Click to See Complete Forum and Search --> : Adware and Spyware removal :Introduction:


foxyloxley
January 21st, 2005, 12:38 AM
An Attempt to put into one place a small tutorial, that will [hopefully]
be used as a link for all of those threads that ask the same question:

How do I get rid of pop-ups / adware / spyware?

There is a plethora of software tools out there, waiting for you to take them home, I will just stay with the ones that I have used myself, as I believe that if I can use it, then it really IS idiot proof. I have included tools that are freeware as well as those that require you to buy them to get the full options.

I have concentrated on the adware, spyware problem, and as such I haven’t mentioned Anti-Virus, or Firewalls, as I think that each PC SHOULD have those as a MINIMUM defence, I’m just adding my little bit to the extra defences required in today’s PC environment.

Where an OS is mentioned, I am basing it on Windows, as I run W2K Pro. XP will be very similar.

To combat this problem you should have the following in your armoury at least:

Google tool bar: http://toolbar.google.com/ The reason for this selection is that I think that this item should be on everyone’s PC, and it has a pop-up blocker built in. Google themselves keep information from you for their own use, but you do have the option to disable this as you install. Also there are a few extra items that the toolbar runs that are not strictly required, they can all be disabled in the options tab on the toolbar itself.

AdAware SE: http://www.lavasoft.de This one is the one that everyone SHOULD know about.

SpyBot S+D: http://www.safer-networking.org/en/download/index.html
Get its immunization mode running in the background, stopping the bad stuff from even getting in.

Swatit: http://swatit.org/ Bots and Trojan cleaner. It is said to be slow, but it is effective.

CWShredder: http://www.intermute.com/spysubtract/cwshredder_download.html
This is a very quick worker, and very easy to use.

Crap Cleaner http://www.ccleaner.com/
I'm adding this, as there are a lot of supposedly temp files that can be cleared away safely, that are scattered all over the drive, and this one tool will remove damn nigh all of them in one hit.
Just leave the default settings, and run it.

Spyware Blaster http://www.javacoolsoftware.com/spywareblaster.html
This is software that will stop the bad guys from even getting onto your PC in the first place. Again, it's a free download, and it's a load and forget device, even has auto-update enabled for us really forgetful types.

Prevx http://www.prevx.com/
Another piece of software that detects when the registry is being changed, and will alert you to it, to let you decide whether to allow / disallow.
One tip. suspend Prevx protection when you are loading software, as it will question EVERYTHING that you are doing :)
15 day free trial. But it works so well I PAID for it ......

HiJackThis: http://www.merijn.org/downloads.html
This will give you a list of everything that has loaded up, and is running on your system. It will allow you to delete them, but be warned, this is a very dangerous tool if used without care. Check in AO tutorial index for instructions on use.

Itty Bitty Process Manager: It is also found at Merijn.org, to see why this has been included:

Small update: I've been seeing more and more cases of infections by trojans that kill any antivirus or antispyware programs you try to use and remove them. For such cases, I created a standalone version of the 'Itty Bitty Process Manager' inside HiJackThis. It should be a bit harder for trojans to detect, since it has no window caption. If they do start targeting it by filename, rename the executable before running it and you should be good to go.

Registry Cleaners:
I use Registry Mechanic, and I’ve recently discovered Macecraft, and their RegSupreme. Both work well, but I find that RegSupreme to be the easiest of these to use.

Registry Mechanic: http://www.winguides.com/

Macecraft: http://www.macecraft.com/

And finally, I would advise everyone to keep their system updated with the latest patches, as and when they are available.
For Windows: http://v4.windowsupdate.microsoft.com/en/default.asp
This is for Win2K and is V4, if you are running XP, then it will be V6 as the latest, and it will download the latest software to allow you to use this version before you can get any updates.

To help keep these neat and tidy, I open a new file in Program Files, called 'Security'.
Download each tool there.

On your desktop, in the tool bar at the bottom [default position] of the screen,
right click, and click on toolbars, then on 'quick launch'.

Right click inside the quick launch area, [if none seen, right click toolbar, click on 'unlock toolbar'.] select open folder, inside there, right click and select 'new folder', label it 'Security'.
Close it down, you will now have a Security folder icon in the quick launch section.

Go to the Security file, open each application, and right click on the .exe that would open it.
Select 'send to desktop'. You now have all the shortcuts on your desktop.

Click on the Security folder in quick launch, reduce the size of the window so that you can see the short cuts, drag and drop each one into the folder. Close folder. You now have your security tools ready to use at a moments notice ....................

Now to run our new toys:

First rule: Only run one application at a time……… Conflicts will happen if two applications are trying to clean the same fault.

You need to update each tool, prior to using it, to ensure that you are using the latest version. Remember to open, update then CLOSE each application, before you update the next one.

If you are running XP, then shut off the system restore [Right-click My Computer, select properties, then System Restore tab, then tick/check the Turn off System Restore.]

This is an application that keeps a back up of settings of your system, and if you are infected, it is possible that the restore option would 'restore' the baddies. That is the reason I say switch it off first.

However, if you are a complete novice at this, then it is in your own interest to keep the restore option working, then if you do the worst................ you CAN get out of jail free.

System Restore :
start > all programmes > accessories > system tools > system restore.
If you are going to use the restore option, you might as well set yourself a known good restore point, at least it will be back to where you began.

Check the 'create a restore point' click next ........then enter the description for the point ....... start point would do, then click create. You now have a point to return to IF it goes wrong.

Ideally you should be in Safe Mode to run these tools, as this is a mode that only starts the bare minimum of applications to get you running, and [hopefully] none of the problem programmes will start.

Safe Mode is accessed on start up, by tapping on the F8 button [some systems use F2 / F10] repeatedly, until a screen opens with a menu of safe options.

AdAware, SpyBot, Swatit and CWShredder can be run, and whatever they find is fairly safe to remove straight away.

HiJackThis and the stand alone Itty Bitty Program Manager are a little different, in that they will generate a comprehensive list of running processes on your system, then it is up to you to decide what should be there, and what should not. BE WARNED, once deleted, it’s GONE. And you can do a lot of damage to your system if you do it wrong.

You can always save the file as a .txt in notepad, and post it on AO for help in deciphering what, if anything, is wrong.

The registry cleaners are another special case, these will generate a list of [to them] registry keys that can be removed. BE WARNED, do not mess with the registry at all, if you are not sure, then DON’T DO IT. Run the cleaner, then examine each entry on the list carefully.

As a quick and dirty method, I delete all those identified as obsolete, or non-existent, and I tend to take my time with the others. REMEMBER : if in doubt : DON'T. It is better to leave a suspect setting in the system, rather than remove it and find that nothing works anymore.

To finish, I like to do the windows update now. Get all the critical ones first, then do any stand alone ones [these are the ones that have do be done singularly] Finally get any optional ones for the system, drivers etc.
I like to follow this with Defrag [Right click My Computer, select Explore, Right click on C drive, click on tools] I also do scandisk as well, [now called error checking] same place as defrag, set it to do its work automatically, click OK, the PC will then say it cannot do it now, would you like to start scandisk the next time you start windows. Click yes.

You should now be the proud owner of a cleaner, leaner, faster PC.

PS [If you are running XP, and you DID disable the system restore. Now would be a good time to start it again.]

You should also be aware that there are nowadays, programmes that can and will defeat your tools.
Either by hiding from them, or by switching them off. This tutorial is not addressed at those, it is merely an introduction into keeping your PC as YOUR PC.

Also CuseMMA has a thread (http://www.antionline.com/showthread.php?s=&threadid=267907) that covers this subject from a different perspective.
Worth a read to give a more rounded view of this problem.

And another way here, by brokencrow (http://www.antionline.com/showthread.php?threadid=274621)
if you wish to go about it manually.

[edit] sorting out links
[edit 2] adding points from the posts. restore option / Google tool bar.
[edit 3] Crap Cleaner, Spyware Blaster and Prevx added.
[edit 4] link to CuseMMA's clean up thread.
[edit 5] Windows update now at V6 for XP : system restore details : update apps
[edit 6] Link to brokencrow's manual removal thread added
I'll add tools as and when I've used them, ONLY if they pass the criteria of me being able to use them EASILY :) AND they do what they say they will do.

One final word :
If the software is FREE, but you could afford to pay something, then DO SO.
The more people that do pay towards the cost of these tools, then the more these people will develop their tools.

The Duck
January 21st, 2005, 02:31 AM
Nice tut dude, hopefully we will be getting less of those annoying "help, spyware on my PC" threads.

I would give you AP's but:

You must spread your AntiPoints around before giving it to foxyloxley again.

Not like I can give much anyway lol...

