Tuesday, May 18, 2004
Monday, May 17, 2004
Sunday, May 16, 2004
Saturday, May 15, 2004
Friday, May 14, 2004
Thursday, May 13, 2004
Wednesday, May 12, 2004
Tuesday, May 11, 2004
Monday, May 10, 2004
spyware
Apparently my dad had a new variant of Coolwebsearch. It was a nasty SOB. Nothing would remove it.
All of the spyware apps had to be renamed to foo.exe (via another computer over the net) before they would even show up in Explorer.
CWShredder detected that it was being shut down by CWS and changed its title bar to garbage characters so it could run. It said it removed CWS, but it was wrong.
.... ....
AdAware would clean it off, but it would add itself right back in. Hijack this also helped but it still kept coming back.
If it isn't in the startup
It isn't a service that installed itself
Isn't an aberrent process running that can be killed via Task Manager
Isn't in the run section of the registry (HKLM\Software\Microsoft\Windows\Current Version\Run)
It is because these homepage hijack usually are in the installed programs section of Internet Explorer, which is why virus scanners and normal spyware cannot locate the root process, because it's actually running under IEexplore.exe's process!!!
Steps I have found that clean machines infected this way.
Go to IE's Internet properties (Internet Properties\General\Temporary Internet Files\Settings\View Objects (which is usually c:\%windir%\Downloaded Program Files).
Delete all objects (you can always reload flash and the other applications in there)
Then choose Internet Properties\Programs\Reset Web Settings.
Run AdAware/Hijack this one final time to clear out any last minute payload reinstalls.
You should now be able to browse normally without the page hijacking.
Apparently my dad had a new variant of Coolwebsearch. It was a nasty SOB. Nothing would remove it.
All of the spyware apps had to be renamed to foo.exe (via another computer over the net) before they would even show up in Explorer.
CWShredder detected that it was being shut down by CWS and changed its title bar to garbage characters so it could run. It said it removed CWS, but it was wrong.
.... ....
AdAware would clean it off, but it would add itself right back in. Hijack this also helped but it still kept coming back.
If it isn't in the startup
It isn't a service that installed itself
Isn't an aberrent process running that can be killed via Task Manager
Isn't in the run section of the registry (HKLM\Software\Microsoft\Windows\Current Version\Run)
It is because these homepage hijack usually are in the installed programs section of Internet Explorer, which is why virus scanners and normal spyware cannot locate the root process, because it's actually running under IEexplore.exe's process!!!
Steps I have found that clean machines infected this way.
Go to IE's Internet properties (Internet Properties\General\Temporary Internet Files\Settings\View Objects (which is usually c:\%windir%\Downloaded Program Files).
Delete all objects (you can always reload flash and the other applications in there)
Then choose Internet Properties\Programs\Reset Web Settings.
Run AdAware/Hijack this one final time to clear out any last minute payload reinstalls.
You should now be able to browse normally without the page hijacking.
Saturday, May 08, 2004
Friday, May 07, 2004
Thursday, May 06, 2004
Subscribe to:
Posts (Atom)