Home | Forum


  Fixes: 41
  Resolutions: 4673


Remove Spyware
Safe Mode and Internet Explorer Cleanup
Remove Spyware

Resolutions:237 | Views:51313
Comments [29]

Let's review what was done up to this point and also watch what happened on our lab computer.

We went into Safe mode with networking where spyware is "asleep" and won't fight back. We'll see that although 99% percent of the spyware programs are disabled one of them is still running in safe mode and it's spawning pop-ups from time to time. That program managed to stay active in safe mode by infecting components of the Winlogon process. Winlogon is a critical part of the operating system and because Winlogon is active all the time we cannot heal it with conventional methods. From time to time the malware will spawn pop-ups which are located in a random named dll file. The name of the file looks like this: asd57hva.dll and changes at each reboot.

In order to execute these pop-ups the virus will use a system application called rundll32.exe which is also used to run harmless Control Panel components.You will notice the presence of this rundll32.exe application in the task manager list even when we're not running Control Panel applets.

After we booted in safe mode we executed the task manager and launched the Internet Options to clean-up the Internet Explorer. We performed this action in order to be able to download the Ad-Aware antispyware program (subject covered on the next page) and to disable all the toolbars and add-ons that attached to the browser.


   Click here if this resolved your issue.

Submitted by Paul Ionescu
Last modified 2007-09-30
Submit Comments
Article Rating: Low High
Your Name:
Your Comments:
Remove Spyware
Slides:
    1. What is Spyware?
    2. How Can You Get Infected
    3. The Effects of Spyware
    4. The Removal Process
    5. Going In Safe Mode with Networking
    6. Cleaning Internet Explorer
    7. Safe Mode and Internet Explorer Cleanup
    8. Using Ad-Aware
    9. Add-Remove Programs
    10. Performing a MSConfig Clean Boot
    11. The Results of the Initial Cleanup
    12. Spy Sweeper
    13. The End
    14. Submit Your HijackThis Log

In the same category
Articles:
  Uninstall McAfee
  How Can Network W...
  Remove Alemod / E...
  The McAfee Remova...

Quick Fixes:
  
Firewalls
    Internet stops ...

  
Spyware
    Virus Alert - R...

Add new slideshow

     ©2005-2007 Paul Ionescu, All Rights Reserved | Privacy