Spyware

I travelled home to visit my parents and siblings on the weekend, and what should have been a relaxing time with the family, turned into a weekend of battling with spyware. It amazed me how much of this stuff was on their computers!

I had the most success with Spybot-Search and Destroy and Ad-Aware Personal Edition, although there were a couple of “Home Page Hijackers” that needed to be removed with special programs. From what I read online, it seems that to remove spyware, you need both the above programs to catch most of the trash that get’s deposited on your systems.

I’d be curious to know what other’s use to remove and prevent spyware. On my system at home, I surf with Firefox and have had very few spyware problems (most of what I get now comes from freeware installers).

2 Responses to “Spyware”

  1. Critter said on November 16th, 2004 at 10:52 am

    ha… i did just the same thing a few days ago… i actually ran out of time trying to get rid of everything.. i /did/ at least install firefox.. but i still could not get rid of a “lucky today” or something ie toolbar…

  2. Richard Leggett said on November 16th, 2004 at 11:20 am

    Know the feeling, every time I go home!! Those programs do an ok job, but they don’t get rid of them all.

    The only way to do that is to boot up in Safe Mode (sometimes command prompt only), then search around msconfig.exe use regedit to look in the “HKEY_LOCAL_MACHINE-SOFTWARE-Microsoft-Windows-
    CurrentVersion-Run”, “RunOnce” and “RunServices” keys (also for user accounts not just localmachine).

    Also check task manager and google all of the exe names in processes.

    Then I had to check notepad.exe, calc.exe iexplore.exe for possible usage of Windows logic bombs, see K1line 45, http://www.nettwerked.net/K-1ine_45.txt). One was being used.

    Finally searching all major Windows folders (inc system32) for new batch files and exe’s using sort by date, and removing at speed!

    I even came up against spyware that blocked ctrl+alt+del and regedit, CD booting Knoppix was the only way around it! :s

    Then I just removed all links to explore and installed Firefox :p