Spy ware.

Operating System, Common Application & ThinkPad Utilities Questions...
Post Reply
Message
Author
ThinkPad
ThinkPadder
ThinkPadder
Posts: 1085
Joined: Sun Nov 21, 2004 7:33 pm
Location: Windy City

Spy ware.

#1 Post by ThinkPad » Wed Aug 31, 2005 11:05 pm

What is the best spyware detection and removal program out there?
Thinkpad X-41 Tablet 1869 CSU- 1.6GHz
Thinkpad T-42P 2373 GUU-2.1 GHz; 2 GB RAM; Mini-dock
::Sierra AirCard WWAN 875::NMB Thai::
RIP-Thinkpad T41 2379 DJU

Mumin
Posts: 20
Joined: Fri May 27, 2005 6:47 pm

#2 Post by Mumin » Thu Sep 01, 2005 12:06 am

Ad-aware and Spybot combined

pphilipko
Senior Member
Senior Member
Posts: 631
Joined: Sat May 22, 2004 10:32 am
Location: Philadelphia

#3 Post by pphilipko » Thu Sep 01, 2005 12:07 am

Try out the Microsoft Anti-spyware. It's better than one would expect it to be..
Phil
IBM X40, 2371-AV0
Lenovo T61, 6458-AB1
En route: X61t

GZheng12
Posts: 28
Joined: Fri Nov 12, 2004 5:31 pm
Location: Edgewater, NJ
Contact:

Counterspy is the best one

#4 Post by GZheng12 » Thu Sep 01, 2005 10:27 am

Try out Counterspy 1.5, it is rated #1 by PCWorld.com. I have been using it for two months, its spyware definition is frequently update (about every 2, 3 days) and the interface is clean and intuitive. Full version costs only $19.99.

Recommended.
Regards,

Yigo

dssjon
Posts: 40
Joined: Thu Jun 30, 2005 4:02 pm

#5 Post by dssjon » Thu Sep 01, 2005 10:44 am

As a technician; i would recommend using the bazooka scanner to detect spyware. Once it detects the spyware it will refer you to a website with instructions on how to manually remove it from the registry, etc. There is spyware out there suchas 'surf sidekick III' that ms antispyware, adaware, etc. cannot fix. :)
[T43 2686E7U] [14.1" SXGA+]
[1.86GHz M] [756MB DDR2]
[7200 RPM 60GB HD]
[ATI Radeon X300]

brainpicker
Senior Member
Senior Member
Posts: 723
Joined: Mon Mar 28, 2005 6:13 pm
Location: Shady Hills, Florida (USA)

#6 Post by brainpicker » Thu Sep 01, 2005 11:30 am

Whatever you use make sure you use it WITH Hijackthis! as it calls attention to things spyware will miss. Download it here: http://www.merijn.org/files/hijackthis.zip , and if you are new at this use the log analyzer here for some help: http://hjt.iamnotageek.com/ .

Yak

nikemen
Senior Member
Senior Member
Posts: 579
Joined: Sat Apr 24, 2004 10:17 am
Location: Menlo Park, CA

purchased

#7 Post by nikemen » Thu Sep 01, 2005 11:49 am

I use spybot and adaware, but also purchased the spysweeper program from webroot, and have been happy with it. automated, and up to date gets most things, even more than others.

but, there mosst recent update has moved it to a service with a memory hit, gotta decide which is most important.

Nolonemo
Senior Member
Senior Member
Posts: 594
Joined: Wed Mar 16, 2005 5:58 pm
Location: Los Angeles

#8 Post by Nolonemo » Thu Sep 01, 2005 12:21 pm

nikemen, I tried and rejected Spysweeper, because it would only run under an administrator login, and my home machine runs under a limited user login unless I'm doing maintenance. Is this still the case with the newest version?
560, 560x, T23, T61

nikemen
Senior Member
Senior Member
Posts: 579
Joined: Sat Apr 24, 2004 10:17 am
Location: Menlo Park, CA

not sure what that was

#9 Post by nikemen » Thu Sep 01, 2005 12:56 pm

I am not sure what the issue was before, I run it under many limited user profiles, on parents machines and friends machines, works fine.

removing admin, install, etc access is a nice way to reduce spyware and slams from viriii as well.

syhead
Sophomore Member
Posts: 140
Joined: Sun Jan 02, 2005 12:23 am
Location: Goiânia, Brazil

#10 Post by syhead » Thu Sep 01, 2005 7:14 pm

I got a massive infection last week

My solution: backed up my documents, completely restored the computer using a BASE backup created a few weeks ago, and finaly replace my documents with the updated folders...

