Monday, November 10, 2008

Spyware/adware trouble?

How to Remove Adware and Spyware
By Mary Landesman, About.com

Getting stubborn adware and spyware off your PC can be frustrating. However, there are steps you can take to make the process easier and more effective. If your system is heavily infested, you'll need access to a clean computer to download the necessary tools. If you don't have a second computer, ask a friend to download the tools for you and burn them to a cd. If you plan to use a USB drive to transfer the downloaded files, make sure both your computer and your friend's computer have autorun disabled1.

1. Disconnect from the Internet
Close all open browser windows and applications (including email) and then disconnect your PC from the Internet. If you can access the back of the computer, the easiest thing to do is just remove the phone line or cable connecting the PC to the modem or router. If the back of the computer isn't easily accessible, you can remove the ethernet cable or phone line from router or modem.

2. Try a Traditional Uninstall
A suprising number of applications labeled as adware and spyware have fully functioning uninstallers that will cleanly remove the program. Before moving on to more complex steps, start with the easiest route and check the Add/Remove Programs list in the Windows Control Panel2. If the unwanted program is listed, simply highlight it and click the Remove button. In Windows Vista, the Add/Remove Programs feature is listed in Control Panel as Programs and Features. After removing the adware or spyware via Control Panel's Add/Remove Programs, reboot the computer. Make sure you reboot after the uninstall, even if you aren't prompted to do so.

3. Scan Your Computer

After you've disconnected from the Internet, removed any adware or spyware listed in Add/Remove Programs, and rebooted the computer, the next step is to run a full system scan using an up-to-date antivirus scanner. If your scanner will allow it, can the system in Safe Mode3. If you don't have antivirus installed, select from one of these top-rated antivirus scanners4 or from one of these free antivirus scanners5. If prompted, allow the scanner to clean, quarantine, or delete6 as appropriate.

4. Using SmitFraudFix7

Much of today's spyware is delivered via the Zlob family of Trojan downloaders. The free SmitFraudFix tool does a good job of removing many variants of Zlob-related adware and spyware. For download and usage instructions, see: SmitFraudFix Removes Zlob and Other Pests8.

5. Get Clear Access to the Problem

While scanning the system in Safe Mode9 is good practice, it may not be enough to thwart some malware. If the adware or spyware persists despite the above efforts, you'll need to get access to the drive without allowing the adware or spyware to load. The most effective means to get clean access to the drive is to use a BartPE Bootable CD10. Once you've booted to the BartPE CD, you can access the file manager, locate the installed antivirus and rescan the system. Or, locate the offending files and folders and manually delete them.

6. Undo the Residual Damage

After removing the active infestation, you'll need to make sure the adware or spyware won't simply reintegrate itself when the computer is reconnecting to the Internet.

* Before reconnecting, reset your browser start and home pages. (See Resetting Internet Explorer Settings11).
* Ensure your HOSTS file hasn't been hijacked. (See Protecting the HOSTS file12)
* Make sure undesirable websites haven't been added to your Trusted Sites Zone. (See How to Check Your Trusted Sites List13)

7. Preventing Adware and Spyware14
To avoid future adware and spyware infections, be discriminating about what programs you install on your PC. If you see an offer for a program that seems to good to be true, research it first using your favorite search engine. Make sure your Web browser security15 is up to snuff, keep your system fully patched, and follow these adware and spyware prevention tips16.

To view this page in its original form, please click here.

Links in this article:

1. http://antivirus.about.com/od/securitytips/ht/autorun.htm
2. http://antivirus.about.com/od/windowsbasics/ht/controlpanel.htm
3. http://antivirus.about.com/od/securitytips/ht/safemode.htm
4. http://antivirus.about.com/od/antivirussoftwarereviews/tp/aatpavwin.htm
5. http://antivirus.about.com/od/antivirussoftwarereviews/a/freeav.htm
6. http://antivirus.about.com/b/2007/03/11/clean-quarantine-or-delete.htm
7. http://antivirus.about.com/od/freeantivirussoftware/fr/smitfraudfix.htm
8. http://antivirus.about.com/od/freeantivirussoftware/fr/smitfraudfix.htm
9. http://antivirus.about.com/od/securitytips/ht/safemode.htm
10. http://antivirus.about.com/b/2007/11/12/bartpe-bootable-cd-for-windows.htm
11. http://antivirus.about.com/od/securitytips/ht/resetexplorer.htm
12. http://antivirus.about.com/od/securitytips/ss/hosts.htm
13. http://antivirus.about.com/od/securitytips/ht/trustedzone.htm
14. http://antivirus.about.com/od/spywareandadware/a/preventspyware.htm
15. http://antivirus.about.com/od/securitytips/a/websecurity.htm
16. http://antivirus.about.com/od/spywareandadware/a/preventspyware.htm

No comments: