{"id":42,"date":"2004-05-10T23:18:00","date_gmt":"2004-05-10T23:18:00","guid":{"rendered":"http:\/\/www.noidea.us\/wordpress\/?p=42"},"modified":"2004-05-10T23:18:00","modified_gmt":"2004-05-10T23:18:00","slug":"anti-virus-and-spyware-resources","status":"publish","type":"post","link":"http:\/\/www.noidea.us\/wordpress\/2004\/05\/anti-virus-and-spyware-resources\/","title":{"rendered":"Anti-Virus and Spyware Resources"},"content":{"rendered":"<p><![CDATA[In response to numerous requests I get for information on cleaning up viruses and spyware from personal computers running Microsoft Windows, I have put together the following document.\n\n<p>\n\n<div class=\"spydoc\">\n<span class=\"sdhead\">Cleaning up Spyware and Viruses<\/span><br \/>\n\n\n<p>\nFirst, gather the proper tools:\n\n<p>\n\n\n<ul>\n\n\n<li>McAfee Associates&#8217; <a href=\"http:\/\/download.nai.com\/products\/mcafee-avert\/s-t-i-n-g-e-r.exe\">Stinger<\/a> Anti-Virus scanner<br \/>\n\n\n<li>Lavasoft&#8217;s <a href=\"http:\/\/www.lavasoft.de\/support\/download\/#free\">Ad-Aware<\/a><br \/>\n\n\n<li>PepiMK&#8217;s <a href=\"http:\/\/www.safer-networking.org\/index.php?page=mirrors\">Spybot Search &#038; Destroy<\/a><br \/>\n\n\n<li>Merijn&#8217;s (SpywareInfo.com) <a href=\"http:\/\/209.133.47.200\/~merijn\/files\/HijackThis.exe\">Hijack This<\/a> and <a href=\"http:\/\/cwshredder.net\/bin\/CWShredder.exe\">CWShredder<\/a> (note that CWShredder was sold to InterMute, which has now been bought by Trend Micro.)<br \/>\n\n\n<li>DefinitiveSolutions.Com&#8217;s<a href=\"http:\/\/downloads.pcworld.com\/pub\/new\/utilities\/security\/BHODemon20Setup_2020.exe\">BHODemon<\/a><br \/>\n\n\n<li>Mike Lin&#8217;s <a href=\"http:\/\/www.mlin.net\/files\/StartupCPL.zip\">Startup Control Panel<\/a> (This really should have come with Windows!)<br \/>\n\n\n<li>Darren Schroeder&#8217;s <a href=\"\/download.php?f=MyTop.exe\">MyTop<\/a> utility<br \/>\n\n\n<li>If you don&#8217;t have a zip utility, I recommend <a href=\"http:\/\/www.oldversion.com\/downloadx\/powarc611.exe\">PowerArchiver 6.x<\/a>.  This is the last free version of a very nicely done WinZip clone.<br \/>\n\n\n<li>UPDATE 05-16-2004 &#8211; <a href=\"\/download.php?f=RKDetector.zip\">RootKit Detector<\/a> and <a href=\"\/download.php?f=aports.exe\">aports.exe<\/a><br \/>\n\n\n<li>Added 07-03-2004 &#8211; <a href=\"http:\/\/www.sysinternals.com\/ntw2k\/freeware\/procexp.shtml\">SysInternals&#8217; Process Explorer<\/a><br \/>\n<\/ul>\n\n<br \/>\n(Each of these is discussed in more detail below.)<br \/>\n\n\n<p>\nNow, you&#8217;re going to run the listed tools.  Each one performs a different function (although several of them are similar).<br \/>\n\n\n<p>\nIf you run into any problems with this process, visit any of the forums listed at <a href=\"http:\/\/asap.maddoktor2.com\/\">the Alliance of Security Analysis Professionals<\/a>.<br \/>\n\n\n<p>\nThe first tool to run is McAfee&#8217;s <span class=\"tool\">Stinger<\/span> utility.  Stinger is a stand-alone antivirus scanner that is regularly updated by McAfee that will catch and clean the most current viruses and worms.  Simply double-click the <span class=\"command\">S-T-I-N-G-E-R.EXE<\/span> file, then click the <span class=\"command\">Scan Now<\/span> icon. Let the scanner run to completion.<br \/>\n\n\n<p>\nAs a checkpoint, now run <span class=\"tool\">HijackThis<\/span>.  It&#8217;s also a stand-alone utility that will scan for certain anomolies and make a list that can be analyzed.  Double-click the <span class=\"command\">HijackThis.exe<\/span> icon, the click the <span class=\"command\">Scan<\/span> button.  When the scan finishes, click the same button (now labeled <span class=\"command\">Save Log<\/span>) and save the file somewhere you can find it.  Then you can exit the HijackThis utility.<br \/>\n\n\n<p> The third step is to install and run Lavasoft&#8217;s <span class=\"tool\">Ad-Aware<\/span>.  Double-click the <span class=\"command\">aawpersonal.exe<\/span> file and click <span class=\"command\">Next<\/span> four times, then <span class=\"command\">Finish<\/span>.  The installation program will put an icon on your desktop.<br \/>\n\n\n<p>\nClose all open windows, especially any Explorer and Internet Explorer windows. Double-click the icon, then click on the <span class=\"command\">Check for updates now<\/span> link.  In the update window, click the <span class=\"command\">Connect<\/span> button, then click <span class=\"command\">OK<\/span> to update the signature file.  (Keep in mind the dates in this program are in European format, DAY.MO.YEAR.)  After the update is done, click <span class=\"command\">Finish<\/span>, then <span class=\"command\">Start<\/span> and <span class=\"command\">Next<\/span>.  When the scan finishes, click <span class=\"command\">Next<\/span> twice and say <span class=\"command\">OK<\/span> when prompted.  After that, you can close Ad-Aware.<br \/>\n\n\n<p>\nStep four: <span class=\"tool\">Spybot Search &#038; Destroy<\/span>.  Double-click the <span class=\"command\">spybotsd14.exe<\/span> icon.  click  <span class=\"command\">Next<\/span>, Read and accept the license agreement and click <span class=\"command\">Next<\/span> twice.  On the &#8220;Select Components&#8221; screen, uncheck everything except the &#8220;Main Files&#8221; component, then click <span class=\"command\">Next<\/span> twice.  On the &#8220;Select Additional Tasks&#8221; screen, uncheck the &#8220;Create a Quick Launch icon&#8221;, then <span class=\"command\">Next<\/span> and <span class=\"command\">Finish<\/span>.<br \/>\n\n\n<p>\nDouble-click the <span class=\"command\">Spybot &#8211; Search &#038; Destroy<\/span> icon.  Select the language (English is the white flag with the red cross).  On the next two dialog boxes, read the warnings and click <span class=\"command\">OK<\/span>.  Then, click the <span class=\"command\">Search for updates<\/span> button.  Install any updates found; the program will restart on it&#8217;s own.  After it restarts, click  <br \/>\n<span class=\"command\">Check for problems<\/span>.<br \/>\nWhen the scan finishes, click <span class=\"command\">Fix selected problems<\/span> and remove everything selected by default.<br \/>\n\n\n<p>\nLast, run <span class=\"tool\">HijackThis<\/span> again, and save the second log file with a new name (&#8220;hijack2.log&#8221; for example&#8221;).  Then, if you have any questions or concerns about anything else installed on your computer, post the contents of the second log file to one of the <a href=\"http:\/\/asap.maddoktor2.com\/\">ASAP<\/a> member forums.<br \/>\n\n\n<p>\nThe last four tools, <span class=\"tool\">CWShredder<\/span> is designed to clean up a specific strain of spyware, known under the name &#8220;Cool Web Search&#8221;.  <span class=\"tool\">BHODemon<\/span>, <span class=\"tool\">Startup Control Panel<\/span> and <span class=\"tool\">MyTop<\/span> are not specifically spyware or virus removal tools, but are useful for diagnostics.<br \/>\n\n\n<p>\n\n\n<dl>\n\n\n<dt class=\"tool\">CWShredder<\/dt>\n\n<br \/>\n\n\n<dd>From the original author of HijackThis: CWShredder is &#8220;a small utility for removing CoolWebSearch (aka CoolWwwSearch, YouFindAll, White-Pages.ws and a dozen other names)&#8230;.This program is updated to remove the new variants once they come out.<br \/>\nRead my article with documentation on Coolwebsearch <a href=\"http:\/\/www.spywareinfo.com\/~merijn\/cwschronicles.html\">here<\/a>.&#8221;<br \/> From <a href=\"http:\/\/www.intermute.com\/products\/cwshredder.html\">Intermute<\/a>: &#8220;CWShredder\ufffd finds and destroys traces of CoolWebSearch. CoolWebSearch is a name given to a wide range of different browser hijackers. Though the code is very different between variants, they are all used to redirect users to coolwebsearch.com and other sites affiliated with its operators.&#8221;<br \/>\n<\/dd>\n\n<br \/>\n\n\n<dt class=\"tool\">BHODemon<\/dt>\n\n<br \/>\n\n\n<dd>From the author: &#8220;BHODemon scans your Registry for BHOs (Browser Helper Objects), and presents any it finds in a list.  By highlighting a BHO in this list, and clicking the &#8220;Details&#8221; button, you can see information about this BHO, and even disable it if you wish.&#8221;<br \/>\n<\/dd>\n\n<br \/>\n\n\n<dt class=\"tool\">Startup Control Panel<\/dt>\n\n<br \/>\n\n\n<dd>From the Author: &#8220;Startup Control Panel is a nifty control panel applet that allows you to easily configure which programs run when your computer starts. It&#8217;s simple to use and, like all my programs, is very small and won&#8217;t burden your system. A valuable tool for system administrators!&#8221;<br \/>\n<\/dd>\n\n<br \/>\n\n\n<dt class=\"tool\">MyTop<\/dt>\n\n<br \/>\n\n\n<dd>Handy utility, especially with Windows 95\/98 (and possibly ME) which do not have a task manager.  MyTop lists all currently running processes on your computer and gives you the ability to kill them, without having to give a CTRL-ALT-DEL.  Windows NT, 2000 and XP all have a built-in utility that performs the same function, the Task Manager, which can be accessed by either  pressing CTRL-ALT-DEL and clicking &#8220;Task List&#8221;,  right-clicking on the Taskbar and selecting &#8220;Task Manager&#8221;, or pressing SHIFT-CTRL-ESC.<br \/>\n<\/dd>\n\n<br \/>\n\n\n<dt class=\"tool\">Process Explorer<\/dt>\n\n<br \/>\n\n\n<dd>From the Author: &#8220;The unique capabilities of Process Explorer make it useful for tracking down DLL-version problems or handle leaks, and provide insight into the way Windows and applications work.&#8221;<br \/>\n\n\n<dt class=\"tool\">Root Kit Detector<\/dt>\n\n<br \/>\n\n\n<dt class=\"tool\">aports.exe<\/dt>\n\n<br \/>\n\n\n<dd>This set of tools is useful in removing a newer, nasty version of CoolWebSearch that uses a malicious hacker tool called Hacker Defender to prevent removal of it&#8217;s files and hide the processes and other means of identifying the offender.  Instructions can be found at <a href=\"http:\/\/bagpuss.swan.ac.uk\/comms\/hxdef.htm\">This page at the University of Wales at Swansea<\/a>.<br \/>\n<\/dl>\n\n\n\n\n<\/div>\n\n<br \/>\n]]><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Cleaning up Spyware and Viruses First, gather the proper tools: McAfee Associates&#8217; Stinger Anti-Virus scanner Lavasoft&#8217;s Ad-Aware PepiMK&#8217;s Spybot Search &#038; Destroy Merijn&#8217;s (SpywareInfo.com) Hijack This and CWShredder (note that CWShredder was sold to InterMute, which has now been bought by Trend Micro.) DefinitiveSolutions.Com&#8217;sBHODemon Mike Lin&#8217;s Startup Control Panel (This really should have come with [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"class_list":["post-42","post","type-post","status-publish","format-standard","hentry","category-computers"],"_links":{"self":[{"href":"http:\/\/www.noidea.us\/wordpress\/wp-json\/wp\/v2\/posts\/42","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.noidea.us\/wordpress\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.noidea.us\/wordpress\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.noidea.us\/wordpress\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/www.noidea.us\/wordpress\/wp-json\/wp\/v2\/comments?post=42"}],"version-history":[{"count":0,"href":"http:\/\/www.noidea.us\/wordpress\/wp-json\/wp\/v2\/posts\/42\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.noidea.us\/wordpress\/wp-json\/wp\/v2\/media?parent=42"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.noidea.us\/wordpress\/wp-json\/wp\/v2\/categories?post=42"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.noidea.us\/wordpress\/wp-json\/wp\/v2\/tags?post=42"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}