Spyware: how to clean registry and stop returns

R

Ron

Hi, glad you're there for us!

I have an almost inoperable PC that's just two weeks old.
I run WinsXP home, Service pack 1, with I.E Exlorer.
The system came with Norton AntVirus 2004 but I failed to
turn on it's Firewall for the first 2 days.
I added Ad-Aware (Personal SE), SpyBot's (Search &
Destroy), and Registry Cleaner. The systems detect
hundreds of Spyware items, remove many of these malicious
files, and clean up some of their registry entries.
But I'm always always left with enough Spyware and
registry changes that they seem to come back in full
disabling force when I go online.

Question 1:
I realize I need to clean my registry, and it's obvious
that the above applications can't do that ENTIRE
cleansing, but is their an alternative to using "regedit"
and manually removing the hundreds of offending registry
items Spyware created?

Question 2:
I just installed "Spybalster 3.2". It claims to prevent
re-entry of Spyware, and even "prevent it from running on
your system'. Does that mean I can effectively prevent
even the Spyware registry entries from reinstalling or re-
activating these pests?

Thanks, Ron
 
G

Guest

Ron said:
Hi, glad you're there for us!

I have an almost inoperable PC that's just two weeks old.
I run WinsXP home, Service pack 1, with I.E Exlorer.
The system came with Norton AntVirus 2004 but I failed to
turn on it's Firewall for the first 2 days.
I added Ad-Aware (Personal SE), SpyBot's (Search &
Destroy), and Registry Cleaner. The systems detect
hundreds of Spyware items, remove many of these malicious
files, and clean up some of their registry entries.
But I'm always always left with enough Spyware and
registry changes that they seem to come back in full
disabling force when I go online.

Question 1:
I realize I need to clean my registry, and it's obvious
that the above applications can't do that ENTIRE
cleansing, but is their an alternative to using "regedit"
and manually removing the hundreds of offending registry
items Spyware created?

Question 2:
I just installed "Spybalster 3.2". It claims to prevent
re-entry of Spyware, and even "prevent it from running on
your system'. Does that mean I can effectively prevent
even the Spyware registry entries from reinstalling or re-
activating these pests?

Thanks, Ron
 
R

Rock

Ron said:
Hi, glad you're there for us!

I have an almost inoperable PC that's just two weeks old.
I run WinsXP home, Service pack 1, with I.E Exlorer.
The system came with Norton AntVirus 2004 but I failed to
turn on it's Firewall for the first 2 days.
I added Ad-Aware (Personal SE), SpyBot's (Search &
Destroy), and Registry Cleaner. The systems detect
hundreds of Spyware items, remove many of these malicious
files, and clean up some of their registry entries.
But I'm always always left with enough Spyware and
registry changes that they seem to come back in full
disabling force when I go online.

Question 1:
I realize I need to clean my registry, and it's obvious
that the above applications can't do that ENTIRE
cleansing, but is their an alternative to using "regedit"
and manually removing the hundreds of offending registry
items Spyware created?

Question 2:
I just installed "Spybalster 3.2". It claims to prevent
re-entry of Spyware, and even "prevent it from running on
your system'. Does that mean I can effectively prevent
even the Spyware registry entries from reinstalling or re-
activating these pests?

Thanks, Ron

You need to run a combination of programs and do so in safe mode.
You'll need to check for spyware/adware as well as viruses.

In addition to Adaware and Spybot which you say you have (note Adaware
just released a new version 1.05), run these programs to check for
spyware/malware. After installing update them, then boot into safe mode
and run them. You should update and run them weekly.

Cwshredder
http://aumha.org/freeware/freeware.php#cwshred

Pest Patrol Free Pest Scanner
http://www.pestscan.com/ScanOrTrial.asp

If you’re still having problems after running these then run HijackThis
and post the log to one of the specialty forums, _NOT_ this one.

HijackThis
http://www.majorgeeks.com/download.php?det=3155

Forums to Interpret HijackThis Logs:

http://www.spywareinfo.com/forums/
http://forum.aumha.org/viewforum.php?f=30
http://forums.tomcoyote.org/
http://www.wilderssecurity.com/

For viruses start with Trend Micro's Sysclean. After downloading the
program and signature file turn off system restore, boot into safe mode
and run it. Then boot back into normal mode, turn system restore, and
do a complete scan with your AV product. Also do a scan with at least
two of these on line services:

Trend Micro Sysclean
http://www.trendmicro.com/download/dcs.asp

Trend Micro Signature File
http://www.trendmicro.com/download/pattern.asp

Online and Downloadable Virus Scanning:

Panda ActiveScan
http://www.pandasoftware.com/activescan/com/activescan_principal.htm

Bit Defender Online Virus Scan:
http://www.bitdefender.com/scan/license.php

Symantec Online Virus and Security Scan:
http://security.symantec.com/ssc/home.asp

TrendMicro:
http://housecall.trendmicro.com/housecall/start_corp.asp

McAfee Online Virus Scan:
http://www.mcafee.com/myapps/mfs/default.asp

RAV AntiVirus - Scan Online
http://www.ravantivirus.com/scan/

F-Secure:
http://support.f-secure.com/enu/home/ols.shtml

After your system is clean use these programs to help keep it clean:

Spywareblaster
www.javacoolsoftware.com/sbdownload.html

Spywareguard
http://www.javacoolsoftware.com/sgdownload.html

IE-SPYAD
http://www.staff.uiuc.edu/~ehowes/resource.htm
 
J

Jim Macklin

It is a good list, but on a computer that is only two weeks
old, it would be easier to reformat and do a clean install,
install those programs, be sure the firewall and anti-virus
are turned on. Then start over clean.


--
The people think the Constitution protects their rights;
But government sees it as an obstacle to be overcome.


| Ron wrote:
|
| > Hi, glad you're there for us!
| >
| > I have an almost inoperable PC that's just two weeks
old.
| > I run WinsXP home, Service pack 1, with I.E Exlorer.
| > The system came with Norton AntVirus 2004 but I failed
to
| > turn on it's Firewall for the first 2 days.
| > I added Ad-Aware (Personal SE), SpyBot's (Search &
| > Destroy), and Registry Cleaner. The systems detect
| > hundreds of Spyware items, remove many of these
malicious
| > files, and clean up some of their registry entries.
| > But I'm always always left with enough Spyware and
| > registry changes that they seem to come back in full
| > disabling force when I go online.
| >
| > Question 1:
| > I realize I need to clean my registry, and it's obvious
| > that the above applications can't do that ENTIRE
| > cleansing, but is their an alternative to using
"regedit"
| > and manually removing the hundreds of offending registry
| > items Spyware created?
| >
| > Question 2:
| > I just installed "Spybalster 3.2". It claims to prevent
| > re-entry of Spyware, and even "prevent it from running
on
| > your system'. Does that mean I can effectively prevent
| > even the Spyware registry entries from reinstalling or
re-
| > activating these pests?
| >
| > Thanks, Ron
|
| You need to run a combination of programs and do so in
safe mode.
| You'll need to check for spyware/adware as well as
viruses.
|
| In addition to Adaware and Spybot which you say you have
(note Adaware
| just released a new version 1.05), run these programs to
check for
| spyware/malware. After installing update them, then boot
into safe mode
| and run them. You should update and run them weekly.
|
| Cwshredder
| http://aumha.org/freeware/freeware.php#cwshred
|
| Pest Patrol Free Pest Scanner
| http://www.pestscan.com/ScanOrTrial.asp
|
| If you’re still having problems after running these then
run HijackThis
| and post the log to one of the specialty forums, _NOT_
this one.
|
| HijackThis
| http://www.majorgeeks.com/download.php?det=3155
|
| Forums to Interpret HijackThis Logs:
|
| http://www.spywareinfo.com/forums/
| http://forum.aumha.org/viewforum.php?f=30
| http://forums.tomcoyote.org/
| http://www.wilderssecurity.com/
|
| For viruses start with Trend Micro's Sysclean. After
downloading the
| program and signature file turn off system restore, boot
into safe mode
| and run it. Then boot back into normal mode, turn system
restore, and
| do a complete scan with your AV product. Also do a scan
with at least
| two of these on line services:
|
| Trend Micro Sysclean
| http://www.trendmicro.com/download/dcs.asp
|
| Trend Micro Signature File
| http://www.trendmicro.com/download/pattern.asp
|
| Online and Downloadable Virus Scanning:
|
| Panda ActiveScan
|
http://www.pandasoftware.com/activescan/com/activescan_principal.htm
|
| Bit Defender Online Virus Scan:
| http://www.bitdefender.com/scan/license.php
|
| Symantec Online Virus and Security Scan:
| http://security.symantec.com/ssc/home.asp
|
| TrendMicro:
| http://housecall.trendmicro.com/housecall/start_corp.asp
|
| McAfee Online Virus Scan:
| http://www.mcafee.com/myapps/mfs/default.asp
|
| RAV AntiVirus - Scan Online
| http://www.ravantivirus.com/scan/
|
| F-Secure:
| http://support.f-secure.com/enu/home/ols.shtml
|
| After your system is clean use these programs to help keep
it clean:
|
| Spywareblaster
| www.javacoolsoftware.com/sbdownload.html
|
| Spywareguard
| http://www.javacoolsoftware.com/sgdownload.html
|
| IE-SPYAD
| http://www.staff.uiuc.edu/~ehowes/resource.htm
|
 
R

Ron

Hi DAVE,
I see two posts from you above but they don't contain any
messages from you. They just repeat my original post.

Thanks, Ron
 
R

RON

Thanks Jim,
You're probably correct that I ought to just start over
clean but I have spent so much time on this that the
dedicated side of mwe wants to try to clean up the little
Spyware demons and liberate my machine.
Also, if the PC came loaded with MS XP and I only have an
XP Recovery disc, can I stil reformat?
Accordingly, I think I'll give one shot to Dave's
suggestion above.
One thing I can't understand though. I can't get my MS XP
home ed. Firewall enabled. Is that firewall the same as
the one called "Internet Connection Firewall"??
It's the only firewall item I can find on XP yet it seems
to apply only to 'networking' applications, not one PC. Am
I looking for XP's firewall in the wrong place?in the
correct place? I went to "Network Connections" where the
sole entry was 'Local Area Connection Enabled, via Rhine
2'. (I use a cable modem so that seemed odd). I then
went to 'advanced' tab and check off "Enable Internet
Connection Firewall". But when i click "OK" I get the
network connection error, "An error occured when ICF was
being enabled. The dependecy service or group failed to
start."
I haven't a clue what this means. Can you guide me?

Thanks, Ron
 
J

Jim Macklin

Your recovery CD will probably format and reinstall, that's
what they do, which is why they are so limited in
usefulness.

The viruses you have are probably blocking your turning the
ICF ON.

Sometimes it is easier and faster to just "blow it out"
(format) and start over correctly...but it is a learning
experience, when you're done you'll be much wiser.


--
The people think the Constitution protects their rights;
But government sees it as an obstacle to be overcome.


|
|
| Thanks Jim,
| You're probably correct that I ought to just start over
| clean but I have spent so much time on this that the
| dedicated side of mwe wants to try to clean up the little
| Spyware demons and liberate my machine.
| Also, if the PC came loaded with MS XP and I only have an
| XP Recovery disc, can I stil reformat?
| Accordingly, I think I'll give one shot to Dave's
| suggestion above.
| One thing I can't understand though. I can't get my MS XP
| home ed. Firewall enabled. Is that firewall the same as
| the one called "Internet Connection Firewall"??
| It's the only firewall item I can find on XP yet it seems
| to apply only to 'networking' applications, not one PC. Am
| I looking for XP's firewall in the wrong place?in the
| correct place? I went to "Network Connections" where the
| sole entry was 'Local Area Connection Enabled, via Rhine
| 2'. (I use a cable modem so that seemed odd). I then
| went to 'advanced' tab and check off "Enable Internet
| Connection Firewall". But when i click "OK" I get the
| network connection error, "An error occured when ICF was
| being enabled. The dependecy service or group failed to
| start."
| I haven't a clue what this means. Can you guide me?
|
| Thanks, Ron
|
|
|
| >-----Original Message-----
| >It is a good list, but on a computer that is only two
| weeks
| >old, it would be easier to reformat and do a clean
| install,
| >install those programs, be sure the firewall and anti-
| virus
| >are turned on. Then start over clean.
| >
| >
| >--
| >The people think the Constitution protects their rights;
| >But government sees it as an obstacle to be overcome.
| >
| >
| >| >| Ron wrote:
| >|
| >| > Hi, glad you're there for us!
| >| >
| >| > I have an almost inoperable PC that's just two weeks
| >old.
| >| > I run WinsXP home, Service pack 1, with I.E Exlorer.
| >| > The system came with Norton AntVirus 2004 but I
| failed
| >to
| >| > turn on it's Firewall for the first 2 days.
| >| > I added Ad-Aware (Personal SE), SpyBot's (Search &
| >| > Destroy), and Registry Cleaner. The systems detect
| >| > hundreds of Spyware items, remove many of these
| >malicious
| >| > files, and clean up some of their registry entries.
| >| > But I'm always always left with enough Spyware and
| >| > registry changes that they seem to come back in full
| >| > disabling force when I go online.
| >| >
| >| > Question 1:
| >| > I realize I need to clean my registry, and it's
| obvious
| >| > that the above applications can't do that ENTIRE
| >| > cleansing, but is their an alternative to using
| >"regedit"
| >| > and manually removing the hundreds of offending
| registry
| >| > items Spyware created?
| >| >
| >| > Question 2:
| >| > I just installed "Spybalster 3.2". It claims to
| prevent
| >| > re-entry of Spyware, and even "prevent it from
| running
| >on
| >| > your system'. Does that mean I can effectively
| prevent
| >| > even the Spyware registry entries from reinstalling
| or
| >re-
| >| > activating these pests?
| >| >
| >| > Thanks, Ron
| >|
| >| You need to run a combination of programs and do so in
| >safe mode.
| >| You'll need to check for spyware/adware as well as
| >viruses.
| >|
| >| In addition to Adaware and Spybot which you say you
| have
| >(note Adaware
| >| just released a new version 1.05), run these programs
| to
| >check for
| >| spyware/malware. After installing update them, then
| boot
| >into safe mode
| >| and run them. You should update and run them weekly.
| >|
| >| Cwshredder
| >| http://aumha.org/freeware/freeware.php#cwshred
| >|
| >| Pest Patrol Free Pest Scanner
| >| http://www.pestscan.com/ScanOrTrial.asp
| >|
| >| If you're still having problems after running these
| then
| >run HijackThis
| >| and post the log to one of the specialty forums, _NOT_
| >this one.
| >|
| >| HijackThis
| >| http://www.majorgeeks.com/download.php?det=3155
| >|
| >| Forums to Interpret HijackThis Logs:
| >|
| >| http://www.spywareinfo.com/forums/
| >| http://forum.aumha.org/viewforum.php?f=30
| >| http://forums.tomcoyote.org/
| >| http://www.wilderssecurity.com/
| >|
| >| For viruses start with Trend Micro's Sysclean. After
| >downloading the
| >| program and signature file turn off system restore,
| boot
| >into safe mode
| >| and run it. Then boot back into normal mode, turn
| system
| >restore, and
| >| do a complete scan with your AV product. Also do a
| scan
| >with at least
| >| two of these on line services:
| >|
| >| Trend Micro Sysclean
| >| http://www.trendmicro.com/download/dcs.asp
| >|
| >| Trend Micro Signature File
| >| http://www.trendmicro.com/download/pattern.asp
| >|
| >| Online and Downloadable Virus Scanning:
| >|
| >| Panda ActiveScan
| >|
|
| ncipal.htm
| >|
| >| Bit Defender Online Virus Scan:
| >| http://www.bitdefender.com/scan/license.php
| >|
| >| Symantec Online Virus and Security Scan:
| >| http://security.symantec.com/ssc/home.asp
| >|
| >| TrendMicro:
| >|
http://housecall.trendmicro.com/housecall/start_corp.asp
| >|
| >| McAfee Online Virus Scan:
| >| http://www.mcafee.com/myapps/mfs/default.asp
| >|
| >| RAV AntiVirus - Scan Online
| >| http://www.ravantivirus.com/scan/
| >|
| >| F-Secure:
| >| http://support.f-secure.com/enu/home/ols.shtml
| >|
| >| After your system is clean use these programs to help
| keep
| >it clean:
| >|
| >| Spywareblaster
| >| www.javacoolsoftware.com/sbdownload.html
| >|
| >| Spywareguard
| >| http://www.javacoolsoftware.com/sgdownload.html
| >|
| >| IE-SPYAD
| >| http://www.staff.uiuc.edu/~ehowes/resource.htm
| >|
| >
| >
| >.
| >
 
A

Alex Nichol

Jim Macklin said:
Sometimes it is easier and faster to just "blow it out"
(format) and start over correctly...but it is a learning
experience, when you're done you'll be much wiser.

Add: SP2 is now available on Free CD on magazine cover disks and in
places like Staples, as well as on order from Microsoft. I would get
one, and immediately after doing a clean recover run it to bring
yourself up to date, before ever connecting to the net at all
 
J

Jim Macklin

An excellent idea. Here is the link to order on-line,
delivery is fairly fast
http://www.microsoft.com/windowsxp/downloads/updates/sp2/cdorder/en_us/default.mspx


message | "Jim Macklin" <p51mustang[threeX12]@xxxhotmail.calm>
wrote:
|
| >
| >Sometimes it is easier and faster to just "blow it out"
| >(format) and start over correctly...but it is a learning
| >experience, when you're done you'll be much wiser.
| >
|
| Add: SP2 is now available on Free CD on magazine cover
disks and in
| places like Staples, as well as on order from Microsoft.
I would get
| one, and immediately after doing a clean recover run it to
bring
| yourself up to date, before ever connecting to the net at
all
|
|
| --
| Alex Nichol MS MVP (Windows Technologies)
| Bournemouth, U.K. (e-mail address removed)8E8L.org (remove the D8
bit)
 
R

RON

Thanks Alex and Jim,
1) I have some trepidation about installing Service Pack 2
given the hundreds of complaints I've seen here from
apparent experienced users who have had frustrating SP2
experiences. I guess the problem *wasn't* SP2 but some
other factor. Still, that *many* complaints makes me very
wary.

Please respond to two questions if possible.
1) I just went through the exact routine outlined above
for cleaning my hard drive. (Every anti Spyware and
Antivirus application listed, and in precisely the order
given.) I showed NO virus or Spyware/Malware after I ran
through that entire proceedure.
BUT, when I rebooted in 'normal' mode I did not have my
firewall yet enabled. Reason: As stated above I can't
enable my ICF.

Kindly re-read the sentences below and tell me why you
think I can't enable my XP Firewall:(It was suggested that
a 'virus' was presenting me from enebling it but that was
not the case)
can't get my MS XP
home ed. Firewall enabled. Is that firewall the same as
the one called "Internet Connection Firewall"??
It's the only firewall item I can find on XP yet it seems
to apply only to 'networking' applications, not one PC. Am
I looking for XP's firewall in the wrong place?in the
correct place? I went to "Network Connections" where the
sole entry was 'Local Area Connection Enabled, via Rhine
2'. (I use a cable modem so that seemed odd). I then
went to 'advanced' tab and check off "Enable Internet
Connection Firewall". But when i click "OK" I get the
network connection error, "An error occured when ICF was
being enabled. The dependecy service or group failed to
start."
I haven't a clue what this means. Can you guide me?
(END REPOST)<<<

I installed instead "Sygate's Personal Firewall".
But I couldn't install it in 'Safe' mode, so I had to boot
in 'Normal' first. I presume that in that brief internet
connection to install Sygate there was a pre-firewall
protection vulnerability of 3 or 4 moments that let
Spyware back in. The result was I now have back 84 Spyware
files and some registry changes.

So-o-o, I KNOW I've wasted hours on this and should just
reformat, but if I'm a masochist, would it likely work it
I repeat every step I just did with all the listed
downloaded antivirus/ Spyware scans now that I WILL have
an installed, funtional firewall from the second I go
online in 'normal' mode??

Thanks again for all the time you spent reading my
detailed replies,

RON
-----Original Message-----
An excellent idea. Here is the link to order on-line,
delivery is fairly fast
http://www.microsoft.com/windowsxp/downloads/updates/sp2/cd
order/en_us/default.mspx


message | "Jim Macklin" <p51mustang[threeX12]@xxxhotmail.calm>
wrote:
|
| >
| >Sometimes it is easier and faster to just "blow it out"
| >(format) and start over correctly...but it is a learning
| >experience, when you're done you'll be much wiser.
| >
|
| Add: SP2 is now available on Free CD on magazine cover
disks and in
| places like Staples, as well as on order from Microsoft.
I would get
| one, and immediately after doing a clean recover run it to
bring
| yourself up to date, before ever connecting to the net at
all
|
|
| --
| Alex Nichol MS MVP (Windows Technologies)
| Bournemouth, U.K. (e-mail address removed)8E8L.org (remove the D8
bit)


.
 
A

Alex Nichol

RON said:
Thanks Alex and Jim,
1) I have some trepidation about installing Service Pack 2
given the hundreds of complaints I've seen here from
apparent experienced users who have had frustrating SP2
experiences. I guess the problem *wasn't* SP2 but some
other factor. Still, that *many* complaints makes me very
wary.

They are generally when installing by either or both of a: use of the
update method, and b: over a machine with who knows what else running.
That is why I suggest doing it from a CD immediately after a clean
reinstall; that should give no trouble.
Please respond to two questions if possible.
1) I just went through the exact routine outlined above
for cleaning my hard drive. (Every anti Spyware and
Antivirus application listed, and in precisely the order
given.) I showed NO virus or Spyware/Malware after I ran
through that entire proceedure.
BUT, when I rebooted in 'normal' mode I did not have my
firewall yet enabled. Reason: As stated above I can't
enable my ICF.

I just don't know. But some of the 'hijackware' is *extremely*
difficult to remove, and it seems likely that something had managed to
survive
 
D

...D.

If your system is only 2 weeks old, you haven't accumulated too much stuff,
so why not just re-install Windows XP from scratch and wipe the hard drive
clean? That's what I would do. You may never track down the stuff... You
might even have some kind of a worm.. You can get something like a worm in
one minute without a firewall.

If you are on dial up, send away for the free CD with service pack 2 on it.
But it will take a while. Whatever you do, if you reinstall SP1, do not
forget to turn the firewall on - it happened to me on a re-install. Forgot
- that's why SP-2 is such an improvement, firewall = on by default.

I just read somewhere that it is now over 50% in the USA - broadband users
vs dial-up...
...D.
-------
OT : The steel knights (st33l-Kn1ghts) is a small Yahoo Messenger based
chatroom club. Whether you are a techie or a newbie, female or male, we're
looking for some new blood. Requirements: be half-way mature... It's nice
to know the people you chat with in a chatroom environment.
http://www.steel-knights.com . (you can run Yahoo Messenger & Windows/MSN
Messenger at the same time with no conflicts).
 
C

cquirke (MVP Win9x)

If your system is only 2 weeks old, you haven't accumulated too much stuff,
so why not just re-install Windows XP from scratch and wipe the hard drive
clean? That's what I would do. You may never track down the stuff... You
might even have some kind of a worm.. You can get something like a worm in
one minute without a firewall.

You've just answered your own question!

If you "just format and re-install", you will:
- never figure out what happened before
- be completely unpatched
- get infected immediately you reconnect

http://cquirke.mvps.org/reinst.htm refers.

Do the prelim, as per...

http://cquirke.mvps.org/9x/bthink.htm

....i.e. hardware diags, formal av scan etc.

Truth is, if you build a PC using pre-SP2 XP installation CD (as they
all are, as at Sep 2004) the result is a PC that is unfit for use on
the Internet, unless you manually turn on firewall at least.

So your typical OOBE is:
- immediately get infected
- find you can't formally scan/clean NTFS

Of course; that's a given.

1) Get off all networks, including internet and wireless
2) Formally scan for traditional malware (viruses etc.)
3) Research and clean this traditional malware
4) Scan for and clean commercial malware
5) Purge hiding places; mailboxes, System Restore data
6) Set baseline System Restore point, HOSTS, etc.
7) Apply patches and risk management
8) Enable/add firewall and antivirus

Don't ever "just re-install Windows" as a first-step in
troubleshooting, because you will end up at square one.

-- Risk Management is the clue that asks:
"Why do I keep open buckets of petrol next to all the
ashtrays in the lounge, when I don't even have a car?"
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top