Jump to content

Recommended Posts

Posted

Right. I came back yesterday to find one of our desktop systems infected (so much for Windows Defender!). It's recurrent spywear and since this morning I've taken the following actions to remove it (it keeps coming back the little tyke!)

 

1. Ran Windows Defender with Delte set on all options. It said it found nothing.

 

2. Ran Ad Aware. Again it found nothing.

 

3. Ran Spybot S&D. It found lots and removed them

 

4. Deleted all of the system restore points.

 

5. Deleted the startup entries.

 

6. Cleared all temp files and temporary internet files maually, just to be sure.

 

7. Rebooted.

 

8. Watched the pop-ups start again.

 

Any extra ideas would be greatly appreciated.

Posted

1. IE BO?

2. win.ini run= ?

3. win.ini shell= ?

4. Startup program group?

5. Device driver?

6. Service?

 

Also bear in mind, the spyware might be using a rootkit to hide itself.

 

All in all, I'd suggest you format/reimage. It's quicker.

Posted

Believe it or not, I've found spyware sat in the root of the C:\ drive in various exe forms... not sure it'll help you.

 

Have you got your Sys Restore turned back on? Does it still pop up if you turn sys restore off?

 

(I'm sure you've looked at that... but just thought I'd check)

Posted

when doing spyware searches i always run in safe mode as most of the time they will not be running then and usually 100% fix rate on all machines with adaware and safe mode also go into registry

 

hklm\software\microsoft\windows\current version\run - and all the other run options and delete all the keys that you don't recognise.(hkcu aswell same path but usually everything resides in hklm)

 

as i said i do this on any pc with spyware issues and found it to be 100% effective!

Posted
I oncew had a piece of malware that launched as part of the shell, attaching itself to explorer. This was hidden in the registry.
Posted
boot up into safe mode with networking ( That way you can still access the internet to get things )

 

I would suggest ewido from http://www.ewido.net , spy sweeper from http://www.webroot.com

 

Make sure to update the defintions for ewido and spy sweeper.

 

As for things starting up with windows get startup control panel from http://www.mlin.net ( great little utility ).

 

I already use Startup COntrol Panel. The entries keep re-installing themselves on the fly (aaaarrrrgggghhhhhh!)

 

So far I've had no joy, not even with the Sysinterals rootkit proggy.

Posted
yes there's probably a couple of processes running and monitoring each other. In the past i've gone into safe mode and wiped out everything in the startup reg etc with msconfig. Then hit F5 to refresh and check which ones have re-registered themselves. Those will be the evil ones!

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...