Bill Kuhl wrote:
> Are there good solutions for removing those awful trojan viruses that
> Symantec doesn't stop and that keep loading spyware on your computer?
> Ran into same situation as you described below; website that was
> suppose to be uninstall actually downloaded the virus. I really did
> not want to try the uninstall but was getting desperate.    

I haven't had any big problems with browser hijackers/trojans at work.
That's one of the only things McAfee VSE does well.  However, on the rare
occasion that I get a nasty at work, I just reimage the machine, and
sometimes have to recreate the user's profile.

However, for home machines (or side/consulting work)...

I find the folks over at www.spywareinfo.com to be a great resource.
Additionally, the HiJackThis tool from their website can assist in finding
browser hijackers.

In my experience dealing with tough to remove critters, the best procedures
go something like this.

1) Create a BartPE boot CD w/ Adaware & McAfee http://www.nu2.nu/pebuilder/
2) Boot the system into safe mode.  Disable system restore (if XP) and
third-party browser extensions (IE advanced settings).
3) Boot of the BartPE disk, run McAfee to clean and/or delete any viruses.
The newer McAfee scan defs will pick up some browser trojans and hijackers.
3) Still from BartPE, run Adaware, telling it to scan just the C drive.
4) Still from BartPE, run regedt32 and manually load the HKLM_Software and
HKLM_System hives, as well as any user hives.  Look for anything suspicious
loading in any of the keys mentioned here -
http://is-it-true.org/nt/xp/atips/atips26.shtml.  Remove the suspicious
entries (after making a backup, of course).  Also check the Startup folders
in the various user profiles.
5) Boot back into the PC, again from safe mode.  Run Adaware again off the
BartPE disk.  Install Spybot S&D, manually update defs, scan with that.  Run
HiJackThis, remove any baddies Note, you really have to know how to use
HiJackThis, as it's not automated. There's a good overview at
www.spywareinfo.com.
6) Still in safe mode, delete the IE cache and cookies, check the hosts
file, reset your security zones.  Immunize w/ Spybot and Spywareblaster
(www.javacoolsoftware.com).  Also, use the IE-SpyAd list if you can.
https://netfiles.uiuc.edu/ehowes/www/resource.htm
7) Install Firefox with some extensions, and don't look back.
http://www.mrchuckles.net/archives/000208.php

HTH,
Steven
---
Steven Dickenson <[EMAIL PROTECTED]>
Computer Network Manager
The Key School, Annapolis Maryland

_________________________________________________________________
List posting FAQ:       http://www.swinc.com/resource/exch_faq.htm
Web Interface: 
http://intm-dl.sparklist.com/cgi-bin/lyris.pl?enter=exchange&text_mode=&lang=english
To unsubscribe send a blank email to [EMAIL PROTECTED]
Exchange List admin:    [EMAIL PROTECTED]
To unsubscribe via postal mail, please contact us at:
Jupitermedia Corp.
Attn: Discussion List Management
475 Park Avenue South
New York, NY 10016

Please include the email address which you have been contacted with.

Reply via email to