Bill Kuhl wrote: > Are there good solutions for removing those awful trojan viruses that > Symantec doesn't stop and that keep loading spyware on your computer? > Ran into same situation as you described below; website that was > suppose to be uninstall actually downloaded the virus. I really did > not want to try the uninstall but was getting desperate.
I haven't had any big problems with browser hijackers/trojans at work. That's one of the only things McAfee VSE does well. However, on the rare occasion that I get a nasty at work, I just reimage the machine, and sometimes have to recreate the user's profile. However, for home machines (or side/consulting work)... I find the folks over at www.spywareinfo.com to be a great resource. Additionally, the HiJackThis tool from their website can assist in finding browser hijackers. In my experience dealing with tough to remove critters, the best procedures go something like this. 1) Create a BartPE boot CD w/ Adaware & McAfee http://www.nu2.nu/pebuilder/ 2) Boot the system into safe mode. Disable system restore (if XP) and third-party browser extensions (IE advanced settings). 3) Boot of the BartPE disk, run McAfee to clean and/or delete any viruses. The newer McAfee scan defs will pick up some browser trojans and hijackers. 3) Still from BartPE, run Adaware, telling it to scan just the C drive. 4) Still from BartPE, run regedt32 and manually load the HKLM_Software and HKLM_System hives, as well as any user hives. Look for anything suspicious loading in any of the keys mentioned here - http://is-it-true.org/nt/xp/atips/atips26.shtml. Remove the suspicious entries (after making a backup, of course). Also check the Startup folders in the various user profiles. 5) Boot back into the PC, again from safe mode. Run Adaware again off the BartPE disk. Install Spybot S&D, manually update defs, scan with that. Run HiJackThis, remove any baddies Note, you really have to know how to use HiJackThis, as it's not automated. There's a good overview at www.spywareinfo.com. 6) Still in safe mode, delete the IE cache and cookies, check the hosts file, reset your security zones. Immunize w/ Spybot and Spywareblaster (www.javacoolsoftware.com). Also, use the IE-SpyAd list if you can. https://netfiles.uiuc.edu/ehowes/www/resource.htm 7) Install Firefox with some extensions, and don't look back. http://www.mrchuckles.net/archives/000208.php HTH, Steven --- Steven Dickenson <[EMAIL PROTECTED]> Computer Network Manager The Key School, Annapolis Maryland _________________________________________________________________ List posting FAQ: http://www.swinc.com/resource/exch_faq.htm Web Interface: http://intm-dl.sparklist.com/cgi-bin/lyris.pl?enter=exchange&text_mode=&lang=english To unsubscribe send a blank email to [EMAIL PROTECTED] Exchange List admin: [EMAIL PROTECTED] To unsubscribe via postal mail, please contact us at: Jupitermedia Corp. Attn: Discussion List Management 475 Park Avenue South New York, NY 10016 Please include the email address which you have been contacted with.
