Results 1 to 14 of 14

Tutorial: The Hunt for Spyware

  1. Child's Play Donor Technical Help Senior Member General Discussions Senior Member Homeworld Senior Member Forum Subscriber  #1
    Gimme your lunch Moeney! Moe's Avatar
    Join Date
    Oct 2003
    Location
    #homeworld

    Tutorial: The Hunt for Spyware


    Introduction

    This tutorial is intended as a general guide on how to fight spyware for inexperienced computer users. It is by no means complete, but will help you get rid of a bunch of nasty bugs and show you how to avoid getting hit in the future.

    Table of Contents
    What is Spyware?
    Types of Spyware
    Fighting Spyware - First Steps
    Fighting Spyware - The Tools Pt. 1
    Fighting Spyware - The Tools Pt. 2
    Using the Tools
    Preventing Spyware Infections


    What is Spyware?
    Strictly speaking there is spyware, adware, and a lot of other stuff that can be summarily called malware. I'll refer to the whole thing as spyware in this guide.
    These are programs that aren't really classified as viruses but are not something you want to have on your computer nonetheless. They range from rather harmless tracking cookies to browser hijacks, dialers and other nasty stuff. Effects include redirecting internet searches, pop-ups, compromising security and generally slowing down your computer.

    Spyware is the most annoying form of advertising. The idea behind it is to literally bombard you with ads. The next section will list a few of the dozens of things spyware can do:


    Types of Spyware - a short Overview
    • Tracking cookie: This is the most harmless form of spyware. A cookie is a small file used to identify your computer to a website. These forums use a cookie to keep you logged in, for example. Tracking cookies try to track your movement throughout the web, allowing certain websites to hit you with targetted advertising. If you browse through a lot of hardware websites, certain sites will start showing you hardware ads. These things are quite harmless, but people generally value their privacy and don't want to get tracked.
    • Browser Hijack: A browser hijack is a much more serious form of spyware. The name describes it pretty well. This hijack re-sets your homepage to a usually ad-ridden page offering everything from viagra to online gambling - in short, a page that will try to get you to give them money in exchange for nothing. Internet Explorer is quite vulnerable to this, I haven't experienced any other browser hijacks, although I'm quite confident that they are out there as well.
    • Search Redirects: Similar to the hijack, these redirects will prevent you from using google or other regular search engines, and instead direct you to a page that will display sponsored links. Whatever you search for, you can be sure that the pages listed as search results will try to sell it to you.
    • Popups: A small program that runs in the background. It will open popups at random, even if you're not currently surfing, and possibly drop shortcuts to online casinos and other junk on your desktop
    • Search Bar/Weather Bar/Search Assistant: These programs offer little functionality at all and are used as a transport medium for some of the spyware programs mentioned above.



    Fighting Spyware - First steps

    Depending on which form of spyware you have been hit with it can be very easy or almost impossible to get rid of it. Towards that end, there are a bunch of helpful programs, which I will comment on in the next section. For now, here are the first steps you should take before attempting to remove spyware.

    • Back up your personal data. Most of the programs you can use to fight spyware are quite safe, but you never know. Also, some (albeit quite rare) forms of spyware object to being removed and may damage your installation of windows when you remove them.
    • Turn off system restore. There is no point in removing all spyware, only to have windows put it back on your system from a previous restore point. Instructions on how to turn off system restore can be found here.



