Thursday, February 01, 2007

How2 fix: Browser Hijack, Spyware, Malware

Definitions:
Browser Hijack: when you can't change your browser start page or control where you surf
Spyware: software that logs where you surf
Malware: any software that does something malicious; like report email address to a spammer

Trash any Norton/Symantec Antivirus/Firewall products (really!)

The Tools:
Recomended O/S; Windows XP sp2 with firewall enabled
Turn off windows file protection (WinXp): SFC /CACHESIZE=0, SFC /PURGECACHE, reboot (WFP can re-install viruses you remove)
Turn off system restore (WinXp): Right click My Computer, properties, system restore tab, uncheck (*Optional*)
windowsupdate.microsoft.com follow the prompts, lather rinse repeat, make sure you update to Internet Explorer 7

AVG antivirus free edition - as good as any commercial product
FreeScan is an online scanning tool; no installation required
AVG Antispyware - a free spyware tool that stays in the system tray (also M$AntiSpyare, Adaware, Spybot)
Autoruns - find programs that start at boot (just uncheck everything you dont recognize it can be re-enabled later)

Stubborn Infections may require these:
RootkitRevealer - a root kit is a special type of malware that embeds itself in the o/s
Hijack This - is your last resort, it is a powerful removal tool HowTo here
Stuff recommended by others: SwatIt, CWShreader, Macecraft Reg Cleaner
system file check&restore; sfc /scannow (put the WinXp Cd in the drive)
reinstall winsock KB817571
resetting the TCP/IP stack KB299357


After things are working right:
SFC /CACHESIZE=50
Turn system restore back on if you want your pc to run extra slow

To prevent reoccurrance:
follow this standard build

Disclaimer: This is a recipie not only to clean a system but also to build a system that has proven to me to be cost effective and resistant to most malware without being intrusive. I take no respnsiblity for actions incured by this article.

No comments: