Dos_Box Posted June 20, 2006 Posted June 20, 2006 Right. I came back yesterday to find one of our desktop systems infected (so much for Windows Defender!). It's recurrent spywear and since this morning I've taken the following actions to remove it (it keeps coming back the little tyke!) 1. Ran Windows Defender with Delte set on all options. It said it found nothing. 2. Ran Ad Aware. Again it found nothing. 3. Ran Spybot S&D. It found lots and removed them 4. Deleted all of the system restore points. 5. Deleted the startup entries. 6. Cleared all temp files and temporary internet files maually, just to be sure. 7. Rebooted. 8. Watched the pop-ups start again. Any extra ideas would be greatly appreciated.
Geoff Posted June 20, 2006 Posted June 20, 2006 1. IE BO? 2. win.ini run= ? 3. win.ini shell= ? 4. Startup program group? 5. Device driver? 6. Service? Also bear in mind, the spyware might be using a rootkit to hide itself. All in all, I'd suggest you format/reimage. It's quicker.
Dos_Box Posted June 20, 2006 Author Posted June 20, 2006 I'm consideriung the last option, belive me. I did try the other options you listed too.
indiegirl Posted June 20, 2006 Posted June 20, 2006 Believe it or not, I've found spyware sat in the root of the C:\ drive in various exe forms... not sure it'll help you. Have you got your Sys Restore turned back on? Does it still pop up if you turn sys restore off? (I'm sure you've looked at that... but just thought I'd check)
DMcCoy Posted June 20, 2006 Posted June 20, 2006 Its probably hidden from windows by a rootkit running as a driver. Try this http://www.sysinternals.com/Utilities/RootkitRevealer.html to find any suspicious files. I found one on a relatives machine, most informative. Safe mode helps if its a driver.
krisd32 Posted June 20, 2006 Posted June 20, 2006 when doing spyware searches i always run in safe mode as most of the time they will not be running then and usually 100% fix rate on all machines with adaware and safe mode also go into registry hklm\software\microsoft\windows\current version\run - and all the other run options and delete all the keys that you don't recognise.(hkcu aswell same path but usually everything resides in hklm) as i said i do this on any pc with spyware issues and found it to be 100% effective!
mac_shinobi Posted June 20, 2006 Posted June 20, 2006 boot up into safe mode with networking ( That way you can still access the internet to get things ) I would suggest ewido from http://www.ewido.net , spy sweeper from http://www.webroot.com Make sure to update the defintions for ewido and spy sweeper. As for things starting up with windows get startup control panel from http://www.mlin.net ( great little utility ).
Ric_ Posted June 20, 2006 Posted June 20, 2006 I oncew had a piece of malware that launched as part of the shell, attaching itself to explorer. This was hidden in the registry.
Dos_Box Posted June 20, 2006 Author Posted June 20, 2006 boot up into safe mode with networking ( That way you can still access the internet to get things ) I would suggest ewido from http://www.ewido.net , spy sweeper from http://www.webroot.com Make sure to update the defintions for ewido and spy sweeper. As for things starting up with windows get startup control panel from http://www.mlin.net ( great little utility ). I already use Startup COntrol Panel. The entries keep re-installing themselves on the fly (aaaarrrrgggghhhhhh!) So far I've had no joy, not even with the Sysinterals rootkit proggy.
_Bob_ Posted June 20, 2006 Posted June 20, 2006 yes there's probably a couple of processes running and monitoring each other. In the past i've gone into safe mode and wiped out everything in the startup reg etc with msconfig. Then hit F5 to refresh and check which ones have re-registered themselves. Those will be the evil ones!
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now