    Fighting Spyware - The Tools Pt. 1
    A bunch of nasty critters can be removed from your system with the tools windows puts at your disposal. We'll have a look at them now.
    • Common Sense: I cannot stress this enough, probably the number one reason for spyware infections are gullible users. First off, 99% of the content on the internet isn't free, even if it says so. There is almost always a catch.
      A blinking banner telling you that you have won something means you didn't win shit, but they will tell you that after you entered your email and maybe home address. They will also tell you that by giving them your address you agreed to receive five dozen emails per day offering products to enlarge your penis.
      "Free search bars" or "free weather bars" or "free smilies" are just an excuse to drop all kinds of nasty programs on your computer, and it will take you hours to clean up that mess. Be smart, think about what you do online. The general rule of thumb is, the flashier the banner, the more emphasis is put on the words "absolutely free", the more likely it is to drop unwanted programs on your computer.
    • Software Uninstall: That's right, some programs allow you to remove them voluntarily. Click on start, select "settings", then click on "control panel". Then click on "Add or Remove Programs". After a short while, a list of all installed software products will appear. Go through it and look for suspicious entries, such as "Search Assistant" or "Weather Bar" . Click on remove.
    • msconfig: This tool lets you control which programs and services are launched at windows startup. To activate it, click on "Start", select "run", and type "msconfig". Then hit enter.
      In the new window click on the "Startup" tab. You can choose which programs windows is supposed to launch when it boots up. Disable suspicious entries here, but make sure not to kill vital processes. It's usually a good idea to google for then name of the suspicious process, there are a bunch of sites that offer detailed info on whether this is spyware or merely your mouse driver.



    Fighting Spyware - The Tools Pt. 2
    Some of the nastier forms of spyware can't be killed so easily and require you to download external programs. All of the tools I will now describe are available for free. After downloading them, make sure to update them using their update functions.
    • Lavasoft Ad-Aware: A handy tool that can detect a lot of common spyware threats and remove them. It can also scan for dangerous windows settings.
    • Spybot Search & Destroy: This program uses a different search approach and complements Ad-Aware nicely. It also offers an "immunize" function which will block a number of bad sites, preventing you from getting certain types of spyware in the first place.
    • Ewido Security Suite: This program is not freeware, but it has a free trial version which you can use for two weeks. It is one of the most comprehensive anti-spyware tools I have come across so far,and offers a bunch of very useful features, such as scanning your RAM for active spyware threats. The trial version is fully functional.
    • HijackThis!: This tool analyzes your startup list and certain registry entries and will show whether or not you are infected. Be careful before you kill any entries there, a lot of them are from legitimate programs. However, most forums dedicated to helping people with spyware problems will require you to post a log from this program so the pros can have a detailed look at your problem.



    Fighting Spyware - Using the Tools
    Make sure you followed the steps detailed in the section Fighting Spyware - First Steps before running any of the programs.
    After you have done that, download and install the tools mentioned above. Make sure to let the programs update their definitions afterwards.
    You can run all those tools in normal mode, however a lot of the newer spyware variants won't be removed that way. A better idea is to reboot in safe mode. To do that, reboot your computer and press F8 before windows loads. You will be presented with a screen with multiple boot options. Select "safe mode" (should be the first item on the list).
    Windows will boot, but it will probably look like crap. That is because in safe mode only the most basic drivers are loaded, which results in reduced graphics functions etc. Don't worry, the next normal reboot will reveal windows in its full glory again.
    Run the tools one after another. Remove all entries they find. Reboot the computer again in normal mode.


    Preventing Spyware Infections
    There's a bunch of stuff you can to to reduce the risk of getting hit by spyware again.
    • Think before you click. This sounds trivial, but the best defense is still an informed user. Don't click on popups promising to increase your computer performance. Don't open suspicious emails. Don't click on banners offering free icons, or weather bars, etc. There is no such thing as a free lunch, this stuff is almost always infected with spyware or worse.
    • Keep your software up to date. This means updating windows on a regular basis. Security holes are found and fixed all the time, and you should take advantage of those fixes.
    • Don't use IE. Internet Explorer is the #1 most used browser on the web, meaning that most people who program spyware target IE and it's security holes. You can avoid a lot of nasty stuff by switching to a different browser. Firefox and Opera are popular, easy to use and offer advanced browsing features which IE lacks.
    • Run spyware sweeps on a regular basis. You should install the tools mentioned in the sections above and run them every now and then with updated definitions to kill off any spyware you might have contracted. Some of them also offer guards, programs that run in the background similar to a virus scanner and alert you when spyware attempts to infect you.
    • You might want to install a firewall as well, which will alert you if unknown programs try to access the internet. There are several free firewalls out there. I use Kerio Personal Firewall myself. Other free firewall software solutions are Zone Alarm and Tiny Personal Firewall.


    If you still run into spyware problems you can't solve, you can create a thread about it in the Technical Discussions Forum. Please include a log from HijackThis.

  2. #2
    A176's Avatar
    Join Date
    Nov 2001
    Location
    Canada
    A1 says common sense is the #1 tool to fight spyware. i do use IE but have not gotten one piece of spyware (minus tracking cookies) since...a long time ;|

    ps:

    types of spyware: a.k.a. malware or adware, programs that are installed on your computer that use your own computer resources for whatever purpose the developer of the program wants.

    fighting spyware: MS Antispyware, or what was once known was Giant Antispyware, is a great program for every kind of user, whether a computer noob or if you build computers from scratch. the main reason to get this is its integration and monitoring abilities with Windows itself, notifying you of every unknown program installation to make sure your computer is clean.
    <Hyperian> yes treb
    <Hyperian> teach me how to be a player like you
    <treb|coffee> 1. learn to dance 2. be yourself 3. treat them as friends
    <Hyperian> those dont work

  3. #3
    Reignfire
    Guest
    Quote Originally Posted by Moe
    Preventing Spyware Infections
    I recommend SpywareBlaster. It doesn't remove anything, but it prevents adware/spyware from being installed. I've had this installed for at least a year and Spybot never finds anything and Ad-aware only finds Tracking Cookies.

  4. #4
    Otherworldly Invader Gyokuran's Avatar
    Join Date
    Dec 2002
    Location
    Washington State
    Quote Originally Posted by A176
    A1 says common sense is the #1 tool to fight spyware. i do use IE but have not gotten one piece of spyware (minus tracking cookies) since...a long time ;|

    ps:

    types of spyware: a.k.a. malware or adware, programs that are installed on your computer that use your own computer resources for whatever purpose the developer of the program wants.

    fighting spyware: MS Antispyware, or what was once known was Giant Antispyware, is a great program for every kind of user, whether a computer noob or if you build computers from scratch. the main reason to get this is its integration and monitoring abilities with Windows itself, notifying you of every unknown program installation to make sure your computer is clean.
    I agree with everything in this post. Its very easy to use IE and not have a spyware infested system, I cant remember the last time I've picked some up. And I've also been quite happy with Microsoft Antispyware. Also remember 1 program isnt recomended, I use both Adaware, Spybot and MAS, in the case of spyware searching programs the more the better as some pick up stuff others miss.

  5. Child's Play Donor Technical Help Senior Member General Discussions Senior Member Homeworld Senior Member Forum Subscriber  #5
    Gimme your lunch Moeney! Moe's Avatar
    Join Date
    Oct 2003
    Location
    #homeworld
    I did put something like "common sense" in the "preventing infections" section, but I'll put it in there again, it is pretty important.

    MS Antispyware is based off of GIANT antispyware and is still a beta, I'm pretty sure once it gets out of the beta phase MS won't be giving it away for free, which is why I didn't include it in that list, but I suppose I could edit it in if someone would please provide me with a description for it?

    Anything else I missed?

    By the way, you guys should try Ewido, it's fantastic. Beats MAS hands-down.

  6. #6
    CounterSpy Enterprise edition is used by our buisness. It works well. I've had Microsoft, Adaware, and Spybot scan my system, and nothing is ever found. I highly recommend it.
    Last edited by Merturk_NB; 19th Jun 05 at 5:10 PM.

  7. Child's Play Donor Technical Help Senior Member General Discussions Senior Member Homeworld Senior Member Forum Subscriber  #7
    Gimme your lunch Moeney! Moe's Avatar
    Join Date
    Oct 2003
    Location
    #homeworld
    Merty: make a new thread about that in tech discussions please.

  8. #8
    Here we go. The Collector has some notes, courtesy of a spyware attack by buddylinks.net

    First off trust nothing online and whatnot and on and on and on.

    Two. When you notice anything strange going on with your progs (changed wallpapers, new folders, new icons on desktop), immediately go to Task Manager and have a snoop around for new programs. search for the names on google.

    At the same time, run the traditional spyware/virus checks at the same time. Purge the system.

    Check msconfig for startup stuff. Eliminate it. Check Add/Remove Programs. Eliminate it. reboot.

    On startup, check taskman again. Check for shortcuts again. If something popped up, search for the file on the hard drive and delete manually.

    Then search the registry for the name of the program (not the file name). You may need to broaden the search terms a bit. In the registry, be vewy, vewy careful about what you do. Post on the RB or any other board full of people who know what they're doing (or have half an idea), and be prepared for the possibility of ruining your registry.

    Remove registry entries corresponding to spyware. At this point, by executing said action you release me from any responsibility/obligations stemming from your actions.

    Reboot.

    Check one more time.

    Post on Relic Forums, or try broadening search terms. You may have a second piece of low-profile spyware, running in background/hiding in HD/hiding in registry, either running itself or resurrecting the other one.
    "In the future, I plan on taking more of an active role in the decisions I make." ~Paris Hilton

  9. #9
    Banned Roysalipuran's Avatar
    Join Date
    Dec 2008
    Location
    On the frontlines. Vehicle: PzKpfw Tiger II. Loyalty:To the Philippines
    thanks Moe you helped me quite a lot!

  10. General Discussions Senior Member The Workshop Senior Member  #10
    I can baluga my lawnmower Belgarion's Avatar
    Join Date
    Jun 2003
    Location
    Bonnie Scotland
    I also recommend Malwarebytes
    www.malwarebytes.org
    It doesnt automatically update but it is rather good at scareware nasties
    Is 20 pound for the weight like 30 pounds if a guy lifts?
    REKI
    So either your little non-english speaking weightlifting neighbour has broken in to your house to borrow your computer & Relic forums login, or you're spinning us a line.. :p

  11. #11
    Banned Roysalipuran's Avatar
    Join Date
    Dec 2008
    Location
    On the frontlines. Vehicle: PzKpfw Tiger II. Loyalty:To the Philippines
    Youp and you might want to use CCleaner ( http://www.ccleaner.com/ ) if and when you want to remove cookies.. (It works for me when i do get infected sometimes)

  12. #12
    Banned Spey's Avatar
    Join Date
    Dec 2008
    Location
    The heart of the Galaxy (Balcora)
    Hi, just spotted this thread, great information Moe

    On my computer, I use PC Tools Firewall Plus and AVG Anti-Virus Free. They're great programs, free and I recommend them whole-heartedly.

  13. Forum Subscriber  #13
    I'm busy reading the rules for a Spiral Knights Fashion Contest Afoxi's Avatar
    Join Date
    Jun 2003
    Advanced Spyware detection/removal aid for Windows:
    http://technet.microsoft.com/en-us/s...s/default.aspx

    Provided you know how your OS works, some of these tools will help you manually locate and remove malware (and even virii!), or at least cripple them to the point where they're pretty much harmless.

    You can also pretty much screw over windows depending on what you do... I managed to disable the registry and get stuck in a neverending reboot cycle once, but I did manage to fix it.
    E=mc^(OMG)/wtf

  14. #14
    If you don't mind training a firewall, COMODO Internet security is a really nice program. It's defense+ ability can stop infections and it allows you to spot and take care of spyware/maleware before they become a problem. Be prepared for a lot of pop-ups when you start training the defense+ systems though. You can also choose to disable it if you just want the firewall.

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

     

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •