PDA

View Full Version : Spyware and Viruses Plague


Raider Rakkasans
25 October 2004, 18:41
OK computer SOCNET peeps. I need to know how to find out if my PC has spyware crap on it and viruses. Just FYI I have Norton 2004 would that square it away? Need help PC is sluggish and I don't know why. I have XP home ed, 512 memory that is off the top of my head. HELP! My system should be flying! THe capacity thing show 68%!?

medicchick
25 October 2004, 18:42
Rsov and I both use Spy-bot and Ad-aware. Both are free, and work quite well.

Wootnik
25 October 2004, 18:46
I use spybot at the moment, writing my own program that should be done in a week or 2, will give you a copy once im done testing for bugs and so on.

Mikey G
25 October 2004, 18:46
Originally posted by medicchick
Rsov and I both use Spy-bot and Ad-aware. Both are free, and work quite well.

Amen to that, I use the same as well, great programs.

Raider Rakkasans
25 October 2004, 18:48
Where can I download Spybot and adware? Will they solve my problem?

MicSierra
25 October 2004, 18:48
Although not a specific area of expertise, I thought I'd offer some help.

For Spyware/Adware, I reccomend downloading Ad-Aware (http://www.lavasoftusa.com/software/adaware/) and SpyBot - Search & Destory (http://www.safer-networking.org/en/index.html) Both are highly rated, FREE peices of software that do their job well in my opinion.

As far as virii go, make sure your virus definitions are all up to date. Just look for something called "LiveUpdate" inside Norton and that'll make sure you're all up to date (as long as your subscription to this service is current!). From there, you can set up a 'Full-System Scan' as well as configure other things.

I'm not sure what you mean by 'Capacity' being at 68%. You'll need to be more specific. If it's CPU usage you're speaking of, 68% is extremely high for your computer idling.

Run all 3 peices of software and post back when you get a chance,

Hope that helped,

Mike

Wootnik
25 October 2004, 18:53
Also what I would do is this, go to control panel, add remove programs, and remove all the programs that you dont use/need.

then go to find files and folders, and search and delete all the "gator" files, then go to the the registry and delete anything you see with the word "Gator" in it. Also if you have Kazaa, get rid of it, unless you have the light version. (the regular version creates popups)

ibquiet
25 October 2004, 19:44
Not to intrude folks, but Raider, if you do try ad-aware or spybot, be very carefull about what your delete, both of these programs can, and in most cases will show some norton files as potential viruses, or questionable programs. If you delete a norton file by mistake, there will be nothing but pop-up windows showing error codes when you start the computer, as norton embeds files everywhere in your system, and will be looking for them if they are removed. Norton is really quite invasive and a pain to remove before a re-install.

I got rid of Norton and went with Mcafee a year and a half ago, havent had a single virus since.

I think Norton is the worst virus going, but that's just my opinion.

Cass
25 October 2004, 20:41
Raider
Your PC may be plugged up with tempo files that are saved as you hop from Web to Web. To clean out these Temp Files:

Start>Accessories>System Tools>Disk Cleanup. A "Select Drive" Dialog Box should appear. Click on arrowhead to [C]>OK> A progress bar will appear. Wait for progress bar to bring up "Disk Cleanup" Dialog Box.> Click "OK", then "Yes" on next box. Wait for progress bar and box to disappear.

The first time I used my Adware I had 99 parasites sucking at my computer. Now I have approx 4 every two weeks try to jump on for a ride. Spybot had approx 20 parasites the first time. Now I may not get any in two weeks.

MEP
25 October 2004, 20:47
the rest of the folks mentioned some good spyware.. but also if you haven't done it in a long time, you may need to Defrag (http://support.microsoft.com/default.aspx?scid=kb;EN-US;314848) your hard drive(s).

offcamber
25 October 2004, 22:22
Do a search for a freeware app called Hijackthis. It basically just lists registry keys and such that are the most likely to be exploited. You just check those that you want to correct. If you are at all PC savvy, I've found to hijackthis to be the best for handling spyware that's really new and not on the latest profiles.

JoeShmoe
25 October 2004, 22:33
I would get the Norton System Works along with the Norton Personal Firewall. These have several functions which protects your system from incoming threats, repairs damaged files, and optimizes computer performance.

I installed these about 7 months ago and have had great success with them. I run the System Works about every three days and it keeps my PC running well.

Don't know who your ISP is, but I have heard about problems with some anti-virus programs conflicting with AOL's software.

The Norton systems mentioned above might cost a little more , but I feel they are very efficient. I prefer buying the boxed CD's rather than downloading off their website, this way you get the manual, Cd's etc.

Sharky
25 October 2004, 23:29
Originally posted by Wootnik
then go to the the registry and delete anything you see with the word "Gator" in it.



Be damn sure you know what youre doing before you do ANYTHING in the registry. BTDT. I learned how to dump my hard drive and start all over that same weekend. If you're not sure, dont fuck with it. Get someone who knows to help you.

s1chmoe
25 October 2004, 23:48
are you sure about the "gator" file thing, i found about 12, most are "class" (whatever that means, and 2 are bitmap images...

Wootnik
25 October 2004, 23:54
If it is just a bitmap, then it is probably a picture you downloaded or something that is just named that, but most files, registry names, and so on that say "Gator" it is bad. you will just have to look at the location of the said item, if it is in your "My Documents" Folder, I wouldnt worry about it, but if it is part of C drive or program files then would remove it. BUT, Spy Bot should actually take care of ALOT of the gator stuff.

Raider Rakkasans
26 October 2004, 01:30
I did everything recommended but the link for adware is a no go. I had 79 hit using spybot. No viruses!

Doogie320
26 October 2004, 02:30
I had some really good threads about this stuff. I guess the server upgrade killed them.

medicchick
26 October 2004, 03:52
Try this one for Ad-aware http://www.lavasoft.de/support/download/

danjam
26 October 2004, 03:56
try cnet.com for downloading spybot and ad-aware.

ad-aware: http://www.download.com/3001-8022-10319876.html

spybot: http://www.download.com/Spybot-Search-Destroy/3000-8022-10289035.html?tag=bc

Run them seperately, sometimes ad-aware and will find files from spybot and vice-versa. After this run the Norton (after you have done live update).

If you are still having problems, try starting your computer up in safe mode and then running ad-aware etc...

And after all of this..... defrag ... good luck

charmon
26 October 2004, 23:14
Before you do any of this: if you’re using Windows XP create a restore point.

To create a Restore Point in Windows XP:
1. Click Start, Programs, Accessories, System Tools, System Restore.
2. The System Restore window will appear. Chose Create a Restore Point and click the Next button.
3. Next, you will be given the opportunity to create a name for the Restore Point. Type in the name and click create.


Preparing to clean up (read this entire section before attempting any of these procedures)

Download one of these:
Adaware 6.0
SpyBot

Another good one and one that I recommend is Pest Patrol. This can be found at http://www.pestpatrol.com. The cost is $39.99 for home users but it is well worth the price.

When finished, disconnect from the cable/dsl modem and restart your computer in Safe Mode. This is done by pressing the F8 key while the PC is booting up before the Windows splash screen appears. If the Windows splash screen appears just restart and do it again. If you’ve never done this before you might have to press the F8 key several times to get it to take. If you are successful, you’ll get a DOS menu. At the top of the list you should see Safe Mode. Regardless of where it is, highlight Safe Mode using the up and down arrow keys and press Enter. Once the boot process is complete you’ll see the windows desktop. Don’t worry about what the video looks like.

The Cleaning Process for XP and 2000

First we’re going to do a little manual cleaning. Open up My Computer and double click on the C drive.
1. Look for a file that ends in .XML. If you see it, delete it. It shouldn’t be there.
2. On the Drop Down menus at the top of the window click on Tools, Folder Options, View. In the new window look down the list and click the button beside Shall All Files. Then exit by clicking OK on all the windows.
3. Open up the C drive again, if you just closed it, then open up the Windows Folder. Then open up the folder called Temps. Delete all the files in this folder.
4. Close these windows until you are viewing the contents of the C drive.
5. Open the Windows folder. Look for the Temp folder and delete the contents of the folder. Navigate back to the Contents of C.
6. Open the Documents and Settings Folder
7. Open the folder that is named the same name that you use to log onto the computer. If you don’t have to login open the Administrator folder. Open the Local Settings folder.
8. Next, open the Temp folder and delete all the files out of it.
9. Open the Temporary Internet Files folder. Delete the files in this folder. Sometimes login information is stored here for things like web forums, and web sites that require a log in and password. Unless you want to go through every file and delete them one by one, delete everything. You’ll just have to enter an account and password for the web forum you go to all the time.
10. Open up Internet Explorer. Click on Tools, Internet Options, Settings, View Objects. These are application plug-ins like Flash Player, Real Player, etc. If any are listed as “unknown” remove them.

When finished, close all open windows. Look on the desktop for the Adaware icon. Double click the icon and run the application. It could take 15 or 20 minutes to run.

Next, do the same with Spybot. There’s a good chance that Adaware will get everything but it never hurts to be sure.

Now that you’ve gotten rid of the registry entries and cookies, we’re going to get rid of the applications themselves.

Open up the Control Panel then double-click the Add/Remove Programs icon. It’s time to remove some applications. Look for any of the following and remove them:
• EBates
• GAIN
• Golden Retriever
• IGetNet
• IPinsight
• King Solomon's Casino
• MyWay Speedbar
• NetPalNow.com
• Purity Scan
• Sidestep
• Webhancer
• Sidesearch
These are just a few.

Now go through the applications and make a list of the ones that you don’t know what they do. (Did that make sense?) If you’re sure that you didn’t install them and know that you don’t need them, remove them. If you’re not sure, look them up on the internet. If you take the second option there’s a good chance that you’ll have to go through this process again.

If you're using Internet Explorer you'll need to do the following. Open IE, on the drop down menus clickTools, Internet Options. On the box that appears click the button that says Settings. In the next window is a button that says View Objects. These are little applets that play eye candy like flash and java stuff. They also reinstall the spyware you've just spent the entire night trying to get rid of. Click this button and see what's there. To remove one of the entries just Right click on it and choose remove. It might ask you if you're sure, click yes. You can remove everything here if you're not sure what to remove. It won't hurt anything. If you delete something that's needed it will just prompt you to reinstall when needed.

If at anytime you are prompted to reboot the computer DON”T DO IT! If you reboot before you uninstall these apps you’ll have to start the whole process over again. Sometimes this can’t be avoided. If the PC reboots its self during the process make a note of the application you were uninstalling when it happened. Next time do it last.

Hope this helps.

K