: 1

      I think theres actually a Win32s call that does that. Hope the program isn't expensive :)

      --

      Religion is a gateway psychosis. -- Dave Foley

    14. Re:Here's how to do it on Win2k by patio11 · · Score: 1

      Take that, malware authors! MS handily left us an exploit to exploit your exploits away!

    15. Re:Here's how to do it on Win2k by Werelock · · Score: 1
      step 5) open the registry (RegEdit) and search for "RunOnce"; directly above it will be "Run". We don't search the registry for "Run" because it appears like 1000 times. Delete any keys in the "Run" folder that don't look right. Search about 3 more times for this entry - it appears in multiple places.
      Unfortunately, I had a customer's machine last year that taught me something - Registry keys are just like path names. So if they want, mal/spyware authors can put their startup entry somewhere else entirely as long as they use the HKCU\Software\.etc.\Run as the key name, and their exe for the value (or perhaps it was both as simply a value under the Default key... can't recall now). Since Windows reads and processes the entire registry at startup, it will find that and run it just like it's part of the Run entries. Wish I could recall which particular piece of crud was doing this, but I'm drawing a blank atm.
    16. Re:Here's how to do it on Win2k by EdelFactor19 · · Score: 1

      if your solution is to unplug the computer to prevent shutdown writing... than among other things you aren't removing it properly; and IMHO you shouldnt be giving anyone any advice, my magic answer for this stuff, msconfig; you can temp disable any service you want, and reboot until you find exactly which service is the "mal" service. without moving or deleting anything either important or unimportant. once you find and disable the correct startup services youll be able to remove the entirety of the malware.. occasionally youll have to go to safe mode as well.. the other thing i like about msconfig is that it will tell you exactly where in the registry the service is for you to delete once your ready to remove it from the registry... and if you pull the plug that fast there is no guarentee that your changes get written to the hard disk either

      --
      "Jazz isn't dead, it just smells funny" ~Frank Zappa
      EdelFactor
  6. Comment removed by account_deleted · · Score: 1

    Comment removed based on user account deletion

  7. FDISK by Grand · · Score: 4, Informative

    After all the time you spend cleaning it, its probably faster to just backup his important files and re-install. And tell him to browse his porn with opera or firefox.

    1. Re:FDISK by eclectro · · Score: 1

      And tell him to browse his porn with opera or firefox

      Normally I would agree with this statement. However the malware has become so pervasive on Windows that countless innocents are getting it as well.

      You are right about reinstalling. It is often quicker than trying to weed it out, and the only way you can be sure that you have removed it all.

      With my family, they are moving to linux or getting their own machines and servicing. It's just too much of an hassle/risk anymore.

      --
      Take the cheese to sickbay, the doctor should see it as soon as possible - B'Elanna Torres, "Learning Curve"
  8. Neat little trick - NTFS permissions by JackAsh · · Score: 3, Informative

    I came up with this one last year while going through a similar problem - I managed to delete a number of files the malware was using and then discovered it was repopulating itself from one source file I couldn't get rid of. So, I repermissioned the file so no one had access to it except some made up account I created on the spot. I think I even used negative NTFS permissions (block access to this file to System, Adminstrators, etc.). There were some more steps such as searching and removing every instance in the registry of any file that this thing copied, but the NTFS repermissioning was the key.

    If you are one Win9x or have FAT32 on your drive, this won't work for you... but good luck anyway.

    Finally, I hate to give in, but go ahead and run the uninstaller - their malware already 0wnzors the computer you are working on, this is not likely to make it any worse...

    -Jack Ash

    PS: Another thing you might try is booting up one of those WinPE environments (bootable windows on a cd) floating around the net, and deleting it from there...

    1. Re:Neat little trick - NTFS permissions by Nos. · · Score: 1

      Another good file to change permissions on is the hosts file. I've seen these have some interesting entries... like redirecting common search engine URLs to add sites.

      Also, make sure that you're not running/surfing as administrator - common sense I know, but some still do it. Assuming the malware isn't to sophisticated, this will often prevent it from getting itself fully installed (like in the Run/RunOnce registry keys). While it may still get installed, its usually easier to get rid of if it wasn't "installed" with admin privileges.

    2. Re:Neat little trick - NTFS permissions by TykeClone · · Score: 1

      I've seen a virus rewrite the hosts file to include the symantec, norton, and AVG update sites and redirect them to the localhost. It even went so far as to add a bunch of new lines so that it wasn't immediately obvious in notepad.

      --
      A fine is a tax you pay for doing wrong and a tax is a fine you pay for doing all right.
  9. Most Important Step... by Plac3bo · · Score: 2, Funny

    Boot into Safe-Mode first, then... ...do everything else that will be suggested here.

    1. Re:Most Important Step... by Anonymous Coward · · Score: 0

      exactly right

  10. Hate malware? by WetCat · · Score: 1, Informative

    Ditch M$ and install Linux!

    1. Re:Hate malware? by Stevyn · · Score: 2, Informative

      Or you could find a live-cd that uses the ntfs.sys driver to read/write NTFS partitions. Knoppix will read them out of the box, but I'm not sure if it will write properly. Last I read, which was a few months ago, the NTFS write support with the driver in the kernel could only write to a file as long as the size didn't change. So I assume that means deleting is out of the question.

      Another good tool is a boot cd called "Hiren's Boot Disk". It has lots of commercial software so I believe you'd have to look for it on P2P or torrent websites to obtain it, but it has some good tools on it.

      As these people write better malware, it's going to get increasingly more difficult to remove them while windows is running.

      Or, like the parent suggested, run linux and exchange this hassle for different hassles. I know I did. But it's more fun in the long run.

    2. Re:Hate malware? by bhtooefr · · Score: 1

      Hmm... interesting trick I thought of, and Captive NTFS isn't even necessary.

      Every .EXE has the characters "MZ" at the beginning. To render the program inoperable, simply replace "MZ" with anything else (or, if you're really bored, dd if=/dev/zero of=/mnt/windows/windows/malware.exe - correct me if I'm wrong on the usage of dd). It's suddenly no longer a valid Win32 image, but it still exists on the filesystem.

    3. Re:Hate malware? by Grinler · · Score: 1

      At that point you may as well just remove the infection instead of deleting the header. Aurora is not hard to fix if you know the files causing it. Generally nail.exe, bolger.dll, svcproc.exe, and then some random files in the %System% directory.

    4. Re:Hate malware? by bhtooefr · · Score: 1

      This is useful if you're using the Linux Kernel NTFS driver, and you CAN'T DELETE FILES (or change the file size at all).

      If you're using Captive NTFS, however, then your way IS the best - nuke those files. Same goes for a Windows PE (BartPE or Winternals ERD Commander) boot CD.

  11. If all else fails... by SouperIan · · Score: 2, Interesting

    Unplug the hard drive, and dump it into a specially-configured "disinfectant" computer. Make sure it has up-to-date malware scanners - the four mentioned earlier should do the trick - and then scan it a lot. That should help get rid of some that loads on bootup. Then you might have to go in by hand to get rid of the rest, but it should get you started.

    --
    http://unelite.freelinuxhost.com - Rock/Scissors/Paper and RPGs shouldn't mix.
  12. Safe mode! by sootman · · Score: 1

    After playing whack-a-mole with processes that would respawn themselves after being killed via task manager and would re-write themselves into the registry if you deleted the reg key, I finally remembered to start up in Safe Mode (press F8 repeatedly as soon as your computer finishes POST) and then remove the keys. My kid borked up a machine pretty bad and after running SB:S&D and AA that was what it took to kill the last little bugger.

    --
    Dear Slashdot: next time you want to mess with the site, add a rich-text editor for comments.
  13. Cut/Paste into recycle bin by MuNansen · · Score: 1

    one other thing that SOMETIMES works is that although they don't allow themselves to be deleted, these files do like to be copied. So try Cut/Paste into the recycle bin, then Empty it. Has worked a few times for me.

    1. Re:Cut/Paste into recycle bin by dJCL · · Score: 1

      Sometimes works, you cannot delete a file that is in use, like a running process. But you can move it.

      Move it to the recycle bin, then restart. On startup, the file is not where it should be, so it does not run, and then you can empty the recycle bin.

      Worked for me a few times.
      Safe mode works too.

      --
      On Arrakis: early worm gets the bird. Magister mundi sum!
  14. stopping unstoppable malware? by ShecoDu · · Score: 1

    if you stop it, then it's not stoppable, is it?

    otherwise, you would need to make it stoppable first. :)

    1. Re:stopping unstoppable malware? by Anonymous Coward · · Score: 0

      if you stop it, then it's not stoppable, is it?

      Actually, it is...

    2. Re:stopping unstoppable malware? by ShecoDu · · Score: 1

      I meant "then it's not unstoppable" obviously

      Have to remember previewing first.

    3. Re:stopping unstoppable malware? by Anonymous Coward · · Score: 0

      How is that obvious?
      You could have also meant "then it's stoppable".

  15. Title makes no sense by Profane+MuthaFucka · · Score: 3, Funny

    You can't stop an unstoppable malware program, by definition. So, to say that you can stop an unstoppable malware program would imply that he program wasn't truly unstoppable.

    Which leads me to the next question: God is omnipotent, so I wonder, could God create a malware program that even HE could not remove? If you have a computer that is behaving badly, start it working on that problem. While it's distracted and busy trying to figure it out, WHAM, you hit it in the head, just like Captain Kirk in that M-5 episode.

    --
    Fascism trolls keeping me up every night. When I starts a preachin', he HITS ME WITH HIS REICH!
  16. Had a similar issue by LouCifer · · Score: 1

    With another piece of crapware.

    Got rid of it with a combination of SpySubtract and system restore under XP. I don't know if SpySubtract will work, but its free for 30 days and worth a shot.

    Incidentally, did you google for some help?

    --
    Religion is for people afraid of going to hell.
  17. HiJack this by iamzack · · Score: 5, Informative

    You need to use HiJack This. http://www.spywareinfo.com/~merijn/downloads.html

    This program doesn't actually detect spyware/adware/malware, but rather it shows all items that are currently loaded on your system. It does have some helpful hints as to what these itmes might be, but doesn't specifically tell you if something is malware. You have to be saavy enough to figure it out yourself. I've gotten rid of a few nasty progs with this helpful tool.

    1. Re:HiJack this by Anonymous Coward · · Score: 0

      Please, mod parent up. Quite informative and effective.

      only yes men get points

    2. Re:HiJack this by mooingyak · · Score: 1

      I've had to bail to HiJack this exactly once. All other times the AA/S&D combo took care of things. Don't remember the name of the critter, but it might well have slipped under the radar except for the fact that it insisted on setting the IE homepage every time you opened IE. It was very unobtrusive otherwise (at least, in ways that I could notice).

      --
      William of Ockham had no beard. The most likely explanation is that it was chewed off by squirrels every morning.
    3. Re:HiJack this by leuk_he · · Score: 1

      Why wasn't this mentioned before. Hijack this is the prefrerred way of scanning for adware/spyware in most online fora (forums? excuse my englisch) . It manages to find most(if not all) software that start up.

      The only thing it does not find are rootkit things(yes, ther is spyware with rootkit behaviour!). There is very little software to find the rootkit in windows land.

      Recent test show that even the best signature based anti spyware toosl only find 90% of de bad software. MS antipy and hitman pro (last is a combination) are among the best and free(as in beer).

  18. Preventing Spyware by chaotica1974 · · Score: 1, Informative

    Stop downloading Porn.

    1. Re:Preventing Spyware by Anonymous Coward · · Score: 0

      Stop downloading Porn.

      With IE and without Microsoft Anti-spyware and/or restrictive security settings.

      OR

      Stop downloading spyware-installing programs to help you download more porn.

    2. Re:Preventing Spyware by slaker · · Score: 1

      I download porn constantly. If I run anti-spyware programs on my Windows machines, I never have anything but cookies. Porn is not the problem.

      Using a non-IE browser, however, is almost certainly part of the solution.

      --
      -- I wanna decide who lives and who dies - Crow T. Robot, MST3K
  19. Spybot and Ad-Aware by BrookHarty · · Score: 1

    Currious, Ad-Aware and Spybot now include "report ware" or whatever they call it, is there any truly free 3rd party program scanner?

    I've been hit a couple times by downloading shareware with addons, or some popup that both have ignore, that leads me to a DDL/Reg hunt also.

    Even microsoft's beta scanner doesnt catch them. Was wondering when someone would bring this up on Slashdot, its been crazy.

  20. Kill me now, I know... by Anonymous Coward · · Score: 3, Interesting

    I have found that very little if any spyware ever shows up on my Windows computer if I have Microsoft Anti-Spyware Beta 1 installed. It has grabbed a few things, and kept me relatively nuisance free.

  21. Re:two things... w/ links by yamcha666 · · Score: 2, Informative
    I did some google searching relating to killbox and aurora and I found some links:

    KillBox

    Tech Guy Support Forums

    and most notable: MyPCTuneUp which I am assuming is that Aurora Uninstaller you were talking about. According to the forum link above, the uninstaller really works. And it can't hurt to try, considering Aurora has already hijacked your PC, what more can an uninstaller do besides uninstall the malware.

    And from personal experience, I've had a few Malware uninstallers from the official company that did a better job removing the malware than SpyBot, MS Anti-Spyware, and Lavasoft Ad-aware.

  22. Re:Here's how I cleaned a system by Anonymous Coward · · Score: 0

    removing ALL start-up programs is really dirty.. that should be a last resort thing.

  23. Hijack This/MS-Config by vancera · · Score: 1

    http://www.spywareinfo.com/~merijn/downloads.html Hijack This will create a log of possible Malware. Google all the entries to figure out which ones aren't legit. Not always easy since some malware will randonly rename themselves. Remove questionable entries, either by googling the specific manual removal instructions or let HT delete the entry for you. Also use msconfig to turn off all startup items. then got to "services", hide the MS services and turn off everything left. Reboot. Turn all services left and reboot. Turn on each item turned off and reboot till Malware shows itself. Once the baddie is located research manual removal instructions. I had a similiar problem with my PHB's wife's PC. The above helped though the biggest problem turned out there were 6 worms hiding out and turning Norton off at each reboot. Had to download and burn to CD 20 something worm/virus detect and removal progs.

  24. Experiment.... by Bozzio · · Score: 2, Interesting

    I've been experimenting with combinations of software for security, and this is by far the best combination for general use:

    FireFox (Browser)
    Avast! Home Edition (Anti-virus)

    Part of my experiment was to operate as an Administrator at all times. I've been running like this for several months now, and have not encountered a single problem!

    No viruses, No Spy-ware/Mal-ware, no annoying restrictions (I'm not using SP2).

    Anyone else use this combination? It is by far the strongest combination I've ever used.

    --
    I just pooped your party.
  25. Nuke the machine. by km790816 · · Score: 2, Insightful

    Burn the important files to CD. Get an external harddrive, whatever.

    Then nuke the harddrive and start over. In my experience going through the pain of finding all of the problems is worse than finding old install disks. You can also start with a clean build of XP SP2 which makes it *much* harder to get infected.

    When you image the machine, make sure you set up at least two partitions so starting over in the future is less painful.

    1. Re:Nuke the machine. by lilmouse · · Score: 1

      Too true.

      Final point: Boot from Knoppix/Ubuntu/what-have-you, and back up useful data from that, not from Windoze...

      --LWM

  26. Your system is compromised... by Baloo+Ursidae · · Score: 1

    ...therefor the only secure option is to format and reinstall from a known good backup. Otherwise, there's a big unknown whether or not you got rid of the compromising situation. Perhaps now is a good time to consider a platform that doesn't make your problem inevitable.

    --
    Help us build a better map!
  27. Non-volatile malware?? by Curtman · · Score: 1

    Interesting that this story should show up the day after I spent several hours trying to reinstall a friend's downed computer.

    The symptoms it had when I got there was, the mouse didn't work, and various "properties" pages wouldn't come up, like "System" in the control panel did nothing, right clicking "My Computer" and clicking properties didn't work either, but clicking "Manage", and going to the device manager did work.

    In there, I notice several strange things like yellow exclaimation marks on the "Terminal server keyboard", "Terminal server HID mouse", etc.. I disabled those, and the mouse began working again, but a dialog came up telling me the machine would reboot in 1 minute, so I opened 'cmd', and tried to cancel the shutdown, but it would reappear every time I did.

    At this point I told him it was probably best that we reinstall, because I couldn't guarantee I could destroy either the virus/trojan/malware itself, or the source of infection. So I started the XP install, deleted the partition, created a new one, and tried to format it with NTFS. It spent a half hour doing that, and then said something to the effect of "Windows is unable to format this device due to corruption". Soooo.. I booted Knoppix, downloaded Maxblast, did the diagnostic thing (which said the drive is fine) in that, zero'd the drive with it, and tried again. Same damn message.

    So I figured I would try booting a Win98 cd, and try with a FAT32 partition which I created and formatted there. When I booted the WinXP cd, and picked the FAT32 partition, and picked the 'leave filesystem intact (no changes)' option, it said "Windows had modified the partition table and must be restarted". And now it just keeps doing that.

    I'm heading back there shortly to take another round at it, so if anyone has any suggestions I'd love to hear 'em. :)

    1. Re:Non-volatile malware?? by LennyDotCom · · Score: 1

      Have you tried fdisk /mbr

      --
      http://Lenny.com
    2. Re:Non-volatile malware?? by Anonymous Coward · · Score: 1, Interesting

      Forget Maxblast - boot back into Knoppix and zero the drive with dd.

      # dd if=/dev/zero of=/dev/hda bs=1M count=100

      The count=100 is a bit of overkill (you'd probably get away with just 1), but this will zero the first hundred megs of /dev/hda. Of course, if you have any other drives (or if the target HD isn't /dev/hda), you'll want to use hdb/hdc/etc. If it still acts up, you can drop "count=100" entirely from that line to zero the whole drive byte by byte.

      If you still run into corruption, blame hardware.

    3. Re:Non-volatile malware?? by Curtman · · Score: 1

      Yeah, zeroing the entire hard drive erases the mbr, the partition table, and all the data.

    4. Re:Non-volatile malware?? by LennyDotCom · · Score: 1

      well I don't know about that I would give it a try just for the hell of it. It has worked wonders for me in the past

      --
      http://Lenny.com
    5. Re:Non-volatile malware?? by DA-MAN · · Score: 1

      Forget Maxblast - boot back into Knoppix and zero the drive with dd.

      # dd if=/dev/zero of=/dev/hda bs=1M count=100


      Although I concur with using dd instead of third party programs, the gp did state that he used Maxblast to zero out the drive. Not sure how this would give different results. As far as I know dd does not have any magical drive fixing powers that I am aware of.

      --
      Can I get an eye poke?
      Dog House Forum
    6. Re:Non-volatile malware?? by Curtman · · Score: 1

      Turns out it was bad RAM. I'd just like to say thanks to whoever came up with the idea of putting memtest86 on the Knoppix CD. :)

    7. Re:Non-volatile malware?? by Curtman · · Score: 1

      The way to do it with the XP cd is to go into the recovery console and type 'fixmbr'. The problem was the installer wouldn't use the drive though, not an unbootable system.. Like I said in the other reply in this thread though, it was faulty RAM. Its working great now. :)

      What I find really interesting is that the Ubuntu live cd was running fine for two days on bad RAM, with no problems but the Windows installer couldn't handle the hype. Hehehe

    8. Re:Non-volatile malware?? by LennyDotCom · · Score: 1

      not suprising I have seen winXP do some really wierd shit with faulty RAM

      --
      http://Lenny.com
  28. MS by sznupi · · Score: 1

    AdAware & Spybot weren't that good lately. And surprisingly, MS antispyware is very good (although slow)

    --
    One that hath name thou can not otter
    1. Re:MS by budgenator · · Score: 1

      My first encounter with spybot was on recomendation of a MS tech rep; it wouldn't suprise me that MS had a channel to spybot and was feeding them malware defs on the QT. If so, that source has dried up now that MS antispy is distributed and security is something they are officialy admiting to be in need of improvement.

      --
      Apocalypse Cancelled, Sorry, No Ticket Refunds
  29. tips by InternetVoting · · Score: 1

    comb through the running processes running. A simple google search will turn up enough information (usually). If anything is identified as malware, running regedit and doing a search for said file names will often find those keys intentionally put in random sources. Delete them. Also be sure to clear any of the said files in "%systemroot%/system32" and the like.

  30. Are you Serious ? by Anonymous Coward · · Score: 0

    Asking this question here you should expect 500 replies from people telling you to install Linux and be done with it. (which you should BTW)

  31. More info on using NTFS permissions by Crosse · · Score: 4, Informative
    It's great to find someone else that uses the same tactic that I use. I would add a couple things to the above list, though:
    (I do all my perm editing from the command prompt using the CACLS utility that comes with XP)

    1. Instead of having to create a bogus account and deny specific users, just use the command-line switch "/D Everyone" to do the same thing. By doing this you are explicity denying everyone access to that particular file, which gives the added benefit that Windows will not be able to start the process after a reboot! NOTE: Use this with caution! Please do NOT try to execute this command on, say, any files or directories needed for Windows to run!

    2. Once you have found and edited the ACLs of the offending processes, reboot the machine. See if any other rogue processes start, and if so repeat step 1 on those.

    3. All the registry entries used by the spyware will still be there, but since the reboot they can't run, i.e., you can now delete the reg entries without them coming back.

    4. Once you are certain you have found and deleted all the malware entries in "Run", "RunOnce", the Startup folder, etc., re-edit the ACLS of all the malware files (you wrote them down, right?) so that you can delete them (easily done by granting Everyone Full Permission: "cacls /G Everyone:F")

    5. To get rid of bogus / malware Services, do the above and then find the Services reg key (HKLM\System\CurrentControlSet\Services) and look for the malware filenames (found by viewing the properties of the service in the Services applet). NOTE: Do NOT delete random keys here...that can be rather dangerous for the stability of the system! When in doubt, leave the entry. As long as the file is safely deleted using the above methods, it should not come back. This process is only to make the malware service disappear from the Services applet.

    6. The last tip I have is to use a free utility from SysInternals called RegMon. It monitors the registry hives for any process making changes. Malware and spyware are seemingly *always* making changes, which means they will be rather easy to spot. Use the Filter option liberally to filter out generic Windows processes and other known good ones. By using this method, you may find malware processes accessing the registry that DO NOT SHOW UP in Task Manager or directory listings. While these files definitely exist, they are hooked into the OS in such a way that they hide their presence. You can neither find these files in Explorer, nor using "dir" in a command prompt...but CACLS will still operate on them! (I had to use this method to clean a laptop over the weekend...12 hours of cleaning, because the girl couldn't find her WinXP Home CD, and I didn't have one laying around--irritating, to say the least.)

    Now for the usual disclaimer: I am a sysadmin, I know what I'm doing, and I'm responsible for what I screw up. I am NOT responsible for your screwups though, so please be VERY careful when using the above methods...you can really hose your system if done improperly. If you feel like this is a bit too tech for you, I highly recommend SpyBot S&D and TrendMicro's HouseCall. In fact, I used both of those on that laptop along with the above methods to clean the thing entirely.

    Happy malware hunting!

  32. blah blah blah by vbrtrmn · · Score: 1

    There's enough tutorial here to get you started, after you (hopefully) remove the spyware from your friend's computer..
    1. Get him a decent firewall that you can configure to only let certain executables through. I like sygate firewall.
    2. Delete or disable Internet Explorer, if that's too extreme, remove it from the desktop.
    3. Install FireFox
    4. Uncheck "Hide extensions for known file types.", this is in Tools -> Folder Options..., in explorer
    5. Tell him not to run any executable pr0n he downloads off of p2p.
    6. Install Firefox & Thunderbird, tell him to never use Outlook & IE again.

    --
    it's a sig, wtf?
    1. Re:blah blah blah by DA-MAN · · Score: 1

      5. Tell him not to run any executable pr0n he downloads off of p2p.

      Some of my best material comes from p2p . . .

      --
      Can I get an eye poke?
      Dog House Forum
    2. Re:blah blah blah by usmc.spitfire · · Score: 1

      Wow, he has to install Firefox twice (3,6)? ;)

  33. give up by PapaZit · · Score: 1

    Step 1: back up all of the data on the machine that you care about. Try not to back up any applications.

    Step 2: Reformat the hard drive. Reinstall. Patch, patch, and patch some more. Get the AV and anti-spyware tools in place. Reinstall applications. Restore backups.

    Think of it as a test of your backup program.

    --
    Forward, retransmit, or republish anything I say here. Just don't misquote me.
  34. All of these are good programs: by jasonmicron · · Score: 3, Informative

    Try using all of these programs:

    Microsoft Anti-Spyware
    Spybot
    AdAware
    HijackThis

    Those are 4 programs I run regularly. I usually do these in this order:

    1) Update all definitions in all programs
    2) Reboot to Safe Mode
    3) Run Add/Remove Programs and remove any unknown programs
    3) Run AdAware, remove all infected files
    4) Run Spybot, remove all infected files
    5) Run Anti-Spyware, remove all infected files
    6) Run HijackThis, remove all non-system files (only run this if you are an expert at it)
    7) Clean out Internet Explorer Cookies
    8) Clean out ALL temp files
    9) Clean out all unknown files in the Windows & System32 directories (again, expert only)
    10) Reboot (pick safe mode again)
    11) Run all of the scanners again to be sure of removal
    12) Reboot into normal mode, run scanners AGAIN (to verify)

    Obviously if malware comes back shortly (within 10 minutes or so) check Services (start --> run --> "services.msc") and remove any that you don't recognize.

    The only piece of malware that I haven't been able to remove was a variant of CoolWebSearch. Not even CWShredder got rid of it (or even detected it) as well as all of the other cleaners.

    Good luck.

    1. Re:All of these are good programs: by foniksonik · · Score: 1

      You should join another 12 step program.... the one you're in doesn't look like it's helping much.

      One of these should help you out ;-p

      http://www.theclairefiles.com/ms12steps.html

      http://www.cio.com/archive/010102/shop.html

      --
      A fool throws a stone into a well and a thousand sages can not remove it.
    2. Re:All of these are good programs: by PixelCat · · Score: 1
      The only piece of malware that I haven't been able to remove was a variant of CoolWebSearch. Not even CWShredder got rid of it (or even detected it) as well as all of the other cleaners.


      I think I have managed to nuke CoolWWWSearch on a computer this weekend. We created a new user, downloaded MS Antispyware, and immediately ran it. It took out a bunch of stuff, 30-40 entries. Fortunately, he uses webmail only, so we copied the few documents he had over to the new My Documents directory, saved his favorites teh same way, and deleted the old user. Computer seems to work now.
    3. Re:All of these are good programs: by Meph_the_Balrog · · Score: 1

      The only piece of malware that I haven't been able to remove was a variant of CoolWebSearch. Not even CWShredder got rid of it (or even detected it) as well as all of the other cleaners.

      I managed to toast a version of this on a friends machine using assistance from Tech Suuport Guy forums, hijack this and CW Shredder. After this it was still a case of selectively searing registry entries and hunting obscure .dll's in the system and system32 directories. I also recommend to the original poster something that scans for BHO's. I believe software like BHODemon or MS's Spyware scanner check for these.

      Its a good thing I enjoy hunting bugs on computers, its frustrating as hell, but I really do enjoy the challenge =).

    4. Re:All of these are good programs: by AvantLegion · · Score: 1
      Gee, after reading all that, I'm glad I use simple user-friendly Windows instead of that complex Linux stuff!

  35. Avast! by alexo · · Score: 1

    I had a similar problem.

    A friend's computer was so badly infected with various kinds of malware that it had almost no spare cycles left for actual work.

    I tried all the usual approaches, asked for help on the free PC support sites, downloaded and ran every anti-spyware that I could lay my hands on but still couldn't remove everything.

    Then I removed the ineffective Norton AntiVirus from the machine and installed the free avast! 4 Home Edition.
    It restarted the machine, cleaned up everything, restarted again and no problems so far.

  36. Fool-proof solution by lbmouse · · Score: 3, Funny

    format c:

  37. filemon, regmon by Datoyminaytah · · Score: 1

    www.sysinternals.com Lotsa good stuff. Especially: filemon regmon process explorer rootkitrevealer For filemon and regmon be sure to set some filters or you will be deluged with info on every process running on the system.

    --
    assert(birth_date<time-86400)
  38. Ewido security suite and Aurora by bbutton · · Score: 1

    Funny you should ask :) I just removed this very same program from a friend's computer this weekend. I searched all over the web to find out how to remove it. The best answer I got was here.

    I loaded Ewido Security Suite, rebooted, and on the way up, it detected and removed all traces of it (as far as I could tell).

    Also consider booting into safe mode. In safe mode, Aurora's software isn't loaded, and you can do all sorts of interesting things. -- bab
  39. Did you turn off System Restore? by TFGeditor · · Score: 1

    I hesitate even asking this because it probably insults your skills, but, not knowing your skill level, did you turn off System Restore (Win XP) before attempting manual removal? After you successfully remove the malware, reactivate System Restore.

    --
    Ignorance is curable, stupid is forever.
  40. dont install something to uninstall a trojan by mozkill · · Score: 1

    hey guys, its not really adviseable to install anti-spyware software in order to get rid of a specific trojan. what you might end up doing is installing something that disables your trojan but then it installs another trojan(s).

    i would recommend backing up your files, doing a windows re-install (takes 1-2 hours), install microsoft anti-spyware ONLY and then just being more careful in the future.

    --

    -- Betting on the survival of the media industry is a serious risk. I advise investing elsewhere.
    1. Re:dont install something to uninstall a trojan by chivo243 · · Score: 1

      In reality, it is someone else's system... he can only advise, as I do with all the requests I get for this very problem.

      --
      Sig Hansen?
  41. Bart PE by p7 · · Score: 3, Informative

    You might want to look into Bart PE. It is a program to create a bootable cd that runs Microsofts Pre-execution Environment. There is a plugin for Ad-Aware, and you may be able to find plugins for Spybot-SD and MS Antispyware beta (not sure though). This is useful, because you are now running a lite version of your MS os from the CD. The antispyware software should now have a much easier time removing files, since the os won't have them open.

    1. Re:Bart PE by Kelerain · · Score: 1

      The Ultimate boot cd for windows is a system built on Bart PE, with a lot of helpful utilities on it for just this kind of thing. It had adaware, hijack-this and a few other anti-spyware applications bundled, as well as antivir antivirus. I highly recomend it for removing malware.

  42. http://www.nu2.nu/pebuilder/ by Anonymous Coward · · Score: 0

    Here is the link to save some time.
    http://www.nu2.nu/pebuilder/

  43. Reformat and don't be a moron by Anonymous Coward · · Score: 0

    How about reinstalling Windows and then setting up a limited user account for daily use so this crap never happens again? Seriously, anyone running as admin on Windows is just asking for a borked system. You could also spend hours trying to fix malware and still not be sure if it's all gone; might as well spend that time on a sure-fire fix.

  44. cleaning the stubborn ones. by Deathlizard · · Score: 4, Informative

    your going to want to get a few things first, and your going to need some time to do this.

    First get these. do a google search if you dont know where to get them.

    HijackThis
    Microsoft Antispyware
    spywareblaster
    winsockfix (it's at majorgeeks if you do a google search)

    First off, make a restore point, then if you cant get online at all run the winsock fix which should fix that, then install spywareblaster, update it and enable all protection

    From there update all of your existing anti-virus/anti-spyware to the latest revisions and defs, Then Install Microsoft Antispyware and update it to the latest defs. The reason you want MSAS is because MSAS will start prompting about any questionable activity it detects. make sure you set anything it considers questionable to block or remove. This will at least give you a general Idea what to look for and keep the reinfection down to a point. Then in MSAS, do a full system scan. Remove everything that it finds and restart the PC in safe mode with no network.

    When it boots up in safe mode, stop and keep in mind that if you open up any explorer windows you just reinfected your PC again, so make sure everything you need is on the desktop or accessable in the start menu. From there do another scan with MSAS, as well as any other anti-virus/spyware app you updated in the first part with full system scans. Then using the command prompt, delete everything in the following folders

    C:\documents and settings\\local settings\temp
    C:\documents and settings\\local settings\temporary internet files
    C:\windows\temp

    From there run hijackthis and look it over. anything you see there that looks questionable in there you remove. in particular, startup entries going to temp folders, random named exe files, exe files in C:\windows or C:\windows\system32 and any bho or dpf that you cant remember installing, or has the word search, bar, smiley, sounds fishy or like it's trying to benefit something that should be ok by itself, especially if you dont have it, such as "Microsoft Antispyware Helper" (yes I saw a real nasty one using this as it's name). If you are really in doubt, and have access to another machine, go to http://www.hijackthis.de/en put the hijackthis log into it, and it will tell you what to delete and why. After you clean it up make a clean log from hijackthis and restart.

    From there restart and it should be clear or relitively clear. If it's not, then run hijackthis again and compare it to the old file. It should give you clues on what to look for, but there is a good chance that your system is rootkited (something rootkitrevealer will tell you). If it is, I'd recommend a reinstall since there's no telling whats going on in the background, but if you still need to clean it the only way is to insert the hard drive into another PC and do another full anti spyware/virus scan on the drive. or use pebuilder to boot the machine into windows and do it that way.

  45. Answers lie within! by Anonymous Coward · · Score: 0

    KIRA
    About the deflector array -- is there any way to use it to deactivate the malware?

    ROM
    [confident]
    Nope! I designed the files to be self-replicating. The only way to keep them from replacing themselves is to isolate them in an anti-graviton beam. The deflector array can't do that!
    [Suddenly something occurs to him...]
    Unless... you reconfigured the field generators...
    [confidence crumbling]
    -- and re-focused the emitters...
    [deflated]
    Which would turn the deflector array into one big anti-graviton beam!

    KIRA
    How can we disable the deflector array?

    ROM
    All you have to do to is access the EPS feed and overload the waveguide.

    KIRA
    Let's do it.

  46. Safe Mode by Anonymous Coward · · Score: 1, Informative

    What the hell? So many comments, and nobody has yet mentioned safe mode?

    As every tech support monkey knows, the first thing to try if malware keeps replacing itself is to run your scanner in safe mode, to stop said malware loading itself up in the first place. Upgrade your scanner first while still connected to the net, then restart the computer in safe mode and wipe out the little bastards to your heart's content.

  47. the easier way to do this by foszae · · Score: 3, Informative

    You see, i hate using all these miscellaneous programs to find trojans. partly because i want to go in and quickly fix a person's problems.

    The first thing i recommend is the Startup Control Panel which installs a very handy control panel. It will show you every startup that Windows has, including the registry-only ones that aren't apparent to the user. Install, run, and see what starts with the computer.

    open the Task Manager (Ctrl-Shift-Esc), and using "End Process Tree," shut off any programs that you found in the Startup Control Panel

    Then go in to the Startup Control Panel and turn off their registry entries for startup. If you've shut down the process, it won't reregister. then you can worry about tracking down the files later.

    This has never failed me, regardless of the malware. Frankly, it surprises me how reliable it is. The one other concern is maybe you end up shutting down an infected vital system process (one virus not worth mentioning that infected lsass.exe). If in the process of killing processes, the computer suddenly says it's shutting down in 30 seconds (which happens when you kill the lsass process), then hit Windows-R for a run dialogue, and type "shutdown /a" which will abort the shutdown command, and allow you to continue your cleanup.

    1. Re:the easier way to do this by digitalsushi · · Score: 2, Insightful

      Question for the windows folks. If you're in msconfig and you change it to Selective Startup, is there a way to leave it in this default state with no popups that cancel the effect after rebooting? For my own machine I would be more than happy to be the person initiating everything. You can see clearly that the machine will work fine without loading any of that extra stuff... why cant i just NOT have autoloading events?

      --
      slashdot: where everyone yells sarcastic metaphors to themselves to understand the issue
    2. Re:the easier way to do this by DiscoSnorlax · · Score: 1

      For those who don't have a Windows key (1987 IBM Model M keyboard in my case), ctrl-esc brings up the start menu also, might be able to select run with R from there. (Win-R seems to bypass the start menu entirely?)

  48. Mod parent up please by Banner · · Score: 1

    Good advice.

  49. Only one gurantee by pbaer · · Score: 1

    Back up important files (finacial data etc.) format and reinstall the OS.

    --
    There are 11 types of people, those who know unary and those who don't.
  50. Try Broadband Reports' security forum... by antdude · · Score: 1

    I see a few threads in Broadband Reports' security forum.

    --
    Ant(Dude) @ Quality Foraged Links (AQFL.net) & The Ant Farm (antfarm.ma.cx / antfarm.home.dhs.org).
  51. Check the HOSTS file as well!!!!!!! by barc0001 · · Score: 1

    I ran into something nasty like this last night on an aquintance's computer. I was sure after using Spybot, Ad-Aware, msconfig, etc. that I had gotten everything, but still weird pop ups were appearing even when I started the browsers, both IE and Firefox (home page was set to be Google). Then I noticed that the search results I was getting from Google were a little... off. Also, I noticed Google and Yahoo and a few other sites were running a little slow. No idea why I looked, but I decided to have a boo at the HOSTS file on the machine, and lo and behold, it's stuffed with 7K of redirects. Every search engine, most well known portals, the lot, all going to these bastards instead of where they're supposed to be. Which explained the popups and the slowness. They were taking the query you enter and then firing it off at the real thing and scraping the result.
    I blanked the HOSTS file, and all is good now.

    1. Re:Check the HOSTS file as well!!!!!!! by loddington · · Score: 1

      Spybot has this feature and can add its own enties redirecting known bad sites to 127.0.0.1, it then locks the hosts file to stop any unauthorised additions.

      You need to use spybot in advanced mode to find this setting.

      Dunc

      --
      --- Who put this sig here? ---
    2. Re:Check the HOSTS file as well!!!!!!! by barc0001 · · Score: 1

      ah! Good to know. I never deal with this crap on my box, so I am somewhat a fish out of water when others call with this problem and I have to bail them out.

    3. Re:Check the HOSTS file as well!!!!!!! by jasonmicron · · Score: 1

      Same deal with AdAware & HijackThis (though the latter doesn't lock it, it just tells you if there is anything in there that shouldn't be).

  52. Can't do when 'hot' by x_terminat_or_3 · · Score: 1

    Hi frustrated person.

    I think it is almost *impossible* to do this while windows is running since there are ways to hide a process from the process list.

    Even when starting windows in 'safe' mode, the program can be loaded in memory.

    I suggest using a Live CD (like Knoppix) and mount your ntfs partition there. Writing to NTFS is supported these days. If you are afraid to screw your ntfs partition by deleting files, then you might want to do cat '' > file so that the disk structure doesn't change but you actually erase the contents of the file.

    * prepare
    In windows, identify as much related files as possible
    * Boot from Live CD
    Erase those files

    Optionally
    * use a 'offline' registery editor to remove the offending keys from the register. (google for it)

    Boot windows
    If needed, repeat steps

    An additional note on the Live CD. Every good computer guru has one in its toolbox. Even if you are called to repair only windows systems, then still it has great use. Most Live CD's detect configure automatically all the hardware and the internet connection so if you are missing a driver to start windows, just pop in your Live CD, download the driver and restart in windows.

    While you're at it, why not ask your friend to switch to 'nix for its daily taks (Surfing, Email, Chat, Office, Multimedia,...) and switch to Windows for games?

    Kind regards

    x_terminat_or_3

    --
    Only those who risk going too far can possibly find out how far they can go. T. S. Eliot
  53. Re:knoppix & ntfs by jago25_98 · · Score: 1

    I couldn't get knoppix or knoppix STD to mount NTFS r/w.

    I tried `mount -t captive-ntfs /dev/partition /mnt` but it said that captive wasn't included in both versions.

    I don't fancy having to roll my own.

  54. I know, I know, I know but seriously by Dark+Coder · · Score: 1

    Isn't any of this a viable option for the ubergeek?

    1a. Move your precious stuff to another partition.
    1b. Insert a OSS distro (FreeBSD, BeOS, Linux, Solaris x86)

    I don't know many applications not found on OSS (www.freshmeat.net, sourceforge.com, www.acroread.com, openoffice.org, gimp.org, mysql, Perl/PHP, C++ compiler) that can be done reliably in place of Microsoft Windows.

    I mean, I got everything I need so far, why bother with the pain of many unsecured Windows APIs?

  55. Crude but effective by mister_jpeg · · Score: 1
    Most of the malware I've seen lately has a watchdog process guarding the registry in addition to the spyware. You'll see something like wkjtis.exe in the process list in addition to bargains.exe.

    I find the name of that process with HijackThis, which also gives the filename. It'll be in %system32%, and the spyware will be in Program Files.

    The directory in Program Files will have a few .dat files which contain the .exe and the .dll in %system32%. Obviously when you delete the reg key loading the dll, or delete the spyware .exe, the process spawned from the .dll will rewrite either.

    My strategy is to keep a copy of vi.exe around. I can vi the .dat, dG the file (deleting all the contents), write it, and bingo! done. It appears console apps don't go throught the same permissions layer that Windows Explorer does.

    So I:
    - kill the spyware process
    - vi and delete the contents of the .dat
    - kill the process launched from the dll
    - let HijackThis delete the registry entry calling the dll
    - vi and delete the contents of the .dll
    - vi and delete the contents of the spyware .exe
    - reboot if necessary.

    It's important to note that thesse things hook into Explorer, so opening a new Explorer or IE window starts them again. Don't do that during this process.

    I have to say I'm impressed with the watchdog processes. I've always been reminded of this ccool hack when fighting them.

    --
    -jpeg
  56. Alas Microsoft by fm6 · · Score: 3, Insightful
    I notice that nobody has had the courage to point out that AdAware and Spybot are no longer the leading antispyware tools. The leader is (gasp) Microsoft Antispyware, and it catches a lot of stuff Spybot misses. Though Spybot also catches a few things MA misses. As for AdAware, it's fallen so far behind I rarely bother with it.

    I still have one small piece of spyware hiding somewhere that none of the above can find. It only runs when I run IE (which I very rarely do these days), pathetically raising popup windows with nothing in them! I haven't bothered to chase it down, since it isn't that much of a nuisance. But maybe I'll apply some of the tricks I learned today, just for the exercise!

    Which brings me to the #1 anti-spyware measure: run Internet Explorer as little as you can!

    1. Re:Alas Microsoft by ArielMT · · Score: 1

      The main reason MS-Antispyware Beta is so good is because MS only recently just bought the anti spyware company GiantCompany.com and Giant Antispyware came as part of the deal. MS just hasn't finished microsofting Giant Antispyware yet. Trust me, from twenty years of seeing the wheat that is the typical MS beta turned into the chaff that is the typical MS final product, Microsoft Windows Antispyware will become so ineffective (and possibly destructive) that it might, just might, become the first Microsoft product to be officially declared spyware by the compsec industry.

      --
      It must be Windows. It needs half a gig of RAM and a hardware-accelerated graphics card just to run Solitaire.
    2. Re:Alas Microsoft by fm6 · · Score: 1

      You're quite right -- Microsoft has a unique ability to screw up perfectly good products, and will undoubtedly turn Giant Antispyware into a piece of crap eventually. But until they do, it's the #1 antispyware product, and should be in every consultants toolset.

  57. Switch off System Restore by petefine · · Score: 0

    I'm no expert on this kind of thing, but I have found/read that somehow this kind of software can regenerate itself via system restore. Disable XP
    System Restore, (My Computer->Properties->System Restore), then run you're virus scanner/spyware detector etc again.

    This has saved a couple of friend's PC's from being reformatted, so it's worth a try.

    Peter

  58. This is hilarious... by adjuster · · Score: 0, Redundant

    The discussion threads for this article are killing me! You silly little Windows users w/ your cadres of anti-"spyware" programs, your bordering-on-mythos secondhand, thirdhand, and forthhand instructions on how to remove these unwanted programs, and your fun little superstitions-- you're hilarious!

    I run Windows 2000 Profesional on a couple of my boxes, but I don't have a "spyware" problem. It baffles me that anybody else does, at least with any of the NT-based Windows OS's.

    • Don't logon as a user with administrative rights except when absolutely necessary. If an application doesn't run right as a non-Administrator user, figure out why and fix the permissions causing the problem, or get a better app. There's no excuse for needing to run apps as an Administrator user in 2005.
    • Don't install crappy software that you're not sure the origin of. You're monumentally stupid to install most peer-to-peer file sharing apps.
    • Password protect all the user accounts on the PC with reasonably good passwords, lest file-and-print-based self-replicating programs copy themselves onto the PC via default "Administrative shares".
    • Keep up-to-date with operating system and application patches.
    • Consider using a browser other than Internet Explorer and a mail reader that doesn't use the IE engine to render HTML. Better yet, stop using HTML email.
    • Install the OS with the PC disconnected from a LAN. Apply service packs and fixes via CD before plugging into the LAN.

    Is it really all that hard?

    The most hilarious things are the myths and superstitions. I liked the dude who suggested you should "unplug" the computer after removing "malware", because "Some malware will try reinsert registry keys at shutdown". That's suitably vague, and dangerous! Instead of just explaining WinLogon Notification Packages (the way that most of this unwanted software handles re-populating the registry with its references on shutdown) and how to disable them, the author just suggests you risk trashing your filesystem! It highlights the fact that most of you little Windows puppies don't have any idea how the OS works.

    I'd clean a contaminated PC up by putting the contaiminated hard disk into a clean Windows PC, accesing the registry hives of the contaminated PC, and cleaning up its filesystem and registry carefully. Then you don't have to muck around with hostile programs detecting that you're excising them and trying to put themselves back. Don't have a second PC to do that on? Get a second hard disk drive, pull the contaminated one, install a clean OS on the new drive, then strap in the contaminated drive and clean away? (Don't boot the contaminated disk, though, or you get to start all over again.) Can't afford that? Use some rigged bootable CD thingamagig and take your chances... Sucks to be you.

    The trick of using NTFS ACL's to deny the unwanted software access to its own files is cute, but the authors of this software are already working around that. They usually have SYSTEM privileges-- they don't need to worry about ACL's if they don't want to. In general, the days of troubleshooting contaminated PC's while booted in the contaminated environment are fast drawing to a close.

    This is the state of the art in our industry... Sheesh. I'm so proud to work in IT.

    --
    The Attitude Adjuster, I hate me, you can too.
    1. Re:This is hilarious... by barc0001 · · Score: 1

      Great! Now just get your sister, and parents, and random associates to do all of that, and you'll never get calls at 10 at night begging for help with this.
      If you'll read most of the comments, it's usually not POSTERS with the problem, but rather relatives/friends/associates/coworkers. Since I myself don't have a spyware problem, I usually find myself less than entirely equipped to deal with others' problems out of the gate due to lack of first hand experience.
      Which is, you'll note, the impetus for this Ask Slashdot. Unless the poster means themselves when they say their "friend"

    2. Re:This is hilarious... by $mooth · · Score: 1

      What a pompous dumbass

  59. Aurora is FAR more malicious than that. by mosel-saar-ruwer · · Score: 4, Interesting

    step 5) open the registry (RegEdit) and search for "RunOnce"; directly above it will be "Run".

    Sadly, you can't do that with Aurora [I was up with it until 5AM last night, and I'll be at it for the rest of tonight, and much of tomorrow]. I'll expound on the registry stuff in a moment, but first let me outline a few other things you'll have to deal with.

    Aurora installs at least two services [Start | Programs | Administrative Tools | Services]; they're down at the bottom, called "Win" this, and "Win" that [I forget the exact names, but they're pretty obviously malware services]. It also installs executables and "cabinet" [.CAB] files all over your computer, as well as desktop links and web browser plugins, and probably a whole host of other things I didn't discover. And every user who logs in after the infection will get copies of this crap installed throughout the entirety of their "Documents and Settings" folder.

    If you have a second copy of the operating system [at worst, take the hard drive out and install it in another computer as a secondary drive], then you can search the entire hard drive for files that were introduced on or later than the date of infection and delete MOST of the crap that was installed.

    However, in our case, the underlying file that invoked "Aurora" was \WINNT\zbkiebmtvti.exe [it might have a different name for you], but it was somehow installed with a modification date of 04/09/2004 [our infection was yesterday, 05/08/2005], so a simple search on recently-modified files will not find that one [and may not find other newly-introduced files, with fake modification dates, that are lurking in other parts of your hard drive].

    However, even if you disable the services installed by Aurora, and even if you could delete all the files it installs, it does something FAR more malicious - something that I've never before seen in malware, which gets back to the point I wanted to make at the beginning of this reply: At or near the registry point HKLM\Software, Aurora inserts an "infinitely large" subtree into your computer's registry [I assume that they used either the maximum size of a registry subtree in Windows, or the maximum size of an entry in the underlying MSJet database, or something similar]. When either regedit.exe or regedt32.exe encounters this "infinitely large" subtree, they both crash, and tend to exit Dr Watson style [I guess it never dawned on the poor guys who designed regedit.exe and/or regedt32.exe that someone would do something quite so evil]. You can't search beyond this "infinitely large" subtree, and neither regedit.exe nor regedt32.exe are capable of deleting any of its branches [at either the beginning of the subtree, or at its end], so you can't do the old trick of searching for "RunOnce" and then moving up one key to get to Run.

    Anyway, it seems to me that anyone who would do something as malicious as purposely inserting an "infinitely large" subtree into your registry, with the intent of crashing regedit.exe and regedt32.exe, is precisely the sort of person who would install a keyboard sniffer to record your VISA and Mastercard info. So I'm basically wiping the drive clean and reinstalling the operating system from scratch.

    Quite frankly, if I ever meet the bastards who wrote this crap [and who thought that it would be some kinduva nifty-cool business plan to go around inserting "infinitely large" subtrees into people's registries], then I will be sorely tempted to shoot them and throw their God-damned corpses in a swamp.

    And no, I am not kidding.

    1. Re:Aurora is FAR more malicious than that. by SleepyHappyDoc · · Score: 2, Funny

      Quite frankly, if I ever meet the bastards who wrote this crap [and who thought that it would be some kinduva nifty-cool business plan to go around inserting "infinitely large" subtrees into people's registries], then I will be sorely tempted to shoot them and throw their God-damned corpses in a swamp.

      Perhaps you can find a 'registry' to shove that 'infinitely large tree' up.

      --
      Stasis is death. Embrace change.
  60. Removing the (almost) worst malware by Zaffle · · Score: 1

    I had a piece of malware that had hooked itself in the WinLogon api, so even in safemode the malware ran.

    If you went into safemode, and removed the registry entries, it would put itself right back in.

    The file couldn't be delted even in safemode because the process locked the file.

    The solution was, in the end, easy:
    Boot to a WinXP/2000 recovery CD, go into recovery console (DOS), delete the files from there, reboot.

    Windows may complain about the lack of the files, but removing the registry entries then, tidies it all up.

    Try to figure out which exploit the malware used to get it, and patch it.

    Oh, and why is this the almost worst? The worst is malware that hooks in at kernel level and intercepts all the api calls and removes itself from every list (directory list, process list, memory usage list, everything). You can pop into DOS, do a DIR /ah and still not see it. The file and process is effectivily hidden. The process also removes its own entries from the registry, so when you list a regkey, it doesn't appear, even though its there.
    With this piece of malware, the only way to remove it is as follows: Produce a complete filesystem list from windows with the filename and md5sum. Then boot to a CD (eg knoppix) and produce the same filesystem list with name and md5sum, compare the results. Files that appear in the 2nd list are ones that are hidden (or unreadbale).
    Thats a bitch to remove, i'm just hoping someone will write the tools to do it for me. :)

    --

    I use to have a funny sig, but slash cut it off, and I forgot what the punchline was.
  61. MOD PARENT UP by kkerwin · · Score: 1
    In all honesty, this is probably the simplest solution.

    In my humble opinion, nuking a Windows machine every six months or so can be a healthy thing anyway, so long as important files are preserved. I typically nuke my Linux partitions on a comparable time frame, also. It's just a good way to clean up.

    If the above partitioning idea doesn't work or is not feasible (say the solution is too complicated for the user), teach the user to make regular backups on CD, or to invest in a 1Gig thumbdrive or so, and keep his personal files there.

    Kris Kerwin
    kkerwin@insi__REMOVE_ME__ghtbb.com

    --
    Kris Kerwin kkerwin@insi__REMOVE_ME__ghtbb.com
    1. Re:MOD PARENT UP by eclectro · · Score: 1

      I have yet to meet a windows machine that didn't need a yearly reinstall for one reason or another.

      --
      Take the cheese to sickbay, the doctor should see it as soon as possible - B'Elanna Torres, "Learning Curve"
    2. Re:MOD PARENT UP by Angelyne · · Score: 1

      Amend to that. I reinstall at least every 6 months, which keeps my computer running fast and smooth. This is made quite painless by keeping all of my documents and settings on a separate drive. There are no better clean up than that !

  62. What's the problem here? by corvid13 · · Score: 1

    A Mac Mini is only $500.00. . . .

  63. After deleting, to prevent re-infection by peter+hoffman · · Score: 1

    If I find the malware was in a directory like C:\Program Files\Malware\ I delete the directory and then create a file with the same name. I put some text in the file like "This is here to prevent Malware infections." and then I change the mode to be read-only and hidden.

    Not perfect but it helps and I haven't seen it mentioned here.

  64. MOD GRANDPARENT UP by Anonymous Coward · · Score: 0

    Because he's right.

  65. Manual "clean", huh? by RomulusNR · · Score: 1

    ...I've had to try to manually clean the system. However, the files re-write themselves, making the malware grow back as fast as you can remove it.

    Files don't suddenly become sentient and rewrite themselves, so the "manual clean" you did clearly didn't actually clean it. Probably, a running or startup process stuck around to restore them.

    Ideas:
    1. Reboot in safe mode, and do your manual cleanup. See if it recurs in normal mode.
    2. Kill as many processes as possible before running a malware cleaner.
    3. Instead of deleting identified malware files, replace them with blank read-only files, and reboot.

    --
    Terrorists can attack freedom, but only Congress can destroy it.
  66. Anti spyware tool by dodobh · · Score: 1

    Click here or here or even here

    --
    I can throw myself at the ground, and miss.
  67. symantec finaly got something right by cwraig · · Score: 1

    Symantec Ghost is one of the single most useful programs ever written 1) do a format with a windows partition and a data partition and do a clean windows install 2)install all the apps you generaly use 3)run mircrosofts powertoy tweakui and move all the important folders from your windows partition to your data partition for example i move Desktop favorites My docs ...music...pics etc ive also got batch files written to copy my media library files and other assorted usefull files to the data partition on every shutdown 4) run ghost and backup your system. This solution has a number of advantages *from a 4gb ghost image i can be back at my login screen in about 3and a half mins. Clean and crisp like windows installs always are :P (for the first few hours) *any trials you intall after this point will have their 30day counters restarted when you ghost again *if you really wanted you could have your machine ghost itself every night at say 5am that way its clean everyday without any hassles Just an idea... it works for me good luck Cwraig

  68. Stopped using IE by g0bshiTe · · Score: 1

    I stopped using IE unless I absolutely have to, I modified my hosts.deny to incorporate most redirects to known spyware sites. I have disabled all Javascript execution no matter the browser. I also have had to write programs that removed these nasties. I have had a few that refused to die, while trying to ressurect a WinXP box for a freind. Since XP doesn't allow for true SafeMode Command Prompt Only booting ( I say that cause it loads thet malware anyways ) I had to write a program that simply deleted them and their respective registry entries before they were loaded into Windows.

    Surprisingly enough adding a Reg entry into the Run folder of the registry is all that was needed to have it run before they did ( which I found a problem ) I had to first export the Key and add my entry first as apparently Windows executes registry entries in order of installation. This cured my problem from even the most hardened malware.

    Unfortunately there is no one cureall app out there yet, best to go with an army, X may not catch Y etc etc, but using X, Y, and Z apps together you are assured to catch and stop much more than using any single one as a stand alone.

    --
    I am Bennett Haselton! I am Bennett Haselton!
  69. XP? by phorm · · Score: 1

    Anyone tried this on XP (don't have an available XP machine at the moment)

    1. Re:XP? by canadiangoose · · Score: 1

      It should work on any version of NT that includes the task manager and task scheduler, which I believe is all of them. I've personally tested it on everything from NT4 to Server 2003.

      --
      Never eat more than you can lift -- Miss Piggy
  70. Absolutely, without a doubt! (NT) by ArielMT · · Score: 1

    Absolutely, without a doubt!

    --
    It must be Windows. It needs half a gig of RAM and a hardware-accelerated graphics card just to run Solitaire.
  71. Nothing is untouchable... by msimm · · Score: 1

    BHODemon should let you peak at your browser help objects and remove those that don't belong.

    --
    Quack, quack.
    1. Re:Nothing is untouchable... by fm6 · · Score: 1

      Microsoft Antispyware includes a BHO editor. Though I may have forgotten to run it...

    2. Re:Nothing is untouchable... by msimm · · Score: 1

      Then your covered. I was pretty supicious when I tried the beta (MS) but it did do a decent job. I'll keep my toolset varied though, its an arms race and every product slips up at some point.

      --
      Quack, quack.
    3. Re:Nothing is untouchable... by fm6 · · Score: 1
      You're damned right about it being an arms race. The way malware gets more and more sophisticated is the most amazing/scary thing that doesn't involve WMDs!

      You're also right in wanting a varied toolset. Unfortunately, that doesn't do as much good as it should. LavaSoft has never put as much work into AdAware as they should, probably because they promised Steve Gibson that they'd always provide a free version of his invention -- which kind of removes their profit incentive. Spybot has only recently stopped being more than a hobby project, and is still overdependent on volunteers and donations. Established security companies like McAfee and Symantec waited way too long to enter the market, and their products are still pretty immature. Who else is there?

  72. What to do if Malware cannot be removed by Anonymous Coward · · Score: 0

    Install Ubuntu Linux.