Why all that work? Because I felt like I would never bee able to return my computer to the original condition, before the infection.
Current: X200, X40
Past: T42, 600E

fbrdphreak
**SENIOR** Member
**SENIOR** Member
Posts: 529
Joined: Sat Nov 20, 2004 8:11 pm
Location: Raleigh, NC

#11 Post by fbrdphreak » Fri Sep 02, 2005 8:13 am

It still amazes me to see how many computer savvy people (and how many more non-computer savvy people) manage to get infections. So many people say "IE sucks, I'm using FF." I've used IE for YEARS, my gf has used IE for YEARS. Neither of us have ever gotten spyware, except maybe one random infection that was easily cleaned. Anyway, getting to removing spyware: I almost make a living off of this now, doing IT work for an agriculture department on campus. Here is what I do and this works for 95% of the machines:

*Download & install MS AntiSpyware & Spybot. Update both and use Spybot to immunize IE. Update your AV client
*You need to remove all TEMP files and Temporary Internet Files. I recommend going to the user's directory and clearing these out. Under Win2K & WinXP, it is roughly:

C:\Documents and Settings\%USERNAME%\Local Settings\Temp
C:\Documents and Settings\%USERNAME%\Local Settings\Temporary Internet Files

Delete everything that you can in these folders. Also do the same for any other users on the local machine. Somes files won't be able to delete, mainly "index" files, just work around those; BUT CLEAR ALL THOSE FILES OUT. Also, if you think the infection might have come in through e-mail, clear all local e-mail downloads (these are usually stored in a temp folder as well, depending on your e-mail client).

*Go to Control Panel-->System-->System Restore and DISABLE System Restore for all drives. This is CRITICAL

*Go to Control Panel-->Add/Remove Programs. Uninstall any junk that you don't recognize and looks like Spyware. A lot of them will have a small install size or no comments/size listed at all, just a name. Try to remove as many as possible through the CP; altho some I've encountered just freeze the computer. Also some require their own "uninstaller" from the adware company's website; I've DLed those and used 'em, overall they seem to work.

*With your updated anti-spyware software, reboot into safe mode.

*I begin by running Spybot, letting it find & fix all spyware. Reboot and re-run Spybot until it can't find any more. At this point load up MS AntiSpyware, chances are it will find more. Scan, fix, reboot, repeat. ALWAYS IN SAFE MODE.

*If you had a browser hijacker, you will need to restore your browser settings.

This usually does the trick. If you're still infected, then you pretty much need to go in manually and remove everything. If you have Norton AV, it picks up most spyware these days and if you go to http://www.symantec.com and search for the name it found (example: Adware.Aurora), they have good removal instructions; reg keys and all. Also, Bazooka is a free spyware removal program that detects spyware and links you to its website, where it has detailed manual removal instructions.

If anyone has any questions, feel free to shoot 'em my way :)
Have used just about every ThinkPad since the T42 days...

dssjon
Posts: 40
Joined: Thu Jun 30, 2005 4:02 pm

#12 Post by dssjon » Fri Sep 02, 2005 2:22 pm

fbrdphreak,

have you run into surf sidekick 3 yet? it boots into safe mode.. do you know if this has to do with system restore?
[T43 2686E7U] [14.1" SXGA+]
[1.86GHz M] [756MB DDR2]
[7200 RPM 60GB HD]
[ATI Radeon X300]

fbrdphreak
**SENIOR** Member
**SENIOR** Member
Posts: 529
Joined: Sat Nov 20, 2004 8:11 pm
Location: Raleigh, NC

#13 Post by fbrdphreak » Fri Sep 02, 2005 4:30 pm

I think I have seen this before. The only thing I can suggest is to kill the process and see if it stays down. Either way, MS Antispyware I think did a good job of removing it.

Worst case try Bazooka, just make sure you have a clean computer with net access so you can look up the program on their website
Have used just about every ThinkPad since the T42 days...

bhtooefr
ThinkPadder
ThinkPadder
Posts: 1370
Joined: Mon Jun 06, 2005 1:02 pm
Location: Newark, Ohio
Contact:

#14 Post by bhtooefr » Fri Sep 02, 2005 6:27 pm

Re: CounterSpy vs. MSAS...

CounterSpy and MSAS actually use the same engine. Granted, the definitions come from different sources, but CS's defs are based on the MSAS defs, IIRC. (If not the MSAS defs, it's the GIANT AntiSpyware defs (MSAS was previously known as GIANT AntiSpyware before MS bought GIANT out))
Current: 365XD (120 MHz, 72 MiB, 6.4 GB, 4x CD-ROM, 10.4" TFT)
Past: T61p 15.0" QXGA, T60p 15.0" QXGA, X61 Tablet SXGA+, R51e 14.1" XGA, X21

Post Reply

Return to “Windows OS (Versions prior to Windows 7)”

Who is online

Users browsing this forum: No registered users and 4 guests