I personally think this should be made a sticky... ?

meeeeeee
January 21st, 2005, 02:41 AM
Very nice. The only thing I would bicker about it turning off system restore before running the tools. Especially as you have the theoretical "idiot" running several different tools including HijackThis & regcleaners. It's easy to make a mistake with those tools if you don't know what you're doing. If someone was to follow your instructions and then do something ignorant and hose their system then they have no system restore left to fall back on.

As I understand it, nothing within system restore can infect the users computer. And everything in system restore is gone when you flush your restore points. There is no need to turn off restore and then run your cleaning apps. Simply disabling and re-enabling system restore after a thorough cleaning is enough to accomplish this.

Other than that, I think it's a nice tutorial that explains the basics on a simple level. Good job!

:)

nihil
January 21st, 2005, 11:02 AM
Nice one Foxy~

I know it is still in Beta, but the Microsoft anti-spyware tool is worth a look..............only for Win2k/XP.

Also EWIDO.............a new scanner/interactive defence. You have to buy the interactive one, but the on demand scanner is free for private use. It has an enormous pattern/signature file of around 90,000 items. You can update the on demand scanner as well:)

http://www.ewido.net/en/

Yes, there are several tools that seem to do the same thing, but each one is liable to find stuff that the others do not, so you cannot rely on a single solution as you might with an AV or firewall.

Cheers

phernandez
January 21st, 2005, 06:38 PM
A good post indeed Foxy.

A little nit about the Google Toolbar, which I like but no longer use (thanks to Firefox). For completely secure browsing, be sure to keep the enhanced options off (pagerank and page info widgets). Sure, the information it sends may be totally benign and you may trust Google with it, but there are privacy implications nonetheless, especially for those that are concerned about programs that transmit info about your Web behavior.

Luckily, Google is very upfront about this when you install the toolbar or choose to activate these options at a later time.

And I agree with nihil, MS AntiSpyware is actually rather good. At least in my experience.

foxyloxley
January 21st, 2005, 08:17 PM
Thanks to everyone for the comments.

Just to point out that in the tut, I did say that I would stick to what I had used myself.

Hence no mention of MS's own anti-spyware, or of a 'more' secure browser [Firefox] to combat pop-ups.

I have recently gone to dual boot with XP Pro on my W2K Pro box. I'll get a copy of the MS Anti-spyware, and try it out on that, as I haven't migrated all my files and settings across yet.

Might even go wild and get me some of that there FireFox I've heard so much about :)

KuiXing-2005
January 21st, 2005, 08:25 PM
A most excellent post! We have been combatting spyware for some time and started compiling a selection of software, many including what you posted and I will be suggesting the one you listed that we don't have.

Quick note: for us the google-tool bar works great, like other people already stated, we recommend not using the enhanced features. Also - if your company or organization uses NetMeeting or Lotus Samtime, the Google-Pop-Up blocker tends to not allow those applications to work properly.

Quick note2: the Microsquish AntiSpyware Beta is also working quite well - it seemed to take less time than AdAware on my boxes, but that could have been my feeling of overjoyness because MS has a security tool that works well.

Again - great work foxy!

KuiXing-2005.

Egaladeist
January 21st, 2005, 10:41 PM
Originally posted here (http://www.AntiOnline.com/showthread.php?threadid=265440#post818589) by foxyloxley
Thanks to everyone for the comments.

Just to point out that in the tut, I did say that I would stick to what I had used myself.

Hence no mention of MS's own anti-spyware, or of a 'more' secure browser [Firefox] to combat pop-ups.

I have recently gone to dual boot with XP Pro on my W2K Pro box. I'll get a copy of the MS Anti-spyware, and try it out on that, as I haven't migrated all my files and settings across yet.

Might even go wild and get me some of that there FireFox I've heard so much about :)

hi,foxyloxley...

just in case you didn't know...firefox has a google toolbar you can download on it...if you already knew...errr...ignore this post.

:D

Computernerd22
January 22nd, 2005, 12:21 AM
Very useful information foxyloxely. This will surely help with the spyware issue. Here are some other useful URLs that have tons of useful information.

http://www.spywareguide.com/
www.spywareinfo.com
www.castlecops.com

I am surprised no one mention modifying the LMHOST file yet. :D

Falcon21
January 25th, 2005, 01:36 PM
I just saw this guide "AntiSpyware Removal Pro" (ebook) today in download.com that briefly talks about spyware and adware. Although it has a ad that link to a program "noadware", it does not mention or promote this program in the guide. Quite a good read.

ams2d
January 25th, 2005, 05:53 PM
Very informative tutorial and I do have a question:

Which programs listed would you add to a "cleaner disk"? Any others would you include?

Why I am asking is I read on another thread about horror stories when members went to visit parents, friends, etc. and they had multiple issues on the systems and the fun they had cleaning those systems.

I want to make a CD of as many of the programs as possible, in case needed and that way I don't have to worry about downloading them and just have them with me.

Thanks!

MoonWolf
January 25th, 2005, 06:55 PM
All of the above. also i dont know about itty bitty process explorer but this one. Can be run from cd

http://www.sysinternals.com/ntw2k/freeware/procexp.shtml

foxyloxley
January 25th, 2005, 07:52 PM
Originally posted here (http://www.AntiOnline.com/showthread.php?threadid=265440#post819183) by ams2d

Which programs listed would you add to a "cleaner disk"? Any others would you include?

Why I am asking is...................

I want to make a CD of as many of the programs as possible.....................



I actually carry this lot on a 128 MB flash memory stick [128 leaves lots of room] I copied the security file completely, when needed [daily at work] I just copy it to wherever it's required.

On CD I carry the above, plus I visited Foundstone : http://www.foundstone.com/index.htm?subnav=resources/navigation.htm&subcontent=/resources/freetools.htm
and helped myself to a variety of tools.

Also use PuTTY : http://www.chiark.greenend.org.uk/~sgtatham/putty/download.html
BEWARE : READ the warnings, it might be illegal in your country..............

I have a fair collection, and to be honest, I haven't began to fully understand the workings on a lot of those I do have.

In short : trial and error still has a lot of life left in its weary old cliched bones.

Just suck it and see...............

Doh !

Just busted those writing rules .........http://www.antionline.com/showthread.php?s=&threadid=265497
5. Avoid cliche's like the plague. (They're old hat)

Falcon21
January 26th, 2005, 06:06 AM
I always have Portable Firefox http://johnhaller.com/jh/mozilla/portable_firefox/ on my zip disk as I don't feel comfortable using IE (a lot of adware and hijackers in my campus computers).

foxyloxley
June 5th, 2005, 11:00 AM
Just added some more tools [edit 3]
and am bumping it to give it air time :)

Aspman
September 23rd, 2005, 10:59 AM
Since this has been bumped anyway....

Could/should this be made a sticky? It's such a common question.

warriorfan808
September 23rd, 2005, 12:09 PM
Thanks for all the great links. The only spyware detection software I've been using has been adaware and spybot s&d. Good to see that there are a whole bunch of great, "free", options out there :)

MrBabis
September 25th, 2005, 11:30 PM
yeehhhh
DrWeb has released cureit utility that can scan comuter for virus and repair
Is free for use, but is very big in size that invcreases with updates,

About:
http://download.drweb.com/drweb+antivirus+free+services/#0

Mirrors for download:
ftp://ftp.drweb.ru/pub/drweb/cureit/
ftp://ftp.drweb.com/pub/drweb/cureit/

miracle
October 4th, 2005, 06:39 PM
One final word :
If the software is FREE, but you could afford to pay something, then DO SO.
The more people that do pay towards the cost of these tools, then the more these people will develop their tools.


Thank you for this ^^^^^^^^^^^^^ disclaimer. People (myself included) don't give enough monetarily to those that are volunteering their time to write tools for the community.

fastnet
October 4th, 2005, 07:01 PM
Also try Counterspy. For me is the best one, also it can run in background mode that helps a lot: www.sunbelt-software.com. Nice tutorial.

ech0
October 4th, 2005, 10:13 PM
Great post foxyloxley! Theres a few programs I've never seen and will check out!

MrBabis
October 4th, 2005, 10:57 PM
ehh... too much but I recommend not go wrong way and get more info about prog (by some search engine and words "you prog namne spyware/help/problem") that you want to download b4 downloading.

This page have much descripton on bad "Anti-Anti"_progs "follow" them who have "good" reputation

http://www.spywarewarrior.com/rogue_anti-spyware.htm

darkcod3r
December 14th, 2005, 01:28 PM
That's a nice article you have there! But I think one more addition will help. Try Secretmaker from www.secretmarker.org. It is a great app... running in the background it helps with things like changes in searchpage/homepage addition/modification to the startup programs etc. It's also got a nice random password generator built in!

foxyloxley
December 14th, 2005, 01:31 PM
link don't work DC :(

as stated in the first post, I am only mentioning those tools that I have tried and found to be simple AND effective............

although I am aware that as time goes on there will be bigger and better out there, and when I find them, and use them, then they will be added ......

Pax