PDA

View Full Version : How to Manually remove spyware


appleyum
10-04-2004, 07:06 PM
Tips on manually fix some of the problems.

Boot into Safe Mode without Network support. Press F5 or Press Shift during your computer startup
Internet Explorer -> Tools -> Internet Options -> Home Page. Change to homepage you want.
Hit Delete Files, Delete Cookies while you at it.
Check Start -> Programs -> Startup
Start -> Run -> Msconfig -> Startup. Uncheck suspicious ones. Reboot and see if you remove the problem.
If you don't have Msconfig use this Starup Control Panel (http://www.mlin.net/StartupCPL.shtml) http://www.mlin.net/StartupCPL.shtml. Disable before you delete.
If you are registry savy then Start -> Run -> Regedit -> HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run and HKCU\Software\Microsoft\Windows\CurrentVersion\Run. Backup your registry before you delete anything. To backup File -> Export or Right Click on the folder -> Export.
Another places to look for in register is HKLM\SOFTWARE\Microsoft\Internet Explorer\. Check Extensions, Main and Toolbar.
Check Scheduled Tasks. Start -> Programs -> Accessories -> System Tools -> Scheduled Tasks.
Check your Hosts file. %systemroot%\system32\drivers\etc\hosts. Spyware might put false info in there or make it easier for them to link to their site.
Remember to write down file path for those suspicious files because you need to remove them once you determine they are the files that are causing the problem.
If you can't remove the file try rebooting. If that doesn't work, kill suspicious task by going to Task manager ctrl - alt- del or ctr - shift - esc.
Some steps need to be combined or repeated because sometime spyware are located in multiple locations and if you don't catch them all they will respawn the ones you deleted.


If all else fail try system restore if you have it on. Just make sure you know what was changed between current point and restore point. You might have to reinstall certain application softwares.

appleyum
10-04-2004, 07:10 PM
(Reserve)

Dude111
02-14-2009, 08:45 PM
One time the XP upstairs in our house had some trojan on it,my father was doing something and some page said he "You need this codec to watch this clip" (YOU DIDNT NEED IT BUT HE DIDNT KNOW THAT (LIKE ALOT OF PEOPLE :())

Well good thing i went up to that room that night @ 2am!!

The trojan was actively attacking OTHER COMPUTERS FROM THE XP!!

I pulled the modem from the feed STRAIGHT AWAY! (It had COMPLETE CONTROL over the computer (It was a STEALTH trojan)) I opened task manager and started '"ENDING TASK" on random things i didnt recognize,when i ended task on the TROJAN'S EXE,the AV recognized and deleted it straight away!! (Norton was on there @ the time,now SPY SWEEPER is on there)

Then i went thru and deleted the folder that was created by the thing (Video ACTIVE-X object),i checked the reg and it was clean. I did a FULL VIRUS SCAN (Which was clean),I rebooted the computer and was greeted with "The system has recovered from a fatel error"

Makes ya feel good when you can do stuff yourself and MANUALLY without the help of commercial S/W that may or may not work..... (Doing things your familar with is sometimes better to do (Opposed to using S/W that you dont know what its doing))